Webshell Intelligent Avira

Source: Internet
Author: User

First, the emergency response in the Web backdoor troubleshooting and efficient analysis of Web log skills

first check the web back door in advance , you can start from several aspects.
1.web Backdoor Avira Software
Recommended D-Shield on Windows, recommended P7 Mage's Seayfindshell on Linux

2. Last modified time of file
You can check for script files that have been modified after a certain point in time by command, and then check if the Web backdoor is not.

3. Slowly analyze the log based on approximate time
The most stupid way, not to be forced to use this method, compare time, and not directly. Because the general Websever does not record post, cookies, the light from the URL requires an experienced person to be able to see it.

The second thing is to look for an intrusion vulnerability .
Suppose we find the back door seay.php and action.php and so on, and then look at the back door of the last modification time, if this time is not the intruder later modified, then this time is the invasion time, go directly to the log to find the log in the vicinity of this time line. Even if the change is not OK, directly the Web backdoor file name to the Web log search, you can efficiently locate the intrusion time and IP.

So now we have found the intruder's invasion time and IP, the next trick, how to quickly extract the intruder's behavior log, that is, through the intruder IP to retrieve all the IP log, and then can be very smooth to find the vulnerability.

Webshell Intelligent Avira

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.