PDA

View Full Version : Hack needed urgently for the registration process


05-14-2000, 10:54 AM
Currently, vB allows a new user registering on the BB to choose his\her own password, instead of having to wait for an auto-generated password to be sent to him\her by e-mail.

This allows users to use a non-existent email address and lthough users cannot post without first activating their account, the syntax for the activation URL is very easy to emulate and thus you don't really need the e-mail confirmation to post on the BB after you registered.

This is quite a security risk. As far as I am concerned, I need to know that any user on my BB can be reached via e-mail if necessary. In fact, I don't even allow hotmail.com and such e-mail addresses.

Therefore, I am asking for your help. Can anyone here write a hack that will revert the registration process to the UBB-like process - whereby a new user cannot determine his\her password during registration and must wait till the password (auto-generated) will arrive by e-mail? (he could then change the password in the profile, but must have a valid e-mail to receive a password to begin with). Furthermore, if the user changes his e-mail address in the profile, a new password will be auto-generated and sent to his new e-mail.

This assures, to a larger degree, that users have a valid e-mail address.

I would REALLY appreciate it if someone here can come up with this hack asap.

Thank you,

Bira

05-14-2000, 11:37 AM
A more secure way of doing this will be in the next version - I am trying to get this rolled out as quickly as possible, but I am extremely busy at the moment. If your traffic is not too high, you can select to moderate all new members, viewing their profile before they can start posting. This may be a suitable workaround in the meantime.

John

05-14-2000, 11:42 AM
John,

My traffic is quite high (If it wasn't high, then UBB would have been enough, I guess ;)) and monitoring new registrants is bound to drive me or my admins nuts :(

05-16-2000, 08:12 AM
ditto ditto ditto

not to mention the url in the email to the users is forked when there is a space in the username!

common john...quit your job! this is your future

:)