summaryrefslogtreecommitdiff
path: root/tests.sh
diff options
context:
space:
mode:
authorMathieu Deous2022-05-02 20:18:23 +0200
committerGitHub2022-05-02 20:18:23 +0200
commit48936efa96ae17295be4e0a71be3294f0ec6aef8 (patch)
treef4e69551f1368aa048edf46b7b061600f3668329 /tests.sh
parentbbc738e16f8b637afde58d65196374af98a5e0e2 (diff)
Make application go-install-able and create a docker image
Diffstat (limited to '')
-rwxr-xr-xtests.sh (renamed from php-malware-finder/tests.sh)18
1 files changed, 9 insertions, 9 deletions
diff --git a/php-malware-finder/tests.sh b/tests.sh
index f8c5109..a302031 100755
--- a/php-malware-finder/tests.sh
+++ b/tests.sh
@@ -1,7 +1,7 @@
1#!/bin/bash 1#!/bin/bash
2 2
3PMF=./phpmalwarefinder 3PMF=./php-malware-finder
4SAMPLES=./samples 4SAMPLES=./data/samples
5 5
6type yara 2>/dev/null 1>&2 || (echo "[-] Please make sure that yara is installed" && exit 1) 6type yara 2>/dev/null 1>&2 || (echo "[-] Please make sure that yara is installed" && exit 1)
7 7
@@ -29,17 +29,17 @@ run_test classic/ajaxshell.php 'DodgyStrings'
29run_test classic/ajaxshell.php '0x23e2:$: shell_exec' 29run_test classic/ajaxshell.php '0x23e2:$: shell_exec'
30run_test classic/ajaxshell.php "0x16e0:\$ini_get: ini_get('safe_mode" 30run_test classic/ajaxshell.php "0x16e0:\$ini_get: ini_get('safe_mode"
31run_test classic/ajaxshell.php "0x17f1:\$ini_get: ini_get('open_basedir" 31run_test classic/ajaxshell.php "0x17f1:\$ini_get: ini_get('open_basedir"
32run_test classic/angel.php '0x1d:$disable_magic_quotes:' 32run_test classic/angel.php '0x1b:$disable_magic_quotes:'
33run_test classic/b374k.php 'ObfuscatedPhp' 33run_test classic/b374k.php 'ObfuscatedPhp'
34run_test classic/b374k.php "0xe9:\$b374k: 'ev'.'al'" 34run_test classic/b374k.php "0xe9:\$b374k: 'ev'.'al'"
35run_test classic/b374k.php '0xb3:$align: $func="cr"."eat"."e_fun"."cti"."on";$b374k=$func(' 35run_test classic/b374k.php '0xb3:$align: $func="cr"."eat"."e_fun"."cti"."on";$b374k=$func('
36run_test classic/b374k.php '0xd6:$align: ;$b374k=$func(' 36run_test classic/b374k.php '0xd6:$align: ;$b374k=$func('
37run_test classic/b374k.php '0x43:$: github.com/b374k/b374k' 37run_test classic/b374k.php '0x43:$: github.com/b374k/b374k'
38run_test classic/sosyete.php '0x1a2d:$execution: shell_exec($_POST' 38run_test classic/sosyete.php '0x194e:$execution: shell_exec($_POST'
39run_test classic/simattacker.php '0x16e:$: fpassthru' 39run_test classic/simattacker.php '0x158:$: fpassthru'
40run_test classic/r57.php '0x149da:$: xp_cmdshell' 40run_test classic/r57.php '0x142a2:$: xp_cmdshell'
41run_test classic/cyb3rsh3ll.php '0x23323:$udp_dos: fsockopen("udp://' 41run_test classic/cyb3rsh3ll.php '0x2200d:$udp_dos: fsockopen("udp://'
42run_test classic/c99.php '0x3d56:$eval: {exec(' 42run_test classic/c99.php '0x3bb4:$eval: {exec('
43run_test classic/c100.php '0x4f8d:$eval: {eval(' 43run_test classic/c100.php '0x4f8d:$eval: {eval('
44 44
45# Obfuscated php 45# Obfuscated php
@@ -81,7 +81,7 @@ run_test artificial/bypasses.php "0x132:\$var_as_func: \$_POST\['funct'\]("
81# real 81# real
82run_test real/sucuri_2014_04.php '0x67:$execution3:' 82run_test real/sucuri_2014_04.php '0x67:$execution3:'
83run_test real/novahot.php 'DodgyStrings' 83run_test real/novahot.php 'DodgyStrings'
84run_test real/guidtz.php '0x12d8:$non_printables:' 84run_test real/guidtz.php '0x286:$non_printables:'
85run_test real/ice.php 'double_var' 85run_test real/ice.php 'double_var'
86run_test real/srt.php '$register_function' 86run_test real/srt.php '$register_function'
87run_test real/awvjtnz.php '$reversed:' 87run_test real/awvjtnz.php '$reversed:'