vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vBulletin 4.x Add-ons (https://vborg.vbsupport.ru/forumdisplay.php?f=245)
-   -   Administrative and Maintenance Tools - [DBTech] vBSecurity v2 (vB4) (https://vborg.vbsupport.ru/showthread.php?t=276228)

madness85 12-10-2013 11:40 AM

Quote:

Originally Posted by rhody401 (Post 2467157)
I think I found a bug in version 1.1.1

On my 4.2.1 patched system, this has happened twice in the past month.

I have multiple admins and if an admin enters the wrong password just ONCE, it treats it like 25+ brute force attempts. It takes action with one attempt, ignoring the settings for # of attempts.

Under SECURITY WATCHERS: GENERAL - I have:



Twice it has set off both of the above (two emails, closed forum, etc) for a single wrong password attempt.

I have temporarily taken away its ability to close the forum, because I was out yesterday and it shut down the forum for almost 5 hours.

If I can help in any way to help duplicate/identify this behavior - don't hesitate to email me.

Thanks
Rhody

Same here buddy 1 failed login ip banned mostly from my mobile :(

rhody401 12-10-2013 07:24 PM

Ya i was able to duplicate it again last night, with a single wrong password attempt. For now, I disabled all but EMAIL ADMINISTRATOR - so it wont shut down the forum again.

Thanks for the reply to let me know I'm not imagining things :)

Rhody

DragonByte Tech 12-15-2013 02:07 AM

I'll attempt to replicate this myself as soon as I have time, if I can't I'll reach out to one of you for FTP/AdminCP information.

Fillip

final kaoss 12-15-2013 06:39 PM

There is a bit of a change I would make to this mod. Add an option to add IP to a blacklist (for 30 days or increments in months) for failed logins within x amount of time would be great.

https://vborg.vbsupport.ru/attachmen...4&d=1325289905

Mukashi 02-23-2014 01:50 AM

Finally got around to upgrading to 1.1.1 today on vB4.2.1, and I'm having a very strange error. My users and staff (including moderators but not including admins) cannot access their notifications or profile pages. I had updated several other addons in the same session (all DB Tech addons: Advanced User Tagging, vB Arcade, Username Change and AJAX Threads), but we've confirmed the error did not crop up until after this addon was installed.
The error only happened after this addon was updated, but did not seem to vanish when the addon was disabled/uninstalled.

EDIT: Hmmmm. Looks like it may be an addon conflict with Tournaments, Ladders & Leagues Manager v4.x. Disabled that addon, and now it's working again. Don't know how the heck that error could stay there even when I'd disabled/uninstalled vBSecurity, but since it only cropped up after updating this...*shrugs*

ZUCCO 02-23-2014 05:27 AM

Thank you ! I will try it :D

DragonByte Tech 06-29-2014 03:34 PM

vBSecurity v1.1.2

ACP Access Log / Verifier
  • Triggers an email alert if the IP addresses no longer match
  • Sends email to the Webmaster Email listed in the vBulletin Options


Fillip

woodmj 02-23-2015 08:44 AM

Please could I check something with this mod?

There's 2 kinds of rules you can set up for failed login attempts. 1 is for any IP address in eg. 5 mins and the other is for 1 IP address in eg. 5 mins. I think I understand the alerts produced for 1 IP address in eg. 5 mins in that 1 IP address has made multiple attempts to access accounts and has failed? but was does the alert for any IP address in eg. 5 mins mean? It will mention a handful of usernames but only one IP so I'm not sure what the IP relates to in that situation?

neptunesys 02-24-2015 02:11 PM

So far, this has been a great mod to have. I wish I'd installed in sooner :)

I would like to see two improvements in the Login Strikes Viewer to make this even more useful.

1. Differentiate between bogus (non-existent) usernames and existing usernames
2. Indicate if the displayed IP address has been banned

409industries 03-24-2015 04:43 PM

Awesome mod. Purchased the pro version.

Wish i had found this a long time ago to enforce password complexity requirements during registration / password changes.

Support is awesome too, they listened to some of my suggestions regarding the mass password reset feature and got the changes implemented very quickly. :-)


All times are GMT. The time now is 08:07 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01131 seconds
  • Memory Usage 1,740KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete