PluginProbe
WebTotem Security / 2.4.29
WebTotem Security v2.4.29
3.0.1 3.0.0 trunk 1.0 1.1 1.2 1.3 1.3.1 1.3.2 1.3.3 2.0 2.1 2.1.1 2.1.2 2.1.3 2.1.4 2.1.5 2.1.6 2.1.7 2.1.8 2.1.9 2.2.1 2.2.2 2.2.3 2.2.4 All 109 releases
wt-security / src / Common.php

Common.php in WebTotem Security 2.4.29, at src/Common.php

266 lines 10.7 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 if (!defined('WEBTOTEM_INIT') || WEBTOTEM_INIT !== true) {
4 if (!headers_sent()) {
5 header('HTTP/1.1 403 Forbidden');
6 }
7 die("Protected By WebTotem!");
8 }
9
10 add_action('upgrader_process_complete', 'wt_security_upgrade_complete', 10, 2);
11 function wt_security_upgrade_complete($upgrader, $options)
12 {
13 /**
14 * Creating a marker file after updating the plugin.
15 */
16 if ($options['type'] === 'plugin' && $options['action'] === 'update' && $upgrader->result['destination_name'] == 'wt-security') {
17 WebTotemAgentManager::generateMarkerFile();
18 }
19
20 /**
21 * Check CVE list after install or update plugin.
22 */
23 if ($options['type'] === 'plugin' && ($options['action'] === 'update' || $options['action'] === 'install')){
24 WebTotem::updateCveDataByPluginName($upgrader->new_plugin_data);
25 }
26 }
27
28 /**
29 * Remove CVE from list after plugin delete.
30 */
31 add_action( 'deleted_plugin', 'wt_security_deleted_plugin_action', 10, 2 );
32 function wt_security_deleted_plugin_action( $plugin_file, $deleted ){
33 if($deleted){
34 $slug = str_replace('.php', '', basename($plugin_file));
35 if($slug != 'wt-security'){
36 WebTotemDB::deleteData(['slug' => $slug], 'plugins_cve_list');
37 }
38 }
39 }
40
41 if (defined('WEBTOTEM')) {
42
43 /**
44 * Define which javascript and css files will be loaded in the header of the plugin pages.
45 */
46 $_page = WebTotemRequest::get('page');
47 if (strpos($_page, 'wtotem') === 0) {
48 add_action('admin_enqueue_scripts', 'WebTotemInterface::enqueueScripts', 1);
49 }
50
51 add_filter('pre_current_active_plugins', 'WebTotemInterface::registerDeletePrompt');
52
53 /** Define role of current user */
54 add_action('init', 'WebTotem::getUserRole');
55
56 /** Execute pre-checks before every page */
57 add_action('init', 'WebTotemInterface::startupChecks');
58
59 /** Attach HTTP request handlers for the AJAX requests */
60 add_action('wp_ajax_nopriv_wtotem_ajax', 'wtotem_public_ajax_callback');
61 add_action('wp_ajax_wtotem_ajax', 'wtotem_ajax_callback');
62
63 if (WebTotemOption::isActivated()) {
64 if (WebTotemCaptcha::isEnabled() or WebTotemLogin::anyTwoFactorActivated()) {
65 /** Login Page */
66 add_action('login_enqueue_scripts', 'WebTotemInterface::loginEnqueueScripts');
67 }
68
69 /** Add authenticate filter */
70 add_filter('authenticate', 'WebTotemInterface::wt_authenticate', 25, 3);
71
72 /** Add lostpassword filter */
73 add_action('lostpassword_errors', 'WebTotemInterface::wt_lost_password', 1, 2);
74
75 /** Add site or new sites if it is multisite */
76 add_action('wp_insert_site', 'WebTotemInterface::addNewSite');
77 }
78
79 if (WebTotemOption::getPluginSettings('hide_wp_version')) {
80 /** Restore readme file before WP update, then after update hide readme file */
81 add_filter('update_feedback', 'WebTotemInterface::restoreReadmeWhenUpdating');
82
83 /** Remove the WordPress generator meta-tag from the source code. */
84 remove_action('wp_head', 'wp_generator');
85 }
86
87 /** User Profile */
88 global $pagenow;
89 if ('profile.php' === $pagenow or 'user-edit.php' === $pagenow) {
90 add_action('admin_enqueue_scripts', 'WebTotemInterface::enqueueScripts', 1);
91 add_action('show_user_profile', 'WebTotemInterface::add2faProfileForm');
92 add_action('edit_user_profile', 'WebTotemInterface::add2faProfileForm');
93 }
94
95 /** Launch of the daily cron. */
96 add_action('wp', 'webtotem_add_cron_');
97 function webtotem_add_cron_()
98 {
99 if (!wp_next_scheduled('webtotem_daily_cron')) {
100 wp_schedule_event(time(), 'daily', 'webtotem_daily_cron');
101 }
102 }
103
104 add_action('webtotem_daily_cron', 'WtotemDailyCron');
105
106 function WtotemDailyCron()
107 {
108 WebTotemOption::setOptions(['scan_init' => 1]);
109 WebTotem::updateCveData();
110 }
111
112 /** Launch of the minute cron. */
113 if (WebTotemOption::getOption('scan_init')) {
114
115 // Register the n minute interval
116 add_filter('cron_schedules', 'cron_add_some_min');
117 function cron_add_some_min($schedules)
118 {
119 $schedules['some_min'] = array(
120 'interval' => 60,
121 'display' => __('Every few minutes', 'wtotem'),
122 );
123 return $schedules;
124 }
125
126 // Registering an event
127 add_action('wp', 'wtotem_step_cron');
128 function wtotem_step_cron()
129 {
130 if (!wp_next_scheduled('wtotem_step_init_cron')) {
131 wp_schedule_event(time(), 'some_min', 'wtotem_step_init_cron');
132 }
133 }
134
135 // Linking the function to the cron event/task
136 add_action('wtotem_step_init_cron', 'WebTotemScan::initialize');
137 }
138
139 /**
140 * List an associative array with the sub-pages of this plugin.
141 *
142 * @return array List of sub-pages of this plugin.
143 */
144 function wtotemPages()
145 {
146 if (WebTotem::isMultiSite()) {
147 $pages['wtotem_all_sites'] = ['title' => __('All sites', 'wtotem'), 'slug' => 'wtotem'];
148 }
149 $slug = WebTotem::isMultiSite() ? 'wtotem_' : 'wtotem';
150
151 $pages['wtotem_dashboard'] = ['title' => __('Dashboard', 'wtotem'), 'slug' => $slug];
152 $pages['wtotem_open_paths'] = ['title' => __('Open paths', 'wtotem'), 'slug' => $slug];
153 $pages['wtotem_firewall'] = ['title' => __('Firewall', 'wtotem'), 'slug' => $slug];
154
155 if (!WebTotem::isMultiSite() or is_super_admin()) {
156 $pages['wtotem_antivirus'] = ['title' => __('Antivirus', 'wtotem'), 'slug' => $slug];
157 $pages['wtotem_settings'] = ['title' => __('Settings', 'wtotem'), 'slug' => $slug];
158 }
159 $pages['wtotem_reports'] = ['title' => __('Reports', 'wtotem'), 'slug' => $slug];
160 $pages['wtotem_documentation'] = ['title' => __('Documentation', 'wtotem'), 'slug' => 'wtotem'];
161 $pages['wtotem_wpscan'] = ['title' => __('WP scan', 'wtotem'), 'slug' => 'wtotem'];
162
163 return $pages;
164 }
165
166 if (function_exists('add_action')) {
167 /**
168 * Display extension menu and submenu items in the correct interface.
169 *
170 * @return void
171 */
172 function wtotemAddMenu()
173 {
174
175 $page = !WebTotemOption::isActivated() ? 'activation' : (WebTotem::isMultiSite() ? 'all_sites' : 'dashboard');
176
177 add_menu_page(
178 __('WebTotem', 'wtotem'),
179 __('WebTotem', 'wtotem'),
180 'manage_options',
181 'wtotem',
182 'wtotem_' . $page . '_page',
183 WebTotem::getImagePath('logo_17x17_w.png')
184 );
185
186 if (WebTotemOption::isActivated()) {
187 $pages = wtotemPages();
188 foreach ($pages as $sub_page_function => $sub_page) {
189 add_submenu_page(
190 $sub_page['slug'],
191 $sub_page['title'],
192 $sub_page['title'],
193 'manage_options',
194 $sub_page_function,
195 $sub_page_function . '_page'
196 );
197 }
198
199 } else {
200 add_submenu_page(
201 'wtotem',
202 __('Activation', 'wtotem'),
203 __('Activation', 'wtotem'),
204 'manage_options',
205 'wtotem_activation',
206 'wtotem_activation_page'
207 );
208 }
209 }
210
211 /* Attach HTTP request handlers for the internal plugin pages */
212 if (WebTotem::isMultiSite()) {
213 add_action('network_admin_menu', 'wtotemAddMenu');
214 }
215 add_action('admin_menu', 'wtotemAddMenu');
216 }
217
218 /**
219 * Event hooks.
220 *
221 */
222 if (class_exists('WebTotemEventListener')) {
223
224 add_action('add_user_to_blog', 'WebTotemEventListener::hookAddUserToBlog', 50, 4);
225
226 add_action('add_user_to_blog', 'WebTotemEventListener::hookAddUserToBlog', 50, 4);
227 add_action('remove_user_from_blog', 'WebTotemEventListener::hookRemoveUserFromBlog', 50, 2);
228 add_action('login_form_resetpass', 'WebTotemEventListener::hookLoginFormResetpass', 50, 5);
229 add_action('profile_update', 'WebTotemEventListener::hookProfileUpdate', 50, 5);
230 add_action('retrieve_password', 'WebTotemEventListener::hookRetrievePassword', 50, 5);
231 add_action('user_register', 'WebTotemEventListener::hookUserRegister', 50, 5);
232 add_action('deleted_user', 'WebTotemEventListener::hookUserDelete', 50, 3);
233 add_action('wp_login', 'WebTotemEventListener::hookLoginSuccess', 50, 5);
234 add_action('wp_login_failed', 'WebTotemEventListener::hookLoginFailure', 50, 5);
235 add_action('add_link', 'WebTotemEventListener::hookLinkAdd', 50, 5);
236 add_action('edit_link', 'WebTotemEventListener::hookLinkEdit', 50, 5);
237 add_action('create_category', 'WebTotemEventListener::hookCategoryCreate', 50, 5);
238 add_action('publish_post', 'WebTotemEventListener::hookPublishPost', 50, 5);
239 add_action('transition_post_status', 'WebTotemEventListener::hookPostStatus', 50, 3);
240 add_action('xmlrpc_publish_post', 'WebTotemEventListener::hookPublishPostXMLRPC', 50, 5);
241 add_action('before_delete_post', 'WebTotemEventListener::hookPostBeforeDelete', 50, 5);
242 add_action('delete_post', 'WebTotemEventListener::hookPostDelete', 50, 5);
243 add_action('wp_trash_post', 'WebTotemEventListener::hookPostTrash', 50, 5);
244 add_action('publish_page', 'WebTotemEventListener::hookPublishPage', 50, 5);
245 add_action('add_attachment', 'WebTotemEventListener::hookAttachmentAdd', 50, 5);
246 add_action('activated_plugin', 'WebTotemEventListener::hookPluginActivate', 50, 2);
247 add_action('deactivated_plugin', 'WebTotemEventListener::hookPluginDeactivate', 50, 2);
248 add_action('switch_theme', 'WebTotemEventListener::hookThemeSwitch', 50, 5);
249
250 add_action('admin_init', 'WebTotemEventListener::hookCoreUpdate');
251 add_action('admin_init', 'WebTotemEventListener::hookOptionsManagement');
252 add_action('admin_init', 'WebTotemEventListener::hookPluginDelete');
253 add_action('admin_init', 'WebTotemEventListener::hookPluginEditor');
254 add_action('admin_init', 'WebTotemEventListener::hookPluginInstall');
255 add_action('admin_init', 'WebTotemEventListener::hookPluginUpdate');
256 add_action('admin_init', 'WebTotemEventListener::hookThemeDelete');
257 add_action('admin_init', 'WebTotemEventListener::hookThemeEditor');
258 add_action('admin_init', 'WebTotemEventListener::hookThemeInstall');
259 add_action('admin_init', 'WebTotemEventListener::hookThemeUpdate');
260 add_action('admin_init', 'WebTotemEventListener::hookWidgetAdd');
261 add_action('admin_init', 'WebTotemEventListener::hookWidgetDelete');
262
263 }
264
265 }
266