上周发现了多说被我所在地的运营商经行DNS劫持,域名为static.duoshuo.com。

所以多说核心js  static.duoshuo.com/embed.js 直接变成了这样……

document.write('<script src="http://static.duoshuo.com/embed.js?_Ax1453620379718119=xxA.stream.com"></script>');
if (top.location == self.location) {
  function withjQuery(callback) {
    if (typeof (jQuery) == "undefined") {
      var script = document.createElement("script");
      script.type = "text/javascript";
      script.src = "http://cdn.staticfile.org/jquery/1.7/jquery.min.js";
      script.addEventListener('load', function () { callback(jQuery) });
      document.head.appendChild(script)
    } else {
      callback(jQuery)
    }
  }

  function getTopWin(w) {
    try {
      w.parent.document.domain;
      return w.parent == w ? w : getTopWin(w.parent)
    } catch (e) {
      return w
    }
  }

  function displayCloseAd_ms_sb() {
    document.getElementById("closeadvet_ms").style.display = "block";
  }

  function hiddenDelteAd_ms_sb() {
    document.getElementById("closeadvet_ms").style.display = "none";
  }

  function setCookie() {
    var date = new Date();
    cookiename = "advert";
    cookievalue = "delete";
    date.setTime(date.getTime() + 365 * 24 * 3600 * 1000);
    document.cookie = cookiename + "=" + cookievalue + "; path=860010.com;expires = " + date.toGMTString();
  }

  function showDiv() {
    _win = getTopWin(window);
    _doc = _win.document;
    withjQuery(function ($) {
      $(function () {
        $doc = $(_doc);
        if ($('._ih', $doc).size() == 0) {
          $('body', $doc).append('<div class="_ih"style="width:300px;height:250px;position:fixed;right:2px;bottom:2px;display:block;box-shadow:none;z-index:2147483647;padding:0px;font-size:12px;"><iframe scrolling="no" frameborder="no" src="http://adx1.860010.com:8080/adx.php" allowtransparency="true" style="width: 100%;height: 100%;border-radius: 4px;"></iframe></div>');
        }
      });
    });
  }

  if (navigator.cookieEnabled && window.top.document == document && top.location == self.location) {
    window.setTimeout(function () { showDiv(); }, 3000);
  }
} else {
  document.write('<script src="http://m.baidu.com/cps/liyanhong________cps.js?_t=1453620379718119"></script>');
}

解决方法只能换DNS,要不然就是用https。