Password change by himself !!!!

This is the place to report bugs and get support. When posting in this forum, please always provide as much detail as possible.

Please do not report problems with a custom build or custom code in this forum. If you are producing your own build from the source code and have problems or questions, ask in the developer forum, do not report it as a bug.

This is the place to report bugs and get support

When posting in this forum, please try to provide as many relevant details as possible. Particularly the following:

  • What operating system were you running when the bug appeared?
  • What database platform is your site using?
  • What version of mojoPortal are you running?
  • What version of .NET do you use?
  • What steps are necessary to reproduce the issue? Compare expected results vs actual results.
Please do not report problems with a custom build or custom code in this forum. If you are producing your own build from the source code and have problems or questions, ask in the developer forum.
This thread is closed to new posts. You must sign in to post in the forums.
7/13/2012 5:35:05 AM
Gravatar
Total Posts 23

Password change by himself !!!!

Hy all !!

mojoPortal Versione 2.3.8.5 MSSQL
Sistema Operativo Microsoft Windows NT 6.1.7601 Service Pack 1
Informazioni ASP.NET v4.0.30319 Esecuzione in 'Partial Trust'

I had a problem so I went to see the database to find the solution, At this point i look in the user table and i saw that all user password were the same and more worst they are my admin password !!!!!!

At this point i made a test user whit a pasword like 12343567 everything fine i sign  in and out no problem. I enter whit my admin reference and and the same time i open the database  to see if change appears. So i open the user list and menage the new user and i saw that in the field Live Messenger CID was my email and the password field was fill whit black point. I looked back in DB and refresch and the test user password was changed whit my admin password

 

I think is because i used Firefox 14.0 i made the same step, after re change the test user password, with IExplorer and no email in  

Live Messenger CID field and no mask password in his field and no change

 

Strange but now i have to ask everyone to change password and change my too because all know that

Regards

7/13/2012 8:07:41 AM
Gravatar
Total Posts 18444

Re: Password change by himself !!!!

All I can guess is that either your hosting has been compromised and someone has access to your database, or there is custom code like a user sign in event handler that is updating the database or someone put a trigger on a table that changes the data or someone altered a stored procedure and changed the where clause.

I don't see how browser version like Firefox vs IE can be a factor in database changes and I don't see how this could be a bug in mojoPortal, if it was then it would be happening to everyone. Version 2.3.8.5 has been out for quite a while and no-one else has reported any such problem. It does not happen in my testing or in any sites I'm involved with.

7/13/2012 10:37:16 AM
Gravatar
Total Posts 23

Re: Password change by himself !!!!

I know that Im a morrow and dont understand nothing!!! 

sorry but you're right some body is change my little stupid site and i found in the blog comment more then 80 spam i clean everything

i change admin email and pwd  and ,only whit firefox (i also clean his cache cookie remove psw from his database) when i log als admin and visit the user list and menage one user his pwd change like the one from admin

Help Should i reinstall evrything??

 

Thanks for your endless patience

7/13/2012 11:00:04 AM
Gravatar
Total Posts 23

Re: Password change by himself !!!!

So i have try whit opera and safari and no change and whit chrome i have a change like whit firefox

lokk at this picture pls http://www.coroliricoterreverdiane.it/example.gif

you will see my old email and the pwd  

and when i save new pwd will be register!!!

 

Is something to do whit the messenger module???

 

7/13/2012 12:32:32 PM
Gravatar
Total Posts 18444

Re: Password change by himself !!!!

The messenger module does not update the database.

I do not know what is going on with your site. It sounds like possibly someone has altered your database or installed custom code, but I have no way of knowing.

I would make sure you are not allowing any strangers any edit access on your site.

I would check to make sure there is only one file in the folder:

/Setup/ProviderConfig/usersignineventhandlers

and also make sure there is only one file in the folder:

/Setup/ProviderConfig/userregisteredeventhandlers

I would also look around in the database for any triggers that someone may have added

I would check that no-one except you has administrator role

I would change my ftp password

I would use Administration > Security Advisor to make sure your site is configured securely

If you don't know how to do these things I would suggest get a more technical friend to help or hire someone with more technical skills to investigate it.

Possibly its just automatic form populating happening by your browser preferences updating form fields based on previous forms. ie your browser is filling in the form for you automatically based on previous forms and when you save it that is when it updates the database, the browser doesn't update the database it just updates the page, but as soon as you save it updates the database.

See also:

How to disable form autocomplete in Firefox

How to disable form auto complete in Chrome

Hope that helps,

Joe

You must sign in to post in the forums. This thread is closed to new posts.