Online Services

Blog

  • Reminder to Update to WordPress 4.7.2 and Check Your Site

    During the past few weeks we have seen two WordPress core security updates. WordPress 4.7.1 was released on January 11th which was a security update. Then WordPress 4.7.2 was released a few days ago on January 26th.

    Both of these releases contain important security updates that fix known vulnerabilities in previous WordPress versions.

    These are ‘minor’ updates. That means that if you have a default install of WordPress, your site has probably been updated automatically, unless you have restrictive file permissions or some other restriction in place that prevents automatic updates.

    The Wordfence firewall currently protects against all vulnerabilities that are fixed in these two releases. This includes the privilege escalation vulnerability in 4.7.2 that was disclosed yesterday.

    If you do have automatic update enabled and your site has been updated to 4.7.2, we encourage you to visit your site and make sure that everything is functioning as expected. WordPress core releases are well tested, but it’s always better to be safe and to verify site functionality after a series of automatic updates like this.

    If you would like to learn how to change the automatic update behavior of WordPress, you can read about the WP_AUTO_UPDATE_CORE constant in wp-config.php. The default behavior of WordPress is to automatically upgrade your site to minor releases. And the default behavior is to not automatically update to major releases or development releases. Security releases like the ones mentioned above are ‘minor’ releases, so the updates are applied automatically.

    The post Reminder to Update to WordPress 4.7.2 and Check Your Site appeared first on Wordfence.

  • The January 2017 WordPress Attack Activity Report

    Last month we introduced a monthly attack activity report. This report gives you an indication of attack trends during the past month and how they have changed. Today we are releasing the January WordPress attack activity report which covers the period from January 1st until January 31st.

    Most Active IPs

    In the table below we have listed the most active attack IPs for January 2017. Note that the ‘Attacks’ column is in millions and is the total of all attacks that originated from each IP. Further right in the table (you may have to scroll right) we break out the attacks into ‘brute force’ attacks and ‘complex’ attacks.

    Brute force attacks are login guessing attacks. What we refer to as ‘complex’ attacks are attacks that were blocked by a rule in the Wordfence firewall.

    We have also included the netblock owner which is the organization, usually a company, that owns the block of IP addresses that the attack IP belongs to. You can Google the name of the owner for more information. A Google search for any of these IP addresses frequently shows reports of attacks.

    The hostname included is the PTR record (reverse DNS record) that the IP address owner created for their IP, so this is not reliable data but we include it for interest. For example, we have seen PTR records that claim the IP is a Tor exit node, but it is clearly not based on traffic.

    We also include the country and a country flag. To the far right of the report we show the date in January we started logging attacks and the date attacks stopped. For many of these IPs we logged attacks for the entire month. For some you can see there is a clearly defined attack ‘window’ where the IP started and stopped.

    The first interesting thing about our January attack data is that the same Ukraine IP holds the number one spot this January as we saw in December. Our top 3 attacking IPs all appeared in last month’s list.

    However, only 5 of the attacking IP addresses in this month’s top 25 also appeared in last month’s top 25 list. This is an illustration of how the IP addresses that attackers use are rotated out and new ones are used to launch attacks.

    The Seychelles attacker we saw last month has dropped off the list. In addition, we have Turkey appearing on the list for the first time with three IP addresses hosted at “Yalcin Kanbur trading as Webrano Hosting”, generating over 6 million attacks during January between them.

    India has also appeared on the list for the first time with an IP hosted at “Reliance Communications” generating around 2 million attacks during January.

    A Change in Complex Attacks vs Brute Force

    Last month we saw 66.7 million brute force attacks and 63.9 million complex attacks from our top 25 attacking IPs. You’ll recall that a complex attack is one that targets a plugin, theme or core vulnerability and is blocked by the Wordfence firewall.

    This month we’re seeing 64.1 million brute force attacks from our top 25 attacking IPs. However, this time around we’re only seeing 34.5 million complex attacks.

    This change indicates that the most prolific attackers have changed their strategy and are focusing more on brute force WordPress attacks than on trying to exploit vulnerabilities in WordPress core, themes and plugins.

    Brute Force Attacks on WordPress in January 2017

    Brute Force Attacks on WordPress in January 2017

    The chart above shows the brute force activity on WordPress sites that we saw in January. You’ll notice a huge spike in activity just before the middle of the month. This really gives you an idea of the kind of volatility that can occur.

    We will occasionally see situations like this where an attacker will gain access to servers that they can use as an attack platform. They will generate a huge amount of activity until their IPs are shut down by the hosting provider or network admin.

    In December we saw a similar spike but it only peaked at about 46 million attacks per day. In January the peak was approximately 53 million attacks per day.

    This contributed to an increase in the average attacks per day for January which was 26 million attacks per day compered to 20 million for December.

    Complex Attacks on WordPress in January 2017

    We saw a decrease in attacks on the Wordfence firewall in January 2017. The average number of attacks dropped from 5 million attacks per day in December to 4.7 million attacks per day in January.

    This decrease in the number of attacks is due to only a single large spike in attack traffic in January compared to a sustained spike in December that lasted more than 1 week.

    However the number of attacks in January during the low periods was significantly higher than in December with 3.5 million in December compared to 4 million at the lowest activity in January.

    Attacks on Plugins

    The table above shows the top 25 plugins that experienced the most attacks during January 2017. The table shows the rank in January, and then the change in ranking compared to December. If you scroll to the far right you can see the number of attacks per plugin during the period.

    The WP-Mobile-Detector plugin saw the biggest gain in the number of attacks, jumping 25 points in our rankings to position 12. The plugin has been removed from the WordPress plugin repository, probably because a vulnerability was not fixed by the author, and the last review was posted over 7 months ago.

    The plugin continues to see attacks, which may indicate that some WordPress sites still have this installed and are still vulnerable. It may also simply be because attack toolkits that attempt to exploit multiple vulnerabilities incorporate this exploit and then throw a series of exploits at websites in the hope that one of them works.

    Let me know in the comments if you have any additional data you’d like to contribute that may indicate reasons for plugin gains or losses in number of attacks, or any other insight you’d like to share.

    Attacks on Themes

    The table above shows attacks we saw on themes in January and we’ve included the change in ranking since December. The rankings for these themes are incredibly stable. The largest change we saw is “linenity” which has a local file inclusion or LFI vulnerability that became public knowledge back in April 2014. The vulnerability allows an attacker to download the wp-config.php file.

    The stability of the rankings in theme attacks suggests that there is not much innovation among attackers targeting themes for attack. They are likely using the same old attack toolkits that try to exploit the same old theme vulnerabilities and the rankings stay stable as the attack toolkits remain relatively unchanged.

    Attacks by Country

    In this report for the first time, we are including data on the number of attacks originating in each country. Because this is a new addition to our monthly attack activity report, we won’t have ranking change data for this month.

    The number of attacks below are the sum of brute force and complex attacks that originate in each country. It’s important to note that this does not indicate that a specific country’s government is launching attacks. Instead this is a general indication of the state of security in each country.

    There are a few factors that may cause an increase in attacks from a particular country:

    • The country simply has a large number of servers hosted within it’s borders. This is likely the case with the United States which has the most servers hosted within it’s borders out of any other nation.
    • The country may have a lack of enforcement when complaints are received. In other words, if local law enforcement is lax, there may be malicious hosting providers within the country that are able to act as attack platforms.
    • There may simply be a large hosting provider within the country that has a security problem and is inadvertently providing an attack platform via compromised servers for the rest of the world.

    Conclusion

    That concludes our first Wordfence Attack Activity Report of 2017. As always we welcome you to download the data in the tables above to perform your own analysis and share it here in the comments.

    Please post any questions or feedback in the comments and as always I will be around to try to answer them.

    Regards,

    Mark Maunder – Wordfence Founder/CEO.

    Special thanks to Dan Moen and other Wordfence team members who produced this report and who also tirelessly manage the code and infrastructure that enables us to provide this insight to the community. 

    The post The January 2017 WordPress Attack Activity Report appeared first on Wordfence.

  • Staying Safe: The Wordfence Cyber Security Survival Guide

    Occasionally at Wordfence we publish posts that are public service announcements that help the broader online community including your team, friends and relatives. Today I’m publishing a guide that will help improve your overall personal cyber security. This guide focuses on the basics: How to reduce the truly important life altering risks that we face from the cyber realm.

    This is a “cyber security survival guide”. In it I’m going to start by giving you a clear picture of the current state of cyber security. Then I’m going to help you prioritize what you should be protecting. In this guide I am focusing on the biggest risks that we are all presented with. This is, after all, a survival guide. Finally I will explain how to reduce risk for each category.

    I have written this guide to be as readable as possible. It is designed to be shared with your less technical friends and family. Most of my day is spent focusing on protecting our customer websites from attack. Today I am focusing on the bigger picture, the important basics, like protecting your physical safety and your basic financial means.

    “Si vis pacem, para bellum.” ~Vegetius. Circa 4th century.

    Translation: If you wish for peace, prepare for war.

    The hostile cyber security environment we find ourselves in today would startle even the most cynical predictions of a decade ago. This guide will improve the security posture of anyone who has an online presence, which today means everyone. In addition, today is “Safer Internet Day“, so this is our contribution to helping improve the safety of the online community.

    The State of Cyber Security

    Your data has a 2 in 3 chance of already having been stolen and it will be stolen again and again. It doesn’t matter if you use secure passwords and have two factor authentication enabled on your accounts. It doesn’t matter if you are old or young, male or female, which country you are based in or which services you use and which companies you do business with.

    At various points in your life your data will be stolen. And it will, in all likelihood, be stolen repeatedly.

    Today, 64% of Americans have already had their data stolen through data breaches. That is almost 2 out of three people. This percentage is rapidly trending towards 100% of the population in the US alone.

    In the past 3 years we saw the first data breach of over 1 billion user accounts with the Yahoo breach. That breach affected 1 in 7 people on planet Earth. In the United States, the OPM breach saw the data of our top spies stolen, including their fingerprints, personal data and their answers to some very personal questions during an interview using a lie detector. Even our intelligence services can’t protect highly confidential personnel data.

    Data has been stolen in the hundreds of millions of records from private companies, intelligence agencies and the military. Even companies who are experts in security have had their data stolen too.

    Data that has been stolen includes usernames, passwords, email addresses, social security numbers, biometric data, medical records and more.

    How Data is Stolen

    Even if you use a strong password, two factor authentication and security best practices, your data will still be stolen because the companies whose services you use in some cases will fail to protect their own networks.

    The trend at this point is undeniable and the track record so far makes it clear: Companies and government organizations are being breached at an increasing rate and the breaches are becoming increasingly severe.

    If you would like a visual representation that illustrates this point, visit dataisbeautiful.com and take a look at their bubble chart visual showing breaches since 2004. As you scroll up through the years, the bubbles become bigger and more abundant until they simply merge into each other.

    Prioritizing What We Need to Protect as Individuals

    If data breaches are the new normal and if you accept the premise that they are inevitable and unavoidable, the problem we need to solve in our personal and business lives becomes “How do I reduce the risk and the impact of a breach?”

    It’s helpful to start this conversation by prioritizing what we need to protect. Once again, in this post I am focusing on the really important items and people in our lives. In order of importance, in the cyber realm we need to protect:

    1. Information about us that may help criminals target us in the real world.
    2. Our financial means. In other words, savings accounts, ability to borrow and our assets.
    3. Sensitive personal information like medical records, tax data and other private data.
    4. Our ability to earn an income through our reputation and our ability to provide products or services, including our own labor, to others.

    The above list is, in my opinion, in order of importance.

    I think we all agree that our personal safety and the physical safety of those we care about is number one on the list. Most of the items on this list are things that can be fixed or recovered from. A human life is irreplaceable. Reducing the risk of real world targeting by criminals through the cyber realm is therefore at the top of the list.

    Financial means is second because without your savings and income, you don’t have the ability to feed, clothe and house yourself and your family. If your savings account is emptied, you may literally find yourself homeless without the ability to fend for yourself.

    Sensitive personal data is third on the list. Having sensitive medical data disclosed, for example, can irreparably damage or affect some people’s lives. This is not something that can be repaired or undone.

    Fourth on the list is our ability to earn an income. If you are not able to earn an income or damage your reputation, your quality of life and that of your family will be severely impacted.

    Preventing Real World Targeting via Cyber

    In most developed countries, it is rare to hear stories of real-world targeting of individuals through information they have ‘leaked’ into the cyber realm. Most of the world is still developing economically and has a high disparity in wealth distribution. The reality in many countries that are still developing is that crime is significantly higher than developed countries like the United States, Australia or the United Kingdom, for example.

    Kidnapping for ransom, carjacking and robbery is a reality in many parts of the world. In order to reduce your own risk of being targeted if you are in a high risk environment, I suggest the following:

    1. Never flaunt high value items online, including cars and jewelry.
    2. Share your location in general terms and if you want to share a specific location, do it after you have left that location.
    3. Don’t share information that may indicate when you have been paid.
    4. Consider making social profiles only accessible to people you have approved. Your social profile can provide someone with enough data to give you the impression they know you or are a friend of a friend.
    5. If you work in a job with privileged access or access to sensitive data, avoid disclosing who your employer is and your position. This includes disclosure on public websites like LinkedIn.

    Protecting Your Financial Means

    In this section I’m not concerned with credit card fraud. That risk falls on the vendor and the transactions can be reversed. Instead, I’m focused on the kind of risk that can have a permanent impact on your long term financial well-being.

    If an attacker is able to authorize a wire transfer from your savings account, they can empty your bank account and the funds may never be recoverable. This risk applies to savings accounts, checking accounts and investments like brokerage accounts and money market accounts.

    If they are able to borrow in your name, it can permanently damage your credit score and your ability to borrow money to buy a home, for example.

    I suggest taking the following steps to reduce the risk of large scale financial fraud:

    1. Make a list of savings accounts and investment accounts. Audit each account to determine how you prove your identity when transferring funds and get a clear understanding of what an attacker would need to do to commit fraud on each account. Contact banks, brokerages and lenders where necessary to get the data you need.
    2. Implement any additional security that your bank provides. This may include:
      • A callback to a predetermined number,
      • Authorization from multiple parties required before transferring funds,
      • Two factor or hardware based authentication and
      • Limiting transaction size when you are not at the bank in person to perform the transaction.
      • Your bank may also provide real-time alerts when a transaction is processed.
    3. Monitor your account statements weekly for unauthorized activity. Make this a routine.
    4. If you are in the United States, place a credit freeze on your credit report. This restricts access to your credit report and makes it difficult for thieves to open new accounts in your name which allows them to borrow money as you. You may have a similar option in your own country if you don’t live in the USA.
    5.  Also in the US, you can place a fraud alert on your credit report. This lasts 90 days and forces a business to verify your identity before issuing credit in your name. You can renew the fraud alert every 90 days. Outside the US you may find that your own country has similar protections available that prevent unauthorized borrowing.

    In all of the above cases if you are able to choose a password, use a complex password and use a password manager like 1Password to store and manage your long and complex passwords.

    Protecting Sensitive Data About You

    Sensitive data that you need to protect may include medical records, tax information and your own social security number. There are two surprisingly easy ways you can help protect your own personal data.

    Firstly, try to avoid creating data about yourself. If it doesn’t exist, it doesn’t need protection. You will frequently find forms that ask you for your social security number or equivalent. Most of the forms I encounter asking for this don’t actually require that information. I simply don’t enter it and rarely receive a complaint. Skip any optional forms and optional form fields. When entering sensitive data, find out if it is required or optional.

    Secondly, the best way to protect data is to delete it. Once again, if it doesn’t exist, it doesn’t need protection. If you have old data on a workstation that is sensitive but that you don’t need to keep, delete it and empty your trash to permanently delete the data. If you have old databases lying around on servers that you don’t need but that present a risk, delete them. Don’t hoard sensitive data.

    Where you do need to store and protect data on your own systems, use hard drive encryption if it is available for your operating system. Password protect your devices including your cellphone, tablets, laptops and workstations. Use complex codes, gestures or passwords.

    In the medical domain it is difficult to protect your data. You don’t control where the data is stored and who has access to it. Medical data can be shared widely among providers which creates a large attack surface with many potential points of entry. Currently the best approach is to do your best to avoid creating data about yourself in the first place.

    Protecting Your Ability to Earn an Income and Your Reputation

    Most of us rely on IT infrastructure in some way to make our living. Whether you are an architect, photographer or computer programmer, it is important that you secure the systems you use. Here are a few tips to secure your own systems and the services you use:

    • If you publish a WordPress website, install a malware scanner and firewall like Wordfence to keep hackers out and detect any intrusions.
    • Use a password manager like 1Password to automatically generate and store long complex passwords that are different for each system you access. That way if one provider experiences a data breach, your other accounts won’t be compromised.
    • Secure your phones, tablets and workstations by using disk encryption where available on workstations and use complex passwords, codes or gestures that are required to gain access.
    • Avoid adding data to systems and services that you don’t need to. Once again, the best way to protect data is to delete it or to not create it in the first place.
    • Enable two factor authentication on all services that you use.
    • Consider using a YubiKey for cloud services. A YubiKey is a hardware two-factor authentication device. An increasing number of cloud providers are supporting hardware authentication. Enable this where you can. YubiKey adoption is increasing rapidly as it becomes more popular.
    • Keep backup drives in a secure place and destroy their data if they are no longer needed. Never simply throw backup drives or devices in the trash. They need to be wiped using secure drive wiping software.

    Protecting Your Reputation

    If you use social media, never simply ‘Share’ or retweet someone else’s post until you have fully read it, understood it and also understand any context around it. If you accidentally share something that is highly controversial without fully understanding what you’re sharing, you may find your professional reputation severely damaged.

    Secure any social media accounts that you own. If your account is hacked, it may be used for spam which could damage your online reputation.

    Secure any websites that you own. If your website is hacked, it will damage your search engine ranking and infuriate your customers if their data is stolen. This can have a severe impact on your reputation. If you use WordPress, install Wordfence which will help prevent a hack.

    Make sure that your email accounts are secure. If your email account is compromised, your contacts list is also compromised. This usually results in your contacts receiving phishing emails that also try to hack their email accounts. They may also receive spam. This will damage your reputation among your contacts. Brian Krebs has a great writeup on the value of a hacked email account.

    When installing apps on your smartphone, avoid installing apps that are aggressively viral. Some apps gain access to your contacts list and can SMS, private message or email your contacts a message from you that suggests they also sign up for the service. These messages can be infuriating and won’t help your reputation among your friends and colleagues. When installing a new app, think before you click.

    Additional Tips and Techniques

    How to Avoid Social Engineering

    Social Engineering is what happens when someone phones you and pretends to be an organization or individual that you trust. They will try to get sensitive information out of you including passwords, usernames and a description of systems that you have access to.

    This kind of attack is common and is used to commit tax refund fraud. It is also used to gain access to your bank accounts. You will even find attackers trying to get access to your workstation by telling you that they have found something wrong and asking you to install their software to fix it.

    To avoid social engineering you can use a simple technique. Usually the individual will claim they’re from a reputable company or organization. Simply hang up, find the organization’s central number, call back and ask for that individual or someone in the same role.

    Don’t let the person who called you provide the number you call back. Instead find the central number via Google or elsewhere online and call that instead. If it’s an IRS agent, call the IRS back yourself. Use this technique no matter how friendly, polite, aggressive or scary the person on the other end of the line is.

    Using the callback method is an effective way to defeat social engineering.

    How to Avoid Phishing and Spear Phishing

    Phishing is when someone sends you an email that looks like it came from a bank or service you trust. They try to get you to open an attachment that compromises your device or to click on a web link and to sign in on a malicious website.

    Spear phishing is the same as phishing, except the email you receive is especially crafted just for you. The attacker has researched you well and knows who your friends, family and associates are. They may know who you work for and what you are working on. The phishing email received in a spear phishing campaign looks much more authentic, appears to come from someone you know and may refer to something you are working on. Spear phishing attacks have a much higher success rate.

    To avoid spear phishing campaigns, follow these two simple rules:

    1. Never open an attachment unless you are 100% sure that someone you trust sent it to you. If in doubt, phone them to verify they sent you the file.
    2. Never click on a website link unless you are 100% sure that the person or organization that sent it to you is someone you trust. When you do open the link, check your browser location bar at the top for the following:
      • The location should start with https://
      • The part after https:// should be the domain name of an organization you trust. For example, it should say paypal.com and not paypal.com.badsite.com. Everything from the first forward slash to the final forward slash in the location should be a name that you trust.
      • The https:// part should be green if you are using Chrome and it should also say “Secure” to the left.

    If you receive an email that makes you suspicious in any way, don’t click anything in it, don’t open any attachments, and don’t reply to the email. Instead, contact the person or organization that sent it and ask them what it is about.

    Some of the largest data breaches are as a result of spear phishing attacks and the average cost of a successful spear phishing attack is $1.6 million.

    Use a Password Manager

    I have mentioned 1Password several times in this post as an example of a password manager that helps you use unique passwords across all the services that you use. Using long, complex and unique passwords is one of the most effective things that you can do to protect yourself against future data breaches.

    There is an argument that all your “eggs” are in one basket when using a password manager. However, among security professionals it is widely agreed that this risk is outweighed by the benefit of being able to reliably use unique complex passwords across services.

    Don’t Create Data You Don’t Have to, Delete Data You Don’t Need

    I mentioned this earlier in the post but it bears repeating: to protect yourself from future data breaches, avoid creating data you don’t have to and delete data you don’t need.

    Deleting data includes any profiles on websites that you don’t use anymore. If you are on a social media website that you don’t use, delete your profile. The recent MySpace breach that was announced is a great example. Many people don’t use the service anymore, but last year a MySpace breach was announced that affected over 300 million accounts.

    Use Backups to Protect Yourself Against Ransomware

    One final tip. Ransomware is malware that encrypts your entire hard drive and forces you to pay a hacker to get your data back. Sadly this attack is very effective and many people pay to get their data back, including large organizations. Two thirds of companies that fall victim to ransomware actually pay the ransom.

    Use backups to protect yourself against a ransomware attack. Make sure that your backups are not connected to the computer you are trying to protect once the backups have completed or the ransomware may also encrypt your backup drive.

    Crashplan is a cloud backup service that can protect you against ransomware. We don’t have any commercial relationship with them but we have heard good things.

    Help Keep Friends and Family Safe

    I hope this cyber security survival guide improves your security posture online. I have kept it as readable and accessible as possible so that the guide is usable by technical and non-technical readers alike. You can help improve online and offline safety by sharing this with friends and family that may benefit by reading it.

    Stay safe!

    Mark Maunder – Wordfence Founder/CEO.

     

    The post Staying Safe: The Wordfence Cyber Security Survival Guide appeared first on Wordfence.

  • A Feeding Frenzy to Deface WordPress Sites

    In this report we share data on the ongoing flood of WordPress REST-API exploits we are seeing in the wild. We include data on 20 different site defacement campaigns we are currently tracking.

    We show how attackers have switched to the REST-API exploit and how it has increased their success rates. We have also seen an evolution in the attack method targeting the REST-API exploit and have evolved our rule-set accordingly. We also demonstrate how hackers are competing to deface sites using the REST-API exploit.

    This report highlights the immediate need to protect your site against this attack. Both our attack data and our site cleaning team’s observations are indicating that this attack is having a wide impact.

    Background on the REST-API Vulnerability

    On January 26th, WordPress released version 4.7.2 which contained a security fix for a vulnerability that allows attackers to modify content on a WordPress site. They did not announce the fix at the time so that attackers would not be aware of the vulnerability while the WordPress auto-update mechanism updated vulnerable sites.

    The hidden security fix was announced on  February 1st, six days later, at which time attackers became aware of the exploit. By that time a substantial number of WordPress websites had updated to version 4.7.2.

    We immediately deployed a firewall rule to our Premium customers on February 1st and started logging attacks targeting the REST API vulnerability. We didn’t see many attacks until February 3 when volume started picking up.

    Attacks continued and February 6th we saw attackers had discovered a new variant on the attack which bypassed our rule and the rules that other firewall vendors had put into place. We immediately deployed a second rule to our Premium Wordfence customers which was pushed out in real-time early on February 6th.

    The new rule is in red on the chart above and shows how attackers massively ramped up the volume of attacks they were launching using this new, more successful variant of the attack. The chart above is up to midnight last night, Pacific time. We have confirmed that the second newer variant of the attack still bypasses at least one major cloud firewall vendor as of 10am PST this morning.

    This vulnerability has resulted in a kind of feeding frenzy where attackers are competing with each other to deface vulnerable WordPress websites. During the past 48 hours we have seen over 800,000 attacks exploiting this specific vulnerability across the WordPress sites we monitor.

    If you are using Wordfence Premium, you are fully protected against this vulnerability, even if you are running an older vulnerable version of WordPress. There are multiple variants of the REST-API exploit and the Wordfence firewall Premium rule-set protects against all of them.

    Tracking REST-API Defacement Campaigns

    The attackers using the REST-API exploit are defacing websites by leaving their own signature on a defaced WordPress page. We are currently tracking 20 different defacement campaigns.

    The table below shows the total attacks for each campaign, the number of unique WordPress websites attacked and the number of IP addresses that each attacker is using. On the far right we also include the number of defaced pages for each campaign, according to this morning’s Google results.

    Success Rates for REST-API Attack Campaigns

    To determine which campaigns have the highest success rate, we did a Google search for each campaign name in quotes. This gives us an indication of the approximate number of defaced pages per campaign. The actual numbers are in the table above in the far right column.

    In some cases the attacker may have used a different exploit to deface a page. However, as you’ll see below, the number of defaced pages for each of these campaigns has increased dramatically since the emergence of the REST-API exploit.

    How the REST-API vulnerability has increased total compromised sites over time

    By using Google Trends, we can get a good indication of the success rate of our attackers over time. Using Trends, we found that since mid 2014, these campaigns have had little success compromising websites.

    Then starting in early February when the REST API vulnerability was disclosed, the success rate for these campaigns massively increased. Google started indexing compromised pages and it shows up in Google trends:

    If we change the scale of the chart to just show 2017, you can see the huge spike in success these attack campaigns have had infecting WordPress websites using the REST-API vulnerability. This spike coincides exactly with the date the REST-API vulnerability was disclosed.

    Well Known Attackers Switching to the REST-API Exploit

    Lets take a look at our top defacer. If we look at the list of MuhmadEmad’s compromised sites on Zone-H.org, he usually drops a file called krd.html or defaces the home page. The content usually looks like this.

    On zone-h, which is an archive of hacked sites, it is clear that he took a break for a couple of days after the REST-API attack emerged on February 1st, perhaps to develop a new exploit.

    Then he started attacking starting February 4th, and you can see the compromised URLs change to individual defaced WordPress pages:

    Hackers Competing to Compromise Sites

    In some cases we are seeing hackers competing to deface sites. On the defaced page below you can see HolaKo has defaced the current page, and the link to the next page shows that the following page is defaced by ‘Imam’.

    In some cases we can see defaced pages being defaced again by another attacker. The hackers are getting hacked. This page was defaced by ‘Imam’:

    But when you visit the page, the title has now been changed to show another defacer has taken over.

    Sites that suffer from this vulnerability will continue to be defaced and re-defaced until they either install a firewall like Wordfence or upgrade to WordPress 4.7.2.

    Top 25 Attacking IPs Exploiting the REST-API Vulnerability

    The following is a list of the top 25 IP addresses by number of attacks, that are exploiting the WordPress REST-API vulnerability. If you are a security researcher you’re welcome to download this table and incorporate it into your own research.

     

    Conclusion

    This is one of the worst WordPress related vulnerabilities to emerge in some time. Our site cleaners have been working with site owners all week to help them clean defaced sites. In every case the customer was not running our Premium firewall and had not updated to WordPress 4.7.2.

    If you have not been able to update to WordPress 4.7.2 but are using Wordfence Premium, you have been protected against this since exploitation started.

    As always, I will be around to reply to your comments.

    Mark Maunder – Wordfence Founder/CEO.

    The post A Feeding Frenzy to Deface WordPress Sites appeared first on Wordfence.