1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
|
<?php header("Content-type:text/html;charset=euckr"); @session_start();
function sql_injection_stop2($array){ foreach($array as $key=>$str){ $str=preg_replace("/\s{1,}1\=(.*)+/","",$str); // 공백이후 1=1이 있을 경우 제거 //$str=preg_replace("/\s{1,}(or|and|null|where|limit)/i"," ",$str); // 공백이후 or, and 등이 있을 경우 제거 //$str = preg_replace("/[\s\t\'\;\=]+/","", $str); // 공백이나 탭 제거, 특수문자 제거
$array[$key] = $str; }
return $array; }
$_GET = sql_injection_stop2($_GET); $_POST = sql_injection_stop2($_POST); $_REQUEST = sql_injection_stop2($_REQUEST); $_SERVER = sql_injection_stop2($_SERVER); $_SESSION = sql_injection_stop2($_SESSION);
@extract($_GET); @extract($_POST); @extract($_REQUEST); @extract($_SERVER); @extract($_SESSION);
foreach($_FILES as $key=>$val){ if($key=='add_file'){ $add_file = $val['tmp_name']; $add_file_name = $val['name']; } }
//if($_SERVER['REMOTE_ADDR']=='58.151.27.172'){
$pageName1 = basename($_SERVER['PHP_SELF']);
if((!isset($_SERVER['HTTPS']) || $_SERVER['HTTPS'] == "") && $pageName1 != "friday_program.php"){ $redirect = "https://".$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']; //echo $redirect; //echo "<script>window.location.href='".$redirect."';</script>"; header("Location: $redirect"); } //} ?>
|