If you are in charge of the companyWebsite construction's work, website rental, you'd better look down.
Have you ever received such emails as "large flow customer notification" and "resource consuming customer notification";Or the website is closed by the access provider, and the website background cannot log in and upload, etc.Today, I specially sorted out a radical cure for resource consumption and high traffic of enterprise websites.
If you want to solve it thoroughly, you must know the reason;To understand the reasons, first analyze the problems on the website, as follows:
1. The homepage, inner page and even the management background of the website are hung with a lot of junk text links or garbled characters.
2. The website was uploaded with suspicious files.
3. The message board was flooded, and a large number of garbage messages appeared.
4. The database was injected, and a lot of junk information appeared in the news and product systems.
5. The membership system was flooded, and a large number of garbage members appeared.
6. The background cannot log in or publish information.
7. The comment system intrudes and a large number of garbage comments appear.
Part I: Resource consumption
Reasons and general handling methods for suspicious files being uploaded:
Access providers (such as HiChina) will give information about which files consume resources, show evidence (email notification, or call HiChina directly), and use FTP to directly delete those files that consume resources.In addition, the evidence will not give all the resource consuming documents. There are still some documents that the administrator needs to find by himself. Some documents on the website are necessary documents for the website, and some are suspicious documents, which need to be checked one by one.If it is not cleaned up, it is hard to say when the remaining suspicious files will consume resources.
How are suspicious files transferred?
Channel 1: The website FTP password is leaked, such as the company changing the website leader, the website company changing the technology, the password is too simple to be cracked, etc. With the password, hackers can operate the website at will.
Channel 2: In the background of small (enterprise) websites, many of them use open source CMS (content management system) circulated on the Internet, such as the DEDECMS of Zhimeng, as well as many small CMS, which are countless. In fact, some website building companies claim that many CMS developed by themselves are improved based on a certain CMS.Because these CMS are open source and open, its vulnerabilities are also open. Hackers use these vulnerabilities to upload these files to the website host.
Channel 3: One server carries hundreds of websites. If a website is invaded or attacked, viruses or trojans uploaded to the server will affect other websites on the server.
Channel 4: Each website management background has an ADMIN who has the highest authority to manage the website. If the password is disclosed or cracked, hackers can also operate the website at will.
The above measures are temporary solutions. How can we solve the problem?
If the suspicious files are not thoroughly cleaned up or all the causes are not found, it will not be long before you receive a notice of "resource consumption" and "large traffic". Because your website has been included in the hacker's "chicken" list, they will visit and use your website twice a day, which can be as long as one month, or as short as three days.Wanwang gives three opening opportunities every month.If a website is closed three times, it will only be opened next month.
The reasons for resource consumption and high traffic of websites are complex. We should find out the causes and solve them one by one before we can cure them.
Solution for Channel 1: If the website uses open source CMS and does not consider replacing CMS recently, first upgrade the patch, upgrade the website to the latest CMS patch, and then upgrade the CMS patch manually on a regular basis. Open source CMS will release the patch irregularly, automatically or manually.
The solution for the second and third channels: change the FTP password once a month, and the password of the website super administrator should also be changed regularly. The password should preferably be more than 8 characters, including uppercase letters, lowercase letters and numbers.Change the password immediately after changing the website administrator.
Solution for Channel 4: This is difficult to deal with, but we can regularly back up the website. Once the website changes in a large range, we can use the backup file with a recent date to restore it.
Part II: Large flow
First, let's talk about what is traffic. In addition to the difference in the size of the web page space, there is also a parameter that is not often noticed, that is, "traffic". For example, the M3 host of Wanwang has 1GB of web page space, and the maximum monthly traffic is 30GB.If the monthly traffic exceeds this limit, HiChina will notify you.How do we understand this traffic?