vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   Catching the members in the act... (https://vborg.vbsupport.ru/showthread.php?t=57753)

Dean C 10-13-2003 03:45 PM

As long as it's stated in the privacy policy the admin can do what they want with the users information. Besides the ethics of it it's legal to have users passwords etc.

Zzed 10-13-2003 04:06 PM

Thank you Xenon and Mist for your replies.

nooppid, as I stated, I get an Email notice for all failed attempts. If the moderator/admin login succeeds there there is no need to take any action or send any notices.

blakkboy, I have not released this hack. :(

We have had a lot of break ins into our private forums via compromised passwords of our moderators. The discussions in our moderator forum were being broadcast to other boards. I have incorporated additional security layers on top of the existing VB security. I have made a hack that logs all access to the private forums, I made a hack that does an IP ban for my private forms, and I have made a trusted host list hack per moderator for additional authentication of every moderator in my forums. I have been locked out on several occasions because I was logged into my forums from an IP address that was not listed in the trusted host list. And in such a case I also disable access to the admin and the mod CP's aswell and I also disable a lot of the moderation functions when somsone is logged in from an "un-trusted" host. ;)

nfortunately none of these hacks are published, and I have my personal reasons for my hesitation to publish them. :(

jjj0923 01-23-2004 10:55 AM

a hack I'd really like to find is simultaneous logins by the same user from different IP addresses. I believe a few people on my forum are sharing logins but need something to confirm my suspicions - any ideas on how to do this?

thanks

MGM 01-23-2004 10:55 PM

Quote:

Originally Posted by Zzed
Thank you Xenon and Mist for your replies.

nooppid, as I stated, I get an Email notice for all failed attempts. If the moderator/admin login succeeds there there is no need to take any action or send any notices.

blakkboy, I have not released this hack. :(

We have had a lot of break ins into our private forums via compromised passwords of our moderators. The discussions in our moderator forum were being broadcast to other boards. I have incorporated additional security layers on top of the existing VB security. I have made a hack that logs all access to the private forums, I made a hack that does an IP ban for my private forms, and I have made a trusted host list hack per moderator for additional authentication of every moderator in my forums. I have been locked out on several occasions because I was logged into my forums from an IP address that was not listed in the trusted host list. And in such a case I also disable access to the admin and the mod CP's aswell and I also disable a lot of the moderation functions when somsone is logged in from an "un-trusted" host. ;)

nfortunately none of these hacks are published, and I have my personal reasons for my hesitation to publish them. :(

I think I understand your reasoning.... the code you used could perhaps be used against you if a member were to see it posted on vb.org. Perhaps the code you're using isn't all that secure itself ;)

I would love to have a hack like that though. Perhaps one day you could show me?

MGM out

Zzed 01-23-2004 11:15 PM

Quote:

Originally Posted by MetalGearMaster
I think I understand your reasoning.... the code you used could perhaps be used against you if a member were to see it posted on vb.org. Perhaps the code you're using isn't all that secure itself ;)

I would love to have a hack like that though. Perhaps one day you could show me?

MGM out

I posted my Admin password in my forum last friday and invited people to login as me. I know what I did is quite insane, but every single one of those people were stopped in their tracks. They came back to that thread and whined about it too. :D

There were about 145 login attempts, and all of them did log in as me. But the trusted hosts hack gave all of them an error screen that they were illegally logged in as a moderator or administrator of the board. ;)

MGM 01-24-2004 03:53 PM

does that work for the forums too or just the admincp?

Because it'd be quite a big problem if they logged in as you in the forums as well

But then, what would you do if someone was hacking your board and you were at a friends house. You can't do anything about it but watch!

MGM out

RDX1 01-24-2004 09:27 PM

Quote:

Originally Posted by MetalGearMaster
But then, what would you do if someone was hacking your board and you were at a friends house. You can't do anything about it but watch!

Personally, i know that the AdminCP doesn't offer any protection from hackers but turning the board off, and if you don't have your admincp htaccessed, you should.

But if someone was hacking my board, i know i wouldn't use the admincp to stop it. I would use the control panel software on the server to htaccess everything down until i could get the issue resolved.

Zzed 01-26-2004 05:55 PM

Quote:

Originally Posted by MetalGearMaster
does that work for the forums too or just the admincp?

Because it'd be quite a big problem if they logged in as you in the forums as well

But then, what would you do if someone was hacking your board and you were at a friends house. You can't do anything about it but watch!

MGM out

It works for both Admin CP and the forums. ;)

But I never said I didn't have ways to take over my own board. ;):D

vbmechanic 01-26-2004 06:49 PM

Want to see something funny as well as pitiful?

Run a query that lists all users where password = md5( yoursitename)... Had a site where over 5% of the users had the site name as their password.


All times are GMT. The time now is 03:14 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01151 seconds
  • Memory Usage 1,739KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (4)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (9)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete