Passa al contenuto
Odoo Menu
  • Accedi
  • Provalo gratis
  • App
    Finanze
    • Contabilità
    • Fatturazione
    • Note spese
    • Fogli di calcolo (BI)
    • Documenti
    • Firma
    Vendite
    • CRM
    • Vendite
    • Punto vendita Negozio
    • Punto vendita Ristorante
    • Abbonamenti
    • Noleggi
    Siti web
    • Configuratore sito web
    • E-commerce
    • Blog
    • Forum
    • Live chat
    • E-learning
    Supply chain
    • Magazzino
    • Produzione
    • PLM
    • Acquisti
    • Manutenzione
    • Qualità
    Risorse umane
    • Dipendenti
    • Assunzioni
    • Ferie
    • Valutazioni
    • Referral dipendenti
    • Parco veicoli
    Marketing
    • Social marketing
    • E-mail marketing
    • SMS marketing
    • Eventi
    • Marketing automation
    • Sondaggi
    Servizi
    • Progetti
    • Fogli ore
    • Assistenza sul campo
    • Helpdesk
    • Pianificazione
    • Appuntamenti
    Produttività
    • Comunicazioni
    • Approvazioni
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    App di terze parti Odoo Studio Piattaforma cloud Odoo
  • Settori
    Retail
    • Libreria
    • Negozio di abbigliamento
    • Negozio di arredamento
    • Alimentari
    • Ferramenta
    • Negozio di giocattoli
    Cibo e ospitalità
    • Bar e pub
    • Ristorante
    • Fast food
    • Pensione
    • Grossista di bevande
    • Hotel
    Agenzia immobiliare
    • Agenzia immobiliare
    • Studio di architettura
    • Edilizia
    • Gestione immobiliare
    • Impresa di giardinaggio
    • Associazione di proprietari immobiliari
    Consulenza
    • Società di contabilità
    • Partner Odoo
    • Agenzia di marketing
    • Studio legale
    • Selezione del personale
    • Audit e certificazione
    Produzione
    • Tessile
    • Metallo
    • Arredamenti
    • Alimentare
    • Birrificio
    • Ditta di regalistica aziendale
    Benessere e sport
    • Club sportivo
    • Negozio di ottica
    • Centro fitness
    • Centro benessere
    • Farmacia
    • Parrucchiere
    Commercio
    • Tuttofare
    • Hardware e assistenza IT
    • Ditta di installazione di pannelli solari
    • Calzolaio
    • Servizi di pulizia
    • Servizi di climatizzazione
    Altro
    • Organizzazione non profit
    • Ente per la tutela ambientale
    • Agenzia di cartellonistica pubblicitaria
    • Studio fotografico
    • Punto noleggio di biciclette
    • Rivenditore di software
    Carica tutti i settori
  • Community
    Apprendimento
    • Tutorial
    • Documentazione
    • Certificazioni 
    • Formazione
    • Blog
    • Podcast
    Potenzia la tua formazione
    • Programma educativo
    • Scale Up! Business Game
    • Visita Odoo
    Ottieni il software
    • Scarica
    • Versioni a confronto
    • Note di versione
    Collabora
    • Github
    • Forum
    • Eventi
    • Traduzioni
    • Diventa nostro partner
    • Servizi per partner
    • Registra la tua società di contabilità
    Ottieni servizi
    • Trova un partner
    • Trova un contabile
    • Incontra un esperto
    • Servizi di implementazione
    • Testimonianze dei clienti
    • Supporto
    • Aggiornamenti
    GitHub Youtube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Richiedi una demo
  • Prezzi
  • Aiuto

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Contabilità
  • Magazzino
  • PoS
  • Progetti
  • MRP
All apps
È necessario essere registrati per interagire con la community.
Tutti gli articoli Persone Badge
Etichette (Mostra tutto)
odoo accounting v14 pos v15
Sul forum
È necessario essere registrati per interagire con la community.
Tutti gli articoli Persone Badge
Etichette (Mostra tutto)
odoo accounting v14 pos v15
Sul forum
Assistenza

eCommerce in Odoo 16 - New random fake user accounts [SOLVED]

Iscriviti

Ricevi una notifica quando c'è un'attività per questo post

La domanda è stata contrassegnata
accountsbotsvirusUsersodoo16
13 Risposte
6223 Visualizzazioni
Avatar
Patrick Sedney Palomar

For inquiries about the solution module, you can e-mail me at psedney@hotmail.com


Hi all,

For the last 3 or 4 days, I've been suffering what looks like a bot attack or something.

I'm running an Odoo 16 eCommerce and it's been somewhere between 100 and 150 new fake users with random names and e-mails.

I've tried to add a recaptcha module for the Sign Up page, but still having the issue with new fake users.

They are all coming from different IP addresses, most likely from VPN servers.

Now, I don't know where the problem is exacty. I've updated and upgraded the list of services in Ubuntu and still the problem.

I'll be glad if anybody can point me to the right direction.

Thank you so much

4
Avatar
Abbandona
Raynald CANDELIER

same issue !  There is no email validation to create an account user ,then the website is exposed for hacks...

wilfried

Same issue here (Odoo 17 online). Around 100 - 120 fake accounts every day and password reset attempts for these accounts. No idea how to stop this.

Patrick Sedney Palomar
Autore

In my case, everyone of these fake accounts are open from the French version of my website. Don't know if that's your case too.
I've been wondering about blocking the French version in the website and see what happens.

Patrick Sedney Palomar
Autore

Good News!

Thanks to the ideas of André Canilho in this post, I've come to a possible solution for this issue.
Given the fact that, at least in my specific case, every name in every fake account is a random name with random uppercase and lowercase letters, I've developed a small module that will control the field "name" to only have one capital letter per word.
That, along with a reCaptcha validation seems to work adding new users (the reCaptcha by itself wouldn't do anything for this matter).

I've installed it it my iteration of odoo and I'm running successful sign up tests at the moment. If in a day or two this fake user creation has been controlled, I'll share the module.

Patrick Sedney Palomar
Autore

Well, finally, I can say my module works. I had no fake accounts for a whole week. 😄
If anybody is interested in the module send me a message!

Els Guns (osadmin.be)

Hi Patrick
I'm experiencing the same issue and I'm interested in your module. I see I need to drop you an e-mail but I am not sure where to find your address? :-) Thank you!

Patrick Sedney Palomar
Autore

you can find my address written below, but here it is again
psedney@hotmail.com

administration@zoratech.lu

Hello can i have the module administration@zoratech.lu

Thanks a lot

Avatar
Niyas Raphy (Walnut Software Solutions)
Risposta migliore

Hi,
Try enabling this feature and see how it goes:  https://odoo-community.org/shop/verify-email-at-signup-545

Thanks

2
Avatar
Abbandona
Massimiliano Gandini

I have the same problem, but my odoo is online, can I use the https://odoo-community.org/shop/verify-email-at-signup-545 ? Thanks

Avatar
Javier Ruiz Diez - 71341924H
Risposta migliore

Please check:-

https://apps.odoo.com/apps/modules/18.0/recaptcha_signup

1
Avatar
Abbandona
Avatar
Patrick Sedney Palomar
Autore Risposta migliore

I've just found out that the e-mail addresses in the fake accounts are real. Not only the majority of them aren't being returned, but some are giving back automatic away replies set up by users.

This is a bigger issue than I thought, as the domain might be flagged as spammer over time.

Did anybody find any solutions? Two days ago I updated and upgraded Ubuntu services and it got worse...

1
Avatar
Abbandona
wilfried

Indeed, very bad for email server reputation.

I opened a support ticket weeks ago. Odoo plans to protect the signup page by ReCAPTCHA, as this is not the case at this moment. I'm deleting fake users and fake contacts on a daily basis, but that doesn't prevent all these emails from being sent.

wilfried

My domain just got blocked by onmicrosoft.com because of "flooding".

Avatar
Misalf
Risposta migliore

Same issue here.

Exactly the same !

100 fake accounts are being accepted by Odoo every day since 1 month approx.

ReCAPTCHA V3 is not able to avoiding them, no way to stop them even on max score defense (1.0).

Email validation does not fix at all, because spammers are anyway registering. Odoo default allow web account sign-up, no matter email being verified or not. Even not verified, any sign-up account is being create as not-connected "portal user" and partner "contact". 

Thas is a real flow at Odoo.

There is no way to stop them.

HELP.

PS: we are on self hosted Odoo.


 


1
Avatar
Abbandona
Avatar
André Canilho
Risposta migliore

This looks like a coordinated attack, with 2 processes running from the same machine, and constantly switching their VPN host. 

There are multiple measures that you can put in place just to disable it, but that doesn't mean the attacker will not adapt to those measures.

First of all, make sure you are not using any default passwords for your database or for your Oddo configuration.
Set in place a second validation for the username, for instance, right now, the bot is creating users with a lot of uppercase letters. 

You can force usernames to only have one uppercase letter and those accounts will not be allowed.
You could also set in place a human validation system (CAPTCHA)  when the account is created, to limit bot accounts. 

Not allowing more than one account to be created from the same IP is another possibility, that will immediately reduce half of those account creations. 

1
Avatar
Abbandona
Patrick Sedney Palomar
Autore

That all makes a lot of sense.
I'll try to find de way to do that.
Thank you so much!

wilfried

This might work for Odoo.sh or self hosted Odoo, but in Odoo online, there is no way to implement the suggested measures: no way to force usernames in a certain format, Google CAPTCHA (v3) doesn't prevent the creation of these fake accounts, no way to filter on IP address.
I can only manually delete 100 - 150 user accounts and related contacts, every day again.
I would really like Odoo to step in here and think of a solution for Odoo Online customers.

Avatar
Marcos
Risposta migliore

@patrick could you please send-me the module to? my emails is mendez.foto@gmail.com

0
Avatar
Abbandona
Avatar
Eduardo Baltazar Castañón Humanizardo
Risposta migliore

Hi Patrick ! can I get your module please ? 

This is my Email: humanizar.do@gmail.com

thank you very much :) 

0
Avatar
Abbandona
Avatar
Pasquale Barretta
Risposta migliore

Normally, bots fill in all fields. Couldn't we consider adding a hidden field to the registration form and, if it is filled in, prevent the registration from proceeding?

0
Avatar
Abbandona
Avatar
Luca
Risposta migliore

@patrick

Please check your email

0
Avatar
Abbandona
Patrick Sedney Palomar
Autore

I see no e-mails from you. Please, check you've sent it to the right address. Thanks

Avatar
Miguel Angel Jimenez Gordillo
Risposta migliore

I'm also having this issue, I removed the option for the portal users to be able to request a password reset to avoid spamming. I'm interested in the module solution if possible. 

0
Avatar
Abbandona
Patrick Sedney Palomar
Autore

Miguel Ángel, drop me an e-mail and I will send you the module so you can try. It's important for you to have a test platform before putting it in production.

Miguel Ángel, puedes enviarme un e-mail a psedney@hotmail.com y te enviaré el módulo.
Es importante que tengas un entorno de pruebas para comprobar que quede bien instalado en tu Odoo ya que no puedo hacerme responsable de cualquier pérdida de datos que puedas tener por incompatibilidad.

Miguel Angel Jimenez Gordillo

Hello Patrick, I sent ou an email a while ago, not sure if you received it, I'll send you a new one today. Thanks in advance for your help.

Avatar
Haris Ramdedovic
Risposta migliore

Hi all
Have the Same issue. 
The comment out of signup form is no option for me. Only temporary.

Is there anyway to fix this issue?

Greetings,

0
Avatar
Abbandona
Avatar
Cristofferson Reyes
Risposta migliore

Exactly same issue here. 

Anyone with a solution? 

0
Avatar
Abbandona
Avatar
Bert Super
Risposta migliore

I have commented out the signup/login webpage. I add portal users manually anyway. The last couple of days no new fake accounts have appeared.

0
Avatar
Abbandona
Ti stai godendo la conversazione? Non leggere soltanto, partecipa anche tu!

Crea un account oggi per scoprire funzionalità esclusive ed entrare a far parte della nostra fantastica community!

Registrati
Post correlati Risposte Visualizzazioni Attività
Automatic Batch Transfer Risolto
odoo16
Avatar
Avatar
1
ago 25
1482
Operacion No valida fecha limite y Viceversa
accounts
Avatar
Avatar
Avatar
Avatar
Avatar
4
ago 25
3499
Automatic Batch Transfer
odoo16
Avatar
Avatar
1
mag 25
2318
Portal Users Risolto
Users
Avatar
Avatar
1
apr 25
1951
Bank statement import via email
odoo16
Avatar
0
nov 24
2247
Community
  • Tutorial
  • Documentazione
  • Forum
Open source
  • Scarica
  • Github
  • Runbot
  • Traduzioni
Servizi
  • Hosting Odoo.sh
  • Supporto
  • Aggiornamenti
  • Sviluppi personalizzati
  • Formazione
  • Trova un contabile
  • Trova un partner
  • Diventa nostro partner
Chi siamo
  • La nostra azienda
  • Branding
  • Contattaci
  • Lavora con noi
  • Eventi
  • Podcast
  • Blog
  • Clienti
  • Note legali • Privacy
  • Sicurezza
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo è un gestionale di applicazioni aziendali open source pensato per coprire tutte le esigenze della tua azienda: CRM, Vendite, E-commerce, Magazzino, Produzione, Fatturazione elettronica, Project Management e molto altro.

Il punto di forza di Odoo è quello di offrire un ecosistema unico di app facili da usare, intuitive e completamente integrate tra loro.

Website made with

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now