summaryrefslogtreecommitdiff
path: root/execute.php
blob: 9761c5729680b7c1a3b0dae3e075fb1df5fe20b6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
<?php

/*
 * Looking Glass - An easy to deploy Looking Glass
 * Copyright (C) 2014 Guillaume Mazoyer <gmazoyer@gravitons.in>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 3 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
 * along with this program; if not, write to the Free Software Foundation,
 * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301  USA
 */

require_once 'config.php';
require_once 'router.php';
require_once 'utils.php';

// Obvious spam
if (!isset($_POST['dontlook']) || !empty($_POST['dontlook'])) {
  log_to_file('Spam detected from '.$_SERVER['REMOTE_ADDR'].'.');
  die('Spam detected');
}

if (isset($_POST['query']) && !empty($_POST['query']) &&
    isset($_POST['routers']) && !empty($_POST['routers']) &&
    isset($_POST['parameters']) && !empty($_POST['parameters'])) {
  $query = htmlspecialchars($_POST['query']);
  $hostname = htmlspecialchars($_POST['routers']);
  $parameters = htmlspecialchars($_POST['parameters']);
  $valid_request = false;

  switch ($query) {
    case 'bgp':
      if (match_ipv4($parameters) || match_ipv6($parameters)) {
        $valid_request = true;
      } else {
        $error = 'The parameter is not an IPv4/IPv6 address.';
      }
      break;

    case 'as-path-regex':
      if (match_aspath_regex($parameters)) {
        $valid_request = true;
      } else {
        $error = 'The parameter is not an AS-Path regular expression.';
      }
      break;

    case 'as':
      if (match_as($parameters)) {
        $valid_request = true;
      } else {
        $error = 'The parameter is not an AS number.';
      }
      break;

    case 'ping':
    case 'traceroute':
      if (match_ipv4($parameters) || match_ipv6($parameters) ||
          match_fqdn($parameters)) {
        $valid_request = true;
      } else {
        $error = 'The parameter is not an IPv4/IPv6 address or a FQDN.';
      }
      break;

    default:
      $error = 'Unknown request: '.$query;
      break;
  }

  if (!$valid_request && isset($error)) {
    // Unknown query or invalid parameters
    echo $error;
  } else {
    // Do the processing
    // Router connection, command execution, disconnection
    $router = new Router($hostname, $_SERVER['REMOTE_ADDR']);
    $data = $router->send_command($query, $parameters);

    // Process the output line by line
    $return = '';
    foreach (preg_split("/((\r?\n)|(\r\n?))/", $data) as $line) {
      // Get rid of empty lines
      if (empty($line)) {
        continue;
      }

      $valid = true;

      foreach ($config['filters'] as $filter) {
        // Line has been marked as invalid
        if (!$valid) {
          break;
        }

        // Filter line based on the configuration
        if (preg_match($filter, $line) === 1) {
          $valid = false;
          break;
        }
      }

      // The line is valid, print it
      if ($valid) {
        $return .= $line."\n";
      }
    }

    // Display the result of the command
    echo $return;
  }
}

// End of execute.php