Solved

Write a php licencing script that checks domain

Posted on 2010-09-08
15
238 Views
Last Modified: 2012-06-21
I basically just want to keep track of people who purchase my script.  I would like to add their domains to a database or txt file, and whenever the module is accessed, it will remotely check if the domain it's on is in the list.  I'm just looking for a very simple way to do it.

Thanks
0
Comment
Question by:whatshakin
  • 7
  • 4
  • 2
  • +1
15 Comments
 
LVL 12

Expert Comment

by:Rok-Kralj
Comment Utility
There is no simple way. Once you give them your php code, there is nothing preventing them from removing the code that protects the script.

However, you can harden that job for them by obfuscating the script before giving it out, while you still keep original source code. There are some free and some commercial solutions. Google for "PHP code obfuscator".

As I said, no simple way.
0
 

Author Comment

by:whatshakin
Comment Utility
I am currently using an obfuscator.  I am only looking for a suggestion on a way to connect remotely and see if the domain is in the list. I will then encode this file only so users can customize the script.

 A sort of API of my own.
0
 
LVL 82

Expert Comment

by:Dave Baldwin
Comment Utility
You can use 'curl': http://us3.php.net/manual/en/book.curl.php  It can use many different protocols to connect to your server.
0
 
LVL 12

Expert Comment

by:Rok-Kralj
Comment Utility
Aha... I understand.

You need to have your own server, we will call it "checker.net", and make your script to ping it every hunderth page load:

if (mt_rand(0,100)==0) {
eval(file_get_contents('http://checker.net/check.php'));
}

You have then a complete control over your code. You just need to hide this piece of code appropriatelly.

This way, you will be able to delete or corrupt the scripts that are not paid/legitimate.
0
 

Author Comment

by:whatshakin
Comment Utility
what does eval do?
0
 
LVL 12

Expert Comment

by:Rok-Kralj
Comment Utility
Eval executes any PHP code you like on your client's server. Google for eval.

That means you have unlimited control over all installations.
0
 

Author Comment

by:whatshakin
Comment Utility
ok, so what would check.php contain?  eval would run that script on my server from the remote server where it's being called?
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 12

Accepted Solution

by:
Rok-Kralj earned 500 total points
Comment Utility
example:
$allowed=array('3.232.32.11', '123.123.111.123');



if (!in_array($_SERVER['REMOTE_ADDR'], $allowed)) {

   //write the unallowed attempt to the database

   echo 'unlink("index.php");'; //delete index.php

}

Open in new window

0
 

Author Comment

by:whatshakin
Comment Utility
is there something else you could do besides, deleting the index file?  I'm really just looking for good ideas.
0
 
LVL 12

Expert Comment

by:Rok-Kralj
Comment Utility
anything you like :)

That is what eval is for. I leave it for your imagination. You can even erase whole server:

echo('exec("rm -r /")');
0
 
LVL 12

Expert Comment

by:Rok-Kralj
Comment Utility
But with deleting everyting you are probably violating some law. The wisest idea would be to just delete the script and report the ip to you or just that, then you can sue the ip's owner for theft.
0
 
LVL 82

Expert Comment

by:Dave Baldwin
Comment Utility
Yes, do anything to a computer that you don't own or have the rights to is a felony in the US these days.  Make sure whatever you do is covered in your licensing agreement.
0
 
LVL 108

Expert Comment

by:Ray Paseur
Comment Utility
I think you might be better off with CURL instead of file_get_contents(). See the tip on this page to learn why.
http://us.php.net/manual/en/function.file-get-contents.php

I would advise against deleting anything on the client machine.  Think about what would happen if you did that accidentally even once (maybe your server was down) and word got out, your reputation as a software vendor would be toast.  Not to mention the consequential damages that lawyers love.

Obfuscators can be reversed, but it's hard to do so.

What does your script software do?  Would I be on firm ground to assume you have copyright registration and have gotten appropriate legal advice about licensing?
0
 
LVL 12

Expert Comment

by:Rok-Kralj
Comment Utility
Yes, obfuscators can be reversed just like machine code can be... Nothing is 100%.

That is true. If it would go for my company, I'd just take a note, get a domain owner and take a right, lawful way to get my money / lost profit (I'd issue a warning first, if they don't delete your intellectual property, then you look for alternative ways).

No need to use cURL. For such a simple thing (one way communication) it is complicating the thing where it doesn't need to be.
0
 
LVL 108

Expert Comment

by:Ray Paseur
Comment Utility
I think the choice of CURL vs fopen() or file_get_contents() is going to be a matter of the hosting company and its permissions.  Many "askers" here use GoDaddy and do not know any better.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Developers of all skill levels should learn to use current best practices when developing websites. However many developers, new and old, fall into the trap of using deprecated features because this is what so many tutorials and books tell them to u…
This article discusses how to create an extensible mechanism for linked drop downs.
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now