8 ms·
Huge attack on WordPress sites could spawn never-before-seen super botnet
- js4all 13y agoIt is time for every Wordpress user to consider to switch to Octopress. Static sites have no attack vector, don't need security updates and are faster out of the box. Octopress has importers for many blogging systems including Wordpress: https://github.com/mojombo/jekyll/wiki/blog-migrations https://github.com/mojombo/jekyll/wiki/blog-migrations P.S.: I have migrated a few days ago myself from Posterous to Octopress. It was a piece of cake.
- jacques_chester 13y agoI am prepared to bet folding money that only software-sy types like us consider this a viable option. For everyone else it will seem like an unnecessary complication.
- modernerd 13y agoStatic site generators require a lot of sacrifices: What about non-technical users? Multi-author blogs? Idiot-proof extensibility? Updates from phones and tablets? Huge sites with thousands of posts? Editorial and review systems? Access to thousands of cheap or free themes? The ideal static site user is in a pretty privileged group. Most WordPress users would be better off securing WordPress and using a caching plugin that gives them the benefits of a powerful, dynamic platform while serving static files with automatic serverside compilation: http://wordpress.org/extend/plugins/wp-super-cache/ http://wordpress.org/extend/plugins/wp-super-cache/
- kmfrk 13y agoExactly. My own static blog is pretty much the perfect CMS that I wouldn't recommend to anyone for the life of me. At the very least, it needs something like http://prose.io/ http://prose.io/ on top of it, and since their website keeps not working, you don't want to put all your eggs in one basket, if shit hits the fan.
- lousy_sysadmin 13y agoThis is what I think WordPress 1) Beginner friendly - One doesn't need to be a coder or mess with cmd to use it. - Abundance of tutorial(text/audio/video) - You can host it anywhere, even for free. FTP? I know that from work. - Hosting provider even install it for you - Expert support is all over the web - Drupal and Joomla can't beat WordPress new user adoption, why? They're made to be customized(more developer-centric). Too much option is apparently not good for new user. 2) Features - Need something? there's plugin for that - People/visitors loves nice design/layout, WordPress have thousands of themes - Secure. Attacked by some random ddos/script kiddies? Hosting provider will take care of it. Malicious code? same case. Static site generator. 1) Beginner friendly - Yes, at least if you're familiar with cmd. - Most tutorial suggesting Amazon S3/CDN/cloud etc. Well those service are inaccessible to many. - Write new post, generate, upload...complicated! - Lets embed image/audio/video with one-click...nope! - Lets edit old blog post... oh why art thou so hard - Lets try it on my phone, nope! 2) Features - I want to add Facebook comment, how? Read the manual, download that, configure...blabla. No thanks - Lets add analytics code. Edit template and insert this javascript, save and regenerate...blabla. No thanks Conclusion : it might be a piece of cake for you but not to most people. Remember "most user are idiot"?. If I want to have simple static blog with nice editor I would use Blogger. Dumping random text? I have pastebin for that. Static site generator sure is attractive but we are just not there yet. I have a feeling that 'campaign' to promote static site generator to WordPress user is strikingly similar to Windows-to-Linux campaign. It just never going to happen for most user, at this rate.
- js4all 13y agoI see you points, but many of them are not valid: > - Most tutorial suggesting Amazon S3/CDN/cloud etc. Well those service are inaccessible to many. Because you just need to serve static content, there are more options than for Wordpress, incl. Google and Github. > - Write new post, generate, upload...complicated! Not at all: 1. Create a new post: rake new_post["title"] 2. Edit using your favorite editor 3. Sync: rake deploy > - Lets embed image/audio/video with one-click...nope! There are tags for that, i,e, {% img /img/pic01.png %} > - Lets edit old blog post... oh why art thou so hard You can edit any post. They are in folders sorted by year and month. > - Lets try it on my phone, nope! Correct. Conclusion: Blogging this way seems complicated, but is isn't if you are really doing it. Please try it for sake of a faster and safer Internet.
- navs 13y agoI've also noticed an increase in spam comments and trackbacks that akismet doesn't catch. Is this possibly related? At least on two occasions I've noticed the ip address of a spam comment match against an attempted login.
- ushi 13y agoAhaha, great headline... Seriously, the security of password protected systems are a disaster(, when combined with the average user). We should push static content generators like jekyll & co the reduce the surface, till somebody solves the authentication problem.
- uptown 13y agoRate-limiting login attempts out-of-the-box is something Wordpress should have included a LONG time ago. Maybe 1% of installs will setup the plugin to do this. No idea why they haven't added this yet.
- eksith 13y agoThat's usually the first mod done for clients who insist on using WP. For a few clients specifically, we don't let any users set their passwords at all; they get a randomly generated password upon registering or reset; WP is a good platform that does a lot out of the box (performance could use some work too though), so I don't think we should throw the baby out with the bathwater. There's just some housekeeping that needs to be taken care of beforehand. The alternative, of course, is building something custom with the bare minimum of necessities server-side and scrubbing all input/global vars. A lot of flexibility can still be retained by implementing a taxonomy system that define what posts can be (which is pretty much a very loose Entity-Attribute-Value model).
- Lifescape 13y agoWhich particular plugin would you recommend?
- navs 13y agohttp://www.wordfence.com/ http://www.wordfence.com/ here. Implemented it ever since I started noticing these attacks.
- medell 13y agoI've been using Better WP Security, one of the two linked in the article, and have nothing but good things to say. And the developer is on top of it.
- eksith 13y agoDitto for BWPS. You always want to pick plugins where the developers are actively participating in the community and regularly staying on top of any potential security issues.
- nwh 13y agoThe effect is probably reasonably limited though. Most of the time you're going to be in safe mode or on shared hosting, which means no SYN floods and no bitcoin mining.
- callmeed 13y agoI can confirm. We host a lot of WordPress blogs (for photographers) and our scans have have detected an uptick in installs infected with malicious files. I'm not sure if it's the same attack mentioned in the article but the last 2 weeks have been the worst I've seen. In my experience people get compromised due to bad folder permissions or old versions of WP. I hadn't considered brute-force password attacks.
- eksith 13y agoI've lost count of how many times I've seen people chmod /wp-content/upload to 777. I blame laziness, stupid presets in "one-click" installations and silly how-to's found all over the web.
- disgruntledphd2 13y agoI was setting up a Wordpress site for someone once (I'm not really a web developer). I downloaded an image gallery plugin and installed it locally. Wouldn't work. I went to the instructions and found that it required wp-content/upload to be set to 777. I abandoned the plugin soon after. However, if I hadn't been running Linux for a year before that, I'd probably have just done it. The difficulty with the democratisation of software and web development is that inevitably, people will make mistakes like this. The sad part is there's probably millions of articles explaining why this is a bad idea, but the people most at risk will never see them.
- bigiain 13y agoCan I suggest it might be worth investigating the "Wordfence Security" plugin? I use it pretty much everywhere that I have anything to do with WordPress - I'd noticed an uptick early this week of random ip addresses from far-flung countries getting locked out after 5 login attempts or multiple lost password attempts. (One site in particular gets a _lot_ of drive-by login attempts - it's got the word "anonymous" in the domain, which I suspect attracts mostly the wrong sort of traffic... Wordfence is locked down _much_ tighter on that site.)
- 13y ago
- socillion 13y ago"...the distributed attacks are attempting to brute force the administrative portals of WordPress servers, employing the username "admin" and 1,000 or so common passwords." I'm a little surprised that such a simple attack vector is a legitimate threat in creating a "super botnet."
- forrestthewoods 13y ago4.7% of users have the password password; 8.5% have the passwords password or 123456; 9.8% have the passwords password, 123456 or 12345678; 14% have a password from the top 10 passwords 40% have a password from the top 100 passwords 79% have a password from the top 500 passwords 91% have a password from the top 1000 passwords http://xato.net/passwords/more-top-worst-passwords/ http://xato.net/passwords/more-top-worst-passwords/
- minimaxir 13y agoOn older Wordpress installs (pre-3.0 I believe), you couldn't change the username of the first user from "admin" when setting up a blog, and you had to manually change it later. Yes, it was stupid.
- FuzzyDunlop 13y agoI remember having to perform some magical incantation to actually pull that off around then. Set up WP, log in, create new user, set it as admin, log in as the new user, try to delete the admin account, log back in as admin because you forgot something, log in as the new user again, actually delete account. No wonder everyone stuck with 'admin'.
- brittohalloran 13y agoI'm sorry but white on black makes my eyes angry
- deleted 13y ago[deleted]
- eof 13y agoI wonder if this is related to the DDOS that has been off and on against the bitcoin exchanges.
- mmuro 13y agoIn my opinion, Better WP Security is a requirement for any WordPress site.
- ck2 13y agoIf you still have user id #1 and/or the user "admin" on your wordpress install, you just haven't been using wordpress long enough to know what bad ideas those are.
- lenazegher 13y agoI've not heard of the problem of a user with id #1 before, can you explain please? What's the issue with a user id #1 when the username is not admin?
- francescolaffi 13y agoif user #1 is still an admin but with a different name you can just go to wpurl/?author=1 and if url rewriting is enabled you'll be redirected to wpurl/author/nicename and nicename is usually equal to the username
- pdkp 13y agoI don't think this adds the layer of security you think it does, merely a minor bit of obscurity. In context of the specific vector you reference, author={$user_id}, it probably doesn't do anything at all to protect you. Not that there is anything wrong with adding a bit of obscurity, not using 'admin' as a username and using a non-privileged author for posts can go a long way. However, if you are worried about someone getting your username from "author={$user_id}," using a user_id of 2,3,4,5, ect, probably isn't going to protect you. I think you are incorrectly assuming that the person that would use this method to get a username is going to stop if they get a 404 at #1(or even after just a single attempt.)
- lenazegher 13y agoThanks for the reply.
- archagon 13y agoI'm a new WordPress user. Are there any guides online with best practices that I can follow? (Some suggestions I see in this thread: rate-limiting plugin, don't have user id #1, don't have user "admin".)
- ereckers 13y agoStart here: http://codex.wordpress.org/Hardening_WordPress http://codex.wordpress.org/Hardening_WordPress Find a good host, use a secure password password, pay attention to the 3rd party plugins you're installing, and keep your install updated.
- cheald 13y agoYou can add HTTP basic auth to your wp-login.php and wp-admin/ paths, which will require that the user provide authentication before ever getting to pass data to those scripts. That can protect you against vulnerabilities in the software, but it won't protect you from bad passwords.
- jameswyse 13y agoAnother nice bit of advertising for Cloudflare.. There's some more about this on their blog: http://blog.cloudflare.com/patching-the-internet-fixing-the-wordpress-br http://blog.cloudflare.com/patching-the-internet-fixing-the-...
- micheljansen 13y agoExactly what I thought when I read "Operators of WordPress sites can take other measures too, including installing plugins such as this one and this one, which close some of the holes most frequently exploited in these types of attacks. Beyond that, operators can sign up for a free plan from CloudFlare that automatically blocks login attempts that bear the signature of the brute-force attack.". Then I saw the source for this "news": Cloudflare's blog.
- ChuckMcM 13y agoNot surprisingly one of the most commonly scripted search query at Blekko is for wordpress themes in one way or another. We do what we can to not return them any useful data.
- nichols 13y agoTime to start moving away from TurdPress.
- thefreeman 13y agotldr; automated scripts attacking default wordpress username with weak password. Welcome to the internet.
- ianstormtaylor 13y agoDon't know if this is a dumb question: but would it be possible for a good party to use the same method to get admin access and install rate-limiting login plugins on all of these insecure WordPress blogs? Seems like that would be badass.
- pwim 13y agoSee this post for an explanation why it isn't a good idea: http://www.schneier.com/blog/archives/2008/02/benevolent_worm_1.html http://www.schneier.com/blog/archives/2008/02/benevolent_wor...
- modernerd 13y agoUse a two-factor auth plugin like https://wordpress.org/extend/plugins/google-authenticator/ https://wordpress.org/extend/plugins/google-authenticator/ It works with the Google Authenticator app. Duo Security is also good: http://wordpress.org/extend/plugins/duo-wordpress/ http://wordpress.org/extend/plugins/duo-wordpress/ The WordPress.com team have already announced two-factor auth support for wp.com blogs, and are working on an official solution for wp.org sites: http://macmanx.com/2013/04/12/two-step-authentication-on-wordpress-com/ http://macmanx.com/2013/04/12/two-step-authentication-on-wor...
- GabrielF00 13y agoOne problem is that WordPrss sites are often built by small web designers for clients with limited computer skills and very little patience for complex passwords, much less two-factor authentication. For 2/3 of the WordPress sites I administer, I use a very long, complex admin password. The other site is for a group that wanted multiple admin accounts, but the people who use these accounts have a lot of trouble with complex passwords. After several emails telling me that "the website doesn't work" because the user had trouble with a long password with special characters, I gave up and switched it to an easy-to-remember password with just uppercase and lowercase letters.
- didip 13y agoI try to educate using [XKCD style password](http://xkcd.com/936/ http://xkcd.com/936/) to mainstream people. So far, they seemed to get it.
- NuZZ 13y agoOr just generate random 15+ character passwords for admin accounts. From the article it appears the concern is from brute forcing "admin" account passwords. Good luck bruting MT#r!}A1(hIQ4^pC*7`K.KGiL\&[A\k#TUC4R<R?
- WA 13y agoGood luck typing that without a password manager ;)
- deleted 13y ago[deleted]
- infinity 13y agoI write all (futile) login attempts on my site to a log file. I can confirm this rise in password bruteforcing attempts during the last days. This is what the bruteforce passwords look like, these tried to login as "admin": [Sat Apr 13 05:30:31 2013] nevalidniipass [Sat Apr 13 05:30:34 2013] gfhjkm [Sat Apr 13 05:30:37 2013] gggggggg [Sat Apr 13 05:30:39 2013] ghbdtn [Sat Apr 13 05:30:41 2013] ghgftmn6 [Sat Apr 13 05:30:43 2013] ghghgh [Sat Apr 13 05:30:44 2013] ghjkju [Sat Apr 13 05:30:46 2013] ghjrdjcn [Sat Apr 13 05:30:48 2013] gjkzyjxr [Sat Apr 13 05:30:50 2013] globax123 [Sat Apr 13 05:30:52 2013] go0gle [Sat Apr 13 05:30:54 2013] go2fuck [Sat Apr 13 05:30:55 2013] gogogo [Sat Apr 13 05:30:57 2013] goldz [Sat Apr 13 05:30:59 2013] gthtw112 [Sat Apr 13 05:31:02 2013] guest [Sat Apr 13 05:31:05 2013] h69s9t [Sat Apr 13 05:31:07 2013] hackett [Sat Apr 13 05:31:08 2013] hal9000 [Sat Apr 13 05:31:10 2013] hazem200 [Sat Apr 13 05:31:12 2013] heccrbqh [Sat Apr 13 05:31:14 2013] herbie [Sat Apr 13 05:31:16 2013] hghgh [Sat Apr 13 05:31:18 2013] hhhh1 [Sat Apr 13 05:31:20 2013] hhhhhaaaaa [Sat Apr 13 05:31:21 2013] hockey [Sat Apr 13 05:31:23 2013] home555 [Sat Apr 13 05:31:25 2013] honda [Sat Apr 13 05:31:27 2013] htrdbtv [Sat Apr 13 05:31:29 2013] http [Sat Apr 13 05:31:31 2013] hycvibck [Sat Apr 13 05:31:33 2013] i_am [Sat Apr 13 05:31:35 2013] ib6ub9 [Sat Apr 13 05:31:37 2013] icing [Sat Apr 13 05:31:38 2013] icq123 [Sat Apr 13 05:31:40 2013] icqpass [Sat Apr 13 05:31:42 2013] if6was9 [Sat Apr 13 05:31:44 2013] ifhgtq79 [Sat Apr 13 05:31:46 2013] ifyfif [Sat Apr 13 05:31:48 2013] iiiiiiii [Sat Apr 13 05:31:50 2013] ikaihsot [Sat Apr 13 05:31:52 2013] il0vey0u [Sat Apr 13 05:31:54 2013] iloveaol [Sat Apr 13 05:31:56 2013] iloveu [Sat Apr 13 05:31:57 2013] iloveyou [Sat Apr 13 05:31:59 2013] inferno [Sat Apr 13 05:32:01 2013] infinity [Sat Apr 13 05:32:05 2013] infree [Sat Apr 13 05:32:08 2013] iof314 [Sat Apr 13 05:32:11 2013] jake4440 [Sat Apr 13 05:32:13 2013] jamie1 [Sat Apr 13 05:32:15 2013] janice [Sat Apr 13 05:32:16 2013] jay18birdman [Sat Apr 13 05:32:18 2013] jc5000 [Sat Apr 13 05:32:20 2013] jeffery [Sat Apr 13 05:32:22 2013] john1 [Sat Apr 13 05:32:24 2013] joomla [Sat Apr 13 05:32:26 2013] joshua [Sat Apr 13 05:32:27 2013] keys [Sat Apr 13 05:32:29 2013] kholmsk3 [Sat Apr 13 05:32:31 2013] kir11421 [Sat Apr 13 05:32:33 2013] kkkkkk [Sat Apr 13 05:32:35 2013] kngvhpg [Sat Apr 13 05:32:37 2013] ko#]|7sz [Sat Apr 13 05:32:39 2013] kxvq4k2d [Sat Apr 13 05:32:41 2013] laksmi [Sat Apr 13 05:32:42 2013] lefty [Sat Apr 13 05:32:44 2013] lex1977 [Sat Apr 13 05:32:46 2013] linux [Sat Apr 13 05:32:48 2013] lol [Sat Apr 13 05:32:50 2013] lol777 [Sat Apr 13 05:32:52 2013] lollol [Sat Apr 13 05:32:54 2013] lovelove [Sat Apr 13 05:32:55 2013] lucille2000 [Sat Apr 13 05:32:57 2013] lyxasgje [Sat Apr 13 05:32:59 2013] m@$ter [Sat Apr 13 05:33:02 2013] m@ster [Sat Apr 13 05:33:07 2013] m1911a1 [Sat Apr 13 05:33:11 2013] google [Sat Apr 13 05:33:13 2013] facebook [Sat Apr 13 05:33:15 2013] microsoft [Sat Apr 13 05:33:17 2013] obama [Sat Apr 13 05:33:18 2013] twitter [Sat Apr 13 05:33:20 2013] wp [Sat Apr 13 05:33:22 2013] wordpress [Sat Apr 13 05:33:24 2013] 060890 [Sat Apr 13 05:33:26 2013] 060891 [Sat Apr 13 05:33:28 2013] 060893 [Sat Apr 13 05:33:30 2013] 060988 [Sat Apr 13 05:33:32 2013] 060989 They also try to get access as "administrator".
- sikhnerd 13y agoIt's actually two separate, but extremely similar attacks. One is exactly as described in the article, fairly distributed dictionary attack with user admin against wp-login.php. The second one is slightly more advanced, much much more distributed and I've seen it go for Joomla and wordpress, trying common usernames at times (though generally sticking to administrator/admin) and going through what appears to be a dictionary of about 3000 passwords. The bigger issue is these are coming in so fast and from so many directions, on resource constrained machines this is essentially ending up like a DDoS, which has a lot of ancillary effects. mod_sec and other similar methods of identifying these incoming before hitting apache and spawning a php thread are proving to be very much not enough.
- desbest 13y agoJust get the Login Lockdown plugin and install it.
- lousy_sysadmin 13y ago1) Login Lockdown 2) WP Better Security 3) WPScan (https://github.com/wpscanteam/wpscan https://github.com/wpscanteam/wpscan) Should be sufficient for most small/medium installation
- ajtaylor 13y agoI've used WordPress in the past because it was easy to setup and use. However, given the consistently bad security record I'd love to try something different. Anyone have recommendations for other open source CMS's? Similar functionality to WP is enough - I don't need anything fancy.
- recusancy 13y agoDrupal
- joshaidan 13y agoWhat URL is the login requests sent to? Would changing the wp-admin directory to something random help avoid the attacks? Or does wordpress have another point of entry for authentication?
- medell 13y agoAttacks are continuing, I've logged two more attempts from todays. There is no reason these sites have login attempts from said countries: 79.28.255.65 (Italy) 80.35.80.139 (Spain)