Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How to stop scam registrations - junk in profile?How to stop scam registrations - junk in profile?
Previous
 
Next
New Post
7/17/2014 3:13 PM
 
cathal connolly wrote:

Paul,

I don't wish to criticize in public, but I'm still waiting on responses to both my mails. My first mail also did not suggest that module, but rather asked for what filtering you're using (e.g. ISAPI, urlrewrite module or IIS request filtering) - pleas re-read it and respond accordingly. In my second mail I confirmed that the logs you gave me do not show automated registration but rather returning spam users attempting to view their profile page - as I indicated in that mail a simple filter to map those requests to a 404 would block ~95% of that traffic. That said, the logs show that this site receives less than 10,000 page views a day which in real terms in not large so I am surprised that its affecting performance of that site much at all. Note: the logs are dropping in size rapidly suggesting that the spam requests are dropping naturally as they fail to log in.

If you could respond to one of my mails I will continue to try to help, but I would prefer if you would not post inaccurate information to try to drum up public controversy as that's coming dangerously close to trolling (e.g. you've stated on a mail to our support lead that you spend $25,000 a year at the dnnstore but now you've said you've made 200 purchases - you also say you've been doing DNN for 14 years (we've been going for 11) these figures do not correlate well. )

Note: DNN is free and open-source - there should be no expectation of free support. The fact that you have hundreds of (paying) clients, does not make you different from any other user and expecting free support is unrealistic as it's not something we can offer to the whole community. As security team lead I've chosen to help you as I find it odd that you've been disproportionately affected (99% of others affected have simply applied one of the workarounds and the issue went away) and I want to analyse the reasons why to see if there are additional defence-in-depth measures we should add to 7.3.2. However my time is limited (I'm actually makes the fixes as we speak), so please keep all further correspondence with me to email responses.

thanks,

Cathal

 Cathal.

Again, please read my response, what I said exactly was "If my post came across as ungrateful, then I failed to write it correctly. I'm grateful for your help" and again in the second to last paragraph I state "If that sounds ungrateful, it's not meant to be".  So twice I said that if I sounded like I didn't appreciate your help, I admit I failed in my response. And I specifically said that I am grateful for your help. Neither of these statements are any attempts to drum up any public controversy.  I'll say it again, I am grateful for your help. Very grateful. All I'm saying is that none of what has been suggested has helped. Even now my server is maxed. I don't expect to be treated differently. I love DNN, it's the only CMS I prefer to build in, as I'm sure you can see on  my portfolio page. I am NOT trying to promote other CMS's. I personally don't like WP, and would hate to switch.

Maybe I should have been more accurate in my phrase, I've been building websites for 14 years, and ever since DNN was released I've been using it, so you are correct, I've been using DNN for 11 years, not 14. It's just after using DNN for 90% of our websites it seems like I've used it for 14 years. Yes, when I check my purchase history, it's 20 pages of purchases, at 10 per page equaly 200ish purchases on snowcovered/dnnsoftware. That was an accurate statement. EIther way, I agree with you that this banter doesn't help anyone, I just felt the need to re-iterate that I stated in my previous post that I'm grateful for your help. And wanted to say again, I'm grateful for your help.

Like I mentioned before, we've stopped the registrations, we've hidden the profile pages so Google doesn't index the spam links. Our problem is that the 100,000+ spam registrations across several sites contintue to try and login to their now non-existent profile pages and it's consuming memory.

From this point on, I'll only respond to you by email. My public statements here were only to

1. Try and get help.

2. See if anyone else has the same problem after they stopped the registrations.

3. Publicly say again, I am grateful for your help.

Thank you.


Hawaii Web Design and SEO by One Wave Designs
 
New Post
7/22/2014 1:40 PM
 
I feel it necessary to publicly admit that Cathal has been very attentive and helpful VIA email to help us try and resolve our situation. Although we have not found a solution, this is no fault of his own. His suggestions have been very positive and he has taken the time to provide answers and suggestions. I am thankful for his help and grateful for his suggestions.

Hawaii Web Design and SEO by One Wave Designs
 
New Post
9/7/2014 10:50 PM
 
Hi All,

I changed the registration page names, implemented a captcha, then used DNN Sharps URL Adapter to rewrite any url attempt to access registration.aspx or anything using ctl=register.

This seems to have been successful and I have no further spam registrations. Now it's time to clean things up.

Good luck to all. :-)
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How to stop scam registrations - junk in profile?How to stop scam registrations - junk in profile?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out