Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Registration and approval email  (Read 4235 times)

0 Members and 1 Guest are viewing this topic.

cgc0202

  • Coppermine frequent poster
  • ***
  • Offline Offline
  • Posts: 199
Registration and approval email
« on: May 30, 2007, 07:31:34 pm »

Hello,

I hope this is the correct place to post this, but as Admin of the photogallery site, I request approval of those who registered.  The auto-email sent to me though is not very informative:

"A new user with the username "plain_lion" has registered in your gallery.

 In order to activate the account, you need to click on the link below or copy and paste it in your web browser.

http://mygallery/register.php?activate=aa9105909daa6b48fe977a5c60770169"

Not knowing who "plain_lion" is I now have to login into the gallery to find out who (s)he is.  Is there a way so that the information in the registration sheet be transmitted also, especially the email and website, if needed?

What I found more disturbing today is that, a bot most likely was able to register -- I was not sent a notification for this, at all.   It had been sitting in the site for a bit and found out about it only because someone registered.  And, this one was on the site for a bit of already.  How could it have by-passed the procedure?  I did not recognize the name at all, and fortunately it gave a URL address.  When I checked the URL it was hardcore porn.

Had it succeeded to post any of its photos, my webhosting service would have deleted my entire account  because posting nude photos is not allowed -- they do not even accept nude art photos, like "David"  by Micheangelo.  So, porn photos would even be a more grave violation.  Porn sites also, I was told has ways to plant "phish" and other datagathering info.  And, I think that was the intent of the porn registrant.

To circumvent automated bots from registration, the other programs I use instituted a verification procedure, like writing down the challenge codes.  Can this not be instituted also?

I hope these issue are addressed.

Cornelio

Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Registration and approval email
« Reply #1 on: May 31, 2007, 08:18:32 am »

Post an actual link to your gallery for a start...
Logged
Pages: [1]   Go Up
 

Page created in 0.017 seconds with 19 queries.