View-Source hijacked?! (0/1)

E

Eriq

An e-mail to update Citibank account details was sent with a link to a
server in your net block. Here is the webpage:

http://66.63.81.105:87/cit/index.htm
has some %-encoded characters, but decoding those gives

http://66.63.81.105:87/cit/index.htm

This means you connect using normal web http on port 87 to host
66.63.81.105 and fetch /cit/index.htm

The URL is accessible as http://66.63.81.105:87/cit/index.htm and is
hosted by 66.63.81.105



Here is the e-mail header containing the link:



Return-Path: <[email protected]>

Received: from cable-161-199.inter.net.il
([email protected] [80.230.161.199])

by typhon.host4u.net (8.11.6/8.11.6) with SMTP id
i8RKLj100950

for <[email protected]>; Mon, 27 Sep 2004 15:21:48
-0500

Message-Id: <[email protected]>

X-Mozilla-Status: 0001

X-Mozilla-Status2: 00000000

FCC: mailbox://[email protected]/Sent

X-Identity-Key: id1

Date: Mon, 27 Sep 2004 19:23:16 -0200

From: Citibank <[email protected]>

X-Mozilla-Draft-Info: internal/draft; vcard=0; receipt=0; uuencode=0

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4)
Gecko/20030624 Netscape/7.1 (ax)

X-Accept-Language: en-us, en

MIME-Version: 1.0

To: (e-mail address removed)

Subject: CitiBank reminder: please update your details

Content-Type: multipart/related;

boundary="------------040302030706030804080005"

Status:
 
E

Eriq

Aparently some kind of bug that just happened by chance? I cleared my
cache and the view-source feature started working again.
 
M

Michael Winter

Aparently some kind of bug that just happened by chance? I cleared my
cache and the view-source feature started working again.

I believe you're experiencing a known bug in IE which occurs due to a full
cache.

In case you didn't realise, that e-mail's a scam. It very much like ones I
receive, and I'm not even a Citibank customer, never have been, and never
will be.

Finally, in future do not send attachments to this group or any other
unless they are a binary group. Not only will some clients not be able to
read the contents, but servers (mine included) will reject binary data.

[snip]

Mike
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Members online

No members online now.

Forum statistics

Threads
473,763
Messages
2,569,562
Members
45,038
Latest member
OrderProperKetocapsules

Latest Threads

Top