GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Global Wordpress Brute Force Attack (https://gfy.com/showthread.php?t=1106205)

AdultKing 04-12-2013 08:50 AM

Global Wordpress Brute Force Attack
 
Right now there is a global Wordpress brute force attack taking place where up to 90,000 individual IP addresses have been detected as involved.

http://blog.sucuri.net/2013/04/mass-...r-reality.html

http://blog.sucuri.net/2013/04/prote...e-attacks.html

Check your server logs, ensure you have strong passwords and preferably don't use "admin" as your login name.

Phoenix 04-12-2013 09:24 AM

who would have guessed wordpress is vulnerable?

2013 04-12-2013 09:32 AM

what's a word press

Nasty 04-12-2013 09:35 AM

This plugin prevents the unlimited login attempt's WordPress allows

http://wordpress.org/extend/plugins/...ogin-attempts/

Fat Panda 04-12-2013 09:37 AM

fun stuff

2012 04-12-2013 09:38 AM

i made da wordpess imma da webpage dedinuuhhhh . i dedign webpage
http://i.imgur.com/7lbvhHX.jpg

CurrentlySober 04-12-2013 09:40 AM

Quote:

Originally Posted by 2013 (Post 19574904)
what's a word press

i cunt a4d a word being pressed... :(

Mark.Roy 04-12-2013 09:54 AM

Thanks for heads up.

Emil 04-12-2013 10:38 AM

I assume that as long as you use a decent password you should be OK since they're using wordlists for the attacks?

ottopottomouse 04-12-2013 10:43 AM

Quote:

Originally Posted by Phoenix (Post 19574881)
who would have guessed wordpress is vulnerable?

The vulnerability is just down to the number of users and the likelihood of people being stupid enough to use abc123 as their password.

seeandsee 04-12-2013 10:52 AM

I use good password, so they will not enter that way

bigluv 04-12-2013 11:37 AM

Thanks for the heads up. It always amazes me that websites dont have more sophisticated anti-hacking measures along these lines.

RubyGoodnight 04-12-2013 12:56 PM

Thanks, AK - passed the word along.

GonZo 04-12-2013 12:58 PM

Quote:

Originally Posted by AdultKing (Post 19574802)
Right now there is a global Wordpress brute force attack taking place where up to 90,000 individual IP addresses have been detected as involved.

http://blog.sucuri.net/2013/04/mass-...r-reality.html

http://blog.sucuri.net/2013/04/prote...e-attacks.html

Check your server logs, ensure you have strong passwords and preferably don't use "admin" as your login name.

MojoHost took care of me hours ago as they always do.
Issue was resolved before I got out of bed.

Only reason you might worry is if your server isnt hosted at MojoHost.

JesseQuinn 04-12-2013 01:03 PM

Quote:

Originally Posted by Nasty (Post 19574912)
This plugin prevents the unlimited login attempt's WordPress allows

http://wordpress.org/extend/plugins/...ogin-attempts/

^^that plugin is great for keeping out specific people who want to fuck with someone's wordpress, but from the articles linked in the OP it appears that so many different IPs (90 000 unique IPs) are involved that the plugin isn't very effective

it's still a great plugin, just not against this sort of attack


Quote:

Originally Posted by ottopottomouse (Post 19575072)
The vulnerability is just down to the number of users and the likelihood of people being stupid enough to use abc123 as their password.

^^^I'm saying.

unrelated to wordpress, I had a bunch of weird questions from pseudo-customers a few weeks back (3 on the same day) asking me to play the 'porn star name game' (where the answers are one's middle name, street one grew up on, name of one's first pet, etc). It didn't occur to me that it was anything significant (other than being weird) until I read that those are often password retrieval questions for online accounts. It was a total 'duh' moment and I'm glad I just ignored the losers who had asked me.

/threadjack

thanks for posting the links, AdultKing

ottopottomouse 04-12-2013 01:34 PM

There is always quite a few sites about harvesting passwords in the guise of Check How Secure Your Password Is too.

Heath 04-12-2013 01:38 PM

So is admin1234 not secure? Man. I got a lot of sites to change. Can anyone help?

Forest 04-12-2013 01:55 PM

Quote:

Originally Posted by Populace (Post 19575406)
So is admin1234 not secure? Man. I got a lot of sites to change. Can anyone help?

change it to pass123

NaughtyVisions 04-12-2013 01:58 PM

Quote:

Originally Posted by Forest (Post 19575442)
change it to pass123

or simply "password." :2 cents: :thumbsup

LouiseLloyd 04-12-2013 02:08 PM

Use .htaccess to password protect /wp-admin folder and add deny access to all traffic excluding your own IP.

RazorSharpe 04-12-2013 02:16 PM

http://wordpress.org/extend/plugins/...in-security-2/

this looks rather nifty

xxxjay 04-12-2013 03:48 PM

We had to deal with it yesterday

discounts.xxx 04-12-2013 04:15 PM

Why would they want to hit Wordpress? I was aware of this yesterday....unfortunately..

Captain Kawaii 04-12-2013 11:31 PM

Thanks for the info all.

babymaker 04-13-2013 12:11 AM

Quote:

Originally Posted by GonZo (Post 19575331)
MojoHost took care of me hours ago as they always do.
Issue was resolved before I got out of bed.

Only reason you might worry is if your server isnt hosted at MojoHost.

M3Server took care of it before I heard of it as well, got an email awhile ago :thumbsup

blazin 04-13-2013 12:16 AM

Stick you wp-admin directory behind a basic authentication prompt as well

just a punk 04-13-2013 01:27 AM

Quote:

Originally Posted by Phoenix (Post 19574881)
who would have guessed wordpress is vulnerable?

Vulnerable? How password bruteforcing is related to the definition of "vulnerability"?

icymelon 04-13-2013 01:47 AM

Quote:

Originally Posted by GonZo (Post 19575331)
MojoHost took care of me hours ago as they always do.
Issue was resolved before I got out of bed.

Only reason you might worry is if your server isnt hosted at MojoHost.

my server was down at mojo. they want me to upgrade. too many blogs on one box

Freedom6995 04-13-2013 04:27 AM

Quote:

Originally Posted by LouiseLloyd (Post 19575461)
Use .htaccess to password protect /wp-admin folder and add deny access to all traffic excluding your own IP.

:thumbsup


All times are GMT -7. The time now is 09:50 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc