<small id="60cm0"></small>
<small id="60cm0"></small>
<small id="60cm0"><wbr id="60cm0"></wbr></small>
<small id="60cm0"></small>
<div id="60cm0"></div><small id="60cm0"><div id="60cm0"></div></small>
<div id="60cm0"></div><div id="60cm0"><button id="60cm0"></button></div>
技術文章
阿里云提示Discuz memcache+ssrf GETSHELL漏洞如何解決
發布日期:2019-08-15 閱讀次數:2181 字體大?。?a href="javascript:;" onclick="ChangeFontSize('content',16)">大

一般這個漏洞都是下面文件,source/function/function_core.php

搜索下面代碼:

$content = preg_replace($_G['setting']['output']['preg']['search'], $_G['setting']['output']['preg']['replace'], $content);

在此行代碼前增加下面代碼:

if (preg_match("(/|#|\+|%).*(/|#|\+|%)e", $_G['setting']['output']['preg']['search']) !== FALSE) { die("request error"); }

加完代碼以后效果:

if (preg_match("(/|#|\+|%).*(/|#|\+|%)e", $_G['setting']['output']['preg']['search']) !== FALSE) { die("request error"); }
$content = preg_replace($_G['setting']['output']['preg']['search'], $_G['setting']['output']['preg']['replace'], $content);

上傳文件,重新進行驗證就可以解決。

a曰本va欧美va视频|国产剧情顶级私人订制失踪|狠狠久久亚洲欧美专区|久久99热精品深田咏美|亚洲国产一区二区三区
<small id="60cm0"></small>
<small id="60cm0"></small>
<small id="60cm0"><wbr id="60cm0"></wbr></small>
<small id="60cm0"></small>
<div id="60cm0"></div><small id="60cm0"><div id="60cm0"></div></small>
<div id="60cm0"></div><div id="60cm0"><button id="60cm0"></button></div>