[ Mini Kiebo ]
Server: Windows NT AKFAR_SERVER 10.0 build 26200 (Windows 10) AMD64
Path:
D:
/
xampp
/
htdocs
/
repository_afbs
/
includes
/
[
Home
]
File: security.php
<?php // CSRF Protection function generateCSRFToken() { if (!isset($_SESSION['csrf_token'])) { $_SESSION['csrf_token'] = bin2hex(random_bytes(32)); } return $_SESSION['csrf_token']; } function verifyCSRFToken($token) { if (!isset($_SESSION['csrf_token']) || $token !== $_SESSION['csrf_token']) { die('CSRF token validation failed'); } return true; } // XSS Protection function escape($string) { return htmlspecialchars($string, ENT_QUOTES, 'UTF-8'); } // SQL Injection Protection (already using PDO prepared statements) // Rate Limiting function checkRateLimit($key, $limit = 60, $period = 3600) { $redis = new Redis(); $redis->connect('127.0.0.1', 6379); $current = $redis->get($key); if ($current && $current >= $limit) { return false; } $redis->incr($key); $redis->expire($key, $period); return true; } // File Upload Security function validateFileUpload($file, $allowed_types = ['pdf']) { $errors = []; // Check file size (max 20MB) if ($file['size'] > 20 * 1024 * 1024) { $errors[] = "File terlalu besar. Maksimal 20MB."; } // Check file type $file_ext = strtolower(pathinfo($file['name'], PATHINFO_EXTENSION)); if (!in_array($file_ext, $allowed_types)) { $errors[] = "Tipe file tidak diizinkan. Hanya PDF."; } // Check MIME type $finfo = finfo_open(FILEINFO_MIME_TYPE); $mime = finfo_file($finfo, $file['tmp_name']); finfo_close($finfo); if ($file_ext == 'pdf' && $mime != 'application/pdf') { $errors[] = "File bukan PDF valid."; } return $errors; } // Password Strength Checker function isPasswordStrong($password) { $errors = []; if (strlen($password) < 8) { $errors[] = "Password minimal 8 karakter"; } if (!preg_match('/[A-Z]/', $password)) { $errors[] = "Password harus mengandung huruf besar"; } if (!preg_match('/[a-z]/', $password)) { $errors[] = "Password harus mengandung huruf kecil"; } if (!preg_match('/[0-9]/', $password)) { $errors[] = "Password harus mengandung angka"; } if (!preg_match('/[!@#$%^&*(),.?":{}|<>]/', $password)) { $errors[] = "Password harus mengandung karakter khusus"; } return $errors; } // Session Security function regenerateSession() { session_regenerate_id(true); // Hapus session lama $params = session_get_cookie_params(); setcookie(session_name(), '', time() - 42000, $params["path"], $params["domain"], $params["secure"], $params["httponly"] ); } // Brute Force Protection function logFailedLogin($username) { $file = '../logs/failed_logins.log'; $ip = $_SERVER['REMOTE_ADDR']; $timestamp = date('Y-m-d H:i:s'); $log = "[$timestamp] IP: $ip | Username: $username\n"; file_put_contents($file, $log, FILE_APPEND | LOCK_EX); } function isLoginBlocked($username) { $file = '../logs/failed_logins.log'; if (!file_exists($file)) return false; $ip = $_SERVER['REMOTE_ADDR']; $lines = file($file, FILE_IGNORE_NEW_LINES | FILE_SKIP_EMPTY_LINES); $attempts = 0; $time_limit = strtotime('-15 minutes'); foreach(array_reverse($lines) as $line) { if (preg_match("/\[(.*?)\] IP: $ip \| Username: $username/", $line, $matches)) { $attempt_time = strtotime($matches[1]); if ($attempt_time > $time_limit) { $attempts++; } else { break; } } } return $attempts >= 5; // Block after 5 failed attempts in 15 minutes } ?>