-
Notifications
You must be signed in to change notification settings - Fork 97
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Pattern Not Found in JS Files #91
Comments
Could you create a sample in ZIP and share it so i can run local test against those files in structure? |
@scr34m Are you looking for files in structure or just the files. I've attached the files here. The structure is part of quite a large application and the paths are as follows: /www/assets/components/cliche/mgr/thumbnail/tv/cards/main.js
/www/assets/components/cliche/mgr/core/main.panel.js
/www/js/jquery-1.js
/www/js/jquery.js |
Sorry for the delay, but we don't have any rule for javascript code matching, if you know these files are problematic then it is possible to extend the rule set. |
Hey @scr34m it's a fair point. I'm not sure what the best approach is given that a hacked site is a hacked site and that it's not uncommon for attacks to use a variety of PHP and JS for malicious control. It feels redundant to have to somehow run a PHP malware scanner and a JS one when this seems to catch things such as eval() and obfuscated code. The first line of each of those files above contains obfuscated malicious js that was causing redirects within a MODX Revolution website Manager. MODX is written mostly in PHP but the manager makes significant use of ExtJS3 and has a parser event system that can trigger files in points in time of the system. These files were contributing to external requests and redirects out to malicious websites. |
If you can send me with malware infected JS the no problem to make some rules and slowly evolve the set. |
Hey @scr34m in the badfiles.zip, each of those 4 files contains the malicious code on line 1. |
@scr34m I'm also not sure what you mean by: "I've created 2 pattern for the files, you can check on master, not version tagged yet." Could you elaborate? Maybe I'm misunderstanding your requests here. |
You have to use the master branch to test, no version tag created so packages won't offer you an update. |
@scr34m I tested on my end and all is good here - the sigs were picked up. |
We ran the following script command to try to find bad files in a site that was having issues. There were a half dozen js files referenced by PHP that were not found by the script.
And the findings found false-positives in JPGs, PDFs, other JS files and PHP files, but didn't find actual postives in js files in the following format that we found on manual inspection of plugins (MODX) triggered by PHP. These are following strings are in the top portion of the files at line 1. These files were within the
www/
recursive path and should have been found:and
Let us know if you have any further questions or want any further examples. They're all the same format but with slightly different output. I'm sure they're using an encoder to generate the obfuscated JS.
The text was updated successfully, but these errors were encountered: