Skip ke Konten
Odoo Menu
  • Login
  • Uji coba gratis
  • Aplikasi
    Keuangan
    • Akuntansi
    • Faktur
    • Pengeluaran
    • Spreadsheet (BI)
    • Dokumen
    • Tanda Tangan
    Sales
    • CRM
    • Sales
    • POS Toko
    • POS Restoran
    • Langganan
    • Rental
    Website
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Rantai Pasokan
    • Inventaris
    • Manufaktur
    • PLM
    • Purchase
    • Maintenance
    • Kualitas
    Sumber Daya Manusia
    • Karyawan
    • Rekrutmen
    • Cuti
    • Appraisal
    • Referensi
    • Armada
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Acara
    • Otomatisasi Marketing
    • Survei
    Layanan
    • Project
    • Timesheet
    • Layanan Lapangan
    • Meja Bantuan
    • Planning
    • Appointment
    Produktivitas
    • Discuss
    • Approval
    • IoT
    • VoIP
    • Pengetahuan
    • WhatsApp
    Aplikasi pihak ketiga Odoo Studio Platform Odoo Cloud
  • Industri-Industri
    Retail
    • Toko Buku
    • Toko Baju
    • Toko Furnitur
    • Toko Kelontong
    • Toko Hardware
    • Toko Mainan
    Makanan & Hospitality
    • Bar dan Pub
    • Restoran
    • Fast Food
    • Rumah Tamu
    • Distributor Minuman
    • Hotel
    Real Estate
    • Agensi Real Estate
    • Firma Arsitektur
    • Konstruksi
    • Estate Management
    • Perkebunan
    • Asosiasi Pemilik Properti
    Konsultansi
    • Firma Akuntansi
    • Mitra Odoo
    • Agensi Marketing
    • Firma huku
    • Talent Acquisition
    • Audit & Sertifikasi
    Manufaktur
    • Tekstil
    • Logam
    • Perabotan
    • Makanan
    • Brewery
    • Corporate Gift
    Kesehatan & Fitness
    • Sports Club
    • Toko Kacamata
    • Fitness Center
    • Wellness Practitioners
    • Farmasi
    • Salon Rambut
    Perdagangan
    • Handyman
    • IT Hardware & Support
    • Sistem-Sistem Energi Surya
    • Pembuat Sepatu
    • Cleaning Service
    • Layanan HVAC
    Lainnya
    • Organisasi Nirlaba
    • Agen Lingkungan
    • Rental Billboard
    • Fotografi
    • Penyewaan Sepeda
    • Reseller Software
    Browse semua Industri
  • Komunitas
    Belajar
    • Tutorial-tutorial
    • Dokumentasi
    • Sertifikasi
    • Pelatihan
    • Blog
    • Podcast
    Empower Education
    • Program Edukasi
    • Game Bisnis 'Scale Up!'
    • Kunjungi Odoo
    Dapatkan Softwarenya
    • Download
    • Bandingkan Edisi
    • Daftar Rilis
    Kolaborasi
    • Github
    • Forum
    • Acara
    • Terjemahan
    • Menjadi Partner
    • Layanan untuk Partner
    • Daftarkan perusahaan Akuntansi Anda.
    Dapatkan Layanan
    • Temukan Mitra
    • Temukan Akuntan
    • Temui penasihat
    • Layanan Implementasi
    • Referensi Pelanggan
    • Bantuan
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Dapatkan demo
  • Harga
  • Bantuan

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Akuntansi
  • Inventaris
  • PoS
  • Project
  • MRP
All apps
Anda harus terdaftar untuk dapat berinteraksi di komunitas.
Semua Post Orang Lencana-Lencana
Label (Lihat semua)
odoo accounting v14 pos v15
Mengenai forum ini
Anda harus terdaftar untuk dapat berinteraksi di komunitas.
Semua Post Orang Lencana-Lencana
Label (Lihat semua)
odoo accounting v14 pos v15
Mengenai forum ini
Help

eCommerce in Odoo 16 - New random fake user accounts [SOLVED]

Langganan

Dapatkan notifikasi saat terdapat aktivitas pada post ini

Pertanyaan ini telah diberikan tanda
accountsbotsvirusUsersodoo16
13 Replies
6199 Tampilan
Avatar
Patrick Sedney Palomar

For inquiries about the solution module, you can e-mail me at psedney@hotmail.com


Hi all,

For the last 3 or 4 days, I've been suffering what looks like a bot attack or something.

I'm running an Odoo 16 eCommerce and it's been somewhere between 100 and 150 new fake users with random names and e-mails.

I've tried to add a recaptcha module for the Sign Up page, but still having the issue with new fake users.

They are all coming from different IP addresses, most likely from VPN servers.

Now, I don't know where the problem is exacty. I've updated and upgraded the list of services in Ubuntu and still the problem.

I'll be glad if anybody can point me to the right direction.

Thank you so much

4
Avatar
Buang
Raynald CANDELIER

same issue !  There is no email validation to create an account user ,then the website is exposed for hacks...

wilfried

Same issue here (Odoo 17 online). Around 100 - 120 fake accounts every day and password reset attempts for these accounts. No idea how to stop this.

Patrick Sedney Palomar
Penulis

In my case, everyone of these fake accounts are open from the French version of my website. Don't know if that's your case too.
I've been wondering about blocking the French version in the website and see what happens.

Patrick Sedney Palomar
Penulis

Good News!

Thanks to the ideas of André Canilho in this post, I've come to a possible solution for this issue.
Given the fact that, at least in my specific case, every name in every fake account is a random name with random uppercase and lowercase letters, I've developed a small module that will control the field "name" to only have one capital letter per word.
That, along with a reCaptcha validation seems to work adding new users (the reCaptcha by itself wouldn't do anything for this matter).

I've installed it it my iteration of odoo and I'm running successful sign up tests at the moment. If in a day or two this fake user creation has been controlled, I'll share the module.

Patrick Sedney Palomar
Penulis

Well, finally, I can say my module works. I had no fake accounts for a whole week. 😄
If anybody is interested in the module send me a message!

Els Guns (osadmin.be)

Hi Patrick
I'm experiencing the same issue and I'm interested in your module. I see I need to drop you an e-mail but I am not sure where to find your address? :-) Thank you!

Patrick Sedney Palomar
Penulis

you can find my address written below, but here it is again
psedney@hotmail.com

administration@zoratech.lu

Hello can i have the module administration@zoratech.lu

Thanks a lot

Avatar
Niyas Raphy (Walnut Software Solutions)
Jawaban Terbai

Hi,
Try enabling this feature and see how it goes:  https://odoo-community.org/shop/verify-email-at-signup-545

Thanks

2
Avatar
Buang
Massimiliano Gandini

I have the same problem, but my odoo is online, can I use the https://odoo-community.org/shop/verify-email-at-signup-545 ? Thanks

Avatar
Javier Ruiz Diez - 71341924H
Jawaban Terbai

Please check:-

https://apps.odoo.com/apps/modules/18.0/recaptcha_signup

1
Avatar
Buang
Avatar
Patrick Sedney Palomar
Penulis Jawaban Terbai

I've just found out that the e-mail addresses in the fake accounts are real. Not only the majority of them aren't being returned, but some are giving back automatic away replies set up by users.

This is a bigger issue than I thought, as the domain might be flagged as spammer over time.

Did anybody find any solutions? Two days ago I updated and upgraded Ubuntu services and it got worse...

1
Avatar
Buang
wilfried

Indeed, very bad for email server reputation.

I opened a support ticket weeks ago. Odoo plans to protect the signup page by ReCAPTCHA, as this is not the case at this moment. I'm deleting fake users and fake contacts on a daily basis, but that doesn't prevent all these emails from being sent.

wilfried

My domain just got blocked by onmicrosoft.com because of "flooding".

Avatar
Misalf
Jawaban Terbai

Same issue here.

Exactly the same !

100 fake accounts are being accepted by Odoo every day since 1 month approx.

ReCAPTCHA V3 is not able to avoiding them, no way to stop them even on max score defense (1.0).

Email validation does not fix at all, because spammers are anyway registering. Odoo default allow web account sign-up, no matter email being verified or not. Even not verified, any sign-up account is being create as not-connected "portal user" and partner "contact". 

Thas is a real flow at Odoo.

There is no way to stop them.

HELP.

PS: we are on self hosted Odoo.


 


1
Avatar
Buang
Avatar
André Canilho
Jawaban Terbai

This looks like a coordinated attack, with 2 processes running from the same machine, and constantly switching their VPN host. 

There are multiple measures that you can put in place just to disable it, but that doesn't mean the attacker will not adapt to those measures.

First of all, make sure you are not using any default passwords for your database or for your Oddo configuration.
Set in place a second validation for the username, for instance, right now, the bot is creating users with a lot of uppercase letters. 

You can force usernames to only have one uppercase letter and those accounts will not be allowed.
You could also set in place a human validation system (CAPTCHA)  when the account is created, to limit bot accounts. 

Not allowing more than one account to be created from the same IP is another possibility, that will immediately reduce half of those account creations. 

1
Avatar
Buang
Patrick Sedney Palomar
Penulis

That all makes a lot of sense.
I'll try to find de way to do that.
Thank you so much!

wilfried

This might work for Odoo.sh or self hosted Odoo, but in Odoo online, there is no way to implement the suggested measures: no way to force usernames in a certain format, Google CAPTCHA (v3) doesn't prevent the creation of these fake accounts, no way to filter on IP address.
I can only manually delete 100 - 150 user accounts and related contacts, every day again.
I would really like Odoo to step in here and think of a solution for Odoo Online customers.

Avatar
Marcos
Jawaban Terbai

@patrick could you please send-me the module to? my emails is mendez.foto@gmail.com

0
Avatar
Buang
Avatar
Eduardo Baltazar Castañón Humanizardo
Jawaban Terbai

Hi Patrick ! can I get your module please ? 

This is my Email: humanizar.do@gmail.com

thank you very much :) 

0
Avatar
Buang
Avatar
Pasquale Barretta
Jawaban Terbai

Normally, bots fill in all fields. Couldn't we consider adding a hidden field to the registration form and, if it is filled in, prevent the registration from proceeding?

0
Avatar
Buang
Avatar
Luca
Jawaban Terbai

@patrick

Please check your email

0
Avatar
Buang
Patrick Sedney Palomar
Penulis

I see no e-mails from you. Please, check you've sent it to the right address. Thanks

Avatar
Miguel Angel Jimenez Gordillo
Jawaban Terbai

I'm also having this issue, I removed the option for the portal users to be able to request a password reset to avoid spamming. I'm interested in the module solution if possible. 

0
Avatar
Buang
Patrick Sedney Palomar
Penulis

Miguel Ángel, drop me an e-mail and I will send you the module so you can try. It's important for you to have a test platform before putting it in production.

Miguel Ángel, puedes enviarme un e-mail a psedney@hotmail.com y te enviaré el módulo.
Es importante que tengas un entorno de pruebas para comprobar que quede bien instalado en tu Odoo ya que no puedo hacerme responsable de cualquier pérdida de datos que puedas tener por incompatibilidad.

Miguel Angel Jimenez Gordillo

Hello Patrick, I sent ou an email a while ago, not sure if you received it, I'll send you a new one today. Thanks in advance for your help.

Avatar
Haris Ramdedovic
Jawaban Terbai

Hi all
Have the Same issue. 
The comment out of signup form is no option for me. Only temporary.

Is there anyway to fix this issue?

Greetings,

0
Avatar
Buang
Avatar
Cristofferson Reyes
Jawaban Terbai

Exactly same issue here. 

Anyone with a solution? 

0
Avatar
Buang
Avatar
Bert Super
Jawaban Terbai

I have commented out the signup/login webpage. I add portal users manually anyway. The last couple of days no new fake accounts have appeared.

0
Avatar
Buang
Menikmati diskusi? Jangan hanya membaca, ikuti!

Buat akun sekarang untuk menikmati fitur eksklufi dan agar terlibat dengan komunitas kami!

Daftar
Post Terkait Replies Tampilan Aktivitas
Automatic Batch Transfer Diselesaikan
odoo16
Avatar
Avatar
1
Agu 25
1456
Operacion No valida fecha limite y Viceversa
accounts
Avatar
Avatar
Avatar
Avatar
Avatar
4
Agu 25
3493
Automatic Batch Transfer
odoo16
Avatar
Avatar
1
Mei 25
2281
Portal Users Diselesaikan
Users
Avatar
Avatar
1
Apr 25
1941
Bank statement import via email
odoo16
Avatar
0
Nov 24
2227
Komunitas
  • Tutorial-tutorial
  • Dokumentasi
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Terjemahan
Layanan
  • Odoo.sh Hosting
  • Bantuan
  • Peningkatan
  • Custom Development
  • Pendidikan
  • Temukan Akuntan
  • Temukan Mitra
  • Menjadi Partner
Tentang Kami
  • Perusahaan kami
  • Aset Merek
  • Hubungi kami
  • Tugas
  • Acara
  • Podcast
  • Blog
  • Pelanggan
  • Hukum • Privasi
  • Keamanan
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo adalah rangkaian aplikasi bisnis open source yang mencakup semua kebutuhan perusahaan Anda: CRM, eCommerce, akuntansi, inventaris, point of sale, manajemen project, dan seterusnya.

Mudah digunakan dan terintegrasi penuh pada saat yang sama adalah value proposition unik Odoo.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now