#!/bin/bash
#wirte by zhenglong 20150818
#Centos
# php Trojan checking
email="1525356778@qq.com"
rm -rf /tmp/file.txt
echo "Contain suspicious files:" >> /tmp/file.txt
find / -name "*.php" -type f -print0 | xargs -0 egrep "(phpspy|c99sh|milw0rm|eval\(gzuncompress\(base64_decoolcode|eval\(base64_decoolcode|spider_bc|gzinflate)" | awk -F: '{print $1}' | sort | uniq >> /tmp/file.txt
echo -e "\nContain file_put_contents:" >>/tmp/file.txt
grep -r --include=*.php 'file_put_contents(.*$_POST\[.*\]);' / >>/tmp/file.txt
echo -e "\nContain eval:" >> /tmp/file.txt
grep -r --include=*.php '[^a-z]eval($_POST' / >>/tmp/file.txt
echo -e "\n PHP file change in one day:" >> /tmp/file.txt
find / -mtime -1 -type f -name *.php >>/tmp/file.txt
cat /tmp/file.txt |mail -s "PHP Trojan" ${email}
另外有需要云服务器可以了解下创新互联cdcxhl.cn,海内外云服务器15元起步,三天无理由+7*72小时售后在线,公司持有idc许可证,提供“云服务器、裸金属服务器、高防服务器、香港服务器、美国服务器、虚拟主机、免备案服务器”等云主机租用服务以及企业上云的综合解决方案,具有“安全稳定、简单易用、服务可用性高、性价比高”等特点与优势,专为企业上云打造定制,能够满足用户丰富、多元化的应用场景需求。
网站栏目:统计php更改文件,可疑文件-创新互联
标题来源:http://tyjierui.cn/article/ehsec.html