display cronjob of all users

for user in $(cut -f1 -d: /etc/passwd); do crontab -u $user -l; done

Drop Sync/DDOS Attack

1. Find.. to which IP address in the server is targeted by the ddos attack netstat -plan  | grep  :80 | awk ‘{print $4}’ | cut -d: -f1 |sort |uniq -c 2. Find… from which IPs, the attack is coming

Script for replacing a string in multiple files

for y in `ls | grep .html`; do sed “s/abc/xyz/g” $y > temp; mv -f temp $y; done

Hiding redirect url

Create an index.html file : <frameset rows=”100%”> <frame src=””&gt; </frameset> <noframes> <body>Please follow <a href=””>link</a&gt;!</body> </noframes>

Script used to transfer account from cpanel server

#!/bin/bash ls -1 /var/cpanel/users > /root/user_list PORT=”22″ ssh-keygen -t dsa KEY=`cat /root/.ssh/` ssh $1 -p$PORT “mkdir -p /root/.ssh;echo ${KEY} >> /root/.ssh/authorized_keys” 2>&1 scp /var/cpanel/packages/* $1:/var/cpanel/packages/ for user in $(cat /root/user_list);do /scripts/pkgacct $user;done scp /home/user_list $1:/home scp /home/cpmove* $1:/home

Script used to correct permission of files after suphp

#!/bin/bash # For some stupid reason, cPanel screws up the directory permissions. chmod 755 /opt/suphp find /opt/suphp -type d -exec chmod 755 {} \; # Ensure that the permissions are sane and won’t cause a 500 error. for user in

Script used to find vulnerable php files

#!/bin/bash shellpattern=’r0nin|m0rtix|upl0ad|r57|c99|shellbot|phpshell|void\.ru|phpremoteview|directmail|bash_history|vulnscan|spymeta|raslan58′ for user in `/bin/ls /var/cpanel/users` do find /home/$user/public_html \( -name ‘*.php’ -o -name ‘*.cgi’ -o -name ‘*.inc’ \) -exec \ egrep -il “$shellpattern” {} \; done

