当前位置:网站首页>What are the forms of attack and tampering on the home page of the website
What are the forms of attack and tampering on the home page of the website
2022-04-23 12:34:00 【websinesafe】
Let's take a look at several forms of website hacking , In all the work orders I have handled, it is the customer's problem , Basically, if his website is hacked , This is the 4 In the form of . The first page of its website index.php Be tampered with , the second , Added a third party to his website JS Jump code , The third added a home page file ,index.html, The fourth is the third one 301 Retargeting term . In view of these situations . We . Now let's show you . In fact, it was hard to find yesterday , Because we have dealt with the customers who were hacked before , Then I found a hacked original program file from the local computer , This is a diagnostic kit for the customer , Then I have backed up this diagnostic package to the local , Then I'll pack it online now , Then let's take a look and demonstrate this effect .
After uploading, I unzip it . Drag the file out , After dragging it out , Then let's restore this website now , After restoration , Here we need to compare that with the one under the directory install Delete a file inside , Why delete , Because if you don't delete it , Your website can't be rewritten and installed , Because this file is used to check whether your website has been successfully installed , After deletion , Then let's reinstall .
My database is ACSESS, What we said here just now is that we should have , Security awareness can't be set so simple , Because I used to operate locally before , So often admin, So let's make it a little more complicated , You include the cell phone number here , We need to fill in the real , At that time, your website background will find the password , And including these mailboxes , Fill in the real one . Of course, this is not my email , I'm just saying demonstrate , I tell you to fill in your real email here , Then we log in to the background now .
good , After logging into the background , Then we import in a data of this user , After importing in , Then let's take a look at this website , Can you see , My website looks normal , Can't you see any sign of being hacked , Now let's take a look at , If we go to modify the content , See if there's a problem ? For example . I'll go to the website computer here , This is one of our 5.3.6 An old system version of . We are now 7.0 Words , So why is functionality becoming more and more powerful , Is to support visual editing , Look at an old version of the previous , Relatively speaking , One of its modifications is not very convenient , For example, I would like to modify a content of our home page .
For example, I modify a message in this profile , I'll add one here , Then save , After saving , Then let's take a look . It still works here . Now let me set the priority , Because many users , He may be a priority for his website to access files , The latest visit is this index.html, That may be the case . If you open the home page directly, you will jump to other websites , Because the code I modified contains the jump function .
Next, let's take a look at our website , See if it will have a jump . Did you find out? No, he's jumping now , So basically, one of us was hacked and his one . The forms of expression are basically these . The first is through . Tamper with your index file , The second is that it can add a third party js Adjust the code , The third new homepage file , Second point html, The fourth is what I just demonstrated 301 Retargeting term , So it's basically one of our blackened performance forms , Basically, it's just these . If there is a situation that has been tampered with repeatedly and you can't solve it , You can tell the website vulnerability repair company SINE Seek technical support for security .
版权声明
本文为[websinesafe]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231225471077.html
边栏推荐
猜你喜欢
【每日一题】棋盘问题
SSL证书退款说明
亿级流量架构,服务器如何扩容?写得太好了!
In idea Solution to the problem of garbled code in Chinese display of properties file
Metalama简介4.使用Fabric操作项目或命名空间
Idea database navigator plug-in
Why is there a wrapper class? By the way, how to convert basic data types, wrapper classes and string classes?
一个平面设计师的异想世界|ONES 人物
The database navigator uses the default MySQL connection prompt: the server time zone value 'Ö Ð¹ ú±ê ×¼ ʱ ¼ ä’ is unrecognized or repres
C set Logo Icon and shortcut icon
随机推荐
S2-062 remote command execution vulnerability recurrence (cve-2021-31805)
BUUCTF WEB [GXYCTF2019]禁止套娃
NPDP|产品经理如何做到不会被程序员排斥?
uni-app 原生APP-本地打包集成极光推送(JG-JPUSH)详细教程
Labels and paths
Symmetric encryption, certificate encryption
box-sizing
QT draw image
SSL证书退款说明
万事有你 未来可期 | ONES 2022校园招聘正式开启
Lesson 26 static member functions of classes
Uni app native app cloud packaging integrated Aurora push (jg-jpush) detailed tutorial
Idea code formatting plug-in save actions
Fastjson 2 来了,性能继续提升,还能再战十年
解锁OpenHarmony技术日!年度盛会,即将揭幕!
第二十五课 类的静态成员变量
【微信小程序】z-index失效
worder字体网页字体对照表
bert-base-chinese下载(智取)
Realize several "Postures" in which a box is horizontally and vertically centered in the parent box