Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
Dysfunctional
No. VIP is a optional thing on retros. Its the same thing on Habbo. If you want more benefits you have an option to purchase VIP.
Ofcourse VIP is optional, just like Habbo. Read my post agian. Retros should be 100% free with a option to DONATE to the hotel owner to help him out with the server-bill. Not *PAY* for VIP with benefits in return
A perfect example is Fresh hotel, that kid is charging for VIP, Rares, Bots, Coins, Pixels, Achievement score, Customs, eXpert rank (WOW), and much more. He also did sell Event Staff positions for 40£, but I guess he removed it. That greedy bastard is even selling Enhanced Account Security for 5£ which should be included in the account. Pay for account security? Thats the biggest bullshit I've ever heard
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
HickDead
Ofcourse VIP is optional, just like Habbo. Read my post agian. Retros should be 100% free with a option to DONATE to the hotel owner to help him out with the server-bill. Not *PAY* for VIP with benefits in return
A perfect example is Fresh hotel, that kid is charging for VIP, Rares, Bots, Coins, Pixels, Achievement score, Customs, eXpert rank (WOW), and much more. He also did sell Event Staff positions for 40£, but I guess he removed it. That greedy bastard is even selling Enhanced Account Security for 5£ which should be included in the account. Pay for account security? Thats the biggest bullshit I've ever heard
I've owned Zap for 2 years now and i've had to pay over $7,000 for server hosting. We need VIP donations to survive.
To add, no user is just going to donate for nothing. You need to offer a reward.
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
Jonteh
I've owned Zap for 2 years now and i've had to pay over $7,000 for server hosting. We need VIP donations to survive.
To add, no user is just going to donate for nothing. You need to offer a reward.
I know someone who was donated over £500 just for keeping his hotel open :/
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
HickDead
*Ragezone habbo commuinty* They don't like purchasing VIP.
And personally I'm with them, many retro owners are like Paul LaFontaine and trying to drag money out of their players (DONATE OR I SHUTDOWN / BAN YOU!). Retros have become to much like Habbo, pay for dit, pay for dat. They've forgot WHY WE MAKE RETROS, the whole fucking point. The reason why people join retros is beacuse the don't wanna have to pay for everything, if they wanted to pay for everything they would pretty much stay with Habbo and not quit for retros.
Look, I understand you run a RevCMS hotel, get a maximum of 10 online and run off a $15 VPS. But you see, for any one with in 20th and minus on the Habbos. You need a decent server, and you most probably need DDoS protection. Virtually every retro owner is a skid with a booter and they still stop at nothing to take your hotel down. With this, you require donations and external funding. Despite what it is, a website should at least pay for its self in terms of money. I've hosted hotels and done nothing to other owners, I don't even speak to any of them. Yet I got booted offline daily. So I had to use hotel money to invest in DDoS protection. I'm not gonna pay for something which is costly.
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
I take surplus from PayPal because my VPS is cheap. Matthew's exactly right, and I would like to know where he gets DDoS protection because LimestoneNetworks isn't giving KrypticCloud jack squat protection. The point is, VIP+ poses a benefit to the hotel AND its users. It keeps me online and rich, and it gives the users a great opportunity to be more active and get something in return. VIP+ so far is a huge hit on the hotel, the problem being I'm a sucker and I give it for free if the person's PayPal isn't sending money due to restrictions (I ask for a screencap), and I give it away in competitions. We in no way are to be compared to Sulake. Sulake uses heavy advertisement, 5+ payment methods, and doesn't treat the subscriptions like a 'fun deal', where they give it away and play around with it under conditions. To anyone arguing "Well, I know this guy/owner who donated/got a donation for free just for the hotel to stay online.", shut up. They were just kissing ass, nobody would donate to a hotel where there's no return item for them, and you know that to be true. And if they weren't donating to kiss ass, they gave money to their friend. Now let's stop this, because it's not a discussion thread here, this is a release, and if you want to discuss this whole VIP debate, open a thread in /f282/, despite it being debated over and over and over.
Quote:
Originally Posted by
Divide
I like it, few exploits found.. But they can easily be changed.
Thanks for telling me. I'd appreciate it if anyone in this section finds an exploit, they also mention what it is and how to change it. :>
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
Jonteh
There's a perfectly fine IPN released with every CMS release of mine.
Exactly my point, Jonty!
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
PHP Code:
mysql_query("UPDATE users SET vip = '1', rank = '2', credits = credits + 2000, activity_points = activity_points + 10 WHERE username = '".$p->ipn_data['custom']."' LIMIT 1");
I've not looked at all the code, but this seems unfiltered.
The filter function only filters html tags, doesn't seem to return a safe mysql string.
[PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
Eronisch
PHP Code:
mysql_query("UPDATE users SET vip = '1', rank = '2', credits = credits + 2000, activity_points = activity_points + 10 WHERE username = '".$p->ipn_data['custom']."' LIMIT 1");
I've not looked at all the code, but this seems unfiltered.
The filter function only filters html tags, doesn't seem to return a safe mysql string.
See I have no idea how injections work. Can you send me a link or something because Wikipedia is really not working for me.
Quote:
Originally Posted by
Eronisch
PHP Code:
mysql_query("UPDATE users SET vip = '1', rank = '2', credits = credits + 2000, activity_points = activity_points + 10 WHERE username = '".$p->ipn_data['custom']."' LIMIT 1");
I've not looked at all the code, but this seems unfiltered.
The filter function only filters html tags, doesn't seem to return a safe mysql string.
Divide sent me the updated and secured code. I'll update the thread this evening.
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
FullmetalPride
I take surplus from PayPal because my VPS is cheap. Matthew's exactly right, and I would like to know where he gets DDoS protection because LimestoneNetworks isn't giving KrypticCloud jack squat protection. The point is, VIP+ poses a benefit to the hotel AND its users. It keeps me online and rich, and it gives the users a great opportunity to be more active and get something in return. VIP+ so far is a huge hit on the hotel, the problem being I'm a sucker and I give it for free if the person's PayPal isn't sending money due to restrictions (I ask for a screencap), and I give it away in competitions. We in no way are to be compared to Sulake. Sulake uses heavy advertisement, 5+ payment methods, and doesn't treat the subscriptions like a 'fun deal', where they give it away and play around with it under conditions. To anyone arguing "Well, I know this guy/owner who donated/got a donation for free just for the hotel to stay online.", shut up. They were just kissing ass, nobody would donate to a hotel where there's no return item for them, and you know that to be true. And if they weren't donating to kiss ass, they gave money to their friend. Now let's stop this, because it's not a discussion thread here, this is a release, and if you want to discuss this whole VIP debate, open a thread in /f282/, despite it being debated over and over and over.
Thanks for telling me. I'd appreciate it if anyone in this section finds an exploit, they also mention what it is and how to change it. :>
To fix exploits just filter any dynamic $_POST or $_GET variable. (mysql_real_escape_string if connected to a db.)
As for DDoS protection, talk to <Joh />. I switch between 4 of his servers and a couple of my own and it seems effective so far. Both Fresh and I put our hotels on it and it crashed though, not sure how stable it is.
If his doesn't work for you I suppose I can set you up on my personal server (for a fee.)
[PayPal] PayPal IPN - Automatic VIP [TESTED]
I'm doing fine right now. What I need is votes. And jonteh thanks for the help but I really don't understand much php or MySQL yet. And I've got injections in my own CMS.
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
What is so exclusive about VIP if you dont have to pay for it.. you shouldnt call it VIP if its free.
[PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by ;7450861
What is so exclusive about VIP if you dont have to pay for it.. you shouldnt call it VIP if its free.
Wat.
What're you on about? This makes VIP given automatically after purchase, not free..
:l read the thread ffs
Re: [PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by
FullmetalPride
Wat.
What're you on about? This makes VIP given automatically after purchase, not free..
:l read the thread ffs
Wasnt talking about your release - was talking about the people arguing over wether it should be free or not. :):
[PayPal] PayPal IPN - Automatic VIP [TESTED]
Quote:
Originally Posted by ;7452227
Wasnt talking about your release - was talking about the people arguing over wether it should be free or not. :):
Ah sorry.