vBulletin does not allow you anymore to use a password that's the same as the username.
Run a manual query on the database to encode the pass to be like the username.
Then use the internal tool to diagnose for vulenarable passwords, it will find ALL users ..
then rewrite it to not show as vulnerable but as password reset email ..
and it generates the new pass for the user and emails them.
--------------- Added [DATE]1275630577[/DATE] at [TIME]1275630577[/TIME] ---------------
PHP Code:
<?php // made with help by ryan ashbrook, madmikeyb and chroder, // for floris at http://vbfans.com
die(); // uncomment this before using, and after editing this file. require_once ( './global.php' ); $query = $vbulletin->db->query_read ( "SELECT * FROM `" . TABLE_PREFIX . "user` WHERE usergroupid = 95" ); while ( $user = $vbulletin->db->fetch_array ( $query ) ) { echo ( '<p>Updating user ' . $user['username'] . '...' ); $vbulletin->db->query_write ( ' UPDATE `' . TABLE_PREFIX . 'user` SET password = \'' . md5 ( md5 ( $user['username']) . $user['salt'] ) . '\' WHERE userid = ' . $user['userid'] . ' ' ); echo ( ' done!</p>' ); } ?>
This is what I used on 3.8 forum to force the usergroupid 95 to have the same password as the username, so afterwards I could use the ' check for vulnerable pass ' feature built-in from vbulletin 3.8.
surely this works on 4.0 too.
BACK YOUR DB UP
put this in like 'forcepass.php' and put it in admincp/
edit the file to point to the usergroup,
add // in front of die();
and run it from the browser.
good luck
Very nice Floris i will be bookmarking this page for sure thanks for the share :up: