Page 1 of 1

How to Remove Salt function in joomla 1.5

Posted: Thu Oct 08, 2009 6:14 am
by arjuninfo
How to Remove Salt function in joomla 1.5


its very simple


root\joomla\libraries\joomla\user

helper.php

remove this code in line no 284


$salt = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";

To

$salt = '';

Re: How to Remove Salt function in joomla 1.5

Posted: Thu Oct 08, 2009 6:19 am
by arjuninfo
Another thing goto

root\joomla\libraries\joomla\user

user.php (in line 400 to 410)

Replace

$salt = JUserHelper::genRandomPassword(32);
$crypt = JUserHelper::getCryptedPassword($array['password'], $salt);
$array['password'] = $crypt.':'.$salt;



To


$salt = JUserHelper::genRandomPassword(32);
$crypt = JUserHelper::getCryptedPassword($array['password'], $salt);
$array['password'] = $crypt;



And in line around 430 to 450

again change this line Replace


$salt = JUserHelper::genRandomPassword(32);
$crypt = JUserHelper::getCryptedPassword($array['password'], $salt);
$array['password'] = $crypt.':'.$salt;


To



$salt = JUserHelper::genRandomPassword(32);
$crypt = JUserHelper::getCryptedPassword($array['password'], $salt);
$array['password'] = $crypt;


------------------------------------------------------------------------------------

Re: How to Remove Salt function in joomla 1.5

Posted: Thu Oct 08, 2009 6:25 am
by arjuninfo
look at this screenshot

Re: How to Remove Salt function in joomla 1.5

Posted: Thu Oct 08, 2009 6:31 am
by mark_up
A most informative post arjuninfo, thank you very much.

I wonder though, why would you want to do this? Why reduce the security that Joomla currently offers?

Re: How to Remove Salt function in joomla 1.5

Posted: Thu Oct 08, 2009 6:40 am
by arjuninfo
GollumX wrote:A most informative post arjuninfo, thank you very much.

I wonder though, why would you want to do this? Why reduce the security that Joomla currently offers?

Please check this post ,,,,then u will know why i posted this topic ...

http://forum.joomla.org/viewtopic.php?f=304&t=448432

Re: How to Remove Salt function in joomla 1.5

Posted: Thu Oct 08, 2009 7:01 am
by mark_up
Thanks

Re: How to Remove Salt function in joomla 1.5

Posted: Fri Oct 09, 2009 9:48 am
by selvaganeshj
arjuninfo wrote:
GollumX wrote:A most informative post arjuninfo, thank you very much.

I wonder though, why would you want to do this? Why reduce the security that Joomla currently offers?

Please check this post ,,,,then u will know why i posted this topic ...

http://forum.joomla.org/viewtopic.php?f=304&t=448432
Hi Arjuninfo,

I saw the post which you linked here.
i think there is no need to remove the salt to add the old password functionalities.
we can use the JUserhelper calss to check the old password. :)

Re: How to Remove Salt function in joomla 1.5

Posted: Fri Oct 09, 2009 10:33 am
by ooffick
Mod Note: Moved to Core Hacks Forum