vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Member Archives (https://vborg.vbsupport.ru/forumdisplay.php?f=202)
-   -   Obtaining Passwords (https://vborg.vbsupport.ru/showthread.php?t=23624)

da_selector 07-25-2001 02:43 PM

I think this is the right forum...is there any way of getting a password from any of the files???

tubedogg 07-25-2001 10:14 PM

Why are you so intent on finding passwords? I wouldn't register at your board if I knew the admin was going to take my password...

TheComputerGuy 07-25-2001 11:12 PM

Well why would you need the password, because Admins have the overall power

razaz 07-26-2001 12:04 AM

Maybe he needs the passwords cause his board is on a host like spaceports where they have disabled the email so if his members lose there pass then he has no way to send it to them so the only option they have it to resign backup....Just a thought! :)

Delhaze 07-26-2001 12:09 AM

in admin/config.php

PHP Code:

// allow password viewing / editing in control panel
// 0 = not visible or editable
// 1 = not visible, but can be edited
// 2 = visible and can be edited
$pwdincp=0


leadZERO 07-26-2001 01:14 AM

I look up users passwords every now and then to make sure they have access to what they need to. However, I always reset the timestamps so they don't miss anything.

However, I usually ask them before I do that.

Learner29 08-19-2002 04:19 PM

Quote:

Originally posted by Delhaze
in admin/config.php

PHP Code:

// allow password viewing / editing in control panel
// 0 = not visible or editable
// 1 = not visible, but can be edited
// 2 = visible and can be edited
$pwdincp=0


Hi Delhaze

I have this pwdincp=2 setup on my config.php but still, the passwords are not visible in the CP, but yes, I can edit them (by typing a new password)

I had vb 2.2.3 that was updated with updates without reuploading all the new php files of the new vb versions.

I would highly apperciate your help

Dean C 08-19-2002 05:38 PM

those lines aren't in config.php for me :S

Steve Machol 08-19-2002 05:40 PM

Those lines are from pre-2.2.0 versions of vB. They are no longer functional.

Learner29 08-19-2002 11:31 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
those lines aren't in config.php for me :S
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

then, you have the new version. !

Dean C 08-20-2002 06:00 PM

:(

Learner29 08-29-2002 04:36 PM

why nobody is trying to help Smachol ???

Why would one assume that whenever someone would want to see the password, then he has bad intentions.

on my board, I had more than one person signing up with free email adresses such as hotmail and yahoo, only to spam the board with their filth.

Yes, I could ban the bad user, but he would have signed up with many many usernames, so when I ban one username he would enjoy relogging with another username and spreading his garbage again.

remember you can't always block the ip number.

sometimes the ip number is that of a proxy for a big city, and blocking this one person's ip would mean blocking the whole city....

the only way to know those people was to look at their password, as they were using the same password in all the other accounts that they planned to use once the username they are using now is banned.

DrkFusion 08-29-2002 04:50 PM

Its because, the password is encrypted in the database, none of the vb hackers have actually really found out how to decrypt it, and if it were decrypted, alot of other security software would be in danger, the ones that use the same encryption tool.

Also I highly doubt the encryption is standard, it possible is random. Not really sure

NTLDR 08-29-2002 04:55 PM

OK lets make this clear:

vB Uses MD5 Irriversable encryption. THIS MEANS, that once the password is encrypted into the DB YOU CANNOT decrypt it full stop.

Learner29 08-29-2002 10:11 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Its because, the password is encrypted in the database, none of the vb
hackers have actually really found out how to decrypt it, and if it were
decrypted, alot of other security software would be in danger, the ones that
use the same encryption tool.

Also I highly doubt the encryption is standard, it possible is random. Not
really sure
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ahah! thank you so much for your feedback ...
so do you think I should continue to look for it, or is it really a loss of
time ??

NTLDR 08-29-2002 10:15 PM

Well if you wish to waste your life away trying to reverse iriversable encryption go ahead. Even if you do manage to crack it YOU CAN'T display it in the Admin CP and you would have to spend a few more years posibly decades runing the cracking algorithum on it.

Scott MacVicar 08-29-2002 11:03 PM

Its not actually encryption btw ;) Its a hash

http://www.faqs.org/rfcs/rfc1321.html

Quote:

This document describes the MD5 message-digest algorithm. The algorithm takes as input a message of arbitrary length and produces as output a 128-bit "fingerprint" or "message digest" of the input.
It is conjectured that it is computationally infeasible to produce two messages having the same message digest, or to produce any message having a given prespecified target message digest

g-force2k2 08-29-2002 11:38 PM

yep PPN is correct... md5 is not an encryption there is no way to decrypt (hence it is not an encryption / decryption function) md5 passwords... (at least not to my knowledge you can't undo the md5 function) and the passwords are stored as md5.... yes passwords can be obtained... but vb seems to have taken that function away as Smachol stated probably because of malice useage... regards...

g-force2k2

Logician 08-30-2002 08:01 AM

Quote:

Originally posted by Learner29
on my board, I had more than one person signing up with free email adresses such as hotmail and yahoo, only to spam the board with their filth.

Yes, I could ban the bad user, but he would have signed up with many many usernames, so when I ban one username he would enjoy relogging with another username and spreading his garbage again.

Your Solution:
https://vborg.vbsupport.ru/showthrea...threadid=38909

Enjoy..

Erwin 08-30-2002 08:06 AM

Ban free emails. I do.

Erwin 08-30-2002 08:09 AM

eva2000's mega-list of 30,000 free email domains formatted for vB right here:

http://i4net.tv/marticle/get.php?act...e&articleid=30

Cut and paste... :)

Learner29 08-30-2002 03:35 PM

Quote:

Originally posted by NTLDR
Well if you wish to waste your life away trying to reverse iriversable encryption go ahead. Even if you do manage to crack it YOU CAN'T display it in the Admin CP and you would have to spend a few more years posibly decades runing the cracking algorithum on it.
LOOOOOL :cheeky: :cheeky: :cheeky:

now I understand where your name comes from.....

OK OK . that was Very encouraging NTLDR ....

In fact, that was as encouraging as booting your windows 2000 and getting this lovely message......


NTLDR ......


(for those who are not too much into computer tech, this means your computer does not recognize your hard disk as a boot partition, i.e., either you caught a serious boot virus, or that you simply lost your hard disk (and possibly all files on it) .....

THANK YOU NTLDR ...

that actually was a full answer.... LOL.

Learner29 08-30-2002 03:41 PM

Big Big thanks to PPN, g-force2k2, Erwin and Logician for the very kind help .

thank you very sincerely....

Now I understand I will have to give up this idea....... I was so frustrated but thanks to you guys, I am fine now.

special thanks to Logician who YES provided a solution to my problem.

Kind Regards.

king sting 09-07-2002 11:09 AM

yeah if the option is only in the older verisons of vbulletin.. how can i down-grade my vbulletin to the older verison? I have good reasons so please dont give me ++++ about it. But I think this is a most for admins. Its just my opinion.. but again.. how can i down grade?

Erwin 09-07-2002 11:14 AM

You can't. vB no longer offers any copies of the old versions.

king sting 09-07-2002 11:25 AM

what? how come? so your telling me i paid for a software I dont have total control of? thats ++++ing bull++++ in my eyes... all these realeases and ++++ they wont give me a older verison? even after I already paid for it? what hell nah.. I think this feature needs to be put into the admin cp.. its our boards and we have to pay for the right to use vbulletin, how we run our boards is up to us, not the software heads at vbulletin.

I ++++ing demand something is done about this.

g-force2k2 09-07-2002 02:04 PM

with that kind of attitude no one is going to do anything about it... like i said its privacy invasion... you want an older version? it probably wont' even work anymore... so in otherwords settle down... demand eh? you ain't getting nothing from me...

g-force2k2

Chris M 09-07-2002 04:47 PM

It has already been proved impossible...

Whether you like it or not, vB will not change their policy, and I agree with g-force...

Satan

NTLDR 09-07-2002 04:59 PM

There is *never* a good reason for needing somones password, you can send members a new one and you can check if passwords are the same by comparing the MD5 hashes. Also why would Jelsoft provide old unstable and insecure versions of vB to the public?

I may want Windows 1.01, but Microsoft wouldn't supply me with a copy even if I paid.

Tip: Save each origional zip and store on your computer. Then you can use whatever version you want on your live board.

Learner29 09-07-2002 05:09 PM

come on, you need to understand that the encryption of the password is for
the security of your people, members of your boards. It is not an
out-of-the-cough decision by some heads at jelsoft... it is a thoughtful
idea about the security of your board.

king sting 09-07-2002 07:00 PM

vbulletins policys are just like the american government.. always trying to censer our freedoms. I paid for a software that censers me. thats bull++++. where the ++++ are the software heads? out planing more ways to kill freedom as we know it? ++++ing terriost.

king sting 09-07-2002 09:20 PM

To everyone that thinks they should beable to view passwords, and doesn't want to be censered by the vbulletin freedom haters, please go to this thread I made on vbulletin.com and voice your opinion.

We paid for a software, we should have total control of it.

http://www.vbulletin.com/forum/showt...threadid=54380

Steve Machol 09-08-2002 01:40 AM

You do have total control of it. If you do not likepassword encryption, then just hack it out of the code. You can also hack in a password generator and have the new passwords emailed to your members. This is all entirely within your control. There's not a single person in the world who can stop you from doing this.

By the way you efforts at branding Jelsoft as 'censors' are ridiculous. You clearly have no understanding of the word.

2 X Viverridae 09-08-2002 01:55 AM

@ king sting - I certainly hope that nobody bothers to go to http://www.illstylez.com/board/ and PM's or email's your members there with copies of your posts about wanting to get their passwords.

Then again, it's probably all right with you, eh - anything else would be censorship! :rolleyes:

There is no good reason to have a users password - unless you want to either log in and pretend to be them in a post, (Very unethical!) or you want to see if the same password works works in other sites or locations. (More than just a little unethical!)

Any information that you can get as a logged in user is available to you, if you take the time to learn how to access the database.

See you on the boards, eh!

Logician 09-08-2002 04:17 AM

Quote:

Originally posted by king sting
what? how come? so your telling me i paid for a software I dont have total control of? thats ++++ing bull++++ in my eyes... all these realeases and ++++ they wont give me a older verison? even after I already paid for it? what hell nah.. I think this feature needs to be put into the admin cp.. its our boards and we have to pay for the right to use vbulletin, how we run our boards is up to us, not the software heads at vbulletin.

I ++++ing demand something is done about this.

It's very clear that you dont have any knowledge about internet security nor intentions of the developers about securing the passwords in the database. All good software secure passwords because they can be exploited by people other than Site Admins. Your hosting company's/isp's people can get them, someone who hacks your board can get them, hackers watching the internet can get them while you backup your database and in the end it's your boards passwords that will be revealed and it's you your members would accuse even if these wouldnt be your fault.

By securing the passwords in the database Jelsoft saves YOU and your users from the trouble and from this point of view you have no rights to complain about "paying money to them", its these security features you are (at least should be) paying for this software. If you are Winoows XP user, go complain to Microsoft too, because they are using the same mechanism for all passwords (user etc.) in the software..

It's never aimed to hide passwords from Site Admins. And in fact Site Admins can still get user's passwords if they want to, but dont ask me the way, I have no intentions of telling you how..

king sting 09-08-2002 05:16 AM

Ok.. everyone says it can be done, and I can hack it in myself.. yet no one wants to tell me how? If you people wont tell me how.. then how can I?

@2 X Viverridae.. go away.

I think this is stupid. Its just a simple request and no one wants to help me with it just because you people think its unmoral or something?

Someone just tell me please.

Logician 09-08-2002 05:26 AM

Quote:

Originally posted by king sting
I think this is stupid. Its just a simple request and no one wants to help me with it just because you people think its unmoral or something?

Someone just tell me please.

Why dont you tell us why you want to get the passwords? What good and legal use they can be used for? I really wonder..

king sting 09-08-2002 05:33 AM

does it matter what I want them for? no it doesn't. thats my business.

I really dont even need them. I just think as a owner of the software I should have control over things like this.

Please point me in the direction of the hack. Whats with all this debate over it? Its my board, I'll run it as I want.

Logician 09-08-2002 05:44 AM

Quote:

Originally posted by king sting
does it matter what I want them for? no it doesn't.

himm let me put it in this way: If you are asking the answer from me, yes it matters to me (and apperantly to the other contributers of this thread), because we dont want to help an Admin who might try to get user's passwords so as to hack into their other accounts in other boards, their personal pages or their email accounts. I cant see another reason as to why an Admin will try to get this info.

Quote:

thats my business.
sure it is .. And people's willing to help you is their business then..

Quote:

Whats with all this debate over it?
I dont debate.. You asked why people does not help and I'm stating why..

king sting 09-08-2002 05:49 AM

Man.. the support around here sucks.


All times are GMT. The time now is 01:41 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01438 seconds
  • Memory Usage 1,832KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_php_printable
  • (9)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete