2012-06-18 13:26:00 +02:00
|
|
|
<?php
|
|
|
|
/**
|
2019-03-09 20:44:14 +01:00
|
|
|
* @package Joomla.JEDChecker
|
|
|
|
*
|
2019-03-10 17:09:42 +01:00
|
|
|
* @copyright Copyright (C) 2017 - 2019 Open Source Matters, Inc. All rights reserved.
|
|
|
|
* Copyright (C) 2008 - 2016 compojoom.com . All rights reserved.
|
2019-03-10 09:49:52 +01:00
|
|
|
* @author Daniel Dimitrov <daniel@compojoom.com>
|
|
|
|
* eaxs <support@projectfork.net>
|
|
|
|
*
|
2019-03-09 20:44:14 +01:00
|
|
|
* @license GNU General Public License version 2 or later; see LICENSE.txt
|
2012-06-18 13:26:00 +02:00
|
|
|
*/
|
|
|
|
|
|
|
|
defined('_JEXEC') or die('Restricted access');
|
|
|
|
|
2023-08-13 13:22:27 +04:00
|
|
|
use Joomla\CMS\Language\Text;
|
|
|
|
|
2012-07-07 01:45:06 +02:00
|
|
|
// Include the rule base class
|
2013-11-05 21:17:39 +01:00
|
|
|
require_once JPATH_COMPONENT_ADMINISTRATOR . '/models/rule.php';
|
2012-07-07 01:45:06 +02:00
|
|
|
|
2012-06-18 13:26:00 +02:00
|
|
|
/**
|
2013-11-05 21:17:39 +01:00
|
|
|
* class JedcheckerRulesJexec
|
|
|
|
*
|
2012-06-18 13:26:00 +02:00
|
|
|
* This class searches all files for the _JEXEC check
|
|
|
|
* which prevents direct file access.
|
|
|
|
*
|
2013-11-05 21:17:39 +01:00
|
|
|
* @since 1.0
|
2012-06-18 13:26:00 +02:00
|
|
|
*/
|
2013-11-05 21:17:39 +01:00
|
|
|
class JedcheckerRulesJexec extends JEDcheckerRule
|
2012-06-18 13:26:00 +02:00
|
|
|
{
|
2013-11-05 21:17:39 +01:00
|
|
|
/**
|
|
|
|
* The formal ID of this rule. For example: SE1.
|
|
|
|
*
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
protected $id = 'PH2';
|
|
|
|
|
|
|
|
/**
|
|
|
|
* The title or caption of this rule.
|
|
|
|
*
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
protected $title = 'COM_JEDCHECKER_RULE_PH2';
|
|
|
|
|
|
|
|
/**
|
|
|
|
* The description of this rule.
|
|
|
|
*
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
protected $description = 'COM_JEDCHECKER_RULE_PH2_DESC';
|
|
|
|
|
2021-05-17 23:21:34 +03:00
|
|
|
/**
|
|
|
|
* The ordering value to sort rules in the menu.
|
|
|
|
*
|
|
|
|
* @var integer
|
|
|
|
*/
|
|
|
|
public static $ordering = 600;
|
|
|
|
|
2021-02-23 22:22:29 +03:00
|
|
|
/**
|
|
|
|
* Regexp to match _JEXEC-like guard
|
|
|
|
*
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
protected $regex;
|
|
|
|
|
2021-03-09 23:41:06 +03:00
|
|
|
/**
|
|
|
|
* Regexp to match directories to skip
|
|
|
|
*
|
|
|
|
* @var string
|
|
|
|
*/
|
|
|
|
protected $regexExcludeFolders;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* List of files related to libraries
|
|
|
|
*
|
|
|
|
* @var array
|
|
|
|
*/
|
|
|
|
protected $libFiles;
|
|
|
|
|
2013-11-05 21:17:39 +01:00
|
|
|
/**
|
|
|
|
* Initiates the file search and check
|
|
|
|
*
|
|
|
|
* @return void
|
|
|
|
*/
|
|
|
|
public function check()
|
|
|
|
{
|
2021-09-09 10:32:52 +03:00
|
|
|
$this->report->setDefaultSubtype($this->id);
|
|
|
|
|
2021-04-04 15:06:48 +03:00
|
|
|
$this->initJexec();
|
2021-02-23 22:22:29 +03:00
|
|
|
|
2013-11-05 21:17:39 +01:00
|
|
|
// Find all php files of the extension
|
2021-03-09 23:41:06 +03:00
|
|
|
$files = $this->files($this->basedir);
|
2013-11-05 21:17:39 +01:00
|
|
|
|
|
|
|
// Iterate through all files
|
|
|
|
foreach ($files as $file)
|
|
|
|
{
|
|
|
|
// Try to find the _JEXEC check in the file
|
|
|
|
if (!$this->find($file))
|
|
|
|
{
|
|
|
|
// Add as error to the report if it was not found
|
2023-08-13 13:22:27 +04:00
|
|
|
$this->report->addError($file, Text::_('COM_JEDCHECKER_ERROR_JEXEC_NOT_FOUND'));
|
2013-11-05 21:17:39 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Reads a file and searches for the _JEXEC statement
|
|
|
|
*
|
|
|
|
* @param string $file - The path to the file
|
|
|
|
*
|
|
|
|
* @return boolean True if the statement was found, otherwise False.
|
|
|
|
*/
|
|
|
|
protected function find($file)
|
|
|
|
{
|
2021-04-04 15:06:48 +03:00
|
|
|
// Load file and strip comments
|
2021-02-23 22:20:25 +03:00
|
|
|
$content = php_strip_whitespace($file);
|
|
|
|
|
2021-05-17 20:04:37 +03:00
|
|
|
// Strip BOM (it is checked separately)
|
|
|
|
$content = preg_replace('/^\xEF\xBB\xBF/', '', $content);
|
|
|
|
|
2021-04-04 15:06:48 +03:00
|
|
|
// Skip empty files
|
2021-11-16 20:00:36 +03:00
|
|
|
if ($content === '' || preg_match('#^\s*<\?php\s+$#', $content))
|
2021-02-23 22:20:25 +03:00
|
|
|
{
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2021-04-04 15:06:48 +03:00
|
|
|
// Check guards
|
2021-02-23 22:22:29 +03:00
|
|
|
if (preg_match($this->regex, $content))
|
|
|
|
{
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
return false;
|
|
|
|
}
|
2013-11-05 21:17:39 +01:00
|
|
|
|
2021-02-23 22:22:29 +03:00
|
|
|
/**
|
2021-04-04 15:06:48 +03:00
|
|
|
* Prepare regexps aforehand
|
2021-02-23 22:22:29 +03:00
|
|
|
*
|
|
|
|
* @return void
|
|
|
|
*/
|
2021-04-04 15:06:48 +03:00
|
|
|
protected function initJexec()
|
2021-02-23 22:22:29 +03:00
|
|
|
{
|
2021-04-04 15:00:40 +03:00
|
|
|
// Generate regular expression to match JEXEC quard
|
2013-11-05 21:17:39 +01:00
|
|
|
$defines = $this->params->get('constants');
|
|
|
|
$defines = explode(',', $defines);
|
2012-06-27 16:53:50 +03:00
|
|
|
|
2021-02-23 22:22:29 +03:00
|
|
|
foreach ($defines as $i => $define)
|
2013-11-05 21:17:39 +01:00
|
|
|
{
|
2021-02-23 22:22:29 +03:00
|
|
|
$defines[$i] = preg_quote(trim($define), '#');
|
2013-11-05 21:17:39 +01:00
|
|
|
}
|
|
|
|
|
2021-02-23 22:22:29 +03:00
|
|
|
$this->regex
|
2021-11-16 20:00:36 +03:00
|
|
|
= '#^\s*' // at the beginning of the file
|
2021-02-23 22:22:29 +03:00
|
|
|
. '<\?php\s+' // there is an opening php tag
|
2021-03-09 23:39:05 +03:00
|
|
|
. '(?:declare ?\(strict_types ?= ?1 ?\) ?; ?)?' // optionally followed by declare(strict_types=1) directive
|
|
|
|
. '(?:namespace [0-9A-Za-z_\\\\]+ ?; ?)?' // optionally followed by namespace directive
|
|
|
|
. '(?:use [0-9A-Za-z_\\\\]+ ?(?:as [0-9A-Za-z_]+ ?)?; ?)*' // optionally followed by use directives
|
2021-10-26 15:12:02 +03:00
|
|
|
. '\\\\?defined ?\( ?' // followed by defined test
|
2021-02-23 22:22:29 +03:00
|
|
|
. '([\'"])(?:' . implode('|', $defines) . ')\1' // of any of given constant
|
|
|
|
. ' ?\) ?(?:or |\|\| ?)(?:die|exit)\b' // or exit
|
|
|
|
. '#i'; // (case insensitive)
|
2021-03-09 23:41:06 +03:00
|
|
|
|
|
|
|
// Generate regular expression to match excluded directories
|
|
|
|
$libfolders = $this->params->get('libfolders');
|
|
|
|
$libfolders = explode(',', $libfolders);
|
|
|
|
|
|
|
|
foreach ($libfolders as &$libfolder)
|
|
|
|
{
|
|
|
|
$libfolder = preg_quote(trim($libfolder), '#');
|
|
|
|
}
|
|
|
|
|
|
|
|
// Prepend libFolders with default Joomla's exclude list
|
|
|
|
$this->regexExcludeFolders = '#^(?:\.svn|CVS|\.DS_Store|__MACOSX|' . implode('|', $libfolders) . ')$#';
|
|
|
|
|
|
|
|
// Generate list of libraries fingerprint files
|
|
|
|
$libFiles = $this->params->get('libfiles');
|
|
|
|
$this->libFiles = array_map('trim', explode(',', $libFiles));
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Collect php files to check (excluding external library directories)
|
|
|
|
*
|
|
|
|
* @param string $path The path of the folder to read.
|
2023-08-02 14:38:55 +04:00
|
|
|
* @param int $level The current hierarchy level.
|
2021-03-09 23:41:06 +03:00
|
|
|
*
|
|
|
|
* @return array
|
|
|
|
* @since 3.0
|
|
|
|
*/
|
2023-08-02 14:38:55 +04:00
|
|
|
protected function files($path, $level = 0)
|
2021-03-09 23:41:06 +03:00
|
|
|
{
|
|
|
|
$arr = array();
|
|
|
|
|
|
|
|
// Read the source directory
|
|
|
|
if ($handle = @opendir($path))
|
|
|
|
{
|
|
|
|
while (($file = readdir($handle)) !== false)
|
|
|
|
{
|
|
|
|
// Skip excluded directories
|
|
|
|
if ($file !== '.' && $file !== '..' && !preg_match($this->regexExcludeFolders, $file))
|
|
|
|
{
|
|
|
|
$fullpath = $path . '/' . $file;
|
|
|
|
|
|
|
|
if (is_dir($fullpath))
|
|
|
|
{
|
2023-08-02 14:38:55 +04:00
|
|
|
if ($level > 0)
|
2021-03-09 23:41:06 +03:00
|
|
|
{
|
2023-08-02 14:38:55 +04:00
|
|
|
// Detect and skip external library directories
|
|
|
|
foreach ($this->libFiles as $libFile)
|
2021-03-09 23:41:06 +03:00
|
|
|
{
|
2023-08-02 14:38:55 +04:00
|
|
|
if (is_file($fullpath . '/' . $libFile))
|
|
|
|
{
|
|
|
|
// Skip processing of this directory
|
|
|
|
continue 2;
|
|
|
|
}
|
2021-03-09 23:41:06 +03:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-08-02 14:38:55 +04:00
|
|
|
$arr = array_merge($arr, $this->files($fullpath, $level + 1));
|
2021-03-09 23:41:06 +03:00
|
|
|
}
|
|
|
|
elseif (preg_match('/\.php$/', $file))
|
|
|
|
{
|
|
|
|
$arr[] = $fullpath;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
closedir($handle);
|
|
|
|
}
|
|
|
|
|
|
|
|
return $arr;
|
2013-11-05 21:17:39 +01:00
|
|
|
}
|
2012-06-18 13:26:00 +02:00
|
|
|
}
|