Merv

Community Blog Registration Hijacked

Vote 0 Votes

I have a community blog where the public can register to post entries and comment. I noticed I was getting several spam registrations per day. Username is 9 random lower case letters, email is from hotmail and always a URL from a french company. Obvious spam.

I have disabled comment registration and create entry. They were still appearing. I removed all the code from the site that had anything to do with registrations. I am still getting these registrations. Fortunately there are no permissions set. I also removed the general "add user" from the blog user list.

Any ideas how this might be happening? How to disable community for this Blog (have another private, protected blog also using the community addons.

Thanks,
Merv

PS: MT 4.35

Reported on Movable Type 4.3

6 Replies

| Add a Reply
  • Hi Merv,

    I would recommend you to start from upgrading your movable type installation to v4.37.

    The reason is that a couple of vulnerabilities related to the registration process have been fixed since v4.35.

    Kind Regards,
    Mihai Bocsaru

    ----------------------------------
    Daily Movable Type Consultant

    Web Development
    Movable Type Consulting
    Six Apart Partner

    http://www.pro-it-service.com/
    ----------------------------------

    Movable Type Demo
    http://www.movabletypedemo.org/
    ----------------------------------

    Open Melody Demo
    http://www.openmelodydemo.org/

  • AHHH ... Thanks Mihai, will do.

  • Merv:

    In addition to what Mihai said, please note that Movable Type versions 4.35, 4.36, 4.361, and 4.37 have all been mandatory security updates.

    For instance, if you take a look at the text of the Movable Type 5.05 and 4.36 Release Notes, you'll see the following:

    A remote attacker could execute arbitrary code in a logged-in users' web browser. A remote attacker could read or modify the contents in the system under certain circumstances.

    Everybody reading this thread should review their Movable Type instances to make sure they are running the latest version of Movable Type on their release branch.

  • Thanks Dave,
    I understand and appreciate "mandatory" from your standpoint. I also understand "mandatory" from my clients standpoint. I (my client) have been on MT since 2004 and have never experienced these issues. On Community since it was first released in MT 4.

    Now that we have this issue, the upgrade to 4.37 is warranted if they (my client) concurs and willing to pay. Always a balancing act.

    Thanks again.
    Merv

  • Merv, unfortunately we all have this problem, at least the consultants that build up projects and then have to take care that the client is aware of a risk and is willing to pay for the upgrade service.

    In my experience sometimes a client won't like to pay for upgrading an installation, even if the client understands the risk.

    It's like believing it would never happen to them...

Add a Reply

If you need to share template code, replace all the "<" signs with "&lt;" or use this utility.

Forum Groups

code.sixapart.com

137 479

Last Topic: Getting a thumbnail with xpath by Peter on Mar 13, 2011

238 797

Last Topic: Manifest Schema Compatibility Issue When Restoring Blog by Matt on Oct 17, 2012

1858 6594

Last Topic: Categories and Basename Publishing Issues by e21media on Oct 25, 2012

88 307

Last Topic: absolute publish date in Manage Entries screen by .mau. on Apr 18, 2012

1488 5347

Last Topic: Anti-cloning by .mau. on Oct 29, 2012

732 3093

Last Topic: Blog moved server - now users cannot access blog? by mowgs on Oct 30, 2012

89 317

Last Topic: How to "pretify" a url in htaccess with a few wildcards by Caio on May 30, 2012

183 771

Last Topic: Commenting with TypePad by Rob Ferrara on Oct 17, 2012

212 680

Last Topic: Does MT-Approval work in MT5? by DLpres on Sep 25, 2012

27 100

Last Topic: Upgrading MT by Caio on Oct 15, 2012

49 224

Last Topic: Movable Type 6 Ideas by Caio on May 28, 2012

65 248

Last Topic: Expanding new rich text editor and implementing table function by Takeshi Nick Osanai on Jul 30, 2012