vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 Programming Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=15)
-   -   Question about the login system. (https://vborg.vbsupport.ru/showthread.php?t=186139)

Spybot S&D 07-23-2008 03:20 PM

Question about the login system.
 
I was wondering how I would improve vbulletin's security system.

The problem is, that there is a member on our forum that has been banned numerous times, and he now owns a website similar to the content of ours. We believe that he has downloaded his forum's database and has been cracking the hashes, getting access to some of the members on our forum.

I was wondering if there was a way to change the login algorithm to something a LOT more complicated. Like, pretend this is the login algorithm now:

md5(md5(password + salt))

I would want to change mine to something like this:

md5(md5(md5(md5(md5(userid + username + password + salt)))))

Or even something more secure.

Is there any way of doing this? A tutorial would be a GREAT help :)

Thanks!

DarkScythe 07-23-2008 03:58 PM

I just wanted to comment about that method.. I've read about it before as I used to want to do something similar, but from what I've read, I don't think that actually improves security any.. some say it actually makes it worse.

If the guy has downloaded your database, I'd look into securing the path he took to get to it first. Anyway, adding a userid and username to it won't be too much help if that guy figures it out because he will also have the userids and usernames of everyone on the forum. What you would want to do is probably either have everyone change their passwords to invalidate his copy of the database, or change the current salt / add a second salt to the extra round of hashing.

md5(md5(md5(password)+salt)+salt2) might be better.. This is based from what I've read though, so I could be wrong.

Spybot S&D 07-23-2008 05:00 PM

Quote:

Originally Posted by DarkScythe (Post 1582405)
I just wanted to comment about that method.. I've read about it before as I used to want to do something similar, but from what I've read, I don't think that actually improves security any.. some say it actually makes it worse.

If the guy has downloaded your database, I'd look into securing the path he took to get to it first. Anyway, adding a userid and username to it won't be too much help if that guy figures it out because he will also have the userids and usernames of everyone on the forum. What you would want to do is probably either have everyone change their passwords to invalidate his copy of the database, or change the current salt / add a second salt to the extra round of hashing.

md5(md5(md5(password)+salt)+salt2) might be better.. This is based from what I've read though, so I could be wrong.

He doesn't have access to my database. He owns a forum, and a lot of my members are also members on his forum.

Dismounted 07-24-2008 06:44 AM

It probably would be difficult to change the current algorithm. Even so, your "suggested" algorithm wouldn't provide much more "protection".

Marco van Herwaarden 07-24-2008 07:09 AM

Most likely scenario is that users from your forum also registered in his using he same password. He might have hacked his own board to log the real password the users use, and use that logged password to login to your board.

Nothing you can do against this, except ask your users not to use the same password on other sites.


All times are GMT. The time now is 12:52 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02500 seconds
  • Memory Usage 1,718KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (5)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete