michelem09 / wassup

WassUp Real Time Analytics for WordPress
https://www.wpwp.org
4 stars 4 forks source link

FP hack/malware attempt in WassUp v1.9.4.5-RC #12

Open LuboTomov opened 4 years ago

LuboTomov commented 4 years ago

Hi, There is a lot of false positives in WassUp v1.9.4.5-RC from Google Search

Raw Info: `Необработени данни: Тип посещение: Спамер/Хакер

IP:XX.XX.XXX.XX
Име на хоста:gw.kkelectronics.com
Изискан URL:/%D0%BA%D0%B0%D0%BA-%D0%BF%D1%80%D0%B0%D0%B2%D0%B8%D0%BC-%D0%B8%D0%B7%D0%B1%D0%BE%D1%80/
Post/page ID:0
Отпратка:https://www.google.com/
Търсачка:Google
Търсене:_notprovided_
Страница:1
Потребителски агент:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36
Браузър:Google Chrome
ОС:Win10
Езикови настройки/Език:us
Разделителна способност:1920 x 1080
Спам:3  (hack/malware attempt)
Wassup ID:0b_e349557337514888ac28227e4679e75d
Краен времеви маркер:2020-01-20 15:14:52 ( 1579533292 )

2 URLs visited in session`

Screenshot: https://imgur.com/SowCRtw

WordPress 4.9.13 PHP Version: 7.0.30 My site is on cyrillic.

Thanks.

hdunk commented 4 years ago

Thanks for reporting this!! I will work on a fix ASAP.

LuboTomov commented 4 years ago

Hi again, As I see, these FP comes from /wp-admin/admin-ajax.php requests. When I add /wp-admin/admin-ajax.php to Exclude by URL request, FP gone. There is no such a problem with earlier versions on WassUp. I am using WassUp ver: 1.9.4.5 Official now.

Regards.