Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- $scan = new MalScanner('.');
- echo $scan->showAlerts();
- class MalScanner
- {
- private $scannedFiles = array();
- private $infectedFiles = array();
- public function __construct($directory = __DIR__)
- {
- if($directory == '.')
- {
- $directory = __DIR__ . substr($directory, 1);
- }
- if(!is_dir($directory))
- {
- throw new Exception("Unable to locate scan directory '$directory'.");
- }
- $this->scanDirectory($directory);
- }
- public function showAlerts()
- {
- if(count($this->infectedFiles) > 0)
- {
- $message = "== MALICIOUS CODE FOUND == \r\n\r\n";
- $message .= "The following files appear to be infected: \r\n";
- foreach($this->infectedFiles as $file)
- {
- $message .= " - $file\r\n";
- }
- $message .= "\r\n== MALICIOUS CODE FOUND ==\r\n";
- return $message;
- }
- }
- public function sendAlerts()
- {
- if(count($this->infectedFiles) > 0)
- {
- $message = "== MALICIOUS CODE FOUND == \r\n\r\n";
- $message .= "The following files appear to be infected: \r\n";
- foreach($this->infectedFiles as $file)
- {
- $message .= " - $file\r\n";
- }
- $message .= "\r\n== MALICIOUS CODE FOUND ==\r\n";
- mail(TO_EMAIL, 'Malicious Code Found!', $message, 'FROM: malscanner@localhost');
- }
- }
- private function scanDirectory($directory)
- {
- $this->scannedFiles[] = $directory;
- $unscannedFiles = scandir($directory);
- if(!is_array($unscannedFiles))
- {
- throw new Exception("Unable to scan directory '$Directory'. Please make sure proper permissions have been set.");
- }
- foreach($unscannedFiles as $unscannedFile)
- {
- if(is_file("$directory/$unscannedFile") && !in_array("$directory/$unscannedFile", $this->scannedFiles))
- {
- $this->checkFile("$directory/$unscannedFile");
- }
- elseif(is_dir("$directory/$unscannedFile") && substr($unscannedFile, 0, 1) != '.' && substr($unscannedFile, 0, 2) != '..')
- {
- $this->scanDirectory("$directory/$unscannedFile");
- }
- }
- }
- private function checkFile($file)
- {
- $this->scannedFiles[] = $file;
- if(preg_match('/eval\((base64|eval|\$_|\$\$|\$[A-Za-z_0-9\{]*(\(|\{|\[))/i', file_get_contents($file)))
- {
- if($file != __FILE__)
- {
- $this->infectedFiles[] = $file;
- }
- }
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment