World Wide attack affecting all wordpress sites at all hosts

Discussion in 'WordPress' started by purpleorange, Apr 13, 2013.

  1. #1
    Surprised to see DP forums not discussing on this issue. You can read the following links for more info.

    http://blog.sucuri.net/2013/04/protecting-against-wordpress-brute-force-attacks.html
    http://www.inmotionhosting.com/support/news/general/wp-login-brute-force-att
    ack
    http://blog.hostgator.com/2013/04/11/global-wordpress-brute-force-flood/
    http://bad-behavior.ioerror.us/2013/04/10/wordpress-brute-force-login-attacks-stepped-up/

    s-stepped-up/

    In short a botnet operating on over 90,000+ IP addresses has been launching a brute attack.

    So a few hosting providers have decided to cut off access to the Login page.

    Any way it is wise to change your pw to a more secure one right away!!!
     
    purpleorange, Apr 13, 2013 IP
  2. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #2
    It is interesting that only (my) websites written in English are affected, others are fine.

    Although it sucks that I can't log in to my WP, I don't plan to move all files to another location because I am too lazy and I believe that such kind of attack is very rare (and thus won't happen often which would probably make me do something about it).

    It would be nice if the people who control the botnet released some stats after end ing this IMO futile attempt to hack sites.
     
    Last edited: Apr 14, 2013
    Devtard, Apr 14, 2013 IP
  3. avantemedia

    avantemedia Active Member

    Messages:
    285
    Likes Received:
    52
    Best Answers:
    0
    Trophy Points:
    90
    #3
    I seen this with my host trying to log in, they have put the login area on another secure part with a particular username and password before i can see my login page a bit of a pain but atleast the host is looking our for me.
     
    avantemedia, Apr 14, 2013 IP
  4. Nigel Lew

    Nigel Lew Notable Member

    Messages:
    4,642
    Likes Received:
    406
    Best Answers:
    21
    Trophy Points:
    295
    #4
    Nigel Lew, Apr 14, 2013 IP
  5. finalroundmedia

    finalroundmedia Well-Known Member

    Messages:
    368
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    140
    #5
    Another great plugin is Better WP Security. So far I haven't been affected and I have around 40 WP sites.

    http://wordpress.org/extend/plugins/better-wp-security/
     
    finalroundmedia, Apr 16, 2013 IP
  6. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #6
    I am sure that there are lots of "security" plugins but I doubt that any of them would help in this situation.
     
    Devtard, Apr 16, 2013 IP
  7. Nigel Lew

    Nigel Lew Notable Member

    Messages:
    4,642
    Likes Received:
    406
    Best Answers:
    21
    Trophy Points:
    295
    #7
    If your wp-admin folder and any hackable file is not the in it's native location the problem is solved.

    Nigel
     
    Nigel Lew, Apr 16, 2013 IP
  8. Devtard

    Devtard Notable Member

    Messages:
    850
    Likes Received:
    133
    Best Answers:
    4
    Trophy Points:
    220
    #8
    That's true.

    But do you really need a plugin to do that for you? All these security plugins seem like a way to waste server resources to me.
     
    Devtard, Apr 16, 2013 IP
  9. Nigel Lew

    Nigel Lew Notable Member

    Messages:
    4,642
    Likes Received:
    406
    Best Answers:
    21
    Trophy Points:
    295
    #9
    For us perhaps, for my clients, not so much lol... Just gives you a UI really.

    Nigel
     
    Nigel Lew, Apr 16, 2013 IP
  10. jeff23

    jeff23 Member

    Messages:
    141
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    26
    #10
    my website was affected too

    username seems to be different in admin panel

    I resetted it and than changed the password again
     
    jeff23, Apr 17, 2013 IP