Viewing 10 replies - 1 through 10 (of 10 total)
  • Had a similar situation on a site quite a while ago, changed the default field names from your-name, your-email, … to something else and in addition installed Contact Form 7 Honeypot plugin, that stopped the spam.

    As a more recent alternative there is now also the built-in recaptcha feature in CF7 to prevent spam.

    +1 for the Contact Form 7 Honeypot

    Thread Starter dawidadach

    (@dawidadach)

    I realized that messages were coming from our test server.

    The weird part is that first I have removed all contact forms from plugins – didn’t help. Later on I removed plugin totally – emails were still coming from this domain. I thought that maybe it accessing files directly so I added Options -Indexes to .htaccess – didn’t help. I renamed index.php name so blog wasn’t accessible – no result. Finaly I created folder archive on FTP and moved all files into it – that finally “solved” the issue – any clue why bot was still able to use contact form after deletion ?

    Plugin Author Takayuki Miyoshi

    (@takayukister)

    Why do you think the bot is using Contact Form 7?

    Thread Starter dawidadach

    (@dawidadach)

    Because that is the only contact form I had on the page. Contact form was working fine , I was getting normal messages from users via contact form and then I started getting thousands of email via the same form from bot.

    Plugin Author Takayuki Miyoshi

    (@takayukister)

    But the plugin has been deactivated (and removed)?

    Reason could also be that these “thousands of messages” were actually sent via still active plugin and continued to arrive after plugin removal because they were already sent/on their way…

    Thread Starter dawidadach

    (@dawidadach)

    Indeed, as I mentioned before

    1) I removed all forms – didn’t help
    2) I deactivated plugin – didn’t help
    3) I renamed index.php name so website wasn’t accsessible – didn’t help
    4) I changed .htaccess so users can’t list files in directory – didn’t help
    5) I moved all wp files to another folder – that finally solved the issue.

    So somehow bot still had access to form…

    Regarding delay – I also thought about that but I was waiting few hours between each step. I was struggling with this issue for 2 days…

    Have seen mailservers which use some form of mail throttling (send out max. nr of messages per hour or similar) so in your case with “thousands of messages” the sending/arrival could take a long time.

    Actually there is no other explanation for the described behaviour.

    Plugin Author Takayuki Miyoshi

    (@takayukister)

    Have you confirmed the source IP address of the spam?

Viewing 10 replies - 1 through 10 (of 10 total)
  • The topic ‘Getting spammed by bot’ is closed to new replies.