![]() |
|
Tutorial [MyBB] Improved password encryption. - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: PHP (https://sinister.li/Forum-PHP) +--- Thread: Tutorial [MyBB] Improved password encryption. (/Thread-Tutorial-MyBB-Improved-password-encryption) |
RE: [MyBB] Improved password encryption. - Lain - 01-05-2015 (01-05-2015, 12:49 AM)Oni Wrote: I'd love to do something like this for SL... Although there's no way I'm doing this manually 8,000 times. You could make the users do it themselves. By leaving the existing hashes there, their passwords won't work until they do a password reset. RE: [MyBB] Improved password encryption. - phyrrus9 - 01-05-2015 Or send a mass password reset and update the code. They won't even be able to log in until they use the password sent via email, then they have to update it. I wouldn't encrypt posts though, seems rather pointless. Lets do it RE: [MyBB] Improved password encryption. - Oni - 01-07-2015 (01-05-2015, 06:59 AM)phyrrus9 Wrote: Or send a mass password reset and update the code. They won't even be able to log in until they use the password sent via email, then they have to update it. I wouldn't encrypt posts though, seems rather pointless. Lets do it As if we need more people that can't login...
RE: [MyBB] Improved password encryption. - Lain - 01-07-2015 (01-07-2015, 12:59 AM)Oni Wrote: As if we need more people that can't login... It'd be worth it. Alternatively you could store the old hash and the new encrypted password in the database; then run a check for logged in users to see if there's any content in the deprecated hash column and force the user to change their password if there is. Then once it has been changed, you can NULL that column for that user. That way, they can still login; and once their password is changed, the old (unsecure) hash is removed. RE: [MyBB] Improved password encryption. - phyrrus9 - 01-07-2015 (01-07-2015, 12:59 AM)Oni Wrote: As if we need more people that can't login... Well, it would be a neat little thing to play with and implement at a later time. If you gave me a little sandbox to play with I could write one up. Like maybe a default mybb install with fs access to only that directory (I hate using webhosting, and I do not want to set up apache+php5 on a chromebook) RE: [MyBB] Improved password encryption. - Yani - 01-27-2015 Regarding this discussion on changing the passwords of the current users, MySQL has an md5() function, so a query like this would be 100 times easier: Code: UPDATE `users` SET `password` = md5(`password` + 'salt')RE: [MyBB] Improved password encryption. - Eclipse - 01-27-2015 (01-27-2015, 07:48 AM)Yani Wrote: Regarding this discussion on changing the passwords of the current users, MySQL has an md5() function, so a query like this would be 100 times easier: You're retarded. Did you even read anything but the title? RE: [MyBB] Improved password encryption. - Yani - 01-27-2015 (01-27-2015, 07:55 AM)Eclipse Wrote: You're retarded. Did you even read anything but the title? Yeah, and I saw a discussion about changing all the passwords to the updated one, while you can use the md5() function from MySQL to update the whole column. I was only giving an example with the code I posted. No need to be harsh against a new member. RE: [MyBB] Improved password encryption. - Lain - 01-28-2015 (01-27-2015, 07:55 AM)Eclipse Wrote: You're retarded. Did you even read anything but the title? No, you're retarded; What Yani said is correct, you can use a query similar to the one he posted, to update the passwords. RE: [MyBB] Improved password encryption. - Oni - 01-28-2015 (01-27-2015, 07:55 AM)Eclipse Wrote: You're retarded. Did you even read anything but the title? No, he is helpful, actually. I forgot MySQL had md5(). |