Jump to content
thirty bees forum
  • 0

Spam attack via contact form


vsn

Question

Dear all, I am currently suffering under a heavy spam attack. The standard contact form is used filled with target email address and target message. After submitting it, a confirmation email is automatically sent out from the e-shop server to the target email address compromising my email address, domain and server IP. 

As a workaround I renamed contact form URL, this helps for a while. But as the contact form is a public URL it can be used again any time.

I am using google re-captcha v2. This does not help, they somehow overcome it. Re-captcha V3, which seems to be more advanced, does not work.

Any ideas???

Link to comment
Share on other sites

3 answers to this question

Recommended Posts

  • 0
38 minutes ago, vsn said:

Dear all, I am currently suffering under a heavy spam attack. The standard contact form is used filled with target email address and target message. After submitting it, a confirmation email is automatically sent out from the e-shop server to the target email address compromising my email address, domain and server IP. 

As a workaround I renamed contact form URL, this helps for a while. But as the contact form is a public URL it can be used again any time.

I am using google re-captcha v2. This does not help, they somehow overcome it. Re-captcha V3, which seems to be more advanced, does not work.

Any ideas???

There's a bug in captcha module that allows contact form submission when Login attempts settings is set to non-zero value. So this should be the first thing you should check.

image.png.b4b7b7ba586a6aa889e942a750066a33.png

  • Like 1
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...