$Date: 2006-06-08 17:11:50 +0100 (Thu, 08 Jun 2006) $ | > $Revision: 289 $ | > $Author: bfarber $ +--------------------------------------------------------------------------- | | > Admin Logs Stuff | > Module written by Matt Mecham | > Date started: 11nd September 2002 | | > Module Version Number: 1.0.0 | > DBA Checked: Mon 24th May 2004 +-------------------------------------------------------------------------- */ if ( ! defined( 'IN_ACP' ) ) { print "

Incorrect access

You cannot access this file directly. If you have recently upgraded, make sure you upgraded 'admin.php'."; exit(); } class ad_security { var $base_url; /** * Section title name * * @var string */ var $perm_main = "admin"; /** * Section title name * * @var string */ var $perm_child = "security"; function auto_run() { $this->ipsclass->admin->nav[] = array( $this->ipsclass->form_code, 'IPB Security Center' ); //----------------------------------------- // Kill globals - globals bad, Homer good. //----------------------------------------- $tmp_in = array_merge( $_GET, $_POST, $_COOKIE ); foreach ( $tmp_in as $k => $v ) { unset($$k); } //----------------------------------------- // LOAD HTML //----------------------------------------- $this->html = $this->ipsclass->acp_load_template('cp_skin_admin'); switch($this->ipsclass->input['code']) { default: case 'virus_check': $this->anti_virus_check(); break; case 'deep_scan': $this->deep_scan(); break; case 'list_admins': $this->list_admins(); break; } } /*-------------------------------------------------------------------------*/ // List admins /*-------------------------------------------------------------------------*/ function list_admins() { //----------------------------------------- // INIT //----------------------------------------- $content = ""; $groups = array(); $query = ""; $members = array(); //----------------------------------------- // Get all admin groups... //----------------------------------------- $this->ipsclass->DB->build_query( array( 'select' => '*', 'from' => 'groups', 'where' => 'g_access_cp > 0 AND g_access_cp IS NOT NULL' ) ); $o = $this->ipsclass->DB->exec_query(); while( $row = $this->ipsclass->DB->fetch_row( $o ) ) { $_gid = intval( $row['g_id'] ); # I hate looped queries, but this should be OK. $this->ipsclass->DB->build_query( array( 'select' => '*', 'from' => 'members', 'where' => "mgroup LIKE '%,". $_gid .",%' OR mgroup_others LIKE '%,". $_gid .",%' OR mgroup='".$_gid."' OR mgroup_others='".$_gid."' OR mgroup='".$_gid.",' OR mgroup_others='".$_gid.",' OR mgroup=',".$_gid."' OR mgroup_others=',".$_gid."'", 'order' => 'joined DESC' ) ); $b = $this->ipsclass->DB->exec_query(); while( $member = $this->ipsclass->DB->fetch_row( $b ) ) { if ( ! $member['mgroup'] AND ! $member['mgroup_others'] ) { continue; } $members[ $member['id'] ] = $member; } $groups[ $row['g_id'] ] = $row; } //----------------------------------------- // Generate list //----------------------------------------- foreach( $members as $id => $member ) { $member['members_display_name'] = $member['members_display_name'] ? $member['members_display_name'] : $member['name']; $member['_mgroup'] = $this->ipsclass->cache['group_cache'][ $member['mgroup'] ]['g_title']; $_tmp = array(); $member['_joined'] = $this->ipsclass->get_date( $member['joined'], 'JOINED' ); foreach( explode( ",", $member['mgroup_others'] ) as $gid ) { if ( $gid ) { $_tmp[] = $this->ipsclass->cache['group_cache'][ $gid ]['g_title']; } } $member['_mgroup_others'] = implode( ", ", $_tmp ); $content .= $this->html->list_admin_row( $member ); } $this->ipsclass->html_help_title = "Members with ACP Access"; $this->ipsclass->html_help_msg = "Below is a list of all members with access to your ACP.
If you do not recognize any, please remove their ACP access immediately."; #$this->ipsclass->html .= $this->ipsclass->skin_acp_global->information_box( "Members with ACP Access", "Below is a list of all members with access to your ACP.
If you do not recognize any, please remove their ACP access immediately." ) ."
"; $this->ipsclass->html .= $this->html->list_admin_overview( $content ); $this->ipsclass->admin->nav[] = array( '', 'List Administrators' ); $this->ipsclass->admin->output(); } /*-------------------------------------------------------------------------*/ // Deep scan /*-------------------------------------------------------------------------*/ function deep_scan() { //----------------------------------------- // INIT //----------------------------------------- $filter = trim( $this->ipsclass->input['filter'] ); $file_count = 0; $bad_count = 0; $content = ""; $checked_content = ""; $colors = array( 0 => '#84ff00', 1 => '#84ff00', 2 => '#b5ff00', 3 => '#b5ff00', 4 => '#ffff00', 5 => '#ffff00', 6 => '#ffde00', 7 => '#ffde00', 8 => '#ff8400', 9 => '#ff8400', 10 => '#ff0000' ); //----------------------------------------- // Get class //----------------------------------------- require_once( ROOT_PATH . 'sources/classes/class_virus_checker.php' ); $class_virus_checker = new class_virus_checker(); $class_virus_checker->ipsclass =& $this->ipsclass; //----------------------------------------- // Run it... //----------------------------------------- $class_virus_checker->anti_virus_deep_scan( ROOT_PATH, '(php|cgi|pl|perl|php3|php4|php5|php6)' ); //----------------------------------------- // Got any bad files? //----------------------------------------- if ( is_array( $class_virus_checker->bad_files ) and count( $class_virus_checker->bad_files ) ) { foreach( $class_virus_checker->bad_files as $idx => $data ) { $file_count++; $_data = array(); $_info = stat( $data['file_path'] ); $_data['size'] = filesize( $data['file_path'] ); $_data['human'] = ceil( $_data['size'] / 1024 ); $_data['mtime'] = $this->ipsclass->get_date( $_info['mtime'], 'SHORT' ); $_data['score'] = $data['score']; $_data['left_width'] = $data['score'] * 5; $_data['right_width'] = 50 - $_data['left_width']; $_data['color'] = $colors[ $data['score'] ]; if ( $data['score'] >= 7 ) { $bad_score++; } if ( strstr( $filter, 'score' ) ) { $_filter = intval( str_replace( 'score-', '', $filter ) ); if ( $data['score'] < $_filter ) { continue; } } else if ( $filter == 'large' ) { if ( $_data['human'] < 55 ) { continue; } } else if ( $filter == 'recent' ) { if ( $_info['mtime'] < time() - 86400 * 30 ) { continue; } } else if ( $filter == 'all' ) { } else { $filter = ""; } $content .= $this->html->deep_scan_bad_files_row( preg_replace( "#^/#", "", str_replace( ROOT_PATH, '', $data['file_path'] ) ), $data['file_name'], $_data ); } if ( $bad_score ) { $this->ipsclass->html_help_title = 'All Executables'; $this->ipsclass->html_help_msg = 'The deep scanner has found the following files.
'.$bad_score.' of '.$file_count.' files are rating 7/10 or more.
If you\'re unsure of their origin, please investigate them immediately.'; } else { $this->ipsclass->html_help_title = 'All Executables'; $this->ipsclass->html_help_msg = 'The deep scanner has found '.$file_count.' files.
If you\'re unsure of their origin, please investigate them immediately.'; } $this->ipsclass->html .= $this->html->deep_scan_bad_files_wrapper( $content ); } //----------------------------------------- // Fix filter... //----------------------------------------- if ( $filter ) { $this->ipsclass->html = preg_replace( "#(value=[\"']".preg_quote( $filter, '#' )."['\"])#i", "\\1 selected='selected'", $this->ipsclass->html ); } $this->ipsclass->admin->nav[] = array( '', 'Deep Scan' ); $this->ipsclass->admin->output(); } /*-------------------------------------------------------------------------*/ // Anti virus checker /*-------------------------------------------------------------------------*/ function anti_virus_check() { //----------------------------------------- // INIT //----------------------------------------- $content = ""; $checked_content = ""; $colors = array( 0 => '#84ff00', 1 => '#84ff00', 2 => '#b5ff00', 3 => '#b5ff00', 4 => '#ffff00', 5 => '#ffff00', 6 => '#ffde00', 7 => '#ffde00', 8 => '#ff8400', 9 => '#ff8400', 10 => '#ff0000' ); //----------------------------------------- // Get class //----------------------------------------- require_once( ROOT_PATH . 'sources/classes/class_virus_checker.php' ); $class_virus_checker = new class_virus_checker(); $class_virus_checker->ipsclass =& $this->ipsclass; //----------------------------------------- // Run it... //----------------------------------------- $class_virus_checker->run_scan(); //----------------------------------------- // Got any bad files? //----------------------------------------- if ( is_array( $class_virus_checker->bad_files ) and count( $class_virus_checker->bad_files ) ) { foreach( $class_virus_checker->bad_files as $idx => $data ) { $_data = array(); $_info = stat( $data['file_path'] ); $_data['size'] = filesize( $data['file_path'] ); $_data['human'] = ceil( $_data['size'] / 1024 ); $_data['mtime'] = $this->ipsclass->get_date( $_info['mtime'], 'SHORT' ); $_data['score'] = $data['score']; $_data['left_width'] = $data['score'] * 5; $_data['right_width'] = 50 - $_data['left_width']; $_data['color'] = $colors[ $data['score'] ]; $content .= $this->html->anti_virus_bad_files_row( preg_replace( "#^/#", "", str_replace( ROOT_PATH, '', $data['file_path'] ) ), $data['file_name'], $_data ); } $this->ipsclass->html_help_title = 'Suspicious Files Detected'; $this->ipsclass->html_help_msg = 'The anti-virus scan located the following suspicious files.
If you\'re unsure of their origin, please remove them immediately.'; $this->ipsclass->html .= $this->html->anti_virus_bad_files_wrapper( $content ); } else { $this->ipsclass->html_help_title = 'No Suspicious Files Detected'; $this->ipsclass->html_help_msg = 'The anti-virus scan did not identify any suspicious files.
Please scan regularly to ensure that your system is secure.'; } //----------------------------------------- // Show checked folders... //----------------------------------------- if ( is_array( $class_virus_checker->checked_folders ) and count( $class_virus_checker->checked_folders ) ) { foreach( $class_virus_checker->checked_folders as $name ) { $checked_content .= $this->html->anti_virus_checked_row( str_replace( ROOT_PATH, '', $name ) ); } $this->ipsclass->html .= $this->html->anti_virus_checked_wrapper( $checked_content ); } $this->ipsclass->admin->nav[] = array( '', 'Virus Check' ); $this->ipsclass->admin->output(); } } ?>