269 lines
11 KiB
Bash
269 lines
11 KiB
Bash
function cmdMalwareUserList() {
|
|
printRow
|
|
|
|
local output error databaseList
|
|
if ! run output error mariadbDatabaseListGet; then
|
|
printDotText "Databases" "$labelUnknown"
|
|
printDanger "$error"
|
|
return
|
|
fi
|
|
mapfile -t databaseList < <(awk 'NF' <<< "$output")
|
|
printDotText "Databases" "${#databaseList[@]}"
|
|
(( ${#databaseList[@]} > 0 )) || return
|
|
printRow
|
|
|
|
local inList
|
|
inList=$(printf "'%s'," "${databaseList[@]}")
|
|
inList="${inList%,}"
|
|
|
|
local sql
|
|
sql=$(cat << 'EOF'
|
|
SET SESSION group_concat_max_len = 1000000;
|
|
SELECT GROUP_CONCAT(CONCAT(
|
|
"SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,",
|
|
" ID,",
|
|
" CONVERT(user_login USING utf8mb4) COLLATE utf8mb4_unicode_ci AS user_login,",
|
|
" user_registered,",
|
|
" CONVERT('", t.table_name, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS table_name",
|
|
" FROM `", t.table_schema, "`.`", t.table_name, "`",
|
|
" WHERE user_login LIKE 'adm\\_%' OR user_login LIKE 'admin\\_%' OR user_login LIKE 'administrator\\_%' OR user_login LIKE 'backup\\_%'"
|
|
) SEPARATOR ' UNION ALL ') INTO @sql
|
|
FROM information_schema.tables t
|
|
WHERE t.table_schema IN (__IN_LIST__)
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='user_login')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='ID')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='user_registered');
|
|
PREPARE stmt FROM @sql;
|
|
EXECUTE stmt;
|
|
DEALLOCATE PREPARE stmt;
|
|
EOF
|
|
)
|
|
sql="${sql/__IN_LIST__/$inList}"
|
|
|
|
mariadbMasterRootQuery "$sql"
|
|
}
|
|
|
|
function cmdMalwareOptionsList() {
|
|
printRow
|
|
local output error databaseList
|
|
if ! run output error mariadbDatabaseListGet; then
|
|
printDotText "Databases" "$labelUnknown"
|
|
printDanger "$error"
|
|
return
|
|
fi
|
|
mapfile -t databaseList < <(awk 'NF' <<< "$output")
|
|
printDotText "Databases" "${#databaseList[@]}"
|
|
(( ${#databaseList[@]} > 0 )) || return
|
|
printRow
|
|
local inList
|
|
inList=$(printf "'%s'," "${databaseList[@]}")
|
|
inList="${inList%,}"
|
|
local sql
|
|
sql=$(cat << 'EOF'
|
|
SET SESSION group_concat_max_len = 1000000;
|
|
SELECT GROUP_CONCAT(CONCAT(
|
|
"SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,",
|
|
" option_id,",
|
|
" CONVERT(option_name USING utf8mb4) COLLATE utf8mb4_unicode_ci AS option_name,",
|
|
" CONVERT(autoload USING utf8mb4) COLLATE utf8mb4_unicode_ci AS autoload,",
|
|
" CONVERT('", t.table_name, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS table_name",
|
|
" FROM `", t.table_schema, "`.`", t.table_name, "`",
|
|
" WHERE option_name LIKE 'sc\\_%'"
|
|
) SEPARATOR ' UNION ALL ') INTO @sql
|
|
FROM information_schema.tables t
|
|
WHERE t.table_schema IN (__IN_LIST__)
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_id')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_name')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='autoload');
|
|
PREPARE stmt FROM @sql;
|
|
EXECUTE stmt;
|
|
DEALLOCATE PREPARE stmt;
|
|
EOF
|
|
)
|
|
sql="${sql/__IN_LIST__/$inList}"
|
|
|
|
mariadbMasterRootQuery "$sql"
|
|
}
|
|
|
|
function cmdMalwareMuPluginList() {
|
|
local allowedFiles="
|
|
index.php
|
|
00-hosting-loader.php
|
|
load.php
|
|
hosting-wp-domain-rename.php
|
|
burst_rest_api_optimizer.php
|
|
elementor-safe-mode.php
|
|
mailoptin-customizer-optimizer.php
|
|
wgpwpp-cache.php
|
|
installatron_hide_status_test.php
|
|
"
|
|
|
|
run vhostsList error fileList "$olsVhostsPath" d || { printDanger "$error"; return 1; }
|
|
while read -r dir; do
|
|
local found=0 pluginList
|
|
|
|
# unknown
|
|
run itemList error fileList "$olsVhostsPath/$dir/www/wp-content/mu-plugins/" f || continue
|
|
while read -r item; do
|
|
if grep -qF '($i){static $a=null' "$olsVhostsPath/$dir/www/wp-content/mu-plugins/$item"; then
|
|
(( found++ )) || printSection "$dir"
|
|
printDotText "$item" "${fontRed}malware$fontReset"
|
|
elif ! listContains "$item" "$allowedFiles"; then
|
|
(( found++ )) || printSection "$dir"
|
|
printDotText "/wp-content/mu-plugins/$item" "$labelUnknown"
|
|
fi
|
|
done < <(awk 'NF' <<< "$itemList")
|
|
|
|
# wp2shell
|
|
pluginList=$(find "$olsVhostsPath/$dir/www/wp-content/plugins" -maxdepth 1 -type d -name 'wp2shell*' 2>/dev/null)
|
|
if [ -n "$pluginList" ]; then
|
|
while IFS= read -r item; do
|
|
(( found++ )) || printSection "$dir"
|
|
printDotText "${item#"$olsVhostsPath/$dir/www"}" "${fontRed}malware$fontReset"
|
|
done <<< "$pluginList"
|
|
fi
|
|
|
|
# wp-static-cache
|
|
pluginList=$(find "$olsVhostsPath/$dir/www/wp-content/plugins" -maxdepth 1 -type d -name 'wp-static-cache*' 2>/dev/null)
|
|
if [ -n "$pluginList" ]; then
|
|
while IFS= read -r item; do
|
|
(( found++ )) || printSection "$dir"
|
|
printDotText "${item#"$olsVhostsPath/$dir/www"}" "${fontRed}malware$fontReset"
|
|
done <<< "$pluginList"
|
|
fi
|
|
|
|
# other
|
|
for subdir in wp-content/mu-plugins wp-content/plugins; do
|
|
pluginList=$(find "$olsVhostsPath/$dir/www/$subdir" -maxdepth 1 -regextype posix-extended -regex '^.*[^0-9a-f][0-9a-f]{6,8}(\.php)?$' 2>/dev/null)
|
|
if [ -n "$pluginList" ]; then
|
|
while IFS= read -r item; do
|
|
(( found++ )) || printSection "$dir"
|
|
printDotText "${item#"$olsVhostsPath/$dir/www"}" "${fontYellow}warning$fontReset"
|
|
done <<< "$pluginList"
|
|
fi
|
|
done
|
|
done < <(awk 'NF' <<< "$vhostsList")
|
|
}
|
|
|
|
function cmdMalwareFilesCheck() {
|
|
local target="$1"
|
|
local vhostList error
|
|
|
|
printRow
|
|
|
|
if [[ -z "$target" ]]; then
|
|
printDanger "Target not specified";
|
|
elif ! run vhostList error openlitespeedConfigVhostList; then
|
|
printDanger "Cannot get vhost list: $error";
|
|
elif [[ "$target" == "all" ]]; then
|
|
local domain
|
|
for domain in $vhostList; do
|
|
mapfile -t diffArray < <(siteFilesCheck "$domain")
|
|
if [[ ${#diffArray[@]} -gt 0 ]]; then
|
|
printSection "$domain"
|
|
local line
|
|
for line in "${diffArray[@]}"; do
|
|
printText "$line"
|
|
done
|
|
fi
|
|
done
|
|
elif ! listContains "$target" "$vhostList"; then
|
|
printDanger "Unknown domain: $target";
|
|
else
|
|
mapfile -t diffArray < <(siteFilesCheck "$target")
|
|
if [[ ${#diffArray[@]} -gt 0 ]]; then
|
|
printDotText "$target" "$labelFail"
|
|
local line
|
|
for line in "${diffArray[@]}"; do
|
|
printText "$line"
|
|
done
|
|
else
|
|
printDotText "$target" "$labelDone"
|
|
fi
|
|
fi
|
|
}
|
|
|
|
|
|
function cmdMalwareOptionsTimestamps() {
|
|
printRow
|
|
local output error databaseList
|
|
if ! run output error mariadbDatabaseListGet; then
|
|
printDotText "Databases" "$labelUnknown"
|
|
printDanger "$error"
|
|
return
|
|
fi
|
|
mapfile -t databaseList < <(awk 'NF' <<< "$output")
|
|
printDotText "Databases" "${#databaseList[@]}"
|
|
(( ${#databaseList[@]} > 0 )) || return
|
|
printRow
|
|
local inList
|
|
inList=$(printf "'%s'," "${databaseList[@]}")
|
|
inList="${inList%,}"
|
|
local sql
|
|
sql=$(cat << 'EOF'
|
|
SET SESSION group_concat_max_len = 1000000;
|
|
SELECT GROUP_CONCAT(CONCAT(
|
|
"SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,",
|
|
" option_id,",
|
|
" CONVERT(option_name USING utf8mb4) COLLATE utf8mb4_unicode_ci AS option_name,",
|
|
" CONVERT(option_value USING utf8mb4) COLLATE utf8mb4_unicode_ci AS option_value",
|
|
" FROM `", t.table_schema, "`.`", t.table_name, "`",
|
|
" WHERE option_name IN ('sc_last_fetch_ts','sc_last_rescan','sc_last_rpc')"
|
|
) SEPARATOR ' UNION ALL ') INTO @sql
|
|
FROM information_schema.tables t
|
|
WHERE t.table_schema IN (__IN_LIST__)
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_id')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_name')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_value');
|
|
PREPARE stmt FROM @sql;
|
|
EXECUTE stmt;
|
|
DEALLOCATE PREPARE stmt;
|
|
EOF
|
|
)
|
|
sql="${sql/__IN_LIST__/$inList}"
|
|
|
|
mariadbMasterRootQuery "$sql" | sort -t$'\t' -k4 -rn
|
|
}
|
|
|
|
function cmdMalwareOptionsSuspiciousNames() {
|
|
printRow
|
|
local output error databaseList
|
|
if ! run output error mariadbDatabaseListGet; then
|
|
printDotText "Databases" "$labelUnknown"
|
|
printDanger "$error"
|
|
return
|
|
fi
|
|
mapfile -t databaseList < <(awk 'NF' <<< "$output")
|
|
printDotText "Databases" "${#databaseList[@]}"
|
|
(( ${#databaseList[@]} > 0 )) || return
|
|
printRow
|
|
local inList
|
|
inList=$(printf "'%s'," "${databaseList[@]}")
|
|
inList="${inList%,}"
|
|
local sql
|
|
sql=$(cat << 'EOF'
|
|
SET SESSION group_concat_max_len = 1000000;
|
|
SELECT GROUP_CONCAT(CONCAT(
|
|
"SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,",
|
|
" CONVERT('", t.table_name, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS table_name,",
|
|
" option_id,",
|
|
" CONVERT(option_name USING utf8mb4) COLLATE utf8mb4_unicode_ci AS option_name",
|
|
" FROM `", t.table_schema, "`.`", t.table_name, "`",
|
|
" WHERE option_name LIKE 'sc\\_%' ESCAPE '\\\\'",
|
|
" OR option_name REGEXP '^[0-9a-f]{12}$'"
|
|
) SEPARATOR ' UNION ALL ') INTO @sql
|
|
FROM information_schema.tables t
|
|
WHERE t.table_schema IN (__IN_LIST__)
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_id')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_name')
|
|
AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_value');
|
|
PREPARE stmt FROM @sql;
|
|
EXECUTE stmt;
|
|
DEALLOCATE PREPARE stmt;
|
|
EOF
|
|
)
|
|
sql="${sql/__IN_LIST__/$inList}"
|
|
|
|
mariadbMasterRootQuery "$sql" | sort -t$'\t' -k1,1 -k2,2 -k4,4
|
|
}
|