TUCoPS :: Web BBS :: etc :: neoboa~1.txt

Neoboard 3.0 default password crypt salt

COMMAND

    Neoboard

SYSTEMS AFFECTED

    Neoboard 3.0

PROBLEM

    Jonathan  Leto  found  following.   He  was  browsing  the code of
    neoboard_register.php and found at line 210 this:

        if($this->style->USE_CRYPT) $userpassword = crypt($userpassword, '.v');

    All passwords are  generated with a  salt of ".v".   This isn't  a
    huge security  hole, but  if someone  gets to  the hashes  in your
    database, it will be a lot easier to crack them.

SOLUTION

    Nothing yet.

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH