Previous Thread
Next Thread
Print Thread
Hop To
Joined: Jul 2005
Posts: 45
M
mig
Offline
newbie
newbie
M Offline
Joined: Jul 2005
Posts: 45
Hi all,

We received an email from a member, saying they'd received over 100 'request for password' emails from our system, and due to the annoyance of this, they wished to be deleted from our database. We obliged the request but it's left us wondering how many other members might be affected similarly.

We're running 7.5.9

I suppose it was some rotten robot code responsible. Would anyone be able to please advise if there a way in the CP that would allow us to limit the number of password requests to a single user that is permitted within a given time frame? If not, is there any other method that would work to prevent this sort of thing? I've peeked around in the CP, admin manual and tried a quick search here but didn't spot anything.

Any thoughts would be greatly appreciated!
mig

Joined: Jun 2006
Posts: 16,299
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,299
Likes: 116
Do you have the ability to browse the mail log from your mail server? You can validate exactly how many emails left your system to this user if so. If someone other than him requested a new password it was likely either a bot or another malicious user trying to get access to his account (though I'm not sure what they thought requesting a new password would accomplish).


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Jul 2005
Posts: 45
M
mig
Offline
newbie
newbie
M Offline
Joined: Jul 2005
Posts: 45
Hi Gizmo,

Yes, I think I do have the ability to browse the mail log. I haven't been in there in, well, years now so I'll have to muddle my way through. That sounds worth checking at least to validate what occurred. I'm guessing it was a dumb bot.

Thanks for the suggestion - I appreciate your reply!!
mig

Joined: Jun 2006
Posts: 16,299
Likes: 116
UBB.threads Developer
UBB.threads Developer
Joined: Jun 2006
Posts: 16,299
Likes: 116
I was talking with Isaac last night and he made a good observation, it's possible that there could have been a server hiccup (aka the page wasn't loaded) and an impatient user could have hit the refresh button during a page load of the forgot password system, which could also result in multiple messages being sent to the user as well (though, the mail log should be able to tell us how many messages where actually sent to a user, what IP address requested the new password link, and with the IP you can see if it was any of your legit users by comparing via the member management tool in the CP).


I am a Web Development Contractor, I do not work for UBBCentral. I have provided free User to User Support since the beginning of these support forums.
Do you need Forum Install or Upgrade Services?
Forums: A Gardeners Forum, Scouters World
UBB.threads: UBBWiki, UBB Styles, UBB.Sitemaps
Longtime Supporter & Resident Post-A-Holic
VNC Web Services: Code Modifications, Upgrades, Styling, Coding Services, Disaster Recovery, and more!
Joined: Dec 2003
Posts: 6,562
Likes: 78
Joined: Dec 2003
Posts: 6,562
Likes: 78
If it were me, I would test it for myself; meaning just log out and request a lost password.

Even though it will send you an email with a temporary password, it is just that; you can ignore the new password and continue to use the original one.

I don't doubt the user had multiple emails sent by some fluke but 100 is a lot. Possibly he only had a few to many but 100?.

But anyway the software is designed to send only one email per request.


Blue Man Group
There is no such thing as stupid questions. Just stupid answers

Link Copied to Clipboard
ShoutChat
Comment Guidelines: Do post respectful and insightful comments. Don't flame, hate, spam.
Recent Topics
Bots
by Outdoorking - 04/13/2024 5:08 PM
Can you add html to language files?
by Baldeagle - 04/07/2024 2:41 PM
Do I need to rebuild my database?
by Baldeagle - 04/07/2024 2:58 AM
This is not a bug, but a suggestion
by Baldeagle - 04/05/2024 11:25 PM
spam issues
by ECNet - 03/19/2024 11:45 PM
Who's Online Now
2 members (Ruben, Nightcrawler), 411 guests, and 171 robots.
Key: Admin, Global Mod, Mod
Random Gallery Image
Latest Gallery Images
Los Angeles
Los Angeles
by isaac, August 6
3D Creations
3D Creations
by JAISP, December 30
Artistic structures
Artistic structures
by isaac, August 29
Stones
Stones
by isaac, August 19
Powered by UBB.threads™ PHP Forum Software 8.0.0
(Preview build 20230217)