網站被駭 - 資安
![Lucy avatar](/img/cat2.jpg)
By Lucy
at 2009-11-03T22:34
at 2009-11-03T22:34
Table of Contents
我社團上的官網
有十幾個PHP檔跟HTML檔
都被加了 <scirpt src="某網站的PHP檔 內容是清IFRAME的語法"></script>
PHP加了 eval( base64("一堆碼") )
還有 smarty引擊被加了 自動生出上面那個<script>的PHP法法
我是想問倒底是怎麼入侵的
我記得XSS INJECTION 只能改DB的
可是改到PHP檔案是怎麼成功的啊!?
而且我們的網站已經被駭第二次了 CRYCRY
駭客好像是反IFRAME人仕
INJECT的JS都是 d = getElementsByTag(Iframe) d[i].clear()
有什麼方法防範啊
改FTP, DB 的 PASSWD !?
--
Tags:
資安
All Comments
![Annie avatar](/img/cat3.jpg)
By Annie
at 2009-11-07T06:43
at 2009-11-07T06:43
![Hedda avatar](/img/cat4.jpg)
By Hedda
at 2009-11-10T01:46
at 2009-11-10T01:46
![Cara avatar](/img/cat5.jpg)
By Cara
at 2009-11-14T22:50
at 2009-11-14T22:50
Related Posts
租屋的網路隱私問題
![Jack avatar](/img/cat3.jpg)
By Jack
at 2009-11-02T22:27
at 2009-11-02T22:27
幾個關於木馬的蠢問題
![Hardy avatar](/img/boy2.jpg)
By Hardy
at 2009-11-01T03:09
at 2009-11-01T03:09
請問用無線網卡當AP?
![Joe avatar](/img/boy1.jpg)
By Joe
at 2009-10-25T12:25
at 2009-10-25T12:25
請問用無線網卡當AP?
![Joe avatar](/img/beret.jpg)
By Joe
at 2009-10-25T01:40
at 2009-10-25T01:40
關於架站的問題
![Delia avatar](/img/cat5.jpg)
By Delia
at 2009-10-24T16:24
at 2009-10-24T16:24