/etc
NameSizeModeActions
alsa/-0755rm
alternatives/-0755rm
apache2/-0755rm
audit/-0750rm
authselect/-0755rm
bash_completion.d/-0755rm
binfmt.d/-0755rm
bluetooth/-0555rm
cagefs/-0755rm
chkconfig.d/-0755rm
chkserv.d/-0755rm
cifs-utils/-0755rm
cl.selector/-0755rm
cpanel/-0751rm
cron.d/-0755rm
cron.daily/-0755rm
cron.hourly/-0755rm
cron.monthly/-0755rm
cron.weekly/-0755rm
crypto-policies/-0755rm
dbus-1/-0755rm
dconf/-0755rm
debuginfod/-0755rm
default/-0755rm
depmod.d/-0755rm
dhcp/-0755rm
dnf/-0755rm
dovecot/-0755rm
dpkg/-0755rm
dracut.conf.d/-0755rm
egl/-0755rm
environment-modules/-0755rm
exports.d/-0755rm
firewalld/-0750rm
flatpak/-0755rm
fonts/-0755rm
fwupd/-0755rm
gcrypt/-0755rm
geoclue/-0755rm
glvnd/-0755rm
gnupg/-0755rm
groff/-0755rm
grub.d/-0700rm
gss/-0755rm
gssproxy/-0755rm
ImageMagick-6/-0755rm
imunify-agent-proxy/-0700rm
imunify360/-0755rm
init.d/-0755rm
iproute2/-0755rm
issue.d/-0755rm
kdump/-0755rm
kernel/-0755rm
keys/-0755rm
keyutils/-0755rm
krb5.conf.d/-0755rm
ld.so.conf.d/-0755rm
libibverbs.d/-0755rm
libnl/-0755rm
libpaper.d/-0755rm
libreport/-0755rm
libssh/-0755rm
logrotate.d/-0755rm
lvm/-0755rm
lynis/-0755rm
mail/-0755rm
microcode_ctl/-0755rm
modprobe.d/-0755rm
modulefiles/-0755rm
modules-load.d/-0755rm
motd.d/-0755rm
my.cnf.d/-0755rm
named/-0750rm
needrestart/-0755rm
NetworkManager/-0755rm
nftables/-0700rm
nginx/-0755rm
openldap/-0755rm
opt/-0755rm
ostree/-0755rm
pam.d/-0755rm
pcp/-0755rm
pdns/-0755rm
pkcs11/-0755rm
pkgconfig/-0755rm
pki/-0755rm
pm/-0755rm
polkit-1/-0755rm
popt.d/-0755rm
profile.d/-0755rm
proftpd/-0751rm
pulse/-0755rm
pure-ftpd/-0755rm
rc.d/-0755rm
rc0.d/-0755rm
rc1.d/-0755rm
rc2.d/-0755rm
rc3.d/-0755rm
rc4.d/-0755rm
rc5.d/-0755rm
rc6.d/-0755rm
request-key.d/-0755rm
rpm/-0755rm
rsyslog.d/-0755rm
rwtab.d/-0755rm
samba/-0755rm
sasl2/-0755rm
scl/-0755rm
security/-0755rm
selinux/-0755rm
sgml/-0755rm
skel/-0755rm
smartmontools/-0755rm
ssh/-0755rm
ssl/-0755rm
sssd/-0700rm
statetab.d/-0755rm
sudoers.d/-0750rm
sw-engine/-0755rm
sysconfig/-0755rm
sysctl.d/-0755rm
systemd/-0755rm
terminfo/-0755rm
tmpfiles.d/-0755rm
tpm2-tss/-0755rm
udev/-0755rm
UPower/-0755rm
valiases/-0751rm
vdomainaliases/-0751rm
vfilters/-0751rm
vmware-tools/-0755rm
vulkan/-0755rm
wireplumber/-0755rm
X11/-0755rm
xdg/-0755rm
xml/-0755rm
yum/-0755rm
yum.repos.d/-0755rm
.pwd.lock00600editdlrm
.updated2080644editdlrm
.whostmgrft00644editdlrm
adjtime160644editdlrm
agent360-token.ini720640editdlrm
agent360.ini9620640editdlrm
agent360.ini.rpmnew8170600editdlrm
agent360.ini.rpmsave9510640editdlrm
aliases15290644editdlrm
almalinux-release370644editdlrm
anacrontab5410644editdlrm
antivirus.exim106340644editdlrm
asound.conf550644editdlrm
at.deny10644editdlrm
backupmxhosts00640editdlrm
bashrc34590644editdlrm
bindresvport.blacklist5350644editdlrm
blocked_incoming_email_countries00640editdlrm
blocked_incoming_email_country_ips00640editdlrm
blocked_incoming_email_domains00640editdlrm
chrony.conf13740644editdlrm
chrony.keys5400640editdlrm
cpanel_exim_system_filter121440644editdlrm
cpanel_mail_netblocks150640editdlrm
cpbackup-exclude.conf1470644editdlrm
cpsources.conf.plugins.example28430644editdlrm
cpspamd.conf00644editdlrm
cpupdate.conf1110644editdlrm
cron.deny70644editdlrm
crontab4510644editdlrm
crypttab00600editdlrm
csh.cshrc14010644editdlrm
csh.login11120644editdlrm
dbowners7730640editdlrm
demodomains00640editdlrm
demouids00640editdlrm
demousers00640editdlrm
digestshadow00640editdlrm
DIR_COLORS46730644editdlrm
DIR_COLORS.lightbgcolor47550644editdlrm
domainips830644editdlrm
domainusers10040640editdlrm
domain_remote_mx_ips.cdb64060640editdlrm
dracut.conf1170644editdlrm
email_send_limits34970640editdlrm
environment00644editdlrm
ethertypes13620644editdlrm
exim.conf886510644editdlrm
exim.conf.dist264080644editdlrm
exim.conf.localopts20930644editdlrm
exim.conf.localopts.shadow00600editdlrm
exim.conf.mailman2.dist297290644editdlrm
exim.conf.mailman2.exiscan.dist299040644editdlrm
exim.crt56790660editdlrm
exim.key16790660editdlrm
exim.pl2310644editdlrm
exim.pl.local4989770644editdlrm
eximmailtrap00644editdlrm
eximrejects1630644editdlrm
eximrejects.rpmorig3670644editdlrm
exim_suspended_list7150640editdlrm
exim_trusted_configs240644editdlrm
exports00644editdlrm
favicon.png2260644editdlrm
filesystems660644editdlrm
freetds.conf11540644editdlrm
fstab7860644editdlrm
ftpd-ca.pem00660editdlrm
ftpd-rsa-key.pem16790660editdlrm
ftpd-rsa.pem56790660editdlrm
fuse.conf380644editdlrm
GREP_COLORS940644editdlrm
greylist_common_mail_providers697220644editdlrm
greylist_trusted_netblocks00640editdlrm
group18880644editdlrm
group-18730644editdlrm
grub2-efi.cfg-0editdlrm
grub2.cfg-0editdlrm
gshadow15370600editdlrm
gshadow-15260600editdlrm
host.conf90644editdlrm
hostname260644editdlrm
hosts2190644editdlrm
idmapd.conf57990644editdlrm
inittab4900644editdlrm
inputrc9430644editdlrm
ipaddrpool690644editdlrm
ips2540644editdlrm
issue230644editdlrm
issue.net220644editdlrm
kdump.conf90770644editdlrm
krb5.conf8800644editdlrm
ld.so.cache390790644editdlrm
ld.so.conf280644editdlrm
libaudit.conf1910640editdlrm
libuser.conf23910644editdlrm
localaliases480644editdlrm
localdomains15160640editdlrm
localdomains.rpmnew00644editdlrm
locale.conf150644editdlrm
locales.conf3700644editdlrm
localtime35520644editdlrm
lock_manager_local.ini8290644editdlrm
login.defs77790644editdlrm
logrotate.conf4960644editdlrm
machine-id330444editdlrm
magic1110644editdlrm
mailbox_formats6890640editdlrm
mailcap2720644editdlrm
mailhelo280640editdlrm
mailips00640editdlrm
makedumpfile.conf.sample51220644editdlrm
manualmx10640editdlrm
man_db.conf52350644editdlrm
mime.types674540644editdlrm
mke2fs.conf12080644editdlrm
motd00644editdlrm
mtab00444editdlrm
my.cnf14800644editdlrm
named.conf181030644editdlrm
named.conf.cache23400600editdlrm
named.conf.precpanelinstall17390640editdlrm
named.conf.prerebuilddnsconfig35150644editdlrm
named.conf.rebuilddnsconfig35150644editdlrm
named.conf.zonedir.cache570600editdlrm
named.rfc1912.zones10290640editdlrm
named.root.key6860644editdlrm
nanorc103730644editdlrm
neighbor_netblocks460640editdlrm
netconfig7670644editdlrm
networks580644editdlrm
nfs.conf16510644editdlrm
nfsmount.conf36040644editdlrm
nocgiusers110640editdlrm
nscd.conf27290644editdlrm
nsswitch.conf21240644editdlrm
nsswitch.conf.bak21080644editdlrm
odbc.ini00644editdlrm
odbcinst.ini18960644editdlrm
os-release5720644editdlrm
outgoing_mail_hold_users00640editdlrm
outgoing_mail_suspended_users250640editdlrm
papersize680644editdlrm
passwd55640644editdlrm
passwd-55210644editdlrm
passwd.cache314190600editdlrm
passwd.nouids.cache161970600editdlrm
pcp.conf73380644editdlrm
pool.conf2190644editdlrm
printcap2330644editdlrm
profile27000644editdlrm
protocols65680644editdlrm
pure-ftpd.conf111080600editdlrm
pure-ftpd.pem73580660editdlrm
rc.local4740644editdlrm
recent_authed_mail_ips290644editdlrm
recent_authed_mail_ips_users2090644editdlrm
recent_recipient_mail_server_ips10510640editdlrm
redhat-release370644editdlrm
relayhosts290644editdlrm
relayhostsusers2090644editdlrm
remotedomains2530644editdlrm
request-key.conf17870644editdlrm
resolv.conf1020644editdlrm
rpc16340644editdlrm
rsyncd.conf4580644editdlrm
rsyslog.conf33000644editdlrm
s-nail.rc96240444editdlrm
secondarymx00640editdlrm
senderverifybypasshosts00640editdlrm
services6922520644editdlrm
sestatus.conf2160644editdlrm
shadow60970600editdlrm
shadow-60970600editdlrm
shadow.nouids.cache197540600editdlrm
shells1280644editdlrm
skipsmtpcheckhosts00640editdlrm
spammeripblocks00640editdlrm
spammers00644editdlrm
ssldomains00600editdlrm
stats.conf370644editdlrm
subgid200644editdlrm
subgid-00644editdlrm
subuid200644editdlrm
subuid-00644editdlrm
sudo-ldap.conf31810640editdlrm
sudo.conf43560640editdlrm
sudoers43280440editdlrm
sysctl.conf4490644editdlrm
system-release370644editdlrm
system-release-cpe370644editdlrm
trueuserdomains10040640editdlrm
trueuserowners6370640editdlrm
trusted-key.key3750644editdlrm
trustedmailhosts00640editdlrm
trusted_mail_users00640editdlrm
userbwlimits7300640editdlrm
userdatadomains123850640editdlrm
userdatadomains.json135480640editdlrm
userdomains26090640editdlrm
userips8520640editdlrm
userplans7800640editdlrm
vconsole.conf280644editdlrm
virc11840644editdlrm
webspam00644editdlrm
wgetrc49250644editdlrm
wwwacct.conf2570644editdlrm
wwwacct.conf.cache3260644editdlrm
wwwacct.conf.shadow860600editdlrm
wwwacct.conf.shadow.cache4360600editdlrm
xattr.conf8170644editdlrm
yum.conf2160644editdlrm
Edit: /etc/antivirus.exim (10634B)
# Exim filter ## Version: 0.17 # $Id: system_filter.exim,v 1.11 2001/09/19 11:27:56 nigel Exp $ ## Exim system filter to refuse potentially harmful payloads in ## mail messages ## (c) 2000-2001 Nigel Metheringham ## ## This program is free software; you can redistribute it and/or modify ## it under the terms of the GNU General Public License as published by ## the Free Software Foundation; either version 2 of the License, or ## (at your option) any later version. ## ## This program is distributed in the hope that it will be useful, ## but WITHOUT ANY WARRANTY; without even the implied warranty of ## MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the ## GNU General Public License for more details. ## ## You should have received a copy of the GNU General Public License ## along with this program; if not, write to the Free Software ## Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA ## -A copy of the GNU General Public License is distributed with exim itself ## -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- ## If you haven't worked with exim filters before, read ## the install notes at the end of this file. ## The install notes are not a replacement for the exim documentation ## -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- ## ----------------------------------------------------------------------- # Only run any of this stuff on the first pass through the # filter - this is an optomisation for messages that get # queued and have several delivery attempts # # we express this in reverse so we can just bail out # on inappropriate messages # if not first_delivery then finish endif ## ----------------------------------------------------------------------- # Check for MS buffer overruns as per BUGTRAQ. # http://www.securityfocus.com/frames/?content=/templates/article.html%3Fid%3D61 # This could happen in error messages, hence its placing # here... # We substract the first n characters of the date header # and test if its the same as the date header... which # is a lousy way of checking if the date is longer than # n chars long if ${length_80:$header_date:} is not $header_date: then fail text "This message has been rejected because it has\n\ an overlength date field which can be used\n\ to subvert Microsoft mail programs\n\ The following URL has further information\n\ http://www.securityfocus.com/frames/?content=/templates/article.html%3Fid%3D61" seen finish endif ## ----------------------------------------------------------------------- # These messages are now being sent with a <> envelope sender, but # blocking all error messages that pattern match prevents # bounces getting back.... so we fudge it somewhat and check for known # header signatures. Other bounces are allowed through. if $header_from: contains "@sexyfun.net" then fail text "This message has been rejected since it has\n\ the signature of a known virus in the header." seen finish endif if error_message and $header_from: contains "Mailer-Daemon@" then # looks like a real error message - just ignore it finish endif ## ----------------------------------------------------------------------- # Look for single part MIME messages with suspicious name extensions # Check Content-Type header using quoted filename [content_type_quoted_fn_match] if $header_content-type: matches "(?:file)?name=(\"[^\"]+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc])\")" then fail text "This message has been rejected because it has\n\ potentially executable content $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif # same again using unquoted filename [content_type_unquoted_fn_match] if $header_content-type: matches "(?:file)?name=(\\\\S+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc]))" then fail text "This message has been rejected because it has\n\ potentially executable content $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif ## ----------------------------------------------------------------------- # Attempt to catch embedded VBS attachments # in emails. These were used as the basis for # the ILOVEYOU virus and its variants - many many varients # Quoted filename - [body_quoted_fn_match] if $message_body matches "(?:Content-(?:Type:(?>\\\\s*)[\\\\w-]+/[\\\\w-]+|Disposition:(?>\\\\s*)attachment);(?>\\\\s*)(?:file)?name=|begin(?>\\\\s+)[0-7]{3,4}(?>\\\\s+))(\"[^\"]+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc])\")[\\\\s;]" then fail text "This message has been rejected because it has\n\ a potentially executable attachment $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif # same again using unquoted filename [body_unquoted_fn_match] if $message_body matches "(?:Content-(?:Type:(?>\\\\s*)[\\\\w-]+/[\\\\w-]+|Disposition:(?>\\\\s*)attachment);(?>\\\\s*)(?:file)?name=|begin(?>\\\\s+)[0-7]{3,4}(?>\\\\s+))(\\\\S+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc]))[\\\\s;]" then fail text "This message has been rejected because it has\n\ a potentially executable attachment $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif ## ----------------------------------------------------------------------- #### Version history # # 0.01 5 May 2000 # Initial release # 0.02 8 May 2000 # Widened list of content-types accepted, added WSF extension # 0.03 8 May 2000 # Embedded the install notes in for those that don't do manuals # 0.04 9 May 2000 # Check global content-type header. Efficiency mods to REs # 0.05 9 May 2000 # More minor efficiency mods, doc changes # 0.06 20 June 2000 # Added extension handling - thx to Douglas Gray Stephens & Jeff Carnahan # 0.07 19 July 2000 # Latest MS Outhouse bug catching # 0.08 19 July 2000 # Changed trigger length to 80 chars, fixed some spelling # 0.09 29 September 2000 # More extensions... its getting so we should just allow 2 or 3 through # 0.10 18 January 2001 # Removed exclusion for error messages - this is a little nasty # since it has other side effects, hence we do still exclude # on unix like error messages # 0.11 20 March, 2001 # Added CMD extension, tidied docs slightly, added RCS tag # ** Missed changing version number at top of file :-( # 0.12 10 May, 2001 # Added HTA extension # 0.13 22 May, 2001 # Reformatted regexps and code to build them so that they are # shorter than the limits on pre exim 3.20 filters. This will # make them significantly less efficient, but I am getting so # many queries about this that requiring 3.2x appears unsupportable. # 0.14 15 August,2001 # Added .lnk extension - most requested item :-) # Reformatted everything so its now built from a set of short # library files, cutting down on manual duplication. # Changed \w in filename detection to . - dodges locale problems # Explicit application of GPL after queries on license status # 0.15 17 August, 2001 # Changed the . in filename detect to \S (stops it going mad) # 0.16 19 September, 2001 # Pile of new extensions including the eml in current use # 0.17 19 September, 2001 # Syntax fix # #### Install Notes # # Exim filters run the exim filter language - a very primitive # scripting language - in place of a user .forward file, or on # a per system basis (on all messages passing through). # The filtering capability is documented in the main set of manuals # a copy of which can be found on the exim web site # http://www.exim.org/ # # To install, copy the filter file (with appropriate permissions) # to /etc/exim/system_filter.exim and add to your exim config file # [location is installation depedant - typicaly /etc/exim/config ] # in the first section the line:- # message_filter = /etc/exim/system_filter.exim # message_body_visible = 5000 # # You may also want to set the message_filter_user & message_filter_group # options, but they default to the standard exim user and so can # be left untouched. The other message_filter_* options are only # needed if you modify this to do other functions such as deliveries. # The main exim documentation is quite thorough and so I see no need # to expand it here... # # Any message that matches the filter will then be bounced. # If you wish you can change the error message by editing it # in the section above - however be careful you don't break it. # # After install exim should be restarted - a kill -HUP to the # daemon will do this. # #### LIMITATIONS # # This filter tries to parse MIME with a regexp... that doesn't # work too well. It will also only see the amount of the body # specified in message_body_visible # #### BASIS # # The regexp that is used to pickup MIME/uuencoded body parts with # quoted filenames is replicated below (in perl format). # You need to remember that exim converts newlines to spaces in # the message_body variable. # # (?:Content- # start of content header # (?:Type: (?>\s*) # rest of c/t header # [\w-]+/[\w-]+ # content-type (any) # |Disposition: (?>\s*) # content-disposition hdr # attachment) # content-disposition # ;(?>\s*) # ; space or newline # (?:file)?name= # filename=/name= # |begin (?>\s+) [0-7]{3,4} (?>\s+)) # begin octal-mode # (\"[^\"]+\. # quoted filename. # (?:ad[ep] # list of extns # |ba[st] # |chm # |cmd # |com # |cpl # |crt # |eml # |exe # |hlp # |hta # |in[fs] # |isp # |jse? # |lnk # |md[be] # |ms[cipt] # |pcd # |pif # |reg # |scr # |sct # |shs # |url # |vb[se] # |ws[fhc]) # \" # end quote # ) # end of filename capture # [\s;] # trailing ;/space/newline # # ### [End]