-
Notifications
You must be signed in to change notification settings - Fork 33
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[phpBB 3] passwords with special characters not recognized #221
Comments
Interesting, if it's not a case for the older versions of phpBB we could do a check against the Ideally someone would need to figure what version have it and what versions don't. |
That's weird, I wouldn't have expected them to be escaping entities in passwords at all! We'll definitely have to do some research, I'll look at their code and see if I can see where they hash passwords and how long its been that way. |
From a quick glance at phpBB's current source code, I can't see anything obvious that would be converting characters to HTML entities, but I'm not too familiar with their code. |
I dumped passwords/driver/bcrypt.php to find this out. |
Ah, weird. I looked at pretty much everything except the individual drivers. Thanks @burner1024. |
mark |
Any user having an & (ampersand) in their password is not able to login after merge.
Apparently phpBB replaces it with & prior to hashing and storing in the database. So "test1&test1" password is in fact "test1&test1" as far as phpBB is concerned. But loginconvert.php uses pristine password for comparison, and the result is that the hashes never match.
Same for other special characters.
This lets such users log in:
This is true for phpBB 3.2.4, not sure about other releases.
Also not sure whether it's a bug or a feature of phpBB, but I think Merge System should handle this either way, even it requires some ugly version detection.
The text was updated successfully, but these errors were encountered: