diff --git a/functions.php b/functions.php index b34cb05..f5de95f 100644 --- a/functions.php +++ b/functions.php @@ -125,3 +125,23 @@ function logs($perms, $column, $pid, $user, $dbcon, $player, $val) } } } + +function get_client_ip_server() { + + if ($_SERVER['HTTP_CLIENT_IP']) + $Address = $_SERVER['HTTP_CLIENT_IP']; + else if($_SERVER['HTTP_X_FORWARDED_FOR']) + $Address = $_SERVER['HTTP_X_FORWARDED_FOR']; + else if($_SERVER['HTTP_X_FORWARDED']) + $Address = $_SERVER['HTTP_X_FORWARDED']; + else if($_SERVER['HTTP_FORWARDED_FOR']) + $Address = $_SERVER['HTTP_FORWARDED_FOR']; + else if($_SERVER['HTTP_FORWARDED']) + $Address = $_SERVER['HTTP_FORWARDED']; + else if($_SERVER['REMOTE_ADDR']) + $Address = $_SERVER['REMOTE_ADDR']; + else + $Address = 'UNKNOWN'; + + return $Address; +} diff --git a/login.php b/login.php index 426c9f1..3ae9457 100755 --- a/login.php +++ b/login.php @@ -11,6 +11,7 @@ include 'verifyPanel.php'; loginconnect(); +get_client_ip_server() if (!$dbconL) { echo 'Database connection error'; @@ -34,14 +35,14 @@ if ($username && $password) { if (!isset($_SESSION['failedLogin'])) { - $sql = "SELECT * FROM access WHERE address = '$_SERVER[REMOTE_ADDR]'"; + $sql = "SELECT * FROM access WHERE address = '$Address'"; $sqldata = mysqli_query($dbconL, $sql) or die('Connection could not be established - LOG'); if (mysqli_num_rows($sqldata) == 0) { - $sqli = "INSERT INTO access (address,failed) VALUES ('$_SERVER[REMOTE_ADDR]',0)"; + $sqli = "INSERT INTO access (address,failed) VALUES ('$Address',0)"; $sqlinput = mysqli_query($dbconL, $sqli) or die('Connection could not be established - LOG'); - $sql = "SELECT * FROM access WHERE address = '$_SERVER[REMOTE_ADDR]'"; + $sql = "SELECT * FROM access WHERE address = '$Address'"; $sqldata = mysqli_query($dbconL, $sql) or die('Connection could not be established - LOG'); } $user = $sqldata->fetch_object(); @@ -97,7 +98,7 @@ $_SESSION['perms'] = $perms; $_SESSION['failedLogin'] = 0; - $sqlget = "UPDATE access SET failed = 0 WHERE address = '$_SERVER[REMOTE_ADDR]'"; + $sqlget = "UPDATE access SET failed = 0 WHERE address = '$Address'"; $res = mysqli_query($dbconL, $sqlget); if ($_SESSION['failedLogin'] >= 5) {