Файл: login.php
Строк: 59
<?
include_once 'sys/includes/start.php';
include_once 'sys/includes/compress.php';
include_once 'sys/includes/sess.php';
include_once 'sys/includes/home.php';
include_once 'sys/includes/settings.php';
include_once 'sys/includes/db_connect.php';
include_once 'sys/includes/ipua.php';
include_once 'sys/includes/fnc.php';
include_once 'sys/includes/shif.php';
$show_all=true;
$input_page=true;
include_once 'sys/includes/user.php';
only_unreg();
if (isset($_GET['id']) && isset($_GET['pass']))
{
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = '".intval($_GET['id'])."' AND `pass` = '".shif($_GET['pass'])."' LIMIT 1"), 0)==1)
{
$user=get_user($_GET['id']);
$_SESSION['id_user']=$user['id'];
mysql_query("UPDATE `user` SET `date_aut` = ".time()." WHERE `id` = '$user[id]' LIMIT 1");
mysql_query("UPDATE `user` SET `date_last` = ".time()." WHERE `id` = '$user[id]' LIMIT 1");
mysql_query("INSERT INTO `user_log` (`id_user`, `time`, `ua`, `ip`, `method`) values('$user[id]', '$time', '$user[ua]' , '$user[ip]', '0')");
}else{
$err='Неправильный логин или пароль!';
}
}
else if (isset($_POST['nick']) && isset($_POST['pass']))
{
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `nick` = '".my_esc($_POST['nick'])."' AND `pass` = '".shif($_POST['pass'])."' LIMIT 1"), 0))
{
$user=mysql_fetch_assoc(mysql_query("SELECT `id` FROM `user` WHERE `nick` = '".my_esc($_POST['nick'])."' AND `pass` = '".shif($_POST['pass'])."' LIMIT 1"));
$_SESSION['id_user']=$user['id'];
$user=get_user($user['id']);
if (isset($_POST['aut_save']) && $_POST['aut_save'])
{
setcookie('id_user', $user['id'], time()+60*60*24*365);
setcookie('pass', cookie_encrypt($_POST['pass'],$user['id']), time()+60*60*24*365);
}
mysql_query("UPDATE `user` SET `date_aut` = '$time', `date_last` = '$time' WHERE `id` = '$user[id]' LIMIT 1");
mysql_query("INSERT INTO `user_log` (`id_user`, `time`, `ua`, `ip`, `method`) values('$user[id]', '$time', '$user[ua]' , '$user[ip]', '1')");
}else{
$err='Неправильный логин или пароль!';
}
}
else if (isset($_COOKIE['id_user']) && isset($_COOKIE['pass']) && $_COOKIE['id_user'] && $_COOKIE['pass'])
{
if (mysql_result(mysql_query("SELECT COUNT(*) FROM `user` WHERE `id` = ".intval($_COOKIE['id_user'])." AND `pass` = '".shif(cookie_decrypt($_COOKIE['pass'],intval($_COOKIE['id_user'])))."' LIMIT 1"), 0)==1)
{
$user=get_user($_COOKIE['id_user']);
$_SESSION['id_user']=$user['id'];
mysql_query("UPDATE `user` SET `date_aut` = '$time', `date_last` = '$time' WHERE `id` = '".$user['id']."' LIMIT 1");
$user['type_input']='cookie';
}else{
$err='Ошибка авторизации по COOKIE!';
setcookie('id_user');
setcookie('pass');
}
}else{
$err='Ошибка авторизации!';
}
if (!isset($user))
{
$set['title']='Авторизация';
include_once 'sys/includes/header.php';
title();
auter();
err();
header('Refresh: 1; url=/aut.php');
echo "<a href='/aut.php?$passgen'><div class='foot'>";
echo "<b>Повторить попытку входа</b>";
echo "</div></a>";
include_once 'sys/inc/tfoot.php';
}
$set['title']='Дайджест';
if ($set['web'])
{
if (is_dir(H.'style/themes/'.$user['set_them2']))
{
$set['set_them']=$user['set_them2'];
}else{
mysql_query("UPDATE `user` SET `set_them2` = '".$set['set_them2']."' WHERE `id` = '".$user['id']."' LIMIT 1");
}
}else{
if (is_dir(H.'style/themes/'.$user['set_them']))
{
$set['set_them']=$user['set_them'];
}else{
mysql_query("UPDATE `user` SET `set_them` = '".$set['set_them']."' WHERE `id` = '".$user['id']."' LIMIT 1");
}
}
if (isset($_GET['return']))
{
header('Location: '.urldecode($_GET['return']));
}else{
header("Location: /hello.php?".SID);
}
exit;
?>