403Webshell
Server IP : 142.11.234.102  /  Your IP : 216.73.217.70
Web Server : Apache
System : Linux dal-shared-66.hostwindsdns.com 4.18.0-513.24.1.lve.1.el8.x86_64 #1 SMP Thu May 9 15:10:09 UTC 2024 x86_64
User : krnuyqrm ( 1183)
PHP Version : 7.4.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /opt/cloudlinux/venv/lib64/python3.11/site-packages/clcommon/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /opt/cloudlinux/venv/lib64/python3.11/site-packages//clcommon/clcustomscript.py
#!/usr/bin/python
# coding=utf-8
import os
import stat

__author__ = "Aleksandr Shyshatsky"


def _is_safe_script(path):
    """Return True only if path is absolute, a regular file, executable,
    owned by root, and not writable by group or other (F-13)."""
    if not (os.path.isabs(path) and os.path.isfile(path)
            and os.access(path, os.X_OK)):
        return False
    try:
        st = os.stat(path)
    except OSError:
        return False
    if st.st_uid != 0 or st.st_gid != 0:
        return False
    if st.st_mode & (stat.S_IWGRP | stat.S_IWOTH):
        return False
    return True


def lvectl_custompanel_script():
    """
    Retrives custom panel script for lvectl from CL config file
    :return: Script full path or None if script filename not find in config
    """
    config_param_name = 'CUSTOM_GETPACKAGE_SCRIPT'
    try:
        # Try to determine custom script name
        if os.path.exists(CLSYSCONFIG):
            with open(CLSYSCONFIG, 'r', encoding='utf-8') as f:
                file_lines = f.readlines()
            for line in file_lines:
                line = line.strip()
                if line.startswith(config_param_name):
                    line_parts = line.split('=')
                    if len(line_parts) == 2 and line_parts[0].strip() == config_param_name:
                        script_name = line_parts[1].strip()
                        if _is_safe_script(script_name):
                            return script_name
    except (OSError, IOError, IndexError):
        # We are ignoring all errors, but script name not found in this case
        pass
    # Script name not found or error
    return None


CLSYSCONFIG = '/etc/sysconfig/cloudlinux'

Youez - 2016 - github.com/yon3zu
LinuXploit