← All changes
|
includes/widgets/Login_Register_Form/Security_Manager.php
+13
-4
51.1.14
→
51.1.87
View file →
| @@ -58,9 +58,9 @@ | ||
| 58 | 58 | $attempts++; |
| 59 | 59 | set_transient($transient_key, $attempts, self::LOCKOUT_DURATION); |
| 60 | 60 | |
| 61 | 61 | // Log security event |
| 62 | - error_log("King Addons Security: Failed {$action} attempt #{$attempts} from IP {$ip_address}"); | |
| 62 | + // error_log("King Addons Security: Failed {$action} attempt #{$attempts} from IP {$ip_address}"); | |
| 63 | 63 | |
| 64 | 64 | return $attempts; |
| 65 | 65 | } |
| 66 | 66 | |
| @@ -138,10 +138,19 @@ | ||
| 138 | 138 | 'error' => esc_html__('File type mismatch detected. Upload rejected for security.', 'king-addons') |
| 139 | 139 | ]; |
| 140 | 140 | } |
| 141 | 141 | |
| 142 | - // Check for malicious content in text files | |
| 142 | + // Check for malicious content in text files (limit file size to prevent DoS) | |
| 143 | 143 | if (in_array($file_type['type'], ['text/plain', 'application/pdf'])) { |
| 144 | + // Security fix: Check file size before reading to prevent DoS | |
| 145 | + $file_size = filesize($file_data['tmp_name']); | |
| 146 | + if ($file_size > 1024 * 1024) { // 1MB limit for content scanning | |
| 147 | + return [ | |
| 148 | + 'valid' => false, | |
| 149 | + 'error' => esc_html__('File too large for content scanning.', 'king-addons') | |
| 150 | + ]; | |
| 151 | + } | |
| 152 | + | |
| 144 | 153 | $content = file_get_contents($file_data['tmp_name']); |
| 145 | 154 | if (self::contains_malicious_content($content)) { |
| 146 | 155 | return [ |
| 147 | 156 | 'valid' => false, |
| @@ -183,9 +192,9 @@ | ||
| 183 | 192 | } |
| 184 | 193 | |
| 185 | 194 | // Validate email domain for additional security |
| 186 | 195 | if (!empty($sanitized['email']) && !self::is_safe_email_domain($sanitized['email'])) { |
| 187 | - error_log("King Addons Security: Suspicious email domain from {$provider}: {$sanitized['email']}"); | |
| 196 | + // error_log("King Addons Security: Suspicious email domain from {$provider}: {$sanitized['email']}"); | |
| 188 | 197 | } |
| 189 | 198 | |
| 190 | 199 | return $sanitized; |
| 191 | 200 | } |
| @@ -212,9 +221,9 @@ | ||
| 212 | 221 | ]); |
| 213 | 222 | |
| 214 | 223 | foreach ($suspicious_patterns as $pattern) { |
| 215 | 224 | if (preg_match($pattern, $text_to_check)) { |
| 216 | - error_log("King Addons Security: Suspicious registration pattern detected: {$pattern}"); | |
| 225 | + // error_log("King Addons Security: Suspicious registration pattern detected: {$pattern}"); | |
| 217 | 226 | return true; |
| 218 | 227 | } |
| 219 | 228 | } |
| 220 | 229 | |