• I’m using the latest version of WP and BP and according to WangGuard it has blocked hundreds of accounts through wrong answers to the security questions. However my site has been flooded with dozens of new spam accounts, far more than there are right answers. Is this a known bug? Thanks.

    https://www.ads-software.com/plugins/wangguard/

Viewing 12 replies - 1 through 12 (of 12 total)
  • Plugin Author Jose Conti

    (@jconti)

    Hi @skyrie,

    No, there is not a known bug. I will test it on my DEV sites.

    Can you tell me your website please?

    Thank you

    I have the same problem. I have installed Wangguard, and have set an impossible sercurity question, but still getting registrations. How can this be? https://www.miningsoftware.org?

    Plugin Author Jose Conti

    (@jconti)

    Hi,

    I tried to register and i’m blocked.

    Your sploggers come from a Chinese Farm, Which are the security questions statistics? (human signups)

    Kind regards

    Plugin Author Jose Conti

    (@jconti)

    Hi,

    I think a found the problem, and I’m working in a fix.

    I think the problem is the plugins load order, but I haven’t this problem so I need that you contact with me for test a version with a fix.

    https://www.wanggaurd.com/contact

    Thank you

    Was getting heaps of spam regos. 20 per hour. Read somewhere that the bot target Registration page and need to rename that page. So I renamed the Register Page to Signup. Spam regos immediately stopped. However new problem. The menu page: Register did not update, so I deleted the Menu item, and added the new Signup page. Now when I log in, the Register Menu item is still displayed, whereas it should be hidden same as log in page.
    Should I have used a plugin to rename the Register page? I couldn’t find one to do that?

    Plugin Author Jose Conti

    (@jconti)

    That not work, really.

    Wait few days, and the bots will arrive again. They use Google, so when Google update your website, the bots will be there again.

    BuddyPress has the registration page /register/ and you have translated this slug to 35 languages + random names. All has slog. But you can try if it work for you.

    I don’t know a plugin that change the signup name page.

    Thread Starter Skyrie

    (@skyrie)

    @j.conti Sorry I didn’t get back to you! Did you find the solution?

    Jose, Are you saying that the bots sidestep the spam blockers (Wangguard) and there is nothing can be done about that?
    So it seems the WordPress setting that allows any user to register is going to open me to a ton of spam. I am even wondering if I turn that setting off, will I still get hit, and is it not really feasible to use Buddypress in the way that I hoped I could.

    Plugin Author Jose Conti

    (@jconti)

    Hi @skyrie,

    I don’t know. Can you install RC2 and try if the security questions are show?

    I made some modifications in the plugin for load many things after BuddyPress, but maybe a forgot something.

    Plugin Author Jose Conti

    (@jconti)

    Hi @amhampton

    No, first we need that security questions work, did you updated to RC2? Is it works?

    Yes? Add some questions, but not math questions, many bots know math.

    No? I will look again for the problem.

    Plugin Author Jose Conti

    (@jconti)

    Ups, I don’t remember that you have an impossible question and the bots are registering.

    Do you use another plugin for signups? Like a membership or something similar.

    When I tried to register in your website, I was allways blocked for the security question, so maybe you have a bug hole… and the Sploggers are using it.

    Think a thing, when you activated the security questions, many bots were registered, but their accounts were not active, so maybe, that Sploggers were registered before security questions.

    I’m having a similar problem – I’m using plain wordpress, with WordPress Access Control and New User Approve. I set 3 security questions, and on the configuration page there have been no correct answers since the one I answered myself to test. However, I am still getting many user registrations per day, so they must be bypassing WangGuard somehow. If I go on and manually try to create an account it prevents me, so the security question is working in some ways, but I assume there must be another way in.
    My wp instance is at https://www.greenwich-academy.com

    Thanks,
    James

Viewing 12 replies - 1 through 12 (of 12 total)
  • The topic ‘Security Questions do not Work’ is closed to new replies.