Skip to content
WJunction - Webmaster Forum

Give your AWSTATS with out giving your cPanel logins

Status
Not open for further replies.
Hey guys i found this some where . Might me usefull speacially in market place for people who sell there sites for giving there stats proof () Real one




Create a file named "awpublicstats.php"

Put the following code in that document (Dont forget to edit the code), upload it to your root folder .
then open it "http://www.example.com/awpublicstats.php"

Thats it .
Code:
<?php


$user = 'YOUR CP YOURS NAME';//your cpanel username

$pass = 'PASS WORD';//your cpanel password

$domain = 'EXAMPLE.com';//do not include 'http://' or 'www.'



/*

Domain of the stats you wish to view, e.g. a subdomain like "cvs.mydomain.com".

If left blank, defaults to the "domain" above

Another option is to set the "config" parameter in the url of your browser, e.g.:

http://www.domain.com/awstats.php?config=sub.domain.com

*/

$config_domain = '';



/*

If you don't know what you're doing, set $dynamic_images equal

to TRUE, and don't worry about the $image_directory variable.

Otherwise,

    - Normally, this script will load images by proxy, i.e. awstats.php

      is called for each <img> tag and will send the correct

      image to the browser. This is not the way the web is designed

      to work. So, if you wish to improve performance and lower

      bandwidth, you can:

      1. Set $dynamic_images to FALSE

      2. Create an image directory in your webroot

      3. Copy all of awstats image sub-directories to this new directory

      4. Point the $image_directory variable to your new directory     

    You will get all the benefits of cached, static images.

    In order to get the Awstats images and their directories, you will

    probably need to download an awstats distribution from

    awstats.sourceforge.net. The final layout will probably look like this:



      awstats_imagedir/

                    browser/

                    clock/

                    cpu/

                    flags/

                    mime/

                    os/

                    other/



    Under each of those sub-directories will be dozens of .png files.

*/



$dynamic_images = true;

$image_directory = './awstats_images/';



//lame attempt to combat referrer spam

$spam_words = array('mortgage', 'sex', 'porn', 'cock', 'slut', 'facial', 'loving', 'gay', '.ro');





/***********

NO NEED TO TOUCH ANYTHING BELOW HERE

************/



//retrieves the file, either .pl or .png

function get_file($fileQuery)

{

  global $user, $pass, $domain;

  return file_get_contents("http://$user:$pass@$domain:2082/".$fileQuery);

}



$requesting_image = (strpos($_SERVER['QUERY_STRING'],'.png')===false)?false:true;



if($requesting_image) //it's a .png file...

{

  if(!$dynamic_images && !is_dir($image_directory))

  {

    exit;

  }

  $fileQuery = $_SERVER['QUERY_STRING'];

}

elseif(empty($_SERVER['QUERY_STRING']))//probably first time to access page...

{

    if(empty($config_domain))

    {

        $config_domain = $domain;

    }

  $fileQuery = "awstats.pl?config=$config_domain";

}

else //otherwise, all other accesses

{

  $fileQuery = 'awstats.pl?'.$_SERVER['QUERY_STRING'];

}



$file = get_file($fileQuery);



//check again to see if it was a .png file

//if it's not, replace the links

if(!$requesting_image)

{

  $file = str_replace('awstats.pl', basename($_SERVER['PHP_SELF']), $file);

  

  if($dynamic_images)

  {

    $imgsrc_search = '="/images';

    $imgsrc_replace = '="'.basename($_SERVER['PHP_SELF']).'?images';

  }

  else

  {

    $imgsrc_search = 'src="/images/awstats/';

    $imgsrc_replace = 'src="'.$image_directory;

  }



  $file = str_replace($imgsrc_search, $imgsrc_replace, $file);

  $file = str_replace($spam_words, 'SPAM', $file);

}

else //if it is a png, output appropriate header

{

  header("Content-type: image/png");

}



//output the file

echo $file;

?>


Credit goes to the original writer .

I wish if this is sticked in the market place
 

7 comments

IMPORTANT SECURITY NOTE:

Create a configpass.php file and chmod it to 400 and then call it with an include in the awpublicstats.php(assuming you are running suexec), otherwise you are asking to get owned when someone accesses that file from a shell loaded on the server.

Yes, openbase_dir can be bypassed and you should ALWAYS assume that it can be.
 
IMPORTANT SECURITY NOTE:

Create a configpass.php file and chmod it to 400 and then call it with an include in the awpublicstats.php(assuming you are running suexec), otherwise you are asking to get owned when someone accesses that file from a shell loaded on the server.

Yes, openbase_dir can be bypassed and you should ALWAYS assume that it can be.
I am not sure , well if some reputed knows this i will be happy to change / add on the first post.
 
OR
You can always use DirectAdmin as your Control Panel, which basically creates a symlink to the awstats file within public_html for the actual stats that are located outside of public_html.
 
Status
Not open for further replies.

About the author

W
Active Member · Joined
Born lazy No idea
212
Messages
0
Reactions
16
Points

Advertise on WJunction

Reach 1000's of webmasters, hosts & affiliates. Banner & sponsored-thread slots available.

Contact us
Back
Top Bottom