This is only the title for the update; update itself is labeled as 3.7.4.This should be 3.7.4![]()
I've seen this affect a number of XenForo forums over the last week, and yes it is absolutely due to compromised passwords.I have an influx of member accounts getting hacked, likely due to insecure passwords.
When will system realize that a user has a compromised pw? When they log in?I've seen this affect a number of XenForo forums over the last week, and yes it is absolutely due to compromised passwords.
You'll need to turn on the "Force email two factor authentication on compromised password". This will force the user to use email 2fa if they don't have 2fa setup and they login and the password is detected as compromised.
Warning; this will general support requests as you'll find people realise they didn't have a working email address linked to their account.
Yup, on login. Which includes when a spammer manages to login with another account.When will system realize that a user has a compromised pw? When they log in?
Moldova | Netherlands | Netherlands | Netherlands |
109.107.166.230 | 5.61.55.218 | 37.220.87.25 | 45.136.48.135 |
I have this installed and ticked and we're still getting logins on old accounts from the spammer with compromised credentials.I've seen this affect a number of XenForo forums over the last week, and yes it is absolutely due to compromised passwords.
You'll need to turn on the "Force email two factor authentication on compromised password". This will force the user to use email 2fa if they don't have 2fa setup and they login and the password is detected as compromised.
Warning; this will general support requests as you'll find people realise they didn't have a working email address linked to their account.
Can you set these options?I have this installed and ticked and we're still getting logins on old accounts from the spammer with compromised credentials.
Pwned password minimum count (hard): 1
Pwned password minimum count (soft): 0
Pwned password cache time: 3
Thanks. Done and will keep an eye on it, of course.Can you set these options?
Code:Pwned password minimum count (hard): 1 Pwned password minimum count (soft): 0 Pwned password cache time: 3
The defaults are a little more tolerant, and I suspect there may be a large breach which hasn't made it to haveibeenpwned yet![]()
You need to block the IP addresses on you server as noted above- https://xenforo.com/community/threads/password-tools.154256/post-1609790Thanks. Done and will keep an eye on it, of course.
We use essential cookies to make this site work, and optional cookies to enhance your experience.