I consider myself to be internet and security savy and I know not to follow links to potently unsafe sites,
I vist AOL chatrooms and recieved an E-mail that claimed to have a link to their AOL member page that has pictures on it. The address on the mail was http://hometown.aol.com/A.g.g.i.e.B.3.4.9./ {.'s added to break link}
Because it was a hometown page I felt safe going there and navigated there through the AOL browser.
On the page was a login box for You Got Pictures which is an AOL service. I figured if I was viewing the page though the AOL browser it should have passed my credentials and I was afraid the logon box was bogus so I went to AOL live chat and asked if the logon box was real
Here is the chat log anything in /\ /\ is what I was thinking
1:04:54 AM System Welcome <my name> …
1:04:54 AM System Connecting to server. Please wait…
1:04:54 AM System Connected to server.
1:05:10 AM System AOLTechAXH has joined this session!
1:05:10 AM System Connected with AOLTechAXH
1:05:14 AM System Hello, <my name>. Welcome to Live Technical Support. My name is Ariel.
1:05:16 AM System <my name> stated the question or problem as: Is the login box on http://hometown.aol.com/A.g.g.i.e.B.3.4.9./ really an AOL pictures login or is it fake?.
1:05:18 AM System Are you signed on with the same computer that you need assistance with?
1:05:46 AM You Yes I am
1:06:27 AM You From the AOL browser when I go to http://hometown.aol.com/A.g.g.i.e.B.3.4.9./ it shows what looks to be an AOL login screen but I’m not sure if it’s real or spoofed
1:07:02 AM AOLTechAXH Levy, I understand that you are have questions about a ‘log in’ window that appears on an AOL Hometown page…
1:08:07 AM AOLTechAXH Levy, please give me a moment to check on that URL you just gave me.
1:11:45 AM AOLTechAXH Hello again.
1:12:44 AM You Yes
1:12:48 AM AOLTechAXH Sorry for the delay, and thanks for waiting.
1:13:01 AM AOLTechAXH The page is legitimate.
1:13:16 AM AOLTechAXH Were you attempting to access another AOL member’s homepage when this appeared?
1:13:42 AM You Thank you. Yes I was attempting to access the pictures on that page and it has a screen name login box
1:14:33 AM AOLTechAXH You are most welcome.
1:14:39 AM AOLTechAXH Anything else I can assist you with?
/\Trying the site. Entered my AOL name and hmm now I’m on another AOL page asking for the password and username again. The address in the bar is an AOL page, could the first page be a hoax?/\
1:15:13 AM You When I just loged it in sent me to another AOL login screen that asked for my id and password to access pictures. Is that normal?
1:16:01 AM AOLTechAXH Do you still have that screen visible?
1:16:49 AM You Yes when I log into that box it sends me to http://pictures.aol.com/ap/welcome.do
1:17:09 AM You Can you try the login box on the original site. I think it is a spoofed login screen that I just fell for
1:18:43 AM You I just looked at the page source and saw this code
1:18:46 AM You <table cellpadding=“0” cellspacing=“0” border=“0” width=“100%” bgcolor=“white”>
<tr>
<td align=“center”>
<SCRIPT LANGUAGE=“JavaScript1.1”>htmlAdWH(‘93212816’, ‘728’, ‘90’);</SCRIPT><NOSCRIPT><A HREF=“http://ar.atwola.com/link/93212816/aol”><IMG SRC="http://ar.atwola.com/image/93212816
1:21:38 AM AOLTechAXH Levy, I also checked on it to verify. It was indeed a scam, and I received the same source code as you.
1:22:00 AM AOLTechAXH Please rest assured that the page has been REPORTED to the appropriate Department for immediate investigation and removal.
1:22:26 AM AOLTechAXH At this time, I’d like to recommend that you immediately change the password you are currently using, to make sure that it is not used to access your AOL Screen Name.
/\ let me see who owns atwola.com hmm accoording to samspade.org it is registered to AOL. It could be real but I’m not trusing it, I’m sticking with my changed password /
AOL, if someone is questioning a site why don’t you try the links and make sure they give what the expected outcome is before saying it’s ok. What if someone not as savvy as myself was scammed and had their account compromised?
I’m really curious what the javascript above does