PageRenderTime 49ms CodeModel.GetById 21ms RepoModel.GetById 0ms app.codeStats 0ms

/dead/announce.php

https://bitbucket.org/nexea/x00n
PHP | 289 lines | 217 code | 61 blank | 11 comment | 85 complexity | 69b79b995ea00356275f8286ba722012 MD5 | raw file
Possible License(s): GPL-2.0
  1. <?php
  2. ob_start("ob_gzhandler");
  3. require_once("include/bittorrent.php");
  4. require_once("include/benc.php");
  5. function err($msg)
  6. {
  7. benc_resp(array("failure reason" => array(type => "string", value => $msg)));
  8. hit_end();
  9. exit();
  10. }
  11. function benc_resp($d)
  12. {
  13. benc_resp_raw(benc(array(type => "dictionary", value => $d)));
  14. }
  15. function benc_resp_raw($x)
  16. {
  17. header("Content-Type: text/plain");
  18. header("Pragma: no-cache");
  19. print($x);
  20. }
  21. foreach (array("passkey","info_hash","peer_id","event","ip", "localip") as $x)
  22. {
  23. if(isset($_GET["$x"]))
  24. $GLOBALS[$x] = "" . $_GET[$x];
  25. }
  26. foreach (array("port","downloaded","uploaded","left") as $x){
  27. $GLOBALS[$x] = 0 + $_GET[$x];
  28. }
  29. if (strpos($passkey, "?")) {
  30. $tmp = substr($passkey, strpos($passkey, "?"));
  31. $passkey = substr($passkey, 0, strpos($passkey, "?"));
  32. $tmpname = substr($tmp, 1, strpos($tmp, "=")-1);
  33. $tmpvalue = substr($tmp, strpos($tmp, "=")+1);
  34. $GLOBALS[$tmpname] = $tmpvalue;
  35. }
  36. foreach (array("passkey","info_hash","peer_id","port","downloaded","uploaded","left") as $x)
  37. if (!isset($x)) err("Missing key: $x");
  38. foreach (array("info_hash","peer_id") as $x)
  39. if (strlen($GLOBALS[$x]) != 20) err("Invalid $x (" . strlen($GLOBALS[$x]) . " - " . urlencode($GLOBALS[$x]) . ")");
  40. if (strlen($passkey) != 32) err("Invalid passkey (" . strlen($passkey) . " - $passkey)");
  41. //if (empty($ip) || !preg_match('/^(d{1,3}.){3}d{1,3}$/s', $ip))
  42. $ip = getip();
  43. $rsize = 50;
  44. foreach(array("num want", "numwant", "num_want") as $k)
  45. {
  46. if (isset($_GET[$k]))
  47. {
  48. $rsize = 0 + $_GET[$k];
  49. break;
  50. }
  51. }
  52. $agent = $_SERVER["HTTP_USER_AGENT"];
  53. // Deny access made with a browser...
  54. if (ereg("^Mozilla\\/", $agent) || ereg("^Opera\\/", $agent) || ereg("^Links ", $agent) || ereg("^Lynx\\/", $agent))
  55. err("torrent not registered with this tracker");
  56. if (!$port || $port > 0xffff)
  57. err("invalid port");
  58. if (!isset($event))
  59. $event = "";
  60. $seeder = ($left == 0) ? "yes" : "no";
  61. dbconn(false);
  62. hit_count();
  63. $valid = @mysql_fetch_row(@mysql_query("SELECT COUNT(*) FROM users WHERE passkey=" . sqlesc($passkey)));
  64. if ($valid[0] != 1) err("Invalid passkey! Re-download the .torrent from $BASEURL");
  65. $res = mysql_query("SELECT id, banned, seeders + leechers AS numpeers, UNIX_TIMESTAMP(added) AS ts FROM torrents WHERE " . hash_where("info_hash", $info_hash)) or err('nog een query');
  66. $torrent = mysql_fetch_assoc($res);
  67. if (!$torrent)
  68. err("torrent not registered with this tracker");
  69. $torrentid = $torrent["id"];
  70. $fields = "seeder, peer_id, ip, port, uploaded, downloaded, userid";
  71. $numpeers = $torrent["numpeers"];
  72. $limit = "";
  73. if ($numpeers > $rsize)
  74. $limit = "ORDER BY RAND() LIMIT $rsize";
  75. $res = mysql_query("SELECT $fields FROM peers WHERE torrent = $torrentid AND connectable = 'yes' $limit") or err('nog iets');
  76. $resp = "d" . benc_str("interval") . "i" . $announce_interval . "e" . benc_str("peers") . "l";
  77. unset($self);
  78. while ($row = mysql_fetch_assoc($res))
  79. {
  80. $row["peer_id"] = hash_pad($row["peer_id"]);
  81. if ($row["peer_id"] === $peer_id)
  82. {
  83. $userid = $row["userid"];
  84. $self = $row;
  85. continue;
  86. }
  87. $resp .= "d" .
  88. benc_str("ip") . benc_str($row["ip"]) .
  89. benc_str("peer id") . benc_str($row["peer_id"]) .
  90. benc_str("port") . "i" . $row["port"] . "e" .
  91. "e";
  92. }
  93. $resp .= "ee";
  94. $selfwhere = "torrent = $torrentid AND " . hash_where("peer_id", $peer_id);
  95. if (!isset($self))
  96. {
  97. $sql = "SELECT $fields FROM peers WHERE $selfwhere";
  98. $res = mysql_query($sql) or err('fout');
  99. $row = mysql_fetch_assoc($res);
  100. if ($row)
  101. {
  102. $userid = $row["userid"];
  103. $self = $row;
  104. }
  105. }
  106. //// Up/down stats ////////////////////////////////////////////////////////////
  107. if (!isset($self))
  108. {
  109. $valid = @mysql_fetch_row(@mysql_query("SELECT COUNT(*) FROM peers WHERE torrent=$torrentid AND passkey=" . sqlesc($passkey))) or err('mistake');
  110. if ($valid[0] >= 1 && $seeder == 'no') err("Connection limit exceeded! You may only leech from one location at a time.");
  111. if ($valid[0] >= 3 && $seeder == 'yes') err("Connection limit exceeded!");
  112. $rz = mysql_query("SELECT id, uploaded, downloaded, class FROM users WHERE passkey=".sqlesc($passkey)." AND enabled = 'yes' ORDER BY last_access DESC LIMIT 1") or err("Tracker error 2");
  113. if ($MEMBERSONLY && mysql_num_rows($rz) == 0)
  114. err("Unknown passkey. Please redownload the torrent from $BASEURL.");
  115. $az = mysql_fetch_assoc($rz);
  116. $userid = $az["id"];
  117. // if ($left > 0 && $az["class"] < UC_VIP)
  118. if ($az["class"] < UC_VIP)
  119. {
  120. $gigs = $az["uploaded"] / (1024*1024*1024);
  121. $elapsed = floor((gmtime() - $torrent["ts"]) / 3600);
  122. $ratio = (($az["downloaded"] > 0) ? ($az["uploaded"] / $az["downloaded"]) : 1);
  123. if ($ratio < 0.5 || $gigs < 5) $wait = 48;
  124. elseif ($ratio < 0.65 || $gigs < 6.5) $wait = 24;
  125. elseif ($ratio < 0.8 || $gigs < 8) $wait = 12;
  126. elseif ($ratio < 0.95 || $gigs < 9.5) $wait = 6;
  127. else $wait = 0;
  128. if ($elapsed < $wait)
  129. err("Not authorized (" . ($wait - $elapsed) . "h) - READ THE FAQ!");
  130. }
  131. }
  132. else
  133. {
  134. $upthis = max(0, $uploaded - $self["uploaded"]);
  135. $downthis = max(0, $downloaded - $self["downloaded"]);
  136. if ($upthis > 0 || $downthis > 0)
  137. mysql_query("UPDATE users SET uploaded = uploaded + $upthis, downloaded = downloaded + $downthis WHERE id=$userid") or err("Tracker error 3");
  138. }
  139. ///////////////////////////////////////////////////////////////////////////////
  140. function portblacklisted($port)
  141. {
  142. // direct connect
  143. if ($port >= 411 && $port <= 413) return true;
  144. // bittorrent
  145. if ($port >= 6881 && $port <= 6889) return true;
  146. // kazaa
  147. if ($port == 1214) return true;
  148. // gnutella
  149. if ($port >= 6346 && $port <= 6347) return true;
  150. // emule
  151. if ($port == 4662) return true;
  152. // winmx
  153. if ($port == 6699) return true;
  154. if ($port == 2706) return true;
  155. return false;
  156. }
  157. $updateset = array();
  158. if ($event == "stopped")
  159. {
  160. if (isset($self))
  161. {
  162. mysql_query("DELETE FROM peers WHERE $selfwhere");
  163. if (mysql_affected_rows())
  164. {
  165. if ($self["seeder"] == "yes")
  166. $updateset[] = "seeders = seeders - 1";
  167. else
  168. $updateset[] = "leechers = leechers - 1";
  169. }
  170. }
  171. }
  172. else
  173. {
  174. if ($event == "completed")
  175. $updateset[] = "times_completed = times_completed + 1";
  176. if (isset($self))
  177. {
  178. mysql_query("UPDATE peers SET uploaded = $uploaded, downloaded = $downloaded, to_go = $left, last_action = NOW(), seeder = '$seeder'"
  179. . ($seeder == "yes" && $self["seeder"] != $seeder ? ", finishedat = " . time() : "") . " WHERE $selfwhere");
  180. if (mysql_affected_rows() && $self["seeder"] != $seeder)
  181. {
  182. if ($seeder == "yes")
  183. {
  184. $updateset[] = "seeders = seeders + 1";
  185. $updateset[] = "leechers = leechers - 1";
  186. }
  187. else
  188. {
  189. $updateset[] = "seeders = seeders - 1";
  190. $updateset[] = "leechers = leechers + 1";
  191. }
  192. }
  193. }
  194. else
  195. {
  196. if (portblacklisted($port))
  197. err("Port $port is blacklisted.");
  198. else
  199. {
  200. $sockres = @fsockopen($ip, $port, $errno, $errstr, 5);
  201. if (!$sockres)
  202. $connectable = "no";
  203. else
  204. {
  205. $connectable = "yes";
  206. @fclose($sockres);
  207. }
  208. }
  209. $ret = mysql_query("INSERT INTO peers (connectable, torrent, peer_id, ip, port, uploaded, downloaded, to_go, started, last_action, seeder, userid, agent, uploadoffset, downloadoffset, passkey) VALUES ('$connectable', $torrentid, " . sqlesc($peer_id) . ", " . sqlesc($ip) . ", $port, $uploaded, $downloaded, $left, NOW(), NOW(), '$seeder', $userid, " . sqlesc($agent) . ", $uploaded, $downloaded, " . sqlesc($passkey) . ")") or err('tracker error');
  210. if ($ret)
  211. {
  212. if ($seeder == "yes")
  213. $updateset[] = "seeders = seeders + 1";
  214. else
  215. $updateset[] = "leechers = leechers + 1";
  216. }
  217. }
  218. }
  219. if ($seeder == "yes")
  220. {
  221. if ($torrent["banned"] != "yes")
  222. $updateset[] = "visible = 'yes'";
  223. $updateset[] = "last_action = NOW()";
  224. }
  225. if (count($updateset))
  226. mysql_query("UPDATE torrents SET " . join(",", $updateset) . " WHERE id = $torrentid");
  227. benc_resp_raw($resp);
  228. ?>