For some reason, Discuz's uc_key value is compromised, and hackers can easily get and reset the administrator's password by this value. In order to fill the loopholes, Uc_key modifications are required.
Modification method: (online UCenter1.6 version)
1. Modify the corresponding Uc_key values in the following three files:
/var/www/html/bbs/config/config_ucenter.php
/var/www/html/ucenter/config.inc.php
/var/www/html/bbs/uc_server/data/cache
2. Login Ucenter Console management, enter application management, the default application will be in the state of communication failure, click Edit, Copy the updated Uc_key to the location, then click the Submit button. Returning to the app list will find the communication successful.
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/75/07/wKiom1YwnP6QwnFYAAGzjfF3il0769.jpg "title=" Qq20151028180112.jpg "alt=" Wkiom1ywnp6qwnfyaagzjff3il0769.jpg "/>
Note: If your app always shows communication failures, you can try the following linked methods:
Http://down.chinaz.com/try/201109/1100_1.htm
http://blog.csdn.net/yanhui_wei/article/details/16960099
Extended read: http://www.bubuko.com/infodetail-687104.html
Discuz X1.5 X2.5 X3 uc_key getshell Write phpcode into config/config_ucenter.php via/api/uc.php Vul
This article is from "Dolphin Watching" blog, please be sure to keep this source http://swht1278.blog.51cto.com/7138082/1707394
Discuz Forum Uc_key Reset