|
8 | 8 | * License: GNU/GPLv2 |
9 | 9 | * @see LICENSE.txt |
10 | 10 | * |
11 | | - * This file: Optional security extras module (last modified: 2025.04.28). |
| 11 | + * This file: Optional security extras module (last modified: 2025.05.12). |
12 | 12 | * |
13 | 13 | * False positive risk (an approximate, rough estimate only): « [ ]Low [x]Medium [ ]High » |
14 | 14 | */ |
|
107 | 107 | '\.w(?:ell-known|p-cli)/(?:.*(?:a(?:bout|dmin)[\da-z]*|fierza[\da-z]*|install[\da-z]*|moon[\da-z]*|shell[\da-z]*|wp-login[\da-z]*|x)|go|radio)|' . |
108 | 108 | '\.?rxr(?:_[\da-z]+)?|' . |
109 | 109 | '\d{3,5}[a-z]{3,5}|\d+-?backdoor|0byte|0[xz]|10+|1337|1ppy|4price|85022df0ed31|991176|' . |
110 | | - 'a(?:b1ux1ft|dmin-heade\d*|hhygskn|lexus|lfa(?:-rex|_data|a?cgiapi|ioxi|new|shell)?\d*|njas|pismtp|xx)|' . |
| 110 | + 'a(?:b1ux1ft|dmin-heade\d*|hhygskn|lexus|lfa(?:-?rex|-?ioxi|_data|a?cgiapi|new|shell)?\d*|njas|pismtp|xx)|' . |
111 | 111 | 'b(?:0|3d2acc621a0|ak|ala|axa\d+|eence|ibil_0day)|' . |
112 | 112 | 'c(?:(?:9|10)\d+|adastro-2|asper[\da-z]+|d(?:.*tmp.*rm-rf|chmod.*\d{3,})|fom[-_]files|(?:gi-bin|(?:fm|ss))/(?:luci/;|moon|newgolden|radio|sgd|stok=/|uploader|well-known|wp-login)|lass(?:smtps|withtostring)|offee/fw|olors/blue/uploader|omfunctions|ong|ontentloader1|opypaths|ss/colors/coffee/index)|' . |
113 | 113 | 'd(?:7|eadcode\d*|elpaths|epotcv|isagraep|kiz|oiconvs|ummyyummy/wp-signup)|' . |
114 | | - 'e(?:e|pinyins)|' . |
| 114 | + 'e(?:e|pinyins|rin\d+)|' . |
115 | 115 | 'f(?:ddqradz|ilefun)|' . |
116 | 116 | 'g(?:dftps|el4y|etid3-core|h[0o]st|lab-rare|zismexv)|' . |
117 | 117 | 'h(?:[4a]x+[0o]r|6ss|anna1337|ehehe|sfpdcd|tmlawedtest)|' . |
118 | | - 'i(?:\d{3,}[a-z]{2,}|cesword|d3/class-config|mages/sym|ndoxploit|optimize|oxi/alfa-ioxi|r7szrsouep|itsec|xr/(?:allez|wp-login))|' . |
| 118 | + 'i(?:\d{3,}[a-z]{2,}|cesword|d3/class-config|mages/sym|ndoxploit|optimize|oxi\d*|r7szrsouep|itsec|xr/(?:allez|wp-login))|' . |
119 | 119 | 'kvkjguw|' . |
120 | 120 | 'l(?:ock0?360|eaf_mailer|eaf_php|ufix(?:-shell)?|uuf)|' . |
121 | 121 | 'm(?:akeasmtp|iin|oduless|u-plugins/db-safe-mode|y1)|' . |
122 | 122 | 'njima|' . |
123 | 123 | 'o(?:ld(?:/wp-admin/install|-up-ova)|rvx(?:-shell)?|thiondwmek)|' . |
124 | 124 | 'p(?:erl\.alfa|hp(?:1|_niu_\d+)|lugins/(?:backup_index|vwcleanerplugin/bump|zedd/\d+)|oison|riv8|wnd|zaiihfi)|' . |
125 | | - 'rendixd|' . |
| 125 | + 'r(?:andkeyword|endixd)|' . |
126 | 126 | 's(?:_n?e|ession91|h[3e]ll[sx]?\d*|hrift|idwso|ilic|kipper(?:shell)?|llolx|onarxleetxd|pammervip|rc/util/php/(?:eval(?:-stdin)?|kill)|ystem_log)|' . |
127 | 127 | 't(?:62|aptap-null|enda\.sh.*tenda\.sh|emplates/beez/index|hemes/(?:finley/min|pridmag/db|universal-news/www)|ermps|homs|hreefox(?:_exploit/index)?|inymce/(?:langs/about|plugins/compat3x/css/index)|k_dencode_\d+|mp/vuln|opxoh/(?:drsx|wdr))|' . |
128 | 128 | 'u(?:bh/up|nisibfu|pfile(?:_\\(\d\\))?|pgrade-temp-backup/wp-login|ploader_by_cloud7_agath|tchiha(?:_uploader)?)|' . |
|
141 | 141 | $LCNrURI |
142 | 142 | ), 'Probing for webshells/backdoors')) { |
143 | 143 | $CIDRAM['Reporter']->report([15, 20, 21], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']); |
144 | | - } // 2023.08.18 mod 2025.04.17 |
| 144 | + } // 2023.08.18 mod 2025.05.12 |
145 | 145 |
|
146 | 146 | /** Probing for vulnerable plugins or webapps. */ |
147 | 147 | if ( |
|
159 | 159 | $CIDRAM['Reporter']->report([15, 20], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']); |
160 | 160 | } // 2024.02.18 mod 2025.04.28 |
161 | 161 |
|
| 162 | + /** Probing for webshells/backdoors. */ |
| 163 | + if ($Trigger(preg_match( |
| 164 | + '~(?:^|[/?])(?:perl.alfa|search/label/php-shells)(?:$|[/?])~', |
| 165 | + $LCNrURI |
| 166 | + ), 'Probing for webshells/backdoors')) { |
| 167 | + $CIDRAM['Reporter']->report([15, 20, 21], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']); |
| 168 | + } // 2025.05.12 |
| 169 | + |
162 | 170 | /** Probing for exposed Git data. */ |
163 | 171 | if ($Trigger(preg_match('~\.git(?:config)?(?:$|\W)~', $LCNrURI), 'Probing for exposed git data')) { |
164 | 172 | $CIDRAM['Reporter']->report([15, 21], ['Caught probing for exposed git data.'], $CIDRAM['BlockInfo']['IPAddr']); |
|
0 commit comments