1
0
mirror of https://github.com/vichan-devel/vichan.git synced 2024-11-30 18:24:29 +01:00
vichan/inc/anti-bot.php

200 lines
5.3 KiB
PHP
Raw Permalink Normal View History

2012-04-12 09:20:49 +02:00
<?php
/*
2013-01-20 11:23:46 +01:00
* Copyright (c) 2010-2013 Tinyboard Development Group
2012-04-12 09:20:49 +02:00
*/
defined('TINYBOARD') or exit;
2012-04-12 09:20:49 +02:00
class AntiBot {
2024-09-19 23:09:02 +02:00
public $salt;
public $inputs = [];
public $index = 0;
2013-09-08 09:01:55 +02:00
public static function randomString($length, $uppercase = false, $special_chars = false, $unicode_chars = false) {
2012-04-12 09:20:49 +02:00
$chars = 'abcdefghijklmnopqrstuvwxyz0123456789';
2024-09-19 23:09:02 +02:00
if ($uppercase) {
2012-04-12 09:20:49 +02:00
$chars .= 'ABCDEFGHIJKLMNOPQRSTUVWXYZ';
2024-09-19 23:09:02 +02:00
}
if ($special_chars) {
$chars .= ' ~!@#$%^&*()_+,./;\'[]\\{}|:<>?=-` ';
2024-09-19 23:09:02 +02:00
}
2013-09-08 09:01:55 +02:00
if ($unicode_chars) {
$len = strlen($chars) / 10;
2024-09-19 23:09:02 +02:00
for ($n = 0; $n < $len; $n++) {
2013-09-08 09:01:55 +02:00
$chars .= mb_convert_encoding('&#' . mt_rand(0x2600, 0x26FF) . ';', 'UTF-8', 'HTML-ENTITIES');
2024-09-19 23:09:02 +02:00
}
2013-09-08 09:01:55 +02:00
}
2013-09-08 09:01:55 +02:00
$chars = preg_split('//u', $chars, -1, PREG_SPLIT_NO_EMPTY);
2024-09-19 23:09:02 +02:00
$ch = [];
2012-04-12 09:20:49 +02:00
// fill up $ch until we reach $length
2012-04-12 16:18:19 +02:00
while (count($ch) < $length) {
2012-04-12 09:20:49 +02:00
$n = $length - count($ch);
$keys = array_rand($chars, $n > count($chars) ? count($chars) : $n);
2012-04-12 16:18:19 +02:00
if ($n == 1) {
2012-04-12 09:20:49 +02:00
$ch[] = $chars[$keys];
break;
}
shuffle($keys);
2024-09-19 23:09:02 +02:00
foreach ($keys as $key) {
2012-04-12 09:20:49 +02:00
$ch[] = $chars[$key];
2024-09-19 23:09:02 +02:00
}
2012-04-12 09:20:49 +02:00
}
2012-04-12 09:20:49 +02:00
$chars = $ch;
2012-04-12 09:20:49 +02:00
return implode('', $chars);
}
2012-04-12 09:20:49 +02:00
public static function make_confusing($string) {
2013-09-08 09:01:55 +02:00
$chars = preg_split('//u', $string, -1, PREG_SPLIT_NO_EMPTY);
2012-04-12 16:18:19 +02:00
foreach ($chars as &$c) {
2024-09-19 23:09:02 +02:00
if (mt_rand(0, 3) != 0) {
2012-08-25 15:52:37 +02:00
$c = utf8tohtml($c);
2024-09-19 23:09:02 +02:00
} else {
$c = mb_encode_numericentity($c, [ 0, 0xffff, 0, 0xffff ], 'UTF-8');
}
2012-04-12 09:20:49 +02:00
}
2012-04-12 09:20:49 +02:00
return implode('', $chars);
}
2024-09-19 23:09:02 +02:00
public function __construct(array $salt = []) {
2012-04-12 09:20:49 +02:00
global $config;
2012-04-12 16:18:19 +02:00
if (!empty($salt)) {
2024-09-19 23:09:02 +02:00
// Create a salted hash of the "extra salt"
2012-04-12 09:20:49 +02:00
$this->salt = implode(':', $salt);
} else {
2012-04-12 09:20:49 +02:00
$this->salt = '';
}
2012-04-12 09:20:49 +02:00
shuffle($config['spam']['hidden_input_names']);
2013-09-08 09:01:55 +02:00
$input_count = mt_rand($config['spam']['hidden_inputs_min'], $config['spam']['hidden_inputs_max']);
2012-04-12 09:20:49 +02:00
$hidden_input_names_x = 0;
2012-04-12 16:18:19 +02:00
for ($x = 0; $x < $input_count ; $x++) {
2013-09-08 09:01:55 +02:00
if ($hidden_input_names_x === false || mt_rand(0, 2) == 0) {
2012-04-12 09:20:49 +02:00
// Use an obscure name
2013-09-08 09:01:55 +02:00
$name = $this->randomString(mt_rand(10, 40), false, false, $config['spam']['unicode']);
2012-04-12 09:20:49 +02:00
} else {
// Use a pre-defined confusing name
$name = $config['spam']['hidden_input_names'][$hidden_input_names_x++];
2024-09-19 23:09:02 +02:00
if ($hidden_input_names_x >= count($config['spam']['hidden_input_names'])) {
2012-04-12 09:20:49 +02:00
$hidden_input_names_x = false;
2024-09-19 23:09:02 +02:00
}
2012-04-12 09:20:49 +02:00
}
2013-09-08 09:01:55 +02:00
if (mt_rand(0, 2) == 0) {
2012-04-12 09:20:49 +02:00
// Value must be null
$this->inputs[$name] = '';
2013-09-08 09:01:55 +02:00
} elseif (mt_rand(0, 4) == 0) {
2012-04-12 09:20:49 +02:00
// Numeric value
2013-09-08 09:01:55 +02:00
$this->inputs[$name] = (string)mt_rand(0, 100000);
2012-04-12 09:20:49 +02:00
} else {
// Obscure value
2013-09-08 09:01:55 +02:00
$this->inputs[$name] = $this->randomString(mt_rand(5, 100), true, true, $config['spam']['unicode']);
2012-04-12 09:20:49 +02:00
}
}
}
2013-09-08 09:01:55 +02:00
public static function space() {
2024-09-19 23:09:02 +02:00
if (mt_rand(0, 3) != 0) {
2013-09-08 09:01:55 +02:00
return ' ';
2024-09-19 23:09:02 +02:00
}
2013-09-08 09:01:55 +02:00
return str_repeat(' ', mt_rand(1, 3));
}
2012-04-12 09:20:49 +02:00
public function html($count = false) {
2024-09-19 23:09:02 +02:00
$elements = [
2012-04-12 09:20:49 +02:00
'<input type="hidden" name="%name%" value="%value%">',
'<input type="hidden" value="%value%" name="%name%">',
2013-09-08 09:01:55 +02:00
'<input name="%name%" value="%value%" type="hidden">',
'<input value="%value%" name="%name%" type="hidden">',
2012-04-12 09:20:49 +02:00
'<input style="display:none" type="text" name="%name%" value="%value%">',
'<input style="display:none" type="text" value="%value%" name="%name%">',
'<span style="display:none"><input type="text" name="%name%" value="%value%"></span>',
'<div style="display:none"><input type="text" name="%name%" value="%value%"></div>',
'<div style="display:none"><input type="text" name="%name%" value="%value%"></div>',
'<textarea style="display:none" name="%name%">%value%</textarea>',
'<textarea name="%name%" style="display:none">%value%</textarea>'
2024-09-19 23:09:02 +02:00
];
2012-04-12 09:20:49 +02:00
$html = '';
2012-04-12 16:18:19 +02:00
if ($count === false) {
$count = mt_rand(1, (int)abs(count($this->inputs) / 15) + 1);
}
2012-04-12 16:18:19 +02:00
if ($count === true) {
2024-09-19 23:09:02 +02:00
// All elements
2012-04-12 09:20:49 +02:00
$inputs = array_slice($this->inputs, $this->index);
} else {
$inputs = array_slice($this->inputs, $this->index, $count);
}
$this->index += count($inputs);
2012-04-12 16:18:19 +02:00
foreach ($inputs as $name => $value) {
2012-04-12 09:20:49 +02:00
$element = false;
2012-04-12 16:18:19 +02:00
while (!$element) {
2012-04-12 09:20:49 +02:00
$element = $elements[array_rand($elements)];
2013-09-08 09:01:55 +02:00
$element = str_replace(' ', self::space(), $element);
2024-09-19 23:09:02 +02:00
if (mt_rand(0, 5) == 0) {
2013-09-08 09:01:55 +02:00
$element = str_replace('>', self::space() . '>', $element);
2024-09-19 23:09:02 +02:00
}
2012-04-12 16:18:19 +02:00
if (strpos($element, 'textarea') !== false && $value == '') {
2012-04-12 09:20:49 +02:00
// There have been some issues with mobile web browsers and empty <textarea>'s.
$element = false;
}
}
2012-04-12 09:20:49 +02:00
$element = str_replace('%name%', utf8tohtml($name), $element);
2024-09-19 23:09:02 +02:00
if (mt_rand(0, 2) == 0) {
2012-04-12 09:20:49 +02:00
$value = $this->make_confusing($value);
2024-09-19 23:09:02 +02:00
} else {
2012-04-12 09:20:49 +02:00
$value = utf8tohtml($value);
2024-09-19 23:09:02 +02:00
}
2024-09-19 23:09:02 +02:00
if (strpos($element, 'textarea') === false) {
$value = str_replace('"', '&quot;', $value);
2024-09-19 23:09:02 +02:00
}
2012-04-12 09:20:49 +02:00
$element = str_replace('%value%', $value, $element);
2012-04-12 09:20:49 +02:00
$html .= $element;
}
2012-04-12 09:20:49 +02:00
return $html;
}
public function reset() {
$this->index = 0;
}
2012-04-12 09:20:49 +02:00
public function hash() {
global $config;
2012-04-12 09:20:49 +02:00
// This is the tricky part: create a hash to validate it after
// First, sort the keys in alphabetical order (A-Z)
$inputs = $this->inputs;
ksort($inputs);
2012-04-12 09:20:49 +02:00
$hash = '';
// Iterate through each input
2012-04-12 16:18:19 +02:00
foreach ($inputs as $name => $value) {
2012-04-12 09:20:49 +02:00
$hash .= $name . '=' . $value;
}
// Add a salt to the hash
$hash .= $config['cookies']['salt'];
2012-04-12 09:20:49 +02:00
// Use SHA1 for the hash
return sha1($hash . $this->salt);
}
}