Go Back   vb.org Archive > Community Central > Community Lounge
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 10-13-2003, 03:45 PM
Dean C's Avatar
Dean C Dean C is offline
 
Join Date: Jan 2002
Location: England
Posts: 9,071
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As long as it's stated in the privacy policy the admin can do what they want with the users information. Besides the ethics of it it's legal to have users passwords etc.
Reply With Quote
  #12  
Old 10-13-2003, 04:06 PM
Zzed's Avatar
Zzed Zzed is offline
 
Join Date: Feb 2002
Location: Glendale, CA, USA
Posts: 463
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Thank you Xenon and Mist for your replies.

nooppid, as I stated, I get an Email notice for all failed attempts. If the moderator/admin login succeeds there there is no need to take any action or send any notices.

blakkboy, I have not released this hack.

We have had a lot of break ins into our private forums via compromised passwords of our moderators. The discussions in our moderator forum were being broadcast to other boards. I have incorporated additional security layers on top of the existing VB security. I have made a hack that logs all access to the private forums, I made a hack that does an IP ban for my private forms, and I have made a trusted host list hack per moderator for additional authentication of every moderator in my forums. I have been locked out on several occasions because I was logged into my forums from an IP address that was not listed in the trusted host list. And in such a case I also disable access to the admin and the mod CP's aswell and I also disable a lot of the moderation functions when somsone is logged in from an "un-trusted" host.

nfortunately none of these hacks are published, and I have my personal reasons for my hesitation to publish them.
Reply With Quote
  #13  
Old 01-23-2004, 10:55 AM
jjj0923's Avatar
jjj0923 jjj0923 is offline
 
Join Date: Mar 2002
Location: Maryland
Posts: 146
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

a hack I'd really like to find is simultaneous logins by the same user from different IP addresses. I believe a few people on my forum are sharing logins but need something to confirm my suspicions - any ideas on how to do this?

thanks
Reply With Quote
  #14  
Old 01-23-2004, 10:55 PM
MGM MGM is offline
 
Join Date: Jan 2003
Location: Michigan
Posts: 245
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Zzed
Thank you Xenon and Mist for your replies.

nooppid, as I stated, I get an Email notice for all failed attempts. If the moderator/admin login succeeds there there is no need to take any action or send any notices.

blakkboy, I have not released this hack.

We have had a lot of break ins into our private forums via compromised passwords of our moderators. The discussions in our moderator forum were being broadcast to other boards. I have incorporated additional security layers on top of the existing VB security. I have made a hack that logs all access to the private forums, I made a hack that does an IP ban for my private forms, and I have made a trusted host list hack per moderator for additional authentication of every moderator in my forums. I have been locked out on several occasions because I was logged into my forums from an IP address that was not listed in the trusted host list. And in such a case I also disable access to the admin and the mod CP's aswell and I also disable a lot of the moderation functions when somsone is logged in from an "un-trusted" host.

nfortunately none of these hacks are published, and I have my personal reasons for my hesitation to publish them.
I think I understand your reasoning.... the code you used could perhaps be used against you if a member were to see it posted on vb.org. Perhaps the code you're using isn't all that secure itself

I would love to have a hack like that though. Perhaps one day you could show me?

MGM out
Reply With Quote
  #15  
Old 01-23-2004, 11:15 PM
Zzed's Avatar
Zzed Zzed is offline
 
Join Date: Feb 2002
Location: Glendale, CA, USA
Posts: 463
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MetalGearMaster
I think I understand your reasoning.... the code you used could perhaps be used against you if a member were to see it posted on vb.org. Perhaps the code you're using isn't all that secure itself

I would love to have a hack like that though. Perhaps one day you could show me?

MGM out
I posted my Admin password in my forum last friday and invited people to login as me. I know what I did is quite insane, but every single one of those people were stopped in their tracks. They came back to that thread and whined about it too.

There were about 145 login attempts, and all of them did log in as me. But the trusted hosts hack gave all of them an error screen that they were illegally logged in as a moderator or administrator of the board.
Reply With Quote
  #16  
Old 01-24-2004, 03:53 PM
MGM MGM is offline
 
Join Date: Jan 2003
Location: Michigan
Posts: 245
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

does that work for the forums too or just the admincp?

Because it'd be quite a big problem if they logged in as you in the forums as well

But then, what would you do if someone was hacking your board and you were at a friends house. You can't do anything about it but watch!

MGM out
Reply With Quote
  #17  
Old 01-24-2004, 09:27 PM
RDX1 RDX1 is offline
 
Join Date: Apr 2002
Posts: 497
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MetalGearMaster
But then, what would you do if someone was hacking your board and you were at a friends house. You can't do anything about it but watch!
Personally, i know that the AdminCP doesn't offer any protection from hackers but turning the board off, and if you don't have your admincp htaccessed, you should.

But if someone was hacking my board, i know i wouldn't use the admincp to stop it. I would use the control panel software on the server to htaccess everything down until i could get the issue resolved.
Reply With Quote
  #18  
Old 01-26-2004, 05:55 PM
Zzed's Avatar
Zzed Zzed is offline
 
Join Date: Feb 2002
Location: Glendale, CA, USA
Posts: 463
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MetalGearMaster
does that work for the forums too or just the admincp?

Because it'd be quite a big problem if they logged in as you in the forums as well

But then, what would you do if someone was hacking your board and you were at a friends house. You can't do anything about it but watch!

MGM out
It works for both Admin CP and the forums.

But I never said I didn't have ways to take over my own board.
Reply With Quote
  #19  
Old 01-26-2004, 06:49 PM
vbmechanic vbmechanic is offline
 
Join Date: Jan 2004
Posts: 104
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Want to see something funny as well as pitiful?

Run a query that lists all users where password = md5( yoursitename)... Had a site where over 5% of the users had the site name as their password.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 02:21 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04479 seconds
  • Memory Usage 2,253KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (4)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (9)post_thanks_box
  • (9)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (9)post_thanks_postbit_info
  • (9)postbit
  • (9)postbit_onlinestatus
  • (9)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete