You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

header.php文件保存后被cPanel自动删除的技术求助

header.php保存后被cPanel自动删除的排查与解决

我的header.php文件保存后几秒就从cPanel中消失,且未运行该文件。排查确认是以下代码段触发了cPanel的安全拦截:

if (substr_count($uri_path, 'index')>0){
    $uri_path = str_replace("index", "!", $uri_path);
    $url_path='index.php';
}

对应的前置代码:

$url_path=$_SERVER['PHP_SELF'];
$position=strrpos($_SERVER['PHP_SELF'],'/');
$uri_path= substr($_SERVER['PHP_SELF'],0,$position).'/';
// *** url_rewrite ***
if ($humo_option["url_rewrite"]=="j"){
   $uri_path=$_SERVER['REQUEST_URI'];

原因分析

这段代码被cPanel的安全防护机制(如ModSecurity或内置恶意代码检测)误判为潜在威胁——对URI路径中的关键字进行直接替换的逻辑,可能被识别为路径篡改、恶意URL重写类的攻击行为。

解决办法

  1. 重构代码逻辑,避免触发安全规则
    改用更安全、直观的写法,减少被误判的概率:

    if (str_contains($uri_path, 'index')) {
        $url_path = 'index.php';
        // 使用正则替换时确保逻辑明确,避免模糊匹配
        $uri_path = preg_replace('/\bindex\b/', '!', $uri_path);
    }
    

    注:PHP 8.0+支持str_contains,低版本可改用strpos($uri_path, 'index') !== false替代。

  2. 将文件加入cPanel安全白名单
    在cPanel的「Security」板块找到「ModSecurity」或「Malware Scanner」选项,将header.php添加到白名单,跳过对该文件的恶意代码检测。(测试完成后建议重新评估规则,避免长期放宽安全限制)

  3. 检查上下文变量安全性
    确保$humo_option["url_rewrite"]的取值是可信的,避免未过滤的用户输入进入路径处理逻辑,从根源减少安全风险。

内容的提问来源于stack exchange,提问作者Faisal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 01:26:10