Hi All,
We're upgrading software, had a bit of a security hole, and may require you to reset your password to log back in. Sorry for the hassle!
Thanks,
Walker





Hi All,
We're upgrading software, had a bit of a security hole, and may require you to reset your password to log back in. Sorry for the hassle!
Thanks,
Walker
Yeah, I had to change the pw, but nbd. Thanks for the heads-up Walker.
No problem, thanks for the update.
cool... kinda wondered what that was...
My new password is much easier to remember:
)nEzQJgMtro0
johnwirtz wrote >>
My new password is much easier to remember:
)nEzQJgMtro0
Ha! You can reset it to whatever you like. Click on your username either next to your avatar or up at the very top of the page and click "edit" to enter a new password.
(I'm hoping you've actually already done this before displaying that generated password.)
;)
This is an outrage! I demand compensation! I demand satisfaction!
There's a story in the IT world, back from when passwords were still novel, that some office dick chose "penis" as a password and it was rejected as "too short" because the password protocol required at least six characters.
Let's all use 'password' and that way we can help remind one another in case we forget.
Mellon
[At this point, gramarye was suddenly attacked by the CU kraken ...]
I'm an admin on a car board and I can search the password field in the member database. It's surprising how many use the name of the manufaturer or a model name as their passwords.
Walker wrote >>
johnwirtz wrote >>
My new password is much easier to remember:
)nEzQJgMtro0Ha! You can reset it to whatever you like. Click on your username either next to your avatar or up at the very top of the page and click "edit" to enter a new password.
(I'm hoping you've actually already done this before displaying that generated password.)
;)
Indeed I had.
done, problem with this sticky is it's not the top of the threads (or even the first page) if you are not logged in.
(it is now.. Bump)
Yeah, it only shows at top of General Discussion only.
Roland wrote >>
alexs wrote >>
I'm an admin on a car board and I can search the password field in the member database. It's surprising how many use the name of the manufaturer or a model name as their passwords.Shouldn't those be stored as salted hash values? shame shame!
Yes, hash is always better when properly salted..
(Yes, yes, I know. And I'm sorry.)
That board is on vBulletin 2.2.8, way out of date.
When I look at individual member profiles, the password field is blank, but in the member search page I can populate the password field and see how many users have that string of characters in their passwords.
In the IT world, I've heard a few stories about "white hat" security experts who raise hell just to demonstrate a system's vulnerabilities. Stuff like touring the control room and while no one is looking, going to the admin console and creating a new admin-level user for later attacks.
I've got to stop this, I'm getting Active Directory flashbacks, someone save me! I'm back in a domain of trees and forests... look at the MOSS...
got it all sorted thx Walker
noticed the login page is a bit askew still :o
You must log in to post.