Files
IPB/applications/core/modules/admin/overview/security.php
T
2025-12-19 05:44:59 -08:00

403 lines
14 KiB
PHP

<?php
/**
* @brief Security Settings
* @author <a href='https://www.invisioncommunity.com'>Invision Power Services, Inc.</a>
* @copyright (c) Invision Power Services, Inc.
* @license https://www.invisioncommunity.com/legal/standards/
* @package Invision Community
* @since 11 Jun 2013
*/
namespace IPS\core\modules\admin\overview;
/* To prevent PHP errors (extending class does not exist) revealing path */
if ( !defined( '\IPS\SUITE_UNIQUE_KEY' ) )
{
header( ( isset( $_SERVER['SERVER_PROTOCOL'] ) ? $_SERVER['SERVER_PROTOCOL'] : 'HTTP/1.0' ) . ' 403 Forbidden' );
exit;
}
/**
* Security Settings
*/
class _security extends \IPS\Dispatcher\Controller
{
/**
* Execute
*
* @return void
*/
public function execute()
{
\IPS\Dispatcher::i()->checkAcpPermission( 'security_manage' );
parent::execute();
}
/**
* Security Center
*
* @return void
*/
protected function manage()
{
/* Init */
$content = array();
\IPS\Output::i()->sidebar['actions'] = array(
'settings' => array(
'icon' => 'cog',
'link' => \IPS\Http\Url::internal( 'app=core&module=overview&controller=security&do=settings' ),
'title' => 'security_settings',
'data' => array( 'ipsDialog' => '', 'ipsDialog-title' => \IPS\Member::loggedIn()->language()->addToStack('security_settings') )
),
'list_admins' => array(
'icon' => 'key',
'link' => \IPS\Http\Url::internal( 'app=core&module=members&controller=members&filter=members_filter_administrators' ),
'title' => 'security_list_admins',
),
);
/* open_basedir */
$dir = @dir( '/' );
if ( $dir instanceof Directory )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('open_basedir_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('open_basedir_desc'),
'risk' => "high",
);
}
/* Htaccess Protection */
$needUploads = FALSE;
foreach( \IPS\Db::i()->select( '*', 'core_file_storage', array( 'method=?', 'FileSystem' ) ) as $uploads )
{
$uploads = json_decode( $uploads['configuration'], TRUE );
if( isset( $uploads['dir'] ) )
{
$uploads['dir'] = str_replace( '{root}', \IPS\ROOT_PATH, $uploads['dir'] );
if( !is_file( $uploads['dir'] . '/.htaccess' ) )
{
$needUploads = TRUE;
}
}
}
$storeSettings = json_decode( \IPS\STORE_CONFIG, TRUE );
if ( ( $needUploads OR
( \IPS\STORE_METHOD == 'FileSystem' AND !is_file( str_replace( '{root}', \IPS\ROOT_PATH, $storeSettings['path'] ) . '/.htaccess' ) ) ) AND !\IPS\NO_WRITES )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('htaccess_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('htaccess_desc'),
'risk' => "high",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_run_tool'), 'action' => "app=core&module=overview&controller=security&do=htaccess" ),
);
}
/* Configuration File */
if ( is_writable( \IPS\ROOT_PATH . '/conf_global.php' ) AND !\IPS\NO_WRITES )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('conf_writeable_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('conf_writeable_desc'),
'risk' => "high",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_run_tool'), 'action' => "app=core&module=overview&controller=security&do=conf" ),
);
}
/* Disabled PHP Functions */
$functionsToDisable = array( 'exec', 'system', 'passhtru', 'pcntl_exec', 'popen', 'proc_open', 'shell_exec' );
$showingFunctionWarning = FALSE;
foreach ( $functionsToDisable as $k => $function )
{
if ( function_exists( $function ) )
{
$showingFunctionWarning = TRUE;
}
else
{
unset( $functionsToDisable[ $k ] );
}
}
if ( $showingFunctionWarning )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('disable_functions_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('disable_functions_desc', FALSE, array( 'sprintf' => array( implode( ', ', $functionsToDisable ) ) ) ),
'risk' => "high",
);
}
/* Display Errors */
if ( ini_get( 'display_errors' ) )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('display_errors_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('display_errors_desc'),
'risk' => "medium",
);
}
/* ACP Directory Name */
if ( \IPS\CP_DIRECTORY == 'admin' and !\IPS\CIC )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('rename_admin_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('rename_admin_desc'),
'risk' => "low",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_learn_more'), 'action' => "app=core&module=overview&controller=security&do=renameAdmin" ),
);
}
/* ACP Password Protection */
if ( ! is_file( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htaccess' ) AND !\IPS\NO_WRITES AND !\IPS\CIC )
{
$content[] = array(
'title' => \IPS\Member::loggedIn()->language()->addToStack('admin_pass_title'),
'description' => \IPS\Member::loggedIn()->language()->addToStack('admin_pass_desc'),
'risk' => "low",
'button' => array( 'title' => \IPS\Member::loggedIn()->language()->addToStack('security_run_tool'), 'action' => "app=core&module=overview&controller=security&do=acpHtaccess" ),
);
}
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('security_center');
\IPS\Output::i()->cssFiles = array_merge( \IPS\Output::i()->cssFiles, \IPS\Theme::i()->css( 'system/security.css', 'core', 'admin' ) );
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'overview' )->security( $content );
}
/**
* Security Settings
*
* @return void
*/
protected function settings()
{
$form = new \IPS\Helpers\Form;
/* IP Addresses */
$form->addHeader( 'security_header_ips' );
if ( !\IPS\CIC )
{
$form->add( new \IPS\Helpers\Form\YesNo( 'xforward_matching', \IPS\Settings::i()->xforward_matching, FALSE ) );
}
$form->add( new \IPS\Helpers\Form\YesNo( 'match_ipaddress', \IPS\Settings::i()->match_ipaddress, FALSE ) );
if( \IPS\BYPASS_ACP_IP_CHECK === TRUE )
{
\IPS\Member::loggedIn()->language()->words['match_ipaddress_warning'] = \IPS\Member::loggedIn()->language()->addToStack('ip_override_warn');
}
/* Account Security */
$form->addHeader( 'security_header_accounts' );
$form->add( new \IPS\Helpers\Form\YesNo( 'device_management', \IPS\Settings::i()->device_management, FALSE ) );
/* Password Strength */
$form->addHeader( 'security_header_passwords' );
$form->add( new \IPS\Helpers\Form\YesNo( 'password_strength_meter', \IPS\Settings::i()->password_strength_meter, FALSE, array( 'togglesOn' => array( 'password_strength_meter_enforce' ) ), NULL, NULL, NULL, 'password_strength_meter' ) );
$form->add( new \IPS\Helpers\Form\YesNo( 'password_strength_meter_enforce', \IPS\Settings::i()->password_strength_meter_enforce, FALSE, array( 'togglesOn' => array( 'password_strength_option' ) ), NULL, NULL, NULL, 'password_strength_meter_enforce' ) );
$strengthOptions = array(
'3' => 'strength_3',
'4' => 'strength_4',
'5' => 'strength_5',
);
$form->add( new \IPS\Helpers\Form\Radio( 'password_strength_option', \IPS\Settings::i()->password_strength_option, FALSE, array( 'options' => $strengthOptions ), NULL, NULL, NULL, 'password_strength_option' ) );
/* ACP Link */
$form->addHeader( 'security_header_admincp' );
$form->add( new \IPS\Helpers\Form\YesNo( 'security_remove_acp_link', !\IPS\Settings::i()->security_remove_acp_link, FALSE ) );
/* Handle Submissions */
if ( $values = $form->values() )
{
$values['security_remove_acp_link'] = $values['security_remove_acp_link'] ? FALSE : TRUE;
/* Disabling the password strength meter should also disable enforcing a strength */
$values['password_strength_meter_enforce'] = $values['password_strength_meter'] ? $values['password_strength_meter_enforce'] : FALSE;
$form->saveAsSettings( $values );
\IPS\Session::i()->log( 'acplogs__security_settings' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'saved' );
}
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('security_settings');
\IPS\Output::i()->output = \IPS\Theme::i()->getTemplate('global')->block( 'storage_settings', $form );
}
/**
* Change conf global permissions
*
* @return void
*/
protected function conf()
{
/* INIT */
$done = FALSE;
/* Try... */
if ( \IPS\NO_WRITES or !@chmod( \IPS\ROOT_PATH . '/conf_global.php', 0444 ) )
{
\IPS\Output::i()->error( 'conf_not_altered', '2C258/2', 500, '' );
}
/* All Done */
\IPS\Session::i()->log( 'acplogs__security_conf' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'conf_altered' );
}
/**
* Add htaccess files to writeable directory
*
* @return void
*/
protected function htaccess()
{
if ( \IPS\NO_WRITES )
{
\IPS\Output::i()->error( 'no_writes', '1C258/7', 403, '' );
}
/* INIT */
$errors = array();
$deny = <<<EOF
#<ipb-protection>
<Files ~ "^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml|([a-z0-9]{32}))$">
Order allow,deny
Deny from all
</Files>
#</ipb-protection>
EOF;
foreach( \IPS\Db::i()->select( '*', 'core_file_storage', array( 'method=?', 'FileSystem' ) ) as $uploads )
{
$uploads = json_decode( $uploads['configuration'], TRUE );
if( isset( $uploads['dir'] ) )
{
$uploads['dir'] = str_replace( '{root}', \IPS\ROOT_PATH, $uploads['dir'] );
if( !is_file( $uploads['dir'] . '/.htaccess' ) )
{
if ( !@\file_put_contents( $uploads['dir'] . '/.htaccess', $deny ) )
{
$errors[] = $uploads['dir'];
}
}
}
}
if ( isset( $uploadSettings['FileSystem']['dir'] ) )
{
$directory = $uploadSettings['FileSystem']['dir'];
if ( !@\file_put_contents( $directory . '/.htaccess', $deny ) )
{
$errors[] = $directory;
}
}
$storeSettings = json_decode( \IPS\STORE_CONFIG, TRUE );
if ( \IPS\STORE_METHOD == 'FileSystem' )
{
$directory = str_replace( '{root}', \IPS\ROOT_PATH, $storeSettings['path'] );
if ( !@\file_put_contents( $directory . '/.htaccess', $deny ) )
{
$errors[] = $directory;
}
}
if( count( $errors ) )
{
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'htaccess_not_written', FALSE, array( 'sprintf' => \IPS\Member::loggedIn()->language()->formatList( $errors ) ) ), '2C258/1', 403, '', array(), $deny );
}
/* All Done */
\IPS\Session::i()->log( 'acplogs__security_htaccess_writeable' );
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'htaccess_written' );
}
/**
* Rename ACP directory
*
* @return void
*/
protected function renameAdmin()
{
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('rename_admin_title');
\IPS\Output::i()->breadcrumb[] = array( NULL, \IPS\Output::i()->title );
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'overview' )->securityRenameAdmin();
}
/**
* ACP Htaccess Protection
*
* @return void
*/
protected function acpHtaccess()
{
if ( \IPS\NO_WRITES )
{
\IPS\Output::i()->error( 'no_writes', '1C258/6', 403, '' );
}
if ( !is_writable( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) )
{
\IPS\Output::i()->error( \IPS\Member::loggedIn()->language()->addToStack( 'err_not_writable', FALSE, array( 'sprintf' => array( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY ) ) ), '1C258/5', 403, '' );
}
$form = new \IPS\Helpers\Form;
$form->add( new \IPS\Helpers\Form\Text( 'htaccess_username', NULL, TRUE ) );
$form->add( new \IPS\Helpers\Form\Password( 'htaccess_password', NULL, TRUE ) );
if ( $values = $form->values() )
{
$done = FALSE;
/* See this for an explanation why ErrorDocument is needed: http://www.myriadinteractive.com/blog/view/id/29/conflict-between-apache-url-rewriting-and-basic-authentication */
$htaccess_auth = "ErrorDocument 401 \"Unauthorized Access\"\n"
. "AuthType Basic\n"
. "AuthName \"Invision Community AdminCP\"\n"
. 'AuthUserFile "' . \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . "/.htpasswd\"\n"
. "Require valid-user\n";
$htaccess_pw = $values['htaccess_username'] . ":" .
( ( mb_strtoupper( mb_substr( PHP_OS, 0, 3 ) ) === 'WIN' ) ? $values['htaccess_password'] : crypt( $values['htaccess_password'], base64_encode( $values['htaccess_password'] ) ) );
if ( $FH = @\fopen( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htpasswd', 'w' ) )
{
\fwrite( $FH, $htaccess_pw );
\fclose( $FH );
$FF = @\fopen( \IPS\ROOT_PATH . '/' . \IPS\CP_DIRECTORY . '/.htaccess', 'w' );
\fwrite( $FF, $htaccess_auth );
\fclose( $FF );
$done = TRUE;
\IPS\Session::i()->log( 'acplogs__security_acp_password' );
\IPS\IPS::resyncIPSCloud('Added htaccess protection to ACP');
}
/* All Done */
if ( $done )
{
\IPS\Output::i()->redirect( \IPS\Http\Url::internal( "app=core&module=overview&controller=security" ), 'admin_pass_written' );
}
else
{
\IPS\Output::i()->error( 'admin_pass_not_written', '1C258/3', 403, '' );
}
}
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'global', 'core', 'global' )->message( 'admin_pass_warning', 'warning' );
\IPS\Output::i()->title = \IPS\Member::loggedIn()->language()->addToStack('admin_pass_title');
\IPS\Output::i()->output .= \IPS\Theme::i()->getTemplate( 'global' )->block( \IPS\Output::i()->title, $form );
}
}