- Posts: 7
- Thank you received: 0
Please post all pre-sales questions of all products on this forum
Invite a Friend Exploit
- Bing Crosby
- Topic Author
- Offline
- New Member
-
Less
More
9 months 3 weeks ago #167368
by Bing Crosby
Invite a Friend Exploit was created by Bing Crosby
There appears to be a vulnerablity within your "invite a friend" component. It is causing sever spamming from my site. My ISP has blocked the IP address that is causing the exploit but it is only a matter of time before another address finds this issue. I have provided the report from my ISP below. Please advise how we can correct this issue. I note that there is at least one other report of this matter within this forum. Thank you for your assistance!
Bing,It looks like this component Event Booking is vulnerable and the spammers can exploit this bug:
This is how they trigger those emails - we've blocked the IP number, but they'll surely change it.You should contact the extension developer for a fix to this issue.Regards,Kris Sibinski | System Administrator
CloudAccess.net
Bing,It looks like this component Event Booking is vulnerable and the spammers can exploit this bug:
Code:
182.16.30.194 - - [11/Jun/2024:16:14:13 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:16 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:17 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:19 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
CloudAccess.net
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
9 months 3 weeks ago #167375
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
Hello
Yes. That could be the source of spam. But spam could come from anywhere. To prevent spam like that:
1. You can setup and enable captcha in the extension
2. Or go to Events Booking -> Configuration, set Enable Invite Friend config option to No
Regards,
Tuan
Yes. That could be the source of spam. But spam could come from anywhere. To prevent spam like that:
1. You can setup and enable captcha in the extension
2. Or go to Events Booking -> Configuration, set Enable Invite Friend config option to No
Regards,
Tuan
Please Log in or Create an account to join the conversation.
- Bevan Calliess
- Offline
- New Member
-
Less
More
- Posts: 13
- Thank you received: 0
9 months 3 weeks ago #167382
by Bevan Calliess
Replied by Bevan Calliess on topic Invite a Friend Exploit
Our website was also a victim of this exploit last night so for now I have turned off this option. Unfortunately I did not have the Captcha setting turned on (it is now). I am hesitant to turn the invite friend option back on now that it has been exploited once. It looks like the Captcha security covers the Invite Friend form but just want to make sure before I tune it back on.
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
9 months 3 weeks ago #167384
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
Hi Bevan
You can turn that off for now. That is not a very useful feature, I think.
Regards,
Tuan
You can turn that off for now. That is not a very useful feature, I think.
Regards,
Tuan
Please Log in or Create an account to join the conversation.
- Bevan Calliess
- Offline
- New Member
-
Less
More
- Posts: 13
- Thank you received: 0
9 months 3 weeks ago #167385
by Bevan Calliess
Replied by Bevan Calliess on topic Invite a Friend Exploit
Sorry which feature do you mean when you say "You can turn that off for now" the invite a friend button or Captcha?
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
9 months 3 weeks ago #167386
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
The invite friend feature. Just go to Events Booking -> Configuration, set Enable Invite Friend config option to No to disable that feature
Regards,
Tuan
Regards,
Tuan
Please Log in or Create an account to join the conversation.
- Bevan Calliess
- Offline
- New Member
-
Less
More
- Posts: 13
- Thank you received: 0
9 months 3 weeks ago #167388
by Bevan Calliess
Replied by Bevan Calliess on topic Invite a Friend Exploit
Thanks for the clarification, Yes I turned the invite friend feature off as soon as our webhost informed me that is was the source of the issue.
Please Log in or Create an account to join the conversation.
- Bing Crosby
- Topic Author
- Offline
- New Member
-
Less
More
- Posts: 7
- Thank you received: 0
9 months 3 weeks ago #167391
by Bing Crosby
Replied by Bing Crosby on topic Invite a Friend Exploit
Tuan, thank you for the quick reply. I have enabled Captcha and disabled Invite a Friend.
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
-
9 months 3 weeks ago #167404
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
OK. Actually, for this specific issue, just Disable Invite Friend should be enough
Tuan
Tuan
Please Log in or Create an account to join the conversation.
Moderators: Tuan Pham Ngoc, Giang Dinh Truong, Mr. Dam
Support
Documentation
Information
Copyright © 2025 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.