技术求助:wp-login.php脚本导致core dump,存储空间被占满
Hey there, I’ve dealt with similar stubborn WordPress server issues before, so let’s break down actionable steps to get to the bottom of this—your core files regenerating immediately and space filling up means the root cause is still lurking, even if scanners didn’t catch it:
Dig into the core files for clues
Usegdbto analyze the core dump and pinpoint exactly what’s triggering the crash. Run this command (adjust paths to match your server’s setup):gdb /usr/bin/php /path/to/your/core/fileOnce in gdb, type
btto pull up the backtrace. This will show you the sequence of code/processes that led to the crash—whether it’s a hidden malicious script, a faulty PHP extension, or something else entirely.Verify wp-login.php hasn’t been tampered with
Scanners sometimes miss subtle modifications. Grab a fresh copy of wp-login.php from the exact same version of WordPress you’re running, back up your current file, then replace it. If core dumps stop, you know the original file had hidden malicious code.Hunt for abnormal server activity
- Use
htoportopto monitor real-time processes—look for unexpected PHP-FPM/Apache instances spiking around wp-login.php, or unknown system processes writing to your filesystem. - Check your web server access logs (e.g.,
/var/log/apache2/access.logor/var/log/nginx/access.log) for weird traffic to wp-login.php: unusual request volumes, sketchy User-Agents, or strange query parameters that might be triggering the crash.
- Use
Root out hidden malicious files
Malware often hides in obscure places scanners overlook. Run these commands to hunt for suspicious scripts:# Find PHP files with common malicious functions find /path/to/wordpress/root -type f -name "*.php" -exec grep -l "eval\|base64_decode\|shell_exec" {} \; # Check uploads directory for unexpected files ls -la /path/to/wp-content/uploads/ | grep -v ".jpg\|.png\|.pdf"Also check for hidden files (starting with
.) in your WordPress root—some malware uses these to persist.Rule out PHP environment issues
Core dumps can happen if a PHP extension is corrupted or unstable. Temporarily disable non-essential extensions (via php.ini or your hosting control panel) and see if the crashes stop. Also check your PHP error logs (e.g.,/var/log/php-fpm/error.log) for crash-related error messages that scanners might not flag.
If none of these steps resolve the issue, I’m open to collaborating with you—feel free to share what kind of labor you’re able to provide, and we can work out a way to get this fixed.
内容的提问来源于stack exchange,提问作者halobule

