View Single Post
  #28  
Old 11-04-2001, 01:11 AM
thewitt's Avatar
thewitt thewitt is offline
 
Join Date: Oct 2001
Location: Maine
Posts: 45
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally posted by Bald Bouncer
[clip]my main forum has been running for over 5 years now and we have never had a security breach and have always been very carefull.
As in most password exploits, you would likely never know if someone was using other people's accounts on your server because their passwords were exposed.

As for selling me, you posted here looking for support for adding a feature back into the product that is a no-no in every intellegent security resource on the planet. If you just wanted to ask Jelsoft to put it back in, you could have done so in a private email. That appears to me to be a solicitation for support, and I'm simply telling you that you don't have mine yet.

If you don't care, that's fine. I'm not put out by it, just giving you a chance to explain your reasoning for asking for what I consider to be a huge security hole in the software.

I would suggest that it will take more than a "put it back cause I don't like the change" argument to make a difference - but I've been wrong before.

Now someone could certainly write a hack that intercepts the password validation process and writes the plain-text, pre-encrypted password into another field in the database. I suspect this will be the way you'll expose the passwords in your forums in the future, and not by some reversal of design in vBulletin - but again, I've been wrong before.

If you want Jelsoft to put it back the way it was, you might also post your concerns in the vBulleting community forums and not in the hack forums. I'm not sure if that will make a difference, but I susect that's a better place to ask Jelsoft for changes.

Good luck,

-t
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01215 seconds
  • Memory Usage 1,765KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete