Thinkphp 5.0index.php was replaced with home page content and malicious code was injected
The original TP project is 5.0.10. Recently, when logging in to the backstage,
Domain name / admin, jump to the home page of the website. Unable to enter the background login page.
Then I found that public/index.php had been changed.
Upgrade to 5.0.24 first.
Or got shot.
Then I checked the nginx log.
Log in / home/wwwlogs/ domain name .log
Found that there are .php files in the directory where the pictures are uploaded.
192.168.100.1-[06/Mar/2019:14:16:35 + 0800] "POST / uploads/image/chinaword/2017/06/a60a38662b5ddcd5cfdf365ca97af24c.php HTTP/1.1" 200 3355 "http:// domain name / uploads/image/chinaword/2017/06/a60a38662b5ddcd5cfdf365ca97af24c.php"Mozilla/5.0 (Windows NT 6.1; Win64) X64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.84 Safari/537.36 "192.168.100.1-- [06/Mar/2019:14:16:36 + 0800]" GET / comon.php HTTP/1.1 "200827" http:// domain name / uploads/image/chinaword/2017/06/a60a38662b5ddcd5cfdf365ca97af24c.php "Mozilla/5.0 (Windows NT 6.1; Win64 X64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.84 Safari/537.36 "
Then delete the php file.
There are many related topics on the TP website. The situation is different for everyone.
Http://www.thinkphp.cn/Search/
Searching: vulnerabilities in