Does anyone like a mystery? Mystery "welcome" emails

Discussion regarding Joomla! 2.5 security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Locked
brentwilliams2
Joomla! Apprentice
Joomla! Apprentice
Posts: 48
Joined: Tue Oct 28, 2008 5:57 pm

Does anyone like a mystery? Mystery "welcome" emails

Post by brentwilliams2 » Sun Jun 28, 2015 8:12 pm

There is a spammer that runs a bot trying to create accounts on my site. My site successfully stops the registration, so no account is ever created, but somehow a "Welcome" email still gets sent out. The problem is that creates a bunch of bogus failure emails getting bounced back, and our host is saying that is making it show our system as spamming. So they are threatening to take our email offline until we can figure it out.

Any suggestions?

Relevant notes:
1) I use JomSocial which has the domain name they use blocked. During tests, I am unable to register myself using that blocked email.
2) I have tested using the main joomla registration, but I'm using DomainRestriction plugin, and that stops it, at least during my own tests. I've also enabled captcha just in case.
Last edited by imanickam on Mon Jun 29, 2015 3:09 am, edited 1 time in total.
Reason: Moved the topic from the forum General Questions/New to Joomla! 2.5 to the forum Security in Joomla! 2.5

itoctopus
Joomla! Virtuoso
Joomla! Virtuoso
Posts: 4025
Joined: Mon Nov 25, 2013 4:35 pm
Location: Montreal, Canada
Contact:

Re: Does anyone like a mystery? Mystery "welcome" emails

Post by itoctopus » Mon Jun 29, 2015 5:53 pm

Have you checked your logs to see how your website is being spammed? It might be that there is vulnerability somewhere and that vulnerability is being exploited for failed registration attempts that also send out emails.

Checking the logs helps substantially. Also, if you website doesn't send out emails then you can disable email sending completely.
http://www.itoctopus.com - Joomla consulting at its finest
https://twitter.com/itoctopus - Follow us on Twitter

User avatar
Bernard T
Joomla! Guru
Joomla! Guru
Posts: 782
Joined: Thu Jun 29, 2006 11:44 am
Location: Hrvatska
Contact:

Re: Does anyone like a mystery? Mystery "welcome" emails

Post by Bernard T » Mon Jun 29, 2015 6:02 pm

Post FPA report.

I agree, investigate your access logs to collect more details about which URL's are being used for registration, and form which IP's, etc.
VEL Team || Security Forum || PHP/Web Security Specialist || OWASP member
JAMSS author http://forum.joomla.org/viewtopic.php?f=621&t=777957
Twitter: @toplak

User avatar
Slackervaara
Joomla! Ace
Joomla! Ace
Posts: 1115
Joined: Sat Aug 13, 2011 6:27 am

Re: Does anyone like a mystery? Mystery "welcome" emails

Post by Slackervaara » Mon Jun 29, 2015 7:35 pm

From the emails bouncing back you can look in the header of the original mail and see if the senders ip-address is in it maybe. If the ip-address is identical in all mails you can ban it in .htaccess and stop this.

User avatar
Bernard T
Joomla! Guru
Joomla! Guru
Posts: 782
Joined: Thu Jun 29, 2006 11:44 am
Location: Hrvatska
Contact:

Re: Does anyone like a mystery? Mystery "welcome" emails

Post by Bernard T » Mon Jun 29, 2015 7:37 pm

@Slackervaara: read the OP post again. His Joomla is the one sending out the emails.
VEL Team || Security Forum || PHP/Web Security Specialist || OWASP member
JAMSS author http://forum.joomla.org/viewtopic.php?f=621&t=777957
Twitter: @toplak


Locked

Return to “Security in Joomla! 2.5”