]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blob - config/cfgroot/header.pl
syslog: Listen to network and block access from anywhere but localhost
[people/pmueller/ipfire-2.x.git] / config / cfgroot / header.pl
1 # SmoothWall CGIs
2 #
3 # This code is distributed under the terms of the GPL
4 #
5 # (c) The SmoothWall Team
6 # Copyright (C) 2002 Alex Hudson - getcgihash() rewrite
7 # Copyright (C) 2002 Bob Grant <bob@cache.ucr.edu> - validmac()
8 # Copyright (c) 2002/04/13 Steve Bootes - add alias section, helper functions
9 # Copyright (c) 2002/08/23 Mark Wormgoor <mark@wormgoor.com> validfqdn()
10 # Copyright (c) 2003/09/11 Darren Critchley <darrenc@telus.net> srtarray()
11 #
12 package Header;
13
14 use CGI();
15 use File::Basename;
16 use HTML::Entities();
17 use Socket;
18 use Time::Local;
19
20 $|=1; # line buffering
21
22 require "/var/ipfire/aws-functions.pl";
23
24 $Header::revision = 'final';
25 $Header::swroot = '/var/ipfire';
26 $Header::graphdir='/srv/web/ipfire/html/graphs';
27 $Header::pagecolour = '#ffffff';
28 #$Header::tablecolour = '#a0a0a0';
29 $Header::tablecolour = '#FFFFFF';
30 $Header::bigboxcolour = '#F6F4F4';
31 $Header::boxcolour = '#EAE9EE';
32 $Header::bordercolour = '#000000';
33 $Header::table1colour = '#E0E0E0';
34 $Header::table2colour = '#F0F0F0';
35 $Header::colourred = '#993333';
36 $Header::colourorange = '#FF9933';
37 $Header::colouryellow = '#FFFF00';
38 $Header::colourgreen = '#339933';
39 $Header::colourblue = '#333399';
40 $Header::colourovpn = '#339999';
41 $Header::colourfw = '#000000';
42 $Header::colourvpn = '#990099';
43 $Header::colourerr = '#FF0000';
44 $Header::viewsize = 150;
45 $Header::errormessage = '';
46 my %menuhash = ();
47 my $menu = \%menuhash;
48 %settings = ();
49 %ethsettings = ();
50 %pppsettings = ();
51 @URI = ();
52
53 ### Make sure this is an SSL request
54 if ($ENV{'SERVER_ADDR'} && $ENV{'HTTPS'} ne 'on') {
55 print "Status: 302 Moved\r\n";
56 print "Location: https://$ENV{'SERVER_ADDR'}:444/$ENV{'PATH_INFO'}\r\n\r\n";
57 exit 0;
58 }
59
60 ### Initialize environment
61 &General::readhash("${swroot}/main/settings", \%settings);
62 &General::readhash("${swroot}/ethernet/settings", \%ethsettings);
63 &General::readhash("${swroot}/ppp/settings", \%pppsettings);
64 $hostname = $settings{'HOSTNAME'};
65 $hostnameintitle = 0;
66
67 ### Initialize language
68 require "${swroot}/lang.pl";
69 $language = &Lang::FindWebLanguage($settings{"LANGUAGE"});
70
71 ### Read English Files
72 if ( -d "/var/ipfire/langs/en/" ) {
73 opendir(DIR, "/var/ipfire/langs/en/");
74 @names = readdir(DIR) or die "Cannot Read Directory: $!\n";
75 foreach $name(@names) {
76 next if ($name eq ".");
77 next if ($name eq "..");
78 next if (!($name =~ /\.pl$/));
79 require "${swroot}/langs/en/${name}";
80 };
81 };
82
83
84 ### Enable Language Files
85 if ( -d "/var/ipfire/langs/${language}/" ) {
86 opendir(DIR, "/var/ipfire/langs/${language}/");
87 @names = readdir(DIR) or die "Cannot Read Directory: $!\n";
88 foreach $name(@names) {
89 next if ($name eq ".");
90 next if ($name eq "..");
91 next if (!($name =~ /\.pl$/));
92 require "${swroot}/langs/${language}/${name}";
93 };
94 };
95
96 our $THEME_NAME = $settings{'THEME'};
97
98 require "${swroot}/langs/en.pl";
99 require "${swroot}/langs/${language}.pl";
100 eval `/bin/cat /srv/web/ipfire/html/themes/$THEME_NAME/include/functions.pl`;
101
102 sub green_used() {
103 if ($ethsettings{'GREEN_DEV'} && $ethsettings{'GREEN_DEV'} ne "") {
104 return 1;
105 }
106
107 return 0;
108 }
109
110 sub orange_used () {
111 if ($ethsettings{'CONFIG_TYPE'} =~ /^[24]$/) {
112 return 1;
113 }
114 return 0;
115 }
116
117 sub blue_used () {
118 if ($ethsettings{'CONFIG_TYPE'} =~ /^[34]$/) {
119 return 1;
120 }
121 return 0;
122 }
123
124 sub is_modem {
125 if ($ethsettings{'CONFIG_TYPE'} =~ /^[0]$/) {
126 return 1;
127 }
128 return 0;
129 }
130
131 ### Initialize menu
132 sub genmenu {
133
134 my %subsystemhash = ();
135 my $subsystem = \%subsystemhash;
136
137 my %substatushash = ();
138 my $substatus = \%substatushash;
139
140 my %subnetworkhash = ();
141 my $subnetwork = \%subnetworkhash;
142
143 my %subserviceshash = ();
144 my $subservices = \%subserviceshash;
145
146 my %subfirewallhash = ();
147 my $subfirewall = \%subfirewallhash;
148
149 my %subipfirehash = ();
150 my $subipfire = \%subipfirehash;
151
152 my %sublogshash = ();
153 my $sublogs = \%sublogshash;
154
155 if ( -e "/var/ipfire/main/gpl_accepted") {
156
157 eval `/bin/cat /var/ipfire/menu.d/*.menu`;
158 eval `/bin/cat /var/ipfire/menu.d/*.main`;
159
160 if (! blue_used()) {
161 $menu->{'05.firewall'}{'subMenu'}->{'60.wireless'}{'enabled'} = 0;
162 }
163 if ( $ethsettings{'CONFIG_TYPE'} =~ /^(1|2|3|4)$/ && $ethsettings{'RED_TYPE'} eq 'STATIC' ) {
164 $menu->{'03.network'}{'subMenu'}->{'70.aliases'}{'enabled'} = 1;
165 }
166
167 if (&General::RedIsWireless()) {
168 $menu->{'01.system'}{'subMenu'}->{'21.wlan'}{'enabled'} = 1;
169 }
170
171 if ( $ethsettings{'RED_TYPE'} eq "PPPOE" && $pppsettings{'MONPORT'} ne "" ) {
172 $menu->{'02.status'}{'subMenu'}->{'74.modem-status'}{'enabled'} = 1;
173 }
174
175 # Disbale unusable things on EC2
176 if (&AWS::running_on_ec2()) {
177 $menu->{'03.network'}{'subMenu'}->{'30.dhcp'}{'enabled'} = 0;
178 $menu->{'03.network'}{'subMenu'}->{'80.macadressmenu'}{'enabled'} = 0;
179 $menu->{'03.network'}{'subMenu'}->{'90.wakeonlan'}{'enabled'} = 0;
180 }
181
182 # Disable proxy when no GREEN is available
183 if (!&green_used()) {
184 $menu->{'03.network'}{'subMenu'}->{'20.proxy'}{'enabled'} = 0;
185 $menu->{'03.network'}{'subMenu'}->{'21.urlfilter'}{'enabled'} = 0;
186 $menu->{'03.network'}{'subMenu'}->{'22.updxlrator'}{'enabled'} = 0;
187 }
188 }
189 }
190
191 sub showhttpheaders
192 {
193 print "Cache-control: private\n";
194 print "Content-type: text/html; charset=UTF-8\n\n";
195 }
196
197 sub is_menu_visible($) {
198 my $link = shift;
199 $link =~ s#\?.*$##;
200 return (-e $ENV{'DOCUMENT_ROOT'}."/../$link");
201 }
202
203
204 sub getlink($) {
205 my $root = shift;
206 if (! $root->{'enabled'}) {
207 return '';
208 }
209 if ($root->{'uri'} !~ /^$/) {
210 my $vars = '';
211 if ($root->{'vars'} !~ /^$/) {
212 $vars = '?'. $root->{'vars'};
213 }
214 if (! is_menu_visible($root->{'uri'})) {
215 return '';
216 }
217 return $root->{'uri'}.$vars;
218 }
219 my $submenus = $root->{'subMenu'};
220 if (! $submenus) {
221 return '';
222 }
223 foreach my $item (sort keys %$submenus) {
224 my $link = getlink($submenus->{$item});
225 if ($link ne '') {
226 return $link;
227 }
228 }
229 return '';
230 }
231
232
233 sub compare_url($) {
234 my $conf = shift;
235
236 my $uri = $conf->{'uri'};
237 my $vars = $conf->{'vars'};
238 my $novars = $conf->{'novars'};
239
240 if ($uri eq '') {
241 return 0;
242 }
243 if ($uri ne $URI[0]) {
244 return 0;
245 }
246 if ($novars) {
247 if ($URI[1] !~ /^$/) {
248 return 0;
249 }
250 }
251 if (! $vars) {
252 return 1;
253 }
254 return ($URI[1] eq $vars);
255 }
256
257
258 sub gettitle($) {
259 my $root = shift;
260
261 if (! $root) {
262 return '';
263 }
264 foreach my $item (sort keys %$root) {
265 my $val = $root->{$item};
266 if (compare_url($val)) {
267 $val->{'selected'} = 1;
268 if ($val->{'title'} !~ /^$/) {
269 return $val->{'title'};
270 }
271 return 'EMPTY TITLE';
272 }
273
274 my $title = gettitle($val->{'subMenu'});
275 if ($title ne '') {
276 $val->{'selected'} = 1;
277 return $title;
278 }
279 }
280 return '';
281 }
282
283 sub getcgihash {
284 my ($hash, $params) = @_;
285 my $cgi = CGI->new ();
286 $hash->{'__CGI__'} = $cgi;
287 return if ($ENV{'REQUEST_METHOD'} ne 'POST');
288 if (!$params->{'wantfile'}) {
289 $CGI::DISABLE_UPLOADS = 1;
290 $CGI::POST_MAX = 1024 * 1024;
291 } else {
292 $CGI::POST_MAX = 10 * 1024 * 1024;
293 }
294
295 $cgi->referer() =~ m/^https?\:\/\/([^\/]+)/;
296 my $referer = $1;
297 $cgi->url() =~ m/^https?\:\/\/([^\/]+)/;
298 my $servername = $1;
299 return if ($referer ne $servername);
300
301 ### Modified for getting multi-vars, split by |
302 %temp = $cgi->Vars();
303 foreach my $key (keys %temp) {
304 $hash->{$key} = $temp{$key};
305 $hash->{$key} =~ s/\0/|/g;
306 $hash->{$key} =~ s/^\s*(.*?)\s*$/$1/;
307 }
308
309 if (($params->{'wantfile'})&&($params->{'filevar'})) {
310 $hash->{$params->{'filevar'}} = $cgi->upload
311 ($params->{'filevar'});
312 }
313 return;
314 }
315
316
317 # Test if IP is within a subnet
318 # Call: IpInSubnet (Addr, Subnet, Subnet Mask)
319 # Subnet can be an IP of the subnet: 10.0.0.0 or 10.0.0.1
320 # Everything in dottted notation
321 # Return: TRUE/FALSE
322 sub IpInSubnet
323 {
324 $ip = unpack('N', inet_aton(shift));
325 $start = unpack('N', inet_aton(shift));
326 $mask = unpack('N', inet_aton(shift));
327 $start &= $mask; # base of subnet...
328 $end = $start + ~$mask;
329 return (($ip >= $start) && ($ip <= $end));
330 }
331
332 sub escape($) {
333 my $s = shift;
334 return HTML::Entities::encode_entities($s);
335 }
336
337 sub cleanhtml {
338 my $outstring =$_[0];
339 $outstring =~ tr/,/ / if not defined $_[1] or $_[1] ne 'y';
340
341 return escape($outstring);
342 }
343
344 sub connectionstatus
345 {
346 my %pppsettings = ();
347 my %netsettings = ();
348 my $iface='';
349
350 $pppsettings{'PROFILENAME'} = 'None';
351 &General::readhash("${General::swroot}/ppp/settings", \%pppsettings);
352 &General::readhash("${General::swroot}/ethernet/settings", \%netsettings);
353
354 my $profileused='';
355 unless ( $netsettings{'RED_TYPE'} =~ /^(DHCP|STATIC)$/ ) {
356 $profileused="- $pppsettings{'PROFILENAME'}";
357 }
358
359 my ($timestr, $connstate);
360
361 my $connstate = "<span>$Lang::tr{'idle'} $profileused</span>";
362
363 if (-e "${General::swroot}/red/active") {
364 $timestr = &General::age("${General::swroot}/red/active");
365 $connstate = "<span>$Lang::tr{'connected'} - (<span>$timestr</span>) $profileused</span>";
366 } else {
367 if ((open(KEEPCONNECTED, "</var/ipfire/red/keepconnected") == false) && ($pppsettings{'RECONNECTION'} eq "persistent")) {
368 $connstate = "<span>$Lang::tr{'connection closed'} $profileused</span>";
369 } elsif (($pppsettings{'RECONNECTION'} eq "dialondemand") && ( -e "${General::swroot}/red/dial-on-demand")) {
370 $connstate = "<span>$Lang::tr{'dod waiting'} $profileused</span>";
371 } else {
372 $connstate = "<span>$Lang::tr{'connecting'} $profileused</span>" if (system("ps -ef | grep -q '[p]ppd'"));
373 }
374 }
375
376 return $connstate;
377 }
378
379 sub CheckSortOrder {
380 #Sorting of allocated leases
381 if ($ENV{'QUERY_STRING'} =~ /^IPADDR|^ETHER|^HOSTNAME|^ENDTIME/ ) {
382 my $newsort=$ENV{'QUERY_STRING'};
383 &General::readhash("${swroot}/dhcp/settings", \%dhcpsettings);
384 $act=$dhcpsettings{'SORT_LEASELIST'};
385 #Reverse actual ?
386 if ($act =~ $newsort) {
387 if ($act !~ 'Rev') {$Rev='Rev'};
388 $newsort.=$Rev
389 };
390
391 $dhcpsettings{'SORT_LEASELIST'}=$newsort;
392 &General::writehash("${swroot}/dhcp/settings", \%dhcpsettings);
393 $dhcpsettings{'ACTION'} = 'SORT'; # avoid the next test "First lauch"
394 }
395
396 }
397
398 sub PrintActualLeases
399 {
400 &openbox('100%', 'left', $tr{'current dynamic leases'});
401 print <<END
402 <table width='100%' class='tbl'>
403 <tr>
404 <th width='25%' align='center'><a href='$ENV{'SCRIPT_NAME'}?IPADDR'><b>$tr{'ip address'}</b></a></th>
405 <th width='25%' align='center'><a href='$ENV{'SCRIPT_NAME'}?ETHER'><b>$tr{'mac address'}</b></a></th>
406 <th width='20%' align='center'><a href='$ENV{'SCRIPT_NAME'}?HOSTNAME'><b>$tr{'hostname'}</b></a></th>
407 <th width='25%' align='center'><a href='$ENV{'SCRIPT_NAME'}?ENDTIME'><b>$tr{'lease expires'} (local time d/m/y)</b></a></th>
408 <th width='5%' align='center'><b>Add to fix leases<b></th>
409 </tr>
410 END
411 ;
412
413 open(LEASES,"/var/state/dhcp/dhcpd.leases") or die "Can't open dhcpd.leases";
414 while ($line = <LEASES>) {
415 next if( $line =~ /^\s*#/ );
416 chomp($line);
417 @temp = split (' ', $line);
418
419 if ($line =~ /^\s*lease/) {
420 $ip = $temp[1];
421 #All field are not necessarily read. Clear everything
422 $endtime = 0;
423 $ether = "";
424 $hostname = "";
425 }
426
427 if ($line =~ /^\s*ends/) {
428 $line =~ /(\d+)\/(\d+)\/(\d+) (\d+):(\d+):(\d+)/;
429 $endtime = timegm($6, $5, $4, $3, $2 - 1, $1 - 1900);
430 }
431
432 if ($line =~ /^\s*hardware ethernet/) {
433 $ether = $temp[2];
434 $ether =~ s/;//g;
435 }
436
437 if ($line =~ /^\s*client-hostname/) {
438 $hostname = "$temp[1] $temp[2] $temp[3]";
439 $hostname =~ s/;//g;
440 $hostname =~ s/\"//g;
441 }
442
443 if ($line eq "}") {
444 @record = ('IPADDR',$ip,'ENDTIME',$endtime,'ETHER',$ether,'HOSTNAME',$hostname);
445 $record = {}; # create a reference to empty hash
446 %{$record} = @record; # populate that hash with @record
447 $entries{$record->{'IPADDR'}} = $record; # add this to a hash of hashes
448 }
449 }
450 close(LEASES);
451
452 my $id = 0;
453 my $col="";
454 foreach my $key (sort leasesort keys %entries) {
455 print "<form method='post' action='/cgi-bin/dhcp.cgi'>\n";
456 my $hostname = &cleanhtml($entries{$key}->{HOSTNAME},"y");
457
458 if ($id % 2) {
459 print "<tr>";
460 $col="bgcolor='$table1colour'";
461 }
462 else {
463 print "<tr>";
464 $col="bgcolor='$table2colour'";
465 }
466
467 print <<END
468 <td align='center' $col><input type='hidden' name='FIX_ADDR' value='$entries{$key}->{IPADDR}' />$entries{$key}->{IPADDR}</td>
469 <td align='center' $col><input type='hidden' name='FIX_MAC' value='$entries{$key}->{ETHER}' />$entries{$key}->{ETHER}</td>
470 <td align='center' $col><input type='hidden' name='FIX_REMARK' value='$hostname' />&nbsp;$hostname</td>
471 <td align='center' $col><input type='hidden' name='FIX_ENABLED' value='on' />
472 END
473 ;
474
475 ($sec, $min, $hour, $mday, $mon, $year, $wday, $yday, $dst) = localtime ($entries{$key}->{ENDTIME});
476 $enddate = sprintf ("%02d/%02d/%d %02d:%02d:%02d",$mday,$mon+1,$year+1900,$hour,$min,$sec);
477
478 if ($entries{$key}->{ENDTIME} < time() ){
479 print "<strike>$enddate</strike>";
480 } else {
481 print "$enddate";
482 }
483 print <<END
484 </td><td $col><input type='hidden' name='ACTION' value='$Lang::tr{'add'}2' /><input type='submit' name='SUBMIT' value='$Lang::tr{'add'}' />
485 </td></tr></form>
486 END
487 ;
488 $id++;
489 }
490
491 print "</table>";
492 &closebox();
493 }
494
495
496 # This sub is used during display of actives leases
497 sub leasesort {
498 if (rindex ($dhcpsettings{'SORT_LEASELIST'},'Rev') != -1)
499 {
500 $qs=substr ($dhcpsettings{'SORT_LEASELIST'},0,length($dhcpsettings{'SORT_LEASELIST'})-3);
501 if ($qs eq 'IPADDR') {
502 @a = split(/\./,$entries{$a}->{$qs});
503 @b = split(/\./,$entries{$b}->{$qs});
504 ($b[0]<=>$a[0]) ||
505 ($b[1]<=>$a[1]) ||
506 ($b[2]<=>$a[2]) ||
507 ($b[3]<=>$a[3]);
508 }else {
509 $entries{$b}->{$qs} cmp $entries{$a}->{$qs};
510 }
511 }
512 else #not reverse
513 {
514 $qs=$dhcpsettings{'SORT_LEASELIST'};
515 if ($qs eq 'IPADDR') {
516 @a = split(/\./,$entries{$a}->{$qs});
517 @b = split(/\./,$entries{$b}->{$qs});
518 ($a[0]<=>$b[0]) ||
519 ($a[1]<=>$b[1]) ||
520 ($a[2]<=>$b[2]) ||
521 ($a[3]<=>$b[3]);
522 }else {
523 $entries{$a}->{$qs} cmp $entries{$b}->{$qs};
524 }
525 }
526 }
527
528 sub colorize {
529 my $string = $_[0];
530 my @array = split(/\//,$string);
531 my $string2 = $array[0];
532
533 if ( $string eq "*" or $string eq "" ){
534 return $string;
535 } elsif ( $string =~ "ipsec" ){
536 return "<font color='".${Header::colourvpn}."'>".$string."</font>";
537 } elsif ( $string =~ "tun" ){
538 return "<font color='".${Header::colourovpn}."'>".$string."</font>";
539 } elsif ( $string =~ "lo" or $string =~ "127.0.0.0" ){
540 return "<font color='".${Header::colourfw}."'>".$string."</font>";
541 } elsif ( $string =~ $ethsettings{'GREEN_DEV'} or &IpInSubnet($string2,$ethsettings{'GREEN_NETADDRESS'},$ethsettings{'GREEN_NETMASK'}) ){
542 return "<font color='".${Header::colourgreen}."'>".$string."</font>";
543 } elsif ( $string =~ "ppp0" or $string =~ $ethsettings{'RED_DEV'} or $string =~ "0.0.0.0" or $string =~ $ethsettings{'RED_ADDRESS'} ){
544 return "<font color='".${Header::colourred}."'>".$string."</font>";
545 } elsif ( $ethsettings{'CONFIG_TYPE'}>1 and ( $string =~ $ethsettings{'BLUE_DEV'} or &IpInSubnet($string2,$ethsettings{'BLUE_NETADDRESS'},$ethsettings{'BLUE_NETMASK'}) )){
546 return "<font color='".${Header::colourblue}."'>".$string."</font>";
547 } elsif ( $ethsettings{'CONFIG_TYPE'}>2 and ( $string =~ $ethsettings{'ORANGE_DEV'} or &IpInSubnet($string2,$ethsettings{'ORANGE_NETADDRESS'},$ethsettings{'ORANGE_NETMASK'}) )){
548 return "<font color='".${Header::colourorange}."'>".$string."</font>";
549 } else {
550 return $string;
551 }
552 }