|
|
|
![]() |
|
|||||||
|
||||||||
![]() |
|
|
Thread Tools | Rate Thread | Display Modes |
|
|
|
#1
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
Brandon, do you have any way to reset the passwords of users that are using their username as their password? Most of the users involved had 0 or 1 posts and aren't likely to log in any time soon to see this message.
|
|
#2
|
||||
|
||||
|
Re: Inappropriate Spam Private Messages
Mine are completely gone as of Friday morning. Thank you very much for getting rid of the spam so quickly! Just another happy CDer knowing that Chief Delphi is the best site out there...
![]() |
|
#3
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
When I get back from IRI, I will be notifying those users with the same username/password that their password will be reset for them. I will also be upgrading the forums to the latest version, in the off chance that this was a vulnerability being exploited in our version of the software.
I have 2 unread PMs that I can't see in my inbox somewhere .. so I will go through and repair the PM listings when I get back home from IRI. Doing the quick fix that I did last night wasn't a complete fix .. just enough to get the inappropriate material out of peoples inboxes. |
|
#4
|
|||
|
|||
|
Re: Inappropriate Spam Private Messages
all part of web development and admnistration, always protecting your site against SQL injection, XSS attacks, etc....
|
|
#5
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
An update: after some research, this was not a vBulletin exploit. No data was compromised, or hacked. There are multiple other forums experiencing the same PM spam, all reporting that the accounts being compromised had username==password.
I will be resetting passwords on anybody who has username==password, to prevent this from happening in the future. vBulletin will most likely prevent people from setting username==password in future versions, it looks like, as well. I still have to clean up inboxes -- mine has 2 unread, missing PMs. EDIT: 117 passwords reset .. and it will perform this reset automatically, every night without notice to prevent future attacks. EDIT: The private messages should be cleaned up now. Let me know if you still have weird things happening in your PM inbox. Last edited by Brandon Martus : 21-07-2008 at 11:30. |
|
#6
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
Anyone still have a bold number X of unread private messages but none in their inbox like I still do?
|
|
#7
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
A few have reported it .. one person got rid of the bold # by selecting all messages, marking as read. I'll look into it a little this weekend, if I can find some time.
|
|
#8
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
That method worked for me.
|
|
#9
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
Quote:
|
|
#10
|
||||
|
||||
|
Re: Inappropriate Spam Private Messages
Brandon - My box is showing 1 stored message, but it doesn't show up anywhere to delete. Clicking the "empty box" command doesn't get rid of it.
|
|
#11
|
||||
|
||||
|
Re: Inappropriate Spam Private Messages
Quote:
Quote:
|
|
#12
|
||||
|
||||
|
Re: Inappropriate Spam Private Messages
Same for me!
|
|
#13
|
|||
|
|||
|
Re: Inappropriate Spam Private Messages
I figured it out, check the checkbox in the header of the table, then in the bottom select "Mark as read". This will force the "unread messages" number in the database to refresh.
Either a SQL DELETE was used to get rid of the messages, or there is a bug in vBulletin which doesn't issue an update after a mass delete (I don't think vBulletin has such a control panel that can delete PMs, last I checked a few years ago). Anyways, this solution worked for me. That bold "1 Unread message" was driving me crazy too. |
|
#14
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
Quote:
|
|
#15
|
|||||
|
|||||
|
Re: Inappropriate Spam Private Messages
I liked having messages from 1969 in my PM box! Then I could say to my kids, "Hey kids, when I was your age, CD got attacked, and I have these messages from 1969 to show when Brandon fixed the problem remotely from IRI using nothing but his cell phone, a wad of gum and a paperclip!" On a serious note, awesome job Brandon fixing everything promptly!Jacob |
![]() |
| Thread Tools | |
| Display Modes | Rate This Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| private messages | Anarkissed | CD Forum Support | 13 | 26-01-2009 09:37 |
| Reputation and private messages | RyanMcE | Chit-Chat | 8 | 22-04-2004 07:40 |
| Private Messages, or are they? | D.J. Fluck | CD Forum Support | 8 | 21-12-2003 01:34 |
| Ventures & Private Messages | Brandon Martus | Announcements | 0 | 03-04-2003 12:02 |