Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Verisign's 'SiteFinder' finds privacy hullabaloo
Deborah Radcliff, SecurityFocus 2003-09-19

Privacy advocates have joined the chorus of critics of Verisign's "SiteFinder," which on Monday began directing mistyped dot-com and dot-net e-mail and Web addresses to a search site operated by the company and Overture.com, a Pasadena, Calif.-based advertising company that brands itself as a search engine.

Comments Mode:
Who's Omniture and what's all this stuff? 2003-09-19
Anonymous
What's all this stuff from the sitefinder page?

0){s_prop12="Yes"}

var s_prop14="No"

if(s_prop15>0){s_prop14="Yes"}

var s_prop16="No"

if(s_prop17>0){s_prop16="Yes"}

var s_prop2=s_prop1+" ("+s_prop13+"/"+s_prop15+")";

var s_prop22="NOT SET"

var s_code=' '//-->

=0

),s_d=s_wd.document,s_n=navigator,s_u=s_n.userAgent,s_apn=s_n.appName,

s_v=s_n.appVersion,s_apv,s_i,s_ie=s_v.indexOf('MSIE '),s_ns6=

s_u.indexOf('Netscape6/');if(s_v.indexOf('Opera')>=0||s_u.indexOf(

'Opera')>=0)s_apn='Opera';var s_isie=(s_apn==

'Microsoft Internet Explorer'),s_isns=(s_apn=='Netscape'),s_isopera=(

s_apn=='Opera'),s_ismac=(s_u.indexOf('Mac')>=0);if(s_ie>0){s_apv=

parseInt(s_i=s_v.substring(s_ie+5));if(s_apv>3)s_apv=parseFloat(s_i)}

else if(s_ns6>0)s_apv=parseFloat(s_u.substring(s_ns6+10));else s_apv=

parseFloat(s_v);function s_num(x){var s=x.toString(),g='0123456789',p,

d;for(p=0;p

0?n.length:1;while(s&&i>=0){s=s.substring(0,i)+n+s.substring(i

+o.length);i=s.indexOf(o,i+l)}return s}function s_ape(s){s=s.toString?

s.toString():s;return s?s_rep(escape(s),'+','%2B'):s}function s_epa(s)

{s=s.toString?s.toString():s;return s?unescape(s_rep(s,'+',' ')):s}

function s_pt(s,d,f,a){var t=s,x=0,y,r;while(t){y=t.indexOf(d);y=y =5){try{return f(a)}catch(e){return et(e)}d=1}@end@*/

if(!d){if(s_ismac&&s_u.indexOf('MSIE 4')>=0)return fb(a);else{

s_wd.s_oe=s_wd.onerror;s_wd.onerror=oe;r=f(a);s_wd.onerror=s_wd.s_oe

return r}}}function s_gtfset(e){return s_tfs}function s_gtfsoe(e){

s_wd.onerror=s_wd.s_oe;s_etfs=1;var code=s_gs(s_un);if(code)s_d.write(

code);s_etfs=0;return true}function s_gtfsfb(a){return s_wd}

function s_gtfsf(w){var p=w.parent,l=w.location;s_tfs=w;if(p&&

p.location!=l&&p.location.host==l.host){s_tfs=p;return s_gtfsf(s_tfs)}

return s_tfs}function s_gtfs(){if(!s_tfs){s_tfs=s_wd;if(!s_etfs)s_tfs=

s_cet(s_gtfsf,s_tfs,s_gtfset,s_gtfsoe,s_gtfsfb)}return s_tfs}

function s_ca(un){un=un.toLowerCase()

var ci=un.indexOf(','),fun=ci =3&&!s_isopera&&(s_ns6 =6.1))

s_ios=1;if(!s_csss&&s_ios&&!s_d.images[imn]){s_d.write(' ');if(!s_d.images[imn])

s_ios=0}}function s_mr(un,sess,q){un=un.toLowerCase();var ci=

un.indexOf(','),fun=ci =0){var b=new Date,e=new Date;while(e.getTime()-b.getTime() '}function s_gg(v){var g='s_'+v

return s_wd[g]?s_wd[g]:s_wd[v]}var s_qav='';function s_havf(t,a){var

b=t.substring(0,4),s=t.substring(4),n=parseInt(s),k='s_g_'+t,m=

's_vpm_'+t,q=t;if(!s_wd['s_'+t])s_wd['s_'+t]='';s_wd[k]=s_wd[m]?s_wd[

's_vpv_'+t]:s_gg(t);s_wd[m]=0;if(t=='charSet')q='ce';else if(t==

'cookieDomainPeriods')q='cdp';else if(t=='channel')q='ch';else if(t==

'campaign')q='v0';else if(s_num(s)){if(b=='prop')q='c'+n;else if(b==

'eVar')q='v'+n}if(s_wd[k]&&t!='linkName'&&t!='linkType')s_qav+='&'+q

+'='+s_ape(s_wd[k]);return ''}function s_hav(){var n,av='charSet,cook'

+'ieDomainPeriods,pageName,channel,server,pageType,campaign,state,zip'

+',events,products,purchaseID,eVarCFG,linkName,linkType'

for(n=1;n =0?'Y':'N',hp=

'',ct='';if(s_apv>=4)s=screen.width+'x'+screen.height;if(s_isns||

s_isopera){if(s_apv>=3){j='1.1';var i1=0,i2=0,sta;while(i2 100)sta=sta.substring(0,100);sta+=';';if(p.indexOf(sta) =4){j=

'1.2';c=screen.pixelDepth;bw=s_wd.innerWidth;bh=s_wd.innerHeight}if(

s_apv>=4.06)j='1.3'}else if(s_isie){if(s_apv =4){v=

navigator.javaEnabled()?'Y':'N';j='1.2';c=screen.colorDepth}if(s_apv>=

5){bw=s_d.documentElement.offsetWidth;bh=

s_d.documentElement.offsetHeight;j='1.3';if(!s_ismac&&s_d.body){

s_d.body.addBehavior("#default#homePage");hp=s_d.body.isHomePage(tl)?

"Y":"N";s_d.body.addBehavior("#default#clientCaps");ct=

s_d.body.connectionType}}}s_q=(g?'&g='+s_ape(s_fl(g,255)):'')+(r?'&r='

+s_ape(s_fl(r,255)):'')+(s?'&s='+s_ape(s):'')+(c?'&c='+s_ape(c):'')+(

j?'&j='+j:'')+(v?'&v='+v:'')+(k?'&k='+k:'')+(bw?'&bw='+bw:'')+(bh?

'&bh='+bh:'')+(vb?'&vb='+vb:'')+(ct?'&ct='+s_ape(ct):'')+(hp?'&hp='

+hp:'')+(p?'&p='+s_ape(p):'')}return s_mr(un,sess,((t?'&t='+s_ape(t):

'')+s_hav()))}function s_dc(un){un=un.toLowerCase()

s_ca(un);return s_gs(un)}

//-->

=0)document.write(unescape('%3C')+'\!-'+'-')

//-->

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/7009/22427#22427
Fighting SiteFinder 2003-09-21
bl0rf
Verisign's 'SiteFinder' finds privacy hullabaloo 2003-09-24
Hugo van der Kooij (2 replies)
Not their first sleazy tactic. 2003-09-29
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus