mirror of
https://github.com/scr34m/php-malware-scanner.git
synced 2026-06-16 12:30:35 +00:00
Compare commits
21 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
55e75079df | ||
|
|
c9e4050b7d | ||
|
|
31fa36c82a | ||
|
|
ba466dc1ff | ||
|
|
201ab77516 | ||
|
|
46024eca5e | ||
|
|
a31cc18dc5 | ||
|
|
96806c69e9 | ||
|
|
42c2aad685 | ||
|
|
cad03dc3b4 | ||
|
|
c542a745e4 | ||
|
|
7ac65c0c8d | ||
|
|
5061e319e3 | ||
|
|
b2b2c4b081 | ||
|
|
26458d20af | ||
|
|
70edc4210d | ||
|
|
aec0f56af5 | ||
|
|
2e8b9c604f | ||
|
|
802ead97cc | ||
|
|
4666a101f9 | ||
|
|
e4755feeef |
3
.gitignore
vendored
Normal file
3
.gitignore
vendored
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
.idea/
|
||||||
|
whitelist.dat
|
||||||
|
vendor/
|
||||||
15
Dockerfile
Normal file
15
Dockerfile
Normal file
@@ -0,0 +1,15 @@
|
|||||||
|
FROM php:8.2-cli
|
||||||
|
|
||||||
|
# Install dependencies
|
||||||
|
RUN apt-get update && apt-get install -y \
|
||||||
|
git \
|
||||||
|
unzip \
|
||||||
|
libzip-dev \
|
||||||
|
&& docker-php-ext-install zip
|
||||||
|
|
||||||
|
WORKDIR /scanner
|
||||||
|
COPY . .
|
||||||
|
RUN chmod +x scan
|
||||||
|
|
||||||
|
ENTRYPOINT ["./scan"]
|
||||||
|
CMD ["/code"]
|
||||||
36
README.md
36
README.md
@@ -34,7 +34,7 @@ Usage: php scan.php -d <directory>
|
|||||||
-t --time Show time of last file change
|
-t --time Show time of last file change
|
||||||
-L --line-number Display matching pattern line number in file
|
-L --line-number Display matching pattern line number in file
|
||||||
-o --output-format Custom defined output format
|
-o --output-format Custom defined output format
|
||||||
-j --wordpress-version Version of wordpress to get md5 signatures
|
-j <version> --wordpress-version Version of wordpress to get md5 signatures
|
||||||
--combined-whitelist Combined whitelist
|
--combined-whitelist Combined whitelist
|
||||||
--custom-whitelist Loads whitelist from specified file and merge with existing
|
--custom-whitelist Loads whitelist from specified file and merge with existing
|
||||||
--disable-stats Disable statistics output
|
--disable-stats Disable statistics output
|
||||||
@@ -146,3 +146,37 @@ Licensing
|
|||||||
---------
|
---------
|
||||||
|
|
||||||
PHP malware scanner is [licensed](https://github.com/scr34m/php-malware-scanner/blob/master/LICENSE.txt) under the GNU General Public License v3.
|
PHP malware scanner is [licensed](https://github.com/scr34m/php-malware-scanner/blob/master/LICENSE.txt) under the GNU General Public License v3.
|
||||||
|
|
||||||
|
Docker Usage
|
||||||
|
-----------
|
||||||
|
|
||||||
|
You can also run the scanner using Docker:
|
||||||
|
|
||||||
|
1. Build the image:
|
||||||
|
```bash
|
||||||
|
docker build -t php-malware-scanner .
|
||||||
|
```
|
||||||
|
|
||||||
|
2. Scan a directory:
|
||||||
|
```bash
|
||||||
|
docker run -v /path/to/scan:/code php-malware-scanner -d /code
|
||||||
|
```
|
||||||
|
|
||||||
|
For example, to scan a WordPress installation:
|
||||||
|
```bash
|
||||||
|
docker run -v /var/www/html:/code php-malware-scanner -d /code -j 6.4.1
|
||||||
|
```
|
||||||
|
|
||||||
|
Common usage with flags:
|
||||||
|
```bash
|
||||||
|
# Show only infected files (hide OK status)
|
||||||
|
docker run -v /path/to/scan:/code php-malware-scanner -d /code -k
|
||||||
|
|
||||||
|
# Show comments for matched patterns
|
||||||
|
docker run -v /path/to/scan:/code php-malware-scanner -d /code -c
|
||||||
|
|
||||||
|
# Show MD5 hashes and continue after first match
|
||||||
|
docker run -v /path/to/scan:/code php-malware-scanner -d /code -m -s
|
||||||
|
```
|
||||||
|
|
||||||
|
The `/code` directory inside the container is where your files will be mounted for scanning.
|
||||||
|
|||||||
@@ -6,7 +6,7 @@
|
|||||||
"license": "GPL-3.0",
|
"license": "GPL-3.0",
|
||||||
"homepage": "https://github.com/scr34m/php-malware-scanner",
|
"homepage": "https://github.com/scr34m/php-malware-scanner",
|
||||||
"require": {
|
"require": {
|
||||||
"php": ">=5.2.0"
|
"php": ">=5.3.0"
|
||||||
},
|
},
|
||||||
"autoload": {
|
"autoload": {
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -22,14 +22,23 @@ SHELL_PASSWORD
|
|||||||
ConnectBackShell
|
ConnectBackShell
|
||||||
ShellBOT
|
ShellBOT
|
||||||
== "bindshell"
|
== "bindshell"
|
||||||
|
".\x00..\x20"
|
||||||
|
FM_SESSION_ID
|
||||||
|
HACKED BY
|
||||||
|
_Mybb
|
||||||
|
|
||||||
#Remote Code
|
#Remote Code
|
||||||
curl_get_from_webpage
|
curl_get_from_webpage
|
||||||
file_get_contents('http://codepad.org
|
file_get_contents('http://codepad.org
|
||||||
|
|
||||||
|
#mailers
|
||||||
|
leafmailer.pw
|
||||||
|
|
||||||
#Base64 String Samples. Each plain text string should have 3 base64 equivalents
|
#Base64 String Samples. Each plain text string should have 3 base64 equivalents
|
||||||
|
|
||||||
|
# https://
|
||||||
|
aHR0cHM6Ly
|
||||||
|
|
||||||
# "shell" in base64
|
# "shell" in base64
|
||||||
c2hlbG
|
c2hlbG
|
||||||
NoZWxs
|
NoZWxs
|
||||||
@@ -179,15 +188,23 @@ RlZmluZ
|
|||||||
kZWZpbm
|
kZWZpbm
|
||||||
|
|
||||||
# Obfuscation related code
|
# Obfuscation related code
|
||||||
|
'.'6'.'4'.'_'.'
|
||||||
|
bas'.'e64_dec
|
||||||
|
file'.'_put_co
|
||||||
|
fil'.'e_ex
|
||||||
|
Pz4=
|
||||||
|
L3gvaQ==
|
||||||
eval("?>
|
eval("?>
|
||||||
eval('?>
|
eval('?>
|
||||||
|
@eval(
|
||||||
"base64_decode"
|
"base64_decode"
|
||||||
='base'.(32*2).'_de'.'code'
|
='base'.(32*2).'_de'.'code'
|
||||||
"p"."r"."e"."g"."_"
|
"p"."r"."e"."g"."_"
|
||||||
WSOstripslashes
|
WSOstripslashes
|
||||||
\x73\x79\x73\x74\x65\x6d' /* case, dec/hex issue? */, // system
|
\x5f\x43\x4f\x4f\x4b\x49\x45
|
||||||
\x70\x72\x65\x67\x5f\x72\x65\x70\x6c\x61\x63\x65' /* case, dec/hex issue? */, // preg_replace
|
\x73\x79\x73\x74\x65\x6d
|
||||||
\x65\x78\x65\x63' /* dec/hex issue? */, // exec
|
\x70\x72\x65\x67\x5f\x72\x65\x70\x6c\x61\x63\x65
|
||||||
|
\x65\x78\x65\x63
|
||||||
ev\x61l
|
ev\x61l
|
||||||
\x65\166\x61\154\x28' /* dec/hex issue? */,
|
\x65\166\x61\154\x28' /* dec/hex issue? */,
|
||||||
\x65\x76\x61\x6C' /* case, dec/hex issue? */,
|
\x65\x76\x61\x6C' /* case, dec/hex issue? */,
|
||||||
@@ -200,11 +217,21 @@ base=base64_encode
|
|||||||
'b'.'ase6'.'4_e'.'ncode'
|
'b'.'ase6'.'4_e'.'ncode'
|
||||||
cr"."eat"."e_fun"."cti"."on
|
cr"."eat"."e_fun"."cti"."on
|
||||||
gz'.'inf'.'late
|
gz'.'inf'.'late
|
||||||
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
|
||||||
http://www.fopo.com.ar/
|
|
||||||
@eval("\
|
@eval("\
|
||||||
";eval(
|
";eval(
|
||||||
eval(eval(
|
eval(eval(
|
||||||
|
@eval(`
|
||||||
|
eVaL('?>
|
||||||
|
eval($_REQUEST
|
||||||
|
convert_uudecode(convert_uuencode
|
||||||
|
"64_decode"
|
||||||
|
'f' . 'il' . 'e' . '_'
|
||||||
|
'co' . 'nt' . 'e' . 'nt'
|
||||||
|
'h' . 'tm' . 'l' . 'sp'
|
||||||
|
'ha' . 'r' . 's'
|
||||||
|
|
||||||
|
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
||||||
|
http://www.fopo.com.ar/
|
||||||
|
|
||||||
#Malware/Attack specific strings/fingerprints/signatures
|
#Malware/Attack specific strings/fingerprints/signatures
|
||||||
MagelangCyber
|
MagelangCyber
|
||||||
@@ -262,6 +289,13 @@ FaisaL Ahmed aka rEd X
|
|||||||
smisbot
|
smisbot
|
||||||
smotherbot
|
smotherbot
|
||||||
Indonesian Hacker Rulez
|
Indonesian Hacker Rulez
|
||||||
|
pwetan.com
|
||||||
|
iNHUMaN
|
||||||
|
Heartzz
|
||||||
|
Bye Bye Litespeed
|
||||||
|
BunnyInvisible
|
||||||
|
SEMOGABERKAH
|
||||||
|
BUTERFLYCOUNTRY
|
||||||
|
|
||||||
# WP-VCD Malware https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/
|
# WP-VCD Malware https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/
|
||||||
wp-vcd
|
wp-vcd
|
||||||
@@ -359,6 +393,7 @@ php_uname()
|
|||||||
str_split(rawurldecode(str_rot13(
|
str_split(rawurldecode(str_rot13(
|
||||||
# generating PHP file name to put content
|
# generating PHP file name to put content
|
||||||
substr(md5(time()), 0, 8) . ".php"
|
substr(md5(time()), 0, 8) . ".php"
|
||||||
|
'a:1:{s:13:\"administrator\";b:1;}'
|
||||||
|
|
||||||
# webshell
|
# webshell
|
||||||
0byt3m1n1
|
0byt3m1n1
|
||||||
@@ -377,6 +412,7 @@ ZeroByte
|
|||||||
# SEO poisoning control site call
|
# SEO poisoning control site call
|
||||||
"http://$xxx
|
"http://$xxx
|
||||||
?useragent=$botbotbot
|
?useragent=$botbotbot
|
||||||
|
[#*#*#]
|
||||||
|
|
||||||
# php://input encoded in base64
|
# php://input encoded in base64
|
||||||
cGhwOi8vaW5wdXQ=
|
cGhwOi8vaW5wdXQ=
|
||||||
@@ -395,6 +431,7 @@ Array("1207", "3gso", "4thp", "501i", "502i", "503i", "504i", "505i", "506i",
|
|||||||
|
|
||||||
# eval url decoded string
|
# eval url decoded string
|
||||||
eval(rawurldecode('
|
eval(rawurldecode('
|
||||||
|
eval(htmlspecialchars_decode(
|
||||||
|
|
||||||
# simple obfuscated function
|
# simple obfuscated function
|
||||||
'gz'.'unc'.'ompress'
|
'gz'.'unc'.'ompress'
|
||||||
@@ -404,3 +441,30 @@ eval(rawurldecode('
|
|||||||
'base', '64_dec', 'ode'
|
'base', '64_dec', 'ode'
|
||||||
'cook', 'set', 'ie'
|
'cook', 'set', 'ie'
|
||||||
'repl', 'str_', 'ace'
|
'repl', 'str_', 'ace'
|
||||||
|
"base"."64_"
|
||||||
|
'base'.'64_'
|
||||||
|
"t"."m"."p"."_"."n"."a"."m"."e"
|
||||||
|
"f"."i"."l"."e"."_"."p"."u"."t"
|
||||||
|
"f"."i"."l"."e"."_"."g"."e"."t"
|
||||||
|
'ode', 'e64_', 'bas', 'dec'
|
||||||
|
'unct', 'ion', 'te_f', 'crea'
|
||||||
|
'te', 'g', 'nf', 'l', 'a', 'zi'
|
||||||
|
'tion', 'e_func', 'creat'
|
||||||
|
'64_d', 'se', 'eco', 'de', 'ba'
|
||||||
|
'co', 'ki', 'e', 'o', 'set'
|
||||||
|
'str', '_rep', 'lace'
|
||||||
|
|
||||||
|
# process data from request object directly
|
||||||
|
extract($_REQUEST) && @$
|
||||||
|
extract($_REQUEST)&&@$
|
||||||
|
xtract($_REQUEST)&&@$
|
||||||
|
|
||||||
|
# uncompress cafted content
|
||||||
|
gzuncompress(strrev(substr(
|
||||||
|
|
||||||
|
# disable error reporting
|
||||||
|
<?php error_reporting(0);?>
|
||||||
|
|
||||||
|
# infected file include attached on the top of a legit file
|
||||||
|
<?php if (file_exists(dirname(__FILE__) . '/class.theme-modules.php')) include_once(dirname(__FILE__) . '/class.theme-modules.php'); ?>
|
||||||
|
<?php if (file_exists(dirname(__FILE__) . '/class.plugin-modules.php')) include_once(dirname(__FILE__) . '/class.plugin-modules.php'); ?>
|
||||||
|
|||||||
@@ -79,7 +79,7 @@ chr\s*\(\s*['"]?\s*((95)|(0[Xx]5[Ff]))\s*['"]?\s*\)
|
|||||||
#Escaped path characters: \x2fho\x6de/\x69mp\x75ls\x69oq\x65/w\x77w. or \x2fhome\x2fimpu\x6csioq\x65/www\x2emusc
|
#Escaped path characters: \x2fho\x6de/\x69mp\x75ls\x69oq\x65/w\x77w. or \x2fhome\x2fimpu\x6csioq\x65/www\x2emusc
|
||||||
(\\x[0-9abcdef]{2}[a-z0-9.-\/]{1,4}){4,}
|
(\\x[0-9abcdef]{2}[a-z0-9.-\/]{1,4}){4,}
|
||||||
|
|
||||||
#Malware inffected files sometimes marked with comments like /*87cda*/ to avoid infect again
|
#Malware infected files sometimes marked with comments like /*87cda*/ to avoid infect again
|
||||||
\/\*[a-z0-9]{5}\*\/
|
\/\*[a-z0-9]{5}\*\/
|
||||||
|
|
||||||
# XOR-ed strings with custom math
|
# XOR-ed strings with custom math
|
||||||
@@ -141,10 +141,27 @@ explode\('\|\x01\|\x03\|\x03', gzinflate\(
|
|||||||
\$[a-z]11 \^ [a-z]8\(\$[a-z]6, \$[a-z]14, \$[a-z]6\[13\]\(\$[a-z]11\)\)\)\);
|
\$[a-z]11 \^ [a-z]8\(\$[a-z]6, \$[a-z]14, \$[a-z]6\[13\]\(\$[a-z]11\)\)\)\);
|
||||||
|
|
||||||
# eval function return and concat
|
# eval function return and concat
|
||||||
eval\([A-Za-z]{5,}\(\) \. '
|
eval\([A-Za-z0-9]{5,}\(\) \. '
|
||||||
|
|
||||||
# eval function return, parameter is a hex string
|
# eval function return, parameter is a hex string
|
||||||
eval\([A-Za-z0-9]{5,}\(\"[A-Z0-9]{16,}
|
eval\([A-Za-z0-9]{5,}\(\"[A-Z0-9]{16,}
|
||||||
|
|
||||||
|
eval\(\s+'\?>'
|
||||||
|
|
||||||
# gzip payload called by variable named function
|
# gzip payload called by variable named function
|
||||||
\$[a-zA-Z0-9]{6,}\('\x78\x9C\xAD\x90\x41\x0E
|
\$[a-zA-Z0-9]{6,}\('\x78\x9C\xAD\x90\x41\x0E
|
||||||
|
|
||||||
|
# obfuscated code return with error suppression
|
||||||
|
return @\$[a-z]{2}\d+\[\d+\]\(\$[a-z]{2}\d+\[\d+\],
|
||||||
|
|
||||||
|
# htaccess alternating
|
||||||
|
[a-z]{1}\([a-z]{1}\(\$[a-z]{2}\.'\/\.htaccess'\)
|
||||||
|
|
||||||
|
# Javascript specific rules
|
||||||
|
|
||||||
|
# JS - escaped command
|
||||||
|
\.fromCharCode\([0-9,]{4,}\)
|
||||||
|
\+-parseInt\(\w\('0x[0-9a-z]+'\)\)\/
|
||||||
|
|
||||||
|
# concated hash value
|
||||||
|
('[a-z0-9]{2,}'\.){4,}
|
||||||
|
|||||||
59
scan.php
59
scan.php
@@ -203,7 +203,10 @@ class MalwareScanner
|
|||||||
$fp = fopen($file, 'r');
|
$fp = fopen($file, 'r');
|
||||||
while (!feof($fp)) {
|
while (!feof($fp)) {
|
||||||
$line = fgets($fp);
|
$line = fgets($fp);
|
||||||
$this->whitelist[] = substr($line, 0, 32);
|
$hash = substr($line, 0, 32);
|
||||||
|
if (strlen($hash) === 32) {
|
||||||
|
$this->whitelist[] = $hash;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
fclose($fp);
|
fclose($fp);
|
||||||
}
|
}
|
||||||
@@ -212,16 +215,32 @@ class MalwareScanner
|
|||||||
|
|
||||||
public function addWordpressChecksums($wp_version)
|
public function addWordpressChecksums($wp_version)
|
||||||
{
|
{
|
||||||
$apiurl = 'https://api.wordpress.org/core/checksums/1.0/?version=' . $wp_version;
|
if (!preg_match('/^\d+\.\d+(\.\d+)?$/', $wp_version)) {
|
||||||
$json = json_decode(file_get_contents($apiurl));
|
$this->error('Invalid WordPress version format: ' . $wp_version);
|
||||||
$checksums = $json->checksums;
|
exit(-1);
|
||||||
|
}
|
||||||
|
|
||||||
if ($checksums->$wp_version == false) { #no checksum returned
|
$apiurl = 'https://api.wordpress.org/core/checksums/1.0/?version=' . $wp_version;
|
||||||
|
$raw = file_get_contents($apiurl);
|
||||||
|
if ($raw === false) {
|
||||||
$this->error('Cannot load wordpress checksums from: ' . $apiurl);
|
$this->error('Cannot load wordpress checksums from: ' . $apiurl);
|
||||||
exit(-1);
|
exit(-1);
|
||||||
}
|
}
|
||||||
|
|
||||||
foreach ($checksums->$wp_version as $file => $checksum) {
|
$json = json_decode($raw);
|
||||||
|
if ($json === null || !isset($json->checksums)) {
|
||||||
|
$this->error('Invalid response from WordPress checksums API');
|
||||||
|
exit(-1);
|
||||||
|
}
|
||||||
|
|
||||||
|
$checksums = $json->checksums;
|
||||||
|
if ($checksums === false || empty((array)$checksums)) {
|
||||||
|
$this->error('No checksums returned for WordPress version: ' . $wp_version);
|
||||||
|
exit(-1);
|
||||||
|
}
|
||||||
|
|
||||||
|
$entries = isset($checksums->$wp_version) ? $checksums->$wp_version : $checksums;
|
||||||
|
foreach ($entries as $file => $checksum) {
|
||||||
$this->whitelist[] = $checksum;
|
$this->whitelist[] = $checksum;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -231,7 +250,7 @@ class MalwareScanner
|
|||||||
private function parseArgs()
|
private function parseArgs()
|
||||||
{
|
{
|
||||||
$options = getopt(
|
$options = getopt(
|
||||||
'd:e:i:o:abmcxlhkwnsptLj:E',
|
'd:e:i:o:abmcxlhkrwnsptLj:E',
|
||||||
array(
|
array(
|
||||||
'directory:',
|
'directory:',
|
||||||
'extension:',
|
'extension:',
|
||||||
@@ -244,6 +263,7 @@ class MalwareScanner
|
|||||||
'follow-link',
|
'follow-link',
|
||||||
'help',
|
'help',
|
||||||
'hide-ok',
|
'hide-ok',
|
||||||
|
'hide-err',
|
||||||
'hide-whitelist',
|
'hide-whitelist',
|
||||||
'no-color',
|
'no-color',
|
||||||
'no-stop',
|
'no-stop',
|
||||||
@@ -622,8 +642,8 @@ class MalwareScanner
|
|||||||
private function report($start, $dir)
|
private function report($start, $dir)
|
||||||
{
|
{
|
||||||
$end = time();
|
$end = time();
|
||||||
echo 'Start time: ' . strftime('%Y-%m-%d %H:%M:%S', $start) . PHP_EOL;
|
echo 'Start time: ' . date('Y-m-d H:i:s', $start) . PHP_EOL;
|
||||||
echo 'End time: ' . strftime('%Y-%m-%d %H:%M:%S', $end) . PHP_EOL;
|
echo 'End time: ' . date('Y-m-d H:i:s', $end) . PHP_EOL;
|
||||||
echo 'Total execution time: ' . ($end - $start) . PHP_EOL;
|
echo 'Total execution time: ' . ($end - $start) . PHP_EOL;
|
||||||
echo 'Base directory: ' . $dir . PHP_EOL;
|
echo 'Base directory: ' . $dir . PHP_EOL;
|
||||||
echo 'Total directories scanned: ' . $this->stat['directories'] . PHP_EOL;
|
echo 'Total directories scanned: ' . $this->stat['directories'] . PHP_EOL;
|
||||||
@@ -679,6 +699,12 @@ class MalwareScanner
|
|||||||
{
|
{
|
||||||
$this->stat['files_scanned']++;
|
$this->stat['files_scanned']++;
|
||||||
$fileContent = file_get_contents($path);
|
$fileContent = file_get_contents($path);
|
||||||
|
if ($fileContent === false) {
|
||||||
|
if (!$this->flagHideErr) {
|
||||||
|
echo $this->ANSI_RED . '# ER' . $this->ANSI_OFF . ' # {' . $path . '} (unreadable)' . PHP_EOL;
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
$found = false;
|
$found = false;
|
||||||
$inWhitelist = false;
|
$inWhitelist = false;
|
||||||
$hash = md5($fileContent);
|
$hash = md5($fileContent);
|
||||||
@@ -724,7 +750,10 @@ class MalwareScanner
|
|||||||
//Patterns will match multiple lines, though you can use ^$ to match the beginning and end of a line.
|
//Patterns will match multiple lines, though you can use ^$ to match the beginning and end of a line.
|
||||||
private function scanFunc_RE(&$pattern, &$content)
|
private function scanFunc_RE(&$pattern, &$content)
|
||||||
{
|
{
|
||||||
$ret = preg_match('/' . $pattern . '/im', $content, $match, PREG_OFFSET_CAPTURE);
|
$ret = @preg_match('/' . $pattern . '/im', $content, $match, PREG_OFFSET_CAPTURE);
|
||||||
|
if ($ret === false) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
if ($ret) {
|
if ($ret) {
|
||||||
return $match[0][1];
|
return $match[0][1];
|
||||||
}
|
}
|
||||||
@@ -789,11 +818,14 @@ class MalwareScanner
|
|||||||
|
|
||||||
private function updateCombinedWhitelist($url = 'https://scr34m.github.io/php-malware-scanner')
|
private function updateCombinedWhitelist($url = 'https://scr34m.github.io/php-malware-scanner')
|
||||||
{
|
{
|
||||||
$latest_hash = trim(file_get_contents($url . '/database/compressed.sha256'));
|
$ctx = stream_context_create(array('http' => array('timeout' => 30)));
|
||||||
|
|
||||||
|
$latest_hash = file_get_contents($url . '/database/compressed.sha256', false, $ctx);
|
||||||
if ($latest_hash === false) {
|
if ($latest_hash === false) {
|
||||||
$this->error('Unable to download database checksum');
|
$this->error('Unable to download database checksum');
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
$latest_hash = trim($latest_hash);
|
||||||
|
|
||||||
$file = __DIR__ . '/whitelist.dat';
|
$file = __DIR__ . '/whitelist.dat';
|
||||||
if (is_readable($file)) {
|
if (is_readable($file)) {
|
||||||
@@ -808,7 +840,7 @@ class MalwareScanner
|
|||||||
}
|
}
|
||||||
|
|
||||||
if ($download) {
|
if ($download) {
|
||||||
$data = file_get_contents($url . '/database/compressed.dat');
|
$data = file_get_contents($url . '/database/compressed.dat', false, $ctx);
|
||||||
if ($data === false) {
|
if ($data === false) {
|
||||||
$this->error('Unable to download database');
|
$this->error('Unable to download database');
|
||||||
return false;
|
return false;
|
||||||
@@ -818,6 +850,7 @@ class MalwareScanner
|
|||||||
$hash = hash_file('sha256', $file);
|
$hash = hash_file('sha256', $file);
|
||||||
if ($hash != $latest_hash) {
|
if ($hash != $latest_hash) {
|
||||||
$this->error('Downloaded database hash mismatch');
|
$this->error('Downloaded database hash mismatch');
|
||||||
|
return false;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -859,7 +892,7 @@ class MalwareScanner
|
|||||||
echo ' -t --time Show time of last file change' . PHP_EOL;
|
echo ' -t --time Show time of last file change' . PHP_EOL;
|
||||||
echo ' -L --line-number Display matching pattern line number in file' . PHP_EOL;
|
echo ' -L --line-number Display matching pattern line number in file' . PHP_EOL;
|
||||||
echo ' -o --output-format Custom defined output format' . PHP_EOL;
|
echo ' -o --output-format Custom defined output format' . PHP_EOL;
|
||||||
echo ' -j --wordpress-version Version of wordpress to get md5 signatures' . PHP_EOL;
|
echo ' -j <version> --wordpress-version Version of wordpress to get md5 signatures' . PHP_EOL;
|
||||||
echo ' --combined-whitelist Combined whitelist' . PHP_EOL;
|
echo ' --combined-whitelist Combined whitelist' . PHP_EOL;
|
||||||
echo ' --disable-stats Disable statistics output' . PHP_EOL;
|
echo ' --disable-stats Disable statistics output' . PHP_EOL;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user