Cross your fingers and click

UH!Mustaca!HTML

  30 June 2006

Description

Making what looks like a valid link to PayPal turn into a link to a phishing site using a FORM and a cleverly constructed INPUT tag.

Submitted by Sorin Mustaca.

Example

<FORM action=http://201.117.14.43:8090/xxev/cmd_run/index.php?>
<p><a href="https://www.paypal.com/cgi-bin/webscr?cmd=_login-run">
<font size="2" face="Arial, Verdana">
<INPUT style="BORDER-RIGHT: 0pt;
BORDER-TOP: 0pt; FONT-SIZE: 10pt; BORDER-LEFT: 0pt; CURSOR:
hand; COLOR: blue; BORDER-BOTTOM: 0pt; BACKGROUND-COLOR: transparent;
TEXT-DECORATION: underline" type=submit
value=https://www.paypal.com/cgi-bin/webscr?cmd=_login-run>
</font></a></p></form>

Entries

Are you feeling lucky, Sergey?

Spammers compendium entry - Are you feeling lucky, Sergey?

Pretty Darn Fancy

Spammers compendium entry - Pretty Darn Fancy

In the background

Spammers compendium entry - In the background

Doing The Twist

Spammers compendium entry - Doing The Twist

A Flash In The Pan

Spammers compendium entry - A Flash In The Pan