Notifications
Clear all

wpForo 1.x.x [Closed] Being Spammed by Fake members

9 Posts
2 Users
1 Reactions
1,561 Views
Posts: 1212
Topic starter
(@percysgrowroom)
Noble Member
Joined: 6 years ago

I am being spammed right now by some one signing up multiple accounts, with similar users names, all from different fake email address. 

I am not able to find their IP address in the forum, so unable to stop this. 

Is there some way to prevent my forum being spammed like this? Surely the email address should be valid before an account is made? Is that possible? 

I feel like if this guy doesn't stop ill just have 100 new members today from fake accounts! 

8 Replies
dimalifragis
Posts: 2611
(@dimalifragis)
Famed Member
Joined: 5 years ago

All those issues should be addressed BEFORE the user reaching the forum (or any other service).

That is when registering/login.

How do you protect your WP? With what plugin?

Posts: 1212
Topic starter
(@percysgrowroom)
Noble Member
Joined: 6 years ago

I use askimet to prevent spam, and its not usually a problem..... is there something else you would suggest? 

 

Thanks for the speedy reply mate 

dimalifragis
Posts: 2611
(@dimalifragis)
Famed Member
Joined: 5 years ago

I'm not familiar with Akismet. I ask what you do with people/bots trying to register/login?

Any security plugin apart from Akismet?

Also do you LOG the IPs (login/register)? If not try https://wordpress.org/plugins/when-last-login/

1 Reply
(@percysgrowroom)
Joined: 6 years ago

Noble Member
Posts: 1212

@dimalifragis I used black hole for bad bots for a while, But my security stuff is mainly in my cPanel I think, would you recommend I install a security plug in then? 

I use google capture on sign in and sign up pages too 

dimalifragis
Posts: 2611
(@dimalifragis)
Famed Member
Joined: 5 years ago

ok, so in previous (related) topic you said you found the IP and you asked how to block. I suggested to use IP block from Cpanel. That didn't work?

Also you say you use NO security plugin. Since you have already a heavy loaded site, i suggest you use this very lighweight plugin

https://wordpress.org/plugins/ninjafirewall/

or at least try it. This plugin doesn't connect to ANY cloud to check and everything happens in YOUR server, so it is fast.

After installing be sure you enable full waf mode, that prepends "the check for security" before reaching Wordpress (at .htaccess). Also be sure you enable login protection for bots.

 

2 Replies
(@percysgrowroom)
Joined: 6 years ago

Noble Member
Posts: 1212

@dimalifragis yes mate it worked, but this is a different user and I cant find any details about the address

 

dimalifragis
(@dimalifragis)
Joined: 5 years ago

Famed Member
Posts: 2611
Posted by: @percysgrowroom

@dimalifragis yes mate it worked, but this is a different user and I cant find any details about the address

 

That is why it is better to proactively protect before the register/login.

 

Page 1 / 2