Method and device for collecting evidence from website servers
By backing up and restoring the Baota panel log, the problem of low evidence for the Baota panel server is solved, and data integrity and originality are protected.
Patent Information
- Application Number
- CN202111640405.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-29
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2041-12-29
AI Technical Summary
In the prior art, the method for obtaining evidence of the website server built by the pagoda panel is inefficient and difficult, and there is a lack of effective means.
By establishing a connection with the target server, sending backup instructions to backup the Baota panel log, logging in to the Baota panel to obtain the backup file, and sending log restore instructions to restore the panel log, including backup and restore of the operation log and access log.
It achieves efficient and complete fixation of the target website data, ensuring the completeness and originality of the data content.
Smart Images

Figure CN114491663B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method and device for collecting evidence from a website server. Background Art
[0002] Baota Panel is a server management software that can easily manage servers through the web and improve operation and maintenance efficiency. In recent years, with the rise of Baota Panel, more and more illegal websites have been built using Baota Panel.
[0003] Traditionally, there are two methods for obtaining evidence from website servers: one is to create a complete mirror of the website server, which is time-consuming and prone to interruptions, leading to failure. The other is to locate and fix the web and database directories on the server. This method requires high technical skills and is difficult to reproduce. If the website on the server is built using the Baota Panel, the convenience of the Baota Panel can significantly reduce the difficulty of server forensics. However, obtaining evidence using the Baota Panel is still in the exploratory stage, and no single method has been proven to be particularly effective. Summary of the Invention
[0004] The present invention provides a method and device for collecting evidence from a website server, which are used to solve the defect of difficulty in collecting evidence from a website server in the prior art and realize convenient and efficient evidence collection from the server.
[0005] In a first aspect, the present invention provides a method for collecting evidence from a website server, comprising:
[0006] Establish a connection with the target server, the target server is the server of the target website, and the target website is built based on the Baota panel;
[0007] Sending a backup instruction to the target server, wherein the backup instruction is used to instruct the target server to back up the panel log, wherein the panel log includes the pagoda panel operation log and the pagoda panel access log;
[0008] Log in to the Baota panel and obtain a backup file, which is obtained by backing up the data stored on the target server based on the Baota panel;
[0009] A log restoration instruction is sent to the target server, where the log restoration instruction is used to instruct the target server to restore the panel log based on the backed-up panel log.
[0010] Optionally, the login panel includes:
[0011] Obtain the login information sent by the target server, the login information including the Pagoda panel address, user name and password;
[0012] Send an access request to the panel address and log in to the pagoda panel based on the username and password.
[0013] Optionally, after sending the access request to the panel address, the method further includes:
[0014] Determining that basic authorization verification exists, sending a first removal instruction to the target server, where the first removal instruction is used to instruct the target server to disable basic authorization verification restrictions;
[0015] After obtaining the backup file, a first restore instruction is sent to the target server, where the first restore instruction is used to instruct the target server to enable basic authorization verification restrictions.
[0016] Optionally, after sending the access request to the panel address, the method further includes:
[0017] Determining that an IP restriction exists, sending a second removal instruction to the target server, wherein the second removal instruction is used to instruct the target server to disable the IP restriction;
[0018] After obtaining the backup file, a second restore instruction is sent to the target server, where the second restore instruction is used to instruct the target server to enable IP restriction.
[0019] Optionally, the step of sending an access request to the panel address further includes:
[0020] Determining that a domain name restriction exists, sending a third removal instruction to the target server, wherein the third removal instruction is used to instruct the target server to disable the domain name restriction;
[0021] After obtaining the backup file, a third restoration instruction is sent to the target server, where the third restoration instruction is used to instruct the target server to enable domain name restriction.
[0022] Optionally, the method further includes:
[0023] Determining that the password is incorrect, sending a password change instruction to the target server, and obtaining a changed password;
[0024] Log in to the Pagoda panel based on the user name and the modified password.
[0025] Optionally, obtaining the backup file includes:
[0026] Back up the target website and the target database corresponding to the target website based on the scheduled task module of the Pagoda panel, and obtain the target website backup file and the target database backup file;
[0027] Send an installation instruction to the Baota panel, wherein the installation instruction is used to instruct the Baota panel to install the Baota configuration backup plug-in on the target server;
[0028] The configuration information of the target website is backed up based on the Pagoda configuration backup plug-in to obtain a configuration backup file.
[0029] Optionally, after obtaining the configuration backup file, the method further includes:
[0030] Send a delete instruction to the Baota panel, wherein the delete instruction is used to instruct the Baota panel to delete the backup process file;
[0031] The backup process files include one or more of the following:
[0032] A target website backup file stored on the target server;
[0033] A target database backup file stored on the target server;
[0034] The Pagoda configuration backup plug-in installed on the target server.
[0035] In a second aspect, the present invention further provides a device for collecting evidence from a website server, comprising:
[0036] A connection module is used to establish a connection with a target server, where the target server is a server of a target website, and the target website is built based on the Pagoda panel;
[0037] An instruction module is used to send a backup instruction to the target server, wherein the backup instruction is used to instruct the target server to back up the panel log, wherein the panel log includes the pagoda panel operation log and the pagoda panel access log;
[0038] A backup module is used to log in to the Pagoda panel and obtain a backup file, wherein the backup file is obtained by backing up the data stored on the target server based on the Pagoda panel;
[0039] The restoration module is used to send a log restoration instruction to the target server, wherein the log restoration instruction is used to instruct the target server to restore the panel log.
[0040] In a third aspect, the present invention also provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method for collecting evidence from a website server as described in the first aspect are implemented.
[0041] In a fourth aspect, the present invention further provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method for collecting evidence from a website server as described in the first aspect.
[0042] In a fifth aspect, the present invention further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the steps of the method for collecting evidence from a website server as described in the first aspect.
[0043] The method for collecting evidence on a website server provided by an embodiment of the present invention collects evidence on a target server corresponding to a target website based on the Baota panel. Since the target website is built through the Baota panel, the Baota panel program stores the file storage information of the target website, thereby achieving efficient and complete fixation of the data of the target website and ensuring the content integrity of the collected data. In addition, the method for collecting evidence on a website server provided by an embodiment of the present invention restores the panel log after the evidence collection is completed, ensuring that the data in the target server remains in its original state when the data was generated, thereby protecting the originality of the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0045] Figure 1 This is one of the flow charts of the method for collecting evidence from a website server provided by an embodiment of the present invention;
[0046] Figure 2 This is the second flow chart of the method for collecting evidence from a website server provided by an embodiment of the present invention;
[0047] Figure 3 1 is a schematic diagram of the structure of an apparatus for collecting evidence from a website server provided by an embodiment of the present invention;
[0048] Figure 4 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0049] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0050] The following combination Figure 1-Figure 2 The present invention describes a method for collecting evidence from a website server according to an embodiment of the present invention.
[0051] Figure 1 This is one of the flow charts of the method for obtaining evidence from a website server provided by an embodiment of the present invention. Figure 1 As shown, the method for collecting evidence from a website server provided by an embodiment of the present invention includes:
[0052] Step 110, establishing a connection with a target server, wherein the target server is a server of a target website, and the target website is built based on the Pagoda panel;
[0053] The method for collecting evidence on a website server provided by an embodiment of the present invention can be implemented on a forensic device, which can be a terminal device such as a smart phone, a laptop, a note pad, a wireless broadband (WiBro) terminal, a local PC, and a smart PC. The forensic device establishes a connection with the target server based on a remote control protocol (such as telnet, rlogin, ssh, rfb or rdp protocols), and the target server IP address, user name and password used in the connection establishment process can be obtained in advance by the forensic personnel. The target server is used for the publication and application of target websites (such as counterfeit websites or illegal websites such as Trojan horses) on the Internet, and is the infrastructure of the target network application. The target website is built on the target server through the Baota panel. It can be understood that the Baota panel server end is installed on the target server for users to perform operation and maintenance management of the target website. The Baota panel can realize server operation and maintenance operations such as server deployment and system environment, software installation, etc. For example, the forensic device is used to establish a remote connection with the server based on the SSH protocol, and the Baota Panel installation instructions are used to install the Baota Panel client (also called the Baota Panel server) on the server. After the Baota Panel is installed, the panel address, user name and password information will be returned to the forensic device. The user can access the panel address to enter the Baota Panel WEB terminal and manage the server through the interactive interface of the WEB terminal.
[0054] Step 120: Send a backup instruction to the target server, wherein the backup instruction is used to instruct the target server to back up the panel log, wherein the panel log includes the pagoda panel operation log and the pagoda panel access log;
[0055] The panel log includes the Baota Panel operation log and the Baota Panel access log. The Baota Panel operation log records information such as new operations or modifications performed by users on the Baota Panel. The Baota Panel access log records access information such as user access requests, access time, and terminal used to access the Baota Panel. For example, if the remote server is a Linux system, the Linux cp command can be sent to the target server based on the operation of the forensic personnel to instruct the remote server to copy the panel log. The copied panel log is the panel log before logging into the Baota Panel, that is, the panel log before the forensic operation and access records of the forensic device are recorded.
[0056] Step 130: Log in to the Pagoda panel and obtain a backup file, wherein the backup file is obtained by backing up the data stored on the target server based on the Pagoda panel;
[0057] Log in to the Baota panel, copy the target files stored on the target server based on the Baota panel, obtain the backup files, and download the backup files to the forensic device. The target files may include the website root directory, website database, and website configuration files of the target website. The website root directory, also known as the website root folder, is a folder in the website server that contains all the files that make up the website (such as website programs). The website database is used to store and manage the data of the website. The website configuration file is used to configure the website, including website configuration-related information (such as domain name management, pseudo-static settings, and traffic limits, etc.), firewall configuration information, and the website's FTP information.
[0058] Step 140: Send a log restoration instruction to the target server, where the log restoration instruction is used to instruct the target server to restore the panel log based on the backed-up panel log.
[0059] A log restoration instruction is sent to the target server to instruct the target server to replace the current panel log (i.e., the panel log that has recorded the evidence collection operations and access records of the evidence collection device) with the panel log backed up in step 120. For example, if the remote server is a Linux system, a Linux mv command can be sent to the target server based on the operation of the evidence collection personnel to instruct the remote server to move the panel log copied in step 120 to the folder where the current panel log is located to replace the current panel log.
[0060] The method for collecting evidence on a website server provided by an embodiment of the present invention collects evidence on a target server corresponding to a target website based on the Baota panel. Since the target website is built through the Baota panel, the Baota panel program stores the file storage information of the target website, thereby achieving efficient and complete fixation of the data of the target website and ensuring the content integrity of the collected data. In addition, the method for collecting evidence on a website server provided by an embodiment of the present invention restores the panel log after the evidence collection is completed, ensuring that the data in the target server remains in its original state when the data was generated, thereby protecting the originality of the data.
[0061] The following further describes possible implementations of the above steps in specific embodiments.
[0062] Step 130: log in to the Pagoda panel and obtain a backup file, wherein the backup file is obtained by backing up the data stored on the target server based on the Pagoda panel.
[0063] Optionally, the login panel includes:
[0064] Step 131, obtaining the login information sent by the target server, the login information including the Pagoda panel address, user name and password;
[0065] Specifically, a connection is established with the target server based on a remote control client (such as an SSH client), and a BT command is sent to the target server through the remote control client, instructing the target server to return login information to the forensic device, and receiving the login information sent by the target server to the forensic device. The login information includes the Pagoda panel address, user name and password.
[0066] Step 132: Send an access request to the panel address and log in to the pagoda panel based on the user name and password.
[0067] The forensic device calls the browser program to initiate an access request to the panel address, fills in the user name and password into the input box of the Baota panel web interface, and logs in to the Baota panel.
[0068] Optionally, after sending the access request to the panel address, the method further includes:
[0069] Step 1331: Determine whether basic authorization verification exists, and send a first removal instruction to the target server, wherein the first removal instruction is used to instruct the target server to disable basic authorization verification restrictions;
[0070] Specifically, it is determined that there is a basic authorization verification (such as the user identity authentication displayed on the Baota panel web interface). The basic authorization verification usually uses the method of verifying the user name and password entered by the user to identify the authenticity of the user's identity rights. It can be understood that the basic authorization verification and the login permission verification of the Baota panel constitute a double verification (usually based on security considerations, the username and password for the two verifications are different). Therefore, the username and password obtained in step 131 may not pass the basic authorization verification. Based on the remote control client sending a first removal instruction to the target server, instructing the remote server to back up the basic authorization verification configuration file of the Baota panel, the basic authorization verification configuration file is removed, thereby closing the basic authorization verification.
[0071] Step 1332: After obtaining the backup file, a first restore instruction is sent to the target server, where the first restore instruction is used to instruct the target server to enable basic authorization verification restrictions.
[0072] After the backup file is downloaded locally, the remote control client sends a first restore instruction to the target server to instruct the remote server to restore the backed-up basic authorization verification configuration file, that is, to enable basic authorization verification.
[0073] Optionally, after sending the access request to the panel address, the method further includes:
[0074] Step 1341: Determine if IP restriction exists, and send a second removal instruction to the target server, where the second removal instruction is used to instruct the target server to disable IP restriction.
[0075] Specifically, it is determined that there is an IP restriction (such as the Pagoda panel web interface displays "Your IP is not authorized"), and based on the remote control client, a second removal instruction is sent to the target server, instructing the remote server to back up the IP restriction configuration file of the Pagoda panel, and then remove the basic authorization verification configuration file, thereby turning off the IP restriction.
[0076] Step 1342: After obtaining the backup file, a second restore instruction is sent to the target server, where the second restore instruction is used to instruct the target server to enable IP restriction.
[0077] After the backup file is downloaded locally, the remote control client sends a second restore instruction to the target server, instructing the remote server to restore the backed-up IP restriction configuration file, that is, to enable IP restriction.
[0078] Optionally, the step of sending an access request to the panel address further includes:
[0079] Step 1351: Determine if domain name restriction exists, and send a third removal instruction to the target server, wherein the third removal instruction is used to instruct the target server to disable domain name restriction.
[0080] Specifically, it is determined that there is a domain name restriction (such as the Pagoda panel web interface displays "Please use the correct domain name to access"), and based on the remote control client, a third removal instruction is sent to the target server, instructing the remote server to back up the domain name restriction configuration file of the Pagoda panel, and then remove the basic authorization verification configuration file, thereby closing the domain name restriction.
[0081] Step 1352: After obtaining the backup file, a third restore instruction is sent to the target server, where the third restore instruction is used to instruct the target server to enable domain name restriction.
[0082] After the backup file is downloaded locally, the remote control client sends a third restore instruction to the target server to instruct the remote server to restore the backed-up domain name restriction configuration file, that is, to enable domain name restriction.
[0083] It is understandable that the present invention does not limit the order in which basic authorization verification, IP restriction, and domain name restriction are closed or opened.
[0084] Optionally, the method further includes:
[0085] Step 1361: Determine that the password is incorrect, send a password change instruction to the target server, and obtain a modified password;
[0086] Specifically, it is determined that the password is incorrect (such as after entering the username and password obtained in step 131, the Baota panel web interface displays that the username or password is incorrect), based on the user's input, a password change instruction is generated, and the password change instruction is sent to the target server based on the remote control client to reset the Baota panel login password.
[0087] Step 1362: Log in to the Pagoda panel based on the user name and the modified password.
[0088] On the Baota Panel web page, fill in the user name and modified password into the input box and log in to the Baota Panel.
[0089] Optionally, obtaining the backup file includes:
[0090] Step 137: Back up the target website and the target database corresponding to the target website based on the scheduled task module of the Pagoda panel, and obtain the target website backup file and the target database backup file;
[0091] Specifically, in the scheduled tasks section of the Pagoda panel, select the task type: Backup Website or Backup Database. If the Pagoda panel includes multiple websites, select one or more target websites and their corresponding databases to back up. Backup file storage locations include the target server disk, local storage, and FTP storage. If the backup file is stored in a non-local storage space, the Pagoda panel will download the backup file to the local computer.
[0092] Step 138, sending an installation instruction to the Pagoda panel, wherein the installation instruction is used to instruct the Pagoda panel to install the Pagoda configuration backup plug-in on the target server;
[0093] Step 139: Back up the configuration information of the target website based on the Pagoda configuration backup plug-in to obtain a configuration backup file.
[0094] After the installation is complete, click "Create Backup" and "Download" to download the relevant configuration files to your local computer.
[0095] Optionally, after obtaining the configuration backup file, the method further includes:
[0096] Send a delete instruction to the Baota panel, wherein the delete instruction is used to instruct the Baota panel to delete the backup process file;
[0097] The backup process files include one or more of the following:
[0098] A target website backup file stored on the target server;
[0099] a target database backup file stored on the target server;
[0100] The Pagoda configuration backup plug-in installed on the target server.
[0101] Specifically, the Baota configuration backup plug-in installed on the target server is deleted, and in the case where the backup file is stored on the target server disk, the backup file stored on the target server is deleted. It is understood that the backup file stored on the target server may include the target website backup file, the target database backup file, and the configuration backup file. This ensures that the data in the target server remains in its original state when the data was generated, protecting the originality of the data.
[0102] Figure 2 This is a second flow chart of a method for obtaining evidence from a website server provided by an embodiment of the present invention. Figure 2 As shown, the method for collecting evidence from a website server provided by an embodiment of the present invention includes:
[0103] 1. Start collecting evidence.
[0104] Establish a connection with the target server and log in to the server 10.91.217.XXX.
[0105] 2. Back up operation logs and access logs.
[0106] Send a backup instruction to the target server to back up / www / server / panel / data / default.db (Baota panel operation log) and / www / server / panel / logs / request (Baota panel access log). Send the following Linux command to the target server:
[0107] #Backup default.db;
[0108] cd / www / server / panel / data / ;
[0109] cp default.db default_bak.db;
[0110] #Backup request;
[0111] cd / www / server / panel / logs / ;
[0112] cp -r request request_bak.
[0113] 3. Check the Pagoda panel address, username and password.
[0114] Send bt 14 command to the remote server to view the Baota panel address, username and password. The Baota panel address, username and password sent by the target server are as follows:
[0115] Panel address: http: / / 10.91.217.XXX:8888 / pansafe;
[0116] Username: aaaaaaaaaa;
[0117] Password: 123456.
[0118] 4. Open the browser and visit the Pagoda panel address.
[0119] Visit the Baota panel address: http: / / 10.91.217.XXX:8888 / pansafe.
[0120] 5. If a login window pops up, back up and remove "basic_auth.json".
[0121] If there is BasicAuth authentication, the first removal instruction is sent to the target server to back up the file " / www / server / panel / config / basic_auth.json" and temporarily remove it. Then, a bt4 command is sent to the target server to reload the panel service. The Linux command sent to the target server is as follows:
[0122] cd / www / server / panel / config / ;
[0123] mv basic_auth.json basic_auth_bak.json;
[0124] bt 4.
[0125] 6. If IP is restricted, back up and remove "limitip.conf".
[0126] If there is an IP restriction, send a second removal instruction to the target server, back up the file " / www / server / panel / data / limitip.conf" and temporarily remove it. The Linux command sent to the target server is as follows:
[0127] cd / www / server / panel / data / ;
[0128] mv limitip.conf limitip_bak.conf.
[0129] 7. If you restrict domain names, back up and remove "domain.conf".
[0130] If there is a domain name restriction, a third removal instruction is sent to the target server to back up the file " / www / server / panel / data / domain.conf" and temporarily remove it to disable the domain name restriction. The Linux command sent to the target server is as follows:
[0131] cd / www / server / panel / data / ;
[0132] mv domain.conf domain_bak.conf.
[0133] 8. Try to log in using the obtained username and password.
[0134] After successfully entering the Baota panel, enter the username aaaaaaaaaaa and password 123456 obtained above to log in.
[0135] 9. If you cannot log in normally, change your password and log in again.
[0136] If you are unable to log in, send the password change command "bt 5" to the target server, change the panel password, and log in again.
[0137] 10. After successful login, back up the website, database and configuration files, and download them to your local computer.
[0138] After successfully logging into the Baota panel, click the "Scheduled Tasks" module on the left, select the task type "Backup Website", and select "All" to back up all websites built based on the Baota panel; select the task type "Database" and select "All" to back up all databases.
[0139] After the backup is completed, click "Website" and "Database" on the left to download the backup files of the website and database to your local computer one by one.
[0140] Click "Software Store" on the left and install the "Baota Configuration Backup" plug-in. After the installation is complete, click "Create Backup" and then "Download" to download the relevant configuration files to your local computer.
[0141] 11. Delete the backup file.
[0142] After the electronic data is fixed, the "Baota Configuration Backup" plug-in installed on the target server will be deleted. If during the backup process, you choose to store the website backup files and database backup files on the target server, all website backup files and database backup files stored on the target server will be deleted.
[0143] 12. Restore deleted backup files.
[0144] Restore all the files backed up before logging in, and send the following Linux commands to the target server:
[0145] #Restore default.db
[0146] cd / www / server / panel / data / ;
[0147] mv default_bak.db default.db;
[0148] #Restore request
[0149] cd / www / server / panel / logs / ;
[0150] rm-rf / www / server / panel / logs / request;
[0151] mv / www / server / panel / logs / request_bak / www / server / panel / logs / request;
[0152] #If there is BasicAuth authentication, restore
[0153] cd / www / server / panel / config / ;
[0154] mv basic_auth_bak.json basic_auth.json;
[0155] bt 4;
[0156] #If there is IP restriction, restore
[0157] cd / www / server / panel / data / ;
[0158] mv limitip_bak.conf limitip.conf;
[0159] #If there is a domain name restriction, restore
[0160] cd / www / server / panel / data / ;
[0161] mv domain_bak.conf domain.conf.
[0162] 13. Evidence collection is completed.
[0163] The website server forensics method provided by the present invention protects the originality of the data by backing up operation logs, access logs, and configuration files, and restoring them after forensics is complete. The backup process utilizes the "Scheduled Tasks" and "Baota Configuration Backup" plug-ins, improving efficiency while ensuring the integrity of the forensic data.
[0164] The following describes the device for collecting evidence from a website server provided by the present invention. The device for collecting evidence from a website server described below and the method for collecting evidence from a website server described above can be referenced to each other.
[0165] Figure 3 FIG. 1 is a schematic diagram of a device for collecting evidence from a website server according to an embodiment of the present invention. Figure 3 As shown, the device for collecting evidence from a website server provided by an embodiment of the present invention includes: a connection module 310, an instruction module 320, a backup module 330 and a restoration module 340;
[0166] The connection module 310 is used to establish a connection with a target server, where the target server is a server of a target website, and the target website is built based on the Pagoda panel;
[0167] An instruction module 320 is configured to send a backup instruction to the target server, wherein the backup instruction is configured to instruct the target server to back up panel logs, wherein the panel logs include a Pagoda panel operation log and a Pagoda panel access log;
[0168] The backup module 330 is used to log in to the Pagoda panel and obtain a backup file, wherein the backup file is obtained by backing up the data stored on the target server based on the Pagoda panel;
[0169] The restoration module 340 is configured to send a log restoration instruction to the target server, wherein the log restoration instruction is configured to instruct the target server to restore the panel log.
[0170] It should be noted here that the above-mentioned device provided by the embodiment of the present invention can implement all the method steps implemented by the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects that are the same as the method embodiment in this embodiment will not be described in detail here.
[0171] Figure 4 An example of a physical structure diagram of an electronic device is shown below. Figure 4 As shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communication interface 420, and the memory 430 communicate with each other via the communication bus 440. The processor 410 may call the logic instructions in the memory 430 to execute a method for obtaining evidence from a website server, the method comprising: establishing a connection with a target server, the target server being the server of a target website, the target website being built based on a pagoda panel; sending a backup instruction to the target server, the backup instruction being used to instruct the target server to back up a panel log, the panel log including a pagoda panel operation log and a pagoda panel access log; logging into the pagoda panel to obtain a backup file, the backup file being obtained by backing up the data stored on the target server by the pagoda panel; and sending a log restore instruction to the target server, the log restore instruction being used to instruct the target server to restore the panel log based on the backed-up panel log.
[0172] In addition, the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0173] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the method of collecting evidence on a website server provided by the above methods, the method including: establishing a connection with a target server, the target server is the server of a target website, and the target website is built based on a pagoda panel; sending a backup instruction to the target server, the backup instruction is used to instruct the target server to back up the panel log, the panel log includes a pagoda panel operation log and a pagoda panel access log; logging in to the pagoda panel to obtain a backup file, the backup file is obtained based on the pagoda panel backing up the data stored on the target server; sending a log restore instruction to the target server, the log restore instruction is used to instruct the target server to restore the panel log based on the backed up panel log.
[0174] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the method for collecting evidence on a website server provided by the above-mentioned methods, the method comprising: establishing a connection with a target server, the target server being the server of a target website, the target website being built based on a pagoda panel; sending a backup instruction to the target server, the backup instruction being used to instruct the target server to back up the panel log, the panel log comprising a pagoda panel operation log and a pagoda panel access log; logging into the pagoda panel to obtain a backup file, the backup file being obtained based on backing up the data stored on the target server by the pagoda panel; sending a log restore instruction to the target server, the log restore instruction being used to instruct the target server to restore the panel log based on the backed-up panel log.
[0175] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0176] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.
[0177] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A method for collecting evidence from a website server, characterized in that: include: Establish a connection with the target server, the target server is the server of the target website, and the target website is built based on the Baota panel; Sending a backup instruction to the target server, wherein the backup instruction is used to instruct the target server to back up the panel log, wherein the panel log includes the pagoda panel operation log and the pagoda panel access log; Log in to the Baota panel and obtain a backup file, which is obtained by backing up the data stored on the target server based on the Baota panel; A log restoration instruction is sent to the target server, where the log restoration instruction is used to instruct the target server to restore the panel log based on the backed-up panel log.
2. The method for collecting evidence from a website server according to claim 1, characterized in that: The login panel includes: Obtain the login information sent by the target server, the login information including the Pagoda panel address, user name and password; Send an access request to the panel address and log in to the pagoda panel based on the username and password.
3. The method for collecting evidence from a website server according to claim 2, characterized in that: After sending the access request to the panel address, the method further includes: Determining that basic authorization verification exists, sending a first removal instruction to the target server, where the first removal instruction is used to instruct the target server to disable basic authorization verification restrictions; After obtaining the backup file, a first restore instruction is sent to the target server, where the first restore instruction is used to instruct the target server to enable basic authorization verification restrictions.
4. The method for collecting evidence from a website server according to claim 2, wherein: After sending the access request to the panel address, the method further includes: Determining that an IP restriction exists, sending a second removal instruction to the target server, wherein the second removal instruction is used to instruct the target server to disable the IP restriction; After obtaining the backup file, a second restore instruction is sent to the target server, where the second restore instruction is used to instruct the target server to enable IP restriction.
5. The method for collecting evidence from a website server according to claim 2, characterized in that: The step of sending an access request to the panel address further includes: Determining that a domain name restriction exists, sending a third removal instruction to the target server, wherein the third removal instruction is used to instruct the target server to disable the domain name restriction; After obtaining the backup file, a third restoration instruction is sent to the target server, where the third restoration instruction is used to instruct the target server to enable domain name restriction.
6. The method for collecting evidence from a website server according to claim 2, characterized in that: The method further comprises: Determining that the password is incorrect, sending a password change instruction to the target server, and obtaining a changed password; Log in to the Pagoda panel based on the user name and the modified password.
7. The method for collecting evidence from a website server according to any one of claims 1 to 6, characterized in that: The obtaining of the backup file includes: Back up the target website and the target database corresponding to the target website based on the scheduled task module of the Pagoda panel, and obtain the target website backup file and the target database backup file; Send an installation instruction to the Baota panel, wherein the installation instruction is used to instruct the Baota panel to install the Baota configuration backup plug-in on the target server; The configuration information of the target website is backed up based on the Pagoda configuration backup plug-in to obtain a configuration backup file.
8. The method for collecting evidence from a website server according to claim 7, characterized in that: After obtaining the configuration backup file, the method further includes: Send a delete instruction to the Baota panel, wherein the delete instruction is used to instruct the Baota panel to delete the backup process file; The backup process files include one or more of the following: A target website backup file stored on the target server; A target database backup file stored on the target server; The Pagoda configuration backup plug-in installed on the target server.
9. A device for collecting evidence from a website server, characterized in that: include: A connection module is used to establish a connection with a target server, where the target server is a server of a target website, and the target website is built based on the Pagoda panel; An instruction module is used to send a backup instruction to the target server, wherein the backup instruction is used to instruct the target server to back up the panel log, wherein the panel log includes the pagoda panel operation log and the pagoda panel access log; A backup module is used to log in to the Pagoda panel and obtain a backup file, wherein the backup file is obtained by backing up the data stored on the target server based on the Pagoda panel; The restoration module is used to send a log restoration instruction to the target server, wherein the log restoration instruction is used to instruct the target server to restore the panel log.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the method for collecting evidence from a website server as described in any one of claims 1 to 8 are implemented.
11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for collecting evidence from a website server as claimed in any one of claims 1 to 8 are implemented.
12. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method for collecting evidence from a website server as claimed in any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Online evidence obtaining method and device based on macOS system, equipment and storage medium
CN111339538A
Evidence obtaining method, evidence obtaining device and server
CN112714351A