Does this Code have "Backdoor" access in?

Feb 3, 2013
56
3
PHP:
<?php
error_reporting(0);
$getRanks = mysql_query("SELECT id,name FROM ranks WHERE id =12 ORDER BY id DESC");
$Bans = mysql_query("SELECT * FROM `bans` WHERE `username` = '" . $Users['username'] . "'");
$BanCount = mysql_num_rows($Bans);
echo $BanCount;
while ($Ranks = mysql_fetch_assoc($getRanks))
{
    echo '<div class="habblet-container ">    
<div class="cbb clearfix red ">
<h2 class="title"><span style="float: left;">Founder</span> <span style="float: right; font-weight: normal; font-size: 75%;"></span></h2>';

    $getMembers = mysql_query("SELECT id,username,motto,look,account_created,online,last_online,role,age,country FROM users WHERE rank = '" . $Ranks['id'] . "'");
    echo '<div class="box-content">';
    if (mysql_num_rows($getMembers) > 0)
    {
        $oe = 1;
        while ($member = mysql_fetch_assoc($getMembers))
        {
            if ($oe == 2)
            {
                $oe = 1;
            }
            else
            {
                $oe = 2;
            }
$Bans = mysql_query("SELECT * FROM `bans` WHERE `added_by` = '" . $member['username'] . "'");
$BanCount = mysql_num_rows($Bans);
            echo '<table width="107%" height="50px" style="padding: 5px; margin-left: -15px; background-color: ' . (($oe == 2) ? '#fff' : '#E6E6E6') . ';">
            <tbody>
                <tr>
                    <td valign="middle" width="25">
                        <img style="margin-top: -10px;" src="http://www.habbo.nl/habbo-imaging/avatarimage?figure=' .$member['look'] . '&size=m&direction=2&head_direction=3&gesture=sml">
                    </td>
                    <td valign="top">
                        </br><p style="margin-top: -10px;" style="font-size: 100%;"><strong><a><u>' .$member['username'] . '</a></u></strong><br>Last online: <i>' . date('d M, Y', $member['last_online']) . '</i><br>Motto: "<i>' . $member['motto'] . '</i>"<br>' . (($member['online'] == "1") ? '<font color="darkgreen"><p style="margin-left: 165px; margin-top: -37px;"><strong>Online</stromg>': '<font color="darkred"><strong><p style="margin-left: 165px; margin-top: -37px;">Offline</stromg>') . '</p></font></font></strong>
                        <hr>
                        Role: <b>' . $member['role'] . '</b><br>
                        Age: ' . $member['age'] . '</br>
                        Registered on: <b>' . date('d M, Y', $member['account_created']) . '</b></br>
                        Bans: <b>'; echo $BanCount;
                   
                   
                   
                   
                   
                   
               
                   
                    echo '<br><img src="http://URLhotel.cf/r63/Flags/' .$member['country'] . '.png">
                    </td>
               
                    </td>
                </tr>
            </tbody>
            </table>';
        }
    }
    else
    {
        echo '<i>No information available.</i>';
    }
    echo '</div>
    </div>
</div>
<script type="text/javascript">if (!$(document.body).hasClassName(\'process-template\')) { Rounder.init(); }</script> ';
}
?>
<?php
error_reporting(0);
$getRanks = mysql_query("SELECT id,name FROM ranks WHERE id =11 ORDER BY id DESC");
$Bans = mysql_query("SELECT * FROM `bans` WHERE `username` = '" . $Users['username'] . "'");
$BanCount = mysql_num_rows($Bans);
echo $BanCount;
while ($Ranks = mysql_fetch_assoc($getRanks))
{
    echo '<div class="habblet-container ">    
<div class="cbb clearfix red ">
<h2 class="title"><span style="float: left;">Technician</span> <span style="float: right; font-weight: normal; font-size: 75%;"></span></h2>';

    $getMembers = mysql_query("SELECT id,username,motto,look,account_created,online,last_online,role,age,country FROM users WHERE rank = '" . $Ranks['id'] . "'");
    echo '<div class="box-content">';
    if (mysql_num_rows($getMembers) > 0)
    {
        $oe = 1;
        while ($member = mysql_fetch_assoc($getMembers))
        {
            if ($oe == 2)
            {
                $oe = 1;
            }
            else
            {
                $oe = 2;
            }
$Bans = mysql_query("SELECT * FROM `bans` WHERE `added_by` = '" . $member['username'] . "'");
$BanCount = mysql_num_rows($Bans);
            echo '<table width="107%" height="50px" style="padding: 5px; margin-left: -15px; background-color: ' . (($oe == 2) ? '#fff' : '#E6E6E6') . ';">
            <tbody>
                <tr>
                    <td valign="middle" width="25">
                        <img style="margin-top: -10px;" src="http://www.habbo.nl/habbo-imaging/avatarimage?figure=' .$member['look'] . '&size=m&direction=2&head_direction=3&gesture=sml">
                    </td>
                    <td valign="top">
                        </br><p style="margin-top: -10px;" style="font-size: 100%;"><strong><a><u>' .$member['username'] . '</a></u></strong><br>Last online: <i>' . date('d M, Y', $member['last_online']) . '</i><br>Motto: "<i>' . $member['motto'] . '</i>"<br>' . (($member['online'] == "1") ? '<font color="darkgreen"><p style="margin-left: 165px; margin-top: -37px;"><strong>Online</stromg>': '<font color="darkred"><strong><p style="margin-left: 165px; margin-top: -37px;">Offline</stromg>') . '</p></font></font></strong>
                        <hr>
                        Role: <b>' . $member['role'] . '</b><br>
                        Age: ' . $member['age'] . '</br>
                        Registered on: <b>' . date('d M, Y', $member['account_created']) . '</b></br>
                        Bans: <b>'; echo $BanCount;
                   
                   
                   
                   
                   
                   
               
                   
                    echo '<br><img src="http://URLhotel.cf/r63/Flags/' .$member['country'] . '.png">
                    </td>
               
                    </td>
                </tr>
            </tbody>
            </table>';
        }
    }
    else
    {
        echo '<i>No information available.</i>';
    }
    echo '</div>
    </div>
</div>
<script type="text/javascript">if (!$(document.body).hasClassName(\'process-template\')) { Rounder.init(); }</script> ';
}
?>

             
</div>
        <script type="text/javascript">if (!$(document.body).hasClassName('process-template')) { Rounder.init(); }</script>
   
        <div id="column2" class="column"><div class="habblet-container ">
<?php
$getRanks = mysql_query("SELECT id,name FROM ranks WHERE id = 10 ORDER BY id DESC");
while ($Ranks = mysql_fetch_assoc($getRanks))
{
    echo '<div class="habblet-container ">    
<div class="cbb clearfix settings ">
<h2 class="title"><span style="float: left;">Manager</span> <span style="float: right; font-weight: normal; font-size: 75%;"></span></h2>';
    $getMembers = mysql_query("SELECT id,username,motto,look,account_created,online,last_online,role,age,country FROM users WHERE rank = '" . $Ranks['id'] . "'");
    echo '<div class="box-content">';
    if (mysql_num_rows($getMembers) > 0)
    {
        $oe = 1;
   
        while ($member = mysql_fetch_assoc($getMembers))
        {
            if ($oe == 2)
            {
                $oe = 1;
            }
            else
            {
                $oe = 2;
            }
    $Bans = mysql_query("SELECT * FROM `bans` WHERE `added_by` = '" . $member['username'] . "'");
$BanCount = mysql_num_rows($Bans);
            echo '<table width="107%" height="50px" style="padding: 5px; margin-left: -15px; background-color: ' . (($oe == 2) ? '#fff' : '#E6E6E6') . ';">
            <tbody>
                <tr>
                    <td valign="middle" width="25">
                        <img style="margin-top: -10px;" src="http://www.habbo.nl/habbo-imaging/avatarimage?figure=' .$member['look'] . '&size=m&direction=2&head_direction=3&gesture=sml">
                    </td>
                    <td valign="top">
                        </br><p style="margin-top: -10px;" style="font-size: 100%;"><strong><a><u>' .$member['username'] . '</a></u></strong><br>Last online: <i>' . date('d M, Y', $member['last_online']) . '</i><br>Motto: "<i>' . $member['motto'] . '</i>"<br>' . (($member['online'] == "1") ? '<font color="darkgreen"><p style="margin-left: 165px; margin-top: -37px;"><strong>Online</stromg>': '<font color="darkred"><strong><p style="margin-left: 165px; margin-top: -37px;">Offline</stromg>') . '</p></font></font></strong>
                        <hr>
                        Role: <b>' . $member['role'] . '</b><br>
                        Age: ' . $member['age'] . '</br>
                        Registered on: <b>' . date('d M, Y', $member['account_created']) . '</b></br>
                        Bans: <b>'; echo $BanCount;
                   
                   
                   
                   
                   
               
                   
                     echo '<br><img src="http://URLhotel.cf/r63/Flags/' .$member['country'] . '.png">
                    </td>
               
                    </td>
                </tr>
            </tbody>
            </table>';
        }
    }
    else
    {
        echo '<i>No information available.</i>';
    }
    echo '</div>
    </div>
</div>
<script type="text/javascript">if (!$(document.body).hasClassName(\'process-template\')) { Rounder.init(); }</script> ';
}
?>
<div id="column2" class="column"><div class="habblet-container ">
<?php
$getRanks = mysql_query("SELECT id,name FROM ranks WHERE id = 9 ORDER BY id DESC");
while ($Ranks = mysql_fetch_assoc($getRanks))
{
    echo '<div class="habblet-container ">    
<div class="cbb clearfix green ">
<h2 class="title"><span style="float: left;">Administrator</span> <span style="float: right; font-weight: normal; font-size: 75%;"></span></h2>';
    $getMembers = mysql_query("SELECT id,username,motto,look,account_created,online,last_online,role,age,country FROM users WHERE rank = '" . $Ranks['id'] . "'");
    echo '<div class="box-content">';
    if (mysql_num_rows($getMembers) > 0)
    {
        $oe = 1;
   
        while ($member = mysql_fetch_assoc($getMembers))
        {
            if ($oe == 2)
            {
                $oe = 1;
            }
            else
            {
                $oe = 2;
            }
    $Bans = mysql_query("SELECT * FROM `bans` WHERE `added_by` = '" . $member['username'] . "'");
$BanCount = mysql_num_rows($Bans);
            echo '<table width="107%" height="50px" style="padding: 5px; margin-left: -15px; background-color: ' . (($oe == 2) ? '#fff' : '#E6E6E6') . ';">
            <tbody>
                <tr>
                    <td valign="middle" width="25">
                        <img style="margin-top: -10px;" src="http://www.habbo.nl/habbo-imaging/avatarimage?figure=' .$member['look'] . '&size=m&direction=2&head_direction=3&gesture=sml">
                    </td>
                    <td valign="top">
                        </br><p style="margin-top: -10px;" style="font-size: 100%;"><strong><a><u>' .$member['username'] . '</a></u></strong><br>Motto: ' . $member['motto'] . '' . (($member['online'] == "1") ? '<font color="darkgreen"><p style="margin-left: 165px; margin-top: -37px;"><strong>Online</stromg>': '<font color="darkred"><strong><p style="margin-left: 165px; margin-top: -37px;">Offline</stromg>') . '</p></p><p style="margin-top: -8px;"><img src="http://URLhotel.cf/r63/c_images/album1584/ADM.gif"></p>
                        ';
                   
               
                   
                    echo '<br><img src="http://URLhotel.cf/r63/Flags/' .$member['country'] . '.png">
                    </td>
               
                    </td>
                </tr>
            </tbody>
            </table>';
        }
    }
    else
    {
        echo '<i>No information available.</i>';
    }
    echo '</div>
    </div>
</div>
<script type="text/javascript">if (!$(document.body).hasClassName(\'process-template\')) { Rounder.init(); }</script> ';
}
?>
</div></div></div></div>
<script type="text/javascript">if (!$(document.body).hasClassName('process-template')) { Rounder.init(); }</script>
        <div id="column2" class="column"><div class="habblet-container ">
<?php
$getRanks = mysql_query("SELECT id,name FROM ranks WHERE id = 7 ORDER BY id DESC");
while ($Ranks = mysql_fetch_assoc($getRanks))
{
    echo '<div class="habblet-container ">    
<div class="cbb clearfix blue ">
<h2 class="title"><span style="float: left;">Moderators</span> <span style="float: right; font-weight: normal; font-size: 75%;"></span></h2>';
    $getMembers = mysql_query("SELECT id,username,motto,look,account_created,online,last_online,role,age,country FROM users WHERE rank = '" . $Ranks['id'] . "'");
    echo '<div class="box-content">';
    if (mysql_num_rows($getMembers) > 0)
    {
        $oe = 1;
   
        while ($member = mysql_fetch_assoc($getMembers))
        {
            if ($oe == 2)
            {
                $oe = 1;
            }
            else
            {
                $oe = 2;
            }
            echo '<table width="107%" height="50px" style="padding: 5px; margin-left: -15px; background-color: ' . (($oe == 2) ? '#fff' : '#E6E6E6') . ';">
            <tbody>
                <tr>
                    <td valign="middle" width="25">
                        <img style="margin-top: -10px;" src="http://www.habbo.nl/habbo-imaging/avatarimage?figure=' .$member['look'] . '&size=m&direction=2&head_direction=3&gesture=sml">
                    </td>
                    <td valign="top">
                        </br><p style="margin-top: -10px;" style="font-size: 100%;"><strong><a><u>' .$member['username'] . '</a></u></strong><br>Last online: <i>' . date('d M, Y', $member['last_online']) . '</i><br>Motto: "<i>' . $member['motto'] . '</i>"<br>' . (($member['online'] == "1") ? '<font color="darkgreen"><p style="margin-left: 165px; margin-top: -37px;"><strong>Online</stromg>': '<font color="darkred"><strong><p style="margin-left: 165px; margin-top: -37px;">Offline</stromg>') . '</p></font></font></strong>
                        <hr>
                        Role: <b>' . $member['role'] . '</b><br>
                        Age: ' . $member['age'] . '</br>
                        Registered on: <b>' . date('d M, Y', $member['account_created']) . '</b></br>
                        Bans: <b>'; echo $BanCount;
                   
                   
                   
                   
                   
               
                   
                    echo '<br><img src="http://URLhotel.cf/r63/Flags/' .$member['country'] . '.png">
                    </td>
               
                    </td>
                </tr>
            </tbody>
            </table>';
        }
    }
    else
    {
        echo '<i>No information available.</i>';
    }
    echo '</div>
    </div>
</div>
<script type="text/javascript">if (!$(document.body).hasClassName(\'process-template\')) { Rounder.init(); }</script> ';
}
?>
<div id="container">
    <div id="content">
    <div id="column2" class="column">
<?php
error_reporting(0);
$getRanks = mysql_query("SELECT id,name FROM ranks WHERE id = 4 ORDER BY id DESC");
$Bans = mysql_query("SELECT * FROM `bans` WHERE `username` = '" . $Users['username'] . "'");
$BanCount = mysql_num_rows($Bans);
echo $BanCount;
while ($Ranks = mysql_fetch_assoc($getRanks))
{
    echo '<div class="habblet-container ">    
<div class="cbb clearfix red ">
<h2 class="title"><span style="float: left;">Trial Moderator</span> <span style="float: right; font-weight: normal; font-size: 75%;"></span></h2>';
    $getMembers = mysql_query("SELECT id,username,motto,look,account_created,online,last_online,role,age,country FROM users WHERE rank = '" . $Ranks['id'] . "'");
    echo '<div class="box-content">';
    if (mysql_num_rows($getMembers) > 0)
    {
        $oe = 1;
        while ($member = mysql_fetch_assoc($getMembers))
        {
            if ($oe == 2)
            {
                $oe = 1;
            }
            else
            {
                $oe = 2;
            }
$Bans = mysql_query("SELECT * FROM `bans` WHERE `added_by` = '" . $member['username'] . "'");
$BanCount = mysql_num_rows($Bans);
            echo '<table width="107%" height="50px" style="padding: 5px; margin-left: -15px; background-color: ' . (($oe == 2) ? '#fff' : '#E6E6E6') . ';">
            <tbody>
                <tr>
                    <td valign="middle" width="25">
                        <img style="margin-top: -10px;" src="http://www.habbo.nl/habbo-imaging/avatarimage?figure=' .$member['look'] . '&size=m&direction=2&head_direction=3&gesture=sml">
                    </td>
                    <td valign="top">
                        </br><p style="margin-top: -10px;" style="font-size: 100%;"><strong><a><u>' .$member['username'] . '</a></u></strong><br>Last online: <i>' . date('d M, Y', $member['last_online']) . '</i><br>Motto: "<i>' . $member['motto'] . '</i>"<br>' . (($member['online'] == "1") ? '<font color="darkgreen"><p style="margin-left: 165px; margin-top: -37px;"><strong>Online</stromg>': '<font color="darkred"><strong><p style="margin-left: 165px; margin-top: -37px;">Offline</stromg>') . '</p></font></font></strong>
                        <hr>
                        Role: <b>' . $member['role'] . '</b><br>
                        Age: ' . $member['age'] . '</br>
                        Registered on: <b>' . date('d M, Y', $member['account_created']) . '</b></br>
                   
                        Bans: <b>'; echo $BanCount;
                   
                   
                   
                   
                   
                   
               
                   
                    echo '<img src="http://URLhotel.cf/r63/Flags/' .$member['country'] . '.png">
                    </td>
               
                    </td>
                </tr>
            </tbody>
            </table>';
        }
    }
    else
    {
        echo '<i>No information available.</i>';
    }
    echo '</div>
    </div>
</div>
<script type="text/javascript">if (!$(document.body).hasClassName(\'process-template\')) { Rounder.init(); }</script> ';
}
?>
 

Khalil

IDK
Dec 6, 2011
1,642
786
That code only grabs data from your database and displays it, so no. Backdoors are usually found in code that inserts data into the database, not extracts data from it.

P.S: Don't call yourself helper if you're unable to help yourself. :p
 

Users who are viewing this thread

Top