CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 927
Comments: 25
block bottom
spacer spacer

SIRT(TM)

Spam Incident Reporting and Termination(TM) Squad

A global spam termination operation launched by CastleCops, the volunteer SIRT Squad is comprised of folks who report spam, investigate spam, and actively work on spam takedown and termination. SIRT is funded by CastleCops. Become a SIRT Squad terminator by reporting spam today!

[ How-To / FAQ ]

SIRT -> Confirmed Spam | Terminated Spam


evidence status: confirmed spam

HTTP Response
06 Jul, 2008
10:22:16
HTTP/1.1 301 Moved Permanently
HTTP/1.1 403 Forbidden
ID174283 (termination link)
TitleCanadian Pharmacy, Geocities redirect
Entry
SIRT Squad
Reporter
maps_on
Timestamp15 May, 2008 @ 20:30:33
Topic ID221818 - Read/respond to SIRT commentary.
Handler Note:
16 May, 2008
01:51:00
tembow: Geocities redirection to Canadian Pharmacy site forwardwish.com

Obfuscated Java Script

var goiiinj='jzonwydprqyrxcegw';var ouxmo=0;var nmoldnk, kwczbj, sdxfs='56090C1C1E0910501E1017150D0202024A48300E18162A07021B010D5046140C0913050D411A18094A1C1D121806110C0B491F181F094E4A5 9431806050948574C0308051D1B1D0A001017185C12161F5F585948040908061E0347';kwczbj='';var erafqnh;for( nmoldnk=0;nmoldnk < sdxfs.length;nmoldnk+=2){erafqnh = unescape( '%' + sdxfs.substr( nmoldnk,2));kwczbj += String.fromCharCode( erafqnh.charCodeAt(0) ^ goiiinj.charCodeAt(ouxmo++) );if ( ouxmo >= goiiinj.length ) ouxmo = 0;}document.write(kwczbj);

Decodes to

window.top.location.href = 'http://forwardwish.com';

Use the redirection format as a fingerprint to remove all such breaches of the Geocities Terms of Service

NOTE: The generic fingerprint for redirection scripts starts with
var {TS}='{TSLONG}';var {TS}=0;var{TS}, {TS}, {TS}='{HEX}';{TS}='';var {TS};for( {TS}=0;{TS} < {TS}.length;{TS}+=2){{TS} = unescape( '%' + {TS}.substr( {TS},2));

where {TS} is a variable lower case text string of 3 - 9 characters
and {TSLONG} is a longer lower case text string 5 - 40 characters
and {HEX} is a long hexadecimal character string compring the set 0-9, A-F

Using this generic fingerprint, scan every Geocities page, and remove every page that matches. Keep running the scan and removal until the abuse ceases. Monitor for changes in fingerprint and adjust accordingly.
Handler Note:
16 May, 2008
02:03:28
tembow: LEGAL EVIDENCE OF CRIME - REFER TO YAHOO! LEGAL COUNSEL
Yahoo! and Geocities is shown to be in a nexus with criminal actions at the public information site designed for Law Enforcement
http://www.spamtrackers.eu/wiki/index.php?title=Geocities

The criminal abuse of Yahoo Geocities terms of service is documented in evidence at
http://www.spamtrackers.eu/wiki/index.php?title=Blogspot#Obfuscated_Java_Script_redirections

Criminal Evidence of the frauds perpetrated at the target sites to which Yahoo Geocities is actively providing the access path is at
http://www.spamtrackers.eu/wiki/index.php?title=Canadian_Pharmacy

Yahoo Geocities must act immediately to fulfil its duty to enact its terms of service
"In section 5 MEMBER CONDUCT of its Terms of Service, Yahoo! Geocities has clauses that these redirections violate, and in section 12 TERMINATION there is the right to terminate. Yahoo! Geocities has both a legal right to terminate all of these violations, and a legal obligation to do so."

Reefer also to http://www.castlecops.com/Geocities_redirect_spam174335.html
Handler Note:
16 May, 2008
02:05:17
tembow: Generated and sent email spam alert to respective parties.
Fetched URLs

Report for at 15 May, 2008 @ 20:13:48


fetched page

at 15 May, 2008 @ 20:14:32
MD5 Fingerprint: 55c91036da779243224d7f2f50b531a0
SHA1 Fingerprint: 414f7d3d8f2fbb91a5eaab65a34880a7b317ab86
Version 1.0
spacer spacer