Page Index Toggle Pages: [1] 2 3 
Topic Tools
Very Hot Topic (More than 25 Replies) ALERT!! Form Spoofing Detected coming from IP (Read 20,511 times)
Jens Brix Christiansen
YaBB Newcomer
*
Offline



Posts: 26
Location: Frederiksberg, Denmark
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #39 - Dec 4th, 2009 at 1:05pm
Post Tools
deti wrote on Dec 4th, 2009 at 10:56am:
Never use changed files from a single fix! There may be changes in it from another fix that affected other files too. You must always use ALL new files from CVS to get a working actual beta version.

I see the point. Thanks for that.
  
Back to top
 
IP Logged
 
deti
Legacy Dev Team
Development Team
****
Offline



Posts: 2,650
Location: Prien am Chiemsee, Germany
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #38 - Dec 4th, 2009 at 10:56am
Post Tools
@ Jens Brix Christiansen

Huh Sorry I can't confirm.

Please DON'T mix versions!! You are using the YaBB.pl form Branch 2_4_x and the Register.pl from 2.4 (non branch tag 2_4). This can't work!

In the fix this thread is referring to this part of the code you are referring to was NOT changed, but in another fix before! Wink

Never use changed files from a single fix! There may be changes in it from another fix that affected other files too. You must always use ALL new files from CVS to get a working actual beta version.
  

Was immer Du tun kannst
oder erträumst tun zu können,
beginne es.
Kühnheit besitzt Genie,
Macht und magische Kraft.
Beginne es jetzt.
Whatever you can do
or dream you can,
begin it.
Boldness has genius,
power and magic in it.
Begin it now.
J. W. Goethe
Back to top
WWW  
IP Logged
 
Jens Brix Christiansen
YaBB Newcomer
*
Offline



Posts: 26
Location: Frederiksberg, Denmark
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #37 - Dec 4th, 2009 at 9:30am
Post Tools
deti wrote on May 22nd, 2009 at 4:41pm:
New
Languages\English\Error.lng

YaBB.pl
in CVS.

The YaBB.pl in question is version 1.22.2.2. Unfortunately, it has a bug, which was introduced in version 1.22.2.1, and which clobbered my forum when I attempted to use it.

Here is an excerpt from version 1.22 (as released in YaBB 2.4):
Code
Select All
if (-e "$memberdir/memberlist.inactive" && $inactsize > 2 && ($regtype == 1 || $regtype == 2)) {
	&RegApprovalCheck;
	require "$sourcedir/Register.pl";
	&activation_check;
}

my $aprsize = -s "$memberdir/memberlist.approve";
if (-e "$memberdir/memberlist.approve" && $aprsize > 2 && ($regtype == 1 || $regtype == 2) && $yyadmin_alert eq "") {
	&RegApprovalCheck;
} 



Here is the corresponding code in version 1.22.2.2:
Code
Select All
if ($regtype == 1 || $regtype == 2) {
	if (-s "$memberdir/memberlist.inactive" > 2) {
		&RegApprovalCheck; &activation_check;
	} elsif (-s "$memberdir/memberlist.approve" > 2) {
		&RegApprovalCheck;
	}
}  



This crashes when new members register and the settings have a regtype of 1 or 2. Reintroducing the require fixes the problem:
Code
Select All
if ($regtype == 1 || $regtype == 2) {
	if (-s "$memberdir/memberlist.inactive" > 2) {
		&RegApprovalCheck;
		require "$sourcedir/Register.pl";
		&activation_check;
	} elsif (-s "$memberdir/memberlist.approve" > 2) {
		&RegApprovalCheck;
	}
} 



I am not sure where I should report a bug in a CVS version like 1.22.2.2, so I have reported it here. I am willing to learn the proper procedure.
« Last Edit: Dec 4th, 2009 at 9:32am by Jens Brix Christiansen »  
Back to top
 
IP Logged
 
tk
YaBB Newcomer
*
Offline



Posts: 35
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #36 - Jun 6th, 2009 at 5:59pm
Post Tools
This is most often caused by entering your password after it has been changed or generated without refreshing the page your entering your password on.

Follow that?

So, tell your members that if they get that error to refresh the page and enter log in info again. Should fix it.

Programmers, you should make the password pages refresh after resetting passwords and anyplace else applicable.

To test, just re-set password. Don't refresh the page, get the email and paste new password in. Hit enter and you'll get the error. Go back, refresh page, re-enter pass and your in.

Hope this helps.

And if you have a new cookie code wouldn't the new forum just see you as a guest until you log in to get the new cookie?

Tis the way it works on our forum. Even if you was logged into the old forum, doesn't matter. The new forum doesn't see, search for or recognize the old cookie. Just like you came to the board for the first time.

So if you didn't do a fresh install it seems to me renaming the cookies after the update should fix the "already logged in" issues. Yes? As I made a new install in a new location I have not had a problem with the already logged in issues, but seems like an easy fix to me.  Tongue

Should solve the problem for links, shortcuts, favorites or whatever. Without the user doing anything.
« Last Edit: Jun 6th, 2009 at 6:24pm by Jet Li »  
Back to top
 
IP Logged
 
cepheid
Senior Member
****
Offline



Posts: 516
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #35 - May 31st, 2009 at 12:38am
Post Tools
That's just another manifestation of "you are already logged in," which has been discussed earlier in this thread.
  
Back to top
WWW  
IP Logged
 
TonyL
Junior Member
**
Offline



Posts: 99
Location: Ontario, Canada

None
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #34 - May 30th, 2009 at 9:47pm
Post Tools
That is what I am talking about.LoneWebSurfer wrote on May 30th, 2009 at 9:26pm:
links saved to your pc.. such as favorites.. or a shortcut to the site saved on desktop etc. etc.
is my guess.

  
Back to top
 
IP Logged
 
LoneWebSurfer
Past Team Members
Offline



Posts: 1,279
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #33 - May 30th, 2009 at 9:26pm
Post Tools
links saved to your pc.. such as favorites.. or a shortcut to the site saved on desktop etc. etc.
is my guess.
« Last Edit: May 30th, 2009 at 9:26pm by LoneWebSurfer »  

Closed all my sites due to lack of Internet access
Back to top
WWW  
IP Logged
 
Rad_one
Full Member
***
Offline



Posts: 333
Location: Newport Beach, California
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #32 - May 30th, 2009 at 9:23pm
Post Tools
what "links" are you talking about?
  
Back to top
 
IP Logged
 
TonyL
Junior Member
**
Offline



Posts: 99
Location: Ontario, Canada

None
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #31 - May 30th, 2009 at 11:21am
Post Tools
I have been able to duplicate the ALERT! Form Spoofing Error coming from IP address. If the user has a link to their forum before the upgrade saved on their computer and they are logged in for keeps. If they just close their browser and don't log out and the next time they want to login they use the saved link they will get the form spoofing error. To correct the problem users must delete the links, login to their forum and save a new link.
Tony
  
Back to top
 
IP Logged
 
deti
Legacy Dev Team
Development Team
****
Offline



Posts: 2,650
Location: Prien am Chiemsee, Germany
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #30 - May 27th, 2009 at 6:26pm
Post Tools
JonB wrote on May 26th, 2009 at 11:03pm:
could this behavior be related to this fix?

No.
  

Was immer Du tun kannst
oder erträumst tun zu können,
beginne es.
Kühnheit besitzt Genie,
Macht und magische Kraft.
Beginne es jetzt.
Whatever you can do
or dream you can,
begin it.
Boldness has genius,
power and magic in it.
Begin it now.
J. W. Goethe
Back to top
WWW  
IP Logged
 
JonB
YaBB Administrator
YaBB Next Team
Operations Team
Beta Testers
Support Team
*****
Offline



Posts: 3,821
Location: Land of the Blazing Sun!

YaBB 2.6.1
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #29 - May 26th, 2009 at 11:03pm
Post Tools
could this behavior be related to this fix?

http://www.yabbforum.com/community/YaBB.pl?num=1241087649

Thanks
Smiley
  

I find your lack of faith disturbing.
Back to top
IP Logged
 
deti
Legacy Dev Team
Development Team
****
Offline



Posts: 2,650
Location: Prien am Chiemsee, Germany
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #28 - May 22nd, 2009 at 4:41pm
Post Tools
New
Languages\English\Error.lng

YaBB.pl

in CVS.

I you do now what you did, OH Eng, you will see this:
"You are logged in already with the username: "....
  

Was immer Du tun kannst
oder erträumst tun zu können,
beginne es.
Kühnheit besitzt Genie,
Macht und magische Kraft.
Beginne es jetzt.
Whatever you can do
or dream you can,
begin it.
Boldness has genius,
power and magic in it.
Begin it now.
J. W. Goethe
Back to top
WWW  
IP Logged
 
OH Eng
Past Team Members
Documentation Team
Offline



Posts: 4,026
Location: Pensacola, Florida USA
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #27 - May 22nd, 2009 at 2:24pm
Post Tools
deti wrote on May 21st, 2009 at 6:58pm:
Hmmmm, can someone tell me how to reproduce this error on this forum here? If I use it as normal nothing abnormal happen to me Huh


The only way I can force the error here is to log in, go one screen forward (click on a board), then use browser back button to get to login screen and click login (while already logged in).  Maybe a way to determine if this is a case of double-logging in or not would be the change the error for that to "You're already logged in" instead of Form Spoofing. 



  

 
Back to top
 
IP Logged
 
Jet Li
Legacy Dev Team
Development Team
****
Offline



Posts: 6,588
Location: Hong Kong
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #26 - May 22nd, 2009 at 10:56am
Post Tools
TonyL wrote on May 22nd, 2009 at 10:48am:
Check you error log and you will see that it does happen on this site.

haha. We have not access to Error Log here, only Corey Chapman. Tongue We are only YaBB 2 Developer.
  

PM me for YaBB Installation Service
Back to top
WWWGTalkFacebook  
IP Logged
 
TonyL
Junior Member
**
Offline



Posts: 99
Location: Ontario, Canada

None
Re: ALERT!! Form Spoofing Detected coming from IP
Reply #25 - May 22nd, 2009 at 10:48am
Post Tools
Check you error log and you will see that it does happen on this site. It just happened to me. This is the error it returned. I don't have any isea what I did to cause this error.
ALERT!! Form Spoofing Detected coming from IP address: 75.119.251.253
Tony

  
Back to top
 
IP Logged
 
Page Index Toggle Pages: [1] 2 3 
Topic Tools
 
  « Board Index ‹ Board  ^Top