PalmaSolutions

old SL installer

Nov 2nd, 2018
6,802
0
Never
2
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Perl 17.37 KB | None | 0 0
  1. #!/usr/bin/perl
  2.  
  3. use CGI;
  4. use File::Path qw(mkpath rmtree);
  5.  
  6. BEGIN {
  7.     $SIG{__DIE__} = sub {
  8.         my $msg = shift;
  9.         print "Status: 500\n";
  10.         print "Content-type: text/html\n\n";
  11.         $msg =~ s/\n/\0/g;
  12.         print "error: $msg\n";
  13.         CORE::die $msg;
  14.     }
  15. }
  16.  
  17. $| = 1;
  18. our $q = CGI->new;
  19.  
  20. print "Content-type: text/html\n\n";
  21.  
  22. if ($q->param('task') eq 'detect_redirect') {
  23.     print '1';
  24.     exit;
  25. }
  26.  
  27. if ($q->param('task') eq 'exists_securelive_max_archive') {
  28.     my $username = $q->param('user');
  29.     die('No username was provided') unless $username;
  30.     die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
  31.  
  32.     print -e "/home/$username/securelive_max.tar.bz2";
  33.     exit;
  34. }
  35.  
  36. if ($q->param('task') eq 'extract_securelive_max_archive') {
  37.     my $username = $q->param('user');
  38.     die('No username was provided') unless $username;
  39.     die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
  40.  
  41.     my $cmd = `tar -jxvf ./securelive_max.tar.bz2 -C /home/$username 2>&1`;
  42.     print $cmd;
  43.     &site_chmod("/home/$username/securelive_max", 1);
  44.     exit;
  45. }
  46.  
  47. if ($q->param('task') eq 'delete_securelive_max_archive') {
  48.     my $username = $q->param('user');
  49.     die('No username was provided') unless $username;
  50.     die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
  51.  
  52.     my $del = unlink("/home/$username/securelive_max.tar.bz2");
  53.     die("Could not delete /home/$username/securelive_max.tar.bz2: $!") unless $del;
  54.     exit;
  55. }
  56.  
  57. if ($q->param('task') eq 'exists_securelive_max_directory') {
  58.     my $username = $q->param('user');
  59.     die('No username was provided') unless $username;
  60.     die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
  61.  
  62.     print -e "/home/$username/securelive_max";
  63.     exit;
  64. }
  65.  
  66. if ($q->param('task') eq 'delete_securelive_max_directory') {
  67.     my $username = $q->param('user');
  68.     die('No username was provided') unless $username;
  69.     die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
  70.  
  71.     rmtree("/home/$username/securelive_max", {verbose => 1});
  72.     exit;
  73. }
  74.  
  75. if ($q->param('task') eq 'extract_sl_admin_archive') {
  76.     my $username = $q->param('user');
  77.     die('No username was provided') unless $username;
  78.     die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
  79.     my $directory = $q->param('directory');
  80.     die('No directory was provided') unless $directory;
  81.     mkpath("/home/$username/$directory", {verbose => 1}) unless -e "/home/$username/$directory";
  82.  
  83.     my $cmd = `tar -jxvf ./sl_admin.tar.bz2 -C /home/$username/$directory 2>&1`;
  84.     print $cmd;
  85.     &disable_mod_security("/home/$username/$directory/sl_admin");
  86.     &site_chmod("/home/$username/$directory/sl_admin", 1);
  87.     exit;
  88. }
  89.  
  90. if ($q->param('task') eq 'delete_sl_admin_archive') {
  91.     my $username = $q->param('user');
  92.     die('No username was provided') unless $username;
  93.     die('Username is invalid') unless $username =~ /^[A-Za-z0-9]+$/;
  94.  
  95.     my $del = unlink("/home/$username/sl_admin.tar.bz2");
  96.     die("Could not delete /home/$username/sl_admin.tar.bz2: $!") unless $del;
  97.     exit;
  98. }
  99.  
  100. if ($q->param('task') eq 'delete_sl_admin_directory') {
  101.     my $username = $q->param('user');
  102.     die('No username was provided') unless $username;
  103.     die("Username ($username) is invalid") unless $username =~ /^[A-Za-z0-9]+$/;
  104.     my $directory = $q->param('directory');
  105.     die('No directory was provided') unless $directory;
  106.     die("directory (/home/$username/$directory) is invalid") unless -e "/home/$username/$directory";
  107.  
  108.     rmtree("/home/$username/$directory/sl_admin", {verbose => 1});
  109.     exit;
  110. }
  111.  
  112. if ($q->param('task') eq 'delete_self') {
  113.     my $del = unlink($ENV{'SCRIPT_FILENAME'});
  114.     die("Could not delete $ENV{'SCRIPT_FILENAME'}: $!") unless $del;
  115.     exit;
  116. }
  117.  
  118. if ($q->param('task') eq 'configure_install') {
  119.     my $directory = $q->param('directory');
  120.     my $user = $q->param('user');
  121.     my $domain = $q->param('domain');
  122.  
  123.     my $unified_directory = "/home/$user/$directory";
  124.     $unified_directory =~ s/\/\//\//g;
  125.  
  126.     &create_authenticator($user);
  127.  
  128.     if (-e  "$unified_directory/.htaccess") {
  129.         &install_htaccess($unified_directory, $user, 1);
  130.     }
  131.     else {
  132.         my $fh;
  133.         open ($fh, '>', "$unified_directory/.htaccess") || die($!);
  134.         print $fh "<IfModule mod_suphp.c>\n";
  135.         print $fh "\tsuPHP_ConfigPath $unified_directory\n";
  136.         print $fh "</IfModule>\n";
  137.         print $fh "AddHandler application/x-httpd-php5 .php5 .php4 .php .php3 .php2 .phtml\n" unless -e '/opt/hosting/VERSION'; # LPCP servers are all PHP 5
  138.         close $fh;
  139.         &install_php_ini($unified_directory, $user, "$unified_directory/.htaccess");
  140.     }
  141.  
  142.     foreach my $entry (&find_htaccess($unified_directory)) {
  143.         next unless $entry;
  144.         &install_htaccess($entry, $user, 0);
  145.     }
  146.     exit;
  147. }
  148.  
  149. if ($q->param('task') eq 'configure_delete') {
  150.     my $directory = $q->param('directory');
  151.     my $user = $q->param('user');
  152.     my @exclude = $q->param('exclude_path');
  153.     my $unified_directory = "/home/$user/$directory";
  154.     $unified_directory =~ s/\/\//\//g;
  155.  
  156.     foreach my $entry (&find_htaccess($unified_directory)) {
  157.         next unless $entry;
  158.         my $safe_path = 1;
  159.         foreach my $path (@exclude_path) {
  160.             $safe_path = 0 if $entry =~ /$path/;
  161.         }
  162.         &delete_htaccess($entry, $user) if $safe_path;
  163.     }
  164.     exit;
  165. }
  166.  
  167. if ($q->param('task') eq 'enable_domain') {
  168.     my $user = $q->param('user');
  169.     my $domain = $q->param('domain');
  170.  
  171.     &enable_domain($user, $domain);
  172.     exit;
  173. }
  174.  
  175. if ($q->param('task') eq 'delete_domain') {
  176.     my $user = $q->param('user');
  177.     my $domain = $q->param('domain');
  178.  
  179.     &delete_domain($user, $domain);
  180.     exit;
  181. }
  182.  
  183. sub disable_mod_security {
  184.     my ($dir) = @_;
  185.  
  186.     my $fh;
  187.     open ($fh, '>>', "$dir/.htaccess") || die($!);
  188.     print $fh "RewriteEngine off\n";
  189.     print $fh "<IfModule mod_security.c>\n";
  190.     print $fh "\tSecFilterEngine Off\n";
  191.     print $fh "\tSecFilterScanPOST Off\n";
  192.     print $fh "</IfModule>\n";
  193.     close $fh;
  194. }
  195.  
  196. sub site_chmod {
  197.     my ($start_dir, $chmod_start) = @_;
  198.     opendir(DIR, $start_dir) || die "$start_dir: $!";
  199.         my @files = grep {!-d "$start_dir\/$_"} readdir(DIR);
  200.     closedir DIR;
  201.     opendir(DIR, $start_dir) || die "$start_dir: $!";
  202.         my @folders = grep {-d "$start_dir\/$_"} readdir(DIR);
  203.     closedir DIR;
  204.  
  205.     if ($chmod_start) {
  206.         chmod 0755, $start_dir;
  207.     }
  208.  
  209.     foreach my $file (sort @files) {
  210.         $file =~ s/\"/\\\"/i;
  211.         $file = "$start_dir\/$file";
  212.         if ($file =~ /\.pl$/ || $file =~ /\.cgi$/) {
  213.             chmod 0755, $file;
  214.         }
  215.         else {
  216.             chmod 0644, $file;
  217.         }
  218.     }
  219.     foreach my $folder (sort @folders) {
  220.         if ($folder !~ /^\.\.?$/) {
  221.             $folder =~ s/\"/\\\"/i;
  222.             $folder = "$start_dir\/$folder";
  223.             chmod 0755, $folder;
  224.             &site_chmod($folder, 0);
  225.         }
  226.     }
  227. }
  228.  
  229. sub find_htaccess {
  230.     my ($start_dir) = @_;
  231.     print "information: Scanning for additional .htaccess files\n";
  232.     my @htaccess = &dir ($start_dir);
  233.     print "information: Scan for additional .htaccess files complete\n";
  234.     return @htaccess;
  235. }
  236.  
  237. sub enable_domain {
  238.     my ($user, $domain) = @_;
  239.     my $file = "/home/$user/securelive_max/lunarpages.php";
  240.     my $fh;
  241.  
  242.     unless (-e $file) {
  243.         &create_authenticator($user);
  244.     }
  245.  
  246.     chmod 0644, $file;
  247.  
  248.     open($fh, "<$file") || die("Unable to open $file: $!");
  249.     my @lines = <$fh>;
  250.     close ($fh);
  251.     foreach (@lines) {
  252.         next unless $_ =~ /\$domains = array\((.*?)\)/;
  253.         my @domains = split(/,\s?/, $1);
  254.         my $found = 0;
  255.            
  256.         foreach my $entry (@domains) {
  257.             $entry =~ s/\"//g;
  258.             $found = 1 if $entry eq $domain;
  259.             $entry = "\"$entry\"";
  260.             last if $found;
  261.         }
  262.            
  263.         push (@domains, "\"$domain\"") unless $found;
  264.         $_ = '$domains = array(' . join(',', sort(@domains)) . ');' . "\n";
  265.     }
  266.  
  267.     open($fh, ">$file") || die("Unable to open $file: $!");
  268.     print $fh join('', @lines);
  269.     close($fh);
  270. }
  271.  
  272. sub delete_domain {
  273.     my ($user, $domain) = @_;
  274.     my $file = "/home/$user/securelive_max/lunarpages.php";
  275.     my $fh;
  276.  
  277.     return unless -e $file;
  278.  
  279.     chmod 0644, $file;
  280.  
  281.     open($fh, "<$file") || die("Unable to open $file: $!");
  282.     my @lines = <$fh>;
  283.     close ($fh);
  284.  
  285.     foreach (@lines) {
  286.         next unless $_ =~ /\$domains = array\((.*?)\)/;
  287.         my @domains = split(/,\s?/, $1);
  288.         my @new_domains;
  289.            
  290.         foreach my $entry (@domains) {
  291.             $entry =~ s/\"//g;
  292.             if ($entry ne $domain) {
  293.                 push(@new_domains, "\"$entry\"");
  294.             }
  295.         }
  296.            
  297.         $_ = '$domains = array(' . join(',', sort(@new_domains)) . ');' . "\n";
  298.     }
  299.  
  300.     open($fh, ">$file") || die("Unable to open $file: $!");
  301.     print $fh join('', @lines);
  302.     close($fh);
  303. }
  304.                
  305.  
  306. sub create_authenticator {
  307.     my ($user) = @_;
  308.     my $file = "/home/$user/securelive_max/lunarpages.php";
  309.     my $fh;
  310.    
  311.     return if -e $file;
  312.  
  313.     chmod 0644, $file;
  314.  
  315.     print "information: Creating authentication file\n";
  316.  
  317.     open($fh, ">$file") || die("Unable to open $file: $!");
  318.     print $fh '<?php', "\n";
  319.     print $fh '$domain = $_SERVER["HTTP_HOST"];', "\n";
  320.     print $fh '$domains = array();', "\n";
  321.     print $fh "\n";
  322.     print $fh 'foreach ($domains as $entry) {', "\n";
  323.     print $fh "\t", 'if ($domain === $entry || stristr($domain, $entry)) {', "\n";
  324.     print $fh "\t\t", 'include("/home/', $user, '/securelive_max/sl8.php");', "\n";
  325.     print $fh "\t", '}', "\n";
  326.     print $fh '}', "\n";
  327.     print $fh '?>';
  328.     close($fh);
  329. }
  330.  
  331. sub install_htaccess {
  332.     my ($directory, $user, $required_php) = @_;
  333.     my $file = "$directory/.htaccess";
  334.     my $fh;
  335.  
  336.     print "information: Scanning .htaccess file at $file for suPHP_ConfigPath entries and PHP 5 handlers\n";
  337.  
  338.     open($fh, "<$file") || die("Unable to open $file: $!");
  339.     my @lines = <$fh>;
  340.     close $fh;
  341.  
  342.     my $php5 = 0;
  343.     my $php_found = 0;
  344.     my $protect_php_ini = 0;
  345.     foreach (@lines) {
  346.         if (/^suPHP_ConfigPath\s+(.+)/) {
  347.             my $phpini = $1;
  348.             $phpini =~ s/\s+$//;
  349.             print "information: Found suPHP_ConfigPath entry in $file, pointing to $phpini/php.ini\n";            
  350.             &install_php_ini($phpini, $user, $file);
  351.             $required_php = 1 if $phpini eq $directory;
  352.             $php_found = 1;
  353.         }
  354.         if (/^AddHandler application\/x-httpd-php5/) {
  355.             print "information: Found PHP 5 handler entry\n";
  356.             $php5 = 1;
  357.         }
  358.         if (/^\<Files php\.ini\>/) {
  359.             print "information: Found php.ini protection line";
  360.             $protect_php_ini = 1;
  361.         }
  362.         $_ = "$_\n" unless substr($_,-1) eq "\n"; # Add a newline to the end of a line that doesn't have one
  363.     }
  364.  
  365.     $php5 = 1 if -e '/opt/hosting/VERSION'; # LPCP servers are all PHP 5
  366.     if ($required_php) {
  367.         if (!$php_found) {
  368.             print "information: No suPHP_ConfigPath entry found in $file, where required\n";
  369.             print "information: Adding suPHP_ConfigPath entry to $file, pointing to $directory/php.ini\n";
  370.             unshift(@lines, "</IfModule>\n");
  371.             unshift(@lines, "suPHP_ConfigPath $directory\n");
  372.             unshift(@lines, "<IfModule mod_suphp.c>\n");
  373.             &install_php_ini($directory, $user, $file);
  374.         }
  375.         if (!$php5) {
  376.             print "information: No PHP 5 handler entry found in $file, where required\n";
  377.             print "information: Adding PHP 5 handler entry to $file\n";
  378.             unshift(@lines, "AddHandler application/x-httpd-php5 .php5 .php4 .php .php3 .php2 .phtml\n");
  379.         }
  380.         if (!$protect_php_ini) {
  381.             print "information: No php.ini protection found in $file, where required\n";
  382.             print "information: Adding php.ini protection entries to $file\n";
  383.             push(@lines, "<Files php.ini>\n");
  384.             push(@lines, "    Order allow,deny\n");
  385.             push(@lines, "    Deny from all\n");
  386.             push(@lines, "</Files>\n");
  387.         }
  388.            
  389.         chmod 0644, $file;
  390.         open ($fh, ">$file") || die("Unable to open $file: $!");
  391.         print $fh @lines;
  392.         close $fh;
  393.     }
  394.  
  395.     print "information: Scan of .htaccess file at $file complete\n";
  396. }
  397.  
  398. sub install_php_ini {
  399.     my ($directory, $user, $ref) = @_;
  400.     my $file = "$directory/php.ini";
  401.     my $fh;
  402.  
  403.     print "information: Scanning php.ini file at $file for SecureLive auto_prepend entries\n";
  404.  
  405.     my @lines;
  406.     if (-e $file) {
  407.         open($fh, "<$file") || die("Unable to open $file (from $ref): $!");
  408.         @lines = <$fh>;
  409.         close $fh;
  410.     }
  411.  
  412.     my $auto_append_found = 0;
  413.     foreach (@lines) {
  414.         if (/auto_prepend_file = \/home\/$user\/securelive_max\/lunarpages.php/) {
  415.             print "information: Found SecureLive auto_prepend entry in $file\n";
  416.             $auto_append_found = 1;
  417.         }
  418.         elsif (
  419.             /auto_prepend_file = \/home\/$user\/securelive_max/) {
  420.             print "information: Found SecureLive auto_prepend entry in $file for a different installation, skipping\n";
  421.             $auto_append_found = 1;
  422.         }
  423.     }
  424.     if (!$auto_append_found) {
  425.         print "information: No SecureLive auto_prepend entry found in $file, where required\n";
  426.         print "information: Adding SecureLive auto_prepend entry to $file\n";
  427.         chmod 0644, $file;
  428.         open ($fh, ">$file") || die("Unable to open $file (from $ref): $!");
  429.         unshift(@lines, "auto_prepend_file = /home/$user/securelive_max/lunarpages.php\n");
  430.         print $fh @lines;
  431.         close $fh;
  432.     }
  433.     print "information: Scan of php.ini file at $file complete\n";
  434. }
  435.  
  436. sub delete_htaccess {
  437.     my ($directory, $user) = @_;
  438.     my $file = "$directory/.htaccess";
  439.     my $fh;
  440.  
  441.     print "information: Scanning .htaccess file at $file for suPHP_ConfigPath entries\n";
  442.  
  443.     chmod 0644, $file;
  444.     open($fh, "<$file") || die("Unable to open $file: $!");
  445.     my @lines = <$fh>;
  446.     close $fh;
  447.  
  448.     open($fh, ">$file") || die("Unable to open $file: $!");
  449.     foreach (@lines) {
  450.         if (/^suPHP_ConfigPath\s+(.+)/) {
  451.             my $directory = $1;
  452.             print "information: Found suPHP_ConfigPath entry in $file, pointing to $1/php.ini\n";
  453.             &delete_php_ini($directory, $user);
  454.  
  455.             if (!-e "$directory/php.ini") {
  456.                 #After the edit, a php.ini file can be removed, clean up the .htaccess as well
  457.                 if (scalar(@lines) == 1) {
  458.                     print "information: Removing suPHP_ConfigPath entry as php.ini file at $1 has been removed\n";
  459.                     print "information: Removing empty .htaccess $file\n";
  460.                     close($fh);
  461.                     unlink($file);
  462.                 }
  463.             }
  464.             else {
  465.                 print $fh $_;
  466.             }
  467.         }
  468.         else {
  469.             print $fh $_;
  470.         }
  471.     }
  472.     close($fh);
  473.  
  474.     print "information: Scan of .htaccess file at $file complete\n";
  475. }
  476.  
  477. sub delete_php_ini {
  478.     my ($directory, $user) = @_;
  479.     my $file = "$directory/php.ini";
  480.     my $fh;
  481.  
  482.     print "information: Scanning php.ini file at $file for SecureLive auto_prepend entries\n";
  483.  
  484.     my @lines;
  485.     if (-e $file) {
  486.         open($fh, "<$file") || die($!);
  487.         @lines = <$fh>;
  488.         close $fh;
  489.     }
  490.  
  491.     if (scalar(@lines) == 1 && $lines[0] =~ /auto_prepend_file = \/home\/$user\/securelive_max\/lunarpages.php/) {
  492.         print "information: Found SecureLive auto_prepend entry in $file\n";
  493.         print "information: Removing SecureLive auto_prepend entry from $file\n";
  494.         print "information: Removing empty php.ini $file\n";
  495.         my $del = unlink($file);
  496.     }
  497.     else {
  498.         chmod 0644, $file;
  499.         open ($fh, ">$file") || die($!);
  500.         foreach (@lines) {
  501.             next unless $_;
  502.             next if /^\s+$/;
  503.             if (/auto_prepend_file = \/home\/$user\/securelive_max\/lunarpages.php/) {
  504.                 print "information: Found SecureLive auto_prepend entry in $file\n";
  505.                 print "information: Removing SecureLive auto_prepend entry from $file\n";
  506.                 next;
  507.             }
  508.             else {
  509.                 print $fh "$_" if $_;
  510.             }
  511.         }
  512.         close $fh;
  513.     }
  514.  
  515.     if ((stat($file))[7] == 0) {
  516.         print "information: Removing SecureLive auto_prepend entry from $file\n";
  517.         print "information: Removing empty php.ini $file\n";
  518.         my $del = unlink($file);
  519.     }
  520.  
  521.     print "information: Scan of php.ini file at $file complete\n";
  522. }
  523.  
  524. sub dir {
  525.     my ($start_dir) = @_;
  526.     return if -l $start_dir;
  527.     my @results;
  528.  
  529.     if (opendir(DIR, $start_dir)) {
  530.         my @files = grep {!-d "$start_dir\/$_"} readdir(DIR);
  531.         rewinddir DIR;
  532.         my @folders = grep {-d "$start_dir\/$_"} readdir(DIR);
  533.  
  534.         foreach my $file (sort @files) {
  535.             if ($file eq '.htaccess') {
  536.                 print "information: Found .htaccess at $start_dir/.htaccess\n";            
  537.                 push(@results, $start_dir);
  538.             }
  539.         }
  540.         foreach my $folder (sort @folders) {
  541.             if ($folder !~ /^\.\.?$/) {
  542.                 $folder =~ s/\"/\\\"/i;
  543.                 push(@files, dir("$start_dir/$folder"));
  544.             }
  545.         }
  546.         closedir DIR
  547.     }
  548.  
  549.     return @results;
  550. }
  551.  
  552. 42;
Advertisement
Comments
  • User was banned
  • User was banned
Add Comment
Please, Sign In to add comment