summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2016-01-04Add a whitelist for wordpress 4.4jvoisin
2016-01-04Perf optimization and rules completionjvoisin
2016-01-04Simplify a bit some rulesjvoisin
- Remove `b64_concat` since it was close to useless - Make `too_many_chr` non-greddy Those changes will make our malwares.yara rules yara-git friendly.
2015-12-11cleaning rule updatedJulien "shaddai" Reveret
2015-12-03files with no end of line or less than 3 lines and huge (more than 300) ↵Julien "shaddai" Reveret
amonts of characters are detected as suspicious
2015-12-03added double base64 encoding detectionJulien "shaddai" Reveret
2015-11-26added tennc repo to the listshaddai
2015-11-26new rulesshaddai
some samples from this repo weren't detected : https://github.com/tennc/webshell Fixes #3
2015-11-06added signature for base64 concatenationJulien "shaddai" Reveret
2015-11-02packaging inside a squeeze chroot modifies the malwares.yara file, adding a ↵Julien "shaddai" Reveret
git checkout to make sure it is restored before packaging starts
2015-10-29indent with spacesMathieu Deous
2015-10-29Merge branch 'master' of gitlab.nbs-system.com:packages/php-malware-finderMathieu Deous
Conflicts: php-malware-finder/bin/yara
2015-10-29reverting change since it triggers too many false positivesJulien "shaddai" Reveret
2015-10-29signatures: eval can be prefixed by an open square bracketMathieu Deous
2015-10-29tested php-malware-finder against many webshells, completed the signature listsJulien "shaddai" Reveret
2015-10-29added whitelist to packageJulien "shaddai" Reveret
2015-10-29builddir changed, modifying install files accordinglyJulien "shaddai" Reveret
2015-10-29control file modificationJulien "shaddai" Reveret
2015-10-29Makefile changed : no more git clone, new build dirJulien "shaddai" Reveret
2015-10-29reorganized git repoJulien "shaddai" Reveret
2015-10-29Add some more rulesjvoisin
2015-10-29Add some more dodgy functionsjvoisin
2015-10-29Add `pack` to the listjvoisin
2015-10-19reverting change since it triggers too many false positivesJulien "shaddai" Reveret
2015-10-15Merge pull request #12 from jvoisin/patch-1blotus
Fix #11
2015-10-15Fix #11jvoisin
This is a bit hackish, but I can't manage to find a more elegant way to do it.
2015-10-14signatures: eval can be prefixed by an open square bracketMathieu Deous
2015-10-09tested php-malware-finder against many webshells, completed the signature listsJulien "shaddai" Reveret
2015-10-09added whitelist to packageJulien "shaddai" Reveret
2015-10-09builddir changed, modifying install files accordinglyJulien "shaddai" Reveret
2015-10-09control file modificationJulien "shaddai" Reveret
2015-10-08Makefile changed : no more git clone, new build dirJulien "shaddai" Reveret
2015-10-08reorganized git repoJulien "shaddai" Reveret
2015-09-08Merge pull request #9 from gdelpierre/masterblotus
fix shebang typo
2015-09-08fix shebang typoGuillaume Delpierre
2015-09-08Merge pull request #8 from gdelpierre/masterblotus
Add shebang
2015-09-08Add shebangGuillaume Delpierre
2015-09-08remove empty lineGuillaume Delpierre
2015-09-08Remove glob library, not usedGuillaume Delpierre
2015-09-08Add shebangGuillaume Delpierre
2015-09-08Merge pull request #7 from gdelpierre/masterblotus
Use bash built-in and use portability shebang
2015-09-08Use type built-in instead of commandGuillaume Delpierre
2015-09-08TypoGuillaume Delpierre
2015-09-08Use bash builtinGuillaume Delpierre
2015-09-08PortabilityGuillaume Delpierre
2015-08-29Merge pull request #5 from ahpnils/masterMathieu D.
Update the whitelist for Dotclear 2.8.0
2015-08-28Add whitelist for Dotclear 2.8.0ahpnils
2015-08-28try to manually sync with upstreamahpnils
2015-08-28Merge remote-tracking branch 'upstream/master'ahpnils
2015-07-29Add some more rulesjvoisin