Ad Widget

Collapse

GMail Ban

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • dmittner
    Junior Member
    • Aug 2014
    • 5

    #1

    GMail Ban

    Just wanted to drop a note to say that banning all @gmail email accounts at registration is absolutely ridiculous. If you have a problem with spammers, improve your security. Don't screw over a large percentage of internet users by rejecting their email addresses.

    I ended up having no choice but to use my work email to register. And even it is maintained by Google behind the scenes. As was my last job's email. I'm luck I could use it or I wouldn't have been able to register here at all.
  • richlv
    Senior Member
    Zabbix Certified Trainer
    Zabbix Certified SpecialistZabbix Certified Professional
    • Oct 2005
    • 3112

    #2
    Originally posted by dmittner
    Just wanted to drop a note to say that banning all @gmail email accounts at registration is absolutely ridiculous. If you have a problem with spammers, improve your security.
    we had almost two thousands of accounts registering per day.
    if you have a solution to that, we'd be glad to hear about it
    Zabbix 3.0 Network Monitoring book

    Comment

    • dmittner
      Junior Member
      • Aug 2014
      • 5

      #3
      Originally posted by richlv
      we had almost two thousands of accounts registering per day.
      if you have a solution to that, we'd be glad to hear about it
      Quantity means little.

      You're using VBulletin which is one of the most popular forum systems, therefor one that any script kiddie and aspiring hacker could easily find scripts to exploit. Those 2000 accounts per day could be the result of one attacker, or the accumulated effect of dozens or hundreds of malicious web crawlers. You need to close the hole they're exploiting. Whether it's 2, 2000, or 20,000 accounts per day, closing the holes will stop them.

      The easiest solution for most people is to upgrade to the most recent software version. However, it looks like your version is only 3.8.6. The newest version is 5. So you're already two major revisions behind. And from a quick Google search the 3.8.6 version has some pretty major security flaws.

      But let's take a step back. It's software you have to pay for and you haven't upgraded in at least 4 years, so the likelihood of upgrading now is financially and technically unlikely.

      There's a silver lining. If you're not worried about upgrading and keeping your implementation in an upgradable state, you can hack the code to your heart's content with little consequence. This means it should be easy for you to add a CAPTCHA check of your choosing to the registration process, or customize the process enough that generic VBulletin hack scripts become useless.

      Even something as simple as changing the username/password variables, or requiring a new variable from the form, might be enough to get in the clear. If someone is dedicated to hacking your site then they might be able to compensate for that, but if that's what you were dealing with then a simple email domain block wouldn't have stopped them for long.

      Comment

      Working...