• Xenforo forums over the past few months have been seeing spam posts from existing user accounts. Bots hitting forums using lists of emails/passwords leaked elsewhere. We strongly recommend that all users change their password ASAP.

Concerned, please advise.

Ash600

Of dust and shadows
SF Creative
SF Supporter
#21
Yes, but looking into things here on my end I'm seeing that breach, and that my password to this site was compromised 6 months ago. I'm wondering if the most recent upgrade to Xenforo is something that can rectify those shenanigans as well.
One would've thought, though there's always the possibility of an update being flawed and so allowing for exploits. So it could be a case of a security patch being rolled out.

Perhaps it's something that either @Freya or @Walker may care to address?
 

Freya

Loves SF
Admin
SF Author
SF Supporter
#22
We definitely need to look at updating our xenforo version but that's a complex multi-layer affair as the new version has features we would need to turn off (such as reddit style upvoting and down voting of responses) and when we last updated the version it completely broke chat and took several days of sleepless nights of coding to make it work. Our chat is heavily customised, plus we would want to update chat also as I'm not sure our current version would work with a newer xenforo etc. Essentially, it's something we need a staging site for, developers in place, and at least a couple of months of rigorous testing or it will be an absolute horror show.

We do have daily health checks on our own forum software, file monitoring for any new changes to forum files plus frequent security scanning for any malware or injections.

Speaking of testing - I can't see my own banner - is it generally visible to people?

Further speaking of testing, ash's tag is the first alert I've had here. Please can someone tag me in the next post? If I'm not getting alerts then that needs sorting pronto. @Harmony I didn't get your alert - did you get this one?

2FA is a good idea but SO many people here use fake everything that most people probably can't enable it.
 

Ash600

Of dust and shadows
SF Creative
SF Supporter
#23
We definitely need to look at updating our xenforo version but that's a complex multi-layer affair as the new version has features we would need to turn off (such as reddit style upvoting and down voting of responses) and when we last updated the version it completely broke chat and took several days of sleepless nights of coding to make it work. Our chat is heavily customised, plus we would want to update chat also as I'm not sure our current version would work with a newer xenforo etc. Essentially, it's something we need a staging site for, developers in place, and at least a couple of months of rigorous testing or it will be an absolute horror show.

We do have daily health checks on our own forum software, file monitoring for any new changes to forum files plus frequent security scanning for any malware or injections.

Speaking of testing - I can't see my own banner - is it generally visible to people?

Further speaking of testing, ash's tag is the first alert I've had here. Please can someone tag me in the next post? If I'm not getting alerts then that needs sorting pronto. @Harmony I didn't get your alert - did you get this one?

2FA is a good idea but SO many people here use fake everything that most people probably can't enable it.

Well now, isn't this quite the pickle we seem to be in. The issues that a rolled out new version of xenforo can bring vs the glitches that the current one offers such as (amongst others) security exploits and what seems to be erratic notification alerts for the site owner....

I won't peform a test tag considering my last attempt was successful. Best to let another member give it another shot so it'll be more of an unbiased and therefore representative test. Because who knows, it may just have been down to my unique tagging methods.

Regarding your banner, don't worry it's clearly visible in all it's sparkling glory
 
#25
Interestingly, the edit window on the post above closed after only 2 minutes.

While the select-name-from-the-drop-down-window method of tagging is the most reliable, I can't use that (at least for now) because I have scripts turned off. If previous taggers also didn't use that method, that might explain why you didn't see the tags, though strictly speaking, if you correctly spell and capitalize a name in a tag, it should work.
 

Freya

Loves SF
Admin
SF Author
SF Supporter
#29
Regarding the banner I meant the banner notice I put at the top of the site asking people to change their password which I can't see even in incognito but that the admin panel insists is enabled.

I did not get May's tag so that's troubling. I've no clue what to do about that so I'll have to try to escalate it to a higher power. Unsure why Ash's tag magically alerted me if other tags are not.

Re the edit window, this has to be set by node I think so it might just be messed up on this node. I can check that. Is there a glitch with quoting? I didn't understand that part....

Thanks for all assistance!
 
#31
Regarding the banner I meant the banner notice I put at the top of the site asking people to change their password which I can't see even in incognito but that the admin panel insists is enabled.
I recall seeing that earlier, but I can't see it now. Maybe that's related to having javascript turned off?

I did not get May's tag so that's troubling
If @Angie and @Harmony can confirm the method they used in tagging, that would probably narrow things down.
 

Harmony

Well-Known member
SF Supporter
#32
So the issues seem to be with tagging using the @ (I've attempted to tag you again above Freya) as it might just be hit or miss. We'll see.

There has been an ongoing problem with using "Reply" when responding to a user's post.
 

Freya

Loves SF
Admin
SF Author
SF Supporter
#33
So the issues seem to be with tagging using the @ (I've attempted to tag you again above Freya) as it might just be hit or miss. We'll see.

There has been an ongoing problem with using "Reply" when responding to a user's post.
Attempting to reply to you with reply. From what I can see from your reply post it seems like it truncated it and maybe didn't let you type?

I got your tag alert this time - did you do it differently?

Thank you!
 

Ash600

Of dust and shadows
SF Creative
SF Supporter
#34
Interestingly, the edit window on the post above closed after only 2 minutes.
I noticed that myself the other day but on a different thread. So there could be a variable time out for editing posts issues as well?

I'm having the same issue noted here by Livelife. See my above response to May after using 'Reply' in an attempt to respond. That should properly illustrate it for you @Freya
That's something that I've noriced happening with other members on other threads. It's an occurence that I've seen going on for quite some time though it does look like a random event.

Regarding the banner I meant the banner notice I put at the top of the site asking people to change their password
Oh yes, that's there when one has to log in. Been there for around the last 10 days or so.

Unsure why Ash's tag magically alerted me if other tags are not.
That's because prior to tagging you, I lit two josticks and drew a pentagram on floor.
 

Freya

Loves SF
Admin
SF Author
SF Supporter
#38
Using drop-down to tag @Freya
I have this tag. I don't have the previous tag. Regarding editing I think maybe being in an extra user group e.g supporter or creative might be overriding something, but it should override it everywhere not just here. @Ash600 (done with dropdown) can you edit in other forums?
 

Ash600

Of dust and shadows
SF Creative
SF Supporter
#39
I have this tag. I don't have the previous tag. Regarding editing I think maybe being in an extra user group e.g supporter or creative might be overriding something, but it should override it everywhere not just here. @Ash600 (done with dropdown) can you edit in other forums?

I've just made a test post on another forum, and the edit tab is there.
That user gp (in my case creative) as I recall was the reason why I was completely blocked from accessing the faith/religion section. Either that or someone hung some garlic over the entrance
 

Please Donate to Help Keep SF Running

Total amount
$20.00
Goal
$255.00
Top