PluginProbe ʕ •ᴥ•ʔ
Anti-Malware Security and Brute-Force Firewall / 4.18.71
Anti-Malware Security and Brute-Force Firewall v4.18.71
4.23.90 trunk 1.2.03.23 1.3.02.15 3.07.06 4.14.47 4.15.16 4.16.17 4.17.28 4.17.29 4.17.44 4.17.57 4.17.58 4.17.68 4.17.69 4.18.52 4.18.62 4.18.63 4.18.69 4.18.71 4.18.74 4.18.76 4.19.44 4.19.50 4.19.68 4.19.69 4.20.59 4.20.72 4.20.92 4.20.93 4.20.94 4.20.95 4.20.96 4.21.74 4.21.83 4.21.84 4.21.85 4.21.86 4.21.87 4.21.88 4.21.89 4.21.90 4.21.91 4.21.92 4.21.93 4.21.94 4.21.95 4.21.96 4.23.56 4.23.57 4.23.67 4.23.68 4.23.69 4.23.71 4.23.73 4.23.77 4.23.81 4.23.83 4.23.85 4.23.87 4.23.88 4.23.89
gotmls / index.php
gotmls Last commit date
images 7 years ago languages 7 years ago safe-load 7 years ago index.php 7 years ago readme.txt 7 years ago
index.php
1858 lines
1 <?php
2 /*
3 Plugin Name: Anti-Malware Security and Brute-Force Firewall
4 Plugin URI: http://gotmls.net/
5 Author: Eli Scheetz
6 Text Domain: gotmls
7 Author URI: http://wordpress.ieonly.com/category/my-plugins/anti-malware/
8 Contributors: scheeeli, gotmls
9 Donate link: https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=QZHD8QHZ2E7PE
10 Description: This Anti-Virus/Anti-Malware plugin searches for Malware and other Virus like threats and vulnerabilities on your server and helps you remove them. It's always growing and changing to adapt to new threats so let me know if it's not working for you.
11 Version: 4.18.71
12 */
13 if (isset($_SERVER["DOCUMENT_ROOT"]) && ($SCRIPT_FILE = str_replace($_SERVER["DOCUMENT_ROOT"], "", isset($_SERVER["SCRIPT_FILENAME"])?$_SERVER["SCRIPT_FILENAME"]:isset($_SERVER["SCRIPT_NAME"])?$_SERVER["SCRIPT_NAME"]:"")) && strlen($SCRIPT_FILE) > strlen("/".basename(__FILE__)) && substr(__FILE__, -1 * strlen($SCRIPT_FILE)) == substr($SCRIPT_FILE, -1 * strlen(__FILE__)))
14 include(dirname(__FILE__)."/safe-load/index.php");
15 else
16 require_once(dirname(__FILE__)."/images/index.php");
17 /* ___
18 * / /\ GOTMLS Main Plugin File
19 * / /:/ @package GOTMLS
20 * /__/::\
21 Copyright \__\/\:\__ © 2012-2019 Eli Scheetz (email: eli@gotmls.net)
22 * \ \:\/\
23 * \__\::/ This program is free software; you can redistribute it
24 * ___ /__/:/ and/or modify it under the terms of the GNU General Public
25 * /__/\ _\__\/ License as published by the Free Software Foundation;
26 * \ \:\ / /\ either version 2 of the License, or (at your option) any
27 * ___\ \:\ /:/ later version.
28 * / /\\ \:\/:/
29 / /:/ \ \::/ This program is distributed in the hope that it will be useful,
30 / /:/_ \__\/ but WITHOUT ANY WARRANTY; without even the implied warranty
31 /__/:/ /\__ of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
32 \ \:\/:/ /\ See the GNU General Public License for more details.
33 \ \::/ /:/
34 \ \:\/:/ You should have received a copy of the GNU General Public License
35 * \ \::/ with this program; if not, write to the Free Software Foundation,
36 * \__\/ Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA */
37
38 load_plugin_textdomain('gotmls', false, basename(GOTMLS_plugin_path).'/languages');
39 require_once(GOTMLS_plugin_path.'images/index.php');
40
41 function GOTMLS_install() {
42 global $wp_version;
43 if (isset($wp_version) && ($wp_version))
44 GOTMLS_define("GOTMLS_wp_version", $wp_version);
45 else
46 GOTMLS_define("GOTMLS_wp_version", "Unknown");
47 if (version_compare(GOTMLS_wp_version, GOTMLS_require_version, "<"))
48 die(GOTMLS_require_version_LANGUAGE.", NOT version: ".GOTMLS_wp_version);
49 else
50 delete_option("gotmls_definitions_blob");
51 }
52 register_activation_hook(__FILE__, "GOTMLS_install");
53
54 function GOTMLS_menu() {
55 $GOTMLS_Full_plugin_logo_URL = GOTMLS_images_path.'GOTMLS-16x16.gif';
56 $base_page = "GOTMLS-settings";
57 $base_function = "GOTMLS_settings";
58 $pluginTitle = "Anti-Malware";
59 $pageTitle = "$pluginTitle ".GOTMLS_Scan_Settings_LANGUAGE;
60 if (GOTMLS_user_can()) {
61 $my_admin_page = add_menu_page($pageTitle, $pluginTitle, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $base_page, $base_function, $GOTMLS_Full_plugin_logo_URL);
62 add_action('load-'.$my_admin_page, 'GOTMLS_admin_add_help_tab');
63 add_submenu_page($base_page, "$pluginTitle ".GOTMLS_Scan_Settings_LANGUAGE, GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $base_page, $base_function);
64 add_submenu_page($base_page, "$pluginTitle Firewall Options", "Firewall Options", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS-Firewall-Options", "GOTMLS_Firewall_Options");
65 add_submenu_page($base_page, "$pluginTitle ".GOTMLS_View_Quarantine_LANGUAGE, GOTMLS_View_Quarantine_LANGUAGE.(($Qs = GOTMLS_get_quarantine(true))?' <span class="awaiting-mod count-'.$Qs.'"><span class="awaiting-mod">'.$Qs.'</span></span>':""), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS-View-Quarantine", "GOTMLS_View_Quarantine");
66 }
67 }
68 add_action("admin_menu", "GOTMLS_menu");
69 add_action("network_admin_menu", "GOTMLS_menu");
70
71 function GOTMLS_admin_add_help_tab() {
72 $screen = get_current_screen();
73 $screen->add_help_tab(array(
74 'id' => "GOTMLS_Getting_Started",
75 'title' => __("Getting Started", 'gotmls'),
76 'content' => '<p>'.__("Make sure the Definition Updates are current and Run a Complete Scan.").'</p><p>'.sprintf(__("If Known Threats are found and displayed in red then there will be a button to '%s'. If only Potentional Threats are found then there is no automatic fix because those are probably not malicious."), GOTMLS_Automatically_Fix_LANGUAGE).'</p><p>'.__("A backup of the original infected files are placed in the Quarantine in case you need to restore them or just want to look at them later. You can delete these files if you don't want to save more.").'</p>'
77 ));
78 $FAQMarker = '== Frequently Asked Questions ==';
79 if (is_file(dirname(__FILE__).'/readme.txt') && ($readme = explode($FAQMarker, @file_get_contents(dirname(__FILE__).'/readme.txt').$FAQMarker)) && strlen($readme[1]) && ($readme = explode("==", $readme[1]."==")) && strlen($readme[0])) {
80 $screen->add_help_tab(array(
81 'id' => "GOTMLS_FAQs",
82 'title' => __("FAQs", 'gotmls'),
83 'content' => '<p>'.preg_replace('/\[(.+?)\]\((.+?)\)/', "<a target=\"_blank\" href=\"\\2\">\\1</a>", preg_replace('/[\r\n]+= /', "</p><b>", preg_replace('/ =[\r\n]+/', "</b><p>", $readme[0]))).'</p>'
84 ));
85 }
86 }
87
88 function GOTMLS_close_button($box_id, $margin = '6px') {
89 return '<a href="javascript:void(0);" style="float: right; color: #F00; overflow: hidden; width: 20px; height: 20px; text-decoration: none; margin: '.$margin.'" onclick="showhide(\''.$box_id.'\');"><span class="dashicons dashicons-dismiss"></span>X</a>';
90 }
91
92 function GOTMLS_enqueue_scripts() {
93 wp_enqueue_style('dashicons');
94 }
95 add_action('admin_enqueue_scripts', 'GOTMLS_enqueue_scripts');
96
97 function GOTMLS_display_header($optional_box = "") {
98 global $current_user, $wpdb;
99 wp_get_current_user();
100 $GOTMLS_url_parts = explode('/', GOTMLS_siteurl);
101 if (isset($_GET["check_site"]) && $_GET["check_site"])
102 echo '<div id="check_site" style="z-index: 1234567;"><img src="'.GOTMLS_images_path.'checked.gif" height=16 width=16 alt="&#x2714;"> '.__("Tested your site. It appears we didn't break anything",'gotmls').' ;-)</div><script type="text/javascript">window.parent.document.getElementById("check_site_warning").style.backgroundColor=\'#0C0\';</script><li>Please <a target="_blank" href="https://wordpress.org/support/view/plugin-reviews/gotmls#postform">write a "Five-Star" Review</a> on WordPress.org if you like this plugin.</li><style>#footer, #GOTMLS-metabox-container, #GOTMLS-right-sidebar, #admin-page-container, #wpadminbar, #adminmenuback, #adminmenuwrap, #adminmenu, .error, .updated, .update-nag {display: none !important;} #wpbody-content {padding-bottom: 0;} #wpbody, html.wp-toolbar {padding-top: 0 !important;} #wpcontent, #footer {margin-left: 5px !important;}';
103 else
104 echo '<style>#GOTMLS-right-sidebar {float: right; margin-right: 0px;}';
105 $Update_Definitions = array(GOTMLS_update_home.'definitions.js'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"].'&ver='.GOTMLS_Version.'&wp='.GOTMLS_wp_version.'&'.GOTMLS_set_nonce(__FUNCTION__."108").'&d='.ur1encode(GOTMLS_siteurl));
106 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])
107 array_unshift($Update_Definitions, admin_url('admin-ajax.php?action=GOTMLS_auto_update&'.GOTMLS_set_nonce(__FUNCTION__."109").'&UPDATE_definitions_array=1'));
108 else
109 $Update_Definitions[] = str_replace("//", "//www.", $Update_Definitions[0]);
110 $Update_Link = '<div style="text-align: center;"><a href="';
111 $new_version = "";
112 $file = basename(GOTMLS_plugin_path).'/index.php';
113 $current = get_site_transient("update_plugins");
114 if (isset($current->response[$file]->new_version) && version_compare(GOTMLS_Version, $current->response[$file]->new_version, "<")) {
115 $new_version = sprintf(__("Upgrade to %s now!",'gotmls'), $current->response[$file]->new_version).'<br /><br />';
116 $Update_Link .= wp_nonce_url(self_admin_url('update.php?action=upgrade-plugin&plugin=').$file, 'upgrade-plugin_'.$file);
117 }
118 $Update_Link .= "\">$new_version</a></div>";
119 $defLatest = (is_numeric($Latest = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"]))) && is_numeric($Default = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Default"]))) && $Latest > $Default)?1:0;
120 if (is_array($keys = maybe_unserialize(get_option('GOTMLS_Installation_Keys', array()))) && array_key_exists(GOTMLS_installation_key, $keys))
121 $isRegistered = $keys[GOTMLS_installation_key];
122 else
123 $isRegistered = "";
124 $Update_Div ='<div id="findUpdates" style="display: none;"><center>'.__("Searching for updates ...",'gotmls').'<br /><img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /><br /><input type="button" value="Cancel" onclick="cancelserver(\'findUpdates\');" /></center></div>';
125 $php_version = "<li>PHP: <span class='GOTMLS_date'>".phpversion()."</span></li>\n";
126 if (isset($_SERVER["SERVER_SOFTWARE"]) && preg_match('/Apache\/([0-9\.]+)/i', $_SERVER["SERVER_SOFTWARE"], $GLOBALS["GOTMLS"]["tmp"]["apache"]) && count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
127 $php_version .= "<li>Apache: <span class='GOTMLS_date'>".$GLOBALS["GOTMLS"]["tmp"]["apache"][1]."</span></li>\n";
128 elseif (isset($_SERVER["SERVER_SOFTWARE"]) && strlen($_SERVER["SERVER_SOFTWARE"]))
129 $php_version .= "<li>".$_SERVER["SERVER_SOFTWARE"]."</li>\n";
130 if ((isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)) {
131 $reg_email_key = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
132 $isRegistered = GOTMLS_get_registrant($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]);
133 } else
134 $reg_email_key = "";
135 $head_nonce = GOTMLS_set_nonce(__FUNCTION__."141");
136 echo '
137 span.GOTMLS_date {float: right; width: 130px; white-space: nowrap;}
138 .GOTMLS_page {float: left; border-radius: 10px; padding: 0 5px;}
139 .GOTMLS_quarantine_item {margin: 4px 12px;}
140 .rounded-corners {margin: 10px; border-radius: 10px; -moz-border-radius: 10px; -webkit-border-radius: 10px; border: 1px solid #000;}
141 .shadowed-box {box-shadow: -3px 3px 3px #666; -moz-box-shadow: -3px 3px 3px #666; -webkit-box-shadow: -3px 3px 3px #666;}
142 .sidebar-box {background-color: #CCC;}
143 .GOTMLS-scanlog li a {display: none;}
144 .GOTMLS-scanlog li:hover a {display: block;}
145 .GOTMLS-sidebar-links {list-style: none;}
146 .GOTMLS-sidebar-links li img {margin: 3px; height: 16px; vertical-align: middle;}
147 .GOTMLS-sidebar-links li {margin-bottom: 0 !important;}
148 .popup-box {background-color: #FFC; display: none; position: absolute; left: 0px; z-index: 10;}
149 .shadowed-text {text-shadow: #00F -1px 1px 1px;}
150 .sub-option {float: left; margin: 3px 5px;}
151 .inside {margin: 10px;}
152 .GOTMLS_li, .GOTMLS_plugin li {list-style: none;}
153 .GOTMLS_plugin {margin: 5px; background: #cfc; border: 1px solid #0C0; padding: 0 5px; border-radius: 3px;}
154 .GOTMLS_plugin.known, .GOTMLS_plugin.db_scan, .GOTMLS_plugin.htaccess, .GOTMLS_plugin.timthumb, .GOTMLS_plugin.errors {background: #f99; border: 1px solid #f00;}
155 .GOTMLS_plugin.potential, .GOTMLS_plugin.wp_core, .GOTMLS_plugin.skipdirs, .GOTMLS_plugin.skipped {background: #ffc; border: 1px solid #fc6;}
156 .GOTMLS ul li {margin-left: 12px;}
157 .GOTMLS h2 {margin: 0 0 10px;}
158 .postbox {margin-right: 10px;}
159 #pastDonations li {list-style: none;}
160 #quarantine_buttons {position: absolute; right: 0px; top: -54px; margin: 0px; padding: 0px;}
161 #quarantine_buttons input.button-primary {margin-right: 20px;}
162 #reclean_buttons {
163 color: #a00;
164 min-height: 32px;
165 border-top: solid 2px black;
166 padding-top: 10px;
167 }
168 #reclean_buttons input.button-primary {float: right;}
169 #delete_button {
170 background-color: #C33;
171 color: #FFF;
172 background-image: linear-gradient(to bottom, #C22, #933);
173 border-color: #933 #933 #900;
174 box-shadow: 0 1px 0 rgba(230, 120, 120, 0.5) inset;
175 text-decoration: none; text-shadow: 0 1px 0 rgba(0, 0, 0, 0.1);
176 margin-top: 10px;
177 }
178 #main-page-title {
179 background: url("'.$GLOBALS["GOTMLS"]["tmp"]["protocol"].'//gravatar.com/avatar/5feb789dd3a292d563fea3b885f786d6?s=64") no-repeat scroll 0 0 transparent;
180 height: 64px;
181 line-height: 58px;
182 margin: 10px 0 0 0;
183 max-width: 600px;
184 padding: 0 110px 0 84px;
185 }
186 #main-page-title h1 {
187 background: url("'.$GLOBALS["GOTMLS"]["tmp"]["protocol"].'//gravatar.com/avatar/8151cac22b3fc543d099241fd573d176?s=64") no-repeat scroll top right transparent;
188 height: 64px;
189 line-height: 32px;
190 margin: 0;
191 padding: 0 84px 0 0;
192 display: table-cell;
193 text-align: center;
194 vertical-align: middle;
195 }
196 </style>
197 <div id="div_file" class="shadowed-box rounded-corners sidebar-box" style="padding: 0; display: none; position: fixed; top: '.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1].'; left: '.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0].'; width: '.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3].'; height: '.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2].'; border: solid #c00; z-index: 112358;"><table style="width: 100%; height: 100%;" cellspacing="0" cellpadding="0"><tr><td style="border-bottom: 1px solid #EEE; height: 32px;" colspan="2">'.GOTMLS_close_button("div_file").'<h3 onmousedown="grabDiv();" onmouseup="releaseDiv();" id="windowTitle" style="cursor: move; border-bottom: 0px none; z-index: 2345677; position: absolute; left: 0px; top: 0px; margin: 0px; padding: 6px; width: 90%; height: 20px;">'.GOTMLS_Loading_LANGUAGE.'</h3></td></tr><tr><td colspan="2" style="height: 100%"><div style="width: 100%; height: 100%; position: relative; padding: 0; margin: 0;" class="inside"><br /><br /><center><img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="..."> '.GOTMLS_Loading_LANGUAGE.'<br /><br /><input type="button" onclick="showhide(\'GOTMLS_iFrame\', true);" value="'.__("If this is taking too long, click here.",'gotmls').'" class="button-primary" /></center><iframe id="GOTMLS_iFrame" name="GOTMLS_iFrame" style="top: 0px; left: 0px; position: absolute; width: 100%; height: 100%; background-color: #CCC;"></iframe></td></tr><tr><td style="height: 20px;"><iframe id="GOTMLS_statusFrame" name="GOTMLS_statusFrame" style="width: 100%; height: 20px; background-color: #CCC;"></iframe></div></td><td style="height: 20px; width: 20px;"><h3 id="cornerGrab" onmousedown="grabCorner();" onmouseup="releaseCorner();" style="cursor: move; height: 24px; width: 24px; margin: 0; padding: 0; z-index: 2345678; overflow: hidden; position: absolute; right: 0px; bottom: 0px;"><span class="dashicons dashicons-editor-expand"></span>&#8690;</h3></td></tr></table></div>
198 <script type="text/javascript">
199 function showhide(id) {
200 divx = document.getElementById(id);
201 if (divx) {
202 if (divx.style.display == "none" || arguments[1]) {
203 divx.style.display = "block";
204 divx.parentNode.className = (divx.parentNode.className+"close").replace(/close/gi,"");
205 return true;
206 } else {
207 divx.style.display = "none";
208 return false;
209 }
210 }
211 }
212 function checkAllFiles(check) {
213 var checkboxes = new Array();
214 checkboxes = document["GOTMLS_Form_clean"].getElementsByTagName("input");
215 for (var i=0; i<checkboxes.length; i++)
216 if (checkboxes[i].type == "checkbox" && checkboxes[i].id.substring(0, 6) == "check_")
217 checkboxes[i].checked = check;
218 }
219 function setvalAllFiles(val) {
220 var checkboxes = document.getElementById("GOTMLS_fixing");
221 if (checkboxes)
222 checkboxes.value = val;
223 }
224 function getWindowWidth(min) {
225 if (typeof window.innerWidth != "undefined" && window.innerWidth > min)
226 min = window.innerWidth;
227 else if (typeof document.documentElement != "undefined" && typeof document.documentElement.clientWidth != "undefined" && document.documentElement.clientWidth > min)
228 min = document.documentElement.clientWidth;
229 else if (typeof document.getElementsByTagName("body")[0].clientWidth != "undefined" && document.getElementsByTagName("body")[0].clientWidth > min)
230 min = document.getElementsByTagName("body")[0].clientWidth;
231 return min;
232 }
233 function getWindowHeight(min) {
234 if (typeof window.innerHeight != "undefined" && window.innerHeight > min)
235 min = window.innerHeight;
236 else if (typeof document.documentElement != "undefined" && typeof document.documentElement.clientHeight != "undefined" && document.documentElement.clientHeight > min)
237 min = document.documentElement.clientHeight;
238 else if (typeof document.getElementsByTagName("body")[0].clientHeight != "undefined" && document.getElementsByTagName("body")[0].clientHeight > min)
239 min = document.getElementsByTagName("body")[0].clientHeight;
240 return min;
241 }
242 function loadIframe(title) {
243 showhide("GOTMLS_iFrame", true);
244 showhide("GOTMLS_iFrame");
245 document.getElementById("windowTitle").innerHTML = title;
246 if (curDiv) {
247 windowW = getWindowWidth(200);
248 windowH = getWindowHeight(200);
249 if (windowW > 200)
250 windowW -= 30;
251 if (windowH > 200)
252 windowH -= 20;
253 if (px2num(curDiv.style.width) > windowW) {
254 curDiv.style.width = windowW + "px";
255 curDiv.style.left = "0px";
256 } else if ((px2num(curDiv.style.left) + px2num(curDiv.style.width)) > windowW) {
257 curDiv.style.left = (windowW - px2num(curDiv.style.width)) + "px";
258 }
259 if (px2num(curDiv.style.height) > windowH) {
260 curDiv.style.height = windowH + "px";
261 curDiv.style.top = "0px";
262 } else if ((px2num(curDiv.style.top) + px2num(curDiv.style.height)) > windowH) {
263 curDiv.style.top = (windowH - px2num(curDiv.style.height)) + "px";
264 }
265 if (px2num(curDiv.style.left) < 0)
266 curDiv.style.left = "0px";
267 if (px2num(curDiv.style.top)< 0)
268 curDiv.style.top = "0px";
269 }
270 showhide("div_file", true);
271 if (IE)
272 curDiv.scrollIntoView(true);
273 }
274 function cancelserver(divid) {
275 document.getElementById(divid).innerHTML = "<div class=\'error\'>'. __("No response from server!",'gotmls').'</div>";
276 }
277 function checkupdateserver(server, divid) {
278 var updatescript = document.createElement("script");
279 updatescript.setAttribute("src", server);
280 divx = document.getElementById(divid);
281 if (divx) {
282 divx.appendChild(updatescript);
283 if (arguments[2])
284 return setTimeout("stopCheckingDefinitions = checkupdateserver(\'"+arguments[2]+"\',\'"+divid+"\')",15000);
285 else
286 return setTimeout("cancelserver(\'"+divid+"\')",'.($GLOBALS["GOTMLS"]["tmp"]['execution_time']+1).'000+3000);
287 }
288 }
289 var IE = document.all?true:false;
290 //if (!IE) document.addEventListener("mousemove", getMouseXY);
291 document.onmousemove = getMouseXY;
292 var offsetX = 0;
293 var offsetY = 0;
294 var offsetW = 0;
295 var offsetH = 0;
296 var curX = 0;
297 var curY = 0;
298 var curDiv;
299 function getMouseXY(e) {
300 if (IE) { // grab the mouse pos if browser is IE
301 curX = event.clientX + document.body.scrollLeft;
302 curY = event.clientY + document.body.scrollTop;
303 } else { // grab the mouse pos if browser is Not IE
304 curX = e.pageX - document.body.scrollLeft;
305 curY = e.pageY - document.body.scrollTop;
306 }
307 if (curX < 0) {curX = 0;}
308 if (curY < 0) {curY = 0;}
309 if (offsetX && curX > 10) {curDiv.style.left = (curX - offsetX)+"px";}
310 if (offsetY && (curY - offsetY) > 0) {curDiv.style.top = (curY - offsetY)+"px";}
311 if (offsetW && (curX - offsetW) > 360) {curDiv.style.width = (curX - offsetW)+"px";}
312 if (offsetH && (curY - offsetH) > 200) {curDiv.style.height = (curY - offsetH)+"px";}
313 return true;
314 }
315 function px2num(px) {
316 return parseInt(px.substring(0, px.length - 2), 10);
317 }
318 function setDiv(DivID) {
319 if (curDiv = document.getElementById(DivID)) {
320 if (IE)
321 curDiv.style.position = "absolute";
322 curDiv.style.left = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0].'";
323 curDiv.style.top = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1].'";
324 curDiv.style.height = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2].'";
325 curDiv.style.width = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3].'";
326 }
327 }
328 function grabDiv() {
329 corner = document.getElementById("windowTitle");
330 if (corner) {
331 corner.style.width="100%";
332 corner.style.height="100%";
333 }
334 offsetX=curX-px2num(curDiv.style.left);
335 offsetY=curY-px2num(curDiv.style.top);
336 }
337 function releaseDiv() {
338 corner = document.getElementById("windowTitle");
339 if (corner) {
340 corner.style.width="90%";
341 corner.style.height="20px";
342 }
343 document.getElementById("GOTMLS_statusFrame").src = "'.admin_url('admin-ajax.php?action=GOTMLS_position&'.$head_nonce.'&GOTMLS_x=').'"+curDiv.style.left+"&GOTMLS_y="+curDiv.style.top;
344 offsetX=0;
345 offsetY=0;
346 }
347 function grabCorner() {
348 corner = document.getElementById("cornerGrab");
349 if (corner) {
350 corner.style.width="100%";
351 corner.style.height="100%";
352 }
353 offsetW=curX-px2num(curDiv.style.width);
354 offsetH=curY-px2num(curDiv.style.height);
355 }
356 function releaseCorner() {
357 corner = document.getElementById("cornerGrab");
358 if (corner) {
359 corner.style.width="20px";
360 corner.style.height="20px";
361 }
362 document.getElementById("GOTMLS_statusFrame").src = "'.admin_url('admin-ajax.php?action=GOTMLS_position&'.$head_nonce.'&GOTMLS_w=').'"+curDiv.style.width+"&GOTMLS_h="+curDiv.style.height;
363 offsetW=0;
364 offsetH=0;
365 }
366 setDiv("div_file");
367 </script>
368 <div id="main-page-title"><h1 style="vertical-align: middle;">Anti-Malware from&nbsp;GOTMLS.NET</h1></div>
369 <div id="admin-page-container">
370 <div id="GOTMLS-right-sidebar" style="width: 300px;" class="metabox-holder">
371 '.GOTMLS_box(__("Updates & Registration",'gotmls'), "<ul>$php_version<li>WordPress: <span class='GOTMLS_date'>".GOTMLS_wp_version."</span></li>\n<li>Plugin: <span class='GOTMLS_date'>".GOTMLS_Version.'</span></li>
372 <li><div id="GOTMLS_Key" style="margin: 0;'.((!$defLatest && !$isRegistered)?' display: none;">Key: <span style="float: right;">'.GOTMLS_installation_key.'</span></div><div style="':'">Key: <span style="float: right;" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">'.GOTMLS_installation_key.'</span></div><div style="display: none;').'"><form method="POST" action="'.admin_url('admin-ajax.php?'.$head_nonce).'" target="GOTMLS_iFrame" name="GOTMLS_Form_lognewkey"><input type="hidden" name="GOTMLS_installation_key" value="'.GOTMLS_installation_key.'"><input type="hidden" name="action" value="GOTMLS_lognewkey"><span style="color: #F00;" id="GOTMLS_No_Key">No Key! <input type="submit" style="float: right;" value="'.__("Get FREE Key!",'gotmls').'" class="button-primary" onclick="showhide(\'GOTMLS_No_Key\');showhide(\'GOTMLS_Key\', true);check_for_updates(\'Definition_Updates\');" /></span></form></div></li>
373 <li>Definitions: <span id="GOTMLS_definitions_date" class="GOTMLS_date">'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"].'</span></li></ul>
374 <form id="updateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
375 <img style="display: none; float: left; margin-right: 4px;" src="'.GOTMLS_images_path.'checked.gif" height=16 width=16 alt="definitions updated" id="autoUpdateDownload" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">
376 '.str_replace('findUpdates', 'Definition_Updates', $Update_Div).'
377 <div id="autoUpdateForm" style="display: none;">
378 <input type="submit" style="width: 100%;" name="auto_update" value="'.__("Download new definitions!",'gotmls').'">
379 </div>
380 </form>
381 <form id="clearupdateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
382 <input name="UPDATE_definitions_array" value="D" type="hidden">
383 <input type="submit" style="display: none; width: 100%; color: #ff0; background-color: #c33" id="clear_updates" value="'.__("Delete ALL definitions!",'gotmls').'">
384 </form>
385 <div id="registerKeyForm" style="display: none;"><span id="registerFormMessage" style="color: #F00">'.__("<p>Get instant access to definition updates.</p>",'gotmls').'</span><p>
386 '.__("If you have not already registered your Key then register now using the form below.<br />* All registration fields are required<br />** I will NOT share your information.",'gotmls').'</p>
387 <form id="registerform" onsubmit="return sinupFormValidate(this);" action="'.GOTMLS_plugin_home.'wp-login.php?action=register" method="post" name="registerform" target="GOTMLS_iFrame"><input type="hidden" name="redirect_to" id="register_redirect_to" value="/donate/"><input type="hidden" name="user_login" id="register_user_login" value=""><input type="hidden" name="old_user_email" id="old_user_email" value="'.$reg_email_key.'">
388 <div>'.__("Your Full Name:",'gotmls').'</div>
389 <div style="float: left; width: 50%;"><input style="width: 100%;" id="first_name" type="text" name="first_name" value="'.$current_user->user_firstname.'" /></div>
390 <div style="float: left; width: 50%;"><input style="width: 100%;" id="last_name" type="text" name="last_name" value="'.$current_user->user_lastname.'" /></div>
391 <div style="clear: left; width: 100%;">
392 <div>'.__("A password will be e-mailed to this address:",'gotmls').(strlen($reg_email_key) == 32 && $reg_email_key != md5($current_user->user_email)?'<br /><span style="color: #C00;">'.__("Note: The pre-populated email below is NOT the address this site is currently registered under!",'gotmls').'</span>':"").'</div>
393 <input style="width: 100%;" id="user_email" type="text" name="user_email" value="'.$current_user->user_email.'" /></div>
394 <div>
395 <div>'.__("Your WordPress Site URL:",'gotmls').'</div>
396 <input style="width: 100%;" id="user_url" type="text" name="user_url" value="'.GOTMLS_siteurl.'" readonly /></div>
397 <div>
398 <div>'.__("Plugin Installation Key:",'gotmls').'</div>
399 <input style="width: 100%;" id="installation_key" type="text" name="installation_key" value="'.GOTMLS_installation_key.'" readonly /><input id="old_key" type="hidden" name="old_key" value="'.md5($GOTMLS_url_parts[2]).'" /></div>
400 <input style="width: 100%;" id="wp-submit" type="submit" name="wp-submit" value="Register Now!" /></form></div>'.(false && $isRegistered?'Registered to: '.$isRegistered:"").$Update_Link, "stuffbox").'
401 <script type="text/javascript">
402 var alt_addr = "'.$Update_Definitions[1].'";
403 function check_for_updates(update_type) {
404 showhide(update_type, true);
405 stopCheckingDefinitions = checkupdateserver("'.$Update_Definitions[0].'", update_type, alt_addr);
406 }
407 function updates_complete(chk) {
408 if (auto_img = document.getElementById("autoUpdateDownload")) {
409 auto_img.style.display="block";
410 check_for_donation(chk);
411 }
412 }
413 function check_for_donation(chk) {
414 if (document.getElementById("autoUpdateDownload").src.replace(/^.+\?/,"")=="0")
415 if (chk.substr(0, 8) != "Changed " || chk.substr(8, 1) != "0")
416 chk += "\\n\\n'.__("Please make a donation for the use of this wonderful feature!",'gotmls').'";
417 alert(chk);
418 }
419 function sinupFormValidate(form) {
420 var error = "";
421 if(form["first_name"].value == "")
422 error += "'.__("First Name is a required field!",'gotmls').'\n";
423 if(form["last_name"].value == "")
424 error += "'.__("Last Name is a required field!",'gotmls').'\n";
425 if(form["user_email"].value == "")
426 error += "'.__("Email Address is a required field!",'gotmls').'\n";
427 else {
428 if (uem = document.getElementById("register_user_login"))
429 uem.value = form["user_email"].value;
430 if (uem = document.getElementById("register_redirect_to"))
431 uem.value = "/donate/?email="+form["user_email"].value.replace("@", "%40");
432 }
433 if(form["user_url"].value == "")
434 error += "'.__("Your WordPress Site URL is a required field!",'gotmls').'\n";
435 if(form["installation_key"].value == "")
436 error += "'.__("Plugin Installation Key is a required field!",'gotmls').'\n";
437 if(error != "") {
438 alert(error);
439 return false;
440 } else {
441 document.getElementById("Definition_Updates").innerHTML = \'<img src="'.GOTMLS_images_path.'wait.gif">'.__("Submitting Registration ...",'gotmls').'\';
442 showhide("Definition_Updates", true);
443 setTimeout(\'stopCheckingDefinitions = checkupdateserver("'.$Update_Definitions[0].'", "Definition_Updates", "'.$Update_Definitions[1].'")\', 3000);
444 showhide("registerKeyForm");
445 return true;
446 }
447 }
448 var divNAtext = false;
449 function loadGOTMLS() {
450 clearTimeout(divNAtext);
451 setDivNAtext();
452 '.$GLOBALS["GOTMLS"]["tmp"]["onLoad"].'
453 }
454 if ('.($defLatest+strlen($isRegistered)).')
455 check_for_updates("Definition_Updates");
456 /* else
457 showhide("registerKeyForm", true);*/
458 if (divNAtext)
459 loadGOTMLS();
460 else
461 divNAtext=true;
462 </script>
463 '.GOTMLS_box(__("Resources & Links",'gotmls'), '
464 <div id="pastDonations"></div>
465 <form name="ppdform" id="ppdform" action="https://www.paypal.com/cgi-bin/webscr" method="post" target="_blank">
466 <input type="hidden" name="cmd" value="_s-xclick">
467 <input type="hidden" name="hosted_button_id" value="NKANR75NUL9WY">
468 <input type="hidden" name="on0" value="Contribution Level">
469 <center>
470 <input type="radio" name="os0" value="Basic">$15
471 <input type="radio" name="os0" value="Full" checked>$29
472 <input type="radio" name="os0" value="Double">$52
473 <input type="radio" name="os0" value="Elite">$100
474 <input type="radio" name="os0" value="Ninja">$200
475 </center>
476 <input type="hidden" name="currency_code" value="USD">
477 <img alt="" border="0" src="https://www.paypalobjects.com/en_US/i/scr/pixel.gif" width="1" height="1">
478 <input type="hidden" name="no_shipping" value="1">
479 <input type="hidden" name="no_note" value="1">
480 <input type="hidden" name="tax" value="0">
481 <input type="hidden" name="lc" value="US">
482 <input type="hidden" name="item_name" value="Donation to Eli\'s Anti-Malware Plugin">
483 <input type="hidden" name="item_number" value="GOTMLS-key-'.GOTMLS_installation_key.'">
484 <input type="hidden" name="custom" value="key-'.GOTMLS_installation_key.'">
485 <input type="hidden" name="notify_url" value="'.GOTMLS_plugin_home.GOTMLS_installation_key.'/ipn">
486 <input type="hidden" name="page_style" value="GOTMLS">
487 <input type="hidden" name="return" value="'.GOTMLS_plugin_home.'donate/?donation-source=paid">
488 <input type="hidden" name="cancel_return" value="'.GOTMLS_plugin_home.'donate/?donation-source=cancel">
489 <input type="image" id="pp_button" src="'.GOTMLS_images_path.'btn_donateCC_WIDE.gif" border="0" name="submitc" alt="'.__("Make a Donation with PayPal",'gotmls').'">
490 <div>
491 <ul class="GOTMLS-sidebar-links">
492 <li style="float: right;"><b>on <a target="_blank" href="https://profiles.wordpress.org/scheeeli#content-plugins">WordPress.org</a></b><ul class="GOTMLS-sidebar-links">
493 <li><a target="_blank" href="https://wordpress.org/plugins/gotmls/faq/">Plugin FAQs</a></li>
494 <li><a target="_blank" href="https://wordpress.org/support/plugin/gotmls">Forum Posts</a></li>
495 <li><a target="_blank" href="https://wordpress.org/support/view/plugin-reviews/gotmls">Plugin Reviews</a></li>
496 </ul></li>
497 <li><img src="//gravatar.com/avatar/5feb789dd3a292d563fea3b885f786d6?s=16" border="0" alt="Plugin site:"><b><a target="_blank" href="'.GOTMLS_plugin_home.'">GOTMLS.NET</a></b></li>
498 <li><img src="//gravatar.com/avatar/8151cac22b3fc543d099241fd573d176?s=16" border="0" alt="Developer site:"><b><a target="_blank" href="http://wordpress.ieonly.com/category/my-plugins/anti-malware/">Eli\'s Blog</a></b></li>
499 <li><img src="https://ssl.gstatic.com/ui/v1/icons/mail/favicon.ico" border="0" alt="mail:"><b><a target="_blank" href="mailto:eli@gotmls.net">Email Eli</a></b></li>
500 <li><iframe allowtransparency="true" frameborder="0" scrolling="no" src="https://platform.twitter.com/widgets/follow_button.html?screen_name=GOTMLS&amp;show_count=false" style="width:125px; height:20px;"></iframe></li>
501 </ul>
502 </div>
503 </form>
504 <a target="_blank" href="https://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html#url='.urlencode(GOTMLS_siteurl).'">Google Safe Browsing Diagnostic</a>', "stuffbox").//GOTMLS_box(__("Last Scan Status",'gotmls'), GOTMLS_scan_log(), "stuffbox").
505 $optional_box.'
506 </div>';
507 if (isset($GLOBALS["GOTMLS"]["tmp"]["stuffbox"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["stuffbox"])) {
508 echo '
509 <script type="text/javascript">
510 function stuffbox_showhide(id) {
511 divx = document.getElementById(id);
512 if (divx) {
513 if (divx.style.display == "none" || arguments[1]) {';
514 $else = '
515 if (divx = document.getElementById("GOTMLS-right-sidebar"))
516 divx.style.width = "30px";
517 if (divx = document.getElementById("GOTMLS-main-section"))
518 divx.style.marginRight = "30px";';
519 foreach ($GLOBALS["GOTMLS"]["tmp"]["stuffbox"] as $md5 => $bTitle) {
520 echo "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'block';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".GOTMLS_strip4java($bTitle, true)."';";
521 $else .= "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'none';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".substr($bTitle, 0, 1)."';";
522 }
523 echo '
524 if (divx = document.getElementById("GOTMLS-right-sidebar"))
525 divx.style.width = "300px";
526 if (divx = document.getElementById("GOTMLS-main-section"))
527 divx.style.marginRight = "300px";
528 return true;
529 } else {'.$else.'
530 return false;
531 }
532 }
533 }
534 if (getWindowWidth(780) == 780)
535 setTimeout("stuffbox_showhide(\'inside_'.$md5.'\')", 200);
536 </script>';
537 }
538 echo '
539 <div id="GOTMLS-main-section" style="margin-right: 300px;">
540 <div class="metabox-holder GOTMLS" style="width: 100%;" id="GOTMLS-metabox-container">';
541 }
542
543 function GOTMLS_box($bTitle, $bContents, $bType = "postbox") {
544 $md5 = md5($bTitle);
545 if (isset($GLOBALS["GOTMLS"]["tmp"]["$bType"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["$bType"]))
546 $GLOBALS["GOTMLS"]["tmp"]["$bType"]["$md5"] = "$bTitle";
547 else
548 $GLOBALS["GOTMLS"]["tmp"]["$bType"] = array("$md5"=>"$bTitle");
549 return '
550 <div id="box_'.$md5.'" class="'.$bType.'"><h3 title="Click to toggle" onclick="if (typeof '.$bType.'_showhide == \'function\'){'.$bType.'_showhide(\'inside_'.$md5.'\');}else{showhide(\'inside_'.$md5.'\');}" style="cursor: pointer;" class="hndle"><span id="title_'.$md5.'">'.$bTitle.'</span></h3>
551 <div id="inside_'.$md5.'" class="inside">
552 '.$bContents.'
553 </div>
554 </div>';
555 }
556
557 function GOTMLS_get_scanlog() {
558 global $wpdb;
559 $LastScan = '';
560 if (isset($_GET["GOTMLS_cl"]) && GOTMLS_get_nonce()) {
561 $SQL = $wpdb->prepare("DELETE FROM `$wpdb->options` WHERE option_name LIKE %s AND substring_index(option_name, '/', -1) < %s", 'GOTMLS_scan_log/%', $_GET["GOTMLS_cl"]);
562 if ($cleared = $wpdb->query($SQL))
563 $LastScan .= sprintf(__("Cleared %s records from this log.",'gotmls'), $cleared);
564 // else $LastScan .= $wpdb->last_error."<li>$SQL</li>";
565 }
566 $SQL = "SELECT substring_index(option_name, '/', -1) AS `mt`, option_name, option_value FROM `$wpdb->options` WHERE option_name LIKE 'GOTMLS_scan_log/%' ORDER BY mt DESC";
567 if ($rs = $wpdb->get_results($SQL, ARRAY_A)) {
568 $units = array("seconds"=>60,"minutes"=>60,"hours"=>24,"days"=>365,"years"=>10);
569 $LastScan .= '<ul class="GOTMLS-scanlog GOTMLS-sidebar-links">';
570 foreach ($rs as $row) {
571 $LastScan .= "\n<li>";
572 $GOTMLS_scan_log = (isset($row["option_name"])?get_option($row["option_name"], array()):array());
573 if (isset($GOTMLS_scan_log["scan"]["type"]) && strlen($GOTMLS_scan_log["scan"]["type"]))
574 $LastScan .= GOTMLS_htmlentities($GOTMLS_scan_log["scan"]["type"]);
575 else
576 $LastScan .= "Unknown scan type";
577 if (isset($GOTMLS_scan_log["scan"]["dir"]) && is_dir($GOTMLS_scan_log["scan"]["dir"]))
578 $LastScan .= " of ".basename($GOTMLS_scan_log["scan"]["dir"]);
579 if (isset($GOTMLS_scan_log["scan"]["start"]) && is_numeric($GOTMLS_scan_log["scan"]["start"])) {
580 $time = (time() - $GOTMLS_scan_log["scan"]["start"]);
581 $ukeys = array_keys($units);
582 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= $units[$ukeys[$key]]); $unit = $ukeys[++$key])
583 $time = floor($time/$units[$ukeys[$key]]);
584 if (1 == $time)
585 $unit = substr($unit, 0, -1);
586 $LastScan .= " started $time $unit ago";
587 if (isset($GOTMLS_scan_log["scan"]["finish"]) && is_numeric($GOTMLS_scan_log["scan"]["finish"]) && ($GOTMLS_scan_log["scan"]["finish"] >= $GOTMLS_scan_log["scan"]["start"])) {
588 $time = ($GOTMLS_scan_log["scan"]["finish"] - $GOTMLS_scan_log["scan"]["start"]);
589 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= $units[$ukeys[$key]]); $unit = $ukeys[++$key])
590 $time = floor($time/$units[$ukeys[$key]]);
591 if (1 == $time)
592 $unit = substr($unit, 0, -1);
593 if ($time)
594 $LastScan .= " and ran for $time $unit";
595 else
596 $LastScan = str_replace("started", "ran", $LastScan);
597 } else
598 $LastScan .= " and has not finish";
599 } else
600 $LastScan .= " failed to started";
601 $LastScan .= '<a href="'.GOTMLS_script_URI.'&GOTMLS_cl='.$row["mt"].'&'.GOTMLS_set_nonce(__FUNCTION__."600").'">[clear log below this entry]</a></li>';
602 }
603 $LastScan .= '</ul>';
604 } else
605 $LastScan .= '<h3>'.__("No Scans have been logged",'gotmls').'</h3>';
606 return "$LastScan\n";
607 }
608
609 function GOTMLS_get_whitelists() {
610 $Q_Page = '';
611 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"])) {
612 $Q_Page .= '<ul name="found_Quarantine" id="found_Quarantine" class="GOTMLS_plugin known" style="background-color: #ccc; padding: 0;"><h3>'.__("Globally White-listed files",'gotmls').'<span class="GOTMLS_date">'.__("# of patterns",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Updated",'gotmls').'</span></h3>';
613 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"] as $file => $non_threats) {
614 if (isset($non_threats[0])) {
615 $updated = GOTMLS_sexagesimal($non_threats[0]);
616 unset($non_threats[0]);
617 } else
618 $updated = "Unknown";
619 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($non_threats).'</span><span class="GOTMLS_date">'.$updated."</span>$file</li>\n";
620 }
621 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"])) {
622 $Q_Page .= '<h3>'.__("WordPress Core files",'gotmls').'<span class="GOTMLS_date">'.__("# of files",'gotmls').'</span></h3>';
623 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"] as $ver => $files) {
624 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($files)."</span>Version $ver</li>\n";
625 }
626 }
627 $Q_Page .= "</ul>";
628 }
629 return "$Q_Page\n";
630 }
631
632 function GOTMLS_get_quarantine($only = false) {
633 global $wpdb, $post;
634 if (is_numeric($only))
635 return get_post($only, ARRAY_A);
636 elseif ($only)
637 return $wpdb->get_var("SELECT COUNT(*) FROM $wpdb->posts WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'private'");
638 else
639 $args = array('posts_per_page' => (isset($_GET['posts_per_page'])&&is_numeric($_GET['posts_per_page'])&&$_GET['posts_per_page']>0?$_GET['posts_per_page']:200), 'orderby' => 'date', 'post_type' => 'GOTMLS_quarantine', "post_status" => "private");
640 if (isset($_POST["paged"]))
641 $args["paged"] = $_POST["paged"];
642 $my_query = new WP_Query($args);
643 $Q_Paged = '<form method="POST" name="GOTMLS_Form_page"><input type="hidden" id="GOTMLS_paged" name="paged" value="1"><div style="float: left;">Page:</div>';
644 $Q_Page = '
645 <form method="POST" action="'.admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."645")).(isset($_SERVER["QUERY_STRING"])&&strlen($_SERVER["QUERY_STRING"])?"&".$_SERVER["QUERY_STRING"]:"").'" target="GOTMLS_iFrame" name="GOTMLS_Form_clean"><input type="hidden" id="GOTMLS_fixing" name="GOTMLS_fixing" value="1"><input type="hidden" name="action" value="GOTMLS_fix">';
646 if ($my_query->have_posts()) {
647 $Q_Page .= '<p id="quarantine_buttons" style="display: none;"><input id="repair_button" type="submit" value="'.__("Restore selected files",'gotmls').'" class="button-primary" onclick="if (confirm(\''.__("Are you sure you want to overwrite the previously cleaned files with the selected files in the Quarantine?",'gotmls').'\')) { setvalAllFiles(1); loadIframe(\'File Restoration Results\'); } else return false;" /><input id="delete_button" type="submit" class="button-primary" value="'.__("Delete selected files",'gotmls').'" onclick="if (confirm(\''.__("Are you sure you want to permanently delete the selected files in the Quarantine?",'gotmls').'\')) { setvalAllFiles(2); loadIframe(\'File Deletion Results\'); } else return false;" /></p><p><b>'.__("The following items highlighted in yellow had been found to contain malicious code, they have been cleaned and the malicious contents have been removed. A record of the infection has been saved here in the Quarantine for your review and could help with any future investigations. The code is safe here and you do not need to do anything further with these files.",'gotmls').'</b></p>
648 <p id="reclean_buttons" style="display: none;"><input id="reclean_button" type="submit" value="'.__("Re-clean re-infected files",'gotmls').'" class="button-primary" onclick="checkAllFiles(false); setvalAllFiles(1); loadIframe(\'Reinfected File Recleaning Results\');" /><b>'.__("The items highlighted in red have been found to be re-infected. The malicious code has returned and needs to be cleaned again.",'gotmls').'</b></p>
649 <ul name="found_Quarantine" id="found_Quarantine" class="GOTMLS_plugin known" style="background-color: #ccc; padding: 0;"><h3 style="margin: 8px 12px;">'.($my_query->post_count>1?'<input type="checkbox" onchange="checkAllFiles(this.checked); document.getElementById(\'quarantine_buttons\').style.display = \'block\';"> '.sprintf(__("Check all %d",'gotmls'),$my_query->post_count):"").__(" Items in Quarantine",'gotmls').'<span class="GOTMLS_date">'.__("Quarantined",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Infected",'gotmls').'</span></h3>';
650 $root_path = implode(GOTMLS_slash(), array_slice(GOTMLS_explode_dir(__FILE__), 0, (2 + intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"])) * -1));
651 while ($my_query->have_posts()) {
652 $my_query->the_post();
653 $gif = 'blocked.gif';
654 $threat = 'potential';
655 $action = $post->ID.'" id="check_'.$post->ID.'" onchange="document.getElementById(\'quarantine_buttons\').style.display = \'block\';';
656 $link = GOTMLS_error_link(__("The current/live file is missing or deleted",'gotmls'), $post->ID, $threat);
657 if (is_file($post->post_title)) {
658 GOTMLS_scanfile($post->post_title);
659 if (count($GLOBALS["GOTMLS"]["tmp"]["threats_found"])) {
660 $gif = 'threat.gif" onload="document.getElementById(\'reclean_buttons\').style.display = \'block\';';
661 $threat = 'known';
662 $action = GOTMLS_encode(realpath($post->post_title)).'" id="ilist_'.$post->ID.'" checked="true';
663 }
664 $link = GOTMLS_error_link(__("View current/live version",'gotmls'), $post->post_title, $threat);
665 } elseif (is_array($postdb = explode(":", $post->post_title.":")) && count($postdb) > 3 && is_numeric($postdb[1])) {
666 if ("options" == substr($postdb[0], -7)) {
667 if ($opt_row = $wpdb->get_row("SELECT * FROM `$wpdb->options` WHERE `option_id` = ".$postdb[0], ARRAY_A))
668 $link = GOTMLS_error_link(__("View Option Record: ",'gotmls').$postdb[1], $postdb[1].'.1', $threat);
669 elseif ($opt_row = $wpdb->get_row($SQL = $wpdb->prepare("SELECT * FROM `$wpdb->options` WHERE `option_name` LIKE %s", trim($postdb[2], '"')), ARRAY_A))
670 $link = GOTMLS_error_link(__("View Option Record: ",'gotmls').htmlspecialchars($postdb[2]), $opt_row["option_id"].'.1', $threat);
671 else
672 $link = GOTMLS_error_link(__("View Quarantine Record",'gotmls'), $post->ID, $threat);
673 } else {
674 $link = '<a target="_blank" href="';
675 if ("revision" == $postdb[0])
676 $link .= admin_url('revision.php?revision='.$postdb[1])."\" title=\"View this revision";
677 else
678 $link .= admin_url('post.php?action=edit&post='.$postdb[1])."\" title=\"View current ".$postdb[0];
679 $link .= "\" id=\"list_edit_$postdb[1]\" class=\"GOTMLS_plugin $threat\">";
680 }
681 }
682 $Q_Page .= '
683 <li id="GOTMLS_quarantine_'.$post->ID.'" class="GOTMLS_quarantine_item" onmouseover="this.style.fontWeight=\'bold\';" onmouseout="this.style.fontWeight=\'normal\';"><span class="GOTMLS_date">'.GOTMLS_error_link(__("View Quarantine Record",'gotmls'), $post->ID, $threat).$post->post_date_gmt.'</a></span><span class="GOTMLS_date">'.$post->post_modified_gmt.'</span><input type="checkbox" name="GOTMLS_fix[]" value="'.$action.'" /><img src="'.GOTMLS_images_path.$gif.'" height=16 width=16 alt="Q">'.$link.str_replace($root_path, "...", $post->post_title)."</a></li>\n";
684 }
685 $Q_Page .= "\n</ul>";
686 for ($p = 1; $p <= $my_query->max_num_pages; $p++) {
687 $Q_Paged .= '<input class="GOTMLS_page" type="submit" value="'.$p.'"'.((isset($_POST["paged"]) && $_POST["paged"] == $p) || (!isset($_POST["paged"]) && 1 == $p)?" DISABLED":"").' onclick="document.getElementById(\'GOTMLS_paged\').value = \''.$p.'\';">';
688 }
689 } else
690 $Q_Page .= '<h3>'.__("No Items in Quarantine",'gotmls').'</h3>';
691 wp_reset_query();
692 $return = "$Q_Paged\n</form><br style=\"clear: left;\" />\n$Q_Page\n</form>\n$Q_Paged\n</form><br style=\"clear: left;\" />\n";
693 if (($trashed = $wpdb->get_var("SELECT COUNT(*) FROM $wpdb->posts WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` != 'private'")) > 1)
694 $return = '<a href="'.admin_url('admin-ajax.php?action=GOTMLS_empty_trash&'.GOTMLS_set_nonce(__FUNCTION__."720")).'" id="empty_trash_link" style="float: right;" target="GOTMLS_statusFrame">['.sprintf(__("Clear %s Deleted Files from the Trash",'gotmls'), $trashed)."]</a>$return";
695 return $return;
696 }
697
698 function GOTMLS_View_Quarantine() {
699 GOTMLS_ajax_auto_update();
700 $echo = GOTMLS_box($Q_Page = __("White-lists",'gotmls'), GOTMLS_get_whitelists());
701 if (!isset($_GET['Whitelists']))
702 $echo .= "\n<script>\nshowhide('inside_".md5($Q_Page)."');\n</script>\n";
703 $echo .= GOTMLS_box($Q_Page = __("Quarantine",'gotmls'), GOTMLS_get_quarantine());
704 GOTMLS_display_header();
705 echo $echo."\n</div></div></div>";
706 }
707
708 function GOTMLS_Firewall_Options() {
709 global $current_user, $wpdb, $table_prefix;
710 GOTMLS_ajax_auto_update();
711 GOTMLS_display_header();
712 $GOTMLS_nonce_found = GOTMLS_get_nonce();
713 $gt = ">";
714 $lt = "<";
715 $save_action = "";
716 $patch_attr = array(
717 array(
718 "icon" => "blocked",
719 "language" => "<b>".__("(This patch only works under Apache servers and requires mod_rewrite and session_start to be active and functional)",'gotmls')."</b><br />\n".__("Your WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. Applying this patch will block access to the WordPress Login page whenever this type of attack is detected.",'gotmls'),
720 "status" => __('Not Installed','gotmls'),
721 "action" => __('Install Patch','gotmls')
722 ),
723 array(
724 "language" => __("Your WordPress site has the current version of my brute-force Login protection installed.",'gotmls'),
725 "action" => __('Uninstall Patch','gotmls'),
726 "status" => __('Enabled','gotmls'),
727 "icon" => "checked"
728 ),
729 array(
730 "language" => __("Your WordPress Login page has the old version of my brute-force protection installed. Upgrade this patch to improve the protection on the WordPress Login page and preserve the integrity of your WordPress core files.",'gotmls'),
731 "action" => __('Upgrade Patch','gotmls'),
732 "status" => __('Out of Date','gotmls'),
733 "icon" => "threat"
734 )
735 );
736 $find = '|<Files[^>]+xmlrpc.php>(.+?)</Files>\s*(# END GOTMLS Patch to Block XMLRPC Access\s*)*|is';
737 $deny = "\n<IfModule !mod_authz_core.c>\norder deny,allow\ndeny from all";
738 $allow = "";
739 if (isset($_SERVER["REMOTE_ADDR"])) {
740 $deny .= "\nallow from ".$_SERVER["REMOTE_ADDR"];
741 $allow .= " ".$_SERVER["REMOTE_ADDR"];
742 }
743 if (isset($_SERVER["SERVER_ADDR"])) {
744 $deny .= "\nallow from ".$_SERVER["SERVER_ADDR"];
745 $allow .= " ".$_SERVER["SERVER_ADDR"];
746 }
747 $deny .= "\n</IfModule>\n<IfModule mod_authz_core.c>\nRequire";
748 if (strlen(trim($allow)) > 0)
749 $deny .= " ip$allow";
750 else
751 $deny .= " all denied";
752 $deny .= "\n</IfModule>";
753 if (count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
754 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
755 else
756 $errdiv = "<div class='error'>Unable to read Apache Version, this patch may not work!</div>";
757 $patch_action = $lt.'form method="POST" name="GOTMLS_Form_XMLRPC_patch"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."1159")).'"'.$gt.$lt.'script'.$gt."\nfunction setFirewall(opt, val) {\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_opt'))\n\t\tautoUpdateDownloadGIF.value = opt;\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_val'))\n\t\tautoUpdateDownloadGIF.value = val;\n}\nfunction testComplete() {\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_XMLRPC_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".__("You must register and donate to use this feature!",'gotmls')."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".__("This feature is available to those who have donated!",'gotmls')."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_XMLRPC_patch_searching');\n\tshowhide('GOTMLS_XMLRPC_patch_button', true);\n}\n}\nwindow.onload=testComplete;\n$lt/script$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="hidden" name="GOTMLS_XMLRPC_patching" value="';
758 $patch_found = false;
759 $head = str_replace(array('|<Files[^>]+', '(.+?)', '\\s*(', '\\s*)*|is'), array("<Files ", "$deny\n", "\n", "\n"), $find);
760 $htaccess = "";
761 if (is_file(ABSPATH.'.htaccess'))
762 if (($htaccess = @file_get_contents(ABSPATH.'.htaccess')) && strlen($htaccess))
763 $patch_found = preg_match($find, $htaccess);
764 if ($patch_found) {
765 $errdiv = "";
766 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0) && GOTMLS_file_put_contents(ABSPATH.'.htaccess', preg_replace($find, "", $htaccess)))
767 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Allowing Access';
768 elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0))
769 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Blocking: '.sprintf(__("Failed to remove XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
770 else
771 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Blocked';
772 } else {
773 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0) && GOTMLS_file_put_contents(ABSPATH.'.htaccess', "$head$htaccess")) {
774 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Blocked';
775 $errdiv = "";
776 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0))
777 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Allowing Access: '.sprintf(__("Failed to install XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
778 else
779 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Allowing Access';
780 }
781 $patch_action .= ")$errdiv$lt/b$gt$lt/p$gt".__("Most WordPress sites do not use the XMLRPC features and hack attempts on the xmlrpc.php file are more common then ever before. Even if there are no vulnerabilities for hackers to exploit, these attempts can cause slowness or downtime similar to a DDoS attack. This patch automatically blocks all external access to the xmlrpc.php file.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt.$lt.'hr /'.$gt;
782 $patch_status = 0;
783 $patch_found = -1;
784 $find = "#if\s*\(([^\&]+\&\&)?\s*file_exists\((.+?)(safe-load|wp-login)\.php'\)\)\s*require(_once)?\((.+?)(safe-load|wp-login)\.php'\);#";
785 $head = str_replace(array('#', '\\(', '\\)', '(_once)?', ')\\.', '\\s*', '(.+?)(', '|', '([^\\&]+\\&\\&)?'), array(' ', '(', ')', '_once', '.', ' ', '\''.dirname(__FILE__).'/', '/', '!in_array($_SERVER["REMOTE_ADDR"], array("'.$_SERVER["REMOTE_ADDR"].'")) &&'), $find);
786 if (is_file(ABSPATH.'../wp-config.php') && !is_file(ABSPATH.'wp-config.php'))
787 $wp_config = '../wp-config.php';
788 else
789 $wp_config = 'wp-config.php';
790 if (is_file(ABSPATH.$wp_config)) {
791 if (($config = @file_get_contents(ABSPATH.$wp_config)) && strlen($config)) {
792 if ($patch_found = preg_match($find, $config)) {
793 if (strpos($config, substr($head, strpos($head, "file_exists")))) {
794 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && GOTMLS_file_put_contents(ABSPATH.$wp_config, preg_replace('#'.$lt.'\?[ph\s]+(//.*\s*)*\?'.$gt.'#i', "", preg_replace($find, "", $config))))
795 $patch_action .= $lt.'div class="error"'.$gt.__("Removed Brute-Force Protection",'gotmls').$lt.'/div'.$gt;
796 else
797 $patch_status = 1;
798 } else {
799 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && GOTMLS_file_put_contents(ABSPATH.$wp_config, preg_replace($find, "$head", $config))) {
800 $patch_action .= $lt.'div class="updated"'.$gt.__("Upgraded Brute-Force Protection",'gotmls').$lt.'/div'.$gt;
801 $patch_status = 1;
802 } else
803 $patch_status = 2;
804 }
805 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && strlen($config) && ($patch_found == 0) && GOTMLS_file_put_contents(ABSPATH.$wp_config, "$lt?php$head// Load Brute-Force Protection by GOTMLS.NET before the WordPress bootstrap. ?$gt$config")) {
806 $patch_action .= $lt.'div class="updated"'.$gt.__("Installed Brute-Force Protection",'gotmls').$lt.'/div'.$gt;
807 $patch_status = 1;
808 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]))
809 $patch_action .= $lt.'div class="updated"'.$gt.sprintf(__("Failed to install Brute-Force Protection (wp-config.php %s)",'gotmls'),(is_readable(ABSPATH.$wp_config)?'read-'.(is_writable(ABSPATH.$wp_config)?'write':'only'):"unreadable").": ".strlen($config).GOTMLS_fileperms(ABSPATH.$wp_config)).$lt.'/div'.$gt;
810 } else
811 $patch_action .= $lt.'div class="error"'.$gt.__("wp-config.php Not Readable!",'gotmls').$lt.'/div'.$gt;
812 } else
813 $patch_action .= $lt.'div class="error"'.$gt.__("wp-config.php Not Found!",'gotmls').$lt.'/div'.$gt;
814 if ($GOTMLS_nonce_found && file_exists(ABSPATH.'wp-login.php') && ($login = @file_get_contents(ABSPATH.'wp-login.php')) && strlen($login) && (preg_match($find, $login))) {
815 if (isset($_POST["GOTMLS_patching"]) && ($source = GOTMLS_get_URL("http://core.svn.wordpress.org/tags/".GOTMLS_wp_version.'/wp-login.php')) && (strlen($source) > 500) && GOTMLS_file_put_contents(ABSPATH.'wp-login.php', $source))
816 $patch_action .= $lt.'div class="updated"'.$gt.__("Removed Old Brute-Force Login Patch",'gotmls').$lt.'/div'.$gt;
817 else
818 $patch_status = 2;
819 }
820 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_firewall_option"]) && strlen($_POST["GOTMLS_firewall_option"]) && isset($_POST["GOTMLS_firewall_value"]) && strlen($_POST["GOTMLS_firewall_value"])) {
821 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"][$_POST["GOTMLS_firewall_option"]] = $_POST["GOTMLS_firewall_value"];
822 if (update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]))
823 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";
824 else
825 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSave Failed!$lt/div$gt\n";
826 }
827 $sec_opts = $lt.'form method="POST" name="GOTMLS_Form_firewall"'.$gt.$lt.'input type="hidden" id="fw_opt" name="GOTMLS_firewall_option" value="traversal"'.$gt.$lt.'input type="hidden" name="GOTMLS_firewall_value" id="fw_val" value="0"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."805")).'"'.$gt;
828 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]) && array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]))
829 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"] as $TP => $VA)
830 if (is_array($VA) && count($VA) > 3 && strlen($VA[1]) && strlen($VA[2]))
831 $sec_opts .= $lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="submit" style="float: right;" value="'.(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]?"Enable Protection\" onclick=\"setFirewall('$TP', 0);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt."b$gt$VA[1] (Currently Disabled)":"Disable Protection\" onclick=\"setFirewall('$TP', 1);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt."b$gt$VA[1] (Automatically Enabled)")."$lt/b$gt$lt/p$gt$VA[2]$lt/div$gt$lt".'hr /'.$gt;
832 $sec_opts .= "$lt/form$gt\n$patch_action\n$lt".'form method="POST" name="GOTMLS_Form_patch"'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."807")).'"'.$gt.$lt.'input type="submit" value="'.$patch_attr[$patch_status]["action"].'" style="float: right;'.($patch_status?'"'.$gt:' display: none;" id="GOTMLS_patch_button"'.$gt.$lt.'div id="GOTMLS_patch_searching" style="float: right;"'.$gt.__("Checking for session compatibility ...",'gotmls').' '.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /'.$gt.$lt.'/div'.$gt).$lt.'input type="hidden" name="GOTMLS_patching" value="1"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$patch_attr[$patch_status]["icon"].'.gif"'.$gt.$lt.'b'.$gt.'Brute-force Protection '.$patch_attr[$patch_status]["status"].$lt.'/b'.$gt.$lt.'/p'.$gt.$patch_attr[$patch_status]["language"].__(" For more information on Brute-Force attack prevention and the WordPress wp-login-php file ",'gotmls').' '.$lt.'a target="_blank" href="http://gotmls.net/tag/wp-login-php/"'.$gt.__("read my blog",'gotmls')."$lt/a$gt.$lt/div$gt$lt/form$gt\n$lt"."script type='text/javascript'$gt\nfunction search_patch_onload() {\n\tstopCheckingSession = checkupdateserver('".GOTMLS_images_path."gotmls.js?SESSION=0', 'GOTMLS_patch_searching');\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', search_patch_onload)\nelse\n\tdocument.attachEvent('onload', search_patch_onload);\n$lt/script$gt";
833 $admin_notice = "";
834 if ($current_user->user_login == "admin") {
835 $admin_notice .= $lt.'hr /'.$gt;
836 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_admin_username"]) && ($current_user->user_login != trim($_POST["GOTMLS_admin_username"])) && strlen(trim($_POST["GOTMLS_admin_username"])) && preg_match('/^\s*[a-z_0-9\@\.\-]{3,}\s*$/i', $_POST["GOTMLS_admin_username"])) {
837 if ($wpdb->update($wpdb->users, array("user_login" => trim($_POST["GOTMLS_admin_username"])), array("user_login" => $current_user->user_login))) {
838 $wpdb->query("UPDATE `{$table_prefix}sitemeta` SET `meta_value` = REPLACE(`meta_value`, 's:5:\"admin\";', 's:".strlen(trim($_POST["GOTMLS_admin_username"])).":\"".trim($_POST["GOTMLS_admin_username"])."\";') WHERE `meta_key` = 'site_admins' AND `meta_value` like '%s:5:\"admin\";%'");
839 $admin_notice .= $lt.'div class="updated"'.$gt.sprintf(__("You username has been change to %s. Don't forget to use your new username when you login again.",'gotmls'), $_POST["GOTMLS_admin_username"]).$lt.'/div'.$gt;
840 } else
841 $admin_notice .= $lt.'div class="error"'.$gt.sprintf(__("SQL Error changing username: %s. Please try again later.",'gotmls'), $wpdb->last_error).$lt.'/div'.$gt;
842 } else {
843 if (isset($_POST["GOTMLS_admin_username"]))
844 $admin_notice .= $lt.'div class="updated"'.$gt.sprintf(__("Your new username must be at least 3 characters and can only contain &quot;%s&quot;. Please try again.",'gotmls'), "a-z0-9_.-@").$lt.'/div'.$gt;
845 $admin_notice .= $lt.'form method="POST" name="GOTMLS_Form_admin"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'div style="float: left;"'.$gt.__("Change your username:",'gotmls').$lt.'/div'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."1235")).'"'.$gt.$lt.'input style="float: left;" type="text" id="GOTMLS_admin_username" name="GOTMLS_admin_username" size="6" value="'.$current_user->user_login.'"'.$gt.$lt.'input style="float: left;" type="submit" value="Change"'.$gt.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Admin Notice'.$lt.'/b'.$gt.$lt.'/p'.$gt.__("Your username is \"admin\", this is the most commonly guessed username by hackers and brute-force scripts. It is highly recommended that you change your username immediately.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt;
846 }
847 }
848 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_wpfirewall_action"])) {
849 if ($_POST["GOTMLS_wpfirewall_action"] == "exclude_terms")
850 update_option("WP_firewall_exclude_terms", "");
851 elseif ($_POST["GOTMLS_wpfirewall_action"] == "whitelisted_ip" && isset($_SERVER["REMOTE_ADDR"])) {
852 $ips = maybe_unserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"));
853 if (is_array($ips))
854 $ips = array_merge($ips, array($_SERVER["REMOTE_ADDR"]));
855 else
856 $ips = array($_SERVER["REMOTE_ADDR"]);
857 update_option("WP_firewall_whitelisted_ip", serialize($ips));
858 }
859 }
860 if (get_option("WP_firewall_exclude_terms", "Not Found!") == "allow") {
861 $end = "$lt/div$gt$lt/form$gt\n{$lt}hr /$gt";
862 $img = 'threat.gif"';
863 $button = $lt.'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'exclude_terms\';" value="'.__("Disable this Rule",'gotmls').'"'.$gt;
864 $wpfirewall_action = $lt.'form method="POST" name="GOTMLS_Form_wpfirewall2"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="hidden" name="GOTMLS_wpfirewall_action" id="GOTMLS_wpfirewall_action" value=""'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."1223")).'"'.$gt.$button.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$img.$gt.$lt.'b'.$gt."WP Firewall 2 (Conflicting Firewall Rule)$lt/b$gt$lt/p$gt".__("The Conflicting Firewall Rule (WP_firewall_exclude_terms) activated by the WP Firewall 2 plugin has been shown to interfere with the Definition Updates and WP Core File Scans in my Anti-Malware plugin. I recommend that you disable this rule in the WP Firewall 2 plugin.",'gotmls').$end;
865 if (isset($_SERVER["REMOTE_ADDR"])) {
866 if (is_array($ips = maybe_unserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"))) && in_array($_SERVER["REMOTE_ADDR"], $ips))
867 $wpfirewall_action = str_replace(array($img, $end), array('question.gif"', __(" However, your current IP has been Whitelisted so you could probably keep this rule enabled if you really want to.",'gotmls').$end), $wpfirewall_action);
868 else
869 $wpfirewall_action = str_replace(array($button, $end), array($button.$lt."br /$gt$lt".'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'whitelisted_ip\';" value="'.__("Whitelist your IP",'gotmls').'"'.$gt, __(" However, if you would like to keep this rule enabled you should at least Whitelist your IP.",'gotmls').$end), $wpfirewall_action);
870 }
871 $sec_opts = $wpfirewall_action.$sec_opts;
872 }
873 echo GOTMLS_box(__("Firewall Options",'gotmls'), $save_action.$sec_opts.$admin_notice)."\n</div></div></div>";
874 }
875
876 function GOTMLS_get_registrant($you) {
877 global $current_user, $wpdb;
878 wp_get_current_user();
879 if (isset($you["you"]))
880 $you = $you["you"];
881 if (isset($you["user_email"]) && strlen($you["user_email"]) == 32) {
882 if ($you["user_email"] == md5($current_user->user_email))
883 $registrant = $current_user->user_email;
884 elseif (!($registrant = $wpdb->get_var("SELECT `user_nicename` FROM `$wpdb->users` WHERE MD5(`user_email`) = '".$you["user_email"]."'")))
885 $registrant = GOTMLS_siteurl;
886 } else
887 $registrant = GOTMLS_siteurl;
888 return $registrant;
889 }
890
891 function GOTMLS_ajax_auto_update() {
892 global $wpdb;
893 $GOTMLS_definitions_versions = array();
894 $user_info = array();
895 $saved = false;
896 $moreJS = "";
897 $finJS = "\n}";
898 $form = 'registerKeyForm';
899 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key could not be confirmed!</li>";
900 $autoUpJS = '<span style="color: #C00;">This new feature is currently only available to registered users who have donated above the default level.</span><br />';
901 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names)
902 foreach ($definition_names as $definition_name=>$definition_version)
903 if (is_array($definition_version) && isset($definition_version[0]) && strlen($definition_version[0]) == 5)
904 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
905 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
906 asort($GOTMLS_definitions_versions);
907 if (isset($_REQUEST["UPDATE_definitions_array"]) && strlen($_REQUEST["UPDATE_definitions_array"]) && GOTMLS_get_nonce()) {
908 $DEF_url = 'http:'.GOTMLS_update_home.'definitions.php?ver='.GOTMLS_Version.'&wp='.GOTMLS_wp_version.'&'.GOTMLS_set_nonce(__FUNCTION__."870").'&d='.ur1encode(GOTMLS_siteurl);
909 if (strlen($_REQUEST["UPDATE_definitions_array"]) > 1) {
910 $GOTnew_definitions = maybe_unserialize(GOTMLS_decode($_REQUEST["UPDATE_definitions_array"]));
911 if (is_array($GOTnew_definitions)) {
912 $form = 'autoUpdateDownload';
913 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('Downloaded Definitions');";
914 }
915 } elseif ($_REQUEST["UPDATE_definitions_array"] == "D") {
916 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = array();
917 $GOTnew_definitions = array();
918 } elseif (($DEF = GOTMLS_get_URL($DEF_url)) && is_array($GOTnew_definitions = maybe_unserialize(GOTMLS_decode($DEF))) && count($GOTnew_definitions)) {
919 if (isset($GOTnew_definitions["you"]["user_email"]) && strlen($GOTnew_definitions["you"]["user_email"]) == 32) {
920 $toInfo = GOTMLS_get_registrant($GOTnew_definitions["you"]);
921 $innerHTML = "<li style=\\\"color: #0C0\\\">Your Installation Key is Registered to:<br /> $toInfo</li>";
922 $form = 'autoUpdateForm';
923 if (isset($GOTnew_definitions["you"]["user_donations"]) && isset($GOTnew_definitions["you"]["user_donation_total"]) && isset($GOTnew_definitions["you"]["user_donation_freshness"])) {
924 $user_donations_src = $GOTnew_definitions["you"]["user_donations"];
925 if ($GOTnew_definitions["you"]["user_donation_total"] > 27.99) {
926 $autoUpJS = '<input type="radio" id="auto_UPDATE_definitions_1" name="UPDATE_definitions_array" value="1">Yes | <input type="radio" id="auto_UPDATE_definitions_0" name="UPDATE_definitions_array" value="0" checked>No <input type="hidden" name="UPDATE_definitions_checkbox" value="UPDATE_definitions_array">';
927 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
928 foundUpdates.innerHTML = "<a href=\'javascript:document.getElementById(\\"GOTMLS_Form\\").submit();\' onclick=\'document.getElementById(\\"auto_UPDATE_definitions_1\\").checked=true;\' style=\'color: #f00;\'>Set Definition Updates to Automatically Download to activate this feature.</a>";';
929 }
930 if ($user_donations_src > 0 && $GOTnew_definitions["you"]["user_donation_total"] > 0)
931 $li = "<li> You have made $user_donations_src donation".($user_donations_src?'s totalling':' for').' $'.$GOTnew_definitions["you"]["user_donation_total"].".</li><!-- ".$GOTnew_definitions["you"]["user_donation_freshness"]." -->";
932 }
933 } else
934 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key is not registered!</li>";
935 asort($GOTnew_definitions);
936 if (serialize($GOTnew_definitions) == serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
937 unset($GOTnew_definitions);
938 else {
939 $debug = substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), 0, 9)." ".md5(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".strlen(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), -9)." = ".substr(serialize($GOTnew_definitions), 0, 9)." ".md5(serialize($GOTnew_definitions))." ".strlen(serialize($GOTnew_definitions)." ".substr(serialize($GOTnew_definitions), -9));
940 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = $GOTnew_definitions;
941 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('New Definitions Automatically Installed :-)');";
942 }
943 $finJS .= "\nif (divNAtext)\n\tloadGOTMLS();\nelse\n\tdivNAtext = setTimeout('loadGOTMLS()', 4000);";
944 $finJS .= "\nif (typeof stopCheckingDefinitions !== 'undefined')\n\tclearTimeout(stopCheckingDefinitions);";
945 } else
946 $innerHTML = "<li style=\\\"color: #f00\\\"><a title='report error' href='#' onclick=\\\"stopCheckingDefinitions = checkupdateserver(alt_addr+'&error=".GOTMLS_encode(serialize(array("get_URL"=>$GLOBALS["GOTMLS"]["get_URL"])))."', 'Definition_Updates');\\\">Automatic Update Connection Failed!</a></li>";
947 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]))
948 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]);
949 } else
950 $innerHTML = "<li style=\\\"color: #f00\\\">".GOTMLS_Invalid_Nonce("Nonce Error")."</li>";
951 if (isset($GOTnew_definitions) && is_array($GOTnew_definitions)) {
952 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = GOTMLS_array_replace($GLOBALS["GOTMLS"]["tmp"]["definitions_array"], $GOTnew_definitions);
953 if (file_exists(GOTMLS_plugin_path.'definitions_update.txt'))
954 @unlink(GOTMLS_plugin_path.'definitions_update.txt');
955 $saved = GOTMLS_update_option('definitions', $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]);
956 $_REQUEST["check"] = array();
957 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names) {
958 if ($threat_level != "potential")
959 $_REQUEST["check"][] = $threat_level;
960 foreach ($definition_names as $definition_name=>$definition_version)
961 if (is_array($definition_version) && isset($definition_version[0]) && strlen($definition_version[0]) == 5)
962 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
963 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
964 }
965 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = $_REQUEST["check"];
966 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $_REQUEST["check"];
967 asort($GOTMLS_definitions_versions);
968 $autoUpJS .= '<span style="color: #0C0;">(Newest Definition Updates Installed.)</span>';
969 } elseif ($form != 'registerKeyForm') {
970 $form = 'autoUpdateDownload';
971 $autoUpJS .= '<span style="color: #0C0;">(No newer Definition Updates are available at this time.)</span>';
972 $innerHTML .= "<li style=\\\"color: #0C0\\\">No Newer Definition Updates Available.</li>";
973 }
974 if (isset($_SERVER["SCRIPT_FILENAME"]) && preg_match('/\/admin-ajax\.php/i', $_SERVER["SCRIPT_FILENAME"]) && isset($_REQUEST["action"]) && $_REQUEST["action"] == "GOTMLS_auto_update") {
975 if (!$user_donations_src)
976 $li = "<li style=\\\"color: #f00;\\\">You have not donated yet!</li>";
977 if (strlen($moreJS) == 0)
978 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
979 foundUpdates.innerHTML = "<a href=\'javascript:document.ppdform.submit();\' onclick=\'document.ppdform.amount.value=32;\' style=\'color: #f00;\'>Donate $29+ now then enable Automatic Definition Updates to Scan for Core Files changes.</a>";';
980 $moreJS .= "\n\tif (foundUpdates = document.getElementById('pastDonations'))\n\tfoundUpdates.innerHTML = '$li';";
981 @header("Content-type: text/javascript");
982 if (is_array($GOTMLS_definitions_versions) && count($GOTMLS_definitions_versions) && (strlen($new_ver = trim(array_pop($GOTMLS_definitions_versions))) == 5) && $saved) {
983 $innerHTML .= "<li style=\\\"color: #0C0\\\">New Definition Updates Installed.</li>";
984 $finJS .= "\nif (foundUpdates = document.getElementById('GOTMLS_definitions_date')) foundUpdates.innerHTML = '$new_ver';";
985 } elseif (is_array($GOTnew_definitions) && count($GOTnew_definitions))
986 $finJS .= "\nalert('Definition update $new_ver could not be saved because update_option Failed! $debug');";
987 if (isset($_REQUEST["UPDATE_core"]) && ($_REQUEST["UPDATE_core"] == GOTMLS_wp_version) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version])) {
988 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][$_REQUEST["UPDATE_core"]] as $file => $md5) {
989 if (is_file(ABSPATH.$file)) {
990 $GLOBALS["GOTMLS"]["tmp"]["file_contents"] = file_get_contents(ABSPATH.$file);
991 if (GOTMLS_check_threat($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"], ABSPATH.$file)) {
992 if (isset($GLOBALS["GOTMLS"]["tmp"]["new_contents"]) && isset($_REQUEST["UPDATE_restore"]) && (md5($GLOBALS["GOTMLS"]["tmp"]["new_contents"])."O".strlen($GLOBALS["GOTMLS"]["tmp"]["new_contents"]) == $_REQUEST["UPDATE_restore"]))
993 $autoUpJS .= "<li>Core File Restored: $file</li>";
994 else
995 $autoUpJS .= "<li>Core File MODIFIED: $file (".md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"])."O".strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"])." => $md5)</li>";
996 }
997 } else
998 $autoUpJS .= "<li>Core File MISSING: $file</li>";
999 }
1000 $autoUpJS .= '<div class="update">Definition update: '.$_REQUEST["UPDATE_core"].' checked '.count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][$_REQUEST["UPDATE_core"]]).' core files!</div>';
1001 }
1002 die('//<![CDATA[
1003 var inc_form = "";
1004 if (foundUpdates = document.getElementById("autoUpdateDownload"))
1005 foundUpdates.src += "?'.$user_donations_src.'";
1006 if (foundUpdates = document.getElementById("registerKeyForm"))
1007 foundUpdates.style.display = "none";
1008 if (foundUpdates = document.getElementById("'.$form.'"))
1009 foundUpdates.style.display = "block";
1010 if (foundUpdates = document.getElementById("Definition_Updates"))
1011 foundUpdates.innerHTML = "<ul class=\\"sidebar-links\\">'.$innerHTML.'</ul>"+inc_form;
1012 function setDivNAtext() {
1013 var foundUpdates;
1014 '.$moreJS.$finJS.'
1015 if (foundUpdates = document.getElementById("UPDATE_definitions_div"))
1016 foundUpdates.innerHTML = \''.$autoUpJS.'\';
1017 //]]>');
1018 }
1019 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] = '?div=Definition_Updates';
1020 foreach ($GOTMLS_definitions_versions as $definition_name=>$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"])
1021 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[$definition_name]=".$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"];
1022 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)
1023 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[you]=".$GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
1024 }
1025
1026 function GOTMLS_settings() {
1027 global $wpdb, $GOTMLS_dirs_at_depth, $GOTMLS_dir_at_depth;
1028 $GOTMLS_scan_groups = array();
1029 $gt = ">";
1030 $lt = "<";
1031 GOTMLS_ajax_auto_update();
1032 if (($GOTMLS_nonce_found = GOTMLS_get_nonce()) && isset($_REQUEST["check"]) && is_array($_REQUEST["check"]))
1033 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $_REQUEST["check"];
1034 /* removed old code */
1035 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"])) {
1036 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
1037 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1038 }
1039 $dirs = GOTMLS_explode_dir(__FILE__);
1040 for ($SL=0;$SL<intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);$SL++)
1041 $GOTMLS_scan_groups[] = $lt.'b'.$gt.implode(GOTMLS_slash(), array_slice($dirs, -1 * (3 + $SL), 1)).$lt.'/b'.$gt;
1042 if (isset($_POST["exclude_ext"])) {
1043 if (strlen(trim(str_replace(",","",$_POST["exclude_ext"]).' ')) > 0)
1044 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(str_replace('.', ',', GOTMLS_htmlentities($_POST["exclude_ext"]))), -1, PREG_SPLIT_NO_EMPTY);
1045 else
1046 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = array();
1047 }
1048 $default_exclude_ext = str_replace(",gotmls", "", implode(",", $GLOBALS["GOTMLS"]["tmp"]["skip_ext"]));
1049 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
1050 if (isset($_POST["UPDATE_definitions_checkbox"])) {
1051 if (isset($_POST[$_POST["UPDATE_definitions_checkbox"]]) && strlen(trim(" ".$_POST[$_POST["UPDATE_definitions_checkbox"]])))
1052 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = $_POST[$_POST["UPDATE_definitions_checkbox"]];
1053 else
1054 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = "";
1055 }
1056 if (isset($_POST["exclude_dir"])) {
1057 if (strlen(trim(str_replace(",","",$_POST["exclude_dir"]).' ')) > 0)
1058 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(GOTMLS_htmlentities($_POST["exclude_dir"])), -1, PREG_SPLIT_NO_EMPTY);
1059 else
1060 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = array();
1061 for ($d=0; $d<count($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]); $d++)
1062 if (dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]) != ".")
1063 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d] = str_replace("\\", "", str_replace("/", "", str_replace(dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]), "", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d])));
1064 }
1065 $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"] = array_merge($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"], $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"]);
1066 if (isset($_POST["scan_what"]) && is_numeric($_POST["scan_what"]) && $_POST["scan_what"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"])
1067 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = $_POST["scan_what"];
1068 if (isset($_POST["check_custom"]) && $_POST["check_custom"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"])
1069 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = stripslashes($_POST["check_custom"]);
1070 if (isset($_POST["scan_depth"]) && is_numeric($_POST["scan_depth"]) && $_POST["scan_depth"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])
1071 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = $_POST["scan_depth"];
1072 /* removed old code */
1073 if (isset($_POST['skip_quarantine']) && $_POST['skip_quarantine'])
1074 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = $_POST['skip_quarantine'];
1075 elseif (isset($_POST["exclude_ext"]))
1076 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = 0;
1077 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1078 $scan_whatopts = '';
1079 $scan_optjs = "\n{$lt}script type=\"text/javascript\"$gt\nfunction showOnly(what) {\n";
1080 foreach ($GOTMLS_scan_groups as $mg => $GOTMLS_scan_group) {
1081 $scan_optjs .= "document.getElementById('only$mg').style.display = 'none';\n";
1082 $scan_whatopts = "\n$lt/div$gt\n$lt/div$gt\n$scan_whatopts";
1083 $dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + $mg)));
1084 $files = GOTMLS_getfiles($dir);
1085 if (is_array($files))
1086 foreach ($files as $file)
1087 if (is_dir(GOTMLS_trailingslashit($dir).$file))
1088 $scan_whatopts = $lt.'input type="checkbox" name="scan_only[]" value="'.GOTMLS_htmlentities($file).'" /'.$gt.GOTMLS_htmlentities($file).$lt.'br /'.$gt.$scan_whatopts;
1089 $scan_whatopts = "\n$lt".'div style="padding: 4px 30px;" id="scan_group_div_'.$mg.'"'.$gt.$lt.'input type="radio" name="scan_what" id="not-only'.$mg.'" value="'.$mg.'"'.($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]==$mg?' checked':'').' /'.$gt.$lt.'a style="text-decoration: none;" href="#scan_what" onclick="showOnly(\''.$mg.'\');document.getElementById(\'not-only'.$mg.'\').checked=true;"'."$gt$GOTMLS_scan_group$lt/a$gt{$lt}br /$gt\n$lt".'div class="rounded-corners" style="position: absolute; display: none; background-color: #CCF; margin: 0; padding: 10px; z-index: 10;" id="only'.$mg.'"'.$gt.$lt.'div style="padding-bottom: 6px;"'.$gt.GOTMLS_close_button('only'.$mg, 0).$lt.'b'.$gt.str_replace(" ", "&nbsp;", __("Only Scan These Folders:",'gotmls')).$lt.'/b'.$gt.$lt.'/div'.$gt.$scan_whatopts;
1090 }
1091 $scan_optjs .= "document.getElementById('only'+what).style.display = 'block';\n}";
1092 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && strlen(trim(" ".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])))
1093 $scan_optjs .= "\nfunction auto_UPDATE_check() {\n\tif (auto_UPdef_check = document.getElementById('auto_UPDATE_definitions_".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]."'))\n\t\tauto_UPdef_check.checked = true;\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', auto_UPDATE_check)\nelse\n\tdocument.attachEvent('onload', auto_UPDATE_check);\n";
1094 $scan_optjs .= "$lt/script$gt";
1095 $GOTMLS_nonce_URL = GOTMLS_set_nonce(__FUNCTION__."853");
1096 $scan_opts = "\n$lt".'form method="POST" id="GOTMLS_Form" name="GOTMLS_Form"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', $GOTMLS_nonce_URL).'"'.$gt.$lt.'input type="hidden" name="scan_type" id="scan_type" value="Complete Scan" /'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="submit" id="complete_scan" value="'.__("Run Complete Scan",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Complete Scan\';" /'.$gt.$lt.'/div'.$gt.'
1097 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to look for:",'gotmls').$lt.'/b'.$gt.$lt.'/p'.$gt.'
1098 '.$lt.'div style="padding: 0 30px;"'.$gt;
1099 $cInput = '"'.$gt.$lt.'input';
1100 $pCheck = "$cInput checked";
1101 $kCheck = "";
1102 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $threat_level_name=>$threat_level) {
1103 $scan_opts .= $lt.'div id="check_'.$threat_level.'_div" style="padding: 0; position: relative;';
1104 if (($threat_level != "wp_core" && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level])) || isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level][GOTMLS_wp_version])) {
1105 if ($threat_level != "potential" && in_array($threat_level,$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"])) {
1106 $pCheck = " display: none;$cInput";
1107 $scan_opts .= "$cInput checked";
1108 } elseif ($threat_level == "potential")
1109 $scan_opts .= $pCheck;
1110 else
1111 $scan_opts .= $cInput;
1112 if ($threat_level != "potential")
1113 $kCheck .= ",'$threat_level'";
1114 $scan_opts .= ' type="checkbox" onchange="pCheck(this);" name="check[]" id="check_'.$threat_level.'_Yes" value="'.$threat_level.'" /'.$gt.' '.$lt.'a style="text-decoration: none;" href="#check_'.$threat_level.'_div_0" onclick="document.getElementById(\'check_'.$threat_level.'_Yes\').checked=true;pCheck(document.getElementById(\'check_'.$threat_level.'_Yes\'));showhide(\'dont_check_'.$threat_level.'\');"'."$gt{$lt}b$gt$threat_level_name$lt/b$gt$lt/a$gt\n";
1115 if (isset($_GET["SESSION"])) {
1116 $scan_opts .= "\n$lt".'div style="padding: 0 20px; position: relative; top: -18px; display: none;" id="dont_check_'.$threat_level.'"'.$gt.$lt.'a class="rounded-corners" style="position: absolute; left: 0; margin: 0; padding: 0 4px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;" href="#check_'.$threat_level.'_div_0" onclick="showhide(\'dont_check_'.$threat_level.'\');"'.$gt.'X'.$lt.'/a'.$gt;
1117 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level] as $threat_name => $threat_regex)
1118 $scan_opts .= $lt."br /$gt\n$lt".'input type="checkbox" name="dont_check[]" value="'.GOTMLS_htmlspecialchars($threat_name).'"'.(in_array($threat_name, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])?' checked /'.$gt.$lt.'script'.$gt.'showhide("dont_check_'.$threat_level.'", true);'.$lt.'/script'.$gt:' /'.$gt).(isset($_SESSION["GOTMLS_debug"][$threat_name])?$lt.'div style="float: right;"'.$gt.print_r($_SESSION["GOTMLS_debug"][$threat_name],1)."$lt/div$gt":"").GOTMLS_htmlspecialchars($threat_name);
1119 $scan_opts .= "\n$lt/div$gt";
1120 }
1121 } else
1122 $scan_opts .= $lt.'a title="'.__("Download Definition Updates to Use this feature",'gotmls').'"'.$gt.$lt.'img src="'.GOTMLS_images_path.'blocked.gif" height=16 width=16 alt="X"'.$gt.$lt.'b'.$gt.'&nbsp; '.$threat_level_name.$lt.'/b'.$gt.$lt.'br /'.$gt.$lt.'div style="padding: 14px;" id="check_'.$threat_level.'_div_NA"'.$gt.$lt.'span style="color: #F00"'.$gt.__("Download the new definitions (Right sidebar) to activate this feature.",'gotmls')."$lt/span$gt$lt/div$gt";
1123 $scan_opts .= "\n$lt/div$gt";
1124 }
1125 $scan_opts .= $lt.'/div'.$gt.$lt.'/div'.$gt.'
1126 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to scan:",'gotmls').$lt.'/b'.$gt.$lt.'/p'.$gt.$scan_whatopts.$scan_optjs.$lt.'/div'.$gt.'
1127 '.$lt.'div style="float: left;" id="scanwhatfolder"'.$gt.$lt.'/div'.$gt.'
1128 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Scan Depth:",'gotmls').$lt.'/b'.$gt.$lt.'/p'.$gt.'
1129 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" value="'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"].'" name="scan_depth" size="5"'.$gt.$lt.'br /'.$gt.__("how far to drill down",'gotmls').$lt.'br /'.$gt.'('.__("-1 is infinite depth",'gotmls').')'.$lt.'/div'.$gt.$lt.'/div'.$gt.$lt.'br style="clear: left;"'.$gt;
1130 if (isset($_GET["SESSION"]) && isset($_SESSION["GOTMLS_debug"]['total'])) {$scan_opts .= $lt.'div style="float: right;"'.$gt.print_r($_SESSION["GOTMLS_debug"]['total'],1)."$lt/div$gt"; unset($_SESSION["GOTMLS_debug"]);}
1131 if (isset($_GET["eli"])) {//still testing this option
1132 if ($_GET["eli"] == "find") {
1133 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && (count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) > 1)) {
1134 $fe = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][0];
1135 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][1];
1136 } else {
1137 $fe = " no";
1138 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"] as $f => $e)
1139 if (is_array($e) && in_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"], $e))
1140 $fe = " $f";
1141 }
1142 } else
1143 $fe = "";
1144 $scan_opts .= "\n$lt".'div style="padding: 10px;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Custom RegExp:",'gotmls').$fe.$lt.'/b'.$gt.' ('.__("For very advanced users only. Do not use this without talking to Eli first. If used incorrectly you could easily break your site.",'gotmls').')'.$lt.'/p'.$gt.$lt.'input type="text" name="check_custom" style="width: 100%;" value="'.GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]).'" /'."$gt$lt/div$gt\n";
1145 }
1146 $QuickScan = $lt.((is_dir(dirname(__FILE__)."/../../../wp-includes") && is_dir(dirname(__FILE__)."/../../../wp-admin"))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&$GOTMLS_nonce_URL").'" class="button-primary" style="height: 22px; line-height: 13px; padding: 3px;">WP_Core</a':"!-- No wp-includes or wp-admin --").$gt;
1147 foreach (array("Plugins", "Themes") as $ScanFolder)
1148 $QuickScan .= '&nbsp;'.$lt.((is_dir(dirname(__FILE__)."/../../../wp-content/".strtolower($ScanFolder)))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&scan_only[]=wp-content/".strtolower($ScanFolder)."&$GOTMLS_nonce_URL")."\" class=\"button-primary\" style=\"height: 22px; line-height: 13px; padding: 3px;\"$gt$ScanFolder$lt/a":"!-- No $ScanFolder in wp-content --").$gt;
1149 $scan_opts .= "\n$lt".'p'.$gt.$lt.'b'.$gt.__("Skip files with the following extensions:",'gotmls')."$lt/b$gt".(($default_exclude_ext!=implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))?" {$lt}a href=\"javascript:void(0);\" onclick=\"document.getElementById('exclude_ext').value = '$default_exclude_ext';\"{$gt}[Restore Defaults]$lt/a$gt":"").$lt.'/p'.$gt.'
1150 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a comma separated list of file extentions to skip",'gotmls').'" name="exclude_ext" id="exclude_ext" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]).'" style="width: 100%;" /'."$gt$lt/div$gt$lt".'p'.$gt.$lt.'b'.$gt.__("Skip directories with the following names:",'gotmls')."$lt/b$gt$lt/p$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a folder name or comma separated list of folder names to skip",'gotmls').'" name="exclude_dir" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]).'" style="width: 100%;" /'.$gt.$lt.'/div'.$gt.'
1151 '.$lt.'table style="width: 100%" cellspacing="10"'.$gt.$lt.'tr'.$gt.$lt.'td nowrap valign="top" style="white-space: nowrap; width: 1px;"'.$gt.$lt.'b'.$gt.__("Automatically Update Definitions:",'gotmls').$lt."br$gt$lt/b$gt$lt/td$gt$lt".'td'.$gt.$lt.'div id="UPDATE_definitions_div"'.$gt.$lt.'br'.$gt.$lt.'span style="color: #C00;"'.$gt.__("This feature is only available to registered users who have donated at a certain level.",'gotmls')."$lt/span$gt$lt/div$gt$lt/td$gt$lt".'td align="right" valign="bottom"'.$gt.$lt.'input type="submit" id="save_settings" value="'.__("Save Settings",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Save\';" /'."$gt$lt/td$gt$lt/tr$gt$lt/table$gt$lt/form$gt";
1152 $title_tagline = $lt."li$gt Site Title: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogname'"));
1153 $title_tagline .= "$lt/li$gt$lt"."li$gt Tagline: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogdescription'"));
1154 if (preg_match('/h[\@a]ck[3e]d.*by/is', $title_tagline))
1155 echo $lt.'div class="error"'.$gt.sprintf(__("Your Site Title or Tagline suggests that you may have been hacked ...%sThis could impact the indexing of your site and may even lead to blacklisting. You can change those options on the %sGeneral Settings$lt/a$gt page.",'gotmls'), "$title_tagline$lt/li$gt", $lt.'a href="'.admin_url("options-general.php").'"'.$gt)."$lt/div$gt";
1156 @ob_start();
1157 $OB_default_handlers = array("default output handler", "zlib output compression");
1158 $OB_handlers = @ob_list_handlers();
1159 if (is_array($OB_handlers) && count($OB_handlers))
1160 foreach ($OB_handlers as $OB_last_handler)
1161 if (!in_array($OB_last_handler, $OB_default_handlers))
1162 echo $lt.'div class="error"'.$gt.sprintf(__("Another Plugin or Theme is using '%s' to handle output buffers. <br />This prevents actively outputing the buffer on-the-fly and could severely degrade the performance of this (and many other) Plugins. <br />Consider disabling caching and compression plugins (at least during the scanning process).",'gotmls'), $OB_last_handler)."$lt/div$gt";
1163 GOTMLS_display_header();
1164 $scan_groups = array_merge(array(__("Scanned Files",'gotmls')=>"scanned",__("Selected Folders",'gotmls')=>"dirs",__("Scanned Folders",'gotmls')=>"dir",__("Skipped Folders",'gotmls')=>"skipdirs",__("Skipped Files",'gotmls')=>"skipped",__("Read/Write Errors",'gotmls')=>"errors",__("Quarantined Files",'gotmls')=>"bad"), $GLOBALS["GOTMLS"]["tmp"]["threat_levels"]);
1165 echo $lt.'script type="text/javascript">
1166 var percent = 0;
1167 function pCheck(chkb) {
1168 var kCheck = ['.trim($kCheck,",").'];
1169 chk = true;
1170 for (var i = 0; i < kCheck.length; i++) {
1171 var chkbox = document.getElementById("check_"+kCheck[i]+"_Yes");
1172 if (chkbox && chkb.id == "check_potential_Yes" && chkb.checked == false) {
1173 chk = false;
1174 chkbox.checked = true;
1175 } else if (chkbox && chkbox.checked) {
1176 chk = false;
1177 }
1178 }
1179 if (chkbox = document.getElementById("check_potential_Yes"))
1180 chkbox.checked = chk;
1181 if (chk) {
1182 document.getElementById("check_potential_div").style.display = "block";
1183 alert("If you do not select any other threat types, then only potential threats will be found and the automatic fix will not be available!");
1184 } else
1185 document.getElementById("check_potential_div").style.display = "none";
1186 }
1187 function changeFavicon(percent) {
1188 var oldLink = document.getElementById("wait_gif");
1189 if (oldLink) {
1190 if (percent >= 100) {
1191 document.getElementsByTagName("head")[0].removeChild(oldLink);
1192 var link = document.createElement("link");
1193 link.id = "wait_gif";
1194 link.type = "image/gif";
1195 link.rel = "shortcut icon";
1196 var threats = '.implode(" + ", array_merge($GLOBALS["GOTMLS"]["tmp"]["threat_levels"], array(__("Potential Threats",'gotmls')=>"errors",__("WP-Login Updates",'gotmls')=>"errors"))).';
1197 if (threats > 0) {
1198 if ((errors * 2) == threats)
1199 linkhref = "blocked";
1200 else
1201 linkhref = "threat";
1202 } else
1203 linkhref = "checked";
1204 link.href = "'.GOTMLS_images_path.'"+linkhref+".gif";
1205 document.getElementsByTagName("head")[0].appendChild(link);
1206 }
1207 } else {
1208 var icons = document.getElementsByTagName("link");
1209 var link = document.createElement("link");
1210 link.id = "wait_gif";
1211 link.type = "image/gif";
1212 link.rel = "shortcut icon";
1213 link.href = "'.GOTMLS_images_path.'wait.gif";
1214 // document.head.appendChild(link);
1215 document.getElementsByTagName("head")[0].appendChild(link);
1216 }
1217 }
1218 function update_status(title, time) {
1219 sdir = (dir+direrrors);
1220 if (arguments[2] >= 0 && arguments[2] <= 100)
1221 percent = arguments[2];
1222 else
1223 percent = Math.floor((sdir*100)/dirs);
1224 scan_state = "6F6";
1225 if (percent == 100) {
1226 showhide("pause_button", true);
1227 showhide("pause_button");
1228 title = "'.$lt.'b'.$gt.__("Scan Complete!",'gotmls').$lt.'/b'.$gt.'";
1229 } else
1230 scan_state = "99F";
1231 changeFavicon(percent);
1232 if (sdir) {
1233 if (arguments[2] >= 0 && arguments[2] <= 100)
1234 timeRemaining = Math.ceil(((time-startTime)*(100/percent))-(time-startTime));
1235 else
1236 timeRemaining = Math.ceil(((time-startTime)*(dirs/sdir))-(time-startTime));
1237 if (timeRemaining > 59)
1238 timeRemaining = Math.ceil(timeRemaining/60)+" Minute";
1239 else
1240 timeRemaining += " Second";
1241 if (timeRemaining.substr(0, 2) != "1 ")
1242 timeRemaining += "s";
1243 } else
1244 timeRemaining = "Calculating Time";
1245 timeElapsed = Math.ceil(time);
1246 if (timeElapsed > 59)
1247 timeElapsed = Math.floor(timeElapsed/60)+" Minute";
1248 else
1249 timeElapsed += " Second";
1250 if (timeElapsed.substr(0, 2) != "1 ")
1251 timeElapsed += "s";
1252 divHTML = \''.$lt.'div align="center" style="vertical-align: middle; background-color: #ccc; z-index: 3; height: 18px; width: 100%; border: solid #000 1px; position: relative; padding: 10px 0;"'.$gt.$lt.'div style="height: 18px; padding: 10px 0; position: absolute; top: 0px; left: 0px; background-color: #\'+scan_state+\'; width: \'+percent+\'%"'.$gt.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; left: 10px; z-index: 5; line-height: 16px;" align="left"'.$gt.'\'+sdir+" Folder"+(sdir==1?"":"s")+" Checked'.$lt.'br /'.$gt.'"+timeElapsed+\' Elapsed'.$lt.'/div'.$gt.$lt.'div style="height: 38px; position: absolute; top: 0px; left: 0px; width: 100%; z-index: 5; line-height: 38px; font-size: 30px; text-align: center; box-sizing: content-box;"'.$gt.'\'+percent+\'%'.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; right: 10px; z-index: 5; line-height: 16px;" align="right"'.$gt.'\'+(dirs-sdir)+" Folder"+((dirs-sdir)==1?"":"s")+" Remaining'.$lt.'br /'.$gt.'"+timeRemaining+" Remaining'.$lt.'/div'.$gt.$lt.'/div'.$gt.'";
1253 document.getElementById("status_bar").innerHTML = divHTML;
1254 document.getElementById("status_text").innerHTML = title;
1255 dis="none";
1256 divHTML = \''.$lt.'ul style="float: right; margin: 0 20px; text-align: right;"'.$gt.'\';
1257 /*'.$lt.'!--*'.'/';
1258 $MAX = 0;
1259 $vars = "var i, intrvl, direrrors=0";
1260 $fix_button_js = "";
1261 $found = "";
1262 $li_js = "return false;";
1263 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Quick Scan") {
1264 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
1265 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1266 if ($check != "potential")
1267 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $check;
1268 }
1269 foreach ($scan_groups as $scan_name => $scan_group) {
1270 if ($MAX++ == 6) {
1271 $quarantineCountOnly = GOTMLS_get_quarantine(true);
1272 $vars .= ", $scan_group=$quarantineCountOnly";
1273 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0)\n\t\tscan_state = ' potential'; \n\telse\n\t\tscan_state = '';\n\tdivHTML += '</ul><ul style=\"text-align: left;\"><li class=\"GOTMLS_li\"><a href=\"admin.php?page=GOTMLS-View-Quarantine\" class=\"GOTMLS_plugin".("'+scan_state+'\" title=\"".GOTMLS_strip4java(GOTMLS_View_Quarantine_LANGUAGE))."\">'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
1274 $found = "Found ";
1275 $fix_button_js = "\n\t\tdis='block';";
1276 } else {
1277 $val = 0;
1278 if ($found && !in_array($scan_group, $GLOBALS["GOTMLS"]["log"]["settings"]["check"]))
1279 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("You are not currently scanning for this type of threat!",'gotmls'));
1280 else
1281 $potential_threat = "";
1282 $vars .= ", $scan_group=$val";
1283 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0) {\n\t\tscan_state = ' href=\"#found_$scan_group\" onclick=\"$li_js showhide(\\'found_$scan_group\\', true);\" class=\"GOTMLS_plugin $scan_group\"';$fix_button_js".($MAX>6?"\n\tshowhide('found_$scan_group', true);":"")."\n\t} else\n\t\tscan_state = ' class=\"GOTMLS_plugin$potential_threat\"';\n\tdivHTML += '<li class=\"GOTMLS_li\"".(($found && $scan_group == "potential" && !in_array($scan_group, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))?' style="display: none;"':"")."><a'+scan_state+'>$found'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
1284 }
1285 $li_js = "";
1286 if ($MAX > 11)
1287 $fix_button_js = "";
1288 }
1289 $ScanSettings = $lt.'div style="float: right;"'.$gt.GOTMLS_Run_Quick_Scan_LANGUAGE.":&nbsp;$QuickScan$lt/div$gt".GOTMLS_Scan_Settings_LANGUAGE;
1290 echo "/*--{$gt}*".'/
1291 document.getElementById("status_counts").innerHTML = divHTML+"'.$lt.'/ul'.$gt.'";
1292 document.getElementById("fix_button").style.display = dis;
1293 }
1294 '.$vars.';
1295 function showOnly(what) {
1296 document.getElementById("only_what").innerHTML = document.getElementById("only"+what).innerHTML;
1297 }
1298 var startTime = 0;
1299 '.$lt.'/script'.$gt.GOTMLS_box($ScanSettings, $scan_opts);
1300 $Settings_Saved = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -50px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";//script type='text/javascript'$gt\nalert('Settings Saved!');\n$lt/script$gt\n";
1301 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Save") {
1302 if ($GOTMLS_nonce_found) {
1303 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1304 echo $Settings_Saved;
1305 } else
1306 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Saving these settings requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1307 echo GOTMLS_box(__("Scan Logs",'gotmls'), GOTMLS_get_scanlog());
1308 } elseif (isset($_REQUEST["scan_what"]) && is_numeric($_REQUEST["scan_what"]) && ($_REQUEST["scan_what"] > -1)) {
1309 if ($GOTMLS_nonce_found) {
1310 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1311 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
1312 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1313 $cleadCache = false;
1314 if (function_exists('is_plugin_active')) {
1315 if (function_exists('wp_cache_clear_cache')) {
1316 wp_cache_clear_cache();
1317 $cleadCache = true;
1318 }
1319 if (function_exists('w3tc_pgcache_flush')) {
1320 w3tc_pgcache_flush();
1321 $cleadCache = true;
1322 }
1323 if (class_exists('WpFastestCache')) {
1324 $newCache = new WpFastestCache();
1325 $newCache->deleteCache();
1326 $cleadCache = true;
1327 }
1328
1329 }
1330 if ($cleadCache)
1331 str_replace("Settings Saved!", "Cache Cleared and Settings Saved!", $Settings_Saved);
1332 echo $Settings_Saved;
1333 if (!isset($_REQUEST["scan_type"]))
1334 $_REQUEST["scan_type"] = "Complete Scan";
1335 elseif ($_REQUEST["scan_type"] == "Quick Scan") {
1336 $li_js = "\nfunction testComplete() {\n\tif (percent != 100)\n\t\talert('".__("The Quick Scan was unable to finish because of a shortage of memory or a problem accessing a file. Please try using the Complete Scan, it is slower but it will handle these errors better and continue scanning the rest of the files.",'gotmls')."');\n}\nwindow.onload=testComplete;\n$lt/script$gt\n$lt".'script type="text/javascript"'.$gt;
1337 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
1338 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1339 if ($check != "potential")
1340 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $check;
1341 }
1342 echo "\n$lt".'form method="POST" action="'.admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."1314")).(isset($_SERVER["QUERY_STRING"])&&strlen($_SERVER["QUERY_STRING"])?"&".$_SERVER["QUERY_STRING"]:"").'" target="GOTMLS_iFrame" name="GOTMLS_Form_clean"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_fix"'.$gt.$lt.'input type="hidden" id="GOTMLS_fixing" name="GOTMLS_fixing" value="1"'.$gt;
1343 foreach ($_POST as $name => $value) {
1344 if (substr($name, 0, 10) != 'GOTMLS_fix') {
1345 if (is_array($value)) {
1346 foreach ($value as $val)
1347 echo $lt.'input type="hidden" name="'.$name.'[]" value="'.GOTMLS_htmlspecialchars($val).'"'.$gt;
1348 } else
1349 echo $lt.'input type="hidden" name="'.$name.'" value="'.GOTMLS_htmlspecialchars($value).'"'.$gt;
1350 }
1351 }
1352 echo "\n$lt".'script type="text/javascript"'.$gt.'showhide("inside_'.md5($ScanSettings).'");'.$lt.'/script'.$gt.GOTMLS_box(GOTMLS_htmlspecialchars($_REQUEST["scan_type"]).' Status', $lt.'div id="status_text"'.$gt.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="..."'.$gt.' '.GOTMLS_Loading_LANGUAGE.$lt.'/div'.$gt.$lt.'div id="status_bar"'.$gt.$lt.'/div'.$gt.$lt.'p id="pause_button" style="display: none; position: absolute; left: 0; text-align: center; margin-left: -30px; padding-left: 50%;"'.$gt.$lt.'input type="button" value="Pause" class="button-primary" onclick="pauseresume(this);" id="resume_button" /'.$gt.$lt.'/p'.$gt.$lt.'div id="status_counts"'.$gt.$lt.'/div'.$gt.$lt.'p id="fix_button" style="display: none; text-align: center;"'.$gt.$lt.'input id="repair_button" type="submit" value="'.GOTMLS_Automatically_Fix_LANGUAGE.'" class="button-primary" onclick="loadIframe(\'Examine Results\');" /'.$gt.$lt.'/p'.$gt);
1353 $scan_groups_UL = "";
1354 foreach ($scan_groups as $scan_name => $scan_group)
1355 $scan_groups_UL .= "\n{$lt}ul name=\"found_$scan_group\" id=\"found_$scan_group\" class=\"GOTMLS_plugin $scan_group\" style=\"background-color: #ccc; display: none; padding: 0;\"$gt{$lt}a class=\"rounded-corners\" name=\"link_$scan_group\" style=\"float: right; padding: 0 4px; margin: 5px 5px 0 30px; line-height: 16px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;\" href=\"#found_top\" onclick=\"showhide('found_$scan_group');\"{$gt}X$lt/a$gt{$lt}h3$gt$scan_name$lt/h3$gt\n".($scan_group=='potential'?$lt.'p'.$gt.' &nbsp; * '.__("NOTE: These are probably not malicious scripts (but it's a good place to start looking <u>IF</u> your site is infected and no Known Threats were found).",'gotmls').$lt.'/p'.$gt:($scan_group=='wp_core'?$lt.'p'.$gt.' &nbsp; * '.sprintf(__("NOTE: We have detected changes to the WordPress Core files on your site. This could be an intentional modification or the malicious work of a hacker. We can restore these files to their original state to preserve the integrity of your original WordPress %s installation.",'gotmls'), GOTMLS_wp_version).' (for more info '.$lt.'a target="_blank" href="http://gotmls.net/tag/wp-core-files/"'.$gt.__("read my blog",'gotmls').$lt.'/a'.$gt.').'.$lt.'/p'.$gt:$lt.'br /'.$gt)).$lt.'/ul'.$gt;
1356 if (!($dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + $_REQUEST["scan_what"]))))) $dir = "/";
1357 GOTMLS_update_scan_log(array("scan" => array("dir" => $dir, "start" => time(), "type" => GOTMLS_htmlentities($_REQUEST["scan_type"]))));
1358 echo GOTMLS_box($lt.'div id="GOTMLS_scan_dir" style="float: right;"'.$gt.'&nbsp;('.$GLOBALS["GOTMLS"]["log"]["scan"]["dir"].")&nbsp;$lt/div$gt".__("Scan Details:",'gotmls'), $scan_groups_UL);
1359 $no_flush_LANGUAGE = __("Not flushing OB Handlers: %s",'gotmls');
1360 if (isset($_REQUEST["no_ob_end_flush"]))
1361 echo $lt.'div class="error"'.$gt.sprintf($no_flush_LANGUAGE, print_r(ob_list_handlers(), 1))."$lt/div$gt\n";
1362 elseif (is_array($OB_handlers) && count($OB_handlers)) {
1363 // $GOTMLS_OB_handlers = get_option("GOTMLS_OB_handlers", array());
1364 foreach (array_reverse($OB_handlers) as $OB_handler) {
1365 if (isset($GOTMLS_OB_handlers[$OB_handler]) && $GOTMLS_OB_handlers[$OB_handler] == "no_end_flush")
1366 echo $lt.'div class="error"'.$gt.sprintf($no_flush_LANGUAGE, $OB_handler)."$lt/div$gt\n";
1367 elseif (in_array($OB_handler, $OB_default_handlers)) {
1368 // $GOTMLS_OB_handlers[$OB_handler] = "no_end_flush";
1369 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1370 @ob_end_flush();
1371 // $GOTMLS_OB_handlers[$OB_handler] = "ob_end_flush";
1372 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1373 }
1374 }
1375 }
1376 @ob_start();
1377 echo "\n{$lt}script type=\"text/javascript\"$gt$li_js\n/*{$lt}!--*"."/";
1378 if (is_dir($dir)) {
1379 $GOTMLS_dirs_at_depth[0] = 1;
1380 $GOTMLS_dir_at_depth[0] = 0;
1381 if (isset($_REQUEST['scan_only']) && is_array($_REQUEST['scan_only'])) {
1382 $GOTMLS_dirs_at_depth[0] += (count($_REQUEST['scan_only']) - 1);
1383 foreach ($_REQUEST['scan_only'] as $only_dir)
1384 if (is_dir(GOTMLS_trailingslashit($dir).$only_dir))
1385 GOTMLS_readdir(GOTMLS_trailingslashit($dir).$only_dir);
1386 } else
1387 GOTMLS_readdir($dir);
1388 } else
1389 echo GOTMLS_return_threat("errors", "blocked", $dir, GOTMLS_error_link("Not a valid directory!"));
1390 if ($_REQUEST["scan_type"] == "Quick Scan")
1391 echo GOTMLS_update_status(__("Completed!",'gotmls'), 100);
1392 else {
1393 echo GOTMLS_update_status(__("Starting Scan ...",'gotmls'));
1394 if (isset($GLOBALS["GOTMLS"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["log"]["settings"]["check"]) && in_array("db_scan", $GLOBALS["GOTMLS"]["log"]["settings"]["check"]))
1395 GOTMLS_db_scan();
1396 echo "/*--{$gt}*"."/\nvar scriptSRC = '".admin_url('admin-ajax.php?action=GOTMLS_scan&'.GOTMLS_set_nonce(__FUNCTION__."1087").'&mt='.$GLOBALS["GOTMLS"]["tmp"]["mt"].preg_replace('/\&(GOTMLS_scan|mt|GOTMLS_mt|action)=/', '&last_\1=', isset($_SERVER["QUERY_STRING"])&&strlen($_SERVER["QUERY_STRING"])?"&".$_SERVER["QUERY_STRING"]:"").'&GOTMLS_scan=')."';\nvar scanfilesArKeys = new Array('".implode("','", array_keys($GLOBALS["GOTMLS"]["tmp"]["scanfiles"]))."');\nvar scanfilesArNames = new Array('Scanning ".implode("','Scanning ", $GLOBALS["GOTMLS"]["tmp"]["scanfiles"])."');".'
1397 var scanfilesI = 0;
1398 var stopScanning;
1399 var gotStuckOn = "";
1400 function scanNextDir(gotStuck) {
1401 clearTimeout(stopScanning);
1402 if (gotStuck > -1) {
1403 if (scanfilesArNames[gotStuck].substr(0, 3) != "Re-") {
1404 if (scanfilesArNames[gotStuck].substr(0, 9) == "Checking ") {
1405 scanfilesArNames.push(scanfilesArNames[gotStuck]);
1406 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_skip_file[]="+encodeURIComponent(scanfilesArNames[gotStuck].substr(9)));
1407 } else {
1408 scanfilesArNames.push("Re-"+scanfilesArNames[gotStuck]);
1409 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_only_file=");
1410 }
1411 } else {
1412 scanfilesArNames.push("Got Stuck "+scanfilesArNames[gotStuck]);
1413 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_skip_dir="+scanfilesArKeys[gotStuck]);
1414 }
1415 }
1416 if (document.getElementById("resume_button").value != "Pause") {
1417 stopScanning=setTimeout("scanNextDir(-1)", 1000);
1418 startTime++;
1419 }
1420 else if (scanfilesI < scanfilesArKeys.length) {
1421 document.getElementById("status_text").innerHTML = scanfilesArNames[scanfilesI];
1422 var newscript = document.createElement("script");
1423 newscript.setAttribute("src", scriptSRC+scanfilesArKeys[scanfilesI]);
1424 divx = document.getElementById("found_scanned");
1425 if (divx)
1426 divx.appendChild(newscript);
1427 stopScanning=setTimeout("scanNextDir("+(scanfilesI++)+")",'.$GLOBALS["GOTMLS"]["tmp"]['execution_time'].'000);
1428 }
1429 }
1430 startTime = ('.ceil(time()-$GLOBALS["GOTMLS"]["log"]["scan"]["start"]).'+3);
1431 stopScanning=setTimeout("scanNextDir(-1)",3000);
1432 function pauseresume(butt) {
1433 if (butt.value == "Resume")
1434 butt.value = "Pause";
1435 else
1436 butt.value = "Resume";
1437 }
1438 showhide("pause_button", true);'."\n/*{$lt}!--*"."/";
1439 }
1440 if (@ob_get_level()) {
1441 GOTMLS_flush('script');
1442 @ob_end_flush();
1443 }
1444 echo "/*--{$gt}*"."/\n$lt/script$gt";
1445 } else
1446 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Starting a Complete Scan requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1447 } else
1448 echo GOTMLS_box(__("Scan Logs",'gotmls'), GOTMLS_get_scanlog());
1449 echo "\n$lt/div$gt$lt/div$gt$lt/div$gt";
1450 }
1451
1452 function GOTMLS_login_form($form_id = "loginform") {
1453 $sess = time();
1454 $ajaxURL = admin_url("admin-ajax.php?action=GOTMLS_logintime&GOTMLS_sess=");
1455 echo '<input type="hidden" name="sess_id" value="'.substr($sess, 4).'"><input type="hidden" id="offset_id" value="0" name="sess'.substr($sess, 4).'"><script type="text/javascript">'."\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_script = document.createElement('script');\nGOTMLS_login_script.src = '$ajaxURL'+GOTMLS_login_offset.getTime();\n\ndocument.head.appendChild(GOTMLS_login_script);\n</script>\n";//GOTMLS_login_script.onload = set_offset_id();
1456 }
1457 add_action("login_form", "GOTMLS_login_form");
1458
1459 function GOTMLS_ajax_logintime() {
1460 @header("Content-type: text/javascript");
1461 $sess = (false && isset($_GET["GOTMLS_sess"]) && is_numeric($_GET["GOTMLS_sess"])) ? GOTMLS_htmlspecialchars($_GET["sess"]) : time();
1462 die("\n//Permission Error: User not authenticated!\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_offset_start = GOTMLS_login_offset.getTime() - ".$sess."000;\nfunction set_offset_id() {\n\tGOTMLS_login_offset = new Date();\n\tif (form_login = document.getElementById('offset_id'))\n\t\tform_login.value = GOTMLS_login_offset.getTime() - GOTMLS_login_offset_start;\n\tsetTimeout(set_offset_id, 15673);\n}\nset_offset_id();");
1463 }
1464
1465 function GOTMLS_ajax_lognewkey() {
1466 @header("Content-type: text/javascript");
1467 if (GOTMLS_get_nonce()) {
1468 if (isset($_POST["GOTMLS_installation_key"]) && ($_POST["GOTMLS_installation_key"] == GOTMLS_installation_key)) {
1469 $keys = maybe_unserialize(get_option('GOTMLS_Installation_Keys', array()));
1470 if (is_array($keys)) {
1471 $count = count($keys);
1472 if (!array_key_exists(GOTMLS_installation_key, $keys))
1473 $keys = array_merge($keys, array(GOTMLS_installation_key => GOTMLS_siteurl));
1474 } else
1475 $keys = array(GOTMLS_installation_key => GOTMLS_siteurl);
1476 update_option("GOTMLS_Installation_Keys", serialize($keys));
1477 die("\n//$count~".count($keys));
1478 } else
1479 die("\n//0");
1480 } else
1481 die(GOTMLS_Invalid_Nonce("\n//Log New Key Error: ")."\n");
1482 }
1483
1484 function GOTMLS_set_plugin_action_links($links_array, $plugin_file) {
1485 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * strlen($plugin_file))) && strlen($plugin_file) > 10)
1486 $links_array = array_merge(array('<a href="'.admin_url('admin.php?page=GOTMLS-settings').'">'.GOTMLS_Scan_Settings_LANGUAGE.'</a>'), $links_array);
1487 return $links_array;
1488 }
1489 add_filter("plugin_action_links", "GOTMLS_set_plugin_action_links", 1, 2);
1490
1491 function GOTMLS_set_plugin_row_meta($links_array, $plugin_file) {
1492 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * strlen($plugin_file))) && strlen($plugin_file) > 10)
1493 $links_array = array_merge($links_array, array('<a target="_blank" href="http://gotmls.net/faqs/">FAQ</a>','<a target="_blank" href="http://gotmls.net/support/">Support</a>','<a target="_blank" href="https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=QZHD8QHZ2E7PE"><span style="font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span>Donate</a>'));
1494 return $links_array;
1495 }
1496 add_filter("plugin_row_meta", "GOTMLS_set_plugin_row_meta", 1, 2);
1497
1498 function GOTMLS_in_plugin_update_message($args) {
1499 $transient_name = 'GOTMLS_upgrade_notice_'.$args["Version"].'_'.$args["new_version"];
1500 if ((false === ($upgrade_notice = get_transient($transient_name))) && ($ret = GOTMLS_get_URL("https://plugins.svn.wordpress.org/gotmls/trunk/readme.txt"))) {
1501 $upgrade_notice = '';
1502 if ($match = preg_split('/==\s*Upgrade Notice\s*==\s+/i', $ret)) {
1503 if (preg_match('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]))
1504 $notice = (array) preg_split('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]);
1505 else
1506 $notice = (array) preg_split('/\n+=/is', $match[1]."\n=");
1507 $upgrade_notice .= '<div class="GOTMLS_upgrade_notice">'.preg_replace('/=\s*([\.0-9]+)\s*=\s*([^=]+)/i', '<li><b>${1}:</b> ${2}</li>', preg_replace('~\[([^\]]*)\]\(([^\)]*)\)~', '<a href="${2}">${1}</a>', $notice[0])).'</div>';
1508 set_transient($transient_name, $upgrade_notice, DAY_IN_SECONDS);
1509 }
1510 }
1511 echo $upgrade_notice;
1512 }
1513 add_action("in_plugin_update_message-gotmls/index.php", "GOTMLS_in_plugin_update_message");
1514
1515 function GOTMLS_init() {
1516 global $wp_version;
1517 if (isset($wp_version) && ($wp_version))
1518 GOTMLS_define("GOTMLS_wp_version", $wp_version);
1519 else
1520 GOTMLS_define("GOTMLS_wp_version", "Not Set");
1521 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]))
1522 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = 2;
1523 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
1524 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = -1;
1525 if (isset($_REQUEST["scan_type"]) && ($_REQUEST["scan_type"] == "Quick Scan")) {
1526 if (!isset($_REQUEST["scan_what"])) $_REQUEST["scan_what"] = 2;
1527 if (!isset($_REQUEST["scan_depth"]))
1528 $_REQUEST["scan_depth"] = 2;
1529 if (!isset($_REQUEST["scan_only"]))
1530 $_REQUEST["scan_only"] = array("","wp-includes","wp-admin");
1531 if ($_REQUEST["scan_only"] && !is_array($_REQUEST["scan_only"]))
1532 $_REQUEST["scan_only"] = array($_REQUEST["scan_only"]);
1533 }
1534 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]))
1535 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = "";
1536 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]) && is_numeric($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1537 $scan_level = intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);
1538 else
1539 $scan_level = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1540 $ajax_functions = array('auto_update', 'empty_trash', 'fix', 'logintime', 'lognewkey', 'position', 'scan', 'whitelist');
1541 if (GOTMLS_get_nonce()) {
1542 if (isset($_REQUEST["dont_check"]) && is_array($_REQUEST["dont_check"]) && count($_REQUEST["dont_check"]))
1543 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = $_REQUEST["dont_check"];
1544 elseif (isset($_POST["scan_type"]) || !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])))
1545 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = array();
1546 if (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"]))
1547 $scan_level = intval($_POST["scan_level"]);
1548 if (isset($scan_level) && is_numeric($scan_level))
1549 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = intval($scan_level);
1550 foreach ($ajax_functions as $ajax_function) {
1551 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1552 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1553 }
1554 } elseif (GOTMLS_user_can()) {
1555 foreach ($ajax_functions as $ajax_function) {
1556 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1557 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", "GOTMLS_ajax_nopriv");
1558 }
1559 } else {
1560 foreach ($ajax_functions as $ajax_function) {
1561 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_nopriv");
1562 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", "GOTMLS_ajax_nopriv");
1563 }
1564 }
1565 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1566 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1567 }
1568 add_action("admin_init", "GOTMLS_init");
1569
1570 function GOTMLS_ajax_position() {
1571 if (GOTMLS_get_nonce()) {
1572 $GLOBALS["GOTMLS_msg"] = __("Default position",'gotmls');
1573 $properties = array("body" => 'style="margin: 0; padding: 0;"');
1574 if (isset($_GET["GOTMLS_msg"]) && $_GET["GOTMLS_msg"] == $GLOBALS["GOTMLS_msg"]) {
1575 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"] = $GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"];
1576 $gl = '><';
1577 $properties["html"] = $gl.'head'.$gl.'script type="text/javascript">
1578 if (curDiv = window.parent.document.getElementById("div_file")) {
1579 curDiv.style.left = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0].'";
1580 curDiv.style.top = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1].'";
1581 curDiv.style.height = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2].'";
1582 curDiv.style.width = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3].'";
1583 }
1584 </script'.$gl.'/head';
1585 } elseif (isset($_GET["GOTMLS_x"]) || isset($_GET["GOTMLS_y"]) || isset($_GET["GOTMLS_h"]) || isset($_GET["GOTMLS_w"])) {
1586 if (isset($_GET["GOTMLS_x"]))
1587 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0] = $_GET["GOTMLS_x"];
1588 if (isset($_GET["GOTMLS_y"]))
1589 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1] = $_GET["GOTMLS_y"];
1590 if (isset($_GET["GOTMLS_h"]))
1591 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2] = $_GET["GOTMLS_h"];
1592 if (isset($_GET["GOTMLS_w"]))
1593 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3] = $_GET["GOTMLS_w"];
1594 $_GET["GOTMLS_msg"] = __("New position",'gotmls');
1595 } else
1596 die("\n//Position Error: No new position to save!\n");
1597 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1598 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_htmlentities($_GET["GOTMLS_msg"]).' '.__("saved.",'gotmls').(implode($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"]) == implode($GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"])?"":' <a href="'.admin_url('admin-ajax.php?action=GOTMLS_position&'.GOTMLS_set_nonce(__FUNCTION__."1350").'&GOTMLS_msg='.urlencode($GLOBALS["GOTMLS_msg"])).'">['.$GLOBALS["GOTMLS_msg"].']</a>'))), $properties));
1599 } else
1600 die(GOTMLS_Invalid_Nonce("\n//Position Error: ")."\n");
1601 }
1602
1603 function GOTMLS_ajax_empty_trash() {
1604 global $wpdb;
1605 $gl = '><';
1606 if (GOTMLS_get_nonce()) {
1607 if ($trashed = $wpdb->query("DELETE FROM $wpdb->posts WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` != 'private'")) {
1608 $wpdb->query("REPAIR TABLE $wpdb->posts");
1609 $trashmsg = __("Emptied $trashed item from the quarantine trash.",'gotmls');
1610 } else
1611 $trashmsg = __("Failed to empty the trash.",'gotmls');
1612 } else
1613 $trashmsg = GOTMLS_Invalid_Nonce("");
1614 $properties = array("html" => $gl.'head'.$gl."script type='text/javascript'>\nif (curDiv = window.parent.document.getElementById('empty_trash_link'))\n\tcurDiv.style.display = 'none';\nalert('$trashmsg');\n</script$gl/head", "body" => 'style="margin: 0; padding: 0;"');
1615 die(GOTMLS_html_tags(array("html" => array("body" => $trashmsg)), $properties));
1616 }
1617
1618 function GOTMLS_ajax_whitelist() {
1619 if (GOTMLS_get_nonce()) {
1620 if (isset($_POST['GOTMLS_whitelist']) && isset($_POST['GOTMLS_chksum'])) {
1621 $file = GOTMLS_decode($_POST['GOTMLS_whitelist']);
1622 $chksum = explode("O", $_POST['GOTMLS_chksum']."O");
1623 if (strlen($chksum[0]) == 32 && strlen($chksum[1]) == 32 && is_file($file) && md5(@file_get_contents($file)) == $chksum[0]) {
1624 $filesize = @filesize($file);
1625 if (true) {
1626 if (!isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][0]))
1627 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][0] = "A0002";
1628 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][$chksum[0].'O'.$filesize] = "A0002";
1629 } else
1630 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file]);
1631 GOTMLS_update_option("definitions", $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]);
1632 $body = "Added $file to Whitelist!<br />\n<iframe style='width: 90%; height: 250px; border: none;' src='".GOTMLS_plugin_home."whitelist.html?whitelist=".GOTMLS_htmlspecialchars($_POST['GOTMLS_whitelist'])."&hash=$chksum[0]&size=$filesize&key=$chksum[1]'></iframe>";
1633 } else
1634 $body = "<li>Invalid Data!</li>";
1635 die(GOTMLS_html_tags(array("html" => array("body" => $body))));
1636 } else
1637 die("\n//Whitelist Error: Invalid checksum!\n");
1638 } else
1639 die(GOTMLS_Invalid_Nonce("\n//Whitelist Error: ")."\n");
1640 }
1641
1642 function GOTMLS_ajax_fix() {
1643 if (GOTMLS_get_nonce()) {
1644 if (isset($_POST["GOTMLS_fix"]) && !is_array($_POST["GOTMLS_fix"]))
1645 $_POST["GOTMLS_fix"] = array($_POST["GOTMLS_fix"]);
1646 if (isset($_REQUEST["GOTMLS_fix"]) && is_array($_REQUEST["GOTMLS_fix"]) && isset($_REQUEST["GOTMLS_fixing"]) && $_REQUEST["GOTMLS_fixing"]) {
1647 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1648 $callAlert = "clearTimeout(callAlert);\ncallAlert=setTimeout('alert_repaired(1)', 30000);";
1649 $li_js = "\n<script type=\"text/javascript\">\nvar callAlert;\nfunction alert_repaired(failed) {\nclearTimeout(callAlert);\nif (failed)\nfilesFailed='the rest, try again to change more.';\nwindow.parent.check_for_donation('Changed '+filesFixed+' files, failed to change '+filesFailed);\n}\n$callAlert\nwindow.parent.showhide('GOTMLS_iFrame', true);\nfilesFixed=0;\nfilesFailed=0;\nfunction fixedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file))\n\tli_file.className='GOTMLS_plugin';\nif (li_file = window.parent.document.getElementById('GOTMLS_quarantine_'+file)) {\n\tli_file.style.display='none';\n\tli_file.innerHTML='';\n\t}\n}\nfunction DeletedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file)) {\n\tli_file.className='GOTMLS_plugin';\n\tif (true || !isNaN(file)) {\n\t\tli_file = li_file.parentNode".(isset($_REQUEST["GOTMLS_fix"][0]) && is_numeric($_REQUEST["GOTMLS_fix"][0])?'.parentNode':'').";\n\t\tli_file.style.display='none';\n\t\tli_file.innerHTML='';\n}}}\nfunction failedFile(file) {\n filesFailed++;\nwindow.parent.document.getElementById('check_'+file).checked=false; \n}\n</script>\n<script type=\"text/javascript\">\n/*<!--*"."/";
1650 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] * 2);
1651 $HTML = explode("split-here-for-content", GOTMLS_html_tags(array("html" => array("body" => "split-here-for-content"))));
1652 echo $HTML[0];
1653 GOTMLS_update_scan_log(array("scan" => array("dir" => count($_REQUEST["GOTMLS_fix"])." Files", "start" => time())));
1654 foreach ($_REQUEST["GOTMLS_fix"] as $clean_file) {
1655 if (is_numeric($clean_file)) {
1656 if (($Q_post = GOTMLS_get_quarantine($clean_file)) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine" && isset($Q_post["post_status"]) && strtolower($Q_post["post_status"]) == "private") {
1657 $path = $Q_post["post_title"];
1658 if ($_REQUEST["GOTMLS_fixing"] > 1) {
1659 echo "<li>Removing $path ... ";
1660 $Q_post["post_status"] = "trash";
1661 if (wp_update_post($Q_post)) {
1662 echo __("Done!",'gotmls');
1663 $li_js .= "/*-->*"."/\nDeletedFile('$clean_file');\n/*<!--*"."/";
1664 } else {
1665 echo __("Failed to remove!",'gotmls');
1666 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1667 }
1668 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Removal from Quarantine")));
1669 } else {
1670 $Q_post["post_status"] = "pending";
1671 $part = explode(":", $Q_post["post_title"].':');
1672 if (count($part) > 2 && is_numeric($part[1])) {
1673 if (($R_post = GOTMLS_get_quarantine($part[1])) && isset($R_post["post_type"]) && strtolower($R_post["post_type"]) == $part[0]) {
1674 if (isset($_GET["eli"]) || ($R_post["post_content"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post["post_content"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1675 echo "<li>Restoring Post ID $part[1] ... ";
1676 $R_post["post_modified_gmt"] = $Q_post["post_modified"];
1677 $R_post["post_content"] = GOTMLS_decode($Q_post["post_content"]);
1678 if (wp_update_post($R_post)) {
1679
1680 echo __("Complete!",'gotmls');
1681 wp_update_post($Q_post);
1682 $li_js .= "/*-->*"."/\nfixedFile('$clean_file');\n/*<!--*"."/";
1683 } else {
1684 echo __("Restoration Failed!",'gotmls');
1685 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1686 }
1687 } else {
1688 echo "<li>".__("Restoration Aborted, post_content was modified outside of this quarantine!<pre>".GOTMLS_htmlspecialchars(print_r(array("R"=>$R_post,"Q"=>$Q_post),1))."</pre>",'gotmls');
1689 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1690 }
1691 } else {
1692 echo "<li>".__("Restore Failed!",'gotmls');
1693 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1694 }
1695 } elseif (isset($_GET["eli"]) || is_file($path)) {
1696 echo "<li>Restoring $path ... ";
1697 if (GOTMLS_file_put_contents($path, GOTMLS_decode($Q_post["post_content"])) && wp_update_post($Q_post)) {
1698 echo __("Complete!",'gotmls');
1699 $li_js .= "/*-->*"."/\nfixedFile('$clean_file');\n/*<!--*"."/";
1700 } else {
1701 echo __("Restore Failed!",'gotmls');
1702 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1703 }
1704 } else {
1705 echo "<li>".__("Restoration Aborted, file $path does not exist!",'gotmls');
1706 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1707 }
1708 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Restoration from Quarantine")));
1709 }
1710 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n</script>\n";
1711 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1712 }
1713 } elseif (is_numeric($decoded_file = GOTMLS_decode($clean_file))) {
1714 $li_js .= GOTMLS_db_scan($decoded_file);
1715 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n</script>\n";
1716 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1717 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "DB Fix")));
1718 } else {
1719 $path = realpath($decoded_file = GOTMLS_decode($clean_file));
1720 if (is_file($path)) {
1721 echo "<li>Fixing $path ... ";
1722 $li_js .= GOTMLS_scanfile($path);
1723 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n</script>\n";
1724 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1725 } else
1726 echo "<li>".sprintf(__("File %s not found!",'gotmls'), GOTMLS_htmlentities($path))."</li>";
1727 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Automatic Fix")));
1728 }
1729 }
1730 $nonce = GOTMLS_set_nonce(__FUNCTION__."1685");
1731 die('<div id="check_site_warning" style="background-color: #F00;">'.sprintf(__("Because some changes were made we need to check to make sure it did not break your site. If this stays Red and the frame below does not load please <a %s>revert the changes</a> made during this automated fix process.",'gotmls'), 'href="'.GOTMLS_images_path.'?page=GOTMLS-View-Quarantine&'.$nonce.'"').' <span style="color: #F00;">'.__("Never mind, it worked!",'gotmls').'</span></div><br /><iframe id="test_frame" name="test_frame" src="'.admin_url('admin.php?page=GOTMLS-settings&check_site=1&'.$nonce).'" style="width: 100%; height: 200px"></iframe>'.$li_js."/*-->*"."/\nalert_repaired(0);\n</script>\n$HTML[1]");
1732 } else
1733 die(GOTMLS_html_tags(array("html" => array("body" => "<script type=\"text/javascript\">\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".__("Nothing Selected to be Changed!",'gotmls')."');\n</script>".__("Done!",'gotmls')))));
1734 } else
1735 die(GOTMLS_html_tags(array("html" => array("body" => "<script type=\"text/javascript\">\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".GOTMLS_Invalid_Nonce("")."');\n</script>".__("Done!",'gotmls')))));
1736 }
1737
1738 function GOTMLS_ajax_scan() {
1739 if (GOTMLS_get_nonce()) {
1740 @error_reporting(0);
1741 if (isset($_GET["GOTMLS_scan"])) {
1742 $script_form = '<script type="text/javascript">
1743 function select_text_range(ta_id, start, end) {
1744 var textBox = document.getElementById(ta_id);
1745 var scrolledText = "";
1746 scrolledText = textBox.value.substring(0, end);
1747 textBox.focus();
1748 if (textBox.setSelectionRange) {
1749 scrolledText = textBox.value.substring(end);
1750 textBox.value = textBox.value.substring(0, end);
1751 textBox.scrollTop = textBox.scrollHeight;
1752 textBox.value = textBox.value + scrolledText;
1753 textBox.setSelectionRange(start, end);
1754 } else if (textBox.createTextRange) {
1755 var range = textBox.createTextRange();
1756 range.collapse(true);
1757 range.moveStart("character", start);
1758 range.moveEnd("character", end);
1759 range.select();
1760 } else
1761 alert("The highlighting function does not work in your browser");
1762 }
1763 if (typeof window.parent.showhide === "function")
1764 window.parent.showhide("GOTMLS_iFrame", true);
1765 </script><table style="top: 0px; left: 0px; width: 100%; height: 100%; position: absolute;"><tr><td style="width: 100%"><form style="margin: 0;" method="post" action="';
1766 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] - 5);
1767 if (is_numeric($_GET["GOTMLS_scan"])) {
1768 if (($Q_post = GOTMLS_get_quarantine($_GET["GOTMLS_scan"])) && isset($Q_post["post_type"]) && $Q_post["post_type"] == "GOTMLS_quarantine" && isset($Q_post["post_status"]) && $Q_post["post_status"] == "private") {
1769 ////////// posts table (quarantine)
1770 $clean_file = $Q_post["post_title"];
1771 $GLOBALS["GOTMLS"]["tmp"]["file_contents"] = GOTMLS_decode($Q_post["post_content"]);
1772 $fa = "";
1773 $function = 'GOTMLS_decode';
1774 if (isset($_GET[$function]) && is_array($_GET[$function])) {
1775 foreach ($_GET[$function] as $decode) {
1776 $fa .= " NO-$decode";
1777 }
1778 } elseif (isset($Q_post["post_excerpt"]) && strlen($Q_post["post_excerpt"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["threats_found"] = @maybe_unserialize(GOTMLS_decode($Q_post["post_excerpt"])))) {
1779 $f = 1;
1780 //print_r(array("excerpt:"=>$GLOBALS["GOTMLS"]["tmp"]["threats_found"]));
1781 foreach ($GLOBALS["GOTMLS"]["tmp"]["threats_found"] as $threats_found => $threats_name) {
1782 list($start, $end, $junk) = explode("-", "$threats_found--", 3);
1783 if (strlen($end) > 0 && is_numeric($start) && is_numeric($end)) {
1784 if ($start < $end)
1785 $fa .= ' <a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range(\'ta_file\', '.$start.', '.$end.');">['.$f++.']</a>';
1786 else
1787 $fa .= ' <a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range(\'ta_file\', '.$end.', '.$start.');">['.$f++.']</a>';
1788 } else {
1789 if (is_numeric($threats_found)) {
1790 $threats_found = $threats_name;
1791 $threats_name = $f;
1792 }
1793 $fpos = 0;
1794 $flen = 0;
1795 $potential_threat = str_replace("\r", "", $threats_found);
1796 while (($fpos = strpos(str_replace("\r", "", $GLOBALS["GOTMLS"]["tmp"]["file_contents"]), ($potential_threat), $flen + $fpos)) !== false) {
1797 $flen = strlen($potential_threat);
1798 $fa .= ' <a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range(\'ta_file\', '.($fpos).', '.($fpos + $flen).');">['.$f++.']</a>';
1799 }
1800 }
1801 }
1802 } //else echo "excerpt:".$Q_post["post_excerpt"];
1803 die("\n$script_form".admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."1779")).'" onsubmit="return confirm(\''.__("Are you sure you want to delete the record of this file from the quarantine?",'gotmls').'\');"><input type="hidden" name="GOTMLS_fix[]" value="'.$Q_post["ID"].'"><input type="hidden" name="GOTMLS_fixing" value="2"><input type="hidden" name="action" value="GOTMLS_fix"><input type="submit" value="DELETE from Quarantine" style="background-color: #C00; float: right;"></form><div id="fileperms" class="shadowed-box rounded-corners" style="display: none; position: absolute; left: 8px; top: 29px; background-color: #ccc; border: medium solid #C00; box-shadow: -3px 3px 3px #666; border-radius: 10px; padding: 10px;"><b>File Details</b><br />size: '.strlen(GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["file_contents"])).' bytes<br />infected:'.$Q_post["post_modified_gmt"].'<br />encoding: '.(isset($GLOBALS["GOTMLS"]["tmp"]["encoding"])?$GLOBALS["GOTMLS"]["tmp"]["encoding"]:(function_exists("mb_detect_encoding")?mb_detect_encoding($GLOBALS["GOTMLS"]["tmp"]["file_contents"]):"Unknown")).'<br />quarantined:'.$Q_post["post_date_gmt"].'</div><div style="overflow: auto;"><span onmouseover="document.getElementById(\'fileperms\').style.display=\'block\';" onmouseout="document.getElementById(\'fileperms\').style.display=\'none\';">'.__("File Details:",'gotmls').'</span> ('.$fa.' )</div></td></tr><tr><td style="height: 100%"><textarea id="ta_file" style="width: 100%; height: 100%">'.GOTMLS_htmlentities(str_replace("\r", "", $GLOBALS["GOTMLS"]["tmp"]["file_contents"])).'</textarea></td></tr></table>');
1804 } else
1805 die(GOTMLS_html_tags(array("html" => array("body" => __("This record no longer exists in the quarantine.",'gotmls')."<br />\n<script type=\"text/javascript\">\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n</script>"))));
1806 } else {
1807 $file = GOTMLS_decode($_GET["GOTMLS_scan"]);
1808 if (is_numeric($file))
1809 die("\n$script_form".GOTMLS_db_scan($file));
1810 elseif (is_dir($file)) {
1811 @error_reporting(0);
1812 @header("Content-type: text/javascript");
1813 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))
1814 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
1815 @ob_start();
1816 echo GOTMLS_scandir($file);
1817 if (@ob_get_level()) {
1818 GOTMLS_flush();
1819 @ob_end_clean();//_flush();
1820 }
1821 die('//END OF JavaScript');
1822 } elseif (file_exists($file)) {
1823 GOTMLS_scanfile($file);
1824 $fa = "";
1825 $function = 'GOTMLS_decode';
1826 if (isset($_GET[$function]) && is_array($_GET[$function])) {
1827 foreach ($_GET[$function] as $decode) {
1828 $fa .= " NO-$decode";
1829 }
1830 } elseif (isset($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && count($GLOBALS["GOTMLS"]["tmp"]["threats_found"])) {
1831 $f = 1;
1832 foreach ($GLOBALS["GOTMLS"]["tmp"]["threats_found"] as $threats_found => $threats_name) {
1833 list($start, $end, $junk) = explode("-", "$threats_found--", 3);
1834 if ($start > $end)
1835 $fa .= 'ERROR['.($f++).']: Threat_size{'.$threats_found.'} Content_size{'.strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'}';
1836 else
1837 $fa .= ' <a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range(\'ta_file\', '.$start.', '.$end.');">['.$f++.']</a>';
1838 }
1839 } else
1840 $fa = " No Threats Found";
1841 die("\n$script_form".admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."1821")).'" onsubmit="return confirm(\''.__("Are you sure this file is not infected and you want to ignore it in future scans?",'gotmls').'\');"><input type="hidden" name="GOTMLS_whitelist" value="'.GOTMLS_encode($file).'"><input type="hidden" name="action" value="GOTMLS_whitelist"><input type="hidden" name="GOTMLS_chksum" value="'.md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'O'.GOTMLS_installation_key.'"><input type="submit" value="Whitelist this file" style="float: right;"></form>'.GOTMLS_file_details($file).'<div style="overflow: auto;"><span onmouseover="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'block\';" onmouseout="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'none\';">'.__("Potential threats in file:",'gotmls').'</span> ('.$fa.' )</div></td></tr><tr><td style="height: 100%"><textarea id="ta_file" style="width: 100%; height: 100%">'.GOTMLS_htmlentities(str_replace("\r", "", $GLOBALS["GOTMLS"]["tmp"]["file_contents"])).'</textarea></td></tr></table>');
1842 } else
1843 die(GOTMLS_html_tags(array("html" => array("body" => sprintf(__("The file %s does not exist, it must have already been deleted.",'gotmls'), GOTMLS_htmlspecialchars($file))."<script type=\"text/javascript\">\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n</script>"))));
1844 }
1845 } else
1846 die("\n//Directory Error: Nothing to scan!\n");
1847 } else {
1848 if (isset($_GET["GOTMLS_scan"]) && is_dir(GOTMLS_decode($_GET["GOTMLS_scan"])))
1849 @header("Content-type: text/javascript");
1850 die(GOTMLS_Invalid_Nonce("\n//Ajax Scan Error: ")."\n");
1851 }
1852 }
1853
1854 function GOTMLS_ajax_nopriv() {
1855 die("\n//Permission Error: User not authenticated!\n");
1856 }
1857
1858