Password protection

Get help with installation and running phpBB 3.2.x here. Please do not post bug reports, feature requests, or extension related questions here.
Post Reply
water01
Registered User
Posts: 119
Joined: Tue Dec 07, 2010 11:54 am

Password protection

Post by water01 » Fri Sep 21, 2018 4:14 pm

I am currently running 3.2.0.

A user reported that he received a phishing email (one of those you have been watching porn, we demand lots of bitcoins or else types), but the unusual thing about was it contained his forum password in the subject line. He assures me he only uses that password on the forum, but he does use the stay signed in feature, which presumably keeps the password in a cookie.

Is it feasible for someone to have extracted his password and used it in an email as the subject line or is it more likely he has a key logger malware on his computer (says he has run a scan)?

User avatar
canonknipser
Registered User
Posts: 2096
Joined: Thu Sep 08, 2011 4:16 am
Location: Germany
Name: Frank Jakobs
Contact:

Re: Password protection

Post by canonknipser » Fri Sep 21, 2018 4:20 pm

User passwords are not stored anywhere in phpBB or phpBB cookies - so there is no chance to grab the password from any of those sources.
Greetings, Frank
phpbb.de support team member
English is not my native language - no support via PM or mail
New arrival - Extensions and scripts for phpBB

water01
Registered User
Posts: 119
Joined: Tue Dec 07, 2010 11:54 am

Re: Password protection

Post by water01 » Fri Sep 21, 2018 4:26 pm

Thank you for your reply but surely they are encrypted on the MySQL database in the Users table?

User avatar
canonknipser
Registered User
Posts: 2096
Joined: Thu Sep 08, 2011 4:16 am
Location: Germany
Name: Frank Jakobs
Contact:

Re: Password protection

Post by canonknipser » Fri Sep 21, 2018 4:51 pm

no, there is only a salted password hash in the users table
Greetings, Frank
phpbb.de support team member
English is not my native language - no support via PM or mail
New arrival - Extensions and scripts for phpBB

water01
Registered User
Posts: 119
Joined: Tue Dec 07, 2010 11:54 am

Re: Password protection

Post by water01 » Fri Sep 21, 2018 5:37 pm

OK thank you that is what I thought.

Post Reply

Return to “[3.2.x] Support Forum”