CN104793957A - Method and device for detecting website existing in server and device - Google Patents

Method and device for detecting website existing in server and device Download PDF

Info

Publication number
CN104793957A
CN104793957A CN201510219111.6A CN201510219111A CN104793957A CN 104793957 A CN104793957 A CN 104793957A CN 201510219111 A CN201510219111 A CN 201510219111A CN 104793957 A CN104793957 A CN 104793957A
Authority
CN
China
Prior art keywords
server
website
middleware
server middleware
configuration file
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201510219111.6A
Other languages
Chinese (zh)
Other versions
CN104793957B (en
Inventor
李云龙
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Inspur Electronic Information Industry Co Ltd
Original Assignee
Inspur Electronic Information Industry Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inspur Electronic Information Industry Co Ltd filed Critical Inspur Electronic Information Industry Co Ltd
Priority to CN201510219111.6A priority Critical patent/CN104793957B/en
Publication of CN104793957A publication Critical patent/CN104793957A/en
Application granted granted Critical
Publication of CN104793957B publication Critical patent/CN104793957B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Information Transfer Between Computers (AREA)

Abstract

The invention provides a method and device for detecting a website existing in a server. The method comprises the steps that keywords of progresses of middleware of all kinds of servers are determined, and whether any one of the keywords is included in a first process running in the current server or not is judged. If any one of the keywords is included in the first progress running in the current server, a storage path of a directory structure corresponding to the middleware of the first server is determined according to the storage position of the first process. At the same time, according to the storage path of the directory structure corresponding to the middleware of the first server, a directory structure corresponding to the middleware of the first server is searched for, and a configuration file under the directory structure corresponding to the middleware of the first server is acquired. By analyzing information about the website storage position in the configuration file, the first website, corresponding to the middleware of the first server, existing in the current server is detected, and the website existing in the server is automatically detected.

Description

A kind ofly detect the method and apparatus that server exists website
Technical field
The present invention relates to computer software application field, particularly a kind ofly detect the method and apparatus that server exists website.
Background technology
Web server refers to the program residing at certain type computer on the Internet, and it can store website file and data file, browses and download for user.And the site file be present on Web server often needs to be carried out some process with the security increasing these site files, so, before security process is carried out to these websites, first the memory location finding out these site files on Web server is needed, and the relevant information that these site files are corresponding.
At present the detection of website on server is mainly detected targetedly by manual type, namely according to the keyword of certain website, where the associated documents detecting certain website are stored in server, as: detect the website be based upon on Internet Information Services (IIS) platform, the relevant information of IIS file need be inputted on the server by manual type, and the site information by existing under these acquisition of informations to the catalogue and this catalogue of Internet Information Services (IIS).
In the prior art, mainly by manual type detection server exists website.
Summary of the invention
The invention provides and a kind ofly detect the method and apparatus that server exists website, there is website automatically to detect on server.
Detect the method that server exists website, the key word of the process of all kinds of server middleware can be determined, also comprise:
Judge whether comprise key word described in any one in the first process that current server runs, if comprised, then determine that the first process is the process of the first server middleware in described all kinds of server middleware;
According to the memory location of the first process, determine the store path of the bibliographic structure that described first server middleware is corresponding;
According to the store path of bibliographic structure corresponding to described first server middleware, search the bibliographic structure that described first server middleware is corresponding, and obtain the configuration file under bibliographic structure corresponding to described first server middleware;
Resolve the website deposit position information in configuration file, detect the first website corresponding to described first server middleware that described current server exists.
Preferably, described determine that the first process is the process of first server middleware in described all kinds of server middleware after, comprise further:
According to described first process, determine the type of described first server middleware;
Configuration file under the bibliographic structure that described acquisition described first server middleware is corresponding comprises: according to the type of described server middleware, obtains the configuration file of described first server middleware from the bibliographic structure that the described first server middleware found is corresponding.
Preferably, comprise further: determine all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station;
Described detect the website that described destination server exists after, comprise further: described all kinds of information of building a station template characteristic of correspondence information and described first website is carried out characteristic matching, identify used first the building a station template in described first website;
To build a station template according to described first, safe handling is carried out to the first website.
Preferably, described configuration file is the MetaBase.xml of IIS class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in MetaBase.xml, detect the first website corresponding to IIS6 version server middleware that described current server exists;
Preferably, described configuration file is the application.config of IIS class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in application.config, detect that described current server exists corresponding to IIS7 version and website corresponding to the above server middleware of IIS7 version.
Preferably, described configuration file is the httpd.conf of Apache class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in described httpd.conf, detect first website corresponding corresponding to Apache class server middleware that described current server exists;
After website deposit position information in described parsing configuration file, comprise further: whether the described Apache class server middleware run described in judgement opens fictitious host computer vhost, if, then continue to resolve configuration file httpd-vhosts.conf corresponding to fictitious host computer, detect the second website corresponding to Apache class server middleware that described fictitious host computer exists.
Preferably, described configuration file is server.xml;
Comprise further: by CATALINA_HOME environmental variance, obtain the configuration file server.xml under bibliographic structure corresponding to Tomcat class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in described server.xml, detect the first website corresponding to Tomcat class server middleware that described current server exists.
Detect the device that server exists website, comprising:
First determining unit, for determining the key word of the process of all kinds of server middleware;
Judging unit, for judging whether comprise key word described in any one in the first process that current server runs, if comprised, then determines that the first process is the process of the first server middleware in described all kinds of server middleware;
Second determining unit, for the memory location according to the first process, determines the store path of the bibliographic structure that described first server middleware is corresponding;
Acquiring unit, for the store path according to bibliographic structure corresponding to described first server middleware, searches the bibliographic structure that described first server middleware is corresponding, and obtains the configuration file under bibliographic structure corresponding to described first server middleware;
Detecting unit, for resolving the website deposit position information in configuration file, detects the first website corresponding to described first server middleware that described current server exists.
Preferably, this device comprises further: the 3rd determining unit, wherein,
Described 3rd determining unit, for described first process determined according to described judging unit, determines the type of described first server middleware;
Described acquiring unit, is further used for: according to the type of described server middleware, obtains the configuration file of described first server middleware from the bibliographic structure that the described first server middleware found is corresponding.
Preferably, this device comprises further: the 4th determining unit, recognition unit and secure processing units, wherein,
Described 4th determining unit, for determining all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station;
Described recognition unit, carries out characteristic matching for all kinds of information of building a station template characteristic of correspondence information and described first website described 4th determining unit determined, identifies used first the building a station template in described first website;
Described secure processing units, for building a station template according to described first, carries out safe handling to the first website.
Preferably, the configuration file that described acquiring unit obtains is the MetaBase.xml of IIS class server middleware;
Described detecting unit, is further used for resolving the website deposit position information in MetaBase.xml, detects the first website corresponding to IIS6 version server middleware that described current server exists.
Preferably, the configuration file that described acquiring unit obtains is the application.config of IIS class server middleware;
Described detecting unit, is further used for resolving the website deposit position information in application.config, detect that described current server exists corresponding to IIS7 version and website corresponding to the above server middleware of IIS7 version;
Preferably, the configuration file that described acquiring unit obtains is the httpd.conf of Apache class server middleware;
Described detecting unit, be further used for the website deposit position information of resolving in described httpd.conf, detect first website corresponding corresponding to Apache class server middleware that described current server exists, and whether the described Apache class server middleware run described in judging opens fictitious host computer vhost, if, then continue to resolve configuration file httpd-vhosts.conf corresponding to fictitious host computer, detect the second website corresponding to Apache class server middleware that described fictitious host computer exists.
Preferably, the configuration file that described acquiring unit obtains is server.xml;
Described acquiring unit, is further used for by CATALINA_HOME environmental variance, obtains the configuration file under bibliographic structure corresponding to Tomcat class server middleware;
Described detecting unit, is further used for the website deposit position information of resolving in described server.xml, detects the first website corresponding to Tomcat class server middleware that described current server exists.
Embodiments provide and a kind ofly detect the method and apparatus that server exists website, that define the key word of the process of all kinds of server middleware, so, by judging whether comprise key word described in any one in the first process that current server runs, can determine that the first process is the process of the first server middleware in described all kinds of server middleware.Process due to server middleware contains the memory location of process, and the memory location of server middleware process is consistent with the memory location of the bibliographic structure of server middleware, so, according to the memory location of the first process, the store path of the bibliographic structure that described first server middleware is corresponding can be determined, according to the store path of bibliographic structure corresponding to this first server middleware, search the bibliographic structure that described first server middleware is corresponding, and the configuration file obtained under bibliographic structure corresponding to described first server middleware, and the deposit position information of website in this configuration file can determine the existence of website, therefore, the embodiment of the present invention is by resolving the website deposit position information in the configuration file that got by said process, the first website corresponding to described first server middleware that described current server exists can be detected, achieve automatically to detect on server by said process and there is website.
Accompanying drawing explanation
There is the method flow diagram of website for detection server that one embodiment of the invention provides in Fig. 1;
There is the method flow diagram of website for detection server that another embodiment of the present invention provides in Fig. 2;
There is the apparatus structure schematic diagram of website for detection server that one embodiment of the invention provides in Fig. 3;
There is the apparatus structure schematic diagram of website for detection server that one embodiment of the invention provides in Fig. 4.
Embodiment
Below in conjunction with the accompanying drawing in the embodiment of the present invention, the technical scheme in the embodiment of the present invention is clearly and completely described.Obviously, described embodiment is only the present invention's part embodiment, instead of whole embodiments.Based on the embodiment in the present invention, those of ordinary skill in the art, not making the every other embodiment obtained under creative work prerequisite, belong to the scope of protection of the invention.
At present, being classified as follows of Web server:
Internet Information Services (IIS) class: this IIS class is the Web server product of Microsoft, IIS is the Web server allowing to release news on public Intranet or Internet.IIS is one of current most popular Web server product, and much famous website is all be based upon on the platform of IIS.IIS provides the management tool of a graphical interfaces, is called Internet service managerZ-HU, can be used for monitoring that configuration and control Internet serve, and the server middleware of its correspondence can be described as IIS class server middleware;
WebLogic class: be a kind of multi-functional, measured web application server, the application building oneself for enterprise provides solid foundation.No matter various application and development, dispose all critical tasks, be integrated various system and database, or submit service to, across Internet cooperation, starting point is all BEA WebLogic Server.Because it has comprehensive function, the compliance to open standard, multi-layer framework, support component-based development, enterprise based on Internet all selects it to develop, dispose best application, and the server middleware of its correspondence can be described as WebLogic class server middleware;
Apache class: be maximum Web server in the world, market share reaches about 60%.It comes from NCSAhttpd server, and after NCSAWWW server item stops, those use the people of NCSA www server to start to exchange the patch for this server, and this is also the origin (pache patch) of apache title.Website much famous is in the world all the product of Apache, its successful part be mainly it open source, have the exploitation troop of an opening, support the aspects such as cross-platform application (may operate on nearly all Unix, Windows, linux system platform) and its portability, the server middleware of its correspondence can be described as Apache class server middleware;
Tomcat class: be an open source code, the Web application software container based on Java running servlet and JSP Web application software.Carry out performing according to servlet and JSP specification, the server middleware of its correspondence can be described as Tomcat class server middleware.
So, the server middleware that IIS class server is corresponding is called as IIS class server middleware; The server middleware that WebLogic class server is corresponding is called as WebLogic class server middleware; The server middleware that Apache class server is corresponding is called as Apache class server middleware; Server middleware corresponding to Tomcat class can be described as Tomcat class server middleware.
As shown in Figure 1, embodiments provide a kind of server that detects and there is web site method, the method can comprise the following steps:
Step 101: the key word determining the process of all kinds of server middleware;
Step 102: judge whether comprise key word described in any one in the first process that current server runs, if so, then determines that the first process is the process of the first server middleware in described all kinds of server middleware;
Step 103: according to the memory location of the first process, determines the store path of the bibliographic structure that described first server middleware is corresponding;
Step 104: according to the store path of bibliographic structure corresponding to described first server middleware, search the bibliographic structure that described first server middleware is corresponding, and obtain the configuration file under bibliographic structure corresponding to described first server middleware;
Step 105: resolve the website deposit position information in configuration file, detects the first website corresponding to described first server middleware that described current server exists.
In an embodiment of the invention, in order to obtain configuration file more fast, after step 102, comprising further: according to described first process, determining the type of described first server middleware; Obtain the embodiment of the configuration file under bibliographic structure corresponding to described first server middleware in step 104: according to the type of described server middleware, from the bibliographic structure that the described first server middleware found is corresponding, obtain the configuration file of described first server middleware.
In an embodiment of the invention, in order to more definite understanding server exists the Template Information of building a station of website, with convenient, safe handling is carried out to website.Comprise further: determine all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station, after step 105, comprise further: described all kinds of information of building a station template characteristic of correspondence information and described first website is carried out characteristic matching, identify used first the building a station template in described first website, and to build a station template according to described first, safe handling is carried out to the first website.
In an embodiment of the invention, the website corresponding to IIS class server middleware is detected, when described configuration file is the MetaBase.xml of IIS class server middleware, the embodiment of step 105: resolve the website deposit position information in MetaBase.xml, detects the first website corresponding to IIS6 version server middleware that described current server exists; When described configuration file is the application.config of IIS class server middleware, the embodiment of step 105: resolve the website deposit position information in application.config, detect that described current server exists corresponding to IIS7 version and website corresponding to the above server middleware of IIS7 version.
In an embodiment of the invention, the website corresponding to Apache class server middleware is detected, described configuration file is the httpd.conf of Apache class server middleware, the embodiment of step 105: resolve the website deposit position information in described httpd.conf, detects first website corresponding corresponding to Apache class server middleware that described current server exists; Whether the described Apache class server middleware run described in judgement opens fictitious host computer vhost, if, then continue to resolve configuration file httpd-vhosts.conf corresponding to fictitious host computer, detect the second website corresponding to Apache class server middleware that described fictitious host computer exists.
In an embodiment of the invention, the website corresponding to Tomcat class server middleware is detected, described configuration file is server.xml, can further by passing through CATALINA_HOME environmental variance, obtain the configuration file server.xml under bibliographic structure corresponding to Tomcat class server middleware, the embodiment of step 105: resolve the website deposit position information in described server.xml, detects the first website corresponding to Tomcat class server middleware that described current server exists.
As shown in Figure 2, embodiments provide and a kind ofly detect the method that server exists webpage, it is as follows that the method comprising the steps of:
Step 200: determine all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station;
Due to the script file that common program of building a station is all based on php, asp or jsp etc., generally again operating system can not start process or service, so, itself start with from these files, analyze the bibliographic structure of each program of building a station, tag file, keyword, uses that build a station program under judging this directory web site with this.Therefore, these characteristic key words can be organized into file or database, convenient expansion.
Step 201: the key word determining the process of all kinds of server middleware;
In this step, by the key word of the process of all kinds of server middleware of building database mode storage as much as possible, this is because the key word of Multiple type servers middleware process is different, such as: the key word of Apache class server middleware process is generally containing Apache, and the key word of Tomcat class server middleware process is generally containing Tomcat, so, can using the key word of Apache as Apache class server middleware process, using the key word of Tomcat as Tomcat class server middleware process, in the database set up, can also expand keyword, more to contain keyword.
Step 202: judge whether comprise key word described in any one in the first process that current server runs, if so, then triggered step 203; Otherwise, triggered step 204;
Step 203: determine that the first process is the process of the first server middleware in described all kinds of server middleware;
Step 204: determine that the first process is not the process of server middleware;
The detailed process of above-mentioned steps 202 to step 204 scans in turn each process that current server runs, to understand the key word whether containing arbitrary all kinds of server middleware in each process of current server, such as: a certain process run by scanning current server, find in this process and contain key word Apache, then illustrate that this process is the process of Apache class server middleware; If scanning the first process, does not find the key word relevant to the described all kinds of server middleware process key words determined, then illustrates that this process is not the process of server middleware, can continue to judge next process.
Step 205: according to described first process, determines the type of described first server middleware;
Due to server middleware process because the kind of server middleware is different, and otherness to some extent, so, the kind of server middleware can be determined according to server middleware process, and the bibliographic structure of same class server middleware is identical, so, after determining server middleware type, the bibliographic structure of server middleware can be determined, such as: the server middleware of IIS6 version, its partial list structure including configuration file be %windir% system32 inetsrv MetaBase.xml, the server middleware of IIS7 and above version, its partial list structure including configuration file be %windir% system32 inetsrv config application.config.
Step 206: according to the memory location of the first process, determines the store path of the bibliographic structure that described first server middleware is corresponding;
In process, not only comprise the key word of process, and include this process physical storage locations, namely the position of the disk of server is stored in, and server middleware includes server middleware process and server middleware bibliographic structure, and server middleware process and server middleware bibliographic structure are generally stored in same position.
Step 207: according to the store path of bibliographic structure corresponding to described first server middleware, search the bibliographic structure that described first server middleware is corresponding;
What deserves to be explained is, for IIS class server middleware, the deposit position of its bibliographic structure is determined, so, after determining that server middleware is IIS class, directly can skip this step and perform subsequent step.
Step 208: according to the type of described server middleware, obtains the configuration file of described first server middleware from the bibliographic structure that the described first server middleware found is corresponding;
Such as: the configuration file of Apache class server middleware be conf under Apache bibliographic structure httpd.conf file in httpd.conf;
The configuration file of Tomcat class server middleware be conf under bibliographic structure server.xml file in server.xml;
What deserves to be explained is, for IIS class server middleware, the deposit position of its bibliographic structure is what determined, as: for the server middleware of IIS6 version, from bibliographic structure, get corresponding configuration file, namely from %windir% system32 inetsrv obtain MetaBase.xml file MetaBase.xml;
For server middleware more than IIS7 version and IIS7 version, from bibliographic structure, get corresponding configuration file, namely from %windir% system32 inetsrv config get configuration file application.config file application.config.
Step 209: resolve the website deposit position information in configuration file, detects the first website corresponding to described first server middleware that described current server exists;
Such as: by resolving the website deposit position information in MetaBase.xml, the first website corresponding to IIS6 version server middleware that described current server exists is detected;
By resolving the website deposit position information in application.config, detect that described current server exists corresponding to IIS7 version and website corresponding to the above server middleware of IIS7 version;
By resolving the website deposit position information in described httpd.conf, detect first website corresponding corresponding to Apache class server middleware that described current server exists, what deserves to be explained is, by resolving httpd.conf, whether the described Apache class server middleware run described in can also judging opens fictitious host computer vhost, if, then continue to resolve configuration file httpd-vhosts.conf corresponding to fictitious host computer, detect the second website corresponding to Apache class server middleware that described fictitious host computer exists, website corresponding to Apache class server middleware can be made as much as possible all to be detected,
By resolving the website deposit position information in described server.xml, detect the first website corresponding to Tomcat class server middleware that described current server exists, what deserves to be explained is, if server middleware has been defined as Tomcat class, so, the CATALINA_HOME environmental variance that Tomcat class server middleware configures for server can also be utilized, get the path of the bibliographic structure of Tomcat class server middleware, and then parse the configuration file server.xml under bibliographic structure.
What deserves to be explained is, in configuration file, except the website deposit position information that the embodiment of the present invention is mentioned, can also comprise: the domain name, listening port, IP address, website name etc. of website; When have in configuration file in these information any one time, this step can also detect website by any one of resolving in these information.
Step 210: described all kinds of information of building a station template characteristic of correspondence information and described first website is carried out characteristic matching, identifies used first the building a station template in described first website;
Achieved detection server by above-mentioned steps 201 to step 209 and there is website, and this step is in order to after detecting that server exists webpage, analyzes further to each webpage, for providing certain reference frame to the subsequent treatment of webpage.In the prior art, masterplate of building a station usually is adopted to set up a web site, as: the website of forum's character, may Discuz be selected; Individual's blog can select WordPress; PHPCMS or DedeCMS etc. can be selected in the website of Content Management type.
Step 211: to build a station template according to described first, safe handling is carried out to the first website.
One embodiment of the invention proposes and a kind ofly detects the device that server exists website, and as shown in Figure 3, this device comprises:
First determining unit 301, for determining the key word of the process of all kinds of server middleware;
Judging unit 302, for judging whether comprise key word described in any one in the first process that current server runs, if comprised, then determines that the first process is the process of the first server middleware in described all kinds of server middleware;
Second determining unit 303, for the memory location according to the first process, determines the store path of the bibliographic structure that described first server middleware is corresponding;
Acquiring unit 304, for the store path according to bibliographic structure corresponding to described first server middleware, searches the bibliographic structure that described first server middleware is corresponding, and obtains the configuration file under bibliographic structure corresponding to described first server middleware;
Detecting unit 305, for resolving the website deposit position information in configuration file, detects the first website corresponding to described first server middleware that described current server exists.
In an alternative embodiment of the invention, as shown in Figure 4, the device that described detection server exists website can comprise further: the 3rd determining unit 401, wherein,
Described 3rd determining unit 401, for described first process determined according to described judging unit, determines the type of described first server middleware;
Described acquiring unit 304, is further used for: according to the type of described server middleware, obtains the configuration file of described first server middleware from the bibliographic structure that the described first server middleware found is corresponding.
In an embodiment of the invention, there is the device of website in described detection server, can comprise further: the 4th determining unit, recognition unit and secure processing units (not illustrating in the drawings), wherein,
Described 4th determining unit, for determining all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station;
Described recognition unit, carries out characteristic matching for all kinds of information of building a station template characteristic of correspondence information and described first website described 4th determining unit determined, identifies used first the building a station template in described first website;
Described secure processing units, for building a station template according to described first, carries out safe handling to the first website.
In an embodiment of the invention, the configuration file that described acquiring unit obtains is the MetaBase.xml of IIS class server middleware;
Described detecting unit, is further used for resolving the website deposit position information in MetaBase.xml, detects the first website corresponding to IIS6 version server middleware that described current server exists.
In an embodiment of the invention, the configuration file that described acquiring unit obtains is the application.config of IIS class server middleware;
Described detecting unit, is further used for resolving the website deposit position information in application.config, detect that described current server exists corresponding to IIS7 version and website corresponding to the above server middleware of IIS7 version.
In an embodiment of the invention, the configuration file that described acquiring unit obtains is the httpd.conf of Apache class server middleware;
Described detecting unit, be further used for the website deposit position information of resolving in described httpd.conf, detect first website corresponding corresponding to Apache class server middleware that described current server exists, and whether the described Apache class server middleware run described in judging opens fictitious host computer vhost, if, then continue to resolve configuration file httpd-vhosts.conf corresponding to fictitious host computer, detect the second website corresponding to Apache class server middleware that described fictitious host computer exists.
In an embodiment of the invention, the configuration file that described acquiring unit obtains is server.xml;
Described acquiring unit, is further used for by CATALINA_HOME environmental variance, obtains the configuration file under bibliographic structure corresponding to Tomcat class server middleware;
Described detecting unit, is further used for the website deposit position information of resolving in described server.xml, detects the first website corresponding to Tomcat class server middleware that described current server exists.
The embodiment of the present invention at least can reach following beneficial effect:
1., by by judging whether comprise key word described in any one in the first process that current server runs, can determine that the first process is the process of the first server middleware in described all kinds of server middleware.Process due to server middleware contains the memory location of process, and the memory location of server middleware process is consistent with the memory location of the bibliographic structure of server middleware, so, according to the memory location of the first process, the store path of the bibliographic structure that described first server middleware is corresponding can be determined, according to the store path of bibliographic structure corresponding to this first server middleware, search the bibliographic structure that described first server middleware is corresponding, and the configuration file obtained under bibliographic structure corresponding to described first server middleware, and the deposit position information of website in this configuration file can determine the existence of website, therefore, the embodiment of the present invention is by resolving the website deposit position information in the configuration file that got by said process, the first website corresponding to described first server middleware that described current server exists can be detected, achieve automatically to detect on server by said process and there is website.
2. by determining the type of described first server middleware further, can according to the type of described server middleware, from the bibliographic structure that the described first server middleware found is corresponding, obtain the configuration file of described first server middleware, effectively raise the speed obtaining configuration file.
3. the embodiment of the present invention is by determining all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station, and described all kinds of information of building a station template characteristic of correspondence information and described first website is carried out characteristic matching, identify used first the building a station template in described first website, and to build a station template according to described first, safe handling is carried out to the first website.There is the Template Information of building a station of website with more definite understanding server, safe handling is carried out as security protection to website, wooden horse killing etc. with convenient.
It should be noted that, in this article, the relational terms of such as first and second and so on is only used for an entity or operation to separate with another entity or operational zone, and not necessarily requires or imply the relation that there is any this reality between these entities or operation or sequentially.And, term " comprises ", " comprising " or its any other variant are intended to contain comprising of nonexcludability, thus make to comprise the process of a series of key element, method, article or equipment and not only comprise those key elements, but also comprise other key elements clearly do not listed, or also comprise by the intrinsic key element of this process, method, article or equipment.When not more restrictions, the key element " being comprised " limited by statement, and be not precluded within process, method, article or the equipment comprising described key element and also there is other same factor.
The foregoing is only preferred embodiment of the present invention, not in order to limit the present invention, within the spirit and principles in the present invention all, any amendment made, equivalent replacement, improvement etc., all should be included within the scope of protection of the invention.

Claims (10)

1. detect the method that server exists website, it is characterized in that, determine the key word of the process of all kinds of server middleware, also comprise:
Judge whether comprise key word described in any one in the first process that current server runs, if comprised, then determine that the first process is the process of the first server middleware in described all kinds of server middleware;
According to the memory location of the first process, determine the store path of the bibliographic structure that described first server middleware is corresponding;
According to the store path of bibliographic structure corresponding to described first server middleware, search the bibliographic structure that described first server middleware is corresponding, and obtain the configuration file under bibliographic structure corresponding to described first server middleware;
Resolve the website deposit position information in configuration file, detect the first website corresponding to described first server middleware that described current server exists.
2. method according to claim 1, is characterized in that, described determine that the first process is the process of first server middleware in described all kinds of server middleware after, comprise further:
According to described first process, determine the type of described first server middleware;
Configuration file under the bibliographic structure that described acquisition described first server middleware is corresponding comprises: according to the type of described server middleware, obtains the configuration file of described first server middleware from the bibliographic structure that the described first server middleware found is corresponding.
3. method according to claim 1, is characterized in that, comprises further: determine all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station;
Described detect the website that described destination server exists after, comprise further: described all kinds of information of building a station template characteristic of correspondence information and described first website is carried out characteristic matching, identify used first the building a station template in described first website;
To build a station template according to described first, safe handling is carried out to the first website.
4. method according to claim 1 or 2, is characterized in that, described configuration file is the MetaBase.xml of IIS class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in MetaBase.xml, detect the first website corresponding to IIS6 version server middleware that described current server exists;
Or,
Described configuration file is the application.config of IIS class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in application.config, detect that described current server exists corresponding to IIS7 version and website corresponding to the above server middleware of IIS7 version.
5. method according to claim 1 or 2, is characterized in that, described configuration file is the httpd.conf of Apache class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in described httpd.conf, detect first website corresponding corresponding to Apache class server middleware that described current server exists;
After website deposit position information in described parsing configuration file, comprise further: whether the described Apache class server middleware run described in judgement opens fictitious host computer vhost, if, then continue to resolve configuration file httpd-vhosts.conf corresponding to fictitious host computer, detect the second website corresponding to Apache class server middleware that described fictitious host computer exists.
6. method according to claim 1 or 2, is characterized in that, described configuration file is server.xml;
Comprise further: by CATALINA_HOME environmental variance, obtain the configuration file server.xml under bibliographic structure corresponding to Tomcat class server middleware;
Website deposit position information in described parsing configuration file, detect the first website corresponding to described first server middleware that described current server exists, comprise: resolve the website deposit position information in described server.xml, detect the first website corresponding to Tomcat class server middleware that described current server exists.
7. detect the device that server exists website, it is characterized in that, comprising:
First determining unit, for determining the key word of the process of all kinds of server middleware;
Judging unit, for judging whether comprise key word described in any one in the first process that current server runs, if comprised, then determines that the first process is the process of the first server middleware in described all kinds of server middleware;
Second determining unit, for the memory location according to the first process, determines the store path of the bibliographic structure that described first server middleware is corresponding;
Acquiring unit, for the store path according to bibliographic structure corresponding to described first server middleware, searches the bibliographic structure that described first server middleware is corresponding, and obtains the configuration file under bibliographic structure corresponding to described first server middleware;
Detecting unit, for resolving the website deposit position information in configuration file, detects the first website corresponding to described first server middleware that described current server exists.
8. device according to claim 7, is characterized in that, the 3rd determining unit, wherein,
Described 3rd determining unit, for described first process determined according to described judging unit, determines the type of described first server middleware;
Described acquiring unit, is further used for: according to the type of described server middleware, obtains the configuration file of described first server middleware from the bibliographic structure that the described first server middleware found is corresponding.
9. device according to claim 7, is characterized in that, comprise further: the 4th determining unit, recognition unit and secure processing units, wherein,
Described 4th determining unit, for determining all kinds of template and the described all kinds of template characteristic of correspondence information of building a station of building a station;
Described recognition unit, carries out characteristic matching for all kinds of information of building a station template characteristic of correspondence information and described first website described 4th determining unit determined, identifies used first the building a station template in described first website;
Described secure processing units, for building a station template according to described first, carries out safe handling to the first website.
10. device according to claim 7 or 8, is characterized in that,
The configuration file that described acquiring unit obtains is the MetaBase.xml of IIS class server middleware;
Described detecting unit, is further used for resolving the website deposit position information in MetaBase.xml, detects the first website corresponding to IIS6 version server middleware that described current server exists;
Or,
The configuration file that described acquiring unit obtains is the application.config of IIS class server middleware;
Described detecting unit, is further used for resolving the website deposit position information in application.config, detect that described current server exists corresponding to IIS7 version and website corresponding to the above server middleware of IIS7 version;
Or,
The configuration file that described acquiring unit obtains is the httpd.conf of Apache class server middleware;
Described detecting unit, be further used for the website deposit position information of resolving in described httpd.conf, detect first website corresponding corresponding to Apache class server middleware that described current server exists, and whether the described Apache class server middleware run described in judging opens fictitious host computer vhost, if, then continue to resolve configuration file httpd-vhosts.conf corresponding to fictitious host computer, detect the second website corresponding to Apache class server middleware that described fictitious host computer exists;
Or,
The configuration file that described acquiring unit obtains is server.xml;
Described acquiring unit, is further used for by CATALINA_HOME environmental variance, obtains the configuration file under bibliographic structure corresponding to Tomcat class server middleware;
Described detecting unit, is further used for the website deposit position information of resolving in described server.xml, detects the first website corresponding to Tomcat class server middleware that described current server exists.
CN201510219111.6A 2015-04-30 2015-04-30 The method and apparatus that a kind of detection service device has website Active CN104793957B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510219111.6A CN104793957B (en) 2015-04-30 2015-04-30 The method and apparatus that a kind of detection service device has website

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510219111.6A CN104793957B (en) 2015-04-30 2015-04-30 The method and apparatus that a kind of detection service device has website

Publications (2)

Publication Number Publication Date
CN104793957A true CN104793957A (en) 2015-07-22
CN104793957B CN104793957B (en) 2017-11-21

Family

ID=53558773

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510219111.6A Active CN104793957B (en) 2015-04-30 2015-04-30 The method and apparatus that a kind of detection service device has website

Country Status (1)

Country Link
CN (1) CN104793957B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105812393A (en) * 2016-05-24 2016-07-27 浪潮电子信息产业股份有限公司 Website protection device and method
CN109905396A (en) * 2019-03-11 2019-06-18 北京奇艺世纪科技有限公司 A kind of WebShell file test method, device and electronic equipment
CN117492874A (en) * 2023-10-26 2024-02-02 厦门国际银行股份有限公司 Middleware configuration discovery management method, system, equipment and storage medium

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2003590A1 (en) * 2007-06-11 2008-12-17 Richard Mervyn Gardner Integrated systems for simultaneous mutual authentification of database and user
CN103259877A (en) * 2013-04-15 2013-08-21 北京百度网讯科技有限公司 IP address geographic position determination method and system
CN103631636A (en) * 2012-08-21 2014-03-12 国际商业机器公司 Enabling multi-tenancy for a commerce server

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2003590A1 (en) * 2007-06-11 2008-12-17 Richard Mervyn Gardner Integrated systems for simultaneous mutual authentification of database and user
CN103631636A (en) * 2012-08-21 2014-03-12 国际商业机器公司 Enabling multi-tenancy for a commerce server
CN103259877A (en) * 2013-04-15 2013-08-21 北京百度网讯科技有限公司 IP address geographic position determination method and system

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105812393A (en) * 2016-05-24 2016-07-27 浪潮电子信息产业股份有限公司 Website protection device and method
CN109905396A (en) * 2019-03-11 2019-06-18 北京奇艺世纪科技有限公司 A kind of WebShell file test method, device and electronic equipment
CN117492874A (en) * 2023-10-26 2024-02-02 厦门国际银行股份有限公司 Middleware configuration discovery management method, system, equipment and storage medium

Also Published As

Publication number Publication date
CN104793957B (en) 2017-11-21

Similar Documents

Publication Publication Date Title
CN102333122B (en) Downloaded resource provision method, device and system
US20180219907A1 (en) Method and apparatus for detecting website security
CN105069355B (en) The static detection method and device of webshell deformations
CN109376291B (en) Website fingerprint information scanning method and device based on web crawler
US20150207811A1 (en) Vulnerability vector information analysis
CN107341399B (en) Method and device for evaluating security of code file
CN102591874B (en) Prompt method, terminal and server
CN102419808A (en) Method, device and system for detecting safety of download link
CN111104579A (en) Identification method and device for public network assets and storage medium
CN105956136B (en) Method and device for acquiring login information
US20200336498A1 (en) Method and apparatus for detecting hidden link in website
CN109446801B (en) Method, device, server and storage medium for detecting simulator access
CN110309667B (en) Website hidden link detection method and device
CN114465741B (en) Abnormality detection method, abnormality detection device, computer equipment and storage medium
CN104793957A (en) Method and device for detecting website existing in server and device
CN103475673B (en) Fishing website recognition methods, device and client
CN104468459A (en) Vulnerability detection method and apparatus
CN104065736A (en) URL redirection method, device, and system
CN107085684B (en) Program feature detection method and device
CN111143722A (en) Method, device, equipment and medium for detecting webpage hidden link
CN111597422A (en) Buried point mapping method and device, computer equipment and storage medium
CN105354490A (en) Method and device for processing hijacked browser
CN103390129A (en) Method and device for detecting security of uniform resource locator
CN111131236A (en) Web fingerprint detection device, method, equipment and medium
CN103152381A (en) Method and server system of processing browser corrupted data

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
EXSB Decision made by sipo to initiate substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant