Main Menu

New password for Badmovies.org Forum

Started by Allhallowsday, August 05, 2012, 11:42:40 PM

Previous topic - Next topic

Allhallowsday

What is this?  I received an email, the text of which is copied below.  I've not forgotten or ever changed my password: 

Dear Allhallowsday,

This mail was sent because the 'forgot password' function has been applied to your account. To set a new password click the following link:

http://www.badmovies.org/forum/index.php?action=reminder;sa=setpassword;u=1302;code=71c931c9b5

IP: 201.73.178.98

Username: Allhallowsday

Regards,
The Badmovies.org Forum Team.
If you want to view paradise . . . simply look around and view it!

bob

Kubrick, Nolan, Tarantino, Wan, Iñárritu, Scorsese, Chaplin, Abrams, Wes Anderson, Gilliam, Kurosawa, Villeneuve - the elite



I believe in the international communist conspiracy to sap and impurify all of our precious bodily fluids.

dean

Same here. Looks like someone's trying to join the fun.
------------The password will be: Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch

dean

Same I.P too. Incidentally some should move this to the trouble tickets so it gets attention
------------The password will be: Llanfairpwllgwyngyllgogerychwyrndrobwllllantysiliogogogoch

Psycho Circus

Me too, just found it in my spam inbox.  :question:

Trevor

I received nothing like this but it is a bit weird.
We shall meet in the place where there is no darkness.

Andrew

This was someone trying to brute force guess some account passwords.  When that didn't work (the system only allows a few before it temporarily locks out more attempts) it appears they, for some reason, used the forum's forgot password function.

Two possibilities exist.  One is that they hoped the lost password function would allow them to guess a secret phrase and still gain access to the account.  The other is that the attack was carried out by a piece of software, and either by nature or setting it resorts to the lost password function.

The attempts came from a ISP in Brazil.  None of them gained access to any account.  I've now put a permanent block in place, but that's just a temporary measure for anyone who really wants to get into an account.  Please always use a strong password that will resist attempts to guess it.
Andrew Borntreger
Badmovies.org

Allhallowsday

Thank you Andrew

In future, I will post any such problems in the Trouble Ticket section; I didn't even think of it. 
If you want to view paradise . . . simply look around and view it!

Flangepart

"Aggressivlly eccentric, and proud of it!"

BoyScoutKevin

Not to belabor the point, but I got the same message, but it is good to know I am not going mad, as I did wonder if I had asked for a new password, but when I was able to log one with the old password, I just ignored the message.