Network Security Internet Technology Development Database Servers Mobile Phone Android Software Apple Software Computer Software News IT Information

In addition to Weibo, there is also WeChat

Please pay attention

WeChat public account

Shulou

PhpStudy hides the back door and how to prevent it

2025-04-04 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Internet Technology >

Share

Shulou(Shulou.com)06/02 Report--

PhpStudy hides the back door and how to prevent it. In view of this problem, this article introduces the corresponding analysis and answer in detail, hoping to help more partners who want to solve this problem to find a more simple and feasible way.

0x01: preface

Recently, phpStudy was announced to be suspected of being attacked by hackers. The php_xmlrpc.dll module with PHP in the package has a hidden back door. Netizens have confirmed that some versions of phpStudy2016 and phpStudy2018 have a back door. It is recommended that users who use this version carry out security reinforcement immediately.

Through analysis, the backdoor code exists in the extphp_xmlrpc.dll module, and there are at least 2 versions:

Users can quickly determine whether there is a backdoor version by searching for the keyword "@ eval" in the php_xmlrpc.dll module. The command refers to:

Findstr / m / s / c: "@ eval" *. *

0x02: reproduce

0x02: prevent php-5.4.45 version of PHP from being loaded by default when phpStudy starts. This version has a backdoor. You can download the original php-5.4.45 version or php-5.2.17 version from the PHP official website and replace the php_xmlrpc.dll in it. Download address: https://windows.php.net/downloads/releases/archives/php-5.2.17-Win32-VC6-x86.ziphttps://windows.php.net/downloads/releases/archives/php-5.4.45-Win32-VC9-x86.zip about phpStudy hidden back door and how to prevent the answer to the question shared here, I hope the above content can be of some help to you, if you still have a lot of questions unsolved You can follow the industry information channel for more related knowledge.

Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.

Views: 0

*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.

Share To

Internet Technology

Wechat

© 2024 shulou.com SLNews company. All rights reserved.

12
Report