• There is NO official Otland's Discord server and NO official Otland's server list. The Otland's Staff does not manage any Discord server or server list. Moderators or administrator of any Discord server or server lists have NO connection to the Otland's Staff. Do not get scammed!
  • 2026 staff recruitment is open! Check it out and consider applying!

[USA] mtibiaonline.net 8.6

You sir, fail in php.
From your website:
<html xmlns="http://www.w3.org/1999/xhtml">
<?php
function anti_injection($sql)
{
// remove palavras que contenham sintaxe sql
$sql = preg_replace(sql_regcase("/(from|select|insert|delete|where|drop table|show tables|#|\*|--|\\\\)/"),"",$sql);
$sql = trim($sql);//limpa espaços vazio
$sql = strip_tags($sql);//tira tags html e php
$sql = addslashes($sql);//Adiciona barras invertidas a uma string
return $sql;
}

//modo de usar pegando dados vindos do formulario
$nome = anti_injection($_POST["nome"]);
$senha = anti_injection($_POST["senha"]);

//changing html characters using htmlspecialchars() Learn more here: PHP: htmlspecialchars - Manual
//$_POST['link'] = <a href="test">test</a>

$link = htmlspecialchars($_POST['link'], ENT_QUOTES);
echo $link; //outputs: &lt;a href='test'&gt;Test&lt;/a&gt;

header("Content-Type: text/html; charset=ISO-8859-1",true)
?>
 
please dude, do things that u know what they do and how they works, dont do things that u dont know anything =/ that just sux
 
Evil Puncker said:
how much did kito paid to u guys?
+1 XD! haha

Lol kito you're so obvious, I bet you are giving premium points to your players to come and post here a fake message "OMG IS THE BEST SERVER EVER".. What a paid/fake message. haha.
 
please dude, do things that u know what they do and how they works, dont do things that u dont know anything =/ that just sux

So, how to test them if I don't know how to exploit an injection?
Some people like me are not pros on php and don't have time to study this and make a lot of test, I search things and implement them if the other users said that it worked.

+1 XD! haha

Lol kito you're so obvious, I bet you are giving premium points to your players to come and post here a fake message "OMG IS THE BEST SERVER EVER".. What a paid/fake message. haha.

Where it says it is illegal?

Do you even know how to add php codes into your website?

Oh yeah, just check the website, it didn't form by itself :)
 
Last edited by a moderator:
Want to know the best part Kekox?

23:28 New record: 25 players are logged in.
23:31 New record: 26 players are logged in.
23:33 New record: 27 players are logged in.
23:35 New record: 28 players are logged in.

It worked!
Three days online and Im proud of this progress.

Neither by yourself. LOL


Is not, is just noobish.

Hahaha you don't think so?
I can find the script and implement them.
I can pay for script and implement them.

And what? It works fine :)

About "noobish", call it as what you want, but it works :)
 
Last edited by a moderator:
Of course it works when all you want is money but learn.. Thats stupid.. Learn doing thing by yourself, then you wont have to pay anyone, trust me, that works better than paying ;)

Btw, 28 players in 3 days? LOOL! You call that progress?
 
+1 XD! haha

Lol kito you're so obvious, I bet you are giving premium points to your players to come and post here a fake message "OMG IS THE BEST SERVER EVER".. What a paid/fake message. haha.

i love u for that kekox
 
Of course it works when all you want is money but learn.. Thats stupid.. Learn doing thing by yourself, then you wont have to pay anyone, trust me, that works better than paying ;)

Btw, 28 players in 3 days? LOOL! You call that progress?

I call it a progress, coming to outer world without knowing people from here, just Chilean people and for me it is a progress.

If for you it isn't a progress, damn, your a pro, nice, good luck with your life :)
 
Its easy to get players on America, there is like 5 active countrys, while chile is only 1..
 
Oh yeah Kekox, but Im not looking for "temporal players", Im looking for leaders with teams to have wars, no custom players that comes to test it, play 2-3 days an leave.
 
somebody is spamming, everybody with just one comment and the comments withs 1 - 2 mins of difference

@edit: didn't see that kekox said that before xp
 
quite hilarious the first 4 pages there is no1 with more then 1 (except for 1 which have 3) posts
 
kito said:
Oh yeah Kekox, but Im not looking for "temporal players", Im looking for leaders with teams to have wars, no custom players that comes to test it, play 2-3 days an leave.
How does that makes sence in what we were talking about?
 
Back
Top