// --Konfiguration-------------------------- $blockedStrings = ['www.', 'https:','http:']; $checkedFields = ['firstname', 'lastname']; $checkedFiles = [FILENAME_CREATE_GUEST_ACCOUNT, FILENAME_CREATE_ACCOUNT]; // ----------------------------------------- if (in_array(basename($PHP_SELF), $checkedFiles)) { if ( isset($_POST['action']) && $_POST['action'] === 'process' && function_exists('xss_write_blacklist') ) { foreach ($checkedFields as $field) { if (!empty($_POST[$field])) { foreach ($blockedStrings as $bad) { if (stripos($_POST[$field], $bad) !== false) { require_once(XSS_PATH . 'inc/xtc_get_ip_address.inc.php'); xss_add_blacklist(xtc_get_ip_address()); header("Location: " . XSS_BASE . "error.html"); exit; } } } } } }