MyBB Community Forums

Full Version: Making a FAKE Admin CP Login Page
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2 3 4
I just made one undetectable and it will has a setting to allow automatic banning the IP. I was thinking of doing this before anyways. I won't release it though.
nice idea for security reason.

this script will collect IP Address form someone who try to login.
But, if possible Zash. It's Better to include with email notification, The "username" (if exist) read from MyBB session. So, Administrator can see (easily) that "damn" user want to try (or curious) login into admin panel Smile

Nice idea.. Cool
THis screenshot for email send.

Quote:####################################################
THIS IS AN AUTOMATED EMAIL - DO NOT RESPOND
####################################################

Somebody just attempted to login to your fake MyBB Admin CP. The person's login details and IP address were recorded:

Username: admin
Password: admin
IP Address: xxx.xxx.xxx.xxx

If this is not the first login attempt from the above IP address, it is recommend that you ban it from accessing your forums.
(2009-08-09, 01:19 AM)labrocca Wrote: [ -> ]I just made one undetectable and it will has a setting to allow automatic banning the IP. I was thinking of doing this before anyways. I won't release it though.

Hey bro am ready to pay if its custom Smile
(2009-08-09, 04:03 AM)FBI Wrote: [ -> ]But, if possible Zash. It's Better to include with email notification, The "username" (if exist) read from MyBB session. So, Administrator can see (easily) that "damn" user want to try (or curious) login into admin panel Smile
That's not a bad idea. For now, just do a simple IP search on your forums Smile
Right Zash, thats not a bad idea Smile
But, in my country. mostly visitor connect internet using Dynamic IP address.
We have many ISP (Internet Service Provider) which provide dynamic IP for personal (home) user and static IP for corporate (big company user). And sometimes (many) different user using same IP address (even in 1 of 100 IP listed)

So, without username attached to email. It's difficult to find the original (first) person who try to login from fake admin. Do you understand what I mean? Smile
Ah, that's a problem that faces all IP bans. You could probably guess what member it is if you pay attention to behavior, but I'll look into the username thing.
This is great. I'll be using this!
(2009-08-09, 12:16 PM)kan3 Wrote: [ -> ]
(2009-08-09, 01:19 AM)labrocca Wrote: [ -> ]I just made one undetectable and it will has a setting to allow automatic banning the IP. I was thinking of doing this before anyways. I won't release it though.

Hey bro am ready to pay if its custom Smile

You do know it would take a few lines of basic PHP to ban them, right? Unless labrocca has some super sexy solution, it would be a waste of money (no offense).

It should be noted that your method of sanitizing the username and password only works with PHP 5.2+. Any decent host will have this version, but just in case your still running PHP 4, you'll get errors.
Ok thanks for the headsup. But technically MyBB doesn't support PHP4 either.
Thanks!
Also in the
// The 'From' Email
$from = "[email protected]";
I do not change yes?
Pages: 1 2 3 4