The following warnings occurred:
Warning [2] Undefined variable $unreadreports - Line: 26 - File: global.php(961) : eval()'d code PHP 8.2.25 (Linux)
File Line Function
/global.php(961) : eval()'d code 26 errorHandler->error
/global.php 961 eval
/showthread.php 28 require_once





× This forum is read only. As of July 23, 2019, the UserSpice forums have been closed. To receive support, please join our Discord by clicking here. Thank you!

  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
danger: us4.2, us4.3 hackable easly
#4
The patch was issued in 4.2.12 and in 4.3. I'd love for you to take a look at it. Here's my math on the new vericode...

To give you an idea, the current 6 digit numeric vericode could have been brute forced at 18.52 mins online (with a rate of 1000 guesses per second hitting your webserver, on average they would get in at 9.26 minutes). The new code takes 4.01 trillion centuries at 1000 guesses a second. Even a massive attack of 100 Trillion guesses a second would take 40.08 centuries.

User banning after too many vericode attempts is coming soon. We're just trying to stabilize 4.3 as a whole.
Thanks so much for your help!
  Reply


Messages In This Thread
danger: us4.2, us4.3 hackable easly - by Brandin - 11-05-2017, 06:21 PM
danger: us4.2, us4.3 hackable easly - by mudmin - 11-06-2017, 01:12 PM
danger: us4.2, us4.3 hackable easly - by mudmin - 11-12-2017, 12:59 PM

Forum Jump:


Users browsing this thread: 1 Guest(s)