vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   Account locked? (https://vborg.vbsupport.ru/showthread.php?t=280796)

BirdOPrey5 04-09-2014 01:28 PM

You would follow the forgot password link to reset your password- but unless your password is absurdly easy, no one is getting it from this kind of attack.

Ladybbird 04-09-2014 03:13 PM

The Hacker came from China-


IP Location: China Beijing China Mobile Communications Corporation
ASN: China AS9808 CMNET-GD Guangdong Mobile Communication Co.Ltd.,CN (registered Jan 10, 2000)
IP Address:

& Trust me the Chinese are very good at hacking.
Note they have used a mobile device to hack vBulletin

A couple of years ago they even hacked Skype and used/stole all members log in details and money on their accounts. I had a heck of a fight trying to get my money back from Skype - Never happened, cos Skype simply wouldn't admit they had been hacked!

Even Google, Facebook etc have been hacked in the past. That's why I NEVER use any social media site

So don't blame vBulletin forum.

A little tip: NEVER use the same password on all or multi sites. Use your notepads and record your DIFFERENT log-in details for every site your use.....;)

I thank the staff at vBulletin, for their prompt action on this matter....:up:

OmniBuzz 04-09-2014 03:32 PM

Hi, I am having the same issue but for some reason, I cannot access https://vborg.vbsupport.ru/profile.php?do=editpassword page. Even when logged in it is still asking for my login / pwd ... when entered it does not log me in again...
I have not accessed this forum for a VERY long time and my pwd was no longer valid. I had to change it using the email reset system...

EDIT : That was an ie11 issue, I was able to access with FF...

rockerzteam 04-09-2014 04:32 PM

Dear rockerzteam,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address:

BirdOPrey5 04-09-2014 04:38 PM

It is not necessary to report this emails. We are aware of the situation. As long as you have a secure password you have nothing to worry about.

Posting the IP addresses is not going to help, but thank you for your effort.

ForceHSS 04-09-2014 05:01 PM

They never try my account :)

ego 04-09-2014 05:41 PM

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address:

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:

All the best,
vBulletin.org Forum

Many tries last 1hour please block these hackers

Chris8 04-09-2014 05:49 PM

Mine was locked 4 times during last 2 days.

ego 04-09-2014 06:01 PM

Thats not funny.
Please delete my account here. 20 mails in 1.5 hours

evelynpriscilla 04-09-2014 06:04 PM

From: "vBulletin.org Forum" <webmaster@vbulletin.org>
Date: 10 April, 2014 2:19:20 AM GMT+08:00
Subject: Account on vBulletin.org Forum locked out

Dear evelynpriscilla,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address:

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:
All the best,
vBulletin.org Forum

BirdOPrey5 04-09-2014 06:11 PM


Originally Posted by ego (Post 2492301)
Thats not funny.
Please delete my account here. 20 mails in 1.5 hours

We don't delete accounts.

If you don't want your account change your email address to some non-existent address/domain. You will stop getting the emails.

ForceHSS 04-09-2014 08:30 PM


Originally Posted by ego (Post 2492301)
Thats not funny.
Please delete my account here. 20 mails in 1.5 hours

Go to your options and change some settings so you dont get emails

billstelling 04-09-2014 09:01 PM

someone tried with my account as well today.. Flipping scammers..

Grae 04-09-2014 09:44 PM

I've received 5 in the last few minutes.

starman? 04-10-2014 02:20 AM

Just had someone from Brazil try it.

Nick Harris 04-10-2014 02:26 AM

Add me to the list of people who was locked out and received an email after 5 wrong attempts by someone else.

For me the IP was from China -

My pass is impossibly hard, even to remember, and it's not shared anywhere else so no worries. Thank you for keeping the 5 attempt lockout in the forums, all forums need it!

Sparrow-Sean 04-10-2014 02:48 AM

Me too:


Dear Sparrow-Sean,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address:

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:

All the best,
vBulletin.org Forum

Draygonia 04-10-2014 04:19 AM

These IPs have been attempting to log into my account. Thankfully my password is very secure, but this is alarming and makes me wonder whether this is website based or username based.

Appears to be using Mikrotik, a software that turns a PC into a router. Likely using infected computers to do the job.

hexonxonx 04-10-2014 07:23 AM

It's happened to me three times, all with different IPs. I changed my password to a much longer one. I did this through my iPad which asked me if I wanted it to suggest a password. I said yes and it entered a very nice and strong password.

Hoffi 04-10-2014 07:52 AM

The attempts to hack accounts raises. Please hurry to check the IP's.

BirdOPrey5 04-10-2014 07:59 AM


Originally Posted by Hoffi (Post 2492395)
The attempts to hack accounts raises. Please hurry to check the IP's.

There is no point to checking/blocking IPs. These IPs are of "Zombie" PCs- they are your friends/neighbors/random people who have been infected with viruses and are now running the commands of hackers. There are millions of them out there and there is no point to try to block them all- they are always changing.

The easiest thing to do is simply delete the emails and continue on with your life.

PS- You're never actually locked out- the lock follows the IP address not the username, so you would always be able to log in so long as the attack isn't coming from your IP address.

Jaydee 2 04-10-2014 08:04 AM

I agree! About 50 emails between 10.15 and 10.21! (German local time -> 08.15 UTC)


Originally Posted by ForceHSS (Post 2492288)
They never try my account :)

Am i to? :D

--------------- Added [DATE]1397121364[/DATE] at [TIME]1397121364[/TIME] ---------------


Originally Posted by BirdOPrey5 (Post 2492396)

The easiest thing to do is simply delete the emails and continue on with your life.

Hehe, first i read "[...] and continue on with your wife." :D

Electronic Punk 04-10-2014 09:02 AM

Hmm, also got this, account seems fine however.

pets.ca 04-10-2014 10:24 AM

I have gotten about 25 in the last 24 hours....

sburns1992 04-10-2014 11:05 AM

Yeah I keep getting loads, can I request a username change?

TheLastSuperman 04-10-2014 11:12 AM


Originally Posted by sburns1992 (Post 2492418)
Yeah I keep getting loads, can I request a username change?

Sure :cool: however I cannot do it for you, you will need to send a private message to an Administrator on the site, here is a list of Staff I suggest Lynne or Princeton as Paul is away currently.


BirdOPrey5 04-10-2014 11:19 AM


Originally Posted by sburns1992 (Post 2492418)
Yeah I keep getting loads, can I request a username change?

A username change likely won't do anything to stop the emails, in fact it will probably just make you get more as they will eventually stop with your account and move on to others.

Sascha Henken 04-10-2014 11:36 AM

I keep getting these emails several times a day. Seems a Bot Network is trying to hijacking forum accounts. I?ve managed to change my password to a more secure one!

Dear Sascha Henken,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address: XXX.XXX.XXX.XXX

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:

All the best,
vBulletin.org Forum

teou 04-10-2014 12:19 PM

Massive bruteforcing attack obviously. I have also received several emails. IP addresses of the attackers so far:

Is there any way to disable email notifications at least?

p.s. Suggestion to vbulletin staff: make an option to have one screen/post name and another login name. Thus the attackers will not be able to get login names from posts and will have to bruteforce them first.. and that will greately enhance security and will stop this email spam.

p.p.s. Similar suggestion here - https://vborg.vbsupport.ru/showthrea...=264376&page=2
Using emails for login (only email and not both mail or username as many sites do). Must be pretty easy to implement, 1-2 rows of php here and there?

BirdOPrey5 04-10-2014 12:38 PM

We are not going to be making massive changes to the software, we do apologize for the inconvenience.

Some people have reported that editing your options and seeing unchecking the option to Allow Administrators to Send You Email stops the account locked emails, but other people say it does not help- honestly I'm not sure if that setting was ever intended to stop such emails since they technically are being sent from the board itself, not an Administrator.

For those who no longer wish to have accounts go ahead and change your emails address on record in the settings to some random/undeliverable value.

jefferis 04-10-2014 01:39 PM

Continuing every day! FROM

ANGLICO 04-10-2014 02:30 PM

I would like to be able to block IP addresses that appear to originate from certain countries from trying to log into my account. Is there a way to do that? Perhaps an easier option would be to PERMIT only an IP address originating in the USA to log into my account.


Belay the previous, I just saw this:

Originally Posted by BirdOPrey5 (Post 2492396)
There is no point to checking/blocking IPs. These IPs are of "Zombie" PCs- they are your friends/neighbors/random people who have been infected with viruses and are now running the commands of hackers. There are millions of them out there and there is no point to try to block them all- they are always changing.

The easiest thing to do is simply delete the emails and continue on with your life.

PS- You're never actually locked out- the lock follows the IP address not the username, so you would always be able to log in so long as the attack isn't coming from your IP address.

Andem 04-10-2014 02:31 PM

zackw 04-10-2014 02:32 PM

I think the solution is simple, the forum should just stop sending these emails. Clearly, if the block is only IP based, then it doesn't affect your own login attempts, and since no harm is done, your account was always safe.

The only email I might want is perhaps something that says that a successful login took place, from a different IP that my last login.

All I need to know is if someone is changing my password or changing my email or even if they have logged in from an IP not normal for me. This could alert me to a compromised account.

These emails about lockouts don't seem to serve any purpose if the intention is NOT to block every single IP that comes through. I personally can't do jack with the emails, it's not like I can come here and do IP blocks myself. So this may be a case of TMI. Just stop emailing people about failed login attempts.

Is that hard?

BirdOPrey5 04-10-2014 02:52 PM


Originally Posted by zackw (Post 2492451)
I think the solution is simple, the forum should just stop sending these emails. Clearly, if the block is only IP based, then it doesn't affect your own login attempts, and since no harm is done, your account was always safe.

The only email I might want is perhaps something that says that a successful login took place, from a different IP that my last login.

All I need to know is if someone is changing my password or changing my email or even if they have logged in from an IP not normal for me. This could alert me to a compromised account.

These emails about lockouts don't seem to serve any purpose if the intention is NOT to block every single IP that comes through. I personally can't do jack with the emails, it's not like I can come here and do IP blocks myself. So this may be a case of TMI. Just stop emailing people about failed login attempts.

Is that hard?

This is certainly something we will consider in the future.

Antivirus 04-10-2014 03:40 PM

Yes - I've been getting the notifications as well. I just delete em, fortunately once the lock kicks in they seem to move on to another username until the following day - no biggie

carsafety 04-10-2014 03:42 PM

Ditto. Started a few days ago, happening a lot more today.

whitetigergrowl 04-10-2014 03:59 PM


Originally Posted by Antivirus (Post 2492464)
Yes - I've been getting the notifications as well. I just delete em, fortunately once the lock kicks in they seem to move on to another username until the following day - no biggie

No biggie until they eventually hack into your account and get your password. Anyone that says this is no biggie is seriously underestimating what is going on and potentially willing to compromise their account and information here and elsewhere.

I had 2 attempts on my account at the same time today. (8:09am)

Do not underestimate or downplay this. One IP is from Columbia and another from China in my case.

JetLee 04-10-2014 04:04 PM

I've had four attempts in the last few days.

What got me worrying is that someone also called my cell phone carrier trying to ascertain my home address. WTF? I've since put extra security measures in place with all utilities and banks as well as changing all forum passwords to something even more complicated than I was already using.

Lynne 04-10-2014 04:47 PM

You've already had replies from Staff. This happens every couple of months. If you have a secure password, then you have nothing to worry about. I have not been told of one person who actually has had their account hacked through one of these attacks.

All times are GMT. The time now is 05:47 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01766 seconds
  • Memory Usage 1,837KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (13)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (40)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete