问题描述
网站被挂马,请朋友们帮忙分析一下漏洞.现在我把IIS日志发出来,希望懂的朋友们,尽量帮忙看看,鄙人不甚感激.IIS日志#Software:MicrosoftInternetInformationServices6.0#Version:1.0#Date:2012-10-1510:11:04#Fields:datetimes-sitenames-ipcs-methodcs-uri-stemcs-uri-querys-portcs-usernamec-ipcs(User-Agent)sc-statussc-substatussc-win32-status2012-10-1510:11:04W3SVC1123.126.186.23OPTIONS*-80-116.255.236.244-20000#Software:MicrosoftInternetInformationServices6.0#Version:1.0#Date:2012-10-1510:55:10#Fields:datetimes-sitenames-ipcs-methodcs-uri-stemcs-uri-querys-portcs-usernamec-ipcs(User-Agent)sc-statussc-substatussc-win32-status2012-10-1510:55:10W3SVC1123.126.186.23PUT/1.txt-80-116.255.236.244-201002012-10-1510:55:15W3SVC1123.126.186.23MOVE/1.txt-80-116.255.236.244-201002012-10-1510:55:21W3SVC1123.126.186.23GET/ZeeWJ.asp-80-123.53.219.77Mozilla/4.0+(compatible;+MSIE+8.0;+Windows+NT+5.1;+Trident/4.0)200002012-10-1510:55:21W3SVC1123.126.186.23GET/favicon.ico-80-123.53.219.77Mozilla/4.0+(compatible;+MSIE+8.0;+Windows+NT+5.1;+Trident/4.0)404022012-10-1510:55:26W3SVC1123.126.186.23POST/ZeeWJ.asp-80-123.53.219.77Mozilla/4.0+(compatible;+MSIE+8.0;+Windows+NT+5.1;+Trident/4.0)200002012-10-1510:55:26W3SVC1123.126.186.23GET/favicon.ico-80-123.53.219.77Mozilla/4.0+(compatible;+MSIE+8.0;+Windows+NT+5.1;+Trident/4.0)40402
解决方案
解决方案二:
你的网站有IIS写权限漏洞,在IIS中设置默认网站属性,将主目录中的“写入”和“脚本资源访问”的勾去掉就可以了。