Forgotten Password Emails
Forgotten Password Emails
Author
Discussion

roadsmash

Original Poster:

2,667 posts

93 months

Friday 22nd February 2019
quotequote all
Anyone else getting these?

I didn’t want to forward to “adverts@pistonheads.com” because it doesn’t sound like the right address, regardless of what the email says.

Is it legit? Is someone trying to penetrate me using a Trojan in my back door? tongue out

Is it spam?

Cheers


Jack Mansfield

3,273 posts

113 months

PH TEAM

Friday 22nd February 2019
quotequote all
Hi,

This isn't spam, it is a legitimate password reset email, however, it could be another user using your username to request a password reset (but that is all they can do)... The password reset is only a request and is not carried out unless you follow the link and carry out the change. Please just ignore any password resets you may get.

This is something we're going to look at into the future so that users can only reset their own password.

Apologies for the annoyance that this causes.

roadsmash

Original Poster:

2,667 posts

93 months

Friday 22nd February 2019
quotequote all
Thanks Jack

Just had another one. Seems pointless why they would do it, I’ll just mark these emails to be ignored.

Cheers

Sheepshanks

39,135 posts

142 months

Friday 22nd February 2019
quotequote all
Is the link to reset the password genuine looking?

I wondered if someone had a similar name to you so looked you up - oddly your name doesn't appear in the member directory!

roadsmash

Original Poster:

2,667 posts

93 months

Friday 22nd February 2019
quotequote all
Sheepshanks said:
Is the link to reset the password genuine looking?

I wondered if someone had a similar name to you so looked you up - oddly your name doesn't appear in the member directory!
It looks relatively genuine but didn’t want to risk it.

Spooky! Maybe I am a ghost. :-)

eybic

9,212 posts

197 months

Friday 22nd February 2019
quotequote all
It's strange that it directs you to email adverts@, that leads me to believe it's the classified side of your account rather than forums. Do you have a separate account you use for the classifieds?

roadsmash

Original Poster:

2,667 posts

93 months

Friday 22nd February 2019
quotequote all
No not at all. I have only one account and don’t view the classifieds.

B'stard Child

30,766 posts

269 months

Thursday 28th February 2019
quotequote all
Sheepshanks said:
Is the link to reset the password genuine looking?

I wondered if someone had a similar name to you so looked you up - oddly your name doesn't appear in the member directory!
I thought Name change - Joined (or early posts around time of joining are) as maclarkk

But that one isn't in the members directory either...........

GravelBen

16,327 posts

253 months

Tuesday 5th March 2019
quotequote all
I got one too, I don't think I've ever used PH classifieds as there isn't much point outside the UK.

MYOB

5,090 posts

161 months

Tuesday 5th March 2019
quotequote all
I got one tonight too...biazarre.

BenLowden

7,215 posts

200 months

PH Marketing Bloke

PH TEAM

Wednesday 6th March 2019
quotequote all
For anyone receiving these suspiciously, can you forward on to me please at blowden@pistonheads.com and we will investigate with our product team.

We've been using a single sign on for a couple of years now and no longer have separate accounts for forums and classifieds, so even if you don't use one or the other, you may still receive one of these emails if someone is trying to access your account.

roadsmash

Original Poster:

2,667 posts

93 months

Wednesday 6th March 2019
quotequote all
BenLowden said:
For anyone receiving these suspiciously, can you forward on to me please at blowden@pistonheads.com and we will investigate with our product team.

We've been using a single sign on for a couple of years now and no longer have separate accounts for forums and classifieds, so even if you don't use one or the other, you may still receive one of these emails if someone is trying to access your account.
Hi Ben - thanks.

But why would a non-classified user be targeted? What is the potential gain?

As far as I can see there is none.

BenLowden

7,215 posts

200 months

PH Marketing Bloke

Wednesday 6th March 2019
quotequote all
roadsmash said:
Hi Ben - thanks.

But why would a non-classified user be targeted? What is the potential gain?

As far as I can see there is none.
True although I'm not a criminal mastermind so I'm not one for ideas in this area hehe

It could be that it's a genuine email from our system that's randomly firing unprompted, so it would be helpful to see some examples so we can try and work out what's going on.

Lemming Train

5,567 posts

95 months

Thursday 4th April 2019
quotequote all
Ben : I am receiving these again now. Could you please investigate and found out which member is trying to hack into the user accounts. It's been going on for months !

I have forwarded the most recent one to your email address above.

funkyrobot

18,789 posts

251 months

Saturday 6th April 2019
quotequote all
Just had this myself. Please look into it.

BenLowden

7,215 posts

200 months

PH Marketing Bloke

Tuesday 9th April 2019
quotequote all
I've received emails from quite a few of you, thanks. I've passed these on to our product team for investigation and will report back in due course.

roadsmash

Original Poster:

2,667 posts

93 months

Tuesday 9th April 2019
quotequote all
As a suggestion I believe it would be more secure for people to reset their passwords by entering their email address, opposed to their username.

This change would resolve the issue.

thebraketester

15,444 posts

161 months

Tuesday 23rd April 2019
quotequote all
Still happening.

No way to stop it? Or can the admin not be arsed?

Gilhooligan

2,221 posts

167 months

Wednesday 12th August 2020
quotequote all
Just had 5 password reset request emails come through in the same minute, despite not requesting it. Decided to change my password by going through my settings instead of clicking any links.

I’m guessing someone is trying to change my account password?

roadsmash

Original Poster:

2,667 posts

93 months

Wednesday 12th August 2020
quotequote all
As per my earlier post, surely this issue can be simply resolved by making a change in the code of the website to ask for the email account of the user to reset the password, rather than the username.

Any chance of this happening?