Linux Find PHP Trojan Horse program Example

Source: Internet
Author: User

1, the security of the server itself

Install Denyhost, prevent SSH brute force, concrete installation method Reference "denyhost prevent SSH brute force to crack, protect your Linux" a article.

Also add an I permission to some important files in the system

Like what:

The code is as follows Copy Code

# chattr +I/ETC/PASSWD

# chattr +i/etc/group

# chattr +i/etc/shadow

# chattr +i/etc/gshadow

# chattr +i/etc/ssh/sshd_config

2, Nginx and PHP security

(1) to discuz/attachments,uchome/attachment,ucenter/data/tmp and other users upload the directory, limit the PHP program. Centos+nginx itself should be relatively safe, the average hacker is the use of Webshell to invade.

Add in Nginx's configuration file

The code is as follows Copy Code

Location ~ *\. (PHP|PHP5)? $ {

.......

#——————————————

Rewrite ^/(uc\_client|templates|include|plugins|admin|attachments|images|

Forumdata)/.*\. (PHP|PHP5) $/50x.php last;

#——————————————-

}

(2) Modify PHP.ini

Find: Disable_functions

Add after = after found

The code is as follows Copy Code

Exec,system,passthru,error_log,ini_alter,dl,openlog,syslog,readlink,symlink,

Link,leak,fsockopen,proc_open,

Popepassthru,chroot,scandir,chgrp,chown,escapeshellcmd,escapeshellarg,

Shell_exec,proc_get_status,popen

Here are the functions that are prohibited from executing in PHP

(3) To some important and do not need to modify the file to add I permissions, method with the "1, the security of the server itself" section

3, how to find the server in the PHP trojan

The most obvious feature of the PHP Trojan is the use of the Eval and Base64_decode function, so we can find

The code is as follows Copy Code

find/var/www/-type f-name "*.php" | Xargs grep "eval (" |more

If you find such words, most of them are Trojan horse programs.

The code is as follows Copy Code

Eval (Base64_decode (...)); and the other;

Experience Sharing: If you are a Windows system we can use like a secure dog or Webshell plugin to scan the server PHP file is not a PHP trojan, I often use the latter to find very good, of course, security is a very important step, is to put some system functions to prohibit.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.