Cross your fingers and click

UH!Mustaca!HTML

  30 June 2006

Description

Making what looks like a valid link to PayPal turn into a link to a phishing site using a FORM and a cleverly constructed INPUT tag.

Submitted by Sorin Mustaca.

Example

<FORM action=http://201.117.14.43:8090/xxev/cmd_run/index.php?>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_login-run">
<font size="2" face="Arial, Verdana">
<INPUT style="BORDER-RIGHT: 0pt;
BORDER-TOP: 0pt; FONT-SIZE: 10pt; BORDER-LEFT: 0pt; CURSOR:
hand; COLOR: blue; BORDER-BOTTOM: 0pt; BACKGROUND-COLOR: transparent;
TEXT-DECORATION: underline" type=submit
value=https://www.paypal.com/cgi-bin/webscr?cmd=_login-run>
</font></a></p></form>

Entries

Ignore the smallprint

Spammers compendium entry - Ignore the smallprint

A small area

Spammers compendium entry - A small area

Script in the middle

Spammers compendium entry - Script in the middle

The Responsibility Transfer

Spammers compendium entry - The Responsibility Transfer

Colored Matrix

Spammers compendium entry - Colored Matrix