Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 6.2 and DNN 7.2 Hacked already... HELP ME....DNN 6.2 and DNN 7.2 Hacked already... HELP ME....
Previous
 
Next
New Post
10/1/2014 6:48 PM
 
you do not need to move your login pages - that was a workaround that provided a level of "security by obscurity" as the automated script looked for a fixed page name. In 7.3.2 we fixed a critical error in the captcha logic that allowed a single cracked captcha (either automated or manual) to be used to create multiple accounts - this has resolved the issue for almost everyone. A few sites still report getting a (dramatically reduced) number of new accounts registered but upgrading to 7.3.2/7.3.3 has fixed this for most people. Note: we have reports from a few people who put recaptcha solutions in place and they still see a few automated registrations so this would suggest either a particularly good automated captcha-cracker, or (more likely) that captchas are being cracked by humans, either paid or via redirects (e.g. where a captcha image is copied to another site where a user must supply an answer to it to gain access to content - there are plenty of examples of sites hosting free xxx content that use this approach to solve captchas on 3rd party sites)

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
10/1/2014 6:50 PM
 
brian wrote:
Again, this statement is not accurate. I get many people emailing me asking what is going on!


•Sites that have enabled verified registration typically do not see this issue as the spam accounts do not use real email addresses, and user profile fields for unverified users are not visible to normal users (admin/host can view the profile)

What about this statement do you not believe is true -we checked and only admin/host users can view profiles of unverified users. If a spammer is creating new accounts when verified is enabled then those accounts have no value to them as noone will ever view the spam.


Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
10/2/2014 4:21 PM
 
cathal connolly wrote:
you do not need to move your login pages - that was a workaround that provided a level of "security by obscurity" as the automated script looked for a fixed page name. In 7.3.2 we fixed a critical error in the captcha logic that allowed a single cracked captcha (either automated or manual) to be used to create multiple accounts - this has resolved the issue for almost everyone. A few sites still report getting a (dramatically reduced) number of new accounts registered but upgrading to 7.3.2/7.3.3 has fixed this for most people. Note: we have reports from a few people who put recaptcha solutions in place and they still see a few automated registrations so this would suggest either a particularly good automated captcha-cracker, or (more likely) that captchas are being cracked by humans, either paid or via redirects (e.g. where a captcha image is copied to another site where a user must supply an answer to it to gain access to content - there are plenty of examples of sites hosting free xxx content that use this approach to solve captchas on 3rd party sites)

Dear Cathal

You mean If I remove reCAPTCHA and return to DNN CAPTCHA this 10-20 Spam Per day will finish or will very less?

 
New Post
10/2/2014 4:49 PM
 
we have no real idea as we don't have access to the statistics of requests/captcha cracking - reCaptcha is regarded as an industry standard so it is the main target for captha-crackers so they tend to be quite good. DNN's captcha is not as complex as reCaptcha but as it's not explicitly being targeted it may be that it performs better. I'd recommend that you upgrade to 7.3.2 or above and switch to dnn's captcha and see if that changes anything - if it does please report back.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
10/2/2014 5:50 PM
 

"Sites that have enabled verified registration typically do not see this issue as the spam accounts do not use real email addresses"

How can anyone say they don't use real email addresses.   The issue is they are using real email addresses because I have people emailing me about being registered or having a verification for registering.  Maybe not all but this is an issue which should make you even more concerned because it is making dnn based websites look really bad (for the owners).

I upgraded to 7.3.2 the day it came out.   It has not solved the problem.   I have captcha on, it has not solved the problem.    The ONLY one of many dnn websites I have that is not having the problem is one that I moved the login page to a new name (as suggested somewhere in the forums).   That is a great idea..  and one that dnn could have scripted into 7.3.2 very easily.

cathal connolly wrote:

brian wrote:
Again, this statement is not accurate. I get many people emailing me asking what is going on!


•Sites that have enabled verified registration typically do not see this issue as the spam accounts do not use real email addresses, and user profile fields for unverified users are not visible to normal users (admin/host can view the profile)

What about this statement do you not believe is true -we checked and only admin/host users can view profiles of unverified users. If a spammer is creating new accounts when verified is enabled then those accounts have no value to them as noone will ever view the spam.

 

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 6.2 and DNN 7.2 Hacked already... HELP ME....DNN 6.2 and DNN 7.2 Hacked already... HELP ME....


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out