From 61126b35771eaa7537757362f264dbc8b6a32ed7 Mon Sep 17 00:00:00 2001 From: Mathieu Deous Date: Fri, 15 Apr 2022 22:02:16 +0200 Subject: Rewrite shell script in Go --- debian/changelog | 101 ------------------------------------ debian/compat | 1 - debian/conffiles | 0 debian/control | 14 ----- debian/copyright | 7 --- debian/files | 1 - debian/nbs-phpmalwarefinder.dirs | 1 - debian/nbs-phpmalwarefinder.install | 12 ----- debian/rules | 12 ----- 9 files changed, 149 deletions(-) delete mode 100644 debian/changelog delete mode 100644 debian/compat delete mode 100644 debian/conffiles delete mode 100644 debian/control delete mode 100644 debian/copyright delete mode 100644 debian/files delete mode 100644 debian/nbs-phpmalwarefinder.dirs delete mode 100644 debian/nbs-phpmalwarefinder.install delete mode 100755 debian/rules (limited to 'debian') diff --git a/debian/changelog b/debian/changelog deleted file mode 100644 index e169478..0000000 --- a/debian/changelog +++ /dev/null @@ -1,101 +0,0 @@ -nbs-phpmalwarefinder (0.3.4-1~deb) oldstable; urgency=medium - - * new upstream version : - - update the whitelists - - new rules to prevent bypasses - - readme improvement - - -- jre Mon, 07 Nov 2016 14:26:22 +0100 - -nbs-phpmalwarefinder (0.3.3-1~deb) oldstable; urgency=medium - - * new upstream version : - - add a strrev-based detection - - update the whitelists - - add a new fancy logo - * improve the release process - - -- jvo Mon, 24 Oct 2016 10:02:32 +0200 - -nbs-phpmalwarefinder (0.3.2-1~deb) oldstable; urgency=medium - - * new upstream version : - - whitelists are now split into files, each for one CMS - - a custom whitelist is available for users to add their own - - a mass whitelist helper has been added - * Added the custom whitelist to conffiles to prevent package upgrade from - overwriting users modification. - - -- jre Fri, 29 Jul 2016 09:47:56 +0200 - -nbs-phpmalwarefinder (0.3.1-1~deb) oldstable; urgency=medium - - * new upstream version : - - rules for visbot detection - - now detecting base64 encoded string USER_AGENT - - debian squeeze support dropped - - some false positives fixes - - -- jre Thu, 19 May 2016 15:22:47 +0200 - -nbs-phpmalwarefinder (0.3.0-1~deb) oldstable; urgency=medium - - * rules files refactoring : - - php-malware-finder now comes with asp malware detection - - rules have been split in different files to avoid false positives - - * The -l option allows language specific checks, for now only ASP and PHP - are supported. - * The -u option now allows to update rules without having to upgrade the - package. - - -- jre Thu, 14 Apr 2016 16:04:14 +0200 - -nbs-phpmalwarefinder (0.2.2-1~deb) oldstable; urgency=medium - - * new rules : bad_php.yara to find bad coding practices - * malwares.yara now comes with posix_* functions detection, new hard-coded - strings as well as php:// filter - * The TooShort rule has been improved to reduce FP - - -- jre Mon, 15 Feb 2016 15:48:06 +0100 - -nbs-phpmalwarefinder (0.2.1-1~deb) oldstable; urgency=medium - - * docroot-checker.sh added, helpful for both first and periodic security - scan. - - -- jre Mon, 01 Feb 2016 11:08:08 +0100 - -nbs-phpmalwarefinder (0.2.0-2~deb) oldstable; urgency=medium - - * New detection rules added - - -- sbl Thu, 28 Jan 2016 14:58:45 +0200 - -nbs-phpmalwarefinder (0.2.0-1~deb) oldstable; urgency=medium - - * Now supports whitelist using yara hash function - * New detection rules added (tested against - https://github.com/tennc/webshell malware collection) - - -- jre Fri, 09 Oct 2015 14:58:45 +0200 - -nbs-phpmalwarefinder (0.1.1-1~deb) oldstable; urgency=medium - - * new dependecy on util-linux since the script is using ionice - * postinst script added to create diff folder - - -- jre Tue, 28 Apr 2015 15:07:12 +0200 - -nbs-phpmalwarefinder (0.1.1-1~deb) oldstable; urgency=medium - - * new signature to detect malware in footer and header - - -- jre Tue, 14 Apr 2015 14:40:05 +0000 - -nbs-phpmalwarefinder (0.1) UNRELEASED; urgency=medium - - * Initial release. - - -- jvoisin Tue, 24 Mar 2015 11:10:36 +0100 diff --git a/debian/compat b/debian/compat deleted file mode 100644 index 7ed6ff8..0000000 --- a/debian/compat +++ /dev/null @@ -1 +0,0 @@ -5 diff --git a/debian/conffiles b/debian/conffiles deleted file mode 100644 index e69de29..0000000 diff --git a/debian/control b/debian/control deleted file mode 100644 index b50454f..0000000 --- a/debian/control +++ /dev/null @@ -1,14 +0,0 @@ -Source: nbs-phpmalwarefinder -Section: utils -Priority: optional -Maintainer: Security team -Build-Depends: debhelper (>= 8) -Standards-Version: 3.9.5 -Vcs-Git: https://github.com/nbs-system/php-malware-finder -Vcs-Browser: https://github.com/nbs-system/php-malware-finder - -Package: nbs-phpmalwarefinder -Architecture: any -Depends: nbs-yara, wget, nbs-python-yara, python -Description: yara-based php webshell finder - PhpMalwareFinder is a webshell and malware hunter using yara and signatures. diff --git a/debian/copyright b/debian/copyright deleted file mode 100644 index 6bec77a..0000000 --- a/debian/copyright +++ /dev/null @@ -1,7 +0,0 @@ -Format: http://www.debian.org/doc/packaging-manuals/copyright-format/1.0/ -Upstream-Name: phpmalwarefinder -Source: https://github.com/nbs-system/php-malware-finder - -Files: * -Copyright 2015 Julien (jvoisin) Voisin -License: GPLv3 diff --git a/debian/files b/debian/files deleted file mode 100644 index 23f95ef..0000000 --- a/debian/files +++ /dev/null @@ -1 +0,0 @@ -nbs-phpmalwarefinder_0.1_amd64.deb utils optional diff --git a/debian/nbs-phpmalwarefinder.dirs b/debian/nbs-phpmalwarefinder.dirs deleted file mode 100644 index 61a8d27..0000000 --- a/debian/nbs-phpmalwarefinder.dirs +++ /dev/null @@ -1 +0,0 @@ -etc/phpmalwarefinder/ \ No newline at end of file diff --git a/debian/nbs-phpmalwarefinder.install b/debian/nbs-phpmalwarefinder.install deleted file mode 100644 index 748222d..0000000 --- a/debian/nbs-phpmalwarefinder.install +++ /dev/null @@ -1,12 +0,0 @@ -whitelists/custom.yar etc/phpmalwarefinder/whitelists -whitelists/drupal.yar etc/phpmalwarefinder/whitelists -whitelists/magento2.yar etc/phpmalwarefinder/whitelists -whitelists/phpmyadmin.yar etc/phpmalwarefinder/whitelists -whitelists/prestashop.yar etc/phpmalwarefinder/whitelists -whitelists/symfony.yar etc/phpmalwarefinder/whitelists -whitelists/wordpress.yar etc/phpmalwarefinder/whitelists -utils/generate_whitelist.py usr/bin/ -utils/mass_whitelist.py usr/bin/ -php.yar etc/phpmalwarefinder -whitelist.yar etc/phpmalwarefinder -phpmalwarefinder usr/bin/ diff --git a/debian/rules b/debian/rules deleted file mode 100755 index bcf500a..0000000 --- a/debian/rules +++ /dev/null @@ -1,12 +0,0 @@ -#!/usr/bin/make -f - -BUILDDIR=debian/build - -override_dh_auto_clean: #fuck you debian - -override_dh_auto_build: - -%: - dh $@ - -.PHONY: build -- cgit v1.3