• I’m using WordPress 2.02. I’ve been getting comment SPAM, so I put in tons of restrictions on my commenting, and none have any effect. Finally, I got frustrated and *deleted* wp-comments-post.php from my site. I’m STILL getting comment SPAM!

    How is this possible without a page to POST to? Is there a security hole in WP?

Viewing 5 replies - 1 through 5 (of 5 total)
  • Not interested in waxing analytics, but if you want to stop it I suggest installing Bad Behavior and Akismet.

    Thread Starter geoff34

    (@geoff34)

    Why would I need to? If I delete the file that POSTS comments to the database, that should be the ultimate in security. Since SPAMmers are posting comments to my WP install when the POST handler is deleted, it must mean there’s a security hole in WP. Is there some other post handler in WP?

    Do you want to get rid of spam or do you want an endless arguing? It has been stated many times (just search and read, please, if possible, before posting…) – those are not comments but trackbacks.
    Security hole and spamming “hole” are not the same.
    Recommended thread: https://www.ads-software.com/support/topic/72930

    Thread Starter geoff34

    (@geoff34)

    I’m not arguing… at least I don’t think I am.

    So, if it’s a trackback, it really shouldn’t say it’s a comment in admin and in the e-mails it sends. I guess it’s just a usability issue, then.

    Thanks!

    geoff34, wp treats trackbacks as comments, even though another file handles them.

    Since you are into deleting, delete wp-trackback and see if that helps.

    You should not have to install an antispam plugin.

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Deleted wp-comments-post.php and still receive comment SPAM’ is closed to new replies.