|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2002-01-04, 00:50
|
MerlinCorey 
Regular
|
|
|
|
IB3 Password Encryption
I am an administrator at PlanetMars (just a simple PC message board)... Due to... Internal conflicts (a certain member changed an important password for the site), we really need to find out what his password for the board is (to try HIS password for this other password)... What I am asking is, does anyone know how IB3 passwords are encrypted in the password database..? I found evidence that it may be encrypted using md5, but my own personal test (decrypting my own password and checking the result) has not come out satisfactorily... Perhaps I am implementing it wrong, I do not know; however, if someone - anyone - knows how IB3 passwords are encrypted, please post here...
I am not trying to steal this person's account - I am an administrator and IB3 allows me to change passwords to whatever I desire (thus giving me use of their account) but it no longer (in IB2 it used to) shows the users current password... Please help me... Thanks...
|
|
#2
 2002-01-04, 09:55
|
Jadedfool 
Regular
|
|
|
|
Re: IB3 Password Encryption
I'm not familiar with the IB3 hash, or at least not by that name, but you generally can't decrypt password hashes, what you do is run a crack program that runs everything possible through the same algorithm and check to see if it comes out the same. Can take damn near forever if the guy choose a good password...
if it actually is an MD5 hash with a funny name, you can use this to attempt to crack it...
good luck.
|
|
#3
 2002-01-04, 10:20
|
|
|
Re: IB3 Password Encryption
frag hier
|
|
#4
 2002-01-04, 14:34
|
MerlinCorey 
Regular
|
|
|
|
Re: IB3 Password Encryption
Hmmm, thanks alot... I've already grabbed JohnTheRipper, thanks... And this isn't a UBB board, it's an Ikonboard, but thanks... I've started working on something that may work... I've gotten MY encrypted password, and I know what it is decrypted, so I think I can devise a way to find out what key was used to go in between, and then apply that to finding the other password...
|
|
#5
 2002-01-04, 15:33
|
Wintermute 
Regular
|
|
|
|
Re: IB3 Password Encryption
See? THAT'S why you don't use Ikonboard...
Wouldn't the simplest way to figure it out be to look at the ikonboard code?.
Last time I looked, ib was an almost complete clone of ubb, down to the last perl-y drop...
So, if you can find the section that deals with passwords, that would probably help immensely.
|
|
#6
 2002-01-05, 02:34
|
MerlinCorey 
Regular
|
|
|
|
Re: IB3 Password Encryption
Yeah, I thought about looking at the code for the board but I am pretty sure that when it encrypts the password and decrypts the password in the user database that it calls some function in a DLL located on the server - but I don't know perl/cgi at all and don't feel too confident in going through the board source... Once again, thanks for the help... 
|
|
#7
 2002-01-05, 03:33
|
Wintermute 
Regular
|
|
|
|
Re: IB3 Password Encryption
All you need to do is watch the url.. Whatever point in a password's life that it gets encrypted, the url of the page you're at should tell you which perl file to look at.. Should also tell you where the member files are stored.. With UBB, it's possible to make yourself an admin with ftp access, and do all kinds of fun stuff.. In fact, there's not much you can't do if you play around in the ubb files on the server long enough...
Really, message board software works fairly simply, there's just a lot of code to look at.. If you read long enough though, it becomes clear..
|
|
#8
 2002-01-05, 23:13
|
MerlinCorey 
Regular
|
|
|
|
Re: IB3 Password Encryption
Thank you, Wintermute... I will look for the perl file... I'll post if I find it (that way anyone else looking for need only refer to this topic for the answer  )...
|
|
#9
 2002-01-06, 03:09
|
Wintermute 
Regular
|
|
|
|
Re: IB3 Password Encryption
np, I'd just like to reiterate the fact that Ikonboard sucks.
VBulletin or UBB every time, pref. UBB, because vbulletin gets REALLY bloated really fast.
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|