530
This commit is contained in:
@@ -0,0 +1,89 @@
|
||||
function cmdMalwareUserList() {
|
||||
printRow
|
||||
|
||||
local output error databaseList
|
||||
if ! run output error mariadbDatabaseListGet; then
|
||||
printDot 60 "Databases" "$labelUnknown"
|
||||
printDanger "$error"
|
||||
return
|
||||
fi
|
||||
mapfile -t databaseList < <(awk 'NF' <<< "$output")
|
||||
printDot 60 "Databases" "${#databaseList[@]}"
|
||||
(( ${#databaseList[@]} > 0 )) || return
|
||||
printRow
|
||||
|
||||
local inList
|
||||
inList=$(printf "'%s'," "${databaseList[@]}")
|
||||
inList="${inList%,}"
|
||||
|
||||
local sql
|
||||
sql=$(cat << 'EOF'
|
||||
SET SESSION group_concat_max_len = 1000000;
|
||||
SELECT GROUP_CONCAT(CONCAT(
|
||||
"SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,",
|
||||
" ID,",
|
||||
" CONVERT(user_login USING utf8mb4) COLLATE utf8mb4_unicode_ci AS user_login,",
|
||||
" user_registered,",
|
||||
" CONVERT('", t.table_name, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS table_name",
|
||||
" FROM `", t.table_schema, "`.`", t.table_name, "`",
|
||||
" WHERE user_login LIKE 'adm\\_%' OR user_login LIKE 'admin\\_%' OR user_login LIKE 'administrator\\_%' OR user_login LIKE 'backup\\_%'"
|
||||
) SEPARATOR ' UNION ALL ') INTO @sql
|
||||
FROM information_schema.tables t
|
||||
WHERE t.table_schema IN (__IN_LIST__)
|
||||
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='user_login')
|
||||
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='ID')
|
||||
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='user_registered');
|
||||
PREPARE stmt FROM @sql;
|
||||
EXECUTE stmt;
|
||||
DEALLOCATE PREPARE stmt;
|
||||
EOF
|
||||
)
|
||||
sql="${sql/__IN_LIST__/$inList}"
|
||||
|
||||
mariadbMasterRootQuery "$sql"
|
||||
|
||||
printRow
|
||||
}
|
||||
|
||||
function cmdMalwareMuPluginList() {
|
||||
local allowedFiles="
|
||||
index.php
|
||||
00-hosting-loader.php
|
||||
load.php
|
||||
hosting-wp-domain-rename.php
|
||||
burst_rest_api_optimizer.php
|
||||
elementor-safe-mode.php
|
||||
mailoptin-customizer-optimizer.php
|
||||
wgpwpp-cache.php
|
||||
installatron_hide_status_test.php
|
||||
"
|
||||
|
||||
run vhostsList error fileList "$vhostsPath" d || { printDanger "$error"; return 1; }
|
||||
while read -r dir; do
|
||||
local found=0
|
||||
run itemList error fileList "$vhostsPath/$dir/www/wp-content/mu-plugins/" f || continue
|
||||
while read -r item; do
|
||||
if grep -qF '($i){static $a=null' "$vhostsPath/$dir/www/wp-content/mu-plugins/$item"; then
|
||||
(( found++ )) || printSection "$dir"
|
||||
printDot 60 "$item" "${fontRed}malware$fontReset"
|
||||
elif ! listContains "$item" "$allowedFiles"; then
|
||||
(( found++ )) || printSection "$dir"
|
||||
printDot 60 "$item" "${fontYellow}warning$fontReset"
|
||||
fi
|
||||
done < <(awk 'NF' <<< "$itemList")
|
||||
done < <(awk 'NF' <<< "$vhostsList")
|
||||
|
||||
printRow
|
||||
}
|
||||
|
||||
function cmdMalwareFilesCheck() {
|
||||
local target="${1:-all}"
|
||||
|
||||
if [[ "$target" == "all" ]]; then
|
||||
siteAllFilesCheck || return 1
|
||||
else
|
||||
# printSection "$domain"
|
||||
siteFilesCheck "$target"
|
||||
fi
|
||||
printRow
|
||||
}
|
||||
Reference in New Issue
Block a user