Announcement

Collapse
No announcement yet.

Someone is creating new fake customers accounts

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #91
    David's Cloudflare solution is easy to implement in under five minutes:

    Code:
    Firewall > Firewall Rules > Create Firewall Rule > 
    
    Give Firewall Rule Name  e.g. Account Login JS Challange
    
    Request Match 
    > Select Field URI >  Equals > e.g. /create-account.html
    
    Then Choose Action > JS Challenge
    First time users will see a brief testing screen.
    http://www.alphabetsigns.com/

    Comment


      #92
      aimcmc the Google ReCaptcha module I created has been working for the websites I manage with no problem. See earlier posts on this thread for details
      Looking for work as of March 2024! I've been a web developer for going on 20 years, with most of that time spent on Miva sites.

      Comment


        #93
        Mike521w so, so happy to hear from you. I've been trying to make sense of this thread and how to fix this problem but wasn't sure what's what and where exactly where to go. I'll dig back and search for your messages. I appreciate your help. Will message again if I can't grab the concept. Thanks again. -Ron

        Followup....

        I looked back. Found your discussion, but honestly, not being a miva developer, rather just a longtime user, it doesn't make a lot of sense to me. I wonder - 1) could someone provide a step-by-step instruction, text or video. I'd need from step one to the finished product. 2) if I'm eventually able to accomplish this, will future miva upgrades break it and we'll have redo any changes? 3) if this is an ongoing and horrid problem for all miva users, why doesn't miva corp make this fix for us? This, to me, seems to be a "must" fix, asap. Am I missing something? Is not this a fairly serious problem?

        I'll keep trying to figure out how to fix this, but more importantly we need to continue making sales rather than wasting time fixing problems that should not be our concern as a user. Miva?

        Followup 2...

        Looked again, a couple of times, wasting too much productive time -- I'm LOST, and don't have the time to figure this out. If Miva doesn't feel this is a problem, I guess we just let the fake users be created and ignore them.
        Last edited by aimcmc; 07-03-20, 02:12 PM. Reason: further followup

        Comment


          #94
          Hi aimcmc, not sure if you saw it but I have step-by-step instructions on the github page: https://github.com/MWScripts/Miva_GoogleReCaptcha

          It might still be easier for a developer to follow along
          Looking for work as of March 2024! I've been a web developer for going on 20 years, with most of that time spent on Miva sites.

          Comment


            #95
            Thank you Mike521w Yes I did see that. I have been through it. Your instructions are understandable and reasonable. Where I fail is this ...

            "add Google ReCaptcha javascript to your site"

            I understand the google part, not the site (miva) part (where and how to put it on miva). I've searched for examples, instructions, don't see it.

            Where can I find more instruction how to do that?

            Finally, where and how to find a developer if necessary? Personally I've been a developer for over 49 years... from fortran, cobal, c, pascal, php, you name it, so I can still understand some things, but i'm now old and slow and don't have the energy ... so i need handholding in anything new, but i can comprehend when i can see it. That said, of course I value developers but our budget is stretched, so i need to do what i can if i can.

            Comment


              #96
              aimcmc sorry for such a late response, I was having trouble posting a response to you a while back and finally gave up, and today I remembered to give it another shot.

              Anyway, I understand the trouble! As far as finding developers, I think there's a Help Wanted section on this forum where you can make a post and people will respond if they can help you.

              About where to put the Google javascript, basically you'd put that anywhere on the page that you're checking. So for example if you're checking the ICST page, you'd find the ICST page template in the User Interface section of your Miva admin, and add the code there, somewhere before the closing body tag.
              Looking for work as of March 2024! I've been a web developer for going on 20 years, with most of that time spent on Miva sites.

              Comment


                #97
                Mike521w Thank you. I understand. When I find some time I think I'll give it a whirl. Appreciate your time.

                Comment


                  #98
                  We just discovered someone is creating fake Affiliate accounts on our website, over 1,700!
                  1. Why, what do they gain?
                  2. Is there a way to determine IP address for those accounts?
                  We are already already taken the following measures for now:
                  1. Disable affiliate program option in Admin.
                  2. Disabled affiliate log-in page from ReadyTheme navigation set.
                  3. Disabled affiliate AFCL page. However, page is still being displayed. How would I stop from that page being displayed?
                  Any other suggestions?

                  Thank you, Bill Davis

                  Comment


                    #99
                    Fake affiliate accounts started in 11/04/2019, averaging 3 accounts a day for months. Then is slowly increase to an average of 6 accounts a day for months, then 9, etc... Its now averaging 40 accounts a day -consuming bandwidth $.

                    No unusual Authorization Failures found during this period.
                    Thank you, Bill Davis

                    Comment


                      Hi William Davis - the module I wrote should be able to stop these from being created. The download links / details / instructions are all on this thread, let me know if you have trouble
                      Looking for work as of March 2024! I've been a web developer for going on 20 years, with most of that time spent on Miva sites.

                      Comment


                        Being that I now have a very similar problem, countless of fake affiliate accounts ...it's only a matter of time before they create fake customers accounts on our site, wouldn't a solution like "Phosphor Media Easy Account" address the issue?

                        Essentially speaking, they would have to buy something before they can create the account.

                        For a affiliate accounts one one have to come up with something different.
                        Thank you, Bill Davis

                        Comment


                          Originally posted by William Davis View Post
                          Being that I now have a very similar problem, countless of fake affiliate accounts ...it's only a matter of time before they create fake customers accounts on our site, wouldn't a solution like "Phosphor Media Easy Account" address the issue?

                          Essentially speaking, they would have to buy something before they can create the account.

                          For a affiliate accounts one one have to come up with something different.
                          Interesting call. And yes. Basically there is little value (IMO) to offer creating an account for people who are not ordering something. So, having a method (several themes have this built in) that asks to create a account during or after ordering makes sense.
                          Bruce Golub
                          Phosphor Media - "Your Success is our Business"

                          Improve Your Customer Service | Get MORE Customers | Edit CSS/Javascript/HTML Easily | Make Your Site Faster | Get Indexed by Google | Free Modules | Follow Us on Facebook
                          phosphormedia.com

                          Comment


                            Originally posted by Bruce - PhosphorMedia View Post
                            Interesting call. And yes. Basically there is little value (IMO) to offer creating an account for people who are not ordering something. So, having a method (several themes have this built in) that asks to create a account during or after ordering makes sense.
                            I've appreciate your honesty to that you have always accustom us all to.

                            The only reason I can think of for creating an account without a purchase is for signed-in customer price groups related scenarios, or I'm I missing something something else?
                            Thank you, Bill Davis

                            Comment


                              Well, yea...if you have that going on you'll need an Account Creation link, but that's rare.
                              Bruce Golub
                              Phosphor Media - "Your Success is our Business"

                              Improve Your Customer Service | Get MORE Customers | Edit CSS/Javascript/HTML Easily | Make Your Site Faster | Get Indexed by Google | Free Modules | Follow Us on Facebook
                              phosphormedia.com

                              Comment


                                We are seeing a massive spike in fake accounts on account creation page, and a salesforce form handler.. but only on one of our 9 miva stores. Very odd!

                                Comment

                                Working...
                                X