Hi!

Today (9 Mar 2021, 18:16 EET) there was an attempt to reset password for my account. I myself have not made this request - it was done by someone with not their best intentions in mind (this person is bombarding me spam emails and attempting to access my other online accounts). Is there any information you would be able to provide about where this password request came from? An IP address or anything at all.

Thanks a lot!
A.

Comments

arturs.v created an issue. See original summary.

gisle’s picture

Run-of-the-mill site moderators (such as myself) do not have access to any site logs. However, I shall leave this request open in case somebody is able to provide a better answer.

The reset password link is clickable by anyone. That somebody is else is able to click on it is not having any other effect than you receiving an email with a one-time link. Delete it, and nothing will happen. It is of course annoying if this is done multiple times, but I don't know how to protect against this.

avpaderno’s picture

Component: Spam » User account

Is there any information you would be able to provide about where this password request came from? An IP address or anything at all.

For that kind of queries, the Drupal.org contact form is preferable. It avoids showing in public information that's better to keep private.

Mixologic’s picture

We're not able to provide any PII about usage in our log files, and an IP address falls under that category of PII. I was able to discover their activity, but it is extremely limited, i.e. there is almost no other activity from their IP other than requesting the password reset.

I'll send a private email with the only other info we can provide.

Mixologic’s picture

We're basically in a legal conundrum where we are unsure what we're legally allowed to provide.

We *want* to be able to unmask harassers, because we take harassment seriously, but we do not want to get into some weird legal situation where the harasser can take us to court for providing "their" information under the GDPR.

avpaderno’s picture

@Mixologic It's also probable the IP used to make that password reset request wouldn't be much helpful, as who made the request could be able to use different IPs for each request/attack.

avpaderno’s picture

Status: Active » Fixed

I am closing this issue, as Mixologic already answered it.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.