Using bcrypt on your MyBB forum. 08-06-2015, 10:47 AM
#1
Figured I would create a multi to post one of the tutorials I had written to post as part of Dysfunctional
before @Oni decided to ban me "for the fuck of it" (to quote what he admitted to Yagmi).
I was going to wait until activity had picked up around here, but I guess I'll just post this one now.
You can ban this account and lie about me breaking more non-existant rules if you like Oni; I'm not entirely sure I'd like to return after the shit you've done for no reason.
You can lie to your community, I don't care anymore - posting this is my way of saying goodbye - at least until you change your ways and stop being so corrupt.
I highly recommend doing this on a local development copy of your forum.
First up, we're gonna test your server to see how many rounds would be suitable for your server.
Download this file and place it into your root directory. Now navigate to yourforum.tld/rbieyj.php and record the result. It should look something like this:
Create a directory inside /inc/datahandlers named bcrypt
Download this zip file and extract the contents into your freshly made bcrypt folder.
Edit the bcrypt.php file to appropriately reflect the cost you found earlier in the tutorial (the rounds variable).
Now for the fun parts c:
In inc/datahandlers/login.php replace:
with:
in inc/datahandlers/user.php
replace:
with:
in inc/functions_user.php
replace:
with:
replace:
with:
in member.php
replace:
with
And that's it. To test, logout of your forum account, login again, logout again and login again.
Also, test resetting you password via the "i forgot my password" form and test changing your password via the usercp.
If anything is broken, let me know and I will assist you (assuming I'm not banned).
before @Oni decided to ban me "for the fuck of it" (to quote what he admitted to Yagmi).
I was going to wait until activity had picked up around here, but I guess I'll just post this one now.
You can ban this account and lie about me breaking more non-existant rules if you like Oni; I'm not entirely sure I'd like to return after the shit you've done for no reason.
You can lie to your community, I don't care anymore - posting this is my way of saying goodbye - at least until you change your ways and stop being so corrupt.
I highly recommend doing this on a local development copy of your forum.
First up, we're gonna test your server to see how many rounds would be suitable for your server.
Download this file and place it into your root directory. Now navigate to yourforum.tld/rbieyj.php and record the result. It should look something like this:
Code:
Appropriate Cost Found: (number)Create a directory inside /inc/datahandlers named bcrypt
Download this zip file and extract the contents into your freshly made bcrypt folder.
Edit the bcrypt.php file to appropriately reflect the cost you found earlier in the tutorial (the rounds variable).
Now for the fun parts c:
In inc/datahandlers/login.php replace:
PHP Code:
if($salted_password !== $this->login_data['password'])
{
$this->invalid_combination(true);
return false;
PHP Code:
if(strlen($this->login_data['password']) == 32) {
//if the password is still using md5
if($salted_password != $this->login_data['password'])
{
$this->invalid_combination(true);
return false;
} else {
//update the password to bcrypt
include_once(dirname(__FILE__)."/bcrypt/bcrypt.php");
$hasher = new BcryptHasher;
$sql_array = array(
"password" => $hasher->make($user['password'])
);
$db->update_query("users", $sql_array, "uid = '{$this->login_data['uid']}'");
}
} else {
include_once(dirname(__FILE__)."/bcrypt/bcrypt.php");
$hasher = new BcryptHasher;
if(!$hasher->check($user['password'], $this->login_data['password'])) {
$this->invalid_combination(true);
return false;
}
in inc/datahandlers/user.php
replace:
PHP Code:
// MD5 the password
$user['md5password'] = md5($user['password']);
// Generate our salt
$user['salt'] = generate_salt();
// Combine the password and salt
$user['saltedpw'] = salt_password($user['md5password'], $user['salt']);
with:
PHP Code:
$user['salt'] = "dong"; // hacky fix that works
//return a bcrypt hash
include_once(dirname(__FILE__)."/bcrypt/bcrypt.php");
$hasher = new BcryptHasher;
$user['saltedpw'] = $hasher->make($user['password']);
in inc/functions_user.php
replace:
PHP Code:
if(salt_password(md5($password), $user['salt']) === $user['password'])
{
return $user;
}
else
{
return false;
with:
PHP Code:
if(strlen($user['password']) == 32) {
if(salt_password(md5($password), $user['salt']) == $user['password'])
{
include_once(dirname(__FILE__)."/datahandlers/bcrypt/bcrypt.php");
$hasher = new BcryptHasher;
$user['password'] = $hasher->make($password);
$sql_array = array(
"password" => $user['password']
);
$db->update_query("users", $sql_array, "uid = '{$user['uid']}'");
return $user;
}
else
{
return false;
}
} else {
include_once(dirname(__FILE__)."/datahandlers/bcrypt/bcrypt.php");
$hasher = new BcryptHasher;
if(!$hasher->check($password, $user['password'])) {
$this->invalid_combination(true);
return false;
} else {
return $user;
}
replace:
PHP Code:
$saltedpw = salt_password($password, $salt);
with:
PHP Code:
// replace salted password with bcrypt
include_once(dirname(__FILE__)."/datahandlers/bcrypt/bcrypt.php");
$hasher = new BcryptHasher;
$saltedpw = $hasher->make($password);
in member.php
replace:
PHP Code:
$logindetails = update_password($user['uid'], md5($password), $user['salt']);
with
PHP Code:
$logindetails = update_password($user['uid'], $password, $user['salt']);
And that's it. To test, logout of your forum account, login again, logout again and login again.
Also, test resetting you password via the "i forgot my password" form and test changing your password via the usercp.
If anything is broken, let me know and I will assist you (assuming I'm not banned).


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)












