|
Cant acces phpauction XL 2 admin area
I,
I have setup the phpauction xl 2 but seem that i cant connect to the admin area of phpauction.
Basicaly Evrytime i go to the admin area it askme to create a admin username and password, i have tryied loads of times and always the same screen. I went to my database to check if its writting something in the proper admin table and seems nothing is being iserted there.
I tried even to manualy to input the username and admin password but agan nothing.. it seems that the phpaucting uses a security algorithm calle md5_prefix that i cant understand..
If someone knows abouth this problem that can give me some light i would appreciate. I leave you with the login.php from admin area...
php Code:
Original
- php Code |
|
|
|
<?#//v.2.0.0 #/////////////////////////////////////////////////////// #// COPYRIGHT 2004 Phpauction.org ALL RIGHTS RESERVED// #/////////////////////////////////////////////////////// require('../includes/messages.inc.php'); require('../includes/config.inc.php'); if($HTTP_POST_VARS[action ] == "insert" && basename($HTTP_REFERER) == basename($PHP_SELF)) { #// Additional security check $RR = mysql_query("SELECT id from PHPAUCTIONXL_adminusers"); { print "Fatal error: user cannot be inserted - one or more administrators are already present in the database.<BR><A HREF=login.php>login page</A>"; } $md5_pass= md5($MD5_PREFIX. $password); $query = "insert into PHPAUCTIONXL_adminusers values (10,'$username', '$md5_pass', '20011224', '20020110093458', 1)"; #// Redirect Header("Location: admin.php"); } $query = "select MAX(id) from PHPAUCTIONXL_adminusers"; { $id = $row[0] + 1; } if($id==1) { $id=0; require("./header.php"); ?> <TABLE BORDER=0 WIDTH=650 CELLPADDING=0 CELLSPACING=0 BGCOLOR="#FFFFFF" ALIGN="CENTER"> <TR> <TD><CENTER><FONT FACE="Verdana, Arial, Helvetica, sans-serif" SIZE="4"><BR> <BR> <FORM NAME=login ACTION=login2.php METHOD=POST> <TABLE WIDTH="410" BORDER="0" CELLSPACING="0" CELLPADDING="1" BGCOLOR="#336699"> <TR> <TD> <TABLE WIDTH=100% CELLPADDING=3 ALIGN="CENTER" CELLSPACING="0" BORDER="0" BGCOLOR="#FFFFFF"> <TR BGCOLOR="#336699"> <TD COLSPAN="2" ALIGN=CENTER><FONT FACE="Tahoma, Verdana" SIZE="2" COLOR="#FFFFFF"><B> :: Please create your username and password ::</B></FONT> <? print "$pw=$md5_pass"; ?> </TD> </TR> <TR> <TD></TD> <TD> <FONT FACE="Verdana, Verdana, Arial, Helvetica, sans-serif" SIZE="2" COLOR=red> </FONT> </TD> </TR> <TR> <TD ALIGN=right> <FONT FACE="Verdana, Verdana, Arial, Helvetica, sans-serif" SIZE="2"> $MSG_003; ?> </FONT> </TD> <TD> <INPUT TYPE=TEXT NAME=username SIZE=20 > </TD> </TR> <TR> <TD ALIGN=right> <FONT FACE="Verdana, Verdana, Arial, Helvetica, sans-serif" SIZE="2"> $MSG_004; ?> </FONT> </TD> <TD> <INPUT TYPE=password NAME=password SIZE=20 > </TD> </TR> <TR> <TD></TD> <TD> <INPUT TYPE=submit NAME=action VALUE="insert"> </TD> </TR> </TABLE> </TD> </TR> </TABLE> </FORM> </font> </CENTER> </TD> </TR> </TABLE> <? } else { $id=1; #// if($HTTP_POST_VARS[action] == "login") { if(strlen($HTTP_POST_VARS[username ]) == 0 || strlen($HTTP_POST_VARS[password ]) == 0 ) { $ERR = $ERR_047; } else { $query = "select * from PHPAUCTIONXL_adminusers where username='$HTTP_POST_VARS[username]' and password='". md5($MD5_PREFIX. $HTTP_POST_VARS[password ]). "'"; if(!$res) { } { $ERR = $ERR_048; } else { #// Set sessions vars $PHPAUCTION_ADMIN_LOGIN = $admin[id]; $PHPAUCTION_ADMIN_USER = $admin[username]; #// Update last login information for this user $query = "update PHPAUCTIONXL_adminusers set lastlogin='". date("YmdHis"). "' where username='$admin[username]'"; if(!$rr) { } #// Redirect Header("Location: admin.php"); } } } require("./header.php"); ?> <TABLE BORDER=0 WIDTH=650 CELLPADDING=0 CELLSPACING=0 BGCOLOR="#FFFFFF" ALIGN="CENTER"> <TR> <TD> <CENTER> <FONT FACE="Verdana, Arial, Helvetica, sans-serif" SIZE="4"><BR> <BR> <? if(!$action || ($action && $ERR)) : ?> <FORM NAME=login ACTION=login.php METHOD=POST> <TABLE WIDTH="415" BORDER="0" CELLSPACING="0" CELLPADDING="1" BGCOLOR="#336699"> <TR> <TD> <TABLE WIDTH=100% CELLPADDING=4 ALIGN="CENTER" CELLSPACING="0" BORDER="0" BGCOLOR="#FFFFFF"> <TR BGCOLOR="#33CC33"> <TD COLSPAN="2" ALIGN=CENTER><FONT FACE="Verdana, Verdana, Arial, Helvetica, sans-serif" SIZE="1" COLOR= "#FFFFFF"><B>:: PLEASE LOG IN WITH THE USERNAME & PASSWORD YOU CREATED ::</B></FONT></TD> </TR> <TR> <TD></TD> <TD> <FONT FACE="Verdana, Verdana, Arial, Helvetica, sans-serif" SIZE="2" COLOR=red> <? print "$md5_pass = md5($md5_prefix, password)"; ?> </FONT> </TD> </TR> <TR> <TD ALIGN=right> <FONT FACE="Verdana, Verdana, Arial, Helvetica, sans-serif" SIZE="2"> $MSG_003; ?> </FONT> </TD> <TD> <INPUT TYPE=TEXT NAME=username SIZE=20 >
|