聽
鍘熺悊,鎺ㄥ箍鑰呴€氳繃璁哄潧鑷姩鐢熸垚鐨勫睘浜庤嚜宸辯殑鎺ㄥ箍閾炬帴,鍒嗗彂鍑哄幓鍚?鍏跺畠浜洪€氳繃璇ラ摼鎺ヨ闂?骞垮憡鑱旂洘渚垮彲璁闆綍鎺ㄥ箍鑰呭苟缁欎簣濂栧姳.
娑夊強涓変釜鏂囦歡.cf_conn.php鍙奵f_reg.php,涓轟簡璁╂帹骞塊摼鎺ョ獥鍙e湪甯栧瓙涓樉绀?闇€瑕佷慨鏀筪efault杩欎釜榛樿妯℃澘.濡傛灉鐢ㄧ殑鏄涓夋柟妯℃澘,闇€瑕佽嚜宸卞搴旀ā鏉?\template\default\forum\viewthread_node_body.htm聽
cf_conn.php鐨勫唴瀹逛負
聽
<?php
/*閰嶇疆濂戒笅闈㈢殑鍙傛暟*/
//edusoho鐨凪ysql鏁版嵁搴揑P鍦闆潃鎴栦富鏈哄悕
$dbhost="localhost";
//edusoho鐨凪ysql鏁版嵁搴撹繛鎺ョ敤鎴峰悕
$dbuser="root";
//edusoho鐨凪ysql鏁版嵁搴撹繛鎺ュ瘑鐮?$dbpwd="root";
//edusoho鐨凪ysql鏁版嵁搴撲嬌鐢ㄧ殑鏁版嵁搴撳悕绉?$dbname="discuz2";
//缃戠珯缃戝潃锛屽http://www.a.com/锛屼互/缁撳熬
$shop_url="http://www.a.com/";
//骞垮憡鑱旂洘绋嬪簭瀹夎璺緞锛屽http://www.b.com/锛屼互/缁撳熬
$cf_url="ttp://www.b.com/";
//骞垮憡鑱旂洘绯葷粺瀵嗛挜,绠$悊鍛樺悗鍙闆彲鏌ュ埌,鐧誨綍鍔犲瘑鐢?$cf_syscode="xxxxxxxx";
//骞垮憡鑱旂洘瀵規帴鐨勭▼搴忔櫘閫氱敤鎴風殑骞垮憡ID
$cf_ad_id=126;
//骞垮憡鑱旂洘瀵規帴鐨勭▼搴忔ゼ涓葷殑骞垮憡ID
$cf_ad_idb=123;
//ifrmame楂樺害,璋冭瘯鏃跺彲浠ヨ缃?0鍒?0鍙互鏄劇ず璋冭瘯淇℃伅,瀹屾垚鍚庤缃負0鍗沖彲闅愯棌
$cf_iframeheight=20;
$conn = mysql_connect($dbhost,$dbuser,$dbpwd);
if (!$conn) die ("瀵逛笉璧鳳紝鍙戠敓閿欒锛?璇鋒鏌f_conn.php涓暟鎹簱鐨勯厤缃槸鍚︽纭紒");
mysql_query("set names gbk");
mysql_select_db($dbname,$conn);
//杩囨護闈炴硶瀛楃
function chkstr($paravalue,$paratype){
if($paratype==1){
$filterstr="(and|or)\\b.+?(>|<|=|in|like)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?SELECT|UPDATE.+?SET|INSERT\\s+INTO.+?VALUES|(SELECT|DELETE).+?FROM|(CREATE|ALTER|DROP|TRUNCATE)\\s+(TABLE|DATABASE)";
if (preg_match("/".$filterstr."/is",$paravalue)==1){
exit("浼犻€掔殑鍙傛暟绫誨瀷鏈夐敊璇紒");
}
$inputstr=str_replace("'","''",$paravalue);
}elseif($paratype==2){
if($paravalue!=""&&is_numeric($paravalue)==false){
exit("浼犻€掔殑鍙傛暟绫誨瀷鏈夐敊璇紒");
}else{
$inputstr=$paravalue;
}
}elseif($paratype==3){
if($paravalue!=""&&(strtotime($paravalue)==false||strtotime($paravalue)==-1)){
exit("浼犻€掔殑鍙傛暟绫誨瀷鏈夐敊璇紒");
}else{
$inputstr=$paravalue;
}
}
return $inputstr;
}
?>
聽
聽
聽
聽
聽
cf_reg.php鍐呭涓?
聽
聽
<?php
header("expires:mon,26jul199705:00:00gmt");
header("cache-control:no-cache,must-revalidate");
header("pragma:no-cache");
$action = isset($_GET["action"]) ? $_GET["action"] : "useridget";
if($action=="useridget"){
require './source/class/class_core.php';//寮曞叆绯葷粺鏍稿績鏂囦歡
$discuz = & discuz_core::instance();//浠ヤ笅浠g爜涓哄垱寤哄強鍒濆鍖栧璞?$discuz->cachelist = $cachelist;
$discuz->init();//浠ヤ笂鏄皟鐢╠iscuz鍏叡鎵ц绫葷瓑鏍稿績浠g爜
$userid= $_G['uid'];
$ser=$_SERVER['HTTP_HOST'];
$scr=$_SERVER['SCRIPT_NAME'];
$scr_2=substr($scr,0,strrpos($scr,"/")+1);
//濡傛灉鏄櫥褰曡€呮椂,鏄劇ず鎺ㄥ箍閾炬帴,杩欓噷currurl鐢╞ase64鍔犲瘑闃叉琚弻閲嶄吉闈欐€?if($userid!=""){
echo "document.write(\"<script src='http://".$ser.$scr_2."cf_reg.php?action=usertg&userid=$userid&currurl=\"+base64_encode(window.location.href)+\"' charset='gbk'></script>\");";
@include("cf_conn.php");
$from = isset($_GET["from"]) ? $_GET["from"] : $shop_url;
//var currurl= escape('".str_replace("http://","",$currurl)."');
//currurl='".$cf_ad_id.",".$userid.",,'+currurl;
//str+='".$cf_url."cf.aspx?'+base64_encode(currurl);
//鑾峰彇瀹屾暣鐨剈rl
//$cur_1= 'http://'.$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI'];
$cur_2= str_replace("http://","",$from);
echo "document.write(\"<script>var cur3= escape('".$cur_2."'); var cur='".$cf_ad_id.",".$userid.",,'+cur3;var my_currurl='http://www.b.com/cf.aspx?'+base64_encode(cur);</script>\");";
}
}
//鐧誨綍鐢ㄦ埛鏄劇ず鎺ㄥ箍閾炬帴
if($action=="usertg"){
@include("cf_conn.php");
if($cf_ad_id==0) exit;
//鍙栧嚭褰撳墠椤碉紝鍒ゆ柇鍝簺椤甸潰闇€瑕佸嚭鐜版帹骞挎彁绀?$currurl = isset($_GET["currurl"]) ? chkstr($_GET["currurl"],1) : "";
$currurl=base64_decode($currurl);
//echo("alert('$currurl');");
//鐢ㄦ鍒欒鍙?if(preg_match('/p-([0-9]*)-.*\.html/',$currurl,$matched)){$tid=$matched[1];}else{$tid="";};
$userid = isset($_GET["userid"]) ? chkstr($_GET["userid"],2) : "";
$sql="select email from pre_ucenter_members where uid='$userid'";
$result=mysql_query($sql);
if($rs=mysql_fetch_array($result)){
$username=$rs["email"];
}
if($tid!=""){
//濡傛灉杩欎釜甯栧瓙鏄綋鍓嶇敤鎴峰彂鐨勫垯璋冪敤瀵規ゼ涓葷殑骞垮憡
$sql="select authorid from pre_forum_post where tid='$tid'";
$result=mysql_query($sql);
if($rs=mysql_fetch_array($result)){
$useridb=$rs["authorid"];
if ($userid==$useridb){$cf_ad_id=$cf_ad_idb;}
}
}else{
exit;//闈炰富棰橀〉鏃朵笉鏄劇ず
}
//echo("alert('$currurl');");
//鎶婄敤鎴鋒彁浜ゅ埌鑱旂洘鐢ㄦ埛鏂闆鎺ュ彛
echo "document.write(\"<iframe src='".$cf_url."cf.aspx?action=useradd&userid=$userid&username=$username&checkcode=".md5($userid.$username.$cf_syscode)."' frame);";
echo("
var sxadwidth = 500;
var sxadheight = 120
document.write('<span id=\"cf_sxtg\"></span>');
//鍏抽棴鎸夐挳
str='';
str+='<div align=\"left\" id=\"cf_sxtg\" style=\"background-color:#c6ccd9;padding:7px;width:590px;display:inline-block\">'
str+='<span style=\"font-size:14px;color:#ff0000;\">鎺ㄥ箍鏈珯璧氶挶</span>';
str+='<br><span style=\"font-size:12px;\">澶嶅埗鎺ㄥ箍閾炬帴缁欏埆浜哄彲鑾鋒彁鎴?lt;/span>';
str+='<iframe src=\"".$cf_url."d_info.asp?userid=$userid&checktime=".time()."&checkcode=".md5($userid.time().$cf_syscode)."\" frame;
str+='<br><textarea onfocus=\"select()\"id=\"tgtext\" style=\"width:540px;height:18px;margin-bottom:-3px;\">';
var currurl= escape('".str_replace("http://","",$currurl)."');
currurl='".$cf_ad_id.",".$userid.",,'+currurl;
//alert(currurl);
str+='".$cf_url."cf.aspx?'+base64_encode(currurl);
str+='</textarea> <a style=\"font-size:16px;display:inline-block;\"href=\"javascript:\" onclick=\"tgcopy(\'tgtext\');\"> 澶嶅埗';
str+='</div>';
showMsg(str);
function showMsg(str) {
var s=\"\";
var _width=sxadwidth;_height=sxadheight;
try{
if(document.compatMode && document.compatMode != 'BackCompat'){
s+=('<div style=\"\" id=\"BottomMsg\">');
}else {
s+=('<div style=\"\" id=\"BottomMsg\" >');
}
s+=(str);
s+=('</div>');
document.getElementById('cf_sxtg').innerHTML = s;
}catch(err){}
}
function cf_sxtg_closeDiv(){
document.getElementById('cf_sxtg').style.visibility='hidden';
document.getElementById('cf_sxtg_close').style.visibility='hidden';
}
function tgcopy(ob){
var obj=tgfindObj(ob);
if(-[1,]){
obj.select();
alert(\"鎮ㄧ殑娴忚鍣ㄤ笉鏀寔姝よ繖涓鍒跺姛鑳?璇鋒墜宸ュ鍒舵枃鏈涓唴瀹筡")
}else{
if (obj) {
obj.select();js=obj.createTextRange();js.execCommand(\"Copy\");}
}
}
function tgfindObj(n, d) { //v4.0
var p,i,x; if(!d) d=document; if((p=n.indexOf(\"?\"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=findObj(n,d.layers[i].document);
if(!x && document.getElementById) x=document.getElementById(n); return x;
}
");
}
echo("
function base64_encode(str){
var c1, c2, c3;
var base64EncodeChars = \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";
var i = 0, len= str.length, string = '';
while (i < len){
c1 = str.charCodeAt(i++) & 0xff;
if (i == len){
string += base64EncodeChars.charAt(c1 >> 2);
string += base64EncodeChars.charAt((c1 & 0x3) << 4);
string += \"==\";
break;
}
c2 = str.charCodeAt(i++);
if (i == len){
string += base64EncodeChars.charAt(c1 >> 2);
string += base64EncodeChars.charAt(((c1 & 0x3) << 4) | ((c2 & 0xF0) >> 4));
string += base64EncodeChars.charAt((c2 & 0xF) << 2);
string += \"=\";
break;
}
c3 = str.charCodeAt(i++);
string += base64EncodeChars.charAt(c1 >> 2);
string += base64EncodeChars.charAt(((c1 & 0x3) << 4) | ((c2 & 0xF0) >> 4));
string += base64EncodeChars.charAt(((c2 & 0xF) << 2) | ((c3 & 0xC0) >> 6));
string += base64EncodeChars.charAt(c3 & 0x3F)
}
return string
}
")
?>
聽
聽
聽
聽
聽
涓?濡傛灉瑕佽鐧懼害鍒嗕韓鏄劇ず.骞朵笖鍒嗕韓鍚?闄勫甫鍥炶皟鐨勬湰璁哄潧缃戝潃涓鴻嚜瀹氫箟鐨勬帹骞塊摼鎺?
鍏朵腑{eval}琛ㄧず鍦ㄦā鏉誇腑鐩存帴杩愯php,
濡傛灉瑕佽嚜瀹氫箟閾炬帴.闇€瑕佸鍔燽dUrl:my_currurl 杩欎竴鍙?
涓?浜嗘柟渚垮鏉傛帹骞塊摼鎺?璇蜂笉瑕佸紑鍚櫨搴﹀垝璇嶅垎浜姛鑳?
聽
鍦╘template\default\forum\viewthread_node_body.htm
澶х害62琛?涔熷氨鏄?lt;!--{if $post['first']}-->鐨勪笅闈?瑕佸姞鍦ㄨ繖涓綅缃?鏄洜涓鴻繖涓唬鐮佸彧鎯寵浠栨樉绀哄湪涓婚甯栧瓙涓?鍥炲涓笉鏄劇ず.娣誨姞涓婇潰涓や釜鏂囦歡鐨勮皟鐢ㄥ強鐧懼害鍒嗕韓
浠g爜閮戒笉闇€瑕佸湪鍚庡彴璁劇疆浠€涔?
<!--{eval
$cur_1= 'http://'.$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI'];
echo "<script src='/cf_reg.php?from=".$cur_1."' charset='gbk'></script>";
}-->
<div class="bdsharebuttonbox"><a href="#" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" class="bds_more" data-cmd="more"></a><a href="#" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" class="bds_qzone" data-cmd="qzone" title="鍒嗕韓鍒癚Q绌洪棿"></a><a href="#" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" class="bds_tsina" data-cmd="tsina" title="鍒嗕韓鍒版柊娴井鍗?></a><a href="#" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" class="bds_tqq" data-cmd="tqq" title="鍒嗕韓鍒拌吘璁井鍗?></a><a href="#" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" class="bds_renren" data-cmd="renren" title="鍒嗕韓鍒頒漢浜虹綉"></a><a href="#" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" target="_blank" rel="external nofollow" class="bds_weixin" data-cmd="weixin" title="鍒嗕韓鍒闆井淇?></a></div>
<script>window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"32",bdUrl:my_currurl},"share":{},"image":{"viewList":["qzone","tsina","tqq","renren","weixin"],"viewText":"鍒嗕韓鍒幫細","viewSize":"16"}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)];</script>
聽

聽
聽
聽