"Why am i not staying logged in?"

Started by Serika, February 13, 2011, 09:33:34 PM

Previous topic - Next topic


If you set your login cookie to never expire like i do, you may have noticed you keep getting logged out lately. I am sad to say this looks like a new bot, one that just hangs around the forum all day trying to guess passwords.

I keep an eye on the forum's error log, which records stuff like incorrect passwords. You can tell if it's a hacking attempt if the same IP has password errors for multiple user names, all in the span of an hour no less. That is what is happening. I believe the bot scans for names, tries to guess a password, and when it is wrong this causes your login to expire.

I would love to just ban it, but like all new bots it changes it's IP frequently.

1. Make sure you have a strong password, caps, lower case, and numbers. At least 10 digits.

2. Don't use something dumb like a ZIP code for your password.

3. Your password for this site should not be the same as other sites you go to.

4. If you get hacked, try to contact me and i will try to get you a new password.
New password, huh? Well, I have a so-called strong password and it didn't stop this new bot... I guess I ought to change it to something longer or something.   :S
I know. This shit just makes me angry. Virus and bot makers are ruining the internet.

I don't think there is anything we can do to get rid of this either. Not unless it makes it's IP static.
Gotta love proxies, eh?   :lol:

So much for at least 10 letters and cap letters and numbers being a strong password... Oh well...
Apparently, changing my password had no effect at all. Maybe I didn't change it right or something, but I was again, logged out this morning.
I haven't been logged out as yet... but maybe it's going for figures of higher authority... *points at Star and Serika*... my password is what I would call fairly strong... but as for ideas on how to combat this felonious bot... I dunno  :crying:


It is clear to me now that this is not simply a case of password strength; I just got logged out again and this time, whenever I tried to log back in, it kept telling me the password was wrong, even though it was the right password.

It seems to be something that has damaged the "Forever" login feature as I can log in for an hour and it lets me. And my password, I'd changed it to the strongest one I could possibly imagine.   :S

EDIT: Ah... I see what it is... It's not the "Forever" feature; I just needed to clear out my cookies. n_n

It should be *as* fixed as possible, I guess then.

EDIT 2: Serika, changing my password has had no effect. I've changed it three times and it still continues. If anyone else is suffering from the same problem, it might very well be that changing passwords does not help.
