Skip to content

Commit 3e9aaca

Browse files
committed
Extras module update.
1 parent d84490f commit 3e9aaca

File tree

2 files changed

+16
-8
lines changed

2 files changed

+16
-8
lines changed

modules/module_extras.php

Lines changed: 14 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
* License: GNU/GPLv2
99
* @see LICENSE.txt
1010
*
11-
* This file: Optional security extras module (last modified: 2025.04.28).
11+
* This file: Optional security extras module (last modified: 2025.05.12).
1212
*
1313
* False positive risk (an approximate, rough estimate only): « [ ]Low [x]Medium [ ]High »
1414
*/
@@ -107,22 +107,22 @@
107107
'\.w(?:ell-known|p-cli)/(?:.*(?:a(?:bout|dmin)[\da-z]*|fierza[\da-z]*|install[\da-z]*|moon[\da-z]*|shell[\da-z]*|wp-login[\da-z]*|x)|go|radio)|' .
108108
'\.?rxr(?:_[\da-z]+)?|' .
109109
'\d{3,5}[a-z]{3,5}|\d+-?backdoor|0byte|0[xz]|10+|1337|1ppy|4price|85022df0ed31|991176|' .
110-
'a(?:b1ux1ft|dmin-heade\d*|hhygskn|lexus|lfa(?:-rex|_data|a?cgiapi|ioxi|new|shell)?\d*|njas|pismtp|xx)|' .
110+
'a(?:b1ux1ft|dmin-heade\d*|hhygskn|lexus|lfa(?:-?rex|-?ioxi|_data|a?cgiapi|new|shell)?\d*|njas|pismtp|xx)|' .
111111
'b(?:0|3d2acc621a0|ak|ala|axa\d+|eence|ibil_0day)|' .
112112
'c(?:(?:9|10)\d+|adastro-2|asper[\da-z]+|d(?:.*tmp.*rm-rf|chmod.*\d{3,})|fom[-_]files|(?:gi-bin|(?:fm|ss))/(?:luci/;|moon|newgolden|radio|sgd|stok=/|uploader|well-known|wp-login)|lass(?:smtps|withtostring)|offee/fw|olors/blue/uploader|omfunctions|ong|ontentloader1|opypaths|ss/colors/coffee/index)|' .
113113
'd(?:7|eadcode\d*|elpaths|epotcv|isagraep|kiz|oiconvs|ummyyummy/wp-signup)|' .
114-
'e(?:e|pinyins)|' .
114+
'e(?:e|pinyins|rin\d+)|' .
115115
'f(?:ddqradz|ilefun)|' .
116116
'g(?:dftps|el4y|etid3-core|h[0o]st|lab-rare|zismexv)|' .
117117
'h(?:[4a]x+[0o]r|6ss|anna1337|ehehe|sfpdcd|tmlawedtest)|' .
118-
'i(?:\d{3,}[a-z]{2,}|cesword|d3/class-config|mages/sym|ndoxploit|optimize|oxi/alfa-ioxi|r7szrsouep|itsec|xr/(?:allez|wp-login))|' .
118+
'i(?:\d{3,}[a-z]{2,}|cesword|d3/class-config|mages/sym|ndoxploit|optimize|oxi\d*|r7szrsouep|itsec|xr/(?:allez|wp-login))|' .
119119
'kvkjguw|' .
120120
'l(?:ock0?360|eaf_mailer|eaf_php|ufix(?:-shell)?|uuf)|' .
121121
'm(?:akeasmtp|iin|oduless|u-plugins/db-safe-mode|y1)|' .
122122
'njima|' .
123123
'o(?:ld(?:/wp-admin/install|-up-ova)|rvx(?:-shell)?|thiondwmek)|' .
124124
'p(?:erl\.alfa|hp(?:1|_niu_\d+)|lugins/(?:backup_index|vwcleanerplugin/bump|zedd/\d+)|oison|riv8|wnd|zaiihfi)|' .
125-
'rendixd|' .
125+
'r(?:andkeyword|endixd)|' .
126126
's(?:_n?e|ession91|h[3e]ll[sx]?\d*|hrift|idwso|ilic|kipper(?:shell)?|llolx|onarxleetxd|pammervip|rc/util/php/(?:eval(?:-stdin)?|kill)|ystem_log)|' .
127127
't(?:62|aptap-null|enda\.sh.*tenda\.sh|emplates/beez/index|hemes/(?:finley/min|pridmag/db|universal-news/www)|ermps|homs|hreefox(?:_exploit/index)?|inymce/(?:langs/about|plugins/compat3x/css/index)|k_dencode_\d+|mp/vuln|opxoh/(?:drsx|wdr))|' .
128128
'u(?:bh/up|nisibfu|pfile(?:_\\(\d\\))?|pgrade-temp-backup/wp-login|ploader_by_cloud7_agath|tchiha(?:_uploader)?)|' .
@@ -141,7 +141,7 @@
141141
$LCNrURI
142142
), 'Probing for webshells/backdoors')) {
143143
$CIDRAM['Reporter']->report([15, 20, 21], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']);
144-
} // 2023.08.18 mod 2025.04.17
144+
} // 2023.08.18 mod 2025.05.12
145145

146146
/** Probing for vulnerable plugins or webapps. */
147147
if (
@@ -159,6 +159,14 @@
159159
$CIDRAM['Reporter']->report([15, 20], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']);
160160
} // 2024.02.18 mod 2025.04.28
161161

162+
/** Probing for webshells/backdoors. */
163+
if ($Trigger(preg_match(
164+
'~(?:^|[/?])(?:perl.alfa|search/label/php-shells)(?:$|[/?])~',
165+
$LCNrURI
166+
), 'Probing for webshells/backdoors')) {
167+
$CIDRAM['Reporter']->report([15, 20, 21], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']);
168+
} // 2025.05.12
169+
162170
/** Probing for exposed Git data. */
163171
if ($Trigger(preg_match('~\.git(?:config)?(?:$|\W)~', $LCNrURI), 'Probing for exposed git data')) {
164172
$CIDRAM['Reporter']->report([15, 21], ['Caught probing for exposed git data.'], $CIDRAM['BlockInfo']['IPAddr']);

modules/modules.dat

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -239,7 +239,7 @@ module_cookies.php:
239239
module_extras.php:
240240
Name: "Optional security extras module"
241241
False Positive Risk: "Medium"
242-
Version: "2025.117.0"
242+
Version: "2025.131.0"
243243
Dependencies:
244244
PHP: "^5.4|^7|^8"
245245
CIDRAM Core: "^1.13.1|^2.0.1"
@@ -254,7 +254,7 @@ module_extras.php:
254254
- "module_extras.php"
255255
- "module_extras.yaml"
256256
Checksum:
257-
- "2083205265631b783a5b8c738cca97e6319dfcd8d13add72fc4afae1ef563fec:30750"
257+
- "842aefefd663977f3cfe2e61466bf0ffe16473108738c0eda94562931e8564ef:31178"
258258
- "7b891d1fa4b1c52c410220bc758e8cb7064bd6040430fb149a5b60e9ae2e0838:890"
259259
Used with: "modules"
260260
Reannotate: "modules.dat"

0 commit comments

Comments
 (0)