Skip to Content Skip to Menu

Security: Somebody wants hack my joomla web site

  • fechasoru
  • fechasoru
  • OFFLINE
  • Posts: 3
  • Thanks: 0
  • Karma: 0
13 years 10 months ago #138301 by fechasoru
I have been discovering suspect users are register in a corporate web site developed by me.
This problem is coming about five month .

Why are they suspect?. If you see the below list, you can look the values of the register fields “Name” and “Username” are equals, example Name=” idiodiend idiodiend” and Username ”idiodiend”.

It looks like an automatic attack by robots (bots register) or spammers . I ´m worried about it. I have fear that anybody could robs the joomla administrator password or ftp account.

I have installed CB 1.2 with captcha and four language pack.

I don´t know if it is a bug CB 1.2 ? How I can resolve it?.

My joomla version is 1.5.15

Example:
Name Username
VilliamYH VVilliamYH VVilliamYH Registered tymnbonopinoLup@mailtoo.bij.pl 05/01/2010 10:01:32
idiodiend idiodiend idiodiend Registered disruptivz@gmail.com
05/24/2010 10:18:27
anassydrums anassydrums anassydrums Registered l.a.urelwestmanoce@gmail.com 06/10/2010 06:08:33
Snitteekibtal Snitteekibtal Snitteekibtal Registered nantrennae@lvivs.com
06/15/2010 18:39:38
zerrierlookek zerrierlookek zerrierlookek Registered scopyjoyday@ramireschat.com 06/18/2010 09:15:30
limisuti1985 limisuti1985 limisuti1985 Registered vwymnvxvh54@kamelot-clan.com 06/21/2010 06:44:54
SweernSenia SweernSenia SweernSenia Registered armandpo.well.jy@gmail.com
06/21/2010 20:57:06
Staisizappy Staisizappy Staisizappy Registered tymnarernp@babusya.com
06/22/2010 19:50:14
Nedincink Nedincink Nedincink Registered nornnoneype@uaclub.net
06/23/2010 12:16:23
abnotamok abnotamok abnotamok Registered wrellavaklye@kinozal.tv
06/23/2010 19:35:30
FexySiminainy FexySiminainy FexySiminainy Registered usadswraripaf@babusya.com
06/25/2010 13:15:37
FampheappygeR FampheappygeR FampheappygeR Registered creankcex@peugeot-club.org 06/27/2010 19:34:52

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 68625
  • Thanks: 9109
  • Karma: 1434
13 years 10 months ago #138322 by krileon
Those aren't hack attempts nor can they steal your password, once the password is saved it's encrypted and can not be reversed, ever. Those are simply spammers. I recommend becoming a document subscriber for the latest CB Captcha plugin so you can have captcha protection on registration. I also recommend upgrading to CB 1.2.3. You could also use Confirm (see CB configuration on the registration tab) to require registered users to confirm their email address and then those bots won't even be able to login as typically the emails are fake.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

Moderators: beatnantkrileon
Powered by Kunena Forum

Facebook Twitter LinkedIn