| 1 |
<?php |
| 2 |
|
| 3 |
if (!defined('WEBTOTEM_INIT') || WEBTOTEM_INIT !== true) { |
| 4 |
if (!headers_sent()) { |
| 5 |
header('HTTP/1.1 403 Forbidden'); |
| 6 |
} |
| 7 |
die("Protected By WebTotem!"); |
| 8 |
} |
| 9 |
|
| 10 |
add_action('upgrader_process_complete', 'wt_security_upgrade_complete', 10, 2); |
| 11 |
function wt_security_upgrade_complete($upgrader, $options) |
| 12 |
{ |
| 13 |
/** |
| 14 |
* Creating a marker file after updating the plugin. |
| 15 |
*/ |
| 16 |
if ($options['type'] === 'plugin' && $options['action'] === 'update' && $upgrader->result['destination_name'] == 'wt-security') { |
| 17 |
WebTotemAgentManager::generateMarkerFile(); |
| 18 |
} |
| 19 |
|
| 20 |
/** |
| 21 |
* Check CVE list after install or update plugin. |
| 22 |
*/ |
| 23 |
if ($options['type'] === 'plugin' && ($options['action'] === 'update' || $options['action'] === 'install')){ |
| 24 |
WebTotem::updateCveDataByPluginName($upgrader->new_plugin_data); |
| 25 |
} |
| 26 |
} |
| 27 |
|
| 28 |
/** |
| 29 |
* Remove CVE from list after plugin delete. |
| 30 |
*/ |
| 31 |
add_action( 'deleted_plugin', 'wt_security_deleted_plugin_action', 10, 2 ); |
| 32 |
function wt_security_deleted_plugin_action( $plugin_file, $deleted ){ |
| 33 |
if($deleted){ |
| 34 |
$slug = str_replace('.php', '', basename($plugin_file)); |
| 35 |
if($slug != 'wt-security'){ |
| 36 |
WebTotemDB::deleteData(['slug' => $slug], 'plugins_cve_list'); |
| 37 |
} |
| 38 |
} |
| 39 |
} |
| 40 |
|
| 41 |
if (defined('WEBTOTEM')) { |
| 42 |
|
| 43 |
/** |
| 44 |
* Define which javascript and css files will be loaded in the header of the plugin pages. |
| 45 |
*/ |
| 46 |
$_page = WebTotemRequest::get('page'); |
| 47 |
if (strpos($_page, 'wtotem') === 0) { |
| 48 |
add_action('admin_enqueue_scripts', 'WebTotemInterface::enqueueScripts', 1); |
| 49 |
} |
| 50 |
|
| 51 |
add_filter('pre_current_active_plugins', 'WebTotemInterface::registerDeletePrompt'); |
| 52 |
|
| 53 |
/** Define role of current user */ |
| 54 |
add_action('init', 'WebTotem::getUserRole'); |
| 55 |
|
| 56 |
/** Execute pre-checks before every page */ |
| 57 |
add_action('init', 'WebTotemInterface::startupChecks'); |
| 58 |
|
| 59 |
/** Attach HTTP request handlers for the AJAX requests */ |
| 60 |
add_action('wp_ajax_nopriv_wtotem_ajax', 'wtotem_public_ajax_callback'); |
| 61 |
add_action('wp_ajax_wtotem_ajax', 'wtotem_ajax_callback'); |
| 62 |
|
| 63 |
if (WebTotemOption::isActivated()) { |
| 64 |
if (WebTotemCaptcha::isEnabled() or WebTotemLogin::anyTwoFactorActivated()) { |
| 65 |
/** Login Page */ |
| 66 |
add_action('login_enqueue_scripts', 'WebTotemInterface::loginEnqueueScripts'); |
| 67 |
} |
| 68 |
|
| 69 |
/** Add authenticate filter */ |
| 70 |
add_filter('authenticate', 'WebTotemInterface::wt_authenticate', 25, 3); |
| 71 |
|
| 72 |
/** Add lostpassword filter */ |
| 73 |
add_action('lostpassword_errors', 'WebTotemInterface::wt_lost_password', 1, 2); |
| 74 |
|
| 75 |
/** Add site or new sites if it is multisite */ |
| 76 |
add_action('wp_insert_site', 'WebTotemInterface::addNewSite'); |
| 77 |
} |
| 78 |
|
| 79 |
if (WebTotemOption::getPluginSettings('hide_wp_version')) { |
| 80 |
/** Restore readme file before WP update, then after update hide readme file */ |
| 81 |
add_filter('update_feedback', 'WebTotemInterface::restoreReadmeWhenUpdating'); |
| 82 |
|
| 83 |
/** Remove the WordPress generator meta-tag from the source code. */ |
| 84 |
remove_action('wp_head', 'wp_generator'); |
| 85 |
} |
| 86 |
|
| 87 |
/** User Profile */ |
| 88 |
global $pagenow; |
| 89 |
if ('profile.php' === $pagenow or 'user-edit.php' === $pagenow) { |
| 90 |
add_action('admin_enqueue_scripts', 'WebTotemInterface::enqueueScripts', 1); |
| 91 |
add_action('show_user_profile', 'WebTotemInterface::add2faProfileForm'); |
| 92 |
add_action('edit_user_profile', 'WebTotemInterface::add2faProfileForm'); |
| 93 |
} |
| 94 |
|
| 95 |
/** Launch of the daily cron. */ |
| 96 |
add_action('wp', 'webtotem_add_cron_'); |
| 97 |
function webtotem_add_cron_() |
| 98 |
{ |
| 99 |
if (!wp_next_scheduled('webtotem_daily_cron')) { |
| 100 |
wp_schedule_event(time(), 'daily', 'webtotem_daily_cron'); |
| 101 |
} |
| 102 |
} |
| 103 |
|
| 104 |
add_action('webtotem_daily_cron', 'WtotemDailyCron'); |
| 105 |
|
| 106 |
function WtotemDailyCron() |
| 107 |
{ |
| 108 |
WebTotemOption::setOptions(['scan_init' => 1]); |
| 109 |
WebTotem::updateCveData(); |
| 110 |
} |
| 111 |
|
| 112 |
/** Launch of the minute cron. */ |
| 113 |
if (WebTotemOption::getOption('scan_init')) { |
| 114 |
|
| 115 |
// Register the n minute interval |
| 116 |
add_filter('cron_schedules', 'cron_add_some_min'); |
| 117 |
function cron_add_some_min($schedules) |
| 118 |
{ |
| 119 |
$schedules['some_min'] = array( |
| 120 |
'interval' => 60, |
| 121 |
'display' => __('Every few minutes', 'wtotem'), |
| 122 |
); |
| 123 |
return $schedules; |
| 124 |
} |
| 125 |
|
| 126 |
// Registering an event |
| 127 |
add_action('wp', 'wtotem_step_cron'); |
| 128 |
function wtotem_step_cron() |
| 129 |
{ |
| 130 |
if (!wp_next_scheduled('wtotem_step_init_cron')) { |
| 131 |
wp_schedule_event(time(), 'some_min', 'wtotem_step_init_cron'); |
| 132 |
} |
| 133 |
} |
| 134 |
|
| 135 |
// Linking the function to the cron event/task |
| 136 |
add_action('wtotem_step_init_cron', 'WebTotemScan::initialize'); |
| 137 |
} |
| 138 |
|
| 139 |
/** |
| 140 |
* List an associative array with the sub-pages of this plugin. |
| 141 |
* |
| 142 |
* @return array List of sub-pages of this plugin. |
| 143 |
*/ |
| 144 |
function wtotemPages() |
| 145 |
{ |
| 146 |
if (WebTotem::isMultiSite()) { |
| 147 |
$pages['wtotem_all_sites'] = ['title' => __('All sites', 'wtotem'), 'slug' => 'wtotem']; |
| 148 |
} |
| 149 |
$slug = WebTotem::isMultiSite() ? 'wtotem_' : 'wtotem'; |
| 150 |
|
| 151 |
$pages['wtotem_dashboard'] = ['title' => __('Dashboard', 'wtotem'), 'slug' => $slug]; |
| 152 |
$pages['wtotem_open_paths'] = ['title' => __('Open paths', 'wtotem'), 'slug' => $slug]; |
| 153 |
$pages['wtotem_firewall'] = ['title' => __('Firewall', 'wtotem'), 'slug' => $slug]; |
| 154 |
|
| 155 |
if (!WebTotem::isMultiSite() or is_super_admin()) { |
| 156 |
$pages['wtotem_antivirus'] = ['title' => __('Antivirus', 'wtotem'), 'slug' => $slug]; |
| 157 |
$pages['wtotem_settings'] = ['title' => __('Settings', 'wtotem'), 'slug' => $slug]; |
| 158 |
} |
| 159 |
$pages['wtotem_reports'] = ['title' => __('Reports', 'wtotem'), 'slug' => $slug]; |
| 160 |
$pages['wtotem_documentation'] = ['title' => __('Documentation', 'wtotem'), 'slug' => 'wtotem']; |
| 161 |
$pages['wtotem_wpscan'] = ['title' => __('WP scan', 'wtotem'), 'slug' => 'wtotem']; |
| 162 |
|
| 163 |
return $pages; |
| 164 |
} |
| 165 |
|
| 166 |
if (function_exists('add_action')) { |
| 167 |
/** |
| 168 |
* Display extension menu and submenu items in the correct interface. |
| 169 |
* |
| 170 |
* @return void |
| 171 |
*/ |
| 172 |
function wtotemAddMenu() |
| 173 |
{ |
| 174 |
|
| 175 |
$page = !WebTotemOption::isActivated() ? 'activation' : (WebTotem::isMultiSite() ? 'all_sites' : 'dashboard'); |
| 176 |
|
| 177 |
add_menu_page( |
| 178 |
__('WebTotem', 'wtotem'), |
| 179 |
__('WebTotem', 'wtotem'), |
| 180 |
'manage_options', |
| 181 |
'wtotem', |
| 182 |
'wtotem_' . $page . '_page', |
| 183 |
WebTotem::getImagePath('logo_17x17_w.png') |
| 184 |
); |
| 185 |
|
| 186 |
if (WebTotemOption::isActivated()) { |
| 187 |
$pages = wtotemPages(); |
| 188 |
foreach ($pages as $sub_page_function => $sub_page) { |
| 189 |
add_submenu_page( |
| 190 |
$sub_page['slug'], |
| 191 |
$sub_page['title'], |
| 192 |
$sub_page['title'], |
| 193 |
'manage_options', |
| 194 |
$sub_page_function, |
| 195 |
$sub_page_function . '_page' |
| 196 |
); |
| 197 |
} |
| 198 |
|
| 199 |
} else { |
| 200 |
add_submenu_page( |
| 201 |
'wtotem', |
| 202 |
__('Activation', 'wtotem'), |
| 203 |
__('Activation', 'wtotem'), |
| 204 |
'manage_options', |
| 205 |
'wtotem_activation', |
| 206 |
'wtotem_activation_page' |
| 207 |
); |
| 208 |
} |
| 209 |
} |
| 210 |
|
| 211 |
/* Attach HTTP request handlers for the internal plugin pages */ |
| 212 |
if (WebTotem::isMultiSite()) { |
| 213 |
add_action('network_admin_menu', 'wtotemAddMenu'); |
| 214 |
} |
| 215 |
add_action('admin_menu', 'wtotemAddMenu'); |
| 216 |
} |
| 217 |
|
| 218 |
/** |
| 219 |
* Event hooks. |
| 220 |
* |
| 221 |
*/ |
| 222 |
if (class_exists('WebTotemEventListener')) { |
| 223 |
|
| 224 |
add_action('add_user_to_blog', 'WebTotemEventListener::hookAddUserToBlog', 50, 4); |
| 225 |
|
| 226 |
add_action('add_user_to_blog', 'WebTotemEventListener::hookAddUserToBlog', 50, 4); |
| 227 |
add_action('remove_user_from_blog', 'WebTotemEventListener::hookRemoveUserFromBlog', 50, 2); |
| 228 |
add_action('login_form_resetpass', 'WebTotemEventListener::hookLoginFormResetpass', 50, 5); |
| 229 |
add_action('profile_update', 'WebTotemEventListener::hookProfileUpdate', 50, 5); |
| 230 |
add_action('retrieve_password', 'WebTotemEventListener::hookRetrievePassword', 50, 5); |
| 231 |
add_action('user_register', 'WebTotemEventListener::hookUserRegister', 50, 5); |
| 232 |
add_action('deleted_user', 'WebTotemEventListener::hookUserDelete', 50, 3); |
| 233 |
add_action('wp_login', 'WebTotemEventListener::hookLoginSuccess', 50, 5); |
| 234 |
add_action('wp_login_failed', 'WebTotemEventListener::hookLoginFailure', 50, 5); |
| 235 |
add_action('add_link', 'WebTotemEventListener::hookLinkAdd', 50, 5); |
| 236 |
add_action('edit_link', 'WebTotemEventListener::hookLinkEdit', 50, 5); |
| 237 |
add_action('create_category', 'WebTotemEventListener::hookCategoryCreate', 50, 5); |
| 238 |
add_action('publish_post', 'WebTotemEventListener::hookPublishPost', 50, 5); |
| 239 |
add_action('transition_post_status', 'WebTotemEventListener::hookPostStatus', 50, 3); |
| 240 |
add_action('xmlrpc_publish_post', 'WebTotemEventListener::hookPublishPostXMLRPC', 50, 5); |
| 241 |
add_action('before_delete_post', 'WebTotemEventListener::hookPostBeforeDelete', 50, 5); |
| 242 |
add_action('delete_post', 'WebTotemEventListener::hookPostDelete', 50, 5); |
| 243 |
add_action('wp_trash_post', 'WebTotemEventListener::hookPostTrash', 50, 5); |
| 244 |
add_action('publish_page', 'WebTotemEventListener::hookPublishPage', 50, 5); |
| 245 |
add_action('add_attachment', 'WebTotemEventListener::hookAttachmentAdd', 50, 5); |
| 246 |
add_action('activated_plugin', 'WebTotemEventListener::hookPluginActivate', 50, 2); |
| 247 |
add_action('deactivated_plugin', 'WebTotemEventListener::hookPluginDeactivate', 50, 2); |
| 248 |
add_action('switch_theme', 'WebTotemEventListener::hookThemeSwitch', 50, 5); |
| 249 |
|
| 250 |
add_action('admin_init', 'WebTotemEventListener::hookCoreUpdate'); |
| 251 |
add_action('admin_init', 'WebTotemEventListener::hookOptionsManagement'); |
| 252 |
add_action('admin_init', 'WebTotemEventListener::hookPluginDelete'); |
| 253 |
add_action('admin_init', 'WebTotemEventListener::hookPluginEditor'); |
| 254 |
add_action('admin_init', 'WebTotemEventListener::hookPluginInstall'); |
| 255 |
add_action('admin_init', 'WebTotemEventListener::hookPluginUpdate'); |
| 256 |
add_action('admin_init', 'WebTotemEventListener::hookThemeDelete'); |
| 257 |
add_action('admin_init', 'WebTotemEventListener::hookThemeEditor'); |
| 258 |
add_action('admin_init', 'WebTotemEventListener::hookThemeInstall'); |
| 259 |
add_action('admin_init', 'WebTotemEventListener::hookThemeUpdate'); |
| 260 |
add_action('admin_init', 'WebTotemEventListener::hookWidgetAdd'); |
| 261 |
add_action('admin_init', 'WebTotemEventListener::hookWidgetDelete'); |
| 262 |
|
| 263 |
} |
| 264 |
|
| 265 |
} |
| 266 |
|