PDA

View Full Version : Security Problem with user injection


Pepcfreak
04-19-2011, 12:17 AM
I have been combating for the past few days now users that are being injected into the site. I am running 4.1.3 .

The website is

http://www.revans-legacy.com

Any help would be greatly appreciated.

Zachery
04-19-2011, 12:23 AM
Disable recapcha and quick registration via facebook.

Use Q&A instead.

Pepcfreak
04-19-2011, 12:36 AM
I had q&a at first when it started happening thought rechaptcha would be better. Seems they are injecting fake users.

The ips they are using dont match google analytics. Half are russian and half are india with some france. Yet i have no hits from thos countries.

I reinstated the question and disabled facebook.

These are fake accounts 100%

--------------- Added 1303245243 at 1303245243 ---------------

Bump... they are still getting in.

I cant figure it out. Ive done what u suggested and still no dice. 2 more just made their way in.

Zachery
04-21-2011, 05:57 PM
You're using the stock 1000% completely use Image Verification, you need to use Q&A.

janaf
04-21-2011, 06:36 PM
rechaptcha is broken/hacked since half a year at least! Google for "recaptcha broken" to find out more.

There is plenty of exploit code around. Use something else....