By Don Lewis on Saturday, 01 April 2017
Posted in General
Likes 0
Views 146
Votes 0
Hello,

Today i had a scary incident where someone from russia had registered on my website via easy social and was able to activate their own account. I have everything setup as secure as possible on my website so that when guests register on the website, it requires an admin approval. They cant even log in. I never would have known that this had happened, but i have my settings on the admin of the website so that when a guest registers on the website, they are required to validate their email address, an email goes to me, (the admin), informing me that they have registered and now require approval. I never got any of those emails. The only way i found out that this user had registered and gotten themselves activated was when an email had gotten delivered to me saying that they could not reach the new user email and it had bounced back to me. The only way i knew it was through easysocial (on my website) and not the joomla, is because it has a copy of the email that had failed being delivered and it had the successful activation email. I very quickly went into the admin panel and sure enough, that user had registered and logged in to the website. Obviously I deleted that user, but how in the heck could they do that with all the security settings i have enabled? My biggest concern is how can i keep this from happening again? It is absolutely critical and imperative that the security measure i have taken on my site remain in effect.

While I am on this topic, is there a way to block certain email domains from trying to register on the website, either through joomla or easy social? For example, any email domain ending in .ru or in .rr?
Hello Don,

I am really sorry for the delay of this reply as it is a weekend for us here. I have just tried to sign up on your site and I wasn't able to activate the account.

What I did noticed is that the com_users redirection has been disabled and there is a possibility that the user did try to register via Joomla's registration extension, http://take.ms/QwKYz . When a user registers in Joomla, EasySocial has a user plugin in Joomla which will dispatch e-mails that may seem like an EasySocial registration.

Here's what you can do, you can enable the option highlighted in my screen shot above under the System - EasySocial plugin and monitor if there are new registrations on the site that activates automatically.

In regards to your question about blocking specific domains, you can actually configure this in the custom fields as shown here, http://take.ms/2wJrc . However, if the user is registering via Joomla's registration page, it would then bypass EasySocial's registration
·
Saturday, 01 April 2017 12:23
·
0 Likes
·
0 Votes
·
0 Comments
·
OK, i have taken the steps you recommended. Hopefully this will eliminate this problem.

What exactly is the system easysocial plugin that you had me adjust? What does that setting do?
·
Saturday, 01 April 2017 13:06
·
0 Likes
·
0 Votes
·
0 Comments
·
That settings will ensure that any requests made through com_users would be redirected to EasySocial. This would also ensure that if any spammers / hackers tries to bypass EasySocial by accessing index.php?option=com_users&view=registration would be redirected to EasySocial.
·
Saturday, 01 April 2017 19:31
·
0 Likes
·
0 Votes
·
0 Comments
·
Thank you sir!
·
Saturday, 01 April 2017 22:08
·
0 Likes
·
0 Votes
·
0 Comments
·
You are most welcome Don! If it ever happens again, could you kindly please:

1. Do not delete the user, just block them.

2. Let us know by starting a new ticket and provide us with the reference to this thread (It'll make management of your issues much easier for us)
·
Saturday, 01 April 2017 22:16
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post