Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7884295
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 3, 20262026-06-03T04:45:38+00:00 2026-06-03T04:45:38+00:00

is it possible to create new users (In-band registration) using anonymous user using Strophe.js

  • 0

is it possible to create new users (In-band registration) using anonymous user using Strophe.js like in the example here: http://groups.google.com/group/strophe/browse_thread/thread/a0e15ae226b91a3a?fwc=1 . I managed to register new users with an existing account only (as a normal “not admin” user). Is that a openfire security issue?
I connected anonymously using:

 connection.connect("server.local", null, onConnect);

The server returns:

 <iq xmlns="" type="error" id="reg2" to="7711fc7f@server.local/7711fc7f">
    <query xmlns="jabber:iq:register">
        <username>user</username>
        <password>abc</password>
    </query>
    <error code="400" type="modify">
        <bad-request xmlns="urn:ietf:params:xml:ns:xmpp-stanzas"/>
    </error>
</iq>

If I connect with a registered user it works fine and I can create other users. Would it be unsecure to allow registration from a dedicated user account say register@server.local (with no admin rights) ?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-03T04:45:40+00:00Added an answer on June 3, 2026 at 4:45 am

    I managed to register new users with an existing account only (as a
    normal “not admin” user). Is that a openfire security issue?

    This depends on your point of view – if that’s what you want, no it isn’t a security issue. If you want to restrict account creation to admins in your deployment, yes it is. Openfire should have configuration parameters to control who can create accounts (though in some versions these controls simply don’t work – that was a security issue!).

    There are known scripts around that actively discover and register accounts on servers with open registration. Some people (especially large targets like jabber.org) choose to disable in-band registration entirely, while others simply place per-IP rate-limiting restrictions on it. There is also a specification (XEP-0158) for CAPTCHAs to be sent to clients for in-band registration, but support for this is far from universal yet.

    The server returns:

    The error stanza you gave has xmlns="", which is suspicious to my eyes. It should be “jabber:client”, but it seems Openfire understood it anyway.

    You could also try setting the ‘to’ address of the request to the host that you are trying to register on (e.g. to='example.com' when registering ‘user@example.com’). If you are already setting ‘to’ then try without it. I have seen different interpretations of the specifications around this point.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'd like to make user creation public, so that unauthenticated users can create new
I am using Excel VBA 2003. Is it possible to create new recordset by
I'm using Umbraco 5. Is it possible to create new Document Type programmatically using
I know it is not possible to create Mercurial repositories remotely using HTTP(S), for
Is possible create (register) a new class in runtime using delphi. I have a
Is this possible to create new {variable = x.something} and specify variable name dynamically?
Is it possible to create a new List<T> where the T is dynamically set
I am wondering if it is possible to create a new dataframe with certain
Hi it'd like to know if it's at all possible create a parametric equalizer
How do I add a new key in the registry of other users using

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.