=========================================================== .___ __ __ _________________ __ __ __| _/|__|/ |_ / ___\_` __ \__ \ | | \/ __ | | \\_ __\ / /_/ > | \// __ \| | / /_/ | | || | \___ /|__| (____ /____/\____ | |__||__| /_____/ \/ \/ grep rough audit - static analysis tool v2.8 written by @Wireghoul =================================[justanotherhacker.com]=== elog-3.1.3-1/src/elog.c-611- } elog-3.1.3-1/src/elog.c:612: phe = gethostbyaddr(phe->h_addr, sizeof(int), AF_INET); elog-3.1.3-1/src/elog.c-613- if (phe == NULL) { ############################################## elog-3.1.3-1/src/elogd.c-9005- if (error_str[0]) elog-3.1.3-1/src/elogd.c:9006: sprintf(str, "?cmd=%s&config=%s&fail=%s", loc("Change password"), getparam("unm"), error_str); elog-3.1.3-1/src/elogd.c-9007- else elog-3.1.3-1/src/elogd.c:9008: sprintf(str, "?cmd=%s&config=%s&fail=%d", loc("Change password"), getparam("unm"), wrong_pwd); elog-3.1.3-1/src/elogd.c-9009- redirect(lbs, str); ############################################## elog-3.1.3-1/src/elogd.c-9046- if (isparam("oldpwd") && !(wrong_pwd == 1)) // hidden password for password recovery elog-3.1.3-1/src/elogd.c:9047: rsprintf("<input type=hidden name=oldpwd value=\"%s\"", getparam("oldpwd")); elog-3.1.3-1/src/elogd.c-9048- else { ############################################## elog-3.1.3-1/src/elogd.c-10494- if (isparam("js")) { elog-3.1.3-1/src/elogd.c:10495: rsprintf("<script src=\"%s\" type=\"text/javascript\">\n", getparam("js")); elog-3.1.3-1/src/elogd.c-10496- rsprintf("</script>\n\n"); ############################################## elog-3.1.3-1/src/elogd.c-11495- if (isparam("reply_to")) elog-3.1.3-1/src/elogd.c:11496: rsprintf("<input type=\"hidden\" name=\"reply_to\" value=\"%s\">\n", getparam("reply_to")); elog-3.1.3-1/src/elogd.c-11497- ############################################## elog-3.1.3-1/src/elogd.c-11501- if (isparam("nsel")) { elog-3.1.3-1/src/elogd.c:11502: rsprintf("<input type=\"hidden\" name=\"nsel\" value=\"%s\">\n", getparam("nsel")); elog-3.1.3-1/src/elogd.c-11503- for (i = 0; i < atoi(getparam("nsel")); i++) { ############################################## elog-3.1.3-1/src/elogd.c-11505- if (isparam(str)) { elog-3.1.3-1/src/elogd.c:11506: rsprintf("<input type=\"hidden\" name=\"s%d\" value=\"%s\">\n", i, getparam(str)); elog-3.1.3-1/src/elogd.c-11507- } ############################################## elog-3.1.3-1/src/elogd.c-13575- elog-3.1.3-1/src/elogd.c:13576: sprintf(mail_text + strlen(mail_text), "&code=%d&unm=%s\r\n", code, getparam("new_user_name")); elog-3.1.3-1/src/elogd.c-13577- elog-3.1.3-1/src/elogd.c-13578- if (sendmail(lbs, smtp_host, mail_from, email_addr, mail_text, error, sizeof(error)) == -1) { elog-3.1.3-1/src/elogd.c:13579: sprintf(str, loc("Cannot send email notification to \"%s\""), getparam("new_user_email")); elog-3.1.3-1/src/elogd.c-13580- strlcat(str, " : ", sizeof(str)); ############################################## elog-3.1.3-1/src/elogd.c-13589- rsprintf("<tr><td colspan=2 class=\"dlgtitle\">\n"); elog-3.1.3-1/src/elogd.c:13590: rsprintf(loc("An email has been sent to <%s>"), getparam("new_user_email")); elog-3.1.3-1/src/elogd.c-13591- rsprintf(".<br>\n"); ############################################## elog-3.1.3-1/src/elogd.c-13830- rsprintf("<tr><td class=\"notifymsg\" colspan=2>\n"); elog-3.1.3-1/src/elogd.c:13831: rsprintf(getparam("notice")); elog-3.1.3-1/src/elogd.c-13832- rsprintf("</tr>\n"); ############################################## elog-3.1.3-1/src/elogd.c-14490- if (isparam("nsel")) elog-3.1.3-1/src/elogd.c:14491: rsprintf("<input type=hidden name=nsel value=%s>\n", getparam("nsel")); elog-3.1.3-1/src/elogd.c-14492- ############################################## elog-3.1.3-1/src/elogd.c-14502- if (isparam(str)) { elog-3.1.3-1/src/elogd.c:14503: rsprintf("#%s ", getparam(str)); elog-3.1.3-1/src/elogd.c:14504: rsprintf("<input type=hidden name=%s value=%s>\n", str, getparam(str)); elog-3.1.3-1/src/elogd.c-14505- } ############################################## elog-3.1.3-1/src/elogd.c-14624- elog-3.1.3-1/src/elogd.c:14625: sprintf(str, "../%s/?cmd=Config", getparam("lbname")); elog-3.1.3-1/src/elogd.c-14626- redirect(NULL, str); ############################################## elog-3.1.3-1/src/elogd.c-14948- if (isparam("csvfile")) elog-3.1.3-1/src/elogd.c:14949: rsprintf(" value=\"%s\" ", getparam("csvfile")); elog-3.1.3-1/src/elogd.c-14950- rsprintf("></td></tr>\n"); ############################################## elog-3.1.3-1/src/elogd.c-15015- if (isparam("xmlfile")) elog-3.1.3-1/src/elogd.c:15016: rsprintf(" value=\"%s\" ", getparam("xmlfile")); elog-3.1.3-1/src/elogd.c-15017- rsprintf("></td></tr>\n"); ############################################## elog-3.1.3-1/src/elogd.c-15089- if (isparam("head")) elog-3.1.3-1/src/elogd.c:15090: rsprintf("<input type=hidden name=head value=\"%s\">\n", getparam("head")); elog-3.1.3-1/src/elogd.c-15091- if (isparam("notignore")) elog-3.1.3-1/src/elogd.c:15092: rsprintf("<input type=hidden name=notignore value=\"%s\">\n", getparam("notignore")); elog-3.1.3-1/src/elogd.c-15093- if (isparam("filltext")) elog-3.1.3-1/src/elogd.c:15094: rsprintf("<input type=hidden name=filltext value=\"%s\">\n", getparam("filltext")); elog-3.1.3-1/src/elogd.c-15095- rsprintf("<input type=hidden name=csvfile value=\"%s\">\n", csvfile); ############################################## elog-3.1.3-1/src/elogd.c-15385- if (isparam("head")) elog-3.1.3-1/src/elogd.c:15386: rsprintf("<input type=hidden name=head value=\"%s\">\n", getparam("head")); elog-3.1.3-1/src/elogd.c-15387- if (isparam("keep")) elog-3.1.3-1/src/elogd.c:15388: rsprintf("<input type=hidden name=keep value=\"%s\">\n", getparam("keep")); elog-3.1.3-1/src/elogd.c-15389- rsprintf("<input type=hidden name=xmlfile value=\"%s\">\n", xmlfile); ############################################## elog-3.1.3-1/src/elogd.c-16007- if (isparam("wpwd")) elog-3.1.3-1/src/elogd.c:16008: sprintf(request + strlen(request), "Cookie: wpwd=%s\r\n", getparam("wpwd")); elog-3.1.3-1/src/elogd.c-16009- ############################################## elog-3.1.3-1/src/elogd.c-16300- if (isparam("wpwd")) elog-3.1.3-1/src/elogd.c:16301: sprintf(request + strlen(request), "Cookie: wpwd=%s\r\n", getparam("wpwd")); elog-3.1.3-1/src/elogd.c-16302- ############################################## elog-3.1.3-1/src/elogd.c-16628- if (strstr(p, loc("Please login")) == NULL && strstr(p, "GetPwdFile") && isparam("unm")) elog-3.1.3-1/src/elogd.c:16629: eprintf("\nUser \"%s\" has no admin rights on remote server.", getparam("unm")); elog-3.1.3-1/src/elogd.c-16630- ############################################## elog-3.1.3-1/src/elogd.c-19533- if (year < 1970) { elog-3.1.3-1/src/elogd.c:19534: sprintf(str, "Error: Year %s out of range", getparam(py)); elog-3.1.3-1/src/elogd.c-19535- strencode2(str2, str, sizeof(str2)); ############################################## elog-3.1.3-1/src/elogd.c-21282- if (attr_flags[i] & AF_ICON) { elog-3.1.3-1/src/elogd.c:21283: sprintf(str, "Icon comment %s", getparam(iattr)); elog-3.1.3-1/src/elogd.c-21284- getcfg(lbs->name, str, comment, sizeof(comment)); ############################################## elog-3.1.3-1/src/elogd.c-21307- if (attr_flags[i] & AF_ICON) { elog-3.1.3-1/src/elogd.c:21308: sprintf(str, "Icon comment %s", getparam(attr_list[i])); elog-3.1.3-1/src/elogd.c-21309- getcfg(lbs->name, str, comment, sizeof(comment)); ############################################## elog-3.1.3-1/src/elogd.c-21364- if (attr_flags[i] & AF_ICON) { elog-3.1.3-1/src/elogd.c:21365: sprintf(str, "Icon comment %s", getparam(attr_list[i])); elog-3.1.3-1/src/elogd.c-21366- getcfg(lbs->name, str, comment, sizeof(comment)); ############################################## elog-3.1.3-1/src/elogd.c-22409- if (encoding[0] == 'H') elog-3.1.3-1/src/elogd.c:22410: sprintf(mail_text + strlen(mail_text), "\r\n<HR>\r\n%s", getparam("text")); elog-3.1.3-1/src/elogd.c-22411- else if (encoding[0] == 'E') { ############################################## elog-3.1.3-1/src/elogd.c-24740- if (isparam(attr_list[i])) elog-3.1.3-1/src/elogd.c:24741: sprintf(str, " %s <i>\"%s = %s\"</i>", loc("with"), attr_list[i], getparam(attr_list[i])); elog-3.1.3-1/src/elogd.c-24742- } else ############################################## elog-3.1.3-1/src/elogd.c-26262- if (fail == 2) { elog-3.1.3-1/src/elogd.c:26263: sprintf(str, loc("User \"%s\" has no access to this logbook"), getparam("unm")); elog-3.1.3-1/src/elogd.c-26264- rsprintf("<tr><td class=\"dlgerror\">%s!</td></tr>\n", str); ############################################## elog-3.1.3-1/src/elogd.c-27142- rsprintf(" {\r\n"); elog-3.1.3-1/src/elogd.c:27143: rsprintf(" \"fullName\": \"%s\",\r\n", getparam(attchname)); elog-3.1.3-1/src/elogd.c-27144- ############################################## elog-3.1.3-1/src/elogd.c-28834-#ifdef OS_WINNT elog-3.1.3-1/src/elogd.c:28835: rem_addr.S_un.S_addr = inet_addr(str); elog-3.1.3-1/src/elogd.c-28836-#else elog-3.1.3-1/src/elogd.c:28837: rem_addr.s_addr = inet_addr(str); elog-3.1.3-1/src/elogd.c-28838-#endif ############################################## elog-3.1.3-1/src/elogd.c-28840- if (getcfg("global", "Resolve host names", str, strsize) && atoi(str) == 1) { elog-3.1.3-1/src/elogd.c:28841: phe = gethostbyaddr((char *) &rem_addr, 4, PF_INET); elog-3.1.3-1/src/elogd.c-28842- if (phe != NULL) ############################################## elog-3.1.3-1/src/elogd.c-29954- if (getcfg("global", "Resolve host names", str, sizeof(str)) && atoi(str) == 1) { elog-3.1.3-1/src/elogd.c:29955: phe = gethostbyaddr((char *) &rem_addr, 4, PF_INET); elog-3.1.3-1/src/elogd.c-29956- if (phe != NULL) ############################################## elog-3.1.3-1/contrib/mailelog.txt-27-~/bin/mailelog, and make sure it is executable (`chmod +x mailelog') and on elog-3.1.3-1/contrib/mailelog.txt:28:your path (bash: `export PATH=$HOME/bin:$PATH' or csh/tcsh: `setenv PATH elog-3.1.3-1/contrib/mailelog.txt-29-$HOME/bin:$PATH') ############################################## elog-3.1.3-1/contrib/parsecfg.pl-174- elog-3.1.3-1/contrib/parsecfg.pl:175:print "\n\nCREATE TABLE `$table_prefix$current_section` (\n" ; elog-3.1.3-1/contrib/parsecfg.pl-176-print " `id` int(10) NOT NULL auto_increment,\n" ; ############################################## elog-3.1.3-1/contrib/parsecfg.pl-185- } elog-3.1.3-1/contrib/parsecfg.pl:186: print " `$a` $type default NULL,\n" ; elog-3.1.3-1/contrib/parsecfg.pl-187-} ############################################## elog-3.1.3-1/contrib/parsecfg.pl-197- elog-3.1.3-1/contrib/parsecfg.pl:198:print "\nCREATE TABLE `".$table_prefix."attachment` (\n"; elog-3.1.3-1/contrib/parsecfg.pl-199-print " `id` int(10) NOT NULL auto_increment,\n"; ############################################## elog-3.1.3-1/debian/postinst-100-# Get default port. elog-3.1.3-1/debian/postinst:101:PORT=`awk 'tolower($1) == "port" { print $3 }' /etc/elog.conf` elog-3.1.3-1/debian/postinst-102-if [ -z "$PORT" ]; then ############################################## elog-3.1.3-1/debian/postinst-115- # First try to find the PORT in a memorizable range. elog-3.1.3-1/debian/postinst:116: for try in `seq $(($PORT + 1)) $(($PORT + 10))`; do elog-3.1.3-1/debian/postinst-117- echo -n "Checking $try... " ############################################## elog-3.1.3-1/debian/postrm-19-{ elog-3.1.3-1/debian/postrm:20: arg=`echo "$1" | sed '/^[ ]*$/d'` elog-3.1.3-1/debian/postrm-21- if [ -z "$arg" ]; then ############################################## elog-3.1.3-1/debian/postrm-29-( elog-3.1.3-1/debian/postrm:30: logs=`find $SRVDIR/logbooks/demo -maxdepth 1 -type f 2>/dev/null` elog-3.1.3-1/debian/postrm:31: if [ `count_nonempty_lines "$logs"` -eq 1 ]; then elog-3.1.3-1/debian/postrm:32: records=`grep '[$]@MID@[$]' $logs` elog-3.1.3-1/debian/postrm:33: if [ `count_nonempty_lines "$records"` -eq 1 ] \ elog-3.1.3-1/debian/postrm-34- && grep -q "^Author: ELOG maintainer" $logs; then ############################################## elog-3.1.3-1/debian/elog.init-69-# Always run as a daemon. elog-3.1.3-1/debian/elog.init:70:DAEMON_ARGS=`$DAEMON_ARGS echo $ARGS -D` elog-3.1.3-1/debian/elog.init-71-