Spam Scare
Recently, Carson gave us the go ahead to turn off our SpamShield because it was replaced by another filter. I, like many others here deactivated my WP-SpamShield plugin. Everything was fine for a while, however, recently, I had to flip the switch on WP SpamShield and reactivate it.
It started with a spam email that arrived in my inbox through my contact from. I didn't think much of it . That is until... I began getting one or two a day. So at that point I thought I'd turn WP SpamShield back on again. When I logged in, I was greeted by a pretty disturbing site. In my Admin panel, there was another name. Someone had actually hacked in and gave himself access to my WordPress site dashboard. I was so upset, I didn't think to take a screenshot first. I just wanted this person OUT as soon as possible. So first, I changed my password, then logged in and deleted this new user. I looked around but didn't see anything that had been altered or changed, so I was relieved about that. Nevertheless, I was still shook up finding a stranger lurking in my login box.
Next, I turned WP-SpamShield on again and, so far, no more spam emails. I don't know what to attribute the fact that I was attacked by a hacker and spam when everyone else seems to be protected without the extra layer. I may experiment another in the future by turning of the SpamShield again and documenting any changes if it happens again. For now, however, I'm going with the double dose of website armor.
Recent Comments
32
Have you unchecked the box before " Anyone can register?"
Settings>General>Membership>uncheck>Anyone can register !
Gosh quite scary I still have my antispam bee on hope you alerted support team thank you for alerting us glad I did not turn off my protection
Hal, I am using the Akismet plugin and I was receiving disturbing daily emails through my contact form as well. They all were slightly different using various female names, all saying that they wanted to hook up with me "tonight". I just ignored them. Luckily they have stopped.
Nothing to be glad about. I didn't "find" it. It was right in front of my face next to my own login button.
Hackers can get through even the most protected sites. But have you reported this issue to Kyle and Carson? They should know about it so that they can take a look at what happened.
The Site Manager is in my siterubix so I don't have to worry. Probably, I'll just keep the spamshield in the domains I own.
Please keep us posted to see what's going on in the field. Thanks for sharing your experience, Hal.
o, didn't report it this time. I wasn't thinking. Next time I'll be ready. I' will take screen shots and document any trespass by unknown quantities.
You still can let them know even without the screenshot so that they will be aware that there is something like this going on.
Hi Buddy,
I just check3d mt system and all still OK no spam nothing and all my shields are deactivated so for me it is working OK
So far, I think I'm the only one who's been breached. I haven't seen a single mention of spam by anyone else. One or two spam emails slipping through the cracks doesn't bother me that much, but... Seeing another user name on my log-in screen is what really freaked me out!
My heavens yes! Like walking in your house and seeing someone eating out of your fridge.
Hopefully everything continues to be ok.
See more comments
You are lucky the hacker didn't delete you as admin and took over altogether...though site support could have sorted that out, you would have had a hernia...or some such!
I know, right. That's the scariest thing that could ever happen to our websites. In that case, what do we do?
They won't be able to host your site with anyone else because it is hosted here so WA can evict them.
Does that mean that WA can take them off as admin and get it back for you?
That is a question for you to ask site support so that they can give you a more detailed answer...I don't want to simplify this.
Thank you so much for all the info. That's good to know as it can happen. Have a wonderful weekend!
That was the first thing that crossed my mind.