Quote:
Originally Posted by Ocean
Update - after completely shutting down my browser and going back in - everything works now.
Strange, yes? Perhaps it had something to do with the cookies from the two vB boards (although they did have different prefixes).
As a seperate question, though - since this hack does something extra with the entered password before submitting it through the MD5 Hash - is there any additional security risk? Do normal or AdminCP logins end up with a cleartext copy of the password floating around anywhere?
|
Glad you got it working. To answer your question: No, the only place the attempted password gets passed to is the webmaster's email, and even then only if its incorrect. This has no effect on regular logins.