Search Results for 'spam'
-
AuthorSearch Results
-
June 26, 2013 at 5:24 pm #166963
In reply to: Untraceable spam user
mareksgregs
ParticipantI’ve already removed the plugin. Since I didn’t even use it.
Do I really need to change database password too? How could they even access my database?June 26, 2013 at 5:18 pm #166962In reply to: [Resolved] Show member recent post in members loop
applegateian
ParticipantSorry to spam, but totally stuck on this, any ideas?
June 26, 2013 at 5:12 pm #166961In reply to: Untraceable spam user
Ben Hansen
Participantfyi if your site has been hacked even on a low level you must clean it out and change all the associated admin and database passwords or you will be letting them right back in.
June 26, 2013 at 5:10 pm #166960In reply to: Untraceable spam user
Ben Hansen
Participantits still a bad sign that base 64 stuff is usually a sign of a open door that has been used to hack your site.
June 26, 2013 at 5:08 pm #166959In reply to: Untraceable spam user
mareksgregs
ParticipantThe scan found only one problem, which is:
This file may contain malicious executable code
Filename: wp-content/plugins/user-meta/framework/init.php
File type: Not a core, theme or plugin file.
Issue first detected: 45 secs ago.
Severity: Critical
Status New
This file is a PHP executable file and contains an eval() function and base64() decoding function on the same line. This is a common technique used by hackers to hide and execute code. If you know about this file you can choose to ignore it to exclude it from future scans.I wasn’t using that plugin though. It was deactivated.
June 26, 2013 at 3:21 pm #166942In reply to: Untraceable spam user
Ben Hansen
Participanti think you should really check your site using that wordfence plugin as we both indicated having a user without an associated email is very suspicious.
June 26, 2013 at 8:09 am #166905In reply to: Prevent from spam messages.
Henry
MemberHave you tried searching the WordPress plugin repository for something like ‘buddypress spam messages’?
A good plugin that will certainly resolve the issue is
https://wordpress.org/plugins/buddypress-private-message-for-friends-only/June 26, 2013 at 7:47 am #166901In reply to: Untraceable spam user
mareksgregs
ParticipantI deleted the user from the database yesterday(in which it didn’t have an email either) yesterday. And it hasn’t come back yet. I think it may be finally gone. 🙂
June 25, 2013 at 11:23 pm #166880In reply to: Untraceable spam user
Jose Conti
ParticipantThank’s @ubernaut
June 25, 2013 at 3:28 pm #166839In reply to: Untraceable spam user
Ben Hansen
Participant@jconti keep up the good work!
June 25, 2013 at 7:43 am #166826In reply to: Untraceable spam user
Jose Conti
Participant@mareksgregs use this plugin:
https://wordpress.org/plugins/wordfence/
That plugin will check all core files.
Do you use WordPress simple or WordPress Multisite?
June 25, 2013 at 7:25 am #166824In reply to: Untraceable spam user
mareksgregs
Participant@jconti What am I supposed to look for in those files?
And I found the user in the users database. Should I delete it?June 25, 2013 at 7:04 am #166822In reply to: Untraceable spam user
Jose Conti
ParticipantHi @mareksgregs and @ubernaut,
I’m the WangGuard developer.
Search the user in the database (wp_users). You need to find there.
You need to check wp-config.php, index.php, wp-content and if you use a cache, wp-content/cache
I think you have been hacked. Is impossible that a user don’t have and email and if you delete the users and 5 seconds later, the user I’d there again, there are a script that create the user.
And yes, every 2 days, we have a very big attack. Now, we are looking for bigger servers with a best protections agains this attacks 🙁
Kind regards
June 24, 2013 at 5:47 pm #166770In reply to: Untraceable spam user
Ben Hansen
Participantjust blank space huh? never seen that before not sure how its even possible unless as i said before your site was hacked and even then I’m still not sure how it’s possible. as far as i know every wordpress user account must be associated with an email address.
June 24, 2013 at 5:42 pm #166769In reply to: Untraceable spam user
mareksgregs
ParticipantI think I found out why it says Error – 101 too. When I click “Recheck”, it says “The selected user couldn’t be found on users table”.
So does that mean that it’s beyond user database? o_oEdit: There’s still no email.
June 24, 2013 at 5:42 pm #166768In reply to: Untraceable spam user
Ben Hansen
Participantwell you are assuming they will continue to use the same ip which is i think not a safe assumption. what is the email listed?
June 24, 2013 at 5:38 pm #166767In reply to: Untraceable spam user
mareksgregs
ParticipantI just deleted the user again, and it re-appeared 5 seconds later, but this time Wangguard logged an IP! This means progress!
Any suggestions for how to ban the IP now?
June 24, 2013 at 5:21 pm #166766In reply to: Untraceable spam user
Ben Hansen
Participanthmm i think i have also seen that before i forget exactly what it was but the address was invalidly constructed as i recall (meaning it was not the proper format you’d expect to see for an email). i have noticed that wangguard’s server(s) are not always available (probably get attacked with some frequency). whenever wangguard is not online the plugin just lets people pass but it is rather odd that someone should even be able to complete registration without a valid email.
:/
June 24, 2013 at 5:11 pm #166763In reply to: Untraceable spam user
mareksgregs
Participant@ubernaut I tried that Wangguard plugin (thanks for introducing it to me by the way, it’s awesome) and when I scanned the user, it’s status came back as “Error – 101”
I don’t see how my site could be hacked though. Perhaps the problem is in one of my plugins. Unlikely though. All of my active plugins are legit and shouldn’t have spam bots in their files…
June 24, 2013 at 4:37 pm #166755In reply to: Untraceable spam user
Ben Hansen
Participanti don’t see how that’s possible unless your site was hacked, maybe then, not sure.
June 24, 2013 at 4:33 pm #166753In reply to: Untraceable spam user
mareksgregs
Participant@ubernaut Oh I forgot to mention, there isn’t an email associated with the account either.
I think that something in the files may be creating it over and over again. Would that be possible?June 24, 2013 at 4:17 pm #166751In reply to: Untraceable spam user
Ben Hansen
Participantwhen you say “has no registration ip” i’m assuming you are using wangguard or some other plugin to get that info. fact is there must be an ip it may be spoofed but regardless why not just ban whatever email they are using to register?
June 20, 2013 at 12:14 pm #166472Sea Jay
ParticipantWe are using WP-Better-Emails. Works great. Still have to suggest people check their spam folders.
June 20, 2013 at 2:27 am #166446In reply to: Buddypress Spam BOTS PLEASE HELP
inge12
ParticipantLeofitz, WangGuard will check your user base for spammers and delete them.
See https://wordpress.org/plugins/wangguard/
The author says that “WangGuard not only protect your site from sploggers, spam users or unwanted users, WangGuard cleans your database from them. No plugin or service does this, only with WangGuard you will get this feature,” and I believe him. His English may not be too good, but the plugin is really outstanding.
There’s just one consideration for you: In order to have your database cleaned up, you will have to submit far more than 500 queries the first month. Perhaps you can arrange to pay for a month?
Here’s my suggestion to reduce database queries after that. (It worked for me.) Buddypress allows for the customization of User Profiles. Add a couple of questions that require a certain amount of intelligence to answer and make them required. That means the form will not be submitted either to WordPress or to WangGuard if the required fields are not filled out. It’s not fool-proof, but it decreased queries on my very busy site to just a few a day.
Incidentally, I added a question, “How do you plan to participate?” Among the choices offered the user are these:
“I want to increase my online presence.” and
“I want to sell my stuff.”We don’t need anyone not bright enough to figure out that these replies do not make the user desirable. Now all I need is a script to automatically kick out users who choose these replies. 😉 (As it is, they can be manually deleted if other users report them.)
I don’t know what happens to a group when all the users are unsubscribed, so this may not be precisely what you are looking for. But WangGuard will make your site secure against almost all sploggers. (One registrant passed all tests on our site, and we had to delete manually, but that person must have registered manually too.)
Good luck!
Inge (http://ssnet.org)
June 19, 2013 at 4:38 pm #166405In reply to: Buddypress Spam BOTS PLEASE HELP
Ben Hansen
Participantmaybe not as long as you think if you use the backend, can’t you mass delete them that way?
-
AuthorSearch Results