asda?‰PNG  IHDR ? f ??C1 sRGB ??é gAMA ±? üa pHYs ? ??o¨d GIDATx^íüL”÷e÷Y?a?("Bh?_ò???¢§?q5k?*:t0A-o??¥]VkJ¢M??f?±8\k2íll£1]q?ù???T #!/usr/bin/perl #WHMADDON:addonupdates:ConfigServer Security&Firewall ############################################################################### # Copyright 2006-2023, Way to the Web Limited # URL: http://www.configserver.com # Email: sales@waytotheweb.com ############################################################################### ## no critic (RequireUseWarnings, ProhibitExplicitReturnUndef, ProhibitMixedBooleanOperators, RequireBriefOpen) # start main use strict; use File::Find; use Fcntl qw(:DEFAULT :flock); use Sys::Hostname qw(hostname); use IPC::Open3; use lib '/usr/local/csf/lib'; use ConfigServer::DisplayUI; use ConfigServer::Config; use ConfigServer::Slurp qw(slurp); our ($script, $script_da, $images, $myv, %FORM, %daconfig); my $config = ConfigServer::Config->loadconfig(); my %config = $config->config; my $slurpreg = ConfigServer::Slurp->slurpreg; my $cleanreg = ConfigServer::Slurp->cleanreg; our %session; our @sessiondata; unless (-e "/var/lib/csf/csf.da.skip") { if ($ENV{SESSION_ID} =~ /^\w+$/) { open (my $SESSION, "<", "/usr/local/directadmin/data/sessions/da_sess_".$ENV{SESSION_ID}) or &loginfail("Security Error: No valid session ID for [$ENV{SESSION_ID}]"); flock ($SESSION, LOCK_SH); @sessiondata = <$SESSION>; close ($SESSION); chomp @sessiondata; foreach my $line (@sessiondata) { my ($name, $value) = split(/\=/,$line); $session{$name} = $value; } } if (($session{key} eq "") or ($session{ip} eq "") or ($session{key} ne $ENV{SESSION_KEY})) { &loginfail("Security Error: No valid session key"); exit; } my ($ppid, $pexe) = &getexe(getppid()); if ($pexe ne "/usr/local/directadmin/directadmin") { &loginfail("Security Error: Invalid parent"); exit; } } open (my $IN, "<", "/etc/csf/version.txt") or die $!; $myv = <$IN>; close ($IN); chomp $myv; $script = "/CMD_PLUGINS_ADMIN/csf/index.raw"; $script_da = "/CMD_PLUGINS_ADMIN/csf/index.raw"; $images = "/CMD_PLUGINS_ADMIN/csf/images"; my $buffer = $ENV{'QUERY_STRING'}; if ($buffer eq "") {$buffer = $ENV{POST}} if ($ENV{POST} eq "stdin=true") { $buffer = ""; while (<>) { s/\0//; $buffer .= $_; } chomp $buffer; } my @pairs = split(/&/, $buffer); foreach my $pair (@pairs) { my ($name, $value) = split(/=/, $pair); $value =~ tr/+/ /; $value =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg; $FORM{$name} = $value; } open (my $DIRECTADMIN, "<", "/usr/local/directadmin/conf/directadmin.conf"); my @data = <$DIRECTADMIN>; close ($DIRECTADMIN); chomp @data; foreach my $line (@data) { my ($name,$value) = split(/\=/,$line); $daconfig{$name} = $value; } my $bootstrapcss = ""; my $jqueryjs = ""; my $bootstrapjs = ""; my @header; my @footer; my $bodytag; my $htmltag = " data-post='$FORM{action}' "; if (-e "/etc/csf/csf.header") { open (my $HEADER, "<", "/etc/csf/csf.header"); flock ($HEADER, LOCK_SH); @header = <$HEADER>; close ($HEADER); } if (-e "/etc/csf/csf.footer") { open (my $FOOTER, "<", "/etc/csf/csf.footer"); flock ($FOOTER, LOCK_SH); @footer = <$FOOTER>; close ($FOOTER); } if (-e "/etc/csf/csf.htmltag") { open (my $HTMLTAG, "<", "/etc/csf/csf.htmltag"); flock ($HTMLTAG, LOCK_SH); $htmltag .= <$HTMLTAG>; chomp $htmltag; close ($HTMLTAG); } if (-e "/etc/csf/csf.bodytag") { open (my $BODYTAG, "<", "/etc/csf/csf.bodytag"); flock ($BODYTAG, LOCK_SH); $bodytag = <$BODYTAG>; chomp $bodytag; close ($BODYTAG); } unless ($config{STYLE_CUSTOM}) { undef @header; undef @footer; $htmltag = ""; $bodytag = ""; } unless ($FORM{action} eq "tailcmd" or $FORM{action} =~ /^cf/ or $FORM{action} eq "logtailcmd" or $FORM{action} eq "loggrepcmd") { print < ConfigServer Security & Firewall $bootstrapcss $jqueryjs $bootstrapjs \n"; print @header; print <

ConfigServer Security & Firewall - csf v$myv

EOF } ConfigServer::DisplayUI::main(\%FORM, $script, $script_da, $images, $myv); unless ($FORM{action} eq "tailcmd" or $FORM{action} =~ /^cf/ or $FORM{action} eq "logtailcmd" or $FORM{action} eq "loggrepcmd") { print < \n"; print @footer; print "\n"; print "\n"; } sub getexe { my $thispid = shift; open (my $STAT, "<", "/proc/".$thispid."/stat"); my $stat = <$STAT>; close ($STAT); chomp $stat; $stat =~ /\w\s+(\d+)\s+[^\)]*$/; my $ppid = $1; my $exe = readlink("/proc/".$ppid."/exe"); return ($ppid, $exe); } sub loginfail { my $message = shift; my $file = "/var/lib/csf/da".time.".error"; print $message."

Information saved to [$file]\n"; sysopen (my $FILE, $file, O_WRONLY | O_CREAT | O_TRUNC); flock ($FILE, LOCK_EX); print $FILE "To disable DirectAdmin session checks, create a touch file called /var/lib/csf/csf.da.skip\n\n"; print $FILE $message."\n\n"; print $FILE "Session ID = [$ENV{SESSION_ID}]\n"; print $FILE "Session File [/usr/local/directadmin/data/sessions/da_sess_".$ENV{SESSION_ID}."]..."; if (-e "/usr/local/directadmin/data/sessions/da_sess_".$ENV{SESSION_ID}) { print $FILE "exists.\n\n"; } else { print $FILE "does not exist\n\n"; close ($FILE); exit; } print $FILE "Environment data:\n"; print $FILE "REMOTE_ADDR = [$ENV{REMOTE_ADDR}]\n"; print $FILE "SESSION_KEY = [$ENV{SESSION_KEY}]\n"; print $FILE "SESSION_ID = [$ENV{SESSION_ID}]\n\n"; print $FILE "Session data:\n"; print $FILE "ip = [$session{ip}]\n"; print $FILE "key = [$session{key}]\n\n"; print $FILE "Session file contents:\n"; print $FILE join("\n",@sessiondata); close ($FILE); exit; } 1;