Stop registration being hacked

  • Posts: 220
  • Thank you received: 0
  • Hikashop Essential
3 years 2 months ago #329808

Hello,

Do you know which free plug-in I can use to stop joomla registration being hacked? Thank you a lot.

Please Log in or Create an account to join the conversation.

  • Posts: 81515
  • Thank you received: 13069
  • MODERATOR
3 years 2 months ago #329814

Hi,

Joomla registration cannot be "hacked" as far as I know.
I suppose that you're talking about bots creating fake accounts on your website.
There are three main ways:
- add a captcha to the registration form. That way, the user registering has to validate the captcha to register. However, some bots can also validate captchas, so while it can help, it's not a perfect solution. It might do nothing for you based on how the bots targeting your website are coded.
We do provide a free Recaptcha plugin that can be installed for that here:
www.hikashop.com/support/documentation/7...-with-recaptcha.html
- This extension www.joomlashack.com/joomla-extensions/ospam-a-not/ is a bit like a captcha solution but without the user having to do anything. And most bots will probably be fooled by it. But it's possible that it can also block normal users when they do some strange operations on their browser (because they don't know what they are doing, and refresh too much the page, or resubmit the form too quickly etc).
- the other solution is to check the information provided by the user in the registration form against a database of known bots. This is a very effective solution. However, it requires someone managing that database. Such a database, that is used by a lot of websites to check the information of all their new users can require many big servers, and the database needs to be cured, maintained, etc. So such a solution is usually proposed as a service, and thus not free. You can find many such extensions here: extensions.joomla.org/tags/spam-protection/

Please Log in or Create an account to join the conversation.

  • Posts: 220
  • Thank you received: 0
  • Hikashop Essential
3 years 2 months ago #329827

Thank you a lot, Nicholas. I used Hikashop free plug-in. But it shows ERROR for site owner: Invalid key type
Even I used the different no cookie browser. Could you help me? Thank you. See attachment.

Attachments:
Last edit: 3 years 2 months ago by clairewang.

Please Log in or Create an account to join the conversation.

  • Posts: 12953
  • Thank you received: 1778
3 years 2 months ago #329907

Hello,

if you see the "Invalid key type" message, this means that you are using an incorrect reCaptcha key type. For example, V3 keys are not compatible with V2 reCaptcha, and V2 keys are not compatible with Invisible reCaptcha. Key types are not interchangeable.

So make sure you generate the correct key type.

Kind regards,
Mohamed.

Please Log in or Create an account to join the conversation.

  • Posts: 220
  • Thank you received: 0
  • Hikashop Essential
3 years 3 weeks ago #331414

Hi,

I have installed your Captcha but still get hacked emails. What can I do? Thank you so much.

Please Log in or Create an account to join the conversation.

  • Posts: 81515
  • Thank you received: 13069
  • MODERATOR
3 years 3 weeks ago #331419

Hi,

What do you mean by "get hacked emails" ?
Emails can't be "hacked". Do you mean "notification emails of user account created with invalid email addresses" ?
While a captcha can help for that, I already told you that it might not help at all:

However, some bots can also validate captchas, so while it can help, it's not a perfect solution. It might do nothing for you based on how the bots targeting your website are coded.

www.hikashop.com/forum/install-update/90...g-hacked.html#329814
I already gave you two other solutions which are better to stop spam registrations :
- This extension www.joomlashack.com/joomla-extensions/ospam-a-not/ is a bit like a captcha solution but without the user having to do anything. And most bots will probably be fooled by it. But it's possible that it can also block normal users when they do some strange operations on their browser (because they don't know what they are doing, and refresh too much the page, or resubmit the form too quickly etc).
- the other solution is to check the information provided by the user in the registration form against a database of known bots. This is a very effective solution. However, it requires someone managing that database. Such a database, that is used by a lot of websites to check the information of all their new users can require many big servers, and the database needs to be cured, maintained, etc. So such a solution is usually proposed as a service, and thus not free. You can find many such extensions here: extensions.joomla.org/tags/spam-protection/
I don't have other solutions.

Please Log in or Create an account to join the conversation.

Time to create page: 0.069 seconds
Powered by Kunena Forum