PluginProbe
WebTotem Security / 2.2.2
WebTotem Security v2.2.2
3.0.2 3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 All 110 releases
← All changes | services.php +165 -99 2.1.42.2.2 View file →
@@ -1,89 +1,137 @@
1 1 <?php defined('ABSPATH') or die("Protected By WT!");
2 2
3 -function wtsec_cmd($wp_filesystem,$cmd, $service, $_service, $uid, $status,$domain = ''){
3 +function wtsec_cmd($cmd, $service, $_service, $uid, $status, $domain = '')
4 +{
5 + global $wp_filesystem;
4 6
7 + //bug fix with wp file system, which return null
8 + if (empty($wp_filesystem)) {
9 + require_once(ABSPATH . '/wp-admin/includes/file.php');
10 + WP_Filesystem();
11 + }
12 +
13 + //retry checking
14 + if (empty($wp_filesystem)) {
15 + WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
16 + return false;
17 + }
18 +
5 19 switch ($cmd) {
6 20 case $_service . "_install":
7 21 try {
8 22 $file = wtsec_generateFile($uid, $service);
9 - if($service === "WAF"){
10 - $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
11 - $path = $plugin_path;
12 - $target_dir = $wp_filesystem->find_folder($path);
13 - if(!$wp_filesystem->is_dir($path)) {
14 - $wp_filesystem->mkdir($target_dir);
23 + if (is_null($file['name'])) {
24 + WTSEC_LIBRARY_Session::setNotification("error", wtsec_locale("failed_to_download_agent"));
25 + return false;
15 26 }
16 - $target_file = trailingslashit($target_dir).$file['name'];
17 - if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)){
18 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
19 - }else{
20 - wtsec_app()->set($_service . '_installed_file',$file['name']);
21 - }
22 - }else{
27 + if ($service === "WAF") {
28 + $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
29 + $path = $plugin_path;
30 + $target_dir = $wp_filesystem->find_folder($path);
31 + if (!$wp_filesystem->is_dir($path)) {
32 + $wp_filesystem->mkdir($target_dir);
33 + }
34 + $target_file = trailingslashit($target_dir) . $file['name'];
35 + if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)) {
36 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
37 + } else {
38 + wtsec_app()->set($_service . '_installed_file', $file['name']);
39 + }
40 + } else {
23 41 $target_dir = $wp_filesystem->find_folder($wp_filesystem->abspath());
24 - $target_file = trailingslashit($target_dir).$file['name'];
25 - if(!$wp_filesystem->put_contents($target_file, $file['file'])) {
26 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
27 - }else{
28 - wtsec_app()->set($_service . '_installed_file',$file['name']);
42 + $target_file = trailingslashit($target_dir) . $file['name'];
43 + if (!$wp_filesystem->put_contents($target_file, $file['file'])) {
44 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
45 + } else {
46 + wtsec_app()->set($_service . '_installed_file', $file['name']);
47 + if ($service === "AM") {
48 + wtsec_addCheckFile($file['name']);
49 + }
29 50 }
30 51 }
31 - wtsec_serviceConnect($uid, $service,$domain.'/'.$file['name']);
52 + if ($service !== "AM") {
53 + //wtsec_serviceConnect($uid, $service, $domain . '/' . $file['name']);
54 + }
32 55 } catch (Exception $e) {
33 - print_r($e->getMessage());
34 - die();
56 + WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
57 + return false;
35 58 }
36 59 break;
37 60 case $_service . "_start":
38 - WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
39 - wtsec_app()->set($_service.'_status',"start");
61 + WTSEC_LIBRARY_WT::changeStatus($status['config_id'], $uid);
62 + wtsec_app()->set($_service . '_status', "start");
40 63 break;
41 64 case $_service . "_stop":
42 65 // WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
43 - wtsec_app()->set($_service.'_status',"stop");
66 + wtsec_app()->set($_service . '_status', "stop");
44 67 break;
45 68 case $_service . "_connect":
46 69 $file = wtsec_getInstalledFile($_service);
47 70 if ($file) {
48 - wtsec_serviceConnect($uid, $service, $domain . '/' . $file);
49 - }else{
50 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
71 + //wtsec_serviceConnect($uid, $service, $domain . '/' . $file);
72 + } else {
73 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
51 74 }
52 75 break;
53 76 case $_service . "_uninstall":
54 77 try {
55 78 $file = wtsec_getInstalledFile($_service);
56 - if($service === "WAF"){
79 + if ($service === "WAF") {
57 80 $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
58 81 $mainDir = $plugin_path;
59 - }else{
82 + } else {
60 83 $mainDir = $wp_filesystem->abspath();
61 84 }
62 85 $target_dir = $wp_filesystem->find_folder($mainDir);
63 - $target_file = trailingslashit($mainDir).$file;
86 + $target_file = trailingslashit($mainDir) . $file;
64 87 if (!$wp_filesystem->delete($target_file)) {
65 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service,'directory' => $target_dir]));
88 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service, 'directory' => $target_dir]));
66 89 }
67 90 wtsec_app()->set($_service . '_status', "uninstalled");
68 91 WTSEC_LIBRARY_App::deleteOption($_service . '_installed_file');
69 92 } catch (Exception $e) {
70 - print_r($e->getMessage());
71 - die();
93 + WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
94 + return false;
72 95 }
73 96 break;
74 97 }
98 + return true;
75 99 }
76 100
101 +// Add check file if plugin is activated
102 +function wtsec_addCheckFile($name){
103 + global $wp_filesystem;
104 +
105 + if (empty($wp_filesystem)) {
106 + require_once(ABSPATH . '/wp-admin/includes/file.php');
107 + WP_Filesystem();
108 + }
109 +
110 + //retry checking
111 + if (empty($wp_filesystem)) {
112 + WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
113 + return false;
114 + }
115 +
116 + $target_dir = $wp_filesystem->find_folder(WTSEC_PLUGIN_PATH);
117 + $target_file = trailingslashit($target_dir) . 'generate.php';
118 +
119 + if ($wp_filesystem->put_contents($target_file, '<?php exit(); ?>'.$name, FS_CHMOD_FILE)) {
120 + return true;
121 + }
122 + return false;
123 +}
124 +
77 125 function wtsec_checkStatus($id, $service)
78 126 {
79 127 $service = ucfirst(strtolower($service));
80 128 $is_active = null;
81 129 $config_id = null;
82 - $result = WTSEC_LIBRARY_WT::checkStatus($id,$service);
130 + $result = WTSEC_LIBRARY_WT::checkStatus($id, $service);
83 131 $data = $result['data']['auth']['viewer']['sites']['one']['configs'];
84 - foreach ($data as &$cfg){
85 - if(!empty($cfg)){
132 + foreach ($data as &$cfg) {
133 + if (!empty($cfg)) {
86 134 $is_active = $cfg['isActive'];
87 135 $config_id = $cfg['id'];
88 136 }
89 137 }
@@ -93,37 +141,61 @@
93 141 }
94 142 return ['active' => $is_active, 'config_id' => $config_id];
95 143 }
96 144
145 +function wtsec_generateFile($id, $service)
146 +{
147 + if ($service === "AM") {
148 + $result = WTSEC_LIBRARY_WT::generateAmFile($id);
149 + if (!isset($result['data']['auth']['am']['install'])) {
150 + $file = ['filename' => null, "body" => null];
151 + } else {
152 + $result = $result['data']['auth']['am']['install'];
97 153
154 + $url = $result['downloadLink'];
155 + $amFilename = $result['amFilename'];
156 + $wafFilename = $result['wafFilename'];
98 157
99 -function wtsec_generateFile($id, $service)
100 -{
101 - $result = WTSEC_LIBRARY_WT::generateFile($id,$service);
102 - $name = $result['data']['auth']['agents']['generate']['agentName'];
103 - $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
104 - if(empty($file)){
158 + if($wafFilename){
159 + wtsec_app()->set('waf_installed_file', $wafFilename);
160 + }
161 +
162 + $file = WTSEC_LIBRARY_WT::getFileByUrl($url, $amFilename);
163 + if (empty($file)) {
164 + $file = WTSEC_LIBRARY_WT::getFileByUrl($url, $amFilename);
165 + }
166 + }
167 +
168 + $name = $file["filename"];
169 + $file = $file["body"];
170 + } else {
171 + $result = WTSEC_LIBRARY_WT::generateFile($id, $service);
172 + $name = $result['data']['auth']['agents']['generate']['agentName'];
105 173 $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
174 + if (empty($file)) {
175 + $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
176 + }
106 177 }
178 +
107 179 return ['file' => $file, 'name' => $name];
108 180 }
109 181
110 -function wtsec_serviceConnect($id, $service,$domain = '')
182 +function wtsec_serviceConnect($id, $service, $domain = '')
111 183 {
112 - $result = WTSEC_LIBRARY_WT::serviceConnect($id,$service);
184 + $result = WTSEC_LIBRARY_WT::serviceConnect($id, $service);
113 185 $status = isset($result['errors']) && !isset($result['data']['auth']['agents']['check']) ? false : true;
114 186 if (!$status) {
115 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
187 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
116 188 }
117 189 return $status;
118 190 }
119 191
120 192
121 -function wtsec_servicePing($service,$domain = '')
193 +function wtsec_servicePing($service, $domain = '')
122 194 {
123 - if($domain == NULL) return false;
124 - if(stripos($domain,"http") === false){
125 - $domain = "http://".$domain;
195 + if ($domain == NULL) return false;
196 + if (stripos($domain, "http") === false) {
197 + $domain = "http://" . $domain;
126 198 }
127 199 $args = [
128 200 'timeout' => '10',
129 201 'sslverify' => false,
@@ -128,78 +200,71 @@
128 200 'timeout' => '10',
129 201 'sslverify' => false,
130 202 'redirection' => 3,
131 203 ];
132 - $response = wp_remote_get($domain,$args);
204 + $response = wp_remote_get($domain, $args);
133 205 $httpcode = wp_remote_retrieve_response_code($response);
134 - if($httpcode>=200 && $httpcode<400){
206 + if ($httpcode >= 200 && $httpcode < 400) {
135 207 return true;
136 208 } else {
137 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
209 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
138 210 return false;
139 211 }
140 212 }
141 213
142 -function wtsec_button($label = '',$class = ''){
143 - return '<button class="ww-button '.$class.'">'.$label.'</button>';
214 +function wtsec_button($label = '', $class = '')
215 +{
216 + return '<button class="ww-button ' . $class . '">' . $label . '</button>';
144 217 }
145 218
146 -function wtsec_main_button($label = '',$class = ''){
147 - return '<button class="ww-button '.$class.'">'.$label.'</button>';
219 +function wtsec_main_button($label = '', $class = '')
220 +{
221 + return '<button class="ww-button ' . $class . '">' . $label . '</button>';
148 222 }
149 223
150 -function wtsec_generateButtons($uid,$_service, $service, $status,$domain = '')
224 +function wtsec_generateButtons($uid, $_service, $service, $status, $domain = '')
151 225 {
152 226 $url = esc_url(admin_url('admin-post.php'));
153 227 $buttons = [];
154 228
155 - $form = '<form action="'.$url.'" method="post" style="display:inline-block;">
156 - <input type="hidden" name="service" value="'.$_service.'">
229 + $form = '<form action="' . $url . '" method="post" style="display:inline-block;">
230 + <input type="hidden" name="service" value="' . $_service . '">
157 231 <input type="hidden" name="action" value="ajax_cmd">
158 - <input type="hidden" name="uid" value="'.$uid.'">
232 + <input type="hidden" name="uid" value="' . $uid . '">
159 233 <input type="hidden" name="cmd" value="{{{cmd}}}">{{{button}}}</form>';
160 234 $result = [];
161 235 $installedFile = wtsec_checkInstalledFile($_service);
162 - $runned = $status['active'];
236 + $disable_uninstall = false;
237 + $first_class = "ww-button--block ";
163 238
164 - if($service === "WAF"){
165 - $first_class = "";
166 - }else{
167 - $first_class = "ww-button--block ";
168 - }
169 - $disable_uninstall = false;
170 - if (!$installedFile['status']) {
171 - $cmd = $_service . '_install';
172 - $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'),$first_class."ww-button--success"),'cmd' => $cmd];
173 - } else {
174 - if($service === "WAF"){
175 - $url = $domain.'/?ping='.$installedFile['file'];
176 - }else{
177 - $url = $domain.'/'.$installedFile['file'];
178 - }
179 - $connected = wtsec_servicePing($service,$url);
180 - if (!$connected) {
181 - $disable_uninstall = false;
182 - $cmd = $_service . '_connect';
183 - $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('connect'),$first_class."ww-button--success"),'cmd' => $cmd];
239 + if ($service === "AM") {
240 + if (!$installedFile['status']) {
241 + $cmd = $_service . '_install';
242 + $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
184 243 } else {
185 - if ($runned) {
186 - $cmd = $_service . '_stop';
187 -// $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('stop'),"ww-button--primary"),'cmd' => $cmd];
188 - } else {
189 - $cmd = $_service . '_start';
190 -// $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('run'),"ww-button--primary"),'cmd' => $cmd];
244 +// $url = $domain.'/'.$installedFile['file'];
245 +// $connected = wtsec_servicePing($service,$url);
246 + if (!$disable_uninstall) {
247 + $cmd = $_service . '_uninstall';
248 + $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'), $first_class . "ww-button--attention"), 'cmd' => $cmd];
191 249 }
192 250 }
193 - if(!$disable_uninstall){
194 - $cmd = $_service . '_uninstall';
195 - $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'),$first_class."ww-button--attention"),'cmd' => $cmd];
251 + } else {
252 + if ($service === "WAF") {
253 + $first_class = "";
196 254 }
255 +
256 + if ($status === "not_installed") {
257 + $cmd = $_service . '_install';
258 + $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
259 + }
197 260 }
198 - foreach ($buttons as $btn){
261 +
262 +
263 + foreach ($buttons as $btn) {
199 264 $newform = $form;
200 - $newform = str_replace("{{{cmd}}}",$btn['cmd'],$newform);
201 - $newform = str_replace("{{{button}}}",$btn['button'],$newform);
265 + $newform = str_replace("{{{cmd}}}", $btn['cmd'], $newform);
266 + $newform = str_replace("{{{button}}}", $btn['button'], $newform);
202 267 $result[$btn['place']] = $newform;
203 268 }
204 269 return $result;
205 270 }
@@ -206,15 +271,16 @@
206 271
207 272 function wtsec_checkInstalledFile($service)
208 273 {
209 274 $file = wtsec_getInstalledFile($service);
210 - if($service == "waf"){
275 + if ($service == "waf") {
211 276 $root = WTSEC_INSTALLATION_DIR;
212 - }else{
277 + } else {
213 278 $root = ABSPATH;
214 279 }
215 - return ['status' => ((bool) $file) && is_file($root.$file),'file' => $file];
280 + return ['status' => ((bool)$file) && is_file($root . $file), 'file' => $file];
216 281 }
217 282
218 -function wtsec_getInstalledFile($service){
219 - return wtsec_app()->get($service."_installed_file");
283 +function wtsec_getInstalledFile($service)
284 +{
285 + return wtsec_app()->get($service . "_installed_file");
220 286 }