assuming you're sending the emails from the admincp, the username variable should be $username. I could be wrong, but i dont think you can send the password out. What i usually do is is link them to the page to change their password if they've forgotten it. At least that way it's a bit more secure (even though if someone else got the e-mail the new pass would be sent to that email anyway.)
The rules can be changed in the forum_rules_description phrase
|