<?PHP
$item = $_REQUEST["item"];
$fromnum = $_REQUEST["fromnum"];
$extid = $_REQUEST["extid"];
$mobio_remote_addr = "194.12.244.114";
$servID = 1111;
$db_serv = '77.78.162.132';
$db_user = 'sa';
$db_pass = 'sql pass';
$db_name = 'MuOnline';
$credits_to_add = '500';
if($_SERVER['REMOTE_ADDR'] == $mobio_remote_addr) {
$sms_reply = 'Greshka. Spazvaite to4no instrukciite';
$conn = mssql_connect($db_serv, $db_user, $db_pass);
if($conn) {
mssql_select_db($db_name);
$res = mssql_query("SELECT credits FROM MEMB_CREDITS WHERE memb___id='$item'");
if(mssql_num_rows($res)>0) {
mssql_query("UPDATE MEMB_CREDITS SET credits=credits+'$credits_to_add' WHERE memb___id='$item'");
}else{
mssql_query("INSERT INTO MEMB_CREDITS (memb___id, credits) VALUES('$item', '$credits_to_add')");
}
$sms = mssql_fetch_row(mssql_query("SELECT count(*) memb___id FROM sms_ranking WHERE memb___id='$item'"));
if($sms[0] == 0) { mssql_query("INSERT INTO sms_ranking (memb___id, sms_count) VALUES('$item', '1')"); }
else { mssql_query("UPDATE sms_ranking SET sms_count=sms_count+1 WHERE memb___id='$item'"); }
$res = mssql_query("SELECT credits FROM MEMB_CREDITS WHERE memb___id='$item'");
if(mssql_num_rows($res)>0) {
$row = mssql_fetch_row($res);
$sms_reply = "Vashite krediti sa uspeshno zakupeni. Imate {$row[0]} crediti.";
}
}
file("http://mobio.bg/paynotify/pnsendsms.php?servID=$servID&tonum=$fromnum&extid=$extid&message=".urlencode($sms_reply));
}
?>