Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How to stop scam registrations - junk in profile?How to stop scam registrations - junk in profile?
Previous
 
Next
New Post
5/19/2014 9:11 AM
 

Will Do.
D.

 
New Post
5/19/2014 10:25 AM
 
I have hosted 3 DNN sites on Arvixe under 3 different accounts and all 3 sites have the same problem. Where do you have hosted your infected sites?

I just changed the password strength to 11 and no new users for a long time. But that is not s solution since my new real users are not interesting this.

I believe the DNN Captcha is totally useless or it is not working with DNN registration process. That mean there is a way to skip the Captcha to register a new user even when we enable the captcha.

It is strange that still we do not have a solution. :(

I believe it is better if the core team can help us now.
 
New Post
5/19/2014 10:28 AM
 

I found out something about all the spam accounts, if you go to Google Analytics (I'm just assuming that you all use Google Analytics) and view the queries and if you see that it says people are looking up "Membership for this website is public" then that's how they're finding you to make their SPAM accounts, so what you need to do is set the registration as private so you can approve of the users you want to approve of so you don't have the SPAM accounts adding junk into their biographies, you still will get SPAM accounts sign-ups but they won't be able to do anything until you approve of them. 

 

Pogona, out. 


 photo Untitled-6_zps46c5526d1_zpsd6fa44c5.gif
 
New Post
5/19/2014 2:14 PM
 

... but as has been previously mentioned, a number of people have sites that need the verification/public mechanism (e-Commerce sites for example), so going private only solves the problem for a few....

Your comments about captcha appear to be correct and like you, I wonder how the Spammers get past that. A security gap IMHO.

... more testing
==========
I've just added an extra Profile field to the registration form, made it 'required' and tested it manually. All worked.

Unfortunately, I'm still getting SPAM registrations (they are coming in hot'n fast - thatnks for the test rig, spammers... )

So I guess the spammers aren't using the registration module at all (hence captcha and extra fields not working?? )
Another security gap maybe??

Regards,
Duncan.

 
New Post
5/20/2014 2:16 AM
 
Captcha has been broken for years. Here is a 2008 (six years ago) article. http://www.theregister.co.uk/2008/02/...

Thinking that Captcha is a serious defence is naïve. In the six years since that article was written compute power has got cheaper, the crooks more sophisticated. As The Register noted, the tools are being sold as a service.

Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How to stop scam registrations - junk in profile?How to stop scam registrations - junk in profile?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out