vBulletin SEO Forums

SEO

vBulletin Search Engine Optimization

Buy vBSEO Now! HACKER SAFE certified sites prevent over 99.9% of hacker crime.
ne nw
New vBSEO Discount Level for Network Builders Meet vBSEO Team in New York (Nov. 3rd & 4th) vBSEO 3.2.0 GOLD Has Landed Success with vBSEO = 600ore Web Visitors + $1400 in a Day! Crawlability Inc. Files for SEO Technology Patent
se sw

Visible Runcode Password

This is a discussion on Visible Runcode Password within the Bug Reporting forums, part of the vBSEO Google/Yahoo Sitemap category; While the runcode password is only a cookie for that session, it is stored unencrypted. I strongly suggest that it ...

Go Back   vBulletin SEO Forums > vBSEO Google/Yahoo Sitemap > Bug Reporting

Enhancing 80 million pages.

Register FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read
  #1  
Old 12-19-2005, 02:50 AM
T2DMan's Avatar
Senior Member
vBSEO Pre-Release Team
 
Real Name: Michael Brandon
Join Date: Jul 2005
Location: Auckland, New Zealand
Posts: 357
Send a message via ICQ to T2DMan Send a message via AIM to T2DMan Send a message via MSN to T2DMan Send a message via Yahoo to T2DMan
Visible Runcode Password

While the runcode password is only a cookie for that session, it is stored unencrypted. I strongly suggest that it be encrypted, and done in such a way that even if you knew the php code, that it could not be unencrypted easily.

Yes, all you need to do is close the browser and the cookie should be gone, but why have the risk.

Many people may use the same password for many other applications, so it really is not worth it to leave accessable.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2  
Old 01-19-2006, 10:55 AM
MentaL's Avatar
Senior Member
Big Board Administrator
 
Real Name: Daniel James
Join Date: Oct 2005
Location: Wales
Posts: 253
Re: Visible Runcode Password

Very good check especially for any future XSS problems that may happen, suprised the team didnt check this one already.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3  
Old 01-19-2006, 11:14 AM
Keith Cohen's Avatar
vBSEO Staff
vBSEO Total Customer SupportBig Board Administrator
 
Real Name: Keith Cohen
Join Date: Jul 2005
Location: Raleigh, NC USA
Posts: 6,265
Blog Entries: 1
Re: Visible Runcode Password

I'd like to see the process changed a bit to allow passwords with special characters. If I wanted to use a password with a # in it, I can't because it's passed on the URL and the # screws it up.
__________________
Keith Cohen / Crawlability Inc.
vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

vBSEO Google Sitemap Generator - Version 2.2 Released Mandatory Upgrade for vBSEO 3.2.0 GOLD

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.


My Personal Sites: My Blog | GPS Discussion Forum
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4  
Old 01-19-2006, 12:08 PM
Oleg Ignatiuk's Avatar
vBSEO Staff
vBSEO Total Customer SupportvBSEO Documenter
 
Real Name: Oleg Ignatiuk
Join Date: Jun 2005
Location: Belarus
Posts: 21,449
Blog Entries: 1
Re: Visible Runcode Password

Thank you, it is implemented already and will be available in the next vBSEO Sitemap Generator release.
__________________
Oleg Ignatiuk / Crawlability Inc.
vBSEO 3.2.0 Launched - Maximum Overdrive for Your Web Traffic! Over 100 Instant SEO Optimizations

vBSEO Google Sitemap Generator - Version 2.2 Released Mandatory Upgrade for vBSEO 3.2.0 GOLD

6X Traffic - $1400 in One Day with vBSEO! Imagine What the vBSEO Patent Pending Technology Can Do For You.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Installation question: Please select a password. bob Troubleshooting 2 02-04-2006 11:10 PM
This area is password protected. Greg Watson Troubleshooting 10 10-30-2005 04:54 PM


All times are GMT -4. The time now is 11:46 AM.


Powered by vBulletin Version 3.8.0 Beta 3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.5 ©2008, Crawlability, Inc.