Memberlist Function DISABLED

  • WELCOME TO THE NEW SERVER!

    If you are seeing this you are on our new server WELCOME HOME!

    While the new server is online Scott is still working on the backend including the cachine. But the site is usable while the work is being completes!

    Thank you for your patience and again WELCOME HOME!

    CLICK THE X IN THE TOP RIGHT CORNER OF THE BOX TO DISMISS THIS MESSAGE
Status
Not open for further replies.

Scott Greczkowski

Welcome HOME!
Original poster
Staff member
HERE TO HELP YOU!
Cutting Edge
Sep 7, 2003
102,581
25,915
Newington, CT
As a security percaution I have disabled the Memberlist function here on SatelliteGuys.

As you might have heard over the weekend Gawker had its userlist stolen which included all the passwords for all Gawker accounts (Gawker is parent company of sites like Gizmodo, Lifehacker and a few others.)

The usernames and passwords were posted to the internet via a number of torrent sites.Over a million accounts were posted.

To protect people here at SatelliteGuys who might use the same password they used on the Gawker sites I have disabled the memberlist to keep bots from scanning for matching user account names here and then using your password gaining full control of your account.

If you do use the same password here that you do (or did) use on the Gawker sites I highly recomend that you consider changing your password here.

Thanks for your understanding!
 
Thanks for watching out for us, Scott. Will it be enabled at some future point?
 
Hmmmm. Not happy. But I can't see a way around the necessity, either.
 
Doubtfull. In researching it found out that Bot's are harvesting the data and spaming members by email and also via PM.

In addition bots are trying every min to access the memberlist function trying to download it to exploit the Gawker accounts and passwords. In talking with some vBulletin guys I wouldn't be surprised if the feature is removed entirely from the next version of the software as it is that much of a security hole.
 
It was a nice feature but oh well.
 
Fully understood, but it sucks. TOo bad we couldn't find a way to just make it viewable by pub members....
 
There is no sercurity level settings for it unfortunately, its eaither on or off.

Looking at the logs this morning it appears bots from russia and china tried accessing it over 2000 times in an hour.
 
Maybe once a month you could post a "top 100" posters in the Pub? Just names and post counts?
 
Status
Not open for further replies.

Users Who Are Viewing This Thread (Total: 0, Members: 0, Guests: 0)

Who Read This Thread (Total Members: 1)

Latest posts