Online Services

Blog

  • The April 2017 WordPress Attack Report

    Today we are releasing the WordPress Attack Report for April, 2017. You can also find these previous attack reports on our blog:

    This report contains the top 25 attacking IPs for the month of April and their details. It also includes charts of brute force attack activity and complex attack activity for the period. We also include the top themes and plugins that were attacked and which countries generated the most attacks for the period.

    The Top 25 Attacking IPs

    I’m including our standard explanation of how the table below works. If you are familiar with our attack reports, you can skip down to the table below which contains the April data and read my comments that follow the table.

    Brief introduction if you are new to viewing these reports

    In the table below we have listed the most active attack IPs for April 2017. Note that the ‘Attacks’ column is in millions and is the total of all attacks that originated from each IP. Further right in the table (you may have to scroll right) we break out the attacks into ‘brute force’ attacks and ‘complex’ attacks.

    Brute force attacks are login guessing attacks. What we refer to as ‘complex’ attacks are attacks that were blocked by a rule in the Wordfence firewall.

    We have also included the netblock owner, which is the organization, usually a company, that owns the block of IP addresses that the attack IP belongs to. You can Google the name of the owner for more information. A Google search for any of these IP addresses frequently shows reports of attacks.

    The hostname included is the PTR record (reverse DNS record) that the IP address owner created for their IP, so this is not reliable data but we include it for interest. For example, we have seen PTR records that claim the IP is a Tor exit node, but it is clearly not, based on traffic.

    We also include the country and city if available. To the far right of the report we show the date in April when we started logging attacks and the date attacks stopped.

    The Top Attacking IPs

    The total attacks from our top 25 attackers increased from 118 million in March to 137 million total attacks on WordPress sites from these IP addresses in April 2017.

    The distribution of brute force attacks compared to complex attacks among the top 25 attackers remained roughly the same. 32% of attacks on WordPress sites in April were complex attacks. 68% were brute force attacks. Brute force attacks remain by far the most popular attack method on WordPress sites.

    Turkey made up a total of 11 of our top 25 attacking IPs in April. There are a total of 5 separate ISPs in Turkey that contributed to the top 25 attacking IPs.

    Brute Force Attacks on WordPress in April 2017

    The chart below shows the brute force attack activity on WordPress sites that we monitor for the month of April.

    The average number of daily brute force attacks from March to April 2017 is amazingly consistent. We saw almost exactly 35 million average attacks per day for both months. There was a slight upward trend in volume during the month and about the same level of volatility. The peak in March was just over 45 million attacks in a single day and the lowest day was at the beginning of the month with 27 million brute force attacks in a single day.

    Complex Attacks on WordPress in April 2017

    The graph below shows complex attacks (attacks that try to exploit a vulnerability) for the month of April 2017.

    We saw an uptick in complex attack activity in April on WordPress sites that Wordfence protects. The daily average increased from 3.8 million attacks per day to 5.9 attacks per day.

    We also saw a significant upward swing in attacks towards the end of the month with the daily total complex attacks on WordPress sites approaching 10 million.

    Attacks on Themes in April 2017

    The table below shows the total number of attacks on WordPress themes. We identify each theme using it’s ‘slug’ which is the directory in which it is installed in WordPress.

    The most commonly attacked themes on WordPress for the month of April is surprisingly stable. Almost all themes in our top 25 were also in the list last month with a slight reshuffling.

    Attacks on Plugins in April 2017

    The table below shows the attacks we saw on plugins across the sites Wordfence protects. As with themes, we identify each plugin by its unique ‘slug’ which is the unique installation directory where the plugin is installed.

    The biggest gainer in our top 25 most attacked plugins is the “N-Media Post Front-end Form”. The plugin author fixed a file upload vulnerability about 7 months ago. The vulnerability was disclosed in August 2015, so was in the wild for a long time before it was fixed, which is probably why it became part of many attack toolkits even though it only has 60 active installs. It is important to note that the large majority of these attacks are attempting to exploit vulnerabilities that have already been fixed.

    Attacks by Country for April 2017

    The table below shows the top 25 countries that attacks originated from in the month of April on WordPress sites that we monitor.

    Our usual suspects are still at the top of the list of the top countries from where attacks on WordPress originate. The most remarkable thing about the list is that Algeria is still in the top 25. The home router botnet we wrote about in early April continued attacking WordPress sites throughout the month of April.

    We published a post 48 hours ago in which we explained that there was a dramatic drop in attacks on WordPress from hacked routers around the world. The drop occurred rapidly when you consider the scale of attacks. This includes attacks from Algeria and we expect that Algeria may drop out of the top 25 list completely in next months report if the home router botnet remains shut down.

    Conclusion

    That concludes our attack report for the month of April 2017. As always we will continue to monitor attack activity on WordPress sites in real-time. If you have any questions or comments about the report, as always I welcome your feedback in the comments and I’ll do my best to reply.

    Mark Maunder – Wordfence Founder/CEO.

    The post The April 2017 WordPress Attack Report appeared first on Wordfence.

  • Home Router Botnet Shut Down in Past 72 Hours. Who did it?

    On April 11th, 3 weeks ago, we published a story discussing routers at a specific set of ISPs that have been hacked. These routers have been used to launch attacks on WordPress websites. The ISPs with compromised routers included Telecom Algeria, BSNL in India, PLDT in the Philippines and many more large ISPs around the world.

    When we discovered this botnet over 3 weeks ago, we started monitoring attacks originating from those IPs. This allowed us to add the attacking IPs to the Wordfence Premium real-time blacklist to protect our customers.

    Yesterday morning we noticed that there was a rapid drop-off in attacks from the ISPs we identified 3 weeks ago, that had targeted WordPress websites.

    This is what the change in activity looked like from the top 50 ISPs from where these attacks were originating during a 72 hour period ending yesterday (Monday) evening. Click the chart for a larger version.

     

    The chart above shows attacks per hour by ISP. This is the most recent 72 hour period, ending yesterday evening at approximately 5pm Pacific time. Each line is an Internet Service Provider from which these attacks were originating.

    As you can see, starting at around midnight on Sunday night (April 30th) Pacific time, the number of attacks we are seeing from ISPs where we found vulnerable routers have dropped from peaks of 40,000 in some cases to peaks of just above 5,000 attacks per hour. In many cases the attacks drop to much lower levels and continue to decrease.

    Why did the attacks stop?

    The data indicates that this is a botnet that was acting in a coordinated fashion and attacking WordPress sites that we protect. In the past 72 hours, the attack frequency dropped simultaneously across hundreds of ISPs in many countries.

    One possibility is that the individual or group controlling the botnet stopped attacking WordPress and that resulted in a rapid decrease in attack volume over a 24 hour period.

    Another possibility is that the command and control servers of the botnet were taken offline by a coordinated effort involving security services in multiple countries.

    It is worth noting that earlier this month, INTERPOL worked with investigators in Indonesia, Malaysia, Myanmar, Philippines, Singapore, Thailand and Vietnam to identify almost 9,000 command and control servers and just under 270 hacked websites. They produced reports for authorities in each country which allowed local enforcement to take action against the compromised systems.

    This kind of coordinated action by INTERPOL is encouraging. It helps protect the global online community and creates a safer internet.

    This is great news!

    This reduction in attacks originating from hundreds of ISPs around the world is great news. Attacks on WordPress sites around the world have been reduced.

    The attacks originating from these ISPs were also resulting in their IP addresses being blacklisted by Wordfence and other services like SpamHaus. That resulted in the customers of those ISPs suffering because certain websites and services would block them. By reducing these attacks, this ensures those ISP customers have full internet access again.

    We will continue to monitor the situation

    It is unclear whether this reduction in attacks is a permanent change or just a temporary respite. We will continue to monitor the situation and if attacks increase again, the Wordfence algorithms will react very rapidly and will add offending IPs to the Wordfence Premium blacklist in a matter of minutes to protect our WordPress site owners.

    As new data emerges, we will publish it here. As always, I encourage you to share your thoughts in the comments below and I will be around to reply if needed. If you haven’t already, please consider joining our mailing list.

    The post Home Router Botnet Shut Down in Past 72 Hours. Who did it? appeared first on Wordfence.

  • 20 Minutes to a Secure WordPress Website

    Securing WordPress has become easy thanks to the amazing work the WordPress team continuously do to fix vulnerabilities and improve the security of the platform. With the addition of Wordfence, it is possible to run a secure WordPress site and sleep well at night knowing your investment is safe.

    Today I’m going to provide you with a checklist you can get through in 15 minutes that will help you secure your WordPress website. Time is short, so lets get started!

    1. Ensure that your site is backed up

    Backups are the first step in securing your website. Your backups ensure that even if your site is compromised or damaged in some way, you can always recover it. We suggest running a full backup before making the changes below so that you can recover your site if you break anything.

    Your hosting provider may already provide free backups. If not, there are a wide range of backup plugins available for WordPress. We like UpdraftPlus which is well maintained, has excellent ratings and has a large install base of over 1 million sites.

    2. Delete any old public WordPress installations and other old software

    Sign in to your WordPress website using FTP or a file manager. You need to be able to view all files in your hosting account. Check to see if you have any old WordPress installations lying around. For example in a directory called ‘backup’, ‘doc_root.old’, ‘old_wordpress’ or something similar.

    If you are unsure what a directory is, ask your hosting provider or a developer if you work with one. Any directories that are old and no longer used should be deleted. They are probably not being maintained and hackers may eventually discover them and use vulnerabilities in the out-of-date software to gain access to your site.

    Now do the same for any other software that you have installed but aren’t using or maintaining. This includes old PHP applications like phpmyadmin, MediaWiki, Joomla and Drupal.

    3. Delete any themes, plugins or extensions that you don’t need or that aren’t maintained

    Sign in to your WordPress site and go to Plugins > Installed Plugins. Delete any plugins that you no longer use. Check everything else and make sure you recognize it and use it.

    You can click the “Details” link next to each plugin to see when it was last updated. We strongly recommend that you delete any plugin that has not been updated for 2 years or more. It is unlikely that the author is maintaining the plugin and if a vulnerability is reported, it may not be fixed quickly.

    Do the same for WordPress themes. Go to Appearance > Themes. Then delete any themes you no longer use. If you switched themes at some point and still require images in another theme directory, we recommend you delete as much as you can of the legacy theme and just preserve static assets like images and stylesheets.

    If you use Joomla, Drupal or other applications, sign in to each application and remove old extensions that you no longer use or that are not being maintained by the author.

    Deleting old extensions, plugins and themes will remove them as potential entry points for a hacker.

    4. Secure your WordPress admin accounts and CPanel

    Secure any admin accounts on your site. Sign in to WordPress. Go to Users > All Users and then click on ‘Administrator’ at the top of the screen to view all administrator level accounts. Make sure you recognize all admin accounts. If you don’t recognize an account, find out who it belongs to. If you have an unauthorized admin account and suspect you may have been hacked, you may need to contact our security services team.

    Delete any admin accounts that are no longer needed. 

    If you aren’t sure if your admin passwords are secure, go in and change them to something random and ensure your admin account owners are alerted to the change. We strongly recommend using WordPress’s automatically generated password which is very secure. Use a password manager like 1Password to store the generated passwords.

    Sign in to CPanel and make sure you are using a secure password there too. It should be random and preferably 20 characters or more. You can use 1Password or another password manager to generate a random password and store it.

    5. Update absolutely all software in your hosting account

    You need to bring everything up-to-date. Under absolutely no circumstances should you be running out of date software. Complete the following steps:

    • Update all WordPress core installations.
    • Update all WordPress plugins.
    • Update all WordPress themes.
    • Update any Joomla, Drupal, MediaWiki, PHPMyAdmin or other applications you have installed.
    • Update any extensions in any applications like Joomla or Drupal that you have installed.

    A special note on custom WordPress themes

    If your theme is custom designed and you aren’t able to update it, you are going to need a developer to maintain that software. This is an unfortunate reality and expense of having a custom theme installed. You can’t just install and forget.

    Many themes use libraries that eventually have vulnerabilities discovered in them. If your theme is not maintained, your site will eventually become hacked through this vulnerable software. When engaging the services of a company that designs custom WordPress websites, you should ask them if they will be maintaining any custom software they install on your WordPress site.

    6. Install the Wordfence Firewall in “Extended Protection” mode

    Install the Wordfence plugin on your WordPress site. Go to the “Firewall” menu and enable “Extended protection”. This ensures the following:

    1. The Wordfence firewall code will inspect any request before it executes any PHP code including WordPress core code. That allows Wordfence to intercept and stop any vulnerability before it even reaches your PHP applications.
    2. Wordfence will also protect any other PHP applications that are installed off your WordPress base directory. This happens automatically and is an added benefit of Wordfence that many people aren’t aware of.

    We recommend you upgrade to Wordfence Premium if you can, to ensure that you receive the IP Blacklist, firewall rules and malware signatures in real-time as new attacks emerge.

    7. Perform a full Wordfence scan on your site

    Go to the Wordfence > Scan menu. Click the button to perform a Wordfence scan. This will perform a large number of security checks on your site and will ensure that your site is clear of any infection. Any issues that are found will be clearly displayed and need to be resolved.

    You can visit the Wordfence options page and scroll down to “Scans to Include” where you’ll find an option to “Scan files outside your WordPress installation”. You can enable this to have Wordfence scan all files outside of your WordPress root directory, even web applications that are not part of WordPress. This is a great way to get extended scan coverage for all of the files in your hosting account.

    8. Enable 2 Factor Authentication, aka Cellphone Sign-in

    Go to Wordfence > Tools. Click the tab at the top titled “Cellphone Sign-in”. Enable cellphone sign-in on all your administrator accounts. You can sign in using an SMS to your cellphone or using the Google Authenticator app.

    Enabling this feature will significantly improve the security of your WordPress admin accounts because anyone who signs in as an admin on your site will now have to verify that they know their password and also are in possession of their cellphone. A hacker will have to steal your cellphone and know your password to be able to sign in as you.

    Note that cellphone sign-in is a Premium Wordfence feature.

    Now share it!

    Completing these easy steps will provide you with a significantly more secure website than most WordPress installations on the web today. Share this post with the community to help other WordPress site administrators secure their websites.

    Now that you are done, we suggest you pour yourself a glass of something tall and cold and take a well deserved break. You’ve earned it!

    For a deeper dive on WordPress security, check out The WordPress Security Learning Center.

    The post 20 Minutes to a Secure WordPress Website appeared first on Wordfence.

  • Website Malware: Unwanted Exit to YourBrexit

    Website Malware: Unwanted Exit to YourBrexit

    Website Malware: Unwanted Exit to YourBrexit

    Some website hacks aim to make some political statements. Defacements are well known for this. Some infections redirect visitors to scam sites that push (usually counterfeit) goods or (often illegal) services. But what would you feel if your site redirected visitors to a political news site?

    This time we are talking about an attack that mainly targets UK sites and has redirected over 2 million (mostly UK) visitors to YourBrexit[.]net – a site that publishes politically-charged commentary about Brexit.

    Continue reading Website Malware: Unwanted Exit to YourBrexit at Sucuri Blog.