当前位置:网站首页>What are the forms of attack and tampering on the home page of the website
What are the forms of attack and tampering on the home page of the website
2022-04-23 12:34:00 【websinesafe】
Let's take a look at several forms of website hacking , In all the work orders I have handled, it is the customer's problem , Basically, if his website is hacked , This is the 4 In the form of . The first page of its website index.php Be tampered with , the second , Added a third party to his website JS Jump code , The third added a home page file ,index.html, The fourth is the third one 301 Retargeting term . In view of these situations . We . Now let's show you . In fact, it was hard to find yesterday , Because we have dealt with the customers who were hacked before , Then I found a hacked original program file from the local computer , This is a diagnostic kit for the customer , Then I have backed up this diagnostic package to the local , Then I'll pack it online now , Then let's take a look and demonstrate this effect .
After uploading, I unzip it . Drag the file out , After dragging it out , Then let's restore this website now , After restoration , Here we need to compare that with the one under the directory install Delete a file inside , Why delete , Because if you don't delete it , Your website can't be rewritten and installed , Because this file is used to check whether your website has been successfully installed , After deletion , Then let's reinstall .

My database is ACSESS, What we said here just now is that we should have , Security awareness can't be set so simple , Because I used to operate locally before , So often admin, So let's make it a little more complicated , You include the cell phone number here , We need to fill in the real , At that time, your website background will find the password , And including these mailboxes , Fill in the real one . Of course, this is not my email , I'm just saying demonstrate , I tell you to fill in your real email here , Then we log in to the background now .

good , After logging into the background , Then we import in a data of this user , After importing in , Then let's take a look at this website , Can you see , My website looks normal , Can't you see any sign of being hacked , Now let's take a look at , If we go to modify the content , See if there's a problem ? For example . I'll go to the website computer here , This is one of our 5.3.6 An old system version of . We are now 7.0 Words , So why is functionality becoming more and more powerful , Is to support visual editing , Look at an old version of the previous , Relatively speaking , One of its modifications is not very convenient , For example, I would like to modify a content of our home page .
For example, I modify a message in this profile , I'll add one here , Then save , After saving , Then let's take a look . It still works here . Now let me set the priority , Because many users , He may be a priority for his website to access files , The latest visit is this index.html, That may be the case . If you open the home page directly, you will jump to other websites , Because the code I modified contains the jump function .
Next, let's take a look at our website , See if it will have a jump . Did you find out? No, he's jumping now , So basically, one of us was hacked and his one . The forms of expression are basically these . The first is through . Tamper with your index file , The second is that it can add a third party js Adjust the code , The third new homepage file , Second point html, The fourth is what I just demonstrated 301 Retargeting term , So it's basically one of our blackened performance forms , Basically, it's just these . If there is a situation that has been tampered with repeatedly and you can't solve it , You can tell the website vulnerability repair company SINE Seek technical support for security .
版权声明
本文为[websinesafe]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231225471077.html
边栏推荐
- 实现一个盒子在父盒子中水平垂直居中的几种“姿势”
- On lambda powertools typescript
- In idea Solution to the problem of garbled code in Chinese display of properties file
- Zero trust in network information security
- BUUCTF WEB [GXYCTF2019]禁止套娃
- 万事有你 未来可期 | ONES 2022校园招聘正式开启
- How much does software testing help reduce program bugs?
- 对话PostgreSQL作者Bruce:“转行”是为了更好地前行
- Uni app native app local packaging integrated Aurora push (jg-jpush) detailed tutorial
- QT one process runs another
猜你喜欢
随机推荐
php生成json处理中文
Intelligent multi line elastic cloud adds independent IP address. How to realize multi line function?
box-sizing
BUUCTF WEB [BJDCTF2020]The mystery of ip
第二十三课 临时对象
A graphic designer's fantasy world | ones characters
QT interprocess communication
C set Logo Icon and shortcut icon
MySQL function - recursive function
Pagoda panel command line help tutorial (including resetting password)
[unity note] basic lighting in l4unity
How to switch PHP version in Windows 2008 system
Basic software testing Day2 - Case Execution
Web17——EL与JSTL的使用
Why is there a wrapper class? By the way, how to convert basic data types, wrapper classes and string classes?
One way ANOVA of SPSS
Hard core parsing promise object (do you know these seven common APIs and seven key questions?)
对称加密、证书加密
Qt进程间通信
论文解读(CGC)《CGC: Contrastive Graph Clustering for Community Detection and Tracking》








