Register for your free account! | Forgot your password?

You last visited: Today at 02:43

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Faction Change [PHP]

Discussion on Faction Change [PHP] within the Shaiya PServer Guides & Releases forum part of the Shaiya Private Server category.

Reply
 
Old   #1
 
[GameAdvisor]Finn's Avatar
 
elite*gold: 0
Join Date: Sep 2016
Posts: 171
Received Thanks: 107
Faction Change [PHP]

removed. base on Unix comment i think is not helping..
[GameAdvisor]Finn is offline  
Thanks
1 User
Old 03/25/2019, 17:38   #2

 
{Skrillex}'s Avatar
 
elite*gold: 0
Join Date: Mar 2013
Posts: 850
Received Thanks: 408
Hi,
first at all: thank you for your release. This Script is really outdated. It uses old mssql drivers wich will not supported by PHP 5.3 or higher.
I just opened the index.php and can see a lot of sql injections.

PHP Code:
$userid $_POST['userid'];
$pass   $_POST['pass'];
//Check if UserID Exists
        
{
        
$useruid = [MENTION=1039734]mss[/MENTION]ql_query('SELECT UserID,Pw FROM  PS_UserData.dbo.Users_Master WHERE UserID = \'' $userid '\'');
        if (
mssql_num_rows($useruid) == 0)
            die(
'"<center>Account Dosent Exist! Redirect Please wait..</center> <meta http-equiv="refresh" content="2;url=index.php">"');
        else
        
// Check if UserID and Password match
            
$useruid1 = [MENTION=1039734]mss[/MENTION]ql_query('SELECT UserID,Pw FROM  PS_UserData.dbo.Users_Master WHERE UserID = \'' $userid '\' and PW = \'' $pass '\'');
    }
    if (
mssql_num_rows($useruid1) == 0)
        die(
'"<center>Account and Password mixmatch! Redirect Please wait..</center> <meta http-equiv="refresh" content="2;url=index.php">"');
    else {
        
$useruid2 = [MENTION=1039734]mss[/MENTION]ql_query('SELECT * FROM  PS_UserData.dbo.Users_Master WHERE UserID = \'' $userid '\' and PW = \'' $pass '\'');
    } 
Every user input will executed directly into database without escaping.

Nobody should use this script for public bcs of missing security.


Regards
{Skrillex} is offline  
Thanks
2 Users
Reply


Similar Threads Similar Threads
Battlefield 5 Faction/Bad Company 3 Faction Turkey ?
09/10/2015 - Battlefield - 3 Replies
https://www.youtube.com/watch?v=nuH_G0XDUdU Is this something like a Huge announcement ? https://www.youtube.com/watch?t=54&v=DJAkVZyW 80g
[Buying] Faction or faction + any camp accounts,connected with mails!
01/14/2015 - Guild Wars Trading - 0 Replies
As threat say,i need x30 faction accs,connected with mails or faction + any camp if you dont have faction only account! Pm me on skype:bartulovic7
[O] Bastion, Red Faction: Armageddon, Red Faction: Armageddon Path to War, Darksiders
04/09/2013 - ArmA Trading - 10 Replies
As Topic say: I'm offering keys for steam Bastion Red Faction: Armageddon Red Faction: Armageddon Path to War DLC Darksiders Darksider II Red Faction: Guerrilla



All times are GMT +1. The time now is 02:43.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.