View Single Post
Old 01-25-2010, 03:23 PM  
quantum-x
Confirmed User
 
quantum-x's Avatar
 
Join Date: Feb 2002
Location: ICQ: 251425 Fr/Au/Ca
Posts: 6,863
Quote:
Originally Posted by ********** View Post
I don't think this is possible.

GFY uses vbulletin (www.vbulletin.com). The passswords of its users are not visible in the administrator program. Administrators can change the passwords of users, but cannot see the actual passwords. Password attemps are also not stored.

I think you are safe. If VBulletin had this kind of vulnerability they wouldn't be so popular.
I thought you had a bit of coding background Mark?
Seriously, stealing the passwords is a total fucking doddle.

#1 - They're probably not running a copy of VB - simple passing the login / password onto gfy.com - and saving a copy as it goes

#2 - Even if they were - VB is clear source. Nothing stopping you making it save passes in an open format.

#3 - Even if it WASN'T clear source, you could probably acheive the same with db triggers.

'I think you are safe'.. lol
quantum-x is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote