<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Safely Investigating Malicious JavaScript</title>
	<atom:link href="http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/feed/" rel="self" type="application/rss+xml" />
	<link>http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Wed, 10 Mar 2010 17:00:15 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Stomme poes</title>
		<link>http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/comment-page-1/#comment-237086</link>
		<dc:creator>Stomme poes</dc:creator>
		<pubDate>Mon, 16 Nov 2009 10:34:41 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/#comment-237086</guid>
		<description>The JS above looks like a goofed version of PeterNed&#039;s csshover.htc.  All the goofy characters are where the regexes are supposed to be.  He doesn&#039;t obfu it, so someone else did (maybe passing it off as their own?).</description>
		<content:encoded><![CDATA[<p>The JS above looks like a goofed version of PeterNed&#8217;s csshover.htc.  All the goofy characters are where the regexes are supposed to be.  He doesn&#8217;t obfu it, so someone else did (maybe passing it off as their own?).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ashish</title>
		<link>http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/comment-page-1/#comment-114136</link>
		<dc:creator>Ashish</dc:creator>
		<pubDate>Tue, 06 May 2008 07:54:31 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/#comment-114136</guid>
		<description>hello everyone
i have a problem that my javascript is encoded and i want to edit this code but i dont know how to decode it here is the code if anyone help me 
eval(function(p,a,c,k,e,d){e=function(c){return(c&lt;a?&quot;&quot;:e(c/a))+String.fromCharCode(c%a+161)};if(!&#039;&#039;.replace(/^/,String)){while(c--){d[e(c)]=k[c]&#124;&#124;e(c)}k=[(function(e){return d[e]})];e=(function(){return&#039;[\xa1-\xff]+&#039;});c=1};while(c--){if(k[c]){p=p.replace(new RegExp(e(c),&#039;g&#039;),k[c])}}return p}(&#039;£ ´=µ Ù();£ Ç=µ Ù();£ ª=»;£ ¿=0;£ ¢´=Õ;£ ü=÷;£ ¢¹=÷;¦ ¢¯(Å){Ô(£ i ë Ç){¯(Ç[i].Å==Å)¹ Ç[i].¢Á}¹ »};¦ ø(){Ô(£ i=0;i&lt;´.¢æ;i++)¯(´[i])´[i].°.À.Â.¢²=´[i].°.z};¦ ¸(ö,±){¯(!¢´)¹;¯(¤.Æ(ö))¤.Æ(ö).Ò=±;û ¢Ï(±)};¦ î(©){£ ¢=¡;¡.ù=©[&quot;¢µ&quot;]?©[&quot;¢µ&quot;]:»;¡.³=©[&quot;³&quot;]?©[&quot;³&quot;]:¢Ð;¡.¼=©[&quot;¼&quot;]?©[&quot;¼&quot;]:»;¡.w=©[&quot;Ä&quot;]?©[&quot;Ä&quot;]:&quot;¢Ñ&quot;;¡.h=©[&quot;Ë&quot;]?©[&quot;Ë&quot;]:&quot;¢Ò&quot;;¡.È=»;¯(¡.ù){´[0]=µ ¢¿(¡.³,¡.w,¡.h);¤.Æ(¡.ù).¥(´[0].Ó())}¡.É=¦(º){¢.¾=»;¢§{¢.¢¶(º.Þ)}¢ª(e){¸(&quot;¸&quot;,&quot;î ¢¬: &quot;+º.Þ);¢½(¢.ê);¸(&quot;¸&quot;,e.¢Ó());¸(&quot;¸&quot;,e.¢Ô+&quot;:&quot;+e.¢Ú);¹}¢.¾=µ Ø(¢.É);¸(&quot;¸&quot;,º.Þ);¢Õ.¢Ö=¢×()};¡.¢¶=¦(º){¯(!¢.È)¢.È=µ ¢¼(¢.³,¢.¼,¢.w,¢.h);ª=¢Ø(&quot;(&quot;+º+&quot;)&quot;);¢.È.Û();¢.¢¸()};¡.¾=µ Ø(¢.É);¡.Û=¦(){¯(¢.¾.¢Ù()==0)¢.¾.ç(&quot;½.è?å=½&quot;,&quot;ä=¢Û&amp;¿=&quot;+¿)};¡.ê=¢Ý(¢.Û,¢.³);¡.¢¸=¦(){¯(ª.Á){Ê=0;Ô(£ i ë ª.Á){Ê=ª.Á[i].½;¯(!´[Ê])´[Ê]=µ õ(¢.³,Ê,¢.w,¢.h);¯(¿&lt;ª.Á[i].¿)¿=ª.Á[i].¿;¯(ª.Á[i].±.ã(0,5)==&quot;\\\\¢» &quot;){´[Ê].à(ª.Á[i].±.ã(5))}û ´[Ê].Ü(ª.Á[i].Ì,ª.Á[i].±)}ª.Á=»}¯(¢¹&amp;&amp;ª.Ã){Ô(£ i ë ª.Ã){¯(¿&lt;ª.Ã[i].¿)¿=ª.Ã[i].¿;¯(!´[0])¢ß;¯(ª.Ã[i].±.ã(0,5)==&quot;\\\\¢» &quot;){´[0].à(ª.Ã[i].±.ã(5))}û ´[0].Ü(ª.Ã[i].Ì,ª.Ã[i].±)}ª.Ã=»}}};¦ ¢¼(³,¼,w,h){£ ¢=¡;¡.w=w;¡.h=h;¡.³=³;¡.¼=¼;¡.ê=»;¡.ÿ=¦(){¯(!¤.Æ(¢.¼)){¢½(¢.ê);¹}¢â(¤.Æ(¢.¼).¢À)¤.Æ(¢.¼).¢ä(¤.Æ(¢.¼).¢À);¯(Ç){£ ×;£ a;£ é;Ô(£ i ë Ç){é=Ç[i];×=¤.§(&quot;×&quot;);a=¤.§(&quot;a&quot;);a.¥(¤.í(é.¢Á));a.ð(&quot;¢å&quot;,&quot;#&quot;);a.«=&quot;½&quot;;¯(ü)a.Ö=¢.þ(¢.³,é.Å);×.¥(a);¤.Æ(¢.¼).¥(×)}}};¡.þ=¦(³,Å){¹ ¦(){¯(!´[Å]){ø();´[Å]=µ õ(³,Å,¢.w,¢.h)}¹ Õ}};¡.Û=¦(){¯(ª.È){Ç=ª.È;¢.ÿ()}ª.È=»}};¦ ì(®){£ ¢=¡;¡.®=®?®:»;¡.­=¤.§(&quot;­&quot;);¡.­.«=&quot;Ñ&quot;;¡.­.ð(&quot;¢Ä&quot;,&quot;¢Å&quot;);¡.­.ð(&quot;¢Æ&quot;,&quot;­&quot;);£ À=¤.§(&quot;À&quot;);£ Ð=À.¥(¤.§(&quot;Ð&quot;));£ ¶=Ð.¥(¤.§(&quot;¶&quot;));£ ²=¶.¥(¤.§(&quot;²&quot;));£ ô=¶.¥(¤.§(&quot;²&quot;));£ ò=¶.¥(¤.§(&quot;²&quot;));À.«=&quot;Ñ&quot;;Ð.«=&quot;Ñ&quot;;¶.«=&quot;Ñ&quot;;².«=&quot;¢Ç&quot;;ô.«=&quot;Ñ&quot;;ò.«=&quot;¢È&quot;;¡.­=ô.¥(¡.­);ò.Ö=¦(){£ ¾=µ Ø(¢.É);¾.ç(&quot;½.è?å=½&quot;,&quot;ä=¢¤&amp;±=&quot;+¢¥(¢.­.Ý,1)+(¢.®?&quot;&amp;®=&quot;+¢.®:&quot;&quot;));¢.­.Ý=&quot;&quot;;¢.­.ó();¹ Õ};¡.Î=¤.§(&quot;Î&quot;);¡.Î.«=&quot;Ñ&quot;;¡.Î.¥(À);¡.Î.¢É=¦(){£ ¾=µ Ø(¢.É);¾.ç(&quot;½.è?å=½&quot;,&quot;ä=¢¤&amp;±=&quot;+¢¥(¢.­.Ý,1)+(¢.®?&quot;&amp;®=&quot;+¢.®:&quot;&quot;));¢.­.Ý=&quot;&quot;;¢.­.ó();¹ Õ};¡.ñ=¦(){¢.­.ó()};¡.É=¦(º){º=º.Þ;¢§{¯(º)¸(&quot;¸&quot;,º)}¢ª(e){¸(&quot;¸&quot;,&quot;ì ¢¬: &quot;+º)}};¡.Ó=¦(){¹ ¢.Î}};¦ õ(³,®,w,h){£ ¢=¡;¡.³=³;¡.®=®;¡.­=µ ì(®);¡.¢°=¢¯(®);£ ©=µ Ù();©[&quot;æ&quot;]=&quot;¢Ê ½ ¢Ë &quot;+¢.¢°+&quot;&quot;;©[&quot;ï&quot;]=&quot;½&quot;;©[&quot;Ä&quot;]=w;©[&quot;Ë&quot;]=h;©[&quot;¢¢&quot;]=÷;¡.°=µ ¢£(©);¡.°.À.¢Í=¦(){ø();´[¢.®].°.À.Â.¢²++};¡.°.¢Î=¦(){¢.¾=µ Ø(¢.É);¢.¾.ç(&quot;½.è?å=½&quot;,&quot;ä=¢Ü&amp;®=&quot;+¢.®);´[¢.®]=»};¡.¬=¡.°.¢¦(¤.§(&quot;¨&quot;));¡.¬.Â.Ä=&quot;Ï%&quot;;¡.¬.Â.Ë=&quot;Ï%&quot;;¡.¬.Â.¢¨=&quot;¢«&quot;;¡.¬.«=&quot;¢­&quot;;¡.Ú=¦(){£ t=¤.§(&quot;À&quot;);t.Â.Ä=&quot;Ï%&quot;;t.¢±=&quot;0&quot;;t.¢³=&quot;0&quot;;£ â=t.¥(¤.§(&quot;Ð&quot;));£ ¶=â.¥(¤.§(&quot;¶&quot;));£ ²=¶.¥(¤.§(&quot;²&quot;));².«=&quot;¢Þ&quot;;²=¶.¥(¤.§(&quot;²&quot;));².«=&quot;¢·&quot;;².Ò=¢.°.æ;£ Í=¶.¥(¤.§(&quot;²&quot;));Í.«=&quot;¢º&quot;;Í.Ö=¢.°.¢Â;£ ú=¶.¥(¤.§(&quot;²&quot;));ú.«=&quot;¢à&quot;;ú.Ö=¢.°.¢á;¹ t};¡.°.ý(¡.Ú());¡.°.¢¡(¡.­.Ó());¡.Ü=¦(Ì,±){£ ¨;£ ·;·=¤.§(&quot;·&quot;);·.¥(¤.í(Ì+&quot;: &quot;));·.«=&quot;¢©&quot;;¨=¤.§(&quot;¨&quot;);¨.«=&quot;¢®&quot;;¨.¥(·);¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.à=¦(±){£ ¨;¨=¤.§(&quot;¨&quot;);¨.«=&quot;¢¾&quot;;¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.°.¢ã();¡.­.ñ()};¦ ¢¿(³,w,h){£ ¢=¡;¡.³=³;¡.®=0;¡.­=µ ì(¡.®);£ ©=µ Ù();©[&quot;æ&quot;]=&quot;¢Ã î&quot;;©[&quot;ï&quot;]=&quot;Ã&quot;;©[&quot;Ä&quot;]=w;©[&quot;Ë&quot;]=h;©[&quot;¢¢&quot;]=Õ;¡.°=µ ¢£(©);¡.¬=¡.°.¢¦(¤.§(&quot;¨&quot;));¡.¬.Â.Ä=&quot;Ï%&quot;;¡.¬.Â.Ë=&quot;Ï%&quot;;¡.¬.Â.¢¨=&quot;¢«&quot;;¡.¬.«=&quot;¢­&quot;;¡.Ú=¦(){£ t=¤.§(&quot;À&quot;);t.Â.Ä=&quot;Ï%&quot;;t.¢±=&quot;0&quot;;t.¢³=&quot;0&quot;;£ â=t.¥(¤.§(&quot;Ð&quot;));£ ¶=â.¥(¤.§(&quot;¶&quot;));£ ²=¶.¥(¤.§(&quot;²&quot;));².«=&quot;¢·&quot;;².¥(¤.í(¢.°.æ));£ Í=¶.¥(¤.§(&quot;²&quot;));Í.«=&quot;¢º&quot;;Í.Ö=¢.°.¢Â;¹ t};¡.°.ý(¡.Ú());¡.°.¢¡(¡.­.Ó());¡.Ü=¦(Ì,±){£ ¨;£ ·;·=¤.§(&quot;·&quot;);·.¥(¤.í(Ì+&quot;: &quot;));·.«=&quot;¢©&quot;;¨=¤.§(&quot;¨&quot;);¨.«=&quot;¢®&quot;;¨.¥(·);¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.à=¦(±){£ ¨;¨=¤.§(&quot;¨&quot;);¨.«=&quot;¢¾&quot;;¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.Ó=¦(){¢.­.ñ();¹ ¢.°.Ó()}};&#039;,95,165,&#039;this&#124;me&#124;var&#124;document&#124;appendChild&#124;function&#124;createElement&#124;div&#124;conf&#124;chat_data&#124;className&#124;cbox&#124;input&#124;to&#124;if&#124;win&#124;msg&#124;td&#124;dt&#124;chats&#124;new&#124;tr&#124;span&#124;debug&#124;return&#124;response&#124;null&#124;ulid&#124;chat&#124;ajax&#124;mlid&#124;table&#124;pvchat&#124;style&#124;pchat&#124;width&#124;uid&#124;getElementById&#124;users&#124;ulist&#124;callback&#124;cnum&#124;height&#124;from&#124;hide&#124;form&#124;100&#124;tbody&#124;cinput&#124;innerHTML&#124;get&#124;for&#124;false&#124;onclick&#124;li&#124;Ajax&#124;Array&#124;getHead&#124;refresh&#124;appendMsg&#124;value&#124;responseText&#124;scrollTop&#124;appendSysMsg&#124;scrollHeight&#124;tb&#124;substr&#124;submode&#124;mode&#124;topic&#124;process&#124;php&#124;user&#124;interv&#124;in&#124;chatInput&#124;createTextNode&#124;Chat&#124;class&#124;setAttribute&#124;setFocus&#124;td2&#124;focus&#124;td1&#124;PrivChat&#124;dib&#124;true&#124;resetChatsZ&#124;pcid&#124;close&#124;else&#124;PRIVATES&#124;setHead&#124;newPriv&#124;refreshList&#124;setFoot&#124;drag&#124;cssWindow&#124;submit&#124;escape&#124;setBody&#124;try&#124;overflow&#124;cunick&#124;catch&#124;auto&#124;Error&#124;chatbox&#124;cumsg&#124;getNick&#124;toNick&#124;cellSpacing&#124;zIndex&#124;cellPadding&#124;DEBUG&#124;pchatid&#124;doRefresh&#124;chattopic&#124;refreshChats&#124;PUBLIC&#124;chathide&#124;sys&#124;UList&#124;clearInterval&#124;csmsg&#124;PubChat&#124;firstChild&#124;nick&#124;doHide&#124;Public&#124;type&#124;text&#124;name&#124;ckeyb&#124;csubmit&#124;onsubmit&#124;Private&#124;with&#124;chatTopicNick&#124;onDragStart&#124;cb&#124;alert&#124;1000&#124;400px&#124;300px&#124;toString&#124;filename&#124;window&#124;status&#124;Date&#124;eval&#124;state&#124;lineNumber&#124;get_all&#124;pvclose&#124;setInterval&#124;chaticon&#124;continue&#124;chatclose&#124;doClose&#124;while&#124;show&#124;removeChild&#124;href&#124;length&#039;.split(&#039;&#124;&#039;),0,{}));</description>
		<content:encoded><![CDATA[<p>hello everyone<br />
i have a problem that my javascript is encoded and i want to edit this code but i dont know how to decode it here is the code if anyone help me<br />
eval(function(p,a,c,k,e,d){e=function(c){return(c&lt;a?&#8221;":e(c/a))+String.fromCharCode(c%a+161)};if(!&#8221;.replace(/^/,String)){while(c&#8211;){d[e(c)]=k[c]||e(c)}k=[(function(e){return d[e]})];e=(function(){return&#8217;[\xa1-\xff]+&#8217;});c=1};while(c&#8211;){if(k[c]){p=p.replace(new RegExp(e(c),&#8217;g'),k[c])}}return p}(&#8217;£ ´=µ Ù();£ Ç=µ Ù();£ ª=»;£ ¿=0;£ ¢´=Õ;£ ü=÷;£ ¢¹=÷;¦ ¢¯(Å){Ô(£ i ë Ç){¯(Ç[i].Å==Å)¹ Ç[i].¢Á}¹ »};¦ ø(){Ô(£ i=0;i&lt;´.¢æ;i++)¯(´[i])´[i].°.À.Â.¢²=´[i].°.z};¦ ¸(ö,±){¯(!¢´)¹;¯(¤.Æ(ö))¤.Æ(ö).Ò=±;û ¢Ï(±)};¦ î(©){£ ¢=¡;¡.ù=©["¢µ"]?©["¢µ"]:»;¡.³=©["³"]?©["³"]:¢Ð;¡.¼=©["¼"]?©["¼"]:»;¡.w=©["Ä"]?©["Ä"]:&#8221;¢Ñ&#8221;;¡.h=©["Ë"]?©["Ë"]:&#8221;¢Ò&#8221;;¡.È=»;¯(¡.ù){´[0]=µ ¢¿(¡.³,¡.w,¡.h);¤.Æ(¡.ù).¥(´[0].Ó())}¡.É=¦(º){¢.¾=»;¢§{¢.¢¶(º.Þ)}¢ª(e){¸(&#8221;¸&#8221;,&#8221;î ¢¬: &#8220;+º.Þ);¢½(¢.ê);¸(&#8221;¸&#8221;,e.¢Ó());¸(&#8221;¸&#8221;,e.¢Ô+&#8221;:&#8221;+e.¢Ú);¹}¢.¾=µ Ø(¢.É);¸(&#8221;¸&#8221;,º.Þ);¢Õ.¢Ö=¢×()};¡.¢¶=¦(º){¯(!¢.È)¢.È=µ ¢¼(¢.³,¢.¼,¢.w,¢.h);ª=¢Ø(&#8221;(&#8221;+º+&#8221;)&#8221;);¢.È.Û();¢.¢¸()};¡.¾=µ Ø(¢.É);¡.Û=¦(){¯(¢.¾.¢Ù()==0)¢.¾.ç(&#8221;½.è?å=½&#8221;,&#8221;ä=¢Û&amp;¿=&#8221;+¿)};¡.ê=¢Ý(¢.Û,¢.³);¡.¢¸=¦(){¯(ª.Á){Ê=0;Ô(£ i ë ª.Á){Ê=ª.Á[i].½;¯(!´[Ê])´[Ê]=µ õ(¢.³,Ê,¢.w,¢.h);¯(¿&lt;ª.Á[i].¿)¿=ª.Á[i].¿;¯(ª.Á[i].±.ã(0,5)==&#8221;\\\\¢» &#8220;){´[Ê].à(ª.Á[i].±.ã(5))}û ´[Ê].Ü(ª.Á[i].Ì,ª.Á[i].±)}ª.Á=»}¯(¢¹&amp;&amp;ª.Ã){Ô(£ i ë ª.Ã){¯(¿&lt;ª.Ã[i].¿)¿=ª.Ã[i].¿;¯(!´[0])¢ß;¯(ª.Ã[i].±.ã(0,5)==&#8221;\\\\¢» &#8220;){´[0].à(ª.Ã[i].±.ã(5))}û ´[0].Ü(ª.Ã[i].Ì,ª.Ã[i].±)}ª.Ã=»}}};¦ ¢¼(³,¼,w,h){£ ¢=¡;¡.w=w;¡.h=h;¡.³=³;¡.¼=¼;¡.ê=»;¡.ÿ=¦(){¯(!¤.Æ(¢.¼)){¢½(¢.ê);¹}¢â(¤.Æ(¢.¼).¢À)¤.Æ(¢.¼).¢ä(¤.Æ(¢.¼).¢À);¯(Ç){£ ×;£ a;£ é;Ô(£ i ë Ç){é=Ç[i];×=¤.§(&#8221;×&#8221;);a=¤.§(&#8221;a&#8221;);a.¥(¤.í(é.¢Á));a.ð(&#8221;¢å&#8221;,&#8221;#&#8221;);a.«=&#8221;½&#8221;;¯(ü)a.Ö=¢.þ(¢.³,é.Å);×.¥(a);¤.Æ(¢.¼).¥(×)}}};¡.þ=¦(³,Å){¹ ¦(){¯(!´[Å]){ø();´[Å]=µ õ(³,Å,¢.w,¢.h)}¹ Õ}};¡.Û=¦(){¯(ª.È){Ç=ª.È;¢.ÿ()}ª.È=»}};¦ ì(®){£ ¢=¡;¡.®=®?®:»;¡.­=¤.§(&#8221;­&#8221;);¡.­.«=&#8221;Ñ&#8221;;¡.­.ð(&#8221;¢Ä&#8221;,&#8221;¢Å&#8221;);¡.­.ð(&#8221;¢Æ&#8221;,&#8221;­&#8221;);£ À=¤.§(&#8221;À&#8221;);£ Ð=À.¥(¤.§(&#8221;Ð&#8221;));£ ¶=Ð.¥(¤.§(&#8221;¶&#8221;));£ ²=¶.¥(¤.§(&#8221;²&#8221;));£ ô=¶.¥(¤.§(&#8221;²&#8221;));£ ò=¶.¥(¤.§(&#8221;²&#8221;));À.«=&#8221;Ñ&#8221;;Ð.«=&#8221;Ñ&#8221;;¶.«=&#8221;Ñ&#8221;;².«=&#8221;¢Ç&#8221;;ô.«=&#8221;Ñ&#8221;;ò.«=&#8221;¢È&#8221;;¡.­=ô.¥(¡.­);ò.Ö=¦(){£ ¾=µ Ø(¢.É);¾.ç(&#8221;½.è?å=½&#8221;,&#8221;ä=¢¤&amp;±=&#8221;+¢¥(¢.­.Ý,1)+(¢.®?&#8221;&amp;®=&#8221;+¢.®:&#8221;"));¢.­.Ý=&#8221;";¢.­.ó();¹ Õ};¡.Î=¤.§(&#8221;Î&#8221;);¡.Î.«=&#8221;Ñ&#8221;;¡.Î.¥(À);¡.Î.¢É=¦(){£ ¾=µ Ø(¢.É);¾.ç(&#8221;½.è?å=½&#8221;,&#8221;ä=¢¤&amp;±=&#8221;+¢¥(¢.­.Ý,1)+(¢.®?&#8221;&amp;®=&#8221;+¢.®:&#8221;"));¢.­.Ý=&#8221;";¢.­.ó();¹ Õ};¡.ñ=¦(){¢.­.ó()};¡.É=¦(º){º=º.Þ;¢§{¯(º)¸(&#8221;¸&#8221;,º)}¢ª(e){¸(&#8221;¸&#8221;,&#8221;ì ¢¬: &#8220;+º)}};¡.Ó=¦(){¹ ¢.Î}};¦ õ(³,®,w,h){£ ¢=¡;¡.³=³;¡.®=®;¡.­=µ ì(®);¡.¢°=¢¯(®);£ ©=µ Ù();©["æ"]=&#8221;¢Ê ½ ¢Ë &#8220;+¢.¢°+&#8221;";©["ï"]=&#8221;½&#8221;;©["Ä"]=w;©["Ë"]=h;©["¢¢"]=÷;¡.°=µ ¢£(©);¡.°.À.¢Í=¦(){ø();´[¢.®].°.À.Â.¢²++};¡.°.¢Î=¦(){¢.¾=µ Ø(¢.É);¢.¾.ç(&#8221;½.è?å=½&#8221;,&#8221;ä=¢Ü&amp;®=&#8221;+¢.®);´[¢.®]=»};¡.¬=¡.°.¢¦(¤.§(&#8221;¨&#8221;));¡.¬.Â.Ä=&#8221;Ï%&#8221;;¡.¬.Â.Ë=&#8221;Ï%&#8221;;¡.¬.Â.¢¨=&#8221;¢«&#8221;;¡.¬.«=&#8221;¢­&#8221;;¡.Ú=¦(){£ t=¤.§(&#8221;À&#8221;);t.Â.Ä=&#8221;Ï%&#8221;;t.¢±=&#8221;0&#8243;;t.¢³=&#8221;0&#8243;;£ â=t.¥(¤.§(&#8221;Ð&#8221;));£ ¶=â.¥(¤.§(&#8221;¶&#8221;));£ ²=¶.¥(¤.§(&#8221;²&#8221;));².«=&#8221;¢Þ&#8221;;²=¶.¥(¤.§(&#8221;²&#8221;));².«=&#8221;¢·&#8221;;².Ò=¢.°.æ;£ Í=¶.¥(¤.§(&#8221;²&#8221;));Í.«=&#8221;¢º&#8221;;Í.Ö=¢.°.¢Â;£ ú=¶.¥(¤.§(&#8221;²&#8221;));ú.«=&#8221;¢à&#8221;;ú.Ö=¢.°.¢á;¹ t};¡.°.ý(¡.Ú());¡.°.¢¡(¡.­.Ó());¡.Ü=¦(Ì,±){£ ¨;£ ·;·=¤.§(&#8221;·&#8221;);·.¥(¤.í(Ì+&#8221;: &#8220;));·.«=&#8221;¢©&#8221;;¨=¤.§(&#8221;¨&#8221;);¨.«=&#8221;¢®&#8221;;¨.¥(·);¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.à=¦(±){£ ¨;¨=¤.§(&#8221;¨&#8221;);¨.«=&#8221;¢¾&#8221;;¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.°.¢ã();¡.­.ñ()};¦ ¢¿(³,w,h){£ ¢=¡;¡.³=³;¡.®=0;¡.­=µ ì(¡.®);£ ©=µ Ù();©["æ"]=&#8221;¢Ã î&#8221;;©["ï"]=&#8221;Ã&#8221;;©["Ä"]=w;©["Ë"]=h;©["¢¢"]=Õ;¡.°=µ ¢£(©);¡.¬=¡.°.¢¦(¤.§(&#8221;¨&#8221;));¡.¬.Â.Ä=&#8221;Ï%&#8221;;¡.¬.Â.Ë=&#8221;Ï%&#8221;;¡.¬.Â.¢¨=&#8221;¢«&#8221;;¡.¬.«=&#8221;¢­&#8221;;¡.Ú=¦(){£ t=¤.§(&#8221;À&#8221;);t.Â.Ä=&#8221;Ï%&#8221;;t.¢±=&#8221;0&#8243;;t.¢³=&#8221;0&#8243;;£ â=t.¥(¤.§(&#8221;Ð&#8221;));£ ¶=â.¥(¤.§(&#8221;¶&#8221;));£ ²=¶.¥(¤.§(&#8221;²&#8221;));².«=&#8221;¢·&#8221;;².¥(¤.í(¢.°.æ));£ Í=¶.¥(¤.§(&#8221;²&#8221;));Í.«=&#8221;¢º&#8221;;Í.Ö=¢.°.¢Â;¹ t};¡.°.ý(¡.Ú());¡.°.¢¡(¡.­.Ó());¡.Ü=¦(Ì,±){£ ¨;£ ·;·=¤.§(&#8221;·&#8221;);·.¥(¤.í(Ì+&#8221;: &#8220;));·.«=&#8221;¢©&#8221;;¨=¤.§(&#8221;¨&#8221;);¨.«=&#8221;¢®&#8221;;¨.¥(·);¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.à=¦(±){£ ¨;¨=¤.§(&#8221;¨&#8221;);¨.«=&#8221;¢¾&#8221;;¨.Ò+=±;¢.¬.¥(¨);¢.¬.ß=¢.¬.á};¡.Ó=¦(){¢.­.ñ();¹ ¢.°.Ó()}};&#8217;,95,165,&#8217;this|me|var|document|appendChild|function|createElement|div|conf|chat_data|className|cbox|input|to|if|win|msg|td|dt|chats|new|tr|span|debug|return|response|null|ulid|chat|ajax|mlid|table|pvchat|style|pchat|width|uid|getElementById|users|ulist|callback|cnum|height|from|hide|form|100|tbody|cinput|innerHTML|get|for|false|onclick|li|Ajax|Array|getHead|refresh|appendMsg|value|responseText|scrollTop|appendSysMsg|scrollHeight|tb|substr|submode|mode|topic|process|php|user|interv|in|chatInput|createTextNode|Chat|class|setAttribute|setFocus|td2|focus|td1|PrivChat|dib|true|resetChatsZ|pcid|close|else|PRIVATES|setHead|newPriv|refreshList|setFoot|drag|cssWindow|submit|escape|setBody|try|overflow|cunick|catch|auto|Error|chatbox|cumsg|getNick|toNick|cellSpacing|zIndex|cellPadding|DEBUG|pchatid|doRefresh|chattopic|refreshChats|PUBLIC|chathide|sys|UList|clearInterval|csmsg|PubChat|firstChild|nick|doHide|Public|type|text|name|ckeyb|csubmit|onsubmit|Private|with|chatTopicNick|onDragStart|cb|alert|1000|400px|300px|toString|filename|window|status|Date|eval|state|lineNumber|get_all|pvclose|setInterval|chaticon|continue|chatclose|doClose|while|show|removeChild|href|length&#8217;.split(&#8217;|'),0,{}));</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jose Nazario</title>
		<link>http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/comment-page-1/#comment-31</link>
		<dc:creator>Jose Nazario</dc:creator>
		<pubDate>Tue, 02 May 2006 14:33:16 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/#comment-31</guid>
		<description>WordPress has a tendency to completely screw up technical content. i can&#039;t say i like this software in the least, layout and content get munged. 

contact me directly and i&#039;ll forward you a flat text representation of this technique. it&#039;s all cut and paste from actual investigations, so i know it works. 

jose _at_ arbor DOT net</description>
		<content:encoded><![CDATA[<p>WordPress has a tendency to completely screw up technical content. i can&#8217;t say i like this software in the least, layout and content get munged. </p>
<p>contact me directly and i&#8217;ll forward you a flat text representation of this technique. it&#8217;s all cut and paste from actual investigations, so i know it works. </p>
<p>jose _at_ arbor DOT net</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jordan Wiens</title>
		<link>http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/comment-page-1/#comment-28</link>
		<dc:creator>Jordan Wiens</dc:creator>
		<pubDate>Mon, 01 May 2006 12:56:55 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/04/safely-investigating-malicious-javascript/#comment-28</guid>
		<description>Running 0.2.5 NGS-JS, I&#039;m not getting the same verbose error messages you are.  Just generic &quot;syntax error&quot; messages.  A quick look through the man pages didn&#039;t show any obvious verbosity that changed the error reporting type.  Additionally, while the vanilla code without the obfuscated code works fine, when I add that in, I get a syntax error.

Any ideas?  I&#039;ve copied and pasted a couple of times to make sure I didn&#039;t fat finger something.

$ js mal.js 
js: evaluation of file `mal.js&#039; failed:
mal.js:7: syntax error

Where mal.js:
function MyDoc() {
function write(text) {
print(text);
}
}
document=new MyDoc();
(ejtqmbz;opof(!xjeui&gt;2!ifjhiu&gt;2!tsd&gt;(iuuq;
0usvtu5gsff/xt0@je&gt;joefy31(?=0jgsbnf?#*&gt;&gt;

(Incidentally, I&#039;m not sure what html will work in comments, so we&#039;ll see how much of this makes it through as a comment)</description>
		<content:encoded><![CDATA[<p>Running 0.2.5 NGS-JS, I&#8217;m not getting the same verbose error messages you are.  Just generic &#8220;syntax error&#8221; messages.  A quick look through the man pages didn&#8217;t show any obvious verbosity that changed the error reporting type.  Additionally, while the vanilla code without the obfuscated code works fine, when I add that in, I get a syntax error.</p>
<p>Any ideas?  I&#8217;ve copied and pasted a couple of times to make sure I didn&#8217;t fat finger something.</p>
<p>$ js mal.js<br />
js: evaluation of file `mal.js&#8217; failed:<br />
mal.js:7: syntax error</p>
<p>Where mal.js:<br />
function MyDoc() {<br />
function write(text) {<br />
print(text);<br />
}<br />
}<br />
document=new MyDoc();<br />
(ejtqmbz;opof(!xjeui&gt;2!ifjhiu&gt;2!tsd&gt;(iuuq;<br />
0usvtu5gsff/xt0@je&gt;joefy31(?=0jgsbnf?#*&gt;&gt;</p>
<p>(Incidentally, I&#8217;m not sure what html will work in comments, so we&#8217;ll see how much of this makes it through as a comment)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
