ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

How did a user change his group?

September 30, 2010 4:12pm

Subscribe [4]
  • #1 / Sep 30, 2010 4:12pm

    gazettejournal

    8 posts

    It seems we have two problems on our site:

    1 - Registration Spam (I’m trying some tips from another thread)
    2 - we just found someone registered as a subscriber, who has no reason to be there at all. He has not made a purchase - which is required to become a subscriber.

    We don’t have forums or even comments, but people do need to register to make a purchase.

    How did he do this?
    http://www.gazettejournal.net

  • #2 / Sep 30, 2010 4:47pm

    gazettejournal

    8 posts

    Same user is in your member list, and in solspace, and in several other EE sites. All list him as joined the same day he joined our site - 9/27/10

  • #3 / Sep 30, 2010 10:20pm

    Will Dieterle

    56 posts

    Hi Gazette Journal,

    ExpressionEngine has some pre-built templates for registration and the like, and unless you protect them, they can be accessed for spamming.  Is it possible that your spammer registered through the member/register template here:

    http://www.gazettejournal.net/index.php/member/register

    Or edited his profile through the template here:

    http://www.gazettejournal.net/index.php/member/profile

  • #4 / Oct 01, 2010 3:22pm

    Sue Crocker

    26054 posts

    Thanks for the assist, Will.

    gazettejournal, does that help at all?

  • #5 / Oct 01, 2010 3:24pm

    Sue Crocker

    26054 posts

    That’s exactly what happened. In fact, you’ll notice I just registered as EETest.

  • #6 / Oct 01, 2010 3:29pm

    atelier2

    181 posts

    And the protecting solution could be to rename the “member” part of the URL into something_else. The actual link to your registration Template would be in that case: http://www.gazettejournal.net/index.php/something_else/register. And no-one guesses that. But do not forget to alter all the links in your Templates once you have “hidden” the Member Templates.

  • #7 / Oct 03, 2010 12:33pm

    Greg Salt

    3988 posts

    Hi gazettejournal,

    Do you still need further assistance?

    @atelier2, thanks for the assist.

    Cheers

    Greg

  • #8 / Oct 03, 2010 10:22pm

    gazettejournal

    8 posts

    Sorry for the long delay in reply. I’ll make those changes.
    Thank you everyone!

  • #9 / Oct 04, 2010 11:33am

    Sue Crocker

    26054 posts

    No worries, that’s what we’re here for. Don’t hesitate to post again as needed.

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases