Just a quick reminder that you can check that you do not have any unread PM's by clicking This Link


Clicking on the X top right will close this notification

Password Reset

If you want to know something or have a problem, look here first
User avatar
The Kaptain
Owner and Site Admin
Posts: 901
Joined: Sun Feb 23, 2014 11:48 am

Password Reset

Post by The Kaptain »

Following on from last weeks problem with passwords I have been in contact with Kualo on a daily basis and between us we have discovered a hitherto unknown incompatibility between phpBB 3.3.x (the Kabin) php 8.x.x (the language it uses) and Kualos server. As yet we haven't discovered the exact problem but between us I am sure we will get there in the end.

In the meantime, if you haven't logged in since 24th August you will need to reset you password using the link on the Log On page.
The man with the big stick
User avatar
Lanark
Full Member
Posts: 67
Joined: Sat Sep 07, 2019 1:21 pm

Re: Password Reset

Post by Lanark »

Do you mean we need to reset in order to login, or do we need to reset the password even if it currently works due to some security issue?
Turntable - Fluted Walnut LP12, Cirkus, Kore, trampolin, Ittok LVII, Lingo 4, Krystal.
Amplifier - Arcam A32.
Speakers - Spendor S-3/5.
CD Player - Linn Genki.
Tuner - Quad FM 4 (with output stage mod.)
Cables - Naim NAC A4.
Support - Sound Organisation.
User avatar
The Kaptain
Owner and Site Admin
Posts: 901
Joined: Sun Feb 23, 2014 11:48 am

Re: Password Reset

Post by The Kaptain »

No its certainly not a security issue, but a problem with the hashing of the passwords on the database.

Short version:- The hashed passwords became corrupted in the database and need resetting

Long version:- I updated from php 7.xx. to php 8.x.x (the language that the Kabin uses to function) which hashes the passwords in a different way. The upgrade caused a hitherto unreported bug in the email function which led to many notification emails being rejected by the receivers email server. Reverting back to php 7.x.x. resolved the email issue but meant that the passwords could no longer be unhashed meaning that even though your password was correct it could not match what was saved on the database.

Once you reset your password the issue no longer exists as it will be hashed using the method in php 7.x.x.

More about hashing can be read HERE Incidentally the password is also Salted

In short that means that even in the very unlikely chance of a hacker gaining access to the database he would be unable to read your passwords.
The man with the big stick
User avatar
The Kaptain
Owner and Site Admin
Posts: 901
Joined: Sun Feb 23, 2014 11:48 am

Re: Password Reset

Post by The Kaptain »

After lots of digging through code and testing we finally have solution thanks to Kualo and phpBB working together which now means that I have updated the server language to the latest supported version that is available to us.

Yo do not need to do anything, and everything should work exactly as before but as always if you know different please let me know.


I really can not praise Kualo highly enough. I know of no other hosting company who would put time and effort into helping solve a problem that ultimately is nothing to do with them.
The man with the big stick
User avatar
Wenge1
Full Member
Posts: 12,292
Joined: Mon Feb 24, 2014 4:26 pm

Re: Password Reset

Post by Wenge1 »

The Kaptain wrote: Wed Nov 09, 2022 10:04 am After lots of digging through code and testing we finally have solution thanks to Kualo and phpBB working together which now means that I have updated the server language to the latest supported version that is available to us.

Yo do not need to do anything, and everything should work exactly as before but as always if you know different please let me know.


I really can not praise Kualo highly enough. I know of no other hosting company who would put time and effort into helping solve a problem that ultimately is nothing to do with them.
Good man James for pursuing and persisting with this along with efforts of the hosting company ...... :smt023
LP12 - Klimax Radikal 2/Urika, Harban Plinth, Karousel, Keel, Karmen, Ekos SE, Skale, Lyra Atlas
CD Players - Roksan Caspian M2 CD Player, dCS Puccini CD Player + Scarlatti Master Clock
Amp - Chord Ultima Integrated
Speakers - Kudos S20 A's in Santos Rosewood
Cables - Linn Silver RCA & K200 speaker cable
.
User avatar
LD100
Full Member
Posts: 896
Joined: Sun Jun 18, 2017 10:57 am
Location: Chicago, Illinois USA

Re: Password Reset

Post by LD100 »

Wenge1 wrote: Wed Nov 09, 2022 3:56 pm Good man James for pursuing and persisting with this along with efforts of the hosting company ...... :smt023
I'll second that... :smt023

xss09
Original 1978 Fluted Afromosia LP12, Ekos 2, Lyra Kleos SL and lots of other stuff from the 70's that still work fine.
HiFi Kabin : Disclaimer