Hello,
So as some of you have already noticed, we seem to being hit by another wave of bots logging into people's accounts and posting spam on the account's behalf, trying to get people to click on a link for a "dating website." This likely isn't targeted at us, nor is it a problem with the Xenforo forum software, as this same bot has also infiltrated forums running on MyBB and Invision Community.
So far I've configuring ZooVille to capture the posts and make them invisible for normal users. It's possible that some posts my still wind up on the forum. If that is the case, please report them.
Here's what we know, and here's what you'll need to do if you can suddenly no longer login:
This bot is only logging into people's accounts. The bot is not changing people's passwords. It pretty much logs in, makes a spam post, then immediately logs out. So most likely this is either from the LastPass breach, or from a computer virus.
Since it's not changing people's passwords, what I'm doing is forcing a password change on the accounts that have been compromised instead of outright banning them. The user will need to log into their email and will need to set a new password by clicking on the password reset link. I'd also advise changing the password on every single account you've used the same password on.
So as some of you have already noticed, we seem to being hit by another wave of bots logging into people's accounts and posting spam on the account's behalf, trying to get people to click on a link for a "dating website." This likely isn't targeted at us, nor is it a problem with the Xenforo forum software, as this same bot has also infiltrated forums running on MyBB and Invision Community.
So far I've configuring ZooVille to capture the posts and make them invisible for normal users. It's possible that some posts my still wind up on the forum. If that is the case, please report them.
Here's what we know, and here's what you'll need to do if you can suddenly no longer login:
This bot is only logging into people's accounts. The bot is not changing people's passwords. It pretty much logs in, makes a spam post, then immediately logs out. So most likely this is either from the LastPass breach, or from a computer virus.
Since it's not changing people's passwords, what I'm doing is forcing a password change on the accounts that have been compromised instead of outright banning them. The user will need to log into their email and will need to set a new password by clicking on the password reset link. I'd also advise changing the password on every single account you've used the same password on.