![]() |
Admin Protection
I couldent find anything like this, even if it is so simple, anywhere on here so i decided to make it myself..
Description: Checks IP of moderator or administrator before allowing access to mod/admincp or editing threads. Requires mods to functions_login.php,postings.php,inlinemod.php, txt file named ippool.txt in forum root directory,apparse.php uploaded to forum root,ipauth.php uploaded to forum root. Instructions for install: 1.download attachments 2.open adminprotection.php and edit the variables to their correct settings. 3.upload ipauth.php,apparse.php,adminprotection.php,ippool. txt to forum root 4.find.. Code:
// admin control panel or upgrade script login Code:
//admin protection Code:
if ($logintype === 'modcplogin') Code:
//admin protection Code:
switch ($_REQUEST['do']) Code:
//admin protection Code:
switch ($_POST['do']) Code:
//admin protection Code:
switch ($_POST['do']) Code:
case 'open': 9. visit http://yoursite.com/ipauth.php and enter your ip and click submit 10. repeat for all admins/moderators on your forum 11. you're finished! *note this hack does not work with a dynamic ip yet, i plan to add it later on. Future Mods: Switch to MySQL table,Support for DSL/dialup IPs,Save to database on all unauthorized logins |
You know IPs can be spoofed, right? ;)
|
I've unfortunately had to remove the attachment for the time being..
Hopefully the author can make some necessary adjustments to the installation, and it can be re-uploaded again shortly. |
all fixed, organized the code alot better too =) Now will send email/log to file when unauthorized user tries to login.
|
Thanks for the quick fix-me-up cerjam, it is much appreciated. :)
|
And if my PC breakes donw?huh?
|
I suppose you have never tried to login at more tham one PC. HMM not sure this is such a good Idea. Unless you have a static IP this is not good.
|
Quote:
I'm not coming back into this thread so don't waist your time. Good work cerjam by the way :banana: |
Quote:
Well then i suppose you can just got right back into ipauth.php and add your new ip :idea: one a side note it would be a pain in the butt for dial up folks, does this support wildcards? |
Quote:
|
Quote:
|
Very useful mod, prevents the security of your entire forum from relying on all of your moderator/admin passwords.
Nice work *installed* |
ick, i woke up to a inbox full of 'unauthorized login' emails, i misplaced the code in functions_login.php, check original post for fix.
|
Good job on that!
/me installs |
prevents you from logging on elsewhere
|
No? What do you think ipauth.php is for? lets you add another ip to the ippool. and it doesnt support wildcards yet, i use dialup myself and it really isnt a hassle adding my ip everytime i reconnect, but then again i stay online for 3-4 days at a time >.>
|
I'm using .htaccess for extra protection, but I don't see how this couldn't work.
|
Parse error: syntax error, unexpected T_INCLUDE, expecting T_CASE or T_DEFAULT or '}' in /home/epirate/public_html/forums/inlinemod.php on line 93
Code:
switch ($_POST['do']) |
8. CHMOD apparse and adminprotection.php to 777
DO NOT DO THIS.. if you have someone THINKING bout or ATTEMPTING to hack your forum.. i recently had a member use the 777 to his own advantage and save blank adminprotection.php and apparse files to my ftp in an attempt to gain access to my admincp.. |
All times are GMT. The time now is 06:18 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|