Private Messages in the Miscellaneous forum at Todd and Tyler Unauthorized Forums - and delete the spam messages they have sent to people, So private messages really aren't 100% private?...

Members Panel
Go Back   Todd and Tyler Unauthorized Forums > Other Crap > Miscellaneous

Reply
Old 02-25-2008   #1
Bud
Wanna Bet???
Dave says I'm special!
Over 1000 posts!
 
Bud's Avatar
 
Listens: Z92 - Mornings
Join Date: Jul 2006
Location: Plattsmeth
Age: 38
Posts: 9,903
Private Messages

Quote:
and delete the spam messages they have sent to people,
So private messages really aren't 100% private?
__________________
Time is Short

Click Here, Free Naked Ladies

2007 TNTU.net Fantasy NASCAR Champion !!!

Bud is offline   Reply With Quote
Old 02-25-2008   #2
i ride the short bus because i'm
Dave says I'm special!
Over 1000 posts!
 
lilyvon schtupp's Avatar
 
Listens: I don't listen
Join Date: Feb 2006
Location: counciltucky
Posts: 1,280
Re: Private Messages

maybe he accessed their account and deleted it that way?
__________________
A man melts the sands so he can see the world outside.--U2, Lemon
lilyvon schtupp is offline   Reply With Quote
Old 02-25-2008   #3
Straight Pimpin
Really don't mess with this person!
 
Dave's Avatar
 
Listens: Z92 - Mornings
Join Date: Jun 2004
Age: 38
Posts: 4,992
Send a message via MSN to Dave
Re: Private Messages

Quote:
So private messages really aren't 100% private?
Actually, private messages are stored in the database just like posts, so if I was interested in reading them I could. I think I've made that point before. It does take a little work though I think to match up recipient id's and sender id's to a message.

In this case however, I took care of problem by running a database query on the "pm_text" and "pm" tables to say "DELETE from <the table> WHERE fromuserid = 3645". 3645 is the userid for "Jeannette". I didn't have to browse through the private message table one by one, looking for spam messages.

Its a good question, and one that I've tried to address in the past. Yes, anybody that has access to the database your forum is using can read private messages. Obviously, its a frowned upon practice.

To curb the practice, and make them "more private", you can make sure that you delete your "sent" message as soon as you send it, and make sure that the recipient also delete's the message after reading it. Once the message is deleted by the sender and the recipient, it isn't saved anywhere in the database.

On this site, I'm the only administrator, and the only person with access to the database. In a normal vB environment, members assigned "administrator" status can only see the total number of private messages a person has. You need a different kind of access (via the database) to actually view the messages.
__________________
"Perverting the court of justice"
--------------------------------------------
Todd and Tyler Streaming
Questions, comments, concerns?
Contact the Empire

Last edited by Dave; 02-25-2008 at 10:08 PM.
Dave is offline   Reply With Quote
Old 02-26-2008   #4
TnTU College
 
harmany's Avatar
 
Listens: Z92 - Mornings
Join Date: Feb 2006
Location: papillion ne
Age: 25
Posts: 505
Re: Private Messages

oh dave i love when you talk geek
__________________
BIG XII NORTH CHAMPIONS
GO TIGERS!!!
harmany is offline   Reply With Quote
Old 02-26-2008   #5
Bud
Wanna Bet???
Dave says I'm special!
Over 1000 posts!
 
Bud's Avatar
 
Listens: Z92 - Mornings
Join Date: Jul 2006
Location: Plattsmeth
Age: 38
Posts: 9,903
Re: Private Messages

Thanks Dave.

Quote:
It does take a little work though I think to match up recipient id's and sender id's to a message.
Unless you know Floris.
__________________
Time is Short

Click Here, Free Naked Ladies

2007 TNTU.net Fantasy NASCAR Champion !!!

Bud is offline   Reply With Quote
Old 02-26-2008   #6
Straight Pimpin
Really don't mess with this person!
 
Dave's Avatar
 
Listens: Z92 - Mornings
Join Date: Jun 2004
Age: 38
Posts: 4,992
Send a message via MSN to Dave
Re: Private Messages

Quote:
Unless you know Floris.
I don't know what that means. Floris from vb.com?
__________________
"Perverting the court of justice"
--------------------------------------------
Todd and Tyler Streaming
Questions, comments, concerns?
Contact the Empire
Dave is offline   Reply With Quote
Old 02-26-2008   #7
Bud
Wanna Bet???
Dave says I'm special!
Over 1000 posts!
 
Bud's Avatar
 
Listens: Z92 - Mornings
Join Date: Jul 2006
Location: Plattsmeth
Age: 38
Posts: 9,903
Re: Private Messages

Or Dream.

Floris and Dream both have add ons to vbulletin that make it very simple and easy to read PM's of anybody.

Super Admins can Read Private Messages - vBulletin.org Forum

Read PMs - vBulletin.org Forum


I am in no way implying that our admin is reading our PM's, I would like to think that our admin is above that, only that PM's are not as "private" as you may think. Regardless of the site you are on.

I'm only showing this so that you can cover your ass, especially in todays world.

Quote:
To curb the practice, and make them "more private", you can make sure that you delete your "sent" message as soon as you send it, and make sure that the recipient also delete's the message after reading it. Once the message is deleted by the sender and the recipient, it isn't saved anywhere in the database.
I'm not sold on this either. I always delete my PM's. And on more than one site, this one included, I have experienced a board having to goto a backup due to a software problem or who knows what. Anyways I've had deleted PM's show back up.

So don't go telling stories of how you killed your mother-in-law and buried her in the neighbors back yard in PM's.
__________________
Time is Short

Click Here, Free Naked Ladies

2007 TNTU.net Fantasy NASCAR Champion !!!

Bud is offline   Reply With Quote
Old 02-26-2008   #8
ob1
Sith Chef
Dave says I'm special!
Over 1000 posts!
 
ob1's Avatar
 
Listens: Z92 - Mornings
Join Date: May 2005
Location: CBIA
Age: 38
Posts: 5,813
Re: Private Messages

Dave, I think you have addresssed the issue with more disclosure and better ethics then what I have been involved with in the past with other boards. Thanks for being direct.

PM's are private only in the sense that they cannot be read publicly by the members of the site.
ob1 is offline   Reply With Quote
Old 02-26-2008   #9
Bud
Wanna Bet???
Dave says I'm special!
Over 1000 posts!
 
Bud's Avatar
 
Listens: Z92 - Mornings
Join Date: Jul 2006
Location: Plattsmeth
Age: 38
Posts: 9,903
Re: Private Messages

Quote:
Dave, I think you have addresssed the issue with more disclosure and better ethics then what I have been involved with in the past with other boards.
Ditto. If it wasn't for Dave sparking my interest I would still have a false sense of security.

I guess no more dealing Pugs on the black market via PM's.
__________________
Time is Short

Click Here, Free Naked Ladies

2007 TNTU.net Fantasy NASCAR Champion !!!

Bud is offline   Reply With Quote
Old 02-26-2008   #10
Straight Pimpin
Really don't mess with this person!
 
Dave's Avatar
 
Listens: Z92 - Mornings
Join Date: Jun 2004
Age: 38
Posts: 4,992
Send a message via MSN to Dave
Re: Private Messages

Yes, I agree, I don't mind talking about security and access. A lot of boards/sites don't even mention who their admins or mods are, so I always try to make it a point that I'm the only one with that access.

If your ever curious about a vbulletin site, the "admins can read PM's" hack is easy to spot if you're thinking about joining a vB message board. If you visit the site's forum, and try to go to this url:
http://thesite.com/theforumurl/admincp/pm.php

Iff you see an administration log in page, then the hack is installed, if you get a "page not found" message, or are redirected to the site's home page, the hack isn't installed. You can use this whether you're a registered member to the forum or not.
__________________
"Perverting the court of justice"
--------------------------------------------
Todd and Tyler Streaming
Questions, comments, concerns?
Contact the Empire
Dave is offline   Reply With Quote
Old 02-26-2008   #11
ob1
Sith Chef
Dave says I'm special!
Over 1000 posts!
 
ob1's Avatar
 
Listens: Z92 - Mornings
Join Date: May 2005
Location: CBIA
Age: 38
Posts: 5,813
Re: Private Messages

Thanks for the insite Big Guy!
ob1 is offline   Reply With Quote
Old 02-26-2008   #12
Bud
Wanna Bet???
Dave says I'm special!
Over 1000 posts!
 
Bud's Avatar
 
Listens: Z92 - Mornings
Join Date: Jul 2006
Location: Plattsmeth
Age: 38
Posts: 9,903
Re: Private Messages

Quote:
Originally Posted by Dave View Post
If your ever curious about a vbulletin site, the "admins can read PM's" hack is easy to spot if you're thinking about joining a vB message board. If you visit the site's forum, and try to go to this url:
http://thesite.com/theforumurl/admincp/pm.php

Iff you see an administration log in page, then the hack is installed, if you get a "page not found" message, or are redirected to the site's home page, the hack isn't installed. You can use this whether you're a registered member to the forum or not.
Good trick.

But doesn't the other one hide in the regular control panel?
__________________
Time is Short

Click Here, Free Naked Ladies

2007 TNTU.net Fantasy NASCAR Champion !!!

Bud is offline   Reply With Quote
Old 02-26-2008   #13
Straight Pimpin
Really don't mess with this person!
 
Dave's Avatar
 
Listens: Z92 - Mornings
Join Date: Jun 2004
Age: 38
Posts: 4,992
Send a message via MSN to Dave
Re: Private Messages

Yes, but the other one puts a file called "read_pms.php" in the admincp folder, so to check for both hacks, look for a "pm.php" and "read_pms.php" in the "admincp" folder of the vBulletin installation on the site.

Code:
http://thesite.com/theforumurl/admincp/pm.php
http://thesite.com/theforumurl/admincp/read_pms.php
__________________
"Perverting the court of justice"
--------------------------------------------
Todd and Tyler Streaming
Questions, comments, concerns?
Contact the Empire
Dave is offline   Reply With Quote
Old 02-28-2008   #14
i ride the short bus because i'm
Dave says I'm special!
Over 1000 posts!
 
lilyvon schtupp's Avatar
 
Listens: I don't listen
Join Date: Feb 2006
Location: counciltucky
Posts: 1,280
Re: Private Messages

i'd let dave look at my private(s) messages any day
__________________
A man melts the sands so he can see the world outside.--U2, Lemon
lilyvon schtupp is offline   Reply With Quote
Sponsored Links
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

All times are GMT -5. The time now is 12:26 AM.
Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC5
Template-Modifications by TMS
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
Rules & Privacy


Hipster Blog | Flights | Car Finance | World Websites 2006 | Problem Mortgage

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37