Several of my forum members are telling me that their passwords have been disabled or logons "hacked" into. One of the admin level users were reset to normal level but not by anybody else. I'm also seeing one logon taking over other logons - this security problem is concerning our members can anybody help.
Its not a problem with the forum software. Either one of the admins is not acting as they should or one of the admins used a very weak password. The "superadmin" Porka924 should review all administrators email addresses. If they are correct they should reset the passwords to strong ones (letters, numbers and a special character). Or remove all unnecessary admins, you only need one.
I've checked these items. I've also advised all the admin to change their passwords as a precaution. My concern I had was one logon appears to take over another. One example I had was from a member called mike who logon is porsche, but has managed to post as at least 4 user names but was unaware they were doing so and actually contacted me because they couldn't easily find their posts.
My guys logs onto the forum as himself, but appears as someone else, their posts show as someone else and they can PM from this other users account - but they have not hacked a password to break in.
Its quite impossible to do. Even if there was a dodgy proxy server serving cached pages between the ForumCo Servers and your two users the forum software would not allow the post to be posted because the username and encrypted password in the cookie would be different.
If you PM me the names & email addresses of the two users in question I can investigate further.