/etc
NameSizeModeActions
alternatives/-0755rm
apache2/-0755rm
audit/-0750rm
authselect/-0755rm
bash_completion.d/-0755rm
binfmt.d/-0755rm
bluetooth/-0755rm
cagefs/-0755rm
chkconfig.d/-0755rm
chkserv.d/-0755rm
cifs-utils/-0755rm
cl.selector/-0755rm
cloud/-0755rm
cpanel/-0751rm
cron.d/-0755rm
cron.daily/-0755rm
cron.hourly/-0755rm
cron.monthly/-0755rm
cron.weekly/-0755rm
crypto-policies/-0755rm
csf/-0600rm
dbus-1/-0755rm
default/-0755rm
depmod.d/-0755rm
dhcp/-0750rm
dnf/-0755rm
dovecot/-0755rm
dpkg/-0755rm
dracut.conf.d/-0755rm
environment-modules/-0755rm
exports.d/-0755rm
firewalld/-0750rm
fonts/-0755rm
fwupd/-0755rm
gcrypt/-0755rm
gnupg/-0755rm
groff/-0755rm
grub.d/-0700rm
gss/-0755rm
gssproxy/-0755rm
ImageMagick-6/-0755rm
imunify-agent-proxy/-0700rm
imunify360/-0755rm
init.d/-0755rm
iproute2/-0755rm
kdump/-0755rm
kernel/-0755rm
keyutils/-0755rm
krb5.conf.d/-0755rm
ld.so.conf.d/-0755rm
libblockdev/-0755rm
libibverbs.d/-0755rm
libnl/-0755rm
libpaper.d/-0755rm
libreport/-0755rm
libssh/-0755rm
logrotate.d/-0755rm
mail/-0755rm
microcode_ctl/-0755rm
modprobe.d/-0755rm
modulefiles/-0755rm
modules-load.d/-0755rm
motd.d/-0755rm
my.cnf.d/-0755rm
named/-0750rm
needrestart/-0755rm
NetworkManager/-0755rm
nftables/-0700rm
openldap/-0755rm
opt/-0755rm
pam.d/-0755rm
pdns/-0755rm
pkcs11/-0755rm
pki/-0755rm
pm/-0755rm
polkit-1/-0755rm
popt.d/-0755rm
profile.d/-0755rm
proftpd/-0751rm
pure-ftpd/-0755rm
qemu-ga/-0755rm
qemu-kvm/-0755rm
rc.d/-0755rm
rc0.d/-0755rm
rc1.d/-0755rm
rc2.d/-0755rm
rc3.d/-0755rm
rc4.d/-0755rm
rc5.d/-0755rm
rc6.d/-0755rm
request-key.d/-0755rm
rhsm/-0755rm
rpm/-0755rm
rsyslog.d/-0755rm
rwtab.d/-0755rm
sasl2/-0755rm
scl/-0755rm
security/-0755rm
selinux/-0755rm
skel/-0755rm
smartmontools/-0755rm
ssh/-0755rm
ssl/-0755rm
sssd/-0700rm
stunnel/-0755rm
sudoers.d/-0750rm
sw-engine/-0755rm
sysconfig/-0755rm
sysctl.d/-0755rm
systemd/-0755rm
terminfo/-0755rm
tmpfiles.d/-0755rm
tuned/-0755rm
udev/-0755rm
udisks2/-0755rm
unbound/-0755rm
valiases/-0751rm
vdomainaliases/-0751rm
vfilters/-0751rm
X11/-0755rm
xdg/-0755rm
xinetd.d/-0755rm
yum/-0755rm
yum.repos.d/-0755rm
.pwd.lock00600editdlrm
.updated2080644editdlrm
.whostmgrft00644editdlrm
adjtime160644editdlrm
agent360.ini8170600editdlrm
aliases15290644editdlrm
almalinux-release420644editdlrm
almalinux-release-upstream520644editdlrm
anacrontab5410644editdlrm
antivirus.exim106340644editdlrm
at.deny10644editdlrm
backupmxhosts00640editdlrm
bashrc37180644editdlrm
bindresvport.blacklist5350644editdlrm
blocked_incoming_email_countries00640editdlrm
blocked_incoming_email_country_ips00640editdlrm
blocked_incoming_email_domains00640editdlrm
centos-release420644editdlrm
chrony.conf10880644editdlrm
chrony.keys5400640editdlrm
cpanel_exim_system_filter121440644editdlrm
cpanel_mail_netblocks150640editdlrm
cpsources.conf.plugins.example28430644editdlrm
cpspamd.conf00644editdlrm
cpupdate.conf1110644editdlrm
cron.deny70644editdlrm
crontab4510644editdlrm
crypttab00600editdlrm
csh.cshrc16290644editdlrm
csh.login10870644editdlrm
dbowners320640editdlrm
demodomains00640editdlrm
demouids00640editdlrm
demousers00640editdlrm
digestshadow00640editdlrm
DIR_COLORS45360644editdlrm
DIR_COLORS.256color52140644editdlrm
DIR_COLORS.lightbgcolor46180644editdlrm
domainips150644editdlrm
domainusers290640editdlrm
domain_remote_mx_ips.cdb25360640editdlrm
dracut.conf1170644editdlrm
email_send_limits12330640editdlrm
environment00644editdlrm
ethertypes13620644editdlrm
exim.conf928560644editdlrm
exim.conf.dist264080644editdlrm
exim.conf.localopts21100644editdlrm
exim.conf.localopts.shadow00600editdlrm
exim.conf.mailman2.dist297290644editdlrm
exim.conf.mailman2.exiscan.dist299040644editdlrm
exim.crt56790660editdlrm
exim.key16790660editdlrm
exim.pl2310644editdlrm
exim.pl.local4989770644editdlrm
eximmailtrap00644editdlrm
eximrejects1630644editdlrm
eximrejects.rpmorig3670644editdlrm
exim_suspended_list7150640editdlrm
exim_trusted_configs240644editdlrm
exports00644editdlrm
favicon.png2260644editdlrm
filesystems660644editdlrm
fstab7210644editdlrm
ftpd-ca.pem00660editdlrm
ftpd-rsa-key.pem16790660editdlrm
ftpd-rsa.pem56790660editdlrm
GREP_COLORS940644editdlrm
greylist_common_mail_providers700220644editdlrm
greylist_trusted_netblocks00640editdlrm
group11480644editdlrm
group-11090644editdlrm
grub2-efi.cfg-0editdlrm
grub2.cfg-0editdlrm
gshadow9510600editdlrm
gshadow-9250000editdlrm
host.conf90644editdlrm
hostname250644editdlrm
hosts2000644editdlrm
idmapd.conf48490644editdlrm
inittab4900644editdlrm
inputrc9420644editdlrm
ipaddrpool00644editdlrm
ips440644editdlrm
issue230644editdlrm
issue.net220644editdlrm
kdump.conf85500644editdlrm
krb5.conf8120644editdlrm
ld.so.cache303110644editdlrm
ld.so.conf280644editdlrm
libaudit.conf1910640editdlrm
libuser.conf23910644editdlrm
localaliases240644editdlrm
localdomains6970640editdlrm
localdomains.rpmnew00644editdlrm
locale.conf170644editdlrm
localtime1270644editdlrm
lock_manager_local.ini8290644editdlrm
login.defs30760644editdlrm
logrotate.conf4380644editdlrm
machine-id330444editdlrm
magic1110644editdlrm
mail.rc19680644editdlrm
mailbox_formats380640editdlrm
mailcap2720644editdlrm
mailhelo270640editdlrm
mailips00640editdlrm
makedumpfile.conf.sample51220644editdlrm
man_db.conf51650644editdlrm
mime.types603520644editdlrm
mke2fs.conf11080644editdlrm
motd00644editdlrm
mtab00444editdlrm
my.cnf4030644editdlrm
named.conf55630644editdlrm
named.conf.cache4120600editdlrm
named.conf.precpanelinstall17230640editdlrm
named.conf.prerebuilddnsconfig39170644editdlrm
named.conf.rebuilddnsconfig39170644editdlrm
named.conf.zonedir.cache570600editdlrm
named.rfc1912.zones10290640editdlrm
named.root.key10700644editdlrm
nanorc94500644editdlrm
neighbor_netblocks150640editdlrm
netconfig7670644editdlrm
networks580644editdlrm
nfs.conf12510644editdlrm
nfsmount.conf36060644editdlrm
nocgiusers00640editdlrm
nscd.conf27290644editdlrm
nsswitch.conf21200644editdlrm
nsswitch.conf.bak21970644editdlrm
nsswitch.conf.save_by_rpm22150644editdlrm
odbc.ini00644editdlrm
odbcinst.ini11250644editdlrm
os-release5850644editdlrm
outgoing_mail_hold_users00640editdlrm
outgoing_mail_suspended_users00640editdlrm
papersize680644editdlrm
passwd28710644editdlrm
passwd-28710644editdlrm
passwd.cache167950600editdlrm
passwd.nouids.cache87800600editdlrm
printcap2330644editdlrm
profile29240644editdlrm
protocols65680644editdlrm
pure-ftpd.conf110650600editdlrm
pure-ftpd.pem73580660editdlrm
rc.local4740644editdlrm
recent_authed_mail_ips290644editdlrm
recent_authed_mail_ips_users1230644editdlrm
recent_recipient_mail_server_ips3410640editdlrm
redhat-release420644editdlrm
relayhosts290644editdlrm
relayhostsusers1230644editdlrm
remotedomains00644editdlrm
request-key.conf17870644editdlrm
resolv.conf790644editdlrm
rpc16340644editdlrm
rsyslog.conf32950644editdlrm
secondarymx00640editdlrm
senderverifybypasshosts00640editdlrm
services6922520644editdlrm
sestatus.conf2160644editdlrm
shadow13230600editdlrm
shadow-13230600editdlrm
shadow.nouids.cache89470600editdlrm
shells1280644editdlrm
skipsmtpcheckhosts00640editdlrm
spammeripblocks00640editdlrm
spammers00644editdlrm
ssldomains00600editdlrm
stats.conf370644editdlrm
subgid00644editdlrm
subuid00644editdlrm
sudo-ldap.conf31810640editdlrm
sudo.conf17860640editdlrm
sudoers43280440editdlrm
sysctl.conf4490644editdlrm
system-release420644editdlrm
system-release-cpe370644editdlrm
tcsd.conf70460640editdlrm
trueuserdomains290640editdlrm
trueuserowners150640editdlrm
trusted-key.key3750644editdlrm
trustedmailhosts00640editdlrm
trusted_mail_users00640editdlrm
userbwlimits370640editdlrm
userdatadomains43400640editdlrm
userdatadomains.json47050640editdlrm
userdomains9410640editdlrm
userips370640editdlrm
userplans320640editdlrm
vconsole.conf280644editdlrm
vimrc19820644editdlrm
virc12040644editdlrm
webspam00644editdlrm
wgetrc49250644editdlrm
wwwacct.conf2890644editdlrm
wwwacct.conf.cache3220644editdlrm
wwwacct.conf.shadow.cache3220600editdlrm
xattr.conf6520644editdlrm
yum.conf2460644editdlrm
Edit: /etc/antivirus.exim (10634B)
# Exim filter ## Version: 0.17 # $Id: system_filter.exim,v 1.11 2001/09/19 11:27:56 nigel Exp $ ## Exim system filter to refuse potentially harmful payloads in ## mail messages ## (c) 2000-2001 Nigel Metheringham ## ## This program is free software; you can redistribute it and/or modify ## it under the terms of the GNU General Public License as published by ## the Free Software Foundation; either version 2 of the License, or ## (at your option) any later version. ## ## This program is distributed in the hope that it will be useful, ## but WITHOUT ANY WARRANTY; without even the implied warranty of ## MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the ## GNU General Public License for more details. ## ## You should have received a copy of the GNU General Public License ## along with this program; if not, write to the Free Software ## Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA ## -A copy of the GNU General Public License is distributed with exim itself ## -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- ## If you haven't worked with exim filters before, read ## the install notes at the end of this file. ## The install notes are not a replacement for the exim documentation ## -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- ## ----------------------------------------------------------------------- # Only run any of this stuff on the first pass through the # filter - this is an optomisation for messages that get # queued and have several delivery attempts # # we express this in reverse so we can just bail out # on inappropriate messages # if not first_delivery then finish endif ## ----------------------------------------------------------------------- # Check for MS buffer overruns as per BUGTRAQ. # http://www.securityfocus.com/frames/?content=/templates/article.html%3Fid%3D61 # This could happen in error messages, hence its placing # here... # We substract the first n characters of the date header # and test if its the same as the date header... which # is a lousy way of checking if the date is longer than # n chars long if ${length_80:$header_date:} is not $header_date: then fail text "This message has been rejected because it has\n\ an overlength date field which can be used\n\ to subvert Microsoft mail programs\n\ The following URL has further information\n\ http://www.securityfocus.com/frames/?content=/templates/article.html%3Fid%3D61" seen finish endif ## ----------------------------------------------------------------------- # These messages are now being sent with a <> envelope sender, but # blocking all error messages that pattern match prevents # bounces getting back.... so we fudge it somewhat and check for known # header signatures. Other bounces are allowed through. if $header_from: contains "@sexyfun.net" then fail text "This message has been rejected since it has\n\ the signature of a known virus in the header." seen finish endif if error_message and $header_from: contains "Mailer-Daemon@" then # looks like a real error message - just ignore it finish endif ## ----------------------------------------------------------------------- # Look for single part MIME messages with suspicious name extensions # Check Content-Type header using quoted filename [content_type_quoted_fn_match] if $header_content-type: matches "(?:file)?name=(\"[^\"]+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc])\")" then fail text "This message has been rejected because it has\n\ potentially executable content $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif # same again using unquoted filename [content_type_unquoted_fn_match] if $header_content-type: matches "(?:file)?name=(\\\\S+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc]))" then fail text "This message has been rejected because it has\n\ potentially executable content $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif ## ----------------------------------------------------------------------- # Attempt to catch embedded VBS attachments # in emails. These were used as the basis for # the ILOVEYOU virus and its variants - many many varients # Quoted filename - [body_quoted_fn_match] if $message_body matches "(?:Content-(?:Type:(?>\\\\s*)[\\\\w-]+/[\\\\w-]+|Disposition:(?>\\\\s*)attachment);(?>\\\\s*)(?:file)?name=|begin(?>\\\\s+)[0-7]{3,4}(?>\\\\s+))(\"[^\"]+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc])\")[\\\\s;]" then fail text "This message has been rejected because it has\n\ a potentially executable attachment $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif # same again using unquoted filename [body_unquoted_fn_match] if $message_body matches "(?:Content-(?:Type:(?>\\\\s*)[\\\\w-]+/[\\\\w-]+|Disposition:(?>\\\\s*)attachment);(?>\\\\s*)(?:file)?name=|begin(?>\\\\s+)[0-7]{3,4}(?>\\\\s+))(\\\\S+\\\\.(?:ad[ep]|ba[st]|chm|cmd|com|cpl|crt|eml|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|pcd|pif|reg|scr|sct|shs|url|vb[se]|ws[fhc]))[\\\\s;]" then fail text "This message has been rejected because it has\n\ a potentially executable attachment $1\n\ This form of attachment has been used by\n\ recent viruses or other malware.\n\ If you meant to send this file then please\n\ package it up as a zip file and resend it." seen finish endif ## ----------------------------------------------------------------------- #### Version history # # 0.01 5 May 2000 # Initial release # 0.02 8 May 2000 # Widened list of content-types accepted, added WSF extension # 0.03 8 May 2000 # Embedded the install notes in for those that don't do manuals # 0.04 9 May 2000 # Check global content-type header. Efficiency mods to REs # 0.05 9 May 2000 # More minor efficiency mods, doc changes # 0.06 20 June 2000 # Added extension handling - thx to Douglas Gray Stephens & Jeff Carnahan # 0.07 19 July 2000 # Latest MS Outhouse bug catching # 0.08 19 July 2000 # Changed trigger length to 80 chars, fixed some spelling # 0.09 29 September 2000 # More extensions... its getting so we should just allow 2 or 3 through # 0.10 18 January 2001 # Removed exclusion for error messages - this is a little nasty # since it has other side effects, hence we do still exclude # on unix like error messages # 0.11 20 March, 2001 # Added CMD extension, tidied docs slightly, added RCS tag # ** Missed changing version number at top of file :-( # 0.12 10 May, 2001 # Added HTA extension # 0.13 22 May, 2001 # Reformatted regexps and code to build them so that they are # shorter than the limits on pre exim 3.20 filters. This will # make them significantly less efficient, but I am getting so # many queries about this that requiring 3.2x appears unsupportable. # 0.14 15 August,2001 # Added .lnk extension - most requested item :-) # Reformatted everything so its now built from a set of short # library files, cutting down on manual duplication. # Changed \w in filename detection to . - dodges locale problems # Explicit application of GPL after queries on license status # 0.15 17 August, 2001 # Changed the . in filename detect to \S (stops it going mad) # 0.16 19 September, 2001 # Pile of new extensions including the eml in current use # 0.17 19 September, 2001 # Syntax fix # #### Install Notes # # Exim filters run the exim filter language - a very primitive # scripting language - in place of a user .forward file, or on # a per system basis (on all messages passing through). # The filtering capability is documented in the main set of manuals # a copy of which can be found on the exim web site # http://www.exim.org/ # # To install, copy the filter file (with appropriate permissions) # to /etc/exim/system_filter.exim and add to your exim config file # [location is installation depedant - typicaly /etc/exim/config ] # in the first section the line:- # message_filter = /etc/exim/system_filter.exim # message_body_visible = 5000 # # You may also want to set the message_filter_user & message_filter_group # options, but they default to the standard exim user and so can # be left untouched. The other message_filter_* options are only # needed if you modify this to do other functions such as deliveries. # The main exim documentation is quite thorough and so I see no need # to expand it here... # # Any message that matches the filter will then be bounced. # If you wish you can change the error message by editing it # in the section above - however be careful you don't break it. # # After install exim should be restarted - a kill -HUP to the # daemon will do this. # #### LIMITATIONS # # This filter tries to parse MIME with a regexp... that doesn't # work too well. It will also only see the amount of the body # specified in message_body_visible # #### BASIS # # The regexp that is used to pickup MIME/uuencoded body parts with # quoted filenames is replicated below (in perl format). # You need to remember that exim converts newlines to spaces in # the message_body variable. # # (?:Content- # start of content header # (?:Type: (?>\s*) # rest of c/t header # [\w-]+/[\w-]+ # content-type (any) # |Disposition: (?>\s*) # content-disposition hdr # attachment) # content-disposition # ;(?>\s*) # ; space or newline # (?:file)?name= # filename=/name= # |begin (?>\s+) [0-7]{3,4} (?>\s+)) # begin octal-mode # (\"[^\"]+\. # quoted filename. # (?:ad[ep] # list of extns # |ba[st] # |chm # |cmd # |com # |cpl # |crt # |eml # |exe # |hlp # |hta # |in[fs] # |isp # |jse? # |lnk # |md[be] # |ms[cipt] # |pcd # |pif # |reg # |scr # |sct # |shs # |url # |vb[se] # |ws[fhc]) # \" # end quote # ) # end of filename capture # [\s;] # trailing ;/space/newline # # ### [End]