Why do people 'register' as administrators?

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
User avatar
zonkd
Joomla! Explorer
Joomla! Explorer
Posts: 261
Joined: Tue Sep 11, 2007 1:46 pm
Location: Kingston, London, by the famous stream
Contact:

Why do people 'register' as administrators?

Post by zonkd » Fri Jul 31, 2015 5:37 pm

Every so often, Polish email people somehow log into a 1.5 site I built some time ago, and I receive email messages like this:

A new user has registered at [domain name] . This e-mail contains their details:
Name: acdrgbddrejos
E-mail: [email protected]
Username: acdrgbddrejos

I go to the back end and delete the new name. A short time later another email arrives to say another Polish station has registered.

I wonder why they do it, and how they do it? Does it actually endanger the site?

Is the answer to upgrade the site to Joomla 3.4? I would have done so when this problem first started, only I haven't found this particular template in the latest format.

Be very grateful for advice. Cheers
paul

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Why do people 'register' as administrators?

Post by mandville » Fri Jul 31, 2015 8:09 pm

are they administrators?
you have registration enabled, enable captcha on the reg form
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

User avatar
zonkd
Joomla! Explorer
Joomla! Explorer
Posts: 261
Joined: Tue Sep 11, 2007 1:46 pm
Location: Kingston, London, by the famous stream
Contact:

Re: Why do people 'register' as administrators?

Post by zonkd » Fri Jul 31, 2015 9:47 pm

Ah, interesting, Mandville, and thank you. I don't find captcha, but you're right about registration being enabled. Well, well, we learn all the time. Thank you!

But, Mandville, why would anyone bother to keep registering 'administrators'. I mean, what do they achieve, or hope to achieve?

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: Why do people 'register' as administrators?

Post by mandville » Fri Jul 31, 2015 11:31 pm

are they registering "administrator" as a name / user name or as a user level?
if its a level then you need to check the "new user level".
if its a name then there is no issue. most spam users like that are attemtping to register to post links and stuff.
only some is to disrupt your site.

https://nakedsecurity.sophos.com/2015/0 ... t-zombies/
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

User avatar
zonkd
Joomla! Explorer
Joomla! Explorer
Posts: 261
Joined: Tue Sep 11, 2007 1:46 pm
Location: Kingston, London, by the famous stream
Contact:

Re: Why do people 'register' as administrators?

Post by zonkd » Sat Aug 01, 2015 8:46 am

Thanks, Mandville, all noted and appreciated. All the best paul


Locked

Return to “Security in Joomla! 1.5”