Title: possible hack?
Last modified: August 18, 2016

---

# possible hack?

 *  spyder
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/)
 * possible hack?

Viewing 8 replies - 1 through 8 (of 8 total)

 *  Thread Starter Anonymous
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-103880)
 * it’s kind of strange.. I got home from work today, and noticed someone posted
   a comment on 1 of my posts… on a freshly installed blog no one knows about… ..
   only 1 comment..
    but if i load up the comments table in mysql.. it shows 31 
   comments posted… all along the same lines…
 *  Thread Starter Anonymous
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-103881)
 * eg.
    1) Name: online poker | E-mail: [lilo@suddenenlightenment.us](https://wordpress.org/support/topic/possible-hack/lilo@suddenenlightenment.us?output_format=md)
   | URI: [http://www.I’m_a_stupid_spammer.com](http://www.I&apos;m_a_stupid_spammer.com)
   | IP: 62.39.107.121 God not only plays dice. He also sometimes throws the dice
   where they cannot be seen. by online poker Posted Oct 26, 3:22 PM 2) Name: free
   online poker | E-mail: [lilo@suddenenlightenment.us](https://wordpress.org/support/topic/possible-hack/lilo@suddenenlightenment.us?output_format=md)
   | URI: [http://www.I’m_a_stupid_spammer.com](http://www.I&apos;m_a_stupid_spammer.com)
   IP: 203.113.29.3 Ã¢ï¿½ï¿½A cucumber is bitter.Ã¢ï¿½ï¿½ Throw it away. Ã¢ï¿½ï¿
   ½There are briars in the road.Ã¢ï¿½ï¿½ Turn aside from them. This is enough. 
   Do not add, Ã¢ï¿½ï¿½And why were such things made in the world?Ã¢ï¿½ï¿½ by free
   online poker Posted Oct 26, 3:22 PM 3) Name: online poker | E-mail: [lilo@suddenenlightenment.us](https://wordpress.org/support/topic/possible-hack/lilo@suddenenlightenment.us?output_format=md)
   | URI: [http://www.I’m_a_stupid_spammer.com](http://www.I&apos;m_a_stupid_spammer.com)
   | IP: 62.183.198.60 A common mistake that people make when trying to design something
   completely foolproof is to underestimate the ingenuity of complete fools. by 
   online poker Posted Oct 26, 3:21 PM in total they spent about 30 minutes adding
   comments… but yet.. there is only the 1 visable from my main page.. [Moderated–
   URL’s removed]
 *  Thread Starter Anonymous
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-103882)
 * btw… i am running cvs “1.3-alpha-4”
 *  Thread Starter Anonymous
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-103887)
 * here are the apache logs… doesn’t show too much, nothing weird or strange.. just
   those ips accesing the page.
    ` [root@x log]# grep -i "216.17.211.9" httpd/access.
   log 216.17.211.9 - - [26/Oct/2004:14:44:22 -0400] "POST /wp-comments-post.php
   HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
   216.17.211.9 - - [26/Oct/2004:14:44:23 -0400] "GET /index.php?p=1 HTTP/1.1" 200
   3962 "-" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 216.17.211.9--[
   26/Oct/2004:15:18:43 -0400] "POST /wp-comments-post.php HTTP/1.1" 302 - "-" "
   Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 216.17.211.9 - -[
   26/Oct/2004:15:18:44 -0400] "GET /index.php?p=25 HTTP/1.1" 200 3962 "-" "Mozilla/
   4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" [root@x log]# grep -i "62.39.107.121"
   httpd/access.log 62.39.107.121 - - [26/Oct/2004:15:22:32 -0400] "POST /wp-comments-
   post.php HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; 
   Win 9x 4.90)" 62.39.107.121 - - [26/Oct/2004:15:22:36 -0400] "GET /index.php?
   p=31 HTTP/1.1" 200 3962 "-" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win
   9x 4.90)" [root@x log]# grep -i "203.113.29.3" httpd/access.log 203.113.29.3 --[
   26/Oct/2004:15:22:00 -0400] "POST /wp-comments-post.php HTTP/1.1" 302 - "-" "
   Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 203.113.29.3 - -[
   26/Oct/2004:15:22:01 -0400] "GET /index.php?p=30 HTTP/1.1" 200 3962 "-" "Mozilla/
   4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 203.113.29.3 - - [26/Oct/
   2004:15:22:02 -0400] "GET /print.css HTTP/1.1" 404 280 "http://www.x.org/index.
   php?p=30" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 203.113.29.3--[
   26/Oct/2004:15:22:02 -0400] "GET /wp-atom.php HTTP/1.1" 200 1098 "http://www.
   x.org/index.php?p=30" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 
   4.90)" 203.113.29.3 - - [26/Oct/2004:15:22:02 -0400] "GET /wp-rss2.php HTTP/1.1"
   200 1102 "http://www.x.org/index.php?p=30" "Mozilla/4.0 (compatible; MSIE 5.5;
   Windows 98; Win 9x 4.90)" 203.113.29.3 - - [26/Oct/2004:15:22:02 -0400] "GET /
   wp-rss.php HTTP/1.1" 200 632 "http://www.x.org/index.php?p=30" "Mozilla/4.0 (
   compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 203.113.29.3 - - [26/Oct/2004:
   15:22:03 -0400] "GET /?m=200410 HTTP/1.1" 200 7734 "http://www.x.org/index.php?
   p=30" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 203.113.29.3--[
   26/Oct/2004:15:22:03 -0400] "GET /xmlrpc.php HTTP/1.1" 200 42 "http://www.x.org/
   index.php?p=30" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
 *  [TechGnome](https://wordpress.org/support/users/techgnome/)
 * (@techgnome)
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-103890)
 * He’s been hitting a lot of WP blogs lately. Somehow this guy wrote a script that
   hits the target blog with a bunch of comments to posts that don’t exist yet……
   
   I swear….. if we catch this guy…… grrrr…. TG
 *  [Brak](https://wordpress.org/support/users/brak/)
 * (@brak)
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-103899)
 * It spams wp-comments.php with random post ID’s, so it’s completely random on 
   which posts it appears. You can rename wp-comments.php to solve the problem, 
   or blacklist him 🙂
 *  Thread Starter Anonymous
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-103939)
 * cool, thanks for the inputs guys!
 *  [Beel](https://wordpress.org/support/users/beel/)
 * (@beel)
 * [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-104119)
 * Lookie, lookie, I cursed! Looks like a bit of a misdirect of my own minor frustration
   with comment spamming (though I hope the point is not missed on future posters).
   Dang, now I’ll have to wash my hands with soap.

Viewing 8 replies - 1 through 8 (of 8 total)

The topic ‘possible hack?’ is closed to new replies.

 * In: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
 * 8 replies
 * 4 participants
 * Last reply from: [Beel](https://wordpress.org/support/users/beel/)
 * Last activity: [21 years, 7 months ago](https://wordpress.org/support/topic/possible-hack/#post-104119)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
