PluginProbe
WebTotem Security / 2.3.14
WebTotem Security v2.3.14
3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 2.2.4 All 109 releases
← All changes | services.php +249 -104 1.22.3.14 View file →
@@ -1,122 +1,201 @@
1 1 <?php defined('ABSPATH') or die("Protected By WT!");
2 2
3 -function wtsec_cmd($wp_filesystem,$cmd, $service, $_service, $uid, $status,$domain = ''){
3 +function wtsec_cmd($cmd, $service, $_service, $uid, $status, $domain = '')
4 +{
5 + global $wp_filesystem;
4 6
7 + //bug fix with wp file system, which return null
8 + if (empty($wp_filesystem)) {
9 + require_once(ABSPATH . '/wp-admin/includes/file.php');
10 + WP_Filesystem();
11 + }
12 +
13 + //retry checking
14 + if (empty($wp_filesystem)) {
15 + WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
16 + return false;
17 + }
18 +
5 19 switch ($cmd) {
6 20 case $_service . "_install":
7 21 try {
8 22 $file = wtsec_generateFile($uid, $service);
9 - if($service === "WAF"){
10 - $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
11 - $path = $plugin_path;
12 - $target_dir = $wp_filesystem->find_folder($path);
13 - if(!$wp_filesystem->is_dir($path)) {
14 - $wp_filesystem->mkdir($target_dir);
23 + if (is_null($file['name'])) {
24 + WTSEC_LIBRARY_Session::setNotification("error", wtsec_locale("failed_to_download_agent"));
25 + return false;
15 26 }
16 - $target_file = trailingslashit($target_dir).$file['name'];
17 - if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)){
18 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
19 - }else{
20 - wtsec_app()->set($_service . '_installed_file',$file['name']);
21 - }
22 - }else{
27 + if ($service === "WAF") {
28 + $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
29 + $path = $plugin_path;
30 + $target_dir = $wp_filesystem->find_folder($path);
31 + if (!$wp_filesystem->is_dir($path)) {
32 + $wp_filesystem->mkdir($target_dir);
33 + }
34 + $target_file = trailingslashit($target_dir) . $file['name'];
35 + if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)) {
36 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
37 + } else {
38 + wtsec_app()->set($_service . '_installed_file', $file['name']);
39 + }
40 + } else {
23 41 $target_dir = $wp_filesystem->find_folder($wp_filesystem->abspath());
24 - $target_file = trailingslashit($target_dir).$file['name'];
25 - if(!$wp_filesystem->put_contents($target_file, $file['file'])) {
26 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service,'directory' => $target_dir]));
27 - }else{
28 - wtsec_app()->set($_service . '_installed_file',$file['name']);
42 + $target_file = trailingslashit($target_dir) . $file['name'];
43 + if (!$wp_filesystem->put_contents($target_file, $file['file'])) {
44 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
45 + } else {
46 + wtsec_app()->set($_service . '_installed_file', $file['name']);
47 + if ($service === "AM") {
48 + wtsec_addCheckFile($file['name']);
49 + }
29 50 }
30 51 }
31 - wtsec_serviceConnect($uid, $service,$domain.'/'.$file['name']);
52 + if ($service !== "AM") {
53 + //wtsec_serviceConnect($uid, $service, $domain . '/' . $file['name']);
54 + }
32 55 } catch (Exception $e) {
33 - print_r($e->getMessage());
34 - die();
56 + WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
57 + return false;
35 58 }
36 59 break;
37 60 case $_service . "_start":
38 - WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
39 - wtsec_app()->set($_service.'_status',"start");
61 + WTSEC_LIBRARY_WT::changeStatus($status['config_id'], $uid);
62 + wtsec_app()->set($_service . '_status', "start");
40 63 break;
41 64 case $_service . "_stop":
42 65 // WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
43 - wtsec_app()->set($_service.'_status',"stop");
66 + wtsec_app()->set($_service . '_status', "stop");
44 67 break;
45 68 case $_service . "_connect":
46 69 $file = wtsec_getInstalledFile($_service);
47 70 if ($file) {
48 - wtsec_serviceConnect($uid, $service, $domain . '/' . $file);
49 - }else{
50 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
71 + //wtsec_serviceConnect($uid, $service, $domain . '/' . $file);
72 + } else {
73 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
51 74 }
52 75 break;
53 76 case $_service . "_uninstall":
54 77 try {
55 78 $file = wtsec_getInstalledFile($_service);
56 - if($service === "WAF"){
79 + if ($service === "WAF") {
57 80 $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
58 81 $mainDir = $plugin_path;
59 - }else{
82 + } else {
60 83 $mainDir = $wp_filesystem->abspath();
61 84 }
62 85 $target_dir = $wp_filesystem->find_folder($mainDir);
63 - $target_file = trailingslashit($mainDir).$file;
86 + $target_file = trailingslashit($mainDir) . $file;
64 87 if (!$wp_filesystem->delete($target_file)) {
65 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service,'directory' => $target_dir]));
88 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service, 'directory' => $target_dir]));
66 89 }
67 90 wtsec_app()->set($_service . '_status', "uninstalled");
68 91 WTSEC_LIBRARY_App::deleteOption($_service . '_installed_file');
69 92 } catch (Exception $e) {
70 - print_r($e->getMessage());
71 - die();
93 + WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
94 + return false;
72 95 }
73 96 break;
74 97 }
98 + return true;
75 99 }
76 100
101 +// Add check file if plugin is activated
102 +function wtsec_addCheckFile($name){
103 + global $wp_filesystem;
104 +
105 + if (empty($wp_filesystem)) {
106 + require_once(ABSPATH . '/wp-admin/includes/file.php');
107 + WP_Filesystem();
108 + }
109 +
110 + //retry checking
111 + if (empty($wp_filesystem)) {
112 + WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
113 + return false;
114 + }
115 +
116 + $target_dir = $wp_filesystem->find_folder(WTSEC_PLUGIN_PATH);
117 + $target_file = trailingslashit($target_dir) . 'generate.php';
118 +
119 + if ($wp_filesystem->put_contents($target_file, '<?php exit(); ?>'.$name, FS_CHMOD_FILE)) {
120 + return true;
121 + }
122 + return false;
123 +}
124 +
77 125 function wtsec_checkStatus($id, $service)
78 126 {
79 - $result = WTSEC_LIBRARY_WT::checkStatus($id,$service);
80 - $data = $result['data'][strtolower($service) . 'ServiceChecks'][0];
81 - $is_active = (boolean)$data['config']['isActive'];
82 - $config_id = $data['config']['id'];
83 - $status = $data['status'];
84 - if ($status == -300 && $is_active) {
85 - wtsec_app()->set($service . '_connected_' . $id, false);
127 + $service = ucfirst(strtolower($service));
128 + $is_active = null;
129 + $config_id = null;
130 + $result = WTSEC_LIBRARY_WT::checkStatus($id, $service);
131 + $data = $result['data']['auth']['viewer']['sites']['one']['configs'];
132 + foreach ($data as &$cfg) {
133 + if (!empty($cfg)) {
134 + $is_active = $cfg['isActive'];
135 + $config_id = $cfg['id'];
136 + }
86 137 }
87 - return ['active' => $is_active, 'status' => $status, 'config_id' => $config_id];
138 +
139 + if ($is_active === false) {
140 + wtsec_app()->set($service . '_connected_' . $id, true);
141 + }
142 + return ['active' => $is_active, 'config_id' => $config_id];
88 143 }
89 144
145 +function wtsec_generateFile($id, $service)
146 +{
147 + if ($service === "AM") {
148 + $result = WTSEC_LIBRARY_WT::generateAmFile($id);
149 + if (!isset($result['data']['auth']['am']['install'])) {
150 + $file = ['filename' => null, "body" => null];
151 + } else {
152 + $result = $result['data']['auth']['am']['install'];
90 153
154 + $url = $result['downloadLink'];
155 + $amFilename = $result['amFilename'];
156 + $wafFilename = $result['wafFilename'];
91 157
92 -function wtsec_generateFile($id, $service)
93 -{
94 - $result = WTSEC_LIBRARY_WT::generateFile($id,$service);
95 - $name = $result['data']['generateAgent']['agentName'] . '.' . strtolower($service) . '.php';
96 - $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
97 - if(empty($file)){
158 + if($wafFilename){
159 + wtsec_app()->set('waf_installed_file', $wafFilename);
160 + }
161 +
162 + $file = WTSEC_LIBRARY_WT::getFileByUrl($url, $amFilename);
163 + if (empty($file)) {
164 + $file = WTSEC_LIBRARY_WT::getFileByUrl($url, $amFilename);
165 + }
166 + }
167 +
168 + $name = $file["filename"];
169 + $file = $file["body"];
170 + } else {
171 + $result = WTSEC_LIBRARY_WT::generateFile($id, $service);
172 + $name = $result['data']['auth']['agents']['generate']['agentName'];
98 173 $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
174 + if (empty($file)) {
175 + $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
176 + }
99 177 }
178 +
100 179 return ['file' => $file, 'name' => $name];
101 180 }
102 181
103 -function wtsec_serviceConnect($id, $service,$domain = '')
182 +function wtsec_serviceConnect($id, $service, $domain = '')
104 183 {
105 - $result = WTSEC_LIBRARY_WT::serviceConnect($id,$service);
106 - $status = (isset($result['errors']) || isset($result['data']['checkAgent']['lockFor']) || (isset($result['data']['checkAgent']['installed']) && $result['data']['checkAgent']['installed'] === false)) ? false : true;
184 + $result = WTSEC_LIBRARY_WT::serviceConnect($id, $service);
185 + $status = isset($result['errors']) && !isset($result['data']['auth']['agents']['check']) ? false : true;
107 186 if (!$status) {
108 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
187 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
109 188 }
110 189 return $status;
111 190 }
112 191
113 192
114 -function wtsec_servicePing($service,$domain = '')
193 +function wtsec_servicePing($service, $domain = '')
115 194 {
116 - if($domain == NULL) return false;
117 - if(mb_stripos($domain,"http") === false){
118 - $domain = "http://".$domain;
195 + if ($domain == NULL) return false;
196 + if (stripos($domain, "http") === false) {
197 + $domain = "http://" . $domain;
119 198 }
120 199 $args = [
121 200 'timeout' => '10',
122 201 'sslverify' => false,
@@ -121,78 +200,131 @@
121 200 'timeout' => '10',
122 201 'sslverify' => false,
123 202 'redirection' => 3,
124 203 ];
125 - $response = wp_remote_get($domain,$args);
204 + $response = wp_remote_get($domain, $args);
126 205 $httpcode = wp_remote_retrieve_response_code($response);
127 - if($httpcode>=200 && $httpcode<400){
206 + if ($httpcode >= 200 && $httpcode < 400) {
128 207 return true;
129 208 } else {
130 - WTSEC_LIBRARY_Session::setNotification("warning",WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service,'site' => $domain]));
209 + WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
131 210 return false;
132 211 }
133 212 }
134 213
135 -function wtsec_button($label = '',$class = ''){
136 - return '<button class="ww-button '.$class.'">'.$label.'</button>';
214 +
215 +function wtsec_AVLogsData($logs){
216 + foreach ($logs as $key => $log){
217 + $log = $log['node'];
218 + $log['filePath'] = urldecode($log['filePath']);
219 + $log['text'] = (strlen($log['filePath']) > 40) ? substr($log['filePath'],0,40).'...' : $log['filePath'];
220 + $log['time'] = convertToCurrentTime($log['time']);
221 + $log['class_path'] = '';
222 + $log['class_info'] = '';
223 +
224 + if ($log['event'] === 'modified') {
225 + $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.normal");
226 + $log['class_path'] = "wtotem_file-table__td_changed";
227 + $log['class_info'] = "wtotem_file-table__td_normal";
228 + $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.changed");
229 + } elseif ($log['event'] === 'quarantine') {
230 + $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.backdoor_virus");
231 + $log['class_path'] = "wtotem_file-table__td_changed";
232 + $log['class_info'] = "wtotem_file-table__td_normal";
233 + $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.quarantine");
234 + } elseif ($log['event'] === 'infected') {
235 + $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.backdoor_virus");
236 + $log['class_path'] = "wtotem_file-table__td_critical";
237 + $log['class_info'] = "wtotem_file-table__td_critical";
238 + $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.infected");
239 + } elseif ($log['event'] === 'deleted') {
240 + $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.deleted");
241 + $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.deleted");
242 + }elseif ($log['event'] === 'new'){
243 + $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.normal");
244 + $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.new");
245 + }elseif ($log['event'] === 'scanned'){
246 + $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.normal");
247 + $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.scanned");
248 + }else{
249 + $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.error");
250 + $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.error");
251 + }
252 +
253 + $logs[$key]['node'] = $log;
254 + }
255 + return $logs;
137 256 }
138 257
139 -function wtsec_main_button($label = '',$class = ''){
140 - return '<button class="ww-button '.$class.'">'.$label.'</button>';
258 +function wtsec_getConfigs($host_id)
259 +{
260 + $config = WTSEC_LIBRARY_WT::getConfigs($host_id);
261 + return wtsec_arrayIndex($config['data']['auth']['viewer']['sites']['one']['configs'], 'service');
141 262 }
142 263
143 -function wtsec_generateButtons($uid,$_service, $service, $status,$domain = '')
264 +function wtsec_arrayIndex($array, $key){
265 + $newArray = [];
266 + foreach ($array as $item){
267 + if(array_key_exists($key,$item)){
268 + $newArray[$item[$key]] = $item;
269 + }
270 + }
271 + return $newArray;
272 +}
273 +
274 +function wtsec_button($label = '', $class = '')
144 275 {
276 + return '<button class="ww-button ' . $class . '">' . $label . '</button>';
277 +}
278 +
279 +function wtsec_main_button($label = '', $class = '')
280 +{
281 + return '<button class="ww-button ' . $class . '">' . $label . '</button>';
282 +}
283 +
284 +function wtsec_generateButtons($uid, $_service, $service, $status, $domain = '')
285 +{
145 286 $url = esc_url(admin_url('admin-post.php'));
146 287 $buttons = [];
147 288
148 - $form = '<form action="'.$url.'" method="post" style="display:inline-block;">
149 - <input type="hidden" name="service" value="'.$_service.'">
289 + $form = '<form action="' . $url . '" method="post" style="display:inline-block;">
290 + <input type="hidden" name="service" value="' . $_service . '">
150 291 <input type="hidden" name="action" value="ajax_cmd">
151 - <input type="hidden" name="uid" value="'.$uid.'">
292 + <input type="hidden" name="uid" value="' . $uid . '">
152 293 <input type="hidden" name="cmd" value="{{{cmd}}}">{{{button}}}</form>';
153 294 $result = [];
154 295 $installedFile = wtsec_checkInstalledFile($_service);
155 - $runned = $status['active'];
296 + $disable_uninstall = false;
297 + $first_class = "ww-button--block ";
156 298
157 - if($service === "WAF"){
158 - $first_class = "";
159 - }else{
160 - $first_class = "ww-button--block ";
161 - }
162 - $disable_uninstall = false;
163 - if (!$installedFile['status']) {
164 - $cmd = $_service . '_install';
165 - $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'),$first_class."ww-button--success"),'cmd' => $cmd];
166 - } else {
167 - if($service === "WAF"){
168 - $url = $domain.'/?ping='.$installedFile['file'];
169 - }else{
170 - $url = $domain.'/'.$installedFile['file'];
171 - }
172 - $connected = wtsec_servicePing($service,$url);
173 - if (!$connected) {
174 - $disable_uninstall = false;
175 - $cmd = $_service . '_connect';
176 - $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('connect'),$first_class."ww-button--success"),'cmd' => $cmd];
299 + if ($service === "AM") {
300 + if (!$installedFile['status']) {
301 + $cmd = $_service . '_install';
302 + $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
177 303 } else {
178 - if ($runned) {
179 - $cmd = $_service . '_stop';
180 -// $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('stop'),"ww-button--primary"),'cmd' => $cmd];
181 - } else {
182 - $cmd = $_service . '_start';
183 -// $buttons[] = ['place' => 'second','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('run'),"ww-button--primary"),'cmd' => $cmd];
304 +// $url = $domain.'/'.$installedFile['file'];
305 +// $connected = wtsec_servicePing($service,$url);
306 + if (!$disable_uninstall) {
307 + $cmd = $_service . '_uninstall';
308 + $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'), $first_class . "ww-button--attention"), 'cmd' => $cmd];
184 309 }
185 310 }
186 - if(!$disable_uninstall){
187 - $cmd = $_service . '_uninstall';
188 - $buttons[] = ['place' => 'first','button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'),$first_class."ww-button--attention"),'cmd' => $cmd];
311 + } else {
312 + if ($service === "WAF") {
313 + $first_class = "";
189 314 }
315 +
316 + if ($status === "not_installed") {
317 + $cmd = $_service . '_install';
318 + $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
319 + }
190 320 }
191 - foreach ($buttons as $btn){
321 +
322 +
323 + foreach ($buttons as $btn) {
192 324 $newform = $form;
193 - $newform = str_replace("{{{cmd}}}",$btn['cmd'],$newform);
194 - $newform = str_replace("{{{button}}}",$btn['button'],$newform);
325 + $newform = str_replace("{{{cmd}}}", $btn['cmd'], $newform);
326 + $newform = str_replace("{{{button}}}", $btn['button'], $newform);
195 327 $result[$btn['place']] = $newform;
196 328 }
197 329 return $result;
198 330 }
@@ -199,10 +331,23 @@
199 331
200 332 function wtsec_checkInstalledFile($service)
201 333 {
202 334 $file = wtsec_getInstalledFile($service);
203 - return ['status' => (bool) $file,'file' => $file];
335 + if ($service == "waf") {
336 + $root = WTSEC_INSTALLATION_DIR;
337 + } else {
338 + $root = ABSPATH;
339 + }
340 + return ['status' => ((bool)$file) && is_file($root . $file), 'file' => $file];
204 341 }
205 342
206 -function wtsec_getInstalledFile($service){
207 - return wtsec_app()->get($service."_installed_file");
208 -}
343 +function wtsec_getInstalledFile($service)
344 +{
345 + return wtsec_app()->get($service . "_installed_file");
346 +}
347 +
348 +function wtsec_DeleteAm(){
349 + $host = WTSEC_LIBRARY_WT::getOwnSite();
350 + if(!empty($host)){
351 + WTSEC_LIBRARY_WT::deleteAm($host['id']);
352 + }
353 +}