﻿{"id":400,"date":"2011-01-15T10:38:15","date_gmt":"2011-01-15T10:38:15","guid":{"rendered":""},"modified":"2011-11-18T17:12:24","modified_gmt":"2011-11-18T09:12:24","slug":"400","status":"publish","type":"post","link":"http:\/\/zerobox.org\/notes\/400.html","title":{"rendered":"\u6d45\u8c08\u4ecePHP\u5185\u6838\u5c42\u9762\u9632\u8303PHP WebShell"},"content":{"rendered":"<p>By \u5496\u5561(k4kup8_0x4154_gmail.com)<\/p>\n<p>[\u76ee\u5f55]<\/p>\n<p>1. \u7b80\u8ff0<br \/>\n2. php\u7684\u6267\u884c\u6d41\u7a0b<br \/>\n3. php\u7684\u751f\u547d\u5468\u671f<br \/>\n4. php\u6e90\u4ee3\u7801\u5206\u6790\u4ee5\u53ca\u529f\u80fd\u6027\u4ee3\u7801\u7684\u5b9e\u73b0<br \/>\n5. \u603b\u7ed3<br \/>\n6. \u53c2\u8003\u8d44\u6599<br \/>\n\u4e00\u3001\u7b80\u8ff0<\/p>\n<p>\u4f9d\u636ephp\u7279\u5b9a\u8fd0\u884c\u73af\u5883\u3001php\u67d0\u4e9b\u7279\u5b9a\u51fd\u6570\u7f3a\u9677\u3001php\u666e\u901a\u51fd\u6570\u53ef\u4ee5\u5b9e\u73b0\u53d8\u5316\u591a\u7aef\u7684php<br \/>\nwebshell\uff0cphp\u7248\u672c\u7684scanwebshell\u4e5f\u4e0d\u662f\u592a\u7ed9\u529b\u3002php webshell\u529f\u80fd\u6700\u5927\u5316\u5c31\u662f\u5b9e\u73b0\u6587\u4ef6\u3001<br \/>\n\u76ee\u5f55\u3001\u547d\u4ee4\u3001\u6570\u636e\u5e93\u7b49\u64cd\u4f5c\uff0c\u8fd9\u4e9b\u90fd\u662f\u57fa\u4e8ephp\u4ee3\u7801\u5b9e\u73b0\u7684\u3002\u628a\u76f8\u5173\u529f\u80fd\u5316\u7684php\u51fd\u6570\u8fd0\u884c\u53c2<br \/>\n\u6570\u63d0\u53d6\u51fa\u6765\uff0c\u7136\u540e\u505a\u4e00\u4e2a\u5224\u65ad\uff0c\u8fd9\u6837\u5c31\u80fd\u4ece\u672c\u8d28\u4e0a\u9632\u8303php webshell\uff0c\u5728php\u8fd9\u4e2a\u5c42\u9762\u5b9e\u73b0<br \/>\n\u5176\u5b89\u5168\u7684\u6700\u5927\u5316\u3002\u8fd9\u91cc\u4ecb\u7ecd\u4e0b\u901a\u8fc7\u7f16\u5199php\u6269\u5c55\u6765\u5b9e\u73b0\u8fd9\u4e2a\u601d\u8def\uff0c\u5f53\u7136\u9700\u8981\u7684\u8bdd\u4e5f\u53ef\u4ee5\u91cd\u65b0<br \/>\n\u7f16\u8bd1php\u6e90\u4ee3\u7801\u6765\u5b9e\u73b0\u3002<\/p>\n<p>\u9996\u5148\u6211\u4eec\u4e86\u89e3\u4e0bphp\u7684\u6267\u884c\u6d41\u7a0b\u3001php\u751f\u547d\u5468\u671f\uff0c\u63a5\u4e0b\u6765\u901a\u8fc7\u5206\u6790\u5177\u4f53\u51fd\u6570\u7684php\u6e90\u4ee3\u7801<br \/>\n\u6765\u5b9e\u73b0\u529f\u80fd\u6027\u4ee3\u7801\u3002<br \/>\n\u4e8c\u3001php\u7684\u6267\u884c\u6d41\u7a0b<\/p>\n<p>2.1 scanner<\/p>\n<p>\u5c06PHP\u4ee3\u7801\u8f6c\u6362\u4e3aTokens\uff0c\u8be6\u89c1\u4ee3\u7801Zend\/zend_language_scanner.l\u3002<\/p>\n<p>2.2 parser<\/p>\n<p>\u5c06Tokens\u8f6c\u6362\u6210\u8868\u8fbe\u5f0f\uff0c\u8be6\u89c1\u4ee3\u7801Zend\/zend_language_parser.y\u3002<\/p>\n<p>2.3 compile<\/p>\n<p>\u5c06\u8868\u8fbe\u5f0f\u7f16\u8bd1\u6210opcode\u3002opcode\u5b58\u653e\u5728op_array\u4e2d\u3002<\/p>\n<p>2.4 execute<\/p>\n<p>Zend Engine\u8c03\u7528zend_execute\u6765\u6267\u884cop_array\uff0c\u8f93\u51fa\u7ed3\u679c\u3002<\/p>\n<p>\u4e09\u3001php\u7684\u751f\u547d\u5468\u671f<\/p>\n<p>3.1 STARTUP<\/p>\n<p>1\u3001\u521d\u59cb\u5316\u5f15\u64ce\u548c\u6838\u5fc3\u7ec4\u4ef6\u3002<br \/>\n2\u3001\u89e3\u6790php.ini\u3002<br \/>\n3\u3001\u521d\u59cb\u5316\u9759\u6001\u6784\u5efa\u7684\u6a21\u5757(MINIT)\u3002<br \/>\n4\u3001\u521d\u59cb\u5316\u5171\u4eab\u6a21\u5757(MINIT)\u3002<\/p>\n<p>3.2 ACTIVATION<\/p>\n<p>1\u3001\u521d\u59cb\u5316\u73af\u5883\u53d8\u91cf\u3001\u53d8\u91cf\u3002<br \/>\n2\u3001\u6fc0\u6d3b\u9759\u6001\u6784\u5efa\u7684\u6a21\u5757(RINIT) \u3002<br \/>\n3\u3001\u6fc0\u6d3b\u5171\u4eab\u6a21\u5757(RINIT) \u3002<\/p>\n<p>3.3 RUNTIME<\/p>\n<p>1\u3001\u7f16\u8bd1\u548c\u6267\u884cphp.ini\u4e2dauto_prepend_file\u9009\u9879\u6307\u5b9a\u7684\u6587\u4ef6\u3002<br \/>\n2\u3001\u7f16\u8bd1\u548c\u6267\u884c\u6240\u8bf7\u6c42\u7684\u6587\u4ef6\u3002<br \/>\n3\u3001\u7f16\u8bd1\u548c\u6267\u884cphp.ini\u4e2dauto_append_file\u9009\u9879\u6307\u5b9a\u7684\u6587\u4ef6\u3002<\/p>\n<p>3.4 DEACTIVATION<\/p>\n<p>1\u3001\u8c03\u7528\u7528\u6237\u6307\u5b9a\u7684\u9000\u51fa\u51fd\u6570\u3002<br \/>\n2\u3001\u9500\u6bc1\u5bf9\u8c61\u5b9e\u4f8b\u3002<br \/>\n3\u3001\u505c\u7528\u6a21\u5757(RSHUTDOWN)\u3002<br \/>\n4\u3001\u6e05\u7a7a\u8f93\u51fa\u3002<br \/>\n5\u3001\u6e05\u7406\u73af\u5883\u3002<br \/>\n6\u3001\u91ca\u653e\u5269\u4f59\u7684\u975e\u6301\u4e45\u5185\u5b58\u3002<\/p>\n<p>3.5 SHUTDOWN<\/p>\n<p>1\u3001\u5173\u95ed\u542f\u52a8\u7684\u5168\u90e8\u6a21\u5757(MSHUTDOWN)\u3002<br \/>\n2\u3001\u5173\u95ed\u5f15\u64ce\u3002<\/p>\n<p>\u56db\u3001php\u6e90\u4ee3\u7801\u5206\u6790\u4ee5\u53ca\u529f\u80fd\u6027\u4ee3\u7801\u7684\u5b9e\u73b0<\/p>\n<p>php\u51fd\u6570\u5206\u4e3a\u4e24\u79cd\uff1a\u4e00\u79cd\u662fZend\u7684\u51fd\u6570\uff0c\u8fd9\u7c7b\u51fd\u6570\u6570\u91cf\u6bd4\u8f83\u5c11\uff0c\u6bd4\u5982eval\u51fd\u6570\u3002\u7b2c\u4e8c\u79cd<br \/>\n\u662f\u7531PHP_FUNCTION\u5b8f\u7f16\u5199\u7684\uff0c\u8fd9\u7c7b\u51fd\u6570\u6570\u91cf\u6bd4\u8f83\u591a\uff0c\u6bd4\u5982system\u51fd\u6570\u3002\u5b9e\u73b0\u5bf9\u4e24\u7c7b\u51fd\u6570\u5728\u63d0<br \/>\n\u53d6\u8fd0\u884c\u65f6\u7684\u53c2\u6570\u7684\u65b9\u5f0f\u4e5f\u4e0d\u76f8\u540c\uff0c\u6bd4\u5982\u5904\u7406eval\u51fd\u6570\u7528\u91cd\u5199zend_compile_string\u7684\u65b9\u5f0f\uff0c<br \/>\n\u800c\u5904\u7406system\u51fd\u6570\u5219\u5bf9HashTable\u64cd\u4f5c\u3002\u4e0b\u8fb9\u5c31\u4ee5eval\u51fd\u6570\u548csystem\u51fd\u6570\u4e3a\u4f8b\u8fdb\u884c\u5206\u6790\u3001\u4ee3<br \/>\n\u7801\u5b9e\u73b0\u3002<\/p>\n<p>4.1 eval\u51fd\u6570\u4ee3\u7801\u5206\u6790\u4e0e\u4ee3\u7801\u5b9e\u73b0<\/p>\n<p>\u9996\u5148\u6211\u4eec\u770bphp\u6e90\u4ee3\u7801\u4e2deval\u51fd\u6570\u662f\u5982\u4f55\u5b9e\u73b0\u7684\uff0c\u90e8\u5206\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n\/\/ PHPSRC\/Zend\/zend_vm_def.h<\/p>\n<p>if (inc_filename-&gt;type!=IS_STRING) {<br \/>\ntmp_inc_filename = *inc_filename;<br \/>\nzval_copy_ctor(&amp;tmp_inc_filename);<br \/>\nconvert_to_string(&amp;tmp_inc_filename);<br \/>\ninc_filename = &amp;tmp_inc_filename;<br \/>\n}<\/p>\n<p>case ZEND_EVAL: {<br \/>\n\/* \u8c03\u7528zend_make_compiled_string_description\u51fd\u6570 *\/<br \/>\nchar *eval_desc = zend_make_compiled_string_description(&#8220;eval()&#8221;d code&#8221; TSRMLS_CC);<br \/>\n\/* \u8c03\u7528zend_compile_string\u51fd\u6570 *\/<br \/>\nnew_op_array = zend_compile_string(inc_filename, eval_desc TSRMLS_CC);<br \/>\nefree(eval_desc);<br \/>\n}<br \/>\n\/* \u6267\u884cop_array *\/<br \/>\nzend_execute(new_op_array TSRMLS_CC);<\/p>\n<p>\/\/PHPSRC\/Zend\/zend.c<\/p>\n<p>#define COMPILED_STRING_DESCRIPTION_FORMAT &#8220;%s(%d) : %s&#8221;<br \/>\nZEND_API char *zend_make_compiled_string_description(char *name TSRMLS_DC)<br \/>\n{<br \/>\nzend_spprintf(&amp;compiled_string_description, 0, COMPILED_STRING_DESCRIPTION_FORMAT, cur_filename, cur_lineno, name);<br \/>\nreturn compiled_string_description; \/\/\u8fd4\u56de\u503c\u5305\u542b&#8221;eval()&#8221;d code&#8221;\u5b57\u7b26\u4e32<br \/>\n}<\/p>\n<p>\/\/PHPSRC\/Zend\/zend_compile.c<\/p>\n<p>ZEND_API zend_op_array *(*zend_compile_string)(zval *source_string, char *filename TSRMLS_DC);<\/p>\n<p>zend_compile_string\u4e00\u4e2a\u51fd\u6570\u6307\u9488\u3002\u4e0b\u8fb9\u770b\u4e0b\u5f15\u64ce\u521d\u59cb\u5316\u7684\u65f6\u5019\u5bf9zend_compile_string\u7684\u64cd\u4f5c\u3002<\/p>\n<p>int zend_startup(zend_utility_functions *utility_functions, char **extensions, int start_builtin_functions)<br \/>\n{<br \/>\nzend_compile_string = compile_string; \/\/\u5bf9zend_compile_string\u51fd\u6570\u7684\u5730\u5740\u8d4b\u503c<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u53ea\u8981\u68c0\u67e5op_array\u4e2d\u662f\u5426\u542b\u6709&#8221;eval()&#8221;d code&#8221;\u5b57\u7b26\u4e32\uff0c\u5c31\u80fd\u5224\u65ad\u662f\u5426\u662f\u5728\u6267\u884ceval\u51fd\u6570\u3002<br \/>\n\u5728\u5f15\u64ce\u521d\u59cb\u5316\u7684\u65f6\u5019\uff0c\u9ed8\u8ba4\u4f1a\u5c06compile_string\u51fd\u6570\u7684\u5730\u5740\u8d4b\u503c\u7ed9zend_compile_string\uff0c<br \/>\ncompile_string\u51fd\u6570\u5219\u8fd4\u56de\u4e00\u4e2a\u6307\u5411zend_op_array\u7684\u6307\u9488\u3002\u5982\u679c\u80fd\u5728php\u4ee3\u7801\u7f16\u8bd1\u4e4b\u524d\u5bf9<br \/>\nzend_compile_string\u8fdb\u884c\u91cd\u5199\uff0c\u90a3\u4e48\u5c31\u80fd\u8fbe\u5230\u52ab\u6301\u7684\u76ee\u7684\u3002\u6839\u636ephp\u7684\u751f\u547d\u5468\u671f\uff0c\u5bf9<br \/>\nzend_compile_string\u8fdb\u884c\u91cd\u5199\u5e94\u8be5\u653e\u5728STARTUP\u6216\u8005ACTIVATION\u8fd9\u4e24\u4e2a\u9636\u6bb5\uff0c\u800c\u7f16\u5199php\u6269<br \/>\n\u5c55\u6240\u4f7f\u7528\u5230\u7684PHP_MINIT_FUNCTION\u548cPHP_RINIT_FUNCTION\u5b8f\u5c31\u5206\u522b\u5904\u5728STARTUP\u548cACTIVATION<br \/>\n\u8fd9\u4e2a\u4e24\u4e2a\u9636\u6bb5\uff0c\u8fd9\u662f\u4e3a\u4ec0\u4e48\u5462\uff1f\u6211\u4eec\u5148\u770b\u4e0bphp.h\u4ee3\u7801\u4e2d\u5bf9PHP_MINIT_FUNCTION\u5b8f\u7684\u5b9a\u4e49\u3002<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n#define PHP_MINIT_FUNCTION ZEND_MODULE_STARTUP_D<br \/>\n\/\/ZEND_MODULE_STARTUP_D\u5b9a\u4e49\u5728zend_API.h<br \/>\n#define ZEND_MODULE_STARTUP_D(module) int ZEND_MODULE_STARTUP_N(module)(INIT_FUNC_ARGS)<br \/>\n\/\/ZEND_MODULE_STARTUP_N\u5b9a\u4e49\u5728zend_API.h<br \/>\n#define ZEND_MODULE_STARTUP_N(module)\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 zm_startup_##module<br \/>\n\/\/INIT_FUNC_ARGS\u5b9a\u4e49\u5728zend_modules.h<br \/>\n#define INIT_FUNC_ARGS int type, int module_number TSRMLS_DC<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>PHP_MINIT_FUNCTION(module)\u7684\u539f\u578b\u5c31\u662f\uff1a<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nzm_startup_module(int type, int module_number TSRMLS_DC)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u540c\u6837\u7684PHP_RINIT_FUNCTION(module)\u7684\u539f\u578b\u4e3a:<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nzm_activate_module(int type, int module_number TSRMLS_DC)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u5173\u4e8e\u5bf9eval\u51fd\u6570\u8fd0\u884c\u53c2\u6570\u622a\u53d6\u5206\u6790\u7684\u5b9e\u73b0\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n#define OVECCOUNT 30<br \/>\n\/* \u5177\u4f53\u6b63\u5219\u8868\u8fbe\u5f0f\u8981\u6309\u7167\u5177\u4f53\u7684\u9700\u6c42\u6765\u5199\uff0c\u4e0b\u9762\u6b63\u5219\u4ec5\u4e3a\u6d4b\u8bd5\u7528 *\/<br \/>\n#define eval_regex_value\u00a0\u00a0 &#8220;(((chr\\(\\d*?\\)|base64_decode\\(|eval|gzinflate\\(|system|shell_exec|popen|pclose|proc_close|proc_get_status|proc_nice|proc_terminate|exec|passthru|show_source|escapeshellcmd|escapeshellarg system|shell_exec|popen|pclose|proc_open|proc_close|proc_get_status|proc_nice|proc_terminate|exec|passthru|show_source|escapeshellcmd|escapeshellarg)\\([{}&#8221;$\\w\\s]*?\\));).*?&#8221;<\/p>\n<p>static zend_op_array* (*old_compile_string)(zval *source_string, char *filename TSRMLS_DC);<br \/>\nstatic zend_op_array* safe_compile_string(zval *source_string, char *filename TSRMLS_DC);<\/p>\n<p>PHP_RINIT_FUNCTION(safe) \/\/PHP_MINIT_FUNCTION(safe)\u4e5f\u53ef<br \/>\n{<br \/>\nsafe_hook_execute();<br \/>\nreturn SUCCESS;<br \/>\n}<\/p>\n<p>PHP_RSHUTDOWN_FUNCTION(safe) \/\/PHP_MSHUTDOWN_FUNCTION(safe)\u4e5f\u53ef<br \/>\n{<br \/>\nsafe_unhook_execute();<br \/>\nreturn SUCCESS;<br \/>\n}<\/p>\n<p>int matchpattern(char *src, char *pattern, int i) \/\/\u6b63\u5219\u5339\u914d\u51fd\u6570<br \/>\n{<br \/>\npcre *re;<br \/>\nconst char *error;<br \/>\nint erroffset;<br \/>\nint ovector[OVECCOUNT];<br \/>\nint rc;<br \/>\nchar *substring_start;<br \/>\nint substring_length;<br \/>\nTSRMLS_FETCH();<\/p>\n<p>re = pcre_compile(pattern, PCRE_CASELESS|PCRE_DOTALL, &amp;error, &amp;erroffset, NULL);<br \/>\nif(re == NULL) {<br \/>\n\/\/printf(&#8220;PCRE compilation failed at offset %d: %s<br \/>\n&#8220;, erroffset, error);<br \/>\nreturn 1;<br \/>\n}<\/p>\n<p>rc = pcre_exec(re, NULL, src, strlen(src), 0, 0, ovector, OVECCOUNT);<br \/>\nif(rc &gt;= 0) {<br \/>\nsubstring_start = src + ovector[2*i];<br \/>\nsubstring_length = ovector[2*i+1] &#8211; ovector[2*i];<\/p>\n<p>printf(&#8220;Match_result: %.*s<br \/>\n&#8220;, substring_length, substring_start);<br \/>\nprintf(&#8220;Filename\u00a0\u00a0\u00a0 : %-40s<br \/>\n&#8220;, zend_get_executed_filename(TSRMLS_C));<br \/>\nprintf(&#8220;Line\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : %-50i<br \/>\n&#8220;, zend_get_executed_lineno(TSRMLS_C));<br \/>\n}<br \/>\nfree(re);<br \/>\nreturn rc;<br \/>\n}<\/p>\n<p>static zend_op_array *safe_compile_string(zval *source_string, char *filename TSRMLS_DC)<br \/>\n{<br \/>\nchar *eval_strings;<br \/>\nint x;<br \/>\nzend_op_array *op_array;<\/p>\n<p>op_array = old_compile_string(source_string, filename TSRMLS_CC);<\/p>\n<p>\/* \u8fc7\u6ee4\u975eeval\u51fd\u6570 *\/<br \/>\nif(!strstr(op_array-&gt;filename, &#8220;eval()&#8221;d code&#8221;)) {<br \/>\nreturn old_compile_string(source_string, filename TSRMLS_CC);<br \/>\n}<br \/>\n\/* \u5c06source_string\u5b57\u7b26\u4e32\u8d4b\u503c\u7ed9eval_strings *\/<br \/>\neval_strings = estrndup(Z_STRVAL_P(source_string), Z_STRLEN_P(source_string));<\/p>\n<p>printf(&#8220;%s&#8221;,&#8221;<br \/>\n&#8220;);<br \/>\nprintf(&#8220;Function\u00a0\u00a0\u00a0 : %-40s<br \/>\n&#8220;, &#8220;eval&#8221;);<br \/>\nx = matchpattern(eval_strings, eval_regex_value, 1);<br \/>\nif (x &lt; 0)<br \/>\n{<br \/>\nreturn old_compile_string(source_string, filename TSRMLS_CC);<br \/>\n}<br \/>\nelse if(x &gt;= 0)<br \/>\nreturn FALSE;<br \/>\n}<\/p>\n<p>int safe_hook_execute()<br \/>\n{<br \/>\nold_compile_string = zend_compile_string;<br \/>\nzend_compile_string = safe_compile_string;<br \/>\nsystem_hook_system();\u00a0 \/\/\u5bf9\u5e94\u540e\u8fb9\u5bf9system\u51fd\u6570\u7684\u64cd\u4f5c<br \/>\nreturn TRUE;<br \/>\n}<\/p>\n<p>int safe_unhook_execute()<br \/>\n{<br \/>\nzend_compile_string = old_compile_string;<br \/>\nreturn TRUE;<br \/>\n}<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>4.2 system\u51fd\u6570\u4ee3\u7801\u5206\u6790\u4e0e\u4ee3\u7801\u5b9e\u73b0<\/p>\n<p>\u9996\u5148\u6211\u4eec\u770bphp\u6e90\u4ee3\u7801\u4e2dsystem\u51fd\u6570\u662f\u5982\u4f55\u5b9e\u73b0\u7684\uff0c\u90e8\u5206\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n\/\/PHPSRCextstandardexec.c<\/p>\n<p>PHP_FUNCTION(system)<br \/>\n{<br \/>\n\/* \u8c03\u7528php_exec_ex\u51fd\u6570 *\/<br \/>\nphp_exec_ex(INTERNAL_FUNCTION_PARAM_PASSTHRU, 1);<br \/>\n}<\/p>\n<p>static void php_exec_ex(INTERNAL_FUNCTION_PARAMETERS, int mode)<br \/>\n{<br \/>\nchar *cmd;<\/p>\n<p>if (!ret_array) {<br \/>\n\/* \u8c03\u7528php_exec\u51fd\u6570 *\/<br \/>\nret = php_exec(mode, cmd, NULL, return_value TSRMLS_CC);<br \/>\n} else {<br \/>\nif (Z_TYPE_P(ret_array) != IS_ARRAY) {<br \/>\nzval_dtor(ret_array);<br \/>\narray_init(ret_array);<br \/>\n}<br \/>\nret = php_exec(2, cmd, ret_array, return_value TSRMLS_CC);<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u63a5\u4e0b\u6765\u770bphp_exec\u51fd\u6570\u7684\u5b9a\u4e49\u3002<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nint php_exec(int type, char *cmd, zval *array, zval *return_value TSRMLS_DC)<br \/>\n{<br \/>\nchar *cmd_p, *b, *c, *d=NULL;<\/p>\n<p>if (PG(safe_mode)) {<br \/>\ncmd_p = php_escape_shell_cmd(d);<br \/>\nefree(d);<br \/>\nd = cmd_p;<br \/>\n} else {<br \/>\ncmd_p = cmd;<\/p>\n<p>#ifdef PHP_WIN32<br \/>\nfp = VCWD_POPEN(cmd_p, &#8220;rb&#8221;); \/\/\u8c03\u7528VCWD_POPEN\u51fd\u6570<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u63a5\u4e0b\u6765\u770bVCWD_POPEN\u51fd\u6570\u7684\u5b9a\u4e49\u3002<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n\/\/TSRM srm_virtual_cwd.c<\/p>\n<p>#ifdef TSRM_WIN32 \/\/\u4ee5windows\u5e73\u53f0\u4e3a\u4f8b<\/p>\n<p>CWD_API FILE *virtual_popen(const char *command, const char *type TSRMLS_DC)<br \/>\n{<br \/>\nreturn popen_ex(command, type, CWDG(cwd).cwd, NULL);\/\/\u8c03\u7528popen_ex\u51fd\u6570<br \/>\n}<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u63a5\u4e0b\u6765\u770bpopen_ex\u51fd\u6570\u7684\u5b9a\u4e49\u3002<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n\/\/TSRM srm_win32.c<\/p>\n<p>TSRM_API FILE *popen_ex(const char *command, const char *type, const char *cwd, char *env)<br \/>\n{<br \/>\nchar *cmd;<\/p>\n<p>cmd = (char*)malloc(strlen(command)+strlen(TWG(comspec))+sizeof(&#8221; \/c &#8220;));<br \/>\nsprintf(cmd, &#8220;%s \/c %s&#8221;, TWG(comspec), command);<br \/>\nif (!CreateProcess(NULL, cmd, &amp;security, &amp;security, security.bInheritHandle, NORMAL_PRIORITY_CLASS|CREATE_NO_WINDOW, env, cwd, &amp;startup, &amp;process)) {<br \/>\nreturn NULL;<br \/>\n}<br \/>\nfree(cmd);<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u4e0a\u8fb9\u662fsystem\u51fd\u6570\u6267\u884c\u7684\u53c2\u6570\u4f20\u9012\u7684\u8fc7\u7a0b\uff0c\u5728\u8fd9\u4e2a\u8fc7\u7a0b\u4e2d\u5982\u679c\u53ef\u4ee5\u622a\u53d6\u51fd\u6570\u6267\u884c\u7684\u53c2\u6570<br \/>\n\u7684\u8bdd\uff0c\u5c31\u53ef\u4ee5\u5206\u6790\u53c2\u6570\u662f\u5426\u5305\u542b\u5371\u9669\u7684\u5173\u952e\u5b57\u3002\u4e3a\u4e86\u65b9\u4fbf\u7f16\u5199\u6269\u5c55\u7a0b\u5e8f\uff0c\u6211\u4eec\u76f4\u63a5\u5728exec.c<br \/>\n\u4e2dphp_exec\u51fd\u6570\u4e2d\u6dfb\u52a0\u622a\u53d6\u4ee3\u7801\uff0c\u4e5f\u5c31\u662f\u5728php_exec_ex\u51fd\u6570\u8c03\u7528php_exec\u51fd\u6570\u4e4b\u524d\u7684\u4f4d\u7f6e\u3002<br \/>\n\u6dfb\u52a0\u5982\u4e0b\u4ee3\u7801\u5373\u53ef\u83b7\u53d6\u6267\u884c\u7684\u53c2\u6570\uff1a<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nx = matchpattern(cmd, system_regex_value, 0);\/\/\u8c03\u7528\u6b63\u5219\u51fd\u6570\u8fdb\u884c\u5224\u65ad<br \/>\nif(x &gt;= 0) RETURN_FALSE;<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u4e0b\u8fb9\u6211\u4eec\u5206\u6790\u600e\u4e48\u5b9e\u73b0\u5bf9system\u51fd\u6570\u7684\u91cd\u5199\uff0c\u8fd9\u91cc\u4e3b\u8981\u53c2\u7167main.c\u6587\u4ef6\u4e2d\u5b9e\u73b0php.ini<br \/>\n\u4e2ddisable_functions\u529f\u80fd\u7684php_disable_functions\u51fd\u6570\uff0c\u5b83\u8c03\u7528\u4e86zend_disable_function\u3002<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nZEND_API int zend_disable_function(char *function_name, uint function_name_length TSRMLS_DC)<br \/>\n{<br \/>\nif (zend_hash_del(CG(function_table), function_name, function_name_length+1)==FAILURE) {<br \/>\nreturn FAILURE;<br \/>\n}<br \/>\ndisabled_function[0].fname = function_name;<br \/>\nreturn zend_register_functions(NULL, disabled_function, CG(function_table), MODULE_PERSISTENT TSRMLS_CC);<br \/>\n}<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u540c\u6837\u6211\u4eec\u53ef\u4ee5\u7528zend_hash_del\u51fd\u6570\u5c06system\u4ecefunction_table\u4e2d\u5220\u9664\uff0c\u7136\u540e\u6ce8\u518c\u65b0\u7684<br \/>\nzend\u51fd\u6570\uff0c\u4ee5\u8fbe\u5230\u5bf9system\u51fd\u6570\u52ab\u6301\u7684\u76ee\u7684\u3002<\/p>\n<p>system\u4f5c\u4e3a\u4e00\u4e2a\u6267\u884c\u7cfb\u7edf\u547d\u4ee4\u7684\u51fd\u6570\uff0c\u5728\u8fd9\u91cc\u8fdb\u884c\u4e86\u7981\u7528\u64cd\u4f5c\uff0c\u6ca1\u6709\u4f7f\u7528\u6b63\u5219\u5904\u7406\u51fd\u6570<br \/>\n\u8fdb\u884c\u53c2\u6570\u7684\u68c0\u67e5\uff0c\u5f53\u7136\u4e5f\u53ef\u4ee5\u6839\u636e\u5177\u4f53\u7684\u9700\u6c42\u8fdb\u884c\u5177\u4f53\u7684\u64cd\u4f5c\u3002<\/p>\n<p>\u5b9e\u73b0\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n<p>&#8211;code&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n\/* \u58f0\u660e\u5bfc\u51fa\u51fd\u6570 *\/<br \/>\nPHP_FUNCTION(system1)<br \/>\n{<br \/>\nprintf(&#8220;%s&#8221;,&#8221;<br \/>\n&#8220;);<br \/>\nprintf(&#8220;Function\u00a0\u00a0\u00a0 : %-40s<br \/>\n&#8220;, &#8220;system&#8221;);<br \/>\nprintf(&#8220;Filename\u00a0\u00a0\u00a0 : %-40s<br \/>\n&#8220;, zend_get_executed_filename(TSRMLS_C));<br \/>\nprintf(&#8220;Line\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : %-50i<br \/>\n&#8220;, zend_get_executed_lineno(TSRMLS_C));<br \/>\nprintf(&#8220;%s&#8221;,&#8221;system function is disabled.&#8221;);<br \/>\n}<\/p>\n<p>\/* \u58f0\u660e Zend \u51fd\u6570\u5757 *\/<br \/>\nzend_function_entry hook_system_functions[] = {<br \/>\nPHP_FALIAS(system, system1, NULL) \/\/ \u521b\u5efasystem\u522b\u540d<br \/>\n{NULL, NULL, NULL}<br \/>\n};<\/p>\n<p>\/* \u521b\u5efasystem hook\u51fd\u6570 *\/<br \/>\nint safe_hook_system()<br \/>\n{<br \/>\nTSRMLS_FETCH();<br \/>\n\/* \u5220\u9664function_table\u4e2d\u7684system\u51fd\u6570 *\/<br \/>\nzend_hash_del(CG(function_table), &#8220;system&#8221;, sizeof(&#8220;system&#8221;));<\/p>\n<p>\/* \u6ce8\u518c\u65b0zend\u51fd\u6570 *\/<br \/>\n#ifndef ZEND_ENGINE_2<br \/>\nzend_register_functions(hook_system_functions, NULL, MODULE_PERSISTENT TSRMLS_CC);<br \/>\n#else<br \/>\nzend_register_functions(NULL, hook_system_functions, NULL, MODULE_PERSISTENT TSRMLS_CC);<br \/>\n#endif<br \/>\nreturn 0;<br \/>\n}<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>4.3 demo\u8fd0\u884c\u6548\u679c<\/p>\n<p>4.3.1 \u52a0\u8f7dphp\u6269\u5c55<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nC:phpext&gt;type php.ini | findstr &#8220;^extension=&#8221;<br \/>\nextension=php_safe.dll<\/p>\n<p>C:phpext&gt;php 3.php<\/p>\n<p>Function\u00a0\u00a0\u00a0 : system<br \/>\nFilename\u00a0\u00a0\u00a0 : C:phpext3.php<br \/>\nLine\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : 3<\/p>\n<p>system function is disabled.<\/p>\n<p>Function\u00a0\u00a0\u00a0 : eval<br \/>\nMatch_result: exec(&#8220;ver&#8221;);<br \/>\nFilename\u00a0\u00a0\u00a0 : C:phpext3.php<br \/>\nLine\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 : 9<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>4.3.2 \u4e0d\u52a0\u8f7dphp\u6269\u5c55<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nC:phpext&gt;type php.ini | findstr &#8220;^extension=&#8221;<\/p>\n<p>C:phpext&gt;php 3.php<\/p>\n<p>Microsoft Windows XP [\u7248\u672c 5.1.2600]<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>\u4e94\u3001\u603b\u7ed3<\/p>\n<p>\u5b9e\u73b0php webshell\u7684\u529f\u80fd\u6027\u51fd\u6570\u4f17\u591a\uff0c\u6211\u4eec\u505a\u5230\u63a7\u5236\u5173\u952e\u6027\u7684\u51fd\u6570\u8db3\u4ee5\u3002\u5f53\u7136\u5b9e\u73b0\u51fd\u6570<br \/>\n\u622a\u53d6\u8981\u6839\u636e\u51fd\u6570\u7684\u60c5\u51b5\u8fdb\u884c\u4e00\u4e00\u7684\u5206\u6790\uff0c\u7136\u540e\u505a\u76f8\u5e94\u7684\u5224\u65ad\u3002<\/p>\n<p>\u6700\u540e\u8981\u611f\u8c22\u4e0bSuperHei\uff0c\u6587\u7ae0\u4e0d\u8db3\u4e4b\u5904\u8bf7\u65a7\u6b63\u3002<\/p>\n<p>\u516d\u3001\u53c2\u8003\u8d44\u6599<\/p>\n<p>[1] php\u6e90\u4ee3\u7801\u00a0 http:\/\/www.php.net<br \/>\n[2] PHP Extension Writing http:\/\/talks.somabo.de\/200903_montreal_php_extension_writing.pdf<\/p>\n<p>-EOF-<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By \u5496\u5561(k4kup8_0x4154_gmail.com) [\u76ee\u5f55] 1. \u7b80 &hellip;<\/p>\n<p class=\"read-more\"><a href=\"http:\/\/zerobox.org\/notes\/400.html\">\u7ee7\u7eed\u9605\u8bfb &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[56,132],"class_list":["post-400","post","type-post","status-publish","format-standard","hentry","tag-php","tag-webshell"],"views":858,"_links":{"self":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts\/400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/comments?post=400"}],"version-history":[{"count":0,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/posts\/400\/revisions"}],"wp:attachment":[{"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/media?parent=400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/categories?post=400"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/zerobox.org\/notes\/wp-json\/wp\/v2\/tags?post=400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}