05-14-2000, 10:54 AM
Currently, vB allows a new user registering on the BB to choose his\her own password, instead of having to wait for an auto-generated password to be sent to him\her by e-mail.
This allows users to use a non-existent email address and lthough users cannot post without first activating their account, the syntax for the activation URL is very easy to emulate and thus you don't really need the e-mail confirmation to post on the BB after you registered.
This is quite a security risk. As far as I am concerned, I need to know that any user on my BB can be reached via e-mail if necessary. In fact, I don't even allow hotmail.com and such e-mail addresses.
Therefore, I am asking for your help. Can anyone here write a hack that will revert the registration process to the UBB-like process - whereby a new user cannot determine his\her password during registration and must wait till the password (auto-generated) will arrive by e-mail? (he could then change the password in the profile, but must have a valid e-mail to receive a password to begin with). Furthermore, if the user changes his e-mail address in the profile, a new password will be auto-generated and sent to his new e-mail.
This assures, to a larger degree, that users have a valid e-mail address.
I would REALLY appreciate it if someone here can come up with this hack asap.
Thank you,
Bira
This allows users to use a non-existent email address and lthough users cannot post without first activating their account, the syntax for the activation URL is very easy to emulate and thus you don't really need the e-mail confirmation to post on the BB after you registered.
This is quite a security risk. As far as I am concerned, I need to know that any user on my BB can be reached via e-mail if necessary. In fact, I don't even allow hotmail.com and such e-mail addresses.
Therefore, I am asking for your help. Can anyone here write a hack that will revert the registration process to the UBB-like process - whereby a new user cannot determine his\her password during registration and must wait till the password (auto-generated) will arrive by e-mail? (he could then change the password in the profile, but must have a valid e-mail to receive a password to begin with). Furthermore, if the user changes his e-mail address in the profile, a new password will be auto-generated and sent to his new e-mail.
This assures, to a larger degree, that users have a valid e-mail address.
I would REALLY appreciate it if someone here can come up with this hack asap.
Thank you,
Bira