Zen Cart Logo
Forums / All Other Contributions/Addons / AbuseIPDB Integration module

AbuseIPDB Integration module

Views: 22,005

Results 1 to 20 of 132
16 Apr 2023, 1:12 PM
#1
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

AbuseIPDB Integration module

DOWNLOAD PAGE: https://www.zen-cart.com/downloads.php?do=file&id=2371

I've developed a new module that integrates AbuseIPDB with Zen Cart, and I'm making it available for everyone to use.

What is AbuseIPDB? It's a community-based project that collects and shares data about abusive IP addresses. By integrating with their API, my module allows you to protect your e-commerce website from potentially harmful visitors by checking the confidence score of their IP address and blocking access if it exceeds a predefined threshold.

The module also includes several useful features, such as caching to reduce the number of API calls, a test mode for debugging, and logging to monitor blocked IPs. You can also manually whitelist or blacklist IP addresses to have greater control over access to your site.

I've tested the module and it's ready for use, so if you're interested in trying it out, it's attached: AbuseIPDBO v1.0.0

If you have any questions or encounter any issues while using the module, please don't hesitate to reach out to me. I hope this module proves useful to you.

marcopolo

16 Apr 2023, 1:24 PM
#2
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

Here is the module: AbuseIPDBO v1.0.0

21 May 2023, 5:18 PM
#3
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

Hi @marcopolo

Got this all set up on my 1.5.6c store, api key works & blocking is working. I am however getting a headers already sent error when using it. My logs folder fills up with every visit & page view, so I’ve had to disable the plugin. Sample debug as follows (with api key removed)

[21-May-2023 18:14:44 Europe/London] Threshold: 50
[21-May-2023 18:14:44 Europe/London] Cache Time: 3600
[21-May-2023 18:14:44 Europe/London] Test Mode: false
[21-May-2023 18:14:44 Europe/London] Test IP: 
[21-May-2023 18:14:44 Europe/London] Enable Logging: false
[21-May-2023 18:14:44 Europe/London] Log File Format: abuseipdb_blocked_Y_m.log
[21-May-2023 18:14:44 Europe/London] Log File Path: logs/
[21-May-2023 18:14:44 Europe/London] Whitelisted IPs: 
[21-May-2023 18:14:44 Europe/London] Blocked IPs: 
[21-May-2023 18:14:44 Europe/London] Checking cache for IP: 54.236.1.13
[21-May-2023 18:14:45 Europe/London] API call made for IP: 54.236.1.13 with score: 68
[21-May-2023 18:14:45 Europe/London] IP 54.236.1.13 blocked from API call
[21-May-2023 18:14:45 Europe/London] Request URI: /queen-crown-badge-p-712.html, IP address: 54.236.1.13
#1  header() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/classes/observers/class.abuseipdb_observer.php:137]
#2  abuseipdb_observer->checkAbusiveIP() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/classes/observers/class.abuseipdb_observer.php:19]
#3  abuseipdb_observer->update() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/classes/class.base.php:103]
#4  base->notify() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_header.php:4]
#5  require(/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_header.php) called at [/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_main_page.php:106]
#6  require(/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_main_page.php) called at [/home/brucebli/public_html/koolbadges.co.uk/index.php:97]
--> PHP Warning: Cannot modify header information - headers already sent by (output started at /home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/jscript/jscript_framework.php:17) in /home/brucebli/public_html/koolbadges.co.uk/includes/classes/observers/class.abuseipdb_observer.php on line 137.
21 May 2023, 5:50 PM
#4
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

This is a common PHP error that usually happens when you attempt to send a HTTP header after some output has already been sent to the browser.

In this case, the output has been started at file jscript_framework.php on line 17, which is preventing the header modification in class.abuseipdb_observer.php on line 137.

The issue lies in the sequence of operations where some content was output before the headers could be completely set. This could be due to:

Printing some text or HTML before calling a header function.
A PHP or HTML file which has whitespace or an empty line before the opening PHP tag (<?php) or after the closing PHP tag (?>), if used.
A UTF-8 Byte Order Mark (BOM) at the beginning of one of the files.
Using echo, print, printf, or die functions before setting headers.
To fix this issue, check the file /home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/jscript/jscript_framework.php specifically at line 17 and make sure there's no output before the headers are set in the file class.abuseipdb_observer.php.

If this doesn't solve your problem, consider using output buffering by placing ob_start(); at the beginning of your PHP script. This function will turn output buffering on. While output buffering is active no output is sent from the script (other than headers), instead the output is stored in an internal buffer. You can then use ob_end_flush(); or ob_end_clean(); at the end of the script to send output and turn off output buffering. However, it's better to solve the actual problem of why output is being sent too early, if possible.

21 May 2023, 5:59 PM
#5
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

Let me know what module is using the file: jscript_framework.php as it is not part of this modules files, if you can upload the file here so I can take a look at the code and see what it is doing.

21 May 2023, 6:04 PM
#6
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

The file itself is by lat9 - I personally can't remember which plugin it came from, but I think it might be something to do with the responsive avonlee contempo modified themed I'm running.

File contents as follows

<?php
/**
 * @package admin
 * @copyright Copyright 2003-2017 Zen Cart Development Team
 * @license http://www.zen-cart.com/license/2_0.txt GNU Public License V2.0
 * @version $Id: Author: zcwilt  lat9 Modified in v1.5.6 $
 */
?>
<script type="text/javascript"><!--//<![CDATA[
if (typeof zcJS == "undefined" || !zcJS) {
  window.zcJS = { name: 'zcJS', version: '0.1.0.0' };
};

zcJS.ajax = function (options) {
  options.url = options.url.replace("&", unescape("&"));
  var deferred = jQuery.Deferred(function (d) {
      var securityToken = '<?php echo $_SESSION['securityToken']; ?>';
      var defaults = {
          cache: false,
          type: 'POST',
          traditional: true,
          dataType: 'json',
          timeout: 5000,
          data: jQuery.extend(true,{
            securityToken: securityToken
        }, options.data)
      },
      settings = jQuery.extend(true, {}, defaults, options);
      if (typeof(console.log) == 'function') {
          console.log( settings );
      }

      d.done(settings.success);
      d.fail(settings.error);
      d.done(settings.complete);
      var jqXHRSettings = jQuery.extend(true, {}, settings, {
          success: function (response, textStatus, jqXHR) {
            d.resolve(response, textStatus, jqXHR);
          },
          error: function (jqXHR, textStatus, errorThrown) {
              if (window.console) {
                if (typeof(console.log) == 'function') {
                  console.log(jqXHR);
                }
              }
              d.reject(jqXHR, textStatus, errorThrown);
          },
          complete: d.resolve
      });
      jQuery.ajax(jqXHRSettings);
   }).fail(function(jqXHR, textStatus, errorThrown) {
   var response = jqXHR.getResponseHeader('status');
   var responseHtml = jqXHR.responseText;
   var contentType = jqXHR.getResponseHeader("content-type");
   switch (response)
     {
       case '403 Forbidden':
         var jsonResponse = JSON.parse(jqXHR.responseText);
         var errorType = jsonResponse.errorType;
         switch (errorType)
         {
           case 'ADMIN_BLOCK_WARNING':
           break;
           case 'AUTH_ERROR':
           break;
           case 'SECURITY_TOKEN':
           break;

           default:
             alert('An Internal Error of type '+errorType+' was received while processing an ajax call. The action you requested could not be completed.');
         }
       break;
       default:
        if (jqXHR.status === 200) {
            if (contentType.toLowerCase().indexOf("text/html") >= 0) {
                document.open();
                document.write(responseHtml);
                document.close();
            }
         }
     }
   });

  var promise = deferred.promise();
  return promise;
};
zcJS.timer = function (options) {
  var defaults = {
    interval: 10000,
    startEvent: null,
    intervalEvent: null,
    stopEvent: null

},
  settings = jQuery.extend(true, {}, defaults, options);

  var enabled = new Boolean(false);
  var timerId = 0;
  var mySelf;
  this.Start = function()
  {
      this.enabled = new Boolean(true);

      mySelf = this;
      mySelf.settings = settings;
      if (mySelf.enabled)
      {
          mySelf.timerId = setInterval(
          function()
          {
              if (mySelf.settings.intervalEvent)
              {
                mySelf.settings.intervalEvent(mySelf);
              }
          }, mySelf.settings.interval);
          if (mySelf.settings.startEvent)
          {
            mySelf.settings.startEvent(mySelf);
          }
      }
  };
  this.Stop = function()
  {
    mySelf.enabled = new Boolean(false);
    clearInterval(mySelf.timerId);
    if (mySelf.settings.stopEvent)
    {
      mySelf.settings.stopEvent(mySelf);
    }
  };
};

//]] --></script>
21 May 2023, 7:23 PM
#7
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

I'm not sure why your receiving that error, try this file in place of the one your using now and see if it resolves the issue, see attached AbuseIPDBO_custom_file.zip

21 May 2023, 8:21 PM
#8
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

Thanks marcopolo

With that updated file I still get the headers already sent error

[21-May-2023 21:19:03 Europe/London] Request URI: /teal-heart-boss-bridesmaid-badge-p-6746.html, IP address: 54.236.1.13
#1  header() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/classes/observers/class.abuseipdb_observer.php:144]
#2  abuseipdb_observer->checkAbusiveIP() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/classes/observers/class.abuseipdb_observer.php:19]
#3  abuseipdb_observer->update() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/classes/class.base.php:103]
#4  base->notify() called at [/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_header.php:4]
#5  require(/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_header.php) called at [/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_main_page.php:106]
#6  require(/home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/common/tpl_main_page.php) called at [/home/brucebli/public_html/koolbadges.co.uk/index.php:97]
--> PHP Warning: Cannot modify header information - headers already sent by (output started at /home/brucebli/public_html/koolbadges.co.uk/includes/templates/responsive_avonlee_contempo/jscript/jscript_framework.php:17) in /home/brucebli/public_html/koolbadges.co.uk/includes/classes/observers/class.abuseipdb_observer.php on line 144.
21 May 2023, 8:50 PM
#9
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

Ok.

I tried renaming the jscript_framework.php temporarily to jscript_framework.php.bak just to see if the error went away & it then caused the same error with the jscript_plugin_structured_data.php script, so it would appear the code isn't playing well with other plugins.

21 May 2023, 8:57 PM
#10
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

I would check your tpl_header.php and tpl_main_page.php files against their originals and see if any modification made to them is causing the issue.

The issue is that you're encountering a "headers already sent" error. This is often caused when you attempt to send a header after the HTTP body content has started to be output. Since those files are listed in the log they may have something to do it it:

To fix this, you should check these lines in tpl_header.php and tpl_main_page.php and ensure there is no output before the header() function is called. Output can be any HTML outside PHP tags, any echo or print statement, or even a PHP closing tag (?>) followed by a newline or space.

Hope that helps

21 May 2023, 9:03 PM
#11
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

That file jscript_framework.php is part of zencart, I have the same file and it works on my store so I do not think it is that. Check the two files I outlined the previous post. If those are modified try using the originals and troubleshoot and see if that is your issue.

21 May 2023, 9:07 PM
#12
lat9 avatar

lat9

Administrator

Join Date:
Sep 2009
Location:
Stuart, FL
Posts:
14,100
Plugin Contributions:
56

Re: AbuseIPDB Integration module

FWIW, that "headers already sent" issue is *usually *associated with a file (usual culprits are language files) that has an extra space after the PHP 'end', e.g.

<?

... where there is a blank line after the <?.

22 May 2023, 7:07 AM
#13
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

Thanks both of you.

I checked tpl_header.php and tpl_main_page.php against originals and there are changes to do with my template in use compared to stock files from Zen Cart, but the core of the files are the same. I tried, just to test, dropping in the standard files without modifications & the error persists.

I also went through files looking for extra whitespace & couldn't find anything. The strange thing is, this site has been running for a long time & has quite a few plugins which work perfectly together. This is the first plugin I’ve used which fills up the log files, so it would seem if the error exists in one of my existing files, it doesn't affect any of the other plugins as the only file I ever get in logs is if a square payment is declined or fails.

I spent a few hours last night combing through files trying to find anything that could be issuing a header response before tpl_header.php, but I couldn't find anything. I'll just have to leave it disabled for now which is a shame.

23 May 2023, 2:02 PM
#14
webchills avatar

webchills

Zen Follower

Join Date:
Sep 2005
Location:
Austria
Posts:
99
Plugin Contributions:
1

Re: AbuseIPDB Integration module

Thanks for this great plugin, nice work!

Is there a reason why you redirect blocked IPs to the page_not_found page? I think a 410 redirect would be more suitable.

I have changed in includes/classes/observers/class.abuseipdb_observer.php the three instances of:

header('Location: /index.php?main_page=page_not_found');
                exit();

to:

header('HTTP/1.0 410 Gone');
                zen_exit();

@johnjlarge
could be a fix for your headers already sent issue as well

24 May 2023, 4:26 PM
#15
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

webchills:

Thanks for this great plugin, nice work!

Is there a reason why you redirect blocked IPs to the page_not_found page? I think a 410 redirect would be more suitable.

I have changed in includes/classes/observers/class.abuseipdb_observer.php the three instances of:

header('Location: /index.php?main_page=page_not_found');
exit();

> to:
> ```
header('HTTP/1.0 410 Gone');
                zen_exit();

@johnjlarge
could be a fix for your headers already sent issue as well

Just tried with these changes, still no go for me. Still getting the headers already sent error.

24 May 2023, 5:38 PM
#16
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

So, I've found a way around this which works, are there any issues to doing it this way?

In the index.php file at the root of zen cart, adding the block code before allowing html_header.php to load makes the code work. Will this give me any issues downstream in the code flow?

Around line 40 of index.php I've added the code here

 

/**
 * We now load header code for a given page. 
 * Page code is stored in includes/modules/pages/PAGE_NAME/directory 
 * 'header_php.php' files in that directory are loaded now.
 */
    require($code_page_directory . '/' . $value);
  }
/**
 * We now load the html_header.php file. This file contains code that would appear within the HTML <head></head> code 
 * it is overridable on a template and page basis. 
 * In that a custom template can define its own common/html_header.php file 
 */
 // bof modification AbuseIPDB
if (ABUSEIPDB_ENABLED) {
$GLOBALS['zco_notifier']->notify('NOTIFY_HEADER_START');
}
// eof modification AbuseIPDB
  require($template->get_template_dir('html_header.php',DIR_WS_TEMPLATE, $current_page_base,'common'). '/html_header.php');
/**
 * Define Template Variables picked up from includes/main_template_vars.php unless a file exists in the
 * includes/pages/{page_name}/directory to overide. Allowing different pages to have different overall
 * templates.
 */
24 May 2023, 7:20 PM
#17
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

webchills:

Thanks for this great plugin, nice work!

Is there a reason why you redirect blocked IPs to the page_not_found page? I think a 410 redirect would be more suitable.

I have changed in includes/classes/observers/class.abuseipdb_observer.php the three instances of:

header('Location: /index.php?main_page=page_not_found');
exit();

> to:
> ```
header('HTTP/1.0 410 Gone');
                zen_exit();

@johnjlarge
could be a fix for your headers already sent issue as well

Thank you glad you like it!

In regards to the redirect page I guess I thought giving it no information was better but maybe 410 option is better since it would indicate that the content is permanently gone and discourage further access attempts from the abusive IP addresses. It can also help search engines quickly remove the content from their indexes.

24 May 2023, 7:24 PM
#18
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

johnjlarge:

So, I've found a way around this which works, are there any issues to doing it this way?

In the index.php file at the root of zen cart, adding the block code before allowing html_header.php to load makes the code work. Will this give me any issues downstream in the code flow?

Around line 40 of index.php I've added the code here

/**

  • We now load header code for a given page.
  • Page code is stored in includes/modules/pages/PAGE_NAME/directory
  • 'header_php.php' files in that directory are loaded now.
    /
    require($code_page_directory . '/' . $value);
    }
    /
    *
  • We now load the html_header.php file. This file contains code that would appear within the HTML <head></head> code
  • it is overridable on a template and page basis.
  • In that a custom template can define its own common/html_header.php file
    /
    // bof modification AbuseIPDB
    if (ABUSEIPDB_ENABLED) {
    $GLOBALS['zco_notifier']->notify('NOTIFY_HEADER_START');
    }
    // eof modification AbuseIPDB
    require($template->get_template_dir('html_header.php',DIR_WS_TEMPLATE, $current_page_base,'common'). '/html_header.php');
    /
    *
  • Define Template Variables picked up from includes/main_template_vars.php unless a file exists in the
  • includes/pages/{page_name}/directory to overide. Allowing different pages to have different overall
  • templates.
    */


That is fine for the index page however if one enters on a different page your not protected, that is why it is added to the tpl_header.php page since that will load on every page no matter the entry point.
24 May 2023, 7:50 PM
#19
johnjlarge avatar

johnjlarge

New Zenner

Join Date:
Oct 2007
Location:
Cornwall/Amsterdam
Posts:
61
Plugin Contributions:
0

Re: AbuseIPDB Integration module

Hi @marcopolo

I've just tested it, setting my own IP as the test mode IP & can confirm it works on subpages. As far as I'm aware the index.php always fires, then loads in templates, includes etc. It may be a more elegant way to load it, as the block will launch with minimal code being loaded, possibly reducing server load in the process. I chose index.php as according to the program flow in documentation it's the top level page which everything else loads from. With this being a blocking script, it would make sense to expose as little code/server resources as possible.

Program flow docs https://docs.zen-cart.com/dev/code/program_flow/

I also set the redirect as a 403 forbidden error as this seemed more appropriate for my usage.

// Redirect to the 404 page
            header('HTTP/1.0 403 Forbidden');
            zen_exit();
24 May 2023, 8:28 PM
#20
marcopolo avatar

marcopolo

Totally Zenned

Join Date:
May 2008
Location:
United States
Posts:
520
Plugin Contributions:
2

Re: AbuseIPDB Integration module

johnjlarge:

Hi @marcopolo

I've just tested it, setting my own IP as the test mode IP & can confirm it works on subpages. As far as I'm aware the index.php always fires, then loads in templates, includes etc. It may be a more elegant way to load it, as the block will launch with minimal code being loaded, possibly reducing server load in the process. I chose index.php as according to the program flow in documentation it's the top level page which everything else loads from. With this being a blocking script, it would make sense to expose as little code/server resources as possible.

Program flow docs https://docs.zen-cart.com/dev/code/program_flow/

I also set the redirect as a 403 forbidden error as this seemed more appropriate for my usage.

// Redirect to the 404 page
header('HTTP/1.0 403 Forbidden');
zen_exit();


Your perfectly fine then, apologies for the oversight regarding the index page. I wasn't aware that it loaded on every page. I use one of those SEO page optimizers that rename all my pages to .html pages so I never see the zencart page names. To regards to optimizing server load, the best solution would be to load it from the index page outlined within the flow documentation as you pointed out. A blocked IP, I assume they would just receive a blank page with no content loading from your site?