x2Fusion

MalScanner.class.php

Feb 4th, 2016
202
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 2.24 KB | None | 0 0
  1. <?php
  2.  
  3. $scan = new MalScanner('.');
  4. echo $scan->showAlerts();
  5.  
  6. class MalScanner
  7. {  
  8.     private $scannedFiles = array();
  9.    
  10.     private $infectedFiles = array();
  11.    
  12.     public function __construct($directory = __DIR__)
  13.     {
  14.         if($directory == '.')
  15.         {
  16.             $directory = __DIR__ . substr($directory, 1);
  17.         }
  18.        
  19.         if(!is_dir($directory))
  20.         {
  21.             throw new Exception("Unable to locate scan directory '$directory'.");
  22.         }
  23.        
  24.         $this->scanDirectory($directory);
  25.     }
  26.    
  27.     public function showAlerts()
  28.     {
  29.         if(count($this->infectedFiles) > 0)
  30.         {
  31.             $message = "== MALICIOUS CODE FOUND == \r\n\r\n";
  32.             $message .= "The following files appear to be infected: \r\n";
  33.             foreach($this->infectedFiles as $file)
  34.             {
  35.                 $message .= " - $file\r\n";
  36.             }
  37.             $message .= "\r\n== MALICIOUS CODE FOUND ==\r\n";
  38.            
  39.             return $message;
  40.         }
  41.     }  
  42.  
  43.     public function sendAlerts()
  44.     {
  45.         if(count($this->infectedFiles) > 0)
  46.         {
  47.             $message = "== MALICIOUS CODE FOUND == \r\n\r\n";
  48.             $message .= "The following files appear to be infected: \r\n";
  49.             foreach($this->infectedFiles as $file)
  50.             {
  51.                 $message .= " - $file\r\n";
  52.             }
  53.             $message .= "\r\n== MALICIOUS CODE FOUND ==\r\n";
  54.            
  55.             mail(TO_EMAIL, 'Malicious Code Found!', $message, 'FROM: malscanner@localhost');
  56.         }
  57.     }
  58.  
  59.     private function scanDirectory($directory)
  60.     {
  61.         $this->scannedFiles[] = $directory;    
  62.         $unscannedFiles = scandir($directory);
  63.        
  64.         if(!is_array($unscannedFiles))
  65.         {
  66.             throw new Exception("Unable to scan directory '$Directory'. Please make sure proper permissions have been set.");
  67.         }
  68.        
  69.         foreach($unscannedFiles as $unscannedFile)
  70.         {
  71.             if(is_file("$directory/$unscannedFile") && !in_array("$directory/$unscannedFile", $this->scannedFiles))
  72.             {
  73.                 $this->checkFile("$directory/$unscannedFile");
  74.             }
  75.             elseif(is_dir("$directory/$unscannedFile") && substr($unscannedFile, 0, 1) != '.' && substr($unscannedFile, 0, 2) != '..')
  76.             {
  77.                 $this->scanDirectory("$directory/$unscannedFile");
  78.             }
  79.         }
  80.     }
  81.    
  82.     private function checkFile($file)
  83.     {
  84.         $this->scannedFiles[] = $file;
  85.         if(preg_match('/eval\((base64|eval|\$_|\$\$|\$[A-Za-z_0-9\{]*(\(|\{|\[))/i', file_get_contents($file)))
  86.         {
  87.             if($file != __FILE__)
  88.             {
  89.                 $this->infectedFiles[] = $file;
  90.             }
  91.         }
  92.     }
  93. }
Advertisement
Add Comment
Please, Sign In to add comment