<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>website on LEl_FENG Blog</title><link>https://blog.xpdbk.com/en/categories/website/</link><description>Recent content in website on LEl_FENG Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>LEl_FENG Copyright</copyright><lastBuildDate>Tue, 29 Aug 2023 13:58:11 +0700</lastBuildDate><atom:link href="https://blog.xpdbk.com/en/categories/website/index.xml" rel="self" type="application/rss+xml"/><item><title>A Record of My Blog Being DDoS'ed and Illegally Attacked</title><link>https://blog.xpdbk.com/en/posts/ddos-blog-1/</link><pubDate>Tue, 29 Aug 2023 13:58:11 +0700</pubDate><guid>https://blog.xpdbk.com/en/posts/ddos-blog-1/</guid><description>&lt;blockquote>
&lt;p>&lt;strong>TL;DR / Geek Summary:&lt;/strong>&lt;/p>
&lt;ul>
&lt;li>Threat Intel: Sustained 4-day malicious DDoS/CC assault consuming 75GB+ bandwidth in hours.&lt;/li>
&lt;li>Attack Vector: Mirror link injection via shortcode service and volumetric HTTP floods.&lt;/li>
&lt;li>Mitigation: Deployed Cloudflare CDN (Orange Cloud) and WAF firewall rules to neutralize traffic.&lt;/li>
&lt;/ul>
&lt;/blockquote>
&lt;h2 id="introduction">
&lt;a href="#introduction" class="heading-anchor" aria-label="Anchor for Introduction">#&lt;/a>
Introduction
&lt;/h2>
&lt;p>Because I originally built my blog using &lt;code>wordpress&lt;/code>, I am very familiar with DDoS and CC attacks and have always paid close attention to them. Later on, I successively tried dynamic frameworks like &lt;code>typecho&lt;/code> and &lt;code>Halo&lt;/code>, then moved from &lt;code>jekyll&lt;/code> to &lt;code>Hexo&lt;/code>, before finally settling on &lt;code>Hugo&lt;/code>, a static blog framework. After that, I stopped worrying about server and DDoS protection issues and remained in a completely worry-free state. That is, until a certain &lt;code>person&lt;/code> recently launched a malicious 4-day attack on my website, which forced me to take DDoS and CC protection seriously again.&lt;/p>
&lt;h2 id="how-it-started">
&lt;a href="#how-it-started" class="heading-anchor" aria-label="Anchor for How It Started">#&lt;/a>
How It Started
&lt;/h2>
&lt;p>Around 11 PM, while I was scrolling through my phone, an email arrived telling me my website had already used &lt;code>75GB&lt;/code> of bandwidth. I thought to myself: what on earth used up so much bandwidth?&lt;/p>
&lt;p>&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/2.webp"
width="697"
height="427"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/2_hu61035c777cd25ad0569fb020cc1e0b45_18466_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/2_hu61035c777cd25ad0569fb020cc1e0b45_18466_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="Email Alert"
class="gallery-image"
data-flex-grow="163"
data-flex-basis="391px"
>
&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/3.webp"
width="912"
height="491"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/3_hu7af1aaf68db1dc93fc049848a022485f_14362_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/3_hu7af1aaf68db1dc93fc049848a022485f_14362_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="Bandwidth Exceeded 1"
class="gallery-image"
data-flex-grow="185"
data-flex-basis="445px"
>&lt;/p>
&lt;p>Then I clicked in to take a look, and it literally gave me a jump scare.&lt;/p>
&lt;p>&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/3123.webp"
width="923"
height="493"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/3123_hu0123f6b66a6ab32b027fa7fb52d57284_28416_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/3123_hu0123f6b66a6ab32b027fa7fb52d57284_28416_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="Bandwidth Exceeded 2"
class="gallery-image"
data-flex-grow="187"
data-flex-basis="449px"
>&lt;/p>
&lt;p>If I ignored this, my site would definitely be forced to shut down. And once it&amp;rsquo;s shut down, I would lose all my search engine indexing.&lt;/p>
&lt;h2 id="interlude">
&lt;a href="#interlude" class="heading-anchor" aria-label="Anchor for Interlude">#&lt;/a>
Interlude
&lt;/h2>
&lt;p>This attacker also stuffed a ton of gray-market (illicit) links into my URL shortening service. However, thanks to my HTML modifications to hide the input form, visiting &lt;code>https://l.xpdbk.com&lt;/code> doesn&amp;rsquo;t allow anyone to add links; only I can add them from the backend. I originally intended to make the service available for public use, but because people like this exist, I had no choice but to make it private.&lt;/p>
&lt;p>&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/42434234.webp"
width="1017"
height="563"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/42434234_hud03e8a81990fb7f7046ae308445b0da1_23936_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/42434234_hud03e8a81990fb7f7046ae308445b0da1_23936_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="Short Link Bandwidth Exceeded"
class="gallery-image"
data-flex-grow="180"
data-flex-basis="433px"
>
&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/4234234.webp"
width="1001"
height="380"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/4234234_hu6063fff67e2df29716fcd8bcb1ea4618_7504_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/4234234_hu6063fff67e2df29716fcd8bcb1ea4618_7504_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="Short Link Repository"
class="gallery-image"
data-flex-grow="263"
data-flex-basis="632px"
>
&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/25t24t.webp"
width="563"
height="470"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/25t24t_hue9bc7f51fd3d7e9ef89e1c8ccfd6cfda_24712_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/25t24t_hue9bc7f51fd3d7e9ef89e1c8ccfd6cfda_24712_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="Short Link Edit Interface"
class="gallery-image"
data-flex-grow="119"
data-flex-basis="287px"
>&lt;/p>
&lt;h2 id="taking-action">
&lt;a href="#taking-action" class="heading-anchor" aria-label="Anchor for Taking Action">#&lt;/a>
Taking Action
&lt;/h2>
&lt;p>I quickly rushed to enable &lt;code>CF CDN&lt;/code>. I hadn&amp;rsquo;t turned on the little orange cloud for Cloudflare CDN before because I wanted to accommodate loading speeds for users in China. Blocked by the WAF firewall, all of the attacker&amp;rsquo;s traffic was successfully mitigated.&lt;/p>
&lt;p>&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/53535.webp"
width="995"
height="334"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/53535_hueedac4e5686c85387a92fd68a787b89e_19228_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/53535_hueedac4e5686c85387a92fd68a787b89e_19228_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="WAF Firewall"
class="gallery-image"
data-flex-grow="297"
data-flex-basis="714px"
>
&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/5353a5.webp"
width="1000"
height="220"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/5353a5_hu6e4094afa2e8a5b0820c993b1cd0bbc8_9372_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/5353a5_hu6e4094afa2e8a5b0820c993b1cd0bbc8_9372_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="WAF Firewall 2"
class="gallery-image"
data-flex-grow="454"
data-flex-basis="1090px"
>&lt;/p>
&lt;h2 id="conclusion">
&lt;a href="#conclusion" class="heading-anchor" aria-label="Anchor for Conclusion">#&lt;/a>
Conclusion
&lt;/h2>
&lt;p>All the malicious traffic was completely neutralized.&lt;/p>
&lt;p>&lt;img src="https://blog.xpdbk.com/en/posts/ddos-blog-1/434324234.webp"
width="1020"
height="587"
srcset="https://blog.xpdbk.com/en/posts/ddos-blog-1/434324234_hu84ca457604e8b561332131fc2dee4026_38880_480x0_resize_q75_h2_box_2.webp 480w, https://blog.xpdbk.com/en/posts/ddos-blog-1/434324234_hu84ca457604e8b561332131fc2dee4026_38880_1024x0_resize_q75_h2_box_2.webp 1024w"
loading="lazy"
alt="Total Traffic"
class="gallery-image"
data-flex-grow="173"
data-flex-basis="417px"
>&lt;/p>
&lt;p>A word of advice for the attacker: In this world, you can&amp;rsquo;t get something for nothing.&lt;/p></description></item><item><title>A Record of My Blog Being Reverse Proxied</title><link>https://blog.xpdbk.com/en/posts/web-fake-fandai/</link><pubDate>Thu, 27 Jul 2023 10:11:14 +0700</pubDate><guid>https://blog.xpdbk.com/en/posts/web-fake-fandai/</guid><description>&lt;img src="https://blog.xpdbk.com/en/posts/web-fake-fandai/photo_2023-07-27_21-08-20.webp" alt="Featured image of post A Record of My Blog Being Reverse Proxied" />&lt;blockquote>
&lt;p>&lt;strong>TL;DR / Geek Summary:&lt;/strong>&lt;/p>
&lt;ul>
&lt;li>Incident: Detected a domain hijacking the entire blog via Cloudflare Workers reverse proxy.&lt;/li>
&lt;li>Defensive Patch: Implemented a JavaScript domain validator in the &lt;code>&amp;lt;head&amp;gt;&lt;/code> to force redirects.&lt;/li>
&lt;li>Obfuscation Hack: Used obfuscator.io to encrypt the JS logic, preventing the proxy from rewriting validation rules.&lt;/li>
&lt;/ul>
&lt;/blockquote>
&lt;p>Yesterday, I was checking my Google Analytics data
in my free time and spotted a referral from a domain I had never seen before. Initially, I thought it was just a scraper site or someone referencing my article, so I decided to take a look. However, upon opening the page, I saw my entire blog right there (completely unmodified).&lt;/p>
&lt;p>I wouldn&amp;rsquo;t just say the content was identical; even the page structure was exactly the same. I&amp;rsquo;ve seen scrapers and I&amp;rsquo;ve seen people referencing my work, but I&amp;rsquo;ve never seen an entire site being reverse-proxied like this before&amp;hellip;&lt;/p>
&lt;hr>
&lt;h2 id="at-first">
&lt;a href="#at-first" class="heading-anchor" aria-label="Anchor for At First">#&lt;/a>
At First
&lt;/h2>
&lt;p>At first, I thought they had just scraped and downloaded the site, and I wasn&amp;rsquo;t going to care. But later I realized they were directly reverse proxying it using Cloudflare Workers, and they had even modified the host header. Because of this, standard anti-hotlinking measures were basically useless&amp;hellip;&lt;/p>
&lt;p>After some Googling, I found out that this kind of situation can be handled using a JavaScript script.&lt;/p>
&lt;p>In the beginning, I just used JS to verify if the window&amp;rsquo;s domain was correct. If it wasn&amp;rsquo;t, it would automatically redirect to the correct domain.&lt;/p>
&lt;p>The code is as follows. Please put it inside the &lt;code>&amp;lt;head&amp;gt;&lt;/code> tag:&lt;/p>
&lt;div class="highlight">&lt;div class="chroma">
&lt;table class="lntable">&lt;tr>&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code>&lt;span class="lnt"> 1
&lt;/span>&lt;span class="lnt"> 2
&lt;/span>&lt;span class="lnt"> 3
&lt;/span>&lt;span class="lnt"> 4
&lt;/span>&lt;span class="lnt"> 5
&lt;/span>&lt;span class="lnt"> 6
&lt;/span>&lt;span class="lnt"> 7
&lt;/span>&lt;span class="lnt"> 8
&lt;/span>&lt;span class="lnt"> 9
&lt;/span>&lt;span class="lnt">10
&lt;/span>&lt;span class="lnt">11
&lt;/span>&lt;span class="lnt">12
&lt;/span>&lt;span class="lnt">13
&lt;/span>&lt;span class="lnt">14
&lt;/span>&lt;span class="lnt">15
&lt;/span>&lt;/code>&lt;/pre>&lt;/td>
&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code class="language-JavaScript" data-lang="JavaScript">&lt;span class="line">&lt;span class="cl">&lt;span class="kr">const&lt;/span> &lt;span class="nx">validDomains&lt;/span> &lt;span class="o">=&lt;/span>&lt;span class="p">[&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="s1">&amp;#39;blog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="s1">&amp;#39;vlblog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="s1">&amp;#39;lelfeng.netlify.app&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="s1">&amp;#39;cfblog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="s1">&amp;#39;1x000.github.io&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="s1">&amp;#39;adaewfd321fg3.cachefly.net&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="s1">&amp;#39;127.0.0.1:1313&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="s1">&amp;#39;localhost:1313&amp;#39;&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="p">]&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="k">try&lt;/span> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="k">if&lt;/span> &lt;span class="p">(&lt;/span>&lt;span class="nx">validDomains&lt;/span>&lt;span class="p">.&lt;/span>&lt;span class="nx">indexOf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nb">document&lt;/span>&lt;span class="p">.&lt;/span>&lt;span class="nx">location&lt;/span>&lt;span class="p">.&lt;/span>&lt;span class="nx">hostname&lt;/span> &lt;span class="o">+&lt;/span>&lt;span class="s1">&amp;#39;:&amp;#39;&lt;/span>&lt;span class="o">+&lt;/span> &lt;span class="nb">document&lt;/span>&lt;span class="p">.&lt;/span>&lt;span class="nx">location&lt;/span>&lt;span class="p">.&lt;/span>&lt;span class="nx">port&lt;/span>&lt;span class="p">)&lt;/span> &lt;span class="o">===&lt;/span> &lt;span class="o">-&lt;/span>&lt;span class="mi">1&lt;/span>&lt;span class="p">)&lt;/span> &lt;span class="p">{&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="nb">window&lt;/span>&lt;span class="p">.&lt;/span>&lt;span class="nx">location&lt;/span>&lt;span class="p">.&lt;/span>&lt;span class="nx">href&lt;/span> &lt;span class="o">=&lt;/span> &lt;span class="s1">&amp;#39;http://blog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">;&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl"> &lt;span class="p">}&lt;/span>
&lt;/span>&lt;/span>&lt;span class="line">&lt;span class="cl">&lt;span class="p">}&lt;/span> &lt;span class="k">catch&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">e&lt;/span>&lt;span class="p">)&lt;/span> &lt;span class="p">{}&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/td>&lt;/tr>&lt;/table>
&lt;/div>
&lt;/div>&lt;p>However, this guy didn&amp;rsquo;t play by the rules. Through the reverse proxy, he replaced all the domains in the files with his own domain, which resulted in an infinite loop.&lt;/p>
&lt;p>Later, I used &lt;a class="link" href="https://obfuscator.io/" target="_blank" rel="noopener"
>https://obfuscator.io/&lt;/a>
&lt;span style="white-space: nowrap;">&lt;svg width=".7em"
height=".7em" viewBox="0 0 21 21" xmlns="http://www.w3.org/2000/svg">
&lt;path d="m13 3l3.293 3.293l-7 7l1.414 1.414l7-7L21 11V3z" fill="currentColor" />
&lt;path d="M19 19H5V5h7l-2-2H5c-1.103 0-2 .897-2 2v14c0 1.103.897 2 2 2h14c1.103 0 2-.897 2-2v-5l-2-2v7z"
fill="currentColor">
&lt;/svg>&lt;/span>
to obfuscate the JS code. This successfully prevented the domains from being modified and replaced.&lt;/p>
&lt;p>The obfuscated sample code is as follows:&lt;/p>
&lt;div class="highlight">&lt;div class="chroma">
&lt;table class="lntable">&lt;tr>&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code>&lt;span class="lnt">1
&lt;/span>&lt;/code>&lt;/pre>&lt;/td>
&lt;td class="lntd">
&lt;pre tabindex="0" class="chroma">&lt;code class="language-JavaScript" data-lang="JavaScript">&lt;span class="line">&lt;span class="cl">&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x27a7&lt;/span>&lt;span class="p">;(&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0xafca11&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x40b2b8&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x27a7&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x15b338&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0xafca11&lt;/span>&lt;span class="p">();&lt;/span>&lt;span class="k">while&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="o">!!&lt;/span>&lt;span class="p">[]){&lt;/span>&lt;span class="k">try&lt;/span>&lt;span class="p">{&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x517e5b&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x188&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x1&lt;/span>&lt;span class="o">*&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x196&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x2&lt;/span>&lt;span class="p">)&lt;/span>&lt;span class="o">+-&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x189&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x3&lt;/span>&lt;span class="o">+-&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x18c&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x4&lt;/span>&lt;span class="o">+&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x194&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x5&lt;/span>&lt;span class="o">+&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x1a6&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x6&lt;/span>&lt;span class="o">+-&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x19c&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x7&lt;/span>&lt;span class="o">*&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x1a3&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x8&lt;/span>&lt;span class="p">)&lt;/span>&lt;span class="o">+-&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x19a&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0x9&lt;/span>&lt;span class="o">*&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="o">-&lt;/span>&lt;span class="nb">parseInt&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x35c55e&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x19d&lt;/span>&lt;span class="p">))&lt;/span>&lt;span class="o">/&lt;/span>&lt;span class="mh">0xa&lt;/span>&lt;span class="p">);&lt;/span>&lt;span class="k">if&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x517e5b&lt;/span>&lt;span class="o">===&lt;/span>&lt;span class="nx">_0x40b2b8&lt;/span>&lt;span class="p">)&lt;/span>&lt;span class="k">break&lt;/span>&lt;span class="p">;&lt;/span>&lt;span class="k">else&lt;/span> &lt;span class="nx">_0x15b338&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;push&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nx">_0x15b338&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;shift&amp;#39;&lt;/span>&lt;span class="p">]());}&lt;/span>&lt;span class="k">catch&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x6c5198&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="nx">_0x15b338&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;push&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nx">_0x15b338&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;shift&amp;#39;&lt;/span>&lt;span class="p">]());}}}(&lt;/span>&lt;span class="nx">_0x17e0&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="mh">0x5e4df&lt;/span>&lt;span class="p">));&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x130d92&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="kd">let&lt;/span> &lt;span class="nx">_0x2e53a6&lt;/span>&lt;span class="o">=!!&lt;/span>&lt;span class="p">[];&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="kd">function&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x323b74&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x490435&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x1c497f&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x2e53a6&lt;/span>&lt;span class="o">?&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="k">if&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x490435&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x33bf80&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x490435&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;apply&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nx">_0x323b74&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">arguments&lt;/span>&lt;span class="p">);&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x490435&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="kc">null&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x33bf80&lt;/span>&lt;span class="p">;}}&lt;/span>&lt;span class="o">:&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){};&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x2e53a6&lt;/span>&lt;span class="o">=!&lt;/span>&lt;span class="p">[],&lt;/span>&lt;span class="nx">_0x1c497f&lt;/span>&lt;span class="p">;};}()),&lt;/span>&lt;span class="nx">_0x4b63bb&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x130d92&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="k">this&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x982257&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x27a7&lt;/span>&lt;span class="p">;&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x4b63bb&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x982257&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x184&lt;/span>&lt;span class="p">)]()[&lt;/span>&lt;span class="nx">_0x982257&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x192&lt;/span>&lt;span class="p">)](&lt;/span>&lt;span class="nx">_0x982257&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x198&lt;/span>&lt;span class="p">))[&lt;/span>&lt;span class="nx">_0x982257&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x184&lt;/span>&lt;span class="p">)]()[&lt;/span>&lt;span class="nx">_0x982257&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x19f&lt;/span>&lt;span class="p">)](&lt;/span>&lt;span class="nx">_0x4b63bb&lt;/span>&lt;span class="p">)[&lt;/span>&lt;span class="nx">_0x982257&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x192&lt;/span>&lt;span class="p">)](&lt;/span>&lt;span class="nx">_0x982257&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x198&lt;/span>&lt;span class="p">));});&lt;/span>&lt;span class="nx">_0x4b63bb&lt;/span>&lt;span class="p">();&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x3f0a06&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="kd">let&lt;/span> &lt;span class="nx">_0x2f2ee3&lt;/span>&lt;span class="o">=!!&lt;/span>&lt;span class="p">[];&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="kd">function&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0xf1a2dc&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x12daa7&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x2c78dc&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x2f2ee3&lt;/span>&lt;span class="o">?&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="k">if&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x12daa7&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x1e1bbf&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x12daa7&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;apply&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nx">_0xf1a2dc&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">arguments&lt;/span>&lt;span class="p">);&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x12daa7&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="kc">null&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x1e1bbf&lt;/span>&lt;span class="p">;}}&lt;/span>&lt;span class="o">:&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){};&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x2f2ee3&lt;/span>&lt;span class="o">=!&lt;/span>&lt;span class="p">[],&lt;/span>&lt;span class="nx">_0x2c78dc&lt;/span>&lt;span class="p">;};}()),&lt;/span>&lt;span class="nx">_0x11b84d&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x3f0a06&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="k">this&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x27a7&lt;/span>&lt;span class="p">;&lt;/span>&lt;span class="kd">let&lt;/span> &lt;span class="nx">_0x1c1520&lt;/span>&lt;span class="p">;&lt;/span>&lt;span class="k">try&lt;/span>&lt;span class="p">{&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x48284c&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nb">Function&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x18d&lt;/span>&lt;span class="p">)&lt;/span>&lt;span class="o">+&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x18a&lt;/span>&lt;span class="p">)&lt;/span>&lt;span class="o">+&lt;/span>&lt;span class="s1">&amp;#39;);&amp;#39;&lt;/span>&lt;span class="p">);&lt;/span>&lt;span class="nx">_0x1c1520&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x48284c&lt;/span>&lt;span class="p">();}&lt;/span>&lt;span class="k">catch&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x560e71&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="nx">_0x1c1520&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nb">window&lt;/span>&lt;span class="p">;}&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x4777cb&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x1c1520&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;console&amp;#39;&lt;/span>&lt;span class="p">]&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x1c1520&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x1a5&lt;/span>&lt;span class="p">)]&lt;/span>&lt;span class="o">||&lt;/span>&lt;span class="p">{},&lt;/span>&lt;span class="nx">_0x10f092&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x1a4&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x1a0&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x187&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x18b&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x19b&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x193&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x185&lt;/span>&lt;span class="p">)];&lt;/span>&lt;span class="k">for&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="kd">let&lt;/span> &lt;span class="nx">_0x41e094&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="mh">0x0&lt;/span>&lt;span class="p">;&lt;/span>&lt;span class="nx">_0x41e094&lt;/span>&lt;span class="o">&amp;lt;&lt;/span>&lt;span class="nx">_0x10f092&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x190&lt;/span>&lt;span class="p">)];&lt;/span>&lt;span class="nx">_0x41e094&lt;/span>&lt;span class="o">++&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0xa11f57&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x3f0a06&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x19f&lt;/span>&lt;span class="p">)][&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x197&lt;/span>&lt;span class="p">)][&lt;/span>&lt;span class="s1">&amp;#39;bind&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nx">_0x3f0a06&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x5853a5&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x10f092&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x41e094&lt;/span>&lt;span class="p">],&lt;/span>&lt;span class="nx">_0x418439&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x4777cb&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5853a5&lt;/span>&lt;span class="p">]&lt;/span>&lt;span class="o">||&lt;/span>&lt;span class="nx">_0xa11f57&lt;/span>&lt;span class="p">;&lt;/span>&lt;span class="nx">_0xa11f57&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x1a1&lt;/span>&lt;span class="p">)]&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x3f0a06&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;bind&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nx">_0x3f0a06&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0xa11f57&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x184&lt;/span>&lt;span class="p">)]&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x418439&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5958bf&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x184&lt;/span>&lt;span class="p">)][&lt;/span>&lt;span class="s1">&amp;#39;bind&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nx">_0x418439&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x4777cb&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x5853a5&lt;/span>&lt;span class="p">]&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0xa11f57&lt;/span>&lt;span class="p">;}});&lt;/span>&lt;span class="nx">_0x11b84d&lt;/span>&lt;span class="p">();&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">validDomains&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x191&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x195&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x18e&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x18f&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x19e&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="s1">&amp;#39;adaewfd321fg3.cachefly.net&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x186&lt;/span>&lt;span class="p">),&lt;/span>&lt;span class="s1">&amp;#39;localhost:1313&amp;#39;&lt;/span>&lt;span class="p">];&lt;/span>&lt;span class="kd">function&lt;/span> &lt;span class="nx">_0x27a7&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x30b2be&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x27f11a&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x2f8ec1&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x17e0&lt;/span>&lt;span class="p">();&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x27a7&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x11b84d&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x3f0a06&lt;/span>&lt;span class="p">){&lt;/span>&lt;span class="nx">_0x11b84d&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x11b84d&lt;/span>&lt;span class="o">-&lt;/span>&lt;span class="mh">0x183&lt;/span>&lt;span class="p">;&lt;/span>&lt;span class="kd">let&lt;/span> &lt;span class="nx">_0x2ded53&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x2f8ec1&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x11b84d&lt;/span>&lt;span class="p">];&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x2ded53&lt;/span>&lt;span class="p">;},&lt;/span>&lt;span class="nx">_0x27a7&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x30b2be&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="nx">_0x27f11a&lt;/span>&lt;span class="p">);}&lt;/span>&lt;span class="kd">function&lt;/span> &lt;span class="nx">_0x17e0&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="kr">const&lt;/span> &lt;span class="nx">_0x30092e&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;__proto__&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;http://blog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;248mjjPBK&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;log&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;console&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;2331390Rbmidg&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;location&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;toString&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;trace&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;127.0.0.1:1313&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;info&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;1hGmVnj&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;511494uNxHBt&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;{}.constructor(\x22return\x20this\x22)(\x20)&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;error&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;1689000vVCMXN&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;return\x20(function()\x20&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;lelfeng.netlify.app&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;cfblog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;length&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;blog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;search&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;table&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;2697315oyIMgb&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;vlblog.xpdbk.com&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;405444fEnPtY&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;prototype&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;(((.+)+)+)+$&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;hostname&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;422352iCyGvT&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;exception&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;119035WNGFBa&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;80LiPhiY&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;1x000.github.io&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;constructor&amp;#39;&lt;/span>&lt;span class="p">,&lt;/span>&lt;span class="s1">&amp;#39;warn&amp;#39;&lt;/span>&lt;span class="p">];&lt;/span>&lt;span class="nx">_0x17e0&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="kd">function&lt;/span>&lt;span class="p">(){&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x30092e&lt;/span>&lt;span class="p">;};&lt;/span>&lt;span class="k">return&lt;/span> &lt;span class="nx">_0x17e0&lt;/span>&lt;span class="p">();}&lt;/span>&lt;span class="k">try&lt;/span>&lt;span class="p">{&lt;/span>&lt;span class="nx">validDomains&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="s1">&amp;#39;indexOf&amp;#39;&lt;/span>&lt;span class="p">](&lt;/span>&lt;span class="nb">document&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x183&lt;/span>&lt;span class="p">)][&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x199&lt;/span>&lt;span class="p">)]&lt;/span>&lt;span class="o">+&lt;/span>&lt;span class="s1">&amp;#39;:&amp;#39;&lt;/span>&lt;span class="o">+&lt;/span>&lt;span class="nb">document&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x183&lt;/span>&lt;span class="p">)][&lt;/span>&lt;span class="s1">&amp;#39;port&amp;#39;&lt;/span>&lt;span class="p">])&lt;/span>&lt;span class="o">===-&lt;/span>&lt;span class="mh">0x1&lt;/span>&lt;span class="o">&amp;amp;&amp;amp;&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nb">window&lt;/span>&lt;span class="p">[&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x183&lt;/span>&lt;span class="p">)][&lt;/span>&lt;span class="s1">&amp;#39;href&amp;#39;&lt;/span>&lt;span class="p">]&lt;/span>&lt;span class="o">=&lt;/span>&lt;span class="nx">_0x43eb42&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="mh">0x1a2&lt;/span>&lt;span class="p">));}&lt;/span>&lt;span class="k">catch&lt;/span>&lt;span class="p">(&lt;/span>&lt;span class="nx">_0x573349&lt;/span>&lt;span class="p">){}&lt;/span>
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/td>&lt;/tr>&lt;/table>
&lt;/div>
&lt;/div>&lt;p>By taking this encrypted code and randomly inserting it into one of the scripts referenced on your site, you&amp;rsquo;ll leave the trash running those mirror sites with no way to bypass it.&lt;/p>
&lt;p>&lt;strong>With this, the problem is basically solved. Let those jerks go cry about it.&lt;/strong>&lt;/p></description></item><item><title>Uninstall Apache Advanced Edition</title><link>https://blog.xpdbk.com/en/posts/web-hax/</link><pubDate>Fri, 11 Nov 2022 00:00:00 +0700</pubDate><guid>https://blog.xpdbk.com/en/posts/web-hax/</guid><description>&lt;img src="https://blog.xpdbk.com/en/posts/web-hax/hax.webp" alt="Featured image of post Uninstall Apache Advanced Edition" />&lt;blockquote>
&lt;p>&lt;strong>TL;DR / [Geek Summary]:&lt;/strong>&lt;/p>
&lt;ul>
&lt;li>Clean Slate: Completely purge redundant Apache2 services to reclaim occupied port 80/443 resources.&lt;/li>
&lt;li>Deep Scrub: Use &lt;code>apt-get --purge&lt;/code> to wipe binaries/configs and &lt;code>find | xargs rm&lt;/code> to hunt down and eliminate lingering fragments.&lt;/li>
&lt;li>Geek Goal: Clear the deck for Nginx or custom web stacks, keeping your server environment lightweight and manageable.&lt;/li>
&lt;/ul>
&lt;/blockquote>
&lt;h2 id="delete-apache">
&lt;a href="#delete-apache" class="heading-anchor" aria-label="Anchor for Delete apache">#&lt;/a>
Delete apache
&lt;/h2>
&lt;p>Apache2 is installed by default. Now uninstall this service.&lt;/p>
&lt;h2 id="1-find-web-services">
&lt;a href="#1-find-web-services" class="heading-anchor" aria-label="Anchor for 1. Find web services">#&lt;/a>
1. Find web services
&lt;/h2>
&lt;p>Use the following command:&lt;/p>
&lt;blockquote>
&lt;p>&lt;code>dpkg -l | grep apache2&lt;/code>&lt;/p>
&lt;/blockquote>
&lt;h2 id="2-delete-apache2">
&lt;a href="#2-delete-apache2" class="heading-anchor" aria-label="Anchor for 2. Delete apache2">#&lt;/a>
2. Delete apache2
&lt;/h2>
&lt;p>The deletion command is as follows:&lt;/p>
&lt;p>&lt;code>apt-get --purge remove apache2&lt;/code>&lt;/p>
&lt;p>&lt;code>apt-get --purge remove apache2-doc&lt;/code>&lt;/p>
&lt;p>&lt;code>apt-get --purge remove apache2-utils&lt;/code>&lt;/p>
&lt;p>&lt;code>apt-get --purge remove apache2-bin&lt;/code>&lt;/p>
&lt;p>&lt;code>apt-get --purge remove apache2-data&lt;/code>&lt;/p>
&lt;h2 id="3-delete-redundant-files">
&lt;a href="#3-delete-redundant-files" class="heading-anchor" aria-label="Anchor for 3. Delete redundant files">#&lt;/a>
3. &lt;strong>Delete redundant files&lt;/strong>
&lt;/h2>
&lt;p>After the above execution, execute the following command:&lt;/p>
&lt;p>&lt;code>find /etc -name &amp;quot;apache&amp;quot; |xargs rm -rf&lt;/code>&lt;/p>
&lt;p>&lt;code>rm -rf /var/www&lt;/code>&lt;/p>
&lt;p>&lt;code>rm -rf /etc/libapache2-mod-jk&lt;/code>&lt;/p>
&lt;h2 id="4-finally">
&lt;a href="#4-finally" class="heading-anchor" aria-label="Anchor for 4. Finally">#&lt;/a>
4. Finally
&lt;/h2>
&lt;p>Port 80 is released, no problem.&lt;/p></description></item></channel></rss>