[ Tutorial ] How to Secure you're staff's account's [ Solution ]

Results 1 to 7 of 7
  1. #1
    Enthusiast Crowey is offline
    MemberRank
    May 2013 Join Date
    28Posts

    Support [ Tutorial ] How to Secure you're staff's account's [ Solution ]

    Hey Ragezone,

    I don't know if this Tutorial has been released yet.

    Today I want to show you how to secure your staff's account's


    I - SQL

    1) Create a Table that would keep the IP's.

    We start creating a table that would keep the IP's, incase if someone else got acces on the staff account with a different IP he would not have acces on the housekeeping, This table Would have 2 collums: `ip`, `pseudo`. than you will see that each account have the login IP. This is the SQL to add in you're database :


    CREATE TABLE IF NOT EXISTS `ip_staff` ( `ip` varchar(255) NOT NULL, `pseudo` varchar(255) NOT NULL DEFAULT 'AUCUN') ENGINE=MyISAM DEFAULT CHARSET=latin1;
    - - - - - - - - - - - - - - - - - - - - - - - - - - -
    2) Complete the table.

    To complete the table, Click on "Insert" Than in IP, enter the IP off the staff, In psuedo enter the staff username, than save it


    II - Redirection (on PHP)

    1) We create our mini security system.

    We are now going to make the PHP code that would search the computer that try to login with the staff account, and will compare the IP with the IP given in the Database (You will have to make a page a redirection page, we will call it,
    "staff_protect.php".



    Put the following code in to the CMS main folder : (in my case its global.php)




    <?php/** système anti intrusion par OvZ (peut être modifié/supprimé) **/if($user['rank'] >= 4) {$lancer[1] = mysql_query("SELECT ip,pseudo FROM ip_staff WHERE ip = '".$_SERVER['REMOTE_ADDR']."'");$donnees[1] = mysql_fetch_array($lancer[1]);if($donnees[1][pseudo] != $user['username']) {header("location:./staff_protect.php");die();}} ?>
    Your staffs will be now secured ( you will never know if your mods give there password to someone to buy some furni's in the staff catalogue )

    Credits:

    Forum : Ibuild
    User : OVZCMS
    ME : for the translation & the share

    Crowey
    Last edited by Crowey; 16-05-13 at 05:35 PM. Reason: edited


  2. #2
    Eye Eye Capt'n Spheral is offline
    MemberRank
    May 2010 Join Date
    TumptonshireLocation
    2,488Posts

    Re: [ Tutorial ] How to Secure you're staff's account's [ Solution ]

    Stupid when your staff have dynamic ips.

  3. #3
    Developer Eronisch is offline
    MemberRank
    Jul 2009 Join Date
    The NetherlandsLocation
    1,328Posts

    Re: [ Tutorial ] How to Secure you're staff's account's [ Solution ]

    I've to agree with Spheral, i had the same system as you. But 50% of my staff members had a dynamic ip.
    However, what you could do is create a cookie with some security information in it, and then check it with the database.

  4. #4
    Member Tequiro is offline
    MemberRank
    May 2013 Join Date
    67Posts

    Re: [ Tutorial ] How to Secure you're staff's account's [ Solution ]

    This doesn't seem to work for me.

  5. #5
    Enthusiast Crowey is offline
    MemberRank
    May 2013 Join Date
    28Posts

    Re: [ Tutorial ] How to Secure you're staff's account's [ Solution ]

    released, stupid ? ignore this thread. K thanks

  6. #6
    Lurking around Clawed is offline
    MemberRank
    Jun 2012 Join Date
    RaGEZONELocation
    785Posts

    Re: [ Tutorial ] How to Secure you're staff's account's [ Solution ]

    This won't work with dynamic ips.
    Just add a pin system, make the, choose a pin when they become staff, simples.

  7. #7
    Enthusiast Crowey is offline
    MemberRank
    May 2013 Join Date
    28Posts

    Re: [ Tutorial ] How to Secure you're staff's account's [ Solution ]

    Did u guys read?

    Credits:

    Forum : Ibuild
    User : OVZCMS
    ME : for the translation & the share

    Crowey



Advertisement