  MxxCon
join:1999-11-19 Brooklyn, NY clubs:  
| Verify a Website
seems like ELNK's verification application has a HUGE hole that people might exploit. i found this exploit from another thread on this forum. if you got the following url with IE or Firebird you'll get different results »support.earthlink.net/support/ve···ling.asp
which one is correct?(beside the fact that we know www.start.earthlink.net is real ELNK page) -- [Sig removed by Administrator: Signature can not exceed 20GB] |
|
  jazzman916 Life on the Upbeat Premium,Mod join:2001-09-01 Birdland clubs: | Hopefully just_robert can take a look later today. |
|
 RadioDoc 58ef2c0 Premium,ExMod 2000-03 join:2000-05-11
·AT&T Midwest
| reply to MxxCon That's not what is going on at all. Someone has stolen the source code to some Earthlink pages for the purpose of masking a credit card and bank account number/info theft operation. They use the source code to make it look like it's a valid Earthlink site when in reality it is not. Without going into more detail, it's as slimy as it gets, is based in Brazil, and also baits the trap with child porn.
I'm sending the info to Earthlink right now. |
|
 RadioDoc 58ef2c0 Premium,ExMod 2000-03 join:2000-05-11
·AT&T Midwest
| reply to MxxCon Here is the real meat of the operation... look at the info they are trying to collect! |
|
 KarlP8
join:2003-10-03 Douglasville, GA | reply to MxxCon *hears the sound of write heads happily churning away and people who dont know better giving them the info*
In they go marching 1 by 1........ |
|
  Mark910 Premium join:2002-04-21 Dayton, OH clubs: | reply to MxxCon If Earthlink wants this info they will ask you to log in through your homepage to supply account info. -- "My Wild Oats Have Turned to Shredded Wheat." |
|
  rjackal R.I.P Colin McRae 1968-2007 Premium join:2002-07-09 Plymouth, MI clubs:
| reply to RadioDoc It's interesting that there are almost always some typos or grammatical errors on these fake sites that give them away. Like "Issue Bank Name" isn't quite right.. should be "Issuing Bank Name" Or sometimes there is oddly worded English in the field descriptions or instructions, like "Please give password" or something.
Keep on your toes! Spread the word! -- World Rally Wrules! |
|
  just_robert VIP join:2002-04-25 Harrisburg, PA
| reply to MxxCon EarthLink Electronic Support Response
This is a support response from EarthLink
Thanks for reporting this bug MxxCon.
It seems that whenever a URI has the word "track" in it, the script think's it's an invalid URL and claims it's not EarthLink owned.
For example: »www.support.earthlink.net/foo?billing.asp does not generate the error, but »www.support.earthlink.net/track?billing.asp does.
I have reported this bug to our developers.
Thanks again.
Please respond to this post to let us know if your issue is resolved. If you have any further problems, questions or concerns please feel free to contact us via the live chat link below.
Robert O. Electronic Support EarthLink Incorporated
For live online support please click on the following link.
»support.earthlink.net/chat |
|
  fatness subtle Janitor join:2000-11-17 fishing | If they change anything to eliminate the bug, would you let us know? Thanks. |
|