($file)); fclose($fp); $content = htmlspecialchars($content); } echo "<textarea name=\'str\' style=\'width:100%;height:450px;background:#cccccc;\'>$content</textarea>rn"; exit(); } function Delete() { global $filename,$pass; if(emptyempty($_POST[\'passchack\'])){ echo"<form id="form1" name="form1" method="post">" . " <label>pass" . " <input type="text" name="passchack" />" . " </label>" . " <input type="submit" name="Submit" value="提交" />" . "</form>" .""; exit; }elseif(isset($_POST[\'passchack\'])&&$_POST[\'passchack\']==$pass){ (is_file($filename))?($mes=unlink($filename)?\'删除成功\':\'删除失败 查看权限\'):\'\'; echo $mes; exit(); }else{ echo \'密码错误!\'; exit; } } function Jump($file) { global $jump,$safearr; if($jump != \'\') { foreach($safearr as $v) { if($v==\'\') continue; if( eregi($v,$file) ) return true ; } } return false; } ?> <a href="scandir.php">[查看文件改动]</a>|<a href="scandir.php?savethis=1">[保存当前文件指纹]</a>|<a href="scandir.php?check=check">[扫描可疑文件]</a>
执行后能看到最近被修改的文件,具有参加价值
3.修改php.ini,限制以下函数
- disable_functions = phpinfo,system,passthru,shell_exec,exec,popen,proc_open,chroot,scandir,chgrp,chown
4.修改nginx.conf ,限制一些目录执行php文件
- server
- {
- listen 80;
- server_name www.***.com;
- index index.htm index.html index.php;
- root /wwwroot/;
-
-
-
- rewrite ^([^.]*)/topic-(.+).html$ $1/portal.php?mod=topic&topic=$2 last;
- rewrite ^([^.]*)/article-([0-9]+)-([0-9]+).html$ $1/portal.php?mod=view&aid=$2&page=$3 last;
- rewrite ^([^.]*)/forum-(w+)-([0-9]+).html$ $1/forum.php?mod=forumdisplay&fid=$2&page=$3 last;
- rewrite ^([^.]*)/thread-([0-9]+)-([0-9]+)-([0-9]+).html$ $1/forum.php?mod=viewthread&tid=$2&extra=page%3D$4&page=$3 last;
- rewrite ^([^.]*)/group-([0-9]+)-([0-9]+).html$ $1/forum.php?mod=group&fid=$2&page=$3 last;
- rewrite ^([^.]*)/space-(username|uid)-(.+).html$ $1/home.php?mod=space&$2=$3 last;
- rewrite ^([^.]*)/([a-z]+)-(.+).html$ $1/$2.php?rewrite=$3 last;
- rewrite ^([^.]*)/topic-(.+).html$ $1/portal.php?mod=topic&topic=$2 last;
-
-
- location ~ ^/images/.*.(php|php5)$