Still SPAM Via FormBuilder - Question | JoomShaper
Black Friday sale is live with flat 50% OFF. Sale ends soon! Grab your deal now!

Still SPAM Via FormBuilder

Steve

Steve

SP Page Builder 8 months ago

Hello Joomshaper-Support, first of all thank you very much for your work - I appreciate it very much.

Unfortunately, however, I have to address another existing problem. There is still SPAM via the FormBuilder. I have also activated the option for one customer that a maximum of 4 messages per hour may be sent (rate limiting) - but hundreds have been received. So the form can still be bypassed. Would you please address this problem? I had to hide the forms now.

And before you ask again: No, I can't and don't want to use a Cpatcha that I have to integrate and configure for more than 60 customers and that the customer still has to legally include in a privacy policy ;-)

Best regards...

0
42 Answers
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 6 months ago #191695

You are welcome 😊

I am glad to know. If the answer resolved your query, you can mark it as accepted to help close the post and guide others with similar questions. There is a button to accept answers after each comment.

If there's anything else you need assistance with, feel free to let us know!

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #186655

Hello Steve,

Thank you for reaching out to our technical support forum. I’m sorry to hear about the trouble you’re experiencing. Rest assured, I will look into this issue for you and work to resolve it as quickly as possible.

If you could kindly provide any additional information regarding the issue, it would greatly help me investigate and address it more efficiently.

Please share your administrator access here to check the issue. Use the Hidden Content box to share the credentials. Make sure that you have a full site backup before sharing.

Best regards

0
Steve
Steve
Accepted Answer
8 months ago #186664

Thank you very much for your support and quick response. Please see below.

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #186666

You are welcome 😊

I have enabled the form builder in the article and checked the English menu (link in the hidden content). I have sent 4 test emails. Please ignore these. On the fifth email, I have got the correct message. The rate limit works fine. Please check the screenshots in the hidden content.

0
Steve
Steve
Accepted Answer
8 months ago #186673

Hello Ofi, thank you very much for your quick response.

It may be that the rate limit works for a “normal visitor”. However, my customer received several hundred SPAM messages last night. I think that the protection of the form can still be bypassed.

We have already discussed this topic in various posts over the past >9 months, including with Toufiq. Unfortunately, there is no effective solution so far, so I am still facing my customers with a dozen deactivated forms.

I am sure that the SPAM protection can still be bypassed - and this for several months. In my opinion, even captchas and rate limits don't help in this case. Please find the error in the FormBuilder as soon as possible.

Tank you and best regards...

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #186822

Okay, I will talk to the developer team to recheck this. Can I share your site backup for testing purpose?

0
Steve
Steve
Accepted Answer
8 months ago #186843

Hello Ofi, thank you very much for taking care of this. Hopefully this bug will now be found and fixed after months. You can give access to the site to your developers. But this is no backup - it is a live site. So please let me know if anything is changed. If you prefer to have a backup, I can offer it as a download or send it to you in another way. Beste regards...

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #186848

I would prefer a backup. It is safer to work. Please take a full site backup with Akeeba Backup in ZIP format and share here. Follow this tutorial. I will forward it to the developer team.

0
Steve
Steve
Accepted Answer
8 months ago #186852

Hi Ofi, please note the Hidden Content. Thank you!

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #186959

Thanks for your message.

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #187104

I could not install the backup. Please take the backup using akeeba and share here.

0
Steve
Steve
Accepted Answer
8 months ago #187114

Thank you for your message - see hidden conent. Best regards...

0
Steve
Steve
Accepted Answer
8 months ago #187551
Hi Ofi, see hidden content.
0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #188280

I have downloaded the backup. However, we will release an SP Page Builder update this week. Please update when it is released. Then check your issue.

0
Steve
Steve
Accepted Answer
8 months ago #188287

Thank you!

0
Steve
Steve
Accepted Answer
8 months ago #188423

Hello, Support. Thank you for the update. Unfortunately, the problem is still NOT solved. I received several SPAM mails again within only 5 minutes. Regardless of the rate limit.

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 8 months ago #188450

You are welcome 😊

As far as I know, the issue is fixed. It is not possible to send more emails than the rate limit. Are you sure that you are getting spam from Form Builder addon? Please take a new page and try Form Builder addon.

0
Steve
Steve
Accepted Answer
8 months ago #188452

Hello Ofi, yes I am sure that SPAM comes via the PB-form. I published it after the update and deleting the cache. The SPAM mails came immediately. I have this problem on nearly 50 pages. Best regards.

0
Steve
Steve
Accepted Answer
7 months ago #188582

Hello Ofi, I have tested the new version again with a customer. Neither the SPAM protection nor the rate limit work correctly. Formbuilder is set to 4 messages per hour... Please take a look at the screenshot in the hidden content that I have just received from the customer and pay attention to the times... When can you fix the errors?

0
Steve
Steve
Accepted Answer
7 months ago #189233

Hello Ofi, did you see my last message and the screenshot? Is there anything new? What can we do - I have numerous customer sites where I would have to hide the form builder because of the SPAM. As I said, the messages came AFTER the update and with a rate limit of 4 messages per hour. Best regards

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 7 months ago #189288

Apology for the delayed response. I have seen it. I have to talk about it with the developer team. Since there's a holiday going on, I would ask you for some time. I will share your issue with the team next week.

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 7 months ago #190295

Please activate the access. I will share it with the developer team for checking your issue. Also, share me your contact page link. (I guess it is the Kontakt menu).

0
Steve
Steve
Accepted Answer
7 months ago #190313

Hello Ofi, thank you very much for your support. The account has been reactivated. You can see the access data in the hidden content.

Important: This is a productive customer site. Please take care or use the backup you have received. Furthermore, please undo adjustments or give me feedback about changes.

Please note also the following: 1) The page is cached (incl. Plugin) 2) You can find the forms (both deactivated) under “Content” > Post". The posts are called: “So erreichen Sie unsere Experten...”(DE) and in EN “This is how you can reach our experts...”.

Thank in advance and best regards!

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 6 months ago #191479

Please update SP Page Builder and check your issue.

0
Steve
Steve
Accepted Answer
6 months ago #191627

Thank you very much Ofi, it looks like the problem has been solved. We will keep an eye on it. Thank you very much!

0
Steve
Steve
Accepted Answer
6 months ago #192157

Hi Ofi, I'm sorry but the problem is not solved and still persists.

My customer(s) continue to receive SPAM messages even after the last update to 5.5.7. And this also exceeds the set quota (rate limit) of a maximum of four messages per hour. I also have another screenshot of the messages received and the times - see the hidden content. I (and the customers) would be pleased if this problem could be solved permanently. A start would at least be that the rate limit would work. However, I suspect that the rate limit and the captcha can generally be bypassed in the form builder.

Thanks in advance and best regards...

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 6 months ago #192316

Please enable the access and share the contact page link. I will test the contact page and investigate the issue.

0
Steve
Steve
Accepted Answer
6 months ago #192317

Hello Ofi, thank you for your support. See hidden content or the posts above. The access is the same as 3 weeks ago. Best regards

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 6 months ago #193531

I have checked article id 9. The email is successfully sent. If you do not receive the email, then contact with your hosting provider.

0
Steve
Steve
Accepted Answer
6 months ago #193536

Hello Ofi, thank you very much for your support. However, the problem is not that emails are not being sent. Rather, it is still the case that massive amounts of SPAM messages are being sent via the form builder.

As you can see from the screenshots above (see Hidden Content from post #192157), the “rate limit” is not working either. As I have already mentioned, I suspect that the rate limit and the captcha can generally be bypassed.

Thanks in advance and best regards

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 5 months ago #194139

Unfortunately, the team has not found any such issues. Other customers do not face this issue. However, we will continue monitoring the feature in the future.

0
Steve
Steve
Accepted Answer
5 months ago #194602

This is really annoying and a pity - I can no longer publish the contact forms for my customers. Are you sure there is no solution? I would not like to switch to an alternative from Joomshaper... And looking at the other posts in similar topics in your forum, I'm not the only customer with this problem.

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 5 months ago #194688

Sorry, I have checked again and found the issue on your site. I have also checked on my localhost and test server. Interestingly, on both, it worked fine. May I take an Akeeba Backup from your site and install on my test server to check?

0
Steve
Steve
Accepted Answer
5 months ago #194692

Hello Ofi, thank you very much for your support. I am very pleased that you have found the error. When you were working on the site and activated the form, I received 19 SPAM messages within 4 minutes.

Regarding your question: Yes, please take an Akeeba backup. And I would be very happy if you could tell me where the error is. You know I also have the same problem with other sites. Or will there be a general update on this?

Many thanks and best regards...

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 5 months ago #194859

These spams (fake names) are sent by me for testing purpose. Thank for your permission. I will take a backup and investigate further on the issue.

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 5 months ago #195006

I have tested your site on our test server. Rate Limit works fine here. I have shared the credentials in the hidden content. You can check it.

0
Steve
Steve
Accepted Answer
5 months ago #195014

Thank you Ofi, can you tell me what the error was? Is it fixed on the live site? And by the way, this is not the form from the original site - right? Best regards...

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 5 months ago #195024

I am also clueless. It works on our test server but not on your actual server. Can you talk to your hosting provider about it?

0
Steve
Steve
Accepted Answer
5 months ago #196155

Hello Ofi, have you seen my previous post (#195028) on this topic? Is there anything new, have you been able to find out anything in relation to my assumptions? Thank you and best regards...

0
Viktor
Viktor
Accepted Answer
5 months ago #194617

Hi Steve, I use the OSpam-a-not plugin and it works, there is a free version, try it, here is the link: The best Joomla spam prevention extension

0
Steve
Steve
Accepted Answer
5 months ago #194693

Thanks Viktor, I'll have a look at it.

0
Steve
Steve
Accepted Answer
5 months ago #195028

Dear Ofi, thank you again for your support. As I see it, the two systems differ in two things:

  1. You are running the system with PHP in version 8.2 and on my server in version 8.4.

  2. The form that does not work is embedded in a post with the PageBuilder content plugin - but on your server it is published directly via the component via a menu item.

The form in the post (post ID 8 -> DE and post ID 9 -> EN) does not seem to work for you either. See link in the hidden content.

Perhaps you can take a closer look at this and also check it in the PHP 8.4 test environment. Thank you very much.

PS: The own server is a standard environment and should not be the problem.

0