Sinisterly
Tutorial [MyBB] Improved password encryption. - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Coding (https://sinister.li/Forum-Coding)
+--- Forum: PHP (https://sinister.li/Forum-PHP)
+--- Thread: Tutorial [MyBB] Improved password encryption. (/Thread-Tutorial-MyBB-Improved-password-encryption)

Pages: 1 2 3 4 5 6 7


[MyBB] Improved password encryption. - Lain - 10-28-2013

This makes it exceedingly difficult for an attacker to decrypt the password hashes on your forum. I recommend doing this while you have a small amount of members on your forum.

First up, open inc/functions_user.php in your favourite text editor, search for the following function.
PHP Code:
function salt_password($password, $salt) { return md5(md5($salt).$password); }

Come up with a random 5 character long combination of letters and numbers, I'm going to use 3g45h in the example.

Modify the above function so that it looks like this:
PHP Code:
function salt_password($password, $salt) { return md5(md5(md5($salt).$password)."3g45h"); }

It may seem a little overboard, but the security of your members passwords is the most important thing.

Open PHPMyAdmin and navigate to your mybb_users table, manually update each users password, by following the next step.
Open http://www.adamek.biz/md5-generator.php then enter the users current password hash, with your 5 random characters at the end.

For example.
Code:
1a79a4d60de6718e8e5b326e338ae533

Becomes

Code:
1a79a4d60de6718e8e5b326e338ae5333g45h

Click "Calculate MD5".

Copy the new hash and replace the users old password.

Upload your modified functions_user.php to your server.

Now if an attacker attempts to crack the hashes, it's useless unless they know your 5 random characters.


RE: [MyBB] Advanced password encryption. - lux - 10-28-2013

This is a good idea until they compare the hashes together and notice these additional parts. Otherwise, great thread.


RE: [MyBB] Improved password encryption. - Lain - 10-28-2013

(10-28-2013, 04:41 AM)xLinear Wrote: This is a good idea until they compare the hashes together and notice these additional parts. Otherwise, great thread.

The final hash appears the same as a normal hash. Read the full guide Smile


RE: [MyBB] Improved password encryption. - lux - 10-28-2013

(10-28-2013, 04:42 AM)Poochyena Wrote: The final hash appears the same as a normal hash. Read the full guide Smile

Oh so you encrypt it with the extra characters. Sorry, 4AM brain doesn't work too well. Yawn


RE: [MyBB] Improved password encryption. - w00t - 10-28-2013

Or use a better hashing algorithm.


RE: [MyBB] Improved password encryption. - Lain - 10-28-2013

(10-28-2013, 06:21 AM)w00t Wrote: Or use a better hashing algorithm.

This is a way where you don't have to know the members passwords.


RE: [MyBB] Improved password encryption. - Mercenary - 10-28-2013

Can ı crack mybb user passwords ?


RE: [MyBB] Improved password encryption. - Oni - 10-28-2013

(10-28-2013, 11:27 AM)Mercenary Wrote: Can ı crack mybb user passwords ?

Yes, you can. Why would you even ask this?


RE: [MyBB] Improved password encryption. - Flashwave - 10-28-2013

might as well have the random shit at the end within the hashing too


RE: [MyBB] Improved password encryption. - w00t - 10-28-2013

(10-28-2013, 07:10 AM)Poochyena Wrote: This is a way where you don't have to know the members passwords.

bcrypt the existing hash, problem solved.