Edit File by line
/home/zeestwma/ceyloniy.../wp-conte.../plugins/cookiead.../includes
File: scanner.php
<?php
[0] Fix | Delete
[1] Fix | Delete
namespace CookieAdmin;
[2] Fix | Delete
[3] Fix | Delete
if(!defined('COOKIEADMIN_VERSION') || !defined('ABSPATH')){
[4] Fix | Delete
die('Hacking Attempt');
[5] Fix | Delete
}
[6] Fix | Delete
[7] Fix | Delete
class Scanner{
[8] Fix | Delete
[9] Fix | Delete
static $home_url;
[10] Fix | Delete
static $urls_to_scan = [];
[11] Fix | Delete
static $visited_urls = [];
[12] Fix | Delete
static $raw_redirect_headers = [];
[13] Fix | Delete
static $found_cookies = [];
[14] Fix | Delete
static $scan_limit = 10;
[15] Fix | Delete
[16] Fix | Delete
[17] Fix | Delete
static function start_scan(){
[18] Fix | Delete
[19] Fix | Delete
self::$home_url = get_home_url();
[20] Fix | Delete
self::$urls_to_scan[] = self::$home_url;
[21] Fix | Delete
[22] Fix | Delete
while (! empty(self::$urls_to_scan) && count(self::$visited_urls) < self::$scan_limit){
[23] Fix | Delete
$url = array_shift(self::$urls_to_scan); // Get the next URL from the queue
[24] Fix | Delete
[25] Fix | Delete
if (in_array($url, self::$visited_urls, true)){
[26] Fix | Delete
continue;
[27] Fix | Delete
}
[28] Fix | Delete
[29] Fix | Delete
self::scan_single_url($url);
[30] Fix | Delete
}
[31] Fix | Delete
[32] Fix | Delete
return self::$found_cookies;
[33] Fix | Delete
}
[34] Fix | Delete
[35] Fix | Delete
[36] Fix | Delete
static function scan_single_url($url){
[37] Fix | Delete
[38] Fix | Delete
self::$visited_urls[] = $url;
[39] Fix | Delete
[40] Fix | Delete
$response = wp_remote_get($url, [
[41] Fix | Delete
'sslverify' => false,
[42] Fix | Delete
'timeout' => 15,
[43] Fix | Delete
'redirection' => 5
[44] Fix | Delete
]);
[45] Fix | Delete
[46] Fix | Delete
if (is_wp_error($response)) return;
[47] Fix | Delete
[48] Fix | Delete
if (! empty($response['cookies'])){
[49] Fix | Delete
[50] Fix | Delete
$all_headers = wp_remote_retrieve_headers($response);
[51] Fix | Delete
$raw_cookie_headers = isset($all_headers['set-cookie']) ? $all_headers['set-cookie'] : [];
[52] Fix | Delete
[53] Fix | Delete
self::process_and_store_cookies($response['cookies'], $raw_cookie_headers);
[54] Fix | Delete
}
[55] Fix | Delete
[56] Fix | Delete
$body = wp_remote_retrieve_body($response);
[57] Fix | Delete
if (empty($body)) return;
[58] Fix | Delete
[59] Fix | Delete
$dom = new \DOMDocument();
[60] Fix | Delete
@$dom->loadHTML($body, LIBXML_NOERROR | LIBXML_NOWARNING);
[61] Fix | Delete
[62] Fix | Delete
self::find_and_queue_links($dom);
[63] Fix | Delete
self::scan_forms_on_page($url, $dom);
[64] Fix | Delete
}
[65] Fix | Delete
[66] Fix | Delete
[67] Fix | Delete
static function scan_forms_on_page($page_url, $dom){
[68] Fix | Delete
[69] Fix | Delete
$forms = $dom->getElementsByTagName('form');
[70] Fix | Delete
[71] Fix | Delete
foreach ($forms as $form){
[72] Fix | Delete
[73] Fix | Delete
$method = strtolower($form->getAttribute('method'));
[74] Fix | Delete
if ($method !== 'post'){
[75] Fix | Delete
continue;
[76] Fix | Delete
}
[77] Fix | Delete
[78] Fix | Delete
self::$raw_redirect_headers = [];
[79] Fix | Delete
[80] Fix | Delete
$action_url = $form->getAttribute('action');
[81] Fix | Delete
if (empty($action_url) || $action_url[0] === '#'){
[82] Fix | Delete
$action_url = $page_url;
[83] Fix | Delete
} elseif ($action_url[0] === '/'){
[84] Fix | Delete
$action_url = self::$home_url . $action_url;
[85] Fix | Delete
}
[86] Fix | Delete
[87] Fix | Delete
$post_data = [];
[88] Fix | Delete
$inputs = $form->getElementsByTagName('input');
[89] Fix | Delete
foreach ($inputs as $input){
[90] Fix | Delete
$name = $input->getAttribute('name');
[91] Fix | Delete
$type = strtolower($input->getAttribute('type'));
[92] Fix | Delete
if (empty($name)){
[93] Fix | Delete
continue;
[94] Fix | Delete
}
[95] Fix | Delete
$value = $input->getAttribute('value');
[96] Fix | Delete
[97] Fix | Delete
switch ($type){
[98] Fix | Delete
case 'text':
[99] Fix | Delete
case 'email':
[100] Fix | Delete
case 'url':
[101] Fix | Delete
case 'password':
[102] Fix | Delete
case 'search':
[103] Fix | Delete
// If the value is empty, provide dummy data. Otherwise, use the existing value.
[104] Fix | Delete
if (empty($value)){
[105] Fix | Delete
if($type === 'email') $post_data[$name] = 'scanner@cookieadmin.net';
[106] Fix | Delete
elseif($type === 'url') $post_data[$name] = 'https://cookieadmin.net';
[107] Fix | Delete
else $post_data[$name] = 'Scanner Tester - '.uniqid();
[108] Fix | Delete
} else {
[109] Fix | Delete
$post_data[$name] = $value;
[110] Fix | Delete
}
[111] Fix | Delete
break;
[112] Fix | Delete
[113] Fix | Delete
case 'hidden':
[114] Fix | Delete
$post_data[$name] = $value;
[115] Fix | Delete
break;
[116] Fix | Delete
[117] Fix | Delete
case 'checkbox':
[118] Fix | Delete
case 'radio':
[119] Fix | Delete
if (empty($value)) $post_data[$name] = true;
[120] Fix | Delete
break;
[121] Fix | Delete
[122] Fix | Delete
case 'submit':
[123] Fix | Delete
$post_data[$name] = $value;
[124] Fix | Delete
break;
[125] Fix | Delete
}
[126] Fix | Delete
}
[127] Fix | Delete
[128] Fix | Delete
$textareas = $form->getElementsByTagName('textarea');
[129] Fix | Delete
foreach ($textareas as $textarea){
[130] Fix | Delete
$name = $textarea->getAttribute('name');
[131] Fix | Delete
if(!empty($name) && !isset($post_data[$name])){
[132] Fix | Delete
$post_data[$name] = 'This is a test comment from the scanner. - '.uniqid();
[133] Fix | Delete
}
[134] Fix | Delete
}
[135] Fix | Delete
[136] Fix | Delete
if (!empty($post_data)){
[137] Fix | Delete
[138] Fix | Delete
add_action('requests-before_redirect_check', [self::class, 'capture_redirect_headers'], 10, 1);
[139] Fix | Delete
[140] Fix | Delete
$post_response = wp_remote_post($action_url, [
[141] Fix | Delete
'sslverify' => false,
[142] Fix | Delete
'body' => $post_data,
[143] Fix | Delete
]);
[144] Fix | Delete
[145] Fix | Delete
remove_action('requests-before_redirect_check', [self::class, 'capture_redirect_headers'], 10);
[146] Fix | Delete
[147] Fix | Delete
$final_headers = wp_remote_retrieve_headers($post_response);
[148] Fix | Delete
$final_cookie_headers = isset($final_headers['set-cookie']) ? $final_headers['set-cookie'] : [];
[149] Fix | Delete
if (!is_array($final_cookie_headers)) $final_cookie_headers = [$final_cookie_headers];
[150] Fix | Delete
[151] Fix | Delete
$all_raw_cookie_headers = array_merge(self::$raw_redirect_headers, $final_cookie_headers);
[152] Fix | Delete
[153] Fix | Delete
if (!is_wp_error($post_response) && !empty($post_response['cookies'])){
[154] Fix | Delete
self::process_and_store_cookies($post_response['cookies'], $all_raw_cookie_headers);
[155] Fix | Delete
}
[156] Fix | Delete
[157] Fix | Delete
}
[158] Fix | Delete
}
[159] Fix | Delete
}
[160] Fix | Delete
[161] Fix | Delete
[162] Fix | Delete
static function process_and_store_cookies($cookie_objects, $all_raw_headers){
[163] Fix | Delete
[164] Fix | Delete
if(!is_array($all_raw_headers)){
[165] Fix | Delete
$all_raw_headers = [$all_raw_headers];
[166] Fix | Delete
}
[167] Fix | Delete
[168] Fix | Delete
foreach ($cookie_objects as $cookie){
[169] Fix | Delete
[170] Fix | Delete
if (! isset(self::$found_cookies[$cookie->name])){
[171] Fix | Delete
[172] Fix | Delete
$is_secure = false;
[173] Fix | Delete
$is_httponly = false;
[174] Fix | Delete
$max_age = null;
[175] Fix | Delete
$samesite = null;
[176] Fix | Delete
[177] Fix | Delete
foreach ($all_raw_headers as $header_string){
[178] Fix | Delete
[179] Fix | Delete
if (!empty($header_string) && strpos(trim($header_string), $cookie->name . '=') === 0){
[180] Fix | Delete
[181] Fix | Delete
$is_secure = preg_match('/\bsecure\b/i', $header_string) === 1;
[182] Fix | Delete
$is_httponly = preg_match('/\bhttponly\b/i', $header_string) === 1;
[183] Fix | Delete
[184] Fix | Delete
if (preg_match('/;\s*Max-Age\s*=\s*([0-9]+)/i', $header_string, $matches)){
[185] Fix | Delete
$max_age = (int) $matches[1];
[186] Fix | Delete
}
[187] Fix | Delete
[188] Fix | Delete
if (preg_match('/;\s*SameSite\s*=\s*(Strict|Lax|None)/i', $header_string, $matches)){
[189] Fix | Delete
$samesite = ucfirst(strtolower($matches[1]));
[190] Fix | Delete
}
[191] Fix | Delete
break;
[192] Fix | Delete
}
[193] Fix | Delete
}
[194] Fix | Delete
[195] Fix | Delete
self::$found_cookies[$cookie->name] = [
[196] Fix | Delete
'cookie_name' => $cookie->name,
[197] Fix | Delete
'expires' => $cookie->expires,
[198] Fix | Delete
'path' => $cookie->path,
[199] Fix | Delete
'domain' => $cookie->domain,
[200] Fix | Delete
'secure' => $is_secure,
[201] Fix | Delete
'httponly' => $is_httponly,
[202] Fix | Delete
'Max-Age' => $max_age,
[203] Fix | Delete
'samesite' => $samesite,
[204] Fix | Delete
];
[205] Fix | Delete
}
[206] Fix | Delete
}
[207] Fix | Delete
}
[208] Fix | Delete
[209] Fix | Delete
[210] Fix | Delete
static function find_and_queue_links($dom){
[211] Fix | Delete
[212] Fix | Delete
$links = $dom->getElementsByTagName('a');
[213] Fix | Delete
[214] Fix | Delete
foreach ($links as $link){
[215] Fix | Delete
$href = $link->getAttribute('href');
[216] Fix | Delete
[217] Fix | Delete
if (strpos($href, self::$home_url) === 0 || preg_match('/^\/(?!\/)/', $href)){
[218] Fix | Delete
[219] Fix | Delete
if ($href[0] === '/'){
[220] Fix | Delete
$href = self::$home_url . $href;
[221] Fix | Delete
}
[222] Fix | Delete
[223] Fix | Delete
if (! in_array($href, self::$visited_urls) && ! in_array($href, self::$urls_to_scan)){
[224] Fix | Delete
self::$urls_to_scan[] = $href;
[225] Fix | Delete
}
[226] Fix | Delete
}
[227] Fix | Delete
}
[228] Fix | Delete
}
[229] Fix | Delete
[230] Fix | Delete
static function capture_redirect_headers($response){
[231] Fix | Delete
[232] Fix | Delete
if (is_object($response) && isset($response->headers['set-cookie'])){
[233] Fix | Delete
[234] Fix | Delete
$cookies = $response->headers['set-cookie'];
[235] Fix | Delete
[236] Fix | Delete
if (! is_array($cookies)){
[237] Fix | Delete
$cookies = [$cookies];
[238] Fix | Delete
}
[239] Fix | Delete
[240] Fix | Delete
self::$raw_redirect_headers = array_merge(self::$raw_redirect_headers, $cookies);
[241] Fix | Delete
}
[242] Fix | Delete
[243] Fix | Delete
return $response;
[244] Fix | Delete
}
[245] Fix | Delete
}
[246] Fix | Delete
[247] Fix | Delete
It is recommended that you Edit text format, this type of Fix handles quite a lot in one request
Function