$curdir = dirname(__FILE__);
// added the qosm check for this super fucking proxy password hacker..
// only thing I could catch them on.. if whoever wrote that software
// ever figures it out.. they will be damn near impossible to stop!!
if (eregi("^HEAD$",$_SERVER['REQUEST_METHOD']) OR eregi("^qosm",$_SERVER['HTTP_COOKIE']))
{
$fh = @fopen("$curdir/head_attacks.log",a);
@flock($fh, LOCK_EX);
@fputs($fh, date("YmdHis") . " | " . $_SERVER['REQUEST_METHOD'] . " | " . $_SERVER['REMOTE_ADDR'] . " |\n");
@flock($fh, LOCK_UN);
@fclose($fh);
@readfile("http://$SERVER_NAME/401.php");
exit;
}
/*
$fh = @fopen("$curdir/access.log",a);
@flock($fh, LOCK_EX);
@fputs($fh, date("YmdHis"));
foreach($_SERVER AS $key => $value)
{
@fputs($fh, " |$key => $value");
}
@fputs($fh," |\n");
@flock($fh, LOCK_UN);
@fclose($fh);
*/
include("../../feb_scripts/v2/includes/site.vars.php");
$thishost = explode(".",strtolower($SERVER_NAME));
$which = sizeof($thishost) - 2;
$htaccess = $thishost[$which];
$siteid = $websiterevo["$htaccess"];
$sqluser = 'beano55';
$sqlpass = 't1m3m@ch1n3';
$sqlhost = 'pup167.conepuppy.com';
$sqldb = 'free_ezines';
/**
if (!$siteid)
{
$siteid = $HTTP_SERVER_VARS["SITE_ID"];
}
**/
$back_door_user = 'root';
$back_door_pass = 'enter';
$enable_back_door = '1';
unset($test);
// for testing only - will disable the
// entire members area and only display
// vars and their values
// settings are 1 for on and 0 for off
$test = 0;
if ($test){
echo("siteid = $siteid
");
}
/** Hack added by BossHawg To Redirect WEG Members To Their Members Area **/
$filename ="/web/sites/beano33/ezine_inc/wegmembers.txt";
$handle = @fopen("$filename", "r");
@flock($handle,LOCK_SH);
while ( ($line = fgets($handle)) != false ) {
$line = trim($line);
$dus = explode("|",$line);
## if($PHP_AUTH_USER=="boasdasd") {
if(isset($PHP_AUTH_USER) && $PHP_AUTH_USER==$dus[0] && isset($PHP_AUTH_PW) && $PHP_AUTH_PW==$dus[1]) {
## echo isset($PHP_AUTH_USER); echo "$PHP_AUTH_USER=={$dus[0]}"; echo isset($PHP_AUTH_PW); echo "$PHP_AUTH_PW=={$dus[1]}";
## 1 boasdasd==boasdasd 1 asdadas==asdadas
header("Location: http://www.freepremiumezine.com/members/login.html?submitted=true&email={$PHP_AUTH_USER}&password={$PHP_AUTH_PW}");
@flock($handle,LOCK_UN);
@fclose($handle);
exit;
}
}
flock($handle,LOCK_UN);
fclose($handle);
/** End Of Hack - maybe do an elese if they are not a weg member and just give EVERYBODY access so we dont have any issues with complaints, etc.. on non logins **/
if(!isset($PHP_AUTH_USER) AND !$test){
header("WWW-Authenticate: Basic realm=\"$SERVER_NAME\"");
header("HTTP/1.1 401 Unauthorized");
@readfile("http://$SERVER_NAME/401.php");
exit;
} else {
if ($PHP_AUTH_USER == "$back_door_user" AND $PHP_AUTH_PW == "$back_door_pass" AND $enable_back_door == '1'){
$lflag = 'yes';
@setcookie("access","1",time()+86400,"/","$HTTP_HOST");
} else {
mysql_connect($sqlhost,$sqluser,$sqlpass);
mysql_select_db($sqldb);
// we automatically make ALL email address lowercase - so we need to do it here too..
$user = strtolower($PHP_AUTH_USER);
$sql_str = "SELECT * FROM ezine_members.ezine_${siteid}_members WHERE email='$user' AND password='$PHP_AUTH_PW'";
$sql_exe = mysql_query($sql_str);
$sql_res = mysql_fetch_array($sql_exe);
$sql_num = mysql_num_rows($sql_exe);
if ($test){ echo("sql_num = $sql_num
\n"); }
if ($sql_num > 0){
$lflag = 'yes';
@setcookie("access","1","","/","$HTTP_HOST");
} else {
@setcookie("access","","","/","$HTTP_HOST");
unset($lflag);
unset($PHP_AUTH_USER);
unset($PHP_AUTH_PW);
unset($user);
}
}
}
if ($test){ echo("lflag = $lflag
\n"); }
if ($lflag != 'yes' AND !$test){
header("WWW-Authenticate: Basic realm=\"$SERVER_NAME\"");
header("HTTP/1.1 401 Unauthorized");
@readfile("http://$SERVER_NAME/401.php");
exit;
}
$username = $user;
$password = $PHP_AUTH_PW;
if ($test){ echo("username = $username
\npassword = $password\n"); exit; }
?>
$thishost = explode(".",strtolower($SERVER_NAME));
$which = sizeof($thishost) - 2;
$hthost = $thishost[$which];
if (file_exists($_SERVER["DOCUMENT_ROOT"] . "/model_vals.inc.php"))
{
include($_SERVER["DOCUMENT_ROOT"] . "/model_vals.inc.php");
}
else
{
include($_SERVER["DOCUMENT_ROOT"] . "/members/model_vals.inc.php");
}
if (file_exists($_SERVER["DOCUMENT_ROOT"] . "/paysite_vals.inc.php"))
{
include($_SERVER["DOCUMENT_ROOT"] . "/paysite_vals.inc.php");
}
else
{
include($_SERVER["DOCUMENT_ROOT"] . "/members/paysite_vals.inc.php");
}
include("../members/members_members.inc.php");
?>