• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

getting php code off a site?

Ruckus

Hardforum Moderator-in-Chief
Joined
Oct 12, 2001
Messages
10,768
I know some of you have been able to do it. How can you access the server side code from php? I am not trying to steal a site or anything. Im just trying to figure out how some gaming clans can post live updated america's army honor numbers on their site.

http://notanotherwebsite.mine.nu/omega10mg/una/htm/members.php they do it here but wont say how they are grabbing the info from america's army. I know some of you guys always mess people up when they start my "unreadable code" things and you always manage to tell them the code. So im asking for your help in either telling me how you do it, or giving me that piece of code.
 
Ruckus said:
I know some of you have been able to do it. How can you access the server side code from php? I am not trying to steal a site or anything. Im just trying to figure out how some gaming clans can post live updated america's army honor numbers on their site.

http://notanotherwebsite.mine.nu/omega10mg/una/htm/members.php they do it here but wont say how they are grabbing the info from america's army. I know some of you guys always mess people up when they start my "unreadable code" things and you always manage to tell them the code. So im asking for your help in either telling me how you do it, or giving me that piece of code.

don't know how to read actual PHP files off someone's site, but i do know that one of the mistakes people make (me included!) is to use include files with PHP code in them but did not use a PHP extension (like file.inc). These kinds of files don't get parsed, so if you link directly to them, the browser will simply display it as regular text.
 
Yep. Other than slip-ups like what maw mentioned (the fix is to add an .htaccess line for Apache to parse .inc files, incidentally), you can't.

However, you can probably search and find an AA stats parser. I doubt many clans write their own, so it's probably out in the open.
//edit: something like this maybe?
http://aaotracker.4players.de/
 
100 sites searched and nothing :(
yeah i have a tracker account but they wont tell you how to do it. They are hush hush, and i dont want to use their "sig" because it puts way more than i want.
 
Also, i'd assume that if you managed to compromise the server itself, then you could view whatever you wanted to. if this was the method used, then i can see why they would be unwilling to divulge that info.
 
mr tanooki said:
are you trying to hax0r their website?
Im not trying to hack anytihng i just want to be able to show my clans honor without having to change it every time someone gets 1 more.
 
Email the webmaster, and tell them what you're doing. They might be more than willing to help.
 
NewBlackDak said:
Email the webmaster, and tell them what you're doing. They might be more than willing to help.

heh the guide of the site listed above told me he would "sell me a site" but wouldnt tell me the code. It's like wtf i can make a site im just looking how to add a cetain function to my existing site.
 
i just thought of another possiblity, maybe they are grabbing an RSS feed from the America's Army website and pulling their clan info out of the XML file? at least that may give you a direction to start with if you want to write something similar
 
maw said:
don't know how to read actual PHP files off someone's site, but i do know that one of the mistakes people make (me included!) is to use include files with PHP code in them but did not use a PHP extension (like file.inc). These kinds of files don't get parsed, so if you link directly to them, the browser will simply display it as regular text.

QUESTION... if I do includes in .inc instead of .php, how would the person know where the include files are located? So, regardless.... unless he knows the exact filename, he wouldn't get to my .inc files, right?

In any case... having a .php extension for includes is better, right?
 
RavinDJ said:
QUESTION... if I do includes in .inc instead of .php, how would the person know where the include files are located? So, regardless.... unless he knows the exact filename, he wouldn't get to my .inc files, right?

In any case... having a .php extension for includes is better, right?

Just setup apache to recognize .inc files as php. If you can, always avoid letting people know what your website was written in, it makes it that much harder to find exploits.
 
RavinDJ said:
QUESTION... if I do includes in .inc instead of .php, how would the person know where the include files are located? So, regardless.... unless he knows the exact filename, he wouldn't get to my .inc files, right?

In any case... having a .php extension for includes is better, right?
i save my inc files as whatever.inc.php and have a .htaccess in the directory for double security.
 
tim_m said:
i save my inc files as whatever.inc.php and have a .htaccess in the directory for double security.

AddType application/x-httpd-php .inc

This should fix all your problems.
 
What they are most likely doing is "screen scraping". They open an HTTP connection to the desired server, request a certain page, then parse the data coming back into whatever form they want. It's an old trick, and doesn't require having access to anyone's PHP code. It can still be illegal to rip content from another site and put it on your own without permissions, but especially in this case, is unlikely. Do a google for screen scraping, or curl tutorials, or something along those lines for starters.
 
wow last 4 posts arent too off topic.
Ill look into the screen scraping
 
Back
Top