Online Services

Category: Security

  • Ask Wordfence Episode 2: How to Secure an Old Version of WordPress

    Today we are publishing episode 2 of our “Ask Wordfence” series. Today’s question comes from Ilko in Bulgaria who would like to know how to secure an old outdated WordPress installation.

    You can watch the episode here on our blog or you can watch it on YouTube.

    Don’t forget to visit our YouTube channel and hit the “Subscribe” button to ensure you don’t miss our future episodes.

    The post Ask Wordfence Episode 2: How to Secure an Old Version of WordPress appeared first on Wordfence.

  • The September 2017 WordPress Attack Report

    This edition of the WordPress Attack Report is a continuation of the monthly series we’ve been publishing since December 2016. Reports from the previous months can be found here.

    This report contains the top 25 attacking IPs for September 2017 and their details. It also includes charts of brute force and complex attack activity for the same period, along with a new section revealing changes to the Wordfence real-time IP blacklist throughout the month. We also include the top themes and plugins that were attacked and which countries generated the most attacks for this period.

    Real-time IP Blacklist

    The Wordfence real-time IP blacklist protects our Premium customers from attacks originating from the most malicious IP addresses. Two weeks ago we shared a deep dive on how how the blacklist changed throughout the month of August. The post was well-received, so we decided to include some of that information in these monthly attack reports going forward.

    In the graph below we show the number of IPs added to the blacklist each day in green and the number removed in blue. A total of 117,516 IPs were added during the month, an average of just under four thousand per day. An almost identical number was removed. 

    The Top 25 Attacking IPs

    The next section is our standard explanation of how the table below works. If you are familiar with our attack reports, you can skip down to the table below this section, which contains the data for September along with some commentary.

    Brief Introduction (If You Are New to Viewing These Reports)

    In the table below, we’ve listed the most active attack IPs for September 2017. Note that the “Attacks” column is in millions, and is the total of all attacks that originated from each IP. Farther right in the table (you may have to scroll right) we break down the attacks into “brute force” attacks and “complex” attacks.

    Brute force attacks are login-guessing attacks. You can learn more about how brute force attacks work in our Learning Center article about them. What we refer to as “complex attacks” are attacks blocked by a rule in the Wordfence firewall.

    We have also included the netblock owner, which is the organization (usually a company) that owns the block of IP addresses that the attack IP belongs to. You can Google the name of each owner for more information. A Google search for any of these IP addresses frequently shows reports of attacks.

    The hostname included is the PTR record (reverse DNS record) that the IP address owner created for the IP, so this is not reliable data, but we still include it for interest. For example, we have seen PTR records that claim an IP is a Tor exit node, when, based on traffic, it is clearly not.

    We also include the city and country, if available. To the far right of the report, we show the date in August when we started logging attacks and the date the attacks stopped.

    The Top Attacking IPs

    The total attacks from the top 25 attacking IPs decreased by 8% from August.

    Brute force attacks made up 91% of total attacks for September, the same as August. Complex attacks accounted for 9% of the volume.

    Turkey topped the list this month with 11 of the top 25 IPs after having disappeared from the list last month. The four most active IPs were from Ukraine, with PP SKS-Lugan hosting three of them.

    Brute Force Attacks on WordPress in September 2017

    In the chart below, we show the number of daily brute force attacks on the sites we monitor for the month of September.

    The average number of daily brute force attacks was down a massive 45%. Daily attack volumes grew toward the later half of the month, but were still very low relative to normal months.

    Complex Attacks on WordPress in September 2017

    In the graph below, we show the daily complex attacks (attacks that attempt to exploit a security vulnerability) for September.

    Average daily attack volume for September was down 39% from August for the sites that we protect at 4.7 million. With the exception of a single spike on the 29th, daily volume was significantly lower in the back half of the month.

    Attacks on Themes in September 2017

    The table below shows the total number of attacks on WordPress themes. We identify each theme using its slug, which is the directory where it is installed in WordPress.

    As usual we saw a lot of movement in the top 25 attacked themes. The biggest move on the list moved up 1,382 spots to number 9. We have redacted the theme name as it appears to be contain an unpatched vulnerability. We will attempt to reach out to the author to share what we’ve discovered. It is a premium theme with extremely low lifetime sales quantity. Over 98% of the attacks on this theme originated from just 5 IP addresses, suggesting the attacks are likely the work of a single attacker.

    The second biggest mover was the ‘revelance’ theme, moving up 1103 spots to number 18. The attacker is attempting to exploit the very well-known TimThumb vulnerability. ‘Revelance’ is a premium theme that has been around since 2014, so we assume that at one time it included a vulnerable version of TimThumb.

    The ‘rightnow’ theme was our third biggest mover for the month. The attacks on this theme are attempting to exploit an arbitrary file upload vulnerability from 2014. The theme appears to be abandoned, as we were unable to find any trace of it online. If you’re using this theme, we recommend that you replace it immediately.

    Attacks on Plugins in September 2017

    The table below shows the total number of attacks on WordPress plugins. As with themes, we identify each plugin by its unique slug, which is the unique installation directory where the plugin is installed.

    As usual the top 25 list for plugins was pretty stable at the top, with quite a bit of movement toward the bottom. There were 9 plugins on the list that weren’t in the top 25 in August. We looked into the details behind the first big mover toward the top of the list, Zen Mobile App Native. Attacks on this plugin are trying to exploit a remote file upload vulnerability that was publicly disclosed on February 28th of this year. The plugin has been removed from the WordPress.org plugin directory, so we assume that a fix has not been released. If you are running this plugin we recommend that you remove it from your site immediately.

    We have redacted the details for the next big mover on the list, number 14, because the attack vector may not have a fix yet, so we don’t want to call attention to it and turn it into a much larger problem. (Note: We regret we can’t answer questions about this privately or in the comments.) We were unable to find a reputable source of information on either plugin or the vulnerability. It isn’t listed in the WordPress.org plugin directory, and doesn’t appear to ever have been. We are attempting to reach out to the plugin author to share what we’ve discovered.

    Attacks by Country for September 2017

    The table below shows the top 25 countries from which attacks originated in the month of September on the WordPress sites that we monitor.

    The top of the list was pretty stable, with the United States and Russia trading places at the top and the Ukraine holding at number 3. Turkey jumped into the number 4 spot from 7 with a significant increase in overall volume.

    Conclusion

    That concludes our September 2017 WordPress attack report. We find the dramatic drops in the complex and brute force attack volumes encouraging, though not necessarily indicative of an ongoing trend. Regardless of the volume of attacks, WordPress website owners should not let their guard down, but instead stay vigilant about their site security with up-to-date firewalls and other security best practices to keep their sites safe.

    The post The September 2017 WordPress Attack Report appeared first on Wordfence.

  • Postman SMTP Plugin With Unpatched Vulnerability Removed From Directory

    We have received a number of questions regarding the Postman SMTP plugin which was removed from the WordPress.org directory this week. According to an archived snapshot, the plugin is installed on over 100,000 websites. We assume it was removed because it contains a publicly known reflected cross-site scripting (XSS) vulnerability that has not been fixed. Both Wordfence Free and Premium users who have the firewall enabled have been protected against attempts to exploit this vulnerability from day one. In addition, we alerted all Wordfence users who have the plugin installed when it was removed from the plugin directory.

    Timeline

    On June 29, an unnamed security researcher published the details of the vulnerability, including a proof of concept. A proof of concept is a demonstration that shows the plugin author (and in this case the entire internet, including potential attackers) how to exploit the security vulnerability. The security researcher had apparently attempted to reach the author but had been unable to.

    On October 4 (we think, as we have no way of confirming the exact date), the WordPress.org directory team removed the plugin.

    Also on October 4, someone named Diego (no last name given) reported in comments on the original vulnerability disclosure post that he had reached the author, so hopefully a fix will be released soon.

    Wordfence Firewall Includes Robust XSS Protection

    The Wordfence firewall includes protection against new and emerging XSS attacks. Both Wordfence free and Premium users have been protected against this attack since (and before) it was made public. This is a great example of why using a firewall to protect your website is so important: you are immediately protected against most new threats.

    In cases where we don’t already protect against a new threat, we develop a new firewall rule, deploying it to our Premium customers in real-time and free customers 30 days later. This ‘virtual patching’ by our security analysts and developers keeps your sites safe.

    Wordfence Alerts You When Plugins Are Removed From WordPress.org

    When plugins you have installed on your site are removed from WordPress.org, Wordfence alerts you. There is a long list of reasons why the plugin team at WordPress.org might remove a plugin from the directory. One common reason is that someone has discovered a security vulnerability that has not yet been fixed. Since they don’t publicly announce that plugins have been removed, nor why, it is prudent for site owners to treat the plugin as a potential security risk and take reasonable precautions.

    We wrote at length about how to handle this situation when we released this feature back in June as a part of the 6.3.11 release.

    What To Do

    If you have the Postman SMTP plugin installed on your site, we suggest that you remove it immediately. It contains an unpatched security vulnerability and it appears the author may have abandoned it.

    If you haven’t already, we suggest that you install Wordfence on all of your WordPress websites. It will alert you when your plugins have been abandoned or removed from the the WordPress directory. Its firewall will also protect you against new and emerging attacks.

    Finally, consider upgrading to Wordfence Premium if you haven’t already. The real-time firewall rule updates will protect you from the latest threats. In addition, the real-time IP blacklist will stop all attacks from the most malicious IPs, regardless of what they’re up to.

    The post Postman SMTP Plugin With Unpatched Vulnerability Removed From Directory appeared first on Wordfence.

  • Gravityscan Lowers Price and Adds Free Trial

    We have an exciting announcement today regarding the Gravityscan project. As you know the Wordfence team launched Gravityscan on May 16th of this year. Gravityscan is designed to provide malware and vulnerability scanning for any website.

    Background: Wordfence is a security plugin designed specifically for WordPress. If you have a WordPress website that you need to secure, Wordfence is what you want to use. Gravityscan is a project we launched earlier this year to find security holes and detect malware on any website, not just WordPress websites. Gravityscan works with Joomla, Drupal, Magento, WordPress and a lot of other web applications and publishing systems. Gravityscan can work without any software installed and can instantly scan your site for security problems, but if you want faster and more accurate scans, we suggest you install the Gravityscan ‘accelerator’.

    As with all new products, we have been working closely with our customers to understand your needs and have reshaped the product accordingly. For the past few months, the team has been working on a new release and today we are officially announcing a few important changes to Gravityscan.

    Gravityscan Price Drop: We Are Halving the Price

    Firstly, I am excited to announce that we are dropping the price for Gravityscan Pro from $10 per month to just $4.95 per month. This is an enormously beneficial change for our customers because it makes Gravityscan incredibly affordable – the same price as a venti skinny peppermint mocha at Starbucks.

    I’m incredibly proud that our team managed to get our operational costs low enough to bring world-class malware and vulnerability scanning to our customers for that incredibly low monthly price. Now you have every reason to get the full benefit of Gravityscan Pro, which provides daily security monitoring for your WordPress, Joomla, Drupal, Magento and other websites.

    Introducing a 14 Day Free Trial

    The second big announcement we have is that we have introduced a two week free trial for our Pro accounts. Not only have we lowered the price for Gravityscan Pro, but we have also given you the ability to try out the fully functional Pro version of Gravityscan at no risk, for 14 days!

    I’m a huge fan of this change because it provides complete transparency. Our customers can try out Gravityscan Pro and experience the benefits and peace of mind it provides with daily website scanning for a couple of weeks before making their final decision to buy or not.

    Vulnerability Scans Are Now Paid, But With a Free Trial

    To provide the best possible vulnerability scan engine, we realized that we need to invest heavily in Gravityscan. So we made the decision to make vulnerability scanning a paid-only service.

    As a reminder, malware is an indication you have been hacked or infected and vulnerabilities are security holes. Gravityscan provides free malware scanning. This change makes vulnerability scans a Pro feature. Malware scanning remains completely free.

    The way it works is that we will continue to scan your site for vulnerabilities and malware whenever you do a free scan on Gravityscan. If we find malware on your site we notify you immediately and you see the full result. If we find a vulnerability (security hole), we let you know we found something, but we also ask you to start a free Pro trial to see the result.

    Once you have started your trial, you are not billed and you can see the full vulnerability scan results and have all the features available to Pro including scheduled scanning. If for some reason you don’t like Pro, you can cancel at any time during the 2 week trial and there is no charge.

    If you love Gravityscan Pro, and we think that you will, then you will be billed monthly once your 14 day trial ends.

    Gravityscan Badge Users: Here’s What Changed

    If you are using the Gravityscan badge to get free daily malware scanning you should note that there is a minor change. You will continue to get free daily malware scans and get your malware results free.

    Yesterday, with this new release, we activated vulnerability scanning on your site to let you know if we find a security hole. This scan runs in addition to your existing malware scans. You will need to start a free Pro trial to see your vulnerability results. Malware results are still immediately visible.

    If you don’t want to start a free Pro trial, that’s okay! You will continue to get exactly the same benefit you received before from the badge.

    If you find the vulnerability results useful, start a no-risk free trial and decide if the vulnerability scan results are valuable and whether you want to keep Pro. We think you will find it is a powerful tool to help secure your website and establish an effective security routine through daily monitoring of malware and vulnerabilities.

    Amazing Feedback

    We quietly launched the new version of Gravityscan yesterday to give ourselves a few hours of final testing in production before the big announcement this morning. We have already had a large number of happy customers upgrade to Gravityscan Pro and have received some amazing positive feedback from you all!

    Lowering the price to just $4.95 and adding a free no-risk 14 day trial is a big step forward for Gravityscan and I think it does an amazing job of helping democratize world-class security for publishers. I’m proud of our team for making this release of Gravityscan a reality. I’m also incredibly grateful for the positive support we have received from our customers and your feedback to help us shape this product and better understand your needs.

    Thank you for being part of Gravityscan and the Wordfence family.

    Mark Maunder – Wordfence Founder/CEO.

    The post Gravityscan Lowers Price and Adds Free Trial appeared first on Wordfence.