chuckingit
Forum Replies Created
-
@skvwp – thank you for the fix as it worked for me and error warning is gone … ditto here on hoping for fix with next release …
@scott – i was about to create a gist when i got an idea to use Notepad++ to compare the actual files myself … so i downloaded pods and leaflet-maps-maker plugins from wordpress.org and then downloaded the plugin files on my server and compared them locally …
conclusion = never mind as Notepad said the files were identical … meaning the pods/includes/general.php file (v2.4) on my server and the one from wordpress.org were identical … ditto for the leaflet-maps-marker file …
as fyi, i had re-run Wordfence scan this AM and it still complained about plugin files but this time around it did not show me the files nor the changes it saw like last night … too bad i did not think to take a screen shot last night of the changes Wordfence was showing …
@dlmweb – you might want to do similar as i in pulling down file from your site and comparing it locally to what is in zip from wordpress.org … if you don’t have Notepad++ (and are on windows) you can download here -> http://notepad-plus-plus.org/ … then go to Notepad -> Plugins -> Plugin Manager -> Show Plugin Manager and that will show a bunch of available plugins … check box for the Compare plugin to install, restart Notepad, then load the two files and see if there are any differences …
@dlmweb – thanks for your suggestion to rescan … i did (after i cleared logs and made a couple tweaks to scan options) … and after two scans, the second one yielded results in that it pointed to the offending files (see below) …
interesting in that bulk of complaints had to do with readme files … thus not sure if this is a WP update thing (e.g., readme’s not getting updated properly when plugin gets updated) or ..??..
e.g., the wordpress-importer/readme.txt flagged the “Tested up to: 3.8” and “Stable tag: 0.6.1” whereas the readme file on my server had “Tested up to: 3.6” and “Stable tag: 0.6” …
similar WordFence nitpicks with the other plugin readme files …
but two of the three php files flagged by WordFence are a bit worrisome … the loginlockdown.php file was modified by me and noted so for fine tuned error messages so that is okay … but the changes to pods/includes/general.php and leaflet-maps-marker/inc/showmap.php files are a bit concerning …
@zztype … ditto here on your “Had me all shook up!” … yeesh me too and fact i was bombarded today on other frustration web fronts (besides this WordFence one) had me longing for calm shores of Kona HI free of code and hacks but i digress …
@everybody … while there are many headlines reminding us what is broken in our world, Kudos and BIG Thanks to WP Community for these forums so we can share, improve, upgrade, et al :>) cordially, chuck scott
=======================================
from scan showing files with warnings
=======================================Warnings: * Modified plugin file: wp-content/plugins/bbpress/readme.txt * Modified plugin file: wp-content/plugins/exec-php/docs/readme.html * Modified plugin file: wp-content/plugins/exec-php/readme.txt * Modified plugin file: wp-content/plugins/imsanity/readme.txt * Modified plugin file: wp-content/plugins/leaflet-maps-marker/inc/showmap.php * Modified plugin file: wp-content/plugins/login-lockdown/loginlockdown.php * Modified plugin file: wp-content/plugins/meteor-slides/readme.txt * Modified plugin file: wp-content/plugins/multisite-user-management/readme.txt * Modified plugin file: wp-content/plugins/piklist/readme.txt * Modified plugin file: wp-content/plugins/pods/includes/general.php * Modified plugin file: wp-content/plugins/qr-code-hoerandl/readme.txt * Modified plugin file: wp-content/plugins/simply-exclude/readme.txt * Modified plugin file: wp-content/plugins/wordpress-importer/readme.txtditto here – when i look at the activity logs, they aren’t much help either in that they say a file appears to be malicious but does not say which file name (nor folder path) thus impossible to track down and double check (see below – partial clip from activity log – e.g., http://mysite.org/?_wfsf=viewActivityLog&nonce=0888e8f951) …
[Apr 24 13:43:24:1398361404.960558:2:info] Getting plugin list from WordPress [Apr 24 13:43:24:1398361404.526466:1:info] Contacting Wordfence to initiate scan [Apr 24 13:43:20:1398361400.802450:1:info] Scheduled Wordfence scan starting at Thursday 24th of April 2014 01:43:20 PM [Apr 24 12:05:16:1398355516.493076:2:info] Wordfence used 15.27MB of memory for scan. Server peak memory usage was: 37.65MB [Apr 24 12:05:16:1398355516.402732:1:info] Scan Complete. Scanned 7105 files, 59 plugins, 24 themes, 13 pages, 2 comments and 22925 records in 56 seconds. [Apr 24 12:05:16:1398355516.402481:1:info] ------------------- [Apr 24 12:05:16:1398355516.355055:2:info] The disk has 92501.64 MB space available [Apr 24 12:05:16:1398355516.354822:2:info] Total disk space: 144.5375GB -- Free disk space: 90.3336GB [Apr 24 12:05:16:1398355516.351035:2:info] Scanning DNS MX record for mysite.org [Apr 24 12:05:16:1398355516.345223:2:info] Scanning DNS A record for mysite.org [Apr 24 12:05:16:1398355516.335991:2:info] Starting DNS scan for mysite.org [Apr 24 12:05:16:1398355516.311882:2:info] Starting password strength check on 2 users. [Apr 24 12:05:16:1398355516.306506:2:info] Done host key check. [Apr 24 12:05:15:1398355515.883150:2:info] Checking 10 host keys against Wordfence scanning servers. [Apr 24 12:05:15:1398355515.861408:2:info] Done examining URls [Apr 24 12:05:15:1398355515.860833:2:info] Done host key check. [Apr 24 12:05:15:1398355515.346486:2:info] Checking 96 host keys against Wordfence scanning servers. [Apr 24 12:05:15:1398355515.343899:2:info] Examining URLs found in posts we scanned for dangerous websites [Apr 24 12:05:14:1398355514.890871:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.890228:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.889550:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.888893:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.888232:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.887572:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.886922:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.886264:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.885612:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.884888:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.884238:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.883511:2:info] Adding issue: This file appears to be malicious [Apr 24 12:05:14:1398355514.883114:2:info] Done file contents scan [Apr 24 12:05:13:1398355513.586091:2:info] Done URL check. [Apr 24 12:05:12:1398355512.868854:2:info] Checking 17 URLs from 15 sources. [Apr 24 12:05:12:1398355512.865998:2:info] Done host key check.@mark – wow – way cool on several fronts -> e.g.,
a) super fast response / info – thanks …
b) Wordfence team is on top of error – bravo …
c) glad to know errors were not me-centric :>0
d) loving Wordfence so thanks for update and ongoing improvements …
e) i appreciate these WordPress.org forums / codex where we can learn from each other …accordingly, kudos on all fronts and thanks again for info … cordially, chuck scott
Hi Scott – i did not have WP_DEBUG on when i initially posted this so i went back today to see if i could recreate error / bug and turned on WP_DEBUG but no, it showed no error in the log file and still generated Success: Updated custom field … yet my field was not updated, actually it was turned to blank from the previous value thus ended with no value after i ran the wp user-meta id fieldname fieldvalue …
on this page -> http://wp-cli.org/commands/user-meta/ – there is mention in example of using set but did not see that listed as subcommand so i tried using both update and set and got same – success message from command line but nada in the db table …
the other thing that is a bit odd is that even if i try to update a non-existant field, i still get success message … note i was trying to update a field called membershiptype but in one of my tests i did typo and left out i thus had membershptype and still got a Success message ..??..
so then i went back to my Pod and looked at my custom defined options and saw that i had spaces between the value | label … once i removed those spaces, value|label, then the user-meta update started to work … all of which kind of makes sense now why i was seeing blank in my db ..??.. however, if i did a user-update with a value not in the field list, i still got Success message but my previous value was returned to blank … meaning if the field table has three options (pro, rgular, disabled) and the user is set to pro, but then do user-meta update fieldname with value of dude (which is not in the list), then the pro value is removed, blank value is inserted and still a success message is generate which is a bit misleading …
okay so what does all this mean … i think the really big issue was me having trailing blank spaces in my custom defined options list … hence maybe Pods can scrub (trim blanks) before saving the Pod ..??.. not sure what can be done about false / misleading success message but i guess one could also argue that anybody doing command line should know better and only enter real values and real fields regardless of their typo sensitivies or not :0
i’m gonna mark this thread as resolved because the blank spaces were the culprit and the user-meta update works as planned provided one uses real field names with only one of the values in the custom defined list …
cordially, chuck scott
Update = Disregard my previous post as i believe my problem had too do with my ISP’s or router cache* and not WP, Wordfence, or other plugin, code, conflicts, etc …
note in total today i got locked out several times and it was after the initial time i got back in when i posted thread above thinking it had to do with Wordfence or WP but not so given the subsequent experiences …
as fyi … after i got locked out and unlocked back in, i then repeated the process of re-installing Wordfence, one by one with other steps and still locked out but this time my unlock steps of cleaning tables did not work …
it was only after i asked another person in other office in other state to try with same login credentials that were failing on two of my three client machines, and when that person could log in i realized it was a network thing most likely on my end …
so i uninstalled everything once again, rebuilt, repeated, rinsed, yada yada and then tried to login but still had issues on two of the three machines no matter what i did …
luck would have it that the wife brought her laptop home tonight so after dinner i asked her to fire up her laptop, hop on our wireless network, and OMG – she had no problem logging in with the very same user credentials that were blocked on two of my internal machines …
so once she got on, i then tried to re-log in on one of my erroneous machines and voila – now it could log in …
which leads me to conclude that the router cache (even though i reset it and did hard reboot after power down) or ISP* was doing something …
all of which kind of makes sense looking back as the WP login message was complaining about cookies not enabled which made no sense to me at the time …
but if the ISP* or router cache was serving something sans cookies, well then okay, i now get why that message … and i suspect that the wife’s machine hopping on my network forced the ISP/router cache to adjust (to the new gal) hence now all my machines can log on …
yeesh … what a day … cheers – chuck scott
*Maybe it was all an NSA thing that failed to clean up after its cache self in one of those nifty chip hacks they installed in Big Name High Speed Internet Provider Company modems and routers available at all the Electronic Big Box Stores Near everybody :>0
Awesome Support – Thank YOU!
great – just shot you an email so thanks and to be continued :>) cs
okay – i’ll take a stab at it as i’ve been testing both and took me some time to get my head around them … my sense is that both of these are GUI wrappers around core network functions … i say this because first i installed wp-multi-network and had issues … so then i deactivated and turned on networks-for-wordpress and tried my steps again but this plugin had tooltips that gave me some clues about the errors of my ways in previous plugin … plus this plugin also has a nifty little “check / test” function that allowed me to test the vars i entered to see if i got a green light … once i figured it out (parking domains within networks of networks that is on a multisite wp network) then i went back and deactivated both plugins … i found that my networks still resolved … now maybe if i waited two days or so to flush DNS cache i might have gotten different result but i don’t think so … it appears that once the network is created, it stays active even if the plugins are deactivate … which kind of makes sense as both of these plugins allow you to move sub sites from one network to another and then delete a network … so then i went back to wp-multi-network and reactivated that to see if it would conflict with the settings i had used with networks-for-wordpress and voila – if found all the same info and honored those networks … hence i thought “okay – this is akin to Justin Tadlock’s Members Plugin where he says it is more of a wrapper / gui for core features burried deep within WP” thus my sense is both of these plugins are similar -> wrappers for core features …
while i’m at it and for what ever its worth dept … i was a bit confused on the whole path thing but essentially both plugins are asking for four pieces of info ->
Network Name:
Network URL and path
Create a Main Site
Main Site Nameand to go back further, here is outline of my success steps ->
a) mothership domain … lets call the WP multisite network mothershipnetwork.com … and lets say i want to create a new newtork on mothershipnetwork.com called snoopy.com and have snoppy.com resolve to that new network within mothershipnetwork.com as it’s own domain plus be the root for any sub sites i might add to snoopy …
– note i am using subfolders and not subdomains but process should be similar …
b) start at server … using cPanel i went to mothershipnetwork.com and parked snoopy.com …
c) then i went to mothershipnetwork.com and used either plugin to create new network with the following settings ->
– Network Name = The I Love Snoopy Network (note it appears regardless of which plugin you use, one cannot change the network name once assigned)
– Network URL = http://snoopy.com and the path is /
– Create a main site = checked
– Main Site Name = Snoopy.comand voila – new network created that resolves to snoopy.com … then i used either plugin to move sub sites from mothershipnetwork.com over to the snoopy.com network … say one of the sites was called speaks … so then i log out of mothershipnetwork.com and log into snoopy.com/wp-login.php as super admin, give speaks a theme, tweak a tad, and voila – now i have http://snoopy.com/speaks/ as an active sub site on the snoopy.com network which resides on the mothershipnetwork.com core WP multisite network …
hope this helps somebody as it took me longer than i’d care to admit to figure this out … but having figured it out -> Big Kudos to all of those plugin authors for both of these as they ROCK (or at least i think as now i’ve got to test the users, uploads, plugins, etc for thorough road test but so far so great :>)
Forum: Plugins
In reply to: [Comments Evolved for WordPress] Stumped – one install works, one doesn't.fyi – i had similar issue in that the plugin did not work with many of my Theme Hybrid Parent and Child themes so i reached out to Justin and he said the following (see below) and that worked … so now your plugin works great in my responsive child theme – way cool … hope this helps … cordially, chuck scott
============
from this thread ->
http://themehybrid.com/support/topic/gplus-comments-with-shell-child-themeAdd this to your theme’s functions.php file:
remove_filter( 'comments_template', 'gplus_comments_template' ); add_filter( 'comments_template', 'gplus_comments_template', 99 );Basically, the plugin isn’t adding it’s filter late enough. This is a problem I often see with these types of plugins.
Forum: Plugins
In reply to: [P2 Resolved Posts] Limit access to flag as (un)resolvedPS – i did figure out a hack to plugin that allows only logged in users to flag resolved or unresolved … code below … cheers!
changed this file -> p2-resolved-posts.php
modified this function -> function p2_action_links()
changed line 417 to this ->/* CS Modification - show links for only logged in users - original code was one line -> echo $output; */ if ( is_user_logged_in() ) { echo $output; } else { echo ' | <a href="' . wp_login_url() . '" title="Log in to Flag">Flag</a>'; }result = essentially just shows the word “Flag” preceeded with dividing line, with the word flag being linked to login page for those not logged in … if logged in, goes back to normal per original plugin authors and shows the various links to make a post resoloved, unresolved, etc …
Forum: Plugins
In reply to: [P2 Resolved Posts] Limit access to flag as (un)resolvedditto on kudos to awesome plugin but IMHO Achilles Heel = no user / role / group permissions …
e.g., a private blog with only registered users to read-write that is not honored by plugin and allows public to change status regardless = not good …
accordingly, this plugin is off charts of useability until it has role / capability limits …
but hey, maybe there is an easy hook / filter for child theme functions.php to achieve said limit to author / subscriber roles ..??..
don’t get me wrong, this plugin is WAY COOL but IMHO could benefit GREATLY if had hooks / filters to limited roles for red to green modes but i digress :>0
Forum: Plugins
In reply to: [YOURLS Link Creator] How to use YOURLS shortlink in theme phpHey Andrew – great plugin and really impressed thus far … reason for chiming in is i think a conditional is perhaps best when adding to theme files – e.g.,
`
<?php if ( has_action( ‘yourls_display’ ) ) { do_action(‘yourls_display’); } ?>
`the other thing, and perhaps this is off topic a bit, i’m really looking to get the YOURLS short url to integrate with my post’s social sharing icons … currently using another plugin that allows for Blitly integration and wonder if your plugin could to a wp_get_remote to pull the sharing links that YOURLS provides ..??.. since at the end of the day, i would like my short links to really be default shared when people click on sharing icon in WP post footers but i digress …
thanks again for another Winning Norcross Plugin :>) cheers – chuck scott
Forum: Plugins
In reply to: [TablePress - Tables in WordPress made easy] PHP Warning with array keysGreat – table resaved, i will keep an eye on error logs and am sending email now … thanks again :>) cheers – chuck scott