vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   People are trying to brute force my account (https://vborg.vbsupport.ru/showthread.php?t=294547)

Bluemax712 02-03-2013 12:33 PM

deleted

Big Al 02-03-2013 12:34 PM

Quote:

Originally Posted by Simon Lloyd (Post 2401565)

:)

There are many hackers and scammers that sell what we call " Dumps"

Just as there are email harvesters, so it is for many other places they want to get into.

Hackers in some of the countries that are not so rigid on cybercrime, run websites that advertise such things. I am chasing a guy in India who is actively running some of these websites, that sell programs for harvesting.

Below, chosen at random is part of one of these Dumps. This particular guy is from Nigeria.

Quote:

I am a working boy wey dey run shows for guys online concerning Bobming of mails
Cpanel cloning,bank transfers TRojans to hack PCS & Paypal transfer to any
of your client acount

CONTACT ME ON xxxxx

CeesT 02-03-2013 01:19 PM

Last night I also received 38 mails of failed login attempts.

But why are there 38 mails within a period of 2 minutes ???

After the first attempt, the mail is send and then the next 15 minutes no logins should be possible for my account. But it seems that you can immediately try to login again if you use a different IP adress as the attempts came from different ip's.

Is this normal behaviour or is this a bug in this version of vbulletin (3.6.12) ??

cellarius 02-03-2013 01:33 PM

Quote:

Originally Posted by Simon Lloyd (Post 2401565)

Even without that it's not hard to harvest vB usernames.

Anyway, my account is under attack, too, but I wish them luck with my 20 digit random password including caps, lowercase, digits and special chars. :D

Else, I totally agree with digital jedi - the software is doing its job, it locks out the bots and sends out notifications. All nice and dandy, nothing staff could do about that, really.

Paul M 02-03-2013 02:27 PM

Quote:

Originally Posted by CeesT (Post 2401576)
Last night I also received 38 mails of failed login attempts.

But why are there 38 mails within a period of 2 minutes ???

We process e-mails in batches, plus as far as remember, attempts from a different IP address will trigger a seperate e-mail.

Its obvious its targeting each username from a wide range of IPs. If you have no interest in the e-mails, simply delete them.

Chase 02-03-2013 02:42 PM

I really like vb.orgs email notification saying someone has been trying to log into your account.

How can I implement this on my forum? I find this very useful.

CeesT 02-03-2013 02:47 PM

Quote:

Originally Posted by Paul M (Post 2401593)
We process e-mails in batches, plus as far as remember, attempts from a different IP address will trigger a seperate e-mail.

Its obvious its targeting each username from a wide range of IPs. If you have no interest in the e-mails, simply delete them.

I have no problems with the mails, I was just surprised that the 'locked' account is unlocked directly when the request comes from another ip. I did not know that before.
I have just tested it with one of my forums (3.8.7) and indeed the same happens. When I try to login from another ip, I have 5 more possibilities to use bruteforce hacking.

Perhaps it would be better to lock the account for 15 minutes without checking if the ip has changed. The successrate for a hacker is minimized then and a forum member normally will not change IP if he has typed the wrong password.

The only disadvantage of this is that some joker could stop a real member from logging-in if he continues to do this. So maybe that's the reason for unlocking from a new ip.

Lynne 02-03-2013 04:50 PM

Quote:

Originally Posted by Chase (Post 2401602)
I really like vb.orgs email notification saying someone has been trying to log into your account.

How can I implement this on my forum? I find this very useful.

AdminCP > Settings > Options > General Settings > Use Login "Stikes" System > Yes

CableSux 02-03-2013 08:47 PM

Quote:

Originally Posted by Lynne (Post 2401620)
AdminCP > Settings > Options > General Settings > Use Login "Stikes" System > Yes

Thanks, that works for the user, but I'd like the admin to get a copy of that e-mail, too. Anyone know a way to make that happen?

BigAl205 02-03-2013 10:27 PM

Quote:

Originally Posted by Simon Lloyd (Post 2401565)

I meant to ask how non-members are getting to the members list. I'm assuming that a member is aggregating the list. Is there any way to pull up members within the offending IP range and verify their intent or restrict their permissions?


All times are GMT. The time now is 12:49 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01122 seconds
  • Memory Usage 1,745KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (8)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete