Added reCAPTCHA (still needs some testing), updated links (finally), fixed one more invalid token error, fix very minor "exploit"

git-svn-id: http://kusabax.cultnet.net/svn/repo/stable@306 73d99b7e-4f53-4972-b7b7-2ecd3c4d89ee
This commit is contained in:
Sazpaimon committed 2011-07-26 16:19:55 +00:00
1 parent 9d84e86b7f
commit 0248cd497a
15 files changed
+336 -15

No files matched your search

+21 -4
View File
@@ -128,10 +128,27 @@ class Posting {
/* If the board has captcha's enabled... */
if ($board_class->board['enablecaptcha'] == 1) {
/* Check if they entered the correct code. If not... */
if ($_SESSION['security_code'] != strtolower($_POST['captcha']) || empty($_SESSION['security_code'])) {
/* Kill the script, stopping the posting process */
exitWithErrorPage(_gettext('Incorrect captcha entered.'));
if ($board_class->board['type'] == 1 && $_POST['replythread']) {
/* Check if they entered the correct code. If not... */
if ($_SESSION['security_code'] != strtolower($_POST['captcha']) || empty($_SESSION['security_code'])) {
/* Kill the script, stopping the posting process */
exitWithErrorPage(_gettext('Incorrect captcha entered.'));
}
}
else {
require_once(KU_ROOTDIR.'recaptchalib.php');
$privatekey = "6LdVg8YSAAAAALayugP2r148EEQAogHPfQOSYow-";
// was there a reCAPTCHA response?
$resp = recaptcha_check_answer ($privatekey,
$_SERVER["REMOTE_ADDR"],
$_POST["recaptcha_challenge_field"],
$_POST["recaptcha_response_field"]
);
if (!$resp->is_valid) {
// Show error and give user opportunity to try again.
exitWithErrorPage(_gettext('Incorrect captcha entered.'));
}
}
}
}