PluginProbe
Loginizer / trunk
Loginizer vtrunk
2.1.0 2.0.9 2.0.8 1.9.8 1.9.9 2.0.0 2.0.1 2.0.2 2.0.3 2.0.4 2.0.5 2.0.6 2.0.7 trunk 1.0 1.0.1 1.0.2 1.1.0 1.1.1 1.2.0 1.3.0 1.3.1 1.3.2 1.3.3 1.3.4 All 74 releases
← All changes | init.php +94 -163 2.0.1 → trunk View file →
@@ -4,9 +4,9 @@
4 4 echo 'You are not allowed to access this page directly.';
5 5 exit;
6 6 }
7 7
8 -define('LOGINIZER_VERSION', '2.0.1');
8 +define('LOGINIZER_VERSION', '2.1.0');
9 9 define('LOGINIZER_DIR', dirname(LOGINIZER_FILE));
10 10 define('LOGINIZER_URL', plugins_url('', LOGINIZER_FILE));
11 11 define('LOGINIZER_PRO_URL', 'https://loginizer.com/features#compare');
12 12 define('LOGINIZER_PRICING_URL', 'https://loginizer.com/pricing');
@@ -332,21 +332,22 @@
332 332 // Is called before displaying the error message so that we dont show that the username is wrong or the password
333 333 // Update Error message
334 334 add_action('wp_login_errors', 'loginizer_error_handler', 10001, 2);
335 335 add_action('woocommerce_login_failed', 'loginizer_woocommerce_error_handler', 10001);
336 - add_action('wp_login', 'loginizer_login_success', 10, 2);
336 + add_action('wp_login', 'loginizer_login_success', 11, 2);
337 + add_action('rsssl_two_factor_user_authenticated', 'loginizer_rsssl_2fa_success');
337 338
338 339 if(!empty($loginizer['ultimate-member-active'])){
339 340 add_action('wp_login_failed', 'loginizer_ultimatemember_error_handler', 10001);
340 341 }
341 342
342 - if(!empty($_COOKIE['lz_social_error']) && !empty($loginizer['social_settings']) && !loginizer_is_blacklisted()){
343 + if(!empty($_COOKIE['lz_social_error']) && !empty($loginizer['social_settings'])){
343 344 add_filter('wp_login_errors', 'loginizer_social_login_error_handler', 10000, 2);
344 345 }
345 346 }
346 347
347 348 // Social Login Form Actions
348 - if(!empty($loginizer['social_settings']) && !loginizer_is_blacklisted()){
349 + if(!empty($loginizer['social_settings'])){
349 350 if(!empty($loginizer['social_settings']['login']['login_form'])){
350 351 add_action('login_form', 'loginizer_social_btn_login');
351 352 }
352 353 }
@@ -357,60 +358,13 @@
357 358
358 359 if(is_admin()){
359 360 include_once LOGINIZER_DIR . '/main/admin.php';
360 361 }
361 -
362 +
362 363 // ----------------
363 364 // PRO INIT END
364 365 // ----------------
365 366
366 - // Is the premium features there ?
367 - if(!defined('LOGINIZER_PREMIUM')){
368 -
369 - if(current_user_can('activate_plugins')){
370 - // The promo time
371 - $loginizer['promo_time'] = get_option('loginizer_promo_time');
372 - if(empty($loginizer['promo_time'])){
373 - $loginizer['promo_time'] = time();
374 - update_option('loginizer_promo_time', $loginizer['promo_time']);
375 - }
376 -
377 - // Are we to show the loginizer promo
378 - if(!empty($loginizer['promo_time']) && $loginizer['promo_time'] > 0 && $loginizer['promo_time'] < (time() - (30*24*3600))){
379 -
380 - add_action('admin_notices', 'loginizer_promo');
381 -
382 - }
383 -
384 - if(!empty($loginizer['csrf_promo']) && $loginizer['csrf_promo'] > 0 && $loginizer['csrf_promo'] < (time() - 86400)){
385 -
386 - add_action('admin_notices', 'loginizer_csrf_promo');
387 -
388 - }
389 -
390 - // Are we to disable the promo
391 - if(isset($_GET['loginizer_promo']) && (int)$_GET['loginizer_promo'] == 0){
392 - update_option('loginizer_promo_time', (0 - time()) );
393 - die('DONE');
394 - }
395 -
396 - $loginizer['backuply_promo'] = get_option('loginizer_backuply_promo_time');
397 -
398 - if(empty($loginizer['backuply_promo'])){
399 - $loginizer['backuply_promo'] = abs($loginizer['promo_time']);
400 - update_option('loginizer_backuply_promo_time', $loginizer['backuply_promo']);
401 - }
402 -
403 - // Setting CSRF Promo time
404 - $loginizer['csrf_promo'] = get_option('loginizer_csrf_promo_time');
405 -
406 - if(empty($loginizer['csrf_promo'])){
407 - $loginizer['csrf_promo'] = abs($loginizer['promo_time']);
408 - update_option('loginizer_csrf_promo_time', $loginizer['csrf_promo']);
409 - }
410 - }
411 - }
412 -
413 367 // Secuity checks for social login.
414 368 if(!empty($_GET['lz_social_provider']) && loginizer_can_login() && empty($_GET['lz_api'])){
415 369 add_action('init', 'loginizer_social_login_load');
416 370 return;
@@ -541,26 +495,31 @@
541 495
542 496 if(empty($blacklist)){
543 497 return false;
544 498 }
545 -
499 +
500 + $current_ip_inet = inet_ptoi($loginizer['current_ip']);
501 +
546 502 foreach($blacklist as $k => $v){
547 -
503 +
504 + $start_inet = inet_ptoi($v['start']);
505 + $end_inet = inet_ptoi($v['end']);
506 +
548 507 // Is the IP in the blacklist ?
549 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip']) && inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
508 + if($start_inet <= $current_ip_inet && $current_ip_inet <= $end_inet){
550 509 $result = 1;
551 510 break;
552 511 }
553 -
512 +
554 513 // Is it in a wider range ?
555 - if(inet_ptoi($v['start']) >= 0 && inet_ptoi($v['end']) < 0){
514 + if($start_inet >= 0 && $end_inet < 0){
556 515
557 516 // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of inet_ptoi,
558 517 // if the current IP is <= than the start of the range, it is within the range
559 518 // OR
560 519 // if the current IP is <= than the end of the range, it is within the range
561 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip'])
562 - || inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
520 + if($start_inet <= $current_ip_inet
521 + || $current_ip_inet <= $end_inet){
563 522 $result = 1;
564 523 break;
565 524 }
566 525
@@ -566,9 +525,9 @@
566 525
567 526 }
568 527
569 528 }
570 -
529 +
571 530 // You are blacklisted
572 531 if(!empty($result)){
573 532 $lz_error['ip_blacklisted'] = $loginizer['msg']['ip_blacklisted'];
574 533 return true;
@@ -577,52 +536,8 @@
577 536 return false;
578 537
579 538 }
580 539
581 -function loginizer_is_whitelisted(){
582 -
583 - global $wpdb, $loginizer, $lz_error;
584 -
585 - $whitelist = $loginizer['whitelist'];
586 -
587 - if(empty($whitelist)){
588 - return false;
589 - }
590 -
591 - foreach($whitelist as $k => $v){
592 -
593 - // Is the IP in the blacklist ?
594 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip']) && inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
595 - $result = 1;
596 - break;
597 - }
598 -
599 - // Is it in a wider range ?
600 - if(inet_ptoi($v['start']) >= 0 && inet_ptoi($v['end']) < 0){
601 -
602 - // Since the end of the RANGE (i.e. current IP range) is beyond the +ve value of inet_ptoi,
603 - // if the current IP is <= than the start of the range, it is within the range
604 - // OR
605 - // if the current IP is <= than the end of the range, it is within the range
606 - if(inet_ptoi($v['start']) <= inet_ptoi($loginizer['current_ip'])
607 - || inet_ptoi($loginizer['current_ip']) <= inet_ptoi($v['end'])){
608 - $result = 1;
609 - break;
610 - }
611 -
612 - }
613 -
614 - }
615 -
616 - // You are whitelisted
617 - if(!empty($result)){
618 - return true;
619 - }
620 -
621 - return false;
622 -
623 -}
624 -
625 540 // When the login fails, then this is called
626 541 // We need to update the database
627 542 function loginizer_login_failed($username, $is_2fa = ''){
628 543
@@ -641,53 +556,78 @@
641 556
642 557 if(empty($lz_cannot_login) && empty($loginizer['ip_is_whitelisted']) && empty($loginizer['no_loginizer_logs'])){
643 558
644 559 // The params which comes when social login returns an error, have some characters, which WordPress could not save.
645 - $server_uri = $_SERVER['REQUEST_URI'];
646 - if(!empty($_SERVER['REQUEST_URI']) && strpos($_SERVER['REQUEST_URI'], 'lz_social_provider') !== FALSE){
647 - $request_uri = explode('=', $_SERVER['REQUEST_URI']);
560 + // REQUEST_URI / HTTP_HOST are not always set (WP-CLI, some CGI and XML-RPC setups)
561 + $server_uri = isset($_SERVER['REQUEST_URI']) ? $_SERVER['REQUEST_URI'] : '';
562 + $http_host = isset($_SERVER['HTTP_HOST']) ? $_SERVER['HTTP_HOST'] : '';
563 +
564 + if(!empty($server_uri) && strpos($server_uri, 'lz_social_provider') !== FALSE){
565 + $request_uri = explode('=', $server_uri);
648 566 $server_uri = $request_uri[0];
649 567 }
650 568
651 - $url = @addslashes((!empty($_SERVER['HTTPS']) ? 'https://' : 'http://').$_SERVER['HTTP_HOST'].$server_uri);
652 - $url = esc_url($url);
569 + // No addslashes() here, $wpdb->prepare() below does the escaping
570 + $url = esc_url((!empty($_SERVER['HTTPS']) ? 'https://' : 'http://').$http_host.$server_uri);
653 571
572 + // Must never be 0, we divide by it below
573 + $max_retries = (int) $loginizer['max_retries'] < 1 ? 1 : (int) $loginizer['max_retries'];
574 +
575 + // This way is atomic now, the earlier one were causing race condition.
576 + // NOTE : In the UPDATE part `count` is already the new value, as MySQL / MariaDB
577 + // evaluate the assignments from left to right, so lockout must NOT add 1 again
578 + $upsert = $wpdb->prepare(
579 + "INSERT INTO `".$wpdb->prefix."loginizer_logs`
580 + (username, time, count, ip, lockout, url)
581 + VALUES
582 + (%s, %d, 1, %s, FLOOR(1 / %d), %s)
583 + ON DUPLICATE KEY UPDATE
584 + username = VALUES(username),
585 + time = VALUES(time),
586 + count = count + 1,
587 + lockout = FLOOR(count / %d),
588 + url = VALUES(url)",
589 + $username,
590 + time(),
591 + $loginizer['current_ip'],
592 + $max_retries,
593 + $url,
594 + $max_retries
595 + );
596 + $wpdb->query($upsert);
597 +
598 + // Re-read the persisted row so email/retries-left reflect the actual count
654 599 $sel_query = $wpdb->prepare("SELECT * FROM `".$wpdb->prefix."loginizer_logs` WHERE `ip` = %s", $loginizer['current_ip']);
655 600 $result = lz_selectquery($sel_query);
656 -
657 - if(!empty($result)){
658 - $lockout = floor((($result['count']+1) / $loginizer['max_retries']));
659 -
660 - $update_data = array('username' => $username,
661 - 'time' => time(),
662 - 'count' => $result['count']+1,
663 - 'lockout' => $lockout,
664 - 'url' => $url);
665 -
666 - $where_data = array('ip' => $loginizer['current_ip']);
667 -
668 - $format = array('%s','%d','%d','%d','%s');
669 - $where_format = array('%s');
670 -
671 - $wpdb->update($wpdb->prefix.'loginizer_logs', $update_data, $where_data, $format, $where_format);
672 -
673 - // Do we need to email admin ?
674 - if(!empty($loginizer['notify_email']) && $lockout >= $loginizer['notify_email']){
675 -
676 - $lockout_time = $loginizer['lockout_time'];
677 -
678 - if($lockout >= $loginizer['max_lockouts']){
679 - // extended lockout is in hours so we have to convert to minute
680 - $lockout_time = $loginizer['lockouts_extend'];
681 - }
682 -
683 - $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
684 - $mail = array();
685 - $mail['to'] = $loginizer['notify_email_address'];
686 - $mail['subject'] = 'Failed '.$fail_type.' Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
687 - $mail['message'] = 'Hi,
688 601
689 -'.($result['count']+1).' failed '.strtolower($fail_type).' attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].' on your site :
602 + if(empty($result)){
603 + $result = array('count' => 0);
604 + }
605 +
606 + $count = (int) $result['count'];
607 + $lockout = !empty($result['lockout']) ? (int) $result['lockout'] : 0;
608 +
609 + // The lockout goes up only on every max_retries'th failure, which is the
610 + // attempt that actually locks the IP out. On the failures in between there
611 + // is nothing new to report, so we must not email on each one of them
612 + $is_new_lockout = !empty($count) && ($count % $max_retries) == 0;
613 +
614 + // Do we need to email admin ?
615 + if(!empty($loginizer['notify_email']) && !empty($is_new_lockout) && $lockout >= $loginizer['notify_email']){
616 +
617 + $lockout_time = $loginizer['lockout_time'];
618 +
619 + if($lockout >= $loginizer['max_lockouts']){
620 + $lockout_time = $loginizer['lockouts_extend'];
621 + }
622 +
623 + $sitename = lz_is_multisite() ? get_site_option('site_name') : get_option('blogname');
624 + $mail = array();
625 + $mail['to'] = $loginizer['notify_email_address'];
626 + $mail['subject'] = 'Failed '.$fail_type.' Attempts from IP '.$loginizer['current_ip'].' ('.$sitename.')';
627 + $mail['message'] = 'Hi,
628 +
629 +'.(int) $result['count'].' failed '.strtolower($fail_type).' attempts and '.$lockout.' lockout(s) from IP '.$loginizer['current_ip'].' on your site :
690 630 '.home_url().'
691 631
692 632 Last '.$fail_type.' Attempt : '.date('d/M/Y H:i:s P', time()).'
693 633 Last User Attempt : '.$username.'
@@ -695,35 +635,22 @@
695 635
696 636 Regards,
697 637 Loginizer';
698 638
699 - @wp_mail($mail['to'], $mail['subject'], $mail['message']);
700 - }
701 - }else{
702 - $result = array();
703 - $result['count'] = 0;
704 -
705 - $insert_data = array('username' => $username,
706 - 'time' => time(),
707 - 'count' => 1,
708 - 'ip' => $loginizer['current_ip'],
709 - 'lockout' => 0,
710 - 'url' => $url);
711 -
712 - $format = array('%s','%d','%d','%s','%d','%s');
713 -
714 - $wpdb->insert($wpdb->prefix.'loginizer_logs', $insert_data, $format);
639 + @wp_mail($mail['to'], $mail['subject'], $mail['message']);
715 640 }
716 -
717 - // We need to add one as this is a failed attempt as well
718 - $result['count'] = $result['count'] + 1;
641 +
719 642 loginizer_update_attempt_stats(0);
720 - $loginizer['retries_left'] = ($loginizer['max_retries'] - ($result['count'] % $loginizer['max_retries']));
721 - $loginizer['retries_left'] = $loginizer['retries_left'] == $loginizer['max_retries'] ? 0 : $loginizer['retries_left'];
643 + $loginizer['retries_left'] = $max_retries - ($count % $max_retries);
644 + $loginizer['retries_left'] = $loginizer['retries_left'] == $max_retries ? 0 : $loginizer['retries_left'];
722 645
723 646 }
724 647 }
725 648
649 +function loginizer_rsssl_2fa_success($user){
650 + loginizer_login_success('', $user);
651 +}
652 +
726 653 function loginizer_login_success($user_login, $user) {
727 654 global $wp_version, $loginizer;
728 655
729 656 loginizer_update_attempt_stats(1);
@@ -887,8 +814,12 @@
887 814
888 815 // Handles social login URL
889 816 function loginizer_social_login_error_handler($errors = '', $redirect_to = ''){
890 817 global $loginizer;
818 +
819 + if(loginizer_is_blacklisted()){
820 + return $errors;
821 + }
891 822
892 823 loginizer_get_social_error();
893 824
894 825 if(empty($loginizer['social_errors'])){