• Everyday now I get between ten and fifteen new registrations (subscribers) on my wordpress site. All of them have dodgy names and equaly dodgy email addresses. I have no doubt in my mind that these registrations are testing the security of my site. This activity seems to have increased substancially in the last couple of months. Are other WordPress users experiancing similar registrations and are there any security issues I should be looking at to ensure no-one gets in! I have Akismet 2.1.5 loaded and activated. Is there anything else I should have done but not…?

Viewing 8 replies - 16 through 23 (of 23 total)
  • “I will give you one concession”

    I don’t need your concessions, I’ve just jammed your comments up your arse. I maintain that what you said was misleading.

    Instead of saying “yeah, you’re right, its just MOSTLY spam” like even *I* said myself up there when I corrected you… you went on a bloody undeserved rampage because someone had the balls to suggest you were wrong.

    Get over yourself.

    Whatever percentage you think it is… its still significant, given the nature of the attempts.

    Talk about going on a rampage — I REPLIED because I disagree with you on a “whole”.
    You wanna be semantically correct — ok, the possibility exists that a registered user could attempt an exploit — of course that exists.

    Do I personally find that to be a threat? No. Was it a mispeak to use the word “just”? Yes, but not because I dont find it threatening, but because someone else might.

    As for the rest of your remarks — I’m thinking maybe you are the one who needs to get over themself. Here I thought I was cutting off an argument by saying you were right, and you act like a pr*ck after that.

    figures.

    please don’t pretend you didn’t edit your posts repeatedly.

    this “even after that” stuff is meaningless when you futz with the timeline, as is pretneding that you’re offering concessions, when the truth is I had to pull it from you with pliers.

    You’re only now agreeing that you could have expressed yourself differently, instead of doing so directly after I pointed it out. That’s actually not particularly insightful or conciliatory of you.

    but it’s GREAT, don’t get me wrong, better late than never.

    I doubt anyone here is going to call me a meanie for drumming it into you, after all the fire you spew on everyone. Take your medicine, and perhaps next time you won’t be so quick to insult people by labeling their well-reasoned attempts to provide full-disclosure as ‘bullshit’.

    I DID edit my posts repeatedly. I never said otherwise. I didnt edit any of them AFTER you had posted. Except to try and fix the damn blockquotes.

    And I said THREE posts back in the blockquote one the JUST was wrong. Follow? And if you didnt see it, its because I was editing and you were posting at the same time.

    you’re offering concessions, when the truth is I had to pull it from you with pliers.

    Thats kind of funny. You think you know me well enough to say that? Hahaha. I assure you I can argue for much longer, wrong or right.

    And since you want to be so sematically correct:

    concession: the admitting of a point claimed in argument

    that was a concession – youre taking it the wrong way. I respect you, and while like I said, I dont tend to buy into the registration from bots leads to hacks thing, I respect your opinion enough to have said you were right. Take it or leave it, I dont care.

    Like I said, the timeline is meaningless, so you really should allow for a couple of posts of lag, before you decide I’m sinking the boot in.

    edit: since we’re editing, I’m well aware of the definion of the term concession, as well as the tone in which it was given. We’ve certainly both been around long enough to tell the difference between conciliatory concessions and otherwise.

    I appreciate your respect. The feeling is mutual, but really that enters into it long before points are scored in arguments. Respect is supposed to make you think about what was said before you start arguing against it.

    I’m sorry if you think I’m harping on about this, but I really would prefer this to be the last time we have an exchange like this. If you think I’m going overboard, it’s because I never want to do this again.

    Anyway, this is all moot, I appreciate your willingness to allow for a point of view which you consider to be a statistical anomaly. I don’t think it’s the most likely outcome either, but worth mentioning nevertheless.

    Tignarius: It’s not the wordpress upgrade. I’ve been getting those on my site (as well as friends) for over a year now. It looks like they just finally found your site.

    On another note, take a look through the code in your posts if you have time. I started to notice that around the same time I started getting new bogus registration requests, I was also being hit by sql injections that were putting code in my blog entries. I’m not sure if that was related or not, I just happened to notice it around the same time because one of the injections actually broke my site which made it obvious.

    I’d either disable registrations or setup some sort of captcha.

    Good luck!

    @tignarius
    Yes, I too have been experiencing the same thing. Recently… all of a sudden… I’ve been getting a surge in user registrations from shady folks. And if I search on the offending userid or email I get Google popping up MANY brand new registrations for the same “indivudal” over the course of two or three days (game forums, jazz portals, weight loss discussion boards, blogs, chatrooms, social networking, etc)… and all profiles are completely empty… all activity is zero.

    @whooami
    Every thread you join here seems to turn to poison. I have a picture for you, though.

    @elorgwhee
    Thanks for the info. I just experienced a similar thing. Funny characters turning up in my post. I guess I will simply turn of users registration.

    Please is there any way I can clean the blog of code injected without my knowledge? Thanks.

Viewing 8 replies - 16 through 23 (of 23 total)
  • The topic ‘Are ‘web robots’ testing my wordpress security?’ is closed to new replies.