PHP Code:
<?php
/**
@author Yami King
@version 0.2
@deprecated
@action
Mailbomber zoeker
@todo
1) .htaccess-bestanden lezen for FilesMatch (file extension & mime herschrijving
onderscheppen = `rootkit` onderscheppen);
@changed
Deze nieuwe methode is geïmplementeerd door gewoon elk bestand te scannen
doordat veel servers hun eigen manier van het veranderen van mime-types hebben.
2) ftp_login's in doSendToLabs veranderen in sockets (CAPTCHA idee volgen).
@changed
Deze nieuwe methode is geïmplementeerd door gewoon elk bestand te mailen
naar de Labs i.p.v het huidige FTP en het idee voor sockets.
*/
final class Applicleaner {
private static $threats = array();
private static $illegal = array(
'apache_note',
'apache_setenv',
'closelog',
'connect',
'curl_exec',
'debugger_off',
'debugger_on',
'define_syslog_variables',
'escapeshellarg',
'escapeshellcmd',
'exec' => array(
'pattern' => '/(\*\/|\s{1}?)exec(\s{0}?)(\{|\(|)(\"|\'|)(.+)(\"|\'|)(\}|\)|)(.*)/ismU',
'name' => 'exec'
),
'openlog',
'parse_ini_file',
'passthru',
'pcntl_exec',
'proc_close',
'proc_get_status',
'proc_nice',
'proc_open',
'proc_terminate',
'shell_exec',
/* Shell execution using `` */
'shell_exec' => array(
'pattern' => '/(echo|print|\$(.*)|)(.*)(=|)(.*)`(.+)`/ismU',
'name' => 'quoted version of shell_exec'
),
'show_source',
'socket',
'socket_create',
'stream_socket_client',
'stream_socket_server',
'syscall',
'syslog',
'sysrun',
'system',
);
public static $threatCount = 0;
public static $pthreatCount = 0;
public static $report = NULL;
private static $called = array('dirscan' => 0, 'filescan' => 0);
public static $pushToQuarantaine = 1;
public static function doDirScan($dir) {
self::$called['dirscan'] = 1;
$dir = str_replace('\\', '/', $dir);
if (substr($dir, -1) <> '/') {
$dir .= '/';
}
if (!is_dir($dir) || is_file($dir)) {
self::$report .= "<br><u>/!\</u> Unable to scan the directory (".$dir.") while it doesn't exist or is a file!";
}
$dh = scandir($dir);
if ($dh) {
for ($i = 2; $i < count($dh); $i++) {
if (is_dir($dir.$dh[$i]) && !is_file($dir.$dh[$i])) {
self::doDirScan($dir.$dh[$i].'/');
}
else {
if (sha1_file($dir.$dh[$i]) <> sha1_file('App_Code/applicleaner.class.php')) {
self::doFileScan($dir.$dh[$i]);
}
}
}
}
else {
self::$report .= '<br>Unable to scan the directory ('.$dir.')!';
}
}
public static function doFileScan($file) {
if (self::$called['dirscan'] <> 1) {
self::$report = "<br><u>/!\</u> Unable to scan a file without scanning a directory!";
self::displaythreats();
exit(1);
}
$fh = htmlspecialchars(@file_get_contents($file));
self::$threats[$file] = array();
foreach (self::$illegal as $i) {
if (is_array($i)) {
if (preg_match($i['pattern'], $fh)) {
array_push(self::$threats[$file], $i['name']);
}
}
$patterns = array(
"/(.*)".$i."\(.*\)(.*)(;|)(.*)/ismU",
"/(.*)".$i."\{.*\}(.*)(;|)(.*)/ismU",
"/(.*)".$i."\s{1}\(.*\)(.*)(;|)(.*)/ismU",
"/(.*)".$i."\s{1}\{.*\}(.*)(;|)(.*)/ismU"
);
foreach ($patterns as $pattern) {
if (preg_match($pattern, $fh)) {
array_push(self::$threats[$file], $i);
}
}
}
if (!empty(self::$threats[$file]) && self::$pushToQuarantaine == 1) {
Applicleaner::doPushToQuarantaine($file);
}
}
public static function doPushToQuarantaine($file) {
$file = str_replace('\\', '/', $file);
$dest = substr($file, strrpos($file, '/') + 1);
$dest = 'Quarantaine/NotHealed/'.$dest;
while (@file_exists($dest.'.txt')) {
$dest .= abs(crc32(rand(0, 999999)));
}
if (@copy($file, $dest.'.txt')) {
self::$report .= "<br>Successfully pushed file (".$file.") to the Quarantaine!";
}
else {
self::$report .= "<br><u>/!\</u> Unable to push file (".$file.") to the Quarantaine!";
}
}
public static function displayThreats() {
foreach (array_keys(self::$threats) as $t) {
echo $t.'<br>';
if (count(self::$threats[$t]) == 0) {
echo " <img src='App_Data/images/secure.gif' style='width: 16px;'> <span style='color: #0C0; font-weight: bold;'>No instability found!</span><br />";
}
else {
foreach (self::$threats[$t] as $tt) {
if ($tt == 'socket' || $tt == 'socket_create' || $tt == 'connect' || $tt == 'stream_socket_server' || $tt == 'stream_socket_client') {
echo " <img src='App_Data/images/harmful.gif' style='width: 16px;'> <span style='color: #DD0; font-weight: bold;'><u>/!\</u> Possible instability found: ".$tt."()!</span><br />";
self::$pthreatCount++;
}
else {
echo " <img src='App_Data/images/insecure.gif' style='width: 16px;'> <span style='color: #F00; font-weight: bold;'><u>/!\</u> Instability found: ".$tt."()!</span><br />";
self::$threatCount++;
}
}
}
}
if (empty(self::$report)) {
$report = '<br>-';
}
else {
$report = self::$report;
}
echo "<hr style='border: 1px solid #BBB;'><b>Report:</b>".$report;
}
}
?>
Om de applicatie te gebruiken dien je de zip file te downloaden (er zitten namelijk ook nog plaatjes en een aantal benodigde mappen bij).