From f2e7dbc5ed8833e0168ad506f7855055cd461075 Mon Sep 17 00:00:00 2001 From: thisgun Date: Thu, 16 Apr 2026 03:46:02 +0000 Subject: [PATCH] =?UTF-8?q?[security]=EA=B7=B8=EB=88=84=EB=B3=B4=EB=93=9C5?= =?UTF-8?q?=20XSS,=20SQL=20Injection=20=EC=B7=A8=EC=95=BD=EC=A0=90=20?= =?UTF-8?q?=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- adm/admin.lib.php | 2 +- adm/admin.tail.php | 2 +- adm/board_form_update.php | 10 +++++----- adm/contentformupdate.php | 4 ++-- adm/mail_select_form.php | 2 +- adm/mail_select_list.php | 8 ++++---- adm/shop_admin/orderlist.php | 4 ++-- adm/sms_admin/config_update.php | 14 +++++++------- adm/sms_admin/form_list.php | 2 +- adm/sms_admin/num_book.php | 2 +- bbs/register_email_update.php | 4 ++-- bbs/register_form.php | 2 +- bbs/register_form_update.php | 8 ++++---- lib/common.lib.php | 6 +++--- mobile/shop/itemrecommend.php | 2 +- mobile/shop/nicepay/nicepay_result.php | 2 +- mobile/shop/nicepay/return_url_result.php | 2 +- plugin/social/popup.php | 2 +- plugin/social/register_member.php | 2 +- plugin/social/register_member_update.php | 8 ++++---- shop/itemrecommend.php | 2 +- shop/nicepay/nicepay_result.php | 2 +- shop/orderinquiryview.php | 2 +- shop/settle_nicepay_common.php | 4 ++-- 24 files changed, 49 insertions(+), 49 deletions(-) diff --git a/adm/admin.lib.php b/adm/admin.lib.php index 0f824b269..ff2b9766c 100644 --- a/adm/admin.lib.php +++ b/adm/admin.lib.php @@ -389,7 +389,7 @@ function order_select($fld, $sel = '') // 불법접근을 막도록 토큰을 생성하면서 토큰값을 리턴 function get_admin_token() { - $token = md5(uniqid(rand(), true)); + $token = get_random_token_string(16); set_session('ss_admin_token', $token); return $token; diff --git a/adm/admin.tail.php b/adm/admin.tail.php index 68b6dae12..a44a66acc 100644 --- a/adm/admin.tail.php +++ b/adm/admin.tail.php @@ -17,7 +17,7 @@ $print_version = ($is_admin == 'super') ? 'Version ' . G5_GNUBOARD_VER : ''; diff --git a/adm/board_form_update.php b/adm/board_form_update.php index 83ff74b52..713661932 100644 --- a/adm/board_form_update.php +++ b/adm/board_form_update.php @@ -139,7 +139,7 @@ $bo_hot = isset($_POST['bo_hot']) ? (int) $_POST['bo_hot'] : 0; $bo_image_width = isset($_POST['bo_image_width']) ? (int) $_POST['bo_image_width'] : 0; $bo_use_search = isset($_POST['bo_use_search']) ? (int) $_POST['bo_use_search'] : 0; $bo_use_cert = isset($_POST['bo_use_cert']) ? preg_replace('/[^0-9a-z_]/i', '', $_POST['bo_use_cert']) : ''; -$bo_device = isset($_POST['bo_device']) ? clean_xss_tags($_POST['bo_device'], 1, 1) : ''; +$bo_device = isset($_POST['bo_device']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_device']), 1, 1)) : ''; $bo_list_level = isset($_POST['bo_list_level']) ? (int) $_POST['bo_list_level'] : 0; $bo_read_level = isset($_POST['bo_read_level']) ? (int) $_POST['bo_read_level'] : 0; $bo_write_level = isset($_POST['bo_write_level']) ? (int) $_POST['bo_write_level'] : 0; @@ -155,9 +155,9 @@ $bo_read_point = isset($_POST['bo_read_point']) ? (int) $_POST['bo_read_point'] $bo_write_point = isset($_POST['bo_write_point']) ? (int) $_POST['bo_write_point'] : 0; $bo_comment_point = isset($_POST['bo_comment_point']) ? (int) $_POST['bo_comment_point'] : 0; $bo_download_point = isset($_POST['bo_download_point']) ? (int) $_POST['bo_download_point'] : 0; -$bo_select_editor = isset($_POST['bo_select_editor']) ? clean_xss_tags($_POST['bo_select_editor'], 1, 1) : ''; -$bo_skin = isset($_POST['bo_skin']) ? clean_xss_tags($_POST['bo_skin'], 1, 1) : ''; -$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? clean_xss_tags($_POST['bo_mobile_skin'], 1, 1) : ''; +$bo_select_editor = isset($_POST['bo_select_editor']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_select_editor']), 1, 1)) : ''; +$bo_skin = isset($_POST['bo_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_skin']), 1, 1)) : ''; +$bo_mobile_skin = isset($_POST['bo_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_mobile_skin']), 1, 1)) : ''; $bo_content_head = isset($_POST['bo_content_head']) ? $_POST['bo_content_head'] : ''; $bo_content_tail = isset($_POST['bo_content_tail']) ? $_POST['bo_content_tail'] : ''; $bo_mobile_content_head = isset($_POST['bo_mobile_content_head']) ? $_POST['bo_mobile_content_head'] : ''; @@ -176,7 +176,7 @@ $bo_write_min = isset($_POST['bo_write_min']) ? (int) $_POST['bo_write_min'] : 0 $bo_write_max = isset($_POST['bo_write_max']) ? (int) $_POST['bo_write_max'] : 0; $bo_comment_min = isset($_POST['bo_comment_min']) ? (int) $_POST['bo_comment_min'] : 0; $bo_comment_max = isset($_POST['bo_comment_max']) ? (int) $_POST['bo_comment_max'] : 0; -$bo_sort_field = isset($_POST['bo_sort_field']) ? clean_xss_tags($_POST['bo_sort_field'], 1, 1) : ''; +$bo_sort_field = isset($_POST['bo_sort_field']) ? addslashes(clean_xss_tags(stripslashes($_POST['bo_sort_field']), 1, 1)) : ''; if (strpbrk($bo_skin.$bo_mobile_skin, "?%*:|\"<>") !== false) { alert('스킨 디렉토리명 오류!'); diff --git a/adm/contentformupdate.php b/adm/contentformupdate.php index 2f88546be..61eac97ab 100644 --- a/adm/contentformupdate.php +++ b/adm/contentformupdate.php @@ -35,8 +35,8 @@ $co_timg_del = (isset($_POST['co_timg_del']) && $_POST['co_timg_del']) ? 1 : 0; $co_html = isset($_POST['co_html']) ? (int) $_POST['co_html'] : 0; $co_content = isset($_POST['co_content']) ? $_POST['co_content'] : ''; $co_mobile_content = isset($_POST['co_mobile_content']) ? $_POST['co_mobile_content'] : ''; -$co_skin = isset($_POST['co_skin']) ? clean_xss_tags($_POST['co_skin'], 1, 1) : ''; -$co_mobile_skin = isset($_POST['co_mobile_skin']) ? clean_xss_tags($_POST['co_mobile_skin'], 1, 1) : ''; +$co_skin = isset($_POST['co_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_skin']), 1, 1)) : ''; +$co_mobile_skin = isset($_POST['co_mobile_skin']) ? addslashes(clean_xss_tags(stripslashes($_POST['co_mobile_skin']), 1, 1)) : ''; // 관리자가 자동등록방지를 사용해야 할 경우 if (((isset($co_row['co_include_head']) && $co_row['co_include_head'] !== $co_include_head) || (isset($co_row['co_include_tail']) && $co_row['co_include_tail'] !== $co_include_tail)) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) { diff --git a/adm/mail_select_form.php b/adm/mail_select_form.php index 62ea8f91b..b8c62ab5f 100644 --- a/adm/mail_select_form.php +++ b/adm/mail_select_form.php @@ -80,7 +80,7 @@ require_once './admin.head.php'; - + diff --git a/adm/mail_select_list.php b/adm/mail_select_list.php index 78d802eb3..c040205ab 100644 --- a/adm/mail_select_list.php +++ b/adm/mail_select_list.php @@ -12,10 +12,10 @@ $sql_common = " from {$g5['member_table']} "; $sql_where = " where (1) "; $mb_id1 = isset($_POST['mb_id1']) ? (int) $_POST['mb_id1'] : 1; -$mb_id1_from = isset($_POST['mb_id1_from']) ? clean_xss_tags($_POST['mb_id1_from'], 1, 1, 30) : ''; -$mb_id1_to = isset($_POST['mb_id1_to']) ? clean_xss_tags($_POST['mb_id1_to'], 1, 1, 30) : ''; -$mb_email = isset($_POST['mb_email']) ? clean_xss_tags($_POST['mb_email'], 1, 1, 100) : ''; -$mb_mailling = isset($_POST['mb_mailling']) ? clean_xss_tags($_POST['mb_mailling'], 1, 1, 100) : ''; +$mb_id1_from = isset($_POST['mb_id1_from']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_from']), 1, 1, 30)) : ''; +$mb_id1_to = isset($_POST['mb_id1_to']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_id1_to']), 1, 1, 30)) : ''; +$mb_email = isset($_POST['mb_email']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_email']), 1, 1, 100)) : ''; +$mb_mailling = isset($_POST['mb_mailling']) ? addslashes(clean_xss_tags(stripslashes($_POST['mb_mailling']), 1, 1, 100)) : ''; $mb_level_from = isset($_POST['mb_level_from'])? (int) $_POST['mb_level_from'] : 1; $mb_level_to = isset($_POST['mb_level_to']) ? (int) $_POST['mb_level_to'] : 10; diff --git a/adm/shop_admin/orderlist.php b/adm/shop_admin/orderlist.php index abddc6510..f8aa4e3e1 100644 --- a/adm/shop_admin/orderlist.php +++ b/adm/shop_admin/orderlist.php @@ -26,8 +26,8 @@ $od_cancel_price = isset($_GET['od_cancel_price']) ? preg_replace('/[^0-9a-z]/i' $od_refund_price = isset($_GET['od_refund_price']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_refund_price']) : ''; $od_receipt_point = isset($_GET['od_receipt_point']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_receipt_point']) : ''; $od_coupon = isset($_GET['od_coupon']) ? preg_replace('/[^0-9a-z]/i', '', $_GET['od_coupon']) : ''; -$od_settle_case = isset($_GET['od_settle_case']) ? clean_xss_tags($_GET['od_settle_case'], 1, 1) : ''; -$od_escrow = isset($_GET['od_escrow']) ? clean_xss_tags($_GET['od_escrow'], 1, 1) : ''; +$od_settle_case = isset($_GET['od_settle_case']) ? addslashes(clean_xss_tags(stripslashes($_GET['od_settle_case']), 1, 1)) : ''; +$od_escrow = isset($_GET['od_escrow']) ? addslashes(clean_xss_tags(stripslashes($_GET['od_escrow']), 1, 1)) : ''; $tot_itemcount = $tot_orderprice = $tot_receiptprice = $tot_ordercancel = $tot_misu = $tot_couponprice = 0; $sql_search = ""; diff --git a/adm/sms_admin/config_update.php b/adm/sms_admin/config_update.php index da708f998..9bd20aac6 100644 --- a/adm/sms_admin/config_update.php +++ b/adm/sms_admin/config_update.php @@ -10,14 +10,14 @@ check_admin_token(); $g5['title'] = "SMS 기본설정"; -$cf_phone = isset($_REQUEST['cf_phone']) ? clean_xss_tags($_REQUEST['cf_phone'], 1, 1) : ''; -$cf_sms_use = isset($_REQUEST['cf_sms_use']) ? clean_xss_tags($_REQUEST['cf_sms_use'], 1, 1) : ''; -$cf_sms_type = isset($_REQUEST['cf_sms_type']) ? clean_xss_tags($_REQUEST['cf_sms_type'], 1, 1) : ''; -$cf_icode_id = isset($_REQUEST['cf_icode_id']) ? clean_xss_tags($_REQUEST['cf_icode_id'], 1, 1) : ''; -$cf_icode_pw = isset($_REQUEST['cf_icode_pw']) ? clean_xss_tags($_REQUEST['cf_icode_pw'], 1, 1) : ''; -$cf_icode_server_ip = isset($_REQUEST['cf_icode_server_ip']) ? clean_xss_tags($_REQUEST['cf_icode_server_ip'], 1, 1) : ''; +$cf_phone = isset($_REQUEST['cf_phone']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_phone']), 1, 1)) : ''; +$cf_sms_use = isset($_REQUEST['cf_sms_use']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_sms_use']), 1, 1)) : ''; +$cf_sms_type = isset($_REQUEST['cf_sms_type']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_sms_type']), 1, 1)) : ''; +$cf_icode_id = isset($_REQUEST['cf_icode_id']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_id']), 1, 1)) : ''; +$cf_icode_pw = isset($_REQUEST['cf_icode_pw']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_pw']), 1, 1)) : ''; +$cf_icode_server_ip = isset($_REQUEST['cf_icode_server_ip']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_server_ip']), 1, 1)) : ''; $cf_icode_server_port = isset($_REQUEST['cf_icode_server_port']) ? clean_xss_tags($_REQUEST['cf_icode_server_port'], 1, 1) : ''; -$cf_icode_token_key = isset($_REQUEST['cf_icode_token_key']) ? clean_xss_tags($_REQUEST['cf_icode_token_key'], 1, 1) : ''; +$cf_icode_token_key = isset($_REQUEST['cf_icode_token_key']) ? addslashes(clean_xss_tags(stripslashes($_REQUEST['cf_icode_token_key']), 1, 1)) : ''; // 회신번호 체크 if(!check_vaild_callback($cf_phone)) diff --git a/adm/sms_admin/form_list.php b/adm/sms_admin/form_list.php index 2fb38343b..4322c2b7c 100644 --- a/adm/sms_admin/form_list.php +++ b/adm/sms_admin/form_list.php @@ -114,7 +114,7 @@ function multi_update(sel)
- diff --git a/adm/sms_admin/num_book.php b/adm/sms_admin/num_book.php index 270882031..871c65226 100644 --- a/adm/sms_admin/num_book.php +++ b/adm/sms_admin/num_book.php @@ -130,7 +130,7 @@ function no_hp_click(val) - diff --git a/bbs/register_email_update.php b/bbs/register_email_update.php index b10ad011f..94251219b 100644 --- a/bbs/register_email_update.php +++ b/bbs/register_email_update.php @@ -45,8 +45,8 @@ $subject = '['.$config['cf_title'].'] 인증확인 메일입니다.'; $mb_name = $mb['mb_name']; -// 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 -$mb_md5 = md5(pack('V*', rand(), rand(), rand(), rand())); +// 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 (CSPRNG 사용) +$mb_md5 = get_random_token_string(16); sql_query(" update {$g5['member_table']} set mb_email_certify2 = '$mb_md5' where mb_id = '{$esc_mb_id}' "); diff --git a/bbs/register_form.php b/bbs/register_form.php index df6c1c8dc..d50651a35 100644 --- a/bbs/register_form.php +++ b/bbs/register_form.php @@ -6,7 +6,7 @@ include_once(G5_LIB_PATH.'/register.lib.php'); run_event('register_form_before'); // 불법접근을 막도록 토큰생성 -$token = md5(uniqid(rand(), true)); +$token = get_random_token_string(16); set_session("ss_token", $token); set_session("ss_cert_no", ""); set_session("ss_cert_hash", ""); diff --git a/bbs/register_form_update.php b/bbs/register_form_update.php index e5138519e..6bfabba6d 100644 --- a/bbs/register_form_update.php +++ b/bbs/register_form_update.php @@ -305,9 +305,9 @@ if ($w == '') { if ($config['cf_email_mb_member']) { $subject = '['.$config['cf_title'].'] 회원가입을 축하드립니다.'; - // 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 + // 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 (CSPRNG 사용) if ($config['cf_use_email_certify']) { - $mb_md5 = md5(pack('V*', rand(), rand(), rand(), rand())); + $mb_md5 = get_random_token_string(16); sql_query(" update {$g5['member_table']} set mb_email_certify2 = '$mb_md5' where mb_id = '$mb_id' "); $certify_href = G5_BBS_URL.'/email_certify.php?mb_id='.$mb_id.'&mb_md5='.$mb_md5; } @@ -590,8 +590,8 @@ if( $config['cf_member_img_size'] && $config['cf_member_img_width'] && $config[' if ($config['cf_use_email_certify'] && $old_email != $mb_email) { $subject = '['.$config['cf_title'].'] 인증확인 메일입니다.'; - // 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 - $mb_md5 = md5(pack('V*', rand(), rand(), rand(), rand())); + // 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 (CSPRNG 사용) + $mb_md5 = get_random_token_string(16); sql_query(" update {$g5['member_table']} set mb_email_certify2 = '$mb_md5' where mb_id = '$mb_id' "); diff --git a/lib/common.lib.php b/lib/common.lib.php index 68c1bc2fe..90aa5f313 100644 --- a/lib/common.lib.php +++ b/lib/common.lib.php @@ -2510,7 +2510,7 @@ function _callback_normalizeString($matches){ // 토큰 생성 function _token() { - return md5(uniqid(rand(), true)); + return get_random_token_string(16); } @@ -2578,7 +2578,7 @@ function _get_token_secret() { $secret = get_session('ss_token_secret'); if (!$secret) { - $secret = md5(uniqid(rand(), true)); + $secret = get_random_token_string(16); set_session('ss_token_secret', $secret); } return $secret; @@ -4395,7 +4395,7 @@ function get_sql_affected_rows($link=null) // 불법접근을 막도록 토큰을 생성하면서 토큰값을 리턴 function get_write_token($bo_table) { - $token = md5(uniqid(rand(), true)); + $token = get_random_token_string(16); set_session('ss_write_'.$bo_table.'_token', $token); return $token; diff --git a/mobile/shop/itemrecommend.php b/mobile/shop/itemrecommend.php index c7467ac7f..4a929477d 100644 --- a/mobile/shop/itemrecommend.php +++ b/mobile/shop/itemrecommend.php @@ -7,7 +7,7 @@ if (!$is_member) alert_close('회원만 메일을 발송할 수 있습니다.'); // 스팸을 발송할 수 없도록 세션에 아무값이나 저장하여 hidden 으로 넘겨서 다음 페이지에서 비교함 -$token = md5(uniqid(rand(), true)); +$token = get_random_token_string(16); set_session("ss_token", $token); $it = get_shop_item($it_id, true); diff --git a/mobile/shop/nicepay/nicepay_result.php b/mobile/shop/nicepay/nicepay_result.php index 624a2a19b..d180f87b4 100644 --- a/mobile/shop/nicepay/nicepay_result.php +++ b/mobile/shop/nicepay/nicepay_result.php @@ -16,7 +16,7 @@ $txTid = isset($_POST['TxTid']) ? clean_xss_tags($_POST['TxTid']) : ''; // $authToken = isset($_POST['AuthToken']) ? clean_xss_tags($_POST['AuthToken']) : ''; // authentication TOKEN $payMethod = isset($_POST['PayMethod']) ? clean_xss_tags($_POST['PayMethod']) : ''; // payment method $mid = isset($_POST['MID']) ? clean_xss_tags($_POST['MID']) : ''; // merchant id -$moid = isset($_POST['Moid']) ? clean_xss_tags($_POST['Moid']) : ''; // order number +$moid = isset($_POST['Moid']) ? addslashes(clean_xss_tags(stripslashes($_POST['Moid']))) : ''; // order number $amt = isset($_POST['Amt']) ? (int) preg_replace('/[^0-9]/', '', $_POST['Amt']) : 0; // Amount of payment $reqReserved = isset($_POST['ReqReserved']) ? clean_xss_tags($_POST['ReqReserved']) : ''; // mall custom field $netCancelURL = isset($_POST['NetCancelURL']) ? clean_xss_tags($_POST['NetCancelURL']) : ''; // netCancelURL diff --git a/mobile/shop/nicepay/return_url_result.php b/mobile/shop/nicepay/return_url_result.php index 9b0b031af..c20ee5410 100644 --- a/mobile/shop/nicepay/return_url_result.php +++ b/mobile/shop/nicepay/return_url_result.php @@ -5,7 +5,7 @@ include_once(G5_MSHOP_PATH.'/settle_nicepay.inc.php'); $authResultCode = isset($_POST['AuthResultCode']) ? clean_xss_tags($_POST['AuthResultCode']) : ''; // authentication result code 0000:success $authResultMsg = isset($_POST['AuthResultMsg']) ? clean_xss_tags($_POST['AuthResultMsg']) : ''; // authentication result message $mid = isset($_POST['MID']) ? clean_xss_tags($_POST['MID']) : ''; // merchant id -$moid = isset($_POST['Moid']) ? clean_xss_tags($_POST['Moid']) : ''; // order number +$moid = isset($_POST['Moid']) ? addslashes(clean_xss_tags(stripslashes($_POST['Moid']))) : ''; // order number $sql = " select * from {$g5['g5_shop_order_data_table']} where od_id = '$moid' "; $row = sql_fetch($sql); diff --git a/plugin/social/popup.php b/plugin/social/popup.php index 732dacaeb..6721d5dc6 100644 --- a/plugin/social/popup.php +++ b/plugin/social/popup.php @@ -36,7 +36,7 @@ if (isset($_REQUEST['mylink']) && !empty($_REQUEST['mylink'])) { alert_close('올바른 방법으로 이용해 주십시오.'); } - set_session('ss_social_mylink_token', md5(uniqid(rand(), true))); + set_session('ss_social_mylink_token', get_random_token_string(16)); } } diff --git a/plugin/social/register_member.php b/plugin/social/register_member.php index 7f691602e..1d9929af3 100644 --- a/plugin/social/register_member.php +++ b/plugin/social/register_member.php @@ -40,7 +40,7 @@ $is_exists_email = $user_email ? exist_mb_email($user_email, '') : false; $user_name = isset($user_profile->username) ? $user_profile->username : ''; // 불법접근을 막도록 토큰생성 -$token = md5(uniqid(rand(), true)); +$token = get_random_token_string(16); set_session("ss_token", $token); $g5['title'] = '소셜 회원 가입 - '.social_get_provider_service_name($provider_name); diff --git a/plugin/social/register_member_update.php b/plugin/social/register_member_update.php index 9f0826089..8202e2e76 100644 --- a/plugin/social/register_member_update.php +++ b/plugin/social/register_member_update.php @@ -30,7 +30,7 @@ $mb_password = isset($_POST['mb_password']) ? trim($_POST['mb_password']) : ' $mb_password_re = isset($_POST['mb_password_re']) ? trim($_POST['mb_password_re']) : ''; $mb_nick = isset($_POST['mb_nick']) ? trim(strip_tags($_POST['mb_nick'])) : ''; $mb_email = isset($_POST['mb_email']) ? trim($_POST['mb_email']) : ''; -$mb_name = isset($_POST['mb_name']) ? clean_xss_tags(trim(strip_tags($_POST['mb_name']))) : ''; +$mb_name = isset($_POST['mb_name']) ? addslashes(clean_xss_tags(trim(strip_tags(stripslashes($_POST['mb_name']))))) : ''; $mb_hp = isset($_POST['mb_hp']) ? trim($_POST['mb_hp']) : ''; $mb_email = get_email_address($mb_email); @@ -54,7 +54,7 @@ if( ! $mb_nick || ! $mb_name ){ if( ! isset($mb_password) || ! $mb_password ){ - $mb_password = md5(pack('V*', rand(), rand(), rand(), rand())); + $mb_password = get_random_token_string(16); } @@ -272,8 +272,8 @@ if($result) { } else { // 메일인증을 사용한다면 $subject = '['.$config['cf_title'].'] 인증확인 메일입니다.'; - // 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 - $mb_md5 = md5(pack('V*', rand(), rand(), rand(), rand())); + // 어떠한 회원정보도 포함되지 않은 일회용 난수를 생성하여 인증에 사용 (CSPRNG 사용) + $mb_md5 = get_random_token_string(16); sql_query(" update {$g5['member_table']} set mb_email_certify2 = '$mb_md5' where mb_id = '$mb_id' "); diff --git a/shop/itemrecommend.php b/shop/itemrecommend.php index 37611eaf9..2b04fb4c9 100644 --- a/shop/itemrecommend.php +++ b/shop/itemrecommend.php @@ -12,7 +12,7 @@ if (!$is_member) alert_close('회원만 메일을 발송할 수 있습니다.'); // 스팸을 발송할 수 없도록 세션에 아무값이나 저장하여 hidden 으로 넘겨서 다음 페이지에서 비교함 -$token = md5(uniqid(rand(), true)); +$token = get_random_token_string(16); set_session("ss_token", $token); $sql = " select it_name from {$g5['g5_shop_item_table']} where it_id='$it_id' "; diff --git a/shop/nicepay/nicepay_result.php b/shop/nicepay/nicepay_result.php index 73e6166af..bd78ed89a 100644 --- a/shop/nicepay/nicepay_result.php +++ b/shop/nicepay/nicepay_result.php @@ -16,7 +16,7 @@ $txTid = isset($_POST['TxTid']) ? clean_xss_tags($_POST['TxTid']) : ''; // $authToken = isset($_POST['AuthToken']) ? clean_xss_tags($_POST['AuthToken']) : ''; // authentication TOKEN $payMethod = isset($_POST['PayMethod']) ? clean_xss_tags($_POST['PayMethod']) : ''; // payment method $mid = isset($_POST['MID']) ? clean_xss_tags($_POST['MID']) : ''; // merchant id -$moid = isset($_POST['Moid']) ? clean_xss_tags($_POST['Moid']) : ''; // order number +$moid = isset($_POST['Moid']) ? addslashes(clean_xss_tags(stripslashes($_POST['Moid']))) : ''; // order number $amt = isset($_POST['Amt']) ? (int) preg_replace('/[^0-9]/', '', $_POST['Amt']) : 0; // Amount of payment $reqReserved = isset($_POST['ReqReserved']) ? clean_xss_tags($_POST['ReqReserved']) : ''; // mall custom field $netCancelURL = isset($_POST['NetCancelURL']) ? clean_xss_tags($_POST['NetCancelURL']) : ''; // netCancelURL diff --git a/shop/orderinquiryview.php b/shop/orderinquiryview.php index 8deb5d5ca..c7d8f3d8a 100644 --- a/shop/orderinquiryview.php +++ b/shop/orderinquiryview.php @@ -8,7 +8,7 @@ if( isset($_GET['ini_noti']) && !isset($_GET['uid']) ){ } // 불법접속을 할 수 없도록 세션에 아무값이나 저장하여 hidden 으로 넘겨서 다음 페이지에서 비교함 -$token = md5(uniqid(rand(), true)); +$token = get_random_token_string(16); set_session("ss_token", $token); if (!$is_member) { diff --git a/shop/settle_nicepay_common.php b/shop/settle_nicepay_common.php index 60a80d762..af6209e82 100644 --- a/shop/settle_nicepay_common.php +++ b/shop/settle_nicepay_common.php @@ -22,11 +22,11 @@ if (in_array($_SERVER['REMOTE_ADDR'], $pg_allow_ips)) { $name = isset($_POST['name']) ? clean_xss_tags($_POST['name']) : ''; //구매자명 $GoodsName = isset($_POST['GoodsName']) ? clean_xss_tags($_POST['GoodsName']) : ''; //상품명 $TID = isset($_POST['TID']) ? clean_xss_tags($_POST['TID']) : ''; //거래번호 - $MOID = isset($_POST['MOID']) ? clean_xss_tags($_POST['MOID']) : ''; //주문번호 + $MOID = isset($_POST['MOID']) ? addslashes(clean_xss_tags(stripslashes($_POST['MOID']))) : ''; //주문번호 $AuthDate = isset($_POST['AuthDate']) ? clean_xss_tags($_POST['AuthDate']) : ''; //입금일시 (yyMMddHHmmss) 12 자리 $ResultCode = isset($_POST['ResultCode']) ? clean_xss_tags($_POST['ResultCode']) : ''; //결과코드 ('4110' 경우 입금통보) $ResultMsg = isset($_POST['ResultMsg']) ? clean_xss_tags($_POST['ResultMsg']) : ''; //결과메시지 - $VbankNum = isset($_POST['VbankNum']) ? clean_xss_tags($_POST['VbankNum']) : ''; //가상계좌번호 + $VbankNum = isset($_POST['VbankNum']) ? addslashes(clean_xss_tags(stripslashes($_POST['VbankNum']))) : ''; //가상계좌번호 $FnCd = isset($_POST['FnCd']) ? clean_xss_tags($_POST['FnCd']) : ''; //가상계좌 은행코드 $VbankName = isset($_POST['VbankName']) ? clean_xss_tags($_POST['VbankName']) : ''; //가상계좌 은행명 $VbankInputName = isset($_POST['VbankInputName']) ? clean_xss_tags($_POST['VbankInputName']) : ''; //입금자 명