May 14, 2025

How to Find Malicious Script in File (Linux Command)

 grep -r -i "thailand" /var/www/html

 grep -r -i "gacor" /var/www/html

grep -r -i --exclude-dir=mysql --exclude-dir=db "thailand" /var/www

find /var -type f -perm 0777

grep "?" /var/log/nginx/access.log

grep -Ei "cmd=|exec=|bash|sh" /var/log/nginx/access.log

awk '{print $1}' /var/log/apache2/access.log | sort | uniq -c | sort -nr


-----------------
Configurasi Apache untuk mengetahui IP yang mengakses ke server yang menggunakan Reverse Proxy

<IfModule mod_remoteip.c>
    RemoteIPHeader X-Forwarded-For
    RemoteIPTrustedProxy 127.0.0.1
</IfModule>

"ganti 127.0.0.1 dengan alamat reverse proxy"
----------------------------

find /var -type f -perm 0777