Skip to content
Cameo: membership organiser
  • Home
  • Features
  • Info
    • Demo
    • Pricing
    • More detail
  • For users
    • What’s New
    • Tutorials
    • Notes

Menu

  • Home
  • Features
  • Info
    • Demo
    • Pricing
    • More detail
  • For users
    • What’s New
    • Tutorials
    • Notes

Preventing probes

Posted by, Cameo on 1 Jul 2022

If you see a message from Cameo suggesting you are a robot…

We’ve seen an increasing number of malicious probes attacking Cameo recently. A probe is a robot that tries to access files in common locations that have known security vulnerabilities. Cameo will almost always redirect these to the log-in page, as the intruder simply isn’t logged in.

The main problem for us is not so much the vulnerabilities a probe is looking for, but the load these constant probes put on the server and the bandwidth they consume. This particularly applies when they don’t pause between requests. Many do, partly to try to escape notice, and these are not so much a problem. But when bogus requests flood the server for minutes or hours at a time, it starts to look like a denial-of-service attack.

Cameo’s forms have had a security check for this kind of behaviour for a while. I’ve now added a security check on the main log-in page to detect whether access is by a robot. If Cameo thinks it is a robot, it will block its IP address to prevent further access. Generally, that will get rid of the intruder with less impact, and also persuade a robot to give up sooner.

Allow-list

The IP address of anyone who successfully logs in to is automatically added to an allow-list, so they cannot trigger a false-positive from that address.

I hope you won’t notice any of this. However, if you get a message suggesting you might be a robot, a false positive, Cameo will lock you out. If that happens, please make contact so we can add you to the allow-list of addresses that never get blocked and better tune the detection algorithm.

Posted in What’s NewTagged Login, Security

Post navigation

← Change tags of a notification
Support for Zettle card reader accounts →

Subscribe to updates

Quick Start

  • A rapid-fire guide to what Cameo can do and where to look.

Recent Articles

  • CameoCSP WordPress plugin and Cameo Scriptwatch 21 Mar 2025
  • Automatic transactional lists and opt-out from all 11 Mar 2025
  • Payment processors and references 5 Mar 2025
  • Automatically suspend event booking 12 Feb 2025
  • See more about checked-in places in event bookings 12 Feb 2025
  • Box-office-style event bookings and tickets 9 Feb 2025
  • Named areas update 7 Feb 2025
  • Why do I always get the error message “your password reset link was incorrect or has expired” when l go to log in? 4 Feb 2025
  • Re-send email via pending 3 Feb 2025
  • Payment form can create a contact 3 Feb 2025

Categories

  • Getting Started
  • Notes
  • Questions
  • Tutorials
  • What’s New

Subjects

Admin API Apps Attachments Checkin Contacts CSV Custom Fields Donations Editor Email Enrolment Events Filestore Filters Financial Forms Fundraising Gift aid Images Import Lists Login MembershipRecords News Builder Notifications Optout Payments Questions Reconciliation Renewals Reports Searching Security Signup Social Media Stationery Stripe Substitutions Tags Templates Trading UI Version10 WordPress
Cameo is produced by David Earl.