Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenID Login being Spammed - Either Update OpenID Library or Remove it from Geeklog #653

Open
eSilverStrike opened this issue Jan 18, 2016 · 5 comments
Labels
Geeklog Authentication Improvement Code cleanup, Obsolete functions, or small changes to existing Features.
Milestone

Comments

@eSilverStrike
Copy link
Member

I noticed in the Geeklog error file that are OpenID feature is being spammed somehow with piles of different urls. We should see if we can block these fake attempts.

Mon Jan 11 14:20:19 2016 - 61.93.246.59 - Unable to find an OpenID server for the identity URL http://www.bedrettinyildirim.com.tr/?option=com_k2&view=itemlist&task=user&id=432494
Mon Jan 11 14:34:51 2016 - 187.160.129.67 - Unable to find an OpenID server for the identity URL http://www.comprayvende.cl/author/maryellenco/
Mon Jan 11 18:24:46 2016 - 185.104.219.211 - Unable to find an OpenID server for the identity URL https://plus.google.com/103816658567740702932/videos
Mon Jan 11 18:40:30 2016 - 187.161.150.76 - Unable to find an OpenID server for the identity URL http://jointpainrelief.knowledu.com

@eSilverStrike eSilverStrike added the Bug An issue describing unexpected or malicious behaviour. label Jan 18, 2016
@eSilverStrike eSilverStrike added this to the 2.1.2 milestone Jan 18, 2016
@mystralkk
Copy link
Member

OpenID libraries shipped with Geeklog were created in 2005 and haven't been updated. How about reviewing them with Geeklog 2.2.0 or later?

@eSilverStrike
Copy link
Member Author

eSilverStrike commented Dec 31, 2016

I agree. Maybe we should even consider removing OpenID? Not sure who uses it anymore. Live Journal Authentication #689 is also scheduled to be removed.

@eSilverStrike
Copy link
Member Author

Spam seems to be increasing on Geeklog.net in regards to this opened error. The error log is filled with the above errors

@mystralkk
Copy link
Member

How about disabling OpenID login feature temporarily on geeklog.net?

@eSilverStrike
Copy link
Member Author

eSilverStrike commented Mar 21, 2017

There is also OpenID Connect which our OAuth class currently supports (but is unused by Geeklog): https://www.phpclasses.org/blog/package/7700/post/12-Faster-PHP-Social-Login-with-a-PHP-OpenID-Connect-PHP-OAuth-Library.html

It's not the same thing but something to think about if/when we drop OpenID

@eSilverStrike eSilverStrike modified the milestones: 2.2.0, 2.3.0 Mar 30, 2018
@eSilverStrike eSilverStrike changed the title OpenID Login being Spammed OpenID Login being Spammed - Either Update OpenID Library or Remove it from Geeklog Mar 30, 2018
@eSilverStrike eSilverStrike added Improvement Code cleanup, Obsolete functions, or small changes to existing Features. and removed Bug An issue describing unexpected or malicious behaviour. labels Nov 15, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Geeklog Authentication Improvement Code cleanup, Obsolete functions, or small changes to existing Features.
Projects
None yet
Development

No branches or pull requests

2 participants