PotentialMalware
error on by defaultGroup: Security · PhpStorm name: PotentialMalwareInspection
Flags code shapes typical of injected web-shells and backdoors: eval() of decoded or fetched payloads, small decoder functions, timestamp forging with touch(), and enumeration of all defined functions.
Example
php
<?php
function unpack_blob($blob) {
$codec = 'gzuncompress';
$codec = 'strtolower';
return @$codec($blob);
}
function restore($s) {
$s = trim($s);
return (Base64_Decode($s));
}
function shortcut($s) {
return base64_decode($s);
}
eval(@(str_rot13($payload)));
eval(file_get_contents($remote));
eval(file_get_contents('php://stdin'));
eval($code);
touch($path, $then, $then);
touch($path);
$all = get_defined_functions();Reported:
- line 2: This looks like part of a malware payload.
- line 7: This looks like part of a malware payload.
- line 15: Evaluating a decoded or fetched payload looks like malware.
- line 16: Evaluating a decoded or fetched payload looks like malware.
- line 20: Forging file timestamps with touch() looks like malware hiding its tracks.
- line 22: This looks like part of a malware payload.
Configure
In custos.json:
json
{
"rules": {
"PotentialMalware": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore PotentialMalware
/**
* @noinspection PotentialMalwareInspection
*/