Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions

Reply
 
Thread Tools Display Modes
  #1  
Old 12-20-2001, 02:21 PM
Jawelin Jawelin is offline
 
Join Date: Nov 2001
Posts: 557
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hi.
For security reasons, I would make the adminCP cookie-aware; in other words, how could I make me already known when logging to the AdminCP without retypeing user/pw any new session ?

I wrote 'for security reasons'.... YES! Simply, I would make the admin pw change once a couple of days, so I only need to know the new (randomly generated) one only once and don't remember it, cause my browser could do it for me...

What do you think about ?
Bye
Reply With Quote
  #2  
Old 03-28-2002, 12:45 PM
Jawelin Jawelin is offline
 
Join Date: Nov 2001
Posts: 557
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Anybody ?
Bump, please!
Reply With Quote
  #3  
Old 03-28-2002, 02:56 PM
LaNder LaNder is offline
 
Join Date: Nov 2001
Posts: 19
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

How about to use a shortcut?

http://...../admin/index.php?loginusername=OURNAME&loginpassword=OURP ASS
Reply With Quote
  #4  
Old 03-28-2002, 03:58 PM
Jawelin Jawelin is offline
 
Join Date: Nov 2001
Posts: 557
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Nice, thanks!

What I don't like is to have a persistent query_string with a displayed password all the time...
How could I - for instance - preset at least the user name with cookies ?

Thnx
Reply With Quote
  #5  
Old 03-28-2002, 07:53 PM
okrogius okrogius is offline
 
Join Date: Dec 2001
Location: USA
Posts: 264
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just user the username string, password string isn't needed for it to autorecognize you.
Reply With Quote
  #6  
Old 03-28-2002, 08:38 PM
Jawelin Jawelin is offline
 
Join Date: Nov 2001
Posts: 557
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes!
I tried and actually can use each Admin username to login the AdminCP without any password.
Checked the $bbuserinfo and it's always me (guess from cookie infos..), but the login name can be anyone of the other admins.

Could you explain me why ????

Thanks


P.S.: just a point out. I can use ANY loginusername=dummy to directly enter the AdminCP, bypassing the login challenge page... Neither is needed an actual bb username. Very very unpredictable...

Sessions.... bah!!! aranoid:

It seems unsafe, first touch... but cookies are the network security atom .... :knockedout:
Reply With Quote
  #7  
Old 03-29-2002, 01:02 AM
galt galt is offline
 
Join Date: Mar 2002
Location: USA
Posts: 48
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I do not like the idea of using a cookie that say "loginusername=dummy" to get in. It i stoo easy to guess your admin name or anyone elses (they are on the forum already!!). If you are going to build a login=xxx in a cookie, it should be something hard to just guess and hack. Maybe the md5 encrypted password string. Or both.

Better but not perfect.

SO if this is teh way vB works now, anyone can hack almost any system just by editing their cookie file.

Let's see, I wonder where the Version 3 development forums are ?
Reply With Quote
  #8  
Old 03-29-2002, 06:28 AM
Admin's Avatar
Admin Admin is offline
Coder
 
Join Date: Oct 2023
Location: Server
Posts: 1
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That's not true, Jawelin. If it happened you were either already logged in or messed up your sessions.php file.

Oh and galt: http://beta.jelsoft.com/
Reply With Quote
  #9  
Old 03-29-2002, 08:27 AM
Issvar Issvar is offline
 
Join Date: Mar 2002
Posts: 68
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

FireFly, you are wrong, if you have cookies set you can login to admin control panel, by adding going to /admin/index.php?loginusername=xxx it doesn't matter what xxx is, it can be anything, doesn't have to be a user.

I verified by dumping everything from the session table in myphpadmin and then logging in. It doesn't work if you have cleared your cookies, so you still need to find a board with html enabled anywhere to steal cookies from admins. Btw, if you steal cookies you can still change email and then change password to get admin cp access, so for the endevouring hacker nothing changes
Reply With Quote
  #10  
Old 03-29-2002, 08:49 AM
Jawelin Jawelin is offline
 
Join Date: Nov 2001
Posts: 557
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

[QUOTE]Originally posted by FireFly
That's not true, Jawelin. If it happened you were either already logged in or messed up your sessions.php file.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:59 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03956 seconds
  • Memory Usage 2,235KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete