PluginProbe
Patchstack – WordPress & Plugins Security / 2.1.4
Patchstack – WordPress & Plugins Security v2.1.4
2.3.7 trunk 2.1.0 2.1.1 2.1.10 2.1.11 2.1.12 2.1.13 2.1.14 2.1.15 2.1.16 2.1.17 2.1.18 2.1.19 2.1.2 2.1.20 2.1.21 2.1.22 2.1.23 2.1.24 2.1.25 2.1.3 2.1.4 2.1.5 2.1.6 All 49 releases
← All changes | includes/ban.php +158 -167 trunk2.1.4 View file →
@@ -1,167 +1,158 @@
1 -<?php
2 -
3 -// Do not allow the file to be called directly.
4 -if ( ! defined( 'ABSPATH' ) ) {
5 - exit;
6 -}
7 -
8 -/**
9 - * This class is used to determine if the IP address of the
10 - * user is banned. Along with that we check the IP address whitelist.
11 - */
12 -class P_Ban extends P_Core {
13 -
14 - /**
15 - * Add the actions required for determining the ban.
16 - *
17 - * @param Patchstack $core
18 - * @return void
19 - */
20 - public function __construct( $core ) {
21 - parent::__construct( $core );
22 -
23 - if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) {
24 - return;
25 - }
26 -
27 - add_action( 'init', [ $this, 'ip_ban' ], ~PHP_INT_MAX + 1 );
28 - }
29 -
30 - /**
31 - * Determine if the IP address of the user is blocked.
32 - *
33 - * @return void
34 - */
35 - public function ip_ban() {
36 - if ( ! is_user_logged_in() && $this->is_ip_blocked( $this->get_ip() ) ) {
37 - $this->plugin->firewall_base->display_error_page( 22 );
38 - }
39 - }
40 -
41 - /**
42 - * Check IP ban.
43 - *
44 - * @param string $ip The IP address of the user.
45 - * @return boolean Whether or not the user is blocked.
46 - */
47 - public function is_ip_blocked( $ip ) {
48 - $ip_rules = $this->get_option( 'patchstack_ip_block_list', '' );
49 - if ( empty( $ip_rules ) ) {
50 - return false;
51 - }
52 -
53 - $blocked = false;
54 - $ip_rules = explode( "\n", $ip_rules );
55 - foreach ( $ip_rules as $blocked_ip ) {
56 - $blocked_ip = trim( $blocked_ip );
57 - if ( strpos( $blocked_ip, '*' ) !== false ) {
58 - $blocked = $this->check_wildcard_rule( $ip, $blocked_ip );
59 - } elseif ( strpos( $blocked_ip, '-' ) !== false ) {
60 - $blocked = $this->check_range_rule( $ip, $blocked_ip );
61 - } elseif ( strpos( $blocked_ip, '/' ) !== false ) {
62 - $blocked = $this->check_subnet_mask_rule( $ip, $blocked_ip );
63 - } elseif ( $ip == $blocked_ip ) {
64 - return true;
65 - }
66 -
67 - if ( $blocked ) {
68 - return true;
69 - }
70 - }
71 -
72 - return $blocked;
73 - }
74 -
75 - /**
76 - * Check IP whitelist for login protection.
77 - *
78 - * @param string $ip The IP address of the user.
79 - * @return boolean Whether or not the user is whitelisted.
80 - */
81 - public function is_ip_whitelisted( $ip ) {
82 - $ipRules = explode( "\n", $this->get_option( 'patchstack_login_whitelist', '' ) );
83 - if ( empty( $ipRules ) ) {
84 - return true;
85 - }
86 -
87 - $whitelisted = false;
88 - foreach ( $ipRules as $ipRule ) {
89 - $ipRule = trim( $ipRule );
90 - if ( strpos( $ipRule, '*' ) !== false ) {
91 - $whitelisted = $this->check_wildcard_rule( $ip, $ipRule );
92 - } elseif ( strpos( $ipRule, '-' ) !== false ) {
93 - $whitelisted = $this->check_range_rule( $ip, $ipRule );
94 - } elseif ( strpos( $ipRule, '/' ) !== false ) {
95 - $whitelisted = $this->check_subnet_mask_rule( $ip, $ipRule );
96 - } elseif ( $ip == $ipRule ) {
97 - return true;
98 - }
99 -
100 - if ( $whitelisted ) {
101 - return true;
102 - }
103 - }
104 -
105 - return $whitelisted;
106 - }
107 -
108 - /**
109 - * CIDR notation IP block check.
110 - *
111 - * @param string $ip The IP address of the user.
112 - * @param string $range The range to check.
113 - * @return boolean Whether or not the IP is in the range.
114 - */
115 - public function check_subnet_mask_rule( $ip, $range ) {
116 - list($range, $netmask) = explode( '/', $range, 2 );
117 -
118 - // A malformed netmask (e.g. "1.2.3.4/abc") would throw a TypeError on the
119 - // arithmetic below on PHP 8; treat anything outside 0-32 as a non-match.
120 - if ( ! is_numeric( $netmask ) || $netmask < 0 || $netmask > 32 ) {
121 - return false;
122 - }
123 - $netmask = (int) $netmask;
124 -
125 - $range_decimal = ip2long( $range );
126 - $ip_decimal = ip2long( $ip );
127 - $wildcard_decimal = pow( 2, ( 32 - $netmask ) ) - 1;
128 - $netmask_decimal = ~ $wildcard_decimal;
129 - return ( ( $ip_decimal & $netmask_decimal ) == ( $range_decimal & $netmask_decimal ) );
130 - }
131 -
132 - /**
133 - * Wildcard IP block check.
134 - *
135 - * @param string $ip The IP address of the user.
136 - * @param string $rule The wildcard range to check against.
137 - * @return boolean Whether or not the IP is in the wilcard range.
138 - */
139 - public function check_wildcard_rule( $ip, $rule ) {
140 - $match = explode( '*', $rule );
141 - $match = $match[0];
142 - return ( substr( $ip, 0, strlen( $match ) ) == $match );
143 - }
144 -
145 - /**
146 - * IP range block check.
147 - *
148 - * @param string|array $ip The IP address of the user.
149 - * @param string $rule The range to check against.
150 - * @return boolean Whether or not the IP is in the range.
151 - */
152 - public function check_range_rule( $ip, $rule ) {
153 - // Check if client has multiple IPs
154 - if ( is_array( $ip ) ) {
155 - $ip = $ip[0];
156 - }
157 -
158 - $first_ip = explode( '-', $rule );
159 - $second_ip = explode( '-', $rule );
160 -
161 - $start_ip = ip2long( $first_ip[0] );
162 - $end_ip = ip2long( $second_ip[1] );
163 - $request_ip = ip2long( $ip );
164 -
165 - return ( $request_ip >= $start_ip && $request_ip <= $end_ip );
166 - }
167 -}
1 +<?php
2 +
3 +// Do not allow the file to be called directly.
4 +if ( ! defined( 'ABSPATH' ) ) {
5 + exit;
6 +}
7 +
8 +/**
9 + * This class is used to determine if the IP address of the
10 + * user is banned. Along with that we check the IP address whitelist.
11 + */
12 +class P_Ban extends P_Core {
13 +
14 + /**
15 + * Add the actions required for determining the ban.
16 + *
17 + * @param Patchstack $core
18 + * @return void
19 + */
20 + public function __construct( $core ) {
21 + parent::__construct( $core );
22 +
23 + if ( $this->get_option( 'patchstack_license_free', 0 ) == 1 ) {
24 + return;
25 + }
26 +
27 + add_action( 'init', array( $this, 'ip_ban' ), ~PHP_INT_MAX + 1 );
28 + }
29 +
30 + /**
31 + * Determine if the IP address of the user is blocked.
32 + *
33 + * @return void
34 + */
35 + public function ip_ban() {
36 + if ( ! is_user_logged_in() && $this->is_ip_blocked( $this->get_ip() ) ) {
37 + $this->plugin->firewall_base->display_error_page( 22 );
38 + }
39 + }
40 +
41 + /**
42 + * Check IP ban.
43 + *
44 + * @param string $ip The IP address of the user.
45 + * @return boolean Whether or not the user is blocked.
46 + */
47 + public function is_ip_blocked( $ip ) {
48 + $ip_rules = $this->get_option( 'patchstack_ip_block_list', '' );
49 + if ( empty( $ip_rules ) ) {
50 + return false;
51 + }
52 +
53 + $blocked = false;
54 + $ip_rules = explode( "\n", $ip_rules );
55 + foreach ( $ip_rules as $blocked_ip ) {
56 + $blocked_ip = trim( $blocked_ip );
57 + if ( strpos( $blocked_ip, '*' ) !== false ) {
58 + $blocked = $this->check_wildcard_rule( $ip, $blocked_ip );
59 + } elseif ( strpos( $blocked_ip, '-' ) !== false ) {
60 + $blocked = $this->check_range_rule( $ip, $blocked_ip );
61 + } elseif ( strpos( $blocked_ip, '/' ) !== false ) {
62 + $blocked = $this->check_subnet_mask_rule( $ip, $blocked_ip );
63 + } elseif ( $ip == $blocked_ip ) {
64 + return true;
65 + }
66 +
67 + if ( $blocked ) {
68 + return true;
69 + }
70 + }
71 +
72 + return $blocked;
73 + }
74 +
75 + /**
76 + * Check IP whitelist for login protection.
77 + *
78 + * @param string $ip The IP address of the user.
79 + * @return boolean Whether or not the user is whitelisted.
80 + */
81 + public function is_ip_whitelisted( $ip ) {
82 + $ipRules = explode( "\n", $this->get_option( 'patchstack_login_whitelist', '' ) );
83 + if ( empty( $ipRules ) ) {
84 + return true;
85 + }
86 +
87 + $whitelisted = false;
88 + foreach ( $ipRules as $ipRule ) {
89 + if ( strpos( $ipRule, '*' ) !== false ) {
90 + $whitelisted = $this->check_wildcard_rule( $ip, $ipRule );
91 + } elseif ( strpos( $ipRule, '-' ) !== false ) {
92 + $whitelisted = $this->check_range_rule( $ip, $ipRule );
93 + } elseif ( strpos( $ipRule, '/' ) !== false ) {
94 + $whitelisted = $this->check_subnet_mask_rule( $ip, $ipRule );
95 + } elseif ( $ip == $ipRule ) {
96 + return true;
97 + }
98 +
99 + if ( $whitelisted ) {
100 + return true;
101 + }
102 + }
103 +
104 + return $whitelisted;
105 + }
106 +
107 + /**
108 + * CIDR notation IP block check.
109 + *
110 + * @param string $ip The IP address of the user.
111 + * @param string $range The range to check.
112 + * @return boolean Whether or not the IP is in the range.
113 + */
114 + public function check_subnet_mask_rule( $ip, $range ) {
115 + list($range, $netmask) = explode( '/', $range, 2 );
116 + $range_decimal = ip2long( $range );
117 + $ip_decimal = ip2long( $ip );
118 + $wildcard_decimal = pow( 2, ( 32 - $netmask ) ) - 1;
119 + $netmask_decimal = ~ $wildcard_decimal;
120 + return ( ( $ip_decimal & $netmask_decimal ) == ( $range_decimal & $netmask_decimal ) );
121 + }
122 +
123 + /**
124 + * Wildcard IP block check.
125 + *
126 + * @param string $ip The IP address of the user.
127 + * @param string $rule The wildcard range to check against.
128 + * @return boolean Whether or not the IP is in the wilcard range.
129 + */
130 + public function check_wildcard_rule( $ip, $rule ) {
131 + $match = explode( '*', $rule );
132 + $match = $match[0];
133 + return ( substr( $ip, 0, strlen( $match ) ) == $match );
134 + }
135 +
136 + /**
137 + * IP range block check.
138 + *
139 + * @param string|array $ip The IP address of the user.
140 + * @param string $rule The range to check against.
141 + * @return boolean Whether or not the IP is in the range.
142 + */
143 + public function check_range_rule( $ip, $rule ) {
144 + // Check if client has multiple IPs
145 + if ( is_array( $ip ) ) {
146 + $ip = $ip[0];
147 + }
148 +
149 + $first_ip = explode( '-', $rule );
150 + $second_ip = explode( '-', $rule );
151 +
152 + $start_ip = ip2long( $first_ip[0] );
153 + $end_ip = ip2long( $second_ip[1] );
154 + $request_ip = ip2long( $ip );
155 +
156 + return ( $request_ip >= $start_ip && $request_ip <= $end_ip );
157 + }
158 +}