oPg Gaming Forum
May 25, 2012, 10:50:41 PM *
Welcome, Guest. Please login or register.

Login with username, password and session length
Make payments with PayPal - it's fast, free and secure!
News: Stay tuned to opggaming.com for new features, modifications, and improvements.
 
   Home   opggaming Help Arcade Search Calendar stats SourceBans Login Register  


hd-gaming
Pages: [1]   Go Down
  Print  
Author Topic: Sharing of the community  (Read 637 times)
0 Members and 1 Guest are viewing this topic.
Gidgidonihah
Seriously, what does it mean?
Moderator
Hero Member
*****
Posts: 2163



« on: March 21, 2007, 08:19:21 PM »

Now, I haven't looked at the code to smf yet, but depending on how they handle inserting a new user into the database, it could be quite easy.

All we would have to do is hack the code a little bit (a single function with any luck) to put it in the local database as well as connect to a remote database (the other forum) and input the user info there.

What do you say latro?
Logged

Jedakiah
Hero Member
*****
Posts: 4632



WWW
« Reply #1 on: March 21, 2007, 10:29:47 PM »

Pardon my ignorance, I'm here to learn.  But can you make it secure (I mean REALLY secure)?  You are sending passwords over the web to a remote location.  And obviously that can be bad news if isn't secured like it should be. 
Logged

Gidgidonihah
Seriously, what does it mean?
Moderator
Hero Member
*****
Posts: 2163



« Reply #2 on: March 22, 2007, 01:21:24 AM »

Well first of all the passwords are stored in an md5 hash, so you're not really sending the password, you're sending the hash of the password, and second, you could send it over an encrypted connection, which would of course make the entire process even slower.
Logged

Jakestaby
Guest
« Reply #3 on: March 22, 2007, 09:27:34 AM »

Hosting both forums on the same box would solve the problem.
Logged
Jedakiah
Hero Member
*****
Posts: 4632



WWW
« Reply #4 on: March 22, 2007, 03:01:51 PM »

Well first of all the passwords are stored in an md5 hash, so you're not really sending the password, you're sending the hash of the password, and second, you could send it over an encrypted connection, which would of course make the entire process even slower.
I knew they were stored as a hash, but those are certainly not bulletproof.  When sending information like ADMIN passwords (particularly the ROOT ADMIN who might be dumb enough to use the same password for the site, no offense Latro) you need to be extra careful.  I have read about this being a large security vulnerability in PHP. One that should be protected against. 

It may be nearly impossible to exploit though.  I don't know.  Ask Jake. 

Jake's idea is great one.  If you did this you should try that. 
Logged

Jakestaby
Guest
« Reply #5 on: March 22, 2007, 03:18:24 PM »

Unless someone is sniffing traffic on either side or somewhere along the way and knows what to look for.
Logged
Labyrinthine
Administrator
Hero Member
*****
Posts: 5814


Abuya?!?


« Reply #6 on: March 22, 2007, 03:51:38 PM »

Like Jake  Wink
Logged

Jakestaby
Guest
« Reply #7 on: March 22, 2007, 03:57:51 PM »

And I will use any information maliciously.
Logged
Jedakiah
Hero Member
*****
Posts: 4632



WWW
« Reply #8 on: March 22, 2007, 07:22:10 PM »

When that day comes do me a favor, give Killa the ability to read only. 
Logged

The Grandfather
Hi Halloweenie!!!!!!
Premier Admin
Hero Member
*****
Posts: 3766


Man who scratch ass should not bite fingernails.


WWW
« Reply #9 on: March 22, 2007, 08:58:51 PM »

Whats that supposed to mean?
Logged


[The OPG World]
Man who run in front of car get tired. 
Quote from: Labyrinthine link=topic=3818.msg46378#msg46378
Oh f*** you.
ppstain :  man logical how could you NOT kill me!
Jedakiah
Hero Member
*****
Posts: 4632



WWW
« Reply #10 on: March 22, 2007, 10:07:55 PM »

You can't post, but you can still read the forums. 
Logged

Gidgidonihah
Seriously, what does it mean?
Moderator
Hero Member
*****
Posts: 2163



« Reply #11 on: March 22, 2007, 11:52:49 PM »

Wouldn't that be great.

Yeah, hosting on the same box would work, but I'm not running our server so I'd have to mediate that between latro and the camel...
Logged

Jakestaby
Guest
« Reply #12 on: March 23, 2007, 08:57:02 AM »

Is your server with a webhost like Latro's?  Or is he hosting it?
Logged
Gidgidonihah
Seriously, what does it mean?
Moderator
Hero Member
*****
Posts: 2163



« Reply #13 on: March 23, 2007, 11:00:35 AM »

That, I do not know.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.12 | SMF © 2006-2009, Simple Machines LLC | Sitemap Valid XHTML 1.0! Valid CSS!


Google visited last this page May 17, 2012, 09:22:27 AM