Is My Forum Under Attack? Possibly 3.6.10 related?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • MistyPotato
    Senior Member
    • Nov 2006
    • 133
    • 3.6.x

    Is My Forum Under Attack? Possibly 3.6.10 related?

    Hi,

    I am getting a surge in people requesting help with Activation. To me, it seems very odd to get so many that seem to be written by the same person over and over in such a short time. The email addresses are different but most of the IP addresses seem to be from the same block.

    I am still getting successful registrations so I do not believe there is anything wrong with the site.

    I know there was a security issue and that's why 3.6.10 was released. Could this be an attempt to get me to, for example, log into their account to check it, then a form sends them the admin username and password or something like that??

    Curious.

    Thanks
    Last edited by MistyPotato; Tue 29 Apr '08, 6:03am.
  • Wayne Luke
    vBulletin Technical Support Lead
    • Aug 2000
    • 74132

    #2
    No... The issue that is resolved in 3.6.10 requires that you be logged into your account and visit their website which submits a form. Even then it can't do anything that requires additional input from the user or affect the admincp. They don't even get your Username and Password from the exploit as it relies on your cookies to handle login.

    Could be a phishing attempt but the only way around that is common sense.
    Translations provided by Google.

    Wayne Luke
    The Rabid Badger - a vBulletin Cloud demonstration site.
    vBulletin 5 API

    Comment

    • MistyPotato
      Senior Member
      • Nov 2006
      • 133
      • 3.6.x

      #3
      Very good.

      Probably a disgruntled banned ex-member then.

      Comment

      widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
      Working...