<?php
//([^\.])(\/)?(.)*
//if (!preg_match('/^(http:\/\/)(Бойцовский Клуб\.|top\.|admin\.|test\.)?(capitallcity.ru)((\/(.)*)|(\b))/i',trim($_SERVER['HTTP_REFERER']))>0) die("Для входа в игру воспользуйтесь этой ссылкой: <a href='http://oldcombats.be'>http://oldcombats.be</a>".$_SERVER['HTTP_REFERER']);
//http://scrolls.combats.com/~Taxman/449125.html
include "connect.php";
session_start();
if($_POST['code'] && $_SESSION['sid'] && $_SESSION['puid'] && $_SESSION['stap']){
$data4 = mysql_fetch_array(mysql_query("SELECT pass2,pass FROM `users` WHERE `id` = '".mysql_real_escape_string($_SESSION['puid'])."' LIMIT 1;"));
if(md5($_POST['code'])==$data4['pass2']){
$chkps1="yes";
}else{$koko="<FONT COLOR=\"white\">Неверный пароль</FONT>
";}
}
if(($chkps1=="yes" or $koko) && $_SESSION['stap']==$data4['pass']){
$_SESSION['stap'] = addslashes($_SESSION['stap']);
$data = mysql_fetch_array(mysql_query("SELECT * FROM `users` WHERE `id` = '".mysql_real_escape_string($_SESSION['puid'])."' AND `pass` = '".mysql_real_escape_string($_SESSION['stap'])."' LIMIT 1;"));
}else{
$data = mysql_fetch_array(mysql_query("SELECT * FROM `users` WHERE `login` = '".mysql_real_escape_string($_POST['login'])."' AND `pass` = '".md5($_POST['psw'])."' LIMIT 1;"));
}
if($data['incity']=='angelscity'){echo"<form method=\"POST\" name=\"rdrt\" action=\"http://angelscity.oldcombats.be/enter.php\"><input type=\"hidden\" name=\"login\" value=\"".$data['login']."\"><input type=\"hidden\" name=\"psw\" value=\"".$_POST['psw']."\"></form><script>document.forms.rdrt.submit();</script>";exit();}
elseif($data['incity']=='oldcity'){echo"<form method=\"POST\" name=\"rdrt\" action=\"http://oldcity.oldcombats.be/enter.php\"><input type=\"hidden\" name=\"login\" value=\"".$data['login']."\"><input type=\"hidden\" name=\"psw\" value=\"".$_POST['psw']."\"></form><script>document.forms.rdrt.submit();</script>";exit();}
elseif($data['incity']=='demonscity'){echo"<form method=\"POST\" name=\"rdrt\" action=\"http://demonscity.oldcombats.be/enter.php\"><input type=\"hidden\" name=\"login\" value=\"".$data['login']."\"><input type=\"hidden\" name=\"psw\" value=\"".$_POST['psw']."\"></form><script>document.forms.rdrt.submit();</script>";exit();}
elseif($data['incity']=='devilscity'){echo"<form method=\"POST\" name=\"rdrt\" action=\"http://devilscity.oldcombats.be/enter.php\"><input type=\"hidden\" name=\"login\" value=\"".$data['login']."\"><input type=\"hidden\" name=\"psw\" value=\"".$_POST['psw']."\"></form><script>document.forms.rdrt.submit();</script>";exit();}
elseif($data['incity']=='emeraldscity'){echo"<form method=\"POST\" name=\"rdrt\" action=\"http://emeraldscity.oldcombats.be/enter.php\"><input type=\"hidden\" name=\"login\" value=\"".$data['login']."\"><input type=\"hidden\" name=\"psw\" value=\"".$_POST['psw']."\"></form><script>document.forms.rdrt.submit();</script>";exit();}
elseif($data['incity']=='dungeon'){echo"<form method=\"POST\" name=\"rdrt\" action=\"http://dungeon.oldcombats.be/enter.php\"><input type=\"hidden\" name=\"login\" value=\"".$data['login']."\"><input type=\"hidden\" name=\"psw\" value=\"".$_POST['psw']."\"></form><script>document.forms.rdrt.submit();</script>";exit();}
elseif($data['incity']=='suncity'){echo"<form method=\"POST\" name=\"rdrt\" action=\"http://suncity.oldcombats.be/enter.php\"><input type=\"hidden\" name=\"login\" value=\"".$data['login']."\"><input type=\"hidden\" name=\"psw\" value=\"".$_POST['psw']."\"></form><script>document.forms.rdrt.submit();</script>";exit();}
elseif ($data[0] == null) {
//mysql_query("INSERT INTO `iplog` (owner,ip,date,type) values ('".mysql_real_escape_string($data['id'])."','".mysql_real_escape_string($ip)."','".mysql_real_escape_string($time_now)."','1');");
echo "<html><head><META http-equiv=Content-type content='text/html; charset=windows-1251'><title>Произошла ошибка</title></head><body>
Произошла ошибка!
Неверный пароль, войдите с <a href=index.php>главной страницы</a>.
<hr><table width=100%><tr><td align=left>[b][url="'java"]Назад[/url][/b]</td><td align=right>(C) [u]Бойцовский Клуб[/u]</td></tr></table></body></html>";
}
elseif($data['block']==1)
{
echo "<html><head><META http-equiv=Content-type content='text/html; charset=windows-1251'><title>Произошла ошибка</title></head><body>
Произошла ошибка!
Персонаж заблокирован.
<hr><table width=100%><tr><td align=left>[b][url="'java"]Назад[/url][/b]</td><td align=right>(C) Бойцовский Клуб </td></tr></table></body></html>";
}
else
{
include("functions.php");
if(($chkps1!="yes") or empty($koko)){
session_destroy();
session_start();
//delo_multi
if($_COOKIE['battle']!= null && $data['id'] != $_COOKIE['battle']) {
mysql_query("INSERT INTO `delo_multi` (`idperslater`,`idpersnow`) values ('".mysql_real_escape_string($_COOKIE['battle'])."','".mysql_real_escape_string($data['id'])."');");
}
///
setcookie("battle", $data['id']);
$_SESSION['puid'] = $data['id'];
$_SESSION['sid'] = session_id();
if(!empty($data['pass2'])){$_SESSION['stap'] = $data['pass'];}
}
if($_SESSION['sid'] && $_SESSION['puid'] && $_SESSION['stap']==$data['pass'] && $chkps1!="yes"){
?>
<HTML><HEAD>
<link rel=stylesheet type="text/css" href="http://img.combats.com/i/main.css">
<meta content="text/html; charset=windows-1251" http-equiv=Content-type>
<META Http-Equiv=Cache-Control Content=no-cache>
<meta http-equiv=PRAGMA content=NO-CACHE>
<META Http-Equiv=Expires Content=0>
<TITLE>Второй пароль</TITLE>
</HEAD>
<body bgcolor=666666>
<H3><FONT COLOR="black">Запрос второго пароля к персонажу.</FONT></H3>
<?=$koko?>
<div align="center">
<object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,0,0" width="600" height="250">
<param name=movie value="http://img.oldcombats.be/i/psw2.swf">
<param name=quality value=high>
</object>
[/QUOTE]
</BODY>
</HTML>
<?
include("mail_ru.php");
exit();
}
$_SESSION['uid'] = $data['id'];
$_SESSION['incity'] = $data['incity'];
setcookie("uid",$data['id'],time()+43200,"/",".oldcombats.be");
setcookie("hashcode",md5($data['id'].$data["pass"].$data["login"]),time()+43200,"/",".oldcombats.be");
unset($_SESSION['stap']);
unset($_SESSION['puid']);
mysql_query("UPDATE `online` SET `date` = ".time()." WHERE `id` = '".mysql_real_escape_string($data['id'])."';");
mysql_query("UPDATE `users` SET `sid` = '".session_id()."' WHERE `id` = '".mysql_real_escape_string($data['id'])."';");
//mysql_query("UPDATE `users` SET `ip` = '".$_SERVER['REMOTE_ADDR']."' WHERE `id` = {$data['id']};");
if (!empty($_SERVER['HTTP_CLIENT_IP'])) //check ip from share internet
{
$ip=$_SERVER['HTTP_CLIENT_IP'];
}
elseif (!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) //to check ip is pass from proxy
{
$ip=$_SERVER['HTTP_X_FORWARDED_FOR'];
}
else
{
$ip=$_SERVER['REMOTE_ADDR'];
}
$time_now=time();
//системка
$ll = mysql_fetch_array(mysql_query('SELECT * FROM `iplog` WHERE `owner` = "'.$data['id'].'" ORDER BY `id` DESC LIMIT 1'));
if(isset($ll['id']))
{
if($ll['ip']!=$ip)
{
addchp ('<font color="Black"><font color=red>Внимание!</font> '.date('d.m.Y H:i').' <font color=red>[b]ВНИМАНИЕ![/b]</font> В предыдущий раз этим персонажем заходили с другого компьютера. '.$ll['ip'].'.</font>','{[]}'.$data['login'].'{[]}');
}
}
//конец системки
mysql_query("INSERT INTO `iplog` (owner,ip,date,type) values ('".mysql_real_escape_string($data['id'])."','".mysql_real_escape_string($ip)."','".mysql_real_escape_string($time_now)."','0');");
$drugi1 = mysql_query("SELECT user FROM `friends` WHERE `friend` = '".mysql_real_escape_string($data['id'])."';");
while ($drugi = mysql_fetch_array($drugi1)) {
$dat = mysql_fetch_array(mysql_query("SELECT `login`, `room`, (select `id` from `online` WHERE `date` >= ".(time()-60)." AND `id` = users.`id`) as `online` FROM `users` WHERE `id` = '".mysql_real_escape_string($drugi['user'])."' LIMIT 1;"));
if($dat['online']>0){
addchp ('<font color=red>[b]Вимание![/b]</font> <font color="Black">Вас приветствует [url="java"]'.$data['login'].'[/url]</font>','{[]}'.nick7 ($drugi['user']).'{[]}');
}
}
$rs=mysql_query("SELECT * FROM `telegraph` WHERE `owner` = '".mysql_real_escape_string($data['id'])."';");
mysql_query("DELETE FROM `telegraph` WHERE `owner` = '".mysql_real_escape_string($data['id'])."';");
while($r = mysql_fetch_array($rs)) {
addchp ($r['text'],'{[]}'.$data['login'].'{[]}');
}
header("Location:battle.php");
}
?>