403Webshell
Server IP : 109.234.162.214  /  Your IP : 216.73.216.222
Web Server : Apache
System : Linux servd162214.srv.odns.fr 4.18.0-372.26.1.lve.1.el8.x86_64 #1 SMP Fri Sep 16 14:08:19 EDT 2022 x86_64
User : carpe ( 1178)
PHP Version : 8.0.30
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /home/carpe/public_html/starship/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /home/carpe/public_html/starship/combat.php
<?php

session_start();
        
include 'objet.php';
include 'database.php';
        
$database = new Database();
$connexion = $database->getConnection();
        
if(isset($_SESSION['login'])){
            
}else{
    header("Location: login.php");
    setcookie("resultat", "", time() - 3600, "/");
}


if(isset($_POST['deco'])){
    session_destroy();
    header("Location: login.php");
    setcookie("resultat", "", time() - 3600, "/");
}

if(isset($_POST['retour'])){
    
    if(isset($_POST['resultat'])){
        $id=getId($connexion);
         $sql="UPDATE `users` SET `arriveeFondation`='10',`membresFondation`='0' WHERE id_user ='$id'";
        $statement = $connexion->prepare($sql);
        $statement->execute();
        header("Location: univers.php");
        setcookie("resultat", "", time() - 3600, "/");
        
        $sql2="DELETE from team WHERE id_user ='$id' and classe='Mentaliste'";
        $statement2 = $connexion->prepare($sql2);
        $statement2->execute();
        
    }else{
        header("Location: login.php");
        setcookie("resultat", "", time() - 3600, "/");
        session_destroy();
        $id=getId($connexion);
        $delete1 = "delete from users where id_user = '$id'";
        $statement1 = $connexion->prepare($delete1);
        $statement1->execute();
        $delete2 = "delete from team where id_user = '$id'";
        $statement2 = $connexion->prepare($delete2);
        $statement2->execute();
        $delete3 = "delete from persos where id_user = '$id'";
        $statement3 = $connexion->prepare($delete3);
        $statement3->execute();
        $delete4 = "delete from vaisseaux where id_user = '$id'";
        $statement4 = $connexion->prepare($delete4);
        $statement4->execute();
        $delete5 = "delete from combat where id_user = '$id'";
        $statement5 = $connexion->prepare($delete5);
        $statement5->execute();
    }
    
    
    
    
   
    
    
}



?>
<!DOCTYPE html>
<html>
<head>
    <title>Starship</title>
    <meta charset="utf-8">
</head>
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Nabla&family=Quicksand:wght@300..700&family=VT323&display=swap" rel="stylesheet">
<style>

    body{
        background:black;
        width:100%;
        height:100vh;
        display:flex;
        justify-content:center;
        align-items:center;
        padding:0;
        margin:0;
        color:white;
    }
    
    .result{
        position:absolute;
        bottom:100px;
        color:#d0c2c2;
        font-family: "VT323", monospace;
        font-size:2rem;
        text-align:center;
        width:100%;
    }
    
    .result2{
        position:absolute;
        bottom:30px;
    }
    
    #contain{
        width:800px;
        height:500px;
        background:#F2F2F2;
        background:black;
        border: 5px solid #d0c2c2;
        position:relative;
        flex-wrap:wrap;
  
        
    }
    
    #contain h1{
        color:#d0c2c2;
        font-family: "VT323", monospace;
        font-size:3rem;
        text-align:center;
    }
    
    #contain div{
        display:flex;
        gap:20px;
        justify-content:center;
    }
    #contain div h3{
        color:#d0c2c2;
        font-family: "VT323", monospace;
        font-size:2rem;
    }
    #contain form{
        width:100%;
        display:flex;
        justify-content:center;
        align-items:center;
    }
    #contain input{
        margin:auto;
        background:#d0c2c2;
        color:black;
        font-family: "VT323", monospace;
        font-size:2rem;
        border: 5px solid #d0c2c2;
        transition:.5s all;
        cursor:pointer;
    }
    
    #contain input:hover{
        transition:.5s all;
        color:#d0c2c2;
        background:black;
    }
    
    #deco input{
        position:absolute;
        color:black;
        background:#d0c2c2;
        font-family: "VT323", monospace;
        font-size:1.5rem;
        top:0;
        left:0;
        z-index:999;
        outline:none;
        cursor:pointer;
        border:none;
        transition: .5s all;
        border : 5px solid #d0c2c2;
    }
    
    #deco input:hover{
        color:#d0c2c2;
        background:black;
        transition: .5s all;
        
    }
    
    .note{
        position:absolute;
        right:0;
        width:300px;
        border : 5px solid #d0c2c2;
    }
    .note h1{
        margin:20px;
        color:#d0c2c2;
        font-family: "VT323", monospace;
        font-size:3rem;
    }
    
    .note p{
        margin:20px;
        color:#d0c2c2;
        font-family: "VT323", monospace;
        font-size:2rem;
    }
    
</style>
<body>
    <form id='deco' method='POST' action='univers.php'>
        <input type='submit' name='deco' value='Deconnexion'>
    </form>
    <div class='note'>
        <h1>Explications</h1>
        <p>Les mentalistes présent dans votre équipe ont rejoint les rangs de la fondation, vous avez perdu des membres</p>
    </div>
    <div id='contain'>
        <?php
        
        if(isset($_POST['combat2'])){
            $val = $_POST['val'];
            $membres = $_POST['membres'];
            if($val >= $membres){
                //membres win
                
                //ne pas oublier de changer la valeur de l'arrivée de la fondation dans la bdd
                echo "<div class='result'>Vous avez gagné ! Bien joué !</div>";
                echo "<form class='result2' method='POST' action='combat.php'>
                <input type='submit' name='retour' value='Continuer'>
                <input type='hidden' value='gagner' name='resultat'></form>";
            }else{
                //looose;
                echo "<div class='result'>Vous avez perdu, dommage...</div>";
                echo "<form class='result2' method='POST' action='combat.php'>
                <input type='submit' name='retour' value='Continuer'></form>";
            }
        }
        
        ?>
        <h1>La fondation a trouvé votre planque et engage le combat !</h1>
        <div><h3><?php 
        
        
        
        function getId($connexion){
            $username = $_SESSION['login'];
            $sql = "SELECT id_user from users where username = '$username'";
            $statement = $connexion->prepare($sql);
            $statement->execute();
            $results = $statement->fetchAll(PDO::FETCH_ASSOC);
            foreach ($results as $row) {
                $id = $row['id_user'];
                return $id;
            }
        }
        $id=getId($connexion);
        
        $sql = "select * from users where id_user = '$id'";
        $statement = $connexion->prepare($sql);
        $statement->execute();
        $results = $statement->fetchAll(PDO::FETCH_ASSOC);
        foreach($results as $value){
            $membres = $value['membresFondation'];
        }
        
        $sql = "select * from team where id_user = '$id' and statu = 'vivant' and classe='Mentaliste'";
        $statement = $connexion->prepare($sql);
        $statement->execute();
        $results = $statement->fetchAll(PDO::FETCH_ASSOC);
        $taille = count($results);
        $membresTot = $membres + $taille;
        echo $membresTot;
        
        
        ?> membres de la fondation</h3><h3>VS</h3><h3><?php 
        
        $sql = "select * from team where id_user = '$id' and statu = 'vivant' and classe='Operateur'";
        $statement = $connexion->prepare($sql);
        $statement->execute();
        $results = $statement->fetchAll(PDO::FETCH_ASSOC);
        $val = 0;
        foreach($results as $value){
            $val++;
        }
        
        echo $val;
        
        ?> de vos membres</h3></div>
        <form method='POST' action='combat.php'>
            <?php
            
            echo "<input type='hidden' value='$val' name='val'>
            <input type='hidden' value='$membresTot' name='membres'>
            ";
            
            ?>
            <input type='submit' name='combat2' value='Combattre'>
        </form>
    </div>
    
</body>
</html>

Youez - 2016 - github.com/yon3zu
LinuXploit