View file wapirate/x/admincp.php

File size: 68.73Kb
<?

session_start();

//--------------------------
// user definable variables:
//--------------------------

// maximum number of seconds user can remain idle without having to re-login:
// use a value of zero for no timeout
$max_session_time = 0;

// type of alert to give on incorrect password:
// eg:
// $alert = "joe@foo.com";- sends email to joe@foo.com
// $alert = "blah";- appends to file named 'blah'
// $alert = "";- no alerts
$alert = "./.ht_badlogins";

// acceptable passwords:
$cmp_pass = Array();
$cmp_pass[] = md5("admin");

$cmp_pass[] = md5("admin2");
// add as many as you like

// maximum number of bad logins before user locked out
// use a value of zero for no hammering protection
$max_attempts = 3;

//-----------------------------
// end user definable variables
//-----------------------------


// save session expiry time for later comparision
$session_expires = $_SESSION['mpass_session_expires'];

// have to do this otherwise max_attempts is actually one less than what you specify.
$max_attempts++;

if(!empty($_POST['mpass_pass']))
{
// store md5'ed password
$_SESSION['mpass_pass'] = md5($_POST['mpass_pass']);
}

if(empty($_SESSION['mpass_attempts']))
{
$_SESSION['mpass_attempts'] = 0;
}

// if the session has expired, or the password is incorrect, show login page:
if(($max_session_time>0 && !empty($session_expires) && mktime()>$session_expires) || empty($_SESSION['mpass_pass']) || !in_array($_SESSION['mpass_pass'],$cmp_pass))
{
if(!empty($alert) && !in_array($_SESSION['mpass_pass'],$cmp_pass))
{
// user has submitted incorrect password
// generate alert:

$_SESSION['mpass_attempts']++;

$alert_str = $_SERVER['REMOTE_ADDR']." entered ".htmlspecialchars($_POST['mpass_pass'])." on page ".$_SERVER['PHP_SELF']." on ".date("l dS of F Y h:i:s A")."\r\n";

if(stristr($alert,"@")!==false)
{
// email alert
@mail($alert,"Bad Login on ".$_SERVER['PHP_SELF'],$alert_str,"From: ".$alert);
} else {
// textfile alert
$handle = @fopen($alert,'a');
if($handle)
{
fwrite($handle,$alert_str);
fclose($handle);
}
}
}
// if hammering protection is enabled, lock user out if they've reached the maximum
if($max_attempts>1 && $_SESSION['mpass_attempts']>=$max_attempts)
{
exit("Too many login failures.");
}


// clear session expiry time
$_SESSION['mpass_session_expires'] = "";

?>
<html>
<head>
<title>Enter Password</title>
</head>
<body>
<form action="<?=$_SERVER['REQUEST_URI']?>" method="post">
<h4>Password Protected</h4>
<input type="password" name="mpass_pass"><br/>
<input type="submit" value="login">
</form>
</body>
</html>
<?

// and exit
exit();
}

// if they've got this far, they've entered the correct password:

// reset attempts
$_SESSION['mpass_attempts'] = 0;

// update session expiry time
$_SESSION['mpass_session_expires'] = mktime()+$max_session_time;

// end password protection code
?>
<?php
include("head.php");
include("boring.php");
$sta = getstatusname($uid);
if(!isstatus10(getuid_sid($sid)))
  {
addonline(getuid_sid($sid),"Im Trying To Hack Admin. Naughty Me!","");
      echo "<div><br/>Doh!</<br/></div>";
      echo "<p align=\"center\">";
      echo "You are not an $status10<br/>";
      echo "<br/>";
echo getfoot($sid,$folder);
exit();
}

    addonline(getuid_sid($sid),"Main Page","");
if($action=="general")
{
  $att = mysql_fetch_array(mysql_query("SELECT value FROM ibwf_settings WHERE name='attachment'"));
  $val = mysql_fetch_array(mysql_query("SELECT value FROM ibwf_settings WHERE name='validation'"));
    $xtm = getsxtm();
    $paf = getpmaf();
    $fvw = getfview();
    $fmsg = htmlspecialchars(getfmsg());
    if(canreg())
    {
      $arv = "e";
    }else{
      $arv= "d";
    }
  echo "<div><br/>General Settings</<br/></div>";
  echo "<br/><form action=\"admproc.php?action=general\" method=\"post\">";
  echo "Session Period: ";
  echo "<input name=\"sesp\" format=\"*N\" maxlength=\"3\" size=\"3\" value=\"$xtm\"/>";
  echo "<br/>PM Antiflood<input name=\"pmaf\" format=\"*N\" maxlength=\"3\" size=\"3\" value=\"$paf\"/>";
  echo "<br/>Index Page Message: ";
  echo "<input name=\"fmsg\"  maxlength=\"255\" value=\"$fmsg\"/>";
  echo "<br/>Registration: ";
  echo "<select name=\"areg\" value=\"$arv\">";
  echo "<option value=\"e\">Enabled</option>";
if($arv=="d"){$selected=" selected=\"selected\"";}else{$selected="";}
  echo "<option value=\"d\"$selected>Disabled</option>";
  echo "</select><br/>";
  echo "View: ";
  echo "<select name=\"fvw\" value=\"$fvw\">";
  //$vname[0]="Drop Menu";
  $vname[0]="Horizontal Links";
  $vname[1]="Nothing";
  for($i=0;$i<count($vname);$i++)
  {
if($fvw=="$i"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"$i\"$selected>$vname[$i]</option>";
  }
  
  echo "</select>";
  echo "<br/>Validation: ";
  echo "<select name=\"val\" value=\"$val[0]\">";
  echo "<option value=\"0\">Off</option>";
if($val[0]=="1"){$selected=" selected=\"selected\"";}else{$selected="";}
  echo "<option value=\"1\"$selected>On</option>";
  echo "</select><br/>";
  echo "Attachments: ";
  echo "<select name=\"att\" value=\"$att[0]\">";
  echo "<option value=\"0\">Off</option>";
if($att[0]=="1"){$selected=" selected=\"selected\"";}else{$selected="";}
  echo "<option value=\"1\"$selected>On</option>";
  echo "</select><br/>";
echo "<input type=\"submit\" value=\"submit\"/>";
echo "</form>";
  echo "<p align=\"center\">";
  echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
///////////////////////////
else if($action=="addperm")
{
   echo "<div><br/>Add permission</<br/></div>";
    $forums = mysql_query("SELECT id, name FROM ibwf_forums ORDER BY position, id, name");
echo "<form action=\"admproc.php?action=addperm\" method=\"post\">";
    echo "<br/><br/>Forum: <select name=\"fid\">";
    while ($forum=mysql_fetch_array($forums))
    {
        echo "<option value=\"$forum[0]\">$forum[1]</option>";
    }
    echo "</select>";
    $forums = mysql_query("SELECT id, name FROM ibwf_groups ORDER BY  name, id");
    echo "<br/>UGroups: <select name=\"gid\">";
    while ($forum=mysql_fetch_array($forums))
    {
        echo "<option value=\"$forum[0]\">$forum[1]</option>";
    }
    echo "</select>";
echo "<input type=\"submit\" value=\"Submit\"/>";
echo "</form>";
    echo "<p align=\"center\">";   
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
///////////////////////////////////////
else if($action=="fcats")
{
    echo "<div><br/>Categories</<br/></div>";
    echo "<p>";
    echo "<a href=\"admincp.php?action=addcat\">&#187;Add Category</a><br/>";
    echo "<a href=\"admincp.php?action=edtcat\">&#187;Edit Category</a><br/>";
    echo "<a href=\"admincp.php?action=delcat\">&#187;Delete Category</a><br/>";
    echo "</p>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
///////////////////////////////////////////////
else if($action=="club")
{
	$clid = $_GET["clid"];
       echo "<div><br/>Clubs</<br/></div>";
    echo "<p>";
    echo "<a href=\"admincp.php?action=gccp&amp;clid=$clid\">&#187;Give Credit Plusses</a><br/>";
    echo "<a href=\"admproc.php?action=delclub&amp;clid=$clid\">&#187;Delete Club</a><br/>";
    echo "</p>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////////////////////////
else if($action=="manrss")
{
    echo "<div><br/>RSS</<br/></div>";
    echo "<p>";
    echo "<a href=\"admincp.php?action=addrss\">&#187;Add Source</a><br/>";
    $noi = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_rss"));
    if($noi[0]>0)
    {
        $rss = mysql_query("SELECT title, id FROM ibwf_rss");
  echo "</p>";
echo "<form action=\"admincp.php?action=edtrss\" method=\"post\">";
        echo "<br/><select name=\"rssid\">";
        while($rs=mysql_fetch_array($rss))
        {
            echo "<option value=\"$rs[1]\">$rs[0]</option>";
        }
      echo "</select><br/>";
echo "<input type=\"submit\" value=\"Edit\"/>";
echo "<br/>";
echo "</form>";
}
$noe = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_rss"));
    if($noe[0]>0)
    {
        $rss1 = mysql_query("SELECT title, id FROM ibwf_rss");

echo "<form action=\"admproc.php?action=delrss\" method=\"post\">";
        echo "<br/><select name=\"rssid\">";
        while($rs1=mysql_fetch_array($rss1))
        {
            echo "<option value=\"$rs1[1]\">$rs1[0]</option>";
        }
      echo "</select><br/>";
echo "<input type=\"submit\" value=\"Delete\"/>";
echo "<br/>";
echo "</form>";
    }
     echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////////////////
else if($action=="chrooms")
{
    echo "<div><br/>Chat Rooms</<br/></div>";
    echo "<p>";
    echo "<a href=\"admincp.php?action=addchr\">&#187;Add Room</a><br/>";
    $noi = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_rooms"));
  echo "</p>";
    if($noi[0]>0)
    {
echo "<form action=\"admproc.php?action=delchr\" method=\"post\">";
        $rss = mysql_query("SELECT name, id FROM ibwf_rooms");
        echo "<br/><select name=\"chrid\">";
        while($rs=mysql_fetch_array($rss))
        {
            echo "<option value=\"$rs[1]\">$rs[0]</option>";
        }
      echo "</select><br/>";
echo "<input type=\"submit\" value=\"Delete\"/>";
echo "</form>";
    echo "<br/>";
    }
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////////////
else if($action=="forums")
{
    echo "<div><br/>Forums</<br/></div>";
    echo "<p>";
    echo "<a href=\"admincp.php?action=addfrm\">&#187;Add Forum</a><br/>";
    echo "<a href=\"admincp.php?action=edtfrm\">&#187;Edit Forum</a><br/>";
    echo "<a href=\"admincp.php?action=delfrm\">&#187;Delete Forum</a><br/>";
    echo "</p>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
///////////////////////////////////////////
else if($action=="clrdta")
{
    echo "<div><br/>Clear Data</<br/></div>";
    echo "<p>";
	echo "<a href=\"admproc.php?action=clearall\">&#187;Delete/Clear All Of below</a><br/>";
	echo "<a href=\"admproc.php?action=delatt\">&#187;Delete Attachments</a><br/>";
    echo "<a href=\"admproc.php?action=delpms\">&#187;Delete PMs</a><br/>";
    echo "<a href=\"admproc.php?action=clrmlog\">&#187;Clear ModLog</a><br/>";
    echo "<a href=\"admproc.php?action=delsht\">&#187;Delete Old Shouts</a><br/>";
    echo "<a href=\"admproc.php?action=delcookies\">&#187;Delete Old Cookies</a><br/>";
    echo "</p>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
/////////////////////////////////////////
else if($action=="ugroups")
{
     echo "<div><br/>User Groups</<br/></div>";
    echo "<p>";
    echo "<a href=\"admincp.php?action=addgrp\">&#187;Add User Group</a><br/>";
    //echo "<a href=\"admincp.php?action=edtgrp\">&#187;Edit User group</a><br/>";
    echo "<a href=\"admincp.php?action=delgrp\">&#187;Delete User group</a><br/>";
    echo "</p>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////////
else if($action=="addcat")
{

      echo "<div><br/>Add Category</<br/></div>";
	echo "<form action=\"admproc.php?action=addcat\" method=\"post\">";
    echo "Name: <input name=\"fcname\" maxlength=\"30\"/><br/>";
    echo "Position: <input name=\"fcpos\" format=\"*N\" size=\"3\"  maxlength=\"3\"/><br/>";
echo "<input type=\"submit\" value=\"Add\"/>";
    echo "</form>";
    echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=fcats\">";
  echo "Forum Categories</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
///////////////////////////////////
else if($action=="addfrm")
{
    echo "<div><br/>Add Forum</<br/></div>";
echo "<form action=\"admproc.php?action=addfrm\" method=\"post\">";
    echo "Name: <input name=\"frname\" maxlength=\"30\"/><br/>";
    echo "Position: <input name=\"frpos\" format=\"*N\" size=\"3\"  maxlength=\"3\"/><br/>";
    $fcats = mysql_query("SELECT id, name FROM ibwf_fcats ORDER BY position, id, name");
    echo "Category: <select name=\"fcid\">";
    while ($fcat=mysql_fetch_array($fcats))
    {
        echo "<option value=\"$fcat[0]\">$fcat[1]</option>";
    }
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Add\"/>";
echo "</form>";
      echo "<p align=\"center\">";  
    
    echo "<br/><br/><a href=\"admincp.php?action=forums\">";
  echo "Forums</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////
else if($action=="gccp")
{
     echo "<div><br/>Add club Gold</<br/></div>";
	$clid = $_GET["clid"];
echo "<form action=\"admproc.php?action=gccp&amp;clid=$clid\" method=\"post\">";
    echo "Plusses: <input name=\"plss\" maxlength=\"3\" size=\"3\" format=\"*N\"/><br/>";
echo "<input type=\"submit\" value=\"Give\"/>";
echo "</form>";
      echo "<p align=\"center\">";  
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////////////
else if($action=="addsml")
{
     echo "<div><br/>Add Smileys</<br/></div>";
    echo "<p align=\"center\">";
echo "Smiley Folder And .gif Not Required!<br/><br/>Example: <br/>Code = :happy <br/>Image Source = happy<br/><br/>";
  echo "</p>";
echo "<form action=\"admproc.php?action=addsml\" method=\"post\">";
    echo "Code: <input name=\"smlcde\" maxlength=\"30\"/><br/>";
    echo "Image Source: <input name=\"smlsrc\" maxlength=\"200\"/><br/>";
  echo "<select name=\"hide\">";
  echo "<option value=\"0\">Normal</option>";
  echo "<option value=\"1\">Hidden</option>";
  echo "<option value=\"2\">Mod</option>";
  echo "<option value=\"3\">Banana</option>";
  echo "</select><br/>";
 echo "<input type=\"submit\" value=\"Add\"/>";
echo "</form>";
    echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////////////////////
else if($action=="addavt")
{
     echo "<div><br/>Add Avatar</<br/></div>";

echo "<form action=\"admproc.php?action=addavt\" method=\"post\">";
    echo "Source: <input name=\"avtsrc\" maxlength=\"30\"/><br/>";
echo "<input type=\"submit\" value=\"Add\"/>";
echo "</form>";
    echo "<p align=\"center\">";    
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////////////
else if($action=="addrss")
{
     echo "<div><br/>Add RSS</<br/></div>";

echo "<form action=\"admproc.php?action=addrss\" method=\"post\">";
    echo "Name: <input name=\"rssnm\" maxlength=\"50\"/><br/>";
    echo "Source: <input name=\"rsslnk\" maxlength=\"255\"/><br/>";
    echo "Image: <input name=\"rssimg\" maxlength=\"255\"/><br/>";
    echo "Description: <input name=\"rssdsc\"  maxlength=\"255\"/><br/>";
    $forums = mysql_query("SELECT id, name FROM ibwf_forums ORDER BY position, id, name");
    echo "Forum: <select name=\"fid\">";
    echo "<option value=\"0\">NO FORUM</option>";
    while ($forum=mysql_fetch_array($forums))
    {
        echo "<option value=\"$forum[0]\">$forum[1]</option>";
    }
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Add\"/>";
echo "</form>";
     echo "<p align=\"center\">";  
    echo "<br/><br/><a href=\"admincp.php?action=manrss\">";
  echo "<img src=\"images/rss.gif\" alt=\"rss\"/>Manage RSS</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////
else if($action=="addchr")
{
     echo "<div><br/>Add Room</<br/></div>";

echo "<form action=\"admproc.php?action=addchr\" method=\"post\">";
    echo "Name:<input name=\"chrnm\" maxlength=\"30\"/><br/>";
    echo "Minimum Age:<input name=\"chrage\" format=\"*N\" maxlength=\"3\" size=\"3\"/><br/>";
    echo "Minimum Chat Posts:<input name=\"chrpst\" format=\"*N\" maxlength=\"4\" size=\"4\"/><br/>";
    echo "Permission:<select name=\"chrprm\">";
    echo "<option value=\"0\">Normal</option>";
    echo "<option value=\"1\">$status1</option>";
    echo "<option value=\"2\">$status2</option>";
    echo "<option value=\"3\">$status3</option>";
    echo "<option value=\"4\">$status4</option>";
    echo "<option value=\"5\">$status5</option>";
    echo "<option value=\"6\">$status6</option>";
    echo "<option value=\"7\">$status7</option>";
    echo "<option value=\"8\">$status8</option>";
    echo "<option value=\"9\">$status9</option>";
    echo "<option value=\"10\">$status10</option>";
    echo "</select><br/>";
    echo "Censored:<select name=\"chrcns\">";
    echo "<option value=\"1\">Yes</option>";
    echo "<option value=\"0\">No</option>";
    echo "</select><br/>";
    echo "Fun:<select name=\"chrfun\">";
    echo "<option value=\"0\">No</option>";
    echo "<option value=\"1\">esreveR</option>";
    echo "<option value=\"2\">UltiBabe</option>";
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Add\"/>";
    echo "<form>";
    echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=chrooms\">";
  echo "<img src=\"images/chat.gif\" alt=\"chat\"/>Chatrooms</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////
else if($action=="edtrss")
{
  $rssid = $_POST["rssid"];
  $rsinfo = mysql_fetch_array(mysql_query("SELECT title, link, imgsrc, fid, dscr FROM ibwf_rss WHERE id='".$rssid."'"));
    
     echo "<div><br/>Edit RSS</<br/></div>";   

echo "<form action=\"admproc.php?action=edtrss\" method=\"post\">";
    echo "Name: <input name=\"rssnm\" maxlength=\"50\" value=\"$rsinfo[0]\"/><br/>";
    echo "Source: <input name=\"rsslnk\" maxlength=\"255\" value=\"$rsinfo[1]\"/><br/>";
    echo "Image: <input name=\"rssimg\" maxlength=\"255\" value=\"$rsinfo[2]\"/><br/>";
    echo "Description: <input name=\"rssdsc\"  maxlength=\"255\" value=\"$rsinfo[4]\"/><br/>";
    $forums = mysql_query("SELECT id, name FROM _forums ORDER BY position, id, name");
    echo "Forum: <select name=\"fid\" value=\"$rsinfo[3]\">";
    echo "<option value=\"0\">NO FORUM</option>";
    while ($forum=mysql_fetch_array($forums))
    {
        echo "<option value=\"$forum[0]\">$forum[1]</option>";
    }
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Edit\"/>";
echo "<input type=\"hidden\" name=\"fid\" value=\"$fid\"/>";
echo "<input type=\"hidden\" name=\"rssid\" value=\"$rssid\"/>";
echo "</form>";
    echo "<p align=\"center\">";
        echo "<br/><br/><a href=\"admincp.php?action=manrss\">";
  echo "<img src=\"images/rss.gif\" alt=\"rss\"/>Manage RSS</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////////////////
else if($action=="addgrp")
{
    echo "<div><br/>Add Group</<br/></div>";
echo "<form action=\"admproc.php?action=addgrp\" method=\"post\">";
    echo "Name: <input name=\"ugname\" maxlength=\"30\"/><br/>";
    echo "Auto Assign: <select name=\"ugaa\">";
    echo "<option value=\"1\">Yes</option>";
    echo "<option value=\"0\">No</option>";
    echo "</select><br/>";
    echo "<br/><small><b>For Auto Assign Only</b></small><br/>";
    echo "Allow: <select name=\"allus\">";
    echo "<option value=\"0\">Normal Users</option>";
    echo "<option value=\"1\"$selected>$status1</option>";
    echo "<option value=\"2\"$selected>$status2</option>";
    echo "<option value=\"3\"$selected>$status3</option>";
    echo "<option value=\"4\"$selected>$status4</option>";
    echo "<option value=\"5\"$selected>$status5</option>";
    echo "<option value=\"6\"$selected>$status6</option>";
    echo "<option value=\"7\"$selected>$status7</option>";
    echo "<option value=\"8\"$selected>$status8</option>";
    echo "<option value=\"9\"$selected>$status9</option>";
    echo "<option value=\"10\"$selected>$status10</option>";
    echo "</select><br/>";
    echo "Min Age: ";
    echo "<input name=\"mage\" format=\"*N\" maxlength=\"3\" size=\"3\"/>";
    echo "<br/>Min Posts: ";
    echo "<input name=\"mpst\" format=\"*N\" maxlength=\"3\" size=\"3\"/>";
    echo "<br/>Min Plusses: ";
    echo "<input name=\"mpls\" format=\"*N\" maxlength=\"3\" size=\"3\"/><br/>";
echo "<input type=\"submit\" value=\"Add\"/>";
echo "</form>";
    echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=ugroups\">";
  echo "UGroups</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////


else if($action=="edtfrm")
{
    echo "<div><br/>Edit Forum</<br/></div>";

    $forums = mysql_query("SELECT id,name FROM ibwf_forums ORDER BY position, id, name");
echo "<form action=\"admproc.php?action=edtfrm\" method=\"post\">";
    echo "Forum: <select name=\"fid\">";
    while($forum=mysql_fetch_array($forums))
    {
      echo "<option value=\"$forum[0]\">$forum[1]</option>";
    }
    echo "</select>";
    echo "<br/>Name:<input name=\"frname\" maxlength=\"30\"/><br/>";
    echo "Position: <input name=\"frpos\" format=\"*N\" size=\"3\"  maxlength=\"3\"/><br/>";
    $fcats = mysql_query("SELECT id, name FROM ibwf_fcats ORDER BY position, id, name");
    echo "Category: <select name=\"fcid\">";
    while ($fcat=mysql_fetch_array($fcats))
    {
        echo "<option value=\"$fcat[0]\">$fcat[1]</option>";
    }
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Edit\"/>";
echo "</form>";
    echo "<p align=\"center\">";    
    echo "<br/><br/><a href=\"admincp.php?action=forums\">";
  echo "Forums</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////

else if($action=="delfrm")
{
   echo "<div><br/>Delete Forum</<br/></div>";

    $forums = mysql_query("SELECT id,name FROM ibwf_forums ORDER BY position, id, name");
echo "<form action=\"admproc.php?action=delfrm\" method=\"post\">";
    echo "Forum: <select name=\"fid\">";
    while($forum=mysql_fetch_array($forums))
    {
      echo "<option value=\"$forum[0]\">$forum[1]</option>";
    }
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Delete\"/>";
    echo "</form>";
       echo "<p align=\"center\">"; 
    echo "<br/><br/><a href=\"admincp.php?action=forums\">";
  echo "Forums</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
/////////////////////////////////////
else if($action=="delgrp")
{
 
   echo "<div><br/>Delete UGroup</<br/></div>";

    $forums = mysql_query("SELECT id,name FROM ibwf_groups ORDER BY name, id");
echo "<form action=\"admproc.php?action=delgrp\" method=\"post\">";
    echo "UGroup: <select name=\"ugid\">";
    while($forum=mysql_fetch_array($forums))
    {
      echo "<option value=\"$forum[0]\">$forum[1]</option>";
    }
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Delete\"/>";
echo "</form>";
    echo "<p align=\"center\">";
       echo "<br/><br/><a href=\"admincp.php?action=forums\">";
  echo "Forums</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
/////////////////////////////////
else if($action=="edtcat")
{
     echo "<div><br/>Edit Category</<br/></div>";
    $fcats = mysql_query("SELECT id, name FROM ibwf_fcats ORDER BY position, id, name");
echo "<form action=\"admproc.php?action=edtcat\" method=\"post\">";
    echo "Edit: <select name=\"fcid\">";
    while ($fcat=mysql_fetch_array($fcats))
    {
        echo "<option value=\"$fcat[0]\">$fcat[1]</option>";
    }
    echo "</select><br/>";
    echo "Name: <input name=\"fcname\" maxlength=\"30\"/><br/>";
    echo "Position: <input name=\"fcpos\" format=\"*N\" size=\"3\"  maxlength=\"3\"/><br/>";
echo "<input type=\"submit\" value=\"Edit\"/>";
echo "</form>";
     echo "<p align=\"center\">";   
    echo "<br/><br/><a href=\"admincp.php?action=fcats\">";
  echo "Forum Categories</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////
else if($action=="delcat")
{
    echo "<div><br/>Delete Category</<br/></div>"; 
    $fcats = mysql_query("SELECT id, name FROM ibwf_fcats ORDER BY position, id, name");
echo "<form action=\"admproc.php?action=delcat\" method=\"post\"/>";
    echo "Delete: <select name=\"fcid\">";
    
    while ($fcat=mysql_fetch_array($fcats))
    {
        echo "<option value=\"$fcat[0]\">$fcat[1]</option>";
    }
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Delete\"/>";
    echo "</form>";
     echo "<p align=\"center\">";   
    echo "<br/><br/><a href=\"admincp.php?action=fcats\">";
  echo "Forum Categories</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
/////////////////////////////////user info

else if($action=="chuinfo")
{
    echo "<div><br/>User</<br/></div>";   
    echo "<p align=\"center\">";
    echo "Type user nickname<br/><br/>";
  echo "</p>";
echo "<form action=\"admincp.php?action=acui\" method=\"post\">";
    echo "User: <input name=\"unick\" format=\"*x\" maxlength=\"15\"/><br/>";
echo "<input type=\"submit\" value=\"find\"/>";
echo "</form>";
    echo "<p align=\"center\">";
        echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////////////Change User info

else if($action=="acui")
{
    $unick = $_POST["unick"];
    $tid = getuid_nick($unick);
    if($tid==0)
    {
    echo "<div><br/>Doh!</<br/></div>";
    echo "<p align=\"center\">";
      echo "<img src=\"images/notok.gif\" alt=\"x\"/>User Does Not exist<br/>";
      echo "</p>";
    }else{

    echo "<div><br/>$unick's Info</<br/></div>";
      echo "<p>";
      echo "<a href=\"admincp.php?action=chubi&amp;who=$tid\">&#187;$unick's Profile</a><br/>";
      echo "<a href=\"admincp.php?action=upoints&amp;who=$tid\">&#187;$unick's Points</a><br/>";
      $judg = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_judges WHERE uid='".$tid."'"));
      if($judg[0]>0)
      {
      echo "<a href=\"admproc.php?action=deljdg&amp;who=$tid\">&#187;Remove $unick From Judges List</a><br/>";
      }else{
        echo "<a href=\"admproc.php?action=addjdg&amp;who=$tid\">&#187;Make $unick judge</a><br/>";
      }
      //echo "<a href=\"admincp.php?action=addtog&amp;who=$tid\">&#187;Add  $unick to a group</a><br/>";
      //echo "<a href=\"admincp.php?action=umset&amp;who=$tid\">&#187;$unick's Mod. Settings</a><br/>";
	  echo "<a href=\"admincp.php?action=sure&amp;who=$unick\">&#187;Delete $unick's posts</a><br/>";
      echo "<a href=\"admincp.php?action=sure2&amp;who=$unick\">&#187;Delete $unick</a><br/>";
      echo "<a href=\"lists2.php?action=inb&amp;who=$tid\">&#187;$unick`s Sent Pm`s</a><br/>";
      echo "<a href=\"lists2.php?action=inread&amp;who=$tid\">&#187;$unick`s Inbox</a><br/>";
$staff = mysql_fetch_array(mysql_query("SELECT uid FROM ibwf_staff WHERE uid='".$tid."'"));
$perm = mysql_fetch_array(mysql_query("SELECT hidemyperm FROM ibwf_users WHERE id='".$tid."'"));
if((($perm[0]>0)&&($staff[0]==""))||(($judg[0]>0)&&($staff[0]==""))){
echo "<a href=\"admproc.php?action=addpoints&amp;who=$tid\">&#187;Add $unick Staff Points</a><br/>";
}else if(($perm[0]=="0")&&($staff[0]>0)){
echo "<a href=\"admproc.php?action=delstaff&amp;who=$tid\">&#187;Delete Staff Points</a><br/>";
}
      echo "</p>";
      echo "<p align=\"center\">";
    }
    echo "<a href=\"admincp.php?action=chuinfo\">";
  echo "Users Info</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////////////Sure delete post
else if($action=="sure")
{
    $who = $_GET["who"];
    $unick = $who;
    $tid = getuid_nick($unick);
    if($tid==0)
    {
    echo "<div><br/>Doh!</<br/></div>";
    echo "<p align=\"center\">";
      echo "<img src=\"images/notok.gif\" alt=\"x\"/>User Does Not exist<br/>";
    }else{
    echo "<div><br/>Delete $unick's Posts?</<br/></div>";
    echo "<p align=\"center\">";
echo "<b>Are You Sure You Want To Delete $unick`s posts?</b><br/><br/>";
	  echo "<a href=\"admproc.php?action=delxp&amp;who=$tid\">YES</a><br/><br/>";
      echo "</p>";
      echo "<p align=\"center\">";
    }
    echo "<a href=\"admincp.php?action=chuinfo\">";
  echo "Users Info</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////////////Sure user
else if($action=="sure2")
{
    $who = $_GET["who"];
    $unick = $who;
    $tid = getuid_nick($unick);
    if($tid==0)
    {
    echo "<div><br/>Doh!</<br/></div>";
    echo "<p align=\"center\">";
      echo "<img src=\"images/notok.gif\" alt=\"x\"/>User Does Not exist<br/>";
    }else{
    echo "<div><br/>Delete $unick</<br/></div>";
      echo "<p align=\"center\">";
echo "<b>Are You Sure You Want To Delete $unick?</b>";
      echo "<br/><br/>";
      echo "<a href=\"admproc.php?action=delu&amp;who=$tid\">YES</a><br/><br/>";
      echo "</p>";
      echo "<p align=\"center\">";
    }
    echo "<a href=\"admincp.php?action=chuinfo\">";
  echo "Users Info</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

////////////////////////////////////////////

else if($action=="chubi")
{
    $who = $_GET["who"];
    $unick = getnick_uid($who);
    echo "<div><br/>$unick's Profile Settings</<br/></div>";
    $avat = getavatar($who);
    $ppass = mysql_fetch_array(mysql_query("SELECT ppass FROM ibwf_users WHERE id='".$who."'"));
    $pass = mysql_fetch_array(mysql_query("SELECT pass FROM ibwf_users WHERE id='".$who."'"));
    $email = mysql_fetch_array(mysql_query("SELECT email FROM ibwf_users WHERE id='".$who."'"));
    $site = mysql_fetch_array(mysql_query("SELECT site FROM ibwf_users WHERE id='".$who."'"));
    $bdy = mysql_fetch_array(mysql_query("SELECT birthday FROM ibwf_users WHERE id='".$who."'"));
    $uloc = mysql_fetch_array(mysql_query("SELECT location FROM ibwf_users WHERE id='".$who."'"));
    $usig = mysql_fetch_array(mysql_query("SELECT signature FROM ibwf_users WHERE id='".$who."'"));
    $sx = mysql_fetch_array(mysql_query("SELECT sex FROM ibwf_users WHERE id='".$who."'"));
    $perm = mysql_fetch_array(mysql_query("SELECT hidemyperm FROM ibwf_users WHERE id='".$who."'"));
    $vip = mysql_fetch_array(mysql_query("SELECT vip FROM ibwf_users WHERE id='".$who."'"));
    $noob = mysql_fetch_array(mysql_query("SELECT noob FROM ibwf_users WHERE id='".$who."'"));
    $status = mysql_fetch_array(mysql_query("SELECT status FROM ibwf_users WHERE id='".$who."'"));
    $flag = mysql_fetch_array(mysql_query("SELECT flag FROM ibwf_users WHERE id='".$who."'"));
    $hide = mysql_fetch_array(mysql_query("SELECT hide FROM ibwf_users WHERE id='".$who."'"));
    echo "<p>";
    echo "Pass: $ppass[0]<br/>";
    echo "Pass: $pass[0]<br/>";
    echo "</p>";    
echo "<form action=\"admproc.php?action=uprof&amp;who=$who\" method=\"post\">";
    echo "Nickname: <input name=\"unick\" maxlength=\"30\" value=\"$unick\"/><br/>";
    echo "Status: <input name=\"status\" maxlength=\"100\" value=\"$status[0]\"/><br/>";
    echo "Avatar: <input name=\"savat\" maxlength=\"1000\" value=\"$avat\"/><br/>";
    echo "E-Mail: <input name=\"semail\" maxlength=\"1000\" value=\"$email[0]\"/><br/>";
    echo "Admin Message: <input name=\"usite\" maxlength=\"1000\" value=\"$site[0]\"/><br/>";
    echo "Birthday<small>[YYYY-MM-DD]</small>: <input name=\"ubday\" maxlength=\"50\" value=\"$bdy[0]\"/><br/>";
    echo "Location: <input name=\"uloc\" maxlength=\"1000\" value=\"$uloc[0]\"/><br/>";
    echo "Signature: <input name=\"usig\" maxlength=\"1000\" value=\"$usig[0]\"/><br/>";

    echo "Sex: <select name=\"usex\" value=\"$sx[0]\">";
    echo "<option value=\"M\">Male</option>";
if($sx[0]=="F"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"F\"$selected>Female</option>";
    echo "</select><br/>";

    echo "Privileges: <select name=\"perm\" value=\"$perm[0]\">";
    echo "<option value=\"0\">User</option>";
if($perm[0]=="1"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"1\"$selected>$status1</option>";
if($perm[0]=="2"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"2\"$selected>$status2</option>";
if($perm[0]=="3"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"3\"$selected>$status3</option>";
if($perm[0]=="4"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"4\"$selected>$status4</option>";
if($perm[0]=="5"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"5\"$selected>$status5</option>";
if($perm[0]=="6"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"6\"$selected>$status6</option>";
if($perm[0]=="7"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"7\"$selected>$status7</option>";
if($perm[0]=="8"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"8\"$selected>$status8</option>";
if($perm[0]=="9"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"9\"$selected>$status9</option>";
if($perm[0]=="10"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"10\"$selected>$status10</option>";
    echo "</select><br/>";

    echo "Vip User: <select name=\"vip\" value=\"$vip[0]\">";
    echo "<option value=\"0\">No</option>";
if($vip[0]=="1"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"1\">Yes</option>";
    echo "</select><br/>";

    echo "Noob User: <select name=\"noob\" value=\"$noob[0]\">";
    echo "<option value=\"1\">No</option>";
if($noob[0]=="0"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"0\">Yes</option>";
    echo "</select><br/>";
echo "Invisable: <select name=\"hide\" value=\"$hide[0]\">";
    echo "<option value=\"0\">No</option>";
if($hide[0]=="1"){$selected=" selected=\"selected\"";}else{$selected="";}
    echo "<option value=\"1\">Yes</option>";
    echo "</select><br/>";

echo getflagdd($flag[0]);

echo "<input type=\"submit\" value=\"Update\"/>";
echo "</form>";
   
    echo "<br/><br/>";
echo "<form action=\"admproc.php?action=upwd&amp;who=$who\" method=\"post\">";
    echo "Password: <input name=\"npwd\" format=\"*x\" maxlength=\"15\"/><br/>";
echo "<input type=\"submit\" value=\"Change\"/>";
echo "</form>";
   
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=chuinfo\">";
  echo "Users Info</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
  }
/////////////////////////////////
else if($action=="usergallery")
{
    echo "<div><br/>User Gallery</<br/></div>";
    echo "<p>";
    echo "<a href=\"admincp.php?action=addphoto\">&#187;Add Photo</a><br/>";
    
    echo "</p>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";    
echo getfoot($sid,$folder);
exit();
}
///////////////////////////////////////
else if($action=="addphoto")
{
    echo "<div><br/>Add Photo</<br/></div>";
echo "<form action=\"admproc.php?action=addphoto\" method=\"post\">";  
echo "Username: <input name=\"user\" type=\"text\"/><br/>";
echo "Image URL: <input name=\"imglink\" type=\"text\"/><br/>";
echo "Sex: <select name=\"sex\">";
echo "<option value=\"M\">Male</option>";
echo "<option value=\"F\">Female</option>";
echo "</select>";
echo "<input type=\"submit\" value=\"Add Photo\"/>";
echo "</form>";  
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";    
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////////////here//////////////////////////////////////////
///////////////////////////scramble
else if($action=="addscramble")
{
    echo "<div><br/>Add Scramble Word</<br/></div>";

  echo "<form action=\"admproc.php?action=addscramble\" method=\"post\">";
  echo "Word: <input name=\"word\" maxlength=\"50\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";
    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////////animation add
else if($action=="addani")
{
   echo "<div><br/>Add Animation</<br/></div>";
  echo "<form action=\"admproc.php?action=addani\" method=\"post\">";
  echo "Code: <input name=\"smlcde\" maxlength=\"30\"/><br/>";
  echo "Image Source:<input name=\"smlsrc\" maxlength=\"200\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";
  echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
/////////////////////////////////////spam
else if($action=="addspam")
{
  echo "<div><br/>Add Spam Block</<br/></div>";

  echo "<form action=\"admproc.php?action=addspam\" method=\"post\">";
  echo "Site:<input name=\"smlcde\" maxlength=\"30\"/><br/>";
  echo "Change To:<input name=\"smlsrc\" maxlength=\"200\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";
    echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
///////////////////////////////////////
else if($action=="upoints")
{
    $who = $_GET["who"];
    $unick = getnick_uid($who);
  echo "<div><br/>$unick's Points</<br/></div>";
//lastpnreas
    $lpr = mysql_fetch_array(mysql_query("SELECT lastpnreas FROM ibwf_users WHERE id='".$who."'"));
    $gold = mysql_fetch_array(mysql_query("SELECT gold FROM ibwf_users WHERE id='".$who."'"));
    $plusses = mysql_fetch_array(mysql_query("SELECT plusses FROM ibwf_users WHERE id='".$who."'"));
    $gplus = mysql_fetch_array(mysql_query("SELECT gplus FROM ibwf_users WHERE id='".$who."'"));
    $battlep = mysql_fetch_array(mysql_query("SELECT battlep FROM ibwf_users WHERE id='".$who."'"));
   echo "<p align=\"center\">";
  echo "<b>$unick`s Points!</b><br/></p>";

  echo "</p>";
  echo "<form action=\"admproc.php?action=upoints&amp;who=$who\" method=\"post\">";
  echo "Penalty Reason: <input name=\"lpr\" maxlength=\"255\" value=\"$lpr[0]\"/><br/>";
  echo "Gold: <input name=\"gold\" maxlength=\"15\" value=\"$gold[0]\"/><br/>";
  echo "Plusses: <input name=\"plusses\" maxlength=\"15\" value=\"$plusses[0]\"/><br/>";
  echo "Gp: <input name=\"gplus\" maxlength=\"15\" value=\"$gplus[0]\"/><br/>";
  echo "Bp: <input name=\"battlep\" maxlength=\"15\" value=\"$battlep[0]\"/><br/>";
  echo "<input type=\"submit\" value=\"Update\"/>";
  echo "</form>";

    echo "<br/><br/>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=chuinfo\">";
  echo "Users Info</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}


/////////////////////////////////////Quiz Rooms
else if($action=="quizrooms")
{
  echo "<div><br/>Games Rooms</<br/></div>";
   echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=addquizroom\">&#187;Add Quiz Room</a><br/>";
    $noi = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM quiz_rooms"));
  echo "</p>";
     if($noi[0]>0)
    {
echo "<form action=\"admproc.php?action=delquizroom\" method=\"post\">";
        $rss = mysql_query("SELECT name, id FROM quiz_rooms");
        echo "<br/><select name=\"chrid\">";
        while($rs=mysql_fetch_array($rss))
        {
            echo "<option value=\"$rs[1]\">$rs[0]</option>";
        }
      echo "</select><br/>";
echo "<input type=\"submit\" value=\"Delete\"/>";
echo "</form>";
    echo "<br/>";
    }
   echo "<p align=\"center\">";
    echo "<br/><br/><br/><a href=\"admincp.php?action=addquiz\">";
  echo "Add Question</a><br/>";
    echo "<a href=\"lists.php?action=quiz\">";
  echo "Edit Questions</a><br/>";
    echo "</p>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
///////////////////////////////////
else if($action=="addquizroom")
{
  echo "<div><br/>Add Quiz Room</<br/></div>";
    echo "<form action=\"admproc.php?action=addquizroom\" method=\"post\">";
    echo "Name:<input name=\"chrnm\" maxlength=\"30\"/><br/>";
    echo "Minimum Age:<input name=\"chrage\" format=\"*N\" maxlength=\"3\" size=\"3\"/><br/>";
    echo "Minimum Chat Posts:<input name=\"chrpst\" format=\"*N\" maxlength=\"4\" size=\"4\"/><br/>";
    echo "Permission:<select name=\"chrprm\">";
    echo "<option value=\"0\">Normal</option>";
    echo "<option value=\"1\">Moderators</option>";
    echo "<option value=\"2\">Admins</option>";
    echo "</select><br/>";
    echo "Censored:<select name=\"chrcns\">";
    echo "<option value=\"1\">Yes</option>";
    echo "<option value=\"0\">No</option>";
    echo "</select><br/>";
    echo "Fun:<select name=\"chrfun\">";
    echo "<option value=\"0\">No</option>";
    echo "<option value=\"1\">esreveR</option>";
    echo "<option value=\"2\">UltiBabe</option>";
    echo "</select><br/>";
echo "<input type=\"submit\" value=\"Add\"/>";
    echo "<form>";
    echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=quizrooms\">";
  echo "<img src=\"/smilies/2hmm.gif\" alt=\"chat\"/>Quizrooms</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

////////////////////////////////////////////add quiz words
else if($action=="addquiz")
{
 echo "<div><br/>Add Quiz Question</<br/></div>";
  echo "<form action=\"admproc.php?action=addquiz\" method=\"post\">";
  echo "Question:<input name=\"question\" maxlength=\"250\"/><br/>";
  echo "Answer:<input name=\"answer\" format=\"*x\" maxlength=\"50\"/><br/>";
  echo "Points:<select name=\"points\">";
  echo "<option value=\"10\">10</option>";
  echo "<option value=\"20\">20</option>";
  echo "<option value=\"30\">30</option>";
  echo "</select><br/>";
  echo "<input type=\"submit\" value=\"Update\"/>";
  echo "</form>";
    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"lists.php?action=quiz\">";
  echo "Edit words</a><br/>";
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

////////////////////////////////////////////edit quiz

else if($action=="editquiz")
{
    $smid = $_GET["smid"];
echo "<div><br/>Edit Quiz</<br/></div>";
     $question = mysql_fetch_array(mysql_query("SELECT question FROM quiz WHERE id='".$smid."'"));
    $answer = mysql_fetch_array(mysql_query("SELECT answer FROM quiz WHERE id='".$smid."'"));
    $points = mysql_fetch_array(mysql_query("SELECT points FROM quiz WHERE id='".$smid."'"));



  echo "<form action=\"admproc.php?action=editquiz&amp;smid=$smid\" method=\"post\">";
  echo "Question: <input name=\"question\" maxlength=\"250\"/><br/>";
  echo "Answer: <input name=\"answer\" format=\"*x\" maxlength=\"50\"/><br/>";
  echo "Points: <select name=\"points\" value=\"$points[0]\">";
  echo "<option value=\"10\">10</option>";
if($points[0]=="20"){$selected=" selected=\"selected\"";}else{$selected="";}
  echo "<option value=\"20\"$selected>20</option>";
if($points[0]=="30"){$selected=" selected=\"selected\"";}else{$selected="";}
  echo "<option value=\"30\"$selected>30</option>";
  echo "</select><br/>";
  echo "<input type=\"submit\" value=\"Update\"/>";
  echo "</form>";

    echo "<br/><br/>";
    echo "<p align=\"center\">";
    echo "<a href=\"lists.php?action=quiz\">";
  echo "Quiz Questions</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();    
}

////////////////////////////////////////////edit scramble

else if($action=="editscramble")
{
echo "<div><br/>Edit Scramble</<br/></div>";
    $smid = $_GET["smid"];

     $word = mysql_fetch_array(mysql_query("SELECT word FROM scramble WHERE id='".$smid."'"));


  echo "<form action=\"admproc.php?action=editscramble&amp;smid=$smid\" method=\"post\">";
    echo "Word: <input name=\"word\" format=\"*x\" maxlength=\"50\"/><br/>";
  echo "<input type=\"submit\" value=\"Update\"/>";
  echo "</form>";

    echo "<br/><br/>";
    echo "<p align=\"center\">";
    echo "<a href=\"lists.php?action=scramble\">";
  echo "Scramble Words</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();    
}
///////////////////////////////////////////////
else if($action=="addnews")
{
echo "<div><br/>Add News</<br/></div>";

  echo "<form action=\"admproc.php?action=addnews\" method=\"post\">";
  echo "Title:<input name=\"title\" maxlength=\"100\"/><br/>";
  echo "News:<input name=\"news\" maxlength=\"255\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";
    echo "<p align=\"center\">";
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////////////edit news

else if($action=="editnews")
{
echo "<div><br/>Edit News</<br/></div>";
    $newsid = $_GET["newsid"];

     $news = mysql_fetch_array(mysql_query("SELECT date, news, scode FROM ibwf_news WHERE id='".$newsid."'"));

  echo "<form action=\"admproc.php?action=editnews&amp;newsid=$newsid\" method=\"post\">";
  echo "Title: <input name=\"title\"  maxlength=\"100\"/><br/>";
  echo "News: <input name=\"news\"  maxlength=\"255\"/><br/>";
  echo "Date: <input name=\"date\"  maxlength=\"50\"/><br/>";
  echo "<input type=\"submit\" value=\"Update\"/>";
  echo "</form>";

    echo "<br/><br/>";
     echo "<p align=\"center\">";
    echo "<a href=\"lists2.php?action=news\">";
  echo "News</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////front page link
else if($action=="front")
{
echo "<div><br/>Add Front Page Link</<br/></div>";

  echo "<form action=\"admproc.php?action=front\" method=\"post\">";
  echo "Title:<input name=\"title\" maxlength=\"100\"/><br/>";
  echo "Address:<input name=\"link\" maxlength=\"255\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";
  echo "<p align=\"center\">";
echo "<br/><br/><a href=\"lists2.php?action=front\">";
echo "Front Page Links</a><br/>";
    echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
////////////////////////////////////////////edit front page link

else if($action=="editfront")
{
echo "<div><br/>Edit Link</<br/></div>";
    $lid = $_GET["lid"];

     $news = mysql_fetch_array(mysql_query("SELECT title, link FROM front WHERE id='".$lid."'"));


  echo "<form action=\"admproc.php?action=editfront&amp;lid=$lid\" method=\"post\">";
  echo "Title: <input name=\"title\"  maxlength=\"100\"/><br/>";
  echo "Link: <input name=\"link\"  maxlength=\"255\"/><br/>";
  echo "<input type=\"submit\" value=\"Update\"/>";
  echo "</form>";

    echo "<br/><br/>";
    echo "<p align=\"center\">";
    echo "<a href=\"lists2.php?action=front\">";
  echo "Front Page Links</a><br/>";
    echo "<a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////ban browser
else if($action=="idiots")
{
echo "<div><br/>Ban Browser!</<br/></div>";

  echo "<form action=\"admproc.php?action=idiots\" method=\"post\">";
  echo "Browser:<input name=\"browser\" maxlength=\"255\"/><br/>";
  echo "<input type=\"submit\" value=\"Ban\"/>";
  echo "</form>";
    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
/////////////////////////////////////////add flag
else if($action=="addflag")
{
echo "<div><br/>Add Flag<br/></div>";

  echo "<form action=\"admproc.php?action=addflag\" method=\"post\">";
    echo "Ip 1:<input name=\"ip1\" maxlength=\"10\"/><br/>";
    echo "Ip 2:<input name=\"ip2\" maxlength=\"10\"/><br/>";

echo "Country ";
echo getflagdd();

    echo "Service Provider:<input name=\"isp\" maxlength=\"255\"/><br/>";
  echo "<input type=\"submit\" value=\"Ban\"/>";
  echo "</form>";
    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////////////////////
else if($action=="blocksites")
{
echo "<div><br/>Blocked Sites<br/></div>";
    echo "<p align=\"center\">";
    echo "<a href=\"admincp.php?action=addsite\">Add Site</a><br/>";
    echo "<a href=\"admincp.php?action=viewsite\">View Sites</a><br/>";
    echo "</p>";
    echo "<p align=\"center\">";
  echo "<a href=\"admincp.php?action=admincp\"><img src=\"../images$folder/admn.gif\" alt=\"\"/>$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

else if($action=="addsite")
{
echo "<div><br/>Add Blocked Site<br/></div>";
    echo "Please Enter The Address Of the Site To Block<br/>";
    echo "<form action=\"admproc.php?action=addsite\" method=\"post\">";
    echo "<input name=\"site\"/>";
    echo "<br/><input type=\"Submit\" Name=\"Submit\" Value=\"Block\"></form>";
    echo "<p align=\"center\">";
  echo "<a href=\"admincp.php?action=admincp\"><img src=\"../images$folder/admn.gif\" alt=\"\"/>$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
/////////////////////////////////////
else if($action=="viewsite")
{
echo "<div><br/>View Blocked Sites<br/></div>";
    echo "<p align=\"center\">";
    echo "Currently Blocked Sites Are Listed Below";
    echo "</p><p>";
      $res = mysql_query("SELECT * FROM ibwf_blockedsite");
while ($row = mysql_fetch_array($res)) 
{
   echo $row[1];
   echo " <a href=\"admproc.php?action=delsite&amp;id=$row[0]\">[X]</a>";
   echo "<br/>";
}
    echo "</p>";
    echo "<p align=\"center\">";
  echo "<a href=\"admincp.php?action=admincp\"><img src=\"../images$folder/admn.gif\" alt=\"\"/>$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
//////////////////////////////ban ip
else if($action=="idiotsip")
{
echo "<div><br/>Ban IP!</<br/></div>";

  echo "<form action=\"admproc.php?action=idiotsip\" method=\"post\">";
  echo "IP:<input name=\"ipadd\" maxlength=\"255\"/><br/>";
  echo "<input type=\"submit\" value=\"Ban\"/>";
  echo "</form>";
    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////Themes
else if($action=="editpict")
{
echo "<div><br/>Themes!</<br/></div>";
  echo "<p align=\"center\">";
  echo "Add Fonts<br/>";
  echo "</p>";
  echo "<form action=\"admproc.php?action=fonts\" method=\"post\">";
  echo "Name:<input name=\"name\" maxlength=\"100\"/><br/>";
  echo "Standard Fonts: <select name=\"extra\" value=\"1\">";
  echo "<option value=\"0\">Yes</option>";
  echo "<option value=\"1\">No</option>";
  echo "</select><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";
echo "<form action=\"admproc.php?action=delfont\" method=\"post\">";
    echo "<br/>Font: <select name=\"fid\">";
$fonts = mysql_query("SELECT id, font FROM theme_fonts ORDER BY id");
while ($font=mysql_fetch_array($fonts))
{

echo "<option value=\"$font[0]\">$font[1]</option>";
}
  echo "</select>";
  echo "<input type=\"submit\" value=\"Delete\"/>";
  echo "</form><br/><hr/>";

  echo "<p align=\"center\">";
  echo "Add Background Images<br/>";
  echo "</p>";
  echo "<form action=\"admproc.php?action=bgi\" method=\"post\">";
  echo "Name:<input name=\"name\" maxlength=\"50\" value=\"/backgroundimage/\"/><br/>";
  echo "Url:<input name=\"url\" maxlength=\"200\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";
echo "<form action=\"admproc.php?action=delbgi\" method=\"post\">";
    echo "<br/>Font: <select name=\"bgid\">";
$images = mysql_query("SELECT id, name FROM background_images ORDER BY id");
while ($image=mysql_fetch_array($images))
{

echo "<option value=\"$image[0]\">$image[1]</option>";
}
  echo "</select>";
  echo "<input type=\"submit\" value=\"Delete\"/>";
  echo "</form><br/><hr/>";


  echo "<p align=\"center\">";
  echo "Edit Theme<br/>";
  echo "</p>";
    $folders = mysql_query("SELECT id, name, folder FROM ibwf_folders ORDER BY id");
echo "<form action=\"admincp.php?action=editpict2\" method=\"post\">";
    echo "<br/><br/>Theme: <select name=\"fid\">";
    while ($folder=mysql_fetch_array($folders))
    {
    echo "<option value=\"$folder[0]\">$folder[1]</option>";
    }
  echo "</select>";
  echo "<input type=\"submit\" value=\"Edit\"/>";
  echo "</form><br/><hr/>";
  echo "<p align=\"center\">";
  echo "Add Theme<br/>";
  echo "</p>";
  echo "<form action=\"admproc.php?action=addpict\" method=\"post\">";
  echo "Name:<input name=\"name\" maxlength=\"50\"/><br/>";
  echo "Folder:<input name=\"folder\" maxlength=\"50\"/><br/>";
  echo "Hidden: <select name=\"hide\" value=\"1\">";
  echo "<option value=\"1\">Yes</option>";
  echo "<option value=\"0\">No</option>";
  echo "</select><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";

    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////Themes 2
else if($action=="editpict2")
{
$fid = $_POST["fid"];
echo "<div><br/>Themes!</<br/></div>";
  echo "<p align=\"center\">";
  echo "<br/>Edit Theme <br/>";
  echo "</p>";
  $name = mysql_fetch_array(mysql_query("SELECT name FROM ibwf_folders WHERE id='".$fid."'"));
  $fold = mysql_fetch_array(mysql_query("SELECT folder FROM ibwf_folders WHERE id='".$fid."'"));
  $hide = mysql_fetch_array(mysql_query("SELECT hide FROM ibwf_folders WHERE id='".$fid."'"));
  echo "<form action=\"admproc.php?action=editpict\" method=\"post\">";
  echo "Name:<input name=\"name\" maxlength=\"50\" value=\"$name[0]\"/><br/>";
  echo "Folder:<input name=\"folder\" maxlength=\"50\" value=\"$fold[0]\"/><br/>";
  echo "<input name=\"fid\" type=\"hidden\" value=\"$fid\"/>";
  echo "Hidden: <select name=\"hide\" value=\"0\">";
  echo "<option value=\"0\">No</option>";
if($hide[0]=="1"){$selected=" selected=\"selected\"";}else{$selected="";}
  echo "<option value=\"1\"$selected>Yes</option>";
  echo "</select><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";

    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////Faqs
else if($action=="faqs")
{
  echo "<div><br/>Add Faqs!</<br/></div>";
  echo "<form action=\"admproc.php?action=addfaqs\" method=\"post\">";
  echo "Question:<input name=\"question\" maxlength=\"255\"/><br/>";
  echo "Answer:<input name=\"answer\" maxlength=\"255\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";

    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////Add Monster
else if($action=="addmonster")
{
  echo "<div><br/>Add Monster!</<br/></div>";
  echo "<form action=\"admproc.php?action=addmonster\" method=\"post\">";
  echo "<p>Monster's name:<br/>";
  echo "<input name=\"monstername\"/><br/>";
  echo "Monster's skill points:<br/>";
  echo "<input name=\"skillpts\"/><br/>";
  echo "Skill points gained by players if killed:<br/>";
  echo "<input name=\"killpts\"/><br/>";
  echo "Gold if killed:<br/>";
  echo "<input name=\"goldpts\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";

    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////Delete Monster
else if($action=="delmonster")
{
  echo "<div><br/>Delete Monster!</<br/></div>";
    echo "<p align=\"center\">";
      $selectmonster="SELECT * from km_monsters order by skill ASC";
      
      $selectmonster2=mysql_query($selectmonster) or die("could not select monster");
      $nummonsters=mysql_num_rows($selectmonster2);
      if($nummonsters==0)
      {
	      echo "Their Are No Monsters Currently Created<br/>";
      }else{
      while($selectmonster3=mysql_fetch_array($selectmonster2))
      {
       echo "Monster Name: $selectmonster3[name]<br/>";
       echo "Skill Points: $selectmonster3[skill]<br/>";
       echo "Points If Killed: $selectmonster3[pointsifkilled]<br/>";
       echo "Delete: <a href=\"admproc.php?action=delmonster&amp;mid=$selectmonster3[ID]\">Delete</a><br/><br/>";
      }
  }


  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

/////////////////////////////////ADMIN CP
else if($action=="admincp")
{
  addonline(getuid_sid($sid),"Main Page","");
    echo "<div>";
    echo "<br/>$sta CP<br/>";
    echo "</div>";
    echo "<p align=\"center\">";
    echo getinbox($sid,"index*$action","$sta Cp");
    echo "</p>";
  echo "<p>";
  if(isstatus10(getuid_sid($sid)))
  {
    echo "<a href=\"lists2.php?action=allpms\">&#187;All Pm`s</a><br/>";
    $nrpm = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_private WHERE reported='1'"));
	echo "<a href=\"modcp.php?action=rpm\">&#187;Pr. Messages [$nrpm[0]]</a><br/>";
	$nrps = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_posts WHERE reported='1'"));
    echo "<a href=\"modcp.php?action=rps\">&#187;Posts [$nrps[0]]</a><br/>";
    $nrtp = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_topics WHERE reported='1'"));
    echo "<a href=\"modcp.php?action=rtp\">&#187;Topics [$nrtp[0]]</a><br/>";
	$noi = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM ibwf_vault"));
    echo "<a href=\"lists.php?action=vault\">&#187;Users Vaults [$noi[0]]</a><br/>";
	$nou = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM tusers"));
    echo "<a href=\"lists2.php?action=topu\">&#187;Toplist Users [$nou[0]]</a><hr/>";
    echo "<a href=\"lists2.php?action=admtopics\">&#187;Forum Topics</a><br/>";
    echo "<a href=\"lists2.php?action=admposts\">&#187;Forum Posts</a><br/>";
$not = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM download_topic"));
    echo "<a href=\"lists2.php?action=attop\">&#187;Topic Attachments [$not[0]]</a><br/>";
$nop = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM download_post"));
    echo "<a href=\"lists2.php?action=atpost\">&#187;Post Attachments [$nop[0]]</a><hr/>";
    echo "<a href=\"lists2.php?action=idiots\">&#187;Banned Browsers</a><br/>";
    echo "<a href=\"lists2.php?action=idiotsip\">&#187;Banned IP's</a><br/>";
    echo "<a href=\"lists2.php?action=idiotsinfo\">&#187;Banned Network Info</a><br/>";
	echo "<a href=\"admincp.php?action=proxyblocker\">&#187;Block Proxy IP`s</a><hr/>";
    echo "<a href=\"modxcp.php?action=addbb\">&#187;Add BB Code</a><br/>";
    echo "<a href=\"lists.php?action=bbs\">&#187;Edit BB Codes</a><br/>";
    echo "<a href=\"admincp.php?action=addspam\">&#187;Add Spam Block</a><br/>";
    echo "<a href=\"lists.php?action=spam\">&#187;Edit Spam Block</a><br/>";
    echo "<a href=\"admincp.php?action=blocksites\">&#187;Edit Blocked Sites</a><hr/>";
    echo "<a href=\"admincp.php?action=proxy\">&#187;Proxy Checker</a><br/>";
$nof = mysql_fetch_array(mysql_query("SELECT COUNT(*) FROM fake_users"));
    echo "<a href=\"admincp.php?action=fakeusers\">&#187;Fake Users [$nof[0]]</a><br/>";
    echo "<a href=\"admincp.php?action=general\">&#187;General Settings</a><br/>";
    echo "<a href=\"lists2.php?action=front\">&#187;Front Page Links</a><br/>";
    echo "<a href=\"lists2.php?action=exlinks\">&#187;External Links</a><br/>";
    echo "<a href=\"media.php?action=add\">&#187;Add Radio/Tv</a><br/>";
    echo "<a href=\"admincp.php?action=fcats\">&#187;Forum Categories</a><br/>";
    echo "<a href=\"admincp.php?action=forums\">&#187;Forums</a><br/>";
    echo "<a href=\"admincp.php?action=ugroups\">&#187;User Groups</a><br/>";
    echo "<a href=\"admincp.php?action=addperm\">&#187;Add Permissions</a><br/>";
    echo "<a href=\"admincp.php?action=chuinfo\">&#187;Change User Info</a><br/>";
    echo "<a href=\"admincp.php?action=manrss\">&#187;Manage RSS Sources</a><br/>";
	echo "<a href=\"users/themes.php?\">&#187;Add P.W.S. Theme</a><br/>";
    echo "<a href=\"admincp.php?action=addsml\">&#187;Add Smileys</a><br/>";
    echo "<a href=\"admincp.php?action=addavt\">&#187;Add Avatar</a><br/>";
    echo "<a href=\"admincp.php?action=addflag\">&#187;Add Flag</a><br/>";
    echo "<a href=\"admincp.php?action=chrooms\">&#187;Chatrooms</a><br/>";
    echo "<a href=\"admincp.php?action=editpict\">&#187;Add Site Theme</a><br/>";
   echo "<a href=\"admincp.php?action=addnews\">&#187;Add News</a>";
    echo " &#187; <a href=\"lists2.php?action=news\"> &#187; </a><br/>";
   echo "<a href=\"admincp.php?action=faqs\">&#187;FaQs</a><br/>";
    echo "<a href=\"admincp.php?action=clrdta\">&#187;Clear Data</a><br/>";
    echo "<br/><b>Games</b><br/>";
    echo "<a href=\"admincp.php?action=quizrooms\">&#187;Edit Quiz</a><br/>";
    echo "<a href=\"lists.php?action=scramble\">&#187;Edit Scramble</a><br/>";
    echo "<a href=\"admincp.php?action=addmonster\">&#187;Add Monster</a><br/>";
    echo "<a href=\"admincp.php?action=delmonster\">&#187;Delete Monster</a><br/>";
  }else{
    echo "You are not an Admin";
mysql_query("INSERT INTO ibwf_mlog SET action='hacks', details='<b>".getnick_uid(getuid_sid($sid))."</b> Attempted To Hack Admin(index)', actdt='".time()."'");
  }
echo getfoot($sid,$folder);
exit();
} 

//////////////////////////////proxy
else if($action=="proxy")
{
  echo "<div><br/>Proxy Checker!</<br/></div>";
echo "<font color=\"#008000\"><b>ELITE PROXY</b></font>, ";
echo "<font color=\"#000080\"><b>ANONYMOUS PROXY</b></font>, ";
echo "<font color=\"#D24837\"><b>CODEEN PROXY</b></font>, ";
echo "<font color=\"#996633\"><b>TRANSPARENT PROXY</b></font>, ";
echo "<font color=\"#999999\"><b>BAD PROXY</b></font><br/>";
echo "Max 20 Proxies Per Test ---- Full Proxy Including port number eg: 148.233.159.58:8080<br/>"; 
include("proxy-checker.php");

    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}
else if($action=="proxyblocker")
{
  echo "<div><br/>Proxy Blocker!</<br/></div>";

$text = $_POST["list"];
      echo "<form action=\"admincp.php?action=proxyblocker\" method=\"post\">";
      echo "Ip List: <input name=\"list\"/><br/>";
      echo "<input type=\"submit\" value=\"Update\"/>";
      echo "</form>";
	  $text = str_replace("-"," ",$text);
	  $text = str_replace(":"," ",$text);
$text = preg_replace('/[^0-9. ]/', ' ', $text);
$a = explode(" ",$text);
foreach ($a as $s) { 
$ha = strlen($s);
if($ha>8){
$res = mysql_query("INSERT INTO proxys SET ip='".$s."'");
if($res){
echo "$s Updated<br/>";
}else{
echo "$s Already In Database<br/>";
}
}
}

    echo "<p align=\"center\">";
  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}

//////////////////////////////Fake Users
else if($action=="fakeusers")
{
  echo "<div><br/>Fake Users!</<br/></div>";
    echo "<p align=\"center\">";
 $items = mysql_query("SELECT uid FROM fake_users ORDER BY id");
if(mysql_num_rows($items)>0){
while ($item = mysql_fetch_array($items)){
$whnick = getnick_uid($item[0]);
  echo "$whnick: <a href=\"admproc.php?action=delfakeu&amp;uid=$item[0]\">[X]</a><br/><br/>";
      }
  }
echo "</p><center>";
  echo "<form action=\"admproc.php?action=addfakeu\" method=\"post\">";
  echo "UID: <input name=\"uid\"/><br/>";
  echo "<input type=\"submit\" value=\"Add\"/>";
  echo "</form>";

    echo "</center><p align=\"center\">";

  echo "<br/><br/><a href=\"admincp.php?action=admincp\"><img src=\"images$folder/admn.gif\" alt=\"*\"/>";
  echo "$sta CP</a><br/>";
echo getfoot($sid,$folder);
exit();
}


/////////////////////////////////////////////////
else{
  echo "<div><br/>Doh!<br/></div>";
  echo "<p align=\"center\">";
  echo "I don't know how you got in here, but there's nothing to show<br/><br/>";
mysql_query("INSERT INTO ibwf_mlog SET action='hacks', details='<b>".getnick_uid(getuid_sid($sid))."</b> Attempted To Hack Admincp', actdt='".time()."'");
echo getfoot($sid,$folder);
exit();
}

?>