The Arcive of Official vBulletin Modifications Site.It is not a VB3 engine, just a parsed copy! |
|
#1
|
||||
|
||||
Is there a 'see members pw' hack available?
If so can you point me in the right direction?
edit: Also, could someone not draw up a dummy request for the members name and password. I know nothing about hacking, but how hard would it be to create a section within VB in which upon the member clicking they would be prompted to enter their member name and pw for confirmation. This of course not being encrypted, and either logged or emailed to the admin. |
#2
|
||||
|
||||
First, how come you want your members passwords?
|
#3
|
||||
|
||||
No, because members may use the same password for other forums or sites - it would be bad for an admin to abuse that.
|
#4
|
||||
|
||||
not necessarily.....
why do you assume it is necessarily for a negative reason. if an admin wanna abuse his users, he could sell the email list he has to any porno site, or could do any other thing that might cross your mind. I still would like to ask for this hack. if an admin wanna abuse the user and see his or her password, he could always change the email address of that user in the control panel, to his own email, and send the password to the user. it is that easy. |
#5
|
||||
|
||||
Quote:
|
#6
|
|||
|
|||
He can't change their email to his own email and get the password sent, as it resets the password when being sent.
Also, to answer the thread starters question: vBulletin uses a MD5 hash technology and it's next to impossible to decode it... |
#7
|
||||
|
||||
Quote:
|
#8
|
|||
|
|||
Here's some general advice: Use a different password at every forum you go to, because some people might want it for malicious uses and if ever a hack is released, or they get their hands on a MD5 decoder, you're screwed
|
#9
|
||||
|
||||
The only good use I think think for finding/knowing users passwords is for finding people who have registered dublicate times, in which case there is already a hack that does this, it will compare all the MD5 hashes for duplicate passwords. There is never any need to know what the users password is.
|
#10
|
|||
|
|||
However when people register multiple times, they still could be using a different password, which means there are no uses
|
|
|
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
More Information | |
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|