PluginProbe
Loginizer / trunk
Loginizer vtrunk
2.1.1 2.1.0 2.0.9 2.0.8 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 trunk 1.0 1.0.1 1.0.2 1.1.0 1.1.1 1.2.0 1.3.0 1.3.1 1.3.2 1.3.3 All 75 releases
← All changes | init.php +575 -1350 1.3.2 → trunk View file →
@@ -4,13 +4,14 @@
4 4 echo 'You are not allowed to access this page directly.';
5 5 exit;
6 6 }
7 7
8 -define('LOGINIZER_VERSION', '1.3.2');
9 -define('LOGINIZER_DIR', WP_PLUGIN_DIR.'/'.basename(dirname(LOGINIZER_FILE)));
8 +define('LOGINIZER_VERSION', '2.1.1');
9 +define('LOGINIZER_DIR', dirname(LOGINIZER_FILE));
10 10 define('LOGINIZER_URL', plugins_url('', LOGINIZER_FILE));
11 11 define('LOGINIZER_PRO_URL', 'https://loginizer.com/features#compare');
12 -define('LOGINIZER_DOCS', 'https://loginizer.com/wiki/');
12 +define('LOGINIZER_PRICING_URL', 'https://loginizer.com/pricing');
13 +define('LOGINIZER_DOCS', 'https://loginizer.com/docs/');
13 14
14 15 include_once(LOGINIZER_DIR.'/functions.php');
15 16
16 17 // Ok so we are now ready to go
@@ -23,9 +24,9 @@
23 24
24 25 $sql = array();
25 26
26 27 $sql[] = "DROP TABLE IF EXISTS `".$wpdb->prefix."loginizer_logs`";
27 -
28 +
28 29 $sql[] = "CREATE TABLE `".$wpdb->prefix."loginizer_logs` (
29 30 `username` varchar(255) NOT NULL DEFAULT '',
30 31 `time` int(10) NOT NULL DEFAULT '0',
31 32 `count` int(10) NOT NULL DEFAULT '0',
@@ -30,10 +31,11 @@
30 31 `time` int(10) NOT NULL DEFAULT '0',
31 32 `count` int(10) NOT NULL DEFAULT '0',
32 33 `lockout` int(10) NOT NULL DEFAULT '0',
33 34 `ip` varchar(255) NOT NULL DEFAULT '',
35 + `url` varchar(255) NOT NULL DEFAULT '',
34 36 UNIQUE KEY `ip` (`ip`)
35 - ) ENGINE=MyISAM DEFAULT CHARSET=utf8;";
37 + ) DEFAULT CHARSET=utf8;";
36 38
37 39 foreach($sql as $sk => $sv){
38 40 $wpdb->query($sv);
39 41 }
@@ -42,12 +44,24 @@
42 44 add_option('loginizer_options', array());
43 45 add_option('loginizer_last_reset', 0);
44 46 add_option('loginizer_whitelist', array());
45 47 add_option('loginizer_blacklist', array());
46 -
48 + add_option('loginizer_2fa_whitelist', array());
49 +
50 + // TODO:: REMOVE THIS AFTER MARCH 2025
51 + $softwp_upgrade = get_option('loginizer_softwp_upgrade', 0);
52 + if(!defined('SITEPAD') && empty($softwp_upgrade)){
53 + loginizer_check_softaculous();
54 + }
47 55 }
48 56
49 -// Checks if we are to update ?
57 +/**
58 + * Updates the database structure for Loginizer
59 + *
60 + * If the plugin files are updated but database structure is not updated
61 + * this function will update the database structure as per the plugin version
62 + * NOTE: This does not update plugin files it just updates the database structure
63 + */
50 64 function loginizer_update_check(){
51 65
52 66 global $wpdb;
53 67
@@ -75,9 +89,9 @@
75 89 // Trick the following if conditions to not run
76 90 $version = (int) str_replace('.', '', LOGINIZER_VERSION);
77 91
78 92 }
79 -
93 +
80 94 // Is it less than 1.0.1 ?
81 95 if($version < 101){
82 96
83 97 // TODO : GET the existing settings
@@ -107,9 +121,17 @@
107 121
108 122 // Update the existing failed logs to new table
109 123 if(is_array($lz_failed_logs)){
110 124 foreach($lz_failed_logs as $fk => $fv){
111 - $wpdb->query("INSERT INTO ".$wpdb->prefix."loginizer_logs SET `username` = '".$fv['username']."', `time` = '".$fv['time']."', `count` = '".$fv['count']."', `lockout` = '".$fv['lockout']."', `ip` = '".$fv['ip']."';");
125 + $insert_data = array('username' => $fv['username'],
126 + 'time' => $fv['time'],
127 + 'count' => $fv['count'],
128 + 'lockout' => $fv['lockout'],
129 + 'ip' => $fv['ip']);
130 +
131 + $format = array('%s','%d','%d','%d','%s');
132 +
133 + $wpdb->insert($wpdb->prefix.'loginizer_logs', $insert_data, $format);
112 134 }
113 135 }
114 136
115 137 // Update the existing options to new structure
@@ -158,14 +180,54 @@
158 180 }
159 181
160 182 }
161 183
184 + // Is it less than 1.3.9 ?
185 + if($version < 139){
186 +
187 + $wpdb->query("ALTER TABLE ".$wpdb->prefix."loginizer_logs ADD `url` VARCHAR(255) NOT NULL DEFAULT '' AFTER `ip`;");
188 +
189 + }
190 +
191 + // Setting alignment to left in social login ?
192 + if($version < 201){
193 + $social_settings = get_option('loginizer_social_settings', []);
194 +
195 + if(!empty($social_settings)){
196 + if(!empty($social_settings['login']) && (!empty($social_settings['login']['login_form']) || !empty($social_settings['login']['registration_form']))){
197 + $social_settings['login']['button_alignment'] = 'left';
198 + }
199 +
200 + if(!empty($social_settings['woocommerce']) && (!empty($social_settings['woocommmerce']['login_form']) || !empty($social_settings['woocommerce']['registration_form']))){
201 + $social_settings['woocommerce']['button_alignment'] = 'left';
202 + }
203 +
204 + if(!empty($social_settings['comment']) && !empty($social_settings['comment']['enable_buttons'])){
205 + $social_settings['comment']['button_alignment'] = 'left';
206 + }
207 +
208 + update_option('loginizer_social_settings', $social_settings);
209 + }
210 + }
211 +
162 212 // Save the new Version
163 213 update_option('loginizer_version', LOGINIZER_VERSION);
164 214
215 + // TODO:: REMOVE THIS AFTER MARCH 2025
216 + $softwp_upgrade = get_option('loginizer_softwp_upgrade', 0);
217 + if(!defined('SITEPAD') && empty($softwp_upgrade)){
218 + loginizer_check_softaculous();
219 + }
220 +
221 + // In Sitepad Math Captcha is enabled by default
222 + if(defined('SITEPAD') && get_option('loginizer_captcha') === false){
223 + $option['captcha_no_google'] = 1;
224 + add_option('loginizer_captcha', $option);
225 + }
226 +
165 227 }
166 228
167 -// Add the action to load the plugin
229 +// Add the action to load the plugin
168 230 add_action('plugins_loaded', 'loginizer_load_plugin');
169 231
170 232 // The function that will be called when the plugin is loaded
171 233 function loginizer_load_plugin(){
@@ -174,13 +236,33 @@
174 236
175 237 // Check if the installed version is outdated
176 238 loginizer_update_check();
177 239
240 + // There was an issue were for some users update was stuck, and free was able to get updated through auto updater option
241 + // removing these filters fixes that issue, and our Pro update blocker was improved in 2.1.1
242 + // This check can be removed 1 year from 28.09.2026
243 + if(defined('LOGINIZER_PRO_VERSION') && version_compare(LOGINIZER_PRO_VERSION, '2.1.1', '<')){
244 + foreach(['site_transient_update_plugins', 'pre_site_transient_update_plugins'] as $hook){
245 + remove_filter($hook, 'loginizer_pro_disable_manual_update_for_plugin'); // Older Pro used the default priority
246 + remove_filter($hook, 'loginizer_pro_disable_manual_update_for_plugin', 99);
247 + }
248 + }
249 +
178 250 // Set the array
179 - $loginizer = array();
251 + if(empty($loginizer)){
252 + $loginizer = array();
253 + }
180 254
255 + $loginizer['prefix'] = !defined('SITEPAD') ? 'Loginizer ' : 'SitePad ';
256 + $loginizer['app'] = !defined('SITEPAD') ? 'WordPress' : 'SitePad';
257 + $loginizer['login_basename'] = !defined('SITEPAD') ? 'wp-login.php' : 'login.php';
258 + $loginizer['wp-includes'] = !defined('SITEPAD') ? 'wp-includes' : 'site-inc';
259 +
181 260 // The IP Method to use
182 261 $loginizer['ip_method'] = get_option('loginizer_ip_method');
262 + if($loginizer['ip_method'] == 3){
263 + $loginizer['custom_ip_method'] = get_option('loginizer_custom_ip_method');
264 + }
183 265
184 266 // Load settings
185 267 $options = get_option('loginizer_options');
186 268 $loginizer['max_retries'] = empty($options['max_retries']) ? 3 : $options['max_retries'];
@@ -188,15 +270,43 @@
188 270 $loginizer['max_lockouts'] = empty($options['max_lockouts']) ? 5 : $options['max_lockouts'];
189 271 $loginizer['lockouts_extend'] = empty($options['lockouts_extend']) ? 86400 : $options['lockouts_extend']; // 24 hours
190 272 $loginizer['reset_retries'] = empty($options['reset_retries']) ? 86400 : $options['reset_retries']; // 24 hours
191 273 $loginizer['notify_email'] = empty($options['notify_email']) ? 0 : $options['notify_email'];
192 -
274 + $loginizer['notify_email_address'] = lz_is_multisite() ? get_site_option('admin_email') : get_option('admin_email');
275 + $loginizer['trusted_ips'] = empty($options['trusted_ips']) ? false : true;
276 + $loginizer['blocked_screen'] = empty($options['blocked_screen']) ? false : true;
277 + $loginizer['social_settings'] = get_option('loginizer_social_settings', []);
278 +
279 + if(!empty($options['notify_email_address'])){
280 + $loginizer['notify_email_address'] = $options['notify_email_address'];
281 + $loginizer['custom_notify_email'] = 1;
282 + }
283 +
284 + // Login Success Email Notification.
285 + $loginizer['login_mail'] = get_option('loginizer_login_mail', []);
286 + add_action('init', 'loginizer_load_translation_vars', 0);
287 +
288 + $loginizer['login_mail_subject'] = empty($loginizer['login_mail']['subject']) ? '' : $loginizer['login_mail']['subject'];
289 + $loginizer['login_mail_body'] = empty($loginizer['login_mail']['body']) ? '' : $loginizer['login_mail']['body'];
290 +
193 291 // Load the blacklist and whitelist
194 - $loginizer['blacklist'] = get_option('loginizer_blacklist');
195 - $loginizer['whitelist'] = get_option('loginizer_whitelist');
292 + $loginizer['blacklist'] = get_option('loginizer_blacklist', []);
293 + $loginizer['whitelist'] = get_option('loginizer_whitelist', []);
294 + $loginizer['2fa_whitelist'] = get_option('loginizer_2fa_whitelist');
196 295
296 + // It should not be false
297 + if(empty($loginizer['2fa_whitelist'])){
298 + $loginizer['2fa_whitelist'] = array();
299 + }
300 +
197 301 // When was the database cleared last time
198 302 $loginizer['last_reset'] = get_option('loginizer_last_reset');
303 +
304 + if(!isset($loginizer['ultimate-member-active'])){
305 + $um_is_active = in_array('ultimate-member/ultimate-member.php', apply_filters('active_plugins', get_option('active_plugins', [])));
306 +
307 + $loginizer['ultimate-member-active'] = !empty($um_is_active) ? true : false;
308 + }
199 309
200 310 //print_r($loginizer);
201 311
202 312 // Clear retries
@@ -212,171 +322,66 @@
212 322 $loginizer['ins_time'] = $ins_time;
213 323
214 324 // Set the current IP
215 325 $loginizer['current_ip'] = lz_getip();
326 +
327 + // Is Brute Force Disabled ?
328 + $loginizer['disable_brute'] = get_option('loginizer_disable_brute');
216 329
217 - /* Filters and actions */
330 + // Filters and actions
331 + if(empty($loginizer['disable_brute'])){
218 332
219 - // Use this to verify before WP tries to login
220 - // Is always called and is the first function to be called
221 - //add_action('wp_authenticate', 'loginizer_wp_authenticate', 10, 2);// Not called by XML-RPC
222 - add_filter('authenticate', 'loginizer_wp_authenticate', 10001, 3);// This one is called by xmlrpc as well as GUI
223 -
224 - // Is called when a login attempt fails
225 - // Hence Update our records that the login failed
226 - add_action('wp_login_failed', 'loginizer_login_failed');
227 -
228 - // Is called before displaying the error message so that we dont show that the username is wrong or the password
229 - // Update Error message
230 - add_action('wp_login_errors', 'loginizer_error_handler', 10001, 2);
231 -
232 - // Is the premium features there ?
233 - if(file_exists(LOGINIZER_DIR.'/premium.php')){
333 + // Use this to verify before WP tries to login
334 + // Is always called and is the first function to be called
335 + //add_action('wp_authenticate', 'loginizer_wp_authenticate', 10, 2);// Not called by XML-RPC
336 + add_filter('authenticate', 'loginizer_wp_authenticate', 10001, 3);// This one is called by xmlrpc as well as GUI
234 337
235 - // Include the file
236 - include_once(LOGINIZER_DIR.'/premium.php');
338 + // Is called when a login attempt fails
339 + // Hence Update our records that the login failed
340 + add_action('wp_login_failed', 'loginizer_login_failed');
237 341
238 - loginizer_security_init();
239 -
240 - // Its the free version
241 - }else{
342 + // Is called before displaying the error message so that we dont show that the username is wrong or the password
343 + // Update Error message
344 + add_action('wp_login_errors', 'loginizer_error_handler', 10001, 2);
345 + add_action('woocommerce_login_failed', 'loginizer_woocommerce_error_handler', 10001);
346 + add_action('wp_login', 'loginizer_login_success', 11, 2);
347 + add_action('rsssl_two_factor_user_authenticated', 'loginizer_rsssl_2fa_success');
242 348
243 - // The promo time
244 - $loginizer['promo_time'] = get_option('loginizer_promo_time');
245 - if(empty($loginizer['promo_time'])){
246 - $loginizer['promo_time'] = time();
247 - update_option('loginizer_promo_time', $loginizer['promo_time']);
349 + if(!empty($loginizer['ultimate-member-active'])){
350 + add_action('wp_login_failed', 'loginizer_ultimatemember_error_handler', 10001);
248 351 }
249 -
250 - // Are we to show the loginizer promo
251 - if(!empty($loginizer['promo_time']) && $loginizer['promo_time'] > 0 && $loginizer['promo_time'] < (time() - (30*24*3600))){
252 -
253 - add_action('admin_notices', 'loginizer_promo');
254 -
352 +
353 + if(!empty($_COOKIE['lz_social_error']) && !empty($loginizer['social_settings'])){
354 + add_filter('wp_login_errors', 'loginizer_social_login_error_handler', 10000, 2);
255 355 }
256 -
257 - // Are we to disable the promo
258 - if(isset($_GET['loginizer_promo']) && (int)$_GET['loginizer_promo'] == 0){
259 - update_option('loginizer_promo_time', (0 - time()) );
260 - die('DONE');
356 + }
357 +
358 + // Social Login Form Actions
359 + if(!empty($loginizer['social_settings'])){
360 + if(!empty($loginizer['social_settings']['login']['login_form'])){
361 + add_action('login_form', 'loginizer_social_btn_login');
261 362 }
262 -
263 363 }
264 364
265 -}
365 + if((function_exists('wp_doing_ajax') && wp_doing_ajax()) || (defined( 'DOING_AJAX' ) && DOING_AJAX)){
366 + include_once LOGINIZER_DIR . '/main/ajax.php';
367 + }
266 368
267 -// Show the promo
268 -function loginizer_promo(){
369 + if(is_admin()){
370 + include_once LOGINIZER_DIR . '/main/admin.php';
371 + }
269 372
270 - echo '
271 -<style>
272 -.lz_button {
273 -background-color: #4CAF50; /* Green */
274 -border: none;
275 -color: white;
276 -padding: 8px 16px;
277 -text-align: center;
278 -text-decoration: none;
279 -display: inline-block;
280 -font-size: 16px;
281 -margin: 4px 2px;
282 --webkit-transition-duration: 0.4s; /* Safari */
283 -transition-duration: 0.4s;
284 -cursor: pointer;
373 + // ----------------
374 + // PRO INIT END
375 + // ----------------
376 +
377 + // Secuity checks for social login.
378 + if(!empty($_GET['lz_social_provider']) && loginizer_can_login() && empty($_GET['lz_api'])){
379 + add_action('init', 'loginizer_social_login_load');
380 + return;
381 + }
285 382 }
286 383
287 -.lz_button:focus{
288 -border: none;
289 -color: white;
290 -}
291 -
292 -.lz_button1 {
293 -color: white;
294 -background-color: #4CAF50;
295 -border:3px solid #4CAF50;
296 -}
297 -
298 -.lz_button1:hover {
299 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
300 -color: white;
301 -border:3px solid #4CAF50;
302 -}
303 -
304 -.lz_button2 {
305 -color: white;
306 -background-color: #0085ba;
307 -}
308 -
309 -.lz_button2:hover {
310 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
311 -color: white;
312 -}
313 -
314 -.lz_button3 {
315 -color: white;
316 -background-color: #365899;
317 -}
318 -
319 -.lz_button3:hover {
320 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
321 -color: white;
322 -}
323 -
324 -.lz_button4 {
325 -color: white;
326 -background-color: rgb(66, 184, 221);
327 -}
328 -
329 -.lz_button4:hover {
330 -box-shadow: 0 6px 8px 0 rgba(0,0,0,0.24), 0 9px 25px 0 rgba(0,0,0,0.19);
331 -color: white;
332 -}
333 -
334 -.loginizer_promo-close{
335 -float:right;
336 -text-decoration:none;
337 -margin: 5px 10px 0px 0px;
338 -}
339 -
340 -.loginizer_promo-close:hover{
341 -color: red;
342 -}
343 -</style>
344 -
345 -<script>
346 -jQuery(document).ready( function() {
347 - (function($) {
348 - $("#loginizer_promo .loginizer_promo-close").click(function(){
349 - var data;
350 -
351 - // Hide it
352 - $("#loginizer_promo").hide();
353 -
354 - // Save this preference
355 - $.post("'.admin_url('?loginizer_promo=0').'", data, function(response) {
356 - //alert(response);
357 - });
358 - });
359 - })(jQuery);
360 -});
361 -</script>
362 -
363 -<div class="notice notice-success" id="loginizer_promo" style="min-height:120px">
364 - <a class="loginizer_promo-close" href="javascript:" aria-label="Dismiss this Notice">
365 - <span class="dashicons dashicons-dismiss"></span> Dismiss
366 - </a>
367 - <img src="'.LOGINIZER_URL.'/loginizer-200.png" style="float:left; margin:10px 20px 10px 10px" width="100" />
368 - <p style="font-size:16px">We are glad you like Loginizer and have been using it since the past few days. It is time to take the next step </p>
369 - <p>
370 - <a class="lz_button lz_button1" target="_blank" href="https://loginizer.com/features">Upgrade to Pro</a>
371 - <a class="lz_button lz_button2" target="_blank" href="https://wordpress.org/support/view/plugin-reviews/loginizer">Rate it 5★\'s</a>
372 - <a class="lz_button lz_button3" target="_blank" href="https://www.facebook.com/Loginizer-815504798591884/">Like Us on Facebook</a>
373 - <a class="lz_button lz_button4" target="_blank" href="https://twitter.com/home?status='.rawurlencode('I use @loginizer to secure my #WordPress site - https://loginizer.com').'">Tweet about Loginizer</a>
374 - </p>
375 -</div>';
376 -
377 -}
378 -
379 384 // Should return NULL if everything is fine
380 385 function loginizer_wp_authenticate($user, $username, $password){
381 386
382 387 global $loginizer, $lz_error, $lz_cannot_login, $lz_user_pass;
@@ -388,13 +393,36 @@
388 393 // Are you whitelisted ?
389 394 if(loginizer_is_whitelisted()){
390 395 $loginizer['ip_is_whitelisted'] = 1;
391 396 return $user;
397 +
398 + } else if (!empty($loginizer['trusted_ips'])){
399 + $lz_cannot_login = 1;
400 +
401 + // This is used by WP Activity Log
402 + apply_filters( 'wp_login_blocked', $username );
403 +
404 + // Shows a blocked screen
405 + if(!empty($loginizer['blocked_screen'])){
406 + $lz_error['trusted_ip'] = __('You are restricted from logging in as your IP is not whitelisted.', 'loginizer');
407 + loginizer_blocked_page($lz_error);
408 + }
409 +
410 + return new WP_Error('ip_blacklisted', __('You are restricted from logging in as your IP is not whitelisted.', 'loginizer'));
392 411 }
393 412
394 413 // Are you blacklisted ?
395 414 if(loginizer_is_blacklisted()){
396 415 $lz_cannot_login = 1;
416 +
417 + // This is used by WP Activity Log
418 + apply_filters( 'wp_login_blocked', $username );
419 +
420 + // Shows a blocked screen
421 + if(!empty($loginizer['blocked_screen'])){
422 + loginizer_blocked_page($lz_error);
423 + }
424 +
397 425 return new WP_Error('ip_blacklisted', implode('', $lz_error), 'loginizer');
398 426 }
399 427
400 428 // Is the username blacklisted ?
@@ -400,8 +428,12 @@
400 428 // Is the username blacklisted ?
401 429 if(function_exists('loginizer_user_blacklisted')){
402 430 if(loginizer_user_blacklisted($username)){
403 431 $lz_cannot_login = 1;
432 +
433 + // This is used by WP Activity Log
434 + apply_filters( 'wp_login_blocked', $username );
435 +
404 436 return new WP_Error('user_blacklisted', implode('', $lz_error), 'loginizer');
405 437 }
406 438 }
407 439
@@ -409,11 +441,19 @@
409 441 return $user;
410 442 }
411 443
412 444 $lz_cannot_login = 1;
445 +
446 + // This is used by WP Activity Log
447 + apply_filters( 'wp_login_blocked', $username );
413 448
449 + // Shows a blocked screen
450 + if(!empty($loginizer['blocked_screen'])){
451 + loginizer_blocked_page($lz_error);
452 + }
453 +
414 454 return new WP_Error('ip_blocked', implode('', $lz_error), 'loginizer');
415 -
455 +
416 456 }
417 457
418 458 function loginizer_can_login(){
419 459
@@ -419,12 +459,13 @@
419 459
420 460 global $wpdb, $loginizer, $lz_error;
421 461
422 462 // Get the logs
423 - $result = lz_selectquery("SELECT * FROM `".$wpdb->prefix."loginizer_logs` WHERE `ip` = '".$loginizer['current_ip']."';");
463 + $sel_query = $wpdb->prepare("SELECT * FROM `".$wpdb->prefix."loginizer_logs` WHERE `ip` = %s", $loginizer['current_ip']);
464 + $result = lz_selectquery($sel_query);
424 465
425 466 if(!empty($result['count']) && ($result['count'] % $loginizer['max_retries']) == 0){
426 -
467 +
427 468 // Has he reached max lockouts ?
428 469 if($result['lockout'] >= $loginizer['max_lockouts']){
429 470 $loginizer['lockout_time'] = $loginizer['lockouts_extend'];
430 471 }
@@ -432,21 +473,24 @@
432 473 // Is he in the lockout time ?
433 474 if($result['time'] >= (time() - $loginizer['lockout_time'])){
434 475 $banlift = ceil((($result['time'] + $loginizer['lockout_time']) - time()) / 60);
435 476
436 - //echo 'Current Time '.date('m/d/Y H:i:s', time()).'<br />';
437 - //echo 'Last attempt '.date('m/d/Y H:i:s', $result['time']).'<br />';
438 - //echo 'Unlock Time '.date('m/d/Y H:i:s', $result['time'] + $loginizer['lockout_time']).'<br />';
477 + //echo 'Current Time '.date('d/M/Y H:i:s P', time()).'<br />';
478 + //echo 'Last attempt '.date('d/M/Y H:i:s P', $result['time']).'<br />';
479 + //echo 'Unlock Time '.date('d/M/Y H:i:s P', $result['time'] + $loginizer['lockout_time']).'<br />';
439 480
440 - $_time = $banlift.' minute(s)';
481 + $_time = $banlift.' '.$loginizer['msg']['minutes_err'];
441 482
442 483 if($banlift > 60){
443 484 $banlift = ceil($banlift / 60);
444 - $_time = $banlift.' hour(s)';
485 + $_time = $banlift.' '.$loginizer['msg']['hours_err'];
445 486 }
446 487
447 - $lz_error['ip_blocked'] = 'You have exceeded maximum login retries<br /> Please try after '.$_time;
488 + $lz_error['ip_blocked'] = $loginizer['msg']['lockout_err'].' '.$_time;
448 489
490 + if(!empty($loginizer['ultimate-member-active']) && class_exists('UM')){
491 + \UM()->form()->add_error('blocked_msg', $lz_error['ip_blocked']);
492 + }
449 493 return false;
450 494 }
451 495 }
452 496
@@ -456,27 +500,36 @@
456 500 function loginizer_is_blacklisted(){
457 501
458 502 global $wpdb, $loginizer, $lz_error;
459 503
460 - $blacklist = $loginizer['blacklist'];
461 -
504 + $blacklist = isset($loginizer['blacklist']) ? $loginizer['blacklist'] : [];
505 +
506 + if(empty($blacklist)){
507 + return false;
508 + }
509 +
510 + $current_ip_inet = inet_ptoi($loginizer['current_ip']);
511 +
462 512 foreach($blacklist as $k => $v){
463 -
513 +
514 + $start_inet = inet_ptoi($v['start']);
515 + $end_inet = inet_ptoi($v['end']);
516 +
464 517 // Is the IP in the blacklist ?
465 - if(ip2long($v['start']) <= ip2long($loginizer['current_ip']) && ip2long($loginizer['current_ip']) <= ip2long($v['end'])){
518 + if($start_inet <= $current_ip_inet && $current_ip_inet <= $end_inet){
466 519 $result = 1;
467 520 break;
468 521 }
469 -
522 +
470 523 // Is it in a wider range ?
471 - if(ip2long($v['start']) >= 0 && ip2long($v['end']) < 0){
524 + if($start_inet >= 0 && $end_inet < 0){
472 525
473 - // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of ip2long,
526 + // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of inet_ptoi,
474 527 // if the current IP is <= than the start of the range, it is within the range
475 528 // OR
476 529 // if the current IP is <= than the end of the range, it is within the range
477 - if(ip2long($v['start']) <= ip2long($loginizer['current_ip'])
478 - || ip2long($loginizer['current_ip']) <= ip2long($v['end'])){
530 + if($start_inet <= $current_ip_inet
531 + || $current_ip_inet <= $end_inet){
479 532 $result = 1;
480 533 break;
481 534 }
482 535
@@ -482,12 +535,12 @@
482 535
483 536 }
484 537
485 538 }
486 -
539 +
487 540 // You are blacklisted
488 541 if(!empty($result)){
489 - $lz_error['ip_blacklisted'] = 'Your IP has been blacklisted';
542 + $lz_error['ip_blacklisted'] = $loginizer['msg']['ip_blacklisted'];
490 543 return true;
491 544 }
492 545
493 546 return false;
@@ -493,93 +546,224 @@
493 546 return false;
494 547
495 548 }
496 549
497 -function loginizer_is_whitelisted(){
550 +// When the login fails, then this is called
551 +// We need to update the database
552 +function loginizer_login_failed($username, $is_2fa = ''){
498 553
499 - global $wpdb, $loginizer, $lz_error;
554 + global $wpdb, $loginizer, $lz_cannot_login;
500 555
501 - $whitelist = $loginizer['whitelist'];
502 -
503 - foreach($whitelist as $k => $v){
556 + // Some plugins are changing the value for username as null so we need to handle it before using it for the INSERT OR UPDATE query
557 + if(empty($username) || is_null($username)){
558 + $username = '';
559 + }
560 +
561 + $fail_type = 'Login';
562 +
563 + if(!empty($is_2fa)){
564 + $fail_type = '2FA';
565 + }
566 +
567 + if(empty($lz_cannot_login) && empty($loginizer['ip_is_whitelisted']) && empty($loginizer['no_loginizer_logs'])){
504 568
505 - // Is the IP in the blacklist ?
506 - if(ip2long($v['start']) <= ip2long($loginizer['current_ip']) && ip2long($loginizer['current_ip']) <= ip2long($v['end'])){
507 - $result = 1;
508 - break;
569 + // The params which comes when social login returns an error, have some characters, which WordPress could not save.
570 + // REQUEST_URI / HTTP_HOST are not always set (WP-CLI, some CGI and XML-RPC setups)
571 + $server_uri = isset($_SERVER['REQUEST_URI']) ? $_SERVER['REQUEST_URI'] : '';
572 + $http_host = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '';
573 +
574 + if(!empty($server_uri) && strpos($server_uri, 'lz_social_provider') !== FALSE){
575 + $request_uri = explode('=', $server_uri);
576 + $server_uri = $request_uri[0];
509 577 }
578 +
579 + // No addslashes() here, $wpdb->prepare() below does the escaping
580 + $url = esc_url((!empty($_SERVER['HTTPS']) ? 'https://' : 'http://').$http_host.$server_uri);
510 581
511 - // Is it in a wider range ?
512 - if(ip2long($v['start']) >= 0 && ip2long($v['end']) < 0){
513 -
514 - // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of ip2long,
515 - // if the current IP is <= than the start of the range, it is within the range
516 - // OR
517 - // if the current IP is <= than the end of the range, it is within the range
518 - if(ip2long($v['start']) <= ip2long($loginizer['current_ip'])
519 - || ip2long($loginizer['current_ip']) <= ip2long($v['end'])){
520 - $result = 1;
521 - break;
582 + // Must never be 0, we divide by it below
583 + $max_retries = (int) $loginizer['max_retries'] < 1 ? 1 : (int) $loginizer['max_retries'];
584 +
585 + // This way is atomic now, the earlier one were causing race condition.
586 + // NOTE : In the UPDATE part `count` is already the new value, as MySQL / MariaDB
587 + // evaluate the assignments from left to right, so lockout must NOT add 1 again
588 + $upsert = $wpdb->prepare(
589 + "INSERT INTO `".$wpdb->prefix."loginizer_logs`
590 + (username, time, count, ip, lockout, url)
591 + VALUES
592 + (%s, %d, 1, %s, FLOOR(1 / %d), %s)
593 + ON DUPLICATE KEY UPDATE
594 + username = VALUES(username),
595 + time = VALUES(time),
596 + count = count + 1,
597 + lockout = FLOOR(count / %d),
598 + url = VALUES(url)",
599 + $username,
600 + time(),
601 + $loginizer['current_ip'],
602 + $max_retries,
603 + $url,
604 + $max_retries
605 + );
606 + $wpdb->query($upsert);
607 +
608 + // Re-read the persisted row so email/retries-left reflect the actual count
609 + $sel_query = $wpdb->prepare("SELECT * FROM `".$wpdb->prefix."loginizer_logs` WHERE `ip` = %s", $loginizer['current_ip']);
610 + $result = lz_selectquery($sel_query);
611 +
612 + if(empty($result)){
613 + $result = array('count' => 0);
614 + }
615 +
616 + $count = (int) $result['count'];
617 + $lockout = !empty($result['lockout']) ? (int) $result['lockout'] : 0;
618 +
619 + // The lockout goes up only on every max_retries'th failure, which is the
620 + // attempt that actually locks the IP out. On the failures in between there
621 + // is nothing new to report, so we must not email on each one of them
622 + $is_new_lockout = !empty($count) && ($count % $max_retries) == 0;
623 +
624 + // Do we need to email admin ?
625 + if(!empty($loginizer['notify_email']) && !empty($is_new_lockout) && $lockout >= $loginizer['notify_email']){
626 +
627 + $lockout_time = $loginizer['lockout_time'];
628 +
629 + if($lockout >= $loginizer['max_lockouts']){
630 + $lockout_time = $loginizer['lockouts_extend'];
522 631 }
523 -
632 +
633 + $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
634 + $mail = array();
635 + $mail['to'] = $loginizer['notify_email_address'];
636 + $mail['subject'] = 'Failed '.$fail_type.' Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
637 + $mail['message'] = 'Hi,
638 +
639 +'.(int) $result['count'].' failed '.strtolower($fail_type).' attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].' on your site :
640 +'.home_url().'
641 +
642 +Last '.$fail_type.' Attempt : '.date('d/M/Y H:i:s P', time()).'
643 +Last User Attempt : '.$username.'
644 +IP has been blocked until : '.date('d/M/Y H:i:s P', time() + $lockout_time).'
645 +
646 +Regards,
647 +Loginizer';
648 +
649 + @wp_mail($mail['to'], $mail['subject'], $mail['message']);
524 650 }
651 +
652 + loginizer_update_attempt_stats(0);
653 + $loginizer['retries_left'] = $max_retries - ($count % $max_retries);
654 + $loginizer['retries_left'] = $loginizer['retries_left'] == $max_retries ? 0 : $loginizer['retries_left'];
525 655
526 656 }
527 -
528 - // You are whitelisted
529 - if(!empty($result)){
530 - return true;
531 - }
532 -
533 - return false;
534 -
535 657 }
536 658
659 +function loginizer_rsssl_2fa_success($user){
660 + loginizer_login_success('', $user);
661 +}
537 662
538 -// When the login fails, then this is called
539 -// We need to update the database
540 -function loginizer_login_failed($username){
663 +function loginizer_login_success($user_login, $user) {
664 + global $wp_version, $loginizer;
665 +
666 + loginizer_update_attempt_stats(1);
541 667
542 - global $wpdb, $loginizer, $lz_cannot_login;
668 + if(empty($loginizer['login_mail'])){
669 + return;
670 + }
543 671
544 - if(empty($lz_cannot_login) && empty($loginizer['ip_is_whitelisted']) && empty($loginizer['no_loginizer_logs'])){
545 -
546 - $result = lz_selectquery("SELECT * FROM `".$wpdb->prefix."loginizer_logs` WHERE `ip` = '".$loginizer['current_ip']."';");
547 -
548 - if(!empty($result)){
549 - $lockout = floor((($result['count']+1) / $loginizer['max_retries']));
550 - $sresult = $wpdb->query("UPDATE `".$wpdb->prefix."loginizer_logs` SET `username` = '".$username."', `time` = '".time()."', `count` = `count`+1, `lockout` = '".$lockout."' WHERE `ip` = '".$loginizer['current_ip']."';");
551 -
552 - // Do we need to email admin ?
553 - if(!empty($loginizer['notify_email']) && $lockout >= $loginizer['notify_email']){
554 -
555 - $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
556 - $mail = array();
557 - $mail['to'] = lz_is_multisite() ? get_site_option('admin_email') : get_option('admin_email');
558 - $mail['subject'] = 'Failed Login Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
559 - $mail['message'] = 'Hi,
672 + if(empty($loginizer['login_mail']['enable'])){
673 + return;
674 + }
560 675
561 -'.($result['count']+1).' failed login attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].'
676 + if(!empty($loginizer['login_mail']['disable_whitelist'])){
677 + // Check its whitelist ip
678 + if(loginizer_is_whitelisted()){
679 + return;
680 + }
681 + }
562 682
563 -Last Login Attempt : '.date('d/m/Y H:i:s', time()).'
564 -Last User Attempt : '.$username.'
565 -IP has been blocked until : '.date('d/m/Y H:i:s', time() + $loginizer['lockout_time']).'
683 + if(empty($user_login) && empty($user)){
684 + error_log('Loginizer: No user information to send email');
685 + return;
686 + }
566 687
567 -Regards,
568 -Loginizer';
688 + if(empty($user)){
689 + $user = get_user_by('login', $user_login);
690 + }
569 691
570 - @wp_mail($mail['to'], $mail['subject'], $mail['message']);
571 - }
692 + if(empty($user)){
693 + error_log('Loginizer: Unable to get the user');
694 + return;
695 + }
696 +
697 + if(empty($loginizer['login_mail']['roles']) || !is_array($loginizer['login_mail']['roles'])){
698 + return;
699 + }
700 +
701 + // Check if the user role is enabled for email notification.
702 + if(!array_intersect($user->roles, $loginizer['login_mail']['roles'])){
703 + return;
704 + }
705 +
706 + // current_datetime & wp_timezone_string were introduced in WordPress 5.3
707 + if(!empty($wp_version) && version_compare($wp_version, '5.3', '>') && function_exists('current_datetime')){
708 + $time_zone = wp_timezone_string();
709 +
710 + if(!empty($time_zone) && isset($time_zone[1]) && is_numeric($time_zone[1])){
711 + $time_zone = 'UTC'.$time_zone;
712 + }
713 +
714 + // Setting up data variables.
715 + $date = current_datetime()->format('Y-m-d H:i:s') .' '. $time_zone;
716 + } else {
717 + $date = date("Y-m-d H:i:s", time()) . ' ' . date_default_timezone_get();
718 + }
719 +
720 + $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
721 + $email = $user->data->user_email;
722 +
723 + $vars = array(
724 + 'date' => $date,
725 + 'ip' => esc_html($loginizer['current_ip']),
726 + 'sitename' => $sitename,
727 + 'user_login' => $user_login
728 + );
729 +
730 + $message = lz_lang_vars_name($loginizer['login_mail_body'], $vars);
731 + $subject = lz_lang_vars_name($loginizer['login_mail_subject'], $vars);
732 +
733 + $headers = [];
734 +
735 + // Do we need to send the email as HTML ?
736 + if(!empty($loginizer['login_mail']['html_mail'])){
737 + $headers[] = 'Content-Type: text/html; charset=UTF-8';
738 +
739 + if(!empty($loginizer['login_mail']['body'])){
740 + $message = html_entity_decode($message);
572 741 }else{
573 - $insert = $wpdb->query("INSERT INTO `".$wpdb->prefix."loginizer_logs` SET `username` = '".$username."', `time` = '".time()."', `count` = '1', `ip` = '".$loginizer['current_ip']."', `lockout` = '0';");
742 + $message = preg_replace("/\<br\s*\/\>/i", "<br/>", $message);
743 + $message = preg_replace('/(?<!<br\/>)\n/i', "<br/>\n", $message);
574 744 }
745 + }
746 +
747 + // Sending notification
748 + if(empty(wp_mail($email, $subject, $message, $headers))){
749 + error_log(__('There was a problem sending your email.', 'loginizer'));
750 + return;
751 + }
752 +}
753 +
754 +function loginizer_update_attempt_stats($type){
755 +
756 + $stats = get_option('loginizer_login_attempt_stats', []);
757 + $time = strtotime(date('Y-m-d H:00:00'));
575 758
576 - // We need to add one as this is a failed attempt as well
577 - $result['count'] = $result['count'] + 1;
578 - $loginizer['retries_left'] = ($loginizer['max_retries'] - ($result['count'] % $loginizer['max_retries']));
579 - $loginizer['retries_left'] = $loginizer['retries_left'] == $loginizer['max_retries'] ? 0 : $loginizer['retries_left'];
580 -
759 + if(empty($stats[$time][$type])){
760 + $stats[$time][$type] = 0;
581 761 }
762 +
763 + $stats[$time][$type] += 1;
764 +
765 + update_option('loginizer_login_attempt_stats', $stats, false);
582 766 }
583 767
584 768 // Handles the error of the password not being there
585 769 function loginizer_error_handler($errors, $redirect_to){
@@ -584,11 +768,14 @@
584 768 // Handles the error of the password not being there
585 769 function loginizer_error_handler($errors, $redirect_to){
586 770
587 771 global $wpdb, $loginizer, $lz_user_pass, $lz_cannot_login;
588 -
772 +
589 773 //echo 'loginizer_error_handler :';print_r($errors->errors);echo '<br>';
590 -
774 + if(is_null($errors) || empty($errors)){
775 + return true;
776 + }
777 +
591 778 // Remove the empty password error
592 779 if(is_wp_error($errors)){
593 780
594 781 $codes = $errors->get_error_codes();
@@ -600,1178 +787,201 @@
600 787 }
601 788
602 789 $errors->remove('invalid_username');
603 790 $errors->remove('incorrect_password');
791 +
792 + // Add the error
793 + if(!empty($lz_user_pass) && !empty($show_error) && empty($lz_cannot_login)){
794 + $errors->add('invalid_userpass', '<b>ERROR:</b> ' . $loginizer['msg']['inv_userpass']);
795 + }
604 796
797 + // Add the number of retires left as well
798 + if(count($errors->get_error_codes()) > 0 && isset($loginizer['retries_left'])){
799 + $errors->add('retries_left', loginizer_retries_left());
800 + }
801 +
605 802 }
606 803
607 - // Add the error
608 - if(!empty($lz_user_pass) && !empty($show_error) && empty($lz_cannot_login)){
609 - $errors->add('invalid_userpass', '<b>ERROR:</b> Incorrect Username or Password');
610 - }
611 -
612 - // Add the number of retires left as well
613 - if(count($errors->get_error_codes()) > 0 && isset($loginizer['retries_left'])){
614 - $errors->add('retries_left', loginizer_retries_left());
615 - }
616 -
617 804 return $errors;
618 805
619 806 }
620 807
621 -// Returns a string with the number of retries left
622 -function loginizer_retries_left(){
623 -
808 +// Handles the error of the password not being there
809 +function loginizer_woocommerce_error_handler(){
810 +
624 811 global $wpdb, $loginizer, $lz_user_pass, $lz_cannot_login;
625 812
626 - // If we are to show the number of retries left
627 - if(isset($loginizer['retries_left'])){
628 - return '<b>'.$loginizer['retries_left'].'</b> attempt(s) left';
813 + if(function_exists('wc_add_notice')){
814 + wc_add_notice( loginizer_retries_left(), 'error' );
629 815 }
630 -
631 816 }
632 817
633 -function loginizer_reset_retries(){
818 +function loginizer_ultimatemember_error_handler(){
634 819
635 - global $wpdb, $loginizer;
636 -
637 - $deltime = time() - $loginizer['reset_retries'];
638 - $result = $wpdb->query("DELETE FROM `".$wpdb->prefix."loginizer_logs` WHERE `time` <= '".$deltime."';");
639 -
640 - update_option('loginizer_last_reset', time());
641 -
820 + if(class_exists('UM')){
821 + \UM()->form()->add_error('remaining_tries', loginizer_retries_left());
822 + }
642 823 }
643 824
644 -add_filter("plugin_action_links_$plugin_loginizer", 'loginizer_plugin_action_links');
645 -
646 -// Add settings link on plugin page
647 -function loginizer_plugin_action_links($links) {
825 +// Handles social login URL
826 +function loginizer_social_login_error_handler($errors = '', $redirect_to = ''){
827 + global $loginizer;
648 828
649 - if(!defined('LOGINIZER_PREMIUM')){
650 - $links[] = '<a href="'.LOGINIZER_PRO_URL.'" style="color:#3db634;" target="_blank">'._x('Upgrade', 'Plugin action link label.', 'loginizer').'</a>';
829 + if(loginizer_is_blacklisted()){
830 + return $errors;
651 831 }
652 832
653 - $settings_link = '<a href="admin.php?page=loginizer">Settings</a>';
654 - array_unshift($links, $settings_link);
655 -
656 - return $links;
657 -}
833 + loginizer_get_social_error();
658 834
659 -add_action('admin_menu', 'loginizer_admin_menu');
835 + if(empty($loginizer['social_errors'])){
836 + return $errors;
837 + }
660 838
661 -// Shows the admin menu of Loginizer
662 -function loginizer_admin_menu() {
663 -
664 - global $wp_version, $loginizer;
665 -
666 - // Add the menu page
667 - add_menu_page(__('Loginizer Dashboard'), __('Loginizer Security'), 'activate_plugins', 'loginizer', 'loginizer_page_dashboard');
668 -
669 - // Dashboard
670 - add_submenu_page('loginizer', __('Loginizer Dashboard'), __('Dashboard'), 'activate_plugins', 'loginizer', 'loginizer_page_dashboard');
671 -
672 - // Brute Force
673 - add_submenu_page('loginizer', __('Loginizer Brute Force Settings'), __('Brute Force'), 'activate_plugins', 'loginizer_brute_force', 'loginizer_page_brute_force');
674 -
675 - if(defined('LOGINIZER_PREMIUM')){
676 -
677 - // PasswordLess
678 - add_submenu_page('loginizer', __('Loginizer PasswordLess Settings'), __('PasswordLess'), 'activate_plugins', 'loginizer_passwordless', 'loginizer_page_passwordless');
679 -
680 - // Two Factor Auth
681 - add_submenu_page('loginizer', __('Loginizer Two Factor Authentication'), __('Two Factor Auth'), 'activate_plugins', 'loginizer_2fa', 'loginizer_page_2fa');
682 -
683 - // reCaptcha
684 - add_submenu_page('loginizer', __('Loginizer reCAPTCHA Settings'), __('reCAPTCHA'), 'activate_plugins', 'loginizer_recaptcha', 'loginizer_page_recaptcha');
685 -
686 - // Security Settings
687 - add_submenu_page('loginizer', __('Loginizer Security Settings'), __('Security Settings'), 'activate_plugins', 'loginizer_security', 'loginizer_page_security');
688 -
689 - // Security Settings
690 - add_submenu_page('loginizer', __('Loginizer File Checksums'), __('File Checksums'), 'activate_plugins', 'loginizer_checksums', 'loginizer_page_checksums');
691 -
692 - }elseif(!defined('LOGINIZER_PREMIUM') && !empty($loginizer['ins_time']) && $loginizer['ins_time'] < (time() - (30*24*3600))){
693 -
694 - // Go Pro link
695 - add_submenu_page('loginizer', __('Loginizer Go Pro'), __('Go Pro'), 'activate_plugins', LOGINIZER_PRO_URL);
696 -
839 + if(is_null($errors) || empty($errors) || !is_wp_error($errors)){
840 + $errors = new WP_Error();
697 841 }
698 -
699 -}
700 842
701 -// The Loginizer Admin Options Page
702 -function loginizer_page_header($title = 'Loginizer'){
703 - /*wp_enqueue_script('common');
704 - wp_enqueue_script('wp-lists');
705 - wp_enqueue_script('postbox');
706 - wp_nonce_field('closedpostboxes', 'closedpostboxesnonce', false);
707 -
708 - echo '
709 -<script>
710 -jQuery(document).ready( function() {
711 - //add_postbox_toggles("loginizer");
712 -});
713 -</script>';*/
843 + foreach($loginizer['social_errors'] as $key => $text){
844 + $errors->add($key, $text);
845 + }
714 846
715 -?>
716 -<style>
717 -.lz-right-ul{
718 - padding-left: 10px !important;
847 + return $errors;
719 848 }
720 849
721 -.lz-right-ul li{
722 - list-style: circle !important;
723 -}
724 -</style>
725 -<?php
850 +// Returns a string with the number of retries left
851 +function loginizer_retries_left(){
726 852
727 - echo '<div style="margin: 10px 20px 0 2px;">
728 -<div class="metabox-holder columns-2">
729 -<div class="postbox-container">
730 -<div id="top-sortables" class="meta-box-sortables ui-sortable">
853 + global $wpdb, $loginizer, $lz_user_pass, $lz_cannot_login;
731 854
732 - <table cellpadding="2" cellspacing="1" width="100%" class="fixed" border="0">
733 - <tr>
734 - <td valign="top"><h3>'.$title.'</h3></td>
735 - <td align="right"><a target="_blank" class="button button-primary" href="https://wordpress.org/support/view/plugin-reviews/loginizer">Review Loginizer</a></td>
736 - <td align="right" width="40"><a target="_blank" href="https://twitter.com/loginizer"><img src="'.LOGINIZER_URL.'/twitter.png" /></a></td>
737 - <td align="right" width="40"><a target="_blank" href="https://www.facebook.com/Loginizer-815504798591884"><img src="'.LOGINIZER_URL.'/facebook.png" /></a></td>
738 - </tr>
739 - </table>
740 - <hr />
741 -
742 - <!--Main Table-->
743 - <table cellpadding="8" cellspacing="1" width="100%" class="fixed">
744 - <tr>
745 - <td valign="top">';
746 -
747 -}
748 -
749 -// The Loginizer Theme footer
750 -function loginizer_page_footer(){
751 -
752 - echo '</td>
753 - <td width="200" valign="top" id="loginizer-right-bar">';
754 -
755 - if(!defined('LOGINIZER_PREMIUM')){
855 + // If we are to show the number of retries left
856 + if(isset($loginizer['retries_left'])){
857 + $retries_left = apply_filters('loginizer_retries_left_num', $loginizer['retries_left']);
756 858
757 - echo '
758 - <div class="postbox" style="min-width:0px !important;">
759 - <h2 class="hndle ui-sortable-handle">
760 - <span>Premium Version</span>
761 - </h2>
762 - <div class="inside">
763 - <i>Upgrade to the premium version and get the following features </i>:<br>
764 - <ul class="lz-right-ul">
765 - <li>PasswordLess Login</li>
766 - <li>Two Factor Auth - Email</li>
767 - <li>Two Factor Auth - App</li>
768 - <li>Login Challenge Question</li>
769 - <li>reCAPTCHA</li>
770 - <li>Rename Login Page</li>
771 - <li>Disable XML-RPC</li>
772 - <li>And many more ...</li>
773 - </ul>
774 - <center><a class="button button-primary" href="https://loginizer.com/members/cart.php">Upgrade</a></center>
775 - </div>
776 - </div>';
777 -
778 - }else{
779 -
780 - echo '
781 - <div class="postbox" style="min-width:0px !important;">
782 - <h2 class="hndle ui-sortable-handle">
783 - <span>Recommendations</span>
784 - </h2>
785 - <div class="inside">
786 - <i>We recommed that you enable atleast one of the following security features</i>:<br>
787 - <ul class="lz-right-ul">
788 - <li>Rename Login Page</li>
789 - <li>Login Challenge Question</li>
790 - <li>reCAPTCHA</li>
791 - <li>Two Factor Auth - Email</li>
792 - <li>Two Factor Auth - App</li>
793 - <li>Change \'admin\' Username</li>
794 - </ul>
795 - </div>
796 - </div>';
859 + return '<b>'.esc_html($retries_left).'</b> '.$loginizer['msg']['attempts_left'];
797 860 }
798 861
799 - echo '</td>
800 - </tr>
801 - </table>
802 - <br />
803 - <div style="width:45%;background:#FFF;padding:15px; margin:auto">
804 - <b>Let your friends know that you have secured your website :</b>
805 - <form method="get" action="http://twitter.com/intent/tweet" id="tweet" onsubmit="return dotweet(this);">
806 - <textarea name="text" cols="45" row="3" style="resize:none;">I just secured my @WordPress site against #bruteforce using @loginizer</textarea>
807 - &nbsp; &nbsp; <input type="submit" value="Tweet!" class="button button-primary" onsubmit="return false;" id="twitter-btn" style="margin-top:20px;"/>
808 - </form>
809 -
810 - </div>
811 - <br />
812 -
813 - <script>
814 - function dotweet(ele){
815 - window.open(jQuery("#"+ele.id).attr("action")+"?"+jQuery("#"+ele.id).serialize(), "_blank", "scrollbars=no, menubar=no, height=400, width=500, resizable=yes, toolbar=no, status=no");
816 - return false;
817 - }
818 - </script>
819 -
820 - <hr />
821 - <a href="http://loginizer.com" target="_blank">Loginizer</a> v'.LOGINIZER_VERSION.'. You can report any bugs <a href="http://wordpress.org/support/plugin/loginizer" target="_blank">here</a>.
862 +}
822 863
823 -</div>
824 -</div>
825 -</div>
826 -</div>';
864 +function loginizer_reset_retries(){
827 865
828 -}
866 + global $wpdb, $loginizer;
829 867
830 -// The Loginizer Admin Options Page
831 -function loginizer_page_dashboard(){
832 -
833 - global $loginizer, $lz_error, $lz_env;
868 + $deltime = time() - $loginizer['reset_retries'];
834 869
835 - // Is there a license key ?
836 - if(isset($_POST['save_lz'])){
837 -
838 - $license = lz_optpost('lz_license');
839 -
840 - // Check if its a valid license
841 - if(empty($license)){
842 - $lz_error['lic_invalid'] = __('The license key was not submitted', 'loginizer');
843 - return loginizer_page_dashboard_T();
844 - }
845 -
846 - $resp = wp_remote_get(LOGINIZER_API.'license.php?license='.$license);
847 -
848 - if(is_array($resp)){
849 - $json = json_decode($resp['body'], true);
850 - //print_r($json);
851 - }
852 -
853 - // Save the License
854 - if(empty($json)){
855 -
856 - $lz_error['lic_invalid'] = __('The license key is invalid', 'loginizer');
857 - return loginizer_page_dashboard_T();
858 -
859 - }else{
860 -
861 - update_option('loginizer_license', $json);
862 -
863 - // Mark as saved
864 - $GLOBALS['lz_saved'] = true;
865 - }
866 -
867 - }
868 -
869 -
870 - // Is there a IP Method ?
871 - if(isset($_POST['save_lz_ip_method'])){
872 -
873 - $ip_method = (int) lz_optpost('lz_ip_method');
874 -
875 - if($ip_method >= 0 && $ip_method <= 2){
876 - update_option('loginizer_ip_method', $ip_method);
877 - }
878 -
879 - }
880 -
881 - loginizer_page_dashboard_T();
882 -
883 -}
870 + $del_query = $wpdb->prepare("DELETE FROM `".$wpdb->prefix."loginizer_logs` WHERE `time` <= %d", $deltime);
871 + $result = $wpdb->query($del_query);
884 872
885 -// The Loginizer Admin Options Page - THEME
886 -function loginizer_page_dashboard_T(){
887 -
888 - global $loginizer, $lz_error, $lz_env;
873 + update_option('loginizer_last_reset', time());
889 874
890 - loginizer_page_header('Loginizer Dashboard');
891 -?>
892 -<style>
893 -.welcome-panel{
894 - margin: 0px;
895 - padding: 10px;
896 875 }
897 876
898 -input[type="text"], textarea, select {
899 - width: 70%;
900 -}
877 +function loginizer_load_translation_vars(){
878 + global $loginizer;
879 +
880 + $loginizer['login_mail_default_sub'] = __('Login Successful at $sitename', 'loginizer');
881 + $loginizer['login_mail_default_msg'] = __('Hello $user_login,
901 882
902 -.form-table label{
903 - font-weight:bold;
904 -}
883 +Your account was recently logged in from the IP : $ip
884 +Time : $date
885 +If it was not you who logged in then please report this to us immediately.
905 886
906 -.exp{
907 - font-size:12px;
908 -}
909 -</style>
910 -
911 - <?php
912 - echo '<script src="https://api.loginizer.com/'.(defined('LOGINIZER_PREMIUM') ? 'news_security.js' : 'news.js').'"></script><br>';
887 +Regards,
888 +$sitename','loginizer');
913 889
914 - // Saved ?
915 - if(!empty($GLOBALS['lz_saved'])){
916 - echo '<div id="message" class="updated"><p>'. __('The settings were saved successfully', 'loginizer'). '</p></div><br />';
890 + if(empty($loginizer['login_mail_subject'])){
891 + $loginizer['login_mail_subject'] = $loginizer['login_mail_default_sub'];
917 892 }
918 893
919 - // Any errors ?
920 - if(!empty($lz_error)){
921 - lz_report_error($lz_error);echo '<br />';
894 + if(empty($loginizer['login_mail_body'])){
895 + $loginizer['login_mail_body'] = $loginizer['login_mail_default_msg'];
922 896 }
923 897
924 - ?>
898 + // Default messages
899 + $loginizer['d_msg']['inv_userpass'] = __('Incorrect Username or Password', 'loginizer');
900 + $loginizer['d_msg']['ip_blacklisted'] = __('Your IP has been blacklisted', 'loginizer');
901 + $loginizer['d_msg']['attempts_left'] = __('attempt(s) left', 'loginizer');
902 + $loginizer['d_msg']['lockout_err'] = __('You have exceeded maximum login retries<br /> Please try after', 'loginizer');
903 + $loginizer['d_msg']['minutes_err'] = __('minute(s)', 'loginizer');
904 + $loginizer['d_msg']['hours_err'] = __('hour(s)', 'loginizer');
925 905
926 - <div class="postbox">
906 + // Message Strings
907 + $loginizer['msg'] = get_option('loginizer_msg', []);
927 908
928 - <button class="handlediv button-link" aria-expanded="true" type="button">
929 - <span class="screen-reader-text">Toggle panel: Getting Started</span>
930 - <span class="toggle-indicator" aria-hidden="true"></span>
931 - </button>
932 -
933 - <h2 class="hndle ui-sortable-handle">
934 - <span><?php echo __('Getting Started', 'loginizer'); ?></span>
935 - </h2>
936 -
937 - <div class="inside">
938 -
939 - <form action="" method="post" enctype="multipart/form-data">
940 - <?php wp_nonce_field('loginizer-options'); ?>
941 - <table class="form-table">
942 - <tr>
943 - <td scope="row" valign="top" colspan="2" style="line-height:150%">
944 - <i>Welcome to Loginizer Security. By default the <b>Brute Force Protection</b> is immediately enabled. You should start by going over the default settings and tweaking them as per your needs.</i>
945 - <?php
946 - if(defined('LOGINIZER_PREMIUM')){
947 - echo '<br><i>In the Premium version of Loginizer you have many more features. We recommend you enable features like <b>reCAPTCHA, Two Factor Auth or Email based PasswordLess</b> login. These features will improve your websites security.</i>';
948 - }
949 - ?>
950 - </td>
951 - </tr>
952 - </table>
953 - </form>
954 -
955 - </div>
956 - </div>
909 + foreach($loginizer['d_msg'] as $lk => $lv){
910 + if(empty($loginizer['msg'][$lk])){
911 + $loginizer['msg'][$lk] = $loginizer['d_msg'][$lk];
912 + }
913 + }
957 914
958 - <div class="postbox">
915 + $loginizer['2fa_d_msg']['otp_app'] = __('Please enter the OTP as seen in your App', 'loginizer');
916 + $loginizer['2fa_d_msg']['otp_email'] = __('Please enter the OTP emailed to you', 'loginizer');
917 + $loginizer['2fa_d_msg']['otp_field'] = __('One Time Password', 'loginizer');
918 + $loginizer['2fa_d_msg']['otp_question'] = __('Please answer your security question', 'loginizer');
919 + $loginizer['2fa_d_msg']['otp_answer'] = __('Your Answer', 'loginizer');
959 920
960 - <button class="handlediv button-link" aria-expanded="true" type="button">
961 - <span class="screen-reader-text">Toggle panel: System Information</span>
962 - <span class="toggle-indicator" aria-hidden="true"></span>
963 - </button>
964 -
965 - <h2 class="hndle ui-sortable-handle">
966 - <span><?php echo __('System Information', 'loginizer'); ?></span>
967 - </h2>
968 -
969 - <div class="inside">
970 -
971 - <form action="" method="post" enctype="multipart/form-data">
972 - <?php wp_nonce_field('loginizer-options'); ?>
973 - <table class="wp-list-table fixed striped users" cellspacing="1" border="0" width="95%" cellpadding="10" align="center">
974 - <?php
975 - echo '
976 - <tr>
977 - <th align="left" width="25%">'.__('Loginizer Version', 'loginizer').'</th>
978 - <td>'.LOGINIZER_VERSION.(defined('LOGINIZER_PREMIUM') ? ' (Security PRO Version)' : '').'</td>
979 - </tr>';
980 -
981 - if(defined('LOGINIZER_PREMIUM')){
982 - echo '
983 - <tr>
984 - <th align="left" valign="top">'.__('Loginizer License', 'loginizer').'</th>
985 - <td align="left">
986 - '.(empty($loginizer['license']) ? '<span style="color:red">Unlicensed</span> &nbsp; &nbsp;' : '').'
987 - <input type="text" name="lz_license" value="'.(empty($loginizer['license']) ? '' : $loginizer['license']['license']).'" size="30" placeholder="e.g. WXCSE-SFJJX-XXXXX-AAAAA-BBBBB" style="width:300px;" /> &nbsp;
988 - <input name="save_lz" class="button button-primary" value="Update License" type="submit" />';
989 -
990 - if(!empty($loginizer['license'])){
991 -
992 - $expires = $loginizer['license']['expires'];
993 - $expires = substr($expires, 0, 4).'/'.substr($expires, 4, 2).'/'.substr($expires, 6);
994 -
995 - echo '<div style="margin-top:10px;">License Active : '.(empty($loginizer['license']['active']) ? '<span style="color:red">No</span>' : 'Yes').' &nbsp; &nbsp; &nbsp;
996 - License Expires : '.($loginizer['license']['expires'] <= date('Ymd') ? '<span style="color:red">'.$expires.'</span>' : $expires).'
997 - </div>';
998 - }
999 -
1000 -
1001 - echo
1002 - '</td>
1003 - </tr>';
1004 - }
1005 -
1006 - echo '<tr>
1007 - <th align="left">'.__('URL', 'loginizer').'</th>
1008 - <td>'.get_site_url().'</td>
1009 - </tr>
1010 - <tr>
1011 - <th align="left">'.__('Path', 'loginizer').'</th>
1012 - <td>'.ABSPATH.'</td>
1013 - </tr>
1014 - <tr>
1015 - <th align="left">'.__('Server\'s IP Address', 'loginizer').'</th>
1016 - <td>'.$_SERVER['SERVER_ADDR'].'</td>
1017 - </tr>
1018 - <tr>
1019 - <th align="left">'.__('Your IP Address', 'loginizer').'</th>
1020 - <td>'.lz_getip().'
1021 - <div style="float:right">
1022 - Method :
1023 - <select name="lz_ip_method" style="font-size:11px; width:150px">
1024 - <option value="0" '.lz_POSTselect('lz_ip_method', 0, (@$loginizer['ip_method'] == 0)).'>REMOTE_ADDR</option>
1025 - <option value="1" '.lz_POSTselect('lz_ip_method', 1, (@$loginizer['ip_method'] == 1)).'>HTTP_X_FORWARDED_FOR</option>
1026 - <option value="2" '.lz_POSTselect('lz_ip_method', 2, (@$loginizer['ip_method'] == 2)).'>HTTP_CLIENT_IP</option>
1027 - </select>
1028 - <input name="save_lz_ip_method" class="button button-primary" value="Save" type="submit" />
1029 - </div>
1030 - </td>
1031 - </tr>
1032 - <tr>
1033 - <th align="left">'.__('wp-config.php is writable', 'loginizer').'</th>
1034 - <td>'.(is_writable(ABSPATH.'/wp-config.php') ? '<span style="color:red">Yes</span>' : '<span style="color:green">No</span>').'</td>
1035 - </tr>';
1036 -
1037 - if(file_exists(ABSPATH.'/.htaccess')){
1038 - echo '
1039 - <tr>
1040 - <th align="left">'.__('.htaccess is writable', 'loginizer').'</th>
1041 - <td>'.(is_writable(ABSPATH.'/.htaccess') ? '<span style="color:red">Yes</span>' : '<span style="color:green">No</span>').'</td>
1042 - </tr>';
1043 -
1044 - }
1045 -
1046 - ?>
1047 - </table>
1048 - </form>
1049 -
1050 - </div>
1051 - </div>
921 + // Message Strings
922 + $loginizer['2fa_msg'] = get_option('loginizer_2fa_msg', []);
1052 923
1053 - <div id="" class="postbox">
924 + foreach($loginizer['2fa_d_msg'] as $lk => $lv){
925 + if(empty($loginizer['2fa_msg'][$lk])){
926 + $loginizer['2fa_msg'][$lk] = $loginizer['2fa_d_msg'][$lk];
927 + }
928 + }
1054 929
1055 - <button class="handlediv button-link" aria-expanded="true" type="button">
1056 - <span class="screen-reader-text">Toggle panel: File Permissions</span>
1057 - <span class="toggle-indicator" aria-hidden="true"></span>
1058 - </button>
1059 -
1060 - <h2 class="hndle ui-sortable-handle">
1061 - <span><?php echo __('File Permissions', 'loginizer'); ?></span>
1062 - </h2>
1063 -
1064 - <div class="inside">
1065 -
1066 - <form action="" method="post" enctype="multipart/form-data">
1067 - <?php wp_nonce_field('loginizer-options'); ?>
1068 - <table class="wp-list-table fixed striped users" border="0" width="95%" cellpadding="10" align="center">
1069 - <?php
1070 -
1071 - echo '
1072 - <tr>
1073 - <th style="background:#EFEFEF;">'.__('Relative Path', 'loginizer').'</th>
1074 - <th style="width:10%; background:#EFEFEF;">'.__('Suggested', 'loginizer').'</th>
1075 - <th style="width:10%; background:#EFEFEF;">'.__('Actual', 'loginizer').'</th>
1076 - </tr>';
1077 -
1078 - $wp_content = basename(dirname(dirname(dirname(__FILE__))));
1079 -
1080 - $files_to_check = array('/' => '0755',
1081 - '/wp-admin' => '0755',
1082 - '/wp-includes' => '0755',
1083 - '/wp-config.php' => '0444',
1084 - '/'.$wp_content => '0755',
1085 - '/'.$wp_content.'/themes' => '0755',
1086 - '/'.$wp_content.'/plugins' => '0755',
1087 - '.htaccess' => '0444');
1088 -
1089 - $root = ABSPATH;
1090 -
1091 - foreach($files_to_check as $k => $v){
1092 -
1093 - $path = $root.'/'.$k;
1094 - $stat = @stat($path);
1095 - $suggested = $v;
1096 - $actual = substr(sprintf('%o', $stat['mode']), -4);
1097 -
1098 - echo '
1099 - <tr>
1100 - <td>'.$k.'</td>
1101 - <td>'.$suggested.'</td>
1102 - <td><span '.($suggested != $actual ? 'style="color: red;"' : '').'>'.$actual.'</span></td>
1103 - </tr>';
1104 -
1105 - }
1106 -
1107 - ?>
1108 - </table>
1109 - </form>
1110 -
1111 - </div>
1112 - </div>
930 +}
1113 931
1114 -<?php
1115 -
1116 - loginizer_page_footer();
1117 -
932 +function loginizer_social_login_load(){
933 + include_once LOGINIZER_DIR . '/main/social-login.php';
1118 934 }
1119 935
1120 -// The Loginizer Admin Options Page
1121 -function loginizer_page_brute_force(){
936 +// Checks if softaculous is installed on the server.
937 +function loginizer_check_softaculous(){
1122 938
1123 - global $wpdb, $wp_roles, $loginizer;
1124 -
1125 - if(!current_user_can('manage_options')){
1126 - wp_die('Sorry, but you do not have permissions to change settings.');
939 + // Checking if we have Softaculous installed?
940 + if(!preg_match('/^\/home(?:\d+)?\/.*\//U', ABSPATH, $matches)){
941 + return false;
1127 942 }
1128 943
1129 - /* Make sure post was from this page */
1130 - if(count($_POST) > 0){
1131 - check_admin_referer('loginizer-options');
944 + if(empty($matches) || empty($matches[0])){
945 + return false;
1132 946 }
1133 -
1134 - // BEGIN THEME
1135 - loginizer_page_header('Loginizer - Brute Force Settings');
1136 -
1137 - // Load the blacklist and whitelist
1138 - $loginizer['blacklist'] = get_option('loginizer_blacklist');
1139 - $loginizer['whitelist'] = get_option('loginizer_whitelist');
1140 -
1141 - if(isset($_POST['save_lz'])){
1142 -
1143 - $max_retries = (int) lz_optpost('max_retries');
1144 - $lockout_time = (int) lz_optpost('lockout_time');
1145 - $max_lockouts = (int) lz_optpost('max_lockouts');
1146 - $lockouts_extend = (int) lz_optpost('lockouts_extend');
1147 - $reset_retries = (int) lz_optpost('reset_retries');
1148 - $notify_email = (int) lz_optpost('notify_email');
1149 -
1150 - $lockout_time = $lockout_time * 60;
1151 - $lockouts_extend = $lockouts_extend * 60 * 60;
1152 - $reset_retries = $reset_retries * 60 * 60;
1153 -
1154 - if(empty($error)){
1155 -
1156 - $option['max_retries'] = $max_retries;
1157 - $option['lockout_time'] = $lockout_time;
1158 - $option['max_lockouts'] = $max_lockouts;
1159 - $option['lockouts_extend'] = $lockouts_extend;
1160 - $option['reset_retries'] = $reset_retries;
1161 - $option['notify_email'] = $notify_email;
1162 -
1163 - // Save the options
1164 - update_option('loginizer_options', $option);
1165 -
1166 - $saved = true;
1167 -
1168 - }else{
1169 - lz_report_error($error);
1170 - }
1171 -
1172 - if(!empty($notice)){
1173 - lz_report_notice($notice);
1174 - }
1175 -
1176 - if(!empty($saved)){
1177 - echo '<div id="message" class="updated"><p>'
1178 - . __('The settings were saved successfully', 'loginizer')
1179 - . '</p></div><br />';
1180 - }
1181 -
947 +
948 + $softaculous_path = $matches[0] . '.softaculous/installations.php';
949 + if(!file_exists($softaculous_path)){
950 + return false;
1182 951 }
1183 952
1184 - // Delete a Blackist IP range
1185 - if(isset($_GET['bdelid'])){
1186 -
1187 - $delid = (int) lz_optreq('bdelid');
1188 -
1189 - // Unset and save
1190 - $blacklist = $loginizer['blacklist'];
1191 - unset($blacklist[$delid]);
1192 - update_option('loginizer_blacklist', $blacklist);
1193 -
1194 - echo '<div id="message" class="updated fade"><p>'
1195 - . __('The Blacklist IP range has been deleted successfully', 'loginizer')
1196 - . '</p></div><br />';
1197 -
953 + // Checking if users has changed the branding of Softaculous.
954 + $universal_file = '';
955 + // Plesk, ISPManager, ISPConfig, InterWorx, H-Sphere, CentOS Web Panel, Softaculous Remote and Softaculous Enterprise
956 + if(file_exists('/usr/local/softaculous/enduser/universal.php')){
957 + $universal_file = '/usr/local/softaculous/enduser/universal.php';
958 + }else if(file_exists('/usr/local/cpanel/whostmgr/docroot/cgi/softaculous/enduser/universal.php')){
959 + $universal_file = '/usr/local/cpanel/whostmgr/docroot/cgi/softaculous/enduser/universal.php';
960 + }else if(file_exists('/usr/local/directadmin/plugins/softaculous/enduser/universal.php')){
961 + $universal_file = '/usr/local/directadmin/plugins/softaculous/enduser/universal.php';
962 + }else if(file_exists('/usr/local/vesta/softaculous/enduser/universal.php')){
963 + $universal_file = '/usr/local/vesta/softaculous/enduser/universal.php';
1198 964 }
1199 -
1200 - // Delete a Whitelist IP range
1201 - if(isset($_GET['delid'])){
1202 -
1203 - $delid = (int) lz_optreq('delid');
1204 -
1205 - // Unset and save
1206 - $whitelist = $loginizer['whitelist'];
1207 - unset($whitelist[$delid]);
1208 - update_option('loginizer_whitelist', $whitelist);
1209 -
1210 - echo '<div id="message" class="updated fade"><p>'
1211 - . __('The Whitelist IP range has been deleted successfully', 'loginizer')
1212 - . '</p></div><br />';
1213 -
965 +
966 + if(empty($universal_file)){
967 + return false;
1214 968 }
1215 -
1216 - // Reset All Logs
1217 - if(isset($_POST['lz_reset_all_ip'])){
1218 -
1219 - $result = $wpdb->query("DELETE FROM `".$wpdb->prefix."loginizer_logs`
1220 - WHERE `time` > 0");
1221 -
1222 - echo '<div id="message" class="updated fade"><p>'
1223 - . __('All the IP Logs have been cleared', 'loginizer')
1224 - . '</p></div><br />';
1225 - }
1226 -
1227 - // Reset Logs
1228 - if(isset($_POST['lz_reset_ips']) && is_array($_POST['lz_reset_ips'])){
1229 969
1230 - $ips = $_POST['lz_reset_ips'];
1231 -
1232 - foreach($ips as $ip){
1233 - if(!lz_valid_ip($ip)){
1234 - $error[] = 'The IP - '.$ip.' is invalid !';
1235 - }
1236 - }
1237 -
1238 - if(count($ips) < 1){
1239 - $error[] = 'There are no IPs submitted';
1240 - }
1241 -
1242 - // Should we start deleting logs
1243 - if(empty($error)){
1244 -
1245 - $result = $wpdb->query("DELETE FROM `".$wpdb->prefix."loginizer_logs`
1246 - WHERE `ip` IN ('".implode("', '", $ips)."')");
1247 -
1248 - if(empty($error)){
1249 -
1250 - echo '<div id="message" class="updated fade"><p>'
1251 - . __('The selected IP Logs have been reset', 'loginizer')
1252 - . '</p></div><br />';
1253 -
1254 - }
1255 -
1256 - }
1257 -
1258 - if(!empty($error)){
1259 - lz_report_error($error);echo '<br />';
1260 - }
1261 -
1262 - }
1263 -
1264 - if(isset($_POST['blacklist_iprange'])){
970 + $universal = file_get_contents($universal_file);
1265 971
1266 - $start_ip = lz_optpost('start_ip');
1267 - $end_ip = lz_optpost('end_ip');
1268 -
1269 - if(empty($start_ip)){
1270 - $error[] = 'Please enter the Start IP';
1271 - }
1272 -
1273 - // If no end IP we consider only 1 IP
1274 - if(empty($end_ip)){
1275 - $end_ip = $start_ip;
1276 - }
1277 -
1278 - if(!lz_valid_ip($start_ip)){
1279 - $error[] = 'Please provide a valid start IP';
1280 - }
1281 -
1282 - if(!lz_valid_ip($end_ip)){
1283 - $error[] = 'Please provide a valid end IP';
1284 - }
1285 -
1286 - // Regular ranges will work
1287 - if(ip2long($start_ip) > ip2long($end_ip)){
1288 -
1289 - // BUT, if 0.0.0.1 - 255.255.255.255 is given, it will not work
1290 - if(ip2long($start_ip) >= 0 && ip2long($end_ip) < 0){
1291 - // This is right
1292 - }else{
1293 - $error[] = 'The End IP cannot be smaller than the Start IP';
1294 - }
1295 -
1296 - }
1297 -
1298 - if(empty($error)){
1299 -
1300 - $blacklist = $loginizer['blacklist'];
1301 -
1302 - foreach($blacklist as $k => $v){
1303 -
1304 - // This is to check if there is any other range exists with the same Start or End IP
1305 - if(( ip2long($start_ip) <= ip2long($v['start']) && ip2long($v['start']) <= ip2long($end_ip) )
1306 - || ( ip2long($start_ip) <= ip2long($v['end']) && ip2long($v['end']) <= ip2long($end_ip) )
1307 - ){
1308 - $error[] = 'The Start IP or End IP submitted conflicts with an existing IP range !';
1309 - break;
1310 - }
1311 -
1312 - // This is to check if there is any other range exists with the same Start IP
1313 - if(ip2long($v['start']) <= ip2long($start_ip) && ip2long($start_ip) <= ip2long($v['end'])){
1314 - $error[] = 'The Start IP is present in an existing range !';
1315 - break;
1316 - }
1317 -
1318 - // This is to check if there is any other range exists with the same End IP
1319 - if(ip2long($v['start']) <= ip2long($end_ip) && ip2long($end_ip) <= ip2long($v['end'])){
1320 - $error[] = 'The End IP is present in an existing range!';
1321 - break;
1322 - }
1323 -
1324 - }
1325 -
1326 - $newid = ( empty($blacklist) ? 0 : max(array_keys($blacklist)) ) + 1;
1327 -
1328 - if(empty($error)){
1329 -
1330 - $blacklist[$newid] = array();
1331 - $blacklist[$newid]['start'] = $start_ip;
1332 - $blacklist[$newid]['end'] = $end_ip;
1333 - $blacklist[$newid]['time'] = time();
1334 -
1335 - update_option('loginizer_blacklist', $blacklist);
1336 -
1337 - echo '<div id="message" class="updated fade"><p>'
1338 - . __('Blacklist IP range added successfully', 'loginizer')
1339 - . '</p></div><br />';
1340 -
1341 - }
1342 -
1343 - }
1344 -
1345 - if(!empty($error)){
1346 - lz_report_error($error);echo '<br />';
1347 - }
1348 -
972 + if(empty($universal)){
973 + return false;
1349 974 }
1350 -
1351 - if(isset($_POST['whitelist_iprange'])){
1352 975
1353 - $start_ip = lz_optpost('start_ip_w');
1354 - $end_ip = lz_optpost('end_ip_w');
1355 -
1356 - if(empty($start_ip)){
1357 - $error[] = 'Please enter the Start IP';
1358 - }
1359 -
1360 - // If no end IP we consider only 1 IP
1361 - if(empty($end_ip)){
1362 - $end_ip = $start_ip;
1363 - }
1364 -
1365 - if(!lz_valid_ip($start_ip)){
1366 - $error[] = 'Please provide a valid start IP';
1367 - }
1368 -
1369 - if(!lz_valid_ip($end_ip)){
1370 - $error[] = 'Please provide a valid end IP';
1371 - }
1372 -
1373 - if(ip2long($start_ip) > ip2long($end_ip)){
1374 -
1375 - // BUT, if 0.0.0.1 - 255.255.255.255 is given, it will not work
1376 - if(ip2long($start_ip) >= 0 && ip2long($end_ip) < 0){
1377 - // This is right
1378 - }else{
1379 - $error[] = 'The End IP cannot be smaller than the Start IP';
1380 - }
1381 -
1382 - }
1383 -
1384 - if(empty($error)){
1385 -
1386 - $whitelist = $loginizer['whitelist'];
1387 -
1388 - foreach($whitelist as $k => $v){
1389 -
1390 - // This is to check if there is any other range exists with the same Start or End IP
1391 - if(( ip2long($start_ip) <= ip2long($v['start']) && ip2long($v['start']) <= ip2long($end_ip) )
1392 - || ( ip2long($start_ip) <= ip2long($v['end']) && ip2long($v['end']) <= ip2long($end_ip) )
1393 - ){
1394 - $error[] = 'The Start IP or End IP submitted conflicts with an existing IP range !';
1395 - break;
1396 - }
1397 -
1398 - // This is to check if there is any other range exists with the same Start IP
1399 - if(ip2long($v['start']) <= ip2long($start_ip) && ip2long($start_ip) <= ip2long($v['end'])){
1400 - $error[] = 'The Start IP is present in an existing range !';
1401 - break;
1402 - }
1403 -
1404 - // This is to check if there is any other range exists with the same End IP
1405 - if(ip2long($v['start']) <= ip2long($end_ip) && ip2long($end_ip) <= ip2long($v['end'])){
1406 - $error[] = 'The End IP is present in an existing range!';
1407 - break;
1408 - }
1409 -
1410 - }
1411 -
1412 - $newid = ( empty($whitelist) ? 0 : max(array_keys($whitelist)) ) + 1;
1413 -
1414 - if(empty($error)){
1415 -
1416 - $whitelist[$newid] = array();
1417 - $whitelist[$newid]['start'] = $start_ip;
1418 - $whitelist[$newid]['end'] = $end_ip;
1419 - $whitelist[$newid]['time'] = time();
1420 -
1421 - update_option('loginizer_whitelist', $whitelist);
1422 -
1423 - echo '<div id="message" class="updated fade"><p>'
1424 - . __('Whitelist IP range added successfully', 'loginizer')
1425 - . '</p></div><br />';
1426 -
1427 - }
1428 -
1429 - }
1430 -
1431 - if(!empty($error)){
1432 - lz_report_error($error);echo '<br />';
1433 - }
976 + // Checking if Softaculous is being whitelabeled
977 + if(preg_match('/\$globals\[["\']sn["\']\]\s.?=\s.?["\']Softaculous["\']/', $universal)){
978 + update_option('loginizer_softwp_upgrade', time());
1434 979 }
1435 -
1436 - // Count the Results
1437 - $tmp = lz_selectquery("SELECT COUNT(*) AS num FROM `".$wpdb->prefix."loginizer_logs`");
1438 - //print_r($tmp);
1439 -
1440 - // Which Page is it
1441 - $lz_env['res_len'] = 10;
1442 - $lz_env['cur_page'] = lz_get_page('lzpage', $lz_env['res_len']);
1443 - $lz_env['num_res'] = $tmp['num'];
1444 - $lz_env['max_page'] = ceil($lz_env['num_res'] / $lz_env['res_len']);
1445 -
1446 - // Get the logs
1447 - $result = lz_selectquery("SELECT * FROM `".$wpdb->prefix."loginizer_logs`
1448 - ORDER BY `time` DESC
1449 - LIMIT ".$lz_env['cur_page'].", ".$lz_env['res_len']."", 1);
1450 - //print_r($result);
1451 -
1452 - $lz_env['cur_page'] = ($lz_env['cur_page'] / $lz_env['res_len']) + 1;
1453 - $lz_env['cur_page'] = $lz_env['cur_page'] < 1 ? 1 : $lz_env['cur_page'];
1454 - $lz_env['next_page'] = ($lz_env['cur_page'] + 1) > $lz_env['max_page'] ? $lz_env['max_page'] : ($lz_env['cur_page'] + 1);
1455 - $lz_env['prev_page'] = ($lz_env['cur_page'] - 1) < 1 ? 1 : ($lz_env['cur_page'] - 1);
1456 -
1457 - // Reload the settings
1458 - $loginizer['blacklist'] = get_option('loginizer_blacklist');
1459 - $loginizer['whitelist'] = get_option('loginizer_whitelist');
1460 -
1461 - ?>
1462 980
1463 - <div id="" class="postbox">
1464 -
1465 - <button class="handlediv button-link" aria-expanded="true" type="button">
1466 - <span class="screen-reader-text">Toggle panel: Failed Login Attempts Logs</span>
1467 - <span class="toggle-indicator" aria-hidden="true"></span>
1468 - </button>
1469 -
1470 - <h2 class="hndle ui-sortable-handle">
1471 - <?php echo __('<span>Failed Login Attempts Logs</span> &nbsp; (Past '.($loginizer['reset_retries']/60/60).' hours)','loginizer'); ?>
1472 - </h2>
1473 -
1474 - <script>
1475 - function yesdsd(){
1476 - window.location = '<?php echo menu_page_url('loginizer_brute_force', false);?>&lzpage='+jQuery("#current-page-selector").val();
1477 - return false;
1478 - }
1479 - </script>
1480 -
1481 - <form method="get" onsubmit="return yesdsd();">
1482 - <div class="tablenav">
1483 - <p class="tablenav-pages" style="margin: 5px 10px" align="right">
1484 - <span class="displaying-num"><?php echo $lz_env['num_res'];?> items</span>
1485 - <span class="pagination-links">
1486 - <a class="first-page" href="<?php echo menu_page_url('loginizer_brute_force', false).'&lzpage=1';?>"><span class="screen-reader-text">First page</span><span aria-hidden="true">«</span></a>
1487 - <a class="prev-page" href="<?php echo menu_page_url('loginizer_brute_force', false).'&lzpage='.$lz_env['prev_page'];?>"><span class="screen-reader-text">Previous page</span><span aria-hidden="true">‹</span></a>
1488 - <span class="paging-input">
1489 - <label for="current-page-selector" class="screen-reader-text">Current Page</label>
1490 - <input class="current-page" id="current-page-selector" name="lzpage" value="<?php echo $lz_env['cur_page'];?>" size="3" aria-describedby="table-paging" type="text"><span class="tablenav-paging-text"> of <span class="total-pages"><?php echo $lz_env['max_page'];?></span></span>
1491 - </span>
1492 - <a class="next-page" href="<?php echo menu_page_url('loginizer_brute_force', false).'&lzpage='.$lz_env['next_page'];?>"><span class="screen-reader-text">Next page</span><span aria-hidden="true">›</span></a>
1493 - <a class="last-page" href="<?php echo menu_page_url('loginizer_brute_force', false).'&lzpage='.$lz_env['max_page'];?>"><span class="screen-reader-text">Last page</span><span aria-hidden="true">»</span></a>
1494 - </span>
1495 - </p>
1496 - </div>
1497 - </form>
1498 -
1499 - <form action="" method="post" enctype="multipart/form-data">
1500 - <?php wp_nonce_field('loginizer-options'); ?>
1501 - <div class="inside">
1502 - <table class="wp-list-table widefat fixed users" border="0">
1503 - <tr>
1504 - <th scope="row" valign="top" style="background:#EFEFEF;" width="20">#</th>
1505 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('IP','loginizer'); ?></th>
1506 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('Last Failed Attempt (DD/MM/YYYY)','loginizer'); ?></th>
1507 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('Failed Attempts Count','loginizer'); ?></th>
1508 - <th scope="row" valign="top" style="background:#EFEFEF;" width="150"><?php echo __('Lockouts Count','loginizer'); ?></th>
1509 - </tr>
1510 - <?php
1511 -
1512 - if(empty($result)){
1513 - echo '
1514 - <tr>
1515 - <td colspan="4">
1516 - No Logs. You will see logs about failed login attempts here.
1517 - </td>
1518 - </tr>';
1519 - }else{
1520 - foreach($result as $ik => $iv){
1521 - $status_button = (!empty($iv['status']) ? 'disable' : 'enable');
1522 - echo '
1523 - <tr>
1524 - <td>
1525 - <input type="checkbox" value="'.$iv['ip'].'" name="lz_reset_ips[]" />
1526 - </td>
1527 - <td>
1528 - '.$iv['ip'].'
1529 - </td>
1530 - <td>
1531 - '.date('d/m/Y H:i:s', $iv['time']).'
1532 - </td>
1533 - <td>
1534 - '.$iv['count'].'
1535 - </td>
1536 - <td>
1537 - '.$iv['lockout'].'
1538 - </td>
1539 - </tr>';
1540 - }
1541 - }
1542 -
1543 - ?>
1544 - </table>
1545 -
1546 - <br>
1547 - <input name="lz_reset_ip" class="button button-primary action" value="<?php echo __('Remove From Logs', 'loginizer'); ?>" type="submit" />
1548 - &nbsp; &nbsp;
1549 - <input name="lz_reset_all_ip" class="button button-primary action" value="<?php echo __('Clear All Logs', 'loginizer'); ?>" type="submit" />
1550 - </div>
1551 - </div>
1552 - </form>
1553 - <br />
1554 -
1555 - <div id="" class="postbox">
1556 -
1557 - <button class="handlediv button-link" aria-expanded="true" type="button">
1558 - <span class="screen-reader-text">Toggle panel: Brute Force Settings</span>
1559 - <span class="toggle-indicator" aria-hidden="true"></span>
1560 - </button>
1561 -
1562 - <h2 class="hndle ui-sortable-handle">
1563 - <span><?php echo __('Brute Force Settings', 'loginizer'); ?></span>
1564 - </h2>
1565 -
1566 - <div class="inside">
1567 -
1568 - <form action="" method="post" enctype="multipart/form-data">
1569 - <?php wp_nonce_field('loginizer-options'); ?>
1570 - <table class="form-table">
1571 - <tr>
1572 - <th scope="row" valign="top"><label for="max_retries"><?php echo __('Max Retries','loginizer'); ?></label></th>
1573 - <td>
1574 - <input type="text" size="3" value="<?php echo lz_optpost('max_retries', $loginizer['max_retries']); ?>" name="max_retries" id="max_retries" /> <?php echo __('Maximum failed attempts allowed before lockout','loginizer'); ?> <br />
1575 - </td>
1576 - </tr>
1577 - <tr>
1578 - <th scope="row" valign="top"><label for="lockout_time"><?php echo __('Lockout Time','loginizer'); ?></label></th>
1579 - <td>
1580 - <input type="text" size="3" value="<?php echo (!empty($lockout_time) ? $lockout_time : $loginizer['lockout_time']) / 60; ?>" name="lockout_time" id="lockout_time" /> <?php echo __('minutes','loginizer'); ?> <br />
1581 - </td>
1582 - </tr>
1583 - <tr>
1584 - <th scope="row" valign="top"><label for="max_lockouts"><?php echo __('Max Lockouts','loginizer'); ?></label></th>
1585 - <td>
1586 - <input type="text" size="3" value="<?php echo lz_optpost('max_lockouts', $loginizer['max_lockouts']); ?>" name="max_lockouts" id="max_lockouts" /> <?php echo __('','loginizer'); ?> <br />
1587 - </td>
1588 - </tr>
1589 - <tr>
1590 - <th scope="row" valign="top"><label for="lockouts_extend"><?php echo __('Extend Lockout','loginizer'); ?></label></th>
1591 - <td>
1592 - <input type="text" size="3" value="<?php echo (!empty($lockouts_extend) ? $lockouts_extend : $loginizer['lockouts_extend']) / 60 / 60; ?>" name="lockouts_extend" id="lockouts_extend" /> <?php echo __('hours. Extend Lockout time after Max Lockouts','loginizer'); ?> <br />
1593 - </td>
1594 - </tr>
1595 - <tr>
1596 - <th scope="row" valign="top"><label for="reset_retries"><?php echo __('Reset Retries','loginizer'); ?></label></th>
1597 - <td>
1598 - <input type="text" size="3" value="<?php echo (!empty($reset_retries) ? $reset_retries : $loginizer['reset_retries']) / 60 / 60; ?>" name="reset_retries" id="reset_retries" /> <?php echo __('hours','loginizer'); ?> <br />
1599 - </td>
1600 - </tr>
1601 - <tr>
1602 - <th scope="row" valign="top"><label for="notify_email"><?php echo __('Email Notification','loginizer'); ?></label></th>
1603 - <td>
1604 - <?php echo __('after ','loginizer'); ?>
1605 - <input type="text" size="3" value="<?php echo (!empty($notify_email) ? $notify_email : $loginizer['notify_email']); ?>" name="notify_email" id="notify_email" /> <?php echo __('lockouts <br />0 to disable email notifications','loginizer'); ?>
1606 - </td>
1607 - </tr>
1608 - </table><br />
1609 - <input name="save_lz" class="button button-primary action" value="<?php echo __('Save Settings','loginizer'); ?>" type="submit" />
1610 - </form>
1611 -
1612 - </div>
1613 - </div>
1614 - <br />
1615 -
1616 - <div id="" class="postbox">
1617 -
1618 - <button class="handlediv button-link" aria-expanded="true" type="button">
1619 - <span class="screen-reader-text">Toggle panel: Blacklist IP</span>
1620 - <span class="toggle-indicator" aria-hidden="true"></span>
1621 - </button>
1622 -
1623 - <h2 class="hndle ui-sortable-handle">
1624 - <span><?php echo __('Blacklist IP','loginizer'); ?></span>
1625 - </h2>
1626 -
1627 - <div class="inside">
1628 -
1629 - <?php echo __('Enter the IP you want to blacklist from login','loginizer'); ?>
1630 -
1631 - <form action="" method="post">
1632 - <?php wp_nonce_field('loginizer-options'); ?>
1633 - <table class="form-table">
1634 - <tr>
1635 - <th scope="row" valign="top"><label for="start_ip"><?php echo __('Start IP','loginizer'); ?></label></th>
1636 - <td>
1637 - <input type="text" size="25" value="<?php echo(lz_optpost('start_ip')); ?>" name="start_ip" id="start_ip"/> <?php echo __('Start IP of the range','loginizer'); ?> <br />
1638 - </td>
1639 - </tr>
1640 - <tr>
1641 - <th scope="row" valign="top"><label for="end_ip"><?php echo __('End IP (Optional)','loginizer'); ?></label></th>
1642 - <td>
1643 - <input type="text" size="25" value="<?php echo(lz_optpost('end_ip')); ?>" name="end_ip" id="end_ip"/> <?php echo __('End IP of the range. <br />If you want to blacklist single IP leave this field blank.','loginizer'); ?> <br />
1644 - </td>
1645 - </tr>
1646 - </table><br />
1647 - <input name="blacklist_iprange" class="button button-primary action" value="<?php echo __('Add Blacklist IP Range','loginizer'); ?>" type="submit" />
1648 - </form>
1649 - </div>
1650 -
1651 - <table class="wp-list-table fixed striped users" border="0" width="95%" cellpadding="10" align="center">
1652 - <tr>
1653 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('Start IP','loginizer'); ?></th>
1654 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('End IP','loginizer'); ?></th>
1655 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('Date (DD/MM/YYYY)','loginizer'); ?></th>
1656 - <th scope="row" valign="top" style="background:#EFEFEF;" width="100"><?php echo __('Options','loginizer'); ?></th>
1657 - </tr>
1658 - <?php
1659 - if(empty($loginizer['blacklist'])){
1660 - echo '
1661 - <tr>
1662 - <td colspan="4">
1663 - No Blacklist IPs. You will see blacklisted IP ranges here.
1664 - </td>
1665 - </tr>';
1666 - }else{
1667 - foreach($loginizer['blacklist'] as $ik => $iv){
1668 - echo '
1669 - <tr>
1670 - <td>
1671 - '.$iv['start'].'
1672 - </td>
1673 - <td>
1674 - '.$iv['end'].'
1675 - </td>
1676 - <td>
1677 - '.date('d/m/Y', $iv['time']).'
1678 - </td>
1679 - <td>
1680 - <a class="submitdelete" href="admin.php?page=loginizer_brute_force&bdelid='.$ik.'" onclick="return confirm(\'Are you sure you want to delete this IP range ?\')">Delete</a>
1681 - </td>
1682 - </tr>';
1683 - }
1684 - }
1685 - ?>
1686 - </table>
1687 - <br />
1688 -
1689 - </div>
1690 -
1691 - <br />
1692 -
1693 - <div id="" class="postbox">
1694 -
1695 - <button class="handlediv button-link" aria-expanded="true" type="button">
1696 - <span class="screen-reader-text">Toggle panel: Whitelist IP</span>
1697 - <span class="toggle-indicator" aria-hidden="true"></span>
1698 - </button>
1699 -
1700 - <h2 class="hndle ui-sortable-handle">
1701 - <span><?php echo __('Whitelist IP', 'loginizer'); ?></span>
1702 - </h2>
1703 -
1704 - <div class="inside">
1705 -
1706 - <?php echo __('Enter the IP you want to whitelist for login','loginizer'); ?>
1707 - <form action="" method="post">
1708 - <?php wp_nonce_field('loginizer-options'); ?>
1709 - <table class="form-table">
1710 - <tr>
1711 - <th scope="row" valign="top"><label for="start_ip_w"><?php echo __('Start IP','loginizer'); ?></label></th>
1712 - <td>
1713 - <input type="text" size="25" value="<?php echo(lz_optpost('start_ip_w')); ?>" name="start_ip_w" id="start_ip_w"/> <?php echo __('Start IP of the range','loginizer'); ?> <br />
1714 - </td>
1715 - </tr>
1716 - <tr>
1717 - <th scope="row" valign="top"><label for="end_ip_w"><?php echo __('End IP (Optional)','loginizer'); ?></label></th>
1718 - <td>
1719 - <input type="text" size="25" value="<?php echo(lz_optpost('end_ip_w')); ?>" name="end_ip_w" id="end_ip_w"/> <?php echo __('End IP of the range. <br />If you want to whitelist single IP leave this field blank.','loginizer'); ?> <br />
1720 - </td>
1721 - </tr>
1722 - </table><br />
1723 - <input name="whitelist_iprange" class="button button-primary action" value="<?php echo __('Add Whitelist IP Range','loginizer'); ?>" type="submit" />
1724 - </form>
1725 - </div>
1726 -
1727 - <table class="wp-list-table fixed striped users" border="0" width="95%" cellpadding="10" align="center">
1728 - <tr>
1729 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('Start IP','loginizer'); ?></th>
1730 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('End IP','loginizer'); ?></th>
1731 - <th scope="row" valign="top" style="background:#EFEFEF;"><?php echo __('Date (DD/MM/YYYY)','loginizer'); ?></th>
1732 - <th scope="row" valign="top" style="background:#EFEFEF;" width="100"><?php echo __('Options','loginizer'); ?></th>
1733 - </tr>
1734 - <?php
1735 - if(empty($loginizer['whitelist'])){
1736 - echo '
1737 - <tr>
1738 - <td colspan="4">
1739 - No Whitelist IPs. You will see whitelisted IP ranges here.
1740 - </td>
1741 - </tr>';
1742 - }else{
1743 - foreach($loginizer['whitelist'] as $ik => $iv){
1744 - echo '
1745 - <tr>
1746 - <td>
1747 - '.$iv['start'].'
1748 - </td>
1749 - <td>
1750 - '.$iv['end'].'
1751 - </td>
1752 - <td>
1753 - '.date('d/m/Y', $iv['time']).'
1754 - </td>
1755 - <td>
1756 - <a class="submitdelete" href="admin.php?page=loginizer_brute_force&delid='.$ik.'" onclick="return confirm(\'Are you sure you want to delete this IP range ?\')">Delete</a>
1757 - </td>
1758 - </tr>';
1759 - }
1760 - }
1761 - ?>
1762 - </table>
1763 - <br />
1764 -
1765 - </div>
1766 -
1767 -<?php
1768 -
1769 -loginizer_page_footer();
1770 -
981 + return false;
1771 982 }
1772 983
1773 -
1774 984 // Sorry to see you going
1775 985 register_uninstall_hook(LOGINIZER_FILE, 'loginizer_deactivation');
1776 986
1777 987 function loginizer_deactivation(){
@@ -1789,7 +999,22 @@
1789 999 delete_option('loginizer_options');
1790 1000 delete_option('loginizer_last_reset');
1791 1001 delete_option('loginizer_whitelist');
1792 1002 delete_option('loginizer_blacklist');
1003 + delete_option('loginizer_msg');
1004 + delete_option('loginizer_2fa_msg');
1005 + delete_option('loginizer_2fa_email_template');
1006 + delete_option('loginizer_security');
1007 + delete_option('loginizer_wp_admin');
1008 + delete_option('loginizer_csrf_promo_time');
1009 + delete_option('loginizer_backuply_promo_time');
1010 + delete_option('loginizer_promo_time');
1011 + delete_option('loginizer_ins_time');
1012 + delete_option('loginizer_2fa_whitelist');
1013 + delete_option('loginizer_checksums_last_run');
1014 + delete_option('loginizer_checksums_diff');
1015 + delete_option('loginizer_ip_method');
1016 + delete_option('loginizer_2fa_custom_redirect');
1017 + delete_option('external_updates-loginizer-security');
1018 + delete_option('loginizer_login_attempt_stats');
1793 1019
1794 -}
1795 -
1020 +}