# Compromised Forum Admin

**URL:** https://meta.discourse.org/t/compromised-forum-admin/266954
**Category:** Support
**Created:** [June 1, 2023, 8:35pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954 "2023-06-01T20:35:13Z")
**Posts on this page:** 10
**Page:** 3

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [June 4, 2023, 1:35pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/43 "2023-06-04T13:35:10Z")

</div>

And my Fail2ban agrees. Script kiddies and badly behaving adults are different story IF they are using static IP. That isn’t situation too often when used mobiles for example. And you know very well the most used system to hide IP 😉

---

<div class="post-metadata">

### Author: ![Lilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lilly/32/575047_2.png) [@Lilly](https://meta.discourse.org/u/Lilly)
#### Post date: [June 4, 2023, 1:41pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/44 "2023-06-04T13:41:59Z")

</div>

i don’t disagree generally, but of course FailtoBan helps. but there’s certainly no reason not to block his IP and every reason to do so.

---

<div class="post-metadata">

### Author: ![Lilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lilly/32/575047_2.png) [@Lilly](https://meta.discourse.org/u/Lilly)
#### Post date: [June 4, 2023, 1:45pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/45 "2023-06-04T13:45:25Z")

</div>

have you seen this yet?

> [@What to do if your Discourse is compromised](https://meta.discourse.org/t/what-to-do-if-your-discourse-is-compromised/40129):
>
> We’ve recently had two reports of Discourse sites that were compromised, likely due to weak admin account passwords. So we’d like to document: what to do when compromise happens what we can do to better prevent this in the future The Database Please note that Discourse, for several years now, has the following protections in place around the site database: Full database backup download links will only be sent via valid email of a site administrator, so you can’t just log in (via shoulder …

---

<div class="post-metadata">

### Author: ![ondrej](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ondrej/32/198804_2.png) [@ondrej](https://meta.discourse.org/u/ondrej)
#### Post date: [June 4, 2023, 3:37pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/46 "2023-06-04T15:37:58Z")

</div>

Definitely best they are off the site. As you said they can always create new accounts etc. Although is that suspension reason something you want to ‘advertise’ to new users who wouldn’t know about this rogue admin? If you get what I’m saying?

@Stephen I agreee haha definitely 🚫 for that username 🤣

---

<div class="post-metadata">

### Author: ![Jagster](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jagster/32/192154_2.png) [@Jagster](https://meta.discourse.org/u/Jagster)
#### Post date: [June 4, 2023, 4:07pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/47 "2023-06-04T16:07:24Z")

</div>

Most of ISPs recycles IP-addresses. When that bad apple changes his/hers IP next one gets it. Hopefully that customer doesn’t work with Discourse then 😉

Most of the world doesn’t use unchange static IPs.

---

<div class="post-metadata">

### Author: ![Lilly](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lilly/32/575047_2.png) [@Lilly](https://meta.discourse.org/u/Lilly)
#### Post date: [June 4, 2023, 5:24pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/48 "2023-06-04T17:24:11Z")

</div>

did you review new accounts for suspicious activity? i would be looking closely at all new accounts created recently. if you haven’t already, review activity of any users associated with his account and the impersonated ones.

---

<div class="post-metadata">

### Author: ![codergautam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codergautam/32/261083_2.png) [@codergautam](https://meta.discourse.org/u/codergautam)
#### Post date: [June 5, 2023, 1:58am UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/49 "2023-06-05T01:58:31Z")

</div>

there has been an increase in spammers after the ban, and yes we have been looking at new users and especially their emails, we noticed that most of the spammers use weird custom email domains.

---

<div class="post-metadata">

### Author: ![MikeNolan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mikenolan/32/297597_2.png) [@MikeNolan](https://meta.discourse.org/u/MikeNolan)
#### Post date: [June 5, 2023, 4:41am UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/50 "2023-06-05T04:41:19Z")

</div>

> [@codergautam](#):
>
> we noticed that most of the spammers use weird custom email domains.

Well, THAT part doesn’t sound so unusual, I’ve noticed on other platforms (not Discourse yet) that spammers come in waves of similarity, sometimes the IP addresses are similar, sometimes the email addresses are similar, etc. I think it has to do with spammer dark web sites (wow, that sounds like a cliche) that offer suggestions if not cookbooks about what works on certain sites, or what bypasses the latest spam filters, etc.

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [June 5, 2023, 12:33pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/52 "2023-06-05T12:33:23Z")

</div>

> [@codergautam](#):
>
> I really don’t want to reset everyone’s password, as that will just cause confusion for them if they ever choose to re-log in.

Yes, it may cause confusion, and some even may not have access to their email if they registered a long time ago (especially in the case of a forum that was migrated from another platform).

But if their password isn’t changed, I think it’s fair to consider them as compromised (even if it’s _potentially_).

---

<div class="post-metadata">

### Author: ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)
#### Post date: [July 5, 2023, 12:33pm UTC](https://meta.discourse.org/t/compromised-forum-admin/266954/54 "2023-07-05T12:33:39Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.

[Previous page](https://meta.discourse.org/t/compromised-forum-admin/266954.md?page=2)
