talvez a pagina php de um serevr de GunBound seja semelhante a uma de mu
register.php
CODE
<html>
<head>
<title>Documento sem título</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body bgcolor="#000000" text="#FFFFFF">
<?PHP
include("config.php");
?>
<TABLE width="294" border=0 cellPadding=5 cellSpacing=1 bgcolor="#000000" dwcopytype="CopyTableRow">
<!--DWLayoutTable-->
<FORM method=post name=regform action=idreg.php>
<TBODY>
<TR class="content">
<TD width="127" height="32" align=right valign="top"> <DIV align=left><font>Login</font></DIV>
</TD>
<TD width="144" valign="top"> <INPUT name=ps_loginname id="ps_loginname" class="lanyu" size=12 maxLength=10>
<B></B></TD>
</TR>
<TR class="content">
<TD height="32" align=right valign="top"> <DIV align=left><font>Nome</font></DIV>
</TD>
<TD valign="top"> <INPUT name=ps_name id="ps_name" class="lanyu" size=12 maxLength=10>
<B></B></TD>
</TR>
<TR class="content">
<TD height="32" valign="top"><font>Senha</font></TD>
<TD valign="top"> <INPUT name=ps_password id="ps_password" type=password class="lanyu" size=8 maxLength=10>
<B></B></TD>
</TR>
<TR class="content">
<TD height="32" valign="top">Senha Novamente</TD>
<TD valign="top"> <INPUT name=ps_repassword type=password id="ps_repassword" class="lanyu"
size=8 maxLength=10>
</TD>
</TR>
<TR class="content">
<TD height="32" valign="top"><font>E-mail</font></TD>
<TD valign="top"> <INPUT name=ps_email class="lanyu" id="ps_email" size="20" maxLength=40>
</TD>
</TR>
<TR class="content">
<TD height="32" valign="top"><font>Numero Bau</font></TD>
<TD valign="top"><INPUT class=lanyu maxLength=12 name=ps_person_id id="ps_person_id" size="20">
</TD>
</TR>
<TR class="content">
<TD height="32" valign="top"><font>Pergunta Secreta</font></TD>
<TD valign="top"> <INPUT name=ps_recquest id="ps_recquest" class="lanyu" size=8 maxLength=15>
</TD>
</TR>
<TR class="content">
<TD height="48" valign="top"><font>Resposta Secreta</font></TD>
<TD valign="top"> <INPUT name=ps_recans id="ps_recans" class="lanyu" size=8 maxLength=15>
</TD>
</TR>
<TR class="content">
<TD height="31"
colSpan=2 valign="top"><div align="left"><img src="images/reg.gif" width="40" height="17" border="0" class="hand" onclick="<?php print "$regsubmit"; ?>" > <img src="images/reg1.gif" width="40" height="17" class="hand" onclick="regform.reset()"></div>
</TD>
</TR>
<TR class="content">
<TD height="2"></TD>
<TD></TD>
</TR>
</form>
</table>
</body>
</html>
idreg.php
CODE
<html>
<head>
<LINK REL="StyleSheet" HREF="style.css" TYPE="text/css">
</head>
<body>
<?PHP include("config.php"); ?>
<table border="0" cellspacing="0" cellpadding="0" width="180">
<tr>
<td>
<TABLE width="480" height=100% border=0 align=center cellPadding=5 cellSpacing=1 bgcolor="#000000">
<TBODY>
<TR bgcolor="#000000" class="content">
<TD colSpan=2 align=right> <div align="center" class="bigf Estilo5">
<?php
require 'config.php';
include_once('sql_check.php');
check_inject();
$msconnect=mssql_connect("$dbhost","$dbuser","$dbpasswd");
$msdb=mssql_select_db("MuOnline",$msconnect);
$ps_loginname = stripslashes($_POST['ps_loginname']);
$ps_name = stripslashes($_POST['ps_name']);
$ps_email = stripslashes($_POST['ps_email']);
$ps_person_id = stripslashes($_POST['ps_person_id']);
$ps_password = stripslashes($_POST['ps_password']);
$ps_repassword = stripslashes($_POST['ps_repassword']);
$ps_recquest = stripslashes($_POST['ps_recquest']);
$ps_recans = stripslashes($_POST['ps_recans']);
$extcode = stripslashes($_POST['extcode']);
$extcode1 = stripslashes($_POST['extcode1']);
if ((eregi("[^a-zA-Z0-9_-]", $ps_loginname)) || (eregi("[^a-zA-Z0-9_-]", $ps_name)) ||
(eregi("[^a-zA-Z0-9\.@_-]", $ps_email)) ||
(eregi("[^a-zA-Z0-9_-]", $ps_person_id)) ||
(eregi("[^a-zA-Z0-9_-]", $ps_password)) ||
(eregi("[^a-zA-Z0-9_-]", $ps_repassword)) ||
(eregi("[^a-zA-Z0-9_-]", $ps_recquest)) ||
(eregi("[^a-zA-Z0-9_-]", $ps_recans)) ||
(eregi("[^a-zA-Z0-9_-]", $extcode)) ||
(eregi("[^a-zA-Z0-9_-]", $extcode1)) )
{
echo("SQL Injection Detected. Make sure to ONLY use letters (a-Z) and numbers (0-9)!");
exit();
}
$msconnect=mssql_connect("$dbhost","$dbuser","$dbpasswd");
$msdb=mssql_select_db("MuOnline",$msconnect);
$sql_email_check = mssql_query("SELECT mail_addr FROM MEMB_INFO WHERE mail_addr='$ps_email'");
$sql_username_check = mssql_query("SELECT memb___id FROM MEMB_INFO WHERE memb___id='$ps_loginname'");
$email_check = mssql_num_rows($sql_email_check);
$username_check = mssql_num_rows($sql_username_check);
if (empty($ps_loginname) || empty($ps_name) || empty($ps_email) || empty($ps_person_id) || empty($ps_password) || empty($ps_repassword) || empty($ps_recquest) || empty($ps_recans) ) {
echo "Por Favor<br />Preencha todos os campos para depois apertar OK."; $Error=1;
}
elseif (($email_check > 0) || ($username_check > 0)){
echo "Please fix the following errors: <br />";
if($email_check > 0){
echo "<strong>Your email address has already been used by another member
in our database. Please submit a different Email address!<br />";
$Error=1;
}
if ($username_check > 0){
echo "The username you have selected has already been used by another member
in our database. Please choose a different Username!<br />";
$Error=1;
}
}
elseif ($ps_password != $ps_repassword) {
echo "Please fix the following error:<br />The passwords you entered do not match."; $Error=1;
}
elseif ($extcode != $extcode1) {
echo "Please fix the following error:<br />You entered a bad code."; $Error=1;
}
if ($Error!=1){
$msquery2 = "SET IDENTITY_INSERT MEMB_INFO ON";
$msquery3 = "INSERT INTO MEMB_INFO (memb_guid,memb___id,memb__pwd,memb_name,sno__numb,post_code,addr_info,addr_deta,tel__numb,mail_addr,phon_numb,fpas_ques,fpas_answ,job__code,appl_days,modi_days,out__days,true_days,mail_chek,bloc_code,ctl1_code) VALUES ('1','$ps_loginname','$ps_password','$ps_name', '1','1234','11111','$ps_person_id','12343','$ps_email','$ps_email','$ps_recquest','$ps_recans','1','2003-11-23','2003-11-23','2003-11-23','2003-11-23','1','0','1')";
$msquery4 = "INSERT INTO VI_CURR_INFO (ends_days,chek_code,used_time,memb___id,memb_name,memb_guid,sno__numb,Bill_Section,Bill_value,Bill_Hour,Surplus_Point,Surplus_Minute,Increase_Days ) VALUES ('2005','1',1234,'$ps_loginname','$ps_name',1,'7','6','3','6','6','2003-11-23 10:36:00','0' )";
$msresults= mssql_query($msquery2);
$msresults= mssql_query($msquery3);
$msresults= mssql_query($msquery4);
?>
</div></TD>
</TR>
<div align="center">
<TR bgcolor="#000000" class="content">
<TD height=2 colSpan=2 align=center>Sua conta foi criada com secesso.<br></TD></TR>
<TR bgcolor="#ffffff" class="content">
<TD width="88" align=right valign="top" bgcolor="#000000"> <DIV align=left>Login:</DIV></TD>
<TD width="354" bgcolor="#000000"><B><?php print "$ps_loginname"; ?></B>
<DIV align=center></DIV></TD>
</TR>
<TR bgcolor="#ffffff" class="content">
<TD width="88" align=right valign="top" bgcolor="#000000"> <DIV align=left>Nome:</DIV></TD>
<TD width="354" bgcolor="#000000"><B><?php print "$ps_name"; ?></B>
<DIV align=center></DIV></TD>
</TR>
<TR bgcolor="#ffffff" class="content">
<TD width="88" align=right valign="top" bgcolor="#000000"> <DIV align=left>E-mail:</DIV></TD>
<TD width="354" bgcolor="#000000"><B><?php print "$ps_email"; ?></B>
<DIV align=center></DIV></TD>
</TR>
<TR bgcolor="#ffffff" class="content">
<TD width="88" align=right valign="top" bgcolor="#000000"> <DIV align=left>Senha:</DIV></TD>
<TD width="354" bgcolor="#000000"><B><?php print "$ps_password"; ?></B>
<DIV align=center></DIV></TD>
</TR>
<TR bgcolor="#ffffff" class="content">
<TD width="88" align=right valign="top" bgcolor="#000000"> <DIV align=left>Pergunta
Secreta:</DIV></TD>
<TD width="354" bgcolor="#000000"><B><?php print "$ps_recquest"; ?></B>
<DIV align=center></DIV></TD>
</TR>
<TR bgcolor="#ffffff" class="content">
<TD width="88" align=right valign="top" bgcolor="#000000"> <DIV align=left>Resposta
Secreta:</DIV></TD>
<TD width="354" bgcolor="#000000"><B><?php print "$ps_recans"; ?></B>
<DIV align=center></DIV></TD>
</TR>
<TR bgcolor="#ffffff" class="content">
<TD width="88" align=right valign="top" bgcolor="#000000"> <DIV align=left>Numero:</DIV></TD>
<TD width="354" bgcolor="#000000"><B><?php print "$ps_person_id"; ?></B>
<DIV align=center></DIV></TD>
</TR>
</div>
</TABLE>
</td>
</tr>
</table>
</body>
</html>
<?php
}
?>
Config.php
CODE
<?php
//=============== Area com alguns configs importantes ====================
$dbhost = "127.0.0.1";
// Seu usuario do database (tradicionar sa)
$dbuser = "HelpAssistent";
// Entre com a senha do seu usuario do database.
$dbpasswd = "123456";
// Ip onde o sql esta instalado (tradicional 127.0.0.1)
$host = "127.0.0.1";
// Não mude isso!
$port = "55901";
// Tipo de reset, não mexa!
$reset_reward=points;
// Pontos ganhos por reset.
$reset_points=350;
// Não mexa nisso!
$reset_zen=1;
//=============== Não edite essa area ====================
$alogin = $dbuser;
$apass = $dbpasswd;
$db = 'MuOnline';
$regsubmit = "regform.submit()";
$msconnect=mssql_connect("$host","$alogin","$apass");
$msdb=mssql_select_db("$db",$msconnect);
$ip = $host;
//=============== Edite essa area com seus dados do sql ====================
$dbhost = "127.0.0.1";
$dbuser = "HelpAssistent"; //LOGIN DO SQL
$dbpasswd = "123456"; //SENHA DO SQL
$msconnect=@mssql_connect("$dbhost","$dbuser","$dbpasswd") or die ('ERRO! TENTE MAIS TARDE!');
$msdb=@mssql_select_db("MuOnline",$msconnect) or die ('ERRO! TENTE MAIS TARDE!');
//=============== Area que configura os dados do servidor ====================
$server_name = "MuSkiTos"; //Server Name Não coloque nomes grandes utilize apenas o nome principal
$server_version = "0.97d+99"; //Server Version
$server_ip = "playgames.servegame.com"; //Server IP/DNS
$server_port = "NoLaucher"; //Server Port
$server_exp = "350x"; //Server Experience
$server_drop = "50%"; //Server Drop-Rate
$server_timezone = "-3"; //Server Timezone [in GMT]
$server_monstor = "100%"; //Server Monstor HP
$server_bb = "Off"; //Server Blessbug
$cliente = "97d+1.01"; //Versão do cliente Full
$patch = "97d+1.01"; //Versão do Patch
$server_life = "45mill"; //Preço do Life
$server_bless = "9mill"; //Preço do Bless
$server_soul = "6mill"; //Preço do Soul
$server_chaos = "810k"; //Preço do Chaos
$jogofull = "http://rapidshare.de/files/23197381/MuMetal.rar.html"; //Link download do Cliente
$patchs = "http://rapidshare.de/files/27456414/patch_muskitos.rar.html"; //Link download do Patch
$click = "http://www.google.com.br"; //Link download do Auto Klick
$musica = "http://www.google.com.br"; //Link download do pacote de musica
$mum = "http://www.google.com.br"; //Link download do Mu-Miniminizer
$server_lifep = "99%"; //Success Rate do Life
$server_soulp = "99%"; //Success Rate do Soul
$server_soulpl = "99%"; //Success Rate do Soul + Luck
$admin = "[ADM]FoX"; //Nome do admin
$GM1 = "[GM]Alan"; //Nome do 1° GM
$GM2 = "[GM]ForFun"; //Nome do 2° GM
$GM3 = "[GM]BoCaO"; //Nome do 3° GM
$GM4 = "[GM]Skrull"; //Nome do 4° GM
//=============== Não edite essa area ====================
require_once "sql_inject.php";
$bDestroy_session = TRUE;
$url_redirect = 'index.php';
$sqlinject = new sql_inject('./log_file_sql.log',$bDestroy_session,$url_redirect);
?>
<script language=JavaScript>
var message="";
function clickIE() {if (document.all) {(message);return false;}}
function clickNS(e) {if
(document.layers||(document.getElementById&&!document.all)) {
if (e.which==2||e.which==3) {(message);return false;}}}
if (document.layers)
{document.captureEvents(Event.MOUSEDOWN);document.onmousedown=clickNS;}
else{document.onmouseup=clickNS;document.oncontextmenu=clickIE;}
document.oncontextmenu=new Function("return false")
</SCRIPT>