Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[SOLVED] A banned user becoming an active user again (by itself)
#1
Hi there
Something very strange has been happen on our forum this week.

An user (spammer) has been posting porn content almost every day, even I had banned him.
Initially I thought I was doing something wrong during the process (that is too simple), because in the next day we got the same user post the same porn content.

Today I checked the Moderator Logs and confirm I had already banned him four times (Mar 23, 24, 26 and 27).

Today I notice him accessing the forum at morning (still banned); afternoon (still banned) and now he was already "unbanned" (of course I banned he again).


So, it seems there is something that he can do and gain back his access. Is there any known vulnerability related to this?

Is there anything I can do to try discover how he are doing that? (becoming "unbanned")


I also noticed he was "reading no permission page" in during the banned status. What does that means?



We are using the MyBB 1.6.16.

Thanks in advance
Micheus
#2
Did you ban the bot permanently? Failing that, check File Verification, I've been seeing similar things happen here recently.
#3
(2015-03-28, 09:47 PM)Nebulon Ranger Wrote: Did you ban the bot permanently?

Sorry if it's a stupid question, but what do you mean for permanently?
I just use the "Ban this user in Mod CP" option in the user profile page. Is there other way?

About the file verification I will check it later - at home - and post a result here. Where I'm now I think don't have correct access to the server, since I'm getting this message: "There was a problem communicating with the MyBB server. Please try again in a few minutes."

Our forum is hosted by SourceForge and we already noticed some limitations before.


/Micheus
#4
(2015-03-28, 09:26 PM)Micheus Wrote: We are using the MyBB 1.6.16.

Why was it posted in a 1.8 support forum in that case?

Anyways, are you sure you're banning that user permamently and noone is lifting the ban? If yes, provide a list of your plugins.

(2015-03-28, 09:47 PM)Nebulon Ranger Wrote: I've been seeing similar things happen here recently.

Where? On this forum? Could you elaborate? I'm mostly interested in how you can notice it without having access to moderator logs. I went through 10 first pages and haven't noticed any duplicate ban.

(2015-03-28, 09:58 PM)Micheus Wrote: Sorry if it's a stupid question, but what do you mean for permanently?
I just use the "Ban this user in Mod CP" option in the user profile page.

Clicking it should bring you to a banning page with a Lift Ban After dropdown, which is by default 1 day, which would match your need to ban him every day.
#5
(2015-03-28, 09:59 PM)Destroy666 Wrote: Why was it posted in a 1.8 support forum in that case?

Anyways, are you sure you're banning that user permamently and noone is lifting the ban? If yes, provide a list of your plugins.
Sorry about the wrong forum. I focused in the security and didn't notice I choose for the wrong version. Could you please move it to the right place?

There is only me managing the forum in these last months.

The plugins list is attached.


(2015-03-28, 09:59 PM)Destroy666 Wrote: Clicking it should bring you to a banning page with a Lift Ban After dropdown, which is by default 1 day, which would match your need to ban him every day.

Yes, I'm using this default value.


Attached Files
.pdf   Plugins.pdf (Size: 29.88 KB / Downloads: 282)
#6
(2015-03-28, 10:09 PM)Micheus Wrote: Yes, I'm using this default value.

Well, then there is nothing to do here. If you're lifting a ban after 1 day, the ban will be lifted after 1 day as expected. Choose another option if you want it to be longer.
#7
Oh, Ok. I catch it.  Blush
So it was me doing something stupid.

I just thought that ban someone was permanently thing. Sorry, have been bother you guys.


Thanks


Forum Jump:


Users browsing this thread: 1 Guest(s)