From bab7fa1f394b614c29ff9c92649e8eeb80775dee Mon Sep 17 00:00:00 2001 From: thisgun Date: Thu, 6 Jul 2017 09:22:24 +0900 Subject: [PATCH 01/20] =?UTF-8?q?=EC=9D=B8=EC=8A=A4=ED=86=A8=EC=8B=9C=20?= =?UTF-8?q?=ED=95=84=ED=84=B0=EB=A7=81=20=EB=8B=A8=EC=96=B4=20=EC=88=98?= =?UTF-8?q?=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- install/install_db.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/install/install_db.php b/install/install_db.php index a6eed0e30..e436263e1 100644 --- a/install/install_db.php +++ b/install/install_db.php @@ -120,7 +120,7 @@ $sql = " insert into `{$table_prefix}config` cf_mobile_pages = '5', cf_link_target = '_blank', cf_delay_sec = '30', - cf_filter = '18아,18놈,18새끼,18년,18뇬,18노,18것,18넘,개년,개놈,개뇬,개새,개색끼,개세끼,개세이,개쉐이,개쉑,개쉽,개시키,개자식,개좆,게색기,게색끼,광뇬,뇬,눈깔,뉘미럴,니귀미,니기미,니미,도촬,되질래,뒈져라,뒈진다,디져라,디진다,디질래,병쉰,병신,뻐큐,뻑큐,뽁큐,삐리넷,새꺄,쉬발,쉬밸,쉬팔,쉽알,스패킹,스팽,시벌,시부랄,시부럴,시부리,시불,시브랄,시팍,시팔,시펄,실밸,십8,십쌔,십창,싶알,쌉년,썅놈,쌔끼,쌩쑈,썅,써벌,썩을년,쎄꺄,쎄엑,쓰바,쓰발,쓰벌,쓰팔,씨8,씨댕,씨바,씨발,씨뱅,씨봉알,씨부랄,씨부럴,씨부렁,씨부리,씨불,씨브랄,씨빠,씨빨,씨뽀랄,씨팍,씨팔,씨펄,씹,아가리,아갈이,엄창,접년,잡놈,재랄,저주글,조까,조빠,조쟁이,조지냐,조진다,조질래,존나,존니,좀물,좁년,좃,좆,좇,쥐랄,쥐롤,쥬디,지랄,지럴,지롤,지미랄,쫍빱,凸,퍽큐,뻑큐,빠큐,ㅅㅂㄹㅁ', + cf_filter = '18아,18놈,18새끼,18뇬,18노,18것,18넘,개년,개놈,개뇬,개새,개색끼,개세끼,개세이,개쉐이,개쉑,개쉽,개시키,개자식,개좆,게색기,게색끼,광뇬,뇬,눈깔,뉘미럴,니귀미,니기미,니미,도촬,되질래,뒈져라,뒈진다,디져라,디진다,디질래,병쉰,병신,뻐큐,뻑큐,뽁큐,삐리넷,새꺄,쉬발,쉬밸,쉬팔,쉽알,스패킹,스팽,시벌,시부랄,시부럴,시부리,시불,시브랄,시팍,시팔,시펄,실밸,십8,십쌔,십창,싶알,쌉년,썅놈,쌔끼,쌩쑈,썅,써벌,썩을년,쎄꺄,쎄엑,쓰바,쓰발,쓰벌,쓰팔,씨8,씨댕,씨바,씨발,씨뱅,씨봉알,씨부랄,씨부럴,씨부렁,씨부리,씨불,씨브랄,씨빠,씨빨,씨뽀랄,씨팍,씨팔,씨펄,씹,아가리,아갈이,엄창,접년,잡놈,재랄,저주글,조까,조빠,조쟁이,조지냐,조진다,조질래,존나,존니,좀물,좁년,좃,좆,좇,쥐랄,쥐롤,쥬디,지랄,지럴,지롤,지미랄,쫍빱,凸,퍽큐,뻑큐,빠큐,ㅅㅂㄹㅁ', cf_possible_ip = '', cf_intercept_ip = '', cf_analytics = '', From 3000fc0b35980f185fe0ecbde926e605a07d30af Mon Sep 17 00:00:00 2001 From: thisgun Date: Thu, 6 Jul 2017 10:27:45 +0900 Subject: [PATCH 02/20] =?UTF-8?q?include=20path=20=EC=B2=B4=ED=81=AC?= =?UTF-8?q?=ED=95=A8=EC=88=98=20=EC=88=98=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- lib/common.lib.php | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/lib/common.lib.php b/lib/common.lib.php index fade7b145..2062c4d05 100644 --- a/lib/common.lib.php +++ b/lib/common.lib.php @@ -3320,11 +3320,12 @@ function is_include_path_check($path='') //echo 'Caught exception: ', $e->getMessage(), "\n"; return false; } + + if( preg_match('/\/data\/(file|editor)\/[A-Za-z0-9_]{1,20}\//', $path) ){ + return false; + } } - if( !$path || preg_match('/\/data\/(file|editor)\/[A-Za-z0-9_]{1,20}\//', $path) ){ - return false; - } return true; } ?> \ No newline at end of file From ee9f85628dc5b4af297fa78de9662010fd81430a Mon Sep 17 00:00:00 2001 From: thisgun Date: Thu, 6 Jul 2017 11:00:20 +0900 Subject: [PATCH 03/20] =?UTF-8?q?=EB=AA=A8=EB=B0=94=EC=9D=BC=20=EB=8C=93?= =?UTF-8?q?=EA=B8=80=20https=20=EB=AF=B8=EC=B2=98=EB=A6=AC=20=EC=88=98?= =?UTF-8?q?=EC=A0=95?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- mobile/skin/board/basic/view_comment.skin.php | 2 +- mobile/skin/board/gallery/view_comment.skin.php | 2 +- theme/basic/mobile/skin/board/basic/view_comment.skin.php | 2 +- theme/basic/mobile/skin/board/gallery/view_comment.skin.php | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/mobile/skin/board/basic/view_comment.skin.php b/mobile/skin/board/basic/view_comment.skin.php index ce49cf92a..6a60539e4 100644 --- a/mobile/skin/board/basic/view_comment.skin.php +++ b/mobile/skin/board/basic/view_comment.skin.php @@ -83,7 +83,7 @@ var char_max = parseInt(); // 최대 ?>