当前位置:网站首页>What are the forms of attack and tampering on the home page of the website
What are the forms of attack and tampering on the home page of the website
2022-04-23 12:34:00 【websinesafe】
Let's take a look at several forms of website hacking , In all the work orders I have handled, it is the customer's problem , Basically, if his website is hacked , This is the 4 In the form of . The first page of its website index.php Be tampered with , the second , Added a third party to his website JS Jump code , The third added a home page file ,index.html, The fourth is the third one 301 Retargeting term . In view of these situations . We . Now let's show you . In fact, it was hard to find yesterday , Because we have dealt with the customers who were hacked before , Then I found a hacked original program file from the local computer , This is a diagnostic kit for the customer , Then I have backed up this diagnostic package to the local , Then I'll pack it online now , Then let's take a look and demonstrate this effect .
After uploading, I unzip it . Drag the file out , After dragging it out , Then let's restore this website now , After restoration , Here we need to compare that with the one under the directory install Delete a file inside , Why delete , Because if you don't delete it , Your website can't be rewritten and installed , Because this file is used to check whether your website has been successfully installed , After deletion , Then let's reinstall .

My database is ACSESS, What we said here just now is that we should have , Security awareness can't be set so simple , Because I used to operate locally before , So often admin, So let's make it a little more complicated , You include the cell phone number here , We need to fill in the real , At that time, your website background will find the password , And including these mailboxes , Fill in the real one . Of course, this is not my email , I'm just saying demonstrate , I tell you to fill in your real email here , Then we log in to the background now .

good , After logging into the background , Then we import in a data of this user , After importing in , Then let's take a look at this website , Can you see , My website looks normal , Can't you see any sign of being hacked , Now let's take a look at , If we go to modify the content , See if there's a problem ? For example . I'll go to the website computer here , This is one of our 5.3.6 An old system version of . We are now 7.0 Words , So why is functionality becoming more and more powerful , Is to support visual editing , Look at an old version of the previous , Relatively speaking , One of its modifications is not very convenient , For example, I would like to modify a content of our home page .
For example, I modify a message in this profile , I'll add one here , Then save , After saving , Then let's take a look . It still works here . Now let me set the priority , Because many users , He may be a priority for his website to access files , The latest visit is this index.html, That may be the case . If you open the home page directly, you will jump to other websites , Because the code I modified contains the jump function .
Next, let's take a look at our website , See if it will have a jump . Did you find out? No, he's jumping now , So basically, one of us was hacked and his one . The forms of expression are basically these . The first is through . Tamper with your index file , The second is that it can add a third party js Adjust the code , The third new homepage file , Second point html, The fourth is what I just demonstrated 301 Retargeting term , So it's basically one of our blackened performance forms , Basically, it's just these . If there is a situation that has been tampered with repeatedly and you can't solve it , You can tell the website vulnerability repair company SINE Seek technical support for security .
版权声明
本文为[websinesafe]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231225471077.html
边栏推荐
- Lesson 25 static member variables of classes
- Idea code formatting plug-in save actions
- 软件测试基础DAY2-用例执行
- 实现一个盒子在父盒子中水平垂直居中的几种“姿势”
- SQLserver怎么插入或更新当天的星期数,bit而不是文本
- Dialogue with Bruce, author of PostgreSQL: "changing careers" is to better move forward
- Luogu p5540 [balkanoi2011] timeismoney | minimum product spanning tree problem solution
- mysql中 innoDB执行过程分析
- Next. JS static data generation and server-side rendering
- Windows2008系统如何切换PHP版本
猜你喜欢

论文解读(CGC)《CGC: Contrastive Graph Clustering for Community Detection and Tracking》

软件测试基础DAY2-用例执行

为什么要有包装类,顺便说一说基本数据类型、包装类、String类该如何转换?

网站首页文件被攻击篡改的形式有哪些

Idea database navigator plug-in

一个平面设计师的异想世界|ONES 人物

On lambda powertools typescript

I changed to a programmer at the age of 31. Now I'm 34. Let me talk about my experience and some feelings

对话PostgreSQL作者Bruce:“转行”是为了更好地前行

How to expand the capacity of the server in the 100 million level traffic architecture? Well written!
随机推荐
Please help me see what this is, mysql5 5. Thanks
How to switch PHP version in Windows 2008 system
How do traditional enterprises cope with digital transformation? These books give you the answer
How do programmers finalize nucleic acid statistics with 130 lines of code
SQL 练习(一)
Pre competition practice of TIANTI competition
Next. JS static data generation and server-side rendering
How does sqlserver insert or update the number of weeks of the day instead of text
解决disagrees about version of symbol device_create
Lesson 23 temporary objects
基于卷积神经网络的遥感影像分类识别系统
一个平面设计师的异想世界|ONES 人物
BUUCTF WEB [BUUCTF 2018]Online Tool
QT draw text
One way ANOVA of SPSS
第二十六课 类的静态成员函数
软件测试基础DAY2-用例执行
Basic software testing Day2 - Case Execution
Pagoda panel command line help tutorial (including resetting password)
XinChaCha Trust SSL Organization Validated