Ford Ranger Forums banner

Status
Not open for further replies.
1 - 8 of 8 Posts

·
Premium Member
Joined
·
3,321 Posts
Discussion Starter #1
Hey guys,

Lately, we've been experiencing issues regarding having to log in each time we visit the site. This does not impact everyone, but has caused issues with some.

From what my research has gathered, this seems to be an underlying issue affecting all internet forums running the SMF software.

What seems to be causing it is a few rogue "bots" that are scouring the internet looking for sites running SMF. From what we can tell, they are using Google to search for the copyright located in the footer of each site (thus returning hundreds of thousands of potential targets). By law, this copyright cannot be removed from any site.

From there, the bots are attempting to login to certain users' accounts. We think they have a list of commonly used passwords they are trying.

Our version of SMF has a setting in place that causes a user to become logged out upon someone else attempting (and failing) to login to said account. This is where our issues arise.


So to combat this, I will be upgrading to the newest version of the forum software. This may cause slight rifts in the template the site uses (as it's only confirmed to work with the current version). If you see any changes to the layout, they are caused by this. Please allow a few weeks for all the issues to be worked out (hopefully it wont take that long).


Also, as a side note, if your password is something simple such as "password", "1234", etc., please change your password immediately to something much more difficult to guess. Also, as a general rule of thumb on anything you do online, never use the same username/password combo as your bank information.

If you have any questions, please reply in this thread. If you notice anyone talking about the issues elsewhere on the site, please refer them to this thread.

Thank you!
 

·
Premium Member
Joined
·
3,321 Posts
Discussion Starter #2
Re: Log/Logout Issue

Well, it looks like the upgrade went without a hitch (that I can see). We are now up-to-date.

Will this stop the bots? Not necessarily... there is nothing to keep someone else from trying to login as a different user. This goes for any site on the internet.

However, the new upgrade prevents a user from being logged out because of this. You should no longer have the logout issue.

The bot attacks will eventually cease, but until then, they are still a valid threat to security. This is a prime example of why passwords should be hard to guess. Again, if you have an easy password, PLEASE consider changing it to a more secure one.




If anyone notices anything messed up from the upgrade, please let me know in this thread and I will try to take care of it.

Of course, if you are still experiencing the same issue with logging in/out, please let me know!

Thanks!
 

·
Registered
Joined
·
583 Posts
The logging in issue seems to be working fine for me when I got on tonight.
 

·
Registered
Joined
·
1,340 Posts
While the login issue seems to be fixed for me, there is two other issues I'm having.

1) At the login page this morning, a page popped up that said my password entry was incorrect. I generally use my saved info for this so I was suspicious and clicked on the original login and was granted entry. My thought; this was an attempt by a bot to steal my info. This is the pitts because I generally clear all tracking cookies and saved info about once a week and have to re-enter my password at that time. I'll have to research how to save my new passwords as I will be changing them so they are different for each site as suggested, thanks Danny.

2) I'm still not getting new posts when I click on "show unread posts". Perhaps others are unaware of this problem because they haven't noticed the posts shown at the bottom of the screen BEFORE logging in.

Richard
 

·
Premium Member
Joined
·
3,321 Posts
Discussion Starter #6
Sounds like the upgrade fixed the major issue with loggin in. The main thing the upgrade did was change a setting in the program. Before, whenever someone tried to log in as another user, but used an incorrect password, it would log the real user out. This setting has been amended to where that is no longer the case.


Richard, I think I may know why you are seeing new posts, but once you log in there aren't any. Since you cleared your cookies, all the posts now look new as your computer thinks it has never seen them before. Try hitting the "mark all messages as read" button on the main index of the forum after you are logged in (since you have actually read these before). Then try logging out and see if any of the posts still show as new.

Hopefully we have everything in working order now! If you run into anything, let me know and I'll get it fixed ASAP!
 

·
Registered
Joined
·
1,340 Posts
I'm missing the unread/new at the bottom of the page.

Richard
 

·
Premium Member
Joined
·
3,321 Posts
Discussion Starter #8
I'm working on getting that back installed. I had to remove the portal software we were using as it seems that's what the bots were targeting. I'm going to have to use something else to get them there, or hard code them in.
 
1 - 8 of 8 Posts
Status
Not open for further replies.
Top