Skip to Content Skip to Menu

URGENT: Huge problem with registration security issue

  • lucablue
  • lucablue
  • OFFLINE
  • Posts: 226
  • Thanks: 16
  • Karma: 1
5 years 9 months ago #309562 by lucablue
Hi,
since a pair of weeks, how don't know how someone of them do it, people can register to my website just inserting username, email and password, even if there are a lot fields to fill.

I've tried to do the same thing but my browser, correctly, don't permit me to register 'couse miss all the field required... how can they do? how can solve this issue?

They are not hacker, just normal people...

Thank you for help

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48437
  • Thanks: 8275
  • Karma: 1443
5 years 9 months ago #309565 by krileon
They're probably using Joomla registration, 3rd party extension registration, or CB Connect. CB Connect registrations bypass field checks unless you have it configured to use pre-filled. Joomla registration should be blocked unless you told CB not to within its system plugin in Extensions > Plugins or you unpublished it. As for 3rd party extension registrations there's nothing we can do about those and you'll need to see if any extensions you've installed have their own registration processes.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

  • lucablue
  • lucablue
  • OFFLINE
  • Posts: 226
  • Thanks: 16
  • Karma: 1
5 years 9 months ago #309570 by lucablue

krileon wrote: They're probably using Joomla registration, 3rd party extension registration, or CB Connect. CB Connect registrations bypass field checks unless you have it configured to use pre-filled. Joomla registration should be blocked unless you told CB not to within its system plugin in Extensions > Plugins or you unpublished it. As for 3rd party extension registrations there's nothing we can do about those and you'll need to see if any extensions you've installed have their own registration processes.


Hi Krileon,
Joomla registration is set to NO, since the site born;
In CB Configuration is set the option "Register user even if joomla registration system is set to no";
I've no 3rd party component but Kunena that is set to integrate itself with CB;
I don't use CB Connect.

When I try to register me from the "registrati" button, or by the kunena button the browser correctly bring me directly to the normal registration form.
I've tried to compile only the email, username, password field but browser not register me and say I miss the required field...

Try: www.fareanimazione.it / www.fareanimazione.it/iscriviti.html

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48437
  • Thanks: 8275
  • Karma: 1443
5 years 9 months ago #309589 by krileon
How many users have bypassed the required fields? Only way I can see for them to do that with CB is they put in empty characters (e.g. hit spacebar a bunch), which you can prevent with stronger validation rules on your fields and that'd really only work for text fields. Beyond that I don't know or see how they could bypass field validation except some sort of 3rd party registration. Are you using CB Auto Actions to act on registration in any way? It's possible their registration is being interrupted, which could prevent data from saving.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.

Please Log in or Create an account to join the conversation.

  • lucablue
  • lucablue
  • OFFLINE
  • Posts: 226
  • Thanks: 16
  • Karma: 1
5 years 9 months ago #309612 by lucablue
Ok, it could be for the text fields, but, for example, there are the first field "Animatore o Azienda" and other like the acception of term and conditions that are required and there is no possibility to insert blank space chars... and in their profile were shown not selected.

Since I've opened the website, just 2 persons, last 2 in the last 2 weeks.

I've set just 1 auto action by CB Autoaction: when an user register itself, the user is linked to the "basic" free subscription plan of CB Subscriptions

Please Log in or Create an account to join the conversation.

  • lucablue
  • lucablue
  • OFFLINE
  • Posts: 226
  • Thanks: 16
  • Karma: 1
5 years 9 months ago #309620 by lucablue
Today there is a new!

Another normal user is registered into joomla user db but not into community builder user db...

What's goin'on? Is there some bug in the last update of CB?

Since before Christmas everything worked good....

Please Log in or Create an account to join the conversation.

Moderators: beatnantkrileon
Powered by Kunena Forum