Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #!/bin/bash
- # Helper script to trigger from Plesk Events or on demand to fix flawed/
- # unsafe rewrite directives in nginx config files added by wp-toolkit or other tools
- # Related to CVE-2026-42945 Nginx Rift
- # Target core paths across the filesystem
- VHOST_DIR="/etc/nginx/plesk.conf.d/vhosts"
- SYSTEM_DIR="/var/www/vhosts/system"
- # Force the execution block into a detached subshell wrapper
- (
- # Wait 3 seconds to allow Plesk/wp-toolkit to completely finish writing files to disk
- sleep 3
- # 1. Broadly sanitize any generated file in the active Nginx include path
- if [ -d "$VHOST_DIR" ]; then
- find "$VHOST_DIR" -type f \( -name "*.conf" -o -name "*.config" \) -exec sed -i \
- -e 's|rewrite "\^/(?\!wp-admin/)" "/fake-author-scan" last;|rewrite \^/(\[\^w\]\[\^p\]\[\^-\].\*)\$ /fake-author-scan last;|g' {} +
- fi
- # 2. Broadly sanitize the Plesk systemic internal tracker directories
- if [ -d "$SYSTEM_DIR" ]; then
- find "$SYSTEM_DIR" -type f -name "*.conf" -exec sed -i \
- -e 's|rewrite "\^/(?\!wp-admin/)" "/fake-author-scan" last;|rewrite \^/(\[\^w\]\[\^p\]\[\^-\].\*)\$ /fake-author-scan last;|g' {} +
- fi
- # 3. Perform a syntax test before committing to ensure zero web service downtime
- /usr/sbin/nginx -t >/dev/null 2>&1
- if [ $? -eq 0 ]; then
- /etc/init.d/nginx reload >/dev/null 2>&1
- fi
- ) &
- # Exit immediately so Plesk finishes its repair loop without hanging
- exit 0
Advertisement
Add Comment
Please, Sign In to add comment