Problem with Testing User's Permissions

Get help with installation and running phpBB 3.0.x here. Please do not post bug reports, feature requests, or MOD-related questions here.
Scam Warning
Forum rules
END OF SUPPORT: 1 January 2017 (announcement)
Locked
g unit
Registered User
Posts: 28
Joined: Wed Jun 27, 2007 3:16 am
Location: Pennsylvania, USA
Contact:

Problem with Testing User's Permissions

Post by g unit »

I have a user on my board that is having this issue, and I have no idea why... Every now and then, when he logs in, he will have another user's permissions, and he has to restore permissions to his usual permissions. He is an admin on the board (although I have removed most of his options in case his account is being hacked)... This has occurred 3 times now. After the first two times is when I scaled back his admin permissions. The third time it happened is really concerning to me, because he doesn't even have the ability to test other users' permissions. Any idea what might be going on? Has my board been hacked?

I'm on a Linux server running PHP 4.3.11 and MySQL 5.0
The Pub Playin Killas is a DOD:S and COD:WaW Team.
User avatar
stevemaury
Support Team Member
Support Team Member
Posts: 51474
Joined: Thu Nov 02, 2006 12:21 am
Location: The U.P.
Name: Steve
Contact:

Re: Problem with Testing User's Permissions

Post by stevemaury »

Run his username through the Administrative permission mask. That will show you whether he has a permission you don't think he has.
For REALLY good and VERY inexpensive hosting CLICK HERE

I can stop all your spam. I can upgrade or update your Board. PM or email me. (Paid support)
g unit
Registered User
Posts: 28
Joined: Wed Jun 27, 2007 3:16 am
Location: Pennsylvania, USA
Contact:

Re: Problem with Testing User's Permissions

Post by g unit »

I did that, and it turns out he still did... That would have to be a result of group permissions... I actually WANT him to be able to do that, but for the purposes of figuring out what's going on, I just set it to "never". We'll see what happens, but still... any idea why this would be happening? I suggested it might be something with his cookies, so I had him clear them all (using the link on the board), and it still happened. And, it's been with a different user each time (that is, it gave him permissions from a different user every time).
The Pub Playin Killas is a DOD:S and COD:WaW Team.
User avatar
Brf
Support Team Member
Support Team Member
Posts: 52075
Joined: Tue May 10, 2005 7:47 pm
Location: {postrow.POSTER_FROM}
Contact:

Re: Problem with Testing User's Permissions

Post by Brf »

Your Admin Log should list any times he was testing permissions. That should give you a clue as to whether someone is using his username.
g unit
Registered User
Posts: 28
Joined: Wed Jun 27, 2007 3:16 am
Location: Pennsylvania, USA
Contact:

Re: Problem with Testing User's Permissions

Post by g unit »

Yep, it lists all 3 instances in the Admin Log... Here is what I see:

You can see that his most frequently used IP is what he was on when restored his permissions and logged into the admin panel. Well, I guess you can't see that, but the 1st IP is the one he has posted from most frequently. However, there is a second IP that he has never posted from.

Image

I should also mention that he just changed his password...
The Pub Playin Killas is a DOD:S and COD:WaW Team.
User avatar
Brf
Support Team Member
Support Team Member
Posts: 52075
Joined: Tue May 10, 2005 7:47 pm
Location: {postrow.POSTER_FROM}
Contact:

Re: Problem with Testing User's Permissions

Post by Brf »

If the 2nd IP is not one he would have been using at 2:00 AM, then I would guess his account was compromised. Changing the password was a good idea.
g unit
Registered User
Posts: 28
Joined: Wed Jun 27, 2007 3:16 am
Location: Pennsylvania, USA
Contact:

Re: Problem with Testing User's Permissions

Post by g unit »

yeah, the thing is - he changed his password before the 3rd occurrence of this... I'm having him change it again, though...
The Pub Playin Killas is a DOD:S and COD:WaW Team.
Locked

Return to “[3.0.x] Support Forum”