diff options
| author | Cassio de Campos <cassiopc@gmail.com> | 2017-08-12 18:09:34 +0000 |
|---|---|---|
| committer | Cassio de Campos <cassiopc@gmail.com> | 2017-08-12 18:09:34 +0000 |
| commit | 3dd230e00ab5638d57a6072260d1a1dc745e8ad0 (patch) | |
| tree | cf3ff88fc89d5d990baed7dbf79ac5bfab123c92 /src/logexternal.php | |
| parent | 1a7aa506cf7c239890fab96fd024640b1b712eb8 (diff) | |
| download | boca-3dd230e00ab5638d57a6072260d1a1dc745e8ad0.tar.gz boca-3dd230e00ab5638d57a6072260d1a1dc745e8ad0.zip | |
change of name
Diffstat (limited to 'src/logexternal.php')
| -rw-r--r-- | src/logexternal.php | 56 |
1 files changed, 56 insertions, 0 deletions
diff --git a/src/logexternal.php b/src/logexternal.php new file mode 100644 index 0000000..7d95800 --- /dev/null +++ b/src/logexternal.php @@ -0,0 +1,56 @@ +<?php +ob_start(); +header ("Expires: " . gmdate("D, d M Y H:i:s") . " GMT"); +header ("Last-Modified: " . gmdate("D, d M Y H:i:s") . " GMT"); +header ("Cache-Control: no-cache, must-revalidate"); +header ("Pragma: no-cache"); +header ("Content-Type: text/html; charset=utf-8"); +session_start(); +if (!isset($_POST["comp"])) { + session_unset(); + session_destroy(); + session_start(); + echo session_id(); + exit; +} +ob_end_flush(); + +function sanitizeFilename($text) +{ + $text = str_replace("*", "", $text); + $text = str_replace("$", "", $text); + $text = str_replace(")", "", $text); + $text = str_replace("(", "", $text); + $text = str_replace(";", "", $text); + $text = str_replace("&", "", $text); + $text = str_replace("<", "", $text); + $text = str_replace(">", "", $text); + $text = str_replace("\"", "", $text); + $text = str_replace("'", "", $text); + $text = str_replace("`", "", $text); + $text = addslashes($text); + return $text; +} + +function myhash($k) { + return hash('sha256',$k); +} + +if(isset($_POST["comp"]) && $_POST["comp"] != "" ) { + $name = sanitizeFilename($_POST["comp"]); + $password = $_POST["code"]; + $secrets = file("/var/www/boca/src/private/run-past.config"); + for($i = 0; $i < count($secrets); $i++) { + $secret = explode(' ', $secrets[$i]); + $p = myhash($secret[2] . session_id()); + if($p == $password) { + @file_put_contents("/var/www/boca/src/private/logexternal/" . $secret[0] . '.' . $name, base64_decode($_POST['data']), LOCK_EX | FILE_APPEND); + @file_put_contents("/var/www/boca/src/private/logexternal/logexternal.log", $name . "|" . $secret[0] . '|' . date(DATE_RFC2822) . "\n", LOCK_EX | FILE_APPEND); + echo "ok\n"; + exit; + } + } +} +echo "incorrect\n"; +exit; +?> |