- Posts: 88
- Thank you received: 0
Password
- Mark
-
Topic Author
- Offline
- Premium Member
-
Less
More
9 years 11 months ago - 9 years 11 months ago #62449
by Mark
Password was created by Mark
I've just noticed the "password" column in the membship table.
Is that really the user password? It's stored in plaintext, it seems.
If that is the case it is a really, Really, REALLY bad potential security risk.
Please tell me that you're going get rid of it.
It compromises the entire system, and as people often use the same password on many accounts, it's a very bad security risk for the whole net...
Is that really the user password? It's stored in plaintext, it seems.
If that is the case it is a really, Really, REALLY bad potential security risk.
Please tell me that you're going get rid of it.
It compromises the entire system, and as people often use the same password on many accounts, it's a very bad security risk for the whole net...
Last edit: 9 years 11 months ago by Mark.
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
9 years 11 months ago #62450
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Password
Hi Mark
It is not bad like that. Let me explain:
1. It is encrypted, not your raw password
2. It will only be used if you set "Only create user account when membership active/approved" config option to Yes
3. It will be erase as soon as the subscription record is active/approved. So in case someone uses Paypal, it will be erased right after he makes payment at Paypal (right after the system send usersname and password to him)
Regards,
Tuan
It is not bad like that. Let me explain:
1. It is encrypted, not your raw password
2. It will only be used if you set "Only create user account when membership active/approved" config option to Yes
3. It will be erase as soon as the subscription record is active/approved. So in case someone uses Paypal, it will be erased right after he makes payment at Paypal (right after the system send usersname and password to him)
Regards,
Tuan
The following user(s) said Thank You: Mark
Please Log in or Create an account to join the conversation.
- Mark
-
Topic Author
- Offline
- Premium Member
-
Less
More
- Posts: 88
- Thank you received: 0
9 years 11 months ago - 9 years 11 months ago #62453
by Mark
Replied by Mark on topic Password
Ok. I'll calm down now 
In the table I've got three users from several days ago where the passwords are still in the table.
I think they're accounts that I have manually set to "Active"...
I've now just reset those fields to NULL manually.
PS - I still think it's a really bad idea to send the password to the admin!

In the table I've got three users from several days ago where the passwords are still in the table.
I think they're accounts that I have manually set to "Active"...
I've now just reset those fields to NULL manually.
PS - I still think it's a really bad idea to send the password to the admin!
Last edit: 9 years 11 months ago by Mark.
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
9 years 11 months ago #62471
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Password
Will consider change it. Of course, admin doesn't need to know the password
.
Tuan

Tuan
Please Log in or Create an account to join the conversation.
Support
Documentation
Information
Copyright © 2025 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.