Process of detecting a hacker Station

Source: Internet
Author: User

By: Xiao Kai
 
Today, I read the blog's traffic statistics and found a hacker website ..
 
So I want to check it... find fate, and together, he won a side station. You do not have any permissions. Upload An aspx Trojan to find the writable directory.
 
Initially, the server permission is still acceptable. The out-of-the-stars permission is quite good. I followed the fate for a long time. There was no result .. (The head is a little too curved .)
 
When I wanted to give up, I used the command to input a dir c: column... directory file .. A little excited.
 
So again dir d: Is also a column. But the web disk is e: the disk Column cannot. However, when columns the D disk. Several compressed packages are found. hack ***. rar
 
So we downloaded the file and found that it was not the website. So we copied the second file. Download the hack6 program. Over 900 mb for a long time
 
Decompress the package and find the hack6 program. Find the background directory. Find the old dedecms 5.5 version. I remember a getshell and tried to fix it ..
 
Check the database link information in config. php. Pick up the kitchen knife link. It seems that rp does not work. No link .. (I thought there was a backup, but the old administrator may have changed all mysql)
 
No way at this time, social engineering. Some database connection information accounts are mostly idc login accounts .. find the idc address ** idc.net and try to find the account. A few other passwords are not logged on.
 
In fact, this process is very long. So I saw an independent panel on the top and pulled out the database link information... login... I did not expect to log on...
 
So enter .. phpmyadmin .... find dede_admin. three administrators .. password cannot be unlocked .. the dedecms password is 20-bit md5. Use phpmyadmin to change the management password to 123456.
 
Logging on to the background... dededecms the background is too simple to use the shell... it took a long time to get the shell and hung up a black page... Let's look at the previous figure ..

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.