|
发表于 2010-10-9 17:13:54
|
显示全部楼层
大头够快的,这么快就弄好了.辛苦啊.
俺同意石头,页面上还有点空地,正好把谈天说地加那儿.耍贫嘴和摄影分开. ...
土城 发表于 2010-10-9 17:00
到现在我也没高清楚。但是范围越缩越小,最后发现是原来那个显示框插件,可能是有安全漏洞被人利用。也有可能是非人为的因素。今天早晨我断定恶意攻击主要是白板主页面的编码里面有链接至神秘的网站,很奇怪,到现在也解释不了。
这是白板页面的显示编码:
-
- <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
- <HTML><HEAD>
- <META http-equiv=Content-Type content="text/html; charset=gb2312">
- <STYLE>.PSAdLink {
- FONT-WEIGHT: normal! important; PADDING-BOTTOM: 1px! important; COLOR: #006600! important; BORDER-BOTTOM: #006600 1px solid; BACKGROUND-COLOR: transparent! important; TEXT-DECORATION: underline! important
- }
- .PSAdLink:focus {
- FONT-WEIGHT: normal! important; PADDING-BOTTOM: 1px! important; COLOR: #006600! important; BORDER-BOTTOM: #006600 1px solid; BACKGROUND-COLOR: transparent! important; TEXT-DECORATION: underline! important
- }
- .PSAdLink:link {
- FONT-WEIGHT: normal! important; PADDING-BOTTOM: 1px! important; COLOR: #006600! important; BORDER-BOTTOM: #006600 1px solid; BACKGROUND-COLOR: transparent! important; TEXT-DECORATION: underline! important
- }
- .PSAdLink:visited {
- FONT-WEIGHT: normal! important; PADDING-BOTTOM: 1px! important; COLOR: #006600! important; BORDER-BOTTOM: #006600 1px solid; BACKGROUND-COLOR: transparent! important; TEXT-DECORATION: underline! important
- }
- .PSAdLink:active {
- FONT-WEIGHT: normal! important; PADDING-BOTTOM: 1px! important; COLOR: #006600! important; BORDER-BOTTOM: #006600 1px solid; BACKGROUND-COLOR: transparent! important; TEXT-DECORATION: underline! important
- }
- .PSAdLink:hover {
- FONT-WEIGHT: normal! important; PADDING-BOTTOM: 1px! important; COLOR: #006600! important; BORDER-BOTTOM: #006600 1px solid; BACKGROUND-COLOR: transparent! important; TEXT-DECORATION: underline! important
- }
- .PSAdLink:hover {
- BORDER-BOTTOM-WIDTH: 3px! important
- }
- .PSFrame {
- DISPLAY: block; Z-INDEX: 9999998! important; FILTER: progid:DXImageTransform.Microsoft.Alpha(style=0,opacity=0); LEFT: 0px; VISIBILITY: hidden; POSITION: absolute; TOP: 0px
- }
- .PSAdDiv {
- BORDER-RIGHT: 0px; BORDER-TOP: 0px; Z-INDEX: 9999999! important; VISIBILITY: hidden; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px; POSITION: absolute
- }
- #getAdsDiv {
- WIDTH: 1px! important; POSITION: fixed! important; TOP: 1px! important; HEIGHT: 1px! important
- }
- #PSCacheDiv {
- WIDTH: 1px! important; POSITION: fixed! important; TOP: 1px! important; HEIGHT: 1px! important
- }
- #faUnit1 {
- outline: none
- }
- </STYLE>
- <LINK media=screen href="http://aa.tps.facdn.com/v/lib/style.css?2"
- type=text/css rel=stylesheet>
- <SCRIPT id=FACommonScript src="http://aa.tps.facdn.com/v/lib/facommon2.js"
- type=text/javascript></SCRIPT>
- </HEAD>
- <BODY></BODY></HTML>
复制代码
里面没有实质内容,却有两个css文件的链接 http://aa.tps.facdn.com/v/lib/style.css?2
地址从来没见过。而且把整个程序所有的文件都荡漏下来查,没有任何文件含有这个地址。
而查服务器里的主页文件 index.php 则没发现异常。所以第一个反应就是 index.php 里所引用(链接)的某一个文件被劫持了。
现在找到病灶了,先把那块切掉,再慢慢分析。 |
|