• Resolved davvam

    (@davvam)


    Hi

    Yesterday our site was bombarded by a MailChimp bot from your plugin (over 100,000 requests) from different user agent IP addresses as below:

    (removed)

    Below are some of the requests found in the access log:

    34.75.225.48 – [25/Jan/2024:20:45:04 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth= HTTP/1.1” 403 75193 “-” “MailChimp” | TLSv1.2 | – – 0.091 – 0 NC:000000 UP:-DT


    34.138.92.101 – [25/Jan/2024:21:10:04 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth= HTTP/1.1” 403 75193 “-” “MailChimp” | TLSv1.2 | – – 0.095 – 0 NC:000000 UP:-DT


    34.138.92.101 – [25/Jan/2024:21:10:04 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth= HTTP/1.1” 403 75193 “-” “MailChimp” | TLSv1.2 | – – 0.091 – 0 NC:000000 UP:-DT


    34.138.92.101 – [25/Jan/2024:21:10:04 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth= HTTP/1.1” 403 75193 “-” “MailChimp” | TLSv1.2 | – – 0.091 – 0 NC:000000 UP:-DT


    35.196.249.1 – [25/Jan/2024:21:10:04 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth= HTTP/1.1” 403 75193 “-” “MailChimp” | TLSv1.2 | – – 0.090 – 0 NC:000000 UP:-DT

    Any reason why? Our site actually went down ad the only way I could fix it was to block the IP addresses above.

    Thanks

    • This topic was modified 10 months ago by Yui. Reason: tokens removed
Viewing 6 replies - 1 through 6 (of 6 total)
  • Thread Starter davvam

    (@davvam)

    Any update on this, as we have had another 100 000 requests generated by Mailchimp that seem to relate to member sync? See below:

    34.138.92.101 crystalclear.co.uk – [25/Jan/2024:19:01:22 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth=4 HTTP/1.1” 499 0 “-” “MailChimp” | TLSv1.2 | – 5.530 5.530 – 0 NC:000000 UP:-DT

    34.73.115.0 crystalclear.co.uk – [25/Jan/2024:17:16:01 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth=f HTTP/1.1” 502 89588 “-” “MailChimp” | TLSv1.2 | – 0.000 1.200 – 0 NC:000000 UP:-DT


    34.73.115.0 crystalclear.co.uk – [25/Jan/2024:17:20:41 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth=b HTTP/1.1” 502 89588 “-” “MailChimp” | TLSv1.2 | – 0.000 0.200 – 0 NC:000000 UP:-DT


    34.75.225.48 crystalclear.co.uk – [25/Jan/2024:17:27:32 +0000] “POST /wp-json/mailchimp-for-woocommerce/v1/member-sync?auth=4 HTTP/1.1” 502 89588 “-” “MailChimp” | TLSv1.2 | – 0.000 0.200 – 0 NC:000000 UP:-DT

    • This reply was modified 10 months ago by Yui. Reason: tokens removed
    Plugin Author ryanhungate

    (@ryanhungate)

    @davvam sorry to hear about this – I have a few things for you.

    1. These logs you’re posting have an auth token in the url – and you don’t want to post that anywhere people can see because this is how we identify that the request actually came from Mailchimp… so please redact that information from the post here and we need to take some steps to fix this.
    2. I am going to also recommend that we first delete all the webhooks that are attached to your Mailchimp list manually just to make sure we’re starting from scratch. If you need help doing that – please just log into your Mailchimp account and ask them to guide you to that section – you can just delete all the hooks in there if there’s more than 1.
    3. After you’ve done this, we have 2 options to solve the problem.

    a. You uninstall and reinstall the plugin so it will set you up again as it needs, but if you have a substantial amount of e-commerce data to sync that could take a while.

    b. If you do have a lot of data to sync, it would probably be best to enable remote support so we can help you from our end. You will first need to delete a database record in your options table called “mailchimp-woocommerce-webhook.token” so we can re-issue this hook for you using a new token.

    Either approach will work, but the reason you’re getting so many webhooks could be for a few reasons. If you’re doing massive import / updates into your Mailchimp list, you’re going to get a webhook for each person you’ve updated. That can be a lot on a web server if you don’t have the right infrastructure to handle it. Also, it could be simply because we have too many webhooks configured to send to your server at once… and that will be resolved after you’ve deleted them from your Mailchimp list.

    If you need any other help with this please let us know – but either of those options will solve your problem. If you decide to use the remote support option please just let us know when you’re done with that so we can take care of it from our end.

    Thread Starter davvam

    (@davvam)

    I will go through this in more detail tomorrow, how do I redact the original post I submitted?

    Plugin Author ryanhungate

    (@ryanhungate)

    @davvam you should be able to “edit” your posts here and just remove the auth token from the string if you would like to keep the remainder there. The rest is totally fine. Actually you should only even have 1 valid auth token at a time, so most of these are probably safe – but I just don’t know which one is the active one. There’s a record in your wp-options table that will be your current “webhook.token” record so that one is the current active one we need to delete… then try to re-activate after we’ve cleaned the list up.

    We’ll get you taken care of with a little effort ??

    Thread Starter davvam

    (@davvam)

    Cannot find anywhere listing an edit post link, very annoying this!

    Plugin Support Jordan Rich

    (@builtbyjordan)

    According to the www.remarpro.com Forum FAQ, it’s only possible to edit a post within a 1 hour window. I’ve quoted below their info getting a moderator to remove or edit a post:

    If you feel you have a pressing need (legal or otherwise) to have a post removed, you can report the post (there’s an option on the sidebar) and explain why or come to the?#forums?channel on?Slack.

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘MailChimp Bot’ is closed to new replies.