![]() |
|
Tutorial [MyBB] Improved password encryption. - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: PHP (https://sinister.li/Forum-PHP) +--- Thread: Tutorial [MyBB] Improved password encryption. (/Thread-Tutorial-MyBB-Improved-password-encryption) |
[MyBB] Improved password encryption. - Lain - 10-28-2013 This makes it exceedingly difficult for an attacker to decrypt the password hashes on your forum. I recommend doing this while you have a small amount of members on your forum. First up, open inc/functions_user.php in your favourite text editor, search for the following function. PHP Code: function salt_password($password, $salt)
{
return md5(md5($salt).$password);
}
Come up with a random 5 character long combination of letters and numbers, I'm going to use 3g45h in the example. Modify the above function so that it looks like this: PHP Code: function salt_password($password, $salt)
{
return md5(md5(md5($salt).$password)."3g45h");
}
It may seem a little overboard, but the security of your members passwords is the most important thing. Open PHPMyAdmin and navigate to your mybb_users table, manually update each users password, by following the next step. Open http://www.adamek.biz/md5-generator.php then enter the users current password hash, with your 5 random characters at the end. For example. Code: 1a79a4d60de6718e8e5b326e338ae533Becomes Code: 1a79a4d60de6718e8e5b326e338ae5333g45hClick "Calculate MD5". Copy the new hash and replace the users old password. Upload your modified functions_user.php to your server. Now if an attacker attempts to crack the hashes, it's useless unless they know your 5 random characters. RE: [MyBB] Advanced password encryption. - lux - 10-28-2013 This is a good idea until they compare the hashes together and notice these additional parts. Otherwise, great thread. RE: [MyBB] Improved password encryption. - Lain - 10-28-2013 (10-28-2013, 04:41 AM)xLinear Wrote: This is a good idea until they compare the hashes together and notice these additional parts. Otherwise, great thread. The final hash appears the same as a normal hash. Read the full guide
RE: [MyBB] Improved password encryption. - lux - 10-28-2013 (10-28-2013, 04:42 AM)Poochyena Wrote: The final hash appears the same as a normal hash. Read the full guide Oh so you encrypt it with the extra characters. Sorry, 4AM brain doesn't work too well.
RE: [MyBB] Improved password encryption. - w00t - 10-28-2013 Or use a better hashing algorithm. RE: [MyBB] Improved password encryption. - Lain - 10-28-2013 (10-28-2013, 06:21 AM)w00t Wrote: Or use a better hashing algorithm. This is a way where you don't have to know the members passwords. RE: [MyBB] Improved password encryption. - Mercenary - 10-28-2013 Can ı crack mybb user passwords ? RE: [MyBB] Improved password encryption. - Oni - 10-28-2013 (10-28-2013, 11:27 AM)Mercenary Wrote: Can ı crack mybb user passwords ? Yes, you can. Why would you even ask this? RE: [MyBB] Improved password encryption. - Flashwave - 10-28-2013 might as well have the random shit at the end within the hashing too RE: [MyBB] Improved password encryption. - w00t - 10-28-2013 (10-28-2013, 07:10 AM)Poochyena Wrote: This is a way where you don't have to know the members passwords. bcrypt the existing hash, problem solved. |