mirror of
https://github.com/scr34m/php-malware-scanner.git
synced 2026-06-16 12:30:35 +00:00
Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9624ec4403 | ||
|
|
335b13b7c4 | ||
|
|
78bee49176 | ||
|
|
cc0fdc7a9f | ||
|
|
ec8f9920ba |
@@ -26,6 +26,7 @@ Usage: php scan.php -d <directory>
|
|||||||
-x --extra-check Adds GoogleBot and htaccess to Scan List
|
-x --extra-check Adds GoogleBot and htaccess to Scan List
|
||||||
-l --follow-symlink Follow symlinked directories
|
-l --follow-symlink Follow symlinked directories
|
||||||
-k --hide-ok Hide results with 'OK' status
|
-k --hide-ok Hide results with 'OK' status
|
||||||
|
-r --hide-err Hide results with 'ER' status
|
||||||
-w --hide-whitelist Hide results with 'WL' status
|
-w --hide-whitelist Hide results with 'WL' status
|
||||||
-n --no-color Disable color mode
|
-n --no-color Disable color mode
|
||||||
-s --no-stop Continue scanning file after first hit
|
-s --no-stop Continue scanning file after first hit
|
||||||
|
|||||||
@@ -201,6 +201,7 @@ eval(base64_decode(
|
|||||||
$data = base64_decode("
|
$data = base64_decode("
|
||||||
edoced_46esab
|
edoced_46esab
|
||||||
base=base64_encode
|
base=base64_encode
|
||||||
|
'b'.'ase6'.'4_e'.'ncode'
|
||||||
cr"."eat"."e_fun"."cti"."on
|
cr"."eat"."e_fun"."cti"."on
|
||||||
gz'.'inf'.'late
|
gz'.'inf'.'late
|
||||||
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
# fopo.com.ar - free online php obfuscator. It conveniently leaves comments in the code.
|
||||||
@@ -260,6 +261,9 @@ itsoknoproblembro
|
|||||||
tmhapbzcerff
|
tmhapbzcerff
|
||||||
IndoXploit
|
IndoXploit
|
||||||
FaisaL Ahmed aka rEd X
|
FaisaL Ahmed aka rEd X
|
||||||
|
smisbot
|
||||||
|
smotherbot
|
||||||
|
Indonesian Hacker Rulez
|
||||||
|
|
||||||
# WP-VCD Malware https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/
|
# WP-VCD Malware https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/
|
||||||
wp-vcd
|
wp-vcd
|
||||||
|
|||||||
13
scan.php
13
scan.php
@@ -31,6 +31,7 @@ class MalwareScanner
|
|||||||
private $flagChecksum = false;
|
private $flagChecksum = false;
|
||||||
private $flagComments = false;
|
private $flagComments = false;
|
||||||
private $flagHideOk = false;
|
private $flagHideOk = false;
|
||||||
|
private $flagHideErr = false;
|
||||||
private $flagHideWhitelist = false;
|
private $flagHideWhitelist = false;
|
||||||
private $flagNoStop = false;
|
private $flagNoStop = false;
|
||||||
private $flagPattern = false;
|
private $flagPattern = false;
|
||||||
@@ -298,6 +299,9 @@ class MalwareScanner
|
|||||||
if (isset($options['hide-ok']) || isset($options['k'])) {
|
if (isset($options['hide-ok']) || isset($options['k'])) {
|
||||||
$this->setFlagHideOk(true);
|
$this->setFlagHideOk(true);
|
||||||
}
|
}
|
||||||
|
if (isset($options['hide-err']) || isset($options['r'])) {
|
||||||
|
$this->setFlagHideErr(true);
|
||||||
|
}
|
||||||
if (isset($options['hide-whitelist']) || isset($options['w'])) {
|
if (isset($options['hide-whitelist']) || isset($options['w'])) {
|
||||||
$this->setFlagHideWhitelist(true);
|
$this->setFlagHideWhitelist(true);
|
||||||
}
|
}
|
||||||
@@ -396,6 +400,11 @@ class MalwareScanner
|
|||||||
$this->flagHideOk = $b;
|
$this->flagHideOk = $b;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
public function setFlagHideErr($b)
|
||||||
|
{
|
||||||
|
$this->flagHideErr = $b;
|
||||||
|
}
|
||||||
|
|
||||||
public function setFlagHideWhitelist($b)
|
public function setFlagHideWhitelist($b)
|
||||||
{
|
{
|
||||||
$this->flagHideWhitelist = $b;
|
$this->flagHideWhitelist = $b;
|
||||||
@@ -490,6 +499,9 @@ class MalwareScanner
|
|||||||
$state = 'WL';
|
$state = 'WL';
|
||||||
$state_color = $this->ANSI_YELLOW;
|
$state_color = $this->ANSI_YELLOW;
|
||||||
} else {
|
} else {
|
||||||
|
if ($this->flagHideErr) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
$state = 'ER';
|
$state = 'ER';
|
||||||
$state_color = $this->ANSI_RED;
|
$state_color = $this->ANSI_RED;
|
||||||
}
|
}
|
||||||
@@ -820,6 +832,7 @@ class MalwareScanner
|
|||||||
echo ' -x --extra-check Adds GoogleBot and htaccess to Scan List' . PHP_EOL;
|
echo ' -x --extra-check Adds GoogleBot and htaccess to Scan List' . PHP_EOL;
|
||||||
echo ' -l --follow-symlink Follow symlinked directories' . PHP_EOL;
|
echo ' -l --follow-symlink Follow symlinked directories' . PHP_EOL;
|
||||||
echo ' -k --hide-ok Hide results with \'OK\' status' . PHP_EOL;
|
echo ' -k --hide-ok Hide results with \'OK\' status' . PHP_EOL;
|
||||||
|
echo ' -r --hide-err Hide results with \'ER\' status' . PHP_EOL;
|
||||||
echo ' -w --hide-whitelist Hide results with \'WL\' status' . PHP_EOL;
|
echo ' -w --hide-whitelist Hide results with \'WL\' status' . PHP_EOL;
|
||||||
echo ' -n --no-color Disable color mode' . PHP_EOL;
|
echo ' -n --no-color Disable color mode' . PHP_EOL;
|
||||||
echo ' -s --no-stop Continue scanning file after first hit' . PHP_EOL;
|
echo ' -s --no-stop Continue scanning file after first hit' . PHP_EOL;
|
||||||
|
|||||||
Reference in New Issue
Block a user