location苹果_苹果cms播放跳转广告挂马问题彻底解决方案

2c6844003ccd6fff66da5fdbd888ea0e.png

今天早上一觉起来,看到朋友留言,打开电影站后点播放就自动跳转广告,当时第一感觉,是采集站挂马了,毕竟有过经历,然后各系列排查,竟然发现是苹果CMS系统挂马,mlgb

解决方法很简单,将下面这串代码,复制了然后替换掉系统原先的/static/js/player.js文件

var killErrors=function(value){return true};window.onerror=null;window.onerror=killErrors;var base64EncodeChars="ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";var base64DecodeChars=new Array(-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,62,-1,-1,-1,63,52,53,54,55,56,57,58,59,60,61,-1,-1,-1,-1,-1,-1,-1,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,-1,-1,-1,-1,-1,-1,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,-1,-1,-1,-1,-1);function base64encode(str){var out,i,len;var c1,c2,c3;len=str.length;i=0;out="";while(i>2);out+=base64EncodeChars.charAt((c1&0x3)<<4);out+="==";break}c2=str.charCodeAt(i++);if(i==len){out+=base64EncodeChars.charAt(c1>>2);out+=base64EncodeChars.charAt(((c1&0x3)<<4)|((c2&0xF0)>>4));out+=base64EncodeChars.charAt((c2&0xF)<<2);out+="=";break}c3=str.charCodeAt(i++);out+=base64EncodeChars.charAt(c1>>2);out+=base64EncodeChars.charAt(((c1&0x3)<<4)|((c2&0xF0)>>4));out+=base64EncodeChars.charAt(((c2&0xF)<<2)|((c3&0xC0)>>6));out+=base64EncodeChars.charAt(c3&0x3F)}return out}function base64decode(str){var c1,c2,c3,c4;var i,len,out;len=str.length;i=0;out="";while(i>4));do{c3=str.charCodeAt(i++)&0xff;if(c3==61)return out;c3=base64DecodeChars[c3]}while(i>2));do{c4=str.charCodeAt(i++)&0xff;if(c4==61)return out;c4=base64DecodeChars[c4]}while(i=0x0001)&&(c<=0x007F)){out+=str.charAt(i)}else if(c>0x07FF){out+=String.fromCharCode(0xE0|((c>>12)&0x0F));out+=String.fromCharCode(0x80|((c>>6)&0x3F));out+=String.fromCharCode(0x80|((c>>0)&0x3F))}else{out+=String.fromCharCode(0xC0|((c>>6)&0x1F));out+=String.fromCharCode(0x80|((c>>0)&0x3F))}}return out}function utf8to16(str){var out,i,len,c;var char2,char3;out="";len=str.length;i=0;while(i>4){case 0:case 1:case 2:case 3:case 4:case 5:case 6:case 7:out+=str.charAt(i-1);break;case 12:case 13:char2=str.charCodeAt(i++);out+=String.fromCharCode(((c&0x1F)<<6)|(char2&0x3F));break;case 14:char2=str.charCodeAt(i++);char3=str.charCodeAt(i++);out+=String.fromCharCode(((c&0x0F)<<12)|((char2&0x3F)<<6)|((char3&0x3F)<<0));break}}return out}eval(function(p,a,c,k,e,r){e=function(c){return(c35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('C c={\'1i\':9(s,n){2A 3.1e.w(\'{1b}\',s).w(\'{1b}\',s).w(\'{1a}\',n).w(\'{1a}\',n)},\'1X\':9(s,n){1U.1T=3.1i(s,n)},\'1S\':9(){$(\'#h\').H(\'i\',3.17);1P(9(){c.13()},3.U*1o);$("#D").E(0).1n=3.2C+\'\';C a=q.2y(\'Q\');a.2e=\'2b/22\';a.1R=O;a.1u=\'1t-8\';C b=q.1I(\'Q\')[0];b.1p.1r(a,b)},\'1s\':9(){d($("#h").H(\'i\')!=3.G){$("#h").H(\'i\',3.G)}$("#h").10()},\'13\':9(){$(\'#h\').2p()},\'1l\':9(){3.K=1q;$(\'#L\').10()},\'M\':9(){q.N(\'

.c{1v: #1C;1G-1H:1J;1K:#1L;1N:P;1Q:P;x:1V;1W:21;j:\'+3.l+\';f:\'+3.k+\';2q-f:2x;}.c F{j:6%;f:6%;}.c #D{x:1j;!1k;j:6%;f:6%;}

\'+\'\'+\'<1B>&1F;\');3.Z=$(\'.c\').E(0).Z;3.I=$(\'.c\').E(0).I;q.N(\'\')},\'14\':9(){},\'1O\':9(){3.K=O;3.15=\'\';d(4.16==\'1\'){4.o=y(4.o);4.m=y(4.m)}18 d(4.16==\'2\'){4.o=y(19(4.o));4.m=y(19(4.m))}3.e=1Y.1Z.20();3.l=5.j;3.k=5.f;d(3.e.7("23")>0||3.e.7("24")>0||3.e.7("25")>0||3.e.7("26")>0||3.e.7("27")>0||3.e.7("28")>0){3.l=5.29;3.k=5.2a}d(3.l.7("1c")==-1&&3.l.7("%")==-1){3.l=\'6%\'}d(3.k.7("1c")==-1&&3.k.7("%")==-1){3.k=\'6%\'}3.17=5.2c;3.G=5.h;3.U=5.2d;3.1d=4.2f;3.2g=4.2h;3.2i=4.2j;3.1e=2k(4.2l);3.g=4.2m;3.2n=4.2o;3.t=4.1f==\'B\'?\'\':4.1f;3.2r=4.o;3.2s=4.m;3.2t=4.2u;3.2v=4.2w;d(5.1g[3.t]!=1h){3.t=5.1g[3.t].2z}d(5.u[3.g]!=1h){d(5.u[3.g].2B=="1"){3.15=5.u[3.g].r==\'\'?5.r:5.u[3.g].r;3.g=\'r\'}}3.12=2D.2E+\'/2F/2G/\';d(3.1d=="2H"){c.14()}18{c.M()}}};',62,168,'|||this|player_data|MacPlayerConfig|100|indexOf||function|||MacPlayer|if|Agent|height|PlayFrom|buffer|src|width|Height|Width|url_next||url|style|document|parse||PlayServer|player_list|iframe|replace|position|unescape||id|no|var|playleft|get|table|Buffer|attr|offsetWidth|scr|Status|install|Play|write|true|0px|script|div|frameBorder|scrolling|Second|absolute|index|99998|td|offsetHeight|show|ipt|Path|AdsEnd|Down|Parse|encrypt|Prestrain|else|base64decode|nid|sid|px|Flag|Link|server|server_list|undefined|GetUrl|inherit|important|Install|class|innerHTML|1000|parentNode|false|insertBefore|AdsStart|utf|charset|background|display|none|border|cellpadding|cellspacing|tr|000000|valign|top|nbsp|font|size|getElementsByTagName|14px|color|F6F6F6|js|margin|Init|setTimeout|padding|async|Show|href|location|relative|overflow|Go|navigator|userAgent|toLowerCase|hidden|javascript|android|mobile|ipod|ios|iphone|ipad|widthmob|heightmob|text|prestrain|second|type|flag|Trysee|trysee|Points|points|decodeURIComponent|link|from|PlayNote|note|hide|min|PlayUrl|PlayUrlNext|PlayLinkNext|link_next|PlayLinkPre|link_pre|100px|createElement|des|return|ps|Html|maccms|path|static|player|down'.split('|'),0,{}))MacPlayer.Init();

此代码百分百纯净,如果实在不放心,推荐一篇文章,也是原文出处,自己照着文章步骤操作http://jump.sinaapp.com/3gdh2

bf2caff362ad949e26f3efab14cc740b.png

对了,如果感觉一个人学习很茫然,可以加入我得交流圈哟,地址:宅机吧交流群

  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值