viewing passwords in 2.21

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • slip
    Member
    • Jan 2001
    • 66

    viewing passwords in 2.21

    sorry if this has been asked before, but i recall previously being able to change something in config.php or something that allowed admins to see users passwords instead of just a blank field.. is there a way to make these viewable again?


    thanks,
    slip
  • WizyWyg
    Senior Member
    • Jul 2001
    • 1309
    • 2.3.0

    #2
    Re: viewing passwords in 2.21

    Originally posted by slip
    sorry if this has been asked before, but i recall previously being able to change something in config.php or something that allowed admins to see users passwords instead of just a blank field.. is there a way to make these viewable again?


    thanks,
    slip
    Sorry, with MD5 encryption, its no longer viewable to anyone (viewable through your Database as it always has been)
    I'd also question as to why anyone would need to view the "personal" passwords of their members.

    Edit : sorry misread the post, but you can only view the pw's through mysql query (or if you have phpmyadmin or mysqlman) but you wont be able to make them out because they are encrypted.
    Last edited by WizyWyg; Sat 1 Dec '01, 11:13pm.
    There are only 10 types of people in the world: Those who understand binary, and those who don't

    Comment

    • tubedogg
      Senior Member
      • Feb 2001
      • 13602

      #3
      Follow the link in my sig to my Admin Functions set of scripts which contains a file that will convert normal strings of text into md5 encrypted strings so you can compare them with the passwords in the database.

      Comment

      • CondorZ
        Senior Member
        • Oct 2001
        • 238

        #4
        Re: Re: viewing passwords in 2.21

        Originally posted by WizyWyg



        I'd also question as to why anyone would need to view the "personal" passwords of their members.

        A guy asks a simple question and here comes the ethics and morality lecture yet again.

        Comment

        • Fusion
          Senior Member
          • Aug 2001
          • 4346
          • 3.8.x

          #5
          We're suspicious by nature, that's not necessarily a bad thing.
          Toddler from Hell

          Comment

          • Black Tiger
            Senior Member
            • Mar 2001
            • 668

            #6
            How many reasons you need for an admin viewing the passwords of his users, especially on a little more private board or a board with private forums on it?

            I can name you two for starters. Not all your users are bright, and you want to check if they are not using a too easy password (like login name and pw = same).

            The second one is if you know a hell of a lot of your users, and you meet on irc and icq, it's faster for a user to ask you to lookup his password then following the lost password procedure, especially is he/she's busy.

            One should first think of reasons that could be valid before being courious.

            Curiousity killed the cat.
            Greetings, Black Tiger

            Comment

            • WizyWyg
              Senior Member
              • Jul 2001
              • 1309
              • 2.3.0

              #7
              Originally posted by Black Tiger
              How many reasons you need for an admin viewing the passwords of his users, especially on a little more private board or a board with private forums on it?

              I can name you two for starters. Not all your users are bright, and you want to check if they are not using a too easy password (like login name and pw = same).
              Then what's it your business to know that? IF they choose to have an "easy" password, that's their business. Let them suffer if something happens to compromise it.

              The second one is if you know a hell of a lot of your users, and you meet on irc and icq, it's faster for a user to ask you to lookup his password then following the lost password procedure, especially is he/she's busy.
              Oh and this is "bright". Someone on IRc asks for their password to your board. Hmmm.. Dont you see the fallacy in this? Can you really confirm that that person is actually the person with pw?


              One should first think of reasons that could be valid before being courious.

              Curiousity killed the cat.
              Nope, still no valid reasons for knowing your member's pw. One should first think about their "answers" before posting them ^_~
              There are only 10 types of people in the world: Those who understand binary, and those who don't

              Comment

              • tubedogg
                Senior Member
                • Feb 2001
                • 13602

                #8
                I am ending this here...he did not ask for a lecture, he asked for an answer to his question.

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...