123
返回列表 发新帖
楼主: fanyu919
收起左侧

[病毒样本] www.17173.com图片服务器被人挂木马

[复制链接]
香甜卡饭
发表于 2008-3-27 16:25:01 | 显示全部楼层
ESS没有报啊
qigang
发表于 2008-3-27 21:31:43 | 显示全部楼层

解不出!

http://smcreative.allyes.com/smcreative/newff/flashpop2_17173.js



eval(function(p,a,c,k,e,d){e=function(c){return(c35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)d[e(c)]=k[c]||e(c);k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('b 3z(w){6 O,A;O=w+"=";A=3.I.14(O);8(A!=-1){A+=O.1V;N=3.I.14(";",A);8(N==-1)N=3.I.1V;l 3y(3.I.3x(A,N))}a l 1w}b 1P(w,1U,17){3.I=w+"="+3w(1U)+"; 17="+17.3v()+"; 3u=/"}b 1J(){8(3t!=2){6 3s=1h;M.1M(x.y-h-1L,x.m-g-3r,h,g)}a{M.3q()}}8(c.1T){1T.3p.k=b(1S){8(1S)l H.1R.3o(H);a{6 16=3.3n();16.3m(H);l H.1R.3l(16.3k(),H)}}}b 3j(){v{1A.1z()}u(e){}3i(1y);8(j){3.7("i").9.m=0;3.7("i").9.y=0}3.7("K").k(f);3.7("13").k(f);3.7("D").k(f);3.7("t").k(f)}b 1Q(){8(3h==1){8(M.3.7("K").3g()!=1I){p(\'1Q()\',B)}a{12();p(\'L()\',B)}}a{p(\'L()\',B)}}b 12(){8(!15)15=1;1P(3f,15,3e)}b 3d(1N){l 1O.3c(1O.3b()*1N)+1}6 1K="";6 1H="";b L(){8(G>3a){}a 8(G<=g){M.1M(x.y-h-1L,x.m,h,G)}a 8(G>g){1K=c.T("1J()",1I)}G+=10;1H=p("L();",1r)}6 4=f;8(!11){11="39"}b 38(){8(37.36.14("35")>-1){6 F=z.34;6 E=z.33}a{6 F=c.32;6 E=c.31}8(2Z==1){6 n=z.1G-(h+1F);6 o=z.1E-(g+1D);3.7("t").9.s=o+F+"d";8(!3.7("t")){8(j){3.7("i").9.m=0;3.7("i").9.y=0}3.7("13").k(f);3.7("K").k(f);l}3.7("t").9.r=n+E+"d";8(j){3.7("i").9.s=o+F+"d";3.7("i").9.r=n+E+"d"}3.7("D").9.s=(o+1C)+F+"d";3.7("D").9.r=(n+h-1B)+E+"d"}a{6 n=z.1G-(h+1F);6 o=z.1E-(g+1D);3.7("t").9.s=o+"d";8(!3.7("t")){8(j){3.7("i").9.m=0;3.7("i").9.y=0}3.7("13").k(f);3.7("K").k(f);l}3.7("t").9.r=n+"d";8(j){3.7("i").9.s=o+"d";3.7("i").9.r=n+"d"}3.7("D").9.s=(o+1C)+"d";3.7("D").9.r=(n+h-1B)+"d"}}b 1g(){v{1A.1z()}u(e){}}6 1y;b 2Y(){6 1x="";8(2X==1){v{4=c.2W(1x,"2V","s="+1s+",r="+Z+",m="+g+",y="+h+",2U=C,2T=C,2S=C,2R=C,2Q=0,2P=0")}u(e){4=1w}8(4&&4!="2O"){8(2N(4["w"])=="2M"){12();v{4.3.2L("");4.3.5("<1u>");4.3.5("<1v>"+11+"");4.3.5("<2K 2J-2I=\'2H-2G\' 2F=\'2E/Q; 2D=2C\'>");4.3.5("");4.3.5("<1e 1d=1c>");4.3.5("6 j = "+j+";");4.3.5("6 2B = \'"+2A.2z+"\';");4.3.5("6 1t = \'"+1t+"\';");4.3.5("6 J = \'"+Z+"\';");4.3.5("6 1o = \'"+1s+"\';");4.3.5("6 2y = \'"+h+"\';");4.3.5("6 V = \'"+g+"\';");4.3.5("6 W = \'"+2x+"\';");4.3.5("6 2w = \'"+2v+"\';");4.3.5("6 1i = \'2u\';");4.3.5("6 R = "+1r+";");4.3.5("6 2t = \'"+Z+"\';");4.3.5("6 g = \'"+g+"\';");4.3.5("6 1q = \'"+1q+"\';");4.3.5("6 Y = \'"+Y+"\';");4.3.5("6 2s = \'"+Y+"\';");4.3.5("6 2r = \'"+2q+"\';");4.3.5("6 1p = \'"+1p+"\';");4.3.5("6 2p = \'2o\';");4.3.5("6 2n = \'2m\';");4.3.5("8(j==f){6 q=c.1n;6 X=c.2l;}a{6 q=c.1m;6 X=c.2k;}");4.3.5("6 1j = X - J;");4.3.5("6 2j = q - 1o;");4.3.5("6 1k;");4.3.5("");4.3.5("6 2i = 0;");4.3.5("b S()");4.3.5("{");4.3.5("8(j==f){6 q=c.1n;}a{6 q=c.1m;}");4.3.5("   8 (q < x.m - 1l(V) - 1l(W))");4.3.5("   {");4.3.5("    2h(1k);");4.3.5("    2g = x.m - W - V - 1j;");4.3.5("    2f = J;");4.3.5("    l;");4.3.5("   }a");4.3.5("   {");4.3.5("   v{c.2e(J, q - 1i);}");4.3.5("   u(e) {}}");4.3.5("}");4.3.5("");4.3.5("<19 2b=0 2a=0 29=C 28=\'1h.1g();\'>");4.3.5("<1f w=27 26=\'\'9=\'25:24\'>");4.3.5("<1e 1d=1c>c.23();");4.3.5("b U(){v{");4.3.5("8(3.7(\'22\').21()>0){");4.3.5("c.T(\'S()\', R);}a{");4.3.5("p(\'U()\', B);}}u(e){");4.3.5("p(\'U()\', B);}}c.T(\'S()\', R);");4.3.5("<20 1Z=\'"+1Y+"\'>")}u(e){}}a{P()}}a{P()}}a{P()}}b 18(){1X=2}p("18()",1W*30);',62,222,'|||document|temopenflag|writeln|var|getElementById|if|style|else|function|window|px||true|popheight|popwidth|swfifram|ie|removeNode|return|height|flash_left2006|flash_top2006|setTimeout|temietop|left|top|divname1|catch|try|name|screen|width|temdocument|offset|50|no|divnameimgdis|temscrollleft|temscrolltop|popTop|this|cookie|winLeft|hotson|popshow|oPopup|end|search|divpopmsg|html|winInterval|fnEffect|setInterval|loadload100|winHeight|toolbarHeight|temieleft|temclickadd|winLeft20060609191217||kuantongtitle|creativeCookie|imgcoltem|indexOf|AllyesviewtvCookieVal|range|expires|sohuadmjs|body|RIPT|SC|JavaScript|language|script|IFRAME|do173end|opener|winMove|cmpWidth|intervalHdl|parseInt|screenY|screenTop|winTop|adftrack_ref|bannerswfadd|flash_settimevalue|winTop20060609191217|flvadd|head|title|false|openWinCode|tttt|playDone|VideoPlay|tclosegifx|tclosegify|temtopdeff|clientHeight|temleftdeff|clientWidth|mytime|100|getfocusepop|inteval|toleftwid|show|num|Math|setCookie|load100|parentNode|removeChildren|Node|value|length|1000|temsohuendflag|flashpop1add|SRC|SCRIPT|CurrentFrame|button690|focus|none|display|src|frmdownload|onbeforeunload|scroll|topmargin|leftmargin|ipt|scr|moveTo|endWinLeft|endWinTop|clearTimeout|switchFlag|cmpHeight|screenX|screenLeft|stop|stopflag|_blank|targetflag|temadfhost|ADFHOSTBannerIDAllyes|ADFUSERBannerIDAllyes|srcHeight|40|toolbarWidth20060609191217|toolbarWidth|toolbarHeight20060609191217|winWidth|flash_var_list|parent|fvarList|gb2312|charset|text|content|Type|Content|equiv|http|meta|write|string|typeof|null|scrollbars|resizable|location|menubar|toolbar|status|newwin|open|winpopflag|dohtmlshow|temmoveflag||pageXOffset|pageYOffset|scrollLeft|scrollTop|MSIE|userAgent|navigator|movelook|SmartCreative|920|random|floor|rand|AllyesviewtvExpDate|tem11|PercentLoaded|temloadyes|clearInterval|disdiv|extractContents|replaceChild|selectNodeContents|createRange|removeChild|prototype|hide|tobottomhei|pluto|temflag|path|toGMTString|escape|substring|unescape|getCookie'.split('|'),0,{}))
fanyu919
 楼主| 发表于 2008-3-28 20:40:06 | 显示全部楼层
今天上去整个网站都报告
qigang
发表于 2008-3-28 21:20:28 | 显示全部楼层

js里很多eval,但没见着东西,晕死!

Log is generated by FreShow.
[wide]http://www.17173.com
    [script]http://www.17173.com/script/flash17173.js
    [script]http://www.17173.com/script/common.js
    [script]http://www.17173.com/script/ggcommon.js
    [script]http://www.17173.com/script/index08login.js
    [script]http://www.17173.com/script/sjuqh.js
    [script]http://js.17173.com/ping.js
    [script]http://smcreative.allyes.com/smcreative/flash_fx.js
    [script]http://sohusc.allyes.com/main/adfshow?user=sohusc|17173homepage|mercurywanmei0525&db=sohusc&border=0&local=yes&js=ie
    [script]http://images.sohu.com/cs/sohuim/xiaozt/version/2.0/js/loader.sohu.js
fanyu919
 楼主| 发表于 2008-3-29 06:35:27 | 显示全部楼层
到底是怎么回师啊我有时候上去连整个网站都报告有时候不报告!
我的咔吧司机 拒绝访问 是不是病毒就没有进来啊?
醉一生爱妍
发表于 2008-3-29 08:53:02 | 显示全部楼层
挂到51上面就/。。。
雨宫优子
发表于 2008-3-29 09:00:47 | 显示全部楼层
基本可以确定是误报....
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-1 07:06 , Processed in 0.086775 second(s), 14 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表