1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Someone register without email in database

Discussion in 'Security' started by Plamen Nikolov, Apr 16, 2013.

  1. #1
    I have a system with registrations. Someone register an account without email. I log the IP address of the visitors and members but that person have not got an IP address. My database is users with fields email, password, ip . The user in database is zadmin. This server is mine and have a fresh installation of Centos.

    P.S. My english is not good. I'm from Bulgaria.
    SEMrush
    Regards: Plamen Nikolov
     
    Plamen Nikolov, Apr 16, 2013 IP
    SEMrush
  2. MilesWeb

    MilesWeb Well-Known Member

    Messages:
    856
    Likes Received:
    33
    Best Answers:
    7
    Trophy Points:
    123
    #2
    Welcome to DP forums !

    Do you mean when a users register on your website, the details are not captured into the database ?
     
    MilesWeb, Apr 17, 2013 IP
  3. Plamen Nikolov

    Plamen Nikolov Peon

    Messages:
    2
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    1
    #3
    No the user does not register over the website. I have email validator on my web site and i test it with invalid email and registration does not continue
     
    Plamen Nikolov, Apr 17, 2013 IP
  4. healzer

    healzer Greenhorn

    Messages:
    16
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    23
    #4
    Hey,
    If you could PM me your website link I can take a look.
    Very strange, maybe it was an SQL injection, or just a bug, there could be a lot of reasons
     
    healzer, May 10, 2013 IP
  5. bob_swc

    bob_swc Greenhorn

    Messages:
    1
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    11
    #5
    He can bypass validation if you are only testing with java script.

    You need to validate the data again on the server too.

    I hope this helps,

    Bob
     
    bob_swc, Jun 27, 2013 IP
  6. humtuma

    humtuma Notable Member

    Messages:
    1,222
    Likes Received:
    24
    Best Answers:
    3
    Trophy Points:
    200
    #6
    Its a spam registration. Check that IP address in google if it is. It might be possible , you server is compromised.
     
    humtuma, Jul 1, 2013 IP