Mail headers View basic headersReceived from localhost (localhost [127.0.0.1]) by mail.fc-host48.de (Postfix) with ESMTP id 3C3F75400AC for <ihakufuqn@rtotlmail.com>; Wed, 13 Jan 2016 21:20:18 +0100 (CET)Received from mail.fc-host48.de ([127.0.0.1]) by localhost (fc-host48.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VUYboKqZMk9u for <ihakufuqn@rtotlmail.com>; Wed, 13 Jan 2016 21:20:18 +0100 (CET)Received by mail.fc-host48.de (Postfix, from userid 2018) id 2DBA95400AD; Wed, 13 Jan 2016 21:20:18 +0100 (CET)To ahodelsaku uyigiebatate <ihakufuqn@rtotlmail.com>Subject Danke für Ihre RegistrierungX-PHP-Originating-Script 2018:SimpleMailInvoker.phpMessage-ID <5f52d3a07490f3124d96bc22f2d18f66@montepreso.de>Date Wed, 13 Jan 2016 20:20:18 +0000From MySide <elxis@myadress.de>MIME-Version 1.0Content-Type text/plain; charset=UTF-8Content-Transfer-Encoding quoted-printableX-Priority 3 (Normal)X-Mailer Elxis
Elxis Defender blocked an attack to your site!Reference code: SEC-DEFG-0225Elxis Defender reportSignatures: generalMatch method: rmatchHaystack: requesturiPattern match: /administrator/index.phpReason: Common CMS scanRequested URI: /administrator/index.phpIP address: 198.57.180.16Hostname: prolinux2.barrieweb.netUser agent: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.86 Safari/537.36Date (UTC): 2016-01-19 10:59:29Site URL: http://xxx.de
Dateiname: defender_ban.phpZuletzt bearbeitet: 19. Januar 2016 11:59 UhrAbwehr Bannungen# IP Blo Referenz Code Datum1 81.177.49.139 1 SEC-DEFG-0198 So 10. Januar 2016 05:51 Uhr2 77.75.78.160 1 SEC-DEFG-0130 Mo 11. Januar 2016 01:40 Uhr3 68.180.228.118 1 SEC-DEFG-0130 Mo 11. Januar 2016 23:38 Uhr4 77.75.76.166 1 SEC-DEFG-0130 Mi 13. Januar 2016 08:38 Uhr5 136.243.151.102 1 SEC-DEFG-0130 Do 14. Januar 2016 14:50 Uhr6 77.75.79.17 1 SEC-DEFG-0130 So 17. Januar 2016 01:51 Uhr7 195.154.194.111 1 SEC-DEFG-0197 So 17. Januar 2016 16:46 Uhr8 5.9.73.227 1 SEC-DEFG-0130 Mo 18. Januar 2016 13:45 Uhr9 177.19.39.170 1 SEC-DEFG-0185 Mo 18. Januar 2016 16:57 Uhr10 178.24.113.152 2 SEC-DEFG-0130 Di 19. Januar 2016 04:41 Uhr11 198.57.180.16 1 SEC-DEFG-0225 Di 19. Januar 2016 11:59 Uhr
This list doesn't help. If they are bots inorder to block them I must see how they manage to login and the only way to see that is by inspecting your apache access log file.
I have thought of something else: Usually these users after registration they dont validate their emails so they can't actually login. What about if I implemented a feature that would auto-delete such accounts after X days?Procedure- Bot/human registers in site. But he doesn't validate his email account so the account remains blocked.- After X (configurable) days Elxis auto-deletes the user account that haven't valiated their email.The above idea will not solve you the registration problem but will help you kep the site clean from such accounts.