PDA

View Full Version : vB Password security outdated?


silvermerc
02-27-2009, 06:16 PM
Well today as you may have read my site got defaced due to a moderators encrypted password being leaked by another forum, I was wondering if theres any way to encrypt the passwords better?
Ross

snakes1100
02-27-2009, 10:32 PM
Well today as you may have read my site got defaced due to a moderators encrypted password being leaked by another forum, I was wondering if theres any way to encrypt the passwords better?
Ross

vbulletins security wasnt the issue in your case as you've pointed out, if the other forum wasnt hashing their passwds and just encrypting them, then your moderator made the mistake of using the same passwd on both sites.

encryption is reversible, hashing as vbulletin does isn't.

silvermerc
02-27-2009, 11:49 PM
Well here is what he showed me:
f53436bfa82d5583f7e3034f34884e53
As his password