User account activiation
5 posters
Page 1 of 1
User account activiation
Hi
I am administrator on a forum where I have set preferences so that any new user accounts need to be validated by an administrator before they can be activated.
Today I have had 2 people register accounts, I have received notifications to my personal email account informing these accounts have been registered and are awaiting activation. I did not in either case click the link in the email to activate these accounts and yet both accounts have been activated.
I created a dummy account for myself to try and test what is going on, but was unable to log in with this account until I had activated it.
Is there anyway people would be able to bypass the account activation process?
I am administrator on a forum where I have set preferences so that any new user accounts need to be validated by an administrator before they can be activated.
Today I have had 2 people register accounts, I have received notifications to my personal email account informing these accounts have been registered and are awaiting activation. I did not in either case click the link in the email to activate these accounts and yet both accounts have been activated.
I created a dummy account for myself to try and test what is going on, but was unable to log in with this account until I had activated it.
Is there anyway people would be able to bypass the account activation process?
Re: User account activiation
No, there's no way to bypass it. Are you sure it's on 'Admin' and not 'User'?
Re: User account activiation
Definitely set to 'Admin'. I registered a dummy account myself as a test and was unable to access without doing the validation. This was after I had had one 'unauthorised' registration. A few minutes later I noticed another person had managed to register an account and it had also been activated.Illest wrote:No, there's no way to bypass it. Are you sure it's on 'Admin' and not 'User'?
The first person who registered was a user whose account I had deleted a couple of days ago, so I wondered if by re-registering under the same username they could have bypassed authorisation. But the second person to register had not had an account before and were using a completely new username.
Re: User account activiation
Please provide your forum link so I can test it out myself.
Thanks in advance.
Thanks in advance.
Re: User account activiation
That's strange because it requires you to activate my account before I can login, which is what you want but you said it's not doing it for other members?
Re: User account activiation
Two people definitely managed to register without my having activated them. The other thing I noticed when I first went to the administration panel to check my settings was that it was set to 'simple' rather than 'advanced' (I always have it set to 'advanced').
Could someone have hacked my account? Even if they had (unlikely), the permissions for new users were still set to only allow 'admin' activation.
I am going to change setting to 'allow new members' - no, as an extra measure for the moment and monitor what happens.
Could someone have hacked my account? Even if they had (unlikely), the permissions for new users were still set to only allow 'admin' activation.
I am going to change setting to 'allow new members' - no, as an extra measure for the moment and monitor what happens.
Re: User account activiation
That's odd too because your preferences aren't supposed to change.
And that's a good idea. But I would enable re-authentication into the ACP just for more security.
You can do this by going to ACP => General => Forum => Security => Confirm password to administration access : Yes
And that's a good idea. But I would enable re-authentication into the ACP just for more security.
You can do this by going to ACP => General => Forum => Security => Confirm password to administration access : Yes
Re: User account activiation
Thank you. I have done that.
I will monitor the situation. Hopefully there will be no further irregular activities.
I will monitor the situation. Hopefully there will be no further irregular activities.
Re: User account activiation
Are you the founder of the forum? Also are there other administrators?
Lost Founder's Password |Forum's Utilities |Report a Forum |General Rules |FAQ |Tricks & Tips
You need one post to send a PM.
You need one post to send a PM.
When your topic has been solved, ensure you mark the topic solved.
Never post your email in public.
Re: User account activiation
Hi - yes I am the founder of the forum. I have one other administrator, but he also 100% did not activate these accounts. (He is also tech smart, so he would not have accidentally clicked any activation link by mistake).SLGray wrote:Are you the founder of the forum? Also are there other administrators?
For added security we decided to temporarily remove his admin status in case that could be an issue.
Re: User account activiation
Hello,
There's a feature in the admin panel that tracks all administrators' activities:
AP > General > Security > Administration:
Check if there's an action : "User updated"
There's a feature in the admin panel that tracks all administrators' activities:
AP > General > Security > Administration:
Check if there's an action : "User updated"
Jophy- ForumGuru
- Posts : 17924
Reputation : 836
Language : English
Location : Somewhere
Re: User account activiation
Okay, I've looked at the list of Administration actions. I have 'User updated ' showing for 6th when I gave admin status. It shows again for last night when I removed that admin status. There are no Administration actions showing that are not under my username. There are no actions listed showing activation of the 2 accounts from last night. Previous members that I did activate, all show up as being activated by me in the list.
Re: User account activiation
Ok, so the other admin did the activation as being shown in the administration logs?
Jophy- ForumGuru
- Posts : 17924
Reputation : 836
Language : English
Location : Somewhere
Re: User account activiation
No - there is nothing in the logs showing these 2 accounts were activated by anyone. The other admin has done nothing. The only actions that show up under his name are post deletions listed under the moderation tab.Jophy wrote:Ok, so the other admin did the activation as being shown in the administration logs?
That is the mystery - there is nothing to show the permissions for user account activation were changed by either me or the other admin and nothing to show these accounts were activated by myself or the other admin. And yet both these accounts were active because one of them was able to post several messages on the forum.
Re: User account activiation
Helloghost_2005 wrote:No - there is nothing in the logs showing these 2 accounts were activated by anyone. The other admin has done nothing. The only actions that show up under his name are post deletions listed under the moderation tab.Jophy wrote:Ok, so the other admin did the activation as being shown in the administration logs?
That is the mystery - there is nothing to show the permissions for user account activation were changed by either me or the other admin and nothing to show these accounts were activated by myself or the other admin. And yet both these accounts were active because one of them was able to post several messages on the forum.
Could you send me a private message with:
- Your forum
- 2 usernames registred without your validation
- their registration date
- the link of this topic
Many thanks in advance
Shadow- Manager
- Posts : 16217
Reputation : 1831
Language : French, English
Similar topics
» Please delete my user account
» Hitskin User Account =/= Forummotion Account?
» User Account Already Exists
» User account deletion
» New User Account Notifications
» Hitskin User Account =/= Forummotion Account?
» User Account Already Exists
» User account deletion
» New User Account Notifications
Page 1 of 1
Permissions in this forum:
You cannot reply to topics in this forum