Online Services

Category: Security

  • Wordfence Is Now Defiant

    Today we are announcing that our company name is changing to Defiant Inc. Over the past 5 years we have grown significantly and have expanded beyond WordPress. As a security organization, we now have a stable of products and services to offer our customers. To reflect this change, we are changing the name of the company that produces Wordfence to Defiant Inc.

    Our new corporate website will be defiant.com. We have written a full announcement with more details on the Defiant.com blog. I recommend you head over there and read about this exciting change and where our company is headed.

    I know that some of you may have questions about this change, so to put your minds at ease, I’m including a short FAQ about the name change below:

    Why are you changing your company name?

    For legacy reasons, until this point our company name has been Feedjit Inc. But that name has nothing to do with security or the products and services we offer. It is related to an old business we were in many years ago that provided real-time analytics services.

    We have been growing so fast since the 2012 Wordfence launch that we never got around to changing our corporate name. Today, we are finally doing that, and we are very excited to announce our new company name, Defiant Inc., and our new corporate website at defiant.com.

    Why didn’t you change the name to Wordfence Inc?

    Our team provides a growing stable of products and services. You can read more about those on the Defiant website in our announcement. Some of those security products are not just for WordPress – they support Joomla, Magento and other platforms.

    As we grow, and, in some cases, expand beyond WordPress, we need a company name that can be an umbrella for all of our products and services. Defiant Inc is that name and that umbrella. The defiant.com website is a jumping-off point where you can learn about everything our company does, get corporate news and learn about openings if you want to join our team.

    Will this affect the Wordfence security plugin and the service I receive from Wordfence in any way?

    Wordfence is our core business and our biggest source of revenue. It is therefore our main focus in everything that we do. Wordfence will continue to grow, and we will continue to deliver the amazing product development and customer service you have become accustomed to.

    Did Wordfence just raise funding or close some kind of investment round? Did you get bought by someone?

    Hell no! We are still an independent, profitable and growing company. The Defiant name should give you a clear picture of how independent we are and want to remain. We aren’t run by bankers, and we aren’t run by some mega-corp with tacky Super Bowl ads.

    Kerry, Dan and I are still an independent and highly capable executive team. Along with our incredible engineering team and customer service team, we will continue to deliver awesome security for your website, your customers and your assets.

    Can I be Defiant?

    Yes you can. If you use any of our free or paid products, like Wordfence, Gravityscan, our site cleaning service, our security audit or if you chat with our customer service team on the free forums or in our Premium support system, you stand Defiant alongside us in protecting your website, your customers and your assets from hackers.

    As always, I will be around to answer any questions you may have in the comments.

    Mark Maunder – Defiant CEO.

    The post Wordfence Is Now Defiant appeared first on Wordfence.

  • Vulnerabilities in Formidable Forms, Duplicator and Yoast SEO Plugins

    Vulnerabilities have been reported in the Formidable Forms, Duplicator and Yoast SEO WordPress plugins. The Premium version of Wordfence protects against all of these vulnerabilities, even if you have not updated your plugins yet. We do recommend that you update immediately, whether or not you are using the Premium version of Wordfence.

    The details of the vulnerabilities are as follows:

    Formidable Forms 2.05.02 and older has multiple severe vulnerabilities

    Jouko Pynnönen disclosed multiple vulnerabilities in Formidable Forms version 2.05.02 and older. The report included multiple serious problems:

    • A preview function allowed unauthenticated users to execute an arbitrary shortcode. Normally, the use of shortcodes is restricted to site authors or administrators, as many of them could be used to exploit a site.
    • One of the plugin’s shortcodes included a SQL injection vulnerability.
    • Another shortcode allowed an unauthenticated user to view form responses.
    • Form previews were vulnerable to reflected cross site scripting.
    • Form input was not sufficiently sanitized to prevent stored cross site scripting, which could have been used to target administrators when they viewed form responses.

    Formidable Forms is used by over 200,000 active sites according to WordPress.org. The Formidable Forms team has released multiple updates addressing these issues, starting at 2.05.02. We released a firewall rule today, protecting Wordfence Premium customers from attempts to exploit this vulnerability. Free users should upgrade to version 2.05.05 immediately.

    Duplicator 1.2.28 and older vulnerable to stored XSS

    WPVulnDB also reports that the Duplicator, running on over 1 million active sites, fixed a stored cross site scripting vulnerability affecting versions 1.2.28 and older. This report also included the code changes.

    Duplicator version 1.2.29 fixed this issue, but their changelog does not mention a vulnerability (there is no currently entry at all for version 1.2.29). Wordfence includes built-in protection against attacks of this nature, so both Premium and free users should be safe.

    Yoast SEO 5.7.1 and older vulnerable to unauthenticated XSS

    Ryan Dewhurst’s WPVulnDB is reporting that Yoast SEO fixed an unauthenticated cross site scripting vulnerability that affected versions 5.7.1 and older. The code change showing the fix is linked to from the WPVulnDB report.

    Wordfence also protects against this exploit (both free and Premium).

    Conclusion

    We encourage you to share these vulnerabilities with the larger WordPress community to help keep site owners safe from exploitation.

    The post Vulnerabilities in Formidable Forms, Duplicator and Yoast SEO Plugins appeared first on Wordfence.

  • Ask Wordfence: Should I Permanently Block IPs That I See Wordfence Blocking?

    This is the fifth installment in a new series we started last month called Ask Wordfence. You can access previous posts here.

    Today’s question comes from Brooke in Harrisonburg:

    When I see IPs blocked by firewall, or blocked for trying to log in, is there a benefit to permanently blocking them, one by one, or is it enough that Wordfence just blocks them each time?

    This great question is likely shared by a broad audience. We know that the blocking features in Wordfence are incredibly popular. In short, there is a potential benefit to permanently blocking these IPs, but there are also risks associated with it.

    To help you decide how you want use blocking as part of your security strategy, we’ve pulled together a number of factors you should consider.

    The Amount of Attacking IPs Can Be Overwhelming

    In our monthly WordPress attack report for October, we reported that we had added 123,277 IPs to the Wordfence real-time IP blacklist during the month. That’s over 4,000 per day and 166 per hour. It is literally impossible for a site owner to keep up with the massive, ever-changing list of IP addresses that attack WordPress sites. By manually blocking even 1,000 malicious IP addresses, you are barely making a dent.

    To visually illustrate the scale of the challenge we created this motion chart, which shows the total number of IPs we added and removed for just the top 10 countries this past Monday, by hour.

    Attackers Cycle Through IPs Quickly

    One of the most important factors to consider when developing your blocking strategy is how long IPs continue to attack. It varies dramatically by IP address. 91.200.12.91, for example, was the top attacking IP in our WordPress Attack Report in both September and October and was number 24 on the list in August. On the other side of the spectrum, many IPs stop attacking after just a few hours. Back in September we did a deep dive on the Wordfence real-time IP blacklist and found that the average IP address spends just 10 hours on the list.

    The criminals that attack WordPress websites know that the IPs they use are going to be blocked by site owners and blacklists. In an effort to avoid being blocked, they regularly cycle through different IP addresses.

    Attackers Don’t Reuse IPs as Often as You Might Think

    In the blacklist deep dive we mentioned in the previous section, we also looked at how often attackers reuse IPs. We found that, for the most part, they used an IP address just once, with less than a third being used twice or more. The table below shows the breakdown of the number of times we added IPs to the Wordfence real-time IP blacklist during the month of August.

    Many Attacking IPs Actually Belong to Other Attack Victims

    As we’ve discussed above, attackers need access to lots of IP addresses. Being criminals, they generally don’t solve that problem by going out and paying for them. Instead they find ways to take over the IPs of victims who have clean reputations. As we wrote last week, in many cases it is your clean reputation that makes you a target.

    One source of clean and fresh IPs that we see attacking WordPress websites is hacked home routers. You might remember our posts earlier in the year about a large home router botnet being used for WordPress brute force attacks. The IPs belonged to a long list of ISPs from around the globe, and each one represented an unsuspecting victim’s home.

    Putting It All Together

    Blocking IPs manually is generally an ineffective security tactic. Attackers generally cycle through IPs quickly and tend not to reuse them. Attacking IPs often belong to victims, so you risk blocking real users who want to access your website.

    Blocking large groups of IPs, like entire countries, is a popular approach many site owners use. But there are significant risks and headaches associated with blocking legitimate requests from online services like Google Adwords, search engines and service providers. If you can overcome those challenges, however, this can be a very useful layer of security for some site owners.

    Let Wordfence Do the Work For You

    Wordfence Premium includes an IP blacklist that we update in real time. We add thousands of IPs to the list each day, staying a step ahead of attackers as they cycle through IPs in their attempts to evade IP-level blocks. We also remove thousands of IPs  each day, minimizing the impact of blocking IPs that belong to the unsuspecting victims’ routers and other devices. The most you’ll pay for Premium is $99 per year, which means you can enable 24/7 real-time blocking at scale for less than 30 cents per day. Considering how much time is typically involved in manually trying to manage your own IP block list, we think that’s a great value.

    The post Ask Wordfence: Should I Permanently Block IPs That I See Wordfence Blocking? appeared first on Wordfence.

  • SQL Injection in bbPress

    SQL Injection in bbPress

    SQL Injection in bbPress

    During regular audits of our Sucuri Firewall (WAF), one of our researchers at the time, Slavco Mihajloski, discovered an SQL Injection vulnerability affecting bbPress. If the proper conditions are met, this vulnerability is very easy to abuse by any visitors on the victim’s website.

    Because details about this vulnerability have been made public today on a Hackerone report, and updating to the latest version of WordPress fixes the root cause of the problem, we chose to disclose this bug and make the details public.

    Continue reading SQL Injection in bbPress at Sucuri Blog.