• Resolved igwebs

    (@igwebs)


    Someone is publishing posts on my blog as “admin”. They have been doing this for a while now and I have been deleting the posts as they are garbage but I like to put a stop to it. So far, I have not been able to figure out how they’re doing it. Has anyone else run into something like this or know how this could be done? Here’s a link to the blog and the posts’ title is always “what did I do on xx/xx/xx” http://www.sowhatdidyouthink.net/swdidytblog . If you don’t see one now give it a little time and you will.
    Thanks in advance for your help.

Viewing 12 replies - 1 through 12 (of 12 total)
  • Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    🏳️‍🌈 Advisor and Activist

    Thread Starter igwebs

    (@igwebs)

    Thank you. That was very helpful. He was coming through Twitter Tools plugin and I cleared him out on the settings page.

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    🏳️‍🌈 Advisor and Activist

    Eeek! THIS Twitter Tools!?

    http://ww.wp.xz.cn/extend/plugins/twitter-tools/

    How did that happen?

    Thread Starter igwebs

    (@igwebs)

    No sure. He was using it and bit.ly, not sure how he got in but I changed the Authentication Unique Keys along with the password and anything else I could change. So far that seems to have stopped him. He was just using the site to create back links.

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    🏳️‍🌈 Advisor and Activist

    Twitter password too, I hope.

    Ugh. I wonder if it’s related to Twitter’s recent changes.

    Thread Starter igwebs

    (@igwebs)

    No, I don’t think so. His links used bit.ly but didn’t do them right so the link goes to a 404 page. But it did post to my blog which bugged me a lot!

    alexkingorg

    (@alexkingorg)

    Please be very careful with statements like this:

    He was coming through Twitter Tools plugin

    From your description this sounds incorrect, and it is potentially damaging and unnecessary FUD.

    Thread Starter igwebs

    (@igwebs)

    OK, how would you say it?

    Moderator Ipstenu (Mika Epstein)

    (@ipstenu)

    🏳️‍🌈 Advisor and Activist

    Alex’s point was why I was (a) hella shocked and (b) wondering how the guy got in.

    The guy got in via twitter (Twitter Tools only pulls in from YOUR twitter stream, right?)

    I cleared him out on the settings page.

    Can you elaborate what you mean here.

    Thread Starter igwebs

    (@igwebs)

    Ok, I’ll try and remember. On the Twitter Tools setting page, the experimental section was filled in with his stuff. Then on the bit.ly section he had “admin” for a user name. I believe that is all that was there that I had not put in. I hope that helps.

    alexkingorg

    (@alexkingorg)

    Based on the information you have provided, it sounds most likely this person had/has access to your WordPress admin.

    Thread Starter igwebs

    (@igwebs)

    That’s possible. Anything is possible!

Viewing 12 replies - 1 through 12 (of 12 total)

The topic ‘Security question’ is closed to new replies.