 |

terryally
User
Mar 23, 2006, 4:33 PM
Post #1 of 2
(3476 views)
Shortcut
|
|
Encrypted password - Article Manager
|
Can't Post
|
|
Dear InteractiveTools, The password as entered in Article Manager->Setup->Login Accounts as well as account.dat.cgi are in plain text. I would like to see this encrypted and assume that it shall be done in the MySQL version?? As it is now, it can be open to abuse - which I have encountered by other users downloading the file, accessing my password and then logging in as me. Terry
|
|
|  |
 |

Donna
Staff
/ Moderator

Mar 24, 2006, 11:45 AM
Post #2 of 2
(3448 views)
Shortcut
|
|
Re: [terryally] Encrypted password - Article Manager
[In reply to]
|
Can't Post
|
|
Dear Terry, Thanks for your post. Since the file has a .cgi extension, it shouldn't be possible for other users to download the file. Since only authorized users should have access to the /data/ directory (as setup by your web hosting provider), this shouldn't be an issue at all. Can you give me more details about how any unauthorized users were able to access this? Donna
Hire me! Save time by getting our experts to help with your project. Template changes, advanced features, full integration, whatever you need. Whether you need one hour or fifty, get it done fast with Priority Consulting.
|
|
|  |
|