PDA

View Full Version : UserSystem v1.0.3



MrCraig
21-09-2007, 03:24 PM
Ok,

UserSystem v1.0.3 has now been released and as well as cleaning up some vars better, its also loaded with some new features including VIP management, send furni, profiles, memberlist etc etc etc

I've replaced htmlspecialchars with a clean function


<?php
function clean($str)
{
$st = strip_tags(addslashes(stripslashes(htmlspecialchar s($str))));
return $st;
}
?>


Hope thats sufficient Oo

Anyways, heres link

http://www.habbo-center.com/scripts/


Please post any feedback

GoldenMerc
21-09-2007, 03:25 PM
Could you do a list of all the features?

Puma
21-09-2007, 03:25 PM
any demos xD

MrCraig
21-09-2007, 03:27 PM
Could you do a list of all the features?

theyrs a full list of features on the download page :)


any demos xD

Nope, havent got a demo set up yet due to all the CMS'y aspects of the script.

Sunny.
21-09-2007, 03:27 PM
Any demo available?

Edit: okay, if anyone sets it up please do post :) Thanks

Tomm
21-09-2007, 03:33 PM
Grr! Tis still unsecure.

You should use:

http://www.php.net/mysql_real_escape_string
"Note: If this function is not used to escape data, the query is vulnerable to SQL Injection Attacks."

Plus why strip and add slashes again? If you are concerned that it is already stripped using magic quotes then just check magic_quotes_gpc to see if it is enabled...

GoldenMerc
21-09-2007, 03:33 PM
Here are the features:

Some Features of the system include:
- Furni System
- PM System
- Badge System
- Credits System
- Automated VIP System
- Mini-CMS
- Easy to use admin options
- Easy to use installer
- Only need to edit ONE file.

MrCraig
21-09-2007, 03:38 PM
Grr! Tis still unsecure.

You should use:

http://www.php.net/mysql_real_escape_string
"Note: If this function is not used to escape data, the query is vulnerable to SQL Injection Attacks."

Plus why strip and add slashes again? If you are concerned that it is already stripped using magic quotes then just check magic_quotes_gpc to see if it is enabled...

magicquotes is enabled..

Tomm
21-09-2007, 03:42 PM
Errm.. magic quotes is dependant on the PHP configuration so unless you have magic powers to decide that people who run your usersystem has magic quotes enabled you should check first.

Also please review the link about mysql_real_escape_string as if the end user's server runs a different char set to the default one then you could be exposing them to SQL injection.


magicquotes is enabled..

headboard
21-09-2007, 03:46 PM
HabboStation.net/user1
u: admin
p: admin

demo :]

MrCraig
21-09-2007, 03:47 PM
HabboStation.net/user1
u: admin
p: admin

demo :]

ty ;)

6chars..

LegendOfNoob
21-09-2007, 03:51 PM
Very Nice Script +Rep(Or Atleast ill try)

Been Looking For Something Like This for my fansite :]

MrCraig
21-09-2007, 03:54 PM
Ty :)

Rep returned

LegendOfNoob
21-09-2007, 04:02 PM
OFf Topic: Added Rep when figured out on Your Ty Rep Returned Post

and now trying on my site just downlaoded it

Luke
21-09-2007, 04:11 PM
nice of you to gicve this out for free

although i dislike the template, maybe make a proper habbo template?

Puma
21-09-2007, 04:53 PM
nice of you to gicve this out for free

although i dislike the template, maybe make a proper habbo template?

ditto that and i really dnt lyk the navigator aswell.. try changing it but overall everything is nice..

:Edzy
21-09-2007, 05:04 PM
Quite nice and useful, could do with skin tho :)

MrCraig
22-09-2007, 02:22 PM
nice of you to gicve this out for free

although i dislike the template, maybe make a proper habbo template?


ditto that and i really dnt lyk the navigator aswell.. try changing it but overall everything is nice..


Quite nice and useful, could do with skin tho :)


Thanks ;)

With regards to the skinning of it, I was really concentrating on making something that works before i did skin and one of the main reasons i made it open-source is so people could be creative with it.

But yh, when i get round to making a skin for it, i will :)

Invent
22-09-2007, 02:42 PM
This is still VERY insecure, I think you need to learn more about php security.

abnormal
22-09-2007, 03:22 PM
disco-tragedy.org/habbgeeks/index.php

er. wth?

Jebbo
22-09-2007, 03:48 PM
Very Nice Script +Rep ;)

GoldenMerc
22-09-2007, 03:50 PM
Your IP was NOT logged
Ah whats the point in that?

Codex
22-09-2007, 03:53 PM
Ah whats the point in that?
So it tells someone who has nothing to do they can have as many admin sign in attempts without ever being known.

MrCraig
22-09-2007, 05:03 PM
Ah whats the point in that?

IP logging can be enabled/disabled through the System Prefrences page, If IP logging is enabled, Your IP: -Your IP Here- will be displayed.


So it tells someone who has nothing to do they can have as many admin sign in attempts without ever being known.

Haha, funny :S

GoldenMerc
22-09-2007, 05:04 PM
Sorry but thats pretty pointless

Invent
22-09-2007, 05:05 PM
Their IP is stored in a hidden field?

I LOL'D.

MrCraig
22-09-2007, 05:07 PM
disco-tragedy.org/habbgeeks/index.php

er. wth?

It would help if you ran the installer...


+
yh simon, coded login page ages ago.

abnormal
22-09-2007, 05:08 PM
It would help if you ran the installer...


+
yh simon, coded login page ages ago.

I did. =[

Invent
22-09-2007, 05:08 PM
If the IP is taken from the hidden input field.

Then that is the most idiotic thing EVER.

MrCraig
22-09-2007, 05:10 PM
I did. =[

did u edit the config.php file to your database details?


If the IP is taken from the hidden input field.

Then that is the most idiotic thing EVER.

Il change it now Oo

abnormal
22-09-2007, 05:11 PM
Si, Senor.
xD

MrCraig
22-09-2007, 05:15 PM
Thats weird then :S

it works fine for everyone else..

abnormal
22-09-2007, 05:20 PM
Can you install it for me?

MrCraig
22-09-2007, 05:22 PM
Can you install it for me?

Theres no reason it shouldnt work for you...

Try deleting the database, remaking and reinstalling it.

Ed.
22-09-2007, 05:23 PM
Can I see a Demo of this as I still dont understand what the hell it is :p

MrCraig
22-09-2007, 05:24 PM
Can I see a Demo of this as I still dont understand what the hell it is :p

Ed, il set one up now for you, give me 2 mins and il pm when done.

Ed.
22-09-2007, 05:25 PM
Thanks Babe:D

abnormal
22-09-2007, 05:28 PM
Still not working.
</3

MrCraig
22-09-2007, 05:30 PM
prudence, i just installed one in under a minute there.. theres nothing wrong with the script, so either your not installing it correctly, or your server does not meet the requirements needed to run it.

GoldenMerc
22-09-2007, 05:32 PM
Could you show me a demo aswell xo

Ed.
22-09-2007, 05:33 PM
Its kl but whats the point of it?

abnormal
22-09-2007, 05:33 PM
You don't have to be rude...

Ed.
22-09-2007, 05:36 PM
Im not - Its good but whats the point of it - what u meant to use it for

MrCraig
22-09-2007, 05:37 PM
Merc, il set you up a demo acc now :)

abnormal
22-09-2007, 05:39 PM
CJ.
Set me up a demo also?

MrCraig
22-09-2007, 05:44 PM
k, pm'd you both. :)

mousey
22-09-2007, 05:50 PM
Sj55 set me aswell please i may use

GoldenMerc
22-09-2007, 05:53 PM
Its quite nice but the layout is well discusting and it does need more features but i suppose it could be a beginer site ;)b

MrCraig
22-09-2007, 05:56 PM
I know about the layout :P

I posted something about it 2 pages or so back, or i didnt and im going weird..

But thanks :) And if you have any feature requests, pm me :)

Want to hide these adverts? Register an account for free!