Zen Cart Logo
Forums / Addon Admin Tools / IP Blocker for v1.5.x

IP Blocker for v1.5.x

Views: 34,654

Results 121 to 125 of 125
10 Aug 2020, 3:50 PM
#121
yesaul avatar

yesaul

New Zenner

Join Date:
Apr 2011
Location:
Espoo, Finland
Posts:
73
Plugin Contributions:
0

IP Blocker for v1.5.x

Hello,

The following PHP Warnings appeared in the logs, when I tried to add the IP-address to "Blocked IP Addresses" list for the first time (using a link on "Who's Online" page)

--> PHP Warning: in_array() expects parameter 2 to be array, boolean given in admin/includes/functions/extra_functions/ip_blocker_functions.php on line 167.
--> PHP Warning: in_array() expects parameter 2 to be array, boolean given in admin/includes/functions/extra_functions/ip_blocker_functions.php on line 169.

I tried to understand what happened adding and removing (some and all) another IP-addresses.
I tried even to remove all lines from ip_blocker table manually and then add IP-address again.
But unfortunately (??? :-) ) the issue has not appeared again.
Probably I should try to fully remove this addon and then install it again (in order to get the same issue again), but this is not possible at the moment, sorry.

        $blocked_ip_array = unserialize($blocklist->fields['ib_blocklist']);

        $is_new_address = false;
        if (!in_array($newaddress, $blocked_ip_array)) {
            $newaddress_all = substr($newaddress, 0, strrpos($newaddress, '.')) . '*';
            if (!in_array($newaddress_all, $blocked_ip_array)) {
                $blocked_ip_array[] = $newaddress;
                $is_new_address = true;
            }
        }

In my homble opinion (I'm definitely not a pro), something is wrong with usage of unserialize function, which can return a very diffetent typs of value

https://www.php.net/manual/en/function.unserialize.php

31 Jul 2021, 9:34 PM
#122
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,718
Plugin Contributions:
56

Re: IP Blocker for v1.5.x

Is this plugin deprecated or has it just not been updated for 1.5.7 yet?

That Software Guy. My Store: Zen Cart Support
Available for hire - See my ad in Services
Plugin Moderator, Documentation Curator, Chief Cook and Bottle-Washer.
Do you benefit from Zen Cart? Then please support the project.

1 Aug 2021, 1:13 PM
#123
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,107
Plugin Contributions:
56

Re: IP Blocker for v1.5.x

swguy:

Is this plugin deprecated or has it just not been updated for 1.5.7 yet?
I find the Access Blocker (https://www.zen-cart.com/showthread.php?225161-Access-Blocker-Support-Thread) less intrusive/difficult so I won't be updating*** IP Blocker***. If anyone wants to take its support over, I'll be happy to transfer the GitHub account.

1 Aug 2021, 4:04 PM
#124
swguy avatar

swguy

Administrator

Join Date:
Feb 2006
Location:
Tampa Bay, Florida
Posts:
10,718
Plugin Contributions:
56

Re: IP Blocker for v1.5.x

Roger that. I will update the web page for IP blocker with this recommendation. I wasn't sure if it was a superset or not - thanks for confirming.

Access Blocker download is at
https://www.zen-cart.com/downloads.php?do=file&id=2237

That Software Guy. My Store: Zen Cart Support
Available for hire - See my ad in Services
Plugin Moderator, Documentation Curator, Chief Cook and Bottle-Washer.
Do you benefit from Zen Cart? Then please support the project.

10 Apr 2026, 11:38 AM
#125
jimmie avatar

jimmie

Totally Zenned

Join Date:
Jan 2013
Location:
New Port Richey, Florida
Posts:
971
Plugin Contributions:
0

Re: IP Blocker for v1.5.x

here is fix for ip_blocker_functions.php for zen 2.10```
// -----
// Insert a single ipV4 IP address into the IP Blocker blocked-address database table.
//
function ip_blocker_insert_block_address($newaddress)
{
global $db;
$error_ip = '';
if (!ip_blocker_validate_address($newaddress, $ip_info, true)) {
$error_ip = sprintf(ERROR_NOT_SINGLE_ADDRESS, $newaddress);
} else {
$blocklist = $db->Execute("SELECT ib_blocklist FROM " . TABLE_IP_BLOCKER . " WHERE ib_id=1");

    // PHP 8 Fix: Ensure we have an array even if unserialize fails or is empty
    $blocked_ip_array = unserialize($blocklist->fields['ib_blocklist'] ?? '');
    if (!is_array($blocked_ip_array)) {
        $blocked_ip_array = [];
    }

    $is_new_address = false;
    // Now in_array will always receive an array as the second argument
    if (!in_array($newaddress, $blocked_ip_array)) {
        $newaddress_all = substr($newaddress, 0, strrpos($newaddress, '.')) . '.*'; // Added dot for standard CIDR logic
        if (!in_array($newaddress_all, $blocked_ip_array)) {
            $blocked_ip_array[] = $newaddress;
            $is_new_address = true;
        }
    }

    if ($is_new_address) {
        $blocked_ip_list = serialize($blocked_ip_array);
        // Use bindVars for security to prevent SQL injection and handle quotes in serialized data
        $sql = "UPDATE " . TABLE_IP_BLOCKER . " 
                SET ib_blocklist = :blocklist:, 
                    ib_date = :date: 
                WHERE ib_id=1";
        $sql = $db->bindVars($sql, ':blocklist:', $blocked_ip_list, 'string');
        $sql = $db->bindVars($sql, ':date:', date('Y-m-d'), 'string');
        $db->Execute($sql);
    }
}
return $error_ip;

}