* -------------------------------------------------------------------- *
* Kurzbeschreibung : Alle GET, POST und COOKIE-Daten sichern *
* -------------------------------------------------------------------- *
- * *
+ * $Revision:: 856 $ *
+ * $Date:: 2009-03-06 20:24:32 +0100 (Fr, 06. Mär 2009) $ *
+ * $Tag:: 0.2.1-FINAL $ *
+ * $Author:: stelzi $ *
+ * Needs to be in all Files and every File needs "svn propset *
+ * svn:keywords Date Revision" (autoprobset!) at least!!!!!! *
* -------------------------------------------------------------------- *
* Copyright (c) 2003 - 2008 by Roland Haeder *
* For more information visit: http://www.mxchange.org *
//require("/usr/share/php/ipfilter.php");
// Generate arrays which holds the relevante chars to replace
-global $SEC_CHARS, $URL_CHARS;
-$SEC_CHARS = array(
+$GLOBALS['security_chars'] = array(
// The chars we are looking for...
'from' => array("{", "}", "/", ".", "'", "$", "(", ")", '{--', '--}', "%", ";", "[", "]", ":", "--"),
// ... and we will replace to.
"{CLOSE_ANCHOR2}",
"{SLASH}",
"{DOT}",
- '{QUOT}',
+ "{QUOT}",
"{DOLLAR}",
"{OPEN_ANCHOR}",
"{CLOSE_ANCHOR}",
//
// Note: Do not replace 'to' with 'from' and vise-versa! When you do this all booked URLs will be
// rejected because of the {SLASH}, {DOT} and all below listed items inside the URL.
-$URL_CHARS = array(
+$GLOBALS['url_chars'] = array(
// Search for these secured characters
'to' => array("{SLASH}", "{DOT}", "{PER}", "{DBL_DOT}", "{COMMENT}"),
// Replace with these characters
unset($_GET[$seckey]);
} else {
// Only variables are allowed (non-array) but we secure them all!
- foreach ($SEC_CHARS['from'] as $key => $char) {
+ foreach ($GLOBALS['security_chars']['from'] as $key => $char) {
// Pass all through
- $_GET[$seckey] = str_replace($char , $SEC_CHARS['to'][$key], $_GET[$seckey]);
+ $_GET[$seckey] = str_replace($char , $GLOBALS['security_chars']['to'][$key], $_GET[$seckey]);
}
// Strip all other out
foreach ($_POST as $seckey => $secvalue) {
if (!is_array($secvalue)) {
// Only variables are allowed (non-array) to be secured...
- foreach ($SEC_CHARS['from'] as $key => $char) {
+ foreach ($GLOBALS['security_chars']['from'] as $key => $char) {
// Pass all through
- $_POST[$seckey] = str_replace($char , $SEC_CHARS['to'][$key], $_POST[$seckey]);
+ $_POST[$seckey] = str_replace($char , $GLOBALS['security_chars']['to'][$key], $_POST[$seckey]);
}
// Strip all other out