Linux?в???php??????????
???????????? ???????[ 2015/11/30 11:52:30 ] ??????????????
????php?????????????????php???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????λ?????Щ????php???????????????????y??ɡ?
???????denyhost?????SSH???????????尲??????ο???denyhost???SSH??????????????linux??????
????1????????????Щ????????????i???
????????:
????????????
????# chattr +i /etc/passwd
????# chattr +i /etc/group
????# chattr +i /etc/shadow
????# chattr +i /etc/gshadow
????# chattr +i /etc/ssh/sshd_config
????2??nginx??php????
????(1)??discuz/attachments??uchome/attachment??ucenter/data/tmp??????????????????php????centos+nginx???????????????????????????webshell???????
??????nginx????????????????
????????????
????location ~ .*??.(php|php5)?$ {
????…….
????#——————————————
????rewrite ^/(uc??_client|templates|include|plugins|admin|attachments|images|
????forumdata)/.*??.(php|php5)?$ /50x.php last;
????#——————————————-
????}
????(2)???php.ini
?????????disable_functions
???????????=???????
????????????
????exec??system??passthru??error_log??ini_alter??dl??openlog??syslog??readlink??symlink??
????link??leak??fsockopen??proc_open??
????popepassthru??chroot??scandir??chgrp??chown??escapeshellcmd??escapeshellarg??
????shell_exec??proc_get_status??popen
??????????????php??????е????
????(3)???Щ?????????????????????i???????????1?????????????????????
????3????β?????????е?php???
????PHP???????????????????eval??base64_decode???????????????????????
????????????
????find /var/www/ -type f -name “*.php” | xargs grep “eval(” |more
??????????????????????????????????
????????????
????eval(base64_decode(…………..));
???????????????????windows???????????????????webshell?????????????php??????????php?????????????ú???????????????????????????????????????????Щ????????????????
??????
???·???
??????????????????
2023/3/23 14:23:39???д?ò??????????
2023/3/22 16:17:39????????????????????Щ??
2022/6/14 16:14:27??????????????????????????
2021/10/18 15:37:44???????????????
2021/9/17 15:19:29???·???????·
2021/9/14 15:42:25?????????????
2021/5/28 17:25:47??????APP??????????
2021/5/8 17:01:11