The Joomla! Forum ™



Forum rules


Forum Rules
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 9 posts ] 
Author Message
PostPosted: Thu Jul 19, 2007 4:54 am 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 1:16 am
Posts: 1005
Location: Glendale, CA, USA
Revision 8072

Front-end user registration, user receives two emails.
Quote:
Hello mike,

Thank you for registering at Joomla 1.5. Your account is created and must be activated before you can use it.To activate the account click on the following link or copy-paste it in your browser:
http://dev.example.com/index.php?option ... d0a69c13c2

After activation you may login to http://dev.example.com using the following username and password:

username - mike
password - password



This same email is send to site Admin too, note instead of username is site name in this case 'Joomla 1.5', this email shouldn't be sent to registered user.
Quote:
Hello Joomla 1.5,

A new User has registered at Joomla 1.5.
This e-mail contains their details:

Name - mike
e-mail - mike@email.com
Username - mike

Please do not respond to this message as it is automatically generated and is for information purposes only.



If method of registration is set to No User Activation than following email is sent.
Quote:
Hello mike,

Thank you for registering at Joomla 1.5.

You may now Login to http://dev.example.com/home/ using the username and password you registered with.

Note username and password missing for this email, I think it should be included.

_________________
http://www.virtuemart-extensions.com


Top
 Profile  
 
PostPosted: Thu Jul 19, 2007 8:06 pm 
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Wed Jul 04, 2007 2:42 pm
Posts: 207
Just making it clear right from the start that this error involves emails being sent to the admin, and not to the registering user.

Well, I've been doing a few test registrations with my site (not live yet), and I've found something rather troubling with the email that gets sent to me when a user registers.  Joomla! will send an email to my admin email, but also to another email.  I've tested this four times, and once it went to the email I registered the new user with, which is fine, I'm pretty sure thats whats supposed to happen.  However, the other three times, the email was (part of registration email I entered before the @ sign)@premium8.geo.yahoo8.akadns.net.  I never typed @premium8.geo.yahoo8.akadns.net (trust me, thats far too long for me to bother with) anywhere.  As these emails contain usernames and passwords, its obviously not a good thing for them to be going to some random email address.

As I understand the above can be confusing, I'll provide an example:

Lets say I register with the email fake@website.com.

My admin account later recieves an email with the username/password info, however, the same email goes to fake@premium8.geo.yahoo8.akadns.net.

This happened both on a nightly build from about a week ago, and the latest nightly build.  This is a MAJOR cause for concern, as it seems to indicate a fairly serious security issue.

EDIT: Whoops, forgot system info

PHP Built on:  Linux new-host-4 2.6.20-1.2962.fc6 #1 SMP Tue Jun 19 19:27:14 EDT 2007 i686
Database Version: 5.0.27
Database Collation: utf8_general_ci
PHP Version: 5.1.6
Web Server: Apache/2.2.4 (Fedora)
Web Server to PHP interface: apache2handler
Joomla! Version: Joomla! 1.5.0 Development [ Khepri ] 04-May-2007 00:00 GMT
User Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.12) Gecko/20070530 Fedora/1.5.0.12-1.fc6 Firefox/1.5.0.12


Last edited by Lottario on Thu Jul 19, 2007 8:08 pm, edited 1 time in total.

Top
 Profile  
 
PostPosted: Thu Jul 19, 2007 10:17 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 1:16 am
Posts: 1005
Location: Glendale, CA, USA
I have been testing registration and email part, last revision I checked was 8072, if things have changed since I don't know but I am sure no user password is being send to Admin only to user and only when 'User Activation' method is selected.

Also see -> http://forum.joomla.org/index.php/topic,192179.0.html

_________________
http://www.virtuemart-extensions.com


Top
 Profile  
 
PostPosted: Fri Jul 20, 2007 2:19 am 
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Wed Jul 04, 2007 2:42 pm
Posts: 207
Ah, ok, maybe it doesn't send passwords then (sorry, had a troubling day with Joomla!, nothing seemed to want to work), but the point is still that it sends to an email address that it seeming gets out of nowhere, which is very troubling.


Top
 Profile  
 
PostPosted: Fri Jul 20, 2007 4:47 am 
User avatar
Joomla! Virtuoso
Joomla! Virtuoso
Offline

Joined: Sat Sep 24, 2005 11:01 pm
Posts: 4778
Location: Toronto, Canada
How are you determining that this email is being sent?
Do you have SMTP logs that indicate this?  This is really odd.  I can assure you that there is nothing within Joomla! that is doing this, as I've certainly not noticed the same behaviour.  I did find this link:
http://www.castlecops.com/modules.php?n ... c&p=769303

But I'm not quite sure how to interpret that info.

Any information that you can provide would be helpful.  Is this site locally hosted?  Or what host is it on?

Ian


Top
 Profile  
 
PostPosted: Fri Jul 20, 2007 1:05 pm 
Joomla! Enthusiast
Joomla! Enthusiast
Offline

Joined: Wed Jul 04, 2007 2:42 pm
Posts: 207
The site is locally hosted on a Linux Virtual Machine.  The only way I determine that the email is being sent is when it arrives in my inbox showing the extra email.  How would I go about getting SMTP logs or anything else relevant to the issue to post back (sorry, I'm fairly new at all this)


Top
 Profile  
 
PostPosted: Mon Oct 22, 2007 1:16 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Wed Sep 21, 2005 9:25 am
Posts: 1544
Location: Thailand
aravot, a lot of work has been done on the email issue since you first posted this, and I think I worked on some code specifically.  Is this still an issue?

tcp

_________________
Sell Memberships and Subscriptions to Premium Content, Digital Goods, and Online Services.
http://oursitesolution.com


Top
 Profile  
 
PostPosted: Mon Oct 22, 2007 4:07 pm 
User avatar
Joomla! Ace
Joomla! Ace
Offline

Joined: Thu Aug 18, 2005 1:16 am
Posts: 1005
Location: Glendale, CA, USA
I'll check it today

_________________
http://www.virtuemart-extensions.com


Top
 Profile  
 
PostPosted: Thu Sep 08, 2011 7:46 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Tue Jul 05, 2011 11:57 am
Posts: 3
aravot wrote:
Revision 8072

Front-end user registration, user receives two emails.
Quote:
Hello mike,

Thank you for registering at Joomla 1.5. Your account is created and must be activated before you can use it.To activate the account click on the following link or copy-paste it in your browser:
http://dev.example.com/index.php?option ... d0a69c13c2

After activation you may login to http://dev.example.com using the following username and password:

username - mike
password - password



This same email is send to site Admin too, note instead of username is site name in this case 'Joomla 1.5', this email shouldn't be sent to registered user.
Quote:
Hello Joomla 1.5,

A new User has registered at Joomla 1.5.
This e-mail contains their details:

Name - mike
e-mail - mike@email.com
Username - mike

Please do not respond to this message as it is automatically generated and is for information purposes only.



If method of registration is set to No User Activation than following email is sent.
Quote:
Hello mike,

Thank you for registering at Joomla 1.5.

You may now Login to http://dev.example.com/home/ using the username and password you registered with.

Note username and password missing for this email, I think it should be included.


hello,
Users dont get activation emails when they register on my site, but they get the message that an activation email will be sent, been looking for solutions everywhere then stumbled on this thread, please can you help me out? i will most appreciate it


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 



Who is online

Users browsing this forum: Google Feedfetcher and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group