#!/bin/sh # SPDX-License-Identifier: LicenseRef-EUPL-1.2 # TLP:CLEAR # This script is not specific for CVE-2025-6543, there are also checks for post compromise activity. run_checks() { VERSION="1.8.3" HOSTNAME=$(hostname) LOGFILE="/var/log/custom_checks_v${VERSION}_${HOSTNAME}_$(date +'%Y-%m-%d_%H-%M-%S').log" : > "$LOGFILE" # empty the log file first echo "===== Check script version $VERSION =====" echo "===== Check script version $VERSION =====" >> "$LOGFILE" echo "===== PHP files in /var/netscaler/ =====" >> "$LOGFILE" find /var/netscaler/ -type f -name '*.php' -not -path '/var/netscaler/gui/admin_ui/*' -exec ls -al {} \; 1>>"$LOGFILE" echo "===== XHTML files in /var/netscaler/ =====" >> "$LOGFILE" find /var/netscaler/ -type f -name '*.xhtml' -not -path '/var/netscaler/gui/admin_ui/*' -exec ls -al {} \; 1>>"$LOGFILE" echo -e "\n===== Check for setuid shell at /var/tmp/sh =====" >> "$LOGFILE" if [ -u /var/tmp/sh ]; then file /var/tmp/sh >> "$LOGFILE" else echo "/var/tmp/sh does not exist or is not setuid." >> "$LOGFILE" fi echo -e "\n===== Root-owned SUID files =====" >> "$LOGFILE" find /var \( -perm -4001 -or \( -perm -4010 -group nobody \) \) -user root -exec ls -al {} \; 1>>"$LOGFILE" echo -e "\n===== NSPPE core dumps (low confidence indicator) =====" >> "$LOGFILE" find /var/core/ -iname 'NSPPE*' -exec ls -al {} \; 1>>"$LOGFILE" echo -e "\n===== Checking rc.netscaler for backdoor =====" >> "$LOGFILE" grep python /flash/nsconfig/rc.netscaler >> "$LOGFILE" echo -e "\n===== Checking httpd configuration changes =====" >> "$LOGFILE" ext=$(grep 'httpd-php' /etc/httpd.conf | grep -oE '\.[A-Za-z0-9]+' | grep -Ev '\.phps?$') && [ -n "$ext" ] && find /var/netscaler -type f -name "*$ext" >> "$LOGFILE" grep -E -C 1 "#\s+Require all denied" /etc/httpd.conf >> "$LOGFILE" grep -E -C 1 "#\s+php_flag engine off" /etc/httpd.conf >> "$LOGFILE" echo -e "\nAll checks completed. Log saved to $LOGFILE" } run_checks