what do you think uses something
) wait to see Wapmaster who know

include("config.php"); include("core.php"); $bcon = connectdb(); if (!$bcon){
function crk($l){ global $CURUSER; write_log("Hacking Attempt! User:" . $CURUSER['username'] . " IP:".$_SERVER['REMOTE_ADDR']." - Attempt: ".$l, "delete"); header("Location: /index.php"); exit(); }
$ban2 = array( "delete from", "ibwf_users", "<script", "<object", ".write", ".location", ".cookie", ".open", "vbscript:", "<iframe", "<layer", "<style", ":expression", "<base", "id_level", "users_level", "xbt_", "c99.txt", "c99shell", "r57.txt", "r57shell.txt", "/home/", "/var/", "/www/", "/etc/", "/bin", "/sbin/", "\$_GET", "\$_POST", "\$_REQUEST", "window.open", "javascript:", "xp_cmdshell", ".htpasswd", ".htaccess", "<?php", "<?", "?>", "</script>" );
$cepl = $_SERVER['QUERY_STRING'];
if (!empty($cepl)) $cepl = strtolower(urldecode(preg_replace('/([\x00-\x08][\x0b-\x0c][\x0e-\x20])/', '', $cepl)));
$ban = array(); $ban["union"] = "select"; $ban["update"] = "set"; $ban["drop"] = "table"; $ban["alter"] = "table"; $ban["truncate"] = "table"; $ban["drop"] = "database"; $ban["create"] = "table"; $ban["set password for"] = "@";
foreach ($ban as $k => $l) if (str_replace($k, '', $cepl) != $cepl && str_replace($l,'',cepl) != $cepl) crk($cepl); if (str_replace($ban2, '', $cepl) != $cepl) crk($cepl);
$cepl = implode(" ", $_REQUEST); if (!empty($cepl)) $cepl = strtolower(urldecode(preg_replace('/([\x00-\x08][\x0b-\x0c][\x0e-\x20])/', '', $cepl)));
foreach ($ban as $k => $l) if (str_replace($k, '', $cepl) != $cepl && str_replace($l, '', $cepl) != $cepl) crk($cepl);
if (str_replace($ban2, '', $cepl) != $cepl) crk($cepl);
$cepl = implode(" ", $_COOKIE);
if (!empty($cepl)) $cepl = strtolower(urldecode(preg_replace('/([\x00-\x08][\x0b-\x0c][\x0e-\x20])/', '', $cepl)));
foreach ($ban as $k => $l) if(str_replace($k, '', $cepl) != $cepl && str_replace($l, '',$cepl) != $cepl) crk($cepl);
if(str_replace($ban2, '', $cepl) !=$cepl) crk($cepl);
Comment