Go Back   vb.org Archive > Community Central > vBulletin.org Site Feedback
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #41  
Old 02-03-2013, 01:02 AM
Amaury Amaury is offline
 
Join Date: Nov 2011
Location: Ellensburg, WA
Posts: 1,075
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by CaseLogic View Post
First off, I disagree. They can start banning IP ranges so this doesn't keep happening slowly to their entire userbase.

Secondly, even if they don't take any action to prevent it, it couldn't hurt to send users emails to inform them that apparently botnets are trying to brute force their way into people's accounts, and to take the proper measures (ensure passwords are secured, etc).
They do send out e-mails.

Quote:
Account on vBulletin.org Forum locked out

Dear Amaury25,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address: 218.17.157.20

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:
https://vborg.vbsupport.ru/login.php?do=lostpw

All the best,
vBulletin.org Forum
  #42  
Old 02-03-2013, 01:07 AM
BigAl205's Avatar
BigAl205 BigAl205 is offline
 
Join Date: Oct 2010
Location: Hayden,AL
Posts: 69
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by CaseLogic View Post
First off, I disagree. They can start banning IP ranges so this doesn't keep happening slowly to their entire userbase.

Secondly, even if they don't take any action to prevent it, it couldn't hurt to send users emails to inform them that apparently botnets are trying to brute force their way into people's accounts, and to take the proper measures (ensure passwords are secured, etc).
You can't be too broad with your restrictions unless your board has a specific target. For companies working with a global market such as VB, it's bad business to block too many ranges. I'm sure even China has legitimate customers using VB who would be blocked if a large enough range was used.
Благодарность от:
Amaury
  #43  
Old 02-03-2013, 01:13 AM
Carpesimia Carpesimia is offline
 
Join Date: Jun 2011
Posts: 49
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hacking is at a big-time high. Twitter just got hacked. If your site is big enough, expect to someone to try and hack you.

vBulletin is working great knocking away the brute force attempts and sending emails to alert users someone is trying to log in as them. I got like 50 emails tonight, and decided to come in and update my already decent password to an even better one. Thats what the emails are for, in my opinion.

And VB not caring? If they didnt care, they wouldnt have built it into the system. People try to hack, they fail, and then they go away. If VB staff made a big deal about it each time, it would only encourage the people to try harder.

My $.02, anyways.
3 благодарности(ей) от:
Amaury, CAG CheechDogg, Lynne
  #44  
Old 02-03-2013, 01:17 AM
Big Al Big Al is offline
 
Join Date: Nov 2011
Posts: 54
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Dear Big Al,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address: 41.67.2.2

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:
https://vborg.vbsupport.ru/login.php?do=lostpw

All the best,
vBulletin.org Forum
IP= 41.67.2.2 Proxy from Khartoum.

There is no doubt that spamming is getting worse and newer advanced programs are being used to counteract anti-spam measures we take. The providers need to become pro active, not brush the problem aside.
VB does send out an email, thanks, but action needs to be initiated to counteract the advances the spammer are putting in place.

Quote:
If you checked "Remember Me?" whenever you last logged in and just close your browser when you're done browsing instead of logging out, then these brute force attacks won't affect you.
A valid point, but I think it will only work if you allow cookies to be stored.
Many people delete cookies when they log off.

--------------- Added [DATE]1359858815[/DATE] at [TIME]1359858815[/TIME] ---------------

Quote:
99% of SPAM comes from China. I have no reason for anyone in China to view any content on my servers, so I block all Chinese IP space at the firewall level.
Exact figures are hard to come by. But it does appear that most spam comes from the USA.

Currently there is a lot from USA, China and Ukraine etc.

China is sensitive to international pressure and their reputation.

They have made large strides recently to curb scammers and other fraud. Closing down large numbers of bad sites etc . This is to their credit and is welcome.

However most governments are reluctant to curb any income producing method and the income from Chinese business who use spam is very large.

Until recently, a lot of the traffic was curtailed and quite a few businesses used ISP's in Hong Kong and Switzerland to bypass restrictions in mainland china. I think this is now not so common.
  #45  
Old 02-03-2013, 02:23 AM
chiapeterson chiapeterson is offline
 
Join Date: Oct 2007
Posts: 7
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I've received 40 messages in the last 5 minutes about my account being locked because someone has entered the password wrong 5 times. Each message has a different IP address. PLEASE close\delete this account. I've not used VBulletin in over 4 years. Thank you!
  #46  
Old 02-03-2013, 02:36 AM
Amaury Amaury is offline
 
Join Date: Nov 2011
Location: Ellensburg, WA
Posts: 1,075
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

As far as I know, they don't delete accounts here.
  #47  
Old 02-03-2013, 02:44 AM
chrisngrod's Avatar
chrisngrod chrisngrod is offline
 
Join Date: Oct 2010
Posts: 83
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Just wanted to chime in that they are trying to brute force mine as well.
  #48  
Old 02-03-2013, 02:53 AM
Chevy II Chevy II is offline
 
Join Date: Nov 2003
Posts: 34
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I also received 47 of these email. The reports were from many different IP addresses too. Romania, China, Brazil and India to name a few...

What is up with this?

--------------- Added [DATE]1359863784[/DATE] at [TIME]1359863784[/TIME] ---------------

BTW, this was an attempt from someone trying to log into my account 5 times with the wrong PW... Not an account deletion.

Here is an example of 1 of the 47 email I received.

Quote:
Dear Chevy II,

Your account on vBulletin.org Forum has been locked because someone has tried to log into the account with the wrong password more than 5 times. You will be able to attempt to log in again in another 15 minutes.

The person trying to log into your account had the following IP address: 103.7.64.51

Don't forget that the password is case sensitive. Forgotten your password? Use the link below:
https://vborg.vbsupport.ru/login.php?do=lostpw

All the best,
vBulletin.org Forum
  #49  
Old 02-03-2013, 03:01 AM
Amaury Amaury is offline
 
Join Date: Nov 2011
Location: Ellensburg, WA
Posts: 1,075
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Chevy II View Post
I also received 47 of these email. The reports were from many different IP addresses too. Romania, China, Brazil and India to name a few...

What is up with this?

--------------- Added [DATE]1359863784[/DATE] at [TIME]1359863784[/TIME] ---------------

BTW, this was an attempt from someone trying to log into my account 5 times with the wrong PW... Not an account deletion.

Here is an example of 1 of the 47 email I received.
Nothing to worry about if you have a strong password. Just spam accounts trying to get in.
  #50  
Old 02-03-2013, 03:21 AM
Digital Jedi's Avatar
Digital Jedi Digital Jedi is offline
 
Join Date: Oct 2006
Location: PopCulturalReferenceLand
Posts: 5,171
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by CaseLogic View Post
Damn, this is happening to me now. I came to create a thread but apparently some botnet is having a field day on these forums.

And clearly VB staff doesn't care much about these attempts given no one has officially commented in the past few days?
Quote:
Originally Posted by Amaury25 View Post
The staff has no control over it.
Um, Paul commented on it today. The software is working like it's supposed to. This thread is bewildering. The software is doing what it's supposed to. Locking them out, and informing you of attempts. But this is, for some reason, considered out of control? So far no one has answered my question. What more do you want it to do?
2 благодарности(ей) от:
cellarius, mykkal
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 04:50 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04686 seconds
  • Memory Usage 2,281KB
  • Queries Executed 13 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (10)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (10)post_thanks_box
  • (6)post_thanks_box_bit
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (3)post_thanks_postbit
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • fetch_musername
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • post_thanks_function_fetch_thanks_bit_start
  • post_thanks_function_show_thanks_date_start
  • post_thanks_function_show_thanks_date_end
  • post_thanks_function_fetch_thanks_bit_end
  • post_thanks_function_fetch_post_thanks_template_start
  • post_thanks_function_fetch_post_thanks_template_end
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete