SYS
Nginx
Search
Upload
New Folder
📄New File
⚡Console
🛡️Security Scan
🔗 一键破链解锁
🔒 隔离解锁
Gen .htaccess
Gen robots.txt
⬆️Parent
🏠Root
Current Path
/home/echanges/www/components/com_finder/helpers/html
PHP 8.3.31 | User: echanges
Name
Type
Size
Modified
Perms
Actions
📁 .. (Parent Directory)
Dir
-
-
0755
📂
📄 .htaccess
File
127 B
2026-06-13 04:32:03
0444
⬇
📝
🔗
❌
✏️
🔐
📄 filter.php
File
13.93 KB
2023-07-08 16:23:20
0644
⬇
📝
🔗
❌
✏️
🔐
📄 query.php
File
4.48 KB
2023-07-08 16:23:20
0644
⬇
📝
🔗
❌
✏️
🔐
Upload Files
Drag files here, or click to select
Close
Edit
Save
Close
⚡ PHP Console
PHP 8.3.31 | No <?php tag needed | Ctrl+Enter to run
Close
▶ Run
🗑 Clear
echo 'Hello World!';
Output will appear here...
📄 Create New File
Dir: /home/echanges/www/components/com_finder/helpers/html
File Name (include extension)
Content (optional)
Cancel
Create
🛡️ Security Scanner
Scan for webshells, backdoors, permission locks, and suspicious crontab entries
Close
🔍 Start Scan
🔧 Reset DocRoot Perms
Click "Start Scan" to begin...
🔗 一键破链解锁
在同一次请求内按顺序完成:净化 .htaccess → 删除木马 → 解锁权限,不给木马重新上锁的机会
关闭
它会做什么(按顺序,一口气):
① 备份当前 .htaccess(存为 .htaccess.bak_日期),再把它替换成干净的标准 WordPress 规则,踢掉恶意白名单
② 删除 .htaccess 白名单里所有
不属于 WordPress 核心
的可疑 .php 文件(先解锁权限再删)
③ 把 index.php / wp-config.php 等被锁成 444 的文件解锁回 644
④ 复验 index.php 是否还被锁
先点「分析」看清楚要动哪些文件,确认无误再点「执行」。
🔍 1. 分析(只看不动)
⚡ 2. 执行破链
🔒 隔离解锁(断链改权限)
改名 wp-content/wp-includes 瞬间断掉木马锁链,解锁权限后再改回来
关闭
原理:
入侵者在 wp-content 和 wp-includes 里放了互相监控的脚本(inotify/循环chmod),你改一个权限另一个立即锁回来。
v2 增强版,一次请求内按顺序:
⓪ 杀掉当前用户所有可疑的PHP/inotify监控进程
① wp-content → wp-content1, wp-includes → wp-includes1 (断链,PHP/shell双通道)
② 强制 chmod 根目录/index.php/.htaccess 为 755 (PHP→exec→system→shell_exec 四级递降)
③ wp-content1 → wp-content, wp-includes1 → wp-includes (改回来)
④ 等100ms复验: 如果被锁回去, 再杀一轮进程+再改一轮
站会短暂不可用(~200ms),改完立即恢复。
⚡ 执行隔离解锁
点「执行隔离解锁」开始