Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: password...  (Read 6363 times)

0 Members and 1 Guest are viewing this topic.

tanfwc

  • Contributor
  • Coppermine frequent poster
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 108
    • tanfwc.com
password...
« on: March 27, 2004, 06:50:53 am »

why is the password in the database not in md5 hashes? it is in PLAIN TEXT...
Logged
tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
password...
« Reply #1 on: March 27, 2004, 08:05:11 am »

there has been a discussion about this a while ago, please search the board for "md5 AND password".
There's a mod available: http://forum.coppermine-gallery.net/index.php?topic=2179

GauGau
Logged

tanfwc

  • Contributor
  • Coppermine frequent poster
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 108
    • tanfwc.com
password...
« Reply #2 on: March 27, 2004, 08:14:53 am »

ok. Thanx. Why dun u put that function into this gallery?
Logged
tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
password...
« Reply #3 on: March 27, 2004, 08:16:34 am »

I hope you read the posting I was refering to: there's always ease of use against security: some people prefer having the passwords stored in plain text, because they run a gallery with newbie-users who forget their passwords every now and then: it's easier to look up their passwords if they're plain-text.
If someone hacks your site and is able to see your database (e.g. gains access to phpMyAdmin) and its contents, you probably have to worry about other things anyway...
The main reason why this hasn't been done yet I guess is: it simply has been forgotten. There are so many features that are being considered when developing a new version: sometimes you simply forget about stuff you were thinking about before.

GauGau
Logged

tanfwc

  • Contributor
  • Coppermine frequent poster
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 108
    • tanfwc.com
password...
« Reply #4 on: March 27, 2004, 08:22:14 am »

does this md5 feature install in the future versions?
Logged
tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
password...
« Reply #5 on: March 27, 2004, 08:48:55 am »

maybe, but it's not in cpg1.3.0, which is in the release pipeline.

GauGau
Logged

tanfwc

  • Contributor
  • Coppermine frequent poster
  • ***
  • Offline Offline
  • Gender: Male
  • Posts: 108
    • tanfwc.com
password...
« Reply #6 on: March 27, 2004, 03:14:24 pm »

ok. :)
Logged
tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting
Pages: [1]   Go Up
 

Page created in 0.017 seconds with 19 queries.