vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin.org Site Feedback (https://vborg.vbsupport.ru/forumdisplay.php?f=7)
-   -   Account locked? (https://vborg.vbsupport.ru/showthread.php?t=280796)

weave 04-11-2014 02:21 PM

You can always uncheck the box (userCP) to stop getting emails from the admin....or change your email address to some bogus one.

doogie88 04-11-2014 03:11 PM

Glad I'm not the only one.

Valter 04-11-2014 03:14 PM

Same here.

smacklan 04-11-2014 03:38 PM

Quote:

Originally Posted by BirdOPrey5 (Post 2492628)
No one is locked out. Even when they get the emails, they aren't locked out. The lock only applies to the IP address causing the problem, so unless their own computer is part of the attack they can always access their account.

Not true. After 5 invalid attempts, the account is locked out for 15 minutes even for the valid passcode.

More wrong info from certain staff members...like in the now closed recent "delete my account" threads here, users were instructed to uncheck receive site admin emails to stop getting these notifications which does not work for account locked due to 5 invalid login attempts. I have had all of those email options unchecked on my account here for years and still get mailings on my account. vB 3.6.12...lovely piece of software to be still running on an official vB company forum in 2014. :rolleyes:

eatworksleepdie 04-11-2014 03:46 PM

I am getting the messages too. I got 8 last night. several additional emails over the last few days. I've changed my password from super-tough, to super-duper-tough..

any fix for this besides a workaround to not get admin emails? that seems like a bad idea.

BirdOPrey5 04-11-2014 04:37 PM

Quote:

Originally Posted by smacklan (Post 2492683)
Not true. After 5 invalid attempts, the account is locked out for 15 minutes even for the valid passcode.

I'm absolutely not wrong. The "lock" is only on the IP address causing the problem. If I try to log in to your account from my computer it only blocks me from logging in, not you. I've tested it myself.

nochkin 04-11-2014 05:27 PM

Quote:

Originally Posted by smacklan (Post 2492683)
Not true. After 5 invalid attempts, the account is locked out for 15 minutes even for the valid passcode.

It works exactly as BirdOPrey5 mentioned: the lock is per IP, not per username.

Kat-2 04-11-2014 05:34 PM

I figured that was what was going on again. I was hit this time. Didn't make it in though. :)

MrHorror 04-11-2014 06:51 PM

I got the email warnings as well. They failed to get into my account though.

Digital Jedi 04-11-2014 10:06 PM

1 Attachment(s)
Quote:

Originally Posted by whitetigergrowl (Post 2492494)
It may happen every few months, but it doesn't make it any less serious. Maybe there is something the site can do to help prevent or minimize further attacks? I'm sure there are a number of things that can be done.

Vbulletin.org is the only site I have had this happen at. While its possible or likely it may have happened at others and I never knew about it, its still not reassuring IMO.

vB.org is the only site that's informed you that it's happened. There's a difference. And it's the biggest, brightest point we're trying to make. The "thing being done about it" has already been done. It's just, this time, you were informed. Not all websites will tell you unless the attempt was successful. And even then...


Quote:

Originally Posted by USAMustangs.com (Post 2492534)
Come on vb.org, this is absolutely ridiculous. What's the issue here and what have you done to address it?

Quote:

Originally Posted by sb225 (Post 2492558)
I am too getting a lot of emails from the past, that some one is trying to loginto my account, can you keep my account in safe place.

Come on guys, read the last few posts.

If the guy below me posts without reading the last few posts again, I'm going to drop a spork on his head.

weave 04-11-2014 11:43 PM

Quote:

Originally Posted by Digital Jedi (Post 2492740)
If the guy below me posts without reading the last few posts again, I'm going to drop a spork on his head.

I have learned that, while reading is the most fundamental skill we all are supposed to have, it is the one most often never used....

camoit 04-12-2014 12:32 AM

2 for me today and one from the other day. Someone should block the IP's

The person trying to log into your account had the following IP address: 223.84.180.232
China
The person trying to log into your account had the following IP address: 178.22.51.220
Russian Federation
The person trying to log into your account had the following IP address: 183.223.163.214
China

I blocked them from my site

Atakan KOC 04-12-2014 05:05 PM

Quote:

Account on vBulletin.org Forum locked out

Dear Atakan KOC,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address: 190.99.64.5

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:
https://vborg.vbsupport.ru/login.php?do=lostpw

All the best,
vBulletin.org Forum‏
What is happening?

TheLastSuperman 04-12-2014 06:22 PM

Quote:

Originally Posted by Atakan KOC (Post 2492833)
What is happening?

Someone is trying to login to your account, since they failed the system notified you.
https://vborg.vbsupport.ru/showpost....7&postcount=93
  • You are not blocked for 15 minutes UNLESS your IP is the same as that listed in the emails so no fret.
  • We are not making changes to the site, it is functioning as-intended and you're being notified properly which is what it was designed to do, it was not designed however to cause mass panic and should not be misconstrued as such either.
  • You can change your email address on file and make changes to your account to stop these emails.
  • This happens on many sites daily not just vBulletin.org, it is a common spam/hacking technique, of course they want to know your username and password please Google the term "Social Engineering" to learn more.

Zachery 04-12-2014 06:22 PM

People are trying to brute force accounts, If you took 10 seconds to read the topic, or other topics, you'd know this.

BirdOPrey5 04-12-2014 09:10 PM

This is a pretty interesting list of the 10,000 most common passwords...

Suffice to say if your password is on this list you should change it... If it's in the top 100 you really need to change it.

https://xato.net/passwords/more-top-.../#.U0mvURBZ3of

darnoldy 04-13-2014 01:00 AM

I especially like how michael and jennifer were in the top 20. I wonder if the're dating.

Max Taxable 04-13-2014 01:28 AM

Cool site for checking the strength of your password... This is what I got for mine:

Quote:

It would take a desktop PC about 55 trillion years to crack your password.
https://howsecureismypassword.net/

Knightmane 04-13-2014 04:50 AM

When I see a strange IP address included in an email from vb.org, I run the IP address through http://network-tools.com/ to find out what country the attempt came from.

I got several emails this week regarding the attempted logins and most of the IP addresses came from either Asia, China, or India. Just letting you know.

setishock 04-13-2014 12:37 PM

I finally got "The Email". Da Da Daaaaaaaaa
Curious though, (Cue creepy organ music) what are they really after? There's no credit card info here. Even if there was and they got my numbers, it's only got 5 bucks on it. Don't spend it all in one place...

BirdOPrey5 04-13-2014 12:49 PM

Quote:

Originally Posted by setishock (Post 2492964)
I finally got "The Email". Da Da Daaaaaaaaa
Curious though, (Cue creepy organ music) what are they really after? There's no credit card info here. Even if there was and they got my numbers, it's only got 5 bucks on it. Don't spend it all in one place...

My guess is one of the following-

1) Spam
2) Licensed account to download all modification for pirate use / trade with other pirates
3) Looking for members who may use the same password here as on their own websites or vb.com- but it would still take effort to figure out their forums or accounts unless they posted links or had links in the signature or in the homepage link in user cp.

setishock 04-13-2014 12:55 PM

Interesting. Thanks.

Max Taxable 04-13-2014 05:03 PM

Quote:

Originally Posted by Knightmane (Post 2492916)
When I see a strange IP address included in an email from vb.org, I run the IP address through http://network-tools.com/ to find out what country the attempt came from.

I got several emails this week regarding the attempted logins and most of the IP addresses came from either Asia, China, or India. Just letting you know.

It's not even relevant really anymore, where a given IP might resolve to - since they're so easy to spoof now.

Max Taxable 04-13-2014 05:05 PM

Quote:

Originally Posted by BirdOPrey5 (Post 2492966)
My guess is one of the following-

1) Spam
2) Licensed account to download all modification for pirate use / trade with other pirates
3) Looking for members who may use the same password here as on their own websites or vb.com- but it would still take effort to figure out their forums or accounts unless they posted links or had links in the signature or in the homepage link in user cp.

And I would bet the bolded is the biggest one.

It's why when I see accounts posting that were long dormant until the posts, I get suspicious.

JeffyJoe 04-13-2014 09:30 PM

Quote:

Originally Posted by Max Taxable (Post 2493008)
It's why when I see accounts posting that were long dormant until the posts, I get suspicious.

im one of those max
i have not logged in here for a few years now, and got flooded with emails recently saying locked out bad pass attempt..
i just changed my pass and checked my username for new posts, a few mins ago and there were none, so all is good

:-)

Max Taxable 04-13-2014 10:08 PM

Quote:

Originally Posted by JeffyJoe (Post 2493045)
im one of those max
i have not logged in here for a few years now, and got flooded with emails recently saying locked out bad pass attempt..
i just changed my pass and checked my username for new posts, a few mins ago and there were none, so all is good

:-)

I don't get suspicious when I see dormant accounts reply to threads such as this, or create threads such as this. It's expected, happens every time there is a brute force attack.

It's some time after, when you'll see a few long dormant accounts here and there, posting weird stuff and making strange requests.

You and several others though ARE proof that email prompting does work for getting the activity up! :D

Paul M 04-14-2014 03:04 AM

Quote:

Originally Posted by Atakan KOC (Post 2492833)
What is happening?

The world is ending, apparently :erm:


(it could at least wait until my holiday is over)

setishock 04-15-2014 12:41 PM

Or until the rain quits so I could fly my quads and hex one more time.

adom7 04-19-2014 06:15 PM

Its happening to me as well.
I've had 100 emails since morning. IP location shows all from China

The person trying to log into your account had the following IP address: 117.174.231.191
The person trying to log into your account had the following IP address: 183.220.197.192

I think that it is a bot or something and its gonna find my password soon :eek: :down:

Paul M 04-20-2014 02:05 AM

Quote:

Originally Posted by BigJimTheLug (Post 2493876)
For some reason, vbulletin.org's default password creating algorithm only creates passwords with numbers.

Ummm, not sure what are you referring to here ?

camoit 04-21-2014 12:31 AM

I wish there was a way to collect just the IP addresses everyone has been posting up with out going through the hole post. This way I can drop them in my ban list.
Even though I have some 267,495 IP banned already mostly from China, venezuela, and the Russian federation just from using the stop forum spam list. If I get a spammer or a hacker report from a member I ban the address range by the C string. 111.222.333.*** Then I use the stop forum spam db to see all the nearby addresses and drop them in just for fun. I haven't had any spammers or hackers get through in months since I started doing that.

BirdOPrey5 04-21-2014 10:09 AM

Quote:

Originally Posted by camoit (Post 2493973)
I wish there was a way to collect just the IP addresses everyone has been posting up with out going through the hole post. This way I can drop them in my ban list.
Even though I have some 267,495 IP banned already mostly from China, venezuela, and the Russian federation just from using the stop forum spam list. If I get a spammer or a hacker report from a member I ban the address range by the C string. 111.222.333.*** Then I use the stop forum spam db to see all the nearby addresses and drop them in just for fun. I haven't had any spammers or hackers get through in months since I started doing that.

That would be an incredible waste of time... These are likely mostly dynamic IPs, in a few days they won't even belong to the people they belong to now.

Also- your vBulletin banned IP list isn't designed to handle hundreds (or thousands) on entries. Each IP is loaded on every page load- keep your banned IP list short. Ban IPs from your server if you have to.

Blaine0002 08-11-2014 12:29 AM

Im also getting an incredible amount of emails about someone trying to get into my account.

Quote:

Originally Posted by Paul M (Post 2493899)
Ummm, not sure what are you referring to here ?

When you 'forget your password?' vb.org sends you a new password that consists only of numbers.

Mark.B 08-11-2014 11:07 AM

Just ignore them. The system is behaving exactly as it should, by denying access.

marto 12-08-2014 12:26 PM

The person trying to log into your account had the following IP address: 221.141.1.222
The person trying to log into your account had the following IP address: 61.158.173.188

Make sure your passwords are up to standards.

If it was me I'd ban all china IP's from the server but that's just me.

ozzy47 12-08-2014 12:39 PM

So if vB.org was to block all China ip's how would legitimate users from China come here for support and get mods?


All times are GMT. The time now is 01:02 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01582 seconds
  • Memory Usage 1,829KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (19)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (36)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete