Page 1 of 1

exceeded login attempts?

Posted: Mon Feb 14, 2011 6:20 pm
by AJOwens
I haven't logged in for weeks. Just now, I typed my username and password once, and was told I'd exceeded my login requests and had to decipher the code in a graphic.

Is there a bug, or is somebody trying to hack in as me? (If so, they're lousy hackers - my password is not a masterpiece of security.)

Also, that graphic is murder to figure out!

Re: exceeded login attempts?

Posted: Mon Feb 14, 2011 6:24 pm
by fluffy
I've been having that lately as well.

Re: exceeded login attempts?

Posted: Mon Feb 14, 2011 6:32 pm
by JonPorobil
I haven't had it, but Signboy was complaining about it in the chatroom.

Re: exceeded login attempts?

Posted: Mon Feb 14, 2011 8:06 pm
by Billy's Little Trip
I haven't had that issue yet.

Re: exceeded login attempts?

Posted: Mon Feb 14, 2011 9:03 pm
by Caravan Ray
Billy's Little Trip wrote:I haven't had that issue yet.
That is because you have not actually logged out for the past 4 years.

Re: exceeded login attempts?

Posted: Mon Feb 14, 2011 9:43 pm
by JonPorobil
Billy's Little Trip wrote:I haven't had that issue yet.
PHEW! That's a load off of everyone's minds. Thanks for not leaving us in suspense, dude.

Re: exceeded login attempts?

Posted: Mon Feb 14, 2011 9:45 pm
by BBABM
I had that problem too, but I was trying to sign in on a different ISP... And kinda assumed tha t it was because of that... But I agree that the graphic is super hard to figure out

Re: exceeded login attempts?

Posted: Tue Feb 15, 2011 12:00 am
by Billy's Little Trip
Generic wrote:
Billy's Little Trip wrote:I haven't had that issue yet.
PHEW! That's a load off of everyone's minds. Thanks for not leaving us in suspense, dude.
No problem. Sometimes people ask me, hey BLT, how is it that you give and you give and you give, then after that, you give some more? It's simple really, it's because I'm a giver.

Re: exceeded login attempts?

Posted: Tue Feb 15, 2011 12:06 am
by fluffy
ugh, don't make me think about goatse

Re: exceeded login attempts?

Posted: Tue Feb 15, 2011 9:16 am
by Billy's Little Trip
no :shock:

Re: exceeded login attempts?

Posted: Wed Feb 16, 2011 9:17 am
by JonPorobil
Hey, this issue just happened to me. The captcha image was kind of unusual, and had some floating bits that were the same color as the letters, which made it difficult to read, but I still figured it out relatively quickly.

Is PhpBB mishandling cookies, or something?

Re: exceeded login attempts?

Posted: Wed Feb 16, 2011 10:08 am
by fluffy
From the logs it looks like there might actually be someone trying to brute-force their way in using existing usernames. There are a few IP addresses which have had hundreds of login attempts over the last couple days. However, it's hard to tell if the worst ones are legitimate users who just have a badly-set-up auto-login thing or if they're actively reading the forum looking for potential victims or the like, so I'm not ready to IPban them just yet.

As far as the captcha, phpBB's captcha system is pretty notoriously awful. Either it's too hard for humans or it's too easy for bots. Personally I think it should just be disabled entirely, or replaced with reCaptcha or something.

Re: exceeded login attempts?

Posted: Thu Feb 17, 2011 12:21 am
by Billy's Little Trip
They're after our music! It's 2012! It wants our music! I say we give it to it so it leaves peacefully.

....then when it's leaving, we kill it...with our music. irony, Foster's

Image

Re: exceeded login attempts?

Posted: Sat Apr 02, 2011 12:19 pm
by jack
This just happened to me too. I thought maybe my account got hacked. EDIT: Just read fluffy's synopsis. That sucks. Stupid hax0rz.

Re: exceeded login attempts?

Posted: Sat Apr 02, 2011 2:36 pm
by Lunkhead
It's happened to me every time I've logged in for the last few weeks. My guess is the admins have it set to force people to enter the CAPTCHA on login in order to combat all the spam that the boards had been getting in the last few months. EDIT: just read fluffy's synopsis. Dang spammers...

Re: exceeded login attempts?

Posted: Sat Apr 02, 2011 2:39 pm
by Manhattan Glutton
I just assumed someone was trying to log in as me because, hey, who doesn't want to be me? But now that you guys have reported the problem too, I don't feel as special. Specialer than BLT, of course, though.

Re: exceeded login attempts?

Posted: Mon Apr 04, 2011 8:37 pm
by Spud
Hey, it fucking happens to me, too. I don't think we've changed anything. It's phpbb responding automatically to the attacks that fluffy mentioned. Actually, I think that's pretty cool.

Re: exceeded login attempts?

Posted: Fri Apr 08, 2011 12:27 pm
by roymond
What man do we have to make beaten to hear Caravan Ray?

Re: exceeded login attempts?

Posted: Sat Apr 09, 2011 10:20 am
by Spud
Not understanding your question, Roymond, nor what it is doing in this thread...