Sub Menu
Links Menu
Online Users

In total there are 319 users online :: 3 registered, 0 hidden and 316 guests

Most users ever online was 1091 on Wed Aug 16, 2023 5:27 pm

Registered users: Bing [Bot], Google [Bot], Majestic-12 [Bot] based on users active over the past 60 minutes

it is impossible for a normal user to deblock his Account :(

Support for IntegraMOD 141

Moderator: Integra Moderator

it is impossible for a normal user to deblock his Account :(

PostAuthor: Juppertje » Sun May 06, 2007 2:54 pm

Your phpBB Version: 2.0.22
phpBB Type: Integramod 141
MODs: No
Your knowledge: Beginner
Board URL: [url]http://[/url]

PHP Version:
MySQL Version:


What was done before the problem appeared?
[i]played with ACP/CrackerTracker/Settings :(
Last edited by Juppertje on Sun May 06, 2007 3:46 pm, edited 1 time in total.

Juppertje
Integra Member
Integra Member
 
Posts: 113
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 12:12 pm
Cash on hand: 0.00

Re: it is impossible to deblock account for a normal user :(

PostAuthor: Juppertje » Sun May 06, 2007 3:41 pm

I know that i can deblock all accounts that are blocked in phpmyadmin with UPDATE phpbb_users SET phpBBSecurity_login_tries = '0' WHERE user_id > '-2';

But why can a normal user not deblock him self when he presses on deblock your account when he does press that he see only a screen to reset his/hers cookies

I think i have somthing wrong in ACP/CrackerTracker/Settings ?

is there somwhere a screen shot or a list how the settings has to be set?

with kind regards J Uppert
Last edited by Juppertje on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

Juppertje
Integra Member
Integra Member
 
Posts: 113
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 12:12 pm
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: .QUACK.Major.Pain » Sun May 06, 2007 6:47 pm

I've had complaints about that too. They had to try many many times until it worked
Last edited by .QUACK.Major.Pain on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

.QUACK.Major.Pain
Sr Integra Member
Sr Integra Member
 
Posts: 986
Likes: 0 post
Liked in: 0 post
Joined: Sat Jan 27, 2007 10:15 am
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Juppertje » Mon May 07, 2007 10:13 am

It is a serious problem manny user can't unblock their own account ;)
Last edited by Juppertje on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

Juppertje
Integra Member
Integra Member
 
Posts: 113
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 12:12 pm
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Helter » Mon May 07, 2007 11:02 am

they can unblock thier own accounts without help. The prob comes when phpbb security and CTracker are both locked. Users will have to go through the unlocking procedure twice.

the easiest way to make this less likely is to go to acp/security/configuration

set "Auto Ban" to "disabled"
set "Login Attempts" to "9"

this should leave CTracker to be the only one blocking login

in acp/CTracker/configuration

set "Spammer Protection" to "disabled"
set "Password Reset Check" to "disabled"
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4167
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 172.60
Location: Seattle Wa
IntegraMOD version: IM 3

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Juppertje » Mon May 07, 2007 1:35 pm

txs for you answer but password reset check disabled? then theire is nothing to check the password?
Last edited by Juppertje on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

Juppertje
Integra Member
Integra Member
 
Posts: 113
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 12:12 pm
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Juppertje » Mon May 07, 2007 1:54 pm

Okay i have exactly done what you said but and tested it with a user account but still we have the same problem the screen to deblock the accoutn does not appear afther the account is blocked by ctcracker
Last edited by Juppertje on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

Juppertje
Integra Member
Integra Member
 
Posts: 113
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 12:12 pm
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Helter » Mon May 07, 2007 3:49 pm

password reset check disabled, means that you may continue to request a new password. If it is enabled, it will only reset the password once and will not reset it again until you correctly enter it.

these settings will not unlock accounts that are already locked, but will affect accounts locked in the future. Those that are locked now will have to go through the unlocking precedure for both ctracker and phpbb security
Last edited by Helter on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4167
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 172.60
Location: Seattle Wa
IntegraMOD version: IM 3

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Frost » Mon May 07, 2007 10:12 pm

You might want to be careful who you do this for, and think about it before you disable security because users claim they can't get in. There is no reason why any one user, or many for that matter, should have that much of a problem.

Now, I can speak from personal experience (Helter knows what I'm talking about) that sometimes this happens to anyone, and you just kind of get stuck in a rut about it.

But my concern here is from an old member trying to brute force his way into other member's accounts on a trading site. I was admin/owner of several, and this became a quick fad amongst some of the members who liked to cheat and steal. They would get several people to band together and start complaining, then hope the settings would get turned down enough for them to have several tries each on a member's account.

This may not be the case with you, but just a caution,
Last edited by Frost on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.
[size=99px]PhpBB3 Themes[/url] ]PhpBB3 Development Center[/url] [/size]

Frost
Sr Integra Member
Sr Integra Member
 
Posts: 776
Likes: 0 post
Liked in: 0 post
Joined: Wed Sep 13, 2006 1:04 am
Cash on hand: 0.00
Location: Photoshop CS3

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Juppertje » Mon May 07, 2007 11:53 pm

I know i have to be carefull but this are all oficial clubmembers i know them in person and 90% of the people of our board are clubmembers

I tried it my self with a second club account and got blocked so far so good but the screen does not appear to unblock that account i cannot see the code i have to fill in neither the block off user name and email account so it does not work <img>

Manny clubmembers come only 3 or 4 times a year on our board and bij then they forgot theire password and that's why they block them selves
Last edited by Juppertje on Wed Dec 31, 1969 4:00 pm, edited 1 time in total.

Juppertje
Integra Member
Integra Member
 
Posts: 113
Likes: 0 post
Liked in: 0 post
Joined: Sat May 20, 2006 12:12 pm
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: AlaskaMat » Sat Jan 22, 2011 10:59 am

"HelterSkelter" wrote:they can unblock thier own accounts without help. The prob comes when phpbb security and CTracker are both locked. Users will have to go through the unlocking procedure twice.

the easiest way to make this less likely is to go to acp/security/configuration

set "Auto Ban" to "disabled"
set "Login Attempts" to "9"

this should leave CTracker to be the only one blocking login

in acp/CTracker/configuration

set "Spammer Protection" to "disabled"
set "Password Reset Check" to "disabled"

Helter,
I am also having problems with my AKMat site being attacked by Brute Force. Many members are being locked out, so I found this thread and tried to follow your instructions. But when I go to the acp, mine reads "CrackerTracker" as opposed to "CTracker," and I don't have a configuraton selection. Can you explain to me how to achieve the second part of your instructions?

Also, is there a way to determine the IP address that these hack attemps are coming from so that I can block it?

Much thanks

AlaskaMat
Newbie
Newbie
 
Posts: 21
Likes: 0 post
Liked in: 0 post
Joined: Fri Aug 20, 2010 1:43 pm
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Helter » Sat Jan 22, 2011 6:49 pm

Thomas, your running a newer version of CTracker. Your path should be as follows

"HelterSkelter" wrote:they can unblock their own accounts without help. The prob comes when phpbb security and CTracker are both locked. Users will have to go through the unlocking procedure twice.

the easiest way to make this less likely is to go to acp/security/configuration

set "Auto Ban" to "disabled"
set "Login Attempts" to "9"

this should leave CTracker to be the only one blocking login

in acp/CrackerTracker/settings

set "Spammer Detection" to "off"
set "Password Reset Checker" to "Deactivate"


If you continue to have problems let me know.
FYI in December the spam bots broke googles "re-captcha" It is an alternative to our captcha and very popular in phpBB3 boards. This seems to have started a stampede of new attacks on all versions of phpBB. Youll notice I disabled it here and replaced it with a simple question/answer for registrations and downloads. Ill look into IM141 and see if we can do the same thing. I know captcha can be a pain sometimes
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4167
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 172.60
Location: Seattle Wa
IntegraMOD version: IM 3

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: AlaskaMat » Sat Jan 22, 2011 7:40 pm

Got it. Thanks as always for the support, Helter.

AlaskaMat
Newbie
Newbie
 
Posts: 21
Likes: 0 post
Liked in: 0 post
Joined: Fri Aug 20, 2010 1:43 pm
Cash on hand: 0.00

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: Helter » Sun Jan 23, 2011 12:46 am

your welcome as always. You might consider setting one forum as viewable to guests only, make an information post about your site but done let anyone post to it and set all the rest of your forums to viewable to logged in users only and be sure your memberlist is set so guests cannot view it. Then the bots cannot hammer your users accounts. they are probably searching your posts or memberlist to get account names to try to hack via brute force
Always use Protection
Image


Please do not PM for support
User avatar
Helter
Administrator
Administrator
 
Posts: 4167
Likes: 0 post
Liked in: 0 post
Images: 0
Joined: Sat Mar 11, 2006 3:46 pm
Cash on hand: 172.60
Location: Seattle Wa
IntegraMOD version: IM 3

Re: it is impossible for a normal user to deblock his Accoun

PostAuthor: AlaskaMat » Sun Jan 23, 2011 2:13 pm

Ahhh - good advice. I thought I had all my forms set to registered only, but found two that were not. That explains how they were accessing user names.

AlaskaMat
Newbie
Newbie
 
Posts: 21
Likes: 0 post
Liked in: 0 post
Joined: Fri Aug 20, 2010 1:43 pm
Cash on hand: 0.00

Next

Return to IntegraMOD 141

Who is online

Registered users: Bing [Bot], Google [Bot], Majestic-12 [Bot]

cron