Keyword

[SOLVED]K2 hacked every day

  • Django
  • Django's Avatar Topic Author
  • Offline
  • Premium Member
More
10 years 4 months ago - 10 years 4 months ago #128537 by Django
[SOLVED]K2 hacked every day was created by Django
Hello

On a site Joomla 2.5.13 + K2 2.6.8, I have spams every day in the K2 elements.

I suppose they come by the frontend form, but the Joomla captcha doesn't work with this form, Askimet cost 5$/month, and the StopForumSpam website is no more online.

Another solution ?

Please Log in or Create an account to join the conversation.

More
10 years 4 months ago #128538 by Lefteris
Replied by Lefteris on topic Re: K2 hacked every day
Hi. What do you mean by saying "K2 elements" ? DO you mean comments? If yes try to:

1. Disable totally comments if you don't need them in your site. You can do this in K2 parameters.

2. Enable comments for registered users only if you don't want guests to be able to comment.

3. Enable one of the Antispam solutions K2 provides. Don't leave K2 comments enabled with no antispam.

JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.

  • Django
  • Django's Avatar Topic Author
  • Offline
  • Premium Member
More
10 years 4 months ago #128539 by Django
Replied by Django on topic Re: K2 hacked every day
I meant "items" ("elements" is the french translation in the K2 admin).

I'ts not in the comments.

And as I said, I can't use any of the 3 captcha solutions.

Please Log in or Create an account to join the conversation.

More
10 years 4 months ago #128540 by Lefteris
Replied by Lefteris on topic Re: K2 hacked every day
K2 has it's own reCAPTCHA settings and work fine. Of course this applies to the comments. So you mean that your site gets full of new items that you have not created? Then probably you have set up K2 to assign new users to a K2 user group which is allowed to create items. So check K2 parameters and K2 user groups settings.

JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.

  • Django
  • Django's Avatar Topic Author
  • Offline
  • Premium Member
More
10 years 4 months ago #128541 by Django
Replied by Django on topic Re: K2 hacked every day
The problem is that I must allow the new registered to write items (recipes), and the the site owner enable them, or not, to be displayed in frontend.


www.conserverie-artisanale-bretonne.com/

Page "Recettes" : Recipes = K2 items.

Page "Vos secrets", visitors can leave their "cooking secrets",(items in the category "secrets"), after creating an account. => K2 frontend form.

How can I add a captcha to this form ? I think the spams are made by robots.

Please Log in or Create an account to join the conversation.

More
10 years 4 months ago #128542 by Lefteris
Replied by Lefteris on topic Re: K2 hacked every day
You cannot add captcha to the K2 item submission form. I suggest to search over the web just in case you find a plugin to do that. I would also try to add a captcha in registration form. Finally you can set the user group of new users to be able to create items but not publish items.

JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.

  • Django
  • Django's Avatar Topic Author
  • Offline
  • Premium Member
More
10 years 4 months ago #128543 by Django
Replied by Django on topic Re: K2 hacked every day
Recaptcha enabled in the Joomla config, but I can't see where to enable it in the K2 connexion module.

The connected users are not allowed to publish, but I would appreciate not to have about 10 new spams to delete in the items of this category everyday.

Please Log in or Create an account to join the conversation.

More
10 years 4 months ago #128544 by Lefteris
Replied by Lefteris on topic Re: K2 hacked every day
K2 has parameters to enable reCAPTCHA on registration, not in log in. Check the options named " Enable reCaptcha on registration form" and " Enable StopForumSpam.com integration on the user registration form " under K2 parameters.

JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.

  • Django
  • Django's Avatar Topic Author
  • Offline
  • Premium Member
More
10 years 4 months ago #128545 by Django
Replied by Django on topic Re: K2 hacked every day
Thanks a lot. That was the good information !
Now I have a super recaptcha below the registration form.
I hope it will be effective against the automatic spams.

Please Log in or Create an account to join the conversation.

More
10 years 4 months ago #128546 by Lefteris
Replied by Lefteris on topic Re: K2 hacked every day
Yes but you also need to delete the existing spam users. If you find an item which contains spam, delete also the author from your system.

JoomlaWorks Support Team
---
Please search the forum before posting a new topic :)

Please Log in or Create an account to join the conversation.


Powered by Kunena Forum