![]() |
|
|
Thread Tools |
|
#1
|
||||||||
|
||||||||
|
Attempting to Limit User Password Length Through PHP Plugins
Hey all,
I'm trying to make it so user passwords need to be at least 6 to 20 characters long. PHP Plugins: register_addmember_process
profile_updatepassword_start
Now for some reason, every time I execute a plugin, both of the echo statements echo out '0' because supposedly the field I'm calling has no length. If anyone could help me out and explain what needs to be done to actually obtain the length of the password inputted in the textfield, I'd appreciate it! Thanks, Mark No members have liked this post.
|
||||||||
|
#2
|
||||
|
||||
|
Wouldn't you check the register template and evaluate password1.value and password2.value?
__________________
Kind regards, Simon Microsoft Office Help My Mods: Prevent Number Only Registrations, Ban Spiders by User Agent, WhoIsIp Info from any post, Insert Objects/ads anywhere using php, Floating Notice Box in Forumhome, Ban IP's Easily No members have liked this post.
|
|
#3
|
||||
|
||||
|
I want something that's not able to be changed by the user, meaning nothing in HTML/JS.
No members have liked this post.
|
|
#4
|
||||
|
||||
|
I think your problem is that normally the user's browser hashes the password and clears the plain text password field. You can disable that by defining DISABLE_PASSWORD_CLEARING to 1, such as in your config.php or in a plugin:
or if you wanted you might be able to define it only for the registration and profile pages so that you still have that security feature for normal logins.
__________________
Please don't PM me - post your questions in the appropriate forum.
Please don't PM me to ask me to read your thread. No members have liked this post.
|
||||
|
#5
|
||||
|
||||
|
Originally Posted by kh99
Would that lead to potential vulnerabilities and security exploits?
No members have liked this post.
|
||||
|
#6
|
||||
|
||||
|
I don't think so. What it does is it keeps the password from being sent "in the clear". But it doesn't even really protect your forum because if someone were somehow monitoring communications between a users' browser and your forum they could just as easily intercept the hashed password and use it to log in. (but they wouldn't know what the original password was, which I think is the point).
__________________
Please don't PM me - post your questions in the appropriate forum.
Please don't PM me to ask me to read your thread. No members have liked this post.
|
![]() |
«
Previous Thread
|
Next Thread
»
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Minimum Password Length | Eric | vBulletin 4.x Add-ons | 44 | Yesterday 15:08 |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) |
| Thread Tools | |
|
|
| New To Site? | Need Help? |
All times are GMT. The time now is 22:51.




