防止恶意刷新js_防止执行恶意Javascript

i am using a wordpress site, and i found a malware script, whenever i try to save page and click on text panel in WYSIWYG, a malware javascript tag is automatically added to the page. here is the script that is automatically added.

i tried to remove the src file by the following code. but it didn't work, The script executes last before the closing of body tag. I tried using this script, but the malware script loads after all javascript loaded. here is my code.

$("script[src='http://cracks4free.info/5/adds.js']").remove()

I need to remove this code, or prevent this code from executing through javasript, jquery, ajax anything.. Just want to get rid of this. Thanks

解决方案

If your server has been compromised you need to rebuild it:

Export your existing content

Rebuild the box with an up to date wordpress version

Import your content

Regularly apply security updates

Trying to use javascript to clean up the content is not a solution. You've got a compromised Wordpress installation and it's a matter of time before some other script-kiddy adds their own personal touches, or something worse happens.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值