Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 5 12345 LastLast
Results 1 to 10 of 49
  1. #1
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default UserSystem v1.0.3

    Ok,

    UserSystem v1.0.3 has now been released and as well as cleaning up some vars better, its also loaded with some new features including VIP management, send furni, profiles, memberlist etc etc etc

    I've replaced htmlspecialchars with a clean function
    PHP Code:
    <?php
    function clean($str)
    {
    $st strip_tags(addslashes(stripslashes(htmlspecialchars($str))));
    return 
    $st;
    }
    ?>
    Hope thats sufficient Oo

    Anyways, heres link

    http://www.habbo-center.com/scripts/


    Please post any feedback
    Coming and going...
    Highers are getting the better of me

  2. #2
    Join Date
    Oct 2005
    Location
    Spain, Valencia
    Posts
    20,492
    Tokens
    3,575
    Habbo
    GoldenMerc

    Latest Awards:

    Default

    Could you do a list of all the features?

  3. #3
    Join Date
    Nov 2006
    Posts
    1,939
    Tokens
    0

    Latest Awards:

    Default

    any demos

  4. #4
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by GoldenMerc View Post
    Could you do a list of all the features?
    theyrs a full list of features on the download page

    Quote Originally Posted by TnYello™ View Post
    any demos
    Nope, havent got a demo set up yet due to all the CMS'y aspects of the script.
    Coming and going...
    Highers are getting the better of me

  5. #5
    Join Date
    Aug 2006
    Location
    United Kingdom
    Posts
    3,843
    Tokens
    1,121

    Latest Awards:

    Default

    Any demo available?

    Edit: okay, if anyone sets it up please do post Thanks

  6. #6
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    Grr! Tis still unsecure.

    You should use:

    http://www.php.net/mysql_real_escape_string
    "Note: If this function is not used to escape data, the query is vulnerable to SQL Injection Attacks."

    Plus why strip and add slashes again? If you are concerned that it is already stripped using magic quotes then just check magic_quotes_gpc to see if it is enabled...

  7. #7
    Join Date
    Oct 2005
    Location
    Spain, Valencia
    Posts
    20,492
    Tokens
    3,575
    Habbo
    GoldenMerc

    Latest Awards:

    Default

    Here are the features:
    Some Features of the system include:
    - Furni System
    - PM System
    - Badge System
    - Credits System
    - Automated VIP System
    - Mini-CMS
    - Easy to use admin options
    - Easy to use installer
    - Only need to edit ONE file.

  8. #8
    Join Date
    May 2006
    Posts
    1,797
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Tomm View Post
    Grr! Tis still unsecure.

    You should use:

    http://www.php.net/mysql_real_escape_string
    "Note: If this function is not used to escape data, the query is vulnerable to SQL Injection Attacks."

    Plus why strip and add slashes again? If you are concerned that it is already stripped using magic quotes then just check magic_quotes_gpc to see if it is enabled...
    magicquotes is enabled..
    Coming and going...
    Highers are getting the better of me

  9. #9
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    Errm.. magic quotes is dependant on the PHP configuration so unless you have magic powers to decide that people who run your usersystem has magic quotes enabled you should check first.

    Also please review the link about mysql_real_escape_string as if the end user's server runs a different char set to the default one then you could be exposing them to SQL injection.

    Quote Originally Posted by Cj555 View Post
    magicquotes is enabled..

  10. #10
    Join Date
    Jun 2006
    Location
    Nottingham
    Posts
    373
    Tokens
    0

    Default

    HabboStation.net/user1
    u: admin
    p: admin

    demo :]

Page 1 of 5 12345 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •