Go Back   vb.org Archive > Community Discussions > Modification Requests/Questions (Unpaid)
  #1  
Old 07-16-2002, 01:53 PM
PaulBearer2k PaulBearer2k is offline
 
Join Date: Jul 2002
Posts: 24
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default 2 Hack Requests

These are probably just simple little hacks, but I'm slow so well I'll let you guys give it a crack.

For the moderator's cp, I have many only about 6 mods, and I trust them since I'm the only admin at my place. So I was wondering on the mod cp, can you make it so that the moderator's can view the passwords?

Is there anyway to add a hole new function called Junior Moderator's. These would be like moderator's with less functions and without a cp. They'd get to open/close/move threads and that's about it. There name wouldn't be special on the who's online, nor would there name be under moderators. Just a small hack I'd like. But more importantly, the mods cp view pass hack. Thanks in advanced.
Reply With Quote
  #2  
Old 07-16-2002, 02:00 PM
SaintDog SaintDog is offline
 
Join Date: Nov 2001
Location: Tennessee
Posts: 1,975
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

1. Passwords are MD5'ed for security, you can set a new password but admins nor mods can view the passwords by default (it is best this way as well).

2. Add a new user group and set their priviledges according to what you want them to have access to, you can do this buy going to:

Admin Cp -> User Groups -> Add

Regards,

- SaintDog
Reply With Quote
  #3  
Old 07-16-2002, 04:06 PM
PaulBearer2k PaulBearer2k is offline
 
Join Date: Jul 2002
Posts: 24
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Alright, well is there anyway that I can view passwords in the admin cp? I know this hack is available for ubb's, phpbb's but not sure about vbulletin.
Reply With Quote
  #4  
Old 07-16-2002, 04:33 PM
filburt1 filburt1 is offline
 
Join Date: Feb 2002
Location: Maryland, US
Posts: 6,144
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally posted by PaulBearer2k
Alright, well is there anyway that I can view passwords in the admin cp? I know this hack is available for ubb's, phpbb's but not sure about vbulletin.
After 2.0.3, you can't. Even if you hacked it, users would have to re-enter the passwords since they're stored as MD5 hashes which can't be decrypted back to their original values.
Reply With Quote
  #5  
Old 07-16-2002, 07:27 PM
scsa20's Avatar
scsa20 scsa20 is offline
 
Join Date: Mar 2002
Location: Mars
Posts: 458
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally posted by filburt1


After 2.0.3, you can't. Even if you hacked it, users would have to re-enter the passwords since they're stored as MD5 hashes which can't be decrypted back to their original values.
nicely said

unlike uBB and phpBB, vbulletin used the MD5 hashes (like filburt and SaintDog said ) meaning you can not decrypt them...basicly you first asked if mods can view passwords in the mod cp and SaintDog said that you can't, so that basicly answered your second question about viewing it in the admin cp

Reason for this?? it's because any normal hacker that likes to hack into peoples sites won't be able to crack a MD5 hashe encryption (unless they are on the run for doing so)...and so that any of your admins/mods won't be able to go into someones account and start posting sh*t under there name
Reply With Quote
  #6  
Old 07-17-2002, 08:33 AM
Logician's Avatar
Logician Logician is offline
 
Join Date: Nov 2001
Location: inside vb code
Posts: 4,449
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally posted by scsa20
Reason for this?? it's because any normal hacker that likes to hack into peoples sites won't be able to crack a MD5 hashe encryption (unless they are on the run for doing so)...and so that any of your admins/mods won't be able to go into someones account and start posting sh*t under there name
Are you sure?

If you manage to access MD5 hash password of someone all you have to do is to change your vb cookie in your browser and replace userid and password sections with these info of the user. So you will be able to login as HIM unless he disabled "remember me" setting in his User CP and you dont need to decrypt his password.

Besides if a hacker managed to login your site and access your database, user password security and his spamming in your site as you will be your last concern..

@PaulBearer2k: whatever the reason to save password in MD5 format is, it's true that you and your mods cant read them inside your cp. No way unless you alter your database and save the unencrypted version of the password in a new field whenever it's updated..

Logician
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:59 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04387 seconds
  • Memory Usage 2,209KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (3)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (6)post_thanks_box
  • (6)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (6)post_thanks_postbit_info
  • (6)postbit
  • (6)postbit_onlinestatus
  • (6)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete