PluginProbe ʕ •ᴥ•ʔ
Anti-Malware Security and Brute-Force Firewall / 4.23.81
Anti-Malware Security and Brute-Force Firewall v4.23.81
4.23.90 trunk 1.2.03.23 1.3.02.15 3.07.06 4.14.47 4.15.16 4.16.17 4.17.28 4.17.29 4.17.44 4.17.57 4.17.58 4.17.68 4.17.69 4.18.52 4.18.62 4.18.63 4.18.69 4.18.71 4.18.74 4.18.76 4.19.44 4.19.50 4.19.68 4.19.69 4.20.59 4.20.72 4.20.92 4.20.93 4.20.94 4.20.95 4.20.96 4.21.74 4.21.83 4.21.84 4.21.85 4.21.86 4.21.87 4.21.88 4.21.89 4.21.90 4.21.91 4.21.92 4.21.93 4.21.94 4.21.95 4.21.96 4.23.56 4.23.57 4.23.67 4.23.68 4.23.69 4.23.71 4.23.73 4.23.77 4.23.81 4.23.83 4.23.85 4.23.87 4.23.88 4.23.89
gotmls / index.php
gotmls Last commit date
images 1 year ago languages 1 year ago safe-load 1 year ago index.php 1 year ago readme.txt 1 year ago
index.php
1911 lines
1 <?php
2 /*
3 Plugin Name: Anti-Malware Security and Brute-Force Firewall
4 Plugin URI: https://gotmls.net/
5 Author: Eli Scheetz
6 Text Domain: gotmls
7 Author URI: https://anti-malware.ninja/
8 Contributors: scheeeli, gotmls
9 Donate link: https://gotmls.net/donate/
10 Description: This Anti-Virus/Anti-Malware plugin searches for Malware and other Virus like threats and vulnerabilities on your server and helps you remove them. It's always growing and changing to adapt to new threats so let me know if it's not working for you.
11 License: GPLv3 or later
12 License URI: https://www.gnu.org/licenses/gpl-3.0.html#license-text
13 Version: 4.23.81
14 Requires PHP: 5.6
15 Requires CP: 1.1.1
16 */
17 if (isset($_SERVER["DOCUMENT_ROOT"]) && ($SCRIPT_FILE = str_replace($_SERVER["DOCUMENT_ROOT"], "", (isset($_SERVER["SCRIPT_FILENAME"])?$_SERVER["SCRIPT_FILENAME"]:(isset($_SERVER["SCRIPT_NAME"])?$_SERVER["SCRIPT_NAME"]:"")))) && strlen($SCRIPT_FILE) > strlen("/".basename(__FILE__)) && substr(__FILE__, -1 * strlen($SCRIPT_FILE)) == substr($SCRIPT_FILE, -1 * strlen(__FILE__)) || !(function_exists("add_action") && function_exists("load_plugin_textdomain")))
18 include(dirname(__FILE__)."/safe-load/index.php");
19 else
20 require_once(dirname(__FILE__)."/images/index.php");
21 /* ___
22 * / /\ GOTMLS Main Plugin File
23 * / /:/ @package GOTMLS
24 * /__/::\
25 Copyright \__\/\:\__ © 2012-2025 Eli Scheetz (email: eli@gotmls.net)
26 * \ \:\/\
27 * \__\::/ This program is free software; you can redistribute it
28 * ___ /__/:/ and/or modify it under the terms of the GNU General Public
29 * /__/\ _\__\/ License as published by the Free Software Foundation;
30 * \ \:\ / /\ either version 3 of the License, or (at your option) any
31 * ___\ \:\ /:/ later version.
32 * / /\\ \:\/:/
33 / /:/ \ \::/ This program is distributed in the hope that it will be useful,
34 / /:/_ \__\/ but WITHOUT ANY WARRANTY; without even the implied warranty
35 /__/:/ /\__ of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
36 \ \:\/:/ /\ See the GNU General Public License for more details.
37 \ \::/ /:/
38 \ \:\/:/ You should have received a copy of the GNU General Public License
39 * \ \::/ with this program; if not, write to the Free Software Foundation,
40 * \__\/ Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA */
41
42 function GOTMLS_install() {
43 if (strpos(GOTMLS_get_version("URL"), '&wp=') && version_compare(GOTMLS_wp_version, GOTMLS_require_version, "<"))
44 die(GOTMLS_htmlspecialchars(GOTMLS_require_version_LANGUAGE.", NOT version: ".GOTMLS_wp_version));
45 else
46 delete_option("GOTMLS_definitions_array");
47 }
48 register_activation_hook(__FILE__, "GOTMLS_install");
49
50 function GOTMLS_uninstall() {
51 delete_option('GOTMLS_get_URL_blob');
52 delete_option('GOTMLS_definitions_blob');
53 delete_option('GOTMLS_nonce_blob');
54 delete_option('GOTMLS_settings_array');
55 GOTMLS_create_session_file(false);
56 }
57 register_deactivation_hook(__FILE__, "GOTMLS_uninstall");
58
59 function GOTMLS_menu() {
60 if (GOTMLS_user_can()) {
61 $GLOBALS["GOTMLS"]["tmp"]["my_admin_page"] = add_menu_page($GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"], $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $GLOBALS["GOTMLS"]["tmp"]["base_page"], "GOTMLS_settings", GOTMLS_images_path.'GOTMLS-16x16.gif');
62 add_action('load-'.$GLOBALS["GOTMLS"]["tmp"]["my_admin_page"], 'GOTMLS_admin_add_help_tab');
63 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_Scan_Settings_LANGUAGE, GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $GLOBALS["GOTMLS"]["tmp"]["base_page"], "GOTMLS_settings");
64 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." Firewall Options", "Firewall Options", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS-Firewall-Options", "GOTMLS_Firewall_Options");
65 }
66 }
67 add_action("admin_menu", "GOTMLS_menu", 8);
68 add_action("network_admin_menu", "GOTMLS_menu", 8);
69
70 function GOTMLS_menu_Quarantine() {
71 if (GOTMLS_user_can() && isset($GLOBALS["GOTMLS"]["tmp"]["my_admin_page"]))
72 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_View_Quarantine_LANGUAGE, GOTMLS_View_Quarantine_LANGUAGE.(($Qs = GOTMLS_get_quarantine(true))?' <span class="awaiting-mod count-'.$Qs.'"><span class="awaiting-mod">'.$Qs.'</span></span>':""), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS_View_Quarantine", "GOTMLS_View_Quarantine");
73 }
74 add_action("admin_menu", "GOTMLS_menu_Quarantine", 16);
75 add_action("network_admin_menu", "GOTMLS_menu_Quarantine", 16);
76
77 function GOTMLS_admin_add_help_tab() {
78 $screen = get_current_screen();
79 $screen->add_help_tab(array(
80 'id' => "GOTMLS_Getting_Started",
81 'title' => __("Getting Started", 'gotmls'),
82 'content' => '<p>'.__("Make sure the Definition Updates are current and Run a Complete Scan.", 'gotmls').'</p><p>'.sprintf(__("If Known Threats are found and displayed in red then there will be a button to '%s'. If only Potentional Threats are found then there is no automatic fix because those are probably not malicious.", 'gotmls'), GOTMLS_Automatically_Fix_LANGUAGE).'</p><p>'.__("A backup of the original infected files are placed in the Quarantine in case you need to restore them or just want to look at them later. You can delete these files if you don't want to save more.", 'gotmls').'</p>'
83 ));
84 $FAQMarker = '== Frequently Asked Questions ==';
85 if (is_file(dirname(__FILE__).'/readme.txt') && ($readme = explode($FAQMarker, @file_get_contents(dirname(__FILE__).'/readme.txt').$FAQMarker)) && GOTMLS_strlen($readme[1]) && ($readme = explode("==", $readme[1]."==")) && GOTMLS_strlen($readme[0])) {
86 $screen->add_help_tab(array(
87 'id' => "GOTMLS_FAQs",
88 'title' => __("FAQs", 'gotmls'),
89 'content' => '<p>'.preg_replace('/\[(.+?)\]\((.+?)\)/', "<a target=\"_blank\" href=\"\\2\">\\1</a>", preg_replace('/[\r\n]+= /', "</p><b>", preg_replace('/ =[\r\n]+/', "</b><p>", $readme[0]))).'</p>'
90 ));
91 }
92 }
93
94 function GOTMLS_enqueue_scripts() {
95 wp_enqueue_style('dashicons');
96 }
97 add_action('admin_enqueue_scripts', 'GOTMLS_enqueue_scripts');
98
99 function GOTMLS_display_header($optional_box = "") {
100 global $current_user, $wpdb;
101 wp_get_current_user();
102 $head_nonce = GOTMLS_set_nonce(__FUNCTION__."100");
103 $GOTMLS_url_parts = explode('/', GOTMLS_siteurl);
104 $Update_Definitions = array(GOTMLS_update_home.'definitions.js'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"].'&'.GOTMLS_get_version_URL.'&'.GOTMLS_set_nonce(GOTMLS_update_home).'&d='.ur1encode(GOTMLS_siteurl));
105 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])
106 array_unshift($Update_Definitions, GOTMLS_admin_url('GOTMLS_load_update', $head_nonce.'&UPDATE_definitions_array=1'));
107 else
108 $Update_Definitions[] = GOTMLS_admin_url('GOTMLS_load_update', $head_nonce.'&UPDATE_definitions_array=1');
109 $Update_Link = '<div style="text-align: center;"><a href="';
110 $new_version = "";
111 $file = basename(GOTMLS_plugin_path).'/index.php';
112 $current = get_site_transient("update_plugins");
113 if (isset($current->response[$file]->new_version) && version_compare(GOTMLS_Version, $current->response[$file]->new_version, "<")) {
114 $new_version = sprintf(__("Upgrade to %s now!",'gotmls'), $current->response[$file]->new_version).'<br /><br />';
115 $Update_Link .= wp_nonce_url(self_admin_url('update.php?action=upgrade-plugin&plugin=').$file, 'upgrade-plugin_'.$file);
116 }
117 $Update_Link .= "\">$new_version</a></div>";
118 $defLatest = (is_numeric($Latest = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"]))) && is_numeric($Default = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Default"]))) && $Latest > $Default)?1:0;
119 if (is_array($keys = GOTMLS_uckserialize(get_option('GOTMLS_Installation_Keys', array()))) && isset($keys[GOTMLS_installation_key]))
120 $isRegistered = $keys[GOTMLS_installation_key];
121 else
122 $isRegistered = "";
123 $Update_Div ='<div id="findUpdates" style="display: none;"><center>'.__("Searching for updates ...",'gotmls').'<br /><img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /><br /><input type="button" value="Cancel" onclick="cancelserver(\'findUpdates\');" /></center></div>';
124 $php_version = "<li>PHP: <span class='GOTMLS_date'>".phpversion()."</span></li>\n";
125 if (isset($_SERVER["SERVER_SOFTWARE"]) && preg_match('/Apache\/([0-9\.]+)/i', $_SERVER["SERVER_SOFTWARE"], $GLOBALS["GOTMLS"]["tmp"]["apache"]) && count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
126 $php_version .= "<li>Apache: <span class='GOTMLS_date'>".$GLOBALS["GOTMLS"]["tmp"]["apache"][1]."</span></li>\n";
127 elseif (isset($_SERVER["SERVER_SOFTWARE"]) && GOTMLS_strlen($_SERVER["SERVER_SOFTWARE"]))
128 $php_version .= "<li>".esc_html($_SERVER["SERVER_SOFTWARE"])."</li>\n";
129 if ((isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)) {
130 $reg_email_key = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
131 $isRegistered = GOTMLS_get_registrant($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]);
132 } else
133 $reg_email_key = "";
134 echo GOTMLS_get_header().'
135 <div id="admin-page-container">
136 <div id="GOTMLS-right-sidebar" style="width: 300px;" class="metabox-holder">
137 '.GOTMLS_box(__("Updates & Registration",'gotmls'), "<ul>$php_version<li>".(function_exists('classicpress_version')?"ClassicPress: <span class='GOTMLS_date' title='CP: ".classicpress_version()."\nWP: ".GOTMLS_wp_version."'>".preg_replace( '#[+-].*$#', '', classicpress_version()):"WordPress: <span class='GOTMLS_date'>".GOTMLS_wp_version)."</span></li>\n<li>Plugin: <span class='GOTMLS_date'>".GOTMLS_Version.'</span></li>
138 <li><div id="GOTMLS_Key" style="margin: 0;'.((!$defLatest && !$isRegistered)?' display: none;">Key: <span style="float: right;">'.GOTMLS_installation_key.'</span></div><div style="':'">Key: <span style="float: right;" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">'.GOTMLS_installation_key.'</span></div><div style="display: none;').'"><form method="POST" action="'.admin_url('admin-ajax.php?'.$head_nonce).'" target="GOTMLS_iFrame" name="GOTMLS_Form_lognewkey"><input type="hidden" name="GOTMLS_installation_key" value="'.GOTMLS_installation_key.'"><input type="hidden" name="action" value="GOTMLS_lognewkey"><span style="color: #F00;" id="GOTMLS_No_Key">No Key! <input type="submit" style="float: right;" value="'.__("Get FREE Key!",'gotmls').'" class="button-primary" onclick="showhide(\'GOTMLS_No_Key\');showhide(\'GOTMLS_Key\', true);check_for_updates();" /></span></form></div></li>
139 <li>Definitions: <span id="GOTMLS_definitions_date" class="GOTMLS_date">'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"].'</span></li></ul>
140 <form id="updateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
141 <img style="display: none; float: left; margin-right: 4px;" src="'.GOTMLS_images_path.'checked.gif" height=16 width=16 alt="definitions updated" id="autoUpdateDownload" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">
142 '.str_replace('findUpdates', 'Definition_Updates', $Update_Div).'
143 <div id="autoUpdateForm" style="display: none;">
144 <input type="submit" style="width: 100%;" name="auto_update" value="'.__("Download new definitions!",'gotmls').'">
145 </div>
146 </form>
147 <form id="clearupdateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
148 <input name="UPDATE_definitions_array" value="D" type="hidden">
149 <input type="submit" style="display: none; width: 100%; color: #ff0; background-color: #c33" id="clear_updates" value="'.__("Delete ALL definitions!",'gotmls').'">
150 </form>
151 <div id="registerKeyForm" style="display: none;"><button onclick="force_update_check(500);" style="float: right;">Check Again</button><span id="registerFormMessage" style="color: #F00"><p>'.__("Get instant access to definition updates.",'gotmls').'</p></span><p>
152 '.__("If you have not already registered your Key then register now using the form below.<br />* All registration fields are required<br />** I will NOT share your information.",'gotmls').'</p>
153 <form id="registerform" onsubmit="return sinupFormValidate(this);" action="'.GOTMLS_plugin_home.'wp-login.php?action=register" method="post" name="registerform" target="_blank"><input type="hidden" name="redirect_to" id="register_redirect_to" value="/donate/"><input type="hidden" name="user_login" id="register_user_login" value=""><input type="hidden" name="old_user_email" id="old_user_email" value="'.$reg_email_key.'">
154 <div>'.__("Your Full Name:",'gotmls').'</div>
155 <div style="float: left; width: 50%;"><input style="width: 100%;" id="first_name" type="text" name="first_name" value="'.$current_user->user_firstname.'" /></div>
156 <div style="float: left; width: 50%;"><input style="width: 100%;" id="last_name" type="text" name="last_name" value="'.$current_user->user_lastname.'" /></div>
157 <div style="clear: left; width: 100%;">
158 <div>'.__("A password will be e-mailed to this address:",'gotmls').(GOTMLS_strlen($reg_email_key) == 32 && $reg_email_key != md5($current_user->user_email)?'<br /><span style="color: #C00;">'.__("Note: The pre-populated email below is NOT the address this site is currently registered under!",'gotmls').'</span>':"").'</div>
159 <input style="width: 100%;" id="user_email" type="text" name="user_email" value="'.$current_user->user_email.'" /></div>
160 <div>
161 <div>'.__("Your WordPress Site URL:",'gotmls').'</div>
162 <input style="width: 100%;" id="user_url" type="text" name="user_url" value="'.GOTMLS_siteurl.'" readonly /></div>
163 <div>
164 <div>'.__("Plugin Installation Key:",'gotmls').'</div>
165 <input style="width: 100%;" id="installation_key" type="text" name="installation_key" value="'.GOTMLS_installation_key.'" readonly /><input id="old_key" type="hidden" name="old_key" value="'.md5($GOTMLS_url_parts[2]).'" /></div>
166 <input style="width: 100%;" id="wp-submit" type="submit" name="wp-submit" value="Register Now!" /></form></div>'.(false && $isRegistered?'Registered to: '.$isRegistered:"").$Update_Link, "stuffbox").'
167 <script type="text/javascript">
168 var pri_addr = "'.$Update_Definitions[0].'";
169 var alt_addr = "'.$Update_Definitions[1].'";
170 function check_for_updates() {
171 showhide("Definition_Updates", true);
172 stopCheckingDefinitions = checkPrimaryUpdateServer();
173 }
174 function force_update_check(wait) {
175 document.getElementById("Definition_Updates").innerHTML = \'<img src="'.GOTMLS_images_path.'wait.gif">'.GOTMLS_strip4java(__("Checking Registration ...",'gotmls')).'\';
176 showhide("Definition_Updates", true);
177 showhide("autoUpdateForm", true);
178 showhide("autoUpdateForm");
179 showhide("registerKeyForm", true);
180 showhide("registerKeyForm");
181 showhide("clear_updates", true);
182 showhide("clear_updates");
183 setTimeout(function() {var GOTMLS_update_time = new Date();stopCheckingDefinitions = checkPrimaryUpdateServer(\'&dt=\'+GOTMLS_update_time.getTime());}, wait);
184 }
185 function updates_complete(chk) {
186 if (auto_img = document.getElementById("autoUpdateDownload")) {
187 auto_img.style.display="block";
188 check_for_donation(chk);
189 }
190 }
191 function sinupFormValidate(form) {
192 var error = "";
193 if(form["first_name"].value == "")
194 error += "'.__("First Name is a required field!",'gotmls').'\n";
195 if(form["last_name"].value == "")
196 error += "'.__("Last Name is a required field!",'gotmls').'\n";
197 if(form["user_email"].value == "")
198 error += "'.__("Email Address is a required field!",'gotmls').'\n";
199 else {
200 if (uem = document.getElementById("register_user_login"))
201 uem.value = form["user_email"].value;
202 if (uem = document.getElementById("register_redirect_to"))
203 uem.value = "/donate/?email="+form["user_email"].value.replace("@", "%40");
204 }
205 if(form["user_url"].value == "")
206 error += "'.__("Your WordPress Site URL is a required field!",'gotmls').'\n";
207 if(form["installation_key"].value == "")
208 error += "'.__("Plugin Installation Key is a required field!",'gotmls').'\n";
209 if(error != "") {
210 alert(error);
211 return false;
212 } else {
213 force_update_check(15000);
214 return true;
215 }
216 }
217 var divNAtext = false;
218 function loadGOTMLS() {
219 clearTimeout(divNAtext);
220 setDivNAtext();
221 '.$GLOBALS["GOTMLS"]["tmp"]["onLoad"].'
222 }
223 if ('.($defLatest+GOTMLS_strlen($isRegistered)).')
224 check_for_updates();
225 /* else
226 showhide("registerKeyForm", true);*/
227 if (divNAtext)
228 loadGOTMLS();
229 else
230 divNAtext=true;
231 </script>
232 '.GOTMLS_box(__("Resources & Links",'gotmls'), '
233 <div id="pastDonations"></div>
234 <center>
235 <a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span> Donate Here <span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span></a>
236 </center>
237 <ul class="GOTMLS-sidebar-links">
238 <li style="float: right;"><b>on <a target="_blank" href="https://profiles.wordpress.org/scheeeli#content-plugins">WordPress.org</a></b><ul class="GOTMLS-sidebar-links">
239 <li><a target="_blank" href="https://wordpress.org/plugins/gotmls/faq/">Plugin FAQs</a></li>
240 <li><a target="_blank" href="https://wordpress.org/support/plugin/gotmls">Forum Posts</a></li>
241 <li><a target="_blank" href="https://wordpress.org/support/view/plugin-reviews/gotmls">Plugin Reviews</a></li>
242 </ul></li>
243 <li><img src="//gravatar.com/avatar/5feb789dd3a292d563fea3b885f786d6?s=16" border="0" alt="Plugin site:"><b><a target="_blank" href="'.GOTMLS_plugin_home.'">GOTMLS.NET</a></b></li>
244 <li><img src="//gravatar.com/avatar/c0a17ace1ccb92bf930ab3621bfd5e7c?s=16" border="0" alt="Hosting site:"><b><a target="_blank" href="https://supersecurehosting.com/">Secure Hosting</a></b></li>
245 <li><img src="https://s.gravatar.com/avatar/7530906968df6594bfbe934ddc117f58?s=16" border="0" alt="mail:"><b><a target="_blank" href="mailto:eli@gotmls.net">Email Eli</a></b></li>
246 </ul>
247 <a target="_blank" href="https://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html#url='.rawurlencode(GOTMLS_siteurl).'">Google Safe Browsing Diagnostic</a>', "stuffbox").$optional_box.'</div>';
248 if (isset($GLOBALS["GOTMLS"]["tmp"]["stuffbox"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["stuffbox"])) {
249 echo '
250 <script type="text/javascript">
251 function stuffbox_showhide(id) {
252 divx = document.getElementById(id);
253 if (divx) {
254 if (divx.style.display == "none" || arguments[1]) {';
255 $else = '
256 if (divx = document.getElementById("GOTMLS-right-sidebar"))
257 divx.style.width = "30px";
258 if (divx = document.getElementById("GOTMLS-main-section"))
259 divx.style.marginRight = "30px";';
260 foreach ($GLOBALS["GOTMLS"]["tmp"]["stuffbox"] as $md5 => $bTitle) {
261 echo "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'block';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".GOTMLS_strip4java($bTitle, true)."';";
262 $else .= "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'none';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".substr($bTitle, 0, 1)."';";
263 }
264 echo '
265 if (divx = document.getElementById("GOTMLS-right-sidebar"))
266 divx.style.width = "300px";
267 if (divx = document.getElementById("GOTMLS-main-section"))
268 divx.style.marginRight = "300px";
269 return true;
270 } else {'.$else.'
271 return false;
272 }
273 }
274 }
275 if (getWindowWidth(780) == 780)
276 setTimeout(function() {stuffbox_showhide("inside_'.$md5.'");}, 200);
277 </script>';
278 }
279 echo '
280 <div id="GOTMLS-main-section" style="margin-right: 300px;">
281 <div class="metabox-holder GOTMLS" style="width: 100%;" id="GOTMLS-metabox-container">';
282 }
283
284 function GOTMLS_get_scan_history() {
285 global $wpdb;
286 $GOTMLS_nonce_context = __FUNCTION__."285";
287 $GOTMLS_nonce = GOTMLS_set_nonce($GOTMLS_nonce_context);
288 $imported = 0;
289 $LastScan = '';
290 if (isset($_GET["GOTMLS_clear_history"]) && (GOTMLS_strlen($clear_hist = preg_replace('/[^0-9a-f]++]i/', "", $_GET["GOTMLS_clear_history"])) == 32) && GOTMLS_get_nonce($GOTMLS_nonce_context) && GOTMLS_user_can()) {
291 if (($ors = $wpdb->get_results($wpdb->prepare("SELECT ID, post_parent, post_date FROM `$wpdb->posts` WHERE post_type = %s AND post_name = %s", 'gotmls_results', $clear_hist), ARRAY_A)) && isset($ors[0]["post_parent"]) && is_numeric($ors[0]["post_parent"]) && ($ors[0]["post_parent"] > 0) && ($wpdb->get_results($wpdb->prepare("SELECT COUNT(ID) FROM `$wpdb->posts` WHERE post_type = %s AND post_parent = %s", 'gotmls_results', $ors[0]["ID"]), ARRAY_A)) && ($cleared = $wpdb->query($wpdb->prepare("DELETE FROM `$wpdb->posts` WHERE post_type = %s AND post_date < %s", 'gotmls_results', $ors[0]["post_date"]))))
292 $wpdb->update($wpdb->posts, array("post_parent" => 0), array("post_type" => 'gotmls_results', "ID" => $ors[0]["ID"]));
293 $LastScan .= sprintf(__("Cleared %s records from the history.",'gotmls'), $cleared);
294 }
295 $SQL = $wpdb->prepare("SELECT * FROM `$wpdb->posts` WHERE post_type = %s ORDER BY post_date DESC", 'gotmls_results');
296 $units = array("seconds"=>60,"minutes"=>60,"hours"=>24,"days"=>365,"years"=>10);
297 if (!($prs = $wpdb->get_results($SQL, ARRAY_A))) {
298 if ($ors = $wpdb->get_results($wpdb->prepare("SELECT substring_index(option_name, '/', -1) AS `mt`, option_name, option_value FROM `$wpdb->options` WHERE option_name LIKE %s ORDER BY mt ASC", 'GOTMLS_scan_log/%'), ARRAY_A)) {
299 $parent = 0;
300 foreach ($ors as $row) {
301 $GOTMLS_scanlog = (isset($row["option_name"])?get_option($row["option_name"], array()):array());
302 $option_names = explode("/", "/".$row["option_name"]);
303 $mt = array_pop($option_names);
304 if (GOTMLS_strlen($mt) && is_numeric($mt)) {
305 $insert = array("post_name" => md5($mt), "post_content" => json_encode($GOTMLS_scanlog), "post_author" => GOTMLS_get_current_user_id(0), "post_type" => 'gotmls_results', "post_date_gmt" => date("Y-m-d H:i:s", (int) $mt), "post_parent" => $parent);
306 if (isset($GOTMLS_scanlog["scan"]["type"]) && GOTMLS_strlen($GOTMLS_scanlog["scan"]["type"]))
307 $insert["post_title"] = GOTMLS_sanitize($GOTMLS_scanlog["scan"]["type"]);
308 else
309 $insert["post_title"] = "Unknown scan type";
310 if (isset($GOTMLS_scanlog["scan"]["dir"]) && @is_dir($GOTMLS_scanlog["scan"]["dir"]))
311 $insert["post_title"] .= " of ".basename($GOTMLS_scanlog["scan"]["dir"]);
312 if (isset($GOTMLS_scanlog["scan"]["start"]) && is_numeric($GOTMLS_scanlog["scan"]["start"])) {
313 $insert["post_date"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["start"]);
314 $insert["post_modified"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["start"]);
315 $ukeys = array_keys($units);
316 $insert["post_title"] .= " on ".date("Y-m-d", $GOTMLS_scanlog["scan"]["start"]);
317 if (isset($GOTMLS_scanlog["scan"]["finish"]) && is_numeric($GOTMLS_scanlog["scan"]["finish"]) && ($GOTMLS_scanlog["scan"]["finish"] >= $GOTMLS_scanlog["scan"]["start"])) {
318 $insert["post_modified"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["finish"]);
319 $insert["post_modified_gmt"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["finish"]);
320 $time = ($GOTMLS_scanlog["scan"]["finish"] - $GOTMLS_scanlog["scan"]["start"]);
321 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= (2 * $units[$ukeys[$key]])); $unit = $ukeys[++$key])
322 $time = floor($time/$units[$ukeys[$key]]);
323 if (1 == $time)
324 $unit = substr($unit, 0, -1);
325 if ($time)
326 $insert["post_title"] .= " ran for $time $unit";
327 } else
328 $insert["post_title"] .= " was not finished!";
329 } else
330 $insert["post_title"] .= " failed to started!";
331 if ($inserted = $wpdb->insert($wpdb->posts, $insert)) {
332 $imported++;
333 $parent = $wpdb->insert_id;
334 } else
335 return sprintf(__("Failed to Import Scan History ID %s : %s",'gotmls'), $mt, $wpdb->last_error);
336 } else
337 return sprintf(__("Error: Failed to migrate old Scan History from %s.",'gotmls'), $row["option_name"]);
338 }
339 if ($cleared = $wpdb->query($wpdb->prepare("DELETE FROM `$wpdb->options` WHERE option_name LIKE %s", 'GOTMLS_scan_log/%')))
340 $LastScan .= sprintf(__("Converted %s of %s records from the Scan History into the new Scan Log record. Future Scans will now store more result data in the new Log.",'gotmls'), $imported, $cleared);
341 $prs = $wpdb->get_results($SQL, ARRAY_A);
342 }
343 }
344 if ($prs && is_array($prs) && count($prs)) {
345 $scans = 0;
346 $PreScan = '<ul class="GOTMLS-scanlog GOTMLS-sidebar-links">'."\n<li>";
347 foreach ($prs as $row) {
348 $LastScan .= $PreScan.GOTMLS_sanitize($row["post_title"]);
349 if ($scans)
350 $PreScan = '<a href="'.GOTMLS_script_URI.'&GOTMLS_clear_history='.$row["post_name"].'&'.$GOTMLS_nonce.'">[clear history below this entry]</a></li>'."\n<li>";
351 else
352 $PreScan = "</li>\n<li>";
353 $scans++;
354 }
355 $LastScan .= '</li></ul>';
356 } else
357 $LastScan .= '<h3>'.__("No Scans have been logged",'gotmls').'</h3>';
358 return "$LastScan\n";
359 }
360
361 function GOTMLS_get_whitelists() {
362 global $wpdb, $post;
363 $Q_Page = '';
364 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"])) {
365 $Q_Page .= '<ul name="found_Quarantine" id="found_Quarantine" class="GOTMLS_plugin known" style="background-color: #ccc; padding: 0;"><h3>'.__("Globally White-listed files",'gotmls').'<span class="GOTMLS_date">'.__("# of patterns",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Updated",'gotmls').'</span></h3>';
366 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"] as $file => $non_threats) {
367 if (isset($non_threats[0])) {
368 $updated = GOTMLS_sexagesimal($non_threats[0]);
369 unset($non_threats[0]);
370 } else
371 $updated = "Unknown";
372 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($non_threats).'</span><span class="GOTMLS_date">'.$updated."</span>$file</li>\n";
373 }
374 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"])) {
375 $Q_Page .= '<h3>'.__("WordPress Core files",'gotmls').'<span class="GOTMLS_date">'.__("# of files",'gotmls').'</span></h3>';
376 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"] as $ver => $files) {
377 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($files)."</span>Version $ver</li>\n";
378 }
379 }
380 $Q_Page .= "</ul>";
381 }
382 $my_query = new WP_Query(array("orderby" => 'date', "post_type" => 'GOTMLS_quarantine', "post_status" => array('pending'), "posts_per_page" => 500));
383 if ($my_query->have_posts()) {
384 $Q_Page .= '<form method="POST" action="'.admin_url('admin-ajax.php').'" target="GOTMLS_iFrame" name="GOTMLS_Form_whitelist"><input type="hidden" id="GOTMLS_whitelist" name="GOTMLS_whitelist" value="list_group"><input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce("GOTMLS_whitelist")).'"><input type="hidden" name="action" value="GOTMLS_whitelist"><p id="whitelist_buttons" style="display: none;"><input id="repair_button" type="submit" value="'.__("Remove selected files from the whitelist",'gotmls').'" class="button-primary" onclick="if (confirm(\''.__("Are you sure you want to remove these files from the whitelist?",'gotmls').'\')) { loadIframe(\'File Removal Results\'); } else return false;" /></p><p><b>'.__("The following files have been whitelisted by you. Any infections or malicious code found in the current versions of these files will be ignored in future scans. If these files are modified or updated from the current versions recorded here or if you remove them from this list then they may be flagged again in future scans.",'gotmls').'</b></p>
385 <ul name="found_whitelist" id="found_whitelist" class="GOTMLS_plugin" style="background-color: #ccc; padding: 0;"><h3 style="margin: 8px 12px;">'.__(" Whitelisted Files",'gotmls').'<span class="GOTMLS_date">'.__("Whitelisted",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Modified",'gotmls').'</span></h3>';
386 $root_path = implode(GOTMLS_slash(), array_slice(GOTMLS_explode_dir(__FILE__), 0, (2 + intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"])) * -1));
387 while ($my_query->have_posts()) {
388 $my_query->the_post();
389 $gif = 'checked.gif';
390 $threat = '';
391 $action = "\" onchange=\"document.getElementById('whitelist_buttons').style.display = 'block';";
392 $fa = GOTMLS_threats_found_meta(GOTMLS_object_to_array($post));
393 if (is_file($post->post_title))
394 $link = GOTMLS_error_link(__("View Whitelisted File",'gotmls').md5(GOTMLS_decode($post->post_content))."O".intval(GOTMLS_decode($post->post_content)), $post->post_title, $threat);
395 else {
396 $gif = "question.gif\" onload=\"document.getElementById('whitelist_buttons').style.display = 'block'; if (Whitelists = document.getElementById('box_".md5("Whitelists")."')) Whitelists.style.display = 'block';";
397 $_GET['Whitelists'] = "visible";
398 $threat = 'potential';
399 $action = '" checked="true';
400 $link = GOTMLS_error_link(__("Remove Missing File from Whitelist",'gotmls'), $post->post_title, $threat);
401 }
402 $chksum = preg_replace('/[^a-f\d]++/', "", $post->post_mime_type)."O".intval($post->comment_count);
403 $Q_Page .= '
404 <li id="GOTMLS_whitelist_'.$chksum.'" class="GOTMLS_quarantine_item" onmouseover="this.style.fontWeight=\'bold\';" onmouseout="this.style.fontWeight=\'normal\';"><span class="GOTMLS_date">'.GOTMLS_error_link(__("View Whitelisted Contents $chksum",'gotmls'), $post->ID, $threat).$post->post_date_gmt.'</a></span><span title="modified: '.GOTMLS_htmlspecialchars($post->post_modified).'" class="GOTMLS_date">'.GOTMLS_htmlspecialchars($post->post_modified_gmt).'</span><input type="checkbox" name="GOTMLS_chksum[]" id="whitelist_'.$chksum.'" value="'.$chksum.$action.'" /><img src="'.GOTMLS_images_path.$gif.'" height=16 width=16 alt="Q">'.$link.GOTMLS_htmlspecialchars(str_replace($root_path, "...", $post->post_title))."</a></li>\n";
405 }
406 $Q_Page .= "\n</ul>\n</form>";
407 }
408 wp_reset_query();
409 return "$Q_Page\n";
410 }
411
412 function GOTMLS_Quarantine_Trash() {
413 global $wpdb;
414 $Q_Page = '<div id="empty_trash_link" style="float: right;"><form method="post" onsubmit="if (curDiv = document.getElementById(\'empty_trash_link\')) curDiv.style.display = \'none\';" target="GOTMLS_statusFrame" action="'.GOTMLS_admin_url('GOTMLS_empty_trash', GOTMLS_set_nonce(__FUNCTION__."346")).'">';
415 if (($trashed = $wpdb->get_var("SELECT COUNT(*) FROM $wpdb->posts WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) > 1)
416 $Q_Page .= '<input class="primary" style="float: right;" type="submit" value="RESTORE" name="alter"><input class="primary" style="color: red; float: right;" type="submit" value="DELETE" name="alter"><span style="float: right; margin: 3px;">'.sprintf(__("%d Quarantine Records in the Trash",'gotmls'), (INT) $trashed)."</span>";
417 return "$Q_Page</form></div>\n";
418 }
419
420 function GOTMLS_ajax_View_Quarantine() {
421 GOTMLS_ajax_load_update();
422 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_get_header().GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine())))));
423 }
424
425 function GOTMLS_View_Quarantine() {
426 GOTMLS_ajax_load_update();
427 $echo = GOTMLS_box($Q_Page = "Whitelists", GOTMLS_get_whitelists());
428 if (!isset($_GET['Whitelists']))
429 $echo .= "\n<script>\nshowhide('inside_".md5($Q_Page)."');\n</script>\n";
430 $echo .= GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine());
431 GOTMLS_display_header();
432 echo "$echo\n</div></div></div>";
433 }
434
435 function GOTMLS_Firewall_Options() {
436 global $current_user, $wpdb, $table_prefix;
437 GOTMLS_ajax_load_update();
438 GOTMLS_display_header();
439 $GOTMLS_nonce_found = GOTMLS_get_nonce();
440 $gt = ">"; // This local variable never changes
441 $lt = "<"; // This local variable never changes
442 $save_action = "";
443 $patch_attr = array(
444 array(
445 "icon" => "blocked",
446 "language" => __("Your WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. Applying this patch will block access to the WordPress Login page whenever this type of attack is detected.",'gotmls'),
447 "status" => __('Not Installed','gotmls'),
448 "action" => __('Install Patch','gotmls')
449 ),
450 array(
451 "language" => __("Your WordPress site has the current version of my brute-force Login protection installed.",'gotmls'),
452 "action" => __('Uninstall Patch','gotmls'),
453 "status" => __('Enabled','gotmls'),
454 "icon" => "checked"
455 ),
456 array(
457 "language" => __("Your WordPress Login page has the old version of my brute-force protection installed. Upgrade this patch to improve the protection on the WordPress Login page and preserve the integrity of your WordPress core files.",'gotmls'),
458 "action" => __('Upgrade Patch','gotmls'),
459 "status" => __('Out of Date','gotmls'),
460 "icon" => "threat"
461 )
462 );
463 $find = '|<Files[^>]+xmlrpc.php>(.+?)</Files>\s*(# END GOTMLS Patch to Block XMLRPC Access\s*)*|is';
464 $deny = "\n<IfModule !mod_authz_core.c>\norder deny,allow\ndeny from all\nallow from ".GOTMLS_REMOTEADDR;
465 $allow = GOTMLS_REMOTEADDR;
466 if (isset($_SERVER["SERVER_ADDR"])) {
467 $deny .= "\nallow from ".GOTMLS_safe_ip($_SERVER["SERVER_ADDR"]);
468 $allow .= " ".GOTMLS_safe_ip($_SERVER["SERVER_ADDR"]);
469 }
470 $deny .= "\n</IfModule>\n<IfModule mod_authz_core.c>\nRequire";
471 if (GOTMLS_strlen(trim($allow)) > 0)
472 $deny .= " ip $allow";
473 else
474 $deny .= " all denied";
475 $deny .= "\n</IfModule>";
476 if (count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
477 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
478 else {
479 if (isset($GLOBALS["GOTMLS"]["tmp"]["apache"][0]) && (strtolower(substr($GLOBALS["GOTMLS"]["tmp"]["apache"][0]."123456", 0, 6)) == "apache"))
480 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
481 else
482 $errdiv = "<div class='error'>".__('Unable to find Apache on this server, this patch work on Apache servers!','gotmls')."</div>";
483 }
484 $Firewall_nonce = $lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."420")).'"'.$gt;
485 $XMLRPC_patch_action = $lt.'hr /'.$gt.$lt.'form method="POST" name="GOTMLS_Form_XMLRPC_patch"'.$gt.$Firewall_nonce.$lt."script$gt\nfunction setFirewall(opt, val) {\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_opt'))\n\t\tautoUpdateDownloadGIF.value = opt;\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_val'))\n\t\tautoUpdateDownloadGIF.value = val;\n}\nfunction testComplete() {\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_XMLRPC_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_XMLRPC_patch_searching');\n\tshowhide('GOTMLS_XMLRPC_patch_button', true);\n}\n}\nwindow.onload=testComplete;\n$lt/script$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="hidden" name="GOTMLS_XMLRPC_patching" value="';
486 $patch_found = false;
487 $head = str_replace(array('|<Files[^>]+', '(.+?)', '\\s*(', '\\s*)*|is'), array("<Files ", "$deny\n", "\n", "\n"), $find);
488 $htaccess = "";
489 if (is_file(ABSPATH.'.htaccess'))
490 if (($htaccess = @file_get_contents(ABSPATH.'.htaccess')) && GOTMLS_strlen($htaccess))
491 $patch_found = preg_match($find, $htaccess);
492 if ($patch_found) {
493 $errdiv = "";
494 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0) && GOTMLS_save_contents(ABSPATH.'.htaccess', preg_replace($find, "", $htaccess)))
495 $XMLRPC_patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Allowing Access';
496 elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0))
497 $XMLRPC_patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Blocking: '.sprintf(__("Failed to remove XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".GOTMLS_strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
498 else
499 $XMLRPC_patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Blocked';
500 } else {
501 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0) && GOTMLS_save_contents(ABSPATH.'.htaccess', "$head$htaccess")) {
502 $XMLRPC_patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Blocked';
503 $errdiv = "";
504 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0))
505 $XMLRPC_patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Allowing Access: '.sprintf(__("Failed to install XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".GOTMLS_strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
506 else
507 $XMLRPC_patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Allowing Access';
508 }
509 $XMLRPC_patch_action .= ")$errdiv$lt/b$gt$lt/p$gt{$lt}b$gt".__("(This patch only works on Apache servers and requires mod_rewrite to be functional)",'gotmls')."$lt/b$gt{$lt}br$gt\n".__("Most WordPress sites do not use the XMLRPC features and hack attempts on the xmlrpc.php file are more common then ever before. Even if there are no vulnerabilities for hackers to exploit, these attempts can cause slowness or downtime similar to a DDoS attack. This patch automatically blocks all external access to the xmlrpc.php file.",'gotmls')."$lt/div$gt$lt/form$gt";
510 $patch_status = 0;
511 $patch_found = -1;
512 $find = "#if\s*\(([^\&]+\&\&)?\s*file_exists\((.+?)(safe-load|wp-login)\.php'\)\)\s*require(_once)?\((.+?)(safe-load|wp-login)\.php'\);#";
513 $head = str_replace(array('#', '\\(', '\\)', '(_once)?', ')\\.', '\\s*', '(.+?)(', '|', '([^\\&]+\\&\\&)?'), array(' ', '(', ')', '_once', '.', ' ', '\''.dirname(__FILE__).'/', '/', '!in_array($_SERVER["REMOTE_ADDR"], array("'.GOTMLS_REMOTEADDR.'")) &&'), $find);
514 if (is_file(ABSPATH.'../wp-config.php') && !is_file(ABSPATH.'wp-config.php'))
515 $wp_config = '../wp-config.php';
516 else
517 $wp_config = 'wp-config.php';
518 $BFLP_patch_action = "";
519 if (is_file(ABSPATH.$wp_config)) {
520 if (($config = @file_get_contents(ABSPATH.$wp_config)) && GOTMLS_strlen($config)) {
521 if ($patch_found = preg_match($find, $config)) {
522 if (strpos($config, substr($head, strpos($head, "file_exists")))) {
523 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0) && GOTMLS_save_contents(ABSPATH.$wp_config, preg_replace('#'.$lt.'\?(?:php)?+\s*+(?://.*+\s*+)*+\?'.$gt.'#i', "", preg_replace($find, "", $config))))
524 $BFLP_patch_action .= GOTMLS_error_div(__("Removed Brute-Force Protection",'gotmls'));
525 else
526 $patch_status = 1;
527 } else {
528 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0) && GOTMLS_save_contents(ABSPATH.$wp_config, preg_replace($find, "$head", $config))) {
529 $BFLP_patch_action .= GOTMLS_error_div(__("Upgraded Brute-Force Protection",'gotmls'), "updated");
530 $patch_status = 1;
531 } else
532 $patch_status = 2;
533 }
534 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0) && GOTMLS_strlen($config) && ($patch_found == 0) && GOTMLS_save_contents(ABSPATH.$wp_config, "$lt?php\n$head// Load Brute-Force Protection by GOTMLS.NET before the WordPress bootstrap. ?$gt$config")) {
535 $BFLP_patch_action .= GOTMLS_error_div(__("Installed Brute-Force Protection",'gotmls'), "updated");
536 $patch_status = 1;
537 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0))
538 $BFLP_patch_action .= GOTMLS_error_div(sprintf(__("Failed to install Brute-Force Protection (wp-config.php %s)",'gotmls'),(is_readable(ABSPATH.$wp_config)?'read-'.(is_writable(ABSPATH.$wp_config)?'write':'only'):"unreadable").": ".GOTMLS_strlen($config).GOTMLS_fileperms(ABSPATH.$wp_config)), "updated");
539 } else
540 $BFLP_patch_action .= GOTMLS_error_div(__("wp-config.php Not Readable!",'gotmls'));
541 } else
542 $BFLP_patch_action .= GOTMLS_error_div(__("wp-config.php Not Found!",'gotmls'));
543 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_firewall_option"]) && GOTMLS_strlen($_POST["GOTMLS_firewall_option"]) && isset($_POST["GOTMLS_firewall_value"]) && GOTMLS_strlen($_POST["GOTMLS_firewall_value"])) {
544 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"][GOTMLS_sanitize($_POST["GOTMLS_firewall_option"])] = (INT) $_POST["GOTMLS_firewall_value"];
545 if (update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]))
546 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";
547 else
548 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSave Failed!$lt/div$gt\n";
549 }
550 $sec_opts = $lt.'form method="POST" name="GOTMLS_Form_firewall"'.$gt.$lt.'input type="hidden" id="fw_opt" name="GOTMLS_firewall_option" value="traversal"'.$gt.$lt.'input type="hidden" name="GOTMLS_firewall_value" id="fw_val" value="0"'.$gt.$Firewall_nonce;
551 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]) && array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]))
552 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"] as $TP => $VA)
553 if (is_array($VA) && count($VA) > 3 && GOTMLS_strlen($VA[1]) && GOTMLS_strlen($VA[2]))
554 $sec_opts .= $lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="submit" style="float: right;" value="'.(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]?"Enable Protection\" onclick=\"setFirewall('$TP', 0);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt."b$gt$VA[1] (Currently Disabled)":"Disable Protection\" onclick=\"setFirewall('$TP', 1);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt."b$gt$VA[1] (Automatically Enabled)")."$lt/b$gt$lt/p$gt$VA[2]$lt/div$gt$lt".'hr /'.$gt;
555 $style = ' display: none;" id="GOTMLS_patch_button"'.$gt.$lt.'div id="GOTMLS_patch_searching" style="float: right;"'.$gt.__("Checking for session compatibility ...",'gotmls').' '.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /'.$gt.$lt.'/div'.$gt;
556 $script = "";
557 if ($patch_status) {
558 $sec_opts .= $lt.'input type="submit" style="float: right; margin: 6px;" value="'.(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]?"Show Protection Logo\" onclick=\"setFirewall('BFLP', 0);\"$gt$lt".'div style="float: right; margin: 8px;"'."$gt Logo will be hidden on the login page":"Hide Protection Logo\" onclick=\"setFirewall('BFLP', 1);\"$gt$lt".'div style="float: right; margin: 8px;"'.$gt.$lt.'img style="height: 24px; vertical-align: middle;"src="'.GOTMLS_images_path.'GOTMLS-Loading.gif" /'."$gt Brute-Force Protection is Active")."$lt/div$gt";
559 $style = '"'.$gt;
560 } else
561 $script = $lt."script type='text/javascript'$gt\nfunction search_patch_onload() {\n\tstopCheckingSession = checkupdateserver('".GOTMLS_admin_url('GOTMLS_log_session')."');\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', search_patch_onload)\nelse\n\tdocument.attachEvent('onload', search_patch_onload);\n$lt/script$gt";
562 $sec_opts .= "$lt/form$gt\n$BFLP_patch_action\n$lt".'form method="POST" name="GOTMLS_Form_patch"'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$Firewall_nonce.$lt.'input type="submit" value="'.$patch_attr[$patch_status]["action"].'" style="float: right;'.$style.$lt.'input type="hidden" name="GOTMLS_patching" value="1"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$patch_attr[$patch_status]["icon"].'.gif"'.$gt.$lt.'b'.$gt.'Brute-force Protection '.$patch_attr[$patch_status]["status"].$lt.'/b'.$gt.$lt.'/p'.$gt.$patch_attr[$patch_status]["language"].__(" For more information on Brute-Force attack prevention and the WordPress wp-login-php file ",'gotmls').' '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-login-php/"'.$gt.__("read my blog",'gotmls')."$lt/a$gt.$lt/div$gt$lt/form$gt\n$XMLRPC_patch_action\n$script";
563 $admin_notice = "";
564 if ($current_user->user_login == "admin") {
565 $admin_notice .= $lt.'hr /'.$gt;
566 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_admin_username"]) && ($current_user->user_login != trim($_POST["GOTMLS_admin_username"])) && GOTMLS_strlen(trim($_POST["GOTMLS_admin_username"])) && preg_match('/^\s*[a-z_0-9\@\.\-]{3,}\s*$/i', $_POST["GOTMLS_admin_username"])) {
567 if ($wpdb->update($wpdb->users, array("user_login" => trim($_POST["GOTMLS_admin_username"])), array("user_login" => $current_user->user_login))) {
568 $wpdb->query($wpdb->prepare("UPDATE `{$wpdb->prefix}sitemeta` SET `meta_value` = REPLACE(`meta_value`, 's:5:\"admin\";', %s) WHERE `meta_key` = 'site_admins' AND `meta_value` like %s", 's:'.GOTMLS_strlen(trim($_POST["GOTMLS_admin_username"])).':"'.trim($_POST["GOTMLS_admin_username"]).'";', '%s:5:"admin";%'));
569 $admin_notice .= GOTMLS_error_div(sprintf(__("You username has been change to %s. Don't forget to use your new username when you login again.",'gotmls'), $_POST["GOTMLS_admin_username"]), "updated");
570 } else
571 $admin_notice .= GOTMLS_error_div(sprintf(__("SQL Error changing username: %s. Please try again later.",'gotmls'), $wpdb->last_error));
572 } else {
573 if (isset($_POST["GOTMLS_admin_username"]))
574 $admin_notice .= GOTMLS_error_div(sprintf(__("Your new username must be at least 3 characters and can only contain &quot;%s&quot;. Please try again.",'gotmls'), "a-z0-9_.-@"), "updated");
575 $admin_notice .= $lt.'form method="POST" name="GOTMLS_Form_admin"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'div style="float: left;"'.$gt.__("Change your username:",'gotmls').$lt.'/div'.$gt.$Firewall_nonce.$lt.'input style="float: left;" type="text" id="GOTMLS_admin_username" name="GOTMLS_admin_username" size="6" value="'.$current_user->user_login.'"'.$gt.$lt.'input style="float: left;" type="submit" value="Change"'.$gt.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Admin Notice'.$lt.'/b'.$gt.$lt.'/p'.$gt.__("Your username is \"admin\", this is the most commonly guessed username by hackers and brute-force scripts. It is highly recommended that you change your username immediately.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt;
576 }
577 }
578 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_wpfirewall_action"])) {
579 if ($_POST["GOTMLS_wpfirewall_action"] == "exclude_terms")
580 update_option("WP_firewall_exclude_terms", "");
581 elseif ($_POST["GOTMLS_wpfirewall_action"] == "whitelisted_ip") {
582 $ips = GOTMLS_uckserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"));
583 if (is_array($ips))
584 $ips = array_merge($ips, array(GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"])));
585 else
586 $ips = array(GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"]));
587 update_option("WP_firewall_whitelisted_ip", serialize($ips));
588 }
589 }
590 if (get_option("WP_firewall_exclude_terms", "Not Found!") == "allow") {
591 $end = "$lt/div$gt$lt/form$gt\n{$lt}hr /$gt";
592 $img = 'threat.gif"';
593 $button = $lt.'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'exclude_terms\';" value="'.__("Disable this Rule",'gotmls').'"'.$gt;
594 $wpfirewall_action = $lt.'form method="POST" name="GOTMLS_Form_wpfirewall2"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="hidden" name="GOTMLS_wpfirewall_action" id="GOTMLS_wpfirewall_action" value=""'.$gt.$Firewall_nonce.$button.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$img.$gt.$lt.'b'.$gt."WP Firewall 2 (Conflicting Firewall Rule)$lt/b$gt$lt/p$gt".__("The Conflicting Firewall Rule (WP_firewall_exclude_terms) activated by the WP Firewall 2 plugin has been shown to interfere with the Definition Updates and WP Core File Scans in my Anti-Malware plugin. I recommend that you disable this rule in the WP Firewall 2 plugin.",'gotmls').$end;
595 if (isset($_SERVER["REMOTE_ADDR"])) {
596 if (is_array($ips = GOTMLS_uckserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"))) && in_array($_SERVER["REMOTE_ADDR"], $ips))
597 $wpfirewall_action = str_replace(array($img, $end), array('question.gif"', __(" However, your current IP has been Whitelisted so you could probably keep this rule enabled if you really want to.",'gotmls').$end), $wpfirewall_action);
598 else
599 $wpfirewall_action = str_replace(array($button, $end), array($button.$lt."br /$gt$lt".'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'whitelisted_ip\';" value="'.__("Whitelist your IP",'gotmls').'"'.$gt, __(" However, if you would like to keep this rule enabled you should at least Whitelist your IP.",'gotmls').$end), $wpfirewall_action);
600 }
601 $sec_opts = $wpfirewall_action.$sec_opts;
602 }
603 echo GOTMLS_box(__("Firewall Options",'gotmls'), $save_action.$sec_opts.$admin_notice)."\n</div></div></div>";
604 }
605
606 function GOTMLS_get_registrant($you) {
607 global $current_user, $wpdb;
608 wp_get_current_user();
609 if (isset($you["you"]))
610 $you = $you["you"];
611 if (isset($you["user_email"]) && GOTMLS_strlen($you["user_email"]) == 32) {
612 if ($you["user_email"] == md5($current_user->user_email))
613 $registrant = $current_user->user_email;
614 elseif (!($registrant = $wpdb->get_var($wpdb->prepare("SELECT `user_nicename` FROM `$wpdb->users` WHERE MD5(`user_email`) = %s", $you["user_email"]))))
615 $registrant = GOTMLS_siteurl;
616 } else
617 $registrant = GOTMLS_siteurl;
618 return $registrant;
619 }
620
621 function GOTMLS_ajax_load_update() {
622 global $wpdb;
623 $GOTMLS_nonce_found = GOTMLS_get_nonce();
624 $YES_user_can = GOTMLS_user_can();
625 $GOTMLS_definitions_versions = array();
626 $user_info = array();
627 $saved = false;
628 $moreJS = "";
629 $finJS = "\n}";
630 $form = 'registerKeyForm';
631 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key could not be confirmed!</li>";
632 $autoUpJS = '<span style="color: #C00;">This new feature is currently only available to registered users who have donated $29 or more.</span><br />';
633 if (is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
634 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names)
635 foreach ($definition_names as $definition_name=>$definition_version)
636 if (is_array($definition_version) && isset($definition_version[0]) && GOTMLS_strlen($definition_version[0]) == 5)
637 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
638 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
639 asort($GOTMLS_definitions_versions);
640 if (isset($_REQUEST["UPDATE_definitions_array"]) && GOTMLS_strlen($_REQUEST["UPDATE_definitions_array"]) && $GOTMLS_nonce_found && $YES_user_can) {
641 $DEF_url = 'http:'.GOTMLS_update_home.'definitions.php?'.GOTMLS_get_version_URL.'&'.GOTMLS_set_nonce(GOTMLS_update_home).'&d='.ur1encode(GOTMLS_siteurl);
642 if (isset($_REQUEST["dt"]) && GOTMLS_strlen($_REQUEST["dt"]))
643 $DEF_url .= '&dt='.preg_replace('/[^\w]/', "", $_REQUEST["dt"]);
644 if (GOTMLS_strlen($_REQUEST["UPDATE_definitions_array"]) > 1) {
645 $GOTnew_definitions = GOTMLS_uckserialize(GOTMLS_decode($_REQUEST["UPDATE_definitions_array"]));
646 if (is_array($GOTnew_definitions)) {
647 $form = 'autoUpdateDownload';
648 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('Downloaded Definitions');";
649 }
650 } elseif ($_REQUEST["UPDATE_definitions_array"] == "D") {
651 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = array();
652 $GOTnew_definitions = array();
653 delete_option('GOTMLS_get_URL_array');
654 } elseif (($DEF = GOTMLS_get_URL($DEF_url)) && is_array($GOTnew_definitions = GOTMLS_uckserialize(GOTMLS_decode($DEF))) && count($GOTnew_definitions)) {
655 if (isset($GOTnew_definitions["you"]["user_email"]) && GOTMLS_strlen($GOTnew_definitions["you"]["user_email"]) == 32) {
656 $toInfo = GOTMLS_get_registrant($GOTnew_definitions["you"]);
657 $innerHTML = "<li style=\\\"color: #0C0\\\">Your Installation Key is Registered to:<br /> $toInfo</li>";
658 $form = 'autoUpdateForm';
659 if (isset($GOTnew_definitions["you"]["user_donations"]) && isset($GOTnew_definitions["you"]["user_donation_total"]) && isset($GOTnew_definitions["you"]["user_donation_freshness"])) {
660 $user_donations_src = $GOTnew_definitions["you"]["user_donations"];
661 if ($GOTnew_definitions["you"]["user_donation_total"] > 27.99) {
662 $autoUpJS = '<input type="radio" id="auto_UPDATE_definitions_1" name="UPDATE_definitions_array" value="1">Yes | <input type="radio" id="auto_UPDATE_definitions_0" name="UPDATE_definitions_array" value="0" checked>No <input type="hidden" name="UPDATE_definitions_checkbox" value="UPDATE_definitions_array">';
663 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
664 foundUpdates.innerHTML = "<a href=\'javascript:document.getElementById(\\"GOTMLS_Form\\").submit();\' onclick=\'document.getElementById(\\"auto_UPDATE_definitions_1\\").checked=true;\' style=\'color: #f00;\'>Set Definition Updates to Automatically Download to activate this feature.</a>";';
665 }
666 if ($user_donations_src > 0 && $GOTnew_definitions["you"]["user_donation_total"] > 0)
667 $li = "<li> You have made $user_donations_src donation".($user_donations_src?'s totalling':' for').' $'.$GOTnew_definitions["you"]["user_donation_total"].".</li><!-- ".$GOTnew_definitions["you"]["user_donation_freshness"]." -->";
668 }
669 } else
670 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key is not registered!</li>";
671 asort($GOTnew_definitions);
672 if (serialize($GOTnew_definitions) == serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
673 unset($GOTnew_definitions);
674 else {
675 $debug = substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), 0, 9)." ".md5(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".GOTMLS_strlen(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), -9)." != ".substr(serialize($GOTnew_definitions), 0, 9)." ".md5(serialize($GOTnew_definitions))." ".GOTMLS_strlen(serialize($GOTnew_definitions)." ".substr(serialize($GOTnew_definitions), -9));
676 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = $GOTnew_definitions;
677 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('New Definitions Automatically Installed :-)');";
678 }
679 $finJS .= "\nif (divNAtext)\n\tloadGOTMLS();\nelse\n\tdivNAtext = setTimeout(function() {loadGOTMLS();}, 4000);";
680 $finJS .= "\nif (typeof stopCheckingDefinitions !== 'undefined' && stopCheckingDefinitions)\n\tclearTimeout(stopCheckingDefinitions);";
681 } else
682 $innerHTML = "<li style=\\\"color: #f00\\\"><a title='report error' href='#' onclick=\\\"stopCheckingDefinitions = checkAlternateUpdateServer('&error=".GOTMLS_encode(serialize(array("get_URL"=>$GLOBALS["GOTMLS"]["get_URL"])))."');\\\">Automatic Update Connection Failed!</a></li>";
683 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]))
684 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]);
685 } else {
686 if (!$GOTMLS_nonce_found)
687 $reason = GOTMLS_Invalid_Nonce();
688 elseif (!$YES_user_can)
689 $reason = __("Permission Error: Only an administrator can update settings!", 'gotmls');
690 else
691 $reason = __("definitions_array not set!", 'gotmls');
692 $innerHTML = "<li style=\\\"color: #f00\\\">".GOTMLS_htmlspecialchars($reason)."</li>";
693 }
694 if (isset($GOTnew_definitions) && is_array($GOTnew_definitions)) {
695 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = GOTMLS_array_replace($GLOBALS["GOTMLS"]["tmp"]["definitions_array"], $GOTnew_definitions);
696 if (file_exists(GOTMLS_plugin_path.'definitions_update.txt'))
697 @unlink(GOTMLS_plugin_path.'definitions_update.txt');
698 $saved = GOTMLS_update_option('definitions', $GLOBALS["GOTMLS"]["tmp"]["definitions_array"], false);
699 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"] = array();
700 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names) {
701 if ($threat_level != "potential")
702 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"][] = $threat_level;
703 foreach ($definition_names as $definition_name=>$definition_version)
704 if (is_array($definition_version) && isset($definition_version[0]) && GOTMLS_strlen($definition_version[0]) == 5)
705 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
706 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
707 }
708 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"];
709 asort($GOTMLS_definitions_versions);
710 $autoUpJS .= '<span style="color: #0C0;">(Newest Definition Updates Installed.)</span>';
711 } elseif ($form != 'registerKeyForm') {
712 $form = 'autoUpdateDownload';
713 $autoUpJS .= '<span style="color: #0C0;">(No newer Definition Updates are available at this time.)</span>';
714 $innerHTML .= "<li style=\\\"color: #0C0\\\">No Newer Definition Updates Available.</li>";
715 }
716 if (isset($_SERVER["SCRIPT_FILENAME"]) && preg_match('/[\/\\\\]admin-ajax\.php/i', $_SERVER["SCRIPT_FILENAME"]) && isset($_REQUEST["action"]) && $_REQUEST["action"] == "GOTMLS_load_update") {
717 if (!$user_donations_src)
718 $li = "<li style=\\\"color: #f00;\\\"><button onclick=\\\"force_update_check(500);\\\" style=\\\"float: right;\\\">Check Again</button>You have not donated yet!</li>";
719 if (GOTMLS_strlen($moreJS) == 0)
720 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
721 foundUpdates.innerHTML = "<a target=\'_blank\' href=\'https://gotmls.net/donate/?key='.GOTMLS_installation_key.'\' style=\'color: #f00;\'>Donate $29+ now then enable Automatic Definition Updates to Scan for Core Files changes.</a>";';
722 $moreJS .= "\n\tif (foundUpdates = document.getElementById('pastDonations'))\n\tfoundUpdates.innerHTML = '$li';";
723 if ($GOTMLS_nonce_found)
724 @header("Content-type: text/javascript");
725 else
726 die(GOTMLS_Invalid_Nonce("Nonce Error: "));
727 if (is_array($GOTMLS_definitions_versions) && count($GOTMLS_definitions_versions) && (GOTMLS_strlen($new_ver = trim(array_pop($GOTMLS_definitions_versions))) == 5) && $saved) {
728 $innerHTML .= "<li style=\\\"color: #0C0\\\">New Definition Updates Installed.</li>";
729 $finJS .= "\nif (foundUpdates = document.getElementById('GOTMLS_definitions_date')) foundUpdates.innerHTML = '$new_ver';\nif (foundUpdates = document.getElementById('autoUpdateForm')) foundUpdates.style.display = 'none';";
730 } elseif (isset($GOTnew_definitions) && is_array($GOTnew_definitions) && count($GOTnew_definitions))
731 $finJS .= "\nalert('Definition update $new_ver could not be saved because update_option Failed! (saved=".($saved?"TRUE":"FALSE").") $debug');";
732 if (isset($_REQUEST["UPDATE_core"]) && ($_REQUEST["UPDATE_core"] == GOTMLS_wp_version) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version])) {
733 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version] as $file => $md5) {
734 if (is_file(ABSPATH.$file)) {
735 GOTMLS_load_contents(file_get_contents(ABSPATH.$file));
736 if (GOTMLS_check_threat($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"], ABSPATH.$file)) {
737 if (isset($GLOBALS["GOTMLS"]["tmp"]["new_contents"]) && isset($_REQUEST["UPDATE_restore"]) && ($_REQUEST["UPDATE_restore"] == md5($GLOBALS["GOTMLS"]["tmp"]["new_contents"])."O".GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["new_contents"])))
738 $autoUpJS .= "<li>Core File Restored: $file</li>";
739 else
740 $autoUpJS .= "<li>Core File MODIFIED: $file ".md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"])."O".GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"])." => $md5</li>";
741 }
742 } else
743 $autoUpJS .= "<li>Core File MISSING: $file</li>";
744 }
745 $autoUpJS .= GOTMLS_error_div('Definition update: '.preg_replace('/[^0-9\.]/', "", $_REQUEST["UPDATE_core"]).' checked '.count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version]).' core files!', "update");
746 }
747 die('//<![CDATA[
748 var inc_form = "";
749 if (foundUpdates = document.getElementById("autoUpdateDownload"))
750 foundUpdates.src += "?'.$user_donations_src.'";
751 if (foundUpdates = document.getElementById("registerKeyForm"))
752 foundUpdates.style.display = "none";
753 if (foundUpdates = document.getElementById("'.$form.'"))
754 foundUpdates.style.display = "block";
755 if (foundUpdates = document.getElementById("Definition_Updates"))
756 foundUpdates.innerHTML = "<ul class=\\"GOTMLS-sidebar-links\\">'.$innerHTML.'</ul>"+inc_form;
757 function setDivNAtext() {
758 var foundUpdates;
759 '.$moreJS.$finJS.'
760 if (foundUpdates = document.getElementById("UPDATE_definitions_div"))
761 foundUpdates.innerHTML = \''.$autoUpJS.'\';
762 //]]>');
763 }
764 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] = '?div=Definition_Updates';
765 foreach ($GOTMLS_definitions_versions as $definition_name=>$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"])
766 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[$definition_name]=".$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"];
767 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)
768 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[you]=".$GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
769 }
770
771 function GOTMLS_settings() {
772 global $wpdb, $GOTMLS_dirs_at_depth, $GOTMLS_dir_at_depth;
773 $GOTMLS_scan_groups = array();
774 $gt = ">"; // This local variable never changes
775 $lt = "<"; // This local variable never changes
776 GOTMLS_ajax_load_update();
777 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))
778 $_REQUEST["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
779 if (($GOTMLS_nonce_found = GOTMLS_get_nonce()) && ((isset($_REQUEST["check"]) && is_array($_REQUEST["check"])) || (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"])))) {
780 if (isset($_REQUEST["check"]) && is_array($_REQUEST["check"]))
781 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = GOTMLS_sanitize($_REQUEST["check"]);
782 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
783 }
784 $dirs = GOTMLS_explode_dir(__FILE__);
785 for ($SL=0;$SL<intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);$SL++)
786 $GOTMLS_scan_groups[] = implode(GOTMLS_slash(), array_slice($dirs, -1 * (3 + $SL), 1));
787 if (isset($_POST["exclude_ext"])) {
788 if (GOTMLS_strlen(trim(str_replace(",","",$_POST["exclude_ext"]).' ')) > 0)
789 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(str_replace('.', ',', GOTMLS_sanitize($_POST["exclude_ext"]))), -1, PREG_SPLIT_NO_EMPTY);
790 else
791 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = array();
792 }
793 $default_exclude_ext = str_replace(",gotmls", "", implode(",", $GLOBALS["GOTMLS"]["tmp"]["skip_ext"]));
794 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
795 if (isset($_POST["UPDATE_definitions_checkbox"])) {
796 if (isset($_POST[$_POST["UPDATE_definitions_checkbox"]]) && is_numeric($_POST[$_POST["UPDATE_definitions_checkbox"]]))
797 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = (INT) $_POST[$_POST["UPDATE_definitions_checkbox"]];
798 else
799 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = "";
800 }
801 if (isset($_POST["exclude_dir"])) {
802 if (GOTMLS_strlen(trim(str_replace(",","",$_POST["exclude_dir"]).' ')) > 0)
803 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(GOTMLS_sanitize($_POST["exclude_dir"])), -1, PREG_SPLIT_NO_EMPTY);
804 else
805 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = array();
806 for ($d=0; $d<count($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]); $d++)
807 if (dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]) != ".")
808 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d] = str_replace("\\", "", str_replace("/", "", str_replace(dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]), "", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d])));
809 }
810 $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"] = array_merge($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"], $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"]);
811 if (isset($_POST["scan_what"]) && is_numeric($_POST["scan_what"]) && $_POST["scan_what"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"])
812 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = (INT) $_POST["scan_what"];
813 if (isset($_POST["check_custom"]) && $_POST["check_custom"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"])
814 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = GOTMLS_verify_regex(trim(stripslashes($_POST["check_custom"])));
815 if (isset($_POST["scan_depth"]) && is_numeric($_POST["scan_depth"]) && $_POST["scan_depth"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])
816 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = (INT) $_POST["scan_depth"];
817 if (isset($_POST['skip_quarantine']) && is_numeric($_POST['skip_quarantine']) && $_POST['skip_quarantine'])
818 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = (INT) $_POST['skip_quarantine'];
819 elseif (isset($_POST["exclude_ext"]))
820 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = 0;
821 GOTMLS_update_scanlog(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
822 $scan_whatopts = '';
823 $scan_root = "public_html";
824 $scan_optjs = "\n{$lt}script type=\"text/javascript\"$gt\nfunction showOnly(what) {\n";
825 foreach ($GOTMLS_scan_groups as $mg => $GOTMLS_scan_group) {
826 $scan_optjs .= "document.getElementById('only$mg').style.display = 'none';\n";
827 $scan_whatopts = "\n$lt/div$gt\n$lt/div$gt\n$scan_whatopts";
828 $scan_root = $GOTMLS_scan_group;
829 $dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + $mg)));
830 $files = GOTMLS_getfiles($dir);
831 if (isset($files) && is_array($files) && count($files))
832 foreach ($files as $file)
833 if (is_dir(GOTMLS_trailingslashit($dir).$file))
834 $scan_whatopts = $lt.'input type="checkbox" onchange="showhide(\'custom_quick_scan\', true);" name="scan_only[]" value="'.GOTMLS_htmlspecialchars($file).'" /'.$gt.GOTMLS_htmlspecialchars($file).$lt.'br /'.$gt.$scan_whatopts;
835 $scan_whatopts = "\n$lt".'div style="padding: 4px 30px;" id="scan_group_div_'.$mg.'"'.$gt.$lt.'input type="radio" name="scan_what" id="not-only'.$mg.'" value="'.$mg.'"'.($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]==$mg?' checked':'').' /'.$gt.$lt.'a style="text-decoration: none;" href="#scan_what" onclick="showOnly(\''.$mg.'\');document.getElementById(\'not-only'.$mg.'\').checked=true;"'."$gt{$lt}b$gt$GOTMLS_scan_group$lt/b$gt$lt/a$gt{$lt}br /$gt\n$lt".'div class="rounded-corners" style="position: absolute; display: none; background-color: #CCF; margin: 0; padding: 10px; z-index: 10;" id="only'.$mg.'"'.$gt.$lt.'div style="padding-bottom: 6px;"'.$gt.GOTMLS_close_button('only'.$mg, 0).$lt.'b'.$gt.str_replace(" ", "&nbsp;", __("Only Scan These Folders:",'gotmls')).$lt.'/b'.$gt.$lt.'/div'.$gt.$scan_whatopts;
836 }
837 $scan_optjs .= "document.getElementById('only'+what).style.display = 'block';\n}";
838 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && GOTMLS_strlen(trim(" ".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])))
839 $scan_optjs .= "\nfunction auto_UPDATE_check() {\n\tif (auto_UPdef_check = document.getElementById('auto_UPDATE_definitions_".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]."'))\n\t\tauto_UPdef_check.checked = true;\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', auto_UPDATE_check)\nelse\n\tdocument.attachEvent('onload', auto_UPDATE_check);\n";
840 $scan_optjs .= "$lt/script$gt";
841 $GOTMLS_nonce_URL = GOTMLS_set_nonce(__FUNCTION__."790");
842 $scan_opts = "\n$lt".'form method="POST" id="GOTMLS_Form" name="GOTMLS_Form"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', $GOTMLS_nonce_URL).'"'.$gt.$lt.'input type="hidden" name="scan_type" id="scan_type" value="Complete Scan" /'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="submit" id="complete_scan" value="'.__("Run Complete Scan",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Complete Scan\';" /'.$gt.$lt.'/div'.$gt.'
843 '.$lt.'div style="float: right; margin: 0 5px;"'.$gt.$lt.'input style="display: none;" type="submit" id="custom_quick_scan" value="'.__("Custom Quick Scan",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Quick Scan\';" /'.$gt.$lt.'/div'.$gt.$lt.'div id="gotmls_wtl4" style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to look for:",'gotmls')."$lt/b$gt".GOTMLS_dashicon_button(__("Check for all threat types, if any of these are in red or otherwise unavailable then please download the latest definition updates.",'gotmls')).GOTMLS_dashicon_button(__("If you are having trouble Posting Array Variables to your site then you can temporarily remove this section to avoid errors when Scanning or Saving from this form.",'gotmls'), 'dismiss', 'color: #F00; text-decoration: none;" onclick="if (wtl4 = document.getElementById(\'gotmls_wtl4\')) wtl4.innerHTML = \'\'')."$lt/p$gt\n$lt".'div style="padding: 0 30px;"'.$gt;
844 $cInput = '"'.$gt.$lt.'input';
845 $pCheck = "$cInput checked";
846 $kCheck = "";
847 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $threat_level_name=>$threat_level) {
848 $scan_opts .= $lt.'div id="check_'.$threat_level.'_div" style="padding: 0; position: relative;';
849 if (($threat_level != "wp_core" && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level])) || isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level][GOTMLS_wp_version])) {
850 if ($threat_level != "potential" && in_array($threat_level,$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"])) {
851 $pCheck = " display: none;$cInput";
852 $scan_opts .= "$cInput checked";
853 } elseif ($threat_level == "potential")
854 $scan_opts .= $pCheck;
855 else
856 $scan_opts .= $cInput;
857 if ($threat_level != "potential")
858 $kCheck .= ",'$threat_level'";
859 $scan_opts .= ' type="checkbox" onchange="pCheck(this);" name="check[]" id="check_'.$threat_level.'_Yes" value="'.$threat_level.'" /'.$gt.' '.$lt.'a style="text-decoration: none;" href="#check_'.$threat_level.'_div_0" onclick="document.getElementById(\'check_'.$threat_level.'_Yes\').checked=true;pCheck(document.getElementById(\'check_'.$threat_level.'_Yes\'));showhide(\'dont_check_'.$threat_level.'\');"'."$gt{$lt}b$gt$threat_level_name$lt/b$gt$lt/a$gt\n";
860 if (isset($_GET["SESSION"])) {
861 $scan_opts .= "\n$lt".'div style="padding: 0 20px; position: relative; top: -18px; display: none;" id="dont_check_'.$threat_level.'"'.$gt.$lt.'a class="rounded-corners" style="position: absolute; left: 0; margin: 0; padding: 0 4px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;" href="#check_'.$threat_level.'_div_0" onclick="showhide(\'dont_check_'.$threat_level.'\');"'.$gt.'X'.$lt.'/a'.$gt;
862 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level] as $threat_name => $threat_regex)
863 $scan_opts .= $lt."br /$gt\n$lt".'input type="checkbox" name="dont_check[]" value="'.GOTMLS_htmlspecialchars($threat_name).'"'.(in_array(GOTMLS_sanitize($threat_name), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])?' checked /'.$gt.$lt.'script'.$gt.'showhide("dont_check_'.$threat_level.'", true);'.$lt.'/script'.$gt:' /'.$gt).(isset($_SESSION["GOTMLS_debug"][$threat_name])?$lt.'div style="float: right;"'.$gt.GOTMLS_htmlspecialchars(print_r($_SESSION["GOTMLS_debug"][$threat_name],1))."$lt/div$gt":"").GOTMLS_htmlspecialchars($threat_name);
864 $scan_opts .= "\n$lt/div$gt";
865 }
866 } else
867 $scan_opts .= $lt.'a title="'.__("Download Definition Updates to Use this feature",'gotmls').'"'.$gt.$lt.'img src="'.GOTMLS_images_path.'blocked.gif" height=16 width=16 alt="X"'.$gt.$lt.'b'.$gt.'&nbsp; '.$threat_level_name.$lt.'/b'.$gt.$lt.'br /'.$gt.$lt.'div style="padding: 14px;" id="check_'.$threat_level.'_div_NA"'.$gt.$lt.'span style="color: #F00"'.$gt.__("Download the new definitions (Right sidebar) to activate this feature.",'gotmls')."$lt/span$gt$lt/div$gt";
868 $scan_opts .= "\n$lt/div$gt";
869 }
870 $scan_opts .= $lt.'/div'.$gt.$lt.'/div'.$gt.'
871 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to scan:",'gotmls')."$lt/b$gt".GOTMLS_dashicon_button(sprintf(__("The higher up in the directory hierarchy you start the more sub-directories get scanned (e.g. scanning the %s directory will also include the sub-directories wp-content and plugins within it).",'gotmls'), $scan_root))."$lt/p$gt$scan_whatopts$scan_optjs$lt/div$gt\n$lt".'div style="float: left;" id="scanwhatfolder"'.$gt.$lt.'/div'.$gt.'
872 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Directory Scan Depth:",'gotmls')."$lt/b$gt".GOTMLS_dashicon_button(__("How many directories deep to scan: -1 is infinite depth, 0 to skip the file scan completely.",'gotmls'))."$lt/p$gt\n$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" value="'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"].'" name="scan_depth" size="5"'.$gt.$lt.'/div'.$gt.$lt.'/div'.$gt.$lt.'br style="clear: left;"'.$gt;
873 if (isset($_GET["SESSION"]) && isset($_SESSION["GOTMLS_debug"])) {$scan_opts .= $lt.'div style="float: right;"'.$gt.GOTMLS_htmlspecialchars(print_r(array("sess" => $_SESSION),1))."$lt/div$gt"; $_SESSION["GOTMLS_debug"] = array("GOTMLS_settings(811)" => microtime(true));}
874 if (isset($_GET["eli"])) {//still testing this option['total']['total']
875 if ($_GET["eli"] == "find") {
876 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && (count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) > 1)) {
877 $fe = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][0];
878 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][1];
879 } else {
880 $fe = " no";
881 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"] as $f => $e)
882 if (is_array($e) && in_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"], $e))
883 $fe = " $f";
884 }
885 } else
886 $fe = "";
887 $scan_opts .= "\n$lt".'div style="padding: 10px;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Custom RegExp:",'gotmls').$fe.$lt.'/b'.$gt.' ('.__("For very advanced users only. Do not use this without talking to Eli first. If used incorrectly you could easily break your site.",'gotmls').')'.$lt.'/p'.$gt.$lt.'input type="text" name="check_custom" style="width: 100%;" value="'.GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]).'" /'."$gt$lt/div$gt\n";
888 }
889 $QuickScan = $lt.((is_dir(dirname(__FILE__)."/../../../wp-includes") && is_dir(dirname(__FILE__)."/../../../wp-admin"))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&$GOTMLS_nonce_URL").'" class="button-primary" style="min-height: 22px; height: 22px; line-height: 13px; padding: 3px;">WP_Core</a':"!-- No wp-includes or wp-admin --").$gt;
890 foreach (array("Plugins", "Themes") as $ScanFolder)
891 $QuickScan .= '&nbsp;'.$lt.((is_dir(dirname(__FILE__)."/../../../wp-content/".strtolower($ScanFolder)))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&scan_only%5B%5D=wp-content/".strtolower($ScanFolder)."&$GOTMLS_nonce_URL")."\" class=\"button-primary\" style=\"min-height: 22px; height: 22px; line-height: 13px; padding: 3px;\"$gt$ScanFolder$lt/a":"!-- No $ScanFolder in wp-content --").$gt;
892 $scan_opts .= "\n$lt".'p'.$gt.$lt.'b'.$gt.__("Skip files with the following extensions:",'gotmls')."$lt/b$gt".(($default_exclude_ext!=implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))?" {$lt}a href=\"javascript:void(0);\" onclick=\"document.getElementById('exclude_ext').value = '$default_exclude_ext';\"{$gt}[Restore Defaults]$lt/a$gt":"").$lt.'/p'.$gt.'
893 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a comma separated list of file extentions to skip",'gotmls').'" name="exclude_ext" id="exclude_ext" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]).'" style="width: 100%;" /'."$gt$lt/div$gt$lt".'p'.$gt.$lt.'b'.$gt.__("Skip directories with the following names:",'gotmls')."$lt/b$gt$lt/p$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a folder name or comma separated list of folder names to skip",'gotmls').'" name="exclude_dir" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]).'" style="width: 100%;" /'.$gt.$lt.'/div'.$gt.'
894 '.$lt.'table style="width: 100%" cellspacing="10"'.$gt.$lt.'tr'.$gt.$lt.'td nowrap valign="top" style="white-space: nowrap; width: 1px;"'.$gt.$lt.'b'.$gt.__("Automatically Update Definitions:",'gotmls').$lt."br$gt$lt/b$gt$lt/td$gt$lt".'td'.$gt.$lt.'div id="UPDATE_definitions_div"'.$gt.$lt.'br'.$gt.$lt.'span style="color: #C00;"'.$gt.__("This feature is only available to registered users who have donated at a certain level.",'gotmls')."$lt/span$gt$lt/div$gt$lt/td$gt$lt".'td align="right" valign="bottom"'.$gt.$lt.'input type="submit" id="save_settings" value="'.__("Save Settings",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Save\';" /'."$gt$lt/td$gt$lt/tr$gt$lt/table$gt$lt/form$gt";
895 $title_tagline = $lt."li$gt Site Title: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogname'"));
896 $title_tagline .= "$lt/li$gt{$lt}li$gt Tagline: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogdescription'"));
897 if (preg_match('/h[\@a]ck[3e]d.*by/is', $title_tagline))
898 echo GOTMLS_error_div(sprintf(__("Your Site Title or Tagline suggests that you may have been hacked ...%sThis could impact the indexing of your site and may even lead to blacklisting. You can change those options on the %sGeneral Settings$lt/a$gt page.",'gotmls'), "$title_tagline$lt/li$gt", $lt.'a href="'.admin_url("options-general.php").'"'.$gt));
899 @ob_start();
900 $OB_default_handlers = array("default output handler", "zlib output compression");
901 $OB_handlers = @ob_list_handlers();
902 if (is_array($OB_handlers) && count($OB_handlers))
903 foreach ($OB_handlers as $OB_last_handler)
904 if (!in_array($OB_last_handler, $OB_default_handlers))
905 echo GOTMLS_error_div(sprintf(__("Another Plugin or Theme is using '%s' to handle output buffers. <br />This prevents actively outputting the buffer on-the-fly and could severely degrade the performance of this (and many other) Plugins. <br />Consider disabling caching and compression plugins (at least during the scanning process).",'gotmls'), GOTMLS_htmlspecialchars($OB_last_handler)));
906 GOTMLS_display_header();
907 $scan_groups = array_merge(array(__("Scanned Files",'gotmls')=>"scanned",__("Selected Folders",'gotmls')=>"dirs",__("Scanned Folders",'gotmls')=>"dir",__("Skipped Folders",'gotmls')=>"skipdirs",__("Skipped Files",'gotmls')=>"skipped",__("Scan/Read Errors",'gotmls')=>"errors",__("Quarantined Files",'gotmls')=>"bad"), $GLOBALS["GOTMLS"]["tmp"]["threat_levels"]);
908 echo $lt.'script type="text/javascript">
909 var percent = 0;
910 function pCheck(chkb) {
911 var kCheck = ['.trim($kCheck,",").'];
912 chk = true;
913 for (var i = 0; i < kCheck.length; i++) {
914 var chkbox = document.getElementById("check_"+kCheck[i]+"_Yes");
915 if (chkbox && chkb.id == "check_potential_Yes" && chkb.checked == false) {
916 chk = false;
917 chkbox.checked = true;
918 } else if (chkbox && chkbox.checked) {
919 chk = false;
920 }
921 }
922 if (chkbox = document.getElementById("check_potential_Yes"))
923 chkbox.checked = chk;
924 if (chk) {
925 document.getElementById("check_potential_div").style.display = "block";
926 alert("If you do not select any other threat types, then only potential threats will be found and the automatic fix will not be available!");
927 } else
928 document.getElementById("check_potential_div").style.display = "none";
929 }
930 function changeFavicon(percent) {
931 var oldLink = document.getElementById("wait_gif");
932 if (oldLink) {
933 if (percent >= 100) {
934 document.getElementsByTagName("head")[0].removeChild(oldLink);
935 var link = document.createElement("link");
936 link.id = "wait_gif";
937 link.type = "image/gif";
938 link.rel = "shortcut icon";
939 var threats = '.implode(" + ", array_merge($GLOBALS["GOTMLS"]["tmp"]["threat_levels"], array(__("Potential Threats",'gotmls')=>"errors",__("WP-Login Updates",'gotmls')=>"errors"))).';
940 if (threats > 0) {
941 if ((errors * 2) == threats)
942 linkhref = "blocked";
943 else
944 linkhref = "threat";
945 } else
946 linkhref = "checked";
947 link.href = "'.GOTMLS_images_path.'"+linkhref+".gif";
948 document.getElementsByTagName("head")[0].appendChild(link);
949 }
950 } else {
951 var icons = document.getElementsByTagName("link");
952 var link = document.createElement("link");
953 link.id = "wait_gif";
954 link.type = "image/gif";
955 link.rel = "shortcut icon";
956 link.href = "'.GOTMLS_images_path.'wait.gif";
957 // document.head.appendChild(link);
958 document.getElementsByTagName("head")[0].appendChild(link);
959 }
960 }
961 function update_status(title, time) {
962 sdir = (dir+direrrors);
963 if (arguments[2] >= 0 && arguments[2] <= 100)
964 percent = arguments[2];
965 else
966 percent = Math.floor((sdir*100)/dirs);
967 scan_state = "6F6";
968 if (percent == 100) {
969 showhide("pause_button", true);
970 showhide("pause_button");
971 title = "'.$lt.'b'.$gt.GOTMLS_strip4java(__("Scan Complete!",'gotmls')).$lt.'/b'.$gt.'";
972 } else
973 scan_state = "99F";
974 changeFavicon(percent);
975 if (sdir) {
976 if (arguments[2] >= 0 && arguments[2] <= 100)
977 timeRemaining = Math.ceil(((time-startTime)*(100/percent))-(time-startTime));
978 else
979 timeRemaining = Math.ceil(((time-startTime)*(dirs/sdir))-(time-startTime));
980 if (timeRemaining > 59)
981 timeRemaining = Math.ceil(timeRemaining/60)+" Minute";
982 else
983 timeRemaining += " Second";
984 if (timeRemaining.substr(0, 2) != "1 ")
985 timeRemaining += "s";
986 } else
987 timeRemaining = "Calculating Time";
988 timeElapsed = Math.ceil(time);
989 if (timeElapsed > 59)
990 timeElapsed = Math.floor(timeElapsed/60)+" Minute";
991 else
992 timeElapsed += " Second";
993 if (timeElapsed.substr(0, 2) != "1 ")
994 timeElapsed += "s";
995 divHTML = \''.$lt.'div align="center" style="vertical-align: middle; background-color: #ccc; z-index: 3; height: 18px; width: 100%; border: solid #000 1px; position: relative; padding: 10px 0;"'.$gt.$lt.'div style="height: 18px; padding: 10px 0; position: absolute; top: 0px; left: 0px; background-color: #\'+scan_state+\'; width: \'+percent+\'%"'.$gt.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; left: 10px; z-index: 5; line-height: 16px;" align="left"'.$gt.'\'+sdir+" Folder"+(sdir==1?"":"s")+" Checked'.$lt.'br /'.$gt.'"+timeElapsed+\' Elapsed'.$lt.'/div'.$gt.$lt.'div style="height: 38px; position: absolute; top: 0px; left: 0px; width: 100%; z-index: 5; line-height: 38px; font-size: 30px; text-align: center; box-sizing: content-box;"'.$gt.'\'+percent+\'%'.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; right: 10px; z-index: 5; line-height: 16px;" align="right"'.$gt.'\'+(dirs-sdir)+" Folder"+((dirs-sdir)==1?"":"s")+" Remaining'.$lt.'br /'.$gt.'"+timeRemaining+" Remaining'.$lt.'/div'.$gt.$lt.'/div'.$gt.'";
996 document.getElementById("status_bar").innerHTML = divHTML;
997 document.getElementById("status_text").innerHTML = title;
998 dis="none";
999 divHTML = \''.$lt.'ul style="float: right; margin: 0 20px; text-align: right;"'.$gt.'\';
1000 /*'.$lt.'!--*'.'/';
1001 $MAX = 0;
1002 $vars = "var i, intrvl, direrrors=0";
1003 $fix_button_js = "";
1004 $found = "";
1005 $li_js = ($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["scan_depth"]==1?"":"return false;");
1006 if ((isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Quick Scan") || (!(isset($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"])))) {
1007 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"] = array();
1008 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1009 if ($check != "potential")
1010 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"][] = $check;
1011 }
1012 foreach ($scan_groups as $scan_name => $scan_group) {
1013 if ($MAX++ == 6) {
1014 $quarantineCountOnly = GOTMLS_get_quarantine(true);
1015 $vars .= ", $scan_group=$quarantineCountOnly";
1016 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0)\n\t\tscan_state = ' potential'; \n\telse\n\t\tscan_state = '';\n\tdivHTML += '</ul><ul style=\"text-align: left;\"><li class=\"GOTMLS_li\"><a href=\"admin.php?page=GOTMLS_View_Quarantine\" class=\"GOTMLS_plugin".("'+scan_state+'\" title=\"".GOTMLS_strip4java(GOTMLS_View_Quarantine_LANGUAGE))."\">'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
1017 $found = "Found ";
1018 $fix_button_js = "\n\t\tdis='block';";
1019 } else {
1020 $val = 0;
1021 if ($MAX > 8 && !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
1022 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("Directory Scan Depth set to 0, no files will be scanned for this type of threat!",'gotmls'));
1023 elseif ($found && !in_array($scan_group, $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]))
1024 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("You are not currently scanning for this type of threat!",'gotmls'));
1025 else
1026 $potential_threat = "";
1027 $vars .= ", $scan_group=$val";
1028 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0) {\n\t\tscan_state = ' href=\"#found_$scan_group\" onclick=\"$li_js showhide(\\'found_$scan_group\\', true);\" class=\"GOTMLS_plugin $scan_group\"';$fix_button_js".($MAX>6?"\n\tshowhide('found_$scan_group', true);":"")."\n\t} else\n\t\tscan_state = ' class=\"GOTMLS_plugin$potential_threat\"';\n\tdivHTML += '<li class=\"GOTMLS_li\"".(($found && $scan_group == "potential" && !in_array($scan_group, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))?' style="display: none;"':"")."><a'+scan_state+'>$found'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
1029 }
1030 $li_js = "";
1031 if ($MAX > 11)
1032 $fix_button_js = "";
1033 }
1034 $ScanSettings = $lt.'div style="float: right;"'.$gt.GOTMLS_Run_Quick_Scan_LANGUAGE.":&nbsp;$QuickScan$lt/div$gt".GOTMLS_Scan_Settings_LANGUAGE;
1035 echo "/*--{$gt}*".'/
1036 document.getElementById("status_counts").innerHTML = divHTML+"'.$lt.'/ul'.$gt.'";
1037 document.getElementById("fix_button").style.display = dis;
1038 }
1039 '.$vars.';
1040 function showOnly(what) {
1041 document.getElementById("only_what").innerHTML = document.getElementById("only"+what).innerHTML;
1042 }
1043 var startTime = 0;
1044 '.$lt.'/script'.$gt.GOTMLS_box($ScanSettings, $scan_opts);
1045 $Settings_Saved = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -50px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";//script type='text/javascript'$gt\nalert('Settings Saved!');\n$lt/script$gt\n";
1046 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Save") {
1047 if ($GOTMLS_nonce_found) {
1048 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1049 echo $Settings_Saved;
1050 } else
1051 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Saving these settings requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1052 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scan_history());
1053 } elseif (isset($_REQUEST["scan_what"]) && is_numeric($_REQUEST["scan_what"]) && ($_REQUEST["scan_what"] > -1)) {
1054 if ($GOTMLS_nonce_found) {
1055 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1056 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"] = array();
1057 GOTMLS_update_scanlog(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1058 $cleadCache = false;
1059 if (function_exists('is_plugin_active')) {
1060 if (function_exists('wp_cache_clear_cache')) {
1061 wp_cache_clear_cache();
1062 $cleadCache = true;
1063 }
1064 if (function_exists('w3tc_pgcache_flush')) {
1065 w3tc_pgcache_flush();
1066 $cleadCache = true;
1067 }
1068 if (class_exists('WpFastestCache')) {
1069 $newCache = new WpFastestCache();
1070 $newCache->deleteCache();
1071 $cleadCache = true;
1072 }
1073
1074 }
1075 if ($cleadCache)
1076 str_replace("Settings Saved!", "Cache Cleared and Settings Saved!", $Settings_Saved);
1077 echo $Settings_Saved;
1078 if (!isset($_REQUEST["scan_type"]))
1079 $_REQUEST["scan_type"] = "Complete Scan";
1080 elseif ($_REQUEST["scan_type"] == "Quick Scan") {
1081 $li_js = "\nfunction testComplete() {\n\tif (percent != 100)\n\t\talert('".__("The Quick Scan was unable to finish because of a shortage of memory or a problem accessing a file. Please try using the Complete Scan, it is slower but it will handle these errors better and continue scanning the rest of the files.",'gotmls')."');\n}\nwindow.onload=testComplete;\n$lt/script$gt\n$lt".'script type="text/javascript"'.$gt;
1082 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
1083 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1084 if ($check != "potential")
1085 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"][] = $check;
1086 }
1087 $_SERVER_QUERY_STRING = "?";
1088 foreach ($_GET as $name => $value) {
1089 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1090 if (is_array($value)) {
1091 foreach ($value as $val)
1092 $_SERVER_QUERY_STRING .= rawurlencode($name).'[]='.rawurlencode($val).'&';
1093 } else
1094 $_SERVER_QUERY_STRING .= rawurlencode($name).'='.rawurlencode($value).'&';
1095 }
1096 }
1097 echo "\n$lt".'form method="POST" action="'.admin_url("admin-ajax.php$_SERVER_QUERY_STRING").'" target="GOTMLS_iFrame" name="GOTMLS_Form_clean" id="GOTMLS_Form_clean"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', $GOTMLS_nonce_URL).'"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_fix"'.$gt.$lt.'input type="hidden" id="GOTMLS_fixing" name="GOTMLS_fixing" value="1"'.$gt;
1098 foreach ($_POST as $name => $value) {
1099 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1100 if (is_array($value)) {
1101 foreach ($value as $val)
1102 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'[]" value="'.GOTMLS_htmlspecialchars($val).'"'.$gt;
1103 } else
1104 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'" value="'.GOTMLS_htmlspecialchars($value).'"'.$gt;
1105 }
1106 }
1107 echo "\n$lt".'script type="text/javascript"'.$gt.'showhide("inside_'.md5($ScanSettings).'");'.$lt.'/script'.$gt.GOTMLS_box(GOTMLS_htmlspecialchars($_REQUEST["scan_type"]).' Status', $lt.'div id="status_text"'.$gt.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="..."'.$gt.' '.GOTMLS_Loading_LANGUAGE.$lt.'/div'.$gt.$lt.'div id="status_bar"'.$gt.$lt.'/div'.$gt.$lt.'p id="pause_button" style="display: none; position: absolute; left: 0; text-align: center; margin-left: -30px; padding-left: 50%;"'.$gt.$lt.'input type="button" value="Pause" class="button-primary" onclick="pauseresume(this);" id="resume_button" /'.$gt.$lt.'/p'.$gt.$lt.'div id="status_counts"'.$gt.$lt.'/div'.$gt.$lt.'p id="fix_button" style="display: none; text-align: center;"'.$gt.$lt.'input id="repair_button" type="submit" value="'.GOTMLS_Automatically_Fix_LANGUAGE.'" class="button-primary" onclick="loadIframe(\'Examine Results\');" /'.$gt.$lt.'/p'.$gt);
1108 $scan_groups_UL = "";
1109 foreach ($scan_groups as $scan_name => $scan_group)
1110 $scan_groups_UL .= "\n{$lt}ul name=\"found_$scan_group\" id=\"found_$scan_group\" class=\"GOTMLS_plugin $scan_group\" style=\"background-color: #ccc; display: none; padding: 0;\"$gt{$lt}a class=\"rounded-corners\" name=\"link_$scan_group\" style=\"float: right; padding: 0 4px; margin: 5px 5px 0 30px; line-height: 16px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;\" href=\"#found_top\" onclick=\"showhide('found_$scan_group');\"{$gt}X$lt/a$gt{$lt}h3$gt$scan_name$lt/h3$gt\n".($scan_group=='potential'?$lt.'p'.$gt.' &nbsp; * '.__("NOTE: These are probably not malicious scripts (but it's a good place to start looking <u>IF</u> your site is infected and no Known Threats were found).",'gotmls').$lt.'/p'.$gt:($scan_group=='wp_core'?$lt.'p'.$gt.' &nbsp; * '.sprintf(__("NOTE: We have detected changes to the WordPress Core files on your site. This could be an intentional modification or the malicious work of a hacker. We can restore these files to their original state to preserve the integrity of your original WordPress %s installation.",'gotmls'), GOTMLS_wp_version).' (for more info '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-core-files/"'.$gt.__("read my blog",'gotmls').$lt.'/a'.$gt.').'.$lt.'/p'.$gt:$lt.'br /'.$gt)).$lt.'/ul'.$gt;
1111 if (!($dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + (INT) $_REQUEST["scan_what"])))))
1112 $dir = "/";
1113 $scanlog = array("dir" => $dir, "start" => time(), "type" => GOTMLS_sanitize($_REQUEST["scan_type"]));
1114 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && count($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) == 1 && ($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"][0] == "db_scan"))
1115 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = 0;
1116 $scanlog["settings"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"];
1117 if (isset($_REQUEST['scan_only']))
1118 $scanlog['scan_only'] = $_REQUEST['scan_only'];
1119 GOTMLS_update_scanlog(array("scan" => $scanlog));
1120 echo GOTMLS_box($lt.'div id="GOTMLS_scan_dir" style="float: right;"'.$gt.'&nbsp;('.(isset($GLOBALS["GOTMLS"]["scan"]["log"]["scan"]["dir"]) ? $GLOBALS["GOTMLS"]["scan"]["log"]["scan"]["dir"] : "Unknown path").")&nbsp;$lt/div$gt".__("Scan Details:",'gotmls'), $scan_groups_UL);
1121 $no_flush_LANGUAGE = __("Not flushing OB Handlers: %s",'gotmls');
1122 if (isset($_REQUEST["no_ob_end_flush"]))
1123 echo GOTMLS_error_div(sprintf($no_flush_LANGUAGE, GOTMLS_htmlspecialchars(print_r(ob_list_handlers(), 1))));
1124 elseif (is_array($OB_handlers) && count($OB_handlers)) {
1125 // $GOTMLS_OB_handlers = get_option("GOTMLS_OB_handlers", array());
1126 foreach (array_reverse($OB_handlers) as $OB_handler) {
1127 if (isset($GOTMLS_OB_handlers[$OB_handler]) && $GOTMLS_OB_handlers[$OB_handler] == "no_end_flush")
1128 echo GOTMLS_error_div(sprintf($no_flush_LANGUAGE, GOTMLS_htmlspecialchars($OB_handler)));
1129 elseif (in_array($OB_handler, $OB_default_handlers)) {
1130 // $GOTMLS_OB_handlers[$OB_handler] = "no_end_flush";
1131 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1132 @ob_end_flush();
1133 // $GOTMLS_OB_handlers[$OB_handler] = "ob_end_flush";
1134 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1135 }
1136 }
1137 }
1138 @ob_start();
1139 echo "\n{$lt}script type=\"text/javascript\"$gt$li_js\n/*{$lt}!--*"."/";
1140 if (!(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])) {
1141 echo GOTMLS_return_threat("dirs", "wait", $dir).GOTMLS_update_status(sprintf(__("Preparing %s",'gotmls'), GOTMLS_replace_dirname($dir)), 0);//GOTMLS_return_threat("skipdirs", "blocked", $dir, GOTMLS_error_link("Directory Scan Depth set to 0, no files will be scanned!"));
1142 $GLOBALS["GOTMLS"]["tmp"]["scanfiles"][GOTMLS_encode($dir)] = GOTMLS_strip4java(GOTMLS_replace_dirname($dir));
1143 } elseif (is_dir($dir)) {
1144 $GOTMLS_dirs_at_depth[0] = 1;
1145 $GOTMLS_dir_at_depth[0] = 0;
1146 if (isset($_REQUEST['scan_only']) && is_array($_REQUEST['scan_only'])) {
1147 $GOTMLS_dirs_at_depth[0] += (count($_REQUEST['scan_only']) - 1);
1148 foreach ($_REQUEST['scan_only'] as $only_dir)
1149 if (is_dir(GOTMLS_trailingslashit($dir).$only_dir))
1150 GOTMLS_readdir(GOTMLS_trailingslashit($dir).$only_dir);
1151 } else
1152 GOTMLS_readdir($dir);
1153 } else
1154 echo GOTMLS_return_threat("errors", "blocked", $dir, GOTMLS_error_link("Not a valid directory!"));
1155 if ($_REQUEST["scan_type"] == "Quick Scan")
1156 echo GOTMLS_update_status(__("Completed!",'gotmls'), 100);
1157 else {
1158 echo GOTMLS_update_status(__("Starting Scan ...",'gotmls'));
1159 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && in_array("db_scan", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))
1160 $DB_scan_JS = ", 'db_scan'";
1161 if (isset($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]) && in_array("db_scan", $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]))
1162 echo GOTMLS_return_threat("dirs", "wait", "db_scan");//.GOTMLS_update_status(__("Starting Database Scan ...",'gotmls'));
1163 //else $DB_scan_JS = "";
1164 GOTMLS_flush('script');
1165 echo "/*--{$gt}*"."/\nvar scriptSRC = '".GOTMLS_admin_url('GOTMLS_scan', $GOTMLS_nonce_URL.'&mt='.$GLOBALS["GOTMLS"]["tmp"]["mt"].'&GOTMLS_scan=')."';\nvar scanfilesArKeys = ['".implode("','", array_keys($GLOBALS["GOTMLS"]["tmp"]["scanfiles"]))."'$DB_scan_JS];\nvar scanfilesArNames = ['Scanning ".implode("','Scanning ", $GLOBALS["GOTMLS"]["tmp"]["scanfiles"])."'".str_replace("db_scan", "Starting Database Scan ...", $DB_scan_JS).'];
1166 var scanfilesI = 0;
1167 var stopScanning;
1168 var gotStuckOn = -1;
1169 function scanNextDir(gotStuck) {
1170 clearTimeout(stopScanning);
1171 if (gotStuck > -1) {
1172 gotStuck = gotStuckOn;
1173 if (scanfilesArNames[gotStuck].substr(0, 3) != "Re-" && scanfilesArNames[gotStuck].substr(0, 10) != "Got Stuck ") {
1174 if (scanfilesArNames[gotStuck].substr(0, 9) == "Checking ") {
1175 scanfilesArNames.push(scanfilesArNames[gotStuck]);
1176 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_skip_file[]="+encodeURIComponent(scanfilesArNames[gotStuck].substr(9)));
1177 } else {
1178 scanfilesArNames.push("Re-"+scanfilesArNames[gotStuck]);
1179 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_only_file=");
1180 }
1181 } else {
1182 var uri = scanfilesArKeys[gotStuck].split("&limit=", 2);
1183 var skipdir = (scanfilesArKeys[gotStuck]+"&").split("&",2);
1184 if (uri.length == 2) {
1185 var lim = (uri[1]+"&").split("&", 2);
1186 if (isNaN(lim[0]))
1187 lim[0] = 1024;
1188 else
1189 lim[0] = Math.round(lim[0]/2);
1190 scanfilesArKeys.push(uri[0]+"&limit="+lim[0]+"&"+lim[1]+"&GOTMLS_skip_dir="+skipdir[0]);
1191 } else {
1192 var lim = ["2048"];
1193 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&limit=2048&GOTMLS_skip_dir="+skipdir[0]);
1194 }
1195 scanfilesArNames.push("Got Stuck ("+lim[0]+") "+scanfilesArNames[gotStuck]);
1196 }
1197 }
1198 if (document.getElementById("resume_button").value != "Pause") {
1199 stopScanning=setTimeout(function() {scanNextDir(-1);}, 1000);
1200 startTime++;
1201 } else if (scanfilesI < scanfilesArKeys.length) {
1202 document.getElementById("status_text").innerHTML = scanfilesArNames[scanfilesI];
1203 var newscript = document.createElement("script");
1204 newscript.setAttribute("src", scriptSRC+scanfilesArKeys[scanfilesI]);
1205 divx = document.getElementById("found_scanned");
1206 if (divx)
1207 divx.appendChild(newscript);
1208 gotStuckOn = scanfilesI++;
1209 stopScanning=setTimeout(function() {scanNextDir(0);}, '.$GLOBALS["GOTMLS"]["tmp"]['execution_time'].'000);
1210 }
1211 }
1212 startTime = ('.ceil(time()-$GLOBALS["GOTMLS"]["scan"]["log"]["scan"]["start"]).'+3);
1213 stopScanning=setTimeout(function() {scanNextDir(-1);}, 3000);
1214 function pauseresume(butt) {
1215 if (butt.value == "Resume")
1216 butt.value = "Pause";
1217 else
1218 butt.value = "Resume";
1219 }
1220 showhide("pause_button", true);'."\n/*{$lt}!--*"."/";
1221 }
1222 if (@ob_get_level()) {
1223 GOTMLS_flush('script');
1224 @ob_end_flush();
1225 }
1226 echo "/*--{$gt}*"."/\n$lt/script$gt$lt/form$gt";
1227 } else
1228 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Starting a Complete Scan requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1229 } else
1230 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scan_history());
1231 echo "\n$lt/div$gt$lt/div$gt$lt/div$gt";
1232 }
1233
1234 function GOTMLS_login_error($elementId, $ERROR, $alert_txt = "") {
1235 $js = "\nif (GOTMLS_field = document.getElementById('$elementId'))\n\tGOTMLS_field.innerHTML = '<h2 style=\"text-align: center\">".GOTMLS_strip4java($ERROR)."</h2>';";
1236 return $js;
1237 }
1238
1239 function GOTMLS_print_login_form($ops = array()) {
1240 if (!is_array($ops))
1241 $ops = array();
1242 echo GOTMLS_login_form($ops);
1243 }
1244 if (defined("GOTMLS_SESSION_TIME") && is_numeric(GOTMLS_SESSION_TIME)) {
1245 add_action("login_form", "GOTMLS_print_login_form");
1246 }
1247
1248 function GOTMLS_login_form($ops = array(), $form_id = "", $shortcode = "") {
1249 $gt = ">"; // This local variable never changes
1250 $lt = "<"; // This local variable never changes
1251 $up = "";
1252 foreach (array("form_id" => "loginform", "top" => "-200px", "height" => "280px", "u" => "log", "p" => "pwd") as $field => $default) {
1253 if (!(isset($ops["$field"]) && preg_match('/^[\w\-]++$/', $ops["$field"]) && GOTMLS_strlen($ops["$field"]) < 50))
1254 $ops["$field"] = $default;
1255 if (GOTMLS_strlen($field) == 1)
1256 $up .= "&GOTMLS_$field=".rawurlencode($ops["$field"]);
1257 }
1258 if (!(isset($GLOBALS["GOTMLS"]["tmp"]["loginform_id"]) && $GLOBALS["GOTMLS"]["tmp"]["loginform_id"]))
1259 $GLOBALS["GOTMLS"]["tmp"]["loginform_id"] = 0;
1260 $form_id = ++$GLOBALS["GOTMLS"]["tmp"]["loginform_id"];
1261 $loading_bits = '" id="loading_BRUTEFORCE_'.$form_id.'"'.$gt.$lt.'div style="top: '.$ops["top"].'; position: relative; background-color: #FFF; z-index: 99999;"'.$gt.$lt.'img style="height: '.$ops["height"];
1262 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]) {
1263 $loading_bits = ' z-index: 9999; opacity: 0; top: 0; left: 0; width: 100%; height: 100%;'.$loading_bits;
1264 $other = " display: none;";
1265 } else
1266 $other = "";
1267 if (defined("GOTMLS_LOGIN_PROTECTION") && preg_match('/^[\da-f]{32}$/i', GOTMLS_LOGIN_PROTECTION)) {
1268 $ajaxURL = GOTMLS_admin_url("GOTMLS_logintime", GOTMLS_set_nonce($sess = GOTMLS_LOGIN_PROTECTION, GOTMLS_REMOTEADDR)."$up&GOTMLS_sess=$sess&GOTMLS_form_id=$form_id&GOTMLS_time=");
1269 return "$lt!-- Loading GOTMLS Brute-Force Protection --$gt$lt".'div style="position: absolute;'.$loading_bits.';" alt="Loading Brute-Force Protection ..." src="'.GOTMLS_images_path."GOTMLS-Loading.gif\" /$gt{$lt}div id='checking_BRUTEFORCE_$form_id'$gt Checking for JavaScript ... $lt/div$gt$lt/div$gt$lt/div$gt\n$lt".'div style="font-weight: bold;'."$other\"$gt$lt".'img style="height: 20px; vertical-align: middle;" alt="Brute-Force Protection from GOTMLS. NET" src="'.GOTMLS_images_path."checked.gif\" /$gt Brute-Force Protection is Active$lt/div$gt$lt".'input type="hidden" name="GOTMLS_sess" id="GOTMLS_sess_id_'.$form_id.'" value="'."$sess\" /$gt$lt".'input type="hidden" id="GOTMLS_offset_id_'.$form_id.'" value="0" name="GOTMLS_time" /'.$gt.$lt.'script type="text/javascript"'."$gt\nfunction GOTMLS_chk_session_$form_id() {\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_script = document.createElement('script');\nGOTMLS_login_script.src = '$ajaxURL'+GOTMLS_login_offset.getTime();\nif (GOTMLS_field = document.getElementById('GOTMLS_offset_id_$form_id')) {\n\tGOTMLS_field.value = GOTMLS_login_offset.getTime();\n}".GOTMLS_login_error("checking_BRUTEFORCE_$form_id", ' Checking for Session ... ')."\nif (GOTMLS_loading_gif = document.getElementById('loading_BRUTEFORCE_$form_id')) GOTMLS_loading_gif.style.display = 'block';\ndocument.head.appendChild(GOTMLS_login_script);\n}\nGOTMLS_chk_session_$form_id();\nsetInterval(function (){GOTMLS_chk_session_$form_id();}, 150000);\n$lt/script$gt\n";
1270 } else
1271 return "$lt!-- GOTMLS Brute-Force Protection is Disabled in the Firewall Options --$gt";
1272 }
1273 add_shortcode("gotmls-brute-force-protection", "GOTMLS_login_form");
1274
1275 function GOTMLS_ihc_login_form($ops = array()) {
1276 $gt = ">"; // This local variable never changes
1277 $lt = "<"; // This local variable never changes
1278 $return = "$lt!-- ihc_login_form: Indeed Ultimate Membership Pro is not installed --$gt";
1279 $form_end = "$lt/form$gt";
1280 if (function_exists("ihc_login_form")) {
1281 if (strpos($return = ihc_login_form($ops), $form_end))
1282 $return = str_replace($form_end, GOTMLS_login_form(array("form_id" => "ihc_login_form", "top" => "-280px")).$form_end, $return);
1283 else
1284 $return .= "\n$lt!-- ihc_login_form: form_end not found --$gt";
1285 }
1286 return "\n$lt!-- ihc_login_form: GOTMLS Brute-Force Protection integration with indeed-membership-pro --$gt$return";
1287 }
1288
1289 function GOTMLS_ajax_logintime() {
1290 if (headers_sent($filename, $linenum))
1291 $error_txt = sprintf("//Headers already sent in %s on line %s.\n", $filename, $linenum);
1292 else
1293 $error_txt = __("Please refresh the page before attempting to login.", 'gotmls');
1294 @header("Content-type: text/javascript");
1295 if (!defined("GOTMLS_FORMID"))
1296 define("GOTMLS_FORMID", (isset($_GET["GOTMLS_form_id"])&&is_numeric($_GET["GOTMLS_form_id"]))?(INT) $_GET["GOTMLS_form_id"]:0);
1297 $form_id = GOTMLS_FORMID;
1298 if (defined("GOTMLS_SESS_ERROR"))
1299 die(GOTMLS_login_error("checking_BRUTEFORCE_$form_id", GOTMLS_SESS_ERROR, $error_txt));
1300 elseif (defined("GOTMLS_LOGIN_PROTECTION") && preg_match('/^[\da-f]{32}$/i', GOTMLS_LOGIN_PROTECTION) && defined("GOTMLS_SESSION_TIME") && is_numeric(GOTMLS_SESSION_TIME) && defined("GOTMLS_logintime_JS") && defined("GOTMLS_SESS")) {
1301 if (GOTMLS_get_nonce(substr(GOTMLS_SESS, 0, 32), GOTMLS_REMOTEADDR))
1302 die(GOTMLS_logintime_JS);
1303 else
1304 die(GOTMLS_login_error("checking_BRUTEFORCE_$form_id", GOTMLS_Invalid_Nonce("//DEBUG: $form_id "), $error_txt));
1305 } else
1306 die(GOTMLS_login_error("checking_BRUTEFORCE_$form_id", 'Login Session Not Started!', $error_txt));
1307 }
1308
1309 function GOTMLS_ajax_lognewkey() {
1310 @header("Content-type: text/javascript");
1311 if (isset($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]) && $GLOBALS["GOTMLS"]["tmp"]["HeadersError"])
1312 echo "\n//Header Error: ".GOTMLS_strip4java(GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]));
1313 if (GOTMLS_get_nonce()) {
1314 if (isset($_POST["GOTMLS_installation_key"]) && ($_POST["GOTMLS_installation_key"] == GOTMLS_installation_key)) {
1315 $keys = GOTMLS_uckserialize(get_option('GOTMLS_Installation_Keys', array()));
1316 if (is_array($keys)) {
1317 $count = count($keys);
1318 if (!isset($keys[GOTMLS_installation_key]))
1319 $keys = array_merge($keys, array(GOTMLS_installation_key => GOTMLS_siteurl));
1320 } else
1321 $keys = array(GOTMLS_installation_key => GOTMLS_siteurl);
1322 update_option("GOTMLS_Installation_Keys", serialize($keys));
1323 die("\n//$count~".count($keys));
1324 } else
1325 die("\n//0");
1326 } else
1327 die(GOTMLS_Invalid_Nonce("\n//Log New Key Error: ")."\n");
1328 }
1329
1330 function GOTMLS_ajax_log_session() {
1331 $fail_msg = "/* GOTMLS SESSION FAIL */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\ndocument.getElementById('GOTMLS_patch_searching').innerHTML = '<div class=\"error\">".GOTMLS_strip4java(__("Your Server could not start a Session!",'gotmls'));
1332 if (headers_sent($filename, $linenum)) {
1333 if (!$filename)
1334 $filename = __("an unknown file",'gotmls');
1335 if (!is_numeric($linenum))
1336 $linenum = __("unknown",'gotmls');
1337 $fail_msg .= sprintf(__('<b>Headers already sent</b> in %1$s on line %2$s.','gotmls'), $filename, $linenum);
1338 die($fail_msg."</div>';");
1339 }
1340 if (is_file(GOTMLS_plugin_path."safe-load/session.php"))
1341 require_once(GOTMLS_plugin_path."safe-load/session.php");
1342 GOTMLS_session_start();
1343 if (!($sess_id = session_id()))
1344 session_start();
1345 header("Content-type: text/javascript");
1346 if (isset($_SESSION["GOTMLS_SESSION_TEST"]))
1347 die("/* GOTMLS SESSION PASS */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nshowhide('GOTMLS_patch_searching', true);\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_patch_searching');\n\tshowhide('GOTMLS_patch_button', true);\n}\n");
1348 else {
1349 $_SESSION["GOTMLS_SESSION_TEST"] = 1;
1350 if (isset($_GET["SESSION"]) && is_numeric($_GET["SESSION"]) && $_GET["SESSION"] > 0)
1351 die($fail_msg."</div>';");
1352 else
1353 die("/* GOTMLS SESSION TEST */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nstopCheckingSession = checkupdateserver('".GOTMLS_script_URI."&SESSION=1');");
1354 }
1355 }
1356
1357 function GOTMLS_set_plugin_action_links($links_array, $plugin_file) {
1358 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * GOTMLS_strlen($plugin_file))) && GOTMLS_strlen($plugin_file) > 10)
1359 $links_array = array_merge(array('<a href="'.admin_url('admin.php?page=GOTMLS-settings').'">'.GOTMLS_Scan_Settings_LANGUAGE.'</a>'), $links_array);
1360 return $links_array;
1361 }
1362 add_filter("plugin_action_links", "GOTMLS_set_plugin_action_links", 1, 2);
1363
1364 function GOTMLS_set_plugin_row_meta($links_array, $plugin_file) {
1365 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * GOTMLS_strlen($plugin_file))) && GOTMLS_strlen($plugin_file) > 10)
1366 $links_array = array_merge($links_array, array('<a target="_blank" href="'.GOTMLS_plugin_home.'faqs/">FAQ</a>','<a target="_blank" href="'.GOTMLS_plugin_home.'support/">Support</a>','<a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span>Donate</a>'));
1367 return $links_array;
1368 }
1369 add_filter("plugin_row_meta", "GOTMLS_set_plugin_row_meta", 1, 2);
1370
1371 function GOTMLS_in_plugin_update_message($args) {
1372 $transient_name = 'GOTMLS_upgrade_notice_'.preg_replace('/[^0-9\.\_]/', "", $args["Version"].'_'.$args["new_version"]);
1373 if ((false === ($upgrade_notice = get_transient($transient_name))) && ($ret = GOTMLS_get_URL("https://plugins.svn.wordpress.org/gotmls/trunk/readme.txt"))) {
1374 $upgrade_notice = '';
1375 if ($match = preg_split('/==\s*Upgrade Notice\s*==\s+/i', $ret)) {
1376 if (preg_match('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]))
1377 $notice = (array) preg_split('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]);
1378 else
1379 $notice = (array) preg_split('/\n+=/is', $match[1]."\n=");
1380 if (preg_match_all('/=\s*([\.0-9]+)\s*=\s*([^=]+)/i', $notice[0], $matches, PREG_SET_ORDER)) {
1381 foreach ($matches as $m)
1382 $upgrade_notice .= GOTMLS_html_tags(array('br /' => array('span' => GOTMLS_html_tags(array('b' => esc_html($m[1]).': ')).esc_html($m[2]))));
1383 set_transient($transient_name, $upgrade_notice, DAY_IN_SECONDS);
1384 }
1385 }
1386 }
1387 echo wp_kses($upgrade_notice, array('br' => array(), 'span' => array(), 'b' => array()));
1388 }
1389 add_action("in_plugin_update_message-gotmls/index.php", "GOTMLS_in_plugin_update_message");
1390
1391 function GOTMLS_debug_hook($function) {
1392 return "\n<!-- Debugging $function ".round(microtime(true)-$GLOBALS["GOTMLS"]["MT"], 4)." -->\n";
1393 }
1394
1395 function GOTMLS_begin_wp_body_open() {
1396 return GOTMLS_debug_hook(__FUNCTION__);
1397 }
1398 function GOTMLS_finish_wp_body_open() {
1399 return GOTMLS_debug_hook(__FUNCTION__);
1400 }
1401 function GOTMLS_begin_wp_head() {
1402 echo GOTMLS_debug_hook(__FUNCTION__);
1403 }
1404 function GOTMLS_finish_wp_head() {
1405 echo GOTMLS_debug_hook(__FUNCTION__);
1406 }
1407 function GOTMLS_begin_wp_footer() {
1408 echo GOTMLS_debug_hook(__FUNCTION__);
1409 }
1410 function GOTMLS_finish_wp_footer() {
1411 echo GOTMLS_debug_hook(__FUNCTION__);
1412 }
1413
1414 if (isset($_REQUEST["eli"]) && ($_REQUEST["eli"] == "debug")) {
1415 foreach (array('wp_head', 'wp_body_open', 'wp_footer') as $wp_hook) {
1416 if (function_exists("GOTMLS_begin_$wp_hook"))
1417 add_action($wp_hook, "GOTMLS_begin_$wp_hook", 0);
1418 if (function_exists("GOTMLS_finish_$wp_hook"))
1419 add_action($wp_hook, "GOTMLS_finish_$wp_hook", 999999);
1420 }
1421 }
1422
1423 function GOTMLS_admin_init() {
1424 GOTMLS_define("GOTMLS_get_version_URL", GOTMLS_get_version("URL"));
1425 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]))
1426 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = 2;
1427 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
1428 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = -1;
1429 if (isset($_REQUEST["scan_type"]) && ($_REQUEST["scan_type"] == "Quick Scan")) {
1430 if (!isset($_REQUEST["scan_what"])) $_REQUEST["scan_what"] = 2;
1431 if (!isset($_REQUEST["scan_only"])) {
1432 $_REQUEST["scan_only"] = array("","wp-includes","wp-admin");
1433 $dirs = GOTMLS_explode_dir(__FILE__);
1434 $dir = ABSPATH;//implode(GOTMLS_slash(), array_slice($dirs, 0, -2));
1435 $files = GOTMLS_getfiles($dir);
1436 $dirs = array();
1437 if (isset($files) && is_array($files) && count($files))
1438 foreach ($files as $file)
1439 if (is_dir(GOTMLS_trailingslashit($dir).$file))
1440 $dirs[] = GOTMLS_trailingslashit($dir).$file;
1441 $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"] = array_merge($dirs, $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"]);
1442 $_REQUEST["scan_depth"] = -1;
1443 } elseif (!isset($_REQUEST["scan_depth"]))
1444 $_REQUEST["scan_depth"] = 2;
1445 if ($_REQUEST["scan_only"] && !is_array($_REQUEST["scan_only"]))
1446 $_REQUEST["scan_only"] = array($_REQUEST["scan_only"]);
1447 }
1448 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]))
1449 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = "";
1450 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]) && is_numeric($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1451 $scan_level = intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);
1452 else
1453 $scan_level = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1454 $ajax_functions = array('load_update', 'log_session', 'empty_trash', 'fix', 'logintime', 'lognewkey', 'position', 'scan', 'View_Quarantine', 'whitelist');
1455 if (GOTMLS_get_nonce()) {
1456 if (isset($_REQUEST["dont_check"]) && is_array($_REQUEST["dont_check"]) && count($_REQUEST["dont_check"]))
1457 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = GOTMLS_sanitize($_REQUEST["dont_check"]);
1458 elseif (isset($_POST["scan_type"]) || !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])))
1459 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = array();
1460 if (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"]))
1461 $scan_level = intval($_POST["scan_level"]);
1462 if (isset($scan_level) && is_numeric($scan_level))
1463 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = intval($scan_level);
1464 }
1465 foreach ($ajax_functions as $ajax_function) {
1466 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1467 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", substr($ajax_function, 0, 3) == "log"?"GOTMLS_ajax_$ajax_function":"GOTMLS_ajax_nopriv");
1468 }
1469 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1470 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1471 }
1472 add_action("admin_init", "GOTMLS_admin_init");
1473
1474 function GOTMLS_init() {
1475 load_plugin_textdomain('gotmls', false, basename(GOTMLS_plugin_path).'/languages');
1476 GOTMLS_define("GOTMLS_Failed_to_list_LANGUAGE", __("Failed to list files in directory!",'gotmls'));
1477 GOTMLS_define("GOTMLS_Run_Quick_Scan_LANGUAGE", __("Quick Scan",'gotmls'));
1478 GOTMLS_define("GOTMLS_View_Quarantine_LANGUAGE", __("View Quarantine",'gotmls'));
1479 GOTMLS_define("GOTMLS_View_Scan_Log_LANGUAGE", __("View Scan History",'gotmls'));
1480 GOTMLS_define("GOTMLS_require_version_LANGUAGE", sprintf(__("This Plugin requires WordPress version %s or higher",'gotmls'), GOTMLS_require_version));
1481 GOTMLS_define("GOTMLS_Scan_Settings_LANGUAGE", __("Scan Settings",'gotmls'));
1482 GOTMLS_define("GOTMLS_Loading_LANGUAGE", __("Loading, Please Wait ...",'gotmls'));
1483 GOTMLS_define("GOTMLS_Automatically_Fix_LANGUAGE", __("Automatically Fix SELECTED Files Now",'gotmls'));
1484 GOTMLS_define("GOTMLS_position_msg", __("Default position",'gotmls'));
1485 $GLOBALS["GOTMLS"]["tmp"]["threat_levels"] = array(__("Database Injections",'gotmls')=>"db_scan",__("htaccess Threats",'gotmls')=>"htaccess",__("TimThumb Exploits",'gotmls')=>"timthumb",__("Known Threats",'gotmls')=>"known",__("Core File Changes",'gotmls')=>"wp_core",__("Potential Threats",'gotmls')=>"potential");
1486 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))
1487 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
1488 if (defined("GOTMLS_SESSION_TIME") && is_numeric(GOTMLS_SESSION_TIME)) {
1489 if (function_exists("ihc_login_form"))
1490 add_shortcode("ihc-login-form", "GOTMLS_ihc_login_form");
1491 if (function_exists("GOTMLS_print_up_login_form")) {
1492 if (function_exists("wc_get_template"))
1493 add_action("woocommerce_login_form", "GOTMLS_print_up_login_form");
1494 if (function_exists("wpum_login_form"))
1495 add_action("wpum_before_submit_button_login_form", "GOTMLS_print_up_login_form");
1496 }
1497 }
1498 register_post_type(
1499 'gotmls_quarantine',
1500 array(
1501 'labels' => array(
1502 'name' => _x( 'Quarantine', 'post type general name' ),
1503 'singular_name' => _x( 'Quarantine', 'post type singular name' ),
1504 'view_item' => __( 'View Quarantine Record' ),
1505 'all_items' => __( 'All Quarantine Records' ),
1506 ),
1507 'public' => false,
1508 'map_meta_cap' => true,
1509 'hierarchical' => false,
1510 'rewrite' => false,
1511 'query_var' => false,
1512 'can_export' => false,
1513 'delete_with_user' => false,
1514 'supports' => array( 'title', 'author', 'editor', 'excerpt', 'custom-fields' ),
1515 'capability_type' => 'customize_gotmls_quarantine',
1516 'capabilities' => array(
1517 'create_posts' => 'customize',
1518 'delete_others_posts' => 'customize',
1519 'delete_post' => 'customize',
1520 'delete_posts' => 'customize',
1521 'delete_private_posts' => 'customize',
1522 'delete_published_posts' => 'do_not_allow',
1523 'edit_others_posts' => 'do_not_allow',
1524 'edit_post' => 'do_not_allow',
1525 'edit_posts' => 'do_not_allow',
1526 'edit_private_posts' => 'do_not_allow',
1527 'edit_published_posts' => 'do_not_allow',
1528 'publish_posts' => 'customize',
1529 'read' => 'do_not_allow',
1530 'read_post' => 'do_not_allow',
1531 'read_private_posts' => 'customize',
1532 ),
1533 )
1534 );
1535 register_post_type(
1536 'gotmls_results',
1537 array(
1538 'labels' => array(
1539 'name' => _x( 'Results', 'post type general name' ),
1540 'singular_name' => _x( 'Result', 'post type singular name' ),
1541 'view_item' => __( 'View Scan Results' ),
1542 'all_items' => __( 'All Scans' ),
1543 ),
1544 'public' => false,
1545 'map_meta_cap' => true,
1546 'hierarchical' => true,
1547 'rewrite' => false,
1548 'query_var' => false,
1549 'can_export' => false,
1550 'delete_with_user' => false,
1551 'supports' => array( 'title', 'author', 'editor', 'excerpt', 'custom-fields' ),
1552 'capability_type' => 'customize_gotmls_reults',
1553 'capabilities' => array(
1554 'create_posts' => 'customize',
1555 'delete_others_posts' => 'customize',
1556 'delete_post' => 'customize',
1557 'delete_posts' => 'customize',
1558 'delete_private_posts' => 'customize',
1559 'delete_published_posts' => 'do_not_allow',
1560 'edit_others_posts' => 'do_not_allow',
1561 'edit_post' => 'do_not_allow',
1562 'edit_posts' => 'do_not_allow',
1563 'edit_private_posts' => 'do_not_allow',
1564 'edit_published_posts' => 'do_not_allow',
1565 'publish_posts' => 'customize',
1566 'read' => 'do_not_allow',
1567 'read_post' => 'do_not_allow',
1568 'read_private_posts' => 'customize',
1569 ),
1570 )
1571 );
1572 }
1573 add_action("init", "GOTMLS_init");
1574
1575 function GOTMLS_ajax_position() {
1576 if (GOTMLS_get_nonce(GOTMLS_position_msg)) {
1577 $properties = array("body" => 'style="margin: 0; padding: 0;"');
1578 if (isset($_GET["GOTMLS_msg"]) && $_GET["GOTMLS_msg"] == GOTMLS_position_msg) {
1579 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"] = $GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"];
1580 $gl = '><';
1581 $properties["html"] = $gl.'head'.$gl.'script type="text/javascript">
1582 if (curDiv = window.parent.document.getElementById("div_file")) {
1583 curDiv.style.left = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0].'";
1584 curDiv.style.top = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1].'";
1585 curDiv.style.height = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2].'";
1586 curDiv.style.width = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3].'";
1587 }
1588 </script'.$gl.'/head';
1589 } elseif (isset($_GET["GOTMLS_x"]) || isset($_GET["GOTMLS_y"]) || isset($_GET["GOTMLS_h"]) || isset($_GET["GOTMLS_w"])) {
1590 if (isset($_GET["GOTMLS_x"]))
1591 GOTMLS_validate_position(0, $_GET["GOTMLS_x"]);
1592 if (isset($_GET["GOTMLS_y"]))
1593 GOTMLS_validate_position(1, $_GET["GOTMLS_y"]);
1594 if (isset($_GET["GOTMLS_h"]))
1595 GOTMLS_validate_position(2, $_GET["GOTMLS_h"]);
1596 if (isset($_GET["GOTMLS_w"]))
1597 GOTMLS_validate_position(3, $_GET["GOTMLS_w"]);
1598 $_GET["GOTMLS_msg"] = __("New position",'gotmls');
1599 } else
1600 die("\n//Position Error: No new position to save!\n");
1601 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1602 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_htmlentities($_GET["GOTMLS_msg"]).' '.__("saved.",'gotmls').(implode($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"]) == implode($GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"])?"":' <a href="'.GOTMLS_admin_url('GOTMLS_position', GOTMLS_set_nonce(GOTMLS_position_msg).'&GOTMLS_msg='.GOTMLS_esc_url(GOTMLS_position_msg)).'">['.GOTMLS_position_msg.']</a>'))), $properties));
1603 } else
1604 die(GOTMLS_Invalid_Nonce("\n//Position Error: ")."\n");
1605 }
1606
1607 function GOTMLS_validate_position($vector, $position) {
1608 if (preg_match('/^[0-9]+px$/', $position)) {
1609 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][$vector] = $position;
1610 return true;
1611 } else
1612 return false;
1613 }
1614
1615 function GOTMLS_ajax_empty_trash() {
1616 global $wpdb;
1617 $gl = '><';
1618 $action = array("RESTORE" => "UPDATE $wpdb->posts SET `post_status` = 'private'", "DELETE" => "DELETE FROM $wpdb->posts");
1619 if (GOTMLS_get_nonce() && isset($_REQUEST["alter"]) && isset($action[$_REQUEST["alter"]])) {
1620 if ($trashed = $wpdb->query($action[$_REQUEST["alter"]]." WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) {
1621 $wpdb->query("REPAIR TABLE $wpdb->posts");
1622 $trashmsg = sprintf(__("%s %d item from the quarantine trash.",'gotmls'), strtoupper(GOTMLS_sanitize($_REQUEST["alter"])."d"), (INT) $trashed);
1623 } else
1624 $trashmsg = __("Failed to empty the trash.",'gotmls');
1625 } else
1626 $trashmsg = GOTMLS_Invalid_Nonce("");
1627 $properties = array("html" => $gl.'head'.$gl."script type='text/javascript'>\nalert('".GOTMLS_strip4java($trashmsg)."');\nif (curDiv = window.parent)\n\tcurDiv.location.reload(false);\nelse\n\twindow.opener.location.reload(false);</script$gl/head", "body" => 'style="margin: 0; padding: 0;"');
1628 die(GOTMLS_html_tags(array("html" => array("body" => $trashmsg)), $properties));
1629 }
1630
1631 function GOTMLS_ajax_whitelist() {
1632 global $wpdb;
1633 $body = "Whitelist Error: No file or checksum!";
1634 $script = "window.parent.showhide('GOTMLS_iFrame', true);";
1635 if (GOTMLS_get_nonce("GOTMLS_whitelist")) {
1636 if (isset($_POST["GOTMLS_whitelist"]) && isset($_POST["GOTMLS_chksum"])) {
1637 if (("list_group" == $_POST["GOTMLS_whitelist"]) && is_array($_POST["GOTMLS_chksum"])) {
1638 $valid_chksums = array();
1639 foreach ($_POST["GOTMLS_chksum"] as $chksum)
1640 if (preg_match('/^[\da-f]{32}O\d++$/', $chksum))
1641 $valid_chksums[] = "'$chksum'";
1642 if (count($valid_chksums)) {
1643 $trash = "UPDATE `$wpdb->posts` SET `post_status` = 'trash' WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'pending' AND CONCAT(`post_mime_type`, 'O', `comment_count`) IN (".implode(", ", $valid_chksums).")";
1644 if ($count = $wpdb->query($trash)) {
1645 foreach ($valid_chksums as $chksum)
1646 $script .= "\nif (chksum = window.parent.document.getElementById('whitelist_".substr($chksum, 1)."))\n\tchksum.checked = false;\nif (chksum = window.parent.document.getElementById('GOTMLS_whitelist_".substr($chksum, 1)."))\n\tchksum.style.display = 'none';";
1647 if (count($_POST["GOTMLS_chksum"]) == count($valid_chksums) && count($valid_chksums) == $count)
1648 $body = "Removed $count files from the Whitelist";
1649 else
1650 $body = "<li>Removed $count of ".count($valid_chksums)." (of ".count($_POST["GOTMLS_chksum"])." posted)</li>";
1651 } else
1652 $body = "<li>Whitelist Not Updated!</li>";
1653 } else
1654 $body = "<li>No Valid chksums!</li>";
1655 } else {
1656 $file = GOTMLS_decode($_POST["GOTMLS_whitelist"]);
1657 $chksum = explode("O", $_POST["GOTMLS_chksum"]."O");
1658 if (GOTMLS_strlen($chksum[0]) == 32 && GOTMLS_strlen($chksum[1]) == 32 && is_file($file) && (($filesize = @filesize($file)) == GOTMLS_load_contents($TXT = @file_get_contents($file))) && md5($TXT) == $chksum[0] && GOTMLS_write_quarantine($file, "whitelist", "pending"))
1659 $body = "Added $file to Whitelist!<br />\n<iframe style='width: 90%; height: 250px; border: none;' src='".GOTMLS_plugin_home."whitelist.html?whitelist=".GOTMLS_htmlspecialchars($_POST["GOTMLS_whitelist"])."&hash=$chksum[0]&size=$filesize&key=$chksum[1]'></iframe>";
1660 else
1661 $body = "<li>Invalid checksum!</li>";
1662 }
1663 } else
1664 $body = "Whitelist Error: No file or checksum!";
1665 } else
1666 $body = GOTMLS_Invalid_Nonce("\n//Whitelist Error: ");
1667 die(GOTMLS_html_tags(array("html" => array("body" => $body, "script" => $script))));
1668 }
1669
1670 function GOTMLS_ajax_fix() {
1671 global $wpdb;
1672 $gt = ">"; // This local variable never changes
1673 $lt = "<"; // This local variable never changes
1674 if (GOTMLS_get_nonce()) {
1675 if (isset($_REQUEST["GOTMLS_fix"]) && !is_array($_REQUEST["GOTMLS_fix"]))
1676 $_REQUEST["GOTMLS_fix"] = array($_REQUEST["GOTMLS_fix"]);
1677 if (isset($_REQUEST["GOTMLS_fix"]) && is_array($_REQUEST["GOTMLS_fix"]) && isset($_REQUEST["GOTMLS_fixing"]) && $_REQUEST["GOTMLS_fixing"]) {
1678 GOTMLS_update_scanlog(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1679 $callAlert = "clearTimeout(callAlert);\ncallAlert=setTimeout(function() {alert_repaired(1);}, 30000);";
1680 $li_js = $lt."script type=\"text/javascript\"$gt\nscanned = 0;\nvar callAlert;\nfunction alert_repaired(failed) {\nclearTimeout(callAlert);\nif (failed)\nfilesFailed='the rest, try again to change more.';\nwindow.parent.check_for_donation('Fixed '+filesFixed+' files, failed to fix '+filesFailed);\n}\n$callAlert\nwindow.parent.showhide('GOTMLS_iFrame', true);\nfilesFixed=0;\nfilesFailed=0;\nfunction fixedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file))\n\tli_file.className='GOTMLS_plugin';\nif (li_file = window.parent.document.getElementById('GOTMLS_quarantine_'+file)) {\n\tli_file.style.display='none';\n\tli_file.innerHTML='';\n\t}\n}\nfunction DeletedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file)) {\n\tli_file.className='GOTMLS_plugin';\n\tif (true || !isNaN(file)) {\n\t\tli_file = li_file.parentNode".(isset($_REQUEST["GOTMLS_fix"][0]) && is_numeric($_REQUEST["GOTMLS_fix"][0])?'.parentNode':'').";\n\t\tli_file.style.display='none';\n\t\tli_file.innerHTML='';\n}}}\nfunction failedFile(file) {\n filesFailed++;\nwindow.parent.document.getElementById('check_'+file).checked=false; \n}\n$lt/script$gt\n{$lt}script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1681 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] * 2);
1682 $HTML_safe = explode("split-here-for-content", GOTMLS_html_tags(array("html" => array("body" => "split-here-for-content"))));
1683 echo $HTML_safe[0];
1684 GOTMLS_update_scanlog(array("scan" => array("dir" => count($_REQUEST["GOTMLS_fix"])." Files", "start" => time())));
1685 foreach ($_REQUEST["GOTMLS_fix"] as $clean_file) {
1686 if (is_numeric($clean_file)) {
1687 if (($Q_post = GOTMLS_get_quarantine($clean_file)) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine" && isset($Q_post["post_status"])) {
1688 $safe_path = esc_html($Q_post["post_title"]);
1689 if ($_REQUEST["GOTMLS_fixing"] > 1) {
1690 echo $lt."li$gt ".sprintf(__("Removing %s ... ",'gotmls'), $safe_path);
1691 $Q_post["post_status"] = "trash";
1692 if (wp_update_post($Q_post)) {
1693 echo __("Done!",'gotmls');
1694 $li_js .= "/*--$gt*"."/\nDeletedFile('$clean_file');\n/*$lt!--*"."/";
1695 } else {
1696 echo __("Failed to remove!",'gotmls');
1697 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1698 }
1699 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "Removal from Quarantine")));
1700 } else {
1701 $Q_post["post_status"] = "pending";
1702 $part = explode(":", $Q_post["post_title"].':');
1703 if (count($part) > 2 && is_numeric($part[1])) {
1704 if (!(substr($part[0], -7) == "options" && ($R_post = $wpdb->get_results("SELECT option_name, option_value FROM `$part[0]` WHERE option_id = ".(INT) $part[1], ARRAY_A)) && count($R_post)))
1705 $R_post = GOTMLS_get_quarantine((INT) $part[1]);
1706 if (isset($R_post["post_type"]) && strtolower($R_post["post_type"]) == $part[0]) {
1707 if (isset($_GET["eli"]) || ($R_post["post_content"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post["post_content"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1708 echo $lt."li$gt Restoring Post ID $part[1] ... ";
1709 $R_post["post_modified_gmt"] = $Q_post["post_modified"];
1710 $R_post["post_content"] = GOTMLS_decode($Q_post["post_content"]);
1711 if (wp_update_post($R_post)) {
1712 echo __("Complete!",'gotmls');
1713 wp_update_post($Q_post);
1714 $li_js .= "/*--$gt*"."/\nfixedFile('$clean_file');\n/*$lt!--*"."/";
1715 } else {
1716 echo __("Restoration of post_content Failed!",'gotmls');
1717 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1718 }
1719 } else {
1720 echo $lt."li$gt".__("Restoration Aborted, post_content was modified outside of this quarantine!",'gotmls').$lt."pre$gt".GOTMLS_htmlspecialchars(print_r(array("R"=>$R_post,"Q"=>$Q_post),1))."$lt/pre$gt";
1721 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1722 }
1723 } elseif (isset($R_post[0]["option_name"]) && strtolower($R_post[0]["option_name"]) == strtolower(trim($part[2], "\" "))) {
1724 if (isset($_GET["eli"]) || ($R_post[0]["option_value"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post[0]["option_value"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1725 echo $lt."li$gt Restoring Option ID $part[1] ... ";
1726 if ($wpdb->update($part[0], array("option_value" => GOTMLS_decode($Q_post["post_content"])), array("option_id" => $part[1]))) {
1727 echo __("Complete!",'gotmls');
1728 wp_update_post($Q_post);
1729 $li_js .= "/*--$gt*"."/\nfixedFile('$clean_file');\n/*$lt!--*"."/";
1730 } else {
1731 echo __("Restoration of option_value Failed!{$lt}pre$gt".GOTMLS_htmlspecialchars(print_r(array("part"=>$part,"error"=>$wpdb->last_error),1))."$lt/pre$gt",'gotmls');
1732 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1733 }
1734 } else {
1735 echo $lt."li$gt".__("Restoration Aborted, option_value was modified outside of this quarantine!",'gotmls').$lt."pre$gt".GOTMLS_htmlspecialchars(print_r(array(GOTMLS_decode($Q_post["post_content_filtered"]) => $R_post[0]["option_value"], "R"=>$R_post[0],"Q"=>$Q_post),1))."$lt/pre$gt";
1736 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1737 }
1738 } else {
1739 echo $lt."li$gt".__("Restore Failed!",'gotmls').$lt."pre$gt".GOTMLS_htmlspecialchars(print_r(array('$part' => $part, "R"=>$R_post,"Q"=>$Q_post),1))."$lt/pre$gt";
1740 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1741 }
1742 } elseif (isset($_GET["eli"]) || is_file($safe_path)) {
1743 echo sprintf(__($lt."li$gt Restoring %s ... ",'gotmls'), $safe_path);
1744 if (GOTMLS_save_contents($safe_path, GOTMLS_decode($Q_post["post_content"])) && wp_update_post($Q_post)) {
1745 echo __("Complete!",'gotmls');
1746 $li_js .= "/*--$gt*"."/\nfixedFile('$clean_file');\n/*$lt!--*"."/";
1747 } else {
1748 echo __("Restore Failed!",'gotmls');
1749 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1750 }
1751 } else {
1752 echo $lt."li$gt".sprintf(__("Restoration Aborted, file %s does not exist!",'gotmls'), $safe_path);
1753 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1754 }
1755 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "Restoration from Quarantine")));
1756 }
1757 echo "$lt/li$gt\n$li_js/*--$gt*"."/\n$callAlert\n$lt/script$gt\n";
1758 $li_js = $lt."script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1759 }
1760 } elseif (is_numeric($decoded_file = GOTMLS_decode($clean_file))) {
1761 $li_js .= GOTMLS_db_scan($decoded_file);
1762 echo $lt."/li$gt\n$li_js/*--$gt*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n$lt/script$gt\n";
1763 $li_js = $lt."script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1764 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "DB Fix")));
1765 } else {
1766 $safe_path = esc_html(realpath($decoded_file = GOTMLS_decode($clean_file)));
1767 if (is_file($safe_path)) {
1768 echo $lt."li$gt".sprintf(__("Fixing %s ... ",'gotmls'), $safe_path);
1769 $li_js .= GOTMLS_scanfile($safe_path);
1770 echo "$lt/li$gt\n$li_js/*--$gt*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n$lt/script$gt\n";
1771 $li_js = $lt."script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1772 } else
1773 echo $lt."li$gt".sprintf(__("File %s not found!",'gotmls'), $safe_path)."$lt/li$gt";
1774 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "Automatic Fix")));
1775 }
1776 }
1777 $nonce = GOTMLS_set_nonce(__FUNCTION__."1676");
1778 die($lt.'div id="check_site_warning" style="background-color: #F00;"'.$gt.sprintf(__("Because some changes were made we need to check to make sure it did not break your site. If this stays Red and the frame below does not load please %srevert the changes%s made during this automated fix process",'gotmls'), $lt.'a href="'.GOTMLS_images_path.'?page=GOTMLS_View_Quarantine&'.GOTMLS_set_nonce(GOTMLS_update_home).'"'.$gt, "$lt/a$gt").'... '.$lt.'span style="color: #F00;"'.$gt.__("Never mind, it worked!",'gotmls')."$lt/span$gt$lt/div$gt$lt".'br /'.$gt.$lt.'iframe id="test_frame" name="test_frame" src="'.GOTMLS_admin_url('GOTMLS_View_Quarantine', 'check_site=1&'.$nonce).'" style="width: 100%; height: 200px"'."$gt$lt/iframe$gt$li_js/*--$gt*"."/\nalert_repaired(0);\n$lt/script$gt\n$HTML_safe[1]");
1779 } else
1780 die(GOTMLS_html_tags(array("html" => array("body" => $lt."script type=\"text/javascript\"$gt\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".__("Nothing Selected to be Changed!",'gotmls')."');\n$lt/script$gt".__("Done!",'gotmls')))));
1781 } else
1782 die(GOTMLS_html_tags(array("html" => array("body" => $lt."script type=\"text/javascript\"$gt\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt".__("Done!",'gotmls')))));
1783 }
1784
1785 function GOTMLS_ajax_scan() {
1786 $gt = ">"; // This local variable never changes
1787 $lt = "<"; // This local variable never changes
1788 if (GOTMLS_get_nonce()) {
1789 @error_reporting(0);
1790 if (isset($_GET["GOTMLS_scan"])) {
1791 $script_form = GOTMLS_html_tags(array("script" => GOTMLS_js_text_range())).$lt.'table style="top: 0px; left: 0px; width: 100%; height: 100%; position: absolute;"'.$gt.$lt.'tr'.$gt.$lt.'td style="width: 100%"'.$gt;
1792 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] - 5);
1793 if (is_numeric($_GET["GOTMLS_scan"])) {
1794 if (($Q_post = GOTMLS_get_quarantine((INT) $_GET["GOTMLS_scan"])) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine") {
1795 GOTMLS_load_contents(GOTMLS_decode($Q_post["post_content"]));
1796 GOTMLS_view_details($Q_post, $lt.'form style="margin: 0;" method="post" action="'.admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."1605")).'" onsubmit="return confirm(\''.__("Are you sure you want to delete the record of this file from the quarantine?",'gotmls').'\');"'.$gt.$lt.'input type="hidden" name="GOTMLS_fix[]" value="'.$Q_post["ID"].'"'.$gt.$lt.'input type="hidden" name="GOTMLS_fixing" value="2"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_fix"'.$gt.$lt.'input type="submit" value="DELETE from Quarantine" style="display: none; background-color: #C00; float: right;"'.$gt.$lt.'/form'.$gt);
1797 } else
1798 die(GOTMLS_html_tags(array("html" => array("body" => __("This record no longer exists in the quarantine.",'gotmls').$lt."br /$gt\n{$lt}script type=\"text/javascript\"$gt\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n$lt/script$gt"))));
1799 } elseif (substr($_GET["GOTMLS_scan"]."1234567", 0, 7) == "db_scan") {
1800 @header("Content-type: text/javascript");
1801 if (isset($_GET["GOTMLS_only_file"])) {
1802 if (GOTMLS_strlen($_GET["GOTMLS_only_file"])) {
1803 echo '//re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1804 die(GOTMLS_db_scan().'//END OF JavaScript');
1805 } else {
1806 echo '//re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1807 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1808 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1809 $path = "db_scan=$file";
1810 echo "/*--$gt*"."/\nscanfilesArKeys.push('db_scan&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*$lt!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1811 }
1812 }
1813 die(GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Database Scan ...",'gotmls'))."/*--$gt*"."/\nscanNextDir(-1);\n/*$lt!--*"."/");
1814 }
1815 } else {
1816 echo '//db_scan: '.gmdate("Y-m-d H:i:s\n");
1817 die(GOTMLS_db_scan().'//END OF JavaScript');
1818 }
1819 } else {
1820 $file = GOTMLS_decode($_GET["GOTMLS_scan"]);
1821 if (is_numeric($file))
1822 die("\n$script_form".GOTMLS_db_scan($file));
1823 elseif (substr($file."1234567", 0, 7) == "db_scan") {
1824 @header("Content-type: text/javascript");
1825 if (isset($_GET["GOTMLS_only_file"])) {
1826 if (GOTMLS_strlen($_GET["GOTMLS_only_file"])) {
1827 echo '//encoded re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1828 die(GOTMLS_db_scan().'//END OF JavaScript');
1829 } else {
1830 echo '//encoded re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1831 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1832 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1833 $path = "db_scan=$file";
1834 echo "/*--$gt*"."/\nscanfilesArKeys.push('".GOTMLS_encode($dir)."&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*$lt!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1835 }
1836 }
1837 echo GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Encoded Database Scan ...",'gotmls'))."/*--$gt*"."/\nscanNextDir(-1);\n/*$lt!--*"."/";
1838 }
1839 } else {
1840 echo '//encoded db_scan: but no GOTMLS_only_file'.gmdate("Y-m-d H:i:s\n");
1841 die(GOTMLS_db_scan().'//END OF JavaScript');
1842 }
1843 } elseif (is_dir($file)) {
1844 @error_reporting(0);
1845 @header("Content-type: text/javascript");
1846 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))
1847 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
1848 @ob_start();
1849 echo GOTMLS_scandir($file);
1850 if (@ob_get_level()) {
1851 GOTMLS_flush();
1852 @ob_end_clean();//_flush();
1853 }
1854 die('//END OF JavaScript');
1855 } elseif (file_exists($file)) {
1856 $real_file = realpath($file);
1857 if (is_file($real_file) && ($filesize = filesize($real_file)))
1858 GOTMLS_load_contents(file_get_contents($real_file));
1859 else
1860 GOTMLS_load_contents("");
1861 if (isset($GLOBALS["GOTMLS"]["tmp"]["encoding"]) && !headers_sent($filename, $linenum))
1862 @header("Content-type: text/html; charset=".$GLOBALS["GOTMLS"]["tmp"]["encoding"]);
1863 echo $lt."html$gt\n{$lt}head$gt\n{$lt}title{$gt}Scan File: ".esc_html($file)." (".(isset($GLOBALS["GOTMLS"]["tmp"]["file_contents"])?GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]):filesize($file))." bytes ".(isset($GLOBALS["GOTMLS"]["tmp"]["encoding"])?$GLOBALS["GOTMLS"]["tmp"]["encoding"]:"... Bad Encoding").")$lt/title$gt\n$lt/head$gt\n{$lt}body$gt\n";
1864 $fa = $lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /'.$gt.__("Scanning file contents ... ",'gotmls');
1865 $show_wl_form = "if (sid = document.getElementById('whitelist_form'))\n\tsid.style.display = 'block';\n";
1866 $show_uw_form = "";
1867 $fadef = " No Threats Found";
1868 if (isset($GLOBALS["GOTMLS"]["tmp"]["contents_whitelist"]) && $GLOBALS["GOTMLS"]["tmp"]["contents_whitelist"]) {
1869 $wl_form = __("Are you sure you want to remove this file from the whitelist so it will be included in future scans?",'gotmls').'\');"'.$gt.$lt.'input type="hidden" name="GOTMLS_whitelist" value="list_group"'.$gt.$lt.'input type="hidden" name="GOTMLS_chksum[]" value="'.md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'O'.GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'"'.$gt.$lt.'input type="submit" value="Remove from Whitelist" style="float: left;"';
1870 $show_uw_form = $show_wl_form;
1871 $fadef = " File is Whitelisted";
1872 } else
1873 $wl_form = __("Are you sure this file is not infected and you want to ignore it in future scans?",'gotmls').'\');"'.$gt.$lt.'input type="hidden" name="GOTMLS_whitelist" value="'.GOTMLS_encode($file).'"'.$gt.$lt.'input type="hidden" name="GOTMLS_chksum" value="'.md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'O'.GOTMLS_installation_key.'"'.$gt.$lt.'input type="submit" value="Whitelist this file" style="float: left;"';
1874 echo "\n$script_form\n$lt".'form style="margin: 0; display: none;" id="whitelist_form" method="post" action="'.admin_url('admin-ajax.php').'" onsubmit="return confirm(\''.$wl_form.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce("GOTMLS_whitelist")).'"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_whitelist"'."$gt\n$lt/form$gt\n".GOTMLS_file_details($file)."\n$lt".'div style="overflow: auto;"'."$gt\n$lt".'span onmouseover="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'block\';" onmouseout="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'none\';"'.$gt.__("Potential threats in file:",'gotmls')."$lt/span$gt\n{$lt}span style=\"position: absolute; right: 5px;\" id=\"threats_in_file\"$gt$fa$lt/span$gt\n$lt/div$gt$lt/td$gt$lt/tr$gt\n{$lt}tr$gt{$lt}td style=\"height: 100%\"$gt\n{$lt}textarea id=\"ta_file\" style=\"width: 100%; height: 100%\"$gt".GOTMLS_htmlentities(str_replace("\r", "", $GLOBALS["GOTMLS"]["tmp"]["file_contents"]))."$lt/textarea$gt$lt/td$gt$lt/tr$gt$lt/table$gt";
1875 GOTMLS_scanfile($real_file);
1876 $fa = "";
1877 $f = 0;
1878 if (isset($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && count($GLOBALS["GOTMLS"]["tmp"]["threats_found"])) {
1879 $f = 1;
1880 foreach ($GLOBALS["GOTMLS"]["tmp"]["threats_found"] as $threats_found => $threats_name) {
1881 list($start, $end, $junk) = explode("-", "$threats_found--", 3);
1882 if ($start > $end)
1883 $fa .= "ERROR[$f]: $threats_found / ".GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]);
1884 else
1885 $fa .= $lt.'a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range('."'ta_file', $start, $end);\"".$gt."[$f]$lt/a$gt ";
1886 $f++;
1887 }
1888 } else
1889 $fa = $fadef;
1890 die($lt."script$gt\nif (sid = document.getElementById('threats_in_file'))\n\tsid.style.display = 'none';\n".(($f>0)?$show_wl_form:$show_uw_form)."$lt/script$gt\n$lt".'span style="position: absolute; right: 5px; top: 2px;"'.$gt." ( $fa ) $lt/span$gt\n$lt/body$gt$lt/html$gt");
1891 } else {
1892 //@header("Content-type: text/javascript");
1893 die("// ERROR: ".sprintf(__("The file %s does not exist, it must have already been deleted.",'gotmls'), GOTMLS_htmlspecialchars($file)).$lt."script type=\"text/javascript\"$gt\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n//$lt/script$gt");
1894 }
1895 }
1896 } else
1897 die("\n//Directory Error: Nothing to scan!\n");
1898 } else {
1899 $alert = "if (is_button = document.getElementById('resume_button')) is_button.value = 'Resume'; alert('Invalid or Expired Nonce Token! You probably need to restart the scan :-(');";
1900 if (isset($_GET["GOTMLS_scan"]) && is_dir(GOTMLS_decode($_GET["GOTMLS_scan"])))
1901 @header("Content-type: text/javascript");
1902 else
1903 $alert = $lt."script type='text/javascript'$gt\n$alert\n$lt/script$gt";
1904 die(GOTMLS_Invalid_Nonce("$alert\n//Ajax Scan Nonce Error: ")."\n");
1905 }
1906 }
1907
1908 function GOTMLS_ajax_nopriv() {
1909 die("\n//Permission Error: User not authenticated!\n");
1910 }
1911