Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 Programming Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 07-23-2008, 04:20 PM
Spybot S&D Spybot S&D is offline
 
Join Date: Jun 2007
Posts: 57
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Question about the login system.

I was wondering how I would improve vbulletin's security system.

The problem is, that there is a member on our forum that has been banned numerous times, and he now owns a website similar to the content of ours. We believe that he has downloaded his forum's database and has been cracking the hashes, getting access to some of the members on our forum.

I was wondering if there was a way to change the login algorithm to something a LOT more complicated. Like, pretend this is the login algorithm now:

md5(md5(password + salt))

I would want to change mine to something like this:

md5(md5(md5(md5(md5(userid + username + password + salt)))))

Or even something more secure.

Is there any way of doing this? A tutorial would be a GREAT help

Thanks!
Reply With Quote
  #2  
Old 07-23-2008, 04:58 PM
DarkScythe DarkScythe is offline
 
Join Date: Jun 2008
Posts: 21
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I just wanted to comment about that method.. I've read about it before as I used to want to do something similar, but from what I've read, I don't think that actually improves security any.. some say it actually makes it worse.

If the guy has downloaded your database, I'd look into securing the path he took to get to it first. Anyway, adding a userid and username to it won't be too much help if that guy figures it out because he will also have the userids and usernames of everyone on the forum. What you would want to do is probably either have everyone change their passwords to invalidate his copy of the database, or change the current salt / add a second salt to the extra round of hashing.

md5(md5(md5(password)+salt)+salt2) might be better.. This is based from what I've read though, so I could be wrong.
Reply With Quote
  #3  
Old 07-23-2008, 06:00 PM
Spybot S&D Spybot S&D is offline
 
Join Date: Jun 2007
Posts: 57
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by DarkScythe View Post
I just wanted to comment about that method.. I've read about it before as I used to want to do something similar, but from what I've read, I don't think that actually improves security any.. some say it actually makes it worse.

If the guy has downloaded your database, I'd look into securing the path he took to get to it first. Anyway, adding a userid and username to it won't be too much help if that guy figures it out because he will also have the userids and usernames of everyone on the forum. What you would want to do is probably either have everyone change their passwords to invalidate his copy of the database, or change the current salt / add a second salt to the extra round of hashing.

md5(md5(md5(password)+salt)+salt2) might be better.. This is based from what I've read though, so I could be wrong.
He doesn't have access to my database. He owns a forum, and a lot of my members are also members on his forum.
Reply With Quote
  #4  
Old 07-24-2008, 07:44 AM
Dismounted's Avatar
Dismounted Dismounted is offline
 
Join Date: Jun 2005
Location: Melbourne, Australia
Posts: 15,047
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

It probably would be difficult to change the current algorithm. Even so, your "suggested" algorithm wouldn't provide much more "protection".
Reply With Quote
  #5  
Old 07-24-2008, 08:09 AM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Most likely scenario is that users from your forum also registered in his using he same password. He might have hacked his own board to log the real password the users use, and use that logged password to login to your board.

Nothing you can do against this, except ask your users not to use the same password on other sites.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:35 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05056 seconds
  • Memory Usage 2,197KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (5)post_thanks_box
  • (5)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (5)post_thanks_postbit_info
  • (5)postbit
  • (5)postbit_onlinestatus
  • (5)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete