Someone tried to hack my blog – can WordPress identify them?
-
Hi,
I get email and text messages asking if I wanted to reset my password. Someone was obviously trying to hack my account. Is there any way to research who did that?
Thanks!
The blog I need help with is: (visible only to logged in users)
-
I see no indication of your blog at http://1eternitymatters.wordpress.com/ being hacked.
re: hacked accounts and blogs
If anyone is posting anything to your blog or removing anything from it, or changing anything in it, or if your blog has been deleted and you did not delete it, then it’s most likely that you have provided them with the ability to do so, either deliberately by adding them as official users, or by allowing them access to your login information, or by posting content that makes it easy for them to guess what your log-in information is.
For you the question that needs to be answered is: Who, aside from me, has access to my login information?
If you registered this blog:
Go to your email program immediately and change the password to a very difficult one because that’s how many hackers gain access to blogs. Read > http://en.support.wordpress.com/security/
1. If you can log-in go here > Users > All Users and delete any user that does not belong there.
2. Disable post by email > http://en.support.wordpress.com/post-by-email/
3. Disable post by voice > http://en.support.wordpress.com/post-by-voice/
4. Change your blog password to a very difficult one > http://en.support.wordpress.com/passwords/#change-your-password
You can also reset your password via your Settings tab on the WordPress.com home page:
http://wordpress.com/#!/settings/5. Use a secure, encrypted connection to connect to your Dashboard. Under Users → Personal Settings, check the box that says “Always use HTTPS when visiting administration pages, and click Save Changes.
6. Use two step authentication http://en.support.wordpress.com/security/two-step-authentication/
7. Run a security scan on your computer.
8. Never leave your computer logged into your blogs and walk away from it. Always log out properly.
P.S. Staff have records of who did what under which username and login information and when they did it. I flagged this thread for a Staff follow-up. Please subscribe to it so you are notified when they respond. To subscribe look in the sidebar of this thread, find the subscribe to topics link and click it. Note that there is a backlog and be patient while waiting.
-
Not really, no. All it means was that someone typed your email address into the Lost Password form. They might have had a similar email address and made a typo, or they might have guessed your address if it happens to be easily guessable.
It didn’t succeed – that’s why we send the confirmation message. There is very little information available to identify the source of the attempt, and you’ll need a court order or similar legal document to request it. It probably wouldn’t tell you anything useful. It’s not unusual to see random reset attempts.
Use two-step auth if you’re concerned. There’s no indication that anything has been compromised.
-
- The topic ‘Someone tried to hack my blog – can WordPress identify them?’ is closed to new replies.