PluginProbe ʕ •ᴥ•ʔ
Anti-Malware Security and Brute-Force Firewall / 4.23.83
Anti-Malware Security and Brute-Force Firewall v4.23.83
4.23.90 trunk 1.2.03.23 1.3.02.15 3.07.06 4.14.47 4.15.16 4.16.17 4.17.28 4.17.29 4.17.44 4.17.57 4.17.58 4.17.68 4.17.69 4.18.52 4.18.62 4.18.63 4.18.69 4.18.71 4.18.74 4.18.76 4.19.44 4.19.50 4.19.68 4.19.69 4.20.59 4.20.72 4.20.92 4.20.93 4.20.94 4.20.95 4.20.96 4.21.74 4.21.83 4.21.84 4.21.85 4.21.86 4.21.87 4.21.88 4.21.89 4.21.90 4.21.91 4.21.92 4.21.93 4.21.94 4.21.95 4.21.96 4.23.56 4.23.57 4.23.67 4.23.68 4.23.69 4.23.71 4.23.73 4.23.77 4.23.81 4.23.83 4.23.85 4.23.87 4.23.88 4.23.89
gotmls / index.php
gotmls Last commit date
images 9 months ago languages 9 months ago safe-load 9 months ago index.php 9 months ago readme.txt 9 months ago
index.php
1915 lines
1 <?php
2 /*
3 Plugin Name: Anti-Malware Security and Brute-Force Firewall
4 Plugin URI: https://gotmls.net/
5 Author: Eli Scheetz
6 Text Domain: gotmls
7 Author URI: https://anti-malware.ninja/
8 Contributors: scheeeli, gotmls
9 Donate link: https://gotmls.net/donate/
10 Description: This Anti-Virus/Anti-Malware plugin searches for Malware and other Virus like threats and vulnerabilities on your server and helps you remove them. It's always growing and changing to adapt to new threats so let me know if it's not working for you.
11 License: GPLv3 or later
12 License URI: https://www.gnu.org/licenses/gpl-3.0.html#license-text
13 Version: 4.23.83
14 Requires PHP: 5.6
15 Requires CP: 1.1.1
16 */
17 if (isset($_SERVER["DOCUMENT_ROOT"]) && ($SCRIPT_FILE = str_replace($_SERVER["DOCUMENT_ROOT"], "", (isset($_SERVER["SCRIPT_FILENAME"])?$_SERVER["SCRIPT_FILENAME"]:(isset($_SERVER["SCRIPT_NAME"])?$_SERVER["SCRIPT_NAME"]:"")))) && strlen($SCRIPT_FILE) > strlen("/".basename(__FILE__)) && substr(__FILE__, -1 * strlen($SCRIPT_FILE)) == substr($SCRIPT_FILE, -1 * strlen(__FILE__)) || !(function_exists("add_action") && function_exists("load_plugin_textdomain")))
18 include(dirname(__FILE__)."/safe-load/index.php");
19 else
20 require_once(dirname(__FILE__)."/images/index.php");
21 /* ___
22 * / /\ GOTMLS Main Plugin File
23 * / /:/ @package GOTMLS
24 * /__/::\
25 Copyright \__\/\:\__ © 2012-2025 Eli Scheetz (email: eli@gotmls.net)
26 * \ \:\/\
27 * \__\::/ This program is free software; you can redistribute it
28 * ___ /__/:/ and/or modify it under the terms of the GNU General Public
29 * /__/\ _\__\/ License as published by the Free Software Foundation;
30 * \ \:\ / /\ either version 3 of the License, or (at your option) any
31 * ___\ \:\ /:/ later version.
32 * / /\\ \:\/:/
33 / /:/ \ \::/ This program is distributed in the hope that it will be useful,
34 / /:/_ \__\/ but WITHOUT ANY WARRANTY; without even the implied warranty
35 /__/:/ /\__ of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
36 \ \:\/:/ /\ See the GNU General Public License for more details.
37 \ \::/ /:/
38 \ \:\/:/ You should have received a copy of the GNU General Public License
39 * \ \::/ with this program; if not, write to the Free Software Foundation,
40 * \__\/ Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA */
41
42 function GOTMLS_install() {
43 if (strpos(GOTMLS_get_version("URL"), '&wp=') && version_compare(GOTMLS_wp_version, GOTMLS_require_version, "<"))
44 die(GOTMLS_htmlspecialchars(GOTMLS_require_version_LANGUAGE.", NOT version: ".GOTMLS_wp_version));
45 else
46 delete_option("GOTMLS_definitions_array");
47 }
48 register_activation_hook(__FILE__, "GOTMLS_install");
49
50 function GOTMLS_uninstall() {
51 delete_option('GOTMLS_get_URL_blob');
52 delete_option('GOTMLS_definitions_blob');
53 delete_option('GOTMLS_nonce_blob');
54 delete_option('GOTMLS_settings_array');
55 GOTMLS_create_session_file(false);
56 }
57 register_deactivation_hook(__FILE__, "GOTMLS_uninstall");
58
59 function GOTMLS_menu() {
60 if (GOTMLS_user_can()) {
61 $GLOBALS["GOTMLS"]["tmp"]["my_admin_page"] = add_menu_page($GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"], $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $GLOBALS["GOTMLS"]["tmp"]["base_page"], "GOTMLS_settings", GOTMLS_images_path.'GOTMLS-16x16.gif');
62 add_action('load-'.$GLOBALS["GOTMLS"]["tmp"]["my_admin_page"], 'GOTMLS_admin_add_help_tab');
63 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_Scan_Settings_LANGUAGE, GOTMLS_Scan_Settings_LANGUAGE, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], $GLOBALS["GOTMLS"]["tmp"]["base_page"], "GOTMLS_settings");
64 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." Firewall Options", "Firewall Options", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS-Firewall-Options", "GOTMLS_Firewall_Options");
65 }
66 }
67 add_action("admin_menu", "GOTMLS_menu", 8);
68 add_action("network_admin_menu", "GOTMLS_menu", 8);
69
70 function GOTMLS_menu_Quarantine() {
71 if (GOTMLS_user_can() && isset($GLOBALS["GOTMLS"]["tmp"]["my_admin_page"]))
72 add_submenu_page($GLOBALS["GOTMLS"]["tmp"]["base_page"], $GLOBALS["GOTMLS"]["tmp"]["pluginTitle"]." ".GOTMLS_View_Quarantine_LANGUAGE, GOTMLS_View_Quarantine_LANGUAGE.(($Qs = GOTMLS_get_quarantine(true))?' <span class="awaiting-mod count-'.$Qs.'"><span class="awaiting-mod">'.$Qs.'</span></span>':""), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["user_can"], "GOTMLS_View_Quarantine", "GOTMLS_View_Quarantine");
73 }
74 add_action("admin_menu", "GOTMLS_menu_Quarantine", 16);
75 add_action("network_admin_menu", "GOTMLS_menu_Quarantine", 16);
76
77 function GOTMLS_admin_add_help_tab() {
78 $screen = get_current_screen();
79 $screen->add_help_tab(array(
80 'id' => "GOTMLS_Getting_Started",
81 'title' => __("Getting Started", 'gotmls'),
82 'content' => '<p>'.__("Make sure the Definition Updates are current and Run a Complete Scan.", 'gotmls').'</p><p>'.sprintf(__("If Known Threats are found and displayed in red then there will be a button to '%s'. If only Potentional Threats are found then there is no automatic fix because those are probably not malicious.", 'gotmls'), GOTMLS_Automatically_Fix_LANGUAGE).'</p><p>'.__("A backup of the original infected files are placed in the Quarantine in case you need to restore them or just want to look at them later. You can delete these files if you don't want to save more.", 'gotmls').'</p>'
83 ));
84 $FAQMarker = '== Frequently Asked Questions ==';
85 if (is_file(dirname(__FILE__).'/readme.txt') && ($readme = explode($FAQMarker, @file_get_contents(dirname(__FILE__).'/readme.txt').$FAQMarker)) && GOTMLS_strlen($readme[1]) && ($readme = explode("==", $readme[1]."==")) && GOTMLS_strlen($readme[0])) {
86 $screen->add_help_tab(array(
87 'id' => "GOTMLS_FAQs",
88 'title' => __("FAQs", 'gotmls'),
89 'content' => '<p>'.preg_replace('/\[(.+?)\]\((.+?)\)/', "<a target=\"_blank\" href=\"\\2\">\\1</a>", preg_replace('/[\r\n]+= /', "</p><b>", preg_replace('/ =[\r\n]+/', "</b><p>", $readme[0]))).'</p>'
90 ));
91 }
92 }
93
94 function GOTMLS_enqueue_scripts() {
95 wp_enqueue_style('dashicons');
96 }
97 add_action('admin_enqueue_scripts', 'GOTMLS_enqueue_scripts');
98
99 function GOTMLS_display_header($optional_box = "") {
100 global $current_user, $wpdb;
101 wp_get_current_user();
102 $head_nonce = GOTMLS_set_nonce(__FUNCTION__."100");
103 $GOTMLS_url_parts = explode('/', GOTMLS_siteurl);
104 $Update_Definitions = array(GOTMLS_update_home.'definitions.js'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"].'&'.GOTMLS_get_version_URL.'&'.GOTMLS_set_nonce(GOTMLS_update_home).'&d='.ur1encode(GOTMLS_siteurl));
105 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])
106 array_unshift($Update_Definitions, GOTMLS_admin_url('GOTMLS_load_update', $head_nonce.'&UPDATE_definitions_array=1'));
107 else
108 $Update_Definitions[] = GOTMLS_admin_url('GOTMLS_load_update', $head_nonce.'&UPDATE_definitions_array=1');
109 $Update_Link = '<div style="text-align: center;"><a href="';
110 $new_version = "";
111 $file = basename(GOTMLS_plugin_path).'/index.php';
112 $current = get_site_transient("update_plugins");
113 if (isset($current->response[$file]->new_version) && version_compare(GOTMLS_Version, $current->response[$file]->new_version, "<")) {
114 $new_version = sprintf(__("Upgrade to %s now!",'gotmls'), $current->response[$file]->new_version).'<br /><br />';
115 $Update_Link .= wp_nonce_url(self_admin_url('update.php?action=upgrade-plugin&plugin=').$file, 'upgrade-plugin_'.$file);
116 }
117 $Update_Link .= "\">$new_version</a></div>";
118 $defLatest = (is_numeric($Latest = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"]))) && is_numeric($Default = preg_replace('/[^0-9]/', "", GOTMLS_sexagesimal($GLOBALS["GOTMLS"]["tmp"]["Definition"]["Default"]))) && $Latest > $Default)?1:0;
119 if (is_array($keys = GOTMLS_uckserialize(get_option('GOTMLS_Installation_Keys', array()))) && isset($keys[GOTMLS_installation_key]))
120 $isRegistered = $keys[GOTMLS_installation_key];
121 else
122 $isRegistered = "";
123 $Update_Div ='<div id="findUpdates" style="display: none;"><center>'.__("Searching for updates ...",'gotmls').'<br /><img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /><br /><input type="button" value="Cancel" onclick="cancelserver(\'findUpdates\');" /></center></div>';
124 $php_version = "<li>PHP: <span class='GOTMLS_date'>".phpversion()."</span></li>\n";
125 if (isset($_SERVER["SERVER_SOFTWARE"]) && preg_match('/Apache\/([0-9\.]+)/i', $_SERVER["SERVER_SOFTWARE"], $GLOBALS["GOTMLS"]["tmp"]["apache"]) && count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
126 $php_version .= "<li>Apache: <span class='GOTMLS_date'>".$GLOBALS["GOTMLS"]["tmp"]["apache"][1]."</span></li>\n";
127 elseif (isset($_SERVER["SERVER_SOFTWARE"]) && GOTMLS_strlen($_SERVER["SERVER_SOFTWARE"]))
128 $php_version .= "<li>".esc_html($_SERVER["SERVER_SOFTWARE"])."</li>\n";
129 if ((isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)) {
130 $reg_email_key = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
131 $isRegistered = GOTMLS_get_registrant($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]);
132 } else
133 $reg_email_key = "";
134 echo GOTMLS_get_header().'
135 <div id="admin-page-container">
136 <div id="GOTMLS-right-sidebar" style="width: 300px;" class="metabox-holder">
137 '.GOTMLS_box(__("Updates & Registration",'gotmls'), "<ul>$php_version<li>".(function_exists('classicpress_version')?"ClassicPress: <span class='GOTMLS_date' title='CP: ".classicpress_version()."\nWP: ".GOTMLS_wp_version."'>".preg_replace( '#[+-].*$#', '', classicpress_version()):"WordPress: <span class='GOTMLS_date'>".GOTMLS_wp_version)."</span></li>\n<li>Plugin: <span class='GOTMLS_date'>".GOTMLS_Version.'</span></li>
138 <li><div id="GOTMLS_Key" style="margin: 0;'.((!$defLatest && !$isRegistered)?' display: none;">Key: <span style="float: right;">'.GOTMLS_installation_key.'</span></div><div style="':'">Key: <span style="float: right;" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">'.GOTMLS_installation_key.'</span></div><div style="display: none;').'"><form method="POST" action="'.admin_url('admin-ajax.php?'.$head_nonce).'" target="GOTMLS_iFrame" name="GOTMLS_Form_lognewkey"><input type="hidden" name="GOTMLS_installation_key" value="'.GOTMLS_installation_key.'"><input type="hidden" name="action" value="GOTMLS_lognewkey"><span style="color: #F00;" id="GOTMLS_No_Key">No Key! <input type="submit" style="float: right;" value="'.__("Get FREE Key!",'gotmls').'" class="button-primary" onclick="showhide(\'GOTMLS_No_Key\');showhide(\'GOTMLS_Key\', true);check_for_updates();" /></span></form></div></li>
139 <li>Definitions: <span id="GOTMLS_definitions_date" class="GOTMLS_date">'.$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"].'</span></li></ul>
140 <form id="updateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
141 <img style="display: none; float: left; margin-right: 4px;" src="'.GOTMLS_images_path.'checked.gif" height=16 width=16 alt="definitions updated" id="autoUpdateDownload" onclick="showhide(\'autoUpdateForm\', true); showhide(\'registerKeyForm\', true); showhide(\'clear_updates\', true); getElementById(\'registerFormMessage\').innerHTML = \'<p>You can change your registered email here if you want.</p>\';">
142 '.str_replace('findUpdates', 'Definition_Updates', $Update_Div).'
143 <div id="autoUpdateForm" style="display: none;">
144 <input type="submit" style="width: 100%;" name="auto_update" value="'.__("Download new definitions!",'gotmls').'">
145 </div>
146 </form>
147 <form id="clearupdateform" method="post" name="updateform" action="'.str_replace("GOTMLS_mt=", "GOTMLS_last_mt=", GOTMLS_script_URI).'&'.$head_nonce.'">
148 <input name="UPDATE_definitions_array" value="D" type="hidden">
149 <input type="submit" style="display: none; width: 100%; color: #ff0; background-color: #c33" id="clear_updates" value="'.__("Delete ALL definitions!",'gotmls').'">
150 </form>
151 <div id="registerKeyForm" style="display: none;"><button onclick="force_update_check(500);" style="float: right;">Check Again</button><span id="registerFormMessage" style="color: #F00"><p>'.__("Get instant access to definition updates.",'gotmls').'</p></span><p>
152 '.__("If you have not already registered your Key then register now using the form below.<br />* All registration fields are required<br />** I will NOT share your information.",'gotmls').'</p>
153 <form id="registerform" onsubmit="return sinupFormValidate(this);" action="'.GOTMLS_plugin_home.'wp-login.php?action=register" method="post" name="registerform" target="_blank"><input type="hidden" name="redirect_to" id="register_redirect_to" value="/donate/"><input type="hidden" name="user_login" id="register_user_login" value=""><input type="hidden" name="old_user_email" id="old_user_email" value="'.$reg_email_key.'">
154 <div>'.__("Your Full Name:",'gotmls').'</div>
155 <div style="float: left; width: 50%;"><input style="width: 100%;" id="first_name" type="text" name="first_name" value="'.$current_user->user_firstname.'" /></div>
156 <div style="float: left; width: 50%;"><input style="width: 100%;" id="last_name" type="text" name="last_name" value="'.$current_user->user_lastname.'" /></div>
157 <div style="clear: left; width: 100%;">
158 <div>'.__("A password will be e-mailed to this address:",'gotmls').(GOTMLS_strlen($reg_email_key) == 32 && $reg_email_key != md5($current_user->user_email)?'<br /><span style="color: #C00;">'.__("Note: The pre-populated email below is NOT the address this site is currently registered under!",'gotmls').'</span>':"").'</div>
159 <input style="width: 100%;" id="user_email" type="text" name="user_email" value="'.$current_user->user_email.'" /></div>
160 <div>
161 <div>'.__("Your WordPress Site URL:",'gotmls').'</div>
162 <input style="width: 100%;" id="user_url" type="text" name="user_url" value="'.GOTMLS_siteurl.'" readonly /></div>
163 <div>
164 <div>'.__("Plugin Installation Key:",'gotmls').'</div>
165 <input style="width: 100%;" id="installation_key" type="text" name="installation_key" value="'.GOTMLS_installation_key.'" readonly /><input id="old_key" type="hidden" name="old_key" value="'.md5($GOTMLS_url_parts[2]).'" /></div>
166 <input style="width: 100%;" id="wp-submit" type="submit" name="wp-submit" value="Register Now!" /></form></div>'.(false && $isRegistered?'Registered to: '.$isRegistered:"").$Update_Link, "stuffbox").'
167 <script type="text/javascript">
168 var pri_addr = "'.$Update_Definitions[0].'";
169 var alt_addr = "'.$Update_Definitions[1].'";
170 function check_for_updates() {
171 showhide("Definition_Updates", true);
172 stopCheckingDefinitions = checkPrimaryUpdateServer();
173 }
174 function force_update_check(wait) {
175 document.getElementById("Definition_Updates").innerHTML = \'<img src="'.GOTMLS_images_path.'wait.gif">'.GOTMLS_strip4java(__("Checking Registration ...",'gotmls')).'\';
176 showhide("Definition_Updates", true);
177 showhide("autoUpdateForm", true);
178 showhide("autoUpdateForm");
179 showhide("registerKeyForm", true);
180 showhide("registerKeyForm");
181 showhide("clear_updates", true);
182 showhide("clear_updates");
183 setTimeout(function() {var GOTMLS_update_time = new Date();stopCheckingDefinitions = checkPrimaryUpdateServer(\'&dt=\'+GOTMLS_update_time.getTime());}, wait);
184 }
185 function updates_complete(chk) {
186 if (auto_img = document.getElementById("autoUpdateDownload")) {
187 auto_img.style.display="block";
188 check_for_donation(chk);
189 }
190 }
191 function sinupFormValidate(form) {
192 var error = "";
193 if(form["first_name"].value == "")
194 error += "'.__("First Name is a required field!",'gotmls').'\n";
195 if(form["last_name"].value == "")
196 error += "'.__("Last Name is a required field!",'gotmls').'\n";
197 if(form["user_email"].value == "")
198 error += "'.__("Email Address is a required field!",'gotmls').'\n";
199 else {
200 if (uem = document.getElementById("register_user_login"))
201 uem.value = form["user_email"].value;
202 if (uem = document.getElementById("register_redirect_to"))
203 uem.value = "/donate/?email="+form["user_email"].value.replace("@", "%40");
204 }
205 if(form["user_url"].value == "")
206 error += "'.__("Your WordPress Site URL is a required field!",'gotmls').'\n";
207 if(form["installation_key"].value == "")
208 error += "'.__("Plugin Installation Key is a required field!",'gotmls').'\n";
209 if(error != "") {
210 alert(error);
211 return false;
212 } else {
213 force_update_check(15000);
214 return true;
215 }
216 }
217 var divNAtext = false;
218 function loadGOTMLS() {
219 clearTimeout(divNAtext);
220 setDivNAtext();
221 '.$GLOBALS["GOTMLS"]["tmp"]["onLoad"].'
222 }
223 if ('.($defLatest+GOTMLS_strlen($isRegistered)).')
224 check_for_updates();
225 /* else
226 showhide("registerKeyForm", true);*/
227 if (divNAtext)
228 loadGOTMLS();
229 else
230 divNAtext=true;
231 </script>
232 '.GOTMLS_box(__("Resources & Links",'gotmls'), '
233 <div id="pastDonations"></div>
234 <center>
235 <a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span> Donate Here <span style="text-decoration: none !important; font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span></a>
236 </center>
237 <ul class="GOTMLS-sidebar-links">
238 <li style="float: right;"><b>on <a target="_blank" href="https://profiles.wordpress.org/scheeeli#content-plugins">WordPress.org</a></b><ul class="GOTMLS-sidebar-links">
239 <li><a target="_blank" href="https://wordpress.org/plugins/gotmls/faq/">Plugin FAQs</a></li>
240 <li><a target="_blank" href="https://wordpress.org/support/plugin/gotmls">Forum Posts</a></li>
241 <li><a target="_blank" href="https://wordpress.org/support/view/plugin-reviews/gotmls">Plugin Reviews</a></li>
242 </ul></li>
243 <li><img src="//gravatar.com/avatar/5feb789dd3a292d563fea3b885f786d6?s=16" border="0" alt="Plugin site:"><b><a target="_blank" href="'.GOTMLS_plugin_home.'">GOTMLS.NET</a></b></li>
244 <li><img src="//gravatar.com/avatar/c0a17ace1ccb92bf930ab3621bfd5e7c?s=16" border="0" alt="Hosting site:"><b><a target="_blank" href="https://supersecurehosting.com/">Secure Hosting</a></b></li>
245 <li><img src="https://s.gravatar.com/avatar/7530906968df6594bfbe934ddc117f58?s=16" border="0" alt="mail:"><b><a target="_blank" href="mailto:eli@gotmls.net">Email Eli</a></b></li>
246 </ul>
247 <a target="_blank" href="https://www.google.com/transparencyreport/safebrowsing/diagnostic/index.html#url='.rawurlencode(GOTMLS_siteurl).'">Google Safe Browsing Diagnostic</a>', "stuffbox").$optional_box.'</div>';
248 if (isset($GLOBALS["GOTMLS"]["tmp"]["stuffbox"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["stuffbox"])) {
249 echo '
250 <script type="text/javascript">
251 function stuffbox_showhide(id) {
252 divx = document.getElementById(id);
253 if (divx) {
254 if (divx.style.display == "none" || arguments[1]) {';
255 $else = '
256 if (divx = document.getElementById("GOTMLS-right-sidebar"))
257 divx.style.width = "30px";
258 if (divx = document.getElementById("GOTMLS-main-section"))
259 divx.style.marginRight = "30px";';
260 foreach ($GLOBALS["GOTMLS"]["tmp"]["stuffbox"] as $md5 => $bTitle) {
261 echo "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'block';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".GOTMLS_strip4java($bTitle, true)."';";
262 $else .= "\nif (divx = document.getElementById('inside_$md5'))\n\tdivx.style.display = 'none';\nif (divx = document.getElementById('title_$md5'))\n\tdivx.innerHTML = '".substr($bTitle, 0, 1)."';";
263 }
264 echo '
265 if (divx = document.getElementById("GOTMLS-right-sidebar"))
266 divx.style.width = "300px";
267 if (divx = document.getElementById("GOTMLS-main-section"))
268 divx.style.marginRight = "300px";
269 return true;
270 } else {'.$else.'
271 return false;
272 }
273 }
274 }
275 if (getWindowWidth(780) == 780)
276 setTimeout(function() {stuffbox_showhide("inside_'.$md5.'");}, 200);
277 </script>';
278 }
279 echo '
280 <div id="GOTMLS-main-section" style="margin-right: 300px;">
281 <div class="metabox-holder GOTMLS" style="width: 100%;" id="GOTMLS-metabox-container">';
282 }
283
284 function GOTMLS_get_scan_history() {
285 global $wpdb;
286 $GOTMLS_nonce_context = __FUNCTION__."285";
287 $GOTMLS_nonce = GOTMLS_set_nonce($GOTMLS_nonce_context);
288 $imported = 0;
289 $LastScan = '';
290 if (isset($_GET["GOTMLS_clear_history"]) && (GOTMLS_strlen($clear_hist = preg_replace('/[^0-9a-f]++]i/', "", $_GET["GOTMLS_clear_history"])) == 32) && GOTMLS_get_nonce($GOTMLS_nonce_context) && GOTMLS_user_can()) {
291 if (($ors = $wpdb->get_results($wpdb->prepare("SELECT ID, post_parent, post_date FROM `$wpdb->posts` WHERE post_type = %s AND post_name = %s", 'gotmls_results', $clear_hist), ARRAY_A)) && isset($ors[0]["post_parent"]) && is_numeric($ors[0]["post_parent"]) && ($ors[0]["post_parent"] > 0) && ($wpdb->get_results($wpdb->prepare("SELECT COUNT(ID) FROM `$wpdb->posts` WHERE post_type = %s AND post_parent = %s", 'gotmls_results', $ors[0]["ID"]), ARRAY_A)) && ($cleared = $wpdb->query($wpdb->prepare("DELETE FROM `$wpdb->posts` WHERE post_type = %s AND post_date < %s", 'gotmls_results', $ors[0]["post_date"]))))
292 $wpdb->update($wpdb->posts, array("post_parent" => 0), array("post_type" => 'gotmls_results', "ID" => $ors[0]["ID"]));
293 $LastScan .= sprintf(__("Cleared %s records from the history.",'gotmls'), $cleared);
294 }
295 $SQL = $wpdb->prepare("SELECT * FROM `$wpdb->posts` WHERE post_type = %s ORDER BY post_date DESC", 'gotmls_results');
296 $units = array("seconds"=>60,"minutes"=>60,"hours"=>24,"days"=>365,"years"=>10);
297 if (!($prs = $wpdb->get_results($SQL, ARRAY_A))) {
298 if ($ors = $wpdb->get_results($wpdb->prepare("SELECT substring_index(option_name, '/', -1) AS `mt`, option_name, option_value FROM `$wpdb->options` WHERE option_name LIKE %s ORDER BY mt ASC", 'GOTMLS_scan_log/%'), ARRAY_A)) {
299 $parent = 0;
300 foreach ($ors as $row) {
301 $GOTMLS_scanlog = (isset($row["option_name"])?get_option($row["option_name"], array()):array());
302 $option_names = explode("/", "/".$row["option_name"]);
303 $mt = array_pop($option_names);
304 if (GOTMLS_strlen($mt) && is_numeric($mt)) {
305 $insert = array("post_name" => md5($mt), "post_content" => json_encode($GOTMLS_scanlog), "post_author" => GOTMLS_get_current_user_id(0), "post_type" => 'gotmls_results', "post_date_gmt" => date("Y-m-d H:i:s", (int) $mt), "post_parent" => $parent);
306 if (isset($GOTMLS_scanlog["scan"]["type"]) && GOTMLS_strlen($GOTMLS_scanlog["scan"]["type"]))
307 $insert["post_title"] = GOTMLS_sanitize($GOTMLS_scanlog["scan"]["type"]);
308 else
309 $insert["post_title"] = "Unknown scan type";
310 if (isset($GOTMLS_scanlog["scan"]["dir"]) && @is_dir($GOTMLS_scanlog["scan"]["dir"]))
311 $insert["post_title"] .= " of ".basename($GOTMLS_scanlog["scan"]["dir"]);
312 if (isset($GOTMLS_scanlog["scan"]["start"]) && is_numeric($GOTMLS_scanlog["scan"]["start"])) {
313 $insert["post_date"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["start"]);
314 $insert["post_modified"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["start"]);
315 $ukeys = array_keys($units);
316 $insert["post_title"] .= " on ".date("Y-m-d", $GOTMLS_scanlog["scan"]["start"]);
317 if (isset($GOTMLS_scanlog["scan"]["finish"]) && is_numeric($GOTMLS_scanlog["scan"]["finish"]) && ($GOTMLS_scanlog["scan"]["finish"] >= $GOTMLS_scanlog["scan"]["start"])) {
318 $insert["post_modified"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["finish"]);
319 $insert["post_modified_gmt"] = date("Y-m-d H:i:s", $GOTMLS_scanlog["scan"]["finish"]);
320 $time = ($GOTMLS_scanlog["scan"]["finish"] - $GOTMLS_scanlog["scan"]["start"]);
321 for ($unit = $ukeys[0], $key=0; (isset($units[$ukeys[$key]]) && $key < (count($ukeys) - 1) && $time >= (2 * $units[$ukeys[$key]])); $unit = $ukeys[++$key])
322 $time = floor($time/$units[$ukeys[$key]]);
323 if (1 == $time)
324 $unit = substr($unit, 0, -1);
325 if ($time)
326 $insert["post_title"] .= " ran for $time $unit";
327 } else
328 $insert["post_title"] .= " was not finished!";
329 } else
330 $insert["post_title"] .= " failed to started!";
331 if ($inserted = $wpdb->insert($wpdb->posts, $insert)) {
332 $imported++;
333 $parent = $wpdb->insert_id;
334 } else
335 return sprintf(__("Failed to Import Scan History ID %s : %s",'gotmls'), $mt, $wpdb->last_error);
336 } else
337 return sprintf(__("Error: Failed to migrate old Scan History from %s.",'gotmls'), $row["option_name"]);
338 }
339 if ($cleared = $wpdb->query($wpdb->prepare("DELETE FROM `$wpdb->options` WHERE option_name LIKE %s", 'GOTMLS_scan_log/%')))
340 $LastScan .= sprintf(__("Converted %s of %s records from the Scan History into the new Scan Log record. Future Scans will now store more result data in the new Log.",'gotmls'), $imported, $cleared);
341 $prs = $wpdb->get_results($SQL, ARRAY_A);
342 }
343 }
344 if ($prs && is_array($prs) && count($prs)) {
345 $scans = 0;
346 $PreScan = '<ul class="GOTMLS-scanlog GOTMLS-sidebar-links">'."\n<li>";
347 foreach ($prs as $row) {
348 $LastScan .= $PreScan.GOTMLS_sanitize($row["post_title"]);
349 if ($scans)
350 $PreScan = '<a href="'.GOTMLS_script_URI.'&GOTMLS_clear_history='.$row["post_name"].'&'.$GOTMLS_nonce.'">[clear history below this entry]</a></li>'."\n<li>";
351 else
352 $PreScan = "</li>\n<li>";
353 $scans++;
354 }
355 $LastScan .= '</li></ul>';
356 } else
357 $LastScan .= '<h3>'.__("No Scans have been logged",'gotmls').'</h3>';
358 return "$LastScan\n";
359 }
360
361 function GOTMLS_get_whitelists() {
362 global $wpdb, $post;
363 $Q_Page = '';
364 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"])) {
365 $Q_Page .= '<ul name="found_Quarantine" id="found_Quarantine" class="GOTMLS_plugin known" style="background-color: #ccc; padding: 0;"><h3>'.__("Globally White-listed files",'gotmls').'<span class="GOTMLS_date">'.__("# of patterns",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Updated",'gotmls').'</span></h3>';
366 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["whitelist"] as $file => $non_threats) {
367 if (isset($non_threats[0])) {
368 $updated = GOTMLS_sexagesimal($non_threats[0]);
369 unset($non_threats[0]);
370 } else
371 $updated = "Unknown";
372 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($non_threats).'</span><span class="GOTMLS_date">'.$updated."</span>$file</li>\n";
373 }
374 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"])) {
375 $Q_Page .= '<h3>'.__("WordPress Core files",'gotmls').'<span class="GOTMLS_date">'.__("# of files",'gotmls').'</span></h3>';
376 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"] as $ver => $files) {
377 $Q_Page .= '<li style="margin: 4px 12px;"><span class="GOTMLS_date">'.count($files)."</span>Version $ver</li>\n";
378 }
379 }
380 $Q_Page .= "</ul>";
381 }
382 $my_query = new WP_Query(array("orderby" => 'date', "post_type" => 'GOTMLS_quarantine', "post_status" => array('pending'), "posts_per_page" => 500));
383 if ($my_query->have_posts()) {
384 $Q_Page .= '<form method="POST" action="'.admin_url('admin-ajax.php').'" target="GOTMLS_iFrame" name="GOTMLS_Form_whitelist"><input type="hidden" id="GOTMLS_whitelist" name="GOTMLS_whitelist" value="list_group"><input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce("GOTMLS_whitelist")).'"><input type="hidden" name="action" value="GOTMLS_whitelist"><p id="whitelist_buttons" style="display: none;"><input id="repair_button" type="submit" value="'.__("Remove selected files from the whitelist",'gotmls').'" class="button-primary" onclick="if (confirm(\''.__("Are you sure you want to remove these files from the whitelist?",'gotmls').'\')) { loadIframe(\'File Removal Results\'); } else return false;" /></p><p><b>'.__("The following files have been whitelisted by you. Any infections or malicious code found in the current versions of these files will be ignored in future scans. If these files are modified or updated from the current versions recorded here or if you remove them from this list then they may be flagged again in future scans.",'gotmls').'</b></p>
385 <ul name="found_whitelist" id="found_whitelist" class="GOTMLS_plugin" style="background-color: #ccc; padding: 0;"><h3 style="margin: 8px 12px;">'.__(" Whitelisted Files",'gotmls').'<span class="GOTMLS_date">'.__("Whitelisted",'gotmls').'</span><span class="GOTMLS_date">'.__("Date Modified",'gotmls').'</span></h3>';
386 $root_path = implode(GOTMLS_slash(), array_slice(GOTMLS_explode_dir(__FILE__), 0, (2 + intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"])) * -1));
387 while ($my_query->have_posts()) {
388 $my_query->the_post();
389 $gif = 'checked.gif';
390 $threat = '';
391 $action = "\" onchange=\"document.getElementById('whitelist_buttons').style.display = 'block';";
392 $fa = GOTMLS_threats_found_meta(GOTMLS_object_to_array($post));
393 if (is_file($post->post_title))
394 $link = GOTMLS_error_link(__("View Whitelisted File",'gotmls').md5(GOTMLS_decode($post->post_content))."O".intval(GOTMLS_decode($post->post_content)), $post->post_title, $threat);
395 else {
396 $gif = "question.gif\" onload=\"document.getElementById('whitelist_buttons').style.display = 'block'; if (Whitelists = document.getElementById('box_".md5("Whitelists")."')) Whitelists.style.display = 'block';";
397 $_GET['Whitelists'] = "visible";
398 $threat = 'potential';
399 $action = '" checked="true';
400 $link = GOTMLS_error_link(__("Remove Missing File from Whitelist",'gotmls'), $post->post_title, $threat);
401 }
402 $chksum = preg_replace('/[^a-f\d]++/', "", $post->post_mime_type)."O".intval($post->comment_count);
403 $Q_Page .= '
404 <li id="GOTMLS_whitelist_'.$chksum.'" class="GOTMLS_quarantine_item" onmouseover="this.style.fontWeight=\'bold\';" onmouseout="this.style.fontWeight=\'normal\';"><span class="GOTMLS_date">'.GOTMLS_error_link(__("View Whitelisted Contents $chksum",'gotmls'), $post->ID, $threat).$post->post_date_gmt.'</a></span><span title="modified: '.GOTMLS_htmlspecialchars($post->post_modified).'" class="GOTMLS_date">'.GOTMLS_htmlspecialchars($post->post_modified_gmt).'</span><input type="checkbox" name="GOTMLS_chksum[]" id="whitelist_'.$chksum.'" value="'.$chksum.$action.'" /><img src="'.GOTMLS_images_path.$gif.'" height=16 width=16 alt="Q">'.$link.GOTMLS_htmlspecialchars(str_replace($root_path, "...", $post->post_title))."</a></li>\n";
405 }
406 $Q_Page .= "\n</ul>\n</form>";
407 }
408 wp_reset_query();
409 return "$Q_Page\n";
410 }
411
412 function GOTMLS_Quarantine_Trash() {
413 global $wpdb;
414 $Q_Page = '<div id="empty_trash_link" style="float: right;"><form method="post" onsubmit="if (curDiv = document.getElementById(\'empty_trash_link\')) curDiv.style.display = \'none\';" target="GOTMLS_statusFrame" action="'.GOTMLS_admin_url('GOTMLS_empty_trash', GOTMLS_set_nonce("empty_trash")).'">';
415 if (($trashed = $wpdb->get_var("SELECT COUNT(*) FROM $wpdb->posts WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) > 1)
416 $Q_Page .= '<input class="primary" style="float: right;" type="submit" value="RESTORE" name="alter"><input class="primary" style="color: red; float: right;" type="submit" value="DELETE" name="alter"><span style="float: right; margin: 3px;">'.sprintf(__("%d Quarantine Records in the Trash",'gotmls'), (INT) $trashed)."</span>";
417 return "$Q_Page</form></div>\n";
418 }
419
420 function GOTMLS_ajax_View_Quarantine() {
421 GOTMLS_kill_invalid_user();
422 GOTMLS_ajax_load_update();
423 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_get_header().GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine())))));
424 }
425
426 function GOTMLS_View_Quarantine() {
427 GOTMLS_ajax_load_update();
428 $echo = GOTMLS_box($Q_Page = "Whitelists", GOTMLS_get_whitelists());
429 if (!isset($_GET['Whitelists']))
430 $echo .= "\n<script>\nshowhide('inside_".md5($Q_Page)."');\n</script>\n";
431 $echo .= GOTMLS_box(GOTMLS_Quarantine_Trash().__("View Quarantine",'gotmls'), GOTMLS_get_quarantine());
432 GOTMLS_display_header();
433 echo "$echo\n</div></div></div>";
434 }
435
436 function GOTMLS_Firewall_Options() {
437 global $current_user, $wpdb, $table_prefix;
438 GOTMLS_ajax_load_update();
439 GOTMLS_display_header();
440 $GOTMLS_nonce_found = GOTMLS_get_nonce();
441 $gt = ">"; // This local variable never changes
442 $lt = "<"; // This local variable never changes
443 $save_action = "";
444 $patch_attr = array(
445 array(
446 "icon" => "blocked",
447 "language" => __("Your WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. Applying this patch will block access to the WordPress Login page whenever this type of attack is detected.",'gotmls'),
448 "status" => __('Not Installed','gotmls'),
449 "action" => __('Install Patch','gotmls')
450 ),
451 array(
452 "language" => __("Your WordPress site has the current version of my brute-force Login protection installed.",'gotmls'),
453 "action" => __('Uninstall Patch','gotmls'),
454 "status" => __('Enabled','gotmls'),
455 "icon" => "checked"
456 ),
457 array(
458 "language" => __("Your WordPress Login page has the old version of my brute-force protection installed. Upgrade this patch to improve the protection on the WordPress Login page and preserve the integrity of your WordPress core files.",'gotmls'),
459 "action" => __('Upgrade Patch','gotmls'),
460 "status" => __('Out of Date','gotmls'),
461 "icon" => "threat"
462 )
463 );
464 $find = '|<Files[^>]+xmlrpc.php>(.+?)</Files>\s*(# END GOTMLS Patch to Block XMLRPC Access\s*)*|is';
465 $deny = "\n<IfModule !mod_authz_core.c>\norder deny,allow\ndeny from all\nallow from ".GOTMLS_REMOTEADDR;
466 $allow = GOTMLS_REMOTEADDR;
467 if (isset($_SERVER["SERVER_ADDR"])) {
468 $deny .= "\nallow from ".GOTMLS_safe_ip($_SERVER["SERVER_ADDR"]);
469 $allow .= " ".GOTMLS_safe_ip($_SERVER["SERVER_ADDR"]);
470 }
471 $deny .= "\n</IfModule>\n<IfModule mod_authz_core.c>\nRequire";
472 if (GOTMLS_strlen(trim($allow)) > 0)
473 $deny .= " ip $allow";
474 else
475 $deny .= " all denied";
476 $deny .= "\n</IfModule>";
477 if (count($GLOBALS["GOTMLS"]["tmp"]["apache"]) > 1)
478 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
479 else {
480 if (isset($GLOBALS["GOTMLS"]["tmp"]["apache"][0]) && (strtolower(substr($GLOBALS["GOTMLS"]["tmp"]["apache"][0]."123456", 0, 6)) == "apache"))
481 $errdiv = "<!-- ".$GLOBALS["GOTMLS"]["tmp"]["apache"][0]." -->";
482 else
483 $errdiv = "<div class='error'>".__('Unable to find Apache on this server, this patch work on Apache servers!','gotmls')."</div>";
484 }
485 $Firewall_nonce = $lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce(__FUNCTION__."420")).'"'.$gt;
486 $XMLRPC_patch_action = $lt.'hr /'.$gt.$lt.'form method="POST" name="GOTMLS_Form_XMLRPC_patch"'.$gt.$Firewall_nonce.$lt."script$gt\nfunction setFirewall(opt, val) {\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_opt'))\n\t\tautoUpdateDownloadGIF.value = opt;\n\tif (autoUpdateDownloadGIF = document.getElementById('fw_val'))\n\t\tautoUpdateDownloadGIF.value = val;\n}\nfunction testComplete() {\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_XMLRPC_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_XMLRPC_patch_searching');\n\tshowhide('GOTMLS_XMLRPC_patch_button', true);\n}\n}\nwindow.onload=testComplete;\n$lt/script$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="hidden" name="GOTMLS_XMLRPC_patching" value="';
487 $patch_found = false;
488 $head = str_replace(array('|<Files[^>]+', '(.+?)', '\\s*(', '\\s*)*|is'), array("<Files ", "$deny\n", "\n", "\n"), $find);
489 $htaccess = "";
490 if (is_file(ABSPATH.'.htaccess'))
491 if (($htaccess = @file_get_contents(ABSPATH.'.htaccess')) && GOTMLS_strlen($htaccess))
492 $patch_found = preg_match($find, $htaccess);
493 if ($patch_found) {
494 $errdiv = "";
495 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0) && GOTMLS_save_contents(ABSPATH.'.htaccess', preg_replace($find, "", $htaccess)))
496 $XMLRPC_patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Allowing Access';
497 elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] < 0))
498 $XMLRPC_patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Blocking: '.sprintf(__("Failed to remove XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".GOTMLS_strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
499 else
500 $XMLRPC_patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Blocked';
501 } else {
502 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0) && GOTMLS_save_contents(ABSPATH.'.htaccess', "$head$htaccess")) {
503 $XMLRPC_patch_action .= '-1"'.$gt.$lt.'input style="float: right;" type="submit" value="Unblock XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Now Blocked';
504 $errdiv = "";
505 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_XMLRPC_patching"]) && ($_POST["GOTMLS_XMLRPC_patching"] > 0))
506 $XMLRPC_patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Still Allowing Access: '.sprintf(__("Failed to install XMLRPC Protection [.htaccess %s]",'gotmls'),(is_readable(ABSPATH.'.htaccess')?'read-'.(is_writable(ABSPATH.'.htaccess')?'write?':'only!'):"unreadable!").": ".GOTMLS_strlen($htaccess).GOTMLS_fileperms(ABSPATH.'.htaccess'));
507 else
508 $XMLRPC_patch_action .= '1"'.$gt.$lt.'input style="float: right;" type="submit" value="Block XMLRPC Access" /'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'question.gif"'.$gt.$lt.'b'.$gt.'Block XMLRPC Access (Currently Allowing Access';
509 }
510 $XMLRPC_patch_action .= ")$errdiv$lt/b$gt$lt/p$gt{$lt}b$gt".__("(This patch only works on Apache servers and requires mod_rewrite to be functional)",'gotmls')."$lt/b$gt{$lt}br$gt\n".__("Most WordPress sites do not use the XMLRPC features and hack attempts on the xmlrpc.php file are more common then ever before. Even if there are no vulnerabilities for hackers to exploit, these attempts can cause slowness or downtime similar to a DDoS attack. This patch automatically blocks all external access to the xmlrpc.php file.",'gotmls')."$lt/div$gt$lt/form$gt";
511 $patch_status = 0;
512 $patch_found = -1;
513 $find = "#if\s*\(([^\&]+\&\&)?\s*file_exists\((.+?)(safe-load|wp-login)\.php'\)\)\s*require(_once)?\((.+?)(safe-load|wp-login)\.php'\);#";
514 $head = str_replace(array('#', '\\(', '\\)', '(_once)?', ')\\.', '\\s*', '(.+?)(', '|', '([^\\&]+\\&\\&)?'), array(' ', '(', ')', '_once', '.', ' ', '\''.dirname(__FILE__).'/', '/', '!in_array($_SERVER["REMOTE_ADDR"], array("'.GOTMLS_REMOTEADDR.'")) &&'), $find);
515 if (is_file(ABSPATH.'../wp-config.php') && !is_file(ABSPATH.'wp-config.php'))
516 $wp_config = '../wp-config.php';
517 else
518 $wp_config = 'wp-config.php';
519 $BFLP_patch_action = "";
520 if (is_file(ABSPATH.$wp_config)) {
521 if (($config = @file_get_contents(ABSPATH.$wp_config)) && GOTMLS_strlen($config)) {
522 if ($patch_found = preg_match($find, $config)) {
523 if (strpos($config, substr($head, strpos($head, "file_exists")))) {
524 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0) && GOTMLS_save_contents(ABSPATH.$wp_config, preg_replace('#'.$lt.'\?(?:php)?+\s*+(?://.*+\s*+)*+\?'.$gt.'#i', "", preg_replace($find, "", $config))))
525 $BFLP_patch_action .= GOTMLS_error_div(__("Removed Brute-Force Protection",'gotmls'));
526 else
527 $patch_status = 1;
528 } else {
529 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0) && GOTMLS_save_contents(ABSPATH.$wp_config, preg_replace($find, "$head", $config))) {
530 $BFLP_patch_action .= GOTMLS_error_div(__("Upgraded Brute-Force Protection",'gotmls'), "updated");
531 $patch_status = 1;
532 } else
533 $patch_status = 2;
534 }
535 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0) && GOTMLS_strlen($config) && ($patch_found == 0) && GOTMLS_save_contents(ABSPATH.$wp_config, "$lt?php\n$head// Load Brute-Force Protection by GOTMLS.NET before the WordPress bootstrap. ?$gt$config")) {
536 $BFLP_patch_action .= GOTMLS_error_div(__("Installed Brute-Force Protection",'gotmls'), "updated");
537 $patch_status = 1;
538 } elseif ($GOTMLS_nonce_found && isset($_POST["GOTMLS_patching"]) && ($_POST["GOTMLS_patching"] > 0))
539 $BFLP_patch_action .= GOTMLS_error_div(sprintf(__("Failed to install Brute-Force Protection (wp-config.php %s)",'gotmls'),(is_readable(ABSPATH.$wp_config)?'read-'.(is_writable(ABSPATH.$wp_config)?'write':'only'):"unreadable").": ".GOTMLS_strlen($config).GOTMLS_fileperms(ABSPATH.$wp_config)), "updated");
540 } else
541 $BFLP_patch_action .= GOTMLS_error_div(__("wp-config.php Not Readable!",'gotmls'));
542 } else
543 $BFLP_patch_action .= GOTMLS_error_div(__("wp-config.php Not Found!",'gotmls'));
544 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_firewall_option"]) && GOTMLS_strlen($_POST["GOTMLS_firewall_option"]) && isset($_POST["GOTMLS_firewall_value"]) && GOTMLS_strlen($_POST["GOTMLS_firewall_value"])) {
545 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"][GOTMLS_sanitize($_POST["GOTMLS_firewall_option"])] = (INT) $_POST["GOTMLS_firewall_value"];
546 if (update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]))
547 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";
548 else
549 $save_action = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -40px; margin: 0 300px 0 130px;' class='updated'$gt\nSave Failed!$lt/div$gt\n";
550 }
551 $sec_opts = $lt.'form method="POST" name="GOTMLS_Form_firewall"'.$gt.$lt.'input type="hidden" id="fw_opt" name="GOTMLS_firewall_option" value="traversal"'.$gt.$lt.'input type="hidden" name="GOTMLS_firewall_value" id="fw_val" value="0"'.$gt.$Firewall_nonce;
552 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]) && array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"]))
553 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["firewall"] as $TP => $VA)
554 if (is_array($VA) && count($VA) > 3 && GOTMLS_strlen($VA[1]) && GOTMLS_strlen($VA[2]))
555 $sec_opts .= $lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="submit" style="float: right;" value="'.(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["$TP"]?"Enable Protection\" onclick=\"setFirewall('$TP', 0);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt."b$gt$VA[1] (Currently Disabled)":"Disable Protection\" onclick=\"setFirewall('$TP', 1);\"$gt$lt".'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'checked.gif"'.$gt.$lt."b$gt$VA[1] (Automatically Enabled)")."$lt/b$gt$lt/p$gt$VA[2]$lt/div$gt$lt".'hr /'.$gt;
556 $style = ' display: none;" id="GOTMLS_patch_button"'.$gt.$lt.'div id="GOTMLS_patch_searching" style="float: right;"'.$gt.__("Checking for session compatibility ...",'gotmls').' '.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /'.$gt.$lt.'/div'.$gt;
557 $script = "";
558 if ($patch_status) {
559 $sec_opts .= $lt.'input type="submit" style="float: right; margin: 6px;" value="'.(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]?"Show Protection Logo\" onclick=\"setFirewall('BFLP', 0);\"$gt$lt".'div style="float: right; margin: 8px;"'."$gt Logo will be hidden on the login page":"Hide Protection Logo\" onclick=\"setFirewall('BFLP', 1);\"$gt$lt".'div style="float: right; margin: 8px;"'.$gt.$lt.'img style="height: 24px; vertical-align: middle;"src="'.GOTMLS_images_path.'GOTMLS-Loading.gif" /'."$gt Brute-Force Protection is Active")."$lt/div$gt";
560 $style = '"'.$gt;
561 } else
562 $script = $lt."script type='text/javascript'$gt\nfunction search_patch_onload() {\n\tstopCheckingSession = checkupdateserver('".GOTMLS_admin_url('GOTMLS_log_session')."');\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', search_patch_onload)\nelse\n\tdocument.attachEvent('onload', search_patch_onload);\n$lt/script$gt";
563 $sec_opts .= "$lt/form$gt\n$BFLP_patch_action\n$lt".'form method="POST" name="GOTMLS_Form_patch"'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$Firewall_nonce.$lt.'input type="submit" value="'.$patch_attr[$patch_status]["action"].'" style="float: right;'.$style.$lt.'input type="hidden" name="GOTMLS_patching" value="1"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$patch_attr[$patch_status]["icon"].'.gif"'.$gt.$lt.'b'.$gt.'Brute-force Protection '.$patch_attr[$patch_status]["status"].$lt.'/b'.$gt.$lt.'/p'.$gt.$patch_attr[$patch_status]["language"].__(" For more information on Brute-Force attack prevention and the WordPress wp-login-php file ",'gotmls').' '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-login-php/"'.$gt.__("read my blog",'gotmls')."$lt/a$gt.$lt/div$gt$lt/form$gt\n$XMLRPC_patch_action\n$script";
564 $admin_notice = "";
565 if ($current_user->user_login == "admin") {
566 $admin_notice .= $lt.'hr /'.$gt;
567 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_admin_username"]) && ($current_user->user_login != trim($_POST["GOTMLS_admin_username"])) && GOTMLS_strlen(trim($_POST["GOTMLS_admin_username"])) && preg_match('/^\s*[a-z_0-9\@\.\-]{3,}\s*$/i', $_POST["GOTMLS_admin_username"])) {
568 if ($wpdb->update($wpdb->users, array("user_login" => trim($_POST["GOTMLS_admin_username"])), array("user_login" => $current_user->user_login))) {
569 $wpdb->query($wpdb->prepare("UPDATE `{$wpdb->prefix}sitemeta` SET `meta_value` = REPLACE(`meta_value`, 's:5:\"admin\";', %s) WHERE `meta_key` = 'site_admins' AND `meta_value` like %s", 's:'.GOTMLS_strlen(trim($_POST["GOTMLS_admin_username"])).':"'.trim($_POST["GOTMLS_admin_username"]).'";', '%s:5:"admin";%'));
570 $admin_notice .= GOTMLS_error_div(sprintf(__("You username has been change to %s. Don't forget to use your new username when you login again.",'gotmls'), $_POST["GOTMLS_admin_username"]), "updated");
571 } else
572 $admin_notice .= GOTMLS_error_div(sprintf(__("SQL Error changing username: %s. Please try again later.",'gotmls'), $wpdb->last_error));
573 } else {
574 if (isset($_POST["GOTMLS_admin_username"]))
575 $admin_notice .= GOTMLS_error_div(sprintf(__("Your new username must be at least 3 characters and can only contain &quot;%s&quot;. Please try again.",'gotmls'), "a-z0-9_.-@"), "updated");
576 $admin_notice .= $lt.'form method="POST" name="GOTMLS_Form_admin"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'div style="float: left;"'.$gt.__("Change your username:",'gotmls').$lt.'/div'.$gt.$Firewall_nonce.$lt.'input style="float: left;" type="text" id="GOTMLS_admin_username" name="GOTMLS_admin_username" size="6" value="'.$current_user->user_login.'"'.$gt.$lt.'input style="float: left;" type="submit" value="Change"'.$gt.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.'threat.gif"'.$gt.$lt.'b'.$gt.'Admin Notice'.$lt.'/b'.$gt.$lt.'/p'.$gt.__("Your username is \"admin\", this is the most commonly guessed username by hackers and brute-force scripts. It is highly recommended that you change your username immediately.",'gotmls').$lt.'/div'.$gt.$lt.'/form'.$gt;
577 }
578 }
579 if ($GOTMLS_nonce_found && isset($_POST["GOTMLS_wpfirewall_action"])) {
580 if ($_POST["GOTMLS_wpfirewall_action"] == "exclude_terms")
581 update_option("WP_firewall_exclude_terms", "");
582 elseif ($_POST["GOTMLS_wpfirewall_action"] == "whitelisted_ip") {
583 $ips = GOTMLS_uckserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"));
584 if (is_array($ips))
585 $ips = array_merge($ips, array(GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"])));
586 else
587 $ips = array(GOTMLS_safe_ip($_SERVER["REMOTE_ADDR"]));
588 update_option("WP_firewall_whitelisted_ip", serialize($ips));
589 }
590 }
591 if (get_option("WP_firewall_exclude_terms", "Not Found!") == "allow") {
592 $end = "$lt/div$gt$lt/form$gt\n{$lt}hr /$gt";
593 $img = 'threat.gif"';
594 $button = $lt.'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'exclude_terms\';" value="'.__("Disable this Rule",'gotmls').'"'.$gt;
595 $wpfirewall_action = $lt.'form method="POST" name="GOTMLS_Form_wpfirewall2"'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="hidden" name="GOTMLS_wpfirewall_action" id="GOTMLS_wpfirewall_action" value=""'.$gt.$Firewall_nonce.$button.$lt.'/div'.$gt.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'p'.$gt.$lt.'img src="'.GOTMLS_images_path.$img.$gt.$lt.'b'.$gt."WP Firewall 2 (Conflicting Firewall Rule)$lt/b$gt$lt/p$gt".__("The Conflicting Firewall Rule (WP_firewall_exclude_terms) activated by the WP Firewall 2 plugin has been shown to interfere with the Definition Updates and WP Core File Scans in my Anti-Malware plugin. I recommend that you disable this rule in the WP Firewall 2 plugin.",'gotmls').$end;
596 if (isset($_SERVER["REMOTE_ADDR"])) {
597 if (is_array($ips = GOTMLS_uckserialize(get_option("WP_firewall_whitelisted_ip", "not Array!"))) && in_array($_SERVER["REMOTE_ADDR"], $ips))
598 $wpfirewall_action = str_replace(array($img, $end), array('question.gif"', __(" However, your current IP has been Whitelisted so you could probably keep this rule enabled if you really want to.",'gotmls').$end), $wpfirewall_action);
599 else
600 $wpfirewall_action = str_replace(array($button, $end), array($button.$lt."br /$gt$lt".'input type="submit" onclick="document.getElementById(\'GOTMLS_wpfirewall_action\').value=\'whitelisted_ip\';" value="'.__("Whitelist your IP",'gotmls').'"'.$gt, __(" However, if you would like to keep this rule enabled you should at least Whitelist your IP.",'gotmls').$end), $wpfirewall_action);
601 }
602 $sec_opts = $wpfirewall_action.$sec_opts;
603 }
604 echo GOTMLS_box(__("Firewall Options",'gotmls'), $save_action.$sec_opts.$admin_notice)."\n</div></div></div>";
605 }
606
607 function GOTMLS_get_registrant($you) {
608 global $current_user, $wpdb;
609 wp_get_current_user();
610 if (isset($you["you"]))
611 $you = $you["you"];
612 if (isset($you["user_email"]) && GOTMLS_strlen($you["user_email"]) == 32) {
613 if ($you["user_email"] == md5($current_user->user_email))
614 $registrant = $current_user->user_email;
615 elseif (!($registrant = $wpdb->get_var($wpdb->prepare("SELECT `user_nicename` FROM `$wpdb->users` WHERE MD5(`user_email`) = %s", $you["user_email"]))))
616 $registrant = GOTMLS_siteurl;
617 } else
618 $registrant = GOTMLS_siteurl;
619 return $registrant;
620 }
621
622 function GOTMLS_ajax_load_update() {
623 global $wpdb;
624 $GOTMLS_nonce_found = GOTMLS_get_nonce();
625 $YES_user_can = GOTMLS_kill_invalid_user();
626 $GOTMLS_definitions_versions = array();
627 $user_info = array();
628 $saved = false;
629 $moreJS = "";
630 $finJS = "\n}";
631 $form = 'registerKeyForm';
632 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key could not be confirmed!</li>";
633 $autoUpJS = '<span style="color: #C00;">This new feature is currently only available to registered users who have donated $29 or more.</span><br />';
634 if (is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
635 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names)
636 foreach ($definition_names as $definition_name=>$definition_version)
637 if (is_array($definition_version) && isset($definition_version[0]) && GOTMLS_strlen($definition_version[0]) == 5)
638 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
639 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
640 asort($GOTMLS_definitions_versions);
641 if (isset($_REQUEST["UPDATE_definitions_array"]) && GOTMLS_strlen($_REQUEST["UPDATE_definitions_array"]) && $GOTMLS_nonce_found && $YES_user_can) {
642 $DEF_url = 'http:'.GOTMLS_update_home.'definitions.php?'.GOTMLS_get_version_URL.'&'.GOTMLS_set_nonce(GOTMLS_update_home).'&d='.ur1encode(GOTMLS_siteurl);
643 if (isset($_REQUEST["dt"]) && GOTMLS_strlen($_REQUEST["dt"]))
644 $DEF_url .= '&dt='.preg_replace('/[^\w]/', "", $_REQUEST["dt"]);
645 if (GOTMLS_strlen($_REQUEST["UPDATE_definitions_array"]) > 1) {
646 $GOTnew_definitions = GOTMLS_uckserialize(GOTMLS_decode($_REQUEST["UPDATE_definitions_array"]));
647 if (is_array($GOTnew_definitions)) {
648 $form = 'autoUpdateDownload';
649 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('Downloaded Definitions');";
650 }
651 } elseif ($_REQUEST["UPDATE_definitions_array"] == "D") {
652 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = array();
653 $GOTnew_definitions = array();
654 delete_option('GOTMLS_get_URL_array');
655 } elseif (($DEF = GOTMLS_get_URL($DEF_url)) && is_array($GOTnew_definitions = GOTMLS_uckserialize(GOTMLS_decode($DEF))) && count($GOTnew_definitions)) {
656 if (isset($GOTnew_definitions["you"]["user_email"]) && GOTMLS_strlen($GOTnew_definitions["you"]["user_email"]) == 32) {
657 $toInfo = GOTMLS_get_registrant($GOTnew_definitions["you"]);
658 $innerHTML = "<li style=\\\"color: #0C0\\\">Your Installation Key is Registered to:<br /> $toInfo</li>";
659 $form = 'autoUpdateForm';
660 if (isset($GOTnew_definitions["you"]["user_donations"]) && isset($GOTnew_definitions["you"]["user_donation_total"]) && isset($GOTnew_definitions["you"]["user_donation_freshness"])) {
661 $user_donations_src = $GOTnew_definitions["you"]["user_donations"];
662 if ($GOTnew_definitions["you"]["user_donation_total"] > 27.99) {
663 $autoUpJS = '<input type="radio" id="auto_UPDATE_definitions_1" name="UPDATE_definitions_array" value="1">Yes | <input type="radio" id="auto_UPDATE_definitions_0" name="UPDATE_definitions_array" value="0" checked>No <input type="hidden" name="UPDATE_definitions_checkbox" value="UPDATE_definitions_array">';
664 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
665 foundUpdates.innerHTML = "<a href=\'javascript:document.getElementById(\\"GOTMLS_Form\\").submit();\' onclick=\'document.getElementById(\\"auto_UPDATE_definitions_1\\").checked=true;\' style=\'color: #f00;\'>Set Definition Updates to Automatically Download to activate this feature.</a>";';
666 }
667 if ($user_donations_src > 0 && $GOTnew_definitions["you"]["user_donation_total"] > 0)
668 $li = "<li> You have made $user_donations_src donation".($user_donations_src?'s totalling':' for').' $'.$GOTnew_definitions["you"]["user_donation_total"].".</li><!-- ".$GOTnew_definitions["you"]["user_donation_freshness"]." -->";
669 }
670 } else
671 $innerHTML = "<li style=\\\"color: #f00\\\">Your Installation Key is not registered!</li>";
672 asort($GOTnew_definitions);
673 if (serialize($GOTnew_definitions) == serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))
674 unset($GOTnew_definitions);
675 else {
676 $debug = substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), 0, 9)." ".md5(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".GOTMLS_strlen(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]))." ".substr(serialize($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]), -9)." != ".substr(serialize($GOTnew_definitions), 0, 9)." ".md5(serialize($GOTnew_definitions))." ".GOTMLS_strlen(serialize($GOTnew_definitions)." ".substr(serialize($GOTnew_definitions), -9));
677 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = $GOTnew_definitions;
678 $GLOBALS["GOTMLS"]["tmp"]["onLoad"] .= "updates_complete('New Definitions Automatically Installed :-)');";
679 }
680 $finJS .= "\nif (divNAtext)\n\tloadGOTMLS();\nelse\n\tdivNAtext = setTimeout(function() {loadGOTMLS();}, 4000);";
681 $finJS .= "\nif (typeof stopCheckingDefinitions !== 'undefined' && stopCheckingDefinitions)\n\tclearTimeout(stopCheckingDefinitions);";
682 } else
683 $innerHTML = "<li style=\\\"color: #f00\\\"><a title='report error' href='#' onclick=\\\"stopCheckingDefinitions = checkAlternateUpdateServer('&error=".GOTMLS_encode(serialize(array("get_URL"=>$GLOBALS["GOTMLS"]["get_URL"])))."');\\\">Automatic Update Connection Failed!</a></li>";
684 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]))
685 unset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["backdoor"]);
686 } else {
687 if (!$GOTMLS_nonce_found)
688 $reason = GOTMLS_Invalid_Nonce();
689 elseif (!$YES_user_can)
690 $reason = __("Permission Error: Only an administrator can update settings!", 'gotmls');
691 else
692 $reason = __("definitions_array not set!", 'gotmls');
693 $innerHTML = "<li style=\\\"color: #f00\\\">".GOTMLS_htmlspecialchars($reason)."</li>";
694 }
695 if (isset($GOTnew_definitions) && is_array($GOTnew_definitions)) {
696 $GLOBALS["GOTMLS"]["tmp"]["definitions_array"] = GOTMLS_array_replace($GLOBALS["GOTMLS"]["tmp"]["definitions_array"], $GOTnew_definitions);
697 if (file_exists(GOTMLS_plugin_path.'definitions_update.txt'))
698 @unlink(GOTMLS_plugin_path.'definitions_update.txt');
699 $saved = GOTMLS_update_option('definitions', $GLOBALS["GOTMLS"]["tmp"]["definitions_array"], false);
700 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"] = array();
701 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"] as $threat_level=>$definition_names) {
702 if ($threat_level != "potential")
703 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"][] = $threat_level;
704 foreach ($definition_names as $definition_name=>$definition_version)
705 if (is_array($definition_version) && isset($definition_version[0]) && GOTMLS_strlen($definition_version[0]) == 5)
706 if (!isset($GOTMLS_definitions_versions[$threat_level]) || $definition_version[0] > $GOTMLS_definitions_versions[$threat_level])
707 $GOTMLS_definitions_versions[$threat_level] = $definition_version[0];
708 }
709 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"];
710 asort($GOTMLS_definitions_versions);
711 $autoUpJS .= '<span style="color: #0C0;">(Newest Definition Updates Installed.)</span>';
712 } elseif ($form != 'registerKeyForm') {
713 $form = 'autoUpdateDownload';
714 $autoUpJS .= '<span style="color: #0C0;">(No newer Definition Updates are available at this time.)</span>';
715 $innerHTML .= "<li style=\\\"color: #0C0\\\">No Newer Definition Updates Available.</li>";
716 }
717 if (isset($_SERVER["SCRIPT_FILENAME"]) && preg_match('/[\/\\\\]admin-ajax\.php/i', $_SERVER["SCRIPT_FILENAME"]) && isset($_REQUEST["action"]) && $_REQUEST["action"] == "GOTMLS_load_update") {
718 if (!$user_donations_src)
719 $li = "<li style=\\\"color: #f00;\\\"><button onclick=\\\"force_update_check(500);\\\" style=\\\"float: right;\\\">Check Again</button>You have not donated yet!</li>";
720 if (GOTMLS_strlen($moreJS) == 0)
721 $moreJS = 'if (foundUpdates = document.getElementById("check_wp_core_div_NA"))
722 foundUpdates.innerHTML = "<a target=\'_blank\' href=\'https://gotmls.net/donate/?key='.GOTMLS_installation_key.'\' style=\'color: #f00;\'>Donate $29+ now then enable Automatic Definition Updates to Scan for Core Files changes.</a>";';
723 $moreJS .= "\n\tif (foundUpdates = document.getElementById('pastDonations'))\n\tfoundUpdates.innerHTML = '$li';";
724 if ($GOTMLS_nonce_found)
725 @header("Content-type: text/javascript");
726 else
727 die(GOTMLS_Invalid_Nonce("Nonce Error: "));
728 if (is_array($GOTMLS_definitions_versions) && count($GOTMLS_definitions_versions) && (GOTMLS_strlen($new_ver = trim(array_pop($GOTMLS_definitions_versions))) == 5) && $saved) {
729 $innerHTML .= "<li style=\\\"color: #0C0\\\">New Definition Updates Installed.</li>";
730 $finJS .= "\nif (foundUpdates = document.getElementById('GOTMLS_definitions_date')) foundUpdates.innerHTML = '$new_ver';\nif (foundUpdates = document.getElementById('autoUpdateForm')) foundUpdates.style.display = 'none';";
731 } elseif (isset($GOTnew_definitions) && is_array($GOTnew_definitions) && count($GOTnew_definitions))
732 $finJS .= "\nalert('Definition update $new_ver could not be saved because update_option Failed! (saved=".($saved?"TRUE":"FALSE").") $debug');";
733 if (isset($_REQUEST["UPDATE_core"]) && ($_REQUEST["UPDATE_core"] == GOTMLS_wp_version) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version])) {
734 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version] as $file => $md5) {
735 if (is_file(ABSPATH.$file)) {
736 GOTMLS_load_contents(file_get_contents(ABSPATH.$file));
737 if (GOTMLS_check_threat($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"], ABSPATH.$file)) {
738 if (isset($GLOBALS["GOTMLS"]["tmp"]["new_contents"]) && isset($_REQUEST["UPDATE_restore"]) && ($_REQUEST["UPDATE_restore"] == md5($GLOBALS["GOTMLS"]["tmp"]["new_contents"])."O".GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["new_contents"])))
739 $autoUpJS .= "<li>Core File Restored: $file</li>";
740 else
741 $autoUpJS .= "<li>Core File MODIFIED: $file ".md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"])."O".GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"])." => $md5</li>";
742 }
743 } else
744 $autoUpJS .= "<li>Core File MISSING: $file</li>";
745 }
746 $autoUpJS .= GOTMLS_error_div('Definition update: '.preg_replace('/[^0-9\.]/', "", $_REQUEST["UPDATE_core"]).' checked '.count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["wp_core"][GOTMLS_wp_version]).' core files!', "update");
747 }
748 die('//<![CDATA[
749 var inc_form = "";
750 if (foundUpdates = document.getElementById("autoUpdateDownload"))
751 foundUpdates.src += "?'.$user_donations_src.'";
752 if (foundUpdates = document.getElementById("registerKeyForm"))
753 foundUpdates.style.display = "none";
754 if (foundUpdates = document.getElementById("'.$form.'"))
755 foundUpdates.style.display = "block";
756 if (foundUpdates = document.getElementById("Definition_Updates"))
757 foundUpdates.innerHTML = "<ul class=\\"GOTMLS-sidebar-links\\">'.$innerHTML.'</ul>"+inc_form;
758 function setDivNAtext() {
759 var foundUpdates;
760 '.$moreJS.$finJS.'
761 if (foundUpdates = document.getElementById("UPDATE_definitions_div"))
762 foundUpdates.innerHTML = \''.$autoUpJS.'\';
763 //]]>');
764 }
765 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] = '?div=Definition_Updates';
766 foreach ($GOTMLS_definitions_versions as $definition_name=>$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"])
767 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[$definition_name]=".$GLOBALS["GOTMLS"]["tmp"]["Definition"]["Latest"];
768 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) && GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"]) == 32)
769 $GLOBALS["GOTMLS"]["tmp"]["Definition"]["Updates"] .= "&def[you]=".$GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["you"]["user_email"];
770 }
771
772 function GOTMLS_settings() {
773 global $wpdb, $GOTMLS_dirs_at_depth, $GOTMLS_dir_at_depth;
774 $GOTMLS_scan_groups = array();
775 $gt = ">"; // This local variable never changes
776 $lt = "<"; // This local variable never changes
777 GOTMLS_ajax_load_update();
778 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))
779 $_REQUEST["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
780 if (($GOTMLS_nonce_found = GOTMLS_get_nonce()) && ((isset($_REQUEST["check"]) && is_array($_REQUEST["check"])) || (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"])))) {
781 if (isset($_REQUEST["check"]) && is_array($_REQUEST["check"]))
782 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = GOTMLS_sanitize($_REQUEST["check"]);
783 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
784 }
785 $dirs = GOTMLS_explode_dir(__FILE__);
786 for ($SL=0;$SL<intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);$SL++)
787 $GOTMLS_scan_groups[] = implode(GOTMLS_slash(), array_slice($dirs, -1 * (3 + $SL), 1));
788 if (isset($_POST["exclude_ext"])) {
789 if (GOTMLS_strlen(trim(str_replace(",","",$_POST["exclude_ext"]).' ')) > 0)
790 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(str_replace('.', ',', GOTMLS_sanitize($_POST["exclude_ext"]))), -1, PREG_SPLIT_NO_EMPTY);
791 else
792 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"] = array();
793 }
794 $default_exclude_ext = str_replace(",gotmls", "", implode(",", $GLOBALS["GOTMLS"]["tmp"]["skip_ext"]));
795 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
796 if (isset($_POST["UPDATE_definitions_checkbox"])) {
797 if (isset($_POST[$_POST["UPDATE_definitions_checkbox"]]) && is_numeric($_POST[$_POST["UPDATE_definitions_checkbox"]]))
798 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = (INT) $_POST[$_POST["UPDATE_definitions_checkbox"]];
799 else
800 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"] = "";
801 }
802 if (isset($_POST["exclude_dir"])) {
803 if (GOTMLS_strlen(trim(str_replace(",","",$_POST["exclude_dir"]).' ')) > 0)
804 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = preg_split('/[\s]*([,]+[\s]*)+/', trim(GOTMLS_sanitize($_POST["exclude_dir"])), -1, PREG_SPLIT_NO_EMPTY);
805 else
806 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"] = array();
807 for ($d=0; $d<count($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]); $d++)
808 if (dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]) != ".")
809 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d] = str_replace("\\", "", str_replace("/", "", str_replace(dirname($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d]), "", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"][$d])));
810 }
811 $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"] = array_merge($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"], $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"]);
812 if (isset($_POST["scan_what"]) && is_numeric($_POST["scan_what"]) && $_POST["scan_what"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"])
813 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = (INT) $_POST["scan_what"];
814 if (isset($_POST["check_custom"]) && $_POST["check_custom"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"])
815 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = GOTMLS_verify_regex(trim(stripslashes($_POST["check_custom"])));
816 if (isset($_POST["scan_depth"]) && is_numeric($_POST["scan_depth"]) && $_POST["scan_depth"] != $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])
817 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = (INT) $_POST["scan_depth"];
818 if (isset($_POST['skip_quarantine']) && is_numeric($_POST['skip_quarantine']) && $_POST['skip_quarantine'])
819 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = (INT) $_POST['skip_quarantine'];
820 elseif (isset($_POST["exclude_ext"]))
821 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]['skip_quarantine'] = 0;
822 GOTMLS_update_scanlog(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
823 $scan_whatopts = '';
824 $scan_root = "public_html";
825 $scan_optjs = "\n{$lt}script type=\"text/javascript\"$gt\nfunction showOnly(what) {\n";
826 foreach ($GOTMLS_scan_groups as $mg => $GOTMLS_scan_group) {
827 $scan_optjs .= "document.getElementById('only$mg').style.display = 'none';\n";
828 $scan_whatopts = "\n$lt/div$gt\n$lt/div$gt\n$scan_whatopts";
829 $scan_root = $GOTMLS_scan_group;
830 $dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + $mg)));
831 $files = GOTMLS_getfiles($dir);
832 if (isset($files) && is_array($files) && count($files))
833 foreach ($files as $file)
834 if (is_dir(GOTMLS_trailingslashit($dir).$file))
835 $scan_whatopts = $lt.'input type="checkbox" onchange="showhide(\'custom_quick_scan\', true);" name="scan_only[]" value="'.GOTMLS_htmlspecialchars($file).'" /'.$gt.GOTMLS_htmlspecialchars($file).$lt.'br /'.$gt.$scan_whatopts;
836 $scan_whatopts = "\n$lt".'div style="padding: 4px 30px;" id="scan_group_div_'.$mg.'"'.$gt.$lt.'input type="radio" name="scan_what" id="not-only'.$mg.'" value="'.$mg.'"'.($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]==$mg?' checked':'').' /'.$gt.$lt.'a style="text-decoration: none;" href="#scan_what" onclick="showOnly(\''.$mg.'\');document.getElementById(\'not-only'.$mg.'\').checked=true;"'."$gt{$lt}b$gt$GOTMLS_scan_group$lt/b$gt$lt/a$gt{$lt}br /$gt\n$lt".'div class="rounded-corners" style="position: absolute; display: none; background-color: #CCF; margin: 0; padding: 10px; z-index: 10;" id="only'.$mg.'"'.$gt.$lt.'div style="padding-bottom: 6px;"'.$gt.GOTMLS_close_button('only'.$mg, 0).$lt.'b'.$gt.str_replace(" ", "&nbsp;", __("Only Scan These Folders:",'gotmls')).$lt.'/b'.$gt.$lt.'/div'.$gt.$scan_whatopts;
837 }
838 $scan_optjs .= "document.getElementById('only'+what).style.display = 'block';\n}";
839 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]) && GOTMLS_strlen(trim(" ".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"])))
840 $scan_optjs .= "\nfunction auto_UPDATE_check() {\n\tif (auto_UPdef_check = document.getElementById('auto_UPDATE_definitions_".$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["auto_UPDATE_definitions"]."'))\n\t\tauto_UPdef_check.checked = true;\n}\nif (window.addEventListener)\n\twindow.addEventListener('load', auto_UPDATE_check)\nelse\n\tdocument.attachEvent('onload', auto_UPDATE_check);\n";
841 $scan_optjs .= "$lt/script$gt";
842 $GOTMLS_nonce_URL = GOTMLS_set_nonce(__FUNCTION__."790");
843 $scan_opts = "\n$lt".'form method="POST" id="GOTMLS_Form" name="GOTMLS_Form"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', $GOTMLS_nonce_URL).'"'.$gt.$lt.'input type="hidden" name="scan_type" id="scan_type" value="Complete Scan" /'.$gt.$lt.'div style="float: right;"'.$gt.$lt.'input type="submit" id="complete_scan" value="'.__("Run Complete Scan",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Complete Scan\';" /'.$gt.$lt.'/div'.$gt.'
844 '.$lt.'div style="float: right; margin: 0 5px;"'.$gt.$lt.'input style="display: none;" type="submit" id="custom_quick_scan" value="'.__("Custom Quick Scan",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Quick Scan\';" /'.$gt.$lt.'/div'.$gt.$lt.'div id="gotmls_wtl4" style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to look for:",'gotmls')."$lt/b$gt".GOTMLS_dashicon_button(__("Check for all threat types, if any of these are in red or otherwise unavailable then please download the latest definition updates.",'gotmls')).GOTMLS_dashicon_button(__("If you are having trouble Posting Array Variables to your site then you can temporarily remove this section to avoid errors when Scanning or Saving from this form.",'gotmls'), 'dismiss', 'color: #F00; text-decoration: none;" onclick="if (wtl4 = document.getElementById(\'gotmls_wtl4\')) wtl4.innerHTML = \'\'')."$lt/p$gt\n$lt".'div style="padding: 0 30px;"'.$gt;
845 $cInput = '"'.$gt.$lt.'input';
846 $pCheck = "$cInput checked";
847 $kCheck = "";
848 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $threat_level_name=>$threat_level) {
849 $scan_opts .= $lt.'div id="check_'.$threat_level.'_div" style="padding: 0; position: relative;';
850 if (($threat_level != "wp_core" && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level])) || isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level][GOTMLS_wp_version])) {
851 if ($threat_level != "potential" && in_array($threat_level,$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"])) {
852 $pCheck = " display: none;$cInput";
853 $scan_opts .= "$cInput checked";
854 } elseif ($threat_level == "potential")
855 $scan_opts .= $pCheck;
856 else
857 $scan_opts .= $cInput;
858 if ($threat_level != "potential")
859 $kCheck .= ",'$threat_level'";
860 $scan_opts .= ' type="checkbox" onchange="pCheck(this);" name="check[]" id="check_'.$threat_level.'_Yes" value="'.$threat_level.'" /'.$gt.' '.$lt.'a style="text-decoration: none;" href="#check_'.$threat_level.'_div_0" onclick="document.getElementById(\'check_'.$threat_level.'_Yes\').checked=true;pCheck(document.getElementById(\'check_'.$threat_level.'_Yes\'));showhide(\'dont_check_'.$threat_level.'\');"'."$gt{$lt}b$gt$threat_level_name$lt/b$gt$lt/a$gt\n";
861 if (isset($_GET["SESSION"])) {
862 $scan_opts .= "\n$lt".'div style="padding: 0 20px; position: relative; top: -18px; display: none;" id="dont_check_'.$threat_level.'"'.$gt.$lt.'a class="rounded-corners" style="position: absolute; left: 0; margin: 0; padding: 0 4px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;" href="#check_'.$threat_level.'_div_0" onclick="showhide(\'dont_check_'.$threat_level.'\');"'.$gt.'X'.$lt.'/a'.$gt;
863 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"][$threat_level] as $threat_name => $threat_regex)
864 $scan_opts .= $lt."br /$gt\n$lt".'input type="checkbox" name="dont_check[]" value="'.GOTMLS_htmlspecialchars($threat_name).'"'.(in_array(GOTMLS_sanitize($threat_name), $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])?' checked /'.$gt.$lt.'script'.$gt.'showhide("dont_check_'.$threat_level.'", true);'.$lt.'/script'.$gt:' /'.$gt).(isset($_SESSION["GOTMLS_debug"][$threat_name])?$lt.'div style="float: right;"'.$gt.GOTMLS_htmlspecialchars(print_r($_SESSION["GOTMLS_debug"][$threat_name],1))."$lt/div$gt":"").GOTMLS_htmlspecialchars($threat_name);
865 $scan_opts .= "\n$lt/div$gt";
866 }
867 } else
868 $scan_opts .= $lt.'a title="'.__("Download Definition Updates to Use this feature",'gotmls').'"'.$gt.$lt.'img src="'.GOTMLS_images_path.'blocked.gif" height=16 width=16 alt="X"'.$gt.$lt.'b'.$gt.'&nbsp; '.$threat_level_name.$lt.'/b'.$gt.$lt.'br /'.$gt.$lt.'div style="padding: 14px;" id="check_'.$threat_level.'_div_NA"'.$gt.$lt.'span style="color: #F00"'.$gt.__("Download the new definitions (Right sidebar) to activate this feature.",'gotmls')."$lt/span$gt$lt/div$gt";
869 $scan_opts .= "\n$lt/div$gt";
870 }
871 $scan_opts .= $lt.'/div'.$gt.$lt.'/div'.$gt.'
872 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("What to scan:",'gotmls')."$lt/b$gt".GOTMLS_dashicon_button(sprintf(__("The higher up in the directory hierarchy you start the more sub-directories get scanned (e.g. scanning the %s directory will also include the sub-directories wp-content and plugins within it).",'gotmls'), $scan_root))."$lt/p$gt$scan_whatopts$scan_optjs$lt/div$gt\n$lt".'div style="float: left;" id="scanwhatfolder"'.$gt.$lt.'/div'.$gt.'
873 '.$lt.'div style="float: left;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Directory Scan Depth:",'gotmls')."$lt/b$gt".GOTMLS_dashicon_button(__("How many directories deep to scan: -1 is infinite depth, 0 to skip the file scan completely.",'gotmls'))."$lt/p$gt\n$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" value="'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"].'" name="scan_depth" size="5"'.$gt.$lt.'/div'.$gt.$lt.'/div'.$gt.$lt.'br style="clear: left;"'.$gt;
874 if (isset($_GET["SESSION"]) && isset($_SESSION["GOTMLS_debug"])) {$scan_opts .= $lt.'div style="float: right;"'.$gt.GOTMLS_htmlspecialchars(print_r(array("sess" => $_SESSION),1))."$lt/div$gt"; $_SESSION["GOTMLS_debug"] = array("GOTMLS_settings(811)" => microtime(true));}
875 if (isset($_GET["eli"])) {//still testing this option['total']['total']
876 if ($_GET["eli"] == "find") {
877 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]) && isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) && (count($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]]) > 1)) {
878 $fe = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][0];
879 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = $GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"][$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]][1];
880 } else {
881 $fe = " no";
882 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["known"] as $f => $e)
883 if (is_array($e) && in_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"], $e))
884 $fe = " $f";
885 }
886 } else
887 $fe = "";
888 $scan_opts .= "\n$lt".'div style="padding: 10px;"'.$gt.$lt.'p'.$gt.$lt.'b'.$gt.__("Custom RegExp:",'gotmls').$fe.$lt.'/b'.$gt.' ('.__("For very advanced users only. Do not use this without talking to Eli first. If used incorrectly you could easily break your site.",'gotmls').')'.$lt.'/p'.$gt.$lt.'input type="text" name="check_custom" style="width: 100%;" value="'.GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]).'" /'."$gt$lt/div$gt\n";
889 }
890 $QuickScan = $lt.((is_dir(dirname(__FILE__)."/../../../wp-includes") && is_dir(dirname(__FILE__)."/../../../wp-admin"))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&$GOTMLS_nonce_URL").'" class="button-primary" style="min-height: 22px; height: 22px; line-height: 13px; padding: 3px;">WP_Core</a':"!-- No wp-includes or wp-admin --").$gt;
891 foreach (array("Plugins", "Themes") as $ScanFolder)
892 $QuickScan .= '&nbsp;'.$lt.((is_dir(dirname(__FILE__)."/../../../wp-content/".strtolower($ScanFolder)))?'a href="'.admin_url("admin.php?page=GOTMLS-settings&scan_type=Quick+Scan&scan_only%5B%5D=wp-content/".strtolower($ScanFolder)."&$GOTMLS_nonce_URL")."\" class=\"button-primary\" style=\"min-height: 22px; height: 22px; line-height: 13px; padding: 3px;\"$gt$ScanFolder$lt/a":"!-- No $ScanFolder in wp-content --").$gt;
893 $scan_opts .= "\n$lt".'p'.$gt.$lt.'b'.$gt.__("Skip files with the following extensions:",'gotmls')."$lt/b$gt".(($default_exclude_ext!=implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))?" {$lt}a href=\"javascript:void(0);\" onclick=\"document.getElementById('exclude_ext').value = '$default_exclude_ext';\"{$gt}[Restore Defaults]$lt/a$gt":"").$lt.'/p'.$gt.'
894 '.$lt.'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a comma separated list of file extentions to skip",'gotmls').'" name="exclude_ext" id="exclude_ext" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]).'" style="width: 100%;" /'."$gt$lt/div$gt$lt".'p'.$gt.$lt.'b'.$gt.__("Skip directories with the following names:",'gotmls')."$lt/b$gt$lt/p$gt$lt".'div style="padding: 0 30px;"'.$gt.$lt.'input type="text" placeholder="'.__("a folder name or comma separated list of folder names to skip",'gotmls').'" name="exclude_dir" value="'.implode(",", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_dir"]).'" style="width: 100%;" /'.$gt.$lt.'/div'.$gt.'
895 '.$lt.'table style="width: 100%" cellspacing="10"'.$gt.$lt.'tr'.$gt.$lt.'td nowrap valign="top" style="white-space: nowrap; width: 1px;"'.$gt.$lt.'b'.$gt.__("Automatically Update Definitions:",'gotmls').$lt."br$gt$lt/b$gt$lt/td$gt$lt".'td'.$gt.$lt.'div id="UPDATE_definitions_div"'.$gt.$lt.'br'.$gt.$lt.'span style="color: #C00;"'.$gt.__("This feature is only available to registered users who have donated at a certain level.",'gotmls')."$lt/span$gt$lt/div$gt$lt/td$gt$lt".'td align="right" valign="bottom"'.$gt.$lt.'input type="submit" id="save_settings" value="'.__("Save Settings",'gotmls').'" class="button-primary" onclick="document.getElementById(\'scan_type\').value=\'Save\';" /'."$gt$lt/td$gt$lt/tr$gt$lt/table$gt$lt/form$gt";
896 $title_tagline = $lt."li$gt Site Title: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogname'"));
897 $title_tagline .= "$lt/li$gt{$lt}li$gt Tagline: ".GOTMLS_htmlspecialchars($wpdb->get_var("SELECT `option_value` FROM `$wpdb->options` WHERE `option_name` = 'blogdescription'"));
898 if (preg_match('/h[\@a]ck[3e]d.*by/is', $title_tagline))
899 echo GOTMLS_error_div(sprintf(__("Your Site Title or Tagline suggests that you may have been hacked ...%sThis could impact the indexing of your site and may even lead to blacklisting. You can change those options on the %sGeneral Settings$lt/a$gt page.",'gotmls'), "$title_tagline$lt/li$gt", $lt.'a href="'.admin_url("options-general.php").'"'.$gt));
900 @ob_start();
901 $OB_default_handlers = array("default output handler", "zlib output compression");
902 $OB_handlers = @ob_list_handlers();
903 if (is_array($OB_handlers) && count($OB_handlers))
904 foreach ($OB_handlers as $OB_last_handler)
905 if (!in_array($OB_last_handler, $OB_default_handlers))
906 echo GOTMLS_error_div(sprintf(__("Another Plugin or Theme is using '%s' to handle output buffers. <br />This prevents actively outputting the buffer on-the-fly and could severely degrade the performance of this (and many other) Plugins. <br />Consider disabling caching and compression plugins (at least during the scanning process).",'gotmls'), GOTMLS_htmlspecialchars($OB_last_handler)));
907 GOTMLS_display_header();
908 $scan_groups = array_merge(array(__("Scanned Files",'gotmls')=>"scanned",__("Selected Folders",'gotmls')=>"dirs",__("Scanned Folders",'gotmls')=>"dir",__("Skipped Folders",'gotmls')=>"skipdirs",__("Skipped Files",'gotmls')=>"skipped",__("Scan/Read Errors",'gotmls')=>"errors",__("Quarantined Files",'gotmls')=>"bad"), $GLOBALS["GOTMLS"]["tmp"]["threat_levels"]);
909 echo $lt.'script type="text/javascript">
910 var percent = 0;
911 function pCheck(chkb) {
912 var kCheck = ['.trim($kCheck,",").'];
913 chk = true;
914 for (var i = 0; i < kCheck.length; i++) {
915 var chkbox = document.getElementById("check_"+kCheck[i]+"_Yes");
916 if (chkbox && chkb.id == "check_potential_Yes" && chkb.checked == false) {
917 chk = false;
918 chkbox.checked = true;
919 } else if (chkbox && chkbox.checked) {
920 chk = false;
921 }
922 }
923 if (chkbox = document.getElementById("check_potential_Yes"))
924 chkbox.checked = chk;
925 if (chk) {
926 document.getElementById("check_potential_div").style.display = "block";
927 alert("If you do not select any other threat types, then only potential threats will be found and the automatic fix will not be available!");
928 } else
929 document.getElementById("check_potential_div").style.display = "none";
930 }
931 function changeFavicon(percent) {
932 var oldLink = document.getElementById("wait_gif");
933 if (oldLink) {
934 if (percent >= 100) {
935 document.getElementsByTagName("head")[0].removeChild(oldLink);
936 var link = document.createElement("link");
937 link.id = "wait_gif";
938 link.type = "image/gif";
939 link.rel = "shortcut icon";
940 var threats = '.implode(" + ", array_merge($GLOBALS["GOTMLS"]["tmp"]["threat_levels"], array(__("Potential Threats",'gotmls')=>"errors",__("WP-Login Updates",'gotmls')=>"errors"))).';
941 if (threats > 0) {
942 if ((errors * 2) == threats)
943 linkhref = "blocked";
944 else
945 linkhref = "threat";
946 } else
947 linkhref = "checked";
948 link.href = "'.GOTMLS_images_path.'"+linkhref+".gif";
949 document.getElementsByTagName("head")[0].appendChild(link);
950 }
951 } else {
952 var icons = document.getElementsByTagName("link");
953 var link = document.createElement("link");
954 link.id = "wait_gif";
955 link.type = "image/gif";
956 link.rel = "shortcut icon";
957 link.href = "'.GOTMLS_images_path.'wait.gif";
958 // document.head.appendChild(link);
959 document.getElementsByTagName("head")[0].appendChild(link);
960 }
961 }
962 function update_status(title, time) {
963 sdir = (dir+direrrors);
964 if (arguments[2] >= 0 && arguments[2] <= 100)
965 percent = arguments[2];
966 else
967 percent = Math.floor((sdir*100)/dirs);
968 scan_state = "6F6";
969 if (percent == 100) {
970 showhide("pause_button", true);
971 showhide("pause_button");
972 title = "'.$lt.'b'.$gt.GOTMLS_strip4java(__("Scan Complete!",'gotmls')).$lt.'/b'.$gt.'";
973 } else
974 scan_state = "99F";
975 changeFavicon(percent);
976 if (sdir) {
977 if (arguments[2] >= 0 && arguments[2] <= 100)
978 timeRemaining = Math.ceil(((time-startTime)*(100/percent))-(time-startTime));
979 else
980 timeRemaining = Math.ceil(((time-startTime)*(dirs/sdir))-(time-startTime));
981 if (timeRemaining > 59)
982 timeRemaining = Math.ceil(timeRemaining/60)+" Minute";
983 else
984 timeRemaining += " Second";
985 if (timeRemaining.substr(0, 2) != "1 ")
986 timeRemaining += "s";
987 } else
988 timeRemaining = "Calculating Time";
989 timeElapsed = Math.ceil(time);
990 if (timeElapsed > 59)
991 timeElapsed = Math.floor(timeElapsed/60)+" Minute";
992 else
993 timeElapsed += " Second";
994 if (timeElapsed.substr(0, 2) != "1 ")
995 timeElapsed += "s";
996 divHTML = \''.$lt.'div align="center" style="vertical-align: middle; background-color: #ccc; z-index: 3; height: 18px; width: 100%; border: solid #000 1px; position: relative; padding: 10px 0;"'.$gt.$lt.'div style="height: 18px; padding: 10px 0; position: absolute; top: 0px; left: 0px; background-color: #\'+scan_state+\'; width: \'+percent+\'%"'.$gt.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; left: 10px; z-index: 5; line-height: 16px;" align="left"'.$gt.'\'+sdir+" Folder"+(sdir==1?"":"s")+" Checked'.$lt.'br /'.$gt.'"+timeElapsed+\' Elapsed'.$lt.'/div'.$gt.$lt.'div style="height: 38px; position: absolute; top: 0px; left: 0px; width: 100%; z-index: 5; line-height: 38px; font-size: 30px; text-align: center; box-sizing: content-box;"'.$gt.'\'+percent+\'%'.$lt.'/div'.$gt.$lt.'div style="height: 32px; position: absolute; top: 3px; right: 10px; z-index: 5; line-height: 16px;" align="right"'.$gt.'\'+(dirs-sdir)+" Folder"+((dirs-sdir)==1?"":"s")+" Remaining'.$lt.'br /'.$gt.'"+timeRemaining+" Remaining'.$lt.'/div'.$gt.$lt.'/div'.$gt.'";
997 document.getElementById("status_bar").innerHTML = divHTML;
998 document.getElementById("status_text").innerHTML = title;
999 dis="none";
1000 divHTML = \''.$lt.'ul style="float: right; margin: 0 20px; text-align: right;"'.$gt.'\';
1001 /*'.$lt.'!--*'.'/';
1002 $MAX = 0;
1003 $vars = "var i, intrvl, direrrors=0";
1004 $fix_button_js = "";
1005 $found = "";
1006 $li_js = ($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["scan_depth"]==1?"":"return false;");
1007 if ((isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Quick Scan") || (!(isset($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"])))) {
1008 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"] = array();
1009 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1010 if ($check != "potential")
1011 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"][] = $check;
1012 }
1013 foreach ($scan_groups as $scan_name => $scan_group) {
1014 if ($MAX++ == 6) {
1015 $quarantineCountOnly = GOTMLS_get_quarantine(true);
1016 $vars .= ", $scan_group=$quarantineCountOnly";
1017 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0)\n\t\tscan_state = ' potential'; \n\telse\n\t\tscan_state = '';\n\tdivHTML += '</ul><ul style=\"text-align: left;\"><li class=\"GOTMLS_li\"><a href=\"admin.php?page=GOTMLS_View_Quarantine\" class=\"GOTMLS_plugin".("'+scan_state+'\" title=\"".GOTMLS_strip4java(GOTMLS_View_Quarantine_LANGUAGE))."\">'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
1018 $found = "Found ";
1019 $fix_button_js = "\n\t\tdis='block';";
1020 } else {
1021 $val = 0;
1022 if ($MAX > 8 && !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
1023 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("Directory Scan Depth set to 0, no files will be scanned for this type of threat!",'gotmls'));
1024 elseif ($found && !in_array($scan_group, $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]))
1025 $potential_threat = ' potential" title="'.GOTMLS_strip4java(__("You are not currently scanning for this type of threat!",'gotmls'));
1026 else
1027 $potential_threat = "";
1028 $vars .= ", $scan_group=$val";
1029 echo "/*--{$gt}*"."/\n\tif ($scan_group > 0) {\n\t\tscan_state = ' href=\"#found_$scan_group\" onclick=\"$li_js showhide(\\'found_$scan_group\\', true);\" class=\"GOTMLS_plugin $scan_group\"';$fix_button_js".($MAX>6?"\n\tshowhide('found_$scan_group', true);":"")."\n\t} else\n\t\tscan_state = ' class=\"GOTMLS_plugin$potential_threat\"';\n\tdivHTML += '<li class=\"GOTMLS_li\"".(($found && $scan_group == "potential" && !in_array($scan_group, $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))?' style="display: none;"':"")."><a'+scan_state+'>$found'+$scan_group+'&nbsp;'+($scan_group==1?('$scan_name').slice(0,-1):'$scan_name')+'</a></li>';\n/*{$lt}!--*"."/";
1030 }
1031 $li_js = "";
1032 if ($MAX > 11)
1033 $fix_button_js = "";
1034 }
1035 $ScanSettings = $lt.'div style="float: right;"'.$gt.GOTMLS_Run_Quick_Scan_LANGUAGE.":&nbsp;$QuickScan$lt/div$gt".GOTMLS_Scan_Settings_LANGUAGE;
1036 echo "/*--{$gt}*".'/
1037 document.getElementById("status_counts").innerHTML = divHTML+"'.$lt.'/ul'.$gt.'";
1038 document.getElementById("fix_button").style.display = dis;
1039 }
1040 '.$vars.';
1041 function showOnly(what) {
1042 document.getElementById("only_what").innerHTML = document.getElementById("only"+what).innerHTML;
1043 }
1044 var startTime = 0;
1045 '.$lt.'/script'.$gt.GOTMLS_box($ScanSettings, $scan_opts);
1046 $Settings_Saved = "\n{$lt}div onclick=\"this.style.display='none';\" style='position: relative; top: -50px; margin: 0 300px 0 130px;' class='updated'$gt\nSettings Saved!$lt/div$gt\n";//script type='text/javascript'$gt\nalert('Settings Saved!');\n$lt/script$gt\n";
1047 if (isset($_REQUEST["scan_type"]) && $_REQUEST["scan_type"] == "Save") {
1048 if ($GOTMLS_nonce_found) {
1049 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1050 echo $Settings_Saved;
1051 } else
1052 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Saving these settings requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1053 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scan_history());
1054 } elseif (isset($_REQUEST["scan_what"]) && is_numeric($_REQUEST["scan_what"]) && ($_REQUEST["scan_what"] > -1)) {
1055 if ($GOTMLS_nonce_found) {
1056 update_option('GOTMLS_settings_array', $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1057 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"] = array();
1058 GOTMLS_update_scanlog(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1059 $cleadCache = false;
1060 if (function_exists('is_plugin_active')) {
1061 if (function_exists('wp_cache_clear_cache')) {
1062 wp_cache_clear_cache();
1063 $cleadCache = true;
1064 }
1065 if (function_exists('w3tc_pgcache_flush')) {
1066 w3tc_pgcache_flush();
1067 $cleadCache = true;
1068 }
1069 if (class_exists('WpFastestCache')) {
1070 $newCache = new WpFastestCache();
1071 $newCache->deleteCache();
1072 $cleadCache = true;
1073 }
1074
1075 }
1076 if ($cleadCache)
1077 str_replace("Settings Saved!", "Cache Cleared and Settings Saved!", $Settings_Saved);
1078 echo $Settings_Saved;
1079 if (!isset($_REQUEST["scan_type"]))
1080 $_REQUEST["scan_type"] = "Complete Scan";
1081 elseif ($_REQUEST["scan_type"] == "Quick Scan") {
1082 $li_js = "\nfunction testComplete() {\n\tif (percent != 100)\n\t\talert('".__("The Quick Scan was unable to finish because of a shortage of memory or a problem accessing a file. Please try using the Complete Scan, it is slower but it will handle these errors better and continue scanning the rest of the files.",'gotmls')."');\n}\nwindow.onload=testComplete;\n$lt/script$gt\n$lt".'script type="text/javascript"'.$gt;
1083 $GLOBALS["GOTMLS"]["log"]["settings"]["check"] = array();
1084 foreach ($GLOBALS["GOTMLS"]["tmp"]["threat_levels"] as $check)
1085 if ($check != "potential")
1086 $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"][] = $check;
1087 }
1088 $_SERVER_QUERY_STRING = "?";
1089 foreach ($_GET as $name => $value) {
1090 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1091 if (is_array($value)) {
1092 foreach ($value as $val)
1093 $_SERVER_QUERY_STRING .= rawurlencode($name).'[]='.rawurlencode($val).'&';
1094 } else
1095 $_SERVER_QUERY_STRING .= rawurlencode($name).'='.rawurlencode($value).'&';
1096 }
1097 }
1098 echo "\n$lt".'form method="POST" action="'.admin_url("admin-ajax.php$_SERVER_QUERY_STRING").'" target="GOTMLS_iFrame" name="GOTMLS_Form_clean" id="GOTMLS_Form_clean"'.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', $GOTMLS_nonce_URL).'"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_fix"'.$gt.$lt.'input type="hidden" id="GOTMLS_fixing" name="GOTMLS_fixing" value="1"'.$gt;
1099 foreach ($_POST as $name => $value) {
1100 if (substr($name, 0, 10) != 'GOTMLS_fix' && $name != 'GOTMLS_mt') {
1101 if (is_array($value)) {
1102 foreach ($value as $val)
1103 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'[]" value="'.GOTMLS_htmlspecialchars($val).'"'.$gt;
1104 } else
1105 echo $lt.'input type="hidden" name="'.GOTMLS_htmlspecialchars($name).'" value="'.GOTMLS_htmlspecialchars($value).'"'.$gt;
1106 }
1107 }
1108 echo "\n$lt".'script type="text/javascript"'.$gt.'showhide("inside_'.md5($ScanSettings).'");'.$lt.'/script'.$gt.GOTMLS_box(GOTMLS_htmlspecialchars($_REQUEST["scan_type"]).' Status', $lt.'div id="status_text"'.$gt.$lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="..."'.$gt.' '.GOTMLS_Loading_LANGUAGE.$lt.'/div'.$gt.$lt.'div id="status_bar"'.$gt.$lt.'/div'.$gt.$lt.'p id="pause_button" style="display: none; position: absolute; left: 0; text-align: center; margin-left: -30px; padding-left: 50%;"'.$gt.$lt.'input type="button" value="Pause" class="button-primary" onclick="pauseresume(this);" id="resume_button" /'.$gt.$lt.'/p'.$gt.$lt.'div id="status_counts"'.$gt.$lt.'/div'.$gt.$lt.'p id="fix_button" style="display: none; text-align: center;"'.$gt.$lt.'input id="repair_button" type="submit" value="'.GOTMLS_Automatically_Fix_LANGUAGE.'" class="button-primary" onclick="loadIframe(\'Examine Results\');" /'.$gt.$lt.'/p'.$gt);
1109 $scan_groups_UL = "";
1110 foreach ($scan_groups as $scan_name => $scan_group)
1111 $scan_groups_UL .= "\n{$lt}ul name=\"found_$scan_group\" id=\"found_$scan_group\" class=\"GOTMLS_plugin $scan_group\" style=\"background-color: #ccc; display: none; padding: 0;\"$gt{$lt}a class=\"rounded-corners\" name=\"link_$scan_group\" style=\"float: right; padding: 0 4px; margin: 5px 5px 0 30px; line-height: 16px; text-decoration: none; color: #C00; background-color: #FCC; border: solid #F00 1px;\" href=\"#found_top\" onclick=\"showhide('found_$scan_group');\"{$gt}X$lt/a$gt{$lt}h3$gt$scan_name$lt/h3$gt\n".($scan_group=='potential'?$lt.'p'.$gt.' &nbsp; * '.__("NOTE: These are probably not malicious scripts (but it's a good place to start looking <u>IF</u> your site is infected and no Known Threats were found).",'gotmls').$lt.'/p'.$gt:($scan_group=='wp_core'?$lt.'p'.$gt.' &nbsp; * '.sprintf(__("NOTE: We have detected changes to the WordPress Core files on your site. This could be an intentional modification or the malicious work of a hacker. We can restore these files to their original state to preserve the integrity of your original WordPress %s installation.",'gotmls'), GOTMLS_wp_version).' (for more info '.$lt.'a target="_blank" href="'.GOTMLS_plugin_home.'tag/wp-core-files/"'.$gt.__("read my blog",'gotmls').$lt.'/a'.$gt.').'.$lt.'/p'.$gt:$lt.'br /'.$gt)).$lt.'/ul'.$gt;
1112 if (!($dir = implode(GOTMLS_slash(), array_slice($dirs, 0, -1 * (2 + (INT) $_REQUEST["scan_what"])))))
1113 $dir = "/";
1114 $scanlog = array("dir" => $dir, "start" => time(), "type" => GOTMLS_sanitize($_REQUEST["scan_type"]));
1115 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && count($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) == 1 && ($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"][0] == "db_scan"))
1116 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = 0;
1117 $scanlog["settings"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"];
1118 if (isset($_REQUEST['scan_only']))
1119 $scanlog['scan_only'] = $_REQUEST['scan_only'];
1120 GOTMLS_update_scanlog(array("scan" => $scanlog));
1121 echo GOTMLS_box($lt.'div id="GOTMLS_scan_dir" style="float: right;"'.$gt.'&nbsp;('.(isset($GLOBALS["GOTMLS"]["scan"]["log"]["scan"]["dir"]) ? $GLOBALS["GOTMLS"]["scan"]["log"]["scan"]["dir"] : "Unknown path").")&nbsp;$lt/div$gt".__("Scan Details:",'gotmls'), $scan_groups_UL);
1122 $no_flush_LANGUAGE = __("Not flushing OB Handlers: %s",'gotmls');
1123 if (isset($_REQUEST["no_ob_end_flush"]))
1124 echo GOTMLS_error_div(sprintf($no_flush_LANGUAGE, GOTMLS_htmlspecialchars(print_r(ob_list_handlers(), 1))));
1125 elseif (is_array($OB_handlers) && count($OB_handlers)) {
1126 // $GOTMLS_OB_handlers = get_option("GOTMLS_OB_handlers", array());
1127 foreach (array_reverse($OB_handlers) as $OB_handler) {
1128 if (isset($GOTMLS_OB_handlers[$OB_handler]) && $GOTMLS_OB_handlers[$OB_handler] == "no_end_flush")
1129 echo GOTMLS_error_div(sprintf($no_flush_LANGUAGE, GOTMLS_htmlspecialchars($OB_handler)));
1130 elseif (in_array($OB_handler, $OB_default_handlers)) {
1131 // $GOTMLS_OB_handlers[$OB_handler] = "no_end_flush";
1132 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1133 @ob_end_flush();
1134 // $GOTMLS_OB_handlers[$OB_handler] = "ob_end_flush";
1135 // update_option("GOTMLS_OB_handlers", $GOTMLS_OB_handlers);
1136 }
1137 }
1138 }
1139 @ob_start();
1140 echo "\n{$lt}script type=\"text/javascript\"$gt$li_js\n/*{$lt}!--*"."/";
1141 if (!(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"])) {
1142 echo GOTMLS_return_threat("dirs", "wait", $dir).GOTMLS_update_status(sprintf(__("Preparing %s",'gotmls'), GOTMLS_replace_dirname($dir)), 0);//GOTMLS_return_threat("skipdirs", "blocked", $dir, GOTMLS_error_link("Directory Scan Depth set to 0, no files will be scanned!"));
1143 $GLOBALS["GOTMLS"]["tmp"]["scanfiles"][GOTMLS_encode($dir)] = GOTMLS_strip4java(GOTMLS_replace_dirname($dir));
1144 } elseif (is_dir($dir)) {
1145 $GOTMLS_dirs_at_depth[0] = 1;
1146 $GOTMLS_dir_at_depth[0] = 0;
1147 if (isset($_REQUEST['scan_only']) && is_array($_REQUEST['scan_only'])) {
1148 $GOTMLS_dirs_at_depth[0] += (count($_REQUEST['scan_only']) - 1);
1149 foreach ($_REQUEST['scan_only'] as $only_dir)
1150 if (is_dir(GOTMLS_trailingslashit($dir).$only_dir))
1151 GOTMLS_readdir(GOTMLS_trailingslashit($dir).$only_dir);
1152 } else
1153 GOTMLS_readdir($dir);
1154 } else
1155 echo GOTMLS_return_threat("errors", "blocked", $dir, GOTMLS_error_link("Not a valid directory!"));
1156 if ($_REQUEST["scan_type"] == "Quick Scan")
1157 echo GOTMLS_update_status(__("Completed!",'gotmls'), 100);
1158 else {
1159 echo GOTMLS_update_status(__("Starting Scan ...",'gotmls'));
1160 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]) && in_array("db_scan", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))
1161 $DB_scan_JS = ", 'db_scan'";
1162 if (isset($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]) && is_array($GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]) && in_array("db_scan", $GLOBALS["GOTMLS"]["scan"]["log"]["settings"]["check"]))
1163 echo GOTMLS_return_threat("dirs", "wait", "db_scan");//.GOTMLS_update_status(__("Starting Database Scan ...",'gotmls'));
1164 //else $DB_scan_JS = "";
1165 GOTMLS_flush('script');
1166 echo "/*--{$gt}*"."/\nvar scriptSRC = '".GOTMLS_admin_url('GOTMLS_scan', $GOTMLS_nonce_URL.'&mt='.$GLOBALS["GOTMLS"]["tmp"]["mt"].'&GOTMLS_scan=')."';\nvar scanfilesArKeys = ['".implode("','", array_keys($GLOBALS["GOTMLS"]["tmp"]["scanfiles"]))."'$DB_scan_JS];\nvar scanfilesArNames = ['Scanning ".implode("','Scanning ", $GLOBALS["GOTMLS"]["tmp"]["scanfiles"])."'".str_replace("db_scan", "Starting Database Scan ...", $DB_scan_JS).'];
1167 var scanfilesI = 0;
1168 var stopScanning;
1169 var gotStuckOn = -1;
1170 function scanNextDir(gotStuck) {
1171 clearTimeout(stopScanning);
1172 if (gotStuck > -1) {
1173 gotStuck = gotStuckOn;
1174 if (scanfilesArNames[gotStuck].substr(0, 3) != "Re-" && scanfilesArNames[gotStuck].substr(0, 10) != "Got Stuck ") {
1175 if (scanfilesArNames[gotStuck].substr(0, 9) == "Checking ") {
1176 scanfilesArNames.push(scanfilesArNames[gotStuck]);
1177 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_skip_file[]="+encodeURIComponent(scanfilesArNames[gotStuck].substr(9)));
1178 } else {
1179 scanfilesArNames.push("Re-"+scanfilesArNames[gotStuck]);
1180 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&GOTMLS_only_file=");
1181 }
1182 } else {
1183 var uri = scanfilesArKeys[gotStuck].split("&limit=", 2);
1184 var skipdir = (scanfilesArKeys[gotStuck]+"&").split("&",2);
1185 if (uri.length == 2) {
1186 var lim = (uri[1]+"&").split("&", 2);
1187 if (isNaN(lim[0]))
1188 lim[0] = 1024;
1189 else
1190 lim[0] = Math.round(lim[0]/2);
1191 scanfilesArKeys.push(uri[0]+"&limit="+lim[0]+"&"+lim[1]+"&GOTMLS_skip_dir="+skipdir[0]);
1192 } else {
1193 var lim = ["2048"];
1194 scanfilesArKeys.push(scanfilesArKeys[gotStuck]+"&limit=2048&GOTMLS_skip_dir="+skipdir[0]);
1195 }
1196 scanfilesArNames.push("Got Stuck ("+lim[0]+") "+scanfilesArNames[gotStuck]);
1197 }
1198 }
1199 if (document.getElementById("resume_button").value != "Pause") {
1200 stopScanning=setTimeout(function() {scanNextDir(-1);}, 1000);
1201 startTime++;
1202 } else if (scanfilesI < scanfilesArKeys.length) {
1203 document.getElementById("status_text").innerHTML = scanfilesArNames[scanfilesI];
1204 var newscript = document.createElement("script");
1205 newscript.setAttribute("src", scriptSRC+scanfilesArKeys[scanfilesI]);
1206 divx = document.getElementById("found_scanned");
1207 if (divx)
1208 divx.appendChild(newscript);
1209 gotStuckOn = scanfilesI++;
1210 stopScanning=setTimeout(function() {scanNextDir(0);}, '.$GLOBALS["GOTMLS"]["tmp"]['execution_time'].'000);
1211 }
1212 }
1213 startTime = ('.ceil(time()-$GLOBALS["GOTMLS"]["scan"]["log"]["scan"]["start"]).'+3);
1214 stopScanning=setTimeout(function() {scanNextDir(-1);}, 3000);
1215 function pauseresume(butt) {
1216 if (butt.value == "Resume")
1217 butt.value = "Pause";
1218 else
1219 butt.value = "Resume";
1220 }
1221 showhide("pause_button", true);'."\n/*{$lt}!--*"."/";
1222 }
1223 if (@ob_get_level()) {
1224 GOTMLS_flush('script');
1225 @ob_end_flush();
1226 }
1227 echo "/*--{$gt}*"."/\n$lt/script$gt$lt/form$gt";
1228 } else
1229 echo GOTMLS_box(GOTMLS_Invalid_Nonce(""), __("Starting a Complete Scan requires a valid Nonce Token. No valid Nonce Token was found at this time, either because the token have expired or because the data was invalid. Please try re-submitting the form above.",'gotmls')."\n{$lt}script type='text/javascript'$gt\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt\n");
1230 } else
1231 echo GOTMLS_box(__("Scan History",'gotmls'), GOTMLS_get_scan_history());
1232 echo "\n$lt/div$gt$lt/div$gt$lt/div$gt";
1233 }
1234
1235 function GOTMLS_login_error($elementId, $ERROR, $alert_txt = "") {
1236 $js = "\nif (GOTMLS_field = document.getElementById('$elementId'))\n\tGOTMLS_field.innerHTML = '<h2 style=\"text-align: center\">".GOTMLS_strip4java($ERROR)."</h2>';";
1237 return $js;
1238 }
1239
1240 function GOTMLS_print_login_form($ops = array()) {
1241 if (!is_array($ops))
1242 $ops = array();
1243 echo GOTMLS_login_form($ops);
1244 }
1245 if (defined("GOTMLS_SESSION_TIME") && is_numeric(GOTMLS_SESSION_TIME))
1246 add_action("login_form", "GOTMLS_print_login_form");
1247
1248 function GOTMLS_login_form($ops = array(), $form_id = "", $shortcode = "") {
1249 $gt = ">"; // This local variable never changes
1250 $lt = "<"; // This local variable never changes
1251 $up = "";
1252 foreach (array("form_id" => "loginform", "top" => "-200px", "height" => "280px", "u" => "log", "p" => "pwd") as $field => $default) {
1253 if (!(isset($ops["$field"]) && preg_match('/^[\w\-]++$/', $ops["$field"]) && GOTMLS_strlen($ops["$field"]) < 50))
1254 $ops["$field"] = $default;
1255 if (GOTMLS_strlen($field) == 1)
1256 $up .= "&GOTMLS_$field=".rawurlencode($ops["$field"]);
1257 }
1258 if (!(isset($GLOBALS["GOTMLS"]["tmp"]["loginform_id"]) && $GLOBALS["GOTMLS"]["tmp"]["loginform_id"]))
1259 $GLOBALS["GOTMLS"]["tmp"]["loginform_id"] = 0;
1260 $form_id = ++$GLOBALS["GOTMLS"]["tmp"]["loginform_id"];
1261 $loading_bits = '" id="loading_BRUTEFORCE_'.$form_id.'"'.$gt.$lt.'div style="top: '.$ops["top"].'; position: relative; background-color: #FFF; z-index: 99999;"'.$gt.$lt.'img style="height: '.$ops["height"];
1262 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]) && $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["firewall"]["BFLP"]) {
1263 $loading_bits = ' z-index: 9999; opacity: 0; top: 0; left: 0; width: 100%; height: 100%;'.$loading_bits;
1264 $other = " display: none;";
1265 } else
1266 $other = "";
1267 if (defined("GOTMLS_LOGIN_PROTECTION") && preg_match('/^[\da-f]{32}$/i', GOTMLS_LOGIN_PROTECTION)) {
1268 $ajaxURL = GOTMLS_admin_url("GOTMLS_logintime", GOTMLS_set_nonce($sess = GOTMLS_LOGIN_PROTECTION, GOTMLS_REMOTEADDR)."$up&GOTMLS_sess=$sess&GOTMLS_form_id=$form_id&GOTMLS_time=");
1269 return "$lt!-- Loading GOTMLS Brute-Force Protection --$gt$lt".'div style="position: absolute;'.$loading_bits.';" alt="Loading Brute-Force Protection ..." src="'.GOTMLS_images_path."GOTMLS-Loading.gif\" /$gt{$lt}div id='checking_BRUTEFORCE_$form_id'$gt Checking for JavaScript ... $lt/div$gt$lt/div$gt$lt/div$gt\n$lt".'div style="font-weight: bold;'."$other\"$gt$lt".'img style="height: 20px; vertical-align: middle;" alt="Brute-Force Protection from GOTMLS. NET" src="'.GOTMLS_images_path."checked.gif\" /$gt Brute-Force Protection is Active$lt/div$gt$lt".'input type="hidden" name="GOTMLS_sess" id="GOTMLS_sess_id_'.$form_id.'" value="'."$sess\" /$gt$lt".'input type="hidden" id="GOTMLS_offset_id_'.$form_id.'" value="0" name="GOTMLS_time" /'.$gt.$lt.'script type="text/javascript"'."$gt\nfunction GOTMLS_chk_session_$form_id() {\nvar GOTMLS_login_offset = new Date();\nvar GOTMLS_login_script = document.createElement('script');\nGOTMLS_login_script.src = '$ajaxURL'+GOTMLS_login_offset.getTime();\nif (GOTMLS_field = document.getElementById('GOTMLS_offset_id_$form_id')) {\n\tGOTMLS_field.value = GOTMLS_login_offset.getTime();\n}".GOTMLS_login_error("checking_BRUTEFORCE_$form_id", ' Checking for Session ... ')."\nif (GOTMLS_loading_gif = document.getElementById('loading_BRUTEFORCE_$form_id')) GOTMLS_loading_gif.style.display = 'block';\ndocument.head.appendChild(GOTMLS_login_script);\n}\nGOTMLS_chk_session_$form_id();\nsetInterval(function (){GOTMLS_chk_session_$form_id();}, 150000);\n$lt/script$gt\n";
1270 } else
1271 return "$lt!-- GOTMLS Brute-Force Protection is Disabled in the Firewall Options --$gt";
1272 }
1273 add_shortcode("gotmls-brute-force-protection", "GOTMLS_login_form");
1274
1275 function GOTMLS_ihc_login_form($ops = array()) {
1276 $gt = ">"; // This local variable never changes
1277 $lt = "<"; // This local variable never changes
1278 $return = "$lt!-- ihc_login_form: Indeed Ultimate Membership Pro is not installed --$gt";
1279 $form_end = "$lt/form$gt";
1280 if (function_exists("ihc_login_form")) {
1281 if (strpos($return = ihc_login_form($ops), $form_end))
1282 $return = str_replace($form_end, GOTMLS_login_form(array("form_id" => "ihc_login_form", "top" => "-280px")).$form_end, $return);
1283 else
1284 $return .= "\n$lt!-- ihc_login_form: form_end not found --$gt";
1285 }
1286 return "\n$lt!-- ihc_login_form: GOTMLS Brute-Force Protection integration with indeed-membership-pro --$gt$return";
1287 }
1288
1289 function GOTMLS_ajax_logintime() {
1290 if (headers_sent($filename, $linenum))
1291 $error_txt = sprintf("//Headers already sent in %s on line %s.\n", $filename, $linenum);
1292 else
1293 $error_txt = __("Please refresh the page before attempting to login.", 'gotmls');
1294 @header("Content-type: text/javascript");
1295 if (!defined("GOTMLS_FORMID"))
1296 define("GOTMLS_FORMID", (isset($_GET["GOTMLS_form_id"])&&is_numeric($_GET["GOTMLS_form_id"]))?(INT) $_GET["GOTMLS_form_id"]:0);
1297 $form_id = GOTMLS_FORMID;
1298 if (defined("GOTMLS_SESS_ERROR"))
1299 die(GOTMLS_login_error("checking_BRUTEFORCE_$form_id", GOTMLS_SESS_ERROR, $error_txt));
1300 elseif (defined("GOTMLS_LOGIN_PROTECTION") && preg_match('/^[\da-f]{32}$/i', GOTMLS_LOGIN_PROTECTION) && defined("GOTMLS_SESSION_TIME") && is_numeric(GOTMLS_SESSION_TIME) && defined("GOTMLS_logintime_JS") && defined("GOTMLS_SESS")) {
1301 if (GOTMLS_get_nonce(substr(GOTMLS_SESS, 0, 32), GOTMLS_REMOTEADDR))
1302 die(GOTMLS_logintime_JS);
1303 else
1304 die(GOTMLS_login_error("checking_BRUTEFORCE_$form_id", GOTMLS_Invalid_Nonce("//DEBUG: $form_id "), $error_txt));
1305 } else
1306 die(GOTMLS_login_error("checking_BRUTEFORCE_$form_id", 'Login Session Not Started!', $error_txt));
1307 }
1308
1309 function GOTMLS_ajax_lognewkey() {
1310 @header("Content-type: text/javascript");
1311 if (isset($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]) && $GLOBALS["GOTMLS"]["tmp"]["HeadersError"])
1312 echo "\n//Header Error: ".GOTMLS_strip4java(GOTMLS_htmlspecialchars($GLOBALS["GOTMLS"]["tmp"]["HeadersError"]));
1313 if (GOTMLS_get_nonce()) {
1314 if (isset($_POST["GOTMLS_installation_key"]) && ($_POST["GOTMLS_installation_key"] == GOTMLS_installation_key)) {
1315 $keys = GOTMLS_uckserialize(get_option('GOTMLS_Installation_Keys', array()));
1316 if (is_array($keys)) {
1317 $count = count($keys);
1318 if (!isset($keys[GOTMLS_installation_key]))
1319 $keys = array_merge($keys, array(GOTMLS_installation_key => GOTMLS_siteurl));
1320 } else
1321 $keys = array(GOTMLS_installation_key => GOTMLS_siteurl);
1322 update_option("GOTMLS_Installation_Keys", serialize($keys));
1323 die("\n//$count~".count($keys));
1324 } else
1325 die("\n//0");
1326 } else
1327 die(GOTMLS_Invalid_Nonce("\n//Log New Key Error: ")."\n");
1328 }
1329
1330 function GOTMLS_ajax_log_session() {
1331 $fail_msg = "/* GOTMLS SESSION FAIL */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\ndocument.getElementById('GOTMLS_patch_searching').innerHTML = '<div class=\"error\">".GOTMLS_strip4java(__("Your Server could not start a Session!",'gotmls'));
1332 if (headers_sent($filename, $linenum)) {
1333 if (!$filename)
1334 $filename = __("an unknown file",'gotmls');
1335 if (!is_numeric($linenum))
1336 $linenum = __("unknown",'gotmls');
1337 $fail_msg .= sprintf(__('<b>Headers already sent</b> in %1$s on line %2$s.','gotmls'), $filename, $linenum);
1338 die($fail_msg."</div>';");
1339 }
1340 if (is_file(GOTMLS_plugin_path."safe-load/session.php"))
1341 require_once(GOTMLS_plugin_path."safe-load/session.php");
1342 GOTMLS_session_start();
1343 if (!($sess_id = session_id()))
1344 session_start();
1345 header("Content-type: text/javascript");
1346 if (isset($_SESSION["GOTMLS_SESSION_TEST"]))
1347 die("/* GOTMLS SESSION PASS */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nshowhide('GOTMLS_patch_searching', true);\nif (autoUpdateDownloadGIF = document.getElementById('autoUpdateDownload'))\n\tdonationAmount = autoUpdateDownloadGIF.src.replace(/^.+\?/,'');\nif ((autoUpdateDownloadGIF.src == donationAmount) || donationAmount=='0') {\n\tif (patch_searching_div = document.getElementById('GOTMLS_patch_searching')) {\n\t\tif (autoUpdateDownloadGIF.src == donationAmount)\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("You must register and donate to use this feature!",'gotmls'))."</span>';\n\t\telse\n\t\t\tpatch_searching_div.innerHTML = '<span style=\"color: #F00;\">".GOTMLS_strip4java(__("This feature is available to those who have donated!",'gotmls'))."</span>';\n\t}\n} else {\n\tshowhide('GOTMLS_patch_searching');\n\tshowhide('GOTMLS_patch_button', true);\n}\n");
1348 else {
1349 $_SESSION["GOTMLS_SESSION_TEST"] = 1;
1350 if (isset($_GET["SESSION"]) && is_numeric($_GET["SESSION"]) && $_GET["SESSION"] > 0)
1351 die($fail_msg."</div>';");
1352 else
1353 die("/* GOTMLS SESSION TEST */\nif('undefined' != typeof stopCheckingSession && stopCheckingSession)\n\tclearTimeout(stopCheckingSession);\nstopCheckingSession = checkupdateserver('".GOTMLS_script_URI."&SESSION=1');");
1354 }
1355 }
1356
1357 function GOTMLS_set_plugin_action_links($links_array, $plugin_file) {
1358 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * GOTMLS_strlen($plugin_file))) && GOTMLS_strlen($plugin_file) > 10)
1359 $links_array = array_merge(array('<a href="'.admin_url('admin.php?page=GOTMLS-settings').'">'.GOTMLS_Scan_Settings_LANGUAGE.'</a>'), $links_array);
1360 return $links_array;
1361 }
1362 add_filter("plugin_action_links", "GOTMLS_set_plugin_action_links", 1, 2);
1363
1364 function GOTMLS_set_plugin_row_meta($links_array, $plugin_file) {
1365 if ($plugin_file == substr(str_replace("\\", "/", __FILE__), (-1 * GOTMLS_strlen($plugin_file))) && GOTMLS_strlen($plugin_file) > 10)
1366 $links_array = array_merge($links_array, array('<a target="_blank" href="'.GOTMLS_plugin_home.'faqs/">FAQ</a>','<a target="_blank" href="'.GOTMLS_plugin_home.'support/">Support</a>','<a target="_blank" href="https://gotmls.net/donate/?key='.GOTMLS_installation_key.'"><span style="font-size: 20px; height: 20px; width: 20px;" class="dashicons dashicons-heart"></span>Donate</a>'));
1367 return $links_array;
1368 }
1369 add_filter("plugin_row_meta", "GOTMLS_set_plugin_row_meta", 1, 2);
1370
1371 function GOTMLS_in_plugin_update_message($args) {
1372 $transient_name = 'GOTMLS_upgrade_notice_'.preg_replace('/[^0-9\.\_]/', "", $args["Version"].'_'.$args["new_version"]);
1373 if ((false === ($upgrade_notice = get_transient($transient_name))) && ($ret = GOTMLS_get_URL("https://plugins.svn.wordpress.org/gotmls/trunk/readme.txt"))) {
1374 $upgrade_notice = '';
1375 if ($match = preg_split('/==\s*Upgrade Notice\s*==\s+/i', $ret)) {
1376 if (preg_match('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]))
1377 $notice = (array) preg_split('/\n+=\s*'.str_replace(".", "\\.", GOTMLS_Version).'\s*=\s+/is', $match[1]);
1378 else
1379 $notice = (array) preg_split('/\n+=/is', $match[1]."\n=");
1380 if (preg_match_all('/=\s*([\.0-9]+)\s*=\s*([^=]+)/i', $notice[0], $matches, PREG_SET_ORDER)) {
1381 foreach ($matches as $m)
1382 $upgrade_notice .= GOTMLS_html_tags(array('br /' => array('span' => GOTMLS_html_tags(array('b' => esc_html($m[1]).': ')).esc_html($m[2]))));
1383 set_transient($transient_name, $upgrade_notice, DAY_IN_SECONDS);
1384 }
1385 }
1386 }
1387 echo wp_kses($upgrade_notice, array('br' => array(), 'span' => array(), 'b' => array()));
1388 }
1389 add_action("in_plugin_update_message-gotmls/index.php", "GOTMLS_in_plugin_update_message");
1390
1391 function GOTMLS_debug_hook($function) {
1392 return "\n<!-- Debugging $function ".round(microtime(true)-$GLOBALS["GOTMLS"]["MT"], 4)." -->\n";
1393 }
1394
1395 function GOTMLS_begin_wp_body_open() {
1396 return GOTMLS_debug_hook(__FUNCTION__);
1397 }
1398 function GOTMLS_finish_wp_body_open() {
1399 return GOTMLS_debug_hook(__FUNCTION__);
1400 }
1401 function GOTMLS_begin_wp_head() {
1402 echo GOTMLS_debug_hook(__FUNCTION__);
1403 }
1404 function GOTMLS_finish_wp_head() {
1405 echo GOTMLS_debug_hook(__FUNCTION__);
1406 }
1407 function GOTMLS_begin_wp_footer() {
1408 echo GOTMLS_debug_hook(__FUNCTION__);
1409 }
1410 function GOTMLS_finish_wp_footer() {
1411 echo GOTMLS_debug_hook(__FUNCTION__);
1412 }
1413
1414 if (isset($_REQUEST["eli"]) && ($_REQUEST["eli"] == "debug")) {
1415 foreach (array('wp_head', 'wp_body_open', 'wp_footer') as $wp_hook) {
1416 if (function_exists("GOTMLS_begin_$wp_hook"))
1417 add_action($wp_hook, "GOTMLS_begin_$wp_hook", 0);
1418 if (function_exists("GOTMLS_finish_$wp_hook"))
1419 add_action($wp_hook, "GOTMLS_finish_$wp_hook", 999999);
1420 }
1421 }
1422
1423 function GOTMLS_admin_init() {
1424 GOTMLS_define("GOTMLS_get_version_URL", GOTMLS_get_version("URL"));
1425 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"]))
1426 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_what"] = 2;
1427 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"]))
1428 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_depth"] = -1;
1429 if (isset($_REQUEST["scan_type"]) && ($_REQUEST["scan_type"] == "Quick Scan")) {
1430 if (!isset($_REQUEST["scan_what"])) $_REQUEST["scan_what"] = 2;
1431 if (!isset($_REQUEST["scan_only"])) {
1432 $_REQUEST["scan_only"] = array("","wp-includes","wp-admin");
1433 $dirs = GOTMLS_explode_dir(__FILE__);
1434 $dir = ABSPATH;//implode(GOTMLS_slash(), array_slice($dirs, 0, -2));
1435 $files = GOTMLS_getfiles($dir);
1436 $dirs = array();
1437 if (isset($files) && is_array($files) && count($files))
1438 foreach ($files as $file)
1439 if (is_dir(GOTMLS_trailingslashit($dir).$file))
1440 $dirs[] = GOTMLS_trailingslashit($dir).$file;
1441 $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"] = array_merge($dirs, $GLOBALS["GOTMLS"]["tmp"]["skip_dirs"]);
1442 $_REQUEST["scan_depth"] = -1;
1443 } elseif (!isset($_REQUEST["scan_depth"]))
1444 $_REQUEST["scan_depth"] = 2;
1445 if ($_REQUEST["scan_only"] && !is_array($_REQUEST["scan_only"]))
1446 $_REQUEST["scan_only"] = array($_REQUEST["scan_only"]);
1447 }
1448 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"]))
1449 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check_custom"] = "";
1450 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]) && is_numeric($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1451 $scan_level = intval($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]);
1452 else
1453 $scan_level = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1454 $ajax_functions = array('load_update', 'log_session', 'empty_trash', 'fix', 'logintime', 'lognewkey', 'position', 'scan', 'View_Quarantine', 'whitelist');
1455 if (GOTMLS_get_nonce()) {
1456 if (isset($_REQUEST["dont_check"]) && is_array($_REQUEST["dont_check"]) && count($_REQUEST["dont_check"]))
1457 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = GOTMLS_sanitize($_REQUEST["dont_check"]);
1458 elseif (isset($_POST["scan_type"]) || !(isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"])))
1459 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["dont_check"] = array();
1460 if (isset($_POST["scan_level"]) && is_numeric($_POST["scan_level"]))
1461 $scan_level = intval($_POST["scan_level"]);
1462 if (isset($scan_level) && is_numeric($scan_level))
1463 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = intval($scan_level);
1464 }
1465 foreach ($ajax_functions as $ajax_function) {
1466 add_action("wp_ajax_GOTMLS_$ajax_function", "GOTMLS_ajax_$ajax_function");
1467 add_action("wp_ajax_nopriv_GOTMLS_$ajax_function", substr($ajax_function, 0, 3) == "log"?"GOTMLS_ajax_$ajax_function":"GOTMLS_ajax_nopriv");
1468 }
1469 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"]))
1470 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["scan_level"] = count(explode('/', trailingslashit(GOTMLS_siteurl))) - 1;
1471 }
1472 add_action("admin_init", "GOTMLS_admin_init");
1473
1474 function GOTMLS_init() {
1475 load_plugin_textdomain('gotmls', false, basename(GOTMLS_plugin_path).'/languages');
1476 GOTMLS_define("GOTMLS_Failed_to_list_LANGUAGE", __("Failed to list files in directory!",'gotmls'));
1477 GOTMLS_define("GOTMLS_Run_Quick_Scan_LANGUAGE", __("Quick Scan",'gotmls'));
1478 GOTMLS_define("GOTMLS_View_Quarantine_LANGUAGE", __("View Quarantine",'gotmls'));
1479 GOTMLS_define("GOTMLS_View_Scan_Log_LANGUAGE", __("View Scan History",'gotmls'));
1480 GOTMLS_define("GOTMLS_require_version_LANGUAGE", sprintf(__("This Plugin requires WordPress version %s or higher",'gotmls'), GOTMLS_require_version));
1481 GOTMLS_define("GOTMLS_Scan_Settings_LANGUAGE", __("Scan Settings",'gotmls'));
1482 GOTMLS_define("GOTMLS_Loading_LANGUAGE", __("Loading, Please Wait ...",'gotmls'));
1483 GOTMLS_define("GOTMLS_Automatically_Fix_LANGUAGE", __("Automatically Fix SELECTED Files Now",'gotmls'));
1484 GOTMLS_define("GOTMLS_position_msg", __("Default position",'gotmls'));
1485 $GLOBALS["GOTMLS"]["tmp"]["threat_levels"] = array(__("Database Injections",'gotmls')=>"db_scan",__("htaccess Threats",'gotmls')=>"htaccess",__("TimThumb Exploits",'gotmls')=>"timthumb",__("Known Threats",'gotmls')=>"known",__("Core File Changes",'gotmls')=>"wp_core",__("Potential Threats",'gotmls')=>"potential");
1486 if (!isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"]))
1487 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["check"] = $GLOBALS["GOTMLS"]["tmp"]["threat_levels"];
1488 if (defined("GOTMLS_SESSION_TIME") && is_numeric(GOTMLS_SESSION_TIME)) {
1489 if (function_exists("ihc_login_form"))
1490 add_shortcode("ihc-login-form", "GOTMLS_ihc_login_form");
1491 if (function_exists("GOTMLS_print_up_login_form")) {
1492 if (function_exists("wc_get_template"))
1493 add_action("woocommerce_login_form", "GOTMLS_print_up_login_form");
1494 if (function_exists("wpum_login_form"))
1495 add_action("wpum_before_submit_button_login_form", "GOTMLS_print_up_login_form");
1496 }
1497 }
1498 register_post_type(
1499 'gotmls_quarantine',
1500 array(
1501 'labels' => array(
1502 'name' => _x( 'Quarantine', 'post type general name' ),
1503 'singular_name' => _x( 'Quarantine', 'post type singular name' ),
1504 'view_item' => __( 'View Quarantine Record' ),
1505 'all_items' => __( 'All Quarantine Records' ),
1506 ),
1507 'public' => false,
1508 'map_meta_cap' => true,
1509 'hierarchical' => false,
1510 'rewrite' => false,
1511 'query_var' => false,
1512 'can_export' => false,
1513 'delete_with_user' => false,
1514 'supports' => array( 'title', 'author', 'editor', 'excerpt', 'custom-fields' ),
1515 'capability_type' => 'customize_gotmls_quarantine',
1516 'capabilities' => array(
1517 'create_posts' => 'customize',
1518 'delete_others_posts' => 'customize',
1519 'delete_post' => 'customize',
1520 'delete_posts' => 'customize',
1521 'delete_private_posts' => 'customize',
1522 'delete_published_posts' => 'do_not_allow',
1523 'edit_others_posts' => 'do_not_allow',
1524 'edit_post' => 'do_not_allow',
1525 'edit_posts' => 'do_not_allow',
1526 'edit_private_posts' => 'do_not_allow',
1527 'edit_published_posts' => 'do_not_allow',
1528 'publish_posts' => 'customize',
1529 'read' => 'do_not_allow',
1530 'read_post' => 'do_not_allow',
1531 'read_private_posts' => 'customize',
1532 ),
1533 )
1534 );
1535 register_post_type(
1536 'gotmls_results',
1537 array(
1538 'labels' => array(
1539 'name' => _x( 'Results', 'post type general name' ),
1540 'singular_name' => _x( 'Result', 'post type singular name' ),
1541 'view_item' => __( 'View Scan Results' ),
1542 'all_items' => __( 'All Scans' ),
1543 ),
1544 'public' => false,
1545 'map_meta_cap' => true,
1546 'hierarchical' => true,
1547 'rewrite' => false,
1548 'query_var' => false,
1549 'can_export' => false,
1550 'delete_with_user' => false,
1551 'supports' => array( 'title', 'author', 'editor', 'excerpt', 'custom-fields' ),
1552 'capability_type' => 'customize_gotmls_reults',
1553 'capabilities' => array(
1554 'create_posts' => 'customize',
1555 'delete_others_posts' => 'customize',
1556 'delete_post' => 'customize',
1557 'delete_posts' => 'customize',
1558 'delete_private_posts' => 'customize',
1559 'delete_published_posts' => 'do_not_allow',
1560 'edit_others_posts' => 'do_not_allow',
1561 'edit_post' => 'do_not_allow',
1562 'edit_posts' => 'do_not_allow',
1563 'edit_private_posts' => 'do_not_allow',
1564 'edit_published_posts' => 'do_not_allow',
1565 'publish_posts' => 'customize',
1566 'read' => 'do_not_allow',
1567 'read_post' => 'do_not_allow',
1568 'read_private_posts' => 'customize',
1569 ),
1570 )
1571 );
1572 }
1573 add_action("init", "GOTMLS_init");
1574
1575 function GOTMLS_ajax_position() {
1576 if (GOTMLS_get_nonce(GOTMLS_position_msg)) {
1577 $properties = array("body" => 'style="margin: 0; padding: 0;"');
1578 if (isset($_GET["GOTMLS_msg"]) && $_GET["GOTMLS_msg"] == GOTMLS_position_msg) {
1579 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"] = $GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"];
1580 $gl = '><';
1581 $properties["html"] = $gl.'head'.$gl.'script type="text/javascript">
1582 if (curDiv = window.parent.document.getElementById("div_file")) {
1583 curDiv.style.left = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][0].'";
1584 curDiv.style.top = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][1].'";
1585 curDiv.style.height = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][2].'";
1586 curDiv.style.width = "'.$GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][3].'";
1587 }
1588 </script'.$gl.'/head';
1589 } elseif (isset($_GET["GOTMLS_x"]) || isset($_GET["GOTMLS_y"]) || isset($_GET["GOTMLS_h"]) || isset($_GET["GOTMLS_w"])) {
1590 if (isset($_GET["GOTMLS_x"]))
1591 GOTMLS_validate_position(0, $_GET["GOTMLS_x"]);
1592 if (isset($_GET["GOTMLS_y"]))
1593 GOTMLS_validate_position(1, $_GET["GOTMLS_y"]);
1594 if (isset($_GET["GOTMLS_h"]))
1595 GOTMLS_validate_position(2, $_GET["GOTMLS_h"]);
1596 if (isset($_GET["GOTMLS_w"]))
1597 GOTMLS_validate_position(3, $_GET["GOTMLS_w"]);
1598 $_GET["GOTMLS_msg"] = __("New position",'gotmls');
1599 } else
1600 die("\n//Position Error: No new position to save!\n");
1601 update_option("GOTMLS_settings_array", $GLOBALS["GOTMLS"]["tmp"]["settings_array"]);
1602 die(GOTMLS_html_tags(array("html" => array("body" => GOTMLS_htmlentities($_GET["GOTMLS_msg"]).' '.__("saved.",'gotmls').(implode($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"]) == implode($GLOBALS["GOTMLS"]["tmp"]["default"]["msg_position"])?"":' <a href="'.GOTMLS_admin_url('GOTMLS_position', GOTMLS_set_nonce(GOTMLS_position_msg).'&GOTMLS_msg='.GOTMLS_esc_url(GOTMLS_position_msg)).'">['.GOTMLS_position_msg.']</a>'))), $properties));
1603 } else
1604 die(GOTMLS_Invalid_Nonce("\n//Position Error: ")."\n");
1605 }
1606
1607 function GOTMLS_validate_position($vector, $position) {
1608 if (preg_match('/^[0-9]+px$/', $position)) {
1609 $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["msg_position"][$vector] = $position;
1610 return true;
1611 } else
1612 return false;
1613 }
1614
1615 function GOTMLS_ajax_empty_trash() {
1616 global $wpdb;
1617 GOTMLS_kill_invalid_user();
1618 $gl = '><';
1619 $action = array("RESTORE" => "UPDATE $wpdb->posts SET `post_status` = 'private'", "DELETE" => "DELETE FROM $wpdb->posts");
1620 if (GOTMLS_get_nonce("empty_trash") && isset($_REQUEST["alter"]) && isset($action[$_REQUEST["alter"]])) {
1621 if ($trashed = $wpdb->query($action[$_REQUEST["alter"]]." WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'trash'")) {
1622 $wpdb->query("REPAIR TABLE $wpdb->posts");
1623 $trashmsg = sprintf(__("%s %d item from the quarantine trash.",'gotmls'), strtoupper(GOTMLS_sanitize($_REQUEST["alter"])."d"), (INT) $trashed);
1624 } else
1625 $trashmsg = __("Failed to empty the trash.",'gotmls');
1626 } else
1627 $trashmsg = GOTMLS_Invalid_Nonce("");
1628 $properties = array("html" => $gl.'head'.$gl."script type='text/javascript'>\nalert('".GOTMLS_strip4java($trashmsg)."');\nif (curDiv = window.parent)\n\tcurDiv.location.reload(false);\nelse\n\twindow.opener.location.reload(false);</script$gl/head", "body" => 'style="margin: 0; padding: 0;"');
1629 die(GOTMLS_html_tags(array("html" => array("body" => $trashmsg)), $properties));
1630 }
1631
1632 function GOTMLS_ajax_whitelist() {
1633 global $wpdb;
1634 GOTMLS_kill_invalid_user();
1635 $body = "Whitelist Error: No file or checksum!";
1636 $script = "window.parent.showhide('GOTMLS_iFrame', true);";
1637 if (GOTMLS_get_nonce("GOTMLS_whitelist")) {
1638 if (isset($_POST["GOTMLS_whitelist"]) && isset($_POST["GOTMLS_chksum"])) {
1639 if (("list_group" == $_POST["GOTMLS_whitelist"]) && is_array($_POST["GOTMLS_chksum"])) {
1640 $valid_chksums = array();
1641 foreach ($_POST["GOTMLS_chksum"] as $chksum)
1642 if (preg_match('/^[\da-f]{32}O\d++$/', $chksum))
1643 $valid_chksums[] = "'$chksum'";
1644 if (count($valid_chksums)) {
1645 $trash = "UPDATE `$wpdb->posts` SET `post_status` = 'trash' WHERE `post_type` = 'GOTMLS_quarantine' AND `post_status` = 'pending' AND CONCAT(`post_mime_type`, 'O', `comment_count`) IN (".implode(", ", $valid_chksums).")";
1646 if ($count = $wpdb->query($trash)) {
1647 foreach ($valid_chksums as $chksum)
1648 $script .= "\nif (chksum = window.parent.document.getElementById('whitelist_".substr($chksum, 1)."))\n\tchksum.checked = false;\nif (chksum = window.parent.document.getElementById('GOTMLS_whitelist_".substr($chksum, 1)."))\n\tchksum.style.display = 'none';";
1649 if (count($_POST["GOTMLS_chksum"]) == count($valid_chksums) && count($valid_chksums) == $count)
1650 $body = "Removed $count files from the Whitelist";
1651 else
1652 $body = "<li>Removed $count of ".count($valid_chksums)." (of ".count($_POST["GOTMLS_chksum"])." posted)</li>";
1653 } else
1654 $body = "<li>Whitelist Not Updated!</li>";
1655 } else
1656 $body = "<li>No Valid chksums!</li>";
1657 } else {
1658 $file = GOTMLS_decode($_POST["GOTMLS_whitelist"]);
1659 $chksum = explode("O", $_POST["GOTMLS_chksum"]."O");
1660 if (GOTMLS_strlen($chksum[0]) == 32 && GOTMLS_strlen($chksum[1]) == 32 && is_file($file) && (($filesize = @filesize($file)) == GOTMLS_load_contents($TXT = @file_get_contents($file))) && md5($TXT) == $chksum[0] && GOTMLS_write_quarantine($file, "whitelist", "pending"))
1661 $body = "Added $file to Whitelist!<br />\n<iframe style='width: 90%; height: 250px; border: none;' src='".GOTMLS_plugin_home."whitelist.html?whitelist=".GOTMLS_htmlspecialchars($_POST["GOTMLS_whitelist"])."&hash=$chksum[0]&size=$filesize&key=$chksum[1]'></iframe>";
1662 else
1663 $body = "<li>Invalid checksum!</li>";
1664 }
1665 } else
1666 $body = "Whitelist Error: No file or checksum!";
1667 } else
1668 $body = GOTMLS_Invalid_Nonce("\n//Whitelist Error: ");
1669 die(GOTMLS_html_tags(array("html" => array("body" => $body, "script" => $script))));
1670 }
1671
1672 function GOTMLS_ajax_fix() {
1673 global $wpdb;
1674 GOTMLS_kill_invalid_user();
1675 $gt = ">"; // This local variable never changes
1676 $lt = "<"; // This local variable never changes
1677 if (GOTMLS_get_nonce()) {
1678 if (isset($_REQUEST["GOTMLS_fix"]) && !is_array($_REQUEST["GOTMLS_fix"]))
1679 $_REQUEST["GOTMLS_fix"] = array($_REQUEST["GOTMLS_fix"]);
1680 if (isset($_REQUEST["GOTMLS_fix"]) && is_array($_REQUEST["GOTMLS_fix"]) && isset($_REQUEST["GOTMLS_fixing"]) && $_REQUEST["GOTMLS_fixing"]) {
1681 GOTMLS_update_scanlog(array("settings" => $GLOBALS["GOTMLS"]["tmp"]["settings_array"]));
1682 $callAlert = "clearTimeout(callAlert);\ncallAlert=setTimeout(function() {alert_repaired(1);}, 30000);";
1683 $li_js = $lt."script type=\"text/javascript\"$gt\nscanned = 0;\nvar callAlert;\nfunction alert_repaired(failed) {\nclearTimeout(callAlert);\nif (failed)\nfilesFailed='the rest, try again to change more.';\nwindow.parent.check_for_donation('Fixed '+filesFixed+' files, failed to fix '+filesFailed);\n}\n$callAlert\nwindow.parent.showhide('GOTMLS_iFrame', true);\nfilesFixed=0;\nfilesFailed=0;\nfunction fixedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file))\n\tli_file.className='GOTMLS_plugin';\nif (li_file = window.parent.document.getElementById('GOTMLS_quarantine_'+file)) {\n\tli_file.style.display='none';\n\tli_file.innerHTML='';\n\t}\n}\nfunction DeletedFile(file) {\n filesFixed++;\nif (li_file = window.parent.document.getElementById('check_'+file))\n\tli_file.checked=false;\nif (li_file = window.parent.document.getElementById('list_'+file)) {\n\tli_file.className='GOTMLS_plugin';\n\tif (true || !isNaN(file)) {\n\t\tli_file = li_file.parentNode".(isset($_REQUEST["GOTMLS_fix"][0]) && is_numeric($_REQUEST["GOTMLS_fix"][0])?'.parentNode':'').";\n\t\tli_file.style.display='none';\n\t\tli_file.innerHTML='';\n}}}\nfunction failedFile(file) {\n filesFailed++;\nwindow.parent.document.getElementById('check_'+file).checked=false; \n}\n$lt/script$gt\n{$lt}script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1684 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] * 2);
1685 $HTML_safe = explode("split-here-for-content", GOTMLS_html_tags(array("html" => array("body" => "split-here-for-content"))));
1686 echo $HTML_safe[0];
1687 GOTMLS_update_scanlog(array("scan" => array("dir" => count($_REQUEST["GOTMLS_fix"])." Files", "start" => time())));
1688 foreach ($_REQUEST["GOTMLS_fix"] as $clean_file) {
1689 if (is_numeric($clean_file)) {
1690 if (($Q_post = GOTMLS_get_quarantine($clean_file)) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine" && isset($Q_post["post_status"])) {
1691 $safe_path = esc_html($Q_post["post_title"]);
1692 if ($_REQUEST["GOTMLS_fixing"] > 1) {
1693 echo $lt."li$gt ".sprintf(__("Removing %s ... ",'gotmls'), $safe_path);
1694 $Q_post["post_status"] = "trash";
1695 if (wp_update_post($Q_post)) {
1696 echo __("Done!",'gotmls');
1697 $li_js .= "/*--$gt*"."/\nDeletedFile('$clean_file');\n/*$lt!--*"."/";
1698 } else {
1699 echo __("Failed to remove!",'gotmls');
1700 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1701 }
1702 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "Removal from Quarantine")));
1703 } else {
1704 $Q_post["post_status"] = "pending";
1705 $part = explode(":", $Q_post["post_title"].':');
1706 if (count($part) > 2 && is_numeric($part[1])) {
1707 if (!(substr($part[0], -7) == "options" && ($R_post = $wpdb->get_results("SELECT option_name, option_value FROM `$part[0]` WHERE option_id = ".(INT) $part[1], ARRAY_A)) && count($R_post)))
1708 $R_post = GOTMLS_get_quarantine((INT) $part[1]);
1709 if (isset($R_post["post_type"]) && strtolower($R_post["post_type"]) == $part[0]) {
1710 if (isset($_GET["eli"]) || ($R_post["post_content"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post["post_content"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1711 echo $lt."li$gt Restoring Post ID $part[1] ... ";
1712 $R_post["post_modified_gmt"] = $Q_post["post_modified"];
1713 $R_post["post_content"] = GOTMLS_decode($Q_post["post_content"]);
1714 if (wp_update_post($R_post)) {
1715 echo __("Complete!",'gotmls');
1716 wp_update_post($Q_post);
1717 $li_js .= "/*--$gt*"."/\nfixedFile('$clean_file');\n/*$lt!--*"."/";
1718 } else {
1719 echo __("Restoration of post_content Failed!",'gotmls');
1720 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1721 }
1722 } else {
1723 echo $lt."li$gt".__("Restoration Aborted, post_content was modified outside of this quarantine!",'gotmls').$lt."pre$gt".GOTMLS_htmlspecialchars(print_r(array("R"=>$R_post,"Q"=>$Q_post),1))."$lt/pre$gt";
1724 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1725 }
1726 } elseif (isset($R_post[0]["option_name"]) && strtolower($R_post[0]["option_name"]) == strtolower(trim($part[2], "\" "))) {
1727 if (isset($_GET["eli"]) || ($R_post[0]["option_value"] == GOTMLS_decode($Q_post["post_content_filtered"])) || ($R_post[0]["option_value"] == stripslashes(GOTMLS_decode($Q_post["post_content_filtered"])))) {
1728 echo $lt."li$gt Restoring Option ID $part[1] ... ";
1729 if ($wpdb->update($part[0], array("option_value" => GOTMLS_decode($Q_post["post_content"])), array("option_id" => $part[1]))) {
1730 echo __("Complete!",'gotmls');
1731 wp_update_post($Q_post);
1732 $li_js .= "/*--$gt*"."/\nfixedFile('$clean_file');\n/*$lt!--*"."/";
1733 } else {
1734 echo __("Restoration of option_value Failed!{$lt}pre$gt".GOTMLS_htmlspecialchars(print_r(array("part"=>$part,"error"=>$wpdb->last_error),1))."$lt/pre$gt",'gotmls');
1735 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1736 }
1737 } else {
1738 echo $lt."li$gt".__("Restoration Aborted, option_value was modified outside of this quarantine!",'gotmls').$lt."pre$gt".GOTMLS_htmlspecialchars(print_r(array(GOTMLS_decode($Q_post["post_content_filtered"]) => $R_post[0]["option_value"], "R"=>$R_post[0],"Q"=>$Q_post),1))."$lt/pre$gt";
1739 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1740 }
1741 } else {
1742 echo $lt."li$gt".__("Restore Failed!",'gotmls').$lt."pre$gt".GOTMLS_htmlspecialchars(print_r(array('$part' => $part, "R"=>$R_post,"Q"=>$Q_post),1))."$lt/pre$gt";
1743 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1744 }
1745 } elseif (isset($_GET["eli"]) || is_file($safe_path)) {
1746 echo sprintf(__($lt."li$gt Restoring %s ... ",'gotmls'), $safe_path);
1747 if (GOTMLS_save_contents($safe_path, GOTMLS_decode($Q_post["post_content"])) && wp_update_post($Q_post)) {
1748 echo __("Complete!",'gotmls');
1749 $li_js .= "/*--$gt*"."/\nfixedFile('$clean_file');\n/*$lt!--*"."/";
1750 } else {
1751 echo __("Restore Failed!",'gotmls');
1752 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1753 }
1754 } else {
1755 echo $lt."li$gt".sprintf(__("Restoration Aborted, file %s does not exist!",'gotmls'), $safe_path);
1756 $li_js .= "/*--$gt*"."/\nfailedFile('$clean_file');\n/*$lt!--*"."/";
1757 }
1758 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "Restoration from Quarantine")));
1759 }
1760 echo "$lt/li$gt\n$li_js/*--$gt*"."/\n$callAlert\n$lt/script$gt\n";
1761 $li_js = $lt."script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1762 }
1763 } elseif (is_numeric($decoded_file = GOTMLS_decode($clean_file))) {
1764 $li_js .= GOTMLS_db_scan($decoded_file);
1765 echo $lt."/li$gt\n$li_js/*--$gt*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n$lt/script$gt\n";
1766 $li_js = $lt."script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1767 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "DB Fix")));
1768 } else {
1769 $safe_path = esc_html(realpath($decoded_file = GOTMLS_decode($clean_file)));
1770 if (is_file($safe_path)) {
1771 echo $lt."li$gt".sprintf(__("Fixing %s ... ",'gotmls'), $safe_path);
1772 $li_js .= GOTMLS_scanfile($safe_path);
1773 echo "$lt/li$gt\n$li_js/*--$gt*"."/\n$callAlert\n//".$GLOBALS["GOTMLS"]["tmp"]["debug_fix"]."\n$lt/script$gt\n";
1774 $li_js = $lt."script type=\"text/javascript\"$gt\n/*$lt!--*"."/";
1775 } else
1776 echo $lt."li$gt".sprintf(__("File %s not found!",'gotmls'), $safe_path)."$lt/li$gt";
1777 GOTMLS_update_scanlog(array("scan" => array("finish" => time(), "type" => "Automatic Fix")));
1778 }
1779 }
1780 $nonce = GOTMLS_set_nonce(__FUNCTION__."1676");
1781 die($lt.'div id="check_site_warning" style="background-color: #F00;"'.$gt.sprintf(__("Because some changes were made we need to check to make sure it did not break your site. If this stays Red and the frame below does not load please %srevert the changes%s made during this automated fix process",'gotmls'), $lt.'a href="'.GOTMLS_images_path.'?page=GOTMLS_View_Quarantine&'.GOTMLS_set_nonce(GOTMLS_update_home).'"'.$gt, "$lt/a$gt").'... '.$lt.'span style="color: #F00;"'.$gt.__("Never mind, it worked!",'gotmls')."$lt/span$gt$lt/div$gt$lt".'br /'.$gt.$lt.'iframe id="test_frame" name="test_frame" src="'.GOTMLS_admin_url('GOTMLS_View_Quarantine', 'check_site=1&'.$nonce).'" style="width: 100%; height: 200px"'."$gt$lt/iframe$gt$li_js/*--$gt*"."/\nalert_repaired(0);\n$lt/script$gt\n$HTML_safe[1]");
1782 } else
1783 die(GOTMLS_html_tags(array("html" => array("body" => $lt."script type=\"text/javascript\"$gt\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".__("Nothing Selected to be Changed!",'gotmls')."');\n$lt/script$gt".__("Done!",'gotmls')))));
1784 } else
1785 die(GOTMLS_html_tags(array("html" => array("body" => $lt."script type=\"text/javascript\"$gt\nwindow.parent.showhide('GOTMLS_iFrame', true);\nalert('".GOTMLS_Invalid_Nonce("")."');\n$lt/script$gt".__("Done!",'gotmls')))));
1786 }
1787
1788 function GOTMLS_ajax_scan() {
1789 $gt = ">"; // This local variable never changes
1790 $lt = "<"; // This local variable never changes
1791 GOTMLS_kill_invalid_user();
1792 if (GOTMLS_get_nonce()) {
1793 @error_reporting(0);
1794 if (isset($_GET["GOTMLS_scan"])) {
1795 $script_form = GOTMLS_html_tags(array("script" => GOTMLS_js_text_range())).$lt.'table style="top: 0px; left: 0px; width: 100%; height: 100%; position: absolute;"'.$gt.$lt.'tr'.$gt.$lt.'td style="width: 100%"'.$gt;
1796 @set_time_limit($GLOBALS["GOTMLS"]["tmp"]['execution_time'] - 5);
1797 if (is_numeric($_GET["GOTMLS_scan"])) {
1798 if (($Q_post = GOTMLS_get_quarantine((INT) $_GET["GOTMLS_scan"])) && isset($Q_post["post_type"]) && strtolower($Q_post["post_type"]) == "gotmls_quarantine") {
1799 GOTMLS_load_contents(GOTMLS_decode($Q_post["post_content"]));
1800 GOTMLS_view_details($Q_post, $lt.'form style="margin: 0;" method="post" action="'.admin_url('admin-ajax.php?'.GOTMLS_set_nonce(__FUNCTION__."1605")).'" onsubmit="return confirm(\''.__("Are you sure you want to delete the record of this file from the quarantine?",'gotmls').'\');"'.$gt.$lt.'input type="hidden" name="GOTMLS_fix[]" value="'.$Q_post["ID"].'"'.$gt.$lt.'input type="hidden" name="GOTMLS_fixing" value="2"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_fix"'.$gt.$lt.'input type="submit" value="DELETE from Quarantine" style="display: none; background-color: #C00; float: right;"'.$gt.$lt.'/form'.$gt);
1801 } else
1802 die(GOTMLS_html_tags(array("html" => array("body" => __("This record no longer exists in the quarantine.",'gotmls').$lt."br /$gt\n{$lt}script type=\"text/javascript\"$gt\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n$lt/script$gt"))));
1803 } elseif (substr($_GET["GOTMLS_scan"]."1234567", 0, 7) == "db_scan") {
1804 @header("Content-type: text/javascript");
1805 if (isset($_GET["GOTMLS_only_file"])) {
1806 if (GOTMLS_strlen($_GET["GOTMLS_only_file"])) {
1807 echo '//re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1808 die(GOTMLS_db_scan().'//END OF JavaScript');
1809 } else {
1810 echo '//re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1811 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1812 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1813 $path = "db_scan=$file";
1814 echo "/*--$gt*"."/\nscanfilesArKeys.push('db_scan&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*$lt!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1815 }
1816 }
1817 die(GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Database Scan ...",'gotmls'))."/*--$gt*"."/\nscanNextDir(-1);\n/*$lt!--*"."/");
1818 }
1819 } else {
1820 echo '//db_scan: '.gmdate("Y-m-d H:i:s\n");
1821 die(GOTMLS_db_scan().'//END OF JavaScript');
1822 }
1823 } else {
1824 $file = GOTMLS_decode($_GET["GOTMLS_scan"]);
1825 if (is_numeric($file))
1826 die("\n$script_form".GOTMLS_db_scan($file));
1827 elseif (substr($file."1234567", 0, 7) == "db_scan") {
1828 @header("Content-type: text/javascript");
1829 if (isset($_GET["GOTMLS_only_file"])) {
1830 if (GOTMLS_strlen($_GET["GOTMLS_only_file"])) {
1831 echo '//encoded re-db_scan: '.md5($_GET["GOTMLS_only_file"]).gmdate(" Y-m-d H:i:s\n");
1832 die(GOTMLS_db_scan().'//END OF JavaScript');
1833 } else {
1834 echo '//encoded re-db_scan: all'.gmdate(" Y-m-d H:i:s\n");
1835 if (isset($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"])) {
1836 foreach ($GLOBALS["GOTMLS"]["tmp"]["definitions_array"]["db_scan"] as $file => $regx) {
1837 $path = "db_scan=$file";
1838 echo "/*--$gt*"."/\nscanfilesArKeys.push('".GOTMLS_encode($dir)."&GOTMLS_only_file=".GOTMLS_encode($file)."');\nscanfilesArNames.push('Re-Checking ".GOTMLS_strip4java(str_replace("db_scan", "Database", str_replace("db_scan=", "Database for ", $path)))."');\n/*$lt!--*"."/".GOTMLS_return_threat("dirs", "wait", $path);
1839 }
1840 }
1841 echo GOTMLS_return_threat("dir", "question", "db_scan").GOTMLS_update_status(__("Re-Starting Encoded Database Scan ...",'gotmls'))."/*--$gt*"."/\nscanNextDir(-1);\n/*$lt!--*"."/";
1842 }
1843 } else {
1844 echo '//encoded db_scan: but no GOTMLS_only_file'.gmdate("Y-m-d H:i:s\n");
1845 die(GOTMLS_db_scan().'//END OF JavaScript');
1846 }
1847 } elseif (is_dir($file)) {
1848 @error_reporting(0);
1849 @header("Content-type: text/javascript");
1850 if (isset($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"]))
1851 $GLOBALS["GOTMLS"]["tmp"]["skip_ext"] = $GLOBALS["GOTMLS"]["tmp"]["settings_array"]["exclude_ext"];
1852 @ob_start();
1853 echo GOTMLS_scandir($file);
1854 if (@ob_get_level()) {
1855 GOTMLS_flush();
1856 @ob_end_clean();//_flush();
1857 }
1858 die('//END OF JavaScript');
1859 } elseif (file_exists($file)) {
1860 $real_file = realpath($file);
1861 if (is_file($real_file) && ($filesize = filesize($real_file)))
1862 GOTMLS_load_contents(file_get_contents($real_file));
1863 else
1864 GOTMLS_load_contents("");
1865 if (isset($GLOBALS["GOTMLS"]["tmp"]["encoding"]) && !headers_sent($filename, $linenum))
1866 @header("Content-type: text/html; charset=".$GLOBALS["GOTMLS"]["tmp"]["encoding"]);
1867 echo $lt."html$gt\n{$lt}head$gt\n{$lt}title{$gt}Scan File: ".esc_html($file)." (".(isset($GLOBALS["GOTMLS"]["tmp"]["file_contents"])?GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]):filesize($file))." bytes ".(isset($GLOBALS["GOTMLS"]["tmp"]["encoding"])?$GLOBALS["GOTMLS"]["tmp"]["encoding"]:"... Bad Encoding").")$lt/title$gt\n$lt/head$gt\n{$lt}body$gt\n";
1868 $fa = $lt.'img src="'.GOTMLS_images_path.'wait.gif" height=16 width=16 alt="Wait..." /'.$gt.__("Scanning file contents ... ",'gotmls');
1869 $show_wl_form = "if (sid = document.getElementById('whitelist_form'))\n\tsid.style.display = 'block';\n";
1870 $show_uw_form = "";
1871 $fadef = " No Threats Found";
1872 if (isset($GLOBALS["GOTMLS"]["tmp"]["contents_whitelist"]) && $GLOBALS["GOTMLS"]["tmp"]["contents_whitelist"]) {
1873 $wl_form = __("Are you sure you want to remove this file from the whitelist so it will be included in future scans?",'gotmls').'\');"'.$gt.$lt.'input type="hidden" name="GOTMLS_whitelist" value="list_group"'.$gt.$lt.'input type="hidden" name="GOTMLS_chksum[]" value="'.md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'O'.GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'"'.$gt.$lt.'input type="submit" value="Remove from Whitelist" style="float: left;"';
1874 $show_uw_form = $show_wl_form;
1875 $fadef = " File is Whitelisted";
1876 } else
1877 $wl_form = __("Are you sure this file is not infected and you want to ignore it in future scans?",'gotmls').'\');"'.$gt.$lt.'input type="hidden" name="GOTMLS_whitelist" value="'.GOTMLS_encode($file).'"'.$gt.$lt.'input type="hidden" name="GOTMLS_chksum" value="'.md5($GLOBALS["GOTMLS"]["tmp"]["file_contents"]).'O'.GOTMLS_installation_key.'"'.$gt.$lt.'input type="submit" value="Whitelist this file" style="float: left;"';
1878 echo "\n$script_form\n$lt".'form style="margin: 0; display: none;" id="whitelist_form" method="post" action="'.admin_url('admin-ajax.php').'" onsubmit="return confirm(\''.$wl_form.$gt.$lt.'input type="hidden" name="'.str_replace('=', '" value="', GOTMLS_set_nonce("GOTMLS_whitelist")).'"'.$gt.$lt.'input type="hidden" name="action" value="GOTMLS_whitelist"'."$gt\n$lt/form$gt\n".GOTMLS_file_details($file)."\n$lt".'div style="overflow: auto;"'."$gt\n$lt".'span onmouseover="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'block\';" onmouseout="document.getElementById(\'file_details_'.md5($file).'\').style.display=\'none\';"'.$gt.__("Potential threats in file:",'gotmls')."$lt/span$gt\n{$lt}span style=\"position: absolute; right: 5px;\" id=\"threats_in_file\"$gt$fa$lt/span$gt\n$lt/div$gt$lt/td$gt$lt/tr$gt\n{$lt}tr$gt{$lt}td style=\"height: 100%\"$gt\n{$lt}textarea id=\"ta_file\" style=\"width: 100%; height: 100%\"$gt".GOTMLS_htmlentities(str_replace("\r", "", $GLOBALS["GOTMLS"]["tmp"]["file_contents"]))."$lt/textarea$gt$lt/td$gt$lt/tr$gt$lt/table$gt";
1879 GOTMLS_scanfile($real_file);
1880 $fa = "";
1881 $f = 0;
1882 if (isset($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && is_array($GLOBALS["GOTMLS"]["tmp"]["threats_found"]) && count($GLOBALS["GOTMLS"]["tmp"]["threats_found"])) {
1883 $f = 1;
1884 foreach ($GLOBALS["GOTMLS"]["tmp"]["threats_found"] as $threats_found => $threats_name) {
1885 list($start, $end, $junk) = explode("-", "$threats_found--", 3);
1886 if ($start > $end)
1887 $fa .= "ERROR[$f]: $threats_found / ".GOTMLS_strlen($GLOBALS["GOTMLS"]["tmp"]["file_contents"]);
1888 else
1889 $fa .= $lt.'a title="'.GOTMLS_htmlspecialchars($threats_name).'" href="javascript:select_text_range('."'ta_file', $start, $end);\"".$gt."[$f]$lt/a$gt ";
1890 $f++;
1891 }
1892 } else
1893 $fa = $fadef;
1894 die($lt."script$gt\nif (sid = document.getElementById('threats_in_file'))\n\tsid.style.display = 'none';\n".(($f>0)?$show_wl_form:$show_uw_form)."$lt/script$gt\n$lt".'span style="position: absolute; right: 5px; top: 2px;"'.$gt." ( $fa ) $lt/span$gt\n$lt/body$gt$lt/html$gt");
1895 } else {
1896 //@header("Content-type: text/javascript");
1897 die("// ERROR: ".sprintf(__("The file %s does not exist, it must have already been deleted.",'gotmls'), GOTMLS_htmlspecialchars($file)).$lt."script type=\"text/javascript\"$gt\nif (typeof window.parent.showhide === 'function') window.parent.showhide('GOTMLS_iFrame', true);\n//$lt/script$gt");
1898 }
1899 }
1900 } else
1901 die("\n//Directory Error: Nothing to scan!\n");
1902 } else {
1903 $alert = "if (is_button = document.getElementById('resume_button')) is_button.value = 'Resume'; alert('Invalid or Expired Nonce Token! You probably need to restart the scan :-(');";
1904 if (isset($_GET["GOTMLS_scan"]) && is_dir(GOTMLS_decode($_GET["GOTMLS_scan"])))
1905 @header("Content-type: text/javascript");
1906 else
1907 $alert = $lt."script type='text/javascript'$gt\n$alert\n$lt/script$gt";
1908 die(GOTMLS_Invalid_Nonce("$alert\n//Ajax Scan Nonce Error: ")."\n");
1909 }
1910 }
1911
1912 function GOTMLS_ajax_nopriv() {
1913 die("\n//Permission Error: User not authenticated!\n");
1914 }
1915