Register Members List Search Today's Posts Mark Forums Read

Reply
 
Mod Options
AdminCP Firewall ~ Protect your AdminCP! Details »
AdminCP Firewall ~ Protect your AdminCP!
Mod Version: 1.3.3, by liamwli (Coder) liamwli is offline
Developer Last Online: Dec 2019 I like it Show Printable Version Email this Page

vB Version: 4.x.x Rating: (21 votes - 5.00 average) Installs: 101
Released: 21 Mar 2013 Last Update: 05 Apr 2013 Downloads: 623
Not Supported Uses Plugins Re-usable Code Translations  

This is a mod I made to increase the security of your forum!

It has the following features:
  • Email alert when an Admin logs into the CP
  • IP Checking for Admins
  • E-Mail if the IP isn't whitelisted
  • Block user access to the AdminCP if the IP isn't whitelisted
  • E-Mail if someone fails an AdminCP login
Those features will allow you to secure your AdminCP - and the only upload required is the product file!

So, what are you waiting for? Install now

Update History
Version 1.3.3:
PHP error should be fixed

Version 1.3.2:
Fixed - PHP error message when logging into AdminCP
Branding Removed

Version 1.3.1:
Fixed - text would be displayed on login failure page if failure email turned off or not from admincp

Version 1.3:
Added - Ability to have an email sent when someone fails an admincp login.
Added - Branding. Sorry! Any donation of 2.50 or more will allow you to remove it

Version 1.2:
Added - Ability to specify IP's as CIDR ranges
Added - Ability to set both IP email and IP deny
Added - IP email will now tell you if any forum members registered using the unauthorized IP
Changed - Updated Admin Help Pages

Version 1.1:
Added - Ability to specify multiple email addresses
Added - Help entries for the admin options
Changed - IP's are separated with a line break now, not a comma.

Mark as Installed if Installed and Nominate for MOTM if you think this mod deserves it!

-----------

Donating

I kindly accept donations for my work. Donating will allow you to remove the branding. You can donate via paypal using the link on the right, or using bitcoin. Please PM me if you wish to donate using bitcoin.

This modification is free to modify and distribute with attribution. I no longer own a vBulletin license.

Download Now

Only licensed members can download files, Click Here for more information.

Screenshots

Click image for larger version

Name:	cpfirewall_settings.jpg
Views:	1196
Size:	92.8 KB
ID:	144258  

Show Your Support

  • To receive notifications regarding updates -> Click to Mark as Installed.
  • If you like this modification support the author by donating.
  • This modification may not be copied, reproduced or published elsewhere without author's permission.
Similar Mod
Mod Developer Type Replies Last Post
Protect AdminCP while Away and Log Ip Address DrkFusion vBulletin 2.x Full Releases 13 25 Jan 2003 15:08

  #91  
Old 18 Sep 2013, 11:44
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Real name: Paul M
Just adding the genereric disable hooks define to your config.php would also allow you back in.


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

__________________
Former vBulletin.org Staff Member


Cable Forum
Please do not PM me about custom work - I no longer undertake any.
Note: I will not answer support questions via e-mail or PM - please use the relevant thread or forum.
Reply With Quote
  #92  
Old 18 Sep 2013, 14:07
DemOnstar's Avatar
DemOnstar DemOnstar is offline
 
Join Date: Dec 2012
Installed.
Reply With Quote
  #93  
Old 18 Sep 2013, 14:20
DemOnstar's Avatar
DemOnstar DemOnstar is offline
 
Join Date: Dec 2012
Originally Posted by Paul M View Post
Just adding the genereric disable hooks define to your config.php would also allow you back in.


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.
I did just that...

There is however a slim, coincidental hole with this idea as it will disable all the spam stuff, the protection stuff and everything else for the brief period where one has to do the changes in config.php and then gain access again to add another IP..

There is a vulnerability here... I like the password idea.

Last edited by DemOnstar; 18 Sep 2013 at 14:27.
Reply With Quote
  #94  
Old 18 Sep 2013, 21:29
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Real name: Chris
Originally Posted by Paul M View Post
Just adding the genereric disable hooks define to your config.php would also allow you back in.


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.
Paul, If I understand this mod correctly, it does not use hooks, it can not be disabled that way.

So the way to disable it is the way I said in post #83 and as theOP described in post #2
Reply With Quote
  #95  
Old 19 Sep 2013, 05:04
DemOnstar's Avatar
DemOnstar DemOnstar is offline
 
Join Date: Dec 2012
Originally Posted by Paul M View Post
Just adding the generic disable hooks define to your config.php would also allow you back in.


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.
Originally Posted by ozzy47 View Post
Paul, If I understand this mod correctly, it does not use hooks, it can not be disabled that way.

So the way to disable it is the way I said in post #83 and as theOP described in post #2
I just added both to my config.php and left them commented out..
In that case, when the inevitable day comes where I have to use them, I know they are there...

I guess next I have to protect the includes folder..
Reply With Quote
  #96  
Old 19 Sep 2013, 06:28
Bubble #5 Bubble #5 is offline
 
Join Date: Apr 2005
Smile

Originally Posted by DemOnstar View Post
There is a vulnerability here... I like the password idea.
At a minimum it should have a password, but after thinking about it I'd prefer if the admin could fill out their own security question in the ACP, and then answer it. There are scripts that can guess passwords, but who's going to know the answer to your own security question but you?
__________________
If we don't help each other when we can, then we're not making this world a better place.
Reply With Quote
  #97  
Old 19 Sep 2013, 11:33
DemOnstar's Avatar
DemOnstar DemOnstar is offline
 
Join Date: Dec 2012
Originally Posted by Bubble #5 View Post
At a minimum it should have a password, but after thinking about it I'd prefer if the admin could fill out their own security question in the ACP, and then answer it. There are scripts that can guess passwords, but who's going to know the answer to your own security question but you?
This is a better idea..... Agreed. +1
Reply With Quote
  #98  
Old 19 Sep 2013, 11:35
DemOnstar's Avatar
DemOnstar DemOnstar is offline
 
Join Date: Dec 2012
I had an email..

A user has logged into the AdminCP using an unauthorized IP address.

Ok, I had to check but it doesn't seem to be the case..
Perhaps re-wording the mail to

A user has attempted to log into the AdminCP using an unauthorized IP address.

I will try to do this myself...

EDIT: It was easy, it is all in languages and phrases...Shall see if it shows up the next time...

Last edited by DemOnstar; 19 Sep 2013 at 11:58.
Reply With Quote
  #99  
Old 20 Sep 2013, 19:54
bigs15 bigs15 is offline
 
Join Date: Oct 2006
Mine is dynamic Ip so how does this mod help me?
Reply With Quote
  #100  
Old 21 Sep 2013, 05:15
obglobal.net obglobal.net is offline
 
Join Date: Jan 2013
Could someone please help me with instructions on how to install this? I'd really like to add this mod as I've been hacked twice in the last 2 weeks.

Thanks very much.
Reply With Quote
  #101  
Old 21 Sep 2013, 06:13
DemOnstar's Avatar
DemOnstar DemOnstar is offline
 
Join Date: Dec 2012
Originally Posted by obglobal.net View Post
Could someone please help me with instructions on how to install this? I'd really like to add this mod as I've been hacked twice in the last 2 weeks.

Thanks very much.
Download

Go to your admincP/Plugin and Products/Manage Products/Add/Import Product.
Reply With Quote
  #102  
Old 21 Sep 2013, 08:41
obglobal.net obglobal.net is offline
 
Join Date: Jan 2013
Originally Posted by DemOnstar View Post
Download

Go to your admincP/Plugin and Products/Manage Products/Add/Import Product.
Good gracious! Is that it? Thanks for the heads up, bro! I thought it was gonna be a far more detailed process.

Awesome!
Reply With Quote
  #103  
Old 21 Sep 2013, 08:57
obglobal.net obglobal.net is offline
 
Join Date: Jan 2013
I just tried to set it up with my own IP and everything and it's blocked me from the ACP!


Sorry, you don't have permission to access the administrative controls on this page.

If you need to access this page, ask your lead administrator to enable your permissions for this page using the Administrator Permissions section of the control panel.
Reply With Quote
  #104  
Old 21 Sep 2013, 09:12
ozzy47's Avatar
ozzy47 ozzy47 is offline
 
Join Date: Jul 2009
Real name: Chris
This may work.

Open your config.php and below<?php add this line:


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

So it looks like this:

Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

Reply With Quote
  #105  
Old 21 Sep 2013, 09:21
obglobal.net obglobal.net is offline
 
Join Date: Jan 2013
Originally Posted by ozzy47 View Post
This may work.

Open your config.php and below<?php add this line:


Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.

So it looks like this:

Block Disabled:      (Update License Status)  
Suspended or Unlicensed Members Cannot View Code.
Thanks very much, Ozzy47. I read post #83 and have been looking for where I find config.php.

I searched the vb.org forums and apparently it's in forum/includes, but I don't know where to find that, either. I couldn't find it in cPanel.

I use FileZilla - it should be in there, right?
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Mod Options

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 09:59.

Layout Options | Width: Wide Color: