Registration and approval email Registration and approval email
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

Registration and approval email

Started by cgc0202, May 30, 2007, 07:31:34 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

cgc0202

Hello,

I hope this is the correct place to post this, but as Admin of the photogallery site, I request approval of those who registered.  The auto-email sent to me though is not very informative:

"A new user with the username "plain_lion" has registered in your gallery.

In order to activate the account, you need to click on the link below or copy and paste it in your web browser.

http://mygallery/register.php?activate=aa9105909daa6b48fe977a5c60770169"

Not knowing who "plain_lion" is I now have to login into the gallery to find out who (s)he is.  Is there a way so that the information in the registration sheet be transmitted also, especially the email and website, if needed?

What I found more disturbing today is that, a bot most likely was able to register -- I was not sent a notification for this, at all.   It had been sitting in the site for a bit and found out about it only because someone registered.  And, this one was on the site for a bit of already.  How could it have by-passed the procedure?  I did not recognize the name at all, and fortunately it gave a URL address.  When I checked the URL it was hardcore porn.

Had it succeeded to post any of its photos, my webhosting service would have deleted my entire account  because posting nude photos is not allowed -- they do not even accept nude art photos, like "David"  by Micheangelo.  So, porn photos would even be a more grave violation.  Porn sites also, I was told has ways to plant "phish" and other datagathering info.  And, I think that was the intent of the porn registrant.

To circumvent automated bots from registration, the other programs I use instituted a verification procedure, like writing down the challenge codes.  Can this not be instituted also?

I hope these issue are addressed.

Cornelio


Joachim Müller

Post an actual link to your gallery for a start...