Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Eudemons Online > EO PServer Hosting
You last visited: Today at 22:10

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[release] Reset Lost Password Script

Discussion on [release] Reset Lost Password Script within the EO PServer Hosting forum part of the Eudemons Online category.

Reply
 
Old 04/30/2011, 23:56   #16
 
~*Kronic*~'s Avatar
 
elite*gold: 0
Join Date: Aug 2010
Posts: 219
Received Thanks: 110
Nice release I would add some input sanitization though, to easy to hack that script and gain full access to accounts table (no offense as all the sites on here require that).
~*Kronic*~ is offline  
Old 05/01/2011, 00:18   #17
 
Eurion's Avatar
 
elite*gold: 0
Join Date: Oct 2009
Posts: 1,208
Received Thanks: 926
Since its constantly connected through mysql, you can use mysql's built in mysql_real_escape_string(variable) function. It will sanitize any input that could harm the database.
Eurion is offline  
Old 05/01/2011, 00:44   #18

 
PowerChaos's Avatar
 
elite*gold: 90
Join Date: Feb 2008
Posts: 1,112
Received Thanks: 642
i am not that skilled at mysql/php
i mostly copy/paste the core functions from differend scripts to mix it to a part to do what i need to do (this script is a rebuild of a register script with verification email and a few other scripts where i took the code from)

basicly i wanted to make it with a dual database conection ( single database on website and main database on vps so you can only acces the database from the vps with read acces , is safer then allowing a conection from the web to the vps) but i failt at that part as everyhting that i found doesnt seems to work :'(

anyway
it is atleast a usefull release for some persones , you are free to modifie it for your needs and improve it , but let me know when you want to re release it as it is still my own work

Greets From PowerChaos

if you got example codes for me , please send them to me and i will use them in the script (i just need the basic functions and examples) so i know what i can put in it
PowerChaos is offline  
Old 05/01/2011, 01:18   #19
 
Eurion's Avatar
 
elite*gold: 0
Join Date: Oct 2009
Posts: 1,208
Received Thanks: 926
I've gone through and fixed up the majority of the sanitizing issues. I haven't tested it, but I don't see how it could cause any issues. These are just simple sanitizing functions, if you want to fully secure it, I suggest that you write up your own functions.

If you encounter any problems with this, feel free to post.

newpass.php:

lostpass.php:
Eurion is offline  
Thanks
1 User
Old 05/01/2011, 01:41   #20

 
PowerChaos's Avatar
 
elite*gold: 90
Join Date: Feb 2008
Posts: 1,112
Received Thanks: 642
ok , Thank you
i changed a few more things in it that i noticed (in some cases)

i changed the "echo" comamnds to "die" commands to prevent execution of the other commands (what happends in rare cases)

but after looking true the script i founded something where i can not figure out how it comes that it works ( make no sense for me but it works)

Code:
else{
					$sql = "UPDATE account SET password='$hash' WHERE name='$userid'";
					$query = mysql_query($sql) or die(mysql_error());
if i understand php good enouf , then $query need to run somewhere or it is not even suposed to be running ? (as it is a variable that get set to the command $query so you can use that command to execute on the place you like )

anyway , thank you for the update
i going edit my first post with this new post and the mirror fix on it

Greets From PowerChaos
PowerChaos is offline  
Old 05/01/2011, 01:47   #21
 
Eurion's Avatar
 
elite*gold: 0
Join Date: Oct 2009
Posts: 1,208
Received Thanks: 926
Quote:
Originally Posted by PowerChaos View Post
ok , Thank you
i changed a few more things in it that i noticed (in some cases)

i changed the "echo" comamnds to "die" commands to prevent execution of the other commands (what happends in rare cases)

but after looking true the script i founded something where i can not figure out how it comes that it works ( make no sense for me but it works)

Code:
else{
					$sql = "UPDATE account SET password='$hash' WHERE name='$userid'";
					$query = mysql_query($sql) or die(mysql_error());
if i understand php good enouf , then $query need to run somewhere or it is not even suposed to be running ? (as it is a variable that get set to the command $query so you can use that command to execute on the place you like )

anyway , thank you for the update
i going edit my first post with this new post and the mirror fix on it

Greets From PowerChaos
The $query variable is what's running the sql. Since you have it defined, it will run even if its not called through an echo or print statement.
Eurion is offline  
Reply


Similar Threads Similar Threads
[RELEASE] Secure PHP Web Change Password Script
08/28/2013 - Shaiya PServer Guides & Releases - 8 Replies
This is a secure password change script meant for Shaiya private servers. I noticed a lot of private servers do not allow regular users to change passwords. Be warned, this script is a double-edged sword in a way, ESPECIALLY since most servers do not allow for password recovery via email or some other method. By implementing this script players who have shared their account credentials with other players can now get their password changed unknowingly (and thus their account is now...
[RELEASE]Password Reset Tool
04/04/2011 - Dekaron Private Server - 6 Replies
Dekaron Password Reset Tool This tool will change the passwords of all your Dekaron accounts to a 14 character, case-sensitive, alphanumeric string. Such as "8f9EobZouaMztW". You can use the tool both on the dedicated server or off it. It is easiest to just use on the dedicated server by clicking the check box for "Windows Authentication" then you don't have to enter anything, just click and go! The other feature on this tool is importing your new passwords to a MySQL database for...
[Release] Ip-Reset D2NT-Script!(beta)
10/08/2010 - Diablo 2 - 28 Replies
Soo Leute es ist soweit Hiermit stelle ich die Version 0.97Beta des D2NT-Reconnecters Online! Alle Dateien/Scripts wurden von mir verfasst! Ihr könnt sie gerne scannen! Wollte die Dateien eigentlich openSource anbieten. Jedoch habe ich es schon öfter miterlebt das openSource Programme missbraucht wurden, von 3. Verschlüsselt wurden und weiterverkauft! Somit bekommen hier nur 1 oder 2 Leute denen ich vertraue eine Opensource Version!
Reset password ifyou lost the Secret answer
06/06/2008 - WoW Exploits, Hacks, Tools & Macros - 1 Replies
Hi all So, you have wow and you forgot the password and cant get it changed because your one of the many who either purchased a wow account or you simply cant remember your secret question/answer. This is what I done to reset my password on one of my accounts that I purchased. You have to have the email on the account set to your email btw. Simply get a friend or if you have an alt account do it yourself. And report yourself for buying gold.



All times are GMT +1. The time now is 22:11.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.