The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
|||
|
|||
![]()
Would anyone be interested in writing a hack for finding duplicate users?
There was a hack written for this by checking the ip's and the passwords, and if two users matched it would so it. |
#2
|
||||
|
||||
![]() Quote:
|
#3
|
|||
|
|||
![]()
Hashing can remain with the same password checking, but unique user salts would indeed have to go.
|
#4
|
||||
|
||||
![]() Quote:
now anyone who got the md5 from one site could use it on another vB with the same modifcation made thus creating an insecure system... |
#5
|
|||
|
|||
![]() Quote:
Whether or not these two (see first sentence) can be aplied to a typical vb user, noting especially how many vbulletins run on shared hosting, that is a whole different story. Do you want to remove an extra safety net in case your well versed technical co-admin places a db backup somewhere without any security (another random example why hashes are there, but note that it does not make not hasing any less secure, it's just significantly harder to "screw up" if the passwords are hashed)? |
#6
|
|||
|
|||
![]()
I'm not asking to see the actual passwords, just the md5 hashes, so if the user has the same ip, and the same password i can assume it is a double user.
There was a hack made before for vb2, all i'm asking is for a vb3 version. |
#7
|
|||
|
|||
![]()
<a href="https://vborg.vbsupport.ru/showthread.php?t=36269" target="_blank">https://vborg.vbsupport.ru/showthread.php?t=36269</a>
|
#8
|
||||
|
||||
![]()
We know that
![]() |
#9
|
|||
|
|||
![]()
What's Salt?
And if it can't be done, then just the same ip would be fine. |
#10
|
||||
|
||||
![]() Quote:
md5+salt+password and each salt is random |
![]() |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|