Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 06-27-2025, 11:07 AM   #1
Yamato
Confirmed User
 
Yamato's Avatar
 
Industry Role:
Join Date: Apr 2023
Posts: 148
Is this a new Word Press hack or what?

So, I have this old site on WordPress, and it has all updates installed, so it’s fully patched. Out of the blue, I started getting emails about new users registering and then requesting lost passwords. All of them are coming from the usual suspects—Bangladesh, India, Indonesia, Cambodia, Brazil, etc. The emails they’re registering with look legit and mostly corporate. What’s going on?
Yamato is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-27-2025, 11:25 AM   #2
cerulean
Web & App Development
 
cerulean's Avatar
 
Industry Role:
Join Date: Oct 2023
Location: United States
Posts: 134
Do you have WordFence installed?

This is a pretty common tactic, to use password lists and bombard a site with login and registration attempts looking for vulnerabilities and existing accounts. If they find an active account, the tactic might change. My WordPress sites that employ WordFence have tons of logs of these things happening.
__________________
Cerulean Software Specializes in Website and App Development. Email me today!

Keep Your Business and Members Area Secure with LoginBlue Password and Content Protection
cerulean is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-27-2025, 03:12 PM   #3
Yamato
Confirmed User
 
Yamato's Avatar
 
Industry Role:
Join Date: Apr 2023
Posts: 148
Quote:
Originally Posted by cerulean View Post
Do you have WordFence installed?

This is a pretty common tactic, to use password lists and bombard a site with login and registration attempts looking for vulnerabilities and existing accounts. If they find an active account, the tactic might change. My WordPress sites that employ WordFence have tons of logs of these things happening.
Yes, its WordFence email me these emails every few seconds. It was installed with WP and suddenly started to email be this brute force attempts earlier this week. I wonder if its new version that turned off notifications and now bombarding me because I see summary and it shows same thing happened last week.
Yamato is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-27-2025, 05:35 PM   #4
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,339
best to block all connections except your from wp-admini do that allow from my ip deny from all so they ant even reach the login page.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-27-2025, 07:04 PM   #5
cerulean
Web & App Development
 
cerulean's Avatar
 
Industry Role:
Join Date: Oct 2023
Location: United States
Posts: 134
Quote:
Originally Posted by Yamato View Post
Yes, its WordFence email me these emails every few seconds. It was installed with WP and suddenly started to email be this brute force attempts earlier this week. I wonder if its new version that turned off notifications and now bombarding me because I see summary and it shows same thing happened last week.
That's possible. WordPress accounts for half the websites out there. There are a lot of vulnerabilities from years past, and a lot of malicious actors trying to break into these sites. It's very lucrative to get a crypto bot running or steal user data.

You would do well to have your web developer audit your site and have your host do a cursory anti-malware scan, just to be safe.
__________________
Cerulean Software Specializes in Website and App Development. Email me today!

Keep Your Business and Members Area Secure with LoginBlue Password and Content Protection
cerulean is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 06-27-2025, 08:03 PM   #6
Shoplifter
Richest man in Babylon
 
Shoplifter's Avatar
 
Industry Role:
Join Date: Jan 2002
Location: Posts: 10,002
Posts: 5,697
Quote:
Originally Posted by fris View Post
best to block all connections except your from wp-admini do that allow from my ip deny from all so they ant even reach the login page.
This.

Make a Cloudflare WAF custom rule to block wp-login.php.
Shoplifter is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old Yesterday, 03:01 AM   #7
TubesBooster
Confirmed User
 
TubesBooster's Avatar
 
Industry Role:
Join Date: Oct 2024
Posts: 29
Check if you have updated not only WP, but also plugins and themes, because themes are very often hacked, primarily those that come pre-installed with wordpress. If you don't use them, uninstall them completely.
__________________
Tubes Booster – Next-Gen Video - Tube CMS
AI · VAST · Video Grabbers · SEO · Monetization · New Features Every Week
www.tubesbooster.com[email protected]
TubesBooster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old Yesterday, 05:19 AM   #8
Okaro
Confirmed User
 
Industry Role:
Join Date: Jan 2020
Location: Spain
Posts: 38
For login i change the wp-login page with this plugin: WPS Hide Login

Light and easy.
Okaro is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old Yesterday, 07:51 AM   #9
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,339
Quote:
Originally Posted by Okaro View Post
For login i change the wp-login page with this plugin: WPS Hide Login

Light and easy.
still can find it easily, best to just add a rule in your webserver to block all except your ip.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old Yesterday, 09:13 AM   #10
blackmonsters
Making PHP work
 
blackmonsters's Avatar
 
Industry Role:
Join Date: Nov 2002
Location: 🌎🌅🌈🌇
Posts: 20,304
Also install Fail2ban on your sever.
It will ban IP addresses that try login too many times.

https://github.com/fail2ban/fail2ban

__________________
Make Money with Porn
blackmonsters is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
emails, registering, coming, usual, requesting, lost, passwords, suspects—bangladesh, cambodia, legit, corporate, what’s, they’re, indonesia, brazil, india, blue, site, wordpress, word, press, hack, started, patched, updates



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.