28 |
- |
1 |
<?php
|
121 |
- |
2 |
include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/hosting.php');
|
28 |
- |
3 |
|
|
|
4 |
if (isset($_POST["target"])) {
|
77 |
- |
5 |
include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/constants.php');
|
65 |
- |
6 |
include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/sessions_db.php');
|
|
|
7 |
include_once ($_SERVER['DOCUMENT_ROOT'] . '/php/cryptor.php');
|
122 |
- |
8 |
include_once ("php/NonceUtil.php");
|
28 |
- |
9 |
|
153 |
- |
10 |
$configFile = parse_ini_file(FCM_CONFIGFILE, true);
|
28 |
- |
11 |
$crypt = Cryptor::getInstance($configFile['cryptor']);
|
|
|
12 |
$tmpSessionTab = (isset($_POST["sessionTab"]) && $_POST["sessionTab"] > 0 ? $_POST["sessionTab"] : null);
|
|
|
13 |
$handler = MySessionHandler::getInstance($tmpSessionTab, $configFile['mysqli']);
|
122 |
- |
14 |
$systemConf = $configFile['system'];
|
28 |
- |
15 |
unset($configFile);
|
|
|
16 |
|
120 |
- |
17 |
session_set_cookie_params(604800, '/', '.findcheapmusic.com', true, true);
|
28 |
- |
18 |
session_set_save_handler($handler, true);
|
32 |
- |
19 |
if (!empty($_COOKIE['PHPSESSID'])) {
|
|
|
20 |
session_id($_COOKIE['PHPSESSID']);
|
|
|
21 |
}
|
28 |
- |
22 |
@session_start();
|
|
|
23 |
|
122 |
- |
24 |
if (empty($_POST["nonce"]) || NonceUtil::check($systemConf["nonce_secret"], $_POST["nonce"]) === false) {
|
|
|
25 |
exit;
|
|
|
26 |
}
|
|
|
27 |
|
28 |
- |
28 |
$_sess_db = MySessionHandler::getDBSessionId();
|
|
|
29 |
|
|
|
30 |
$access = mysqli_real_escape_string($_sess_db, time());
|
|
|
31 |
$url = mysqli_real_escape_string($_sess_db, base64_decode($_POST["target"]));
|
154 |
- |
32 |
$userId = (empty($_SESSION['sessData']['userID']) ? null : $_SESSION['sessData']['userID']);
|
96 |
- |
33 |
$ip = inet_pton($_SERVER['REMOTE_ADDR']);
|
154 |
- |
34 |
$sessionId = session_id();
|
28 |
- |
35 |
|
|
|
36 |
$sql = "INSERT
|
|
|
37 |
INTO transfers
|
96 |
- |
38 |
(sessId, access, ip, url, userId)
|
154 |
- |
39 |
VALUES (?, ?, ?, ?, ?)";
|
|
|
40 |
$stmt = mysqli_prepare($_sess_db, $sql);
|
|
|
41 |
mysqli_stmt_bind_param($stmt, 'sdssd', $sessionId, $access, $ip, $url, $userId);
|
28 |
- |
42 |
|
154 |
- |
43 |
if (!mysqli_stmt_execute($stmt)) {
|
28 |
- |
44 |
error_log("Error: " . $sql . " | " . mysqli_error($_sess_db));
|
|
|
45 |
}
|
154 |
- |
46 |
|
|
|
47 |
mysqli_stmt_close($stmt);
|
28 |
- |
48 |
}
|
|
|
49 |
|
65 |
- |
50 |
exit;
|