PDA

View Full Version : Total Admin Security...


Chris M
07-05-2002, 10:00 PM
Ive always hated the fact that other Admins can delete your account...

Its not that they are untrustworthy, but people could get hold of their password or what have you...

So...

There is an easy way to ensure that they cannot change your password, demote you, or delete you...

Just use this hack below, and then they cant!!!

Just remember to change every occurance of X to your userid...

Also : I have posted 2 screenshots...

Other Related Hacks:

More Admin Security - Protect Templates, Templatesets and Styles!!! (https://vborg.vbsupport.ru/showthread.php?s=&threadid=44764)

Satan

Chris M
07-06-2002, 01:26 PM
This one was designed so that Nobody, not even yourself, could delete your user...

Just incase anybody gets hold of your password:)

Satan

Chris M
07-06-2002, 01:28 PM
This is not like my Profile Restricting Hack...

This will not allow them to Update any information about you...

They can still view your profile, but they cannot demote you, or change your password at all...

To do that, they would need to update your information, and this restricts it totally to just you...

Satan

g-force2k2
07-06-2002, 01:33 PM
It looks good hellsatan :) only thing i can say is that it won't help if they have your password ;\ cause they can then update your account and change your usergroup... i've been hacked before and they didn't delete any of the admins only moved them to the banned group and then damaged the forum :p

g-force2k2

Chris M
07-06-2002, 01:41 PM
Precisely...

Im not offering protection against them having your password:)

This simply prevents others from updating or deleting you...i.e. If a hacker gets in to one of the other accounts, you are totally secure...

You can, of course, protect other parts of the CP, like Templates, to just yourself...

Satan

Neo
07-06-2002, 05:41 PM
Nice man, But I would have to say a hack like limit admin abilitys would be better. Like if you didnt want them to have access to forum editing but having access to template editing. That might be cool... I might make that Oo (So many hacks to make)

Chris M
07-06-2002, 05:54 PM
Thats easy...

Ive already done it at our forums:)

I'll post that up if you'd like...

Satan

TECK
07-06-2002, 05:54 PM
another way of doing this could be:
forum/admin/config.php
add at the bottom:// user can edit admins
$editadmin='1';you can add as many users you want there...

forum/admin/user.php
find:adminlog(iif($userid!=0,"user id = $userid",""));below this add:unset($editadmin);
find:if ($HTTP_POST_VARS['action']=="doupdate") {
replace it with:if ($HTTP_POST_VARS['action']=="doupdate" && checklogperms($editadmin,1,"<p>You are not allowed to edit this user.</p>")) {let me know what you think.

Chris M
07-06-2002, 05:58 PM
Hmm...

I'll test that...

If it works, I'll add it to the file (if you dont mind), as an optional extra...

My way still allows them to view your profile, but they cannot delete or modify you...

Your way they can still delete you...

Satan

TECK
07-06-2002, 06:04 PM
np. :)
let me know. the code will stop of doing something 'fancy' to your collegues admins if you are not on the config.php list. that includes password or anything else.

Chris M
07-06-2002, 06:07 PM
Yeh...

One problem...

I did what you said, and my userid is 1...

I get this :

You are not allowed to edit this user.

Satan

ZiRu$
07-06-2002, 06:29 PM
it would be cool if you got a e-mail if they tried anything

TECK
07-06-2002, 06:36 PM
hmm ur right. i also tried:if ($HTTP_POST_VARS['action']=="doupdate" && checklogperms($editadmin,1,"<p>You are not allowed to edit this user.</p>")) { but it doesnt work. anyone can tell me why? it should work.

Chris M
07-06-2002, 06:43 PM
Im not exactly sure...

Its kinda weird...

Satan

g-force2k2
07-06-2002, 06:44 PM
maybe get rid of the $HTTP_POST_VARS and just make it

if ($action=="doupdate" && checklogperms($editadmin,1,"<p>You are not allowed to edit this user.</p>")) {

how about that?

g-force2k2

Chris M
07-06-2002, 06:46 PM
I think that would cause a Parse Error...

Satan

g-force2k2
07-06-2002, 06:50 PM
Originally posted by hellsatan
I think that would cause a Parse Error...

Satan

how would that cause a parse error ;) ?

Edit: Nakkid if that doesn't work try place the:

unset($editadmin);

above:

require("./global.php");

g-force2k2

TECK
07-06-2002, 06:59 PM
it doesnt really matter where you unset the editadmin, as long you do it before the doupdate action. there is something else we all miss. firefly? any hot coder can explain to me? thanks.

update:
is fixed... :)
https://vborg.vbsupport.ru/showthread.php?s=&threadid=40787

GrayFOX
07-06-2002, 07:21 PM
<font color="009999">
Hi,
I need help by this Hack, how can I find out my Admin User ID?

THX
</font>

TECK
07-06-2002, 07:25 PM
mouse over your user link. it will show as userid=x

Chris M
07-06-2002, 07:40 PM
GrayFOX - If you setup the vBulletin board (installed it), you will always be userid 1...

Satan

g-force2k2
07-06-2002, 07:45 PM
Only thing i can think of is that the adminlog variables are global or something while the editadmin isn't ;\ but you can always approach it by defining the editadmin right in the admin/user.php

g-force2k2

Chris M
07-06-2002, 07:50 PM
Yeh you could try that...

Maybe I will in just a few secs:)

Satan

g-force2k2
07-06-2002, 07:52 PM
I know it works because i believe that is the same way that PPN used to setup the permissions for viewing the private messages hack :p

g-force2k2

TECK
07-06-2002, 07:55 PM
i open a new thread related to this issue here:
https://vborg.vbsupport.ru/showthread.php?s=&threadid=40751

bonnmac
07-06-2002, 08:40 PM
Great hack. Thanks.. Just one question... Can they still ban you?

Chris M
07-06-2002, 08:55 PM
No bonnmac - They cant...That would require Updating your status, and this blocks them from doing so...

And folks : If there was ever a Time I was grateful for my own hack, it is now...

We just got hacked by our rogue webmaster, who tried to delete my account (userid = 1) 11 times...

Satan

Marshalus
07-07-2002, 08:31 AM
Nice timing ;) for you and me. I just today realized I should get something like this, and along come the hack :D

Chris M
07-07-2002, 09:44 AM
Yeh lol...

I dont know why I didnt have the idea before...;)

Satan

Jux
07-10-2002, 07:59 PM
A nice addition, especially since I'm about to can one our admins.

E
07-13-2002, 05:02 AM
does it strop them from being able to ban u?

chr@nox
07-13-2002, 01:38 PM
w000t GREAT concept buddy!

this one together with .Htaccess+iprestriction on your admin cp ;)
the perfect security available
hehe
thanx alot for this nice one :)

Originally posted by E
does it strop them from being able to ban u?

that was answerred like a few posts back ;)
yes it does

Chris M
07-15-2002, 01:36 PM
Ya...

It stops you from being Banned, cos they cannot update your account...

Satan

clouds_kid
07-16-2002, 06:50 AM
Man that's pretty sexy. I'm defianetly going to install this one.

Chris M
07-17-2002, 05:05 PM
Lol...

This was quite popular!:eek::p

Never expected that...:)

Satan

Chris M
07-24-2002, 08:54 PM
Oh yeh - If anyone wants me to send them a script on how to protect other files, just ask;)

Satan

asweetdeal
07-31-2002, 11:12 AM
Great Hack! However, if the hacker gets your password... like what happened to me... is there a way to add another admin to be able to edit you?

Chris M
07-31-2002, 01:03 PM
Sure...

Just find :
if (($userid==X) and ($bbuserinfo[userid]!=X)) {

and change it to :
if (($userid==X) and ($bbuserinfo[userid]!=X and $bbuserinfo[userid]!=Y)) {
Replace X with your userid, and Y with the second Admin account...

Satan

GeOrGe
08-12-2002, 12:08 AM
wow men thats cool...

I like this one.

neocorteqz
08-31-2002, 04:07 AM
Nevermind Answered my own question.
This is a sweet hack.
Thanks.

Chris M
08-31-2002, 01:50 PM
No problems;)

Its good to know that other people still use this:) It has been a godsend at 3 forums where I have Administrated...One of them was recently hacked, and only the unprotected Admin account was deleted...Luckily, they werent very vB capable, and I took control back in a matter of minutes...

Satan

410
09-09-2002, 03:18 PM
how do i add multiple users but not ALL Admins? and i tried just one user and I could still edit it...?

Chris M
09-09-2002, 04:41 PM
Just copy the same code underneath the previous code, and change the userid's to match who you want to be protected:)

Satan

Sengir
10-12-2002, 02:13 PM
So sweet :) I was looking for one like this :)

a43079
10-12-2002, 02:23 PM
is there a way to keep them from updating or messing with the templates and styles

Bison
10-12-2002, 02:31 PM
Well ... a timely backup of your database (Downloaded Locally) will also help with this type of vandalism too ... Don't forget that as well!

Chris M
10-12-2002, 02:33 PM
Yes there is a way...

I shall post it up later tonight:)

Satan

a43079
10-12-2002, 02:40 PM
Originally posted by hellsatan
Yes there is a way...

I shall post it up later tonight:)

Satan

thank you that is one of my worries...

Chris M
10-12-2002, 02:54 PM
It was one of mine too:)

Satan

Sengir
10-12-2002, 03:12 PM
heh Lots of worries :)

Chris M
10-12-2002, 03:19 PM
I am very security conscious:D

Satan

Sengir
10-12-2002, 03:31 PM
Me too. Especially after having other admins do things that they were obviously not supposed to do.. (like give an ex-clanmember access to all private/public forums) And I've always been worried about someone deleting or changing my account. (Had a seperate group+account named "_" just in case someone decided to do so..) I can delete that now.. Thanks :)

Chris M
10-12-2002, 03:49 PM
:)

Satan

GoTTi
10-14-2002, 10:13 PM
how can i add other admins to be protected besides myself?

neocorteqz
10-16-2002, 03:24 AM
Originally posted by Da_GoTTi
how can i add other admins to be protected besides myself?


add the lines again, only change the id Number, thats what i did.


if (($userid==X) and ($bbuserinfo[userid]!=X)) {
echo "<p>You cannot update this Admin.</p>";
cpfooter();
exit;
}


and


if ($userid==X) {
echo "<p>You cannot delete this Admin.</p>";
cpfooter();
exit;
}


remember to change X to the user Id you want to protect.

a43079
10-17-2002, 08:30 AM
when are you going to release the protection for the templates and styles

Chris M
10-19-2002, 06:05 PM
@a43079 - Right now:)

Gimme a few minutes to write up the instructions:)

Satan

Graphics
10-19-2002, 06:20 PM
i didn't read the whole thread but is there a way to put 2 admins instead of 1?

Chris M
10-19-2002, 06:22 PM
How do you mean?

a.) Protect more than one admin...
b.) Allow more than one admin to edit a user...

Satan

Graphics
10-19-2002, 06:26 PM
protect more than one admin.

Chris M
10-19-2002, 06:30 PM
Just copy the code again below the first set of code, making sure that you change the ids;)

Satan

Chris M
10-19-2002, 06:33 PM
More Admin Security - Protect Templates, Templatesets and Styles!!! (https://vborg.vbsupport.ru/showthread.php?s=&threadid=44764)

^ That is the Template & Style Protection hack;)

Satan

Yzer0
12-05-2002, 03:56 PM
Is there a way you can simply stop anyone but me to mess with the forum permissions? (I'm a php coder, but its hard to understand vbulletin sometimes)

Thanks in advance

Chris M
12-15-2002, 08:06 PM
Yes there is:)

Open admin/forumpermission.php

Under the "require global.php" bit, add:

if ($bbuserinfo[userid]!="x") {
echo"<p>You cannot perform this function!</p>";
exit;
}

Change "x" to your userid:)

Satan

Bison
12-19-2002, 06:36 PM
What would make this hack even more secure is if you could make the ip address range of the login user an added *Condition* that disallows the user to remove anyone from the Admin list ... other than the TOP Admin (Who IP Falls inside a Range).

Example:

-------DO NOT COPY THIS LINE-------

if ($userid==X) and ($bbuserinfo[userid]!=X and ($bbuserinfo[ipaddress]!= [IP RANGE OF THE ADMIN]) {
echo "<p>You cannot update this Admin.</p>";
cpfooter();
exit;
}

-------DO NOT COPY THIS LINE-------

Also if you could capture the IP of the logged in user, and make a match of the one that the ADMIN assigned, this would give a lot more security than what's included in this hack.

From what I see and what someone already mentioned ... all they need is you password ... this would stop anyone with your password from making changes.

Your opinions ...

Chris M
12-19-2002, 11:03 PM
Sounds good;)

The logged in user's IP would be $bbuserinfo[ipaddress];)

How would you do a range?

You can't just put $user[ipaddress] as the IP Range, as you may not have a static Ip:confused:

Satan

Bison
12-20-2002, 01:35 AM
Under the user profile, you could enter any IP addy and use that as the number to test against the logged in users IP addy.

Abou the range theory, you can convert the ip address into string, and account for the numbers from the first, and second dot in the ip address.

Your isp usually change the last (dot) group of numbers more often.

Another solution would be to grab the ADMIN (IP's) from the database and check the logged in user's ip against those numbers...

sorta like querying that table from the user table and throwing the numbers into an array and test the logged in users ip against the numbers in that table.

Chris M
12-20-2002, 08:16 AM
@Rolodex - But you wouldn't be able to edit the user if your IP wasn't right...

But unfortunately, I forgot to mention that if you had tried to login with the Admin's account, it would update the IP anyway;)

Could you show me what you mean in code form?
Abou the range theory, you can convert the ip address into string, and account for the numbers from the first, and second dot in the ip address.

The other solution would be stumped by the same one as my idea:(

Satan

Bison
12-20-2002, 09:52 PM
From PHP coding perspective, I can't

But from a logical perspective ... I can.

Say that its a given ... that part of your IP address never changes.

[your IP Address]
24.48.xxx.xxx

Store (hard code) that value into a variable: $admin1_ip = 2448
(The Admin_ip is stored into the php code so that it's out of view from the admin CP, and undetected.)

Now you can use these numbers to match the first part of the logged in user's IP address.

Now Capture the IP address of the logged in user:

[logged in user]
198.56.xxx.xxx

Remove everything after the second dot (198.56) and Strip the dots from the IP address (19856).

$temp = $bbuserinfo[ipaddress] (current logged in admin);

$admin2_ip = $temp

$admin_ip2 = 19856

if (userid=1 AND ($Admin2_ip == $Admin1_ip)){

If there's a match, and the other conditions are true,

--- > DO action.
else
----> The action is dis-allowed.

This method is sorta like one of the hacks I saw on this board that disallowed
anyone from accessing the admin CP ... while a certain file was stored on the
server, but this method still allows the "real admin" to make changes to his/her profile.

Chris M
12-21-2002, 05:35 AM
Thats one of my hacks;)

And if you have both hacks installed, there is no way they can access the Admin CP without access to the Server;)

(When the file is uploaded, your account cannot access the server;))

^^ Sounds like a good idea;)

How would you strip that data of the dots and restrict it to just the first 2 parts?:confused:

Other than that, it's doable:)

Satan

Bison
12-21-2002, 05:16 PM
I don't know how it's done in PHP but I believe that you can take the value stored inside the variable [ip address] and count over before the first dot [doing a string_copy] and take those (3) numbers and store them into a temp variable (temp1).

Next, do the same procedure on the [ipaddress] variable, but this time capture the next set of numbers you want to keep by doing another [string_copy] ... store them into another temp variable (temp2).

Then join the two variables ($temp1 and $temp2) and store them into $admin2_ip ... I can do this in perl but I don't know how it's done in PHP.

Maybe someone here can tell us how to perform this in PHP?

Chris M
12-21-2002, 06:22 PM
:confused:

Chen? Where are you when we need you!:D

Satan

Bison
12-22-2002, 01:03 AM
TECK seems to have a good developer mind himself ... you might want to ask him for his advice on this ...

Chris M
12-22-2002, 10:52 AM
I shall actually;)

I'll get back to you with either an answer or a different way of doing it;)

Satan

Zelda-King
01-14-2003, 03:20 PM
An excellent little hack! It works great and yet I can still update myself no problem (Tested on vB 2.2.9). Well done!

Chris M
01-17-2003, 04:57 PM
Thanks:)

Glad you liked it:D

Satan

LangTuDaTinh
04-18-2003, 07:37 AM

KelteN
04-18-2003, 08:19 AM
Nice Hack! Its a good idea :)

sonic3d
05-01-2003, 02:22 PM
installed. works flawlessly

l8er
sonic

Chris M
05-01-2003, 03:32 PM
Im glad!:)

Satan