diff --git a/inc/classes/bans.class.php b/inc/classes/bans.class.php index b8c0ab9..4c5f97e 100644 --- a/inc/classes/bans.class.php +++ b/inc/classes/bans.class.php @@ -72,7 +72,14 @@ class Bans { /* Add a ip/ip range ban */ function BanUser($ip, $modname, $globalban, $duration, $boards, $reason, $staffnote, $appealat=0, $type=0, $allowread=1, $proxyban=false) { global $tc_db; - + + if ($proxyban) { + $check = $tc_db->GetOne("SELECT COUNT(*) FROM `".KU_DBPREFIX."banlist` WHERE `type` = '".$type."' AND `ipmd5` = '".md5($ip)."'"); + if ($check[0] > 0) { + return false; + } + } + if ($duration>0) { $ban_globalban = '0'; } else { @@ -84,7 +91,7 @@ class Bans { $ban_until = '0'; } - $tc_db->Execute("INSERT INTO `".KU_DBPREFIX."banlist` ( `ip` , `ipmd5` , `type` , `allowread` , `globalban` , `boards` , `by` , `at` , `until` , `reason`, `staffnote`, `appealat` ) VALUES ( ".$tc_db->qstr(md5_encrypt($ip, KU_RANDOMSEED))." , '".md5($ip)."' , '".$type."' , '".$allowread."' , '".$globalban."' , '".$boards."' , '".$modname."' , '".time()."' , ".$tc_db->qstr($ban_until)." , ".$reason." , ".$staffnote.", ".$appealat." ) "); + $tc_db->Execute("INSERT INTO `".KU_DBPREFIX."banlist` ( `ip` , `ipmd5` , `type` , `allowread` , `globalban` , `boards` , `by` , `at` , `until` , `reason`, `staffnote`, `appealat` ) VALUES ( ".$tc_db->qstr(md5_encrypt($ip, KU_RANDOMSEED))." , ".$tc_db->qstr(md5($ip))." , ".intval($type)." , ".intval($allowread)." , ".intval($globalban)." , ".$tc_db->qstr($boards)." , ".$tc_db->qstr($modname)."' , ".time()." , ".intval($ban_until)." , ".$tc_db->qstr($reason)." , ".$tc_db->qstr($staffnote).", ".intval($appealat)." ) "); if (!$proxyban && $type == 1) { $this->UpdateHtaccess(); diff --git a/inc/classes/manage.class.php b/inc/classes/manage.class.php index d443eee..d26fa48 100644 --- a/inc/classes/manage.class.php +++ b/inc/classes/manage.class.php @@ -1014,7 +1014,7 @@ class Manage { if (preg_match('/.[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+.*/', $proxy)) { $proxy = trim($proxy); $ips++; - if ($bans_class->BanUser(preg_replace('/:.*/', '', $proxy), 'SERVER', 1, 0, '', 'IP from proxylist automatically banned', '', 0)) { + if ($bans_class->BanUser(preg_replace('/:.*/', '', $proxy), 'SERVER', 1, 0, '', 'IP from proxylist automatically banned', '', 0, 0, 1, true)) { $successful++; } } @@ -3195,7 +3195,7 @@ class Manage { if (in_array(md5($ban_ip), $whitelist)) { exitWithErrorPage(_gettext('That IP is on the whitelist')); } - if ($bans_class->BanUser($ban_ip, $_SESSION['manageusername'], $ban_globalban, $ban_duration, $ban_boards, $tc_db->qstr($ban_reason), $tc_db->qstr($ban_note), $tc_db->qstr($ban_appealat), $ban_type, $ban_allowread)) { + if ($bans_class->BanUser($ban_ip, $_SESSION['manageusername'], $ban_globalban, $ban_duration, $ban_boards, $ban_reason, $ban_note, $ban_appealat, $ban_type, $ban_allowread)) { if (((KU_BANMSG != '' || $_POST['banmsg'] != '') && isset($_POST['addbanmsg']) && (isset($_POST['quickbanpostid']) || isset($_POST['quickmultibanpostid']))) || $instantban ) { $ban_msg = ((KU_BANMSG == $_POST['banmsg']) || empty($_POST['banmsg'])) ? KU_BANMSG : $_POST['banmsg']; if (isset($ban_post_id)) diff --git a/inc/classes/posting.class.php b/inc/classes/posting.class.php index 2a4cdc1..2616339 100644 --- a/inc/classes/posting.class.php +++ b/inc/classes/posting.class.php @@ -316,7 +316,7 @@ class Posting { foreach ($badlinks as $badlink) { if (stripos($_POST['message'], $badlink) !== false) { /* They included a blacklisted link in their post. Ban them for an hour */ - $bans_class->BanUser($_SERVER['REMOTE_ADDR'], 'board.php', 1, 3600, '', $tc_db->qstr(_gettext('Posting a blacklisted link.') . ' (' . $badlink . ')'), $tc_db->qstr($_POST['message'])); + $bans_class->BanUser($_SERVER['REMOTE_ADDR'], 'board.php', 1, 3600, '', _gettext('Posting a blacklisted link.') . ' (' . $badlink . ')', $_POST['message']); exitWithErrorPage(sprintf(_gettext('Blacklisted link ( %s ) detected.'), $badlink)); } }