Previous Thread
Next Thread
Print Thread
Rate Thread
#75850 08/13/2001 7:01 AM
Joined: Jul 2000
Posts: 1,349
Ell Offline
Member
Member
Offline
Joined: Jul 2000
Posts: 1,349
Not at all. It's 100% susceptible to a brute-force attack- there's no flood checking on logging in (which there should be).

AL, at the very least, do this to your files:

[code][/code]

And replace "viewpw" with something unique+non-guessable to you- "pilot", "tomato", whatever. Now, even if this guy hacks in, he's not going to be able to see all your members' passwords (which should be the default behaviour). But, YOU can see them, because you know what the secret "in" word is.. to view a members' password, open their profile as usual, and add "&(yourword)=true" to the url of the profile, and hit enter.

So, if you didn't change my code, and if the URL looks like:

http://www.myubb.com/cp.cgi?ubb=get_profile_for_admin&u=00006479

Change it to:

http://www.myubb.com/cp.cgi?ubb=get_profile_for_admin&u=00006479[b]&viewpw=true[/b]

This will reload the page, and let you see the users' password. (note that you should change "viewpw" to something else, just incase any potential hackers are reading this)

Obviously this won't stop him hacking in in the first place, but it does let you breate if/when he does, knowing that he's not able to get everyone elses' passwords. For this reason, I suggest that you don't tell ANY other admins/anyone else what your secret replacement word for "viewpw" is- they don't have any legitimate reason for needing a members password.

On another note, have you changed all the passwords on your admins' email accounts? If they were the same as the UBB passwords at any point, he may have access to your email, and so to get the latest admin password, he just needs to use the "forgot my password" feature, then check your email.

[ August 13, 2001: Message edited by: Borg ]

Sponsored Links
Entire Thread
Subject Posted By Posted
ubb 6 = easy to hack? Brad.loo 08/12/2001 10:03 PM
Re: ubb 6 = easy to hack? Ell 08/12/2001 10:14 PM
Re: ubb 6 = easy to hack? Brad.loo 08/12/2001 10:17 PM
Re: ubb 6 = easy to hack? Soul 08/12/2001 11:03 PM
Re: ubb 6 = easy to hack? Brad.loo 08/12/2001 11:38 PM
Re: ubb 6 = easy to hack? Greg Hard 08/12/2001 11:44 PM
Re: ubb 6 = easy to hack? Brad.loo 08/12/2001 11:46 PM
Re: ubb 6 = easy to hack? qasic 08/13/2001 12:30 AM
Re: ubb 6 = easy to hack? AllenAyres 08/13/2001 12:55 AM
Re: ubb 6 = easy to hack? Soul 08/13/2001 1:51 AM
Re: ubb 6 = easy to hack? Greg Hard 08/13/2001 2:06 AM
Re: ubb 6 = easy to hack? Burak 08/13/2001 4:40 AM
Re: ubb 6 = easy to hack? jordo 08/13/2001 4:54 AM
Re: ubb 6 = easy to hack? qasic 08/13/2001 5:27 AM
Re: ubb 6 = easy to hack? jordo 08/13/2001 6:16 AM
Re: ubb 6 = easy to hack? Lord Dexter 08/13/2001 9:49 AM
Re: ubb 6 = easy to hack? cal 08/13/2001 12:29 PM
Re: ubb 6 = easy to hack? Ell 08/13/2001 2:01 PM
Re: ubb 6 = easy to hack? cal 08/13/2001 3:02 PM
Re: ubb 6 = easy to hack? Greg Hard 08/13/2001 3:49 PM
Re: ubb 6 = easy to hack? Ell 08/13/2001 4:00 PM
Re: ubb 6 = easy to hack? AllenAyres 08/13/2001 5:45 PM
Re: ubb 6 = easy to hack? Ell 08/13/2001 6:34 PM
Re: ubb 6 = easy to hack? AllenAyres 08/13/2001 6:43 PM
Re: ubb 6 = easy to hack? Ell 08/13/2001 6:48 PM
Re: ubb 6 = easy to hack? Lord Dexter 08/14/2001 10:24 AM
Re: ubb 6 = easy to hack? Brad.loo 08/15/2001 1:08 AM
Re: ubb 6 = easy to hack? qasic 08/15/2001 1:29 AM
Re: ubb 6 = easy to hack? Brad.loo 08/15/2001 5:21 AM
Re: ubb 6 = easy to hack? Lord Dexter 08/15/2001 9:59 AM
Re: ubb 6 = easy to hack? Askushi 08/16/2001 9:26 AM
Re: ubb 6 = easy to hack? qasic 08/16/2001 8:17 PM
Re: ubb 6 = easy to hack? Lord Dexter 08/17/2001 10:17 AM
Re: ubb 6 = easy to hack? Askushi 08/18/2001 11:01 AM
Re: ubb 6 = easy to hack? cal 08/20/2001 9:59 AM

Link Copied to Clipboard
Donate Today!
Donate via PayPal

Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.

Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.
Recommended Hosts
We have personally worked with and recommend the following Web Hosts:
Stable Host
bluehost
InterServer
Visit us on Facebook
Member Spotlight
Bill B
Bill B
Issaquah, WA
Posts: 87
Joined: December 2001
Forum Statistics
Forums63
Topics37,575
Posts293,932
Members13,824
Most Online6,139
Sep 21st, 2024
Today's Statistics
Currently Online
Topics Created
Posts Made
Users Online
Birthdays
Top Posters
AllenAyres 21,079
JoshPet 10,369
LK 7,394
Lord Dexter 6,708
Gizmo 5,835
Greg Hard 4,625
Top Posters(30 Days)
Gizmo 1
Top Likes Received
isaac 82
Gizmo 20
Brett 7
Morgan 2
Top Likes Received (30 Days)
None yet
The UBB.Developers Network (UBB.Dev/Threads.Dev) is ©2000-2025 VNC Web Services

 
Powered by UBB.threads™ PHP Forum Software 8.0.1
(Snapshot build 20240918)