Results 1 to 8 of 8

vBSEO Password

This is a discussion on vBSEO Password within the General Discussion forums, part of the vBSEO SEO Plugin category; Is anyone else bothered that this is stored in plaintext in the config_vbseo.php file? I would feel much better if ...

  1. #1
    Member SirAdrian's Avatar
    Real Name
    Adrian Schneider
    Join Date
    Sep 2006
    Posts
    31
    Liked
    0 times

    vBSEO Password

    Is anyone else bothered that this is stored in plaintext in the config_vbseo.php file? I would feel much better if it was at the very least hashed.

    I can't really see any reason for it not being more secure aside from, well, less than morally correct usage reports.

    Anyway, I'm not implying anything here... just a little bothered by this.

  2. #2
    Senior Member
    Real Name
    Keith Cohen
    Join Date
    Jul 2005
    Location
    Raleigh, NC USA
    Posts
    6,147
    Liked
    12 times
    What about your mySQL password stored as plaintext in vBulletin's config.php?

    Someone hacking into your vBSEO control panel and changing URLs around is nowhere near as destructive as hacking into your mySQL database IMO.

  3. #3
    Member SirAdrian's Avatar
    Real Name
    Adrian Schneider
    Join Date
    Sep 2006
    Posts
    31
    Liked
    0 times
    True, but config.php is required.

    It could be devastating because wouldn't they have access to throw in some of their own rewrite URLs in (pointing to another site, perhaps)?

    Anyway, is there a reason for not doing so?

  4. #4
    Senior Member
    Real Name
    Keith Cohen
    Join Date
    Jul 2005
    Location
    Raleigh, NC USA
    Posts
    6,147
    Liked
    12 times
    It's not a concern me personally, but I can't make the call for Crawlabilty. Management will have to give their official opinion.

  5. #5
    Member SirAdrian's Avatar
    Real Name
    Adrian Schneider
    Join Date
    Sep 2006
    Posts
    31
    Liked
    0 times
    Thanks.

    It's not so much the security concern... just the idea that if something can be more secure, well it should be. The only drawback would be being unable to edit the file directly.

  6. #6
    Senior Member
    Real Name
    Keith Cohen
    Join Date
    Jul 2005
    Location
    Raleigh, NC USA
    Posts
    6,147
    Liked
    12 times
    True. You could clear the password though, and then go to the interface to set a new one.

  7. #7
    vBSEO Staff Juan Muriente's Avatar
    Real Name
    Juan Carlos Muriente
    Join Date
    Jun 2005
    Location
    Puerto Rico
    Posts
    14,267
    Liked
    558 times
    Ok, this refinement has been implemented and will be distributed in the next vBSEO build. The vbseo cp password is now hashed in the text config file.

    Thank-you for the suggestion
    Juan Muriente / Crawlability Inc.
    vBSEO 3.6.0 GOLD Released!
    Unveiling the NEW vBSEO Sitemap Generator 3.0. - available NOW for vBSEO Customers!


  8. #8
    Senior Member libertylounge's Avatar
    Real Name
    Ken
    Join Date
    Aug 2006
    Posts
    439
    Liked
    0 times
    Awesome!
    The Liberty Lounge Political Forums - Our political forums, your two cents.

Similar Threads

  1. vBSEO 2.4.0 Released - Includes Google AdSense Targeting Feature!
    By Juan Muriente in forum vBSEO Announcements
    Replies: 74
    Last Post: 05-20-2006, 10:29 PM
  2. vBSEO 2.0 RC7 Released
    By Juan Muriente in forum vBSEO Announcements
    Replies: 17
    Last Post: 09-09-2005, 12:00 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •