国内流行的内容管理系统(CMS)多端全媒体解决方案 https://www.dedebiz.com
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

84 lines
3.6KB

  1. <!DOCTYPE html>
  2. <html>
  3. <head>
  4. <meta charset="<?php echo $cfg_soft_lang; ?>">
  5. <meta http-equiv="X-UA-Compatible" content="IE=Edge,chrome=1">
  6. <title>木马自检程序</title>
  7. <link rel="stylesheet" href="../static/web/css/bootstrap.min.css">
  8. <link rel="stylesheet" href="../static/web/font/css/font-awesome.min.css">
  9. <link rel="stylesheet" href="../static/web/css/admin.css">
  10. <link rel="stylesheet" href="css/indexbody.css">
  11. <script language="javascript" src="../static/web/js/jquery.min.js"></script>
  12. <script language='javascript' src='js/main.js'></script>
  13. <script language="javascript" src="../static/web/js/webajax.js"></script>
  14. <script language='javascript'>
  15. function LoadCtTest() {
  16. var filetype = $Obj('filetype').value;
  17. var info = $Obj('info').value;
  18. $Obj('loaddiv').style.display = 'block';
  19. fetch('sys_safetest.php?action=test&filetype=' + filetype + "&info=" + info).then(resp=>{
  20. if (resp.ok) {
  21. return resp.text()
  22. }
  23. throw new Error('系统错误,无法获取数据');
  24. }).then((d)=>{
  25. $DE('messagetd').innerHTML = d;
  26. $Obj('loaddiv').style.display = 'none';
  27. }).catch((error) => {
  28. console.log(error);
  29. });
  30. }
  31. function LoadCtClear() {
  32. $Obj('loaddiv').style.display = 'block';
  33. fetch('sys_safetest.php?action=clear').then(resp=>{
  34. if (resp.ok) {
  35. return resp.text()
  36. }
  37. throw new Error('系统错误,无法获取数据');
  38. }).then((d)=>{
  39. $DE('messagetd').innerHTML = d;
  40. $Obj('loaddiv').style.display = 'none';
  41. }).catch((error) => {
  42. $DE('messagetd').innerHTML = errMsg;
  43. });
  44. }
  45. </script>
  46. </head>
  47. <body>
  48. <div id="loaddiv" style="display:none">
  49. <p align="center" style="padding-top:200px"><img src="../static/web/img/loadinglit.gif">请稍后,正在操作中</p>
  50. </div>
  51. <?php echo $alter; ?>
  52. <table width="98%" cellpadding="1" cellspacing="1" align="center" class="table maintable mt-3 mb-3">
  53. <tr>
  54. <td width="100%" height="26" colspan="2" background="../static/web/img/tbg.gif" style="padding-left:10px">木马自检程序</td>
  55. </tr>
  56. <tr>
  57. <td height="73" colspan="2">
  58. 安全建议:<br>
  59. 1、有条件的用户把data、system、theme修改为不可对外访问,static、a目录设置为不允许执行脚本,其它目录禁止写入,系统将更安全;<br>
  60. 2、本检测程以开发模式为标准,如果您的网站目录包含其它系统,此检测程序可能会产生错误判断;<br>
  61. 3、检测程序会跳过对模板缓存目录的检测,为了安全起见,检测完成后建议清空模板缓存
  62. </td>
  63. </tr>
  64. <tr>
  65. <td height="50" colspan="2">
  66. <p>文件类型:<input name="filetype" type="text" id="filetype" value="php|inc" style="width:420px">&nbsp;要检查的文件类型</p>
  67. <p>代码特征:<input name="info" type="text" id="info" value="eval|cmd|system|exec|_GET|_POST|_REQUEST|base64_decode" style="width:420px">&nbsp;特征代码</p>
  68. </td>
  69. </tr>
  70. <tr>
  71. <td colspan="2" align="center" class="py-3">
  72. <button type="button" name="bt1" class="btn btn-success btn-sm" onclick="LoadCtTest();">开始检测</button>
  73. <button type="button" name="bt2" class="btn btn-success btn-sm" onclick="LoadCtClear();">清空模板缓存</button>
  74. </td>
  75. </tr>
  76. <tr>
  77. <td height="26" colspan="2" bgcolor="#f8f8f8">检测结果:结果仅供参考,请务必查看源码后才删除非法文件</td>
  78. </tr>
  79. <tr>
  80. <td height="360" colspan="2" id="messagetd" valign="top"></td>
  81. </tr>
  82. </table>
  83. </body>
  84. </html>