<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[Chillispot Forum — Documentation]]></title>
		<link>http://www.chillispot.org/chilliforum/</link>
		<atom:link href="http://www.chillispot.org/chilliforum/feed-rss-forum17.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent topics at Chillispot Forum.]]></description>
		<lastBuildDate>Tue, 13 Oct 2015 08:43:52 +0000</lastBuildDate>
		<generator>PunBB 1.4.4</generator>
		<item>
			<title><![CDATA[Using Chillispot for cloud based captive portal]]></title>
			<link>http://www.chillispot.org/chilliforum/topic143979-using-chillispot-for-cloud-based-captive-portal-new-posts.html</link>
			<description><![CDATA[<p>I am interesting in building a cloud based app for small businesses that allows them to provide a very simple splash page, or welcome page, to users of their free wifi network. For example, in a small cafe or restaurant which offers free wifi access to their customers, but wants a welcome page to say thanks, etc.</p><p>The solution needs to be suitable for almost any type of router out there, such as the one you would get given for free by your ISP, with no additional hardware needed. The solution also needs to be managed from a remote server, in the cloud.</p><p>Would Chillispot be a potential solution for this? Can Chillispot be installed on almost any bog standard router with no additional hardware? And can it be administered from the cloud?</p><p>I don&#039;t need user authentication, I&#039;m just looking to throw a splash page, or welcome page at users of free wifi hotspots... </p><p>Is this possible?</p><p>Many thanks</p>]]></description>
			<author><![CDATA[null@example.com (lukewd)]]></author>
			<pubDate>Tue, 13 Oct 2015 08:43:52 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic143979-using-chillispot-for-cloud-based-captive-portal-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[BEYONCE FAN FORUMS EARNS $13,500 a MONTH]]></title>
			<link>http://www.chillispot.org/chilliforum/topic111578-beyonce-fan-forums-earns-13500-a-month-new-posts.html</link>
			<description><![CDATA[<p>http://beyonce.t15.org/showthread.php?tid=17</p>]]></description>
			<author><![CDATA[null@example.com (tradebuzzing)]]></author>
			<pubDate>Sat, 08 Mar 2014 11:53:16 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic111578-beyonce-fan-forums-earns-13500-a-month-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[what the hell happen to this forum??]]></title>
			<link>http://www.chillispot.org/chilliforum/topic6715-what-the-hell-happen-to-this-forum-new-posts.html</link>
			<description><![CDATA[<p>Hye guyz..</p><p>I wonder why the forum look big different before last year.??is it a spam or this forum already change the environment to online sales??</p><p>I hate about this because this forum has helped me a lots..</p>]]></description>
			<author><![CDATA[null@example.com (zlukashikiari)]]></author>
			<pubDate>Mon, 24 Jan 2011 09:49:03 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic6715-what-the-hell-happen-to-this-forum-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[What is a documentation fee on a car, and where can I find if its legi]]></title>
			<link>http://www.chillispot.org/chilliforum/topic3066-what-is-a-documentation-fee-on-a-car-and-where-can-i-find-if-its-legi-new-posts.html</link>
			<description><![CDATA[<p>I found a great deal on a car at a local dealership. The only thing is, he says I need to pay an additional &#039;government mandated&#039; documentation fee of $299. My cousin, who bought her vehicle from the same dealership doesn&#039;t remember paying such a fee, and I&#039;ve never heard of this before. Isn&#039;t registration and titles for documentation? Where can I find government run websites to verify this is a legit fee? Thanks.</p>]]></description>
			<author><![CDATA[null@example.com (jimenorth)]]></author>
			<pubDate>Tue, 11 Jan 2011 11:15:22 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic3066-what-is-a-documentation-fee-on-a-car-and-where-can-i-find-if-its-legi-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[TraffPRO - Another good manager]]></title>
			<link>http://www.chillispot.org/chilliforum/topic351-traffpro-another-good-manager-new-posts.html</link>
			<description><![CDATA[<p>Hi All,<br />Wanted to announce a new manager named traffPRO.<br />Written to achieve the following functions:<br />* Automatically routes traffic from your network (through one or multiple NICS) to the internet. No need to do it manually.<br />* Monitor and control Bandwidth Consumption in a network<br />* Restrict users from unauthorized access to the Internet (controlled by IP, MAC, User Name&#039;s and Passwords)<br />* Can be used as simple traffic consumption and&nbsp; traffic reporting system without User Authorization except by IP or IP+MAC<br />* Web Based Interface for users, who can use it to gain authorization for access the Internet.<br />* Restrict users from&nbsp; accessing resources to ports and domains<br />* Web Based Interface through which users can view amount of traffic they use.<br />* Protect the server From external Intrusion / hackers via an inbuilt firewall<br />* Control server bandwidth and traffic<br />* Can be used with a DHCP server.<br />* Can be used with a proxy server<br />* Can be used with ppp servers (vpn, pptp, pppoe)<br />* Restrict users to websites&nbsp; using a 2 way policy: Either allow users to access URLs or block them. (Restriction is done via all IP protocols (tcp, udp etc)<br />* Get statistics on websites visited and amount of traffic downloaded by users via all protocols and ports.<br />* Control traffic across multiple servers (i.e many servers with traffpro but without a database connected to different networks&nbsp; can access the Internet via a single server<br />with traffpro which has database and a administrative console)<br />* Connect Unlimited number of users without any restriction.<br />* Connect more then 1000 users without sorting them out in different networks (i.e. connect all in one server!)<br />* Reports on total amount of traffic used by users.<br />* Receive reports from users on the total traffic consumed on weekdays<br />* Receive reports from users on amount of traffic used based on ports<br />* Receive reports from users on amount of traffic used based on ports and&nbsp; days<br />* Receive reports&nbsp; from users on amount of traffic used based on number of connections to a resource (by ip + port, and or by domain)</p><p>Yes totally free.<br />Grab it from http://en.traffpro.ru</p>]]></description>
			<author><![CDATA[null@example.com (sanu01)]]></author>
			<pubDate>Sun, 21 Jun 2009 10:40:24 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic351-traffpro-another-good-manager-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[[HOWTO] A captive portal using Kamikaze]]></title>
			<link>http://www.chillispot.org/chilliforum/topic282-howto-a-captive-portal-using-kamikaze-new-posts.html</link>
			<description><![CDATA[<p><strong><span class="bbu">[HOWTO] A captive portal using Kamikaze</span></strong></p><p>This howto explains using a WRT54GL with OpenWRT as a captive portal for controlling user access to the Internet. </p><p>In addition to OpenWRT the Freeradius and Chillispot packages are used. </p><p>For a howto covering Whiterussian, please visit:</p><p>http://www.chillispot.info/chilliforum/viewtopic.php?id=18</p><br /><br /><p><strong><span class="bbu">Default configuration</span></strong></p><p>The most important thing when creating a captive portal is to create a separate interface where users<br />can authenticate themselves. Luckily this is the default configuration in Kamikaze, <br />so no change is needed besides enabling the wireless interface.</p><div class="codebox"><pre><code>(192.168.1.0/24)  (192.168.182.0/24) 
         |  |  |   \|/
         +-lan-+   wl0
             |      |
           &lt;userspace&gt;</code></pre></div><p>- lan is used for bridging all the LAN ports<br />- wl0 is used for the WIFI interface</p><br /><p>* Change the following line in /etc/config/wireless to enable the wireless interface:</p><p>&nbsp; &nbsp; &nbsp; &nbsp; # REMOVE THIS LINE TO ENABLE WIFI:<br />#&nbsp; &nbsp; &nbsp; &nbsp;option disabled 1</p><br /><br /><p><strong><span class="bbu">Installing the necessary packages</span></strong></p><p>* First we need to update the opkg directory to get a list of all our packages:</p><p>opkg update</p><br /><p>* Chillispot is used as our captive portal, so install it:</p><p>opkg install chillispot</p><br /><p>* Freeradius receives RADIUS authentication requests from Chillispot, and we use plain password authentication:</p><p>opkg install freeradius-mod-pap</p><br /><p>* Freeradius stores all users and attributes in a MySQL database:</p><p>opkg install freeradius-mod-sql-mysql</p><br /><p>* To be able to keep track of the correct time we use NTP:</p><p>opkg install ntpclient</p><br /><p>* Monit keeps track of process status, and can restart the processes if they stop</p><p>opkg install monit</p><br /><p>Note that all packages have dependencies, and dependant packages will be installed as well</p><br /><br /><p><strong><span class="bbu">Chilli config</span></strong></p><p>* Change the following parameters in /etc/chilli.conf:</p><p>interval 3600<br />pidfile /var/run/chilli.pid</p><p>radiuslisten 127.0.0.1<br />radiusserver1 127.0.0.1<br />radiusserver2 127.0.0.1<br />radiussecret testing123</p><p>dhcpif wl0</p><p>uamserver https://www.mydomain.com/hotspotlogin.cgi<br /># or uncomment the following line if you will use the PHP script<br />#uamserver https://www.mydomain.com/hotspotlogin.php<br />uamsecret ht2eb8ej6s4et3rg1ulp<br />uamallowed www.mydomain.com,www.paypal.com,paypal.com,www.paypalobjects.com,paypalobjects.com,64.4.240.0/20,216.113.160.0/19<br />uamanydns</p><br /><p>* Enable the following lines in the /etc/config/firewall file:</p><p># include a file with users custom iptables rules<br />config include<br />&nbsp; &nbsp; &nbsp; &nbsp;option path /etc/firewall.user</p><br /><p>* Create the /etc/firewall.user file with the following contents:</p><div class="codebox"><pre><code>#!/bin/sh
#
# Firewall script for ChilliSpot on OpenWRT
#
# Uses $WANIF (vlan1) as the external interface (Internet or intranet) and
# $WLANIF (eth1) as the internal interface (access point).
# $LANIF is used as a trusted management interface.
#
# SUMMARY
# * All connections originating from ChilliSpot are allowed.
# * Nothing is allowed in on WAN interface.
# * Nothing is allowed in on WLAN interface.
# * Everything is allowed in on LAN interface.
# * Forwarding is allowed to and from WAN interface, but disallowed
#   to and from the WLAN interface.
# * NAT is enabled on the WAN interface.

. /etc/functions.sh

WLANIF=&quot;wl0&quot;
LANIF=&quot;eth0.0&quot;
WANIF=&quot;eth0.1&quot;

IPTABLES=&quot;/usr/sbin/iptables&quot;

for T in filter nat mangle ; do
  $IPTABLES -t $T -F
  $IPTABLES -t $T -X
done

$IPTABLES -P INPUT DROP
$IPTABLES -P FORWARD ACCEPT
$IPTABLES -P OUTPUT ACCEPT

#Allow related and established on all interfaces (input)
$IPTABLES -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT

#Allow SSH, related and established $WANIF. Reject everything else.
$IPTABLES -A INPUT -i $WANIF -p tcp -m tcp --dport 22 -j ACCEPT
$IPTABLES -A INPUT -i $WANIF -j REJECT

#Allow related and established $WLANIF. Drop everything else.
$IPTABLES -A INPUT -i $WLANIF -j DROP

#Allow 3990 on other interfaces (input).
$IPTABLES -A INPUT -p tcp -m tcp --dport 3990 --syn -j ACCEPT

#Allow everything on loopback interface.
$IPTABLES -A INPUT -i lo -j ACCEPT

#Allow everything on $LANIF
$IPTABLES -A INPUT -i $LANIF -j ACCEPT

#Drop everything to and from $WLANIF (forward)
$IPTABLES -A FORWARD -i $WLANIF -j DROP
$IPTABLES -A FORWARD -o $WLANIF -j DROP

#Enable NAT on output device.
$IPTABLES -t nat -A POSTROUTING -o $WANIF -j MASQUERADE</code></pre></div><p>* Place the following login script &#039;hotspotlogin.cgi&#039; on your SSL and Perl-enabled web server with domain name www.mydomain.com:</p><div class="codebox"><pre><code>#!/usr/bin/perl

# chilli - ChilliSpot.org. A Wireless LAN Access Point Controller
# Copyright (C) 2003, 2004 Mondru AB.
#
# The contents of this file may be used under the terms of the GNU
# General Public License Version 2, provided that the above copyright
# notice and this permission notice is included in all copies or
# substantial portions of the software.

# Redirects from ChilliSpot daemon:
#
# Redirection when not yet or already authenticated
#   notyet:  ChilliSpot daemon redirects to login page.
#   already: ChilliSpot daemon redirects to success status page.
#
# Response to login:
#   already: Attempt to login when already logged in.
#   failed:  Login failed
#   success: Login succeded
#
# logoff:  Response to a logout


# Shared secret used to encrypt challenge with. Prevents dictionary attacks.
# You should change this to your own shared secret.
#$uamsecret = &quot;ht2eb8ej6s4et3rg1ulp&quot;;

# Uncomment the following line if you want to use ordinary user-password
# for radius authentication. Must be used together with $uamsecret.
#$userpassword=1;

# Our own path
$loginpath = $ENV{&#039;SCRIPT_URL&#039;};

use Digest::MD5  qw(md5 md5_hex md5_base64);

# Make sure that the form parameters are clean
$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
$| = 1;
if ($ENV{&#039;CONTENT_LENGTH&#039;}) {
    read (STDIN, $_, $ENV{&#039;CONTENT_LENGTH&#039;});
}
s/[^$OK_CHARS]/_/go;
$input = $_;


# Make sure that the get query parameters are clean
$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
$_ = $query=$ENV{QUERY_STRING};
s/[^$OK_CHARS]/_/go;
$query = $_;


# If she did not use https tell her that it was wrong.
if (!($ENV{HTTPS} =~ /^on$/)) {
    print &quot;Content-type: text/html\n\n
&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login Failed&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login Failed&lt;/h1&gt;
  &lt;center&gt;
    Login must use encrypted connection.
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;102&lt;/ResponseCode&gt;
&lt;ReplyMessage&gt;Login must use encrypted connection&lt;/ReplyMessage&gt;
&lt;/AuthenticationReply&gt; 
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}


#Read form parameters which we care about
@array = split(&#039;&amp;&#039;,$input);
foreach $var ( @array )
{
    @array2 = split(&#039;=&#039;,$var);
    if ($array2[0] =~ /^UserName$/) { $username = $array2[1]; }
    if ($array2[0] =~ /^Password$/) { $password = $array2[1]; }
    if ($array2[0] =~ /^challenge$/) { $challenge = $array2[1]; }
    if ($array2[0] =~ /^button$/) { $button = $array2[1]; }
    if ($array2[0] =~ /^logout$/) { $logout = $array2[1]; }
    if ($array2[0] =~ /^prelogin$/) { $prelogin = $array2[1]; }
    if ($array2[0] =~ /^res$/) { $res = $array2[1]; }
    if ($array2[0] =~ /^uamip$/) { $uamip = $array2[1]; }
    if ($array2[0] =~ /^uamport$/) { $uamport = $array2[1]; }
    if ($array2[0] =~ /^userurl$/)   { $userurl = $array2[1]; }
    if ($array2[0] =~ /^timeleft$/)  { $timeleft = $array2[1]; }
    if ($array2[0] =~ /^redirurl$/)  { $redirurl = $array2[1]; }
}

#Read query parameters which we care about
@array = split(&#039;&amp;&#039;,$query);
foreach $var ( @array )
{
    @array2 = split(&#039;=&#039;,$var);
    if ($array2[0] =~ /^res$/)       { $res = $array2[1]; }
    if ($array2[0] =~ /^challenge$/) { $challenge = $array2[1]; }
    if ($array2[0] =~ /^uamip$/)     { $uamip = $array2[1]; }
    if ($array2[0] =~ /^uamport$/)   { $uamport = $array2[1]; }
    if ($array2[0] =~ /^reply$/)     { $reply = $array2[1]; }
    if ($array2[0] =~ /^userurl$/)   { $userurl = $array2[1]; }
    if ($array2[0] =~ /^timeleft$/)  { $timeleft = $array2[1]; }
    if ($array2[0] =~ /^redirurl$/)  { $redirurl = $array2[1]; }
}


$reply =~ s/\+/ /g;
$reply =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$userurldecode = $userurl;
$userurldecode =~ s/\+/ /g;
$userurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$redirurldecode = $redirurl;
$redirurldecode =~ s/\+/ /g;
$redirurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$password =~ s/\+/ /g;
$password =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

# If attempt to login
if ($button =~ /^Login$/) {
    $hexchal  = pack &quot;H32&quot;, $challenge;
    if (defined $uamsecret) {
    $newchal  = md5($hexchal, $uamsecret);
    }
    else {
    $newchal  = $hexchal;
    }
    $response = md5_hex(&quot;\0&quot;, $password, $newchal);
    $pappassword = unpack &quot;H32&quot;, ($password ^ $newchal);
#sleep 5;
print &quot;Content-type: text/html\n\n&quot;;
print &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;&quot;;
    if ((defined $uamsecret) &amp;&amp; defined($userpassword)) {
    print &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword&amp;userurl=$userurl\&quot;&gt;&quot;;
    } else {
    print &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl\&quot;&gt;&quot;;
    }
print &quot;&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;&quot;;
  print &quot;&lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logging in to ChilliSpot&lt;/h1&gt;&quot;;
  print &quot;
  &lt;center&gt;
    Please wait......
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;201&lt;/ResponseCode&gt;
&quot;;
    if ((defined $uamsecret) &amp;&amp; defined($userpassword)) {
    print &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword&lt;/LoginResultsURL&gt;&quot;;
    } else {
    print &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl&lt;/LoginResultsURL&gt;&quot;;
    }
print &quot;&lt;/AuthenticationReply&gt; 
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}


# Default: It was not a form request
$result = 0;

# If login successful
if ($res =~ /^success$/) { 
    $result = 1;
}

# If login failed 
if ($res =~ /^failed$/) { 
    $result = 2;
}

# If logout successful
if ($res =~ /^logoff$/) { 
    $result = 3;
}

# If tried to login while already logged in
if ($res =~ /^already$/) { 
    $result = 4;
}

# If not logged in yet
if ($res =~ /^notyet$/) { 
    $result = 5;
}

# If login from smart client
if ($res =~ /^smartclient$/) { 
    $result = 6;
}

# If requested a logging in pop up window
if ($res =~ /^popup1$/) { 
    $result = 11;
}

# If requested a success pop up window
if ($res =~ /^popup2$/) { 
    $result = 12;
}

# If requested a logout pop up window
if ($res =~ /^popup3$/) { 
    $result = 13;
}


# Otherwise it was not a form request
# Send out an error message
if ($result == 0) {
    print &quot;Content-type: text/html\n\n
&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login Failed&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login Failed&lt;/h1&gt;
  &lt;center&gt;
    Login must be performed through ChilliSpot daemon.
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}

#Generate the output
print &quot;Content-type: text/html\n\n
&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;SCRIPT LANGUAGE=\&quot;JavaScript\&quot;&gt;
    var blur = 0;
    var starttime = new Date();
    var startclock = starttime.getTime();
    var mytimeleft = 0;

    function doTime() {
      window.setTimeout( \&quot;doTime()\&quot;, 1000 );
      t = new Date();
      time = Math.round((t.getTime() - starttime.getTime())/1000);
      if (mytimeleft) {
        time = mytimeleft - time;
        if (time &lt;= 0) {
          window.location = \&quot;$loginpath?res=popup3&amp;uamip=$uamip&amp;uamport=$uamport\&quot;;
        }
      }
      if (time &lt; 0) time = 0;
      hours = (time - (time % 3600)) / 3600;
      time = time - (hours * 3600);
      mins = (time - (time % 60)) / 60;
      secs = time - (mins * 60);
      if (hours &lt; 10) hours = \&quot;0\&quot; + hours;
      if (mins &lt; 10) mins = \&quot;0\&quot; + mins;
      if (secs &lt; 10) secs = \&quot;0\&quot; + secs;
      title = \&quot;Online time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      if (mytimeleft) {
        title = \&quot;Remaining time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      }
      if(document.all || document.getElementById){
         document.title = title;
      }
      else {   
        self.status = title;
      }
    }

    function popUp(URL) {
      if (self.name != \&quot;chillispot_popup\&quot;) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
    }

    function doOnLoad(result, URL, userurl, redirurl, timeleft) {
      if (timeleft) {
        mytimeleft = timeleft;
      }
      if ((result == 1) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
      }
      if ((result == 1) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
      if ((result == 2) || result == 5) {
        document.form1.UserName.focus()
      }
      if ((result == 2) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(&#039;&#039;, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=400,height=200&#039;);
        chillispot_popup.close();
      }
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
        if (redirurl) {
          opener.location = redirurl;
        }
        else if (userurl) {
          opener.location = userurl;
        }
        else if (opener.home) {
          opener.home();
        }
        else {
          opener.location = \&quot;about:home\&quot;;
        }
        self.focus();
        blur = 0;
      }
      if ((result == 13) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        self.focus();
        blur = 1;
      }
    }

    function doOnBlur(result) {
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        if (blur == 0) {
          blur = 1;
          self.focus();
        }
      }
    }
  &lt;/script&gt;
&lt;/head&gt;
&lt;body onLoad=\&quot;javascript:doOnLoad($result, &#039;$loginpath?res=popup2&amp;uamip=$uamip&amp;uamport=$uamport&amp;userurl=$userurl&amp;redirurl=$redirurl&amp;timeleft=$timeleft&#039;,&#039;$userurldecode&#039;, &#039;$redirurldecode&#039;, &#039;$timeleft&#039;)\&quot; onBlur = \&quot;javascript:doOnBlur($result)\&quot; bgColor = &#039;#c0d8f4&#039;&gt;&quot;;


#      if (!window.opener) {
#        document.bgColor = &#039;#c0d8f4&#039;;
#      }

#print &quot;THE INPUT: $input&quot;;
#foreach $key (sort (keys %ENV)) {
#    print $key, &#039; = &#039;, $ENV{$key}, &quot;&lt;br&gt;\n&quot;;
#}

if ($result == 2) {
    print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login Failed&lt;/h1&gt;&quot;;
    if ($reply) {
    print &quot;&lt;center&gt; $reply &lt;/BR&gt;&lt;/BR&gt;&lt;/center&gt;&quot;;
    }
}

if ($result == 5) {
    print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login&lt;/h1&gt;&quot;;
}

if ($result == 2 || $result == 5) {
  print &quot;
  &lt;form name=\&quot;form1\&quot; method=\&quot;post\&quot; action=\&quot;$loginpath\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;challenge\&quot; VALUE=\&quot;$challenge\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;uamip\&quot; VALUE=\&quot;$uamip\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;uamport\&quot; VALUE=\&quot;$uamport\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;userurl\&quot; VALUE=\&quot;$userurldecode\&quot;&gt;
  &lt;center&gt;
  &lt;table border=\&quot;0\&quot; cellpadding=\&quot;5\&quot; cellspacing=\&quot;0\&quot; style=\&quot;width: 217px;\&quot;&gt;
    &lt;tbody&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;Username:&lt;/td&gt;
        &lt;td&gt;&lt;input STYLE=\&quot;font-family: Arial\&quot; type=\&quot;text\&quot; name=\&quot;UserName\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;Password:&lt;/td&gt;
        &lt;td&gt;&lt;input STYLE=\&quot;font-family: Arial\&quot; type=\&quot;password\&quot; name=\&quot;Password\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;center\&quot; colspan=\&quot;2\&quot; height=\&quot;23\&quot;&gt;&lt;input type=\&quot;submit\&quot; name=\&quot;button\&quot; value=\&quot;Login\&quot; onClick=\&quot;javascript:popUp(&#039;$loginpath?res=popup1&amp;uamip=$uamip&amp;uamport=$uamport&#039;)\&quot;&gt;&lt;/td&gt; 
      &lt;/tr&gt;
    &lt;/tbody&gt;
  &lt;/table&gt;
  &lt;/center&gt;
  &lt;/form&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if ($result == 1) {
  print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logged in to ChilliSpot&lt;/h1&gt;&quot;;

  if ($reply) { 
      print &quot;&lt;center&gt; $reply &lt;/BR&gt;&lt;/BR&gt;&lt;/center&gt;&quot;;
  }

  print &quot;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;Logout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if (($result == 4) || ($result == 12)) {
  print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logged in to ChilliSpot&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;Logout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if ($result == 11) {
  print &quot;&lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logging in to ChilliSpot&lt;/h1&gt;&quot;;
  print &quot;
  &lt;center&gt;
    Please wait......
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if (($result == 3) || ($result == 13)) {
    print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logged out from ChilliSpot&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/prelogin\&quot;&gt;Login&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


exit(0);</code></pre></div><p>* - or place the following login script &#039;hotspotlogin.php&#039; on your SSL and PHP-enabled web server with domain name www.mydomain.com:</p><div class="codebox"><pre><code>&lt;?php
#
# chilli - ChilliSpot.org. A Wireless LAN Access Point Controller
# Copyright (C) 2003, 2004 Mondru AB.
#
# The contents of this file may be used under the terms of the GNU
# General Public License Version 2, provided that the above copyright
# notice and this permission notice is included in all copies or
# substantial portions of the software.

# Redirects from ChilliSpot daemon:
#
# Redirection when not yet or already authenticated
#   notyet:  ChilliSpot daemon redirects to login page.
#  already: ChilliSpot daemon redirects to success status page.
#
# Response to login:
#   already: Attempt to login when already logged in.
#   failed:  Login failed
#   success: Login succeded
#
# logoff:  Response to a logout


# Shared secret used to encrypt challenge with. Prevents dictionary attacks.
# You should change this to your own shared secret.
$uamsecret = &quot;ht2eb8ej6s4et3rg1ulp&quot;;

# Uncomment the following line if you want to use ordinary user-password
# for radius authentication. Must be used together with $uamsecret.
$userpassword=1;

# Our own path
$loginpath = $_SERVER[&#039;PHP_SELF&#039;];

$ChilliSpot=&quot;ChilliSpot&quot;;
$title=&quot;$ChilliSpot Login&quot;;
$centerUsername=&quot;Username&quot;;
$centerPassword=&quot;Password&quot;;
$centerLogin=&quot;Login&quot;;
$centerPleasewait=&quot;Please wait.......&quot;;
$centerLogout=&quot;Logout&quot;;
$h1Login=&quot;$ChilliSpot Login&quot;;
$h1Failed=&quot;$ChilliSpot Login Failed&quot;;
$h1Loggedin=&quot;Logged in to $ChilliSpot&quot;;
$h1Loggingin=&quot;Logging in to $ChilliSpot&quot;;
$h1Loggedout=&quot;Logged out from $ChilliSpot&quot;;
$centerdaemon=&quot;Login must be performed through $ChilliSpot daemon&quot;;
$centerencrypted=&quot;Login must use encrypted connection&quot;;


# Make sure that the form parameters are clean
#$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
#$_ = $input = &lt;STDIN&gt;;
#s/[^$OK_CHARS]/_/go;
#$input = $_;

# Make sure that the get query parameters are clean
#$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
#$_ = $query=$ENV{QUERY_STRING};
#s/[^$OK_CHARS]/_/go;
#$query = $_;


# If she did not use https tell her that it was wrong.
if (!($_ENV[&#039;HTTPS&#039;] == &#039;on&#039;)) {
#    echo &quot;Content-type: text/html\n\n&quot;;
echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Failed&lt;/h1&gt;
  &lt;center&gt;
    $centerencrypted
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;102&lt;/ResponseCode&gt;
&lt;ReplyMessage&gt;Login must use encrypted connection&lt;/ReplyMessage&gt;
&lt;/AuthenticationReply&gt;
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}


# Read form parameters which we care about
if (isset($_POST[&#039;UserName&#039;]))    $username    = $_POST[&#039;UserName&#039;];
if (isset($_POST[&#039;Password&#039;]))    $password    = $_POST[&#039;Password&#039;];
if (isset($_POST[&#039;challenge&#039;]))    $challenge    = $_POST[&#039;challenge&#039;];
if (isset($_POST[&#039;button&#039;]))    $button        = $_POST[&#039;button&#039;];
if (isset($_POST[&#039;logout&#039;]))    $logout        = $_POST[&#039;logout&#039;];
if (isset($_POST[&#039;prelogin&#039;]))    $prelogin    = $_POST[&#039;prelogin&#039;];
if (isset($_POST[&#039;res&#039;]))    $res        = $_POST[&#039;res&#039;];
if (isset($_POST[&#039;uamip&#039;]))    $uamip        = $_POST[&#039;uamip&#039;];
if (isset($_POST[&#039;uamport&#039;]))    $uamport    = $_POST[&#039;uamport&#039;];
if (isset($_POST[&#039;userurl&#039;]))    $userurl    = $_POST[&#039;userurl&#039;];
if (isset($_POST[&#039;timeleft&#039;]))    $timeleft    = $_POST[&#039;timeleft&#039;];
if (isset($_POST[&#039;redirurl&#039;]))    $redirurl    = $_POST[&#039;redirurl&#039;];

# Read query parameters which we care about
if (isset($_GET[&#039;res&#039;]))    $res        = $_GET[&#039;res&#039;];
if (isset($_GET[&#039;challenge&#039;]))    $challenge    = $_GET[&#039;challenge&#039;];
if (isset($_GET[&#039;uamip&#039;]))    $uamip        = $_GET[&#039;uamip&#039;];
if (isset($_GET[&#039;uamport&#039;]))    $uamport    = $_GET[&#039;uamport&#039;];
if (isset($_GET[&#039;reply&#039;]))    $reply        = $_GET[&#039;reply&#039;];
if (isset($_GET[&#039;userurl&#039;]))    $userurl    = $_GET[&#039;userurl&#039;];
if (isset($_GET[&#039;timeleft&#039;]))    $timeleft    = $_GET[&#039;timeleft&#039;];
if (isset($_GET[&#039;redirurl&#039;]))    $redirurl    = $_GET[&#039;redirurl&#039;];


#$reply =~ s/\+/ /g;
#$reply =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$userurldecode = $userurl;
#$userurldecode =~ s/\+/ /g;
#$userurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$redirurldecode = $redirurl;
#$redirurldecode =~ s/\+/ /g;
#$redirurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

#$password =~ s/\+/ /g;
#$password =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

# If attempt to login
if ($button == &#039;Login&#039;) {
  $hexchal = pack (&quot;H32&quot;, $challenge);
  if ($uamsecret) {
    $newchal = pack (&quot;H*&quot;, md5($hexchal . $uamsecret));
  } else {
    $newchal = $hexchal;
  }
  $response = md5(&quot;\0&quot; . $password . $newchal);
  $newpwd = pack(&quot;a32&quot;, $password);
  $pappassword = implode (&quot;&quot;, unpack(&quot;H32&quot;, ($newpwd ^ $newchal)));
# sleep 5;
# echo &#039;Content-type: text/html\n\n&#039;;
  echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;&quot;;
  if (isset($uamsecret) &amp;&amp; isset($userpassword)) {
    echo &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword\&quot;&gt;&quot;;
  } else {
    echo &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl\&quot;&gt;&quot;;
  }
  echo &quot;&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
&lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggingin&lt;/h1&gt;
  &lt;center&gt;
    $centerPleasewait
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;201&lt;/ResponseCode&gt;
&quot;;
  if (isset($uamsecret) &amp;&amp; isset($userpassword)) {
    echo &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword&lt;/LoginResultsURL&gt;&quot;;
  } else {
    echo &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl&lt;/LoginResultsURL&gt;&quot;;
  }
  echo &quot;&lt;/AuthenticationReply&gt; 
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}

switch($res) {
  case &#039;success&#039;:     $result =  1; break; // If login successful
  case &#039;failed&#039;:      $result =  2; break; // If login failed
  case &#039;logoff&#039;:      $result =  3; break; // If logout successful
  case &#039;already&#039;:     $result =  4; break; // If tried to login while already logged in
  case &#039;notyet&#039;:      $result =  5; break; // If not logged in yet
  case &#039;smartclient&#039;: $result =  6; break; // If login from smart client
  case &#039;popup1&#039;:      $result = 11; break; // If requested a logging in pop up window
  case &#039;popup2&#039;:      $result = 12; break; // If requested a success pop up window
  case &#039;popup3&#039;:      $result = 13; break; // If requested a logout pop up window
  default: $result = 0; // Default: It was not a form request
}

# Otherwise it was not a form request
# Send out an error message
if ($result == 0) {
#    echo &quot;Content-type: text/html\n\n&quot;;
    echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Failed&lt;/h1&gt;
  &lt;center&gt;
    $centerdaemon
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}

# Generate the output
#echo &quot;Content-type: text/html\n\n&quot;;
echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;SCRIPT LANGUAGE=\&quot;JavaScript\&quot;&gt;
    var blur = 0;
    var starttime = new Date();
    var startclock = starttime.getTime();
    var mytimeleft = 0;

    function doTime() {
      window.setTimeout( \&quot;doTime()\&quot;, 1000 );
      t = new Date();
      time = Math.round((t.getTime() - starttime.getTime())/1000);
      if (mytimeleft) {
        time = mytimeleft - time;
        if (time &lt;= 0) {
          window.location = \&quot;$loginpath?res=popup3&amp;uamip=$uamip&amp;uamport=$uamport\&quot;;
        }
      }
      if (time &lt; 0) time = 0;
      hours = (time - (time % 3600)) / 3600;
      time = time - (hours * 3600);
      mins = (time - (time % 60)) / 60;
      secs = time - (mins * 60);
      if (hours &lt; 10) hours = \&quot;0\&quot; + hours;
      if (mins &lt; 10) mins = \&quot;0\&quot; + mins;
      if (secs &lt; 10) secs = \&quot;0\&quot; + secs;
      title = \&quot;Online time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      if (mytimeleft) {
        title = \&quot;Remaining time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      }
      if(document.all || document.getElementById){
         document.title = title;
      }
      else {   
        self.status = title;
      }
    }

    function popUp(URL) {
      if (self.name != \&quot;chillispot_popup\&quot;) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
    }

    function doOnLoad(result, URL, userurl, redirurl, timeleft) {
      if (timeleft) {
        mytimeleft = timeleft;
      }
      if ((result == 1) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
      }
      if ((result == 1) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
      if ((result == 2) || result == 5) {
        document.form1.UserName.focus()
      }
      if ((result == 2) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(&#039;&#039;, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=400,height=200&#039;);
        chillispot_popup.close();
      }
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
        if (redirurl) {
          opener.location = redirurl;
        }
        else if (opener.home) {
          opener.home();
        }
        else {
          opener.location = \&quot;about:home\&quot;;
        }
        self.focus();
        blur = 0;
      }
      if ((result == 13) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        self.focus();
        blur = 1;
      }
    }

    function doOnBlur(result) {
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        if (blur == 0) {
          blur = 1;
          self.focus();
        }
      }
    }
  &lt;/script&gt;
&lt;/head&gt;
&lt;body onLoad=\&quot;javascript:doOnLoad($result, &#039;$loginpath?res=popup2&amp;uamip=$uamip&amp;uamport=$uamport&amp;userurl=$userurl&amp;redirurl=$redirurl&amp;timeleft=$timeleft&#039;,&#039;$userurldecode&#039;, &#039;$redirurldecode&#039;, &#039;$timeleft&#039;)\&quot; onBlur = &#039;javascript:doOnBlur($result)&#039; bgColor = &#039;#c0d8f4&#039;&gt;&quot;;

/*# begin debugging
  print &quot;&lt;center&gt;THE INPUT (for debugging):&lt;br&gt;&quot;;
  foreach ($_GET as $key =&gt; $value) {
    print $key . &quot;=&quot; . $value . &quot;&lt;br&gt;&quot;;
  }
  print &quot;&lt;br&gt;&lt;/center&gt;&quot;;
# end debugging
*/
if ($result == 2) {
    echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Failed&lt;/h1&gt;&quot;;
    if ($reply) {
    echo &quot;&lt;center&gt; $reply &lt;/BR&gt;&lt;/BR&gt;&lt;/center&gt;&quot;;
    }
}

if ($result == 5) {
    echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Login&lt;/h1&gt;&quot;;
}

if ($result == 2 || $result == 5) {
  echo &quot;
  &lt;form name=\&quot;form1\&quot; method=\&quot;post\&quot; action=\&quot;$loginpath\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;challenge\&quot; value=\&quot;$challenge\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;uamip\&quot; value=\&quot;$uamip\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;uamport\&quot; value=\&quot;$uamport\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;userurl\&quot; value=\&quot;$userurl\&quot;&gt;
  &lt;center&gt;
  &lt;table border=\&quot;0\&quot; cellpadding=\&quot;5\&quot; cellspacing=\&quot;0\&quot; style=\&quot;width: 217px;\&quot;&gt;
    &lt;tbody&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;$centerUsername:&lt;/td&gt;
        &lt;td&gt;&lt;input style=\&quot;font-family: Arial\&quot; type=\&quot;text\&quot; name=\&quot;UserName\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;$centerPassword:&lt;/td&gt;
        &lt;td&gt;&lt;input style=\&quot;font-family: Arial\&quot; type=\&quot;password\&quot; name=\&quot;Password\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;center\&quot; colspan=\&quot;2\&quot; height=\&quot;23\&quot;&gt;&lt;input type=\&quot;submit\&quot; name=\&quot;button\&quot; value=\&quot;Login\&quot; onClick=\&quot;javascript:popUp(&#039;$loginpath?res=popup1&amp;uamip=$uamip&amp;uamport=$uamport&#039;)\&quot;&gt;&lt;/td&gt; 
      &lt;/tr&gt;
    &lt;/tbody&gt;
  &lt;/table&gt;
  &lt;/center&gt;
  &lt;/form&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if ($result == 1) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggedin&lt;/h1&gt;&quot;;

  if ($reply) { 
      echo &quot;&lt;center&gt; $reply &lt;/br&gt;&lt;/br&gt;&lt;/center&gt;&quot;;
  }

  echo &quot;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;Logout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if (($result == 4) || ($result == 12)) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggedin&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;$centerLogout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if ($result == 11) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggingin&lt;/h1&gt;
  &lt;center&gt;
    $centerPleasewait
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if (($result == 3) || ($result == 13)) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggedout&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/prelogin\&quot;&gt;$centerLogin&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

exit(0);
?&gt;</code></pre></div><p><strong><span class="bbu">Freeradius config</span></strong></p><p>* Change the following attributes in /etc/freeradius/radiusd.conf to use Freeradius with a MySQL backend:</p><p>authorize {<br />&nbsp; &nbsp; sql</p><p>}</p><p>authenticate {<br />&nbsp; &nbsp; Auth-Type PAP {<br />&nbsp; &nbsp; &nbsp; &nbsp; pap<br />&nbsp; &nbsp; }<br />}</p><p>accounting {<br />&nbsp; &nbsp; sql<br />}</p><p>session {<br />&nbsp; &nbsp; sql<br />}</p><br /><p>* Change the following attributes in /etc/freeradius/sql.conf</p><p>sql {<br />&nbsp; &nbsp; driver = &quot;rlm_sql_mysql&quot;</p><p>&nbsp; &nbsp; server = &quot;&lt;replace with the name of your database server&gt;&quot;<br />&nbsp; &nbsp; login = &quot;&lt;replace with your database user login&gt;&quot;<br />&nbsp; &nbsp; password = &quot;&lt;replace with your database user password&gt;&quot;<br />&nbsp; &nbsp; radius_db = &quot;&lt;replace with your database name&gt;&quot;</p><p>&nbsp; &nbsp; # Uncomment simul_count_query to enable simultaneous use checking<br />&nbsp; &nbsp; simul_count_query = &quot;SELECT COUNT(*) FROM ${acct_table1} WHERE UserName=&#039;%{SQL-User-Name}&#039; AND AcctStopTime = 0&quot;</p><p>&nbsp; &nbsp; readclients = yes<br />}</p><br /><p>* Install the Freeradius tables in the MySQL database on the domain mysql.mydomain.com, and configure a test user:</p><p><strong>raduserinfo</strong></p><p>UserName = &#039;testuser&#039;</p><p><strong>radcheck for &#039;testuser&#039;</strong></p><p>User-Password := &#039;password&#039;<br />Auth-Type := &#039;PAP&#039;<br />Simultaneous-Use := 1</p><p><strong>radreply for &#039;testuser&#039;</strong></p><p>Idle-Timeout := 1800</p><br /><br /><p><strong><span class="bbu">NTP config</span></strong></p><p>* Change the attributes in /etc/TZ to match your time zone, for instance:</p><p>CET-1</p><br /><br /><p><strong><span class="bbu">Monit config</span></strong></p><p>* Change the following attributes in /etc/monitrc:</p><p> set mailserver smtp.mymailserver.com<br /> set mail-format { from: monit@mydomain.com }<br /> set alert monit@mydomain.com<br /> set httpd port 2812 and<br />&nbsp; &nbsp; &nbsp;allow admin:monit&nbsp; &nbsp; &nbsp;# user &#039;admin&#039; with password &#039;monit&#039;</p><p> check process chilli with pidfile /var/run/chilli.pid<br />&nbsp; &nbsp;start program = &quot;/etc/init.d/chilli start&quot;<br />&nbsp; &nbsp;stop program = &quot;/etc/init.d/chilli stop&quot;</p><p> check process radiusd with pidfile /var/run/radiusd.pid<br />&nbsp; &nbsp;start program = &quot;/etc/init.d/radiusd start&quot;<br />&nbsp; &nbsp;stop program = &quot;/etc/init.d/radiusd stop&quot;</p><p> check host www.mydomain.com with address www.mydomain.com<br />&nbsp; &nbsp;if failed port 80 protocol http<br />&nbsp; &nbsp; &nbsp; and request &quot;/hotspotlogin.cgi&quot; then alert</p><p> check host mysql.mydomain.com with address mysql.mydomain.com<br />&nbsp; &nbsp;if failed port 3306 protocol mysql then alert</p><br /><br /><p><strong><span class="bbu">Testing the setup</span></strong></p><p>* Start your WEB browser, and write &#039;testuser&#039;/&#039;password&#039; in the WEB page that appears. If you have configured everything correctly, you should be authenticated.</p><p>* If anything fails, connect your PC to one of the LAN ports on the router and start two SSH sessions, one with Chillispot and the other with Freeradius, both in foreground debug mode:</p><p>chilli -fd</p><p>radiusd -X</p><br /><p>Establish a wireless connection to your WLAN and watch the outputs carefully to debug your setup.</p><br /><br /><p>Have fun!</p>]]></description>
			<author><![CDATA[null@example.com (ajauberg)]]></author>
			<pubDate>Thu, 15 Jan 2009 08:35:33 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic282-howto-a-captive-portal-using-kamikaze-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[PepperSpot : next generation captive portal]]></title>
			<link>http://www.chillispot.org/chilliforum/topic244-pepperspot-next-generation-captive-portal-new-posts.html</link>
			<description><![CDATA[<p>Hello everyone,</p><p>I don&#039;t know if it is the right place to talk about it here but I announce that a new captive portal forked from Chillispot is available : PepperSpot.</p><p>This project has started in the Louis Pasteur university, Strasbourg, France. We fix some bugs and cleanup code, but the main &quot;new&quot; functionnality is IPv6 support. PepperSpot can provide IPv6 access for authenticated user (via login pages or WPA). </p><p>The source code can be downloaded from sourceforge website : https://sourceforge.net/projects/pepperspot/</p><p>Any feedback is very welcome in order to improve our implementation.</p><p>Best regards,<br />Sebastien Vincent<br />Network Research Team, University of Strasbourg, France </p><p>---<br />Technical details : <br />- IPv6 platform uses Router Advertisement (RA) to autoconfigure client IPv6 address (no DHCP);<br />- PepperSpot can do authentication with IPv6 Radius server (i.e. Freeradius &gt;= 2.0);<br />- PepperSpot needs a delegate IPv6 prefix to work (as in IPv6 there is no NAT support in Linux&#039;s ip6tables);<br />- Setting routing daemon (rip, ospf, ...) on the captive portal (i.e. Quagga) is strongly recommended, but static configuration also work;<br />- Respect POSIX + XSI standards as much as possible (we update some part);</p><p>A howto is available in the README file of PepperSpot archive / SVN.</p>]]></description>
			<author><![CDATA[null@example.com (ping6)]]></author>
			<pubDate>Tue, 21 Oct 2008 11:27:43 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic244-pepperspot-next-generation-captive-portal-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[ASP.NET Server]]></title>
			<link>http://www.chillispot.org/chilliforum/topic206-aspnet-server-new-posts.html</link>
			<description><![CDATA[<p>Hi, I hope you can help me with this because it&#039;s been driving me crazy.</p><br /><p>Ok, </p><p>I am implementing a Radius Server in C# which connects to an acccess point running Chillispot. It&#039;s working ok and I can do things like setting the Iddle Timeout, SessionTimeout, etc, but when I try to set the MaxBandwidth attiribute, Chillispot does not seem to understand the response I return and keeps sending me the AccessRequest message, so the user cant connect through it.</p><p>The attribute I am setting is the WISPr, setting the VendorType to BandwidthMaxUp (code 7). If I modify&nbsp; the API so it&nbsp; matches with the RFC 2865(http://www.faqs.org/rfcs/rfc2865.html), it still doesnt work.</p><p>Is there any documentation about how I have to specify this attribute? (another RFC, maybe Chillispot uses some different protocol or something,etc). Maybe some really compatible API you know?</p><br /><p>thanks in advance for your help...</p><br /><p>zimzum</p>]]></description>
			<author><![CDATA[null@example.com (zimzum)]]></author>
			<pubDate>Thu, 24 Jul 2008 22:24:39 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic206-aspnet-server-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[I need an screen print.]]></title>
			<link>http://www.chillispot.org/chilliforum/topic161-i-need-an-screen-print-new-posts.html</link>
			<description><![CDATA[<p>Hello everybody,<br />If someone can help me I need a screen print to chillispot when the page is blue and when they ask us the log and the password.<br />Thanks.</p>]]></description>
			<author><![CDATA[null@example.com (toto)]]></author>
			<pubDate>Sat, 12 Apr 2008 14:31:53 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic161-i-need-an-screen-print-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[daloRADIUS 0.9-5 Released!]]></title>
			<link>http://www.chillispot.org/chilliforum/topic91-daloradius-095-released-new-posts.html</link>
			<description><![CDATA[<p>Hey guys,</p><p>i&#039;m not sure how many of you are aware of daloRADIUS, the management platform for RADIUS deployments.<br />daloRADIUS is an advanced RADIUS web management application aimed at managing hotspots and general-purpose <br />ISP deployments. It features user management, graphical reporting, accounting, a billing engine and integrates with <br />GoogleMaps for geo-locating</p><br /><p>Homepage:&nbsp; &nbsp;http://sourceforge.net/projects/daloradius/<br />Wiki page:&nbsp; &nbsp; &nbsp;http://daloradius.wiki.sourceforge.net/<br />Screenshots: http://sourceforge.net/project/screenshots.php?group_id=193562</p><br /><br /><br /><br /><p>&nbsp; &nbsp; * Changelog for Release 0.9.5<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added improved support for sql db queries<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added new contact info for hotspot owners<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added more attributes and ordered existing<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added support to relate users to groups on new user, batch add user and new quick-add users pages<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; as well as editing these groups entries in edit user page<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added suport for database debugging and error handling<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added custom accounting query page<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added disconnect user on maintenance sub-category<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added partial tabindexs support to forms (Antonis Faragitakis)<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added description dialogs for pages upon clicking on page titles<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added and improved new blue css layout<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - added icons and support for deleting single attributes for users<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; in the Edit User management page<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - improved interface with addition of checkboxs for multi-action tasks<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - improved online help support for each page<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - improved support on Test User Connectivity to use radclient with more features<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - improved support on all sidebar input values so that variables are saved when<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; the pages are reloaded/submitted to a new page<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - fixed double-insert records of userinfo data if user exists<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - fixed deleting of userinfo data for a record that is being deleted<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - fixed drawing the options selectbox in the radreply tab in User Edit page<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - fixed saving an existing nas entry in different name (not having to delete it)<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - fixed several typos and variable declerations through-out the pages<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - fixed duplicate groups entries in usergroup table (paparent)<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - language file and variables are better sorted out (finally)<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; - alot of php/html code clean up and code indentation</p><br /><br /><p>Plans for the upcoming 0.9-6 release:</p><p>&nbsp; &nbsp; * A whole re-work of the attributes management is coming in - I&#039;ve already started coding it, based on ajax, the new attributes management is going to be a life saver easy, include tooltips, recommended OP and target table (radcheck/radreply),<br />&nbsp; &nbsp; &nbsp; as well as a helper routine. Definitely something worth waiting for...<br />&nbsp; &nbsp; * More Ajax and more improvements to the GUI layout, more icons</p><br /><br /><br /><p>I&#039;d love to get some feedback.</p><p>Merry Christmas,<br />Liran.</p>]]></description>
			<author><![CDATA[null@example.com (liri)]]></author>
			<pubDate>Tue, 25 Dec 2007 08:35:58 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic91-daloradius-095-released-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[PHP-version of login page]]></title>
			<link>http://www.chillispot.org/chilliforum/topic90-phpversion-of-login-page-new-posts.html</link>
			<description><![CDATA[<p>Hi,</p><p>I have included a PHP-version of the login page in the following howto:</p><p>http://www.chillispot.info/chilliforum/viewtopic.php?id=18</p>]]></description>
			<author><![CDATA[null@example.com (ajauberg)]]></author>
			<pubDate>Sun, 23 Dec 2007 10:38:29 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic90-phpversion-of-login-page-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[Hotcakes Hotspot Manager]]></title>
			<link>http://www.chillispot.org/chilliforum/topic48-hotcakes-hotspot-manager-new-posts.html</link>
			<description><![CDATA[<p>Hi All, </p><p>Many thanks for bringing this site back.</p><p>Those who are looking for a Hotspot management solution are just in time for the new Beta-5.</p><p>Lots of new features, documentation included, and GPL naturally <img src="http://www.chillispot.org/chilliforum/img/smilies/smile.png" width="15" height="15" alt="smile" /></p><p>New with this release<br />1.)Multi user levels (Admin, Cashier, Client)<br />2.)Client&#039;s own personal page.<br />3.)Realms</p>]]></description>
			<author><![CDATA[null@example.com (dvdwalt)]]></author>
			<pubDate>Mon, 12 Nov 2007 10:40:07 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic48-hotcakes-hotspot-manager-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[[HOWTO] Setting up OpenWRT as a captive portal on WRT54GL]]></title>
			<link>http://www.chillispot.org/chilliforum/topic18-howto-setting-up-openwrt-as-a-captive-portal-on-wrt54gl-new-posts.html</link>
			<description><![CDATA[<p><strong><span class="bbu">[HOWTO] Setting up OpenWRT as a captive portal on WRT54GL</span></strong></p><p>This howto explains using a WRT54GL with OpenWRT as a captive portal for controlling user access to the Internet. <br />The configuration of a remote wireless router for repeating the signal is also shown.</p><p>In addition to OpenWRT the Freeradius and Chillispot packages are used.</p><p>At present this configuration only covers NVRAM settings on Whiterussian. <br />Do also note that the NVRAM settings can be applied on other routers than the WRT54GL, <br />but the interfaces for WIFI etc. may be different.</p><br /><p><strong><span class="bbu">Default settings</span></strong></p><p>The default bridging is set up as follows:</p><p> </p><div class="codebox"><pre><code>  (192.168.1.0/24) 
 |   |    |  |  \|/
 +--vlan0-+--+  eth1
     |           |
     +----br0----+ 
           | 
      &lt;userspace&gt;</code></pre></div><p>- vlan0 is used for bridging all the LAN ports<br />- eth1 is used for the WIFI interface<br />- br0 is bridging the WIFI and LAN interface</p><p>* On a WRT54GL the NVRAM settings for this can be found as follows:</p><p>lan_ifname=br0<br />lan_ifnames=vlan0 eth1</p><br /><br /><p><strong><span class="bbu">Creating the captive portal interface</span></strong></p><p>The most important thing when creating a captive portal is to create a separate interface where users<br />can authenticate themselves. This is done by creating a separate bridge that contains the interfaces that <br />we need. In the example we also want to include WDS to extend the range of our wireless network. <br />The &#039;br0&#039; bridge is used for wireless, and we create a separate bridge &#039;br1&#039; for the LAN interface:</p><br /><p> </p><div class="codebox"><pre><code>(192.168.1.0/24)  (192.168.182.0/24) 
|   |    |  |         \|/     \|/
+--vlan0-+--+         eth1    wds
    |                  |       |
   br1                 +--br0--+
    |                      |
    |                 &lt;Chillispot&gt;    
    |                      | 
    |                     tun0
    +-------+    +---------+ 
            |    | 
         &lt;userspace&gt;</code></pre></div><p>- vlan0 is used for bridging all the LAN ports<br />- eth1 is used for the WIFI interface<br />- wds is used for extending the WIFI range using WDS<br />- br0 is the bridge that the captive portal (Chillispot) uses<br />- br1 is a new bridge for the LAN interface</p><br /><p>* The LAN interface is then configured using the new bridge:</p><p>lan_ifname=br1<br />lan_ifnames=vlan0</p><br /><p>* The existing bridge is then used for the wireless interface. For every WDS client that we want to<br />add, we add a new wds0.xxxxx interface, starting at wds0.49153:</p><p>wifi_ifname=br0<br />wifi_ifnames=eth1 wds0.49153 wds0.49154 wds0.49155</p><br /><p>* In addition, the Spanning Tree Protocol is set to avoid circular bridges when using WDS:</p><p>wifi_stp=1</p><br /><p>* We use manual WDS and disables Lazy WDS, and adds the MAC address for all wireless routers<br />that we want to communicate with:</p><p>wl0_lazywds=0<br />wl0_wds=xx:xx:xx:xx:xx:xx yy:yy:yy:yy:yy:yy zz:zz:zz:zz:zz:zz</p><br /><br /><p><strong><span class="bbu">Installing the necessary packages</span></strong></p><p>* First we need to update the ipkg directory to get a list of all our packages:</p><p>ipkg update</p><br /><p>* Chillispot is used as our captive portal, so install it:</p><p>ipkg install chillispot</p><br /><p>* Freeradius receives RADIUS authentication requests from Chillispot, and we use plain password authentication:</p><p>ipkg install freeradius-mod-pap</p><br /><p>* Freeradius stores all users and attributes in a MySQL database:</p><p>ipkg install freeradius-mod-sql-mysql</p><br /><p>* To be able to keep track of the correct time we use NTP:</p><p>ipkg install openntpd <br />ipkg install ntpclient</p><br /><p>* Monit keeps track of process status, and can restart the processes if they stop</p><p>ipkg install monit</p><br /><p>Note that all packages have dependencies, and dependant packages will be installed as well</p><br /><br /><p><strong><span class="bbu">Chillispot config</span></strong></p><p>* Change the following parameters in /etc/chilli.conf:</p><p>interval 3600<br />pidfile /var/run/chilli.pid</p><p>radiuslisten 127.0.0.1<br />radiusserver1 127.0.0.1<br />radiusserver2 127.0.0.1<br />radiussecret testing123</p><p>dhcpif br0</p><p>uamserver https://www.mydomain.com/hotspotlogin.cgi<br />uamsecret ht2eb8ej6s4et3rg1ulp<br />uamallowed www.mydomain.com,www.paypal.com,paypal.com,www.paypalobjects.com,paypalobjects.com,64.4.240.0/20,216.113.160.0/19<br />uamanydns</p><br /><p>* Replace the /etc/init.d/S35firewall file with the following file:</p><div class="codebox"><pre><code>#!/bin/sh
#
# Firewall script for ChilliSpot on OpenWRT
#
# Uses $WANIF (vlan1) as the external interface (Internet or intranet) and
# $WLANIF (eth1) as the internal interface (access point).
# $LANIF is used as a trusted management interface.
#
# SUMMARY
# * All connections originating from ChilliSpot are allowed.
# * Nothing is allowed in on WAN interface.
# * Nothing is allowed in on WLAN interface.
# * Everything is allowed in on LAN interface.
# * Forwarding is allowed to and from WAN interface, but disallowed
#   to and from the WLAN interface.
# * NAT is enabled on the WAN interface.

. /etc/functions.sh

WANIF=$(nvram get wan_ifname)
WLANIF=$(nvram get wifi_ifname)
LANIF=$(nvram get lan_ifname)

IPTABLES=&quot;/usr/sbin/iptables&quot;

for T in filter nat mangle ; do
  $IPTABLES -t $T -F
  $IPTABLES -t $T -X
done

$IPTABLES -P INPUT DROP
$IPTABLES -P FORWARD ACCEPT
$IPTABLES -P OUTPUT ACCEPT

#Allow related and established on all interfaces (input)
$IPTABLES -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT

#Allow SSH, related and established $WANIF. Reject everything else.
$IPTABLES -A INPUT -i $WANIF -p tcp -m tcp --dport   22 -j ACCEPT
$IPTABLES -A INPUT -i $WANIF -j REJECT

#Allow satellite WDSs, related and established $WLANIF. Drop everything else.
$IPTABLES -A INPUT -i $WLANIF -j DROP

#Allow 3990 on other interfaces (input).
$IPTABLES -A INPUT -p tcp -m tcp --dport 3990 --syn -j ACCEPT

#Allow everything on loopback interface.
$IPTABLES -A INPUT -i lo -j ACCEPT

#Allow everything on $LANIF
$IPTABLES -A INPUT -i $LANIF -j ACCEPT

#Drop everything to and from $WLANIF (forward)
$IPTABLES -A FORWARD -i $WLANIF -j DROP
$IPTABLES -A FORWARD -o $WLANIF -j DROP

#Enable NAT on output device.
$IPTABLES -t nat -A POSTROUTING -o $WANIF -j MASQUERADE</code></pre></div><p>* Place the following login script &#039;hotspotlogin.cgi&#039; on your SSL and Perl-enabled web server with domain name www.mydomain.com:</p><div class="codebox"><pre><code>#!/usr/bin/perl

# chilli - ChilliSpot.org. A Wireless LAN Access Point Controller
# Copyright (C) 2003, 2004 Mondru AB.
#
# The contents of this file may be used under the terms of the GNU
# General Public License Version 2, provided that the above copyright
# notice and this permission notice is included in all copies or
# substantial portions of the software.

# Redirects from ChilliSpot daemon:
#
# Redirection when not yet or already authenticated
#   notyet:  ChilliSpot daemon redirects to login page.
#   already: ChilliSpot daemon redirects to success status page.
#
# Response to login:
#   already: Attempt to login when already logged in.
#   failed:  Login failed
#   success: Login succeded
#
# logoff:  Response to a logout


# Shared secret used to encrypt challenge with. Prevents dictionary attacks.
# You should change this to your own shared secret.
#$uamsecret = &quot;ht2eb8ej6s4et3rg1ulp&quot;;

# Uncomment the following line if you want to use ordinary user-password
# for radius authentication. Must be used together with $uamsecret.
#$userpassword=1;

# Our own path
$loginpath = $ENV{&#039;SCRIPT_URL&#039;};

use Digest::MD5  qw(md5 md5_hex md5_base64);

# Make sure that the form parameters are clean
$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
$| = 1;
if ($ENV{&#039;CONTENT_LENGTH&#039;}) {
    read (STDIN, $_, $ENV{&#039;CONTENT_LENGTH&#039;});
}
s/[^$OK_CHARS]/_/go;
$input = $_;


# Make sure that the get query parameters are clean
$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
$_ = $query=$ENV{QUERY_STRING};
s/[^$OK_CHARS]/_/go;
$query = $_;


# If she did not use https tell her that it was wrong.
if (!($ENV{HTTPS} =~ /^on$/)) {
    print &quot;Content-type: text/html\n\n
&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login Failed&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login Failed&lt;/h1&gt;
  &lt;center&gt;
    Login must use encrypted connection.
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;102&lt;/ResponseCode&gt;
&lt;ReplyMessage&gt;Login must use encrypted connection&lt;/ReplyMessage&gt;
&lt;/AuthenticationReply&gt; 
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}


#Read form parameters which we care about
@array = split(&#039;&amp;&#039;,$input);
foreach $var ( @array )
{
    @array2 = split(&#039;=&#039;,$var);
    if ($array2[0] =~ /^UserName$/) { $username = $array2[1]; }
    if ($array2[0] =~ /^Password$/) { $password = $array2[1]; }
    if ($array2[0] =~ /^challenge$/) { $challenge = $array2[1]; }
    if ($array2[0] =~ /^button$/) { $button = $array2[1]; }
    if ($array2[0] =~ /^logout$/) { $logout = $array2[1]; }
    if ($array2[0] =~ /^prelogin$/) { $prelogin = $array2[1]; }
    if ($array2[0] =~ /^res$/) { $res = $array2[1]; }
    if ($array2[0] =~ /^uamip$/) { $uamip = $array2[1]; }
    if ($array2[0] =~ /^uamport$/) { $uamport = $array2[1]; }
    if ($array2[0] =~ /^userurl$/)   { $userurl = $array2[1]; }
    if ($array2[0] =~ /^timeleft$/)  { $timeleft = $array2[1]; }
    if ($array2[0] =~ /^redirurl$/)  { $redirurl = $array2[1]; }
}

#Read query parameters which we care about
@array = split(&#039;&amp;&#039;,$query);
foreach $var ( @array )
{
    @array2 = split(&#039;=&#039;,$var);
    if ($array2[0] =~ /^res$/)       { $res = $array2[1]; }
    if ($array2[0] =~ /^challenge$/) { $challenge = $array2[1]; }
    if ($array2[0] =~ /^uamip$/)     { $uamip = $array2[1]; }
    if ($array2[0] =~ /^uamport$/)   { $uamport = $array2[1]; }
    if ($array2[0] =~ /^reply$/)     { $reply = $array2[1]; }
    if ($array2[0] =~ /^userurl$/)   { $userurl = $array2[1]; }
    if ($array2[0] =~ /^timeleft$/)  { $timeleft = $array2[1]; }
    if ($array2[0] =~ /^redirurl$/)  { $redirurl = $array2[1]; }
}


$reply =~ s/\+/ /g;
$reply =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$userurldecode = $userurl;
$userurldecode =~ s/\+/ /g;
$userurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$redirurldecode = $redirurl;
$redirurldecode =~ s/\+/ /g;
$redirurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$password =~ s/\+/ /g;
$password =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

# If attempt to login
if ($button =~ /^Login$/) {
    $hexchal  = pack &quot;H32&quot;, $challenge;
    if (defined $uamsecret) {
    $newchal  = md5($hexchal, $uamsecret);
    }
    else {
    $newchal  = $hexchal;
    }
    $response = md5_hex(&quot;\0&quot;, $password, $newchal);
    $pappassword = unpack &quot;H32&quot;, ($password ^ $newchal);
#sleep 5;
print &quot;Content-type: text/html\n\n&quot;;
print &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;&quot;;
    if ((defined $uamsecret) &amp;&amp; defined($userpassword)) {
    print &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword&amp;userurl=$userurl\&quot;&gt;&quot;;
    } else {
    print &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl\&quot;&gt;&quot;;
    }
print &quot;&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;&quot;;
  print &quot;&lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logging in to ChilliSpot&lt;/h1&gt;&quot;;
  print &quot;
  &lt;center&gt;
    Please wait......
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;201&lt;/ResponseCode&gt;
&quot;;
    if ((defined $uamsecret) &amp;&amp; defined($userpassword)) {
    print &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword&lt;/LoginResultsURL&gt;&quot;;
    } else {
    print &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl&lt;/LoginResultsURL&gt;&quot;;
    }
print &quot;&lt;/AuthenticationReply&gt; 
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}


# Default: It was not a form request
$result = 0;

# If login successful
if ($res =~ /^success$/) { 
    $result = 1;
}

# If login failed 
if ($res =~ /^failed$/) { 
    $result = 2;
}

# If logout successful
if ($res =~ /^logoff$/) { 
    $result = 3;
}

# If tried to login while already logged in
if ($res =~ /^already$/) { 
    $result = 4;
}

# If not logged in yet
if ($res =~ /^notyet$/) { 
    $result = 5;
}

# If login from smart client
if ($res =~ /^smartclient$/) { 
    $result = 6;
}

# If requested a logging in pop up window
if ($res =~ /^popup1$/) { 
    $result = 11;
}

# If requested a success pop up window
if ($res =~ /^popup2$/) { 
    $result = 12;
}

# If requested a logout pop up window
if ($res =~ /^popup3$/) { 
    $result = 13;
}


# Otherwise it was not a form request
# Send out an error message
if ($result == 0) {
    print &quot;Content-type: text/html\n\n
&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login Failed&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login Failed&lt;/h1&gt;
  &lt;center&gt;
    Login must be performed through ChilliSpot daemon.
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}

#Generate the output
print &quot;Content-type: text/html\n\n
&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;ChilliSpot Login&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;SCRIPT LANGUAGE=\&quot;JavaScript\&quot;&gt;
    var blur = 0;
    var starttime = new Date();
    var startclock = starttime.getTime();
    var mytimeleft = 0;

    function doTime() {
      window.setTimeout( \&quot;doTime()\&quot;, 1000 );
      t = new Date();
      time = Math.round((t.getTime() - starttime.getTime())/1000);
      if (mytimeleft) {
        time = mytimeleft - time;
        if (time &lt;= 0) {
          window.location = \&quot;$loginpath?res=popup3&amp;uamip=$uamip&amp;uamport=$uamport\&quot;;
        }
      }
      if (time &lt; 0) time = 0;
      hours = (time - (time % 3600)) / 3600;
      time = time - (hours * 3600);
      mins = (time - (time % 60)) / 60;
      secs = time - (mins * 60);
      if (hours &lt; 10) hours = \&quot;0\&quot; + hours;
      if (mins &lt; 10) mins = \&quot;0\&quot; + mins;
      if (secs &lt; 10) secs = \&quot;0\&quot; + secs;
      title = \&quot;Online time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      if (mytimeleft) {
        title = \&quot;Remaining time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      }
      if(document.all || document.getElementById){
         document.title = title;
      }
      else {   
        self.status = title;
      }
    }

    function popUp(URL) {
      if (self.name != \&quot;chillispot_popup\&quot;) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
    }

    function doOnLoad(result, URL, userurl, redirurl, timeleft) {
      if (timeleft) {
        mytimeleft = timeleft;
      }
      if ((result == 1) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
      }
      if ((result == 1) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
      if ((result == 2) || result == 5) {
        document.form1.UserName.focus()
      }
      if ((result == 2) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(&#039;&#039;, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=400,height=200&#039;);
        chillispot_popup.close();
      }
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
        if (redirurl) {
          opener.location = redirurl;
        }
        else if (userurl) {
          opener.location = userurl;
        }
        else if (opener.home) {
          opener.home();
        }
        else {
          opener.location = \&quot;about:home\&quot;;
        }
        self.focus();
        blur = 0;
      }
      if ((result == 13) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        self.focus();
        blur = 1;
      }
    }

    function doOnBlur(result) {
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        if (blur == 0) {
          blur = 1;
          self.focus();
        }
      }
    }
  &lt;/script&gt;
&lt;/head&gt;
&lt;body onLoad=\&quot;javascript:doOnLoad($result, &#039;$loginpath?res=popup2&amp;uamip=$uamip&amp;uamport=$uamport&amp;userurl=$userurl&amp;redirurl=$redirurl&amp;timeleft=$timeleft&#039;,&#039;$userurldecode&#039;, &#039;$redirurldecode&#039;, &#039;$timeleft&#039;)\&quot; onBlur = \&quot;javascript:doOnBlur($result)\&quot; bgColor = &#039;#c0d8f4&#039;&gt;&quot;;


#      if (!window.opener) {
#        document.bgColor = &#039;#c0d8f4&#039;;
#      }

#print &quot;THE INPUT: $input&quot;;
#foreach $key (sort (keys %ENV)) {
#    print $key, &#039; = &#039;, $ENV{$key}, &quot;&lt;br&gt;\n&quot;;
#}

if ($result == 2) {
    print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login Failed&lt;/h1&gt;&quot;;
    if ($reply) {
    print &quot;&lt;center&gt; $reply &lt;/BR&gt;&lt;/BR&gt;&lt;/center&gt;&quot;;
    }
}

if ($result == 5) {
    print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;ChilliSpot Login&lt;/h1&gt;&quot;;
}

if ($result == 2 || $result == 5) {
  print &quot;
  &lt;form name=\&quot;form1\&quot; method=\&quot;post\&quot; action=\&quot;$loginpath\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;challenge\&quot; VALUE=\&quot;$challenge\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;uamip\&quot; VALUE=\&quot;$uamip\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;uamport\&quot; VALUE=\&quot;$uamport\&quot;&gt;
  &lt;INPUT TYPE=\&quot;hidden\&quot; NAME=\&quot;userurl\&quot; VALUE=\&quot;$userurldecode\&quot;&gt;
  &lt;center&gt;
  &lt;table border=\&quot;0\&quot; cellpadding=\&quot;5\&quot; cellspacing=\&quot;0\&quot; style=\&quot;width: 217px;\&quot;&gt;
    &lt;tbody&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;Username:&lt;/td&gt;
        &lt;td&gt;&lt;input STYLE=\&quot;font-family: Arial\&quot; type=\&quot;text\&quot; name=\&quot;UserName\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;Password:&lt;/td&gt;
        &lt;td&gt;&lt;input STYLE=\&quot;font-family: Arial\&quot; type=\&quot;password\&quot; name=\&quot;Password\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;center\&quot; colspan=\&quot;2\&quot; height=\&quot;23\&quot;&gt;&lt;input type=\&quot;submit\&quot; name=\&quot;button\&quot; value=\&quot;Login\&quot; onClick=\&quot;javascript:popUp(&#039;$loginpath?res=popup1&amp;uamip=$uamip&amp;uamport=$uamport&#039;)\&quot;&gt;&lt;/td&gt; 
      &lt;/tr&gt;
    &lt;/tbody&gt;
  &lt;/table&gt;
  &lt;/center&gt;
  &lt;/form&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if ($result == 1) {
  print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logged in to ChilliSpot&lt;/h1&gt;&quot;;

  if ($reply) { 
      print &quot;&lt;center&gt; $reply &lt;/BR&gt;&lt;/BR&gt;&lt;/center&gt;&quot;;
  }

  print &quot;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;Logout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if (($result == 4) || ($result == 12)) {
  print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logged in to ChilliSpot&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;Logout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if ($result == 11) {
  print &quot;&lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logging in to ChilliSpot&lt;/h1&gt;&quot;;
  print &quot;
  &lt;center&gt;
    Please wait......
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if (($result == 3) || ($result == 13)) {
    print &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;Logged out from ChilliSpot&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/prelogin\&quot;&gt;Login&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


exit(0);</code></pre></div><p>* - or place the following login script &#039;hotspotlogin.php&#039; on your SSL and PHP-enabled web server with domain name www.mydomain.com:</p><div class="codebox"><pre><code>&lt;?php
#
# chilli - ChilliSpot.org. A Wireless LAN Access Point Controller
# Copyright (C) 2003, 2004 Mondru AB.
#
# The contents of this file may be used under the terms of the GNU
# General Public License Version 2, provided that the above copyright
# notice and this permission notice is included in all copies or
# substantial portions of the software.

# Redirects from ChilliSpot daemon:
#
# Redirection when not yet or already authenticated
#   notyet:  ChilliSpot daemon redirects to login page.
#  already: ChilliSpot daemon redirects to success status page.
#
# Response to login:
#   already: Attempt to login when already logged in.
#   failed:  Login failed
#   success: Login succeded
#
# logoff:  Response to a logout


# Shared secret used to encrypt challenge with. Prevents dictionary attacks.
# You should change this to your own shared secret.
$uamsecret = &quot;ht2eb8ej6s4et3rg1ulp&quot;;

# Uncomment the following line if you want to use ordinary user-password
# for radius authentication. Must be used together with $uamsecret.
$userpassword=1;

# Our own path
$loginpath = $_SERVER[&#039;PHP_SELF&#039;];

$ChilliSpot=&quot;ChilliSpot&quot;;
$title=&quot;$ChilliSpot Login&quot;;
$centerUsername=&quot;Username&quot;;
$centerPassword=&quot;Password&quot;;
$centerLogin=&quot;Login&quot;;
$centerPleasewait=&quot;Please wait.......&quot;;
$centerLogout=&quot;Logout&quot;;
$h1Login=&quot;$ChilliSpot Login&quot;;
$h1Failed=&quot;$ChilliSpot Login Failed&quot;;
$h1Loggedin=&quot;Logged in to $ChilliSpot&quot;;
$h1Loggingin=&quot;Logging in to $ChilliSpot&quot;;
$h1Loggedout=&quot;Logged out from $ChilliSpot&quot;;
$centerdaemon=&quot;Login must be performed through $ChilliSpot daemon&quot;;
$centerencrypted=&quot;Login must use encrypted connection&quot;;


# Make sure that the form parameters are clean
#$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
#$_ = $input = &lt;STDIN&gt;;
#s/[^$OK_CHARS]/_/go;
#$input = $_;

# Make sure that the get query parameters are clean
#$OK_CHARS=&#039;-a-zA-Z0-9_.@&amp;=%!&#039;;
#$_ = $query=$ENV{QUERY_STRING};
#s/[^$OK_CHARS]/_/go;
#$query = $_;


# If she did not use https tell her that it was wrong.
if (!($_ENV[&#039;HTTPS&#039;] == &#039;on&#039;)) {
#    echo &quot;Content-type: text/html\n\n&quot;;
echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Failed&lt;/h1&gt;
  &lt;center&gt;
    $centerencrypted
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;102&lt;/ResponseCode&gt;
&lt;ReplyMessage&gt;Login must use encrypted connection&lt;/ReplyMessage&gt;
&lt;/AuthenticationReply&gt;
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}


# Read form parameters which we care about
if (isset($_POST[&#039;UserName&#039;]))    $username    = $_POST[&#039;UserName&#039;];
if (isset($_POST[&#039;Password&#039;]))    $password    = $_POST[&#039;Password&#039;];
if (isset($_POST[&#039;challenge&#039;]))    $challenge    = $_POST[&#039;challenge&#039;];
if (isset($_POST[&#039;button&#039;]))    $button        = $_POST[&#039;button&#039;];
if (isset($_POST[&#039;logout&#039;]))    $logout        = $_POST[&#039;logout&#039;];
if (isset($_POST[&#039;prelogin&#039;]))    $prelogin    = $_POST[&#039;prelogin&#039;];
if (isset($_POST[&#039;res&#039;]))    $res        = $_POST[&#039;res&#039;];
if (isset($_POST[&#039;uamip&#039;]))    $uamip        = $_POST[&#039;uamip&#039;];
if (isset($_POST[&#039;uamport&#039;]))    $uamport    = $_POST[&#039;uamport&#039;];
if (isset($_POST[&#039;userurl&#039;]))    $userurl    = $_POST[&#039;userurl&#039;];
if (isset($_POST[&#039;timeleft&#039;]))    $timeleft    = $_POST[&#039;timeleft&#039;];
if (isset($_POST[&#039;redirurl&#039;]))    $redirurl    = $_POST[&#039;redirurl&#039;];

# Read query parameters which we care about
if (isset($_GET[&#039;res&#039;]))    $res        = $_GET[&#039;res&#039;];
if (isset($_GET[&#039;challenge&#039;]))    $challenge    = $_GET[&#039;challenge&#039;];
if (isset($_GET[&#039;uamip&#039;]))    $uamip        = $_GET[&#039;uamip&#039;];
if (isset($_GET[&#039;uamport&#039;]))    $uamport    = $_GET[&#039;uamport&#039;];
if (isset($_GET[&#039;reply&#039;]))    $reply        = $_GET[&#039;reply&#039;];
if (isset($_GET[&#039;userurl&#039;]))    $userurl    = $_GET[&#039;userurl&#039;];
if (isset($_GET[&#039;timeleft&#039;]))    $timeleft    = $_GET[&#039;timeleft&#039;];
if (isset($_GET[&#039;redirurl&#039;]))    $redirurl    = $_GET[&#039;redirurl&#039;];


#$reply =~ s/\+/ /g;
#$reply =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$userurldecode = $userurl;
#$userurldecode =~ s/\+/ /g;
#$userurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

$redirurldecode = $redirurl;
#$redirurldecode =~ s/\+/ /g;
#$redirurldecode =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

#$password =~ s/\+/ /g;
#$password =~s/%([a-fA-F0-9][a-fA-F0-9])/pack(&quot;C&quot;, hex($1))/seg;

# If attempt to login
if ($button == &#039;Login&#039;) {
  $hexchal = pack (&quot;H32&quot;, $challenge);
  if ($uamsecret) {
    $newchal = pack (&quot;H*&quot;, md5($hexchal . $uamsecret));
  } else {
    $newchal = $hexchal;
  }
  $response = md5(&quot;\0&quot; . $password . $newchal);
  $newpwd = pack(&quot;a32&quot;, $password);
  $pappassword = implode (&quot;&quot;, unpack(&quot;H32&quot;, ($newpwd ^ $newchal)));
# sleep 5;
# echo &#039;Content-type: text/html\n\n&#039;;
  echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;&quot;;
  if (isset($uamsecret) &amp;&amp; isset($userpassword)) {
    echo &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword\&quot;&gt;&quot;;
  } else {
    echo &quot;  &lt;meta http-equiv=\&quot;refresh\&quot; content=\&quot;0;url=http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl\&quot;&gt;&quot;;
  }
  echo &quot;&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
&lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggingin&lt;/h1&gt;
  &lt;center&gt;
    $centerPleasewait
  &lt;/center&gt;
&lt;/body&gt;
&lt;!--
&lt;?xml version=\&quot;1.0\&quot; encoding=\&quot;UTF-8\&quot;?&gt;
&lt;WISPAccessGatewayParam 
  xmlns:xsi=\&quot;http://www.w3.org/2001/XMLSchema-instance\&quot;
  xsi:noNamespaceSchemaLocation=\&quot;http://www.acmewisp.com/WISPAccessGatewayParam.xsd\&quot;&gt;
&lt;AuthenticationReply&gt;
&lt;MessageType&gt;120&lt;/MessageType&gt;
&lt;ResponseCode&gt;201&lt;/ResponseCode&gt;
&quot;;
  if (isset($uamsecret) &amp;&amp; isset($userpassword)) {
    echo &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;password=$pappassword&lt;/LoginResultsURL&gt;&quot;;
  } else {
    echo &quot;&lt;LoginResultsURL&gt;http://$uamip:$uamport/logon?username=$username&amp;response=$response&amp;userurl=$userurl&lt;/LoginResultsURL&gt;&quot;;
  }
  echo &quot;&lt;/AuthenticationReply&gt; 
&lt;/WISPAccessGatewayParam&gt;
--&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}

switch($res) {
  case &#039;success&#039;:     $result =  1; break; // If login successful
  case &#039;failed&#039;:      $result =  2; break; // If login failed
  case &#039;logoff&#039;:      $result =  3; break; // If logout successful
  case &#039;already&#039;:     $result =  4; break; // If tried to login while already logged in
  case &#039;notyet&#039;:      $result =  5; break; // If not logged in yet
  case &#039;smartclient&#039;: $result =  6; break; // If login from smart client
  case &#039;popup1&#039;:      $result = 11; break; // If requested a logging in pop up window
  case &#039;popup2&#039;:      $result = 12; break; // If requested a success pop up window
  case &#039;popup3&#039;:      $result = 13; break; // If requested a logout pop up window
  default: $result = 0; // Default: It was not a form request
}

# Otherwise it was not a form request
# Send out an error message
if ($result == 0) {
#    echo &quot;Content-type: text/html\n\n&quot;;
    echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
&lt;/head&gt;
&lt;body bgColor = &#039;#c0d8f4&#039;&gt;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Failed&lt;/h1&gt;
  &lt;center&gt;
    $centerdaemon
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;
&quot;;
    exit(0);
}

# Generate the output
#echo &quot;Content-type: text/html\n\n&quot;;
echo &quot;&lt;!DOCTYPE HTML PUBLIC \&quot;-//W3C//DTD HTML 4.01 Transitional//EN\&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;title&gt;$title&lt;/title&gt;
  &lt;meta http-equiv=\&quot;Cache-control\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;meta http-equiv=\&quot;Pragma\&quot; content=\&quot;no-cache\&quot;&gt;
  &lt;SCRIPT LANGUAGE=\&quot;JavaScript\&quot;&gt;
    var blur = 0;
    var starttime = new Date();
    var startclock = starttime.getTime();
    var mytimeleft = 0;

    function doTime() {
      window.setTimeout( \&quot;doTime()\&quot;, 1000 );
      t = new Date();
      time = Math.round((t.getTime() - starttime.getTime())/1000);
      if (mytimeleft) {
        time = mytimeleft - time;
        if (time &lt;= 0) {
          window.location = \&quot;$loginpath?res=popup3&amp;uamip=$uamip&amp;uamport=$uamport\&quot;;
        }
      }
      if (time &lt; 0) time = 0;
      hours = (time - (time % 3600)) / 3600;
      time = time - (hours * 3600);
      mins = (time - (time % 60)) / 60;
      secs = time - (mins * 60);
      if (hours &lt; 10) hours = \&quot;0\&quot; + hours;
      if (mins &lt; 10) mins = \&quot;0\&quot; + mins;
      if (secs &lt; 10) secs = \&quot;0\&quot; + secs;
      title = \&quot;Online time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      if (mytimeleft) {
        title = \&quot;Remaining time: \&quot; + hours + \&quot;:\&quot; + mins + \&quot;:\&quot; + secs;
      }
      if(document.all || document.getElementById){
         document.title = title;
      }
      else {   
        self.status = title;
      }
    }

    function popUp(URL) {
      if (self.name != \&quot;chillispot_popup\&quot;) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
    }

    function doOnLoad(result, URL, userurl, redirurl, timeleft) {
      if (timeleft) {
        mytimeleft = timeleft;
      }
      if ((result == 1) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
      }
      if ((result == 1) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(URL, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=375&#039;);
      }
      if ((result == 2) || result == 5) {
        document.form1.UserName.focus()
      }
      if ((result == 2) &amp;&amp; (self.name != \&quot;chillispot_popup\&quot;)) {
        chillispot_popup = window.open(&#039;&#039;, &#039;chillispot_popup&#039;, &#039;toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=400,height=200&#039;);
        chillispot_popup.close();
      }
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        doTime();
        if (redirurl) {
          opener.location = redirurl;
        }
        else if (opener.home) {
          opener.home();
        }
        else {
          opener.location = \&quot;about:home\&quot;;
        }
        self.focus();
        blur = 0;
      }
      if ((result == 13) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        self.focus();
        blur = 1;
      }
    }

    function doOnBlur(result) {
      if ((result == 12) &amp;&amp; (self.name == \&quot;chillispot_popup\&quot;)) {
        if (blur == 0) {
          blur = 1;
          self.focus();
        }
      }
    }
  &lt;/script&gt;
&lt;/head&gt;
&lt;body onLoad=\&quot;javascript:doOnLoad($result, &#039;$loginpath?res=popup2&amp;uamip=$uamip&amp;uamport=$uamport&amp;userurl=$userurl&amp;redirurl=$redirurl&amp;timeleft=$timeleft&#039;,&#039;$userurldecode&#039;, &#039;$redirurldecode&#039;, &#039;$timeleft&#039;)\&quot; onBlur = &#039;javascript:doOnBlur($result)&#039; bgColor = &#039;#c0d8f4&#039;&gt;&quot;;

/*# begin debugging
  print &quot;&lt;center&gt;THE INPUT (for debugging):&lt;br&gt;&quot;;
  foreach ($_GET as $key =&gt; $value) {
    print $key . &quot;=&quot; . $value . &quot;&lt;br&gt;&quot;;
  }
  print &quot;&lt;br&gt;&lt;/center&gt;&quot;;
# end debugging
*/
if ($result == 2) {
    echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Failed&lt;/h1&gt;&quot;;
    if ($reply) {
    echo &quot;&lt;center&gt; $reply &lt;/BR&gt;&lt;/BR&gt;&lt;/center&gt;&quot;;
    }
}

if ($result == 5) {
    echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Login&lt;/h1&gt;&quot;;
}

if ($result == 2 || $result == 5) {
  echo &quot;
  &lt;form name=\&quot;form1\&quot; method=\&quot;post\&quot; action=\&quot;$loginpath\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;challenge\&quot; value=\&quot;$challenge\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;uamip\&quot; value=\&quot;$uamip\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;uamport\&quot; value=\&quot;$uamport\&quot;&gt;
  &lt;input type=\&quot;hidden\&quot; name=\&quot;userurl\&quot; value=\&quot;$userurl\&quot;&gt;
  &lt;center&gt;
  &lt;table border=\&quot;0\&quot; cellpadding=\&quot;5\&quot; cellspacing=\&quot;0\&quot; style=\&quot;width: 217px;\&quot;&gt;
    &lt;tbody&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;$centerUsername:&lt;/td&gt;
        &lt;td&gt;&lt;input style=\&quot;font-family: Arial\&quot; type=\&quot;text\&quot; name=\&quot;UserName\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;right\&quot;&gt;$centerPassword:&lt;/td&gt;
        &lt;td&gt;&lt;input style=\&quot;font-family: Arial\&quot; type=\&quot;password\&quot; name=\&quot;Password\&quot; size=\&quot;20\&quot; maxlength=\&quot;128\&quot;&gt;&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
        &lt;td align=\&quot;center\&quot; colspan=\&quot;2\&quot; height=\&quot;23\&quot;&gt;&lt;input type=\&quot;submit\&quot; name=\&quot;button\&quot; value=\&quot;Login\&quot; onClick=\&quot;javascript:popUp(&#039;$loginpath?res=popup1&amp;uamip=$uamip&amp;uamport=$uamport&#039;)\&quot;&gt;&lt;/td&gt; 
      &lt;/tr&gt;
    &lt;/tbody&gt;
  &lt;/table&gt;
  &lt;/center&gt;
  &lt;/form&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if ($result == 1) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggedin&lt;/h1&gt;&quot;;

  if ($reply) { 
      echo &quot;&lt;center&gt; $reply &lt;/br&gt;&lt;/br&gt;&lt;/center&gt;&quot;;
  }

  echo &quot;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;Logout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

if (($result == 4) || ($result == 12)) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggedin&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/logoff\&quot;&gt;$centerLogout&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if ($result == 11) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggingin&lt;/h1&gt;
  &lt;center&gt;
    $centerPleasewait
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}


if (($result == 3) || ($result == 13)) {
  echo &quot;
  &lt;h1 style=\&quot;text-align: center;\&quot;&gt;$h1Loggedout&lt;/h1&gt;
  &lt;center&gt;
    &lt;a href=\&quot;http://$uamip:$uamport/prelogin\&quot;&gt;$centerLogin&lt;/a&gt;
  &lt;/center&gt;
&lt;/body&gt;
&lt;/html&gt;&quot;;
}

exit(0);
?&gt;</code></pre></div><p><strong><span class="bbu">Freeradius config</span></strong></p><p>* Change the following attributes in /etc/freeradius/radiusd.conf to use Freeradius with a MySQL backend:</p><p>authorize {<br />&nbsp; &nbsp; sql</p><p>}</p><p>authenticate {<br />&nbsp; &nbsp; Auth-Type PAP {<br />&nbsp; &nbsp; &nbsp; &nbsp; pap<br />&nbsp; &nbsp; }<br />}</p><p>accounting {<br />&nbsp; &nbsp; sql<br />}</p><p>session {<br />&nbsp; &nbsp; sql<br />}</p><br /><p>* Change the following attributes in /etc/freeradius/sql.conf</p><p>sql {<br />&nbsp; &nbsp; driver = &quot;rlm_sql_mysql&quot;</p><p>&nbsp; &nbsp; server = &quot;mysql.mydomain.com&quot;<br />&nbsp; &nbsp; login = &quot;my_login&quot;<br />&nbsp; &nbsp; password = &quot;my_password&quot;<br />&nbsp; &nbsp; radius_db = &quot;my_db&quot;</p><p>&nbsp; &nbsp; # Uncomment simul_count_query to enable simultaneous use checking<br />&nbsp; &nbsp; simul_count_query = &quot;SELECT COUNT(*) FROM ${acct_table1} WHERE UserName=&#039;%{SQL-User-Name}&#039; AND AcctStopTime = 0&quot;</p><p>&nbsp; &nbsp; readclients = yes<br />}</p><br /><p>* Install the Freeradius tables in the MySQL database on the domain mysql.mydomain.com, and configure a test user:</p><p><strong>raduserinfo</strong></p><p>UserName = &#039;testuser&#039;</p><p><strong>radcheck for &#039;testuser&#039;</strong></p><p>User-Password := &#039;password&#039;<br />Auth-Type := &#039;PAP&#039;<br />Simultaneous-Use := 1</p><p><strong>radreply for &#039;testuser&#039;</strong></p><p>Idle-Timeout := 1800</p><br /><br /><p><strong><span class="bbu">NTP config</span></strong></p><p>* Change the attributes in /etc/TZ to match your time zone, for instance:</p><p>CET-1CEST-2,M3.5.0/02:00:00,M10.5.0/03:00:00</p><br /><p><strong><span class="bbu">Monit config</span></strong></p><p>* Change the following attributes in /etc/monitrc:</p><p> set mailserver smtp.mymailserver.com<br /> set mail-format { from: monit@mydomain.com }<br /> set alert monit@mydomain.com<br /> set httpd port 2812 and<br />&nbsp; &nbsp; &nbsp;allow admin:monit&nbsp; &nbsp; &nbsp;# user &#039;admin&#039; with password &#039;monit&#039;</p><p> check process chilli with pidfile /var/run/chilli.pid<br />&nbsp; &nbsp;start program = &quot;/etc/init.d/chilli start&quot;<br />&nbsp; &nbsp;stop program = &quot;/etc/init.d/chilli stop&quot;</p><p> check process radiusd with pidfile /var/run/radiusd.pid<br />&nbsp; &nbsp;start program = &quot;/etc/init.d/radiusd start&quot;<br />&nbsp; &nbsp;stop program = &quot;/etc/init.d/radiusd stop&quot;</p><p> check host www.mydomain.com with address www.mydomain.com<br />&nbsp; &nbsp;if failed port 80 protocol http<br />&nbsp; &nbsp; &nbsp; and request &quot;/hotspotlogin.cgi&quot; then alert</p><p> check host mysql.mydomain.com with address mysql.mydomain.com<br />&nbsp; &nbsp;if failed port 3306 protocol mysql then alert</p><br /><br /><p><strong><span class="bbu">Configuring the remote routers</span></strong></p><p>Since we only want to use the remote routers to repeat our signal, we bridge the WDS, WIFI and LAN:</p><div class="codebox"><pre><code>       (192.168.1.0/24) 
|   |    |  |         \|/     \|/
+--vlan0-+--+         eth1    wds
    |                  |       |
    +----------br0-----+-------+
                | 
          &lt;userspace&gt;</code></pre></div><p>- vlan0 is used for bridging all the LAN ports<br />- eth1 is used for the WIFI interface<br />- wds is used for extending the WIFI range using WDS<br />- br0 is the bridge that connects all the interfaces</p><br /><p>* The existing bridge is then used for the wireless interface. <br />For every WDS client that we want to add, we add a new wds0.xxxxx interface, starting at wds0.49153:</p><p>lan_ifname=br0<br />lan_ifnames=vlan0 eth1 wds0.49153 wds0.49154 wds0.49155</p><br /><p>* In addition, the Spanning Tree Protocol is set to avoid circular bridges when using WDS:</p><p>lan_stp=1</p><br /><p>* We use manual WDS and disables Lazy WDS, and adds the MAC address for all wireless routers<br />that we want to communicate with, including the MAC address of the captive portal: </p><p>wl0_lazywds=0<br />wl0_wds=aa:aa:aa:aa:aa:aa bb:bb:bb:bb:bb:bb cc:cc:cc:cc:cc:cc</p><br /><p>* Last, disable all services you do not need, such as DHCP. This is an important step because we do not want the remote routers to hand out IP addresses that confuses Chillispot.</p><br /><br /><p><strong><span class="bbu">Testing the setup</span></strong></p><p>* Start your WEB browser, and write &#039;testuser&#039;/&#039;password&#039; in the WEB page that appears. If you have configured everything correctly, you should be authenticated.</p><p>* If anything fails, connect your PC to one of the LAN ports on the router and start two SSH sessions, one with Chillispot and the other with Freeradius, both in foreground debug mode:</p><p>chilli -fd</p><p>radiusd -X</p><br /><p>Establish a wireless connection to your WLAN and watch the outputs carefully to debug your setup.</p><br /><br /><p>Have fun!</p>]]></description>
			<author><![CDATA[null@example.com (ajauberg)]]></author>
			<pubDate>Tue, 09 Oct 2007 16:59:26 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic18-howto-setting-up-openwrt-as-a-captive-portal-on-wrt54gl-new-posts.html</guid>
		</item>
		<item>
			<title><![CDATA[Documentation ?]]></title>
			<link>http://www.chillispot.org/chilliforum/topic10-documentation-new-posts.html</link>
			<description><![CDATA[<p>Hello,</p><p>Where can I found a real documentation about chillispot and dd-wrt ?</p><p>Thanks by advance <img src="http://www.chillispot.org/chilliforum/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[null@example.com (Albert)]]></author>
			<pubDate>Tue, 02 Oct 2007 07:31:49 +0000</pubDate>
			<guid>http://www.chillispot.org/chilliforum/topic10-documentation-new-posts.html</guid>
		</item>
	</channel>
</rss>
