![]() |
Here's my version:
In sessions.php find this code: Code:
if (md5($loginpassword)!=$bbuserinfo[password]) { Code:
$ipaddress=iif(getenv("REMOTE_ADDR")!="",getenv("REMOTE_ADDR"),$HTTP_HOST); Quote:
Have fun. :) |
Thanks flyfire :)
|
just installed and tested fine :)
be interesting to see how many people are sneaking around, the admin cp :) |
Lesane, it's FireFly, not FlyFire. ;) :p
Thanks. Just a note, if you test this and don't get an e-mail after 3 seconds, don't panic and scream it's not working. It probably takes a while for the e-mail to arrive. :) |
IS that possible use this code for admin centre? how? thanks
Code:
$ipaddress=iif(getenv("REMOTE_ADDR")!="",getenv("REMOTE_ADDR"),$HTTP_HOST); |
[QUOTE]Originally posted by FireFly
Lesane, it's FireFly, not FlyFire. ;) :p Thanks. |
It's great and working now.
Thank you, FireFly. :D :D |
THANX!! Great HACK!
|
Another good one, Firefly! :)
|
Excellent hack!!!
thanks firefly! |
oh~~thankz FireFly:D
this hack is my looking for~~ |
Nice hack firefly :).
|
hmm it dont works for me.
btw what to do if u get the email with that message. :D |
Many thanks Chen, yet again a great bit of work. :)
[QUOTE]Originally posted by -=dm=- btw what to do if u get the email with that message. :D |
very funny :D :D :D
man Im seriouse what to do? (actually there is nothing u can do) |
Hopefully with the IP, you can trace it to one of your members and ask them what's up. If the IP doesn't belong to a current member, and it happens more than once, you should consider banning that IP from the board. I would personally take it one step further and block that IP out of the entire site by doing a deny from statement in the .htaccess file. :)
|
I've made a slight modification to this hack, so that the email also includes not only the IP name, but the host name as well.
This is the code to add: Code:
$ipaddress=iif(getenv("REMOTE_ADDR")!="",getenv("REMOTE_ADDR"),$HTTP_HOST); |
Great hack.. ^^
But i just have my whole admin folder password protected... So i dont think this would help me... >_< -Syphin |
if ya got htaccess installed this wouldnt do much good would it? or does this send the info upon them entering username and a pw or if they try to access it period i use htaccess to protect my directory
|
Works great! Thanks FlyingFlea! :D
|
goooooooooood idea :) but here is my problem :) : the mailing function is not supported by my host so I had to desactivate it...
Can it send adminitrators PMs instead of emails? thx :) |
Excellent hack for my board. People always trying to get get into my admin panel.
|
[QUOTE]Originally posted by Mincer
Run around your office screaming, grab your nearest workmate, shake them by the shoulders and shout "They're after us, we're DOOOOOOOMED!!!!" :eek: :eek: |
Great hack FireFly, just what I needed !
|
I seem be experienceing what you may call a 'minor problem' with this hack in the updated form. (I have reverted back to the original release now)
If someone tries to login as another user with any password, it rejects it, but I get no email. If I try to log in as the admin WITH ANY PASSWORD, IT LETS ME IN!!! :eek: (I do get the email saying failed lonin though. :confused: ) Just thought it's let you know before I start hacking all ya boards. :eek: ;) (j/k) |
I tried to duplicate Mincer's problems.
I tried to login to the admin cp using my name and an incorrect password. I was not successful; I got the wrong password message, and received the email from this hack. So I could not duplicate that aspect of Mincer's problem. I tried to login as a regular member with that member's correct password, and was simply rejected (the login form reappeared). I received no email from that attempt. So I was able to duplicate this aspect of Mincer's complaint; however, I do not believe this is a problem. I don't believe this hack was designed to send you the email in this situation, although an argument could be made that perhaps it should. |
I also tried some bogus usernames that did not exist. I got no email. Tried using my username with a bad password, and was notified promptly.
I think it would be better suited for this hack to send ANY information regarding failed logon attempts to the admin CP. Is it possible to make that happen? |
So I'm assuming it looks like this?
Code:
if (md5($loginpassword)!=$bbuserinfo[password]) { |
Admin login with incorrect password let me in as well, although I also got the warning email...
Reverted (for now). |
I'd forgotten to include
eval("standarderror(\"".gettemplate("error_wrongpa ssword")."\");"); at the end, re-added it and now I am not logged in with a wrong password... |
Nice hack, quick and easy too :D
|
It works GREAT! Thanks!
|
Kathy, can you explain what effects of the code that you added please.
Thanks. |
This hack should be incorporated into the next version of vBulletin Chen. Please pass the request along to John. This is real nice.
Thank You. |
Erf erf can i ask again ?
Could it send PM to administrator instead of emails as the mail function doesn't work on my server? |
[QUOTE]Originally posted by Baratator
Erf erf can i ask again ? Could it send PM to administrator instead of emails as the mail function doesn't work on my server? |
I have to say that I like the email function, because it also gets passed along to my pager, and I know about it almost instantly.
I would still like to point out that I would like to see it send me a notification on ANY bad attempt to gain access to my Admin CP. Is it possible to make that happen??? |
cheers ears great hack
|
[QUOTE]Originally posted by Baratator
Erf erf can i ask again ? Could it send PM to administrator instead of emails as the mail function doesn't work on my server? |
i had a problem, when i use the right password, he sends the email too! what do i wrong?
|
All times are GMT. The time now is 10:33 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|