Pular para o conteúdo
Odoo Menu
  • Entrar
  • Experimente grátis
  • Aplicativos
    Finanças
    • Financeiro
    • Faturamento
    • Despesas
    • Planilhas (BI)
    • Documentos
    • Assinar Documentos
    Vendas
    • CRM
    • Vendas
    • PDV Loja
    • PDV Restaurantes
    • Assinaturas
    • Locação
    Websites
    • Criador de Sites
    • e-Commerce
    • Blog
    • Fórum
    • Chat ao Vivo
    • e-Learning
    Cadeia de mantimentos
    • Inventário
    • Fabricação
    • PLM - Ciclo de Vida do Produto
    • Compras
    • Manutenção
    • Qualidade
    Recursos Humanos
    • Funcionários
    • Recrutamento
    • Folgas
    • Avaliações
    • Indicações
    • Frota
    Marketing
    • Redes Sociais
    • Marketing por E-mail
    • Marketing por SMS
    • Eventos
    • Automação de Marketing
    • Pesquisas
    Serviços
    • Projeto
    • Planilhas de Horas
    • Serviço de Campo
    • Central de Ajuda
    • Planejamento
    • Compromissos
    Produtividade
    • Mensagens
    • Aprovações
    • Internet das Coisas
    • VoIP
    • Conhecimento
    • WhatsApp
    Aplicativos de terceiros Odoo Studio Plataforma Odoo Cloud
  • Setores
    Varejo
    • Loja de livros
    • Loja de roupas
    • Loja de móveis
    • Mercearia
    • Loja de ferramentas
    • Loja de brinquedos
    Comida e hospitalidade
    • Bar e Pub
    • Restaurante
    • Fast Food
    • Hospedagem
    • Distribuidor de bebidas
    • Hotel
    Imóveis
    • Imobiliária
    • Escritório de arquitetura
    • Construção
    • Administração de propriedades
    • Jardinagem
    • Associação de proprietários de imóveis
    Consultoria
    • Escritório de Contabilidade
    • Parceiro Odoo
    • Agência de marketing
    • Escritório de advocacia
    • Aquisição de talentos
    • Auditoria e Certificação
    Fabricação
    • Têxtil
    • Metal
    • Móveis
    • Alimentação
    • Cervejaria
    • Presentes corporativos
    Saúde e Boa forma
    • Clube esportivo
    • Loja de óculos
    • Academia
    • Profissionais de bem-estar
    • Farmácia
    • Salão de cabeleireiro
    Comércio
    • Handyman
    • Hardware e Suporte de TI
    • Sistemas de energia solar
    • Sapataria
    • Serviços de limpeza
    • Serviços de climatização
    Outros
    • Organização sem fins lucrativos
    • Agência Ambiental
    • Aluguel de outdoors
    • Fotografia
    • Aluguel de bicicletas
    • Revendedor de software
    Navegar por todos os setores
  • Comunidade
    Aprenda
    • Tutoriais
    • Documentação
    • Certificações
    • Treinamento
    • Blog
    • Podcast
    Empodere a Educação
    • Programa de educação
    • Scale Up! Jogo de Negócios
    • Visite a Odoo
    Obtenha o Software
    • Baixar
    • Comparar edições
    • Releases
    Colaborar
    • Github
    • Fórum
    • Eventos
    • Traduções
    • Torne-se um parceiro
    • Serviços para parceiros
    • Cadastre seu escritório contábil
    Obtenha os serviços
    • Encontre um parceiro
    • Encontre um Contador
    • Conheça um consultor
    • Serviços de Implementação
    • Referências de Clientes
    • Suporte
    • Upgrades
    Github YouTube Twitter Linkedin Instagram Facebook Spotify
    +1 (650) 691-3277
    Faça uma demonstração
  • Preços
  • Ajuda

Odoo is the world's easiest all-in-one management software.
It includes hundreds of business apps:

  • CRM
  • e-Commerce
  • Financeiro
  • Inventário
  • PoS
  • Projeto
  • MRP
All apps
É necessário estar registrado para interagir com a comunidade.
Todas as publicações Pessoas Emblemas
Marcadores (Ver tudo)
odoo accounting v14 pos v15
Sobre este fórum
É necessário estar registrado para interagir com a comunidade.
Todas as publicações Pessoas Emblemas
Marcadores (Ver tudo)
odoo accounting v14 pos v15
Sobre este fórum
Ajuda

eCommerce in Odoo 16 - New random fake user accounts [SOLVED]

Inscrever

Seja notificado quando houver atividade nesta publicação

Esta pergunta foi sinalizada
accountsbotsvirusUsersodoo16
13 Respostas
6215 Visualizações
Avatar
Patrick Sedney Palomar

For inquiries about the solution module, you can e-mail me at psedney@hotmail.com


Hi all,

For the last 3 or 4 days, I've been suffering what looks like a bot attack or something.

I'm running an Odoo 16 eCommerce and it's been somewhere between 100 and 150 new fake users with random names and e-mails.

I've tried to add a recaptcha module for the Sign Up page, but still having the issue with new fake users.

They are all coming from different IP addresses, most likely from VPN servers.

Now, I don't know where the problem is exacty. I've updated and upgraded the list of services in Ubuntu and still the problem.

I'll be glad if anybody can point me to the right direction.

Thank you so much

4
Avatar
Cancelar
Raynald CANDELIER

same issue !  There is no email validation to create an account user ,then the website is exposed for hacks...

wilfried

Same issue here (Odoo 17 online). Around 100 - 120 fake accounts every day and password reset attempts for these accounts. No idea how to stop this.

Patrick Sedney Palomar
Autor

In my case, everyone of these fake accounts are open from the French version of my website. Don't know if that's your case too.
I've been wondering about blocking the French version in the website and see what happens.

Patrick Sedney Palomar
Autor

Good News!

Thanks to the ideas of André Canilho in this post, I've come to a possible solution for this issue.
Given the fact that, at least in my specific case, every name in every fake account is a random name with random uppercase and lowercase letters, I've developed a small module that will control the field "name" to only have one capital letter per word.
That, along with a reCaptcha validation seems to work adding new users (the reCaptcha by itself wouldn't do anything for this matter).

I've installed it it my iteration of odoo and I'm running successful sign up tests at the moment. If in a day or two this fake user creation has been controlled, I'll share the module.

Patrick Sedney Palomar
Autor

Well, finally, I can say my module works. I had no fake accounts for a whole week. 😄
If anybody is interested in the module send me a message!

Els Guns (osadmin.be)

Hi Patrick
I'm experiencing the same issue and I'm interested in your module. I see I need to drop you an e-mail but I am not sure where to find your address? :-) Thank you!

Patrick Sedney Palomar
Autor

you can find my address written below, but here it is again
psedney@hotmail.com

administration@zoratech.lu

Hello can i have the module administration@zoratech.lu

Thanks a lot

Avatar
Niyas Raphy (Walnut Software Solutions)
Melhor resposta

Hi,
Try enabling this feature and see how it goes:  https://odoo-community.org/shop/verify-email-at-signup-545

Thanks

2
Avatar
Cancelar
Massimiliano Gandini

I have the same problem, but my odoo is online, can I use the https://odoo-community.org/shop/verify-email-at-signup-545 ? Thanks

Avatar
Javier Ruiz Diez - 71341924H
Melhor resposta

Please check:-

https://apps.odoo.com/apps/modules/18.0/recaptcha_signup

1
Avatar
Cancelar
Avatar
Patrick Sedney Palomar
Autor Melhor resposta

I've just found out that the e-mail addresses in the fake accounts are real. Not only the majority of them aren't being returned, but some are giving back automatic away replies set up by users.

This is a bigger issue than I thought, as the domain might be flagged as spammer over time.

Did anybody find any solutions? Two days ago I updated and upgraded Ubuntu services and it got worse...

1
Avatar
Cancelar
wilfried

Indeed, very bad for email server reputation.

I opened a support ticket weeks ago. Odoo plans to protect the signup page by ReCAPTCHA, as this is not the case at this moment. I'm deleting fake users and fake contacts on a daily basis, but that doesn't prevent all these emails from being sent.

wilfried

My domain just got blocked by onmicrosoft.com because of "flooding".

Avatar
Misalf
Melhor resposta

Same issue here.

Exactly the same !

100 fake accounts are being accepted by Odoo every day since 1 month approx.

ReCAPTCHA V3 is not able to avoiding them, no way to stop them even on max score defense (1.0).

Email validation does not fix at all, because spammers are anyway registering. Odoo default allow web account sign-up, no matter email being verified or not. Even not verified, any sign-up account is being create as not-connected "portal user" and partner "contact". 

Thas is a real flow at Odoo.

There is no way to stop them.

HELP.

PS: we are on self hosted Odoo.


 


1
Avatar
Cancelar
Avatar
André Canilho
Melhor resposta

This looks like a coordinated attack, with 2 processes running from the same machine, and constantly switching their VPN host. 

There are multiple measures that you can put in place just to disable it, but that doesn't mean the attacker will not adapt to those measures.

First of all, make sure you are not using any default passwords for your database or for your Oddo configuration.
Set in place a second validation for the username, for instance, right now, the bot is creating users with a lot of uppercase letters. 

You can force usernames to only have one uppercase letter and those accounts will not be allowed.
You could also set in place a human validation system (CAPTCHA)  when the account is created, to limit bot accounts. 

Not allowing more than one account to be created from the same IP is another possibility, that will immediately reduce half of those account creations. 

1
Avatar
Cancelar
Patrick Sedney Palomar
Autor

That all makes a lot of sense.
I'll try to find de way to do that.
Thank you so much!

wilfried

This might work for Odoo.sh or self hosted Odoo, but in Odoo online, there is no way to implement the suggested measures: no way to force usernames in a certain format, Google CAPTCHA (v3) doesn't prevent the creation of these fake accounts, no way to filter on IP address.
I can only manually delete 100 - 150 user accounts and related contacts, every day again.
I would really like Odoo to step in here and think of a solution for Odoo Online customers.

Avatar
Marcos
Melhor resposta

@patrick could you please send-me the module to? my emails is mendez.foto@gmail.com

0
Avatar
Cancelar
Avatar
Eduardo Baltazar Castañón Humanizardo
Melhor resposta

Hi Patrick ! can I get your module please ? 

This is my Email: humanizar.do@gmail.com

thank you very much :) 

0
Avatar
Cancelar
Avatar
Pasquale Barretta
Melhor resposta

Normally, bots fill in all fields. Couldn't we consider adding a hidden field to the registration form and, if it is filled in, prevent the registration from proceeding?

0
Avatar
Cancelar
Avatar
Luca
Melhor resposta

@patrick

Please check your email

0
Avatar
Cancelar
Patrick Sedney Palomar
Autor

I see no e-mails from you. Please, check you've sent it to the right address. Thanks

Avatar
Miguel Angel Jimenez Gordillo
Melhor resposta

I'm also having this issue, I removed the option for the portal users to be able to request a password reset to avoid spamming. I'm interested in the module solution if possible. 

0
Avatar
Cancelar
Patrick Sedney Palomar
Autor

Miguel Ángel, drop me an e-mail and I will send you the module so you can try. It's important for you to have a test platform before putting it in production.

Miguel Ángel, puedes enviarme un e-mail a psedney@hotmail.com y te enviaré el módulo.
Es importante que tengas un entorno de pruebas para comprobar que quede bien instalado en tu Odoo ya que no puedo hacerme responsable de cualquier pérdida de datos que puedas tener por incompatibilidad.

Miguel Angel Jimenez Gordillo

Hello Patrick, I sent ou an email a while ago, not sure if you received it, I'll send you a new one today. Thanks in advance for your help.

Avatar
Haris Ramdedovic
Melhor resposta

Hi all
Have the Same issue. 
The comment out of signup form is no option for me. Only temporary.

Is there anyway to fix this issue?

Greetings,

0
Avatar
Cancelar
Avatar
Cristofferson Reyes
Melhor resposta

Exactly same issue here. 

Anyone with a solution? 

0
Avatar
Cancelar
Avatar
Bert Super
Melhor resposta

I have commented out the signup/login webpage. I add portal users manually anyway. The last couple of days no new fake accounts have appeared.

0
Avatar
Cancelar
Está gostando da discussão? Não fique apenas lendo, participe!

Crie uma conta hoje mesmo para aproveitar os recursos exclusivos e interagir com nossa incrível comunidade!

Inscreva-se
Publicações relacionadas Respostas Visualizações Atividade
Automatic Batch Transfer Resolvido
odoo16
Avatar
Avatar
1
ago. 25
1482
Operacion No valida fecha limite y Viceversa
accounts
Avatar
Avatar
Avatar
Avatar
Avatar
4
ago. 25
3496
Automatic Batch Transfer
odoo16
Avatar
Avatar
1
mai. 25
2316
Portal Users Resolvido
Users
Avatar
Avatar
1
abr. 25
1951
Bank statement import via email
odoo16
Avatar
0
nov. 24
2244
Comunidade
  • Tutoriais
  • Documentação
  • Fórum
Open Source
  • Baixar
  • Github
  • Runbot
  • Traduções
Serviços
  • Odoo.sh Hosting
  • Suporte
  • Upgrade
  • Desenvolvimentos personalizados
  • Educação
  • Encontre um Contador
  • Encontre um parceiro
  • Torne-se um parceiro
Sobre nós
  • Nossa empresa
  • Ativos da marca
  • Contato
  • Empregos
  • Eventos
  • Podcast
  • Blog
  • Clientes
  • Legal • Privacidade
  • Segurança
الْعَرَبيّة Català 简体中文 繁體中文 (台灣) Čeština Dansk Nederlands English Suomi Français Deutsch हिंदी Bahasa Indonesia Italiano 日本語 한국어 (KR) Lietuvių kalba Język polski Português (BR) română русский язык Slovenský jazyk slovenščina Español (América Latina) Español ภาษาไทย Türkçe українська Tiếng Việt

Odoo é um conjunto de aplicativos de negócios em código aberto que cobre todas as necessidades de sua empresa: CRM, comércio eletrônico, contabilidade, estoque, ponto de venda, gerenciamento de projetos, etc.

A proposta de valor exclusiva Odoo é ser, ao mesmo tempo, muito fácil de usar e totalmente integrado.

Site feito com

Odoo Experience on YouTube

1. Use the live chat to ask your questions.
2. The operator answers within a few minutes.

Live support on Youtube
Watch now