Файл: NskriptS.zip/ip.php
Строк: 287
<?php
error_reporting(0);
include("config.php");
include("./includes/".$ver."/banned");
list($msec, $sec) = explode(chr(32), microtime());
$headtime = $sec + $msec;
$nocache = rand(10000, 99999);
switch($ver)
{
////////////////////////////////////////////////////////
//WML VERSION
////////////////////////////////////////////////////////
case 'wml':
header("Content-type: text/vnd.wap.wml; charset=utf-8");
header("Last-Modified: ".gmdate("D, d M Y H:i:s")." GMT");
header("Cache-Control: no-cache, must-relative");
//AUTH
$id = intval($_GET['id']);
$password = mysql_escape_string($_GET['password']);
$q = mysql_query("SELECT `level` FROM `chat_users` WHERE `id` = '".$id."' AND `password` = '".$password."';");
if(mysql_num_rows($q) == 0)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.3//EN" "http://www.wapforum.org/DTD/wml13.dtd"><wml>n";
echo "<card title="ERROR" ontimer="index.php?ver=wml"><timer value="15"/><p align="left">n";
echo "<small>Ошибка авторизации!<br/>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/>[".round(($sec+$msec)-$headtime,5)."] sec<br/>n";
echo "</small></p></card></wml>";
exit();
}
//END AUTH
$level = mysql_result($q, 0);
if($level != 4)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.3//EN" "http://www.wapforum.org/DTD/wml13.dtd"><wml>n";
echo "<card id="error" title="ERROR" ontimer="menu.php?ver=wml&id=$id&password=$password"><timer value="15"/><p align="left">n";
echo "<small>Доступ запрещен.<br/>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/>[".round(($sec+$msec)-$headtime,5)."] sec<br/>n";
echo "</small></p></card></wml>";
exit();
}
$uid = intval($_GET['uid']);
$sql = mysql_query("SELECT `level`, `nickname` FROM `chat_users` WHERE `id` = '".$uid."';");
if(mysql_num_rows($sql) == 0)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.3//EN" "http://www.wapforum.org/DTD/wml13.dtd"><wml>n";
echo "<card id="error" title="ERROR" ontimer="menu.php?ver=wml&id=$id&password=$password"><timer value="15"/><p align="left">n";
echo "<small>Пользователь не найден.<br/>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/>[".round(($sec+$msec)-$headtime,5)."] sec<br/>n";
echo "</small></p></card></wml>";
exit();
}
else
{
$lev = mysql_result($sql, 0, 'level');
$nick = mysql_result($sql, 0, 'nickname');
}
if($uid == 1)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.3//EN" "http://www.wapforum.org/DTD/wml13.dtd"><wml>n";
echo "<card id="error" title="ERROR" ontimer="menu.php?ver=wml&id=$id&password=$password"><timer value="15"/><p align="left">n";
echo "<small>Вы не можете блокировать данного пользователя. Нет прав.<br/>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/>[".round(($sec+$msec)-$headtime,5)."] sec<br/>n";
echo "</small></p></card></wml>";
exit();
}
//ONLINE
$online = time() + 60;
$update = mysql_query("UPDATE `chat_users` SET `time` = '".$online."', `place` = 0, `ip` = '".getenv('REMOTE_ADDR')."', `ua` = '".htmlspecialchars(getenv('HTTP_USER_AGENT'))."' WHERE `id` = '".$id."';");
//END ONLINE
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE wml PUBLIC "-//WAPFORUM//DTD WML 1.3//EN" "http://www.wapforum.org/DTD/wml13.dtd"><wml>n";
echo "<card title="$nick"><p align="left">n";
if(isset($_GET['act']))
{
$q = mysql_query("SELECT `nickname` FROM `chat_users` WHERE `id` = '".$id."';");
$moder = mysql_result($q, 0);
$q = mysql_query("SELECT `ip` FROM `chat_users` WHERE `id` = '".$uid."';");
$ip = mysql_result($q, 0);
$ban = mysql_query("INSERT INTO `chat_banned` VALUES(0, '".$ip."', '-');");
if($ban)
{
echo "$nick забанен(а) по IP-адресу!<br/>n";
echo "[IP]: <u>".$ip."</u><br/>n";
}
else
{
echo "При занесении IP-адреса в базу данных произошла ошибка!<br/>n";
}
$date = date("d-m-y H:i:s");
$query = mysql_query("SELECT `nickname` FROM `chat_users` WHERE `id` = '".$id."';");
$moder = mysql_result($query, 0);
$q = mysql_query("INSERT INTO `chat_logs` VALUES(0, '".$moder."', 4, '".$nick."', '".$reason."', '".$date."', ".time().");");
}
else
{
echo "Вы уверены, что хотите забанить пользователя $nick по IP-адресу?<br/>n";
if(!empty($_GET['rid'])) echo "<a href="ip.php?act=ban&ver=wml&nocache=$nocache&id=$id&password=$password&uid=$uid&rid=".intval($_GET['rid'])."">[Да]</a> <a href="room.php?id=$id&password=$password&ver=wml&rid=".intval($_GET['rid'])."">[Нет]</a><br/>n";
if(!empty($_GET['key'])) echo "<a href="ip.php?act=ban&ver=wml&nocache=$nocache&id=$id&password=$password&uid=$uid&key=".$_GET['key']."">[Да]</a> <a href="intim.php?id=$id&password=$password&ver=wml&key=".$_GET['key']."">[Нет]</a><br/>n";
}
if(!empty($_GET['rid'])) echo "<a href="room.php?id=$id&password=$password&ver=wml&rid=".intval($_GET['rid'])."">В чат</a><br/>n";
if(!empty($_GET['key'])) echo "<a href="intim.php?id=$id&password=$password&ver=wml&key=".$_GET['key']."">В чат</a><br/>n";
echo "<a href="menu.php?id=$id&password=$password&ver=wml">Меню чата</a><br/>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/><small>[".round(($sec+$msec)-$headtime,5)."] sec</small><br/>n";
echo "</p></card></wml>";
break;
////////////////////////////////////////////////////////
//HTML VERSION
////////////////////////////////////////////////////////
case 'html':
header ("Content-type: text/html; charset=utf-8");
header("Last-Modified: ".gmdate("D, d M Y H:i:s")." GMT");
header("Cache-Control: no-cache, must-relative");
//AUTH
$id = intval($_GET['id']);
$password = mysql_escape_string($_GET['password']);
$q = mysql_query("SELECT `level` FROM `chat_users` WHERE `id` = '".$id."' AND `password` = '".$password."';");
if(mysql_num_rows($q) == 0)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">n";
echo "<html><head>n";
echo "<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>n";
echo '<link href="css.css" rel="stylesheet" type="text/css"><title>'.$title.'</title>
</head>
<body>';
echo "Ошибка авторизации!<br/>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/>[".round(($sec+$msec)-$headtime,5)."] sec<br/>n";
echo "</body></html>";
exit();
}
//END AUTH
//ONLINE
$online = time() + 60;
$update = mysql_query("UPDATE `chat_users` SET `time` = '".$online."', `place` = 0 WHERE `id` = '".$id."';");
//END ONLINE
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">n";
echo "<html><head>n";
echo "<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>n";
echo '<link href="css.css" rel="stylesheet" type="text/css"><title>'.$title.'</title>
</head>
<body>';
$level = mysql_result($q, 0);
if($level != 4)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">n";
echo "<html><head>n";
echo "<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>n";
echo '<link href="css.css" rel="stylesheet" type="text/css"><title>'.$title.'</title>
</head>
<body>';
echo "Доступ запрещен<br/>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/><small>[".round(($sec+$msec)-$headtime,5)."] sec</small><br/>n";
echo "</div></body></html>";
exit();
}
$uid = intval($_GET['uid']);
$sql = mysql_query("SELECT `level`, `nickname` FROM `chat_users` WHERE `id` = '".$uid."';");
if(mysql_num_rows($sql) == 0)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">n";
echo "<html><head>n";
echo "<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>n";
echo '<link href="css.css" rel="stylesheet" type="text/css"><title>ERROR</title>
</head>
<body>';
echo "<div class="lic2">Пользователь не найден в базе данных.</div>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/><small>[".round(($sec+$msec)-$headtime,5)."] sec</small><br/>n";
echo "</div></body></html>";
exit();
}
else
{
$lev = mysql_result($sql, 0, 'level');
$nick = mysql_result($sql, 0, 'nickname');
}
if($uid == 1)
{
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">n";
echo "<html><head>n";
echo "<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>n";
echo '<link href="css.css" rel="stylesheet" type="text/css"><title>ERROR</title>
</head>
<body>';
echo "<div class="lic2">Вы не можете блокировать данного пользователя. Нет прав.</div>n";
list($msec, $sec) = explode(chr(32), microtime());
echo "<br/><small>[".round(($sec+$msec)-$headtime,5)."] sec</small><br/>n";
echo "</div></body></html>";
exit();
}
//ONLINE
$online = time() + 60;
$update = mysql_query("UPDATE `chat_users` SET `time` = '".$online."', `place` = 0, `ip` = '".getenv('REMOTE_ADDR')."', `ua` = '".htmlspecialchars(getenv('HTTP_USER_AGENT'))."' WHERE `id` = '".$id."';");
//END ONLINE
echo "<?xml version="1.0" encoding="UTF-8"?>n";
echo "<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">n";
echo "<html><head>n";
echo "<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>n";
echo '<link href="css.css" rel="stylesheet" type="text/css"><title>'.$nick.'</title>
</head>
<body>';
if(isset($_GET['act']))
{
$q = mysql_query("SELECT `nickname` FROM `chat_users` WHERE `id` = '".$id."';");
$moder = mysql_result($q, 0);
$q = mysql_query("SELECT `ip` FROM `chat_users` WHERE `id` = '".$uid."';");
$ip = mysql_result($q, 0);
$ban = mysql_query("INSERT INTO `chat_banned` VALUES(0, '".$ip."', '-');");
if($ban)
{
echo "$nick забанен(а) по IP-адресу!<br/>n";
echo "[IP]: <u>".$ip."</u><br/>n";
}
else
{
echo "При занесении IP-адреса в базу данных произошла ошибка!<br/>n";
}
$date = date("d-m-y H:i:s");
$query = mysql_query("SELECT `nickname` FROM `chat_users` WHERE `id` = '".$id."';");
$moder = mysql_result($query, 0);
$q = mysql_query("INSERT INTO `chat_logs` VALUES(0, '".$moder."', 4, '".$nick."', '".$reason."', '".$date."', ".time().");");
}
else
{
echo "Вы уверены, что хотите забанить пользователя $nick по IP-адресу?<br/>n";
if(!empty($_GET['rid'])) echo "<a href="ip.php?act=ban&ver=html&nocache=$nocache&id=$id&password=$password&uid=$uid&rid=".intval($_GET['rid'])."">[Да]</a> <a href="room.php?id=$id&password=$password&ver=html&rid=".intval($_GET['rid'])."">[Нет]</a><br/>n";
if(!empty($_GET['key'])) echo "<a href="ip.php?act=ban&ver=html&nocache=$nocache&id=$id&password=$password&uid=$uid&key=".$_GET['key']."">[Да]</a> <a href="intim.php?id=$id&password=$password&ver=html&key=".$_GET['key']."">[Нет]</a><br/>n";
}
if(!empty($_GET['rid'])) echo "<a href="room.php?id=$id&password=$password&ver=html&rid=".intval($_GET['rid'])."">В чат</a><br/>n";
if(!empty($_GET['key'])) echo "<a href="intim.php?id=$id&password=$password&ver=html&key=".$_GET['key']."">В чат</a><br/>n";
echo "<a href="menu.php?id=$id&password=$password&ver=html">Меню чата</a><br/>";
list($msec, $sec) = explode(chr(32), microtime());
echo "</div></body></html>";
break;
}
?>