What possible purpose do these registrants have? Appears to be a robot signing up, then trying to log on immediately and failing. Then they apparently get my email and log on successfully. They have yet to post anything nor, as best I can tell, have they done any harm other than wasting server time. But Google takes up more time than they do. The email addresses used are from two sites, most are from autosloansonlines.com. The rest are from thesearchlife.info and two servers in India.
Google reports the autoloansonline as "suspicious - visiting this web site may harm your computer." The other site appears to be a garbage-collection or scraper site; strings of material filched from other sites designed to get lots of Google hits.
What's the danger to Drupal sites, if any?
user01/23/2010 - 22:07Session opened for rennkolissaasd.rennkolissaasd
user01/23/2010 - 22:05Login attempt failed for rennkolissaasd.Anon
user01/23/2010 - 22:05New user: rennkolissaasd ...Anonedit
user01/23/2010 - 15:23Session opened for Steenrynall.Steenrynall
user01/23/2010 - 15:22Login attempt failed for Steenrynall.Anon
user01/23/2010 - 15:22New user: Steenrynall ...Anonedit
user01/23/2010 - 13:47Session opened for rennkolissa.rennkolissa
user01/23/2010 - 13:43Login attempt failed for rennkolissa.Anon
user01/23/2010 - 13:43New user: rennkolissa ...Anonedit
user01/22/2010 - 22:50Session opened for rennkoliss.rennkoliss
user01/22/2010 - 22:49Login attempt failed for rennkoliss.Anon
user01/22/2010 - 22:49New user: rennkoliss ...Anonedit
user01/22/2010 - 17:43Login attempt failed for qknswbr.Anon
user01/22/2010 - 16:22Session opened for lemmbranntss.lemmbranntss
user01/22/2010 - 16:20Login attempt failed for lemmbranntss.Anon
user01/22/2010 - 16:20New user: lemmbranntss ...Anonedit
user01/22/2010 - 14:33Session opened for mirelaresko.mirelaresko
user01/22/2010 - 14:32Login attempt failed for mirelaresko.Anon
user01/22/2010 - 14:32New user: mirelaresko ...Anonedit
user01/22/2010 - 11:47Session opened for areppefor.areppefor
user01/22/2010 - 11:45Login attempt failed for areppefor.Anon
user01/22/2010 - 11:45New user: areppefor ...Anonedit
user01/22/2010 - 09:48Login attempt failed for veta506.Anon
user01/22/2010 - 08:00Session opened for merrrikaleski.merrrikaleski
user01/22/2010 - 07:57Login attempt failed for merrrikaleski.Anon
user01/22/2010 - 07:57New user: merrrikaleski ...Anonedit
user01/21/2010 - 18:44Session opened for cheectobe.cheectobe
user01/21/2010 - 18:01Login attempt failed for cheectobe.Anon
user01/21/2010 - 18:01New user: cheectobe ...Anonedit
These two once logged in and left spam in comments, so I deleted them. Yet they continue to try to log in. veta506 tries only once every few days. The other one tries multiple times almost every day. These are obviously robots with no human assistance after the original registration.
user01/21/2010 - 07:55Login attempt failed for veta506.Anon
user01/20/2010 - 01:09Login attempt failed for Boinnanyloask.Anon
user01/20/2010 - 00:14Login attempt failed for Boinnanyloask.Anon
user01/19/2010 - 23:55Login attempt failed for Boinnanyloask.Anon
user01/19/2010 - 23:33Login attempt failed for Boinnanyloask.Anon
user01/19/2010 - 23:31Login attempt failed for Boinnanyloask.Anon
user01/19/2010 - 22:37Login attempt failed for Boinnanyloask.Anon
user01/19/2010 - 22:17Login attempt failed for Boinnanyloask.Anon
user01/19/2010 - 21:54Login attempt failed for Boinnanyloask.Anon
user01/19/2010 - 21:52Login attempt failed for Boinnanyloask.Anon
Comments
What's the danger to Drupal
What's the danger to Drupal sites, if any?
I'd say, the same as from every user, that can register with your site: depends on your setup.
If they really use the same domain for registering over and over again, I'd just add a rule for blocking them via admin/user/rules/add
Bot registrants
I've done that. I want to know if there are any vulnerabilities in Drupal or Civicrm that they might already have exploited.