Jump to content

Recommended Posts

Hello,

Whats frong with my Paymentwall Script ?

i became this error messeage -> Missing parameters

<?php
	include('inc/config.php');
	
	if(!is_resource($sql))
	{
		exit("Problemi di connessione, si prega di contattare lo staff.");
	}
	
	define('SECRET', 'SECRET_CODE');
	define('IP_WHITELIST_CHECK_ACTIVE', true);
	
	define('CREDIT_TYPE_CHARGEBACK', 2);
	
	$ipsWhitelist = array('174.36.92.186', '174.36.96.66', '174.36.92.187', '174.36.92.192', '174.37.14.28');
	
	$userId = isset($_GET['uid']) ? $_GET['uid'] : null;
	$credits = isset($_GET['currency']) ? $_GET['currency'] : null;
	$type = isset($_GET['type']) ? $_GET['type'] : null;
	$refId = isset($_GET['ref']) ? $_GET['ref'] : null;
	$signature = isset($_GET['sig']) ? $_GET['sig'] : null;
	$sign_version = isset($_GET['sign_version']) ? $_GET['sign_version'] : null;
	
	$result = false;
	
	$errors = array ();
	
	if (!empty($userId) && !empty($credits) && isset($type) && !empty($refId) && !empty($signature))
	{
		$signatureParams = array();
		
		if (empty($sign_version) || $sign_version <= 1)
		{
			$signatureParams = array('uid' => $userId, 'currency' => $credits, 'type' => $type, 'ref' => $refId);
		}
		else
		{
			$signatureParams = array();
			foreach ($_GET as $param => $value) {$signatureParams[$param] = $value;}
			unset($signatureParams['sig']);
		}
		
		$signatureCalculated = calculatePingbackSignature($signatureParams, SECRET, $sign_version);
		
		if (!IP_WHITELIST_CHECK_ACTIVE || in_array($_SERVER['REMOTE_ADDR'], $ipsWhitelist))
		{
			if ($signature == $signatureCalculated)
			{
				$result = true;
				if ($type == CREDIT_TYPE_CHARGEBACK)
				{
					if ($credits >= '1')
					{
						$update_cash = mysql_query("UPDATE ".$db_account_name.".account SET coins = coins - '".$credits."' WHERE id = ('".$userId."')");
					}
					else
					{
						$update_cash = mysql_query("UPDATE ".$db_account_name.".account SET coins = coins - '1' WHERE id = ('".$userId."')");
					}
				}
				else
				{
					if ($credits >= '1')
					{
						$update_cash = mysql_query("UPDATE ".$db_account_name.".account SET coins = coins + '".$credits."' WHERE id = ('".$userId."')");
					}
					else
					{
						$update_cash = mysql_query("UPDATE ".$db_account_name.".account SET coins = coins + '1' WHERE id = ('".$userId."')");
					}
				}
				
				if (!$update_cash)
				{
					$result = false;
				}
			}
			else
			{
				$errors['signature'] = 'Signature is not valid!';    
			}
		}
		else
		{
			$errors['whitelist'] = 'IP not in whitelist!';
		}
	}
	else
	{
		$errors['params'] = 'Missing parameters!';
	}
	
	if ($result)
	{
		echo 'OK';
	}
	else
	{
		echo implode(' ', $errors);
	}
	
	function calculatePingbackSignature($params, $secret, $version)
	{
		$str = '';
		if ($version == 2)
		{
			ksort($params);
		}
		
		foreach ($params as $k=>$v) {$str .= "$k=$v";}
		$str .= $secret;
		return md5($str);
	}
?>

 

  • Love 1
Link to comment
https://metin2.dev/topic/7470-paymentwall-script/
Share on other sites

$userId = isset($_GET['uid']) ? $_GET['uid'] : null;
$credits = isset($_GET['currency']) ? $_GET['currency'] : null;
$type = isset($_GET['type']) ? $_GET['type'] : null;
$refId = isset($_GET['ref']) ? $_GET['ref'] : null;
$signature = isset($_GET['sig']) ? $_GET['sig'] : null;
$sign_version = isset($_GET['sign_version']) ? $_GET['sign_version'] : null;

At this part better use empty instead of isset. Then you dont have to check it later.

Furthermore you should escape it or use prepared statements to prevent sqli.

Link to comment
https://metin2.dev/topic/7470-paymentwall-script/#findComment-46978
Share on other sites

  • 6 months later...

This is my old paymentwall script. Just change path to config and query lines. This was made for Shock Industries CMS. Dont forget to change the secret key

 

<?php
//###########################
//### Spenden API Script  ###
//### paymentwall_api.php ###
//###########################
// includiere inis
require("../inc/config.inc.php");

// Verbinde zur Datenbank
$sqlHp = mysql_connect(SQL_HP_HOST, SQL_HP_USER, SQL_HP_PASS);
  
if(!$sqlHp) {
    // Beende Script wenn Verbidung fehlgeschlagen.
    exit('Fehler beim Verbinden mit der Datenbank.');
};

define('SECRET', 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx'); // secret key
define('IP_WHITELIST_CHECK_ACTIVE', true); // Whitelist
define('CREDIT_TYPE_CHARGEBACK', 2); // Chargeback ist momentan 2

// Nur IPs von Paymentwall erlauben
$ipsWhitelist = array('174.36.92.186','174.36.96.66','174.36.92.187','174.36.92.192','174.37.14.28');

// Variablen zuordnen
$userId = isset($_GET['uid']) ? $_GET['uid'] : null;
$credits = isset($_GET['currency']) ? $_GET['currency'] : null;
$type = isset($_GET['type']) ? $_GET['type'] : null;
$refId = isset($_GET['ref']) ? $_GET['ref'] : null;

$slength = isset($_GET['slength']) ? $_GET['slength'] : null;
$speriod = isset($_GET['speriod']) ? $_GET['speriod'] : null;
$goodsid = isset($_GET['goodsid']) ? $_GET['goodsid'] : null;

$signature = isset($_GET['sig']) ? $_GET['sig'] : null;
$sign_version = isset($_GET['sign_version']) ? $_GET['sign_version'] : null;

$result = false;

// Wenn Fehler, gebe array aus
$errors = array ();

if(!empty($userId) && isset($type) && isset($goodsid) && !empty($refId) && !empty($signature)) {
    $signatureParams = array();
    
    // Version 1 signature   
    if(empty($sign_version) || $sign_version <= 1) {
        $signatureParams = array('uid' => $userId, 'slength' => $slength, 'speriod' => $speriod, 'currency' => $credits, 'type' => $type, 'ref' => $refId);
    }
    // Version 2 signature
    else {
        $signatureParams = array();
        foreach($_GET as $param => $value) {
            $signatureParams[$param] = $value;
            }
            unset($signatureParams['sig']);
    }

    // Check ob IP in whitelist und ob Signatur stimmt
    $signatureCalculated = calculatePingbackSignature($signatureParams, SECRET, $sign_version);
    // Run securitycheck
    if(!IP_WHITELIST_CHECK_ACTIVE || in_array($_SERVER['REMOTE_ADDR'], $ipsWhitelist)) {
        if($signature == $signatureCalculated) {
            $result = true;
            if ($type == CREDIT_TYPE_CHARGEBACK) {
                // Chargeback - Account sperren
                mysql_connect(SQL_HP_HOST, SQL_HP_USER, SQL_HP_PASS) or die ("keine Verbindung möglich.");
                mysql_select_db("account") or die ("Die Datenbank existiert nicht.");
                
                // Gleiche goodsid mit Datenbank ab
                    $abfrage = "SELECT * FROM paymentwall_coinsliste WHERE `goodsid` = '$goodsid'";
                    $ergebnis = mysql_query($abfrage);
                    while($row = mysql_fetch_object($ergebnis)) {
                        $var01 = $row->coins;
                    }
                    
                // Frage ab wie viel coins vorhanden
                $abfrage = "SELECT id, coins FROM account WHERE `id` = '$userId'";
                $ergebnis = mysql_query($abfrage);
                while($row = mysql_fetch_object($ergebnis)) {
                    $currentcoints = $row->coins;
                }
                
                // Ziehe Coints von vorhandem Betrag ab
                $finalcoins = $currentcoints - $var01;                
                
                // Udate Aktuellen Cointstand des Useres
                $aendern1 = "UPDATE `account` SET `coins` = '$finalcoins' WHERE `id` = '$userId'";
                mysql_query($aendern1);
                
                // Mache Eintrag in die Tabelle paymentwall
                $eintrag = "INSERT INTO paymentwall (UserID, Currency, Type, Date) VALUES ('".$userId."', '-".$var01."', 'Chargeback', '".date("d-m-Y H:i:s")."')";
                mysql_query($eintrag);
                
                // Gebe User den Status DONATE
                $aendern2 = "UPDATE `account` SET `status` = 'DONATE' WHERE `id` = '$userId'";
                mysql_query($aendern2);
                
                // echo "Dein Account wurde blockiert!";
                } else {
                    mysql_connect(SQL_HP_HOST, SQL_HP_USER, SQL_HP_PASS) or die ("keine Verbindung möglich.");
                    mysql_select_db("account") or die ("Die Datenbank existiert nicht.");
                    
                    // Gleiche goodsid mit Datenbank ab
                    $abfrage = "SELECT * FROM paymentwall_coinsliste WHERE `goodsid` = '$goodsid'";
                    $ergebnis = mysql_query($abfrage);
                    while($row = mysql_fetch_object($ergebnis)) {
                        $var01 = $row->coins;
                    }
                    
                    // Mache Eintrag in die Tabelle paymentwall
                    $eintrag = "INSERT INTO paymentwall (UserID, Currency, Type, Date) VALUES ('".$userId."', '".$var01."', 'OK', '".date("d-m-Y H:i:s")."')";
                    mysql_query($eintrag);
                    
                    
                    // Frage ab wie viel coins vorhanden
                    $abfrage = "SELECT id, coins FROM account WHERE `id` = '$userId'";
                    $ergebnis = mysql_query($abfrage);
                    while($row = mysql_fetch_object($ergebnis)) {
                        $currentcoints = $row->coins;
                    }
                    
                    $finalcoins = $currentcoints + $var01;
                    $aendern = "UPDATE `account` SET `coins` = '$finalcoins' WHERE `id` = '$userId'";
                    mysql_query($aendern);
                    // echo "Dir wurden <b>$credits</b> coints gutgeschrieben";
                }
        } else {
            $errors['signature'] = 'Signature ist nicht korrekt!'; 
        }
    } else {
        $errors['whitelist'] = 'IP nicht in der Whitelist!';
    }
} else {
    $errors['params'] = 'Es fehlen Parameter!';
}
// Gebe OK ab um Transaktion zu beenden
if($result) {
    echo 'OK';
} else {
    echo implode(' ', $errors);
}

// Signature calculation function
function calculatePingbackSignature($params, $secret, $version) {
    $str = '';
    if($version == 2) {
        ksort($params);
    }
    foreach($params as $k=>$v) {
        $str .= "$k=$v";
    }
    $str .= $secret;
    return md5($str);
}
class Database
    {
        private $db;
        public function Database($host, $user, $pass, $db) {
            try {
                $this->db = new PDO("mysql:dbname=".$db.";host=".$host.";", $user, $pass);        
            } catch(PDOEXCEPTION $e) {
                die('Error! [Code: '.$e->getCode().']!');
            }
        }
        public function runQuery($query) {
            return $this->db->query($query);    
        }
    }
?>

 This is an old script. I dont know if it works today. You can delete the database class. You dont need it in your case
Link to comment
https://metin2.dev/topic/7470-paymentwall-script/#findComment-59926
Share on other sites

Don't use any images from : imgur, turkmmop, freakgamers, inforge, hizliresim... Or your content will be deleted without notice...
Use : https://metin2.download/media/add/

Please use https://metin2.download/ when uploading files smaller than 100MB, otherwise the approval will take longer due to manual upload.

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
×
×
  • Create New...

Important Information

Terms of Use / Privacy Policy / Guidelines / We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.