2000 mails in a day: is this hacking attempt?

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
Suxkat
Joomla! Apprentice
Joomla! Apprentice
Posts: 30
Joined: Tue Sep 11, 2007 2:57 pm

2000 mails in a day: is this hacking attempt?

Post by Suxkat » Tue Sep 19, 2017 7:29 pm

Hi

Please hepl me, as I am very concerned.
I have a Joomla 3.x site.
May not be very up to date.

Fact is in the last couple of days I have found 2000 mails in my spam folder, which seem to indicate that someone is trying to join my website: fact is that the register module isn't even published.

This is what the mails say (I have replaced my real WWW with "mywebsite"

This is the mail system at host qproxy3.mail.XXXXX.com.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The mail system

<[email protected]>: host inmx.rambler.ru[81.19.78.64] said: 554 5.7.1
Spam message rejected; If this is not spam contact abuse (in reply to end
of DATA command)
Hello Вам поступил перевод со счета #0558 - https://[banned url]/doc321848940_451062077?t1qi0198=34,

Thank you for registering at Mywebsite.com. Your account is created and must be activated before you can use it.
To activate the account select the following link or copy-paste it in your browser:
http://mywebsite.com/index.php/componen ... 73c3e022b0

After activation you may login to http://mywebsite.com/ using the following username and password:

Username: xyz123
Password: sdagdfafk224



What is going on? How concerned should I be?
Advice?

Thank you!

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12785
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: 2000 mails in a day: is this hacking attempt?

Post by brian » Tue Sep 19, 2017 7:46 pm

Simple answer is yes
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
fcoulter
Joomla! Ace
Joomla! Ace
Posts: 1685
Joined: Thu Sep 13, 2007 11:39 am
Location: UK
Contact:

Re: 2000 mails in a day: is this hacking attempt?

Post by fcoulter » Tue Sep 19, 2017 7:49 pm

It seems like a bot creating fake user accounts on your site. From the content of the undelivered message the accounts will have been created but not activated.

In your Joomla admin, go to users->manage - you will see the user accounts that have been created. You can delete them from there.

Also click the options button on the right of the page, set the 'Allow User Registration' option to no, this will stop anyone else from being able to register. The fact is that you do not need a registration module to be published for a user to be able to register.

Since it seems that the users were not activated (the activation email was not delivered), this is not a danger to your site in itself, however it is an annoyance and it is better to remove them.

I suggest that you update your site to Joomla 3.8. It is likely that the bot was trying to exploit a security issue in earlier versions of Joomla.
http://www.spiralscripts.co.uk for Joomla! extensions
http://www.fionacoulter.com/blog my personal website
Security Forum moderator :: VEL team member
"Wearing my tin foil hat with pride"

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12785
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: 2000 mails in a day: is this hacking attempt?

Post by brian » Tue Sep 19, 2017 7:52 pm

Since it seems that the users were not activated (the activation email was not delivered), this is not a danger to your site in itself, however it is an annoyance and it is better to remove them.
That is unknown - they might just be the unsuccessful ones ;)
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

User avatar
fcoulter
Joomla! Ace
Joomla! Ace
Posts: 1685
Joined: Thu Sep 13, 2007 11:39 am
Location: UK
Contact:

Re: 2000 mails in a day: is this hacking attempt?

Post by fcoulter » Tue Sep 19, 2017 9:29 pm

True, Mr T.

Suxkat you can check in the user manager if there are any user accounts that been enabled.
http://www.spiralscripts.co.uk for Joomla! extensions
http://www.fionacoulter.com/blog my personal website
Security Forum moderator :: VEL team member
"Wearing my tin foil hat with pride"


Locked

Return to “Security in Joomla! 3.x”