PluginProbe ʕ •ᴥ•ʔ
Anti-Malware Security and Brute-Force Firewall / 4.20.96
Anti-Malware Security and Brute-Force Firewall v4.20.96
4.23.90 trunk 1.2.03.23 1.3.02.15 3.07.06 4.14.47 4.15.16 4.16.17 4.17.28 4.17.29 4.17.44 4.17.57 4.17.58 4.17.68 4.17.69 4.18.52 4.18.62 4.18.63 4.18.69 4.18.71 4.18.74 4.18.76 4.19.44 4.19.50 4.19.68 4.19.69 4.20.59 4.20.72 4.20.92 4.20.93 4.20.94 4.20.95 4.20.96 4.21.74 4.21.83 4.21.84 4.21.85 4.21.86 4.21.87 4.21.88 4.21.89 4.21.90 4.21.91 4.21.92 4.21.93 4.21.94 4.21.95 4.21.96 4.23.56 4.23.57 4.23.67 4.23.68 4.23.69 4.23.71 4.23.73 4.23.77 4.23.81 4.23.83 4.23.85 4.23.87 4.23.88 4.23.89
gotmls / index.php
gotmls Last commit date
images 4 years ago languages 4 years ago safe-load 4 years ago index.php 4 years ago readme.txt 4 years ago
index.php
1636 lines
1 <?php
2 /*
3 Plugin Name: Anti-Malware Security and Brute-Force Firewall
4 Plugin URI: https://gotmls.net/
5 Author: Eli Scheetz
6 Text Domain: gotmls
7 Author URI: http://wordpress.ieonly.com/category/my-plugins/anti-malware/
8 Contributors: scheeeli, gotmls
9 Donate link: https://gotmls.net/donate/
10 Description: This Anti-Virus/Anti-Malware plugin searches for Malware and other Virus like threats and vulnerabilities on your server and helps you remove them. It's always growing and changing to adapt to new threats so let me know if it's not working for you.
11 Version: 4.20.96
12 */
13 if (isset($_SERVER["DOCUMENT_ROOT"]) && ($SCRIPT_FILE = str_replace($_SERVER["DOCUMENT_ROOT"], "", (isset($_SERVER["SCRIPT_FILENAME"])?$_SERVER["SCRIPT_FILENAME"]:(isset($_SERVER["SCRIPT_NAME"])?$_SERVER["SCRIPT_NAME"]:"")))) && strlen($SCRIPT_FILE) > strlen("/".basename(__FILE__)) && substr(__FILE__, -1 * strlen($SCRIPT_FILE)) == substr($SCRIPT_FILE, -1 * strlen(__FILE__)) || !(function_exists("add_action") && function_exists("load_plugin_textdomain")))
14 include(dirname(__FILE__)."/safe-load/index.php");
15 else
16 require_once(dirname(__FILE__)."/images/index.php");
17 /* ___
18 * / /\ GOTMLS Main Plugin File
19 * / /:/ @package GOTMLS
20 * /__/::\
21 Copyright \__\/\:\__ © 2012-2021 Eli Scheetz (email: eli@gotmls.net)
22 * \ \:\/\
23 * \__\::/ This program is free software; you can redistribute it
24 * ___ /__/:/ and/or modify it under the terms of the GNU General Public
25 * /__/\ _\__\/ License as published by the Free Software Foundation;
26 * \ \:\ / /\ either version 2 of the License, or (at your option) any
27 * ___\ \:\ /:/ later version.
28 * / /\\ \:\/:/
29 / /:/ \ \::/ This program is distributed in the hope that it will be useful,
30 / /:/_ \__\/ but WITHOUT ANY WARRANTY; without even the implied warranty
31 /__/:/ /\__ of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
32 \ \:\/:/ /\ See the GNU General Public License for more details.
33 \ \::/ /:/
34 \ \:\/:/ You should have received a copy of the GNU General Public License
35 * \ \::/ with this program; if not, write to the Free Software Foundation,
36 * \__\/ Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA */
37
38 load_plugin_textdomain('gotmls', false, basename(GOTMLS_plugin_path).'/languages');
39 require_once(GOTMLS_plugin_path.'images/index.php');
40
41 function GOTMLS_install() {
42 if (strpos(GOTMLS_get_version("URL"), '&wp=') && version_compare(GOTMLS_wp_version, GOTMLS_require_version, "<"))
43 die(GOTMLS_require_version_LANGUAGE.", NOT version: ".GOTMLS_wp_version);
44 else
45 delete_option("GOTMLS_definitions_array");
46 }
47 register_activation_hook(__FILE__, "GOTMLS_install");
48
49 function GOTMLS_uninstall() {
50 delete_option('GOTMLS_get_URL_array');
51 delete_option('GOTMLS_definitions_blob');
52 }
53 register_deactivation_hook(__FILE__, "GOTMLS_uninstall");
54
55 function GOTMLS_menu() {
56 $base_page = "GOTMLS-settings";
57 $pluginTitle = "Anti-Malware";
58 if (GOTMLS_user_can()) {
59 $my_admin_page = add_menu_page("$pluginTitle ".GOTMLS_Scan_Settings_LANGUAGE, $pluginTitle, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $base_page, "GOTMLS_settings", GOTMLS_images_path.'GOTMLS-16x16.gif');
60 add_action('load-'.$my_admin_page, 'GOTMLS_admin_add_help_tab');
61 add_submenu_page($base_page, "$pluginTitle ".GOTMLS_Scan_Settings_LANGUAGE, GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $base_page, "GOTMLS_settings");
62 add_submenu_page($base_page, "$pluginTitle Firewall Options", "Firewall Options", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS-Firewall-Options", "GOTMLS_Firewall_Options");
63 add_submenu_page($base_page, "$pluginTitle ".GOTMLS_View_Quarantine_LANGUAGE, GOTMLS_View_Quarantine_LANGUAGE.(($Qs = GOTMLS_get_quarantine(true))?' <span class="awaiting-mod count-'.$Qs.'"><span class="awaiting-mod">'.$Qs.'</span></span>':""), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS_View_Quarantine", "GOTMLS_View_Quarantine");
64 }
65 }
66 add_action("admin_menu", "GOTMLS_menu");
67 add_action("network_admin_menu", "GOTMLS_menu");
68
69 function GOTMLS_admin_add_help_tab() {
70 $screen = get_current_screen();
71 $screen->add_help_tab(array(
72 'id' => "GOTMLS_Getting_Started",
73 'title' => __("Getting Started", 'gotmls'),
74 'content' => '<p>'.__("Make sure the Definition Updates are current and Run a Complete Scan.").'</p><p>'.sprintf(__("If Known Threats are found and displayed in red then there will be a button to '%s'. If only Potentional Threats are found then there is no automatic fix because those are probably not malicious."), GOTMLS_Automatically_Fix_LANGUAGE).'</p><p>'.__("A backup of the original infected files are placed in the Quarantine in case you need to restore them or just want to look at them later. You can delete these files if you don't want to save more.").'</p>'
75 ));
76 $FAQMarker = '== Frequently Asked Questions ==';
77 if (is_file(dirname(__FILE__).'/readme.txt') && ($readme = explode($FAQMarker, @file_get_contents(dirname(__FILE__).'/readme.txt').$FAQMarker)) && strlen($readme[1]) && ($readme = explode("==", $readme[1]."==")) && strlen($readme[0])) {
78 $screen->add_help_tab(array(
79 'id' => "GOTMLS_FAQs",
80 'title' => __("FAQs", 'gotmls'),
81 'content' => '<p>'.preg_replace('/\[(.+?)\]\((.+?)\)/', "<a target=\"_blank\" href=\"\\2\">\\1</a>", preg_replace('/[\r\n]+= /', "</p><b>", preg_replace('/ =[\r\n]+/', "</b><p>", $readme[0]))).'</p>'
82 ));
83 }
84 }
85
86 function GOTMLS_enqueue_scripts() {
87 wp_enqueue_style('dashicons');
88 }
89 add_action('admin_enqueue_scripts', 'GOTMLS_enqueue_scripts');
90
91 function GOTMLS_display_header($optional_box = "") {
92 global $current_user, $wpdb;
93 wp_get_current_user();
94 $head_nonce = GOTMLS_set_nonce(__FUNCTION__."95");
95 $GOTMLS_url_parts = explode('/', GOTMLS_siteurl);
96 $Update_Definitions = array(GOTMLS_update_home.'definitions.js'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"].'&'.GOTMLS_get_version_URL.'&'.$head_nonce.'&d='.ur1encode(GOTMLS_siteurl));
97 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])
98 array_unshift($Update_Definitions, admin_url('admin-ajax.php?action=GOTMLS_load_update&'.$head_nonce.'&UPDATE_definitions_array=1'));
99 else
100 $Update_Definitions[] = str_replace("//", "//www.", $Update_Definitions[0]);
101 $Update_Link = '<div style="text-align: center;"><a href="';
102 $new_version = "";
103 $file = basename(GOTMLS_plugin_path).'/index.php';
104 $current = get_site_transient("update_plugins");
105 if (isset($current->response[$file]->new_version) && version_compare(GOTMLS_Version, $current->response[$file]->new_version, "<")) {
106 $new_version = sprintf(__("Upgrade to %s now!",'gotmls'), $current->response[$file]->new_version).'<br /><br />';
107 $Update_Link .= wp_nonce_url(self_admin_url('update.php?action=upgrade-plugin&plugin=').$file, 'upgrade-plugin_'.$file);
108 }
109 $Update_Link .= "\">$new_version</a></div>";
110 $defLatest = (is_numeric($Latest = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"]))) && is_numeric($Default = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Default"]))) && $Latest > $Default)?1:0;
111 if (is_array($keys = maybe_unserialize(get_option('GOTMLS_Installation_Keys', array()))) && isset($keys[GOTMLS_installation_key]))
112 $isRegistered = $keys[GOTMLS_installation_key];
113 else
114 $isRegistered = "";
115 $Update_Div ='<div id="findUpdates" style="display: none;"><center>'.__("Searching for updates ...",'gotmls').'<br /><img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /><br /><input type="button" value="Cancel" onclick="cancelserver(\'findUpdates\');" /></center></div>';
116 $php_version = "<li>PHP: <span class='GOTMLS_date'>".phpversion()."</span></li>\n";
117 if (isset($_SERVER["SERVER_SOFTWARE"]) && preg_match('/Apache\/([0-9\.]+)/i', $_SERVER["SERVER_SOFTWARE"], $GLOBALS["GOTMLS"]["tmp"]["apache"]) && count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
118 $php_version .= "<li>Apache: <span class='GOTMLS_date'>".$GLOBALS["GOTMLS"]["tmp"]["apache"][1]."</span></li>\n";
119 elseif (isset($_SERVER["SERVER_SOFTWARE"]) && strlen($_SERVER["SERVER_SOFTWARE"]))
120 $php_version .= "<li>".$_SERVER["SERVER_SOFTWARE"]."</li>\n";
121 if ((isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)) {
122 $reg_email_key = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
123 $isRegistered = GOTMLS_get_registrant($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]);
124 } else
125 $reg_email_key = "";
126 echo GOTMLS_get_header().'
127 <div id="admin-page-container">
128 <div id="GOTMLS-right-sidebar" style="width: 300px;" class="metabox-holder">
129 '.GOTMLS_box(__("Updates & Registration",'gotmls'), "<ul>$php_version<li>".(function_exists('classicpress_version')?"ClassicPress: <span class='GOTMLS_date' title='CP: ".classicpress_version()."\nWP: ".GOTMLS_wp_version."'>".preg_replace( '#[+-].*$#', '', classicpress_version()):"WordPress: <span class='GOTMLS_date'>".GOTMLS_wp_version)."</span></li>\n<li>Plugin: <span class='GOTMLS_date'>".GOTMLS_Version.'</span></li>
130 <li><div id="GOTMLS_Key" style="margin: 0;'.((!$defLatest && !$isRegistered)?' display: none;">Key: <span style="float: right;">'.GOTMLS_installation_key.'</span></div><div style="':'">Key: <span style="float: right;" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">'.GOTMLS_installation_key.'</span></div><div style="display: none;').'"><form method="POST" action="'.admin_url('admin-ajax.php?'.$head_nonce).'" target="GOTMLS_iFrame" name="GOTMLS_Form_lognewkey"><input type="hidden" name="GOTMLS_installation_key" value="'.GOTMLS_installation_key.'"><input type="hidden" name="action" value="GOTMLS_lognewkey"><span style="color: #F00;" id="GOTMLS_No_Key">No Key! <input type="submit" style="float: right;" value="'.__("Get FREE Key!",'gotmls').'" class="button-primary" onclick="showhide(\'GOTMLS_No_Key\');showhide(\'GOTMLS_Key\', true);check_for_updates(\'Definition_Updates\');" /></span></form></div></li>
131 <li>Definitions: <span id="GOTMLS_definitions_date" class="GOTMLS_date">'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"].'</span></li></ul>
132 <form id="updateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
133 <img style="display: none; float: left; margin-right: 4px;" src="'.GOTMLS_images_path.'checked.gif" height=16 width=16 alt="definitions updated" id="autoUpdateDownload" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">
134 '.str_replace('findUpdates', 'Definition_Updates', $Update_Div).'
135 <div id="autoUpdateForm" style="display: none;">
136 <input type="submit" style="width: 100%;" name="auto_update" value="'.__("Download new definitions!",'gotmls').'">
137 </div>
138 </form>
139 <form id="clearupdateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
140 <input name="UPDATE_definitions_array" value="D" type="hidden">
141 <input type="submit" style="display: none; width: 100%; color: #ff0; background-color: #c33" id="clear_updates" value="'.__("Delete ALL definitions!",'gotmls').'">
142 </form>
143 <div id="registerKeyForm" style="display: none;"><span id="registerFormMessage" style="color: #F00">'.__("<p>Get instant access to definition updates.</p>",'gotmls').'</span><p>
144 '.__("If you have not already registered your Key then register now using the form below.<br />* All registration fields are required<br />** I will NOT share your information.",'gotmls').'</p>
145 <form id="registerform" onsubmit="return sinupFormValidate(this);" action="'.GOTMLS_plugin_home.'wp-login.php?action=register" method="post" name="registerform" target="_blank"><input type="hidden" name="redirect_to" id="register_redirect_to" value="/donate/"><input type="hidden" name="user_login" id="register_user_login" value=""><input type="hidden" name="old_user_email" id="old_user_email" value="'.$reg_email_key.'">
146 <div>'.__("Your Full Name:",'gotmls').'</div>
147 <div style="float: left; width: 50%;"><input style="width: 100%;" id="first_name" type="text" name="first_name" value="'.$current_user->user_firstname.'" /></div>
148 <div style="float: left; width: 50%;"><input style="width: 100%;" id="last_name" type="text" name="last_name" value="'.$current_user->user_lastname.'" /></div>
149 <div style="clear: left; width: 100%;">
150 <div>'.__("A password will be e-mailed to this address:",'gotmls').(strlen($reg_email_key) == 32 && $reg_email_key != md5($current_user->user_email)?'<br /><span style="color: #C00;">'.__("Note: The pre-populated email below is NOT the address this site is currently registered under!",'gotmls').'</span>':"").'</div>
151 <input style="width: 100%;" id="user_email" type="text" name="user_email" value="'.$current_user->user_email.'" /></div>
152 <div>
153 <div>'.__("Your WordPress Site URL:",'gotmls').'</div>
154 <input style="width: 100%;" id="user_url" type="text" name="user_url" value="'.GOTMLS_siteurl.'" readonly /></div>
155 <div>
156 <div>'.__("Plugin Installation Key:",'gotmls').'</div>
157 <input style="width: 100%;" id="installation_key" type="text" name="installation_key" value="'.GOTMLS_installation_key.'" readonly /><input id="old_key" type="hidden" name="old_key" value="'.md5($GOTMLS_url_parts[2]).'" /></div>
158 <input style="width: 100%;" id="wp-submit" type="submit" name="wp-submit" value="Register Now!" /></form></div>'.(false && $isRegistered?'Registered to: '.$isRegistered:"").$Update_Link, "stuffbox").'
159 <script type="text/javascript">
160 var alt_addr = "'.$Update_Definitions[1].'";
161 function check_for_updates(update_type) {
162 showhide(update_type, true);
163 stopCheckingDefinitions = checkupdateserver("'.$Update_Definitions[0].'", update_type, alt_addr);
164 }
165 function updates_complete(chk) {
166 if (auto_img = document.getElementById("autoUpdateDownload")) {
167 auto_img.style.display="block";
168 check_for_donation(chk);
169 }
170 }
171 function sinupFormValidate(form) {
172 var error = "";
173 if(form["first_name"].value == "")
174 error += "'.__("First Name is a required field!",'gotmls').'\n";
175 if(form["last_name"].value == "")
176 error += "'.__("Last Name is a required field!",'gotmls').'\n";
177 if(form["user_email"].value == "")
178 error += "'.__("Email Address is a required field!",'gotmls').'\n";
179 else {
180 if (uem = document.getElementById("register_user_login"))
181 uem.value = form["user_email"].value;
182 if (uem = document.getElementById("register_redirect_to"))
183 uem.value = "/donate/?email="+form["user_email"].value.replace("@", "%40");
184 }
185 if(form["user_url"].value == "")
186 error += "'.__("Your WordPress Site URL is a required field!",'gotmls').'\n";
187 if(form["installation_key"].value == "")
188 error += "'.__("Plugin Installation Key is a required field!",'gotmls').'\n";
189 if(error != "") {
190 alert(error);
191 return false;
192 } else {
193 document.getElementById("Definition_Updates").innerHTML = \'<img src="'.GOTMLS_images_path.'wait.gif">'.GOTMLS_strip4java(__("Submitting Registration ...",'gotmls')).'\';
194 showhide("Definition_Updates", true);
195 setTimeout(\'stopCheckingDefinitions = checkupdateserver("'.$Update_Definitions[0].'", "Definition_Updates", "'.$Update_Definitions[1].'")\', 11000);
196 showhide("registerKeyForm");
197 return true;
198 }
199 }
200 var divNAtext = false;
201 function loadGOTMLS() {
202 clearTimeout(divNAtext);
203 setDivNAtext();
204 '.$GLOBALS["GOTMLS"]["tmp"]["onLoad"].'
205 }
206 if ('.($defLatest+strlen($isRegistered)).')
207 check_for_updates("Definition_Updates");
208 /* else
209 showhide("registerKeyForm", true);*/
210 if (divNAtext)
211 loadGOTMLS();
212 else
213 divNAtext=true;
214 </script>
215 '.GOTMLS_box(__("Resources & Links",'gotmls'), '
216 <div id="pastDonations"></div>
217 <center>
218 <a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span> Donate Here <span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span></a>
219 </center>
220 <ul class="GOTMLS-sidebar-links">
221 <li style="float: right;"><b>on <a target="_blank" href="https://profiles.wordpress.org/scheeeli#content-plugins">WordPress.org</a></b><ul class="GOTMLS-sidebar-links">
222 <li><a target="_blank" href="https://wordpress.org/plugins/gotmls/faq/">Plugin FAQs</a></li>
223 <li><a target="_blank" href="https://wordpress.org/support/plugin/gotmls">Forum Posts</a></li>
224 <li><a target="_blank" href="https://wordpress.org/support/view/plugin-reviews/gotmls">Plugin Reviews</a></li>
225 </ul></li>
226 <li><img src="//gravatar.com/avatar/5feb789dd3a292d563fea3b885f786d6?s=16" border="0" alt="Plugin site:"><b><a target="_blank" href="'.GOTMLS_plugin_home.'">GOTMLS.NET</a></b></li>
227 <li><img src="//gravatar.com/avatar/8151cac22b3fc543d099241fd573d176?s=16" border="0" alt="Developer site:"><b><a target="_blank" href="http://wordpress.ieonly.com/category/my-plugins/anti-malware/">Eli\'s Blog</a></b></li>
228 <li><img src="https://s.gravatar.com/avatar/7530906968df6594bfbe934ddc117f58?s=16" border="0" alt="mail:"><b><a target="_blank" href="mailto:eli@gotmls.net">Email Eli</a></b></li>
229 </ul>
230 <a target="_blank" href="https://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html#url='.urlencode(GOTMLS_siteurl).'">Google Safe Browsing Diagnostic</a>', "stuffbox").//GOTMLS_box(__("Last Scan Status",'gotmls'), GOTMLS_scan_log(), "stuffbox").
231 $optional_box.'</div>';
232 if (isset($GLOBALS["GOTMLS"]["tmp"]["stuffbox"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["stuffbox"])) {
233 echo '
234 <script type="text/javascript">
235 function stuffbox_showhide(id) {
236 divx = document.getElementById(id);
237 if (divx) {
238 if (divx.style.display == "none" || arguments[1]) {';
239 $else = '
240 if (divx = document.getElementById("GOTMLS-right-sidebar"))
241 divx.style.width = "30px";
242 if (divx = document.getElementById("GOTMLS-main-section"))
243 divx.style.marginRight = "30px";';
244 foreach ($GLOBALS["GOTMLS"]["tmp"]["stuffbox"] as $md5 => $bTitle) {
245 echo "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'block';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".GOTMLS_strip4java($bTitle, true)."';";
246 $else .= "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'none';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".substr($bTitle, 0, 1)."';";
247 }
248 echo '
249 if (divx = document.getElementById("GOTMLS-right-sidebar"))
250 divx.style.width = "300px";
251 if (divx = document.getElementById("GOTMLS-main-section"))
252 divx.style.marginRight = "300px";
253 return true;
254 } else {'.$else.'
255 return false;
256 }
257 }
258 }
259 if (getWindowWidth(780) == 780)
260 setTimeout("stuffbox_showhide(\'inside_'.$md5.'\')", 200);
261 </script>';
262 }
263 echo '
264 <div id="GOTMLS-main-section" style="margin-right: 300px;">
265 <div class="metabox-holder GOTMLS" style="width: 100%;" id="GOTMLS-metabox-container">';
266 }
267
268 function GOTMLS_get_scanlog() {
269 global $wpdb;
270 $LastScan = '';
271 if (isset($_GET["GOTMLS_cl"]) && is_numeric($_GET["GOTMLS_cl"]) && GOTMLS_get_nonce()) {
272 $SQL = $wpdb->prepare("DELETE FROM `$wpdb->options` WHERE option_name LIKE %s AND substring_index(option_name, '/', -1) < %s", 'GOTMLS_scan_log/%', $_GET["GOTMLS_cl"]);
273 if ($cleared = $wpdb->query($SQL))
274 $LastScan .= sprintf(__("Cleared %s records from the history.",'gotmls'), $cleared);
275 // else $LastScan .= $wpdb->last_error."<li>$SQL</li>";
276 }
277 $SQL = $wpdb->prepare("SELECT substring_index(option_name, '/', -1) AS `mt`, option_name, option_value FROM `$wpdb->options` WHERE option_name LIKE %s ORDER BY mt DESC", 'GOTMLS_scan_log/%');
278 if ($rs = $wpdb->get_results($SQL, ARRAY_A)) {
279 $units = array("seconds"=>60,"minutes"=>60,"hours"=>24,"days"=>365,"years"=>10);
280 $LastScan .= '<ul class="GOTMLS-scanlog GOTMLS-sidebar-links">';
281 foreach ($rs as $row) {
282 $LastScan .= "\n<li>";
283 $GOTMLS_scan_log = (isset($row["option_name"])?get_option($row["option_name"], array()):array());
284 if (isset($GOTMLS_scan_log["scan"]["type"]) && strlen($GOTMLS_scan_log["scan"]["type"]))
285 $LastScan .= GOTMLS_sanitize($GOTMLS_scan_log["scan"]["type"]);
286 else
287 $LastScan .= "Unknown scan type";
288 if (isset($GOTMLS_scan_log["scan"]["dir"]) && is_dir($GOTMLS_scan_log["scan"]["dir"]))
289 $LastScan .= " of ".basename($GOTMLS_scan_log["scan"]["dir"]);
290 if (isset($GOTMLS_scan_log["scan"]["start"]) && is_numeric($GOTMLS_scan_log["scan"]["start"])) {
291 $time = (time() - $GOTMLS_scan_log["scan"]["start"]);
292 $ukeys = array_keys($units);
293 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= $units[$ukeys[$key]]); $unit = $ukeys[++$key])
294 $time = floor($time/$units[$ukeys[$key]]);
295 if (1 == $time)
296 $unit = substr($unit, 0, -1);
297 $LastScan .= " started $time $unit ago";
298 if (isset($GOTMLS_scan_log["scan"]["finish"]) && is_numeric($GOTMLS_scan_log["scan"]["finish"]) && ($GOTMLS_scan_log["scan"]["finish"] >= $GOTMLS_scan_log["scan"]["start"])) {
299 $time = ($GOTMLS_scan_log["scan"]["finish"] - $GOTMLS_scan_log["scan"]["start"]);
300 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= $units[$ukeys[$key]]); $unit = $ukeys[++$key])
301 $time = floor($time/$units[$ukeys[$key]]);
302 if (1 == $time)
303 $unit = substr($unit, 0, -1);
304 if ($time)
305 $LastScan .= " and ran for $time $unit";
306 else
307 $LastScan = str_replace("started", "ran", $LastScan);
308 } else
309 $LastScan .= " and has not finish";
310 } else
311 $LastScan .= " failed to started";
312 $LastScan .= '<a href="'.GOTMLS_script_URI.'&GOTMLS_cl='.$row["mt"].'&'.GOTMLS_set_nonce(__FUNCTION__."313").'">[clear history below this entry]</a></li>';
313 }
314 $LastScan .= '</ul>';
315 } else
316 $LastScan .= '<h3>'.__("No Scans have been logged",'gotmls').'</h3>';
317 return "$LastScan\n";
318 }
319
320 function GOTMLS_get_whitelists() {
321 $Q_Page = '';
322 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"])) {
323 $Q_Page .= '<ul name="found_Quarantine" id="found_Quarantine" class="GOTMLS_plugin known" style="background-color: #ccc; padding: 0;"><h3>'.__("Globally White-listed files",'gotmls').'<span class="GOTMLS_date">'.__("# of patterns",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Updated",'gotmls').'</span></h3>';
324 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"] as $file => $non_threats) {
325 if (isset($non_threats[0])) {
326 $updated = GOTMLS_sexagesimal($non_threats[0]);
327 unset($non_threats[0]);
328 } else
329 $updated = "Unknown";
330 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($non_threats).'</span><span class="GOTMLS_date">'.$updated."</span>$file</li>\n";
331 }
332 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"])) {
333 $Q_Page .= '<h3>'.__("WordPress Core files",'gotmls').'<span class="GOTMLS_date">'.__("# of files",'gotmls').'</span></h3>';
334 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"] as $ver => $files) {
335 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($files)."</span>Version $ver</li>\n";
336 }
337 }
338 $Q_Page .= "</ul>";
339 }
340 return "$Q_Page\n";
341 }
342
343 function GOTMLS_Quarantine_Trash() {
344 global $wpdb;
345 $Q_Page = '<div id="empty_trash_link" style="float: right;"><form method="post" onsubmit="if (curDiv = document.getElementById(\'empty_trash_link\')) curDiv.style.display = \'none\';" target="GOTMLS_statusFrame" action="'.admin_url('admin-ajax.php?action=GOTMLS_empty_trash&'.GOTMLS_set_nonce(__FUNCTION__."346")).'">';
346 if (($trashed = $wpdb->get_var("SELECT COUNT(*) FROM $wpdb->posts WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) > 1)
347 $Q_Page .= '<input class="primary" style="float: right;" type="submit" value="RESTORE" name="alter"><input class="primary" style="color: red; float: right;" type="submit" value="DELETE" name="alter"><span style="float: right; margin: 3px;">'.sprintf(__("%d Quarantine Records in the Trash",'gotmls'), (INT) $trashed)."</span>";
348 return "$Q_Page</form></div>\n";
349 }
350
351 function GOTMLS_ajax_View_Quarantine() {
352 GOTMLS_ajax_load_update();
353 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_get_header().GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine())))));
354 }
355
356 function GOTMLS_View_Quarantine() {
357 GOTMLS_ajax_load_update();
358 $echo = GOTMLS_box($Q_Page = __("White-lists",'gotmls'), GOTMLS_get_whitelists());
359 if (!isset($_GET['Whitelists']))
360 $echo .= "\n<script>\nshowhide('inside_".md5($Q_Page)."');\n</script>\n";
361 $echo .= GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine());
362 GOTMLS_display_header();
363 echo "$echo\n</div></div></div>";
364 }
365
366 function GOTMLS_Firewall_Options() {
367 global $current_user, $wpdb, $table_prefix;
368 GOTMLS_ajax_load_update();
369 GOTMLS_display_header();
370 $GOTMLS_nonce_found = GOTMLS_get_nonce();
371 $gt = ">"; // This local variable never changes
372 $lt = "<"; // This local variable never changes
373 $save_action = "";
374 $patch_attr = array(
375 array(
376 "icon" => "blocked",
377 "language" => "<b>".__("(This patch only works under Apache servers and requires mod_rewrite and session_start to be active and functional)",'gotmls')."</b><br />\n".__("Your WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. Applying this patch will block access to the WordPress Login page whenever this type of attack is detected.",'gotmls'),
378 "status" => __('Not Installed','gotmls'),
379 "action" => __('Install Patch','gotmls')
380 ),
381 array(
382 "language" => __("Your WordPress site has the current version of my brute-force Login protection installed.",'gotmls'),
383 "action" => __('Uninstall Patch','gotmls'),
384 "status" => __('Enabled','gotmls'),
385 "icon" => "checked"
386 ),
387 array(
388 "language" => __("Your WordPress Login page has the old version of my brute-force protection installed. Upgrade this patch to improve the protection on the WordPress Login page and preserve the integrity of your WordPress core files.",'gotmls'),
389 "action" => __('Upgrade Patch','gotmls'),
390 "status" => __('Out of Date','gotmls'),
391 "icon" => "threat"
392 )
393 );
394 $find = '|<Files[^>]+xmlrpc.php>(.+?)</Files>\s*(# END GOTMLS Patch to Block XMLRPC Access\s*)*|is';
395 $deny = "\n<IfModule !mod_authz_core.c>\norder deny,allow\ndeny from all";
396 $allow = "";
397 if (isset($_SERVER["REMOTE_ADDR"])) {
398 $deny .= "\nallow from ".$_SERVER["REMOTE_ADDR"];
399 $allow .= " ".$_SERVER["REMOTE_ADDR"];
400 }
401 if (isset($_SERVER["SERVER_ADDR"])) {
402 $deny .= "\nallow from ".$_SERVER["SERVER_ADDR"];
403 $allow .= " ".$_SERVER["SERVER_ADDR"];
404 }
405 $deny .= "\n</IfModule>\n<IfModule mod_authz_core.c>\nRequire";
406 if (strlen(trim($allow)) > 0)
407 $deny .= " ip$allow";
408 else
409 $deny .= " all denied";
410 $deny .= "\n</IfModule>";
411 if (count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
412 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
413 else {
414 if (isset($GLOBALS["GOTMLS"]["tmp"]["apache"][0]) && (strtolower(substr($GLOBALS["GOTMLS"]["tmp"]["apache"][0]."123456", 0, 6)) == "apache"))
415 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
416 else
417 $errdiv = "<div class='error'>".__('Unable to find Apache on this server, this patch work on Apache servers!','gotmls')."</div>";
418 }
419 $Firewall_nonce = $lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."420")).'"'.$gt;
420 $patch_action = $lt.'form method="POST" name="GOTMLS_Form_XMLRPC_patch"'.$gt.$Firewall_nonce.$lt.'script'.$gt."\nfunction setFirewall(opt, val) {\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_opt'))\n\t\tautoUpdateDownloadGIF.value = opt;\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_val'))\n\t\tautoUpdateDownloadGIF.value = val;\n}\nfunction testComplete() {\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_XMLRPC_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_XMLRPC_patch_searching');\n\tshowhide('GOTMLS_XMLRPC_patch_button', true);\n}\n}\nwindow.onload=testComplete;\n$lt/script$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="hidden" name="GOTMLS_XMLRPC_patching" value="';
421 $patch_found = false;
422 $head = str_replace(array('|<Files[^>]+', '(.+?)', '\\s*(', '\\s*)*|is'), array("<Files ", "$deny\n", "\n", "\n"), $find);
423 $htaccess = "";
424 if (is_file(ABSPATH.'.htaccess'))
425 if (($htaccess = @file_get_contents(ABSPATH.'.htaccess')) && strlen($htaccess))
426 $patch_found = preg_match($find, $htaccess);
427 if ($patch_found) {
428 $errdiv = "";
429 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0) && GOTMLS_file_put_contents(ABSPATH.'.htaccess', preg_replace($find, "", $htaccess)))
430 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Allowing Access';
431 elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0))
432 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Blocking: '.sprintf(__("Failed to remove XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
433 else
434 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Blocked';
435 } else {
436 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0) && GOTMLS_file_put_contents(ABSPATH.'.htaccess', "$head$htaccess")) {
437 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Blocked';
438 $errdiv = "";
439 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0))
440 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Allowing Access: '.sprintf(__("Failed to install XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
441 else
442 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Allowing Access';
443 }
444 $patch_action .= ")$errdiv$lt/b$gt$lt/p$gt".__("Most WordPress sites do not use the XMLRPC features and hack attempts on the xmlrpc.php file are more common then ever before. Even if there are no vulnerabilities for hackers to exploit, these attempts can cause slowness or downtime similar to a DDoS attack. This patch automatically blocks all external access to the xmlrpc.php file.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt.$lt.'hr /'.$gt;
445 $patch_status = 0;
446 $patch_found = -1;
447 $find = "#if\s*\(([^\&]+\&\&)?\s*file_exists\((.+?)(safe-load|wp-login)\.php'\)\)\s*require(_once)?\((.+?)(safe-load|wp-login)\.php'\);#";
448 $head = str_replace(array('#', '\\(', '\\)', '(_once)?', ')\\.', '\\s*', '(.+?)(', '|', '([^\\&]+\\&\\&)?'), array(' ', '(', ')', '_once', '.', ' ', '\''.dirname(__FILE__).'/', '/', '!in_array($_SERVER["REMOTE_ADDR"], array("'.$_SERVER["REMOTE_ADDR"].'")) &&'), $find);
449 if (is_file(ABSPATH.'../wp-config.php') && !is_file(ABSPATH.'wp-config.php'))
450 $wp_config = '../wp-config.php';
451 else
452 $wp_config = 'wp-config.php';
453 if (is_file(ABSPATH.$wp_config)) {
454 if (($config = @file_get_contents(ABSPATH.$wp_config)) && strlen($config)) {
455 if ($patch_found = preg_match($find, $config)) {
456 if (strpos($config, substr($head, strpos($head, "file_exists")))) {
457 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && GOTMLS_file_put_contents(ABSPATH.$wp_config, preg_replace('#'.$lt.'\?[ph\s]+(//.*\s*)*\?'.$gt.'#i', "", preg_replace($find, "", $config))))
458 $patch_action .= $lt.'div class="error"'.$gt.__("Removed Brute-Force Protection",'gotmls').$lt.'/div'.$gt;
459 else
460 $patch_status = 1;
461 } else {
462 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && GOTMLS_file_put_contents(ABSPATH.$wp_config, preg_replace($find, "$head", $config))) {
463 $patch_action .= $lt.'div class="updated"'.$gt.__("Upgraded Brute-Force Protection",'gotmls').$lt.'/div'.$gt;
464 $patch_status = 1;
465 } else
466 $patch_status = 2;
467 }
468 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && strlen($config) && ($patch_found == 0) && GOTMLS_file_put_contents(ABSPATH.$wp_config, "$lt?php$head// Load Brute-Force Protection by GOTMLS.NET before the WordPress bootstrap. ?$gt$config")) {
469 $patch_action .= $lt.'div class="updated"'.$gt.__("Installed Brute-Force Protection",'gotmls').$lt.'/div'.$gt;
470 $patch_status = 1;
471 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]))
472 $patch_action .= $lt.'div class="updated"'.$gt.sprintf(__("Failed to install Brute-Force Protection (wp-config.php %s)",'gotmls'),(is_readable(ABSPATH.$wp_config)?'read-'.(is_writable(ABSPATH.$wp_config)?'write':'only'):"unreadable").": ".strlen($config).GOTMLS_fileperms(ABSPATH.$wp_config)).$lt.'/div'.$gt;
473 } else
474 $patch_action .= $lt.'div class="error"'.$gt.__("wp-config.php Not Readable!",'gotmls').$lt.'/div'.$gt;
475 } else
476 $patch_action .= $lt.'div class="error"'.$gt.__("wp-config.php Not Found!",'gotmls').$lt.'/div'.$gt;
477 if ($GOTMLS_nonce_found && file_exists(ABSPATH.'wp-login.php') && ($login = @file_get_contents(ABSPATH.'wp-login.php')) && strlen($login) && (preg_match($find, $login))) {
478 if (isset($_POST["GOTMLS_patching"]) && ($source = GOTMLS_get_URL("http://core.svn.wordpress.org/tags/".GOTMLS_wp_version.'/wp-login.php')) && (strlen($source) > 500) && GOTMLS_file_put_contents(ABSPATH.'wp-login.php', $source))
479 $patch_action .= $lt.'div class="updated"'.$gt.__("Removed Old Brute-Force Login Patch",'gotmls').$lt.'/div'.$gt;
480 else
481 $patch_status = 2;
482 }
483 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_firewall_option"]) && strlen($_POST["GOTMLS_firewall_option"]) && isset($_POST["GOTMLS_firewall_value"]) && strlen($_POST["GOTMLS_firewall_value"])) {
484 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"][GOTMLS_sanitize($_POST["GOTMLS_firewall_option"])] = (INT) $_POST["GOTMLS_firewall_value"];
485 if (update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]))
486 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";
487 else
488 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSave Failed!$lt/div$gt\n";
489 }
490 $sec_opts = $lt.'form method="POST" name="GOTMLS_Form_firewall"'.$gt.$lt.'input type="hidden" id="fw_opt" name="GOTMLS_firewall_option" value="traversal"'.$gt.$lt.'input type="hidden" name="GOTMLS_firewall_value" id="fw_val" value="0"'.$gt.$Firewall_nonce;
491 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]) && array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]))
492 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"] as $TP => $VA)
493 if (is_array($VA) && count($VA) > 3 && strlen($VA[1]) && strlen($VA[2]))
494 $sec_opts .= $lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="submit" style="float: right;" value="'.(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]?"Enable Protection\" onclick=\"setFirewall('$TP', 0);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt."b$gt$VA[1] (Currently Disabled)":"Disable Protection\" onclick=\"setFirewall('$TP', 1);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt."b$gt$VA[1] (Automatically Enabled)")."$lt/b$gt$lt/p$gt$VA[2]$lt/div$gt$lt".'hr /'.$gt;
495 $sec_opts .= "$lt/form$gt\n$patch_action\n$lt".'form method="POST" name="GOTMLS_Form_patch"'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$Firewall_nonce.$lt.'input type="submit" value="'.$patch_attr[$patch_status]["action"].'" style="float: right;'.($patch_status?'"'.$gt:' display: none;" id="GOTMLS_patch_button"'.$gt.$lt.'div id="GOTMLS_patch_searching" style="float: right;"'.$gt.__("Checking for session compatibility ...",'gotmls').' '.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /'.$gt.$lt.'/div'.$gt).$lt.'input type="hidden" name="GOTMLS_patching" value="1"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$patch_attr[$patch_status]["icon"].'.gif"'.$gt.$lt.'b'.$gt.'Brute-force Protection '.$patch_attr[$patch_status]["status"].$lt.'/b'.$gt.$lt.'/p'.$gt.$patch_attr[$patch_status]["language"].__(" For more information on Brute-Force attack prevention and the WordPress wp-login-php file ",'gotmls').' '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-login-php/"'.$gt.__("read my blog",'gotmls')."$lt/a$gt.$lt/div$gt$lt/form$gt\n$lt"."script type='text/javascript'$gt\nfunction search_patch_onload() {\n\tstopCheckingSession = checkupdateserver('".admin_url('admin-ajax.php?action=GOTMLS_log_session')."', 'GOTMLS_patch_searching');\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', search_patch_onload)\nelse\n\tdocument.attachEvent('onload', search_patch_onload);\n$lt/script$gt";
496 $admin_notice = "";
497 if ($current_user->user_login == "admin") {
498 $admin_notice .= $lt.'hr /'.$gt;
499 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_admin_username"]) && ($current_user->user_login != trim($_POST["GOTMLS_admin_username"])) && strlen(trim($_POST["GOTMLS_admin_username"])) && preg_match('/^\s*[a-z_0-9\@\.\-]{3,}\s*$/i', $_POST["GOTMLS_admin_username"])) {
500 if ($wpdb->update($wpdb->users, array("user_login" => trim($_POST["GOTMLS_admin_username"])), array("user_login" => $current_user->user_login))) {
501 $wpdb->query($wpdb->prepare("UPDATE `{$wpdb->prefix}sitemeta` SET `meta_value` = REPLACE(`meta_value`, 's:5:\"admin\";', %s) WHERE `meta_key` = 'site_admins' AND `meta_value` like %s", 's:'.strlen(trim($_POST["GOTMLS_admin_username"])).':"'.trim($_POST["GOTMLS_admin_username"]).'";', '%s:5:"admin";%'));
502 $admin_notice .= $lt.'div class="updated"'.$gt.sprintf(__("You username has been change to %s. Don't forget to use your new username when you login again.",'gotmls'), $_POST["GOTMLS_admin_username"]).$lt.'/div'.$gt;
503 } else
504 $admin_notice .= $lt.'div class="error"'.$gt.sprintf(__("SQL Error changing username: %s. Please try again later.",'gotmls'), $wpdb->last_error).$lt.'/div'.$gt;
505 } else {
506 if (isset($_POST["GOTMLS_admin_username"]))
507 $admin_notice .= $lt.'div class="updated"'.$gt.sprintf(__("Your new username must be at least 3 characters and can only contain &quot;%s&quot;. Please try again.",'gotmls'), "a-z0-9_.-@").$lt.'/div'.$gt;
508 $admin_notice .= $lt.'form method="POST" name="GOTMLS_Form_admin"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'div style="float: left;"'.$gt.__("Change your username:",'gotmls').$lt.'/div'.$gt.$Firewall_nonce.$lt.'input style="float: left;" type="text" id="GOTMLS_admin_username" name="GOTMLS_admin_username" size="6" value="'.$current_user->user_login.'"'.$gt.$lt.'input style="float: left;" type="submit" value="Change"'.$gt.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Admin Notice'.$lt.'/b'.$gt.$lt.'/p'.$gt.__("Your username is \"admin\", this is the most commonly guessed username by hackers and brute-force scripts. It is highly recommended that you change your username immediately.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt;
509 }
510 }
511 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_wpfirewall_action"])) {
512 if ($_POST["GOTMLS_wpfirewall_action"] == "exclude_terms")
513 update_option("WP_firewall_exclude_terms", "");
514 elseif ($_POST["GOTMLS_wpfirewall_action"] == "whitelisted_ip" && isset($_SERVER["REMOTE_ADDR"])) {
515 $ips = maybe_unserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"));
516 if (is_array($ips))
517 $ips = array_merge($ips, array($_SERVER["REMOTE_ADDR"]));
518 else
519 $ips = array($_SERVER["REMOTE_ADDR"]);
520 update_option("WP_firewall_whitelisted_ip", serialize($ips));
521 }
522 }
523 if (get_option("WP_firewall_exclude_terms", "Not Found!") == "allow") {
524 $end = "$lt/div$gt$lt/form$gt\n{$lt}hr /$gt";
525 $img = 'threat.gif"';
526 $button = $lt.'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'exclude_terms\';" value="'.__("Disable this Rule",'gotmls').'"'.$gt;
527 $wpfirewall_action = $lt.'form method="POST" name="GOTMLS_Form_wpfirewall2"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="hidden" name="GOTMLS_wpfirewall_action" id="GOTMLS_wpfirewall_action" value=""'.$gt.$Firewall_nonce.$button.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$img.$gt.$lt.'b'.$gt."WP Firewall 2 (Conflicting Firewall Rule)$lt/b$gt$lt/p$gt".__("The Conflicting Firewall Rule (WP_firewall_exclude_terms) activated by the WP Firewall 2 plugin has been shown to interfere with the Definition Updates and WP Core File Scans in my Anti-Malware plugin. I recommend that you disable this rule in the WP Firewall 2 plugin.",'gotmls').$end;
528 if (isset($_SERVER["REMOTE_ADDR"])) {
529 if (is_array($ips = maybe_unserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"))) && in_array($_SERVER["REMOTE_ADDR"], $ips))
530 $wpfirewall_action = str_replace(array($img, $end), array('question.gif"', __(" However, your current IP has been Whitelisted so you could probably keep this rule enabled if you really want to.",'gotmls').$end), $wpfirewall_action);
531 else
532 $wpfirewall_action = str_replace(array($button, $end), array($button.$lt."br /$gt$lt".'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'whitelisted_ip\';" value="'.__("Whitelist your IP",'gotmls').'"'.$gt, __(" However, if you would like to keep this rule enabled you should at least Whitelist your IP.",'gotmls').$end), $wpfirewall_action);
533 }
534 $sec_opts = $wpfirewall_action.$sec_opts;
535 }
536 echo GOTMLS_box(__("Firewall Options",'gotmls'), $save_action.$sec_opts.$admin_notice)."\n</div></div></div>";
537 }
538
539 function GOTMLS_get_registrant($you) {
540 global $current_user, $wpdb;
541 wp_get_current_user();
542 if (isset($you["you"]))
543 $you = $you["you"];
544 if (isset($you["user_email"]) && strlen($you["user_email"]) == 32) {
545 if ($you["user_email"] == md5($current_user->user_email))
546 $registrant = $current_user->user_email;
547 elseif (!($registrant = $wpdb->get_var($wpdb->prepare("SELECT `user_nicename` FROM `$wpdb->users` WHERE MD5(`user_email`) = %s", $you["user_email"]))))
548 $registrant = GOTMLS_siteurl;
549 } else
550 $registrant = GOTMLS_siteurl;
551 return $registrant;
552 }
553
554 function GOTMLS_ajax_load_update() {
555 global $wpdb;
556 $GOTMLS_nonce_found = GOTMLS_get_nonce();
557 $GOTMLS_definitions_versions = array();
558 $user_info = array();
559 $saved = false;
560 $moreJS = "";
561 $finJS = "\n}";
562 $form = 'registerKeyForm';
563 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key could not be confirmed!</li>";
564 $autoUpJS = '<span style="color: #C00;">This new feature is currently only available to registered users who have donated $29 or more.</span><br />';
565 if (is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
566 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names)
567 foreach ($definition_names as $definition_name=>$definition_version)
568 if (is_array($definition_version) && isset($definition_version[0]) && strlen($definition_version[0]) == 5)
569 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
570 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
571 asort($GOTMLS_definitions_versions);
572 if (isset($_REQUEST["UPDATE_definitions_array"]) && strlen($_REQUEST["UPDATE_definitions_array"])) {
573 $DEF_url = 'http:'.GOTMLS_update_home.'definitions.php?'.GOTMLS_get_version_URL.'&'.GOTMLS_set_nonce(__FUNCTION__."574").'&d='.ur1encode(GOTMLS_siteurl);
574 if (strlen($_REQUEST["UPDATE_definitions_array"]) > 1 && $GOTMLS_nonce_found) {
575 $GOTnew_definitions = maybe_unserialize(GOTMLS_decode($_REQUEST["UPDATE_definitions_array"]));
576 if (is_array($GOTnew_definitions)) {
577 $form = 'autoUpdateDownload';
578 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('Downloaded Definitions');";
579 }
580 } elseif ($_REQUEST["UPDATE_definitions_array"] == "D" && $GOTMLS_nonce_found) {
581 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = array();
582 $GOTnew_definitions = array();
583 delete_option('GOTMLS_get_URL_array');
584 } elseif (($DEF = GOTMLS_get_URL($DEF_url)) && is_array($GOTnew_definitions = maybe_unserialize(GOTMLS_decode($DEF))) && count($GOTnew_definitions)) {
585 if (isset($GOTnew_definitions["you"]["user_email"]) && strlen($GOTnew_definitions["you"]["user_email"]) == 32) {
586 $toInfo = GOTMLS_get_registrant($GOTnew_definitions["you"]);
587 $innerHTML = "<li style=\\\"color: #0C0\\\">Your Installation Key is Registered to:<br /> $toInfo</li>";
588 $form = 'autoUpdateForm';
589 if (isset($GOTnew_definitions["you"]["user_donations"]) && isset($GOTnew_definitions["you"]["user_donation_total"]) && isset($GOTnew_definitions["you"]["user_donation_freshness"])) {
590 $user_donations_src = $GOTnew_definitions["you"]["user_donations"];
591 if ($GOTnew_definitions["you"]["user_donation_total"] > 27.99) {
592 $autoUpJS = '<input type="radio" id="auto_UPDATE_definitions_1" name="UPDATE_definitions_array" value="1">Yes | <input type="radio" id="auto_UPDATE_definitions_0" name="UPDATE_definitions_array" value="0" checked>No <input type="hidden" name="UPDATE_definitions_checkbox" value="UPDATE_definitions_array">';
593 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
594 foundUpdates.innerHTML = "<a href=\'javascript:document.getElementById(\\"GOTMLS_Form\\").submit();\' onclick=\'document.getElementById(\\"auto_UPDATE_definitions_1\\").checked=true;\' style=\'color: #f00;\'>Set Definition Updates to Automatically Download to activate this feature.</a>";';
595 }
596 if ($user_donations_src > 0 && $GOTnew_definitions["you"]["user_donation_total"] > 0)
597 $li = "<li> You have made $user_donations_src donation".($user_donations_src?'s totalling':' for').' $'.$GOTnew_definitions["you"]["user_donation_total"].".</li><!-- ".$GOTnew_definitions["you"]["user_donation_freshness"]." -->";
598 }
599 } else
600 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key is not registered!</li>";
601 asort($GOTnew_definitions);
602 if (serialize($GOTnew_definitions) == serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
603 unset($GOTnew_definitions);
604 else {
605 $debug = substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), 0, 9)." ".md5(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".strlen(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), -9)." != ".substr(serialize($GOTnew_definitions), 0, 9)." ".md5(serialize($GOTnew_definitions))." ".strlen(serialize($GOTnew_definitions)." ".substr(serialize($GOTnew_definitions), -9));
606 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = $GOTnew_definitions;
607 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('New Definitions Automatically Installed :-)');";
608 }
609 $finJS .= "\nif (divNAtext)\n\tloadGOTMLS();\nelse\n\tdivNAtext = setTimeout('loadGOTMLS()', 4000);";
610 $finJS .= "\nif (typeof stopCheckingDefinitions !== 'undefined')\n\tclearTimeout(stopCheckingDefinitions);";
611 } else
612 $innerHTML = "<li style=\\\"color: #f00\\\"><a title='report error' href='#' onclick=\\\"stopCheckingDefinitions = checkupdateserver(alt_addr+'&error=".GOTMLS_encode(serialize(array("get_URL"=>$GLOBALS["GOTMLS"]["get_URL"])))."', 'Definition_Updates');\\\">Automatic Update Connection Failed!</a></li>";
613 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]))
614 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]);
615 } else
616 $innerHTML = "<li style=\\\"color: #f00\\\">".__("definitions_array not set!", 'gotmls')."</li>";
617 if (isset($GOTnew_definitions) && is_array($GOTnew_definitions)) {
618 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = GOTMLS_array_replace($GLOBALS["GOTMLS"]["tmp"]["definitions_array"], $GOTnew_definitions);
619 if (file_exists(GOTMLS_plugin_path.'definitions_update.txt'))
620 @unlink(GOTMLS_plugin_path.'definitions_update.txt');
621 $saved = GOTMLS_update_option('definitions', $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]);
622 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
623 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names) {
624 if ($threat_level != "potential")
625 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $threat_level;
626 foreach ($definition_names as $definition_name=>$definition_version)
627 if (is_array($definition_version) && isset($definition_version[0]) && strlen($definition_version[0]) == 5)
628 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
629 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
630 }
631 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["log"]["settings"]["check"];
632 asort($GOTMLS_definitions_versions);
633 $autoUpJS .= '<span style="color: #0C0;">(Newest Definition Updates Installed.)</span>';
634 } elseif ($form != 'registerKeyForm') {
635 $form = 'autoUpdateDownload';
636 $autoUpJS .= '<span style="color: #0C0;">(No newer Definition Updates are available at this time.)</span>';
637 $innerHTML .= "<li style=\\\"color: #0C0\\\">No Newer Definition Updates Available.</li>";
638 }
639 if (isset($_SERVER["SCRIPT_FILENAME"]) && preg_match('/[\/\\\\]admin-ajax\.php/i', $_SERVER["SCRIPT_FILENAME"]) && isset($_REQUEST["action"]) && $_REQUEST["action"] == "GOTMLS_load_update") {
640 if (!$user_donations_src)
641 $li = "<li style=\\\"color: #f00;\\\">You have not donated yet!</li>";
642 if (strlen($moreJS) == 0)
643 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
644 foundUpdates.innerHTML = "<a target=\'_blank\' href=\'https://gotmls.net/donate/?key='.GOTMLS_installation_key.'\' style=\'color: #f00;\'>Donate $29+ now then enable Automatic Definition Updates to Scan for Core Files changes.</a>";';
645 $moreJS .= "\n\tif (foundUpdates = document.getElementById('pastDonations'))\n\tfoundUpdates.innerHTML = '$li';";
646 if ($GOTMLS_nonce_found)
647 @header("Content-type: text/javascript");
648 else
649 die(GOTMLS_Invalid_Nonce("Nonce Error: "));
650 if (is_array($GOTMLS_definitions_versions) && count($GOTMLS_definitions_versions) && (strlen($new_ver = trim(array_pop($GOTMLS_definitions_versions))) == 5) && $saved) {
651 $innerHTML .= "<li style=\\\"color: #0C0\\\">New Definition Updates Installed.</li>";
652 $finJS .= "\nif (foundUpdates = document.getElementById('GOTMLS_definitions_date')) foundUpdates.innerHTML = '$new_ver';\nif (foundUpdates = document.getElementById('autoUpdateForm')) foundUpdates.style.display = 'none';";
653 } elseif (isset($GOTnew_definitions) && is_array($GOTnew_definitions) && count($GOTnew_definitions))
654 $finJS .= "\nalert('Definition update $new_ver could not be saved because update_option Failed! (saved=".($saved?"TRUE":"FALSE").") $debug');";
655 if (isset($_REQUEST["UPDATE_core"]) && ($_REQUEST["UPDATE_core"] == GOTMLS_wp_version) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version])) {
656 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version] as $file => $md5) {
657 if (is_file(ABSPATH.$file)) {
658 $GLOBALS["GOTMLS"]["tmp"]["file_contents"] = file_get_contents(ABSPATH.$file);
659 if (GOTMLS_check_threat($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"], ABSPATH.$file)) {
660 if (isset($GLOBALS["GOTMLS"]["tmp"]["new_contents"]) && isset($_REQUEST["UPDATE_restore"]) && ($_REQUEST["UPDATE_restore"] == md5($GLOBALS["GOTMLS"]["tmp"]["new_contents"])."O".strlen($GLOBALS["GOTMLS"]["tmp"]["new_contents"])))
661 $autoUpJS .= "<li>Core File Restored: $file</li>";
662 else
663 $autoUpJS .= "<li>Core File MODIFIED: $file (".md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"])."O".strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"])." => $md5)</li>";
664 }
665 } else
666 $autoUpJS .= "<li>Core File MISSING: $file</li>";
667 }
668 $autoUpJS .= '<div class="update">Definition update: '.$_REQUEST["UPDATE_core"].' checked '.count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version]).' core files!</div>';
669 }
670 die('//<![CDATA[
671 var inc_form = "";
672 if (foundUpdates = document.getElementById("autoUpdateDownload"))
673 foundUpdates.src += "?'.$user_donations_src.'";
674 if (foundUpdates = document.getElementById("registerKeyForm"))
675 foundUpdates.style.display = "none";
676 if (foundUpdates = document.getElementById("'.$form.'"))
677 foundUpdates.style.display = "block";
678 if (foundUpdates = document.getElementById("Definition_Updates"))
679 foundUpdates.innerHTML = "<ul class=\\"GOTMLS-sidebar-links\\">'.$innerHTML.'</ul>"+inc_form;
680 function setDivNAtext() {
681 var foundUpdates;
682 '.$moreJS.$finJS.'
683 if (foundUpdates = document.getElementById("UPDATE_definitions_div"))
684 foundUpdates.innerHTML = \''.$autoUpJS.'\';
685 //]]>');
686 }
687 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] = '?div=Definition_Updates';
688 foreach ($GOTMLS_definitions_versions as $definition_name=>$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"])
689 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[$definition_name]=".$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"];
690 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)
691 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[you]=".$GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
692 }
693
694 function GOTMLS_settings() {
695 global $wpdb, $GOTMLS_dirs_at_depth, $GOTMLS_dir_at_depth;
696 $GOTMLS_scan_groups = array();
697 $gt = ">"; // This local variable never changes
698 $lt = "<"; // This local variable never changes
699 GOTMLS_ajax_load_update();
700 if (($GOTMLS_nonce_found = GOTMLS_get_nonce()) && isset($_REQUEST["check"]) && is_array($_REQUEST["check"]))
701 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = GOTMLS_sanitize($_REQUEST["check"]);
702 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"])) {
703 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
704 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
705 }
706 $dirs = GOTMLS_explode_dir(__FILE__);
707 for ($SL=0;$SL<intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);$SL++)
708 $GOTMLS_scan_groups[] = implode(GOTMLS_slash(), array_slice($dirs, -1 * (3 + $SL), 1));
709 if (isset($_POST["exclude_ext"])) {
710 if (strlen(trim(str_replace(",","",$_POST["exclude_ext"]).' ')) > 0)
711 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(str_replace('.', ',', GOTMLS_sanitize($_POST["exclude_ext"]))), -1, PREG_SPLIT_NO_EMPTY);
712 else
713 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = array();
714 }
715 $default_exclude_ext = str_replace(",gotmls", "", implode(",", $GLOBALS["GOTMLS"]["tmp"]["skip_ext"]));
716 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
717 if (isset($_POST["UPDATE_definitions_checkbox"])) {
718 if (isset($_POST[$_POST["UPDATE_definitions_checkbox"]]) && is_numeric($_POST[$_POST["UPDATE_definitions_checkbox"]]))
719 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = (INT) $_POST[$_POST["UPDATE_definitions_checkbox"]];
720 else
721 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = "";
722 }
723 if (isset($_POST["exclude_dir"])) {
724 if (strlen(trim(str_replace(",","",$_POST["exclude_dir"]).' ')) > 0)
725 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(GOTMLS_sanitize($_POST["exclude_dir"])), -1, PREG_SPLIT_NO_EMPTY);
726 else
727 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = array();
728 for ($d=0; $d<count($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]); $d++)
729 if (dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]) != ".")
730 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d] = str_replace("\\", "", str_replace("/", "", str_replace(dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]), "", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d])));
731 }
732 $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"] = array_merge($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"], $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"]);
733 if (isset($_POST["scan_what"]) && is_numeric($_POST["scan_what"]) && $_POST["scan_what"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"])
734 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = (INT) $_POST["scan_what"];
735 if (isset($_POST["check_custom"]) && $_POST["check_custom"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"])
736 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = GOTMLS_verify_regex(trim(stripslashes($_POST["check_custom"])));
737 if (isset($_POST["scan_depth"]) && is_numeric($_POST["scan_depth"]) && $_POST["scan_depth"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])
738 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = (INT) $_POST["scan_depth"];
739 if (isset($_POST['skip_quarantine']) && is_numeric($_POST['skip_quarantine']) && $_POST['skip_quarantine'])
740 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = (INT) $_POST['skip_quarantine'];
741 elseif (isset($_POST["exclude_ext"]))
742 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = 0;
743 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
744 $scan_whatopts = '';
745 $scan_root = "public_html";
746 $scan_optjs = "\n{$lt}script type=\"text/javascript\"$gt\nfunction showOnly(what) {\n";
747 foreach ($GOTMLS_scan_groups as $mg => $GOTMLS_scan_group) {
748 $scan_optjs .= "document.getElementById('only$mg').style.display = 'none';\n";
749 $scan_whatopts = "\n$lt/div$gt\n$lt/div$gt\n$scan_whatopts";
750 $scan_root = $GOTMLS_scan_group;
751 $dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + $mg)));
752 $files = GOTMLS_getfiles($dir);
753 if (isset($files) && is_array($files))
754 foreach ($files as $file)
755 if (is_dir(GOTMLS_trailingslashit($dir).$file))
756 $scan_whatopts = $lt.'input type="checkbox" name="scan_only[]" value="'.GOTMLS_htmlspecialchars($file).'" /'.$gt.GOTMLS_htmlspecialchars($file).$lt.'br /'.$gt.$scan_whatopts;
757 $scan_whatopts = "\n$lt".'div style="padding: 4px 30px;" id="scan_group_div_'.$mg.'"'.$gt.$lt.'input type="radio" name="scan_what" id="not-only'.$mg.'" value="'.$mg.'"'.($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]==$mg?' checked':'').' /'.$gt.$lt.'a style="text-decoration: none;" href="#scan_what" onclick="showOnly(\''.$mg.'\');document.getElementById(\'not-only'.$mg.'\').checked=true;"'."$gt{$lt}b$gt$GOTMLS_scan_group$lt/b$gt$lt/a$gt{$lt}br /$gt\n$lt".'div class="rounded-corners" style="position: absolute; display: none; background-color: #CCF; margin: 0; padding: 10px; z-index: 10;" id="only'.$mg.'"'.$gt.$lt.'div style="padding-bottom: 6px;"'.$gt.GOTMLS_close_button('only'.$mg, 0).$lt.'b'.$gt.str_replace(" ", "&nbsp;", __("Only Scan These Folders:",'gotmls')).$lt.'/b'.$gt.$lt.'/div'.$gt.$scan_whatopts;
758 }
759 $scan_optjs .= "document.getElementById('only'+what).style.display = 'block';\n}";
760 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && strlen(trim(" ".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])))
761 $scan_optjs .= "\nfunction auto_UPDATE_check() {\n\tif (auto_UPdef_check = document.getElementById('auto_UPDATE_definitions_".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]."'))\n\t\tauto_UPdef_check.checked = true;\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', auto_UPDATE_check)\nelse\n\tdocument.attachEvent('onload', auto_UPDATE_check);\n";
762 $scan_optjs .= "$lt/script$gt";
763 $GOTMLS_nonce_URL = GOTMLS_set_nonce(__FUNCTION__."790");
764 $scan_opts = "\n$lt".'form method="POST" id="GOTMLS_Form" name="GOTMLS_Form"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', $GOTMLS_nonce_URL).'"'.$gt.$lt.'input type="hidden" name="scan_type" id="scan_type" value="Complete Scan" /'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="submit" id="complete_scan" value="'.__("Run Complete Scan",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Complete Scan\';" /'.$gt.$lt.'/div'.$gt.'
765 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to look for:",'gotmls').$lt.'/b'.$gt.$lt.'a title="'.__("Check for all threat types, if any of these are in red or otherwise unavailable then please download the latest definition updates.",'gotmls').'"'.$gt.$lt.'span class="dashicons dashicons-editor-help"'.$gt.$lt.'/span'.$gt.$lt.'/a'.$gt.$lt.'/p'.$gt.'
766 '.$lt.'div style="padding: 0 30px;"'.$gt;
767 $cInput = '"'.$gt.$lt.'input';
768 $pCheck = "$cInput checked";
769 $kCheck = "";
770 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $threat_level_name=>$threat_level) {
771 $scan_opts .= $lt.'div id="check_'.$threat_level.'_div" style="padding: 0; position: relative;';
772 if (($threat_level != "wp_core" && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level])) || isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level][GOTMLS_wp_version])) {
773 if ($threat_level != "potential" && in_array($threat_level,$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"])) {
774 $pCheck = " display: none;$cInput";
775 $scan_opts .= "$cInput checked";
776 } elseif ($threat_level == "potential")
777 $scan_opts .= $pCheck;
778 else
779 $scan_opts .= $cInput;
780 if ($threat_level != "potential")
781 $kCheck .= ",'$threat_level'";
782 $scan_opts .= ' type="checkbox" onchange="pCheck(this);" name="check[]" id="check_'.$threat_level.'_Yes" value="'.$threat_level.'" /'.$gt.' '.$lt.'a style="text-decoration: none;" href="#check_'.$threat_level.'_div_0" onclick="document.getElementById(\'check_'.$threat_level.'_Yes\').checked=true;pCheck(document.getElementById(\'check_'.$threat_level.'_Yes\'));showhide(\'dont_check_'.$threat_level.'\');"'."$gt{$lt}b$gt$threat_level_name$lt/b$gt$lt/a$gt\n";
783 if (isset($_GET["SESSION"])) {
784 $scan_opts .= "\n$lt".'div style="padding: 0 20px; position: relative; top: -18px; display: none;" id="dont_check_'.$threat_level.'"'.$gt.$lt.'a class="rounded-corners" style="position: absolute; left: 0; margin: 0; padding: 0 4px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;" href="#check_'.$threat_level.'_div_0" onclick="showhide(\'dont_check_'.$threat_level.'\');"'.$gt.'X'.$lt.'/a'.$gt;
785 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level] as $threat_name => $threat_regex)
786 $scan_opts .= $lt."br /$gt\n$lt".'input type="checkbox" name="dont_check[]" value="'.GOTMLS_htmlspecialchars($threat_name).'"'.(in_array($threat_name, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])?' checked /'.$gt.$lt.'script'.$gt.'showhide("dont_check_'.$threat_level.'", true);'.$lt.'/script'.$gt:' /'.$gt).(isset($_SESSION["GOTMLS_debug"][$threat_name])?$lt.'div style="float: right;"'.$gt.print_r($_SESSION["GOTMLS_debug"][$threat_name],1)."$lt/div$gt":"").GOTMLS_htmlspecialchars($threat_name);
787 $scan_opts .= "\n$lt/div$gt";
788 }
789 } else
790 $scan_opts .= $lt.'a title="'.__("Download Definition Updates to Use this feature",'gotmls').'"'.$gt.$lt.'img src="'.GOTMLS_images_path.'blocked.gif" height=16 width=16 alt="X"'.$gt.$lt.'b'.$gt.'&nbsp; '.$threat_level_name.$lt.'/b'.$gt.$lt.'br /'.$gt.$lt.'div style="padding: 14px;" id="check_'.$threat_level.'_div_NA"'.$gt.$lt.'span style="color: #F00"'.$gt.__("Download the new definitions (Right sidebar) to activate this feature.",'gotmls')."$lt/span$gt$lt/div$gt";
791 $scan_opts .= "\n$lt/div$gt";
792 }
793 $scan_opts .= $lt.'/div'.$gt.$lt.'/div'.$gt.'
794 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to scan:",'gotmls').$lt.'/b'.$gt.$lt.'a title="'.sprintf(__("The higher up in the directory hierarchy you start the more sub-directories get scanned (e.g. scanning the %s directory will also include the sub-directories wp-content and plugins within it).",'gotmls'), $scan_root).'"'.$gt.$lt.'span class="dashicons dashicons-editor-help"'.$gt.$lt.'/span'.$gt.$lt.'/a'.$gt.$lt.'/p'.$gt.$scan_whatopts.$scan_optjs.$lt.'/div'.$gt.'
795 '.$lt.'div style="float: left;" id="scanwhatfolder"'.$gt.$lt.'/div'.$gt.'
796 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Directory Scan Depth:",'gotmls').$lt.'/b'.$gt.$lt.'a title="'.__("How many directories deep to scan: -1 is infinite depth, 0 to skip the file scan completely.",'gotmls').'"'.$gt.$lt.'span class="dashicons dashicons-editor-help"'.$gt.$lt.'/span'.$gt.$lt.'/a'.$gt.$lt.'/p'.$gt.'
797 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" value="'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"].'" name="scan_depth" size="5"'.$gt.$lt.'/div'.$gt.$lt.'/div'.$gt.$lt.'br style="clear: left;"'.$gt;
798 if (isset($_GET["SESSION"]) && isset($_SESSION["GOTMLS_debug"]['total'])) {$scan_opts .= $lt.'div style="float: right;"'.$gt.print_r($_SESSION["GOTMLS_debug"]['total'],1)."$lt/div$gt"; unset($_SESSION["GOTMLS_debug"]);}
799 if (isset($_GET["eli"])) {//still testing this option
800 if ($_GET["eli"] == "find") {
801 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && (count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) > 1)) {
802 $fe = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][0];
803 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][1];
804 } else {
805 $fe = " no";
806 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"] as $f => $e)
807 if (is_array($e) && in_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"], $e))
808 $fe = " $f";
809 }
810 } else
811 $fe = "";
812 $scan_opts .= "\n$lt".'div style="padding: 10px;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Custom RegExp:",'gotmls').$fe.$lt.'/b'.$gt.' ('.__("For very advanced users only. Do not use this without talking to Eli first. If used incorrectly you could easily break your site.",'gotmls').')'.$lt.'/p'.$gt.$lt.'input type="text" name="check_custom" style="width: 100%;" value="'.GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]).'" /'."$gt$lt/div$gt\n";
813 }
814 $QuickScan = $lt.((is_dir(dirname(__FILE__)."/../../../wp-includes") && is_dir(dirname(__FILE__)."/../../../wp-admin"))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&$GOTMLS_nonce_URL").'" class="button-primary" style="min-height: 22px; height: 22px; line-height: 13px; padding: 3px;">WP_Core</a':"!-- No wp-includes or wp-admin --").$gt;
815 foreach (array("Plugins", "Themes") as $ScanFolder)
816 $QuickScan .= '&nbsp;'.$lt.((is_dir(dirname(__FILE__)."/../../../wp-content/".strtolower($ScanFolder)))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&scan_only%5B%5D=wp-content/".strtolower($ScanFolder)."&$GOTMLS_nonce_URL")."\" class=\"button-primary\" style=\"min-height: 22px; height: 22px; line-height: 13px; padding: 3px;\"$gt$ScanFolder$lt/a":"!-- No $ScanFolder in wp-content --").$gt;
817 $scan_opts .= "\n$lt".'p'.$gt.$lt.'b'.$gt.__("Skip files with the following extensions:",'gotmls')."$lt/b$gt".(($default_exclude_ext!=implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))?" {$lt}a href=\"javascript:void(0);\" onclick=\"document.getElementById('exclude_ext').value = '$default_exclude_ext';\"{$gt}[Restore Defaults]$lt/a$gt":"").$lt.'/p'.$gt.'
818 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a comma separated list of file extentions to skip",'gotmls').'" name="exclude_ext" id="exclude_ext" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]).'" style="width: 100%;" /'."$gt$lt/div$gt$lt".'p'.$gt.$lt.'b'.$gt.__("Skip directories with the following names:",'gotmls')."$lt/b$gt$lt/p$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a folder name or comma separated list of folder names to skip",'gotmls').'" name="exclude_dir" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]).'" style="width: 100%;" /'.$gt.$lt.'/div'.$gt.'
819 '.$lt.'table style="width: 100%" cellspacing="10"'.$gt.$lt.'tr'.$gt.$lt.'td nowrap valign="top" style="white-space: nowrap; width: 1px;"'.$gt.$lt.'b'.$gt.__("Automatically Update Definitions:",'gotmls').$lt."br$gt$lt/b$gt$lt/td$gt$lt".'td'.$gt.$lt.'div id="UPDATE_definitions_div"'.$gt.$lt.'br'.$gt.$lt.'span style="color: #C00;"'.$gt.__("This feature is only available to registered users who have donated at a certain level.",'gotmls')."$lt/span$gt$lt/div$gt$lt/td$gt$lt".'td align="right" valign="bottom"'.$gt.$lt.'input type="submit" id="save_settings" value="'.__("Save Settings",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Save\';" /'."$gt$lt/td$gt$lt/tr$gt$lt/table$gt$lt/form$gt";
820 $title_tagline = $lt."li$gt Site Title: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogname'"));
821 $title_tagline .= "$lt/li$gt$lt"."li$gt Tagline: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogdescription'"));
822 if (preg_match('/h[\@a]ck[3e]d.*by/is', $title_tagline))
823 echo $lt.'div class="error"'.$gt.sprintf(__("Your Site Title or Tagline suggests that you may have been hacked ...%sThis could impact the indexing of your site and may even lead to blacklisting. You can change those options on the %sGeneral Settings$lt/a$gt page.",'gotmls'), "$title_tagline$lt/li$gt", $lt.'a href="'.admin_url("options-general.php").'"'.$gt)."$lt/div$gt";
824 @ob_start();
825 $OB_default_handlers = array("default output handler", "zlib output compression");
826 $OB_handlers = @ob_list_handlers();
827 if (is_array($OB_handlers) && count($OB_handlers))
828 foreach ($OB_handlers as $OB_last_handler)
829 if (!in_array($OB_last_handler, $OB_default_handlers))
830 echo $lt.'div class="error"'.$gt.sprintf(__("Another Plugin or Theme is using '%s' to handle output buffers. <br />This prevents actively outputing the buffer on-the-fly and could severely degrade the performance of this (and many other) Plugins. <br />Consider disabling caching and compression plugins (at least during the scanning process).",'gotmls'), $OB_last_handler)."$lt/div$gt";
831 GOTMLS_display_header();
832 $scan_groups = array_merge(array(__("Scanned Files",'gotmls')=>"scanned",__("Selected Folders",'gotmls')=>"dirs",__("Scanned Folders",'gotmls')=>"dir",__("Skipped Folders",'gotmls')=>"skipdirs",__("Skipped Files",'gotmls')=>"skipped",__("Scan/Read Errors",'gotmls')=>"errors",__("Quarantined Files",'gotmls')=>"bad"), $GLOBALS["GOTMLS"]["tmp"]["threat_levels"]);
833 echo $lt.'script type="text/javascript">
834 var percent = 0;
835 function pCheck(chkb) {
836 var kCheck = ['.trim($kCheck,",").'];
837 chk = true;
838 for (var i = 0; i < kCheck.length; i++) {
839 var chkbox = document.getElementById("check_"+kCheck[i]+"_Yes");
840 if (chkbox && chkb.id == "check_potential_Yes" && chkb.checked == false) {
841 chk = false;
842 chkbox.checked = true;
843 } else if (chkbox && chkbox.checked) {
844 chk = false;
845 }
846 }
847 if (chkbox = document.getElementById("check_potential_Yes"))
848 chkbox.checked = chk;
849 if (chk) {
850 document.getElementById("check_potential_div").style.display = "block";
851 alert("If you do not select any other threat types, then only potential threats will be found and the automatic fix will not be available!");
852 } else
853 document.getElementById("check_potential_div").style.display = "none";
854 }
855 function changeFavicon(percent) {
856 var oldLink = document.getElementById("wait_gif");
857 if (oldLink) {
858 if (percent >= 100) {
859 document.getElementsByTagName("head")[0].removeChild(oldLink);
860 var link = document.createElement("link");
861 link.id = "wait_gif";
862 link.type = "image/gif";
863 link.rel = "shortcut icon";
864 var threats = '.implode(" + ", array_merge($GLOBALS["GOTMLS"]["tmp"]["threat_levels"], array(__("Potential Threats",'gotmls')=>"errors",__("WP-Login Updates",'gotmls')=>"errors"))).';
865 if (threats > 0) {
866 if ((errors * 2) == threats)
867 linkhref = "blocked";
868 else
869 linkhref = "threat";
870 } else
871 linkhref = "checked";
872 link.href = "'.GOTMLS_images_path.'"+linkhref+".gif";
873 document.getElementsByTagName("head")[0].appendChild(link);
874 }
875 } else {
876 var icons = document.getElementsByTagName("link");
877 var link = document.createElement("link");
878 link.id = "wait_gif";
879 link.type = "image/gif";
880 link.rel = "shortcut icon";
881 link.href = "'.GOTMLS_images_path.'wait.gif";
882 // document.head.appendChild(link);
883 document.getElementsByTagName("head")[0].appendChild(link);
884 }
885 }
886 function update_status(title, time) {
887 sdir = (dir+direrrors);
888 if (arguments[2] >= 0 && arguments[2] <= 100)
889 percent = arguments[2];
890 else
891 percent = Math.floor((sdir*100)/dirs);
892 scan_state = "6F6";
893 if (percent == 100) {
894 showhide("pause_button", true);
895 showhide("pause_button");
896 title = "'.$lt.'b'.$gt.GOTMLS_strip4java(__("Scan Complete!",'gotmls')).$lt.'/b'.$gt.'";
897 } else
898 scan_state = "99F";
899 changeFavicon(percent);
900 if (sdir) {
901 if (arguments[2] >= 0 && arguments[2] <= 100)
902 timeRemaining = Math.ceil(((time-startTime)*(100/percent))-(time-startTime));
903 else
904 timeRemaining = Math.ceil(((time-startTime)*(dirs/sdir))-(time-startTime));
905 if (timeRemaining > 59)
906 timeRemaining = Math.ceil(timeRemaining/60)+" Minute";
907 else
908 timeRemaining += " Second";
909 if (timeRemaining.substr(0, 2) != "1 ")
910 timeRemaining += "s";
911 } else
912 timeRemaining = "Calculating Time";
913 timeElapsed = Math.ceil(time);
914 if (timeElapsed > 59)
915 timeElapsed = Math.floor(timeElapsed/60)+" Minute";
916 else
917 timeElapsed += " Second";
918 if (timeElapsed.substr(0, 2) != "1 ")
919 timeElapsed += "s";
920 divHTML = \''.$lt.'div align="center" style="vertical-align: middle; background-color: #ccc; z-index: 3; height: 18px; width: 100%; border: solid #000 1px; position: relative; padding: 10px 0;"'.$gt.$lt.'div style="height: 18px; padding: 10px 0; position: absolute; top: 0px; left: 0px; background-color: #\'+scan_state+\'; width: \'+percent+\'%"'.$gt.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; left: 10px; z-index: 5; line-height: 16px;" align="left"'.$gt.'\'+sdir+" Folder"+(sdir==1?"":"s")+" Checked'.$lt.'br /'.$gt.'"+timeElapsed+\' Elapsed'.$lt.'/div'.$gt.$lt.'div style="height: 38px; position: absolute; top: 0px; left: 0px; width: 100%; z-index: 5; line-height: 38px; font-size: 30px; text-align: center; box-sizing: content-box;"'.$gt.'\'+percent+\'%'.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; right: 10px; z-index: 5; line-height: 16px;" align="right"'.$gt.'\'+(dirs-sdir)+" Folder"+((dirs-sdir)==1?"":"s")+" Remaining'.$lt.'br /'.$gt.'"+timeRemaining+" Remaining'.$lt.'/div'.$gt.$lt.'/div'.$gt.'";
921 document.getElementById("status_bar").innerHTML = divHTML;
922 document.getElementById("status_text").innerHTML = title;
923 dis="none";
924 divHTML = \''.$lt.'ul style="float: right; margin: 0 20px; text-align: right;"'.$gt.'\';
925 /*'.$lt.'!--*'.'/';
926 $MAX = 0;
927 $vars = "var i, intrvl, direrrors=0";
928 $fix_button_js = "";
929 $found = "";
930 $li_js = "return false;";
931 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Quick Scan") {
932 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
933 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
934 if ($check != "potential")
935 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $check;
936 }
937 foreach ($scan_groups as $scan_name => $scan_group) {
938 if ($MAX++ == 6) {
939 $quarantineCountOnly = GOTMLS_get_quarantine(true);
940 $vars .= ", $scan_group=$quarantineCountOnly";
941 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0)\n\t\tscan_state = ' potential'; \n\telse\n\t\tscan_state = '';\n\tdivHTML += '</ul><ul style=\"text-align: left;\"><li class=\"GOTMLS_li\"><a href=\"admin.php?page=GOTMLS_View_Quarantine\" class=\"GOTMLS_plugin".("'+scan_state+'\" title=\"".GOTMLS_strip4java(GOTMLS_View_Quarantine_LANGUAGE))."\">'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
942 $found = "Found ";
943 $fix_button_js = "\n\t\tdis='block';";
944 } else {
945 $val = 0;
946 if ($MAX > 8 && !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
947 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("Directory Scan Depth set to 0, no files will be scanned for this type of threat!",'gotmls'));
948 elseif ($found && !in_array($scan_group, $GLOBALS["GOTMLS"]["log"]["settings"]["check"]))
949 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("You are not currently scanning for this type of threat!",'gotmls'));
950 else
951 $potential_threat = "";
952 $vars .= ", $scan_group=$val";
953 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0) {\n\t\tscan_state = ' href=\"#found_$scan_group\" onclick=\"$li_js showhide(\\'found_$scan_group\\', true);\" class=\"GOTMLS_plugin $scan_group\"';$fix_button_js".($MAX>6?"\n\tshowhide('found_$scan_group', true);":"")."\n\t} else\n\t\tscan_state = ' class=\"GOTMLS_plugin$potential_threat\"';\n\tdivHTML += '<li class=\"GOTMLS_li\"".(($found && $scan_group == "potential" && !in_array($scan_group, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))?' style="display: none;"':"")."><a'+scan_state+'>$found'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
954 }
955 $li_js = "";
956 if ($MAX > 11)
957 $fix_button_js = "";
958 }
959 $ScanSettings = $lt.'div style="float: right;"'.$gt.GOTMLS_Run_Quick_Scan_LANGUAGE.":&nbsp;$QuickScan$lt/div$gt".GOTMLS_Scan_Settings_LANGUAGE;
960 echo "/*--{$gt}*".'/
961 document.getElementById("status_counts").innerHTML = divHTML+"'.$lt.'/ul'.$gt.'";
962 document.getElementById("fix_button").style.display = dis;
963 }
964 '.$vars.';
965 function showOnly(what) {
966 document.getElementById("only_what").innerHTML = document.getElementById("only"+what).innerHTML;
967 }
968 var startTime = 0;
969 '.$lt.'/script'.$gt.GOTMLS_box($ScanSettings, $scan_opts);
970 $Settings_Saved = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -50px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";//script type='text/javascript'$gt\nalert('Settings Saved!');\n$lt/script$gt\n";
971 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Save") {
972 if ($GOTMLS_nonce_found) {
973 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
974 echo $Settings_Saved;
975 } else
976 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Saving these settings requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
977 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scanlog());
978 } elseif (isset($_REQUEST["scan_what"]) && is_numeric($_REQUEST["scan_what"]) && ($_REQUEST["scan_what"] > -1)) {
979 if ($GOTMLS_nonce_found) {
980 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
981 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
982 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
983 $cleadCache = false;
984 if (function_exists('is_plugin_active')) {
985 if (function_exists('wp_cache_clear_cache')) {
986 wp_cache_clear_cache();
987 $cleadCache = true;
988 }
989 if (function_exists('w3tc_pgcache_flush')) {
990 w3tc_pgcache_flush();
991 $cleadCache = true;
992 }
993 if (class_exists('WpFastestCache')) {
994 $newCache = new WpFastestCache();
995 $newCache->deleteCache();
996 $cleadCache = true;
997 }
998
999 }
1000 if ($cleadCache)
1001 str_replace("Settings Saved!", "Cache Cleared and Settings Saved!", $Settings_Saved);
1002 echo $Settings_Saved;
1003 if (!isset($_REQUEST["scan_type"]))
1004 $_REQUEST["scan_type"] = "Complete Scan";
1005 elseif ($_REQUEST["scan_type"] == "Quick Scan") {
1006 $li_js = "\nfunction testComplete() {\n\tif (percent != 100)\n\t\talert('".__("The Quick Scan was unable to finish because of a shortage of memory or a problem accessing a file. Please try using the Complete Scan, it is slower but it will handle these errors better and continue scanning the rest of the files.",'gotmls')."');\n}\nwindow.onload=testComplete;\n$lt/script$gt\n$lt".'script type="text/javascript"'.$gt;
1007 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
1008 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1009 if ($check != "potential")
1010 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $check;
1011 }
1012 $_SERVER_QUERY_STRING = "?";
1013 foreach ($_GET as $name => $value) {
1014 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1015 if (is_array($value)) {
1016 foreach ($value as $val)
1017 $_SERVER_QUERY_STRING .= urlencode($name).'[]='.urlencode($val).'&';
1018 } else
1019 $_SERVER_QUERY_STRING .= urlencode($name).'='.urlencode($value).'&';
1020 }
1021 }
1022 echo "\n$lt".'form method="POST" action="'.admin_url("admin-ajax.php$_SERVER_QUERY_STRING"/*.(isset($_SERVER["QUERY_STRING"])&&strlen($_SERVER["QUERY_STRING"])?"?".$_SERVER["QUERY_STRING"]:"")*/).'" target="GOTMLS_iFrame" name="GOTMLS_Form_clean"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."1049")).'"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_fix"'.$gt.$lt.'input type="hidden" id="GOTMLS_fixing" name="GOTMLS_fixing" value="1"'.$gt;
1023 foreach ($_POST as $name => $value) {
1024 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1025 if (is_array($value)) {
1026 foreach ($value as $val)
1027 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'[]" value="'.GOTMLS_htmlspecialchars($val).'"'.$gt;
1028 } else
1029 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'" value="'.GOTMLS_htmlspecialchars($value).'"'.$gt;
1030 }
1031 }
1032 echo "\n$lt".'script type="text/javascript"'.$gt.'showhide("inside_'.md5($ScanSettings).'");'.$lt.'/script'.$gt.GOTMLS_box(GOTMLS_htmlspecialchars($_REQUEST["scan_type"]).' Status', $lt.'div id="status_text"'.$gt.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="..."'.$gt.' '.GOTMLS_Loading_LANGUAGE.$lt.'/div'.$gt.$lt.'div id="status_bar"'.$gt.$lt.'/div'.$gt.$lt.'p id="pause_button" style="display: none; position: absolute; left: 0; text-align: center; margin-left: -30px; padding-left: 50%;"'.$gt.$lt.'input type="button" value="Pause" class="button-primary" onclick="pauseresume(this);" id="resume_button" /'.$gt.$lt.'/p'.$gt.$lt.'div id="status_counts"'.$gt.$lt.'/div'.$gt.$lt.'p id="fix_button" style="display: none; text-align: center;"'.$gt.$lt.'input id="repair_button" type="submit" value="'.GOTMLS_Automatically_Fix_LANGUAGE.'" class="button-primary" onclick="loadIframe(\'Examine Results\');" /'.$gt.$lt.'/p'.$gt);
1033 $scan_groups_UL = "";
1034 foreach ($scan_groups as $scan_name => $scan_group)
1035 $scan_groups_UL .= "\n{$lt}ul name=\"found_$scan_group\" id=\"found_$scan_group\" class=\"GOTMLS_plugin $scan_group\" style=\"background-color: #ccc; display: none; padding: 0;\"$gt{$lt}a class=\"rounded-corners\" name=\"link_$scan_group\" style=\"float: right; padding: 0 4px; margin: 5px 5px 0 30px; line-height: 16px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;\" href=\"#found_top\" onclick=\"showhide('found_$scan_group');\"{$gt}X$lt/a$gt{$lt}h3$gt$scan_name$lt/h3$gt\n".($scan_group=='potential'?$lt.'p'.$gt.' &nbsp; * '.__("NOTE: These are probably not malicious scripts (but it's a good place to start looking <u>IF</u> your site is infected and no Known Threats were found).",'gotmls').$lt.'/p'.$gt:($scan_group=='wp_core'?$lt.'p'.$gt.' &nbsp; * '.sprintf(__("NOTE: We have detected changes to the WordPress Core files on your site. This could be an intentional modification or the malicious work of a hacker. We can restore these files to their original state to preserve the integrity of your original WordPress %s installation.",'gotmls'), GOTMLS_wp_version).' (for more info '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-core-files/"'.$gt.__("read my blog",'gotmls').$lt.'/a'.$gt.').'.$lt.'/p'.$gt:$lt.'br /'.$gt)).$lt.'/ul'.$gt;
1036 if (!($dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + (INT) $_REQUEST["scan_what"])))))
1037 $dir = "/";
1038 GOTMLS_update_scan_log(array("scan" => array("dir" => $dir, "start" => time(), "type" => GOTMLS_sanitize($_REQUEST["scan_type"]))));
1039 echo GOTMLS_box($lt.'div id="GOTMLS_scan_dir" style="float: right;"'.$gt.'&nbsp;('.$GLOBALS["GOTMLS"]["log"]["scan"]["dir"].")&nbsp;$lt/div$gt".__("Scan Details:",'gotmls'), $scan_groups_UL);
1040 $no_flush_LANGUAGE = __("Not flushing OB Handlers: %s",'gotmls');
1041 if (isset($_REQUEST["no_ob_end_flush"]))
1042 echo $lt.'div class="error"'.$gt.sprintf($no_flush_LANGUAGE, print_r(ob_list_handlers(), 1))."$lt/div$gt\n";
1043 elseif (is_array($OB_handlers) && count($OB_handlers)) {
1044 // $GOTMLS_OB_handlers = get_option("GOTMLS_OB_handlers", array());
1045 foreach (array_reverse($OB_handlers) as $OB_handler) {
1046 if (isset($GOTMLS_OB_handlers[$OB_handler]) && $GOTMLS_OB_handlers[$OB_handler] == "no_end_flush")
1047 echo $lt.'div class="error"'.$gt.sprintf($no_flush_LANGUAGE, $OB_handler)."$lt/div$gt\n";
1048 elseif (in_array($OB_handler, $OB_default_handlers)) {
1049 // $GOTMLS_OB_handlers[$OB_handler] = "no_end_flush";
1050 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1051 @ob_end_flush();
1052 // $GOTMLS_OB_handlers[$OB_handler] = "ob_end_flush";
1053 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1054 }
1055 }
1056 }
1057 @ob_start();
1058 echo "\n{$lt}script type=\"text/javascript\"$gt$li_js\n/*{$lt}!--*"."/";
1059 if (!(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])) {
1060 echo GOTMLS_return_threat("dirs", "wait", $dir).GOTMLS_update_status(sprintf(__("Preparing %s",'gotmls'), str_replace(dirname($GLOBALS["GOTMLS"]["log"]["scan"]["dir"]), "...", $dir)), 0);//GOTMLS_return_threat("skipdirs", "blocked", $dir, GOTMLS_error_link("Directory Scan Depth set to 0, no files will be scanned!"));
1061 $GLOBALS["GOTMLS"]["tmp"]["scanfiles"][GOTMLS_encode($dir)] = GOTMLS_strip4java(str_replace(dirname($GLOBALS["GOTMLS"]["log"]["scan"]["dir"]), "...", $dir));
1062 } elseif (is_dir($dir)) {
1063 $GOTMLS_dirs_at_depth[0] = 1;
1064 $GOTMLS_dir_at_depth[0] = 0;
1065 if (isset($_REQUEST['scan_only']) && is_array($_REQUEST['scan_only'])) {
1066 $GOTMLS_dirs_at_depth[0] += (count($_REQUEST['scan_only']) - 1);
1067 foreach ($_REQUEST['scan_only'] as $only_dir)
1068 if (is_dir(GOTMLS_trailingslashit($dir).$only_dir))
1069 GOTMLS_readdir(GOTMLS_trailingslashit($dir).$only_dir);
1070 } else
1071 GOTMLS_readdir($dir);
1072 } else
1073 echo GOTMLS_return_threat("errors", "blocked", $dir, GOTMLS_error_link("Not a valid directory!"));
1074 if ($_REQUEST["scan_type"] == "Quick Scan")
1075 echo GOTMLS_update_status(__("Completed!",'gotmls'), 100);
1076 else {
1077 echo GOTMLS_update_status(__("Starting Scan ...",'gotmls'));
1078 $DB_scan_JS = ", 'db_scan'";
1079 if (isset($GLOBALS["GOTMLS"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["log"]["settings"]["check"]) && in_array("db_scan", $GLOBALS["GOTMLS"]["log"]["settings"]["check"]))
1080 echo GOTMLS_return_threat("dirs", "wait", "db_scan");//.GOTMLS_update_status(__("Starting Database Scan ...",'gotmls'));
1081 else
1082 $DB_scan_JS = "";
1083 GOTMLS_flush('script');
1084 echo "/*--{$gt}*"."/\nvar scriptSRC = '".admin_url('admin-ajax.php?action=GOTMLS_scan&'.GOTMLS_set_nonce(__FUNCTION__."1110").'&mt='.$GLOBALS["GOTMLS"]["tmp"]["mt"]./*preg_replace('/\&(GOTMLS_scan|mt|GOTMLS_mt|action)=/', '&last_\1=', isset($_SERVER["QUERY_STRING"])&&strlen($_SERVER["QUERY_STRING"])?"&".$_SERVER["QUERY_STRING"]:"").*/'&GOTMLS_scan=')."';\nvar scanfilesArKeys = new Array('".implode("','", array_keys($GLOBALS["GOTMLS"]["tmp"]["scanfiles"]))."'$DB_scan_JS);\nvar scanfilesArNames = new Array('Scanning ".implode("','Scanning ", $GLOBALS["GOTMLS"]["tmp"]["scanfiles"])."'".str_replace("db_scan", "Starting Database Scan ...", $DB_scan_JS).");".'
1085 var scanfilesI = 0;
1086 var stopScanning;
1087 var gotStuckOn = "";
1088 function scanNextDir(gotStuck) {
1089 clearTimeout(stopScanning);
1090 if (gotStuck > -1) {
1091 if (scanfilesArNames[gotStuck].substr(0, 3) != "Re-" && scanfilesArNames[gotStuck].substr(0, 10) != "Got Stuck ") {
1092 if (scanfilesArNames[gotStuck].substr(0, 9) == "Checking ") {
1093 scanfilesArNames.push(scanfilesArNames[gotStuck]);
1094 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_skip_file[]="+encodeURIComponent(scanfilesArNames[gotStuck].substr(9)));
1095 } else {
1096 scanfilesArNames.push("Re-"+scanfilesArNames[gotStuck]);
1097 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_only_file=");
1098 }
1099 } else {
1100 var uri = scanfilesArKeys[gotStuck].split("&limit=", 2);
1101 var skipdir = (scanfilesArKeys[gotStuck]+"&").split("&",2);
1102 if (uri.length == 2) {
1103 var lim = (uri[1]+"&").split("&", 2);
1104 if (isNaN(lim[0]))
1105 lim[0] = 1024;
1106 else
1107 lim[0] = Math.round(lim[0]/2);
1108 scanfilesArKeys.push(uri[0]+"&limit="+lim[0]+"&"+lim[1]+"&GOTMLS_skip_dir="+skipdir[0]);
1109 } else {
1110 var lim = ["2048"];
1111 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&limit=2048&GOTMLS_skip_dir="+skipdir[0]);
1112 }
1113 scanfilesArNames.push("Got Stuck ("+lim[0]+") "+scanfilesArNames[gotStuck]);
1114 }
1115 }
1116 if (document.getElementById("resume_button").value != "Pause") {
1117 stopScanning=setTimeout("scanNextDir(-1)", 1000);
1118 startTime++;
1119 } else if (scanfilesI < scanfilesArKeys.length) {
1120 document.getElementById("status_text").innerHTML = scanfilesArNames[scanfilesI];
1121 var newscript = document.createElement("script");
1122 newscript.setAttribute("src", scriptSRC+scanfilesArKeys[scanfilesI]);
1123 divx = document.getElementById("found_scanned");
1124 if (divx)
1125 divx.appendChild(newscript);
1126 stopScanning=setTimeout("scanNextDir("+(scanfilesI++)+")",'.$GLOBALS["GOTMLS"]["tmp"]['execution_time'].'000);
1127 }
1128 }
1129 startTime = ('.ceil(time()-$GLOBALS["GOTMLS"]["log"]["scan"]["start"]).'+3);
1130 stopScanning=setTimeout("scanNextDir(-1)",3000);
1131 function pauseresume(butt) {
1132 if (butt.value == "Resume")
1133 butt.value = "Pause";
1134 else
1135 butt.value = "Resume";
1136 }
1137 showhide("pause_button", true);'."\n/*{$lt}!--*"."/";
1138 }
1139 if (@ob_get_level()) {
1140 GOTMLS_flush('script');
1141 @ob_end_flush();
1142 }
1143 echo "/*--{$gt}*"."/\n$lt/script$gt";
1144 } else
1145 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Starting a Complete Scan requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1146 } else
1147 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scanlog());
1148 echo "\n$lt/div$gt$lt/div$gt$lt/div$gt";
1149 }
1150
1151 function GOTMLS_login_form($form_id = "loginform") {
1152 $sess = time();
1153 $ajaxURL = admin_url("admin-ajax.php?action=GOTMLS_logintime&GOTMLS_sess=");
1154 echo '<input type="hidden" name="sess_id" value="'.substr($sess, 4).'"><input type="hidden" id="offset_id" value="0" name="sess'.substr($sess, 4).'"><script type="text/javascript">'."\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_script = document.createElement('script');\nGOTMLS_login_script.src = '$ajaxURL'+GOTMLS_login_offset.getTime();\n\ndocument.head.appendChild(GOTMLS_login_script);\n</script>\n";//GOTMLS_login_script.onload = set_offset_id();
1155 }
1156 if (defined("GOTMLS_REQUEST_METHOD"))
1157 add_action("login_form", "GOTMLS_login_form");
1158
1159 function GOTMLS_ajax_logintime() {
1160 @header("Content-type: text/javascript");
1161 $sess = (false && isset($_GET["GOTMLS_sess"]) && is_numeric($_GET["GOTMLS_sess"])) ? GOTMLS_htmlspecialchars($_GET["sess"]) : time();
1162 die(((isset($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]) && $GLOBALS["GOTMLS"]["tmp"]["HeadersError"])?"\n//Header Error: ".GOTMLS_strip4java(GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["HeadersError"])):"")."\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_offset_start = GOTMLS_login_offset.getTime() - ".$sess."000;\nfunction set_offset_id() {\n\tGOTMLS_login_offset = new Date();\n\tif (form_login = document.getElementById('offset_id'))\n\t\tform_login.value = GOTMLS_login_offset.getTime() - GOTMLS_login_offset_start;\n\tsetTimeout(set_offset_id, 15673);\n}\nset_offset_id();");
1163 }
1164
1165 function GOTMLS_ajax_lognewkey() {
1166 @header("Content-type: text/javascript");
1167 if (isset($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]) && $GLOBALS["GOTMLS"]["tmp"]["HeadersError"])
1168 echo "\n//Header Error: ".GOTMLS_strip4java(GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]));
1169 if (GOTMLS_get_nonce()) {
1170 if (isset($_POST["GOTMLS_installation_key"]) && ($_POST["GOTMLS_installation_key"] == GOTMLS_installation_key)) {
1171 $keys = maybe_unserialize(get_option('GOTMLS_Installation_Keys', array()));
1172 if (is_array($keys)) {
1173 $count = count($keys);
1174 if (!isset($keys[GOTMLS_installation_key]))
1175 $keys = array_merge($keys, array(GOTMLS_installation_key => GOTMLS_siteurl));
1176 } else
1177 $keys = array(GOTMLS_installation_key => GOTMLS_siteurl);
1178 update_option("GOTMLS_Installation_Keys", serialize($keys));
1179 die("\n//$count~".count($keys));
1180 } else
1181 die("\n//0");
1182 } else
1183 die(GOTMLS_Invalid_Nonce("\n//Log New Key Error: ")."\n");
1184 }
1185
1186 function GOTMLS_set_plugin_action_links($links_array, $plugin_file) {
1187 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * strlen($plugin_file))) && strlen($plugin_file) > 10)
1188 $links_array = array_merge(array('<a href="'.admin_url('admin.php?page=GOTMLS-settings').'">'.GOTMLS_Scan_Settings_LANGUAGE.'</a>'), $links_array);
1189 return $links_array;
1190 }
1191 add_filter("plugin_action_links", "GOTMLS_set_plugin_action_links", 1, 2);
1192
1193 function GOTMLS_set_plugin_row_meta($links_array, $plugin_file) {
1194 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * strlen($plugin_file))) && strlen($plugin_file) > 10)
1195 $links_array = array_merge($links_array, array('<a target="_blank" href="'.GOTMLS_plugin_home.'faqs/">FAQ</a>','<a target="_blank" href="'.GOTMLS_plugin_home.'support/">Support</a>','<a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span>Donate</a>'));
1196 return $links_array;
1197 }
1198 add_filter("plugin_row_meta", "GOTMLS_set_plugin_row_meta", 1, 2);
1199
1200 function GOTMLS_in_plugin_update_message($args) {
1201 $transient_name = 'GOTMLS_upgrade_notice_'.$args["Version"].'_'.$args["new_version"];
1202 if ((false === ($upgrade_notice = get_transient($transient_name))) && ($ret = GOTMLS_get_URL("https://plugins.svn.wordpress.org/gotmls/trunk/readme.txt"))) {
1203 $upgrade_notice = '';
1204 if ($match = preg_split('/==\s*Upgrade Notice\s*==\s+/i', $ret)) {
1205 if (preg_match('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]))
1206 $notice = (array) preg_split('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]);
1207 else
1208 $notice = (array) preg_split('/\n+=/is', $match[1]."\n=");
1209 $upgrade_notice .= '<div class="GOTMLS_upgrade_notice">'.preg_replace('/=\s*([\.0-9]+)\s*=\s*([^=]+)/i', '<li><b>${1}:</b> ${2}</li>', preg_replace('~\[([^\]]*)\]\(([^\)]*)\)~', '<a href="${2}">${1}</a>', $notice[0])).'</div>';
1210 set_transient($transient_name, $upgrade_notice, DAY_IN_SECONDS);
1211 }
1212 }
1213 echo $upgrade_notice;
1214 }
1215 add_action("in_plugin_update_message-gotmls/index.php", "GOTMLS_in_plugin_update_message");
1216
1217 function GOTMLS_debug_hook($function) {
1218 return "\n<!-- Debugging $function (".round(microtime(true)-$GLOBALS["GOTMLS"]["MT"], 4).") -->\n";
1219 }
1220
1221 function GOTMLS_begin_wp_body_open() {
1222 return GOTMLS_debug_hook(__FUNCTION__);
1223 }
1224 function GOTMLS_finish_wp_body_open() {
1225 return GOTMLS_debug_hook(__FUNCTION__);
1226 }
1227 function GOTMLS_begin_wp_head() {
1228 echo GOTMLS_debug_hook(__FUNCTION__);
1229 }
1230 function GOTMLS_finish_wp_head() {
1231 echo GOTMLS_debug_hook(__FUNCTION__);
1232 }
1233 function GOTMLS_begin_wp_footer() {
1234 echo GOTMLS_debug_hook(__FUNCTION__);
1235 }
1236 function GOTMLS_finish_wp_footer() {
1237 echo GOTMLS_debug_hook(__FUNCTION__);
1238 }
1239
1240 if (isset($_REQUEST["eli"]) && ($_REQUEST["eli"] == "debug")) {
1241 foreach (array('wp_head', 'wp_body_open', 'wp_footer') as $wp_hook) {
1242 if (function_exists("GOTMLS_begin_$wp_hook"))
1243 add_action($wp_hook, "GOTMLS_begin_$wp_hook", 0);
1244 if (function_exists("GOTMLS_finish_$wp_hook"))
1245 add_action($wp_hook, "GOTMLS_finish_$wp_hook", 999999);
1246 }
1247 }
1248
1249 function GOTMLS_admin_init() {
1250 GOTMLS_define("GOTMLS_get_version_URL", GOTMLS_get_version("URL"));
1251 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]))
1252 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = 2;
1253 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
1254 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = -1;
1255 if (isset($_REQUEST["scan_type"]) && ($_REQUEST["scan_type"] == "Quick Scan")) {
1256 if (!isset($_REQUEST["scan_what"])) $_REQUEST["scan_what"] = 2;
1257 if (!isset($_REQUEST["scan_depth"]))
1258 $_REQUEST["scan_depth"] = 2;
1259 if (!isset($_REQUEST["scan_only"]))
1260 $_REQUEST["scan_only"] = array("","wp-includes","wp-admin");
1261 if ($_REQUEST["scan_only"] && !is_array($_REQUEST["scan_only"]))
1262 $_REQUEST["scan_only"] = array($_REQUEST["scan_only"]);
1263 }
1264 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]))
1265 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = "";
1266 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]) && is_numeric($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1267 $scan_level = intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);
1268 else
1269 $scan_level = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1270 $ajax_functions = array('load_update', 'log_session', 'empty_trash', 'fix', 'logintime', 'lognewkey', 'position', 'scan', 'View_Quarantine', 'whitelist');
1271 if (GOTMLS_get_nonce()) {
1272 if (isset($_REQUEST["dont_check"]) && is_array($_REQUEST["dont_check"]) && count($_REQUEST["dont_check"]))
1273 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = GOTMLS_sanitize($_REQUEST["dont_check"]);
1274 elseif (isset($_POST["scan_type"]) || !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])))
1275 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = array();
1276 if (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"]))
1277 $scan_level = intval($_POST["scan_level"]);
1278 if (isset($scan_level) && is_numeric($scan_level))
1279 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = intval($scan_level);
1280 foreach ($ajax_functions as $ajax_function) {
1281 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1282 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1283 }
1284 } elseif (GOTMLS_user_can()) {
1285 foreach ($ajax_functions as $ajax_function) {
1286 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1287 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", "GOTMLS_ajax_nopriv");
1288 }
1289 } else {
1290 foreach ($ajax_functions as $ajax_function) {
1291 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_nopriv");
1292 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", substr($ajax_function, 0, 1) == "l"?"GOTMLS_ajax_$ajax_function":"GOTMLS_ajax_nopriv");
1293 }
1294 }
1295 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1296 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1297 }
1298 add_action("admin_init", "GOTMLS_admin_init");
1299
1300 function GOTMLS_init() {
1301 register_post_type(
1302 'gotmls_quarantine',
1303 array(
1304 'labels' => array(
1305 'name' => _x( 'Quarantine', 'post type general name' ),
1306 'singular_name' => _x( 'Quarantine', 'post type singular name' ),
1307 'view_item' => __( 'View Quarantine Record' ),
1308 'all_items' => __( 'All Quarantine Records' ),
1309 ),
1310 'public' => false,
1311 'map_meta_cap' => true,
1312 'hierarchical' => false,
1313 'rewrite' => false,
1314 'query_var' => false,
1315 'can_export' => false,
1316 'delete_with_user' => false,
1317 'supports' => array( 'title', 'author', 'editor', 'excerpt', 'custom-fields' ),
1318 'capability_type' => 'customize_gotmls_quarantine',
1319 'capabilities' => array(
1320 'create_posts' => 'customize',
1321 'delete_others_posts' => 'customize',
1322 'delete_post' => 'customize',
1323 'delete_posts' => 'customize',
1324 'delete_private_posts' => 'customize',
1325 'delete_published_posts' => 'do_not_allow',
1326 'edit_others_posts' => 'do_not_allow',
1327 'edit_post' => 'do_not_allow',
1328 'edit_posts' => 'do_not_allow',
1329 'edit_private_posts' => 'do_not_allow',
1330 'edit_published_posts' => 'do_not_allow',
1331 'publish_posts' => 'customize',
1332 'read' => 'do_not_allow',
1333 'read_post' => 'do_not_allow',
1334 'read_private_posts' => 'customize',
1335 ),
1336 )
1337 );
1338 }
1339 add_action("init", "GOTMLS_init");
1340
1341 function GOTMLS_ajax_log_session() {
1342 header("Content-type: text/javascript");
1343 if (is_file(GOTMLS_plugin_path."safe-load/session.php"))
1344 require_once(GOTMLS_plugin_path."safe-load/session.php");
1345 if (isset($_SESSION["GOTMLS_SESSION_TEST"]))
1346 die("/* GOTMLS SESSION PASS */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nshowhide('GOTMLS_patch_searching', true);\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_patch_searching');\n\tshowhide('GOTMLS_patch_button', true);\n}\n");
1347 else {
1348 $_SESSION["GOTMLS_SESSION_TEST"] = 1;
1349 if (isset($_GET["SESSION"]) && is_numeric($_GET["SESSION"]) && $_GET["SESSION"] > 0)
1350 die("/* GOTMLS SESSION FAIL */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\ndocument.getElementById('GOTMLS_patch_searching').innerHTML = '<div class=\"error\">".GOTMLS_strip4java(__("Your Server could not start a Session!",'gotmls'))."</div>';");
1351 else
1352 die("/* GOTMLS SESSION TEST */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nstopCheckingSession = checkupdateserver('".GOTMLS_script_URI."&SESSION=1', 'GOTMLS_patch_searching');");
1353 }
1354 }
1355
1356 function GOTMLS_ajax_position() {
1357 if (GOTMLS_get_nonce()) {
1358 $GLOBALS["GOTMLS_msg"] = __("Default position",'gotmls');
1359 $properties = array("body" => 'style="margin: 0; padding: 0;"');
1360 if (isset($_GET["GOTMLS_msg"]) && $_GET["GOTMLS_msg"] == $GLOBALS["GOTMLS_msg"]) {
1361 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"] = $GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"];
1362 $gl = '><';
1363 $properties["html"] = $gl.'head'.$gl.'script type="text/javascript">
1364 if (curDiv = window.parent.document.getElementById("div_file")) {
1365 curDiv.style.left = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0].'";
1366 curDiv.style.top = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1].'";
1367 curDiv.style.height = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2].'";
1368 curDiv.style.width = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3].'";
1369 }
1370 </script'.$gl.'/head';
1371 } elseif (isset($_GET["GOTMLS_x"]) || isset($_GET["GOTMLS_y"]) || isset($_GET["GOTMLS_h"]) || isset($_GET["GOTMLS_w"])) {
1372 if (isset($_GET["GOTMLS_x"]))
1373 GOTMLS_validate_position(0, $_GET["GOTMLS_x"]);
1374 if (isset($_GET["GOTMLS_y"]))
1375 GOTMLS_validate_position(1, $_GET["GOTMLS_y"]);
1376 if (isset($_GET["GOTMLS_h"]))
1377 GOTMLS_validate_position(2, $_GET["GOTMLS_h"]);
1378 if (isset($_GET["GOTMLS_w"]))
1379 GOTMLS_validate_position(3, $_GET["GOTMLS_w"]);
1380 $_GET["GOTMLS_msg"] = __("New position",'gotmls');
1381 } else
1382 die("\n//Position Error: No new position to save!\n");
1383 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1384 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_htmlentities($_GET["GOTMLS_msg"]).' '.__("saved.",'gotmls').(implode($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"]) == implode($GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"])?"":' <a href="'.admin_url('admin-ajax.php?action=GOTMLS_position&'.GOTMLS_set_nonce(__FUNCTION__."1448").'&GOTMLS_msg='.urlencode($GLOBALS["GOTMLS_msg"])).'">['.$GLOBALS["GOTMLS_msg"].']</a>'))), $properties));
1385 } else
1386 die(GOTMLS_Invalid_Nonce("\n//Position Error: ")."\n");
1387 }
1388
1389 function GOTMLS_validate_position($vector, $position) {
1390 if (preg_match('/^[0-9]+px$/', $position)) {
1391 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][$vector] = $position;
1392 return true;
1393 } else
1394 return false;
1395 }
1396
1397 function GOTMLS_ajax_empty_trash() {
1398 global $wpdb;
1399 $gl = '><';
1400 $action = array("RESTORE" => "UPDATE $wpdb->posts SET `post_status` = 'private'", "DELETE" => "DELETE FROM $wpdb->posts");
1401 if (GOTMLS_get_nonce() && isset($_REQUEST["alter"]) && isset($action[$_REQUEST["alter"]])) {
1402 if ($trashed = $wpdb->query($action[$_REQUEST["alter"]]." WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) {
1403 $wpdb->query("REPAIR TABLE $wpdb->posts");
1404 $trashmsg = sprintf(__("%s %d item from the quarantine trash.",'gotmls'), strtoupper(GOTMLS_sanitize($_REQUEST["alter"])."d"), (INT) $trashed);
1405 } else
1406 $trashmsg = __("Failed to empty the trash.",'gotmls');
1407 } else
1408 $trashmsg = GOTMLS_Invalid_Nonce("");
1409 $properties = array("html" => $gl.'head'.$gl."script type='text/javascript'>\nalert('".GOTMLS_strip4java($trashmsg)."');\nif (curDiv = window.parent)\n\tcurDiv.location.reload(false);\nelse\n\twindow.opener.location.reload(false);</script$gl/head", "body" => 'style="margin: 0; padding: 0;"');
1410 die(GOTMLS_html_tags(array("html" => array("body" => $trashmsg)), $properties));
1411 }
1412
1413 function GOTMLS_ajax_whitelist() {
1414 if (GOTMLS_get_nonce()) {
1415 if (isset($_POST['GOTMLS_whitelist']) && isset($_POST['GOTMLS_chksum'])) {
1416 $file = GOTMLS_decode($_POST['GOTMLS_whitelist']);
1417 $chksum = explode("O", $_POST['GOTMLS_chksum']."O");
1418 if (strlen($chksum[0]) == 32 && strlen($chksum[1]) == 32 && is_file($file) && md5(@file_get_contents($file)) == $chksum[0]) {
1419 $filesize = @filesize($file);
1420 if (true) {
1421 if (!isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][0]))
1422 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][0] = "A0002";
1423 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][$chksum[0].'O'.$filesize] = "A0002";
1424 } else
1425 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file]);
1426 GOTMLS_update_option("definitions", $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]);
1427 $body = "Added $file to Whitelist!<br />\n<iframe style='width: 90%; height: 250px; border: none;' src='".GOTMLS_plugin_home."whitelist.html?whitelist=".GOTMLS_htmlspecialchars($_POST['GOTMLS_whitelist'])."&hash=$chksum[0]&size=$filesize&key=$chksum[1]'></iframe>";
1428 } else
1429 $body = "<li>Invalid Data!</li>";
1430 die(GOTMLS_html_tags(array("html" => array("body" => $body))));
1431 } else
1432 die("\n//Whitelist Error: Invalid checksum!\n");
1433 } else
1434 die(GOTMLS_Invalid_Nonce("\n//Whitelist Error: ")."\n");
1435 }
1436
1437 function GOTMLS_ajax_fix() {
1438 if (GOTMLS_get_nonce()) {
1439 if (isset($_POST["GOTMLS_fix"]) && !is_array($_POST["GOTMLS_fix"]))
1440 $_POST["GOTMLS_fix"] = array($_POST["GOTMLS_fix"]);
1441 if (isset($_REQUEST["GOTMLS_fix"]) && is_array($_REQUEST["GOTMLS_fix"]) && isset($_REQUEST["GOTMLS_fixing"]) && $_REQUEST["GOTMLS_fixing"]) {
1442 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1443 $callAlert = "clearTimeout(callAlert);\ncallAlert=setTimeout('alert_repaired(1)', 30000);";
1444 $li_js = "\n<script type=\"text/javascript\">\nscanned = 0;\nvar callAlert;\nfunction alert_repaired(failed) {\nclearTimeout(callAlert);\nif (failed)\nfilesFailed='the rest, try again to change more.';\nwindow.parent.check_for_donation('Fixed '+filesFixed+' files, failed to fix '+filesFailed);\n}\n$callAlert\nwindow.parent.showhide('GOTMLS_iFrame', true);\nfilesFixed=0;\nfilesFailed=0;\nfunction fixedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file))\n\tli_file.className='GOTMLS_plugin';\nif (li_file = window.parent.document.getElementById('GOTMLS_quarantine_'+file)) {\n\tli_file.style.display='none';\n\tli_file.innerHTML='';\n\t}\n}\nfunction DeletedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file)) {\n\tli_file.className='GOTMLS_plugin';\n\tif (true || !isNaN(file)) {\n\t\tli_file = li_file.parentNode".(isset($_REQUEST["GOTMLS_fix"][0]) && is_numeric($_REQUEST["GOTMLS_fix"][0])?'.parentNode':'').";\n\t\tli_file.style.display='none';\n\t\tli_file.innerHTML='';\n}}}\nfunction failedFile(file) {\n filesFailed++;\nwindow.parent.document.getElementById('check_'+file).checked=false; \n}\n</script>\n<script type=\"text/javascript\">\n/*<!--*"."/";
1445 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] * 2);
1446 $HTML = explode("split-here-for-content", GOTMLS_html_tags(array("html" => array("body" => "split-here-for-content"))));
1447 echo $HTML[0];
1448 GOTMLS_update_scan_log(array("scan" => array("dir" => count($_REQUEST["GOTMLS_fix"])." Files", "start" => time())));
1449 foreach ($_REQUEST["GOTMLS_fix"] as $clean_file) {
1450 if (is_numeric($clean_file)) {
1451 if (($Q_post = GOTMLS_get_quarantine($clean_file)) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine" && isset($Q_post["post_status"])) {
1452 $path = $Q_post["post_title"];
1453 if ($_REQUEST["GOTMLS_fixing"] > 1) {
1454 echo "<li>Removing $path ... ";
1455 $Q_post["post_status"] = "trash";
1456 if (wp_update_post($Q_post)) {
1457 echo __("Done!",'gotmls');
1458 $li_js .= "/*-->*"."/\nDeletedFile('$clean_file');\n/*<!--*"."/";
1459 } else {
1460 echo __("Failed to remove!",'gotmls');
1461 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1462 }
1463 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Removal from Quarantine")));
1464 } else {
1465 $Q_post["post_status"] = "pending";
1466 $part = explode(":", $Q_post["post_title"].':');
1467 if (count($part) > 2 && is_numeric($part[1])) {
1468 if (($R_post = GOTMLS_get_quarantine($part[1])) && isset($R_post["post_type"]) && strtolower($R_post["post_type"]) == $part[0]) {
1469 if (isset($_GET["eli"]) || ($R_post["post_content"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post["post_content"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1470 echo "<li>Restoring Post ID $part[1] ... ";
1471 $R_post["post_modified_gmt"] = $Q_post["post_modified"];
1472 $R_post["post_content"] = GOTMLS_decode($Q_post["post_content"]);
1473 if (wp_update_post($R_post)) {
1474
1475 echo __("Complete!",'gotmls');
1476 wp_update_post($Q_post);
1477 $li_js .= "/*-->*"."/\nfixedFile('$clean_file');\n/*<!--*"."/";
1478 } else {
1479 echo __("Restoration Failed!",'gotmls');
1480 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1481 }
1482 } else {
1483 echo "<li>".__("Restoration Aborted, post_content was modified outside of this quarantine!<pre>".GOTMLS_htmlspecialchars(print_r(array("R"=>$R_post,"Q"=>$Q_post),1))."</pre>",'gotmls');
1484 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1485 }
1486 } else {
1487 echo "<li>".__("Restore Failed!",'gotmls');
1488 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1489 }
1490 } elseif (isset($_GET["eli"]) || is_file($path)) {
1491 echo "<li>Restoring $path ... ";
1492 if (GOTMLS_file_put_contents($path, GOTMLS_decode($Q_post["post_content"])) && wp_update_post($Q_post)) {
1493 echo __("Complete!",'gotmls');
1494 $li_js .= "/*-->*"."/\nfixedFile('$clean_file');\n/*<!--*"."/";
1495 } else {
1496 echo __("Restore Failed!",'gotmls');
1497 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1498 }
1499 } else {
1500 echo "<li>".__("Restoration Aborted, file $path does not exist!",'gotmls');
1501 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1502 }
1503 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Restoration from Quarantine")));
1504 }
1505 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n</script>\n";
1506 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1507 }
1508 } elseif (is_numeric($decoded_file = GOTMLS_decode($clean_file))) {
1509 $li_js .= GOTMLS_db_scan($decoded_file);
1510 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n</script>\n";
1511 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1512 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "DB Fix")));
1513 } else {
1514 $path = realpath($decoded_file = GOTMLS_decode($clean_file));
1515 if (is_file($path)) {
1516 echo "<li>Fixing $path ... ";
1517 $li_js .= GOTMLS_scanfile($path);
1518 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n</script>\n";
1519 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1520 } else
1521 echo "<li>".sprintf(__("File %s not found!",'gotmls'), GOTMLS_htmlspecialchars($path))."</li>";
1522 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Automatic Fix")));
1523 }
1524 }
1525 $nonce = GOTMLS_set_nonce(__FUNCTION__."1588");
1526 die('<div id="check_site_warning" style="background-color: #F00;">'.sprintf(__("Because some changes were made we need to check to make sure it did not break your site. If this stays Red and the frame below does not load please <a %s>revert the changes</a> made during this automated fix process.",'gotmls'), 'href="'.GOTMLS_images_path.'?page=GOTMLS_View_Quarantine&'.$nonce.'"').' <span style="color: #F00;">'.__("Never mind, it worked!",'gotmls').'</span></div><br /><iframe id="test_frame" name="test_frame" src="'.admin_url('admin-ajax.php?action=GOTMLS_View_Quarantine&check_site=1&'.$nonce).'" style="width: 100%; height: 200px"></iframe>'.$li_js."/*-->*"."/\nalert_repaired(0);\n</script>\n$HTML[1]");
1527 } else
1528 die(GOTMLS_html_tags(array("html" => array("body" => "<script type=\"text/javascript\">\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".__("Nothing Selected to be Changed!",'gotmls')."');\n</script>".__("Done!",'gotmls')))));
1529 } else
1530 die(GOTMLS_html_tags(array("html" => array("body" => "<script type=\"text/javascript\">\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".GOTMLS_Invalid_Nonce("")."');\n</script>".__("Done!",'gotmls')))));
1531 }
1532
1533 function GOTMLS_ajax_scan() {
1534 if (GOTMLS_get_nonce()) {
1535 @error_reporting(0);
1536 if (isset($_GET["GOTMLS_scan"])) {
1537 $script_form = GOTMLS_js_text_range();
1538 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] - 5);
1539 if (is_numeric($_GET["GOTMLS_scan"])) {
1540 if (($Q_post = GOTMLS_get_quarantine((INT) $_GET["GOTMLS_scan"])) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine") {
1541 $GLOBALS["GOTMLS"]["tmp"]["file_contents"] = GOTMLS_decode($Q_post["post_content"]);
1542 GOTMLS_view_details($Q_post, '<form style="margin: 0;" method="post" action="'.admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."1605")).'" onsubmit="return confirm(\''.__("Are you sure you want to delete the record of this file from the quarantine?",'gotmls').'\');"><input type="hidden" name="GOTMLS_fix[]" value="'.$Q_post["ID"].'"><input type="hidden" name="GOTMLS_fixing" value="2"><input type="hidden" name="action" value="GOTMLS_fix"><input type="submit" value="DELETE from Quarantine" style="display: none; background-color: #C00; float: right;"></form>');
1543 } else
1544 die(GOTMLS_html_tags(array("html" => array("body" => __("This record no longer exists in the quarantine.",'gotmls')."<br />\n<script type=\"text/javascript\">\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n</script>"))));
1545 } elseif (substr($_GET["GOTMLS_scan"]."1234567", 0, 7) == "db_scan") {
1546 @header("Content-type: text/javascript");
1547 if (isset($_GET["GOTMLS_only_file"])) {
1548 if (strlen($_GET["GOTMLS_only_file"])) {
1549 echo '//re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1550 die(GOTMLS_db_scan().'//END OF JavaScript');
1551 } else {
1552 echo '//re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1553 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1554 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1555 $path = "db_scan=$file";
1556 echo "/*-->*"."/\nscanfilesArKeys.push('db_scan&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*<!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1557 }
1558 }
1559 die(GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Database Scan ...",'gotmls'))."/*-->*"."/\nscanNextDir(-1);\n/*<!--*"."/");
1560 }
1561 } else {
1562 echo '//db_scan: '.gmdate("Y-m-d H:i:s\n");
1563 die(GOTMLS_db_scan().'//END OF JavaScript');
1564 }
1565 } else {
1566 $file = GOTMLS_decode($_GET["GOTMLS_scan"]);
1567 if (is_numeric($file))
1568 die("\n$script_form".GOTMLS_db_scan($file));
1569 elseif (substr($file."1234567", 0, 7) == "db_scan") {
1570 @header("Content-type: text/javascript");
1571 if (isset($_GET["GOTMLS_only_file"])) {
1572 if (strlen($_GET["GOTMLS_only_file"])) {
1573 echo '//encoded re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1574 die(GOTMLS_db_scan().'//END OF JavaScript');
1575 } else {
1576 echo '//encoded re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1577 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1578 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1579 $path = "db_scan=$file";
1580 echo "/*-->*"."/\nscanfilesArKeys.push('".GOTMLS_encode($dir)."&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*<!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1581 }
1582 }
1583 echo GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Encoded Database Scan ...",'gotmls'))."/*-->*"."/\nscanNextDir(-1);\n/*<!--*"."/";
1584 }
1585 } else {
1586 echo '//encoded db_scan: but no GOTMLS_only_file'.gmdate("Y-m-d H:i:s\n");
1587 die(GOTMLS_db_scan().'//END OF JavaScript');
1588 }
1589 } elseif (is_dir($file)) {
1590 @error_reporting(0);
1591 @header("Content-type: text/javascript");
1592 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))
1593 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
1594 @ob_start();
1595 echo GOTMLS_scandir($file);
1596 if (@ob_get_level()) {
1597 GOTMLS_flush();
1598 @ob_end_clean();//_flush();
1599 }
1600 die('//END OF JavaScript');
1601 } elseif (file_exists($file)) {
1602 echo "<html>\n<head>\n<title>Scan File: ".htmlspecialchars($file)."</title>\n</head>\n<body>";
1603 GOTMLS_scanfile($file);
1604 $fa = "";
1605 $f = 0;
1606 if (isset($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && count($GLOBALS["GOTMLS"]["tmp"]["threats_found"])) {
1607 $f = 1;
1608 foreach ($GLOBALS["GOTMLS"]["tmp"]["threats_found"] as $threats_found => $threats_name) {
1609 list($start, $end, $junk) = explode("-", "$threats_found--", 3);
1610 if ($start > $end)
1611 $fa .= 'ERROR['.($f++).']: Threat_size{'.$threats_found.'} Content_size{'.strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'}';
1612 else
1613 $fa .= ' <a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range(\'ta_file\', '.$start.', '.$end.');">['.$f++.']</a>';
1614 }
1615 } else
1616 $fa = " No Threats Found";
1617 die("\n$script_form".'<form style="margin: 0;'.(($f==0)?" display: none;":"").'" method="post" action="'.admin_url('admin-ajax.php').'" onsubmit="return confirm(\''.__("Are you sure this file is not infected and you want to ignore it in future scans?",'gotmls').'\');"><input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."1680")).'"><input type="hidden" name="GOTMLS_whitelist" value="'.GOTMLS_encode($file).'"><input type="hidden" name="action" value="GOTMLS_whitelist"><input type="hidden" name="GOTMLS_chksum" value="'.md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'O'.GOTMLS_installation_key.'"><input type="submit" value="Whitelist this file" style="float: right;"></form>'.GOTMLS_file_details($file).'<div style="overflow: auto;"><span onmouseover="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'block\';" onmouseout="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'none\';">'.__("Potential threats in file:",'gotmls').'</span> ('.$fa.' )</div></td></tr><tr><td style="height: 100%"><textarea id="ta_file" style="width: 100%; height: 100%">'.GOTMLS_htmlentities(str_replace("\r", "", $GLOBALS["GOTMLS"]["tmp"]["file_contents"])).'</textarea></td></tr></table>');
1618 } else
1619 die(GOTMLS_html_tags(array("html" => array("body" => sprintf(__("The file %s does not exist, it must have already been deleted.",'gotmls'), GOTMLS_htmlspecialchars($file))."<script type=\"text/javascript\">\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n</script>"))));
1620 }
1621 } else
1622 die("\n//Directory Error: Nothing to scan!\n");
1623 } else {
1624 if (isset($_GET["GOTMLS_scan"]) && is_dir(GOTMLS_decode($_GET["GOTMLS_scan"]))) {
1625 @header("Content-type: text/javascript");
1626 $alert = "if (is_button = document.getElementById('resume_button')) is_button.value = 'Resume'; alert('Invalid or expired Nonce Token! You probably need to restart the scan :-(');";
1627 } else
1628 $alert = "<script type='text/javascript'>if (xFrame = window.parent.document.getElementById('GOTMLS_iFrame')) xFrame.style.display = 'block'; alert('Invalid or expired Nonce Token! You probably need to restart the scan :-(');</script>";
1629 die(GOTMLS_Invalid_Nonce("$alert\n//Ajax Scan Nonce Error: ")."\n");
1630 }
1631 }
1632
1633 function GOTMLS_ajax_nopriv() {
1634 die("\n//Permission Error: User not authenticated!\n");
1635 }
1636