committing changes in /etc made by "bash i360deploy.sh --key IMUNX4Nv23rDqdjndBH"

Package changes:
This commit is contained in:
2023-02-09 14:52:03 +02:00
parent 4911d0453d
commit 54c4e5b173
56 changed files with 695496 additions and 11 deletions

View File

@@ -41,7 +41,6 @@ mkdir -p './imunify360-webshield/webshield-backend.conf.d'
mkdir -p './imunify360-webshield/webshield-captcha.conf.d' mkdir -p './imunify360-webshield/webshield-captcha.conf.d'
mkdir -p './imunify360-webshield/webshield-server.conf.d' mkdir -p './imunify360-webshield/webshield-server.conf.d'
mkdir -p './imunify360-webshield/webshield-splashscreen.conf.d' mkdir -p './imunify360-webshield/webshield-splashscreen.conf.d'
mkdir -p './imunify360/user_config'
mkdir -p './incron.d' mkdir -p './incron.d'
mkdir -p './java/security/security.d' mkdir -p './java/security/security.d'
mkdir -p './jvm' mkdir -p './jvm'
@@ -342,9 +341,11 @@ maybe chmod 0644 'cron.d/imunify-antivirus'
maybe chmod 0644 'cron.d/imunify-notifier' maybe chmod 0644 'cron.d/imunify-notifier'
maybe chmod 0644 'cron.d/imunify360' maybe chmod 0644 'cron.d/imunify360'
maybe chmod 0644 'cron.d/imunify360-webshield-check' maybe chmod 0644 'cron.d/imunify360-webshield-check'
maybe chmod 0600 'cron.d/imunify_scan_schedule'
maybe chmod 0644 'cron.d/lfd-cron' maybe chmod 0644 'cron.d/lfd-cron'
maybe chmod 0644 'cron.d/maldet_pub' maybe chmod 0644 'cron.d/maldet_pub'
maybe chmod 0644 'cron.d/shrinker-cron' maybe chmod 0644 'cron.d/shrinker-cron'
maybe chmod 0600 'cron.d/waf_configurator'
maybe chmod 0755 'cron.daily' maybe chmod 0755 'cron.daily'
maybe chmod 0755 'cron.daily/cloudlinux-backup-utils' maybe chmod 0755 'cron.daily/cloudlinux-backup-utils'
maybe chmod 0700 'cron.daily/csget' maybe chmod 0700 'cron.daily/csget'
@@ -1069,6 +1070,7 @@ maybe chmod 0644 'imunify360-webshield/virtserver.conf'
maybe chmod 0755 'imunify360-webshield/webshield-backend.conf.d' maybe chmod 0755 'imunify360-webshield/webshield-backend.conf.d'
maybe chmod 0755 'imunify360-webshield/webshield-captcha.conf.d' maybe chmod 0755 'imunify360-webshield/webshield-captcha.conf.d'
maybe chmod 0755 'imunify360-webshield/webshield-http.conf.d' maybe chmod 0755 'imunify360-webshield/webshield-http.conf.d'
maybe chmod 0660 'imunify360-webshield/webshield-http.conf.d/captchakeys.conf'
maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/resolver.conf' maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/resolver.conf'
maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/static-whitelist.conf' maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/static-whitelist.conf'
maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/wscheckdata.conf' maybe chmod 0644 'imunify360-webshield/webshield-http.conf.d/wscheckdata.conf'
@@ -1080,6 +1082,94 @@ maybe chmod 0644 'imunify360-webshield/win-utf'
maybe chmod 0644 'imunify360-webshield/wscheck.conf' maybe chmod 0644 'imunify360-webshield/wscheck.conf'
maybe chmod 0600 'imunify360/unified-access-logger.conf' maybe chmod 0600 'imunify360/unified-access-logger.conf'
maybe chmod 0755 'imunify360/user_config' maybe chmod 0755 'imunify360/user_config'
maybe chgrp '5yFVdI0o' 'imunify360/user_config/5yFVdI0o'
maybe chmod 0750 'imunify360/user_config/5yFVdI0o'
maybe chgrp '5yFVdI0o' 'imunify360/user_config/5yFVdI0o/imunify360.config'
maybe chmod 0640 'imunify360/user_config/5yFVdI0o/imunify360.config'
maybe chgrp '6LFzChlC' 'imunify360/user_config/6LFzChlC'
maybe chmod 0750 'imunify360/user_config/6LFzChlC'
maybe chgrp '6LFzChlC' 'imunify360/user_config/6LFzChlC/imunify360.config'
maybe chmod 0640 'imunify360/user_config/6LFzChlC/imunify360.config'
maybe chgrp 'PxAzpq9B' 'imunify360/user_config/PxAzpq9B'
maybe chmod 0750 'imunify360/user_config/PxAzpq9B'
maybe chgrp 'PxAzpq9B' 'imunify360/user_config/PxAzpq9B/imunify360.config'
maybe chmod 0640 'imunify360/user_config/PxAzpq9B/imunify360.config'
maybe chgrp 'ZTmpNnll' 'imunify360/user_config/ZTmpNnll'
maybe chmod 0750 'imunify360/user_config/ZTmpNnll'
maybe chgrp 'ZTmpNnll' 'imunify360/user_config/ZTmpNnll/imunify360.config'
maybe chmod 0640 'imunify360/user_config/ZTmpNnll/imunify360.config'
maybe chgrp '_AodQqBu' 'imunify360/user_config/_AodQqBu'
maybe chmod 0750 'imunify360/user_config/_AodQqBu'
maybe chgrp '_AodQqBu' 'imunify360/user_config/_AodQqBu/imunify360.config'
maybe chmod 0640 'imunify360/user_config/_AodQqBu/imunify360.config'
maybe chgrp 'bogdan' 'imunify360/user_config/bogdan'
maybe chmod 0750 'imunify360/user_config/bogdan'
maybe chgrp 'bogdan' 'imunify360/user_config/bogdan/imunify360.config'
maybe chmod 0640 'imunify360/user_config/bogdan/imunify360.config'
maybe chgrp 'cfb' 'imunify360/user_config/cfb'
maybe chmod 0750 'imunify360/user_config/cfb'
maybe chgrp 'cfb' 'imunify360/user_config/cfb/imunify360.config'
maybe chmod 0640 'imunify360/user_config/cfb/imunify360.config'
maybe chgrp 'csf' 'imunify360/user_config/csf'
maybe chmod 0750 'imunify360/user_config/csf'
maybe chgrp 'csf' 'imunify360/user_config/csf/imunify360.config'
maybe chmod 0640 'imunify360/user_config/csf/imunify360.config'
maybe chgrp 'gigi' 'imunify360/user_config/gigi'
maybe chmod 0750 'imunify360/user_config/gigi'
maybe chgrp 'gigi' 'imunify360/user_config/gigi/imunify360.config'
maybe chmod 0640 'imunify360/user_config/gigi/imunify360.config'
maybe chgrp 'laser' 'imunify360/user_config/laser'
maybe chmod 0750 'imunify360/user_config/laser'
maybe chgrp 'laser' 'imunify360/user_config/laser/imunify360.config'
maybe chmod 0640 'imunify360/user_config/laser/imunify360.config'
maybe chgrp 'litecoin' 'imunify360/user_config/litecoin'
maybe chmod 0750 'imunify360/user_config/litecoin'
maybe chgrp 'litecoin' 'imunify360/user_config/litecoin/imunify360.config'
maybe chmod 0640 'imunify360/user_config/litecoin/imunify360.config'
maybe chgrp 'madalin' 'imunify360/user_config/madalin'
maybe chmod 0750 'imunify360/user_config/madalin'
maybe chgrp 'madalin' 'imunify360/user_config/madalin/imunify360.config'
maybe chmod 0640 'imunify360/user_config/madalin/imunify360.config'
maybe chgrp 'mailcow' 'imunify360/user_config/mailcow'
maybe chmod 0750 'imunify360/user_config/mailcow'
maybe chgrp 'mailcow' 'imunify360/user_config/mailcow/imunify360.config'
maybe chmod 0640 'imunify360/user_config/mailcow/imunify360.config'
maybe chgrp 'public' 'imunify360/user_config/public'
maybe chmod 0750 'imunify360/user_config/public'
maybe chgrp 'public' 'imunify360/user_config/public/imunify360.config'
maybe chmod 0640 'imunify360/user_config/public/imunify360.config'
maybe chgrp 'pydio' 'imunify360/user_config/pydio'
maybe chmod 0750 'imunify360/user_config/pydio'
maybe chgrp 'pydio' 'imunify360/user_config/pydio/imunify360.config'
maybe chmod 0640 'imunify360/user_config/pydio/imunify360.config'
maybe chgrp 'rundeck' 'imunify360/user_config/rundeck'
maybe chmod 0750 'imunify360/user_config/rundeck'
maybe chgrp 'rundeck' 'imunify360/user_config/rundeck/imunify360.config'
maybe chmod 0640 'imunify360/user_config/rundeck/imunify360.config'
maybe chgrp 'sara' 'imunify360/user_config/sara'
maybe chmod 0750 'imunify360/user_config/sara'
maybe chgrp 'sara' 'imunify360/user_config/sara/imunify360.config'
maybe chmod 0640 'imunify360/user_config/sara/imunify360.config'
maybe chgrp 'sftp' 'imunify360/user_config/sftp'
maybe chmod 0750 'imunify360/user_config/sftp'
maybe chgrp 'sftp' 'imunify360/user_config/sftp/imunify360.config'
maybe chmod 0640 'imunify360/user_config/sftp/imunify360.config'
maybe chgrp 'smiti' 'imunify360/user_config/smiti'
maybe chmod 0750 'imunify360/user_config/smiti'
maybe chgrp 'smiti' 'imunify360/user_config/smiti/imunify360.config'
maybe chmod 0640 'imunify360/user_config/smiti/imunify360.config'
maybe chgrp 'spamd' 'imunify360/user_config/spamd'
maybe chmod 0750 'imunify360/user_config/spamd'
maybe chgrp 'spamd' 'imunify360/user_config/spamd/imunify360.config'
maybe chmod 0640 'imunify360/user_config/spamd/imunify360.config'
maybe chgrp 'vampi' 'imunify360/user_config/vampi'
maybe chmod 0750 'imunify360/user_config/vampi'
maybe chgrp 'vampi' 'imunify360/user_config/vampi/imunify360.config'
maybe chmod 0640 'imunify360/user_config/vampi/imunify360.config'
maybe chgrp 'www-data' 'imunify360/user_config/www-data'
maybe chmod 0750 'imunify360/user_config/www-data'
maybe chgrp 'www-data' 'imunify360/user_config/www-data/imunify360.config'
maybe chmod 0640 'imunify360/user_config/www-data/imunify360.config'
maybe chmod 0644 'incron.conf' maybe chmod 0644 'incron.conf'
maybe chmod 0755 'incron.d' maybe chmod 0755 'incron.d'
maybe chmod 0644 'inittab' maybe chmod 0644 'inittab'
@@ -4790,6 +4880,8 @@ maybe chmod 0644 'openldap/ldap.conf'
maybe chmod 0755 'opt' maybe chmod 0755 'opt'
maybe chmod 0600 'ossec-init.conf' maybe chmod 0600 'ossec-init.conf'
maybe chmod 0755 'pam.d' maybe chmod 0755 'pam.d'
maybe chmod 0660 'pam.d/.password-auth.i360patch'
maybe chmod 0660 'pam.d/.system-auth.i360patch'
maybe chmod 0644 'pam.d/atd' maybe chmod 0644 'pam.d/atd'
maybe chmod 0644 'pam.d/chfn' maybe chmod 0644 'pam.d/chfn'
maybe chmod 0644 'pam.d/chsh' maybe chmod 0644 'pam.d/chsh'
@@ -4805,6 +4897,7 @@ maybe chmod 0644 'pam.d/mock'
maybe chmod 0644 'pam.d/other' maybe chmod 0644 'pam.d/other'
maybe chmod 0644 'pam.d/passwd' maybe chmod 0644 'pam.d/passwd'
maybe chmod 0644 'pam.d/password-auth' maybe chmod 0644 'pam.d/password-auth'
maybe chmod 0644 'pam.d/password-auth.i360bak'
maybe chmod 0644 'pam.d/polkit-1' maybe chmod 0644 'pam.d/polkit-1'
maybe chmod 0644 'pam.d/postlogin' maybe chmod 0644 'pam.d/postlogin'
maybe chmod 0644 'pam.d/ppp' maybe chmod 0644 'pam.d/ppp'
@@ -4825,6 +4918,7 @@ maybe chmod 0644 'pam.d/sudo'
maybe chmod 0644 'pam.d/sudo-i' maybe chmod 0644 'pam.d/sudo-i'
maybe chmod 0644 'pam.d/system-auth' maybe chmod 0644 'pam.d/system-auth'
maybe chmod 0755 'pam.d/system-auth-ac' maybe chmod 0755 'pam.d/system-auth-ac'
maybe chmod 0644 'pam.d/system-auth.i360bak'
maybe chmod 0644 'pam.d/systemd-user' maybe chmod 0644 'pam.d/systemd-user'
maybe chmod 0644 'pam.d/vlock' maybe chmod 0644 'pam.d/vlock'
maybe chmod 0644 'pam.d/vmtoolsd' maybe chmod 0644 'pam.d/vmtoolsd'
@@ -5823,7 +5917,16 @@ maybe chmod 0644 'sysconfig/garb'
maybe chmod 0644 'sysconfig/htcacheclean' maybe chmod 0644 'sysconfig/htcacheclean'
maybe chmod 0750 'sysconfig/imunify360' maybe chmod 0750 'sysconfig/imunify360'
maybe chmod 0660 'sysconfig/imunify360/.imunify360.backup_config' maybe chmod 0660 'sysconfig/imunify360/.imunify360.backup_config'
maybe chmod 0600 'sysconfig/imunify360/auth.admin'
maybe chmod 0644 'sysconfig/imunify360/custom_billing.config' maybe chmod 0644 'sysconfig/imunify360/custom_billing.config'
maybe chmod 0755 'sysconfig/imunify360/generic'
maybe chmod 0644 'sysconfig/imunify360/generic/global_disabled_rules.conf'
maybe chmod 0644 'sysconfig/imunify360/generic/imunify-plugin.zip'
maybe chmod 0644 'sysconfig/imunify360/generic/modsec.conf'
maybe chmod 0700 'sysconfig/imunify360/generic/modsec.conf.d'
maybe chmod 0644 'sysconfig/imunify360/generic/modsec.conf.d/empty.conf'
maybe chmod 0644 'sysconfig/imunify360/generic/modsec2.imunify.conf'
maybe chmod 0644 'sysconfig/imunify360/generic/nginx.modsec3.imunify.conf'
maybe chmod 0644 'sysconfig/imunify360/imunify360-merged.config' maybe chmod 0644 'sysconfig/imunify360/imunify360-merged.config'
maybe chmod 0600 'sysconfig/imunify360/imunify360.config' maybe chmod 0600 'sysconfig/imunify360/imunify360.config'
maybe chmod 0700 'sysconfig/imunify360/imunify360.config.d' maybe chmod 0700 'sysconfig/imunify360/imunify360.config.d'
@@ -5832,7 +5935,18 @@ maybe chmod 0600 'sysconfig/imunify360/imunify360.config.defaults.example'
maybe chmod 0640 'sysconfig/imunify360/integration.conf' maybe chmod 0640 'sysconfig/imunify360/integration.conf'
maybe chmod 0755 'sysconfig/imunify360/malware-filters-admin-conf' maybe chmod 0755 'sysconfig/imunify360/malware-filters-admin-conf'
maybe chmod 0644 'sysconfig/imunify360/malware-filters-admin-conf/ignored.txt' maybe chmod 0644 'sysconfig/imunify360/malware-filters-admin-conf/ignored.txt'
maybe chmod 0770 'sysconfig/imunify360/malware-filters-admin-conf/processed'
maybe chmod 0660 'sysconfig/imunify360/malware-filters-admin-conf/processed/basedirs-list.txt'
maybe chmod 0770 'sysconfig/imunify360/malware-filters-admin-conf/processed/ignored'
maybe chmod 0660 'sysconfig/imunify360/malware-filters-admin-conf/processed/ignored/av-admin-paths.txt'
maybe chmod 0660 'sysconfig/imunify360/malware-filters-admin-conf/processed/ignored/av-admin.txt'
maybe chmod 0660 'sysconfig/imunify360/malware-filters-admin-conf/processed/ignored/av-internal.txt'
maybe chmod 0660 'sysconfig/imunify360/malware-filters-admin-conf/processed/ignored/pd-combined.txt'
maybe chmod 0770 'sysconfig/imunify360/malware-filters-admin-conf/processed/watched'
maybe chmod 0660 'sysconfig/imunify360/malware-filters-admin-conf/processed/watched/av-admin.txt'
maybe chmod 0660 'sysconfig/imunify360/malware-filters-admin-conf/processed/watched/av-internal.txt'
maybe chmod 0644 'sysconfig/imunify360/malware-filters-admin-conf/watched.txt' maybe chmod 0644 'sysconfig/imunify360/malware-filters-admin-conf/watched.txt'
maybe chmod 0660 'sysconfig/imunify360/panel-name.txt'
maybe chmod 0600 'sysconfig/ip6tables-config' maybe chmod 0600 'sysconfig/ip6tables-config'
maybe chmod 0600 'sysconfig/iptables-config' maybe chmod 0600 'sysconfig/iptables-config'
maybe chmod 0644 'sysconfig/iptables.old-2020-10-20-17_37_02' maybe chmod 0644 'sysconfig/iptables.old-2020-10-20-17_37_02'

View File

@@ -0,0 +1,2 @@
# DO NOT EDIT. AUTOMATICALLY GENERATED.
0 3 * * 0 root /usr/bin/imunify360-agent malware user scan --background >/dev/null 2>&1

2
cron.d/waf_configurator Normal file
View File

@@ -0,0 +1,2 @@
# DO NOT EDIT. AUTOMATICALLY GENERATED BY IMUNIFY360.
51 4 * * * root /opt/alt/python38/share/imunify360/scripts/report-command-error /opt/alt/python38/share/imunify360/scripts/update_components_versions.py > /dev/null 2>&1

View File

@@ -166,3 +166,4 @@ tcp:in:d=5666:s=194.63.143.34 # file.rocks
# csf_tool: # csf_tool:
148.251.142.83 # imunify360 server - Thu Feb 9 14:49:32 2023 148.251.142.83 # imunify360 server - Thu Feb 9 14:49:32 2023
69.175.3.10 # files.imunify360.com server - Thu Feb 9 14:49:32 2023 69.175.3.10 # files.imunify360.com server - Thu Feb 9 14:49:32 2023
Include /var/imunify360/files/whitelist/v2/imunify360.txt

View File

@@ -139,7 +139,7 @@ LF_SPI = "1"
TCP_IN = "20,21,22,25,26,53,80,88,110,143,443,465,587,873,904,953,992,993,995,1723,1986,2082,2083,2086,2087,2095,2096,5080,5222,5269,5432,5665,5666,8000,8001,8080,8443,8800,8988,9080,9391,9443,9999,11898,52222,65534,1907:1909,40000:40100" TCP_IN = "20,21,22,25,26,53,80,88,110,143,443,465,587,873,904,953,992,993,995,1723,1986,2082,2083,2086,2087,2095,2096,5080,5222,5269,5432,5665,5666,8000,8001,8080,8443,8800,8988,9080,9391,9443,9999,11898,52222,65534,1907:1909,40000:40100"
# Allow outgoing TCP ports # Allow outgoing TCP ports
TCP_OUT = ",1:65535" TCP_OUT = "8443,44445,55556,1:65535,7770:7800"
# Allow incoming UDP ports # Allow incoming UDP ports
UDP_IN = "20,21,53,67,68,123,161,500,514,517,518,1027,1194,1514,1701,1981,4500,33434:33523" UDP_IN = "20,21,53,67,68,123,161,500,514,517,518,1027,1194,1514,1701,1981,4500,33434:33523"

View File

@@ -139,7 +139,7 @@ LF_SPI = "1"
TCP_IN = "20,21,22,25,26,53,80,88,110,143,443,465,587,873,904,953,992,993,995,1723,1986,2082,2083,2086,2087,2095,2096,5080,5222,5269,5432,5665,5666,8000,8001,8080,8443,8800,8988,9080,9391,9443,9999,11898,52222,65534,1907:1909,40000:40100" TCP_IN = "20,21,22,25,26,53,80,88,110,143,443,465,587,873,904,953,992,993,995,1723,1986,2082,2083,2086,2087,2095,2096,5080,5222,5269,5432,5665,5666,8000,8001,8080,8443,8800,8988,9080,9391,9443,9999,11898,52222,65534,1907:1909,40000:40100"
# Allow outgoing TCP ports # Allow outgoing TCP ports
TCP_OUT = "1:65535" TCP_OUT = ",1:65535"
# Allow incoming UDP ports # Allow incoming UDP ports
UDP_IN = "20,21,53,67,68,123,161,500,514,517,518,1027,1194,1514,1701,1981,4500,33434:33523" UDP_IN = "20,21,53,67,68,123,161,500,514,517,518,1027,1194,1514,1701,1981,4500,33434:33523"

File diff suppressed because it is too large Load Diff

File diff suppressed because it is too large Load Diff

View File

@@ -1 +1 @@
splashscreen_antibot off; splashscreen_antibot on;

View File

@@ -0,0 +1,17 @@
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # #
#
# !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
# DO NOT EDIT. AUTOMATICALLY GENERATED.
# !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
#
# Direct modifications to this file WILL be lost upon subsequent
# regeneration of this configuration file.
#
# To have your modifications retained, you should use
# update settings in UI.
#
# # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # # #
captcha_site_key 6LcLaPwUAAAAAOLoPlKRFZnQW2QNKjKN2v1ReY2S;
captcha_secret_key 6LcLaPwUAAAAAE3JSA-AEzkQ5_N7vr8Pg8k1UDqa;

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,11 @@
BACKUP_RESTORE:
max_days_in_backup: null
MALWARE_SCANNING:
default_action: null
try_restore_from_backup_first: null
PROACTIVE_DEFENCE:
blamer: null
mode: null
SECURE_SITE:
enable: false
purchase_page_url: https://secure.site

View File

@@ -0,0 +1,8 @@
--- /etc/pam.d/password-auth 2021-08-26 19:12:51.778023053 +0300
+++ - 2023-02-09 14:51:46.796675536 +0200
@@ -1,3 +1,5 @@
auth required pam_env.so
+auth required pam_imunify.so check_only
auth sufficient pam_unix.so try_first_pass nullok
+auth required pam_imunify.so
auth required pam_deny.so

View File

@@ -0,0 +1,8 @@
--- /etc/pam.d/system-auth 2022-10-08 19:09:45.000000000 +0300
+++ - 2023-02-09 14:51:46.801236173 +0200
@@ -4,3 +4,5 @@
auth required pam_env.so
+auth required pam_imunify.so check_only
auth sufficient pam_unix.so try_first_pass nullok
+auth required pam_imunify.so
auth required pam_deny.so

View File

@@ -1,5 +1,7 @@
auth required pam_env.so auth required pam_env.so
auth required pam_imunify.so check_only
auth sufficient pam_unix.so try_first_pass nullok auth sufficient pam_unix.so try_first_pass nullok
auth required pam_imunify.so
auth required pam_deny.so auth required pam_deny.so
account required pam_unix.so account required pam_unix.so

View File

@@ -0,0 +1,16 @@
auth required pam_env.so
auth sufficient pam_unix.so try_first_pass nullok
auth required pam_deny.so
account required pam_unix.so
password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=
password sufficient pam_unix.so try_first_pass use_authtok nullok sha512 shadow
password required pam_deny.so
session optional pam_keyinit.so
session required pam_limits.so
-session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session required pam_unix.so

View File

@@ -2,7 +2,9 @@
# This file is auto-generated. # This file is auto-generated.
# User changes will be destroyed the next time authselect is run. # User changes will be destroyed the next time authselect is run.
auth required pam_env.so auth required pam_env.so
auth required pam_imunify.so check_only
auth sufficient pam_unix.so try_first_pass nullok auth sufficient pam_unix.so try_first_pass nullok
auth required pam_imunify.so
auth required pam_deny.so auth required pam_deny.so
account required pam_unix.so account required pam_unix.so

18
pam.d/system-auth.i360bak Normal file
View File

@@ -0,0 +1,18 @@
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authselect is run.
auth required pam_env.so
auth sufficient pam_unix.so try_first_pass nullok
auth required pam_deny.so
account required pam_unix.so
password requisite pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=
password sufficient pam_unix.so try_first_pass use_authtok nullok sha512 shadow
password required pam_deny.so
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session required pam_unix.so

View File

@@ -0,0 +1 @@
root

Binary file not shown.

View File

View File

@@ -0,0 +1,10 @@
# Imunify360 mod_security config patch
<IfModule security2_module>
# The following two settings are needed for realtime scanning of uploaded files
SecRequestBodyAccess On
SecTmpSaveUploadedFiles On
SecResponseBodyLimitAction ProcessPartial
# Warning: custom SecTmpDir/SecUploadDir do not work with cPanel apache jailshell
SecTmpDir /var/imunify360/tmp_modsec
SecUploadDir /var/imunify360/tmp_modsec
</IfModule>

View File

@@ -0,0 +1,10 @@
# Imunify360 mod_security config patch
# The following two settings are needed for realtime scanning of uploaded files
SecRequestBodyAccess On
SecTmpSaveUploadedFiles On
SecResponseBodyLimitAction ProcessPartial
# Warning: custom SecTmpDir/SecUploadDir do not work with cPanel apache jailshell
SecTmpDir /var/imunify360/tmp_modsec
SecUploadDir /var/imunify360/tmp_modsec
# used as work-around for DEF-14411
SecUploadKeepFiles On

View File

@@ -81,7 +81,7 @@ KERNELCARE:
LOGGER: LOGGER:
backup_count: 5 backup_count: 5
max_log_file_size: 62914560 max_log_file_size: 62914560
syscall_monitor: false syscall_monitor: true
MALWARE_CLEANUP: MALWARE_CLEANUP:
keep_original_files_days: 14 keep_original_files_days: 14
trim_file_instead_of_removal: true trim_file_instead_of_removal: true
@@ -96,7 +96,7 @@ MALWARE_SCANNING:
enable_scan_inotify: true enable_scan_inotify: true
enable_scan_modsec: true enable_scan_modsec: true
enable_scan_pure_ftpd: true enable_scan_pure_ftpd: true
hyperscan: false hyperscan: true
max_cloudscan_size_to_scan: 10485760 max_cloudscan_size_to_scan: 10485760
max_mrs_upload_file: 10485760 max_mrs_upload_file: 10485760
max_signature_size_to_scan: 1048576 max_signature_size_to_scan: 1048576
@@ -158,8 +158,8 @@ PERMISSIONS:
user_override_proactive_defense: false user_override_proactive_defense: false
PROACTIVE_DEFENCE: PROACTIVE_DEFENCE:
blamer: true blamer: true
mode: LOG mode: KILL
php_immunity: false php_immunity: true
RESOURCE_MANAGEMENT: RESOURCE_MANAGEMENT:
cpu_limit: 2 cpu_limit: 2
io_limit: 2 io_limit: 2

View File

@@ -0,0 +1 @@
/etc/sysconfig/imunify360/malware-filters-admin-conf/processed/ignored/pd-combined.txt

View File

@@ -0,0 +1,3 @@
L3Byb2M=
L3N5cw==
L3Vzci9zaGFyZS9jYWdlZnMtc2tlbGV0b24vcHJvYw==

View File

@@ -0,0 +1 @@
\.log(?:[.-]\d)?(?:\.gz)?$|\.ini$|\.socket$|\.sock$|/error_log$|^/usr/share/cagefs-skeleton(?:$|/)|^/tmp/lshttpd/.+?\.sock$|^/tmp/lshttpd/.+?\.rtreport[.0-9]*$|^/usr/local/apache/domlogs(?:$|/)|^/var/log/(?:apache2?|httpd)/domlogs(?:$|/)|^/etc/(?:apache2?|httpd)/logs/domlogs(?:$|/)|^/var/ossec(?:$|/)|^/(home[1-9]?|var/www|var/imunify360/tmp)/\.restore-infected/.*(?:$|/)|/template_\w{32}.css$|/cache/object/\w{1,10}/\w{1,10}/\w{1,10}/\w{32}\.php$|/wp-content/cache/object/\w{1,5}/\w{1,5}/\w{32}\.php$|/system/cache/templates_c/\w{1,40}\.php$|/assets/cache/rss/\w{1,60}$|/cache/minify/minify_\w{32}$|/cache/page/\w{32}\.php$|/cache/wp-cache-\d{32}\.php$|/cache/page/\w{32}\.php_expire$|/cache/page/\w{32}-cache-page-\w{32}\.php$|\w{32}-cache-com_content-\w{32}\.php$|\w{32}-cache-mod_custom-\w{32}\.php$|\w{32}-cache-mod_templates-\w{32}\.php$|\w{32}-cache-_system-\w{32}\.php$|/autoptimize/js/autoptimize_\w{32}\.js$|/files/templates_c/.{1,150}\.html\.php$|/uploads/javascript_global/.{1,150}\.js$|сore/cache/resource/web/resources/\d+\.cache\.php$|/assets/cache/docid_\d+_\w{32}\.pageCache\.php$|/t3-assets/dev/t3/.{1,150}-cache-\w{1,20}-.{1,150}\.php$|/t3-assets/js/js-\w{1,30}\.js$|/temp/cache/SC/.{1,100}/\.cache\..{1,100}\.php$|/tmp/sess\_\w{32}$|/assets/cache/docid\_.{1,100}\.pageCache\.php$|/stat/usage\_\w{1,100}\.html$|/stat/usage_\d+\.html$|/stat/site\_\w{1,100}\.html$|/gallery/item/list/\w{1,100}\.cache\.php$|/core/cache/registry/.{1,100}/ext-.{1,100}\.php$|/core/cache/resource/shk\_/\w{1,50}\.cache\.php$|/cache/\w{1,40}/\w+-cache-\w+-\w{32,40}\.php$|/hyper-cache/[^/]{1,50}/[^/]{1,50}/[^/]{1,50}/index\.html$|/application/logs/\d+/\d+/\d+\.php$|/session/sess_\w{32}$|/litespeed/(?:[uc]?css|js)/(?:\d/)?[0-9a-f]{3,32}\.(?:css|js)(?:\.tmp)?$|/cache/(?:db/)?(?:\d+/)*options/[0-9a-f]{3}/[0-9a-f]{3}/[0-9a-f]{32}\.php$|/cache/wp-rocket/.+\.html_(?:gzip|temp|gzip_temp)$|/cache(?:-off)?/autoptimize/(?:\d/)?(?:js/|css/)?autoptimize_\w+\.(?:js|css|img|php)$|/(?:et-cache/|cache/et/)(?:[0-9a-f]+|notfound)/et-.+\.css$|/plugins/elementor/assets/(?:css|js|lib|[^/]*shapes|svg-paths|images)/.+\.(?:css|js|svg|gif|png)$|/cache/(?:prod|dev)/smarty/compile/.{1,150}\.tpl(?:\.cache)?\.php$|/smarty/(?:compile|cache)/.*[0-9a-f]{2}/[0-9a-f]{2}/[0-9a-f]{2}/wrt[0-9a-f]{14}_\d{8}$|/cache/(?:pro[d_]|dev)/(?:annotations|doctrine)/\w{2}/\w{16,150}\.doctrinecache\.data$|/sessions/sess_[0-9a-f]{32}$|/cache/cachestore_file/default_application/\w+/.+\.(?:cache|temp)$|/cache/models/(?:model/)?\w+_cake_model_\w+$|/var/(?:page_)?cache/mage-tags/mage---\w+$|/wflogs/config\.tmp\.\w{6}$|/api/user_(?:message|logs)\.db$|/#sql[\w.-]+\.M[YA][DI]$|^/(?:dev/shm(?:/lsws)?|(?:var/)?tmp/lshttpd/swap)/[0-9a-f]/[0-9a-f]/[0-9a-f]{30}\.ls[bz]l?$|/media/catalog/product/cache/.+\.(?:jpe?g|gif|png)$|/cache/zend_cache---[\w-]+$|/images/\d{4}/\d{2}/\d{2}/[^/]+\.(?:jpe?g|gif)$|^/dev/shm/|/cache/cache(?:\.\w+)+\.\d{10}$|/\.wp-toolkit/tmp\.\w{10}$|/media/videos/tmb/[0-9a-f]+/[^/]+\.jpg$

View File

@@ -0,0 +1 @@
\.log(?:[.-]\d)?(?:\.gz)?$|\.ini$|\.socket$|\.sock$|/error_log$|^/usr/share/cagefs-skeleton(?:$|/)|^/tmp/lshttpd/.+?\.sock$|^/tmp/lshttpd/.+?\.rtreport[.0-9]*$|^/usr/local/apache/domlogs(?:$|/)|^/var/log/(?:apache2?|httpd)/domlogs(?:$|/)|^/etc/(?:apache2?|httpd)/logs/domlogs(?:$|/)|^/var/ossec(?:$|/)|^/(home[1-9]?|var/www|var/imunify360/tmp)/\.restore-infected/.*(?:$|/)|/template_\w{32}.css$|/cache/object/\w{1,10}/\w{1,10}/\w{1,10}/\w{32}\.php$|/wp-content/cache/object/\w{1,5}/\w{1,5}/\w{32}\.php$|/system/cache/templates_c/\w{1,40}\.php$|/assets/cache/rss/\w{1,60}$|/cache/minify/minify_\w{32}$|/cache/page/\w{32}\.php$|/cache/wp-cache-\d{32}\.php$|/cache/page/\w{32}\.php_expire$|/cache/page/\w{32}-cache-page-\w{32}\.php$|\w{32}-cache-com_content-\w{32}\.php$|\w{32}-cache-mod_custom-\w{32}\.php$|\w{32}-cache-mod_templates-\w{32}\.php$|\w{32}-cache-_system-\w{32}\.php$|/autoptimize/js/autoptimize_\w{32}\.js$|/files/templates_c/.{1,150}\.html\.php$|/uploads/javascript_global/.{1,150}\.js$|сore/cache/resource/web/resources/\d+\.cache\.php$|/assets/cache/docid_\d+_\w{32}\.pageCache\.php$|/t3-assets/dev/t3/.{1,150}-cache-\w{1,20}-.{1,150}\.php$|/t3-assets/js/js-\w{1,30}\.js$|/temp/cache/SC/.{1,100}/\.cache\..{1,100}\.php$|/tmp/sess\_\w{32}$|/assets/cache/docid\_.{1,100}\.pageCache\.php$|/stat/usage\_\w{1,100}\.html$|/stat/usage_\d+\.html$|/stat/site\_\w{1,100}\.html$|/gallery/item/list/\w{1,100}\.cache\.php$|/core/cache/registry/.{1,100}/ext-.{1,100}\.php$|/core/cache/resource/shk\_/\w{1,50}\.cache\.php$|/cache/\w{1,40}/\w+-cache-\w+-\w{32,40}\.php$|/hyper-cache/[^/]{1,50}/[^/]{1,50}/[^/]{1,50}/index\.html$|/application/logs/\d+/\d+/\d+\.php$|/session/sess_\w{32}$|/litespeed/(?:[uc]?css|js)/(?:\d/)?[0-9a-f]{3,32}\.(?:css|js)(?:\.tmp)?$|/cache/(?:db/)?(?:\d+/)*options/[0-9a-f]{3}/[0-9a-f]{3}/[0-9a-f]{32}\.php$|/cache/wp-rocket/.+\.html_(?:gzip|temp|gzip_temp)$|/cache(?:-off)?/autoptimize/(?:\d/)?(?:js/|css/)?autoptimize_\w+\.(?:js|css|img|php)$|/(?:et-cache/|cache/et/)(?:[0-9a-f]+|notfound)/et-.+\.css$|/plugins/elementor/assets/(?:css|js|lib|[^/]*shapes|svg-paths|images)/.+\.(?:css|js|svg|gif|png)$|/cache/(?:prod|dev)/smarty/compile/.{1,150}\.tpl(?:\.cache)?\.php$|/smarty/(?:compile|cache)/.*[0-9a-f]{2}/[0-9a-f]{2}/[0-9a-f]{2}/wrt[0-9a-f]{14}_\d{8}$|/cache/(?:pro[d_]|dev)/(?:annotations|doctrine)/\w{2}/\w{16,150}\.doctrinecache\.data$|/sessions/sess_[0-9a-f]{32}$|/cache/cachestore_file/default_application/\w+/.+\.(?:cache|temp)$|/cache/models/(?:model/)?\w+_cake_model_\w+$|/var/(?:page_)?cache/mage-tags/mage---\w+$|/wflogs/config\.tmp\.\w{6}$|/api/user_(?:message|logs)\.db$|/#sql[\w.-]+\.M[YA][DI]$|^/(?:dev/shm(?:/lsws)?|(?:var/)?tmp/lshttpd/swap)/[0-9a-f]/[0-9a-f]/[0-9a-f]{30}\.ls[bz]l?$|/media/catalog/product/cache/.+\.(?:jpe?g|gif|png)$|/cache/zend_cache---[\w-]+$|/images/\d{4}/\d{2}/\d{2}/[^/]+\.(?:jpe?g|gif)$|^/dev/shm/|/cache/cache(?:\.\w+)+\.\d{10}$|/\.wp-toolkit/tmp\.\w{10}$|/media/videos/tmb/[0-9a-f]+/[^/]+\.jpg$

View File

@@ -0,0 +1,5 @@
/tmp
/run/shm
/dev/shm
/dev/mqueue
/var/tmp

View File

@@ -0,0 +1 @@
generic panel