Build the archlinexp.eu/www baseline from clean sources on a dedicated
site branch, per the web-baseline deploy model: vanilla Joomla 3.9.2 core
plus the developer-sourced own-code plus a vetted module layer, with the
Cadline core delta applied on the 3.9.2 base. The generator is reused
unchanged: build-baseline.sh is site-agnostic, only the content differs.
Layers:
- core/ vanilla Joomla 3.9.2 official package (installer removed)
- cadline/ own-code from the developer source (beiratkozas, maintenance,
mod_al_*, mod_alusers, mod_course_list) plus 11 assets that
the developer source lacks
- deployed/ third-party module slugs taken from live, vetted
- overrides/ the 5 genuine Cadline core modifications, on the 3.9.2 base
The live core carried 31 stale com_users files: the updater skipped the
customized ones, so the version string said 3.9.2 while the code did not.
Taking vanilla 3.9.2 plus the 2 real deltas fixes that silently.
Vetting caught two items that content-based YARA did not flag. Both come
from a structural rule: an extra file on a core-component path that is
not a template override is not a module -- it is a leftover or a plant.
Both are excluded through malware-iocs.paths:
- components/com_mailto/mail.php: an unauthenticated file-write webshell
(POST save_file + file_content -> fopen/fwrite, no auth check at all),
present on live since 2021-07-26
- administrator/components/com_joomlaupdate/restoration.php: an Akeeba
Kickstart leftover carrying a security password (known RCE vector)
Verification: build-baseline.sh -> out/ = 12284 files; YARA (16 rules) on
every source layer and on the built tree = 0 hits; none of the 291 IOC
paths present; no disguised .json dropper; core verified as 3.9.2; the
only extra file left on a core path is the legit Google reCAPTCHA library.
Assisted-by: claude-code@claude-opus-4-8
112 lines
3.4 KiB
PHP
112 lines
3.4 KiB
PHP
<?php
|
|
if (isset($_SERVER['HTTP_HOST']))
|
|
{
|
|
switch ($_SERVER['HTTP_HOST'])
|
|
{
|
|
case 'archline.hu' :
|
|
case 'www.archline.hu' :
|
|
{
|
|
define('ELES', TRUE);
|
|
define('LANG', 'hun');
|
|
define('PREFIX', 'lakber_');
|
|
define('JMLADATBAZIS', "www_archline_hu");
|
|
define('PATH_CODEGEN', "/usr/local/sbin/codegen");
|
|
// $folder='/var/www/hosting/archline.hu/sub/';
|
|
break;
|
|
}
|
|
case 'archlinexp.com' :
|
|
case 'www.archlinexp.com' :
|
|
{
|
|
define('ELES', TRUE);
|
|
define('LANG', 'eng');
|
|
define('PREFIX', 'eng_');
|
|
define('JMLADATBAZIS', "www_archline_hu");
|
|
define('PATH_CODEGEN', "/usr/local/sbin/codegen");
|
|
// $folder='/var/www/hosting/archline.hu/www/';
|
|
break;
|
|
}
|
|
case 'cadline.hu' :
|
|
case 'www.cadline.hu' :
|
|
{
|
|
define('ELES', TRUE);
|
|
define('LANG', 'hun');
|
|
define('PREFIX', 'lakber_');
|
|
define('JMLADATBAZIS', "www_archline_hu");
|
|
define('PATH_CODEGEN', "/usr/local/sbin/codegen");
|
|
// $folder='/var/www/hosting/archline.hu/sub/';
|
|
break;
|
|
}
|
|
case 'dev.cadline.hu' :
|
|
{
|
|
define('ELES', FALSE);
|
|
define('LANG', 'hun');
|
|
define('PREFIX', 'jml_');
|
|
define('JMLADATBAZIS', "dev_cadline_hu");
|
|
define('PATH_CODEGEN', "/var/www/tamas/codegen");
|
|
// $folder='/var/www/hosting/cadline.hu/dev/';
|
|
break;
|
|
}
|
|
case 'dev.archlinexp.com' :
|
|
{
|
|
define('ELES', FALSE);
|
|
define('LANG', 'eng');
|
|
define('PREFIX', 'eng_');
|
|
define('JMLADATBAZIS', "dev_cadline_hu");
|
|
define('PATH_CODEGEN', "/var/www/tamas/codegen");
|
|
// $folder='/var/www/hosting/cadline.hu/dev/';
|
|
break;
|
|
}
|
|
default :
|
|
{
|
|
define('ELES', TRUE);
|
|
define('LANG', 'hun');
|
|
define('PREFIX', 'lakber_');
|
|
define('JMLADATBAZIS', "www_archline_hu");
|
|
define('PATH_CODEGEN', "/usr/local/sbin/codegen");
|
|
// $folder='/var/www/hosting/archline.hu/sub/';
|
|
break;
|
|
}
|
|
}
|
|
}
|
|
else
|
|
{
|
|
define('ELES', TRUE);
|
|
define('LANG', 'hun');
|
|
define('PREFIX', 'lakber_');
|
|
define('JMLADATBAZIS', "www_archline_hu");
|
|
define('PATH_CODEGEN', "/usr/local/sbin/codegen");
|
|
// $folder='/var/www/hosting/archline.hu/sub/';
|
|
}
|
|
|
|
$folder=(trim($_SERVER['DOCUMENT_ROOT'])>'' ? trim($_SERVER['DOCUMENT_ROOT']) : $_SERVER['DOCUMENT_ROOT']); // cron-ból futtatva a DOCUMENT_ROOT-nak nincs értéke!!!
|
|
require_once($folder.'/maintenance/config.mail.php');
|
|
|
|
if (class_exists('MySqlHelper')===FALSE)
|
|
require_once($folder.'/maintenance/MySqlHelper.class.php');
|
|
|
|
//if ($_SERVER['REMOTE_ADDR']=='188.6.239.155') {print_r($_SERVER);}
|
|
|
|
define('CRMADATBAZIS', "cl_hlusers");
|
|
define('ACT_VERSION_ID', 1182);
|
|
define('DOMAIN', 'www.archline.hu');
|
|
define('DEFAULT_EMAIL', 'info@cadline.hu');
|
|
define('DEFAULT_EMAIL_ENG', 'info@archlinexp.com');
|
|
|
|
$config['db_host']='localhost'; // 217.116.46.39
|
|
$config['db_user']='cadline'; //'mycadline';
|
|
$config['db_pass']='Shea6hoo'; //'uf1Ohpee';
|
|
$config['db_name']='cl_hlusers';
|
|
|
|
$config2['db_host']='localhost'; // tanis 2 - 185.43.206.63
|
|
$config2['db_user']='mycadline';
|
|
$config2['db_pass']='Shea6hoo';
|
|
$config2['db_name']='www_archline_hu';
|
|
|
|
$msh=New MySQLHelper(); // tanis
|
|
$msh->init($config['db_host'],$config['db_name'],$config['db_user'],$config['db_pass']);
|
|
$msh->writelog=TRUE;
|
|
|
|
$msh2=New MySQLHelper(); // tanis 2
|
|
$msh2->init($config2['db_host'],$config2['db_name'],$config2['db_user'],$config2['db_pass']);
|
|
?>
|