php forum
php mysql forum
php mysql smarty
 
Topic Options
#57173 - 01/30/04 05:47 AM Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
Hi,
when a user login, the input type="text" get the password and send it thru POST, so the password is not viewable in the URl, but if a person use a sniffer can grab the password...what about using a MD5 client side javascript (like vbulletin does http://www.vbulletin.com/forum/clientscript/vbulletin_md5.js )?

Top
#57174 - 01/30/04 12:56 PM Re: Login and MD5
Charles Capps Offline
Admin Emeritus

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
If you're parinoid enough to worry about sniffing, then you should be using SSL to protect your entire site.
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57175 - 01/30/04 05:43 PM Re: Login and MD5
Gizmo Offline

Wizard

Registered: 01/10/00
Posts: 5354
Loc: Portland, OR, USA
Haha agreed; anyone can sniff messages; heck till recently AIM could be sniffed, it still can for those users don't want to spend $15 a year for an SSL cert for AIM :x...
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design & Development President
UBB.Threads: My UBBSkins, UBB.Sitemaps

Top
#57176 - 02/02/04 07:00 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
when a user come back to the forum, the md5 hash is taken from the cookie, right? and then the ubb script have to hash the plain text password contained in the user file and compare, right? or the md5 hash is already written in the user file too?

Top
#57177 - 02/02/04 09:57 AM Re: Login and MD5
Ron M Offline
Admin Emeritus

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
Right now, the plain text password is hashed and compared to the cookie. I would wager that eventually, there will be md5 server side also ( mentioned here ).
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57178 - 02/03/04 03:15 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
CC wrote:
Sure, why not?

cp2_editprofile.pl... find the line reading:

# Password viewing removed entirely per 6/13 meeting

Uncomment the next 7 lines or so. There's your viewable password.

Unfortunately, that will break entirely when we switch to encrypted passwords in the future.... you'll see something akin to "__MD5:abcdef1234567890abcdef1234567890" instead of the password you were expecting.


so in the future all the password will be in md5?

I think this is a good idea..every time ubb request a cookie has to calculate an md5 hash...

comparing the md5 hash (created with a javascript by the client) and the md5 hash stored in the user profile should be better for ubb performance...

Top
#57179 - 02/03/04 03:25 AM Re: Login and MD5
Charles Capps Offline
Admin Emeritus

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
Actually, when the switch occurs, the method of storing the authentication token will also change, which will still require some MD5 calculations. Sorry to disappoint. smile
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57180 - 02/03/04 04:19 AM Re: Login and MD5
Gizmo Offline

Wizard

Registered: 01/10/00
Posts: 5354
Loc: Portland, OR, USA
Well, when can we expect this? UBB 6.9? I say that since, from what I hear, 6.8 will be mainly coding fixes and rewrites.
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design & Development President
UBB.Threads: My UBBSkins, UBB.Sitemaps

Top
#57181 - 02/03/04 09:26 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
Quote:
Originally posted by Gizzy:

6.8 will be mainly coding fixes and rewrites.


I hope not...

Top
#57182 - 02/03/04 09:29 AM Re: Login and MD5
Ian Spence Offline
Master Hacker

Registered: 01/25/03
Posts: 3765
Loc: Saint Johns, PA
Gizzy, where did you hear this? The only thing I've heard from CC is that he can't tell us anything

Top
#57183 - 02/03/04 09:40 AM Re: Login and MD5
Ron M Offline
Admin Emeritus

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
I don't recall hearing any announcements about what 6.8 will entail yet
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57184 - 02/03/04 10:22 AM Re: Login and MD5
Gizmo Offline

Wizard

Registered: 01/10/00
Posts: 5354
Loc: Portland, OR, USA
/me whistles and walks away innocently
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design & Development President
UBB.Threads: My UBBSkins, UBB.Sitemaps

Top
#57185 - 02/03/04 01:10 PM Re: Login and MD5
Charles Offline
Veteran

Registered: 10/22/00
Posts: 2637
Loc: London, UK
Quote:
Originally posted by Gizzy:

/me whistles and walks away innocently

you better run fast before cc catches you tipsy or he will lock you down in PHP hell tipsy
_________________________
Do you believe in love at first sight,
or should I walk by again?

Top
#57186 - 02/03/04 01:24 PM Re: Login and MD5
Charles Capps Offline
Admin Emeritus

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
*rains down 40-character-long PHP functions upon Gizzy*
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57187 - 02/03/04 02:40 PM Re: Login and MD5
Ron M Offline
Admin Emeritus

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
There's nothing wrong with PHP. You just have to have the proper level of insanity to use it tipsy
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57188 - 02/03/04 07:23 PM Re: Login and MD5
Gizmo Offline

Wizard

Registered: 01/10/00
Posts: 5354
Loc: Portland, OR, USA
/me is in PHP hell; send help...

I use PHP, should show you that I'm indeed insane smirk...
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design & Development President
UBB.Threads: My UBBSkins, UBB.Sitemaps

Top



Moderator:  Gizmo 
Latest Posts
[7.2.1] - Naked shoutbox
by bellaonline
05/05/12 05:00 PM
[7.x] Stop Forum Spam Integration v0.4
by bellaonline
05/05/12 03:53 PM
Shout Box

(Views)Popular Topics
Known public proxy servers 1689885
Integrated Index Page (IIP) 5.3.1 555705
Finished-[6.5.2] Games Arcade Deluxe v1.9 501236
Integrated Index Page (IIP) 5.1.1 415112
TLD Bv2.1 Released - Threads Links Directory 396822
[6.0x] Who's Online 4.0.0 [Finished] 389412
Finished-[6.5.1] Integrated Index Page (IIP) 6.5 330423
Q & A 298663
Slash UBB 266936
[6.3.x] [beta] Hit Hack 2.0 227970
Forum Stats
13621 Members
59 Forums
37191 Topics
295716 Posts

Max Online: 686 @ 06/28/07 07:04 AM

 

 

 
fusionbb message board php hacks