| @@ -41,9 +41,28 @@ | ||
| 41 | 41 | $current_options = get_option( Vigilante_Settings::OPTION_NAME ); |
| 42 | 42 | |
| 43 | 43 | if ( false === $current_options ) { |
| 44 | 44 | // First installation - set defaults |
| 45 | - update_option( Vigilante_Settings::OPTION_NAME, $settings->get_default_options() ); | |
| 45 | + $first_run = $settings->get_default_options(); | |
| 46 | + | |
| 47 | + /* | |
| 48 | + * XML-RPC on a brand new install: block the pingback methods, which is | |
| 49 | + * what gets abused for amplification, and leave the rest reachable so | |
| 50 | + * the WordPress app, Jetpack or a remote manager keep working out of | |
| 51 | + * the box. Disabling it completely is the stricter choice and the one | |
| 52 | + * the settings screen recommends, but it is not imposed on a site that | |
| 53 | + * never asked for it. Brute force through XML-RPC stays covered either | |
| 54 | + * way, because those logins go through wp_authenticate() and the login | |
| 55 | + * lockout hooks into it. | |
| 56 | + * | |
| 57 | + * Only written here, on a first installation. Sites upgrading keep | |
| 58 | + * whatever they had: the activation hook does not run on an update, and | |
| 59 | + * Vigilante_Comment_Security::resolve_xmlrpc_mode() answers 'full' when | |
| 60 | + * nothing is stored, which is what every version since 1.0.0 did. | |
| 61 | + */ | |
| 62 | + $first_run = Vigilante_Settings::apply_install_tweaks( $first_run ); | |
| 63 | + | |
| 64 | + update_option( Vigilante_Settings::OPTION_NAME, $first_run ); | |
| 46 | 65 | // Refresh settings instance to get new values |
| 47 | 66 | $settings->clear_cache(); |
| 48 | 67 | $settings = new Vigilante_Settings(); |
| 49 | 68 | } else { |
| @@ -53,11 +72,8 @@ | ||
| 53 | 72 | $settings = new Vigilante_Settings(); |
| 54 | 73 | } |
| 55 | 74 | } |
| 56 | 75 | |
| 57 | - // Create backup of current files FIRST (before any modifications) | |
| 58 | - self::create_activation_backup( $settings ); | |
| 59 | - | |
| 60 | 76 | // Apply htaccess protection (part of firewall module) |
| 61 | 77 | if ( $settings->is_module_enabled( 'firewall' ) ) { |
| 62 | 78 | self::apply_htaccess_protection( $settings ); |
| 63 | 79 | } |
| @@ -90,8 +106,11 @@ | ||
| 90 | 106 | |
| 91 | 107 | // Schedule cron events |
| 92 | 108 | self::schedule_events(); |
| 93 | 109 | |
| 110 | + // Capture the self-integrity anchor (A3: manifest fingerprint in DB). | |
| 111 | + self::anchor_self_integrity( $settings ); | |
| 112 | + | |
| 94 | 113 | // Set activation transient for admin notice |
| 95 | 114 | set_transient( 'vigilante_activated', true, 30 ); |
| 96 | 115 | |
| 97 | 116 | // Store activation time |
| @@ -107,8 +126,35 @@ | ||
| 107 | 126 | ob_end_clean(); |
| 108 | 127 | } |
| 109 | 128 | |
| 110 | 129 | /** |
| 130 | + * Anchor the self-integrity check on activation | |
| 131 | + * | |
| 132 | + * The first activation captures the fingerprint of the shipped manifest, | |
| 133 | + * unless WordPress.org distributes something else for that version, so | |
| 134 | + * the self-check has a baseline from the very first run. A | |
| 135 | + * reactivation keeps the anchor it already has and checks against it: | |
| 136 | + * capturing again adopted whatever manifest the folder held at that | |
| 137 | + * moment, a regenerated one included, the same reason the critical files | |
| 138 | + * baseline is not thrown away on reactivation. | |
| 139 | + * | |
| 140 | + * @since 3.0.0 | |
| 141 | + * | |
| 142 | + * @param Vigilante_Settings $settings Settings instance. | |
| 143 | + * @return void | |
| 144 | + */ | |
| 145 | + public static function anchor_self_integrity( $settings ) { | |
| 146 | + if ( ! class_exists( 'Vigilante_Self_Integrity' ) ) { | |
| 147 | + require_once VIGILANTE_INCLUDES_DIR . 'class-self-integrity.php'; | |
| 148 | + } | |
| 149 | + // run_check() captures on the first run itself, but only when | |
| 150 | + // WordPress.org does not contradict the manifest; with an anchor already | |
| 151 | + // there it checks against it. | |
| 152 | + $self_integrity = new Vigilante_Self_Integrity( $settings ); | |
| 153 | + $self_integrity->run_check( 'activation' ); | |
| 154 | + } | |
| 155 | + | |
| 156 | + /** | |
| 111 | 157 | * Idempotent migrations for existing installations. |
| 112 | 158 | * |
| 113 | 159 | * @param array $current_options Current vigilante_options array. |
| 114 | 160 | * @return bool True if any migration changed the stored option. |
| @@ -207,25 +253,8 @@ | ||
| 207 | 253 | return true; |
| 208 | 254 | } |
| 209 | 255 | |
| 210 | 256 | /** |
| 211 | - * Create backup of important files | |
| 212 | - * | |
| 213 | - * @param Vigilante_Settings $settings Settings instance. | |
| 214 | - */ | |
| 215 | - private static function create_activation_backup( $settings ) { | |
| 216 | - require_once VIGILANTE_INCLUDES_DIR . 'class-backup-manager.php'; | |
| 217 | - | |
| 218 | - $backup_manager = new Vigilante_Backup_Manager(); | |
| 219 | - $result = $backup_manager->create_backups(); | |
| 220 | - | |
| 221 | - if ( is_wp_error( $result ) ) { | |
| 222 | - // Store error for admin notice | |
| 223 | - set_transient( 'vigilante_backup_error', $result->get_error_message(), 60 ); | |
| 224 | - } | |
| 225 | - } | |
| 226 | - | |
| 227 | - /** | |
| 228 | 257 | * Apply htaccess protection |
| 229 | 258 | * |
| 230 | 259 | * @param Vigilante_Settings $settings Settings instance. |
| 231 | 260 | */ |
| @@ -231,8 +260,9 @@ | ||
| 231 | 260 | */ |
| 232 | 261 | private static function apply_htaccess_protection( $settings ) { |
| 233 | 262 | // Only apply if Apache server |
| 234 | 263 | if ( ! self::is_apache() ) { |
| 264 | + self::mark_server_files_pending(); | |
| 235 | 265 | return; |
| 236 | 266 | } |
| 237 | 267 | |
| 238 | 268 | require_once VIGILANTE_INCLUDES_DIR . 'class-htaccess-protection.php'; |
| @@ -248,8 +278,9 @@ | ||
| 248 | 278 | */ |
| 249 | 279 | private static function apply_security_headers( $settings ) { |
| 250 | 280 | // Only apply if Apache server |
| 251 | 281 | if ( ! self::is_apache() ) { |
| 282 | + self::mark_server_files_pending(); | |
| 252 | 283 | return; |
| 253 | 284 | } |
| 254 | 285 | |
| 255 | 286 | require_once VIGILANTE_INCLUDES_DIR . 'class-security-headers.php'; |
| @@ -313,8 +344,14 @@ | ||
| 313 | 344 | * |
| 314 | 345 | * @param Vigilante_Settings $settings Settings instance. |
| 315 | 346 | */ |
| 316 | 347 | private static function remove_sensitive_files( $settings ) { |
| 348 | + // They sit in the root every site of a network shares. Until 2.11.6 the | |
| 349 | + // activation on any site removed them. | |
| 350 | + if ( ! Vigilante_Settings::can_write_shared_files() ) { | |
| 351 | + return; | |
| 352 | + } | |
| 353 | + | |
| 317 | 354 | $advanced = $settings->get_section( 'advanced' ); |
| 318 | 355 | |
| 319 | 356 | // Remove readme.html |
| 320 | 357 | if ( ! empty( $advanced['remove_readme'] ) ) { |
| @@ -354,9 +391,15 @@ | ||
| 354 | 391 | $database = new Vigilante_Database(); |
| 355 | 392 | $activity_log = null; // Not needed for baseline generation |
| 356 | 393 | |
| 357 | 394 | $fi = new Vigilante_File_Integrity( $settings, $database, $activity_log ); |
| 358 | - $fi->regenerate_all_baselines(); | |
| 395 | + | |
| 396 | + // Same care as the migration: reactivating the plugin on a site that | |
| 397 | + // already has an approved baseline must not throw it away and adopt | |
| 398 | + // whatever the files say today. | |
| 399 | + if ( ! $fi->get_critical_files_baseline() ) { | |
| 400 | + $fi->regenerate_all_baselines(); | |
| 401 | + } | |
| 359 | 402 | } |
| 360 | 403 | |
| 361 | 404 | /** |
| 362 | 405 | * Schedule cron events |
| @@ -452,12 +495,50 @@ | ||
| 452 | 495 | * |
| 453 | 496 | * @return bool |
| 454 | 497 | */ |
| 455 | 498 | private static function is_apache() { |
| 456 | - if ( ! function_exists( 'apache_get_modules' ) ) { | |
| 457 | - // Check server software | |
| 458 | - $server = isset( $_SERVER['SERVER_SOFTWARE'] ) ? sanitize_text_field( wp_unslash( $_SERVER['SERVER_SOFTWARE'] ) ) : ''; | |
| 459 | - return stripos( $server, 'apache' ) !== false || stripos( $server, 'litespeed' ) !== false; | |
| 499 | + require_once VIGILANTE_INCLUDES_DIR . 'class-htaccess-manager.php'; | |
| 500 | + | |
| 501 | + // One detection for the whole plugin. This used to be a second copy of | |
| 502 | + // the same logic, so fixing one never fixed the other. | |
| 503 | + return Vigilante_Htaccess_Manager::get_instance()->is_apache(); | |
| 504 | + } | |
| 505 | + | |
| 506 | + /** | |
| 507 | + * Leave the server layer pending when the server could not be identified | |
| 508 | + * | |
| 509 | + * An activation from WP-CLI has no request to read the server software | |
| 510 | + * from, so before 2.9.9 the two apply_* guards below simply returned and | |
| 511 | + * the site was left without the .htaccess layer, with every switch showing | |
| 512 | + * as on. Now it is written down, so the first web request applies it, and | |
| 513 | + * it is logged, so it is visible that it happened. | |
| 514 | + * | |
| 515 | + * @since 2.9.9 | |
| 516 | + */ | |
| 517 | + private static function mark_server_files_pending() { | |
| 518 | + require_once VIGILANTE_INCLUDES_DIR . 'class-htaccess-manager.php'; | |
| 519 | + | |
| 520 | + // On a server known not to be Apache there is nothing to write, ever. | |
| 521 | + if ( ! Vigilante_Htaccess_Manager::get_instance()->server_is_unknown() ) { | |
| 522 | + return; | |
| 460 | 523 | } |
| 461 | - return true; | |
| 524 | + | |
| 525 | + update_option( 'vigilante_server_files_pending', 1 ); | |
| 526 | + | |
| 527 | + // The activation runs before the plugin has loaded its own files, so | |
| 528 | + // every link of the chain has to be pulled in: the log asks the database | |
| 529 | + // for the client IP, and that resolves it through the IP helper. | |
| 530 | + require_once VIGILANTE_INCLUDES_DIR . 'class-ip-utils.php'; | |
| 531 | + require_once VIGILANTE_INCLUDES_DIR . 'class-database.php'; | |
| 532 | + require_once VIGILANTE_INCLUDES_DIR . 'class-activity-log.php'; | |
| 533 | + | |
| 534 | + $settings = new Vigilante_Settings(); | |
| 535 | + $activity_log = new Vigilante_Activity_Log( $settings, new Vigilante_Database() ); | |
| 536 | + $activity_log->log( | |
| 537 | + 'system', | |
| 538 | + 'server_rules_pending', | |
| 539 | + __( 'The server type could not be identified from this request, so the .htaccess rules were left pending and will be written on the first web request.', 'vigilante' ), | |
| 540 | + array( 'sapi' => PHP_SAPI ), | |
| 541 | + 'warning' | |
| 542 | + ); | |
| 462 | 543 | } |
| 463 | 544 | } |