How come passwords in coppermine database are not encrypted? How come passwords in coppermine database are not encrypted?
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

How come passwords in coppermine database are not encrypted?

Started by kfc, November 15, 2004, 08:25:59 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

kfc

I'm not sure if this has been fixed in 1.3, but in 1.2 they are open for the admin to see. I did a 1.2 to 1.3 upgrade and I still see them unencrypted. IMO this gives the admins more info than they need, if the passwords are used for more than one thing by the user. (email, ftp, computer)

Casper

This (md5 encrypted passwords) is on the list of features we hope to include in version 1.4, although it is not done yet.  It involves changes to several things, such as the password reminder system, as well as just adding md5.

This has been discussed at length, please search in future, and this also belongs in the general board, as this is not a support request, but just a discussion item.  Please post in the correct place for the correct type of topic.
It has been a long time now since I did my little bit here, and have done no coding or any other such stuff since. I'm back to being a noob here

Joachim Müller

@kfc: great question, why don't you ask some more questions like this, e.g. "why can't coppermine make coffee and wash the dishes". Let's see some contributions from your side instead of nagging and reluctance to search before posting - you have been told so before already. >:(

Joachim

kfc

Do you wake up on the wrong side of the bed every day GauGau? Or do you have something crammed up your rear again?

STFU and stop acting like an ass. I'm a noob with 29 posts, you have 10032 posts. Do you comprehend?

Tranz

#4
@kfc Imagine being someone who has 10,000 posts. GauGau has helped more people than you probably ever will in your lifetime. If it weren't for the strict policies, GauGau would have many more posts and repeating himself more than he already has to do, and bringing himself closer to carpel tunnel syndrome. Imagine how you would feel repeating yourself literally hundreds of times. You probably aren't going to be all friendly. Especially since you are already striking out against someone who helps people. How much patience are you going to have when giving assistance to people who get help and don't give back, but yet have the audacity and insolence to disregard rules repeatedly?

Joachim Müller

The content of my lower body regions is no business of yours, and something you probably wouldn't want to investigate further, so stop your little medical discourse; we don't want to hear more from your anal fixation. Swearing won't get you on anybody's valentine card list either. Having 10,000+ posts at least shows I actually used the search function of the board every now and then, and this is what I have been telling you: a quick search for "encrypt password" would have shown you all the relevant threads - you don't need to have experience to use the search button, some common sense will do.

I will now do as you suggest an shut up, maybe we all should and stop replying to you, as long as you don't review your attitude. Have a nice life.

Joachim


Tarique Sani

SANIsoft PHP applications for E Biz