Simple Membership Plugin › Forums › Simple Membership Plugin › Hackers injecting members
Tagged: Hackers injecting members
- This topic has 3 replies, 2 voices, and was last updated 2 years, 3 months ago by
The Assurer.
-
AuthorPosts
-
July 2, 2024 at 12:48 pm #28348
shiplofts
ParticipantGood Day Support & community, I have version of Simple WordPress Membership installed, newest being the current release.
Both are receiving membership injections. Seems a bot is successfully inserting a member that shows up on the Membership::Members. These stay in Activation Required mode and tend to come from different ip address and is inserted a fake / undeliverables email address. The failed message sit in the WWW- email account as bounces.
94.103.188.103 – – [02/Jul/2024:05:23:43 -0700] “GET /registration/ HTTP/2.0” 200 54251 “” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36”
94.103.188.103 – – [02/Jul/2024:05:23:46 -0700] “POST / HTTP/2.0” 200 98144 “https://XXXXXXXX.com/registration/” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36”Any assistance would be appreciated as we get 10-20 of these per day.
-D
July 2, 2024 at 10:01 pm #28349The Assurer
ModeratorThese stay in Activation Required…
So, the default behavior of SWPM is keeping the bots at bay, but your tables are filling up wuth junk entries.
Please take a look at this:
These stay in Activation Required
https://simple-membership-plugin.com/blacklisting-whitelisting-feature/Another idea is to require a token payment of $0.50 to register. This small amount not only covers your payment processing fee, but you will generate a token revenue stream. The $0.50 amount is the minimum you can accept with Stripe. PayPal will accept a lower amount, but you want to recover your processing fee.
July 2, 2024 at 10:19 pm #28350shiplofts
ParticipantNot only tables filing up, but also the mail system tries to sent out emails to these bogus accounts as well. These get stuck in www-mail account, which builds up as well and because of all the bad mail, lowers your mail reputation score with the large providers such as Gmail.
Each time is a different IP & email combination, so whitelist/blacklist is not a solution.
I wish I could charge a fee for but, but unfortunately cannot.
If these are indeed coming from a Bot, how is it getting past Captcha v3
There has to be a better solution to the issue.
July 4, 2024 at 11:33 pm #28355The Assurer
ModeratorIf these are indeed coming from a Bot, how is it getting past Captcha v3
AI — Captcha v3 is over 6 years old. And that’s not all — per Wikipedia… “In October 2023, it was found that OpenAI’s GPT-4 chatbot could solve CAPTCHAs.”
Your best strategy is to charge a $1 registration fee, good for a discount on a paid membership. That’s what I would do.
-
AuthorPosts
- You must be logged in to reply to this topic.