-
Notifications
You must be signed in to change notification settings - Fork 13
Expand file tree
/
Copy pathflowview_security.php
More file actions
73 lines (65 loc) · 2.05 KB
/
Copy pathflowview_security.php
File metadata and controls
73 lines (65 loc) · 2.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
<?php
/*
+-------------------------------------------------------------------------+
| Copyright (C) 2004-2026 The Cacti Group |
+-------------------------------------------------------------------------+
| Cacti: The Complete RRDtool-based Graphing Solution |
+-------------------------------------------------------------------------+
*/
/**
* Validates and normalizes a listener port value (accepting an int or a
* purely-numeric string) to an integer within the valid TCP/UDP port
* range. Called from flowview_build_listener_status_command() before
* building a shell command that embeds the port value, to prevent
* command injection via an unvalidated port.
* not a valid port.
*
* @param mixed $value
*
* @return mixed
*/
function flowview_normalize_listener_port($value) {
if (is_int($value)) {
$port = $value;
} elseif (is_string($value) && preg_match('/^[0-9]+$/', $value)) {
$port = (int) $value;
} else {
return false;
}
if ($port < 1 || $port > 65535) {
return false;
}
return $port;
}
/**
* Builds an OS-appropriate shell command string to check whether a
* given port has an active listener, validating the port first to
* ensure it can't be used for shell command injection. Called from
* device/collector connectivity checks before checking whether the
* flow collector's listener port is active.
* FreeBSD-style netstat filter, otherwise a
* Linux-style command is used.
* flowview_normalize_listener_port()).
* command instead of the preferred `ss`
* command (non-FreeBSD only).
* the port is invalid.
*
* @param mixed $os
* @param mixed $port
* @param bool $use_fallback
*
* @return mixed
*/
function flowview_build_listener_status_command($os, $port, bool $use_fallback = false) {
$port = flowview_normalize_listener_port($port);
if ($port === false) {
return false;
}
if ($os == 'freebsd') {
return "netstat -an | grep '." . $port . " '";
}
if ($use_fallback) {
return "netstat -an | grep ':" . $port . " '";
}
return "ss -lntu | grep ':" . $port . " '";
}