Ò»¡¢Ç°ÑÔ
²»ÖªÔõµÄ×î½üÉõÊÇ˼ÄîУ԰Éú»î£¬Ë¼ÄîʳÌõij´·¹¡£ÄÇʱ»áÈ¥¸÷ÖÖ°²È«bbsÉÏˢˢÌû×Ó£¬Ï²»¶¿´±ðÈËдµÄһЩ¹ØÓÚ°²È«¼¼ÇÉ»ò¾ÑéµÄ×ܽ᣻ÄÇʱBBSÉϺܶàÎÄÕ±êÌⶼÊÇ£º³É¹¦Éø͸XXX£¬³É¹¦ÄÃÏÂXXX¡£ÕâÀï±ãÒÔһƪÈëÇÖ·ÆÂɱöij´óѧµÄÎÄÕÂÒý³öÎÄÕµÄÖ÷Ì⣬ÎÒÃÇÏȼòÒª¿´Ò»Ï¹ý³Ì¡£´óѧÍøվʹÓÃÁËÃûΪjoomlaµÄ¿ªÔ´web³ÌÐò£¬(1)ÇàÄêʹÓÃÒ»¸öjoomlaÒѾ¹«¿ªµÄ©¶´½øÈëwebºǫ́(2)ÇàÄêʹÓÃjoomlaºǫ́ÉÏ´«ÏÞÖƲ»ÑϵÄȱÏÝÉÏ´«ÁËÒ»¸öwebshell(3)¿ØÖÆÖ÷»úÔùËÍÎÒ¹ú¹úÆì¡£
ÔÀ´ÈëÇÖһ̨Ö÷»úÈç´ËÈÝÒ×£¬¹ÜÀíÔ±¹û¶Ï¸øweb³ÌÐò´òÉÏ°²È«²¹¶¡¡£¹ÜÀíÔ±µÄ¹¤×÷ÊǽáÊøÁË£¬×÷Ϊ°²È«´ÓÒµÈËÔ±ÔÙÒ»ÏëÊDz»ÊÇjoomlaºǫ́ÕâÀï¿ÉÒÔÉÏ´«webshellÊDz»ÊÇÓÐÎÊÌâÄØ£¬Èç¹ûjoomlaºǫ́²»ÄÜÉÏ´«webshell£¬ÊDz»ÊÇ¿ÉÒÔ¼õÉÙÈëÇֵĿÉÄܺÍËðʧ¡£ÏÂÃæ½øÈë±¾ÎĵÄÖ÷Ì⣺webºǫ́³ÌÐòµÄ°²È«ÐÔ¡£
¶þ¡¢¼ò½é
¹úÄںܶàÕ¾µã¶¼ÊÇ»ùÓÚ¿ªÔ´ÂÛ̳¡¢cms´î½¨µÄ£¬±ÈÈçdiscuz¡¢phpwind¡¢dedecmsµÈ¡£ÕâЩ³ÌÐò¶¼ÊǹúÄÚ¿ªÔ´web³ÌÐòÖеÄٮٮÕߣ¬Ò²±È½Ï×¢ÖØ°²È«ÐÔ¡£Æ½Ê±´ó¼Ò¹Ø×¢±È½Ï¶àµÄÊÇsql×¢Èë¡¢xssÕâЩ¿ÉÒÔÖ±½ÓÇÔÈ¡Óû§Êý¾ÝµÄ©¶´¡£ÍøÉÏÒòΪÈõ¿ÚÁî±»ÈëÇֵݸÀýÊý²»Ê¤Êý£¬´ËÍâÓû§Êý¾Ýй©Ê¼þʱ¶ø·¢Éú£¬µ¥´¿¿¿ÃÜÂë·À»¤µÄºǫ́±»Í»ÆÆ£¬±»É繤µÄ¿ÉÄÜÐÔÔ½À´Ô½´ó¡£»ñÈ¡Ò»¸ö¹ÜÀíºǫ́ÃÜÂëºó£¬ÔÙ½áºÏºǫ́³ÌÐòµÄÈÎÒâ´úÂëÖ´ÐС¢Îļþ°üº¬»òÃüÁî×¢ÈëµÈ©¶´µÃµ½Ò»¸öshell£¬ÇÔÈ¡Óû§×ÊÁϲ»ÊÇʲôÄÑÊ¡£´Ëʱºǫ́³ÌÐòµÄ°²È«ÐÔ³ÉΪһ¸ö¶Ì°å¡£
DiscuzÊÇÒ»¿îÁ÷ÐеÄÂÛ̳³ÌÐò£¬±ÊÕßÕâÀï¾ÍÒÔËüµÄºǫ́³ÌÐòΪÀý¼òµ¥·ÖÎöÒ»ÏÂÆ䰲ȫÐÔ£¬ÏÂÃæÖ±½Ó¿´Ò»Ð©Â©¶´°¸Àý(Discuz×îа汾ÒÑ´ò²¹¶¡,ÇëÓû§¼°Ê±Éý¼¶µ½×îаæ-Discuz! X3.1 R20140101)¡£
Èý¡¢°¸Àý·ÖÎö
Tips£ºÏÂÎÄÌáµ½µÄ$settingnewÊÇdiscuzºǫ́´æ´¢±íµ¥Êý¾ÝµÄ±äÁ¿£¬ºǫ́Óû§¿É¿Ø¡£
°¸ÀýÒ»£ºÓû§ÊäÈëÊý¾Ý¹ýÂËÂß¼²»µ±
©¶´Îļþ£ºX3\source\admincp\admincp_setting.php
·ÖÎö£º
// 1¡¢aliceÐÞ¸Ä$settingnew['extcredits']·ÇÊý×é
if(is_array($settingnew['extcredits'])) {
foreach($settingnew['extcredits'] as $key => $value) {
// 2¡¢¸ø$settingnew['initcredits'][1]´«Èëphpinfo()£»,·ÇÊý×éÈƹýintvalת»»
$settingnew['initcredits'][$i] = intval($settingnew['initcredits'][$i])£»
... Ê¡ÂÔ ...
for($i = 1£» $i <= 8£» $i++) {
// 3¡¢ phpinfo()£»±»¸³Öµ¸ø$initformula
$initformula = str_replace('extcredits'.$i, $settingnew['initcredits'][$i], $initformula)£»
}
// 4¡¢phpinfo()´øÈëevalÖ´ÐÐ
eval("\$_G['setting']['initcredits'] = round($initformula)£»")£»
(ÔðÈα༣º°²²©ÌÎ)