📁
SKYSHELL MANAGER
PHP v8.0.30
Create
Create
Path:
root
/
home
/
aljabrcp
/
public_html
/
Name
Size
Perm
Actions
📁
.render-cache
-
0755
🗑️
🏷️
🔒
📁
.tmb
-
0777
🗑️
🏷️
🔒
📁
.well-known
-
0755
🗑️
🏷️
🔒
📁
e4b5c3
-
0755
🗑️
🏷️
🔒
📁
well-known
-
0755
🗑️
🏷️
🔒
📁
wp-admin
-
0755
🗑️
🏷️
🔒
📁
wp-content
-
0755
🗑️
🏷️
🔒
📁
wp-includes
-
0755
🗑️
🏷️
🔒
📄
.072335799904244.php
0.73 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.303133550574645.php
0.73 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.771565434277360.php
0.72 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.ftpquota
0.02 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.htaccess
0.06 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.htaccess_old
2.38 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.maintenance
0.03 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
.render-orig.php
0.4 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
admin.php
1073.33 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ajyycson.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
bjspsdnw.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
btxouxnz.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
byobdpit.php
161.75 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
dot.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
dtypulkn.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
error_log
1.77 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
fdkvhqgp.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
features.php
9.84 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
fiouvmwk.php
18.51 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
gkliwelb.php
19.47 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
hhxpypnm.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ichqcdtz.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
iggrnuqs.php
1073.33 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ijigqafs.php
215.7 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ilkifkhe.php
18.48 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
index.php
0.08 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
japeqpqk.php
18.55 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
kxkjgars.php
14.76 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
legcmbtx.php
161.75 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
license.txt
19.44 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
lufix.php
53.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
mdlyonrh.php
161.75 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
memkgrwi.php
18.55 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
min.php
6.83 KB
0444
🗑️
🏷️
⬇️
✏️
🔒
📄
mlqeheok.php
35.6 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
mmkegijm.php
18.5 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
mqbfmtzr.php
14.76 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
nkuxvifp.php
18.56 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ocngdtip.php
18.55 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ops.php
31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
options.php
1.29 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
php.ini
0.1 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
pjqgidra.php
19.54 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
qpggioxw.php
14.76 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
readme.html
7.23 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
robots.txt
0.35 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
rpudqgij.php
15.4 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
tvuydrna.php
18.36 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
uymbqzzs.php
215.7 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
vxbezeuh.php
15.4 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
vxeskmxs.php
19.54 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-activate.php
7.2 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-blog-header.php
0.34 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-comments-post.php
2.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config-sample.php
3.26 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.bak
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.before-debug
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.before-debug.2026-06-26-151429
3.31 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.before-debug.2026-06-26-151542
3.26 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.broken.2026-06-26-152109
3.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.broken.2026-06-26-152153
3.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-config.php.broken.2026-06-26-152623
3.27 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-cron.php
5.49 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-links-opml.php
2.43 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-load.php
3.84 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-mail.php
8.52 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-server.php
162 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-settings.php
31.88 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-signup.php
33.81 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wp-trackback.php
5.09 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
wpxml.php
12.37 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
xmlrpc.php
3.13 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
xyn.php
5.65 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
ydrqjvyq.php
18.51 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
📄
zwmxmsbj.php
215.7 KB
0777
🗑️
🏷️
⬇️
✏️
🔒
Edit: eventviewer
#!/usr/bin/python3 # # This utility displays the most frequent events generated by EDR, grouped by # process path, file path and other standard fields. It supports filter patterns # for excluding events from statistics and uses the standard 'less' utility for # search and pagination. # # These statistics can be used to create GravityZone OnAccess exclusions for # processes and file paths or folders. # # This utility parses the current format of the bdsecd-ctc.log files, which is # not documented and may change in new releases. Therefore, the parsing code # from this script should not be reused in other utilities. # # Copyright (c) 2025 Bitdefender. All rights reserved. import sys, os, subprocess, shutil, termios, tty, tempfile, traceback, glob, time from dataclasses import dataclass, field from shutil import which if sys.version_info < (3,6,0): sys.exit("This utility needs Python version 3.6 or newer to run.") for p in ["tmux", "less"]: if not which(p): sys.exit(f"The {p} command is needed but was not found.") tui = sys.argv[1:2] == ["tui"] logFiles = sys.argv[2 if tui else 1:] if logFiles == []: if os.path.exists("bdsecd-ctc.log"): logFiles = glob.glob("bdsecd-ctc_*.log") + \ ["bdsecd-ctc.log"] elif os.path.exists(os.path.dirname(sys.argv[0]) + "/../var/log/bdsecd-ctc.log"): logFiles = glob.glob(os.path.dirname(sys.argv[0]) + "/../var/log/bdsecd-ctc_*.log") + \ [os.path.dirname(sys.argv[0]) + "/../var/log/bdsecd-ctc.log"] elif os.path.exists("/opt/bitdefender-security-tools/var/log/bdsecd-ctc.log"): logFiles = glob.glob("/opt/bitdefender-security-tools/var/log/bdsecd-ctc_*.log") + \ ["/opt/bitdefender-security-tools/var/log/bdsecd-ctc.log"] else: sys.exit("syntax: eventviewer [bdsecd-ctc.log...]") editor = os.getenv("VISUAL", os.getenv("EDITOR", "vi")) pager = os.getenv("PAGER", "less") uiFields = ["event", "proc_path", "parent_proc_path", "argv", "file_path", "pid", "ppid", "uid", "euid", "gid", "func"] quotedFields = set(["proc_path", "parent_proc_path", "file_path", "in_path", "out_path", "sock_path", "argv", "new_path", "path", "kmod_path"]) selectedField = 0 class Filter: def __init__(self, field, regex): self.field = field self.regex = regex filters = [] processing = None needRefresh = False cols, rows = shutil.get_terminal_size() if cols < 90: sys.exit("A terminal that is at least 90 columns wide is needed.") def redraw(**kwargs): active = kwargs.get('active', True) b = "\033[30m" # black foreground g = "\033[37m" # grey foreground w = "\033[97m" # white foreground y = "\033[33m" # yellow foreground B = "\033[40m" # black background G = "\033[47m" # grey background Y = "\033[43m" # yellow background e = "\033[K" # erase to EOL if not active: g = y = w = b B = Y = G s = "\033[1;1f" # go to row, col s += f"{g}{B} Enter {b}{G} Group " s += f"{g}{B} F {b}{G} Filters " if needRefresh: s += f"{g}{B} A {y}{G} Apply " else: s += f"{g}{B} A {b}{G} Apply " # s += f"{g}{B} D {b}{G} TimeDate " # s += f"{g}{B} P {b}{G} PID TID " # s += f"{g}{B} A {b}{G} Align " s += f"{g}{B} X {b}{G} Exit " s += f"{e}\r\n{e}\r\n{e}" lst = [] for i in range(len(uiFields)): f = uiFields[i] if i == selectedField: lst.append(f"{w}{Y}[{f}]{b}{G}") else: lst.append(f"{g}{B} {f} {b}{G}") s += " ".join(lst) s += f"{e}\r\n{e}\r\n" if processing == None: if not filters: s += f"Filters: none{e}\r\n{e}" else: allFilters = [] for field in uiFields: fieldFilters = [] regexps = [f.regex for f in filters if f.field == field] if regexps: fieldFilters.append(", ".join(regexps)) if fieldFilters: allFilters.append(field + ": " + ", ".join(fieldFilters)) s += "; ".join(allFilters) + f"{e}\r\n" else: s += "Processing " + r"-\|/"[processing % 4] s += f"{e}\r\n{e}" s += f"\033[0m" # reset colors print(s, end="") def fieldRegex(f, regex): if f == "event": return "^" + regex + ":" else: return " " + f + ': ' + regex def filterRegex(filtr): regex = filtr.regex.lstrip("!") if filtr.field in quotedFields: expr = f'"[^"]*{regex}[^"]*"' else: expr = f'[^ ]*{regex}[^ ]*' return fieldRegex(filtr.field, expr) def groupRegex(f): regex = '"[^"]+"' if f in quotedFields else '[^ ]*' return fieldRegex(f, regex) havePane = False firstLineFile = None def less(**kwargs): group = kwargs.get('group', None) cmd = "grep -F ': debug: CTCIPC: ' " + " ".join([l for l in logFiles]) + \ " | grep -Fv -e 'CTCIPC: CtcIpc parent:' -e 'CTCIPC: cloud settings:'" + \ " -e 'CTCIPC: SetFeatureState:' -e 'CTCIPC: sending ' -e 'CTCIPC: failed to send '" + \ " | sed 's/.*: debug: CTCIPC: //'" for field in uiFields: includes, excludes = "", "" for f in [f for f in filters if f.field == field and not f.regex.startswith("!")]: includes += " -e '%s'" % filterRegex(f) for f in [f for f in filters if f.field == field and f.regex.startswith("!")]: excludes += " -e '%s'" % filterRegex(f) if includes: cmd += " | grep -E" + includes if excludes: cmd += " | grep -Ev" + excludes if group: cmd += " | grep -E -o '%s' | sort | uniq -c | sort -rg" % groupRegex(uiFields[selectedField]) global firstLineFile if not firstLineFile: firstLineFile = tempfile.NamedTemporaryFile(prefix="first_line", delete=False) firstLineFile.truncate() firstLineFile.close() else: with open(firstLineFile.name, "w") as f: f.truncate() cmd += f" | tee >( (head -n 1; echo) > {firstLineFile.name})" cmd += " | less -XS; tmux wait -S channel; tail -f /dev/null" tmux1 = ["tmux"] global havePane if havePane: tmux1 += ["kill-pane", "-t", "1", ";"] havePane = True tmux1 += ["split-window", cmd, ";", "resize-pane", "-t", "0", "-y", "6", ";"] subprocess.run(tmux1, check=True) waitForStdout() tmux2 = ["tmux", "wait", "channel", ";", "select-pane", "-t", "0"] subprocess.run(tmux2, check=True) filtersTmpFile = None def waitForStdout(): global processing processing = 0 while os.path.getsize(firstLineFile.name) == 0: processing += 1 raw() redraw(active=False) cooked() time.sleep(0.1) processing = None raw() redraw(active=False) cooked() def editFilters(): field = uiFields[selectedField] global filtersTmpFile, filters, needRefresh if not filtersTmpFile: filtersTmpFile = tempfile.NamedTemporaryFile(prefix="filters", delete=False) filtersTmpFile.close() with open(filtersTmpFile.name, "w") as tmpf: print(f"# egrep patterns for {field}, prefix with '!' to exclude\n", file=tmpf) for f in filters: if f.field == field: print(f.regex, file=tmpf) tmux = ["tmux"] global havePane if havePane: tmux += ["kill-pane", "-t", "1", ";"] havePane = False vi = [e for e in ["vi", "nvi", "neovim"] if os.path.basename(editor).startswith(e)] flags = "'+set history=0' --cmd 'let g:loaded_mru=1'" if vi else "" cmd = f"{editor} {flags} {filtersTmpFile.name}; tmux wait -S channel" tmux += ["split-window", cmd, ";", "resize-pane", "-t", "0", "-y", "6", ";", "wait", "channel", ";", "select-pane", "-t", "0"] subprocess.run(tmux, check=True) with open(filtersTmpFile.name, "r") as tmpf: newFilters = [] for line in [l.strip() for l in tmpf.readlines()]: if line and not line.startswith("#"): newFilters.append(Filter(field, line)) newFilters += [f for f in filters if f.field != field] if newFilters != filters: filters = newFilters needRefresh = True if __name__ == "__main__": if not tui: # continue in a new tmux server and set an env var so it can log exceptions back to us to display cmd = ["tmux", "-L", "eventviewer", "-f", "/dev/null", "set", "-g", "status", "off", ";", "new-session", sys.argv[0], "tui"] + sys.argv[1:] env = os.environ.copy() env["EVENTVIEWER_PPID"] = str(os.getpid()) subprocess.run(cmd, check=True, env=env) fname = "/tmp/eventviewer-%d.txt" % os.getpid() if os.path.exists(fname): with open(fname, "r") as f: print("\n" + f.read(), end="") os.unlink(fname) sys.exit() with open("/dev/tty", "rb", buffering=0) as f: attrs = termios.tcgetattr(f.fileno()) def raw(): tty.setraw(f.fileno()) print("\033[?25l", end="") # hide cursor def cooked(): termios.tcsetattr(f.fileno(), termios.TCSADRAIN, attrs) print("\033[?25h", end="") # show cursor try: raw() redraw() while True: buf = f.read(1).decode() if buf.lower() in ["\003", "q", "x"]: # Ctrl-C is \003 if havePane: subprocess.run(["tmux", "kill-pane", "-t", "1"]) break elif buf.lower() in [" ", "a"]: redraw(active=False) cooked() less() needRefresh = False raw() redraw() elif buf == "\r": redraw(active=False) cooked() less(group=True) needRefresh = False raw() redraw() elif buf.lower() == "f": redraw(active=False) cooked() editFilters() raw() redraw() elif buf == "\033": while not buf[-1].isalpha(): buf += f.read(1).decode() if buf == "\033[D": # Left if selectedField > 0: selectedField -= 1 redraw() elif buf == "\033[C": # Right if selectedField < len(uiFields) - 1: selectedField += 1 redraw() except Exception: if havePane: subprocess.run(["tmux", "kill-pane", "-t", "1"]) ppid = int(os.getenv("EVENTVIEWER_PPID", "0")) if ppid: with open(f"/tmp/eventviewer-{ppid}.txt", "w") as f: print(traceback.format_exc(), file=f) else: traceback.print_exc() finally: cooked() if filtersTmpFile: os.unlink(filtersTmpFile.name) if firstLineFile: os.unlink(firstLineFile.name)
Save