30
Quote:
BDW wrote:
actually, heres my thought.
If XOOPS is now being exploited by Spam Bots that can activate their accounts even though you have set your site to email activation only then surely there is a security issue within xoops.
this should be looked into ASAP.
Good thought, but the one registration that I had wasn't activated at the time I spotted it.
Could it be that all those email addresses used to refgister the accounts forward to another (single) place and there's a real person clicking the links?
My site doesn't allow anonymous postings/comments, so perhaps I'm lucky in that I intercepted the account before it was activated.
I don't get many user activations on my site so I might set the system to "Activation by administrators" until this business quietens down.
Oh, and I back-up my database twice a day at the moment