[
MAINHACK
]
Mail Test
BC
Config Scan
HOME
Create...
New File
New Folder
Viewing / Editing File: webshield.py
File is not writable. Editing disabled.
"""Webshield related iptables rules.""" from typing import AbstractSet, Iterator, Mapping from im360.internals.core import firewall from im360.internals.core.firewall import FirewallRules from im360.subsys import webshield from im360.utils.validate import IPVersion from .port import redirect_port_rules from .types_ import FirewallRule, WebshieldRuleBuilder def rules( ipset_name: str, ip_version: IPVersion, gray_rules: WebshieldRuleBuilder ) -> Iterator[FirewallRule]: """Yield iptables *ip_version* rules for *ipset_name* using *gray_rules* builder. This is intended for ipsets that require webshield to implement their behavior e.g., to show captcha, splashscreen to the ips from the ipset """ redirect_map = webshield.port_redirect_map() dest_ports = webshield.redirected_to_webshield_ports() & set(redirect_map) yield from _redirect_rules( ipset_name, ip_version, redirect_map, dest_ports, gray_rules ) if firewall.is_nat_available(ip_version): yield from gray_rules.logdrop_chain_rules(ipset_name) yield from redirect_port_rules( ipset_name, dest_ports, redirect_map, FirewallRules.NAT, FirewallRules.redirect_to_captcha, ) else: # What we are doing if we encounter with centos 6 and ipv6? # Full description is available into: # https://cloudlinux.atlassian.net/browse/DEF-2898 # https://access.redhat.com/solutions/311493 # Mark traffic to http, https hosts and from graylist ip yield from redirect_port_rules( ipset_name, dest_ports, redirect_map, FirewallRules.MANGLE, FirewallRules.redirect_to_captcha_via_tproxy, ) yield from gray_rules.drop_tproxy_rules(ipset_name) def _redirect_rules( ipset_name: str, ip_version: IPVersion, redirect_map: Mapping[int, int], dest_ports: AbstractSet[int], gray_rules: WebshieldRuleBuilder, ) -> Iterator[FirewallRule]: """Yield rules for to-be-redirected ports""" yield from check_access_to_webshield_ports_rules( ipset_name, set(redirect_map[p] for p in dest_ports) ) yield from gray_rules.open_webshield_ports_for_localhost_rules(ip_version) yield from gray_rules.block_webshield_ports_rules( redirect_map, dest_ports ) yield from gray_rules.redirect_panel_ports(ip_version) yield FirewallRule( rule=FirewallRules.open_dst_ports_for_src_list( ipset_name, set(redirect_map[p] for p in dest_ports) ), ) def check_access_to_webshield_ports_rules( ipset_name: str, dest_ports: AbstractSet[int] ) -> Iterator[FirewallRule]: yield FirewallRule( chain=FirewallRules.WEBSHIELD_PORTS_INPUT_CHAIN, rule=FirewallRules.open_dst_ports_for_src_list( ipset_name, dest_ports, policy=FirewallRules.RETURN ), )
Save Changes
Cancel / Back
Close ×
Server Info
Hostname: server05.hostinghome.co.in
Server IP: 192.168.74.40
PHP Version: 7.4.33
Server Software: Apache
System: Linux server05.hostinghome.co.in 3.10.0-962.3.2.lve1.5.81.el7.x86_64 #1 SMP Wed May 31 10:36:47 UTC 2023 x86_64
HDD Total: 1.95 TB
HDD Free: 690.26 GB
Domains on IP: N/A (Requires external lookup)
System Features
Safe Mode:
Off
disable_functions:
None
allow_url_fopen:
On
allow_url_include:
Off
magic_quotes_gpc:
Off
register_globals:
Off
open_basedir:
None
cURL:
Enabled
ZipArchive:
Disabled
MySQLi:
Enabled
PDO:
Enabled
wget:
Yes
curl (cmd):
Yes
perl:
Yes
python:
Yes
gcc:
Yes
pkexec:
No
git:
Yes
User Info
Username: itsweb
User ID (UID): 1619
Group ID (GID): 1621
Script Owner UID: 1619
Current Dir Owner: N/A