403Webshell
Server IP : 66.29.132.122  /  Your IP : 18.219.40.177
Web Server : LiteSpeed
System : Linux business142.web-hosting.com 4.18.0-553.lve.el8.x86_64 #1 SMP Mon May 27 15:27:34 UTC 2024 x86_64
User : admazpex ( 531)
PHP Version : 7.2.34
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /proc/self/root/proc/self/root/proc/thread-self/root/proc/thread-self/root/proc/self/root/proc/thread-self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/opt/imunify360/venv/lib/python3.11/site-packages/imav/malwarelib/utils/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /proc/self/root/proc/self/root/proc/thread-self/root/proc/thread-self/root/proc/self/root/proc/thread-self/root/proc/self/root/proc/self/root/proc/self/root/proc/self/root/opt/imunify360/venv/lib/python3.11/site-packages/imav/malwarelib/utils/check_file.py
"""
This program is free software: you can redistribute it and/or modify it under
the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License,
or (at your option) any later version.


This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. 
See the GNU General Public License for more details.


You should have received a copy of the GNU General Public License
 along with this program.  If not, see <https://www.gnu.org/licenses/>.

Copyright © 2019 Cloud Linux Software Inc.

This software is also available under ImunifyAV commercial license,
see <https://www.imunify360.com/legal/eula>
"""
import re

LOG_AND_MAIL_REGEX = (
    r"/sess\_\w*$",
    r"/stat/usage\_\w+\.html",
    r"/stat/site\_\w+\.html",
    r"/webstat/awstats.*\.txt",
    r"/awstats/awstats.*\.txt",
    r"/awstats/.{1,80}\.pl",
    r"/awstats/.{1,80}\.html",
    r"/logs/error\_log\..*",
    r"/logs/xferlog\..*",
    r"/logs/access\_log\..*",
    r"/domlogs/.+",
    r"/logs/cron\..*",
    r"/logs/exceptions/.+\.log(?:\.\d)?(?:\.gz)?$",
    r"/mail(?:/[^/]+)*/[^,]+,S=[^,]+,W=.+",
    r"/mail(?:/[^/]+)*/[^,]+,S=.+",
    r"/mail(?:/[^/]+)*/storage/u\.[0-9]+",
    r"/mail(?:/[^/]+)*/storage/m\.[0-9]+",
    r"/Maildir(?:/[^/]+)*/[^,]+,S=[^,]+,W=.+",
    r"/Maildir(?:/[^/]+)*/[^,]+,S=.+",
    r"^/var/ossec/.*",
)

IMUNIFY_LOG_REGEX = (
    r"/var/log/imunify360/acronis-installer\.log$",
    r"/var/log/imunify360/console\.log(?:\.\d)?(?:\.gz)?$",
    r"/var/log/imunify360/debug\.log$",
    r"/var/log/imunify360/error\.log$",
    r"/var/log/install-mod\_remoteip\.log(?:\.\d{1.4})?(?:\.pid)?r$",
    r"/var/log/imunify360/malware\_scan\_\d{10}\.log$",
    r"/var/log/imunify360/network\.log$",
    r"/var/log/imunify360/process\_message\.log$",
    r"/var/log/imunify360-webshield/access.log(?:-\d{8})?(?:.gz)?$",
    r"/var/log/imunify360-webshield/error.log(?:-\d{8})?(?:.gz)?$",
    r"/.revisium_antivirus_cache/.revisium\d+/",
    r"/admin/plib/modules/revisium-antivirus/library/externals/",
)

BYTES_TO_READ = 50

REGEX_IGNORE = [*map(re.compile, LOG_AND_MAIL_REGEX + IMUNIFY_LOG_REGEX)]


def check_log_and_mail(data) -> bool:
    """
    Check if file extension matches log file extension
    """
    for regex_obj in REGEX_IGNORE:
        if regex_obj.search(data):
            return True
    return False

Youez - 2016 - github.com/yon3zu
LinuXploit