GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   How to stop shortcut logins?!?! (https://gfy.com/showthread.php?t=108443)

cafeaulait 02-15-2003 05:27 AM

How to stop shortcut logins?!?!
 
Is it possible to stop members logging in using the http://username:[email protected] format?

And force an authentication box onto them?

Cheers.

G

JayJay 02-15-2003 05:51 AM

/\ BUMP /\

also looking for an answer to this question

J B 02-15-2003 06:04 AM

Not sure but wouldn't a referrer check do the trick?

Maqua 02-15-2003 07:51 AM

You may find your answer here: http://groups.google.com/ :)

gothweb 02-15-2003 07:52 AM

I asked someone about this, and got a suggestion for my htaccess files. Unfortunately, neither of us could make it work. I would really love a solution about this.

Calvinguy 02-15-2003 07:58 AM

Try to add the following to your htaccess file.

RewriteEngine On
RewriteCond %{HTTP_REFERER} !^http://([a-z0-9-]+\.)*domain.com/ [NC]
RewriteCond %{HTTP_REFERER} !^$
RewriteRule /* http://www.domain.com/ [L,R]


Nevermind. Just tried it and it didn't work....

notjoe 02-15-2003 08:18 AM

Quote:

Originally posted by cafeaulait
Is it possible to stop members logging in using the http://username:[email protected] format?

And force an authentication box onto them?

Cheers.

G

Yes there is. Check the referring url upon login and if it isnt from y our pre-login page/domain you reject the login.

notjoe 02-15-2003 08:18 AM

Quote:

Originally posted by J B
Not sure but wouldn't a referrer check do the trick?
Yes it would!

rowan 02-15-2003 09:24 AM

I fiddled around with this myself, and from my experiments concluded that the user:pass@host format is local only - it's not actually passed through to the web server. The referer solution is probably your best bet, although it will cause problems with software that blocks it.

gothweb 02-15-2003 10:06 AM

Quote:

Originally posted by rowan
I fiddled around with this myself, and from my experiments concluded that the user:pass@host format is local only - it's not actually passed through to the web server. The referer solution is probably your best bet, although it will cause problems with software that blocks it.
I thought it might be local only, based on the kinds of failures we saw. That is a shame. Does anyone else mostly hate these because of public (free) trackers?

CDSmith 02-15-2003 10:53 AM

Quote:

Originally posted by gothweb
Does anyone else mostly hate these because of public (free) trackers?
The paysites I've worked for had that problem a few years ago, but when I switched them over to a password protected paycounter it was never a problem again. Not sure why else anyone would want to block the quick login..... it's pretty convenient for members, especially regular long timers.

chupacabra 02-15-2003 10:59 AM

switching to a 'script-based' authentication model instead of 'server-based (straight .htaccess -> .htpasswd), will solve this problem... people will be forced to go through a login gateway that relies on a script to call to .htpasswd, and i don't believe it can be crossed by user:pass@host login attempts... pw sentry uses a script-based auth model, i highly recommend it..


All times are GMT -7. The time now is 06:39 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123