Email this evening from this mod:
Quote:
Hi,
northernangel logged into the AdminCP from IP address 209.105.205.53.
AdminCP Firewall
|
northernangel is a valid membername from a member who had not logged in for a long time. The member was not ad admin or moderator. The records show that member did log in to her account about the time the email was generated but it was from a different IP address and a different country than the one on record. There is no indication in the logs of any entry into the admincp from that member or indeed any member other than the two admins.
How is this possible? Is this a false positive?
I have changed the password for that member, banned the member at the forum level, and banned the IP at the server level to be safe. But should there not be a log entry if there indeed was a breach?
By the way, in order to gain access to the AdminCP, two passwords are required.