VirtueMart Forum

VirtueMart 2 + 3 + 4 => Security (https) / Performance / SEO, SEF, URLs => Topic started by: psteimann on April 27, 2012, 00:38:35 AM

Title: Security-Leak in 2.06, (spammed by ask a question feature is not security leak)
Post by: psteimann on April 27, 2012, 00:38:35 AM
I have activated "questions about the product. since then, i get tons of emails like this:

Hi vendor PGS Online-Shop   
Question About Mifare-Ausweiskarte
A question was asked by Ajay (saida@wi.rr.com)
Google docs and presentations work in Hebrew and Arabic, but some stutneds lose formatting when they send it to themselves and then open it and use it for the presentation. SueBy send it to themselves do you mean, save the Google doc/presentation as a file and open in Powerpoint or Keynote or view on another computer? I could see formatting loss if they attempted to view on a computer that did not have Arabic or Hebrew fonts/editing enabled Alex
Hi vendor PGS Online-Shop
   
Question About PIS (Personal-Informationssystem)
A question was asked by Maria (l.tacx@home.nl)
Reader review! A Lodi lirbray patron has this book review to share with us. Interested in reading it? Log in to and put in a request then pick it up at the Lodi lirbray!=============================================Spark: The Revolutionary New Science of Exercise and the Brain, by John J. Ratey, MD, should be

I disabled the button now, but it does not stop

it seems that i get a question from every ask-button of my articles

Any ideas?

site: www.timesoft.ch

Best Regards

Peter

Title: Re: Security-Leak in 2.06
Post by: balai on April 27, 2012, 10:30:03 AM
It seems that spam bots are using this form.

i think that it needs something like a captcha code
Title: Re: Security-Leak in 2.06
Post by: jjk on April 27, 2012, 13:00:54 PM
Last week one of my Joomla websites was discovered by a spambot which was sending emails through contact forms, too. I installed this extension:
http://extensions.joomla.org/search?q=spambotcheck (http://extensions.joomla.org/search?q=spambotcheck)
Since I've installed it, I didn't receive spam emails from spambots anymore.