2024 Ohio Reef Frag Swap

2024 flyer

Author Topic: Log in every time???  (Read 5945 times)

0 Members and 1 Guest are viewing this topic.

Offline Kenn

  • Lifetime Premium Member
  • *****
  • Posts: 3,176
Re: Log in every time???
« Reply #25 on: February 17, 2011, 20:12:09 »
thats a good possibility ... someone could also collect member names from the home page. Online members are listed on the left even if your not signed in
Currently doing a 75g build | http://ohioreef.com/index.php?topic=16275.0| tanks of the past : 26g Bowfront LPS and Fish| http://www.ohioreef.com/index.php?topic=4858.0 || 37g a little of everything | http://www.ohioreef.com/index.php?topic=7751.0

"A person is smart. People are dumb, panicky dangerous animals and you know it. Fifteen hundred years ago everybody knew the Earth was the center of the universe. Five hundred years ago, everybody knew the Earth was flat, and fifteen minutes ago, you knew that humans were alone on this planet. Imagine what you'll know tomorrow."   < K >

Offline cyberwollf

  • 2010 FragSwap Chairman
  • Posts: 3,268
Re: Log in every time???
« Reply #26 on: February 17, 2011, 20:15:34 »
thats a good possibility ... someone could also collect member names from the home page. Online members are listed on the left even if your not signed in

Are we really a big enough club for someone to go through the hassel of manually collecting usernames?  I'd think someone would write a script to target SMF fourms since they'd all use the same HTTP Headers.  They could just get a list of all SMF sites and let the CPU do its work.
75G Mixed Reef w/ 30G sump/refuge

Electrical Engineers do it on impulse, with faster rise times, with more power, and less resistance at higher frequencies, without shorts, until it Hertz


Offline ohioreef

  • Lifetime Premium Member
  • *****
  • Posts: 4,673
  • Founding Member
Re: Log in every time???
« Reply #27 on: February 17, 2011, 20:47:44 »
We aren't the only ones experiencing this:  http://www.simplemachines.org/community/index.php?topic=416928.0

Offline Kenn

  • Lifetime Premium Member
  • *****
  • Posts: 3,176
Re: Log in every time???
« Reply #28 on: February 17, 2011, 22:23:26 »
Are we really a big enough club for someone to go through the hassel of manually collecting usernames?  I'd think someone would write a script to target SMF fourms since they'd all use the same HTTP Headers.  They could just get a list of all SMF sites and let the CPU do its work.

I dont disagree with you but people who do this have a lot of time on thier hands and when you discount someone would do it just because YOU (not you personally :) ) think it is a slow and tedious way, you open yourself up to exploitation.

 
Currently doing a 75g build | http://ohioreef.com/index.php?topic=16275.0| tanks of the past : 26g Bowfront LPS and Fish| http://www.ohioreef.com/index.php?topic=4858.0 || 37g a little of everything | http://www.ohioreef.com/index.php?topic=7751.0

"A person is smart. People are dumb, panicky dangerous animals and you know it. Fifteen hundred years ago everybody knew the Earth was the center of the universe. Five hundred years ago, everybody knew the Earth was flat, and fifteen minutes ago, you knew that humans were alone on this planet. Imagine what you'll know tomorrow."   < K >

Offline lazylivin

  • Administrator
  • Adult
  • *****
  • Posts: 11,471
Re: Log in every time???
« Reply #29 on: February 17, 2011, 23:12:30 »
Thanks for the link Gary, it led me to a fix that is looking promising.   :-ThumbUpsm

Paul the list I provided was a sort by IP addresses so I could show a single IP to many account logon attempts. There were 100's of new IP addresses hitting us each hour.

Offline lazylivin

  • Administrator
  • Adult
  • *****
  • Posts: 11,471
Re: Log in every time???
« Reply #30 on: February 18, 2011, 22:37:45 »
We are definitely good to go. Was seeing several attempted logins per minute last night and haven't seen one since the fix. You may have had to re-login once more after the fix but that shouldn't not happen anymore.  :-ThumbUpsm

Offline ohioreef

  • Lifetime Premium Member
  • *****
  • Posts: 4,673
  • Founding Member
Re: Log in every time???
« Reply #31 on: February 18, 2011, 22:56:09 »
Seems to be fixed here!!  Good job, Brian!!

Offline lazylivin

  • Administrator
  • Adult
  • *****
  • Posts: 11,471
Re: Log in every time???
« Reply #32 on: February 19, 2011, 00:36:07 »
Great! Thanks

Offline Kenn

  • Lifetime Premium Member
  • *****
  • Posts: 3,176
Re: Log in every time???
« Reply #33 on: February 19, 2011, 00:57:20 »
Everything is working good on my end as well

Thanks for all the work Brian  :-ThumbUpsm
Currently doing a 75g build | http://ohioreef.com/index.php?topic=16275.0| tanks of the past : 26g Bowfront LPS and Fish| http://www.ohioreef.com/index.php?topic=4858.0 || 37g a little of everything | http://www.ohioreef.com/index.php?topic=7751.0

"A person is smart. People are dumb, panicky dangerous animals and you know it. Fifteen hundred years ago everybody knew the Earth was the center of the universe. Five hundred years ago, everybody knew the Earth was flat, and fifteen minutes ago, you knew that humans were alone on this planet. Imagine what you'll know tomorrow."   < K >

Offline Secondgen

  • Lifetime Premium Member
  • *****
  • Posts: 1,372
Re: Log in every time???
« Reply #34 on: February 19, 2011, 01:23:00 »
Good for me Brian. Thank you.

Offline micki

  • Best mamaw Reefer!!!
  • Posts: 7,239
  • My munchkins! :)
Re: Log in every time???
« Reply #35 on: February 19, 2011, 07:56:40 »
I'm gone most of this weekend, but thought I would try this morning before I left and it's a GOOD TO GO!!!  Thanks so much Brian!!!

Offline reefkeeper

  • Juvenile
  • ***
  • Posts: 155
Re: Log in every time???
« Reply #36 on: February 19, 2011, 09:34:15 »
Thanks Brian.  It's working great now!
Jeff
120g baby reef w/ 55g refug
Penn State & Steelers Fan

Offline Telekinesis

  • Fry
  • **
  • Posts: 32
  • Because we couldn't go for three
Re: Log in every time???
« Reply #37 on: February 19, 2011, 10:02:47 »
Good thing I have the most ridiculous password ever. Those of you who had auto-login issues might want to change your passwords, as I'm pretty sure this means your account was successfully logged into. I'm assuming providing an incorrect password for a random username from a different connection/PC wouldn't be enough to tamper with your settings. In fact, I'd make sure you weren't using the same one for bank info or anything more personal. Maybe it isn't that serious, but it's better to be safe than sorry. There are a lot of reasons people steal passwords, but posting under your account on a reef club forum is hardly one of them.

Just my two cents. Feel free to correct me if I'm wrong about the log settings.

Offline ohioreef

  • Lifetime Premium Member
  • *****
  • Posts: 4,673
  • Founding Member
Re: Log in every time???
« Reply #38 on: February 19, 2011, 10:17:56 »
Unless your password was ridiculously easy, ie same as log-in, I'm pretty sure no passwords were compromised. The error log showed all incorrect attempts, correct me if I'm wrong, Brian. The need to log-in each time was a security feature of the software.

Offline Joel

  • Adult
  • ****
  • Posts: 1,384
Re: Log in every time???
« Reply #39 on: February 19, 2011, 10:20:52 »
All is back to normal for me as well, great job!

Offline lazylivin

  • Administrator
  • Adult
  • *****
  • Posts: 11,471
Re: Log in every time???
« Reply #40 on: February 19, 2011, 10:39:18 »
You are 100% correct Gary, it is very unlikely a password was comprised and the need to relogin was a result of the Security protection feature on Ohio Reef.  Just to add to that the log won't show a successful login, so a account could have been comprised and not know to us. With this said it is a good idea to change your passwords for your online financial banking/transactions if it was the same as what you have on Ohio Reef.

Offline Telekinesis

  • Fry
  • **
  • Posts: 32
  • Because we couldn't go for three
Re: Log in every time???
« Reply #41 on: February 19, 2011, 10:44:46 »
Ahh, gotcha. Thanks for the info, all.  I've never maintained an SMF board, so it's nice to know there's a security feature like that in place. I'm glad to see it appears to be resolved. I'm far too lazy to log in and out all the time. :laugh:

Offline lazylivin

  • Administrator
  • Adult
  • *****
  • Posts: 11,471
Re: Log in every time???
« Reply #42 on: February 19, 2011, 11:03:38 »
I just checked the configuration and it was set to trigger at three failed attempts. When breaching that it would remove the cached session in the database and require a authentication. I am not sure how that helps from a security stand point other then creating awareness that there is an issue. Maybe that is it?

Offline cyberwollf

  • 2010 FragSwap Chairman
  • Posts: 3,268
Re: Log in every time???
« Reply #43 on: February 20, 2011, 19:48:21 »
You'd be surprised at some of the password dictionaries that have been created for cracking.  #1 make sure your password is NOTHING that exists in Websters, etc.  #2 not a ASDF type keyboard pattern.  Those too are pretty well mapped and easily guessed in the first few 100,000 tries lol.  Anytime a password database is hacked, those guys pass around the results to update "common" passwords
75G Mixed Reef w/ 30G sump/refuge

Electrical Engineers do it on impulse, with faster rise times, with more power, and less resistance at higher frequencies, without shorts, until it Hertz


Offline rayviv

  • Posts: 1,128
  • Here fishy, fishy.
Re: Log in every time???
« Reply #44 on: February 20, 2011, 20:00:52 »
 What is === ASDF type keyboard pattern?
The mind is a wonderful servant but a dangerous master!

Offline Wall_Tank

  • Administrator
  • Adult
  • *****
  • Posts: 3,754
Re: Log in every time???
« Reply #45 on: February 20, 2011, 20:03:20 »
Look at your keyboard Ray.    You would be surprised how many use passwords

12345
qwerty
asdfg
zxcvb

etc.

Offline rayviv

  • Posts: 1,128
  • Here fishy, fishy.
Re: Log in every time???
« Reply #46 on: February 20, 2011, 20:21:14 »
Thanks man.
 Seems the older I get the more I seem to need things spelled out for me.
Appreciate your help.
The mind is a wonderful servant but a dangerous master!

Offline cyberwollf

  • 2010 FragSwap Chairman
  • Posts: 3,268
Re: Log in every time???
« Reply #47 on: February 20, 2011, 20:58:46 »
What is === ASDF type keyboard pattern?

like just going across the middle line of the keyboard "asdfghjkl" (or top line "qwertyuiop")  same goes with vertical patterns.  You figure lots of folks have lots of passwords and a pattern is easier to remember.  BUT those are much easier to crack.  Just think, If its anything that anyone else might EVER consider, its in a password cracker database somewhere (names included).  Combinations of special charactors (@#$%) and numbers with words is best.
75G Mixed Reef w/ 30G sump/refuge

Electrical Engineers do it on impulse, with faster rise times, with more power, and less resistance at higher frequencies, without shorts, until it Hertz


Offline cyberwollf

  • 2010 FragSwap Chairman
  • Posts: 3,268
Re: Log in every time???
« Reply #48 on: February 20, 2011, 21:00:04 »
Look at your keyboard Ray.    You would be surprised how many use passwords

12345
qwerty
asdfg
zxcvb

etc.

DOH, didnt refresh to see your response lol
75G Mixed Reef w/ 30G sump/refuge

Electrical Engineers do it on impulse, with faster rise times, with more power, and less resistance at higher frequencies, without shorts, until it Hertz


 

Powered by EzPortal