PluginProbe
WebTotem Security / 1.1
WebTotem Security v1.1
3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 2.2.4 All 109 releases
wt-security / library / WT.php

WT.php in WebTotem Security 1.1, at library/WT.php

451 lines 22.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php defined('ABSPATH') or die("Protected By WT!");
2
3
4 class WTSEC_LIBRARY_WT
5 {
6 const URL = "https://api.wtotem.com/v1/graphql";
7
8 public static function auth($key)
9 {
10 $payload = '{"query":"mutation{\n apiServiceMutation{\n auth(apiKey:\"' . $key . '\"){\n value\n refreshToken\n expiresIn\n }\n }\n}\n\n"}';
11 return self::requestApi($payload);
12 }
13
14 protected static function requestApi($payload, $token = false, $repeat = false)
15 {
16 if ($token) {
17 $token = WTSEC_LIBRARY_App::getToken();
18 }
19 $args = [
20 'body' => $payload,
21 'timeout' => '15',
22 'sslverify' => false,
23 'headers' => ['Content-Type:application/json'],
24 ];
25 if (!is_null($token) && $token) {
26 $authorization = "Bearer " . $token;
27 $args['headers'] = array_merge($args['headers'], ["Authorization" => $authorization]);
28 }
29 $response = wp_remote_post(self::URL, $args);
30 $httpcode = wp_remote_retrieve_response_code($response);
31
32 if ($httpcode < 200) {
33 WTSEC_LIBRARY_Session::setNotification("error", WTSEC_LIBRARY_Localization::lmsg('could_not_connect_to_the_server'));
34 }
35 $response = wp_remote_retrieve_body($response);
36
37 $result = json_decode($response, true);
38 if (isset($result['errors'][0]['message'])) {
39 $message = self::diffMesageForHuman($result['errors'][0]['message']);
40 if (stripos($result['errors'][0]['message'], "token") !== false && !$repeat) {
41 $result = WTSEC_LIBRARY_WT::auth(wtsec_app()->get("api_key"));
42 if (isset($result['data']['apiServiceMutation']['auth']['value'])) {
43 $token_ = $result['data']['apiServiceMutation']['auth']['value'];
44 WTSEC_LIBRARY_App::login($token_);
45 return self::requestApi($payload, $token, true);
46 } else {
47 WTSEC_LIBRARY_App::logout();
48 }
49 } else {
50 if ($message !== false) {
51 WTSEC_LIBRARY_Session::setNotification("warning", $message);
52 }
53 }
54 }
55 return $result;
56 }
57
58 public static function diffMesageForHuman($message)
59 {
60 $definition = $message;
61 $excepts = [
62 "RESOURCE_NOT_FOUND", "DUPLICATE_HOST", "INVALID_CREDENTIALS", "INVALID_API_KEY", "Invalid token",
63 ];
64 if (in_array($message, $excepts)) {
65 return false;
66 }
67 switch ($message) {
68 case 'HOSTS_LIMIT_EXCEEDED':
69 $definition = WTSEC_LIBRARY_Localization::lmsg('hosts_limit_exceed');
70 break;
71 case 'RESOURCE_NOT_FOUND':
72 $definition = WTSEC_LIBRARY_Localization::lmsg('resource_not_found');
73 break;
74 case 'Invalid token':
75 $definition = WTSEC_LIBRARY_Localization::lmsg('invalid_token');
76 break;
77 case 'USER_ALREADY_REGISTERED':
78 $definition = WTSEC_LIBRARY_Localization::lmsg('user_already_exist');
79 break;
80 case 'DUPLICATE_HOST':
81 $definition = WTSEC_LIBRARY_Localization::lmsg('duplicate_host');
82 break;
83 case 'Agent does not exist or has been already verified':
84 $definition = WTSEC_LIBRARY_Localization::lmsg('agent_does_not_exist_or_has_been_already_verified');
85 break;
86 case 'INVALID_DOMAIN_NAME':
87 $definition = WTSEC_LIBRARY_Localization::lmsg('invalid_domain_name');
88 break;
89 }
90 return $definition;
91 }
92
93 public static function requestURL($url)
94 {
95 $args = [
96 'timeout' => '15',
97 'sslverify' => false,
98 ];
99 $response = wp_remote_post($url, $args);
100 $httpcode = wp_remote_retrieve_response_code($response);
101 if ($httpcode < 200) {
102 WTSEC_LIBRARY_Session::setNotification("error", WTSEC_LIBRARY_Localization::lmsg('could_not_connect_to_the_server'));
103 }
104 $response = wp_remote_retrieve_body($response);
105 return $response;
106 }
107
108 public static function getOwnSite()
109 {
110 $payload = '{"query":"{\n userHostsList{\n id\n hostname\n }\n}"}';
111 $result = self::requestApi($payload, true);
112 if (isset($result['data']['userHostsList'])) {
113 //mutator
114 foreach ($result['data']['userHostsList'] as &$m) {
115 if (isset($m['hostname'])) {
116 $m['hostname'] = WTSEC_LIBRARY_Idn::idn_to_utf8($m['hostname']);
117 if (self::isSiteUrl($m['hostname'])) {
118 return $result['data']['userHostsList'] = $m;
119 break;
120 }
121 }
122 }
123 $add_site = self::addSite(WTSEC_SITE_URL);
124 if (isset($add_site['errors'])) {
125 return $result['data']['userHostsList'] = [];
126 } else {
127 return self::getOwnSite();
128 }
129 }
130 return [];
131 }
132
133 public static function isSiteUrl($url)
134 {
135 return WTSEC_LIBRARY_Idn::idn_to_utf8(WTSEC_SITE_URL) === $url;
136 }
137
138 public static function addSite($url)
139 {
140 $payload = '{"query":"\n mutation($input: AddUserHostInput!) {\n addUserHost(input: $input) {\n id\n title\n hostname\n tags\n stack\n services {\n id\n name\n configs {\n id\n data\n isActive\n createdAt\n }\n }\n isActive\n createdAt\n }\n }\n ","variables":{"input":{"hostname":"' . $url . '","services":[{"id":1,"configs":[{"scheme":"http","port":80,"check_interval":1,"responsetime_threshold":30,"path":"/","http_errors":[400,401,402,403,404,500,501,502,503],"alert_after":0}]},{"id":2,"configs":[{"check_interval":5,"notify_expiry_day":true,"notify_expiry_month":true,"notify_expiry_week":true,"port":443}]},{"id":4,"configs":[{"check_interval":5,"path":"/","scheme":"http","port":80}]},{"id":5,"configs":[{"check_interval":5,"path":"/","scheme":"http","port":80}]},{"id":6,"configs":[{"check_interval":5,"path":"/","scheme":"http","port":80}]},{"id":7,"configs":[{"check_interval":5,"ports_udp":[18,19,53,27,29,31,71,74],"ports_tcp":[21,22,25,3306,5432,80,443,88,8000,8080]}]},{"id":9,"configs":[{"scheme":"http","port":80,"path":"/"}]},{"id":8,"configs":[{"check_interval":30,"scheme":"http","port":80,"path":"/"}]},{"id":3,"configs":[{"check_interval":60,"notify_expiry_day":true,"notify_expiry_month":true,"notify_expiry_week":true}]},{"id":10,"configs":[{"check_interval":30,"path":"/","scheme":"http","port":80}]}],"title":"' . $url . '"}}}';
141 return self::requestApi($payload, true);
142 }
143
144 public static function getAllChecks($host_id)
145 {
146 $from = time() - (60 * 60 * 24);
147 $to = time();
148 $from_waf = time() - (60 * 60 * 24 * 7);
149 $payload = '{"query":"query getAllChecks( $hostId:Int!, $dateRange: DateRangeInput!, $dateRangeWaf:DateRangeInput! ){\n waServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n isDown\n status\n average(dateRange: $dateRange)\n responseTime(dateRange: $dateRange)\n testsResults(dateRange: $dateRange)\n }\n sslServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n status\n issued\n expires\n daysLeft\n tls\n }\n decServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n email\n daysLeft\n created\n expires\n registrar\n owner\n status\n }\n avServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n lastTestId\n lastTestTime\n status\n count\n list\n }\n cmsServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n lastTestId\n lastTestTime\n status\n count\n list\n }\n dcServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n lastTestTime\n status\n count\n list\n }\n psServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n ip\n lastTestId\n lastTestTime\n status\n count\n openTCPs\n openUDPs\n }\n wafServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n lastTestTime\n status\n count\n countIP \n chart(dateRangeWaf:$dateRangeWaf){\n date\n count\n }\n }\n vcServiceChecks(userHostId:$hostId){\n config{\n id\n isActive\n }\n status\n list\n fileChangesCount\n errorsCount\n signaturesCount\n }\n \n}\n\n\n\n","variables":{"hostId":' . $host_id . ',"dateRange":{"from":' . $from . ',"to":' . $to . '},"dateRangeWaf":{"to":' . $to . ',"from":' . $from_waf . '}}}';
150 return self::requestApi($payload, true);
151 }
152
153 public static function changeStatus($config_id, $host_id)
154 {
155 $payload = '{"query":"\n mutation {\n toggleServiceConfig(\n id: ' . $config_id . '\n userhostId: ' . $host_id . '\n ) {\n isActive\n }\n }\n "}';
156 return self::requestApi($payload, true);
157 }
158
159 public static function serviceConnect($id, $service)
160 {
161 $payload = '{"query":"{ checkAgent(userHostId: ' . $id . ', service: ' . strtoupper($service) . ') }"}';
162 return self::requestApi($payload, true);
163 }
164
165 public static function generateFile($id, $service)
166 {
167 $payload = '{"query":"{ generateAgent(userHostId: ' . $id . ', service: ' . strtoupper($service) . ') }"}';
168 return self::requestApi($payload, true);
169 }
170
171 public static function checkStatus($id, $service)
172 {
173 $payload = '{"query":"{\n ' . strtolower($service) . 'ServiceChecks(userHostId:' . $id . '){\n status\n config{\n isActive\n id\n }\n }\n}"}';
174 return self::requestApi($payload, true);
175 }
176
177 public static function getOptions($host_id)
178 {
179 $payload = '{"query":"query{\nuserHost(id:' . $host_id . '){\n id\n title\n hostname\n stack\n createdAt\n services {\n id\n name\n configs {\n id\n \tdata\n isActive\n }\n }\n }\n}"}';
180 return self::requestApi($payload, true);
181 }
182
183 public static function getAntivirus($host_id)
184 {
185 $payload = '{"query":"query{\n vcServiceChecks(userHostId:' . $host_id . '){\n config{\n id,\n isActive\n }\n status\n list\n fileChangesCount\n errorsCount\n signaturesCount\n }\n}\n\n"}';
186 return self::requestApi($payload, true);
187 }
188
189 public static function getStatusIcon($status, $service)
190 {
191 $color = '';
192 $definition = '';
193 switch ($service) {
194 case 'wa':
195 switch ((string)$status) {
196 case '-1':
197 $color = self::getColor("error");
198 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
199 break;
200 case '-200':
201 $color = self::getColor("grey");
202 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
203 break;
204 case '0':
205 $color = self::getColor("success");
206 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
207 break;
208 case '1':
209 $color = self::getColor("error");
210 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.unavailable');
211 break;
212 }
213 break;
214 case 'ssl':
215 switch ((string)$status) {
216 case '-1':
217 $color = self::getColor("grey");
218 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
219 break;
220 case '-200':
221 $color = self::getColor("grey");
222 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
223 break;
224 case '0':
225 $color = self::getColor("green");
226 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
227 break;
228 case '1':
229 $color = self::getColor("red");
230 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.invalid');
231 break;
232 case '2':
233 $color = self::getColor("red");
234 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.expired');
235 break;
236 case '3':
237 $color = self::getColor("orange");
238 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.expires');
239 break;
240 case '4':
241 $color = self::getColor("red");
242 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.expires_today');
243 break;
244 }
245 break;
246 case 'dec':
247 switch ((string)$status) {
248 case '-3':
249 $color = self::getColor("grey");
250 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.not_registered');
251 break;
252 case '-2':
253 $color = self::getColor("grey");
254 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.unsupported');
255 break;
256 case '-1':
257 $color = self::getColor("grey");
258 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
259 break;
260 case '-200':
261 $color = self::getColor("grey");
262 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
263 break;
264 case '0':
265 $color = self::getColor("green");
266 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
267 break;
268 case '1':
269 $color = self::getColor("orange");
270 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.expires');
271 break;
272 case '2':
273 $color = self::getColor("orange");
274 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.expired');
275 break;
276 case '3':
277 $color = self::getColor("red");
278 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.expires_today');
279 break;
280 }
281 break;
282 case 'av':
283 switch ((string)$status) {
284 case '-1':
285 $color = self::getColor("grey");
286 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
287 break;
288 case '-200':
289 $color = self::getColor("grey");
290 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
291 break;
292 case '0':
293 $color = self::getColor("green");
294 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
295 break;
296 case '1':
297 $color = self::getColor("red");
298 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.blacklisted');
299 break;
300 }
301 break;
302 case 'cms':
303 switch ((string)$status) {
304 case '-1':
305 $color = self::getColor("grey");
306 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
307 break;
308 case '-200':
309 $color = self::getColor("grey");
310 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
311 break;
312 case '0':
313 $color = self::getColor("green");
314 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
315 break;
316 case '1':
317 $color = self::getColor("red");
318 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.miner_detected');
319 break;
320 }
321 break;
322 case 'dc':
323 switch ((string)$status) {
324 case '-1':
325 $color = self::getColor("grey");
326 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
327 break;
328 case '-200':
329 $color = self::getColor("grey");
330 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
331 break;
332 case '0':
333 $color = self::getColor("green");
334 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
335 break;
336 case '1':
337 $color = self::getColor("red");
338 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.deface');
339 break;
340 case '2':
341 $color = self::getColor("orange");
342 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.modified');
343 break;
344 }
345 break;
346 case 'ps':
347 switch ((string)$status) {
348 case '-1':
349 $color = self::getColor("grey");
350 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
351 break;
352 case '-200':
353 $color = self::getColor("grey");
354 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
355 break;
356 case '0':
357 $color = self::getColor("green");
358 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
359 break;
360 case '1':
361 $color = self::getColor("orange");
362 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.open');
363 break;
364 }
365 break;
366 case 'waf':
367 switch ((string)$status) {
368 case '-400':
369 $color = self::getColor("red");
370 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.blocked');
371 break;
372 case '-300':
373 $color = self::getColor("orange");
374 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.not_installed');
375 break;
376 case '-1':
377 $color = self::getColor("grey");
378 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
379 break;
380 case '-200':
381 $color = self::getColor("grey");
382 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
383 break;
384 case '0':
385 $color = self::getColor("green");
386 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
387 break;
388 case '1':
389 $color = self::getColor("red");
390 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.attacks_detected');
391 break;
392 }
393 break;
394 case 'vc':
395 switch ((string)$status) {
396 case '-400':
397 $color = self::getColor("red");
398 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.blocked');
399 break;
400 case '-300':
401 $color = self::getColor("orange");
402 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.not_installed');
403 break;
404 case '-1':
405 $color = self::getColor("grey");
406 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.error');
407 break;
408 case '-200':
409 $color = self::getColor("grey");
410 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.pending');
411 break;
412 case '0':
413 $color = self::getColor("green");
414 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.ok');
415 break;
416 case '1':
417 $color = self::getColor("orange");
418 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.file_changes');
419 break;
420 case '2':
421 $color = self::getColor("red");
422 $definition = WTSEC_LIBRARY_Localization::lmsg('statuses.signature_found');
423 break;
424 }
425 break;
426 }
427 return ["icon" => $color["icon"], "color" => $color["color"], "text" => "<span class='" . $color["color"] . "'>" . $definition . "</span>"];
428 }
429
430 public static function getColor($type)
431 {
432 $types = [
433 "green" => "is--status--ok",
434 "red" => "is--status--error",
435 "success" => "is--status--ok",
436 "error" => "is--status--error",
437 "orange" => "is--status--warning",
438 "grey" => "ww--status_unknow"
439 ];
440 $icon_types = [
441 "green" => "ww-icon--status_ok",
442 "red" => "ww-icon--status_error",
443 "success" => "ww-icon--status_ok",
444 "error" => "ww-icon--status_error",
445 "orange" => "ww-icon--status_warning",
446 "grey" => "ww-icon--status_unknow"
447 ];
448 return ["icon" => $icon_types[$type], "color" => $types[$type]];
449 }
450
451 }