PluginProbe
WebTotem Security / 2.3.23
WebTotem Security v2.3.23
3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 2.2.4 All 109 releases
wt-security / services.php

services.php in WebTotem Security 2.3.23, at services.php

354 lines 13.8 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php defined('ABSPATH') or die("Protected By WT!");
2
3 function wtsec_cmd($cmd, $service, $_service, $uid, $status, $domain = '')
4 {
5 global $wp_filesystem;
6
7 //bug fix with wp file system, which return null
8 if (empty($wp_filesystem)) {
9 require_once(ABSPATH . '/wp-admin/includes/file.php');
10 WP_Filesystem();
11 }
12
13 //retry checking
14 if (empty($wp_filesystem)) {
15 WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
16 return false;
17 }
18
19 switch ($cmd) {
20 case $_service . "_install":
21 try {
22 $file = wtsec_generateFile($uid, $service);
23 if (is_null($file['name'])) {
24 WTSEC_LIBRARY_Session::setNotification("error", wtsec_locale("failed_to_download_agent"));
25 return false;
26 }
27 if ($service === "WAF") {
28 $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
29 $path = $plugin_path;
30 $target_dir = $wp_filesystem->find_folder($path);
31 if (!$wp_filesystem->is_dir($path)) {
32 $wp_filesystem->mkdir($target_dir);
33 }
34 $target_file = trailingslashit($target_dir) . $file['name'];
35 if (!$wp_filesystem->put_contents($target_file, $file['file'], FS_CHMOD_FILE)) {
36 WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
37 } else {
38 wtsec_app()->set($_service . '_installed_file', $file['name']);
39 }
40 } else {
41 $target_dir = $wp_filesystem->find_folder($wp_filesystem->abspath());
42 $target_file = trailingslashit($target_dir) . $file['name'];
43 if (!$wp_filesystem->put_contents($target_file, $file['file'])) {
44 WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_install_file', ['service' => $service, 'directory' => $target_dir]));
45 } else {
46 wtsec_app()->set($_service . '_installed_file', $file['name']);
47 if ($service === "AM") {
48 wtsec_addCheckFile($file['name']);
49 }
50 }
51 }
52 if ($service !== "AM") {
53 //wtsec_serviceConnect($uid, $service, $domain . '/' . $file['name']);
54 }
55 } catch (Exception $e) {
56 WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
57 return false;
58 }
59 break;
60 case $_service . "_start":
61 WTSEC_LIBRARY_WT::changeStatus($status['config_id'], $uid);
62 wtsec_app()->set($_service . '_status', "start");
63 break;
64 case $_service . "_stop":
65 // WTSEC_LIBRARY_WT::changeStatus($status['config_id'],$uid);
66 wtsec_app()->set($_service . '_status', "stop");
67 break;
68 case $_service . "_connect":
69 $file = wtsec_getInstalledFile($_service);
70 if ($file) {
71 //wtsec_serviceConnect($uid, $service, $domain . '/' . $file);
72 } else {
73 WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('file_not_found', ['service' => $service]));
74 }
75 break;
76 case $_service . "_uninstall":
77 try {
78 $file = wtsec_getInstalledFile($_service);
79 if ($service === "WAF") {
80 $plugin_path = str_replace(ABSPATH, $wp_filesystem->abspath(), WTSEC_INSTALLATION_DIR);
81 $mainDir = $plugin_path;
82 } else {
83 $mainDir = $wp_filesystem->abspath();
84 }
85 $target_dir = $wp_filesystem->find_folder($mainDir);
86 $target_file = trailingslashit($mainDir) . $file;
87 if (!$wp_filesystem->delete($target_file)) {
88 WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('could_not_uninstall_file', ['service' => $service, 'directory' => $target_dir]));
89 }
90 wtsec_app()->set($_service . '_status', "uninstalled");
91 WTSEC_LIBRARY_App::deleteOption($_service . '_installed_file');
92 } catch (Exception $e) {
93 WTSEC_LIBRARY_Session::setNotification("error", $e->getMessage());
94 return false;
95 }
96 break;
97 }
98 return true;
99 }
100
101 // Add check file if plugin is activated
102 function wtsec_addCheckFile($name){
103 global $wp_filesystem;
104
105 if (empty($wp_filesystem)) {
106 require_once(ABSPATH . '/wp-admin/includes/file.php');
107 WP_Filesystem();
108 }
109
110 //retry checking
111 if (empty($wp_filesystem)) {
112 WTSEC_LIBRARY_Session::setNotification("error", "WP FileSystem path error");
113 return false;
114 }
115
116 $target_dir = $wp_filesystem->find_folder(WTSEC_PLUGIN_PATH);
117 $target_file = trailingslashit($target_dir) . 'generate.php';
118
119 if ($wp_filesystem->put_contents($target_file, '<?php exit(); ?>'.$name, FS_CHMOD_FILE)) {
120 return true;
121 }
122 return false;
123 }
124
125 function wtsec_checkStatus($id, $service)
126 {
127 $service = ucfirst(strtolower($service));
128 $is_active = null;
129 $config_id = null;
130 $result = WTSEC_LIBRARY_WT::checkStatus($id, $service);
131 $data = $result['data']['auth']['viewer']['sites']['one']['configs'];
132 foreach ($data as &$cfg) {
133 if (!empty($cfg)) {
134 $is_active = $cfg['isActive'];
135 $config_id = $cfg['id'];
136 }
137 }
138
139
140 return ['active' => $is_active, 'config_id' => $config_id];
141 }
142
143 function wtsec_generateFile($id, $service)
144 {
145 if ($service === "AM") {
146 $result = WTSEC_LIBRARY_WT::generateAmFile($id);
147 if (!isset($result['data']['auth']['am']['install'])) {
148 $file = ['filename' => null, "body" => null];
149 } else {
150 $result = $result['data']['auth']['am']['install'];
151
152 $url = $result['downloadLink'];
153 $amFilename = $result['amFilename'];
154 $wafFilename = $result['wafFilename'];
155
156 if($wafFilename){
157 wtsec_app()->set('waf_installed_file', $wafFilename);
158 }
159
160 $file = WTSEC_LIBRARY_WT::getFileByUrl($url, $amFilename);
161 if (empty($file)) {
162 $file = WTSEC_LIBRARY_WT::getFileByUrl($url, $amFilename);
163 }
164 }
165
166 $name = $file["filename"];
167 $file = $file["body"];
168 } else {
169 $result = WTSEC_LIBRARY_WT::generateFile($id, $service);
170 $name = $result['data']['auth']['agents']['generate']['agentName'];
171 $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
172 if (empty($file)) {
173 $file = WTSEC_LIBRARY_WT::requestURL(WTSEC_FILE_URL . '/' . $name);
174 }
175 }
176
177 return ['file' => $file, 'name' => $name];
178 }
179
180 function wtsec_serviceConnect($id, $service, $domain = '')
181 {
182 $result = WTSEC_LIBRARY_WT::serviceConnect($id, $service);
183 $status = isset($result['errors']) && !isset($result['data']['auth']['agents']['check']) ? false : true;
184 if (!$status) {
185 WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
186 }
187 return $status;
188 }
189
190
191 function wtsec_servicePing($service, $domain = '')
192 {
193 if ($domain == NULL) return false;
194 if (stripos($domain, "http") === false) {
195 $domain = "http://" . $domain;
196 }
197 $args = [
198 'timeout' => '10',
199 'sslverify' => false,
200 'redirection' => 3,
201 ];
202 $response = wp_remote_get($domain, $args);
203 $httpcode = wp_remote_retrieve_response_code($response);
204 if ($httpcode >= 200 && $httpcode < 400) {
205 return true;
206 } else {
207 WTSEC_LIBRARY_Session::setNotification("warning", WTSEC_LIBRARY_Localization::lmsg('unable_to_connect_to_service', ['service' => $service, 'site' => $domain]));
208 return false;
209 }
210 }
211
212
213 function wtsec_AVLogsData($logs){
214 foreach ($logs as $key => $log){
215 $log = $log['node'];
216 $log['filePath'] = urldecode($log['filePath']);
217 $log['text'] = (strlen($log['filePath']) > 40) ? substr($log['filePath'],0,40).'...' : $log['filePath'];
218 $log['time'] = convertToCurrentTime($log['time']);
219 $log['class_path'] = '';
220 $log['class_info'] = '';
221
222 if ($log['event'] === 'modified') {
223 $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.normal");
224 $log['class_path'] = "wtotem_file-table__td_changed";
225 $log['class_info'] = "wtotem_file-table__td_normal";
226 $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.changed");
227 } elseif ($log['event'] === 'quarantine') {
228 $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.backdoor_virus");
229 $log['class_path'] = "wtotem_file-table__td_changed";
230 $log['class_info'] = "wtotem_file-table__td_normal";
231 $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.quarantine");
232 } elseif ($log['event'] === 'infected') {
233 $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.backdoor_virus");
234 $log['class_path'] = "wtotem_file-table__td_critical";
235 $log['class_info'] = "wtotem_file-table__td_critical";
236 $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.infected");
237 } elseif ($log['event'] === 'deleted') {
238 $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.deleted");
239 $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.deleted");
240 }elseif ($log['event'] === 'new'){
241 $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.normal");
242 $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.new");
243 }elseif ($log['event'] === 'scanned'){
244 $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.info.normal");
245 $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.scanned");
246 }else{
247 $log['info'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.error");
248 $log['description'] = WTSEC_LIBRARY_Localization::lmsg("antivirus.status.error");
249 }
250
251 $logs[$key]['node'] = $log;
252 }
253 return $logs;
254 }
255
256 function wtsec_getConfigs($host_id)
257 {
258 $config = WTSEC_LIBRARY_WT::getConfigs($host_id);
259 return wtsec_arrayIndex($config['data']['auth']['viewer']['sites']['one']['configs'], 'service');
260 }
261
262 function wtsec_arrayIndex($array, $key){
263 $newArray = [];
264 foreach ($array as $item){
265 if(array_key_exists($key,$item)){
266 $newArray[$item[$key]] = $item;
267 }
268 }
269 return $newArray;
270 }
271
272 function wtsec_button($label = '', $class = '')
273 {
274 return '<button class="ww-button ' . $class . '">' . $label . '</button>';
275 }
276
277 function wtsec_main_button($label = '', $class = '')
278 {
279 return '<button class="ww-button ' . $class . '">' . $label . '</button>';
280 }
281
282 function wtsec_generateButtons($uid, $_service, $service, $status, $domain = '')
283 {
284 $url = esc_url(admin_url('admin-post.php'));
285 $buttons = [];
286
287 $form = '<form action="' . $url . '" method="post" style="display:inline-block;">
288 <input type="hidden" name="service" value="' . $_service . '">
289 <input type="hidden" name="action" value="ajax_cmd">
290 <input type="hidden" name="uid" value="' . $uid . '">
291 <input type="hidden" name="cmd" value="{{{cmd}}}">{{{button}}}</form>';
292 $result = [];
293 $installedFile = wtsec_checkInstalledFile($_service);
294 $disable_uninstall = false;
295 $first_class = "ww-button--block ";
296
297 if ($service === "AM") {
298 if (!$installedFile['status']) {
299 $cmd = $_service . '_install';
300 $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
301 } else {
302 // $url = $domain.'/'.$installedFile['file'];
303 // $connected = wtsec_servicePing($service,$url);
304 if (!$disable_uninstall) {
305 $cmd = $_service . '_uninstall';
306 $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('uninstall'), $first_class . "ww-button--attention"), 'cmd' => $cmd];
307 }
308 }
309 } else {
310 if ($service === "WAF") {
311 $first_class = "";
312 }
313
314 if ($status === "not_installed") {
315 $cmd = $_service . '_install';
316 $buttons[] = ['place' => 'first', 'button' => wtsec_button(WTSEC_LIBRARY_Localization::lmsg('install'), $first_class . "ww-button--success"), 'cmd' => $cmd];
317 }
318 }
319
320
321 foreach ($buttons as $btn) {
322 $newform = $form;
323 $newform = str_replace("{{{cmd}}}", $btn['cmd'], $newform);
324 $newform = str_replace("{{{button}}}", $btn['button'], $newform);
325 $result[$btn['place']] = $newform;
326 }
327 return $result;
328 }
329
330 function wtsec_checkInstalledFile($service)
331 {
332 $file = wtsec_getInstalledFile($service);
333 if ($service == "waf") {
334 $root = WTSEC_INSTALLATION_DIR;
335 } else {
336 $root = ABSPATH;
337 }
338 return ['status' => ((bool)$file) && is_file($root . $file), 'file' => $file];
339 }
340
341 function wtsec_getInstalledFile($service)
342 {
343 return wtsec_app()->get($service . "_installed_file");
344 }
345
346 function wtsec_DeleteAm(){
347 $host = WTSEC_LIBRARY_WT::getOwnSite();
348 if(!empty($host)) {
349 WTSEC_LIBRARY_WT::deleteAm($host['id']);
350 return true;
351 }
352 return false;
353 }
354