Hey guys,
Recently one of my admins passwords was "exposed" lol, and a user was able to get into the admin panel, I have had secures now, only letting certain ip's into the admin.php but I noticed the lack of any kind of logs. So not sure what they did, but i know the user was able to edit the templates and add in his own little password logger, log all the passwords without me even noticing, then gain access to the super admins info and just cause more trouble. If he didn't TELL me (being a cocky basterd), it would have been such a trouble to track down, where the security hole was. Without logs I feel a admin could do anything and you would have no proof of who actuality did it, and general protection. I used vbulletins logs almost once a week, making sure no one was doing anything screwy tweaking post counts, baning or unbanning users. Logs are very important I hope they are hidden somewhere were I cant seem them.
Vbulletins extensive logging was some what over done but it really a feature that is needed for protection and just general monitoring of staff.