Jump to content

fiodh

Members
  • Content count

    74
  • Joined

  • Last visited

Everything posted by fiodh

  1. fiodh

    Fake accounts

    I did this now also, and it worked, no fake accounts for the last three days! Thanks for mentioning it, you've saved me several minutes each morning.
  2. fiodh

    Fake accounts

    That sucks! The google captcha is complicated for me to install, I don't get it. Something about server side code verifying in the database, as well as editing the php files... I am at the edge of my understanding when it gets to database bits so am going to have to look into this. But it's a shame the only solution is to go worship at the altar of google, and give them access to everyone who registers.
  3. fiodh

    Fake accounts

    They say if one is using a page reader program, for the blind, it won''t be able to pass the slider.
  4. fiodh

    Fake accounts

    That is interesting. Can this slider captcha be installed in osC? I am looking at it now at wordpress.org https://wordpress.org/support/plugin/slider-captcha/
  5. fiodh

    Fake accounts

    Here is an interesting description of why these accounts are being created: https://webmasters.stackexchange.com/questions/61291/why-do-registration-bots-exist-what-do-they-gain-from-registering-on-my-site TLDR: They use your site confirmation email along with many others to hide online scams or purchases made with hacked accounts. They also use spam text in the email to spam to customers. The only solution so far is to install google captcha. If you don't mind google having their fingers on every account created at your site. One major issue from these accounts is that the email addresses are often valid, so when people receive a robots spammy customer welcome email, they likely will mark it as SPAM. If this happens enough, your site will be blacklisted on junk lists.
  6. fiodh

    Fake accounts

    Honestly I'd prefer not to post my entire customers.php file to the forum, plus my site is sort of a hacked together non-standard old mess that will likely only cause confusion.
  7. fiodh

    Fake accounts

    oh, sorry, that bit, I have no idea about that. We haven't used company names in our customer account form since the very beginning. If you can tell me where I can find that code, I'll have a look.
  8. fiodh

    Fake accounts

    That's not the company names, thats the "how did you find us? question count.
  9. fiodh

    Fake accounts

    Even with the honeypot add on, now I am getting 15 fake accounts in less than 24 hours.
  10. fiodh

    Fake accounts

    One pattern I have noticed with these accounts is that 99% of them have at least the same first 5 characters of each of their first and last names. Maybe we could make a filter that checked for that and prevented them? Here's a screenshot of the latest batch I've got yesterday. It would mean though, that poor "Frank Franklin" and "David Davidson" wouldn't be able to create an account...
  11. fiodh

    Fake accounts

    Some good ideas there. Doesn't seem like they are all using particular spam emails. In fact some of these emails look quite valid, like they are US emails that the spammers are testing to see if they get bounced.
  12. fiodh

    Fake accounts

    I have blocked hundreds if not thousands of IP ranges from Russia, Estonia, Romania, etc. In regards to the referral question I wonder if the consultant I hired to install it just hard coded it in, instead of an add-on.
  13. fiodh

    Fake accounts

    Now getting about 12 account in an 8 hour period. I had google captcha for a while on there but it didn't do anything. I think because captcha wasn't properly installed with the authentication codes set on the server side. It's a bit out of my league at this time. Honestly I am also loathe to hand over my customer data to Google - they get notified every time someone uses that captcha. My Referral question doesn't appear to be sourced from "How Did You Hear" as I can't find any setting for it as a module in my admin. Any other ideas?
  14. sent you a pm

  15. fiodh

    Fake accounts

    Woke up this morning to 60 honey pot messages, but only 3 fake accounts made.
  16. fiodh

    Fake accounts

    Yes that had occurred to me, to just change the name of the file, but I wasn't sure where all the mentions of create_account.php would be and if that would mess it all up? Unless, somehow, the spammers are accessing the database directly, as they don't seem to be using my modified page. I've been running this shop for 15 years so far and expect to continue!
  17. fiodh

    Fake accounts

    Hi Jack I just want to say I don't hold you responsible for these problems - your add on contribution has really helped tremendously. Thanks for all your work.
  18. fiodh

    Fake accounts

    Yes the IPs are different for most of them, I block them and and then more arrive! I have been a bit lazy about religiously banning every IP, after a while I just keep deleting and deleting... Here's the settings: Email Addresses Allowed False Email Addresses Show Message True URL's Allowed False URL Show Message True Create Account Check True Create Account Count 2 Create Account Period 480 Create Account Notify True
  19. fiodh

    Fake accounts

    I am really getting pounded with these, even with the honey pot add on, I am now getting 8-10 accounts a day. Doesn't seem like much until you have spend a couple minutes every morning deleting these.
  20. fiodh

    Fake accounts

    On my create account page, I have a question "how did you find us" and some radio button style options. (google, bing, friend, repeat visit). When the spammers submit their accounts, this question is always blank. I assume this is because the bots/spammers are accessing the create account function script directly. Question - Is there a way to prevent someone from creating an account if they don't provide answer to this "referral" question? This might give the spammers an error and send them on their way?
  21. fiodh

    Fake accounts

    I'm sorry, I have to rescind what I said - I am getting 2-3 a day after installing honey pot. I just had a flourish of them in a short while the other day which made me think I was getting that many. (if I sound like an idiot, in this case, I am one) two to three ain't too bad. Blocking the countries or each single spammer's IP didn't really do anything. Are the maybe using this process to test emails to use for spamming? Thanks
  22. fiodh

    Fake accounts

    I've installed honey pot but still get 20-30 a day.
  23. fiodh

    Fake accounts

    Yes, yes, I know Albania is a country. I guess I put it in quotes to make it sound more far fetched that I would ever sell there. Wag the Dog was a great movie... or is it a documentary? I am mostly US, UK, CA and AUS. But if I remove extra countries, they are just going to use whatever is left. Wish I could ban them by Tax ID like John did.
  24. fiodh

    Fake accounts

    The fake customers all have stupid names, I never do business in "Albania" or Russia, and also, I have an extra field on my create account page "how did you find us" and the bot scripts never fill that one out, but everyone else does. So those accounts are obvious. What I am noticing today though is that they are using many different IPs and the list of banned addresses is going to get quite long by the looks of it. I will say, your Honeypot contribution has about halved the amount of accounts, thank you very much.
  25. fiodh

    Fake accounts

    Thank you, I will do that! Then I could ban every IP I receive.
×