Online Services

Blog

  • Thousands of Hacked Home Routers are Attacking WordPress Sites

    Last week, while creating the Wordfence monthly attack report, we noticed that Algeria had moved from position 60 in our “Top Attacking Countries” list to position 24. That was a big jump and we were curious why Algeria had climbed the attack rankings so rapidly.

    What we discovered on closer examination is that over 10,000 IP addresses in Algeria were attacking WordPress websites in March. Most IPs were only launching between 50 and 1000 attacks during the entire month.

    The following chart is a histogram. It groups IP addresses by the number of times they attacked. As you can see by the spike on the left, the most common number of attacks was around 100 to 200 for an IP address. Few of the attacking IPs generated more than 2,000 attacks during the entire month of March, 2017.

    We wanted to learn more about these attacking IPs, so we dug a little deeper.

    A Botnet Using Burst Attacks

    We extracted the list of Algerian attack IPs and we included the time of first attack logged and the time of last attack logged. The majority of the IPs spent just a few hours attacking and then stopped for the rest of the month. The histogram below shows how many IPs spent less than a day (shown as 0) attacking compared to those that spent 1 or more days. As you can see over 7,000 IPs spent just a few hours attacking during March before they stopped.

    These IPs switch on, perform a few attacks and then switch off and aren’t heard from again for a month. What we have found is a botnet that is distributed across thousands of IPs. Each IP is only performing a few attacks, those attacks are spread across many websites and the attacks only last a few minutes or hours.

    The attacker controlling this botnet is using several evasive techniques. They are spreading their attacks across a very large number of IP addresses. They are using low frequency attacks to avoid being blocked. They are also spreading their attacks across a large number of WordPress sites.

    These evasive techniques indicate a higher level of sophistication than we see from, for example, “PP Sks-Lugan” which we’ve written about in the past where we see a single IP generating millions of attacks.

    Hacked Home Routers Hacking WordPress

    When we looked at who owns each of the attacking IPs in Algeria, we found, over 97% of them are owned by Telecom Algeria. There are approximately 30 different ISPs in Algeria. We do see some attacks from other networks, but nothing compared to the volume that originates from Telecom Algeria.

    The attacks we saw in March originated from the following networks:

    • 41.96.0.0/12 which ranges from 41.96.0.0 to 41.111.255.255 had 4671 attacking IPs in March.
    • 105.96.0.0/12 which ranges from 105.96.0.0 to 105.111.255.255 had 4591 attacking IPs in March.
    • 154.240.0.0/12 which ranges from 154.240.0.0 to 154.255.255.255 had 715 attacking IPs in March.
    • 197.112.0.0/13 which ranges from 192.112.0.0 to 197.119.255.255 had 401 attacking IPs in March.

    Telecom Algeria is the state owned telecommunications provider in Algeria. It is therefore the largest telecommunications provider in the country.

    We performed a network survey on a sample of 8,962 IPs on Telecom Algeria’s network. We received responses from 3,855 IP addresses.

    Out of those IPs we discovered that  1501 are Zyxel routers that are listening on port 7547 and are running “Allegro RomPager 4.07 UPnP|1.0 (ZyXEL ZyWALL 2)”.

    Allegro RomPager 4.07 is an embedded web server that has a severe vulnerability, dubbed the Misfortune Cookie by Checkpoint, who discovered it in 2014. The identifier is CVE-2014-9222.

    It appears that attackers have exploited home routers on Algeria’s state owned telecommunications network and are using the exploited routers to attack WordPress websites globally.

    Other ISPs With Vulnerable Routers

    Algeria drew our attention because its country ranking jumped from 60 to 24 in our top attacking countries for March. Once we took a closer look at the attacking IPs, we were able to identify a specific pattern of behavior for these attack IPs:

    • They generally attack for less than 48 hours and then stop.
    • Most of them generate less than 1000 attacks.
    • There is usually a large number of attacking IPs on a single ISP.

    By searching for similar patterns, we found that there are several other ISPs that seem to have the same problem that Telecom Algeria has.

    BSNL – India

    BSNL is a state owned telecommunications provider in India. During March we saw attacks from 11,495 IPs on their network.

    In a survey of BSNLs network, we found that:

    • 11,495 IPs on BSNLs network attacked WordPress sites in March.
    • Out of those attacking IPs, 4857 IPs also have port 7547 open.
    • We found that 1635 of the IPs that attacked WordPress sites are also running “Allegro RomPager 4.07 UPnP|1.0 (ZyXEL ZyWALL 2)” which is vulnerable.

    PLDT aka. Philippine Long Distance Telephone

    PLDT is the largest telecommunications provider and digital services company in the Philippines.

    In a survey of PLDT’s network we found that:

    • 3697 IPs on their network attacked WordPress sites in March.
    • 1612 of those attacking IPs on PLDTs network have port 7547 open.
    • 137 of those IPs are running “Allegro RomPager 4.07 UPnP|1.0 (ZyXEL ZyWALL 2)” which is vulnerable to remote exploitation.

    28 ISPs with Suspicious Attack Patterns Indicating Compromised Routers

    Once we could identify the attack pattern of compromised routers, we searched for other ISPs where the attack patterns fit the same criteria. That is, low frequency of attacks, each IP attacks for less than 48 hours and a large number of IPs are attacking WordPress sites from a specific ISP.

    This is the full list of ISPs we found globally where attacks that match this criteria are originating from. Notice the low “average attacks per IP column” on the right of the table (scroll right) and the large number of attacking IPs per ISP.

    What is port 7547 and TR-069 and why is it a problem?

    Port 7547 is a management port on home routers. It allows ISPs to manage the routers that their customers use on their home networks. It uses a protocol called TR-069 to provide a management interface. The TR-069 protocol can be used to provision devices, provide tech support and remote management, monitor routers for faults, for diagnostics, to replace a faulty configuration and to deploy upgraded firmware.

    This protocol and port has had at least two serious security vulnerabilities associated with it in the past 4 years.

    We have already mentioned the misfortune cookie vulnerability which targets management port 7547 and which some of the ISPs above are suffering from. RomPager version 4.07 suffers from the misfortune cookie vulnerability. In the ISPs that we are seeing attacks originating from, 14 out of 28 ISPs have remotely accessible routers that have a vulnerable version of RomPager version 4.07 on port 7547

    Another vulnerability emerged in November last year which allows an attacker to use port 7547 and the management interface to gain administrative access to a router.

    6.7% of Attacks on WordPress Sites are from Home Routers with Port 7547 Open

    In addition to the network surveys we did on ISPs from which attacks are originating, we also surveyed 865,467 additional IP addresses which have engaged in brute force or complex attacks during the past 3 days. Out of those, 57,971 have port 7547 open indicating that they are home routers from which attacks are originating.

    That means that 6.7% of all attacks on WordPress sites that we protect, during the past 3 days, came from home routers that have port 7547 open.

    Shodan, an internet survey search engine, currently shows that over 41 million devices on the Internet are listening on port 7547. The TR-069 protocol is widely used among ISPs world-wide.

     

    The Security Risk to Home Users

    If a home router is successfully exploited, an attacker can access your internal home network. They have penetrated any firewall function that the router provides and can also bypass router network address translation. This enables them to exploit internal targets like workstations, mobile devices using WiFi and IoT devices like home climate control systems and home cameras.

    We are already seeing bulk exploitation of TR-069 which has turned home routers into a botnet attacking WordPress sites. It is quite feasible that home network exploitation is already underway as well.

    Security Risk to the Internet at Large

    OVH was hit by a 1 Terabyte DDoS attack in September last year, one of the largest in history. Approximately 152,000 IOT (Internet of Things) devices that had been compromised generated the traffic in that attack.

    In just the past month we have seen over 90,000 unique IP addresses at 28 ISPs that fit our compromised-router attack pattern. We monitor these attacks across our customer websites which is an attack surface of over 2 million websites. We only see a sample of the attacks that all websites globally experience. If you extrapolate the numbers, it indicates that there is a very large number of compromised ISP routers out there performing attacks and acting in concert.

    At this point it would not be a stretch to say that vulnerabilities in TR-069 may have created a very large botnet which could soon generate the largest DDoS attack the Internet has ever seen.

    How ISPs can help

    Exposing port 7547 to the public Internet gives attackers the opportunity to exploit vulnerabilities in the TR-069 protocol. ISPs should filter out traffic on their network coming from the public internet that is targeting port 7547. The only traffic that should be allowed is traffic from their own Auto Configuration Servers or ACS servers to and from customer equipment.

    There are already a large number of compromised routers out there. ISPs should immediately start monitoring traffic patterns on their own networks for malicious activity to identify compromised routers. They should also force-update their customers to firmware that fixes any vulnerabilities and removes malware.

    What we are doing

    At Wordfence we run a real-time IP blacklist for our premium customers. We are adjusting our blacklist algorithms to identify and include IP addresses that engage in these kinds of attacks. We are also working to create awareness among ISPs and security professionals about the risk that TR-069 presents and how they can help to mitigate that risk.

    The post Thousands of Hacked Home Routers are Attacking WordPress Sites appeared first on Wordfence.

  • Check if your Home Router is Vulnerable

    At Wordfence, we make a firewall and malware scanner that protects over 2 million WordPress websites. We also monitor attacks on those sites to determine which IPs are attacking them and we block those IPs in real-time through a blacklist.

    Tuesday morning we published a post showing how 6.7% of all attacks we see on WordPress sites come from hacked home routers. In the past month alone we have seen over 57,000 unique home routers being used to attack WordPress sites. Those home networks are now being explored by hackers who have full access to them via the hacked home router. They can access workstations, mobile devices, wifi cameras, wifi climate control and any other devices that use the home WiFi network.

    Half of the internet service providers we analyzed have routers with a very specific vulnerability. This vulnerability is known as the “misfortune cookie”. We will call it the MC vulnerability for short. It has been known for a few years and was first disclosed by CheckPoint in 2014. It is now being used to hack home routers. Using the tool below you can tell if you have the MC vulnerability.

    The MC vulnerability exists in a service that your ISP uses to remotely manage your home router. That service listens on a “port” number, which is 7547. Besides the MC vulnerability, this port can have other vulnerabilities, one of which was disclosed a few months ago. Researchers have been discussing the dangers of port 7547 in home routers for a few years now.

    Your ISP should not allow someone from the public internet to connect to your router’s port 7547. Only your ISP should be able to access this port to manage your home router. They have the ability to configure their network to prevent outsiders from accessing that port. Many ISPs do not block public access to port 7547.

    You can use the tool below to determine if your port 7547 is open to the public internet. If it is, we suggest you contact your ISP and ask them to prevent outsiders from accessing that port on your home router. Even if you aren’t vulnerable to one of the two vulnerabilities we posted above, future vulnerabilities may emerge on port 7547. By blocking public access you will protect yourself and your home network.

    Check if you are vulnerable

    To use this tool, simply click the ‘Scan me’ button and we will check the IP you are visiting this site from to determine if port 7547 is open on your router and if it is vulnerable to the misfortune cookie vulnerability.

    Scan me

    What to do with the results

    If you are vulnerable, we recommend that you:

    • Immediately reboot your home router. This may flush any malware from your home router.
    • Upgrade your router firmware if you can to the newest version. Close port 7547 in your router config if you are able to. (Many routers don’t allow this)
    • If you can’t upgrade your own firmware, immediately call your ISP and let them know you have a serious security vulnerability in your home router and you need help fixing it. You can point them to this blog post (the page you are on) and this CheckPoint website for more information. Let them know that your router has a vulnerability on port 7547 in “Allegro RomPager” that can allow an attacker to access your home network and launch attacks from your router on others.
    • Run a virus scan on all your home workstations.
    • Update all home workstations and devices to the newest versions of operating system and applications or apps.
    • Update any firmware on home devices where needed.

    If you are not vulnerable, but port 7547 is open on your router, we recommend that you:

    • Reboot your home router immediately. You may suffer from other port 7547 vulnerabilities.
    • Upgrade your router firmware if you can.
    • Close port 7547 on your router if you can. (Many routers don’t allow this)
    • Contact your ISP and let them know that port 7547 on your home router is accessible from the public internet. Let them know that port 7547 is used by your ISP to manage the router. It should not be publicly available. Suggest that they filter access to that port to prevent anyone on the public internet accessing it.

    How you can help

    According to Shodan, a popular network analysis tool, over 41 million home routers world-wide have port 7547 open to the public internet. We are trying to get the word out to home users and ISPs to block this port and patch any vulnerable routers. This will help reduce attacks on the websites we protect and, far more importantly, it will help secure over 41 million home networks.

    We found over 10,000 infected home routers in Algeria who use Telecom Algeria for internet access. These are home networks that have already been hacked. We found over 11,000 hacked home routers in India with BSNL, another major ISP in that country, where the routers have already been hacked. Let’s help secure our fellow internet citizens and prevent others from having their home networks compromised.

    You can help by sharing this post and empowering home users to check if they are vulnerable. They can then contact their ISPs with the information and this will gradually cause ISPs to close port 7547 to outside access and to disinfect and patch vulnerable routers.

    The post Check if your Home Router is Vulnerable appeared first on Wordfence.

  • The March 2017 WordPress Attack Report

    Today we are releasing the WordPress Attack Report for March, 2017. You can also find the following previous attack reports on our blog: December 2016, January 2017 and February 2017.

    This report contains the top 25 attacking IPs for the month of March and their details. It also includes charts of brute force attack activity and complex attack activity for the period. We also include the top themes and plugins that were attacked and which countries generated the most attacks for the period.

    One of the more surprising data points in this report is the rise of Algeria as a source of attacks. After creating this report we dug a little deeper and will be releasing our additional findings regarding Algeria next week.

    The Top 25 Attacking IPs

    I’m including our usual explanation of how the table below works. If you’re familiar with our attack reports, you can skip down to the table below which contains the March data and read my comments that follow the table.

    Brief introduction if you’re new to viewing these reports

    In the table below we have listed the most active attack IPs for March 2017. Note that the ‘Attacks’ column is in millions and is the total of all attacks that originated from each IP. Further right in the table (you may have to scroll right) we break out the attacks into ‘brute force’ attacks and ‘complex’ attacks.

    Brute force attacks are login guessing attacks. What we refer to as ‘complex’ attacks are attacks that were blocked by a rule in the Wordfence firewall.

    We have also included the netblock owner, which is the organization, usually a company, that owns the block of IP addresses that the attack IP belongs to. You can Google the name of the owner for more information. A Google search for any of these IP addresses frequently shows reports of attacks.

    The hostname included is the PTR record (reverse DNS record) that the IP address owner created for their IP, so this is not reliable data but we include it for interest. For example, we have seen PTR records that claim the IP is a Tor exit node, but it is clearly not, based on traffic.

    We also include the country and a country flag. To the far right of the report we show the date in March when we started logging attacks and the date attacks stopped. For many of these IPs we logged attacks for the entire month. For some you can see there is a clearly defined attack ‘window’ where the IP started and stopped.

    The Top Attacking IPs

    Our top two attacking IPs are in Russia and Ukraine respectively. Both of them are only launching complex attacks on WordPress. Our top IP has doubled its attacks from 7 million to 15 million attacks. Our second place IP went from 7 million to 12 million attacks per month.

    The total number of complex attacks from the top 25 IPs went from 63 million in February to 85 million in March. The total brute force attacks from the top 25 IPs increased from 18 million in February to 32 million in March. This indicates an increase in how aggressively these top 25 IPs are attacking sites.

    If we cluster the top 25 attacking IPs by country, it becomes apparent that Ukraine is by far the top source for attacks. We also have a surprisingly large number of top attacking IPs from Turkey in March.

     

     

     

     

    Brute Force Attacks on WordPress in March 2017

    The chart below shows the brute force attack activity on WordPress sites that we monitor for the month of March.

    We saw a slight increase in the average daily attacks from 30 million in February to 34 million in March. Not a big change, so in general the attack frequency and activity is fairly steady. In February we saw a huge sustained spike in activity towards the end of the month. We did not see that in March for brute force attacks.

    Complex Attacks on WordPress in March 2017

    The graph below shows complex attacks (attacks that try to exploit a vulnerability) for the month of March 2017.

     

    The average daily attacks increased from 3.4 million in February to 3.8 in March. In February the attack graph was fairly constant throughout the month. March saw a huge spike early in the month which quickly subsided.

    Once the spike subsided, we saw a sustained period of relative calm with only 3 million attacks per day and then a gradual pick-up later in the month.

    Attacks on Themes in March 2017

    The table below shows the total number of attacks on WordPress themes. We identify each theme using it’s ‘slug’ which is the directory in which it is installed in WordPress.

    There is some movement in the rankings, but for the most part the same themes are being targeted.

    One interesting change we noted is that for the month of March, the attacks are more spread out. Below we generate a graph showing the “long tail” of attacks on themes. We have created a distribution from left to right of the most attacked themes to the least attacked. It creates a curve which is commonly known as a “long tail” among statisticians.

    As you can see, for the month of March, the long-tail flattens out because we are seeing attacks more evenly distributed across themes, rather than focusing on a smaller number of frequently attacked themes.

     

    Attacks on Plugins in March 2017

    The table below shows the attacks we saw on plugins across the sites Wordfence protects. As with themes, we identify each plugin by its unique ‘slug’ which is the unique installation directory where the plugin is installed.

    The list of plugins being targeted has had some shuffling around, but as you can see, all plugins in the list are well known targets of attack that are generally in the top 50 attacked plugins for WordPress.

    If we look at the long-tail distribution for plugins we can see that the attack distribution has not changed much and is still roughly the same as February.

     

    Attacks by Country for March 2017

    The table below shows the top 25 countries that attacks originated from in the month of March on WordPress sites that we monitor. The most surprising thing in this list is the sudden appearance of Algeria as an attack source. In our previous report, Algeria was ranked way down at 60 for total attacks.

    We will be posting a follow-up post which explains why Algeria has suddenly jumped in the country rankings. We dug a little deeper and found some very interesting data that we will be including in a report which we expect to release next week.

    Conclusion

    I hope you’ve enjoyed this overview of the WordPress attack landscape. If you are in the threat intelligence field, I encourage you to grab this data and incorporate it into your own analysis. I know some of you already have and have shared your findings with us privately and I very much appreciate that.

    We will be publishing a follow-up to this report describing why Algeria has risen in the attack ranks some time next week.

    The post The March 2017 WordPress Attack Report appeared first on Wordfence.

  • WordPress Security – Unwanted Redirects via Infected JavaScript Files

    WordPress Security – Unwanted Redirects via Infected JavaScript Files

    WordPress Security – Unwanted Redirects via Infected JavaScript Files

    We’ve been watching a specific WordPress infection for several months and would like to share details about it.

    The attacks inject malicious JavaScript code into almost every .js file it can find. Previous versions of this malware injected only jquery.js files, but now we remove this code from hundreds of infected files. Due to a bug in the injector code, it also infects files whose extensions contain “.js” (such as .js.php or .json).

    Continue reading WordPress Security – Unwanted Redirects via Infected JavaScript Files at Sucuri Blog.