Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Results 1 to 4 of 4
  1. #1
    Join Date
    Sep 2007
    Location
    USA
    Posts
    474
    Tokens
    0

    Default Need VERY SECURE login

    im making a staff panel kinda underground but i wanted to get a secure login then once i get it finish beta test it a little might give out

    but anyways i want a really secure login to hook up to everything possibly
    a authenication required window then the regular staff login to make sure no unauthorized people get in to even try to get to the pw source or anything
    Post Meter
    ______________________________________________
    400 450 500 550 600 650 700 750 800 850 900-1k
    Green=Done | Orange=Almost | Red=Not Done
    ______________________________________________
    Habbo fury Coming Soon!
    My Img tag has ran away

  2. #2
    Join Date
    Jan 2007
    Posts
    825
    Tokens
    0

    Default

    SSL typed login?

    I think you need a citificate im not sure though
    That post was really sensible!

  3. #3
    Join Date
    Sep 2007
    Location
    USA
    Posts
    474
    Tokens
    0

    Default

    i basically meant a extremly secure regular login that people cant get into i dont mean like ssl though it would be nice
    Post Meter
    ______________________________________________
    400 450 500 550 600 650 700 750 800 850 900-1k
    Green=Done | Orange=Almost | Red=Not Done
    ______________________________________________
    Habbo fury Coming Soon!
    My Img tag has ran away

  4. #4
    Join Date
    Sep 2006
    Location
    Hobart, Australia
    Posts
    593
    Tokens
    0

    Default

    Just a secure login? Or a secure session checker as well? I'd have both, IMO.

    Have the login store the useragent and IP address in an 'online' table on the database, and if the user tries to login again with a different useragent or IP, make the first login logout. Set the script to delete any entries from the online table that are older than, say, 25 minutes.

    As for login, make sure you are encrypting your passwords with a salt:

    PHP Code:
    $salt 'OiuhgoewihgIOUGHe';
    $encrypted_password md5($_POST['password'] . $salt); 
    That way, your hashes are immune from rainbow tables.

    Flush all your user inputted content with mysql_real_escape_string, and you're set!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •