/var/www/html/wp-content/plugins/wp-cerber/

OS : Linux

PHP Version : 7.4.33

Software : Apache/2.4.6 (CentOS) PHP/7.4.33

Information System : Linux apprendre2 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64

Disable Function : The variable {TRIGGER.IP} contains the blocked IP address, the variable {TRIGGER.reason} contains the reason why. '; public static $fields = array( 'filter' => array( 'type' => 'group', 'fields' => array( 'locks' => array( 'type' => 'text', 'label' => 'Start if an IP address has been locked out more than times', 'default' => '0', 'autocomplete' => 0 ), 'period' => array( 'type' => 'text', 'label' => 'in the last minutes', 'default' => '60', 'autocomplete' => 0 ), ) ), 'limit' => array( 'type' => 'text', 'label' => 'Start if the number of currently locked out IP addresses is greater than', 'default' => '0', 'required' => 1, 'autocomplete' => 0 ), ); function execute( $fields ) { global $wpdb; list ( $fields, $previous, $env, $wp_arguments ) = func_get_args(); if ( cerber_blocked_num() <= absint( $fields['limit'] ) ) { return new WF_Stop( __CLASS__ ); } if ( ! empty( $fields['filter']['locks'] ) ) { $locks = absint( $fields['filter']['locks'] ); } else { $locks = 0; } if ( $locks > 0 ) { $ip = $wp_arguments[0]['IP']; $stamp = time() - absint( $fields['filter']['period'] ) * 60; $lockouts = $wpdb->get_var( $wpdb->prepare( 'SELECT count(ip) FROM ' . CERBER_LOG_TABLE . ' WHERE ip = %s AND activity IN (10,11) AND stamp > %d', $ip, $stamp ) ); $lockouts = absint( $lockouts ); if ( ! $lockouts || $lockouts <= $locks ) { return new WF_Stop( __CLASS__ ); } } return $wp_arguments[0]; } static function getStarterInfo( $config, $context ) { return 'After IP address has been locked out by Cerber'; } } class WF_WHOIS extends WF_Action { public static $section = 'network'; public static $name = 'Get WHOIS info'; public static $description = 'Get extended information about IP address'; public static $form_help = ' Sends request to a WHOIS server and retrieves details about a given IP address. The WHOIS information is publicly available and provided for free. There are no reasons for security concerns, because a list of WHOIS servers are maintained by ICANN.

Bear in mind that each WHOIS request takes some time to retrieve data from the remote WHOIS server. A request can take up to 500 ms approximately, so the workflow will be waiting all this time for a response.

The result is a list. To get a country name in the next action, use variable {PREVIOUS.country-name}, for the two-letter country code: {PREVIOUS.country}, for the abuse email address: {PREVIOUS.abuse-mailbox}, for the network as IP range: {PREVIOUS.inetnum}. The full list of available fields depends on a network owner. You can request WHOIS data manually to find out what kind of fields are available on this page: http://wq.apnic.net/apnic-bin/whois.pl. '; public static $fields = array( 'ip' => array( 'type' => 'text', 'label' => 'IP address', 'default' => '{TRIGGER.IP}', 'required' => 1, ), ); function execute( $fields ) { list ( $fields, $previous, $env, $wp_arguments ) = func_get_args(); $ip = filter_var( $fields['ip'], FILTER_VALIDATE_IP ); if ( ! $ip ) { return false; } $whois = cerber_ip_whois_info( $ip ); if ( ! empty( $whois['error'] ) ) { return new WF_Error ( __CLASS__, 'Unable to obtain IP info' ); } $ret = $whois['data']; if ( empty( $ret['abuse-mailbox'] ) && ! empty( $ret['OrgAbuseEmail'] ) ) { $ret['abuse-mailbox'] = $ret['OrgAbuseEmail']; } if ( ! is_email( $ret['abuse-mailbox'] ) ) { $ret['abuse-mailbox'] = ''; } $ret['country-name'] = cerber_country_name( $ret['country'] ); return $ret; } } wof_register( array( 'TR_IP_Locked', 'WF_WHOIS' ) ); }