php forum
php mysql forum
php mysql smarty
 
Topic Options
#57173 - 01/30/04 05:47 AM Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65

   Login and MD5 to Del.icio.us Add to del.icio.us
  Digg Login and MD5 Digg it
Hi,
when a user login, the input type="text" get the password and send it thru POST, so the password is not viewable in the URl, but if a person use a sniffer can grab the password...what about using a MD5 client side javascript (like vbulletin does http://www.vbulletin.com/forum/clientscript/vbulletin_md5.js )?

Top
#57174 - 01/30/04 12:56 PM Re: Login and MD5
Charles Capps Offline
Admin Emeritus
Resident Code Hacker

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
If you're parinoid enough to worry about sniffing, then you should be using SSL to protect your entire site.
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57175 - 01/30/04 05:43 PM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5123
Loc: Portland, OR, USA
Haha agreed; anyone can sniff messages; heck till recently AIM could be sniffed, it still can for those users don't want to spend $15 a year for an SSL cert for AIM :x...
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top
#57176 - 02/02/04 07:00 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
when a user come back to the forum, the md5 hash is taken from the cookie, right? and then the ubb script have to hash the plain text password contained in the user file and compare, right? or the md5 hash is already written in the user file too?

Top
#57177 - 02/02/04 09:57 AM Re: Login and MD5
Ron M Offline
Admin Emeritus
Developer

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
Right now, the plain text password is hashed and compared to the cookie. I would wager that eventually, there will be md5 server side also ( mentioned here ).
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57178 - 02/03/04 03:15 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
CC wrote:
Sure, why not?

cp2_editprofile.pl... find the line reading:

# Password viewing removed entirely per 6/13 meeting

Uncomment the next 7 lines or so. There's your viewable password.

Unfortunately, that will break entirely when we switch to encrypted passwords in the future.... you'll see something akin to "__MD5:abcdef1234567890abcdef1234567890" instead of the password you were expecting.


so in the future all the password will be in md5?

I think this is a good idea..every time ubb request a cookie has to calculate an md5 hash...

comparing the md5 hash (created with a javascript by the client) and the md5 hash stored in the user profile should be better for ubb performance...

Top
#57179 - 02/03/04 03:25 AM Re: Login and MD5
Charles Capps Offline
Admin Emeritus
Resident Code Hacker

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
Actually, when the switch occurs, the method of storing the authentication token will also change, which will still require some MD5 calculations. Sorry to disappoint. smile
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57180 - 02/03/04 04:19 AM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5123
Loc: Portland, OR, USA
Well, when can we expect this? UBB 6.9? I say that since, from what I hear, 6.8 will be mainly coding fixes and rewrites.
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top
#57181 - 02/03/04 09:26 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
Quote:
Originally posted by Gizzy:

6.8 will be mainly coding fixes and rewrites.


I hope not...

Top
#57182 - 02/03/04 09:29 AM Re: Login and MD5
Ian Spence Offline
Master Hacker

Registered: 01/25/03
Posts: 3765
Loc: Saint Johns, PA
Gizzy, where did you hear this? The only thing I've heard from CC is that he can't tell us anything
_________________________
Code monkey like Fritos

Top
#57183 - 02/03/04 09:40 AM Re: Login and MD5
Ron M Offline
Admin Emeritus
Developer

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
I don't recall hearing any announcements about what 6.8 will entail yet
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57184 - 02/03/04 10:22 AM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5123
Loc: Portland, OR, USA
/me whistles and walks away innocently
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top
#57185 - 02/03/04 01:10 PM Re: Login and MD5
Charles Offline
Veteran

Registered: 10/22/00
Posts: 2637
Loc: London, UK
Quote:
Originally posted by Gizzy:

/me whistles and walks away innocently

you better run fast before cc catches you tipsy or he will lock you down in PHP hell tipsy
_________________________
Do you believe in love at first sight,
or should I walk by again?

Top
#57186 - 02/03/04 01:24 PM Re: Login and MD5
Charles Capps Offline
Admin Emeritus
Resident Code Hacker

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
*rains down 40-character-long PHP functions upon Gizzy*
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57187 - 02/03/04 02:40 PM Re: Login and MD5
Ron M Offline
Admin Emeritus
Developer

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
There's nothing wrong with PHP. You just have to have the proper level of insanity to use it tipsy
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57188 - 02/03/04 07:23 PM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5123
Loc: Portland, OR, USA
/me is in PHP hell; send help...

I use PHP, should show you that I'm indeed insane smirk...
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top


Moderator:  Gizmo 
Who's Online
0 Registered (), 46 Guests and 7 Spiders online.
Key: Admin, Global Mod, Mod
Shout Box

Latest Posts
Blogs, love em or hate em?
by AllenAyres
10/07/08 02:05 PM
What do you use to edit the files
by Ian_W
10/05/08 03:33 PM
BeyondCompare v3.00
by Ian_W
10/05/08 03:32 PM
Glossy Black Theme with Image Reflection
by Gizmo
10/05/08 02:17 PM
ShareThis
by Gizmo
09/28/08 05:06 AM
[7.3] Viewing MySQL logfiles made easier
by AllenAyres
09/27/08 09:57 PM
Looking for a simple upload script
by Murphdog
09/26/08 08:45 PM
New Mods
[7.3] Viewing MySQL logfiles made easier
by blaaskaak
09/24/08 05:39 PM
[7.3.1] add search to showmembers page
by blaaskaak
09/07/08 04:50 AM
Multiple Identity Detector
by
12/30/06 06:39 PM
Newest Members
pisa666, ghengis317, NitroX, Dogan, EliYah-
13345 Registered Users
Top Posters Last 30 Days
AllenAyres 11
blaaskaak 7
tackaberry 5
FREAK1 5
Chris Bale 4
Ian_W 4
Gizmo 4

 

 

 
fusionbb message board php hacks