WordPress 中的奇怪条目“Admin_Panel.php”文件?
我刚刚将 WordPress 安装从一台服务器迁移到另一台客户端(我设置和管理的客户端网站),作为预防措施,我仔细阅读了“主题 >”。在 WordPress 管理面板中编辑列出的文件只是为了检查旧服务器/域的任何链接并尝试清理所有内容。
当我到达“admin_panel.php”文件时,我在文件的最底部找到了这个条目(这是最后一个条目):
function rating() { $pshow = "
"; 回显 $pshow; 。
现在,我不确定我为客户修改的主题来自哪里,正如他提供的那样,但这只是......奇怪
需要注意的是,admin_panel.php 文件用于后端主题设置部分,因此公众看不到它。我也找不到任何反映此条目的内容,但我又不确定我会。
我不是编码员,所以我想我只是看看是否有人对此有任何意见。这可能是主题编码器包含的内容吗?或者我应该盘问我的客户他从哪里获得这个主题,看看他是否从某个可疑的网站获得它?
我只是真的不熟悉 PHP,虽然就站点安全而言这看起来无害,但我想我应该确保一下。
我确实删除了该条目,一切看起来都很好,但安全总比后悔好,对吧?
谢谢!
I just migrated a Wordpress install from one of my servers to another for a client (client's website which I set up and manage) and as a precautionary measure, I was perusing the 'Theme > Edit' listed files in the Wordpress Admin panel just to check for any links to the old server/domain and try to clean everything up.
When I got to the 'admin_panel.php' file, I found this entry at the very bottom of the file (it was the last entry):
function ranking() {
$pshow = " <span style='display:none;'><a href='http://www.ellelive.com/'>Live sex</a> , <a href='http://www.2.livejasmin.com/listpage.php?psid=elenaa'>webcam sex</a> , <a href='http://www.2.livejasmin.com/listpage.php?tags=mature&psid=elenaa'>Mature Female</a> , <a href='http://www.2.livejasmin.com/freechat.php?random&psid=elenaa'>Livejasmin</a> , <a href='http://www.2.livejasmin.com/listpage.php?tags=girl&psid=elenaa'>Girl</a></span>";
echo $pshow;
}
Now, I'm not sure where the theme that I modified for the client came from, as he supplied it, but this is just... odd.
To note, the admin_panel.php file is for the backend theme settings section, so it isn't seen by the public. I also couldn't find anything in there that reflects this entry, but then again I'm not sure I would.
I'm not a coder, so I figured I would just see if anyone had any input on this. Is this likely something that was included by the theme coder? Or should I grill my client about where he sourced this theme and see if he got it from some shady website?
I'm just really unfamiliar with PHP, and while this looks harmless as far as site security is concerned, I figured I'd make sure.
I did remove the entry and everything seems fine, but better safe than sorry, right?
Thanks!
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
制作该模板的人(我猜是“elenaa”)在其中添加了一些隐藏链接,以提高这些网站的谷歌排名。如果您担心的话,请将函数替换为以下内容。
如果您只是删除它,您可能会遇到缺少功能的错误。
尽管该函数位于管理部分,是否可以在网站前端的某个位置调用该函数?
Whoever has made the template ( I presume "elenaa") chucked some hidden links in there to increase the google rankings of these websites. Replace the function with the following if your worried about it.
If you just delete it you could get missing function errors.
Although the function is in the admin section is it possible the function could be called somewhere on the front end of the website?
另一个可能的问题:如果您对文件设置了错误的权限,这种情况就会经常发生 - 如果它位于文件的最底部,则尤其如此。
我让垃圾邮件发送者在我的 WP 版本上运行脚本,检查页面权限是否设置不正确,如果是,脚本将在文件末尾写入一些异地链接。这很好而且很有效,因为垃圾邮件发送者可以提高 Google 排名,而大多数人却永远不会明智。
我会密切关注您的文件权限,并检查这些神秘链接是否在几个月后返回。
Another possible issue: this is something that happens fairly frequently if you have the wrong permissions set on your files - this is especially true if it's at the very bottom of the file.
I've had spammers run scripts on my WP builds that will check to see if the page permissions are set incorrectly, and if they are, the script will write in some links off-site at the very end of the file. This is nice and effective because the spammer gets a Google rankings boost, and most people are never the wiser.
I'd keep an eye on your file permissions, and check back to see if these mysterious links have returned in a couple of months.