Go Back   vb.org Archive > Community Central > vBulletin.org Site Feedback

Closed Thread
 
Thread Tools Display Modes
  #21  
Old 02-02-2013, 08:57 PM
Amit86 Amit86 is offline
 
Join Date: Feb 2008
Location: Israel
Posts: 108
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just received 180 emails about my account being locked for wrong password
  #22  
Old 02-02-2013, 08:58 PM
Amenadiel's Avatar
Amenadiel Amenadiel is offline
 
Join Date: Sep 2006
Posts: 171
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

A few more IPs from last hours

111.221.3.218
85.133.162.132
84.241.52.97
213.154.203.148
59.57.15.71
111.161.30.218
187.5.228.123
42.121.16.222
180.250.130.186
62.210.226.142
202.69.105.154
190.153.5.95
78.134.255.43
111.221.3.218
77.110.120.200
210.14.143.53
186.95.122.150

at least they bothered to hire a botnet to perform the attack.
  #23  
Old 02-02-2013, 09:10 PM
Alex_Grist Alex_Grist is offline
 
Join Date: Jan 2008
Posts: 8
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've also had over 150 emails regarding my account being locked due to someone attempting to brute force my password; VBulletin should be better prepared for something like this, surely having an account locked means you can't attempt at all for 15 minutes? This is annoying spam that needs to be prevented.

Edit:

Added a GMail filter to automatically delete the annoying emails.
  #24  
Old 02-02-2013, 10:00 PM
Azunai Azunai is offline
 
Join Date: Feb 2012
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Well how about an email WHENEVER someone SUCCESSFULLY logs into your account
this would be very intersting to now + avoid "login try" spam
  #25  
Old 02-02-2013, 10:11 PM
BarelyHangingOn BarelyHangingOn is offline
 
Join Date: Feb 2003
Posts: 108
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I am getting a pole load of them too. Annoying.
  #26  
Old 02-02-2013, 10:18 PM
DAMINK DAMINK is offline
 
Join Date: Jun 2010
Location: Melbourne Australia
Posts: 301
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I changed locations for my admin and mod areas.
Never had an issue with false logins unless its me screwing up (happens often).

I made a fake admin/mod area that ultimately leads to a trap and .htaccess bans that ip address.
Nice simple easy solution.
I imagine these attacks are automated and looking for /admincp/ sort of thing.

I highly recommend renaming your admin and mod areas.
Not to mention hiding your version number as they often use the 2 as a means of targeting the desired board.
  #27  
Old 02-02-2013, 10:50 PM
Bluemax712 Bluemax712 is offline
 
Join Date: Oct 2010
Posts: 186
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yes - it should be redesigned to lockout for 15 minutes from any IP
I got 14 emails listing 14 different IPs within 5 minutes

or maybe it is locking out from all IPs for 15 minutes
and it's the message that should be changed when there are more attempts from different IPs during the lockout period:

Account already locked but another attempt has been made by xxx.xxx.xxx.xxx
  #28  
Old 02-02-2013, 10:57 PM
AuroraStorm's Avatar
AuroraStorm AuroraStorm is offline
 
Join Date: Nov 2006
Location: ATHell
Posts: 332
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yep...I got the same thing from an IP 180.241.113.26 that I tracked to Indonesia...
Благодарность от:
mykkal
  #29  
Old 02-02-2013, 11:01 PM
Digital Jedi's Avatar
Digital Jedi Digital Jedi is offline
 
Join Date: Oct 2006
Location: PopCulturalReferenceLand
Posts: 5,171
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Alex_Grist View Post
I've also had over 150 emails regarding my account being locked due to someone attempting to brute force my password; VBulletin should be better prepared for something like this, surely having an account locked means you can't attempt at all for 15 minutes? This is annoying spam that needs to be prevented.

Edit:

Added a GMail filter to automatically delete the annoying emails.
Better prepared? The didn't get in. They got locked out. Your account did not get compromised. AND you were informed. Exactly what would be better than that?
  #30  
Old 02-02-2013, 11:18 PM
Beretta1526 Beretta1526 is offline
 
Join Date: Mar 2008
Posts: 9
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

More IP's from about 45 minutes ago, and then 36 minutes ago:

190.37.38.210
190.221.174.130
186.103.129.84
177.53.104.9
186.103.136.228
84.55.76.228

I guess it's a good thing I didn't use "monkey" for my password, huh?

.
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 10:37 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04581 seconds
  • Memory Usage 2,250KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (10)post_thanks_box
  • (1)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete