幸福魔方
ThinkPHP 5.x漏洞自查清单:你的后台还裸奔吗_我的网站

一 |
一键部署OpenClaw
ThinkPHP是国内站长的老朋友,也是老漏洞的重灾区。 Veteran South Korean actor O Yeong-su, best known for his award-winning role in Netflix’s global hit Squid Game, has been acquitted of sexual misconduct charges by an appellate court. The Suwon District Court announced the decision on Tuesday, overturning a previous ruling that had found the 81-year-old guilty of harassment.
The case dates back to 2017, when O was accused of hugging and kissing a woman without her consent during a regional theatre tour. In 2022, a lower court convicted him and sentenced him to eight months in prison, suspended for two years. Prosecutors had sought a one-year jail term, which was also pushed in the appeal.
However, the appellate judges dismissed the conviction, stating that while there were grounds for suspicion, there wasn’t enough evidence to prove the case beyond doubt. The court noted that the woman had sought counselling for sexual violence six months after the alleged incident and that O Yeong-su had apologized at her request. Still, the judges raised concerns about potential inconsistencies in her recollection of events over time and stressed the importance of protecting the defendant’s rights in cases with lingering uncertainty.
The alleged victim expressed disappointment following the verdict. In a statement shared through the women’s rights organization Womenlink, she said, Despite today’s ruling, I will continue to speak the truth to the very end. This decision cannot erase my pain or the reality of what happened.
Womenlink also criticized the court’s judgment, calling it “a decision that once again hides the issue of sexual violence in the theatre industry.
O Yeong-su rose to worldwide fame with his emotional portrayal of Player 001 in Squid Game, a role that earned him a Golden Globe Award in 2022. While his legal battle had cast a shadow over his later career, the new ruling clears his name, at least in the eyes of the law.
Also Read: Shah Rukh Khan Poses With Squid Game Stars Lee Jung-jae and Lee Byung-hun。5.x早期版本暴露过多次高危问题,比如远程代码执行、控制器任意调用。最坑的是很多站上线后没再更新过框架,漏洞一直躺在那儿。
自查第一步是确认版本。

二 | ThinkPHP 5.0.x/5.1.x低于特定小版本就要升级。先把composer.lock或者框架目录里的base.php版本号翻出来,再对照官方安全公告。 # 快速查看当前ThinkPHP版本 grep -r "VERSION" vendor/topthink/framework/src/think/App.php # 或者看composer.lock grep -A1 '"name": "topthink/framework"' composer.lock
自查第二步是限制后台入口。把admin、manage这些路径用Nginx做IP白名单或者加HTTP基本认证,别让搜索引擎随便扫到。同时关闭debug模式,runtime目录禁止执行脚本。 # Nginx中禁止访问敏感路径 location ~* ^/(application|extend|runtime|thinkphp|vendor)/ { deny all; } # 禁止执行上传目录里的PHP location ~* ^/upload/.*\.(php|php5|phtml)$ { deny all; }
最后一条容易被忽略:不要用默认的应用名和入口。

三 | 很多扫描器直接请求/index.php/admin/login或者/index.php?s=/admin,你把后台入口改名,就能挡住一大半批量攻击。

四 | 数据来源:ThinkPHP官方安全公告及topthink/framework GitHub仓库版本更新记录
申请创业报道,分享创业好点子。点击此处,共同探讨创业新机遇!。
Current article:http://s8w.ningshunsaotuiqiao.shop/news/20260826_3804.html
Published on:08:53:53