terrylinooo / shieldon

Web Application Firewall (WAF) for PHP.
https://shieldon.io
MIT License
849 stars 98 forks source link

小心enphp... #41

Closed c2xusnpq6 closed 1 year ago

c2xusnpq6 commented 3 years ago

https://enphp.djunny.com/

https://github.com/djunny/enphp

terrylinooo commented 3 years ago

什麼意思?

c2xusnpq6 commented 3 years ago

怕shieldon不會擋經enphp的木馬...

經enphp的b374k: magic.zip

https://www.virustotal.com/gui/file/db069fb498469425e1b38abc4bbb32224d9ef0e08248b844de6c5807a44e246c/detection

image

c2xusnpq6 commented 3 years ago

image https://www.virustotal.com/gui/file/bdb35b2c8b389ac35e5fcda1c71d2c8748b7e8ff0978793fc5aa74fc4a7c27f9/detection

terrylinooo commented 3 years ago

沒關係喔。Shieldon 不是防毒。是偵測網頁 request 的異常,主要擋暴力攻擊和惡意爬蟲。不過還是謝謝您的提醒。

c2xusnpq6 commented 3 years ago

image

c2xusnpq6 commented 3 years ago

就是怕用户上傳經enphp的木馬.....

terrylinooo commented 3 years ago

關於掃描上傳檔案這個功能,我再研究看看或許可加入第三方的防毒掃描 API 作為進階功能。 謝謝您的建議。有進一步的消息我再回覆在這篇貼文。

c2xusnpq6 commented 3 years ago

連eset, bitdefender都不會顯示suspicious/經混淆的超超超強木馬?.............

c2xusnpq6 commented 3 years ago

eset, bitdefender我都跟他們講了

您這邊進展如何?

github-actions[bot] commented 1 year ago

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days.

github-actions[bot] commented 1 year ago

This issue was closed because it has been inactive for 14 since being marked as stale.