• Hi,

    I’ve been a WP user for about 4 years and have not had any problems… Always kept versions and plugins set to auto-update. Except that ONE forgotten site, and bam 20,000 pages… yes that’s 20K pages uploaded to my site and the site completely re-written (in a very very professionally coded manner)so as to be hidden from public viewing that provided SEO and linking to a ton of Hindi shopping sites and bookmarks to where one can find hacked games and other stuff.

    AND… AND… To add insult to injury, the hacker deleted my backup directory and put a hacked version of the site in there so that when I restored from this “backup” I restored a site with a backdoor in it and got hacked again! Gotta give respect where’s due… Touche.

    So now, on another of our sites, I am having some technical difficulties and the support again (from India) has asked me create and admin user on WP so he can connect and figure out what the problem is.

    I used to do this all the time with GoDaddy, a theme author, or coder contractor… But as stated now, once bitten, twice shy. Is there any harm to give a support agent access to a site and to delete their username after the support session is over?

    What an open-ended question… But, I’m asking it for some feedback.

Viewing 4 replies - 1 through 4 (of 4 total)
  • If you need a help with the site, this is the only way to give an admin access. Just wisely choose to who you will give it.

    Do you trust the company with the support agent?

    I use a Polish theme company and from their performance in the past I trust them completely. I also trusted GoDaddy, but their level of quality varied agent to agent. The next Hosting company I had I fired because their support was inept most of the time.

    You said the first problem was caused from not Auto-updating which makes it sound like you had vulnerabilities that were being exploited, not from giving someone Admin to your site.

    Depending on your answer to my first question, I would say that if they are willing to take the time to log in and try to fix it instead of giving me the tech brush off I would probably take the chance.

    BTW I had a site I let get that way when I was a WP newb. My tech guy at the time said we should just take it down and start over. Taught me that lesson well!

    Hope this helps a little

    Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    A safer way, but more time consuming, would be to hire someone to teach you how to fix the issue.

    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    So now, on another of our sites, I am having some technical difficulties and the support again (from India) has asked me create and admin user on WP so he can connect and figure out what the problem is.

    If you have a paid support relationship with that company or you’ve paid that person to provide support then that is up to you.

    That level of support may be included in what you are paying for. Though for being hacked you may want to consider https://sucuri.net/ as they’re very reputable and well established in the community.

    If that came from someone you do not have that relationship then flat out NO. Don’t do it.

    That’s the online equivalent of you mailing them the keys to your house with your schedule telling them when you are out of the house. Also writen on the box in big letters “Keys to my house at 123 Main Street”. Yes, it’s that serious.

    *Looks to drink coffee*

    If you received that contact via these forums then please let me know from who via the #forums Slack channel. Don’t post their forum ID here.

    Slack

    Or if you prefer to do so privately in the Make WordPress Slack then my user ID there is jan_dembowski and you can DM me there.

    The reason is this: no one should be contacting anyone from these forums and requesting admin or file access. If someone is doing that then a short and possibly terse conversation needs to happen with them. That’s just not allowed and whole companies have been banned from here for doing that.

    https://codex.www.ads-software.com/Forum_Welcome#The_Bad_Stuff

    It’s unclear to me if that’s the case here but I just wanted to be safe and cover that base too.

Viewing 4 replies - 1 through 4 (of 4 total)
  • The topic ‘Once bitten, twice shy – Giving a tech support agent access to WP’ is closed to new replies.