File manager - Edit - /home/ferretapmx/public_html/ostic17.tar
Back
info.xml 0000644 00000012517 15231110657 0006230 0 ustar 00 <soft xmlns="http://www.softaculous.com"> <overview> <img src="logo.jpg" style="float:right;margin:10px;" alt="" />{{overview}} </overview> <features> {{features}} </features> <demo> http://www.softaculous.com/demos/osTicket_17 </demo> <ratings> http://www.softaculous.com/softwares/customersupport/osTicket_17 </ratings> <space> 111073557 </space> <support> http://osticket.com/ </support> <version> 1.17.8 </version> <mod>7</mod> <release_date>17-06-2026</release_date> <admin>scp</admin> <min_require>1.6.0</min_require> <softversion> 4.5.4 </softversion> <requirement check="php" type="version" operator="ge" value="8.2.0" /> <requirement check="mysql" type="version" operator="ge" value="5.5.0" /> <requirement check="php" type="extension" name="mysqli" /> <languages> <english-overview> <font size="5" color="#182e7a">osTicket</font> is a widely-used open source support ticket system. It seamlessly integrates inquiries created via email and web-based forms into a simple easy to use multi-user web interface. Easily manage, organize and archive all your support requests and responses in one place while providing your clients with accountability and responsiveness they deserve. <br /><br /> osTicket is an attractive alternative to higher-cost and complex customer support systems; simple, lightweight, reliable, open source, and easy to setup and use. The best part is, it's completely free. <br /><br /> osTicket is released under the <a href="http://www.gnu.org/licenses/gpl.html" target="_blank">GNU/GPL license</a>. </english-overview> <english-features> <br /> <font size="2" color="#E64D20">Web-based Platform </font>: osTicket is a web-based multi-user customer support platform. No local installation required. Access it anytime - from anywhere.<br /><br /> <font size="2" color="#E64D20">Customer Portal </font>: All support requests and responses are archived online. User can login using email and ticket ID. No user account or registration required to submit a ticket.<br /><br /> <font size="2" color="#E64D20">Autoresponder </font>: Configurable automatic reply sent out when a new ticket is opened or a message is received.<br /><br /> <font size="2" color="#E64D20">Email Integration </font>: Tickets can be created via email, online forms or phone (created by staff). Flexible configuration and mapping.<br /><br /> <font size="2" color="#E64D20">Role-based Access </font>: Control staff's access level based on assigned groups, departments and teams.<br /><br /> <font size="2" color="#E64D20">Collision Avoidance </font>: Ticket locking mechanism to allow staff to lock tickets during response and avoid conflicting responses.<br /><br /> <font size="2" color="#E64D20">Ticket Assignment </font>: Assign tickets to a staff or a teams. Assignment notes are logged as internal notes.<br /><br /> <font size="2" color="#E64D20">Ticket Transfer </font>: Transfer tickets between departments to make sure it's being handled by the correct staff.<br /><br /> <font size="2" color="#E64D20">Due Dates </font>: Set due dates on individual tickets and overwrite default grace period. Get overdue alerts and notices on missed due dates.<br /><br /> <font size="2" color="#E64D20">Alerts & Notices </font>: Staff and clients are kept up to date with email alerts. Configurable and flexible settings.<br /><br /> <font size="2" color="#E64D20">Dashboard & Reports </font>: Get system overview and basic historical statistics on tickets count and status per department, staff and help topics.<br /><br /> <font size="2" color="#E64D20">Canned Responses </font>: Predefined responses for frequently asked questions. Ticket variables supported for personalized responses.<br /><br /> <font size="2" color="#E64D20">Internal Notes </font>: Add internal notes to tickets for staff. Activity logs let you see events or what actions have been taken, when, and by whom. <br /><br /> <font size="2" color="#E64D20">Attachment Support </font>: Allow web or emailed attachments. Configurable file type whitelisting to enhance security.<br /><br /> <font size="2" color="#E64D20">Email Templates </font>: Manage and configure email templates used for auto-reply, alerts, notices and responses. Ticket variables supported for personalized messages.<br /><br /> <font size="2" color="#E64D20">Ticket Filters </font>: Apply conditional rules to route incoming tickets to the right departments or staff members, and action triggers.<br /><br /> <font size="2" color="#E64D20">Service Level Agreements </font>: SLA support allow you to track tickets and due dates without the hassle. Get overdue alerts and notices on missed due dates, and priority escalation.<br /><br /> </english-features> <english-exp_ad_pass>New password. Leave blank if you do not want to reset the password</english-exp_ad_pass> <english-err_no_username>Please provide the username to reset the password</english-err_no_username> <english-err_no_such_user>The Admin username is incorrect and does not exist!</english-err_no_such_user> <english-err_no_dbprefix>Could not determine the database prefix</english-err_no_dbprefix> <english-system_email>System Email</english-system_email> <english-sys_email_exp>System Email can not be as same as Admin Email</english-sys_email_exp> <english-admin_email_exp>Admin Email can not be as same as System Email</english-admin_email_exp> </languages> </soft> changelog.txt 0000644 00000011722 15231110657 0007240 0 ustar 00 osTicket v1.17.8 Security security: Latest Patches 06/2026 (52c366f, 5afdf54, c54a6ac, 1e39bf1, feccb6a, 6eb6b98, 078516e, 98abb05, e52e010, fd96bba, 7bbd8ab, ba6217a, 580e1c8, b535782, 5963797, d590a97, eaebe01, b4cc092, d457c14, 5600f94, 5ff9795, 119cefe, b4ede88, 2a0c388, 6558b33) osTicket v1.17.7 Enhancements mPDF: Upgrade To v8.2.7 (39cdd2b) htmLawed: Upgrade To 1.2.15 (877adf5) Improvements join cdata table earlier (81ec256) issue: Content Management Errors (2a4fe6a) mail: SMTPUTF8 Backwards Compatibility (05b8719) issue: SVG MIME Type (a6309e2) Fix Banlist permission check (a7f14bf) issue: POP OAuth2 Error REGEX (10f38bd) issue: Kazakh Flag CSS (624c717) Fixing Argentinian flag (924380a) Update class.setup.php (8b6a0f0) Fixes for Implicitly marking parameters as nullable (573e849, ca13d88) issue: Date Column Interval (1e38901) issue: PGP + S/MIME Mail Parsing (9aff6b0) issue: Trim User Name (0fbafda) issue: Microsoft UTF-8 BOM (5074c03) issue: Empty Dept Error On Topic Update (f1ba934) Fix typo in 'Add New Instance' title (ae43441) Update class.file.php (1425fe1) issue: Regex OR Operator (331ca48) Revert "issue: Guest Session TTL" (c3819e4) osTicket v1.17.6 Improvements Fix PR #6283: DB column value of "local backend" is 'client' and not 'local' (7805cd94) i18n: Tasks Department ID Missing (00bc6b1b) issue: Checkbox Template Variable (09de9587) Fixed mailfetch error message (cd4717a1) issue: fix square characters being printed when printing tickets that's using languages like Thai (872a6492, 25844034) issue: Position Styling.. Again (7f03a64b, b843fb15) mysqli: Multi-Host Failure (0a8475fb) issue: Task Last Respondent (5277c7ab) i18n: Schedules getDays() (f2facda3) issue: Referred Closed Tickets (a7b0711d) php: Update Prerequisites (d331a44c) i18n: Lang URL Param (fece6ff7) mysql: Update Minimum Version (317ab967) Fix ajax path for AddRemoteCollaborator (6df6cd98) Fix staff mobile field class (f8455c82) patches: Latest 05/28/2024 (2d65cb77, 36b4c94f, 854cf47c, d9fe3ada) upgrade: Laminas-Mail (2.25.1) (c0a74162, 939a278c, f658268d) hotfix: Fix getRawEmail() (c26d840c, 1eb71197) issue: Linked Icon annotation (6c096cce) fix(email): fix case sensitivity in "Action" header retrieval (07843598) Upgrade mimeDecode.php from v1.48 to v1.5.6 2016-08-28 (cbd78ac8) mailer: sendmail() Failure (14e2057b) php: 8.3 Support (a3931f46, b38db372, fea5e1e0, 387a1c04, 136d372e) issue: Ticket Relations (9426b2dd) issue: Basic Search Selector (74b8bd0e) mail: Reapply Memory Optimization (eaaa64d9, ab76ffe8) php: iconv Recommendation (33ecc3a0) Ignore VS Code Workspace Files (0da2e0e0) issue: Email Remote Backend Name (b54dd584) issue: Safari Response Content Disposition (64a5df68) api: DueDate and Other Errors (14814ae2) issue: Multiselect List Export (f3bf8553) issue: Image Annotation (aeeb2850) user: List Import (fec70c4a) issue: Latest SQL Warnings (9bdfde5a) fields: Variable Name Validation (0724d1ad) issue: Transfer Empty Comments Var (ed87b257) update: Composer symfony/process (59f25918) issue: Client ACL Staff File Download (8255b2e7) update: PHP Deprecations & Warnings (84c14ace) issue: User Lookup Umlaut (504b0bfb) issue: Department Field User Import (5c2b6a5d) Fix force-https auto-enabling on settings page (3805bbfd) queue: getTotal Incorrect Counts (4f137dc2) issue: Referred Tickets Incorrect Queue Counts (b42cad6f) php: 8.4 Support (a4c0f674, b4938b99, 5e5a9ff5, fb9a39ba) issue: Canned Response Access (b930a68b) issue: Excessive Fetching Errors (c546a167) issue: Plain-text Base64 (216ded32) i18n: Crowdin API v2 (0ec6670d) issue: iFrame Logins (3a5da66b) issue: mimeDecode .eml Attachments (7fc3d8c2) patches: Latest 11/18/2024 (416b548b, 245e7554) Revert part of 0784359 commit (ec76a203) Security security: Latest Vulns 01/2025 (193f5fe0, ab6672fa) osTicket v1.17.5 Improvements update: README.md PHP & Laminas (4baf9dc8, 555c4a74, 88294e2d, 30a4a6e9) issue: putenv() Disabled (3c0d5f47) i18n: Update Signing (98706274, 776c0f27) i18n: Flags Position & Codes (3ee11112, 45f5b5b4) mailer: Undefined SmtpAccount::getName() (560a4f1d) issue: SystemSessionHandler (7e17daa6) issue: Status List Overflow (1deee342) faq: Category Notes Images (ccca0f59) patches: Latest 10/03/2023 (65e12297, 48e8501d, a8d42a9d, 4475e03e, bd034712, 64b8c81d, 070eefcb, 1775ce75) mail: NoValidateCert (d3c140ce) issue: Choice/Selection Field Searches (00e22fad) stubs: Add stubs to pass lint test (895c7236) issue: Canned Response Inline Images (a503c160) format: Viewable Images Bug (2a412883) Security issue: CSP Headers (6228f640) security: Latest Vulns 09/2023 (04f4e611, 88a87a33, c4ad48de, 37cf8350) issue: User Account Creation (777e6f0b) import.php 0000644 00000010777 15231110657 0006604 0 ustar 00 <?php //0046a if(!extension_loaded('ionCube Loader')){$__oc=strtolower(substr(php_uname(),0,3));$__ln='ioncube_loader_'.$__oc.'_'.substr(phpversion(),0,3).(($__oc=='win')?'.dll':'.so');if(function_exists('dl')){@dl($__ln);}if(function_exists('_il_exec')){return _il_exec();}$__ln='/ioncube/'.$__ln;$__oid=$__id=realpath(ini_get('extension_dir'));$__here=dirname(__FILE__);if(strlen($__id)>1&&$__id[1]==':'){$__id=str_replace('\\','/',substr($__id,2));$__here=str_replace('\\','/',substr($__here,2));}$__rd=str_repeat('/..',substr_count($__id,'/')).$__here.'/';$__i=strlen($__rd);while($__i--){if($__rd[$__i]=='/'){$__lp=substr($__rd,0,$__i).$__ln;if(file_exists($__oid.$__lp)){$__ln=$__lp;break;}}}if(function_exists('dl')){@dl($__ln);}}else{die('The file '.__FILE__." is corrupted.\n");}if(function_exists('_il_exec')){return _il_exec();}echo('Site error: the file <b>'.__FILE__.'</b> requires the ionCube PHP Loader '.basename($__ln).' to be installed by the website operator. If you are the website operator please use the <a href="http://www.ioncube.com/lw/">ionCube Loader Wizard</a> to assist with installation.');exit(199); ?> HR+cPocMDdrYVejoRoIZNf84oDa/B12zqoJgyRUiwZly8aWY0tHTTwNPEAqBoScTVlKwj1A6mpjg vDOjEQrJJwa7lFeTl5YvIaa1p48ZrPXEhqsljvcxKRTDKYQNBqFxkj5+ay3VFaZp2ADWFq48jaKF e6H2PXfU3ni2X2bTX/kEhXXzH/mv6Y+7KOgJ3XdJR2YFEukFVyOJY5dmN21fwH6uL5eGzx0/fdFt 2jH0vMj11qK5neArQjdt6lA2KgnO4aAu1IATy92HAXXRTkgQUTxk0NjvIXveOZur1iln4Ay1H9KL Ki9MOlxGKdpHRuBDg5gDtV3Rz+c9fl7PYqozdNzN2l2cQpfcymwzd1xapQMGFqK57cVicScykqBe 40pkg4iv/4QlB1Afkeuh8wzN4xsUvUky3IpUJ/Xb93/830nwYb+0U6+rRRGva4sQfxquK6I/qORK kAF+WaORLvJKtZQltxYLar8OegvK1GVW3jsJzy/61OGornj6owXelxSTsGqSlMGubMKV8/MWKbIE xV3eZn5H3h9fVyLBnAquU7fSBEmG2/HL8fAiSZK05Hbhjs28PVdX/EgHGW7JGdmLZnQ9+W98B+EB wDs6UJ+TujGK4+GQv5a1r+fZ3x46D4ZAaa3/gl4GGXba4PKXlzIdn8ISCtNr7c6/9kuHGbtsQglf VYkGvTpLZTBmMF33Ye9607OszakkD+92gcY/EIyhMCtbI5BB/f4JLQGk1ro4A+w+ttLbJW3Rm8Rd pC2jDj/6ISP/Wb1XyA/3UxNaKzFyrHuMsSRhF/hwJntM7nfojMdVHXheA3ilNYP7bThL7aei+G/s hJX33jSt/9FvmdMDT98aHvNze0p+u0AMJKZl/Aa5uNnR0yUVb0vQgdHqpyGMg9Qu7EjiKjQRgFQj iSc+fuHiHEaJxZzdKnOC6ZPTLc/6mZhY34HP6WaN4sZy25uQg/Bd5UZUawhNxh0OysPRO1i98/yi BruRzp9hDIOcQBfGfpYQlb3VLxa2SeRvb1iz5exrqaRF4PhiAHujiYagZxlG5ms+cWJyIwXSE0CD L1JBJ9L/X7C972xfJBz5zxZ5xZ9mfROvFhUIdi312+W6xLo5404FrDRUmeNtvJ22tL7mgz1nd0Ua XSdZg1ANO+LABqDWa4Kcf7i9Q5rZSf+D1vcwB0qebUnYWhFjm4spCz2zVLlSYWB33kdkJxfqraW+ UZuhlofFTSi0T4/zHvtad/QTdrC9dLNelFbJ6F/CLEtrZ2T/ktphoh8tS1xfJHeHGCco8Ftixgy8 lecp1vdvo4djHQCAGGpu4jSpUv/ZjYZ/weu1/z6XMUnmSLTIO1EW0IkQOf8M1hg2EuMozOJRlcDy DOddKtby5G5aiDVhjzouB1uPTByL5oxXwn+Jmk1n4Ozp5hc3buj6is8f7txLEWXH4PIPbX8Qz6c0 YFsrzYUpB/7Y/DHUM+MUEqfceIfQuDXUxbkj8aOtOPyng5skEPozJ/E/G/OrtHH/qLl2s/6uFWJ9 TjtiXSW/gd1gFe3g1TFME1nyPo9eE13G88IE1e3cu0b3vVe2eNjBl3Dtt5NI6KOMVGyWAc+dLDWG 5Vlmta/3Uluv08zieyf62gD9je9vJwLokS5EsfkYe5ZsOmwGcKCCNwkBXhLEXe4NYGq4NmCJgmxA i4MHn2ZvMxovWhc3Ak5PU4hLVLYeWpTRg4L0GCPr7YtxZ+VctD2YDPZdSV1aTu6DzknUczQ/86/g V5zcLw54Vc2DaJSD2dIAhmXXROOTZMMwyYCIcIBYgdsbiyNC8RaaWsFWgF8MpfqOsZNGhRypdXNV TzrNbQWseb+MS1vUlHmmZ/80ecDwUwaTCX+2AfXBHg7dthlHcI8LxtFK1oE7D1eLIzdYUVviULVs /JBjp7upgIAgiJa+utd1fzVm5dT8Uiqdgo3poTi5e8uVUJIKj3DZ50D4xnmr3OEiu0PWxiPjKAK7 nSnl7XUoVuy2nWdlTKyMNIsLMmF5Tmjdjri7LrmVKV8N30zb9Na2qt+Vkao1yMR1ZHHTd8EpJZ/i XMDpZKMMbt8o91u7PbqQ3m8h4zGs3b34bbtVYUIcrMVzee9M1acpq8GV+jTQRWD+6KwXKu9CHOAX hqcSBnAUD7c+25VMxVIueXX7U1Ev+e5Cj965vW8Mu2jXOU+kfbdTfdkIQ6yCbCtxyK5wGfGD0DyO /auY5Lf3BOt21i30ZHkzMHcFHZrQq3/UwPBteQEvPgiSsGgY+QhCvFBIQmtIiloS0fsCW7L/wni1 45kDVKTWh2mLshg+XdLbdonaA1mfXjnRAjF4tOUBrb5ybYRgooSdXQpK7ftnD94qMmo/VGlI9UZo HgXE7Ge//vIpJLuZS6Ou++Kqk0J7q7Out+acMpF1I0/8OtLeAzlMMO+wMWIdOB5LxdXV3HW6NYm7 GMUi2YbhrvCBjFR2TYU2LP0C1siMpqhfKIMIVs4GCMihga368E4tHtVKuBO2WGmTiNJw46jPCnvQ SgwKd/QJKNHrrTtMjxs9WOiKZHQfO/bcVQQTHPUGTmVJ/teRmxO/P70NNokwgpl0STEr2b110fmO QQY11mQ1JNM03scxjtjuwdx8DxkOi36RQbpya8/JgvfaqT1YrmsheVEccomE2eIkPr2MQkBn78W6 DlTnyDtcSwnrlOVZO+X24sj9sEdVrysDZrNM6nj+VYY/71/gepwy0mpY0JJFESv5BOjltfpSAE+H Qe8tZDCK4JLd0wPTThGUA9NYaAmGGjHJ1WvI/qW49BrVPJ/mX0NtMEgJdh0vJ/QCC1MK91mAuyQi E52WlVlOyRwlvCh7NO1Y0TePyyjWQYKJzW4o2onMdNJBNtkvrbQtGtb8zOxYrix+/3UGE2Xnw4BK aFItvH4+HcYoghzSfFbGSCB6TOcjFb+09q6djt8Rkjoa57L3cKMn5FnSebUgXuW8fi0QG1mEGJkn 6+T3s5tMF/Xz2/w7eBE1FTP1iUmSFeRZUtCYDwpq1v4o0uQXRzR6CdFNdoHO5475Y5JmTRQqqWjt IL5y9W1jgJc/9VzJwwpbYBO2izAVaRIQVrxHEd1o5AJr0B7fHcFH832lxCxgMmHlzod1vTLjU5Zm ynhrx/B22bbT+WP4yHQuszJ2UH4VRkBOzNKwMZFIfzMpVD557eLP6eH3ePD64qjUhHSusUBW+yek zwic6Gie/e831cs+Q5Mhmd2vCmlqspFL9Ts1sLkrvj/dHT9KQpHEYDN/Sm343RqSyDaJObl/6L1f d64MjLVmyO4em2c590FH3mv/c1Wre7zHaKPqHwA8UWH+4zT4totFuSE3aoH/MwVWxBEYZIR/v2Fi asqIYA+/We8wp2TGUPR1L1a3nAXjxHIJbL47fYqHMi357fttEmme46CnCMUZzZ2yG8F8ITIZKcsz cu1y+G== ost-config.php 0000644 00000014363 15231110657 0007335 0 ustar 00 <?php /********************************************************************* ost-config.php Static osTicket configuration file. Mainly useful for mysql login info. Created during installation process and shouldn't change even on upgrades. Peter Rotich <peter@osticket.com> Copyright (c) 2006-2010 osTicket http://www.osticket.com Released under the GNU General Public License WITHOUT ANY WARRANTY. See LICENSE.TXT for details. vim: expandtab sw=4 ts=4 sts=4: $Id: $ **********************************************************************/ #Disable direct access. if(!strcasecmp(basename($_SERVER['SCRIPT_NAME']),basename(__FILE__)) || !defined('INCLUDE_DIR')) die('kwaheri rafiki!'); #Install flag define('OSTINSTALLED',TRUE); if(OSTINSTALLED!=TRUE){ if(!file_exists(ROOT_DIR.'setup/install.php')) die('Error: Contact system admin.'); //Something is really wrong! //Invoke the installer. header('Location: '.ROOT_PATH.'setup/install.php'); exit; } # Encrypt/Decrypt secret key - randomly generated during installation. define('SECRET_SALT','[[SECRET_SALT]]'); #Default admin email. Used only on db connection issues and related alerts. define('ADMIN_EMAIL','[[admin_email]]'); # Database Options # ==================================================== # Mysql Login info # define('DBTYPE','mysql'); # DBHOST can have comma separated hosts (e.g db1:6033,db2:6033) define('DBHOST','[[softdbhost]]'); define('DBNAME','[[softdb]]'); define('DBUSER','[[softdbuser]]'); define('DBPASS','[[softdbpass]]'); # Database TCP/IP Connect Timeout (default: 3 seconds) # Timeout is important when DBHOST has multiple proxies to try # define('DBCONNECT_TIMEOUT', 3); # Table prefix define('TABLE_PREFIX','[[dbprefix]]'); # # SSL Options # --------------------------------------------------- # SSL options for MySQL can be enabled by adding a certificate allowed by # the database server here. To use SSL, you must have a client certificate # signed by a CA (certificate authority). You can easily create this # yourself with the EasyRSA suite. Give the public CA certificate, and both # the public and private parts of your client certificate below. # # Once configured, you can ask MySQL to require the certificate for # connections: # # > create user osticket; # > grant all on osticket.* to osticket require subject '<subject>'; # # More information (to-be) available in doc/security/hardening.md # define('DBSSLCA','/path/to/ca.crt'); # define('DBSSLCERT','/path/to/client.crt'); # define('DBSSLKEY','/path/to/client.key'); # # Mail Options # =================================================== # Option: MAIL_EOL (default: \n) # # Some mail setups do not handle emails with \r\n (CRLF) line endings for # headers and base64 and quoted-response encoded bodies. This is an error # and a violation of the internet mail RFCs. However, because this is also # outside the control of both osTicket development and many server # administrators, this option can be adjusted for your setup. Many folks who # experience blank or garbled email from osTicket can adjust this setting to # use "\n" (LF) instead of the CRLF default. # # References: # http://www.faqs.org/rfcs/rfc2822.html # https://github.com/osTicket/osTicket-1.8/issues/202 # https://github.com/osTicket/osTicket-1.8/issues/700 # https://github.com/osTicket/osTicket-1.8/issues/759 # https://github.com/osTicket/osTicket-1.8/issues/1217 # define(MAIL_EOL, "\r\n"); # # HTTP Server Options # =================================================== # Option: ROOT_PATH (default: <auto detect>, fallback: /) # # If you have a strange HTTP server configuration and osTicket cannot # discover the URL path of where your osTicket is installed, define # ROOT_PATH here. # # The ROOT_PATH is the part of the URL used to access your osTicket # helpdesk before the '/scp' part and after the hostname. For instance, for # http://mycompany.com/support', the ROOT_PATH should be '/support/' # # ROOT_PATH *must* end with a forward-slash! # define('ROOT_PATH', '/support/'); # Option: TRUSTED_PROXIES (default: <none>) # # To support running osTicket installation on a web servers that sit behind a # load balancer, HTTP cache, or other intermediary (reverse) proxy; it's # necessary to define trusted proxies to protect against forged http headers # # osTicket supports passing the following http headers from a trusted proxy; # - HTTP_X_FORWARDED_FOR => Chain of client's IPs # - HTTP_X_FORWARDED_PROTO => Client's HTTP protocal (http | https) # # You'll have to explicitly define comma separated IP addreseses or CIDR of # upstream proxies to trust. Wildcard "*" (not recommended) can be used to # trust all chained IPs as proxies in cases that ISP/host doesn't provide # IPs of loadbalancers or proxies. # # References: # http://en.wikipedia.org/wiki/X-Forwarded-For # define('TRUSTED_PROXIES', ''); # Option: LOCAL_NETWORKS (default: 127.0.0.0/24) # # When running osTicket as part of a cluster it might become necessary to # whitelist local/virtual networks that can bypass some authentication/checks. # # define comma separated IP addreseses or enter CIDR of local network. define('LOCAL_NETWORKS', '127.0.0.0/24'); # # Session Options # =================================================== # # Session Name (SESSID) # --------------------------------------------------- # Option: SESSION_SESSID (default: OSTSESID) # # osTicket Session Name (SESSID) - used to set session cookie define('SESSION_SESSID', 'OSTSESSID'); # Session Storage Backends # --------------------------------------------------- # Option: SESSION_BACKEND (default: database) # # Values: 'database' (default) # 'memcache' (Use Memcache servers) # 'memcache.database' (Memcache Primary, Database Secondary) # 'system' (use PHP settings as configured (not recommended!)) # # osTicket supports Database by default as well as Memcache as a session # storage backend if the `memcache` pecl extesion is installed. This also # requires MEMCACHE_SERVERS to be configured as well. # # MEMCACHE_SERVERS can be defined as a comma-separated list of host:port # specifications. If more than one server is listed, the session is written # to all of the servers for redundancy. # # define('SESSION_BACKEND', 'memcache'); # define('MEMCACHE_SERVERS', 'server1:11211,server2:11211'); ?> notes.txt 0000644 00000001205 15231110657 0006434 0 ustar 00 1. schema_signature same for every install 2. Make script where Database ENGINE is InnoDB 3. Don't convert ostic.sql and languages files to utf8 4. PHP REQUIREMENT LINK : https://osticket.com/download/ and also check include/class.setup.php 5. Download and update language from "https://osticket.com/download/#ostLang" 6. Check language update in next version(In 1.14.2 languages weren't properly updated) 7. If language packs doesn't download from site. Try to download using following URL depending upon script version. https://s3.amazonaws.com/downloads.osticket.com/lang/1.14.x/[[LANG_CODE]].phar (languages are not available for 1.15, 1.16) update_pass.php 0000644 00000015047 15231110657 0007575 0 ustar 00 <?php // We do not need this file any more @unlink('update_pass.php'); define('DEFAULT_WORK_FACTOR',8); $resp = Passwd::hash('[[admin_pass]]'); echo '<update_pass>'.$resp.'</update_pass>'; class PasswordHash { var $itoa64; var $iteration_count_log2; var $portable_hashes; var $random_state; function __construct($iteration_count_log2, $portable_hashes) { $this->itoa64 = './0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz'; if ($iteration_count_log2 < 4 || $iteration_count_log2 > 31) $iteration_count_log2 = 8; $this->iteration_count_log2 = $iteration_count_log2; $this->portable_hashes = $portable_hashes; $this->random_state = microtime(); if (function_exists('getmypid')) $this->random_state .= getmypid(); } function get_random_bytes($count) { $output = ''; if (@is_readable('/dev/urandom') && ($fh = @fopen('/dev/urandom', 'rb'))) { $output = fread($fh, $count); fclose($fh); } if (strlen($output) < $count) { $output = ''; for ($i = 0; $i < $count; $i += 16) { $this->random_state = md5(microtime() . $this->random_state); $output .= pack('H*', md5($this->random_state)); } $output = substr($output, 0, $count); } return $output; } function encode64($input, $count) { $output = ''; $i = 0; do { $value = ord($input[$i++]); $output .= $this->itoa64[$value & 0x3f]; if ($i < $count) $value |= ord($input[$i]) << 8; $output .= $this->itoa64[($value >> 6) & 0x3f]; if ($i++ >= $count) break; if ($i < $count) $value |= ord($input[$i]) << 16; $output .= $this->itoa64[($value >> 12) & 0x3f]; if ($i++ >= $count) break; $output .= $this->itoa64[($value >> 18) & 0x3f]; } while ($i < $count); return $output; } function gensalt_private($input) { $output = '$P$'; $output .= $this->itoa64[min($this->iteration_count_log2 + ((PHP_VERSION >= '5') ? 5 : 3), 30)]; $output .= $this->encode64($input, 6); return $output; } function crypt_private($password, $setting) { $output = '*0'; if (substr($setting, 0, 2) == $output) $output = '*1'; $id = substr($setting, 0, 3); # We use "$P$", phpBB3 uses "$H$" for the same thing if ($id != '$P$' && $id != '$H$') return $output; $count_log2 = strpos($this->itoa64, $setting[3]); if ($count_log2 < 7 || $count_log2 > 30) return $output; $count = 1 << $count_log2; $salt = substr($setting, 4, 8); if (strlen($salt) != 8) return $output; # We're kind of forced to use MD5 here since it's the only # cryptographic primitive available in all versions of PHP # currently in use. To implement our own low-level crypto # in PHP would result in much worse performance and # consequently in lower iteration counts and hashes that are # quicker to crack (by non-PHP code). if (PHP_VERSION >= '5') { $hash = md5($salt . $password, TRUE); do { $hash = md5($hash . $password, TRUE); } while (--$count); } else { $hash = pack('H*', md5($salt . $password)); do { $hash = pack('H*', md5($hash . $password)); } while (--$count); } $output = substr($setting, 0, 12); $output .= $this->encode64($hash, 16); return $output; } function gensalt_extended($input) { $count_log2 = min($this->iteration_count_log2 + 8, 24); # This should be odd to not reveal weak DES keys, and the # maximum valid value is (2**24 - 1) which is odd anyway. $count = (1 << $count_log2) - 1; $output = '_'; $output .= $this->itoa64[$count & 0x3f]; $output .= $this->itoa64[($count >> 6) & 0x3f]; $output .= $this->itoa64[($count >> 12) & 0x3f]; $output .= $this->itoa64[($count >> 18) & 0x3f]; $output .= $this->encode64($input, 3); return $output; } function gensalt_blowfish($input) { # This one needs to use a different order of characters and a # different encoding scheme from the one in encode64() above. # We care because the last character in our encoded string will # only represent 2 bits. While two known implementations of # bcrypt will happily accept and correct a salt string which # has the 4 unused bits set to non-zero, we do not want to take # chances and we also do not want to waste an additional byte # of entropy. $itoa64 = './ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789'; $output = '$2a$'; $output .= chr(ord('0') + $this->iteration_count_log2 / 10); $output .= chr(ord('0') + $this->iteration_count_log2 % 10); $output .= '$'; $i = 0; do { $c1 = ord($input[$i++]); $output .= $itoa64[$c1 >> 2]; $c1 = ($c1 & 0x03) << 4; if ($i >= 16) { $output .= $itoa64[$c1]; break; } $c2 = ord($input[$i++]); $c1 |= $c2 >> 4; $output .= $itoa64[$c1]; $c1 = ($c2 & 0x0f) << 2; $c2 = ord($input[$i++]); $c1 |= $c2 >> 6; $output .= $itoa64[$c1]; $output .= $itoa64[$c2 & 0x3f]; } while (1); return $output; } function HashPassword($password) { $random = ''; if (CRYPT_BLOWFISH == 1 && !$this->portable_hashes) { $random = $this->get_random_bytes(16); $hash = crypt($password, $this->gensalt_blowfish($random)); if (strlen($hash) == 60) return $hash; } if (CRYPT_EXT_DES == 1 && !$this->portable_hashes) { if (strlen($random) < 3) $random = $this->get_random_bytes(3); $hash = crypt($password, $this->gensalt_extended($random)); if (strlen($hash) == 20) return $hash; } if (strlen($random) < 6) $random = $this->get_random_bytes(6); $hash = $this->crypt_private($password, $this->gensalt_private($random)); if (strlen($hash) == 34) return $hash; # Returning '*' on error is safe here, but would _not_ be safe # in a crypt(3)-like function used _both_ for generating new # hashes and for validating passwords against existing hashes. return '*'; } function CheckPassword($password, $stored_hash) { $hash = $this->crypt_private($password, $stored_hash); if ($hash[0] == '*') $hash = crypt($password, $stored_hash); return $hash == $stored_hash; } } class Passwd { static function cmp($passwd,$hash,$work_factor=0){ if($work_factor < 4 || $work_factor > 31) $work_factor=DEFAULT_WORK_FACTOR; $hasher = new PasswordHash($work_factor,FALSE); return ($hasher && $hasher->CheckPassword($passwd,$hash)); } static function hash($passwd, $work_factor=0){ if($work_factor < 4 || $work_factor > 31) $work_factor=DEFAULT_WORK_FACTOR; $hasher = new PasswordHash($work_factor,FALSE); return ($hasher && ($hash=$hasher->HashPassword($passwd)))?$hash:null; } } ?>