user activation approved by "Anonymous"?

Get help with installation and running phpBB 3.3.x here. Please do not post bug reports, feature requests, or extension related questions here.
richxrich
Registered User
Posts: 188
Joined: Mon Nov 21, 2016 9:17 am
Name: Rich

user activation approved by "Anonymous"?

Post by richxrich »

I got an new user activation email earlier today and didn't have a chance to review it.

However, upon logging into our forum, the user was already activated. We have a specific rule for how usernames are to be formatted and this person didn't follow the rule and wouldn't have been approved.

Looking at the Admin Log, I was alarmed to find that the approval was done by "Anonymous." Not only was the user not automatically added to Newly registered users, it was added to the Global Moderators group.

My understanding is the Anonymous is just a general username for all unregistered guests. Is this correct?
Screenshot 2023-01-16 at 6.27.47 PM.png
Global Moderator group
Screenshot 2023-01-16 at 6.22.53 PM.png
I have removed this person from Global Moderators group.

I've gone ahead and changed all my passwords for the board but I'm wondering how this happened and what I need to do to prevent this from happening in the future.
You do not have the required permissions to view the files attached to this post.
bikeridr
Registered User
Posts: 92
Joined: Wed Oct 14, 2020 9:19 pm

Re: user activation approved by "Anonymous"?

Post by bikeridr »

Are you using TapaTalk on your forum?
In that case, the user might have been registering through TT and thus bypassed the normal login credentials.
There is a reason phpBB does not approve TT.

On my forum, (before I permanently threw out TT), users registered through TT became Global Moderator ("Green") by default.
User avatar
KevC
Support Team Member
Support Team Member
Posts: 72616
Joined: Fri Jun 04, 2004 10:44 am
Location: Oxford, UK

Re: user activation approved by "Anonymous"?

Post by KevC »

Yep 100% check tapatalk. On some older versions the default settings are that everyone goes in to the global mods group and the reg users group.

I think the settings are in the customise tab of the admin panel.
-:|:- Support Request Template -:|:-
Image
"Step up to red alert. Sir, are you absolutely sure? It does mean changing the bulb"
richxrich
Registered User
Posts: 188
Joined: Mon Nov 21, 2016 9:17 am
Name: Rich

Re: user activation approved by "Anonymous"?

Post by richxrich »

Ahhh, yes we do use the Tapatalk extension on our board. Thanks for the info. This is good to know.

Looks like we'll have to revisit its use going forward.

Someone who knows about this "backdoor" could potentially exploit it and cause harm. Luckily, this time it was just a regular joe.
richxrich
Registered User
Posts: 188
Joined: Mon Nov 21, 2016 9:17 am
Name: Rich

Re: user activation approved by "Anonymous"?

Post by richxrich »

KevC wrote: Tue Jan 17, 2023 9:57 am I think the settings are in the customise tab of the admin panel.
The settings were on the Extensions tab. I changed it so new users are auto-approved and defaulted into the "New registered users" group.

I will still have a conversation with our steering group to see if we want to keep Tapatalk as an option.

Thanks again, all!
User avatar
stevemaury
Support Team Member
Support Team Member
Posts: 52794
Joined: Thu Nov 02, 2006 12:21 am
Location: The U.P.
Name: Steve

Re: user activation approved by "Anonymous"?

Post by stevemaury »

Tapatalk is dangerous and unnecessary.
I can stop all your spam. I can upgrade or update your Board. PM or email me. (Paid support)

Return to “[3.3.x] Support Forum”