Results 1 to 5 of 5
  1. #1
    Join Date
    Dec 2006
    Location
    Swindon
    Posts
    3,299
    Tokens
    215
    Habbo
    dunko

    Latest Awards:

    Default UserSystem - by Froobe

    I made a free, simple, open-source usersystem:

    Features:
    • Login
    • Register
    • Logout
    • Install


    Files:
    • index.php
    • installer.php
    • style.css
    • inc/
    • inc/config.php
    • inc/usersystem.class.php


    Link:

    http://www.uploadz.co.uk/703usersystem.rar

    Password:

    Code:
    froobe
    Please enjoy.

    To install go to "index.php"

    Sorry about the page titles. I forgot to edit them...
    Last edited by Blob; 27-07-2007 at 11:30 AM.

  2. #2
    Join Date
    Aug 2005
    Location
    Tunbridge Wells, Kent
    Posts
    5,063
    Tokens
    1,624

    Latest Awards:

    Default

    Nice welldone =]
    Never argue with an idiot, he'll drag you down to his level, and beat you with experience.

    Quote Originally Posted by Recursion
    *oh trust me
    *I would NEVER go ATi
    And 15 mins later...
    Sapphire ATI Radeon HD 5850 1024MB GDDR5 PCI-Express Graphics Card £195.73 1 £195.73
    *ordered.

  3. #3
    ScottDiamond. Guest

    Default

    Well done on helping out people. I may use it for a clients' Members Area.

  4. #4
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    Errm hate to burst your bubble but its unsecure.

    Atleast use mysql_real_escape_string and check if magic_quotes_gpc if enabled else you'll end up adding slashes twice.

    Example source:

    PHP Code:
    SELECT FROM users WHERE user='aidan' AND password='' OR ''='' 
    Cba to add dynamic crap.

    But it should not let this query run as I typed it as it would let me login as anyone I want without knowing the password...

    It returns:

    SELECT * FROM users WHERE user='aidan' AND password='' OR ''=''

    As I typed it....

    Another example:

    $ryan = new UserSystem();

    $test = "UPDATE `users` SET `password`='lolowned' WHERE `username`='admin';";
    echo $ryan->clean($test);

    Returns:

    UPDATE `users` SET `password`='lolowned' WHERE `username`='admin';
    Last edited by Tomm; 27-07-2007 at 12:02 PM.

  5. #5
    Join Date
    Aug 2005
    Location
    Tunbridge Wells, Kent
    Posts
    5,063
    Tokens
    1,624

    Latest Awards:

    Default

    *bubble burst*
    Never argue with an idiot, he'll drag you down to his level, and beat you with experience.

    Quote Originally Posted by Recursion
    *oh trust me
    *I would NEVER go ATi
    And 15 mins later...
    Sapphire ATI Radeon HD 5850 1024MB GDDR5 PCI-Express Graphics Card £195.73 1 £195.73
    *ordered.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •