Skip to Content
Menu
This question has been flagged
13 Replies
3110 Views

For inquiries about the solution module, you can e-mail me at psedney@hotmail.com


Hi all,

For the last 3 or 4 days, I've been suffering what looks like a bot attack or something.

I'm running an Odoo 16 eCommerce and it's been somewhere between 100 and 150 new fake users with random names and e-mails.

I've tried to add a recaptcha module for the Sign Up page, but still having the issue with new fake users.

They are all coming from different IP addresses, most likely from VPN servers.

Now, I don't know where the problem is exacty. I've updated and upgraded the list of services in Ubuntu and still the problem.

I'll be glad if anybody can point me to the right direction.

Thank you so much

Avatar
Discard

same issue !  There is no email validation to create an account user ,then the website is exposed for hacks...

Same issue here (Odoo 17 online). Around 100 - 120 fake accounts every day and password reset attempts for these accounts. No idea how to stop this.

Author

In my case, everyone of these fake accounts are open from the French version of my website. Don't know if that's your case too.
I've been wondering about blocking the French version in the website and see what happens.

Author

Good News!

Thanks to the ideas of André Canilho in this post, I've come to a possible solution for this issue.
Given the fact that, at least in my specific case, every name in every fake account is a random name with random uppercase and lowercase letters, I've developed a small module that will control the field "name" to only have one capital letter per word.
That, along with a reCaptcha validation seems to work adding new users (the reCaptcha by itself wouldn't do anything for this matter).

I've installed it it my iteration of odoo and I'm running successful sign up tests at the moment. If in a day or two this fake user creation has been controlled, I'll share the module.

Author

Well, finally, I can say my module works. I had no fake accounts for a whole week. 😄
If anybody is interested in the module send me a message!

Hi Patrick
I'm experiencing the same issue and I'm interested in your module. I see I need to drop you an e-mail but I am not sure where to find your address? :-) Thank you!

Author

you can find my address written below, but here it is again
psedney@hotmail.com

Best Answer

Hi,
Try enabling this feature and see how it goes:  https://odoo-community.org/shop/verify-email-at-signup-545

Thanks

Avatar
Discard

I have the same problem, but my odoo is online, can I use the https://odoo-community.org/shop/verify-email-at-signup-545 ? Thanks

Author Best Answer

I've just found out that the e-mail addresses in the fake accounts are real. Not only the majority of them aren't being returned, but some are giving back automatic away replies set up by users.

This is a bigger issue than I thought, as the domain might be flagged as spammer over time.

Did anybody find any solutions? Two days ago I updated and upgraded Ubuntu services and it got worse...

Avatar
Discard

Indeed, very bad for email server reputation.

I opened a support ticket weeks ago. Odoo plans to protect the signup page by ReCAPTCHA, as this is not the case at this moment. I'm deleting fake users and fake contacts on a daily basis, but that doesn't prevent all these emails from being sent.

My domain just got blocked by onmicrosoft.com because of "flooding".

Best Answer

Same issue here.

Exactly the same !

100 fake accounts are being accepted by Odoo every day since 1 month approx.

ReCAPTCHA V3 is not able to avoiding them, no way to stop them even on max score defense (1.0).

Email validation does not fix at all, because spammers are anyway registering. Odoo default allow web account sign-up, no matter email being verified or not. Even not verified, any sign-up account is being create as not-connected "portal user" and partner "contact". 

Thas is a real flow at Odoo.

There is no way to stop them.

HELP.

PS: we are on self hosted Odoo.


 


Avatar
Discard
Best Answer

This looks like a coordinated attack, with 2 processes running from the same machine, and constantly switching their VPN host. 

There are multiple measures that you can put in place just to disable it, but that doesn't mean the attacker will not adapt to those measures.

First of all, make sure you are not using any default passwords for your database or for your Oddo configuration.
Set in place a second validation for the username, for instance, right now, the bot is creating users with a lot of uppercase letters. 

You can force usernames to only have one uppercase letter and those accounts will not be allowed.
You could also set in place a human validation system (CAPTCHA)  when the account is created, to limit bot accounts. 

Not allowing more than one account to be created from the same IP is another possibility, that will immediately reduce half of those account creations. 

Avatar
Discard
Author

That all makes a lot of sense.
I'll try to find de way to do that.
Thank you so much!

This might work for Odoo.sh or self hosted Odoo, but in Odoo online, there is no way to implement the suggested measures: no way to force usernames in a certain format, Google CAPTCHA (v3) doesn't prevent the creation of these fake accounts, no way to filter on IP address.
I can only manually delete 100 - 150 user accounts and related contacts, every day again.
I would really like Odoo to step in here and think of a solution for Odoo Online customers.

Best Answer

@patrick could you please send-me the module to? my emails is mendez.foto@gmail.com

Avatar
Discard
Best Answer

Hi Patrick ! can I get your module please ? 

This is my Email: humanizar.do@gmail.com

thank you very much :) 

Avatar
Discard
Best Answer

Normally, bots fill in all fields. Couldn't we consider adding a hidden field to the registration form and, if it is filled in, prevent the registration from proceeding?

Avatar
Discard
Best Answer

@patrick

Please check your email

Avatar
Discard
Author

I see no e-mails from you. Please, check you've sent it to the right address. Thanks

Best Answer

I'm also having this issue, I removed the option for the portal users to be able to request a password reset to avoid spamming. I'm interested in the module solution if possible. 

Avatar
Discard
Author

Miguel Ángel, drop me an e-mail and I will send you the module so you can try. It's important for you to have a test platform before putting it in production.

Miguel Ángel, puedes enviarme un e-mail a psedney@hotmail.com y te enviaré el módulo.
Es importante que tengas un entorno de pruebas para comprobar que quede bien instalado en tu Odoo ya que no puedo hacerme responsable de cualquier pérdida de datos que puedas tener por incompatibilidad.

Hello Patrick, I sent ou an email a while ago, not sure if you received it, I'll send you a new one today. Thanks in advance for your help.

Best Answer

Hi all
Have the Same issue. 
The comment out of signup form is no option for me. Only temporary.

Is there anyway to fix this issue?

Greetings,

Avatar
Discard
Best Answer

Exactly same issue here. 

Anyone with a solution? 

Avatar
Discard
Best Answer

I have commented out the signup/login webpage. I add portal users manually anyway. The last couple of days no new fake accounts have appeared.

Avatar
Discard
Related Posts Replies Views Activity
1
May 25
184
1
Apr 25
279
2
Jan 25
1212
0
Nov 24
711
2
Oct 24
683