Chirpy

Chirpy

New cxs v2.89

Changes: – Improvements to –decode ([D]) – Repurposed –options [u] to specifically highlight scripts only within directories deemed suspicious, rather than general directories such as /image/ or /upload(s)/. This should make the option more useful and help avoid false-positives –…

New csf v6.06

Changes: – Prevent csf/lfd from failing to run if a non-critical configuration file does not exist – In webmin, force table stylesheet to override webmin css. Requires webmin module reinstall on existing installations

New csf v6.05

Changes: – Improvements to minimal perl module detection on new installs – Bugfix for default lfd.pl perl shebang

New csf v6.04

Changes: – Implement slurp routine for configuration files to cater for incorrect linefeeds – Ignore leading and trailing spaces from lines in configuration files – Fixed Include statements in csf.ignore not implemented in lfd – Additional debug logging for RT_*_LIMIT…

New cxs v2.88

Changes: – Include gzdecode() detection for PHP scripts – Switched from using LWP to HTTP::Tiny to reduce memory footprint and reliance on the LWP perl module. The HTTP::Tiny module is included in the distribution, so no further action is necessary…

New csf v6.03

Changes: – Switched from using LWP to HTTP::Tiny to reduce memory footprint and reliance on the LWP perl module. The HTTP::Tiny module is included in the distribution, so no further action is necessary – Modified lfd perl module loading to…

New csf v6.02

Changes: – Modify MESSENGER HTML header to return code 403 instead of 200 – Modify UI daemon to fallback to IPv4 if IPV6 setting is not enabled – Added new options LF_SYMLINK and LF_SYMLINK_PERM. This feature enables detection of repeated…

New cxs v2.87

Changes: – Improvements to the main decoder regex – Reverted to using temporary files during PHP file decoding due to a major bug in PHP v5.4.* which produces “Ran out of opcode space!” in interactive mode – Exploit regex definitions…