-
Bug
-
Resolution: Fixed
-
Low
-
3.3.0-OD-04, 3.2.3, 3.4.0
-
Severity 3 - Minor
-
NOTE: This bug report is for JIRA Service Desk Server. Using JIRA Service Desk Cloud? See the corresponding bug report.
Several customers have reported that their instances have recently been flooded with spam accounts that appear to be part of a systematic phishing attack, which suggests that the honeypot strategy we’ve been using since JSD 3.2 is no longer effective.
This is a slightly different issue to JSD-4324 and JSD-1316 as they were first reported, so to minimise any confusion, please head to JSDSERVER-5706 for more details, including two potential workarounds and a guide to cleaning up the spam.
On behalf of the JSD server team, we’re sorry for the inconvenience this has caused, and we’ll make a solution available as soon as we can.
Hi everyone,
The fix for this issue was released in JSD 3.2.0. Instead of Captcha, we implemented the honeypot technique to prevent spam bots from creating accounts on the customer portal. Here's more information about it: https://confluence.atlassian.com/display/AdminJIRAServer072/Enabling+public+signup+and+CAPTCHA
Summary
Currently when public signup is enabled for both JIRA and Service Desk, Captcha is only displayed from JIRA signup page, not from Customer Portal signup page.
Steps to reproduce
- Go to JIRA Administration -> System -> General Configuration -> Edit Settings
- Change Mode to Public and CAPTCHA on signup to ON
- Go to JIRA Administration -> Applications -> JIRA SERVICE DESK -> Configuration -> Turn ON Public signup
- Sign up a new account from JIRA and then from Customer Portal
Expected behavior
CAPTCHA is displayed on both signup pages.
Actual behavior
CAPTCHA is only displayed on JIRA signup page. It's not available on Customer Portal signup page:
Note
It seems that CAPTCHA on signup from General Configuration only takes effect on JIRA side, not Customer Portal
- duplicates
-
JSDSERVER-1316 Service Desk Cloud - Enabling public signup does not display Captcha
-
- Closed
-
- has a regression in
-
JSDSERVER-5706 Honeypot strategy is no longer effectively preventing spam account signup
-
- Closed
-
- relates to
-
JSDCLOUD-4324 Enabling public signup does not display Captcha
-
- Closed
-
- mentioned in
-
Page Failed to load
Form Name |
---|
[JSDSERVER-4324] Enabling public signup does not display Captcha
Workflow | Original: JSD Bug Workflow v5 - TEMP [ 2305085 ] | New: JAC Bug Workflow v3 [ 3126212 ] |
Description |
Original:
{panel:bgColor=#e7f4fa}
*NOTE:* This bug report is for *JIRA Service Desk Server*. Using *JIRA Service Desk Cloud*? [See the corresponding bug report|http://jira.atlassian.com/browse/JSDCLOUD-4324]. {panel} {panel:title=Update as of March 2018|bgColor=#F5F5F5}Several customers have reported that their instances have recently been flooded with spam accounts that appear to be part of a systematic phishing attack, which suggests that the honeypot strategy we’ve been using since JSD 3.2 is no longer effective. This is a slightly different issue to On behalf of the JSD server team, we’re sorry for the inconvenience this has caused, and we’ll make a solution available as soon as we can.{panel} {panel:title=Update as of May 2017|bgColor=#f5f5f5} Hi everyone, The fix for this issue was released in JSD 3.2.0. Instead of Captcha, we implemented the honeypot technique to prevent spam bots from creating accounts on the customer portal. Here's more information about it: https://confluence.atlassian.com/display/AdminJIRAServer072/Enabling+public+signup+and+CAPTCHA {panel} h4. Summary Currently when public signup is enabled for both JIRA and Service Desk, Captcha is only displayed from JIRA signup page, not from Customer Portal signup page. h4. Steps to reproduce # Go to JIRA Administration -> System -> General Configuration -> Edit Settings # Change Mode to Public and CAPTCHA on signup to ON # Go to JIRA Administration -> Applications -> JIRA SERVICE DESK -> Configuration -> Turn ON Public signup # Sign up a new account from JIRA and then from Customer Portal h4. Expected behavior CAPTCHA is displayed on both signup pages. h4. Actual behavior CAPTCHA is only displayed on JIRA signup page. It's not available on Customer Portal signup page: !sdsignup.png|thumbnail! h4. Note It seems that CAPTCHA on signup from General Configuration only takes effect on JIRA side, not Customer Portal |
New:
{panel:bgColor=#e7f4fa}
*NOTE:* This bug report is for *JIRA Service Desk Server*. Using *JIRA Service Desk Cloud*? [See the corresponding bug report|http://jira.atlassian.com/browse/JSDCLOUD-4324]. {panel} {panel:title=Update as of March 2018|titleBGColor=#f5f5f5|bgColor=#f5f5f5} Several customers have reported that their instances have recently been flooded with spam accounts that appear to be part of a systematic phishing attack, which suggests that the honeypot strategy we’ve been using since JSD 3.2 is no longer effective. This is a slightly different issue to On behalf of the JSD server team, we’re sorry for the inconvenience this has caused, and we’ll make a solution available as soon as we can. {panel} {panel:title=Update as of May 2017|titleBGColor=#f5f5f5|bgColor=#f5f5f5} Hi everyone, The fix for this issue was released in JSD 3.2.0. Instead of Captcha, we implemented the honeypot technique to prevent spam bots from creating accounts on the customer portal. Here's more information about it: [https://confluence.atlassian.com/display/AdminJIRAServer072/Enabling+public+signup+and+CAPTCHA] {panel} h4. Summary Currently when public signup is enabled for both JIRA and Service Desk, Captcha is only displayed from JIRA signup page, not from Customer Portal signup page. h4. Steps to reproduce # Go to JIRA Administration -> System -> General Configuration -> Edit Settings # Change Mode to Public and CAPTCHA on signup to ON # Go to JIRA Administration -> Applications -> JIRA SERVICE DESK -> Configuration -> Turn ON Public signup # Sign up a new account from JIRA and then from Customer Portal h4. Expected behavior CAPTCHA is displayed on both signup pages. h4. Actual behavior CAPTCHA is only displayed on JIRA signup page. It's not available on Customer Portal signup page: !sdsignup.png|thumbnail! h4. Note It seems that CAPTCHA on signup from General Configuration only takes effect on JIRA side, not Customer Portal |
Symptom Severity | Original: Minor [ 14432 ] | New: Severity 3 - Minor [ 15832 ] |
Link |
Original:
This issue is a regression of |
Link |
New:
This issue duplicates |
Description |
Original:
{panel:bgColor=#e7f4fa}
*NOTE:* This bug report is for *JIRA Service Desk Server*. Using *JIRA Service Desk Cloud*? [See the corresponding bug report|http://jira.atlassian.com/browse/JSDCLOUD-4324]. {panel} {panel:title=Update as of May 2017|bgColor=#f5f5f5} Hi everyone, The fix for this issue was released in JSD 3.2.0. Instead of Captcha, we implemented the honeypot technique to prevent spam bots from creating accounts on the customer portal. Here's more information about it: https://confluence.atlassian.com/display/AdminJIRAServer072/Enabling+public+signup+and+CAPTCHA {panel} h4. Summary Currently when public signup is enabled for both JIRA and Service Desk, Captcha is only displayed from JIRA signup page, not from Customer Portal signup page. h4. Steps to reproduce # Go to JIRA Administration -> System -> General Configuration -> Edit Settings # Change Mode to Public and CAPTCHA on signup to ON # Go to JIRA Administration -> Applications -> JIRA SERVICE DESK -> Configuration -> Turn ON Public signup # Sign up a new account from JIRA and then from Customer Portal h4. Expected behavior CAPTCHA is displayed on both signup pages. h4. Actual behavior CAPTCHA is only displayed on JIRA signup page. It's not available on Customer Portal signup page: !sdsignup.png|thumbnail! h4. Note It seems that CAPTCHA on signup from General Configuration only takes effect on JIRA side, not Customer Portal |
New:
{panel:bgColor=#e7f4fa}
*NOTE:* This bug report is for *JIRA Service Desk Server*. Using *JIRA Service Desk Cloud*? [See the corresponding bug report|http://jira.atlassian.com/browse/JSDCLOUD-4324]. {panel} {panel:title=Update as of March 2018|bgColor=#F5F5F5}Several customers have reported that their instances have recently been flooded with spam accounts that appear to be part of a systematic phishing attack, which suggests that the honeypot strategy we’ve been using since JSD 3.2 is no longer effective. This is a slightly different issue to On behalf of the JSD server team, we’re sorry for the inconvenience this has caused, and we’ll make a solution available as soon as we can.{panel} {panel:title=Update as of May 2017|bgColor=#f5f5f5} Hi everyone, The fix for this issue was released in JSD 3.2.0. Instead of Captcha, we implemented the honeypot technique to prevent spam bots from creating accounts on the customer portal. Here's more information about it: https://confluence.atlassian.com/display/AdminJIRAServer072/Enabling+public+signup+and+CAPTCHA {panel} h4. Summary Currently when public signup is enabled for both JIRA and Service Desk, Captcha is only displayed from JIRA signup page, not from Customer Portal signup page. h4. Steps to reproduce # Go to JIRA Administration -> System -> General Configuration -> Edit Settings # Change Mode to Public and CAPTCHA on signup to ON # Go to JIRA Administration -> Applications -> JIRA SERVICE DESK -> Configuration -> Turn ON Public signup # Sign up a new account from JIRA and then from Customer Portal h4. Expected behavior CAPTCHA is displayed on both signup pages. h4. Actual behavior CAPTCHA is only displayed on JIRA signup page. It's not available on Customer Portal signup page: !sdsignup.png|thumbnail! h4. Note It seems that CAPTCHA on signup from General Configuration only takes effect on JIRA side, not Customer Portal |
Link |
New:
This issue has a regression in |
Workflow | Original: JSD Bug Workflow v5 [ 2059011 ] | New: JSD Bug Workflow v5 - TEMP [ 2305085 ] |
Workflow | Original: JSD Bug Workflow v5 - TEMP [ 2056395 ] | New: JSD Bug Workflow v5 [ 2059011 ] |
Workflow | Original: JSD Bug Workflow v5 [ 1956480 ] | New: JSD Bug Workflow v5 - TEMP [ 2056395 ] |