您好,登錄后才能下訂單哦!
#!/bin/bash
#wirte by zhenglong 20150818
#Centos
# php Trojan checking
email="1525356778@qq.com"
rm -rf /tmp/file.txt
echo "Contain suspicious files:" >> /tmp/file.txt
find / -name "*.php" -type f -print0 | xargs -0 egrep "(phpspy|c99sh|milw0rm|eval\(gzuncompress\(base64_decoolcode|eval\(base64_decoolcode|spider_bc|gzinflate)" | awk -F: '{print $1}' | sort | uniq >> /tmp/file.txt
echo -e "\nContain file_put_contents:" >>/tmp/file.txt
grep -r --include=*.php 'file_put_contents(.*$_POST\[.*\]);' / >>/tmp/file.txt
echo -e "\nContain eval:" >> /tmp/file.txt
grep -r --include=*.php '[^a-z]eval($_POST' / >>/tmp/file.txt
echo -e "\n PHP file change in one day:" >> /tmp/file.txt
find / -mtime -1 -type f -name *.php >>/tmp/file.txt
cat /tmp/file.txt |mail -s "PHP Trojan" ${email}
免責(zé)聲明:本站發(fā)布的內(nèi)容(圖片、視頻和文字)以原創(chuàng)、轉(zhuǎn)載和分享為主,文章觀點(diǎn)不代表本網(wǎng)站立場,如果涉及侵權(quán)請聯(lián)系站長郵箱:is@yisu.com進(jìn)行舉報(bào),并提供相關(guān)證據(jù),一經(jīng)查實(shí),將立刻刪除涉嫌侵權(quán)內(nèi)容。