<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:x="urn:schemas-microsoft-com:office:excel" xmlns:p="urn:schemas-microsoft-com:office:powerpoint" xmlns:a="urn:schemas-microsoft-com:office:access" xmlns:dt="uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s="uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs="urn:schemas-microsoft-com:rowset" xmlns:z="#RowsetSchema" xmlns:b="urn:schemas-microsoft-com:office:publisher" xmlns:ss="urn:schemas-microsoft-com:office:spreadsheet" xmlns:c="urn:schemas-microsoft-com:office:component:spreadsheet" xmlns:odc="urn:schemas-microsoft-com:office:odc" xmlns:oa="urn:schemas-microsoft-com:office:activation" xmlns:html="http://www.w3.org/TR/REC-html40" xmlns:q="http://schemas.xmlsoap.org/soap/envelope/" xmlns:rtc="http://microsoft.com/officenet/conferencing" xmlns:D="DAV:" xmlns:Repl="http://schemas.microsoft.com/repl/" xmlns:mt="http://schemas.microsoft.com/sharepoint/soap/meetings/" xmlns:x2="http://schemas.microsoft.com/office/excel/2003/xml" xmlns:ppda="http://www.passport.com/NameSpace.xsd" xmlns:ois="http://schemas.microsoft.com/sharepoint/soap/ois/" xmlns:dir="http://schemas.microsoft.com/sharepoint/soap/directory/" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:dsp="http://schemas.microsoft.com/sharepoint/dsp" xmlns:udc="http://schemas.microsoft.com/data/udc" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:sub="http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/" xmlns:ec="http://www.w3.org/2001/04/xmlenc#" xmlns:sp="http://schemas.microsoft.com/sharepoint/" xmlns:sps="http://schemas.microsoft.com/sharepoint/soap/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:udcs="http://schemas.microsoft.com/data/udc/soap" xmlns:udcxf="http://schemas.microsoft.com/data/udc/xmlfile" xmlns:udcp2p="http://schemas.microsoft.com/data/udc/parttopart" xmlns:wf="http://schemas.microsoft.com/sharepoint/soap/workflow/" xmlns:dsss="http://schemas.microsoft.com/office/2006/digsig-setup" xmlns:dssi="http://schemas.microsoft.com/office/2006/digsig" xmlns:mdssi="http://schemas.openxmlformats.org/package/2006/digital-signature" xmlns:mver="http://schemas.openxmlformats.org/markup-compatibility/2006" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns:mrels="http://schemas.openxmlformats.org/package/2006/relationships" xmlns:spwp="http://microsoft.com/sharepoint/webpartpages" xmlns:ex12t="http://schemas.microsoft.com/exchange/services/2006/types" xmlns:ex12m="http://schemas.microsoft.com/exchange/services/2006/messages" xmlns:pptsl="http://schemas.microsoft.com/sharepoint/soap/SlideLibrary/" xmlns:spsl="http://microsoft.com/webservices/SharePointPortalServer/PublishedLinksService" xmlns:Z="urn:schemas-microsoft-com:" xmlns:st="" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 12 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:SimSun;
        panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:Verdana;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
        {font-family:"\@SimSun";
        panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal;
        font-family:"Arial","sans-serif";
        color:windowtext;}
span.EmailStyle18
        {mso-style-type:personal;
        font-family:"Verdana","sans-serif";
        color:blue;
        font-weight:normal;
        font-style:normal;
        text-decoration:none none;}
span.EmailStyle19
        {mso-style-type:personal;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
span.EmailStyle20
        {mso-style-type:personal;
        font-family:"Arial","sans-serif";
        color:navy;}
span.EmailStyle21
        {mso-style-type:personal-reply;
        font-family:"Calibri","sans-serif";
        color:#1F497D;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page Section1
        {size:595.3pt 841.9pt;
        margin:72.0pt 90.0pt 72.0pt 90.0pt;}
div.Section1
        {page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=EN-GB link=blue vlink=purple>
<div class=Section1>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Of course not. I’m just pointing out how easy it is to
descramble an MD5 hash using your favourtie hacking util google.<o:p></o:p></span></p>
<p class=MsoNormal><span style='font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p> </o:p></span></p>
<div>
<div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm'>
<p class=MsoNormal style='margin-left:36.0pt'><b><span lang=EN-US
style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span
lang=EN-US style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>
xerte-bounces@lists.nottingham.ac.uk
[mailto:xerte-bounces@lists.nottingham.ac.uk] <b>On Behalf Of </b>Jeremy
Hopkins<br>
<b>Sent:</b> Friday, May 22, 2009 12:32 PM<br>
<b>To:</b> Xerte discussion list<br>
<b>Subject:</b> RE: [Xerte] Cannot Log In as Admin<o:p></o:p></span></p>
</div>
</div>
<p class=MsoNormal style='margin-left:36.0pt'><o:p> </o:p></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif";color:navy'>Hello Julian,<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif";color:navy'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif";color:navy'>Surely you are not advocating that
passwords are left in plain text?<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif";color:navy'>For the miniscule amount of effort
required to enable it, I think MD5 is better on than off. <o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif";color:navy'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif";color:navy'>Jeremy<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif";color:navy'><o:p> </o:p></span></p>
<div>
<div class=MsoNormal align=center style='margin-left:36.0pt;text-align:center'><span
lang=EN-US>
<hr size=2 width="100%" align=center>
</span></div>
<p class=MsoNormal style='margin-left:36.0pt'><b><span lang=EN-US
style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span
lang=EN-US style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>
xerte-bounces@lists.nottingham.ac.uk
[mailto:xerte-bounces@lists.nottingham.ac.uk] <b>On Behalf Of </b>Julian Tenney<br>
<b>Sent:</b> 22 May 2009 11:46<br>
<b>To:</b> Xerte discussion list<br>
<b>Subject:</b> RE: [Xerte] Cannot Log In as Admin</span><span lang=EN-US><o:p></o:p></span></p>
</div>
<p class=MsoNormal style='margin-left:36.0pt'><o:p> </o:p></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif"'>Here’s a password hashed in the one way
uncrackable MD5 algorithm:<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif"'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif"'>e6078b9b1aac915d11b9fd59791030bf<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif"'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif"'>Now, go and paste that into google and see
how long it takes you to work out the actual password…<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:11.0pt;
font-family:"Calibri","sans-serif";color:#1F497D'><o:p> </o:p></span></p>
<div>
<div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm'>
<p class=MsoNormal style='margin-left:72.0pt'><b><span lang=EN-US
style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span
lang=EN-US style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>
xerte-bounces@lists.nottingham.ac.uk
[mailto:xerte-bounces@lists.nottingham.ac.uk] <b>On Behalf Of </b>Patrick
Lockley<br>
<b>Sent:</b> Friday, May 22, 2009 11:41 AM<br>
<b>To:</b> Xerte discussion list<br>
<b>Subject:</b> RE: [Xerte] Cannot Log In as Admin<o:p></o:p></span></p>
</div>
</div>
<p class=MsoNormal style='margin-left:72.0pt'><o:p> </o:p></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'>Hello,<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'>Yes management.php, it is LDAP
free.<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'>If you go to your sitedetails
table, you can set the admin_username and admin_password. Assuming these are
set, and it sounds like they are – does it just say they aren’t correct. Mine
works fine – I think Johnathan’s works as well – pretty sure Ron’s works too.<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'>Re MD5 – yep, over sight on my
part – reasoning – we had a lot of people with 0.5 and 0.8 installs where there
was no admin role. When we moved to 0.9 and 1.0 originally we modded the
logindetails table to allow for a user role flag, but this would mean everyone
with an install modding their tables. Which seemed a hassle. So I put the admin
username into the sitedetails table at the last minute instead, and left it.<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'>You’re welcome to MD5 it
yourself though – you’d just need to put an un md5 command into config.php. <o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'>I’ll put it in the list for the
next version.<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'>Pat<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:72.0pt'><span style='font-size:10.0pt;
font-family:"Verdana","sans-serif";color:blue'><o:p> </o:p></span></p>
<div>
<div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm 0cm 0cm'>
<p class=MsoNormal style='margin-left:108.0pt'><b><span lang=EN-US
style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span
lang=EN-US style='font-size:10.0pt;font-family:"Tahoma","sans-serif"'>
xerte-bounces@lists.nottingham.ac.uk [mailto:xerte-bounces@lists.nottingham.ac.uk]
<b>On Behalf Of </b>Jeremy Hopkins<br>
<b>Sent:</b> 22 May 2009 11:32<br>
<b>To:</b> xerte@lists.nottingham.ac.uk<br>
<b>Subject:</b> [Xerte] Cannot Log In as Admin<o:p></o:p></span></p>
</div>
</div>
<p class=MsoNormal style='margin-left:108.0pt'><o:p> </o:p></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'>Hello All,<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'>I have installed the full version Xerte on a
linux virtual server. All seemed to go according to plan until I came to log
in.<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'>I cannot log in using the administrators
username and password. I have re-installed / checked fields in database etc and
it still will not allow me in.<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'>I have not got LDAP running yet, but am
assuming that LDAP is not required for the admin account, and that admin is
completely independent of the normal routines with the credential residing in
the sitedetails table? (would it not be better to MD5 the password in site
details?)<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'>Has anyone else experienced this problem?<o:p></o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p> </o:p></span></p>
<p class=MsoNormal style='margin-left:108.0pt'><span style='font-size:10.0pt;
font-family:"Arial","sans-serif"'>Thanks, Jeremy<o:p></o:p></span></p>
</div>
</body>
</html>