• Resolved scotten

    (@scotten)


    I have recently got plenty of hacker attempts, trying to login in using “admin” (which is removed) and in the email it says an IP-nbr and a User hostname vps.agenciaspin.com

    BUT – when I tried to login in myself, with an old and now removed user – it says the following i.e. – it reports the SAME User hostname:

    How does that work? (It feels like WordFnece is rtaking tha last User hostnamen that has been reported to me – not the correct User hostnamen that my IP belongs to.

    User IP: 81.232.69.81
    User hostname: vps.agenciaspin.com
    User location: Bromma, Sweden

    https://www.ads-software.com/plugins/wordfence/

Viewing 3 replies - 16 through 18 (of 18 total)
  • Thread Starter scotten

    (@scotten)

    Hi Mark, thanks for your reply. As you mention that the vulnerability was discovered by you and you even call it “vulnerability” as if it was not a real vulnerability – does that mean that this software is kind of fake or if you don′t want to give that answer – will not be needed if you already use WordFence. As I have had several strange problems with WF – I finally – after googling around bought and installed WP Site Guardian.

    I have had plenty of unauthorized logins attempts (according to WF) but I am not sure if these have bee real attempt′s as the behavior has been very strange and incorrect. I have now reinstalled WF following the instructions I got from Matt – and it seems that it is much more “calm” now – just a few attempts.

    But IF all these (50 each day) has been real attempts – and on that particular site – there was also comment fields open(not on my other sites) – the why have not ANYBODY tried this other vulnerability?

    As I dont like to be “fucked up” to buy software that I don′t need and that is kind of fake – I need some more guidance from you .- and then I will go back to the salesman of WP Guardian and claim the purchase – as they seems to have given incorrect information (they sad that non (including WordFence) did not take care of this “exploit vulnerability”
    (Sorry for my “bad” english

    PeA

    Plugin Author Wordfence Security

    (@mmaunder)

    @scotten Why don’t you drop us an email at [email protected] and one of our guys (Probably Matt R) will give you some personal assistance with whatever you need.

    Hopefully we can help secure your site and get you back to focusing on your business.

    Regards,

    Mark.

    Thread Starter scotten

    (@scotten)

    OK – I will do that. I will just first check what is happening now – I dont have as much attempts now after the reinstallation and deleting of the database – but there are still some.

    If I feel it seems to work now I am satisfied, If I still feels there is something straneg going one – I will email genbiz@

    PeA

Viewing 3 replies - 16 through 18 (of 18 total)
  • The topic ‘Reports same User hostname for MYSELF as for hackers’ is closed to new replies.