Register Chat Members List Search Today's Posts Mark Forums Read

Reply
 
Mod Options
Password Security Tools Details »»
Password Security Tools
Mod Version: 1.3.2PL1, by John (Coder) John is offline
Developer Last Online: Feb 2010 Show Printable Version Email this Page

vB Version: 3.7.2 Rating: (10 votes - 4.60 average) Installs: 67
Released: 13 Aug 2008 Last Update: 15 Aug 2008 Downloads: 279
Supported DB Changes Uses Plugins Additional Files Re-usable Code Translations Is in Beta Stage  

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Password Security Tools
For vBulletin 3.7.0 and above
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Description
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
A product designed to combat the recent increase in weak password attacks by spammers.

For background information, read the following threads:
http://www.vbulletin.com/forum/showthread.php?t=278975
http://www.vbulletin.com/forum/showthread.php?t=281371

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
The Problem
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
The problem stems from the fact that vBulletin doesn't check the quality of a user's password when registering or changing the password in the User CP. As a result, users are able to choose easily guessable passwords to protect their account. The most common passwords are things like "password", "12345", "qwerty", "letmein", as well as the user's own username. On a large forum, these poorly protected accounts can number hundreds or even thousands, and this has shown itself to be a prime opportunity for spammers to exploit. With a relatively simple script, spammers are able to scrape the member list from your forum and automatically validate which of the accounts have such passwords. A spammer with access to tens, hundreds or thousands of legitimate user accounts is a situation you don't want to be in.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
What This Does
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
This product has two main functions.
1. It prevents users from using their own username as a password, or any other commonly used word. (An editable list of banned passwords is available in the Admin CP.) The same rules apply if a user tries to change their password after registration.
2. It provides you with a tool to identify existing user accounts that have bad passwords, and lets you reset those passwords. Emails will be automatically dispatched to affected users notifying them of the change, and providing instructions on how to gain access to their account.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Installation
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
To install:
1. Upload cpnav_passrepair.xml to includes/xml/
2. Upload passsec.php to admincp/
3. Upload product-passrepair.xml to your Admin CP as a product
4. Enable the product in vBulletin Options

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Password Scanner - Usage Notes
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
The password scanning portion of this product is a utility designed for use by administrators. There are a few things to be aware of.
1. BACK UP YOUR DATA BEFORE USING THIS SCRIPT.
2. It's not a tool designed for frequent usage, it's a quick and dirty way of getting the job done. If Jelsoft don't address this issue, I might return to it and optimize the password scanner to make it a little less server intensive. Use it sparingly, and close your forums before commencing a scan.
3. The password scanner has the potential to send out a lot of email. Use the "Users Per Page" setting to process accounts at whatever rate you deem your server capable of handling.
4. After you've installed this product it'll be impossible for users to register using a blacklisted or invalid password (or to change it to one afterwards). As a result, you should only need to use the password scanner once. Feel free to remove the passsec.php and cpnav_passrepair.xml files from your server once you're done with the scanner, the rest of the product will still function.
5. For unattended bulk processing of accounts, there's some javascript in passsec.php that's currently commented out. Use it at your own risk.

Download Now

Only licensed members can download files, Click Here for more information.

Show Your Support

  • To receive notifications regarding updates -> Click to Mark as Installed.
  • This modification may not be copied, reproduced or published elsewhere without author's permission.
Similar Mod
Mod Developer Type Replies Last Post
Password Security Andreas vBulletin 3.5 Add-ons 41 31 Dec 2009 15:37
Security Password for Admincp Hacks AnhTuanCool vBulletin 3.0 Beta Releases 47 14 May 2007 06:55

Comments
  #2  
Old 13 Aug 2008, 05:06
glorify's Avatar
glorify glorify is offline
 
Join Date: Aug 2004
Weeeeee. Installing now John
Reply With Quote
  #3  
Old 13 Aug 2008, 05:24
GaiLoan's Avatar
GaiLoan GaiLoan is offline
 
Join Date: Dec 2007
Real name: Lee Sung Ho
wow sound kool, thanks let me try
Reply With Quote
  #4  
Old 13 Aug 2008, 06:18
sinucello sinucello is offline
 
Join Date: Apr 2006
Location: dutch-german border
Hi,

thanks a lot for sharing this. Should have already been released by Jelsoft IMHO, but this has been discussed in the threads you mentioned. Great job anyway.

all the best,
Sacha
Reply With Quote
  #5  
Old 13 Aug 2008, 08:25
RedTrinity's Avatar
RedTrinity RedTrinity is offline
 
Join Date: Mar 2008
I just got the following error after running the script to update bad passwords, it happened as soon as it tried to attend to the first member in the list:

Database error in vBulletin 3.7.2:

Invalid SQL:
UPDATE user SET password='19c024c9537eca5a91fca3606caa7796' WHERE userid=81;

MySQL Error : Table 'xxxx_forums.user' doesn't exist
Error Number : 1146
Request Date : Wednesday, August 13th 2008 @ 05:21:56 PM
Error Date : Wednesday, August 13th 2008 @ 05:21:56 PM
Script : http://www.theparentingsanctuary.com...?do=dopassscan
Referrer : http://www.theparentingsanctuary.com...reparepassscan
IP Address : xxxx
Username : xxxx
Classname : vB_Database
MySQL Version : 5.0.48
__________________
http://www.theparentingsanctuary.com.au - Connecting Australian Parents
Reply With Quote
  #6  
Old 13 Aug 2008, 08:56
digicom's Avatar
digicom digicom is offline
 
Join Date: Apr 2006
Installed Thankyou
__________________
underground-modems.com
Reply With Quote
  #7  
Old 13 Aug 2008, 12:26
wacnstac wacnstac is offline
 
Join Date: Nov 2001
Thank you, thank you, thank you! Too bad you had to do Jelsoft's job for them. They'll probably be using this hack too, or they should be.
Reply With Quote
  #8  
Old 13 Aug 2008, 14:02
John's Avatar
John John is offline
 
Join Date: Mar 2002
Real name: John Warwick
Originally Posted by GamerGirl27 View Post
I just got the following error after running the script to update bad passwords, it happened as soon as it tried to attend to the first member in the list:
Ah, missed a table prefix. Download the zip again, and overwrite passsec.php.
Reply With Quote
  #9  
Old 13 Aug 2008, 15:08
MGSteve MGSteve is offline
 
Join Date: Aug 2002
Is there any reason this won't work on 3.6.0? I haven't upgraded my forum in a while (haven't got the time to redo all the plugins I've done again)!
__________________
Regards

Steve Childs.

mg-rover.org & xpowerforums.com
Yes, I have a bit of an MG & Rover obession.:cross-eyed:
Reply With Quote
  #10  
Old 13 Aug 2008, 15:17
John's Avatar
John John is offline
 
Join Date: Mar 2002
Real name: John Warwick
Originally Posted by MGSteve View Post
Is there any reason this won't work on 3.6.0? I haven't upgraded my forum in a while (haven't got the time to redo all the plugins I've done again)!
Try it on a test installation first. (You might have to edit the product XML file to remove the 3.7.0 vBulletin version dependency.) There's a good chance it'll work, although I haven't tested.
Reply With Quote
  #11  
Old 13 Aug 2008, 15:20
MGSteve MGSteve is offline
 
Join Date: Aug 2002
Thanks for the quick reply, I'll give it a try!

You've got my vote for Mod Of The Month too....
__________________
Regards

Steve Childs.

mg-rover.org & xpowerforums.com
Yes, I have a bit of an MG & Rover obession.:cross-eyed:
Reply With Quote
  #12  
Old 13 Aug 2008, 16:56
John's Avatar
John John is offline
 
Join Date: Mar 2002
Real name: John Warwick
Let me know how it goes, if it doesn't work I'll upload a 3.6.x version for you.
Reply With Quote
  #13  
Old 13 Aug 2008, 17:16
Elenna Elenna is offline
 
Join Date: Jan 2006
Location: St. Charles, MO
Real name: Dana
Thanks very much for this! Thankfully I only had one user with an insecure password, but I'm sure there are more where that came from.
Reply With Quote
  #14  
Old 13 Aug 2008, 17:35
Hostboard Hostboard is online now
 
Join Date: May 2002
Is there anyway this can be integrated with the Ajax registration modification???
http://www.vbulletin.org/forum/showthread.php?t=182005

Would be a great merger of 2 modifications that complement each other
Reply With Quote
  #15  
Old 13 Aug 2008, 18:02
RvG2's Avatar
RvG2 RvG2 is offline
 
Join Date: Jan 2007
Originally Posted by Hostboard View Post
Is there anyway this can be integrated with the Ajax registration modification???
http://www.vbulletin.org/forum/showthread.php?t=182005

Would be a great merger of 2 modifications that complement each other
i agree with you
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
Mod Options

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
Forum Jump


New To Site? Need Help?

All times are GMT. The time now is 17:35.

Layout Options | Width: Wide Color: