网站地址:http://bngamer.com/bbs
挂马情况:页面近底部植入恶意JS脚本.
此JS.又框架转向到http://x1.315666.net/m10.html?bng
不过x1.315666.net本站反黑HOSTS已经封过了..而且封了2次..
http://x1.315666.net/news.html..8进制加密.解开后是
http://user1.33220.net/ms06014.js
http://user1.33220.net/Thunder.html
http://user1.33220.net/GLWORLD.html
http://user1.33220.net/StormII.html
http://user1.33220.net/Real.html
http://user1.33220.net/real.js
http://user1.33220.net/Baidu.cab
全部下载http://user1.33220.net/bak.css
user1.33220.net这个还没封...回头封上..
...没有让俺中毒的漏洞...继续发掘ING...
|