The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
Password Security Tools Details »» | |||||||||||||||||||||||||
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Password Security Tools For vBulletin 3.7.0 and above -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Description -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- A product designed to combat the recent increase in weak password attacks by spammers. For background information, read the following threads: http://www.vbulletin.com/forum/showthread.php?t=278975 http://www.vbulletin.com/forum/showthread.php?t=281371 -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- The Problem -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- The problem stems from the fact that vBulletin doesn't check the quality of a user's password when registering or changing the password in the User CP. As a result, users are able to choose easily guessable passwords to protect their account. The most common passwords are things like "password", "12345", "qwerty", "letmein", as well as the user's own username. On a large forum, these poorly protected accounts can number hundreds or even thousands, and this has shown itself to be a prime opportunity for spammers to exploit. With a relatively simple script, spammers are able to scrape the member list from your forum and automatically validate which of the accounts have such passwords. A spammer with access to tens, hundreds or thousands of legitimate user accounts is a situation you don't want to be in. -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- What This Does -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- This product has two main functions. 1. It prevents users from using their own username as a password, or any other commonly used word. (An editable list of banned passwords is available in the Admin CP.) The same rules apply if a user tries to change their password after registration. 2. It provides you with a tool to identify existing user accounts that have bad passwords, and lets you reset those passwords. Emails will be automatically dispatched to affected users notifying them of the change, and providing instructions on how to gain access to their account. -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Installation -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- To install: 1. Upload cpnav_passrepair.xml to includes/xml/ 2. Upload passsec.php to admincp/ 3. Upload product-passrepair.xml to your Admin CP as a product 4. Enable the product in vBulletin Options -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Password Scanner - Usage Notes -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- The password scanning portion of this product is a utility designed for use by administrators. There are a few things to be aware of. 1. BACK UP YOUR DATA BEFORE USING THIS SCRIPT. 2. It's not a tool designed for frequent usage, it's a quick and dirty way of getting the job done. If Jelsoft don't address this issue, I might return to it and optimize the password scanner to make it a little less server intensive. Use it sparingly, and close your forums before commencing a scan. 3. The password scanner has the potential to send out a lot of email. Use the "Users Per Page" setting to process accounts at whatever rate you deem your server capable of handling. 4. After you've installed this product it'll be impossible for users to register using a blacklisted or invalid password (or to change it to one afterwards). As a result, you should only need to use the password scanner once. Feel free to remove the passsec.php and cpnav_passrepair.xml files from your server once you're done with the scanner, the rest of the product will still function. 5. For unattended bulk processing of accounts, there's some javascript in passsec.php that's currently commented out. Use it at your own risk. Show Your Support
|
Благодарность от: | ||
markslevent |
Comments |
#32
|
||||
|
||||
Come back soon for free soup.
Thanks! |
#33
|
||||
|
||||
specify your own custom banned passwords here.
So I can copy and paste! |
#34
|
|||
|
|||
Just wanted to say thank you for the great mod!
Our 70k users database had about 900 people using their name as password, and another 600+ using weak passwords, we were getting slammed with spam PMs today from some script exploiting users with weak passwords, this proved very useful. |
#35
|
|||
|
|||
awww, I think I am the only one getting the database error :/ I hope you can help me John, I really want to use this bad. your work is much appreciated!
|
#36
|
||||
|
||||
Try this.
|
#37
|
||||
|
||||
Try the attached passsec.php in the above post.
|
#38
|
|||
|
|||
<font color="Red"> Users with usernames as passwords: 5214
Users with common passwords: 8801</font> thanks it works now, however I should have uped it from 100 before starting lol, I now have to click on next 140 times. Didn't' take too long tho. many thanks. |
#40
|
||||
|
||||
Installed, ran the scan, works perfectly. 84 passwords=usernames and 82 matched the common password list. Out of 3,355 members, by the way.
Thanks John! |
#41
|
||||
|
||||
I keep getting an in complete or corrupted download. When I extract it there is only a zero byte file. TIA.
P.S. I also had this happen with another file from another Mod. Not yours though. |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|