Forum Activity for @strumelia

Strumelia
@strumelia
06/23/18 06:50:55PM
3,605 posts

Looks like my jr domain Mailgun acct was hacked


Using Jamroom

Thanks Michael. I've been spending a while now attending to a bunch of stuff the Mailgun guy recommended in his ticket response.
I've now done the following:
1) changed my Mailgun account password.
2) reset my Mailgun Private API key (and then filled the new one in on my JR server settings and then ran a test email which worked)
3) I enabled 2factor authentication in my mailgun account, using my current password program authenticator App for my android phone. (a total pain in the butt but I suppose now a necessary evil).
4) the mailgun guy also told me two IP addresses from which the spam was being sent and I banned the ranges of both.

================

The last suggestion from the mailgun support guy:
This is the one thing I may have screwed up: resetting my Mailgun domain "SMTP credentials" passwords. I wasn't quite sure what they WERE so I reset them with my main JR password. Now it seems I can no longer send or receive emails through my main ___@fotmd.com address, my JR email support "Test Email address" sending FROM my main @fotmd email is now no longer working since I did this it seems. (was still working still after I reset the API though)
Here's a screenshot from the Mailgun Help blog showing the SMTP settings area I'm talking about, and mine has a setting both for my main @fotmd.com email and also "postmaster@___". I'm not sure whether those PWs need to be the same as my Mailgun Account main PW, and/or do they need to be the same as _WHICH_ PWs on my Jamroom end? Do I find the PWs for those items on my Jamroom settings and need to update them?
Right now I'm no longer getting emails from OR to my fotmd.com email address aliases.. My JR mail log seems to confirm this stoppage as well... due to my messing 'something' up I think with the smtp MG passwords, or else by resetting those and not synching the new pws to something on the other end in JR. ?
MG SMTP.png MG SMTP.png - 164KB

updated by @strumelia: 06/23/18 07:48:44PM
Strumelia
@strumelia
06/23/18 01:56:53PM
3,605 posts

Looks like my jr domain Mailgun acct was hacked


Using Jamroom

Went to my fotmd.com jamroom site Mailgun log today and saw this (see screenshot).
Looks like last night someone sent out almost 2 million spam emails from my Mailgun domain account associated with my jamroom network. GaaaCK! =8-0
I just opened a Mailgun ticket, hope I don't get my site mail shut down over this. And I hope they can help me! I have no idea who this was or how it happened.
All I know is that the day prior to this, I received a response from Mailgun about a ticket that I supposedly opened with them requesting a dedicated IP be added to my account. I did NOT request that, yet there was a real actual ticket open in MG requesting it. In the ticket, MG had responded to the person and asked for more info about how many and what kind of mail they were intending to send on the IP. I replied yesterday to the MG ticket saying that *I* did not request this.

Apparently MG must have gone ahead and granted it or something, and now the next day almost 2 million spam messages were sent out from my domain. Yikes.
Anyway, I just now opened a new ticket with MG telling them that was NOT me and asking for their help in un-hacking my account. I hope my MG account doesn't get blocked or dumped because of this! :(
I'm posting this here just in case another JR member is experiencing this or as a warning if they get a notice from MG about a ticket they supposedly opened asking for a dedicated IP... beware if that happens, contact MG immediately!
I just now changed my MG password, but am waiting to hear back from Mailgun with my new ticket.
log.jpg log.jpg - 333KB

updated by @strumelia: 10/01/18 06:38:51PM
Strumelia
@strumelia
06/20/18 06:23:11AM
3,605 posts

auto-follow a discussion when you've posted to it


Using Jamroom

THANK YOU !!
These fixes for Forums and Groups are really going to have a SIGNIFICANT effect on member participation, for many JR site owners. Because it was working for me (as Admin), I always assumed the 'auto-follow thread' worked for all members but only recently discovered it wasn't. :(
But now (as I suspect it was intended to be), ALL members who posted in a discussion they were interested in, but later drifted away, will now by default be informed if that discussion gets new posts.

On my site we have a lot of Groups and Forum threads that have subjects and valuable info that gets added to over time by various members. I'm SO pleased you gentlemen have created fixes for both Group and Forum discussions! :D
Strumelia
@strumelia
06/14/18 09:18:22AM
3,605 posts

Followers sometimes get doubled listing in 'my followers' list


Using Jamroom

Ok thank you for your help... I did this as you suggest Michael. I then did integrity check, also cleared cache, also did a browser hard refresh, closed and reopened browser. It does not seem to help in any way.

Here's what's happening.. and I'm seeing it on various member profiles, but this is a good example one to see it happening on:
https://fotmd.com/ariane/follow She's the regular member who wrote to me many weeks ago that she was seeing this on her profile and on other member profiles.

When I am logged in as Master admin (Strumelia), or as my OTHER 'test' Master admin (Martha Campbell)... I do NOT see double Follower avatars anywhere- on my own profile or other member profiles.

I DO see the double avatars (on other people's profile pages and on my own) in all these other instances:
- when logged OUT
- when logged in as my test Profile Admin
- when logged in as my new 'test' regular member (that I created from scratch yesterday, unrelated to any admin accounts)
- plus, regular member Ariane is reporting to me that she still sees the doubles on her own and other member profiles, despite the fixes above that I've applied so far.

Should I maybe open a support ticket on this and give you logins for the various test accounts I have in different quotas?
Oh, here again is the screenshot on what is being seen for example on real member Ariane's Follow page:

twins.jpg twins.jpg - 334KB

updated by @strumelia: 06/14/18 09:19:19AM
Strumelia
@strumelia
06/13/18 09:04:30AM
3,605 posts

Followers sometimes get doubled listing in 'my followers' list


Using Jamroom

I'm afraid I have to revisit this issue, because I've had some regular members report that they are STILL seeing doubled follower avatars in both locations, despite hard refreshing browsers and integ checks etc.
It appears that in doing the above fixes, it has only fixed the issue for myself (Admin) and for my regular test member -that test profile was created long ago by a former Admin, so apparently retains some 'stuck' attributes that are messing up my objective view. Using that particular test member caused me to believe this issue was solved... but it's not solved.

After receiving new reports of the double avatar from a real regular member, I just now created a new 'test' regular member from scratch (one that was not created by me as master admin as a sub-profile), and when logged in as that new test member I too now see the double avatars in both places... see SCREENSHOT attached here.
One can also easily see the double avatars identical to the screenshot when NOT logged in at all... see here on a sample of a random member profile page showing twin follower avatars in the TWO places: both her "My Followers" TAB and also in her profile sidebar 'latest followers' grid:
https://fotmd.com/ariane/follow

So it seems the fixes above that I've applied have only fixed it for site viewers that are Admin-associated.
twins.jpg twins.jpg - 334KB

updated by @strumelia: 06/13/18 09:05:43AM
Strumelia
@strumelia
06/13/18 07:43:00AM
3,605 posts

Help removing pager


Using Jamroom

Yes that worked. It's gone. Marking this 'solved'.
Thank you Douglas, Michael... and Steve! :)
updated by @strumelia: 06/13/18 07:44:17AM
Strumelia
@strumelia
06/12/18 03:57:47PM
3,605 posts

Help removing pager


Using Jamroom

Douglas thank you so much- but one question before I do this-
doing what you suggest will remove the pager from my site's main index page section for Latest Forum posts.... but will NOT remove the pager from the 'mother page' which is: https://fotmd.com/forums/forum/new_posts
...right? (I don't want to remove the pager from that 'mother' page.... only from the main site index page widget)
So, which of those pages does the index_forum.tpl actually control?
updated by @strumelia: 06/12/18 04:58:15PM
Strumelia
@strumelia
06/12/18 01:59:55PM
3,605 posts

Help removing pager


Using Jamroom

I put a QQQQ right BEFORE that core list function, and the QQQQ appears at the TOP of the section's forum posts there in that block/section, right below the section's Title bar. Then I put the QQQQ right AFTER the core list call, and the Qs appeared right UNDERneath the pager I'm trying to get rid of.

I'm not seeing any pager in the template after the code lines in question. It just goes on to create the remaining blocks of content in different areas, but no specific paging mentions.
This has got me all like scratchin' ma head. =8-\
Strumelia
@strumelia
06/12/18 12:46:04PM
3,605 posts

auto-follow a discussion when you've posted to it


Using Jamroom

The fix in jrForum 2.2.6 seems to have fixed the problem for Forums, Michael... YAY!! :)

However- I am still seeing the problem occurring in GROUP Discussions. When a regular member joins a Group and then makes a new post in an existing group discussion, they are not automatically set to be 'following' that thread.

How can we fix this for Group discussions as well?
updated by @strumelia: 06/13/18 09:36:01AM
Strumelia
@strumelia
06/12/18 12:17:46PM
3,605 posts

Followers sometimes get doubled listing in 'my followers' list


Using Jamroom

Ok, so after getting sidetracked for a few weeks, I came back to this and (finally) figured out to apply your code snippet to my custom skin template: profile_sidebar.tpl ...in the 'followers' core list call section there. It worked- thank you! All solved. :D
  40