![]() |
vBSecurity v1.1.8
New Features: Login Strikes Viewer
Fillip |
vBSecurity v1.1.8 Patch Level 2
Bug Fixes:
Fillip |
For some reason, real users/visitors get IP banned when using this mod even though there were no signs of brute force login from them. I have cases when visitors got IP banned by trying to login to accounts that don't even exist in my forum database.
|
Quote:
I have just upgraded to 1.2.1 and several users are reporting that they get locked out when updating their profile to "Enable IP Verification". As an Admin I also did not receive the verification email when accessing the adminCP for the first time after installation, but I was able to gain access with a quick query. Is there a way to resend or view the email queue? Or authorize their IP through the adminCP? |
vBSecurity v1.2.1
New Features: IP Verification: Front-End
IP Access Log
IP Access Log: Search New IPs
IP Access Log: Multiple Account Access IPs
Changes To Existing Features:
Fillip |
vBSecurity v2.0.0
New Features: (Pro) New Security Watcher: "Failed Logins: Non-Existent Usernames"
(Pro) New Security Watcher: "Failed Mass Logins: Non-Existent Usernames"
(Pro) Compromised Accounts Detection
(Pro) IP Ban Log Viewer
Multiple Watcher Actions
Log Pruning
Changes To Existing Features: Security Watcher Log
Fillip |
Quote:
1) So will this mod prevent prevent that? ---- 2) Can this Mod notify mods/admins by posting in a specific forum section (via designated userID selected by the admin), when multiple accounts are being logged into by the same IP address? 3) Can this Mod notify mods/admins by posting in a specific forum section (via designated userID selected by the admin), when one account is being logged into by the multiple IP address? 4) Can this Mod notify mods/admins by posting in a specific forum section (via designated userID selected by the admin), when multiple accounts are being logged into on the same computer (cookies/cache detection)? 5) Can this Mod notify mods/admins by posting in a specific forum section (via designated userID selected by the admin), when one account is being logged into by the multiple computers (cookies/cache detection)? |
Quote:
Quote:
All alerts go to the Webmaster Email account as well :) Fillip |
vBSecurity v2.1.0
New Features: IP Verification
Admin IP Verification: Re-Send Emails
User IP Verification: Re-Send Emails
Security Watcher Display
(Pro) User IP Verification: Admin Control
(Pro) IP Address Search: Country Display
(Pro) IP Host Lookup: Country Display
(Pro) IP Address Search: IP Usage
(Pro) Compromised Accounts Log
(Pro) Watcher log
(Pro) User IP Verification log
(Pro) Admin IP Verification log
Changes To Existing Features:
Bug Fixes:
Fillip |
Excellent! Thanks for the quick development.
|
Brilliant update.
I might buy the PRO version in the future. |
vBSecurity v2.1.0 Patch Level 3
Bug Fixes:
Fillip |
vBSecurity v2.1.0 Patch Level 4
Bug Fixes:
Fillip |
vBSecurity v2.2.0
New Features: Global IP Address Whitelist
Fillip |
Changed Features:
Fillip |
vBSecurity v2.2.2
New Features: "Failed Logons" Watcher
Changed Features:
Bug Fixes:
Fillip |
vBSecurity v2.2.3
New Features: CLI Maintenance Script
Search IP Addresses: Find Potential Intruder IP Addresses
Bug Fixes:
vBSecurity v2.2.4 Changed Features: Password Reset
Fillip |
I can´t loging with my account on dragonbyte-tech.com
My password is. expired I recive the email : New Account Access From xxx.xxx.xxx.xxx If you recognise this IP address and would like to add it to the whitelist, please click here but when i click the link nothing will be happen. It is the same ...... i can´t edit my password |
Quote:
Fillip |
I think I found a bug or conflict in version 2.2.4 lite
If a user tries to reset their lost password, they get the email from VB and click the link. But when clicked, it gives either a blank white page or sometimes an error 500. If I disable this script, everything works well again. I can reproduce this reliably by enabling or disabling version 2.2.4 My info: VB 4.2.3 pl2 Server Litespeed PHP 5.5.38 MySQL 10.0.25-MariaDB-cll-lve If you need anything else to help fix it, let me know. Thanks Mike |
You will need to check your error log for the real reason behind a 500 Internal Server Error.
Fillip |
I have similar problem. User can't reset password. Error message was displayed after clik on reset link.
Quote:
|
I had to disable it didnt have time to debug this time, but will re install next version.
|
Quote:
Fillip |
vBSecurity v3.3.0:
Feature: New option: Enable Account Breach Check Feature: New option: Account Breach Check: Check Username This mod has been updated to be brought in line with the XenForo version. Fillip |
I updated this today (overwriting the old install) without realizing that I needed PHP Ver 5.6. I have PHP 5.3.29. Can I get the latest version that works with 5.3.29 please?
Thanks. |
I'm really impressed with some of the features in the new version of this modification. Thanks for all the good work.
I notice you included instructions for using bcrypt for passwords. Do those instructions re-encrypt the entire password database? This is a huge issue that I've been concerned about for some time. I also would like to ask the impact of forum upgrades - so if you deploy it in 4.2.5 and then upgrade to 4.2.6, do you need to make those changes again? |
Quote:
Fillip |
The download package has been updated to address a minor security vulnerability that could allow an attacker to inject code for their own user only (not other users) when viewing their currently active login sessions.
This vulnerability cannot be used to exploit your forum, this is not a critical vulnerability. Fillip |
If I do a mass password reset for all of my users, will they get an email saying that their password was reset? If so, can I customize that email?
Thanks |
All times are GMT. The time now is 11:47 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|