Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php /* chmod_iterator.php - http://pastebin.com/e4bmbUi7 */
- /**
- * *** WARNING: Use at your own risk!!! PASSWORD protect this file! ***
- *
- * Needs to be readable by the webserver, so make sure you protected it
- * properly. Be nice to use HTTP Auth, SSL, *AND* the $_GET(['passwd']).
- * The GET password could be found in server access logs / browser history!
- *
- * I take *NO* resposibility if this blows up your server, empties your bank
- * account, steals your girlfriend and recks your car! You have been WARNED!!!
- *
- * BACKUP YOUR DATA *first* through your control panel or any means possible!!!
- *
- *
- * This sets *ALL* files to 0664 (-rw-rw-r--) chmod u=rw,g=rw,o=r
- * and *ALL* subdirectories to 0775 (drwxrwxr-x) chmod u=rwx,g=rwx,o=rx
- *
- * meaning you do *not* want to use it on anything with the sticky bits set.
- * Possible Operation not permitted Warnings if the webserver is not owner.
- *
- * I built this script hastily to solve a problem where files and directories
- * owned by the webserver (often 'nobody') were unreadable by my
- * user/FTP/SSH account. This can also happen often when changing servers.
- *
- * USAGE EXAMPLES:
- * chmod_iterator.php?dir=.&passwd=yourpass
- * chmod_iterator.php?dir=.&passwd=yourpass&verbose
- * chmod_iterator.php?dir=uploads&passwd=yourpass
- * chmod_iterator.php?dir=./concrete5/files&passwd=yourpass
- *
- * @param string $dir required, cannot start with / nor have .. in it
- * @param string $passwd required, must match the PASSWD below
- * @see http://www.thebitmill.com/tools/password.html Password Generator
- * @param bool $verbose optional, lists the user & files/dirs processed
- *
- * @author John Steele
- * @copyright Copyright (c) 2011, Steelesoft Consulting
- * @link http://www.steelesoftconsuting.com/ Steelesoft Consulting
- * @link http://www.concrete5.org/r/-/13433 concrete5 User jasteele123
- * @version 0.8 Beta 2011-07-15
- * @license http://opensource.org/licenses/gpl-license.php GNU Public License
- *
- * // TODO Integrate into concrete5 authentication / permissions
- * @todo Integrate into concrete5 authentication / permissions
- *
- * Requires PHP 5 since it uses the SPL (Standard PHP Library) Iterators()
- * If you are not familiar with it (you should be!)
- * See:
- * @link http://www.php.net/manual/en/book.spl.php Standard PHP Library (SPL)
- * @link http://devzone.zend.com/article/2565 Zend Developer Zone
- * @link http://php.net/ stat(), posix_getpwuid() and fileperms() functions
- *
- */
- // *** CHANGE THIS!!! *** Avoid URL special characters!!!
- define('PASSWD', 'eAb1ZUNyoUG2cmXU'); // I used 16 Upper/Lower/Numbers
- // you *could* change these
- define('SERVR', 'nobody'); // mess these octals up and KABLOOIE!!!
- define('FPERM', 0664); // (-rw-rw-r--) chmod u=rw,g=rw,o=r
- define('DPERM', 0777); // (drwxrwxrwx) chmod u=rwx,g=rwx,o=rx
- check_dir_die($dir = trim(@$_GET['dir']));
- check_passwd_die($passwd = trim(htmlentities(@$_GET['passwd'])));
- $verbose = isset($_GET['verbose']);
- error_reporting(E_ALL);
- set_time_limit(0);
- $total = 0;
- $total_errors = 0;
- $iterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($dir),
- RecursiveIteratorIterator::SELF_FIRST);
- foreach($iterator as $item) {
- clearstatcache();
- $ss = @stat($item); // this can fail for many reasons @see stat()
- // echo '$ss<xmp>'. print_r($ss, 1). '</xmp>';
- $owner = (function_exists('posix_getpwuid')) ? @posix_getpwuid($ss['uid']) : '';
- // echo '$owner<xmp>'. print_r($owner, 1). '</xmp>';
- $owner_name = ($ss['uid'] ? $owner['name'] : 'dir -x ? '); // directory not executable?
- /*
- $fperms = fileperms($item) & 511; // octal bitwise AND to get the lowest three
- $fperms = sprintf('0%o', $fperms);
- echo $item. ' '. $fperms. '<br />'. "\n";
- */
- if($verbose) {
- echo (SERVR != $owner_name ? "<strong>$owner_name</strong>" : $owner_name);
- echo " $item<br />\n";
- }
- $mod = 0000;
- if(SERVR == $owner['name']) {
- if(!$type = filetype($item))
- continue;
- if('file' == $type) $mod = FPERM;
- elseif('dir' == $type) $mod = DPERM;
- if($mod) {
- $total++;
- if(!chmod($item, $mod))
- $total_errors++;
- else
- clearstatcache();
- }
- }
- }
- echo "<br />Total items processed: $total\n";
- echo "<br />$total_errors errors occurred.\n";
- /**
- * Check that the $dir does not start with / or contain .. characters and
- * that it is not empty, exists and is readable - or DIE
- *
- * @param string $dir
- *
- */
- function check_dir_die($dir) {
- if('/' == $dir[0] || ($pos = strpos($dir, '..')))
- die('Illegal Directory! '. htmlentities($dir));
- if(!$dir) die('dir required.');
- if(!is_dir($dir)) die('Directory does not exist: '. htmlentities($dir));
- if(!is_readable($dir)) die('Directory is not readable: '. htmlentities($dir));
- }
- /**
- * Check that the password is not empty and that it matches the PASSWD defined
- *
- * @param string $dir
- *
- */
- function check_passwd_die($passwd) {
- if(!$passwd) die('passwd required!');
- if(PASSWD != $passwd) die('Incorrect passwd!');
- }
- ?>
Advertisement
Add Comment
Please, Sign In to add comment