New User Authentication Bypass?

2 months 3 weeks ago #336997 by Brontecreek
New User Authentication Bypass? was created by Brontecreek
I'm having issues with new users logging in and creating accounts without the need for an authentication email, or at least the bots are responding to the authentication emails (not sure which!). I just know that I'm getting about a dozen new users daily that show as authorized but they are obviously fake from their email addresses. I'm not sure how they are even accessing it because they are creating the accounts with no subscription which should not be possible if going through our front end! Any thoughts on where to look how to stop!

Please Log in to join the conversation.

2 months 3 weeks ago #337011 by krileon
Replied by krileon on topic New User Authentication Bypass?
They're either using the confirmation links being sent to them or you've a backdoor registration somewhere. There's nothing you can really do about them using the confirmation links. I'd recommend using CB AntiSpam and providing a captcha of some kind to help reduce the spam, but this is basically the world we live in now as bots get better and better.

As for backdoor registrations can happen if you've a 3rd party extension that has a registration feature. Typically the best way to turn off other Joomla registrations is to explicitly turn Joomla's off. This is done by going to Users > Manage > Options and turning registration off then in CB > Configuration > Registration ensure CBs is enabled explicitly.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.183 seconds

Facebook Twitter LinkedIn