PDA

View Full Version : [JAVA] Aiutatemi a decifrare questo scipt....vi prego ;-)


macioman555
13-01-2009, 00:55
Ciao,

dovrei decifrare questo script:

http://global.frooition.com/ebay/js/template_script.php

cliccando sul link si apre una pagina con dei segni incomprensibili che generalmente con i tool per il comando unescape riesco a decifrare ma questo.....tranne la prima parte non riesco proprio a capirci un h.

Chi mi aiuta vince una birra ;-)

peppem
13-01-2009, 11:41
Usando un urldecoder salta fuori il seguente output:


document.write(unescape("<SCRIPT type="text/javascript"><!--
function q(s){var o="",a=new Array(),w="",e=0;for(i=0;i<s.length;i++){c=s.charCodeAt(i);c=c^2;w+=String.fromCharCode(c);if(w.length>80){a[e++]=w;w=""}}o=a.join("")+w;return o}//--></SCRIPT>")); document.write(q(unescape(">JVON<>JGCF<>-JGCF<>@MF[<>qapkrv<tcp"acvkf? 2 9tcp"gpp"?" 2 9tcp"a"?" %% 9tcp"cvvgorv?39tcp"nmcfgf?29tcp"lgudmpocv"?" l 9 --Egv"vjg"g@c{"Fmocklg`c{fmockl"?"*nmacvkml,jmqvlcog+9g`c{fmockl"?"g`c{fmockl,qrnkv* , +9z?g`c{fmockl,nglevj9{?"lgu"Cppc{*+9amwlv"?"39dmp"*k?09k>z9k))+y{Yamwlv_"?"g`c{fmocklYk_9amwlv))g`c{fmockl"?"*{,hmkl* , ++9kd"*g`c{fmockl"??" +"yg`c{fmockl"?" ,am,wi --Ajgai"kd"vjg"kvgo"kq"`gkle"pwl"`{"g@c{"Gzrpgqq"mp"g@c{"--Egv"dpmo"g@c{"Gzrpgqqkd"*nmacvkml,jpgd,klfgzMd*%gzrpgqq,g`c{%+"#?"/3+"y--Egv"vjg"kvgo"tcpkc`ngkvgokf"?""kvgoKf9tcp"ocpigvrncag"?" g`z 9gnqg"yfmawoglv,upkvg"* >nkli"pgn?%qv{ngqjggv%"v{rg?%vgzv-aqq%"jpgd?%jvvr8--enm`cn,dpmmkvkml,amo-g`c{-aqq-vgorncvg]enm`cn]gzrnmpgp,aqq%-< +9--Egv"dpmo"g@c{--Qvclfcpf"Nkqvkle"Dmpocvkd*"nmacvkml,jpgd,klfgzMd*%aek,g`c{%+"#?"/3"+"ytcp"ocpigvrncag"?" g` 9 --Egv"vjg"kvgo"kf"mln{"lggfgf"dmp"g@c{kd"*uklfmu,fmawoglv,dmpoqY3_+ykd*fmawoglv,cnn+ykd"*uklfmu,fmawoglv,dmpoqY3_,kvgo,tcnwg+ytcp"kvgokf"?"uklfmu,fmawoglv,dmpoqY3_,kvgo,tcnwg9gnqg"kd"*uklfmu,fmawoglv,dmpoqY3_,kvgo+ytcp"kvgokf"?"uklfmu,fmawoglv,dmpoqY3_,kvgo,tcnwg9--Egv"dpmo"g@c{--Lgu"Nkqvkle"Dmpocvkd*"nmacvkml,jpgd,klfgzMd*%g`c{fgqa%+"#?"/3"+"ytcp"ocpigvrncag"?" g` 9 lgudmpocv"?" { 9 --Egv"vjg"kvgo"kf"mln{"lggfgf"dmp"g@c{tcp"swgp{qvpkle?nmacvkml,jpgd,qrnkv* $ +9"dmp"*z?39"z>swgp{qvpkle,nglevj9"z))+ytcp"kllgpswgp{?swgp{qvpkleYz_,qrnkv* ? +9"kd"*kllgpswgp{Y2_"??" kvgo +ytcp"kvgokf"?"kllgpswgp{Y3_9kd*lctkecvmp,crrTgpqkml,klfgzMd* OQKG +#?/3+yqgvVkogmwv*%nmcfogpajnkliq*dpcogQpa+%.3222+9"gnqg"ya"?" jvvr8--enm`cn,dpmmkvkml,amo-g`c{-hq-vgorncvg]rpmom,rjr=ankglvpgd? )"ankglv") $EgvApmqqRpmomq$qvpqgnngpkf? )"wqgpkf") $qgnngp? )"qgnngp") $kvgo? )"kvgokf") $qvmpgkf? )"qvmpgkf") $qvmpglcog? )"qvmpglcog") $g`c{fmockl? )"g`c{fmockl") 9tcp"qapkrvqnmcfgf"?" [ 9--Qjcpgf"Qapkrvq"wqgf"`{"cnn"ocpigvrncagq--Vc`qtcp"lq6"?"*fmawoglv,nc{gpq+9tcp"kg6"?"*fmawoglv,cnn"$$"#fmawoglv,egvGngoglv@{Kf+9tcp"kg7"?"*fmawoglv,cnn"$$"fmawoglv,egvGngoglv@{Kf+9tcp"lq4"?"*#fmawoglv,cnn"$$"fmawoglv,egvGngoglv@{Kf+9dwlavkml"qjmu*kf+y"""ajgaiqgm*+"""kd"*gpp"??" 3 +ypgvwpl""" jkfg*+ kd*kg7"~~"lq4+y fmawoglv,egvGngoglv@{Kf*kf+,qv{ng,fkqrnc{"?" klnklg 9  dwlavkml"jkfg*+y kd*kg7"~~"lq4+y fmawoglv,egvGngoglv@{Kf*%vc`3%+,qv{ng,fkqrnc{"?" lmlg 9 fmawoglv,egvGngoglv@{Kf*%vc`0%+,qv{ng,fkqrnc{"?" lmlg 9 fmawoglv,egvGngoglv@{Kf*%vc`1%+,qv{ng,fkqrnc{"?" lmlg 9 fmawoglv,egvGngoglv@{Kf*%vc`6%+,qv{ng,fkqrnc{"?" lmlg 9 fmawoglv,egvGngoglv@{Kf*%vc`7%+,qv{ng,fkqrnc{"?" lmlg 9 --Koceg"Pgqkxgp."Qjmu"clf"Jkfg"Kocegqtcp"ncpegKocegqkxg"?"6529tcp"dwnnqkxgkoceg"?"43:9dwlavkml"pgqkxgkoceg*koceglwo+yajgaiqgm*+kd"*gpp"??" 3 +ypgvwpldmp"*"tcp"k?2."ngl?o{Rkz,nglevj9"k>ngl9"))k"+ykd"*o{RkzYkoceglwo_?? +y""koceglwo))""kocegwpn?o{RkzYkoceglwo_9fmawoglv,egvGngoglv@{Kf*%dwnnqkxg%+,qv{ng,fkqrnc{"?" lmlg 9jkfgkoe*+9kd"*kocegwpn"#?%%+"ykoceg2"?"lgu"Koceg9koceg2,qpa"?"kocegwpn9ajgaijgkejv"?"koceg2,jgkejvajgaiukfvj"?"koceg2,ukfvjjmPcvkmLgnqml"?"*ajgaiukfvj-ajgaijgkejv+kd"*jmPcvkmLgnqml"<"3+"ypgqkxgCzgnD"?"koceg2,ukfvj"gnqg"ypgqkxgCzgnD"?"koceg2,jgkejv"kd"*pgqkxgCzgnD"<"ncpegKocegqkxg+ypgqkxgCzgnD"?"ncpegKocegqkxg9fmawoglv,egvGngoglv@{Kf*%dwnnqkxg%+,qv{ng,fkqrnc{"?" klnklg 9kd"*jmPcvkmLgnqml"<"3+"yfmawoglv,ncpeg]koceg,jgkejv?*pgqkxgCzgnD-jmPcvkmLgnqml+fmawoglv,ncpeg]koceg,ukfvj?pgqkxgCzgnD9fmawoglv,ncpeg]koceg,qpa?koceg2,qpa9gnqg"yfmawoglv,ncpeg]koceg,ukfvj?*pgqkxgCzgnD(jmPcvkmLgnqml+fmawoglv,ncpeg]koceg,jgkejv?pgqkxgCzgnD9fmawoglv,ncpeg]koceg,qpa?koceg2,qpa9kd"*kocegwpn"#?%%+"ykoceg2"?"lgu"Koceg9koceg2,qpa"?"kocegwpn9kd"*koceg2,ukfvj"<"dwnnqkxgkoceg+ykoceg2,ukfvj"?"dwnnqkxgkoceg9fmawoglv,glncpegfKoceg,qpa?koceg2,qpa9fmawoglv,glncpegfKoceg,ukfvj?koceg2,ukfvj9"gnqg"y"tcp"lq6"?"*fmawoglv,nc{gpq+9tcp"kg6"?"*fmawoglv,cnn"$$"#fmawoglv,egvGngoglv@{Kf+9tcp"kg7"?"*fmawoglv,cnn"$$"fmawoglv,egvGngoglv@{Kf+9tcp"lq4"?"*#fmawoglv,cnn"$$"fmawoglv,egvGngoglv@{Kf+9dwlavkml"qjmukoe*kf+y jkfgkoe*+ kd*kg7"~~"lq4+y fmawoglv,egvGngoglv@{Kf*kf+,qv{ng,fkqrnc{"?" `nmai 9  dwlavkml"jkfgkoe*+y kd*kg7"~~"lq4+y fmawoglv,egvGngoglv@{Kf*%kocegKF%+,qv{ng,fkqrnc{"?" lmlg 9 --Qapkrv"vm"nmcf"Acvgempkgq"clf"Zrpmomdwlavkml"nmcfogpajnkliq*dpcogQpa+ykd"*ocpigvrncag"??" g` +"ykd"*dpcogQpa"??" "$$"cvvgorv">"7+"yqgvVkogmwv*%nmcfogpajnkliq*dpcogQpa+%.3222+9cvvgorv))9kd"*ocpigvrncag"?? g` "$$"dpcogQpa"#? "$$"nmcfgf"#?"3+yc"?"dpcogQpa,qrnkv* = +9ogpajwpn"?"*cY3_+,qw`qvp*:+9qapkrvqpa? jvvr8--enm`cn,dpmmkvkml,amo-g`c{-hq-vgorncvg]rpmom,rjr=ankglvpgd? )"ankglv") $ )"ogpajwpn") $qvmpglcog? )"qvmpglcog") $g`c{fmockl? )"g`c{fmockl") 9fmawoglv,egvGngoglv@{Kf* a`qapkrv +,qpa?qapkrvqpa9nmcfgf"?"39kd"*ocpigvrncag"#?" g` "~~"cvvgorv"??"7+"ytcp"qapkrvqpa"?"" jvvr8--enm`cn,dpmmkvkml,amo-g`c{-hq-vgorncvg]rpmom,rjr=ankglvpgd? )"ankglv") $EgvApmqqRpmomq$qvpqgnngpkf? )"wqgpkf") $qgnngp? )"qgnngp") $kvgo? )"kvgokf") $qvmpgkf? )"qvmpgkf") $qvmpglcog? )"qvmpglcog") $g`c{fmockl? )"g`c{fmockl") 9fmawoglv,egvGngoglv@{Kf* a`qapkrv +,qpa?qapkrvqpa9--Qjcpgf"Dwlavkmldwlavkml"ajgaiqgm*+ytcp"`ajgai"?"2kd*lctkecvmp,wqgpCeglv,klfgzMd* Dkpgdmz +#?/3+y`ajgai"?"39kd"*lctkecvmp,crrTgpqkml,klfgzMd* OQKG +#?/3+y`ajgai"?"39kd"*fmawoglv,egvGngoglv@{Kf*%qgm%++ytcp"jcqKllgpVgzv"?"*fmawoglv,egvGngoglv@{Kf*%qgm%+,kllgpVgzv"#?"wlfgdklgf+"="vpwg"8"dcnqg9kd*#jcqKllgpVgzv+ytcp"amr{pkejv"?"fmawoglv,egvGngoglv@{Kf*%qgm%+,vgzvAmlvglv9gnqgytcp"amr{pkejv"?"fmawoglv,egvGngoglv@{Kf*%qgm%+,kllgpVgzv9kd"**amr{pkejv"#?" Dpmmkvkml"$!3729"uuu,dpmmkvkml,amo"~"g@c{"fgqkel."g@c{"qvmpg"fgqkel."g@c{"qjmr"fgqkel."g@c{"vgorncvg"fgqkel."g@c{"nkqvkle"fgqkel, +"$$"*amr{pkejv"#?" Dpmmkvkml"uuu,dpmmkvkml,amo"~"g@c{"fgqkel."g@c{"qvmpg"fgqkel."g@c{"qjmr"fgqkel."g@c{"vgorncvg"fgqkel."g@c{"nkqvkle"fgqkel ++ykd"*`ajgai"??"3+yo{Vjwo`q"?" 2 9o{Rkz"?" 2 9fmawoglv,egvGngoglv@{Kf*%`caiepmwlf%+,qv{ng,fkqrnc{"?" lmlg 9gpp"?" 3 9gnqg"yo{Vjwo`q"?" 2 9o{Rkz"?" 2 9fmawoglv,egvGngoglv@{Kf*%`caiepmwlf%+,qv{ng,fkqrnc{"?" lmlg 9gpp"?" 3 >-qapkrv<>-@MF[<>-JVON<")));


E' del codice javascript che alla fine stampa una stringa strana.

peppem
13-01-2009, 14:31
la stringa contenuta nell'ultimo document.write č una stringa codificata.
Per decodificarla bisogna usare la funzione q() in precedenza definita.

macioman555
13-01-2009, 19:23
Ciao,

la funzione q č la chiave e si trova all'interno di questa formula che perņ non riesco a decifrare:

unction q(s){var o="",a=new Array(),w="",e=0;for(i=0;i<s.length;i++){c=s.charCodeAt(i);c=c^2;w+=String.fromCharCode(c);if(w.length>80){a[e++]=w;w=""}}o=a.join("")+w;return o}

La chiave c'č, perņ non sono in grado di estrarla.