Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
Who's Online
3 Registered (gliderdad, Island Piper, 1 invisible), 20 Guests and 17 Spiders online.
Key: Admin, Global Mod, Mod
Top Posters
Gizmo 11707
Rick 7567
Ian 4107
Mark S 3983
ntdoc 3114
Sirdude 2041
jgeoff 1882
David Dreezer 1759
driv 1569
AllenAyres 1530
Latest Photos
Carrie - So Very
Testing
Test Photo
4TH of July at the river!
Test shots from D300 part 3
Page 1 of 2 1 2 >
Topic Options
Rate This Topic
#216259 - 08/06/08 09:27 AM 7.3 exploit - Use one email address to create multiple accounts.
markeedragon Offline
newbie

Registered: 05/07/06
Posts: 31
When you have the option turned on to verify a users email address before they can post. This feature is working properly. But we have found that spammers are now creating the accounts. Verifying them. Then they go and change their email address in their profile. It does not reverify the email address. The result is that they can put anything in there and it will take it. They then go on to create more new accounts using the original email address they just used previously.

I'm pretty sure the spammers have scripted this as we are getting 20 or so of these per day where they create an account then change the email address afterwards.

My suggestion would be a reverification of an email address to complete an email change. That will stop this exploit from happening. It also might be good to log what then original email address was that setup the account.

Top
#216264 - 08/06/08 02:02 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: markeedragon]
AllenAyres Moderator Offline

***

Registered: 12/29/03
Posts: 1530
Loc: Texas
hmm... I thought we did that. Maybe it was .classic
_________________________
- Allen
- ThreadsDev | PraiseCafe

Top
#216265 - 08/06/08 02:30 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: AllenAyres]
blaaskaak Offline


Registered: 08/30/06
Posts: 1218
Loc: Breda, NL
I remember from "way back" it was done.

A change of main e-mail address always resulted in a new password, so you had to put in something valid, or it was a no-go.


Edited by blaaskaak (08/06/08 02:30 PM)
_________________________

Top
#216269 - 08/06/08 05:01 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: blaaskaak]
Thelockman Offline
enthusiast

Registered: 02/10/07
Posts: 263
Loc: Pennsylvania
That was in classic that made you verify again at each email change, threads just lets you change it after verified the first time.
_________________________
Beagle World - A forum for those who are owned by beagles.
Track Thunder - The Unofficial Racing Forum

Top
#216272 - 08/06/08 08:02 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: Thelockman]
Sirdude Moderator Offline


Registered: 04/19/07
Posts: 2041
Loc: SoCal, USA
i think we should put this in 7.3.2, since it should be coming out soon..

i'm gonna change my board software for this (due to your report), because it shouldn't be allowed.. imho..
_________________________

A taxpayer voting for Obama is like a chicken voting for Colonel Sanders.

Top
#216273 - 08/06/08 08:19 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: Sirdude]
Gizmo Moderator Offline


Registered: 06/04/06
Posts: 11707
Loc: Portland, OR; USA
I had this as a feature request somewhere some time ago; I figured it got added in :shrug:...
_________________________
UGN Security, Elite Web Gamers & VNC Web Design Owner
Longtime UBB Supporter, UBB7 Beta Tester & Resident Post-A-Holic

Top
#216275 - 08/06/08 08:48 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: Gizmo]
Sirdude Moderator Offline


Registered: 04/19/07
Posts: 2041
Loc: SoCal, USA
nope.. you didn't do enough leg humping before release date laugh
_________________________

A taxpayer voting for Obama is like a chicken voting for Colonel Sanders.

Top
#216277 - 08/07/08 07:01 AM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: Sirdude]
Gizmo Moderator Offline


Registered: 06/04/06
Posts: 11707
Loc: Portland, OR; USA
<snicker> Rickypooh is a busy guy, probably overlooked it :x...
_________________________
UGN Security, Elite Web Gamers & VNC Web Design Owner
Longtime UBB Supporter, UBB7 Beta Tester & Resident Post-A-Holic

Top
#216382 - 08/11/08 01:37 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: Gizmo]
Rick Administrator Offline

*****

Registered: 06/04/06
Posts: 7567
Loc: Aberdeen, WA
I can get this in, but my only thought is how to handle a fat-fingered email address. If you change your email, but make a typo, then you're not going to be able to validate the new email address since you won't get it and thus be locked out of your account.

I guess it just becomes a matter of contacting the admin at that point, but was looking for a more elegant solution.
_________________________
UBB.threads™ Developer
My Personal Website · StogieSmokers.com

Top
#216386 - 08/11/08 02:36 PM Re: 7.3 exploit - Use one email address to create multiple accounts. [Re: Rick]
AllenAyres Moderator Offline

***

Registered: 12/29/03
Posts: 1530
Loc: Texas
I believe that's how we handled it before.
_________________________
- Allen
- ThreadsDev | PraiseCafe

Top
Page 1 of 2 1 2 >


Shout Box

Recent Topics
[7.3.x] Ignore link showed in userprofile for global moderators
by blaaskaak
Today at 01:27 PM
[7.3.x] Database password shown in adminlogs...
by blaaskaak
Today at 10:24 AM
7.3.1 Flood protection
by MattUK
Today at 03:55 AM
Changing title of forum
by Baby Boomer
Yesterday at 07:38 AM
Disable PM's for one group
by Musky
Yesterday at 07:10 AM
Forum Stats
4026 Members
33 Forums
30883 Topics
156827 Posts

Max Online: 978 @ 06/24/07 08:19 PM