Anyone seen an uptick in WordPress comment spam May 2015?

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

Patrick

Administrator
Staff member
Dec 21, 2010
12,514
5,807
113
I would imagine if this hit a site on shared hosting it would bring the site town. Is there a new network creating this spam? These are only successful spam requests. Akismet Pro does a good job clearing them but it is basically 1 per second at this point.

STH WP Comment SPAM 2009-2015-05-12.JPG

Yikes!
 

T_Minus

Build. Break. Fix. Repeat
Feb 15, 2015
7,641
2,058
113
You got picked up on a list or someone let their bot go stupid. That's an absurd amount in 1 day.

I see 400,000 spam comments every month on a # of sites, but not 800,000 in 1 day. I'm talking about sites more popular than this one too, so that's def something to keep an eye on.

I didn't notice any uptick.

However, GOogle did an update over the weekend that could have penalized others so you may be ranking for new/more terms or higher up and thus some spammer bots picked you up from your footprint. (This is why it's best to remove all WP footprints as possible, same with any platform IMHO.)
 

neo

Well-Known Member
Mar 18, 2015
672
363
63
Is it only on WordPress or the forums too? There has been a plethora of WordPress vulnerabilities discovered lately - I imagine there are bots surveying specifically for said exploits. Can you check your logs for the countries of origin, are the majority from China? Similarly, IP wise is it from a distinct block of specific IPs? I do InfoSec, PM me for further assistance if you wish.
 
  • Like
Reactions: Patrick

Patrick

Administrator
Staff member
Dec 21, 2010
12,514
5,807
113
Is it only on WordPress or the forums too? There has been a plethora of WordPress vulnerabilities discovered lately - I imagine there are bots surveying specifically for said exploits. Can you check your logs for the countries of origin, are the majority from China? Similarly, IP wise is it from a distinct block of specific IPs? I do InfoSec, PM me for further assistance if you wish.
Seems to be a pretty random scattering of addresses. From the usual sources. I may take you up on help one of these days.
 

T_Minus

Build. Break. Fix. Repeat
Feb 15, 2015
7,641
2,058
113
I guess I should say we block all the country IPs with MaxMind we don't want traffic from / bad countries. Russia, China, India, Pakistan, and a couple smaller ones. I expected my load on server to INCREASE due to the checks for EVERY HIT... my load dropped 10-15% to give you an idea how bad they were spamming :( ~dozen sites.

In the end happy with the results.