Please post all pre-sales questions of all products on this forum

Invite a Friend Exploit

  • Bing Crosby
  • Topic Author
  • Offline
  • New Member
  • New Member
More
9 months 3 weeks ago #167368 by Bing Crosby
Invite a Friend Exploit was created by Bing Crosby
There appears to be a vulnerablity within your "invite a friend" component.  It is causing sever spamming from my site.  My ISP has blocked the IP address that is causing the exploit but it is only a matter of time before another address finds this issue.  I have provided the report from my ISP below.  Please advise how we can correct this issue.  I note that there is at least one other report of this matter within this forum.  Thank you for your assistance!

   Bing,It looks like this component Event Booking is vulnerable and the spammers can exploit this bug:
Code:
182.16.30.194 - - [11/Jun/2024:16:14:13 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:16 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:17 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:19 -0400] "POST [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 500 1591 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 182.16.30.194 - - [11/Jun/2024:16:14:18 -0400] "GET [url=http://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component]www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url] HTTP/1.1" 200 9551 "[url]https://www.rehobothbeachmuseum.org/index.php/component/eventbooking/elements-in-art-kids-classes-07-11-2024/invite-friend?tmpl=component[/url]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
This is how they trigger those emails - we've blocked the IP number, but they'll surely change it.You should contact the extension developer for a fix to this issue.Regards,Kris Sibinski | System Administrator
CloudAccess.net 

Please Log in or Create an account to join the conversation.

More
9 months 3 weeks ago #167375 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
Hello

Yes. That could be the source of spam. But spam could come from anywhere. To prevent spam like that:

1. You can setup and enable captcha in the extension

2. Or go to Events Booking -> Configuration, set Enable Invite Friend config option to No

Regards,

Tuan

Please Log in or Create an account to join the conversation.

More
9 months 3 weeks ago #167382 by Bevan Calliess
Replied by Bevan Calliess on topic Invite a Friend Exploit
Our website was also a victim of this exploit last night so for now I have turned off this option. Unfortunately I did not have the Captcha setting turned on (it is now). I am hesitant to turn the invite friend option back on now that it has been exploited once. It looks like the Captcha security covers the Invite Friend form but just want to make sure before I tune it back on.

Please Log in or Create an account to join the conversation.

More
9 months 3 weeks ago #167384 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
Hi Bevan

You can turn that off for now. That is not a very useful feature, I think.

Regards,

Tuan

Please Log in or Create an account to join the conversation.

More
9 months 3 weeks ago #167385 by Bevan Calliess
Replied by Bevan Calliess on topic Invite a Friend Exploit
Sorry which feature do you mean when you say "You can turn that off for now" the invite a friend button or Captcha?

Please Log in or Create an account to join the conversation.

More
9 months 3 weeks ago #167386 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
The invite friend feature. Just go to Events Booking -> Configuration, set Enable Invite Friend config option to No to disable that feature

Regards,

Tuan

Please Log in or Create an account to join the conversation.

More
9 months 3 weeks ago #167388 by Bevan Calliess
Replied by Bevan Calliess on topic Invite a Friend Exploit
Thanks for the clarification, Yes I turned the invite friend feature off as soon as our webhost informed me that is was the source of the issue.

Please Log in or Create an account to join the conversation.

  • Bing Crosby
  • Topic Author
  • Offline
  • New Member
  • New Member
More
9 months 3 weeks ago #167391 by Bing Crosby
Replied by Bing Crosby on topic Invite a Friend Exploit
Tuan, thank you for the quick reply. I have enabled Captcha and disabled Invite a Friend.

Please Log in or Create an account to join the conversation.

More
9 months 3 weeks ago #167404 by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Invite a Friend Exploit
OK. Actually, for this specific issue, just Disable Invite Friend should be enough

Tuan

Please Log in or Create an account to join the conversation.

Moderators: Tuan Pham NgocGiang Dinh TruongMr. Dam