QUOTE(RobertMidd @ Jul 11 2006, 03:47 PM)

How does getting the pass_hash of Admin gain access to the ACP ... the pass_hash canot be decoded to the actual password. If they are gaining access to the ACP then they must know the password or be using brute force.
actually I don't know how they got access to Admin CP.
but I do know that they got pass_hash of member(also converge_pass_hash and converge_salt), then gained acces to admin CP, added new attachement type: .phtml and uploaded some script to upload folder.
so by hacking into admin cp (other question is how) - hacker can get access to whole site (and with wrong server's security - to whole server).
also, for example there is such situation:
we have site of programmers, who share .php files via Forum.
How administrator can do it without using mods ?

(Yes I know how, but still, administrators should not worry about "to enable this feature, you have to know/do this, this and this)