Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 6.2 and DNN 7.2 Hacked already... HELP ME....DNN 6.2 and DNN 7.2 Hacked already... HELP ME....
Previous
 
Next
New Post
10/7/2014 9:42 AM
 

Armin,

  We appreciate the feedback, however Spam Registration is not a bug on our part. It is an epidemic that affects the entire internet community.  It is not as simple as saying, "I have identified the issue, now fix it in the next release please."  I would love it if this were no longer a problem for DNN, but the fact remains that it is a problem for any website (not just DNN sites) that accepts public registrations.  This problem is the reason that products like reCaptcha exist.  Given that Google with a dedicated team, led by some very brilliant computer scientists, is unable to solve the problem, then I am under no illusion that the DNN community or DNN Corp will suddenly solve the issue on a single release.

We will continue to work on improving the DNN Platform to deal with SPAM bots and already have some plans in the works for 7.4.0, but I only expect to get an incremental improvement in this area and not a magical cure all to a problem which has plagued the internet for the better part of 20 years.


Joe Brinkman
DNN Corp.
 
New Post
10/7/2014 7:14 PM
 
It would seem to me that a random url for the login page could be generated so each dnn install would have a unique url for the registration page, therefore making it harder for bots to find.
 
New Post
10/8/2014 3:00 AM
 
As Cathal pointed out above...

"...It would be trivial to change the script to make a request for a secured page (e.g. yoursite.com/host), then record the page it redirects to (the login page) and then use that... "

Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
New Post
10/8/2014 1:10 PM
 
1. Yes, spam registration affects every website. However, none of my non-dnn websites are having any issues.

2. Bbscure url could be found. Sure, yes we all know this. Why not do it anyhow for now to stop the massive flood. You could have stopped this over a month ago for everyone for a while but why would you want to solve a problem even if temporarily? Why not?

You do realize that many website owners have no idea this is even happening because they are not being notified of registrations. Then when they try to eventually delete 20,000 users.. it will time out.
 
New Post
10/8/2014 1:48 PM
 

"You could have stopped this over a month ago for everyone"

That's not quite correct.  It would only be stopped for people prepared, able, and willing to do an upgrade to the latest code.   All those people would have to do some work anyway.  They could spend that work time on manually creating a login page.  I don't see a massive net win.

"You do realize that many website owners have no idea this is even happening... "

None of those are going to upgrade to a new version.  As you point out they don't even know they have a problem.  Making a code change would not help them.

"none of my non-dnn websites are having any issues"

I'm very pleased for you.  It tells us nothing useful.  A few seconds in google finds people complaining about thousands of spam registrations per day in Wordpress (https://wordpress.org/support/topic/how-does-one-stop-spam-user-registrations). I'm sure it's just as bad in the other CMS's.

OTOH I have DNN sites that get no spam registrations and I have DNN sites that do.


Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN 6.2 and DNN 7.2 Hacked already... HELP ME....DNN 6.2 and DNN 7.2 Hacked already... HELP ME....


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out