Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,152,818 members, 7,817,381 topics. Date: Saturday, 04 May 2024 at 11:18 AM

There Is Global Attack On Wordpress Sites - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / There Is Global Attack On Wordpress Sites (1430 Views)

Dedicated, VPS Web Servers For Wordpress Sites & Businesses / There’s A Global Attack On Wordpress Sites Please Take Precautions / Webmasters, It Is Time To Show Us Your Wordpress Sites! (2) (3) (4)

(1) (Reply) (Go Down)

There Is Global Attack On Wordpress Sites by Trut(m): 10:26pm On Apr 12, 2013
As I write this post, there is an on going and highly distributed, global attack on wordpress installations to crack open admin accounts and inject various malicious scripts.

To give you a little history, we recently heard from a major law enforcement agency about a massive attack on US financial institutions originating from our servers.

We did a detailed analysis of the attack pattern and found out that most of the attack was originating from CMSs (mostly wordpress). Further analysis revealed that the admin accounts had been compromised (in one form or the other) and malicious scripts were uploaded into the directories.

Today, this attack is happening at a global level and wordpress instances across hosting providers are being targeted. Since the attack is highly distributed in nature (most of the IP’s used are spoofed), it is making it difficult for us to block all malicious data.

To ensure that your customers’ websites are secure and safeguarded from this attack, we recommend the following steps:

1. Update and upgrade your wordpress installation and all installed plugins
2. Install the security plugin listed here: http://wordpress.org/extend/plugins/better-wp-security/
3. Ensure that your admin password is secure and preferably randomly generated
4. Other ways of Hardening a WordPress installation are shared at http://codex.wordpress.org/Hardening_WordPress

These additional steps can be taken to further secure wordpress websites:

1. Disable DROP command for the DB_USER. This is never commonly needed for any purpose in a wordpress setup
2. Remove README and license files (important) since this exposes version information
3. Move wp-config.php to one directory level up, and change its permission to 400
4. Prevent world reading of the htaccess file
5. Restrict access to wp-admin only to specific IPs
6. A few more plugins – wp-security-scan, wordpress-firewall, ms-user-management, wp-maintenance-mode, ultimate-security-scanner, wordfence, http://wordpress.org/extend/plugins/better-wp-security/. These may help in several occasions

Also, we recommend using Cloudflare, which is available free with all our cPanel accounts, to prevent the attack from affecting the functionality of your site.

Source: http://www.gossimer.com/announcements/8/Global-Attack-on-WordPress-Sites.html
Re: There Is Global Attack On Wordpress Sites by Toonfreak(m): 10:45pm On Apr 12, 2013
I heard dt too! How can i locate ma meta key 4 verifying ma wordpress blog? I have tired d webmaster tool,but just can't find it. What if i failed 2 verify it,does it affect ma blog?
Re: There Is Global Attack On Wordpress Sites by mededot(m): 10:49pm On Apr 12, 2013
Thanks for the heads up! Trut
Re: There Is Global Attack On Wordpress Sites by Nobody: 12:29am On Apr 13, 2013
@OP that would be a DDOS,
Thanks for sharing.
Re: There Is Global Attack On Wordpress Sites by AFOLSNETWORKS(m): 12:48am On Apr 13, 2013
I pray this does not affect the one and only website I have on wordpress.
Re: There Is Global Attack On Wordpress Sites by Trut(m): 7:48am On Apr 13, 2013
AFOLSNETWORKS: I pray this does not affect the one and only website I have on wordpress.

Take the security STEPs outlined, it will help.
Re: There Is Global Attack On Wordpress Sites by mededot(m): 12:26pm On Apr 14, 2013
Well, thanks again for this headsup... I have almost 30 websites built with wordpress and I wasted no time improving the security of the very important ones!

Thankfully, the plugin mentioned: better wp security is a real blessing and I utilised a lot of the features!

I just got a notification now of how one of my less important sites was trying to be hacked! Check it out:

A host, 37.57.25.225(you can check the host at http://ip-adress.com/ip_tracer/37.57.25.225) has been locked out of the WordPress site at http://ayodejiagboola.com until Sunday, April 14th, 2013 at 11:50:46 am UTC due to too many login attempts. You may login to the site to manually release the lock if necessary.

So this is for real guys!
Re: There Is Global Attack On Wordpress Sites by UncleJJ(m): 4:35am On Apr 15, 2013
mededot: Well, thanks again for this headsup... I have almost 30 websites built with wordpress and I wasted no time improving the security of the very important ones!

Thankfully, the plugin mentioned: better wp security is a real blessing and I utilised a lot of the features!

I just got a notification now of how one of my less important sites was trying to be hacked! Check it out:

A host, 37.57.25.225(you can check the host at http://ip-adress.com/ip_tracer/37.57.25.225) has been locked out of the WordPress site at http://ayodejiagboola.com until Sunday, April 14th, 2013 at 11:50:46 am UTC due to too many login attempts. You may login to the site to manually release the lock if necessary.

So this is for real guys!
grin
Re: There Is Global Attack On Wordpress Sites by Trut(m): 9:12am On Apr 15, 2013
@ MOD. please move this thread to front page, alot of need to read and take the security steps.
Re: There Is Global Attack On Wordpress Sites by rufaai(m): 9:35am On Apr 15, 2013
I wrote about this on GigaLayer too:
http://blog.gigalayer.com/post/47790939048/wordpress-hacking-10-steps-to-stay-protected-like-a-pro

Its very crucial to keep your installation protected.
Re: There Is Global Attack On Wordpress Sites by phpNET(m): 9:05pm On Apr 15, 2013
Thanks bro for sharing!
Re: There Is Global Attack On Wordpress Sites by Dmayor7(m): 11:11am On Dec 17, 2014
i also noticed that in my newly opened wordpress site...... Too much login attempts by different IP's and usernames.....they where trying to login in to my admin but could not.....for several days they where doing this.

Do you know what i did, i laughed and deleted the wordpress since nothing much is there...... I changed host servers reinstalled wordpress and reinforce it with strong sercurity plugins.....

Since then i am good to go....
Re: There Is Global Attack On Wordpress Sites by Nobody: 12:58pm On Dec 17, 2014
Dmayor7:
i also noticed that in my newly opened wordpress site...... Too much login attempts by different IP's and usernames.....they where trying to login in to my admin but could not.....for several days they where doing this.

Do you know what i did, i laughed and deleted the wordpress since nothing much is there...... I changed host servers reinstalled wordpress and reinforce it with strong sercurity plugins.....

Since then i am good to go....

Friday, April 12, 2013 undecided
Re: There Is Global Attack On Wordpress Sites by sunnedee2: 2:44pm On Dec 17, 2014
I wrote a blog post here on how to prevent your WordPress website from being hacked here.

Please read and implement and you should be safe. Once again click here to read and implement.7 ways to prevent Your WordPress website from being hacked
Re: There Is Global Attack On Wordpress Sites by sunnedee2: 2:46pm On Dec 17, 2014
Nathan2222:


Friday, April 12, 2013 undecided

Tricked me too. grin grin grin

(1) (Reply)

Learn How To Build Complex E-commerce Websites Like Jumia And Forum Websites / You Can Now Sell Your Bltc0ins On Our F0rum / Top 3 Webhosting Companies In Nigeria: Review, Specs And Price

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 29
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.