The proof of concept is foiled. But how about something similar like:
<noscript>
<meta http-equiv="refresh" content="600"
url="phish.php">
</noscript>