include("includes/config.php"); include("includes/functions.php"); session_start(); include("includes/session.php"); $Session = new Session(); $Session->read(); foreach($_GET as $var => $val) { $get[$var] = @stripslashes(trim($val)); $get_safe[$var] = @mysql_escape_string($get[$var]); } foreach($_POST as $var => $val) { $post[$var] = @stripslashes(trim($val)); $post_safe[$var] = @mysql_escape_string($post[$var]); } $user_ip = GetIP(); if (isset($_COOKIE["sess_key"]) && !isset($_SESSION["user"]["id"])) { $GetLogInfo = mysql_query("SELECT user_id from sessions where sess_key = '".addslashes($_COOKIE["sess_key"])."'") or print(mysql_error() . " " . __FILE__ . " #" . __LINE__); if(mysql_num_rows($GetLogInfo) == 1) { $_SESSION["user"]["id"] = mysql_result($GetLogInfo, 0); } @mysql_free_result($GetLogInfo); } if(isset($_SESSION["user"]) || $_SESSION["user"]["id"] != ""){ $loggedin = true; $sess_user_id = $_SESSION["user"]["id"]; $sess_user_status = $_SESSION["user"]["status"]; $CharacterInfo = GetCharacterInfo($sess_user_id); $WeaponInfo = GetWeaponInfo($CharacterInfo); $ArmourInfo = GetArmourInfo($CharacterInfo); $strMod = ceil($CharacterInfo['strength'] / 2); } $population = mysql_query("SELECT COUNT(id) from users WHERE status > 0") or print(mysql_error() . " " . __FILE__ . " #" . __LINE__); $population = mysql_result($population, 0); $online = mysql_query("SELECT COUNT(id) FROM sessions WHERE (UNIX_TIMESTAMP() - last_update) < 7200") or print(mysql_error() . " " . __FILE__ . " #" . __LINE__); $online = mysql_result($online, 0); $page = $_GET["page"]; $page = str_replace("../", "", $page); // no backtracking! $page = str_replace("./", "", $page); // Stop it!! $page = str_replace("/", "", $page); // Im gonna hurt you.. $page = str_replace(substr(strrchr($page,"."),1), "",$page); // remove extention... no page.html or anyhting fruity like .zip if(file_exists("./pages/$page.php")){ if(file_exists("./includes/{$page}_functions.php")){ include("./includes/{$page}_functions.php"); } } if($loggedin){ //get alerts & messages $AQ = mysql_query("SELECT COUNT(id) FROM alerts WHERE receiver_id = '{$CharacterInfo['id']}' AND seen = '0'") or print(mysql_error() . " " . __FILE__ . " #" . __LINE__); if(mysql_result($AQ, 0) > 0){ $Alert = true; } $MQ = mysql_query("SELECT COUNT(id) FROM messages WHERE receiver_id = '{$CharacterInfo['id']}' AND seen = '0'") or print(mysql_error() . " " . __FILE__ . " #" . __LINE__); if(mysql_result($MQ, 0) > 0){ $Message = true; } } ?>
Hello, =$CharacterInfo["name"];?>! | |||
Weapon: | =$WeaponInfo["name"];?> | Armour: | =$ArmourInfo["name"];?> |
Hit Points: | =$CharacterInfo["now_hp"]."/".$CharacterInfo["max_hp"];?> | Level: | =$CharacterInfo['level'];?> |
Exp: | =$CharacterInfo['exp'];?> | Money: | =format($CharacterInfo['money']);?> KD |
Logout |