PluginProbe ʕ •ᴥ•ʔ
Anti-Malware Security and Brute-Force Firewall / 4.21.96
Anti-Malware Security and Brute-Force Firewall v4.21.96
4.23.90 trunk 1.2.03.23 1.3.02.15 3.07.06 4.14.47 4.15.16 4.16.17 4.17.28 4.17.29 4.17.44 4.17.57 4.17.58 4.17.68 4.17.69 4.18.52 4.18.62 4.18.63 4.18.69 4.18.71 4.18.74 4.18.76 4.19.44 4.19.50 4.19.68 4.19.69 4.20.59 4.20.72 4.20.92 4.20.93 4.20.94 4.20.95 4.20.96 4.21.74 4.21.83 4.21.84 4.21.85 4.21.86 4.21.87 4.21.88 4.21.89 4.21.90 4.21.91 4.21.92 4.21.93 4.21.94 4.21.95 4.21.96 4.23.56 4.23.57 4.23.67 4.23.68 4.23.69 4.23.71 4.23.73 4.23.77 4.23.81 4.23.83 4.23.85 4.23.87 4.23.88 4.23.89
gotmls / index.php
gotmls Last commit date
images 2 years ago languages 2 years ago safe-load 2 years ago index.php 2 years ago readme.txt 2 years ago
index.php
1679 lines
1 <?php
2 /*
3 Plugin Name: Anti-Malware Security and Brute-Force Firewall
4 Plugin URI: https://gotmls.net/
5 Author: Eli Scheetz
6 Text Domain: gotmls
7 Author URI: https://supersecurehosting.com/
8 Contributors: scheeeli, gotmls
9 Donate link: https://gotmls.net/donate/
10 Description: This Anti-Virus/Anti-Malware plugin searches for Malware and other Virus like threats and vulnerabilities on your server and helps you remove them. It's always growing and changing to adapt to new threats so let me know if it's not working for you.
11 Version: 4.21.96
12 Requires PHP: 5.6
13 Requires CP: 1.1.1
14 */
15 if (isset($_SERVER["DOCUMENT_ROOT"]) && ($SCRIPT_FILE = str_replace($_SERVER["DOCUMENT_ROOT"], "", (isset($_SERVER["SCRIPT_FILENAME"])?$_SERVER["SCRIPT_FILENAME"]:(isset($_SERVER["SCRIPT_NAME"])?$_SERVER["SCRIPT_NAME"]:"")))) && strlen($SCRIPT_FILE) > strlen("/".basename(__FILE__)) && substr(__FILE__, -1 * strlen($SCRIPT_FILE)) == substr($SCRIPT_FILE, -1 * strlen(__FILE__)) || !(function_exists("add_action") && function_exists("load_plugin_textdomain")))
16 include(dirname(__FILE__)."/safe-load/index.php");
17 else
18 require_once(dirname(__FILE__)."/images/index.php");
19 /* ___
20 * / /\ GOTMLS Main Plugin File
21 * / /:/ @package GOTMLS
22 * /__/::\
23 Copyright \__\/\:\__ © 2012-2023 Eli Scheetz (email: eli@gotmls.net)
24 * \ \:\/\
25 * \__\::/ This program is free software; you can redistribute it
26 * ___ /__/:/ and/or modify it under the terms of the GNU General Public
27 * /__/\ _\__\/ License as published by the Free Software Foundation;
28 * \ \:\ / /\ either version 2 of the License, or (at your option) any
29 * ___\ \:\ /:/ later version.
30 * / /\\ \:\/:/
31 / /:/ \ \::/ This program is distributed in the hope that it will be useful,
32 / /:/_ \__\/ but WITHOUT ANY WARRANTY; without even the implied warranty
33 /__/:/ /\__ of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
34 \ \:\/:/ /\ See the GNU General Public License for more details.
35 \ \::/ /:/
36 \ \:\/:/ You should have received a copy of the GNU General Public License
37 * \ \::/ with this program; if not, write to the Free Software Foundation,
38 * \__\/ Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA */
39
40 load_plugin_textdomain('gotmls', false, basename(GOTMLS_plugin_path).'/languages');
41 require_once(GOTMLS_plugin_path.'images/index.php');
42
43 function GOTMLS_install() {
44 if (strpos(GOTMLS_get_version("URL"), '&wp=') && version_compare(GOTMLS_wp_version, GOTMLS_require_version, "<"))
45 die(GOTMLS_htmlspecialchars(GOTMLS_require_version_LANGUAGE.", NOT version: ".GOTMLS_wp_version));
46 else
47 delete_option("GOTMLS_definitions_array");
48 }
49 register_activation_hook(__FILE__, "GOTMLS_install");
50
51 function GOTMLS_uninstall() {
52 delete_option('GOTMLS_get_URL_array');
53 delete_option('GOTMLS_definitions_blob');
54 }
55 register_deactivation_hook(__FILE__, "GOTMLS_uninstall");
56
57 function GOTMLS_menu() {
58 if (GOTMLS_user_can()) {
59 $GLOBALS["GOTMLS"]["tmp"]["my_admin_page"] = add_menu_page($GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"], $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $GLOBALS["GOTMLS"]["tmp"]["base_page"], "GOTMLS_settings", GOTMLS_images_path.'GOTMLS-16x16.gif');
60 add_action('load-'.$GLOBALS["GOTMLS"]["tmp"]["my_admin_page"], 'GOTMLS_admin_add_help_tab');
61 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_Scan_Settings_LANGUAGE, GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $GLOBALS["GOTMLS"]["tmp"]["base_page"], "GOTMLS_settings");
62 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." Firewall Options", "Firewall Options", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS-Firewall-Options", "GOTMLS_Firewall_Options");
63 }
64 }
65 add_action("admin_menu", "GOTMLS_menu", 8);
66 add_action("network_admin_menu", "GOTMLS_menu", 8);
67
68 function GOTMLS_menu_Quarantine() {
69 if (GOTMLS_user_can() && isset($GLOBALS["GOTMLS"]["tmp"]["my_admin_page"]))
70 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_View_Quarantine_LANGUAGE, GOTMLS_View_Quarantine_LANGUAGE.(($Qs = GOTMLS_get_quarantine(true))?' <span class="awaiting-mod count-'.$Qs.'"><span class="awaiting-mod">'.$Qs.'</span></span>':""), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS_View_Quarantine", "GOTMLS_View_Quarantine");
71 }
72 add_action("admin_menu", "GOTMLS_menu_Quarantine", 16);
73 add_action("network_admin_menu", "GOTMLS_menu_Quarantine", 16);
74
75 function GOTMLS_admin_add_help_tab() {
76 $screen = get_current_screen();
77 $screen->add_help_tab(array(
78 'id' => "GOTMLS_Getting_Started",
79 'title' => __("Getting Started", 'gotmls'),
80 'content' => '<p>'.__("Make sure the Definition Updates are current and Run a Complete Scan.", 'gotmls').'</p><p>'.sprintf(__("If Known Threats are found and displayed in red then there will be a button to '%s'. If only Potentional Threats are found then there is no automatic fix because those are probably not malicious.", 'gotmls'), GOTMLS_Automatically_Fix_LANGUAGE).'</p><p>'.__("A backup of the original infected files are placed in the Quarantine in case you need to restore them or just want to look at them later. You can delete these files if you don't want to save more.", 'gotmls').'</p>'
81 ));
82 $FAQMarker = '== Frequently Asked Questions ==';
83 if (is_file(dirname(__FILE__).'/readme.txt') && ($readme = explode($FAQMarker, @file_get_contents(dirname(__FILE__).'/readme.txt').$FAQMarker)) && strlen($readme[1]) && ($readme = explode("==", $readme[1]."==")) && strlen($readme[0])) {
84 $screen->add_help_tab(array(
85 'id' => "GOTMLS_FAQs",
86 'title' => __("FAQs", 'gotmls'),
87 'content' => '<p>'.preg_replace('/\[(.+?)\]\((.+?)\)/', "<a target=\"_blank\" href=\"\\2\">\\1</a>", preg_replace('/[\r\n]+= /', "</p><b>", preg_replace('/ =[\r\n]+/', "</b><p>", $readme[0]))).'</p>'
88 ));
89 }
90 }
91
92 function GOTMLS_enqueue_scripts() {
93 wp_enqueue_style('dashicons');
94 }
95 add_action('admin_enqueue_scripts', 'GOTMLS_enqueue_scripts');
96
97 function GOTMLS_display_header($optional_box = "") {
98 global $current_user, $wpdb;
99 wp_get_current_user();
100 $head_nonce = GOTMLS_set_nonce(__FUNCTION__."100");
101 $GOTMLS_url_parts = explode('/', GOTMLS_siteurl);
102 $Update_Definitions = array(GOTMLS_update_home.'definitions.js'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"].'&'.GOTMLS_get_version_URL.'&'.$head_nonce.'&d='.ur1encode(GOTMLS_siteurl));
103 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])
104 array_unshift($Update_Definitions, GOTMLS_admin_url('GOTMLS_load_update', $head_nonce.'&UPDATE_definitions_array=1'));
105 else
106 $Update_Definitions[] = GOTMLS_admin_url('GOTMLS_load_update', $head_nonce.'&UPDATE_definitions_array=1');
107 $Update_Link = '<div style="text-align: center;"><a href="';
108 $new_version = "";
109 $file = basename(GOTMLS_plugin_path).'/index.php';
110 $current = get_site_transient("update_plugins");
111 if (isset($current->response[$file]->new_version) && version_compare(GOTMLS_Version, $current->response[$file]->new_version, "<")) {
112 $new_version = sprintf(__("Upgrade to %s now!",'gotmls'), $current->response[$file]->new_version).'<br /><br />';
113 $Update_Link .= wp_nonce_url(self_admin_url('update.php?action=upgrade-plugin&plugin=').$file, 'upgrade-plugin_'.$file);
114 }
115 $Update_Link .= "\">$new_version</a></div>";
116 $defLatest = (is_numeric($Latest = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"]))) && is_numeric($Default = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Default"]))) && $Latest > $Default)?1:0;
117 if (is_array($keys = GOTMLS_uckserialize(get_option('GOTMLS_Installation_Keys', array()))) && isset($keys[GOTMLS_installation_key]))
118 $isRegistered = $keys[GOTMLS_installation_key];
119 else
120 $isRegistered = "";
121 $Update_Div ='<div id="findUpdates" style="display: none;"><center>'.__("Searching for updates ...",'gotmls').'<br /><img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /><br /><input type="button" value="Cancel" onclick="cancelserver(\'findUpdates\');" /></center></div>';
122 $php_version = "<li>PHP: <span class='GOTMLS_date'>".phpversion()."</span></li>\n";
123 if (isset($_SERVER["SERVER_SOFTWARE"]) && preg_match('/Apache\/([0-9\.]+)/i', $_SERVER["SERVER_SOFTWARE"], $GLOBALS["GOTMLS"]["tmp"]["apache"]) && count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
124 $php_version .= "<li>Apache: <span class='GOTMLS_date'>".$GLOBALS["GOTMLS"]["tmp"]["apache"][1]."</span></li>\n";
125 elseif (isset($_SERVER["SERVER_SOFTWARE"]) && strlen($_SERVER["SERVER_SOFTWARE"]))
126 $php_version .= "<li>".esc_html($_SERVER["SERVER_SOFTWARE"])."</li>\n";
127 if ((isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)) {
128 $reg_email_key = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
129 $isRegistered = GOTMLS_get_registrant($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]);
130 } else
131 $reg_email_key = "";
132 echo GOTMLS_get_header().'
133 <div id="admin-page-container">
134 <div id="GOTMLS-right-sidebar" style="width: 300px;" class="metabox-holder">
135 '.GOTMLS_box(__("Updates & Registration",'gotmls'), "<ul>$php_version<li>".(function_exists('classicpress_version')?"ClassicPress: <span class='GOTMLS_date' title='CP: ".classicpress_version()."\nWP: ".GOTMLS_wp_version."'>".preg_replace( '#[+-].*$#', '', classicpress_version()):"WordPress: <span class='GOTMLS_date'>".GOTMLS_wp_version)."</span></li>\n<li>Plugin: <span class='GOTMLS_date'>".GOTMLS_Version.'</span></li>
136 <li><div id="GOTMLS_Key" style="margin: 0;'.((!$defLatest && !$isRegistered)?' display: none;">Key: <span style="float: right;">'.GOTMLS_installation_key.'</span></div><div style="':'">Key: <span style="float: right;" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">'.GOTMLS_installation_key.'</span></div><div style="display: none;').'"><form method="POST" action="'.admin_url('admin-ajax.php?'.$head_nonce).'" target="GOTMLS_iFrame" name="GOTMLS_Form_lognewkey"><input type="hidden" name="GOTMLS_installation_key" value="'.GOTMLS_installation_key.'"><input type="hidden" name="action" value="GOTMLS_lognewkey"><span style="color: #F00;" id="GOTMLS_No_Key">No Key! <input type="submit" style="float: right;" value="'.__("Get FREE Key!",'gotmls').'" class="button-primary" onclick="showhide(\'GOTMLS_No_Key\');showhide(\'GOTMLS_Key\', true);check_for_updates();" /></span></form></div></li>
137 <li>Definitions: <span id="GOTMLS_definitions_date" class="GOTMLS_date">'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"].'</span></li></ul>
138 <form id="updateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
139 <img style="display: none; float: left; margin-right: 4px;" src="'.GOTMLS_images_path.'checked.gif" height=16 width=16 alt="definitions updated" id="autoUpdateDownload" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">
140 '.str_replace('findUpdates', 'Definition_Updates', $Update_Div).'
141 <div id="autoUpdateForm" style="display: none;">
142 <input type="submit" style="width: 100%;" name="auto_update" value="'.__("Download new definitions!",'gotmls').'">
143 </div>
144 </form>
145 <form id="clearupdateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
146 <input name="UPDATE_definitions_array" value="D" type="hidden">
147 <input type="submit" style="display: none; width: 100%; color: #ff0; background-color: #c33" id="clear_updates" value="'.__("Delete ALL definitions!",'gotmls').'">
148 </form>
149 <div id="registerKeyForm" style="display: none;"><button onclick="force_update_check(500);" style="float: right;">Check Again</button><span id="registerFormMessage" style="color: #F00"><p>'.__("Get instant access to definition updates.",'gotmls').'</p></span><p>
150 '.__("If you have not already registered your Key then register now using the form below.<br />* All registration fields are required<br />** I will NOT share your information.",'gotmls').'</p>
151 <form id="registerform" onsubmit="return sinupFormValidate(this);" action="'.GOTMLS_plugin_home.'wp-login.php?action=register" method="post" name="registerform" target="_blank"><input type="hidden" name="redirect_to" id="register_redirect_to" value="/donate/"><input type="hidden" name="user_login" id="register_user_login" value=""><input type="hidden" name="old_user_email" id="old_user_email" value="'.$reg_email_key.'">
152 <div>'.__("Your Full Name:",'gotmls').'</div>
153 <div style="float: left; width: 50%;"><input style="width: 100%;" id="first_name" type="text" name="first_name" value="'.$current_user->user_firstname.'" /></div>
154 <div style="float: left; width: 50%;"><input style="width: 100%;" id="last_name" type="text" name="last_name" value="'.$current_user->user_lastname.'" /></div>
155 <div style="clear: left; width: 100%;">
156 <div>'.__("A password will be e-mailed to this address:",'gotmls').(strlen($reg_email_key) == 32 && $reg_email_key != md5($current_user->user_email)?'<br /><span style="color: #C00;">'.__("Note: The pre-populated email below is NOT the address this site is currently registered under!",'gotmls').'</span>':"").'</div>
157 <input style="width: 100%;" id="user_email" type="text" name="user_email" value="'.$current_user->user_email.'" /></div>
158 <div>
159 <div>'.__("Your WordPress Site URL:",'gotmls').'</div>
160 <input style="width: 100%;" id="user_url" type="text" name="user_url" value="'.GOTMLS_siteurl.'" readonly /></div>
161 <div>
162 <div>'.__("Plugin Installation Key:",'gotmls').'</div>
163 <input style="width: 100%;" id="installation_key" type="text" name="installation_key" value="'.GOTMLS_installation_key.'" readonly /><input id="old_key" type="hidden" name="old_key" value="'.md5($GOTMLS_url_parts[2]).'" /></div>
164 <input style="width: 100%;" id="wp-submit" type="submit" name="wp-submit" value="Register Now!" /></form></div>'.(false && $isRegistered?'Registered to: '.$isRegistered:"").$Update_Link, "stuffbox").'
165 <script type="text/javascript">
166 var pri_addr = "'.$Update_Definitions[0].'";
167 var alt_addr = "'.$Update_Definitions[1].'";
168 function check_for_updates() {
169 showhide("Definition_Updates", true);
170 stopCheckingDefinitions = checkPrimaryUpdateServer();
171 }
172 function force_update_check(wait) {
173 document.getElementById("Definition_Updates").innerHTML = \'<img src="'.GOTMLS_images_path.'wait.gif">'.GOTMLS_strip4java(__("Checking Registration ...",'gotmls')).'\';
174 showhide("Definition_Updates", true);
175 setTimeout(function() {var GOTMLS_update_time = new Date();stopCheckingDefinitions = checkPrimaryUpdateServer(\'&dt=\'+GOTMLS_update_time.getTime());}, wait);
176 showhide("registerKeyForm");
177 }
178 function updates_complete(chk) {
179 if (auto_img = document.getElementById("autoUpdateDownload")) {
180 auto_img.style.display="block";
181 check_for_donation(chk);
182 }
183 }
184 function sinupFormValidate(form) {
185 var error = "";
186 if(form["first_name"].value == "")
187 error += "'.__("First Name is a required field!",'gotmls').'\n";
188 if(form["last_name"].value == "")
189 error += "'.__("Last Name is a required field!",'gotmls').'\n";
190 if(form["user_email"].value == "")
191 error += "'.__("Email Address is a required field!",'gotmls').'\n";
192 else {
193 if (uem = document.getElementById("register_user_login"))
194 uem.value = form["user_email"].value;
195 if (uem = document.getElementById("register_redirect_to"))
196 uem.value = "/donate/?email="+form["user_email"].value.replace("@", "%40");
197 }
198 if(form["user_url"].value == "")
199 error += "'.__("Your WordPress Site URL is a required field!",'gotmls').'\n";
200 if(form["installation_key"].value == "")
201 error += "'.__("Plugin Installation Key is a required field!",'gotmls').'\n";
202 if(error != "") {
203 alert(error);
204 return false;
205 } else {
206 force_update_check(15000);
207 return true;
208 }
209 }
210 var divNAtext = false;
211 function loadGOTMLS() {
212 clearTimeout(divNAtext);
213 setDivNAtext();
214 '.$GLOBALS["GOTMLS"]["tmp"]["onLoad"].'
215 }
216 if ('.($defLatest+strlen($isRegistered)).')
217 check_for_updates();
218 /* else
219 showhide("registerKeyForm", true);*/
220 if (divNAtext)
221 loadGOTMLS();
222 else
223 divNAtext=true;
224 </script>
225 '.GOTMLS_box(__("Resources & Links",'gotmls'), '
226 <div id="pastDonations"></div>
227 <center>
228 <a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span> Donate Here <span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span></a>
229 </center>
230 <ul class="GOTMLS-sidebar-links">
231 <li style="float: right;"><b>on <a target="_blank" href="https://profiles.wordpress.org/scheeeli#content-plugins">WordPress.org</a></b><ul class="GOTMLS-sidebar-links">
232 <li><a target="_blank" href="https://wordpress.org/plugins/gotmls/faq/">Plugin FAQs</a></li>
233 <li><a target="_blank" href="https://wordpress.org/support/plugin/gotmls">Forum Posts</a></li>
234 <li><a target="_blank" href="https://wordpress.org/support/view/plugin-reviews/gotmls">Plugin Reviews</a></li>
235 </ul></li>
236 <li><img src="//gravatar.com/avatar/5feb789dd3a292d563fea3b885f786d6?s=16" border="0" alt="Plugin site:"><b><a target="_blank" href="'.GOTMLS_plugin_home.'">GOTMLS.NET</a></b></li>
237 <li><img src="//gravatar.com/avatar/c0a17ace1ccb92bf930ab3621bfd5e7c?s=16" border="0" alt="Hosting site:"><b><a target="_blank" href="https://supersecurehosting.com/">Secure Hosting</a></b></li>
238 <li><img src="https://s.gravatar.com/avatar/7530906968df6594bfbe934ddc117f58?s=16" border="0" alt="mail:"><b><a target="_blank" href="mailto:eli@gotmls.net">Email Eli</a></b></li>
239 </ul>
240 <a target="_blank" href="https://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html#url='.rawurlencode(GOTMLS_siteurl).'">Google Safe Browsing Diagnostic</a>', "stuffbox").//GOTMLS_box(__("Last Scan Status",'gotmls'), GOTMLS_scan_log(), "stuffbox").
241 $optional_box.'</div>';
242 if (isset($GLOBALS["GOTMLS"]["tmp"]["stuffbox"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["stuffbox"])) {
243 echo '
244 <script type="text/javascript">
245 function stuffbox_showhide(id) {
246 divx = document.getElementById(id);
247 if (divx) {
248 if (divx.style.display == "none" || arguments[1]) {';
249 $else = '
250 if (divx = document.getElementById("GOTMLS-right-sidebar"))
251 divx.style.width = "30px";
252 if (divx = document.getElementById("GOTMLS-main-section"))
253 divx.style.marginRight = "30px";';
254 foreach ($GLOBALS["GOTMLS"]["tmp"]["stuffbox"] as $md5 => $bTitle) {
255 echo "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'block';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".GOTMLS_strip4java($bTitle, true)."';";
256 $else .= "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'none';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".substr($bTitle, 0, 1)."';";
257 }
258 echo '
259 if (divx = document.getElementById("GOTMLS-right-sidebar"))
260 divx.style.width = "300px";
261 if (divx = document.getElementById("GOTMLS-main-section"))
262 divx.style.marginRight = "300px";
263 return true;
264 } else {'.$else.'
265 return false;
266 }
267 }
268 }
269 if (getWindowWidth(780) == 780)
270 setTimeout(function() {stuffbox_showhide("inside_'.$md5.'");}, 200);
271 </script>';
272 }
273 echo '
274 <div id="GOTMLS-main-section" style="margin-right: 300px;">
275 <div class="metabox-holder GOTMLS" style="width: 100%;" id="GOTMLS-metabox-container">';
276 }
277
278 function GOTMLS_get_scanlog() {
279 global $wpdb;
280 $LastScan = '';
281 if (isset($_GET["GOTMLS_cl"]) && is_numeric($_GET["GOTMLS_cl"]) && GOTMLS_get_nonce()) {
282 $SQL = $wpdb->prepare("DELETE FROM `$wpdb->options` WHERE option_name LIKE %s AND substring_index(option_name, '/', -1) < %s", 'GOTMLS_scan_log/%', $_GET["GOTMLS_cl"]);
283 if ($cleared = $wpdb->query($SQL))
284 $LastScan .= sprintf(__("Cleared %s records from the history.",'gotmls'), $cleared);
285 // else $LastScan .= $wpdb->last_error."<li>$SQL</li>";
286 }
287 $SQL = $wpdb->prepare("SELECT substring_index(option_name, '/', -1) AS `mt`, option_name, option_value FROM `$wpdb->options` WHERE option_name LIKE %s ORDER BY mt DESC", 'GOTMLS_scan_log/%');
288 if ($rs = $wpdb->get_results($SQL, ARRAY_A)) {
289 $units = array("seconds"=>60,"minutes"=>60,"hours"=>24,"days"=>365,"years"=>10);
290 $LastScan .= '<ul class="GOTMLS-scanlog GOTMLS-sidebar-links">';
291 foreach ($rs as $row) {
292 $LastScan .= "\n<li>";
293 $GOTMLS_scan_log = (isset($row["option_name"])?get_option($row["option_name"], array()):array());
294 if (isset($GOTMLS_scan_log["scan"]["type"]) && strlen($GOTMLS_scan_log["scan"]["type"]))
295 $LastScan .= GOTMLS_sanitize($GOTMLS_scan_log["scan"]["type"]);
296 else
297 $LastScan .= "Unknown scan type";
298 if (isset($GOTMLS_scan_log["scan"]["dir"]) && @is_dir($GOTMLS_scan_log["scan"]["dir"]))
299 $LastScan .= " of ".basename($GOTMLS_scan_log["scan"]["dir"]);
300 if (isset($GOTMLS_scan_log["scan"]["start"]) && is_numeric($GOTMLS_scan_log["scan"]["start"])) {
301 $time = (time() - $GOTMLS_scan_log["scan"]["start"]);
302 $ukeys = array_keys($units);
303 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= $units[$ukeys[$key]]); $unit = $ukeys[++$key])
304 $time = floor($time/$units[$ukeys[$key]]);
305 if (1 == $time)
306 $unit = substr($unit, 0, -1);
307 $LastScan .= " started $time $unit ago";
308 if (isset($GOTMLS_scan_log["scan"]["finish"]) && is_numeric($GOTMLS_scan_log["scan"]["finish"]) && ($GOTMLS_scan_log["scan"]["finish"] >= $GOTMLS_scan_log["scan"]["start"])) {
309 $time = ($GOTMLS_scan_log["scan"]["finish"] - $GOTMLS_scan_log["scan"]["start"]);
310 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= $units[$ukeys[$key]]); $unit = $ukeys[++$key])
311 $time = floor($time/$units[$ukeys[$key]]);
312 if (1 == $time)
313 $unit = substr($unit, 0, -1);
314 if ($time)
315 $LastScan .= " and ran for $time $unit";
316 else
317 $LastScan = str_replace("started", "ran", $LastScan);
318 } else
319 $LastScan .= " and has not finish";
320 } else
321 $LastScan .= " failed to started";
322 $LastScan .= '<a href="'.GOTMLS_script_URI.'&GOTMLS_cl='.$row["mt"].'&'.GOTMLS_set_nonce(__FUNCTION__."313").'">[clear history below this entry]</a></li>';
323 }
324 $LastScan .= '</ul>';
325 } else
326 $LastScan .= '<h3>'.__("No Scans have been logged",'gotmls').'</h3>';
327 return "$LastScan\n";
328 }
329
330 function GOTMLS_get_whitelists() {
331 $Q_Page = '';
332 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"])) {
333 $Q_Page .= '<ul name="found_Quarantine" id="found_Quarantine" class="GOTMLS_plugin known" style="background-color: #ccc; padding: 0;"><h3>'.__("Globally White-listed files",'gotmls').'<span class="GOTMLS_date">'.__("# of patterns",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Updated",'gotmls').'</span></h3>';
334 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"] as $file => $non_threats) {
335 if (isset($non_threats[0])) {
336 $updated = GOTMLS_sexagesimal($non_threats[0]);
337 unset($non_threats[0]);
338 } else
339 $updated = "Unknown";
340 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($non_threats).'</span><span class="GOTMLS_date">'.$updated."</span>$file</li>\n";
341 }
342 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"])) {
343 $Q_Page .= '<h3>'.__("WordPress Core files",'gotmls').'<span class="GOTMLS_date">'.__("# of files",'gotmls').'</span></h3>';
344 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"] as $ver => $files) {
345 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($files)."</span>Version $ver</li>\n";
346 }
347 }
348 $Q_Page .= "</ul>";
349 }
350 return "$Q_Page\n";
351 }
352
353 function GOTMLS_Quarantine_Trash() {
354 global $wpdb;
355 $Q_Page = '<div id="empty_trash_link" style="float: right;"><form method="post" onsubmit="if (curDiv = document.getElementById(\'empty_trash_link\')) curDiv.style.display = \'none\';" target="GOTMLS_statusFrame" action="'.GOTMLS_admin_url('GOTMLS_empty_trash', GOTMLS_set_nonce(__FUNCTION__."346")).'">';
356 if (($trashed = $wpdb->get_var("SELECT COUNT(*) FROM $wpdb->posts WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) > 1)
357 $Q_Page .= '<input class="primary" style="float: right;" type="submit" value="RESTORE" name="alter"><input class="primary" style="color: red; float: right;" type="submit" value="DELETE" name="alter"><span style="float: right; margin: 3px;">'.sprintf(__("%d Quarantine Records in the Trash",'gotmls'), (INT) $trashed)."</span>";
358 return "$Q_Page</form></div>\n";
359 }
360
361 function GOTMLS_ajax_View_Quarantine() {
362 GOTMLS_ajax_load_update();
363 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_get_header().GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine())))));
364 }
365
366 function GOTMLS_View_Quarantine() {
367 GOTMLS_ajax_load_update();
368 $echo = GOTMLS_box($Q_Page = __("White-lists",'gotmls'), GOTMLS_get_whitelists());
369 if (!isset($_GET['Whitelists']))
370 $echo .= "\n<script>\nshowhide('inside_".md5($Q_Page)."');\n</script>\n";
371 $echo .= GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine());
372 GOTMLS_display_header();
373 echo "$echo\n</div></div></div>";
374 }
375
376 function GOTMLS_Firewall_Options() {
377 global $current_user, $wpdb, $table_prefix;
378 GOTMLS_ajax_load_update();
379 GOTMLS_display_header();
380 $GOTMLS_nonce_found = GOTMLS_get_nonce();
381 $gt = ">"; // This local variable never changes
382 $lt = "<"; // This local variable never changes
383 $save_action = "";
384 $patch_attr = array(
385 array(
386 "icon" => "blocked",
387 "language" => "<b>".__("(This patch only works under Apache servers and requires mod_rewrite and session_start to be active and functional)",'gotmls')."</b><br />\n".__("Your WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. Applying this patch will block access to the WordPress Login page whenever this type of attack is detected.",'gotmls'),
388 "status" => __('Not Installed','gotmls'),
389 "action" => __('Install Patch','gotmls')
390 ),
391 array(
392 "language" => __("Your WordPress site has the current version of my brute-force Login protection installed.",'gotmls'),
393 "action" => __('Uninstall Patch','gotmls'),
394 "status" => __('Enabled','gotmls'),
395 "icon" => "checked"
396 ),
397 array(
398 "language" => __("Your WordPress Login page has the old version of my brute-force protection installed. Upgrade this patch to improve the protection on the WordPress Login page and preserve the integrity of your WordPress core files.",'gotmls'),
399 "action" => __('Upgrade Patch','gotmls'),
400 "status" => __('Out of Date','gotmls'),
401 "icon" => "threat"
402 )
403 );
404 $find = '|<Files[^>]+xmlrpc.php>(.+?)</Files>\s*(# END GOTMLS Patch to Block XMLRPC Access\s*)*|is';
405 $deny = "\n<IfModule !mod_authz_core.c>\norder deny,allow\ndeny from all";
406 $allow = "";
407 if (isset($_SERVER["REMOTE_ADDR"])) {
408 $deny .= "\nallow from ".GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"]);
409 $allow .= " ".GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"]);
410 }
411 if (isset($_SERVER["SERVER_ADDR"])) {
412 $deny .= "\nallow from ".GOTMLS_safe_ip($_SERVER["SERVER_ADDR"]);
413 $allow .= " ".GOTMLS_safe_ip($_SERVER["SERVER_ADDR"]);
414 }
415 $deny .= "\n</IfModule>\n<IfModule mod_authz_core.c>\nRequire";
416 if (strlen(trim($allow)) > 0)
417 $deny .= " ip$allow";
418 else
419 $deny .= " all denied";
420 $deny .= "\n</IfModule>";
421 if (count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
422 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
423 else {
424 if (isset($GLOBALS["GOTMLS"]["tmp"]["apache"][0]) && (strtolower(substr($GLOBALS["GOTMLS"]["tmp"]["apache"][0]."123456", 0, 6)) == "apache"))
425 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
426 else
427 $errdiv = "<div class='error'>".__('Unable to find Apache on this server, this patch work on Apache servers!','gotmls')."</div>";
428 }
429 $Firewall_nonce = $lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."420")).'"'.$gt;
430 $patch_action = $lt.'form method="POST" name="GOTMLS_Form_XMLRPC_patch"'.$gt.$Firewall_nonce.$lt.'script'.$gt."\nfunction setFirewall(opt, val) {\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_opt'))\n\t\tautoUpdateDownloadGIF.value = opt;\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_val'))\n\t\tautoUpdateDownloadGIF.value = val;\n}\nfunction testComplete() {\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_XMLRPC_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_XMLRPC_patch_searching');\n\tshowhide('GOTMLS_XMLRPC_patch_button', true);\n}\n}\nwindow.onload=testComplete;\n$lt/script$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="hidden" name="GOTMLS_XMLRPC_patching" value="';
431 $patch_found = false;
432 $head = str_replace(array('|<Files[^>]+', '(.+?)', '\\s*(', '\\s*)*|is'), array("<Files ", "$deny\n", "\n", "\n"), $find);
433 $htaccess = "";
434 if (is_file(ABSPATH.'.htaccess'))
435 if (($htaccess = @file_get_contents(ABSPATH.'.htaccess')) && strlen($htaccess))
436 $patch_found = preg_match($find, $htaccess);
437 if ($patch_found) {
438 $errdiv = "";
439 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0) && GOTMLS_file_put_contents(ABSPATH.'.htaccess', preg_replace($find, "", $htaccess)))
440 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Allowing Access';
441 elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0))
442 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Blocking: '.sprintf(__("Failed to remove XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
443 else
444 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Blocked';
445 } else {
446 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0) && GOTMLS_file_put_contents(ABSPATH.'.htaccess', "$head$htaccess")) {
447 $patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Blocked';
448 $errdiv = "";
449 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0))
450 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Allowing Access: '.sprintf(__("Failed to install XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
451 else
452 $patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Allowing Access';
453 }
454 $patch_action .= ")$errdiv$lt/b$gt$lt/p$gt".__("Most WordPress sites do not use the XMLRPC features and hack attempts on the xmlrpc.php file are more common then ever before. Even if there are no vulnerabilities for hackers to exploit, these attempts can cause slowness or downtime similar to a DDoS attack. This patch automatically blocks all external access to the xmlrpc.php file.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt.$lt.'hr /'.$gt;
455 $patch_status = 0;
456 $patch_found = -1;
457 $find = "#if\s*\(([^\&]+\&\&)?\s*file_exists\((.+?)(safe-load|wp-login)\.php'\)\)\s*require(_once)?\((.+?)(safe-load|wp-login)\.php'\);#";
458 $head = str_replace(array('#', '\\(', '\\)', '(_once)?', ')\\.', '\\s*', '(.+?)(', '|', '([^\\&]+\\&\\&)?'), array(' ', '(', ')', '_once', '.', ' ', '\''.dirname(__FILE__).'/', '/', '!in_array($_SERVER["REMOTE_ADDR"], array("'.GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"]).'")) &&'), $find);
459 if (is_file(ABSPATH.'../wp-config.php') && !is_file(ABSPATH.'wp-config.php'))
460 $wp_config = '../wp-config.php';
461 else
462 $wp_config = 'wp-config.php';
463 if (is_file(ABSPATH.$wp_config)) {
464 if (($config = @file_get_contents(ABSPATH.$wp_config)) && strlen($config)) {
465 if ($patch_found = preg_match($find, $config)) {
466 if (strpos($config, substr($head, strpos($head, "file_exists")))) {
467 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && GOTMLS_file_put_contents(ABSPATH.$wp_config, preg_replace('#'.$lt.'\?[ph\s]+(//.*\s*)*\?'.$gt.'#i', "", preg_replace($find, "", $config))))
468 $patch_action .= GOTMLS_error_div(__("Removed Brute-Force Protection",'gotmls'));
469 else
470 $patch_status = 1;
471 } else {
472 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && GOTMLS_file_put_contents(ABSPATH.$wp_config, preg_replace($find, "$head", $config))) {
473 $patch_action .= GOTMLS_error_div(__("Upgraded Brute-Force Protection",'gotmls'), "updated");
474 $patch_status = 1;
475 } else
476 $patch_status = 2;
477 }
478 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && strlen($config) && ($patch_found == 0) && GOTMLS_file_put_contents(ABSPATH.$wp_config, "$lt?php$head// Load Brute-Force Protection by GOTMLS.NET before the WordPress bootstrap. ?$gt$config")) {
479 $patch_action .= GOTMLS_error_div(__("Installed Brute-Force Protection",'gotmls'), "updated");
480 $patch_status = 1;
481 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]))
482 $patch_action .= GOTMLS_error_div(sprintf(__("Failed to install Brute-Force Protection (wp-config.php %s)",'gotmls'),(is_readable(ABSPATH.$wp_config)?'read-'.(is_writable(ABSPATH.$wp_config)?'write':'only'):"unreadable").": ".strlen($config).GOTMLS_fileperms(ABSPATH.$wp_config)), "updated");
483 } else
484 $patch_action .= GOTMLS_error_div(__("wp-config.php Not Readable!",'gotmls'));
485 } else
486 $patch_action .= GOTMLS_error_div(__("wp-config.php Not Found!",'gotmls'));
487 if ($GOTMLS_nonce_found && file_exists(ABSPATH.'wp-login.php') && ($login = @file_get_contents(ABSPATH.'wp-login.php')) && strlen($login) && (preg_match($find, $login))) {
488 if (isset($_POST["GOTMLS_patching"]) && ($source = GOTMLS_get_URL("http://core.svn.wordpress.org/tags/".GOTMLS_wp_version.'/wp-login.php')) && (strlen($source) > 500) && GOTMLS_file_put_contents(ABSPATH.'wp-login.php', $source))
489 $patch_action .= GOTMLS_error_div(__("Removed Old Brute-Force Login Patch",'gotmls'), "updated");
490 else
491 $patch_status = 2;
492 }
493 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_firewall_option"]) && strlen($_POST["GOTMLS_firewall_option"]) && isset($_POST["GOTMLS_firewall_value"]) && strlen($_POST["GOTMLS_firewall_value"])) {
494 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"][GOTMLS_sanitize($_POST["GOTMLS_firewall_option"])] = (INT) $_POST["GOTMLS_firewall_value"];
495 if (update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]))
496 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";
497 else
498 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSave Failed!$lt/div$gt\n";
499 }
500 $sec_opts = $lt.'form method="POST" name="GOTMLS_Form_firewall"'.$gt.$lt.'input type="hidden" id="fw_opt" name="GOTMLS_firewall_option" value="traversal"'.$gt.$lt.'input type="hidden" name="GOTMLS_firewall_value" id="fw_val" value="0"'.$gt.$Firewall_nonce;
501 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]) && array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]))
502 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"] as $TP => $VA)
503 if (is_array($VA) && count($VA) > 3 && strlen($VA[1]) && strlen($VA[2]))
504 $sec_opts .= $lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="submit" style="float: right;" value="'.(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]?"Enable Protection\" onclick=\"setFirewall('$TP', 0);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt."b$gt$VA[1] (Currently Disabled)":"Disable Protection\" onclick=\"setFirewall('$TP', 1);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt."b$gt$VA[1] (Automatically Enabled)")."$lt/b$gt$lt/p$gt$VA[2]$lt/div$gt$lt".'hr /'.$gt;
505 $sec_opts .= "$lt/form$gt\n$patch_action\n$lt".'form method="POST" name="GOTMLS_Form_patch"'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$Firewall_nonce.$lt.'input type="submit" value="'.$patch_attr[$patch_status]["action"].'" style="float: right;'.($patch_status?'"'.$gt:' display: none;" id="GOTMLS_patch_button"'.$gt.$lt.'div id="GOTMLS_patch_searching" style="float: right;"'.$gt.__("Checking for session compatibility ...",'gotmls').' '.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /'.$gt.$lt.'/div'.$gt).$lt.'input type="hidden" name="GOTMLS_patching" value="1"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$patch_attr[$patch_status]["icon"].'.gif"'.$gt.$lt.'b'.$gt.'Brute-force Protection '.$patch_attr[$patch_status]["status"].$lt.'/b'.$gt.$lt.'/p'.$gt.$patch_attr[$patch_status]["language"].__(" For more information on Brute-Force attack prevention and the WordPress wp-login-php file ",'gotmls').' '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-login-php/"'.$gt.__("read my blog",'gotmls')."$lt/a$gt.$lt/div$gt$lt/form$gt\n$lt"."script type='text/javascript'$gt\nfunction search_patch_onload() {\n\tstopCheckingSession = checkupdateserver('".GOTMLS_admin_url('GOTMLS_log_session')."');\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', search_patch_onload)\nelse\n\tdocument.attachEvent('onload', search_patch_onload);\n$lt/script$gt";
506 $admin_notice = "";
507 if ($current_user->user_login == "admin") {
508 $admin_notice .= $lt.'hr /'.$gt;
509 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_admin_username"]) && ($current_user->user_login != trim($_POST["GOTMLS_admin_username"])) && strlen(trim($_POST["GOTMLS_admin_username"])) && preg_match('/^\s*[a-z_0-9\@\.\-]{3,}\s*$/i', $_POST["GOTMLS_admin_username"])) {
510 if ($wpdb->update($wpdb->users, array("user_login" => trim($_POST["GOTMLS_admin_username"])), array("user_login" => $current_user->user_login))) {
511 $wpdb->query($wpdb->prepare("UPDATE `{$wpdb->prefix}sitemeta` SET `meta_value` = REPLACE(`meta_value`, 's:5:\"admin\";', %s) WHERE `meta_key` = 'site_admins' AND `meta_value` like %s", 's:'.strlen(trim($_POST["GOTMLS_admin_username"])).':"'.trim($_POST["GOTMLS_admin_username"]).'";', '%s:5:"admin";%'));
512 $admin_notice .= GOTMLS_error_div(sprintf(__("You username has been change to %s. Don't forget to use your new username when you login again.",'gotmls'), $_POST["GOTMLS_admin_username"]), "updated");
513 } else
514 $admin_notice .= GOTMLS_error_div(sprintf(__("SQL Error changing username: %s. Please try again later.",'gotmls'), $wpdb->last_error));
515 } else {
516 if (isset($_POST["GOTMLS_admin_username"]))
517 $admin_notice .= GOTMLS_error_div(sprintf(__("Your new username must be at least 3 characters and can only contain &quot;%s&quot;. Please try again.",'gotmls'), "a-z0-9_.-@"), "updated");
518 $admin_notice .= $lt.'form method="POST" name="GOTMLS_Form_admin"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'div style="float: left;"'.$gt.__("Change your username:",'gotmls').$lt.'/div'.$gt.$Firewall_nonce.$lt.'input style="float: left;" type="text" id="GOTMLS_admin_username" name="GOTMLS_admin_username" size="6" value="'.$current_user->user_login.'"'.$gt.$lt.'input style="float: left;" type="submit" value="Change"'.$gt.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Admin Notice'.$lt.'/b'.$gt.$lt.'/p'.$gt.__("Your username is \"admin\", this is the most commonly guessed username by hackers and brute-force scripts. It is highly recommended that you change your username immediately.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt;
519 }
520 }
521 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_wpfirewall_action"])) {
522 if ($_POST["GOTMLS_wpfirewall_action"] == "exclude_terms")
523 update_option("WP_firewall_exclude_terms", "");
524 elseif ($_POST["GOTMLS_wpfirewall_action"] == "whitelisted_ip" && isset($_SERVER["REMOTE_ADDR"])) {
525 $ips = GOTMLS_uckserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"));
526 if (is_array($ips))
527 $ips = array_merge($ips, array(GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"])));
528 else
529 $ips = array(GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"]));
530 update_option("WP_firewall_whitelisted_ip", serialize($ips));
531 }
532 }
533 if (get_option("WP_firewall_exclude_terms", "Not Found!") == "allow") {
534 $end = "$lt/div$gt$lt/form$gt\n{$lt}hr /$gt";
535 $img = 'threat.gif"';
536 $button = $lt.'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'exclude_terms\';" value="'.__("Disable this Rule",'gotmls').'"'.$gt;
537 $wpfirewall_action = $lt.'form method="POST" name="GOTMLS_Form_wpfirewall2"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="hidden" name="GOTMLS_wpfirewall_action" id="GOTMLS_wpfirewall_action" value=""'.$gt.$Firewall_nonce.$button.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$img.$gt.$lt.'b'.$gt."WP Firewall 2 (Conflicting Firewall Rule)$lt/b$gt$lt/p$gt".__("The Conflicting Firewall Rule (WP_firewall_exclude_terms) activated by the WP Firewall 2 plugin has been shown to interfere with the Definition Updates and WP Core File Scans in my Anti-Malware plugin. I recommend that you disable this rule in the WP Firewall 2 plugin.",'gotmls').$end;
538 if (isset($_SERVER["REMOTE_ADDR"])) {
539 if (is_array($ips = GOTMLS_uckserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"))) && in_array($_SERVER["REMOTE_ADDR"], $ips))
540 $wpfirewall_action = str_replace(array($img, $end), array('question.gif"', __(" However, your current IP has been Whitelisted so you could probably keep this rule enabled if you really want to.",'gotmls').$end), $wpfirewall_action);
541 else
542 $wpfirewall_action = str_replace(array($button, $end), array($button.$lt."br /$gt$lt".'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'whitelisted_ip\';" value="'.__("Whitelist your IP",'gotmls').'"'.$gt, __(" However, if you would like to keep this rule enabled you should at least Whitelist your IP.",'gotmls').$end), $wpfirewall_action);
543 }
544 $sec_opts = $wpfirewall_action.$sec_opts;
545 }
546 echo GOTMLS_box(__("Firewall Options",'gotmls'), $save_action.$sec_opts.$admin_notice)."\n</div></div></div>";
547 }
548
549 function GOTMLS_get_registrant($you) {
550 global $current_user, $wpdb;
551 wp_get_current_user();
552 if (isset($you["you"]))
553 $you = $you["you"];
554 if (isset($you["user_email"]) && strlen($you["user_email"]) == 32) {
555 if ($you["user_email"] == md5($current_user->user_email))
556 $registrant = $current_user->user_email;
557 elseif (!($registrant = $wpdb->get_var($wpdb->prepare("SELECT `user_nicename` FROM `$wpdb->users` WHERE MD5(`user_email`) = %s", $you["user_email"]))))
558 $registrant = GOTMLS_siteurl;
559 } else
560 $registrant = GOTMLS_siteurl;
561 return $registrant;
562 }
563
564 function GOTMLS_ajax_load_update() {
565 global $wpdb;
566 $GOTMLS_nonce_found = GOTMLS_get_nonce();
567 $GOTMLS_definitions_versions = array();
568 $user_info = array();
569 $saved = false;
570 $moreJS = "";
571 $finJS = "\n}";
572 $form = 'registerKeyForm';
573 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key could not be confirmed!</li>";
574 $autoUpJS = '<span style="color: #C00;">This new feature is currently only available to registered users who have donated $29 or more.</span><br />';
575 if (is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
576 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names)
577 foreach ($definition_names as $definition_name=>$definition_version)
578 if (is_array($definition_version) && isset($definition_version[0]) && strlen($definition_version[0]) == 5)
579 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
580 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
581 asort($GOTMLS_definitions_versions);
582 if (isset($_REQUEST["UPDATE_definitions_array"]) && strlen($_REQUEST["UPDATE_definitions_array"])) {
583 $DEF_url = 'http:'.GOTMLS_update_home.'definitions.php?'.GOTMLS_get_version_URL.'&'.GOTMLS_set_nonce(__FUNCTION__."574").'&d='.ur1encode(GOTMLS_siteurl);
584 if (isset($_REQUEST["dt"]) && strlen($_REQUEST["dt"]))
585 $DEF_url .= '&dt='.preg_replace('/[^\w]/', "", $_REQUEST["dt"]);
586 if (strlen($_REQUEST["UPDATE_definitions_array"]) > 1 && $GOTMLS_nonce_found) {
587 $GOTnew_definitions = GOTMLS_uckserialize(GOTMLS_decode($_REQUEST["UPDATE_definitions_array"]));
588 if (is_array($GOTnew_definitions)) {
589 $form = 'autoUpdateDownload';
590 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('Downloaded Definitions');";
591 }
592 } elseif ($_REQUEST["UPDATE_definitions_array"] == "D" && $GOTMLS_nonce_found) {
593 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = array();
594 $GOTnew_definitions = array();
595 delete_option('GOTMLS_get_URL_array');
596 } elseif (($DEF = GOTMLS_get_URL($DEF_url)) && is_array($GOTnew_definitions = GOTMLS_uckserialize(GOTMLS_decode($DEF))) && count($GOTnew_definitions)) {
597 if (isset($GOTnew_definitions["you"]["user_email"]) && strlen($GOTnew_definitions["you"]["user_email"]) == 32) {
598 $toInfo = GOTMLS_get_registrant($GOTnew_definitions["you"]);
599 $innerHTML = "<li style=\\\"color: #0C0\\\">Your Installation Key is Registered to:<br /> $toInfo</li>";
600 $form = 'autoUpdateForm';
601 if (isset($GOTnew_definitions["you"]["user_donations"]) && isset($GOTnew_definitions["you"]["user_donation_total"]) && isset($GOTnew_definitions["you"]["user_donation_freshness"])) {
602 $user_donations_src = $GOTnew_definitions["you"]["user_donations"];
603 if ($GOTnew_definitions["you"]["user_donation_total"] > 27.99) {
604 $autoUpJS = '<input type="radio" id="auto_UPDATE_definitions_1" name="UPDATE_definitions_array" value="1">Yes | <input type="radio" id="auto_UPDATE_definitions_0" name="UPDATE_definitions_array" value="0" checked>No <input type="hidden" name="UPDATE_definitions_checkbox" value="UPDATE_definitions_array">';
605 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
606 foundUpdates.innerHTML = "<a href=\'javascript:document.getElementById(\\"GOTMLS_Form\\").submit();\' onclick=\'document.getElementById(\\"auto_UPDATE_definitions_1\\").checked=true;\' style=\'color: #f00;\'>Set Definition Updates to Automatically Download to activate this feature.</a>";';
607 }
608 if ($user_donations_src > 0 && $GOTnew_definitions["you"]["user_donation_total"] > 0)
609 $li = "<li> You have made $user_donations_src donation".($user_donations_src?'s totalling':' for').' $'.$GOTnew_definitions["you"]["user_donation_total"].".</li><!-- ".$GOTnew_definitions["you"]["user_donation_freshness"]." -->";
610 }
611 } else
612 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key is not registered!</li>";
613 asort($GOTnew_definitions);
614 if (serialize($GOTnew_definitions) == serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
615 unset($GOTnew_definitions);
616 else {
617 $debug = substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), 0, 9)." ".md5(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".strlen(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), -9)." != ".substr(serialize($GOTnew_definitions), 0, 9)." ".md5(serialize($GOTnew_definitions))." ".strlen(serialize($GOTnew_definitions)." ".substr(serialize($GOTnew_definitions), -9));
618 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = $GOTnew_definitions;
619 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('New Definitions Automatically Installed :-)');";
620 }
621 $finJS .= "\nif (divNAtext)\n\tloadGOTMLS();\nelse\n\tdivNAtext = setTimeout(function() {loadGOTMLS();}, 4000);";
622 $finJS .= "\nif (typeof stopCheckingDefinitions !== 'undefined' && stopCheckingDefinitions)\n\tclearTimeout(stopCheckingDefinitions);";
623 } else
624 $innerHTML = "<li style=\\\"color: #f00\\\"><a title='report error' href='#' onclick=\\\"stopCheckingDefinitions = checkAlternateUpdateServer('&error=".GOTMLS_encode(serialize(array("get_URL"=>$GLOBALS["GOTMLS"]["get_URL"])))."');\\\">Automatic Update Connection Failed!</a></li>";
625 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]))
626 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]);
627 } else
628 $innerHTML = "<li style=\\\"color: #f00\\\">".__("definitions_array not set!", 'gotmls')."</li>";
629 if (isset($GOTnew_definitions) && is_array($GOTnew_definitions)) {
630 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = GOTMLS_array_replace($GLOBALS["GOTMLS"]["tmp"]["definitions_array"], $GOTnew_definitions);
631 if (file_exists(GOTMLS_plugin_path.'definitions_update.txt'))
632 @unlink(GOTMLS_plugin_path.'definitions_update.txt');
633 $saved = GOTMLS_update_option('definitions', $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]);
634 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
635 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names) {
636 if ($threat_level != "potential")
637 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $threat_level;
638 foreach ($definition_names as $definition_name=>$definition_version)
639 if (is_array($definition_version) && isset($definition_version[0]) && strlen($definition_version[0]) == 5)
640 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
641 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
642 }
643 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["log"]["settings"]["check"];
644 asort($GOTMLS_definitions_versions);
645 $autoUpJS .= '<span style="color: #0C0;">(Newest Definition Updates Installed.)</span>';
646 } elseif ($form != 'registerKeyForm') {
647 $form = 'autoUpdateDownload';
648 $autoUpJS .= '<span style="color: #0C0;">(No newer Definition Updates are available at this time.)</span>';
649 $innerHTML .= "<li style=\\\"color: #0C0\\\">No Newer Definition Updates Available.</li>";
650 }
651 if (isset($_SERVER["SCRIPT_FILENAME"]) && preg_match('/[\/\\\\]admin-ajax\.php/i', $_SERVER["SCRIPT_FILENAME"]) && isset($_REQUEST["action"]) && $_REQUEST["action"] == "GOTMLS_load_update") {
652 if (!$user_donations_src)
653 $li = "<li style=\\\"color: #f00;\\\">You have not donated yet!</li>";
654 if (strlen($moreJS) == 0)
655 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
656 foundUpdates.innerHTML = "<a target=\'_blank\' href=\'https://gotmls.net/donate/?key='.GOTMLS_installation_key.'\' style=\'color: #f00;\'>Donate $29+ now then enable Automatic Definition Updates to Scan for Core Files changes.</a>";';
657 $moreJS .= "\n\tif (foundUpdates = document.getElementById('pastDonations'))\n\tfoundUpdates.innerHTML = '$li';";
658 if ($GOTMLS_nonce_found)
659 @header("Content-type: text/javascript");
660 else
661 die(GOTMLS_Invalid_Nonce("Nonce Error: "));
662 if (is_array($GOTMLS_definitions_versions) && count($GOTMLS_definitions_versions) && (strlen($new_ver = trim(array_pop($GOTMLS_definitions_versions))) == 5) && $saved) {
663 $innerHTML .= "<li style=\\\"color: #0C0\\\">New Definition Updates Installed.</li>";
664 $finJS .= "\nif (foundUpdates = document.getElementById('GOTMLS_definitions_date')) foundUpdates.innerHTML = '$new_ver';\nif (foundUpdates = document.getElementById('autoUpdateForm')) foundUpdates.style.display = 'none';";
665 } elseif (isset($GOTnew_definitions) && is_array($GOTnew_definitions) && count($GOTnew_definitions))
666 $finJS .= "\nalert('Definition update $new_ver could not be saved because update_option Failed! (saved=".($saved?"TRUE":"FALSE").") $debug');";
667 if (isset($_REQUEST["UPDATE_core"]) && ($_REQUEST["UPDATE_core"] == GOTMLS_wp_version) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version])) {
668 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version] as $file => $md5) {
669 if (is_file(ABSPATH.$file)) {
670 GOTMLS_load_contents(file_get_contents(ABSPATH.$file));
671 if (GOTMLS_check_threat($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"], ABSPATH.$file)) {
672 if (isset($GLOBALS["GOTMLS"]["tmp"]["new_contents"]) && isset($_REQUEST["UPDATE_restore"]) && ($_REQUEST["UPDATE_restore"] == md5($GLOBALS["GOTMLS"]["tmp"]["new_contents"])."O".strlen($GLOBALS["GOTMLS"]["tmp"]["new_contents"])))
673 $autoUpJS .= "<li>Core File Restored: $file</li>";
674 else
675 $autoUpJS .= "<li>Core File MODIFIED: $file (".md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"])."O".strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"])." => $md5)</li>";
676 }
677 } else
678 $autoUpJS .= "<li>Core File MISSING: $file</li>";
679 }
680 $autoUpJS .= GOTMLS_error_div('Definition update: '.preg_replace('/[^0-9\.]/', "", $_REQUEST["UPDATE_core"]).' checked '.count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version]).' core files!', "update");
681 }
682 die('//<![CDATA[
683 var inc_form = "";
684 if (foundUpdates = document.getElementById("autoUpdateDownload"))
685 foundUpdates.src += "?'.$user_donations_src.'";
686 if (foundUpdates = document.getElementById("registerKeyForm"))
687 foundUpdates.style.display = "none";
688 if (foundUpdates = document.getElementById("'.$form.'"))
689 foundUpdates.style.display = "block";
690 if (foundUpdates = document.getElementById("Definition_Updates"))
691 foundUpdates.innerHTML = "<ul class=\\"GOTMLS-sidebar-links\\">'.$innerHTML.'</ul>"+inc_form;
692 function setDivNAtext() {
693 var foundUpdates;
694 '.$moreJS.$finJS.'
695 if (foundUpdates = document.getElementById("UPDATE_definitions_div"))
696 foundUpdates.innerHTML = \''.$autoUpJS.'\';
697 //]]>');
698 }
699 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] = '?div=Definition_Updates';
700 foreach ($GOTMLS_definitions_versions as $definition_name=>$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"])
701 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[$definition_name]=".$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"];
702 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)
703 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[you]=".$GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
704 }
705
706 function GOTMLS_settings() {
707 global $wpdb, $GOTMLS_dirs_at_depth, $GOTMLS_dir_at_depth;
708 $GOTMLS_scan_groups = array();
709 $gt = ">"; // This local variable never changes
710 $lt = "<"; // This local variable never changes
711 GOTMLS_ajax_load_update();
712 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))
713 $_REQUEST["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
714 if (($GOTMLS_nonce_found = GOTMLS_get_nonce()) && ((isset($_REQUEST["check"]) && is_array($_REQUEST["check"])) || (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"])))) {
715 if (isset($_REQUEST["check"]) && is_array($_REQUEST["check"]))
716 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = GOTMLS_sanitize($_REQUEST["check"]);
717 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
718 }
719 $dirs = GOTMLS_explode_dir(__FILE__);
720 for ($SL=0;$SL<intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);$SL++)
721 $GOTMLS_scan_groups[] = implode(GOTMLS_slash(), array_slice($dirs, -1 * (3 + $SL), 1));
722 if (isset($_POST["exclude_ext"])) {
723 if (strlen(trim(str_replace(",","",$_POST["exclude_ext"]).' ')) > 0)
724 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(str_replace('.', ',', GOTMLS_sanitize($_POST["exclude_ext"]))), -1, PREG_SPLIT_NO_EMPTY);
725 else
726 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = array();
727 }
728 $default_exclude_ext = str_replace(",gotmls", "", implode(",", $GLOBALS["GOTMLS"]["tmp"]["skip_ext"]));
729 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
730 if (isset($_POST["UPDATE_definitions_checkbox"])) {
731 if (isset($_POST[$_POST["UPDATE_definitions_checkbox"]]) && is_numeric($_POST[$_POST["UPDATE_definitions_checkbox"]]))
732 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = (INT) $_POST[$_POST["UPDATE_definitions_checkbox"]];
733 else
734 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = "";
735 }
736 if (isset($_POST["exclude_dir"])) {
737 if (strlen(trim(str_replace(",","",$_POST["exclude_dir"]).' ')) > 0)
738 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(GOTMLS_sanitize($_POST["exclude_dir"])), -1, PREG_SPLIT_NO_EMPTY);
739 else
740 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = array();
741 for ($d=0; $d<count($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]); $d++)
742 if (dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]) != ".")
743 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d] = str_replace("\\", "", str_replace("/", "", str_replace(dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]), "", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d])));
744 }
745 $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"] = array_merge($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"], $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"]);
746 if (isset($_POST["scan_what"]) && is_numeric($_POST["scan_what"]) && $_POST["scan_what"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"])
747 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = (INT) $_POST["scan_what"];
748 if (isset($_POST["check_custom"]) && $_POST["check_custom"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"])
749 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = GOTMLS_verify_regex(trim(stripslashes($_POST["check_custom"])));
750 if (isset($_POST["scan_depth"]) && is_numeric($_POST["scan_depth"]) && $_POST["scan_depth"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])
751 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = (INT) $_POST["scan_depth"];
752 if (isset($_POST['skip_quarantine']) && is_numeric($_POST['skip_quarantine']) && $_POST['skip_quarantine'])
753 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = (INT) $_POST['skip_quarantine'];
754 elseif (isset($_POST["exclude_ext"]))
755 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = 0;
756 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
757 $scan_whatopts = '';
758 $scan_root = "public_html";
759 $scan_optjs = "\n{$lt}script type=\"text/javascript\"$gt\nfunction showOnly(what) {\n";
760 foreach ($GOTMLS_scan_groups as $mg => $GOTMLS_scan_group) {
761 $scan_optjs .= "document.getElementById('only$mg').style.display = 'none';\n";
762 $scan_whatopts = "\n$lt/div$gt\n$lt/div$gt\n$scan_whatopts";
763 $scan_root = $GOTMLS_scan_group;
764 $dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + $mg)));
765 $files = GOTMLS_getfiles($dir);
766 if (isset($files) && is_array($files))
767 foreach ($files as $file)
768 if (is_dir(GOTMLS_trailingslashit($dir).$file))
769 $scan_whatopts = $lt.'input type="checkbox" name="scan_only[]" value="'.GOTMLS_htmlspecialchars($file).'" /'.$gt.GOTMLS_htmlspecialchars($file).$lt.'br /'.$gt.$scan_whatopts;
770 $scan_whatopts = "\n$lt".'div style="padding: 4px 30px;" id="scan_group_div_'.$mg.'"'.$gt.$lt.'input type="radio" name="scan_what" id="not-only'.$mg.'" value="'.$mg.'"'.($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]==$mg?' checked':'').' /'.$gt.$lt.'a style="text-decoration: none;" href="#scan_what" onclick="showOnly(\''.$mg.'\');document.getElementById(\'not-only'.$mg.'\').checked=true;"'."$gt{$lt}b$gt$GOTMLS_scan_group$lt/b$gt$lt/a$gt{$lt}br /$gt\n$lt".'div class="rounded-corners" style="position: absolute; display: none; background-color: #CCF; margin: 0; padding: 10px; z-index: 10;" id="only'.$mg.'"'.$gt.$lt.'div style="padding-bottom: 6px;"'.$gt.GOTMLS_close_button('only'.$mg, 0).$lt.'b'.$gt.str_replace(" ", "&nbsp;", __("Only Scan These Folders:",'gotmls')).$lt.'/b'.$gt.$lt.'/div'.$gt.$scan_whatopts;
771 }
772 $scan_optjs .= "document.getElementById('only'+what).style.display = 'block';\n}";
773 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && strlen(trim(" ".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])))
774 $scan_optjs .= "\nfunction auto_UPDATE_check() {\n\tif (auto_UPdef_check = document.getElementById('auto_UPDATE_definitions_".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]."'))\n\t\tauto_UPdef_check.checked = true;\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', auto_UPDATE_check)\nelse\n\tdocument.attachEvent('onload', auto_UPDATE_check);\n";
775 $scan_optjs .= "$lt/script$gt";
776 $GOTMLS_nonce_URL = GOTMLS_set_nonce(__FUNCTION__."790");
777 $scan_opts = "\n$lt".'form method="POST" id="GOTMLS_Form" name="GOTMLS_Form"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', $GOTMLS_nonce_URL).'"'.$gt.$lt.'input type="hidden" name="scan_type" id="scan_type" value="Complete Scan" /'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="submit" id="complete_scan" value="'.__("Run Complete Scan",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Complete Scan\';" /'.$gt.$lt.'/div'.$gt.'
778 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to look for:",'gotmls').$lt.'/b'.$gt.$lt.'a title="'.__("Check for all threat types, if any of these are in red or otherwise unavailable then please download the latest definition updates.",'gotmls').'"'.$gt.$lt.'span class="dashicons dashicons-editor-help"'.$gt.$lt.'/span'.$gt.$lt.'/a'.$gt.$lt.'/p'.$gt.'
779 '.$lt.'div style="padding: 0 30px;"'.$gt;
780 $cInput = '"'.$gt.$lt.'input';
781 $pCheck = "$cInput checked";
782 $kCheck = "";
783 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $threat_level_name=>$threat_level) {
784 $scan_opts .= $lt.'div id="check_'.$threat_level.'_div" style="padding: 0; position: relative;';
785 if (($threat_level != "wp_core" && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level])) || isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level][GOTMLS_wp_version])) {
786 if ($threat_level != "potential" && in_array($threat_level,$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"])) {
787 $pCheck = " display: none;$cInput";
788 $scan_opts .= "$cInput checked";
789 } elseif ($threat_level == "potential")
790 $scan_opts .= $pCheck;
791 else
792 $scan_opts .= $cInput;
793 if ($threat_level != "potential")
794 $kCheck .= ",'$threat_level'";
795 $scan_opts .= ' type="checkbox" onchange="pCheck(this);" name="check[]" id="check_'.$threat_level.'_Yes" value="'.$threat_level.'" /'.$gt.' '.$lt.'a style="text-decoration: none;" href="#check_'.$threat_level.'_div_0" onclick="document.getElementById(\'check_'.$threat_level.'_Yes\').checked=true;pCheck(document.getElementById(\'check_'.$threat_level.'_Yes\'));showhide(\'dont_check_'.$threat_level.'\');"'."$gt{$lt}b$gt$threat_level_name$lt/b$gt$lt/a$gt\n";
796 if (isset($_GET["SESSION"])) {
797 $scan_opts .= "\n$lt".'div style="padding: 0 20px; position: relative; top: -18px; display: none;" id="dont_check_'.$threat_level.'"'.$gt.$lt.'a class="rounded-corners" style="position: absolute; left: 0; margin: 0; padding: 0 4px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;" href="#check_'.$threat_level.'_div_0" onclick="showhide(\'dont_check_'.$threat_level.'\');"'.$gt.'X'.$lt.'/a'.$gt;
798 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level] as $threat_name => $threat_regex)
799 $scan_opts .= $lt."br /$gt\n$lt".'input type="checkbox" name="dont_check[]" value="'.GOTMLS_htmlspecialchars($threat_name).'"'.(in_array(GOTMLS_sanitize($threat_name), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])?' checked /'.$gt.$lt.'script'.$gt.'showhide("dont_check_'.$threat_level.'", true);'.$lt.'/script'.$gt:' /'.$gt).(isset($_SESSION["GOTMLS_debug"][$threat_name])?$lt.'div style="float: right;"'.$gt.GOTMLS_htmlspecialchars(print_r($_SESSION["GOTMLS_debug"][$threat_name],1))."$lt/div$gt":"").GOTMLS_htmlspecialchars($threat_name);
800 $scan_opts .= "\n$lt/div$gt";
801 }
802 } else
803 $scan_opts .= $lt.'a title="'.__("Download Definition Updates to Use this feature",'gotmls').'"'.$gt.$lt.'img src="'.GOTMLS_images_path.'blocked.gif" height=16 width=16 alt="X"'.$gt.$lt.'b'.$gt.'&nbsp; '.$threat_level_name.$lt.'/b'.$gt.$lt.'br /'.$gt.$lt.'div style="padding: 14px;" id="check_'.$threat_level.'_div_NA"'.$gt.$lt.'span style="color: #F00"'.$gt.__("Download the new definitions (Right sidebar) to activate this feature.",'gotmls')."$lt/span$gt$lt/div$gt";
804 $scan_opts .= "\n$lt/div$gt";
805 }
806 $scan_opts .= $lt.'/div'.$gt.$lt.'/div'.$gt.'
807 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to scan:",'gotmls').$lt.'/b'.$gt.$lt.'a title="'.sprintf(__("The higher up in the directory hierarchy you start the more sub-directories get scanned (e.g. scanning the %s directory will also include the sub-directories wp-content and plugins within it).",'gotmls'), $scan_root).'"'.$gt.$lt.'span class="dashicons dashicons-editor-help"'.$gt.$lt.'/span'.$gt.$lt.'/a'.$gt.$lt.'/p'.$gt.$scan_whatopts.$scan_optjs.$lt.'/div'.$gt.'
808 '.$lt.'div style="float: left;" id="scanwhatfolder"'.$gt.$lt.'/div'.$gt.'
809 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Directory Scan Depth:",'gotmls').$lt.'/b'.$gt.$lt.'a title="'.__("How many directories deep to scan: -1 is infinite depth, 0 to skip the file scan completely.",'gotmls').'"'.$gt.$lt.'span class="dashicons dashicons-editor-help"'.$gt.$lt.'/span'.$gt.$lt.'/a'.$gt.$lt.'/p'.$gt.'
810 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" value="'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"].'" name="scan_depth" size="5"'.$gt.$lt.'/div'.$gt.$lt.'/div'.$gt.$lt.'br style="clear: left;"'.$gt;
811 if (isset($_GET["SESSION"]) && isset($_SESSION["GOTMLS_debug"])) {$scan_opts .= $lt.'div style="float: right;"'.$gt.GOTMLS_htmlspecialchars(print_r(array("sess" => $_SESSION),1))."$lt/div$gt"; $_SESSION["GOTMLS_debug"] = array();}
812 if (isset($_GET["eli"])) {//still testing this option['total']['total']
813 if ($_GET["eli"] == "find") {
814 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && (count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) > 1)) {
815 $fe = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][0];
816 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][1];
817 } else {
818 $fe = " no";
819 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"] as $f => $e)
820 if (is_array($e) && in_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"], $e))
821 $fe = " $f";
822 }
823 } else
824 $fe = "";
825 $scan_opts .= "\n$lt".'div style="padding: 10px;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Custom RegExp:",'gotmls').$fe.$lt.'/b'.$gt.' ('.__("For very advanced users only. Do not use this without talking to Eli first. If used incorrectly you could easily break your site.",'gotmls').')'.$lt.'/p'.$gt.$lt.'input type="text" name="check_custom" style="width: 100%;" value="'.GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]).'" /'."$gt$lt/div$gt\n";
826 }
827 $QuickScan = $lt.((is_dir(dirname(__FILE__)."/../../../wp-includes") && is_dir(dirname(__FILE__)."/../../../wp-admin"))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&$GOTMLS_nonce_URL").'" class="button-primary" style="min-height: 22px; height: 22px; line-height: 13px; padding: 3px;">WP_Core</a':"!-- No wp-includes or wp-admin --").$gt;
828 foreach (array("Plugins", "Themes") as $ScanFolder)
829 $QuickScan .= '&nbsp;'.$lt.((is_dir(dirname(__FILE__)."/../../../wp-content/".strtolower($ScanFolder)))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&scan_only%5B%5D=wp-content/".strtolower($ScanFolder)."&$GOTMLS_nonce_URL")."\" class=\"button-primary\" style=\"min-height: 22px; height: 22px; line-height: 13px; padding: 3px;\"$gt$ScanFolder$lt/a":"!-- No $ScanFolder in wp-content --").$gt;
830 $scan_opts .= "\n$lt".'p'.$gt.$lt.'b'.$gt.__("Skip files with the following extensions:",'gotmls')."$lt/b$gt".(($default_exclude_ext!=implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))?" {$lt}a href=\"javascript:void(0);\" onclick=\"document.getElementById('exclude_ext').value = '$default_exclude_ext';\"{$gt}[Restore Defaults]$lt/a$gt":"").$lt.'/p'.$gt.'
831 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a comma separated list of file extentions to skip",'gotmls').'" name="exclude_ext" id="exclude_ext" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]).'" style="width: 100%;" /'."$gt$lt/div$gt$lt".'p'.$gt.$lt.'b'.$gt.__("Skip directories with the following names:",'gotmls')."$lt/b$gt$lt/p$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a folder name or comma separated list of folder names to skip",'gotmls').'" name="exclude_dir" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]).'" style="width: 100%;" /'.$gt.$lt.'/div'.$gt.'
832 '.$lt.'table style="width: 100%" cellspacing="10"'.$gt.$lt.'tr'.$gt.$lt.'td nowrap valign="top" style="white-space: nowrap; width: 1px;"'.$gt.$lt.'b'.$gt.__("Automatically Update Definitions:",'gotmls').$lt."br$gt$lt/b$gt$lt/td$gt$lt".'td'.$gt.$lt.'div id="UPDATE_definitions_div"'.$gt.$lt.'br'.$gt.$lt.'span style="color: #C00;"'.$gt.__("This feature is only available to registered users who have donated at a certain level.",'gotmls')."$lt/span$gt$lt/div$gt$lt/td$gt$lt".'td align="right" valign="bottom"'.$gt.$lt.'input type="submit" id="save_settings" value="'.__("Save Settings",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Save\';" /'."$gt$lt/td$gt$lt/tr$gt$lt/table$gt$lt/form$gt";
833 $title_tagline = $lt."li$gt Site Title: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogname'"));
834 $title_tagline .= "$lt/li$gt$lt"."li$gt Tagline: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogdescription'"));
835 if (preg_match('/h[\@a]ck[3e]d.*by/is', $title_tagline))
836 echo GOTMLS_error_div(sprintf(__("Your Site Title or Tagline suggests that you may have been hacked ...%sThis could impact the indexing of your site and may even lead to blacklisting. You can change those options on the %sGeneral Settings$lt/a$gt page.",'gotmls'), "$title_tagline$lt/li$gt", $lt.'a href="'.admin_url("options-general.php").'"'.$gt));
837 @ob_start();
838 $OB_default_handlers = array("default output handler", "zlib output compression");
839 $OB_handlers = @ob_list_handlers();
840 if (is_array($OB_handlers) && count($OB_handlers))
841 foreach ($OB_handlers as $OB_last_handler)
842 if (!in_array($OB_last_handler, $OB_default_handlers))
843 echo GOTMLS_error_div(sprintf(__("Another Plugin or Theme is using '%s' to handle output buffers. <br />This prevents actively outputting the buffer on-the-fly and could severely degrade the performance of this (and many other) Plugins. <br />Consider disabling caching and compression plugins (at least during the scanning process).",'gotmls'), GOTMLS_htmlspecialchars($OB_last_handler)));
844 GOTMLS_display_header();
845 $scan_groups = array_merge(array(__("Scanned Files",'gotmls')=>"scanned",__("Selected Folders",'gotmls')=>"dirs",__("Scanned Folders",'gotmls')=>"dir",__("Skipped Folders",'gotmls')=>"skipdirs",__("Skipped Files",'gotmls')=>"skipped",__("Scan/Read Errors",'gotmls')=>"errors",__("Quarantined Files",'gotmls')=>"bad"), $GLOBALS["GOTMLS"]["tmp"]["threat_levels"]);
846 echo $lt.'script type="text/javascript">
847 var percent = 0;
848 function pCheck(chkb) {
849 var kCheck = ['.trim($kCheck,",").'];
850 chk = true;
851 for (var i = 0; i < kCheck.length; i++) {
852 var chkbox = document.getElementById("check_"+kCheck[i]+"_Yes");
853 if (chkbox && chkb.id == "check_potential_Yes" && chkb.checked == false) {
854 chk = false;
855 chkbox.checked = true;
856 } else if (chkbox && chkbox.checked) {
857 chk = false;
858 }
859 }
860 if (chkbox = document.getElementById("check_potential_Yes"))
861 chkbox.checked = chk;
862 if (chk) {
863 document.getElementById("check_potential_div").style.display = "block";
864 alert("If you do not select any other threat types, then only potential threats will be found and the automatic fix will not be available!");
865 } else
866 document.getElementById("check_potential_div").style.display = "none";
867 }
868 function changeFavicon(percent) {
869 var oldLink = document.getElementById("wait_gif");
870 if (oldLink) {
871 if (percent >= 100) {
872 document.getElementsByTagName("head")[0].removeChild(oldLink);
873 var link = document.createElement("link");
874 link.id = "wait_gif";
875 link.type = "image/gif";
876 link.rel = "shortcut icon";
877 var threats = '.implode(" + ", array_merge($GLOBALS["GOTMLS"]["tmp"]["threat_levels"], array(__("Potential Threats",'gotmls')=>"errors",__("WP-Login Updates",'gotmls')=>"errors"))).';
878 if (threats > 0) {
879 if ((errors * 2) == threats)
880 linkhref = "blocked";
881 else
882 linkhref = "threat";
883 } else
884 linkhref = "checked";
885 link.href = "'.GOTMLS_images_path.'"+linkhref+".gif";
886 document.getElementsByTagName("head")[0].appendChild(link);
887 }
888 } else {
889 var icons = document.getElementsByTagName("link");
890 var link = document.createElement("link");
891 link.id = "wait_gif";
892 link.type = "image/gif";
893 link.rel = "shortcut icon";
894 link.href = "'.GOTMLS_images_path.'wait.gif";
895 // document.head.appendChild(link);
896 document.getElementsByTagName("head")[0].appendChild(link);
897 }
898 }
899 function update_status(title, time) {
900 sdir = (dir+direrrors);
901 if (arguments[2] >= 0 && arguments[2] <= 100)
902 percent = arguments[2];
903 else
904 percent = Math.floor((sdir*100)/dirs);
905 scan_state = "6F6";
906 if (percent == 100) {
907 showhide("pause_button", true);
908 showhide("pause_button");
909 title = "'.$lt.'b'.$gt.GOTMLS_strip4java(__("Scan Complete!",'gotmls')).$lt.'/b'.$gt.'";
910 } else
911 scan_state = "99F";
912 changeFavicon(percent);
913 if (sdir) {
914 if (arguments[2] >= 0 && arguments[2] <= 100)
915 timeRemaining = Math.ceil(((time-startTime)*(100/percent))-(time-startTime));
916 else
917 timeRemaining = Math.ceil(((time-startTime)*(dirs/sdir))-(time-startTime));
918 if (timeRemaining > 59)
919 timeRemaining = Math.ceil(timeRemaining/60)+" Minute";
920 else
921 timeRemaining += " Second";
922 if (timeRemaining.substr(0, 2) != "1 ")
923 timeRemaining += "s";
924 } else
925 timeRemaining = "Calculating Time";
926 timeElapsed = Math.ceil(time);
927 if (timeElapsed > 59)
928 timeElapsed = Math.floor(timeElapsed/60)+" Minute";
929 else
930 timeElapsed += " Second";
931 if (timeElapsed.substr(0, 2) != "1 ")
932 timeElapsed += "s";
933 divHTML = \''.$lt.'div align="center" style="vertical-align: middle; background-color: #ccc; z-index: 3; height: 18px; width: 100%; border: solid #000 1px; position: relative; padding: 10px 0;"'.$gt.$lt.'div style="height: 18px; padding: 10px 0; position: absolute; top: 0px; left: 0px; background-color: #\'+scan_state+\'; width: \'+percent+\'%"'.$gt.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; left: 10px; z-index: 5; line-height: 16px;" align="left"'.$gt.'\'+sdir+" Folder"+(sdir==1?"":"s")+" Checked'.$lt.'br /'.$gt.'"+timeElapsed+\' Elapsed'.$lt.'/div'.$gt.$lt.'div style="height: 38px; position: absolute; top: 0px; left: 0px; width: 100%; z-index: 5; line-height: 38px; font-size: 30px; text-align: center; box-sizing: content-box;"'.$gt.'\'+percent+\'%'.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; right: 10px; z-index: 5; line-height: 16px;" align="right"'.$gt.'\'+(dirs-sdir)+" Folder"+((dirs-sdir)==1?"":"s")+" Remaining'.$lt.'br /'.$gt.'"+timeRemaining+" Remaining'.$lt.'/div'.$gt.$lt.'/div'.$gt.'";
934 document.getElementById("status_bar").innerHTML = divHTML;
935 document.getElementById("status_text").innerHTML = title;
936 dis="none";
937 divHTML = \''.$lt.'ul style="float: right; margin: 0 20px; text-align: right;"'.$gt.'\';
938 /*'.$lt.'!--*'.'/';
939 $MAX = 0;
940 $vars = "var i, intrvl, direrrors=0";
941 $fix_button_js = "";
942 $found = "";
943 $li_js = "return false;";
944 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Quick Scan") {
945 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
946 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
947 if ($check != "potential")
948 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $check;
949 }
950 if (!(isset($GLOBALS["GOTMLS"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["log"]["settings"]["check"])))
951 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
952 foreach ($scan_groups as $scan_name => $scan_group) {
953 if ($MAX++ == 6) {
954 $quarantineCountOnly = GOTMLS_get_quarantine(true);
955 $vars .= ", $scan_group=$quarantineCountOnly";
956 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0)\n\t\tscan_state = ' potential'; \n\telse\n\t\tscan_state = '';\n\tdivHTML += '</ul><ul style=\"text-align: left;\"><li class=\"GOTMLS_li\"><a href=\"admin.php?page=GOTMLS_View_Quarantine\" class=\"GOTMLS_plugin".("'+scan_state+'\" title=\"".GOTMLS_strip4java(GOTMLS_View_Quarantine_LANGUAGE))."\">'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
957 $found = "Found ";
958 $fix_button_js = "\n\t\tdis='block';";
959 } else {
960 $val = 0;
961 if ($MAX > 8 && !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
962 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("Directory Scan Depth set to 0, no files will be scanned for this type of threat!",'gotmls'));
963 elseif ($found && !in_array($scan_group, $GLOBALS["GOTMLS"]["log"]["settings"]["check"]))
964 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("You are not currently scanning for this type of threat!",'gotmls'));
965 else
966 $potential_threat = "";
967 $vars .= ", $scan_group=$val";
968 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0) {\n\t\tscan_state = ' href=\"#found_$scan_group\" onclick=\"$li_js showhide(\\'found_$scan_group\\', true);\" class=\"GOTMLS_plugin $scan_group\"';$fix_button_js".($MAX>6?"\n\tshowhide('found_$scan_group', true);":"")."\n\t} else\n\t\tscan_state = ' class=\"GOTMLS_plugin$potential_threat\"';\n\tdivHTML += '<li class=\"GOTMLS_li\"".(($found && $scan_group == "potential" && !in_array($scan_group, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))?' style="display: none;"':"")."><a'+scan_state+'>$found'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
969 }
970 $li_js = "";
971 if ($MAX > 11)
972 $fix_button_js = "";
973 }
974 $ScanSettings = $lt.'div style="float: right;"'.$gt.GOTMLS_Run_Quick_Scan_LANGUAGE.":&nbsp;$QuickScan$lt/div$gt".GOTMLS_Scan_Settings_LANGUAGE;
975 echo "/*--{$gt}*".'/
976 document.getElementById("status_counts").innerHTML = divHTML+"'.$lt.'/ul'.$gt.'";
977 document.getElementById("fix_button").style.display = dis;
978 }
979 '.$vars.';
980 function showOnly(what) {
981 document.getElementById("only_what").innerHTML = document.getElementById("only"+what).innerHTML;
982 }
983 var startTime = 0;
984 '.$lt.'/script'.$gt.GOTMLS_box($ScanSettings, $scan_opts);
985 $Settings_Saved = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -50px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";//script type='text/javascript'$gt\nalert('Settings Saved!');\n$lt/script$gt\n";
986 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Save") {
987 if ($GOTMLS_nonce_found) {
988 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
989 echo $Settings_Saved;
990 } else
991 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Saving these settings requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
992 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scanlog());
993 } elseif (isset($_REQUEST["scan_what"]) && is_numeric($_REQUEST["scan_what"]) && ($_REQUEST["scan_what"] > -1)) {
994 if ($GOTMLS_nonce_found) {
995 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
996 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
997 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
998 $cleadCache = false;
999 if (function_exists('is_plugin_active')) {
1000 if (function_exists('wp_cache_clear_cache')) {
1001 wp_cache_clear_cache();
1002 $cleadCache = true;
1003 }
1004 if (function_exists('w3tc_pgcache_flush')) {
1005 w3tc_pgcache_flush();
1006 $cleadCache = true;
1007 }
1008 if (class_exists('WpFastestCache')) {
1009 $newCache = new WpFastestCache();
1010 $newCache->deleteCache();
1011 $cleadCache = true;
1012 }
1013
1014 }
1015 if ($cleadCache)
1016 str_replace("Settings Saved!", "Cache Cleared and Settings Saved!", $Settings_Saved);
1017 echo $Settings_Saved;
1018 if (!isset($_REQUEST["scan_type"]))
1019 $_REQUEST["scan_type"] = "Complete Scan";
1020 elseif ($_REQUEST["scan_type"] == "Quick Scan") {
1021 $li_js = "\nfunction testComplete() {\n\tif (percent != 100)\n\t\talert('".__("The Quick Scan was unable to finish because of a shortage of memory or a problem accessing a file. Please try using the Complete Scan, it is slower but it will handle these errors better and continue scanning the rest of the files.",'gotmls')."');\n}\nwindow.onload=testComplete;\n$lt/script$gt\n$lt".'script type="text/javascript"'.$gt;
1022 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
1023 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1024 if ($check != "potential")
1025 $GLOBALS["GOTMLS"]["log"]["settings"]["check"][] = $check;
1026 }
1027 $_SERVER_QUERY_STRING = "?";
1028 foreach ($_GET as $name => $value) {
1029 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1030 if (is_array($value)) {
1031 foreach ($value as $val)
1032 $_SERVER_QUERY_STRING .= rawurlencode($name).'[]='.rawurlencode($val).'&';
1033 } else
1034 $_SERVER_QUERY_STRING .= rawurlencode($name).'='.rawurlencode($value).'&';
1035 }
1036 }
1037 echo "\n$lt".'form method="POST" action="'.admin_url("admin-ajax.php$_SERVER_QUERY_STRING").'" target="GOTMLS_iFrame" name="GOTMLS_Form_clean"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."1049")).'"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_fix"'.$gt.$lt.'input type="hidden" id="GOTMLS_fixing" name="GOTMLS_fixing" value="1"'.$gt;
1038 foreach ($_POST as $name => $value) {
1039 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1040 if (is_array($value)) {
1041 foreach ($value as $val)
1042 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'[]" value="'.GOTMLS_htmlspecialchars($val).'"'.$gt;
1043 } else
1044 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'" value="'.GOTMLS_htmlspecialchars($value).'"'.$gt;
1045 }
1046 }
1047 echo "\n$lt".'script type="text/javascript"'.$gt.'showhide("inside_'.md5($ScanSettings).'");'.$lt.'/script'.$gt.GOTMLS_box(GOTMLS_htmlspecialchars($_REQUEST["scan_type"]).' Status', $lt.'div id="status_text"'.$gt.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="..."'.$gt.' '.GOTMLS_Loading_LANGUAGE.$lt.'/div'.$gt.$lt.'div id="status_bar"'.$gt.$lt.'/div'.$gt.$lt.'p id="pause_button" style="display: none; position: absolute; left: 0; text-align: center; margin-left: -30px; padding-left: 50%;"'.$gt.$lt.'input type="button" value="Pause" class="button-primary" onclick="pauseresume(this);" id="resume_button" /'.$gt.$lt.'/p'.$gt.$lt.'div id="status_counts"'.$gt.$lt.'/div'.$gt.$lt.'p id="fix_button" style="display: none; text-align: center;"'.$gt.$lt.'input id="repair_button" type="submit" value="'.GOTMLS_Automatically_Fix_LANGUAGE.'" class="button-primary" onclick="loadIframe(\'Examine Results\');" /'.$gt.$lt.'/p'.$gt);
1048 $scan_groups_UL = "";
1049 foreach ($scan_groups as $scan_name => $scan_group)
1050 $scan_groups_UL .= "\n{$lt}ul name=\"found_$scan_group\" id=\"found_$scan_group\" class=\"GOTMLS_plugin $scan_group\" style=\"background-color: #ccc; display: none; padding: 0;\"$gt{$lt}a class=\"rounded-corners\" name=\"link_$scan_group\" style=\"float: right; padding: 0 4px; margin: 5px 5px 0 30px; line-height: 16px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;\" href=\"#found_top\" onclick=\"showhide('found_$scan_group');\"{$gt}X$lt/a$gt{$lt}h3$gt$scan_name$lt/h3$gt\n".($scan_group=='potential'?$lt.'p'.$gt.' &nbsp; * '.__("NOTE: These are probably not malicious scripts (but it's a good place to start looking <u>IF</u> your site is infected and no Known Threats were found).",'gotmls').$lt.'/p'.$gt:($scan_group=='wp_core'?$lt.'p'.$gt.' &nbsp; * '.sprintf(__("NOTE: We have detected changes to the WordPress Core files on your site. This could be an intentional modification or the malicious work of a hacker. We can restore these files to their original state to preserve the integrity of your original WordPress %s installation.",'gotmls'), GOTMLS_wp_version).' (for more info '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-core-files/"'.$gt.__("read my blog",'gotmls').$lt.'/a'.$gt.').'.$lt.'/p'.$gt:$lt.'br /'.$gt)).$lt.'/ul'.$gt;
1051 if (!($dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + (INT) $_REQUEST["scan_what"])))))
1052 $dir = "/";
1053 GOTMLS_update_scan_log(array("scan" => array("dir" => $dir, "start" => time(), "type" => GOTMLS_sanitize($_REQUEST["scan_type"]))));
1054 echo GOTMLS_box($lt.'div id="GOTMLS_scan_dir" style="float: right;"'.$gt.'&nbsp;('.(isset($GLOBALS["GOTMLS"]["log"]["scan"]["dir"]) ? $GLOBALS["GOTMLS"]["log"]["scan"]["dir"] : "Unknown path").")&nbsp;$lt/div$gt".__("Scan Details:",'gotmls'), $scan_groups_UL);
1055 $no_flush_LANGUAGE = __("Not flushing OB Handlers: %s",'gotmls');
1056 if (isset($_REQUEST["no_ob_end_flush"]))
1057 echo GOTMLS_error_div(sprintf($no_flush_LANGUAGE, GOTMLS_htmlspecialchars(print_r(ob_list_handlers(), 1))));
1058 elseif (is_array($OB_handlers) && count($OB_handlers)) {
1059 // $GOTMLS_OB_handlers = get_option("GOTMLS_OB_handlers", array());
1060 foreach (array_reverse($OB_handlers) as $OB_handler) {
1061 if (isset($GOTMLS_OB_handlers[$OB_handler]) && $GOTMLS_OB_handlers[$OB_handler] == "no_end_flush")
1062 echo GOTMLS_error_div(sprintf($no_flush_LANGUAGE, GOTMLS_htmlspecialchars($OB_handler)));
1063 elseif (in_array($OB_handler, $OB_default_handlers)) {
1064 // $GOTMLS_OB_handlers[$OB_handler] = "no_end_flush";
1065 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1066 @ob_end_flush();
1067 // $GOTMLS_OB_handlers[$OB_handler] = "ob_end_flush";
1068 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1069 }
1070 }
1071 }
1072 @ob_start();
1073 echo "\n{$lt}script type=\"text/javascript\"$gt$li_js\n/*{$lt}!--*"."/";
1074 if (!(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])) {
1075 echo GOTMLS_return_threat("dirs", "wait", $dir).GOTMLS_update_status(sprintf(__("Preparing %s",'gotmls'), GOTMLS_replace_dirname($dir)), 0);//GOTMLS_return_threat("skipdirs", "blocked", $dir, GOTMLS_error_link("Directory Scan Depth set to 0, no files will be scanned!"));
1076 $GLOBALS["GOTMLS"]["tmp"]["scanfiles"][GOTMLS_encode($dir)] = GOTMLS_strip4java(GOTMLS_replace_dirname($dir));
1077 } elseif (is_dir($dir)) {
1078 $GOTMLS_dirs_at_depth[0] = 1;
1079 $GOTMLS_dir_at_depth[0] = 0;
1080 if (isset($_REQUEST['scan_only']) && is_array($_REQUEST['scan_only'])) {
1081 $GOTMLS_dirs_at_depth[0] += (count($_REQUEST['scan_only']) - 1);
1082 foreach ($_REQUEST['scan_only'] as $only_dir)
1083 if (is_dir(GOTMLS_trailingslashit($dir).$only_dir))
1084 GOTMLS_readdir(GOTMLS_trailingslashit($dir).$only_dir);
1085 } else
1086 GOTMLS_readdir($dir);
1087 } else
1088 echo GOTMLS_return_threat("errors", "blocked", $dir, GOTMLS_error_link("Not a valid directory!"));
1089 if ($_REQUEST["scan_type"] == "Quick Scan")
1090 echo GOTMLS_update_status(__("Completed!",'gotmls'), 100);
1091 else {
1092 echo GOTMLS_update_status(__("Starting Scan ...",'gotmls'));
1093 $DB_scan_JS = ", 'db_scan'";
1094 if (isset($GLOBALS["GOTMLS"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["log"]["settings"]["check"]) && in_array("db_scan", $GLOBALS["GOTMLS"]["log"]["settings"]["check"]))
1095 echo GOTMLS_return_threat("dirs", "wait", "db_scan");//.GOTMLS_update_status(__("Starting Database Scan ...",'gotmls'));
1096 else
1097 $DB_scan_JS = "";
1098 GOTMLS_flush('script');
1099 echo "/*--{$gt}*"."/\nvar scriptSRC = '".GOTMLS_admin_url('GOTMLS_scan', GOTMLS_set_nonce(__FUNCTION__."1110").'&mt='.$GLOBALS["GOTMLS"]["tmp"]["mt"].'&GOTMLS_scan=')."';\nvar scanfilesArKeys = new Array('".implode("','", array_keys($GLOBALS["GOTMLS"]["tmp"]["scanfiles"]))."'$DB_scan_JS);\nvar scanfilesArNames = new Array('Scanning ".implode("','Scanning ", $GLOBALS["GOTMLS"]["tmp"]["scanfiles"])."'".str_replace("db_scan", "Starting Database Scan ...", $DB_scan_JS).");".'
1100 var scanfilesI = 0;
1101 var stopScanning;
1102 var gotStuckOn = -1;
1103 function scanNextDir(gotStuck) {
1104 clearTimeout(stopScanning);
1105 if (gotStuck > -1) {
1106 gotStuck = gotStuckOn;
1107 if (scanfilesArNames[gotStuck].substr(0, 3) != "Re-" && scanfilesArNames[gotStuck].substr(0, 10) != "Got Stuck ") {
1108 if (scanfilesArNames[gotStuck].substr(0, 9) == "Checking ") {
1109 scanfilesArNames.push(scanfilesArNames[gotStuck]);
1110 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_skip_file[]="+encodeURIComponent(scanfilesArNames[gotStuck].substr(9)));
1111 } else {
1112 scanfilesArNames.push("Re-"+scanfilesArNames[gotStuck]);
1113 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_only_file=");
1114 }
1115 } else {
1116 var uri = scanfilesArKeys[gotStuck].split("&limit=", 2);
1117 var skipdir = (scanfilesArKeys[gotStuck]+"&").split("&",2);
1118 if (uri.length == 2) {
1119 var lim = (uri[1]+"&").split("&", 2);
1120 if (isNaN(lim[0]))
1121 lim[0] = 1024;
1122 else
1123 lim[0] = Math.round(lim[0]/2);
1124 scanfilesArKeys.push(uri[0]+"&limit="+lim[0]+"&"+lim[1]+"&GOTMLS_skip_dir="+skipdir[0]);
1125 } else {
1126 var lim = ["2048"];
1127 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&limit=2048&GOTMLS_skip_dir="+skipdir[0]);
1128 }
1129 scanfilesArNames.push("Got Stuck ("+lim[0]+") "+scanfilesArNames[gotStuck]);
1130 }
1131 }
1132 if (document.getElementById("resume_button").value != "Pause") {
1133 stopScanning=setTimeout(function() {scanNextDir(-1);}, 1000);
1134 startTime++;
1135 } else if (scanfilesI < scanfilesArKeys.length) {
1136 document.getElementById("status_text").innerHTML = scanfilesArNames[scanfilesI];
1137 var newscript = document.createElement("script");
1138 newscript.setAttribute("src", scriptSRC+scanfilesArKeys[scanfilesI]);
1139 divx = document.getElementById("found_scanned");
1140 if (divx)
1141 divx.appendChild(newscript);
1142 gotStuckOn = scanfilesI++;
1143 stopScanning=setTimeout(function() {scanNextDir(0);}, '.$GLOBALS["GOTMLS"]["tmp"]['execution_time'].'000);
1144 }
1145 }
1146 startTime = ('.ceil(time()-$GLOBALS["GOTMLS"]["log"]["scan"]["start"]).'+3);
1147 stopScanning=setTimeout(function() {scanNextDir(-1);}, 3000);
1148 function pauseresume(butt) {
1149 if (butt.value == "Resume")
1150 butt.value = "Pause";
1151 else
1152 butt.value = "Resume";
1153 }
1154 showhide("pause_button", true);'."\n/*{$lt}!--*"."/";
1155 }
1156 if (@ob_get_level()) {
1157 GOTMLS_flush('script');
1158 @ob_end_flush();
1159 }
1160 echo "/*--{$gt}*"."/\n$lt/script$gt$lt/form$gt";
1161 } else
1162 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Starting a Complete Scan requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1163 } else
1164 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scanlog());
1165 echo "\n$lt/div$gt$lt/div$gt$lt/div$gt";
1166 }
1167
1168 function GOTMLS_login_form($form_id = "loginform") {
1169 $sess = time();
1170 $ajaxURL = admin_url("admin-ajax.php?action=GOTMLS_logintime&GOTMLS_sess=");
1171 echo '<input type="hidden" name="sess_id" value="'.substr($sess, 4).'"><input type="hidden" id="offset_id" value="0" name="sess'.substr($sess, 4).'"><script type="text/javascript">'."\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_script = document.createElement('script');\nGOTMLS_login_script.src = '$ajaxURL'+GOTMLS_login_offset.getTime();\n\ndocument.head.appendChild(GOTMLS_login_script);\n</script>\n";//GOTMLS_login_script.onload = set_offset_id();
1172 }
1173 if (defined("GOTMLS_REQUEST_METHOD"))
1174 add_action("login_form", "GOTMLS_login_form");
1175
1176 function GOTMLS_ajax_logintime() {
1177 @header("Content-type: text/javascript");
1178 $sess = (false && isset($_GET["GOTMLS_sess"]) && is_numeric($_GET["GOTMLS_sess"])) ? GOTMLS_htmlspecialchars($_GET["sess"]) : time();
1179 die(((isset($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]) && $GLOBALS["GOTMLS"]["tmp"]["HeadersError"])?"\n//Header Error: ".GOTMLS_strip4java(GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["HeadersError"])):"")."\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_offset_start = GOTMLS_login_offset.getTime() - ".$sess."000;\nfunction set_offset_id() {\n\tGOTMLS_login_offset = new Date();\n\tif (form_login = document.getElementById('offset_id'))\n\t\tform_login.value = GOTMLS_login_offset.getTime() - GOTMLS_login_offset_start;\n\tsetTimeout(function() {set_offset_id();}, 15673);\n}\nset_offset_id();");
1180 }
1181
1182 function GOTMLS_ajax_lognewkey() {
1183 @header("Content-type: text/javascript");
1184 if (isset($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]) && $GLOBALS["GOTMLS"]["tmp"]["HeadersError"])
1185 echo "\n//Header Error: ".GOTMLS_strip4java(GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]));
1186 if (GOTMLS_get_nonce()) {
1187 if (isset($_POST["GOTMLS_installation_key"]) && ($_POST["GOTMLS_installation_key"] == GOTMLS_installation_key)) {
1188 $keys = GOTMLS_uckserialize(get_option('GOTMLS_Installation_Keys', array()));
1189 if (is_array($keys)) {
1190 $count = count($keys);
1191 if (!isset($keys[GOTMLS_installation_key]))
1192 $keys = array_merge($keys, array(GOTMLS_installation_key => GOTMLS_siteurl));
1193 } else
1194 $keys = array(GOTMLS_installation_key => GOTMLS_siteurl);
1195 update_option("GOTMLS_Installation_Keys", serialize($keys));
1196 die("\n//$count~".count($keys));
1197 } else
1198 die("\n//0");
1199 } else
1200 die(GOTMLS_Invalid_Nonce("\n//Log New Key Error: ")."\n");
1201 }
1202
1203 function GOTMLS_set_plugin_action_links($links_array, $plugin_file) {
1204 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * strlen($plugin_file))) && strlen($plugin_file) > 10)
1205 $links_array = array_merge(array('<a href="'.admin_url('admin.php?page=GOTMLS-settings').'">'.GOTMLS_Scan_Settings_LANGUAGE.'</a>'), $links_array);
1206 return $links_array;
1207 }
1208 add_filter("plugin_action_links", "GOTMLS_set_plugin_action_links", 1, 2);
1209
1210 function GOTMLS_set_plugin_row_meta($links_array, $plugin_file) {
1211 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * strlen($plugin_file))) && strlen($plugin_file) > 10)
1212 $links_array = array_merge($links_array, array('<a target="_blank" href="'.GOTMLS_plugin_home.'faqs/">FAQ</a>','<a target="_blank" href="'.GOTMLS_plugin_home.'support/">Support</a>','<a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span>Donate</a>'));
1213 return $links_array;
1214 }
1215 add_filter("plugin_row_meta", "GOTMLS_set_plugin_row_meta", 1, 2);
1216
1217 function GOTMLS_in_plugin_update_message($args) {
1218 $transient_name = 'GOTMLS_upgrade_notice_'.preg_replace('/[^0-9\.\_]/', "", $args["Version"].'_'.$args["new_version"]);
1219 if ((false === ($upgrade_notice = get_transient($transient_name))) && ($ret = GOTMLS_get_URL("https://plugins.svn.wordpress.org/gotmls/trunk/readme.txt"))) {
1220 $upgrade_notice = '';
1221 if ($match = preg_split('/==\s*Upgrade Notice\s*==\s+/i', $ret)) {
1222 if (preg_match('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]))
1223 $notice = (array) preg_split('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]);
1224 else
1225 $notice = (array) preg_split('/\n+=/is', $match[1]."\n=");
1226 if (preg_match_all('/=\s*([\.0-9]+)\s*=\s*([^=]+)/i', $notice[0], $matches, PREG_SET_ORDER)) {
1227 foreach ($matches as $m)
1228 $upgrade_notice .= GOTMLS_html_tags(array('br /' => array('span' => GOTMLS_html_tags(array('b' => esc_html($m[1]).':')).esc_html($m[2]))));
1229 set_transient($transient_name, $upgrade_notice, DAY_IN_SECONDS);
1230 }
1231 }
1232 }
1233 echo wp_kses($upgrade_notice, array('br' => array(), 'span' => array(), 'b' => array()));
1234 }
1235 add_action("in_plugin_update_message-gotmls/index.php", "GOTMLS_in_plugin_update_message");
1236
1237 function GOTMLS_debug_hook($function) {
1238 return "\n<!-- Debugging $function (".round(microtime(true)-$GLOBALS["GOTMLS"]["MT"], 4).") -->\n";
1239 }
1240
1241 function GOTMLS_begin_wp_body_open() {
1242 return GOTMLS_debug_hook(__FUNCTION__);
1243 }
1244 function GOTMLS_finish_wp_body_open() {
1245 return GOTMLS_debug_hook(__FUNCTION__);
1246 }
1247 function GOTMLS_begin_wp_head() {
1248 echo GOTMLS_debug_hook(__FUNCTION__);
1249 }
1250 function GOTMLS_finish_wp_head() {
1251 echo GOTMLS_debug_hook(__FUNCTION__);
1252 }
1253 function GOTMLS_begin_wp_footer() {
1254 echo GOTMLS_debug_hook(__FUNCTION__);
1255 }
1256 function GOTMLS_finish_wp_footer() {
1257 echo GOTMLS_debug_hook(__FUNCTION__);
1258 }
1259
1260 if (isset($_REQUEST["eli"]) && ($_REQUEST["eli"] == "debug")) {
1261 foreach (array('wp_head', 'wp_body_open', 'wp_footer') as $wp_hook) {
1262 if (function_exists("GOTMLS_begin_$wp_hook"))
1263 add_action($wp_hook, "GOTMLS_begin_$wp_hook", 0);
1264 if (function_exists("GOTMLS_finish_$wp_hook"))
1265 add_action($wp_hook, "GOTMLS_finish_$wp_hook", 999999);
1266 }
1267 }
1268
1269 function GOTMLS_admin_init() {
1270 GOTMLS_define("GOTMLS_get_version_URL", GOTMLS_get_version("URL"));
1271 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]))
1272 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = 2;
1273 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
1274 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = -1;
1275 if (isset($_REQUEST["scan_type"]) && ($_REQUEST["scan_type"] == "Quick Scan")) {
1276 if (!isset($_REQUEST["scan_what"])) $_REQUEST["scan_what"] = 2;
1277 if (!isset($_REQUEST["scan_depth"]))
1278 $_REQUEST["scan_depth"] = 2;
1279 if (!isset($_REQUEST["scan_only"]))
1280 $_REQUEST["scan_only"] = array("","wp-includes","wp-admin");
1281 if ($_REQUEST["scan_only"] && !is_array($_REQUEST["scan_only"]))
1282 $_REQUEST["scan_only"] = array($_REQUEST["scan_only"]);
1283 }
1284 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]))
1285 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = "";
1286 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]) && is_numeric($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1287 $scan_level = intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);
1288 else
1289 $scan_level = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1290 $ajax_functions = array('load_update', 'log_session', 'empty_trash', 'fix', 'logintime', 'lognewkey', 'position', 'scan', 'View_Quarantine', 'whitelist');
1291 if (GOTMLS_get_nonce()) {
1292 if (isset($_REQUEST["dont_check"]) && is_array($_REQUEST["dont_check"]) && count($_REQUEST["dont_check"]))
1293 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = GOTMLS_sanitize($_REQUEST["dont_check"]);
1294 elseif (isset($_POST["scan_type"]) || !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])))
1295 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = array();
1296 if (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"]))
1297 $scan_level = intval($_POST["scan_level"]);
1298 if (isset($scan_level) && is_numeric($scan_level))
1299 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = intval($scan_level);
1300 foreach ($ajax_functions as $ajax_function) {
1301 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1302 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1303 }
1304 } elseif (GOTMLS_user_can()) {
1305 foreach ($ajax_functions as $ajax_function) {
1306 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1307 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", "GOTMLS_ajax_nopriv");
1308 }
1309 } else {
1310 foreach ($ajax_functions as $ajax_function) {
1311 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_nopriv");
1312 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", substr($ajax_function, 0, 1) == "l"?"GOTMLS_ajax_$ajax_function":"GOTMLS_ajax_nopriv");
1313 }
1314 }
1315 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1316 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1317 }
1318 add_action("admin_init", "GOTMLS_admin_init");
1319
1320 function GOTMLS_init() {
1321 register_post_type(
1322 'gotmls_quarantine',
1323 array(
1324 'labels' => array(
1325 'name' => _x( 'Quarantine', 'post type general name' ),
1326 'singular_name' => _x( 'Quarantine', 'post type singular name' ),
1327 'view_item' => __( 'View Quarantine Record' ),
1328 'all_items' => __( 'All Quarantine Records' ),
1329 ),
1330 'public' => false,
1331 'map_meta_cap' => true,
1332 'hierarchical' => false,
1333 'rewrite' => false,
1334 'query_var' => false,
1335 'can_export' => false,
1336 'delete_with_user' => false,
1337 'supports' => array( 'title', 'author', 'editor', 'excerpt', 'custom-fields' ),
1338 'capability_type' => 'customize_gotmls_quarantine',
1339 'capabilities' => array(
1340 'create_posts' => 'customize',
1341 'delete_others_posts' => 'customize',
1342 'delete_post' => 'customize',
1343 'delete_posts' => 'customize',
1344 'delete_private_posts' => 'customize',
1345 'delete_published_posts' => 'do_not_allow',
1346 'edit_others_posts' => 'do_not_allow',
1347 'edit_post' => 'do_not_allow',
1348 'edit_posts' => 'do_not_allow',
1349 'edit_private_posts' => 'do_not_allow',
1350 'edit_published_posts' => 'do_not_allow',
1351 'publish_posts' => 'customize',
1352 'read' => 'do_not_allow',
1353 'read_post' => 'do_not_allow',
1354 'read_private_posts' => 'customize',
1355 ),
1356 )
1357 );
1358 }
1359 add_action("init", "GOTMLS_init");
1360
1361 function GOTMLS_ajax_log_session() {
1362 header("Content-type: text/javascript");
1363 if (is_file(GOTMLS_plugin_path."safe-load/session.php"))
1364 require_once(GOTMLS_plugin_path."safe-load/session.php");
1365 if (isset($_SESSION["GOTMLS_SESSION_TEST"]))
1366 die("/* GOTMLS SESSION PASS */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nshowhide('GOTMLS_patch_searching', true);\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_patch_searching');\n\tshowhide('GOTMLS_patch_button', true);\n}\n");
1367 else {
1368 $_SESSION["GOTMLS_SESSION_TEST"] = 1;
1369 if (isset($_GET["SESSION"]) && is_numeric($_GET["SESSION"]) && $_GET["SESSION"] > 0)
1370 die("/* GOTMLS SESSION FAIL */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\ndocument.getElementById('GOTMLS_patch_searching').innerHTML = '<div class=\"error\">".GOTMLS_strip4java(__("Your Server could not start a Session!",'gotmls'))."</div>';");
1371 else
1372 die("/* GOTMLS SESSION TEST */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nstopCheckingSession = checkupdateserver('".GOTMLS_script_URI."&SESSION=1');");
1373 }
1374 }
1375
1376 function GOTMLS_ajax_position() {
1377 if (GOTMLS_get_nonce()) {
1378 $GLOBALS["GOTMLS_msg"] = __("Default position",'gotmls');
1379 $properties = array("body" => 'style="margin: 0; padding: 0;"');
1380 if (isset($_GET["GOTMLS_msg"]) && $_GET["GOTMLS_msg"] == $GLOBALS["GOTMLS_msg"]) {
1381 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"] = $GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"];
1382 $gl = '><';
1383 $properties["html"] = $gl.'head'.$gl.'script type="text/javascript">
1384 if (curDiv = window.parent.document.getElementById("div_file")) {
1385 curDiv.style.left = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0].'";
1386 curDiv.style.top = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1].'";
1387 curDiv.style.height = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2].'";
1388 curDiv.style.width = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3].'";
1389 }
1390 </script'.$gl.'/head';
1391 } elseif (isset($_GET["GOTMLS_x"]) || isset($_GET["GOTMLS_y"]) || isset($_GET["GOTMLS_h"]) || isset($_GET["GOTMLS_w"])) {
1392 if (isset($_GET["GOTMLS_x"]))
1393 GOTMLS_validate_position(0, $_GET["GOTMLS_x"]);
1394 if (isset($_GET["GOTMLS_y"]))
1395 GOTMLS_validate_position(1, $_GET["GOTMLS_y"]);
1396 if (isset($_GET["GOTMLS_h"]))
1397 GOTMLS_validate_position(2, $_GET["GOTMLS_h"]);
1398 if (isset($_GET["GOTMLS_w"]))
1399 GOTMLS_validate_position(3, $_GET["GOTMLS_w"]);
1400 $_GET["GOTMLS_msg"] = __("New position",'gotmls');
1401 } else
1402 die("\n//Position Error: No new position to save!\n");
1403 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1404 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_htmlentities($_GET["GOTMLS_msg"]).' '.__("saved.",'gotmls').(implode($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"]) == implode($GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"])?"":' <a href="'.GOTMLS_admin_url('GOTMLS_position', GOTMLS_set_nonce(__FUNCTION__."1448").'&GOTMLS_msg='.GOTMLS_esc_url($GLOBALS["GOTMLS_msg"])).'">['.$GLOBALS["GOTMLS_msg"].']</a>'))), $properties));
1405 } else
1406 die(GOTMLS_Invalid_Nonce("\n//Position Error: ")."\n");
1407 }
1408
1409 function GOTMLS_validate_position($vector, $position) {
1410 if (preg_match('/^[0-9]+px$/', $position)) {
1411 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][$vector] = $position;
1412 return true;
1413 } else
1414 return false;
1415 }
1416
1417 function GOTMLS_ajax_empty_trash() {
1418 global $wpdb;
1419 $gl = '><';
1420 $action = array("RESTORE" => "UPDATE $wpdb->posts SET `post_status` = 'private'", "DELETE" => "DELETE FROM $wpdb->posts");
1421 if (GOTMLS_get_nonce() && isset($_REQUEST["alter"]) && isset($action[$_REQUEST["alter"]])) {
1422 if ($trashed = $wpdb->query($action[$_REQUEST["alter"]]." WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) {
1423 $wpdb->query("REPAIR TABLE $wpdb->posts");
1424 $trashmsg = sprintf(__("%s %d item from the quarantine trash.",'gotmls'), strtoupper(GOTMLS_sanitize($_REQUEST["alter"])."d"), (INT) $trashed);
1425 } else
1426 $trashmsg = __("Failed to empty the trash.",'gotmls');
1427 } else
1428 $trashmsg = GOTMLS_Invalid_Nonce("");
1429 $properties = array("html" => $gl.'head'.$gl."script type='text/javascript'>\nalert('".GOTMLS_strip4java($trashmsg)."');\nif (curDiv = window.parent)\n\tcurDiv.location.reload(false);\nelse\n\twindow.opener.location.reload(false);</script$gl/head", "body" => 'style="margin: 0; padding: 0;"');
1430 die(GOTMLS_html_tags(array("html" => array("body" => $trashmsg)), $properties));
1431 }
1432
1433 function GOTMLS_ajax_whitelist() {
1434 if (GOTMLS_get_nonce()) {
1435 if (isset($_POST['GOTMLS_whitelist']) && isset($_POST['GOTMLS_chksum'])) {
1436 $file = GOTMLS_decode($_POST['GOTMLS_whitelist']);
1437 $chksum = explode("O", $_POST['GOTMLS_chksum']."O");
1438 if (strlen($chksum[0]) == 32 && strlen($chksum[1]) == 32 && is_file($file) && md5(@file_get_contents($file)) == $chksum[0]) {
1439 $filesize = @filesize($file);
1440 if (true) {
1441 if (!isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][0]))
1442 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][0] = "A0002";
1443 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file][$chksum[0].'O'.$filesize] = "A0002";
1444 } else
1445 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"][$file]);
1446 GOTMLS_update_option("definitions", $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]);
1447 $body = "Added $file to Whitelist!<br />\n<iframe style='width: 90%; height: 250px; border: none;' src='".GOTMLS_plugin_home."whitelist.html?whitelist=".GOTMLS_htmlspecialchars($_POST['GOTMLS_whitelist'])."&hash=$chksum[0]&size=$filesize&key=$chksum[1]'></iframe>";
1448 } else
1449 $body = "<li>Invalid Data!</li>";
1450 die(GOTMLS_html_tags(array("html" => array("body" => $body))));
1451 } else
1452 die("\n//Whitelist Error: Invalid checksum!\n");
1453 } else
1454 die(GOTMLS_Invalid_Nonce("\n//Whitelist Error: ")."\n");
1455 }
1456
1457 function GOTMLS_ajax_fix() {
1458 global $wpdb;
1459 if (GOTMLS_get_nonce()) {
1460 if (isset($_POST["GOTMLS_fix"]) && !is_array($_POST["GOTMLS_fix"]))
1461 $_POST["GOTMLS_fix"] = array($_POST["GOTMLS_fix"]);
1462 if (isset($_REQUEST["GOTMLS_fix"]) && is_array($_REQUEST["GOTMLS_fix"]) && isset($_REQUEST["GOTMLS_fixing"]) && $_REQUEST["GOTMLS_fixing"]) {
1463 GOTMLS_update_scan_log(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1464 $callAlert = "clearTimeout(callAlert);\ncallAlert=setTimeout(function() {alert_repaired(1);}, 30000);";
1465 $li_js = "\n<script type=\"text/javascript\">\nscanned = 0;\nvar callAlert;\nfunction alert_repaired(failed) {\nclearTimeout(callAlert);\nif (failed)\nfilesFailed='the rest, try again to change more.';\nwindow.parent.check_for_donation('Fixed '+filesFixed+' files, failed to fix '+filesFailed);\n}\n$callAlert\nwindow.parent.showhide('GOTMLS_iFrame', true);\nfilesFixed=0;\nfilesFailed=0;\nfunction fixedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file))\n\tli_file.className='GOTMLS_plugin';\nif (li_file = window.parent.document.getElementById('GOTMLS_quarantine_'+file)) {\n\tli_file.style.display='none';\n\tli_file.innerHTML='';\n\t}\n}\nfunction DeletedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file)) {\n\tli_file.className='GOTMLS_plugin';\n\tif (true || !isNaN(file)) {\n\t\tli_file = li_file.parentNode".(isset($_REQUEST["GOTMLS_fix"][0]) && is_numeric($_REQUEST["GOTMLS_fix"][0])?'.parentNode':'').";\n\t\tli_file.style.display='none';\n\t\tli_file.innerHTML='';\n}}}\nfunction failedFile(file) {\n filesFailed++;\nwindow.parent.document.getElementById('check_'+file).checked=false; \n}\n</script>\n<script type=\"text/javascript\">\n/*<!--*"."/";
1466 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] * 2);
1467 $HTML_safe = explode("split-here-for-content", GOTMLS_html_tags(array("html" => array("body" => "split-here-for-content"))));
1468 echo $HTML_safe[0];
1469 GOTMLS_update_scan_log(array("scan" => array("dir" => count($_REQUEST["GOTMLS_fix"])." Files", "start" => time())));
1470 foreach ($_REQUEST["GOTMLS_fix"] as $clean_file) {
1471 if (is_numeric($clean_file)) {
1472 if (($Q_post = GOTMLS_get_quarantine($clean_file)) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine" && isset($Q_post["post_status"])) {
1473 $safe_path = esc_html($Q_post["post_title"]);
1474 if ($_REQUEST["GOTMLS_fixing"] > 1) {
1475 echo sprintf(__("<li>Removing %s ... ",'gotmls'), $safe_path);
1476 $Q_post["post_status"] = "trash";
1477 if (wp_update_post($Q_post)) {
1478 echo __("Done!",'gotmls');
1479 $li_js .= "/*-->*"."/\nDeletedFile('$clean_file');\n/*<!--*"."/";
1480 } else {
1481 echo __("Failed to remove!",'gotmls');
1482 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1483 }
1484 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Removal from Quarantine")));
1485 } else {
1486 $Q_post["post_status"] = "pending";
1487 $part = explode(":", $Q_post["post_title"].':');
1488 if (count($part) > 2 && is_numeric($part[1])) {
1489 if (!(substr($part[0], -7) == "options" && ($R_post = $wpdb->get_results("SELECT option_name, option_value FROM `$part[0]` WHERE option_id = ".(INT) $part[1], ARRAY_A)) && count($R_post)))
1490 $R_post = GOTMLS_get_quarantine($part[1]);
1491 if (isset($R_post["post_type"]) && strtolower($R_post["post_type"]) == $part[0]) {
1492 if (isset($_GET["eli"]) || ($R_post["post_content"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post["post_content"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1493 echo "<li>Restoring Post ID $part[1] ... ";
1494 $R_post["post_modified_gmt"] = $Q_post["post_modified"];
1495 $R_post["post_content"] = GOTMLS_decode($Q_post["post_content"]);
1496 if (wp_update_post($R_post)) {
1497 echo __("Complete!",'gotmls');
1498 wp_update_post($Q_post);
1499 $li_js .= "/*-->*"."/\nfixedFile('$clean_file');\n/*<!--*"."/";
1500 } else {
1501 echo __("Restoration of post_content Failed!",'gotmls');
1502 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1503 }
1504 } else {
1505 echo "<li>".__("Restoration Aborted, post_content was modified outside of this quarantine!<pre>".GOTMLS_htmlspecialchars(print_r(array("R"=>$R_post,"Q"=>$Q_post),1))."</pre>",'gotmls');
1506 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1507 }
1508 } elseif (isset($R_post[0]["option_name"]) && strtolower($R_post[0]["option_name"]) == strtolower(trim($part[2], "\" "))) {
1509 if (isset($_GET["eli"]) || ($R_post[0]["option_value"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post[0]["option_value"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1510 echo "<li>Restoring Option ID $part[1] ... ";
1511 if ($wpdb->update($part[0], array("option_value" => GOTMLS_decode($Q_post["post_content"])), array("option_id" => $part[1]))) {
1512 echo __("Complete!",'gotmls');
1513 wp_update_post($Q_post);
1514 $li_js .= "/*-->*"."/\nfixedFile('$clean_file');\n/*<!--*"."/";
1515 } else {
1516 echo __("Restoration of option_value Failed!<pre>".GOTMLS_htmlspecialchars(print_r(array("part"=>$part,"error"=>$wpdb->last_error),1))."</pre>",'gotmls');
1517 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1518 }
1519 } else {
1520 echo "<li>".__("Restoration Aborted, option_value was modified outside of this quarantine!<pre>".GOTMLS_htmlspecialchars(print_r(array(GOTMLS_decode($Q_post["post_content_filtered"]) => $R_post[0]["option_value"], "R"=>$R_post[0],"Q"=>$Q_post),1))."</pre>",'gotmls');
1521 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1522 }
1523 } else {
1524 echo "<li>".__("Restore Failed!<pre>".GOTMLS_htmlspecialchars(print_r(array('$part' => $part, "R"=>$R_post,"Q"=>$Q_post),1))."</pre>",'gotmls');
1525 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1526 }
1527 } elseif (isset($_GET["eli"]) || is_file($safe_path)) {
1528 echo sprintf(__("<li>Restoring %s ... ",'gotmls'), $safe_path);
1529 if (GOTMLS_file_put_contents($safe_path, GOTMLS_decode($Q_post["post_content"])) && wp_update_post($Q_post)) {
1530 echo __("Complete!",'gotmls');
1531 $li_js .= "/*-->*"."/\nfixedFile('$clean_file');\n/*<!--*"."/";
1532 } else {
1533 echo __("Restore Failed!",'gotmls');
1534 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1535 }
1536 } else {
1537 echo "<li>".sprintf(__("Restoration Aborted, file %s does not exist!",'gotmls'), $safe_path);
1538 $li_js .= "/*-->*"."/\nfailedFile('$clean_file');\n/*<!--*"."/";
1539 }
1540 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Restoration from Quarantine")));
1541 }
1542 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n</script>\n";
1543 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1544 }
1545 } elseif (is_numeric($decoded_file = GOTMLS_decode($clean_file))) {
1546 $li_js .= GOTMLS_db_scan($decoded_file);
1547 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n</script>\n";
1548 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1549 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "DB Fix")));
1550 } else {
1551 $safe_path = esc_html(realpath($decoded_file = GOTMLS_decode($clean_file)));
1552 if (is_file($safe_path)) {
1553 echo sprintf(__("<li>Fixing %s ... ",'gotmls'), $safe_path);
1554 $li_js .= GOTMLS_scanfile($safe_path);
1555 echo "</li>\n$li_js/*-->*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n</script>\n";
1556 $li_js = "<script type=\"text/javascript\">\n/*<!--*"."/";
1557 } else
1558 echo "<li>".sprintf(__("File %s not found!",'gotmls'), $safe_path)."</li>";
1559 GOTMLS_update_scan_log(array("scan" => array("finish" => time(), "type" => "Automatic Fix")));
1560 }
1561 }
1562 $nonce = GOTMLS_set_nonce(__FUNCTION__."1588");
1563 die('<div id="check_site_warning" style="background-color: #F00;">'.sprintf(__("Because some changes were made we need to check to make sure it did not break your site. If this stays Red and the frame below does not load please <a %s>revert the changes</a> made during this automated fix process.",'gotmls'), 'href="'.GOTMLS_images_path.'?page=GOTMLS_View_Quarantine&'.$nonce.'"').' <span style="color: #F00;">'.__("Never mind, it worked!",'gotmls').'</span></div><br /><iframe id="test_frame" name="test_frame" src="'.GOTMLS_admin_url('GOTMLS_View_Quarantine', 'check_site=1&'.$nonce).'" style="width: 100%; height: 200px"></iframe>'.$li_js."/*-->*"."/\nalert_repaired(0);\n</script>\n$HTML_safe[1]");
1564 } else
1565 die(GOTMLS_html_tags(array("html" => array("body" => "<script type=\"text/javascript\">\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".__("Nothing Selected to be Changed!",'gotmls')."');\n</script>".__("Done!",'gotmls')))));
1566 } else
1567 die(GOTMLS_html_tags(array("html" => array("body" => "<script type=\"text/javascript\">\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".GOTMLS_Invalid_Nonce("")."');\n</script>".__("Done!",'gotmls')))));
1568 }
1569
1570 function GOTMLS_ajax_scan() {
1571 if (GOTMLS_get_nonce()) {
1572 @error_reporting(0);
1573 if (isset($_GET["GOTMLS_scan"])) {
1574 $script_form = GOTMLS_html_tags(array("script" => GOTMLS_js_text_range())).'<table style="top: 0px; left: 0px; width: 100%; height: 100%; position: absolute;"><tr><td style="width: 100%">';
1575 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] - 5);
1576 if (is_numeric($_GET["GOTMLS_scan"])) {
1577 if (($Q_post = GOTMLS_get_quarantine((INT) $_GET["GOTMLS_scan"])) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine") {
1578 GOTMLS_load_contents(GOTMLS_decode($Q_post["post_content"]));
1579 GOTMLS_view_details($Q_post, '<form style="margin: 0;" method="post" action="'.admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."1605")).'" onsubmit="return confirm(\''.__("Are you sure you want to delete the record of this file from the quarantine?",'gotmls').'\');"><input type="hidden" name="GOTMLS_fix[]" value="'.$Q_post["ID"].'"><input type="hidden" name="GOTMLS_fixing" value="2"><input type="hidden" name="action" value="GOTMLS_fix"><input type="submit" value="DELETE from Quarantine" style="display: none; background-color: #C00; float: right;"></form>');
1580 } else
1581 die(GOTMLS_html_tags(array("html" => array("body" => __("This record no longer exists in the quarantine.",'gotmls')."<br />\n<script type=\"text/javascript\">\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n</script>"))));
1582 } elseif (substr($_GET["GOTMLS_scan"]."1234567", 0, 7) == "db_scan") {
1583 @header("Content-type: text/javascript");
1584 if (isset($_GET["GOTMLS_only_file"])) {
1585 if (strlen($_GET["GOTMLS_only_file"])) {
1586 echo '//re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1587 die(GOTMLS_db_scan().'//END OF JavaScript');
1588 } else {
1589 echo '//re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1590 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1591 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1592 $path = "db_scan=$file";
1593 echo "/*-->*"."/\nscanfilesArKeys.push('db_scan&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*<!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1594 }
1595 }
1596 die(GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Database Scan ...",'gotmls'))."/*-->*"."/\nscanNextDir(-1);\n/*<!--*"."/");
1597 }
1598 } else {
1599 echo '//db_scan: '.gmdate("Y-m-d H:i:s\n");
1600 die(GOTMLS_db_scan().'//END OF JavaScript');
1601 }
1602 } else {
1603 $file = GOTMLS_decode($_GET["GOTMLS_scan"]);
1604 if (is_numeric($file))
1605 die("\n$script_form".GOTMLS_db_scan($file));
1606 elseif (substr($file."1234567", 0, 7) == "db_scan") {
1607 @header("Content-type: text/javascript");
1608 if (isset($_GET["GOTMLS_only_file"])) {
1609 if (strlen($_GET["GOTMLS_only_file"])) {
1610 echo '//encoded re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1611 die(GOTMLS_db_scan().'//END OF JavaScript');
1612 } else {
1613 echo '//encoded re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1614 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1615 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1616 $path = "db_scan=$file";
1617 echo "/*-->*"."/\nscanfilesArKeys.push('".GOTMLS_encode($dir)."&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*<!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1618 }
1619 }
1620 echo GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Encoded Database Scan ...",'gotmls'))."/*-->*"."/\nscanNextDir(-1);\n/*<!--*"."/";
1621 }
1622 } else {
1623 echo '//encoded db_scan: but no GOTMLS_only_file'.gmdate("Y-m-d H:i:s\n");
1624 die(GOTMLS_db_scan().'//END OF JavaScript');
1625 }
1626 } elseif (is_dir($file)) {
1627 @error_reporting(0);
1628 @header("Content-type: text/javascript");
1629 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))
1630 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
1631 @ob_start();
1632 echo GOTMLS_scandir($file);
1633 if (@ob_get_level()) {
1634 GOTMLS_flush();
1635 @ob_end_clean();//_flush();
1636 }
1637 die('//END OF JavaScript');
1638 } elseif (file_exists($file)) {
1639 GOTMLS_scanfile($file);
1640 if (function_exists("mb_detect_encoding")) {
1641 $en = mb_detect_encoding($GLOBALS["GOTMLS"]["tmp"]["file_contents"], $GLOBALS["GOTMLS"]["tmp"]["default_encodings"]);
1642 @header("Content-type: text/html; charset=$en");
1643 }
1644 echo "<html>\n<head>\n<title>Scan File: ".esc_html($file)."</title>\n</head>\n<body>";
1645 $fa = "";
1646 $f = 0;
1647 if (isset($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && count($GLOBALS["GOTMLS"]["tmp"]["threats_found"])) {
1648 $f = 1;
1649 foreach ($GLOBALS["GOTMLS"]["tmp"]["threats_found"] as $threats_found => $threats_name) {
1650 list($start, $end, $junk) = explode("-", "$threats_found--", 3);
1651 if ($start > $end)
1652 $fa .= 'ERROR['.($f++).']: Threat_size{'.$threats_found.'} Content_size{'.strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'}';
1653 else
1654 $fa .= ' <a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range(\'ta_file\', '.$start.', '.$end.');">['.$f++.']</a>';
1655 }
1656 } else
1657 $fa = " No Threats Found";
1658 die("\n$script_form".'<form style="margin: 0;'.(($f==0)?" display: none;":"").'" method="post" action="'.admin_url('admin-ajax.php').'" onsubmit="return confirm(\''.__("Are you sure this file is not infected and you want to ignore it in future scans?",'gotmls').'\');"><input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."1651")).'"><input type="hidden" name="GOTMLS_whitelist" value="'.GOTMLS_encode($file).'"><input type="hidden" name="action" value="GOTMLS_whitelist"><input type="hidden" name="GOTMLS_chksum" value="'.md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'O'.GOTMLS_installation_key.'"><input type="submit" value="Whitelist this file" style="float: right;"></form>'.GOTMLS_file_details($file).'<div style="overflow: auto;"><span onmouseover="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'block\';" onmouseout="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'none\';">'.__("Potential threats in file:",'gotmls').'</span> ('.$fa.' )</div></td></tr><tr><td style="height: 100%"><textarea id="ta_file" style="width: 100%; height: 100%">'.GOTMLS_htmlentities(str_replace("\r", "", $GLOBALS["GOTMLS"]["tmp"]["file_contents"])).'</textarea></td></tr></table>');
1659 } else {
1660 //@header("Content-type: text/javascript");
1661 die("// ERROR: ".sprintf(__("The file %s does not exist, it must have already been deleted.",'gotmls'), GOTMLS_htmlspecialchars($file))."<script type=\"text/javascript\">\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n//</script>");
1662 }
1663 }
1664 } else
1665 die("\n//Directory Error: Nothing to scan!\n");
1666 } else {
1667 if (isset($_GET["GOTMLS_scan"]) && is_dir(GOTMLS_decode($_GET["GOTMLS_scan"]))) {
1668 @header("Content-type: text/javascript");
1669 $alert = "if (is_button = document.getElementById('resume_button')) is_button.value = 'Resume'; alert('Invalid or expired Nonce Token! You probably need to restart the scan :-(');";
1670 } else
1671 $alert = "<script type='text/javascript'>if (xFrame = window.parent.document.getElementById('GOTMLS_iFrame')) xFrame.style.display = 'block'; alert('Invalid or expired Nonce Token! You probably need to restart the scan :-(');</script>";
1672 die(GOTMLS_Invalid_Nonce("$alert\n//Ajax Scan Nonce Error: ")."\n");
1673 }
1674 }
1675
1676 function GOTMLS_ajax_nopriv() {
1677 die("\n//Permission Error: User not authenticated!\n");
1678 }
1679