Ruben, Gizmo & Yarp -- Thanks for the thoughts but they don't match what I'm seeing here. My personal account, for example, that I have used every day since at least 2002 (it turns out the first version of UBBThreads I installed for this board was 5.5.1 in April 2002) still has one of the shorter, older encoded versions of the password (until I changed it today & got an MD5 hash).
So from what I can tell:
1) The old crypt/hash/encoding is not automatically updated to a new system even if you use it every day and
2) It does not have to be either MD5 or a temporary password as the current version of UBBThreads still seems to be able to validate it.
So either there is some compatibility code with an older system or I'm missing something in how my board has been operating, or older boards have some legacy code hanging around that lets them do this even after upgrading.
Some type of salted crypt sounds pretty likely to me, but of course I'd need to know the specifics to validate individual encoded passwords.
Either way I have 4000 users and many of them are both active & have had accounts for a long time that I'd like to be able to preserve & validate going forward.
Hopefully Rick will have some info on how the passwords were encoded in UBBThreads 5.5.1.--David