Lou: How to Detect and prevent web page hanging horse?

Source: Internet
Author: User

Intermediary transaction http://www.aliyun.com/zixun/aggregation/6858.html ">seo diagnose Taobao guest cloud host technology Hall

In the website optimization design, the detection webpage Trojan is also very important one work, the current popular website is black, is in the corresponding ASP,HTM,JS and so on file, inserts in JS calls the way. This article mainly introduces the type of the Web page hanging horse, how to detect whether the Web page is hanging horse, how to clean the Web Trojan. How to prevent web pages from being hung by horses.

1: The type of the web hanging horse.

The current popular web site is black, is in the corresponding Asp,htm,js and other files, insert in JS call way.

Lou previously did ' need source download Station ' has encountered JS hanging horse

' Campus Falling Day Forum ' will encounter user rights, using the Dynamic Network Program Vulnerability (upload attachment Vulnerability) has webmaster rights. Deleted the forum thousands of data, more than 1000 member ID

2: How to detect whether the Web page is Hung horse.

(1): Professional testing tools, six free Web page security testing Tools lateral Evaluation (Huajun Software Park)

(2): Google detection, or can use Google search your website, blog for testing. If a site has a trojan, Google will be in the search list below prompts the site has unsafe factors.

(3): Antivirus software testing, commonly used anti-virus software can also be detected.

(4): manual detection, open your Web site, blog, right-click the source file, according to the type of horse can also see whether the Trojan.

(5): Plugins that use McAfee SiteAdvisor to securely browse Web pages.

  

3: How to clear the Web Trojan.

Once the Web Trojan, look at those files are recently modified, the main view of these new files, (from the FTP can see the file recently modified time.) Then enter the source file to remove the suspicious code from the related Web page.

If you are unfamiliar with the Web site or blog program you are using, it is recommended that you delete all files (databases, pictures, documents, program template topics, and so on)

4: How to prevent web pages from being hung by horses. If your site has not been put on the horse, please start with prevention.

(1): Users to open upload attachment function of the site must be authenticated, and only allow people who trust to use the upload program.

(2): Ensure that you use the program in a timely manner.

(3): Do not add the background Management Program landing page link on the front page.

(4): Always back up the database and other important files, but do not put the backup database in the program default backup directory.

(5): The Administrator's username and password to have a certain complexity, can not be too simple.

(6): IIS prohibit write and directory prohibit the implementation of the function, two function combination, can effectively prevent ASP Trojan horse.

(7): Can be in the server, the virtual host Control Panel, set executive permission options, will have the right to upload the directory, the operation of the right to cancel the ASP.

(8): Create a robots.txt upload to the site root directory. Robots can effectively prevent hackers who use search engines to steal information.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.