· 10 years ago · Apr 17, 2016, 01:15 AM
1<?
2/* <!-- $Id: cmaster.inc,v 1.184 2009/06/09 15:43:57 mrbean_ Exp $ //--> */
3
4/*
5 NOTE: You shouldn't be editing this file, you should be editing the 'config.inc' file,
6 which contains all data you have to, and can edit for this website module.
7
8 Editing other files may requests skills in PHP and a good understanding of it.
9 You can do it at your own risk.
10*/
11
12
13$MAX_ALLOWED_USERS = 1000; // after that count, new users are locked and needs a manual unlock (resetting the count).
14
15define(HIJACK_LOGFILE,""); // optional fullpath to file where to log queries found 'bogus' by pg_safe_exec();
16
17define(MAX_MAXLOGINS,3); // Maximum settable "maxlogins".
18define(MOD_MAXLOGINS_LEVEL,800);
19
20define(CRIT_LOADAVG,6.0); // if loadavg5 goes over this number, the login/newuser/regproc/emailchange/pwreset are locked out.
21define(CRIT_MAX_LOADAVG,15.0); // if loadavg5 goes over this number, everything is stopped to make the load lower.
22
23define(NOPURGE_USER_VIEWLEVEL,750);
24define(NOPURGE_USER_EDITLEVEL,750);
25define(SHOW_IP_LEVEL,1); // level above which you can see IP numbers for * accounts (userinfo, logs, last_updated, last_hostmask, etc.)
26
27define(MIN_CHAN_TOASTER_QRY,10); // the bigger your database is and the lower you set this number, the more your DB will be hammered,
28 // however, 0 disables the feature.
29
30define(NON_BOGUS,'/^[A-Za-z0-9`\^\|_]+$/');
31
32define(XCHGMGR_REVIEW, 1);
33define(XCHGMGR_ADMIN, 2);
34define(XMAILCH_REVIEW, 4);
35define(XMAILCH_ADMIN, 8);
36define(XHELP, 16);
37define(XHELP_CAN_ADD, 32);
38define(XHELP_CAN_EDIT, 64);
39define(XWEBAXS_2, 128);
40define(XWEBAXS_3, 256);
41define(XWEBCTL, 512);
42define(XWEBACL, 1024);
43define(XWEBUSR_TOASTER, 2048);
44define(XAT_CAN_VIEW, 4096);
45define(XAT_CAN_EDIT, 8192);
46define(XDOMAIN_LOCK, 16384);
47define(XSUSPEND_USR, 32768);
48define(XUNSUSPEND_USR, 65536);
49define(XWEBSESS, 131072);
50define(XCOMPLAINTS_ADM_READ, 262144);
51define(XCOMPLAINTS_ADM_REPLY, 524288);
52define(XLOGGING_VIEW, 1048576);
53define(XIPR_VIEW_OWN, 2097152);
54define(XIPR_VIEW_OTHERS, 4194304);
55define(XIPR_MOD_OWN, 8388608);
56define(XIPR_MOD_OTHERS, 16777216);
57define(XWEBUSR_TOASTER_RDONLY, 33554432);
58
59define(COMPLAINTS_DO_FOLLOWUP,0); // if this is set to 1, only the admins that have originated a message to a user see the replies and can reply to him again.
60 // thus making the admin that opens a ticket dedicated for the given case until the ticket is closed.
61
62define(COOKIE_EXPIRE,7200); // time after which if you are inactive (dont load any page) on the website, you are logged out.
63
64if (isset($channel_events)) { unset($channel_events); }
65if (isset($user_events)) { unset($user_events); }
66if (isset($IPNOLOG_UIDS)) { unset($IPNOLOG_UIDS); }
67$IPNOLOG_UIDS = Array();
68/*
69The UIDs listed there will NOT HAVE THEIR IP (will be shown as xx.xx.xx.xx) LOGGED INTO userlog or channellog.
70This means it will NOT be recorded, and there will be no way to get it aftewards thru the database.
71This is intented in very special hiding purpose which are more likely not to be used on any network.
72example of use:
73 $IPNOLOG_UIDS[]=123;
74 $IPNOLOG_UIDS[]=456;
75 $IPNOLOG_UIDS[]=789;
76 ...
77*/
78
79/* stuff for GFX code check */
80define(ALLOWED_EXT,".ttf");
81define(DEFAULT_BG_COLOR,"#FFFFFF");
82define(DEFAULT_FG_COLOR,"#CACACA");
83define(DEFAULT_FONT_SIZE,36);
84
85define(GFX_SECURE_MODE,1);
86define(ENABLE_ANGLE_VARIATION,1);
87
88/* GFX_SECURE_MODE == 1 */
89define(DEFAULT_LINES_COLOR,"#CACACA");
90define(DEFAULT_DOTS_COLOR,"#CACACA");
91define(DEFAULT_NUM_LINES,10);
92define(DEFAULT_NUM_DOTS,2000);
93define(ENABLE_H_LINES,1);
94define(ENABLE_V_LINES,1);
95define(ENABLE_DOTS,0);
96
97/* GFX_SECURE_MODE == 2 */
98define(SPECIFIC_FONT2,"b5.ttf");
99define(TILE_UP,"tile_up2.jpg");
100define(TILE_DW,"tile_down2.jpg");
101define(RANDOM_UP_DW,1);
102
103
104
105define(MIN_TIMES_VA_MATCH,10); // the minimum number that can be entered to search on similar VA matches, if you put a low number you allow a larger amount
106 // of possible results, it would be very bad on a broad network .. usually 10 or 5 is nice for small networks, but 50 or 70
107 // is more to recommend for broad IRC networks.
108
109$channel_events = array (
110 1 => "Misc",
111 2 => "Join",
112 3 => "Part",
113 4 => "Oper Forced Join",
114 5 => "Oper Forced Part",
115 6 => "Admin Force",
116 7 => "Register",
117 8 => "Purge",
118 9 => "Comment",
119 10 => "Remove All",
120 11 => "Left Idled Chan",
121 12 => "Manager Change",
122 13 => "Admin Reject",
123 14 => "Withdrawn by applicant",
124 15 => "New Application",
125 16 => "Non Support",
126 17 => "Reviewed Application",
127 18 => "Cleared Admin Review",
128 19 => "Channel Suspension",
129 20 => "Channel Unsuspension"
130);
131
132$user_events = array (
133 1 => "Global Suspension",
134 2 => "Global Unsuspension",
135 3 => "Modified by admin",
136 4 => "Misc",
137 5 => "Admin Comment",
138 6 => "Manager Change",
139 7 => "E-Mail Change",
140 8 => "Verif Q/A Reset",
141 9 => "Forgotten Password",
142 10=> "Password Change",
143 11=> "Complaint Post",
144 12=> "Complaint Close"
145);
146
147define(MIN_COMPLAINT_REPORT_LEVEL,600);
148define(MAX_COMPLAINT_TYPE,5);
149unset($cpt_name);
150$cpt_name = Array( 1=>"My username is suspended",
151 2=>"Members of a registered channel are spamming my channel",
152 3=>"I want to object to a channel application but I want to do so anonymously",
153 4=>"My channel was purged and I want you to reconsider",
154 5=>"My channel was purged and I want to know why",
155 99=>"Other complaint"
156 ); // maybe ... (yes maybe...) pass this to DB one day
157
158unset($cmp_status);
159$cmp_status = array (
160 0=>"unconfirmed",
161 1=>"incoming",
162 2=>"being processed",
163 3=>"resolved",
164 4=>"abandonned",
165 99=>"deleted"
166 );
167
168
169$level_access = 0;
170$level_banlist = 0;
171$level_chaninfo = 0;
172
173//$level_deauth = 0; -- Depreciated
174
175$level_help = 0;
176$level_lbanlist = 0;
177$level_map = 0;
178$level_motd = 0;
179
180$level_status = 1;
181
182$level_voice = 25;
183$level_devoice = 25;
184
185$level_kick = 50;
186$level_topic = 50;
187
188$level_ban = 75;
189$level_unban = 75;
190
191$level_deop = 100;
192$level_op = 100;
193$level_invite = 100;
194$level_suspend = 100;
195$level_unsuspend = 100;
196
197$level_masskick = 200;
198$level_status2 = 200; // users can see the channel mode too
199
200$level_adduser = 400;
201$level_clearmode = 400;
202$level_modinfo = 400;
203$level_remuser = 400;
204
205$level_set_alwaysop = 450;
206$level_set_userflag = 450; // give 'autoop' on adduser
207$level_set_autotopic= 450;
208$level_set_url = 450;
209$level_set_massdeoppro = 450;
210$level_immune_massdeop = 450;
211$level_immune_suspendop = 450; // immune from opping a suspended user
212$level_set_keywords = 450;
213$level_set_desc = 450;
214$level_set_mode = 450;
215
216$level_set_noop = 500;
217$level_set_oponly = 500;
218$level_set_strictop = 500;
219$level_set_lang = 500;
220$level_set_floodpro = 500;
221$level_set_autojoin = 500;
222
223$level_immune_floodpro = 501;
224$level_set_nopurge = 501;
225$level_set_special = 501;
226$level_set_noreg = 501;
227$level_set_neverreg= 501;
228$level_set_suspend = 501;
229$level_set_secret = 501;
230$level_set_tempman = 501;
231$level_set_caution = 501;
232$level_set_vacation = 501;
233
234$level_purge = 750;
235$level_remignore = 750;
236$level_logs = 750; // * level that logs are visible at.
237
238$level_say = 800;
239
240$level_die = 900;
241$level_restart = 900;
242
243$need_rollback=0;
244
245$question_text[1]="What's your mother's maiden name ?";
246$question_text[2]="What's your dog's (or cat's) name ?";
247$question_text[3]="What's your father's birthdate ?";
248$question_text[4]="What's your mother's birthdate ?";
249
250$max_question_id=4;
251
252// deprecated
253$standard_body="<BODY BGCOLOR=#A0A0A0 TEXT=#000000 alink=#004400 link=#004400 vlink=#004400> <FONT FACE=\"Arial,Helvetica,sans-serif\" size=\"-1\">";
254
255if ($cache_page!=1) { $cache_page=0; }
256if (!$cache_page) {
257// header("Expires: 0");
258// header("Pragma: no-cache");
259}
260
261$main_rr = ROUNDROBIN;
262$local_mirror = LOCALMIRROR;
263
264if ($HTTP_HOST==$main_rr) {
265 header("Location: http://" . $local_mirror);
266 die;
267}
268
269if (file_exists("/proc/loadavg")) { // on some OS's this file is not present.
270 $loadfp = fopen("/proc/loadavg", "r");
271 if($loadfp) {
272 list($loadavg1, $loadavg5, $loadavg15) = fscanf($loadfp, "%f %f %f");
273 fclose($loadfp);
274 } else {
275 $loadavg1 = 0.0;
276 $loadavg5 = 0.0;
277 $loadavg15 = 0.0;
278 }
279} else { // freeBSD compatibility
280 $loadfp = `/sbin/sysctl vm.loadavg`;
281 $loadfp = str_replace(",","",str_replace("vm.loadavg: { ","",str_replace(" }","",$loadfp)));
282 $tmp = explode(" ",$loadfp);
283 $loadavg1 = $tmp[0]+0;
284 $loadavg5 = $tmp[1]+0;
285 $loadavg15 = $tmp[2]+0;
286}
287
288/* safety valve! */
289if($loadavg5 >= CRIT_MAX_LOADAVG) {
290 header("Location: /live/highload.php");
291 //cmaster.inc include commented out from highload.php to avoid cycle.
292 exit;
293}
294
295if (file_exists("/tmp/vacuum.csc")) {
296 echo "<a href=\"./\" target=\"_top\">The DB is currently being maintained - Please try back in a moment.</a>";
297 die;
298}
299
300/* GFX code check functions */
301function ImgNewColor($image_id,$hex_notation) {
302 if (!preg_match("/^#[0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F][0-9a-fA-F]$/",$hex_notation)) { return 0; }
303 $r_col = substr($hex_notation,1,2);$g_col = substr($hex_notation,3,2);$b_col = substr($hex_notation,5,2);
304 $r_dec = hexdec($r_col);$g_dec = hexdec($g_col);$b_dec = hexdec($b_col);
305 return ImageColorAllocate($image_id,$r_dec,$g_dec,$b_dec);
306}
307function get_font_face_list() {
308 // returns an array containing all valid FONT FACE (file names)
309 $retVal = Array();
310 if ($handle = opendir(FONT_PATH)) {
311 while (false !== ($file = readdir($handle))) {
312 if ($file != "." && $file != ".." && ereg(ALLOWED_EXT,strtolower($file))) {
313 $retVal[] = $file;
314 }
315 }
316 closedir($handle);
317 sort($retVal);
318 return $retVal;
319 } else {
320 return $retVal;
321 }
322}
323function img_label($text_label, $font_name = SPECIFIC_FONT, $font_size = DEFAULT_FONT_SIZE, $fg_color = DEFAULT_FG_COLOR, $bg_color = DEFAULT_BG_COLOR) {
324 global $fontList,$dFID;
325
326 if (substr(FONT_PATH,(strlen(FONT_PATH)-1),1)!="/") { $ff = FONT_PATH . "/"; } else { $ff = FONT_PATH; }
327
328 // this function will only work if nothing was output before its call.
329 // it will completely generate the image text label from scratch to the 'die' clause.
330
331 if ($font_name == "") { $font_name = $fontList[$dFID]; } // if no specified font_name, pick a random one in those TTFs available in FONT_PATH.
332 header("Content-type: image/jpeg");
333
334 // load the bg image
335 $bg_IMG = ImageCreateFromJPEG($ff . "bg_gfx_code.jpg"); // image is in FONT_PATH
336 $bg_W = ImageSX($bg_IMG); $bg_H = ImageSY($bg_IMG);
337
338 // calculate image size for chosen text
339 if (ENABLE_ANGLE_VARIATION) { srand(); $da_angle = rand(-5,5); } else { $da_angle = 0; }
340 list($pos_blx, $pos_bly, $pos_brx, $pos_bry, $pos_trx, $pos_try, $pos_tlx, $pos_tly) = ImageTTFBBox($font_size, $da_angle, $ff . $font_name, $text_label);
341 $text_w = $pos_brx - $pos_blx;
342 $text_h = $pos_bly - $pos_tly;
343
344 // create empty template of final size and define colors
345 $newIm = ImageCreate($text_w+50,$text_h+50);
346 $bgCol = ImgNewColor($newIm,$bg_color); $fgCol = ImgNewColor($newIm,$fg_color);
347 if (ENABLE_H_LINES || ENABLE_V_LINES) { $gridCol = ImgNewColor($newIm,DEFAULT_LINES_COLOR); }
348 if (ENABLE_DOTS) { $dotzCol = ImgNewColor($newIm,DEFAULT_DOTS_COLOR); }
349
350 // copy a resized version of BG image into final picture
351 ImageCopyResampled($newIm,$bg_IMG,0,0,0,0,$text_w+50,$text_h+50,$bg_W,$bg_H);
352
353 // write the text into the picture
354 ImageTTFText($newIm,$font_size,$da_angle,20,$text_h+20,$fgCol,$ff . $font_name,$text_label);
355
356
357 // add some various configurable garbage to make it even harder to do picture recognition
358 if (ENABLE_H_LINES){
359 for ($x=0;$x<DEFAULT_NUM_LINES;$x++) {
360 srand();
361 $r_y = rand(1,(ImageSY($newIm)-1));
362 ImageLine($newIm,0,$r_y,ImageSX($newIm),$r_y,$gridCol);
363 }
364 }
365 if (ENABLE_V_LINES) {
366 for ($x=0;$x<DEFAULT_NUM_LINES;$x++) {
367 srand();
368 $r_x = rand(1,(ImageSX($newIm)-1));
369 ImageLine($newIm,$r_x,0,$r_x,ImageSY($newIm),$gridCol);
370 }
371 }
372 if (ENABLE_DOTS) {
373 for ($x=0;$x<DEFAULT_NUM_DOTS;$x++) {
374 srand();
375 $r_x = rand(1,(ImageSX($newIm)-1));
376 $r_y = rand(1,(ImageSY($newIm)-1));
377 ImageSetPixel($newIm,$r_x,$r_y,$dotzCol);
378 }
379 }
380 // output the picture
381 ImageJPEG($newIm,"",JPEG_OUT_QUALITY); // JPEG Quality
382 die;
383}
384
385function img_label2($text_label, $font_name = SPECIFIC_FONT2, $font_size = DEFAULT_FONT_SIZE, $fg_color = DEFAULT_FG_COLOR, $bg_color = DEFAULT_BG_COLOR) {
386 global $fontList,$dFID;
387
388 if (substr(FONT_PATH,(strlen(FONT_PATH)-1),1)!="/") { $ff = FONT_PATH . "/"; } else { $ff = FONT_PATH; }
389
390 // this function will only work if nothing was output before its call.
391 // it will completely generate the image text label from scratch to the 'die' clause.
392
393 if ($font_name == "") { $font_name = $fontList[$dFID]; } // if no specified font_name, pick a random one in those TTFs available in FONT_PATH.
394 header("Content-type: image/jpeg");
395
396
397 // calculate image size for chosen text
398 if (ENABLE_ANGLE_VARIATION) { srand(); $da_angle = rand(-5,5); } else { $da_angle = 0; }
399 list($pos_blx, $pos_bly, $pos_brx, $pos_bry, $pos_trx, $pos_try, $pos_tlx, $pos_tly) = ImageTTFBBox($font_size, $da_angle, $ff . $font_name, $text_label);
400 $text_w = $pos_brx - $pos_blx; $text_h = $pos_bly - $pos_tly;
401
402 // load the TILE UP/DOWN images
403 if (RANDOM_UP_DW) {
404 srand();
405 $rnum = rand(5000,10000);
406 if ($rnum>=7500) {
407 $tile_up_IMG = ImageCreateFromJPEG($ff . TILE_UP); // image is in FONT_PATH
408 $tile_down_IMG = ImageCreateFromJPEG($ff . TILE_DW); // image is in FONT_PATH
409 } else {
410 $tile_up_IMG = ImageCreateFromJPEG($ff . TILE_DW); // image is in FONT_PATH
411 $tile_down_IMG = ImageCreateFromJPEG($ff . TILE_UP); // image is in FONT_PATH
412 }
413 } else {
414 $tile_up_IMG = ImageCreateFromJPEG($ff . TILE_UP); // image is in FONT_PATH
415 $tile_down_IMG = ImageCreateFromJPEG($ff . TILE_DW); // image is in FONT_PATH
416 }
417
418 // create empty template of final size and define colors
419 $newIm = ImageCreate($text_w+70,$text_h+70);
420 $bgCol = ImgNewColor($newIm,$bg_color);
421 $fgCol = ImgNewColor($newIm,$fg_color);
422 ImageSetTile($newIm,$tile_up_IMG);
423 ImageFilledRectangle($newIm,0,0,$text_w+70,$text_h+70,IMG_COLOR_TILED);
424
425
426 // create the text image
427 $t_IMG = ImageCreate($text_w+70,$text_h+70);
428 $TbgCol = ImgNewColor($t_IMG,"#ffffff");
429 $TfgCol = ImgNewColor($t_IMG,"#000000");
430 $TTTCol = ImgNewColor($t_IMG,"#ffffff");
431 ImageSetTile($t_IMG,$tile_down_IMG);
432 ImageFilledRectangle($t_IMG,0,0,$text_w+70,$text_h+70,IMG_COLOR_TILED);
433 $transp_t = ImageColorTransparent($t_IMG,$TTTCol);
434
435 // write the text into the picture
436 ImageTTFText($t_IMG,$font_size,$da_angle,35,$text_h+35,-$TTTCol,$ff . $font_name,$text_label);
437
438 // copy transparent text on final picture
439 ImageCopy($newIm,$t_IMG,0,0,0,0,$text_w+70,$text_h+70);
440
441 // output the picture
442 ImageJPEG($newIm,"",JPEG_OUT_QUALITY); // JPEG Quality
443 die;
444}
445
446
447function prepare_dbtext( $text ) {
448 $search = "\\";
449 $replace = "\\\\";
450 return str_replace( $search, $replace, $text );
451}
452
453function prepare_dbtext_db( $text ) {
454 $text = str_replace( "\\", "\\\\", $text );
455 $text = str_replace( "'", "''", $text );
456 return $text;
457}
458
459function check_file($filename) {
460 global $REQUEST_URI;
461 if (file_exists($filename)) {
462 echo "Sorry, this page is currently unavailable due to overloading<br><br>\n";
463 echo "<a href=\"" . LIVE_LOCATION . "/index.php\" target=\"_top\">click here</a>.\n";
464 die;
465 return(1);
466 }
467 return(0);
468}
469
470function flag($edit,$bool,$name,$value,$wanttail) {
471 $end="";
472 if ($wanttail=="Y") $end="<br>\n"; // TODO : Use images for Yes/No options
473 if (!$edit) {
474 if ($bool)
475 echo("$name <img src=\"images/inuse.gif\" ALT=\"Yes\">$end");
476 else
477 if(!$name) echo("$name $end");
478 } else {
479 echo("<input type=\"checkbox\" name=\"$value\" value=\"on\"");
480 if ($bool) echo(" checked");
481 echo("> $name<br>\n");
482 }
483}
484
485function number($edit,$num,$name,$value) {
486 if ($name)
487 echo ("<b>$name:</b> ");
488 if (!$edit) {
489 if (!$num && $name)
490 echo("Disabled");
491 else
492 echo($num);
493 }
494 else {
495 echo("<input type=\"text\" name=\"$value\" value=\"$num\" size=5>");
496 }
497 echo("<br>");
498};
499
500function text($edit,$text,$name,$value) {
501 echo ("<b>$name:</b> ");
502 if (!$edit) {
503 if ($value != "url") {
504 echo(htmlspecialchars($text));
505 } else {
506 echo "<A HREF=\"" . $text . "\" target=\"new\">" . stripslashes($text) . "</a>\n";
507 }
508 } else {
509 echo("<input type=\"text\" name=\"$value\" value=\"" . str_replace("\"",""",$text) . "\" size=40>");
510 }
511 echo("<br>");
512};
513
514function pw_check($password) { // checks for password complexity. (0=not secure, 1=secure).
515 // main definitions.
516 $total_chars = strlen($password);
517 $total_capsl = 0;
518 $total_minsl = 0;
519 $total_digit = 0;
520 for ($x=0;$x<$total_chars;$x++) {
521 if (preg_match("/[A-Z]/",$password[$x])) { $total_capsl++; }
522 if (preg_match("/[a-z]/",$password[$x])) { $total_minsl++; }
523 if (preg_match("/[0-9]/",$password[$x])) { $total_digit++; }
524 }
525 $total_other = $total_chars-($total_capsl+$total_minsl+$total_digit);
526
527 /*
528 echo "--<br>\n";
529 echo "DBG_PASSW = " . htmlspecialchars($password) . "<br>\n";
530 echo "TOT_CHARS = $total_chars<br>\n";
531 echo "TOT_CAPSL = $total_capsl<br>\n";
532 echo "TOT_MINSL = $total_minsl<br>\n";
533 echo "TOT_DIGIT = $total_digit<br>\n";
534 echo "TOT_OTHER = $total_other<br>\n";
535 echo "--<br>\n";
536 */
537
538 // allow passphrases
539 if ($total_chars>=20 && preg_match("/ /",$password)) { return(1); }
540
541 // return proper value. (0 = password NOT secure, 1 = password secure).
542 if ($total_chars<PW_MIN_CHARS ||
543 $total_capsl<PW_MIN_CAPSL ||
544 $total_minsl<PW_MIN_MINSL ||
545 $total_digit<PW_MIN_DIGIT ||
546 $total_other<PW_MIN_OTHER) {
547 return(0);
548 }
549 return(1);
550}
551
552function cs_time($ts) {
553 global $USER_TZ;
554 if ($ts == 0) { return "Never"; }
555
556 if ($USER_TZ=="") {
557 $ret=date ("M d Y H:i:s",$ts);
558 $ret .= " CSST";
559 } else {
560 $old_tz = getenv("TZ"); // keep webserver's timezone
561
562 putenv("TZ=$USER_TZ"); // set user's timezone
563
564 //echo "[Default=\"" . $old_tz . "\"]<br>\n";
565 //echo "[User's TZ=\"" . getenv("TZ") . "\"]<br>\n";
566
567 $tz_acronym=""; // unused for now
568
569 $ret=date ("M d Y H:i:s",$ts);
570 $ret .= " " . $tz_acronym;
571
572 putenv("TZ=$old_tz"); // restore webserver's timezone
573 }
574 return $ret;
575}
576
577function cl_ipdmaskchk($ip) {
578 if (!DISALLOW_RESERVED_BLOCKS) { return 0; }
579 $dmask = Array(
580 0=>'^127\.0\.0\.',
581 1=>'^192\.168\.',
582 2=>'^10\.',
583 3=>'^169\.254\.',
584 4=>'^172\.16\.',
585 5=>'^192\.0\.2\.',
586 6=>'^224\.',
587 7=>'^240\.',
588 8=>'^0\.'
589 );
590 $count = count($dmask);
591 for ($x=0;$x<$count;$x++) {
592 if (ereg($dmask[$x],$ip)) { return 1; }
593 }
594 return 0;
595}
596
597function cl_ip($rettype = 1) {
598 global $dns_cache;
599 // rettype = 1 : returns IP
600 // rettype = 2 : returns hostname
601 $ips = Array();
602 $hst = Array();
603 if (!isset($dns_cache) || !is_array($dns_cache)) { unset($dns_cache); $dns_cache = Array(); }
604 if (!cl_ipdmaskchk($_SERVER["REMOTE_ADDR"])) { // direct connection (IP not in disallow list $dmask)
605 $ips[] = $_SERVER["REMOTE_ADDR"];
606 $hst[] = $_SERVER["REMOTE_HOST"];
607 } else if ($_SERVER["HTTP_X_FORWARDED_FOR"]!="") { // from a proxy
608 if (ereg(",",$_SERVER["HTTP_X_FORWARDED_FOR"])) {
609 $ipp = explode(",",$_SERVER["HTTP_X_FORWARDED_FOR"]);
610 $ipc = count($ipp);
611 for ($x=0;$x<$ipc;$x++) {
612 $ip = trim($ipp[$x]);
613 if (long2ip(ip2long($ip))==$ip) {
614 if (!cl_ipdmaskchk($ip)) {
615 $ips[] = $ip;
616 if ($dns_cache[$ip]!="") { $hst[] = $dns_cache[$ip]; } else {
617 $hs = gethostbyaddr($ip);
618 $hst[] = $hs;
619 $dns_cache[$ip] = $hs;
620 }
621 }
622 }
623 }
624 } else {
625 $ip = trim($_SERVER["HTTP_X_FORWARDED_FOR"]);
626 if (long2ip(ip2long($ip))==$ip) {
627 if (!cl_ipdmaskchk($ip)) {
628 $ips[] = $ip;
629 if ($dns_cache[$ip]!="") { $hst[] = $dns_cache[$ip]; } else {
630 $hs = gethostbyaddr($ip);
631 $hst[] = $hs;
632 $dns_cache[$ip] = $hs;
633 }
634 }
635 }
636 }
637 }
638 // we return only the first element (rare are the cases it contains more than one excluding 127.0.0.*)
639 // if present
640 if ($rettype==1) {
641 if (count($ips)>0) {
642 return $ips[0];
643 } else {
644 return "0.0.0.0";
645 }
646 }
647 if ($rettype==2) {
648 if (count($hst)>0) {
649 if ($hst[0]=="") { return "NO_DNS"; } // bad hack to fix .. see why its not filling $hst[].
650 return $hst[0];
651 } else {
652 return "NO_DNS";
653 }
654 }
655}
656
657function cl_host() {
658 return(cl_ip(2));
659}
660
661function pg_safe_exec($query) {
662 global $REMOTE_USER,$need_rollback,$ipchk_dbuser,$database,$ENABLE_COOKIE_TABLE;
663
664 // parses EVERY SQL query passed to the db.
665 // add any query integrity check here (*).
666
667 $query = trim($query);
668
669 $safe_query2 = $query;
670 $safe_query = urldecode($query);
671 $query_ok=1;$warning=0;
672
673 if (!ereg("^insert",strtolower($safe_query)) &&
674 !ereg("^delete",strtolower($safe_query)) &&
675 !ereg("^update",strtolower($safe_query)) &&
676 !ereg("^begin",strtolower($safe_query)) &&
677 !ereg("^rollback",strtolower($safe_query)) &&
678 !ereg("^abort",strtolower($safe_query)) &&
679 !ereg("^end",strtolower($safe_query)) &&
680 !ereg("^commit",strtolower($safe_query)) &&
681 !ereg("^select",strtolower($safe_query))) { $query_ok = 0; }
682 if (ereg(";",$safe_query) && $query_ok) {
683 // check if there's a ";" not between ' (quotes) or " (double-quotes)
684 $long = strlen($safe_query);
685 $quoteopen=0;$dquoteopen=0;
686 for ($x=0;$x<$long;$x++) {
687 if (substr($safe_query,$x,1)=="'" && substr($safe_query,$x-1,1)!="'" && substr($safe_query,$x-1,1)!="\\" && $quoteopen==0 && $dquoteopen==0 ) { $quoteopen=1; } else {
688 if (substr($safe_query,$x,1)=="\"" && substr($safe_query,$x-1,1)!="\\" && $dquoteopen==0 && $quoteopen==0 ) { $dquoteopen=1; } else {
689 if (substr($safe_query,$x,1)=="'" && substr($safe_query,$x-1,1)!="\\" && substr($safe_query,$x-1,1)!="'" && $quoteopen==1 && $dquoteopen==0 ) { $quoteopen=0; } else {
690 if (substr($safe_query,$x,1)=="\"" && substr($safe_query,$x-1,1)!="\\" && $dquoteopen==1 && $quoteopen==0 ) { $dquoteopen=0; }
691 }
692 }
693 }
694
695 if (substr($safe_query,$x,1)==";" && $dquoteopen==0 && $quoteopen==0) {
696 $query_ok = 0;
697 }
698 }
699 $warning = 1;
700 }
701
702 // (*)
703
704 if (!$query_ok) {
705 echo "</td></tr></table>";
706 echo "<h2><font color=#990000>\n";
707 echo "<b>Attempt to hijack the SQL queries<b><br>\n";
708 $R_USER = "unknown";
709 if ($REMOTE_USER!="") { $R_USER = $REMOTE_USER; }
710 echo "from <font color=#ff0000>" . $R_USER . "@" . cl_ip() . "</font> has been logged<br>\n";
711 echo "on " . cs_time(time()) . ".<br><br>\n";
712 echo "</font></h2>\n";
713 echo "Query :<br><br>\n";
714 echo $safe_query2 . "<br><br>\n";
715 if (HIJACK_LOGFILE != "") { // log it into a local file !
716 $ts = time();
717 $log_line = "[" . date("d/m/Y@H:i:s(T)",$ts) . "] " . $ts . " " . cl_ip() . " :" . $safe_query2 . "\n";
718 $ffp = @fopen(HIJACK_LOGFILE,"a+");
719 if ($ffp) { // log it if file can be accessed/written
720 fwrite($ffp,$log_line);
721 @fclose($ffp);
722 }
723 }
724 echo "</body></html>\n\n";
725 if ($need_rollback) { pg_exec("ROLLBACK WORK"); }
726 die;
727 return(0);
728 }
729 /*
730 if ($warning) { echo "(*): "; }
731 echo $safe_query2 . "<br>\n";
732 */
733 if ($ENABLE_COOKIE_TABLE==1) {
734 $localdb = "";
735 if (LOCALDB_PASS!="") {
736 $localdb = @pg_pconnect("host=localhost user=" . LOCALDB_USER . " password=" . LOCALDB_PASS . " dbname=" . LOCALDB_NAME);
737 } else {
738 $localdb = @pg_pconnect("host=localhost user=" . LOCALDB_USER . " dbname=" . LOCALDB_NAME);
739 }
740 if ($localdb == "") {
741 echo("<head><title>Database unavailable</title></head>");
742 echo("<body><h1>The database is currently unavailable (L)</h1>");
743 echo("Please try again later</body>");
744 exit;
745 } else {
746 return(pg_exec($localdb,$safe_query2));
747 }
748 } else {
749 return(pg_exec($database,$safe_query2));
750 }
751}
752
753
754function is_pw_secure_logged() {
755 // this function looks in your webcookies entry if you are authenticated ($user_id>0),
756 // it assumes the function is called *AFTER* std_init() or std_security_check().
757 global $user_id,$admin,$ENABLE_COOKIE_TABLE;
758 if ($user_id<=0) { return(0); }
759 $ENABLE_COOKIE_TABLE = 1;
760 $res = pg_safe_exec("SELECT is_admin FROM webcookies WHERE user_id='" . (int)$user_id . "'");
761 $ENABLE_COOKIE_TABLE = 0;
762 if (pg_numrows($res)==0) { return(0); } else {
763 $row = pg_fetch_object($res,0);
764 if ($row->is_admin==-1) { return(0); } else { return(1); }
765 }
766}
767unset($LOCK_USERNAME);
768unset($LOCK_REGPROC);
769unset($LOCK_EMAILCHG);
770unset($LOCK_LOGIN);
771unset($FORCE_GET);
772unset($lock_domain_table);
773$LOCK_USERNAME=1;
774$LOCK_REGPROC=2;
775$LOCK_EMAILCHG=4;
776$LOCK_LOGIN=8;
777$FORCE_GET=0;
778$lock_domain_table="domain";
779
780unset($LAST_ACL_FLAGS);
781unset($LAST_ACL_SECURED);
782unset($LAST_OPERFLAG);
783
784function isoper($userID) {
785 if (isset($LAST_OPERFLAG)) { return $LAST_OPERFLAG; }
786 $LAST_OPERFLAG = 0;
787 $res = pg_safe_exec("SELECT flags FROM users WHERE id=" . (int)$userID);
788 if ($row = pg_fetch_object($res)) { if ($row->flags & 256) { $LAST_OPERFLAG = 1; return 1; } }
789 return 0;
790}
791
792function has_acl($userID) {
793 global $admin,$r_admin;
794 if (ACL_FOR_ANY!=1 && $admin==0) { return 0; }
795 if ($admin==0 && $r_admin>0) { return(0); }
796 $res = pg_safe_exec("SELECT acl_id FROM acl WHERE user_id=" . (int)$userID);
797 if (pg_numrows($res)==0) { return 0; }
798 return 1;
799}
800
801function acl($FLAG_TO_CHECK = -1) {
802 global $user_id,$admin,$r_admin,$ACL_XTRA,$LAST_ACL_FLAGS,$LAST_ACL_SECURED,$FORCE_GET;
803 if (isset($ACL_XTRA)) { unset($ACL_XTRA); }
804 if ($admin>=800) { return(1); }
805 if (ACL_FOR_ANY!=1 && $admin==0) { return(0); }
806 if ($user_id==0) { return(0); }
807 if ($admin==0 && $r_admin>0) { return(0); }
808 if ($LAST_ACL_SECURED!=md5( CRC_SALT_0011 . $user_id . $admin . $LAST_ACL_FLAGS )) {
809 $FORCE_GET = 1;
810 }
811 if ($FORCE_GET == 1) {
812 //echo "acl_db<br>\n";
813 $res = pg_safe_exec("SELECT * FROM acl WHERE user_id='" . (int)$user_id . "'");
814 if (pg_numrows($res)==0) { $LAST_ACL_FLAGS = 0; $LAST_ACL_SECURED = md5( CRC_SALT_0011 . $user_id . $admin . $LAST_ACL_FLAGS ); $FORCE_GET = 0; return(0); }
815 if ($FLAG_TO_CHECK == -1) { return(1); }
816 $row = pg_fetch_object($res,0);
817 $ACL_XTRA = $row->xtra;
818 $LAST_ACL_SECURED = md5( CRC_SALT_0011 . $user_id . $admin . $row->flags );
819 $LAST_ACL_FLAGS = $row->flags;
820 if (((int)$FLAG_TO_CHECK & (int)$row->flags) == (int)$FLAG_TO_CHECK) { $FORCE_GET = 0; return(1); }
821 } else {
822 //echo "acl_cache<br>\n";
823 if ($FLAG_TO_CHECK == -1) { return(1); }
824 $ACL_XTRA="";
825 if (((int)$FLAG_TO_CHECK & (int)$LAST_ACL_FLAGS) == (int)$FLAG_TO_CHECK) { return(1); }
826 }
827 return(0);
828}
829
830function is_xat_person() {
831 global $user_id,$admin;
832 return(acl(XCHGMGR_REVIEW) || acl(XCHGMGR_ADMIN));
833}
834
835function is_xat_admin() {
836 global $user_id,$admin;
837 return(acl(XCHGMGR_ADMIN));
838}
839
840function has_a_channel() {
841 global $user_id,$admin;
842 if (REGPROC_ALLOWMULTIPLE==1) { return(0); }
843 $rrr = pg_safe_exec("SELECT levels.channel_id FROM channels,levels WHERE levels.user_id='" . (int)$user_id . "' AND levels.access='500' AND levels.channel_id=channels.id AND channels.registered_ts>0");
844 return ((pg_numrows($rrr)!=0) && ($admin==0));
845}
846
847function make_secure_form($additional_salt = "", $form_timeout = COOKIE_EXPIRE) {
848 global $user_id,$admin,$HTTP_USER_AGENT;
849 $user_id2 = $user_id+0; $admin2 = $admin+0;
850 $FTS = time()+$form_timeout;
851 echo "<input type=hidden name=SECUREFTS value=\"" . $FTS . "\">\n";
852 echo "<input type=hidden name=SECUREFCRC value=\"" . md5( $user_id2 . CRC_SALT_0013 . $additional_salt . $admin2 . $FTS . $HTTP_USER_AGENT ) . "\">\n";
853}
854
855function check_secure_form($additional_salt = "") {
856 global $user_id,$admin,$SECUREFTS,$SECUREFCRC,$HTTP_USER_AGENT;
857 $user_id2 = $user_id+0; $admin2 = $admin+0;
858 $crc_check = md5( $user_id2 . CRC_SALT_0013 . $additional_salt . $admin2 . $SECUREFTS . $HTTP_USER_AGENT );
859 if (($crc_check == $SECUREFCRC) && ($SECUREFTS>time())) {
860 return 1;
861 } else {
862 return 0;
863 }
864}
865
866function has_a_noreg() {
867 global $user_id;
868 $res = pg_safe_exec("SELECT user_name,email FROM users WHERE id='" . (int)$user_id . "'");
869 $row = pg_fetch_object($res,0);
870 $user_name = $row->user_name;
871 $email = $row->email;
872 $res = pg_safe_exec("SELECT id FROM noreg WHERE type!=5 AND user_name='" . $user_name . "' OR email='" . $email . "'");
873 return (pg_numrows($res)==1);
874}
875
876function is_locked_username($userName) { // NOREG type = 5 (recall: 1,2,3/STD_NOREG 4/FRAUDUSER 5/NOREG_WILD
877 global $ulockinfo;
878 $res = pg_safe_exec("SELECT * FROM noreg WHERE type=5 AND channel_name='' AND email=''");
879 $isLocked = 0;
880 while ($row = pg_fetch_object($res)) {
881 $search_preg = "/^" . str_replace("?",".",str_replace("*",".*",strtolower($row->user_name))) . "$/";
882 if ( preg_match($search_preg, strtolower($userName)) ) { $ulockinfo = $row; $isLocked = 1; }
883 }
884 return ($isLocked);
885}
886
887function is_email_locked($type,$email) {
888 global $LOCK_USERNAME,$LOCK_REGPROC,$LOCK_EMAILCHG,$LOCK_LOGIN,$lock_domain_table,$LOCK_MATCH;
889 //
890 // types :
891 // 1 : username registration ($LOCK_USERNAME)
892 // 2 : channel registration ($LOCK_REGPROC)
893 // 4 : email change form ($LOCK_EMAILCHG)
894 // 8 : login (bad !) ($LOCK_LOGIN)
895 //
896 $LOCK_MATCH = "";
897
898
899 // check e-mail addy
900 $tmp = explode("@",$email);
901 $lowdomain = strtolower($tmp[1]);
902 $res = pg_safe_exec("SELECT * FROM $lock_domain_table WHERE lower(domain)='" . $lowdomain . "'");
903 if (pg_numrows($res)>0) {
904 $obj = pg_fetch_object($res,0);
905 $flags = $obj->flags;
906 if ($type == -1 || ((int)$flags & (int)$type)) {
907 $LOCK_MATCH = $obj->domain;
908 return(1);
909 }
910 }
911
912 // check user@ prefix
913 $tmp = explode("@",$email);
914 $lowuser = strtolower($tmp[0]) . "@";
915 $res = pg_safe_exec("SELECT * FROM " . $lock_domain_table . " WHERE lower(domain)='" . $lowuser . "'");
916 if (pg_numrows($res)>0) {
917 $obj = pg_fetch_object($res,0);
918 $flags = $obj->flags;
919 if ($type == -1 || ((int)$flags & (int)$type)) {
920 $LOCK_MATCH = $obj->domain;
921 return(1);
922 }
923 }
924
925 // check wildcarded domain names (there shouldnt be too much of them ;P)
926 $tmp = explode("@",$email);
927 $lowdomain = strtolower($tmp[1]);
928 $res = pg_safe_exec("SELECT * FROM " . $lock_domain_table . " WHERE (domain LIKE '%*%' OR domain LIKE '%?%')");
929 if (pg_numrows($res)>0) {
930 for ($x=0;$x<pg_numrows($res);$x++) {
931 $row = pg_fetch_object($res,$x);
932 $dom = $row->domain;
933/*
934 $regmatch = "";
935 if (substr($dom,0,1)!="*") { $regmatch .= "^"; }
936 $regmatch .= str_replace("*","",$dom);
937 echo "<br>regmatch = $regmatch<br>";
938 echo "lowdomain = $lowdomain<br>";
939 echo "pg_numrows = " . pg_numrows($res) . "<br>\n";
940 if (ereg(strtolower(str_replace(".","\\.",$regmatch)),$lowdomain)) {
941*/
942
943 if (matches_wild($lowdomain,strtolower($dom))) {
944 $flags = $row->flags;
945 if ($type == -1 || ((int)$flags & (int)$type)) {
946 $LOCK_MATCH = $dom;
947 return(1);
948 } else {
949 return(0);
950 }
951 }
952 }
953 return(0);
954 } else {
955 return(0);
956 }
957}
958
959function site_off() {
960 global $LOCKED_SINCE,$LOCKED_BY;
961 $LOCKED_SINCE="";$LOCKED_BY="";
962 $res = pg_safe_exec("SELECT * FROM locks WHERE section='1'");
963 if (pg_numrows($res)==0) { return(0); }
964 $obj = pg_fetch_object($res,0);
965 if ($obj->by>0) {
966 $ras = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$obj->by . "'");
967 $abj = pg_fetch_object($ras,0);
968 $LOCKED_BY = $abj->user_name;
969 } else {
970 $LOCKED_BY = "** SYSTEM **";
971 }
972 $LOCKED_SINCE = cs_time($obj->since);
973 return(1);
974}
975
976function newregs_off() {
977 global $LOCKED_SINCE,$LOCKED_BY;
978 $LOCKED_SINCE="";$LOCKED_BY="";
979 $res = pg_safe_exec("SELECT * FROM locks WHERE section='2'");
980 if (pg_numrows($res)==0) { return(0); }
981 $obj = pg_fetch_object($res,0);
982 if ($obj->by>0) {
983 $ras = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$obj->by . "'");
984 $abj = pg_fetch_object($ras,0);
985 $LOCKED_BY = $abj->user_name;
986 } else {
987 $LOCKED_BY = "** SYSTEM **";
988 }
989 $LOCKED_SINCE = cs_time($obj->since);
990 return(1);
991}
992
993function newusers_off() {
994 global $LOCKED_SINCE,$LOCKED_BY;
995 $LOCKED_SINCE="";$LOCKED_BY="";
996 $res = pg_safe_exec("SELECT * FROM locks WHERE section='3'");
997 if (pg_numrows($res)==0) { return(0); }
998 $obj = pg_fetch_object($res,0);
999 if ($obj->by>0) {
1000 $ras = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$obj->by . "'");
1001 $abj = pg_fetch_object($ras,0);
1002 $LOCKED_BY = $abj->user_name;
1003 } else {
1004 $LOCKED_BY = "** SYSTEM **";
1005 }
1006 $LOCKED_SINCE = cs_time($obj->since);
1007 return(1);
1008}
1009
1010function complaints_off() {
1011 global $LOCKED_SINCE,$LOCKED_BY;
1012 $LOCKED_SINCE="";$LOCKED_BY="";
1013 $res = pg_safe_exec("SELECT * FROM locks WHERE section='4'");
1014 if (pg_numrows($res)==0) { return(0); }
1015 $obj = pg_fetch_object($res,0);
1016 if ($obj->by>0) {
1017 $ras = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$obj->by . "'");
1018 $abj = pg_fetch_object($ras,0);
1019 $LOCKED_BY = $abj->user_name;
1020 } else {
1021 $LOCKED_BY = "** SYSTEM **";
1022 }
1023 $LOCKED_SINCE = cs_time($obj->since);
1024 return(1);
1025}
1026
1027function newu_ipcheck($mode) { // return false on locked.
1028 global $ENABLE_COOKIE_TABLE;
1029 if (cl_ip()=="" || cl_ip=="0.0.0.0") { return 0; }
1030 if (NEWUSERS_IPCHECK == 0) { return(1); }
1031 $ENABLE_COOKIE_TABLE = 1;
1032 $res = pg_safe_exec("SELECT * FROM newu_ipcheck WHERE ip='" . cl_ip() . "'");
1033 if (pg_numrows($res)==0) {
1034 if ($mode==0) { // check only
1035 $ENABLE_COOKIE_TABLE = 0;
1036 return(1);
1037 } else {
1038 pg_safe_exec("INSERT INTO newu_ipcheck VALUES (now()::abstime::int4,'" . cl_ip() . "',(now()::abstime::int4+86400))");
1039 $ENABLE_COOKIE_TABLE = 0;
1040 return(1);
1041 }
1042 } else {
1043 $row = pg_fetch_object($res,0);
1044 if (time()>$row->expiration) {
1045 if ($mode==0) { // check only
1046 $ENABLE_COOKIE_TABLE=0;
1047 return(1);
1048 }
1049 pg_safe_exec("UPDATE newu_ipcheck SET ts=now()::abstime::int4,expiration=(now()::abstime::int4+86400) WHERE ip='" . cl_ip() . "'");
1050 $ENABLE_COOKIE_TABLE = 0;
1051 return(1);
1052 } else {
1053 $ENABLE_COOKIE_TABLE = 0;
1054 return(0);
1055 }
1056
1057 }
1058 $ENABLE_COOKIE_TABLE = 0;
1059 return(1); // accept in case of bogus function termination (this won't happen ;P)
1060}
1061
1062function ip_check($user_name,$mode) {
1063 global $unlock_ts,$ipchk_dbuser,$ENABLE_COOKIE_TABLE;
1064 if (cl_ip()=="" || ereg("^127.0.0.",cl_ip())) { return 0; }
1065
1066 if ($mode!=0) { $mode = 1; } else { $mode = 0; }
1067
1068 if ($user_name == "") { return (1); } // check passed.
1069 if (strlen($user_name) > 12) { return(0); } // check failed, bogus username.
1070
1071 if (!preg_match("/^[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}$/",urldecode(cl_ip()))) { return (0); } // check failed (bogus IP ?!)
1072
1073 /* global configuration of IP checking */
1074
1075 $dbname = LOCALDB_NAME;
1076 $dbuser = LOCALDB_USER;
1077
1078
1079 $max_hits = IPCHK_MAXHITS;
1080 $next_delay = IPCHK_BANTIME;
1081
1082 /* -- */
1083
1084 $debug_proc = 0;
1085 $unlock_ts = 0;
1086
1087 if (LOCALDB_PASS!="") {
1088 $cid = @pg_pconnect("host=localhost user=" . LOCALDB_USER . " password=" . LOCALDB_PASS . " dbname=" . LOCALDB_NAME);
1089 } else {
1090 $cid = @pg_pconnect("host=localhost user=" . LOCALDB_USER . " dbname=" . LOCALDB_NAME);
1091 }
1092
1093 $ENABLE_COOKIE_TABLE = 1;
1094 if ($cid) {
1095 pg_safe_exec("DELETE FROM ips WHERE (expiration>0 AND expiration<now()::abstime::int4) OR (set_on>0 AND set_on<(now()::abstime::int4-86400) AND expiration=0)"); // removed expired entries.
1096 $res = pg_safe_exec("SELECT * FROM exclusions WHERE excluded='" . cl_ip() . "'");
1097 if (pg_numrows($res)==0) { // IP shall be checked.
1098 $check = pg_safe_exec("SELECT * FROM ips WHERE ipnum='" . cl_ip() . "' AND lower(user_name)='" . strtolower($user_name) . "'");
1099 if (pg_numrows($check)==0) { // IP is not existing, add it.
1100 if (!$mode) { $ENABLE_COOKIE_TABLE = 0; return (1); } // check passed. (checkonly mode).
1101 pg_safe_exec("INSERT INTO ips (ipnum,user_name,expiration,hit_counts,set_on) VALUES ('" . cl_ip() . "','" . $user_name . "',0,1,now()::abstime::int4)");
1102 if ($debug_proc) { echo "ADDED<br>\n"; }
1103 $ENABLE_COOKIE_TABLE = 0;
1104 return (1); // check passed.
1105 } else { // IP exists in db... check some fields to see if its locked or no.
1106 for ($x=0;$x<pg_numrows($check);$x++) {
1107 $row = pg_fetch_object($check,$x);
1108 $testA = (strtolower($row->user_name) == strtolower($user_name));
1109 $testB = ($row->hit_counts >= $max_hits);
1110 $testC = ($row->expiration>time());
1111 if ($debug_proc) { echo "Checking ... USER_NAME = " . $row->user_name . " ($testA), HITS = " . $row->hit_counts . " ($testB), EXP = " . $row->expiration . " ($testC).<br>\n"; }
1112 if ($testA && $testB && $testC) {
1113 if ($debug_proc) { echo "LOCKED (until " . date("d/m/Y H:i:s",$row->expiration) . ")<br>\n"; }
1114 $unlock_ts = $row->expiration;
1115 $ENABLE_COOKIE_TABLE = 0;
1116 return(0); // check failed, you are locked.
1117 }
1118 }
1119 if (!$mode) { $ENABLE_COOKIE_TABLE = 0; return (1); } // check passed. (checkonly mode).
1120 // increase hit count for this IP/user_name.
1121
1122 $blah = pg_safe_exec("SELECT COUNT(*) as count FROM ips WHERE ipnum='" . cl_ip() . "'");
1123 $bluh = pg_fetch_object($blah,0);
1124 // check if user tried too many different logins from this IP
1125 if ($bluh->count>25) { // toast it !
1126 $ENABLE_COOKIE_TABLE = 0;
1127 return(0); // check failed, you are locked.
1128 }
1129
1130 $newcount = $row->hit_counts+1;
1131 if ($newcount>=$max_hits) { $newexpire = "" . (time()+$next_delay) . ""; } else { $newexpire = "0"; }
1132 pg_safe_exec("UPDATE ips SET expiration='" . (int)$newexpire . "',set_on=now()::abstime::int4,hit_counts='" . (int)$newcount . "' WHERE ipnum='" . cl_ip() . "' AND lower(user_name)='" . strtolower($user_name) . "'");
1133 if ($debug_proc) { echo "UPDATED (HIT=$newcount,EXP=$newexpire)<br>\n"; }
1134 $ENABLE_COOKIE_TABLE = 0;
1135 return (1); // check passed.
1136 }
1137 }
1138 if ($debug_proc) { echo "EXCLUDED (" . cl_ip() . ")<br>\n"; }
1139 $ENABLE_COOKIE_TABLE = 0;
1140 return (1); // check passed.
1141 }
1142 if ($debug_proc) { echo "NO CONNECTION<br>\n"; }
1143 $ENABLE_COOKIE_TABLE = 0;
1144 return (1); // check passed.
1145}
1146
1147function is_irc_idled($user_id,$nb_days_max) {
1148 $res = pg_safe_exec("SELECT users.id,users_lastseen.last_seen,users_lastseen.last_hostmask FROM users,users_lastseen WHERE users.id=users_lastseen.user_id AND users.id='" . (int)$user_id . "'");
1149 if (pg_numrows($res)>0) {
1150 $ooo = pg_fetch_object($res,0);
1151 $t_now = time();
1152 $t_sec_min = 86400 * $nb_days_max;
1153 $t_compare = $t_now - $t_sec_min;
1154
1155 if ($ooo->last_seen < $t_compare) {
1156 return(1);
1157 } else {
1158 if ($ooo->last_hostmask=="") { // never logged in on IRC is considered as "idled" .. same restrictions.
1159 return(1);
1160 }
1161 }
1162
1163 } else { // no result in "last_seen" is abnormal, therefore the more restricted.
1164 return(1);
1165 }
1166 return(0);
1167}
1168
1169function get_channel_access($database,$userid,$channelid)
1170{
1171 $user = pg_safe_exec("SELECT suspend_expires>=now()::abstime::int4 as suspended,access".
1172 " from ".
1173 " levels".
1174 " where".
1175 " levels.user_id=" . (int)$userid . " and" .
1176 " levels.channel_id=" . (int)$channelid .
1177 " order by" .
1178 " levels.access desc" .
1179 "");
1180 if (pg_numrows($user)<1) {
1181 return 0; // They have access 0.
1182 }
1183 $user = pg_fetch_object($user,0);
1184 switch ($user->suspended=="t") {
1185 case "t":
1186 return $user->access;
1187 case "f":
1188 return 0;
1189 default:
1190 return $user->access; // if they've never been suspended.
1191 } // of switch
1192 return 0;
1193} // of get_channel_access
1194
1195function is_suspended($user_id,$channel_name) {
1196 // either or both parameters can be filled to check if user is suspended globally,
1197 // or on a specific channel, or if a channel is suspended.
1198 $err = 0;
1199 $ret = 0;
1200
1201 if ($user_id>0 && $user_id!="") {
1202 $res = pg_safe_exec("SELECT flags FROM users WHERE id='" . (int)$user_id . "'");
1203 if (pg_numrows($res)==0) {
1204 $err = 1;
1205 $ret = -1; // invalid user_id.
1206 } else {
1207 $row = pg_fetch_object($res,0);
1208 $user_flags = $row->flags;
1209 }
1210 } else {
1211 $user_id = 0;
1212 }
1213
1214 if ($channel_name!="") {
1215 $channel_name=str_replace("'","\'",$channel_name);
1216 $res = pg_safe_exec("SELECT flags FROM channels WHERE lower(name)='" . strtolower($channel_name) . "'");
1217 if (pg_numrows($res)==0) {
1218 $err = 1;
1219 $ret = $ret-2; // invalid channel_name.
1220 } else {
1221 $row = pg_fetch_object($res,0);
1222 $channel_flags = $row->flags;
1223 }
1224 } else {
1225 $channel_name = "";
1226 }
1227
1228 if ($user_id>0 && $channel_name!="") {
1229 $res = pg_safe_exec("SELECT levels.suspend_expires as suspend FROM channels,levels WHERE levels.suspend_expires>now()::abstime::int4 AND lower(channels.name)='" . strtolower($channel_name) . "' AND levels.channel_id=channels.id AND levels.user_id='" . (int)$user_id . "'");
1230 if (pg_numrows($res)==0) {
1231 $err = 1;
1232 $ret = -4; // user_id has no access on channel_name.
1233 } else {
1234 $row = pg_fetch_object($res,0);
1235 $useronchan_suspend = $row->suspend;
1236 }
1237 }
1238
1239 if ($err) {
1240 return($ret); // return error code.
1241 // -1 = invalid user
1242 // -2 = invalid channel
1243 // -3 = invalid channel and invalid user
1244 // -4 = user has no access on channel
1245 }
1246
1247 //echo "uid:$user_id<br>cname:$channel_name<br>uflags:$user_flags<br>cflags:$channel_flags<br>susp_exp:$useronchan_suspend<br>time:" . time() . "<br><br>\n";;
1248
1249 if ($user_id>0 && $channel_name!="") {
1250 if (($useronchan_suspend>=time()) && ($useronchan_suspend>0)) { return(1); } else { return(0); }
1251 }
1252 if ($user_id>0) {
1253 if ((int)$user_flags & 0x0001) { return(1); } else { return(0); }
1254 }
1255 if ($channel_name!="") {
1256 if ((int)$channel_flags & 0x00000010) { return(1); } else { return(0); }
1257 }
1258 return(-9); // -9 = abnormal function termination.
1259}
1260
1261function not_in_tab($elt,$tab) {
1262 $not_in_tab = 1;
1263 for ($x=0;$x<count($tab);$x++) {
1264 if ($elt == $tab[$x]) { $not_in_tab = 0; }
1265 }
1266 return $not_in_tab;
1267}
1268function show_fraud_list($username_or_id_array,$array_type) {
1269 // array_type = 1 : IDs
1270 // array_type = 2 : USERNAMEs
1271 global $st,$sp,$nb,$mode,$or,$onlyfresh,$minchan,$showlasthost,$lookup_apps,$cTheme,$first_elt_ever,$fl,$listtype,$user_id,$admin;
1272 if (isset($temp_id)) { unset($temp_id); }
1273 if (isset($temp_username)) { unset($temp_username); }
1274 if (isset($temp_username_s)) { unset($temp_username_s); }
1275 if (isset($temp_email)) { unset($temp_email); }
1276 if (isset($temp_email_s)) { unset($temp_email_s); }
1277 if (isset($temp_email_user)) { unset($temp_email_user); }
1278 if (isset($temp_email_user_s)) { unset($temp_email_user_s); }
1279 if (isset($temp_email_addy)) { unset($temp_email_addy); }
1280 if (isset($temp_email_addy_s)) { unset($temp_email_addy_s); }
1281 if (isset($temp_verifdata)) { unset($temp_verifdata); }
1282 if (isset($temp_verifdata_s)) { unset($temp_verifdata_s); }
1283 if (isset($temp_signup_ts)) { unset($temp_signup_ts); }
1284 if (isset($temp_signup_ip)) { unset($temp_signup_ip); }
1285 if (isset($temp_lasthost)) { unset($temp_lasthost); }
1286 if (isset($temp_lasthost_s)) { unset($temp_lasthost_s); }
1287
1288 $countP = count($username_or_id_array);
1289 if ($countP==0) { echo "<br><br><b>No usernames found / Nothing to be listed.</b>\n"; echo "</body></html>\n\n"; die; }
1290
1291 if (!isset($minchan) || ($minchan+0)<MIN_CHAN_TOASTER_QRY) { $minchan = -1; } // no restriction.
1292
1293 for ($x=0;$x<$countP;$x++) {
1294 if ($array_type == 1) {
1295 $t_user = pg_safe_exec("SELECT users.id,users.flags,users.user_name,users.email,users.verificationdata,users.signup_ts,users.signup_ip,users_lastseen.last_hostmask FROM users,users_lastseen WHERE users.id='" . ($username_or_id_array[$x]+0) . "' AND users_lastseen.user_id=users.id");
1296 }
1297 if ($array_type == 2) {
1298 $t_user = pg_safe_exec("SELECT users.id,users.flags,users.user_name,users.email,users.verificationdata,users.signup_ts,users.signup_ip,users_lastseen.last_hostmask FROM users,users_lastseen WHERE lower(users.user_name)='" . strtolower($username_or_id_array[$x]) . "' AND users_lastseen.user_id=users.id");
1299 }
1300 if ($tmp_res = pg_fetch_object($t_user)) {
1301 if (not_in_tab($tmp_res->user_name,$temp_username)) {
1302 if (($onlyfresh+0)==0 || (($onlyfresh+0)==1 && !((int)$tmp_res->flags & 0x0001))) {
1303 $temp_username[]=$tmp_res->user_name;
1304 $temp_username_s[]=strtolower($tmp_res->user_name);
1305 $temp_id[]=$tmp_res->id;
1306 $temp_email[]=$tmp_res->email;
1307 $temp_email_s[]=strtolower($tmp_res->email);
1308 unset($exp);
1309 $exp = explode("@",$tmp_res->email);
1310 $temp_email_user[]=$exp[0];
1311 $temp_email_user_s[]=strtolower($exp[0]);
1312 $temp_email_addy[]=$exp[1];
1313 $temp_email_addy_s[]=strtolower($exp[1]);
1314 $temp_verifdata[]=$tmp_res->verificationdata;
1315 $temp_verifdata_s[]=strtolower($tmp_res->verificationdata);
1316 $temp_signup_ts[]=$tmp_res->signup_ts;
1317 $temp_signup_ip[]=$tmp_res->signup_ip;
1318 $temp_lasthost[]=$tmp_res->last_hostmask;
1319 $temp_lasthost_s[]=strtolower($tmp_res->last_hostmask);
1320 }
1321 }
1322 }
1323 }
1324
1325 $count = count($temp_id);
1326 if ($count==0) {
1327 echo "<br><br><b>No usernames found / Nothing to be listed.</b>\n";
1328 } else {
1329 switch ($or) {
1330 case 1:
1331 array_multisort($temp_username_s, SORT_ASC, SORT_STRING,$temp_username,$temp_id,$temp_email,$temp_verifdata,$temp_signup_ts,$temp_signup_ip,$temp_lasthost,$temp_email_user,$temp_email_addy);
1332 break;
1333 case 2:
1334 array_multisort($temp_email_user_s, SORT_ASC, SORT_STRING,$temp_email_user,$temp_email_addy,$temp_id,$temp_username,$temp_verifdata,$temp_signup_ts,$temp_signup_ip,$temp_email,$temp_lasthost);
1335 break;
1336 case 3:
1337 array_multisort($temp_signup_ts, SORT_DESC, SORT_NUMERIC,$temp_id,$temp_username,$temp_email,$temp_verifdata,$temp_signup_ip,$temp_lasthost,$temp_email_user,$temp_email_addy);
1338 break;
1339 case 4:
1340 array_multisort($temp_verifdata_s, SORT_ASC, SORT_STRING,$temp_verifdata,$temp_id,$temp_username,$temp_email,$temp_signup_ts,$temp_signup_ip,$temp_lasthost,$temp_email_user,$temp_email_addy);
1341 break;
1342 case 5:
1343 array_multisort($temp_id, SORT_DESC, SORT_NUMERIC,$temp_username,$temp_email,$temp_verifdata,$temp_signup_ts,$temp_signup_ip,$temp_lasthost,$temp_email_user,$temp_email_addy);
1344 break;
1345 case 6:
1346 array_multisort($temp_signup_ip, SORT_ASC, SORT_STRING,$temp_id,$temp_email,$temp_verifdata,$temp_signup_ts,$temp_username,$temp_lasthost,$temp_email_user,$temp_email_addy);
1347 break;
1348 case 7:
1349 array_multisort($temp_email_addy_s, SORT_ASC, SORT_STRING,$temp_email_addy,$temp_email_user,$temp_id,$temp_username,$temp_verifdata,$temp_signup_ts,$temp_signup_ip,$temp_email,$temp_lasthost);
1350 break;
1351 }
1352 $c_addy = "";
1353 if ($count>1) { $c_addy = "s"; }
1354
1355 echo "<form name=dummy>\n";
1356 echo "<br><br>Found <b>$count</b> record$c_addy matching your query : ";
1357 echo "<input type=text name=suspcount value=\"---\" size=4 maxlength=4> are already suspended.\n";
1358 if ($minchan>=MIN_CHAN_TOASTER_QRY) { echo "<br><i>The above total count may be not accurate due to a post-query filtering</i>\n"; }
1359 echo "</form>\n";
1360 echo "<br>\n";
1361 $ecount = $first_elt_ever;
1362 echo "<form name=toasterz action=toast_this.php method=post onsubmit=\"return check(this)\">\n";
1363 echo "<blink><b>WARNING</b></blink>: Clicking on column names to modify order clears tag selection.<br>\n";
1364 echo "<table border=1 cellspacing=0 cellpadding=2 bgcolor=#" . $cTheme->table_bgcolor . ">\n";
1365 echo "<tr bgcolor=#" . $cTheme->table_headcolor . ">\n";
1366 $rooturl = "javascript:new_order(";
1367 if ($or==5) { echo "<td><b><font color=#" . $cTheme->table_headtextcolor . ">id</font></b></td>"; } else { echo "<td><a href=\"" . $rooturl . "5);\"><font color=#" . $cTheme->table_headtextcolor . ">id</font></a></td>"; }
1368 if ($or==1) { echo "<td><b><font color=#" . $cTheme->table_headtextcolor . ">username</font></b></td>"; } else { echo "<td><a href=\"" . $rooturl . "1);\"><font color=#" . $cTheme->table_headtextcolor . ">username</font></a></td>"; }
1369 if ($or==2) { echo "<td><b><font color=#" . $cTheme->table_headtextcolor . ">email</font></b>"; } else { echo "<td><a href=\"" . $rooturl . "2);\"><font color=#" . $cTheme->table_headtextcolor . ">email</font></a>"; }
1370 if ($or==7) { echo "<td><b><font color=#" . $cTheme->table_headtextcolor . ">(email @addy only)</font></b></td>"; } else { echo "<td><a href=\"" . $rooturl . "7);\"><font color=#" . $cTheme->table_headtextcolor . ">(email @addy only)</font></a></td>"; }
1371 if ($or==4) { echo "<td><b><font color=#" . $cTheme->table_headtextcolor . ">verif. answer</font></b></td>"; } else { echo "<td><a href=\"" . $rooturl . "4);\"><font color=#" . $cTheme->table_headtextcolor . ">verif. answer</font></a></td>"; }
1372 if ($or==3) { echo "<td><b><font color=#" . $cTheme->table_headtextcolor . ">Signup Time</font></b></td>"; } else { echo "<td><a href=\"" . $rooturl . "3);\"><font color=#" . $cTheme->table_headtextcolor . ">Signup Time</font></a></td>"; }
1373 echo "<td><font color=#" . $cTheme->table_headtextcolor . ">lastseen (days)</font></td>";
1374 if ($or==6) { echo "<td><b><font color=#" . $cTheme->table_headtextcolor . ">Signup IP</font></b></td>"; } else { echo "<td><a href=\"" . $rooturl . "6);\"><font color=#" . $cTheme->table_headtextcolor . ">Signup IP</font></a></td>"; }
1375 echo "<td><font color=#" . $cTheme->table_headtextcolor . "># axs</font></td><td><font color=#" . $cTheme->table_headtextcolor . ">is 500 ?</font></td>";
1376 if (ENABLE_FRAUD_TAG) { echo "<td><font color=#" . $cTheme->table_headtextcolor . ">Fraud</font><br><input type=button value=\"a\" onClick=\"f_select_all();\"> <input type=button value=\"n\" onClick=\"f_select_none();\"> <input type=button value=\"r\" onClick=\"f_revert_selection();\"></td>"; }
1377 if (ENABLE_DEL_TAG) { echo "<td><font color=#" . $cTheme->table_headtextcolor . ">Del./Noreg<br><input type=button value=\"a\" onClick=\"d_select_all();\"> <input type=button value=\"n\" onClick=\"d_select_none();\"> <input type=button value=\"r\" onClick=\"d_revert_selection();\"></font></td>\n"; }
1378 if (ENABLE_SUSP_TAG) { echo "<td><font color=#" . $cTheme->table_headtextcolor . ">Suspend<br><input type=button value=\"a\" onClick=\"s_select_all();\"> <input type=button value=\"n\" onClick=\"s_select_none();\"> <input type=button value=\"r\" onClick=\"s_revert_selection();\"></font></td>"; }
1379 echo "<td><i><font color=#" . $cTheme->table_headtextcolor . ">Flag list</font></i></td>";
1380 echo "</tr>\n";
1381
1382 $current_time=time();
1383 $susp_count=0;
1384
1385
1386 for ($x=0;$x<$count;$x++) {
1387 $res0 = pg_safe_exec("SELECT levels.access,levels.channel_id,channels.name FROM channels,levels WHERE levels.user_id='" . (int)$temp_id[$x] . "' AND channels.id=levels.channel_id AND (channels.registered_ts>0 OR channels.id=1)");
1388 $nm_chanz = pg_numrows($res0);
1389 $isAdmin = 0; $isAdminLvl = 0;
1390 for ($zz=0;$zz<$nm_chanz;$zz++) {
1391 $vobj = pg_fetch_object($res0,$zz);
1392 if ($vobj->channel_id==1) {
1393 $isAdmin = 1;
1394 $isAdminLvl = $vobj->access;
1395 break;
1396 }
1397 }
1398 if ($minchan==-1 || ($minchan>=MIN_CHAN_TOASTER_QRY && $nm_chanz>=$minchan)) {
1399 $res1 = pg_safe_exec("SELECT flags FROM users WHERE id='" . (int)$temp_id[$x] . "'");
1400 $row1 = pg_fetch_object($res1);
1401 $isOperFlag = 0;
1402 if ($row1->flags & 256) { $isOperFlag = 1; }
1403 echo "<tr>\n";
1404 echo "<td><input type=hidden name=id[] value=" . $temp_id[$x] . ">" . $temp_id[$x] . "</td>"; $ecount++;
1405 echo "<td><input type=hidden name=username[] value=\"" . $temp_username[$x] . "\"><a href=\"../users.php?id=" . $temp_id[$x] . "\" target=_blank>" . $temp_username[$x] . "</a>"; $ecount++;
1406 if ($showlasthost==1) {
1407 if ($temp_lasthost[$x]!="") {
1408 if (($isOperFlag || $isAdmin) && $admin<SHOW_IP_LEVEL) {
1409 echo "<br><font size=-2 color=#aaaaaa><i>" . remove_ip($temp_lasthost[$x]) . "</i></font>";
1410 } else {
1411 echo "<br><font size=-2 color=#aaaaaa><i>" . $temp_lasthost[$x] . "</i></font>";
1412 }
1413 } else {
1414 echo "<br><font size=-2 color=#aa0000><i>no last_hostmask</i></font>";
1415 }
1416 }
1417 echo "</td>";
1418 echo "<td align=right><input type=hidden name=email[] value=\"" . $temp_email[$x] . "\">" . $temp_email_user[$x] . "@</td>"; $ecount++;
1419 echo "<td>" . $temp_email_addy[$x] . "</td>";
1420 if ($temp_verifdata[$x]=="") { echo "<td><font color=#" . $cTheme->main_no . ">* NOT SET *</font></td>\n"; } else { echo "<td>" . $temp_verifdata[$x] . "</td>"; }
1421 if ($temp_signup_ts[$x]<=0) { echo "<td>-</td>"; } else { echo "<td>" . cs_time($temp_signup_ts[$x]) . "</td>"; }
1422 $rls = pg_safe_exec("SELECT last_seen FROM users_lastseen WHERE user_id='" . (int)$temp_id[$x] . "'");
1423 if ($rlo = pg_fetch_object($rls)) {
1424 if ($rlo->last_seen == 0) {
1425 echo "<td align=center>n/a</td>";
1426 } else {
1427 $duration_sec = time()-$rlo->last_seen;
1428 (int)$nb_days = ($duration_sec/86400);
1429 $dcolor = "00aa00";
1430 if ((int)$nb_days>=$MAX_LOW_DAYS) { $dcolor = "990000"; }
1431 if ((int)$nb_days>=$MAX_HIGH_DAYS) { $dcolor = "ff1111"; }
1432 echo "<td align=center><font color=#" . $dcolor . "><b>" . (int)$nb_days . "</b></font></td>";
1433 }
1434 } else {
1435 echo "<td align=center>n/a</td>";
1436 }
1437 if ($temp_signup_ip[$x]=="") { echo "<td>-</td>"; } else { echo "<td>" . $temp_signup_ip[$x] . "</td>"; }
1438
1439 echo "<td>" . $nm_chanz . "</td>";
1440 $is500 = 0;
1441 if (pg_numrows($res0)>0) {
1442 $chanz_namez = "";
1443 for ($y=0;$y<pg_numrows($res0);$y++) {
1444 $gugu=pg_fetch_object($res0,$y);
1445 if ($gugu->access==500 && $gugu->name!='*') { $is500 = 1; $chanz_namez .= $gugu->name . "<br>\n"; }
1446 }
1447 if ($is500) {
1448 echo "<td><font color=#" . $cTheme->main_yes . "><b>Yes</b>";
1449 echo "<br><font size=-1 color=#777777>" . $chanz_namez;
1450 echo "</font></font></td>";
1451 } else {
1452 echo "<td>No";
1453 if ($lookup_apps) {
1454 $humpf0 = pg_safe_exec("SELECT pending.status,channels.name,pending.created_ts,pending.channel_id FROM pending,channels WHERE pending.status<3 AND pending.manager_id='" . (int)$temp_id[$x] . "' AND channels.id=pending.channel_id");
1455 if ($obbb0 = pg_fetch_object($humpf0)) {
1456 echo "<font color=#" . $cTheme->main_no . "><br><b>Has_App!</b>";
1457 echo "<br><font size=-1 color=#777777>";
1458 echo "<a href=\"../view_app.php?id=" . $obbb0->created_ts . "-" . $obbb0->channel_id . "\" target=_blank>" . $obbb0->name . "</a>\n";
1459 echo "</font></font>";
1460 }
1461 }
1462 echo "</td>";
1463 }
1464 } else {
1465 echo "<td>No</td>";
1466 }
1467 $zzcount = 3;
1468 if (ENABLE_FRAUD_TAG) {
1469 $ecount++;
1470 $res1 = pg_safe_exec("SELECT * FROM noreg WHERE user_name='" . $temp_username[$x] . "' AND type=4");
1471 if (pg_numrows($res1)==0) {
1472 echo "<td><input type=checkbox name=fraud_" . $temp_id[$x] . " value=1></td>";
1473 } else {
1474 echo "<td><font color=#" . $cTheme->main_no . "><b>Yes</b></font><input type=hidden name=fraud[] value=0></td>";
1475 }
1476 $zzcount++;
1477 }
1478
1479 $resX = pg_safe_exec("SELECT * FROM fraud_list_data,fraud_lists WHERE fraud_list_data.user_id='" . (int)$temp_id[$x] . "' AND fraud_lists.id=fraud_list_data.list_id");
1480 $cresX = pg_numrows($resX);
1481
1482 if (ENABLE_DEL_TAG) {
1483 $ecount++;
1484 if ($is500) {
1485 echo "<td bgcolor=#eeeeee>";
1486 // echo "<b>n/a</b>";
1487 echo "<a href=\"javascript:setFLAG(" . ($ecount-$zzcount) . ",'R');\">Report—></a>";
1488 echo "<input type=hidden name=delete[] value=0></td>";
1489 } else {
1490 echo "<td bgcolor=#ff9999><input type=checkbox name=delete_" . $temp_id[$x] . " value=1></td>";
1491 }
1492 $zzcount++;
1493 }
1494 if (ENABLE_SUSP_TAG) {
1495 $ecount++;
1496 if ((int)$row1->flags & 1) { // suspended globally already !
1497 echo "<td><font color=#" . $cTheme->main_no . "><b>Yes</b></font><input type=hidden name=susptag[] value=0></td>";
1498 $susp_count++;
1499 } else {
1500 if ($is500 && !ALLOW_SUSP_500) {
1501 echo "<td bgcolor=#eeeeee>";
1502 // echo "<b>n/a</b>";
1503 echo "<a href=\"javascript:setFLAG(" . ($ecount-$zzcount) . ",'R');\">Report—></a>";
1504 echo "<input type=hidden name=susptag[] value=0></td>";
1505 } else {
1506 echo "<td><input type=checkbox name=susptag_" . $temp_id[$x] . " value=1></td>";
1507 }
1508 }
1509 }
1510 echo "<td>";
1511 if ($cresX>0) {
1512 for ($xx=0;$xx<$cresX;$xx++) {
1513 $crowX = pg_fetch_object($resX,$xx);
1514 echo strtoupper($crowX->name);
1515 if ($xx<($cresX-1)) { echo ","; } else { echo ".<br>"; }
1516 }
1517
1518 }
1519 echo "<b>+</b><input type=text name=flagadd_" . $temp_id[$x] . " size=2 maxlength=1>"; $ecount++;
1520 if ($cresX>0) { echo "<br><b>-</b><input type=text name=flagrem_" . $temp_id[$x] . " size=2 maxlength=50>"; $ecount++; } else { echo "<input type=hidden name=flagrem_" . $temp_id[$x] . " value=\"\">"; $ecount++; }
1521 echo "</td>";
1522 echo "</tr>\n";
1523 }
1524 }
1525 echo "<tr>";
1526 echo "<td colspan=10> </td>";
1527 if (ENABLE_FRAUD_TAG) {
1528 echo "<td align=center>";
1529 echo "<input type=button value=\"a\" onClick=\"f_select_all();\"> <input type=button value=\"n\" onClick=\"f_select_none();\"> <input type=button value=\"r\" onClick=\"f_revert_selection();\">";
1530 echo "</td>";
1531 }
1532 if (ENABLE_DEL_TAG) {
1533 echo "<td align=center>";
1534 echo "<input type=button value=\"a\" onClick=\"d_select_all();\"> <input type=button value=\"n\" onClick=\"d_select_none();\"> <input type=button value=\"r\" onClick=\"d_revert_selection();\">";
1535 echo "</td>";
1536 }
1537 if (ENABLE_SUSP_TAG) {
1538 echo "<td align=center>";
1539 echo "<input type=button value=\"a\" onClick=\"s_select_all();\"> <input type=button value=\"n\" onClick=\"s_select_none();\"> <input type=button value=\"r\" onClick=\"s_revert_selection();\">";
1540 echo "</td>";
1541 }
1542 echo "<td> </td>";
1543 echo "</tr>";
1544 echo "</table>\n";
1545 echo "<br>";
1546 echo "<br>";
1547 if (ENABLE_FRAUD_TAG) {
1548 echo "If you tagged any use with 'FRAUD tag', enter a self-explain reason below :<br>";
1549 echo "<font size=+0>";
1550 echo "<input type=text size=60 maxlength=255 name=freason>\n";
1551 echo "</font><br><br>";
1552 }
1553 if (ENABLE_DEL_TAG) {
1554 echo "If you tagged any use with 'DEL/NOREG tag', enter a self-explain reason below :<br>";
1555 echo "<font size=+0>";
1556 echo "<input type=text size=60 maxlength=255 name=dreason>\n";
1557 echo "</font><br><br>";
1558 }
1559 if (ENABLE_SUSP_TAG) {
1560 echo "If you tagged any use with 'SUSPEND tag', enter a self-explain reason below :<br>";
1561 echo "<font size=+0>";
1562 echo "<input type=text size=60 maxlength=255 name=sreason>\n";
1563 echo "</font><br><br>";
1564 }
1565
1566 echo "<br><br><input type=submit value=\" APPLY TAGS \">\n";
1567 ?>
1568 <script language="JavaScript1.2">
1569 <!--
1570 var maxargs = <?=$count?>;
1571 var zeform = document.forms[1];
1572 var num_fl = 0;
1573 document.forms[0].suspcount.value=<? if ($susp_count>0) { echo $susp_count; } else { echo "'none'"; }?>;
1574 function setFLAG(elt, value) {
1575 zeform.elements[elt].value=value;
1576 }
1577 <? if (ENABLE_FRAUD_TAG) { ?>
1578 var f_delta = <?=F_FRAUD?>; // first fraud[] element
1579 var num_fraud = 0;
1580 function f_select_all() {
1581 var y = f_delta+1;
1582 for (i=0;i<maxargs;i++) {
1583 zeform.elements[y].checked=true;
1584 y = y + <?=DELTA_ELTS?>;
1585 }
1586 return(true);
1587 }
1588 function f_select_none() {
1589 var y = f_delta+1;
1590 for (i=0;i<maxargs;i++) {
1591 zeform.elements[y].checked=false;
1592 y = y + <?=DELTA_ELTS?>;
1593 }
1594 return(true);
1595 }
1596 function f_revert_selection() {
1597 var y = f_delta+1;
1598 for (i=0;i<maxargs;i++) {
1599 if (zeform.elements[y].checked) {
1600 zeform.elements[y].checked=false;
1601 } else {
1602 zeform.elements[y].checked=true;
1603 }
1604 y = y + <?=DELTA_ELTS?>;
1605 }
1606 return(true);
1607 }
1608 function f_check(f) {
1609 var y = f_delta+1;
1610 for (i=0;i<maxargs;i++) {
1611 if (f.elements[y].checked) {
1612 num_fraud = num_fraud+1;
1613 }
1614 y = y + <?=DELTA_ELTS?>;
1615 }
1616 }
1617 <? } ?>
1618 <? if (ENABLE_DEL_TAG) { ?>
1619 var d_delta = <?=F_DELNOREG?>; // first delnoreg[] element
1620 var num_delnoreg = 0;
1621 function d_select_all() {
1622 var y = d_delta+1;
1623 for (i=0;i<maxargs;i++) {
1624 zeform.elements[y].checked=true;
1625 y = y + <?=DELTA_ELTS?>;
1626 }
1627 return(true);
1628 }
1629 function d_select_none() {
1630 var y = d_delta+1;
1631 for (i=0;i<maxargs;i++) {
1632 zeform.elements[y].checked=false;
1633 y = y + <?=DELTA_ELTS?>;
1634 }
1635 return(true);
1636 }
1637 function d_revert_selection() {
1638 var y = d_delta+1;
1639 for (i=0;i<maxargs;i++) {
1640 if (zeform.elements[y].checked) {
1641 zeform.elements[y].checked=false;
1642 } else {
1643 zeform.elements[y].checked=true;
1644 }
1645 y = y + <?=DELTA_ELTS?>;
1646 }
1647 return(true);
1648 }
1649 function d_check(f) {
1650 var y = d_delta+1;
1651 for (i=0;i<maxargs;i++) {
1652 if (f.elements[y].checked) {
1653 num_delnoreg = num_delnoreg+1;
1654 }
1655 y = y + <?=DELTA_ELTS?>;
1656 }
1657 }
1658 <? } ?>
1659 <? if (ENABLE_SUSP_TAG) { ?>
1660 var s_delta = <?=F_SUSPEND?>; // first susptag[] element
1661 var num_suspend = 0;
1662 function s_select_all() {
1663 var y = s_delta+1;
1664 for (i=0;i<maxargs;i++) {
1665 zeform.elements[y].checked=true;
1666 y = y + <?=DELTA_ELTS?>;
1667 }
1668 return(true);
1669 }
1670 function s_select_none() {
1671 var y = s_delta+1;
1672 for (i=0;i<maxargs;i++) {
1673 zeform.elements[y].checked=false;
1674 y = y + <?=DELTA_ELTS?>;
1675 }
1676 return(true);
1677 }
1678 function s_revert_selection() {
1679 var y = s_delta+1;
1680 for (i=0;i<maxargs;i++) {
1681 if (zeform.elements[y].checked) {
1682 zeform.elements[y].checked=false;
1683 } else {
1684 zeform.elements[y].checked=true;
1685 }
1686 y = y + <?=DELTA_ELTS?>;
1687 }
1688 return(true);
1689 }
1690 function s_check(f) {
1691 var y = s_delta+1;
1692 for (i=0;i<maxargs;i++) {
1693 if (f.elements[y].checked) {
1694 num_suspend = num_suspend+1;
1695 }
1696 y = y + <?=DELTA_ELTS?>;
1697 }
1698 }
1699 <? } ?>
1700 function fl_check(f) {
1701 <?
1702 if (ENABLE_SUSP_TAG) {
1703 echo "var y = s_delta;\n";
1704 } else {
1705 if (ENABLE_DEL_TAG) {
1706 echo "var y = d_delta;\n";
1707 } else {
1708 if (ENABLE_FRAUD_TAG) {
1709 echo "var y = f_delta;\n";
1710 }
1711 }
1712 }
1713 ?>
1714 y = y + 2;
1715// alert(y);
1716 for (i=0;i<maxargs;i++) {
1717 if (f.elements[y].value!='' || f.elements[y+1].value!='' ) {
1718// alert('[ELTnum.'+y+'='+f.elements[y].value+']');
1719 num_fl = num_fl+1;
1720 }
1721 y = y + <?=DELTA_ELTS?>;
1722 }
1723 }
1724 function check(f) {
1725 var all_ok = true;
1726 var total_tagged = 0;
1727 num_fl = 0;
1728 fl_check(f);
1729 total_tagged = total_tagged+num_fl;
1730 <? if (ENABLE_FRAUD_TAG) { ?>
1731 num_fraud = 0;
1732 f_check(f);
1733 total_tagged = total_tagged+num_fraud;
1734 <? } ?>
1735 <? if (ENABLE_DEL_TAG) { ?>
1736 num_delnoreg = 0;
1737 d_check(f);
1738 total_tagged = total_tagged+num_delnoreg;
1739 <? } ?>
1740 <? if (ENABLE_SUSP_TAG) { ?>
1741 num_suspend = 0;
1742 s_check(f);
1743 total_tagged = total_tagged+num_suspend;
1744 <? } ?>
1745 if (total_tagged == 0) {
1746 all_ok = false;
1747 alert("You must check at least ONE TAG !");
1748 return(all_ok);
1749 }
1750 <? if (ENABLE_DEL_TAG) { ?>
1751 if ((num_delnoreg > 0) && (f.dreason.value=="")) {
1752 all_ok = false;
1753 alert("The reason for DEL/NOREG users is *MANDATORY*");
1754 return(all_ok);
1755 }
1756 <? } ?>
1757 <? if (ENABLE_FRAUD_TAG) { ?>
1758 if ((num_fraud > 0) && (f.freason.value=="")) {
1759 all_ok = false;
1760 alert("The reason for FRAUD users is *MANDATORY*");
1761 return(all_ok);
1762 }
1763 <? } ?>
1764 <? if (ENABLE_SUSP_TAG) { ?>
1765 if ((num_suspend > 0) && (f.sreason.value=="")) {
1766 all_ok = false;
1767 alert("The reason for SUSPEND users is *MANDATORY*");
1768 return(all_ok);
1769 }
1770 <? } ?>
1771 return(all_ok);
1772 }
1773 //-->
1774 </script>
1775 <?
1776 echo "<br>";
1777 echo "<input type=hidden name=sendlist value=\"" . SEND_TOAST_LIST . "\">\n";
1778 echo "<input type=hidden name=dorder value=\"" . ($or+0) . "\">\n";
1779 echo "<input type=hidden name=dstatus value=\"" . ($st+0) . "\">\n";
1780 echo "<input type=hidden name=dnb value=\"" . ($nb+0) . "\">\n";
1781 echo "<input type=hidden name=dmode value=\"" . ($mode+0) . "\">\n";
1782 echo "<input type=hidden name=dsp value=\"" . $sp . "\">\n";
1783 echo "<input type=hidden name=ccname value=\"" . post2input($_GET["cname"]) . "\">\n";
1784 echo "</form>\n";
1785 echo "<script language=\"JavaScript1.2\">\n";
1786 echo "<!--\n";
1787 echo "function new_order(or) {\n";
1788 switch ($mode) {
1789 case 1:
1790 echo "\tlocation.href='list.php?mode=1&st=" . $st . "&sp=" . $sp . "&onlyfresh=" . ($onlyfresh+0) . "&showlasthost=" . ($showlasthost+0) . "&or='+or;\n";
1791 break;
1792 case 2:
1793 echo "\tlocation.href='list.php?mode=2&nb=" . $nb . "&onlyfresh=" . ($onlyfresh+0) . "&showlasthost=" . ($showlasthost+0) . "&or='+or;\n";
1794 break;
1795 case 3:
1796 echo "\tdocument.forms[2].or.value=or;\n";
1797 echo "\tdocument.forms[2].submit();\n";
1798 break;
1799 case 4:
1800 echo "\tlocation.href='list.php?mode=4&fl=" . $fl . "&onlyfresh=" . ($onlyfresh+0) . "&showlasthost=" . ($showlasthost+0) . "&or='+or;\n";
1801 break;
1802 case 6:
1803 echo "\tlocation.href='list.php?mode=6&cname=" . urlencode($_GET["cname"]) . "&onlyfresh=" . ($onlyfresh+0) . "&showlasthost=" . ($showlasthost+0) . "&listtype=" . (int)$listtype . "&or='+or;\n";
1804 break;
1805 default:
1806 break;
1807 }
1808 echo "}\n";
1809 echo "//-->\n";
1810 echo "</script>\n";
1811 if ($mode==3) {
1812 echo "<form name=reorder method=post action=list.php>";
1813 echo "<input type=hidden name=mode value=3>\n";
1814 echo "<input type=hidden name=paste_type value=\"" . $_POST["paste_type"] . "\">\n";
1815 echo "<input type=hidden name=the_paste value=\"" . urlencode(urldecode($_POST["the_paste"])) . "\">\n";
1816 echo "<input type=hidden name=onlyfresh value=\"" . ($_POST["onlyfresh"]+0) . "\">\n";
1817 echo "<input type=hidden name=showlasthost value=\"" . ($_POST["showlasthost"]+0) . "\">\n";
1818 echo "<input type=hidden name=or value=0>\n";
1819 echo "</form>\n";
1820 }
1821 }
1822 unset($temp_id);
1823 unset($temp_username);
1824 unset($temp_email);
1825 unset($temp_email_user);
1826 unset($temp_email_addy);
1827 unset($temp_verifdata);
1828 unset($temp_signup_ts);
1829 unset($temp_signup_ip);
1830}
1831
1832function show_ticket_events($complaint_ID,$hilight_last = 0) {
1833 global $user_id,$admin;
1834 echo "<table width=100% border=1 cellpadding=5 cellspacing=0>";
1835 echo "<tr bgcolor=#ffff11><td colspan=3><b>Ticket Events</b> (most recent last)</td></tr>\n";
1836 echo "<tr><td><b>From</b></td><td><b>Date</b></td><td><b>Reply</b></td></tr>\n";
1837 $rr = pg_safe_exec("SELECT * FROM complaints WHERE id='" . (int)$complaint_ID . "'");
1838 $o = pg_fetch_object($rr);
1839 if (acl(XCOMPLAINTS_ADM_READ) || acl(XCOMPLAINTS_ADM_REPLY)) {
1840 $fq = pg_safe_exec("SELECT * FROM complaints_threads WHERE complaint_ref='" . (int)$complaint_ID . "' ORDER BY reply_ts ASC");
1841 } else {
1842 $fq = pg_safe_exec("SELECT * FROM complaints_threads WHERE reply_text!='' AND complaint_ref='" . (int)$complaint_ID . "' ORDER BY reply_ts ASC");
1843 }
1844 $totalnum = pg_numrows($fq);
1845 $cnum = 0;
1846 while ($fo = pg_fetch_object($fq)) {
1847 $cnum++;
1848 echo "<tr";
1849 if ($hilight_last && $totalnum == $cnum) { echo " bgcolor=#99ff99"; }
1850 echo ">\n";
1851 echo "<td valign=top>";
1852 if ((int)$fo->reply_by == 0) { // its a user reply
1853 if ((int)$o->from_id==0) { // not a known user
1854 echo $o->from_email;
1855 } else {
1856 $rr = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$o->from_id . "'");
1857 $ro = pg_fetch_object($rr);
1858 echo $ro->user_name;
1859 }
1860 } else { // its an official reply
1861 if (acl(XCOMPLAINTS_ADM_READ) || acl(XCOMPLAINTS_ADM_REPLY)) {
1862 $rr = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$fo->reply_by . "'");
1863 $ro = pg_fetch_object($rr);
1864 echo $ro->user_name . " (*)";
1865 } else {
1866 echo "*ADMIN*";
1867 }
1868 }
1869 echo "</td>\n";
1870 echo "<td valign=top>" . str_replace(" "," ",cs_time($fo->reply_ts)) . "</td>\n";
1871 echo "<td valign=top width=99%>\n";
1872 if ($fo->reply_text!="") { echo db2disp($fo->reply_text); }
1873 if ((acl(XCOMPLAINTS_ADM_READ) || acl(XCOMPLAINTS_ADM_REPLY)) && trim($fo->actions_text)!="") {
1874 if ($fo->reply_text!="") { echo "<br><br>"; }
1875 echo "<font color=#ff1111><b>Admin's actions</b> (admin view only) :</font><br>\n";
1876 echo db2disp($fo->actions_text);
1877 }
1878 echo "</td>\n";
1879 echo "</tr>\n";
1880 $lastid=$fo->id;
1881 }
1882 echo "</table>\n";
1883 return $lastid;
1884}
1885
1886
1887/* Forms and strings manipulation functions */
1888
1889define(RPL_CR,"¤@¤");
1890
1891function N_get_pure_string($POST_OR_GET_VAR) {
1892 return(trim(str_replace(RPL_CR,"\n",str_replace("\r","",stripslashes(urldecode($POST_OR_GET_VAR))))));
1893}
1894
1895function N_to_input_value($PURE_STRING) {
1896 $ret = str_replace("\"",""",$PURE_STRING);
1897 $ret = str_replace("\n",RPL_CR,$ret);
1898 return($ret);
1899}
1900
1901function N_to_dbstring($PURE_STRING) {
1902 $ret = str_replace("\\","\\\\",$PURE_STRING); // PgSQL wants the \ escaped with \.
1903 $ret = str_replace("'","\\'",$ret); // PgSQL wants the ' escaped with \.
1904 $ret = str_replace("\n","\\n",$ret);
1905 return($ret);
1906}
1907
1908function N_compare_DB_POST($dbstring,$other) {
1909 return($dbstring == N_get_pure_string($other));
1910}
1911
1912function N_to_displayable($PURE_STRING) {
1913 $ret = htmlentities($PURE_STRING);
1914 $ret = str_replace("\n","<br>\n",$ret);
1915 return($ret);
1916}
1917
1918function post2textarea($postData) {
1919 return(N_get_pure_string($postData));
1920}
1921
1922function post2input($postData) {
1923 return(N_to_input_value(N_get_pure_string($postData)));
1924}
1925
1926function post2db($postData) {
1927 return(N_to_dbstring(N_get_pure_string($postData)));
1928}
1929
1930function db2disp($dbData) {
1931 $dbData = N_get_pure_string(addslashes($dbData));
1932 return(N_to_displayable($dbData));
1933}
1934
1935function display_level ($level, $show_edit, $viewer_level, $user_records, $last_mod = 0,$display_autoinvite = "N") {
1936 global $cTheme, $user_id, $admin;
1937 if (($level->id=="1") && ($admin <1)) {
1938 echo("");
1939 } else {
1940
1941 $colour="#" . $cTheme->table_bgcolor;
1942 if ($level->suspend_expires>time()) { $colour="#" . $cTheme->main_warnmsg; }
1943
1944 if ($user_records=="Y" && $level->channel_id==1) { $colour = "#" . $cTheme->table_tr_enlighten; }
1945
1946 if ($user_records=="N" && $level->channel_id==1 && ($level->uflags & 128)) { $colour = "#eeeeee"; }
1947
1948 echo("
1949<tr bgcolor=$colour>
1950 <td valign=top><font size=-1>");
1951 if ($user_records=="Y") {
1952 echo("<a href=\"channels.php?id=$level->channel_id\">$level->name</a>");
1953 } else {
1954 echo("<a href=\"users.php?id=$level->user_id\">$level->user_name</a>");
1955 if ( ( (acl(XIPR_VIEW_OWN) && ($level->user_id==$user_id)) ||
1956 (acl(XIPR_VIEW_OTHERS)) ||
1957 (acl(XIPR_MOD_OWN) && ($level->user_id==$user_id)) ||
1958 (acl(XIPR_MOD_OTHERS)) ||
1959 $admin >= 800 ) && $level->channel_id==1
1960 ) {
1961 echo "<br>";
1962 echo "<font color=#";
1963 $rtt = pg_safe_exec("SELECT COUNT(id) AS count FROM ip_restrict WHERE user_id='" . (int)$level->user_id . "'");
1964 $rto = pg_fetch_object($rtt);
1965 switch ($rto->count) {
1966 case 0:
1967 echo "33aa33>";
1968 //echo "NO IPR";
1969 break;
1970 default:
1971 echo "aa3333>";
1972 echo "IPR";
1973 break;
1974 }
1975 echo "</font>";
1976 }
1977 if ($level->channel_id==1 && ($level->uflags & 128)) { echo " ALUMNI"; }
1978 }
1979 echo("</td>");
1980 if ($last_mod) {
1981 echo "<td valign=top><font size=-1>";
1982 echo "<font color=#" . $cTheme->main_linkover . "><b>added by</b></font> :<br><i>";
1983 if ($level->added<40000) {
1984 echo "<b>Information not available</b> - (the eternity and ages ago ...)";
1985 } else {
1986 echo $level->added_by . "<br>(" . drake_duration((time()-($level->added))) . " ago)";
1987 }
1988 echo "</i>\n";
1989 if ($level->last_modif != $level->added) {
1990 echo "<br><br><b>last modif by</b> :<br><i>";
1991 echo $level->last_modif_by . "<br>(" . drake_duration((time()-($level->last_modif))) . " ago)";
1992 echo "</i>\n";
1993 }
1994 echo "</font></td>\n";
1995 }
1996 echo ("<td valign=top align=center>
1997 <font size=-1>");
1998 if ($level->access==1000 || ($level->access==500 && $level->channel_id!=1)) {
1999 echo "<b>" . $level->access . "</b>";
2000 } else {
2001 echo $level->access;
2002 }
2003 echo ("</td>
2004 <td valign=top align=center>");
2005
2006 if ($level->flags&0x01) { // AUTO OP On
2007 echo "<img src=\"images/inuse.gif\" alt=\"[@]\">";
2008 } else {
2009 echo " ";
2010 }
2011
2012 echo("</td><td valign=top align=center>");
2013
2014 if ($level->flags&0x08) { // AUTO VOICE On
2015 echo "<img src=\"images/inuse.gif\" alt=\"[+]\">";
2016 } else {
2017 echo " ";
2018 }
2019
2020 if($display_autoinvite == "Y") {
2021 echo("</td><td valign=top align=center>");
2022
2023 if ($level->flags&0x20) { // AUTO INVITE On
2024 echo "<img src=\"images/inuse.gif\" alt=\"[+]\">";
2025 } else {
2026 echo " ";
2027 }
2028
2029 }
2030
2031 echo("
2032 </td>
2033 <td valign=top align=left>");
2034
2035 $expire=$level->suspend_expires;
2036 $now=time();
2037 $duration=$expire-$now;
2038
2039 if ($duration < 1) { echo " "; }
2040
2041 if ($level->suspend_expires>time()) {
2042 echo("<font size=-2>By " . $level->suspend_by . "<br> " . drake_duration($duration) . " remains</font>");
2043 }
2044
2045 if ($show_edit == "Y") {
2046 if (($viewer_level >= $level_modinfo) && (($viewer_level > $level->access) || ($level->id == $user_id))) {
2047
2048 $button=" <form action=\"access.php\" method=\"get\">
2049 <input type=\"hidden\" name=\"action\" value=\"edit\">
2050 <input type=\"hidden\" name=\"channel\" value=\"$level->channel_id\">
2051 <input type=\"hidden\" name=\"user\" value=\"$level->user_id\">
2052 <input type=\"submit\" value=\"Edit\"></form>";
2053
2054 } else if ($admin > $level_modinfo) {
2055
2056 $button=" <form action=\"access.php\" method=\"get\">
2057 <input type=\"hidden\" name=\"action\" value=\"edit\">
2058 <input type=\"hidden\" name=\"channel\" value=\"$level->channel_id\">
2059 <input type=\"hidden\" name=\"user\" value=\"$level->user_id\">
2060 <input type=\"submit\" value=\"Force\"></form>";
2061
2062 } else {
2063
2064 $button=" ";
2065
2066 }
2067
2068 echo("</td>
2069 <td valign=top>
2070 $button
2071 </td>");
2072 } else {
2073 echo "</td>\n";
2074 }
2075
2076 echo("</tr>");
2077 }
2078}
2079
2080function review_count_add($UID) {
2081 if (($UID+0)<=0) { return false; }
2082 $qtest = "SELECT * FROM statistics WHERE stats_type=1 AND users_id='" . (int)$UID . "'";
2083 $rt = pg_safe_exec($qtest);
2084 if (!$rt) { return false; }
2085 if (pg_numrows($rt)==0) {
2086 $qcr = "INSERT INTO statistics (users_id,stats_type,stats_value_int,stats_value_chr,last_updated) VALUES ('" . (int)$UID . "',1,1,'',now()::abstime::int4)";
2087 $rcr = pg_safe_exec($qcr);
2088 if (!$rcr) { return false; }
2089 return($rcr);
2090 } else {
2091 $ro = pg_fetch_object($rt);
2092 $qupd = "UPDATE statistics SET stats_value_int='" . ($ro->stats_value_int+1) . "',last_updated=now()::abstime::int4 WHERE stats_type=1 AND users_id='" . (int)$UID . "'";
2093 $rupd = pg_safe_exec($qupd);
2094 return($rupd);
2095 }
2096}
2097
2098function review_count_rem($UID) {
2099 if (($UID+0)<=0) { return false; }
2100 $qtest = "SELECT * FROM statistics WHERE stats_type=1 AND users_id='" . (int)$UID . "'";
2101 $rt = pg_safe_exec($qtest);
2102 if (!$rt) { return false; }
2103 if (pg_numrows($rt)==0) { return false; } else {
2104 $ro = pg_fetch_object($rt);
2105 $qupd = "UPDATE statistics SET stats_value_int='" . (($ro->stats_value_int)-1) . "',last_updated=now()::abstime::int4 WHERE stats_type=1 AND users_id='" . (int)$UID . "'";
2106 $rupd = pg_safe_exec($qupd);
2107 return($rupd);
2108 }
2109}
2110
2111function is_locked_va($VDATA,$forceignorecase = 0) {
2112 // load lock list
2113 $r = pg_safe_exec("SELECT user_name FROM noreg WHERE type=6");
2114 while ($o = pg_fetch_object($r)) {
2115 unset($pattern);unset($tocheck);
2116 if (substr($o->user_name,0,1)=="!") {
2117 // ignore case in check
2118 $pattern = strtolower(substr($o->user_name,1));
2119 $tocheck = strtolower($VDATA);
2120 } else {
2121 if ($forceignorecase == 1) {
2122 // ignore case in check
2123 $pattern = strtolower($o->user_name);
2124 $tocheck = strtolower($VDATA);
2125 } else {
2126 $pattern = $o->user_name;
2127 $tocheck = $VDATA;
2128 }
2129 }
2130 if (ereg("^".str_replace("*",".*",str_replace("?",".",$pattern))."$", $tocheck)) { // MATCH! (locked !@#)
2131 return true;
2132 }
2133 }
2134 return false;
2135}
2136
2137function log_channel($channel_id,$event_id,$msg) {
2138 global $user_id,$admin,$channel_events,$IPNOLOG_UIDS;
2139 if (not_in_tab($user_id,$IPNOLOG_UIDS)) {
2140 if (cl_host()!="NO_DNS") {
2141 $uhost = cl_host();
2142 } else {
2143 $uhost = cl_ip();
2144 }
2145 } else {
2146 $uhost = "xx.xx.xx.xx";
2147 }
2148 $auser = "";
2149 if ($admin==0 && has_acl($user_id)) { $auser = " [ACL]"; }
2150 $res0 = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$user_id . "'");
2151 if (pg_numrows($res0)==0) {
2152 echo "<b>Invalid User ID</b>";
2153 return(0);
2154 }
2155 $row0 = pg_fetch_object($res0,0);
2156 $user_name = $row0->user_name;
2157 $res0 = pg_safe_exec("SELECT name FROM channels WHERE id='" . (int)$channel_id . "'");
2158 if (pg_numrows($res0)==0) {
2159 echo "<b>Invalid Channel ID</b>";
2160 return(0);
2161 }
2162 $row0 = pg_fetch_object($res0,0);
2163 $channel_name = $row0->name;
2164 if ($event_id<1 || $event_id>count($channel_events)) {
2165 echo "<b>Invalid Event ID</b>";
2166 return(0);
2167 }
2168 $message = "[Web]: $user_name!unknown@$uhost" . $auser . " ($user_name) " . $msg;
2169 $query = "INSERT INTO channellog (ts,channelid,event,message,last_updated,deleted) VALUES (now()::abstime::int4," . (int)$channel_id . "," . (int)$event_id . ",'$message',now()::abstime::int4,0)";
2170 //echo $query;
2171 $res = pg_safe_exec($query);
2172 return($res);
2173}
2174
2175function log_user($uid,$event_id,$msg) {
2176 global $user_id,$admin,$ENABLE_COOKIE_TABLE,$user_events,$IPNOLOG_UIDS;
2177 $auser = "";
2178 if ($admin==0 && has_acl($user_id)) { $auser = " [ACL]"; }
2179 if (not_in_tab($user_id,$IPNOLOG_UIDS)) {
2180 if (cl_host()!="NO_DNS") {
2181 $uhost = cl_host();
2182 } else {
2183 $uhost = cl_ip();
2184 }
2185 } else {
2186 $uhost = "xx.xx.xx.xx";
2187 }
2188
2189 $res0 = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$uid . "'");
2190 if (pg_numrows($res0)==0) {
2191 echo "<b>Invalid User ID (1)</b>";
2192 return(0);
2193 }
2194 $row0 = pg_fetch_object($res0,0);
2195 $uname = $row0->user_name;
2196
2197 $res0 = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$user_id . "'");
2198 if (pg_numrows($res0)==0) {
2199 $user_name = $uname;
2200 } else {
2201 $row0 = pg_fetch_object($res0,0);
2202 $user_name = $row0->user_name;
2203 }
2204
2205 if ($event_id<1 || $event_id>count($user_events)) {
2206 echo "<b>Invalid Event ID</b>";
2207 return(0);
2208 }
2209 $msg = str_replace("%I","$uid",$msg);
2210 $msg = str_replace("%U","$uname",$msg);
2211 $message = "[Web]: " . $user_name . "!unknown@" . $uhost . $auser . " (" . $user_name . ") " . $msg;
2212 if ($event_id == 5) { $message = $msg . " (by " . $user_name . ")"; }
2213 $query = "INSERT INTO userlog (ts,user_id,event,message,last_updated) VALUES (now()::abstime::int4," . (int)$uid . "," . (int)$event_id . ",'$message',now()::abstime::int4)";
2214 //echo $query;
2215 $res = pg_safe_exec($query);
2216 return($res);
2217}
2218
2219function make_duration($duration)
2220{
2221 $ret="";
2222 if ($duration<=0)
2223 return "";
2224// if ($duration>7*24*60*60) {
2225// $ret .= (int)($duration/(7*24*60*60)) . "w ";
2226// $duration %= (7*24*60*60);
2227// }
2228 if ($duration>24*60*60) {
2229 $ret .= (int)($duration/(24*60*60)) . "d ";
2230 $duration %= (24*60*60);
2231 }
2232 if ($duration>60*60) {
2233 $ret .= (int)($duration/(60*60)) . "h ";
2234 $duration %= (60*60);
2235 }
2236 if ($duration>60) {
2237 $ret .= (int)($duration/60) . "m ";
2238 $duration %= 60;
2239 }
2240 if ($duration>0) {
2241 $ret .= $duration . "s ";
2242 }
2243 return $ret;
2244}
2245
2246function drake_duration($duration)
2247{
2248 $days .= (int)($duration/(24*60*60));
2249 $duration %= (24*60*60);
2250 $hours .= (int)($duration/(60*60));
2251 $duration %= (60*60);
2252 $mins .= (int)($duration/60);
2253 $duration %= 60;
2254 $ret=sprintf("%01d days, %02d:%02d:%02d",$days,$hours,$mins,$duration);
2255 return $ret;
2256}
2257
2258function gen_server_url() {
2259 if (isset($_SERVER["HTTP_X_FORWARDED_FOR"])) { // proxy connection
2260 if (ereg(":",$_SERVER["HTTP_HOST"])) {
2261 $pxp = explode(":",$_SERVER["HTTP_HOST"]);
2262 $port = (int)$pxp[1];
2263 } else {
2264 $port = 80;
2265 }
2266 } else {
2267 $port = (int)$_SERVER["SERVER_PORT"];
2268 }
2269 if ($port <= 0) { $port = 80; }
2270 if ($port == "80") {
2271 return "http://" . $_SERVER["SERVER_NAME"];
2272 } else {
2273 return "http://" . $_SERVER["SERVER_NAME"] . ":" . $port;
2274 }
2275}
2276
2277function C_strtolower($txt){
2278 return(strtolower(strtr($txt,"ÀÃÂÃÄÅÇÈÉÊËÌÃÃŽÃÑÒÓÔÕÖØÙÚÛÜÃ","à áâãäåçèéêëìÃîïñòóôõöøùúûüý")));
2279}
2280
2281function C_strtoupper($txt){
2282 return(strtoupper(strtr($txt,"à áâãäåçèéêëìÃîïñòóôõöøùúûüý","ÀÃÂÃÄÅÇÈÉÊËÌÃÃŽÃÑÒÓÔÕÖØÙÚÛÜÃ")));
2283}
2284
2285function js_redir($url, $toTop = 0) {
2286 echo "<script language=\"JavaScript\">\n";
2287 echo "<!--\n";
2288 if ($toTop == 1) { echo "top."; }
2289 echo "location.href='" . $url . "';\n";
2290 echo "//-->\n";
2291 echo "</script>\n";
2292}
2293
2294function initial_complaint( $ticketNumber , $showCurrentOwner = 1) {
2295 global $user_id, $admin, $cpt_name;
2296 $ret = "";
2297 $idt = explode("-",$ticketNumber);
2298 $r = pg_safe_exec("SELECT * FROM complaints WHERE id='" . (int)$idt[0] . "' AND ticket_number='" . $ticketNumber . "'");
2299 if ($o = pg_fetch_object($r)) {
2300 // check if this is a referenced complaints for the "reader"
2301 $refline = "";
2302 $rref = pg_safe_exec("SELECT * FROM complaints_reference WHERE complaints_ref='" . (int)$idt[0] . "' AND referenced_to='" . (int)$user_id . "'");
2303 if ($oref = pg_fetch_object($rref)) {
2304 // yes !
2305 $refline .= "<tr>";
2306 $refline .= "<td bgcolor=#000000 valign=top align=right><font color=#ffffff>";
2307 $refline .= "Referenced by</font></td>";
2308 $refline .= "<td width=99% valign=top>";
2309 $ruQ = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$oref->referenced_by . "'");
2310 $roQ = pg_fetch_object($ruQ);
2311 $refline .= "<b>" . $roQ->user_name . "</b> on " . cs_time($oref->reference_ts) . " (" . $oref->reference_ts . ")";
2312 $refline .= "</td></tr>\n";
2313 if ($oref->is_new == 1) { // update "is_new" when viewing it the first time...
2314 pg_safe_exec("UPDATE complaints_reference SET is_new='0' WHERE complaints_ref='" . (int)$idt[0] . "' AND referenced_to='" . (int)$user_id . "'");
2315 }
2316 }
2317 //$ret .= "<table width=100% border=1 cellpadding=5 cellspacing=0>";
2318 $ret .= $refline;
2319 $ret .= "<tr>";
2320 $ret .= "<td bgcolor=#000000 valign=top align=right><font color=#ffffff>";
2321 $ret .= "From authenticated user</font></td>";
2322 $ret .= "<td width=99% valign=top>";
2323 if ($o->from_id == 0) { $ret .= "<b>NO</b>"; } else {
2324 $rr = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$o->from_id . "'");
2325 if ($oo = pg_fetch_object($rr)) {
2326 $ret .= "<a href=\"../users.php?id=" . $o->from_id . "\" target=_blank>" . $oo->user_name . "</a>";
2327 } else {
2328 $ret .= "<b>NOT FOUND</b>";
2329 }
2330 }
2331 $ret .= "</td></tr>\n";
2332
2333 $ret .= "<tr>";
2334 $ret .= "<td bgcolor=#990000 valign=top align=right><font color=#ffffff>";
2335 $ret .= "From IP</font></td>";
2336 $ret .= "<td width=99% valign=top>";
2337 $ret .= $o->created_ip;
2338 $iphost = gethostbyaddr($o->created_ip);
2339 $ret .= " (" . $iphost . ")";
2340 $ret .= "</td></tr>\n";
2341
2342 $ret .= "<tr>";
2343 $ret .= "<td bgcolor=#000000 valign=top align=right><font color=#ffffff>";
2344 $ret .= "Posted date</font></td>";
2345 $ret .= "<td width=99% valign=top>";
2346 $ret .= cs_time($o->created_ts) . " (" . $o->created_ts . ")";
2347 $ret .= "</td></tr>\n";
2348
2349 $ret .= "<tr>";
2350 $ret .= "<td bgcolor=#000000 valign=top align=right><font color=#ffffff>";
2351 $ret .= "E-Mail for replies</font></td>";
2352 $ret .= "<td width=99% valign=top>";
2353 $ret .= "<a href=\"mailto:" . $o->from_email . "\"><b>" . $o->from_email . "</b></a>";
2354 $ret .= "</td></tr>\n";
2355
2356 $ret .= "<tr>";
2357 $ret .= "<td bgcolor=#000000 valign=top align=right><font color=#ffffff>";
2358 $ret .= "E-Mail in record</font></td>";
2359 $ret .= "<td width=99% valign=top>";
2360 if ($o->inrec_email=="") { $ret .= "<b>N/A</b>"; } else { $ret .= $o->inrec_email; }
2361 $ret .= "</td></tr>\n";
2362
2363 $ret .= "<tr>";
2364 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2365 $ret .= "Original Complaint type</font></td>";
2366 $ret .= "<td width=99% valign=top>";
2367 $ret .= $cpt_name[$o->complaint_type];
2368 $ret .= "</td></tr>\n";
2369
2370 switch ($o->complaint_type) {
2371 case 1:
2372 $ret .= "<tr><td colspan=2 valign=center>Username/Password checked OK</td></tr>\n";
2373 break;
2374 case 2:
2375 $ret .= "<tr>";
2376 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2377 $ret .= "Victim channel</font></td>";
2378 $ret .= "<td width=99% valign=top>";
2379 $ret .= $o->complaint_channel1_name;
2380 if ($o->complaint_channel1_id>0) { $ret .= " (<a href=\"../channels.php?id=" . $o->complaint_channel1_id . "\" target=_blank>registered</a>)"; }
2381 $ret .= "</td></tr>\n";
2382
2383 $ret .= "<tr>";
2384 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2385 $ret .= "Offending channel</font></td>";
2386 $ret .= "<td width=99% valign=top>";
2387 $ret .= $o->complaint_channel2_name;
2388 if ($o->complaint_channel2_id>0) { $ret .= " (<a href=\"../channels.php?id=" . $o->complaint_channel2_id . "\" target=_blank>registered</a>)"; }
2389 $rcc = pg_safe_exec("SELECT COUNT(id) AS count FROM complaints WHERE status!=99 AND created_ts<" . (int)$o->created_ts . " AND complaint_type=2 AND lower(complaint_channel2_name)='" . post2db(strtolower($o->complaint_channel2_name)) . "'");
2390 $rco = pg_fetch_object($rcc);
2391 $ret .= " ";
2392 $ret .= "<b>" . (int)$rco->count . "</b> previous complaint";
2393 if ($rco->count>1) { $ret .= "s"; }
2394 $ret .= " (excluding this one)</td></tr>\n";
2395
2396 break;
2397 case 3:
2398 $ret .= "<tr>";
2399 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2400 $ret .= "Channel to be objected</font></td>";
2401 $ret .= "<td width=99% valign=top>";
2402 $ret .= $o->complaint_channel1_name;
2403 $rp = pg_safe_exec("SELECT pending.status,pending.channel_id,pending.created_ts FROM channels,pending WHERE lower(channels.name)='" . post2db(strtolower($o->complaint_channel1_name)) . "' AND pending.channel_id=channels.id");
2404 if ($ro = pg_fetch_object($rp)) {
2405 $ret .= " (<a href=\"../view_app.php?id=" . $ro->created_ts . "-" . $ro->channel_id . "\" target=_blank>";
2406 $ret .= "application";
2407 $ret .= "</a>)";
2408 }
2409 $ret .= "</td></tr>\n";
2410
2411 break;
2412 case 4:
2413 $ret .= "<tr>";
2414 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2415 $ret .= "Purged channel name</font></td>";
2416 $ret .= "<td width=99% valign=top>";
2417 $ret .= $o->complaint_channel1_name;
2418 $ret .= "</td></tr>\n";
2419
2420 break;
2421 case 5:
2422 $ret .= "<tr>";
2423 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2424 $ret .= "Purged channel name</font></td>";
2425 $ret .= "<td width=99% valign=top>";
2426 $ret .= $o->complaint_channel1_name;
2427 $ret .= "</td></tr>\n";
2428
2429 break;
2430 default:
2431 case 99:
2432 break;
2433
2434 }
2435
2436 $ret .= "<tr>";
2437 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2438 $ret .= "Original Complaint summary</font></td>";
2439 $ret .= "<td width=99% valign=top>";
2440 $ret .= trim(str_replace("\n","<br>\n",htmlspecialchars($o->complaint_text)));
2441 $ret .= "</td></tr>\n";
2442
2443 $ret .= "<tr>";
2444 $ret .= "<td bgcolor=#0000b2 valign=top align=right><font color=#ffffff>";
2445 $ret .= "Original Complaint logs</font></td>";
2446 $ret .= "<td width=99% valign=top>";
2447 if (trim(str_replace("\n","<br>\n",htmlspecialchars($o->complaint_logs)))!="") {
2448 $ret .= trim(str_replace("\n","<br>\n",htmlspecialchars($o->complaint_logs)));
2449 } else {
2450 $ret .= "<b>N/A</b>";
2451 }
2452 $ret .= "</td></tr>\n";
2453
2454 $ret .= "<tr>";
2455 $ret .= "<td bgcolor=#990000 valign=top align=right><font color=#ffffff>";
2456 $ret .= "First replied by</font></td>";
2457 $ret .= "<td width=99% valign=top>";
2458 if ($o->reviewed_by_id==0) {
2459 $ret .= "<b>NOT REPLIED</b>";
2460 } else {
2461 $rx = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$o->reviewed_by_id . "'");
2462 $ox = pg_fetch_object($rx);
2463 $ret .= "<b>" . $ox->user_name . "</b> on <b>" . cs_time($o->reviewed_ts) . "</b> (" . $o->reviewed_ts . ")";
2464 }
2465 $ret .= "</td></tr>\n";
2466 if ($showCurrentOwner) {
2467 $ret .= "<tr>";
2468 $ret .= "<td bgcolor=#990000 valign=top align=right><font color=#ffffff>";
2469 $ret .= "Currently owned by</font></td>";
2470 $ret .= "<td width=99% valign=top>";
2471 if ($o->current_owner==0) {
2472 $ret .= "<b>NOT OWNED</b>";
2473 } else {
2474 $rx = pg_safe_exec("SELECT user_name FROM users WHERE id='" . (int)$o->current_owner . "'");
2475 $ox = pg_fetch_object($rx);
2476 $ret .= "<b>" . $ox->user_name . "</b>";
2477 }
2478 $ret .= "</td></tr>\n";
2479 }
2480
2481/*
2482 $ret .= "<tr>";
2483 $ret .= "<td bgcolor=#990000 valign=top align=right><font color=#ffffff>";
2484 $ret .= "Priority level</font></td>";
2485 $ret .= "<td width=99% valign=top>";
2486 $ret .= $o->nicelevel;
2487 if ($o->nicelevel>0) {
2488 $ret .= " (<big>";
2489 for ($x=0;$x<$o->nicelevel;$x++) {
2490 $ret .= "*";
2491 }
2492 $ret .= "</big>) ";
2493 }
2494 $ret .= "</td></tr>\n";
2495*/
2496 }
2497 return $ret;
2498}
2499
2500function local_seclog( $logMessage, $logFileName = "/tmp/cs.log", $logDescription = "SecLog" ) {
2501 global $user_id,$admin;
2502 $fp = fopen($logFileName, "a+");
2503 if ($fp) {
2504 $username = "(unknown)";
2505 $ip = cl_ip();
2506 $admlvl = (int)$admin;
2507 if ($user_id>0) {
2508 $rr = @pg_safe_exec("SELECT user_name FROM users WHERE id=" . (int)$user_id);
2509 if ($oo = @pg_fetch_object($rr,0)) {
2510 $username = $oo->user_name;
2511 }
2512 }
2513 if ($admlvl==0 && has_acl($user_id)) { $admlvl = "ACL"; }
2514 $msgToWrite = "[" . $logDescription . "] {" . date("Y-m-d H:i:s T") . "} " . $username . " (" . (int)$user_id . ") " . $ip . " *" . $admlvl . " :";
2515 $msgToWrite .= $logMessage;
2516 $msgToWrite .= "\n";
2517 fwrite($fp, $msgToWrite);
2518 fclose($fp);
2519 return 1;
2520 }
2521 return 0;
2522}
2523
2524function log_webrelay( $logMessage ) {
2525 global $user_id,$admin;
2526 $username = "(unknown)";
2527 $ip = cl_ip();
2528 $admlvl = (int)$admin;
2529 if ($user_id>0) {
2530 $rr = @pg_safe_exec("SELECT user_name FROM users WHERE id=" . (int)$user_id);
2531 if ($oo = @pg_fetch_object($rr,0)) {
2532 $username = $oo->user_name;
2533 }
2534 }
2535 if ($admlvl==0 && has_acl($user_id)) { $admlvl = "ACL"; }
2536 $msgToWrite = "[Web] " . N_get_pure_string($username) . " (" . (int)$user_id . ") ";
2537 $msgToWrite .= $logMessage;
2538 $msgToWrite .= "\n";
2539 @pg_safe_exec("INSERT INTO webnotices (created_ts,contents) VALUES (now()::abstime::int4,'" . post2db($msgToWrite) . "')");
2540 return 1;
2541}
2542
2543function isinarray($array,$value) {
2544 $l_array = count($array); $is_in = 0;
2545 for ($x=0;$x<$l_array;$x++) { if ($value == $array[$x]) { $is_in = 1; } }
2546 return $is_in;
2547}
2548
2549function is_ip_restrict() { // assumes user_id is defined or returns TRUE.
2550 global $user_id;
2551 if ((int)$user_id<=0) { return 1; }
2552 $ipmatch = 0;
2553 $rrip = @pg_safe_exec("SELECT * FROM ip_restrict WHERE user_id=" . (int)$user_id . "");
2554 if ($rrip) {
2555 if (pg_numrows($rrip)>0) {
2556 while ($rripo = pg_fetch_object($rrip)) {
2557 if (matches_ip_restrict($rripo)) { $ipmatch = 1; break; }
2558 }
2559 if ($ipmatch == 0) { return 1; } else { return 0; }
2560 }
2561 }
2562 if (IPR_REQUIRED) { return 1; } else { return 0; }
2563}
2564
2565function matches_ip_restrict($ripo) {
2566 $curr_IP = cl_ip();
2567 $curr_HOST = cl_host();
2568 if ($curr_HOST == $curr_IP || $curr_HOST == "NO_DNS") { $curr_HOST = gethostbyaddr($curr_IP); }
2569 $curr_IP_long = ip2long($curr_IP);
2570 if ($ripo->allowrange2 != 0) { // IP range
2571 if ($curr_IP_long>=$ripo->allowrange1 && $curr_IP_long<=$ripo->allowrange2) { return 1; } else { return 0; }
2572 } elseif ($ripo->allowrange1 != 0) { // single IP
2573 if ($curr_IP_long == $ripo->allowrange1) { return 1; } else { return 0; }
2574 } elseif ($ripo->allowmask != "") { // IP / Host mask
2575 if (matches_wild($curr_IP, $ripo->allowmask) || matches_wild($curr_HOST, $ripo->allowmask)) { return 1; } else { return 0; }
2576 }
2577 return 0;
2578}
2579
2580function matches_wild($string_to_match,$wildcard_mask) {
2581 $regexp = "/^" . str_replace("?",".",str_replace("*",".*",str_replace(".","\.",str_replace("-","\-",str_replace("_","\_",$wildcard_mask))))) . "$/";
2582 return (preg_match($regexp,$string_to_match));
2583}
2584
2585function std_sanitise_username(&$username) {
2586 $username2="";
2587 while ($username!="") {
2588 $c=$username[0];
2589 if (($c>="A" && $c<="Z" ) || ($c>="a" && $c<="z") || ($c>="0" && $c<="9")) {
2590 $username2=$username2 . $c;
2591 }
2592 $username=substr($username,2);
2593 }
2594 $username=$username2;
2595}
2596
2597function std_admin() { // Return admin level
2598 global $user_id,$database,$REQUEST_URI,$mode,$auth,$uuflags,$r_admin,$is_alumni;
2599
2600 if (($user_id+0)<=0) { return (0); }
2601
2602
2603 $query="SELECT access FROM levels WHERE channel_id=1 AND user_id=" . (int)$user_id;
2604// echo "Q: $query";
2605 $adminR = pg_safe_exec($query);
2606
2607 if (pg_numrows($adminR)==0) {
2608 $admin=0;
2609 } else {
2610 $adminO=pg_fetch_object($adminR,0);
2611 $admin=$adminO->access;
2612 }
2613
2614 if (BOFH_PASS_ADMIN && !BOFH_PASS_USER) {
2615 if (!is_pw_secure_logged()) {
2616 if (ereg("left.php",$REQUEST_URI)) {
2617 $mode = "empty";
2618 } else {
2619 if (!ereg("confirm",$REQUEST_URI) && !ereg("pwreset.php",$REQUEST_URI) && !ereg("main.php",$REQUEST_URI) && !ereg("logout.php",$REQUEST_URI) && !ereg("right.php",$REQUEST_URI) && !ereg("securize_pw.php",$REQUEST_URI)) {
2620 $unsecure_pw_url = "securize_pw.php?sba=1&SECURE_ID=" . md5( $user_id . CRC_SALT_0013 . $auth );
2621 header("Location: " . $unsecure_pw_url . "\n\n");
2622 die;
2623 }
2624 }
2625 }
2626 }
2627
2628 $r_admin = $admin;
2629 if ($uuflags & 64) { return(0); } // if DISABLEAUTH is set to ON, you're seen as no * person.
2630 if (($uuflags & 128) && $admin>0) { $is_alumni = 1; return(0); } // if ALUMNI is set to ON, you're seen as no * person.
2631
2632 return $admin;
2633}
2634
2635unset($is_alumni); $is_alumni = 0;
2636
2637function std_security_chk($authcookline) {
2638 // TODO: Make sure auth is 0-9a-z
2639 global $user_id,$database,$ENABLE_COOKIE_TABLE,$USER_TZ,$REQUEST_URI,$mode,$uuflags,$r_admin;
2640
2641 $authz = explode(":",$authcookline);
2642 $auth_user = $authz[0];
2643 $auth_uid = $authz[1];
2644 $auth_ts = $authz[2];
2645 $authcook = $authz[3];
2646
2647 if ($authz[5]!=md5($authz[4] . CRC_SALT_EXT1 . $authcook)) { return 0; }
2648
2649 $query="SELECT user_id,tz_setting FROM webcookies WHERE cookie='" . $authcook . "' AND expire>now()::abstime::int4";
2650 $ENABLE_COOKIE_TABLE = 1;
2651 $auth=pg_safe_exec($query);
2652 $ENABLE_COOKIE_TABLE = 0;
2653
2654
2655 if (pg_numrows($auth) == 0) {
2656 $user_id=0;
2657 } else {
2658 $user=pg_fetch_object($auth,0);
2659 $user_id=$user->user_id;
2660
2661 $rrr = pg_safe_exec("SELECT flags FROM users WHERE id='" . (int)$user_id . "'");
2662 $ooo = pg_fetch_object($rrr,0);
2663 $uuflags = (int)$ooo->flags;
2664 if ((int)$ooo->flags & 1) { // suspended, no auth !
2665 $ENABLE_COOKIE_TABLE = 1;
2666 pg_safe_exec("DELETE FROM webcookies WHERE cookie='" . $authcook . "' AND user_id='" . $user_id . "'");
2667 $ENABLE_COOKIE_TABLE = 0;
2668 return(0);
2669 }
2670 $USER_TZ = $user->tz_setting;
2671 $query="UPDATE webcookies SET expire=(now()::abstime::int4+" . COOKIE_EXPIRE . ") WHERE user_id='" . (int)$user_id . "' AND cookie='" . $authcook . "'";
2672 $dynts = time();
2673 $cook2 = md5( $dynts . CRC_SALT_EXT1 . $authcook );
2674 if (COOKIE_DOMAIN!="") {
2675 SetCookie("auth",$auth_user . ":" . $auth_uid . ":" . $auth_ts . ":" . $authcook . ":" . $dynts . ":" . $cook2,time()+COOKIE_EXPIRE,"/",COOKIE_DOMAIN);
2676 } else {
2677 SetCookie("auth",$auth_user . ":" . $auth_uid . ":" . $auth_ts . ":" . $authcook . ":" . $dynts . ":" . $cook2,time()+COOKIE_EXPIRE,"/");
2678 }
2679 $ENABLE_COOKIE_TABLE = 1;
2680 pg_safe_exec($query);
2681 $ENABLE_COOKIE_TABLE = 0;
2682 }
2683 if (std_admin()==0 && !acl()) {
2684 if (site_off()) {
2685 return 0;
2686 }
2687 } else {
2688 if (is_ip_restrict()) {
2689 return 0;
2690 }
2691 }
2692
2693 if (BOFH_PASS_USER && (($user_id+0)>0)) {
2694 if (!is_pw_secure_logged()) {
2695 if (ereg("left.php",$REQUEST_URI)) {
2696 $mode = "empty";
2697 } else {
2698 if (!ereg("confirm",$REQUEST_URI) && !ereg("pwreset.php",$REQUEST_URI) && !ereg("main.php",$REQUEST_URI) && !ereg("logout.php",$REQUEST_URI) && !ereg("right.php",$REQUEST_URI) && !ereg("securize_pw.php",$REQUEST_URI)) {
2699 $unsecure_pw_url = "securize_pw.php?sba=1&SECURE_ID=" . md5( $user_id . CRC_SALT_0013 . $authcook );
2700 header("Location: " . $unsecure_pw_url . "\n\n");
2701 die;
2702 }
2703 }
2704 }
2705 }
2706
2707 return $user_id;
2708}
2709
2710function get_theme_info() {
2711 global $ENABLE_COOKIE_TABLE;
2712 $ECT = $ENABLE_COOKIE_TABLE;
2713 $ENABLE_COOKIE_TABLE = 1;
2714
2715/* TBF
2716 $c_ts = time();
2717 if (AUTO_SWITCH_THEMES) {
2718 $cyear = date("Y",$c_ts);
2719
2720 $start_halloween = mktime(0,0,0,10,31,$cyear);
2721 $end_halloween = mktime(23,59,59,11,1,$cyear);
2722
2723 $start_xmas = mktime(0,0,0,12,22,$cyear);
2724 $end_xmas = mktime(23,59,59,12,27,$cyear);
2725
2726 if ($c_ts>=$start_halloween && $c_ts<=$end_halloween) { $ishalloween = 1; } else { $ishalloween = 0; }
2727 if ($c_ts>=$start_xmas && $c_st<=$end_xmas) { $isxmas = 1; } else { $isxmas = 0; }
2728
2729 if ($ishalloween) {
2730
2731 } else if ($isxmas) {
2732
2733 }
2734
2735 } else {
2736
2737 }
2738*/
2739
2740 $res = pg_safe_exec("SELECT * FROM themes WHERE name='" . STD_THEME . "'"); // Select STD theme from config.inc
2741 if (pg_numrows($res)==0) { // if it doesnt exist...
2742 unset($res);
2743 $res = pg_safe_exec("SELECT * FROM themes WHERE id=1"); // .. select the default theme
2744 if (pg_numrows($res)==0) { // if it doesnt exist (bad !)
2745 die("Your default Theme is not present, please check your site is configured correctly. Recent changes may have caused this.");
2746 }
2747 }
2748
2749 $row = pg_fetch_object($res,0);
2750
2751 $cTheme = $row;
2752 $cTheme->status = 1;
2753 $ENABLE_COOKIE_TABLE = $ECT;
2754
2755 return $cTheme;
2756}
2757
2758function std_theme_body($special_path = "",$onLoadScript = "") { // for "main" only
2759 global $cTheme;
2760 echo "<body bgcolor=#" . $cTheme->main_bgcolor . " text=#" . $cTheme->main_textcolor . " link=#" . $cTheme->main_linkcolor . " vlink=#" . $cTheme->main_linkcolor . " alink=#" . $cTheme->main_linkover . "";
2761 if ($cTheme->main_bgimage!="") {
2762 echo " background=\"" . $special_path . "themes/data/" . $cTheme->sub_dir . "/" . $cTheme->main_bgimage . "\"";
2763 }
2764 if ($onLoadScript!="") { echo " onLoad=\"" . $onLoadScript . "\""; }
2765 echo ">\n";
2766 echo "<font face=\"arial,helvetica\" size=-1>\n";
2767}
2768
2769function std_theme_styles($include_html = 0) { // for "main" only
2770 global $cTheme;
2771 if ($include_html) {
2772 echo "<html><head><title>Register</title>\n";
2773 }
2774 echo "<style type=text/css>\n";
2775 echo "<!--\n";
2776 echo "a:link { font-family: arial,helvetica; color: #" . $cTheme->main_linkcolor . "; }\n";
2777 echo "a:visited { font-family: arial,helvetica; color: #" . $cTheme->main_linkcolor . "; }\n";
2778 echo "a:hover { font-family: arial,helvetica; color: #" . $cTheme->main_linkover . "; }\n";
2779 echo "//-->\n";
2780 echo "</style>\n";
2781 if ($include_html) { echo "</head>\n"; }
2782}
2783
2784function std_connect() {
2785 global $database;
2786
2787 if (REMOTEDB_PASS!="") {
2788 $database= @pg_pconnect("host=" . REMOTEDB_HOST . " port=" . REMOTEDB_PORT . " user=" . REMOTEDB_USER . " password=" . REMOTEDB_PASS . " dbname=" . REMOTEDB_NAME);
2789 } else {
2790 $database= @pg_pconnect("host=" . REMOTEDB_HOST . " port=" . REMOTEDB_PORT . " user=" . REMOTEDB_USER . " dbname=" . REMOTEDB_NAME);
2791 }
2792 if ($database == "") {
2793 echo("<head><title>Database unavailable</title></head>");
2794 echo("<body bgcolor=#ffffff><h1>The database is currently unavailable (R)</h1>");
2795 echo("Please try again later</body></html>");
2796 exit;
2797 }
2798}
2799
2800function get_user_info($id = 0) {
2801 global $user_id;
2802 $uInfo->req_status = 0;
2803 $idchk = ($id+0);
2804 if ($idchk == 0) { $idchk = $user_id; }
2805 if ($idchk>0) {
2806 $res = pg_safe_exec("SELECT * FROM users WHERE id='" . (int)$idchk . "'");
2807 $uInfo = pg_fetch_object($res);
2808 $uInfo->req_status = 1;
2809 }
2810 return $uInfo;
2811}
2812
2813function is_email_valid($email) {
2814 return(preg_match("/^[A-Za-z0-9_+-.]+@[A-Za-z0-9.-]+\.[A-Za-z][A-Za-z]+$/",$email));
2815}
2816
2817function err_newuser($errMsg) {
2818 echo "<font color=#ff1111>Error</font><br>\n";
2819 echo "<ul>\n";
2820 echo $errMsg;
2821 echo "</ul>\n";
2822}
2823
2824function remove_ip($string,$type=1) {
2825 $retv = $string;
2826 if ($type==1) {
2827 if (ereg("@",$string)) {
2828 $bb = explode("@",$string);
2829 $retv = $bb[0] . "@<IP_HIDDEN>";
2830 }
2831 } elseif ($type==2) {
2832 $xx = explode(" ",$string);
2833 if (preg_match('/^\(.*\)$/',$xx[2])) {
2834 $uname = str_replace("(","",str_replace(")","",$xx[2]));
2835 $rru = pg_safe_exec("SELECT levels.access,users.flags FROM users,levels WHERE lower(users.user_name)='" . strtolower($uname) . "' AND levels.channel_id=1 AND levels.user_id=users.id");
2836 $fl = 0; $axs = 0;
2837 if ($oru = @pg_fetch_object($rru)) {
2838 $axs = $oru->access;
2839 $fl = $oru->flags;
2840 }
2841 }
2842 if (ereg("@",$xx[1])) {
2843 if ($axs>0 || $fl&256) {
2844 $bb = explode("@",$xx[1]);
2845 $xx1 = $bb[0] . "@<IP_HIDDEN>";
2846 $xx[1] = $xx1;
2847 }
2848 $retv = "";
2849 for ($x=0;$x<count($xx);$x++) { $retv .= $xx[$x] . " "; }
2850 }
2851 }
2852 return $retv;
2853}
2854
2855function std_init() {
2856 global $user_id,$admin,$auth,$HTTP_SERVER_VARS,$r_admin;
2857
2858 std_connect();
2859
2860 $user_id = std_security_chk($auth);
2861
2862 if ($user_id == 0) {
2863 $url=$HTTP_SERVER_VARS["PHP_SELF"];
2864 header("Location: " . LIVE_LOCATION . "/login.php?redir=" . urlencode($url));
2865 exit;
2866 }
2867
2868 $admin = std_admin();
2869}
2870
2871function std_pwd_chk($password,$crypt) {
2872 if ($crypt=="")
2873 return 1; // Succes
2874 $salt=substr($crypt,0,8);
2875 $crypt=substr($crypt,8);
2876 if (md5($salt . $password) == $crypt)
2877 return 1; // Success!
2878 return 0; // Failed
2879}
2880
2881function chk_password($username,$password,$failret = 0) {
2882 global $database,$cookie_cnx;
2883 $chk = pg_safe_exec("SELECT password,id FROM users WHERE lower(user_name)='" . strtolower($username) . "'");
2884 if (pg_numrows($chk)==0) {
2885 return $failret; // Failed
2886 }
2887 $chkO = pg_fetch_object($chk,0);
2888 $crypt=$chkO->password;
2889// if ($crypt=="") { // empty password field = login without password
2890// return $chkO->id; // Success!
2891// }
2892 $salt=substr($crypt,0,8);
2893 $crypt=substr($crypt,8);
2894 if (md5($salt . $password) == $crypt) {
2895 return $chkO->id; // Success!
2896 }
2897 return $failret; // Failed
2898}
2899
2900if (file_exists("../../php_includes/config.inc")) {
2901 include("../../php_includes/config.inc");
2902} else {
2903 if (file_exists("../../../php_includes/config.inc")) {
2904 include("../../../php_includes/config.inc");
2905 } else {
2906 if (file_exists("../../../../php_includes/config.inc")) {
2907 include("../../../../php_includes/config.inc");
2908 } else {
2909 echo "Missing required <b>config.inc</b> !!";
2910 die;
2911 }
2912 }
2913}
2914
2915$x_at_email = XAT_EMAIL;
2916$purge_at_email = PURGE_EMAIL;
2917$ipchk_dbuser = LOCALDB_USER;
2918define(CLEAR_COOKIES_QUERY,"DELETE FROM webcookies WHERE expire<now()::abstime::int4");
2919$mail_from_new=FROM_NEWUSER;
2920$mail_subject_new=FROM_NEWUSER_SUBJECT;
2921$mail_from_pass=FROM_FPASS;
2922$mail_subject_pass=FROM_FPASS_SUBJECT;
2923$min_time_between_requests=LREQ_TIME; // in seconds (set to 1 for testing purposes, preferably set to 600 (10 minutes)).
2924
2925
2926// do not change the above values here... edit 'config.inc' instead.
2927
2928if (!extension_loaded("gd")) { // checking if LibGD is present in apache/php
2929 define(SHOW_GFXUSRCHK,0);
2930} else {
2931 define(SHOW_GFXUSRCHK,1);
2932}
2933
2934define(HOSTING_STATS_FILENAME,"/tmp/hosting_stats");
2935if (HOSTING_STATS) {
2936 $ftest = @fopen(HOSTING_STATS_FILENAME,"r");
2937 if (!$ftest) {
2938 // file not found, crete it (or try)
2939 $ftest3 = @fopen(HOSTING_STATS_FILENAME,"w");
2940 if (!$ftest3) {
2941 //die("i can't create the file '" . HOSTING_STATS_FILENAME . "', duh !");
2942 define(HOSTING_CLICK_CHECK,0);
2943 } else {
2944 define(HOSTING_CLICK_CHECK,1);
2945 @fclose($ftest3);
2946 }
2947 } else {
2948 @fclose($ftest);
2949 $ftest2 = @fopen(HOSTING_STATS_FILENAME,"a");
2950 if (!$ftest2) {
2951 //die("file '" . HOSTING_STATS_FILENAME . "' exists and is not writable by me !");
2952 define(HOSTING_CLICK_CHECK,0);
2953 } else {
2954 define(HOSTING_CLICK_CHECK,1);
2955 @fclose($ftest2);
2956 }
2957 }
2958} else {
2959 define(HOSTING_CLICK_CHECK,0);
2960}
2961
2962if (!extension_loaded("pgsql")) { // original idea by Leigh.
2963 echo "<b>Your apache server has no <b>PgSQL support</b> built-in.<br><br>Please re-install apache properly to use this web interface.</b>";
2964 die;
2965}
2966
2967if (phpversion()<4) {
2968 echo "<b>Your apache server has </b>PHP " . phpversion() . "<b> support (you need at least version 4+ (<a href=\"http://www.php.net/\" target=\"_blank\">http://www.php.net/</a>))<br><br>Please re-install the latest version of PHP.</b>";
2969 die;
2970}
2971
2972$reg_globs = ini_get("register_globals");
2973if ( (($reg_globs+0) == 1) || (strtolower($reg_globs) == "on") ) {
2974 $bypass42 = 1;
2975} else {
2976 $bypass42 = 0;
2977}
2978
2979if ("". phpversion() . "">="4.2.0" && !$bypass42) {
2980 echo "<font size=+1><br><br>";
2981 echo "Your apache server has <b>PHP ". phpversion() . "</b><br>";
2982 echo "Lots of changes in 4.2 oblige us to update a lot of things.<br><br>\n";
2983 echo "Fortunately, you can solve this problem by activating a now by default desactivated feature<br>\n";
2984 echo "Go edit your <b>php.ini</b> file and find the line defining <b>register_globals</b>, set its value<br>";
2985 echo "to <b>On</b> and then restart your apache (<b>/usr/local/apache/bin/apachectl restart</b>)<br><br>";
2986 echo ".. then reload this page <b>:)</b>\n";
2987 echo "</font><br>\n";
2988 die;
2989}
2990
2991if (DEFAULT_REQUIRED_SUPPORTERS>10 || DEFAULT_REQUIRED_SUPPORTERS<0 || (DEFAULT_REQUIRED_SUPPORTERS+0)!=DEFAULT_REQUIRED_SUPPORTERS ) {
2992 echo "<b>Incorrect default config.inc's value for </b>DEFAULT_REQUIRED_SUPPORTERS<b>, requires a value between 0 and 10.</b>";
2993 die;
2994}
2995
2996unset($ENABLE_COOKIE_TABLE);
2997$ENABLE_COOKIE_TABLE = 0;
2998unset($dns_cache);
2999
3000std_connect();
3001$res = pg_safe_exec("SELECT contents FROM variables WHERE var_name='REQUIRED_SUPPORTERS'");
3002if (pg_numrows($res)==0) {
3003 pg_safe_exec("INSERT INTO variables VALUES ('REQUIRED_SUPPORTERS','" . DEFAULT_REQUIRED_SUPPORTERS . "',now()::abstime::int4)");
3004 $reqsup = DEFAULT_REQUIRED_SUPPORTERS;
3005} else {
3006 $row = pg_fetch_object($res,0);
3007 $reqsup = ($row->contents+0);
3008}
3009define(REQUIRED_SUPPORTERS,$reqsup);
3010unset($res);
3011unset($reqsup);
3012
3013if (cl_ip()=="0.0.0.0") { die("For some reason we cannot determine your IP, you cannot access this service."); }
3014
3015if (isset($cTheme)) { unset($cTheme); }
3016if (isset($uuflags)) { unset($uuflags); }
3017if (isset($r_admin)) { unset($r_admin); }
3018
3019?>