home bbs files messages ]

Just a sample of the Echomail archive

MYSTIC:

<< oldest | < older | list | newer > | newest >> ]

 Message 14,541 of 16,009 
 Bj”rn Wiberg to g00r00 
 hackwarn.txt sent to wrong user if passw 
 24 Mar 22 20:58:35 
 
TID: Mystic BBS 1.12 A48
MSGID: 2:201/137 456a9eb9
TZUTC: 0100
Hello g00r00!

I'm not sure, but I might have stumbled on a small bug related to password
inquiries --

If a user (here, "guest") enters the wrong password a number of times ("Login
Attempts" times), and chooses not to send a password inquiry to the SysOp, the
file hackwarn.txt is correctly sent to the user:

N    58 Possible hack attempt                  Zip             guest

But if the user chooses to send a password inquiry to the SysOp, the recipient
of hackwarn.txt appears to become the same as that of the password inquiry
(i.e. the "Feedback To" user):

N    59 Password Inquiry                       Unknown         Zip
N    60 Possible hack attempt                  Zip             Zip

Here, I would have expected the recipient of the last email to be "guest"
instead of "Zip".

Is this also so for you?

Thanks in advance!

Best regards
Bj”rn

--- Mystic BBS v1.12 A48 2022/03/11 (Linux/64)
 * Origin: Star Collision BBS, Uppsala, Sweden (2:201/137)
SEEN-BY: 1/123 15/0 90/1 103/705 105/81 106/201 114/705 120/340 123/120
SEEN-BY: 123/131 124/5016 129/305 330 331 153/757 7715 154/10 201/0
SEEN-BY: 201/137 203/0 124 218/700 840 220/70 221/0 1 6 242 360 226/17
SEEN-BY: 226/30 100 227/114 229/110 206 307 317 400 424 426 428 452
SEEN-BY: 229/550 664 700 230/0 240/5832 250/5 8 266/512 267/800 280/464
SEEN-BY: 280/5003 282/1038 292/854 8125 298/25 301/1 305/2 3 317/3
SEEN-BY: 320/219 322/757 335/364 341/66 234 342/200 396/45 423/81
SEEN-BY: 460/58 633/280 712/848 770/1 2452/250 3634/24 4500/1
PATH: 201/137 0 203/0 280/464 221/1 6 218/840 770/1 317/3 229/426


<< oldest | < older | list | newer > | newest >> ]


(c) 1994,  bbs@darkrealms.ca