The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#11
|
||||
|
||||
![]()
As long as it's stated in the privacy policy the admin can do what they want with the users information. Besides the ethics of it it's legal to have users passwords etc.
|
#12
|
||||
|
||||
![]()
Thank you Xenon and Mist for your replies.
nooppid, as I stated, I get an Email notice for all failed attempts. If the moderator/admin login succeeds there there is no need to take any action or send any notices. blakkboy, I have not released this hack. ![]() We have had a lot of break ins into our private forums via compromised passwords of our moderators. The discussions in our moderator forum were being broadcast to other boards. I have incorporated additional security layers on top of the existing VB security. I have made a hack that logs all access to the private forums, I made a hack that does an IP ban for my private forms, and I have made a trusted host list hack per moderator for additional authentication of every moderator in my forums. I have been locked out on several occasions because I was logged into my forums from an IP address that was not listed in the trusted host list. And in such a case I also disable access to the admin and the mod CP's aswell and I also disable a lot of the moderation functions when somsone is logged in from an "un-trusted" host. ![]() nfortunately none of these hacks are published, and I have my personal reasons for my hesitation to publish them. ![]() |
#13
|
||||
|
||||
![]()
a hack I'd really like to find is simultaneous logins by the same user from different IP addresses. I believe a few people on my forum are sharing logins but need something to confirm my suspicions - any ideas on how to do this?
thanks |
#14
|
|||
|
|||
![]() Quote:
![]() I would love to have a hack like that though. Perhaps one day you could show me? MGM out |
#15
|
||||
|
||||
![]() Quote:
![]() There were about 145 login attempts, and all of them did log in as me. But the trusted hosts hack gave all of them an error screen that they were illegally logged in as a moderator or administrator of the board. ![]() |
#16
|
|||
|
|||
![]()
does that work for the forums too or just the admincp?
Because it'd be quite a big problem if they logged in as you in the forums as well But then, what would you do if someone was hacking your board and you were at a friends house. You can't do anything about it but watch! MGM out |
#17
|
|||
|
|||
![]() Quote:
But if someone was hacking my board, i know i wouldn't use the admincp to stop it. I would use the control panel software on the server to htaccess everything down until i could get the issue resolved. |
#18
|
||||
|
||||
![]() Quote:
![]() But I never said I didn't have ways to take over my own board. ![]() ![]() |
#19
|
|||
|
|||
![]()
Want to see something funny as well as pitiful?
Run a query that lists all users where password = md5( yoursitename)... Had a site where over 5% of the users had the site name as their password. |
![]() |
Thread Tools | |
Display Modes | |
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|