Author Topic: Logins not working?  (Read 17442 times)

0 Members and 1 Guest are viewing this topic.

Offline StarSlayer

  • 211
  • Men Kaeshi Do
    • Steam
Just got dumped out a sec ago when going from the home page to GD.
“Think lightly of yourself and deeply of the world”

 

Offline Nohiki

  • 28
  • Graf von Kaffeetrinken
    • Steam
I'm getting dumped all day, when i restart the browser, which could be cookie-related. Didn't somebody set the session/cookie time to 0 by any chance? :D

 

Offline newman

  • 211
Yep, happened again several times. But you get the picture by now :)
You know what the chain of command is? It's the chain I go get and beat you with 'til ya understand who's in ruttin' command here! - Jayne Cobb

 

Offline Fury

  • The Curmudgeon
  • 213
I think I know why this is happening. There is already almost 400 counts of incorrect login passwords in the forum error log in the last six hours. SMF logs out the user if someone enters wrong password three times. Looks like someone has launched different kind of spam attack upon HLP, trying to log in as already registered users to post spam.

This certainly would explain why this is do bloody random. Not sure what can be done about it though.

 

Offline Shade

  • 211
That actually makes sense. If whatever bots are trying it manage to find even one weak password and successfully log in, the spam would be a much greater chore to get rid of as simply deleting the user wouldn't be an option. Too bad there's not much to be done about them trying.

Guess it's time to stop using '12345' as my password.

PS. Had to log in again to post this. Figures :p
Report FS_Open bugs with Mantis  |  Find the latest FS_Open builds Here  |  Interested in FRED? Check out the Wiki's FRED Portal | Diaspora: Website / Forums
"Oooooooooooooooooooooooooooooooooooooooh ****ing great. 2200 references to entry->index and no idea which is the one that ****ed up" - Karajorma
"We are all agreed that your theory is crazy. The question that divides us is whether it is crazy enough to have a chance of being correct." - Niels Bohr
<Cobra|> You play this mission too intelligently.

 

Offline Snail

  • SC 5
  • 214
  • Posts: ☂
I have no idea why, but that just gave me goosebumps. Seriously, I'm freaked out man. How can we know who is and who isn't one of them? :shaking:

 

Offline Shade

  • 211
Yes, there could be hordes of bots hiding among us, making perfectly rational posts and releasing new models and campaigns to hide their identity!
Report FS_Open bugs with Mantis  |  Find the latest FS_Open builds Here  |  Interested in FRED? Check out the Wiki's FRED Portal | Diaspora: Website / Forums
"Oooooooooooooooooooooooooooooooooooooooh ****ing great. 2200 references to entry->index and no idea which is the one that ****ed up" - Karajorma
"We are all agreed that your theory is crazy. The question that divides us is whether it is crazy enough to have a chance of being correct." - Niels Bohr
<Cobra|> You play this mission too intelligently.

 

Offline Spicious

  • Master Chief John-158
  • 210
SMF logs out the user if someone enters wrong password three times.
That seems exactly backwards.

 

Offline General Battuta

  • Poe's Law In Action
  • 214
  • i wonder when my postcount will exceed my iq
Dear Friend,

Compliments of the day to you. By way of introduction,I am Saskia Opel,
a staff of Private Banking Services at the CIMB Bank (Malaysia).
I would respectfully request that you keep the contents of this mail
confidential and respect the integrity of the information you come by as a
result of this mail.

I have a business proposal which I believe would be of interest to you. It
concerns a deceased client who deposited The sum of US$ 8,370,000.00,
without naming a beneficiary to The funds, I alone have the
deposit details and they will release the deposit to no one unless I
instruct them to do so. I alone know of the existence of this deposit for
as far as CIMB is concerned, the transaction with our deceased customer
concluded when I sent the funds to the firm, all outstanding interactions
in relation to the file are just customer services and due process. They
are simply awaiting instructions to release the deposit to any party
that comes forward. This is the situation. This bank has spent great
amounts of money trying to track this man's family; they have
investigated for months and have found no family. The investigation has
come to an end.

My proposal; I am prepared to place you in a position to
give instruction for the release of the deposit to you as the closest
Surviving relation. Upon receipt of the deposit, I am prepared to share
the money with you in half. That is: I will simply nominate you as the
next of kin and have them release the deposit to you. We share the proceeds
50/50..

I have all document and existence of funds.

If its in your interest to proceed with the transaction,
please respond to this email account "( [email protected] ) I will
give you a detailed account of the source and origin of the estate as well
as the transaction proper.I anticipate your cooperation.

Regards,

Saskia Opel.

 

Offline Rodo

  • Custom tittle
  • 212
  • stargazer
    • Steam
el hombre vicio...

 

Offline Starman01

  • 213
  • Mechwarrior
    • Wing Commander Saga
It happens to me now again quite often (today and yesterday). But regarding the wrong passwords, couldn't it just be, that this logging out is happening to much more people than the few posting here. Everyone is used to stay login "forever" (like me), and now they suddenly have to reenter password again, that they haven't used in months and maybe have forgotten them :)
MECHCOMMANDER OMNITECH

9 out of 10 voices in my head always tell me that I'm not insane. The 10th is only humming the melody of TETRIS.

 

Offline newman

  • 211
I suppose the bots trying to log in as some of us makes some sense as an explanation, but why is it happening now after the upgrade? It literally never happened to me before and now it happens quite frequently on a daily basis.
Also, if it is the bots, there has to be some way to defend against this?
You know what the chain of command is? It's the chain I go get and beat you with 'til ya understand who's in ruttin' command here! - Jayne Cobb

 

Offline Rodo

  • Custom tittle
  • 212
  • stargazer
    • Steam
Well, they could register a new user before, maybe our accounts are getting attacked because the can't breach the new anti spambot registration quizzzzz.
el hombre vicio...

 

Offline newman

  • 211
If that's the case.. it was infinitely better just permabanning a spambot when it posted it's rubbish than have bots constantly attack user's accounts. Just sayin'...
Also, murdering people who do this sort of thing should be legal and encouraged with all sorts of incentives.
You know what the chain of command is? It's the chain I go get and beat you with 'til ya understand who's in ruttin' command here! - Jayne Cobb

 

Offline Starman01

  • 213
  • Mechwarrior
    • Wing Commander Saga
Quote
Also, murdering people who do this sort of thing should be legal and encouraged with all sorts of incentives.

I definitly support this !!!!  :drevil:
MECHCOMMANDER OMNITECH

9 out of 10 voices in my head always tell me that I'm not insane. The 10th is only humming the melody of TETRIS.

 

Offline Droid803

  • Trusted poster of legit stuff
  • 213
  • /人 ◕ ‿‿ ◕ 人\ Do you want to be a Magical Girl?
    • Skype
    • Steam
So that is why I've been kicked out so many times. :/
(´・ω・`)
=============================================================

 

Offline Fury

  • The Curmudgeon
  • 213
I will be installing a modification later today that changes login procedure to use email address instead of username. Since email addresses are not viewable to anyone except admins, bots can't guess it and cause valid session to be terminated with its failed login attempts.

 

Offline FUBAR-BDHR

  • Self-Propelled Trouble Magnet
  • 212
  • Master Drunk
    • 165th Beer Drinking Hell Raisers
Unless they are getting usernames and other info from another site. 

Oh and email addresses are visible just by clicking on send email from the member list. 
No-one ever listens to Zathras. Quite mad, they say. It is good that Zathras does not mind. He's even grown to like it. Oh yes. -Zathras

 

Offline Fury

  • The Curmudgeon
  • 213
Oh and email addresses are visible just by clicking on send email from the member list. 
Huh? Profile information is not shown to guests, at all. And you should not be seeing email addresses of other users regardless of whether they've enabled the option to allow emails to be sent. You should be only seeing recipient's name, but not his email address.

 

Offline Goober5000

  • HLP Loremaster
  • 214
    • Goober5000 Productions
I'm not a fan of disabling username login altogether.  It would be worth thinking about this a bit more.