I've installed a few rocketlauncher templates/sites on a hostgator account. A couple of them seem to be major attractors of bogus user accounts. Most of the accounts consist of random names, and never actually get activated.
Can someone explain to me the intent of creating such accounts?
Does it have something to do with using my server account for spam? Seems to follow that I also get a LOT of undeliverable email bounced back to me (from bogus email addresses using my domain name), which is why I'm wondering if the fake user accounts are created with the intent of spamming.
How can I fend off such user account creation, yet still allow for legit accounts?
Yes spammers will seek out to take advantage of anyone offering the ability to register with the aim of being able to spam people. I don't know how many "normal" user accounts you would normally expect - but there area couple of things you could do.
1. Change so administrator has to authorise the account before it can be used (can be onerous if you have lots).
2. add better verifcation of the registered members email address (there are numerous email verification services out there) - you can do this manually (as part of 1 above) or automatically - at least that might eliminate some of the people registering (hoaxers).
3. if you getting that sort of interest on your site make sure you have adequate security on your system - because once these people have ideified your site as a target they will keep chipping away to see if they can get further in. So make sure you use something like Akeeba admin tools to set a htpasswd and locked down htaccess file.
4. consider using geoblocking (akeeba admin tools can do this too) to stop people from countries you do want using your site at all. It's not bullet proof - but it will help.
I hope that helps.
Regards, Mark.
Please search forums before posting. Please make sure your post includes the version of the CMS you are using and a link to the problem. Annotations on screenshots can also be helpful to explain problems/goals. Please use the "secure" tab for confidential information.