Results 1 to 4 of 4

Thread: Registrations still appear when the option is switched off - Why and how?

  1. #1
    Thread Starter
    limecanvas's Avatar
    Join Date
    Mar 2013
    Location
    Australia
    Posts
    12
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Registrations still appear when the option is switched off - Why and how?

    I have a WP 4.0 installation with ClassiPress 3.3.2 and the Classi Sky child theme.

    In General > Settings I have Membership > Anyone can register unchecked (the option is off)

    The registration page does not have the registration form on it.
    "** User registration is currently disabled. Please contact the site administrator. **"

    However, contributor registrations are still appearing in the database. I need to know how this is happening when the registration form is disabled.

    I placed a hook on "user_register" to email me when a registration took place. I receive an email for each spam registration. This assures me that the registrations are happening through WordPress and not via SQL/cPanel or any other malicious script.

    I checked the site logs and the spam registrations are posting through the registration page. Here's the HTTP requests (IP and Site URL redacted):

    IP REDACTED - - [11/Nov/2014:13:32:54 +0000] "POST /register/ HTTP/1.1" 302 - "SITE REDACTED/register/" "Mozilla/5.0 (Windows NT 6.1; rv:13.0) Gecko/20100101 Firefox/13.0"

    IP REDACTED - - [11/Nov/2014:13:32:57 +0000] "GET / HTTP/1.1" 200 138849 "-" "Mozilla/5.0 (Windows NT 6.1; rv:13.0) Gecko/20100101 Firefox/13.0"

    The request clearly shows that the user registered through the /register/ page - but there is no form!

    The site has been scanned with sucuri and there are fresh installations of WordPress 4.0 and ClassiPress 3.3.2.

    Interestingly, if I switch to Twenty Twelve (or any other Twenty x themes) the spam registrations stop completely.

    If I switch to the main ClassiPress theme (rather than the child Classi Sky) spam registrations start up again.

    So, somehow users are able to still register on the /register/ page of ClassiPress even when Membership is disabled (General > Settings) and there is no registration form showing on the front end.

    How are they doing this?

    Thanks,
    Wil.

  2. #2
    Thread Starter
    limecanvas's Avatar
    Join Date
    Mar 2013
    Location
    Australia
    Posts
    12
    Thanks
    0
    Thanked 0 Times in 0 Posts
    You must be an AppThemes customer and logged in to view this response. Join today!

  3. #3
    samcy's Avatar
    Join Date
    Mar 2012
    Location
    Germany
    Posts
    12,098
    Thanks
    121
    Thanked 1,756 Times in 1,442 Posts
    You must be an AppThemes customer and logged in to view this response. Join today!
    Rolf Hassel (Samcy)

  4. #4
    Thread Starter
    limecanvas's Avatar
    Join Date
    Mar 2013
    Location
    Australia
    Posts
    12
    Thanks
    0
    Thanked 0 Times in 0 Posts
    You must be an AppThemes customer and logged in to view this response. Join today!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 4
    Last Post: October 18th, 2014, 11:53 AM
  2. [SOLVED] New Registrations
    By muadmz in forum HireBee General Discussion
    Replies: 3
    Last Post: July 7th, 2014, 08:43 AM
  3. Replies: 1
    Last Post: December 12th, 2013, 11:01 AM
  4. New User REgistrations
    By andreajgriffin in forum Report ClassiPress Bugs
    Replies: 3
    Last Post: May 18th, 2012, 09:19 AM