Quote:
Originally Posted by TimberFloorAu
Today we have had 2 members join, whos ips match 2 of our senior moderators.
Now , our mods have denied that they have set up a new acct,.... so can someone explain.
Is their a security flaw?
Someone is obviously, going to the trouble of obtaining our users IP addresses, then signing up , using a bogus IP addy, that matches our Mods.
Sounds Bizarre but true. Currently have VBSEO online with us, assisting with Suhosin settings
Can anyone please explain how this vulnerability can happen ?
|
I happened to check on a friends forum the night before last... I logged in and saw (1 Viewing) beside an admin forum... I looked @ WOL and only me and one other member w/ no guest so I clicked the sub-forum and it had the member listed as viewing their admin forums.
Oddly enough they had setup a general admin account a while back when on 3.6 to post RSS feeds and guess what? The users IP matched the admin accounts IP.
So same question here as it sounds oddly familiar to yours TimberFloorAU except they do not use vBSEO (Gamer forums no need etc).