The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
|
#1
|
|||
|
|||
![]()
I'm selling a program on my site. I trust the coder very well, as im the one taking the money in and then passing on the profits - commision to him.
However now we want to authenticate the program so that it wont be leaked around, and so only the members who buy it will have access and to be able to use it. This is the description the coder gave to me "Alright, pretty simple script. I pass username/md5 hash of password/auth in GET vars. It returns one of three things. Either 0, which means invalid username or password, 1 which means the user isnt an xkb subscriber, or the email address of the user (which means that it's correct user and pass and the usr has access.) the only security issues are A) If I wanted to (only me, because you need the auth) I could try to bruteforce userpasswords with the script. and B) It gives me the users emails. I don't think either of those are an issue aslong as you consider me a trusted party." Basically what im asking is for a vbulletin coder to take a look at the file he wants me to upload to my sever and tell him if it is safe or if it will cause security issues etc. I will forward the email with the program he sent me to any of the vbulletin coders to help me out. (Basically I'm wondering what is the worse that could be done if he decided to do something malicous etc.) Thanks |
![]() |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|