Linux vps-61133.fhnet.fr 4.9.0-19-amd64 #1 SMP Debian 4.9.320-2 (2022-06-30) x86_64
Apache/2.4.25 (Debian)
Server IP : 93.113.207.21 & Your IP : 216.73.216.112
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
var /
www /
html_old /
btm2000_old /
htdocs /
core /
lib /
Delete
Unzip
Name
Size
Permission
Date
Action
accounting.lib.php
8.92
KB
-rw-r--r--
2021-10-16 13:26
admin.lib.php
61.16
KB
-rw-r--r--
2021-10-16 13:26
agenda.lib.php
18.32
KB
-rw-r--r--
2021-10-16 13:26
ajax.lib.php
29.21
KB
-rw-r--r--
2021-10-16 13:26
asset.lib.php
4.78
KB
-rw-r--r--
2021-10-16 13:26
bank.lib.php
12.6
KB
-rw-r--r--
2021-10-16 13:26
barcode.lib.php
13.22
KB
-rw-r--r--
2021-10-16 13:26
categories.lib.php
3.41
KB
-rw-r--r--
2021-10-16 13:26
company.lib.php
75.87
KB
-rw-r--r--
2021-10-16 13:26
contact.lib.php
4.5
KB
-rw-r--r--
2021-10-16 13:26
contract.lib.php
4.73
KB
-rw-r--r--
2021-10-16 13:26
cron.lib.php
4.47
KB
-rw-r--r--
2021-10-16 13:26
date.lib.php
34.54
KB
-rw-r--r--
2021-10-16 13:26
doc.lib.php
6.67
KB
-rw-r--r--
2021-10-16 13:26
doleditor.lib.php
4.11
KB
-rw-r--r--
2021-10-16 13:26
donation.lib.php
3.59
KB
-rw-r--r--
2021-10-16 13:26
ecm.lib.php
4.71
KB
-rw-r--r--
2021-10-16 13:26
emailing.lib.php
2.24
KB
-rw-r--r--
2021-10-16 13:26
expedition.lib.php
3.9
KB
-rw-r--r--
2021-10-16 13:26
expensereport.lib.php
5.64
KB
-rw-r--r--
2021-10-16 13:26
fichinter.lib.php
6.4
KB
-rw-r--r--
2021-10-16 13:26
files.lib.php
115.23
KB
-rw-r--r--
2021-10-16 13:26
fiscalyear.lib.php
1.86
KB
-rw-r--r--
2021-10-16 13:26
format_cards.lib.php
2.8
KB
-rw-r--r--
2021-10-16 13:26
fourn.lib.php
9.05
KB
-rw-r--r--
2021-10-16 13:26
functions.lib.php
388.61
KB
-rw-r--r--
2021-10-16 13:26
functions2.lib.php
89.1
KB
-rw-r--r--
2021-10-16 13:26
functions_ch.lib.php
3.66
KB
-rw-r--r--
2021-10-16 13:26
functionsnumtoword.lib.php
9.86
KB
-rw-r--r--
2021-10-16 13:26
geturl.lib.php
11.44
KB
-rw-r--r--
2021-10-16 13:26
holiday.lib.php
3.42
KB
-rw-r--r--
2021-10-16 13:26
hrm.lib.php
2.81
KB
-rw-r--r--
2021-10-16 13:26
images.lib.php
22.98
KB
-rw-r--r--
2021-10-16 13:26
import.lib.php
1.88
KB
-rw-r--r--
2021-10-16 13:26
index.html
0
B
-rw-r--r--
2021-10-16 13:26
intracommreport.lib.php
2.59
KB
-rw-r--r--
2021-10-16 13:26
invoice.lib.php
7.24
KB
-rw-r--r--
2021-10-16 13:26
invoice2.lib.php
8.83
KB
-rw-r--r--
2021-10-16 13:26
json.lib.php
10.76
KB
-rw-r--r--
2021-10-16 13:26
ldap.lib.php
5.26
KB
-rw-r--r--
2021-10-16 13:26
loan.lib.php
4.95
KB
-rw-r--r--
2021-10-16 13:26
mailmanspip.lib.php
1.24
KB
-rw-r--r--
2021-10-16 13:26
member.lib.php
9.75
KB
-rw-r--r--
2021-10-16 13:26
memory.lib.php
7.59
KB
-rw-r--r--
2021-10-16 13:26
modulebuilder.lib.php
12.95
KB
-rw-r--r--
2021-10-16 13:26
multicurrency.lib.php
2.07
KB
-rw-r--r--
2021-10-16 13:26
oauth.lib.php
5.73
KB
-rw-r--r--
2021-10-16 13:26
order.lib.php
5.6
KB
-rw-r--r--
2021-10-16 13:26
parsemd.lib.php
2.55
KB
-rw-r--r--
2021-10-16 13:26
payments.lib.php
14.54
KB
-rw-r--r--
2021-10-16 13:26
pdf.lib.php
96.97
KB
-rw-r--r--
2021-10-16 13:26
phpsessionindb.lib.php
5.29
KB
-rw-r--r--
2021-10-16 13:26
prelevement.lib.php
2.86
KB
-rw-r--r--
2021-10-16 13:26
price.lib.php
21.26
KB
-rw-r--r--
2021-10-16 13:26
product.lib.php
24.04
KB
-rw-r--r--
2021-10-16 13:26
project.lib.php
104.08
KB
-rw-r--r--
2021-10-16 13:26
propal.lib.php
5.2
KB
-rw-r--r--
2021-10-16 13:26
receiptprinter.lib.php
2.19
KB
-rw-r--r--
2021-10-16 13:26
reception.lib.php
4.03
KB
-rw-r--r--
2021-10-16 13:26
report.lib.php
3.8
KB
-rw-r--r--
2021-10-16 13:26
resource.lib.php
4.66
KB
-rw-r--r--
2021-10-16 13:26
salaries.lib.php
3.46
KB
-rw-r--r--
2021-10-16 13:26
security.lib.php
32.03
KB
-rw-r--r--
2021-10-16 13:26
security2.lib.php
17.27
KB
-rw-r--r--
2021-10-16 13:26
sendings.lib.php
16.54
KB
-rw-r--r--
2021-10-16 13:26
signature.lib.php
2.8
KB
-rw-r--r--
2021-10-16 13:26
stock.lib.php
3.6
KB
-rw-r--r--
2021-10-16 13:26
supplier_proposal.lib.php
4.79
KB
-rw-r--r--
2021-10-16 13:26
takepos.lib.php
2.15
KB
-rw-r--r--
2021-10-16 13:26
tax.lib.php
46.55
KB
-rw-r--r--
2021-10-16 13:26
ticket.lib.php
35.67
KB
-rw-r--r--
2021-10-16 13:26
treeview.lib.php
9.13
KB
-rw-r--r--
2021-10-16 13:26
trip.lib.php
1.98
KB
-rw-r--r--
2021-10-16 13:26
usergroups.lib.php
41.54
KB
-rw-r--r--
2021-10-16 13:26
vat.lib.php
2.5
KB
-rw-r--r--
2021-10-16 13:26
website.lib.php
49.25
KB
-rw-r--r--
2021-10-16 13:26
website2.lib.php
22.24
KB
-rw-r--r--
2021-10-16 13:26
ws.lib.php
3.31
KB
-rw-r--r--
2021-10-16 13:26
xcal.lib.php
16.58
KB
-rw-r--r--
2021-10-16 13:26
Save
Rename
<?php /* Copyright (C) 2008-2020 Laurent Destailleur <eldy@users.sourceforge.net> * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by * the Free Software Foundation; either version 3 of the License, or * (at your option) any later version. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program. If not, see <https://www.gnu.org/licenses/>. * or see https://www.gnu.org/ */ /** * \file htdocs/core/lib/geturl.lib.php * \brief This file contains functions dedicated to get URLs. */ /** * Function to get a content from an URL (use proxy if proxy defined). * Support Dolibarr setup for timeout and proxy. * Enhancement of CURL to add an anti SSRF protection. * * @param string $url URL to call. * @param string $postorget 'POST', 'GET', 'HEAD', 'PUT', 'PUTALREADYFORMATED', 'POSTALREADYFORMATED', 'DELETE' * @param string $param Parameters of URL (x=value1&y=value2) or may be a formated content with $postorget='PUTALREADYFORMATED' * @param integer $followlocation 0=Do not follow, 1=Follow location. * @param string[] $addheaders Array of string to add into header. Example: ('Accept: application/xrds+xml', ....) * @param string[] $allowedschemes List of schemes that are allowed ('http' + 'https' only by default) * @param int $localurl 0=Only external URL are possible, 1=Only local URL, 2=Both external and local URL are allowed. * @return array Returns an associative array containing the response from the server array('content'=>response, 'curl_error_no'=>errno, 'curl_error_msg'=>errmsg...) */ function getURLContent($url, $postorget = 'GET', $param = '', $followlocation = 1, $addheaders = array(), $allowedschemes = array('http', 'https'), $localurl = 0) { //declaring of global variables global $conf; $USE_PROXY = empty($conf->global->MAIN_PROXY_USE) ? 0 : $conf->global->MAIN_PROXY_USE; $PROXY_HOST = empty($conf->global->MAIN_PROXY_HOST) ? 0 : $conf->global->MAIN_PROXY_HOST; $PROXY_PORT = empty($conf->global->MAIN_PROXY_PORT) ? 0 : $conf->global->MAIN_PROXY_PORT; $PROXY_USER = empty($conf->global->MAIN_PROXY_USER) ? 0 : $conf->global->MAIN_PROXY_USER; $PROXY_PASS = empty($conf->global->MAIN_PROXY_PASS) ? 0 : $conf->global->MAIN_PROXY_PASS; dol_syslog("getURLContent postorget=".$postorget." URL=".$url." param=".$param); //setting the curl parameters. $ch = curl_init(); /*print $API_Endpoint."-".$API_version."-".$PAYPAL_API_USER."-".$PAYPAL_API_PASSWORD."-".$PAYPAL_API_SIGNATURE."<br>"; print $USE_PROXY."-".$gv_ApiErrorURL."<br>"; print $nvpStr; exit;*/ curl_setopt($ch, CURLOPT_VERBOSE, 1); curl_setopt($ch, CURLOPT_USERAGENT, 'Dolibarr geturl function'); // We use @ here because this may return warning if safe mode is on or open_basedir is on (following location is forbidden when safe mode is on). // We force value to false so we will manage redirection ourself later. @curl_setopt($ch, CURLOPT_FOLLOWLOCATION, false); if (is_array($addheaders) && count($addheaders)) curl_setopt($ch, CURLOPT_HTTPHEADER, $addheaders); curl_setopt($ch, CURLINFO_HEADER_OUT, true); // To be able to retrieve request header and log it // By default use tls decied by PHP. // You can force, if supported a version like TLSv1 or TLSv1.2 if (!empty($conf->global->MAIN_CURL_SSLVERSION)) curl_setopt($ch, CURLOPT_SSLVERSION, $conf->global->MAIN_CURL_SSLVERSION); //curl_setopt($ch, CURLOPT_SSLVERSION, 6); for tls 1.2 // Turning off the server and peer verification(TrustManager Concept). curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); // Restrict use to some protocols only $protocols = 0; if (is_array($allowedschemes)) { foreach ($allowedschemes as $allowedscheme) { if ($allowedscheme == 'http') $protocols |= CURLPROTO_HTTP; if ($allowedscheme == 'https') $protocols |= CURLPROTO_HTTPS; } curl_setopt($ch, CURLOPT_PROTOCOLS, $protocols); curl_setopt($ch, CURLOPT_REDIR_PROTOCOLS, $protocols); } curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, empty($conf->global->MAIN_USE_CONNECT_TIMEOUT) ? 5 : $conf->global->MAIN_USE_CONNECT_TIMEOUT); curl_setopt($ch, CURLOPT_TIMEOUT, empty($conf->global->MAIN_USE_RESPONSE_TIMEOUT) ? 30 : $conf->global->MAIN_USE_RESPONSE_TIMEOUT); //curl_setopt($ch, CURLOPT_SAFE_UPLOAD, true); // PHP 5.5 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); // We want response if ($postorget == 'POST') { curl_setopt($ch, CURLOPT_POST, 1); // POST curl_setopt($ch, CURLOPT_POSTFIELDS, $param); // Setting param x=a&y=z as POST fields } elseif ($postorget == 'POSTALREADYFORMATED') { curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'POST'); // HTTP request is 'POST' but param string is taken as it is curl_setopt($ch, CURLOPT_POSTFIELDS, $param); // param = content of post, like a xml string } elseif ($postorget == 'PUT') { $array_param = null; curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'PUT'); // HTTP request is 'PUT' if (!is_array($param)) parse_str($param, $array_param); else { dol_syslog("parameter param must be a string", LOG_WARNING); $array_param = $param; } curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($array_param)); // Setting param x=a&y=z as PUT fields } elseif ($postorget == 'PUTALREADYFORMATED') { curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'PUT'); // HTTP request is 'PUT' curl_setopt($ch, CURLOPT_POSTFIELDS, $param); // param = content of post, like a xml string } elseif ($postorget == 'HEAD') { curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'HEAD'); // HTTP request is 'HEAD' curl_setopt($ch, CURLOPT_NOBODY, true); } elseif ($postorget == 'DELETE') { curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'DELETE'); // POST } else { curl_setopt($ch, CURLOPT_POST, 0); // GET } //if USE_PROXY constant set at begin of this method. if ($USE_PROXY) { dol_syslog("getURLContent set proxy to ".$PROXY_HOST.":".$PROXY_PORT." - ".$PROXY_USER.":".$PROXY_PASS); //curl_setopt ($ch, CURLOPT_PROXYTYPE, CURLPROXY_HTTP); // Curl 7.10 curl_setopt($ch, CURLOPT_PROXY, $PROXY_HOST.":".$PROXY_PORT); if ($PROXY_USER) curl_setopt($ch, CURLOPT_PROXYUSERPWD, $PROXY_USER.":".$PROXY_PASS); } $newUrl = $url; $maxRedirection = 5; $info = array(); $response = ''; do { if ($maxRedirection < 1) break; curl_setopt($ch, CURLOPT_URL, $newUrl); // Parse $newUrl $newUrlArray = parse_url($newUrl); $hosttocheck = $newUrlArray['host']; $hosttocheck = str_replace(array('[', ']'), '', $hosttocheck); // Remove brackets of IPv6 if (in_array($hosttocheck, array('localhost', 'localhost.domain'))) { $iptocheck = '127.0.0.1'; } else { // TODO Resolve $iptocheck to get an IP and set CURLOPT_CONNECT_TO to use this ip $iptocheck = $hosttocheck; } if (!filter_var($iptocheck, FILTER_VALIDATE_IP, FILTER_FLAG_IPV4 | FILTER_FLAG_IPV6)) { // This is not an IP $iptocheck = 0; // } if ($iptocheck) { if ($localurl == 0) { // Only external url allowed (dangerous, may allow to get malware) if (!filter_var($iptocheck, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)) { $info['http_code'] = 400; $info['content'] = 'Error bad hostname IP (private or reserved range). Must be an external URL.'; break; } if (in_array($iptocheck, array('100.100.100.200'))) { $info['http_code'] = 400; $info['content'] = 'Error bad hostname IP (Used by Alibaba metadata). Must be an external URL.'; break; } } if ($localurl == 1) { // Only local url allowed (dangerous, may allow to get metadata on server or make internal port scanning) if (filter_var($iptocheck, FILTER_VALIDATE_IP, FILTER_FLAG_NO_PRIV_RANGE | FILTER_FLAG_NO_RES_RANGE)) { $info['http_code'] = 400; $info['content'] = 'Error bad hostname. Must be a local URL.'; break; } } } // Getting response from server $response = curl_exec($ch); $info = curl_getinfo($ch); // Reading of request must be done after sending request $http_code = $info['http_code']; if ($followlocation && ($http_code == 301 || $http_code == 302 || $http_code == 303 || $http_code == 307)) { $newUrl = $info['redirect_url']; $maxRedirection--; // TODO Use $info['local_ip'] and $info['primary_ip'] ? continue; } else { $http_code = 0; } } while ($http_code); $request = curl_getinfo($ch, CURLINFO_HEADER_OUT); // Reading of request must be done after sending request dol_syslog("getURLContent request=".$request); //dol_syslog("getURLContent response =".response); // This may contains binary data, so we dont output it dol_syslog("getURLContent response size=".strlen($response)); // This may contains binary data, so we dont output it $rep = array(); if (curl_errno($ch)) { // Ad keys to $rep $rep['content'] = $response; // moving to display page to display curl errors $rep['curl_error_no'] = curl_errno($ch); $rep['curl_error_msg'] = curl_error($ch); dol_syslog("getURLContent response array is ".join(',', $rep)); } else { //$info = curl_getinfo($ch); // Ad keys to $rep $rep = $info; //$rep['header_size']=$info['header_size']; //$rep['http_code']=$info['http_code']; dol_syslog("getURLContent http_code=".$rep['http_code']); // Add more keys to $rep $rep['content'] = $response; $rep['curl_error_no'] = ''; $rep['curl_error_msg'] = ''; } //closing the curl curl_close($ch); return $rep; } /** * Function get second level domain name. * For example: https://www.abc.mydomain.com/dir/page.html return 'mydomain' * * @param string $url Full URL. * @param int $mode 0=return 'mydomain', 1=return 'mydomain.com', 2=return 'abc.mydomain.com' * @return string Returns domaine name */ function getDomainFromURL($url, $mode = 0) { $tmpdomain = preg_replace('/^https?:\/\//i', '', $url); // Remove http(s):// $tmpdomain = preg_replace('/\/.*$/i', '', $tmpdomain); // Remove part after domain if ($mode == 2) { $tmpdomain = preg_replace('/^.*\.([^\.]+)\.([^\.]+)\.([^\.]+)$/', '\1.\2.\3', $tmpdomain); // Remove part 'www.' before 'abc.mydomain.com' } else { $tmpdomain = preg_replace('/^.*\.([^\.]+)\.([^\.]+)$/', '\1.\2', $tmpdomain); // Remove part 'www.abc.' before 'mydomain.com' } if (empty($mode)) { $tmpdomain = preg_replace('/\.[^\.]+$/', '', $tmpdomain); // Remove first level domain (.com, .net, ...) } return $tmpdomain; } /** * Function root url from a long url * For example: https://www.abc.mydomain.com/dir/page.html return 'https://www.abc.mydomain.com' * For example: http://www.abc.mydomain.com/ return 'https://www.abc.mydomain.com' * * @param string $url Full URL. * @return string Returns root url */ function getRootURLFromURL($url) { $prefix = ''; $tmpurl = $url; $reg = null; if (preg_match('/^(https?:\/\/)/i', $tmpurl, $reg)) $prefix = $reg[1]; $tmpurl = preg_replace('/^https?:\/\//i', '', $tmpurl); // Remove http(s):// $tmpurl = preg_replace('/\/.*$/i', '', $tmpurl); // Remove part after domain return $prefix.$tmpurl; } /** * Function to remove comments into HTML content * * @param string $content Text content * @return string Returns text without HTML comments */ function removeHtmlComment($content) { $content = preg_replace('/<!--[^\-]+-->/', '', $content); return $content; }