{"id":1157,"date":"2013-12-01T19:52:37","date_gmt":"2013-12-01T19:52:37","guid":{"rendered":"http:\/\/www.kodcafe.com\/?p=1157"},"modified":"2013-12-01T19:52:37","modified_gmt":"2013-12-01T19:52:37","slug":"kilim-zararli-yazilimi","status":"publish","type":"post","link":"http:\/\/www.kodcafe.com\/?p=1157","title":{"rendered":"Kilim Zararl\u0131 Yaz\u0131l\u0131m\u0131"},"content":{"rendered":"<p>Sosyal medya kullan\u0131m\u0131n\u0131n artmas\u0131yla e-posta kutular\u0131n\u0131 dolduran spam maillerin benzerleri art\u0131k sosyal medya hesaplar\u0131nda da yayg\u0131nla\u015fmaya ba\u015flad\u0131. Ayr\u0131ca sosyal medya zararl\u0131 yaz\u0131l\u0131mlar\u0131n yay\u0131lmas\u0131\u00a0 i\u00e7in s\u0131kl\u0131kla kullan\u0131lan bir alan olmaya do\u011fru kay\u0131yor. Son g\u00fcnlerde \u00e7e\u015fitli versiyonlar\u0131n\u0131 g\u00f6rd\u00fc\u011f\u00fcm\u00fcz\u00a0<b>Kilim zararl\u0131 yaz\u0131l\u0131m\u0131<\/b>\u00a0da yay\u0131lmak i\u00e7in sosyal medyay\u0131 kullanan zararl\u0131 yaz\u0131l\u0131mlardan biri olarak kar\u015f\u0131m\u0131za \u00e7\u0131kmaktad\u0131r. Kilim zararl\u0131 yaz\u0131l\u0131m\u0131n\u0131n dikkat \u00e7eken bir \u00f6zelli\u011fi ise i\u00e7erdi\u011fi JavaScript kodlar\u0131n\u0131n T\u00fcrk\u00e7e de\u011fi\u015fken ve fonksiyon isimlerine sahip olmas\u0131d\u0131r. Ayn\u0131 zamanda 70milyon.net ve begenihavuzu.com gibi siteler ile ileti\u015fim kurmas\u0131, zararl\u0131 yaz\u0131l\u0131m\u0131n T\u00fcrkler taraf\u0131ndan yaz\u0131ld\u0131\u011f\u0131n\u0131 ve \u00f6zellikle T\u00fcrkleri hedef ald\u0131\u011f\u0131n\u0131 g\u00f6stermektedir.<br \/>\n<!--more--><br \/>\nKilim zararl\u0131 yaz\u0131l\u0131m\u0131, sosyal medya \u00fczerinden,\u00a0<b>chrome\u00a0<\/b>ve t\u00fcrevi olan\u00a0<b>yandex\u00a0<\/b>taray\u0131c\u0131lar\u0131n\u0131 kullanarak yay\u0131lmaktad\u0131r. Bu taray\u0131c\u0131lara olu\u015fturdu\u011fu\u00a0<b>player.crx\u00a0<\/b>dosyas\u0131 ile kendi eklentisi kurmaktad\u0131r ve daha sonra kurban\u0131n sosyal medya hesaplar\u0131 \u00fczerinde \u00e7e\u015fitli de\u011fi\u015fiklikler yapmaktad\u0131r. Kurban\u0131n aktif oturumunu kullanarak yay\u0131lmakta olan kilim zararl\u0131 yaz\u0131l\u0131m\u0131, kurban\u0131n \u00e7e\u015fitli sayfalar\u0131 be\u011fenmesine ve \u00e7e\u015fitli yay\u0131nlar yapmas\u0131na neden olmaktad\u0131r. Daha detayl\u0131 inceledi\u011fimizde yaz\u0131l\u0131m\u0131n paketlenmemi\u015f oldu\u011fu ve ileri analiz engelleme y\u00f6ntemleri gibi karma\u015f\u0131k yap\u0131lar i\u00e7ermedi\u011fi g\u00f6r\u00fclmektedir.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" title=\"1.png\" alt=\"1.png\" src=\"http:\/\/www.bilgiguvenligi.gov.tr\/images\/stories\/ocal\/kilim\/1.png\" width=\"539\" height=\"131\" \/><\/div>\n<p>\u015eekil 1 Kilim Zararl\u0131 Yaz\u0131l\u0131m\u0131 PEiD \u00e7\u0131kt\u0131s\u0131<\/p>\n<h2>Tespit<\/h2>\n<p>Zararl\u0131 yaz\u0131l\u0131m\u0131n \u00f6zet de\u011ferleri ve \u00f6zellikleri \u015f\u00f6yledir:<\/p>\n<blockquote><p><b>MD5 :<\/b>\u00a075a272915b4bbe0f3d7c9bb988f53de8<br \/>\n<b>SHA1:<\/b>\u00a051b4d5f9d5a3ea78ca0b889e4475be8d4c557173<br \/>\nDosya boyutu: 238.2 KB ( 243885 bytes )<\/p><\/blockquote>\n<p><b>\u015eekil 2<\/b>&#8216;de g\u00f6r\u00fclece\u011fi gibi Virus Total taramas\u0131nda 48 anti vir\u00fcs program\u0131n\u0131n 19\u2019u taraf\u0131ndan tan\u0131n\u0131yor.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" title=\"2.png\" alt=\"2.png\" src=\"http:\/\/www.bilgiguvenligi.gov.tr\/images\/stories\/ocal\/kilim\/2.png\" width=\"609\" height=\"131\" \/><\/div>\n<p>\u015eekil 2 Vir\u00fcs Total Taramas\u0131 Sonu\u00e7lar\u0131<\/p>\n<h2>\u00d6zellikleri<\/h2>\n<p><b>Nas\u0131l yay\u0131l\u0131r:<\/b>\u00a0Zararl\u0131 yaz\u0131l\u0131m chrome ve yandex taray\u0131c\u0131lar\u0131n\u0131 kullanan kurbanlar\u0131n sosyal medya oturumlar\u0131n\u0131 kullanarak haz\u0131rlad\u0131\u011f\u0131 iletilerle yay\u0131lmaktad\u0131r. Zararl\u0131 yaz\u0131l\u0131m, olu\u015fturdu\u011fu taray\u0131c\u0131 eklentisi sayesinde kurban\u0131n sosyal medya arkada\u015flar\u0131n\u0131 \u00e7eken\u00a0<b>http<\/b>talepleri haz\u0131rlamaktad\u0131r. Kurban\u0131n sosyal medya arkada\u015flar\u0131n\u0131 elde eden zararl\u0131 yaz\u0131l\u0131m, bu isimlerin ge\u00e7ti\u011fi bir ileti haz\u0131rlamaktad\u0131r. Kurban b\u00f6ylece arkada\u015flar\u0131n\u0131n etiketlendi\u011fi zararl\u0131 yaz\u0131l\u0131m\u0131 yayan iletiler payla\u015fmaktad\u0131r.\u00a0<b>\u015eekil 3<\/b>&#8216;te facebook \u00fczerinde payla\u015f\u0131lm\u0131\u015f zararl\u0131 yaz\u0131l\u0131m\u0131n kendini yaymak i\u00e7in haz\u0131rlad\u0131\u011f\u0131 \u00f6rnek bir ekran g\u00f6r\u00fcnt\u00fcs\u00fc g\u00f6r\u00fclmektedir.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" title=\"3.png\" alt=\"3.png\" src=\"http:\/\/www.bilgiguvenligi.gov.tr\/images\/stories\/ocal\/kilim\/3.png\" width=\"398\" height=\"332\" \/><\/div>\n<p>\u015eekil 3 Kilim Taraf\u0131ndan Olu\u015fturulan \u0130leti \u00d6rne\u011fi<\/p>\n<p>Zararl\u0131 yaz\u0131l\u0131m\u0131n olu\u015fturdu\u011fu dosya sisteminde ve kay\u0131t defteri anahtarlar\u0131nda yapt\u0131\u011f\u0131 de\u011fi\u015fiklikler ise \u015fu \u015fekildedir:<br \/>\nZararl\u0131 yaz\u0131l\u0131m \u00e7al\u0131\u015ft\u0131r\u0131ld\u0131\u011f\u0131nda\u00a0<b>C:\\ProgramData\\VideoPlayer<\/b>\u00a0alt\u0131nda\u00a0<b>\u015eekil 4<\/b>&#8216;te g\u00f6r\u00fclen dosyalar\u0131 olu\u015fturmaktad\u0131r.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" title=\"4.png\" alt=\"4.png\" src=\"http:\/\/www.bilgiguvenligi.gov.tr\/images\/stories\/ocal\/kilim\/4.png\" width=\"411\" height=\"156\" \/><\/div>\n<p>\u015eekil 4 Kilim Taraf\u0131ndan Olu\u015fturulan Dosyalar<\/p>\n<p>Zararl\u0131 yaz\u0131l\u0131m\u0131n ekledi\u011fi anahtarlar ve de\u011ferleri a\u015fa\u011f\u0131daki gibidir:<\/p>\n<blockquote><p>HKLM\\SOFTWARE\\Policies\\Google\\Chrome\\ExtensionInstallForcelist\\1: &#8220;<b>hkfmnabobennlihmnmkiplpinbdkppdp<\/b>;C:\\ProgramData\\VideoPlayer\\update.xml&#8221;<\/p>\n<p>HKLM\\SOFTWARE\\Policies\\YandexBrowser\\ExtensionInstallForcelist\\1: &#8220;<b>hkfmnabobennlihmnmkiplpinbdkppdp<\/b>;C:\\ProgramData\\VideoPlayer\\update.xml&#8221;<\/p>\n<p>&nbsp;<\/p><\/blockquote>\n<p>Zararl\u0131 yaz\u0131l\u0131m, dosya sisteminde olu\u015fturdu\u011fu\u00a0<b>update.xml<\/b>\u00a0dosyas\u0131na g\u00f6re Chrome ve Yandex taray\u0131c\u0131lar\u0131n g\u00fcncellenmesine dair bir kay\u0131t defteri girdisi olu\u015fturmaktad\u0131r.<\/p>\n<p>Update.xml dosyas\u0131n\u0131n i\u00e7eri\u011fi ise a\u015fa\u011f\u0131da verilmi\u015ftir. Dosya i\u00e7eri\u011finden eklenen anahtar de\u011ferleri ile taray\u0131c\u0131n\u0131n zararl\u0131 yaz\u0131l\u0131m\u0131n olu\u015fturdu\u011fu player.crx eklenti dosyas\u0131 ile g\u00fcncellenmek istendi\u011fi anla\u015f\u0131lmaktad\u0131r<\/p>\n<blockquote><p>&lt;?xml version=&#8221;1.0&#8243; encoding=&#8221;UTF-8&#8243; ?&gt;<\/p>\n<p>&#8211; &lt;gupdate xmlns=&#8221;http:\/\/www.google.com\/update2\/response&#8221; protocol=&#8221;2.0&#8243;&gt;<\/p>\n<p>&#8211; &lt;app appid=&#8221;<b>hkfmnabobennlihmnmkiplpinbdkppdp<\/b>&#8220;&gt;<\/p>\n<p>&lt;updatecheck codebase=&#8221;<b>C:\\ProgramData\\VideoPlayer\\player.crx<\/b>&#8221; version=&#8221;1.0&#8243; \/&gt;<\/p>\n<p>&lt;\/app&gt;<\/p>\n<p>&lt;\/gupdate&gt;<\/p>\n<p>&nbsp;<\/p><\/blockquote>\n<p>Zararl\u0131 yaz\u0131l\u0131m,\u00a0<b>sald\u0131rganla ileti\u015fime<\/b>\u00a0ge\u00e7mek i\u00e7in\u00a0<b>70milyon.com<\/b>\u00a0ve\u00a0<b>begenihavuzu.com<\/b>\u00a0sitelerini kullanmaktad\u0131r. Zararl\u0131 yaz\u0131l\u0131m, kurban\u0131n sosyal medya oturumu i\u00e7in kullan\u0131lan token bilgisini haz\u0131rlad\u0131\u011f\u0131 http talebi ile kendi sistemine aktarmaktad\u0131r. Ayr\u0131ca kurban\u0131n, bu sitelerden \u00e7ekti\u011fi (<i>http talepleri ile<\/i>) facebook sayfa isimlerini be\u011fenmesine neden olmaktad\u0131r. Ayr\u0131ca bu sitelerden video, foto\u011fraf gibi bilgiler \u00e7ekerek, bu bilgilerle kurban\u0131n bilgilerini harmanlayarak kurban\u0131n hesab\u0131nda yay\u0131lmak i\u00e7in iletiler yay\u0131nlamaktad\u0131r.<\/p>\n<p>Sitelerin alan ad\u0131 kay\u0131tlar\u0131 a\u015fa\u011f\u0131daki gibidir. Alan ad\u0131 kay\u0131tlar\u0131n\u0131n &#8220;<b>privacyprotect.org<\/b>&#8221; \u00fczerinde yap\u0131ld\u0131\u011f\u0131 g\u00f6r\u00fclmektedir. Daha detayl\u0131 bilgi i\u00e7in &#8220;<b>privacyprotect.org<\/b>&#8220;a talepte bulunulmas\u0131 gerekmektedir.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" title=\"5.png\" alt=\"5.png\" src=\"http:\/\/www.bilgiguvenligi.gov.tr\/images\/stories\/ocal\/kilim\/5.png\" width=\"609\" height=\"286\" \/><\/div>\n<p>\u015eekil 5 Zararl\u0131 Yaz\u0131l\u0131m\u0131n \u0130leti\u015fim Kurdu\u011fu Sitelerin Alan Ad\u0131 Kay\u0131tlar\u0131<\/p>\n<h2>Davran\u0131\u015f ve Kod analizi bulgular\u0131<\/h2>\n<p>Zararl\u0131 yaz\u0131l\u0131m \u00e7al\u0131\u015ft\u0131r\u0131ld\u0131\u011f\u0131nda olu\u015fan proses a\u011fac\u0131\u00a0<b>\u015eekil 6<\/b>&#8216;da g\u00f6r\u00fclmektedir. Komut sat\u0131r\u0131 istemcisi \u00e7al\u0131\u015farak a\u00e7\u0131k olan taray\u0131c\u0131y\u0131 kapatmaktad\u0131r. Daha sonra \u00e7al\u0131\u015fan\u00a0<b>&#8220;verclsid&#8221;\u00a0<\/b>prosesleri ise kay\u0131t defteri girdilerini olu\u015fturmakta ve dosya sistemine gerekli dosyalar\u0131 atmaktad\u0131r.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" title=\"6.png\" alt=\"6.png\" src=\"http:\/\/www.bilgiguvenligi.gov.tr\/images\/stories\/ocal\/kilim\/6.png\" width=\"609\" height=\"156\" \/><\/div>\n<p>\u015eekil 6 Kilim Proses A\u011fac\u0131<\/p>\n<p>Zararl\u0131 yaz\u0131l\u0131m iki a\u015famadan olu\u015fmaktad\u0131r.<\/p>\n<p>Exe uzant\u0131l\u0131 dosyan\u0131n amac\u0131<\/p>\n<ul>\n<li>A\u00e7\u0131k olan chrome, yandex taray\u0131c\u0131n\u0131n kapat\u0131lmas\u0131<\/li>\n<li>Bu taray\u0131c\u0131lar\u0131n g\u00fcncellenmesi i\u00e7in i\u00e7in gerekli anahtar de\u011ferlerinin ayarlanmas\u0131<\/li>\n<li>Bu taray\u0131c\u0131lar\u0131n g\u00fcncellenmesi i\u00e7in gerekli eklenti dosyalar\u0131n\u0131n olu\u015fturulmas\u0131<\/li>\n<\/ul>\n<p>Eklenti dosyas\u0131\u00a0<b>.crx<\/b>\u00a0uzant\u0131l\u0131dr. Eklenti dosyas\u0131 a\u00e7\u0131larak incelendi\u011finde as\u0131l zararl\u0131 aktiviteleri ger\u00e7ekle\u015ftiren JavaScript kodlar\u0131na eri\u015filmektedir. Exe uzant\u0131l\u0131 dosyada kullan\u0131lan string ifadelerin ve yaz\u0131lan JS kodlar\u0131nda kullan\u0131lan de\u011fi\u015fken isimlerinin ve fonksiyonlar\u0131n T\u00fcrk\u00e7e oldu\u011fu dikkat \u00e7ekmektedir. Taray\u0131c\u0131lara eklentiler ekleyen bir video player program\u0131n\u0131n \u015fablon olarak al\u0131n\u0131p \u00fczerinde yap\u0131lan g\u00fcncellemelerle zararl\u0131 yaz\u0131l\u0131m\u0131n olu\u015fturuldu\u011fu d\u00fc\u015f\u00fcn\u00fclmektedir.<\/p>\n<p>JavaScript kodlar\u0131 incelendi\u011finde elde edilen \u00f6nemli bulgular \u015fu \u015fekildedir:<\/p>\n<ul>\n<li>\u00c7al\u0131\u015ft\u0131r\u0131labilir dosya \u00e7al\u0131\u015ft\u0131ktan sonra chrome&#8217;u kapatmakta ve ilk a\u00e7\u0131l\u0131\u015fta\u00a0<b>&#8220;player.crx&#8221;\u00a0<\/b>eklentisi ile g\u00fcncellenmektedir. Eklenti i\u00e7erisindeki kodun ise sadece ilk \u00e7al\u0131\u015fmada t\u00fcm chrome eklentileri kald\u0131rd\u0131\u011f\u0131 g\u00f6r\u00fclm\u00fc\u015ft\u00fcr. Bu kod par\u00e7as\u0131\u00a0<b>\u015eekil 7&#8242;<\/b>de g\u00f6r\u00fclmektedir.<\/li>\n<\/ul>\n<div><img loading=\"lazy\" decoding=\"async\" title=\"7.png\" alt=\"7.png\" src=\"http:\/\/www.bilgiguvenligi.gov.tr\/images\/stories\/ocal\/kilim\/7.png\" width=\"361\" height=\"249\" \/><\/div>\n<p>\u015eekil 7 Taray\u0131c\u0131 Eklentilerini Kald\u0131ran Kod Par\u00e7as\u0131<\/p>\n<p>&nbsp;<\/p>\n<p>Ekte zararl\u0131 yaz\u0131l\u0131m\u0131n yeteneklerini anlatan fonksiyon listesi verilmektedir. Bununla birlikte en \u00f6nemli fonksiyonlar ve ama\u00e7lar\u0131 \u015fu \u015fekildedir:<\/p>\n<ul>\n<li><b>function tokenGonder(token,user) :<\/b>\u00a0Bu fonksiyon,\u00a0<b>&#8220;http:\/\/www.70milyon.net\/kaydet.php&#8221;<\/b>\u00a0\u00fczerinden ki\u015finin<b>&#8220;token&#8221;<\/b>\u00a0bilgisini kaydeder. Yani zararl\u0131 yaz\u0131l\u0131m bu fonksiyon sayesinde bula\u015ft\u0131\u011f\u0131 kullan\u0131c\u0131lar\u0131 kay\u0131t alt\u0131na almaktad\u0131r.<\/li>\n<li><b>function videogonder(hakkinda,isim,resim,token,id)<\/b>,\u00a0<b>function fotogonder(token)<\/b>\u00a0ve\u00a0<b>function postgonder(token,kisi)<\/b>\u00a0 fonksiyonlar\u0131 zararl\u0131 yaz\u0131l\u0131m\u0131n kendini yaymak i\u00e7in olu\u015fturdu\u011fu iletileri haz\u0131rlar ve yay\u0131nlar.<\/li>\n<li><b>function begenigetir(token,kisi)<\/b>\u00a0fonksiyonu ile kurban\u0131n \u00e7e\u015fitli sayfalar\u0131 be\u011fenmesi i\u00e7in http talepleri haz\u0131rlar.<\/li>\n<\/ul>\n<h2>Tavsiyeler<\/h2>\n<p>Sisteme bula\u015f\u0131p bula\u015fmad\u0131\u011f\u0131n\u0131 anlamak i\u00e7in en basit y\u00f6ntem\u00a0<b>&#8220;C:\\ProgramData\\VideoPlayer&#8221;<\/b>\u00a0klas\u00f6r\u00fcn\u00fcn ve alt\u0131nda bulunan dosyalar\u0131n\u0131n var olup olmad\u0131\u011f\u0131na bakmakt\u0131r.<\/p>\n<p>Sistemden temizlemek i\u00e7in:<\/p>\n<ul>\n<li>Chrome ve yandex taray\u0131c\u0131lar\u0131 kald\u0131r\u0131lmal\u0131,<\/li>\n<li><b>&#8220;C:\\ProgramData\\VideoPlayer &#8220;<\/b>klas\u00f6r\u00fc sistemden silinmeli,<\/li>\n<li>\u015eu anahtar de\u011ferleri kald\u0131r\u0131lmal\u0131d\u0131r:<\/li>\n<\/ul>\n<blockquote><p>HKLM\\SOFTWARE\\Policies\\Google\\Chrome\\ExtensionInstallForcelist\\1: &#8220;hkfmnabobennlihmnmkiplpinbdkppdp;C:\\ProgramData\\VideoPlayer\\update.xml&#8221;<\/p>\n<p>HKLM\\SOFTWARE\\Policies\\YandexBrowser\\ExtensionInstallForcelist\\1: &#8220;hkfmnabobennlihmnmkiplpinbdkppdp;C:\\ProgramData\\VideoPlayer\\update.xml&#8221;<\/p><\/blockquote>\n<ul>\n<li>Bu i\u015flemlerden sonra chrome ve yandex taray\u0131c\u0131lar yeniden kurulabilir.<\/li>\n<\/ul>\n<p>Bu zararl\u0131 yaz\u0131l\u0131m sadece kurban\u0131n sosyal medya hesaplar\u0131 \u00fczerinde etkili olmaktad\u0131r. Kurban\u0131n hesab\u0131 \u00fczerinden \u00e7e\u015fitli iletiler yay\u0131nlamakta, \u00e7e\u015fitli sayfalar be\u011fenmekte ve en \u00f6nemlisi kurban\u0131n hesab\u0131 \u00fczerinden yay\u0131lmaktad\u0131r.<\/p>\n<p>Kilim zararl\u0131 yaz\u0131l\u0131m\u0131, yay\u0131lmak i\u00e7in sosyal medyay\u0131 kullanmakta ve motivasyon unsuru olarak reklam gelirini hedeflemektedir. Sosyal medya, zararl\u0131 yaz\u0131l\u0131mlar\u0131n yay\u0131lmak i\u00e7in kulland\u0131\u011f\u0131 ve g\u00fcn ge\u00e7tik\u00e7e de daha \u00e7ok kullanacaklar\u0131 bir mecrad\u0131r.\u00a0 Etkileri hen\u00fcz sosyal medya ile s\u0131n\u0131rl\u0131 olsa da zamanla kazanacaklar\u0131 farkl\u0131 yetenekler ile daha fazla zarar vermeleri beklenmektedir. \u0130lerleyen g\u00fcnlerde yay\u0131lmak i\u00e7in sosyal medya hesaplar\u0131n\u0131 kullanan fakat zararl\u0131 aktivitelerini \u00e7e\u015fitlendiren yaz\u0131l\u0131mlarla kar\u015f\u0131la\u015f\u0131lmas\u0131 beklenmektedir. Kilim yaz\u0131l\u0131m\u0131n\u0131n yay\u0131lmak i\u00e7in sosyal medyay\u0131 kullanma yetene\u011fine, zararl\u0131 aktivite olarak kurban\u0131n aktif internet bankac\u0131l\u0131k oturumunu kullanmas\u0131 yetene\u011fini ekledi\u011fini d\u00fc\u015f\u00fcnmek \u00fcrk\u00fct\u00fcc\u00fc olmaktad\u0131r. Son kullan\u0131c\u0131lar\u0131n mail veya sosyal medya ayr\u0131m\u0131 olmadan g\u00fcvenmedikleri linklere t\u0131klamamalar\u0131, g\u00fcvenmedikleri programlar\u0131 \u00e7al\u0131\u015ft\u0131rmamalar\u0131 \u00f6nem arz etmektedir.<\/p>\n<h2>EK- Zararl\u0131 JS fonksiyonlar\u0131 ve i\u015flevleri<\/h2>\n<p><b>function videogonder(hakkinda,isim,resim,token,id):<\/b>\u00a0&#8220;token&#8221; ve &#8220;id&#8221; de\u011ferleri vas\u0131tas\u0131 ile facebook&#8217;ta kullan\u0131c\u0131n\u0131n hesab\u0131 \u00fczerinden video bilgilerini yay\u0131n yapar.<\/p>\n<p><b>function videogetir(token,tokenSonuc):<\/b>\u00a0&#8220;70milyon.net\/video.php&#8221; sitesinden video bilgilerini indirir.\u00a0 Bu i\u015flemden sonra videogonder fonkisyonunu \u00e7a\u011f\u0131r\u0131r.<\/p>\n<p><b>function postgetir(token,tokenSonuc):<\/b>\u00a0&#8220;70milyon.net\/post.php&#8221; sitesinden post bilgilerini indirir.\u00a0 Bu i\u015flemden sonra postgonder fonkisyonunu \u00e7a\u011f\u0131r\u0131r.<\/p>\n<p><b>function fotogetir(token): &#8220;<\/b>70milyon.net\/photo.php&#8221; sitesinden foto bilgilerini indirir.\u00a0 Bu i\u015flemden sonra fotogonder fonkisyonunu \u00e7a\u011f\u0131r\u0131r.<\/p>\n<p><b>function fotogonder(token):<\/b>\u00a0&#8220;token&#8221; de\u011feri vas\u0131tas\u0131 ile facebook&#8217;ta kullan\u0131c\u0131n\u0131n hesab\u0131 \u00fczerinden foto bilgilerini yay\u0131n yapar.<\/p>\n<p><b>function convertToASCII(metin):<\/b>\u00a0T\u00fcrk\u00e7e karakter uyumsuzluklar\u0131n\u0131 d\u00fczeltmek i\u00e7in<\/p>\n<p><b>function arkadaslar(token):<\/b>\u00a0Facebook&#8217;tan &#8220;token&#8221; bilgisini kullanarak ki\u015finin arkada\u015flar\u0131n\u0131 \u00e7eker.<\/p>\n<p><b>function arkadaspost(token):<\/b>\u00a0\u0130\u00e7i bo\u015f fonksiyon. Kodu yazan ki\u015fi taraf\u0131ndan yaz\u0131lmas\u0131 planlan\u0131p yaz\u0131lmad\u0131\u011f\u0131 d\u00fc\u015f\u00fcn\u00fclmektedir.<\/p>\n<p><b>function postgonder(token,kisi):<\/b>\u00a0&#8220;token&#8221; bilgisi kullan\u0131larak facebook&#8217;ta verilen ki\u015fi i\u00e7in haz\u0131rlanan post yay\u0131nlan\u0131r.<\/p>\n<p><b>function begenigetir(token,kisi):<\/b>\u00a0&#8220;70milyon.net\/likes.php&#8221; sitesinden getirdi\u011fi be\u011feni listesi i\u00e7in ki\u015finin token&#8217;\u0131 ile birlikte limitKontrol fonkisyonunu \u00e7a\u011f\u0131r\u0131r.<\/p>\n<p><b>function limitKontrol(token,sayfa):<\/b>\u00a0Ki\u015finin token&#8217;\u0131n\u0131 kullanarak facebook \u00fczerinden ilgili sayfan\u0131n like say\u0131s\u0131n\u0131 kontrol eder. \u0130stedi\u011fi limite ula\u015fmam\u0131\u015f ise begeniKontrol fonksiyonunu \u00e7a\u011f\u0131r\u0131r.<\/p>\n<p><b>function begeniKontrol(token,sayfa) :<\/b>\u00a0\u0130stedi\u011fi like limitine ula\u015fmam\u0131\u015f olan sayfaya eri\u015filip eri\u015filmedi\u011fini konrol eder ve sayfaBegen fonksiyonunu \u00e7a\u011f\u0131r\u0131r.<\/p>\n<p><b>function sayfaBegen(token,sayfa):<\/b>\u00a0Ki\u015finin token&#8217;\u0131 kullan\u0131larak ilgili sayfan\u0131n be\u011fenilmesi i\u00e7in bir GET talebi haz\u0131rlan\u0131r ve ki\u015finin ilgili facebook sayfas\u0131 be\u011fenilmesi sa\u011flan\u0131r.<\/p>\n<p><b>function tokenGonder(token,user):<\/b>\u00a0Bu fonksiyon, &#8220;http:\/\/www.70milyon.net\/kaydet.php&#8221; \u00fczerinden ki\u015finin &#8220;token&#8221; bilgisini kaydeder.<\/p>\n<p><b>function tokenKontrol(token):<\/b>\u00a0\u0130lgili ki\u015finin token&#8217;\u0131 \u00fczerinden kontrollerle t\u00fcm videoGetir,fotoGetir ve postGetir gibi fonksiyonlar\u0131 \u00e7a\u011f\u0131rmaktad\u0131r.<\/p>\n<p><b>function rastgele(uzunluk):<\/b>\u00a0Verilen uzunlukta rastgele bir string \u00fcretir.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"http:\/\/www.bilgiguvenligi.gov.tr\/zararli-yazilimlar\/kilim-zararli-yazilimi.html\" title=\"kaynak\">Kaynak<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sosyal medya kullan\u0131m\u0131n\u0131n artmas\u0131yla e-posta kutular\u0131n\u0131 dolduran spam maillerin benzerleri art\u0131k sosyal medya hesaplar\u0131nda da yayg\u0131nla\u015fmaya ba\u015flad\u0131. Ayr\u0131ca sosyal medya zararl\u0131 yaz\u0131l\u0131mlar\u0131n yay\u0131lmas\u0131\u00a0 i\u00e7in s\u0131kl\u0131kla kullan\u0131lan bir alan olmaya do\u011fru kay\u0131yor. Son g\u00fcnlerde \u00e7e\u015fitli versiyonlar\u0131n\u0131 g\u00f6rd\u00fc\u011f\u00fcm\u00fcz\u00a0Kilim zararl\u0131 yaz\u0131l\u0131m\u0131\u00a0da yay\u0131lmak i\u00e7in sosyal medyay\u0131 kullanan zararl\u0131 yaz\u0131l\u0131mlardan biri olarak kar\u015f\u0131m\u0131za \u00e7\u0131kmaktad\u0131r. Kilim zararl\u0131 yaz\u0131l\u0131m\u0131n\u0131n dikkat \u00e7eken bir [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":277,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1,15],"tags":[224,459],"class_list":["post-1157","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-genel","category-guvenlik","tag-kilim","tag-virus"],"_links":{"self":[{"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/posts\/1157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1157"}],"version-history":[{"count":0,"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=\/wp\/v2\/posts\/1157\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1157"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.kodcafe.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}