Go Back   vb.org Archive > News and Announcements > vBulletin Pre-Sales Questions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 09-12-2008, 06:33 PM
dvongrad dvongrad is offline
 
Join Date: Sep 2008
Posts: 5
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Auto Login

I am thinking of using vBulletin to host forums on my web site. I would like to access this forum via a menu item in my Windows application that launches a URL and query string similar to the following (or whatever URL and query string I should use):

http://www.mycompany.com/vBulletin/l...id&pw=password

If you could point me to relevant sections of your documentation or examples from your site or other areas of your forums, I would be most appreciative. Thank you for your attention regarding this matter.
Reply With Quote
  #2  
Old 09-12-2008, 06:47 PM
nexialys
Guest
 
Posts: n/a
Default

there is no documentation about how to convert the actual authentication process.

for what you need, someone will have to deactivate all the authentication securities inside vBulletin to make it possible to login from a GET line... so any hacker or spammer will be able to access your forum...

remember that when you deactivate all securities, your site is easy to crack...

also, the session system inside vBulletin let your users be logged-in infinitely, so it is useless to have the login info in the url... once you're logged in, you can be forever logged in...
Reply With Quote
  #3  
Old 09-12-2008, 07:04 PM
dvongrad dvongrad is offline
 
Join Date: Sep 2008
Posts: 5
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Would hacking/spamming still be an issue if the user/password combination was a user who had absolutely no rights other than viewing forum posts?
Reply With Quote
  #4  
Old 09-13-2008, 12:07 AM
nexialys
Guest
 
Posts: n/a
Default

it is not a question of rights of user X, but the ability to spambot X to try any combination of username/password...

why do you think the net evoluted and brought encryption on password and logins ?!... because a spambot can try more than 50 000 combinations of random username/passwords per minute, trying to access your forum OR breaking your server by DDOS or DOSS... (denial of service)...
Reply With Quote
  #5  
Old 09-13-2008, 02:05 AM
SEOvB's Avatar
SEOvB SEOvB is offline
 
Join Date: May 2007
Location: Indianapolis
Posts: 2,451
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by dvongrad View Post

Would hacking/spamming still be an issue if the user/password combination was a user who had absolutely no rights other than viewing forum posts?
Trust us you dont want to remove the built in securities of vBulletin. You'll have some idiot bot pounding at you forum 24x7 just trying everything to get in which could lead to more problems from the bot doing it other than just whatever it may post such as server loads which could get your account suspended.
Reply With Quote
  #6  
Old 09-16-2008, 02:58 PM
dvongrad dvongrad is offline
 
Join Date: Sep 2008
Posts: 5
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

That certainly makes sense and I appreciate your comments. Rather than disabling security outright, is it possible to disable security for a single read-only user and then enable it upon an auto login or would such changes still be prone to attacks? Another approach might be to pass a query string not containing user/password info to vBulletin and then modifying index.php to check for the query string and populate the user/password fields and click the login button (possibly through JavaScript) if there's a match. The Windows application where this URL and query string would come from if fully secured and thus no login info would have to be passed.
Reply With Quote
  #7  
Old 09-21-2008, 01:05 PM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

If you want to allow guests to view threads on the forum (that is what you are trying to do with a single user with low security with read-only access), hen no user account is needed. Simple form permissions can be set to allow guests to read threads.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 08:25 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.03978 seconds
  • Memory Usage 2,211KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (7)post_thanks_box
  • (7)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (7)post_thanks_postbit_info
  • (7)postbit
  • (5)postbit_onlinestatus
  • (7)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete