News:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu

Multiple accounts with same details

Started by Gryzor, January 28, 2017, 04:24:29 AM

Previous topic - Next topic

Gryzor

Hello guys!

Today I saw that a user actually created four accounts with the same user name and same email... I asked him about the how and why, and am waiting for a reply, but I was wondering - is this even supposed to be possible?

Thanks!

PS 2.0.12

Illori

are you sure that the username/email address is exactly the same for all the accounts? by default you can log into SMF with either the username or the email address so it should NEVER be possible to register more then 1 account with the exact same username or email address.

you should also upgrade to 2.0.13 ASAP.

Gryzor

(sorry for the delay, didn't get a notification about your reply!)

Yes, they're the same details. Not sure if the memberlist is public, but do take a look: http://www.cpcwiki.eu/forum/mlist/?sort=registered;start=0;desc . User said he was having computer issues and kept trying, but didn't elaborate. Weird or what??

And yes, I know, just haven't got around to it :D

[EDIT] Ok, just upgraded to .13 :)

[EDIT2] ah no, it's not public, so here's a screenshot; email address is the same, too!

lurkalot


Gryzor


lurkalot

Yep, sorry should have noticed that. I blame my age.  :laugh:

Gryzor

No worries, happens all the time. The real issue is, how did I end up with multiple identical accounts, not you telling me off :D

Illori

sounds like you may have had some server laggyness at the same time he had issues as i dont believe that should happen.

oOo--STAR--oOo

I dunno if its possible to make multiple accounts with the exact same details. They could of used ascii characters that look the same as other characters. Also using spaces, there are multiple ways to create a space but the entry would be different in the database even though it looks the same to you when you see it on the website.

They could of simply used alternate characters that look the same..

I can't see your memberlist without registering so I am unable to investigate what the names really are.
You can't fool a sufficiently talented fool.

http://www.uniquez-home.com
In Design Phase!

Mods I am designing,  No refresh Collapse Categories , Poll Redesign , Pure CSS Breadcrumb , Profile Statuses, Profile Views.

Gryzor

@Illory : thought about server issues myself, but I don't think it should be possible either way: I do guess the software checks the db when creating the new account so even if my db server was taking its sweet time, checks couldn't be skipped...

@oOo--STAR--oOo : yup, similar characters were my guess, too; I didn't bother checking the db itself, but I did try copying the username and email address and then trl-f'ing in the other account pages, they do match.

oOo--STAR--oOo

Quote from: Gryzor on January 28, 2017, 02:02:54 PM
@Illory : thought about server issues myself, but I don't think it should be possible either way: I do guess the software checks the db when creating the new account so even if my db server was taking its sweet time, checks couldn't be skipped...

@oOo--STAR--oOo : yup, similar characters were my guess, too; I didn't bother checking the db itself, but I did try copying the username and email address and then trl-f'ing in the other account pages, they do match.

You viewed the source of your webpage (inspect element) to check this out? Its the HTML not the text already rendered.
You can't fool a sufficiently talented fool.

http://www.uniquez-home.com
In Design Phase!

Mods I am designing,  No refresh Collapse Categories , Poll Redesign , Pure CSS Breadcrumb , Profile Statuses, Profile Views.

Gryzor

No, just the rendered html. I'll check the db tomorrow morning (users table?), but the user doesn't seem to be that technically-minded to do such tricks and besides, you can't do that with email addresses really anyhow...

Gryzor

HMTL source also confirms same details...

Kindred

Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

LoveAngelPr

also your solution doesn't count with situation, where user chooses different internal name for the new account different than JABBER_1. Or that the user creates 2 accounts.

Sir Osis of Liver

No, SMF will not allow either a username or display name to be used by two members.
Ashes and diamonds, foe and friend,
 we were all equal in the end.

                                     - R. Waters

Gryzor

Ok, just went into the database; user name is exactly the same, email addresses are the same, pwd hashes are the same.

Here's my mod list: https://docs.google.com/spreadsheets/d/19mA9K0JZMcpfT7h29jZWdTYK0bo1l-A1E0H5W8O0PTk/edit?usp=sharing .

So... where do I go from here?

Thanks for the help guys :)

Gryzor

Btw, just did the logical test - tried to register twice with the same details; it wouldn't let me, reported both username and email address as in use. So it's not a constant failure... though the four similar accounts are still there!

Shambles

In your Tapatalk configuration, are you allowing members to register indirectly via the Tapatalk forum? It defaults to "yes" in the issued plugin.

Gryzor

Not sure what you mean by "indirectly via the Tapatalk forum" - which forum is that?

I do have "in-app registration" enabled if that's what you mean. But the user was registering from his PC.

Shambles

I meant the plugin setting "Automatic approval for user registered from Tapatalk"

Quote from: helpAutomatically Approve Verified Tapatalk Members.

The plugin code has its own createUser function - just a thought...

Gryzor

Yeah, I know how crappy TT is in that regard, but I repeat, he did it from his PC, not from Tapatalk.

Kindred

Well, for one thing, when we ask for the mod list...  please post it in the message as text... not as an image, and attachment or as a link to a google doc.

Your issue is, almost 100% definitely due to tapatalk.
Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Gryzor

Apologies, I posted it on Sheets because it's easier to read there,won't repeat.

As for TT... again, he didn't register with it. As a matter of fact TT reports no registrations through it for this week, so how could it be?

oOo--STAR--oOo

Quote from: Gryzor on January 29, 2017, 12:28:15 PM
Apologies, I posted it on Sheets because it's easier to read there,won't repeat.

As for TT... again, he didn't register with it. As a matter of fact TT reports no registrations through it for this week, so how could it be?

This is a hard one because SMF is not supposed to function like that. You are not supposed to be-able to use the same email OR username so the fact he did both is like breaking 2 of the normal rules when creating accounts. So if the accounts are indeed matching, it does seem like an error within your source.

Possibly related to TapaTalk, I can't comment too much in regards to TapaTalk because I have never used it.. Maybe it is in some way interfering with your registration. I dunno..

Its not supposed to be possible and the fact we can't recreate it makes it even harder for us to find a solution. Can you re create a user with the exact same details again?

Can the member who did it, do it again. With tech, anything is possible, if its just a one off, I would be fine with that. If its a continuing problem then it would need looking into.
You can't fool a sufficiently talented fool.

http://www.uniquez-home.com
In Design Phase!

Mods I am designing,  No refresh Collapse Categories , Poll Redesign , Pure CSS Breadcrumb , Profile Statuses, Profile Views.

Gryzor

As I said, I did try creating multiple accounts and it prevented me from doing so... I'll ask the member to try again and report!

live627

You mentioned that the user had connectivity issues, and someone suggested server lag. Both of those conditions may have prompted the user to send the same request multiple times, causing race conditions where some codded might run many times while the original request didn't finish, confusing teh checks and balances.

Creating unique indexes in the database on both `member_name` and `email_address` will prevent duplicates.

A bloated banlist also seems to slow the registration process.

Aye Aye





Maybe the Topic Starter should ask that user with the multiple accounts to try an create another couple of accounts using exactly the same username and email address.


lurkalot

Quote from: Aye Aye on January 30, 2017, 03:23:59 AM

Maybe the Topic Starter should ask that user with the multiple accounts to try an create another couple of accounts using exactly the same username and email address.

Quote from: Gryzor on January 29, 2017, 01:13:34 PM
... I'll ask the member to try again and report!

Advertisement: