вот продолжение
Код:
function prs(tl,tll,sx)
{
var n=1,i,xx;
while(n>=0){
n=tl.indexOf('|');
if(n>=0){
xx=tl.substring(0,n);tl=tl.substring(n+1,tl.length);
i=0;
while((i<nx[sx])&&(mu[sx][i]<xx))i++;
if((i<nx[sx])&&(mu[sx][i]!=xx)){
nx[sx]++;
for(j=nx[sx]-1;j>i;j--)mu[sx][j]=mu[sx][j-1];
mu[sx][i]=xx;
}
else if(i==nx[sx])mu[sx][nx[sx]++]=xx;
}}
n=1;
while(n>=0){
n=tll.indexOf('|');
if(n>=0){
xx=tll.substring(0,n);tll=tll.substring(n+1,tll.length);
i=0;
while((i<nx[sx])&&(mu[sx][i]!=xx))i++;
if(i<nx[sx]){
nx[sx]--;
for(j=i;j<nx[sx];j++)mu[sx][j]=mu[sx][j+1];
}}}
}
function uout(sx)
{
var to,tc,t=new Object(),a,out=new Object(),z=new Object(),r=0,nick,ncs;
if(room.charAt(1)!='-')r=1;
out.n=0;out.s='';
for(k=0;k<nx[sx];k++){
to='';tc='';t.f=0;t.i=0;t.o=0;
nick=mu[sx][k].substring(r,mu[sx][k].length-2);
ncol=mu[sx][k].charAt(mu[sx][k].length-2);
stt=mu[sx][k].charAt(mu[sx][k].length-1);
ncs=nick+ncol+stt;
if(!z[ncs]){
z[ncs]=1;
if(stt=='a')stt='<img src=/ch/pics/avl.gif> ';
if(stt=='b')stt='<img src=/ch/pics/pri.gif> ';
if(stt=='d')stt='<img src=/ch/pics/dnd.gif> ';
if(stt=='n')stt='<img src=/ch/pics/n-a.gif> ';
t.o=1;
if(ignors[nick]>0){stt='<img src=/ch/pics/ign.gif> ';t.i=1;t.o=0;}
if(friends[nick]>0){to='<b>';tc='</b>';t.f=1;t.o=0;}
a=0;if((t.o&&cho)||(t.f&chf)||(t.i&chi))a=1;
if(a){out.s+=stt+"<A HREF=javascript:parent.n3t('"+nick+"')><font color="+col(ncol)+">"+to+nick+tc+"</font></A><br>";out.n++;}
}}
return out;
}
function drawus(){
var u=new Object(),n=0;
d=us.document;
d.open();
d.writeln(stl2+'<body bgcolor=#DDDDDD><form action="javascript:parent.drawus()"><nobr><font face="arial,helvetica" size=-1><font color=red>');
u=uout(0);n+=u.n;
d.writeln('<center><B><U>Äåâóøêè</U></B> (<B>'+u.n+'</B>)</center>');
d.writeln(u.s);
u=uout(1);n+=u.n;
d.writeln('<br><center><B><U>Ïàðíè</U></B> (<B>'+u.n+'</B>)</center>');
d.writeln(u.s);
u=uout(2);n+=u.n;
d.writeln('<br><center><B><U>Äðóãèå</U></B> (<B>'+u.n+'</B>)</center>');
d.writeln(u.s);
d.writeln('<center><hr color=#AAAAAA>Â êîìíàòå: <B>'+n+'</B><hr color=#AAAAAA></center></font>');
d.writeln('<center><B>ïîêàçûâàòü:</B></center><table width=100% border=0 cellpadding=0><tr><td>');
d.write('<input type=checkbox onclick="parent.chf=this.checked"'+check(chf)+'> <font color=green>äðóçåé</font><br>');
d.write('<input type=checkbox onclick="parent.chi=this.checked"'+check(chi)+'> <font color=red>èãíîð</font><br>');
d.write('<input type=checkbox onclick="parent.cho=this.checked"'+check(cho)+'> <font color=blue>îñòàëüíûõ</font>');
d.writeln('</td><td align=right valign=center><input type=submit value=OK></td></font></nobr></form></body>');
d.close();
}
function drawr(){
var k=1,cc,img,p=0,t,a,a1,a2;
d=roomz.document;
d.open();
d.writeln('<head><style type="text/css">td{font-family:verdana,helvetica;font-size:10px;}</style></head>');
d.writeln('<body link=black alink=black vlink=black bgcolor=silver><center>');
d.writeln('<font face="arial,helvetica" size=-1 color=#008800><B> ÷àòå: <font color=#BB0000>'+ovl+'</font></B></font><table border=0 cellspacing=0 cellpadding=0 width=90%>');
for(k=0;k<rooms.length;k++){
t=rooms[k].id.charAt(1);
a='<A href=javascript:parent.chroom("'+rooms[k].id+'","0")>';
a2=a;
if(rooms[k].id==room)cc='CC0000';else cc='000000';
if(t=='-'){p=0;img='<img src=/ch/pics/..gif> ';}
else if(t=='+'){
if(rooms[k].ex){img='-';p=1;}else{img='+';p=0;}
a1='<A href="javascript:parent.rer('+k+')">';
img=a1+'<img border=0 src=/ch/pics/'+img+'.gif></A>';
if(!ca)a2=a1;
}
else img=' <img src=/ch/pics/..gif>';
if(t=='-'||t=='+'||p||rooms[k].id==room)d.writeln('<tr><td>'+img+' '+a2+'<font color=#'+cc+'>'+rooms[k].nam+'</font></A></td><td align=right><font color=#008800><B> '+rc[k]+'</B></font></td></tr>');
}
d.writeln('</table></center></body>');
d.close();
}
function rer(k){
rooms[k].ex=!rooms[k].ex;
drawr();
}
rc=new Array();
function updus(lu,fl,fll,ml,mll,ol,oll,rzc){
rn=0,k=1,t,p=-1;
if(glu==0){
nx[0]=0;nx[1]=0;nx[2]=0;
}
prs(fl,fll,0);
prs(ml,mll,1);
prs(ol,oll,2);
drawus(0);
ovl=0;
while(k>=0){
k=rzc.indexOf('|');
if(k>=0){
rc[rn]=parseInt(rzc.substring(0,k));rzc=rzc.substring(k+1,rzc.length);
t=rooms[rn].id.charAt(1);
if(t=='+')p=rn;else if(t=='-')p=-1;
if(t=='-'||t=='+')ovl+=rc[rn];
else{rc[p]+=rc[rn];ovl+=rc[rn];}
rn++;
}}
drawr();
glu=lu;
}
function wopen(url, wnam, w, h) {
window.open(url, wnam, 'width='+w+',height='+h+',menubar=0,location=0,toolbar=0,directories=0,status=0,scrollbars=1,resizable=1');
}
function wo(lt) {
if(lt=='i')wopen('/ch/ilist.html','ilist',200,500);
if(lt=='f')wopen('/ch/flist.html','flist',200,500);
}
function rp(lt) {
if(wopd[lt])wo(lt);
}
function list(wnam,lobj,ltype) {
var i,n=0,larr=new Array(),d=wnam.document;
for(i in lobj)if(lobj[i]>0){larr[n++]=i;}
larr=sort(larr);
for(i=0;i<n;i++)d.write('<input type=checkbox name="nick-'+larr[i]+'"> <a href="javascript:opener.n3t(\''+larr[i]+'\')">'+larr[i]+'</a><br>');
d.write('<br>íèêîâ: '+n+'<hr><input type=submit name=OK value="Óäàëèòü" style="width:100%;">');
d.write('<input type=hidden name=uid value='+uid+'><input type=hidden name=ltype value='+ltype+'>');
}
function sort(arr) {
var n=arr.length,i,j,t;
for(i=0;i<n-1;i++)for(j=i+1;j<n;j++)if(arr[i]>arr[j]){t=arr[i];arr[i]=arr[j];arr[j]=t;}
return(arr);
}
ban=2;
function showban(){
dd=topp.document;
if(ban>0){
dd.open();dd.write('<body bgcolor=white><center>');
if(ban==1){
topp.location='/ban/md.html';
ban=0;setTimeout("ban=2",120000);
}
if(ban==2){
netban();
ban=0;setTimeout("ban=3",120000);
}
if(ban==3){ //TopNet
rn1=room.charAt(0);
if(rn1!='3'&&rn1!='6'&&rn1!='U')if(Math.random()*100<50)dd.write('<a target=_blank href=/cgi-bin/ban/bc?id=top><img width=468 height=60 border=0 src="/cgi-bin/ban/bs?id=top"></a>');
else dd.write('<embed src="/cgi-bin/ban/bs?id=top2" pluginspage="http://www.macromedia.com/shockwave/download/" type="application/x-shockwave-flash" quality="best" width=468 height=60>');
else netban();
ban=0;setTimeout("ban=4",120000);
}
if(ban==8){
rz=Math.random()*100;
if(rz<50)dd.write('<A target=_blank href=/cgi-bin/ban/bc?id=696><img width=468 height=60 border=0 alt="ÆÌÈ - ÓÇÍÀÉ ÁÎËÜØÅ!!!" src=/cgi-bin/ban/bs?id=696></A>');
else dd.write('<img width=468 height=60 border=0 alt="Ãîëîñîâîé ÷àò, çâîíè 461-0-777" src=/cgi-bin/ban/bs?id=v4at>');
ban=0;setTimeout("ban=4",150000);
}
if(ban==4){
netban();ban=0;setTimeout("ban=4",120000);
}
dd.write('</center></body>');dd.close();
}
}
function netban(){
bt=Math.random()*100;
if(bt > 20){
rnd_num = Math.round((Math.random()*10000000));
bbn_l='&'+escape((self!=top)?'f'+dd.referrer:'h'+window.location.href);
dd.write('<iFrame src=http://ad0.bigmir.net/t.bbn?135&0&f&'+rnd_num+bbn_l+' width=468 height=60 frameborder=0 vspace=0 hspace=0 marginwidth=0 marginheight=0 scrolling=no>');
dd.write('<a target=_blank href=http://ad0.bigmir.net/c.bbn?135&0&'+rnd_num+bbn_l+'><img src=http://ad0.bigmir.net/t.bbn?135&0&i&'+rnd_num+bbn_l+' width=468 height=60 border=0 alt="BigBN Common"></a></iFrame>');
} // BigBN code
else{
if(bt < 15){
user = "3213";
page = "2";
pid = Math.round((Math.random() * (10000000 - 1)));
dd.writeln("<iframe src='http://banner.kiev.ua/cgi-bin/bi.cgi?h" + user + "&"+ pid + "&" + page + "' frameborder=0 vspace=0 hspace=0 " + " width=468 height=60 marginwidth=0 marginheight=0 scrolling=no>");
dd.writeln("<a href='http://banner.kiev.ua/cgi-bin/bg.cgi?" + user + "&"+ pid + "&" + page + "' target=_blank>");
dd.writeln("<img border=0 src='http://banner.kiev.ua/" + "cgi-bin/bi.cgi?i" + user + "&" + pid + "&" + page + "' width=468 height=60 alt='Óêðàèíñêà\ÿ áàííåðíà\ÿ ñåòü'></a>");
dd.writeln("</iframe>");
dd.writeln('<br><font size=-1><a href="http://banner.kiev.ua" target=_blank>Óêðàèíñêàÿ áàííåðíàÿ ñåòü</a></font>');
} // UBS code
else{
bn_id='1821';
bn_url='http://b468.abn.com.ua';
bn_rnd=Math.round((Math.random()*10000000));
bn_addurl='?t=468&w=468&h=60&id='+bn_id;
if(window.screen) bn_addurl+='&c='+screen.colorDepth+'&cw='+screen.width;
if(dd.referrer) bn_addurl+='&ref='+escape(dd.referrer);
bn_addurl+='&tz='+(new Date()).getTimezoneOffset()+'&r='+bn_rnd;
dd.write('<iframe src="'+bn_url+'/iframe'+bn_addurl+'" width=468 height=60 frameborder=0 vspace=0 hspace=0 marginwidth=0 marginheight=0 scrolling=no><a href="'+bn_url+'/nsanchor'+bn_addurl+'" target=_top><img src="'+bn_url+'/nsimg'+bn_addurl+'" width="468" height="60" border=0 /></a></iframe>');
} // ABN code
}
}
function refrsh(){
TID1=setTimeout("refrsh()",15000);
if(ref==0)fr.location="/cgi-bin/ch/mshow.pl?uid="+uid+"&room="+plus(room)+"&lp="+lp+"&lc="+lc;
ref++;if(ref>2)ref=0;
}
function plus(s) {
var k=0;
while(k>=0){
k=s.indexOf('+');if(k>=0)s=s.substring(0,k)+'%2B'+s.substring(k+1,s.length);
}return s;
}
function chroom(rid,drw){
room=rid;
if(drw != '0'){inp.location="/cgi-bin/ch/inp.pl?strm=y&"+"uid="+uid+"&color=G&sx=m&room="+plus(room);}
else{fs.location="/cgi-bin/ch/inp.pl?strm=y&"+"uid="+uid+"&color=G&sx=m&drw=0&room="+plus(room);
inp.document.say.room.value=room;inp.document.ustat.room.value=room;}
showban();
}
function n2t(str){
mstat=0;
if(str!='')str+=': ';inp.document.say.EX.focus();inp.document.say.EX.value=str;
}
function n3t(str){
if(str!='')str+=': ';inp.document.say.EX.focus();inp.document.say.EX.value=str;
}
function ntt(str){mstat=0;inp.document.say.EX.focus();inp.document.say.EX.value+='['+str+'] ';}
function pic(str){inp.document.say.EX.focus();inp.document.say.EX.value+='<'+str+'>';}
function clearinp(){
nh++;ch=nh+1;hist[nh]=inp.document.say.EX.value;hist[ch]="";
showban();
setTimeout('n3t("");if(inp.document.say.x)inp.document.say.x.checked=false',100);
}
</SCRIPT>
</HEAD><FRAMESET border=1 frameSpacing=2 borderColor=white rows=*,62 frameBorder=0 onload='chroom("6-","1")'><FRAMESET onload='chroom("6-","1")' cols=58,*,166><FRAME name=pics marginWidth=0 marginHeight=0 src="/ch/pictures.html"><FRAMESET rows=67,*,94 onload='chroom("6-","1")'><FRAME name=topp marginWidth=2 marginHeight=2 src="about:blank" noResize scrolling=no><FRAME name=main marginWidth=4 marginHeight=4 src="about:blank"><FRAME name=priv marginWidth=4 marginHeight=4 src="about:blank" frameBorder=1></FRAMESET><FRAMESET rows=0,38,116,*,34 onload='chroom("6-","1")'><FRAMESET onload='chroom("6-","1")' cols=*,*,*><FRAME name=fs marginWidth=0 marginHeight=0 src="about:blank" scrolling=no><FRAME name=fu marginWidth=0 marginHeight=0 src="about:blank" noResize scrolling=no><FRAME name=fr marginWidth=0 marginHeight=0 src="about:blank" scrolling=no></FRAMESET><FRAME name=links marginWidth=2 marginHeight=2 src="/ch/linx.html" scrolling=no><FRAME name=roomz marginWidth=2 marginHeight=1 src="about:blank"><FRAME name=us marginWidth=4 marginHeight=1 src="about:blank"><FRAME name=hosted marginWidth=0 marginHeight=0 src="/ch/hosted.html" scrolling=no></FRAMESET></FRAMESET><FRAME name=inp marginWidth=0 marginHeight=0 src="about:blank" scrolling=no></FRAMESET>
<BODY onload='chroom("6-","1")'></BODY>
Русские слова чтото глючат. Но суть не в том.
Также мне помогла найти еще не сильно сереезные уязвимости ie xss kit.
Короче нажимаем form_hidden2text и в верхней сторче в четверто поле будет буква вашего цвета. Ставите в место нее пк примеру C и также в нижней строчке, второе поле ставите тоже C, и цвет вашиг месаг изменяется. Также если узнать чейто uid, то мона прочитать чейто приват. Просто в привате жмем LocationReplace и в переменой uid ставите свою. Кто еще знает какието дыры бизара, плз оставляйте здесь
|