云服务器被非法域名恶意指向
Last updated
2023-03-29 10:52:53
{"value":"### \u80cc\u666f\n\n\u4e91\u670d\u52a1\u5668\u88ab\u975e\u6cd5\u57df\u540d\u6076\u610f\u6307\u5411\uff0c\u5de5\u4fe1\u90e8\u626b\u63cf\u5230\u4e4b\u540e\uff0c\u4e5f\u4f1a\u5bf9\u8be5\u4e91\u670d\u52a1\u5668\u8fdb\u884c\u5904\u7f5a\uff0c\u8fd9\u6837\u5c31\u4f1a\u5e26\u6765\u65e0\u8c13\u7684\u635f\u5931\uff0c\u4f46\u4efb\u4f55\u4e00\u53f0\u4e91\u670d\u52a1\u5668\uff0c\u76ee\u524d\u90fd\u65e0\u6cd5\u907f\u514d\u8fd9\u4e2a\u73b0\u8c61\u3002\n\n### \u539f\u7406\n\n\u5982\u679c\u4e00\u4e2a\u975e\u6cd5\u57df\u540d\u6307\u5411\u5230\u67d0\u53f0\u670d\u52a1\u5668\uff0c\u800c\u8be5\u670d\u52a1\u5668\u4e0a\u5b58\u5728\u7740\u7a7a\u4e3b\u673a\u5934\u7684\u7ad9\u70b9\uff0c\u8fd9\u65f6\u5019\u4f7f\u7528\u8be5\u57df\u540d\u8bbf\u95ee\uff0c\u6548\u679c\u662f\u548c\u4f7f\u7528 IP \u8bbf\u95ee\u662f\u4e00\u81f4\u7684\uff0cWeb \u670d\u52a1\u5668\u4f1a\u81ea\u52a8\u7684\u5c06\u8bf7\uff08Request\uff09\u5206\u914d\uff08Dispatch\uff09\u5230\u7a7a\u4e3b\u673a\u5934\u7684\u7ad9\u70b9\u4e0a\uff0c\u8fd9\u6837\u5c31\u4f7f\u5f97\u975e\u6cd5\u6307\u5411\u7684\u6076\u610f\u57df\u540d\u6709\u4e86\u53ef\u8bbf\u95ee\u6027\uff0c\u88ab\u5de5\u4fe1\u90e8\u626b\u63cf\u5230\u4e4b\u540e\uff0c\u53d7\u635f\u5931\u7684\u662f\u8be5\u4e91\u670d\u52a1\u5668\u7684\u5ba2\u6237\u548c\u8be5\u5ba2\u6237\u7684\u670d\u52a1\u5546\u3002\n\n### \u89e3\u51b3\u65b9\u6cd5\n\n\u6587\u6863\u63d0\u4f9b\u4ee5\u4e0b\u51e0\u79cd\u7c7b\u578b\u7684 web \u670d\u52a1\u89e3\u51b3\u65b9\u5f0f\uff1a\n\n**\u00b7**IIS\n\n**\u00b7**Nginx\n\n**\u00b7**Tomcat\n\n**\u00b7**Apache\n\n#### IIS \u914d\u7f6e\u65b9\u6cd5\n1.\u67e5\u770b\u662f\u5426\u7ed1\u5b9a\u4e3b\u673a\u5934\uff0c\u5982\u4ee5\u4e0b\u622a\u56fe\u4e3b\u673a\u540d\u4e3a\u7a7a\uff0c\u5219\u8868\u793a\u672a\u7ed1\u5b9a\u4e3b\u673a\u540d\u3002\n\n![image](http:\/\/156.248.76.32:4999\/server\/index.php?s=\/api\/attachment\/visitFile&sign=13b25f02240beac76dc464fbfbaec797)\n\n\n2.\u914d\u7f6e IIS \u7f51\u7ad9\u7ed1\u5b9a\u4e3b\u673a\u540d\n![](http:\/\/156.248.76.32:4999\/server\/index.php?s=\/api\/attachment\/visitFile&sign=c753eeb93e5750a19c3c02f314501d0c)\n\n\n3.\u9a8c\u8bc1\u53ea\u80fd\u901a\u8fc7\u7ed1\u5b9a\u7684\u57df\u540d\u8bbf\u95ee\uff0c\u5176\u4ed6\u65b9\u5f0f\u65e0\u6cd5\u8bbf\u95ee\u7f51\u7ad9\u9875\u9762\u5373\u53ef\u3002\n\n#### Nginx \u914d\u7f6e\u65b9\u6cd5\n1.\u9996\u5148\u6253\u5f00 nginx \u57df\u540d\u914d\u7f6e\u6587\u4ef6\u5b58\u653e\u76ee\u5f55\uff1a\/etc\/nginx\/nginx.conf\n\n>\u8bf4\u660e\uff1a\n\u4e0d\u540c\u5b89\u88c5\u65b9\u5f0f nginx \u8def\u5f84\u53ef\u80fd\u4e0d\u540c\uff0c\u4f46\u914d\u7f6e\u6587\u4ef6\u5199\u6cd5\u4e00\u6837\u3002\n\n2.\u914d\u7f6e\u9ed8\u8ba4\u7ad9\u70b9\u7981\u6b62 IP \u5730\u5740\u8bbf\u95ee\u3002\n\n\tserver {\n\t listen 80 default_server;\n\t listen [::]:80 default_server;\n\t server_name _;\n\t return 403;\n\t}\n\n3.\u914d\u7f6e\u7f51\u7ad9\u7ed1\u5b9a\u4e3b\u673a\u5934\u3002\n\n\tserver\n\t\t{\n\t\t\tlisten 80;\n\t\t\tserver_name www.server.com; # \u7ed1\u5b9a\u57df\u540d\n\t\t\tindex index.htm index.html index.php; # \u9ed8\u8ba4\u6587\u4ef6\n\t\t\troot \/var\/www\/html\/server\/; # \u7f51\u7ad9\u6839\u76ee\u5f55\n\t\t\tinclude location.conf; # \u8c03\u7528\u5176\u4ed6\u89c4\u5219\uff0c\u4e5f\u53ef\u53bb\u9664\n\t\t}\n4.\u91cd\u542f nginx \u670d\u52a1\u5668\uff0c\u9a8c\u8bc1\u8bbf\u95ee\u6548\u679c\u3002\n\n\u4f7f\u7528 IP \u8bbf\u95ee\u6548\u679c:\n\n![](http:\/\/156.248.76.32:4999\/server\/index.php?s=\/api\/attachment\/visitFile&sign=b50291f104f5ec53a4f8d3dab0b4af87)\n\n#### Tomcat \u914d\u7f6e\u65b9\u6cd5\n1.\u4fee\u6539 **$TOMCAT_HOME\/conf** \u76ee\u5f55\u4e0b\u7684 **server.xml** \u6587\u4ef6\n\n\t<Engine name=\"Catalina\" defaultHost=\"\u4f60\u7684\u9ed8\u8ba4\u542f\u52a8\u57df\u540d\">\n\n\n\n>\u8bf4\u660e\uff1a\n>\u4e0a\u9762\u8fd9\u884c\u7684\u610f\u601d\u662f\u901a\u8fc7 IP \u76f4\u63a5\u8bbf\u95ee\u7684\u662f\u4f60\u7684\u9ed8\u8ba4\u542f\u52a8\u57df\u540d\u6240\u6307\u5411\u7684\u76ee\u5f55\u3002 \uff08\u5728\u6b64\u8bf7\u628a\u9ed8\u8ba4\u542f\u52a8\u57df\u540d\u6307\u5411\u4e00\u4e2a\u4e0d\u5b58\u5728\u7684\u8def\u5f84\uff0c\u8fd9\u6837\u5f53\u6076\u610f\u57df\u540d\u6307\u5411\u65f6\u7cfb\u7edf\u8fd4\u56de 404 \u9519\u8bef\u3002\uff09\n\n\n\n\t<Host name=\"\u4f60\u7684\u57df\u540d\" appBase=\"\u9879\u76ee\u5728\u786c\u76d8\u7684\u7269\u7406\u4f4d\u7f6e,\u4f8b\u5982: \/home\/wwwRoot\"\n\t unpackWARs=\"true\" autoDeploy=\"true\"\n\t xmlValidation=\"false\" xmlNamespaceAware=\"false\">\n\t\t<Context path=\"\" docBase=\"\u9879\u76ee\u5728\u786c\u76d8\u7684\u7269\u7406\u4f4d\u7f6e,\u4f8b\u5982: \/home\/wwwRoot\" reloadable=\"true\" deubg=\"0\" \/>\n\t<\/Host>\n\n\n\n>\u8bf4\u660e\uff1a\n>\u5982\u679c\u8fd8\u6709\u5176\u4ed6\u7684\u57df\u540d,\u518d\u6dfb\u52a0\u4e00\u4e2a\u4ee5\u4e0a Host \u5185\u5bb9\u6bb5\u5185\u5bb9\u5373\u53ef\u3002\n\n2.\u91cd\u542f Tomcat \u670d\u52a1\u3002\n\n#### Apache \u914d\u7f6e\u65b9\u6cd5\nApache \u4e2d\u5bf9\u4e8e\u6bcf\u4e2a VirtualHost\uff0c\u90fd\u8981\u6c42\u6709 ServerName \u6216\u8005 ServerAlias\uff0c\u800c\u4e14\u4e0d\u80fd\u4e3a\u7a7a\u3002\n\n1.\u8fdb\u5165 Apache \u7684 **conf** \u76ee\u5f55\uff0c\u6253\u5f00 **httpd.conf** \u6587\u4ef6\uff0c\u627e\u5230 VirtualHost\u3002\n\n\t<VirtualHost *:80>\n\t DocumentRoot \/home\/domain # \u57df\u540d\u5bf9\u5e94\u7684-\u9879\u76ee\u76ee\u5f55\n\t ServerName blog.com\t# \u9879\u76ee\u76ee\u5f55\u5bf9\u5e94\u7684-\u57df\u540d\n\t<\/VirtualHost>\n\n2.\u91cd\u542f Apache \u670d\u52a1\u3002"}