Thread Rating:
  • 1 Votes - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5

MySessions

02-10-2012, 05:55 AM (This post was last modified: 03-10-2012 04:11 AM by Paul H..)
Post: #1
MySessions
Description:
With this plugin, users can view all of their account's current sessions and log out any sessions they find suspicious. Admins can view all sessions. Based on the functionality found in Gmail and Deviantart.

The below screenshot shows the usercp?action=mysessions page. The useragent "1'" was made by Nathan as he was testing the plugin for vulnerabilities, of which he found some and I fixed immediately :P

IP address links go to *the ip address*.ipaddress.com. If the plugin can, it will display the hostname and location of the IP address.

[Image: gyrd.png]

If there are multiple sessions for the same account, a warning shows up (which can be dismissed)

[Image: gysk.png]

Install:
This plugin adds one database table and edits one template.

Upgrade:
From 1.0 to 1.1: re-upload mysessions.php
From 1.0, 1.1 to 1.2, 1.3: re-upload mysessions.php, deactivate and reactivate. This is needed to add a new column, uid, to the mysessions_kill table.

Change log:
1.0: Initial release
1.1: Minor bug fixes, and feature Multiple Sessions Alerts added
1.2 Added features:
  • Cancel kill request
  • Search by IP/username
Miscellaneous bug fixes
Fully commented code
1.3 Fixed SQL injection (SQLi) issue
1.3.1 Fixed a few links, userCP menu issue, and pagination issue


Attached File(s)
.php  mysessions.php (Size: 20 KB / Downloads: 191)

~Paul H.
quote



02-15-2012, 06:39 AM
Post: #2
RE: MySessions
Has anyone been able to try this out?

~Paul H.
quote
02-15-2012, 07:50 AM
Post: #3
RE: MySessions
Updated to 1.1, one feature added: Multiple Sessions Alerts.

~Paul H.
quote
02-15-2012, 09:12 AM
Post: #4
RE: MySessions
Hm. I don't really see a use for this for me personally. I'll download it and take a look though.

quote
02-29-2012, 06:41 PM
Post: #5
RE: MySessions
what type of hash does the sid have?
quote
02-29-2012, 06:47 PM
Post: #6
RE: MySessions
It's a simple md5 hash. It's used only as a uniquifier.
quote



03-06-2012, 03:04 AM
Post: #7
RE: MySessions
Has anyone else been able to use this? It is used in gmail and deviantart, I thought it'd be a bit more popular.

I'll be adding some more features in the near future.

~Paul H.
quote
03-06-2012, 03:17 AM (This post was last modified: 03-06-2012 03:18 AM by Nathan Malcolm.)
Post: #8
RE: MySessions
I might install it here as a demo. Smiley
quote
03-06-2012, 04:06 AM
Post: #9
RE: MySessions
Upcoming features added to first post.

~Paul H.
quote
03-08-2012, 12:47 AM
Post: #10
RE: MySessions
Also, version 1.2 will be fully commented.

~Paul H.
quote






Who's Online 9 users active in the past 30 minutes (0 members, 0 of whom are invisible, and 8 guests).

Google

Forum Board By MyBB. MyBB Security is not affiliated with nor endorsed by the MyBB Group. MyBB Security theme designed and coded by Codicious.