Get the App
SLTechnology News&Howtos  ›  Development  › 

What is the analysis and traceability of phpStudy batch intrusion?

Shulou Source: shulou.com Published: 2022-06-03 04:29:11 10月03日 Update

Today, I will talk to you about the analysis and traceability of phpStudy batch intrusion, which may not be well understood by many people. in order to make you understand better, the editor has summarized the following contents for you. I hope you can get something according to this article.

I. Preface

Recently, Tencent security Yunding lab detected that a large number of hosts were hacked and added a hidden account called "vusr_dx$". At the same time, Yunding lab also detected that a large number of such accounts were created while corresponding accounts were logged in from other places.

When the Windows account name is followed by a "$" symbol, the account information will not be displayed in the net user command. It is a common way for attackers to hide accounts, and developers generally do not add this type of account. Yunding lab tracked and analyzed the incident and restored the attacker's intrusion techniques and post-invasion operations.

Second, the analysis of invasion methods.

Through the analysis and statistics of all the hosts that have been hacked and added "vusr_dx$" hidden accounts, it is found that most hosts have installed phpStudy components, phpinfo and phpMyAdmin exist in the Web directory, and 50% of the root users of MySQL have weak passwords. From this, we can infer the possible causes of the intrusion:

Users deploy PHP environment on their CVM with one click of phpStudy, which includes phpinfo and phpMyAdmin by default and can be accessed by anyone. At the same time, the default password of MySQL installed is a weak password, so hackers log in to MySQL with a weak password through phpMyAdmin, and then use some means of MySQL to obtain system permissions.

There are several ways to obtain system permissions by using MySQL:

Take advantage of SELECT "

Tags: Attacks attackers accounts hackers analysis passwords ports logins hosts at the same time permissions users entry information commands situations tactics detection security content Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Apple Linux Shulou Information Microsoft Huawei