PalmaSolutions icon

old SL installer

PalmaSolutions | PRO | 11/02/18 03:28:21 PM UTC | 0 ⭐ | 6746 👁️ | Never ⏰ | []
Perl |

17.37 KB

|

None

|

0 👍

/

0 👎

#!/usr/bin/perl
 
use CGI;
use File::Path qw(mkpath rmtree);
 
BEGIN {
    $SIG{__DIE__} = sub {
        my $msg = shift;
        print "Status: 500\n";
        print "Content-type: text/html\n\n";
        $msg =~ s/\n/\0/g;
        print "error: $msg\n";
        CORE::die $msg;
    }
}
 
$| = 1;
our $q = CGI->new;
 
print "Content-type: text/html\n\n";
 
if ($q->param('task') eq 'detect_redirect') {
    print '1';
    exit;
}
 
if ($q->param('task') eq 'exists_securelive_max_archive') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
 
    print -e "/home/$username/securelive_max.tar.bz2";
    exit;
}
 
if ($q->param('task') eq 'extract_securelive_max_archive') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
 
    my $cmd = `tar -jxvf ./securelive_max.tar.bz2 -C /home/$username 2>&1`;
    print $cmd;
    &site_chmod("/home/$username/securelive_max", 1);
    exit;
}
 
if ($q->param('task') eq 'delete_securelive_max_archive') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
 
    my $del = unlink("/home/$username/securelive_max.tar.bz2");
    die("Could not delete /home/$username/securelive_max.tar.bz2: $!") unless $del;
    exit;
}
 
if ($q->param('task') eq 'exists_securelive_max_directory') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
 
    print -e "/home/$username/securelive_max";
    exit;
}
 
if ($q->param('task') eq 'delete_securelive_max_directory') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
 
    rmtree("/home/$username/securelive_max", {verbose => 1});
    exit;
}
 
if ($q->param('task') eq 'extract_sl_admin_archive') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
    my $directory = $q->param('directory');
    die('No directory was provided') unless $directory;
    mkpath("/home/$username/$directory", {verbose => 1}) unless -e "/home/$username/$directory";
 
    my $cmd = `tar -jxvf ./sl_admin.tar.bz2 -C /home/$username/$directory 2>&1`;
    print $cmd;
    &disable_mod_security("/home/$username/$directory/sl_admin");
    &site_chmod("/home/$username/$directory/sl_admin", 1);
    exit;
}
 
if ($q->param('task') eq 'delete_sl_admin_archive') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
 
    my $del = unlink("/home/$username/sl_admin.tar.bz2");
    die("Could not delete /home/$username/sl_admin.tar.bz2: $!") unless $del;
    exit;
}
 
if ($q->param('task') eq 'delete_sl_admin_directory') {
    my $username = $q->param('user');
    die('No username was provided') unless $username;
    die("Username ($username) is invalid") unless $username =~ /^[A-Za-z0-9]+$/;
    my $directory = $q->param('directory');
    die('No directory was provided') unless $directory;
    die("directory (/home/$username/$directory) is invalid") unless -e "/home/$username/$directory";
 
    rmtree("/home/$username/$directory/sl_admin", {verbose => 1});
    exit;
}
 
if ($q->param('task') eq 'delete_self') {
    my $del = unlink($ENV{'SCRIPT_FILENAME'});
    die("Could not delete $ENV{'SCRIPT_FILENAME'}: $!") unless $del;
    exit;
}
 
if ($q->param('task') eq 'configure_install') {
    my $directory = $q->param('directory');
    my $user = $q->param('user');
    my $domain = $q->param('domain');
 
    my $unified_directory = "/home/$user/$directory";
    $unified_directory =~ s/\/\//\//g;
 
    &create_authenticator($user);
 
    if (-e  "$unified_directory/.htaccess") {
        &install_htaccess($unified_directory, $user, 1);
    }
    else {
        my $fh;
        open ($fh, '>', "$unified_directory/.htaccess") || die($!);
        print $fh "<IfModule mod_suphp.c>\n";
        print $fh "\tsuPHP_ConfigPath $unified_directory\n";
        print $fh "</IfModule>\n";
        print $fh "AddHandler application/x-httpd-php5 .php5 .php4 .php .php3 .php2 .phtml\n" unless -e '/opt/hosting/VERSION'; # LPCP servers are all PHP 5
        close $fh;
        &install_php_ini($unified_directory, $user, "$unified_directory/.htaccess");
    }
 
    foreach my $entry (&find_htaccess($unified_directory)) {
        next unless $entry;
        &install_htaccess($entry, $user, 0);
    }
    exit;
}
 
if ($q->param('task') eq 'configure_delete') {
    my $directory = $q->param('directory');
    my $user = $q->param('user');
    my @exclude = $q->param('exclude_path');
    my $unified_directory = "/home/$user/$directory";
    $unified_directory =~ s/\/\//\//g;
 
    foreach my $entry (&find_htaccess($unified_directory)) {
        next unless $entry;
        my $safe_path = 1;
        foreach my $path (@exclude_path) {
            $safe_path = 0 if $entry =~ /$path/;
        }
        &delete_htaccess($entry, $user) if $safe_path;
    }
    exit;
}
 
if ($q->param('task') eq 'enable_domain') {
    my $user = $q->param('user');
    my $domain = $q->param('domain');
 
    &enable_domain($user, $domain);
    exit;
}
 
if ($q->param('task') eq 'delete_domain') {
    my $user = $q->param('user');
    my $domain = $q->param('domain');
 
    &delete_domain($user, $domain);
    exit;
}
 
sub disable_mod_security {
    my ($dir) = @_;
 
    my $fh;
    open ($fh, '>>', "$dir/.htaccess") || die($!);
    print $fh "RewriteEngine off\n";
    print $fh "<IfModule mod_security.c>\n";
    print $fh "\tSecFilterEngine Off\n";
    print $fh "\tSecFilterScanPOST Off\n";
    print $fh "</IfModule>\n";
    close $fh;
}
 
sub site_chmod {
    my ($start_dir, $chmod_start) = @_;
    opendir(DIR, $start_dir) || die "$start_dir: $!";
        my @files = grep {!-d "$start_dir\/$_"} readdir(DIR);
    closedir DIR;
    opendir(DIR, $start_dir) || die "$start_dir: $!";
        my @folders = grep {-d "$start_dir\/$_"} readdir(DIR);
    closedir DIR;
 
    if ($chmod_start) {
        chmod 0755, $start_dir;
    }
 
    foreach my $file (sort @files) {
        $file =~ s/\"/\\\"/i;
        $file = "$start_dir\/$file";
        if ($file =~ /\.pl$/ || $file =~ /\.cgi$/) {
            chmod 0755, $file;
        }
        else {
            chmod 0644, $file;
        }
    }
    foreach my $folder (sort @folders) {
        if ($folder !~ /^\.\.?$/) {
            $folder =~ s/\"/\\\"/i;
            $folder = "$start_dir\/$folder";
            chmod 0755, $folder;
            &site_chmod($folder, 0);
        }
    }
}
 
sub find_htaccess {
    my ($start_dir) = @_;
    print "information: Scanning for additional .htaccess files\n";
    my @htaccess = &dir ($start_dir);
    print "information: Scan for additional .htaccess files complete\n";
    return @htaccess;
}
 
sub enable_domain {
    my ($user, $domain) = @_;
    my $file = "/home/$user/securelive_max/lunarpages.php";
    my $fh;
 
    unless (-e $file) {
        &create_authenticator($user);
    }
 
    chmod 0644, $file;
 
    open($fh, "<$file") || die("Unable to open $file: $!");
    my @lines = <$fh>;
    close ($fh);
    foreach (@lines) {
        next unless $_ =~ /\$domains = array\((.*?)\)/;
        my @domains = split(/,\s?/, $1);
        my $found = 0;
            
        foreach my $entry (@domains) {
            $entry =~ s/\"//g;
            $found = 1 if $entry eq $domain;
            $entry = "\"$entry\"";
            last if $found;
        }
            
        push (@domains, "\"$domain\"") unless $found;
        $_ = '$domains = array(' . join(',', sort(@domains)) . ');' . "\n";
    }
 
    open($fh, ">$file") || die("Unable to open $file: $!");
    print $fh join('', @lines);
    close($fh);
}
 
sub delete_domain {
    my ($user, $domain) = @_;
    my $file = "/home/$user/securelive_max/lunarpages.php";
    my $fh;
 
    return unless -e $file;
 
    chmod 0644, $file;
 
    open($fh, "<$file") || die("Unable to open $file: $!");
    my @lines = <$fh>;
    close ($fh);
 
    foreach (@lines) {
        next unless $_ =~ /\$domains = array\((.*?)\)/;
        my @domains = split(/,\s?/, $1);
        my @new_domains;
            
        foreach my $entry (@domains) {
            $entry =~ s/\"//g;
            if ($entry ne $domain) {
                push(@new_domains, "\"$entry\"");
            }
        }
            
        $_ = '$domains = array(' . join(',', sort(@new_domains)) . ');' . "\n";
    }
 
    open($fh, ">$file") || die("Unable to open $file: $!");
    print $fh join('', @lines);
    close($fh);
}
                
 
sub create_authenticator {
    my ($user) = @_;
    my $file = "/home/$user/securelive_max/lunarpages.php";
    my $fh;
    
    return if -e $file;
 
    chmod 0644, $file;
 
    print "information: Creating authentication file\n";
 
    open($fh, ">$file") || die("Unable to open $file: $!");
    print $fh '<?php', "\n";
    print $fh '$domain = $_SERVER["HTTP_HOST"];', "\n";
    print $fh '$domains = array();', "\n";
    print $fh "\n";
    print $fh 'foreach ($domains as $entry) {', "\n";
    print $fh "\t", 'if ($domain === $entry || stristr($domain, $entry)) {', "\n";
    print $fh "\t\t", 'include("/home/', $user, '/securelive_max/sl8.php");', "\n";
    print $fh "\t", '}', "\n";
    print $fh '}', "\n";
    print $fh '?>';
    close($fh);
}
 
sub install_htaccess {
    my ($directory, $user, $required_php) = @_;
    my $file = "$directory/.htaccess";
    my $fh;
 
    print "information: Scanning .htaccess file at $file for suPHP_ConfigPath entries and PHP 5 handlers\n";
 
    open($fh, "<$file") || die("Unable to open $file: $!");
    my @lines = <$fh>;
    close $fh;
 
    my $php5 = 0;
    my $php_found = 0;
    my $protect_php_ini = 0;
    foreach (@lines) {
        if (/^suPHP_ConfigPath\s+(.+)/) {
            my $phpini = $1;
            $phpini =~ s/\s+$//;
            print "information: Found suPHP_ConfigPath entry in $file, pointing to $phpini/php.ini\n";            
            &install_php_ini($phpini, $user, $file);
            $required_php = 1 if $phpini eq $directory;
            $php_found = 1;
        }
        if (/^AddHandler application\/x-httpd-php5/) {
            print "information: Found PHP 5 handler entry\n";
            $php5 = 1;
        }
        if (/^\<Files php\.ini\>/) {
            print "information: Found php.ini protection line";
            $protect_php_ini = 1;
        }
        $_ = "$_\n" unless substr($_,-1) eq "\n"; # Add a newline to the end of a line that doesn't have one
    }
 
    $php5 = 1 if -e '/opt/hosting/VERSION'; # LPCP servers are all PHP 5
    if ($required_php) {
        if (!$php_found) {
            print "information: No suPHP_ConfigPath entry found in $file, where required\n";
            print "information: Adding suPHP_ConfigPath entry to $file, pointing to $directory/php.ini\n";
            unshift(@lines, "</IfModule>\n");
            unshift(@lines, "suPHP_ConfigPath $directory\n");
            unshift(@lines, "<IfModule mod_suphp.c>\n");
            &install_php_ini($directory, $user, $file);
        }
        if (!$php5) {
            print "information: No PHP 5 handler entry found in $file, where required\n";
            print "information: Adding PHP 5 handler entry to $file\n";
            unshift(@lines, "AddHandler application/x-httpd-php5 .php5 .php4 .php .php3 .php2 .phtml\n");
        }
        if (!$protect_php_ini) {
            print "information: No php.ini protection found in $file, where required\n";
            print "information: Adding php.ini protection entries to $file\n";
            push(@lines, "<Files php.ini>\n");
            push(@lines, "    Order allow,deny\n");
            push(@lines, "    Deny from all\n");
            push(@lines, "</Files>\n");
        }
            
        chmod 0644, $file;
        open ($fh, ">$file") || die("Unable to open $file: $!");
        print $fh @lines;
        close $fh;
    }
 
    print "information: Scan of .htaccess file at $file complete\n";
}
 
sub install_php_ini {
    my ($directory, $user, $ref) = @_;
    my $file = "$directory/php.ini";
    my $fh;
 
    print "information: Scanning php.ini file at $file for SecureLive auto_prepend entries\n";
 
    my @lines;
    if (-e $file) {
        open($fh, "<$file") || die("Unable to open $file (from $ref): $!");
        @lines = <$fh>;
        close $fh;
    }
 
    my $auto_append_found = 0;
    foreach (@lines) {
        if (/auto_prepend_file = \/home\/$user\/securelive_max\/lunarpages.php/) {
            print "information: Found SecureLive auto_prepend entry in $file\n";
            $auto_append_found = 1;
        }
        elsif (
            /auto_prepend_file = \/home\/$user\/securelive_max/) {
            print "information: Found SecureLive auto_prepend entry in $file for a different installation, skipping\n";
            $auto_append_found = 1;
        }
    }
    if (!$auto_append_found) {
        print "information: No SecureLive auto_prepend entry found in $file, where required\n";
        print "information: Adding SecureLive auto_prepend entry to $file\n";
        chmod 0644, $file;
        open ($fh, ">$file") || die("Unable to open $file (from $ref): $!");
        unshift(@lines, "auto_prepend_file = /home/$user/securelive_max/lunarpages.php\n");
        print $fh @lines;
        close $fh;
    }
    print "information: Scan of php.ini file at $file complete\n";
}
 
sub delete_htaccess {
    my ($directory, $user) = @_;
    my $file = "$directory/.htaccess";
    my $fh;
 
    print "information: Scanning .htaccess file at $file for suPHP_ConfigPath entries\n";
 
    chmod 0644, $file;
    open($fh, "<$file") || die("Unable to open $file: $!");
    my @lines = <$fh>;
    close $fh;
 
    open($fh, ">$file") || die("Unable to open $file: $!");
    foreach (@lines) {
        if (/^suPHP_ConfigPath\s+(.+)/) {
            my $directory = $1;
            print "information: Found suPHP_ConfigPath entry in $file, pointing to $1/php.ini\n";
            &delete_php_ini($directory, $user);
 
            if (!-e "$directory/php.ini") {
                #After the edit, a php.ini file can be removed, clean up the .htaccess as well
                if (scalar(@lines) == 1) {
                    print "information: Removing suPHP_ConfigPath entry as php.ini file at $1 has been removed\n";
                    print "information: Removing empty .htaccess $file\n";
                    close($fh);
                    unlink($file);
                }
            }
            else {
                print $fh $_;
            }
        }
        else {
            print $fh $_;
        }
    }
    close($fh);
 
    print "information: Scan of .htaccess file at $file complete\n";
}
 
sub delete_php_ini {
    my ($directory, $user) = @_;
    my $file = "$directory/php.ini";
    my $fh;
 
    print "information: Scanning php.ini file at $file for SecureLive auto_prepend entries\n";
 
    my @lines;
    if (-e $file) {
        open($fh, "<$file") || die($!);
        @lines = <$fh>;
        close $fh;
    }
 
    if (scalar(@lines) == 1 && $lines[0] =~ /auto_prepend_file = \/home\/$user\/securelive_max\/lunarpages.php/) {
        print "information: Found SecureLive auto_prepend entry in $file\n";
        print "information: Removing SecureLive auto_prepend entry from $file\n";
        print "information: Removing empty php.ini $file\n";
        my $del = unlink($file);
    }
    else {
        chmod 0644, $file;
        open ($fh, ">$file") || die($!);
        foreach (@lines) {
            next unless $_;
            next if /^\s+$/;
            if (/auto_prepend_file = \/home\/$user\/securelive_max\/lunarpages.php/) {
                print "information: Found SecureLive auto_prepend entry in $file\n";
                print "information: Removing SecureLive auto_prepend entry from $file\n";
                next;
            }
            else {
                print $fh "$_" if $_;
            }
        }
        close $fh;
    }
 
    if ((stat($file))[7] == 0) {
        print "information: Removing SecureLive auto_prepend entry from $file\n";
        print "information: Removing empty php.ini $file\n";
        my $del = unlink($file);
    }
 
    print "information: Scan of php.ini file at $file complete\n";
}
 
sub dir {
    my ($start_dir) = @_;
    return if -l $start_dir;
    my @results;
 
    if (opendir(DIR, $start_dir)) {
        my @files = grep {!-d "$start_dir\/$_"} readdir(DIR);
        rewinddir DIR;
        my @folders = grep {-d "$start_dir\/$_"} readdir(DIR);
 
        foreach my $file (sort @files) {
            if ($file eq '.htaccess') {
                print "information: Found .htaccess at $start_dir/.htaccess\n";            
                push(@results, $start_dir);
            }
        }
        foreach my $folder (sort @folders) {
            if ($folder !~ /^\.\.?$/) {
                $folder =~ s/\"/\\\"/i;
                push(@files, dir("$start_dir/$folder"));
            }
        }
        closedir DIR
    }
 
    return @results;
}
 
42;

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎