Advertisement
Guest User

Untitled

a guest
Aug 14th, 2017
87
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.03 KB | None | 0 0
  1. <?php
  2. session_start();
  3. include("../config.php");
  4. if($_POST['register']){
  5. $checkemail = mysql_query("SELECT mail FROM users WHERE mail ='".$_POST[email]."'");
  6. $email_exist = mysql_num_rows($checkemail);
  7. if($_POST['email'] == ""){
  8. header("location: ./start.php?error=email");
  9. }elseif($email_exist > 0){
  10. header("location: ./start.php?error=emailexist");
  11. }elseif($_POST['password'] == ""){
  12. header("location: ./start.php?error=password&email=".$_POST[email]."");
  13. }elseif($_POST['secretquestion'] == ""){
  14. header("location: ./start.php?error=secretquestion&email=".$_POST[email]."");
  15. }elseif($_POST['bdday'] == "" or $_POST['bdmonth'] == "" or $_POST['bdyear'] == ""){
  16. header("location: ./start.php?error=birthday&email=".$_POST[email]."");
  17. }
  18. }elseif($_POST['register2']){
  19. $checkuser = mysql_query("SELECT username FROM users WHERE username ='".$_POST[username]."'");
  20. $user_exist = mysql_num_rows($checkuser);
  21. if($_POST['username'] == ""){
  22. header("location: ./look.php?error=username&email=".$_POST['email']."&bdday=".$_POST['bdday']."&bdmonth=".$_POST['bdmonth']."&bdyear=".$_POST['bdday']."&figure=".$_POST['figure']."&secretquestion=".$_POST['secretquestion']."&referid=".$_POST['referid']."");
  23. }elseif(!preg_match('/^[a-zA-Z0-9._:,-]+$/i', $_POST['username'])){
  24. header("location: ./look.php?error=invalidusername&email=".$_POST['email']."&bdday=".$_POST['bdday']."&bdmonth=".$_POST['bdmonth']."&bdyear=".$_POST['bdday']."&figure=".$_POST['figure']."&secretquestion=".$_POST['secretquestion']."&referid=".$_POST['referid']."");
  25. }elseif($user_exist > 0){
  26. header("location: ./look.php?error=usernameexist&email=".$_POST['email']."&bdday=".$_POST['bdday']."&bdmonth=".$_POST['bdmonth']."&bdyear=".$_POST['bdday']."&figure=".$_POST['figure']."&secretquestion=".$_POST['secretquestion']."&referid=".$_POST['referid']."");
  27. }else{
  28. if($_POST['referid'] != ""){
  29. $checkip = mysql_query("SELECT ip_last FROM users WHERE ip_last = '".$_SERVER['REMOTE_ADDR']."'") or die(mysql_error());
  30. $checkip_exist = mysql_num_rows($checkip);
  31. $checkrefer = mysql_query("SELECT ip FROM user_refers WHERE ip = '".$_SERVER['REMOTE_ADDR']."'") or die(mysql_error());
  32. $checkrefer_exist = mysql_num_rows($checkip);
  33. if($checkip_exist == "0" && $checkrefer_exist == "0"){
  34. $reqpoints = mysql_query("SELECT * FROM users WHERE id = '".$_POST['referid']."'");
  35. $pointss = mysql_fetch_array($reqpoints);
  36. $sumarpuntos = $pointss['points']+1;
  37. mysql_query("UPDATE users SET points = '".$sumarpuntos."' WHERE id = '".$_POST['referid']."'");
  38. mysql_query("INSERT INTO user_refers (ip,username,refered,date) VALUES ('".$_SERVER['REMOTE_ADDR']."','".$_POST['username']."','".$pointss['username']."','".time()."')") or die(mysql_error());
  39. }
  40. }
  41. $password = md5($_POST['password']);
  42. $cumple= date("d-m-Y", strtotime("".$_POST['bdday']."-".$_POST['bdmonth']."-".$_POST['bdyear'].""));
  43. $variable_1 = mysql_real_escape_string($_POST['username']);
  44. $variable_2 = mysql_real_escape_string($password);
  45. $variable_3 = mysql_real_escape_string($_POST['email']);
  46. $variable_4 = mysql_real_escape_string($_POST['figure']);
  47. $variable_5 = mysql_real_escape_string($_POST['secretquestion']);
  48. $variable_6 = mysql_real_escape_string($cumple);
  49.  
  50. $query = mysql_query("INSERT INTO users (username, password, mail, look, motto, account_created, last_online, ip_last, ip_reg, auth_ticket, secretquestion, birthday) VALUES ('".$variable_1."', '".$variable_2."', '".$variable_3."', '".$variable_4."', 'Nuevo en ciudadpixel', UNIX_TIMESTAMP(), UNIX_TIMESTAMP(), '".$_SERVER['REMOTE_ADDR']."', '".$_SERVER['REMOTE_ADDR']."', '','".$variable_5."','".$variable_6."')");
  51. $query = mysql_query("SELECT * FROM users WHERE username = '".$_POST['username']."' LIMIT 1");
  52. $user = mysql_fetch_array($query);
  53. $id = $user['id'];
  54. $query = mysql_query("INSERT INTO user_stats (id, RoomVisits, OnlineTime, Respect, RespectGiven, GiftsGiven, GiftsReceived, DailyRespectPoints, DailyPetRespectPoints) VALUES ($id, 0, 0, 0, 0, 0, 0, 3, 3)");
  55. $_SESSION['account'] = $_POST['email'];
  56. header("Location: ../avatars.php");
  57. }
  58. }else{
  59. header("location: start.php");
  60. }
  61. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement