PriMoThemes — now s2Member® (official notice)

This is now a very OLD forum system. It's in READ-ONLY mode.
All community interaction now occurs at WP Sharks™. See: new forums @ WP Sharks™

members registering by-passing required fields

s2Member Plugin. A Membership plugin for WordPress®.

members registering by-passing required fields

Postby smbotans » July 17th, 2011, 4:13 am

hi all,

i have a new members registering problem ... i currently have new members 'signing up' regularly BUT when i check their profile, the LAST NAME required field is blank and the COUNTRY required field is -

how can this be when both fields are required fields and when i checked the registration form, a popup appears when i leave the LAST NAME field blank and when i enter - into the COUNTRY field

am i being spammed? are they by-passing my registration form in some way?

i had a look at the ip of some of those new members, and they are all different

any help or thoughts would be appreciated

serge
User avatar
smbotans
Registered User
Registered User
 
Posts: 4
Joined: July 17, 2011

Re: members registering by-passing required fields

Postby Cristián Lávaque » July 17th, 2011, 3:40 pm

I don't know, it may not be impossible to bypass those checks since they're JavaScript. I need to ask Jason how that could be and if there are any server checks done too. Are you using WP's registration page or s2Member Pro's pro-form?
Cristián Lávaque http://s2member.net
Is s2Member working for you? Please rate it Image at WordPress.org. Thanks! :)
User avatar
Cristián Lávaque
Developer
Developer
 
Posts: 6836
Joined: December 22, 2010

Re: members registering by-passing required fields

Postby smbotans » July 18th, 2011, 12:47 am

thanks for your reply ... i am using the free version of s2member which takes over the wp registration page ... i am getting around 100 new members 'signing' up each day and looks like i will have to delete them all by hand as they are dud members

this is very annoying and i dont like having my membership site taken over like this with fake members signing up en masse

any help would be greatly appreciated ... my site is www.mental-workout.com if it helps

serge
User avatar
smbotans
Registered User
Registered User
 
Posts: 4
Joined: July 17, 2011

Re: members registering by-passing required fields

Postby Cristián Lávaque » July 18th, 2011, 11:31 pm

Ok, you're using the standard WordPress registration form. http://www.mental-workout.com/wp-login.php?action=register

You may want to use some plugins to prevent spam registrations. https://wordpress.org/extend/plugins/se ... gistration
Cristián Lávaque http://s2member.net
Is s2Member working for you? Please rate it Image at WordPress.org. Thanks! :)
User avatar
Cristián Lávaque
Developer
Developer
 
Posts: 6836
Joined: December 22, 2010

Re: members registering by-passing required fields

Postby smbotans » July 19th, 2011, 1:14 am

thanks for your reply :-)

actually i am not as the link you mention in your reply takes me to the s2member registration form where there are required fields which are being bypassed ... ggrr!!!!
User avatar
smbotans
Registered User
Registered User
 
Posts: 4
Joined: July 17, 2011

Re: members registering by-passing required fields

Postby smbotans » July 20th, 2011, 12:22 am

it turns out i was being spammed although how they added new members to my site by-passing the registration form and required fields is a mystery

i used one of the plugins you suggested and no more rogue members signing up ... just a lot of spam registrations being blocked ... since i installed the plugin, i have not had a spam registration

thank you so much for your help and suggesting the plugins ... my sanity has returned :-)

thanks again

serge

ps if it helps others, i used the plugin from http://wordpress.org/extend/plugins/sto ... ns-plugin/
User avatar
smbotans
Registered User
Registered User
 
Posts: 4
Joined: July 17, 2011

Re: members registering by-passing required fields

Postby Cristián Lávaque » July 20th, 2011, 12:55 am

Thanks a lot for the update! I'm very glad you solved it. :)
Cristián Lávaque http://s2member.net
Is s2Member working for you? Please rate it Image at WordPress.org. Thanks! :)
User avatar
Cristián Lávaque
Developer
Developer
 
Posts: 6836
Joined: December 22, 2010

Re: members registering by-passing required fields

Postby Jason Caldwell » July 21st, 2011, 5:53 pm

Thanks for the heads up on this thread.

Yes, this is a case where the site is being spammed, and since there is no server-side validation for Custom Fields, they were allowed to be empty. The only server-side validation is for the Username/Email Address at this time ( i.e. s2Member v110710 ). So although you may configure *required* fields, if someone attempts to spam your site with a bot to POST data directly to the registration system ( i.e. spamming you ), the JavaScript validation can be bypassed in cases such as this.

Can s2Member implement a Captcha Code on my Login/Registration Forms?
Yes and no. We've left this feature out of the plugin intentionally, because many site owners prefer to use Captcha plugins that encompass all aspects of their site ( including comment forms ). We recommend this one: SI CAPTCHA Anti-Spam. That being said, s2Member's Pro Forms for PayPal® Pro and Authorize.Net® ( including Free Registration Forms ) CAN be configured to use Google's reCAPTCHA service ( which is free ). Just add this Attribute to your Pro Form Shortcode ( captcha="clean" ).
~ Jason Caldwell / Lead Developer
& Zeitgeist Movie Advocate: http://www.zeitgeistmovie.com/

Is the s2Member plugin working for you? Please rate s2Member at WordPress.org.
You'll need a WordPress.org account ( comes in handy ). Then rate s2Member here Image
.
User avatar
Jason Caldwell
Lead Developer
Lead Developer
 
Posts: 4045
Joined: May 3, 2010
Location: Georgia / USA

Re: members registering by-passing required fields

Postby Cristián Lávaque » July 21st, 2011, 5:58 pm

Is it be possible to check server-side where the form was submitted from and reject any that isn't from the same server?
Cristián Lávaque http://s2member.net
Is s2Member working for you? Please rate it Image at WordPress.org. Thanks! :)
User avatar
Cristián Lávaque
Developer
Developer
 
Posts: 6836
Joined: December 22, 2010

Re: members registering by-passing required fields

Postby Jason Caldwell » July 21st, 2011, 6:01 pm

Cristián Lávaque wrote:Is it be possible to check server-side where the form was submitted from and reject any that isn't from the same server?
Yes, that could certainly be a solution in many cases. However, I would like to implement true server-side validation in a future release, so that it's NOT impossible for a site owner to build a custom form that submits data from an off-site location, when/if needed.
~ Jason Caldwell / Lead Developer
& Zeitgeist Movie Advocate: http://www.zeitgeistmovie.com/

Is the s2Member plugin working for you? Please rate s2Member at WordPress.org.
You'll need a WordPress.org account ( comes in handy ). Then rate s2Member here Image
.
User avatar
Jason Caldwell
Lead Developer
Lead Developer
 
Posts: 4045
Joined: May 3, 2010
Location: Georgia / USA

Re: members registering by-passing required fields

Postby Cristián Lávaque » July 21st, 2011, 6:02 pm

Yeah, that'd be cool. :)
Cristián Lávaque http://s2member.net
Is s2Member working for you? Please rate it Image at WordPress.org. Thanks! :)
User avatar
Cristián Lávaque
Developer
Developer
 
Posts: 6836
Joined: December 22, 2010

Re: members registering by-passing required fields

Postby 21inspired » August 24th, 2011, 2:37 am

@Jason - any news on the server-side validation future release?

One of our clients using s2memberpro has started receiving numerous spam registrations (began yesterday).
User avatar
21inspired
Registered User
Registered User
 
Posts: 12
Joined: October 14, 2010

Re: members registering by-passing required fields

Postby Jason Caldwell » August 27th, 2011, 2:48 pm

Thanks for your patience.
21inspired wrote:@Jason - any news on the server-side validation future release?

One of our clients using s2memberpro has started receiving numerous spam registrations (began yesterday).

Sorry, I don't have an exact date yet, but yes, we are still working toward this. In the mean time, I would implement a CAPTCHA of some kind, to help prevent automated form submissions.
~ Jason Caldwell / Lead Developer
& Zeitgeist Movie Advocate: http://www.zeitgeistmovie.com/

Is the s2Member plugin working for you? Please rate s2Member at WordPress.org.
You'll need a WordPress.org account ( comes in handy ). Then rate s2Member here Image
.
User avatar
Jason Caldwell
Lead Developer
Lead Developer
 
Posts: 4045
Joined: May 3, 2010
Location: Georgia / USA

Re: members registering by-passing required fields

Postby antseo » September 17th, 2011, 11:01 pm

Hi Jason. Yes, I just experienced a spammer tonight. I would be interested in that feature being in future release. In the meantime, I'll use the captcha you've recommended.
User avatar
antseo
Experienced User
Experienced User
 
Posts: 127
Joined: September 2, 2011

Re: members registering by-passing required fields

Postby dapike » November 26th, 2011, 7:39 am

The site that I oversee has evidently been the target of a similar spam attack that started on Thursday (Thanksgiving no less), whereby bogus registrants are clearly bypassing the intended registration form since they have blank data for all of the mandatory registration fields. Please please please, can something be done to block them? And yes, I do have the SI CAPTCHA plugin installed already.

Thanks,

- David.
User avatar
dapike
Registered User
Registered User
 
Posts: 9
Joined: October 5, 2010


Return to s2Member Plugin

Who is online

Users browsing this forum: Yahoo [Bot] and 2 guests

cron