Kunena 6.3.0 released

The Kunena team has announce the arrival of Kunena 6.3.0 [K 6.3.0] in stable which is now available for download as a native Joomla extension for J! 4.4.x/5.0.x/5.1.x. This version addresses most of the issues that were discovered in K 6.2 and issues discovered during the last development stages of K 6.3

Topics must relate to a currently supported version of Kunena. If you are unsure what is the current supported version of Kunena, please go to the download page.

If you are having problems then, for your own benefit, it would save us all a lot of time if you would kindly post your configuration report when you ask for help from this forum. If you do not post your configuration report we will not ask you for it but you will probably not get your problem solved, either.

Question New Posts email notification in a read-only forum!

More
5 years 9 months ago #1 by Chrisp
Hello,

I'm running Kunena 5.1.1 with J 3.8.8 and these past couple of days I have been receiving email notifications about new (spam) posts in existing topics however when i visit the topics I am not seeing any new posts there!

Here is a sample of the email notification:

Message Subject : nike silver uomo
Category : Firewall Filtering, IDS/IPS & Security
Posted by : ???
URL : www.mydomain.com/forum/10-firewall-filte...n-site-site-vpn.html
Message:
Reuters6Danny Graham gave Blackburn the lead against United before they went on and lost 2-1The search for a new manager will begin with immediate effect.
nike silver uomo www.netl.it/Nike-Koth-Ultra-Low-Knit-Jac...ver-Uomo-PZ1339.html


In order to stop this activity I set the form to "Read Only" mode but this is continuing.

Any ideas? Is this perhaps a bug or is there something suspicious going on which I should be concerned about?

Many thanks for your time and help.

Chris.

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago - 5 years 9 months ago #2 by jtcarlin
I am having the exact same issue and am very concerned. I am also on 5.1.1. Users are reporting this via email, yet no such post exists. Here is one of the emails sent to me:

A new reply has been posted on the The South End

Message Subject : 123
Category : Salmon, Steelies, Lakers
Posted by : ???

URL: www.thesouthend.org/index.php/forum/salm...ke-down-good-and-bad
Message:
kaert chasing Championship gongdiamonds are foreverChelsea's new Nike kit leaked online.
123 www.nkmvp.fr/Nike-Air-Max-90-EM-Hommes-Chaussures-GP965.html

You can unsubscribe from this topic by visiting it and clicking the Unsubscribe button near the top or bottom of the page.

Do not answer to this e-mail notification as it is a generated e-mail.
Last edit: 5 years 9 months ago by jtcarlin. Reason: added email text

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago #3 by Chrisp
While no one has replied with a solution I have found a work-around.
I dug into the apache logs and found which IP address was hitting the URL with HTTP POST command - the IP was identical in all events so I simply blocked the abusive IP address in the site's .htaccess file.

No longer receiving the alerts however I'm suspecting this is a bug.

Thanks,

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago #4 by dirk.potyka
Me too :-(

Situation is almost the same. I have installed the newest kunena and joomla version and receive sometimes auto notifications for threads with sender "???" who is replying to a topic. In fact these are spam mails and when checking the forum there is no new entry and also there were no user log in Joomla / Kunena at this time (but could be that a user logged in days ago...)
So no idea from where this is coming from but high level it looks like a security bug.

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago #5 by jtcarlin
Would be great to get a developer response. Banning IP's works, but I am assuming they are going to start coming from all directions soon.

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago #6 by 810
Could you please all add the kunena report. And how your category is setup with the permissions.

Also please enable kunena logs. setting Is on the configuration. That feature will log all users actions. So maybe I know then how they to it.

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago - 5 years 9 months ago #7 by dirk.potyka
Hello "810". First at all thank you very much for checking this!

Please find attached the configuration report. The only change which I did the past hours was to disable the auto email notifications. At the time it was set on I got spam mails but for the moment not.

In general everybody can display but only registered people (+manager/super user) can open topics or write answers.

Now it's 1 am in the morning here and maybe I became blind or to tired but can't find the log section. Where exactly in "configuration is it" ?

Rergards
-Dirk

This message contains confidential information

Database collation check: The collation of your table fields are correct

Joomla! SEF: Enabled | Joomla! SEF rewrite: Disabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Exists | PHP environment: Max execution time: 30 seconds | Max execution memory: 64M | Max file upload: 200M

Kunena menu details:

Warning: Spoiler!

Joomla default template details : Pulse | author: Crosstec GmbH & Co. KG | version: 1.1.1 | creationdate: November 2014

Kunena default template details : Blue Eagle5 | author: Kunena Team | version: 1.0.2 | creationdate: 2017-01-09

Kunena template params:

Warning: Spoiler!

Kunena version detailed: Kunena 5.1.1 | 2018-06-10 [ Belinda ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: None

Third-party SEF components: None

Plugins: None

Modules: None

Last edit: 5 years 9 months ago by 810.

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago #8 by 810
1) please update blue eagle template to 1.5.0 RC3
2) config - users- Define if you want to log action or moderation set to "Yes"
3) Which category setting do you use: access level or usergroups

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago #9 by dirk.potyka
Hello,

1.) I will update to blue eagle 1.5.0 RC3 today night. PS: Is there any way to get an auto reminder like for other new software versions ?
2.) It's now activated
3.) It's user group based. Typically all is handled by "Registered user"

I also attached a sample of these spam mails. Since yesterday afternoon I did not get any new spams so far.

Regards
-Dirk
Attachments:

Please Log in or Create an account to join the conversation.

More
5 years 9 months ago - 5 years 9 months ago #10 by jtcarlin
Here is my report. I use access level.

This message contains confidential information

Database collation check: The collation of your table fields are correct

Joomla! SEF: Enabled | Joomla! SEF rewrite: Disabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Exists | PHP environment: Max execution time: 90 seconds | Max execution memory: 128M | Max file upload: 10M

Kunena menu details:

Warning: Spoiler!

Joomla default template details : rt_protean | author: RocketTheme, LLC | version: 1.1.1 | creationdate: February 13, 2017

Kunena default template details : Blue Eagle5 | author: Kunena Team | version: 1.0.3 | creationdate: 2017-02-04

Kunena template params:

Warning: Spoiler!

Kunena version detailed: Kunena 5.1.1 | 2018-06-10 [ Belinda ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: UddeIM 3.9

Third-party SEF components: None

Plugins: None

Modules: Kunena Latest 5.1.0

Last edit: 5 years 9 months ago by jtcarlin.

Please Log in or Create an account to join the conversation.

Time to create page: 0.703 seconds