Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 08-28-2007, 03:17 PM
jimatzyne jimatzyne is offline
 
Join Date: May 2007
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Registration compromise

Hello all.
I have a potential issue I wanted to run past you guys, to see what you think. I am running vBulletin 3.6.7 PL1 and have users require email confirmation set to ON.
I had a user sign up today, who created an account, and was posting within minutes. Fine I thought, but about half an hour ago, I got 3 failure messages. One for the confirmation email send, one for a PM someone sent him after he signed up, and another for his welcome email.
The details of the message failure were:
Action: failed
Status: 5.5.0
Diagnostic-Code: smtp;550 Requested action not taken: mailbox unavailable

So this says to me that he never received these emails, yet he still activated his account and was able to post.

My question is, if my thesis is correct, how in the name of zeus's butthole did he manage to activate his account and post?

Any thoughts gratefully received.

TIA

J

EDIT: and I have checked the admin logs, to make sure that the other admin hasnt been playing me about....
Reply With Quote
  #2  
Old 08-28-2007, 03:27 PM
blogtorank's Avatar
blogtorank blogtorank is offline
 
Join Date: Jan 2006
Posts: 450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Bounce is a e-mail bounce message from the person's e-mail provider read more on 550 errors...

Make sure that you have the usergroup for awaiting activation set to NOT post!
Reply With Quote
  #3  
Old 08-28-2007, 03:29 PM
jimatzyne jimatzyne is offline
 
Join Date: May 2007
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

All post permissions are set to "NO".
Was my first thought sadly, I wish it were that simple

EDIT: And besides which, his account is showing as registered user, not user awaiting confirmation email.
Reply With Quote
  #4  
Old 08-28-2007, 03:44 PM
blogtorank's Avatar
blogtorank blogtorank is offline
 
Join Date: Jan 2006
Posts: 450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Hmmm, then shoot me a PM to test that out then I'll sign up on your forums and test it myself and let you know. let me know?
Reply With Quote
  #5  
Old 08-28-2007, 03:51 PM
jimatzyne jimatzyne is offline
 
Join Date: May 2007
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by blogtorank View Post
Hmmm, then shoot me a PM to test that out then I'll sign up on your forums and test it myself and let you know. let me know?
YGPM
Reply With Quote
  #6  
Old 08-28-2007, 04:38 PM
blogtorank's Avatar
blogtorank blogtorank is offline
 
Join Date: Jan 2006
Posts: 450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

blogtorank, you do not have permission to access this page. This could be due to one of several reasons:
  1. Your user account may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
  2. If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
He had to have confirmed his e-mail, because I have tried twice for you, perhaps there is a blacklist of your e-mail that's being sent out too him.... However the biggest factor is I received your welcome e-mail to confirm my e-mail address and all which is gmail so do note that this is more than likely his e-mail server... Suspend his account until further notice, just to see if he responds too you, if not keep him banned perm!

There's no compromise whatsoever in there that I see, just seems his email server is wacked = HOTMAIL or YAHOO?
Reply With Quote
  #7  
Old 08-28-2007, 04:41 PM
jimatzyne jimatzyne is offline
 
Join Date: May 2007
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

So you are thinking he got the emails, but his server sent failures anyway?
Reply With Quote
  #8  
Old 08-28-2007, 04:52 PM
blogtorank's Avatar
blogtorank blogtorank is offline
 
Join Date: Jan 2006
Posts: 450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Perhaps it sent back a failure, but is it a free email service?
Reply With Quote
  #9  
Old 08-28-2007, 04:55 PM
jimatzyne jimatzyne is offline
 
Join Date: May 2007
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yup it is..... and not a good one at that.

Looks like its just me being paranoid.
Reply With Quote
  #10  
Old 08-28-2007, 05:49 PM
blogtorank's Avatar
blogtorank blogtorank is offline
 
Join Date: Jan 2006
Posts: 450
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Yeah I wouldn't worry too much over it , if he spams then ban him, but I would ban him to see if he is a real person rather than that rum runner bot that runs around
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:26 AM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.07846 seconds
  • Memory Usage 2,252KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (1)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (1)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete