Version 2.1.7
This commit is contained in:
1 parent
0eecc172d9
commit
f73f8bff6d
941 files changed
+215301
-103093
No files matched your search
@@ -0,0 +1,401 @@
|
||||
<?php
|
||||
|
||||
/*
|
||||
+--------------------------------------------------------------------------
|
||||
| Invision Power Board v2.1.7
|
||||
| =============================================
|
||||
| by Matthew Mecham
|
||||
| (c) 2001 - 2005 Invision Power Services, Inc.
|
||||
| http://www.invisionpower.com
|
||||
| =============================================
|
||||
| Web: http://www.invisionboard.com
|
||||
| Time: Fri, 14 Jul 2006 08:09:48 GMT
|
||||
| Release: 1b13d7a1c185940e9caa9bf2373b279e
|
||||
| Licence Info: http://www.invisionboard.com/?license
|
||||
+---------------------------------------------------------------------------
|
||||
| > $Date: 2006-06-08 17:11:50 +0100 (Thu, 08 Jun 2006) $
|
||||
| > $Revision: 289 $
|
||||
| > $Author: bfarber $
|
||||
+---------------------------------------------------------------------------
|
||||
|
|
||||
| > Admin Logs Stuff
|
||||
| > Module written by Matt Mecham
|
||||
| > Date started: 11nd September 2002
|
||||
|
|
||||
| > Module Version Number: 1.0.0
|
||||
| > DBA Checked: Mon 24th May 2004
|
||||
+--------------------------------------------------------------------------
|
||||
*/
|
||||
|
||||
|
||||
if ( ! defined( 'IN_ACP' ) )
|
||||
{
|
||||
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'.";
|
||||
exit();
|
||||
}
|
||||
|
||||
class ad_security
|
||||
{
|
||||
|
||||
var $base_url;
|
||||
|
||||
/**
|
||||
* Section title name
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $perm_main = "admin";
|
||||
|
||||
/**
|
||||
* Section title name
|
||||
*
|
||||
* @var string
|
||||
*/
|
||||
var $perm_child = "security";
|
||||
|
||||
function auto_run()
|
||||
{
|
||||
$this->ipsclass->admin->nav[] = array( $this->ipsclass->form_code, 'IPB Security Center' );
|
||||
|
||||
//-----------------------------------------
|
||||
// Kill globals - globals bad, Homer good.
|
||||
//-----------------------------------------
|
||||
|
||||
$tmp_in = array_merge( $_GET, $_POST, $_COOKIE );
|
||||
|
||||
foreach ( $tmp_in as $k => $v )
|
||||
{
|
||||
unset($$k);
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// LOAD HTML
|
||||
//-----------------------------------------
|
||||
|
||||
$this->html = $this->ipsclass->acp_load_template('cp_skin_admin');
|
||||
|
||||
switch($this->ipsclass->input['code'])
|
||||
{
|
||||
default:
|
||||
case 'virus_check':
|
||||
$this->anti_virus_check();
|
||||
break;
|
||||
case 'deep_scan':
|
||||
$this->deep_scan();
|
||||
break;
|
||||
case 'list_admins':
|
||||
$this->list_admins();
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/*-------------------------------------------------------------------------*/
|
||||
// List admins
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
function list_admins()
|
||||
{
|
||||
//-----------------------------------------
|
||||
// INIT
|
||||
//-----------------------------------------
|
||||
|
||||
$content = "";
|
||||
$groups = array();
|
||||
$query = "";
|
||||
$members = array();
|
||||
|
||||
//-----------------------------------------
|
||||
// Get all admin groups...
|
||||
//-----------------------------------------
|
||||
|
||||
$this->ipsclass->DB->build_query( array( 'select' => '*',
|
||||
'from' => 'groups',
|
||||
'where' => 'g_access_cp > 0 AND g_access_cp IS NOT NULL' ) );
|
||||
|
||||
$o = $this->ipsclass->DB->exec_query();
|
||||
|
||||
while( $row = $this->ipsclass->DB->fetch_row( $o ) )
|
||||
{
|
||||
$_gid = intval( $row['g_id'] );
|
||||
|
||||
# I hate looped queries, but this should be OK.
|
||||
|
||||
$this->ipsclass->DB->build_query( array( 'select' => '*',
|
||||
'from' => 'members',
|
||||
'where' => "mgroup LIKE '%,". $_gid .",%' OR mgroup_others LIKE '%,". $_gid .",%' OR mgroup='".$_gid."' OR mgroup_others='".$_gid."' OR mgroup='".$_gid.",' OR mgroup_others='".$_gid.",' OR mgroup=',".$_gid."' OR mgroup_others=',".$_gid."'",
|
||||
'order' => 'joined DESC' ) );
|
||||
|
||||
$b = $this->ipsclass->DB->exec_query();
|
||||
|
||||
while( $member = $this->ipsclass->DB->fetch_row( $b ) )
|
||||
{
|
||||
if ( ! $member['mgroup'] AND ! $member['mgroup_others'] )
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
$members[ $member['id'] ] = $member;
|
||||
}
|
||||
|
||||
$groups[ $row['g_id'] ] = $row;
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// Generate list
|
||||
//-----------------------------------------
|
||||
|
||||
foreach( $members as $id => $member )
|
||||
{
|
||||
$member['members_display_name'] = $member['members_display_name'] ? $member['members_display_name'] : $member['name'];
|
||||
$member['_mgroup'] = $this->ipsclass->cache['group_cache'][ $member['mgroup'] ]['g_title'];
|
||||
$_tmp = array();
|
||||
$member['_joined'] = $this->ipsclass->get_date( $member['joined'], 'JOINED' );
|
||||
|
||||
foreach( explode( ",", $member['mgroup_others'] ) as $gid )
|
||||
{
|
||||
if ( $gid )
|
||||
{
|
||||
$_tmp[] = $this->ipsclass->cache['group_cache'][ $gid ]['g_title'];
|
||||
}
|
||||
}
|
||||
|
||||
$member['_mgroup_others'] = implode( ", ", $_tmp );
|
||||
|
||||
$content .= $this->html->list_admin_row( $member );
|
||||
}
|
||||
|
||||
$this->ipsclass->html_help_title = "Members with ACP Access";
|
||||
$this->ipsclass->html_help_msg = "Below is a list of all members with access to your ACP.<br />If you do not recognize any, please remove their ACP access immediately.";
|
||||
|
||||
#$this->ipsclass->html .= $this->ipsclass->skin_acp_global->information_box( "Members with ACP Access", "Below is a list of all members with access to your ACP.<br />If you do not recognize any, please remove their ACP access immediately." ) ."<br />";
|
||||
$this->ipsclass->html .= $this->html->list_admin_overview( $content );
|
||||
|
||||
$this->ipsclass->admin->nav[] = array( '', 'List Administrators' );
|
||||
|
||||
$this->ipsclass->admin->output();
|
||||
}
|
||||
|
||||
/*-------------------------------------------------------------------------*/
|
||||
// Deep scan
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
function deep_scan()
|
||||
{
|
||||
//-----------------------------------------
|
||||
// INIT
|
||||
//-----------------------------------------
|
||||
|
||||
$filter = trim( $this->ipsclass->input['filter'] );
|
||||
$file_count = 0;
|
||||
$bad_count = 0;
|
||||
$content = "";
|
||||
$checked_content = "";
|
||||
$colors = array( 0 => '#84ff00',
|
||||
1 => '#84ff00',
|
||||
2 => '#b5ff00',
|
||||
3 => '#b5ff00',
|
||||
4 => '#ffff00',
|
||||
5 => '#ffff00',
|
||||
6 => '#ffde00',
|
||||
7 => '#ffde00',
|
||||
8 => '#ff8400',
|
||||
9 => '#ff8400',
|
||||
10 => '#ff0000' );
|
||||
|
||||
//-----------------------------------------
|
||||
// Get class
|
||||
//-----------------------------------------
|
||||
|
||||
require_once( ROOT_PATH . 'sources/classes/class_virus_checker.php' );
|
||||
$class_virus_checker = new class_virus_checker();
|
||||
$class_virus_checker->ipsclass =& $this->ipsclass;
|
||||
|
||||
//-----------------------------------------
|
||||
// Run it...
|
||||
//-----------------------------------------
|
||||
|
||||
$class_virus_checker->anti_virus_deep_scan( ROOT_PATH, '(php|cgi|pl|perl|php3|php4|php5|php6)' );
|
||||
|
||||
//-----------------------------------------
|
||||
// Got any bad files?
|
||||
//-----------------------------------------
|
||||
|
||||
if ( is_array( $class_virus_checker->bad_files ) and count( $class_virus_checker->bad_files ) )
|
||||
{
|
||||
foreach( $class_virus_checker->bad_files as $idx => $data )
|
||||
{
|
||||
$file_count++;
|
||||
|
||||
$_data = array();
|
||||
$_info = stat( $data['file_path'] );
|
||||
|
||||
$_data['size'] = filesize( $data['file_path'] );
|
||||
$_data['human'] = ceil( $_data['size'] / 1024 );
|
||||
$_data['mtime'] = $this->ipsclass->get_date( $_info['mtime'], 'SHORT' );
|
||||
$_data['score'] = $data['score'];
|
||||
$_data['left_width'] = $data['score'] * 5;
|
||||
$_data['right_width'] = 50 - $_data['left_width'];
|
||||
$_data['color'] = $colors[ $data['score'] ];
|
||||
|
||||
if ( $data['score'] >= 7 )
|
||||
{
|
||||
$bad_score++;
|
||||
}
|
||||
|
||||
if ( strstr( $filter, 'score' ) )
|
||||
{
|
||||
$_filter = intval( str_replace( 'score-', '', $filter ) );
|
||||
|
||||
if ( $data['score'] < $_filter )
|
||||
{
|
||||
continue;
|
||||
}
|
||||
}
|
||||
else if ( $filter == 'large' )
|
||||
{
|
||||
if ( $_data['human'] < 55 )
|
||||
{
|
||||
continue;
|
||||
}
|
||||
}
|
||||
else if ( $filter == 'recent' )
|
||||
{
|
||||
if ( $_info['mtime'] < time() - 86400 * 30 )
|
||||
{
|
||||
continue;
|
||||
}
|
||||
}
|
||||
else if ( $filter == 'all' )
|
||||
{
|
||||
|
||||
}
|
||||
else
|
||||
{
|
||||
$filter = "";
|
||||
}
|
||||
|
||||
$content .= $this->html->deep_scan_bad_files_row( preg_replace( "#^/#", "", str_replace( ROOT_PATH, '', $data['file_path'] ) ), $data['file_name'], $_data );
|
||||
}
|
||||
|
||||
if ( $bad_score )
|
||||
{
|
||||
$this->ipsclass->html_help_title = 'All Executables';
|
||||
$this->ipsclass->html_help_msg = 'The deep scanner has found the following files.<br /><strong>'.$bad_score.'</strong> of '.$file_count.' files are rating 7/10 or more.<br />If you\'re unsure of their origin, please investigate them immediately.';
|
||||
}
|
||||
else
|
||||
{
|
||||
$this->ipsclass->html_help_title = 'All Executables';
|
||||
$this->ipsclass->html_help_msg = 'The deep scanner has found '.$file_count.' files.<br />If you\'re unsure of their origin, please investigate them immediately.';
|
||||
}
|
||||
|
||||
$this->ipsclass->html .= $this->html->deep_scan_bad_files_wrapper( $content );
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// Fix filter...
|
||||
//-----------------------------------------
|
||||
|
||||
if ( $filter )
|
||||
{
|
||||
$this->ipsclass->html = preg_replace( "#(value=[\"']".preg_quote( $filter, '#' )."['\"])#i", "\\1 selected='selected'", $this->ipsclass->html );
|
||||
}
|
||||
|
||||
$this->ipsclass->admin->nav[] = array( '', 'Deep Scan' );
|
||||
|
||||
$this->ipsclass->admin->output();
|
||||
}
|
||||
|
||||
/*-------------------------------------------------------------------------*/
|
||||
// Anti virus checker
|
||||
/*-------------------------------------------------------------------------*/
|
||||
|
||||
function anti_virus_check()
|
||||
{
|
||||
//-----------------------------------------
|
||||
// INIT
|
||||
//-----------------------------------------
|
||||
|
||||
$content = "";
|
||||
$checked_content = "";
|
||||
$colors = array( 0 => '#84ff00',
|
||||
1 => '#84ff00',
|
||||
2 => '#b5ff00',
|
||||
3 => '#b5ff00',
|
||||
4 => '#ffff00',
|
||||
5 => '#ffff00',
|
||||
6 => '#ffde00',
|
||||
7 => '#ffde00',
|
||||
8 => '#ff8400',
|
||||
9 => '#ff8400',
|
||||
10 => '#ff0000' );
|
||||
|
||||
//-----------------------------------------
|
||||
// Get class
|
||||
//-----------------------------------------
|
||||
|
||||
require_once( ROOT_PATH . 'sources/classes/class_virus_checker.php' );
|
||||
$class_virus_checker = new class_virus_checker();
|
||||
$class_virus_checker->ipsclass =& $this->ipsclass;
|
||||
|
||||
//-----------------------------------------
|
||||
// Run it...
|
||||
//-----------------------------------------
|
||||
|
||||
$class_virus_checker->run_scan();
|
||||
|
||||
//-----------------------------------------
|
||||
// Got any bad files?
|
||||
//-----------------------------------------
|
||||
|
||||
if ( is_array( $class_virus_checker->bad_files ) and count( $class_virus_checker->bad_files ) )
|
||||
{
|
||||
foreach( $class_virus_checker->bad_files as $idx => $data )
|
||||
{
|
||||
$_data = array();
|
||||
$_info = stat( $data['file_path'] );
|
||||
|
||||
$_data['size'] = filesize( $data['file_path'] );
|
||||
$_data['human'] = ceil( $_data['size'] / 1024 );
|
||||
$_data['mtime'] = $this->ipsclass->get_date( $_info['mtime'], 'SHORT' );
|
||||
$_data['score'] = $data['score'];
|
||||
$_data['left_width'] = $data['score'] * 5;
|
||||
$_data['right_width'] = 50 - $_data['left_width'];
|
||||
$_data['color'] = $colors[ $data['score'] ];
|
||||
|
||||
$content .= $this->html->anti_virus_bad_files_row( preg_replace( "#^/#", "", str_replace( ROOT_PATH, '', $data['file_path'] ) ), $data['file_name'], $_data );
|
||||
}
|
||||
|
||||
$this->ipsclass->html_help_title = 'Suspicious Files Detected';
|
||||
$this->ipsclass->html_help_msg = 'The anti-virus scan located the following suspicious files.<br />If you\'re unsure of their origin, please remove them immediately.';
|
||||
|
||||
$this->ipsclass->html .= $this->html->anti_virus_bad_files_wrapper( $content );
|
||||
}
|
||||
else
|
||||
{
|
||||
$this->ipsclass->html_help_title = 'No Suspicious Files Detected';
|
||||
$this->ipsclass->html_help_msg = 'The anti-virus scan did not identify any suspicious files.<br />Please scan regularly to ensure that your system is secure.';
|
||||
}
|
||||
|
||||
//-----------------------------------------
|
||||
// Show checked folders...
|
||||
//-----------------------------------------
|
||||
|
||||
if ( is_array( $class_virus_checker->checked_folders ) and count( $class_virus_checker->checked_folders ) )
|
||||
{
|
||||
foreach( $class_virus_checker->checked_folders as $name )
|
||||
{
|
||||
$checked_content .= $this->html->anti_virus_checked_row( str_replace( ROOT_PATH, '', $name ) );
|
||||
}
|
||||
|
||||
$this->ipsclass->html .= $this->html->anti_virus_checked_wrapper( $checked_content );
|
||||
}
|
||||
|
||||
$this->ipsclass->admin->nav[] = array( '', 'Virus Check' );
|
||||
|
||||
$this->ipsclass->admin->output();
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
|
||||
?>
|
||||
Reference in new issue
Block a user