Compare commits

...
78 Commits
Author SHA1 Message Date
thisgun 8c505f6f1d 버전 5.5.17 수정 2024-06-07 14:29:02 +09:00
zipuragiandthisgun d950fb3dd1 게시판에서 회원 아이디로 댓글 검색시 잘못된 결과가 나오는 문제 (#322) 2024-06-07 14:22:53 +09:00
thisgun 62c0803cf5 초기화되지 않은 변수 수정 #325 2024-06-07 12:38:32 +09:00
thisgun 08df872863 HTMLPurifier_Filter_iframevideo 클래스명의 대소문자 불일치 수정#324 2024-06-07 12:31:17 +09:00
thisgun 56615a5e9e 비회원인 상태에서 장바구니에서 주문하기 후 로그인하면 장바구니가 비어있는 문제 수정 2024-06-07 12:24:41 +09:00
thisgun e03e01d410 Open Redirect 취약점 수정 #318 2024-06-05 14:56:50 +09:00
thisgun 940e701fa4 관리자 회원관리에서 PHP WARNING 경고문이 나오는 코드 수정 #316 2024-06-05 10:09:24 +09:00
thisgun 031f8b4ef9 소셜로그인 타임아웃 설정타임 수정 #315 2024-06-04 17:59:31 +09:00
thisgun ed6b7f3326 글쓰기 임시저장과 쪽지쓰기 코드 수정 2024-06-04 17:38:33 +09:00
thisgun 0ded1df66d 삼품재고관리가 제대로 표시되지 않는 문제 수정 2024-06-04 11:27:16 +09:00
thisgun f4dfbacf03 글복사 sql query에 볋칭 as 추가 및 포인트 업데이트 코드 수정 2024-06-04 10:25:59 +09:00
thisgun 3fd8740c92 관리자 기본환경설정에서 불필요한 코드 제거 2024-06-03 18:16:59 +09:00
thisgun 68dc0bd4ec KG이니시스 MID SEED대칭키 수정 2024-06-03 18:16:17 +09:00
thisgun cc96048dfa NHN_KCP 결제정보 검증기능 추가 적용 2024-06-03 18:15:45 +09:00
thisgun 6697327265 쇼핑몰 주문 SMS 파일의 금액변수에 (int) 형 추가 2024-06-03 18:15:39 +09:00
kit rioandthisgun 02e0996eb4 kisa seed_cbc undefined 변수 수정
SEED_CBC_Decrypt 함수
return null 전에 초기화
2024-04-17 18:41:44 +09:00
thisgun 61a0236938 버전 5.5.16 수정 2024-04-17 18:23:10 +09:00
thisgun 712172a0ea NHN_KCP 결제정보 검증기능 적용 2024-04-17 18:19:43 +09:00
thisgun ce89cba2c7 버전 5.5.15 수정 2024-04-11 12:14:00 +09:00
thisgun c3634c05f7 KG이니시스 통합인증 암호화적용 여부 선택옵션 추가 2024-04-11 12:10:59 +09:00
thisgun baa114c471 버전 5.5.14 수정 2024-04-03 10:02:42 +09:00
thisgun 2bfd995e49 쇼핑몰 결제시 결세수단 체크 과정 추가 2024-04-03 09:59:02 +09:00
thisgun 1e72d7e81c DB 업그레이드시 기본설정,QA설정,로그인,방문자,쇼핑몰설정 테이블에 pk auto_increment 추가 2024-04-03 09:58:49 +09:00
thisgun 79b0066ec1 Merge branch 'master' of github.com:gnuboard/gnuboard5 2024-04-03 09:57:01 +09:00
kaglaandGitHub 47e243c0ad Fix/db (#311)
* QA설정테이블에 qa_id pkey auto_increment 추가

* 설정, 로그인, 방문자 테이블에 pkey, auto_increment 추가

* 쇼핑몰 설정테이블에 de_id pkey auto_increment 추가
2024-04-03 09:56:45 +09:00
thisgun bf6678e036 글쓰기 sql query 에 별칭 as 추가 #309 2024-04-03 09:44:37 +09:00
thisgun aba7d75de6 쇼핑몰 모바일 상품 리스트 페이지에서 불필요한 변수 제거 #308 2024-03-27 12:21:54 +09:00
thisgun 474fc8f9a9 관리자 xss 체크 alert이 너무 자주 발생하는 문제 #301 수정 2024-03-27 11:22:25 +09:00
thisgun a0eb804918 [KVE-2024-0023] 답변이 달린 상품문의글 수정가능 취약점 수정 2024-03-25 10:47:29 +09:00
thisgun 0d9c773d22 [KVE-2024-0022] 쇼핑몰 사용후기 별점 조작 취약점 수정 2024-03-25 10:03:07 +09:00
thisgun 6705d014f9 [KVE-2024-0021] Stored XSS 취약점 수정 2024-03-25 09:25:53 +09:00
thisgun 985546fbad G5_USE_SHOP 상수가 false 시 기본테마 로그인에 warning 경고문이 나오는 문제 수정 2024-02-19 18:07:18 +09:00
thisgun fa6aa881de 게시글 복사시 첨부파일 변수명값이 초기화가 안된 오류 수정 2024-02-19 12:49:17 +09:00
thisgun 06750e248b 버전 5.5.13 수정 2024-02-19 10:08:31 +09:00
thisgun c1c4089883 Union based SQL injection 취약점 수정 2024-02-15 15:28:48 +09:00
thisgun 248cb2b173 관리자 페이지 원격 명령 실행 취약점 수정 2024-02-14 19:09:20 +09:00
thisgun 8d912e3511 Open Redirection 취약점 다시 재수정 2024-02-14 18:31:52 +09:00
thisgun c67118f374 버전 5.5.12 수정 2024-01-25 16:58:48 +09:00
thisgun 15f2037790 OpenRediect 취약점 수정 2024-01-25 16:50:47 +09:00
thisgun cb6b39cb60 이니시스 본인인증 모듈 최근것으로 적용 2024-01-25 12:30:43 +09:00
thisgun 73a5f4cc47 NHN_KCP 에스크로 마크 상점코드가 SIR로 나왔던 오류 수정 2024-01-24 10:53:16 +09:00
thisgun 5f910f192e 버전 5.5.11 수정 2024-01-02 10:28:48 +09:00
thisgun bc2c939d72 Merge branch 'patch_5.5.11' of github.com:gnuboard/gnuboard5 2024-01-02 10:18:41 +09:00
kkigomiandGitHub b7c557f44e #297 보안취약점 처리 보완 (#300) 2024-01-02 10:17:41 +09:00
thisgun 1ff5df8215 KCP 모바일 결제중 Deprecated 메시지로 결제가 안되는 오류 수정 2024-01-02 09:59:06 +09:00
thisgun 72d03f305c 카카오로 링크 내보내기 스크립트 수정 2023-12-29 18:14:54 +09:00
thisgun 1ec9a0ee12 게시판 아이디를 content로 생성하면 짧은주소 기능과 충돌하는 문제 수정 #299 2023-12-29 11:56:32 +09:00
thisgun a061d6c863 동시성 문제로 wr_seo_title 값이 중복되는 문제 수정 #293 2023-12-18 17:26:30 +09:00
thisgun 4f2f725de8 보안취약점 수정 #297 2023-12-18 12:39:55 +09:00
thisgun fae53d3cd5 관리페이지에서 환경설정을 저장할 때 변조된 데이터가 사용될 수 있는 문제 수정 #296 2023-12-18 11:55:15 +09:00
thisgun 1fc3a343c2 영카트 상품의 짧은주소에 사용되는 it_seo_title이 중복되는 문제 수정 #295 2023-12-18 11:29:37 +09:00
thisgun 5e1ab9c1e7 [KVE-2023-5525] 그누보드(영카트) lgxpay plugin XSS취약점 수정 2023-12-04 18:16:20 +09:00
thisgun 5605b539f4 버전 5.5.10 수정 2023-11-10 14:12:48 +09:00
thisgun a8baa8dd7d ss_mb_key 체크함수의 user_agent 에 hook 추가 2023-11-10 13:57:24 +09:00
thisgun 16051b3049 비회원이 비밀글을 작성할 경우 패스워드를 묻는 오류 문제 수정 2023-11-10 12:47:10 +09:00
thisgun db1d56e07b G5_DOMAIN 설정시 url에 타 도메인을 지정할수 없습니다. 메시지가 나오는 오류 수정 #290 2023-11-10 12:21:19 +09:00
thisgun 4455f7d3c9 버전 5.5.9 수정 2023-10-19 11:29:24 +09:00
thisgun 398967f804 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-10-19 11:28:28 +09:00
KkigomiandGitHub ee75b32b3c adm/index.php 페이지에 컨텐츠를 삽입할 수 있는 Hook 추가 (#283)
* 코드 포맷

* adm/index.php 페이지에 컨텐츠를 삽입할 수 있는 Hook 추가

- adm_index_addtional_content_before
- adm_index_addtional_content_after
2023-10-19 11:27:18 +09:00
MayCactusandGitHub c869f29f0d 세션 쿠키 보안 강화 (#282)
* Enhance Session Cookie Security

* Fix user registration link path
2023-10-19 11:27:00 +09:00
KkigomiandGitHub c95168fb0c IP 변경으로 인한 관리페이지 접근 시 접속이 제한되는 문제 해결 (#284)
* `ss_mb_key`를 생성하고 검증할 때 IP를 제거하고 대체 함

프록시 등의 사용으로 IP가 수시로 변경되는 환경이라면 관리페이지 접근에 수시로 제한이 되는 문제를 해결하기 위함

* `ss_mb_key` 세션 값 생성 코드의 중복을 제거하기 위해 정리

* client_key 유효 시간을 세션 동안만 유지되도록 변경
2023-10-19 11:26:28 +09:00
thisgun b8ffd99362 비밀글이 게시판 목록에서 내용, 썸네일이 노출되는 문제 수정#287 2023-10-19 11:17:16 +09:00
thisgun 64e1fbe786 Merge branch 'master' of github.com:gnuboard/gnuboard5 2023-10-18 17:23:56 +09:00
thisgun 91715ff830 KG이니시스 통합인증 테스트키 수정 2023-10-18 17:23:43 +09:00
thisgunandGitHub 1fb9e28510 Merge pull request #273 from maycactus-FOSS/bug
Refactor: str_encrypt 클래스의 변수 이름 수정
2023-10-18 12:58:13 +09:00
thisgunandGitHub babbc9afdb Merge pull request #278 from kkigomi/master-2
`$wr_id` 전역변수의 값이 잘못된 타입으로 할당되는 문제 고침
2023-10-18 12:57:37 +09:00
thisgunandGitHub 04030f9274 Merge pull request #280 from kkigomi/patch-comment
불필요한 주석 제거
2023-10-18 12:56:55 +09:00
thisgunandGitHub 3085703c61 Merge pull request #279 from kkigomi/patch-1
`delete_cache_latest` Hook 추가
2023-10-18 12:56:31 +09:00
thisgunandGitHub 20dc211a82 Merge pull request #285 from kkigomi/feature/auth.au_menu
관리권한 설정 시 메뉴명(au_menu)의 길이 제한으로 인한 문제 개선
2023-10-18 10:33:39 +09:00
thisgunandGitHub a773839338 Merge pull request #289 from kkigomi/feature/deprecated-sql_password
sql_password() 함수를 사용하는 것을 권장하지 않음을 표기
2023-10-18 10:31:04 +09:00
kkigomi 84b22909c5 sql_password() 함수를 사용하는 것을 권장하지 않음을 표기
https://github.com/gnuboard/gnuboard5/issues/247
2023-10-15 20:39:44 +09:00
kkigomi 28bfcea9c2 관리권한 설정 시 메뉴 ID(au_menu)의 길이 제한을 20에서 50으로 확장 2023-09-09 21:48:34 +09:00
kkigomi 8cd1df0f43 불필요한 주석 제거 2023-08-31 21:18:41 +09:00
KkigomiandGitHub cf2a8ab282 delete_cache_latest Hook 추가
`delete_cache_latest()` 함수에 `delete_cache_latest` Hook 추가
2023-08-30 01:06:07 +09:00
KkigomiandGitHub 941f3e135a $wr_id 전역변수의 값이 잘못된 타입으로 할당되는 문제 고침
짧은 주소 '글 이름' 주소로 접근할 때 `$wr_id` 전역변수의 값이 `string` 타입으로  잘못 할당되는 문제를 `int` 타입으로 올바르게 바로 잡습니다
2023-08-21 09:24:30 +09:00
thisgun 4b9b1af01e 버전 5.5.8.3.4 수정 2023-08-17 14:40:08 +09:00
thisgun 41d48891f4 wr_num 필드 값이 동시성 문제로 겹치는 경우 답변글에 대한 권한이 잘못 주어지는 등의 문제 다시 수정 #265 2023-08-17 14:39:05 +09:00
maycactus 616f5b8d46 Refactor: str_encrypt 클래스의 변수 이름 수정 2023-08-16 15:37:08 -04:00
79 changed files with 1541 additions and 196 deletions
+4 -5
View File
@@ -554,7 +554,7 @@ function admin_check_xss_params($params)
if (is_array($value)) {
admin_check_xss_params($value);
} else if ((preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/[onload|onerror]=.*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) || (preg_match('/[onload|onerror|focus]=.*/ius', $value) && preg_match('/(eval|expression|exec|prompt)(\s*)\((.*)\)/ius', $value))) {
} else if ((preg_match('/<\s?[^\>]*\/?\s?>/i', $value) && (preg_match('/script.*?\/script/ius', $value) || preg_match('/(onload|onerror)=.*/ius', $value))) || preg_match('/^(?=.*token\()(?=.*xmlhttprequest\()(?=.*send\().*$/im', $value) || (preg_match('/(onload|onerror|focus)=.*/ius', $value) && preg_match('/(eval|expression|exec|prompt)(\s*)\((.*)\)/ius', $value))) {
alert('요청 쿼리에 잘못된 스크립트문장이 있습니다.\\nXSS 공격일수도 있습니다.', G5_URL);
die();
}
@@ -617,13 +617,12 @@ if (!$member['mb_id']) {
}
}
// 관리자의 아이피, 브라우저와 다르다면 세션을 끊고 관리자에게 메일을 보낸다.
$admin_key = md5($member['mb_datetime'] . get_real_client_ip() . $_SERVER['HTTP_USER_AGENT']);
if (get_session('ss_mb_key') !== $admin_key) {
// 관리자의 클라이언트를 검증하여 일치하지 않으면 세션을 끊고 관리자에게 메일을 보낸다.
if (!verify_mb_key($member)) {
session_destroy();
include_once G5_LIB_PATH . '/mailer.lib.php';
// 메일 알림
mailer($member['mb_nick'], $member['mb_email'], $member['mb_email'], 'XSS 공격 알림', $_SERVER['REMOTE_ADDR'] . ' 아이피로 XSS 공격이 있었습니다.<br><br>관리자 권한을 탈취하려는 접근이므로 주의하시기 바랍니다.<br><br>해당 아이피는 차단하시고 의심되는 게시물이 있는지 확인하시기 바랍니다.' . G5_URL, 0);
+3 -2
View File
@@ -8,7 +8,7 @@ auth_check_menu($auth, $sub_menu, 'w');
check_admin_token();
$bo_table = isset($_POST['bo_table']) ? $_POST['bo_table'] : null;
$bo_table = isset($_POST['bo_table']) ? substr(preg_replace('/[^a-z0-9_]/i', '', $_POST['bo_table']), 0, 20) : null;
$target_table = isset($_POST['target_table']) ? trim($_POST['target_table']) : '';
$target_subject = isset($_POST['target_subject']) ? trim($_POST['target_subject']) : '';
@@ -24,6 +24,8 @@ if (!preg_match('/[A-Za-z0-9_]{1,20}/', $target_table)) {
alert('게시판 TABLE명은 공백없이 영문자, 숫자, _ 만 사용 가능합니다. (20자 이내)');
}
$target_table = substr(preg_replace('/[^a-z0-9_]/i', '', $target_table), 0, 20);
// 게시판명이 금지된 단어로 되어 있으면
if ($w == '' && in_array($target_table, get_bo_table_banned_word())) {
alert('입력한 게시판 TABLE명을 사용할수 없습니다. 다른 이름으로 입력해 주세요.');
@@ -191,7 +193,6 @@ if ($copy_case == 'schema_data_both') {
sql_query($sql, false);
// 4.00.01
// 위의 코드는 같은 테이블명을 사용하였다는 오류가 발생함. (희한하네 ㅡㅡ;)
$sql = " select * from {$g5['board_file_table']} where bo_table = '$bo_table' ";
$result = sql_query($sql, false);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
+21 -4
View File
@@ -8,7 +8,9 @@ if ($is_admin != 'super') {
alert('최고관리자만 접근 가능합니다.');
}
$copy_config = get_config(true);
// https://github.com/gnuboard/gnuboard5/issues/296 이슈처리
$sql = " select * from {$g5['config_table']} limit 1";
$config = sql_fetch($sql);
if (!isset($config['cf_add_script'])) {
sql_query(
@@ -407,6 +409,11 @@ if (!isset($config['cf_cert_kg_mid'])) {
ADD COLUMN `cf_cert_kg_mid` VARCHAR(255) NOT NULL DEFAULT '' AFTER `cf_cert_kg_cd`; ";
sql_query($sql, false);
}
if (!isset($config['cf_cert_use_seed'])) {
$sql = "ALTER TABLE `{$g5['config_table']}`
ADD COLUMN `cf_cert_use_seed` TINYINT(4) NOT NULL DEFAULT '1' AFTER `cf_cert_kg_mid`; ";
sql_query($sql, false);
}
if (!$config['cf_faq_skin']) {
$config['cf_faq_skin'] = "basic";
}
@@ -699,14 +706,14 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<th scope="row"><label for="cf_analytics">방문자분석 스크립트</label></th>
<td colspan="3">
<?php echo help('방문자분석 스크립트 코드를 입력합니다. 예) 구글 애널리틱스<br>관리자 페이지에서는 이 코드를 사용하지 않습니다.'); ?>
<textarea name="cf_analytics" id="cf_analytics"><?php echo get_text($copy_config['cf_analytics']); ?></textarea>
<textarea name="cf_analytics" id="cf_analytics"><?php echo get_text($config['cf_analytics']); ?></textarea>
</td>
</tr>
<tr>
<th scope="row"><label for="cf_add_meta">추가 메타태그</label></th>
<td colspan="3">
<?php echo help('추가로 사용하실 meta 태그를 입력합니다.<br>관리자 페이지에서는 이 코드를 사용하지 않습니다.'); ?>
<textarea name="cf_add_meta" id="cf_add_meta"><?php echo get_text($copy_config['cf_add_meta']); ?></textarea>
<textarea name="cf_add_meta" id="cf_add_meta"><?php echo get_text($config['cf_add_meta']); ?></textarea>
</td>
</tr>
<tr>
@@ -1001,6 +1008,16 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
</select>
</td>
</tr>
<tr>
<th scope="row" class="cf_cert_service"><label for="cf_cert_use_seed">통합인증 암호화 적용</label></th>
<td class="cf_cert_service">
<?php echo help('KG이니시스 통합인증서비스에 암호화를 적용합니다. 만일 글자가 깨지는 문제가 발생하면 사용안함으로 적용해 주세요.') ?>
<select name="cf_cert_use_seed" id="cf_cert_use_seed">
<?php echo option_selected("0", $config['cf_cert_use_seed'], "사용안함"); ?>
<?php echo option_selected("1", $config['cf_cert_use_seed'], "사용함"); ?>
</select>
</td>
</tr>
<tr>
<th scope="row" class="cf_cert_service"><label for="cf_cert_hp">휴대폰 본인확인</label></th>
<td class="cf_cert_service">
@@ -1392,7 +1409,7 @@ if ($config['cf_sms_use'] && $config['cf_icode_id'] && $config['cf_icode_pw']) {
<th scope="row"><label for="cf_add_script">추가 script, css</label></th>
<td>
<?php echo help('HTML의 &lt;/HEAD&gt; 태그위로 추가될 JavaScript와 css 코드를 설정합니다.<br>관리자 페이지에서는 이 코드를 사용하지 않습니다.') ?>
<textarea name="cf_add_script" id="cf_add_script"><?php echo get_text($copy_config['cf_add_script']); ?></textarea>
<textarea name="cf_add_script" id="cf_add_script"><?php echo get_text($config['cf_add_script']); ?></textarea>
</td>
</tr>
</tbody>
+10 -9
View File
@@ -12,7 +12,6 @@ if ($is_admin != 'super') {
$cf_title = isset($_POST['cf_title']) ? strip_tags(clean_xss_attributes($_POST['cf_title'])) : '';
$cf_admin = isset($_POST['cf_admin']) ? clean_xss_tags($_POST['cf_admin'], 1, 1) : '';
$posts = array();
$mb = get_member($cf_admin);
@@ -28,11 +27,11 @@ $check_keys = array('cf_cert_kcb_cd', 'cf_cert_kcp_cd', 'cf_editor', 'cf_recaptc
foreach ($check_keys as $key) {
if (isset($_POST[$key]) && $_POST[$key]) {
$posts[$key] = $_POST[$key] = preg_replace('/[^a-z0-9_\-\.]/i', '', $_POST[$key]);
$_POST[$key] = preg_replace('/[^a-z0-9_\-\.]/i', '', $_POST[$key]);
}
}
$posts['cf_icode_server_port'] = $_POST['cf_icode_server_port'] = isset($_POST['cf_icode_server_port']) ? preg_replace('/[^0-9]/', '', $_POST['cf_icode_server_port']) : '7295';
$_POST['cf_icode_server_port'] = isset($_POST['cf_icode_server_port']) ? preg_replace('/[^0-9]/', '', $_POST['cf_icode_server_port']) : '7295';
if (isset($_POST['cf_intercept_ip']) && $_POST['cf_intercept_ip']) {
$pattern = explode("\n", trim($_POST['cf_intercept_ip']));
@@ -105,6 +104,7 @@ $check_keys = array(
'cf_cert_ipin' => 'char',
'cf_cert_hp' => 'char',
'cf_cert_simple' => 'char',
'cf_cert_use_seed' => 'int',
'cf_admin_email' => 'char',
'cf_admin_email_name' => 'char',
'cf_add_script' => 'text',
@@ -164,12 +164,12 @@ for ($i = 1; $i <= 10; $i++) {
foreach ($check_keys as $k => $v) {
if ($v === 'int') {
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? (int) $_POST[$k] : 0;
$_POST[$k] = isset($_POST[$k]) ? (int) $_POST[$k] : 0;
} else {
if (in_array($k, array('cf_analytics', 'cf_add_meta', 'cf_add_script', 'cf_stipulation', 'cf_privacy'))) {
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? $_POST[$k] : '';
$_POST[$k] = isset($_POST[$k]) ? $_POST[$k] : '';
} else {
$posts[$key] = $_POST[$k] = isset($_POST[$k]) ? strip_tags(clean_xss_attributes($_POST[$k])) : '';
$_POST[$k] = isset($_POST[$k]) ? strip_tags(clean_xss_attributes($_POST[$k])) : '';
}
}
}
@@ -180,9 +180,9 @@ if ($_POST['cf_cert_use'] && !$_POST['cf_cert_ipin'] && !$_POST['cf_cert_hp'] &&
}
if (!$_POST['cf_cert_use']) {
$posts[$key] = $_POST['cf_cert_ipin'] = '';
$posts[$key] = $_POST['cf_cert_hp'] = '';
$posts[$key] = $_POST['cf_cert_simple'] = '';
$_POST['cf_cert_ipin'] = '';
$_POST['cf_cert_hp'] = '';
$_POST['cf_cert_simple'] = '';
}
$sql = " update {$g5['config_table']}
@@ -284,6 +284,7 @@ $sql = " update {$g5['config_table']}
cf_cert_ipin = '{$_POST['cf_cert_ipin']}',
cf_cert_hp = '{$_POST['cf_cert_hp']}',
cf_cert_simple = '{$_POST['cf_cert_simple']}',
cf_cert_use_seed = '".(int)$_POST['cf_cert_use_seed']."',
cf_cert_kg_cd = '{$_POST['cf_cert_kg_cd']}',
cf_cert_kg_mid = '" . trim($_POST['cf_cert_kg_mid']) . "',
cf_cert_kcb_cd = '{$_POST['cf_cert_kcb_cd']}',
+3
View File
@@ -57,6 +57,9 @@ if ($w == "u") {
if (!$co['co_id']) {
alert('등록된 자료가 없습니다.');
}
if (function_exists('check_case_exist_title')) check_case_exist_title($co, G5_CONTENT_DIR, false);
} else {
$html_title .= ' 입력';
$co = array(
+62
View File
@@ -205,6 +205,68 @@ if (defined('G5_USE_SHOP') && G5_USE_SHOP) {
break;
}
}
if (!isset($default['de_id'])) {
sql_query(" ALTER TABLE `{$g5['g5_shop_default_table']}`
ADD COLUMN `de_id` INT(11) NOT NULL AUTO_INCREMENT FIRST,
ADD PRIMARY KEY (`de_id`); ", true);
$is_check = true;
}
}
// auth.au_menu 컬럼 크기 조정
$sql = " SHOW COLUMNS FROM `{$g5['auth_table']}` LIKE 'au_menu' ";
$row = sql_fetch($sql);
if (
stripos($row['Type'], 'varchar') !== false
&& (int) preg_replace('/[^0-9]/', '', $row['Type']) < 50
) {
sql_query(" ALTER TABLE `{$g5['auth_table']}` CHANGE `au_menu` `au_menu` VARCHAR(50) NOT NULL; ", true);
$is_check = true;
}
// qa config 테이블 auto id key 추가
$row = sql_fetch("select * from `{$g5['qa_config_table']}` limit 1");
if (!isset($row['qa_id'])) {
sql_query(" ALTER TABLE `{$g5['qa_config_table']}` ADD COLUMN `qa_id` INT(11) NOT NULL AUTO_INCREMENT FIRST,
ADD PRIMARY KEY (`qa_id`); ", true);
$is_check = true;
}
// config 기본 테이블 auto id key 추가
if (!isset($config['cf_id'])) {
sql_query(" ALTER TABLE `{$g5['config_table']}`
ADD COLUMN `cf_id` INT(11) NOT NULL AUTO_INCREMENT FIRST,
ADD PRIMARY KEY (`cf_id`); ", true);
$is_check = true;
}
// login 테이블 auto id key 추가
$row = sql_fetch("select * from `{$g5['login_table']}` limit 1");
if (!isset($row['lo_id'])) {
sql_query(" ALTER TABLE `{$g5['login_table']}`
ADD COLUMN `lo_id` INT(11) NOT NULL AUTO_INCREMENT FIRST,
DROP PRIMARY KEY,
ADD PRIMARY KEY (`lo_id`),
ADD UNIQUE KEY `lo_ip_unique` (`lo_ip`) ", true);
$is_check = true;
}
// visit 테이블 auto id key 로 변경
$result = sql_query("describe `{$g5['visit_table']}`");
while ($row = sql_fetch_array($result)){
if (isset($row['Field']) && $row['Field'] === 'vi_id' && (isset($row['Default']) && $row['Default'] == 0)){
sql_query("ALTER TABLE `{$g5['visit_table']}`
CHANGE COLUMN `vi_id` `vi_id` INT(11) NOT NULL AUTO_INCREMENT;
", false);
$is_check = true;
}
}
$is_check = run_replace('admin_dbupgrade', $is_check);
+43 -33
View File
@@ -3,8 +3,10 @@ $sub_menu = '100000';
require_once './_common.php';
@require_once './safe_check.php';
if (function_exists('social_log_file_delete')) {
social_log_file_delete(86400); //소셜로그인 디버그 파일 24시간 지난것은 삭제
//소셜로그인 디버그 파일 24시간 지난것은 삭제
social_log_file_delete(86400);
}
$g5['title'] = '관리자메인';
@@ -14,8 +16,12 @@ $new_member_rows = 5;
$new_point_rows = 5;
$new_write_rows = 5;
if (! auth_check_menu($auth, '200100', 'r', true)) {
$addtional_content_before = run_replace('adm_index_addtional_content_before', '', $is_admin, $auth, $member);
if ($addtional_content_before) {
echo $addtional_content_before;
}
if (!auth_check_menu($auth, '200100', 'r', true)) {
$sql_common = " from {$g5['member_table']} ";
$sql_search = " where (1) ";
@@ -31,7 +37,7 @@ if (! auth_check_menu($auth, '200100', 'r', true)) {
$sql_order = " order by {$sst} {$sod} ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
@@ -41,11 +47,11 @@ if (! auth_check_menu($auth, '200100', 'r', true)) {
$leave_count = $row['cnt'];
// 차단회원수
$sql = " select count(*) as cnt {$sql_common} {$sql_search} and mb_intercept_date <> '' {$sql_order} ";
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} and mb_intercept_date <> '' {$sql_order} ";
$row = sql_fetch($sql);
$intercept_count = $row['cnt'];
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$new_member_rows} ";
$sql = " SELECT * {$sql_common} {$sql_search} {$sql_order} limit {$new_member_rows} ";
$result = sql_query($sql);
$colspan = 12;
@@ -78,7 +84,7 @@ if (! auth_check_menu($auth, '200100', 'r', true)) {
<?php
for ($i = 0; $row = sql_fetch_array($result); $i++) {
// 접근가능한 그룹수
$sql2 = " select count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$sql2 = " SELECT count(*) as cnt from {$g5['group_member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
$group = "";
if ($row2['cnt']) {
@@ -100,7 +106,7 @@ if (! auth_check_menu($auth, '200100', 'r', true)) {
$mb_nick = get_sideview($row['mb_id'], get_text($row['mb_nick']), $row['mb_email'], $row['mb_homepage']);
$mb_id = $row['mb_id'];
?>
?>
<tr>
<td class="td_mbid"><?php echo $mb_id ?></td>
<td class="td_mbname"><?php echo get_text($row['mb_name']); ?></td>
@@ -115,7 +121,7 @@ if (! auth_check_menu($auth, '200100', 'r', true)) {
<td class="td_boolean"><?php echo $row['mb_intercept_date'] ? '예' : '아니오'; ?></td>
<td class="td_category"><?php echo $group ?></td>
</tr>
<?php
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
@@ -128,18 +134,17 @@ if (! auth_check_menu($auth, '200100', 'r', true)) {
<div class="btn_list03 btn_list">
<a href="./member_list.php">회원 전체보기</a>
</div>
</section>
<?php
} //endif 최신 회원
<?php
} //endif 최신 회원
if (! auth_check_menu($auth, '300100', 'r', true)) {
if (!auth_check_menu($auth, '300100', 'r', true)) {
$sql_common = " from {$g5['board_new_table']} a, {$g5['board_table']} b, {$g5['group_table']} c where a.bo_table = b.bo_table and b.gr_id = c.gr_id ";
if ($gr_id) {
$sql_common .= " and b.gr_id = '$gr_id' ";
$sql_common .= " and b.gr_id = '{$gr_id}' ";
}
if (isset($view) && $view) {
if ($view == 'w') {
@@ -150,7 +155,7 @@ if (! auth_check_menu($auth, '300100', 'r', true)) {
}
$sql_order = " order by a.bn_id desc ";
$sql = " select count(*) as cnt {$sql_common} ";
$sql = " SELECT count(*) as cnt {$sql_common} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
@@ -174,16 +179,16 @@ if (! auth_check_menu($auth, '300100', 'r', true)) {
</thead>
<tbody>
<?php
$sql = " select a.*, b.bo_subject, c.gr_subject, c.gr_id {$sql_common} {$sql_order} limit {$new_write_rows} ";
$sql = " SELECT a.*, b.bo_subject, c.gr_subject, c.gr_id {$sql_common} {$sql_order} limit {$new_write_rows} ";
$result = sql_query($sql);
for ($i = 0; $row = sql_fetch_array($result); $i++) {
$tmp_write_table = $g5['write_prefix'] . $row['bo_table'];
// 원글
if ($row['wr_id'] == $row['wr_parent']) {
// 원글
$comment = "";
$comment_link = "";
$row2 = sql_fetch(" select * from $tmp_write_table where wr_id = '{$row['wr_id']}' ");
$row2 = sql_fetch(" SELECT * from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
$name = get_sideview($row2['mb_id'], get_text(cut_str($row2['wr_name'], $config['cf_cut_name'])), $row2['wr_email'], $row2['wr_homepage']);
// 당일인 경우 시간으로 표시함
@@ -194,12 +199,12 @@ if (! auth_check_menu($auth, '300100', 'r', true)) {
} else {
$datetime2 = substr($datetime2, 5, 5);
}
} else // 코멘트
{
} else {
// 코멘트
$comment = '댓글. ';
$comment_link = '#c_' . $row['wr_id'];
$row2 = sql_fetch(" select * from {$tmp_write_table} where wr_id = '{$row['wr_parent']}' ");
$row3 = sql_fetch(" select mb_id, wr_name, wr_email, wr_homepage, wr_datetime from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
$row2 = sql_fetch(" SELECT * from {$tmp_write_table} where wr_id = '{$row['wr_parent']}' ");
$row3 = sql_fetch(" SELECT mb_id, wr_name, wr_email, wr_homepage, wr_datetime from {$tmp_write_table} where wr_id = '{$row['wr_id']}' ");
$name = get_sideview($row3['mb_id'], get_text(cut_str($row3['wr_name'], $config['cf_cut_name'])), $row3['wr_email'], $row3['wr_homepage']);
// 당일인 경우 시간으로 표시함
@@ -211,7 +216,7 @@ if (! auth_check_menu($auth, '300100', 'r', true)) {
$datetime2 = substr($datetime2, 5, 5);
}
}
?>
?>
<tr>
<td class="td_category"><a href="<?php echo G5_BBS_URL ?>/new.php?gr_id=<?php echo $row['gr_id'] ?>"><?php echo cut_str($row['gr_subject'], 10) ?></a></td>
@@ -223,7 +228,7 @@ if (! auth_check_menu($auth, '300100', 'r', true)) {
<td class="td_datetime"><?php echo $datetime ?></td>
</tr>
<?php
<?php
}
if ($i == 0) {
echo '<tr><td colspan="' . $colspan . '" class="empty_table">자료가 없습니다.</td></tr>';
@@ -239,19 +244,19 @@ if (! auth_check_menu($auth, '300100', 'r', true)) {
</section>
<?php
} //endif 최근게시물
} //endif 최근게시물
if (! auth_check_menu($auth, '200200', 'r', true)) {
if (!auth_check_menu($auth, '200200', 'r', true)) {
$sql_common = " from {$g5['point_table']} ";
$sql_search = " where (1) ";
$sql_order = " order by po_id desc ";
$sql = " select count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$sql = " SELECT count(*) as cnt {$sql_common} {$sql_search} {$sql_order} ";
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$sql = " select * {$sql_common} {$sql_search} {$sql_order} limit {$new_point_rows} ";
$sql = " SELECT * {$sql_common} {$sql_search} {$sql_order} limit {$new_point_rows} ";
$result = sql_query($sql);
$colspan = 7;
@@ -282,7 +287,7 @@ if (! auth_check_menu($auth, '200200', 'r', true)) {
$row2['mb_id'] = '';
for ($i = 0; $row = sql_fetch_array($result); $i++) {
if ($row2['mb_id'] != $row['mb_id']) {
$sql2 = " select mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
$sql2 = " SELECT mb_id, mb_name, mb_nick, mb_email, mb_homepage, mb_point from {$g5['member_table']} where mb_id = '{$row['mb_id']}' ";
$row2 = sql_fetch($sql2);
}
@@ -293,7 +298,7 @@ if (! auth_check_menu($auth, '200200', 'r', true)) {
$link1 = '<a href="' . get_pretty_url($row['po_rel_table'], $row['po_rel_id']) . '" target="_blank">';
$link2 = '</a>';
}
?>
?>
<tr>
<td class="td_mbid"><a href="./point_list.php?sfl=mb_id&amp;stx=<?php echo $row['mb_id'] ?>"><?php echo $row['mb_id'] ?></a></td>
@@ -307,7 +312,7 @@ if (! auth_check_menu($auth, '200200', 'r', true)) {
<td class="td_numbig"><?php echo number_format($row['po_mb_point']) ?></td>
</tr>
<?php
<?php
}
if ($i == 0) {
@@ -323,6 +328,11 @@ if (! auth_check_menu($auth, '200200', 'r', true)) {
</div>
</section>
<?php
} //endif
require_once './admin.tail.php';
<?php
} //endif
$addtional_content_after = run_replace('adm_index_addtional_content_after', '', $is_admin, $auth, $member);
if ($addtional_content_after) {
echo $addtional_content_after;
}
require_once './admin.tail.php';
+1 -1
View File
@@ -205,7 +205,7 @@ if (isset($mb_id) && $mb_id) {
if ($mb['mb_intercept_date']) {
$g5['title'] = "차단된 ";
} else {
$g5['title'] .= "";
$g5['title'] = "";
}
$g5['title'] .= '회원 ' . $html_title;
require_once './admin.head.php';
+3 -1
View File
@@ -12,6 +12,7 @@ require_once './admin.head.php';
if (!sql_query(" DESCRIBE `{$g5['qa_config_table']}` ", false)) {
sql_query(
" CREATE TABLE IF NOT EXISTS `{$g5['qa_config_table']}` (
`qa_id` int(11) NOT NULL auto_increment,
`qa_title` varchar(255) NOT NULL DEFAULT'',
`qa_category` varchar(255) NOT NULL DEFAULT'',
`qa_skin` varchar(255) NOT NULL DEFAULT '',
@@ -46,7 +47,8 @@ if (!sql_query(" DESCRIBE `{$g5['qa_config_table']}` ", false)) {
`qa_2` varchar(255) NOT NULL DEFAULT '',
`qa_3` varchar(255) NOT NULL DEFAULT '',
`qa_4` varchar(255) NOT NULL DEFAULT '',
`qa_5` varchar(255) NOT NULL DEFAULT ''
`qa_5` varchar(255) NOT NULL DEFAULT '',
PRIMARY KEY (`qa_id`)
)",
true
);
+3 -3
View File
@@ -28,8 +28,8 @@ if ($_FILES['mobile_logo_img2']['name']) upload_file($_FILES['mobile_logo_img2']
$de_kcp_mid = isset($_POST['de_kcp_mid']) ? substr($_POST['de_kcp_mid'], 0, 3) : '';
$cf_icode_server_port = isset($cf_icode_server_port) ? preg_replace('/[^0-9]/', '', $cf_icode_server_port) : '7295';
$de_shop_skin = isset($_POST['de_shop_skin']) ? preg_replace('#\.+(\/|\\\)#', '', $_POST['de_shop_skin']) : 'basic';
$de_shop_mobile_skin = isset($_POST['de_shop_mobile_skin']) ? preg_replace('#\.+(\/|\\\)#', '', $_POST['de_shop_mobile_skin']) : 'basic';
$de_shop_skin = isset($_POST['de_shop_skin']) ? preg_replace(array('#\.+(\/|\\\)#', '#[\'\"]#'), array('', ''), $_POST['de_shop_skin']) : 'basic';
$de_shop_mobile_skin = isset($_POST['de_shop_mobile_skin']) ? preg_replace(array('#\.+(\/|\\\)#', '#[\'\"]#'), array('', ''), $_POST['de_shop_mobile_skin']) : 'basic';
$skins = get_skin_dir('shop');
@@ -59,7 +59,7 @@ $de_shop_mobile_skin = in_array($de_shop_mobile_skin, $mobile_skins) ? $de_shop_
$check_skin_keys = array('de_type1_list_skin', 'de_type2_list_skin', 'de_type3_list_skin', 'de_type4_list_skin', 'de_type5_list_skin', 'de_mobile_type1_list_skin', 'de_mobile_type2_list_skin', 'de_mobile_type3_list_skin', 'de_mobile_type4_list_skin', 'de_mobile_type5_list_skin', 'de_rel_list_skin', 'de_mobile_rel_list_skin', 'de_search_list_skin', 'de_mobile_search_list_skin', 'de_listtype_list_skin', 'de_mobile_listtype_list_skin');
foreach($check_skin_keys as $key){
$$key = $_POST[$key] = isset($_POST[$key]) ? preg_replace('#\.+(\/|\\\)#', '', strip_tags($_POST[$key])) : '';
$$key = $_POST[$key] = isset($_POST[$key]) ? preg_replace(array('#\.+(\/|\\\)#', '#[\'\"]#'), array('', ''), strip_tags($_POST[$key])) : '';
if( isset($_POST[$key]) && preg_match('#\.+(\/|\\\)#', $_POST[$key]) ){
alert('스킨설정에 유효하지 문자가 포함되어 있습니다.');
+2
View File
@@ -184,6 +184,8 @@ $sql = " update {$g5['g5_shop_item_table']}
where it_id = '$new_it_id' ";
sql_query($sql);
if( function_exists('shop_seo_title_update') ) shop_seo_title_update($new_it_id, true);
/**
* 아이템 복사 처리 후 Event Hook
* @var string $it_id 원본 아이템 ID
+2 -2
View File
@@ -41,8 +41,8 @@ if ($ev_mimg_del) @unlink(G5_DATA_PATH."/event/{$ev_id}_m");
if ($ev_himg_del) @unlink(G5_DATA_PATH."/event/{$ev_id}_h");
if ($ev_timg_del) @unlink(G5_DATA_PATH."/event/{$ev_id}_t");
$ev_skin = preg_replace('#\.+(\/|\\\)#', '', $ev_skin);
$ev_mobile_skin = preg_replace('#\.+(\/|\\\)#', '', $ev_mobile_skin);
$ev_skin = preg_replace(array('#\.+(\/|\\\)#', '#[\'\"]#'), array('', ''), $ev_skin);
$ev_mobile_skin = preg_replace(array('#\.+(\/|\\\)#', '#[\'\"]#'), array('', ''), $ev_mobile_skin);
$skin_regex_patten = "^list.[0-9]+\.skin\.php";
+2
View File
@@ -112,6 +112,8 @@ else if ($w == "u")
if(!$it)
alert('상품정보가 존재하지 않습니다.');
if (function_exists('check_case_exist_title')) check_case_exist_title($it, G5_SHOP_DIR, false);
if (! (isset($ca_id) && $ca_id))
$ca_id = $it['ca_id'];
+2 -2
View File
@@ -285,8 +285,8 @@ if($supply_count) {
$value_array = array();
$count_ii_article = (isset($_POST['ii_article']) && is_array($_POST['ii_article'])) ? count($_POST['ii_article']) : 0;
for($i=0; $i<$count_ii_article; $i++) {
$key = isset($_POST['ii_article'][$i]) ? strip_tags($_POST['ii_article'][$i], '<br><span><strong><b>') : '';
$val = isset($_POST['ii_value'][$i]) ? strip_tags($_POST['ii_value'][$i], '<br><span><strong><b>') : '';
$key = isset($_POST['ii_article'][$i]) ? html_purifier($_POST['ii_article'][$i]) : '';
$val = isset($_POST['ii_value'][$i]) ? html_purifier($_POST['ii_value'][$i]) : '';
$value_array[$key] = $val;
}
$it_info_value = addslashes(serialize($value_array));
+4
View File
@@ -4,6 +4,10 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "r");
if (isset($sfl) && $sfl && !in_array($sfl, array('it_name','it_id','it_maker','it_brand','it_model','it_origin','it_sell_email'))) {
$sfl = '';
}
$g5['title'] = '상품관리';
include_once (G5_ADMIN_PATH.'/admin.head.php');
+4
View File
@@ -4,6 +4,10 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "r");
if (isset($sfl) && $sfl && !in_array($sfl, array('it_name','a.it_id'))) {
$sfl = '';
}
$g5['title'] = '상품문의';
include_once (G5_ADMIN_PATH.'/admin.head.php');
+2 -2
View File
@@ -35,7 +35,7 @@ $sql_common .= $sql_search;
// 테이블의 전체 레코드수만 얻음
$sql = " select count(*) as cnt " . $sql_common;
$row = sql_fetch($sql);
$total_count = $row['cnt'];
$total_count = isset($row['cnt']) ? $row['cnt'] : 0;
$rows = $config['cf_page_rows'];
$total_page = ceil($total_count / $rows); // 전체 페이지 계산
@@ -171,7 +171,7 @@ $listall = '<a href="'.$_SERVER['SCRIPT_NAME'].'" class="ov_listall">전체목
<?php echo $row['it_id']; ?>
</td>
<td class="td_left"><a href="<?php echo $href; ?>"><?php echo get_it_image($row['it_id'], 50, 50); ?> <?php echo cut_str(stripslashes($row['it_name']), 60, "&#133"); ?></a></td>
<td class="td_num<?php echo $it_stock_qty_st; ?>"><?php echo (int)$it_stock_qty; ?></td>
<td class="td_num<?php echo $it_stock_qty_st; ?>"><?php echo get_text($it_stock_qty); ?></td>
<td class="td_num"><?php echo number_format((float)$wait_qty); ?></td>
<td class="td_num"><?php echo number_format((float)$temporary_qty); ?></td>
<td class="td_num">
+4
View File
@@ -4,6 +4,10 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "r");
if (isset($sfl) && $sfl && !in_array($sfl, array('it_name','a.it_id','is_name'))) {
$sfl = '';
}
$g5['title'] = '사용후기';
include_once (G5_ADMIN_PATH.'/admin.head.php');
+2 -2
View File
@@ -4,8 +4,8 @@ include_once('./_common.php');
if (!$is_member) die('0');
$uid = isset($_REQUEST['uid']) ? preg_replace('/[^0-9]/', '', $_REQUEST['uid']) : 0;
$subject = isset($_REQUEST['subject']) ? trim($_REQUEST['subject']) : '';
$content = isset($_REQUEST['content']) ? trim($_REQUEST['content']) : '';
$subject = isset($_REQUEST['subject']) ? preg_replace("#[\\\]+$#", "", substr(trim($_POST['subject']),0,255)) : '';
$content = isset($_REQUEST['content']) ? preg_replace("#[\\\]+$#", "", substr(trim($_POST['content']),0,65536)) : '';
if ($subject && $content) {
$sql = " select count(*) as cnt from {$g5['autosave_table']} where mb_id = '{$member['mb_id']}' and as_subject = '$subject' and as_content = '$content' ";
+14
View File
@@ -104,6 +104,13 @@ if (!$is_search_bbs) {
$list[$i] = get_list($row, $board, $board_skin_url, G5_IS_MOBILE ? $board['bo_mobile_subject_len'] : $board['bo_subject_len']);
$list[$i]['is_notice'] = true;
$list[$i]['list_content'] = $list[$i]['wr_content'];
// 비밀글인 경우 리스트에서 내용이 출력되지 않게 글 내용을 지웁니다.
if (strstr($list[$i]['wr_option'], "secret")) {
$list[$i]['wr_content'] = '';
}
$list[$i]['num'] = 0;
$i++;
$notice_count++;
@@ -197,6 +204,13 @@ if($page_rows > 0) {
$list[$i]['subject'] = search_font($stx, $list[$i]['subject']);
}
$list[$i]['is_notice'] = false;
$list[$i]['list_content'] = $list[$i]['wr_content'];
// 비밀글인 경우 리스트에서 내용이 출력되지 않게 글 내용을 지웁니다.
if (strstr($list[$i]['wr_option'], "secret")) {
$list[$i]['wr_content'] = '';
}
$list_num = $total_count - ($page - 1) * $list_page_rows - $notice_count;
$list[$i]['num'] = $list_num - $k;
+12 -3
View File
@@ -71,8 +71,9 @@ if (! (defined('SKIP_SESSION_REGENERATE_ID') && SKIP_SESSION_REGENERATE_ID)) {
// 회원아이디 세션 생성
set_session('ss_mb_id', $mb['mb_id']);
// FLASH XSS 공격에 대응하기 위하여 회원의 고유키를 생성해 놓는다. 관리자에서 검사함 - 110106
set_session('ss_mb_key', md5($mb['mb_datetime'] . get_real_client_ip() . $_SERVER['HTTP_USER_AGENT']));
// FLASH XSS 공격에 대응하기 위하여 회원의 고유키를 생성해 놓는다. 관리자에서 검사함
generate_mb_key($mb);
// 회원의 토큰키를 세션에 저장한다. /common.php 에서 해당 회원의 토큰값을 검사한다.
if(function_exists('update_auth_session_token')) update_auth_session_token($mb['mb_datetime']);
@@ -146,8 +147,16 @@ if(function_exists('set_cart_id')){
cart_item_clean();
set_cart_id('');
$s_cart_id = get_session('ss_cart_id');
$add_cart_where = '';
// 장바구니에서 주문하기를 하는 경우
if (strpos($link, 'orderform.php') !== false) {
$add_cart_where = " and ct_select_time < '".date('Y-m-d H:i:s', strtotime('-1 hour', G5_SERVER_TIME))."' ";
}
// 선택필드 초기화
$sql = " update {$g5['g5_shop_cart_table']} set ct_select = '0' where od_id = '$s_cart_id' ";
$sql = " update {$g5['g5_shop_cart_table']} set ct_select = '0' where od_id = '$s_cart_id' $add_cart_where ";
sql_query($sql);
}
+5 -1
View File
@@ -19,7 +19,11 @@ if ($url) {
if ( substr($url, 0, 2) == '//' )
$url = 'http:' . $url;
$p = @parse_url(urldecode($url));
if (preg_match('#\\\0#', $url) || preg_match('/^\/{1,}\\\/', $url)) {
alert('url 에 올바르지 않은 값이 포함되어 있습니다.', G5_URL);
}
$p = @parse_url(urldecode(str_replace('\\', '', $url)));
/*
// OpenRediect 취약점관련, PHP 5.3 이하버전에서는 parse_url 버그가 있음 ( Safflower 님 제보 ) 아래 url 예제
// http://localhost/bbs/logout.php?url=http://sir.kr%23@/
+4
View File
@@ -31,6 +31,10 @@ if($url){
if( preg_match('#^/{3,}#', $url) ){
$url = preg_replace('#^/{3,}#', '/', $url);
}
if (function_exists('safe_filter_url_host')) {
$url = safe_filter_url_host($url);
}
}
$url = get_text($url);
+9 -5
View File
@@ -14,24 +14,28 @@ $str_nick_list = '';
$msg = '';
$error_list = array();
$member_list = array('id'=>array(), 'nick'=>array());
$me_memo = isset($_POST['me_memo']) ? preg_replace("#[\\\]+$#", "", substr(trim($_POST['me_memo']),0,65536)) : '';
run_event('memo_form_update_before', $recv_list);
for ($i=0; $i<count($recv_list); $i++) {
$row = sql_fetch(" select mb_id, mb_nick, mb_open, mb_leave_date, mb_intercept_date from {$g5['member_table']} where mb_id = '{$recv_list[$i]}' ");
$recv_list_id = substr(preg_replace("/[^a-zA-Z0-9_]*/", "", $recv_list[$i]), 0, 20);
$row = sql_fetch(" select mb_id, mb_nick, mb_open, mb_leave_date, mb_intercept_date from {$g5['member_table']} where mb_id = '{$recv_list_id}' ");
if ($row) {
if ($is_admin || ($row['mb_open'] && (!$row['mb_leave_date'] && !$row['mb_intercept_date']))) {
$member_list['id'][] = $row['mb_id'];
$member_list['nick'][] = $row['mb_nick'];
} else {
$error_list[] = $recv_list[$i];
$error_list[] = $recv_list_id;
}
}
/*
// 관리자가 아니면서
// 가입된 회원이 아니거나 정보공개를 하지 않았거나 탈퇴한 회원이거나 차단된 회원에게 쪽지를 보내는것은 에러
if ((!$row['mb_id'] || !$row['mb_open'] || $row['mb_leave_date'] || $row['mb_intercept_date']) && !$is_admin) {
$error_list[] = $recv_list[$i];
$error_list[] = $recv_list_id;
} else {
$member_list['id'][] = $row['mb_id'];
$member_list['nick'][] = $row['mb_nick'];
@@ -67,14 +71,14 @@ for ($i=0; $i<count($member_list['id']); $i++) {
$recv_mb_nick = get_text($member_list['nick'][$i]);
// 받는 회원 쪽지 INSERT
$sql = " insert into {$g5['memo_table']} ( me_recv_mb_id, me_send_mb_id, me_send_datetime, me_memo, me_read_datetime, me_type, me_send_ip ) values ( '$recv_mb_id', '{$member['mb_id']}', '".G5_TIME_YMDHIS."', '{$_POST['me_memo']}', '0000-00-00 00:00:00' , 'recv', '{$_SERVER['REMOTE_ADDR']}' ) ";
$sql = " insert into {$g5['memo_table']} ( me_recv_mb_id, me_send_mb_id, me_send_datetime, me_memo, me_read_datetime, me_type, me_send_ip ) values ( '$recv_mb_id', '{$member['mb_id']}', '".G5_TIME_YMDHIS."', '{$me_memo}', '0000-00-00 00:00:00' , 'recv', '{$_SERVER['REMOTE_ADDR']}' ) ";
sql_query($sql);
if( $me_id = sql_insert_id() ){
// 보내는 회원 쪽지 INSERT
$sql = " insert into {$g5['memo_table']} ( me_recv_mb_id, me_send_mb_id, me_send_datetime, me_memo, me_read_datetime, me_send_id, me_type , me_send_ip ) values ( '$recv_mb_id', '{$member['mb_id']}', '".G5_TIME_YMDHIS."', '{$_POST['me_memo']}', '0000-00-00 00:00:00', '$me_id', 'send', '{$_SERVER['REMOTE_ADDR']}' ) ";
$sql = " insert into {$g5['memo_table']} ( me_recv_mb_id, me_send_mb_id, me_send_datetime, me_memo, me_read_datetime, me_send_id, me_type , me_send_ip ) values ( '$recv_mb_id', '{$member['mb_id']}', '".G5_TIME_YMDHIS."', '{$me_memo}', '0000-00-00 00:00:00', '$me_id', 'send', '{$_SERVER['REMOTE_ADDR']}' ) ";
sql_query($sql);
$member_list['me_id'][$i] = $me_id;
+9 -6
View File
@@ -80,7 +80,7 @@ while ($row = sql_fetch_array($result))
}
$sql = " insert into $move_write_table
set wr_num = '$next_wr_num',
set wr_num = " . ($next_wr_num ? "'$next_wr_num'" : "(SELECT IFNULL(MIN(wr_num) - 1, -1) FROM $move_write_table as sq) ") . ",
wr_reply = '{$row2['wr_reply']}',
wr_is_comment = '{$row2['wr_is_comment']}',
wr_comment = '{$row2['wr_comment']}',
@@ -118,20 +118,23 @@ while ($row = sql_fetch_array($result))
sql_query($sql);
$insert_id = sql_insert_id();
if ($next_wr_num === 0) {
$tmp = sql_fetch("select wr_num from $move_write_table where wr_id = '$insert_id'");
$next_wr_num = $tmp['wr_num'];
}
// 코멘트가 아니라면
if (!$row2['wr_is_comment'])
{
if (! $row2['wr_reply']) {
$next_wr_num = -$insert_id;
}
$save_parent = $insert_id;
$sql3 = " select * from {$g5['board_file_table']} where bo_table = '$bo_table' and wr_id = '{$row2['wr_id']}' order by bf_no ";
$result3 = sql_query($sql3);
for ($k=0; $row3 = sql_fetch_array($result3); $k++)
{
$copy_file_name = '';
if ($row3['bf_file'])
{
// 원본파일을 복사하고 퍼미션을 변경
@@ -206,7 +209,7 @@ while ($row = sql_fetch_array($result))
}
}
sql_query(" update $move_write_table set wr_parent = '$save_parent', wr_num = '$next_wr_num' where wr_id = '$insert_id' ");
sql_query(" update $move_write_table set wr_parent = '$save_parent' where wr_id = '$insert_id' ");
if ($sw == 'move')
$save[$cnt]['wr_id'] = $row2['wr_parent'];
+1 -1
View File
@@ -3,7 +3,7 @@ include_once('./_common.php');
$po_id = isset($_POST['po_id']) ? preg_replace('/[^0-9]/', '', $_POST['po_id']) : 0;
$po = sql_fetch(" select * from {$g5['poll_table']} where po_id = '{$_POST['po_id']}' ");
$po = sql_fetch(" select * from {$g5['poll_table']} where po_id = '$po_id' ");
if (! (isset($po['po_id']) && $po['po_id']))
alert('po_id 값이 제대로 넘어오지 않았습니다.');
+2
View File
@@ -1,6 +1,8 @@
<?php
if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
if (function_exists('check_case_exist_title')) check_case_exist_title($write, G5_BBS_DIR, true);
// 게시판에서 두단어 이상 검색 후 검색된 게시물에 코멘트를 남기면 나오던 오류 수정
$sop = strtolower($sop);
if ($sop != 'and' && $sop != 'or')
+10 -6
View File
@@ -257,9 +257,9 @@ if ($w == '' || $w == 'r') {
$wr_num = 0;
$wr_reply = '';
}
$sql = " insert into $write_table
set wr_num = '$wr_num',
set wr_num = " . ($w == 'r' ? "'$wr_num'" : "(SELECT IFNULL(MIN(wr_num) - 1, -1) FROM $write_table as sq) ") . ",
wr_reply = '$wr_reply',
wr_comment = 0,
ca_name = '$ca_name',
@@ -296,10 +296,8 @@ if ($w == '' || $w == 'r') {
$wr_id = sql_insert_id();
$add_wr_update_sql = ($wr_num === 0) ? ", wr_num = '-$wr_id' " : "";
// 부모 아이디에 UPDATE
sql_query(" update $write_table set wr_parent = '$wr_id' $add_wr_update_sql where wr_id = '$wr_id' ");
sql_query(" update $write_table set wr_parent = '$wr_id' where wr_id = '$wr_id' ");
// 새글 INSERT
sql_query(" insert into {$g5['board_new_table']} ( bo_table, wr_id, wr_parent, bn_datetime, mb_id ) values ( '{$bo_table}', '{$wr_id}', '{$wr_id}', '".G5_TIME_YMDHIS."', '{$member['mb_id']}' ) ");
@@ -680,8 +678,14 @@ sql_query(" delete from {$g5['autosave_table']} where as_uid = '{$uid}' ");
//------------------------------------------------------------------------------
// 비밀글이라면 세션에 비밀글의 아이디를 저장한다. 자신의 글은 다시 비밀번호를 묻지 않기 위함
if ($secret)
if ($secret) {
if (! $wr_num) {
$write = get_write($write_table, $wr_id, true);
$wr_num = $write['wr_num'];
}
set_session("ss_secret_{$bo_table}_{$wr_num}", TRUE);
}
// 메일발송 사용 (수정글은 발송하지 않음)
if (!($w == 'u' || $w == 'cu') && $config['cf_email_use'] && $board['bo_use_email']) {
+19 -10
View File
@@ -226,7 +226,12 @@ ini_set("session.gc_maxlifetime", 10800); // session data의 garbage collection
ini_set("session.gc_probability", 1); // session.gc_probability는 session.gc_divisor와 연계하여 gc(쓰레기 수거) 루틴의 시작 확률을 관리합니다. 기본값은 1입니다. 자세한 내용은 session.gc_divisor를 참고하십시오.
ini_set("session.gc_divisor", 100); // session.gc_divisor는 session.gc_probability와 결합하여 각 세션 초기화 시에 gc(쓰레기 수거) 프로세스를 시작할 확률을 정의합니다. 확률은 gc_probability/gc_divisor를 사용하여 계산합니다. 즉, 1/100은 각 요청시에 GC 프로세스를 시작할 확률이 1%입니다. session.gc_divisor의 기본값은 100입니다.
session_set_cookie_params(0, '/', null, false, true);
if (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off') {
session_set_cookie_params(0, '/', null, true, true);
} else {
session_set_cookie_params(0, '/', null, false, true);
}
ini_set("session.cookie_domain", G5_COOKIE_DOMAIN);
function chrome_domain_session_name(){
@@ -381,7 +386,7 @@ if( $config['cf_cert_use'] || (defined('G5_YOUNGCART_VER') && G5_YOUNGCART_VER)
$cookie_session_name = method_exists('XenoPostToForm', 'g5_session_name') ? XenoPostToForm::g5_session_name() : 'PHPSESSID';
foreach ($headers as $header) {
if (!preg_match('~^Set-Cookie: '.$cookie_session_name.'=~', $header)) continue;
$header = preg_replace('~; secure(; HttpOnly)?$~', '', $header) . '; secure; SameSite=None';
$header = preg_replace('~(; secure; HttpOnly)?$~', '; secure; HttpOnly; SameSite=None', $header);
header($header, false);
$g5['session_cookie_samesite'] = 'none';
break;
@@ -421,7 +426,7 @@ if (isset($_REQUEST['sca'])) {
if (isset($_REQUEST['sfl'])) {
$sfl = trim($_REQUEST['sfl']);
$sfl = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\/\^\*\s]/", "", $sfl);
$sfl = preg_replace("/[\<\>\'\"\\\'\\\"\%\=\(\)\/\^\*\s\#]/", "", $sfl);
if ($sfl)
$qstr .= '&amp;sfl=' . urlencode($sfl); // search field (검색 필드)
} else {
@@ -484,6 +489,7 @@ if (isset($_REQUEST['w'])) {
$w = '';
}
/** @var int $wr_id 게시판 글의 ID */
if (isset($_REQUEST['wr_id'])) {
$wr_id = (int)$_REQUEST['wr_id'];
} else {
@@ -507,7 +513,7 @@ if (isset($_REQUEST['url'])) {
if (G5_DOMAIN) {
$p = @parse_url(G5_DOMAIN);
$p['path'] = isset($p['path']) ? $p['path'] : '/';
$urlencode = G5_DOMAIN.urldecode(preg_replace("/^".urlencode($p['path'])."/", "", $urlencode));
$urlencode = rtrim(G5_DOMAIN, '%2F').'%2F'.ltrim(urldecode(preg_replace("/^".urlencode($p['path'])."/", "", $urlencode)), '%2F');
}
}
@@ -581,27 +587,30 @@ if (isset($_SESSION['ss_mb_id']) && $_SESSION['ss_mb_id']) { // 로그인중이
}
/** @var array $write 글 데이터 */
$write = array();
/** @var string $write_table 게시판 테이블 전체이름 */
$write_table = '';
if ($bo_table) {
$board = get_board_db($bo_table, true);
if (isset($board['bo_table']) && $board['bo_table']) {
set_cookie("ck_bo_table", $board['bo_table'], 86400 * 1);
$gr_id = $board['gr_id'];
$write_table = $g5['write_prefix'] . $bo_table; // 게시판 테이블 전체이름
// 게시판 테이블 전체이름
$write_table = $g5['write_prefix'] . $bo_table;
if (isset($wr_id) && $wr_id) {
$write = get_write($write_table, $wr_id);
} else if (isset($wr_seo_title) && $wr_seo_title) {
$write = get_content_by_field($write_table, 'bbs', 'wr_seo_title', generate_seo_title($wr_seo_title));
if( isset($write['wr_id']) ){
$wr_id = $write['wr_id'];
if (isset($write['wr_id'])) {
$wr_id = (int) $write['wr_id'];
}
}
}
// 게시판에서
if (isset($board['bo_select_editor']) && $board['bo_select_editor']){
// 게시판에서 사용하는 에디터를 설정
if (isset($board['bo_select_editor']) && $board['bo_select_editor']) {
$config['cf_editor'] = $board['bo_select_editor'];
}
}
+2
View File
@@ -1,6 +1,8 @@
<?php
if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
define('KGINICIS_USE_CERT_SEED', isset($config['cf_cert_use_seed']) ? (int) $config['cf_cert_use_seed'] : 1);
// 유저 사이드뷰에서 아이콘 지정 안했을시 기본 no 프로필 이미지
define('G5_NO_PROFILE_IMG', '<span class="profile_img"><img src="'.G5_IMG_URL.'/no_profile.gif" alt="no_profile" width="'.$config['cf_member_icon_width'].'" height="'.$config['cf_member_icon_height'].'"></span>');
+12 -5
View File
@@ -7,7 +7,7 @@
DROP TABLE IF EXISTS `g5_auth`;
CREATE TABLE IF NOT EXISTS `g5_auth` (
`mb_id` varchar(20) NOT NULL default '',
`au_menu` varchar(20) NOT NULL default '',
`au_menu` varchar(50) NOT NULL default '',
`au_auth` set('r','w','d') NOT NULL default '',
PRIMARY KEY (`mb_id`,`au_menu`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
@@ -189,6 +189,7 @@ CREATE TABLE IF NOT EXISTS `g5_board_new` (
DROP TABLE IF EXISTS `g5_config`;
CREATE TABLE IF NOT EXISTS `g5_config` (
`cf_id` int(11) NOT NULL auto_increment,
`cf_title` varchar(255) NOT NULL DEFAULT '',
`cf_theme` varchar(100) NOT NULL DEFAULT '',
`cf_admin` varchar(100) NOT NULL DEFAULT '',
@@ -291,6 +292,7 @@ CREATE TABLE IF NOT EXISTS `g5_config` (
`cf_cert_simple` varchar(255) NOT NULL DEFAULT '',
`cf_cert_kg_cd` varchar(255) NOT NULL DEFAULT '',
`cf_cert_kg_mid` varchar(255) NOT NULL DEFAULT '',
`cf_cert_use_seed` tinyint(4) NOT NULL DEFAULT '1',
`cf_cert_kcb_cd` varchar(255) NOT NULL DEFAULT '',
`cf_cert_kcp_cd` varchar(255) NOT NULL DEFAULT '',
`cf_lg_mid` varchar(100) NOT NULL DEFAULT '',
@@ -342,7 +344,8 @@ CREATE TABLE IF NOT EXISTS `g5_config` (
`cf_7` varchar(255) NOT NULL DEFAULT '',
`cf_8` varchar(255) NOT NULL DEFAULT '',
`cf_9` varchar(255) NOT NULL DEFAULT '',
`cf_10` varchar(255) NOT NULL DEFAULT ''
`cf_10` varchar(255) NOT NULL DEFAULT '',
PRIMARY KEY (`cf_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- --------------------------------------------------------
@@ -445,12 +448,14 @@ CREATE TABLE IF NOT EXISTS `g5_group_member` (
DROP TABLE IF EXISTS `g5_login`;
CREATE TABLE IF NOT EXISTS `g5_login` (
`lo_id` int(11) NOT NULL AUTO_INCREMENT,
`lo_ip` varchar(100) NOT NULL default '',
`mb_id` varchar(20) NOT NULL default '',
`lo_datetime` datetime NOT NULL default '0000-00-00 00:00:00',
`lo_location` text NOT NULL,
`lo_url` text NOT NULL,
PRIMARY KEY (`lo_ip`)
PRIMARY KEY (`lo_id`),
UNIQUE KEY `lo_ip_unique` (`lo_ip`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- --------------------------------------------------------
@@ -679,7 +684,7 @@ CREATE TABLE IF NOT EXISTS `g5_scrap` (
DROP TABLE IF EXISTS `g5_visit`;
CREATE TABLE IF NOT EXISTS `g5_visit` (
`vi_id` int(11) NOT NULL default '0',
`vi_id` int(11) NOT NULL AUTO_INCREMENT,
`vi_ip` varchar(100) NOT NULL default '',
`vi_date` date NOT NULL default '0000-00-00',
`vi_time` time NOT NULL default '00:00:00',
@@ -747,6 +752,7 @@ CREATE TABLE IF NOT EXISTS `g5_autosave` (
DROP TABLE IF EXISTS `g5_qa_config`;
CREATE TABLE IF NOT EXISTS `g5_qa_config` (
`qa_id` int(11) NOT NULL AUTO_INCREMENT,
`qa_title` varchar(255) NOT NULL DEFAULT'',
`qa_category` varchar(255) NOT NULL DEFAULT'',
`qa_skin` varchar(255) NOT NULL DEFAULT '',
@@ -782,7 +788,8 @@ CREATE TABLE IF NOT EXISTS `g5_qa_config` (
`qa_2` varchar(255) NOT NULL DEFAULT '',
`qa_3` varchar(255) NOT NULL DEFAULT '',
`qa_4` varchar(255) NOT NULL DEFAULT '',
`qa_5` varchar(255) NOT NULL DEFAULT ''
`qa_5` varchar(255) NOT NULL DEFAULT '',
PRIMARY KEY (`qa_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- --------------------------------------------------------
+3 -1
View File
@@ -209,6 +209,7 @@ CREATE TABLE IF NOT EXISTS `g5_shop_coupon_zone` (
DROP TABLE IF EXISTS `g5_shop_default`;
CREATE TABLE IF NOT EXISTS `g5_shop_default` (
`de_id` int(11) NOT NULL auto_increment,
`de_admin_company_owner` varchar(255) NOT NULL DEFAULT '',
`de_admin_company_name` varchar(255) NOT NULL DEFAULT '',
`de_admin_company_saupja_no` varchar(255) NOT NULL DEFAULT '',
@@ -386,7 +387,8 @@ CREATE TABLE IF NOT EXISTS `g5_shop_default` (
`de_member_reg_coupon_use` tinyint(4) NOT NULL DEFAULT '0',
`de_member_reg_coupon_term` int(11) NOT NULL DEFAULT '0',
`de_member_reg_coupon_price` int(11) NOT NULL DEFAULT '0',
`de_member_reg_coupon_minimum` int(11) NOT NULL DEFAULT '0'
`de_member_reg_coupon_minimum` int(11) NOT NULL DEFAULT '0',
PRIMARY KEY (`de_id`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- --------------------------------------------------------
+6
View File
@@ -1,5 +1,11 @@
function kakaolink_send(text, url, image)
{
if (window.Kakao && (kakao_javascript_apikey !== undefined)) {
if (! Kakao.isInitialized()) {
Kakao.init(kakao_javascript_apikey);
}
}
if( image === undefined ){
image = '';
}
-1
View File
@@ -72,7 +72,6 @@ Class G5_object_cache {
* @param string $key
* @param string $group
* @return bool
* kkigomi 님이 고쳐주심
*/
function delete($type, $key, $group = 'default')
{
+106 -10
View File
@@ -102,6 +102,10 @@ function goto_url($url)
{
run_event('goto_url', $url);
if (function_exists('safe_filter_url_host')) {
$url = safe_filter_url_host($url);
}
$url = str_replace("&amp;", "&", $url);
//echo "<script> location.replace('$url'); </script>";
@@ -155,6 +159,10 @@ function set_cookie($cookie_name, $value, $expire, $path='/', $domain=G5_COOKIE_
global $g5;
$c = run_replace('set_cookie_params', array('path'=>$path, 'domain'=>$domain, 'secure'=>$secure, 'httponly'=>$httponly), $cookie_name);
if (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] != 'off') {
$c['secure'] = true;
}
setcookie(md5($cookie_name), base64_encode($value), G5_SERVER_TIME + $expire, $c['path'], $c['domain'], $c['secure'], $c['httponly']);
}
@@ -178,6 +186,10 @@ function alert($msg='', $url='', $error=true, $post=false)
run_event('alert', $msg, $url, $error, $post);
if (function_exists('safe_filter_url_host')) {
$url = safe_filter_url_host($url);
}
$msg = $msg ? strip_tags($msg, '<br>') : '올바른 방법으로 이용해 주십시오.';
$header = '';
@@ -216,6 +228,12 @@ function confirm($msg, $url1='', $url2='', $url3='')
alert($msg);
}
if (function_exists('safe_filter_url_host')) {
$url1 = safe_filter_url_host($url1);
$url2 = safe_filter_url_host($url2);
$url3 = safe_filter_url_host($url3);
}
if(!trim($url1) || !trim($url2)) {
$msg = '$url1 과 $url2 를 지정해 주세요.';
alert($msg);
@@ -651,7 +669,7 @@ function html_purifier($html)
if ((function_exists('check_html_link_nofollow') && check_html_link_nofollow('html_purifier'))) {
$config->set('HTML.Nofollow', true); // rel=nofollow 으로 스팸유입을 줄임
}
$config->set('URI.SafeIframeRegexp', '%^(https?:)?//(' . $safeiframe . ')%');
$config->set('URI.SafeIframeRegexp', '%^(https?:)?//(' . preg_replace('/\\\?\./', '\.', $safeiframe) . ')%');
$config->set('Attr.AllowedFrameTargets', array('_blank'));
//유튜브, 비메오 전체화면 가능하게 하기
$config->set('Filter.Custom', array(new HTMLPurifier_Filter_Iframevideo()));
@@ -708,7 +726,7 @@ function get_sql_search($search_ca_name, $search_field, $search_text, $search_op
$tmp = explode(",", trim($search_field));
$field = explode("||", $tmp[0]);
$not_comment = "";
if (!empty($tmp[1]))
if (isset($tmp[1]))
$not_comment = $tmp[1];
$str .= "(";
@@ -764,8 +782,11 @@ function get_sql_search($search_ca_name, $search_field, $search_text, $search_op
$op1 = " $search_operator ";
}
$str .= " ) ";
if ($not_comment)
if ($not_comment === '1') {
$str .= " and wr_is_comment = '0' ";
} else if ($not_comment === '0') {
$str .= " and wr_is_comment = '1' ";
}
return $str;
}
@@ -1316,6 +1337,10 @@ function delete_point($mb_id, $rel_table, $rel_id, $rel_action)
and po_rel_action = '$rel_action' ";
$row = sql_fetch($sql);
if (! (isset($row['po_id']) && $row['po_id'])) {
return true;
}
if(isset($row['po_point']) && $row['po_point'] < 0) {
$mb_id = $row['mb_id'];
$po_point = abs($row['po_point']);
@@ -1843,11 +1868,22 @@ function sql_free_result($result)
}
/**
* MySQL PASSWORD() 함수로 생성된 비밀번호의 hash 값을 반환
*
* MySQL 버전에 따라 결과가 다르게 나올 수 있음.
* MySQL 8.0.11 버전 이상에서는 오류 발생(PASSWORD 함수가 제거됨)으로 사용할 수 없음.
*
* @deprecated 이 함수는 안전하지 않으므로 사용하지 않는 것을 권장 함
* @see get_encrypt_string() and check_password()
* @param string $value
* @return string
*/
function sql_password($value)
{
// mysql 4.0x 이하 버전에서는 password() 함수의 결과가 16bytes
// mysql 4.1x 이상 버전에서는 password() 함수의 결과가 41bytes
$row = sql_fetch(" select password('$value') as pass ");
$row = sql_fetch(" SELECT password('{$value}') as pass ");
return $row['pass'];
}
@@ -2255,6 +2291,53 @@ function check_token()
return true;
}
/**
* 브라우저 검증을 위한 세션 반환 및 재생성
* @param array $member 로그인 된 회원의 정보. 가입일시(mb_datetime)를 반드시 포함해야 한다.
* @param bool $regenerate true 이면 재생성
* @return string
*/
function ss_mb_key($member, $regenerate = false)
{
$client_key = ($regenerate) ? null : get_cookie('mb_client_key');
if (!$client_key) {
$client_key = get_random_token_string(16);
set_cookie('mb_client_key', $client_key, G5_SERVER_TIME * -1);
}
$mb_key = md5($member['mb_datetime'] . $client_key) . run_replace('ss_mb_key_user_agent', md5($_SERVER['HTTP_USER_AGENT']));
return $mb_key;
}
/**
* 회원의 클라이언트 검증
* @param array $member 로그인 된 회원의 정보. 가입일시(mb_datetime)를 반드시 포함해야 한다.
* @return bool
*/
function verify_mb_key($member)
{
$mb_key = ss_mb_key($member);
$verified = get_session('ss_mb_key') === $mb_key;
if (!$verified) {
ss_mb_key($member, true);
}
return $verified;
}
/**
* 회원의 클라이언트 검증 키 생성
* 클라이언트 키를 다시 생성하여 생성된 키는 `ss_mb_key` 세션에 저장됨
* @param array $member 로그인 된 회원의 정보. 가입일시(mb_datetime)를 반드시 포함해야 한다.
*/
function generate_mb_key($member)
{
$mb_key = ss_mb_key($member, true);
set_session('ss_mb_key', $mb_key);
}
// 문자열에 utf8 문자가 들어 있는지 검사하는 함수
// 코드 : http://in2.php.net/manual/en/function.mb-check-encoding.php#95289
@@ -2464,14 +2547,19 @@ function check_device($device)
}
// 게시판 최신글 캐시 파일 삭제
/**
* 게시판 최신글 캐시 파일 삭제
* @param string $bo_table 게시판 ID
*/
function delete_cache_latest($bo_table)
{
if (!preg_match("/^([A-Za-z0-9_]{1,20})$/", $bo_table)) {
return;
}
g5_delete_cache_by_prefix('latest-'.$bo_table.'-');
run_event('delete_cache_latest', $bo_table);
g5_delete_cache_by_prefix('latest-' . $bo_table . '-');
}
// 게시판 첨부파일 썸네일 삭제
@@ -3527,6 +3615,13 @@ function login_password_check($mb, $pass, $hash)
return check_password($pass, $hash);
}
function safe_filter_url_host($url) {
$regex = run_replace('safe_filter_url_regex', '\\', $url);
return $regex ? preg_replace('#'. preg_quote($regex, '#') .'#iu', '', $url) : '';
}
// 동일한 host url 인지
function check_url_host($url, $msg='', $return_url=G5_URL, $is_redirect=false)
{
@@ -3538,14 +3633,15 @@ function check_url_host($url, $msg='', $return_url=G5_URL, $is_redirect=false)
}
// KVE-2021-1277 Open Redirect 취약점 해결
if (preg_match('#\\\0#', $url)) {
if (preg_match('#\\\0#', $url) || preg_match('/^\/{1,}\\\/', $url)) {
alert('url 에 올바르지 않은 값이 포함되어 있습니다.');
}
while ( ( $replace_url = preg_replace(array('/\/{2,}/', '/\\@/'), array('//', ''), urldecode($url)) ) != $url ) {
$url = $replace_url;
}
$p = @parse_url(trim($url));
$p = @parse_url(trim(str_replace('\\', '', $url)));
$host = preg_replace('/:[0-9]+$/', '', $_SERVER['HTTP_HOST']);
$is_host_check = false;
@@ -3804,7 +3900,7 @@ function check_vaild_callback($callback){
class str_encrypt
{
var $salt;
var $lenght;
var $length;
function __construct($salt='')
{
@@ -4157,7 +4253,7 @@ function get_random_token_string($length=6)
}
$characters = '0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz';
$output = substr(str_shuffle($characters), 0, $length); // jihan001 님 제안코드로 수정
$output = substr(str_shuffle($characters), 0, $length);
return bin2hex($output);
}
+8 -2
View File
@@ -145,8 +145,14 @@ function get_content_by_field($write_table, $type='bbs', $where_field='', $where
{
global $g5, $g5_object;
static $cache = array();
$order_key = 'wr_id';
if( $type === 'content' ){
$check_array = array('co_id', 'co_html', 'co_subject', 'co_content', 'co_seo_title', 'co_mobile_content', 'co_skin', 'co_mobile_skin', 'co_tag_filter_use', 'co_hit', 'co_include_head', 'co_include_tail');
$order_key = 'co_id';
} else {
$check_array = array('wr_id', 'wr_num', 'wr_reply', 'wr_parent', 'wr_is_comment', 'ca_name', 'wr_option', 'wr_subject', 'wr_content', 'wr_seo_title', 'wr_link1', 'wr_link2', 'wr_hit', 'wr_good', 'wr_nogood', 'mb_id', 'wr_name', 'wr_email', 'wr_homepage', 'wr_datetime', 'wr_ip', 'wr_1', 'wr_2', 'wr_3', 'wr_4', 'wr_5', 'wr_6', 'wr_7', 'wr_8', 'wr_9', 'wr_10');
}
@@ -162,7 +168,7 @@ function get_content_by_field($write_table, $type='bbs', $where_field='', $where
return $cache[$key];
}
$sql = " select * from {$write_table} where $where_field = '".sql_real_escape_string($where_value)."' ";
$sql = " select * from {$write_table} where $where_field = '".sql_real_escape_string($where_value)."' order by $order_key desc limit 1 ";
$cache[$key] = sql_fetch($sql);
@@ -394,7 +400,7 @@ function get_mb_icon_name($mb_id){
// 생성되면 안되는 게시판명
function get_bo_table_banned_word(){
$folders = array();
$folders = array(G5_CONTENT_DIR, 'rss');
foreach(glob(G5_PATH.'/*', GLOB_ONLYDIR) as $dir) {
$folders[] = basename($dir);
+2 -2
View File
@@ -32,9 +32,9 @@ function get_shop_item_with_category($it_id, $seo_title='', $add_query=''){
global $g5, $default;
if( $seo_title ){
$sql = " select a.*, b.ca_name, b.ca_use from {$g5['g5_shop_item_table']} a, {$g5['g5_shop_category_table']} b where a.it_seo_title = '".sql_real_escape_string(generate_seo_title($seo_title))."' and a.ca_id = b.ca_id $add_query";
$sql = " select a.*, b.ca_name, b.ca_use from {$g5['g5_shop_item_table']} a, {$g5['g5_shop_category_table']} b where a.it_seo_title = '".sql_real_escape_string(generate_seo_title($seo_title))."' and a.ca_id = b.ca_id $add_query order by it_id desc limit 1";
} else {
$sql = " select a.*, b.ca_name, b.ca_use from {$g5['g5_shop_item_table']} a, {$g5['g5_shop_category_table']} b where a.it_id = '$it_id' and a.ca_id = b.ca_id $add_query";
$sql = " select a.*, b.ca_name, b.ca_use from {$g5['g5_shop_item_table']} a, {$g5['g5_shop_category_table']} b where a.it_id = '$it_id' and a.ca_id = b.ca_id $add_query order by it_id desc limit 1";
}
$item = sql_fetch($sql);
+33
View File
@@ -2752,6 +2752,39 @@ function get_item_images_info($it, $size=array(), $image_width, $image_height){
return $images;
}
function check_payment_method($od_settle_case) {
global $default;
$is_block = 0;
if ($od_settle_case === '무통장') {
if (! $default['de_bank_use']) {
$is_block = 1;
}
} else if ($od_settle_case === '계좌이체') {
if (! $default['de_iche_use']) {
$is_block = 1;
}
} else if ($od_settle_case === '가상계좌') {
if (! $default['de_vbank_use']) {
$is_block = 1;
}
} else if ($od_settle_case === '휴대폰') {
if (! $default['de_hp_use']) {
$is_block = 1;
}
} else if ($od_settle_case === '신용카드') {
if (! $default['de_card_use']) {
$is_block = 1;
}
}
if ($is_block) {
alert($od_settle_case.' 은 결제수단에서 사용이 금지되어 있습니다.', G5_SHOP_URL);
die('');
}
}
//결제방식 이름을 체크하여 치환 대상인 문자열은 따로 리턴합니다.
function check_pay_name_replace($payname, $od=array(), $is_client=0){
+10 -3
View File
@@ -10,15 +10,22 @@ function get_list_thumbnail($bo_table, $wr_id, $thumb_width, $thumb_height, $is_
$filename = $alt = $data_path = '';
$edt = false;
$row = get_thumbnail_find_cache($bo_table, $wr_id, 'file');
$empty_array = array('src'=>'', 'ori'=>'', 'alt'=>'');
if(isset($row['bf_file']) && $row['bf_file']) {
$write = get_thumbnail_find_cache($bo_table, $wr_id, 'content');
// 비밀글이면 썸네일을 노출하지 않습니다.
if (isset($write['wr_option']) && strstr($write['wr_option'], "secret")) {
return run_replace('is_secret_list_thumbnail', $empty_array, $bo_table, $write);
}
$row = get_thumbnail_find_cache($bo_table, $wr_id, 'file');
if (isset($row['bf_file']) && $row['bf_file']) {
$filename = $row['bf_file'];
$filepath = G5_DATA_PATH.'/file/'.$bo_table;
$alt = get_text($row['bf_content']);
} else {
$write = get_thumbnail_find_cache($bo_table, $wr_id, 'content');
$edt = true;
if( $matches = get_editor_image($write['wr_content'], false) ){
+53 -2
View File
@@ -253,10 +253,61 @@ function exist_seo_url($type, $seo_title, $write_table, $sql_id=0){
return '';
}
function check_case_exist_title($data, $case=G5_BBS_DIR, $is_redirect=false) {
global $config, $g5, $board;
if ((int) $config['cf_bbs_rewrite'] !== 2) {
return;
}
$seo_title = '';
$redirect_url = '';
if ($case == G5_BBS_DIR && isset($data['wr_seo_title'])) {
$db_table = $g5['write_prefix'].$board['bo_table'];
if (exist_seo_url($case, $data['wr_seo_title'], $db_table, $data['wr_id'])) {
$seo_title = $data['wr_seo_title'].'-'.$data['wr_id'];
$sql = " update `{$db_table}` set wr_seo_title = '".sql_real_escape_string($seo_title)."' where wr_id = '{$data['wr_id']}' ";
sql_query($sql, false);
get_write($db_table, $data['wr_id'], false);
$redirect_url = get_pretty_url($board['bo_table'], $data['wr_id']);
}
} else if ($case == G5_CONTENT_DIR && isset($data['co_seo_title'])) {
$db_table = $g5['content_table'];
if (exist_seo_url($case, $data['co_seo_title'], $db_table, $data['co_id'])) {
$seo_title = $data['co_seo_title'].'-'.substr(get_random_token_string(4), 4);
$sql = " update `{$db_table}` set co_seo_title = '".sql_real_escape_string($seo_title)."' where co_id = '{$data['co_id']}' ";
sql_query($sql, false);
get_content_db($data['co_id'], false);
g5_delete_cache_by_prefix('content-' . $data['co_id'] . '-');
$redirect_url = get_pretty_url($case, $data['co_id']);
}
} else if (defined('G5_SHOP_DIR') && $case == G5_SHOP_DIR && isset($data['it_seo_title'])) {
$db_table = $g5['g5_shop_item_table'];
if (shop_exist_check_seo_title($data['it_seo_title'], $case, $db_table, $data['it_id'])) {
$seo_title = $data['it_seo_title'].'-'.substr(get_random_token_string(4), 4);
$sql = " update `{$db_table}` set it_seo_title = '".sql_real_escape_string($seo_title)."' where it_id = '{$data['it_id']}' ";
sql_query($sql, false);
get_shop_item($data['it_id'], false);
$redirect_url = get_pretty_url($case, $data['it_id']);
}
}
if ($is_redirect && $seo_title && $redirect_url) {
goto_url($redirect_url);
}
}
function exist_seo_title_recursive($type, $seo_title, $write_table, $sql_id=0){
static $count = 0;
$seo_title_add = ($count > 0) ? utf8_strcut($seo_title, 200 - ($count+1), '')."-$count" : $seo_title;
$seo_title_add = ($count > 0) ? utf8_strcut($seo_title, 100000 - ($count+1), '')."-$count" : $seo_title;
if( ! exist_seo_url($type, $seo_title_add, $write_table, $sql_id) ){
return $seo_title_add;
@@ -264,7 +315,7 @@ function exist_seo_title_recursive($type, $seo_title, $write_table, $sql_id=0){
$count++;
if( $count > 198 ){
if( $count > 99998 ){
return $seo_title_add;
}
+1 -1
View File
@@ -33,7 +33,7 @@ else
$order_by = 'b.it_order, b.it_id desc';
if ($skin) {
$skin = preg_replace('#\.+(\/|\\\)#', '', $skin);
$skin = preg_replace(array('#\.+(\/|\\\)#', '#[\'\"]#'), array('', ''), $skin);
$ev['ev_skin'] = $skin;
}
+2
View File
@@ -16,6 +16,8 @@ if( isset($row['it_seo_title']) && ! $row['it_seo_title'] ){
shop_seo_title_update($row['it_id']);
}
if (function_exists('check_case_exist_title')) check_case_exist_title($it, G5_SHOP_DIR, true);
if (!($it['ca_use'] && $it['it_use'])) {
if (!$is_admin)
alert('판매가능한 상품이 아닙니다.');
+1 -1
View File
@@ -99,7 +99,7 @@ class PayService extends SoapClient
var $resMsg;
public function PayService( $wsdl = "", $options = array() )
public function __construct( $wsdl = "", $options = array() )
{
foreach( self::$classmap as $key => $value )
{
+18 -1
View File
@@ -9,7 +9,6 @@
/* = Copyright (c) 2010.05 KCP Inc. All Rights Reserved. = */
/* ============================================================================== */
/* ============================================================================== */
/* = 환경 설정 파일 Include = */
/* = -------------------------------------------------------------------------- = */
@@ -110,6 +109,24 @@
/* = -------------------------------------------------------------------------- = */
if ( $req_tx == "pay" )
{
/* 1004원은 실제로 업체에서 결제하셔야 될 원 금액을 넣어주셔야 합니다. 결제금액 유효성 검증 */
$c_PayPlus->mf_set_ordr_data( "ordr_mony", $good_mny );
$kcp_pay_type = ''; // 결제수단 검증 파라미터 pay_type (신용카드 : PACA, 계좌이체 : PABK, 가상계좌 : PAVC, 휴대폰 : PAMC)
if ($use_pay_method == "100000000000" && (in_array($od_settle_case, array('신용카드', '간편결제')))) { // 신용카드
$kcp_pay_type = 'PACA';
} else if ($use_pay_method == "010000000000" && $od_settle_case === '계좌이체') { // 계좌이체
$kcp_pay_type = 'PABK';
} else if ($use_pay_method == "001000000000" && $od_settle_case === '가상계좌') { // 가상계좌
$kcp_pay_type = 'PAVC';
} else if ($use_pay_method == "000010000000" && $od_settle_case === '휴대폰') { // 휴대폰
$kcp_pay_type = 'PAMC';
}
$c_PayPlus->mf_set_ordr_data( "pay_type", $kcp_pay_type );
$c_PayPlus->mf_set_ordr_data( "ordr_no", $ordr_idxx );
$post_enc_data = isset($_POST["enc_data"]) ? $_POST["enc_data"] : '';
$post_enc_info = isset($_POST["enc_info"]) ? $_POST["enc_info"] : '';
+1 -1
View File
@@ -2,7 +2,7 @@
// 해당 페이지는 사용자가 ISP{국민/BC) 카드 결제를 성공하였을 때, 사용자에게 보여지는 페이지입니다.
include_once('./_common.php');
$LGD_OID = clean_xss_tags($_GET['LGD_OID']);
$LGD_OID = clean_xss_tags($_GET['LGD_OID'], 1, 1);
echo "LGD_OID = ".$LGD_OID;
+1 -1
View File
@@ -168,7 +168,7 @@ var g5_shop_url = "<?php echo G5_SHOP_URL; ?>";
<?php
$qstr1 = '';
if($i > 0 && $total_count > $items) {
if($total_count > $items) {
$qstr1 .= 'ca_id='.$ca_id;
$qstr1 .='&sort='.$sort.'&sortodr='.$sortodr;
$ajax_url = G5_SHOP_URL.'/ajax.list.php?'.$qstr1.'&use_sns=1';
+6 -1
View File
@@ -335,6 +335,11 @@ $order_price = $tot_od_price + $send_cost + $send_cost2 - $tot_sc_cp_price - $od
$od_status = '주문';
$od_tno = '';
if (function_exists('check_payment_method')) {
check_payment_method($od_settle_case);
}
if ($od_settle_case == "무통장")
{
$od_receipt_point = $i_temp_point;
@@ -838,7 +843,7 @@ if($config['cf_sms_use'] && ($default['de_sms_use2'] || $default['de_sms_use3'])
$sms_content = str_replace("{보낸분}", $od_name, $sms_content);
$sms_content = str_replace("{받는분}", $od_b_name, $sms_content);
$sms_content = str_replace("{주문번호}", $od_id, $sms_content);
$sms_content = str_replace("{주문금액}", number_format($tot_ct_price + $od_send_cost + $od_send_cost2), $sms_content);
$sms_content = str_replace("{주문금액}", number_format($tot_ct_price + $od_send_cost + (int) $od_send_cost2), $sms_content);
$sms_content = str_replace("{회원아이디}", $member['mb_id'], $sms_content);
$sms_content = str_replace("{회사명}", $default['de_admin_company_name'], $sms_content);
+3 -1
View File
@@ -1,5 +1,7 @@
<?php
include_once('./_common.php');
if (!defined("_GNUBOARD_")) exit; // 개별 페이지 접근 불가
$od_id = isset($_REQUEST['od_id']) ? safe_replace_regex($_REQUEST['od_id'], 'od_id') : '';
// 테마에 orderinquiryview.php 있으면 include
if(defined('G5_THEME_MSHOP_PATH')) {
+1 -1
View File
@@ -33,7 +33,7 @@ add_stylesheet('<link rel="stylesheet" href="'.$member_skin_url.'/style.css">',
<h2>회원로그인 안내</h2>
<div>
<a href="<?php echo G5_BBS_URL ?>/password_lost.php">아이디/비밀번호 찾기</a>
<a href="./register.php">회원 가입</a>
<a href="<?php echo G5_BBS_URL ?>/register.php">회원 가입</a>
</div>
</section>
</form>
+2 -3
View File
@@ -8,11 +8,10 @@ add_javascript('<script src="'.G5_JS_URL.'/jquery.bxslider.js"></script>', 10);
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<form name="fitem" action="<?php echo $action_url; ?>" method="post" onsubmit="return fitem_submit(this);">
+2 -3
View File
@@ -10,11 +10,10 @@ add_javascript('<script src="'.G5_JS_URL.'/shop.list.action.js"></script>', 10);
<?php if(!defined('G5_IS_SHOP_AJAX_LIST') && $config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 메인상품진열 10 시작 { -->
+2 -3
View File
@@ -10,11 +10,10 @@ add_javascript('<script src="'.G5_JS_URL.'/shop.list.action.js"></script>', 10);
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 메인상품진열 10 시작 { -->
+2 -3
View File
@@ -11,11 +11,10 @@ add_javascript('<script src="'.G5_JS_URL.'/shop.list.action.js"></script>', 10);
<script src="<?php echo G5_JS_URL ?>/jquery.fancylist.js"></script>
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 메인상품진열 20 시작 { -->
+2 -3
View File
@@ -11,11 +11,10 @@ add_javascript('<script src="'.G5_JS_URL.'/shop.list.action.js"></script>', 10);
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<div class="st_30_wr">
<!-- 메인상품진열 30 시작 { -->
+2 -3
View File
@@ -8,11 +8,10 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
<script src="<?php echo G5_JS_URL ?>/jquery.fancylist.js"></script>
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 상품진열 10 시작 { -->
+4 -4
View File
@@ -8,7 +8,7 @@ if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
*/
if( !class_exists('HTMLPurifier_Filter_Iframevideo') ){
class HTMLPurifier_Filter_iframevideo extends HTMLPurifier_Filter
class HTMLPurifier_Filter_Iframevideo extends HTMLPurifier_Filter
{
public $name = 'Iframevideo';
@@ -61,9 +61,9 @@ if( !class_exists('HTMLPurifier_Filter_Iframevideo') ){
protected function postFilterCallback($matches)
{
// Domain Whitelist
$youTubeMatch = preg_match('#src="https?://www.youtube(-nocookie)?.com/#i', $matches[1]);
$vimeoMatch = preg_match('#src="https?://player.vimeo.com/#i', $matches[1]);
$fackbookMatch = preg_match('#src="https?://www.facebook.com/#i', $matches[1]);
$youTubeMatch = preg_match('#src="https?://www\.youtube(-nocookie)?\.com/#i', $matches[1]);
$vimeoMatch = preg_match('#src="https?://player\.vimeo\.com/#i', $matches[1]);
$fackbookMatch = preg_match('#src="https?://www\.facebook\.com/#i', $matches[1]);
if ($youTubeMatch || $vimeoMatch || $fackbookMatch) {
$extra = ' frameborder="0"';
if ($youTubeMatch || $fackbookMatch) {
+7 -5
View File
@@ -12,11 +12,12 @@ if($config['cf_cert_use'] == 2) { // 실서비스 일때
$mTxId ='SIR_'.$max_cr_id;
certify_count_check($member['mb_id'], 'simple'); // 금일 인증시도 횟수 체크
} else { // 테스트 일때
$mid = "INIiasTest";
$apiKey = "TGdxb2l3enJDWFRTbTgvREU3MGYwUT09";
$mTxId ='test_'.$max_cr_id;
$mid = "SRAiasTest";
$apiKey = "43700dfd4c795fe9550853aef3b6aaf1";
$mTxId ='SIR_'.$max_cr_id;
}
$reqSvcCd ='01';
$reqSvcCd ='01'; // 요청구분코드 ["01":간편인증, "02":전자서명]
$reservedMsg = (defined('KGINICIS_USE_CERT_SEED') && KGINICIS_USE_CERT_SEED) ? 'isUseToken=Y' : ''; // 결과조회 응답시 개인정보SEED 암호화 처리 요청
// 등록가맹점 확인
$plainText1 = hash("sha256",(string)$mid.(string)$mTxId.(string)$apiKey);
@@ -66,7 +67,8 @@ include_once(G5_PATH.'/head.sub.php');
<input type="hidden" name="userPhone" value="<?php echo $userPhone ?>">
<input type="hidden" name="userBirth" value="<?php echo $userBirth ?>">
<input type="hidden" name="userHash" value="<?php echo $userHash ?>">
<input type="hidden" name="mbId" value="<?php echo $member['mb_id'] ?>">
<input type="hidden" name="reservedMsg" value="<?php echo $reservedMsg; ?>">
<input type="hidden" name="mbId" value="<?php echo $member['mb_id']; ?>">
<input type="hidden" name="directAgency" value="<?php echo isset($_GET['directAgency']) ? clean_xss_tags($_GET['directAgency'], 1, 1) : ''; ?>">
<input type="hidden" name="successUrl" value="<?php echo $resultUrl; ?>"> <!-- 필수 값 -->
+20 -1
View File
@@ -1,8 +1,12 @@
<?php
include_once('./_common.php');
require_once (dirname(__FILE__) .'/libs/KISA_SEED_CBC.php');
require_once (dirname(__FILE__) .'/libs/INILib.php');
$txId = isset($_POST['txId']) ? clean_xss_tags($_POST['txId'], 1, 1) : '';
$mid = substr($txId, 6, 10);
$SEEDKEY = isset($_POST['token']) ? clean_xss_tags($_POST['token'], 1, 1) : '';
$SEEDIV = 'SASHOSTSIRIAS000';
if ($txId && isset($_POST["resultCode"]) && $_POST["resultCode"] === "0000") {
@@ -14,8 +18,15 @@ if ($txId && isset($_POST["resultCode"]) && $_POST["resultCode"] === "0000") {
$post_data = json_encode($data);
$authRequestUrl = isset($_POST["authRequestUrl"]) ? is_inicis_url_return($_POST["authRequestUrl"]) : '';
if(!$authRequestUrl){
// SaSample 에 나와있는대로 url을 검증합니다.
if (!(strpos($authRequestUrl,"https://kssa.inicis.com") == 0 || strpos($authRequestUrl,"https://fcsa.inicis.com") == 0)) {
$authRequestUrl = '';
}
if (! $authRequestUrl) {
alert('잘못된 요청입니다.', G5_URL);
exit;
}
// curl 통신 시작
@@ -42,6 +53,14 @@ if ($txId && isset($_POST["resultCode"]) && $_POST["resultCode"] === "0000") {
$user_name = $res_data['userName']; // 이름
$birth_day = $res_data['userBirthday']; // 생년월일
$ci = $res_data['userCi']; // CI
if (defined('KGINICIS_USE_CERT_SEED') && KGINICIS_USE_CERT_SEED) {
// 개인정보SEED 암호화 된것을 복호화 합니다.
$user_name = decrypt_SEED($user_name, $SEEDKEY, $SEEDIV);
$phone_no = decrypt_SEED($phone_no, $SEEDKEY, $SEEDIV);
$birth_day = decrypt_SEED($birth_day, $SEEDKEY, $SEEDIV);
$ci = decrypt_SEED($ci, $SEEDKEY, $SEEDIV);
}
@insert_cert_history($member['mb_id'], 'inicis', $cert_type); // 인증성공 시 내역 기록
+78
View File
@@ -0,0 +1,78 @@
<?php
function String2Hex($string) {
$hex = array();
for ($i = 0; $i < strlen($string); $i++) {
$hex[] = dechex(ord($string[$i]));
}
return $hex;
}
function Hex2String($hex) {
$str = "";
for ($i = 0; $i < count($hex); $i++) {
$str .= chr(hexdec($hex[$i]));
}
return $str;
}
function encrypt_SEED($str, $bszUser_key, $bszIV) {
$planBytes = String2Hex($str);
$keyBytes = String2Hex(base64_decode($bszUser_key));
$IVBytes = String2Hex(($bszIV));
for ($i = 0; $i < 16; $i++) {
$keyBytes[$i] = hexdec(($keyBytes[$i]));
$IVBytes[$i] = hexdec(($IVBytes[$i]));
}
for ($i = 0; $i < count($planBytes); $i++) {
$planBytes[$i] = hexdec($planBytes[$i]);
}
if (count($planBytes) == 0) {
return $str;
}
$ret = null;
$bszChiperText = null;
$pdwRoundKey = array_pad(array(), 32, 0);
$bszChiperText = KISA_SEED_CBC::SEED_CBC_Encrypt($keyBytes, $IVBytes, $planBytes, 0, count($planBytes));
$r = count($bszChiperText);
for ($i = 0; $i < $r; $i++) {
$ret[] = sprintf("%02X", $bszChiperText[$i]);
}
return base64_encode(Hex2String($ret));
}
function decrypt_SEED($str, $bszUser_key, $bszIV) {
$planBytes = String2Hex(base64_decode($str));
$keyBytes = String2Hex(base64_decode($bszUser_key));
$IVBytes = String2Hex(($bszIV));
for ($i = 0; $i < 16; $i++) {
$keyBytes[$i] = hexdec(($keyBytes[$i]));
$IVBytes[$i] = hexdec(($IVBytes[$i]));
}
for ($i = 0; $i < count($planBytes); $i++) {
$planBytes[$i] = hexdec($planBytes[$i]);
}
if (count($planBytes) == 0) {
return $str;
}
$pdwRoundKey = array_pad(array(), 32, 0);
$bszPlainText = null;
$planBytresMessage = array();
// 방법 1
$bszPlainText = KISA_SEED_CBC::SEED_CBC_Decrypt($keyBytes, $IVBytes, $planBytes, 0, count($planBytes));
for ($i = 0; $i < sizeof((array) $bszPlainText); $i++) {
$planBytresMessage[] = sprintf("%02X", $bszPlainText[$i]);
}
return Hex2String($planBytresMessage);
}
+822
View File
@@ -0,0 +1,822 @@
<?php
/*
@file KISA_SEED_CBC.php
@brief SEED CBC 암호 알고리즘
@author Copyright (c) 2013 by KISA
@remarks http://seed.kisa.or.kr/
*/
if (!defined('_KISA_COMMON_LIB')) {
define('_KISA_COMMON_LIB', 1);
function isLittleEndian() {
$testint = 0x00FF;
$p = pack('S', $testint);
return $testint === current(unpack('v', $p));
}
$_kisa_common_is_little_endian = isLittleEndian();
if (!defined('_KISA_COMMON_IS_LITTLE_ENDIAN')) {
define('_KISA_COMMON_IS_LITTLE_ENDIAN', $_kisa_common_is_little_endian);
}
class Common {
static function arraycopy(&$dst, &$src, $length) {
for ($i = 0; $i < $length; $i++) {
$dst[$i] = $src[$i];
}
}
static function arraycopy_offset(&$dst, $dst_offset, &$src, $src_offset, $length) {
for ($i = 0; $i < $length; $i++) {
$dst[$dst_offset + $i] = $src[$src_offset + $i];
}
}
static function arraycopy_system(&$src, $src_offset, &$dst, $dst_offset, $length) {
for ($i = 0; $i < $length; $i++) {
$dst[$dst_offset + $i] = $src[$src_offset + $i];
}
}
static function arrayinit(&$dst, $value, $length) {
for ($i = 0; $i < $length; $i++) {
$dst[$i] = $value;
}
}
static function arrayinit_offset(&$dst, $dst_offset, $value, $length) {
for ($i = 0; $i < $length; $i++) {
$dst[$dst_offset + $i] = $value;
}
}
static function memcpy_byte2int(&$dst, &$src, $length) {
$iLen = (int) ($length / 4);
for ($i = 0; $i < $iLen; $i++) {
Common::byte_to_int($dst, $i, $src, $i * 4);
}
}
static function memcpy_int2int(&$dst, &$src, $src_offset, $length) {
$iLen = (int) ($length / 4);
for ($i = 0; $i < $iLen; $i++) {
$dst[$i] = $src[$src_offset + $i];
}
}
static function set_byte_for_int(&$dst, $b_offset, $value) {
if (_KISA_COMMON_IS_LITTLE_ENDIAN == true) {
$shift_value = (3 - $b_offset % 4) * 8;
$mask_value = 0x0ff << $shift_value;
$mask_value2 = ~$mask_value;
$value2 = ($value & 0x0ff) << $shift_value;
$dst[(int) ($b_offset / 4)] = ($dst[(int) ($b_offset / 4)] & $mask_value2) | ($value2 & $mask_value);
} else {
$shift_value = ($b_offset % 4) * 8;
$mask_value = 0x0ff << $shift_value;
$mask_value2 = ~$mask_value;
$value2 = ($value & 0x0ff) << $shift_value;
$dst[(int) ($b_offset / 4)] = ($dst[(int) ($b_offset / 4)] & $mask_value2) | ($value2 & $mask_value);
}
}
static function get_byte_for_int(&$src, $b_offset) {
if (_KISA_COMMON_IS_LITTLE_ENDIAN == true) {
$shift_value = (3 - $b_offset % 4) * 8;
$mask_value = 0x0ff << $shift_value;
$value = ($src[(int) ($b_offset / 4)] & $mask_value) >> $shift_value;
return $value & 0x0ff;
} else {
$shift_value = ($b_offset % 4) * 8;
$mask_value = 0x0ff << $shift_value;
$value = ($src[(int) ($b_offset / 4)] & $mask_value) >> $shift_value;
return $value & 0x0ff;
}
}
static function byte_to_int(&$dst, $dst_offset, &$src, $src_offset) {
if (_KISA_COMMON_IS_LITTLE_ENDIAN == true) {
$dst[$dst_offset] = ((0x0ff & $src[$src_offset]) << 24) | ((0x0ff & $src[$src_offset + 1]) << 16) | ((0x0ff & $src[$src_offset + 2]) << 8) | ((0x0ff & $src[$src_offset + 3]));
} else {
$dst[$dst_offset] = ((0x0ff & $src[$src_offset])) | ((0x0ff & $src[$src_offset + 1]) << 8) | ((0x0ff & $src[$src_offset + 2]) << 16) | ((0x0ff & $src[$src_offset + 3]) << 24);
}
}
static function get_byte_to_int(&$src, $src_offset) {
if (_KISA_COMMON_IS_LITTLE_ENDIAN == true) {
return ((0x0ff & $src[$src_offset]) << 24) | ((0x0ff & $src[$src_offset + 1]) << 16) | ((0x0ff & $src[$src_offset + 2]) << 8) | ((0x0ff & $src[$src_offset + 3]));
} else {
return ((0x0ff & $src[$src_offset])) | ((0x0ff & $src[$src_offset + 1]) << 8) | ((0x0ff & $src[$src_offset + 2]) << 16) | ((0x0ff & $src[$src_offset + 3]) << 24);
}
}
static function int_to_byte(&$dst, $dst_offset, &$src, $src_offset) {
Common::int_to_byte_unit($dst, $dst_offset, $src[$src_offset]);
}
static function int_to_byte_unit(&$dst, $dst_offset, $src) {
if (_KISA_COMMON_IS_LITTLE_ENDIAN == true) {
$dst[$dst_offset] = (($src >> 24) & 0x0ff);
$dst[$dst_offset + 1] = (($src >> 16) & 0x0ff);
$dst[$dst_offset + 2] = (($src >> 8) & 0x0ff);
$dst[$dst_offset + 3] = (($src) & 0x0ff);
} else {
$dst[$dst_offset] = (($src) & 0x0ff);
$dst[$dst_offset + 1] = (($src >> 8) & 0x0ff);
$dst[$dst_offset + 2] = (($src >> 16) & 0x0ff);
$dst[$dst_offset + 3] = (($src >> 24) & 0x0ff);
}
}
static function URShift($x, $n) {
if ($n == 0)
return $x;
if ($n >= 32)
return 0;
$v = $x >> $n;
$v_mask = ~(0x80000000 >> ($n - 1));
return $v & $v_mask;
}
static function intToUnsigned($x) {
if ($x >= 0)
return $x;
return $x + pow(2, 32);
}
}
}
if (!defined('_KISA_ENC_DEC_')) {
define('_KISA_ENC_DEC_', '1');
class KISA_ENC_DEC {
const KISA_DECRYPT = 0;
const KISA_ENCRYPT = 1;
}
}
if (!defined('_KISA_SEED_KEY_')) {
define('_KISA_SEED_KEY_', '1');
class KISA_SEED_KEY {
var $key_data = null;
function __construct() {
$this->key_data = array_pad(array(), 32, 0);
}
}
}
if (!defined('_KISA_SEED_INFO_')) {
define('_KISA_SEED_INFO_', '1');
class KISA_SEED_INFO {
var $encrypt = 0;
var $ivec = null;
var $seed_key = null;
var $cbc_buffer = null;
var $buffer_length = 0;
var $cbc_last_block = null;
var $last_block_flag = 0;
function __construct() {
$this->ivec = array_pad(array(), 4, 0);
$this->seed_key = new KISA_SEED_KEY();
$this->cbc_buffer = array_pad(array(), 4, 0);
$this->cbc_last_block = array_pad(array(), 4, 0);
}
}
}
if (!defined('_KISA_LR_VAR')) {
define('LR_L0', 0);
define('LR_L1', 1);
define('LR_R0', 2);
define('LR_R1', 3);
}
class KISA_SEED_CBC {
static $SS0 = array(
0x02989a1a8, 0x005858184, 0x016c6d2d4, 0x013c3d3d0, 0x014445054, 0x01d0d111c, 0x02c8ca0ac, 0x025052124,
0x01d4d515c, 0x003434340, 0x018081018, 0x01e0e121c, 0x011415150, 0x03cccf0fc, 0x00acac2c8, 0x023436360,
0x028082028, 0x004444044, 0x020002020, 0x01d8d919c, 0x020c0e0e0, 0x022c2e2e0, 0x008c8c0c8, 0x017071314,
0x02585a1a4, 0x00f8f838c, 0x003030300, 0x03b4b7378, 0x03b8bb3b8, 0x013031310, 0x012c2d2d0, 0x02ecee2ec,
0x030407070, 0x00c8c808c, 0x03f0f333c, 0x02888a0a8, 0x032023230, 0x01dcdd1dc, 0x036c6f2f4, 0x034447074,
0x02ccce0ec, 0x015859194, 0x00b0b0308, 0x017475354, 0x01c4c505c, 0x01b4b5358, 0x03d8db1bc, 0x001010100,
0x024042024, 0x01c0c101c, 0x033437370, 0x018889098, 0x010001010, 0x00cccc0cc, 0x032c2f2f0, 0x019c9d1d8,
0x02c0c202c, 0x027c7e3e4, 0x032427270, 0x003838380, 0x01b8b9398, 0x011c1d1d0, 0x006868284, 0x009c9c1c8,
0x020406060, 0x010405050, 0x02383a3a0, 0x02bcbe3e8, 0x00d0d010c, 0x03686b2b4, 0x01e8e929c, 0x00f4f434c,
0x03787b3b4, 0x01a4a5258, 0x006c6c2c4, 0x038487078, 0x02686a2a4, 0x012021210, 0x02f8fa3ac, 0x015c5d1d4,
0x021416160, 0x003c3c3c0, 0x03484b0b4, 0x001414140, 0x012425250, 0x03d4d717c, 0x00d8d818c, 0x008080008,
0x01f0f131c, 0x019899198, 0x000000000, 0x019091118, 0x004040004, 0x013435350, 0x037c7f3f4, 0x021c1e1e0,
0x03dcdf1fc, 0x036467274, 0x02f0f232c, 0x027072324, 0x03080b0b0, 0x00b8b8388, 0x00e0e020c, 0x02b8ba3a8,
0x02282a2a0, 0x02e4e626c, 0x013839390, 0x00d4d414c, 0x029496168, 0x03c4c707c, 0x009090108, 0x00a0a0208,
0x03f8fb3bc, 0x02fcfe3ec, 0x033c3f3f0, 0x005c5c1c4, 0x007878384, 0x014041014, 0x03ecef2fc, 0x024446064,
0x01eced2dc, 0x02e0e222c, 0x00b4b4348, 0x01a0a1218, 0x006060204, 0x021012120, 0x02b4b6368, 0x026466264,
0x002020200, 0x035c5f1f4, 0x012829290, 0x00a8a8288, 0x00c0c000c, 0x03383b3b0, 0x03e4e727c, 0x010c0d0d0,
0x03a4a7278, 0x007474344, 0x016869294, 0x025c5e1e4, 0x026062224, 0x000808080, 0x02d8da1ac, 0x01fcfd3dc,
0x02181a1a0, 0x030003030, 0x037073334, 0x02e8ea2ac, 0x036063234, 0x015051114, 0x022022220, 0x038083038,
0x034c4f0f4, 0x02787a3a4, 0x005454144, 0x00c4c404c, 0x001818180, 0x029c9e1e8, 0x004848084, 0x017879394,
0x035053134, 0x00bcbc3c8, 0x00ecec2cc, 0x03c0c303c, 0x031417170, 0x011011110, 0x007c7c3c4, 0x009898188,
0x035457174, 0x03bcbf3f8, 0x01acad2d8, 0x038c8f0f8, 0x014849094, 0x019495158, 0x002828280, 0x004c4c0c4,
0x03fcff3fc, 0x009494148, 0x039093138, 0x027476364, 0x000c0c0c0, 0x00fcfc3cc, 0x017c7d3d4, 0x03888b0b8,
0x00f0f030c, 0x00e8e828c, 0x002424240, 0x023032320, 0x011819190, 0x02c4c606c, 0x01bcbd3d8, 0x02484a0a4,
0x034043034, 0x031c1f1f0, 0x008484048, 0x002c2c2c0, 0x02f4f636c, 0x03d0d313c, 0x02d0d212c, 0x000404040,
0x03e8eb2bc, 0x03e0e323c, 0x03c8cb0bc, 0x001c1c1c0, 0x02a8aa2a8, 0x03a8ab2b8, 0x00e4e424c, 0x015455154,
0x03b0b3338, 0x01cccd0dc, 0x028486068, 0x03f4f737c, 0x01c8c909c, 0x018c8d0d8, 0x00a4a4248, 0x016465254,
0x037477374, 0x02080a0a0, 0x02dcde1ec, 0x006464244, 0x03585b1b4, 0x02b0b2328, 0x025456164, 0x03acaf2f8,
0x023c3e3e0, 0x03989b1b8, 0x03181b1b0, 0x01f8f939c, 0x01e4e525c, 0x039c9f1f8, 0x026c6e2e4, 0x03282b2b0,
0x031013130, 0x02acae2e8, 0x02d4d616c, 0x01f4f535c, 0x024c4e0e4, 0x030c0f0f0, 0x00dcdc1cc, 0x008888088,
0x016061214, 0x03a0a3238, 0x018485058, 0x014c4d0d4, 0x022426260, 0x029092128, 0x007070304, 0x033033330,
0x028c8e0e8, 0x01b0b1318, 0x005050104, 0x039497178, 0x010809090, 0x02a4a6268, 0x02a0a2228, 0x01a8a9298
);
static $SS1 = array(
0x038380830, 0x0e828c8e0, 0x02c2d0d21, 0x0a42686a2, 0x0cc0fcfc3, 0x0dc1eced2, 0x0b03383b3, 0x0b83888b0,
0x0ac2f8fa3, 0x060204060, 0x054154551, 0x0c407c7c3, 0x044044440, 0x06c2f4f63, 0x0682b4b63, 0x0581b4b53,
0x0c003c3c3, 0x060224262, 0x030330333, 0x0b43585b1, 0x028290921, 0x0a02080a0, 0x0e022c2e2, 0x0a42787a3,
0x0d013c3d3, 0x090118191, 0x010110111, 0x004060602, 0x01c1c0c10, 0x0bc3c8cb0, 0x034360632, 0x0480b4b43,
0x0ec2fcfe3, 0x088088880, 0x06c2c4c60, 0x0a82888a0, 0x014170713, 0x0c404c4c0, 0x014160612, 0x0f434c4f0,
0x0c002c2c2, 0x044054541, 0x0e021c1e1, 0x0d416c6d2, 0x03c3f0f33, 0x03c3d0d31, 0x08c0e8e82, 0x098188890,
0x028280820, 0x04c0e4e42, 0x0f436c6f2, 0x03c3e0e32, 0x0a42585a1, 0x0f839c9f1, 0x00c0d0d01, 0x0dc1fcfd3,
0x0d818c8d0, 0x0282b0b23, 0x064264662, 0x0783a4a72, 0x024270723, 0x02c2f0f23, 0x0f031c1f1, 0x070324272,
0x040024242, 0x0d414c4d0, 0x040014141, 0x0c000c0c0, 0x070334373, 0x064274763, 0x0ac2c8ca0, 0x0880b8b83,
0x0f437c7f3, 0x0ac2d8da1, 0x080008080, 0x01c1f0f13, 0x0c80acac2, 0x02c2c0c20, 0x0a82a8aa2, 0x034340430,
0x0d012c2d2, 0x0080b0b03, 0x0ec2ecee2, 0x0e829c9e1, 0x05c1d4d51, 0x094148490, 0x018180810, 0x0f838c8f0,
0x054174753, 0x0ac2e8ea2, 0x008080800, 0x0c405c5c1, 0x010130313, 0x0cc0dcdc1, 0x084068682, 0x0b83989b1,
0x0fc3fcff3, 0x07c3d4d71, 0x0c001c1c1, 0x030310131, 0x0f435c5f1, 0x0880a8a82, 0x0682a4a62, 0x0b03181b1,
0x0d011c1d1, 0x020200020, 0x0d417c7d3, 0x000020202, 0x020220222, 0x004040400, 0x068284860, 0x070314171,
0x004070703, 0x0d81bcbd3, 0x09c1d8d91, 0x098198991, 0x060214161, 0x0bc3e8eb2, 0x0e426c6e2, 0x058194951,
0x0dc1dcdd1, 0x050114151, 0x090108090, 0x0dc1cccd0, 0x0981a8a92, 0x0a02383a3, 0x0a82b8ba3, 0x0d010c0d0,
0x080018181, 0x00c0f0f03, 0x044074743, 0x0181a0a12, 0x0e023c3e3, 0x0ec2ccce0, 0x08c0d8d81, 0x0bc3f8fb3,
0x094168692, 0x0783b4b73, 0x05c1c4c50, 0x0a02282a2, 0x0a02181a1, 0x060234363, 0x020230323, 0x04c0d4d41,
0x0c808c8c0, 0x09c1e8e92, 0x09c1c8c90, 0x0383a0a32, 0x00c0c0c00, 0x02c2e0e22, 0x0b83a8ab2, 0x06c2e4e62,
0x09c1f8f93, 0x0581a4a52, 0x0f032c2f2, 0x090128292, 0x0f033c3f3, 0x048094941, 0x078384870, 0x0cc0cccc0,
0x014150511, 0x0f83bcbf3, 0x070304070, 0x074354571, 0x07c3f4f73, 0x034350531, 0x010100010, 0x000030303,
0x064244460, 0x06c2d4d61, 0x0c406c6c2, 0x074344470, 0x0d415c5d1, 0x0b43484b0, 0x0e82acae2, 0x008090901,
0x074364672, 0x018190911, 0x0fc3ecef2, 0x040004040, 0x010120212, 0x0e020c0e0, 0x0bc3d8db1, 0x004050501,
0x0f83acaf2, 0x000010101, 0x0f030c0f0, 0x0282a0a22, 0x05c1e4e52, 0x0a82989a1, 0x054164652, 0x040034343,
0x084058581, 0x014140410, 0x088098981, 0x0981b8b93, 0x0b03080b0, 0x0e425c5e1, 0x048084840, 0x078394971,
0x094178793, 0x0fc3cccf0, 0x01c1e0e12, 0x080028282, 0x020210121, 0x08c0c8c80, 0x0181b0b13, 0x05c1f4f53,
0x074374773, 0x054144450, 0x0b03282b2, 0x01c1d0d11, 0x024250521, 0x04c0f4f43, 0x000000000, 0x044064642,
0x0ec2dcde1, 0x058184850, 0x050124252, 0x0e82bcbe3, 0x07c3e4e72, 0x0d81acad2, 0x0c809c9c1, 0x0fc3dcdf1,
0x030300030, 0x094158591, 0x064254561, 0x03c3c0c30, 0x0b43686b2, 0x0e424c4e0, 0x0b83b8bb3, 0x07c3c4c70,
0x00c0e0e02, 0x050104050, 0x038390931, 0x024260622, 0x030320232, 0x084048480, 0x068294961, 0x090138393,
0x034370733, 0x0e427c7e3, 0x024240420, 0x0a42484a0, 0x0c80bcbc3, 0x050134353, 0x0080a0a02, 0x084078783,
0x0d819c9d1, 0x04c0c4c40, 0x080038383, 0x08c0f8f83, 0x0cc0ecec2, 0x0383b0b33, 0x0480a4a42, 0x0b43787b3
);
static $SS2 = array(
0x0a1a82989, 0x081840585, 0x0d2d416c6, 0x0d3d013c3, 0x050541444, 0x0111c1d0d, 0x0a0ac2c8c, 0x021242505,
0x0515c1d4d, 0x043400343, 0x010181808, 0x0121c1e0e, 0x051501141, 0x0f0fc3ccc, 0x0c2c80aca, 0x063602343,
0x020282808, 0x040440444, 0x020202000, 0x0919c1d8d, 0x0e0e020c0, 0x0e2e022c2, 0x0c0c808c8, 0x013141707,
0x0a1a42585, 0x0838c0f8f, 0x003000303, 0x073783b4b, 0x0b3b83b8b, 0x013101303, 0x0d2d012c2, 0x0e2ec2ece,
0x070703040, 0x0808c0c8c, 0x0333c3f0f, 0x0a0a82888, 0x032303202, 0x0d1dc1dcd, 0x0f2f436c6, 0x070743444,
0x0e0ec2ccc, 0x091941585, 0x003080b0b, 0x053541747, 0x0505c1c4c, 0x053581b4b, 0x0b1bc3d8d, 0x001000101,
0x020242404, 0x0101c1c0c, 0x073703343, 0x090981888, 0x010101000, 0x0c0cc0ccc, 0x0f2f032c2, 0x0d1d819c9,
0x0202c2c0c, 0x0e3e427c7, 0x072703242, 0x083800383, 0x093981b8b, 0x0d1d011c1, 0x082840686, 0x0c1c809c9,
0x060602040, 0x050501040, 0x0a3a02383, 0x0e3e82bcb, 0x0010c0d0d, 0x0b2b43686, 0x0929c1e8e, 0x0434c0f4f,
0x0b3b43787, 0x052581a4a, 0x0c2c406c6, 0x070783848, 0x0a2a42686, 0x012101202, 0x0a3ac2f8f, 0x0d1d415c5,
0x061602141, 0x0c3c003c3, 0x0b0b43484, 0x041400141, 0x052501242, 0x0717c3d4d, 0x0818c0d8d, 0x000080808,
0x0131c1f0f, 0x091981989, 0x000000000, 0x011181909, 0x000040404, 0x053501343, 0x0f3f437c7, 0x0e1e021c1,
0x0f1fc3dcd, 0x072743646, 0x0232c2f0f, 0x023242707, 0x0b0b03080, 0x083880b8b, 0x0020c0e0e, 0x0a3a82b8b,
0x0a2a02282, 0x0626c2e4e, 0x093901383, 0x0414c0d4d, 0x061682949, 0x0707c3c4c, 0x001080909, 0x002080a0a,
0x0b3bc3f8f, 0x0e3ec2fcf, 0x0f3f033c3, 0x0c1c405c5, 0x083840787, 0x010141404, 0x0f2fc3ece, 0x060642444,
0x0d2dc1ece, 0x0222c2e0e, 0x043480b4b, 0x012181a0a, 0x002040606, 0x021202101, 0x063682b4b, 0x062642646,
0x002000202, 0x0f1f435c5, 0x092901282, 0x082880a8a, 0x0000c0c0c, 0x0b3b03383, 0x0727c3e4e, 0x0d0d010c0,
0x072783a4a, 0x043440747, 0x092941686, 0x0e1e425c5, 0x022242606, 0x080800080, 0x0a1ac2d8d, 0x0d3dc1fcf,
0x0a1a02181, 0x030303000, 0x033343707, 0x0a2ac2e8e, 0x032343606, 0x011141505, 0x022202202, 0x030383808,
0x0f0f434c4, 0x0a3a42787, 0x041440545, 0x0404c0c4c, 0x081800181, 0x0e1e829c9, 0x080840484, 0x093941787,
0x031343505, 0x0c3c80bcb, 0x0c2cc0ece, 0x0303c3c0c, 0x071703141, 0x011101101, 0x0c3c407c7, 0x081880989,
0x071743545, 0x0f3f83bcb, 0x0d2d81aca, 0x0f0f838c8, 0x090941484, 0x051581949, 0x082800282, 0x0c0c404c4,
0x0f3fc3fcf, 0x041480949, 0x031383909, 0x063642747, 0x0c0c000c0, 0x0c3cc0fcf, 0x0d3d417c7, 0x0b0b83888,
0x0030c0f0f, 0x0828c0e8e, 0x042400242, 0x023202303, 0x091901181, 0x0606c2c4c, 0x0d3d81bcb, 0x0a0a42484,
0x030343404, 0x0f1f031c1, 0x040480848, 0x0c2c002c2, 0x0636c2f4f, 0x0313c3d0d, 0x0212c2d0d, 0x040400040,
0x0b2bc3e8e, 0x0323c3e0e, 0x0b0bc3c8c, 0x0c1c001c1, 0x0a2a82a8a, 0x0b2b83a8a, 0x0424c0e4e, 0x051541545,
0x033383b0b, 0x0d0dc1ccc, 0x060682848, 0x0737c3f4f, 0x0909c1c8c, 0x0d0d818c8, 0x042480a4a, 0x052541646,
0x073743747, 0x0a0a02080, 0x0e1ec2dcd, 0x042440646, 0x0b1b43585, 0x023282b0b, 0x061642545, 0x0f2f83aca,
0x0e3e023c3, 0x0b1b83989, 0x0b1b03181, 0x0939c1f8f, 0x0525c1e4e, 0x0f1f839c9, 0x0e2e426c6, 0x0b2b03282,
0x031303101, 0x0e2e82aca, 0x0616c2d4d, 0x0535c1f4f, 0x0e0e424c4, 0x0f0f030c0, 0x0c1cc0dcd, 0x080880888,
0x012141606, 0x032383a0a, 0x050581848, 0x0d0d414c4, 0x062602242, 0x021282909, 0x003040707, 0x033303303,
0x0e0e828c8, 0x013181b0b, 0x001040505, 0x071783949, 0x090901080, 0x062682a4a, 0x022282a0a, 0x092981a8a
);
static $SS3 = array(
0x008303838, 0x0c8e0e828, 0x00d212c2d, 0x086a2a426, 0x0cfc3cc0f, 0x0ced2dc1e, 0x083b3b033, 0x088b0b838,
0x08fa3ac2f, 0x040606020, 0x045515415, 0x0c7c3c407, 0x044404404, 0x04f636c2f, 0x04b63682b, 0x04b53581b,
0x0c3c3c003, 0x042626022, 0x003333033, 0x085b1b435, 0x009212829, 0x080a0a020, 0x0c2e2e022, 0x087a3a427,
0x0c3d3d013, 0x081919011, 0x001111011, 0x006020406, 0x00c101c1c, 0x08cb0bc3c, 0x006323436, 0x04b43480b,
0x0cfe3ec2f, 0x088808808, 0x04c606c2c, 0x088a0a828, 0x007131417, 0x0c4c0c404, 0x006121416, 0x0c4f0f434,
0x0c2c2c002, 0x045414405, 0x0c1e1e021, 0x0c6d2d416, 0x00f333c3f, 0x00d313c3d, 0x08e828c0e, 0x088909818,
0x008202828, 0x04e424c0e, 0x0c6f2f436, 0x00e323c3e, 0x085a1a425, 0x0c9f1f839, 0x00d010c0d, 0x0cfd3dc1f,
0x0c8d0d818, 0x00b23282b, 0x046626426, 0x04a72783a, 0x007232427, 0x00f232c2f, 0x0c1f1f031, 0x042727032,
0x042424002, 0x0c4d0d414, 0x041414001, 0x0c0c0c000, 0x043737033, 0x047636427, 0x08ca0ac2c, 0x08b83880b,
0x0c7f3f437, 0x08da1ac2d, 0x080808000, 0x00f131c1f, 0x0cac2c80a, 0x00c202c2c, 0x08aa2a82a, 0x004303434,
0x0c2d2d012, 0x00b03080b, 0x0cee2ec2e, 0x0c9e1e829, 0x04d515c1d, 0x084909414, 0x008101818, 0x0c8f0f838,
0x047535417, 0x08ea2ac2e, 0x008000808, 0x0c5c1c405, 0x003131013, 0x0cdc1cc0d, 0x086828406, 0x089b1b839,
0x0cff3fc3f, 0x04d717c3d, 0x0c1c1c001, 0x001313031, 0x0c5f1f435, 0x08a82880a, 0x04a62682a, 0x081b1b031,
0x0c1d1d011, 0x000202020, 0x0c7d3d417, 0x002020002, 0x002222022, 0x004000404, 0x048606828, 0x041717031,
0x007030407, 0x0cbd3d81b, 0x08d919c1d, 0x089919819, 0x041616021, 0x08eb2bc3e, 0x0c6e2e426, 0x049515819,
0x0cdd1dc1d, 0x041515011, 0x080909010, 0x0ccd0dc1c, 0x08a92981a, 0x083a3a023, 0x08ba3a82b, 0x0c0d0d010,
0x081818001, 0x00f030c0f, 0x047434407, 0x00a12181a, 0x0c3e3e023, 0x0cce0ec2c, 0x08d818c0d, 0x08fb3bc3f,
0x086929416, 0x04b73783b, 0x04c505c1c, 0x082a2a022, 0x081a1a021, 0x043636023, 0x003232023, 0x04d414c0d,
0x0c8c0c808, 0x08e929c1e, 0x08c909c1c, 0x00a32383a, 0x00c000c0c, 0x00e222c2e, 0x08ab2b83a, 0x04e626c2e,
0x08f939c1f, 0x04a52581a, 0x0c2f2f032, 0x082929012, 0x0c3f3f033, 0x049414809, 0x048707838, 0x0ccc0cc0c,
0x005111415, 0x0cbf3f83b, 0x040707030, 0x045717435, 0x04f737c3f, 0x005313435, 0x000101010, 0x003030003,
0x044606424, 0x04d616c2d, 0x0c6c2c406, 0x044707434, 0x0c5d1d415, 0x084b0b434, 0x0cae2e82a, 0x009010809,
0x046727436, 0x009111819, 0x0cef2fc3e, 0x040404000, 0x002121012, 0x0c0e0e020, 0x08db1bc3d, 0x005010405,
0x0caf2f83a, 0x001010001, 0x0c0f0f030, 0x00a22282a, 0x04e525c1e, 0x089a1a829, 0x046525416, 0x043434003,
0x085818405, 0x004101414, 0x089818809, 0x08b93981b, 0x080b0b030, 0x0c5e1e425, 0x048404808, 0x049717839,
0x087939417, 0x0ccf0fc3c, 0x00e121c1e, 0x082828002, 0x001212021, 0x08c808c0c, 0x00b13181b, 0x04f535c1f,
0x047737437, 0x044505414, 0x082b2b032, 0x00d111c1d, 0x005212425, 0x04f434c0f, 0x000000000, 0x046424406,
0x0cde1ec2d, 0x048505818, 0x042525012, 0x0cbe3e82b, 0x04e727c3e, 0x0cad2d81a, 0x0c9c1c809, 0x0cdf1fc3d,
0x000303030, 0x085919415, 0x045616425, 0x00c303c3c, 0x086b2b436, 0x0c4e0e424, 0x08bb3b83b, 0x04c707c3c,
0x00e020c0e, 0x040505010, 0x009313839, 0x006222426, 0x002323032, 0x084808404, 0x049616829, 0x083939013,
0x007333437, 0x0c7e3e427, 0x004202424, 0x084a0a424, 0x0cbc3c80b, 0x043535013, 0x00a02080a, 0x087838407,
0x0c9d1d819, 0x04c404c0c, 0x083838003, 0x08f838c0f, 0x0cec2cc0e, 0x00b33383b, 0x04a42480a, 0x087b3b437
);
const BLOCK_SIZE_SEED = 16;
const BLOCK_SIZE_SEED_INT = 4;
static function GetB0($A) {
return 0x000000ff & $A;
}
static function GetB1($A) {
return 0x000000ff & ( $A >> 8 );
}
static function GetB2($A) {
return 0x000000ff & ( $A >> 16 );
}
static function GetB3($A) {
return 0x000000ff & ( $A >> 24 );
}
static function Round(&$x, $i7, $i6, $i5, $i4, $i3, $i2, $i1, $i0, $key, $key_offset) {
$x[$i1] = ($x[$i1] + ((KISA_SEED_CBC::$F1[$x[$i0]] ^ $key[$key_offset + 0]) & 0x0ff)) & 0x0ff;
$x[$i3] = ($x[$i3] ^ ((KISA_SEED_CBC::$F0[$x[$i2]] + $key[$key_offset + 1]) & 0x0ff)) & 0x0ff;
$x[$i5] = ($x[$i5] + ((KISA_SEED_CBC::$F1[$x[$i4]] ^ $key[$key_offset + 2]) & 0x0ff)) & 0x0ff;
$x[$i7] = ($x[$i7] ^ ((KISA_SEED_CBC::$F0[$x[$i6]] + $key[$key_offset + 3]) & 0x0ff)) & 0x0ff;
}
static function SeedRound(&$T, &$LR, $L0, $L1, $R0, $R1, &$K, $K_offset) {
$T[0] = $LR[$R0] ^ $K[$K_offset + 0];
$T[1] = $LR[$R1] ^ $K[$K_offset + 1];
$T[1] ^= $T[0];
$T[1] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[1]) & 0x0ff] ^
KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[1]) & 0x0ff];
$T[0] = ($T[0] + $T[1]) & 0x0ffffffff;
$T[0] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[0]) & 0x0ff] ^
KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[0]) & 0x0ff];
$T[1] = ($T[1] + $T[0]) & 0x0ffffffff;
$T[1] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[1]) & 0x0ff] ^
KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[1]) & 0x0ff];
$T[0] = ($T[0] + $T[1]) & 0x0ffffffff;
$LR[$L0] ^= $T[0];
$LR[$L1] ^= $T[1];
}
static function EndianChange($dwS) {
return ((((($dwS) << (8)) | ((($dwS) >> (32 - (8))) & 0x000000ff)) & 0x00ff00ff) | (((($dwS) << (24)) | ((($dwS) >> (32 - (24))) & 0x00ffffff)) & 0xff00ff00) );
}
static $KC0 = 0x9e3779b9;
static $KC1 = 0x3c6ef373;
static $KC2 = 0x78dde6e6;
static $KC3 = 0xf1bbcdcc;
static $KC4 = 0xe3779b99;
static $KC5 = 0xc6ef3733;
static $KC6 = 0x8dde6e67;
static $KC7 = 0x1bbcdccf;
static $KC8 = 0x3779b99e;
static $KC9 = 0x6ef3733c;
static $KC10 = 0xdde6e678;
static $KC11 = 0xbbcdccf1;
static $KC12 = 0x779b99e3;
static $KC13 = 0xef3733c6;
static $KC14 = 0xde6e678d;
static $KC15 = 0xbcdccf1b;
static $ABCD_A = 0;
static $ABCD_B = 1;
static $ABCD_C = 2;
static $ABCD_D = 3;
static function RoundKeyUpdate0(&$T, &$K, $K_offset, &$ABCD, $KC) {
$T[0] = (($ABCD[KISA_SEED_CBC::$ABCD_A] & 0x0ffffffff) + ($ABCD[KISA_SEED_CBC::$ABCD_C] & 0x0ffffffff) - ($KC & 0x0ffffffff)) & 0x0ffffffff;
$T[1] = (($ABCD[KISA_SEED_CBC::$ABCD_B] & 0x0ffffffff) + ($KC & 0x0ffffffff) - ($ABCD[KISA_SEED_CBC::$ABCD_D] & 0x0ffffffff)) & 0x0ffffffff;
$K[$K_offset + 0] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[0]) & 0x0ff];
$K[$K_offset + 1] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[1]) & 0x0ff];
$T[0] = $ABCD[KISA_SEED_CBC::$ABCD_A];
$ABCD[KISA_SEED_CBC::$ABCD_A] = (($ABCD[KISA_SEED_CBC::$ABCD_A] >> 8) & 0x00ffffff) ^ ($ABCD[KISA_SEED_CBC::$ABCD_B] << 24);
$ABCD[KISA_SEED_CBC::$ABCD_B] = (($ABCD[KISA_SEED_CBC::$ABCD_B] >> 8) & 0x00ffffff) ^ ($T[0] << 24);
}
// 0xFFFFFFFF 를 & 연산 시키는 이유: 64bit OS에 설치된 PHP의 정수형 데이터 타입의 크기 차이로 인한 오버플로우 처리 오류
static function RoundKeyUpdate1(&$T, &$K, $K_offset, &$ABCD, $KC) {
$T[0] = (($ABCD[KISA_SEED_CBC::$ABCD_A] & 0xFFFFFFFF) + ($ABCD[KISA_SEED_CBC::$ABCD_C] & 0xFFFFFFFF) - ($KC & 0xFFFFFFFF)) & 0x0ffffffff;
$T[1] = (($ABCD[KISA_SEED_CBC::$ABCD_B] & 0xFFFFFFFF) + ($KC & 0xFFFFFFFF) - ($ABCD[KISA_SEED_CBC::$ABCD_D] & 0xFFFFFFFF)) & 0x0ffffffff;
$K[$K_offset + 0] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[0]) & 0x0ff];
$K[$K_offset + 1] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[1]) & 0x0ff];
$T[0] = $ABCD[KISA_SEED_CBC::$ABCD_C];
$ABCD[KISA_SEED_CBC::$ABCD_C] = (($ABCD[KISA_SEED_CBC::$ABCD_C] << 8) & 0xFFFFFFFF) ^ (($ABCD[KISA_SEED_CBC::$ABCD_D] >> 24) & 0x000000ff);
$ABCD[KISA_SEED_CBC::$ABCD_D] = (($ABCD[KISA_SEED_CBC::$ABCD_D] << 8) & 0xFFFFFFFF) ^ (($T[0] >> 24) & 0x000000ff);
}
static function BLOCK_XOR_CBC(&$OUT_VALUE, $OUT_VALUE_offset, &$IN_VALUE1, $IN_VALUE1_offset, &$IN_VALUE2, $IN_VALUE2_offset) {
$OUT_VALUE[$OUT_VALUE_offset + 0] = ($IN_VALUE1_offset < count($IN_VALUE1) ? $IN_VALUE1[$IN_VALUE1_offset + 0] : 0) ^ ($IN_VALUE2_offset < count($IN_VALUE2) ? $IN_VALUE2[$IN_VALUE2_offset + 0] : 0);
$OUT_VALUE[$OUT_VALUE_offset + 1] = ($IN_VALUE1_offset + 1 < count($IN_VALUE1) ? $IN_VALUE1[$IN_VALUE1_offset + 1] : 0) ^ ($IN_VALUE2_offset + 1 < count($IN_VALUE2) ? $IN_VALUE2[$IN_VALUE2_offset + 1] : 0);
$OUT_VALUE[$OUT_VALUE_offset + 2] = ($IN_VALUE1_offset + 2 < count($IN_VALUE1) ? $IN_VALUE1[$IN_VALUE1_offset + 2] : 0) ^ ($IN_VALUE2_offset + 2 < count($IN_VALUE2) ? $IN_VALUE2[$IN_VALUE2_offset + 2] : 0);
$OUT_VALUE[$OUT_VALUE_offset + 3] = ($IN_VALUE1_offset + 3 < count($IN_VALUE1) ? $IN_VALUE1[$IN_VALUE1_offset + 3] : 0) ^ ($IN_VALUE2_offset + 3 < count($IN_VALUE2) ? $IN_VALUE2[$IN_VALUE2_offset + 3] : 0);
}
static function KISA_SEED_Encrypt_Block_forCBC(&$in, $in_offset, &$out, $out_offset, &$ks) {
$LR = array_pad(array(), 4, 0); // Iuput/output values at each rounds
$T = array_pad(array(), 2, 0); // Temporary variables for round function F
$K = &$ks->key_data; // Pointer of round keys
$LR[LR_L0] = $in[$in_offset + 0];
$LR[LR_L1] = $in[$in_offset + 1];
$LR[LR_R0] = $in[$in_offset + 2];
$LR[LR_R1] = $in[$in_offset + 3];
if (_KISA_COMMON_IS_LITTLE_ENDIAN == false) {
$LR[LR_L0] = KISA_SEED_CBC::EndianChange($LR[LR_L0]);
$LR[LR_L1] = KISA_SEED_CBC::EndianChange($LR[LR_L1]);
$LR[LR_R0] = KISA_SEED_CBC::EndianChange($LR[LR_R0]);
$LR[LR_R1] = KISA_SEED_CBC::EndianChange($LR[LR_R1]);
}
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 0); // Round 1
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 2); // Round 2
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 4); // Round 3
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 6); // Round 4
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 8); // Round 5
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 10); // Round 6
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 12); // Round 7
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 14); // Round 8
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 16); // Round 9
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 18); // Round 10
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 20); // Round 11
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 22); // Round 12
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 24); // Round 13
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 26); // Round 14
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 28); // Round 15
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 30); // Round 16
if (_KISA_COMMON_IS_LITTLE_ENDIAN == false) {
$LR[LR_L0] = KISA_SEED_CBC::EndianChange($LR[LR_L0]);
$LR[LR_L1] = KISA_SEED_CBC::EndianChange($LR[LR_L1]);
$LR[LR_R0] = KISA_SEED_CBC::EndianChange($LR[LR_R0]);
$LR[LR_R1] = KISA_SEED_CBC::EndianChange($LR[LR_R1]);
}
$out[$out_offset + 0] = $LR[LR_R0];
$out[$out_offset + 1] = $LR[LR_R1];
$out[$out_offset + 2] = $LR[LR_L0];
$out[$out_offset + 3] = $LR[LR_L1];
}
static function KISA_SEED_Decrypt_Block_forCBC(&$in, $in_offset, &$out, $out_offset, &$ks) {
$LR = array_pad(array(), 4, 0); // Iuput/output values at each rounds
$T = array_pad(array(), 2, 0); // Temporary variables for round function F
$K = &$ks->key_data; // Pointer of round keys
$LR[LR_L0] = $in[$in_offset + 0];
$LR[LR_L1] = $in[$in_offset + 1];
$LR[LR_R0] = $in[$in_offset + 2];
$LR[LR_R1] = $in[$in_offset + 3];
if (_KISA_COMMON_IS_LITTLE_ENDIAN == false) {
$LR[LR_L0] = KISA_SEED_CBC::EndianChange($LR[LR_L0]);
$LR[LR_L1] = KISA_SEED_CBC::EndianChange($LR[LR_L1]);
$LR[LR_R0] = KISA_SEED_CBC::EndianChange($LR[LR_R0]);
$LR[LR_R1] = KISA_SEED_CBC::EndianChange($LR[LR_R1]);
}
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 30); // Round 1
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 28); // Round 2
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 26); // Round 3
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 24); // Round 4
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 22); // Round 5
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 20); // Round 6
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 18); // Round 7
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 16); // Round 8
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 14); // Round 9
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 12); // Round 10
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 10); // Round 11
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 8); // Round 12
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 6); // Round 13
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 4); // Round 14
KISA_SEED_CBC::SeedRound($T, $LR, LR_L0, LR_L1, LR_R0, LR_R1, $K, 2); // Round 15
KISA_SEED_CBC::SeedRound($T, $LR, LR_R0, LR_R1, LR_L0, LR_L1, $K, 0); // Round 16
if (_KISA_COMMON_IS_LITTLE_ENDIAN == false) {
$LR[LR_L0] = KISA_SEED_CBC::EndianChange($LR[LR_L0]);
$LR[LR_L1] = KISA_SEED_CBC::EndianChange($LR[LR_L1]);
$LR[LR_R0] = KISA_SEED_CBC::EndianChange($LR[LR_R0]);
$LR[LR_R1] = KISA_SEED_CBC::EndianChange($LR[LR_R1]);
}
$out[$out_offset + 0] = $LR[LR_R0];
$out[$out_offset + 1] = $LR[LR_R1];
$out[$out_offset + 2] = $LR[LR_L0];
$out[$out_offset + 3] = $LR[LR_L1];
}
static function chartoint32_for_SEED_CBC(&$in, $inLen) {
$data = null;
$len = 0;
$i = 0;
if ($inLen % 4 > 0)
$len = (0x0ff & ((int) ($inLen / 4))) + 1;
else
$len = (0x0ff & ((int) ($inLen / 4)));
$data = array_pad(array(), $len, 0);
for ($i = 0; $i < $len; $i++) {
Common::byte_to_int($data, $i, $in, $i * 4);
}
return $data;
}
static function int32tochar_for_SEED_CBC(&$in, $inLen) {
$data = null;
$i = 0;
$data = array_pad(array(), $inLen, 0);
if (_KISA_COMMON_IS_LITTLE_ENDIAN == false) {
for ($i = 0; $i < $inLen; $i++) {
$data[$i] = 0x0ff & ($in[(int) ($i / 4)] >> (($i % 4) * 8));
}
} else {
for ($i = 0; $i < $inLen; $i++) {
$data[$i] = 0x0ff & ($in[(int) ($i / 4)] >> ((3 - ($i % 4)) * 8));
}
}
return $data;
}
// 0xFFFFFFFF 를 & 연산 시키는 이유: 64bit OS에 설치된 PHP의 정수형 데이터 타입의 크기 차이로 인한 오버플로우 처리 오류
static function SEED_CBC_init(&$pInfo, $enc, &$pbszUserKey, &$pbszIV) {
$ABCD = array_pad(array(), 4, 0); // Iuput/output values at each rounds
$T = array_pad(array(), 2, 0); // Temporary variable
$K = null;
if (null == $pInfo ||
null == $pbszUserKey ||
null == $pbszIV)
return 0;
$K = &$pInfo->seed_key->key_data; // Pointer of round keys
$pInfo->encrypt = $enc;
Common::memcpy_byte2int($pInfo->ivec, $pbszIV, 16);
$pInfo->last_block_flag = $pInfo->buffer_length = 0;
$ABCD[KISA_SEED_CBC::$ABCD_A] = Common::get_byte_to_int($pbszUserKey, 0 * 4);
$ABCD[KISA_SEED_CBC::$ABCD_B] = Common::get_byte_to_int($pbszUserKey, 1 * 4);
$ABCD[KISA_SEED_CBC::$ABCD_C] = Common::get_byte_to_int($pbszUserKey, 2 * 4);
$ABCD[KISA_SEED_CBC::$ABCD_D] = Common::get_byte_to_int($pbszUserKey, 3 * 4);
if (_KISA_COMMON_IS_LITTLE_ENDIAN == false) {
$ABCD[KISA_SEED_CBC::$ABCD_A] = KISA_SEED_CBC::EndianChange($ABCD[KISA_SEED_CBC::$ABCD_A]);
$ABCD[KISA_SEED_CBC::$ABCD_B] = KISA_SEED_CBC::EndianChange($ABCD[KISA_SEED_CBC::$ABCD_B]);
$ABCD[KISA_SEED_CBC::$ABCD_C] = KISA_SEED_CBC::EndianChange($ABCD[KISA_SEED_CBC::$ABCD_C]);
$ABCD[KISA_SEED_CBC::$ABCD_D] = KISA_SEED_CBC::EndianChange($ABCD[KISA_SEED_CBC::$ABCD_D]);
}
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 0, $ABCD, KISA_SEED_CBC::$KC0); // K_1,0 and K_1,1
KISA_SEED_CBC::RoundKeyUpdate1($T, $K, 2, $ABCD, KISA_SEED_CBC::$KC1); // K_2,0 and K_2,1
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 4, $ABCD, KISA_SEED_CBC::$KC2); // K_3,0 and K_3,1
KISA_SEED_CBC::RoundKeyUpdate1($T, $K, 6, $ABCD, KISA_SEED_CBC::$KC3); // K_4,0 and K_4,1
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 8, $ABCD, KISA_SEED_CBC::$KC4); // K_5,0 and K_5,1
KISA_SEED_CBC::RoundKeyUpdate1($T, $K, 10, $ABCD, KISA_SEED_CBC::$KC5); // K_6,0 and K_6,1
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 12, $ABCD, KISA_SEED_CBC::$KC6); // K_7,0 and K_7,1
KISA_SEED_CBC::RoundKeyUpdate1($T, $K, 14, $ABCD, KISA_SEED_CBC::$KC7); // K_8,0 and K_8,1
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 16, $ABCD, KISA_SEED_CBC::$KC8); // K_9,0 and K_9,1
KISA_SEED_CBC::RoundKeyUpdate1($T, $K, 18, $ABCD, KISA_SEED_CBC::$KC9); // K_10,0 and K_10,1
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 20, $ABCD, KISA_SEED_CBC::$KC10); // K_11,0 and K_11,1
KISA_SEED_CBC::RoundKeyUpdate1($T, $K, 22, $ABCD, KISA_SEED_CBC::$KC11); // K_12,0 and K_12,1
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 24, $ABCD, KISA_SEED_CBC::$KC12); // K_13,0 and K_13,1
KISA_SEED_CBC::RoundKeyUpdate1($T, $K, 26, $ABCD, KISA_SEED_CBC::$KC13); // K_14,0 and K_14,1
KISA_SEED_CBC::RoundKeyUpdate0($T, $K, 28, $ABCD, KISA_SEED_CBC::$KC14); // K_15,0 and K_15,1
$T[0] = (($ABCD[KISA_SEED_CBC::$ABCD_A] & 0xFFFFFFFF) + ($ABCD[KISA_SEED_CBC::$ABCD_C] & 0xFFFFFFFF) - KISA_SEED_CBC::$KC15) & 0x0ffffffff;
$T[1] = (($ABCD[KISA_SEED_CBC::$ABCD_B] & 0xFFFFFFFF) - ($ABCD[KISA_SEED_CBC::$ABCD_D] & 0xFFFFFFFF) + KISA_SEED_CBC::$KC15) & 0x0ffffffff;
$K[30] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[0]) & 0x0ff] ^ // K_16,0
KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[0]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[0]) & 0x0ff];
$K[31] = KISA_SEED_CBC::$SS0[KISA_SEED_CBC::GetB0($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS1[KISA_SEED_CBC::GetB1($T[1]) & 0x0ff] ^ // K_16,1
KISA_SEED_CBC::$SS2[KISA_SEED_CBC::GetB2($T[1]) & 0x0ff] ^ KISA_SEED_CBC::$SS3[KISA_SEED_CBC::GetB3($T[1]) & 0x0ff];
return 1;
}
static function SEED_CBC_Process(&$pInfo, &$in, $inLen, &$out, &$outLen) {
$nCurrentCount = KISA_SEED_CBC::BLOCK_SIZE_SEED;
$pdwXOR = null;
$in_offset = 0;
$out_offset = 0;
$pdwXOR_offset = 0;
if (null == $pInfo ||
null == $in ||
null == $out ||
0 > $inLen)
return 0;
if (KISA_ENC_DEC::KISA_ENCRYPT == $pInfo->encrypt) {
$pdwXOR = &$pInfo->ivec;
$in_offset = 0;
$out_offset = 0;
$pdwXOR_offset = 0;
while ($nCurrentCount <= $inLen) {
KISA_SEED_CBC::BLOCK_XOR_CBC($out, $out_offset, $in, $in_offset, $pdwXOR, $pdwXOR_offset);
KISA_SEED_CBC::KISA_SEED_Encrypt_Block_forCBC($out, $out_offset, $out, $out_offset, $pInfo->seed_key);
$pdwXOR = &$out;
$pdwXOR_offset = $out_offset;
$nCurrentCount += KISA_SEED_CBC::BLOCK_SIZE_SEED;
$in_offset += KISA_SEED_CBC::BLOCK_SIZE_SEED_INT;
$out_offset += KISA_SEED_CBC::BLOCK_SIZE_SEED_INT;
}
$outLen = $nCurrentCount - KISA_SEED_CBC::BLOCK_SIZE_SEED;
$pInfo->buffer_length = $inLen - $outLen;
Common::memcpy_int2int($pInfo->ivec, $pdwXOR, $pdwXOR_offset, KISA_SEED_CBC::BLOCK_SIZE_SEED);
Common::arraycopy_system($in, $in_offset, $pInfo->cbc_buffer, 0, $pInfo->buffer_length);
} else {
$pdwXOR = $pInfo->ivec;
$in_offset = 0;
$out_offset = 0;
$pdwXOR_offset = 0;
while ($nCurrentCount <= $inLen) {
KISA_SEED_CBC::KISA_SEED_Decrypt_Block_forCBC($in, $in_offset, $out, $out_offset, $pInfo->seed_key);
KISA_SEED_CBC::BLOCK_XOR_CBC($out, $out_offset, $out, $out_offset, $pdwXOR, $pdwXOR_offset);
$pdwXOR = &$in;
$pdwXOR_offset = $in_offset;
$nCurrentCount += KISA_SEED_CBC::BLOCK_SIZE_SEED;
$in_offset += KISA_SEED_CBC::BLOCK_SIZE_SEED_INT;
$out_offset += KISA_SEED_CBC::BLOCK_SIZE_SEED_INT;
}
$outLen = $nCurrentCount - KISA_SEED_CBC::BLOCK_SIZE_SEED;
Common::memcpy_int2int($pInfo->ivec, $pdwXOR, $pdwXOR_offset, KISA_SEED_CBC::BLOCK_SIZE_SEED);
Common::memcpy_int2int($pInfo->cbc_last_block, $out, $out_offset - KISA_SEED_CBC::BLOCK_SIZE_SEED_INT, KISA_SEED_CBC::BLOCK_SIZE_SEED);
}
return 1;
}
static function SEED_CBC_Close(&$pInfo, &$out, $out_offset, &$outLen) {
$nPaddngLeng = null;
$i = null;
$outLen = 0;
if (null == $out)
return 0;
if (KISA_ENC_DEC::KISA_ENCRYPT == $pInfo->encrypt) {
$nPaddngLeng = KISA_SEED_CBC::BLOCK_SIZE_SEED - $pInfo->buffer_length;
for ($i = $pInfo->buffer_length; $i < KISA_SEED_CBC::BLOCK_SIZE_SEED; $i++) {
Common::set_byte_for_int($pInfo->cbc_buffer, $i, $nPaddngLeng);
}
KISA_SEED_CBC::BLOCK_XOR_CBC($pInfo->cbc_buffer, 0, $pInfo->cbc_buffer, 0, $pInfo->ivec, 0);
KISA_SEED_CBC::KISA_SEED_Encrypt_Block_forCBC($pInfo->cbc_buffer, 0, $out, $out_offset / 4, $pInfo->seed_key);
$outLen = KISA_SEED_CBC::BLOCK_SIZE_SEED;
} else {
$nPaddngLeng = Common::get_byte_for_int($pInfo->cbc_last_block, KISA_SEED_CBC::BLOCK_SIZE_SEED - 1);
if ($nPaddngLeng > 0 && $nPaddngLeng <= KISA_SEED_CBC::BLOCK_SIZE_SEED) {
for ($i = $nPaddngLeng; $i > 0; $i--) {
Common::set_byte_for_int($out, $out_offset - $i, 0);
}
$outLen = $nPaddngLeng;
} else {
return 0;
}
}
return 1;
}
static function SEED_CBC_Encrypt(&$pbszUserKey, &$pbszIV, &$message, $message_offset, $message_length) {
$info = new KISA_SEED_INFO();
$outbuf = null;
$data = null;
$cdata = null;
$outlen = 0;
$nRetOutLeng = 0;
$nPaddingLeng = 0;
$pbszPlainText = array_pad(array(), $message_length, 0);
Common::arraycopy_system($message, $message_offset, $pbszPlainText, 0, $message_length);
$nPlainTextLen = count($pbszPlainText);
$nPlainTextPadding = (KISA_SEED_CBC::BLOCK_SIZE_SEED - ($nPlainTextLen % KISA_SEED_CBC::BLOCK_SIZE_SEED));
$newpbszPlainText = array_pad(array(), $nPlainTextLen + $nPlainTextPadding, 0);
Common::arraycopy($newpbszPlainText, $pbszPlainText, $nPlainTextLen);
$pbszCipherText = array_pad(array(), count($newpbszPlainText), 0);
KISA_SEED_CBC::SEED_CBC_init($info, KISA_ENC_DEC::KISA_ENCRYPT, $pbszUserKey, $pbszIV);
$outlen = ( ((int) ($nPlainTextLen / 16)) + 1 ) * 4;
$outbuf = array_pad(array(), $outlen, 0);
$data = KISA_SEED_CBC::chartoint32_for_SEED_CBC($newpbszPlainText, $nPlainTextLen);
KISA_SEED_CBC::SEED_CBC_Process($info, $data, $nPlainTextLen, $outbuf, $nRetOutLeng);
KISA_SEED_CBC::SEED_CBC_Close($info, $outbuf, $nRetOutLeng, $nPaddingLeng);
$cdata = KISA_SEED_CBC::int32tochar_for_SEED_CBC($outbuf, $nRetOutLeng + $nPaddingLeng);
Common::arraycopy($pbszCipherText, $cdata, $nRetOutLeng + $nPaddingLeng);
$data = null;
$cdata = null;
$outbuf = null;
return $pbszCipherText;
}
static function SEED_CBC_Decrypt(&$pbszUserKey, &$pbszIV, &$message, $message_offset, $message_length) {
$info = new KISA_SEED_INFO();
$outbuf = null;
$data = null;
$cdata = null;
$outlen = 0;
$nRetOutLeng = 0;
$nPaddingLeng = 0;
$pbszCipherText = array_pad(array(), $message_length, 0);
Common::arraycopy_system($message, $message_offset, $pbszCipherText, 0, $message_length);
$nCipherTextLen = count($pbszCipherText);
$result = null;
if ($nCipherTextLen % KISA_SEED_CBC::BLOCK_SIZE_SEED) {
return $result;
}
$newpbszCipherText = array_pad(array(), $nCipherTextLen, 0);
Common::arraycopy($newpbszCipherText, $pbszCipherText, $nCipherTextLen);
$pbszPlainText = array_pad(array(), count($newpbszCipherText), 0);
$nCipherTextLen = count($newpbszCipherText);
KISA_SEED_CBC::SEED_CBC_init($info, KISA_ENC_DEC::KISA_DECRYPT, $pbszUserKey, $pbszIV);
$outlen = (($nCipherTextLen / 16)) * 4;
$outbuf = array_pad(array(), $outlen, 0);
$data = KISA_SEED_CBC::chartoint32_for_SEED_CBC($newpbszCipherText, $nCipherTextLen);
KISA_SEED_CBC::SEED_CBC_Process($info, $data, $nCipherTextLen, $outbuf, $nRetOutLeng);
if (KISA_SEED_CBC::SEED_CBC_Close($info, $outbuf, $nRetOutLeng, $nPaddingLeng)) {
$cdata = KISA_SEED_CBC::int32tochar_for_SEED_CBC($outbuf, $nRetOutLeng - $nPaddingLeng);
Common::arraycopy($pbszPlainText, $cdata, $nRetOutLeng - $nPaddingLeng);
$message_length = $nRetOutLeng - $nPaddingLeng;
if ($message_length < 0)
$message_length = 0;
$result = array_pad(array(), $message_length, 0);
Common::arraycopy_system($pbszPlainText, 0, $result, 0, $message_length);
}
$data = null;
$cdata = null;
$outbuf = null;
return $result;
}
}
?>
+4 -4
View File
@@ -38,8 +38,8 @@ $payReqMap = $_SESSION['lgd_certify'];//결제 요청시, Session에 저장했
</head>
<body onload="setLGDResult()">
<?php
$LGD_RESPCODE = isset($_POST['LGD_RESPCODE']) ? $_POST['LGD_RESPCODE'] : '';
$LGD_RESPMSG = isset($_POST['LGD_RESPMSG']) ? iconv("EUC-KR", "UTF-8", $_POST['LGD_RESPMSG']) : '';
$LGD_RESPCODE = isset($_POST['LGD_RESPCODE']) ? clean_xss_tags($_POST['LGD_RESPCODE']) : '';
$LGD_RESPMSG = isset($_POST['LGD_RESPMSG']) ? clean_xss_tags(iconv("EUC-KR", "UTF-8", $_POST['LGD_RESPMSG'])) : '';
$LGD_AUTHONLYKEY = "";
$LGD_PAYTYPE = "";
@@ -47,8 +47,8 @@ $payReqMap = $_SESSION['lgd_certify'];//결제 요청시, Session에 저장했
$payReqMap['LGD_RESPMSG'] = $LGD_RESPMSG;
if($LGD_RESPCODE == "0000"){
$payReqMap['LGD_AUTHONLYKEY'] = isset($_POST['LGD_AUTHONLYKEY']) ? $_POST['LGD_AUTHONLYKEY'] : '';
$payReqMap['LGD_PAYTYPE'] = isset($_POST['LGD_PAYTYPE']) ? $_POST['LGD_PAYTYPE'] : '';
$payReqMap['LGD_AUTHONLYKEY'] = isset($_POST['LGD_AUTHONLYKEY']) ? clean_xss_tags($_POST['LGD_AUTHONLYKEY']) : '';
$payReqMap['LGD_PAYTYPE'] = isset($_POST['LGD_PAYTYPE']) ? clean_xss_tags($_POST['LGD_PAYTYPE']) : '';
}
else{
echo "LGD_RESPCODE:" . $LGD_RESPCODE . " ,LGD_RESPMSG:" . $LGD_RESPMSG; //인증 실패에 대한 처리 로직 추가
+9 -3
View File
@@ -25,13 +25,19 @@ $bo_v_sns_class = $config['cf_kakao_js_apikey'] ? 'show_kakao' : '';
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="//developers.kakao.com/sdk/js/kakao.min.js" async charset="utf-8"></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js" charset="utf-8"></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>" charset="utf-8"></script>
<script type='text/javascript'>
//<![CDATA[
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
function Kakao_sendLink() {
if (window.Kakao && (kakao_javascript_apikey !== undefined)) {
if (! Kakao.isInitialized()) {
Kakao.init(kakao_javascript_apikey);
}
}
var webUrl = location.protocol+"<?php echo '//'.$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']; ?>",
imageUrl = $("#bo_v_img").find("img").attr("src") || $(".view_image").find("img").attr("src") || '';
+3 -2
View File
@@ -20,8 +20,8 @@ class OAuth1Client{
public $redirect_uri = "";
public $decode_json = true;
public $curl_time_out = 30;
public $curl_connect_time_out = 30;
public $curl_time_out = 10;
public $curl_connect_time_out = 15;
public $curl_ssl_verifypeer = false;
public $curl_auth_header = true;
public $curl_useragent = "OAuth/1 Simple PHP Client v0.1; HybridAuth http://hybridauth.sourceforge.net/";
@@ -194,6 +194,7 @@ class OAuth1Client{
curl_setopt( $ci, CURLOPT_USERAGENT , $this->curl_useragent );
curl_setopt( $ci, CURLOPT_CONNECTTIMEOUT, $this->curl_connect_time_out );
curl_setopt( $ci, CURLOPT_TIMEOUT , $this->curl_time_out );
curl_setopt( $ci, CURLOPT_MAXREDIRS , 10);
curl_setopt( $ci, CURLOPT_RETURNTRANSFER, true );
curl_setopt( $ci, CURLOPT_HTTPHEADER , array('Expect:') );
curl_setopt( $ci, CURLOPT_SSL_VERIFYPEER, $this->curl_ssl_verifypeer );
+3 -2
View File
@@ -26,8 +26,8 @@ class OAuth2Client
//--
public $sign_token_name = "access_token";
public $curl_time_out = 30;
public $curl_connect_time_out = 30;
public $curl_time_out = 10;
public $curl_connect_time_out = 15;
public $curl_ssl_verifypeer = false;
public $curl_ssl_verifyhost = false;
public $curl_header = array();
@@ -221,6 +221,7 @@ class OAuth2Client
curl_setopt($ch, CURLOPT_TIMEOUT , $this->curl_time_out );
curl_setopt($ch, CURLOPT_USERAGENT , $this->curl_useragent );
curl_setopt($ch, CURLOPT_CONNECTTIMEOUT , $this->curl_connect_time_out );
curl_setopt($ch, CURLOPT_MAXREDIRS , 10);
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER , $this->curl_ssl_verifypeer );
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST , $this->curl_ssl_verifyhost );
curl_setopt($ch, CURLOPT_HTTPHEADER , $this->curl_header );
+1 -1
View File
@@ -50,7 +50,7 @@ else
$order_by = 'b.it_order, b.it_id desc';
if ($skin) {
$skin = preg_replace('#\.+(\/|\\\)#', '', $skin);
$skin = preg_replace(array('#\.+(\/|\\\)#', '#[\'\"]#'), array('', ''), $skin);
$ev['ev_skin'] = $skin;
}
+2
View File
@@ -20,6 +20,8 @@ if( isset($row['it_seo_title']) && ! $row['it_seo_title'] ){
shop_seo_title_update($row['it_id']);
}
if (function_exists('check_case_exist_title')) check_case_exist_title($it, G5_SHOP_DIR, true);
if (!($it['ca_use'] && $it['it_use'])) {
if (!$is_admin)
alert('현재 판매가능한 상품이 아닙니다.');
+7
View File
@@ -60,6 +60,13 @@ else if ($w == "u")
$row = sql_fetch($sql);
if (!$row['cnt'])
alert("자신의 상품문의만 수정하실 수 있습니다.");
$sql = " select iq_answer from `{$g5['g5_shop_item_qa_table']}` where mb_id = '{$member['mb_id']}' and iq_id = '$iq_id' ";
$row = sql_fetch($sql);
if (isset($row['iq_answer']) && $row['iq_answer']) {
alert("답변이 있는 상품문의는 수정하실 수 없습니다.");
}
}
$sql = " update {$g5['g5_shop_item_qa_table']}
+1 -1
View File
@@ -12,7 +12,7 @@ $is_content = preg_replace('#<script(.*?)>(.*?)</script>#is', '', $is_content);
$is_name = isset($_POST['is_name']) ? trim($_POST['is_name']) : '';
$is_password = isset($_POST['is_password']) ? trim($_POST['is_password']) : '';
$is_score = isset($_POST['is_score']) ? (int) $_POST['is_score'] : 0;
$is_score = ($is_score > 5) ? 0 : $is_score;
$is_score = ($is_score > 5 || $is_score < 1) ? 1 : $is_score;
$get_editor_img_mode = $config['cf_editor'] ? false : true;
$is_id = isset($_REQUEST['is_id']) ? (int) $_REQUEST['is_id'] : 0;
$is_mobile_shop = isset($_REQUEST['is_mobile_shop']) ? (int) $_REQUEST['is_mobile_shop'] : 0;
+1 -1
View File
@@ -42,7 +42,7 @@ function escrow_foot_check()
var newForm = jQuery("<form>", {
"id": "nhnkcp_escrow_form_popup",
"action": "http://admin.kcp.co.kr/Modules/escrow/kcp_pop.jsp?site_cd=SR001",
"action": "http://admin.kcp.co.kr/Modules/escrow/kcp_pop.jsp?site_cd="+jQuery("#sod_frm_escrow .nhnkcp_escrow_popup").attr("data-sitecd"),
"target": "escrow_foot_pop",
"method": "post"
}).append(jQuery("<input>", {
+16 -1
View File
@@ -146,7 +146,22 @@ if ( $req_tx == "pay" )
{
/* 1004원은 실제로 업체에서 결제하셔야 될 원 금액을 넣어주셔야 합니다. 결제금액 유효성 검증 */
$c_PayPlus->mf_set_ordr_data( "ordr_mony", $good_mny );
$kcp_pay_type = ''; // 결제수단 검증 파라미터 pay_type (신용카드 : PACA, 계좌이체 : PABK, 가상계좌 : PAVC, 휴대폰 : PAMC)
if ($use_pay_method == "100000000000" && (in_array($od_settle_case, array('신용카드', '간편결제')))) { // 신용카드
$kcp_pay_type = 'PACA';
} else if ($use_pay_method == "010000000000" && $od_settle_case === '계좌이체') { // 계좌이체
$kcp_pay_type = 'PABK';
} else if ($use_pay_method == "001000000000" && $od_settle_case === '가상계좌') { // 가상계좌
$kcp_pay_type = 'PAVC';
} else if ($use_pay_method == "000010000000" && $od_settle_case === '휴대폰') { // 휴대폰
$kcp_pay_type = 'PAMC';
}
$c_PayPlus->mf_set_ordr_data( "pay_type", $kcp_pay_type );
$c_PayPlus->mf_set_ordr_data( "ordr_no", $ordr_idxx );
$post_enc_data = isset($_POST['enc_data']) ? $_POST['enc_data'] : '';
$post_enc_info = isset($_POST['enc_info']) ? $_POST['enc_info'] : '';
+6 -1
View File
@@ -308,6 +308,11 @@ $order_price = $tot_od_price + $send_cost + $send_cost2 - $tot_sc_cp_price - $od
$od_status = '주문';
$od_tno = '';
if (function_exists('check_payment_method')) {
check_payment_method($od_settle_case);
}
if ($od_settle_case == "무통장")
{
$od_receipt_point = $i_temp_point;
@@ -780,7 +785,7 @@ if($config['cf_sms_use'] && ($default['de_sms_use2'] || $default['de_sms_use3'])
$sms_content = str_replace("{보낸분}", $od_name, $sms_content);
$sms_content = str_replace("{받는분}", $od_b_name, $sms_content);
$sms_content = str_replace("{주문번호}", $od_id, $sms_content);
$sms_content = str_replace("{주문금액}", number_format($tot_ct_price + $od_send_cost + $od_send_cost2), $sms_content);
$sms_content = str_replace("{주문금액}", number_format($tot_ct_price + $od_send_cost + (int) $od_send_cost2), $sms_content);
$sms_content = str_replace("{회원아이디}", $member['mb_id'], $sms_content);
$sms_content = str_replace("{회사명}", $default['de_admin_company_name'], $sms_content);
@@ -8,11 +8,10 @@ add_javascript('<script src="'.G5_JS_URL.'/jquery.bxslider.js"></script>', 10);
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<form name="fitem" action="<?php echo $action_url; ?>" method="post" onsubmit="return fitem_submit(this);">
@@ -10,11 +10,10 @@ add_javascript('<script src="'.G5_THEME_JS_URL.'/theme.shop.list.js"></script>',
<?php if(!defined('G5_IS_SHOP_AJAX_LIST') && $config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 메인상품진열 10 시작 { -->
@@ -10,11 +10,10 @@ add_javascript('<script src="'.G5_THEME_JS_URL.'/theme.shop.list.js"></script>',
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 메인상품진열 10 시작 { -->
@@ -11,11 +11,10 @@ add_javascript('<script src="'.G5_THEME_JS_URL.'/theme.shop.list.js"></script>',
<script src="<?php echo G5_JS_URL ?>/jquery.fancylist.js"></script>
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 메인상품진열 20 시작 { -->
@@ -11,11 +11,10 @@ add_javascript('<script src="'.G5_THEME_JS_URL.'/theme.shop.list.js"></script>',
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<div class="st_30_wr">
<!-- 메인상품진열 30 시작 { -->
@@ -8,11 +8,10 @@ add_stylesheet('<link rel="stylesheet" href="'.G5_MSHOP_SKIN_URL.'/style.css">',
<script src="<?php echo G5_JS_URL ?>/jquery.fancylist.js"></script>
<?php if($config['cf_kakao_js_apikey']) { ?>
<script src="https://developers.kakao.com/sdk/js/kakao.min.js" async></script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js"></script>
<script>
// 사용할 앱의 Javascript 키를 설정해 주세요.
Kakao.init("<?php echo $config['cf_kakao_js_apikey']; ?>");
var kakao_javascript_apikey = "<?php echo $config['cf_kakao_js_apikey']; ?>";
</script>
<script src="<?php echo G5_JS_URL; ?>/kakaolink.js?ver=<?php echo G5_JS_VER; ?>"></script>
<?php } ?>
<!-- 상품진열 10 시작 { -->
+1 -1
View File
@@ -39,7 +39,7 @@ add_stylesheet('<link rel="stylesheet" href="'.$member_skin_url.'/style.css">',
</div>
<?php // 쇼핑몰 사용시 여기부터 ?>
<?php if ($default['de_level_sell'] == 1) { // 상품구입 권한 ?>
<?php if (isset($default['de_level_sell']) && $default['de_level_sell'] == 1) { // 상품구입 권한 ?>
<!-- 주문하기, 신청하기 -->
<?php if (preg_match("/orderform.php/", $url)) { ?>
+1 -1
View File
@@ -2,7 +2,7 @@
if (!defined('_GNUBOARD_')) exit; // 개별 페이지 접근 불가
define('G5_VERSION', '그누보드5');
define('G5_GNUBOARD_VER', '5.5.8.3.3');
define('G5_GNUBOARD_VER', '5.5.17');
// 그누보드5.4.5.5 버전과 영카트5.4.5.5.1 버전을 합쳐서 그누보드5.4.6 버전에서 시작함 (kagla-210617)
// G5_YOUNGCART_VER 이 상수를 사용하는 곳이 있으므로 주석 처리 해제함
// 그누보드5.4.6 이상 버전 부터는 영카트를 그누보드에 포함하여 배포하므로 영카트5의 버전은 의미가 없습니다.