Subversion Repositories cheapmusic

Rev

Rev 153 | Details | Compare with Previous | Last modification | View Log | RSS feed

Rev Author Line No. Line
28 - 1
<?php
121 - 2
include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/hosting.php');
28 - 3
 
4
if (isset($_POST["target"])) {
77 - 5
    include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/constants.php');
65 - 6
    include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/sessions_db.php');
7
    include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/cryptor.php');
122 - 8
    include_once ("php/NonceUtil.php");
28 - 9
 
153 - 10
    $configFile = parse_ini_file(FCM_CONFIGFILE, true);
28 - 11
    $crypt = Cryptor::getInstance($configFile['cryptor']);
12
    $tmpSessionTab = (isset($_POST["sessionTab"]) && $_POST["sessionTab"] > 0 ? $_POST["sessionTab"] : null);
13
    $handler = MySessionHandler::getInstance($tmpSessionTab, $configFile['mysqli']);
122 - 14
    $systemConf = $configFile['system'];
28 - 15
    unset($configFile);
16
 
120 - 17
    session_set_cookie_params(604800, '/', '.findcheapmusic.com', true, true);
28 - 18
    session_set_save_handler($handler, true);
32 - 19
    if (!empty($_COOKIE['PHPSESSID'])) {
20
        session_id($_COOKIE['PHPSESSID']);
21
    }
28 - 22
    @session_start();
23
 
122 - 24
    if (empty($_POST["nonce"]) || NonceUtil::check($systemConf["nonce_secret"], $_POST["nonce"]) === false) {
25
        exit;
26
    }
27
 
28 - 28
    $_sess_db = MySessionHandler::getDBSessionId();
29
 
30
    $access = mysqli_real_escape_string($_sess_db, time());
31
    $url = mysqli_real_escape_string($_sess_db, base64_decode($_POST["target"]));
154 - 32
    $userId = (empty($_SESSION['sessData']['userID']) ? null : $_SESSION['sessData']['userID']);
96 - 33
    $ip = inet_pton($_SERVER['REMOTE_ADDR']);
154 - 34
    $sessionId = session_id();
28 - 35
 
36
    $sql = "INSERT
37
            INTO transfers
96 - 38
            (sessId, access, ip, url, userId)
154 - 39
            VALUES  (?, ?, ?, ?, ?)";
40
    $stmt = mysqli_prepare($_sess_db, $sql);
41
    mysqli_stmt_bind_param($stmt, 'sdssd', $sessionId, $access, $ip, $url, $userId);
28 - 42
 
154 - 43
    if (!mysqli_stmt_execute($stmt)) {
28 - 44
        error_log("Error: " . $sql . " | " . mysqli_error($_sess_db));
45
    }
154 - 46
 
47
    mysqli_stmt_close($stmt);
28 - 48
}
49
 
65 - 50
exit;