Lalamymana the Cookie Thief?

Hey guys, found this on my Facebook feed. Thought it would be interesting to read through.

Basically from what I can tell the site writer has literally copy and pasted this "Disable right click script III- By Renigad" and has even left in the instruction tags. My Javascript is a little rusty but what is the point of this page? is it a Facebook cookie thief?

Also why would he put in his www.blogger.com profile? Lalamymana, what a stupid name.


<script language="JavaScript" src="http://j.maxmind.com/app/geoip.js"></script>

<script language="JavaScript">

var country= geoip_country_code();

if(country  == "AU" || country == "IE" || country == "GB" || country == "ZA" || country == "NO"  || country == "US" || country == "CA" || country == "FR" || country == "IE" )      


window.location = "http://www.google.com"


<title>[Video] - Look what this girl is wearing at the beach in front of thousands of people!</title> 

<link rel="shortcut icon" href="http://static.ak.fbcdn.net/rsrc.php/yi/r/q9U99v3_saj.ico" /> 

<meta property="og:title" content="[Video] - Look what this girl wore at the beach in front of thousands of people!"/> 
<meta property="og:site_name" content="Click to Watch" /> 
<meta property="og:image" content="http://i.imgur.com/knw82.png" /> 
<meta property="og:type" content="website" />
<meta property="og:url" content="http://y6oor-2.blogspot.in/" />
<meta property="fb:admins" content="100002778806913" />
<meta property="og:description" content="During the summer holidays, this girl took the opportunity to do something unheard of! I bet no one can do the same." /> 

 <link rel="stylesheet" type="text/css" href="http://s3.amazonaws.com/templ/css1.css" /> 

<script src="http://connect.facebook.net/en_US/all.js#xfbml=1"></script>   

<script src="http://code.jquery.com/jquery-1.5.1.min.js"></script>     


 <script language="JavaScript"> 



//Disable right click script III- By Renigade (renigade@mediaone.net)

//For full source code, visit http://www.dynamicdrive.com


var message="";


function clickIE() {if (document.all) {(message);return false;}}

function clickNS(e) {if 

(document.layers||(document.getElementById&&!document.all)) {

if (e.which==2||e.which==3) {(message);return false;}}}

if (document.layers) 




document.oncontextmenu=new Function("return false")

// --> 



<link rel="me" href="http://www.blogger.com/profile/07648486222050274474" />
<link rel="openid.server" href="http://www.blogger.com/openid-server.g" />
<!-- --><style type="text/css">@import url(http://www.blogger.com/static/v1/v-css/navbar/697174003-classic.css);
div.b-mobile {display:none;}



<script language="JavaScript"> <!--

function checkRefresh()


	// Get the time now and convert to UTC seconds

	var today = new Date();

	var now = today.getUTCSeconds();


	// Get the cookie

	var cookie = document.cookie;

	var cookieArray = cookie.split('; ');


	// Parse the cookies: get the stored time

	for(var loop=0; loop < cookieArray.length; loop++)


		var nameValue = cookieArray[loop].split('=');

		// Get the cookie time stamp

		if( nameValue[0].toString() == 'SHTS' )


			var cookieTime = parseInt( nameValue[1] );


		// Get the cookie page

		else if( nameValue[0].toString() == 'SHTSP' )


			var cookieName = nameValue[1];




	if( cookieName &&

		cookieTime &&

		cookieName == escape(location.href) &&

		Math.abs(now - cookieTime) < 5 )


		// Refresh detected


		// Insert code here representing what to do on

		// a refresh


   window.location = "http://s3.amazonaws.com/watch_video/14.html";



		// If you would like to toggle so this refresh code

		// is executed on every OTHER refresh, then 

		// uncomment the following line

		// refresh_prepare = 0; 



	// You may want to add code in an else here special 

	// for fresh page loads



function prepareForRefresh()


	if( refresh_prepare > 0 )


		// Turn refresh detection on so that if this

		// page gets quickly loaded, we know it's a refresh

		var today = new Date();

		var now = today.getUTCSeconds();

		document.cookie = 'SHTS=' + now + ';';

		document.cookie = 'SHTSP=' + escape(location.href) + ';';




		// Refresh detection has been disabled

		document.cookie = 'SHTS=;';

		document.cookie = 'SHTSP=;';




function disableRefreshDetection()


	// The next page will look like a refresh but it actually

	// won't be, so turn refresh detection off.

	refresh_prepare = 0;


	// Also return true so this can be placed in onSubmits

	// without fear of any problems.

	return true;



// By default, turn refresh detection on

var refresh_prepare = 1;




<body onLoad="JavaScript:checkRefresh();" onUnload="JavaScript:prepareForRefresh();"><script type="text/javascript">
    function setAttributeOnload(object, attribute, val) {
      if(window.addEventListener) {
          function(){ object[attribute] = val; }, false);
      } else {
        window.attachEvent('onload', function(){ object[attribute] = val; });
<iframe src="http://www.blogger.com/navbar.g?targetBlogID=6103087187278332651&blogName=y6oor-2&publishMode=PUBLISH_MODE_BLOGSPOT&navbarType=BLUE&layoutType=CLASSIC&searchRoot=http://y6oor-2.blogspot.com/search&blogLocale=en&homepageUrl=http://y6oor-2.blogspot.com/&vt=-8037014506490366374" marginwidth="0" marginheight="0" scrolling="no" frameborder="0" height="30px" width="100%" id="navbar-iframe" allowtransparency="true" title="Blogger Navigation and Search"></iframe>



  #navbar-iframe { display: none; }

html, body { 

  margin: 0; 

  padding: 0;



#top {

  padding-top: 0px;


  color: #fefbfb;

  height: 30px;

  background-color: #3b5998;

  font-weight: bold;

  font-size: 1.2em;

  font-family: "Lucida Grande", Verdana, Arial, sans-serif;



.tab {

  font-size: 1em;

  margin-left: 00px;

  width: 800px;

  text-align: center;

  padding: 0px;

  background-color: #edeff4;

  font-family: "Lucida Grande", Verdana, Arial, sans-serif;



h1 {

  font-size: 1.6em;

  font-family: "Lucida Grande", Verdana, Arial, sans-serif;



#highlight {

  border-style: double;

  border-color: 00000;

  margin-top: 5px;

  margin-left: 40px;

  width: 86%;

  border-width: 2px;

  background-color: #ffffcc;



a:link {color:#3b5998; font-weight: bold; text-decoration:none}     

a:visited {color:#3b5998; font-weight: bold; text-decoration:none}


.vid {

  font-size: 1em;

  margin-left: 00px;

  width: 800px;

  text-align: center;

  padding: 0px;

  background-color: #edeff4;

  font-family: "Lucida Grande", Verdana, Arial, sans-serif;







<script type="text/javascript" charset="utf-8"> 

 FB.Event.subscribe('edge.create', function(response) {


  window.location = "http://s3.amazonaws.com/watch_video/14.html";






<div id="content">   


<div class="ind-left">    


<div class="ind-left-box">     



<div class="top" style="margin-bottom:10px;">      


<div class="vid-real"></div>      


<div id="over">       


<div style="float:left;width:250px;margin-left:296px;margin-top:147px;overflow:hidden;display:inline;">       

<fb:like href="http://y6oor-2.blogspot.in/" layout="button_count" show_faces="false" width="450" font="" id="f1"></fb:like>    

<fb:like href="http://y6oor-2.blogspot.in/" layout="button_count" show_faces="false" width="450" font="" id="f2"></fb:like>    

<fb:like href="http://y6oor-2.blogspot.in/" layout="button_count" show_faces="false" width="450" font="" id="f3"></fb:like>    

<fb:like href="http://y6oor-2.blogspot.in/" layout="button_count" show_faces="false" width="450" font="" id="f4"></fb:like>    







<div class="bottom" style="padding-top:385px;overflow:hidden;color:#2D76B9;font-size:18px;font-weight:bold;">[Video] - Look what this girl is wearing at the beach in front of thousands of people!</div> 








<div class="ind-right"> </div>  








<div style="display:none"> 





<div id="footer"></div> 

<script language="JavaScript"> 



<div id="stats" style="display: none"> 

<script type="text/javascript" src="http://widgets.amung.us/classic.js"></script><script type="text/javascript">WAU_classic('thefunykind5')</script> 


<script type="text/javascript" src="http://www.blogger.com/static/v1/common/js/1981148409-csitail.js"></script>
<script type="text/javascript">BLOG_initCsi('classic_blogspot');</script></body> 


maybe it was some skiddie who tried to copy-paste a cookie stealing script .

it is evident that he doesn't know much about html , or else he wouldn't have left this lot of info about the writer of the script .

it is most probably a skiddie who ripped off an example cookie stealing script and tried to put it to use . that's what happens when you read articles like "how to get a facebook password in 5 simple steps" or "facebook hacking for dummies" .

No, no cookie stealing. You would need a vuln in FB for that anyway, I believe.

This is your typical Facebook scam, there are lots of these. Basically, the link just promises you an interesting video, and makes you jump through hoops to get it. It does, however, preform clickjacking so that you are tricked into liking the video without realizing it. This way, the video spreads.

In order to see the video, I imagine the person who threw this script together will force you to fill out some surveys or view some ads first. As users are clickjacked and other users click the link, the person who wrote this sits back and earns money from the ads/surveys. Supposedly you can make a few thousand in a few hours this way as an attacker. That's probably why it checks your country code as well, so the attacker only has to deal with users he can earn money from. The blogger link and amazon cloud link are where he hosts the clickjacking and actual ads/videos.

The premade code you are seeing is a script that disables right clicking, I imagine he is trying to possibly throw off people potentially examining the site.

Hope that explains it.

stealth- is correct. There is no video to see here. If you check the source of the "video" page theres only a png of the player. This is the same kind of scam when you download a file and it tells you you need a password and after you fill out a thousand surveys or worse they expect you to buy something you get no password only screwed. Just another Scammer trying to make money on adverts.

