Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Results 1 to 10 of 10

Thread: Form Help

  1. #1
    Join Date
    Sep 2007
    Location
    USA
    Posts
    474
    Tokens
    0

    Default Form Help

    i would like to host and make my own form i know i knwo freedback
    they radomly banned me i have the same coding as when i got it and didnt change...
    how would i go about doing this i laready made my contact us form but this may be a bit harder i need to do like
    (short)Habbo Name:
    (short)Email:
    (short)Program Used
    (drop Down)Applying For:
    (long)Qualifications:
    (long)Why Should We Hire You?
    and then i'm used to feedback could i have ip details sent in with apps?
    Post Meter
    ______________________________________________
    400 450 500 550 600 650 700 750 800 850 900-1k
    Green=Done | Orange=Almost | Red=Not Done
    ______________________________________________
    Habbo fury Coming Soon!
    My Img tag has ran away

  2. #2
    Join Date
    Nov 2006
    Location
    Cheshire.
    Posts
    730
    Tokens
    250

    Default

    You do a hidden form for the IP
    PHP Code:
    <input type="hidden" id="" name="" value="<?php echo $_SERVER["REMOTE_ADDR"]; ?>" />


    Give us an add like!

  3. #3
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    <input type="hidden" id="" name="" value="<?php echo $_SERVER["REMOTE_ADDR"]; ?>" />
    Never, ever, ever...ever do that.

  4. #4
    Join Date
    Sep 2007
    Location
    USA
    Posts
    474
    Tokens
    0

    Default

    why? :S
    Post Meter
    ______________________________________________
    400 450 500 550 600 650 700 750 800 850 900-1k
    Green=Done | Orange=Almost | Red=Not Done
    ______________________________________________
    Habbo fury Coming Soon!
    My Img tag has ran away

  5. #5
    Join Date
    Sep 2006
    Location
    Hobart, Australia
    Posts
    593
    Tokens
    0

    Default

    In the case of hiding an IP input, don't, because simply, there is no point. You can just call for $_SERVER['REMOTE_ADDR'] when you process the script, it's not going to change.

    Hidden inputs are fine for passing things such as IDs to other pages though.

  6. #6
    Join Date
    Oct 2007
    Location
    Luton, England
    Posts
    1,548
    Tokens
    388
    Habbo
    DeejayMachoo

    Latest Awards:

    Default

    Quote Originally Posted by Invent View Post
    Never, ever, ever...ever do that.
    wouldnt it be better to do it in the sql query?


  7. #7
    Join Date
    Sep 2006
    Location
    Hobart, Australia
    Posts
    593
    Tokens
    0

    Default

    Quote Originally Posted by Mattx.org View Post
    wouldnt it be better to do it in the sql query?
    That's what I trying to get across above ^^

    Before someone bites my head off for saying it's fine, obviously if you don't check it's a valid ID, or whether a certain user has permission to do stuff with the ID, you're in trouble. Bottom rule, even if it's defined by you (dropdowns, hidden form inputs etc), sanitize it!

  8. #8
    Join Date
    May 2005
    Location
    San Francisco, CA
    Posts
    7,160
    Tokens
    2,331

    Latest Awards:

    Default

    If the IP used was read from the form then it is bad. That's because you can use memory editors/livebug/etc to alter input forms to any value you like.

  9. #9
    Join Date
    Jul 2005
    Location
    -
    Posts
    2,995
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Invent View Post
    If the IP used was read from the form then it is bad. That's because you can use memory editors/livebug/etc to alter input forms to any value you like.
    could of swore the was a way of doing that through url i may be wrong :S

  10. #10
    Join Date
    Sep 2006
    Location
    Hobart, Australia
    Posts
    593
    Tokens
    0

    Default

    Quote Originally Posted by Jamie. View Post
    could of swore the was a way of doing that through url i may be wrong :S
    If the form is using GET instead of POST, you can change the values of the form fields. However, if you're not sanitizing your GET inputs, you're asking for trouble.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •