Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,9 @@ For any further questions, don't hesitate to contact me under bfstop@bfroehler.i
- Sending the test email needs the permission to change the settings, and the
.htaccess and GeoIP database path settings are validated.
- Subnets with a prefix length like `1e1` or `0x8` are no longer accepted.
- The "Blocked IPs (database)" list now shows whether expired blocks are deleted
automatically ("Prune old attempts" setting), and the username statistics view says
that the table is limited to 10,000 usernames.

## 2.0.0: Joomla 5/6 migration

Expand Down
3 changes: 3 additions & 0 deletions admin/language/de-DE/de-DE.com_bfstop.ini
Original file line number Diff line number Diff line change
Expand Up @@ -83,6 +83,8 @@ COM_BFSTOP_YOUR_IP_IS="Deine IP-Adresse aus der Sicht von BFStop ist %s."
COM_BFSTOP_INSTALL_HINT="Bitte sicherstellen, dass BFStop aktiviert und richtig konfiguriert ist! Gehe zur <a href=\"%s\">Plugin-脺bersicht</a>, klicke auf den Eintrag 'System - Brute Force Stop' (du kannst auch danach oder Teilen des Namens suchen, um es in der langen Liste schneller zu finden), dann setze das Plugin auf 'Aktiviert' - gehe dann zur <a href=\"%s\">Einstellungen-Ansicht der Komponente</a>, um es nach deinen Bed眉rfnissen zu konfigurieren!"
COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_ENABLED="Fehlgeschlagene Login-Versuche, die 盲lter als %d Wochen sind, werden automatisch gel枚scht. Dies kann 眉ber die Einstellung 'L枚schen alter Eintr盲ge' im Reiter 'Advanced' der <a href=\"%s\">Einstellungen</a> ge盲ndert werden."
COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_DISABLED="Alte fehlgeschlagene Login-Versuche werden derzeit nicht automatisch gel枚scht. Um das zu aktivieren, 'L枚schen alter Eintr盲ge' im Reiter 'Advanced' der <a href=\"%s\">Einstellungen</a> setzen, oder mit dem Button 'Alte Eintr盲ge l枚schen' manuell aufr盲umen."
COM_BFSTOP_BLOCKLIST_AUTOPURGE_ENABLED="Abgelaufene Sperren (und ihre Entsperr-Eintr盲ge), die vor mehr als %d Wochen geendet haben, werden automatisch gel枚scht. Dies kann 眉ber die Einstellung 'L枚schen alter Eintr盲ge' im Reiter 'Advanced' der <a href=\"%s\">Einstellungen</a> ge盲ndert werden. Permanente Sperren werden nie automatisch gel枚scht."
COM_BFSTOP_BLOCKLIST_AUTOPURGE_DISABLED="Abgelaufene Sperren werden derzeit nicht automatisch gel枚scht. Um das zu aktivieren, 'L枚schen alter Eintr盲ge' im Reiter 'Advanced' der <a href=\"%s\">Einstellungen</a> setzen. Permanente Sperren werden nie automatisch gel枚scht."
COM_BFSTOP_FAILEDLOGIN_PURGE_BUTTON="Alte Eintr盲ge l枚schen"
COM_BFSTOP_FAILEDLOGIN_PURGE_TITLE="Alte fehlgeschlagene Login-Versuche l枚schen"
COM_BFSTOP_FAILEDLOGIN_PURGE_DESC="Alle fehlgeschlagenen Login-Versuche, die 盲lter als die angegebene Anzahl an Tagen sind, werden endg眉ltig gel枚scht. Dies kann nicht r眉ckg盲ngig gemacht werden. Sperren sind davon nicht betroffen."
Expand All @@ -99,6 +101,7 @@ COM_BFSTOP_HEADING_RANK="#"
COM_BFSTOP_HEADING_FAILED_ATTEMPTS="Fehlgeschlagene Logins"
COM_BFSTOP_HEADING_FIRST_ATTEMPT="Erster Versuch"
COM_BFSTOP_USERNAMESTATS_INFO="Die bei fehlgeschlagenen Login-Versuchen verwendeten Benutzernamen, und wie oft jeder davon verwendet wurde. Diese Statistik wird unabh盲ngig von den fehlgeschlagenen Login-Versuchen gef眉hrt und ist daher nicht betroffen, wenn alte fehlgeschlagene Login-Versuche gel枚scht werden; sie beginnt erst mit der Installation von (bzw. dem Update auf) BFStop 2.0.0, ausgehend von den zu diesem Zeitpunkt vorhandenen fehlgeschlagenen Login-Versuchen. Ein Klick auf einen Benutzernamen zeigt die daf眉r noch gespeicherten fehlgeschlagenen Login-Versuche."
COM_BFSTOP_USERNAMESTATS_AUTOTRIM="Es werden h枚chstens %d Benutzernamen gespeichert: dar眉ber hinaus werden automatisch (einmal t盲glich) die Benutzernamen mit den wenigsten Versuchen gel枚scht. Dieses Limit kann nicht ge盲ndert werden."
COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT="Existierendes Konto"
COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT_DESC="Auf dieser Seite existiert ein Benutzerkonto mit diesem Benutzernamen."
COM_BFSTOP_USERNAMESTATS_PURGE_BUTTON="Veraltete Benutzernamen l枚schen"
Expand Down
3 changes: 3 additions & 0 deletions admin/language/en-GB/en-GB.com_bfstop.ini
Original file line number Diff line number Diff line change
Expand Up @@ -135,6 +135,8 @@ COM_BFSTOP_SETTINGS_RISK_MIN_BLOCK_NUMBER_LABEL="Minimum Allowed Attempts"
COM_BFSTOP_SETTINGS_RISK_MIN_BLOCK_NUMBER_DESC="A hard floor on the risk-adjusted number of allowed failed attempts, so an extreme risk score can never reduce it to zero (or below) and effectively block on the very first attempt."
COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_ENABLED="Failed login entries older than %d weeks are deleted automatically. You can change this via the 'Prune old attempts' setting in the 'Advanced' tab of the <a href=\"%s\">Settings</a>."
COM_BFSTOP_FAILEDLOGIN_AUTOPURGE_DISABLED="Old failed login entries are currently not deleted automatically. To enable this, set 'Prune old attempts' in the 'Advanced' tab of the <a href=\"%s\">Settings</a>, or use the 'Delete Old Entries' button to clean up manually."
COM_BFSTOP_BLOCKLIST_AUTOPURGE_ENABLED="Expired blocks (and their unblock records) which ended more than %d weeks ago are deleted automatically. You can change this via the 'Prune old attempts' setting in the 'Advanced' tab of the <a href=\"%s\">Settings</a>. Permanent blocks are never deleted automatically."
COM_BFSTOP_BLOCKLIST_AUTOPURGE_DISABLED="Expired blocks are currently not deleted automatically. To enable this, set 'Prune old attempts' in the 'Advanced' tab of the <a href=\"%s\">Settings</a>. Permanent blocks are never deleted automatically."
COM_BFSTOP_FAILEDLOGIN_PURGE_BUTTON="Delete Old Entries"
COM_BFSTOP_FAILEDLOGIN_PURGE_TITLE="Delete Old Failed Login Entries"
COM_BFSTOP_FAILEDLOGIN_PURGE_DESC="All failed login entries older than the given number of days will be permanently deleted. This cannot be undone. Blocks are not affected."
Expand All @@ -151,6 +153,7 @@ COM_BFSTOP_HEADING_RANK="#"
COM_BFSTOP_HEADING_FAILED_ATTEMPTS="Failed logins"
COM_BFSTOP_HEADING_FIRST_ATTEMPT="First attempt"
COM_BFSTOP_USERNAMESTATS_INFO="The usernames used in failed login attempts, and how often each was used. These statistics are kept independently of the failed login entries, so they are not affected when old failed login entries are deleted; they only start with the installation of (or update to) BFStop 2.0.0, seeded from the failed login entries which existed at that time. Click a username to see its failed login entries that are still stored."
COM_BFSTOP_USERNAMESTATS_AUTOTRIM="At most %d usernames are kept: beyond that, the usernames with the fewest attempts are deleted automatically (once a day). This limit can't be changed."
COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT="Existing account"
COM_BFSTOP_USERNAMESTATS_EXISTING_ACCOUNT_DESC="A user account with this username exists on this site."
COM_BFSTOP_USERNAMESTATS_PURGE_BUTTON="Delete Stale Usernames"
Expand Down
1 change: 1 addition & 0 deletions admin/src/View/Blocklist/HtmlView.php
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ function display($tpl = null)
// with .htaccess blocking, blocked requests never reach Joomla,
// so attempts can't be counted
$this->attemptsTracked = ParamHelper::get('blockMode', 'params', 'full') !== 'htaccess';
$this->autoPurgeWeeks = (int) ParamHelper::get('deleteOld', 'params', 0);
$this->addToolBar();
parent::display($tpl);
}
Expand Down
2 changes: 2 additions & 0 deletions admin/src/View/Usernamestats/HtmlView.php
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@
defined('_JEXEC') or die;

use Codeling\Component\Bfstop\Administrator\Helper\ToolbarHelper as BfstopToolbarHelper;
use Codeling\Plugin\System\Bfstop\Helper\DatabaseHelper;
use Joomla\CMS\Factory;
use Joomla\CMS\Language\Text;
use Joomla\CMS\MVC\View\HtmlView as BaseHtmlView;
Expand All @@ -27,6 +28,7 @@ function display($tpl = null)
$this->sortColumn = $state->get('list.ordering');
$this->sortDirection = $state->get('list.direction');
$this->maxAttempts = $this->get('MaxAttempts');
$this->maxUsernames = DatabaseHelper::$USERNAME_STATS_MAX_ROWS;
$this->canPurge = Factory::getApplication()->getIdentity()->authorise('core.delete', 'com_bfstop');
if ($this->canPurge)
{
Expand Down
7 changes: 7 additions & 0 deletions admin/tmpl/blocklist/default.php
Original file line number Diff line number Diff line change
Expand Up @@ -9,8 +9,15 @@

use Joomla\CMS\HTML\HTMLHelper;
use Joomla\CMS\Language\Text;
use Joomla\CMS\Router\Route;

$settingsUrl = Route::_('index.php?option=com_bfstop&view=settings', false);
?>
<div class="alert alert-info">
<?php echo ($this->autoPurgeWeeks > 0)
? Text::sprintf('COM_BFSTOP_BLOCKLIST_AUTOPURGE_ENABLED', $this->autoPurgeWeeks, $settingsUrl)
: Text::sprintf('COM_BFSTOP_BLOCKLIST_AUTOPURGE_DISABLED', $settingsUrl); ?>
</div>
<form method="post" name="adminForm" id="adminForm">
<input type="hidden" name="task" value="unblock" />
<?php echo HTMLHelper::_('form.token'); ?>
Expand Down
1 change: 1 addition & 0 deletions admin/tmpl/usernamestats/default.php
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@
?>
<div class="alert alert-info">
<?php echo Text::_('COM_BFSTOP_USERNAMESTATS_INFO'); ?>
<?php echo Text::sprintf('COM_BFSTOP_USERNAMESTATS_AUTOTRIM', $this->maxUsernames); ?>
</div>
<form method="post" name="adminForm" id="adminForm">
<input type="hidden" name="task" value="" />
Expand Down
Loading