Go Back   vb.org Archive > Community Discussions > Modification Requests/Questions (Unpaid)
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 10-17-2004, 03:22 PM
JohnBee JohnBee is offline
 
Join Date: Oct 2004
Posts: 544
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default [vB 3.0.3] A secure .htaccess form login using vB database

I have scanned the forums in search of something but to no avail.
I have found many similar hacks but none that seem to provide a
fully functional approach.

I am looking for a hack or addon that would allow the following.

1) .htaccess form login on a site entrance not generating plain text form data
2) .hataccess security for dirs/ file whatever
3) vBB database l/p authentication

There are java scripts to accomplish form logins with .htaccess
security now that don't pass the form data in your browser
cookies or address bar requiring https or ssl to get rid of.

there is plenty of .htaccess scripts also

What I cannot find is a working .htaccess -> vbulletin user
database script for vbulletin 3.0.3, if I had that perhaps
I could put something together.

Otherwise time is against me, is there anyone up to the task?
I am willing to pay for a job well done.

Your help is appreciated

Sincerely, John B
Reply With Quote
  #2  
Old 10-17-2004, 04:26 PM
Hialls's Avatar
Hialls Hialls is offline
 
Join Date: Jul 2002
Location: Reading, England
Posts: 108
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hmm would this require access by membergroupid's?
I think i have a script i used for an old site somewhere at work, if you still are in need i can check when im at work tommorow and email it you.
Reply With Quote
  #3  
Old 10-18-2004, 10:52 AM
JohnBee JohnBee is offline
 
Join Date: Oct 2004
Posts: 544
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

At this time my own requirements do not call for group access
but simply allow or deny access based on membership confirmation.

The problem I am getting is that using an .htaccess approach
the popup login is still very much there on the advent of incorrect
information submital the .htaccess popup will show its ugly head
hense ruining the clean form login approach I was looking for.

Another issue is that user login and password data depending on
the version of windows and SP you are using may appear in plain
text as well as passed down from the form to the authentication
via plain text, unless SSL / https is used.

There is always a PHP based approach, but it would seem that
PHP alone cannot effectively secure dirs and data as would .htaccess.

There is one program that claims to do this though called "NeedLock"
I have emailed the company with questions regarding my application
to see if it could provide what im looking for.

Perhaps there would be a way to intergrate NeedLock with vBB 3
and we would have a happy couple with a nice clean form login
page instead of that plain htaccess popup.

Unless someone here knows code to PHP a security script that can
protect DIRS and CONTENT and not just individual files
Reply With Quote
  #4  
Old 10-18-2004, 03:36 PM
djohn djohn is offline
 
Join Date: Feb 2004
Posts: 165
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

i have one of these scripts for vb 2.*, and would really like to see one made for vb3. here's a vb2 version in case anyone wants to have a look at it.
Attached Files
File Type: zip htaccessip.zip (2.3 KB, 29 views)
Reply With Quote
  #5  
Old 10-22-2004, 02:59 AM
JohnBee JohnBee is offline
 
Join Date: Oct 2004
Posts: 544
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank you djohn.

I apreciate your help, although your hack might have some valuable bits
to get what I'm looking for done I'm not sure it will be enough to accomplish
this.
Reply With Quote
  #6  
Old 10-22-2004, 03:29 AM
JohnBee JohnBee is offline
 
Join Date: Oct 2004
Posts: 544
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

This is a hack of obvious need "see site search: htaccess"
But every thread ends the same...

Why has this hack not been accomplished and posted is beyond me.
many large sites have sensitive content that would be kept within
there membership sections.

Intergrating the vBB membership database with other areas of the same
site only makes sense. Since there is no competent PHP code to protect
site areas, files etc. .htaccess is left as the obvious choice to get the
job done.

Could someone please create "a working" .htaccess hack that uses
vBB database L/P's to authenticate user access for vB 3.0.3?
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:08 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05346 seconds
  • Memory Usage 2,223KB
  • Queries Executed 14 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (6)post_thanks_box
  • (6)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (6)post_thanks_postbit_info
  • (6)postbit
  • (1)postbit_attachment
  • (6)postbit_onlinestatus
  • (6)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • postbit_attachment
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete