Skip to main content
Eval/Base64 File Scrubber [![Build Status](https://travis-ci.org/michigan-com/eval_scrubber.svg?branch=master)](https://travis-ci.org/michigan-com/eval_scrubber)
=========================

This script will walk through all files in a directory, find, and remove
any content that is suspected to be malicious.

This scan uses a regular expression to seek out any potentially malicious content

```
infected_pattern = re.compile(r"<\?php\s*eval\((.+\()*base64_decode\(.+\)\).+\s*?>")
```

What it is matching is `<?php eval(base64_decode()) ?>` or `<?php eval(gzinflate(base64_decode())) ?>`

It is strongly advized to check that this regular expression will match your needs.

We have not covered all of the edge cases for this script so be warned running this
script could have negative consequences.

The script accepts two arguments: action and directory

Actions:

* Find - Scans directory recursively and lists all potentially infected files
* Remove - Scans directory recursively and removes the regular express match
from all potentially infected files

```
python -m eval_scrubber find <dir>
python -m eval_scrubber remove <dir>
```

Set the log level
```
DEBUG=1 python -m eval_scrubber find <dir>
```

Install via PIP
---------------

```
pip install eval_scrubber
```


CHANGELOG
=========

0.0.3 2015-10-05
----------------

* Better unicode support

0.0.1 2015-10-05
----------------

* Uploaded to pypi

Release files for eval_scrubber 0.0.4

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for eval_scrubber 0.0.4
File Size Uploaded
eval_scrubber-0.0.4.tar.gz 3.8 kB Details

Release files / eval_scrubber-0.0.4.tar.gz

Download URL eval_scrubber-0.0.4.tar.gz
Size 3.8 kB
Tags Source
SHA-256 checksum
How to use checksums
619438a83555c8fcf3895ded60fa9f7100f4150812193fa63c2f186bfe30960e
BLAKE2b-256 checksum
How to use checksums
827ced1d98fa272307aee9e7e810a3977a9262924cf0a4a492f415516372fc71
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

0.0.4 This release

1 release file

0.0.3

1 release file

0.0.2

1 release file

0.0.1

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page