View Single Post
  #1  
Old 2023-01-18, 06:11 PM
xavier242's Avatar
xavier242 xavier242 is offline
TTD Administrator
TTD Staff
 
Join Date: Dec 2008
Location: a warm place
Icon4 Mandatory password reset due to amount of spam

Regarding the wave of spam lately, from the Staff forum:

Quote:
Ok I did some more research on the link "https://t.me/pump_upp" and other platforms (non-vbulletin) are being spammed also using existing accounts. The consensus is that a data breach happened on some site and that the usernames and passwords were posted somewhere. Therefore it's possibly being caused by users reusing their passwords (and maybe usernames) across different sites.

Thus my proposal is to set vbulletin to require passwords be reset and changed (an option I mentioned above). I suggest we do this on the Registered Users and Registered Users Newbies groups (one time only, unless the spam issue comes back).

For the Admins and Moderators, make sure your password is strong and not reused on any site.
I set all Registers users and Registered Newbies passwords to expire 15 days after they last logged in. I apologize for the inconvenience, but I see no other solution. This is the same solution that was done for about 40 million other forum users on various sites. In 14 days, I'll put it back to passwords not expiring. Per a post on vbulletin.org, this should get most users to change their password.

Please use a strong password with at least one number and uppercase character. Don't reuse it on another site.

xavier242
Reply With Quote Reply with Nested Quotes