Support Forum

Feel like giving up in this war against Bots!

MA mann
mann
Member

Not only are the bots registering but surprisingly they created around 500 subsites on my site. 

For example if my site is www.mywebsite.com/

They created www.mywebsite.com/xyz1 , www.mywebsite.com/xyz2 etc

I just wasted more than 1 hour on deleting all these subsites and I wonder how did the bots manage to create them? 

The bots have been registering like anything in the last one week and on top of this now this new problem has crept up.

Could the updation of any plugin have triggered this ? Or could it be that these are some new ingenious bots that have found ways to bypass recaptcha. But had this been the case, then by now all the sites using recaptcha would have been affected.

If I say I’m frustrated-that would really be an understatement. I seriously don’t know what to do! Sorry for the rant…

12 Answers

New Answer

YS Yellow Swordfish
Yellow Swordfish
Member

I think you need to be discussing this with your host to find out how the site has been compromised. It is, after all, also in their interest to help and take it seriously.

Worth checking if your WordPress is up to date as well. Always remember that often a version with a third digit of more than zero has often been put out due to a security issue and that security issue will be known by people wanting to take advantage of it.

MA mann
mann
Member

Thanks Andy. Will do both and update you. I really need to make headway into this before they wreck any more havoc.

MA mann
mann
Member

Quick update. The solution that finally worked is that I regenerated the recaptcha keys for my website. Spam registrations have almost stopped. I’m not sure though regenerating the recaptcha keys actually did this(but whatever did it, I’m happy)  What do you think guys could regenerating keys could have any effect ?

YS Yellow Swordfish
Yellow Swordfish
Member

Speaking purely for myself I have not used recapthcha so can’t really comment but it doesn’t sound like a bad thing to do and if it helps then hey – just do it is what I say!

EK Edward Koon
Edward Koon
Member

I had been running Bad Behavior Plugin but found it blocks lots of blog / forum posts from the Google bot among other legitimate crawlers. Tweeting posts sends a hoard of bots hiding behind Amazon’s Cesspool. Hard to block when the source is hidden, might be blocking a good crawler.

I am running a 60+ percent of bots vs humans. It’s still a problem and a huge waist of server resources. No real solution in sight that i have found.

 

EE Elsa Elsa
Elsa Elsa
Member

Wordfence is fantastic.  Especially the paid version.  It handles pretty much everything, without any effort on your part. It also allows you to easily block entire countries… pretty much anything and everything you might want or need.

I installed it after my site was so badly hacked it took us a month to clean it up. I also lost four months of content.  I’ve had no trouble, since. It’s a lot better to lock the door(s) than to try to get rid of trouble once you’ve been breached! 

EK Edward Koon
Edward Koon
Member

WordFence does work well but blocks after the bad guys hit your server sucking up precious resources. CloudFlare on the other hand does pretty much the same thing but stops threats before they reach your server. CF allows blocking / challenging countries and blocking whole AS and IP ranges. Much better solution and is free!

SP Simple Press
Simple Press
Admin

If it helps anyone, we use three layers of firewall on this site.  First is Cloudflare – stops a lot of bad stuff before it even hits our servers. Any traffic that does hit our servers is then filtered through a set of custom Web Application Firewall rules before it hits the WordPress site.  Anything that makes it through that is then filtered by WordFence.  Nothing works perfectly and each vendor responds to emerging treats differently at different rates – so having multiple security layers is the best approach in our opinion. Performance takes a small hit but we’ll take security over performance any day.

Even with all that, there is still a bunch of stuff that makes it through and attempts dictionary style login attacks.  Those eventually gets taking care of by blocking based on number of failed attempts and such…

JI jim
jim
Member

mann said
Not only are the bots registering but surprisingly they created around 500 subsites on my site…

It sounds like you’re running a WordPress Multisite network. If not, then the hosting account has been seriously compromised.

If so: Do you run any sort of Splog moderation and control, other than captcha on your registration page?

We run a very large WPMS network at Tripawds. I’ve been fighting spam blog registrations for years and have implemented various methods to bring it under control.

Anti-Splog is the first step.

I also implemented a Signup Code and display that on the reg page, to ensure humans are filling out the form.

Finally, I am working with the developer of Beyond Multisite, who is almost ready to release an update to include Blog Moderation, which allows us to prevent first posts from being published, with an easy way to delete sites and users. No ETA on this, but the beta is working great.

FYI: These methods are in addition to server level csf firewall, and our Wordfence Premium account.

EK Edward Koon
Edward Koon
Member

Spam bots are a pita. I use cleantalk.org which is a bargain considering Akismet is now a pay service. The spam firewall is a really good feature. 

ctsc.jpg