jasteele123

chmod_iterator.php

Aug 3rd, 2011
118
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 5.30 KB | None | 0 0
  1. <?php /* chmod_iterator.php - http://pastebin.com/e4bmbUi7 */
  2.  
  3. /**
  4. *    *** WARNING: Use at your own risk!!!  PASSWORD protect this file! ***
  5. *
  6. * Needs to be readable by the webserver, so make sure you protected it
  7. * properly.  Be nice to use HTTP Auth, SSL, *AND* the $_GET(['passwd']).
  8. * The GET password could be found in server access logs / browser history!
  9. *
  10. * I take *NO* resposibility if this blows up your server, empties your bank
  11. * account, steals your girlfriend and recks your car!  You have been WARNED!!!
  12. *
  13. * BACKUP YOUR DATA *first* through your control panel or any means possible!!!
  14. *
  15. *
  16. * This sets *ALL* files to 0664        (-rw-rw-r--)    chmod u=rw,g=rw,o=r
  17. * and *ALL* subdirectories to 0775    (drwxrwxr-x)    chmod u=rwx,g=rwx,o=rx
  18. *
  19. * meaning you do *not* want to use it on anything with the sticky bits set.
  20. * Possible Operation not permitted Warnings if the webserver is not owner.
  21. *
  22. * I built this script hastily to solve a problem where files and directories
  23. * owned by the webserver (often 'nobody') were unreadable by my
  24. * user/FTP/SSH account.  This can also happen often when changing servers.
  25. *
  26. * USAGE EXAMPLES:
  27. *    chmod_iterator.php?dir=.&passwd=yourpass
  28. *    chmod_iterator.php?dir=.&passwd=yourpass&verbose
  29. *    chmod_iterator.php?dir=uploads&passwd=yourpass
  30. *    chmod_iterator.php?dir=./concrete5/files&passwd=yourpass
  31. *
  32. * @param string $dir     required, cannot start with / nor have .. in it
  33. * @param string $passwd  required, must match the PASSWD below
  34. *     @see http://www.thebitmill.com/tools/password.html Password Generator
  35. * @param bool $verbose   optional, lists the user & files/dirs processed
  36. *
  37. * @author John Steele
  38. * @copyright Copyright (c) 2011, Steelesoft Consulting
  39. * @link http://www.steelesoftconsuting.com/ Steelesoft Consulting
  40. * @link http://www.concrete5.org/r/-/13433 concrete5 User jasteele123
  41. * @version 0.8 Beta 2011-07-15
  42. * @license http://opensource.org/licenses/gpl-license.php GNU Public License
  43. *
  44. * // TODO Integrate into concrete5 authentication / permissions
  45. * @todo Integrate into concrete5 authentication / permissions
  46. *
  47. * Requires PHP 5 since it uses the SPL (Standard PHP Library) Iterators()
  48. * If you are not familiar with it (you should be!)
  49. *     See:
  50. * @link http://www.php.net/manual/en/book.spl.php Standard PHP Library (SPL)
  51. * @link http://devzone.zend.com/article/2565 Zend Developer Zone
  52. * @link http://php.net/ stat(), posix_getpwuid() and fileperms() functions
  53. *
  54. */
  55.     // *** CHANGE THIS!!! ***        Avoid URL special characters!!!
  56. define('PASSWD', 'eAb1ZUNyoUG2cmXU');    // I used 16 Upper/Lower/Numbers
  57.  
  58.     // you *could* change these
  59. define('SERVR', 'nobody');                   // mess these octals up and KABLOOIE!!!
  60. define('FPERM', 0664);                   // (-rw-rw-r--)  chmod u=rw,g=rw,o=r
  61. define('DPERM', 0777);                   // (drwxrwxrwx)  chmod u=rwx,g=rwx,o=rx
  62.  
  63.  
  64. check_dir_die($dir = trim(@$_GET['dir']));
  65. check_passwd_die($passwd = trim(htmlentities(@$_GET['passwd'])));
  66. $verbose = isset($_GET['verbose']);
  67.  
  68. error_reporting(E_ALL);
  69. set_time_limit(0);
  70.  
  71. $total = 0;
  72. $total_errors = 0;
  73.  
  74. $iterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($dir),
  75.                       RecursiveIteratorIterator::SELF_FIRST);
  76. foreach($iterator as $item) {
  77.     clearstatcache();
  78.     $ss = @stat($item);                  // this can fail for many reasons @see stat()
  79.         // echo '$ss<xmp>'. print_r($ss, 1). '</xmp>';
  80.  
  81.     $owner = (function_exists('posix_getpwuid')) ? @posix_getpwuid($ss['uid']) : '';
  82.         // echo '$owner<xmp>'. print_r($owner, 1). '</xmp>';
  83.     $owner_name = ($ss['uid'] ? $owner['name'] : 'dir -x ? ');    // directory not executable?
  84.     /*
  85.     $fperms = fileperms($item) & 511;    // octal bitwise AND to get the lowest three
  86.     $fperms = sprintf('0%o', $fperms);
  87.     echo $item. ' '. $fperms. '<br />'. "\n";
  88.     */
  89.     if($verbose) {
  90.         echo (SERVR != $owner_name ? "<strong>$owner_name</strong>" : $owner_name);
  91.         echo "&nbsp; &nbsp; $item<br />\n";
  92.     }
  93.  
  94.     $mod = 0000;
  95.     if(SERVR == $owner['name']) {
  96.         if(!$type = filetype($item))
  97.             continue;
  98.         if('file' == $type)       $mod = FPERM;
  99.         elseif('dir' == $type)    $mod = DPERM;
  100.         if($mod) {
  101.             $total++;
  102.             if(!chmod($item, $mod))
  103.                 $total_errors++;
  104.             else
  105.                 clearstatcache();
  106.         }
  107.     }
  108. }
  109.  
  110. echo "<br />Total items processed: $total\n";
  111. echo "<br />$total_errors errors occurred.\n";
  112.  
  113. /**
  114. * Check that the $dir does not start with / or contain .. characters and
  115. * that it is not empty, exists and is readable - or DIE
  116. *
  117. * @param string $dir
  118. *
  119. */
  120. function check_dir_die($dir) {
  121.     if('/' == $dir[0] || ($pos = strpos($dir, '..')))
  122.         die('Illegal Directory! '. htmlentities($dir));
  123.     if(!$dir)                die('dir required.');
  124.     if(!is_dir($dir))        die('Directory does not exist: '. htmlentities($dir));
  125.     if(!is_readable($dir))   die('Directory is not readable: '. htmlentities($dir));
  126. }
  127.  
  128. /**
  129. * Check that the password is not empty and that it matches the PASSWD defined
  130. *
  131. * @param string $dir
  132. *
  133. */
  134. function check_passwd_die($passwd) {
  135.     if(!$passwd)            die('passwd required!');
  136.     if(PASSWD != $passwd)   die('Incorrect passwd!');
  137. }
  138. ?>
Advertisement
Add Comment
Please, Sign In to add comment