2015-08-07 21:39:10 -03:00
|
|
|
<?php defined('BLUDIT') or die('Bludit CMS.');
|
|
|
|
|
|
|
|
class Security extends dbJSON
|
|
|
|
{
|
|
|
|
private $dbFields = array(
|
2015-10-30 19:44:12 -03:00
|
|
|
'key1'=>'Where we go we dont need roads',
|
2015-08-07 21:39:10 -03:00
|
|
|
'minutesBlocked'=>5,
|
2015-08-12 17:15:17 -03:00
|
|
|
'numberFailuresAllowed'=>10,
|
2015-08-17 23:02:19 -03:00
|
|
|
'blackList'=>array()
|
2015-08-07 21:39:10 -03:00
|
|
|
);
|
|
|
|
|
|
|
|
function __construct()
|
|
|
|
{
|
|
|
|
parent::__construct(PATH_DATABASES.'security.php');
|
|
|
|
}
|
|
|
|
|
2016-06-04 22:31:07 -03:00
|
|
|
// Authentication key
|
|
|
|
// --------------------------------------------------------------------
|
|
|
|
public function key1()
|
|
|
|
{
|
|
|
|
return $this->db['key1'];
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2015-09-07 21:51:48 -03:00
|
|
|
// ====================================================
|
|
|
|
// TOKEN FOR CSRF
|
|
|
|
// ====================================================
|
|
|
|
|
|
|
|
// Generate and save the token in Session.
|
2015-11-28 11:47:03 -03:00
|
|
|
public function generateTokenCSRF()
|
2015-09-07 21:51:48 -03:00
|
|
|
{
|
|
|
|
$token = Text::randomText(8);
|
|
|
|
$token = sha1($token);
|
|
|
|
|
2015-11-28 11:47:03 -03:00
|
|
|
Log::set(__METHOD__.LOG_SEP.'New tokenCSRF was generated '.$token);
|
|
|
|
|
2015-10-20 00:14:28 -03:00
|
|
|
Session::set('tokenCSRF', $token);
|
2015-09-07 21:51:48 -03:00
|
|
|
}
|
|
|
|
|
|
|
|
// Validate the token.
|
2015-11-28 11:47:03 -03:00
|
|
|
public function validateTokenCSRF($token)
|
2015-09-07 21:51:48 -03:00
|
|
|
{
|
2015-10-20 00:14:28 -03:00
|
|
|
$sessionToken = Session::get('tokenCSRF');
|
2015-09-07 21:51:48 -03:00
|
|
|
|
|
|
|
return ( !empty($sessionToken) && ($sessionToken===$token) );
|
|
|
|
}
|
|
|
|
|
|
|
|
// Returns the token.
|
2015-11-28 11:47:03 -03:00
|
|
|
public function getTokenCSRF()
|
2015-09-07 21:51:48 -03:00
|
|
|
{
|
2015-10-20 00:14:28 -03:00
|
|
|
return Session::get('tokenCSRF');
|
2015-09-07 21:51:48 -03:00
|
|
|
}
|
|
|
|
|
2015-11-28 11:47:03 -03:00
|
|
|
public function printTokenCSRF()
|
2015-09-07 21:51:48 -03:00
|
|
|
{
|
2015-10-20 00:14:28 -03:00
|
|
|
echo Session::get('tokenCSRF');
|
2015-09-07 21:51:48 -03:00
|
|
|
}
|
|
|
|
|
|
|
|
// ====================================================
|
|
|
|
// BRUTE FORCE PROTECTION
|
|
|
|
// ====================================================
|
|
|
|
|
2015-08-12 17:15:17 -03:00
|
|
|
public function isBlocked()
|
|
|
|
{
|
|
|
|
$ip = $this->getUserIp();
|
|
|
|
|
|
|
|
if(!isset($this->db['blackList'][$ip])) {
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
$currentTime = time();
|
|
|
|
$userBlack = $this->db['blackList'][$ip];
|
|
|
|
$numberFailures = $userBlack['numberFailures'];
|
|
|
|
$lastFailure = $userBlack['lastFailure'];
|
2015-08-07 21:39:10 -03:00
|
|
|
|
2015-08-12 17:15:17 -03:00
|
|
|
// Check if the IP is expired, then is not blocked.
|
2015-08-17 23:02:19 -03:00
|
|
|
if($currentTime > $lastFailure + ($this->db['minutesBlocked']*60)) {
|
2015-08-12 17:15:17 -03:00
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
// The IP has more failures than number of failures, then the IP is blocked.
|
|
|
|
if($numberFailures >= $this->db['numberFailuresAllowed']) {
|
2015-08-17 23:02:19 -03:00
|
|
|
Log::set(__METHOD__.LOG_SEP.'IP Blocked:'.$ip);
|
2015-08-12 17:15:17 -03:00
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
|
|
|
// Otherwise the IP is not blocked.
|
|
|
|
return false;
|
|
|
|
}
|
2015-08-07 21:39:10 -03:00
|
|
|
|
|
|
|
public function addLoginFail()
|
|
|
|
{
|
|
|
|
$ip = $this->getUserIp();
|
2015-08-12 17:15:17 -03:00
|
|
|
$currentTime = time();
|
|
|
|
$numberFailures = 1;
|
|
|
|
|
2015-08-17 23:02:19 -03:00
|
|
|
if(isset($this->db['blackList'][$ip]))
|
|
|
|
{
|
|
|
|
$userBlack = $this->db['blackList'][$ip];
|
|
|
|
$lastFailure = $userBlack['lastFailure'];
|
|
|
|
|
|
|
|
// Check if the IP is expired, then renew the number of failures.
|
|
|
|
if($currentTime <= $lastFailure + ($this->db['minutesBlocked']*60))
|
|
|
|
{
|
|
|
|
$numberFailures = $userBlack['numberFailures'];
|
|
|
|
$numberFailures = $numberFailures + 1;
|
|
|
|
}
|
2015-08-12 17:15:17 -03:00
|
|
|
}
|
|
|
|
|
|
|
|
$this->db['blackList'][$ip] = array('lastFailure'=>$currentTime, 'numberFailures'=>$numberFailures);
|
2015-08-07 21:39:10 -03:00
|
|
|
|
2015-08-17 23:02:19 -03:00
|
|
|
Log::set(__METHOD__.LOG_SEP.'Blacklist, IP:'.$ip.', Number of failures:'.$numberFailures);
|
|
|
|
|
2015-08-07 21:39:10 -03:00
|
|
|
// Save the database
|
|
|
|
if( $this->save() === false ) {
|
|
|
|
Log::set(__METHOD__.LOG_SEP.'Error occurred when trying to save the database file.');
|
|
|
|
return false;
|
|
|
|
}
|
|
|
|
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2015-08-17 23:18:57 -03:00
|
|
|
public function getNumberFailures($ip=null)
|
|
|
|
{
|
|
|
|
if(empty($ip)) {
|
|
|
|
$ip = $this->getUserIp();
|
|
|
|
}
|
|
|
|
|
|
|
|
if(isset($this->db['blackList'][$ip])) {
|
|
|
|
$userBlack = $this->db['blackList'][$ip];
|
|
|
|
return $userBlack['numberFailures'];
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-08-07 21:39:10 -03:00
|
|
|
public function getUserIp()
|
|
|
|
{
|
|
|
|
// User IP
|
|
|
|
if(getenv('HTTP_X_FORWARDED_FOR'))
|
|
|
|
$ip = getenv('HTTP_X_FORWARDED_FOR');
|
|
|
|
elseif(getenv('HTTP_CLIENT_IP'))
|
|
|
|
$ip = getenv('HTTP_CLIENT_IP');
|
|
|
|
else
|
|
|
|
$ip = getenv('REMOTE_ADDR');
|
|
|
|
|
|
|
|
return $ip;
|
|
|
|
}
|
2015-11-28 11:47:03 -03:00
|
|
|
}
|