Buy Now
Sign in

Version 5.0.14 hacked ?

yardstudio , March 09 at 10:14
Y
yardstudio
Hi I have Joomla Joomla! 3.6.5 Stable [ Noether ] 1-December-2016 22:46 GMT with Chromoform v5 5.0.14 and my hosting provider announce me that form was sending spam
Dobrý deň,  I really want to hear your opinion. https://drive.google.com/file/d/1fxjk3Cxrkrl8p1V30JplD00mnA8wGsoM/preview,

Vďaka za registráciu na XXXX XXXXX s.r.o.. Váš účet bol vytvorený, ale pred jeho použitím musí byť aktivovaný.
Pre aktiváciu účtu použite nasledovný odkaz alebo ho skopírujte a vložte do prehliadača:
http://fluidtechnik.sk/component/users/?task=registration.activate&token=34668ebd98a18a814eed37f5bec04cb4

Po aktivácii sa môžete prihlásiť na stránke http://xxxxxxx.sk/ pomocou tohto používateľského mena a hesla:

Používateľské meno: rhadem14thromin
Heslo: xTbk6doof5

H??Received: from useron11.hostmaster.sk (localhost [127.0.0.1])
by useron11.hostmaster.sk (8.14.4/8.14.4) with ESMTP id w28HBSiU015082
for <lilbaby915@yahoo.com>; Thu, 8 Mar 2018 18:11:28 +0100
H??Received: (from sm020100@localhost)
by useron11.hostmaster.sk (8.14.4/8.14.4/Submit) id w28HBSPK015080;
Thu, 8 Mar 2018 18:11:28 +0100
H??X-Authentication-Warning: useron11.hostmaster.sk: sm020100 set sender to web@xxxxxxx.sk using -f
H??To: lilbaby915@yahoo.com
H??Subject: =?utf-8?Q?Detaily_=C3=BA=C4=8Dtu_pou=C5=BE=C3=ADvate=C4=BEa_I_really_want?= =?utf-8?Q?_to_hear_your_opinion._https://drive.google.com/file/d/1fxjk3Cx?= =?utf-8?Q?rkrl8p1V30JplD00mnA8wGsoM/preview_na_xxxxxxx_xxxxxxkia_s.r.?= =?utf-8?Q?o.?=
H??Date: Thu, 8 Mar 2018 18:11:28 +0100
H??From: "xxxxxxx xxxxxxxx s.r.o." <web@xxxxxxxx.sk>
H??Message-ID: <71a162e6a9f7755c1ee35ef8d46948da@xxxxxxxxx.sk>
H??X-Mailer: PHPMailer 5.2.16 (https://github.com/PHPMailer/PHPMailer)
H??MIME-Version: 1.0
H??Content-Type: text/plain; charset=utf-8
H??Content-Transfer-Encoding: 8bit
GreyHead
Hi yardstudio,
Do you have a Captcha enabled in your form?
Are you validating the data on the server after the form is submitted?
Bob
ChronoForms technical support
If you'd like to buy me a coffee or two, thank you very much
Y
yardstudio
No,
unfortunately I am not using recaptcha or other any security
You have some error in help, for example click on "More info on ChromoEngine.com" come to error page
2018-03-09_21-17-17.png
2018-03-09_21-17-12.png
Attachments
2018-03-09_21-17-17.png
2018-03-09_21-17-17.png
(17.29 KiB)
209 Downloads/Views
2018-03-09_21-17-12.png
2018-03-09_21-17-12.png
(27.36 KiB)
205 Downloads/Views
GreyHead
Hi yardstudio,
You'd need to ask Max about the broken links. What is your question about the ReCaptcha?
Bob
ChronoForms technical support
If you'd like to buy me a coffee or two, thank you very much
admin
H yardstudio,
If you are not using any security and have some dynamic to address then your form can be used to send spam.
You should apply the latest v5 update as well!
Best regards
Max
If your main question got answered then please mark the answer using the button!​
​Please let us know if you have any problems with the new forums text editor, we appreciate your feedback!
Y
yardstudio
Hi,
I have module version V5 RC1.2 installed and enabled.
I was try apply reCaptcha or security question, but I something doing wrong, because this not working for me and still spam comming . Here is my form code:
<div class="form-group gcore-form-row" id="form-row-firma"><label for="firma" class="control-label gcore-label-left">Firma:</label>​
​<div class="gcore-input gcore-display-table" id="fin-firma"><input name="firma" id="firma" value="" placeholder="Zadajte prosím presný názov Vašej firmy" maxlength="50" size="53" class="validate[&#039;required&#039;] form-control A" title="Zadajte prosím presný názov Vašej firmy" style="" data-inputmask="" data-load-state="" data-tooltip="Zadajte prosím presný názov Vašej firmy" type="text" /></div></div><div class="form-group gcore-form-row" id="form-row-meno"><label for="meno" class="control-label gcore-label-left">Meno:</label>​
​<div class="gcore-input gcore-display-table" id="fin-meno"><input name="meno" id="meno" value="" placeholder="Meno pracovníka ktorého môžeme kontaktovať" maxlength="50" size="53" class="validate[&#039;required&#039;] form-control A" title="Zadajte prosím meno pracovníka ktorého môžeme kontaktovať" style="" data-inputmask="" data-load-state="" data-tooltip="Zadajte prosím meno pracovníka ktorého môžeme kontaktovať" type="text" /></div></div><div class="form-group gcore-form-row" id="form-row-ulica"><label for="ulica" class="control-label gcore-label-left">Ulica:</label>​
​<div class="gcore-input gcore-display-table" id="fin-ulica"><input name="ulica" id="ulica" value="" placeholder="" maxlength="50" size="53" class="form-control A" title="" style="" data-inputmask="" data-load-state="" data-tooltip="" type="text" /></div></div><div class="form-group gcore-form-row" id="form-row-psc"><label for="psc" class="control-label gcore-label-left">PSČ:</label>​
​<div class="gcore-input gcore-display-table" id="fin-psc"><input name="psc" id="psc" value="" placeholder="XXX XX" maxlength="6" size="6" class="form-control A" title="Zadajte prosím presné PSČ v tvare XXX XX" style="" data-inputmask="&#039;mask&#039; : &#039;999 99&#039;" data-load-state="" data-tooltip="Zadajte prosím presné PSČ v tvare XXX XX" type="text" /></div></div><div class="form-group gcore-form-row" id="form-row-telefon"><label for="telefon" class="control-label gcore-label-left">Telefón:</label>​
​<div class="gcore-input gcore-display-table" id="fin-telefon"><input name="telefon" id="telefon" value="" placeholder="" maxlength="13" class="validate[&#039;required&#039;,&#039;digit&#039;,&#039;nospace&#039;,&#039;number&#039;,&#039;phone&#039;,&#039;phone_inter&#039;] form-control A" title="Telefónne číslo musí byť v medzinárodnom tvare (napr.: +421903123456)" style="" data-inputmask="&#039;mask&#039; : &#039;+999999999999&#039;" data-load-state="" data-tooltip="Zadajte prosím telefón v medzinárodnom tvare a bez medzier. Príklad: +421903123456" type="text" /></div></div><div class="form-group gcore-form-row" id="form-row-fax"><label for="fax" class="control-label gcore-label-left">Fax:</label>​
​<div class="gcore-input gcore-display-table" id="fin-fax"><input name="fax" id="fax" value="" placeholder="" maxlength="13" class="validate[&#039;digit&#039;,&#039;nospace&#039;,&#039;number&#039;,&#039;phone&#039;,&#039;phone_inter&#039;] form-control A" title="Faxové číslo musí byť v medzinárodnom tvare (napr.: +421903123456)" style="" data-inputmask="&#039;mask&#039; : &#039;+999999999999&#039;" data-load-state="" data-tooltip="Zadajte prosím fax v medzinárodnom tvare a bez medzier. Príklad: +421903123456" type="text" /></div></div><div class="form-group gcore-form-row" id="form-row-poznamka"><label for="poznamka" class="control-label gcore-label-left">Poznámka:</label>​
​<div class="gcore-input gcore-display-table" id="fin-poznamka"><textarea name="poznamka" id="poznamka" placeholder="Max 500 znakov!" rows="3" cols="40" class="form-control A" title="Max 500 znakov!" style="" data-wysiwyg="0" data-load-state="" data-tooltip="Max 500 znakov!"></textarea></div></div><div class="form-group gcore-form-row" id="form-row-email"><label for="email" class="control-label gcore-label-left">Email:</label>​
​<div class="gcore-input gcore-display-table" id="fin-email"><input name="email" id="email" value="" placeholder="Zadajte prosím svoj email" maxlength="50" size="53" class="validate[&#039;required&#039;] form-control A" title="Zadajte prosím svoj email" style="" data-inputmask="" data-load-state="" data-tooltip="Zadajte prosím svoj email" type="text" /></div></div><div class="form-group gcore-form-row" id="form-row-chrono_security_answer11"><label for="chrono_security_answer11" class="control-label gcore-label-left">Koľko je 2+2 ?</label>​
​<div class="gcore-input gcore-display-table" id="fin-chrono_security_answer11"><input name="chrono_security_answer" id="chrono_security_answer11" value="" placeholder="" class="validate[&#039;required&#039;,&#039;digit&#039;,&#039;nospace&#039;,&#039;number&#039;] form-control A" title="" style="" data-inputmask="" data-load-state="" data-tooltip="Vypočítajte prosím tento jednoduchý príklad a napíšte výsledok do políčka vedľa. Ide o bezpečnostnú ochranu pred spammom" type="text" /><span class="help-block">bezpečnostná otázka</span></div></div><div class="form-group gcore-form-row" id="form-row-odoslat"><div class="gcore-input gcore-display-table" id="fin-odoslat"><input name="odoslat" id="odoslat" type="submit" value="Odoslať" class="btn btn-default form-control A" style="" data-load-state="" /></div></div>
2018-05-18_15-18-56.png
GreyHead
Hi yardstudio,
The HTML (render form) action should be the last action in the On Load event
Please add Event Loop actions to the pink On Fail events of the two Check actions - at present they do nothing.
Bob
ChronoForms technical support
If you'd like to buy me a coffee or two, thank you very much
Y
yardstudio
Is it better now?:
2018-05-18_23-02-58.png
Attachments
2018-05-18_23-02-58.png
2018-05-18_23-02-58.png
(63.34 KiB)
100 Downloads/Views
admin
Yes, but you better use "Event loop" instead of a "Show stopper" because the event loop will redisplay the form!
Best regards,
Max
Max
If your main question got answered then please mark the answer using the button!​
​Please let us know if you have any problems with the new forums text editor, we appreciate your feedback!