ClassCreator.com | Blockbuster sites, amazing reunions

Share Tips

New Topic Subscription Options  

Mystery Hijacker

Forums: General Discussion
Created on: 10/18/14 03:45 PM Views: 874 Replies: 7
Saturday, October 18, 2014 at 3:45 PM

There is a name listed in Statistics- (view last log ins)dated 10-10-14 Jj Helm and this person doesn't exist in our class list. No suspects on "profile updates" When you click on the highlighted word, "email" ; it is blank. No attempt to join..just stalking. How did this happen? Will you please let us know any and all specific details that you have on this. and on a trace?
We haven't had issues for 6 years until now. This is especially concerning. In addition of knowing how this happened, and how to avoid it again: this past week, and who it is, the administrators were sent a mean anonymous message that we chose to ignore about a nice classmate, and our recent reunion. And this nice classmate received a very viscous typed letter in her USPS mailbox, sent anonymously. Now this.
We have to find out where it came from, who it is, how they logged on,and how to keep this from happening. Do you think we need to do something in the hand of caution from any info this person may have gathered? Thank you!

Reply
Monday, October 20, 2014 at 10:58 AM - Response #1

I will investigate and get back to you with what I learn.


Reply
Tuesday, October 21, 2014 at 11:46 AM - Response #2

Lori Young wrote:

There is a name listed in Statistics- (view last log ins)dated 10-10-14 Jj Helm and this person doesn't exist in our class list. When you click on the highlighted word, "email" ; it is blank.

I can't think of any way for someone to show up in the Statics Last Login list who wasn't joined with that name at the time they logged in, so this one made me stop and take a second look.

I've seen the same symptoms caused by one of two things. First, it could be a 'hidden' member - one who has been marked as "Show On Class List = NO" instead of "Yes" or "Show as Guest" in their contact details. These show up on the Edit Classmate list near the bottom - at the top of the Guests list.
Second, if someone changed their name and/or email address, you'll see an entry in the Last Login list as you described for the old version. Clicking on EMAIL for that entry gives you a blank since there is no matching (visible) entry in the current class list.

Reply
Thursday, October 23, 2014 at 12:51 PM - Response #3

The good news is no security breach or anything along those lines happened here.

This person entered the class via the Facebook app. They never actually were able to join. They just made it to the "lobby" if you will. They could never fully come in.

You have your Preferences set up so somebody must claim an existing name on your class list in order to join. That didn't happen here (which is good).

Essentially what happened here is this person went into an "awaiting verification" state. That would be normal if you had Classmate Verification turned on on your Preferences page but you don't. There really should have been no record of this person at all, i.e. you should not be seeing this person showing up on your Statistics page. If they were turned away at the door so to speak they should not be awaiting verification and the system should retain no record of them at all.

I have passed this on to Programming for correction. Note that the ONLY data this person was able to see is the exact same data the public can see on your web site. They never gained any member privileges or anything like that.

I have deleted JJ Helm from the system.

Lori Young wrote:

There is a name listed in Statistics- (view last log ins)dated 10-10-14 Jj Helm and this person doesn't exist in our class list. No suspects on "profile updates" When you click on the highlighted word, "email" ; it is blank. No attempt to join..just stalking. How did this happen? Will you please let us know any and all specific details that you have on this. and on a trace?
We haven't had issues for 6 years until now. This is especially concerning. In addition of knowing how this happened, and how to avoid it again: this past week, and who it is, the administrators were sent a mean anonymous message that we chose to ignore about a nice classmate, and our recent reunion. And this nice classmate received a very viscous typed letter in her USPS mailbox, sent anonymously. Now this.
We have to find out where it came from, who it is, how they logged on,and how to keep this from happening. Do you think we need to do something in the hand of caution from any info this person may have gathered? Thank you!


Reply
Thursday, October 23, 2014 at 3:15 PM - Response #4

Thanks for the explaination. I'd wondered if it was some anomaly from FBCC, and I'm glad to confirm that an FBCC visitor is no different than a passer-by who found us with a Google search. Still... it would be nice to see who's hitting the site from FBCC since they're at least a 'known' name there. Maybe just an admin notify?

I do question whether this person had tried to join from FBCC. If so, what would Lori's next step be? What if they'd matched a name from the missing list? For my site where I do have Classmate Verification turned on, the info Lori had would have made me very reluctant to verify them since it sounds like there was nothing more than a name to check on.

Reply
Thursday, October 23, 2014 at 8:06 PM - Response #5

It works the exact same way as your site does. If the site does not have verification turned on, then anyone could take any unused name on the app. Again, same thing on the site. In Lori's case this individual didn't actually merge with any name on the class list (or again they would have showed up as being that classmate). All they did was join Class Connection and select Lori's school and class year. And that's where they stopped.

The difference between the site and the app is this person did actually join the app. i.e. they accepted the permissions, selected Lori's school, selected Lori's class year, and then stopped. They now technically have the app though. But since they haven't left the lobby we just needn't show this person anywhere (like the Statistics page). If this person ever goes back to Class Connection they'll still be right there in the lobby, unable to see anything on the site other than what the public has access to.

Right, like any case of verification, you want to have enough evidence to confirm the identity prior to doing the verification.


Reply
Friday, November 14, 2014 at 12:21 PM - Response #6

I have a similar issue. Yesterday, I received an email from the "Class of 63 website" informing me that a new classmate had joined the site. Below that was his name, David Veselka. He is not a member of our class. His name does not appear in the roster of classmate names on the website. I have never heard of this person. I do have verification turned on and when I went to the "Preferences" area and clicked the link to see a "List of classmates awaiting verification", there were no names listed.

After reading the entries here, I checked Statistics on the website to double check that David Veselka did not appear there. His name did not appear. I routinely check the statistics daily and keep my own log of classmates who sign in, so I would have noticed a name that didn't belong.

I can forward the email to you if that would be helpful in any way. I hope you can figure out what happened.

Susan Waters

UPDATE: I got another email, identical to the one I described above just a little while ago.

Reply
Edited 11/14/14 3:02 PM
Monday, November 17, 2014 at 1:11 PM - Response #7

Let me see what I can find out about Mr Veselka and why you would receive this notification. I do see that there is a A.J. Veselka associated with you class. I wonder if there is a connection? Please forward the email to customersupport@classcreator.com


Reply
New Topic  
Subscription Options: Have all new forum posts sent directly to your email.
Subscription options are available after you log in.