Advertisement
Guest User

Untitled

a guest
Aug 11th, 2017
67
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.62 KB | None | 0 0
  1. <?php
  2.  
  3. if (isset($_GET['u']) && isset($_GET['p']) && isset($_GET['v'])) {
  4.  
  5.  
  6. $version = $_GET['v'];
  7. if ($version >= 1180) {
  8.  
  9.  
  10. include("config.php");
  11.  
  12. include("funcs.php");
  13.  
  14.  
  15. $connect = mysql_connect(MYSQL_ADDRESS,MYSQL_USERNAME,MYSQL_PASSWORD) or die(mysql_error());
  16. mysql_select_db(MYSQL_DATABASE) or die(mysql_error());
  17.  
  18. $loggedin = 0;
  19. $ulevel = 0;
  20. $ufunc = 0;
  21. $cuser = "a";
  22. $username = "a";
  23. $username = $_GET['u'];
  24. $upm = 0;
  25. if (isset($_GET['upm'])) {
  26. $upm = $_GET['upm'];
  27. }
  28. $upm = md5($upm);
  29. $npassword = $_SERVER['QUERY_STRING'];
  30. $password = urlencode($_GET['p']);
  31. $groups = array();
  32. $xpassword = preg_match("/(.*)&v=(.*)&upm=(.*)&p=(.*)/", $npassword, $groups);
  33. $xpassword = $groups[4];
  34. $method = 0;
  35. $username = escapem($username);
  36. $version = escapem($version);
  37. //$password = escapem($password);
  38. $tpassword = md5($xpassword);
  39. if ($upm == 0) {
  40. $res = mysql_query("SELECT username, phlevel FROM ".MYSQL_PREFIX."_users WHERE username='$username' AND password='$tpassword'");
  41. $method = 1;
  42.  
  43. } else {
  44. $res = mysql_query("SELECT username, phlevel, ac_md5 FROM ".MYSQL_PREFIX."_users WHERE username='$username' AND ac_md5='$upm'");
  45. $method = 2;
  46. }
  47. $num = mysql_num_rows($res);
  48. $row = mysql_fetch_array($res);
  49.  
  50. if ($num == 1) {
  51. $ip = $_SERVER['REMOTE_ADDR'];
  52. $now = time();
  53. $username = $row['username'];
  54. $loggedin = 1;
  55. echo "$username";
  56. } else {
  57. echo "error2 - User: $username - Password: $groups[4] - UPM: $upm - $method";
  58. #print_r($groups);
  59. }
  60. } else {
  61. echo "update";
  62. }
  63. }
  64.  
  65. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement