The reason behind why your Elite mail is still safe

Re: Re: The reason behind why your Elite mail is still safe

BiggieSwolls said:
Owners/Admins cannot see a members password on vbulletin operated sites like Steroidology, Elite, etc...

If I was to go to my Admin section here and look at your profile, for the "Password" field it would just be blank.

This is true and not true. You are absolutely right about the password being blank, obviously, but let me clear up some other things.

Passwords are stored in the database. If you look for the "duplicate ip/password list" hack on vb.org you will find that it is very easy to pull up a list and compare passwords from the database. However for the record this was for version 2.2.3 and newer (exception is vb3). And the passwords were encrypted when that came out. It all depends on which version of Vbulletin Elite is using. Passwords at one time were not encrypted. I think that when version 2.2.0 came out they finally encrypted the passwords.

Any current version of vbulletin, the passwords are encrypted. And when you request that a password be mailed to you, it automatically resets the password. However older versions of vbulletin would e-mail you the actual password. So you could change the password in the admin panel, e-mail it to yourself and then change the password back and have their real password without them knowing. Again, this changed with version 2.2 I believe. I also know that Chen, you know him if you visit vb.org or vb.com, even after vb 2.3 and beyond came out he made a post saying that he would login as someone to check on a problem. The password was not given to him, so it is still technically possible even with the encrypted password. Encryption on vb can be broken pretty easily from what I understand if you know what you are doing.

I do not know much about the situation at Elite, and I don't know what they have built into the message board. I am basically just explaining some of the inner workings of vbulletin. Anything is possible with vbulletin, it's just finding someone that knows how.

*Edit to add this.
I know I only have one post now :) , but I admin Anabolic Review and the Message Board. I've been working with vbulletin for years. I don't want you to think I am just making this stuff up.
 
Last edited:
mvmaxx said:
That's an excellent way to tell. I can't say I ever sent an e-mail to EF Sam or George so I couldn't say one way or another. But if you sent an e-mail and it wouldn't encrypt then you're correct, it's because you didn't have access to the recipients public key to encrypt the message. Therefore it wasn't residing on a hush server.

bingo.gif
 
Re: Re: Re: The reason behind why your Elite mail is still safe

Easto said:
It's the same as at Steroidsupport. I can back Biggie up on that one.


This is good to know. I don't deal with vb at all so I assumed there'd be some sort of hack that would allow this. I can't see how it would be that difficult to do if you wanted to.
 
Re: Re: Re: Re: The reason behind why your Elite mail is still safe

mvmaxx said:
This is good to know. I don't deal with vb at all so I assumed there'd be some sort of hack that would allow this. I can't see how it would be that difficult to do if you wanted to.

I don't think there is one good reason why an admin would need to know your password. I'm glad we can't see it! The last thing we need is to be getting acused of.
 
XBiker said:
Mention e-mail and all the NERDS come running!

(Especially PTBYJAS!!)

:D

LMAO, you suck! Hey, I was just happy that I finally found a question that I could answer. :p
 
Last edited:
Back
Top