Skip to content

Commit 5a88a0f

Browse files
committed
Modules update.
1 parent e1096f0 commit 5a88a0f

3 files changed

Lines changed: 17 additions & 13 deletions

File tree

modules/module_botua.php

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
* License: GNU/GPLv2
99
* @see LICENSE.txt
1010
*
11-
* This file: Bot user agents module (last modified: 2025.03.31).
11+
* This file: Bot user agents module (last modified: 2025.07.05).
1212
*
1313
* False positive risk (an approximate, rough estimate only): « [ ]Low [x]Medium [ ]High »
1414
*/
@@ -225,7 +225,7 @@
225225
'^(?:[aim]$|(?!linkedinbot).*http-?(?:agent|client))|' .
226226
'a(?:bonti|ccserver|cme.spider|dreview/\d|jbaxy|nthill$|nyevent-http|ppengine|xios)|' .
227227
'b(?:abbar\.tech|igbozz|lackbird|logsearch|logbot|salsa)|' .
228-
'c(?:astlebot|atexplorador|k=\{\}|lickagy|liqzbot|ontextad|orporama|ortex/\d|rowsnest|yberpatrol)|' .
228+
'c(?:astlebot|atexplorador|k=\{\}|lickagy|liqzbot|ms-?checker|ontextad|orporama|ortex/\d|rowsnest|yberpatrol)|' .
229229
'd(?:eepfield|le_spider|nbcrawler|omainappender|umprendertree)|' .
230230
'expanse|' .
231231
'f(?:lightdeckreportsbot|luid/|orms\.gle)|' .
@@ -248,7 +248,7 @@
248248
) || preg_match(
249249
'~^Mozilla/5\.0( [A-Za-z]{2,5}/0\..)?$~',
250250
$CIDRAM['BlockInfo']['UA']
251-
), 'Unauthorised'); // 2023.09.15 mod 2024.09.15
251+
), 'Unauthorised'); // 2023.09.15 mod 2025.07.05
252252

253253
$Trigger(preg_match('/(?:internet explorer)/', $UA), 'Hostile / Fake IE'); // 2017.02.03
254254

@@ -308,6 +308,8 @@
308308
$UANoSpace
309309
), 'Scraper UA'); // 2023.11.17 mod 2024.04.11
310310

311+
$Trigger(preg_match('~ct‑git‑scanner/~i', $CIDRAM['BlockInfo']['UA']), 'Unauthorised Git scanner'); // 2025.07.05
312+
311313
/** These signatures can set extended tracking options. */
312314
if (
313315
$Trigger(strpos($UANoSpace, '$_' . '[$' . '__') !== false, 'UA shell upload attempt') || // 2017.01.02

modules/module_extras.php

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
* License: GNU/GPLv2
99
* @see LICENSE.txt
1010
*
11-
* This file: Optional security extras module (last modified: 2025.07.01).
11+
* This file: Optional security extras module (last modified: 2025.07.05).
1212
*
1313
* False positive risk (an approximate, rough estimate only): « [ ]Low [x]Medium [ ]High »
1414
*/
@@ -115,7 +115,7 @@
115115
'd(?:7|eadcode\d*|elpaths|epotcv|isagraep|kiz|oiconvs|ummyyummy/wp-signup)|' .
116116
'e(?:ctoplasm/str_shuffcle|e|pinyins|rin\d+)|' .
117117
'f(?:ddqradz|ilefun)|' .
118-
'g(?:dftps|el4y|etid3-core|h[0o]st|lab-rare|zismexv)|' .
118+
'g(?:awean|dftps|el4y|etid3-core|h[0o]st|lab-rare|zismexv)|' .
119119
'h(?:[4a]x+[0o]r|6ss|anna1337|ehehe|sfpdcd|tmlawedtest)|' .
120120
'i(?:\d{3,}[a-z]{2,}|cesword|d3/class-config|mages/sym|ndoxploit|optimize|oxi\d*|r7szrsouep|itsec|xr/(?:allez|wp-login))|' .
121121
'kvkjguw|' .
@@ -143,10 +143,11 @@
143143
$LCNrURI
144144
), 'Probing for webshells/backdoors')) {
145145
$CIDRAM['Reporter']->report([15, 20, 21], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']);
146-
} // 2023.08.18 mod 2025.06.29
146+
} // 2023.08.18 mod 2025.07.05
147147

148148
/** Probing for vulnerable plugins or webapps. */
149149
if (
150+
$Trigger(preg_match('~/civicrm/packages/openflashchart/php-ofc-library/ofc_upload_image\.php[57]?(?:$|[/?])~', $LCNrURI), $Exploit = 'CiviCRM 3x') || // 2025.07.05
150151
$Trigger(preg_match('~/dup-installer/main\.installer\.php[57]?(?:$|[/?])~', $LCNrURI), $Exploit = 'CVE-2022-2551') || // 2024.09.05
151152
$Trigger(preg_match('~/Telerik\.Web\.UI\.WebResource\.axd(?:$|[/?])~i', $LCNrURI), $Exploit = 'CVE-2019-18935') || // 2024.10.30
152153
$Trigger(preg_match('~\?s=../%5c|invokefunction&function=call_user_func_array&|vars%5b0%5d=md5|vars%5b1%5d%5b%5d=hellothinkphp~', $LCNrURI), $Exploit = 'CVE-2018-20062') // 2025.07.01
@@ -156,11 +157,11 @@
156157

157158
/** Probing for webshells/backdoors. */
158159
if ($Trigger(preg_match(
159-
'~(?:^|[/?])(?:[1-9cefimnptuwx]{27}\.jsp|alfa-?rexhp\d\.p|(?:send-)?ses\.sh)(?:$|[/?])~',
160+
'~(?:^|[/?])(?:[1-9cefimnptuwx]{27}\.jsp|alfa_data/alfacgiapi|alfa-?rexhp\d\.p|(?:send-)?ses\.sh)(?:$|[/?])~',
160161
$LCNrURI
161162
), 'Probing for webshells/backdoors')) {
162163
$CIDRAM['Reporter']->report([15, 20], ['Caught probing for webshells/backdoors. Host might be compromised.'], $CIDRAM['BlockInfo']['IPAddr']);
163-
} // 2024.02.18 mod 2025.06.26
164+
} // 2024.02.18 mod 2025.07.05
164165

165166
/** Probing for webshells/backdoors. */
166167
if ($Trigger(preg_match(
@@ -344,7 +345,8 @@
344345
), 'Compromised password used in brute-force attacks'); // 2023.10.10
345346

346347
$Trigger(preg_match('~/etc/passwd:null:null$~', $QueryNoSpace), 'Hack attempt'); // 2024.02.18
347-
$Trigger(preg_match('~\?phpinfo=-1$~', $QueryNoSpace), 'Hack attempt'); // 2025.05.24
348+
$Trigger(preg_match('~(?:^|&)phpinfo=-1$~', $QueryNoSpace), 'Hack attempt'); // 2025.05.24 fix 2025.07.05
349+
$Trigger(preg_match('~(?:^|&)action=p&api=p&path=p&token=$~', $QueryNoSpace), 'Hack attempt'); // 2025.07.05
348350

349351
/** These signatures can set extended tracking options. */
350352
if (

modules/modules.dat

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -203,7 +203,7 @@ module_bgpview.php:
203203
module_botua.php:
204204
Name: "Bot user agents module"
205205
False Positive Risk: "Medium"
206-
Version: "2025.89.0"
206+
Version: "2025.185.0"
207207
Dependencies:
208208
PHP: "^5.4|^7|^8"
209209
CIDRAM Core: "^1.13.1|^2.0.1"
@@ -215,7 +215,7 @@ module_botua.php:
215215
To:
216216
- "module_botua.php"
217217
Checksum:
218-
- "f0b59a54d9c0a709cbbf0ad4f453cc29fce6e82888ffbb204029b709d2373cd8:26711"
218+
- "f75d9259f5a4f154bd3307b356fa62e16d0226e1bed2f476864eeee4b40f481e:26846"
219219
Used with: "modules"
220220
Reannotate: "modules.dat"
221221
module_cookies.php:
@@ -239,7 +239,7 @@ module_cookies.php:
239239
module_extras.php:
240240
Name: "Optional security extras module"
241241
False Positive Risk: "Medium"
242-
Version: "2025.181.0"
242+
Version: "2025.185.0"
243243
Dependencies:
244244
PHP: "^5.4|^7|^8"
245245
CIDRAM Core: "^1.13.1|^2.0.1"
@@ -254,7 +254,7 @@ module_extras.php:
254254
- "module_extras.php"
255255
- "module_extras.yaml"
256256
Checksum:
257-
- "a9a94b94380933970322580765f7c73665813750522ea6e326a091c10693c8b6:31894"
257+
- "54ebf946ab59b9071d4dcf1c58ff350902825523f343945a9b95bfe37ba7a599:32234"
258258
- "7b891d1fa4b1c52c410220bc758e8cb7064bd6040430fb149a5b60e9ae2e0838:890"
259259
Used with: "modules"
260260
Reannotate: "modules.dat"

0 commit comments

Comments
 (0)