ããã«ã¡ã¯haberUserïŒ
ãã®è©±ã¯çŽ2ãæåã«å§ãŸããŸããããã¹ãã£ã³ã°ãµãŒãã¹ãæäŸããŠãããç§ã®è¯ãå人ã§ããAlexanderã¯ããŠã€ã«ã¹å¯Ÿçãåãããã¹ãŠã®ä»®æ³ãã·ã³ã®æ¬¡ã®ã¹ãã£ã³äžã«ãç§ã®ãµã€ãã®ã«ãŒããã£ã¬ã¯ããªã«ããçããã.jsãã¡ã€ã«ãæ€åºããVDSã§æäŸããŠããŸããããããæäŸããŸããã§ããå€...ãããããã¹ãã£ã³ã°ç®¡çè ã¯ããã«å¿é ã«ãªããšæããŸãã
åã®æ³äººã«ãã£ãŠç§ã®ãµã€ãããããã¯ãããŠãããããã2ãæåŸã«ãã¹ãŠãçµäºããŸããã
ããã¹ãã«ãããšãç§ã¯ããªãã«äŒãããïŒ
èŠçŽïŒ
ãããã³ã°ããããŠèå³æ·±ãããšãVDSã§èµ·ããå§ããŸãããæ°å人ã®åä¿¡è ãžã®ã¹ãã ã¡ãŒã«éä¿¡ãçãããã¹ã¯ãªããã®ã€ã³ã¹ããŒã«ãã¡ã€ã³ãµã€ãã®ã«ãŒãã§ã®å¥åŠãªãã¡ã€ã«ã®åºçŸã ççŽã«èšã£ãŠ-ããã¯æãã£ã...ããããããã¯ç§ãéãç Žã£ãããã ïŒã
ãšã³ããªãŒïŒ
ç§ã¯ãã®èšäºãããŒããšããŠãæžããŠããã®ã§ãåé¡ãåçºããå Žåã«æ»ãããšãã§ããŸãã ãã«ãŠã§ã¢ãšã®æŠãã®ããã»ã¹ã«é¢å¿ãããã®ã¯ã以äžã§ãã ãããã£ãŠãå®çšçãªã¢ããã€ã¹ãå¿ èŠãšããå€ãã®æçŽããããŸã-æåŸãŸã§ã¹ã¯ããŒã«ããŠãã ããã
Debian Wheezyã§ãã¹ãããŠããèªåã®ãµã€ããã©ã®ããã«ãããã³ã°ããããWordPressã®ãµã€ããããã¯ãããããå¿ èŠãšããŠãã人
ã©ã®ãããªåé¡ã«ééããã©ã®ããã«èªèããŸãããïŒ
èªåã®ãµã€ãã§åãjsã¹ã¯ãªãããèŠã€ããããªãã£ãçŽåŸã«èœã¡çããŸããã ä»ãç§ã¯ãããèŽåœçãªééãã§ããããšãç解ããŠããŸãã
ç§ã®ãµã€ãã¯Debian Wheezyã§å転ãã i-mscpãã¹ãã£ã³ã°ã³ã³ãããŒã«ããã«ïŒispcpãµã¯ã»ãµïŒãã€ã³ã¹ããŒã«ãããŠããŸããå人çšã®ãµã€ããããã€ããããŸãããããã£ãŠãç§ã¯ç®¡çè ã§ãããVDSãžã®ã¢ã¯ã»ã¹ã誰ã«ãèš±å¯ããŸããã
ãã¹ãŠãããŸãã»ããã¢ãããããã®ã§ãã»ãã¥ãªãã£ã«ã€ããŠã¯å¿é ãããã«ãŒãsshã䜿çšããŠããµãŒãããŒãã£ã®ã©ã€ã¿ãŒã®ã¹ã¯ãªãããå®éšçšã«ãµã€ãã«é 眮ããŸããã WordPressãµã€ããšãã®ããã®ãã©ã°ã€ã³ã¯ãä¿¡ããããªãã»ã©ã®éã§ãã ç§ã¯æéãããããŸããã§ããã確èªããã«ã¯ã ãã®ãµã€ãã¯æé·ããæ°ãããã©ã°ã€ã³ãšã¹ã¯ãªããã§è£å ãããŸãã...
ãªãããããã¹ãŠã®ãã©ã°ã€ã³\æ¡åŒµæ©èœ\ã¹ã¯ãªãããå¿ èŠãªã®ã§ããïŒ
ç§ã®å人ã¯ãã€ãŠç§ã«å°ããŸããã ããœãŒã·ã£ã«åãããããµã€ããå¿ èŠã ãšçããŸãããããŸããŸãªã¹ã¯ãªãããè©Šãããããããµã€ãã®æ©èœãšå€èŠ³ã«ã©ã®ããã«åœ±é¿ãããã確èªããããšæããŸãã ç§ã¯ãã€ãäœããæ¹åããããšããŸãã...
åé¡çªå·2
æåã®è åšã«å¯Ÿå¿ããªãã£ãã®ã¯2é±éåŸã§ãã 次ã®åé¡ããããŸããã
ä»äºäžã«åº§ã£ãŠãããšãçªç¶ããã®ãããªã¡ãã»ãŒãžãé ä¿¡ãããªãã£ããšãããã¹ããã£ãã¯ã¹ã¡ãŒã«ãµãŒããŒããã®ã¡ãã»ãŒãžããGmailã¡ãŒã«ã®ã¹ãã ãã©ã«ããŒã«èœã¡å§ããŸãã 1ç§ãããçŽ50件ã®é ä¿¡äžèœã¡ãã»ãŒãž ã
ç§ã¯ãµãŒããŒã«è¡ãããã°ãèŠãŸãïŒ
tail -f /var/log/mail.log
ãããŠãã¡ãã»ãŒãžãé²é³ããã¹ããŒãã¯ä¿¡ããããªãã»ã©éãã®ã§ãã¡ãŒã©ãŒãåæ¢ããŸãã
/etc/init.d/postfix stop
è¿·æã¡ãŒã«ãæ¢ãŸããŸãããã¡ãŒã«ã®éä¿¡æ¹æ³ã確èªããããšããŠããŸãããçµéšã足ããªããããäœãç解ããŠããªãã®ã§ããã
çµéšçã«ãã¡ã€ã³ïŒsysrtfm dot ruïŒãµã€ãã®ã«ãŒããã£ã¬ã¯ããªã®ååãå€æŽãããããã¹ãã£ã³ã°ã³ã³ãããŒã«ããã«ã§ãã¡ã€ã³ããããã¯ãããšãã¹ãã ãåæ¢ããããšãããããŸãã
圌ããã¡ã€ã³ãµã€ããå£ãããšããèªèããã©ã®ããã«ïŒ
念ã®ãããã¡ãŒã©ãŒã®ãã¥ãŒå šäœãã¯ãªã¢ããŸãã
ïŒã10,000æååé€ïŒpostsuper -d ALL
8æéãå·Šç¿Œã¹ã¯ãªããã®ååšã«ã€ããŠãµã€ãã®ãã£ã¬ã¯ããªãæã§ãã§ãã¯ãããã¹ãŠã®ãã©ã°ã€ã³ãç¡å¹ã«ããŠãã¡ãŒã©ãŒãèµ·åãããã¥ãŒã¹ã¬ã¿ãŒãå床åãåããŸããïŒæ²ããé¡
ãã®åŸãå¶ç¶ããµã€ãã®ã«ãŒããã£ã¬ã¯ããªã§ããã¡ã€ã«/css/sys0972500-1.phpã®ããcssãã©ã«ããŒãèŠã€ããŸããã ç§ã®CMSã®ããããã®æ§é ãç¥ã£ãŠããã°ããã®ãããªãã¡ã€ã«ã¯ååšãã¹ãã§ã¯ãªãããšãç解ããŠããŸãã å æã®ããã¯ã¢ãããããŠã³ããŒãããŠè§£åããŸãããããã¡ã€ã«ã絶察ã«ååšããªãã¯ãã§ãã 圌ã¯ã©ããã£ãŠããã«è¡ããŸãããïŒ ãã®è³ªåã«ã¯ãŸã åçããããŸããããä»ã®ãã¡ã€ã«ãšåãæš©å©ããããŸãã
Apacheãã°ãèªã¿åããŸãã
tail -f /var/log/apache2/sysrtfm.ru.log
ãããèŠãŠãã ããïŒ
"POST /css/sys0972500-1.php HTTP/1.1" 404 55665 "-" "-"
ã»ãŒ30ç§ããšã
ã©ããã誰ãããã®ã¹ã¯ãªãããé ãããå®è¡ããŠããããã¥ãŒã¹ã¬ã¿ãŒãéå§ããŠããããã§ãã
IPãšãã¹ãŠããããã¯ããããã«èŠããŸãããã»ãšãã©åãããã«å€æŽãããŸãã ãã¡ã€ã«ãå«ããã£ã¬ã¯ããªãåé€ããã¡ãŒã«éä¿¡ãåæ¢ããŸããã äºå®äžããŸãã¯å察ãåãå ¥ããªã ãããã³ã°ãã©ã®ããã«çºçããã®ãç解ã§ããŸããã§ããããåé¡ããã®ãŸãŸæ®ããŸããã ã«ãŒããã¹ã¯ãŒããããè€éãªãã®ã«å€æŽãã䜿çšããªããªã£ããã©ã°ã€ã³ãšã¹ã¯ãªãããç¡å¹ã«ããŸããã
次ã«çºèŠãããåé¡ã¯ãWordPressãšã³ãžã³ãéåžžã«äººæ°ãããã誰ãããããç ŽãããšããŠããããšã§ãã Apache2ã®ãã°ãèªãã åŸã管çããã«ã®ãã°ã€ã³ãã©ãŒã ã«ãã«ãŒããã©ãŒã¹ã®ãã°ã€ã³æ»æã絶ãéãªãçºçããŠããããšã«æ°ä»ããŸããã ããããä»¥æ¥ ç§ã¯ãããé·ãéçã£ãŠããŸããããã°ã€ã³ã«äœåºŠã倱æããåŸããŠãŒã¶ãŒããã¯ãã©ã°ã€ã³ãã€ã³ã¹ããŒã«ããŠããŸããïŒãŠãŒã¶ãŒããã«ãŒïŒã
tail -f /var/log/apache2/sysrtfm.ru.log
ãããåç §ããŠãã ããïŒ
"POST /wp-login.php HTTP/1.0" 200 6891 "http://sysrtfm.ru/wp-login.php" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.8.131 Version/11.10"
éåžžã«é«ãé »åºŠã§ã ãã®æ»ææ¹æ³ã«å¯Ÿããä¿è·ã¯ãå¥ã®è°è«ã®ãããã¯ã§ãã ããã§ã¯ããã°ã€ã³è©Šè¡ãæ°åè¡ã£ãåŸãIPã¢ãã¬ã¹ã§æ»æè ããããã¯ãããã©ã°ã€ã³ãè¿œå ããŸããã
第3å·
ã¹ãã ãå·Šç¿Œã¹ã¯ãªãããªãã§3é±éãçµéããŸããã
ãã°ã確èªããããã«VDSã«è¡ããåããã¡ã€ã«ããµã€ãã®ã«ãŒãã«ããããšãçºèŠãããã¥ãŒã¹ã¬ã¿ãŒãåã³èµ·åãããŸããããã¯ããã«å°ããããªã¥ãŒã ã§...ç§ã¯é ãã€ãã¿ãŸããã
ç§ã¯ã¢ã³ããŠã€ã«ã¹ã§ãµã€ãããªã³ã©ã€ã³ã§ã¯ããŒã«ãå§ããŠããŸãïŒ
- vms.drweb.com/online-ãã¹ãŠåé¡ãããŸãã
- 2ip.ru/site-virus-scaner-ãã¹ãŠåé¡ãããŸãã
- www.virustotal.com/en/#url-ãã¹ãŠåé¡ãããŸãã
- antivirus -alarm.ru-ãã¹ãŠãOK
- gimpel.comss.ru-ãã¹ãŠã¯å€§äžå€«ã§ã
ãã©ãŒã©ã ãæ€çŽ¢ããŠãçµæã¯åŸãããŸããã ããããç§ã¯å€ãã®å©ãã«ãªã£ãèšäºãèŠã€ããŸããïŒãããŸã§ãç§ã¯ãããéãããŸãŸã®ã¿ããä¿æããŸãã
ã©ã®ã¹ã¯ãªããããã¥ãŒã¹ã¬ã¿ãŒãèµ·åããããç解ããããã«ãã¡ãŒã«ãµãŒããŒã®æ¡åŒµãã°ãæå¹ã«ããããã»ã¹ã«ã€ããŠèª¬æããŸãã
ãã¿ãã¬ã®äžã®èšäºã®ãœãŒã¹ã³ãŒã
ãã®ãããDebianããŒã¹ã®ãµãŒããŒããããŸãã
ãµãŒããŒããã®éä¿¡ã¹ãã ã«é¢ããèŠæ ã
ã¿ã¹ã¯ïŒãã£ã¹ããããã¥ãŒãã¯ãªã¢ããçç±ãèŠã€ããŸãã
解決çïŒãã¡ãããå€ãã®ãªãã·ã§ã³ããããŸãã ãããã®1ã€ãæ€èšããŠãã ããã
1. SSHçµç±ã§æ¥ç¶ããã¡ãã»ãŒãžãã¥ãŒã確èªããŸãã
mailq
ã¯ããããããã®æçŽããããŸãã
2.ã¡ãŒã«ãµãŒããŒãç¡å¹ã«ããŸãïŒåŸçœ®ã³ã¹ãïŒ
/etc/init.d/postfix stop
3. 25çªç®ã®ããŒãã®æ¥ç¶ã確èªããŸãã
netstat -apn | grep :25
確ç«ãããŠããªãå ŽåãããŒã«ã«ã¡ãŒã«ãµãŒããŒããã€ãã¹ããŠã¡ãŒã«ãéä¿¡ããæªæã®ããã¹ã¯ãªãããä»ããŠã¹ãã ãéä¿¡ãããªãããšãæå³ããŸãã
4.æçŽã®åãã¯ãªã¢ããŸã
EximïŒ
exipick -i | xargs exim -Mrm
åŸçœ®ïŒ
postsuper -d ALL
SendmailïŒ
rm -rf /var/spool/mqueue/*
ãã¡ããããããè¡ãããšãã§ããã°ïŒãã¥ãŒã«ã¯å®éã®ãŠãŒã¶ãŒãžã®å®éã®æçŽããããããããŸããïŒã
postsuper -d ALL postsuper: Deleted: 72849 messages
5.é«åºŠãªã¡ãŒã«ãã®ã³ã°ãæå¹ã«ããŠã¿ãŸãã
mv /usr/sbin/sendmail /usr/sbin/sendmail.org touch /usr/sbin/sendmail chmod +x /usr/sbin/sendmail
echo -n '#!/bin/bash logger -p mail.info sendmail-ext-log: site=${HTTP_HOST}, client=${REMOTE_ADDR}, script=${SCRIPT_NAME}, pwd=${PWD}, uid=${UID}, user=$(whoami) /usr/sbin/sendmail.org -t -i' > /usr/sbin/sendmail
6.ã¡ãŒã«ãµãŒããŒãèµ·åããŸã
/etc/init.d/postfix start
7.ãã°ãèŠã
tail -f /var/log/mail.info
次ã®ãããªãã®ã衚瀺ãããŸãã
Jan 23 16:25:25 danma logger: sendmail-ext-log: site=, client=, script=send.php, pwd=/var/www/danma/data/www/site.ru, uid=33, user=www-data Jan 23 16:25:25 danma postfix/pickup[11520]: E3CD259403D: uid=33 from= Jan 23 16:25:25 danma postfix/cleanup[11522]: E3CD259403D: message-id=
ãããè¡åã®éžæè¢ã®1ã€ã§ãããšããäºå®ã«æ³šç®ããŸãã
èŠæ ã«ã¬ã¿ãŒIDãããå Žåãéä¿¡ãã°ã§ç¢ºèªãã䟡å€ããããŸãã
ãµãŒããŒããªãŒãã³ãœãŒã¹ã§ããããšãããŸããŸãããŸãã
ãŸããã¡ãŒã«ããã¯ã¹ã®ãã¹ã¯ãŒããéžæããã ãã®å ŽåããããŸãã泚æãã䟡å€ããããŸãã
äœè ã®ããã㧠ã ããããåãããŸãã ïŒ
ãã®ã³ã°ãæå¹ã«ããåŸããã®ã¹ã¯ãªããïŒ/css/sys0972500-1.phpïŒããã¹ãã ã¡ãŒãªã³ã°ãéå§ãããããšãããããŸããããããã¯cssãã£ã¬ã¯ããªã®ãã¡ã€ã«ã3åç®ã«åºçŸããåŸã§ã...
圌ãã¯ã©ã®ããã«ç§ãç ŽããŸãããïŒ ã©ãïŒ ç§ã¯äœãä»ã®ãã®ã«ææããŠããããšãããããŸãã...
çºè¡çªå·4
ä»åãå人ãç§ã«æçŽãæžããŠãKaspersky Anti-Virusã¯ç§ã®ãµã€ãã§åœŒãèš±å¯ããŠããªãã
Google Chromeã¯å¥ã®ã³ã³ãã¥ãŒã¿ãŒãææŸããŸããããã®èšäºã®ããããŒã«éåžžã«èµ€ã空çœã衚瀺ãããŠããŸã... GoogleããŠã§ããã¹ã¿ãŒããŒã«ããŒã«æ¬¡ã®ããã«æžããŠãµã€ããçŠæ¢ããŠããã®ãèŠãŠãéåžžã«æã£ãŠããŸããã
ããµã€ãããããŠãŒã¶ãŒã®ã¯ã©ã€ã¢ã³ãPCã«ãã«ãŠã§ã¢ãã€ã³ã¹ããŒã«ãããŸããã 以äžããã€ã³ã¹ããŒã«ãå®è¡ããããªã³ã¯ïŒ
ãµã€ãããã®ããã€ãã®ãªã³ã¯â
ã€ã³ããã¯ã¹ã¯äœãçããªãã£ã...
ç§ã¯ããã«åé¡ãååã«æ©ãæã¡ç Žã£ããšèšããªããã°ãªããŸããã ããã«ç§ããã£ãããšããããŸãïŒ
- ãã¡ã€ã«ãå床çæãããæªæã®ãããã¡ã€ã«ããã£ãã·ã¥ããååŸãããªãããã«ãCMSãã£ãã·ã³ã°ãã©ã°ã€ã³ãç¡å¹ã«ããŸãã
- ããäžåºŠããªã³ã©ã€ã³ãŠã€ã«ã¹å¯ŸçããŒã¿ããŒã¹ã®ãµã€ãããã§ãã¯ããŸããããã®ãŠã€ã«ã¹å¯Ÿçã¢ã©ãŒã ruã¯ãäœããã圹ã«ç«ã¡ãŸããã
- ãªããªã ãã®ãã§ãã¯ã§ã¯ã次ã®ããã«æžãããŠããŸãã
GoogleããŒãžã§ã³ã®çããããªã³ã¯ãå«ãŸããŠããŸãïŒfeeds feedburner com
GoogleããŒãžã§ã³ã®çããããªã³ã¯ãå«ãŸããŠããŸãïŒwww facebook com
GoogleããŒãžã§ã³ã®çããããªã³ã¯ãå«ãŸããŠããŸãïŒwww liveinternet ru
åã³ãç§ã¯ãµãŒãããŒãã£ã®Wordpressãã©ã°ã€ã³ããœãŒã·ã£ã«ãã¿ã³ãã³ã¡ã³ããªã©ã®æããªãã«ããŸããã
èšäºã®ã¯ãã¹æçš¿ããã£ããœãŒã·ã£ã«ãããã¯ãŒã¯ã®ãµã€ããžã®ç§»è¡ããGoogleã«ãã£ãŠçŠæ¢ãããŸãããããã¯ãç§ã®ãµã€ãããè³æããã£ãããã§ãã - Googleã®ãµããŒãã§ãããã¯ã®æ±ºå®ã確èªãããªã¯ãšã¹ããäœæããŸããïŒãããã¯ã®çç±ãèšèŒãããŠããã®ãšåãããŒãžã®ã»ã¯ã·ã§ã³ãã»ãã¥ãªãã£ã®åé¡ãïŒ
- äžæ£ãªãã£ãã·ã³ã°ã¢ã©ãŒããå ±åããããã®ãã©ãŒã ã«èšå ¥ããŸããã
- ãªããªã æåŸã®2ç¹ã¯24æéãšèŠãªããããããã³ã°ã®å¯èœæ§ã®çç±ãç©æ¥µçã«æ€çŽ¢ãå§ããŸããã ãããããftpããã§ãã¯ããªãã£ãããšãããããŸããïŒ
- proftpdãµãŒããŒãã°ãèªã¿åããŸãã
cat /var/log/proftpd/xferlog
éåžžã«èå³æ·±ãããšãããããŸããã
176.28.52.119 42278 /var/www/virtual/sysrtfm.ru/htdocs/css/sys0972500-1.php a _ ir admin@sysrtfm.ru ftp 0 * c
ãããŠãç§ã¯ãã¹ãŠãç解ããŸãã...ïŒæ²ããé¡æåïŒadmin@sysrtfm.ruã¢ã«ãŠã³ããå£ããŸãããããã«ãã¹ã¯ãŒããšãã°ã€ã³ãå€æŽããŸãããä»ã®ãã¹ãŠã®ftpã¢ã«ãŠã³ãããããã¯ããŸããã
å¥ã®ã¬ã³ãŒããèŠã€ãããŸããïŒ
31.7.234.34 0 /var/www/virtual/sysrtfm.ru/htdocs/css/c3x.php b _ or admin@sysrtfm.ru ftp 0 * c
ããã¯ãã¹ãŠåããªãã©ããã®ãã®ã§ããã¡ã€ã«ã¯åé€ãããŸãããããããã¯ã®çç±ã¯ããã§ã¯ãããŸããã§ããã - ããããã ããã§GoogleãŠã§ããã¹ã¿ãŒã®ãã¯ãã«ã«ãµããŒãã®ãã©ãŒã©ã ã§ãããã¯ãéå§ããŸãã ã
è¯ã人ãããŸãã圌ãã¯ãµã€ãããããŠã³ããŒãããã¹ã¯ãªããã§èå³æ·±ããã®ãèŠã€ããŸããïŒ
ãã«ãŠã§ã¢ã¯äœãããŸãããïŒ
-ãã¡ã€ã«wp-content / plugins / usernoise / js / usernoise.jsãftpã§å€æŽããæåŸã«å¥ã®ã¹ã¯ãªãããè¿œå ïŒ/wp-includes/images/smilies/skynet.js
ãã®ã¹ã¯ãªããã¯ããã©ãŠã¶ãŒãGoogle Chromeã§ãªãå Žåã«ã®ã¿å®è¡ããããŠãŒã¶ãŒã®PCã«ãã«ãŠã§ã¢ãããŠã³ããŒãããããšãå€æããŸããã
-次ã«ã/ wp-includes / images / crystal / gocubs.jsã¹ã¯ãªãããç»é²ããã/wp-content/plugins/lazy-load/js/lazy-load.jsãã¡ã€ã«ãææããŸãã - WinSCPãµã€ãããã°ã©ã ãããŒã«ã«ãã£ã¹ã¯ã«ããŠã³ããŒããã total commanderãèµ·åããããŠã³ããŒããããã£ã¬ã¯ããªã«ç§»åããŠããã¹ãŠã®ãã¡ã€ã«ã®åŒã®æ€çŽ¢ãéå§ããŸããã
cr"±"ipt skynet.js docâument.write
èŠã€ãã£ããã¹ãŠã®ãªã«ã¬ã³ã¹ã¯ã¯ãªãŒã³ã¢ãããããŸããã ãããŠã圌ã¯äœåãªãã®ãåé€ããªãã£ãããã§ãã - ãããã®çºçã«ã€ããŠããã©ãŠã¶ã«ãã£ãŠããŠã³ããŒãããããã¹ãŠã®ã¹ã¯ãªãããæåã§ãã§ãã¯ããŸããã ä»ã«äœãèŠã€ãããŸããã§ãã
12æéåŸãGoogleã¯ãµã€ãã®ããã¯ã解é€ããŸããããçµ±èšæ å ±ã¯ãŸã äœäžããŠããŸããïŒ
ããã§åé¡ã¯è§£æ±ºããŸããããä»ã§ã¯å€ãã®çµè«ãåºããŸãã....
ã©ãåå¿ãããã
ä»ãç§ã¯ããªãã®å®å šãšè²¡æ¿ç¶æ³ã ãã§ãªããããªãã®é¡§å®¢ã®æãéèŠãªè²¡æ¿çå®å šæ§ãããã«äŸåããŠãããããããã¬ãã«ã®ãµã€ãã§ãã®ãããªåé¡ãèš±ãããšãã§ããªãããšãç解ããŠããŸã...
2ãæåã«æ£ããåå¿ããå Žåãåçä»ãã®ãã©ã«ããŒã«ããçãããjsãã¡ã€ã«ã«é¢ããå人ããã®ã¡ãã»ãŒãžã«å¯ŸããŠã ãã¹ãŠãç°ãªããŸãã
ããã¯ç§ã«ãšã£ãŠæ·±å»ãªæèšã§ãããä»ãç§ã¯ãã®ãããªããšããã£ãšçå£ã«èããŸãïŒ ãã¹ãŠã®åå¿è ã®Webããã°ã©ããŒãªã©ã«ã¢ããã€ã¹ããããšïŒ
誰ãåé¡ã解決ããã®ãå©ããŠãããŸããã
- Alexander Krainev-æè¡çããã³é埳çãªãµããŒãããã³ããã¢ããã€ã¹ãç§ã®ãµã€ããååšããddosïŒ itservices.su ïŒããã®ä¿è·ãåãããã¹ãã£ã³ã°ã
- Googleã¢ããªãã£ã¯ã¹ã¯ãSEOã®ããŒã«ã§ããã ãã§ãªããè匱æ§ãèŠã€ããæ段ã§ããããŸãã ããã§ã¯ãããåå§çãªAWStatsãµã€ãçµ±èšããŒã«ã®ããã«ããŠãŒã¶ãŒãæãé »ç¹ã«ããã¯ããå Žæãæ¢ããŸããã ããšãã°ãç§ã«ãšã£ãŠã¯ã蚪åããäžäœ10ããŒãžã§ãWPèªèšŒããŒãžãæåã«ãããŸãïŒïŒïŒïŒåããã«ãŒããã©ãŒã¹ãå¿ èŠã§ããããšã¯äžæè°ã§ã¯ãããŸãããããªãã¯ããã«ã€ããŠäœããããå¿ èŠããããŸãã
- GoogleãŠã§ããã¹ã¿ãŒããŒã«ãã©ãŒã©ã ã¯éåžžã«äŸ¿å©ã§ãã
- Google Chromeãããã°ããã«-ãããªãã§ã¯ãäœãããŸãã...ïŒèª¿æ»äžã®ããŒãžã§F12ãæŒããŠã調æ»äžã§ãïŒ
- PuttyãWinSCPãTotalCommander-ãããããªããã°ïŒã¯åžžã«æå ã«ãããŸãïŒ
厩å£ã®å±æ©ã«beingããŠããèªåèªèº«ã«ã©ããªçµè«ãå°ããŸããã
åé¡ããã®ãããªç¶æ ã«ããããšã¯ã§ããŸããã ç§ã®ãµã€ãã§çºçããåé¡ãããã³ã¯ã©ã€ã¢ã³ããµã€ãã§çºçããå¯èœæ§ã®ããåé¡ã¯ãè¿ãå°æ¥ã«æ¡åŒµã¢ãŒãã§æ§ç¯ããèœåã®äžè¶³ã«ããç§ã®åé¡ã§ãã
誰ãããããã¹ãŠå¿ èŠãšããŸããïŒ
誰ãããããã¹ãŠå¿ èŠãšããŸããïŒ ããããã¹ãŠã®æ»æããŠã€ã«ã¹ãã¹ãã€ãŠã§ã¢ïŒ å€ãã®äººããããã®è³ªåã«å¯Ÿããçããç¥ã£ãŠããŸãã ç§ã®èŠç¹ã«ã€ããŠèª¬æããŸãã
å€ãã®äººã \ããã°ã©ã\ãã«ãŠã§ã¢ãåºåãã©ãããã©ãŒã ã«ãªãœãŒã¹ãæäŸããããšã§åå ¥ãåŸãããåãåºåç®çã®ããã«æ å ±ãããã«å©çšããããã«åéãããããŸãã ãµã€ããæªæã®ããããã°ã©ã ã«å¯Ÿããã»ãšãã©ã®æ»æã¯ããããã®ç®çã®ããã«ååšãããšæããŸãã
ãã®åŸãåºåäŒç€Ÿã¯ãã®ãªãœãŒã¹ãè³Œå ¥ããŠããã®åºåãã©ãããã©ãŒã ãããé«äŸ¡ã«é¡§å®¢ã«è²©å£²ããŸãã
ç¡æã®ããã°ãšã³ãžã³ã§100,000åã®ãããã³ã°ããããµã€ãã®ãããã¯ãŒã¯ãæ³åããŠãã ããããã«ãŠã§ã¢ããã°ã©ãããããããããã³ã°ããŸããã ãã®ãªãœãŒã¹ãåºåäŒç€Ÿã«å£²åŽããåºåäŒç€Ÿã¯åºççšã®è³æããªã³ã¯ãæºåããããã°ã©ããŒã¯ãããã³ã°ããããŠã§ããµã€ãã§æ°åã¯ãªãã¯ããã ãã§ãã®äŒç€Ÿå šäœãç«ã¡äžããŸãããã®èšå€§ãªãã©ãã£ãã¯ã¯ã€ã³ã¿ãŒãããå šäœã«è«å€§ãªãéããããããŸãã
åœç¶ããããã³ã°ãç¿ãã ãã®ç¡å®³ãªåŠç«¥ããããã«ãŠã§ã¢ã®ã€ã³ã¹ããŒã«ããŠãŒã¶ãŒã®å人ããŒã¿ã®çé£ïŒãœãŒã·ã£ã«ãããã¯ãŒã¯ãããµãŒãããŒãã£ãžã®ã¯ã¬ãžããã«ãŒããã©ã¡ãŒã¿ãŒããã°ã€ã³ããã¹ã¯ãŒãã®è»¢éïŒãŸã§ãå€ãã®ã¢ããªã±ãŒã·ã§ã³ãèããããŸãããã«ãŠã§ã¢ã¯ããµã€ãã人æ°ã®ãããªãœãŒã¹ã®è匱æ§ãåžžã«æ€çŽ¢ããŸãã
å®çšçãªãã³ã
ã€ã³ã¿ãŒãããã«ã¯ãã®ãããªãã³ãããããããããŸããç§ã¯ããã§æ¬åœã«äŸ¡å€ã®ããç§èŠãéããŸãã
- ã©ã®ãããªç¶æ³ã§ã ããµãŒãã¹ïŒadminãuserãloginãadministratorãªã©ïŒã§ã®æ¿èªã®ããã«æšæºã®åçŽãªãŠãŒã¶ãŒåã䜿çšããªãã§ãã ããã ããã«ãããã»ãã¥ãªãã£ãæäœ50ïŒ åäžããŸãã ããã«ããã£ããã£ãŸãã¯ãã¥ãŒãã³ãã¹ãã䜿çšããŸãã
- åžžã«ããã¯ã¢ããããŸãã質åã¯ãããŸãããåžžã«ããã¯ã¢ãããå¿
èŠã§ãã ããšãã°ãç§ã¯RKãããŒã«ã«ã§å®è¡ããã¹ã¯ãªããã䜿çšããŠã¹ã¯ãªãããWebda v çµç±ã§å€ã«1åYandexãã£ã¹ã¯ã«ããŒãžããé±ã«1åãã¹ãŠãèªå®
ã®ã³ã³ãã¥ãŒã¿ãŒã«è»¢éããŸãã
æ¯ãããŠã³ãããRKãã³ããŒããŠéç¥ãéä¿¡ããBashã¹ã¯ãªããïŒ#!/bin/sh # , STARTB="`date +%Y-%m-%d-%H:%M:%S`" # BACKUPDIR1="/var/www/virtual/sysrtfm.ru/backups/" # YDISK="/mnt/yandex.disk" # BTDIR="siteback" # TARGETDIR="${YDISK}/${BTDIR}/" DATETIME="`date +%Y-%m-%d-%H_%M_%S`" # LOGFILEDATE="`date +%Y%m%d`" # LOGFILE="/var/log/backupall-${LOGFILEDATE}.log" echo `date +%Y-%m-%d-%H:%M:%S`" " >> $LOGFILE # umount -f $YDISK >> $LOGFILE # echo `date +%Y-%m-%d-%H:%M:%S` " ${YDISK}" >> $LOGFILE mount -t davfs https://webdav.yandex.ru:443 $YDISK >> $LOGFILE # echo `date +%Y-%m-%d-%H:%M:%S` " ${TARGETDIR}${DATETIME}" >> $LOGFILE mkdir ${TARGETDIR}${DATETIME} >> $LOGFILE cd $BACKUPDIR1 >> $LOGFILE cp -r -f -p * ${TARGETDIR}${DATETIME} >> $LOGFILE umount -f $YDISK >> $LOGFILE # ENDB="`date +%H:%M:%S`" # STARTEND="Backup script Start of ${STARTB} End of ${ENDB}" mail -s "${STARTEND}" email@domain.com < $LOGFILE exit
- ã©ããªã«å¹³å¡ãªèšèã§ããä»ã§ã¯ãã£ãšè€éãªãã¹ã¯ãŒããçæãŸãã¯çºæããããšãã¿ããªã«å§ããŠããŸã ã ãã¹ã¯ãŒãã¯ããŒãããã¯ã«ä¿åãããïŒANikiBenikiã¯ããã«å°éããŸããïŒã10åèšæ¶ããããšãã§ããŸãã ãããããããã«ããŠããã¢ã¯ã»ã¹ãåãæ»ããæ å ±æŒæŽ©ã«ããåé¡ã解決ãããããç°¡åã§ãã
- 人æ°ã®ããWebã¹ã¯ãªãããŸãã¯CMSã䜿çšããå Žåã¯ããããã®æŽæ°ã«ã泚ç®ãã ããã åžžã«ç©ŽããããŸãã ãã£ãŒãããã¯ãªãã§æªæ€èšŒã®ã¹ã¯ãªããã䜿çšããªãããã«ããŠãã ããã ãµããŒããããŠããªãå€ãWEBã¹ã¯ãªããã䜿çšããªãã§ãã ããã
- ãã©ã°ã€ã³ãŸãã¯.httpasswdïŒä¿è·ããããã£ã¬ã¯ããªã«çœ®ãã ãã®ãã¡ã€ã«ãçæããããã®ãŠã£ã¶ãŒãïŒãä»ããèªèšŒèšå®ã§ãWEB管çã€ã³ã¿ãŒãã§ãŒã¹ãä¿è·ããæ©äŒãåžžã«ãããŸã
- ãµãŒãã¹ãžã®SSLã¢ã¯ã»ã¹ãæå¹ã«ã§ããå Žåã¯ã æå¹ã«ããŠãã ãã ïŒ SFTP ã HTTPS ã SSHã®ä¿è·ã«ããã4ã€ã®ã¹ããã ã
- ãã¹ãŠãçµã³ä»ããããŠããã¡ãŒã«ã®äžè©±ãããŠãã ãã ïŒ åŒ·åãªãã¹ã¯ãŒã ã 2段éèªèšŒãå¿ èŠã§ãïŒ
ããã«ãããã¯ã®ãã³ãããããŸãã ããããç§ã¯äžèšãæåã«å®è£ ããããšèããŠããŸãã ããã«ãåèªããµãŒãã¹ãä¿è·ããããã«ã©ããŸã§è¡ãããã決å®ããŸãã
PSïŒ
ãããŠãç§ã¯æéãç Žããéåžžã«æºè¶³ããŠããŸãïŒçµéšãèç©ããããµã€ããæ©èœããã·ã¹ãã ãçããŠããŸãïŒä»ã§ã¯å°æ¬ãããŠããhabrahabrã³ãã¥ããã£ãšãããè°è«ããã ãã§ãæ°å¹Žã®æåŸ ïŒ
次ã«ãå¿åã®ãµã³ã¿ã¯ããŒã¹ã®ãããžã§ã¯ãã«ç»é²ããHabrausersã«æçšãªãã®ãæ瀺ããŸãã
æ¬å ·ã ã€ãŽã¡ã³ã»ã¬ããã³ ã