function buyzen() {
$zen = "500000000";
$credits = "100";
$zenformat = number_format($zen);
$account = secure($_SESSION['user']);
check_inject();
$query = mssql_query("Select * from MEMB_INFO where memb___id='$account'");
$row = mssql_fetch_assoc($query);
$status = mssql_num_rows(mssql_query("Select * from MEMB_STAT where memb___id='$account' and connectstat='1'"));
if(empty($account)) { echo"<b>Error:</b> Please Log In!"; $error=1; }
else{
if($row['credits'] < $credits) { echo "<font color='red'>You do not enough credits.</font><br>"; $error=1; }
if($status != 0) { echo "<font color='red'>Please logout before buy zen.</font><br>"; $error=1; }
}
if($error != 1) {
mssql_query("UPDATE warehouse set Money=Money+'$zen' where AccountID='$account'");
mssql_query("UPDATE MEMB_INFO set credits=credits-'$credits' where memb___id='$account'");
echo "<font color='green'>You successfully bought $zenformat zen.</font>";
}}