mirror of
https://github.com/scr34m/php-malware-scanner.git
synced 2026-06-16 12:30:35 +00:00
Compare commits
21 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bf13288367 | ||
|
|
088c0761b3 | ||
|
|
18b06fc48b | ||
|
|
f1b8b89ca5 | ||
|
|
c6a52dc67e | ||
|
|
3b76a7270e | ||
|
|
f0bdb1f1e1 | ||
|
|
43876b337b | ||
|
|
1fad164790 | ||
|
|
f4d53e89d8 | ||
|
|
34ea02323b | ||
|
|
b74494a4f1 | ||
|
|
9624ec4403 | ||
|
|
335b13b7c4 | ||
|
|
78bee49176 | ||
|
|
cc0fdc7a9f | ||
|
|
ec8f9920ba | ||
|
|
5883c68f54 | ||
|
|
22b51a1ee3 | ||
|
|
2b1a0c1266 | ||
|
|
c495cc822c |
18
README.md
18
README.md
@@ -26,6 +26,7 @@ Usage: php scan.php -d <directory>
|
|||||||
-x --extra-check Adds GoogleBot and htaccess to Scan List
|
-x --extra-check Adds GoogleBot and htaccess to Scan List
|
||||||
-l --follow-symlink Follow symlinked directories
|
-l --follow-symlink Follow symlinked directories
|
||||||
-k --hide-ok Hide results with 'OK' status
|
-k --hide-ok Hide results with 'OK' status
|
||||||
|
-r --hide-err Hide results with 'ER' status
|
||||||
-w --hide-whitelist Hide results with 'WL' status
|
-w --hide-whitelist Hide results with 'WL' status
|
||||||
-n --no-color Disable color mode
|
-n --no-color Disable color mode
|
||||||
-s --no-stop Continue scanning file after first hit
|
-s --no-stop Continue scanning file after first hit
|
||||||
@@ -35,6 +36,7 @@ Usage: php scan.php -d <directory>
|
|||||||
-o --output-format Custom defined output format
|
-o --output-format Custom defined output format
|
||||||
-j --wordpress-version Version of wordpress to get md5 signatures
|
-j --wordpress-version Version of wordpress to get md5 signatures
|
||||||
--combined-whitelist Combined whitelist
|
--combined-whitelist Combined whitelist
|
||||||
|
--custom-whitelist Loads whitelist from specified file and merge with existing
|
||||||
--disable-stats Disable statistics output
|
--disable-stats Disable statistics output
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -113,6 +115,22 @@ It is guaranteed that IF 'base64_decode' was present in the plain text code, the
|
|||||||
The presence of 'YmFzZTY0X2RlY29kZ' in a block of code may be because 'ase64_decod' was in the original code.
|
The presence of 'YmFzZTY0X2RlY29kZ' in a block of code may be because 'ase64_decod' was in the original code.
|
||||||
ote the missing edge characters which is due to bit misalignment and character bleed.
|
ote the missing edge characters which is due to bit misalignment and character bleed.
|
||||||
|
|
||||||
|
Using as library
|
||||||
|
----------------
|
||||||
|
|
||||||
|
The scan.php perform a check, that it's called by commandline or not, so to use as library use different directory than scan.php it self.
|
||||||
|
|
||||||
|
```php
|
||||||
|
<?php
|
||||||
|
|
||||||
|
require_once '../scan.php';
|
||||||
|
|
||||||
|
$scan = new MalwareScanner();
|
||||||
|
$scan->setFlagHideWhitelist(true);
|
||||||
|
$scan->setFlagHideOk(true);
|
||||||
|
$scan->run('../samples/test');
|
||||||
|
```
|
||||||
|
|
||||||
Resources
|
Resources
|
||||||
---------
|
---------
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#This file contains raw strings that will be matched case-insensitive.
|
# This file contains raw strings that will be matched case-insensitive.
|
||||||
#Comments and whitespace are possible, but comments must have '#' at the first character of the line.
|
# Comments and whitespace are possible, but comments must have '#' at the first character of the line.
|
||||||
|
|
||||||
#List of security service providers that phishers often block.
|
# List of security service providers that phishers often block.
|
||||||
abovenet
|
abovenet
|
||||||
avira
|
avira
|
||||||
bitdefender
|
bitdefender
|
||||||
@@ -16,4 +16,7 @@ opendns
|
|||||||
phishtank
|
phishtank
|
||||||
sophos
|
sophos
|
||||||
surfright
|
surfright
|
||||||
symantec
|
# symantec - removed because already a TLD too so generate many false positives
|
||||||
|
|
||||||
|
# SEO poison, pharmacy redirect
|
||||||
|
dealonline.su
|
||||||
@@ -108,11 +108,6 @@ SFRUUF9VU0VSX0FHRU5U
|
|||||||
hUVFBfVVNFUl9BR0VOV
|
hUVFBfVVNFUl9BR0VOV
|
||||||
IVFRQX1VTRVJfQUdFTl
|
IVFRQX1VTRVJfQUdFTl
|
||||||
|
|
||||||
# "file" in base64
|
|
||||||
ZmlsZ
|
|
||||||
ZpbG
|
|
||||||
maWxl
|
|
||||||
|
|
||||||
# "gzinflate" in base64
|
# "gzinflate" in base64
|
||||||
Z3ppbmZsYXRl
|
Z3ppbmZsYXRl
|
||||||
d6aW5mbGF0Z
|
d6aW5mbGF0Z
|
||||||
@@ -185,6 +180,7 @@ kZWZpbm
|
|||||||
|
|
||||||
# Obfuscation related code
|
# Obfuscation related code
|
||||||
eval("?>
|
eval("?>
|
||||||
|
eval('?>
|
||||||
"base64_decode"
|
"base64_decode"
|
||||||
='base'.(32*2).'_de'.'code'
|
='base'.(32*2).'_de'.'code'
|
||||||
"p"."r"."e"."g"."_"
|
"p"."r"."e"."g"."_"
|
||||||
@@ -201,11 +197,14 @@ eval(base64_decode(
|
|||||||
$data = base64_decode("
|
$data = base64_decode("
|
||||||
edoced_46esab
|
edoced_46esab
|
||||||
base=base64_encode
|
base=base64_encode
|
||||||
|
'b'.'ase6'.'4_e'.'ncode'
|
||||||
cr"."eat"."e_fun"."cti"."on
|
cr"."eat"."e_fun"."cti"."on
|
||||||
gz'.'inf'.'late
|
gz'.'inf'.'late
|
||||||
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
||||||
http://www.fopo.com.ar/
|
http://www.fopo.com.ar/
|
||||||
@eval("\
|
@eval("\
|
||||||
|
";eval(
|
||||||
|
eval(eval(
|
||||||
|
|
||||||
#Malware/Attack specific strings/fingerprints/signatures
|
#Malware/Attack specific strings/fingerprints/signatures
|
||||||
MagelangCyber
|
MagelangCyber
|
||||||
@@ -260,6 +259,9 @@ itsoknoproblembro
|
|||||||
tmhapbzcerff
|
tmhapbzcerff
|
||||||
IndoXploit
|
IndoXploit
|
||||||
FaisaL Ahmed aka rEd X
|
FaisaL Ahmed aka rEd X
|
||||||
|
smisbot
|
||||||
|
smotherbot
|
||||||
|
Indonesian Hacker Rulez
|
||||||
|
|
||||||
# WP-VCD Malware https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/
|
# WP-VCD Malware https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/
|
||||||
wp-vcd
|
wp-vcd
|
||||||
@@ -371,3 +373,24 @@ ZeroByte
|
|||||||
|
|
||||||
# JS escaped: String.fromCharCode(
|
# JS escaped: String.fromCharCode(
|
||||||
83, 116, 114, 105, 110, 103, 46, 102, 114, 111, 109, 67, 104, 97, 114, 67, 111, 100, 101, 40
|
83, 116, 114, 105, 110, 103, 46, 102, 114, 111, 109, 67, 104, 97, 114, 67, 111, 100, 101, 40
|
||||||
|
|
||||||
|
# SEO poisoning control site call
|
||||||
|
"http://$xxx
|
||||||
|
?useragent=$botbotbot
|
||||||
|
|
||||||
|
# php://input encoded in base64
|
||||||
|
cGhwOi8vaW5wdXQ=
|
||||||
|
|
||||||
|
# backdoor script
|
||||||
|
<font color="red">Upload Gagal..</font><br />
|
||||||
|
explode('?>',$shell
|
||||||
|
|
||||||
|
# common mobile agent check in SEO poison scripts
|
||||||
|
Array("1207", "3gso", "4thp", "501i", "502i", "503i", "504i", "505i", "506i",
|
||||||
|
|
||||||
|
# eval url decoded string
|
||||||
|
eval(rawurldecode('
|
||||||
|
|
||||||
|
# simple obfuscated function
|
||||||
|
'gz'.'unc'.'ompress'
|
||||||
|
'create'.'_'.'function'
|
||||||
@@ -4,10 +4,13 @@ eval\/\*[a-z0-9]+\*\/
|
|||||||
#
|
#
|
||||||
eval\([a-z0-9]{4,}\(\$[a-z0-9]{4,}, \$[0-9a-z]{4,}\)\);
|
eval\([a-z0-9]{4,}\(\$[a-z0-9]{4,}, \$[0-9a-z]{4,}\)\);
|
||||||
|
|
||||||
#
|
# chr(101).chr(118).chr(97)
|
||||||
(chr\(\d+\^\d+\)\.){4,}
|
(chr\(\d+\^\d+\)\.){4,}
|
||||||
|
|
||||||
#
|
# $_uU(101).$_uU(118).$_uU(97)
|
||||||
|
(\$\_[a-z0-9]{2,}\(\d+\)\.){4,}
|
||||||
|
|
||||||
|
# $uUx[101].$uUx[118].$uUx[97]
|
||||||
(\$[a-z0-9]{3,}\[\d+\]\.){4,}
|
(\$[a-z0-9]{3,}\[\d+\]\.){4,}
|
||||||
|
|
||||||
#
|
#
|
||||||
@@ -37,6 +40,9 @@ Googlebot['"]{0,1}\s*\)\){echo\s+file_get_contents
|
|||||||
#execute base64 code
|
#execute base64 code
|
||||||
eVaL\(\s*trim\(\s*baSe64_deCoDe\(
|
eVaL\(\s*trim\(\s*baSe64_deCoDe\(
|
||||||
|
|
||||||
|
# execute escaped code
|
||||||
|
exec\("(\\[0-9a-fx]{2,3}){3,}
|
||||||
|
|
||||||
#
|
#
|
||||||
if\s*\(\s*mail\s*\(\s*\$mails\[\$i\]\s*,\s*\$tema\s*,\s*base64_encode\s*\(\s*\$text
|
if\s*\(\s*mail\s*\(\s*\$mails\[\$i\]\s*,\s*\$tema\s*,\s*base64_encode\s*\(\s*\$text
|
||||||
|
|
||||||
@@ -54,7 +60,7 @@ chr\s*\(\s*101\s*\)\s*\.\s*chr\s*\(\s*118\s*\)\s*\.\s*chr\s*\(\s*97\s*\)\s*\.\s*
|
|||||||
|
|
||||||
#Detects the '_' character encoded in a string like "\x5F". '_' is present in many functions that malware would want to hide.
|
#Detects the '_' character encoded in a string like "\x5F". '_' is present in many functions that malware would want to hide.
|
||||||
# '_' as "\x5f"
|
# '_' as "\x5f"
|
||||||
\\[Xx](5[Ff])
|
# \\[Xx](5[Ff]) - removed because generate many false positives
|
||||||
|
|
||||||
#Detects the '_' character placed inside a call to the 'chr()' function
|
#Detects the '_' character placed inside a call to the 'chr()' function
|
||||||
# '_' as 'chr(95)' or 'chr(0x5f)'
|
# '_' as 'chr(95)' or 'chr(0x5f)'
|
||||||
@@ -89,7 +95,7 @@ eval\(\$[a-z0-9_]+\(\$_POST
|
|||||||
("[a-z0-9]+"\.chr\(\d+\)\.){3,}
|
("[a-z0-9]+"\.chr\(\d+\)\.){3,}
|
||||||
|
|
||||||
# nested function call used variables
|
# nested function call used variables
|
||||||
\$[a-z]+\(\$[a-z0-9]+\(
|
\$[a-z0-9_]+\(\$[a-z0-9_]+\(
|
||||||
|
|
||||||
# GLOBALS inject with escaped content
|
# GLOBALS inject with escaped content
|
||||||
\$GLOBALS;\$\{"\\x
|
\$GLOBALS;\$\{"\\x
|
||||||
@@ -108,3 +114,37 @@ function\s+_[0-9]{8,}\(
|
|||||||
|
|
||||||
# create_function is dangerous as like eval() see http://php.net/manual/en/function.create-function.php
|
# create_function is dangerous as like eval() see http://php.net/manual/en/function.create-function.php
|
||||||
create_function\s*\(\s*['"]{2}
|
create_function\s*\(\s*['"]{2}
|
||||||
|
|
||||||
|
# control concated from cookie at the call
|
||||||
|
(\$[a-z]{2,}=urldecode\(\$_COOKIE\['[a-z]{2,}'\]\);){3,}
|
||||||
|
|
||||||
|
# ${$O{18}.$O{7}.$O{24}.$O{2}.$O{50}.$O{8}
|
||||||
|
(\$[A-Z]+\{\d+\}\.){3,}
|
||||||
|
|
||||||
|
# comment in variable name $_REQUEST /*YUsrqpbzvXTSa...QpDNTPYQvLSFPCqsSnWNVqPdSIAYaQj*/[
|
||||||
|
\$_REQUEST\s*\/\*[A-Za-z]+\*\/\[
|
||||||
|
|
||||||
|
# cookie payload if(isset($_COOKIE)){$p=$_COOKIE;(count($p)==55&&in_array(gettype($p).count($p),$p))?(($p[68]=$p[68].$p[22])&&($p[35]=$p[68]($p[35]))&&($p=$p[35]($p[13],$p[68]($p[45])))&&$p()):$p;}
|
||||||
|
\(count\(\$p\)==\d+&&in_array\(gettype\(\$p\)\.count\(\$p\),\$p\)\)
|
||||||
|
|
||||||
|
# gzipped payload post process
|
||||||
|
explode\('\|\x01\|\x03\|\x03', gzinflate\(
|
||||||
|
|
||||||
|
# backdoor reported #71
|
||||||
|
@header\(\w{3,5}::\w{1,2}\('_\w{1,3}' \. '\w{1,3}', '_\w{1,3}'\)\);
|
||||||
|
@header\(\w{3,5}::\w{1,2}\('_\w{1,3}', '_' \. '\w{1,3}' . '\w{1,3}'\)\);
|
||||||
|
|
||||||
|
# backdoor reported #72
|
||||||
|
@\$[a-z]{1}\[\d+\]\(\$[a-z]{1}\[\d+\]\);
|
||||||
|
|
||||||
|
# reported #77
|
||||||
|
\$[a-z]11 \^ [a-z]8\(\$[a-z]6, \$[a-z]14, \$[a-z]6\[13\]\(\$[a-z]11\)\)\)\);
|
||||||
|
|
||||||
|
# eval function return and concat
|
||||||
|
eval\([A-Za-z]{5,}\(\) \. '
|
||||||
|
|
||||||
|
# eval function return, parameter is a hex string
|
||||||
|
eval\([A-Za-z0-9]{5,}\(\"[A-Z0-9]{16,}
|
||||||
|
|
||||||
|
# gzip payload called by variable named function
|
||||||
|
\$[a-zA-Z0-9]{6,}\('\x78\x9C\xAD\x90\x41\x0E
|
||||||
54
scan.php
54
scan.php
@@ -31,6 +31,7 @@ class MalwareScanner
|
|||||||
private $flagChecksum = false;
|
private $flagChecksum = false;
|
||||||
private $flagComments = false;
|
private $flagComments = false;
|
||||||
private $flagHideOk = false;
|
private $flagHideOk = false;
|
||||||
|
private $flagHideErr = false;
|
||||||
private $flagHideWhitelist = false;
|
private $flagHideWhitelist = false;
|
||||||
private $flagNoStop = false;
|
private $flagNoStop = false;
|
||||||
private $flagPattern = false;
|
private $flagPattern = false;
|
||||||
@@ -41,6 +42,7 @@ class MalwareScanner
|
|||||||
private $flagScanEverything = false;
|
private $flagScanEverything = false;
|
||||||
private $flagCombinedWhitelist = false;
|
private $flagCombinedWhitelist = false;
|
||||||
private $flagDisableStats = false;
|
private $flagDisableStats = false;
|
||||||
|
private $customWhitelist = array();
|
||||||
private $outputFormat = '';
|
private $outputFormat = '';
|
||||||
private $whitelist = array();
|
private $whitelist = array();
|
||||||
private $ignore = array();
|
private $ignore = array();
|
||||||
@@ -190,20 +192,25 @@ class MalwareScanner
|
|||||||
return $list;
|
return $list;
|
||||||
}
|
}
|
||||||
|
|
||||||
//Loads the whitelist file
|
/**
|
||||||
public function loadWhitelist()
|
* Loads the whitelist files
|
||||||
|
*/
|
||||||
|
public function loadWhitelists()
|
||||||
{
|
{
|
||||||
if (!is_file(__DIR__ . '/whitelist.txt')) {
|
$a = array_merge([__DIR__ . '/whitelist.txt'], $this->customWhitelist);
|
||||||
return;
|
foreach ($a as $file) {
|
||||||
}
|
if (is_file($file)) {
|
||||||
$fp = fopen(__DIR__ . '/whitelist.txt', 'r');
|
$fp = fopen($file, 'r');
|
||||||
while (!feof($fp)) {
|
while (!feof($fp)) {
|
||||||
$line = fgets($fp);
|
$line = fgets($fp);
|
||||||
$this->whitelist[] = substr($line, 0, 32);
|
$this->whitelist[] = substr($line, 0, 32);
|
||||||
|
}
|
||||||
|
fclose($fp);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
private function addWordpressChecksums($wp_version)
|
public function addWordpressChecksums($wp_version)
|
||||||
{
|
{
|
||||||
$apiurl = 'https://api.wordpress.org/core/checksums/1.0/?version=' . $wp_version;
|
$apiurl = 'https://api.wordpress.org/core/checksums/1.0/?version=' . $wp_version;
|
||||||
$json = json_decode(file_get_contents($apiurl));
|
$json = json_decode(file_get_contents($apiurl));
|
||||||
@@ -247,6 +254,7 @@ class MalwareScanner
|
|||||||
'wordpress-version:',
|
'wordpress-version:',
|
||||||
'scan-everything',
|
'scan-everything',
|
||||||
'combined-whitelist',
|
'combined-whitelist',
|
||||||
|
'custom-whitelist:',
|
||||||
'disable-stats'
|
'disable-stats'
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
@@ -298,6 +306,9 @@ class MalwareScanner
|
|||||||
if (isset($options['hide-ok']) || isset($options['k'])) {
|
if (isset($options['hide-ok']) || isset($options['k'])) {
|
||||||
$this->setFlagHideOk(true);
|
$this->setFlagHideOk(true);
|
||||||
}
|
}
|
||||||
|
if (isset($options['hide-err']) || isset($options['r'])) {
|
||||||
|
$this->setFlagHideErr(true);
|
||||||
|
}
|
||||||
if (isset($options['hide-whitelist']) || isset($options['w'])) {
|
if (isset($options['hide-whitelist']) || isset($options['w'])) {
|
||||||
$this->setFlagHideWhitelist(true);
|
$this->setFlagHideWhitelist(true);
|
||||||
}
|
}
|
||||||
@@ -330,6 +341,13 @@ class MalwareScanner
|
|||||||
if (isset($options['combined-whitelist'])) {
|
if (isset($options['combined-whitelist'])) {
|
||||||
$this->setFlagCombinedWhitelist(true);
|
$this->setFlagCombinedWhitelist(true);
|
||||||
}
|
}
|
||||||
|
if (isset($options['custom-whitelist'])) {
|
||||||
|
$a = $options['custom-whitelist'];
|
||||||
|
if (!is_array($a)) {
|
||||||
|
$a = array($a);
|
||||||
|
}
|
||||||
|
$this->setCustomWhitelist(array_unique($a));
|
||||||
|
}
|
||||||
if (isset($options['disable-stats'])) {
|
if (isset($options['disable-stats'])) {
|
||||||
$this->setFlagDisableStats(true);
|
$this->setFlagDisableStats(true);
|
||||||
}
|
}
|
||||||
@@ -396,6 +414,11 @@ class MalwareScanner
|
|||||||
$this->flagHideOk = $b;
|
$this->flagHideOk = $b;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function setFlagHideErr($b)
|
||||||
|
{
|
||||||
|
$this->flagHideErr = $b;
|
||||||
|
}
|
||||||
|
|
||||||
public function setFlagHideWhitelist($b)
|
public function setFlagHideWhitelist($b)
|
||||||
{
|
{
|
||||||
$this->flagHideWhitelist = $b;
|
$this->flagHideWhitelist = $b;
|
||||||
@@ -426,6 +449,11 @@ class MalwareScanner
|
|||||||
$this->flagDisableStats = $b;
|
$this->flagDisableStats = $b;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function setCustomWhitelist($a)
|
||||||
|
{
|
||||||
|
$this->customWhitelist = $a;
|
||||||
|
}
|
||||||
|
|
||||||
// @see http://stackoverflow.com/a/13914119
|
// @see http://stackoverflow.com/a/13914119
|
||||||
private function pathMatches($path, $pattern, $ignoreCase = false)
|
private function pathMatches($path, $pattern, $ignoreCase = false)
|
||||||
{
|
{
|
||||||
@@ -490,6 +518,9 @@ class MalwareScanner
|
|||||||
$state = 'WL';
|
$state = 'WL';
|
||||||
$state_color = $this->ANSI_YELLOW;
|
$state_color = $this->ANSI_YELLOW;
|
||||||
} else {
|
} else {
|
||||||
|
if ($this->flagHideErr) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
$state = 'ER';
|
$state = 'ER';
|
||||||
$state_color = $this->ANSI_RED;
|
$state_color = $this->ANSI_RED;
|
||||||
}
|
}
|
||||||
@@ -614,7 +645,7 @@ class MalwareScanner
|
|||||||
{
|
{
|
||||||
$this->initializePatterns();
|
$this->initializePatterns();
|
||||||
|
|
||||||
$this->loadWhitelist();
|
$this->loadWhitelists();
|
||||||
|
|
||||||
if ($this->flagCombinedWhitelist && !$this->updateCombinedWhitelist()) {
|
if ($this->flagCombinedWhitelist && !$this->updateCombinedWhitelist()) {
|
||||||
return false;
|
return false;
|
||||||
@@ -820,6 +851,7 @@ class MalwareScanner
|
|||||||
echo ' -x --extra-check Adds GoogleBot and htaccess to Scan List' . PHP_EOL;
|
echo ' -x --extra-check Adds GoogleBot and htaccess to Scan List' . PHP_EOL;
|
||||||
echo ' -l --follow-symlink Follow symlinked directories' . PHP_EOL;
|
echo ' -l --follow-symlink Follow symlinked directories' . PHP_EOL;
|
||||||
echo ' -k --hide-ok Hide results with \'OK\' status' . PHP_EOL;
|
echo ' -k --hide-ok Hide results with \'OK\' status' . PHP_EOL;
|
||||||
|
echo ' -r --hide-err Hide results with \'ER\' status' . PHP_EOL;
|
||||||
echo ' -w --hide-whitelist Hide results with \'WL\' status' . PHP_EOL;
|
echo ' -w --hide-whitelist Hide results with \'WL\' status' . PHP_EOL;
|
||||||
echo ' -n --no-color Disable color mode' . PHP_EOL;
|
echo ' -n --no-color Disable color mode' . PHP_EOL;
|
||||||
echo ' -s --no-stop Continue scanning file after first hit' . PHP_EOL;
|
echo ' -s --no-stop Continue scanning file after first hit' . PHP_EOL;
|
||||||
|
|||||||
@@ -256,25 +256,33 @@ e45b8afd0b65516c175ed23f7183bab1 /jquery-migrate-1.1.1.min.js
|
|||||||
dc0102c151c491b8a0f65a520e26e083 /jquery-migrate-1.1.0.min.js
|
dc0102c151c491b8a0f65a520e26e083 /jquery-migrate-1.1.0.min.js
|
||||||
1f5980833a26b490296db71951e1024f /jquery-migrate-1.0.0.js
|
1f5980833a26b490296db71951e1024f /jquery-migrate-1.0.0.js
|
||||||
dd6f8586a1afae562493e9c7cd1ffeea /jquery-migrate-1.0.0.min.js
|
dd6f8586a1afae562493e9c7cd1ffeea /jquery-migrate-1.0.0.min.js
|
||||||
f2fc939d607b2e861af2701a15d14430 /ace/ace.min.js
|
f2fc939d607b2e861af2701a15d14430 /ace/ace.min.js
|
||||||
2954b8d06fd846e81c12b0fd0b3d2d35 /ace/ace/ace.js
|
2954b8d06fd846e81c12b0fd0b3d2d35 /ace/ace/ace.js
|
||||||
c333e22e892cd099e776e9384bbbaa63 /ace/ace/ext-beautify.js
|
c333e22e892cd099e776e9384bbbaa63 /ace/ace/ext-beautify.js
|
||||||
b391899e17b7aea2cf2998656c40f2c6 /core/components/phpthumbof/model/aws/_compatibility_test/sdk_compatibility_test.php
|
b391899e17b7aea2cf2998656c40f2c6 /core/components/phpthumbof/model/aws/_compatibility_test/sdk_compatibility_test.php
|
||||||
6cfb5a3b2820fe378b73c901ee6fc031 /core/components/phpthumbof/model/aws/sdk.class.php
|
6cfb5a3b2820fe378b73c901ee6fc031 /core/components/phpthumbof/model/aws/sdk.class.php
|
||||||
dd894a093463d38f9c9fdbcb7c88cc23 /core/model/aws/sdk.class.php
|
dd894a093463d38f9c9fdbcb7c88cc23 /core/model/aws/sdk.class.php
|
||||||
1ed9b9eea82c9f1ead337b67c188206b /core/model/phpthumb/phpthumb.class.php
|
1ed9b9eea82c9f1ead337b67c188206b /core/model/phpthumb/phpthumb.class.php
|
||||||
ef55bdc338994e87b650e2cf0f87df45 /core/model/smarty/sysplugins/smarty_internal_template.php
|
ef55bdc338994e87b650e2cf0f87df45 /core/model/smarty/sysplugins/smarty_internal_template.php
|
||||||
f8f2e883e5323ed5935f42b17ceda6ba /core/model/smarty/sysplugins/smarty_template_compiled.php
|
f8f2e883e5323ed5935f42b17ceda6ba /core/model/smarty/sysplugins/smarty_template_compiled.php
|
||||||
3d84a338c9daaacc711834cb7797ac98 /core/model/smarty/sysplugins/smarty_cacheresource_custom.php
|
3d84a338c9daaacc711834cb7797ac98 /core/model/smarty/sysplugins/smarty_cacheresource_custom.php
|
||||||
d6be1074d266aecb739352150798d97d /core/model/smarty/sysplugins/smarty_cacheresource_keyvaluestore.php
|
d6be1074d266aecb739352150798d97d /core/model/smarty/sysplugins/smarty_cacheresource_keyvaluestore.php
|
||||||
c363512229135b182006a97ba43d31e7 /core/model/smarty/sysplugins/smarty_resource_recompiled.php
|
c363512229135b182006a97ba43d31e7 /core/model/smarty/sysplugins/smarty_resource_recompiled.php
|
||||||
fc8f1e9f0ff666af7beb3f61b055c0e8 /core/model/smarty/sysplugins/smarty_internal_cacheresource_file.php
|
fc8f1e9f0ff666af7beb3f61b055c0e8 /core/model/smarty/sysplugins/smarty_internal_cacheresource_file.php
|
||||||
092a5a658bf49a3c1549f9bd809218ea /core/xpdo/compression/pclzip.lib.php
|
092a5a658bf49a3c1549f9bd809218ea /core/xpdo/compression/pclzip.lib.php
|
||||||
761f1578928050a03f4aa4c789f1d136 /manager/assets/fileapi/FileAPI.js
|
761f1578928050a03f4aa4c789f1d136 /manager/assets/fileapi/FileAPI.js
|
||||||
3c9137d88a00b1ae0b41ff6a70571615 /assets/components/tinymcewrapper/frontend/imogen_theme/js/jquery.js
|
3c9137d88a00b1ae0b41ff6a70571615 /assets/components/tinymcewrapper/frontend/imogen_theme/js/jquery.js
|
||||||
bb127b5ce56b45e8b4b91de2e60dd9eb /assets/components/googleanalytics/js/mgr/libs/highcharts.js
|
bb127b5ce56b45e8b4b91de2e60dd9eb /assets/components/googleanalytics/js/mgr/libs/highcharts.js
|
||||||
7d7958bb0a9438a8966807f9202d0bce /assets/components/tinymce/jscripts/tiny_mce/plugins/spellchecker/classes/PSpellShell.php
|
7d7958bb0a9438a8966807f9202d0bce /assets/components/tinymce/jscripts/tiny_mce/plugins/spellchecker/classes/PSpellShell.php
|
||||||
3ee0a4d8a06cedc0a56f29e8f351ef72 /pclzip-2-8-2/pclzip.lib.php
|
3ee0a4d8a06cedc0a56f29e8f351ef72 /pclzip-2-8-2/pclzip.lib.php
|
||||||
abfd2987afd1f66e3eed50bebbeb6750 /sucuri-scanner-1.8.24/src/base.lib.php
|
abfd2987afd1f66e3eed50bebbeb6750 /sucuri-scanner-1.8.24/src/base.lib.php
|
||||||
78477b67cb223e4504689fef33119884 /sucuri-scanner-1.8.24/src/sitecheck.lib.php
|
78477b67cb223e4504689fef33119884 /sucuri-scanner-1.8.24/src/sitecheck.lib.php
|
||||||
e48460f6ef0c911dc5ad558c57bfd52f /sucuri-scanner-1.8.24/src/integrity.lib.php
|
e48460f6ef0c911dc5ad558c57bfd52f /sucuri-scanner-1.8.24/src/integrity.lib.php
|
||||||
|
29f34168b7384cca58ba64885461e115 wp-admin/includes/class-pclzip.php -> Wordpress Core 6.0
|
||||||
|
a54895edc1402cf1b7b5ecd3f5d85e6b wp-includes/formatting.php -> Wordpress Core 6.0
|
||||||
|
178f2fbc6a48f605ed84b156103d5366 wp-content/plugins/wordpress-seo/vendor_prefixed/guzzlehttp/guzzle/src/Middleware.php -> Yoast SEO plugin 19.2
|
||||||
|
1e2d246c57d2123aa8938c8263cb1d3d wp-content/plugins/wordpress-seo/admin/tracking/class-tracking-server-data.php -> Yoast SEO plugin 19.2
|
||||||
|
cacb5670ebb2de31976a4b2eb06cac86 wp-content/plugins/worker/src/MWP/ServiceContainer/Abstract.php -> managewp plugin 4.9.14 from managewp.com
|
||||||
|
ffa76b9ff298702a733747521cfdee69 wp-content/plugins/worker/src/MWP/Action/GetState.php -> managewp plugin 4.9.14 from managewp.com
|
||||||
|
ccce5f45d1ac66bd2bebe75d666b5720 wp-content/plugins/redirection/models/regex.php
|
||||||
|
ae810d74d638c611d8bd958777c9ac6a wp-content/plugins/ssl-insecure-content-fixer/includes/nonces.php
|
||||||
|
|||||||
Reference in New Issue
Block a user