In the past month or so I've seen 3 or 4 new users signing up each day with "awkward" usernames (letters/numbers). Then, a few days later, they start changing their password. And then a few days later they delete the account.
I suspect some kind of hack in progress so I use WordFence on the site; I made sure new users have to use a 'strong' password when they sign up (and a captcha); users can only change their password once.
But I'm wondering still if something is going on. Should I be doing more or am I paranoid?
In the past month or so I've seen 3 or 4 new users signing up each day with "awkward" usernames (letters/numbers). Then, a few days later, they start changing their password. And then a few days later they delete the account.
I suspect some kind of hack in progress so I use WordFence on the site; I made sure new users have to use a 'strong' password when they sign up (and a captcha); users can only change their password once.
But I'm wondering still if something is going on. Should I be doing more or am I paranoid?
My process for cleaning a hacked site includes
There is guidance all over the googles about cleaning hackedsites. And I wrote up a procedure that I use here: https://securitydawg/recovering-from-a-hacked-wordpress-site/
It can be done, just takes a bit of work.
media
folder and so, these files can be used to run remote commands on your server and so on. If your site is already compromised then it is too late to start using a third party plugin likeWordFence
. – Cyclonecode Commented Nov 17, 2018 at 13:01