Web 2.0
server:iis6+asp.net
Phenomenon: ali cloud alarm irregularities said website url, using a mobile phone browser Google browser simulation baidu spider on a cell phone or PC mode access http://www.xxxxx.com/dvo/2020/11/28/76006.aspx (note: can't find in the site directory with dvo/2020/11/28/76006. Aspx corresponding folders and files), the browser will automatically jump to http://dbl28.xyz, but with normal mode access PC browser, do not jump, will show website prompt "this url does not exist,"
Processing: use anti-virus software, firewall software and killing the Trojan software on the system and check website directory file, no problem, then in the web. Config file & lt; HttpModules> Can find a para code & lt; Add name="System. Web. Handlers. Security" type="System. Web. Handlers. Security, System. Web. Handlers, Version=2.0.0.0 you are, Culture=neutral, PublicKeyToken=0 e3c508d5f680cc3"/& gt; , deleted, and then go to http://www.xxxxx.com/dvo/2020/11/28/76006.aspx, the browser doesn't jump, will show website prompt "this url does not exist,"
Problem: the web. Config suspicious code is how to jump to http://www.xxxxx.com/dvo/2020/11/28/76006.aspx http://dbl28.xyz? http://dbl28.xyz this address should be saved in a file server, how to find the file?
CodePudding user response:
All code search again seeCodePudding user response:
Search, and replace with local script, didn't find this address at http://dbl28.xyz