Version 2.3.6

This commit is contained in:
Neo committed 2025-12-19 00:26:08 -08:00
1 parent a3bb603c96
commit 19b38c7c74
764 files changed
+143731 -118164

No files matched your search

File diff suppressed because it is too large. Load diff
+1 -10
View File
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>
+62 -27
View File
@@ -26,8 +26,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class plugin_msg
@@ -132,8 +132,8 @@ class plugin_msg
// INIT
//-----------------------------------------
$rows = array();
$query = '';
$rows = array();
$query = '';
$query_bits = array();
$match = 0;
@@ -161,7 +161,7 @@ class plugin_msg
else
{
$query = implode( " OR ", $query_bits );
}
}
//-----------------------------------------
// Grab 'em
@@ -455,6 +455,34 @@ class plugin_msg
$total_space_allowed = ( $this->ipsclass->member['g_attach_per_post'] ? $this->ipsclass->member['g_attach_per_post'] : $this->ipsclass->member['g_attach_max'] ) * 1024;
//-----------------------------------------
// Generate space used figure
//-----------------------------------------
if ( $this->ipsclass->member['g_attach_per_post'] )
{
//-----------------------------------------
// Per post limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => "attach_post_key='".$post_key."'" ) );
$space_used = intval( $_space_used['figure'] );
}
else
{
//-----------------------------------------
// Global limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => 'attach_member_id='.$member_id . " AND attach_rel_module IN( 'post', 'msg' )" ) );
$space_used = intval( $_space_used['figure'] );
}
//-----------------------------------------
// Generate space allowed figure
//-----------------------------------------
@@ -463,37 +491,44 @@ class plugin_msg
{
if ( $this->ipsclass->member['g_attach_per_post'] )
{
//-----------------------------------------
// Per post limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
$_g_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => "attach_post_key='".$post_key."'" ) );
'where' => 'attach_member_id='.$member_id . " AND attach_rel_module IN( 'post', 'msg' )" ) );
$space_used = intval( $_space_used['figure'] );
$space_allowed = intval( ( $this->ipsclass->member['g_attach_per_post'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? 0 : $space_allowed;
$g_space_used = intval( $_g_space_used['figure'] );
if( intval( ( $this->ipsclass->member['g_attach_max'] * 1024 ) - $g_space_used ) < 0 )
{
$space_used = $g_space_used;
$total_space_allowed = $this->ipsclass->member['g_attach_max'] * 1024;
$space_allowed = intval( ( $this->ipsclass->member['g_attach_max'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
else
{
$space_allowed = intval( ( $this->ipsclass->member['g_attach_per_post'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
}
else
{
//-----------------------------------------
// Global limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => 'attach_member_id='.$member_id ) );
$space_used = intval( $_space_used['figure'] );
$space_allowed = intval( ( $this->ipsclass->member['g_attach_max'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? 0 : $space_allowed;
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
}
else
{
# Unlimited
$space_allowed = 0;
if ( $this->ipsclass->member['g_attach_per_post'] )
{
$space_allowed = intval( ( $this->ipsclass->member['g_attach_per_post'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
else
{
# Unlimited
$space_allowed = 0;
}
}
//-----------------------------------------
@@ -501,7 +536,7 @@ class plugin_msg
//-----------------------------------------
$space_left = $space_allowed ? $space_allowed : 0;
$space_left = ($space_left < 0) ? 0 : $space_left;
$space_left = ($space_left < 0) ? -1 : $space_left;
//-----------------------------------------
// Generate max upload size
+65 -37
View File
@@ -26,8 +26,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class plugin_post
@@ -96,8 +96,8 @@ class plugin_post
{
if( $attach['attach_member_id'] != $this->ipsclass->member['id'] )
{
return FALSE;
}
return FALSE;
}
}
//-----------------------------------------
@@ -116,7 +116,7 @@ class plugin_post
// TheWalrus inspired fix for previewing
// the post and clicking the attachment...
//-----------------------------------------
if ( $attach['attach_rel_id'] == 0 AND $attach['attach_member_id'] == $this->ipsclass->member['id'] )
{
$_ok = 1;
@@ -187,10 +187,10 @@ class plugin_post
// INIT
//-----------------------------------------
$rows = array();
$rows = array();
$query_bits = array();
$query = '';
$match = 0;
$query = '';
$match = 0;
//-----------------------------------------
// Check
@@ -203,6 +203,9 @@ class plugin_post
if ( is_array( $rel_ids ) and count( $rel_ids ) )
{
// We need to reset the array - this query bit will return everything we need, but
// if we "OR" join the above query bit with this one, it causes bigger mysql loads
$query_bits = array();
$query_bits[] = "attach_rel_id IN (" . implode( ",", $rel_ids ) . ")";
//$query = " OR attach_rel_id IN (-1," . implode( ",", $rel_ids ) . ")";
$match = 1;
@@ -524,7 +527,7 @@ class plugin_post
// to upload to another's post...
//-----------------------------------------
if ( ! $this->ipsclass->member['g_is_supmod'] )
if ( ! $this->ipsclass->member['g_is_supmod'] AND !$this->ipsclass->member['is_mod'] )
{
$post = $this->ipsclass->DB->build_and_exec_query( array( 'select' => '*',
'from' => 'posts',
@@ -562,48 +565,73 @@ class plugin_post
// Generate space allowed figure
//-----------------------------------------
if ( $this->ipsclass->member['g_attach_per_post'] )
{
//-----------------------------------------
// Per post limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => "attach_post_key='".$post_key."'" ) );
if ( $this->ipsclass->member['g_attach_per_post'] )
{
//-----------------------------------------
// Per post limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => "attach_post_key='".$post_key."'" ) );
$space_used = intval( $_space_used['figure'] );
}
else
{
//-----------------------------------------
// Global limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => 'attach_member_id='.$member_id ) );
$space_used = intval( $_space_used['figure'] );
}
else
{
//-----------------------------------------
// Global limit...
//-----------------------------------------
$_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => 'attach_member_id='.$member_id . " AND attach_rel_module IN( 'post', 'msg' )" ) );
$space_used = intval( $_space_used['figure'] );
$space_used = intval( $_space_used['figure'] );
}
if ( $this->ipsclass->member['g_attach_max'] > 0 )
{
if ( $this->ipsclass->member['g_attach_per_post'] )
{
$space_allowed = intval( ( $this->ipsclass->member['g_attach_per_post'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? 0 : $space_allowed;
$_g_space_used = $this->ipsclass->DB->build_and_exec_query( array( 'select' => 'SUM(attach_filesize) as figure',
'from' => 'attachments',
'where' => 'attach_member_id='.$member_id . " AND attach_rel_module IN( 'post', 'msg' )" ) );
$g_space_used = intval( $_g_space_used['figure'] );
if( intval( ( $this->ipsclass->member['g_attach_max'] * 1024 ) - $g_space_used ) < 0 )
{
$space_used = $g_space_used;
$total_space_allowed = $this->ipsclass->member['g_attach_max'] * 1024;
$space_allowed = intval( ( $this->ipsclass->member['g_attach_max'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
else
{
$space_allowed = intval( ( $this->ipsclass->member['g_attach_per_post'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
}
else
{
$space_allowed = intval( ( $this->ipsclass->member['g_attach_max'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? 0 : $space_allowed;
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
}
else
{
# Unlimited
$space_allowed = 0;
if ( $this->ipsclass->member['g_attach_per_post'] )
{
$space_allowed = intval( ( $this->ipsclass->member['g_attach_per_post'] * 1024 ) - $space_used );
$space_allowed = $space_allowed < 0 ? -1 : $space_allowed;
}
else
{
# Unlimited
$space_allowed = 0;
}
}
//-----------------------------------------
@@ -611,7 +639,7 @@ class plugin_post
//-----------------------------------------
$space_left = $space_allowed ? $space_allowed : 0;
$space_left = ($space_left < 0) ? 0 : $space_left;
$space_left = ($space_left < 0) ? -1 : $space_left;
//-----------------------------------------
// Generate max upload size
@@ -631,7 +659,7 @@ class plugin_post
}
$return = array( 'space_used' => $space_used, 'space_left' => $space_left, 'space_allowed' => $space_allowed, 'max_single_upload' => $max_single_upload, 'total_space_allowed' => $total_space_allowed );
return $return;
}
File diff suppressed because it is too large. Load diff
@@ -2,27 +2,17 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-11-29 16:22:46 -0600 (Wed, 29 Nov 2006) $
| > $Revision: 745 $
| > $Date: 2008-03-28 18:08:02 -0400 (Fri, 28 Mar 2008) $
| > $Revision: 1232 $
| > $Author: bfarber $
+---------------------------------------------------------------------------
|
@@ -97,8 +87,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_bbcode_core
@@ -398,6 +388,13 @@ class class_bbcode_core
*/
function clean_ipb_html( $t="" )
{
$t = $this->post_db_unparse_bbcode( $t );
//-----------------------------------------
// IE handles RTE BR tags differently
//-----------------------------------------
$t = str_replace( "<BR>", "<br />", $t );
//-----------------------------------------
// left, right, center
//-----------------------------------------
@@ -479,6 +476,24 @@ class class_bbcode_core
$t = preg_replace( "#<\{.+?\}>#", "", $t );
//-----------------------------------------
// Opening style attributes
//-----------------------------------------
$t = preg_replace( "#<!--sizeo:(.+?)-->(.+?)<!--/sizeo-->#" , '<font size="\\1">' , $t );
$t = preg_replace( "#<!--coloro:(.+?)-->(.+?)<!--/coloro-->#" , '<font color="\\1">' , $t );
$t = preg_replace( "#<!--fonto:(.+?)-->(.+?)<!--/fonto-->#" , '<font face="\\1">' , $t );
$t = preg_replace( "#<!--backgroundo:(.+?)-->(.+?)<!--/backgroundo-->#" , '<font background="\\1">' , $t );
//-----------------------------------------
// Closing style attributes
//-----------------------------------------
$t = preg_replace( "#<!--sizec-->(.+?)<!--/sizec-->#" , "</font>" , $t );
$t = preg_replace( "#<!--colorc-->(.+?)<!--/colorc-->#" , "</font>" , $t );
$t = preg_replace( "#<!--fontc-->(.+?)<!--/fontc-->#" , "</font>" , $t );
$t = preg_replace( "#<!--backgroundc-->(.+?)<!--/backgroundc-->#", "</font>" , $t );
//-----------------------------------------
// Clean up code tags
//-----------------------------------------
@@ -503,7 +518,7 @@ class class_bbcode_core
//-----------------------------------------
// INIT
//-----------------------------------------
$txt = $matches[1];
//-----------------------------------------
@@ -532,7 +547,7 @@ class class_bbcode_core
*/
function strip_quote_tags( $txt="" )
{
return preg_replace( "#\[QUOTE(=.+?,.+?)?\].+?\[/QUOTE\]#is", "", $txt );
return preg_replace( "#\[QUOTE(=.+?,.+?)?\].+?\[/QUOTE\]#ism", "", $txt );
}
/*-------------------------------------------------------------------------*/
@@ -545,17 +560,28 @@ class class_bbcode_core
* @param string Raw text
* @return string Converted text
*/
function strip_all_tags( $txt="" )
function strip_all_tags( $txt="", $pre_edit_parse=1 )
{
$txt = $this->strip_quote_tags( $this->pre_edit_parse( $txt ) );
while( preg_match( "#\[.+?\](.+?)\[/.+?\]#is", $txt ) )
if( $pre_edit_parse )
{
$txt = preg_replace( "#\[.+?\](.+?)\[/.+?\]#is", "\\1", $txt );
$txt = $this->pre_edit_parse( $txt );
}
$txt = $this->strip_quote_tags( $txt );
$txt = preg_replace( "#\[(.+?)\](.+?)\[/\\1\]#is", "\\2", $txt );
$txt = preg_replace( "#\[url\s*=\s*(?:\&quot\;|\")\s*(.*?)\s*(?:\&quot\;|\")\s*\](.*?)\[\/url\]#is", "\\2", $txt );
$txt = preg_replace( "#\[url\s*=\s*(.*?)\s*\](.*?)\[\/url\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[email\s*=\s*\&quot\;([\.\w\-]+\@[\.\w\-]+\.[\.\w\-]+)\s*\&quot\;\s*\](.*?)\[\/email\]#i" , "\\2", $txt );
$txt = preg_replace( "#\[email\s*=\s*([\.\w\-]+\@[\.\w\-]+\.[\w\-]+)\s*\](.*?)\[\/email\]#i" , "\\2", $txt );
$txt = preg_replace( "#\[background=([^\]]+)\](.+?)\[/background\]#is", "\\2", $txt );
$txt = preg_replace( "#\[size=([^\]]+)\](.+?)\[/size\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[font=([^\]]+)\](.+?)\[/font\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[color=([^\]]+)\](.+?)\[/color\]#is" , "\\2", $txt );
$txt = preg_replace( "#\[attach.+?\]#is" , "" , $txt );
return $txt;
}
@@ -725,71 +751,76 @@ class class_bbcode_core
if ( $row['bbcode_useoption'] )
{
while (preg_match_all( "#(\[".$preg_tag."=(?:&quot;|&\#39;|\")?(.+?)(?:&quot;|&\#39;|\")?\])((?R)|.*?)(\[/".$preg_tag."\])#si", $t, $match ))
// If we don't check &quot; or &#39;, topic tag dies when it's in format of [topic="number"]
while (preg_match_all( "#(\[".$preg_tag."=(?:\"|&quot;|'|&\#39;)?(.+?)(?:\"|'|&quot;|&\#39;)?\])((?R)|.*?)(\[/".$preg_tag."\])#si", $t, $match ))
{
for ( $i = 0; $i < count($match[0]); $i++)
{
//-----------------------------------------
// Does the option tag come first?
//-----------------------------------------
$_option = 2;
$_content = 3;
if ( $row['bbcode_switch_option'] )
for ( $i = 0; $i < count($match[0]); $i++)
{
$_option = 3;
$_content = 2;
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'post' OR $row['bbcode_tag'] == 'topic' OR $row['bbcode_tag'] == 'snapback' )
{
$match[ $_option ][$i] = intval( $match[ $_option ][$i] );
}
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[ $_content ][$i] ) )
{
$match[ $_content ][$i] = $this->post_db_parse_bbcode( $match[ $_content ][$i] );
}
//-----------------------------------------
// Does the option tag come first?
//-----------------------------------------
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{option}' , $match[ $_option ][$i], $tmp );
$tmp = str_replace( '{content}', $match[ $_content ][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
$_option = 2;
$_content = 3;
if ( $row['bbcode_switch_option'] )
{
$_option = 3;
$_content = 2;
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'post' OR $row['bbcode_tag'] == 'topic' OR $row['bbcode_tag'] == 'snapback' )
{
$match[ $_option ][$i] = intval( $match[ $_option ][$i] );
}
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[ $_content ][$i] ) )
{
$match[ $_content ][$i] = $this->post_db_parse_bbcode( $match[ $_content ][$i] );
}
//$match[ $_content ][$i] = preg_replace( '#(style)=#is', "$1&#61;", $match[ $_content ][$i] );
//$match[ $_option ][$i] = preg_replace( '#(style)=#is', "$1&#61;", $match[ $_option ][$i] );
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{option}' , $this->ipsclass->xss_html_clean( $match[ $_option ][$i] ), $tmp );
$tmp = str_replace( '{content}', $this->ipsclass->xss_html_clean( $match[ $_content ][$i] ), $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
}
}
}
else
{
# Tricky.. match anything that's not a closing tag, or nothing
while (preg_match_all( "#(\[$preg_tag\])((?R)|.*?)(\[/$preg_tag\])#si", $t, $match ))
{
for ( $i = 0; $i < count($match[0]); $i++)
{
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[2][$i] ) )
for ( $i = 0; $i < count($match[0]); $i++)
{
$match[2][$i] = $this->post_db_parse_bbcode( $match[2][$i] );
# Recurse?
if ( preg_match( "#\[.+?\]#s", $match[2][$i] ) )
{
$match[2][$i] = $this->post_db_parse_bbcode( $match[2][$i] );
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'snapback' )
{
$match[2][$i] = intval( $match[2][$i] );
}
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{content}', $match[2][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'snapback' )
{
$match[2][$i] = intval( $match[2][$i] );
}
$tmp = $row['bbcode_replace'];
$tmp = str_replace( '{content}', $match[2][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
}
}
}
}
//-----------------------------------------
// Snapback used?
//-----------------------------------------
@@ -802,6 +833,126 @@ class class_bbcode_core
return $t;
}
/*-------------------------------------------------------------------------*/
// Post DB UNparse BBCode
/*-------------------------------------------------------------------------*/
/**
* Pre-edit unparse custom BBCode
*
* @param string Converted text
* @return string Raw text
*/
function post_db_unparse_bbcode($t="")
{
//-----------------------------------------
// INIT
//-----------------------------------------
$snapback = 0;
//-----------------------------------------
// Check...
//-----------------------------------------
if ( is_array( $this->ipsclass->cache['bbcode'] ) and count( $this->ipsclass->cache['bbcode'] ) )
{
foreach( $this->ipsclass->cache['bbcode'] as $row )
{
if ( strtolower($row['bbcode_tag']) == 'snapback' )
{
$snapback = 1;
}
$preg_tag = preg_quote( $row['bbcode_replace'], '#' );
//NK: only return the first match
$preg_tag = preg_replace( '/\\\{option\\\}/', '(.*?)', $preg_tag, 1 );
$preg_tag = preg_replace( '/\\\{content\\\}/', '(.*?)', $preg_tag, 1 );
$preg_tag = str_replace( '\{option\}', '.*?', $preg_tag );
$preg_tag = str_replace( '\{content\}', '.*?', $preg_tag );
/*$preg_tag = str_replace( '\{option\}', '.(*?)', $preg_tag );
$preg_tag = str_replace( '\{content\}', '(.*?)', $preg_tag );*/
// Bug 5658 - </span> tags in custom bbcode don't play nice with inbuilt bbcode
$preg_tag = str_replace( "\</span\>", "\</span\>(?!\<\!--/sizec|\<\!--/colorc|\<\!--/fontc|\<\!--/backgroundc)", $preg_tag );
//-----------------------------------------
// Slightly slower
//-----------------------------------------
while ( preg_match_all( "#".$preg_tag."#si", $t, $match ) )
{
for ( $i = 0; $i < count($match[0]); $i++)
{
//-----------------------------------------
// Does the option tag come first?
//-----------------------------------------
$_option = 1;
$_content = 2;
if ( $row['bbcode_switch_option'] )
{
$_option = 2;
$_content = 1;
}
else if( count( $match ) == 2 )
{
$_content = 1;
}
# XSS Check: Bug ID: 980
if ( $row['bbcode_tag'] == 'post' OR $row['bbcode_tag'] == 'topic' OR $row['bbcode_tag'] == 'snapback' )
{
$match[ $_option ][$i] = intval( $match[ $_option ][$i] );
}
# Recurse?
if ( preg_match( "#".$preg_tag."#si", $match[ $_content ][$i] ) )
{
$match[ $_content ][$i] = $this->post_db_parse_bbcode( $match[ $_content ][$i] );
}
$tmp = '[' . $row['bbcode_tag'];
if( $row['bbcode_useoption'] )
{
if( $row['bbcode_switch_option'] )
{
$tmp .= '={content}]{option}[/' . $row['bbcode_tag'] . ']';
}
else
{
$tmp .= '={option}]{content}[/' . $row['bbcode_tag'] . ']';
}
}
else
{
$tmp .= ']{content}[/' . $row['bbcode_tag'] . ']';
}
$tmp = str_replace( '{option}' , $match[ $_option ][$i], $tmp );
$tmp = str_replace( '{content}', $match[ $_content ][$i], $tmp );
$t = str_replace( $match[0][$i], $tmp, $t );
}
}
}
}
//-----------------------------------------
// Snapback used?
//-----------------------------------------
if ( ! $snapback )
{
$t = preg_replace( "#\<a href=\'index\.php\?act=findpost&amp;pid=([0-9]+?)\'\>\<\{POST_SNAPBACK\}\>\<\/a\>#is", "[snapback]\\1[/snapback]", $t );
}
return $t;
}
//-----------------------------------------
// Word wrap, wraps 'da word innit
//-----------------------------------------
@@ -823,9 +974,10 @@ class class_bbcode_core
{
return $t;
}
#var_dump( $t );
$t = preg_replace("#([^\s<>'\"/\\-\?&\n\r\%]{".$chrs."})([^\s<>'\"/\\-\?&\n\r\%]{1})#i", "\\1".$replace."\\2" ,$t);
$t = preg_replace("#([^\s<>'\"/\\-\?&\n\r\%]{".$chrs."})#i", "\\1".$replace ,$t);
#print $chrs.' '.var_dump($replace).var_dump( $t );exit;
return $t;
}
@@ -1061,7 +1213,7 @@ class class_bbcode_core
$html = preg_replace( "/^<br>/" , "", $html );
$html = preg_replace( "#^<br />#", "", $html );
$html = preg_replace( "/^\s+/" , "", $html );
$html = preg_replace( "#&lt;([^&<>]+)&gt;#" , "&lt;<span style='color:blue'>\\1</span>&gt;" , $html ); //Matches <tag>
$html = preg_replace( "#&\#60;([a-zA-Z0-9]+)([&gt;|\s])#" , "&#60;<span style='color:blue'>\\1</span>\\2" , $html ); //Matches <script[ |>]
$html = preg_replace( "#&lt;([^&<>]+)\s#" , "&lt;<span style='color:blue'>\\1</span> " , $html ); //Matches <tag
@@ -1144,7 +1296,7 @@ class class_bbcode_core
//-----------------------------------------
// We don't want to trim indentations on the first line
//-----------------------------------------
$txt = rtrim( $matches[1] );
$txt = preg_replace( "#^(\n+)(.+?)$#s", "\\2", $txt );
@@ -1178,12 +1330,12 @@ class class_bbcode_core
//-----------------------------------------
// Ensure that spacing is preserved
//-----------------------------------------
$txt = preg_replace( "#\t#" , "&nbsp;&nbsp;&nbsp;&nbsp;", $txt );
$txt = preg_replace( "#\s{2}#", "&nbsp;&nbsp;" , $txt );
$html = $this->wrap_style( 'code' );
return "<!--c1-->{$html['START']}<!--ec1-->$txt<!--c2-->{$html['END']}<!--ec2-->";
}
@@ -1219,7 +1371,7 @@ class class_bbcode_core
//-----------------------------------------
// Make sure we've not overriden the set image # limit
//-----------------------------------------
if ( $this->ipsclass->vars['max_images'] )
{
if ($this->image_count > $this->ipsclass->vars['max_images'])
@@ -1243,8 +1395,9 @@ class class_bbcode_core
if ( $this->ipsclass->vars['allow_dynamic_img'] != 1 )
{
if ( preg_match( "/[?&;%<\[\]]/", $url) )
if ( preg_match( "/[?&<]/", $url) )
{
//var_dump($url);
$this->error = 'no_dynamic';
return $default;
}
@@ -1256,6 +1409,28 @@ class class_bbcode_core
}
}
//-----------------------------------------
// Is there another bbcode + js?
// Block XSS attempt
//-----------------------------------------
$bbcodes = array( 'b', 'i', 'u', 's', 'center', 'left', 'right', 'url', 'email', 'code', 'quote', 'sql', 'html',
'indent', 'list', 'flash', 'sub', 'sup', 'background', 'color', 'size', 'font' );
if ( is_array( $this->ipsclass->cache['bbcode'] ) and count( $this->ipsclass->cache['bbcode'] ) )
{
foreach( $this->ipsclass->cache['bbcode'] as $row )
{
$bbcodes[] = preg_quote( $row['bbcode_tag'], '#' );
}
}
if ( preg_match( "#\[(" . implode( '|', $bbcodes ) . ")(.*?)\]#is", $url ) )
{
$this->error = 'domain_not_allowed';
return $default;
}
//-----------------------------------------
// Check...
//-----------------------------------------
@@ -1265,6 +1440,42 @@ class class_bbcode_core
return '';
}
//-----------------------------------------
// Don't let emos in URL..
//-----------------------------------------
if ( $this->parse_smilies )
{
if ( count( $this->ipsclass->cache['emoticons'] ) > 0 )
{
foreach( $this->ipsclass->cache['emoticons'] as $row)
{
$code = $row['typed'];
$code = str_replace( '<', '&lt;', str_replace( '>', '&gt;', $code ) );
if( strpos( $url, $code ) )
{
$new = '';
for( $i=0; $i<strlen($code); $i++ )
{
//print dechex(ord($code{$i})).'<Br>';
$new .= '%' . dechex(ord($code{$i}));
}
$url = str_replace( $code, $new, $url );
}
}
// Using the :/ smiley
$url = str_replace( 'http%3a%2f', 'http:/', $url );
$url = str_replace( 'https%3a%2f', 'https:/', $url );
}
}
$url = htmlspecialchars($url);
$url = str_replace( '&amp;amp;', '&amp;', $url );
//-----------------------------------------
// Is the img extension allowed to be posted?
//-----------------------------------------
@@ -1309,6 +1520,11 @@ class class_bbcode_core
foreach( $list_values as $my_url )
{
if( !trim($my_url) )
{
continue;
}
$my_url = preg_quote( $my_url, '/' );
$my_url = str_replace( "\*", "(.*?)", $my_url );
@@ -1355,9 +1571,9 @@ class class_bbcode_core
//-----------------------------------------
// Signature?
//-----------------------------------------
$_class = ( $this->parsing_signature ) ? 'linked-sig-image' : 'linked-image';
// If we add an alt tag - won't be able to delete image in RTE
return "<img src=\"$url\" border=\"0\" class=\"". $_class ."\" />";
}
@@ -1527,17 +1743,23 @@ class class_bbcode_core
//-----------------------------------------
// INIT
//-----------------------------------------
if ( count( $matches ) == 3 )
$types = array( 'a', 'A', 'i', 'I', '1' );
if ( in_array( $matches[2], $types ) )
{
$type = $matches[1];
$txt = $matches[2];
$fnl = $matches[1];
$type = $matches[2];
$txt = $matches[3];
$lnl = $matches[4];
}
else
{
$txt = $matches[1];
$fnl = $matches[1];
$txt = $matches[2];
$lnl = $matches[3];
}
if ( $txt == "" )
{
return;
@@ -1547,11 +1769,11 @@ class class_bbcode_core
if ( $type == "" )
{
return "<ul>".$this->regex_list_item($txt)."</ul>";
return $fnl . "<ul>".$this->regex_list_item($txt)."</ul>" . $lnl;
}
else
{
return "<ol type='$type'>".$this->regex_list_item($txt)."</ol>";
return $fnl . "<ol type='$type'>".$this->regex_list_item($txt)."</ol>" . $lnl;
}
}
@@ -1604,6 +1826,8 @@ class class_bbcode_core
return $txt;
}
//print $txt . "<hr>";
$txt = str_replace( chr(173).']', '&#93;', $txt );
// Trim quoted text
@@ -1612,6 +1836,9 @@ class class_bbcode_core
// Clean usernames with square brackets
$txt = preg_replace_callback( "#(name=(?:&\#39;|&quot;|'|\"))(.+?)(&\#39;|&quot;|'|\")#si", array( &$this, '_make_quote_safe' ), $txt );
// Clean usernames with quotes....
$txt = preg_replace_callback( "#name=(&\#39;|&quot;|'|\")(.+?)(\\1)\s?(post|date)=#si", array( &$this, '_make_quote_name_safe' ), $txt );
$this->quote_html = $this->wrap_style('quote');
$txt = preg_replace_callback( "#\[/quote\]#i" , array( &$this, 'regex_close_quote' ) , $txt );
@@ -1620,7 +1847,12 @@ class class_bbcode_core
$txt = preg_replace_callback( "#\[quote([^\]]+?)?\]#i" , array( &$this, 'regex_simple_quote_tag' ), $txt );
$txt = str_replace( "\n", "<br />", $txt );
# Final clean...
$txt = str_replace( "&#0039;", "&#39;", $txt );
//print htmlspecialchars( $txt ); exit();
if ( ($this->quote_open == $this->quote_closed) and ($this->quote_error == 0) )
{
return $txt;
@@ -1633,7 +1865,6 @@ class class_bbcode_core
}
}
/*-------------------------------------------------------------------------*/
// regex_trim_quote: Trims quoted text
/*-------------------------------------------------------------------------*/
@@ -1888,7 +2119,7 @@ class class_bbcode_core
//-----------------------------------------
// Send off to the correct function...
//-----------------------------------------
return $this->regex_build_url( array( 'st' => $matches[1],
'html' => $matches[2],
'show' => $matches[2],
@@ -1957,6 +2188,11 @@ class class_bbcode_core
foreach( $list_values as $my_url )
{
if( !trim($my_url) )
{
continue;
}
$my_url = preg_quote( $my_url, '/' );
$my_url = str_replace( "\*", "(.*?)", $my_url );
@@ -1984,6 +2220,60 @@ class class_bbcode_core
}
}
//-----------------------------------------
// Is there another bbcode + js?
// Block XSS attempt
//-----------------------------------------
$bbcodes = array( 'b', 'i', 'u', 's', 'center', 'left', 'right', 'url', 'email', 'code', 'quote', 'sql', 'html',
'indent', 'list', 'flash', 'sub', 'sup', 'background', 'color', 'size', 'font', 'img' );
if ( is_array( $this->ipsclass->cache['bbcode'] ) and count( $this->ipsclass->cache['bbcode'] ) )
{
foreach( $this->ipsclass->cache['bbcode'] as $row )
{
$bbcodes[] = preg_quote( $row['bbcode_tag'], '#' );
}
}
if ( preg_match( "#\[(" . implode( '|', $bbcodes ) . ")(.*?)\]#is", $url['html'] ) )
{
$this->error = 'domain_not_allowed';
return $url['html'];
}
//-----------------------------------------
// Don't let emos in URL..
//-----------------------------------------
if ( $this->parse_smilies )
{
if ( count( $this->ipsclass->cache['emoticons'] ) > 0 )
{
foreach( $this->ipsclass->cache['emoticons'] as $row)
{
$code = $row['typed'];
$code = str_replace( '<', '&lt;', str_replace( '>', '&gt;', $code ) );
if( strpos( $url['html'], $code ) )
{
$new = '';
for( $i=0; $i<strlen($code); $i++ )
{
//print dechex(ord($code{$i})).'<Br>';
$new .= '%' . dechex(ord($code{$i}));
}
$url['html'] = str_replace( $code, $new, $url['html'] );
}
}
// Using the :/ smiley
$url['html'] = str_replace( 'http%3a%2f', 'http:/', $url['html'] );
$url['html'] = str_replace( 'https%3a%2f', 'https:/', $url['html'] );
}
}
//-----------------------------------------
// Make sure the last character isn't punctuation..
@@ -2024,6 +2314,7 @@ class class_bbcode_core
// clean up the ampersands / brackets
//-----------------------------------------
$url['html'] = htmlspecialchars( $url['html'] );
$url['html'] = str_replace( "&amp;amp;", "&amp;", $url['html'] );
$url['html'] = str_replace( "[" , "%5b" , $url['html'] );
$url['html'] = str_replace( "]" , "%5d" , $url['html'] );
@@ -2202,7 +2493,7 @@ class class_bbcode_core
return $default;
}
return "<!--Flash $width+$height+$url--><OBJECT CLASSID='clsid:D27CDB6E-AE6D-11cf-96B8-444553540000' WIDTH=$width HEIGHT=$height><PARAM NAME=MOVIE VALUE=$url><PARAM NAME=PLAY VALUE=TRUE><PARAM NAME=LOOP VALUE=TRUE><PARAM NAME=QUALITY VALUE=HIGH><EMBED SRC=$url WIDTH=$width HEIGHT=$height PLAY=TRUE LOOP=TRUE QUALITY=HIGH></EMBED></OBJECT><!--End Flash-->";
return "<!--Flash $width+$height+$url--><OBJECT CLASSID='clsid:D27CDB6E-AE6D-11cf-96B8-444553540000' WIDTH='$width' HEIGHT='$height'><PARAM NAME='MOVIE' VALUE='$url'><PARAM NAME='PLAY' VALUE='TRUE'><PARAM NAME='LOOP' VALUE='TRUE'><PARAM NAME='QUALITY' VALUE='HIGH'><PARAM NAME='allowscriptaccess' VALUE='never'><EMBED AllowScriptAccess='never' SRC='$url' WIDTH='$width' HEIGHT='$height' PLAY='TRUE' LOOP='TRUE' QUALITY='HIGH'></EMBED></OBJECT><!--End Flash-->";
}
/*-------------------------------------------------------------------------*/
@@ -2222,7 +2513,7 @@ class class_bbcode_core
// INIT
//-----------------------------------------
$size = $matches[1];
$size = trim($matches[1]);
$text = $matches[2];
foreach( $this->font_sizes as $k => $v )
@@ -2410,6 +2701,28 @@ class class_bbcode_core
return $begin . $txt . $end;
}
/*-------------------------------------------------------------------------*/
// Fix up quoted usernames
/*-------------------------------------------------------------------------*/
/**
* Fix up quoted usernames
*
* @param array Quote data
* @return string Converted text
*/
function _make_quote_name_safe( $matches=array() )
{
$quote = $matches[1];
$name = $matches[2];
$next = $matches[4];
# Squeeze past the parser...
$name = str_replace( '&#39;', "&#0039;", $name );
return 'name=' . $quote . $name . $quote . ' ' . $next . '=';
}
/*-------------------------------------------------------------------------*/
// Parse new quotes
/*-------------------------------------------------------------------------*/
@@ -2,26 +2,16 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-09-22 05:28:54 -0500 (Fri, 22 Sep 2006) $
| > $Date: 2006-09-22 06:28:54 -0400 (Fri, 22 Sep 2006) $
| > $Revision: 567 $
| > $Author: matt $
+---------------------------------------------------------------------------
@@ -63,8 +53,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_bbcode extends class_bbcode_core
+1 -10
View File
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>␍
+8 -18
View File
@@ -1,28 +1,18 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-09-22 05:28:54 -0500 (Fri, 22 Sep 2006) $
| > $Revision: 567 $
| > $Author: matt $
| > $Date: 2007-12-17 18:07:20 -0500 (Mon, 17 Dec 2007) $
| > $Revision: 1149 $
| > $Author: bfarber $
+---------------------------------------------------------------------------
|
| > CUSTOM PROFILE FIELD CLASS
@@ -44,8 +34,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class custom_fields
@@ -235,7 +225,7 @@ class custom_fields
// Invalid format?
//-----------------------------------------
if ( trim($this->cache_data[$i]['pf_input_format']) and $_POST[ $post.$i ] )
if ( trim($this->cache_data[$i]['pf_input_format']) and trim($_POST[ $post.$i ]) != "" )
{
$regex = str_replace( 'n', '\\d', preg_quote( $this->cache_data[$i]['pf_input_format'], "#" ) );
$regex = str_replace( 'a', '\\w', $regex );
@@ -384,7 +374,7 @@ class custom_fields
{
$pass = 1;
}
else if ( $this->mod )
else if ( $this->supmod )
{
$pass = 1;
}
+68 -59
View File
@@ -1,27 +1,17 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-12-05 09:12:45 -0600 (Tue, 05 Dec 2006) $
| > $Revision: 765 $
| > $Date: 2008-10-02 11:12:17 -0400 (Thu, 02 Oct 2008) $
| > $Revision: 2569 $
| > $Author: matt $
+---------------------------------------------------------------------------
|
@@ -36,7 +26,7 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
@@ -157,36 +147,9 @@ class display {
$version = ( isset( $this->ipsclass->vars['ipb_display_version'] ) AND $this->ipsclass->vars['ipb_display_version'] != 0 ) ? $this->ipsclass->version : '';
if ($this->ipsclass->vars['ipb_copy_number'] && $this->ipsclass->vars['ips_cp_purchase'])
{
$copyright = "";
}
else if ( TRIAL_VERSION )
{
$copyright = "<!-- Copyright Information -->
<div align='center' style='background-color:#FFF;color:#000;font-size:11px;width:auto;'>
Ðàáîòàåò íà <a href='http://www.ibresource.ru/' style='text-decoration:none' target='_blank'>ðóññêîé âåðñèè</a> <a href='http://www.invisionboard.com' target='_blank' style='color:#000'>Invision Power Board</a> (Free Trial)
{$version} &copy; ".date("Y")." &nbsp;<a href='http://www.invisionpower.com'>Invision Power Services, Inc.</a>
<br /><strong>Ñêà÷àéòå òðèàë-âåðñèþ <a href='http://www.invisionboard.com' target='_blank' style='text-decoration:underline;color:#000'>òóò!</a></strong>
</div>
<!-- / Copyright -->";
}
else
{
$copyright = "<!-- Copyright Information -->
<div align='center' class='copyright'>
<a href='http://www.ibresource.ru/' style='text-decoration:none' target='_blank'>Ðóññêàÿ âåðñèÿ</a> <a href='http://www.invisionboard.com' style='text-decoration:none' target='_blank'>IP.Board</a>
{$version} &copy; ".date("Y")." &nbsp;<a href='http://www.invisionpower.com' style='text-decoration:none' target='_blank'>IPS, Inc</a>.
";
if ( $this->ipsclass->vars['ipb_reg_show'] and $this->ipsclass->vars['ipb_reg_name'] )
{
$copyright .= "<div>".$this->ipsclass->lang['licensed_to']. $this->ipsclass->vars['ipb_reg_name']."</div>";
}
$copyright .= "</div>\n\t\t<!-- / Copyright -->";
}
// Do we want a copyright? I say: No!
// Guys... Make a "good" soft, and we keep your copyrights ;)
$copyright = "";
//-----------------------------------------
// Must be called before board_header
@@ -383,7 +346,7 @@ class display {
$this->ipsclass->DB->simple_construct( array( 'update' => 'members', 'set' => 'show_popup=0', 'where' => 'id='.$this->ipsclass->member['id'] ) );
$this->ipsclass->DB->simple_shutdown_exec();
if ( $this->ipsclass->input['act'] != 'Msg' )
if ( $this->ipsclass->input['act'] != 'Msg' AND (!$this->ipsclass->vars['board_offline'] OR $ipsclass->member['g_access_offline']) )
{
$this->ipsclass->skin['_wrapper'] = str_replace( '<!--IBF.NEWPMBOX-->', $this->ipsclass->get_new_pm_notification(), $this->ipsclass->skin['_wrapper'] );
}
@@ -425,7 +388,58 @@ class display {
$this->_finish();
print $this->ipsclass->skin['_wrapper'];
//-----------------------------------------
// Clean up...
//-----------------------------------------
unset( $this->ipsclass->skin['_wrapper'], $output_array, $this->to_print );
//-----------------------------------------
// Memory usage
//-----------------------------------------
if ( IPS_MEMORY_DEBUG_MODE AND defined( 'IPB_MEMORY_START' ) )
{
if ( is_array( $this->ipsclass->_memory_debug ) )
{
$memory .= "<br />\n<div class='tableborder'>\n<div class='subtitle'>MEMORY USAGE</div><div class='row1' style='padding:6px'>\n";
$memory .= "<table cellpadding='4' cellspacing='0' border='0' width='100%'>\n";
$_c = 0;
foreach( $this->ipsclass->_memory_debug as $usage )
{
$_col = ( $_c % 2 ) ? '#eee' : '#ddd';
$_c++;
if ( $usage[1] > 500 * 1024 )
{
$_col .= ";color:#D00000";
}
else if ( $usage[1] < 10 * 1024 )
{
$_col .= ";color:darkgreen";
}
else if ( $usage[1] < 100 * 1024 )
{
$_col .= ";color:darkorange";
}
$memory .= "<tr><td width='60%' style='background-color:{$_col}' align='left'>{$usage[0]}</td><td style='background-color:{$_col}' align='left'><strong>".$this->ipsclass->size_format( $usage[1] )."</strong></td></tr>";
}
$memory .= "</table></div></div>";
}
$end = memory_get_usage();
$peak_end = function_exists('memory_get_peak_usage') ? memory_get_peak_usage() : memory_get_usage();
$_used = $end - IPB_MEMORY_START;
$peak_used = $peak_end - IPB_MEMORY_START;
print $memory;
print "Total Memory Used: " . $this->ipsclass->size_format( $_used ) . " (Peak:".$this->ipsclass->size_format( $peak_used ).")";
}
exit;
}
@@ -820,7 +834,7 @@ class display {
foreach( $this->ipsclass->cache['languages'] as $data )
{
if ( $this->ipsclass->member['language'] == $data['ldir'] )
if ( $this->ipsclass->lang_id == $data['ldir'] )
{
$selected = ' selected="selected"';
}
@@ -1100,7 +1114,7 @@ class display {
//-----------------------------------------
$pass = 0;
$key = isset($_REQUEST['key']) ? trim( $_REQUEST['key'] ) : '';
$key = isset($this->ipsclass->input['key']) ? trim( $this->ipsclass->input['key'] ) : '';
$cust_number = 0;
$acc_number = 0;
$cust_number_tmp = '0,0';
@@ -1120,12 +1134,12 @@ class display {
{
$latest_version = $this->ipsclass->DB->build_and_exec_query( array( 'select' => '*', 'from' => 'upgrade_history', 'order' => 'upgrade_version_id DESC', 'limit' => array(0, 1) ) );
if ( $this->ipsclass->version == 'v2.2.2' )
if ( $this->ipsclass->version == 'v<{%dyn.down.var.human.version%}>' )
{
$this->ipsclass->version = 'v'.$latest_version['upgrade_version_human'];
}
if ( $this->ipsclass->acpversion == '22011' )
if ( $this->ipsclass->acpversion == '<{%dyn.down.var.long_version_id%}>' )
{
$this->ipsclass->acpversion = $latest_version['upgrade_version_id'];
}
@@ -1133,7 +1147,7 @@ class display {
list( $cust_number, $acc_number ) = explode( ',', $cust_number_tmp );
@header( "Content-type: text/xml" );
$out = '<?xml version="1.0" encoding="WINDOWS-1251"?'.'>';
$out = '<?xml version="1.0" encoding="ISO-8859-1"?'.'>';
$out .= "\n<ipscheck>\n\t<result>1</result>\n\t<customer_id>$cust_number</customer_id>\n\t<account_id>$acc_number</account_id>\n\t"
. "<version_id>{$this->ipsclass->acpversion}</version_id>\n\t<version_string>{$this->ipsclass->version}</version_string>\n\t<release_hash><![CDATA[<{%dyn.down.var.md5%}]]>></release_hash>"
. "\n</ipscheck>";
@@ -1144,12 +1158,12 @@ class display {
{
$latest_version = $this->ipsclass->DB->build_and_exec_query( array( 'select' => '*', 'from' => 'upgrade_history', 'order' => 'upgrade_version_id DESC', 'limit' => array(0, 1) ) );
if ( $this->ipsclass->version == 'v2.2.2' )
if ( $this->ipsclass->version == 'v<{%dyn.down.var.human.version%}>' )
{
$this->ipsclass->version = 'v'.$latest_version['upgrade_version_human'];
}
if ( $this->ipsclass->acpversion == '22011' )
if ( $this->ipsclass->acpversion == '<{%dyn.down.var.long_version_id%}>' )
{
$this->ipsclass->acpversion = $latest_version['upgrade_version_id'];
}
@@ -1161,7 +1175,7 @@ class display {
else
{
@header( "Content-type: text/plain" );
print "<result>0</result>\nÂû íå èìååòå äîñòóïà ê ýòîé ñòðàíèöå.";
print "<result>0</result>\nYou do not have permission to view this page.";
exit();
}
}
@@ -1182,11 +1196,6 @@ class display {
$css = $this->ipsclass->compiled_templates['skin_global']->css_inline( str_replace( "<#IMG_DIR#>", $this->ipsclass->skin['_imagedir'], $this->ipsclass->skin['_css'] ) );
}
if ( defined('LEGACY_MODE') && LEGACY_MODE == 1 )
{
$css .= '<style type="text/css" media="all">table { width:100%; }'."\n".'tr, td { padding:4px }</style>';
}
return $css;
}
File diff suppressed because it is too large. Load diff
+13 -18
View File
@@ -1,28 +1,18 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-12-04 10:31:02 -0600 (Mon, 04 Dec 2006) $
| > $Revision: 757 $
| > $Author: matt $
| > $Date: 2007-12-17 18:07:20 -0500 (Mon, 17 Dec 2007) $
| > $Revision: 1149 $
| > $Author: bfarber $
+---------------------------------------------------------------------------
|
| > FORUMS CLASS
@@ -36,7 +26,7 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
@@ -611,6 +601,11 @@ class forum_functions
$forum_data['last_poster_id'] = $data['last_poster_id'];
$forum_data['last_poster_name'] = $data['last_poster_name'];
if( !$forum_data['last_poster_id'] )
{
$forum_data['last_poster_name'] = $this->ipsclass->vars['guest_name_pre'] . $forum_data['last_poster_name'] . $this->ipsclass->vars['guest_name_suf'];
}
# Bug http://forums.invisionpower.com/index.php?autocom=bugtracker&code=show_bug&bug_title_id=3931&bug_cat_id=3
#$forum_data['status'] = $data['status'];
@@ -875,7 +870,7 @@ class forum_functions
if ( isset($forum_data['last_poster_name']))
{
$forum_data['last_poster'] = $forum_data['last_poster_id'] ? "<a href='{$this->ipsclass->base_url}showuser={$forum_data['last_poster_id']}'>{$forum_data['last_poster_name']}</a>"
: $forum_data['last_poster_name'];
: $this->ipsclass->vars['guest_name_pre'] . $forum_data['last_poster_name'] . $this->ipsclass->vars['guest_name_suf'];
}
else
{
@@ -893,7 +888,7 @@ class forum_functions
if ( $this->ipsclass->vars['disable_subforum_show'] == 0 AND $show_subforums == 1 )
{
if ( is_array( $forum_data['subforums'] ) and count( $forum_data['subforums'] ) )
if ( isset($forum_data['subforums']) and is_array( $forum_data['subforums'] ) and count( $forum_data['subforums'] ) )
{
$forum_data['show_subforums'] = $this->ipsclass->compiled_templates['skin_boards']->show_subforum_all_links( implode( ', ', $forum_data['subforums'] ) );
}
@@ -930,7 +925,7 @@ class forum_functions
{
$sub = 1;
}
$fid = $forum_data['fid'] == "" ? $forum_data['id'] : $forum_data['fid'];
# Uncomment if you want to clear markers from the last visit.
+72 -62
View File
@@ -1,27 +1,17 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-11-13 17:05:48 -0600 (Mon, 13 Nov 2006) $
| > $Revision: 728 $
| > $Date: 2008-04-21 17:32:17 -0400 (Mon, 21 Apr 2008) $
| > $Revision: 1249 $
| > $Author: bfarber $
+---------------------------------------------------------------------------
|
@@ -36,7 +26,7 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
@@ -131,7 +121,7 @@ class session
{
$ip = str_replace( '\*', '.*', preg_quote( trim($ip), "/") );
if ( preg_match( "/^$ip$/", $this->ipsclass->input['IP_ADDRESS'] ) )
if ( preg_match( "/^$ip$/", $this->ipsclass->ip_address ) )
{
$this->ipsclass->Error( array( 'LEVEL' => 1, 'MSG' => 'you_are_banned', 'INIT' => 1 ) );
}
@@ -209,16 +199,19 @@ class session
$this->member[ $k ] = $v;
}
$this->member['restrict_post'] = 1;
$this->member['g_use_search'] = 0;
$this->member['g_email_friend'] = 0;
$this->member['g_edit_profile'] = 0;
$this->member['g_use_pm'] = 0;
$this->member['g_is_supmod'] = 0;
$this->member['g_access_cp'] = 0;
$this->member['g_access_offline'] = 0;
$this->member['g_avoid_flood'] = 0;
$this->member['id'] = 0;
$this->member['mgroup'] = $this->member['g_id'];
$this->member['restrict_post'] = 1;
$this->member['g_use_search'] = 0;
$this->member['g_email_friend'] = 0;
$this->member['g_edit_profile'] = 0;
$this->member['g_use_pm'] = 0;
$this->member['g_is_supmod'] = 0;
$this->member['g_access_cp'] = 0;
$this->member['g_access_offline'] = 0;
$this->member['g_avoid_flood'] = 0;
$this->member['id'] = 0;
$this->ipsclass->member['_cache'] = array();
$this->ipsclass->member['_cache']['friends'] = array();
$this->ipsclass->perm_id = $this->member['g_perm_id'];
$this->ipsclass->perm_id_array = explode( ",", $this->ipsclass->perm_id );
@@ -256,11 +249,6 @@ class session
if ( $this->ipsclass->vars['spider_active'] )
{
$this->ipsclass->DB->simple_construct( array( 'delete' => 'sessions',
'where' => "id='".$agent.'='.str_replace('.','',$this->ipsclass->ip_address )."_session'"
) );
$this->ipsclass->DB->simple_exec();
$this->create_bot_session($agent, $this->bot_map[ strtolower($agent) ]);
}
@@ -313,7 +301,7 @@ class session
//-----------------------------------------
// Did we get a member?
//-----------------------------------------
if ( (! $this->member['id']) or ($this->member['id'] == 0) )
{
$this->unload_member();
@@ -532,14 +520,33 @@ class session
foreach( $this->ipsclass->cache['moderators'] as $r )
{
if ( $r['member_id'] == $this->member['id'] or $r['group_id'] == $this->member['mgroup'] )
if ( $r['member_id'] == $this->member['id'] )
{
$this->member['_moderator'][ $r['forum_id'] ] = $r;
$this->member['is_mod'] = 1;
}
else if( $r['group_id'] == $this->member['mgroup'] )
{
// Individual mods override group mod settings
// If array is set, don't override it
if( !is_array($this->member['_moderator'][ $r['forum_id'] ]) OR !count($this->member['_moderator'][ $r['forum_id'] ]) )
{
$this->member['_moderator'][ $r['forum_id'] ] = $r;
}
$this->member['is_mod'] = 1;
}
else if( count($other_mgroups) AND in_array( $r['group_id'], $other_mgroups ) )
{
$this->member['_moderator'][ $r['forum_id'] ] = $r;
// Individual mods override group mod settings
// If array is set, don't override it
if( !is_array($this->member['_moderator'][ $r['forum_id'] ]) OR !count($this->member['_moderator'][ $r['forum_id'] ]) )
{
$this->member['_moderator'][ $r['forum_id'] ] = $r;
}
$this->member['is_mod'] = 1;
}
}
@@ -564,7 +571,6 @@ class session
if ( !isset($this->ipsclass->input['last_activity']) OR !$this->ipsclass->input['last_activity'] )
{
$this->ipsclass->input['last_activity'] = $this->member['last_activity'] ? $this->member['last_activity'] : $this->time_now;
}
if ( !isset($this->ipsclass->input['last_visit']) OR !$this->ipsclass->input['last_visit'] )
@@ -576,7 +582,7 @@ class session
// If there hasn't been a cookie update in 2 hours,
// we assume that they've gone and come back
//-----------------------------------------
if ( ! $this->member['last_visit'] )
{
//-----------------------------------------
@@ -600,12 +606,7 @@ class session
list( $be_anon, $loggedin ) = explode( '&', $this->member['login_anonymous'] );
$this->ipsclass->DB->simple_construct( array( 'update' => 'members',
'set' => "login_anonymous='$be_anon&1', last_activity=".$this->time_now,
'where' => "id=".$this->member['id']
) );
$this->ipsclass->DB->simple_shutdown_exec();
$this->ipsclass->DB->do_shutdown_update( 'members', array( 'login_anonymous' => "{$be_anon}&1", 'last_activity' => $this->time_now ), 'id=' . $this->member['id'] );
}
//-----------------------------------------
@@ -640,7 +641,7 @@ class session
//-----------------------------------------
// Set a session ID cookie
//-----------------------------------------
$this->ipsclass->my_setcookie("session_id", $this->session_id, -1);
return $this->member;
@@ -659,6 +660,12 @@ class session
$less_is_more = array( 'g_search_flood' );
$zero_is_best = array( 'g_attach_max', 'g_attach_per_post', 'g_edit_cutoff', 'g_max_messages' );
# Blog
$zero_is_best = array_merge( $zero_is_best, array( 'g_blog_attach_max', 'g_blog_attach_per_entry', 'g_blog_preventpublish' ) );
# Gallery
$zero_is_best = array_merge( $zero_is_best, array( 'g_max_diskspace', 'g_max_upload', 'g_max_transfer', 'g_max_views', 'g_album_limit', 'g_img_album_limit', 'g_movie_size' ) );
if ( count( $groups_id ) )
{
foreach( $groups_id as $pid )
@@ -860,7 +867,7 @@ class session
return;
}
$this->ipsclass->my_setcookie( "pass_hash", $this->member['member_login_key'], 0, $this->ipsclass->vars['login_key_expire'] );
$this->ipsclass->my_setcookie( "pass_hash", $this->member['member_login_key'], ( $this->ipsclass->vars['login_key_expire'] ? 0 : 1 ), $this->ipsclass->vars['login_key_expire'] );
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
@@ -958,7 +965,7 @@ class session
{
if ( $this->ipsclass->vars['match_browser'] == 1 )
{
$query = " AND browser='".$this->ipsclass->user_agent."'";
$query = " AND browser='". substr( $this->ipsclass->user_agent, 0, 200 ) ."'";
}
if ( $this->ipsclass->vars['match_ipaddress'] == 1 )
@@ -1023,7 +1030,7 @@ class session
// Remove the defunct sessions
//-----------------------------------------
$this->ipsclass->vars['session_expiration'] = $this->ipsclass->vars['session_expiration'] ? (time() - $this->ipsclass->vars['session_expiration']) : (time() - 3600);
//$this->ipsclass->vars['session_expiration'] = $this->ipsclass->vars['session_expiration'] ? (time() - $this->ipsclass->vars['session_expiration']) : (time() - 3600);
$this->ipsclass->DB->do_delete( 'sessions', "member_id=".$this->member['id'] );
@@ -1059,7 +1066,7 @@ class session
'login_type' => intval(substr($this->member['login_anonymous'],0, 1)),
'running_time' => $this->time_now,
'ip_address' => $this->ipsclass->ip_address,
'browser' => $this->ipsclass->user_agent,
'browser' => substr( $this->ipsclass->user_agent, 0, 200 ),
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
@@ -1074,8 +1081,8 @@ class session
//-----------------------------------------
// If this is a member, update their last visit times, etc.
//-----------------------------------------
if ( time() - $this->member['last_activity'] > 3600 )
if ( time() - $this->member['last_activity'] > $this->ipsclass->vars['session_expiration'] )
{
//-----------------------------------------
// Reset the topics read cookie..
@@ -1100,7 +1107,7 @@ class session
$this->ipsclass->input['last_activity'] = $this->time_now;
}
$this->ipsclass->my_setcookie( "pass_hash", $this->member['member_login_key'], 0, $this->ipsclass->vars['login_key_expire'] );
$this->ipsclass->my_setcookie( "pass_hash", $this->member['member_login_key'], ( $this->ipsclass->vars['login_key_expire'] ? 0 : 1 ), $this->ipsclass->vars['login_key_expire'] );
$this->ipsclass->DB->do_shutdown_update( 'members', array( 'member_login_key_expire' => time() + ( $this->ipsclass->vars['login_key_expire'] * 86400 ) ), "id={$this->member['id']}" );
}
@@ -1124,7 +1131,7 @@ class session
$query = array();
$this->ipsclass->vars['session_expiration'] = $this->ipsclass->vars['session_expiration'] ? (time() - $this->ipsclass->vars['session_expiration']) : (time() - 3600);
//$this->ipsclass->vars['session_expiration'] = $this->ipsclass->vars['session_expiration'] ? (time() - $this->ipsclass->vars['session_expiration']) : (time() - 3600);
//-----------------------------------------
// Remove the defunct sessions
@@ -1178,7 +1185,7 @@ class session
'login_type' => 0,
'running_time' => $this->time_now,
'ip_address' => $this->ipsclass->ip_address,
'browser' => $this->ipsclass->user_agent,
'browser' => substr( $this->ipsclass->user_agent, 0, 200 ),
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
@@ -1201,20 +1208,21 @@ class session
// Get module settings
//-----------------------------------------
$vars = $this->_get_location_settings();
$vars = $this->_get_location_settings();
$sid = $bot . '=' . str_replace( '.', '', $this->ipsclass->ip_address ) . '_session';
$this->ipsclass->DB->force_data_type = array( 'member_name' => 'string' );
$this->ipsclass->DB->do_insert( 'sessions',
$this->ipsclass->DB->do_replace_into( 'sessions',
array(
'id' => $bot.'='.str_replace('.','',$this->ipsclass->ip_address ).'_session',
'id' => $sid,
'member_name' => $name ? $name : $bot,
'member_id' => 0,
'member_group' => $this->ipsclass->vars['spider_group'],
'login_type' => intval($this->ipsclass->vars['spider_anon']),
'running_time' => $this->time_now,
'ip_address' => $this->ipsclass->ip_address,
'browser' => $this->ipsclass->user_agent,
'browser' => substr( $this->ipsclass->user_agent, 0, 200 ),
'location' => $vars['location'],
'in_error' => 0,
'location_1_type' => isset($vars['1_type']) ? $vars['1_type'] : '',
@@ -1223,7 +1231,7 @@ class session
'location_2_id' => isset($vars['2_id']) ? intval($vars['2_id']) : 0,
'location_3_type' => isset($vars['3_type']) ? $vars['3_type'] : '',
'location_3_id' => isset($vars['3_id']) ? intval($vars['3_id']) : 0,
)
), array( 'id' )
);
}
@@ -1280,17 +1288,19 @@ class session
if ( $module )
{
$filename = ROOT_PATH.'sources/components_location/'.$this->ipsclass->txt_alphanumerical_clean( $module ).'.php';
$module = $this->ipsclass->txt_alphanumerical_clean( $module );
$filename = ROOT_PATH.'sources/components_location/' . $module .'.php';
if ( file_exists( $filename ) )
{
require_once( $filename );
$toload = 'components_location_'.$module;
$toload = 'components_location_' . $module;
$loader = new $toload;
$loader->ipsclass =& $this->ipsclass;
$return = $loader->get_session_variables();
$return['location'] = 'mod:'.$module;
$return['location'] = 'mod:' . $module;
}
}
@@ -1298,7 +1308,7 @@ class session
// FORUM
//-----------------------------------------
else if ( $this->ipsclass->input['act'] == 'sf' AND $this->ipsclass->input['f'] )
else if ( $this->ipsclass->input['_low_act'] == 'sf' AND ( isset($this->ipsclass->input['f']) AND $this->ipsclass->input['f'] ) )
{
$return = array( 'location' => 'sf',
'2_type' => 'forum',
@@ -1309,7 +1319,7 @@ class session
// TOPIC
//-----------------------------------------
else if ( $this->ipsclass->input['act'] == 'st' AND $this->ipsclass->input['t'] )
else if ( $this->ipsclass->input['act'] == 'st' AND ( isset($this->ipsclass->input['t']) AND $this->ipsclass->input['t'] ) )
{
$return = array( 'location' => 'st',
'1_type' => 'topic',
@@ -1322,7 +1332,7 @@ class session
// POST
//-----------------------------------------
else if ( $this->ipsclass->input['act'] == 'post' AND $this->ipsclass->input['f'] )
else if ( $this->ipsclass->input['act'] == 'post' AND ( isset($this->ipsclass->input['f']) AND $this->ipsclass->input['f'] ) )
{
$return = array( 'location' => 'post',
'1_type' => 'topic',
+476 -486
View File
@@ -1,487 +1,477 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-06-23 10:44:15 +0100 (Fri, 23 Jun 2006) $
| > $Revision: 338 $
| > $Author: matt $
+---------------------------------------------------------------------------
|
| > Virus Checker CLASS
| > Module written by Brandon Farber / Matt Mecham
| > Date started: Monday 3rd July 2006
|
| > Module Version Number: 1.0.0
| > DBA Checked: Wed 19 May 2004
+--------------------------------------------------------------------------
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
}
class class_virus_checker
{
/**
* Global
*/
var $ipsclass;
/**
* Directory separator
*/
var $dir_split = "/";
/**
* Dodgy files
* @var array [ idx ] = ( file_path, file_name );
*/
var $bad_files = array();
/**
* Checked folders
*/
var $checked_folders = array();
/**
* Known names
*/
var $known_names = array();
/*-------------------------------------------------------------------------*/
// CONSTRUCTAA
/*-------------------------------------------------------------------------*/
function class_virus_checker()
{
set_time_limit(0);
if ( strtoupper( substr(PHP_OS, 0, 3) ) === 'WIN' )
{
$this->dir_split = "\\";
}
//-----------------------------------------
// Known names
//-----------------------------------------
require( ROOT_PATH . 'sources/classes/class_virus_checker/lib_known_names.php' );
$this->known_names = $KNOWN_NAMES;
}
/*-------------------------------------------------------------------------*/
// Run the scan
/*-------------------------------------------------------------------------*/
/**
* Runs the scan
* All suspicious files are entered into
* $this->bad_files array
*/
function run_scan()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$expected = array();
$root_dir = preg_replace( "#^(.+?)\/$#", "\\1", ROOT_PATH );
$skin_dirs = array();
//-----------------------------------------
// Load extra db cache file
//-----------------------------------------
$this->ipsclass->DB->load_cache_file( ROOT_PATH.'sources/sql/'.SQL_DRIVER.'_extra_queries.php', 'sql_extra_queries' );
//-----------------------------------------
// Get libs
//-----------------------------------------
require( ROOT_PATH . 'sources/classes/class_virus_checker/lib_writeable_dirs.php' );
require( ROOT_PATH . 'sources/classes/class_virus_checker/lib_lang_files.php' );
//-----------------------------------------
// Sort out directory separator
//-----------------------------------------
if ( $this->dir_split != '/' )
{
$_WRITEABLE_DIRS = $WRITEABLE_DIRS;
$WRITEABLE_DIRS = array();
foreach( $_WRITEABLE_DIRS as $dir )
{
$WRITEABLE_DIRS[] = str_replace( '/' , $this->dir_split, $dir );
}
}
//-----------------------------------------
// Get language directories
//-----------------------------------------
if ( isset($this->ipsclass->cache['languages']) AND is_array( $this->ipsclass->cache['languages'] ) && count( $this->ipsclass->cache['languages'] ) )
{
foreach( $this->ipsclass->cache['languages'] as $v )
{
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'];
foreach( $LANG_FILES as $filename )
{
$expected[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'].$this->dir_split.$filename.'.php';
}
}
}
else
{
$this->ipsclass->DB->build_query( array( 'select' => 'ldir', 'from' => 'languages' ) );
$this->ipsclass->DB->exec_query();
while( $v = $this->ipsclass->DB->fetch_row() )
{
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'];
foreach( $LANG_FILES as $filename )
{
$expected[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'].$this->dir_split.$filename.'.php';
}
}
}
//-----------------------------------------
// Get skin directories
//-----------------------------------------
if ( is_array( $this->ipsclass->cache['skin_id_cache'] ) && count( $this->ipsclass->cache['skin_id_cache'] ) )
{
foreach( $this->ipsclass->cache['skin_id_cache'] as $k => $v )
{
if ( $k == 1 && !IN_DEV )
{
continue;
}
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'skin_cache'.$this->dir_split.'cacheid_'.$v['set_skin_set_id'];
$skin_dirs[] = $v['set_skin_set_id'];
}
}
else
{
$this->ipsclass->DB->build_query( array( 'select' => 'set_skin_set_id', 'from' => 'skin_sets' ) );
$this->ipsclass->DB->exec_query();
while( $v = $this->ipsclass->DB->fetch_row() )
{
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'skin_cache'.$this->dir_split.'cacheid_'.$v['set_skin_set_id '];
$skin_dirs[] = $v['set_skin_set_id'];
}
}
//-----------------------------------------
// Get skin files
//-----------------------------------------
$this->ipsclass->DB->cache_add_query( 'diag_distinct_skins', array(), 'sql_extra_queries' );
$this->ipsclass->DB->cache_exec_query();
while( $v = $this->ipsclass->DB->fetch_row() )
{
foreach( $skin_dirs as $dir )
{
$expected[] = 'cache'.$this->dir_split.'skin_cache'.$this->dir_split.'cacheid_'.$dir.$this->dir_split.$v['group_name'].'.php';
}
}
//-----------------------------------------
// Alright, do it!
//-----------------------------------------
$WRITEABLE_DIRS = array_unique($WRITEABLE_DIRS);
foreach( $WRITEABLE_DIRS as $dir_to_check )
{
if ( $dir_to_check == 'uploads' OR $dir_to_check == 'style_emoticons' )
{
# Leave this 'til later
continue;
}
if ( file_exists( $root_dir . $this->dir_split . $dir_to_check ) )
{
$this->checked_folders[] = $root_dir . $this->dir_split . $dir_to_check;
$dh = opendir( $root_dir . $this->dir_split . $dir_to_check );
while ( false !== ( $file = readdir($dh) ) )
{
if ( preg_match( "#.*\.(php|js|html|htm|cgi|pl|perl|php3|php4|php5|php6)$#i", $file ) )
{
if ( ! in_array( $dir_to_check.$this->dir_split.$file, $expected ) AND $file != "index.html" AND $file != 'lang_javascript.js' )
{
$score = intval( $this->score_file( $root_dir.$this->dir_split.$dir_to_check.$this->dir_split.$file ) );
$this->bad_files[] = array( 'file_path' => $root_dir.$this->dir_split.$dir_to_check.$this->dir_split.$file,
'file_name' => $file,
'score' => $score );
}
}
}
@closedir($dh);
}
}
//-----------------------------------------
// Check 'blog' dir
//-----------------------------------------
if ( file_exists( $root_dir.$this->dir_split.'blog' ) )
{
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'blog', 'all', array( 'index.php' ) );
}
//-----------------------------------------
// Check 'html' dir
//-----------------------------------------
if ( file_exists( $root_dir.$this->dir_split.'html' ) )
{
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'html', 'all', array( 'index.php' ) );
}
//-----------------------------------------
// Check 'Skin' dir
//-----------------------------------------
if ( file_exists( $root_dir.$this->dir_split.'Skin' ) )
{
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'Skin', 'all' );
}
//-----------------------------------------
// Check emoticons
//-----------------------------------------
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'style_emoticons', 'all' );
//-----------------------------------------
// Check image directories
//-----------------------------------------
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'style_images', '(php|cgi|pl|perl|php3|php4|php5|php6|phtml|shtml)' );
//-----------------------------------------
// Check upload directories
//-----------------------------------------
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'uploads' );
}
/*-------------------------------------------------------------------------*/
// Score a file
/*-------------------------------------------------------------------------*/
/**
* Score a file
*
* Return a score from 0 being harmless to 10 being, well the complete opposite to harmless.
*
* Score information:
* Name 3 chars or less + 2
* '- Name 2 chars or less + 4
* Size over 65k + 3
* '- Size over 100k + 4
* User nobody + 3
* Modified in the 30 days + 1
* In non PHP folder + 3
*
* @param string Full file path and name
* @param array stat info
*
* @return int Score (0 - 10 )
*/
function score_file( $file_name, $stat=array() )
{
//-----------------------------------------
// INIT
//-----------------------------------------
$SCORE = 0;
$name = preg_replace( "#^(.*)/(.+?)$#is" , "\\2", $file_name );
$name_sans_ext = preg_replace( "#^(.*)\.(.+?)$#si", "\\1", $name );
//-----------------------------------------
// Check
//-----------------------------------------
if ( ! $file_name )
{
return -1;
}
if ( ! is_array( $stat ) OR ! count( $stat ) )
{
$stat = stat( $file_name );
}
//-----------------------------------------
// Alright...
//-----------------------------------------
if ( in_array( $file_name, $this->known_names ) )
{
$SCORE += 7;
}
//-----------------------------------------
// User nobody?
//-----------------------------------------
if ( $stat['uid'] == 99 )
{
$SCORE += 3;
}
if ( strlen( $name_sans_ext ) < 3 )
{
$SCORE += 4;
}
else if ( $name_sans_ext == 'temp' OR $name_sans_ext == 'test' )
{
$SCORE +=2;
}
else if ( strlen( $name_sans_ext ) < 4 )
{
$SCORE += 2;
}
//-----------------------------------------
// Size
//-----------------------------------------
if ( $stat['size'] > 100 * 1024 )
{
$SCORE += 4;
}
else if ( $stat['size'] > 65 * 1024 )
{
$SCORE += 3;
}
//-----------------------------------------
// Last modified...
//-----------------------------------------
if ( $stat['mtime'] > time() - 86400 * 30 )
{
$SCORE += 1;
}
//-----------------------------------------
// Non PHP folder...
//-----------------------------------------
if ( preg_match( "#(?:style_images|style_emoticons|uploads|style_avatars|default|1|skin_acp|html|skin)/#i", $file_name ) )
{
$SCORE += 3;
}
//-----------------------------------------
// Return
//-----------------------------------------
return $SCORE > 10 ? 10 : $SCORE;
}
/*-------------------------------------------------------------------------*/
// Deep scan
/*-------------------------------------------------------------------------*/
/**
* Deep scan
*
* All suspicious files are entered into
* $this->bad_files array
*/
function anti_virus_deep_scan( $dir, $look_for='(php|js|html|htm|cgi|pl|perl|php3|php4|php5|php6|htaccess|so|phtml|shtml)', $ignore_files=array() )
{
//-----------------------------------------
// Short-hand
//-----------------------------------------
if ( $look_for == 'all' )
{
$look_for = '(php|js|html|htm|cgi|pl|perl|php3|php4|php5|php6|htaccess|so|phtml|shtml)';
}
//-----------------------------------------
// Add into checked folders
//-----------------------------------------
$this->checked_folders[] = $dir . $this->dir_split . $file;
$dh = opendir( $dir );
while ( false !== ( $file = readdir($dh) ) )
{
if ( IN_DEV )
{
if ( $file == '.' or $file == '..' or $file == '.svn' or $file == '.DS_store' or $file == 'index.html' )
{
continue;
}
}
else
{
if ( $file == '.' or $file == '..' )
{
continue;
}
}
if ( is_dir( $dir . $this->dir_split . $file ) )
{
$this->anti_virus_deep_scan( $dir . $this->dir_split . $file, $look_for );
}
else
{
if ( in_array( $dir . $this->dir_split . $file, $ignore_files ) )
{
continue;
}
if ( preg_match( "#^(.*)?\.".$look_for."(?:\..+?)?$#i", $file ) )
{
$score = intval( $this->score_file( $dir . $this->dir_split . $file ) );
$this->bad_files[] = array( 'file_path' => $dir . $this->dir_split . $file,
'file_name' => $file,
'score' => $score );
}
}
}
}
}
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| Licence Info: http://www.invisionboard.com/?license
+---------------------------------------------------------------------------
| > $Date: 2006-06-23 10:44:15 +0100 (Fri, 23 Jun 2006) $
| > $Revision: 338 $
| > $Author: matt $
+---------------------------------------------------------------------------
|
| > Virus Checker CLASS
| > Module written by Brandon Farber / Matt Mecham
| > Date started: Monday 3rd July 2006
|
| > Module Version Number: 1.0.0
| > DBA Checked: Wed 19 May 2004
+--------------------------------------------------------------------------
*/
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_virus_checker
{
/**
* Global
*/
var $ipsclass;
/**
* Directory separator
*/
var $dir_split = "/";
/**
* Dodgy files
* @var array [ idx ] = ( file_path, file_name );
*/
var $bad_files = array();
/**
* Checked folders
*/
var $checked_folders = array();
/**
* Known names
*/
var $known_names = array();
/*-------------------------------------------------------------------------*/
// CONSTRUCTAA
/*-------------------------------------------------------------------------*/
function class_virus_checker()
{
set_time_limit(0);
if ( strtoupper( substr(PHP_OS, 0, 3) ) === 'WIN' )
{
$this->dir_split = "\\";
}
//-----------------------------------------
// Known names
//-----------------------------------------
require( ROOT_PATH . 'sources/classes/class_virus_checker/lib_known_names.php' );
$this->known_names = $KNOWN_NAMES;
}
/*-------------------------------------------------------------------------*/
// Run the scan
/*-------------------------------------------------------------------------*/
/**
* Runs the scan
* All suspicious files are entered into
* $this->bad_files array
*/
function run_scan()
{
//-----------------------------------------
// INIT
//-----------------------------------------
$expected = array();
$root_dir = preg_replace( "#^(.+?)\/$#", "\\1", ROOT_PATH );
$skin_dirs = array();
//-----------------------------------------
// Load extra db cache file
//-----------------------------------------
$this->ipsclass->DB->load_cache_file( ROOT_PATH.'sources/sql/'.SQL_DRIVER.'_extra_queries.php', 'sql_extra_queries' );
//-----------------------------------------
// Get libs
//-----------------------------------------
require( ROOT_PATH . 'sources/classes/class_virus_checker/lib_writeable_dirs.php' );
require( ROOT_PATH . 'sources/classes/class_virus_checker/lib_lang_files.php' );
//-----------------------------------------
// Sort out directory separator
//-----------------------------------------
if ( $this->dir_split != '/' )
{
$_WRITEABLE_DIRS = $WRITEABLE_DIRS;
$WRITEABLE_DIRS = array();
foreach( $_WRITEABLE_DIRS as $dir )
{
$WRITEABLE_DIRS[] = str_replace( '/' , $this->dir_split, $dir );
}
}
//-----------------------------------------
// Get language directories
//-----------------------------------------
if ( isset($this->ipsclass->cache['languages']) AND is_array( $this->ipsclass->cache['languages'] ) && count( $this->ipsclass->cache['languages'] ) )
{
foreach( $this->ipsclass->cache['languages'] as $v )
{
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'];
foreach( $LANG_FILES as $filename )
{
$expected[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'].$this->dir_split.$filename.'.php';
}
}
}
else
{
$this->ipsclass->DB->build_query( array( 'select' => 'ldir', 'from' => 'languages' ) );
$this->ipsclass->DB->exec_query();
while( $v = $this->ipsclass->DB->fetch_row() )
{
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'];
foreach( $LANG_FILES as $filename )
{
$expected[] = 'cache'.$this->dir_split.'lang_cache'.$this->dir_split.$v['ldir'].$this->dir_split.$filename.'.php';
}
}
}
//-----------------------------------------
// Get skin directories
//-----------------------------------------
if ( is_array( $this->ipsclass->cache['skin_id_cache'] ) && count( $this->ipsclass->cache['skin_id_cache'] ) )
{
foreach( $this->ipsclass->cache['skin_id_cache'] as $k => $v )
{
if ( $k == 1 && !IN_DEV )
{
continue;
}
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'skin_cache'.$this->dir_split.'cacheid_'.$v['set_skin_set_id'];
$skin_dirs[] = $v['set_skin_set_id'];
}
}
else
{
$this->ipsclass->DB->build_query( array( 'select' => 'set_skin_set_id', 'from' => 'skin_sets' ) );
$this->ipsclass->DB->exec_query();
while( $v = $this->ipsclass->DB->fetch_row() )
{
$WRITEABLE_DIRS[] = 'cache'.$this->dir_split.'skin_cache'.$this->dir_split.'cacheid_'.$v['set_skin_set_id '];
$skin_dirs[] = $v['set_skin_set_id'];
}
}
//-----------------------------------------
// Get skin files
//-----------------------------------------
$this->ipsclass->DB->cache_add_query( 'diag_distinct_skins', array(), 'sql_extra_queries' );
$this->ipsclass->DB->cache_exec_query();
while( $v = $this->ipsclass->DB->fetch_row() )
{
foreach( $skin_dirs as $dir )
{
$expected[] = 'cache'.$this->dir_split.'skin_cache'.$this->dir_split.'cacheid_'.$dir.$this->dir_split.$v['group_name'].'.php';
}
}
//-----------------------------------------
// Alright, do it!
//-----------------------------------------
$WRITEABLE_DIRS = array_unique($WRITEABLE_DIRS);
foreach( $WRITEABLE_DIRS as $dir_to_check )
{
if ( $dir_to_check == 'uploads' OR $dir_to_check == 'style_emoticons' )
{
# Leave this 'til later
continue;
}
if ( file_exists( $root_dir . $this->dir_split . $dir_to_check ) )
{
$this->checked_folders[] = $root_dir . $this->dir_split . $dir_to_check;
$dh = opendir( $root_dir . $this->dir_split . $dir_to_check );
while ( false !== ( $file = readdir($dh) ) )
{
if ( preg_match( "#.*\.(php|js|html|htm|cgi|pl|perl|php3|php4|php5|php6)$#i", $file ) )
{
if ( ! in_array( $dir_to_check.$this->dir_split.$file, $expected ) AND $file != "index.html" AND $file != 'lang_javascript.js' )
{
$score = intval( $this->score_file( $root_dir.$this->dir_split.$dir_to_check.$this->dir_split.$file ) );
$this->bad_files[] = array( 'file_path' => $root_dir.$this->dir_split.$dir_to_check.$this->dir_split.$file,
'file_name' => $file,
'score' => $score );
}
}
}
@closedir($dh);
}
}
//-----------------------------------------
// Check 'blog' dir
//-----------------------------------------
if ( file_exists( $root_dir.$this->dir_split.'blog' ) )
{
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'blog', 'all', array( 'index.php' ) );
}
//-----------------------------------------
// Check 'html' dir
//-----------------------------------------
if ( file_exists( $root_dir.$this->dir_split.'html' ) )
{
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'html', 'all', array( 'index.php' ) );
}
//-----------------------------------------
// Check 'Skin' dir
//-----------------------------------------
if ( file_exists( $root_dir.$this->dir_split.'Skin' ) )
{
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'Skin', 'all' );
}
//-----------------------------------------
// Check emoticons
//-----------------------------------------
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'style_emoticons', 'all' );
//-----------------------------------------
// Check image directories
//-----------------------------------------
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'style_images', '(php|cgi|pl|perl|php3|php4|php5|php6|phtml|shtml)' );
//-----------------------------------------
// Check upload directories
//-----------------------------------------
$this->anti_virus_deep_scan( $root_dir.$this->dir_split.'uploads' );
}
/*-------------------------------------------------------------------------*/
// Score a file
/*-------------------------------------------------------------------------*/
/**
* Score a file
*
* Return a score from 0 being harmless to 10 being, well the complete opposite to harmless.
*
* Score information:
* Name 3 chars or less + 2
* '- Name 2 chars or less + 4
* Size over 65k + 3
* '- Size over 100k + 4
* User nobody + 3
* Modified in the 30 days + 1
* In non PHP folder + 3
*
* @param string Full file path and name
* @param array stat info
*
* @return int Score (0 - 10 )
*/
function score_file( $file_name, $stat=array() )
{
//-----------------------------------------
// INIT
//-----------------------------------------
$SCORE = 0;
$name = preg_replace( "#^(.*)/(.+?)$#is" , "\\2", $file_name );
$name_sans_ext = preg_replace( "#^(.*)\.(.+?)$#si", "\\1", $name );
//-----------------------------------------
// Check
//-----------------------------------------
if ( ! $file_name )
{
return -1;
}
if ( ! is_array( $stat ) OR ! count( $stat ) )
{
$stat = stat( $file_name );
}
//-----------------------------------------
// Alright...
//-----------------------------------------
if ( in_array( $file_name, $this->known_names ) )
{
$SCORE += 7;
}
//-----------------------------------------
// User nobody?
//-----------------------------------------
if ( $stat['uid'] == 99 )
{
$SCORE += 3;
}
if ( strlen( $name_sans_ext ) < 3 )
{
$SCORE += 4;
}
else if ( $name_sans_ext == 'temp' OR $name_sans_ext == 'test' )
{
$SCORE +=2;
}
else if ( strlen( $name_sans_ext ) < 4 )
{
$SCORE += 2;
}
//-----------------------------------------
// Size
//-----------------------------------------
if ( $stat['size'] > 100 * 1024 )
{
$SCORE += 4;
}
else if ( $stat['size'] > 65 * 1024 )
{
$SCORE += 3;
}
//-----------------------------------------
// Last modified...
//-----------------------------------------
if ( $stat['mtime'] > time() - 86400 * 30 )
{
$SCORE += 1;
}
//-----------------------------------------
// Non PHP folder...
//-----------------------------------------
if ( preg_match( "#(?:style_images|style_emoticons|uploads|style_avatars|default|1|skin_acp|html|skin)/#i", $file_name ) )
{
$SCORE += 3;
}
//-----------------------------------------
// Return
//-----------------------------------------
return $SCORE > 10 ? 10 : $SCORE;
}
/*-------------------------------------------------------------------------*/
// Deep scan
/*-------------------------------------------------------------------------*/
/**
* Deep scan
*
* All suspicious files are entered into
* $this->bad_files array
*/
function anti_virus_deep_scan( $dir, $look_for='(php|js|html|htm|cgi|pl|perl|php3|php4|php5|php6|htaccess|so|phtml|shtml)', $ignore_files=array() )
{
//-----------------------------------------
// Short-hand
//-----------------------------------------
if ( $look_for == 'all' )
{
$look_for = '(php|js|html|htm|cgi|pl|perl|php3|php4|php5|php6|htaccess|so|phtml|shtml)';
}
//-----------------------------------------
// Add into checked folders
//-----------------------------------------
$this->checked_folders[] = $dir . $this->dir_split . $file;
$dh = opendir( $dir );
while ( false !== ( $file = readdir($dh) ) )
{
if ( IN_DEV )
{
if ( $file == '.' or $file == '..' or $file == '.svn' or $file == '.DS_store' or $file == 'index.html' )
{
continue;
}
}
else
{
if ( $file == '.' or $file == '..' )
{
continue;
}
}
if ( is_dir( $dir . $this->dir_split . $file ) )
{
$this->anti_virus_deep_scan( $dir . $this->dir_split . $file, $look_for );
}
else
{
if ( in_array( $dir . $this->dir_split . $file, $ignore_files ) )
{
continue;
}
if ( preg_match( "#^(.*)?\.".$look_for."(?:\..+?)?$#i", $file ) )
{
$score = intval( $this->score_file( $dir . $this->dir_split . $file ) );
$this->bad_files[] = array( 'file_path' => $dir . $this->dir_split . $file,
'file_name' => $file,
'score' => $score );
}
}
}
}
}
?>
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>
@@ -1,24 +1,15 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| =============================================
| Invision Power Board
| ========================================
| by Matthew Mecham
| (c) 2001 - 2003 Invision Power Services
| http://www.invisionpower.com
| =============================================
| ========================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Email: matt@invisionpower.com
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+--------------------------------------------------------------------------
*/
@@ -1,24 +1,15 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| =============================================
| Invision Power Board
| ========================================
| by Matthew Mecham
| (c) 2001 - 2003 Invision Power Services
| http://www.invisionpower.com
| =============================================
| ========================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Email: matt@invisionpower.com
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+--------------------------------------------------------------------------
*/
@@ -1,24 +1,15 @@
<?php
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| =============================================
| Invision Power Board
| ========================================
| by Matthew Mecham
| (c) 2001 - 2003 Invision Power Services
| http://www.invisionpower.com
| =============================================
| ========================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Email: matt@invisionpower.com
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+--------------------------------------------------------------------------
*/
+7 -17
View File
@@ -2,28 +2,18 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-10-31 05:08:21 -0600 (Tue, 31 Oct 2006) $
| > $Revision: 686 $
| > $Author: matt $
| > $Date: 2007-05-23 11:18:41 -0400 (Wed, 23 May 2007) $
| > $Revision: 1005 $
| > $Author: bfarber $
+---------------------------------------------------------------------------
|
| > Posting Editor
@@ -91,8 +81,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_editor
@@ -260,7 +250,7 @@ class class_editor
* @param string regex end
* @return string Converted text
*/
function _rgb_to_hex($t, $t2)
function _rgb_to_hex($matches)
{
$t = $matches[1];
$t2 = $matches[2];
@@ -2,28 +2,18 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-12-04 10:31:02 -0600 (Mon, 04 Dec 2006) $
| > $Revision: 757 $
| > $Author: matt $
| > $Date: 2007-09-11 12:38:15 -0400 (Tue, 11 Sep 2007) $
| > $Revision: 1102 $
| > $Author: bfarber $
+---------------------------------------------------------------------------
|
| > Posting RTE Editor
@@ -63,8 +53,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_editor_module extends class_editor
@@ -232,7 +222,7 @@ class class_editor_module extends class_editor
//-----------------------------------------
// Fix...
//-----------------------------------------
$txt = str_replace( "&lt;br&gt;" , "\n" , $txt );
$txt = str_replace( "&lt;br /&gt;" , "\n" , $txt );
$txt = str_replace( "<br>" , "\n" , $txt );
@@ -340,7 +330,7 @@ class class_editor_module extends class_editor
{
$t = strip_tags( $t, '<h1><h2><h3><h4><h5><h6><font><span><div><br><p><img><a><li><ol><ul><b><strong><em><i><u><strike><blockquote><sub><sup>' );
}
//-----------------------------------------
// WYSI-Weirdness #1: Named anchors
//-----------------------------------------
@@ -366,6 +356,12 @@ class class_editor_module extends class_editor
$t = preg_replace( "#<(h[0-9])>(.+?)</\\1>#is", "\n[b]\\2[/b]\n", $t );
//-----------------------------------------
// WYSI-Weirdness #2.1324613: Font tags
//-----------------------------------------
$t = preg_replace( "#<font (color|size|face)=\"([a-zA-Z0-9\s\#\-]*?)\">(\s*)</font>#is", " ", $t );
//-----------------------------------------
// WYSI-Weirdness #2.5: Fix up smilies
//-----------------------------------------
@@ -668,7 +664,7 @@ class class_editor_module extends class_editor
//-----------------------------------------
// Check for inline style moz may have added
//-----------------------------------------
$this->_parse_style_attributes( $opening_tag, $start_tags, $end_tags );
return $start_tags . $this->_recurse_and_parse( 'span', $between_text, '_parse_span_tag' ) . $end_tags;
@@ -786,7 +782,7 @@ class class_editor_module extends class_editor
//-----------------------------------------
$style = $this->_get_value_of_option( 'style', $opening_tag );
//-----------------------------------------
// Convert RGB to hex
//-----------------------------------------
@@ -1311,7 +1307,7 @@ class class_editor_module extends class_editor
}
else
{
preg_match( "#$option(\s+?)?\=(\s+?)?[\"']?(.+?)([\"']|(\s+?)|$|>)#is", $text, $matches );
preg_match( "#$option(\s*?)?\=(\s*?)?[\"']?(.+?)([\"']|$|\s|>)#is", $text, $matches );
}
//preg_match( "#$option(\s+?)?\=(\s+?)?[\"']?(.+?)([\"']|$|>|\s)#is", $text, $matches );
@@ -11,13 +11,7 @@
| Web: http://www.invisionboard.com
| Licence Info: http://www.invisionboard.com/?license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-09-22 05:28:54 -0500 (Fri, 22 Sep 2006) $
| > $Date: 2006-09-22 06:28:54 -0400 (Fri, 22 Sep 2006) $
| > $Revision: 567 $
| > $Author: matt $
+---------------------------------------------------------------------------
@@ -61,8 +55,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class class_editor_module extends class_editor
+1 -10
View File
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>␍
+1 -10
View File
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>␍
@@ -109,6 +109,8 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "product_id" , $items['product_id'] );
$this->core_add_hidden_field( "quantity" , 1 );
$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -188,7 +190,7 @@ class class_gw_module EXTENDS class_gateway
// INIT
//--------------------------------------
$referers = array( 'www.2checkout.com', '2checkout.com', $_SERVER['HTTP_HOST'], str_replace( 'www.', '', $_SERVER['HTTP_HOST'] ) );
$referers = array( 'www.2checkout.com', '2checkout.com', $this->ipsclass->my_getenv('HTTP_HOST'), str_replace( 'www.', '', $this->ipsclass->my_getenv('HTTP_HOST') ) );
$got_match = 0;
//--------------------------------------
@@ -228,16 +230,17 @@ class class_gw_module EXTENDS class_gateway
// Populate return array
//--------------------------------------
list( $purchase_package_id, $member_id, $cur_sub_id, ) = explode( 'x', trim($_REQUEST['merchant_order_id']) );
list( $purchase_package_id, $member_id, $cur_sub_id, ) = explode( 'x', trim($this->ipsclass->input['merchant_order_id']) );
$return = array( 'currency_code' => 'USD',
'payment_amount' => $_REQUEST['total'],
'payment_amount' => $this->ipsclass->input['total'],
'member_unique_id' => intval($member_id),
'purchase_package_id'=> intval($purchase_package_id),
'current_package_id' => intval($cur_sub_id),
'verified' => TRUE,
'verification' => $this->ipsclass->input['verification'],
'subscription_id' => '0-'.intval($member_id),
'transaction_id' => $_REQUEST['order_number'] .'x'.time() );
'transaction_id' => $this->ipsclass->input['order_number'] .'x'.time() );
//--------------------------------------
// Sort out payment status
@@ -367,6 +370,27 @@ class class_gw_module EXTENDS class_gateway
}
/*-------------------------------------------------------------------------*/
// INSTALL Gateway...
/*-------------------------------------------------------------------------*/
function install_gateway()
{
//--------------------------------------
// DB queries
//--------------------------------------
$this->db_info = array( 'human_title' => '2CheckOut',
'human_desc' => "All major credit cards accepted. See <a href='http://www.2checkout.com/cgi-bin/aff.2c?affid=28376' target='_blank'>2CheckOut</a> for more information.",
'module_name' => $this->i_am,
'allow_creditcards' => 1,
'allow_auto_validate' => 1,
'default_currency' => 'USD' );
$this->install_lang = array( 'gw_'.$this->i_am => 'Click the button below to complete this order via our secure online payment page.' );
}
}
@@ -114,15 +114,22 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "x_amount" , $items['package_cost'] );
$this->core_add_hidden_field( "x_currency_code" , $items['currency_code'] );
$this->core_add_hidden_field( "x_description" , $items['package_title'] );
$this->core_add_hidden_field( "x_relay_response" , 'TRUE' );
#$this->core_add_hidden_field( "x_relay_response" , 'TRUE' );
$this->core_add_hidden_field( "x_receipt_link_method" , 'POST' );
$this->core_add_hidden_field( "x_receipt_link_text" , 'Return to our site!' );
$this->core_add_hidden_field( "x_receipt_link_url" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "x_show_form" , 'PAYMENT_FORM' );
$this->core_add_hidden_field( "x_test_request" , 'FALSE' );
$this->core_add_hidden_field( "x_fp_hash" , $fp_hash );
$this->core_add_hidden_field( "x_fp_timestamp" , $fp_time );
$this->core_add_hidden_field( "x_fp_sequence" , $fp_seq );
$this->core_add_hidden_field( "x_relay_url" , GW_URL_VALIDATE );
#$this->core_add_hidden_field( "x_relay_url" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "x_invoice_num" , $fp_time.'-'.$fp_seq.'-'.$items['currency_code'] );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -142,15 +149,22 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "x_amount" , $items['ttr_balance'] );
$this->core_add_hidden_field( "x_currency_code" , $items['currency_code'] );
$this->core_add_hidden_field( "x_description" , $items['package_title'] );
$this->core_add_hidden_field( "x_relay_response" , 'TRUE' );
$this->core_add_hidden_field( "x_receipt_link_method" , 'POST' );
$this->core_add_hidden_field( "x_receipt_link_text" , 'Return to our site!' );
$this->core_add_hidden_field( "x_receipt_link_url" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
#$this->core_add_hidden_field( "x_relay_response" , 'TRUE' );
$this->core_add_hidden_field( "x_show_form" , 'PAYMENT_FORM' );
$this->core_add_hidden_field( "x_test_request" , 'FALSE' );
$this->core_add_hidden_field( "x_fp_hash" , $fp_hash );
$this->core_add_hidden_field( "x_fp_timestamp" , $fp_time );
$this->core_add_hidden_field( "x_fp_sequence" , $fp_seq );
$this->core_add_hidden_field( "x_relay_url" , GW_URL_VALIDATE );
#$this->core_add_hidden_field( "x_relay_url" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "x_invoice_num" , $fp_time.'-'.$fp_seq.'-'.$items['currency_code'] );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -235,14 +249,14 @@ class class_gw_module EXTENDS class_gateway
// Check hash
//--------------------------------------
list( $fp_time, $fp_seq, $currency_code, ) = explode( '-', $_REQUEST['x_invoice_num'] );
list( $purchase_package_id, $member_id, $cur_sub_id, ) = explode( 'x', trim($_REQUEST['x_cust_id']) );
list( $fp_time, $fp_seq, $currency_code, ) = explode( '-', $this->ipsclass->input['x_invoice_num'] );
list( $purchase_package_id, $member_id, $cur_sub_id, ) = explode( 'x', trim($this->ipsclass->input['x_cust_id']) );
$in_hash = $_REQUEST['x_md5_hash'] ? $_REQUEST['x_md5_hash'] : $_REQUEST['x_MD5_Hash'];
$in_hash = $this->ipsclass->input['x_md5_hash'] ? $this->ipsclass->input['x_md5_hash'] : $this->ipsclass->input['x_MD5_Hash'];
$txn_key = $extra['company_email'];
$fp_hash = $this->my_calculatefp( $extra['vendor_id'], $txn_key, $_REQUEST['x_amount'], intval($fp_seq), intval($fp_time), trim($currency_code) );
$an_response_code = $_REQUEST['x_response_code'];
$test_hash = strtoupper( md5( $extra['vendor_id'] . $_REQUEST['x_trans_id'] . $_REQUEST['x_amount']) );
$fp_hash = $this->my_calculatefp( $extra['vendor_id'], $txn_key, $this->ipsclass->input['x_amount'], intval($fp_seq), intval($fp_time), trim($currency_code) );
$an_response_code = $this->ipsclass->input['x_response_code'];
$test_hash = strtoupper( md5( $extra['vendor_id'] . $this->ipsclass->input['x_trans_id'] . $this->ipsclass->input['x_amount']) );
if ( $in_hash != $test_hash )
{
@@ -258,21 +272,20 @@ class class_gw_module EXTENDS class_gateway
$this->error = 'not_valid';
return array( 'verified' => FALSE );
}
//--------------------------------------
// Populate return array
//--------------------------------------
$return = array( 'currency_code' => trim($currency_code),
'payment_amount' => $_REQUEST['x_amount'],
'payment_amount' => $this->ipsclass->input['x_amount'],
'member_unique_id' => intval($member_id),
'purchase_package_id'=> intval($purchase_package_id),
'current_package_id' => intval($cur_sub_id),
'verified' => TRUE,
'verification' => $this->ipsclass->input['verification'],
'subscription_id' => '0-'.intval($member_id),
'transaction_id' => $_REQUEST['x_trans_id'] );
'transaction_id' => $this->ipsclass->input['x_trans_id'] );
//--------------------------------------
// Sort out payment status
@@ -187,10 +187,10 @@ class class_gateway
$header .= "Content-Type: application/x-www-form-urlencoded\r\n";
$header .= "Content-Length: " . strlen($post_back_str) . "\r\n\r\n";
socket_set_timeout($fp, 30);
if ( $fp = fsockopen( $urls['sock_url'], $port, $errno, $errstr, 30 ) )
{
socket_set_timeout($fp, 30);
fwrite($fp, $header . $post_back_str);
while ( ! feof($fp) )
@@ -289,6 +289,26 @@ class class_gw_module EXTENDS class_gateway
}
/*-------------------------------------------------------------------------*/
// INSTALL Gateway...
/*-------------------------------------------------------------------------*/
function install_gateway()
{
//--------------------------------------
// DB queries
//--------------------------------------
$this->db_info = array( 'human_title' => 'Post Service',
'human_desc' => 'You can use this method if you wish to send us a check, postal order or international money order.',
'module_name' => $this->i_am,
'allow_creditcards' => 0,
'allow_auto_validate' => 0,
'default_currency' => 'USD' );
$this->install_lang = array( 'gw_'.$this->i_am => 'Click here to continue...' );
}
}
@@ -109,8 +109,10 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "email" , $items['company_email'] );
$this->core_add_hidden_field( "From_email" , $items['member_email'] );
$this->core_add_hidden_field( "status" , 'live' );
$this->core_add_hidden_field( "responderurl" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "returnurl" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "responderurl" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "returnurl" , GW_URL_PAYDONE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -126,8 +128,10 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "email" , $items['company_email'] );
$this->core_add_hidden_field( "From_email" , $items['member_email'] );
$this->core_add_hidden_field( "status" , 'live' );
$this->core_add_hidden_field( "responderurl" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "returnurl" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "responderurl" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "returnurl" , GW_URL_PAYDONE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -257,6 +261,7 @@ class class_gw_module EXTENDS class_gateway
'purchase_package_id'=> intval($purchase_package_id),
'current_package_id' => intval($cur_sub_id),
'verified' => TRUE,
'verification' => $this->ipsclass->input['verification'],
'subscription_id' => '0-'.intval($member_id),
'transaction_id' => $_POST['transaction_id'] );
@@ -385,8 +390,27 @@ class class_gw_module EXTENDS class_gateway
return $return;
}
/*-------------------------------------------------------------------------*/
// INSTALL Gateway...
/*-------------------------------------------------------------------------*/
function install_gateway()
{
//--------------------------------------
// DB queries
//--------------------------------------
$this->db_info = array( 'human_title' => 'NOCHEX',
'human_desc' => 'UK debit and credit cards, such as Switch, Solo and VISA Delta. All prices will be converted into GBP (UK Pounds) upon ordering.',
'module_name' => $this->i_am,
'allow_creditcards' => 1,
'allow_auto_validate' => 1,
'default_currency' => 'GBP' );
$this->install_lang = array( 'gw_'.$this->i_am => "Click the button below to complete this order via NOCHEX's website. All costs will be converted into GBP for NOCHEX's website" );
}
}
@@ -95,9 +95,11 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "src" , 1 );
$this->core_add_hidden_field( "rm" , 2 );
$this->core_add_hidden_field( "no_note" , 1 );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -126,9 +128,11 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "src" , 1 );
$this->core_add_hidden_field( "no_note" , 1 );
$this->core_add_hidden_field( "rm" , 2 );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -148,9 +152,11 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "business" , $items['company_email'] );
$this->core_add_hidden_field( "no_shipping" , 1 );
$this->core_add_hidden_field( "src" , 1 );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -171,9 +177,11 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "amount" , $items['ttr_balance'] );
$this->core_add_hidden_field( "no_shipping" , 1 );
$this->core_add_hidden_field( "src" , 1 );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL );
$this->core_add_hidden_field( "notify_url" , GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "return" , GW_URL_PAYDONE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "cancel_return", GW_URL_PAYCANCEL . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -314,6 +322,7 @@ class class_gw_module EXTENDS class_gateway
'purchase_package_id'=> intval($_POST['item_number']),
'current_package_id' => intval($cur_sub_id),
'verified' => TRUE,
'verification' => $this->ipsclass->input['verification'],
'subscription_id' => $_POST['subscr_id'],
'transaction_id' => $_POST['txn_id'] );
@@ -575,6 +584,26 @@ class class_gw_module EXTENDS class_gateway
}
/*-------------------------------------------------------------------------*/
// INSTALL Gateway...
/*-------------------------------------------------------------------------*/
function install_gateway()
{
//--------------------------------------
// DB queries
//--------------------------------------
$this->db_info = array( 'human_title' => 'PayPal',
'human_desc' => 'All major credit cards accepted. See <a href="https://www.paypal.com" target="_blank">PayPal</a> for more information.',
'module_name' => $this->i_am,
'allow_creditcards' => 1,
'allow_auto_validate' => 1,
'default_currency' => 'USD' );
$this->install_lang = array( 'gw_'.$this->i_am => "Click the button below to complete this order via PayPal's website. All costs will be converted into USD for PayPal's website" );
}
}
@@ -113,26 +113,31 @@ class class_gw_module EXTENDS class_gateway
// Generate crypt string
//---------------------------------------
$plain = "VendorTxCode=" . rand(0,1000)."x{$items['member_unique_id']}x{$items['package_id']}x0" . "&";
$plain = "VendorTxCode=" . (rand(0,32000)*rand(0,32000))."x{$items['member_unique_id']}x{$items['package_id']}x0" . "&";
$plain .= "Amount=" . $items['package_cost'] . "&";
$plain .= "Currency=" . $items['currency_code'] . "&";
$plain .= "Description=" . $items['package_title'] ."&";
$plain .= "SuccessURL=" . GW_URL_VALIDATE . "&";
$plain .= "FailureURL=" . GW_URL_VALIDATE . "&";
$plain .= "SuccessURL=" . GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) . "&";
$plain .= "FailureURL=" . GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) . "&";
$plain .= "CustomerName=&";
$plain .= "CustomerEmail=" . $items['member_email'] . "&";
$plain .= "VendorEMail=" . $items['company_email'] . "&";
$plain .= "DeliveryAddress=&";
$plain .= "DeliveryPostCode=&";
$plain .= "BillingAddress=&";
$plain .= "BillingPostCode=";
$plain .= "BillingPostCode=&";
$plain .= "ContactNumber=&";
$plain .= "ContactFax=&";
$plain .= "AllowGiftAid=&";
$plain .= "ApplyAVSCV2=&";
$plain .= "Apply3DSecure=";
$crypt = base64_encode( $this->_simple_xor( $plain, $password ) );
$this->core_add_hidden_field( "Crypt" , $crypt );
$this->core_add_hidden_field( "Vendor" , $username );
$this->core_add_hidden_field( "TxType" , 'PAYMENT' );
$this->core_add_hidden_field( "VPSProtocol" , '2.21' );
$this->core_add_hidden_field( "VPSProtocol" , '2.22' );
return $this->core_compile_hidden_fields();
}
@@ -150,26 +155,31 @@ class class_gw_module EXTENDS class_gateway
// Generate crypt string
//---------------------------------------
$plain = "VendorTxCode=" . rand(0,1000)."x{$items['member_unique_id']}x{$items['package_id']}x{$items['ttr_package_id']}" . "&";
$plain = "VendorTxCode=" . (rand(0,32000)*rand(0,32000))."x{$items['member_unique_id']}x{$items['package_id']}x{$items['ttr_package_id']}" . "&";
$plain .= "Amount=" . $items['ttr_balance'] . "&";
$plain .= "Currency=" . $items['currency_code'] . "&";
$plain .= "Description=" . $items['package_title'] ."&";
$plain .= "SuccessURL=" . GW_URL_VALIDATE . "&";
$plain .= "FailureURL=" . GW_URL_VALIDATE . "&";
$plain .= "SuccessURL=" . GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) . "&";
$plain .= "FailureURL=" . GW_URL_VALIDATE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) . "&";
$plain .= "CustomerName=&";
$plain .= "CustomerEmail=" . $items['member_email'] . "&";
$plain .= "VendorEMail=" . $items['company_email'] . "&";
$plain .= "DeliveryAddress=&";
$plain .= "DeliveryPostCode=&";
$plain .= "BillingAddress=&";
$plain .= "BillingPostCode=";
$plain .= "BillingPostCode=&";
$plain .= "ContactNumber=&";
$plain .= "ContactFax=&";
$plain .= "AllowGiftAid=&";
$plain .= "ApplyAVSCV2=&";
$plain .= "Apply3DSecure=";
$crypt = base64_encode( $this->_simple_xor( $plain, $password ) );
$this->core_add_hidden_field( "Crypt" , $crypt );
$this->core_add_hidden_field( "Vendor" , $username );
$this->core_add_hidden_field( "TxType" , 'PAYMENT' );
$this->core_add_hidden_field( "VPSProtocol" , '2.21' );
$this->core_add_hidden_field( "VPSProtocol" , '2.22' );
return $this->core_compile_hidden_fields();
}
@@ -292,8 +302,9 @@ class class_gw_module EXTENDS class_gateway
'purchase_package_id'=> intval($purchase_package_id),
'current_package_id' => intval($cur_sub_id),
'verified' => TRUE,
'verification' => $this->ipsclass->input['verification'],
'subscription_id' => '0-'.intval($member_id),
'transaction_id' => $values['VPSTxID'] );
'transaction_id' => $values['VPSTxId'] );
//--------------------------------------
// Sort out payment status
@@ -432,8 +443,20 @@ class class_gw_module EXTENDS class_gateway
function _get_token($thisString)
{
$Tokens = array("Status","StatusDetail","VendorTxCode","VPSTxID","TxAuthNo","Amount","AVSCV2");
$Tokens = array(
"Status",
"StatusDetail",
"VendorTxCode",
"VPSTxId",
"TxAuthNo",
"Amount",
"AVSCV2",
"AddressResult",
"PostCodeResult",
"CV2Result",
"GiftAid",
"3DSecureStatus",
"CAVV" );
$output = array();
$resultArray = array();
@@ -468,6 +491,27 @@ class class_gw_module EXTENDS class_gateway
return $output;
}
/*-------------------------------------------------------------------------*/
// INSTALL Gateway...
/*-------------------------------------------------------------------------*/
function install_gateway()
{
//--------------------------------------
// DB queries
//--------------------------------------
$this->db_info = array( 'human_title' => 'Protx',
'human_desc' => 'Accepts all major credit cards',
'module_name' => $this->i_am,
'allow_creditcards' => 1,
'allow_auto_validate' => 1,
'default_currency' => 'GBP' );
$this->install_lang = array( 'gw_'.$this->i_am => "Click the button below to complete this order via Protx's website" );
}
}
@@ -109,11 +109,13 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "vendorid" , $items['vendor_id'] );
$this->core_add_hidden_field( "buttonid" , "Buy" );
$this->core_add_hidden_field( "item1" , $items['package_cost'] );
$this->core_add_hidden_field( "myurl" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "myurl" , GW_URL_PAYDONE . "&verification=" . md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
$this->core_add_hidden_field( "act" , "paysubs" );
$this->core_add_hidden_field( "CODE" , "incoming" );
$this->core_add_hidden_field( "type" , "safshop" );
//$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -217,6 +219,7 @@ class class_gw_module EXTENDS class_gateway
'purchase_package_id'=> intval($purchase_package_id),
'current_package_id' => intval($cur_sub_id),
'verified' => $_POST['safshopresult'] ? TRUE : FALSE,
'verification' => $this->ipsclass->input['verification'],
'subscription_id' => '0-'.intval($member_id),
'transaction_id' => $_POST['safshopresult'] );
@@ -321,6 +324,26 @@ class class_gw_module EXTENDS class_gateway
}
/*-------------------------------------------------------------------------*/
// INSTALL Gateway...
/*-------------------------------------------------------------------------*/
function install_gateway()
{
//--------------------------------------
// DB queries
//--------------------------------------
$this->db_info = array( 'human_title' => 'Safshop',
'human_desc' => 'Accepts all major credit cards',
'module_name' => $this->i_am,
'allow_creditcards' => 1,
'allow_auto_validate' => 1,
'default_currency' => 'USD' );
$this->install_lang = array( 'gw_'.$this->i_am => "Click the button below to complete this order via Safshop's website. All costs will be converted into USD for Safshop's website" );
}
}
@@ -110,6 +110,8 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "responderurl" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "returnurl" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -127,6 +129,8 @@ class class_gw_module EXTENDS class_gateway
$this->core_add_hidden_field( "responderurl" , GW_URL_VALIDATE );
$this->core_add_hidden_field( "returnurl" , GW_URL_PAYDONE );
$this->core_add_hidden_field( "verification" , md5( $items['member_unique_id'] . $items['package_id'] . $this->ipsclass->vars['sql_pass'] ) );
return $this->core_compile_hidden_fields();
}
@@ -248,6 +252,7 @@ class class_gw_module EXTENDS class_gateway
'purchase_package_id'=> intval($purchase_package_id),
'current_package_id' => intval($cur_sub_id),
'verified' => TRUE,
'verification' => $this->ipsclass->input['verification'],
'subscription_id' => '0-'.intval($member_id),
'transaction_id' => $_POST['transaction_id'] );
@@ -28,8 +28,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class customsubs {
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>␍
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>␍
File diff suppressed because it is too large. Load diff
File diff suppressed because it is too large. Load diff
+29 -54
View File
@@ -2,28 +2,18 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-10-25 13:16:34 -0500 (Wed, 25 Oct 2006) $
| > $Revision: 676 $
| > $Author: bfarber $
| > $Date: 2008-10-02 12:04:59 -0400 (Thu, 02 Oct 2008) $
| > $Revision: 2573 $
| > $Author: matt $
+---------------------------------------------------------------------------
|
| > Post Sub-Class
@@ -35,8 +25,8 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
exit();
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
class post_functions extends class_post
@@ -141,39 +131,19 @@ class post_functions extends class_post
if( $this->ipsclass->member['id'] == 0 AND $this->ipsclass->vars['guest_captcha'] )
{
//-----------------------------------------
// Security code stuff
//-----------------------------------------
if ($this->ipsclass->input['imgid'] == "")
if ($this->ipsclass->vars['bot_antispam'])
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
// Validate CAPTCHA
require_once( KERNEL_PATH . 'class_captcha.php' );
$captchaClass = new class_captcha( $this->ipsclass, $this->ipsclass->vars['bot_antispam_type'] );
if ( $captchaClass->validate() !== TRUE )
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
}
}
$this->ipsclass->DB->simple_construct( array( 'select' => '*',
'from' => 'reg_antispam',
'where' => "regid='".trim($this->ipsclass->txt_alphanumerical_clean($this->ipsclass->input['imgid']))."'"
) );
$this->ipsclass->DB->simple_exec();
if ( ! $row = $this->ipsclass->DB->fetch_row() )
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
}
if ( trim( $this->ipsclass->txt_alphanumerical_clean($this->ipsclass->input['captcha']) ) != $row['regcode'] )
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
}
$this->ipsclass->DB->do_delete( 'reg_antispam', "regid='".trim($this->ipsclass->txt_alphanumerical_clean($this->ipsclass->input['imgid']))."'" );
}
$this->save_post();
@@ -209,7 +179,7 @@ class post_functions extends class_post
{
$pinned = 1;
$this->moderate_log('Òåìà áûëà «ïîäíÿòà» ïðè åå ïóáëèêàöèè', $this->ipsclass->input['TopicTitle']);
$this->moderate_log( $this->ipsclass->lang['modlogs_pinned'], $this->ipsclass->input['TopicTitle']);
}
}
else if ($this->ipsclass->input['mod_options'] == 'close')
@@ -218,7 +188,7 @@ class post_functions extends class_post
{
$state = 'closed';
$this->moderate_log('Òåìà áûëà çàêðûòà ïðè åå ïóáëèêàöèè', $this->ipsclass->input['TopicTitle']);
$this->moderate_log( $this->ipsclass->lang['modlogs_closed'], $this->ipsclass->input['TopicTitle']);
}
}
else if ($this->ipsclass->input['mod_options'] == 'pinclose')
@@ -228,7 +198,7 @@ class post_functions extends class_post
$pinned = 1;
$state = 'closed';
$this->moderate_log('Òåìà áûëà «ïîäíÿòà» è çàêðûòà ïðè åå ïóáëèêàöèè', $this->ipsclass->input['TopicTitle']);
$this->moderate_log( $this->ipsclass->lang['modlogs_pinclose'], $this->ipsclass->input['TopicTitle']);
}
}
}
@@ -269,7 +239,7 @@ class post_functions extends class_post
'topic_open_time' => intval( $this->times['open'] ),
'topic_close_time' => intval( $this->times['close'] ),
);
//-----------------------------------------
// Insert the topic into the database to get the
// last inserted value of the auto_increment field
@@ -409,8 +379,13 @@ class post_functions extends class_post
// Are we quoting posts?
//-----------------------------------------
$raw_post = $this->check_multi_quote();
if ( $this->han_editor->method != 'rte' )
{
$_POST['Post'] = str_replace( '&', '&amp;', $_POST['Post'] );
}
$raw_post = $this->check_multi_quote();
//-----------------------------------------
// RTE? Convert RIGHT tags that QUOTE would
// have put there
@@ -419,8 +394,8 @@ class post_functions extends class_post
if ( $this->han_editor->method == 'rte' )
{
$raw_post = $this->parser->convert_ipb_html_to_html( $raw_post );
}
}
//-----------------------------------------
// Sort out the "raw" textarea input and make it safe incase
// we have a <textarea> tag in the raw post var.
@@ -2,27 +2,17 @@
/*
+--------------------------------------------------------------------------
| Invision Power Board 2.2.2
| Invision Power Board
| =============================================
| by Matthew Mecham
| (c) 2001 - 2006 Invision Power Services, Inc.
| http://www.invisionpower.com
| =============================================
| Web: http://www.invisionboard.com
| http://www.ibresource.ru/products/invisionpowerboard/
| Time: Monday 05th of March 2007 10:10:54 PM
| Release: e3790216629e5a2aaf37070b32237f06
| Licence Info: http://www.invisionboard.com/?license
| http://www.ibresource.ru/license
+---------------------------------------------------------------------------
| INVISION POWER BOARD IS NOT FREE / OPEN SOURCE!
+---------------------------------------------------------------------------
| INVISION POWER BOARD ÍÅ ßÂËßÅÒÑß ÁÅÑÏËÀÒÍÛÌ ÏÐÎÃÐÀÌÌÍÛÌ ÎÁÅÑÏÅ×ÅÍÈÅÌ!
| Ïðàâà íà ÏÎ ïðèíàäëåæàò Invision Power Services
| Ïðàâà íà ïåðåâîä IBResource (http://www.ibresource.ru)
+---------------------------------------------------------------------------
| > $Date: 2006-10-11 07:55:47 -0500 (Wed, 11 Oct 2006) $
| > $Revision: 624 $
| > $Date: 2008-10-02 12:04:59 -0400 (Thu, 02 Oct 2008) $
| > $Revision: 2573 $
| > $Author: matt $
+---------------------------------------------------------------------------
|
@@ -35,7 +25,7 @@
if ( ! defined( 'IN_IPB' ) )
{
print "<h1>Íåêîððåêòíûé àäðåñ</h1>Âû íå èìååòå äîñòóïà ê ýòîìó ôàéëó íàïðÿìóþ. Åñëè âû íåäàâíî îáíîâëÿëè ôîðóì, âû äîëæíû îáíîâèòü âñå ñîîòâåòñòâóþùèå ôàéëû.";
print "<h1>Incorrect access</h1>You cannot access this file directly. If you have recently upgraded, make sure you upgraded all the relevant files.";
exit();
}
@@ -172,46 +162,19 @@ class post_functions extends class_post
if( $this->ipsclass->member['id'] == 0 AND $this->ipsclass->vars['guest_captcha'] )
{
//-----------------------------------------
// Security code stuff
//-----------------------------------------
if( isset($this->ipsclass->input['fast_reply_used']) AND $this->ipsclass->input['fast_reply_used'] == 1 )
if ($this->ipsclass->vars['bot_antispam'])
{
$this->obj['post_errors'] = 'reg_code_enter';
$this->show_form();
return;
}
if ($this->ipsclass->input['imgid'] == "")
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
// Validate CAPTCHA
require_once( KERNEL_PATH . 'class_captcha.php' );
$captchaClass = new class_captcha( $this->ipsclass, $this->ipsclass->vars['bot_antispam_type'] );
if ( $captchaClass->validate() !== TRUE )
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
}
}
$this->ipsclass->DB->simple_construct( array( 'select' => '*',
'from' => 'reg_antispam',
'where' => "regid='".trim($this->ipsclass->txt_alphanumerical_clean($this->ipsclass->input['imgid']))."'"
) );
$this->ipsclass->DB->simple_exec();
if ( ! $row = $this->ipsclass->DB->fetch_row() )
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
}
if ( trim( $this->ipsclass->txt_alphanumerical_clean($this->ipsclass->input['captcha']) ) != $row['regcode'] )
{
$this->obj['post_errors'] = 'err_reg_code';
$this->show_form();
return;
}
$this->ipsclass->DB->do_delete( 'reg_antispam', "regid='".trim($this->ipsclass->txt_alphanumerical_clean($this->ipsclass->input['imgid']))."'" );
}
$this->save_post();
@@ -254,7 +217,7 @@ class post_functions extends class_post
{
$this->topic['pinned'] = 1;
$this->moderate_log('Òåìà áûëà «ïîäíÿòà» ïðè îòâåòå', $this->topic['title']);
$this->moderate_log( $this->ipsclass->lang['modlogs_pinned'], $this->topic['title']);
}
}
else if ($this->ipsclass->input['mod_options'] == 'close')
@@ -263,7 +226,7 @@ class post_functions extends class_post
{
$this->topic['state'] = 'closed';
$this->moderate_log('Òåìà áûëà çàêðûòà ïðè îòâåòå', $this->topic['title']);
$this->moderate_log( $this->ipsclass->lang['modlogs_closed'], $this->topic['title']);
}
}
else if ($this->ipsclass->input['mod_options'] == 'move')
@@ -280,7 +243,7 @@ class post_functions extends class_post
$this->topic['pinned'] = 1;
$this->topic['state'] = 'closed';
$this->moderate_log('Òåìà áûëà «ïîäíÿòà» è çàêðûòà ïðè îòâåòå', $this->topic['title']);
$this->moderate_log( $this->ipsclass->lang['modlogs_pinclose'], $this->topic['title']);
}
}
}
@@ -342,10 +305,10 @@ class post_functions extends class_post
// Make sure we don't have too many images
//-----------------------------------------
$new_post = $this->parser->pre_edit_parse( $new_post );
$new_post = $this->parser->pre_db_parse( $new_post );
if( $this->parser->error )
$test_post = $this->parser->pre_edit_parse( $new_post );
$test_post = $this->parser->pre_db_parse( $test_post );
if ( $this->parser->error )
{
$this->obj['post_errors'] = 'merge_'.$this->parser->error;
$this->show_form($class);
@@ -399,7 +362,10 @@ class post_functions extends class_post
// board/forum/topic stats
//-----------------------------------------
$this->pf_update_forum_and_stats($this->topic['tid'], $this->topic['title'], 'reply');
if ( $this->obj['moderate'] != 1 and $this->obj['moderate'] != 3 AND $this->topic['approved'] == 1 )
{
$this->pf_update_forum_and_stats($this->topic['tid'], $this->topic['title'], 'reply');
}
//-----------------------------------------
// Get the correct number of replies
@@ -523,7 +489,7 @@ class post_functions extends class_post
$this->notify_new_topic_approval( $this->topic['tid'], $this->topic['title'], $this->topic['starter_name'], $this->post['pid'], 'reply' );
$page = floor( ($this->topic['posts'] + 1) / $this->ipsclass->vars['display_max_posts']);
$page = floor( $this->topic['posts'] / $this->ipsclass->vars['display_max_posts'] );
$page = $page * $this->ipsclass->vars['display_max_posts'];
$this->ipsclass->print->redirect_screen( $this->ipsclass->lang['moderate_post'], "showtopic={$this->topic['tid']}&st=$page" );
@@ -537,11 +503,14 @@ class post_functions extends class_post
//-----------------------------------------
// Check for subscribed topics
// Pass on the previous last post time of the topic
// XXPass on the previous last post time of the topic
// 12.26.2007 - we want to send email if the new post was
// made after the member's last visit...which should be
// last_activity minus session expiration
// to see if we need to send emails out
//-----------------------------------------
$this->topic_tracker( $this->topic['tid'], $this->post['post'], $poster_name, $this->last_post );
$this->topic_tracker( $this->topic['tid'], $this->post['post'], $poster_name, time() - $this->ipsclass->vars['session_expiration'] );
//-----------------------------------------
// Redirect them back to the topic
@@ -559,8 +528,25 @@ class post_functions extends class_post
}
else
{
$page = floor( ($this->topic['posts'] + 1) / $this->ipsclass->vars['display_max_posts']);
$posts = $this->topic['posts'] + 1;
if( $this->moderator['post_q'] OR $this->ipsclass->member['g_is_supmod'] )
{
$posts = $pcount + $qpcount;
}
if( ( $posts % $this->ipsclass->vars['display_max_posts'] ) == 0 )
{
$page = ( ($posts) / $this->ipsclass->vars['display_max_posts'] );
}
else
{
$page = ( ($posts) / $this->ipsclass->vars['display_max_posts'] );
$page = ceil($page) - 1;
}
$page = $page * $this->ipsclass->vars['display_max_posts'];
$this->ipsclass->boink_it($this->ipsclass->base_url."showtopic={$this->topic['tid']}&st=$page&gopid={$this->post['pid']}&#entry{$this->post['pid']}");
}
}
@@ -576,6 +562,11 @@ class post_functions extends class_post
// Are we quoting posts?
//-----------------------------------------
if ( $this->han_editor->method != 'rte' )
{
$_POST['Post'] = str_replace( '&', '&amp;', $_POST['Post'] );
}
$raw_post = $this->check_multi_quote();
//-----------------------------------------
+1 -10
View File
@@ -1,10 +1 @@
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1251" />
<meta name="author" content="Êîìïàíèÿ IBResource è Invision Power Services Inc.">
<title>Îøèáêà ðóññêîé âåðñèè Invision Power Board</title>
</head><body>
<h1>Îøèáêà <a href="http://www.ibresource.ru/">ðóññêîé âåðñèè Invision Power Board</a></h1>
<font size="4">Âû ïîïàëè íà íåñóùåñòâóþùóþ ñòðàíèöó!<br>Ïîæàëóéñòà íàæìèòå íà êíîïî÷êó &laquo;<b>Íàçàä</b>&raquo; â&nbsp;âàøåì áðàóçåðå äëÿ âîçâðàùåíèÿ íà ïðåäûäóùóþ ñòðàíèöó.</font>
</body>
</html>
<html>␍<head><title>Invision Power Board - Bulletin Board System</title></head>␍<body>␍<h1>403: Invision Power Board -> Forbidden</h1>␍<hr>␍You have reached this Page in error, please use␍your back button to return to Invision Board.␍<hr>␍<a href="http://anonym.to/http://www.invisionboard.com/">Invision Power Board</a>␍</body>␍</html>␍