Rev 2662 | Rev 2817 | Go to most recent revision | Blame | Compare with Previous | Last modification | View Log
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><!-- written by Rexy -->
<HEAD>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<TITLE>ALCASAR DNS BL filtering</TITLE>
<link rel="stylesheet" href="/css/style.css" type="text/css">
</HEAD>
<body>
<?
function form_filter ($form_content)
{
// réencodage iso + format unix + rc fin de ligne (ouf...)
        $list = str_replace("\r\n", "\n", utf8_decode($form_content));
        if (strlen($list) != 0){
                if ($list[strlen($list)-1] != "\n") { $list[strlen($list)]="\n";} ;} ;
        return $list;
}
function form_filter_ip($form_content, $color)
{
        //# reconstruction des ip
        $list = explode("\n", form_filter($form_content));
        $new_list = "";
        foreach($list as &$value)
        {
                if(preg_match('/([0-9]{1,3}.){3}[0-9]{1,3}/', $value))
                {
                        $new_list = $new_list.$value."\n";
                }
        }
        if($color == "white")
        {
                return preg_replace("/(.*)\n/", "add wl_ip_allowed $1\n", $new_list);
        }
        else
        {
                return preg_replace("/(.*)\n/", "add bl_ip_blocked $1\n", $new_list);
        }
}
function echo_file ($filename)
{
        if (file_exists($filename))
        {
                if (filesize($filename) != 0)
                {
                        $pointeur=fopen($filename,"r");
                        $tampon = fread($pointeur, filesize($filename));
                        fclose($pointeur);
                        echo $tampon;
                }
        }
        else
        {
                echo "$filename doesn't exist";
        }
}
function echo_ip_file ($filename)
{
        $filename = escapeshellarg($filename);
        exec("cat $filename | cut -d ' ' -f3", $resultat);
        for($i=0; $i<exec("wc -l $filename"); $i++)
        {
                echo $resultat[$i]."\n";
        }
}
# Choice of language
$Language = 'en';
if(isset($_SERVER['HTTP_ACCEPT_LANGUAGE'])){
        $Langue = explode(",",$_SERVER['HTTP_ACCEPT_LANGUAGE']);
        $Language = strtolower(substr(chop($Langue[0]),0,2));
}
if($Language == 'fr'){
        $l_bl="Liste noire générale";
        $l_load="Chargement...";
        $l_list_version="Version de la liste : ";
        $l_bl_categories="Sélectionnez les catégories à filtrer";
        $l_download_bl="Télécharger la dernière version";
        $l_fingerprint="L'empreinte numérique du fichier téléchargé est : ";
        $l_fingerprint2="Vérifiez-là en suivant ce lien (ligne 'blacklists.tar.gz') : ";
        $l_activate_bl="Activer la nouvelle version";
        $l_reject_bl="Rejeter";
        $l_warning="Temps estimé : une minute";
        $l_specific_filtering="Filtrage special";
        $l_maj_rehabilitated="Noms de domaine ou adresses IP réhabilités";
        $l_rehabilitated_dns="Noms de domaine réhabilités";
        $l_rehabilitated_dns_explain="Entrez ici des noms de domaine bloqués par la liste noire <BR> que vous souhaitez réhabiliter.";
        $l_add_to_bl="Noms de domaine ou adresses IP à ajouter à la liste noire";
        $l_rehabilitated_ip="Adresses IP réhabilitées";
        $l_rehabilitated_ip_explain="Entrez ici des IP bloquées par la liste noire <BR> que vous souhaitez réhabiliter.";
        $l_one_dns="Entrez une adresse DNS par ligne (exemple : www.domaine.com)";
        $l_one_ip="Entrez une IP par ligne (exemple : 123.123.123.123)";
        $l_one_dns_ip="Entrez un nom de domaine ou une adresse IP ou une adresse de réseau par ligne<br>exemple (domaine) : domaine.org. - exemple (ip) : 61.54.52.56 - exemple (réseau) : 172.16.0.0/16";
        $l_record="Enregistrer les modifications";
        $l_wait="Une fois validées, 10 secondes sont nécessaires pour traiter vos modifications";
        $l_ip_filtering="Filtrer les URLs contenant une adresse IP au lieu d'un nom de domaine (ex: http://25.56.58.59/index.htm)";
        $l_safe_searching="Activer le contrôle scolaire/parental pour 'YouTube' et pour les moteurs de recherche 'Google', 'Bing' et 'Qwant'.";
        $l_error_open_file="Erreur d'ouverture du fichier";
        $l_additional_file_title="Fichiers de 'listes noires' additionnels";
        $l_file_list="Liste des fichiers";
        $l_add_file="Ajouter un fichier";
        $l_add_file_explain="Chaque ligne du fichier doit être une adresse IP ou un nom de domaine";
        $l_file_name="Nom du fichier";
        $l_file_action="Action";
        $l_error_upload="Erreur d'envoi du fichier";
        $l_remove="Supprimer";
        $l_submit="Envoyer";
        $l_nb_ip="Nombre d'IP";
        $l_nb_domain_names="Nombre de noms de domaine";
        $l_nbDomainNames="Noms de domaine :";
        $l_nbUrl="Url :";
        $l_nbIp="Ip :";
        $l_update_cat="Mise a jour des catégories automatiquement toutes les 12h (seulement 'malware' actuellement)?";
        $l_disable="Désactiver";
        $l_enable="Activer";
        $l_file_state="Etat";
}
else {
        $l_bl="General BlackList";
        $l_load="Loading...";
        $l_list_version="List version : ";
        $l_bl_categories="Select the categories to filter";
        $l_download_bl="Download the last version";
        $l_fingerprint="The digital fingerprint of the downloaded blacklist is : ";
        $l_fingerprint2="Verify it with this link (line 'blacklists.tar.gz') : ";
        $l_activate_bl="Activate the new version";
        $l_reject_bl="Reject";
        $l_warning="Estimated time : one minute";
        $l_specific_filtering="Specific filtering";
        $l_allowed_dns="Allowed domain names";
        $l_maj_rehabilitated="Domain names or IP addresses to rehabilitated";
        $l_rehabilitated_dns="Domain names to rehabilitated";
        $l_rehabilitated_dns_explain="Enter here domain names that are blocked by the blacklist <BR> and you want to rehabilitate.";
        $l_add_to_bl="Domain names or IP addresses to add to the blacklist";
        $l_rehabilitated_ip="IP addresses to rehabilitated";
        $l_rehabilitated_ip_explain="Enter here IP that are blocked by the blacklist <BR> and you want to rehabilitate.";
        $l_one_dns="Enter one DNS per row (example : www.domain.com)";
        $l_one_ip="Enter one IP per row (example : 123.123.123.123)";
        $l_one_dns_ip="Enter one domain name or one IP address or one network address per row <br>example (domain): domain.org. - example (ip): 61.54.56.52 - example (network) : 172.16.0.0/16";
        $l_record="Save changes";
        $l_wait="Once validated, 10 seconds are necessary to compute your modifications";
        $l_ip_filtering="Filtering URLs that contain an IP address instead of a domain name (ie: http://25.56.58.59/index.htm)";
        $l_safe_searching="Enabling school/parental control for 'YouTube' and for the search engines 'Google', 'Bing' and 'Qwant'";
        $l_error_open_file="Error opening file";
        $l_additional_file_title="Additional blacklist files";
        $l_file_list="Files list";
        $l_add_file="Add a file";
        $l_add_file_explain="Each line of the file must be an IP address or a domain name";
        $l_file_name="Filename";
        $l_file_action="Action";
        $l_error_upload="Error during the upload process";
        $l_remove="Delete";
        $l_submit="Submit";
        $l_nb_ip="Number of IP";
        $l_nb_domain_names="Number of domain names";
        $l_nbDomainNames="Domain names :";
        $l_nbUrl="Url :";
        $l_nbIp="Ip :";
        $l_update_cat="Update automaticly categories every 12 hours (only 'malware' for now)?";
        $l_disable="Disable";
        $l_enable="Enable";
        $l_file_state="State";
}
$dir_etc="/usr/local/etc/";
$dir_dg="/etc/e2guardian/lists/";
$dir_blacklist=$dir_dg."blacklists/";
$dir_bl_ip="/usr/local/share/iptables-bl/";
$dir_bl_ip_enabled="/usr/local/share/iptables-bl-enabled/";
$dir_bl_domain_names="/usr/local/share/unbound-bl/";
$dir_bl_domain_names_enabled="/usr/local/share/unbound-bl-enabled/";
$bl_categories=$dir_etc."alcasar-bl-categories";
$bl_categories_enabled=$dir_etc."alcasar-bl-categories-enabled";
$conf_file=$dir_etc."alcasar.conf";
$domainfilter_file="/etc/unbound/conf.d/blacklist/domainfilter.conf";
$bannedsite_file=$dir_dg."bannedsitelist";
$dir_tmp="/tmp/blacklists";
$update_file_cat="/usr/local/etc/update_cat.conf";
$bl_safesearch="off";
$bl_pureip="off";
# default values
if (is_file ($conf_file))
{
        $tab=file($conf_file);
        if ($tab)
        {
                foreach ($tab as $line)
                {
                        $field=explode("=", $line);
                        switch ($field[0]) {
                                case 'PRIVATE_IP':
                                        $PRIVATE_IP_MASK=trim($field[1]);
                                        $tmp = explode("/",$PRIVATE_IP_MASK);
                                        $PRIVATE_IP=$tmp[0];
                                        break;
                                case 'BL_SAFESEARCH':
                                        if (strtolower(trim($field[1])) == 'on') {
                                                $bl_safesearch='on';
                                        }
                                        break;
                                case 'BL_PUREIP':
                                        if (strtolower(trim($field[1])) == 'on') {
                                                $bl_pureip='on';
                                        }
                                        break;
                        }
                }
        }
}
else { echo "$l_error_open_file $conf_file";}
if (isset($_POST['choix'])){ $choix=$_POST['choix']; } else { $choix=""; }
switch ($choix)
{
        case 'Download_list' :
                exec ("sudo /usr/local/bin/alcasar-bl.sh --download");
                break;
        case 'Active_list' :
                exec ("sudo /usr/local/bin/alcasar-bl.sh --adapt");
                exec ("sudo /usr/local/bin/alcasar-bl.sh --reload");
                break;
        case 'Reject_list' :
                unlink ("$dir_tmp/blacklists.tar.gz"); unlink ("$dir_tmp/md5sum");
                break;
        case 'MAJ_cat_bl' :
                if (file_exists($bl_categories_enabled))
                {
                        exec("/bin/sed -i \"/^ossi-/!d\" $bl_categories_enabled"); // keep ossi custom categories
                        $pointeur=fopen($bl_categories_enabled, "a+");
                        $fichier=fopen($update_file_cat,"w+");
                        foreach ($_POST as $key => $value)
                        {
                                if (strstr($key,'chk-'))
                                {
                                        $line=str_replace('chk-','',$key)."\n";
                                        fwrite($pointeur,$line);
                                        if(trim($line) == 'malware' && $_POST['update_cat'] == 1) //auto-update of malware
                                        {
                                                fputs($fichier, "malware rsync://ftp.ut-capitole.fr/blacklist/dest/malware\n");
                                        }
                                }
                        }
                        fclose($pointeur);
                        fclose($fichier);
                }
                else {echo "$l_error_open_file $bl_categories_enabled";}
                $fichier=fopen($dir_blacklist."ossi-bl/domains","w+");
                fputs($fichier, form_filter($_POST['OSSI_bl']));
                fclose($fichier);
                unset($_POST['OSSI_bl']);
                $fichier=fopen($dir_dg."exceptionsitelist","w+");
                fputs($fichier, form_filter($_POST['BL_rehabilited_domains']));
                fclose($fichier);
                unset($_POST['BL_rehabilited_domains']);
                $fichier=fopen($dir_dg."exceptioniplist","w+");
                fputs($fichier, form_filter($_POST['BL_rehabilited_ip']));
                fclose($fichier);
                unset($_POST['BL_rehabilited_ip']);
                exec ("sudo /usr/local/bin/alcasar-bl.sh --reload");
                break;
        case 'Specific_filtering':
                $bl_pureip='off';
                $bl_safesearch='off';
                foreach ($_POST as $key => $value)
                {
                        if (strstr($key,'chk-ip')) $bl_pureip="on";
                        if (strstr($key,'chk-safesearch')) $bl_safesearch="on";
                }
                exec ("sudo /usr/local/bin/alcasar-url_filter_bl.sh -safesearch_$bl_safesearch -pureip_$bl_pureip");
                break;
        case 'MAJ_ossi_file' :
                foreach($_POST as $fichier => $value)
                {
                        if($fichier != "choix")
                        {
                                $action=$_POST[$fichier];
                                if($action == $l_remove) //delete
                                {
                                        exec("/bin/sed -i ".escapeshellarg("/^$fichier\$/d")." $bl_categories_enabled");
                                        exec("/bin/sed -i ".escapeshellarg("/$fichier\$/d")." $bl_categories");
                                        exec("rm -rf $dir_blacklist".escapeshellarg($fichier));
                                        exec("sudo /usr/local/bin/alcasar-bl.sh --reload");
                                }
                                if($action == $l_disable) //disable
                                {
                                        exec("/bin/sed -i ".escapeshellarg("/^$fichier\$/d")." $bl_categories_enabled");
                                        exec("sudo /usr/local/bin/alcasar-bl.sh --reload");
                                }
                                if($action == $l_enable) //enable
                                {
                                        file_put_contents ($bl_categories_enabled, $fichier."\n", FILE_APPEND);
                                        exec("sudo /usr/local/bin/alcasar-bl.sh --reload");
                                }
                        }
                }
                break;
        case 'MAJ_ossi_file_upload' :
                $file_name = str_replace (".", "_",basename($_FILES['fichier_ip']['name']));
                $dest_dir = $dir_blacklist."ossi-bl-".$file_name; # /etc/e2guardian/list/blacklist/ossi-bl-XXXXXXXX
                if((!empty($file_name)) && (!file_exists($dest_dir)))
                {
                        exec("mkdir ".escapeshellarg($dest_dir));
                        $file=$_FILES['fichier_ip']['tmp_name'];
                        exec('/usr/bin/dos2unix '.escapeshellarg($file));
                        if(move_uploaded_file($_FILES['fichier_ip']['tmp_name'], $dest_dir."/domains")) // copy in the file "domains" (containing @ip & domain names (like over Toulouse categories))
                        {
                                touch ($dest_dir."/urls"); // create the URL file even if it isn't used
                                file_put_contents ($bl_categories, $dest_dir."\n", FILE_APPEND); # add to the categories list
                                file_put_contents ($bl_categories_enabled, "ossi-bl-".$file_name."\n", FILE_APPEND); //Enabled by default
                                exec("sudo /usr/local/bin/alcasar-bl.sh --reload");
                        }
                        else
                        {
                                exec("rm -rf ".escapeshellarg($dest_dir));
                                echo $l_error_upload;
                        }
                }
                break;
}
?>
<table width="100%" border="0" cellspacing="0" cellpadding="0">
        <tr><th>
        <?php echo $l_list_version; echo date ("F d Y", filemtime ('/etc/e2guardian/lists/blacklists/README'));?>
        </th></tr>
        <tr bgcolor="#FFCC66"><td><img src="/images/pix.gif" width="1" height="2"></td></tr>
</table>
<TABLE width="100%" border=1 cellspacing=0 cellpadding=1>
<tr><td valign="middle" align="left" colspan=10>
<FORM action='bl_filter.php' method=POST>
<?php
if ((file_exists("$dir_tmp/blacklists.tar.gz")) && (file_exists("$dir_tmp/md5sum")))
{
        echo "$l_fingerprint"; echo_file ("$dir_tmp/md5sum");
        echo "<br>$l_fingerprint2<a href='http://dsi.ut-capitole.fr/blacklists/download/MD5SUM.LST' target='cat_help' onclick=\"window.open('http://dsi.ut-capitole.fr/blacklists/download/MD5SUM.LST','cat_help','width=600,height=150,toolbar=no,scrollbars=yes,resizable=yes')\" title='verify fingerprint'>dsi.ut-capitole.fr/blacklists/download/MD5SUM.LST</a><br>";
        echo "<input type='hidden' name='choix' value='Active_list'>";
        echo "<input type='submit' onClick=\"this.disabled=true; this.value='$l_load';submit();\" value='$l_activate_bl'> ($l_warning)</FORM>";
        echo "<FORM action='bl_filter.php' method=POST>";
        echo "<input type='hidden' name='choix' value='Reject_list'>";
        echo "<input type='submit' onClick=\"this.disabled=true; this.value='$l_load';submit();\" value='$l_reject_bl'></form>";
}
else
{
        echo "<input type='hidden' name='choix' value='Download_list'>";
        echo "<input type='submit' onClick=\"this.disabled=true; this.value='$l_load';submit();\" value='$l_download_bl'> ($l_warning)</form>";
}
?>
</td></tr>
</table><br>
<table width="100%" border="0" cellspacing="0" cellpadding="0">
        <tr><th><?php echo $l_bl; ?></th></tr>
        <tr bgcolor="#FFCC66"><td><img src="/images/pix.gif" width="1" height="2"></td></tr>
</table>
<FORM action='bl_filter.php' method=POST>
<input type='hidden' name='choix' value='MAJ_cat_bl'>
<table width="100%" border=1 cellspacing=0 cellpadding=1>
<tr><td valign="middle" align="left" colspan=10>
<?php
echo "<center>";
// total number of IP, DNS & URLs
$nbDomainNames = exec("wc -l /usr/local/share/unbound-bl/* | tail -n 1 | awk '{print $1}'") / 2;
$nbUrl = exec("for file in `find /etc/e2guardian/lists/blacklists/ -name 'urls'`; do nb=$((nb+$(wc -l \$file | awk '{print $1}'))); done; echo \$nb");
$nbIp = exec("wc -l /usr/local/share/iptables-bl/* | tail -n 1 | awk '{print $1}'");
echo "<b>$l_nbDomainNames</b> $nbDomainNames, <b>$l_nbUrl</b> $nbUrl, <b>$l_nbIp</b> $nbIp<br/>";
echo "$l_bl_categories</center></td></tr>";
//read & display all BL categories (checked or not)
$cols=1;
if (file_exists($bl_categories))
{
        $bl_files = file($bl_categories);
        $bl_files = preg_grep("/ossi-/", $bl_files, 1); // don't display ossi custom categories
        foreach($bl_files as $fichier => $value)
        {
                if ($cols == 1) { echo "<tr>";}
                $categorie=trim(basename($value));
                echo "<td><a href='bl_categories_help.php?liste=bl&cat=$categorie' target='cat_help' onclick=\"window.open('bl_categories_help.php','cat_help','width=600,height=450,toolbar=no,scrollbars=yes,resizable=yes')\" title='categories help page'>$categorie</a><br>";
                echo "<input type='checkbox' name='chk-$categorie'";
                // if the line is commented, the category is disable
                if (preg_match('/^#/',$value, $r)) { echo ">";}
                else { echo " checked>"; }
                echo "</td>";
                $cols++;
                if ($cols > 10) {
                        echo "</tr>\n";
                        $cols=1;
                }
        }
}
else {
        echo "$l_error_open_file $bl_categories";
}
//update categories with rsync
$update_select = array();
$update_select[0] = "";
$update_select[1] = "";
if ( 0 == filesize( $update_file_cat ) ) $update_select[0] = "checked";
else $update_select[1] = "checked";
echo "</tr>\n";
echo "<tr><td valign='middle' align='left' colspan=10>";
echo "<center>$l_update_cat
        <input type='radio' name='update_cat' value=0 $update_select[0]> $l_disable
        <input type='radio' name='update_cat' value=1 $update_select[1]> $l_enable
        <input type='submit' value='$l_record'></center>";
echo "</td></tr>";
echo "<tr><td valign='middle' align='left' colspan=10>";
echo "<center><b>$l_maj_rehabilitated</b></center></td></tr>";
echo "<tr><td width=50% colspan=5 align=center>";
echo "<H3>$l_rehabilitated_dns</H3>$l_rehabilitated_dns_explain<BR>$l_one_dns<BR>";
echo "<textarea name='BL_rehabilited_domains' rows=3 cols=40>";
echo_file ($dir_dg."exceptionsitelist");
echo "</textarea></td>";
echo "<td width=50% colspan=5 align=center>";
echo "<H3>$l_rehabilitated_ip</H3>$l_rehabilitated_ip_explain<BR>$l_one_ip<BR>";
echo "<textarea name='BL_rehabilited_ip' rows=3 cols=40>";
echo_file ($dir_dg."exceptioniplist");
echo "</textarea></td></tr>";
echo "<tr><td valign='middle' align='left' colspan=10>";
echo "<center><b>$l_add_to_bl</b></center></td></tr>";
echo "<tr><td width=100% colspan=10 align=center>";
echo "$l_one_dns_ip<BR>";
echo "<textarea name='OSSI_bl' rows=3 cols=40>";
echo_file ($dir_blacklist."ossi-bl/domains");
echo "</textarea></td>";
echo "</tr><tr><td colspan=10>";
echo "<input type='submit' onClick=\"this.disabled=true; this.value='$l_load';submit();\" value='$l_record'>";
echo "</td></tr></table><br>";
echo "</form> ($l_wait)";
?>
<table width="100%" border="0" cellspacing="0" cellpadding="0">
        <tr><th><?php echo $l_additional_file_title; ?></th></tr>
        <tr bgcolor="#FFCC66"><td><img src="/images/pix.gif" width="1" height="2"></td></tr>
</table>
<table width="100%" border=1 cellspacing=0 cellpadding=1>
<?php
echo "<tr><td width=50% colspan=5 align=center>";
echo "<H3>$l_file_list</H3>";
echo "<form action='bl_filter.php' method='POST'>";
echo "<input type='hidden' name='choix' value='MAJ_ossi_file'>";
echo "<table cellspacing=2 cellpadding=3 border=1><tr><th>$l_file_name<th>$l_nb_ip<th>$l_nb_domain_names<th colspan=2>$l_file_action</tr>";
//list OSSI custom categories
$fichiersbl = array_diff(scandir($dir_blacklist), array('..','.','ossi-bl','ossi-wl'));
$fichiersbl = preg_grep("/^ossi-bl-/",$fichiersbl);
foreach($fichiersbl as $fichier => $value)
{
        echo "<tr><td><center><a href='bl_categories_help.php?liste=bl&cat=$value&filtre=domain' target='cat_help' onclick=\"window.open('bl_categories_help','cat_help','width=600,height=450,toolbar=no,scrollbars=yes,resizable=yes')\" title='categories help page'>".substr($value,8)."</a></center></td><td><center>".exec("wc -l $dir_bl_ip$value | cut -d\" \" -f1")."</center></td><td><center>".exec("wc -l $dir_bl_domain_names$value.conf | cut -d\" \" -f1")."</center></td><td><center><input type='submit' name='$value'";
        if (file_exists ($dir_bl_domain_names_enabled.$value)) echo " value='$l_disable'>"; else echo " value='$l_enable'>";
        echo "</center></td><td><center><input type='submit' name='$value' value='$l_remove'></center></td></tr>";
}
echo "</table></form><br></td>";
echo "<td width=50% colspan=5 align=center><H3>$l_add_file</H3>";
echo "$l_add_file_explain";
echo "<form action='bl_filter.php' method='POST' enctype='multipart/form-data'>";
echo "<input type='hidden' name='choix' value='MAJ_ossi_file_upload'>";
echo "<input type='file' name='fichier_ip'>";
echo "<input type='submit' onClick=\"this.disabled=true; this.value='$l_load';submit();\" value='$l_submit'>";
echo "</form>";
echo "</td></tr>";
echo "</table><br>";
?>
<table width="100%" border="0" cellspacing="0" cellpadding="0">
        <tr><th><?php echo $l_specific_filtering; ?></th></tr>
        <tr bgcolor="#FFCC66"><td><img src="/images/pix.gif" width="1" height="2"></td></tr>
</table>
<FORM action='bl_filter.php' method='POST'>
<input type='hidden' name='choix' value='Specific_filtering'>
<table width="100%" border=1 cellspacing=0 cellpadding=1>
<tr><td>
<input type='checkbox' name='chk-ip' <?= $bl_pureip == 'on' ? 'checked' : ''; ?>><?= $l_ip_filtering; ?>
</td></tr>
<tr><td>
<input type='checkbox' name='chk-safesearch' <?= $bl_safesearch == 'on' ? 'checked' : ''; ?>><?= $l_safe_searching; ?>
</tr></td>
<tr><td>
<?= "<input type='submit' onClick=\"this.disabled=true; this.value='$l_load';submit();\" value='$l_record'>"; ?>
</td></tr>
</table>
</form>
</BODY>
</HTML>