Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How to stop scam registrations - junk in profile?How to stop scam registrations - junk in profile?
Previous
 
Next
New Post
7/16/2014 7:59 PM
 
brian wrote:
Paul Coffman wrote:
For the first time in 14 years, I am seriously considering leaving DNN hard enough that I interviewed WP and other CMS experts last week to join our team. This is simply costing us thousands of dollars EVERY week!

 I agree.    This is a big issue and what response to do we get.   Nothing.    There are a number of issues going on now and all we get is try this or try that.   Wow.

The only thing I disagree with you is how can this be the first time you thought about leaving.   I stick with it because I am familiar with it..  I wish years ago there was a different option that I became familiar with.   

Why can't DNN simply respond and say we are working on a solution for you..  not 20 steps for you to take and if you are not a developer/technical that you can actually implement!   I don't have time to implement your 20 step solution for your software issues.

Trust me.. there will be silence.   Actually, spammers are using real email addresses somehow..  maybe just accidental.  This is causing more problems.

 

Brian,

It's not the first time I've though of leaving. All CMS's have their strengths and weakneses. However, I've always felt the DNN interface was easiest for our clients to learn when changing their own websites. However, I can't keep doing this. Especially when there's no end in site. I got an email from the support manager at DnnSoftware saying he can't allow his support staff to continue helping me with the issue until I pay for support time. That, most of all, makes me want to leave. 


Hawaii Web Design and SEO by One Wave Designs
 
New Post
7/16/2014 9:02 PM
 
brian wrote:

Paul Coffman wrote:

For the first time in 14 years, I am seriously considering leaving DNN hard enough that I interviewed WP and other CMS experts last week to join our team. This is simply costing us thousands of dollars EVERY week!

 I agree.    This is a big issue and what response to do we get.   Nothing.    There are a number of issues going on now and all we get is try this or try that.   Wow.

The only thing I disagree with you is how can this be the first time you thought about leaving.   I stick with it because I am familiar with it..  I wish years ago there was a different option that I became familiar with.   

Why can't DNN simply respond and say we are working on a solution for you..  not 20 steps for you to take and if you are not a developer/technical that you can actually implement!   I don't have time to implement your 20 step solution for your software issues.

Trust me.. there will be silence.   Actually, spammers are using real email addresses somehow..  maybe just accidental.  This is causing more problems.

 I have posted this on multiple threads/linkedin etc., including http://www.dnnsoftware.com/community-... (which contains a number of acknowledged workarounds including trivial ones such as installing a module), to confirm that 7.3.2 will have a solution to this -those who are interested can track https://dnntracker.atlassian.net/browse/DNN-5494


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
7/16/2014 9:10 PM
 

Paul, by my count at least half a dozen of our staff have been trying to help you, consuming something close to 30hrs in (free) support time. I myself have spent a number of hours examining your IIS logs and sending email responses - of my emails my last two (sent Tue 15/07/2014 22:56 &

Wed 16/07/2014 20:29) have yet to receive responses. I am confused as to your expectations of free support, and then when I offer it (as security team lead) you seem to not take advantage of it.

No one enjoys the situation that we are in at the minute, and we are working hard on resolutions towards it. Whilst a number of people have been affected (i.e. sites that offer public or verified registration), most have found the workarounds at http://www.dnnsoftware.com/community-... to be effective and allow them to continue working whilst we finalise a solution to this with the 7.3.2 release.

 


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
7/16/2014 9:50 PM
 
cathal connolly wrote:

Paul, by my count at least half a dozen of our staff have been trying to help you, consuming something close to 30hrs in (free) support time. I myself have spent a number of hours examining your IIS logs and sending email responses - of my emails my last two (sent Tue 15/07/2014 22:56 &

Wed 16/07/2014 20:29) have yet to receive responses. I am confused as to your expectations of free support, and then when I offer it (as security team lead) you seem to not take advantage of it.

No one enjoys the situation that we are in at the minute, and we are working hard on resolutions towards it. Whilst a number of people have been affected (i.e. sites that offer public or verified registration), most have found the workarounds at http://www.dnnsoftware.com/community-... to be effective and allow them to continue working whilst we finalise a solution to this with the 7.3.2 release.

 

Cathal,

I did receive one email from you today and have tried implementing your suggestion from

http://www.iis.net/learn/extensions/u...

However, this has done nothing. Our problem is that the bots are continuing to try logging in to over 100,000 profiles that don't exist anymore.

We've stopped their ability to register. We've made all profile pages Admin view only to prevent google from indexing the spam links, we've setup redirects in IIS and also tried your suggestions, but still NONE has helped. We even stopped IIS logging for awhile, no help. We blocked the entire country of China, no help. We still are getting 275+ login attempts every single second.

If my post came across as ungrateful, then I failed to write it correctly. I'm grateful for your help. However, (for the sake of a comparison) my house has a HUGE flood in it, and all of the plumbing was built and developed by DNN. Now all my furniture is soaked in water, and is destroyed, my sheetrock walls are falling down and my appliances are floating away.

None of this flood was created by a mistake I made. It happened due to a security leak that was broken by the builders of my home (DNNSoftware.)

My requests to help me save what little is left of my home, what pays my bills, what feeds my kids, what keeps my lights on is not unreasonable to ask of the people who built my house. My posts simply states that if I can't get my builder to help me build my house, then maybe I need another builder. I've been spending money on DNN products for years. I know I'm not a huge spender, but I just looked at my order history and have 200 purchases on Snowcovered/DNNStore. I believe that I've been faithful. I'm just asking for help to keep my lights on. If that sounds ungrateful, it's not meant to be. It's a cry for help in an emergency. I cannot work, I'm losing clients, all of which is occurring due to no fault of my own and I've spent 12-16 hours a day for a 2-3 weeks now trying every single solution that you, this forum, your support staff and anyone else has offered.

None one single thing has helped with my memory overload. I stopped the registrations, deleted the accounts and password protected the profile pages weeks ago when I first saw this happening. Now, I need to get my memory back. My biggest clients are threatening to leave me due to slow loading sites and my server specs aren't bad. They're probably better than most.



Hawaii Web Design and SEO by One Wave Designs
 
New Post
7/17/2014 7:13 AM
 

Paul,

I don't wish to criticize in public, but I'm still waiting on responses to both my mails. My first mail also did not suggest that module, but rather asked for what filtering you're using (e.g. ISAPI, urlrewrite module or IIS request filtering) - pleas re-read it and respond accordingly. In my second mail I confirmed that the logs you gave me do not show automated registration but rather returning spam users attempting to view their profile page - as I indicated in that mail a simple filter to map those requests to a 404 would block ~95% of that traffic. That said, the logs show that this site receives less than 10,000 page views a day which in real terms in not large so I am surprised that its affecting performance of that site much at all. Note: the logs are dropping in size rapidly suggesting that the spam requests are dropping naturally as they fail to log in.

If you could respond to one of my mails I will continue to try to help, but I would prefer if you would not post inaccurate information to try to drum up public controversy as that's coming dangerously close to trolling (e.g. you've stated on a mail to our support lead that you spend $25,000 a year at the dnnstore but now you've said you've made 200 purchases - you also say you've been doing DNN for 14 years (we've been going for 11) these figures do not correlate well. )

Note: DNN is free and open-source - there should be no expectation of free support. The fact that you have hundreds of (paying) clients, does not make you different from any other user and expecting free support is unrealistic as it's not something we can offer to the whole community. As security team lead I've chosen to help you as I find it odd that you've been disproportionately affected (99% of others affected have simply applied one of the workarounds and the issue went away) and I want to analyse the reasons why to see if there are additional defence-in-depth measures we should add to 7.3.2. However my time is limited (I'm actually makes the fixes as we speak), so please keep all further correspondence with me to email responses.

thanks,

Cathal


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How to stop scam registrations - junk in profile?How to stop scam registrations - junk in profile?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out