Abuse of contact form on WordPress.

aimeeandbeatles

watermelon
Joined
Apr 5, 2007
Messages
20,112
OK, some of you probably know about what happened the past few days ... certain users of my site, using proxies (I looked up the IP addresses and it pointed to a proxy), have been sending abusive messages through the contact form (I use Fast Secure Contact Form). So anyways blocking the IP doesnt work 'cos of the proxy thing. They're also putting in fake addresses and stuff.

The first ones were that fake lawyer emails but then it started getting really bad, stuff that I would get infracted for if I posted here (and not because of Petty, either).

Does anyone have any suggestions? Blacklisting IPs or emails doesn't work because they use proxies and fake emails. I'm wondering if a challenge-response thing (not sure about right term) would work -- the thing is, I noticed Yahoo tends to bounce my autoresponse so I dont want to keep legit users from contacting me....

Of course, any recommendations need to work within WordPress and hopefully with a minimum of fuss.

Its gotten to the point where Im scared to check my email in case theres another one. Almost enough to drive me to tears and I'm not one to cry too easy.
 
It sounds like you need to go to the police or report it to your/their ISP. There must be some organisation in Canada where you can report people for internet harassment and/or stalking?
 
Yeah, but they're behind a proxy so I don't think it would work too well.

I really would just ignore it and just delete it, but they're now using legit-looking subjects so I think it may be a legit email. I don't want to miss any legit emails.

For now I've done something strange. I turned the form into a screenshot of the form. The alt text is "Look for a small black dot." When you find it and click it (I hope this troll can't be bothered) it's an email link. Hope he doesn't know about email spoofing.
 
Well the troll already knows your email so I don't see how any of that would help.

Let the harassment organisations decide whether they can help you.
 
My email was hidden behind the form, actually.
 
Though I actually just put the form back for 2 reasons:
a) spambots
b) in case this troll gets it into their head to attach a virus or something
 
It's not hosted on wordpress.com. It's a WordPress site hosted on my own hosting (see my signature). I asked the host about it but other than blocking the IP address (doesn't work because of the proxy) theres really not much.
 
I'd suggest disabling the "send" button, with a note explaining that your contact form is being abused by a jackass - you won't miss any legit emails because you won't get any, but wait a week or two and then re-enable it.
 
Well I was unable to disable the button (it's a shortcode) but I commented it out and put up a notice instead saying it has been temporarily taken down. Go to my site and About > Contact. Might get a laugh :)
 
Now, for contacting the law enforcement, heres what I put together:

a) the emails themselves. (Since they're coming through a contact form, they're coming through the squareserve.org servers and thus a full header wouldn't be very useful)
b) my website logs
c) WHOIS records of the IP addresses

Anything else you would include?
 
Are you sure these aren't bots? If so you could set up a captcha

Well, they all came from the same few IP address. And there was a captcha.
 
Somehow I'm still getting messages via the disabled contact form. I'm very much about to just give up on everything.

Can someone please check my site to see if there's ANY way for the troll to access the disabled form? I commented out the shortcode.
 
I just used the form a second ago - did you get an email? I got the message about the form being disabled though.
 
I got an email. That's odd that you can see the form... I commented it out.

I just removed it entirely, see if you can see it now.
 
Thanks.
 
Back
Top Bottom