By david on Sunday, 12 April 2015
Posted in Technical Issues
Replies 5
Likes 0
Views 0.9K
Votes 0
Hi guys, my blog is being targeted with new posts in foreign languages appearing twice now in two days.

My website/ blog has undergone numerous changes in the past two weeks, these include:
- upgrade from Joomla 2.5.28 -> Joomla 3.4.1 (I upgraded Easy Blog to latest version here too)
- Upgrade of template from artisteer template to purchased template from Themeforest.
- Finally I updated my blog theme although I doubt this is to blame.

I notice the new blog posts, created by new bloggers (I never added them...) and then simply remove both, however this however does not fix the underlying issue.
If it helps, the intruders create new blogger accounts and posts however the rest of the website including my Joomla users are not affected in the least, which makes me think it is specific to the Easy Blog component.

My website address and blog are @ http://www.myebook.co.za

I would really appreciate your advice, i have looked through backend settings but cannot find anything obvious.

Warm Regards
David
Hello David,

Firstly, your blog isn't being hacked and I have edited the title to avoid any misleading information. Your site is practically being targetted by spammers and this really isn't a loop hole in EasyBlog but rather just your ACL setup.

I have dug through the site and noticed that the user "Ipasud" , registered on your site using Joomla's registration tool. He managed to post a blog post because his account is associated with the group "Registered" and since the ACL in EasyBlog allows users to publish blog posts, this is why he was able to post and publish them.

Do take note that even if you ban the user, they don't get logged out automatically. You need to delete these spammers through Joomla's user manager.

I have re-configured your ACL in EasyBlog and also deleted both the spammer and the spammy blog post now. If it ever happens again (which I believe they shouldn't be able to any longer) , let me know
·
Sunday, 12 April 2015 22:21
·
0 Likes
·
0 Votes
·
0 Comments
·
David,

I'm unsure of few certain things, the two blog post wasn't created by your account?
If yes, I already checked with your Easyblog ACL setting, it seems like everything is set correctly.

Can you try changing your password for this David account temporary and see whether does this happening still persists?
·
Sunday, 12 April 2015 14:52
·
0 Likes
·
0 Votes
·
0 Comments
·
Hi Arlex, a few hours after your email another post was created, I am now growing more concerned.
My account is not compromised, it seems to switch authors to me after I delete the fake accounts.
Have a look at the screen shot showing the next article written by someone or something else.

Please can I have some help soon, I am worried it will begin irritating my loyal blog visitors!

Regards
David
·
Sunday, 12 April 2015 21:46
·
0 Likes
·
0 Votes
·
0 Comments
·
Thanks Mark
·
Sunday, 12 April 2015 22:33
·
0 Likes
·
0 Votes
·
0 Comments
·
You are most welcome David
·
Sunday, 12 April 2015 22:59
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post