php forum
php mysql forum
php mysql smarty
 
Topic Options
#57173 - 01/30/04 05:47 AM Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
Hi,
when a user login, the input type="text" get the password and send it thru POST, so the password is not viewable in the URl, but if a person use a sniffer can grab the password...what about using a MD5 client side javascript (like vbulletin does http://www.vbulletin.com/forum/clientscript/vbulletin_md5.js )?

Top
#57174 - 01/30/04 12:56 PM Re: Login and MD5
Charles Capps Offline
Admin Emeritus
Resident Code Hacker

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
If you're parinoid enough to worry about sniffing, then you should be using SSL to protect your entire site.
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57175 - 01/30/04 05:43 PM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5131
Loc: Portland, OR, USA
Haha agreed; anyone can sniff messages; heck till recently AIM could be sniffed, it still can for those users don't want to spend $15 a year for an SSL cert for AIM :x...
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top
#57176 - 02/02/04 07:00 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
when a user come back to the forum, the md5 hash is taken from the cookie, right? and then the ubb script have to hash the plain text password contained in the user file and compare, right? or the md5 hash is already written in the user file too?

Top
#57177 - 02/02/04 09:57 AM Re: Login and MD5
Ron M Offline
Admin Emeritus
Developer

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
Right now, the plain text password is hashed and compared to the cookie. I would wager that eventually, there will be md5 server side also ( mentioned here ).
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57178 - 02/03/04 03:15 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
CC wrote:
Sure, why not?

cp2_editprofile.pl... find the line reading:

# Password viewing removed entirely per 6/13 meeting

Uncomment the next 7 lines or so. There's your viewable password.

Unfortunately, that will break entirely when we switch to encrypted passwords in the future.... you'll see something akin to "__MD5:abcdef1234567890abcdef1234567890" instead of the password you were expecting.


so in the future all the password will be in md5?

I think this is a good idea..every time ubb request a cookie has to calculate an md5 hash...

comparing the md5 hash (created with a javascript by the client) and the md5 hash stored in the user profile should be better for ubb performance...

Top
#57179 - 02/03/04 03:25 AM Re: Login and MD5
Charles Capps Offline
Admin Emeritus
Resident Code Hacker

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
Actually, when the switch occurs, the method of storing the authentication token will also change, which will still require some MD5 calculations. Sorry to disappoint. smile
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57180 - 02/03/04 04:19 AM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5131
Loc: Portland, OR, USA
Well, when can we expect this? UBB 6.9? I say that since, from what I hear, 6.8 will be mainly coding fixes and rewrites.
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top
#57181 - 02/03/04 09:26 AM Re: Login and MD5
*Cartman* Offline
Member

Registered: 03/20/02
Posts: 65
Quote:
Originally posted by Gizzy:

6.8 will be mainly coding fixes and rewrites.


I hope not...

Top
#57182 - 02/03/04 09:29 AM Re: Login and MD5
Ian Spence Offline
Master Hacker

Registered: 01/25/03
Posts: 3765
Loc: Saint Johns, PA
Gizzy, where did you hear this? The only thing I've heard from CC is that he can't tell us anything
_________________________
Code monkey like Fritos

Top
#57183 - 02/03/04 09:40 AM Re: Login and MD5
Ron M Offline
Admin Emeritus
Developer

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
I don't recall hearing any announcements about what 6.8 will entail yet
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57184 - 02/03/04 10:22 AM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5131
Loc: Portland, OR, USA
/me whistles and walks away innocently
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top
#57185 - 02/03/04 01:10 PM Re: Login and MD5
Charles Offline
Veteran

Registered: 10/22/00
Posts: 2637
Loc: London, UK
Quote:
Originally posted by Gizzy:

/me whistles and walks away innocently

you better run fast before cc catches you tipsy or he will lock you down in PHP hell tipsy
_________________________
Do you believe in love at first sight,
or should I walk by again?

Top
#57186 - 02/03/04 01:24 PM Re: Login and MD5
Charles Capps Offline
Admin Emeritus
Resident Code Hacker

Registered: 01/09/00
Posts: 5438
Loc: Lynnwood, WA
*rains down 40-character-long PHP functions upon Gizzy*
_________________________
UBB.classic: Love it or hate it, it was mine.

Top
#57187 - 02/03/04 02:40 PM Re: Login and MD5
Ron M Offline
Admin Emeritus
Developer

Registered: 11/29/01
Posts: 789
Loc: Des Moines, IA
There's nothing wrong with PHP. You just have to have the proper level of insanity to use it tipsy
_________________________
http://thegeeksinc.com
[img]http://www.ubbdev.com/ud/?u=Sub_Zero&s=1[/img] points generated

Top
#57188 - 02/03/04 07:23 PM Re: Login and MD5
Gizmo Administrator Offline
Wizard

Registered: 01/10/00
Posts: 5131
Loc: Portland, OR, USA
/me is in PHP hell; send help...

I use PHP, should show you that I'm indeed insane smirk...
_________________________
UBB.Dev - Where you too can render your UBB install completely useless...
UGN Security, Elite Web Gamers & VNC Web Design Owner

Top


Moderator:  Gizmo 
Who's Online
0 registered (), 31 Guests and 16 Spiders online.
Key: Admin, Global Mod, Mod
Shout Box

Latest Posts
Forum 'Trader Ratings'.
by blaaskaak
11/20/08 08:27 AM
Problems reading a lot of old posts here
by Ruben Rocha
11/18/08 04:33 PM
PhotoPost BB Code Popup
by Iann128
11/15/08 01:24 PM
Customization needed
by Gizmo
11/12/08 12:28 PM
Team UBBDev Rides Again!
by AllenAyres
11/11/08 02:16 PM
Active Topics.
by AllenAyres
11/11/08 02:13 PM
Looking for a simple upload script
by AllenAyres
11/11/08 02:12 PM
New Mods
Forum 'Trader Ratings'.
by McLemore
11/19/08 02:14 PM
[7.4] Keep log of custom title changes
by blaaskaak
10/27/08 07:51 AM
User Authentication Class
by
01/19/07 02:59 PM
Multiple Identity Detector
by
12/30/06 06:39 PM
PhotoPost BB Code Popup
by
11/06/06 05:43 PM
Newest Members
Begbie, cenk, MATTO, DougMMcts, tim Anderson
13361 Registered Users
Top Posters
AllenAyres 25448
JoshPet 11330
Rick 8372
LK 7396
Lord Dexter 6503
Greg Hard 5533
Charles Capps 5438

 

 

 
fusionbb message board php hacks