Sessions are not saved. Cookies
Update # 1: I did not work with vBullettin, but it looks like the classic Remember Me feature.
Update # 2:
Yes, this is a catchy feature, I'm asking why they do it this way
Good ... How do you implement the Remember Me feature? Obviously you need to use cookies, I assume this is clear. Now what do you keep?
The most naive way is to save the user and password in clear text and perform basic authentication. This is one of the most insecure mechanisms you can use, but some sites actually do it that way.
The second slightly less naive way is to save the user hash and password and perform a modified version of basic authentication. Not as bad as the previous method, but it still suffers from some problems; for example, there is no effective way to disable or expire a stored cookie from a server.
The third way is to save the database table with “remembered” sessions, identify each of them with a long unique string and save such a string in a cookie. A string can be random or calculated, but, of course, randomness has the advantage that the string cannot be guessed even if you know the algorithm.
Further security can be achieved by storing dates, IP addresses and other pieces of data on the server.
As I said, I don't know anything about vBulleting, but it seems like they are using method 2 or method 3.
Update # 3:
The content of these cookies is what I think they contain. I'm not sure about that. Of course, if you call the cookie ngivbpassword and contains a hash, my Guess is hashedpassword. It could probably be password + salt. [...] My main concern is this decision to a lot of information when under the attack of swapping cookies.
Successful cookie merging allows you to completely personalize the user so you can simply log in to the control panel and enjoy a free buffet, which rendered the cookie content irrelevant.
Will they keep a salty password or is it just a name that I don’t know.