Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Help Groups for Snitz Forums 2000 Users
 Help: General / Classic ASP versions(v3.4.XX)
 Forum admin account used by spammer
 New Topic
 Printer Friendly
Author Previous Topic Topic Next Topic  

Webbo
Average Member

United Kingdom
982 Posts

Posted - 24 February 2015 :  02:46:24  Show Profile  Visit Webbo's Homepage  Reply with Quote
Early this morning a spam bot managed to use my Admin account to fill my forum full of spam topics/links


Please see screen shot below...


This isn't the first time it has happened, previously it was using a moderators account.

I've got all fixes in place posted on here previously.
The one thing that I have noticed is that the previous account used was account member no. 2 which was set as 'moderator'
Member number 1 is that of the main Admin
Member number 3 is my account, the one that was used on this occasion, set as 'admin'

The previous member number 2 account has been locked for a while now since the last incident, and I have temporarily locked the member number 3 account

There doesn't seem to have been any sign of someone logging in using either account at the time indicating that passwords were used so the spam bot must have been able to post without logging in

Can anyone shed any light on this and hopefully offer a solution?

HuwR
Forum Admin

United Kingdom
20584 Posts

Posted - 24 February 2015 :  05:54:43  Show Profile  Visit HuwR's Homepage
This normally happens if IIS gets reset and the forums app variables are not fully reloaded, although I thought we had plugged that issue

MVC .net dev/test site | MVC .net running on Raspberry Pi
Go to Top of Page

Webbo
Average Member

United Kingdom
982 Posts

Posted - 24 February 2015 :  12:50:26  Show Profile  Visit Webbo's Homepage
That might have been the case as the setup.asp file had to be run this morning as well to load the variables

I'm not aware of IIS being reset though

The previous issue with member number 2 account didn't require setup.asp to be run though.
The spam bot hit us a couple of times and then I locked that account.
It looks as though it is now using no3 account
Go to Top of Page

AnonJr
Moderator

United States
5768 Posts

Posted - 24 February 2015 :  13:49:49  Show Profile  Visit AnonJr's Homepage
I would hazard a guess that whatever the bug, it uses the next active account. Locking #3 is likely to be a temporary solution until the root cause is found.

Do you have access to the IIS logs to see if the server was re-booted or IIS re-started?
Go to Top of Page

Webbo
Average Member

United Kingdom
982 Posts

Posted - 24 February 2015 :  14:32:34  Show Profile  Visit Webbo's Homepage
I can soon find out
Go to Top of Page

bobby131313
Senior Member

USA
1163 Posts

Posted - 24 February 2015 :  15:49:07  Show Profile  Visit bobby131313's Homepage
Patch: http://forum.snitz.com/Forum/topic.asp?TOPIC_ID=67497&whichpage=1

Switch the order of your title tags
Go to Top of Page

Webbo
Average Member

United Kingdom
982 Posts

Posted - 24 February 2015 :  16:39:51  Show Profile  Visit Webbo's Homepage
Thanks Bobby, I don't know why I missed that one, hopefully it will see an end to the issue
Go to Top of Page

bobby131313
Senior Member

USA
1163 Posts

Posted - 24 February 2015 :  18:15:09  Show Profile  Visit bobby131313's Homepage
Ended it for me years ago.

Switch the order of your title tags

Edited by - bobby131313 on 24 February 2015 18:15:32
Go to Top of Page

Webbo
Average Member

United Kingdom
982 Posts

Posted - 25 February 2015 :  04:44:26  Show Profile  Visit Webbo's Homepage
I received the following from our host...

The sever does not appear to have been rebooted. IIS has not reported any system errors which means that it hasn't itself shut down
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20584 Posts

Posted - 25 February 2015 :  06:24:32  Show Profile  Visit HuwR's Homepage
well, if your forum loses its application variables then the only way that can happen is if IIS or your site in particular has been reset or recycled

MVC .net dev/test site | MVC .net running on Raspberry Pi
Go to Top of Page

Webbo
Average Member

United Kingdom
982 Posts

Posted - 25 February 2015 :  12:30:39  Show Profile  Visit Webbo's Homepage
IIS is set to recycle every 1740 minutes which might explain it

Everything has been fine since adding the patch above
Go to Top of Page

Carefree
Advanced Member

Philippines
4207 Posts

Posted - 25 February 2015 :  18:23:22  Show Profile
quote:
Originally posted by HuwR

This normally happens if IIS gets reset and the forums app variables are not fully reloaded, although I thought we had plugged that issue



It's already done in 3.4.07 (before the cookie variables are set).
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.39 seconds. Powered By: Snitz Forums 2000 Version 3.4.07