VirtueMart Forum

VirtueMart 2 + 3 + 4 => General Questions => Topic started by: carsten888 on September 30, 2013, 07:48:46 AM

Title: how to stop bots registering as shoppers? Catcha?
Post by: carsten888 on September 30, 2013, 07:48:46 AM
I got bots registering as shoppers. There should be a captcha on the registeration page. Am I overlooking something?

Also got spam via the 'ask a question about this product' form. Would be nice to have captcha there too.
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: Maxim Pishnyak on September 30, 2013, 07:51:31 AM
Easy Calc Check Plus
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: carsten888 on September 30, 2013, 08:15:19 AM
Thank you. I will check that out.

I got Google ReCaptcha installed in the Joomla core. Would it not be easyer for VM to make the Joomla captcha alaivable in VM?
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: dennis.g on September 30, 2013, 09:41:58 AM
Captcha is only one way for hackers to attack a website. Unfortunately there are a lot more, like old or unpatched versions of joomla or virtuemart, vulnerable extensions other than virtuemart core files, bad configured web server, predictable passwords for the admin user.
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: AH on September 30, 2013, 09:51:13 AM
Good point dennis

There are many generic joomla security threads available on the joomla site http://docs.joomla.org/Security_Checklist (http://docs.joomla.org/Security_Checklist)

carsten is specifically interested in registration and the prevention of bot registration through use of captcha.

If you can address that specific point then I am sure we would all be more than thankful.

Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: dennis.g on September 30, 2013, 10:27:02 AM
That's the point. Only the attacker can tell us what he did. If you have security holes in the system, like the ones I mentioned before, a hacker may be able to upload files. When he uploads files he can do anything. Creating a user is a common way these people go. A common idea is to create hundreds of users so that the administrator can have no clue as to who made what in the system.
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: dennis.g on September 30, 2013, 11:14:36 AM
A friendly advice to carsten, make sure you always keep backups and your website up to date to the latest software releases. Also, do have a look at Hutson's link, there is a lot of must-read information in there.
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: Maxim Pishnyak on October 03, 2013, 15:15:52 PM
Spammers are not hackers.
Quote from: carsten888 on September 30, 2013, 08:15:19 AM
I got Google ReCaptcha installed in the Joomla core. Would it not be easyer for VM to make the Joomla captcha alaivable in VM?
Some captchas doesn't look friendly for customers and shop owners.

In addition 3rd party developer could make a more quality solution for this specific not so e-commerce related task.
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: Usalafuerza on October 06, 2013, 20:56:43 PM
I have disabled user registration and Easy Calc Check Plus does not work in "Add / Edit billing address information" (Botton: saveCartUser).

It does not work when I access the user registration by www.mypage.com / storename / user. (Botton: SaveUser).  :-\
Title: Re: how to stop bots registering as shoppers? Catcha?
Post by: Maxim Pishnyak on October 10, 2013, 09:59:15 AM
Just struggled with this.

My experience:
1. Keycaptcha currently doesn't support latest VM. Also paid version is more friendly to shoppers. Possible issues with shoppers privacy?
2. Paid recaptcha plugin remained untested. Recaptcha became more friendly nowadays?
3. ECC became paid - Dev version 2.5-8. Probably work - I saw support on its forum.

Conclusion:
Just turn off system messages for VM Vendor/Superadmin
OR
Use email filters for your email client to store Registration emails in separate folder out of Incoming email folder.

Elaboration:
Make life of your shoppers easy - Don't use Captcha.
Use your web shop resources for what they were created - For applying as much registrations as possible. For registrations by spambots, why not? Who cares?

Spam bots wouldn't buy your stuff, howdayyouthink?