cnb ya and php nuke some help please

  Post new topicReply to topicPrintable Version
<< View previous topic View next topic >>
Share: Del.icio.us  Digg  Google  Spurl  Blink  Furl  Y! MyWeb  
#1   cnb ya and php nuke some help please
flid
CZ Newbie
 Codezwiz Site Donator
flid has been a member for over 19 year's 19 Year Member
Gender: Female
Status: Offline
Joined: Oct 01, 2005
0.00 posts per day
Posts: 3
Points: 1,777
   
i have CNB_Your_Account_750_440_b2 and phpnuke 7.8 all seem to be working great, but today i was looking at my sql and i notcied that someone has registered twice with the same email. I have the box checked so they arent supposed to be able to do that, does anyone know how they managed?

also since it was installed the users passwords arent encrypted, is there any way i can make sure they are?



Back to top Reply with quote
#2   
Telli
Site Admin
Occupation: Self Employed
Age: 46
Gender: Male
Fav. Sports Team: Detroit Red Wings
Website:
Status: Offline
Joined: May 26, 2003
1.03 posts per day
Posts: 8089
Points: 494,430
   
Thats strange that they are not encrypted. You might want to post this on there support forum for a bug fix.




_________________
The path of the righteous man is beset on all sides by the inequities of the selfish and the tyranny of evil men. Blessed is he, who in the name of charity and good will, shepherds the weak through the valley of darkness, for he is truly his brother's keeper and the finder of lost children. And I will strike down upon thee with great vengeance and furious anger those who would attempt to poison and destroy my brothers. And you will know my name is the Lord when I lay my vengeance upon thee. Ezekiel 25:17
Back to top Reply with quote
#3   re: cnb ya and php nuke some help please
Gareth
CZ Addict
 Codezwiz Site Donator
Gareth has been a member for over 20 year's 20 Year Member
uk.gif
Occupation: Student, Webmaster
Gender: Male
Fav. Sports Team: Liverpool FC
Status: Offline
Joined: May 29, 2004
0.08 posts per day
Posts: 587
Points: 38,220
   
Just to catch your attention, if your user passwords arent encrypted, then they wont be able to login, because the login proccess encrypts the login password and matches it with the encrypted password in the datbase. Which would cause it to say invalid login...

Somewhere in your coding must be missing the md5() encryption function.

And about the same email registrar, your coding might not be checking for duplicate emails correctly.

Was all the other user's information the same, username, etc.. ?

~Gareth




_________________
[ Register or login to view links on this board.]
Back to top Reply with quote
Display posts from previous:      
Add To: Del.icio.us  Digg  Google  Spurl  Blink  Furl  Y! MyWeb  
<< View previous topic View next topic >>
Post new topicReply to topic

Jump to 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum