Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,155,100 members, 7,825,481 topics. Date: Sunday, 12 May 2024 at 03:43 PM

Someone Is Trying To Hack My Blog, What Do I Do? - Webmasters (2) - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Someone Is Trying To Hack My Blog, What Do I Do? (11793 Views)

I Have 300K To Invest With On My Blog, What And What Should I Get? / Mobile 'yes' Is Not Working In My Blog. What Should I Do / Facebook Is Trying To Kill Facekobo.com - A Nigerian Website (2) (3) (4)

(1) (2) (3) (Reply) (Go Down)

Re: Someone Is Trying To Hack My Blog, What Do I Do? by MenaNathsBlog(f): 10:13pm On Dec 23, 2015
For Effective Hypes & Trend Or Publicity For Your Music, Brands, Events, Etc BBM: 58BF14EF OR +2348141643368
Email : Menanathonline@gmail.com
Join our bbm channel: https:///Tu4uAyQJUZ
Instagram and twitter : @Mena_nath.
Thanks
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Nobody: 10:13pm On Dec 23, 2015
Put three pebbles in a cup of water. Drop it on the floor. Then run round it three times.




That should solve your problem

1 Like 1 Share

Re: Someone Is Trying To Hack My Blog, What Do I Do? by emmalexdboy(m): 10:14pm On Dec 23, 2015
WAECFlyer5:
The problem here is that the person knows my recovery email!!!

And also, knows some details about my website.

lalasticlala, please b4 yu sleep, 2mao might be late
Your username is very simple to guess. I'll advise you change that username ASAP, use something creative and very hard-to-guess and use a strong password.

1 Like 1 Share

Re: Someone Is Trying To Hack My Blog, What Do I Do? by sugarbelly1: 10:14pm On Dec 23, 2015
one reason i'm in love with blogger

1 Like

Re: Someone Is Trying To Hack My Blog, What Do I Do? by agent9(m): 10:15pm On Dec 23, 2015
Call 911 undecided undecided
Re: Someone Is Trying To Hack My Blog, What Do I Do? by kingsilly(m): 10:17pm On Dec 23, 2015
I'll strongly advice, open another blog and leave dat one for the hacker... grin

1 Like 1 Share

Re: Someone Is Trying To Hack My Blog, What Do I Do? by mentorandfriend(m): 10:19pm On Dec 23, 2015
publicenemy:
Open a new Blog and leave the old one for the hacker.
Ignoramus undecided
Re: Someone Is Trying To Hack My Blog, What Do I Do? by friends4ever(m): 10:28pm On Dec 23, 2015
CALL 911 ASAP
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Nobody: 10:29pm On Dec 23, 2015
If you're on the blogger platform, once you had an Up-To-Date Backup, GO READ MY POST ON How to Restore your Offline Blog Within or Less than 2hours
Re: Someone Is Trying To Hack My Blog, What Do I Do? by AceRoyal: 10:30pm On Dec 23, 2015
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Afrieyes: 10:33pm On Dec 23, 2015
publicenemy:
Open a new Blog and leave the old one for the hacker.

cheesy cheesy grin grin grin
U must be a Shiite
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Nobody: 10:35pm On Dec 23, 2015
WAECFlyer5:
The problem here is that the person knows my recovery email!!!

And also, knows some details about my website.

lalasticlala, please b4 yu sleep, 2mao might be late

Very simple... update your WordPress or any other outdated plugins that needs an update, change your WordPress and Gmail password to a very strong one, also enable sms verification feature on your gmail account. follow these few measures and you are safe. wink
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Afrieyes: 10:35pm On Dec 23, 2015
sugarbelly1:
one reason i'm in love with blogger
Who told you?

Last week I had to quickly change my password after I got a notification that I logged in anoda place
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Ochiske(m): 10:37pm On Dec 23, 2015
publicenemy:
Open a new Blog and leave the old one for the hacker.
gringringrin
Re: Someone Is Trying To Hack My Blog, What Do I Do? by adewasco2k(m): 10:41pm On Dec 23, 2015
Change your admin login url from the default /wp-admin

2 Likes

Re: Someone Is Trying To Hack My Blog, What Do I Do? by BuddhaPalm(m): 10:50pm On Dec 23, 2015
It's unlikely this person knows your recovery email. And even if they do, it's still useless to them.

However, what the person likely knows is your username - from your posts...post Author.

And they must have clicked on "Lost Password?"

Install Sucuri, so you can see a log of all activities, and an IP ban plugin too - to ban any IPs that attempt to login.

Also have a strong password. Set extended lockouts. Update to current versions as well, and then stop giving a fvck.
Re: Someone Is Trying To Hack My Blog, What Do I Do? by snowland(m): 10:53pm On Dec 23, 2015
Like some people already suggested, install Wordfence and your blog will be secured.

Just got a mail from wordfence about some Aethera Botnet that is attcking wordpress blogs/websites by guessing your password. Read the full detail below:

[size=18pt]Aethera Botnet Attacks WordPress Sites
[/size]
Exec summary: There is currently a botnet that has been identified that is targeting WordPress websites with a password guessing attack. If you have Wordfence installed with our default settings, you are already protected against this attack. The botnet is powered by modem/router devices. ISP’s are gradually patching the devices but many are left vulnerable or infected as some ISP’s respond slowly to this issue.

Full article:

In February of this year a security researcher at Voidsec noticed brute force attacks on his personal WordPress site and he noticed a pattern in the IP addresses attacking his site. They were mostly Italian internet service providers. They were:

Fastweb
Albacom, now BT-Italia
Clouditalia
Qcom
WIND
BSI Assurance UK

What he discovered is that the IP’s attacking his site were all devices. They were all Aethera modem/routers to be exact. By doing some further sleuthing he discovered that all the Aethera devices involved in the attack were using default login credentials (blank/blank).

The modems had obviously been hacked and the attacker had gained access through the default login. They had then installed malware on the modems that launched a brute force password guessing attack on WordPress sites.

The Aethera devices in question suffer from various XSS vulnerabilities, a CSRF vulnerability and a HTML5 cross-origin resource sharing issue.

The researcher then used Shodan, a search engine for devices on the Net, to find out how many vulnerable Aethera devices are on the Net and found around 8,000 vulnerable devices. They likely used a search on Shodan similar to this one.

They estimate that the amount of bandwidth the combined vulnerable devices have access to is between 1.7 and 17 Gigabits per second. This could be used for a massive distributed denial of service attack.

Voidsec tried to contact all ISP’s without much luck. Fastweb was responsive after a time and they have fully patched all affected routers. BT-Italia has been unresponsive and remains vulnerable.

While this research was happening, Krebs published a post about Lizard Squad, a hacking group, and a new DDoS tool that they were trying out to knock websites (and anyone else) offline. It seems that Lizard Squad may have been using the Aethera vulnerability to power their DDoS botnet.

The timeline was as follows:

Feb 13: Voidsec discovers the botnet. They contacted BT-Italy at this time.
Feb 25: Tries again to contact BT Italy using various methods with no luck.
December 11: FastWeb is told about the vulnerability and they agree on a disclosure schedule.
December 22: Disclosure and FastWeb’s routers are fixed.

Here’s the full post on voidsec.com. Voidsec is an Italian company so the post is also available in Italian.

We will continue to monitor activity from this botnet at Wordfence and will share any interesting data we uncover.

There are still many unpatched Aethera router/modems out there and they are still being used to launch attacks. Hopefully with the press coverage around this issue, the unresponsive ISPs involved will patch their customer devices and stop the attacks they’re launching on WordPress websites and other targets.

https://www.wordfence.com/blog/2015/12/aethera-botnet-attacks-wordpress-sites/
Re: Someone Is Trying To Hack My Blog, What Do I Do? by coderoflife: 10:53pm On Dec 23, 2015
Wow, well ask your question out on www.asknote.co
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Chidizman(m): 10:57pm On Dec 23, 2015
You came to Nairaland to seek solutions to your Problem? Young man you are dead!!! cheesy
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Sacramento4real(m): 11:04pm On Dec 23, 2015
kings09:
Hack d person back na.
It's called Reverse Hacking. Hacking the hacker. cool
Re: Someone Is Trying To Hack My Blog, What Do I Do? by deluckiest(m): 11:06pm On Dec 23, 2015
WAECFlyer5:
The problem here is that the person knows my recovery email!!!

And also, knows some details about my website.

lalasticlala, please b4 yu sleep, 2mao might be late


Exactly what you get for wrong site's coding from bad developers.
If you think your Wordpress sites are safe... think again ....watch this WP Site get HACKED IN SECONDS...And the solutions

http:///wpsiteguardian2016
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Tmaritas76(m): 11:13pm On Dec 23, 2015
Kill yourself and the whole episode ends
Re: Someone Is Trying To Hack My Blog, What Do I Do? by kings09(m): 11:13pm On Dec 23, 2015
Weda reverse ooo or foward oo, So far thr z a hack grin
Sacramento4real:

It's called Reverse Hacking. Hacking the hacker. cool
Re: Someone Is Trying To Hack My Blog, What Do I Do? by oieda: 11:14pm On Dec 23, 2015
WAECFlyer5:
The problem here is that the person knows my recovery email!!!

And also, knows some details about my website.

lalasticlala, please b4 yu sleep, 2mao might be late

First step: BACKUP!!!
Re: Someone Is Trying To Hack My Blog, What Do I Do? by classicnews: 12:17am On Dec 24, 2015
amtaken:
Who designed the blog for you?
me
Re: Someone Is Trying To Hack My Blog, What Do I Do? by em3r4ld(m): 1:01am On Dec 24, 2015
Mosaic law applies... 'phi.sh' him out (no pun intended) & do the needful. #WaitingForMySparkling2Cents
Re: Someone Is Trying To Hack My Blog, What Do I Do? by Ifecoded(m): 1:48am On Dec 24, 2015
someone is trying to hack ur blog? You too blog his hack... Since you have a blog and he has a hack.
Re: Someone Is Trying To Hack My Blog, What Do I Do? by amtaken(f): 1:59am On Dec 24, 2015
Ok. Don't know what to say again.
classicnews:
me
Re: Someone Is Trying To Hack My Blog, What Do I Do? by excel111(m): 2:56am On Dec 24, 2015
Curse d person. ...lobatan
Re: Someone Is Trying To Hack My Blog, What Do I Do? by ngmgeek(m): 4:43am On Dec 24, 2015
Abandon the blog if it's not worth the stress and create another one. Learn your lessons and move on. Good luck wink
Re: Someone Is Trying To Hack My Blog, What Do I Do? by okesima18(m): 5:07am On Dec 24, 2015
hahaha d will use your blog as Xmas gift

(1) (2) (3) (Reply)

8 Things I Wish I’d Known When I Started As A Web Developer / September Offer : Receive Free Gift For Any PHP Script You Buy / Fact File: See How The Seven Keys Of The Internet Work - Naijatechguy

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 28
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.