阿里云服务器上发现一些奇怪的文件和文件夹,看文件创建时间,是今天上午 10 点 50 分创建的,文件夹只读和隐藏状态。文件夹叫 C:\0data712\和 C:\Zprogram203\。 操作系统是 windows server 2003 ,非常老,由于有个软件 php 有漏洞,但是系统太老了,无法升级这个软件。所以安装了杀毒软件,可以拦截软件漏洞,但是不确定是否 100%安全。 里面的文件内容都很简单,大家帮我看看是什么情况,是不是破防了。 从 apache 日志看,那个时间的连接没有发现异常请求。
1
foxhunt 60 天前
杀下毒先
八成是有木马了 如果实在没办法升级程序,可以考虑前边加个 WAF ,按量付费的没多少钱 安全策略方面,3389 只对自己 IP 开放 |
2
yinmin 59 天前 via iPhone
杀毒软件不是用来防止软件漏洞的。你需要用 waf
|
3
SWALLOWW 59 天前
我出现幻觉了,我看成我的鼠标被攻击破防了,我还想鼠标怎么破防
|
4
redidea 59 天前
是不是火绒的防勒索病毒诱惑文件夹,每次开机都会变
|
5
wangybsyuct OP @redidea 好像还真是火绒的动作,我用 ProcessMonitor 监视了一下,强力删除后(普通模式删除不掉),开机后的确会重新产生,参数这些奇怪文件的进程是 system 。
动作是这样的 "当天时间","进程名称","PID","操作","路径","结果","详细" "8:26:02.0763788","System","4","创建文件映射","C:\0package824\D7hhnTX.xls","成功","同步类型: 同步类型其它" "8:26:02.0764087","System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\0package824\D7hhnTX.xls","成功","" "8:26:02.0764246","System","4","写入文件","C:","成功","偏移: 0, 长度: 4,096, I/O 标记: 非缓存, 页面 I/O, 同步寻呼 I/O" "8:26:02.0764500","System","4","设置文件结尾信息文件","C:","成功","文件结尾: 2,774" "8:26:02.0764746","System","4","设置文件结尾信息文件","C:","成功","文件结尾: 2,601" "8:26:02.0764956","System","4","创建文件映射","C:\0package824\2rYXhaobzW.sql","成功","同步类型: 同步类型其它" "8:26:02.0765062","System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\0package824\2rYXhaobzW.sql","成功","" "8:26:02.0765193","System","4","写入文件","C:","成功","偏移: 0, 长度: 4,096, I/O 标记: 非缓存, 页面 I/O, 同步寻呼 I/O" |
6
redidea 33 天前
@wangybsyuct 这个问题也困扰了我一天,我也以为是中毒了,后来都恢复快照了,才发现火绒是祸首
|