Skip to:
Content
Pages
Categories
Search
Top
Bottom

Forum Replies Created

Viewing 6 replies - 1 through 6 (of 6 total)

  • guoyunhebrave
    Participant

    @guoyunhebrave

    @mercime

    Please look at my question carefully. I mean this problem appeared in Mobile View.

    If you use smart phone to view the website, you can see a blank admin bar. You can also scale the width of desktop browser to less than 768px.

    This is a CSS problem. I saw it in admin-bar.css file.


    guoyunhebrave
    Participant

    @guoyunhebrave

    @jconti @espellcaste

    It is not a real back door but a weak point. These register forms of plugins cannot be protected by CAPTCHA methods.

    I don’t know there is a sign up form in question page. I guess many site owners won’t know, because it is unnecessary to create another register entry: more entries, more danger.


    guoyunhebrave
    Participant

    @guoyunhebrave

    I finally solved it!

    This is caused by another plugin named “DW Question & Answer“. It has a quick register form that can be used to avoid CAPTCHA methods.

    I disabled this plugin and robots should be stopped.


    guoyunhebrave
    Participant

    @guoyunhebrave

    After disabled BuddyPress, robots didn’t stop. I am almost sure the robot can skip the register page (both WordPress signup.php and BuddyPress register page).

    Maybe robots have a backdoor to register on WordPress. I don’t know how to further test.


    guoyunhebrave
    Participant

    @guoyunhebrave

    I installed this plugin today. I keep receiving robots registering until now.

    I think the robots have passed by WangGuard and any other CAPTCHA plugins, because all of them have no effect.

    Before I use BuddyPress on this site, I didn’t meet these problem. A simple CAPTCHA plugin works well. I will try to disable BuddyPress for hours, and see what will happen.


    guoyunhebrave
    Participant

    @guoyunhebrave

    Something I test with WangGuard:

    I set some WangGuard questions. Once these questions are answered, I could see wrong/right statistics in configuration page. But after robots registered, no information update.

    So maybe the robots can avoid register on the sign up page. That is beyond my knowledge.

Viewing 6 replies - 1 through 6 (of 6 total)
Skip to toolbar