Repository navigation
Expand file tree
/
Copy pathpatch_mutations.php
More file actions
93 lines (86 loc) · 3.2 KB
/
Copy pathpatch_mutations.php
File metadata and controls
93 lines (86 loc) · 3.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
<?php
$files = [
"ajax/img.upload.php",
"ajax/docs.upload.php",
"ajax/clear.cache.php",
"sign-up.php",
"user.role.edit.php",
"comp/docs.delete.php",
"comp/payment.pay.add.php",
"comp/user.delete.php",
"comp/sale.delete.php",
"object/ledger.php",
"comp/project.seller.delete.php",
"comp/project.edit.php",
"comp/sale.add.php",
"comp/account.edit.php",
"comp/role.add.php",
"comp/role.delete.php",
"comp/user.edit.php",
"comp/user.insert.php",
"comp/project.investor.add.php",
"comp/others.delete.php",
"comp/others.add.php",
"comp/project.investor.delete.php",
"comp/account.add.php",
"comp/role.edit.php",
"comp/property.add.php",
"comp/project.seller.add.php",
"comp/payment.pay.delete.php",
"auth/login.auth.php",
"auth/license.validate.functions.php",
"user.role.add.php"
];
$post_only = [
"comp/user.delete.php",
"comp/sale.delete.php",
"comp/project.seller.delete.php",
"comp/role.delete.php",
"comp/others.delete.php",
"comp/project.investor.delete.php",
"comp/payment.pay.delete.php",
"ajax/clear.cache.php",
"ajax/docs.upload.php"
];
foreach ($files as $file) {
if (!file_exists($file)) continue;
$content = file_get_contents($file);
// Add CSRF check if not present
if (strpos($content, 'verify_csrf_token') === false) {
$check = "\nif (!isset(\$_POST['csrf_token']) || !verify_csrf_token(\$_POST['csrf_token'])) {\n header('Location: ../index.php?m=invalid_csrf');\n exit();\n}\n";
// Find a good place to insert it (after session_start or includes)
if (strpos($file, 'comp/') === 0 || strpos($file, 'ajax/') === 0) {
$insert_pos = strpos($content, '######################## Database Connection #######################');
if ($insert_pos !== false) {
$end_pos = strpos($content, '########################', $insert_pos + 50);
if ($end_pos !== false) {
$insert_pos = $end_pos + 69; // approximate end of the block
}
} else {
$insert_pos = strpos($content, '$conn = conn(');
if ($insert_pos !== false) {
$insert_pos = strpos($content, ';', $insert_pos) + 1;
}
}
} else {
$insert_pos = strpos($content, 'session_start();');
if ($insert_pos !== false) {
$insert_pos += 16;
}
}
if ($insert_pos !== false) {
// Also enforce POST method
if (in_array($file, $post_only) || strpos($content, '$_POST') !== false) {
$method_check = "\nif (\$_SERVER['REQUEST_METHOD'] !== 'POST') {\n header('Location: ../index.php?m=invalid_method');\n exit();\n}\n";
$check = $method_check . $check;
}
$content = substr_replace($content, $check, $insert_pos, 0);
}
}
// Convert GET to POST for post_only files
if (in_array($file, $post_only)) {
$content = str_replace('$_GET', '$_POST', $content);
}
file_put_contents($file, $content);
}
echo "Done patching mutations.\n";