Home arrow Forum Latest posts of: Oldiesmann
  Welcome, Guest. Please login or register.
Did you miss your activation email?
January 08, 2009, 12:39:39 AM
Home New Posts Search Calendar


Login with username, password and session length
  Show Posts
Pages: [1]
1  Joomla Hacks / Joomla-SMF 2.0.x / Re: JSMF development will continue on: July 25, 2007, 01:24:19 PM
Well, what I am really thinking is that we should get a second opinion there, cause it is always the FSF opinion, we all know they are GPL supporters, and that's fine, but maybe other lawyers may differ. I am afraid actually other lawyers will differ  Huh

It doesn't matter what other lawyers think - only what the FSF and the Joomla developers think.
2  Joomla Hacks / Joomla-SMF 2.0.x / Re: Not safe? on: February 26, 2007, 11:48:33 AM
Sorry for the delayed response here.

Are you still having problems with the Login2 function? I wasn't aware of that post.

If you have to pass the password through the URL, you should pass the encrypted password and set hash_passwrd to "1". The code we use to hash passwords is as follows:

Code:
sha1(strtolower({membername}) . {password});

{membername} = the username
{password} = the password
3  Joomla Hacks / Joomla-SMF 2.0.x / Re: Not safe? on: February 18, 2007, 10:41:32 PM
The URL will indeed be logged in the browser's history, because at some point, the browser is directed to that URL, whether directly (by clicking on something) or indirectly (being redirected there from another page). Server-side stats programs such as AWStats will also log the URL since the user visited that URL.

Passing the un-hashed password via the query string is extremely insecure - especially on public computers. This is a serious flaw that needs to be addressed. We have already made the decision to warn our users about this, and we would appreciate it if you addressed this.
Pages: [1]


Login with username, password and session length

Powered by MySQL Powered by PHP Joomla Forum | Powered by SMF 1.1 RC1.
© 2001-2005, Lewis Media. All Rights Reserved.
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!

Joomla Hacks is a Joomla Components, Joomla Modules, Joomla Templates, & Joomla Mambots resource portal. None of the text or images in this public website may be copied without the expressed written consent of the authors. Copyright 2005 by JoomlaHacks.com. Powered by Joomla. All rights reserved.
Terms of Use
Joomla Hacks



Joomla Hacks
German Lang French Lang Italian Lang Spanish Lang Japanese Lang Chinese Lang
Search Contact About Advertise Blogs Topsites Submit News Register Login