<?php
function fcnStripUnwantedChars($data) 
{
	$data = strip_tags($data);
	$data = str_replace('“','&quot;',$data);
	
	return str_replace('”','&quot;',$data);
}

function fcnValidateEmail($email) 
{
	$email = trim($email);
	$addresses = array('hiltonselfcatering.co.uk');
	
	if(eregi('^[_a-z0-9-]+(\.[_a-z0-9-]+)*@[a-z0-9-]+(\.[a-z0-9-]+)*(\.[a-z]{2,3})$',$email)) 
	{
		$fails = 0;
		
		foreach($addresses as $address) 
		{
			if(preg_match("/".$address."/i",$email)) 
			{
				$fails++;
			}
		}
		
		if($fails == 0) 
		{
			unset($fails,$email,$addresses);
			
			return true;
		} 
		else 
		{
			unset($fails,$email,$addresses);
			
			return false;
		}
	} 
	else 
	{
  		unset($email,$addresses);	
		
		return false;
	}	
}

function fcnRemoveXSSAttacks($data) 
{
	$data = fcnStripUnwantedChars($data);

	$val = $search = $level = '';
	$val = preg_replace('/([\x00-\x08][\x0b-\x0c][\x0e-\x20])/','',$data);
	$search .= 'abcdefghijklmnopqrstuvwxyz';
	$search .= 'ABCDEFGHIJKLMNOPQRSTUVWXYZ';
	$search .= '1234567890!@#$%^&*()';
	$search .= '~`";:?+/={}[]-_|\'\\';
	
	for($i = 0; $i < strlen($search); ++$i) 
	{
		$val = preg_replace('/(&#[x|X]0{0,8}'.dechex(ord($search[$i])).';?)/i',$search[$i],$val);
		$val = preg_replace('/(&#0{0,8}'.ord($search[$i]).';?)/',$search[$i],$val);
	}
	
	$ra1 = array('javascript','vbscript','expression','applet','meta','xml','blink','link','style','script','embed','iframe','frame','frameset','ilayer','layer','bgsound','title','base');
	$ra2 = array('onabort','onactivate','onafterprint','onafterupdate','onbeforeactivate','onbeforecopy','onbeforecut','onbeforedeactivate','onbeforeeditfocus','onbeforepaste','onbeforeprint','onbeforeunload','onbeforeupdate','onblur','onbounce','oncellchange','onchange','onclick','oncontextmenu','oncontrolselect','oncopy','oncut','ondataavailable','ondatasetchanged','ondatasetcomplete','ondblclick','ondeactivate','ondrag','ondragend','ondragenter','ondragleave','ondragover','ondragstart','ondrop','onerror','onerrorupdate','onfilterchange','onfinish','onfocus','onfocusin','onfocusout','onhelp','onkeydown','onkeypress','onkeyup','onlayoutcomplete','onload','onlosecapture','onmousedown','onmouseenter','onmouseleave','onmousemove','onmouseout','onmouseover','onmouseup','onmousewheel','onmove','onmoveend','onmovestart','onpaste','onpropertychange','onreadystatechange','onreset','onresize','onresizeend','onresizestart','onrowenter','onrowexit','onrowsdelete','onrowsinserted','onscroll','onselect','onselectionchange','onselectstart','onstart','onstop','onsubmit','onunload');
	$ra = array_merge($ra1,$ra2);
	$found = true;
	
	while($found == true) 
	{
		$val_before = $val;
		
		for($i = 0; $i < sizeof($ra); ++$i) 
		{
			$pattern = '/';
			
			for($j = 0; $j < strlen($ra[$i]); ++$j) 
			{
				if($j > 0) 
				{
					$pattern .= '(';
					$pattern .= '(&#[x|X]0{0,8}([9][a][b]);?)?';
					$pattern .= '|(&#0{0,8}([9][10][13]);?)?';
					$pattern .= ')?';
				}
				
				$pattern .= $ra[$i][$j];
			}
			
			$pattern .= '/i';
			$replacement = substr($ra[$i],0,2).'<x>'.substr($ra[$i],2);
			$val = preg_replace($pattern,$replacement,$val);
			
			if($val_before == $val) 
			{
				$found = false;
			}
		}
	}
	
	unset($found,$pattern,$replacement,$j,$i,$val_before,$ra1,$ra2,$ra,$search);
	
	return $val;
}
?>