Zikula: A Flexible Open Source Content Management System
home | forum | contact us

Dizkus

Bottom
Secure login hack
  • Posted: 12.03.2006, 09:57
     
    InvalidResponse
    rank:
    Professional Professional
    registered:
     September 2003
    Status:
    offline
    last visit:
    21.10.07
    Posts:
    2423
    I stumbled on a javascript implementation of the MD5 algorithm and hacked it into the system.. it allows for passwords to be encrypted "before" the form is submitted.. it also uses a truncated hash to prevent the potential for a replay compromise (logging in with the encrypted password).

    Demo

    Download

    note: this is a hack. core files were slightly modified. backup your files before installing and use at your own risk. requires PostNuke version .762

    bye now,
    -IR
    [edit: bad link]

    --
    http://www.invalidresponse.com
  • Posted: 13.03.2006, 22:00
     
    Slugger
    rank:
    Professional Professional
    registered:
     March 2003
    Status:
    offline
    last visit:
    13.08.06
    Posts:
    1185
    Or is that..."buy now". icon_lol

    Sluggo
  • Posted: 14.03.2006, 00:02
     
    InvalidResponse
    rank:
    Professional Professional
    registered:
     September 2003
    Status:
    offline
    last visit:
    21.10.07
    Posts:
    2423

    Slugger

    Or is that..."buy now". icon_lol

    silly slugg-o :D .. it's a thankless "job".. and I'm privileged to do it.

    --
    http://www.invalidresponse.com
  • Posted: 14.03.2006, 01:34
     
    InvalidResponse
    rank:
    Professional Professional
    registered:
     September 2003
    Status:
    offline
    last visit:
    21.10.07
    Posts:
    2423
    ..just to avoid any confusion the above comment may cause.. there's no "fee".. it's a free download.

    --
    http://www.invalidresponse.com
  • Posted: 27.06.2008, 16:42
     
    TakeIT2
    rank:
    Softmore Softmore
    registered:
     December 1969
    Status:
    offline
    last visit:
    23.10.08
    Posts:
    68
    Has any of this been implemented for Zikula?

Main Menu

Extensions Database

Documentation

Development

Login

Donate to Zikula