vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Modification Requests/Questions (Unpaid) (https://vborg.vbsupport.ru/forumdisplay.php?f=112)
-   -   show user password in admin panel v.2.2.0 (https://vborg.vbsupport.ru/showthread.php?t=31947)

dxb 10-31-2001 10:39 PM

I know the passwords are encrypted in v2.2.0 but is there is anyway to have them shown in the admin control panel

I know there is a security risk but I think it's always good to have that option

Palmer ofShinra 11-01-2001 09:05 PM

It's a MAJOR risk...

I had that enabled at my forum, then a hacker got in (thanks to one staff member's utter stupidity).

EVERYONE had to change their passwords... repeatedly.

It was not fun.

Niels vdw 11-01-2001 09:24 PM

You can't decrypt MD5-encrypted passwords

Neo 11-01-2001 10:37 PM

sure you can ;) just takes skill and time

Scott MacVicar 11-01-2001 10:38 PM

md5 produces a 32 character string no matter what, so a book encryped in md5 will be 32 characters and the letter a encrpyted is 32 characters.

There is no way to undo this.

Ruth 11-01-2001 10:46 PM

i dont want to use MD5 encryption because i will be integrating another script along with vB, that calls the passwords from the user table. and this would make it so difficult.

dxb 11-01-2001 11:13 PM

yeah I know that there is a risk in having the passwords visible but I'm the only person who can enter the admin panel and I didnt have any problems for over 3 years since I started with UBB

and I know it's really hard to decrypt the MD5 encryption but I was hoping somebody will figure it out :)

snyx 11-02-2001 03:17 AM

so you want a script to allow you to view passwords via CP, by decrypting the MD5-encrypted passwords on the DB? sorry man, aint NOBODY going to make this, if its at all POSSIBLE! best bet is to take out the encrypting alltogether before you can takle ANYTHING, sorry man, try www.elance.com for this one. your looking at $250 MIN.

Admin 11-02-2001 11:36 AM

It's not that hard to create an encryption that can be later decrypted, but using unique keys so no one will be able to decrypt an encrypted value. (without getting the keys and source code of the encryption, of course)

Btw, I *think* MD5() was already decrypted by someone, but I'm far from sure.
And if anyone will be able to decrypt MD5 hashes with 100% success, trust me he won't be giving it to you. :)

dxb 11-02-2001 02:12 PM

ok then I should forget this idea then :( but I think it was a good idea to give the users the option if they wanted to encrypt the passwords when upgrading

because the reason that keeping from upgrading to 2.2.0 is this thing because I get too many complains of new users that they cant login and things like that and I have to login using their accont to see the problem

anyway I hope Jelsoft Enterprises will consider puting that option back to config file


All times are GMT. The time now is 08:19 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03507 seconds
  • Memory Usage 1,728KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete