Eval/Base64 File Scrubber [](https://travis-ci.org/michigan-com/eval_scrubber)
=========================
This script will walk through all files in a directory, find, and remove
any content that is suspected to be malicious.
This scan uses a regular expression to seek out any potentially malicious content
```
infected_pattern = re.compile(r"<\?php\s*eval\((.+\()*base64_decode\(.+\)\).+\s*?>")
```
What it is matching is `<?php eval(base64_decode()) ?>` or `<?php eval(gzinflate(base64_decode())) ?>`
It is strongly advized to check that this regular expression will match your needs.
We have not covered all of the edge cases for this script so be warned running this
script could have negative consequences.
The script accepts two arguments: action and directory
Actions:
* Find - Scans directory recursively and lists all potentially infected files
* Remove - Scans directory recursively and removes the regular express match
from all potentially infected files
```
python -m eval_scrubber find <dir>
python -m eval_scrubber remove <dir>
```
Set the log level
```
DEBUG=1 python -m eval_scrubber find <dir>
```
Install via PIP
---------------
```
pip install eval_scrubber
```
CHANGELOG
=========
0.0.3 2015-10-05
----------------
* Better unicode support
0.0.1 2015-10-05
----------------
* Uploaded to pypi
=========================
This script will walk through all files in a directory, find, and remove
any content that is suspected to be malicious.
This scan uses a regular expression to seek out any potentially malicious content
```
infected_pattern = re.compile(r"<\?php\s*eval\((.+\()*base64_decode\(.+\)\).+\s*?>")
```
What it is matching is `<?php eval(base64_decode()) ?>` or `<?php eval(gzinflate(base64_decode())) ?>`
It is strongly advized to check that this regular expression will match your needs.
We have not covered all of the edge cases for this script so be warned running this
script could have negative consequences.
The script accepts two arguments: action and directory
Actions:
* Find - Scans directory recursively and lists all potentially infected files
* Remove - Scans directory recursively and removes the regular express match
from all potentially infected files
```
python -m eval_scrubber find <dir>
python -m eval_scrubber remove <dir>
```
Set the log level
```
DEBUG=1 python -m eval_scrubber find <dir>
```
Install via PIP
---------------
```
pip install eval_scrubber
```
CHANGELOG
=========
0.0.3 2015-10-05
----------------
* Better unicode support
0.0.1 2015-10-05
----------------
* Uploaded to pypi
Release files for eval_scrubber 0.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| eval_scrubber-0.0.4.tar.gz | 3.8 kB | Details |
Release files / eval_scrubber-0.0.4.tar.gz
| Download URL | eval_scrubber-0.0.4.tar.gz |
|---|---|
| Size | 3.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
619438a83555c8fcf3895ded60fa9f7100f4150812193fa63c2f186bfe30960e
|
|
BLAKE2b-256 checksum How to use checksums |
827ced1d98fa272307aee9e7e810a3977a9262924cf0a4a492f415516372fc71
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |