Actually, I never meant to imply that I ever had impex installed.
However.... in the currently active users list, what else could an
Unknown Location with something like... "/index.php/impex/ with the script url here" ...mean?
But in the case where these other people have found their own posts and accounts duplicated on a forum they never joined... this IS how it could be done. As for password in the database, and I know this from experience from working on my own board... any Admin with the proper access can back up a database to their computer and view the file in notepad and see the so-called encrypted password. No offence. It's not encrypted.
At any rate, I am not going to say anything more about it, except...
Bottom Line: as Dean C said, "Well it's your own fault if you left a security risk on your server. I believe it does say to remove impex files once you're done."
Those people who leave that up are getting what they deserve and have no right to complain.
Thank you for listening. (PS: I don't type in British English, so typed words have different meanings.

And I am about zonked with needing sleep. And yes, WinXP can crash. It happened to me 2 weeks ago; that's why I'm on Linux now.

)