/home/mjc1/public_html/html/millennium/_common2.php


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
<?php
header
("Content-type:text/html;charset=euckr");
@
session_start();

    function 
sql_injection_stop2($array){
        foreach(
$array as $key=>$str){
            
$str=preg_replace("/\s{1,}1\=(.*)+/","",$str); // 공백이후 1=1이 있을 경우 제거
            //$str=preg_replace("/\s{1,}(or|and|null|where|limit)/i"," ",$str); // 공백이후 or, and 등이 있을 경우 제거
            //$str = preg_replace("/[\s\t\'\;\=]+/","", $str); // 공백이나 탭 제거, 특수문자 제거

            
$array[$key] = $str;
        }

        return 
$array;
    }

    
$_GET sql_injection_stop2($_GET);
    
$_POST sql_injection_stop2($_POST);
    
$_REQUEST sql_injection_stop2($_REQUEST);
    
$_SERVER sql_injection_stop2($_SERVER);
    
$_SESSION sql_injection_stop2($_SESSION);

    @
extract($_GET);
    @
extract($_POST);
    @
extract($_REQUEST);
    @
extract($_SERVER);
    @
extract($_SESSION);

foreach(
$_FILES as $key=>$val){
    if(
$key=='add_file'){
        
$add_file $val['tmp_name'];
        
$add_file_name $val['name'];
    }
}

//if($_SERVER['REMOTE_ADDR']=='58.151.27.172'){ 

$pageName1 basename($_SERVER['PHP_SELF']);

    if((!isset(
$_SERVER['HTTPS']) || $_SERVER['HTTPS'] == "") && $pageName1 != "friday_program.php"){
        
$redirect "https://".$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI'];
        
//echo $redirect;
        //echo "<script>window.location.href='".$redirect."';</script>";
        
header("Location: $redirect");
    }
//}
?>