Contact form spammed

Discussion regarding Joomla! 4.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
cyber_Mike4
Joomla! Apprentice
Joomla! Apprentice
Posts: 6
Joined: Wed Jan 20, 2021 3:36 pm

Contact form spammed

Post by cyber_Mike4 » Tue May 02, 2023 6:28 am

Hi
last year I took down my contact form as it was abused by russian spammers. Even though I turned on google protection. Has that since been improved? I mean that it is no longer possible to send spam mail via my mail server? I think they somehow used a similar/modified contact PHP or alike from outside my website. The webserver log was full of failed php attempts but some worked...
Thank you very much and greetings

User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 25012
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Re: Contact form spammed

Post by pe7er » Tue May 02, 2023 7:41 am

What do you mean by taking down the contact form? Did you only unpublish the menu item to the contact form?
If the component is not unpublished, then you could trigger it via the URL.

Unpublish the component via System > "Extensions" Manage > search for the administrator component "Contacts" and unpublish it.
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

cyber_Mike4
Joomla! Apprentice
Joomla! Apprentice
Posts: 6
Joined: Wed Jan 20, 2021 3:36 pm

Re: Contact form spammed

Post by cyber_Mike4 » Wed May 03, 2023 10:19 am

yea unpublished. Since no more problems. My question is if that was fixed in the meantime?
I find it very strange that the contact form was abused to send spam...

User avatar
AMurray
Joomla! Exemplar
Joomla! Exemplar
Posts: 9832
Joined: Sat Feb 13, 2010 7:35 am
Location: Australia

Re: Contact form spammed

Post by AMurray » Wed May 03, 2023 10:48 pm

"if that was fixed...?" What fix are you hoping for?

Unfortunately, any type of web form is at risk of abuse from spammers or fake submission and it's not an issue unique to Joomla.

You might slow them down (with Recaptcha etc) or another anti-spam tool if you think Google Recaptcha is ineffective (but no such tool is 100% effective). The JED has several alternatives, https://extensions.joomla.org/tags/spam-protection/ or https://extensions.joomla.org/tags/captcha/.

One often mentioned is HashCash (Richeyweb). As the JED listing for HashCash (https://extensions.joomla.org/extension/hashcash/) is currently unpublished, here's the direct link to the developer's site for the download: https://www.richeyweb.com/joomla-extens ... ash-plugin

Other comments on the forum say it works for J4 but advise testing first. (Previous discussion viewtopic.php?t=986288 for reference).
Regards - A Murray
General Support Moderator


Locked

Return to “Security in Joomla! 4.x”