Compare commits

..
139 Commits
Author SHA1 Message Date
Mr Chen 628175a8ee Merge pull request #368 from midoks/dev
0.12.3
2023-02-14 20:13:04 +08:00
Mr Chen 96d0115257 Merge branch 'master' into dev 2023-02-14 20:12:50 +08:00
midoks 801fdf51a7 0.12.3
### 版本更新 0.12.3

* 优先使用firewalld防火墙。
* PHP[APT]加入curl扩展。
* 配置添加【未认证响应状态】功能。
* 存在ipv6时,启动时强制开启。
* OP防火墙-性能优化。
* 网站统计优化。
* 优化backup_ftp插件。
* 各种细节优化。
2023-02-14 20:11:16 +08:00
midoks 24fa3a7ca9 优化backup_ftp插件 2023-02-14 18:29:08 +08:00
midoks 3dc781498c Update index.py 2023-02-14 18:24:43 +08:00
midoks c3afaeb35a Update index.py 2023-02-14 18:23:42 +08:00
midoks 4390180a89 Update config_api.py 2023-02-14 18:20:54 +08:00
midoks 98e22f6eeb Update index.py 2023-02-14 18:19:00 +08:00
midoks 3bfd0f34f5 Update index.py 2023-02-14 18:14:27 +08:00
midoks ec8e46494a Update crontab.js 2023-02-14 18:10:14 +08:00
midoks 7cb9b0acec Update index.py 2023-02-14 17:56:16 +08:00
midoks f97d2a5987 Update ngx_debug.sh 2023-02-13 20:46:19 +08:00
midoks 5a50fe70a8 Update ngx_debug.sh 2023-02-13 20:45:57 +08:00
midoks 4ecb28575e Update install.sh 2023-02-13 20:34:25 +08:00
midoks 07bf8f162c Update debian.sh 2023-02-13 19:27:08 +08:00
midoks 19beb1bccc Update requirements.txt 2023-02-13 19:21:24 +08:00
midoks 33c27d7924 up 2023-02-13 18:56:49 +08:00
midoks a9fb6c9ec9 up 2023-02-13 18:15:10 +08:00
midoks 7198a4de95 up 2023-02-13 15:56:41 +08:00
midoks 53cb56ddf2 up 2023-02-13 15:39:57 +08:00
midoks e4582f328c Update index.py 2023-02-13 14:35:14 +08:00
midoks bb7f1b6a7d up 2023-02-13 14:16:06 +08:00
midoks 1781d879d1 up 2023-02-13 13:36:32 +08:00
midoks d89158124f Update ngx_debug.sh 2023-02-13 03:29:54 +08:00
midoks bfdad5f9a3 Update ngx_debug.sh 2023-02-13 03:23:40 +08:00
midoks 165d9ba14d Update webstats_common.lua 2023-02-13 03:05:26 +08:00
midoks ad102aa940 Update ngx_debug.sh 2023-02-13 03:01:16 +08:00
midoks 1489d15d74 Update ngx_debug.sh 2023-02-13 02:31:08 +08:00
midoks 2dbda3e6dd 优化,Linux系统不再加入到计划任务获取cpu使用率 2023-02-13 01:58:36 +08:00
midoks 4775d4f756 Update waf_common.lua 2023-02-13 01:45:49 +08:00
midoks f57fd600e6 Update test_get_cpu.lua 2023-02-13 01:38:24 +08:00
midoks bf281107b2 up 2023-02-13 00:26:31 +08:00
midoks 083fe59fa5 up 2023-02-12 17:29:29 +08:00
midoks 8f36e0ccb2 Update centos.sh 2023-02-12 02:15:12 +08:00
midoks a5b3a650eb up 2023-02-12 02:14:18 +08:00
midoks 177a08af91 Update waf_common.lua 2023-02-12 02:12:34 +08:00
midoks 5ef4b3d05d firewalld优先 2023-02-12 02:12:28 +08:00
midoks ad3d93cf8b firewalld防火墙优先 2023-02-12 02:03:57 +08:00
midoks 72643b7776 Update rhel.sh 2023-02-12 02:02:27 +08:00
midoks 45128636b0 up 2023-02-12 01:17:23 +08:00
midoks 7b962335e4 up 2023-02-12 01:08:03 +08:00
midoks c0c67095be up 2023-02-12 01:02:19 +08:00
midoks b3a0f11a80 up 2023-02-12 00:44:35 +08:00
midoks 088337765c Update webstats_worker.lua 2023-02-12 00:35:52 +08:00
midoks 066e7087c9 Update webstats_common.lua 2023-02-12 00:35:39 +08:00
midoks 29144595a6 网站统计 2023-02-12 00:22:39 +08:00
midoks 45c2b3cdca Update index.py 2023-02-11 23:44:19 +08:00
midoks e3ecdfb2b3 Update index.py 2023-02-11 23:43:51 +08:00
midoks 560d482f31 up 2023-02-11 23:25:29 +08:00
midoks 62ffc94b69 up 2023-02-11 22:34:18 +08:00
midoks 0cb10cc926 Update webstats_common.lua 2023-02-11 22:23:34 +08:00
midoks fb4eb8747c Update webstats_common.lua 2023-02-11 22:16:08 +08:00
midoks 1a26b83a46 Update webstats_log.lua 2023-02-11 22:06:04 +08:00
midoks 7c2316f005 Update webstats_common.lua 2023-02-11 21:50:32 +08:00
midoks 149baeb1fc Update webstats_log.lua 2023-02-11 21:42:57 +08:00
midoks 9714bcb419 Update init.lua 2023-02-11 17:45:17 +08:00
midoks 4e6a54dbad Update index.py 2023-02-11 17:18:24 +08:00
midoks 18498813c6 up 2023-02-11 17:06:24 +08:00
midoks 854e34a90c Update mw.py 2023-02-11 16:48:57 +08:00
midoks a0898c849e Update lua.conf 2023-02-11 16:47:46 +08:00
midoks 3a26b71828 ip 2023-02-11 16:45:28 +08:00
midoks f500dcac8b Update init_worker.lua 2023-02-11 16:06:25 +08:00
midoks 3a6e2e6e4b Update cpu_usage_file.sh 2023-02-11 16:06:08 +08:00
midoks 1d439e788c Update soft.html 2023-02-11 15:25:44 +08:00
midoks 75a2fcdaaf Update debian.sh 2023-02-11 15:24:17 +08:00
midoks 2ca8598671 up 2023-02-11 06:04:55 +08:00
midoks 2d42486ac5 Update index.py 2023-02-11 05:30:38 +08:00
midoks 24f22b5b8c up 2023-02-11 05:28:54 +08:00
midoks 68f8638638 up 2023-02-11 05:28:27 +08:00
midoks fe6b16eda4 Update index.py 2023-02-11 05:27:34 +08:00
midoks 4e35c34854 up 2023-02-11 05:24:53 +08:00
midoks cc51d9501f Update init.lua 2023-02-11 05:04:37 +08:00
midoks c08cfd4763 Update ip_white.json 2023-02-11 05:00:58 +08:00
midoks 5fdcb8bf71 up 2023-02-11 04:43:30 +08:00
midoks ce3b232c4b Update mw.py 2023-02-11 04:03:41 +08:00
midoks ec7ae65f7d up 2023-02-11 02:52:02 +08:00
midoks e4c5212ac4 Update public.js 2023-02-11 02:51:42 +08:00
midoks 23442accaf Update mw.py 2023-02-11 02:51:25 +08:00
midoks 2e6f5f9add up 2023-02-11 02:51:17 +08:00
midoks 110e356fae up 2023-02-09 17:05:06 +08:00
midoks a243d088ee Update tool_task.py 2023-02-05 16:22:17 +08:00
midoks 365fd466c2 更快获取cpu使用率 2023-02-05 16:21:30 +08:00
midoks d1304de69e Update cli.sh 2023-02-05 15:22:53 +08:00
midoks e51fa2608d Update cli.sh 2023-02-05 15:21:45 +08:00
midoks cbfcd00317 Update mw.tpl 2023-02-05 15:20:08 +08:00
midoks 7a96d3abc5 Update mw.tpl 2023-02-05 15:19:50 +08:00
midoks 33a510a5b5 Update mw.tpl 2023-02-05 12:50:26 +08:00
midoks e8942128b8 Update tool_task.py 2023-02-05 12:49:21 +08:00
midoks 7e2bd928e2 Update tool_task.py 2023-02-05 12:42:30 +08:00
midoks 89185476aa 优化获取cpu方式。 2023-02-05 12:37:49 +08:00
midoks f491641ab8 Create cpu_usage.sh 2023-02-05 12:25:57 +08:00
midoks 8b108d1aff Update ubuntu.sh 2023-02-05 12:16:55 +08:00
midoks 2cfa7ec2ab Update ubuntu.sh 2023-02-05 12:07:29 +08:00
midoks d63aae100d Update ubuntu.sh 2023-02-05 11:57:44 +08:00
midoks e8249adc53 Update tool_task.py 2023-02-05 03:48:22 +08:00
midoks 281427e479 Update tool_task.py 2023-02-05 03:48:03 +08:00
midoks af775fc77d OP防火墙-获取cpu优化 2023-02-05 03:40:18 +08:00
midoks f328354125 #362 2023-02-05 00:25:59 +08:00
midoks 1f70f962cf Update crontab.js 2023-02-05 00:25:25 +08:00
midoks 414787447e Update README.md 2023-02-04 19:27:55 +08:00
midoks 979f2174e5 Update README.md 2023-02-03 21:28:29 +08:00
midoks 84d1c96094 Update config_api.py 2023-02-03 21:17:25 +08:00
midoks 0d8d9022a0 Update mw.py 2023-02-03 21:17:07 +08:00
midoks 44d0e9e11c 存在ipv6,启动时强制开启 2023-02-03 13:42:35 +08:00
midoks 771d6e04ba Update mw.tpl 2023-02-03 13:39:45 +08:00
midoks 87563daa1d Update index.html 2023-02-02 20:50:42 +08:00
midoks 9fefb285e1 Update .gitignore 2023-02-02 20:47:18 +08:00
midoks b9ca4fc11e 配置添加【未认证响应状态】功能 2023-02-02 18:04:44 +08:00
midoks 2646d0565d Update debian.sh 2023-02-02 15:23:35 +08:00
midoks e1f900f1c5 Update tools.py 2023-02-02 14:59:15 +08:00
midoks 908b3341b2 Update rhel.sh 2023-02-01 13:25:01 +08:00
midoks 5aef2467b1 Update debian.sh 2023-02-01 13:20:53 +08:00
midoks f59114a688 自动获取ssh端口 2023-02-01 13:09:28 +08:00
midoks 363ed8b3ff Update index.py 2023-01-31 20:07:39 +08:00
midoks 3970feacc3 Update gitea.js 2023-01-31 19:48:30 +08:00
midoks f6c528149e Update gitea.js 2023-01-31 19:41:00 +08:00
midoks 8f6b5ddba9 Update gitea.js 2023-01-31 19:36:50 +08:00
midoks ef350b9fd2 Update gitea.js 2023-01-31 19:33:46 +08:00
midoks 004dfb5e7d apt php curl是必须的扩展 2023-01-30 14:01:57 +08:00
midoks 3c08d7c159 Update files_api.py 2023-01-30 01:17:09 +08:00
midoks e227204065 编码识别优化。 2023-01-30 00:50:10 +08:00
midoks ce653b7a6a Update README.md 2023-01-29 22:31:52 +08:00
Mr Chen a207215775 Merge pull request #355 from midoks/midoks-patch-1
Update debian.sh
2023-01-29 20:52:22 +08:00
Mr Chen 8115b0fb4d Update debian.sh 2023-01-29 20:48:51 +08:00
midoks 048bd573e8 修复API接口使用 2023-01-29 14:32:38 +08:00
midoks 918ea8d0f9 Update mw.tpl 2023-01-28 11:22:57 +08:00
midoks 97d2fd5a63 Update debian.sh 2023-01-28 10:50:31 +08:00
midoks 617a517048 Update index.html 2023-01-28 01:57:54 +08:00
midoks 2e7910a84c 一键迁移初始化 2023-01-28 01:34:48 +08:00
midoks 2ee4c4e3fd 页面更新跟随更新一遍环境 2023-01-27 21:58:10 +08:00
midoks 9ae4d32ed4 卸载时,删除首页显示 2023-01-27 21:05:16 +08:00
midoks 90a7f4ea10 Update .gitignore 2023-01-27 20:09:09 +08:00
midoks d22cb8305d Update soft.html 2023-01-27 20:08:34 +08:00
midoks a7a78f2103 Update .gitignore 2023-01-27 16:20:50 +08:00
Mr Chen db7ec00c07 Merge pull request #352 from midoks/dev
优化在命令行下修改端口命令
2023-01-27 16:09:29 +08:00
midoks dd21d25295 Update tools.py 2023-01-27 16:04:54 +08:00
midoks f7360aa081 Update tools.py 2023-01-27 16:02:21 +08:00
midoks 1d1ba7192a Update tools.py 2023-01-27 16:00:02 +08:00
midoks 0bf540c5e7 Update mw.py 2023-01-27 15:54:55 +08:00
73 changed files with 1841 additions and 687 deletions
+6 -1
View File
@@ -154,11 +154,15 @@ data/basic_auth.json
data/api.json
data/bind_domain.pl
plugins/vip_*
plugins/own_*
plugins/my_*
plugins/l2tp
plugins/openlitespeed
plugins/migration_api
plugins/system_safe
plugins/tamper_proof
plugins/tamper_proof_*
plugins/op_load_balance
plugins/gdrive
plugins/mtproxy
plugins/zimg
@@ -171,3 +175,4 @@ plugins/file_search
debug.out
data/unauthorized_status.pl
+16 -12
View File
@@ -29,6 +29,12 @@
基本上可以使用,后续会继续优化!欢迎提供意见!
- 吹水组 - https://t.me/mdserver_web
```
如果出现问题,最好私给我面板信息。不要让我猜。如果不提供,不要提出问题,自行解决。 — 座右铭
Talk is cheap, show me the code. -- linus
```
- [兼容性测试报告](/compatibility.md)
- [常用命令说明](/cmd.md)
@@ -38,6 +44,7 @@
* PHP[53-82] - PHP是世界上最好的编程语言。
* MySQL - 一种关系数据库管理系统。
* MariaDB - 是MySQL的一个重要分支。
* MySQL[APT/YUM] - 一种关系数据库管理系统。
* MongoDB - 一种非关系NOSQL数据库管理系统。
* phpMyAdmin - 著名Web端MySQL管理工具。
* Memcached - 一个高性能的分布式内存对象缓存系统。
@@ -84,27 +91,24 @@ PHP[72-81]支持phpMyAdmin[5.2.0]
# Docker
- 由[DDSRem](https://github.com/DDSRem)开发维护。
- https://hub.docker.com/r/ddsderek/mw-server
- https://hub.docker.com/r/ddsderek/mw
```
docker run -itd --name mw-server --privileged=true -p 7200:7200 -p 80:80 -p 443:443 -p 888:888 ddsderek/mw-server:latest
```
### 版本更新 0.12.2
### 版本更新 0.12.3
* 开放菜单权限配置。
* 升级SSH终端2.0。
* 增加已安装类型。
* 加入切换linux软件源的命令。
* iptables安装优化。
* 网站统计POST获取数据优化。
* mysql[apt/yum]迁移优化。
* 优化防火墙导入。
* 图标可设置。
* 优先使用firewalld防火墙。
* PHP[APT]加入curl扩展。
* 配置添加【未认证响应状态】功能。
* 存在ipv6时,启动时强制开启。
* OP防火墙-性能优化。
* 网站统计优化。
* 优化backup_ftp插件。
* 各种细节优化。
### JSDelivr安装地址
- 初始安装
+43 -3
View File
@@ -27,7 +27,7 @@ from flask import request
class config_api:
__version = '0.12.2'
__version = '0.12.3'
__api_addr = 'data/api.json'
def __init__(self):
@@ -647,9 +647,22 @@ class config_api:
else:
return False, ''
def setStatusCodeApi(self):
status_code = request.form.get('status_code', '').strip()
if re.match("^\d+$", status_code):
status_code = int(status_code)
if status_code != 0:
if status_code < 100 or status_code > 999:
return mw.returnJson(False, '状态码范围错误!')
else:
return mw.returnJson(False, '状态码范围错误!')
mw.writeFile('data/unauthorized_status.pl', str(status_code))
mw.writeLog('面板设置', '将未授权响应状态码设置为:{}'.format(status_code))
return mw.returnJson(True, '设置成功!')
def getPanelTokenApi(self):
api_file = self.__api_addr
tmp = mw.readFile(api_file)
if not os.path.exists(api_file):
ready_data = {"open": False, "token": "", "limit_addr": []}
@@ -668,7 +681,7 @@ class config_api:
token = mw.getRandomString(32)
data['token'] = mw.md5(token)
data['token_crypt'] = mw.enCrypt(
data['token'], token).decode('utf-8')
data['token'], token)
mw.writeFile(api_file, json.dumps(data))
data['token'] = "***********************************"
@@ -714,6 +727,31 @@ class config_api:
mw.writeFile(api_file, json.dumps(data))
return mw.returnJson(True, '保存成功!')
def renderUnauthorizedStatus(self, data):
cfg_unauth_status = 'data/unauthorized_status.pl'
if os.path.exists(cfg_unauth_status):
status_code = mw.readFile(cfg_unauth_status)
data['status_code'] = status_code
data['status_code_msg'] = status_code
if status_code == '0':
data['status_code_msg'] = "默认-安全入口错误提示"
elif status_code == '400':
data['status_code_msg'] = "400-客户端请求错误"
elif status_code == '401':
data['status_code_msg'] = "401-未授权访问"
elif status_code == '403':
data['status_code_msg'] = "403-拒绝访问"
elif status_code == '404':
data['status_code_msg'] = "404-页面不存在"
elif status_code == '408':
data['status_code_msg'] = "408-客户端超时"
elif status_code == '416':
data['status_code_msg'] = "416-无效的请求"
else:
data['status_code'] = '0'
data['status_code_msg'] = "默认-安全入口错误提示"
return data
def get(self):
data = {}
@@ -766,6 +804,8 @@ class config_api:
else:
data['bind_domain'] = ''
data = self.renderUnauthorizedStatus(data)
api_token = self.__api_addr
if os.path.exists(api_token):
bac = mw.readFile(api_token)
+21 -51
View File
@@ -677,56 +677,29 @@ class files_api:
if os.path.getsize(path) > 2097152:
return mw.returnJson(False, '不能在线编辑大于2MB的文件!')
if os.path.isdir(path):
return mw.returnJson(False, '这不是一个文件!')
fp = open(path, 'rb')
data = {}
data['status'] = True
try:
if fp:
from chardet.universaldetector import UniversalDetector
detector = UniversalDetector()
srcBody = b""
for line in fp.readlines():
detector.feed(line)
srcBody += line
detector.close()
char = detector.result
data['encoding'] = char['encoding']
if char['encoding'] == 'GB2312' or not char['encoding'] or char[
'encoding'] == 'TIS-620' or char['encoding'] == 'ISO-8859-9':
data['encoding'] = 'GBK'
if char['encoding'] == 'ascii' or char[
'encoding'] == 'ISO-8859-1':
data['encoding'] = 'utf-8'
if char['encoding'] == 'Big5':
data['encoding'] = 'BIG5'
if not data['encoding'] in ['GBK', 'utf-8', 'BIG5']:
data['encoding'] = 'utf-8'
if fp:
srcBody = fp.read()
fp.close()
encoding_list = ['utf-8', 'GBK', 'BIG5']
for el in encoding_list:
try:
if sys.version_info[0] == 2:
data['data'] = srcBody.decode(
data['encoding']).encode('utf-8', errors='ignore')
else:
data['data'] = srcBody.decode(data['encoding'])
except:
data['encoding'] = char['encoding']
if sys.version_info[0] == 2:
data['data'] = srcBody.decode(
data['encoding']).encode('utf-8', errors='ignore')
else:
data['data'] = srcBody.decode(data['encoding'])
return mw.returnJson(True, 'OK', data)
else:
if sys.version_info[0] == 2:
data['data'] = srcBody.decode('utf-8').encode('utf-8')
else:
data['data'] = srcBody.decode('utf-8')
data['encoding'] = 'utf-8'
data['encoding'] = el
data['data'] = srcBody.decode(data['encoding'])
break
except Exception as ex:
if el == 'BIG5':
return mw.returnJson(False, '文件编码不被兼容,无法正确读取文件!' + str(ex))
else:
return mw.returnJson(False, '文件未正常打开!')
return mw.returnJson(True, 'OK', data)
except Exception as ex:
return mw.returnJson(False, '文件编码不被兼容,无法正确读取文件!' + str(ex))
return mw.returnJson(True, 'OK', data)
def saveBody(self, path, data, encoding='utf-8'):
if not os.path.exists(path):
@@ -734,13 +707,10 @@ class files_api:
try:
if encoding == 'ascii':
encoding = 'utf-8'
if sys.version_info[0] == 2:
data = data.encode(encoding, errors='ignore')
fp = open(path, 'w+')
else:
data = data.encode(
encoding, errors='ignore').decode(encoding)
fp = open(path, 'w+', encoding=encoding)
data = data.encode(
encoding, errors='ignore').decode(encoding)
fp = open(path, 'w+', encoding=encoding)
fp.write(data)
fp.close()
+4 -4
View File
@@ -34,13 +34,13 @@ class firewall_api:
def __init__(self):
iptables_file = mw.systemdCfgDir() + '/iptables.service'
if os.path.exists(iptables_file):
self.__isIptables = True
if os.path.exists('/usr/sbin/firewalld'):
self.__isFirewalld = True
if os.path.exists('/usr/sbin/ufw'):
elif os.path.exists(iptables_file):
self.__isIptables = True
elif os.path.exists('/usr/sbin/ufw'):
self.__isUfw = True
if mw.isAppleSystem():
elif mw.isAppleSystem():
self.__isMac = True
##### ----- start ----- ###
+108 -5
View File
@@ -228,6 +228,14 @@ def isIpAddr(ip):
return False
def getWebStatus():
pid = getServerDir() + '/openresty/nginx/logs/nginx.pid'
if os.path.exists(pid):
return True
return False
# ------------------------------ openresty start -----------------------------
def restartWeb():
return opWeb("reload")
@@ -252,6 +260,63 @@ def opWeb(method):
return False
def opLuaMake(cmd_name):
path = getServerDir() + '/web_conf/nginx/lua/lua.conf'
root_dir = getServerDir() + '/web_conf/nginx/lua/' + cmd_name
dst_path = getServerDir() + '/web_conf/nginx/lua/' + cmd_name + '.lua'
def_path = getServerDir() + '/web_conf/nginx/lua/empty.lua'
if not os.path.exists(root_dir):
execShell('mkdir -p ' + root_dir)
files = []
for fl in os.listdir(root_dir):
suffix = getFileSuffix(fl)
if suffix != 'lua':
continue
flpath = os.path.join(root_dir, fl)
files.append(flpath)
if len(files) > 0:
def_path = dst_path
content = ''
for f in files:
t = readFile(f)
f_base = os.path.basename(f)
content += '-- ' + '*' * 20 + ' ' + f_base + ' start ' + '*' * 20 + "\n"
content += t
content += "\n" + '-- ' + '*' * 20 + ' ' + f_base + ' end ' + '*' * 20 + "\n"
writeFile(dst_path, content)
else:
if os.path.exists(dst_path):
os.remove(dst_path)
conf = readFile(path)
conf = re.sub(cmd_name + ' (.*);',
cmd_name + " " + def_path + ";", conf)
writeFile(path, conf)
def opLuaInitFile():
opLuaMake('init_by_lua_file')
def opLuaInitWorkerFile():
opLuaMake('init_worker_by_lua_file')
def opLuaInitAccessFile():
opLuaMake('access_by_lua_file')
def opLuaMakeAll():
opLuaInitFile()
opLuaInitWorkerFile()
opLuaInitAccessFile()
# ------------------------------ openresty end -----------------------------
def restartMw():
import system_api
system_api.system_api().restartMw()
@@ -462,15 +527,15 @@ def getDataFromInt(val):
def writeLog(stype, msg, args=()):
# 写日志
uid = 1
try:
from flask import session
uid = 1
if 'uid' in session:
uid = session['uid']
return writeDbLog(stype, msg, args, uid)
except Exception as e:
print(getTracebackInfo())
return False
pass
# print(getTracebackInfo())
return writeDbLog(stype, msg, args, uid)
def writeDbLog(stype, msg, args=(), uid=1):
@@ -580,7 +645,7 @@ def enCrypt(key, strings):
# 加密字符串
try:
import base64
_key = md5(key).encode('utf-8')
_key = key.encode('utf-8')
_key = base64.urlsafe_b64encode(_key)
if type(strings) != bytes:
@@ -596,6 +661,44 @@ def enCrypt(key, strings):
def deCrypt(key, strings):
# 解密字符串
try:
import base64
_key = key.encode('utf-8')
_key = base64.urlsafe_b64encode(_key)
if type(strings) != bytes:
strings = strings.encode('utf-8')
from cryptography.fernet import Fernet
f = Fernet(_key)
result = f.decrypt(strings).decode('utf-8')
return result
except:
print(getTracebackInfo())
return strings
def enDoubleCrypt(key, strings):
# 加密字符串
try:
import base64
_key = md5(key).encode('utf-8')
_key = base64.urlsafe_b64encode(_key)
if type(strings) != bytes:
strings = strings.encode('utf-8')
import cryptography
from cryptography.fernet import Fernet
f = Fernet(_key)
result = f.encrypt(strings)
return result.decode('utf-8')
except:
print(getTracebackInfo())
return strings
def deDoubleCrypt(key, strings):
# 解密字符串
try:
import base64
+1 -1
View File
@@ -320,7 +320,7 @@ class ssh_terminal:
def getSshInfo(self, file):
rdata = mw.readFile(file)
destr = mw.deCrypt('mdserver-web', rdata)
destr = mw.enDoubleCrypt('mdserver-web', rdata)
return json.loads(destr)
def setAttr(self, sid, info):
+20
View File
@@ -724,6 +724,26 @@ class system_api:
mw.execShell('rm -rf ' + toPath + '/mdserver-web-' + version)
mw.execShell('rm -rf ' + toPath + '/mw.zip')
update_env = '''
#!/bin/bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
if [ ! -f /www/server/mdserver-web/bin/activate ];then
cd /www/server/mdserver-web && python3 -m venv .
cd /www/server/mdserver-web && source /www/server/mdserver-web/bin/activate
else
cd /www/server/mdserver-web && source /www/server/mdserver-web/bin/activate
fi
cn=$(curl -fsSL -m 10 http://ipinfo.io/json | grep "\"country\": \"CN\"")
PIPSRC="https://pypi.python.org/simple"
if [ ! -z "$cn" ];then
PIPSRC="https://pypi.tuna.tsinghua.edu.cn/simple"
fi
cd /www/server/mdserver-web && pip3 install -r /www/server/mdserver-web/requirements.txt -i $PIPSRC
'''
os.system(update_env)
self.restartMw()
return mw.returnJson(True, '安装更新成功!')
+8 -8
View File
@@ -21,12 +21,12 @@ mw_start_task()
sleep 0.3
isStart=$(ps aux |grep 'task.py'|grep -v grep|awk '{print $2}')
if [ "$isStart" == '' ];then
echo -e "\033[31mfailed\033[0m"
echo '------------------------------------------------------'
tail -n 20 $DIR/logs/task.log
echo '------------------------------------------------------'
echo -e "\033[31mError: mw-tasks service startup failed.\033[0m"
return;
echo -e "\033[31mfailed\033[0m"
echo '------------------------------------------------------'
tail -n 20 $DIR/logs/task.log
echo '------------------------------------------------------'
echo -e "\033[31mError: mw-tasks service startup failed.\033[0m"
return;
fi
echo -e "\033[32mdone\033[0m"
else
@@ -62,14 +62,14 @@ mw_stop()
PLIST=`ps -ef|grep app:app |grep -v grep|awk '{print $2}'`
for i in $PLIST
do
kill -9 $i
kill -9 $i > /dev/null 2>&1
done
pids=`ps -ef|grep task.py | grep -v grep |awk '{print $2}'`
arr=($pids)
for p in ${arr[@]}
do
kill -9 $p
kill -9 $p > /dev/null 2>&1
done
}
+8 -5
View File
@@ -194,14 +194,17 @@ def backupAllFunc(stype):
'/scripts/backup.py ' + args
os.system(cmd)
# 开始执行上传信息
bk_prefix = prefix_dict[stype]
bk_name = stype
# 开始执行上传信息.
if stype.find('database_') > -1:
bk_name = 'database'
plugin_name = stype.replace('database_', '')
bk_prefix = plugin_name + '/db'
stype = 'database'
else:
bk_prefix = prefix_dict[stype]
bk_name = stype
find_path = mw.getBackupDir() + '/' + bk_name + '/' + bk_prefix + '_' + name
find_new_file = "ls " + find_path + \
@@ -212,10 +215,10 @@ def backupAllFunc(stype):
mw.echoInfo("not find upload file!")
return False
print("|-准备上传文件 {}".format(filename))
ftp = FtpPSClient()
ftp.uploadFile(filename, stype)
return True
return ''
def backupSite():
+2 -2
View File
@@ -8,8 +8,8 @@
<p onclick="pluginConfig('gitea',null, 'conf');">配置文件</p>
<p onclick="gogsSetConfig();">配置修改</p>
<p onclick="giteaUserList();">用户列表</p>
<p onclick="pluginLogs('gitea',null,'run_log');">运行日志</p>
<p onclick="pluginLogs('gitea',null,'post_receive_log');" title="提交post-receive日志">提交日志</p>
<!-- <p onclick="pluginLogs('gitea',null,'run_log');">运行日志</p> -->
<!-- <p onclick="pluginLogs('gitea',null,'post_receive_log');" title="提交post-receive日志">提交日志</p> -->
<p onclick="giteaRead();">使用说明</p>
</div>
<div class="bt-w-con pd15">
+1 -1
View File
@@ -560,7 +560,7 @@ def userProjectList():
data['data'] = ret_data
data['args'] = args
data['list'] = mw.getPage(
{'count': dlist_sum, 'p': page, 'row': page_size, 'tojs': 'userProjectList'})
{'count': dlist_sum, 'p': page, 'row': page_size, 'tojs': 'userProjectListPost'})
return mw.returnJson(True, 'OK', data)
+3 -2
View File
@@ -187,7 +187,7 @@ function userProjectList(user, search){
<thead><tr><th>项目</th><th>操作</th></tr></thead>\
<tbody></tbody>\
</table>\
<div class='dataTables_paginate paging_bootstrap pagination' style='margin-top:0px;'><ul id='gitea_page' class='page'></ul></div>\
<div class='dataTables_paginate paging_bootstrap pagination' style='margin-top:0px;'><ul class='page'><div class='gitea_page'></div></ul></div>\
</div>\
</div>\
</div>",
@@ -230,7 +230,8 @@ function userProjectListPost(user, search){
var project_list = rdata['data']['data'];
for (i in project_list) {
var name = project_list[i]['name'];
list += '<tr><td>'+name+'</td>\
list += '<tr>\
<td>'+name+'</td>\
<td>\
<a class="btlink" target="_blank" href="'+rdata['data']['root_url']+user+'/'+name+'">源码</a> | \
<a class="btlink" onclick="projectScript(\''+user+'\',\''+name+'\','+project_list[i]['has_hook']+');">脚本</a>\
+5 -2
View File
@@ -62,13 +62,16 @@ def getArgs():
if args_len == 1:
t = args[0].strip('{').strip('}')
t = t.split(':')
if t.strip() == '':
tmp = []
else:
t = t.split(':')
tmp[t[0]] = t[1]
tmp[t[0]] = t[1]
elif args_len > 1:
for i in range(len(args)):
t = args[i].split(':')
tmp[t[0]] = t[1]
return tmp
Binary file not shown.

After

Width:  |  Height:  |  Size: 478 B

+292
View File
@@ -0,0 +1,292 @@
<style>
.migration_content {
position: relative;
height: 450px;
}
.step_head::after {
background-color: #ddd;
border-top: 2px solid #ccc;
content: "";
display: block;
height: 3px;
left: 84px;
position: absolute;
top: 14px;
width: 500px;
z-index: -1;
}
.step_head {
margin: 20px 0;
}
.step_head ul li {
width: 24.5%;
display: inline-block;
}
.step_head ul li span {
width: 30px;
height: 30px;
line-height: 30px;
display: block;
border-radius: 15px;
background-color: #ddd;
color: #878787;
margin: 0 auto;
text-align: center;
font-size: 16px;
font-weight: 600;
}
.step_head ul li p {
text-align: center;
margin-top: 15px;
}
.step_head ul li.active span {
background-color: #20A53A;
color: #fff;
}
.step_content {
text-align: center;
}
.boxHide {
display: none
}
.step_content .psync_info input {
width: 300px;
}
.step_content .psync_info .panel_setp_span {
height: 32px;
line-height: 32px;
overflow: hidden;
padding-right: 20px;
text-align: right;
text-overflow: ellipsis;
white-space: nowrap;
width: 130px;
display: inline-block;
float: left;
}
.step_content .psync_info .mtb20{
padding-left: 40px;
text-align: left;
}
.psync_path .table {
text-align: left;
}
.psync_path .table > tbody > tr > td:nth-child(2n),
.psync_path .table > thead > tr > th:nth-child(2n),
.terlist .table > thead > tr > th:nth-child(2n),
.terlist .table > tbody > tr > td:nth-child(2n),
.terlist .table > tbody > tr > td:nth-child(1),
.terlist .table > thead > tr > th:nth-child(1) {
border-right: #ddd 1px solid;
}
.checkbox_conten {
background-color: #f3f3f3;
border: #ddd 1px solid;
border-radius: 4px;
padding: 10px;
margin: 0px 50px;
}
.checkbox_item span {
display: inline-block;
height: 15px;
overflow: hidden;
text-align: left;
display: block;
padding-left: 20px;
height: 20px;
line-height: 20px;
width: 152px;
text-overflow: ellipsis;
}
label.checkbox_label {
margin-left: 6px;
margin-bottom: 0;
}
label.checkbox_label span {
color: #000;
}
.psync_data {
display: none;
}
.psync_data .checkbox_item input[type="checkbox"] {
width: 15px;
height: 15px;
position: absolute;
top: 50%;
margin-top: -6px;
}
.checkbox_item label {
font-weight: normal;
white-space: nowrap;
position: relative;
}
.psync_data .checkbox_data {
margin: 0 5px 5px;
display: inline-block;
width: 166px;
vertical-align: text-top;
}
.psync_data .checkbox_data:last-child {
margin-right: 0;
}
.checkbox_item ul {
background-color: #fff;
max-height: 174px;
overflow: auto;
width: 100%;
display: block;
margin-top: 10px;
}
.checkbox_item ul li {
padding: 0 6px;
}
.psync_data .checkbox_con {
display: block
}
.progress {
background-color: #e2e2e2;
border-radius: 8px;
height: 16px;
line-height: 16px;
position: relative;
}
.progress-bar {
background-color: #5ab76c;
border-radius: 8px;
height: 16px;
max-width: 100%;
position: absolute;
text-align: right;
transition: all 0.3s ease 0s;
width: 0;
}
.progress-text {
font-size: 12px;
color: #fff;
padding: 0 10px;
position: static;
}
.qystatus {
color: #666;
margin-bottom: 10px;
margin-left: 5px;
}
.success {
padding: 50px 0 60px;
margin-left: -60px;
}
.success p {
margin-top: 20px;
font-size: 16px;
color: #666;
}
.psync_tips{
color: red;
font-size: 15px;
background-color: #fbfbfb;
border: 1px solid #eee;
line-height: 46px;
margin-bottom: 15px;
padding-left: 10px;
}
.psync_tips span{
font-size: 12px;
}
</style>
<div class="migration_api pd15">
<div class="migration_content">
<div class="step_head">
<ul>
<li class="active"><span>1</span><p>填写信息</p></li>
<li><span>2</span><p>检测环境</p></li>
<li><span>3</span><p>选择数据</p></li>
<li><span>4</span><p>一键迁移</p></li>
</ul>
</div>
<div class="step_content">
<div class="pd15 psync_info">
<div class="psync_tips">
<span class="glyphicon glyphicon-alert" style="color: #f39c12; margin-right: 10px;"></span>只需在发送数据服务器安装本软件,请填写<span>『 接收数据服务器 』</span>资料。
<a href="#" target="_blank" class="bt-ico-ask" style="cursor: pointer;">?</a>
</div>
<div class="mtb20">
<span class="panel_setp_span">接收数据的面板地址</span>
<input type="text" class="bt-input-text" name="psync_url" value="" placeholder="接收数据面板地址,如: http://127.0.0.1:8888">
</div>
<div class="mtb20">
<span class="panel_setp_span">接收数据的面板API</span>
<input type="text" class="bt-input-text" name="psync_token" value="" placeholder="接收数据面板API密钥" />
<a href="#" target="_blank" class="btlink ml5">获取API秘钥</a>
</div>
<div class="mtb20">
<span class="panel_setp_span">IP白名单</span>
<span style="height: 32px;line-height: 32px;">必须将本机器IP加入接收数据服务器API的IP白名单,<a href="#" href="javascript:;" target="_blank" class="btlink">如何添加白名单</a></span>
</div>
<div class="mtb20" style="text-align: left;margin-left: 130px;">
<button class="btn btn-success infoNext">下一步</button>
</div>
</div>
<div class="pa15 psync_path" style="margin:0 50px">
</div>
<div class="pa15 psync_data" style="text-align: left;">
<div class="checkbox_conten">
<div class="checkbox_data">
<div class="checkbox_item">
<label class="checkbox_label">
<input type="checkbox" id="sites_All" checked>
<span>网站</span>
</label>
<ul></ul>
</div>
</div>
<div class="checkbox_data">
<div class="checkbox_item">
<label class="checkbox_label">
<input type="checkbox" id="db_All" checked>
<span>数据库</span>
</label>
<ul></ul>
</div>
</div>
</div>
<div class="line mtb20" style="margin:20px 0 0 50px">
<button class="btn btn-default btn-sm mr20 dataBack">上一步</button>
<button class="btn btn-success btn-sm dataMigrate">一键迁移</button>
</div>
</div>
<div class="pa15 psync_migrate"></div>
</div>
<hr style="margin-top: 5px;" />
<div class="step_footer" style="margin: 5px 0 0 20px;text-align: left;">
<ul class="help-info-text c7 mlr20" style="margin-top: 0px;">
<li>一键迁移过程中是后台执行可以关闭当前窗口</li>
<li>一键迁移迁移数据不涉及原来数据的增删(是将原来数据打包发送)</li>
</ul>
</div>
</div>
</div>
<script type="text/javascript">
resetPluginWinWidth(700);
$.getScript( "/plugins/file?name=migration_api&f=js/app.js", function(){
initStep();
});
</script>
+102
View File
@@ -0,0 +1,102 @@
# coding:utf-8
import sys
import io
import os
import time
import re
sys.path.append(os.getcwd() + "/class/core")
import mw
app_debug = False
if mw.isAppleSystem():
app_debug = True
def getPluginName():
return 'migration_api'
def getPluginDir():
return mw.getPluginDir() + '/' + getPluginName()
def getServerDir():
return mw.getServerDir() + '/' + getPluginName()
def getInitDFile():
if app_debug:
return '/tmp/' + getPluginName()
return '/etc/init.d/' + getPluginName()
def getConf():
path = getServerDir() + "/ma.cfg"
return path
def getCfgData():
path = getConf()
if not os.path.exists(path):
mw.writeFile(path, '{}')
t = mw.returnJson(path)
return json.loads(t)
def getArgs():
args = sys.argv[2:]
tmp = {}
args_len = len(args)
if args_len == 1:
t = args[0].strip('{').strip('}')
if t.strip() == '':
tmp = []
else:
t = t.split(':')
tmp[t[0]] = t[1]
tmp[t[0]] = t[1]
elif args_len > 1:
for i in range(len(args)):
t = args[i].split(':')
tmp[t[0]] = t[1]
return tmp
def checkArgs(data, ck=[]):
for i in range(len(ck)):
if not ck[i] in data:
return (False, mw.returnJson(False, '参数:(' + ck[i] + ')没有!'))
return (True, mw.returnJson(True, 'ok'))
def status():
return 'start'
def initDreplace():
return 'ok'
def stepOne():
data = getCfgData()
print(data)
return mw.returnJson(True, 'ok')
if __name__ == "__main__":
func = sys.argv[1]
if func == 'status':
print(status())
elif func == 'start':
print(start())
elif func == 'stop':
print(stop())
elif func == 'step_one':
print(saveConf())
else:
print('error')
+18
View File
@@ -0,0 +1,18 @@
{
"sort": 7,
"ps": "[<span style='color:red;'>潜龙勿用</span>]一键迁移,仅网站数据和MySQL数据",
"name": "migration_api",
"title": "一键迁移API",
"shell": "install.sh",
"versions":["1.0"],
"updates":["1.0"],
"tip": "soft",
"checks": "server/migration_api",
"path":"server/migration_api",
"display": 1,
"author": "midoks",
"date": "2022-01-17",
"home": "https://github.com/midoks/mdserver-web",
"type": 0,
"pid": "4"
}
+31
View File
@@ -0,0 +1,31 @@
#!/bin/bash
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
curPath=`pwd`
rootPath=$(dirname "$curPath")
rootPath=$(dirname "$rootPath")
serverPath=$(dirname "$rootPath")
install_tmp=${rootPath}/tmp/mw_install.pl
VERSION=1.0
Install_App(){
mkdir -p $serverPath/migration_api
echo "${VERSION}" > $serverPath/migration_api/version.pl
echo '正在安装脚本文件...' > $install_tmp
}
Uninstall_App()
{
rm -rf $serverPath/migration_api
}
action=$1
if [ "${1}" == 'install' ];then
Install_App
else
Uninstall_App
fi
+109
View File
@@ -0,0 +1,109 @@
function maPost(method,args,callback){
var _args = null;
if (typeof(args) == 'string'){
_args = JSON.stringify(toArrayObject(args));
} else {
_args = JSON.stringify(args);
}
var loadT = layer.msg('正在获取...', { icon: 16, time: 0, shade: 0.3 });
$.post('/plugins/run', {name:'migration_api', func:method, args:_args}, function(data) {
layer.close(loadT);
if (!data.status){
layer.msg(data.msg,{icon:0,time:2000,shade: [0.3, '#000']});
return;
}
if(typeof(callback) == 'function'){
callback(data);
}
},'json');
}
function maAsyncPost(method,args){
var _args = null;
if (typeof(args) == 'string'){
_args = JSON.stringify(toArrayObject(args));
} else {
_args = JSON.stringify(args);
}
return syncPost('/plugins/run', {name:'migration_api', func:method, args:_args});
}
function maPostCallbak(method, args, callback){
var loadT = layer.msg('正在获取...', { icon: 16, time: 0, shade: 0.3 });
var req_data = {};
req_data['name'] = 'migration_api';
req_data['func'] = method;
args['version'] = '1.0';
if (typeof(args) == 'string'){
req_data['args'] = JSON.stringify(toArrayObject(args));
} else {
req_data['args'] = JSON.stringify(args);
}
$.post('/plugins/callback', req_data, function(data) {
layer.close(loadT);
if (!data.status){
layer.msg(data.msg,{icon:0,time:2000,shade: [0.3, '#000']});
return;
}
if(typeof(callback) == 'function'){
callback(data);
}
},'json');
}
function initStep1(){
maPost('step_one',{}, function(rdata){
console.log(rdata);
});
}
function initStep2(){
maPost('step_one',{}, function(rdata){
console.log(rdata);
});
}
function initStep3(){
maPost('step_one',{}, function(rdata){
console.log(rdata);
});
}
function initStep4(){
maPost('step_one',{}, function(rdata){
console.log(rdata);
});
}
function initStep(){
console.log($('.infoNext'));
$('.infoNext').click(function(){
var step = $('.step_head .active span').text();
// console.log(step);
// initStep1();
switch(step){
case '1':initStep1();break;
case '2':initStep2();break;
case '3':initStep3();break;
case '4':initStep4();break;
}
});
}
+3
View File
@@ -2682,6 +2682,9 @@ def uninstallPreInspection(version):
if mw.isDebugMode():
return 'ok'
import plugins_api
plugins_api.plugins_api().removeIndex(getPluginName(), version)
return "请手动删除MySQL[{}]<br/> rm -rf {}".format(version, getServerDir())
if __name__ == "__main__":
+3
View File
@@ -2639,6 +2639,9 @@ def uninstallPreInspection(version):
if mw.isDebugMode():
return 'ok'
import plugins_api
plugins_api.plugins_api().removeIndex(getPluginName(), version)
return "请手动删除MySQL[{}]<br/> rm -rf {}".format(version, getServerDir())
if __name__ == "__main__":
+3
View File
@@ -2804,6 +2804,9 @@ def uninstallPreInspection(version):
if mw.isDebugMode():
return 'ok'
import plugins_api
plugins_api.plugins_api().removeIndex(getPluginName(), version)
return "请手动删除MySQL[{}]<br/> rm -rf {}".format(version, getServerDir())
if __name__ == "__main__":
+53 -53
View File
@@ -225,6 +225,7 @@ def initTotalInfo():
_name[name] = tmp
total_contents['sites'] = _name
total_contents['start_time'] = str(time.time())
cjson = mw.getJson(total_contents)
mw.writeFile(path_total, cjson)
@@ -324,8 +325,41 @@ def restartWeb():
mw.opWeb('start')
def initDreplace():
def makeDstLua():
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
path = getServerDir()
path_tpl = getPluginDir()
waf_common_tpl = path_tpl + "/waf/lua/waf_common.lua"
waf_common_dst = path + "/waf/lua/waf_common.lua"
content = mw.readFile(waf_common_tpl)
content = contentReplace(content)
mw.writeFile(waf_common_dst, content)
waf_init_tpl = path_tpl + "/waf/lua/init_preload.lua"
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
content = mw.readFile(waf_init_tpl)
content = contentReplace(content)
mw.writeFile(waf_init_dst, content)
init_worker_tpl = path_tpl + "/waf/lua/init_worker.lua"
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
content = mw.readFile(init_worker_tpl)
content = contentReplace(content)
mw.writeFile(init_worker_dst, content)
access_file_tpl = path_tpl + "/waf/lua/init.lua"
access_file_dst = root_access_dir + '/opwaf_init.lua'
content = mw.readFile(access_file_tpl)
content = contentReplace(content)
mw.writeFile(access_file_dst, content)
mw.opLuaMakeAll()
def initDreplace():
path = getServerDir()
if not os.path.exists(path + '/waf/lua'):
sdir = getPluginDir() + '/waf'
@@ -348,20 +382,7 @@ def initDreplace():
content['reqfile_path'] = wfDir
mw.writeFile(config, mw.getJson(content))
config = path + "/waf/lua/init.lua"
content = mw.readFile(config)
content = contentReplace(content)
mw.writeFile(config, content)
config_common = path + "/waf/lua/common.lua"
content = mw.readFile(config_common)
content = contentReplace(content)
mw.writeFile(config_common, content)
init_worker = path + "/waf/lua/init_worker.lua"
content = mw.readFile(init_worker)
content = contentReplace(content)
mw.writeFile(init_worker, content)
makeDstLua()
waf_conf = dstWafConf()
if not os.path.exists(waf_conf):
@@ -396,16 +417,6 @@ def status():
def start():
initDreplace()
path = mw.getServerDir() + '/web_conf/nginx/lua/lua.conf'
init_worker_lua = getServerDir() + '/waf/lua/init_worker.lua'
init_lua = getServerDir() + '/waf/lua/init.lua'
conf = mw.readFile(path)
conf = re.sub('init_worker_by_lua_file (.*);',
"init_worker_by_lua_file " + init_worker_lua + ";", conf)
conf = re.sub('access_by_lua_file (.*);',
"access_by_lua_file " + init_lua + ";", conf)
mw.writeFile(path, conf)
import tool_task
tool_task.createBgTask()
@@ -414,15 +425,21 @@ def start():
def stop():
root_init_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_by_lua_file'
root_worker_dir = mw.getServerDir() + '/web_conf/nginx/lua/init_worker_by_lua_file'
root_access_dir = mw.getServerDir() + '/web_conf/nginx/lua/access_by_lua_file'
path = mw.getServerDir() + '/web_conf/nginx/lua/lua.conf'
empty_lua = mw.getServerDir() + '/web_conf/nginx/lua/empty.lua'
conf = mw.readFile(path)
conf = re.sub('init_worker_by_lua_file (.*);',
"init_worker_by_lua_file " + empty_lua + ";", conf)
conf = re.sub('access_by_lua_file (.*);',
"access_by_lua_file " + empty_lua + ";", conf)
mw.writeFile(path, conf)
waf_init_dst = root_init_dir + "/waf_init_preload.lua"
if os.path.exists(waf_init_dst):
os.remove(waf_init_dst)
init_worker_dst = root_worker_dir + '/opwaf_init_worker.lua'
if os.path.exists(init_worker_dst):
os.remove(init_worker_dst)
access_file_dst = root_access_dir + '/opwaf_init.lua'
if os.path.exists(access_file_dst):
os.remove(access_file_dst)
wafconf = dstWafConf()
if os.path.exists(wafconf):
@@ -431,6 +448,8 @@ def stop():
import tool_task
tool_task.removeBgTask()
mw.opLuaMakeAll()
restartWeb()
return 'ok'
@@ -443,26 +462,7 @@ def restart():
def reload():
stop()
path = getServerDir()
path_tpl = getPluginDir()
config = path + "/waf/lua/common.lua"
config_tpl = path_tpl + "/waf/lua/common.lua"
content = mw.readFile(config_tpl)
content = contentReplace(content)
mw.writeFile(config, content)
config = path + "/waf/lua/init_worker.lua"
config_tpl = path_tpl + "/waf/lua/init_worker.lua"
content = mw.readFile(config_tpl)
content = contentReplace(content)
mw.writeFile(config, content)
config = path + "/waf/lua/init.lua"
config_tpl = path_tpl + "/waf/lua/init.lua"
content = mw.readFile(config_tpl)
content = contentReplace(content)
mw.writeFile(config, content)
makeDstLua()
errlog = mw.getServerDir() + "/openresty/nginx/logs/error.log"
mw.execShell('rm -rf ' + errlog)
+1 -1
View File
@@ -12,5 +12,5 @@
"home":"https://github.com/loveshell/ngx_lua_waf",
"date":"2019-04-21",
"pid": "1",
"versions": ["0.2.4"]
"versions": ["0.2.5"]
}
+7 -8
View File
@@ -24,7 +24,7 @@ else
fi
Install_of(){
Install_App(){
echo '正在安装脚本文件...' > $install_tmp
mkdir -p $serverPath/source/op_waf
@@ -41,7 +41,9 @@ Install_of(){
cd $serverPath/source/op_waf && tar xvf luarocks-3.5.0.tar.gz
# cd luarocks-3.9.1 && ./configure && make bootstrap
cd luarocks-3.5.0 && ./configure --prefix=$serverPath/op_waf/luarocks --with-lua-include=$serverPath/openresty/luajit/include/luajit-2.1 --with-lua-bin=$serverPath/openresty/luajit/bin
cd luarocks-3.5.0 && ./configure --prefix=$serverPath/op_waf/luarocks \
--with-lua-include=$serverPath/openresty/luajit/include/luajit-2.1 \
--with-lua-bin=$serverPath/openresty/luajit/bin
make -I${serverPath}/openresty/luajit/bin
make install
fi
@@ -85,13 +87,10 @@ Install_of(){
echo 'install ok' > $install_tmp
cd ${rootPath} && python3 ${rootPath}/plugins/op_waf/index.py start
# cd ${rootPath} && python3 ${rootPath}/plugins/op_waf/index.py restart
}
Uninstall_of(){
Uninstall_App(){
cd ${rootPath} && python3 ${rootPath}/plugins/op_waf/index.py stop
if [ "$?" == "0" ];then
@@ -102,7 +101,7 @@ Uninstall_of(){
action=$1
if [ "${1}" == 'install' ];then
Install_of
Install_App
else
Uninstall_of
Uninstall_App
fi
+5 -1
View File
@@ -961,8 +961,12 @@ function wafScreen(){
owPost('waf_srceen', {}, function(data){
var rdata = $.parseJSON(data.data);
var end_time = Date.now();
var cos_time = (end_time/1000) - parseInt(rdata['start_time']);
var cos_day = parseInt(parseInt(cos_time)/86400);
var con = '<div class="wavbox alert alert-success" style="margin-right:16px">总拦截<span>'+rdata.total+'</span>次</div>';
con += '<div class="wavbox alert alert-info" style="margin-right:16px">安全防护<span>0</span>天</div>';
con += '<div class="wavbox alert alert-info" style="margin-right:16px">安全防护<span>'+cos_day+'</span>天</div>';
con += '<div class="screen">\
<div class="line"><span class="name">POST渗透</span><span class="val">'+rdata.rules.post+'</span></div>\
+9
View File
@@ -0,0 +1,9 @@
#!/bin/bash
DST_DIR=/www/server/op_waf
DIS_FILE=${DST_DIR}/cpu.info
CPU_USAGE=`top -bn 1 | fgrep 'Cpu(s)' | awk '{print 100 -$8}' | awk -F . '{print $1}'`
echo $CPU_USAGE
echo $CPU_USAGE > $DIS_FILE
echo "done success!"
+50
View File
@@ -0,0 +1,50 @@
#!/bin/bash
DST_DIR=/www/server/op_waf
DIS_FILE=${DST_DIR}/cpu.info
function GetCpuUsage(){
cpu_info=`cat /proc/stat | head -n 1`
idle_cpu=`echo $cpu_info|awk '{print $2}'`
cpu_total_time=0
for ci in ${cpu_info[@]}; do
if [ "$ci" == "cpu" ];then
continue
else
#echo $ci
cpu_total_time=`expr $cpu_total_time + $ci`
fi
done
#echo "idle_cpu:${idle_cpu}"
#echo "cpu_total_time:${cpu_total_time}"
cpu_percet=$(awk "BEGIN{print ((${cpu_total_time}-${idle_cpu})/${cpu_total_time})*100}")
echo "${cpu_percet}"
return 0
}
# one value detal
getOne=`GetCpuUsage`
CPU_USAGE=`echo $getOne | awk -F . '{print $1}'`
echo "cpu usage:${CPU_USAGE}"
echo $CPU_USAGE > $DIS_FILE
echo "done success!"
# two value compare
# getOne=`GetCpuUsage`
# echo "getOne:$getOne"
# sleep 1
# getTwo=`GetCpuUsage`
# echo "getTwo:$getTwo"
# cpu_percet_calc=$(awk "BEGIN{print (${getOne}+${getTwo})/2}")
# echo "cpu_percet_calc:${cpu_percet_calc}"
# #echo '0.61212' | awk -F . '{print $1}'
# CPU_USAGE=`echo $cpu_percet_calc | awk -F . '{print $1}'`
# echo "cpu usage:${CPU_USAGE}"
# echo $CPU_USAGE > $DIS_FILE
# echo "done success!"
+2 -1
View File
@@ -26,4 +26,5 @@ fi
# $RUN_CMD --stap --shdict 'limit 10m' test_find_server_name.lua
# $RUN_CMD test_rand.lua
$RUN_CMD test_ffi_time.lua
# $RUN_CMD test_ffi_time.lua
$RUN_CMD test_get_cpu.lua
+69
View File
@@ -0,0 +1,69 @@
-- cd /www/server/mdserver-web/plugins/op_waf/t/bench && bash bench.sh
local function target()
ngx.re.find("hello, world.", [[\w+\.]], "jo")
end
for i = 1, 100 do
target()
end
local function file_exists(path)
local file = io.open(path, "rb")
if file then file:close() end
return file ~= nil
end
-- 以上为预热操作
collectgarbage()
local json = require "cjson"
local ngx_re = require "ngx.re"
local function data_split(self, str,reps )
local rsList = {}
string.gsub(str,'[^'..reps..']+',function(w)
table.insert(rsList,w)
end)
return rsList
end
local function get_cpu_stat()
local cpu_total = 0
local fp = io.open('/proc/stat','r')
local cpu_line = fp:read()
fp:close()
local list = ngx_re.split(cpu_line," ")
table.remove(list,1)
table.remove(list,1)
local idie = list[4]
for i,v in pairs(list)
do
cpu_total = cpu_total + v
end
local use_percent = tonumber(100-(idie/cpu_total)*100)
return cpu_total,idie,use_percent
end
local function get_cpu_percent()
local cpu_total,idie,use_percent = get_cpu_stat()
ngx.sleep(2)
local cpu_total2,idie2,use_percent2 = get_cpu_stat()
local cpu_usage_percent = tonumber(100-(((idie2-idie)/(cpu_total2-cpu_total))*100))
ngx.say("cpu_usage_percent:"..cpu_usage_percent)
return cpu_usage_percent
end
ngx.update_time()
local begin = ngx.now()
local N = 1e1
for i = 1, N do
get_cpu_stat()
end
ngx.update_time()
ngx.say("test_get_cpu elapsed: ", (ngx.now() - begin))
+86 -20
View File
@@ -1,6 +1,46 @@
#!/bin/sh
export PATH=$PATH:/opt/stap/bin:/opt/stapxx
# cd /www/server/mdserver-web/plugins/op_waf/t && bash ngx_debug.sh lua ok
# cd /www/server/mdserver-web/plugins/op_waf/t && bash ngx_debug.sh c ok
if [ ${_os} == "Darwin" ]; then
OSNAME='macos'
elif grep -Eq "openSUSE" /etc/*-release; then
OSNAME='opensuse'
zypper refresh
zypper install cron wget curl zip unzip
elif grep -Eq "FreeBSD" /etc/*-release; then
OSNAME='freebsd'
elif grep -Eqi "CentOS" /etc/issue || grep -Eq "CentOS" /etc/*-release; then
OSNAME='rhel'
yum install -y wget curl zip unzip tar crontabs
elif grep -Eqi "Fedora" /etc/issue || grep -Eq "Fedora" /etc/*-release; then
OSNAME='fedora'
yum install -y wget curl zip unzip tar crontabs
elif grep -Eqi "Rocky" /etc/issue || grep -Eq "Rocky" /etc/*-release; then
OSNAME='rhel'
yum install -y wget curl zip unzip tar crontabs
elif grep -Eqi "AlmaLinux" /etc/issue || grep -Eq "AlmaLinux" /etc/*-release; then
OSNAME='rhel'
yum install -y wget curl zip unzip tar crontabs
elif grep -Eqi "Amazon Linux" /etc/issue || grep -Eq "Amazon Linux" /etc/*-release; then
OSNAME='amazon'
yum install -y wget curl zip unzip tar crontabs
elif grep -Eqi "Debian" /etc/issue || grep -Eq "Debian" /etc/os-release; then
OSNAME='debian'
apt update -y
apt install -y wget curl zip unzip tar cron
elif grep -Eqi "Ubuntu" /etc/issue || grep -Eq "Ubuntu" /etc/os-release; then
OSNAME='ubuntu'
apt update -y
apt install -y wget curl zip unzip tar cron
else
OSNAME='unknow'
fi
# https://moonbingbing.gitbooks.io/openresty-best-practices/content/flame_graph/install.html
# apt install elfutils
# sudo apt-get install -y systemtap gcc
@@ -23,7 +63,7 @@ then
exit
fi
pid=`ps -ef|grep openresty | grep -v grep | awk '{print $2}'`
pids=`ps -ef|grep nginx | grep -v grep | awk '{print $2}'`
name=$2
@@ -33,7 +73,13 @@ name=$2
# apt install -y kernel-debuginfo-common kernel-debuginfo
# apt install -y kernel-*
if [ "$OSNAME" == "debian" ];then
apt install -y systemtap
apt-get install -y build-essential
apt-get install -y linux-headers-$(uname -r)
elif [ "$OSNAME" == "centos" ];then
yum install -y kernel-devel-$(uname -r)
fi
# /opt/stapxx/samples/lj-lua-stacks.sxx --arg time=5 --skip-badvars -x 45266 > tmp.bt
@@ -58,25 +104,45 @@ if [ ! -d /opt/FlameGraph ];then
cd /opt && git clone https://github.com/brendangregg/FlameGraph
fi
if [ $1 == "lua" ]; then
# /opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p 377452 --luajit20 -t 30 >temp.bt
/opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p $pid --luajit20 -t 30 >temp.bt
# /opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >t1.bt
/opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >${name}.bt
elif [ $1 == "c" ]; then
# /opt/openresty-systemtap-toolkit/sample-bt -p 496435 -t 10 -u > t2.bt
/opt/openresty-systemtap-toolkit/sample-bt -p $pid -t 10 -u > ${name}.bt
else
echo "type is only lua/c"
exit
fi
for pid in ${pids[@]}; do
echo "strace:$pid"
if [ $1 == "lua" ]; then
# --without-luajit-gc64 | lua 模式编译时需要使用此参数
/opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p $pid --luajit20 -t 30 >temp.bt
/opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >${name}_${pid}.bt
elif [ $1 == "c" ]; then
/opt/openresty-systemtap-toolkit/sample-bt -p $pid -t 10 -u > ${name}_${pid}.bt
else
echo "type is only lua/c"
exit
fi
/opt/FlameGraph/stackcollapse-stap.pl ${name}_${pid}.bt >${name}_${pid}.cbt
/opt/FlameGraph/flamegraph.pl ${name}_${pid}.cbt >${name}_${pid}.svg
rm -f temp.bt ${name}_${pid}.bt ${name}_${pid}.cbt
echo "strace:$pid, end!"
echo "${name}_${pid}.svg -- make ok"
done
# if [ $1 == "lua" ]; then
# # /opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p 377452 --luajit20 -t 30 >temp.bt
# /opt/openresty-systemtap-toolkit/ngx-sample-lua-bt -p $pid --luajit20 -t 30 >temp.bt
# # /opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >t1.bt
# /opt/openresty-systemtap-toolkit/fix-lua-bt temp.bt >${name}.bt
# elif [ $1 == "c" ]; then
# # /opt/openresty-systemtap-toolkit/sample-bt -p 496435 -t 10 -u > t2.bt
# /opt/openresty-systemtap-toolkit/sample-bt -p $pid -t 10 -u > ${name}.bt
# else
# echo "type is only lua/c"
# exit
# fi
# # debuginfo-install kernel-3.10.0-1160.80.1.el7.x86_64
# # /opt/FlameGraph/stackcollapse-perf.pl perf.unfold &> perf.folded
# # /opt/FlameGraph/flamegraph.pl perf.folded > perf.svg
# /opt/FlameGraph/stackcollapse-perf.pl perf.unfold &> perf.folded
# /opt/FlameGraph/flamegraph.pl perf.folded > perf.svg
/opt/FlameGraph/stackcollapse-stap.pl ${name}.bt >${name}.cbt
/opt/FlameGraph/flamegraph.pl ${name}.cbt >${name}.svg
rm -f temp.bt ${name}.bt ${name}.cbt
# /opt/FlameGraph/stackcollapse-stap.pl ${name}.bt >${name}.cbt
# /opt/FlameGraph/flamegraph.pl ${name}.cbt >${name}.svg
# rm -f temp.bt ${name}.bt ${name}.cbt
+22 -6
View File
@@ -54,7 +54,9 @@ def createBgTask():
"period": "minute-n",
"minute-n": "1",
}
createBgTaskByName(getPluginName(), args)
if mw.isAppleSystem():
createBgTaskByName(getPluginName(), args)
def createBgTaskByName(name, args):
@@ -97,8 +99,14 @@ logs_file=$plugin_path/${rname}.log
''' % (mw_dir, name, getServerDir(), getPluginDir())
cmd += 'echo "★【`date +"%Y-%m-%d %H:%M:%S"`】 STSRT★" >> $logs_file' + "\n"
cmd += 'echo ">>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>" >> $logs_file' + "\n"
cmd += 'echo "cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1"' + "\n"
cmd += 'cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1' + "\n"
if mw.isAppleSystem():
cmd += 'echo "cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1"' + "\n"
cmd += 'cd $mw_dir && source bin/activate && python3 $script_path/tool_task.py run >> $logs_file 2>&1' + "\n"
else:
cmd += 'echo "cd $mw_dir && source bin/activate && bash $script_path/shell/cpu_usage_file.sh >> $logs_file 2>&1"' + "\n"
cmd += 'cd $mw_dir && source bin/activate && bash $script_path/shell/cpu_usage.sh >> $logs_file 2>&1' + "\n"
cmd += 'echo "【`date +"%Y-%m-%d %H:%M:%S"`】 END★" >> $logs_file' + "\n"
cmd += 'echo "<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<" >> $logs_file' + "\n"
@@ -128,6 +136,9 @@ logs_file=$plugin_path/${rname}.log
def removeBgTask():
if not mw.isAppleSystem():
return False
cfg_list = getConfigData()
for x in range(len(cfg_list)):
cfg = cfg_list[x]
@@ -147,10 +158,15 @@ def removeBgTask():
def getCpuUsed():
import psutil
used = psutil.cpu_percent(interval=1)
path = getServerDir() + "/cpu.info"
mw.writeFile(path, str(int(used)))
if mw.isAppleSystem():
import psutil
used = psutil.cpu_percent(interval=1)
mw.writeFile(path, str(int(used)))
else:
cmd = "top -bn 1 | fgrep 'Cpu(s)' | awk '{print 100 -$8}' | awk -F . '{print $1}'"
data = mw.execShell(cmd)
mw.writeFile(path, str(int(data[0].strip())))
def run():
+20 -13
View File
@@ -1,19 +1,8 @@
local waf_root = "{$WAF_ROOT}"
local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
local waf_sopath = waf_root.."/waf/conf/?.so;"
if not package.path:find(waf_cpath) then
package.path = waf_cpath .. package.path
end
if not package.cpath:find(waf_sopath) then
package.cpath = waf_sopath .. package.cpath
end
local json = require "cjson"
local ngx_match = ngx.re.find
local __WAF = require "common"
local __WAF = require "waf_common"
-- print(json.encode(__C))
local C = __WAF:getInstance()
@@ -47,7 +36,8 @@ local url_rules = require "rule_url"
local url_white_rules = require "rule_url_white"
local server_name = string.gsub(C:get_sn(config_domains),'_','.')
-- local server_name = string.gsub(C:get_sn(config_domains),'_','.')
local server_name = C:get_sn(config_domains)
local function initParams()
local data = {}
@@ -533,41 +523,58 @@ end
function waf()
min_route()
-- C:D("min_route")
-- white ip
if waf_ip_white() then return true end
-- C:D("waf_ip_white")
-- url white
if waf_url_white() then return true end
-- C:D("waf_url_white")
-- black ip
if waf_ip_black() then return true end
-- C:D("waf_ip_black")
-- 封禁ip返回
if waf_drop_ip() then return true end
-- C:D("waf_drop_ip")
-- ua check
if waf_user_agent() then return true end
-- C:D("waf_user_agent")
if waf_url() then return true end
-- C:D("waf_url")
-- cc setting
if waf_cc_increase() then return true end
-- C:D("waf_cc_increase")
if waf_cc() then return true end
-- C:D("waf_cc")
-- cookie检查
if waf_cookie() then return true end
-- C:D("waf_cookie")
-- args参数拦截
if waf_get_args() then return true end
-- C:D("waf_get_args")
-- 扫描软件禁止
if waf_scan_black() then return true end
-- C:D("waf_scan_black")
if waf_post() then return true end
-- C:D("waf_post")
if site_config[server_name] and site_config[server_name]['open'] then
if X_Forwarded() then return true end
-- C:D("X_Forwarded")
if post_X_Forwarded() then return true end
-- C:D("post_X_Forwarded")
if url_ext() then return true end
-- C:D("url_ext")
if post_data() then return true end
-- C:D("post_data")
end
end
+11
View File
@@ -0,0 +1,11 @@
local waf_root = "{$WAF_ROOT}"
local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
local waf_sopath = waf_root.."/waf/conf/?.so;"
if not package.path:find(waf_cpath) then
package.path = waf_cpath .. package.path
end
if not package.cpath:find(waf_sopath) then
package.cpath = waf_sopath .. package.cpath
end
+40 -20
View File
@@ -1,38 +1,58 @@
local waf_root = "{$WAF_ROOT}"
local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
local waf_sopath = waf_root.."/waf/conf/?.so;"
if not package.path:find(waf_cpath) then
package.path = waf_cpath .. package.path
end
-- local waf_cpath = waf_root.."/waf/lua/?.lua;"..waf_root.."/waf/conf/?.lua;"..waf_root.."/waf/html/?.lua;"
-- local waf_sopath = waf_root.."/waf/conf/?.so;"
-- if not package.path:find(waf_cpath) then
-- package.path = waf_cpath .. package.path
-- end
if not package.cpath:find(waf_sopath) then
package.cpath = waf_sopath .. package.cpath
end
-- if not package.cpath:find(waf_sopath) then
-- package.cpath = waf_sopath .. package.cpath
-- end
local json = require "cjson"
local __C = require "common"
local C = __C:getInstance()
local __WAF_C = require "waf_common"
local WAF_C = __WAF_C:getInstance()
local function timer_stats_total_log(premature)
C:timer_stats_total()
local waf_config = require "waf_config"
local waf_site_config = require "waf_site"
WAF_C:setConfData(waf_config, waf_site_config)
WAF_C:setDebug(true)
-- C:D("init worker"..tostring(ngx.worker.id()))
local function waf_timer_stats_total_log(premature)
WAF_C:timer_stats_total()
end
local waf_clean_expire_data = function(premature)
WAF_C:clean_log()
end
ngx.shared.waf_limit:set("cpu_usage", 0, 10)
function timer_every_get_cpu(premature)
local cpu_percent = C:read_file_body(waf_root.."/cpu.info")
if cpu_percent then
ngx.shared.waf_limit:set("cpu_usage", tonumber(cpu_percent), 10)
function waf_timer_every_get_cpu(premature)
if WAF_C:file_exists('/proc/stat') then
local lua_cpu_percent = WAF_C:get_cpu_percent()
-- WAF_C:D("lua_cpu_percent:"..tostring(lua_cpu_percent))
ngx.shared.waf_limit:set("cpu_usage", math.floor(lua_cpu_percent), 10)
else
ngx.shared.waf_limit:set("cpu_usage", 0, 10)
local cpu_percent = WAF_C:read_file_body(waf_root.."/cpu.info")
-- WAF_C:D("cpu_usage:"..tostring(cpu_percent ))
if cpu_percent then
ngx.shared.waf_limit:set("cpu_usage", tonumber(cpu_percent), 10)
else
ngx.shared.waf_limit:set("cpu_usage", 0, 10)
end
end
end
if 0 == ngx.worker.id() then
ngx.timer.every(5, timer_every_get_cpu)
if ngx.worker.id() == 0 then
ngx.timer.every(6, waf_timer_every_get_cpu)
-- 异步执行
ngx.timer.every(3, timer_stats_total_log)
ngx.timer.every(3, waf_timer_stats_total_log)
ngx.timer.every(10, waf_clean_expire_data)
WAF_C:cron()
end
@@ -17,7 +17,9 @@ local mt = { __index = _M }
local json = require "cjson"
local sqlite3 = require "lsqlite3"
local ngx_re = require "ngx.re"
local ngx_match = ngx.re.find
local debug_mode = false
local cpath = waf_root.."/waf/"
@@ -41,42 +43,25 @@ function _M.new(self)
end
function _M.getInstance(self)
if rawget(self, "instance") == nil then
rawset(self, "instance", self:new())
-- function _M.getInstance(self)
-- if rawget(self, "instance") == nil then
-- rawset(self, "instance", self.new())
-- end
-- assert(self.instance ~= nil)
-- return self.instance
-- end
if 0 == ngx.worker.id() then
self:cron()
end
function _M.getInstance(self)
if self.instance == nil then
self.instance = self:new()
end
assert(self.instance ~= nil)
return self.instance
end
function _M.initDB(self)
local path = log_dir .. "/waf.db"
db, err = sqlite3.open(path)
if err then
self:D("initDB err:"..tostring(err))
return nil
end
db:exec([[PRAGMA synchronous = 0]])
db:exec([[PRAGMA cache_size = 8000]])
db:exec([[PRAGMA page_size = 32768]])
db:exec([[PRAGMA journal_mode = wal]])
db:exec([[PRAGMA journal_size_limit = 1073741824]])
return db
end
-- 后台任务
function _M.cron(self)
local timer_every_get_data = function(premature)
self:clean_log()
end
ngx.timer.every(10, timer_every_get_data)
local timer_every_import_data = function(premature)
local llen, _ = ngx.shared.waf_limit:llen('waf_limit_logs')
@@ -91,7 +76,6 @@ function _M.cron(self)
local stmt2 = db:prepare[[INSERT INTO logs(time, ip, domain, server_name, method, status_code, uri, user_agent, rule_name, reason)
VALUES(:time, :ip, :domain, :server_name, :method, :status_code, :uri, :user_agent, :rule_name, :reason)]]
if not stmt2 then
self:D("waf timer db:prepare fail!:"..tostring(stmt2))
return false
@@ -136,6 +120,22 @@ function _M.cron(self)
ngx.timer.every(0.5, timer_every_import_data)
end
function _M.initDB(self)
local path = log_dir .. "/waf.db"
db, err = sqlite3.open(path)
if err then
self:D("initDB err:"..tostring(err))
return nil
end
db:exec([[PRAGMA synchronous = 0]])
db:exec([[PRAGMA cache_size = 8000]])
db:exec([[PRAGMA page_size = 32768]])
db:exec([[PRAGMA journal_mode = wal]])
db:exec([[PRAGMA journal_size_limit = 1073741824]])
return db
end
function _M.clean_log(self)
local db = self:initDB()
@@ -392,6 +392,12 @@ function _M.read_file(self, name)
return data
end
function _M.file_exists(self,path)
local file = io.open(path, "rb")
if file then file:close() end
return file ~= nil
end
function _M.select_rule(self, rules)
if not rules then return {} end
@@ -761,6 +767,34 @@ function _M.is_key(self, arr, key)
return false
end
function _M.get_cpu_stat(self)
local cpu_total = 0
local fp = io.open('/proc/stat','r')
local cpu_line = fp:read()
fp:close()
local list = ngx_re.split(cpu_line," ")
table.remove(list,1)
table.remove(list,1)
local idie = list[4]
for i,v in pairs(list)
do
cpu_total = cpu_total + v
end
local use_percent = tonumber(100-(idie/cpu_total)*100)
return cpu_total,idie,use_percent
end
function _M.get_cpu_percent(self)
local cpu_total,idie,use_percent = self:get_cpu_stat()
ngx.sleep(2)
local cpu_total2,idie2,use_percent2 = self:get_cpu_stat()
local cpu_usage_percent = tonumber(100-(((idie2-idie)/(cpu_total2-cpu_total))*100))
return cpu_usage_percent
end
function _M.return_post_data(self)
if method ~= "POST" then return false end
+1 -1
View File
@@ -1 +1 @@
[[[127, 0, 0, 1], [127, 0, 0, 255]]]
[[[127,0,0,1], [127, 0, 0, 255]]]
+5 -2
View File
@@ -3,8 +3,11 @@ lua_package_cpath "{$SERVER_PATH}/web_conf/nginx/lua/?.so;{$SERVER_PATH}/openres
lua_code_cache on;
#waf
#init_by_lua_file
init_by_lua_file {$SERVER_PATH}/web_conf/nginx/lua/empty.lua;
#init_worker_by_lua
init_worker_by_lua_file {$SERVER_PATH}/web_conf/nginx/lua/empty.lua;
#waf && webstats need;
#access_by_lua_file
access_by_lua_file {$SERVER_PATH}/web_conf/nginx/lua/empty.lua;
+8 -7
View File
@@ -149,16 +149,17 @@ def confReplace():
mw.execShell('mkdir -p ' + lua_conf_dir)
lua_conf = lua_conf_dir + '/lua.conf'
if not os.path.exists(lua_conf):
lua_conf_tpl = getPluginDir() + '/conf/lua.conf'
lua_content = mw.readFile(lua_conf_tpl)
lua_content = lua_content.replace('{$SERVER_PATH}', service_path)
mw.writeFile(lua_conf, lua_content)
lua_conf_tpl = getPluginDir() + '/conf/lua.conf'
lua_content = mw.readFile(lua_conf_tpl)
lua_content = lua_content.replace('{$SERVER_PATH}', service_path)
mw.writeFile(lua_conf, lua_content)
empty_lua = lua_conf_dir + '/empty.lua'
if not os.path.exists(empty_lua):
mw.writeFile(empty_lua, '')
mw.opLuaMakeAll()
# 静态配置
php_conf = mw.getServerDir() + '/web_conf/php/conf'
if not os.path.exists(php_conf):
@@ -203,8 +204,8 @@ def initDreplace():
mw.writeFile(file_bin, content)
mw.execShell('chmod +x ' + file_bin)
# config replace
confReplace()
# config replace
confReplace()
# systemd
# /usr/lib/systemd/system
+2
View File
@@ -2,6 +2,8 @@
PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
# cd /www/server/mdserver-web/plugins/openresty && bash install.sh install 1.21.4.1
curPath=`pwd`
rootPath=$(dirname "$curPath")
rootPath=$(dirname "$rootPath")
+1
View File
@@ -83,6 +83,7 @@ if [ "${action}" == "install" ] && [ -d ${serverPath}/php-apt/${type} ];then
# 安装通用扩展
echo "install PHP-APT[${type}] extend start"
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install curl
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install gd
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install iconv
cd ${rootPath}/plugins/php-apt/versions && bash common.sh ${type:0:1}.${type:1:2} install exif
+13
View File
@@ -233,6 +233,19 @@
"shell": "xml.sh",
"check": "xml"
},
{
"name": "curl",
"versions": [
"74",
"80",
"81",
"82"
],
"type": "通用扩展",
"msg": "通用CURL库!",
"shell": "curl.sh",
"check": "curl"
},
{
"name": "gd",
"versions": [
+1 -1
View File
@@ -16,7 +16,7 @@ function version_lt() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)"
function version_ge() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)" == "$1"; }
version=8.0.25
version=8.0.27
PHP_VER=80
Install_php()
{
+1 -1
View File
@@ -16,7 +16,7 @@ function version_lt() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)"
function version_ge() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)" == "$1"; }
version=8.1.12
version=8.1.15
PHP_VER=81
Install_php()
{
+1 -1
View File
@@ -16,7 +16,7 @@ function version_lt() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)"
function version_ge() { test "$(echo "$@" | tr " " "\n" | sort -rV | head -n 1)" == "$1"; }
version=8.2.0
version=8.2.2
PHP_VER=82
Install_php()
{
+5 -2
View File
@@ -54,13 +54,16 @@ def getArgs():
if args_len == 1:
t = args[0].strip('{').strip('}')
t = t.split(':')
if t.strip() == '':
tmp = []
else:
t = t.split(':')
tmp[t[0]] = t[1]
tmp[t[0]] = t[1]
elif args_len > 1:
for i in range(len(args)):
t = args[i].split(':')
tmp[t[0]] = t[1]
return tmp
+5 -2
View File
@@ -34,13 +34,16 @@ def getArgs():
if args_len == 1:
t = args[0].strip('{').strip('}')
t = t.split(':')
if t.strip() == '':
tmp = []
else:
t = t.split(':')
tmp[t[0]] = t[1]
tmp[t[0]] = t[1]
elif args_len > 1:
for i in range(len(args)):
t = args[i].split(':')
tmp[t[0]] = t[1]
return tmp
+7 -4
View File
@@ -43,13 +43,16 @@ class App():
if args_len == 1:
t = args[0].strip('{').strip('}')
t = t.split(':')
if t.strip() == '':
tmp = []
else:
t = t.split(':')
tmp[t[0]] = t[1]
tmp[t[0]] = t[1]
elif args_len > 1:
for i in range(len(args)):
t = args[i].split(':')
tmp[t[0]] = t[1]
return tmp
def checkArgs(self, data, ck=[]):
@@ -110,7 +113,7 @@ class App():
def getSshInfo(self, file):
rdata = mw.readFile(file)
destr = mw.deCrypt('mdserver-web', rdata)
destr = mw.enDoubleCrypt('mdserver-web', rdata)
return json.loads(destr)
def get_server_by_host(self):
@@ -199,7 +202,7 @@ class App():
if not os.path.exists(dst_host_dir):
os.makedirs(dst_host_dir)
enstr = mw.enCrypt('mdserver-web', json.dumps(info))
enstr = mw.enDoubleCrypt('mdserver-web', json.dumps(info))
mw.writeFile(dst_host_dir + '/info.json', enstr)
return mw.returnJson(True, '添加成功!')
+1 -1
View File
@@ -4,7 +4,7 @@
"name": "webstats",
"title": "网站统计",
"shell": "install.sh",
"versions":["0.2.3"],
"versions":["0.2.4"],
"tip": "soft",
"install_pre_inspection":true,
"checks": "server/webstats",
+2 -1
View File
@@ -39,6 +39,7 @@ Install_App()
echo '正在安装脚本文件...' > $install_tmp
mkdir -p $serverPath/source/webstats
mkdir -p $serverPath/webstats
echo "${VERSION}" > $serverPath/webstats/version.pl
# 下载源码安装包
# curl -O $serverPath/source/webstats/lua-5.1.5.tar.gz https://www.lua.org/ftp/lua-5.1.5.tar.gz
@@ -110,7 +111,7 @@ Install_App()
cp -rf $serverPath/source/webstats/GeoLite2-City.mmdb $serverPath/webstats/GeoLite2-City.mmdb
fi
echo "${VERSION}" > $serverPath/webstats/version.pl
echo '安装完成' > $install_tmp
cd $rootPath && python3 ${rootPath}/plugins/webstats/index.py start
+52 -26
View File
@@ -36,20 +36,26 @@ function _M.new(self)
params = nil,
site_config = nil,
config = nil,
}
-- self.dbs = {}
return setmetatable(self, mt)
end
function _M.getInstance(self)
if rawget(self, "instance") == nil then
rawset(self, "instance", self.new())
-- function _M.getInstance(self)
-- if rawget(self, "instance") == nil then
-- rawset(self, "instance", self.new())
-- self.cron()
-- end
-- assert(self.instance ~= nil)
-- return self.instance
-- end
-- if 0 == ngx.worker.id() then
function _M.getInstance(self)
if self.instance == nil then
self.instance = self:new()
self:cron()
-- end
end
assert(self.instance ~= nil)
return self.instance
@@ -229,16 +235,46 @@ function _M.get_http_origin(self)
return json.encode(headers)
end
function _M.cronPre(self)
local time_key = self:get_store_key()
local time_key_next = self:get_store_key_with_time(ngx.time()+3600)
for site_k, site_v in ipairs(sites) do
local input_sn = site_v["name"]
local db = self:initDB(input_sn)
local wc_stat = {
'request_stat',
'client_stat',
'spider_stat'
}
for _,ws_v in pairs(wc_stat) do
self:_update_stat_pre(db, ws_v, time_key)
self:_update_stat_pre(db, ws_v, time_key_next)
end
if db and db:isopen() then
db:execute([[COMMIT]])
db:close()
end
end
end
-- 后台任务
function _M.cron(self)
local timer_every_get_data = function (premature)
local timer_every_get_data = function (premature)
local llen, _ = ngx.shared.mw_total:llen(total_key)
-- self:D("llen:"..tostring(llen))
-- self:D("PID:"..tostring(ngx.worker.id())..",llen:"..tostring(llen))
if llen == 0 then
return true
end
self:cronPre()
ngx.update_time()
local begin = ngx.now()
@@ -249,10 +285,10 @@ function _M.cron(self)
local url_stats = {}
local time_key = self:get_store_key()
local time_key_next = self:get_store_key_with_time(ngx.time()+3600)
for site_k, site_v in ipairs(sites) do
local input_sn = site_v["name"]
-- self:D("input_sn:"..input_sn)
-- 迁移合并时不执行
if self:is_migrating(input_sn) then
return true
@@ -276,18 +312,6 @@ function _M.cron(self)
tmp_stmt["web_logs"] = stmt
stmts[input_sn] = tmp_stmt
local wc_stat = {
'request_stat',
'client_stat',
'spider_stat'
}
for _,ws_v in pairs(wc_stat) do
self:_update_stat_pre(db, ws_v, time_key)
self:_update_stat_pre(db, ws_v, time_key_next)
end
db:exec([[BEGIN TRANSACTION]])
end
end
@@ -307,7 +331,10 @@ function _M.cron(self)
end
local info = json.decode(data)
-- self:D("info:"..json.encode(info))
local input_sn = info['server_name']
-- self:D("insert data input_sn:"..input_sn)
local db = dbs[input_sn]
local stat_fields_is = stat_fields[input_sn]
if not db then
@@ -458,10 +485,9 @@ function _M.cron(self)
self:unlock_working(cron_key)
ngx.update_time()
-- self:D("--【"..tostring(llen).."】, elapsed: " .. tostring(ngx.now() - begin))
-- self:D("PID:"..tostring(ngx.worker.id()).."--【"..tostring(llen).."】, elapsed: " .. tostring(ngx.now() - begin))
end
ngx.timer.every(1, timer_every_get_data)
ngx.timer.every(0.5, timer_every_get_data)
end
@@ -488,7 +514,7 @@ function _M.store_logs_line(self, db, stmt, input_sn, info)
local request_headers = logline["request_headers"]
local excluded = logline["excluded"]
-- self:D("json:"..json.encode(logline))
local time_key = logline["time_key"]
if not excluded then
+6 -6
View File
@@ -8,7 +8,7 @@ log_by_lua_block {
package.path = cpath .. "?.lua;" .. package.path
end
local ver = '0.2.3'
local ver = '0.2.4'
local debug_mode = true
local __C = require "webstats_common"
@@ -44,7 +44,7 @@ log_by_lua_block {
local sites = require "webstats_sites"
-- string.gsub(C:get_sn(ngx.var.server_name),'_','.')
local server_name = ngx.var.server_name
local server_name = C:get_sn(ngx.var.server_name)
C:setConfData(config, sites)
@@ -210,7 +210,7 @@ log_by_lua_block {
-- local request_time = ngx.var.request_time
local request_time = C:get_request_time()
local client_port = ngx.var.remote_port
local real_server_name = server_name
local real_server_name = ngx.var.server_name
local uri = ngx.var.uri
local status_code = ngx.status
local protocol = ngx.var.server_protocol
@@ -439,7 +439,7 @@ log_by_lua_block {
}
local push_data = json.encode(data)
-- C:D(json.encode(push_data))
local key = C:getTotalKey()
ngx.shared.mw_total:rpush(key, push_data)
end
@@ -630,7 +630,7 @@ log_by_lua_block {
end
local function run_app()
-- D("------------ debug start ------------")
-- C:D("------------ debug start ------------")
init_var()
load_global_exclude_ip()
@@ -641,7 +641,7 @@ log_by_lua_block {
-- cache_logs_old(server_name)
-- store_logs(server_name)
-- D("------------ debug end -------------")
-- C:D("------------ debug end -------------")
end
+4 -1
View File
@@ -386,7 +386,10 @@ def get_admin_safe():
def admin_safe_path(path, req, data, pageFile):
if path != req and not isLogined():
return render_template('path.html')
if data['status_code'] == '0':
return render_template('path.html')
else:
return Response(status=int(data['status_code']))
if not isLogined():
return render_template('login.html', data=data)
+55
View File
@@ -550,6 +550,61 @@ function setTempAccessReq(page){
},'json');
}
function setStatusCode(o){
var code = $(o).data('code');
layer.open({
type: 1,
area: ['420px', '220px'],
title: "设置未认证时的响应状态",
closeBtn: 1,
shift: 5,
btn:['提交','关闭'],
shadeClose: false,
content: '<div class="bt-form bt-form pd20">\
<div class="line">\
<span class="tname">相应状态</span>\
<div class="info-r">\
<select class="bt-input-text mr5" name="status_code" style="width: 250px;"></select>\
</div>\
</div>\
<ul class="help-info-text c7"><li style="color: red;">用于未登录且未正确输入安全入口时的响应,用于隐藏面板特征</li></ul>\
</div>',
success:function(){
var msg_list = [
{'code':'0','msg':'默认-安全入口错误提示'},
{'code':'403','msg':'403-拒绝访问'},
{'code':'404','msg':'404-页面不存在'},
{'code':'416','msg':'416-无效的请求'},
{'code':'408','msg':'408-客户端超时'},
{'code':'400','msg':'400-客户端请求错误'},
{'code':'401','msg':'401-未授权访问'},
];
var tbody = '';
for(i in msg_list){
if (msg_list[i]['code'] == code){
tbody += '<option value="'+msg_list[i]['code']+'" selected>'+msg_list[i]['msg']+'</option>';
} else{
tbody += '<option value="'+msg_list[i]['code']+'">'+msg_list[i]['msg']+'</option>';
}
}
$('select[name="status_code"]').append(tbody);
},
yes:function(index){
var loadT = layer.msg("正在设置未认证时的响应状态", { icon: 16, time: 0, shade: [0.3, '#000'] });
var status_code = $('select[name="status_code"]').val();
$.post('/config/set_status_code', { status_code: status_code }, function (rdata) {
showMsg(rdata.msg, function(){
layer.close(index);
layer.close(loadT);
location.reload();
},{ icon: rdata.status ? 1 : 2 }, 2000);
},'json');
}
});
}
function setTempAccess(){
layer.open({
area: ['700px', '250px'],
+8 -1
View File
@@ -257,7 +257,7 @@ function planAdd(){
$("#set-Config input[name='sType']").val(sType);
$("#set-Config textarea[name='sBody']").val(decodeURIComponent(sBody));
if(sType == 'site' || sType == 'database'){
if(sType == 'site' || sType == 'database' || sType == 'path'){
var backupTo = $(".planBackupTo").find("b").attr("val");
$("#backupTo").val(backupTo);
}
@@ -293,10 +293,17 @@ function planAdd(){
var where1 = $("#ptime input[name='where1']").val();
$("#set-Config input[name='where1']").val(where1);
}
if (type == 'month'){
var where1 = $("#ptime input[name='where1']").val();
$("#set-Config input[name='where1']").val(where1);
}
$("#set-Config input[name='sName']").val(sName);
layer.msg('正在添加,请稍候...!',{icon:16,time:0,shade: [0.3, '#000']});
var data = $("#set-Config").serialize() + '&sBody='+sBody + '&urladdress=' + urladdress;
// console.log(data);
$.post('/crontab/add',data,function(rdata){
if(!rdata.status) {
layer.msg(rdata.msg,{icon:2, time:2000});
+27 -21
View File
@@ -2188,39 +2188,45 @@ function pluginRollingLogs(_name, version, func, _args, line){
var reqTimer = null;
function requestLogs(fileName){
$.post('/files/get_last_body', 'path=' + fileName+'&line='+file_line, function(rdata) {
if (!rdata.status){
return;
}
if(rdata.data == '') {
rdata.data = '当前没有日志!';
}
var ebody = '<textarea readonly="readonly" style="margin: 0px;width: 100%;height: 360px;background-color: #333;color:#fff; padding:0 5px" id="roll_info_log">'+rdata.data+'</textarea>';
$("#plugins_rolling_logs").html(ebody);
var ob = document.getElementById('roll_info_log');
ob.scrollTop = ob.scrollHeight;
},'json');
}
layer.open({
type: 1,
title: _name + '日志',
area: '640px',
end: function(){
// console.log('end!!!');
if (reqTimer){
clearInterval(reqTimer);
}
},
content:'<div class="change-default pd20" id="plugins_rolling_logs">\
<textarea readonly="readonly" style="margin: 0px;width: 100%;height: 360px;background-color: #333;color:#fff; padding:0 5px" id="roll_info_log"></textarea>\
</div>'
</div>',
success:function(){
$.post('/plugins/run', {name:_name, func:func_name, version:version, args:_args},function (data) {
var fileName = data.data;
requestLogs(fileName);
reqTimer = setInterval(function(){
requestLogs(fileName);
},1000);
},'json');
}
});
$.post('/plugins/run', {name:_name, func:func_name, version:version,args:_args},function (data) {
var fileName = data.data;
reqTimer = setInterval(function(){
$.post('/files/get_last_body', 'path=' + fileName+'&line='+file_line, function(rdata) {
if (!rdata.status){
return;
}
if(rdata.data == '') {
rdata.data = '当前没有日志!';
}
var ebody = '<textarea readonly="" style="margin: 0px;width: 100%;height: 360px;background-color: #333;color:#fff; padding:0 5px" id="roll_info_log">'+rdata.data+'</textarea>';
$("#plugins_rolling_logs").html(ebody);
var ob = document.getElementById('roll_info_log');
ob.scrollTop = ob.scrollHeight;
},'json');
},1000);
},'json');
}
+1 -1
View File
@@ -200,7 +200,7 @@ function webAddPage(type) {
}
domainlist = domainlist.substring(0,domainlist.length-1);//子域名json
domain ='{"domain":"'+domain[0]+'","domainlist":['+domainlist+'],"count":'+domain.length+'}';//拼接joson
domain ='{"domain":"'+domain[0]+'","domainlist":['+domainlist+'],"count":'+domain.length+'}';//拼接json
var loadT = layer.msg(lan.public.the_get,{icon:16,time:0,shade: [0.3, "#000"]})
var data = $("#addweb").serialize()+"&port="+webport+"&webinfo="+domain;
+129 -132
View File
@@ -1,155 +1,152 @@
{% extends "layout.html" %}
{% block content %}
<div class="main-content">
<div class="container-fluid" style="padding-bottom:54px">
<div class="pos-box bgw mtb15">
<div class="position f14 c9 pull-left">
<a class="plr10 c4" href="/">首页</a>/<span class="plr10 c4">面板设置</span>
<div class="container-fluid" style="padding-bottom:54px">
<div class="pos-box bgw mtb15">
<div class="position f14 c9 pull-left"><a class="plr10 c4" href="/">首页</a>/<span class="plr10 c4">面板设置</span></div>
</div>
<div class="clearfix bgw mtb15 pd15">
<div class="safe-port pull-left">
<div class="ss-text pull-left mr50">
<em>关闭面板</em>
<div class="ssh-item">
<input class="btswitch btswitch-ios" id="closePl" type="checkbox">
<label class="btswitch-btn" for="closePl" onclick="closePanel()"></label>
</div>
</div>
<div class="ss-text pull-left mr50">
<em>开发模式</em>
<div class="ssh-item">
<input class="btswitch btswitch-ios" id="debugMode" type="checkbox" {{data['debug']}}>
<label class="btswitch-btn" for="debugMode" onclick="debugMode()"></label>
</div>
</div>
<div class="ss-text pull-left mr50">
<em title="开启后允许使用ipv6访问面板">监听IPv6</em>
<div class='ssh-item'>
<input class='btswitch btswitch-ios' id='panelIPv6' type='checkbox' {{data['ipv6']}}>
<label class='btswitch-btn' for='panelIPv6' onclick="setIPv6()"></label>
</div>
</div>
</div>
<div class="clearfix bgw mtb15 pd15">
<div class="safe-port pull-left">
<div class="ss-text pull-left mr50">
<em>关闭面板</em>
<div class="ssh-item">
<input class="btswitch btswitch-ios" id="closePl" type="checkbox">
<label class="btswitch-btn" for="closePl" onclick="closePanel()"></label>
</div>
</div>
<div class="ss-text pull-left mr50">
<em>开发模式</em>
<div class="ssh-item">
<input class="btswitch btswitch-ios" id="debugMode" type="checkbox" {{data['debug']}}>
<label class="btswitch-btn" for="debugMode" onclick="debugMode()"></label>
</div>
</div>
<div class="ss-text pull-left mr50">
<em title="开启后允许使用ipv6访问面板">监听IPv6</em>
<div class='ssh-item'>
<input class='btswitch btswitch-ios' id='panelIPv6' type='checkbox' {{data['ipv6']}}>
<label class='btswitch-btn' for='panelIPv6' onclick="setIPv6()"></label>
</div>
</div>
</div>
</div>
<div class="setbox bgw mtb15">
<div class="title c6 plr15"><h3 class="f16">设置</h3></div>
<div class="info-title-tips" style="margin: 20px 30px 0px;">
<p><span class="glyphicon glyphicon-alert" style="color: #f39c12; margin-right: 10px;"></span>为了提高安全,修改面板密码!</p>
</div>
<div class="setbox bgw mtb15">
<div class="title c6 plr15">
<h3 class="f16">设置</h3>
</div>
<div class="info-title-tips" style="margin: 20px 30px 0px;">
<p><span class="glyphicon glyphicon-alert" style="color: #f39c12; margin-right: 10px;"></span>为了提高安全,修改面板密码!</p>
</div>
<div class="setting-con pd15">
<form id="set_config">
<p class="mtb15">
<span class="set-tit text-right">别名</span>
<input id="webname" name="webname" class="inputtxt bt-input-text" type="text" value="{{data['title']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_webname" disabled>保存</button>
<span class="set-info c7">面板名称</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="服务器IP">服务器IP</span>
<input name="host_ip" class="inputtxt bt-input-text" type="text" value="{{data['ip']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_host_ip" disabled>保存</button>
<span class="set-info c7">默认为外网IP,若您在本地虚拟机测试,请填写虚拟机内网IP!</span>
</p>
<p class="mtb15">
<span class="set-tit text-right">面板端口</span>
<input id="banport" name="port" class="inputtxt bt-input-text" type="numner" value="{{data['port']}}" maxlength="5">
<button type="button" class="btn btn-success btn-sm ml5 btn_port" disabled>保存</button>
<span class="set-info c7">建议端口范围7200 - 65535</span>
</p>
<p class="mtb15">
<span class="set-tit text-right">安全入口</span>
<input id="admin_path" name="admin_path" class="inputtxt bt-input-text disable" type="text" value="{{data['admin_path']}}">
<button type="button" class="btn btn-success btn-sm ml5" onclick="modifyAuthPath()">设置</button>
<span class="set-info c7">面板管理入口,设置后只能通过指定安全入口登录面板,如: /abc</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="默认建站目录">默认建站目录</span>
<input name="sites_path" class="inputtxt bt-input-text" type="text" value="{{data['site_path']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_sites_path" disabled>保存</button>
<span class="set-info c7">新创建的站点,默认将保存到该目录的下级目录!</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="默认建站目录">默认备份目录</span>
<input name="backup_path" class="inputtxt bt-input-text" type="text" value="{{data['backup_path']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_backup_path" disabled>保存</button>
<span class="set-info c7">网站和数据库的备份目录!</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="服务器时间">服务器时间</span>
<input id="systemdate" name="systemdate" class="inputtxt bt-input-text disable" type="text" value="{{data['systemdate']}}">
<button type="button" class="btn btn-success btn-sm ml5" onclick="syncDate()">同步</button>
<span class="set-info c7">同步当前服务器时间</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="面板用户">面板用户</span>
<input name="username_" class="inputtxt bt-input-text disable" type="text" value="{{data['username']}}" disabled>
<button type="button" class="btn btn-success btn-sm ml5" onclick="setUserName()">设置</button>
<span class="set-info c7">设置面板账号</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="面板密码">面板密码</span>
<input name="password_" class="inputtxt bt-input-text disable" type="text" value="******" disabled>
<button type="button" class="btn btn-success btn-sm ml5" onclick="setPassword()">设置</button>
<span class="set-info c7">设置面板密码</span>
</p>
</form>
</div>
<div class="title c6 plr15">
<h3 class="f16">安全</h3>
</div>
<div class="setting-con pd15">
<div class="setting-con pd15">
<form id="set_config">
<p class="mtb15">
<span class="set-tit text-right" title="绑定域名" style="float: left;">绑定域名</span>
<input name="bind_domain" class="inputtxt bt-input-text" type="text" value="{{data['bind_domain']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_bind_domain" disabled>保存</button>
<span class="set-info c7">为面板绑定一个访问域名,<b style="color: red;">注意:一旦绑定域名,只能通过域名访问面板</b></span>
<span class="set-tit text-right">别名</span>
<input id="webname" name="webname" class="inputtxt bt-input-text" type="text" value="{{data['title']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_webname" disabled>保存</button>
<span class="set-info c7">面板名称</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="面板SSL" style="float: left;">面板SSL</span>
<input id="cfg_ssl" name="bind_ssl" class="btswitch btswitch-ios" type="checkbox" {{data['ssl']}}>
<label class="btswitch-btn ml5" for="cfg_ssl" style="float: left;margin-top:4px;"></label>
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="getPanelSSL();">面板SSL配置</button>
<span class="set-info c7">为面板设置https协议访问,提升面板访问<b style="color: red;">安全性</b></span>
<span class="set-tit text-right" title="服务器IP">服务器IP</span>
<input name="host_ip" class="inputtxt bt-input-text" type="text" value="{{data['ip']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_host_ip" disabled>保存</button>
<span class="set-info c7">默认为外网IP,若您在本地虚拟机测试,请填写虚拟机内网IP!</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="BasicAuth认证" style="float: left;">BasicAuth认证</span>
<input class="btswitch btswitch-ios" id="cfg_basic_auth" type="checkbox" {{data['basic_auth']}}/>
<label class="btswitch-btn ml5" for="cfg_basic_auth" style="float: left;margin-top:4px;" onclick="setBasicAuth()"></label>
<span class="set-info c7">为面板增加一道基于BasicAuth的认证服务,有效防止面板被扫描</span>
<span class="set-tit text-right">面板端口</span>
<input id="banport" name="port" class="inputtxt bt-input-text" type="numner" value="{{data['port']}}" maxlength="5">
<button type="button" class="btn btn-success btn-sm ml5 btn_port" disabled>保存</button>
<span class="set-info c7">建议端口范围7200 - 65535</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="API接口" style="float: left;">API接口</span>
<input class="btswitch btswitch-ios" id="cfg_panel_api" type="checkbox" {{data['api_token']}}/>
<label class="btswitch-btn ml5" for="cfg_panel_api" style="float: left;margin-top:4px;" onclick="setPanelApi()"></label>
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="showPanelApi();">API接口配置</button>
<span class="set-info c7">提供面板API接口访问的支持</span>
<span class="set-tit text-right">安全入口</span>
<input id="admin_path" name="admin_path" class="inputtxt bt-input-text disable" type="text" value="{{data['admin_path']}}">
<button type="button" class="btn btn-success btn-sm ml5" onclick="modifyAuthPath()">设置</button>
<span class="set-info c7">面板管理入口,设置后只能通过指定安全入口登录面板,如: /abc</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="临时访问授权">临时访问授权</span>
<button type="button" class="btn btn-success btn-sm ml5" onclick="setTempAccess()">临时访问授权管理</button>
<span class="set-info c7">为非管理员临时提供面板访问权限</span>
<span class="set-tit text-right" title="默认建站目录">默认建站目录</span>
<input name="sites_path" class="inputtxt bt-input-text" type="text" value="{{data['site_path']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_sites_path" disabled>保存</button>
<span class="set-info c7">新创建的站点,默认将保存到该目录的下级目录!</span>
</p>
</div>
<p class="mtb15">
<span class="set-tit text-right" title="默认建站目录">默认备份目录</span>
<input name="backup_path" class="inputtxt bt-input-text" type="text" value="{{data['backup_path']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_backup_path" disabled>保存</button>
<span class="set-info c7">网站和数据库的备份目录!</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="服务器时间">服务器时间</span>
<input id="systemdate" name="systemdate" class="inputtxt bt-input-text disable" type="text" value="{{data['systemdate']}}">
<button type="button" class="btn btn-success btn-sm ml5" onclick="syncDate()">同步</button>
<span class="set-info c7">同步当前服务器时间</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="面板用户">面板用户</span>
<input name="username_" class="inputtxt bt-input-text disable" type="text" value="{{data['username']}}" disabled>
<button type="button" class="btn btn-success btn-sm ml5" onclick="setUserName()">设置</button>
<span class="set-info c7">设置面板账号</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="面板密码">面板密码</span>
<input name="password_" class="inputtxt bt-input-text disable" type="text" value="******" disabled>
<button type="button" class="btn btn-success btn-sm ml5" onclick="setPassword()">设置</button>
<span class="set-info c7">设置面板密码</span>
</p>
</form>
</div>
<div class="title c6 plr15"><h3 class="f16">安全</h3></div>
<div class="setting-con pd15">
<p class="mtb15">
<span class="set-tit text-right" title="绑定域名" style="float: left;">绑定域名</span>
<input name="bind_domain" class="inputtxt bt-input-text" type="text" value="{{data['bind_domain']}}">
<button type="button" class="btn btn-success btn-sm ml5 btn_bind_domain" disabled>保存</button>
<span class="set-info c7">为面板绑定一个访问域名,<b style="color: red;">注意:一旦绑定域名,只能通过域名访问面板</b></span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="面板SSL" style="float: left;">面板SSL</span>
<input id="cfg_ssl" name="bind_ssl" class="btswitch btswitch-ios" type="checkbox" {{data['ssl']}}>
<label class="btswitch-btn ml5" for="cfg_ssl" style="float: left;margin-top:4px;"></label>
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="getPanelSSL();">面板SSL配置</button>
<span class="set-info c7">为面板设置https协议访问,提升面板访问<b style="color: red;">安全性</b></span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="BasicAuth认证" style="float: left;">BasicAuth认证</span>
<input class="btswitch btswitch-ios" id="cfg_basic_auth" type="checkbox" {{data['basic_auth']}}/>
<label class="btswitch-btn ml5" for="cfg_basic_auth" style="float: left;margin-top:4px;" onclick="setBasicAuth()"></label>
<span class="set-info c7">为面板增加一道基于BasicAuth的认证服务,有效防止面板被扫描</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="API接口" style="float: left;">API接口</span>
<input class="btswitch btswitch-ios" id="cfg_panel_api" type="checkbox" {{data['api_token']}}/>
<label class="btswitch-btn ml5" for="cfg_panel_api" style="float: left;margin-top:4px;" onclick="setPanelApi()"></label>
<button ype="button" class="btn btn-default btn-xs panel_api_btn" style="vertical-align: middle; margin-left: 10px" onclick="showPanelApi();">API接口配置</button>
<span class="set-info c7">提供面板API接口访问的支持</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="未认证响应状态">未认证响应状态</span>
<input name="status_code" class="inputtxt bt-input-text disable" type="text" value="{{data['status_code_msg']}}" disabled>
<button type="button" class="btn btn-success btn-sm ml5" data-code="{{data['status_code']}}" onclick="setStatusCode(this)">设置</button>
<span class="set-info c7">用于在未登录且未正确输入安全入口时的响应,可用于隐藏面板特征</span>
</p>
<p class="mtb15">
<span class="set-tit text-right" title="临时访问授权">临时访问授权</span>
<button type="button" class="btn btn-success btn-sm ml5" onclick="setTempAccess()">临时访问授权管理</button>
<span class="set-info c7">为非管理员临时提供面板访问权限</span>
</p>
</div>
</div>
</div>
+2 -2
View File
@@ -10,7 +10,7 @@
</div>
<div class="search pull-right">
<form target="hid" onsubmit='getSList()'>
<input type="text" id="SearchValue" class="ser-text pull-left" placeholder="search" />
<input type="text" id="SearchValue" class="ser-text pull-left" placeholder="搜索" />
<button type="button" class="ser-sub pull-left" onclick='getSList()'></button>
</form>
</div>
@@ -27,7 +27,7 @@
<table class="table table-hover" width="100%" cellspacing="0" cellpadding="0" border="0">
<thead>
<tr>
<th width="165">软件名称</th>
<th width="185">软件名称</th>
<th>说明</th>
<th width="40">位置</th>
<th width="40">状态</th>
+12 -5
View File
@@ -14,7 +14,7 @@
PATH=/usr/local/bin:/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
# export LANG=en_US.UTF-8
export LANG=en_US.UTF-8
mw_path={$SERVER_PATH}
PATH=$PATH:$mw_path/bin
@@ -38,7 +38,7 @@ mw_start_panel()
sleep 0.5
isStart=$(lsof -n -P -i:$port|grep LISTEN|grep -v grep|awk '{print $2}'|xargs)
let n+=1
if [ $n -gt 15 ];then
if [ $n -gt 20 ];then
break;
fi
done
@@ -98,7 +98,7 @@ mw_stop_task()
arr=($pids)
for p in ${arr[@]}
do
kill -9 $p
kill -9 $p > /dev/null 2>&1
done
echo -e "\033[32mdone\033[0m"
}
@@ -109,7 +109,7 @@ mw_stop_panel()
arr=`ps aux|grep 'gunicorn -c setting.py app:app'|grep -v grep|awk '{print $2}'`
for p in ${arr[@]}
do
kill -9 $p &>/dev/null
kill -9 $p > /dev/null 2>&1
done
pidfile=${mw_path}/logs/mw.pid
@@ -313,11 +313,18 @@ case "$1" in
auth_path=$(cat $mw_path/data/admin_path.pl)
fi
if [ "$address" = "" ];then
if [ "$address" == "" ];then
v4=$(python3 $mw_path/tools.py getServerIp 4)
v6=$(python3 $mw_path/tools.py getServerIp 6)
if [ "$v4" != "" ] && [ "$v6" != "" ]; then
if [ ! -f $mw_path/data/ipv6.pl ];then
echo 'True' > $mw_path/data/ipv6.pl
mw_stop
mw_start
fi
address="MW-Panel-Url-Ipv4: http://$v4:$port$auth_path \nMW-Panel-Url-Ipv6: http://[$v6]:$port$auth_path"
elif [ "$v4" != "" ]; then
address="MW-Panel-Url: http://$v4:$port$auth_path"
+21 -21
View File
@@ -14,26 +14,25 @@ dnf install -y python-devel
dnf install -y crontabs
dnf install -y mysql-devel
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
if [ -f /usr/sbin/iptables ];then
# if [ -f /usr/sbin/iptables ];then
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# service iptables save
iptables_status=`service iptables status | grep 'not running'`
if [ "${iptables_status}" == '' ];then
service iptables restart
fi
# iptables_status=`service iptables status | grep 'not running'`
# if [ "${iptables_status}" == '' ];then
# service iptables restart
# fi
#安装时不开启
service iptables stop
fi
# #安装时不开启
# service iptables stop
# fi
if [ ! -f /usr/sbin/iptables ];then
@@ -41,14 +40,15 @@ if [ ! -f /usr/sbin/iptables ];then
systemctl enable firewalld
systemctl start firewalld
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
firewall-cmd --reload
+23 -22
View File
@@ -21,42 +21,43 @@ yum install -y curl-devel libmcrypt libmcrypt-devel
yum install -y mysql-devel
yum install -y expect
if [ -f /usr/sbin/iptables ];then
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
# if [ -f /usr/sbin/iptables ];then
iptables_status=`service iptables status | grep 'not running'`
if [ "${iptables_status}" == '' ];then
service iptables restart
fi
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# service iptables save
#安装时不开启
service iptables stop
fi
# iptables_status=`service iptables status | grep 'not running'`
# if [ "${iptables_status}" == '' ];then
# service iptables restart
# fi
# #安装时不开启
# service iptables stop
# fi
if [ ! -f /usr/sbin/iptables ];then
if [ ! -f /usr/sbin/firewalld ];then
yum install firewalld -y
systemctl enable firewalld
#取消服务锁定
systemctl unmask firewalld
systemctl start firewalld
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
firewall-cmd --reload
+23 -22
View File
@@ -54,40 +54,41 @@ echo y | pacman -Syu icu
hwclock --systohc
if [ -f /usr/sbin/iptables ];then
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
# if [ -f /usr/sbin/iptables ];then
iptables_status=`service iptables status | grep 'not running'`
if [ "${iptables_status}" == '' ];then
service iptables restart
fi
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# service iptables save
#安装时不开启
service iptables stop
fi
# iptables_status=`service iptables status | grep 'not running'`
# if [ "${iptables_status}" == '' ];then
# service iptables restart
# fi
# #安装时不开启
# service iptables stop
# fi
if [ ! -f /usr/sbin/iptables ];then
if [ ! -f /usr/sbin/firewalld ];then
echo y | pacman -Sy firewalld
systemctl enable firewalld
systemctl start firewalld
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
firewall-cmd --reload
-6
View File
@@ -29,9 +29,6 @@ if [ -f /usr/sbin/iptables ];then
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
iptables_status=`service iptables status | grep 'not running'`
@@ -55,9 +52,6 @@ if [ ! -f /usr/sbin/iptables ];then
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
+27 -21
View File
@@ -25,38 +25,44 @@ if [ ! -z "$cn" ];then
fi
ntpdate $NTPHOST | logger -t NTP
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
# choose lang cmd
# dpkg-reconfigure --frontend=noninteractive locales
if [ ! -f /usr/sbin/locale-gen ];then
apt install -y locales
sed -i '/en_US.UTF-8/s/^# //g' /etc/locale.gen
locale-gen en_US.UTF-8
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8
dpkg-reconfigure --frontend=noninteractive locales
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8 > /dev/null 2>&1
update-locale LANG=en_US.UTF-8
else
locale-gen en_US.UTF-8
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8 > /dev/null 2>&1
fi
apt-get update -y
apt install -y wget curl lsof unzip tar cron expect locate
apt install -y python3-pip python3-dev python3-venv
if [ -f /usr/sbin/ufw ];then
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw allow 888/tcp
# ufw allow 7200/tcp
# ufw allow 3306/tcp
# ufw allow 30000:40000/tcp
fi
# if [ -f /usr/sbin/ufw ];then
# if [ "$SSH_PORT" != "" ];then
# ufw allow $SSH_PORT/tcp
# else
# ufw allow 22/tcp
# fi
if [ -f /usr/sbin/ufw ];then
ufw disable
fi
# ufw allow 80/tcp
# ufw allow 443/tcp
# ufw allow 888/tcp
# fi
if [ ! -f /usr/sbin/ufw ];then
# if [ -f /usr/sbin/ufw ];then
# ufw disable
# fi
if [ ! -f /usr/sbin/firewalld ];then
# look
# firewall-cmd --list-all
@@ -66,20 +72,20 @@ if [ ! -f /usr/sbin/ufw ];then
systemctl unmask firewalld
systemctl start firewalld
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
# fix:debian10 firewalld faq
# https://kawsing.gitbook.io/opensystem/andoid-shou-ji/untitled/fang-huo-qiang#debian-10-firewalld-0.6.3-error-commandfailed-usrsbinip6tablesrestorewn-failed-ip6tablesrestore-v1.8
sed -i 's#IndividualCalls=no#IndividualCalls=yes#g' /etc/firewalld/firewalld.conf
firewall-cmd --reload
#安装时不开启
systemctl stop firewalld
fi
+32 -29
View File
@@ -17,45 +17,48 @@ yum install -y wget curl lsof unzip
yum install -y expect
dnf install crontabs -y
if [ -f /usr/sbin/iptables ];then
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
# if [ -f /usr/sbin/iptables ];then
iptables_status=`service iptables status | grep 'not running'`
if [ "${iptables_status}" == '' ];then
service iptables restart
fi
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
# service iptables save
#安装时不开启
service iptables stop
fi
# iptables_status=`service iptables status | grep 'not running'`
# if [ "${iptables_status}" == '' ];then
# service iptables restart
# fi
# #安装时不开启
# service iptables stop
# fi
if [ ! -f /usr/sbin/iptables ];then
yum install firewalld -y
systemctl enable firewalld
systemctl start firewalld
if [ "${isVersion}" == '' ];then
if [ ! -f "/usr/sbin/iptables" ];then
yum install firewalld -y
systemctl enable firewalld
systemctl start firewalld
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
firewall-cmd --reload
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
firewall-cmd --reload
fi
#安装时不开启
systemctl stop firewalld
+21 -23
View File
@@ -39,39 +39,40 @@ pkg install -y harfbuzz
pkg autoremove -y
if [ -f /usr/sbin/iptables ];then
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
# if [ -f /usr/sbin/iptables ];then
iptables_status=`service iptables status | grep 'not running'`
if [ "${iptables_status}" == '' ];then
service iptables restart
fi
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# service iptables save
#安装时不开启
service iptables stop
fi
# iptables_status=`service iptables status | grep 'not running'`
# if [ "${iptables_status}" == '' ];then
# service iptables restart
# fi
# #安装时不开启
# service iptables stop
# fi
if [ ! -f /usr/sbin/iptables ];then
pkg install -y firewalld
systemctl enable firewalld
systemctl start firewalld
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
@@ -80,9 +81,6 @@ if [ ! -f /usr/sbin/iptables ];then
systemctl stop firewalld
fi
cd /www/server/mdserver-web/scripts && bash lib.sh
chmod 755 /www/server/mdserver-web/data
+23 -22
View File
@@ -52,40 +52,41 @@ zypper install -y freetype2-devel
# zypper install -y php-config
if [ -f /usr/sbin/iptables ];then
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
# if [ -f /usr/sbin/iptables ];then
iptables_status=`service iptables status | grep 'not running'`
if [ "${iptables_status}" == '' ];then
service iptables restart
fi
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# service iptables save
#安装时不开启
service iptables stop
fi
# iptables_status=`service iptables status | grep 'not running'`
# if [ "${iptables_status}" == '' ];then
# service iptables restart
# fi
# #安装时不开启
# service iptables stop
# fi
if [ ! -f /usr/sbin/iptables ];then
if [ ! -f /usr/sbin/firewalld ];then
zypper install -y firewalld
systemctl enable firewalld
systemctl start firewalld
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
sed -i 's#AllowZoneDrifting=yes#AllowZoneDrifting=no#g' /etc/firewalld/firewalld.conf
firewall-cmd --reload
+43 -30
View File
@@ -33,42 +33,51 @@ if [ ! -d /root/.acme.sh ];then
curl https://get.acme.sh | sh
fi
echo "iptables wrap start"
if [ -f /usr/sbin/iptables ];then
$PKGMGR install -y iptables-services
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
# iptables -nL --line-number
# redhat , iptables no default
# echo "iptables wrap start"
# if [ -f /usr/sbin/iptables ];then
# $PKGMGR install -y iptables-services
# # iptables -nL --line-number
echo "iptables start"
iptables_status=`systemctl status iptables | grep 'inactive'`
if [ "${iptables_status}" != '' ];then
service iptables restart
# echo "iptables start"
# iptables_status=`systemctl status iptables | grep 'inactive'`
# if [ "${iptables_status}" != '' ];then
# service iptables restart
# iptables -P FORWARD DROP
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -A INPUT -p tcp -s 127.0.0.1 -j ACCEPT
# # iptables -P FORWARD DROP
# iptables -P INPUT DROP
# iptables -P OUTPUT ACCEPT
# iptables -A INPUT -p tcp -s 127.0.0.1 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
service iptables save
fi
# if [ "$SSH_PORT" != "" ];then
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport ${SSH_PORT} -j ACCEPT
# else
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
# fi
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 443 -j ACCEPT
# iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 888 -j ACCEPT
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 7200 -j ACCEPT
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 3306 -j ACCEPT
# # iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 30000:40000 -j ACCEPT
# service iptables save
# fi
# 安装时不开启
# stop之后清空了所有规则,所以安装是不能stop.
# 要在代码修复这个问题,开启时,重新执行一下放行端口。
#service iptables stop
# # 安装时不开启
# # stop之后清空了所有规则,所以安装是不能stop.
# # 要在代码修复这个问题,开启时,重新执行一下放行端口。
# #service iptables stop
echo "iptables end"
fi
echo "iptables wrap start"
# echo "iptables end"
# fi
# echo "iptables wrap start"
if [ ! -f /usr/sbin/iptables ];then
if [ ! -f /usr/sbin/firewalld ];then
$PKGMGR install firewalld -y
systemctl enable firewalld
#取消服务锁定
@@ -81,7 +90,11 @@ if [ ! -f /usr/sbin/iptables ];then
# look
# firewall-cmd --list-all
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
+25 -17
View File
@@ -24,36 +24,44 @@ apt install -y locate
locale-gen en_US.UTF-8
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8
SSH_PORT=`netstat -ntpl|grep sshd|grep -v grep | sed -n "1,1p" | awk '{print $4}' | awk -F : '{print $2}'`
echo "SSH PORT:${SSH_PORT}"
if [ -f /usr/sbin/ufw ];then
# if [ -f /usr/sbin/ufw ];then
ufw allow 22/tcp
ufw allow 80/tcp
ufw allow 443/tcp
ufw allow 888/tcp
# ufw allow 7200/tcp
# ufw allow 3306/tcp
# ufw allow 30000:40000/tcp
# # look
# # ufw status
# ufw enable
fi
# if [ "$SSH_PORT" != "" ];then
# ufw allow $SSH_PORT/tcp
# else
# ufw allow 22/tcp
# fi
# ufw allow 80/tcp
# ufw allow 443/tcp
# ufw allow 888/tcp
# fi
if [ -f /usr/sbin/ufw ];then
ufw disable
fi
# if [ -f /usr/sbin/ufw ];then
# ufw disable
# fi
if [ ! -f /usr/sbin/ufw ];then
if [ ! -f /usr/sbin/firewalld ];then
apt install -y firewalld
systemctl enable firewalld
systemctl start firewalld
firewall-cmd --permanent --zone=public --add-port=22/tcp
if [ "$SSH_PORT" != "" ];then
firewall-cmd --permanent --zone=public --add-port=${SSH_PORT}/tcp
else
firewall-cmd --permanent --zone=public --add-port=22/tcp
fi
firewall-cmd --permanent --zone=public --add-port=80/tcp
firewall-cmd --permanent --zone=public --add-port=443/tcp
firewall-cmd --permanent --zone=public --add-port=888/tcp
# firewall-cmd --permanent --zone=public --add-port=7200/tcp
# firewall-cmd --permanent --zone=public --add-port=3306/tcp
# firewall-cmd --permanent --zone=public --add-port=30000-40000/tcp
# fix:debian10 firewalld faq
# https://kawsing.gitbook.io/opensystem/andoid-shou-ji/untitled/fang-huo-qiang#debian-10-firewalld-0.6.3-error-commandfailed-usrsbinip6tablesrestorewn-failed-ip6tablesrestore-v1.8
+6 -6
View File
@@ -3,12 +3,12 @@ PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:~/bin
export PATH
export DEBIAN_FRONTEND=noninteractive
# apt install -y locate
# locale-gen C.UTF-8
# export LC_CTYPE=C.UTF-8
# export LC_ALL=C.UTF-8
# export LANG=C.UTF-8
apt install -y locate
locale-gen en_US.UTF-8
localedef -v -c -i en_US -f UTF-8 en_US.UTF-8 > /dev/null 2>&1
export LC_CTYPE=en_US.UTF-8
export LC_ALL=en_US.UTF-8
export LANG=en_US.UTF-8
# echo "LC_ALL=en_US.UTF-8" > /etc/default/locale
# echo "LANG=en_US.UTF-8" > /etc/default/locale
+3 -1
View File
@@ -92,6 +92,8 @@ def mwcli(mw_input=0):
firewall_api.firewall_api().addAcceptPortArgs(
in_port, 'WEB面板[TOOLS修改]', 'port')
mw.writeFile('data/port.pl', in_port)
os.system(INIT_CMD + " restart_panel")
os.system(INIT_CMD + " default")
else:
print("|-端口范围在0-65536之间")
return
@@ -167,7 +169,7 @@ def show_panel_pwd():
if mw.md5(file_pwd) == password:
print('password: ' + file_pwd)
return
print("the password has been changed!")
print("password has been changed!")
def set_panel_username(username=None):