You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

技术求助:wp-login.php脚本导致core dump,存储空间被占满

Troubleshooting Persistent wp-login.php Core Dump & Space Exhaustion

Hey there, I’ve dealt with similar stubborn WordPress server issues before, so let’s break down actionable steps to get to the bottom of this—your core files regenerating immediately and space filling up means the root cause is still lurking, even if scanners didn’t catch it:

  • Dig into the core files for clues
    Use gdb to analyze the core dump and pinpoint exactly what’s triggering the crash. Run this command (adjust paths to match your server’s setup):

    gdb /usr/bin/php /path/to/your/core/file
    

    Once in gdb, type bt to pull up the backtrace. This will show you the sequence of code/processes that led to the crash—whether it’s a hidden malicious script, a faulty PHP extension, or something else entirely.

  • Verify wp-login.php hasn’t been tampered with
    Scanners sometimes miss subtle modifications. Grab a fresh copy of wp-login.php from the exact same version of WordPress you’re running, back up your current file, then replace it. If core dumps stop, you know the original file had hidden malicious code.

  • Hunt for abnormal server activity

    • Use htop or top to monitor real-time processes—look for unexpected PHP-FPM/Apache instances spiking around wp-login.php, or unknown system processes writing to your filesystem.
    • Check your web server access logs (e.g., /var/log/apache2/access.log or /var/log/nginx/access.log) for weird traffic to wp-login.php: unusual request volumes, sketchy User-Agents, or strange query parameters that might be triggering the crash.
  • Root out hidden malicious files
    Malware often hides in obscure places scanners overlook. Run these commands to hunt for suspicious scripts:

    # Find PHP files with common malicious functions
    find /path/to/wordpress/root -type f -name "*.php" -exec grep -l "eval\|base64_decode\|shell_exec" {} \;
    # Check uploads directory for unexpected files
    ls -la /path/to/wp-content/uploads/ | grep -v ".jpg\|.png\|.pdf"
    

    Also check for hidden files (starting with .) in your WordPress root—some malware uses these to persist.

  • Rule out PHP environment issues
    Core dumps can happen if a PHP extension is corrupted or unstable. Temporarily disable non-essential extensions (via php.ini or your hosting control panel) and see if the crashes stop. Also check your PHP error logs (e.g., /var/log/php-fpm/error.log) for crash-related error messages that scanners might not flag.

If none of these steps resolve the issue, I’m open to collaborating with you—feel free to share what kind of labor you’re able to provide, and we can work out a way to get this fixed.

内容的提问来源于stack exchange,提问作者halobule

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 16:57:54