Post by pex48 » Sun Oct 02, 2016 6:59 pm

Hi All,

Got a ton of emails to find that nearly 2000 of them were from someone spamming my Returns form on Opencart. They were just placing 1 digit in comments etc and submitting.

For starters, is there a way I can find out their IP address? Then what is my best solution to solve it?

Thanks

New member

Posts

Joined
Thu Dec 26, 2013 9:52 pm

Post by pex48 » Sun Oct 02, 2016 7:32 pm

Okay, I've been looking at customer registrations and there are a ton of fake accounts.

Going back to 18/04 of this year they started registering with fake names The name in every case has the same surname and first name. Sometimes the surnames have two letters added in capitals at the end??

They registered every day originally and then upped the frequency to multiple accounts in a day. In each fake account appears to be a genuine email address, largely Russian names.

Can someone explain what this is about? Some kind of hack attempt or just to spam all these email accounts with our response emails?

New member

Posts

Joined
Thu Dec 26, 2013 9:52 pm

Post by IP_CAM » Sun Oct 02, 2016 8:26 pm

It's spamming ok !
I removed everything, related to this very insecure return Routine, but there are some extensions,
making it a little more complicated, for Spammers.
But you could read here, to prevent certain IP-Ranges from accessing your Site as well, to stop such,
before it even happens:
http://forum.opencart.com/viewtopic.php?f=20&t=168394
---
Extensions:
---
Returns - Customer login
http://www.opencart.com/index.php?route ... n_id=25635
---
Returns force login [OCMOD]
http://www.opencart.com/index.php?route ... n_id=25698
---
Return request mail
http://www.opencart.com/index.php?route ... n_id=15142
---
E-mail de devolução
http://www.opencart.com/index.php?route ... n_id=25526
---
Disable Product Returns
http://www.opencart.com/index.php?route ... n_id=23120
---
Returns Force Login
http://www.opencart.com/index.php?route ... n_id=13529
---
Remove Return (VQMod)
http://www.opencart.com/index.php?route ... n_id=24936
---
Good Luck ;)
Ernie

My Github OC Site: https://github.com/IP-CAM
5'200 + FREE OC Extensions, on the World's largest private Github OC Repository Archive Site.


User avatar
Legendary Member

Posts

Joined
Tue Mar 04, 2014 1:37 am
Location - Switzerland

Post by pex48 » Sun Oct 02, 2016 9:46 pm

Thanks, Ernie,

I've installed Smart AntiSpam shield and hopefully that helps. I hadn't realised there was no Capthca as default on Opencart for registration.

This latest one just seemed malicious as they were not selling anything....just someone banging in random numbers.

New member

Posts

Joined
Thu Dec 26, 2013 9:52 pm
Who is online

Users browsing this forum: Google [Bot] and 291 guests