服务器出现异常网络活动,寻求问题根源排查协助
It sounds like you’re dealing with a tricky post-hijack scenario—you’ve cleaned up the obvious malicious files, but the server’s still showing abnormal network activity, and your initial log dive isn’t turning up clear leads. Let’s break down targeted steps to get to the bottom of this:
Double-Check for Hidden Backdoors: Attackers rarely leave just the obvious hijacked files. Dig into these often-overlooked spots:
- Scan
wp-config.phpfor suspicious code (look for base64-encoded strings, unfamiliarinclude()/require()calls, or modified database credentials) - Compare theme/plugin file checksums with their original versions from WordPress.org or your last clean backup—even a single modified line can be a backdoor
- List hidden files in
public_htmlusingls -lavia SSH; attackers often hide scripts with names like.htaccess.backdooror.malicious.php - Inspect
wp-content/uploadsfor files with fake extensions (e.g.,image.jpg.php)—use thefilecommand to verify actual file types (e.g.,file wp-content/uploads/suspicious-file.jpg)
- Scan
Deep Dive Into the Partial Logs: The snippet you shared is cut off, but focus on these details when reviewing the full logs:
- Unusual request URLs (like unknown admin endpoints,
/wp-content/uploads/*.php, or random string paths) - IP addresses making repeated, automated requests—block these temporarily with
fail2banor your server’s firewall while you investigate - Error messages related to file execution failures or permission errors; these might indicate leftover malicious scripts trying to run
- Unusual request URLs (like unknown admin endpoints,
Check System-Level Logs: Web server logs don’t tell the whole story. Look at these system logs for clues:
/var/log/auth.log: Watch for SSH brute-force attempts or unauthorized login events/var/log/syslog//var/log/messages: Look for unexpected cron jobs, outbound network connections, or unusual process activity- List cron jobs for the affected WordPress user with
crontab -u [wp-username] -l—attackers often add cron jobs to re-infect the site automatically
Harden Your Site Post-Cleanup: Once you’ve eliminated all traces of malware, lock things down to prevent a repeat:
- Update WordPress, all themes, and plugins to their latest secure versions
- Reset all user passwords (especially admin accounts) to strong, unique values
- Add
define('DISALLOW_FILE_EDIT', true);towp-config.phpto block in-theme/plugin file editing - Set proper file permissions: directories to
755, files to644(never use777permissions)
Partial Server Log Provided:
[Wed Apr 25 17:19:59.239790 2018] [:error] [pid 14971:tid 140081856567040] [...]
内容的提问来源于stack exchange,提问作者Richard

