Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Bogus User Account CreationBogus User Account Creation
Previous
 
Next
New Post
7/26/2007 8:34 AM
 

I am running DNN v4.05.03 for several sites right now.  My most popular site is getting several bogus accounts created on it daily.  It is set-up for user accounts to be verified.  The names in the bogus accounts often are european-sounding (whatever that means), and the domains at most times do not appear to be valid.  The accounts never get validated.  In short, it certainly looks like a bot or bots are creating user accounts on my DNN portal. 

My first thought to prevent this sort of thing from happening was to enable CAPTCHA for user registration.  While this has brought the number of bogus accounts down alot, there still appears to be at least one a day getting created. 

Is anyone else experiencing this?  Does anyone know of any additional ways that I can go about preventing this?  Does the Core Team have any future plans to further prevent such abuse of our portals?


Will Strohl

Upendo Ventures Upendo Ventures
DNN experts since 2003
Official provider of the Hotcakes Commerce Cloud and SLA support
 
New Post
7/26/2007 9:18 AM
 

Apart from setting up CAPTCHA, you could also set user accounts to require unique email addresses in the web.config file. The setting is:

requiresUniqueEmail="true"

It's located in the AspNetSqlMembershipProvider provider settings section.

 
New Post
7/26/2007 11:02 AM
 

Ed DeGagne wrote

Apart from setting up CAPTCHA, you could also set user accounts to require unique email addresses in the web.config file. The setting is:

requiresUniqueEmail="true"

It's located in the AspNetSqlMembershipProvider provider settings section.

Unfortunately, the e-mail addresses appear to be mostly random and/or already unique.   Thanks... 


Will Strohl

Upendo Ventures Upendo Ventures
DNN experts since 2003
Official provider of the Hotcakes Commerce Cloud and SLA support
 
New Post
7/26/2007 1:31 PM
 

Will, we are not aware of any bot based user creation, not have we had any other reports - i suspect that you are seeing accounts being manually created. If you want I'd be happy to take a look at your IIS logs to check if there is anything in there that would indicate that this issue exists. Alternatively you could set up verified accounts, that will ensure that at least the users email address is correct.

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
7/26/2007 1:49 PM
 

I hope that is true.  Unfortunately, those sites are hosted by an external web host, so I do not have access to the logs.  I am increasingly more curious if anyone else is experiencing this, but it is encouraging that so far no one else has responded to confirm such activity.  *Whew*  :)


Will Strohl

Upendo Ventures Upendo Ventures
DNN experts since 2003
Official provider of the Hotcakes Commerce Cloud and SLA support
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Bogus User Account CreationBogus User Account Creation


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out