Maybe I’m done on Forums as well

Moderators: HopefulSSer, admin

User avatar
chapmanruss
Platinum Member
Posts: 3488
Joined: Tue Aug 26, 2014 8:16 pm
Location: near Portland, Oregon

Re: Maybe I’m done on Forums as well

Post by chapmanruss »

I would like to see Everett continue adding to this Forum but can understand his frustrations.

John,

If you have contact with Everett please pass along our thanks for all he has contributed here and our hope he decides to return. Although I have his email addresses I don't want to contact him directly at this time to avoid him feeling bombarded by more emails.
Russ

Mark V completely upgraded to Mark 7
Mark V 520
All SPT's & 2 Power Stations
Model 10ER S/N R64000 first one I restored on bench w/ metal ends & retractable casters.
Has Speed Changer, 4E Jointer, Jig Saw with lamp, a complete set of original accessories & much more.
Model 10E's S/N's 1076 & 1077 oldest ones I have restored. Mark 2 S/N 85959 restored. Others to be restored.
User avatar
admin
Gold Member
Posts: 361
Joined: Wed May 24, 2006 1:14 pm
Location: Dayton, OH
Contact:

Re: Maybe I’m done on Forums as well

Post by admin »

Hi- Sorry for the delay here. We don't actually force password changes to my knowledge. I will check it out.
Shopsmith I.T.
User avatar
admin
Gold Member
Posts: 361
Joined: Wed May 24, 2006 1:14 pm
Location: Dayton, OH
Contact:

Re: Maybe I’m done on Forums as well

Post by admin »

It appears that someone may have been repeatedly attempting to log in to Everett's account to trigger the CAPTCHA. I adjusted some settings so that the CAPTCHA is triggered per IP address before it gets triggered per username. Hopefully this additional time-waster will deter people from attempting to annoy other users.

If it becomes an ongoing problem I can probably go into the logs and find the offenders by IP address, but really don't have time for this so if I find that anyone has been doing this it will definitely result in a permanent ban.
Shopsmith I.T.
User avatar
dusty
Platinum Member
Posts: 21371
Joined: Wed Nov 22, 2006 6:52 am
Location: Tucson (Wildcat Country), Arizona

Re: Maybe I’m done on Forums as well

Post by dusty »

I assume that this means Everett can, if he so chooses, log in to the Shopsmith forum with his old password and username.
"Making Sawdust Safely"
Dusty
Sent from my Dell XPS using Firefox.
User avatar
JPG
Platinum Member
Posts: 34643
Joined: Wed Dec 10, 2008 7:42 pm
Location: Lexington, Ky (TAMECAT territory)

Re: Maybe I’m done on Forums as well

Post by JPG »

He can also assume a 'nom de plume'. (I assume)
╔═══╗
╟JPG ╢
╚═══╝

Goldie(Bought New SN 377425)/4" jointer/6" beltsander/12" planer/stripsander/bandsaw/powerstation /Scroll saw/Jig saw /Craftsman 10" ras/Craftsman 6" thicknessplaner/ Dayton10"tablesaw(restoredfromneighborstrashpile)/ Mark VII restoration in 'progress'/ 10
E[/size](SN E3779) restoration in progress, a 510 on the back burner and a growing pile of items to be eventually returned to useful life. - aka Red Grange
DarrenDD
Gold Member
Posts: 103
Joined: Thu Mar 18, 2021 12:47 pm

Re: Maybe I’m done on Forums as well

Post by DarrenDD »

…or pseudonym. ;)
User avatar
rlkeeney
Platinum Member
Posts: 717
Joined: Fri Nov 14, 2008 5:53 am
Location: Tallahassee FL
Contact:

Re: Maybe I’m done on Forums as well

Post by rlkeeney »

admin wrote: Fri Oct 29, 2021 7:13 pm It appears that someone may have been repeatedly attempting to log in to Everett's account to trigger the CAPTCHA. I adjusted some settings so that the CAPTCHA is triggered per IP address before it gets triggered per username. Hopefully this additional time-waster will deter people from attempting to annoy other users.

If it becomes an ongoing problem I can probably go into the logs and find the offenders by IP address, but really don't have time for this so if I find that anyone has been doing this it will definitely result in a permanent ban.
If you are running on a Linux server take a look at Fail2ban.
https://www.fail2ban.org/
Fail2ban scans log files (e.g. /var/log/apache/error_log) and bans IPs that show the malicious signs -- too many password failures, seeking for exploits, etc. Generally Fail2Ban is then used to update firewall rules to reject the IP addresses for a specified amount of time, although any arbitrary other action (e.g. sending an email) could also be configured. Out of the box Fail2Ban comes with filters for various services (apache, courier, ssh, etc).

Fail2Ban is able to reduce the rate of incorrect authentications attempts however it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services.
--
Robert Keeney
Tallahassee Florida
#odinstoyfactory
User avatar
rjent
Platinum Member
Posts: 2121
Joined: Fri Mar 14, 2014 3:00 pm
Location: Hot Springs, New Mexico

Re: Maybe I’m done on Forums as well

Post by rjent »

edma194 wrote: Thu Oct 28, 2021 3:26 pm If anyone can reach out to him personally I hope that they do.
Done.
I hope this can be resolved.... :confused:
Dick
1965 Mark VII S/N 407684
1951 10 ER S/N ER 44570 -- Reborn 9/16/14
1950 10 ER S/N ER 33479 Reborn July 2016
1950 10 ER S/N ER 39671
1951 jigsaw X 2
1951 !0 ER #3 in rebuild
500, Jointer, Bsaw, Bsander, Planer
2014 Mark 7 W/Lift assist - 14 4" Jointer - DC3300
And a plethora of small stuff .....

"The trouble with quotes on the Internet is that you can never know if they are genuine." - Benjamin Franklin
User avatar
admin
Gold Member
Posts: 361
Joined: Wed May 24, 2006 1:14 pm
Location: Dayton, OH
Contact:

Re: Maybe I’m done on Forums as well

Post by admin »

rlkeeney wrote: Wed Nov 03, 2021 6:16 am If you are running on a Linux server take a look at Fail2ban.
https://www.fail2ban.org/
We are running fail2ban already however we don't have any specific rules set up for phpbb, and I don't know that any exist already. Do you know of any? phpbb has some of its own filtering tools built in and I adjusted those settings to hopefully deter this sort of behavior
Shopsmith I.T.
User avatar
rlkeeney
Platinum Member
Posts: 717
Joined: Fri Nov 14, 2008 5:53 am
Location: Tallahassee FL
Contact:

Re: Maybe I’m done on Forums as well

Post by rlkeeney »

Two-part authentication might help. It will annoy some users, but they can't get past the code entrance form. Almost every financial account I have uses two-part authentication. I turn it on in places where I have the option.

Something that helps with spammers is to not allow new users to post links and maybe photos until they have posted several valid posts that do not have links or photos. The number of posts you keep secret and don"t tell them until they try to post a link or photo. Next you delete new accounts that don't post some reasonable amount of time. Spammers will try to post a link, discover that they can't, and go away. Their accounts are deleted after the time-out has expired. Automated if possible. You will occasionally delete someone who isn;t a spammer, but not many. If they don't ever post anything it should not be much of a problem,
--
Robert Keeney
Tallahassee Florida
#odinstoyfactory
Post Reply