It appears to be entirely foiled NoScript (i.e. Javascript whitelisting).
<noscript>
<meta http-equiv="refresh" content="600"
url="phish.php">
</noscript>"Forbid META redirections inside <noscript> elements"
but then I immediately wondered, what about META redirections outside <noscript> elements? I tested this with a fresh install of Firefox and latest NoScript, and those still work. Also: To forbid meta redirections inside noscript elements you have to toggle an option, it's not standard for non-trusted sites.