Jack Cook7 said:Well, not exactly, because passwords aren't actually stored in the database in their original plain-text form; they're hashed using MD5 or SHA1/128/256 or whatever else.
So, even if you somehow manage to get your hands on the password database, you wouldn't be able to just log in using those strings. That’s literally what hashing is designed to prevent.
To be honest, MD5 is about as secure as a screen door on a submarine, and while the SHA algorithms are a step up depending on which version you're looking at, by today's modern standards, none of them are really adequate for actual protection.
I'm not entirely sure what specific stack this particular forum is running, but back in the day, vBulletin used to rely on double MD5—where you hash the password, add a salt, and then hash it all over again. While that does technically kill off pre-calculated attacks, it doesn't actually provide a massive leap in security compared to just using basic MD5 plus a salt. I don't know if they migrated to something more robust later on, but whenever I hear someone on a support desk claiming that double MD5 is significantly more secure than standard salted MD5, it immediately sets off red flags for me. It feels like tech-babble meant to soothe people who don't know better.
Furthermore, we have to consider that SQL injection attacks don't necessarily require someone to read a password to be successful. If an attacker can extract enough information to forge a "remember me" cookie, they can bypass the login process entirely without ever needing to touch a single password string.
In some poorly architected systems, it might even be possible to change a password through such a vulnerability, though the downside there is that the user usually realizes they've been compromised once they find themselves locked out of their own account.
There's also the issue of other potential attack vectors, like advertisements. If they aren't implemented correctly—and I've personally dealt with a few incidents on various US message boards where ads caused malicious redirects because they weren't properly sandboxed—they can end up having access to data they should never have been touching in the first place.