Online Services

Category: Security

  • 3 Severe Plugin Vulnerabilities Fixed in the Last 24 Hours

    The following three plugins contain severe vulnerabilities that have all been fixed within the past 24 hours. Details of these vulnerabilities have been released to the public so they are likely already being exploited. If you use any of these plugins, upgrade immediately. Please share with the larger WordPress community.

    Upgrade immediately if you use any of these and please share this information with the larger WordPress community.

    To learn more about SQL injection vulnerabilities or file upload vulnerabilities, visit our WordPress Security Learning Center.

    The post 3 Severe Plugin Vulnerabilities Fixed in the Last 24 Hours appeared first on Wordfence.

  • 6 Million Password Attacks in 16 Hours and How to Block Them

    Last week in the President’s cyber security op-ed in the Wall Street Journal he implored Americans to move beyond simple passwords and to enable two factor authentication or cellphone sign-in.

    One of the things we monitor at Wordfence is the number of brute force attacks on WordPress websites. Brute force attacks are password guessing attacks, where an attacker tries to sign in as you by guessing your password.

    To give you an idea of the level of attacks in the wild, we gathered data on brute force attacks across the sites we protect within a 16 hour Window starting Sunday until Monday (yesterday) at 2pm Pacific time.

    Here are the highlights. Remember, this is only over a 16 hour window which is relatively short.

    During this time we saw a total of 6,611,909 attacks targeting 72,532 individual websites. We saw attacks during this time from 8,941 unique IP addresses and the average number of attacks per victim website was 6.26.

    The total number of attacking IP’s was actually 55,391 but we only counted IP’s that generated more than 10 failed logins across all sites. That way we excluded accidental login failures.

    So where are these attacks coming from. The results are not what you would expect. The table below shows the total number of attacks (brute force login attempts in this case) ordered by country:

    Brute Force Attacks by Country during our 16 hour window.

    Brute Force Attacks by Country.

     

    The Ukraine is the top offender, but there is a specific reason for this which we explain below. The United States is second. Our hypothesis is that this is where most data centers are based and therefore most compromised sites, from which attacks are launched, will be based in the USA.

    You’ll notice that the Ukraine is at the top of the list. Over 86% of those attacks come from just two IP addresses at a Ukrainian hosting provider. These two IP’s generated 2.4 Million attacks between the two of them.

    During just 16 hours, they targeted 37,454 unique victims. 

    The two attackers that we analyzed are based at a Ukrainian hosting provider. They caused their Ukrainian hosting provider to account for more attacks than the next 19 hosting providers, combined.

    We currently aggregate attack information at a rate of 114 attacks per second. Analyzing data like this at Wordfence helps us understand the changing attack landscape and how to better protect our customers.

    What can you do to protect yourself?

    Firstly, make sure you’re running the free or premium version of Wordfence and that you have the “Wordfence security network” feature enabled.  It is enabled out of the box in Wordfence. With this feature enabled, if you get a failed login from an IP address, Wordfence will contact our cloud services to find out if that IP is one of the attackers we know about (like the two above). If it is, it will immediately be blocked from signing in, protecting your site from a brute force attack. The attacker won’t even get the standard 3 or 5 tries before they are locked out.

    Wordfence also provides login attempt limiting out of the box in the free and premium versions. WordPress does not do this by default, so make sure you have this enabled.

    Next, as Obama suggests, enable cellphone sign-in for your WordPress website, also known as two factor authentication or 2FA. This feature is available in the Premium version of Wordfence and is easy to enable. You can learn more about cellphone sign-in on our documentation website.

    Perform a Password Audit

    Wordfence Premium gives you the ability to securely audit the strength of all your site member passwords, including your administrators. To launch this feature last year, we worked closely with our partners to build a supercomputer with over 40 Terraflops of processing power. That is faster than the fastest computer in the world in 2003.

    gpusRelease2

    Wordfence’s custom built password auditing hardware is pictured above. It is based in our data center in Lynnwood, Washington and uses very high performance GPU’s to audit the security of your passwords.

     

    By performing a password audit with Wordfence, you can launch a simulated password cracking attack on all site member passwords including administrators. Wordfence will then provide a report of which accounts suffer from weak passwords.

    Password Auditing is completely secure and uses a combination of hashing and public key cryptography to protect your data. Once you receive the results, Wordfence provides a way for you to notify users they have a weak password or to force a password change.

    If you haven’t completed a password audit on your website, upgrade to Wordfence Premium and start an audit today.

    Go Deep on Password Security

    Password security is a big subject. To fully understand why strong passwords are important and how attackers target weak passwords, you need to gain an understanding of hashing, password salts and attack methods like rainbow tables, how salts work and why modern GPU’s give attackers a huge advantage.

    As part of our free WordPress Security Learning Center, we have created a comprehensive lesson that explains all of this and much more, including emerging improvements in password algorithms. The lesson is designed to be a place that teachers and university professors can send their students to get a primer on password security and password authentication.

    If you invest the time to read this lesson, you will come away with a complete understanding of many fundamental security concepts that you will use throughout your career as a systems administrator.

    Be warned, we don’t pull any punches. So if you do decide to dive in, make sure you make yourself a cup of something warm and allocate at least an hour to read the entire lesson.

    Once complete, you will have a well grounded understanding of password security, password authentication and modern attack techniques. We even throw in some number theory to help you understand what makes a password strong.

    You can find the full lesson on Password Authentication and Password Cracking by clicking here.

    As always, please share your thoughts below and thanks for being part of Wordfence and our community.

    The post 6 Million Password Attacks in 16 Hours and How to Block Them appeared first on Wordfence.

  • Why Wordfence Supports Strong Encryption Without Backdoors

    This morning global headlines are discussing Apple’s move to oppose a court order issued by the US government regarding breaking into it’s own iPhone. This case has far reaching consequences and is part of a wider debate on cryptography and whether consumers and businesses should have access to strong cryptography and the data protection that comes with it.

    I’m going to start by explaining what is happening in the Apple case. Then we’ll discuss the wider implications and why Wordfence supports Apple’s move to oppose the order by the US government. I’ll also explain how this affects you, both in the WordPress space and in your wider business and personal activities.

    Yesterday a Federal District Court judge in California issued a court order which compels Apple to develop software that will unlock an iPhone used by one of the two attackers who killed 14 people in San Bernardino in California in December 2nd of last year.

    This morning Apple issued a statement expressing sympathy for the victims in the San Bernardino attack and supporting the search for justice, but making it clear that they will oppose the order. The statement explains that by developing a custom version of iOS, the iPhone operating system, as the order requests, they will be creating a master key that will allow the government to unlock all iPhones and access their data too.

    According to Apple:

    Building a version of iOS that bypasses security in this way would undeniably create a backdoor. And while the government may argue that its use would be limited to this case, there is no way to guarantee such control.

    The legal mechanism that the US government is using to compel Apple to build this back door is the All Writs Act of 1789. The relevant quote from the law is that it allows judges to “..issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law.” Apple argues that this new interpretation of the All Writs Act could allow the government to:

    …extend this breach of privacy and demand that Apple build surveillance software to intercept your messages, access your health records or financial data, track your location, or even access your phone’s microphone or camera without your knowledge.

    Now lets chat about why Wordfence supports Apple’s opposition to this order.

    What the government is asking for is a back-door into the encryption that protects the iPhone. Whether this back-door is a key that gives them access, or is a custom built operating system that lets them gain access, is not relevant. The results are the same and the back-door is binary data in both cases.

    The first problem this introduces is that this back door will need to be protected. It will need to be stored by the US government on a secure network or system. If criminals gain access to this back-door or the techniques it employs, or if they are able to reverse engineer the back-door, they will gain access to all iPhones. Criminals will then have the same extraordinary access to encrypted consumer data that the US government has.

    In handing a set of keys to the government, we assume two things:

    1. The US government is infallible. Specifically, they are able to keep all their confidential data secure all the time.
    2. The US government is unimpeachable. Specifically, all employees can be completely trusted.

    At Wordfence, we have the greatest respect for the work that many in government and in public service do. This includes the intelligence community where we have friends who make extraordinary sacrifices to work in those roles. But we think it’s fair to acknowledge that our government and it’s people are human and therefore can make mistakes.

    This problem affects most companies in the same way, but to illustrate, we will use ourselves as an example. Wordfence uses strong encryption to protect your data. Specifically we use public key cryptography along with symmetric cryptography to encrypt sensitive data as it moves across the network. In order to keep that data secure, we need to keep our private keys secure. That’s our job and our responsibility.

    If we were to create a back-door into that encryption, we would be trusting that the holder of that back-door is able to keep the back-door secure. That creates a big problem for us as a practical matter. Right now we have a limited number of entry points or “endpoints” in security speak, that we need to protect.

    If we hand a new set of keys to the government, we suddenly have to protect a huge number of new endpoints that need to be protected to protect those keys. If those endpoints are on a US government network, classified or not, it probably would expand into the tens or hundreds of thousands of new endpoints that need to be protected to protect our secure data.

    We would have no visibility into those endpoints because they would all be ‘classified’. We have no access to audit the government’s network. We simply have to trust that they are infallible and unimpeachable.

    Introducing a back-door with keys for that backdoor into our own cryptography has the effect of massively expanding the number of endpoints that need to be protected to protect our network and our customers.

    This problem extends in a similar way to other companies who use cryptography to protect your data. It also affects consumer devices and software like web browsers and the secure connection they currently enjoy with web servers.

    The effect of this on WordPress publishers is that they may be compelled, or their vendors may be compelled into providing backdoors into cryptography that protects their customer or website data. They may also be forced to provide a backdoor into the secure connection between a visitor web browser and their website. The problems it introduces are:

    • The size of the network that needs to be protected to protect your customer data is suddenly much larger.
    • If the backdoor is compromised, your customer data and website data is compromised.
    • You now have the responsibility of protecting a much larger attack surface behind which are the private keys to your network and you have no visibility into that network or the ability to audit it’s security.

    I’d like to make three more points that relate to this argument:

    Even if you create backdoors into encrypted data used by consumers and businesses, it is a mathematical reality that a bad guy, or terrorist in this case, can write their own encryption software that is unbreakable and has no backdoor. It is relatively easy to write an application that provides unbreakable encryption to a criminal or terrorist – the algorithms are open source. If backdoors are mandated by governments, then the only people with secure encryption will be the very people you are trying to surveil.

    It is possible to perform effective surveillance without backdoors. Tor is an anonymous browser that hides the identities of users by using strong encryption. Using a timing attack (also called end-to-end correlation) you can confirm a Tor user’s identity simply by monitoring the network without being able to break Tor’s encryption. This is an example of using meta-data for surveillance rather than decrypted data. Not having access to a backdoor does not prevent the intelligence services from doing their job.

    Finally, as Alex Stamos, Facebook Chief Security Officer asked Admiral Rogers (Director of the NSA) at a security conference last year: If we give the US government a backdoor into encrypted data, should we give other governments that same access? How do we justify giving the United States extraordinary access if we do business in France and don’t give the French government the same access? The results of granting the US government a backdoor could well be that all governments require that same access if you do business in their jurisdiction.

    Framing this debate as leaving “no stone unturned as we gather as much information and evidence as possible.”, as US Attorney Eilleen M. Decker said, does not fully capture the complexity of this debate and the cost of granting extraordinary access to systems and cryptography. Granting that extraordinary access runs the risk of leaving us less secure while criminals are free to choose to use strong unbreakable encryption.

    For this reason, Wordfence supports Apple in their move to oppose the court order to create a back door into their smartphones.

    I would like to encourage you to learn more about why access to strong cryptography matters and to join the debate. Post your comments below.

    Sincerely,

    Mark Maunder – Wordfence Founder and CEO.

    Additional Resources:

     

    The post Why Wordfence Supports Strong Encryption Without Backdoors appeared first on Wordfence.

  • WordPress-Delivered Ransomware and Hacked Linux Distributions

    In a rather unfortunate turn of events earlier this month, the Hollywood Presbyterian Medical Center was infected with ransomware. Ransomware, if you’re unfamiliar with it, encrypts everything on your workstation and then tells you to pay an attacker to decrypt your system and regain access to your information.

    In the case of Presbyterian, they had to pay 40 bitcoins or the equivalent of $17,000 to regain access to their systems. The ransomware attack affected CT scans, documentation, lab work, pharmacy functions and their email went down. Last week they paid the attacker the $17,000 and their systems were decrypted and they’re back online.

    Unfortunately WordPress has been a source of ransomware infections. It’s unknown whether it contributed to the Presbyterian attack or not. During the past month the information security industry has seen WordPress used as a kind of platform to launch ransomware attacks. It works as follows:

    • A WordPress site is hacked through any method available. That may be a brute force password guessing attack or by exploiting a vulnerability in a plugin, theme or core.
    • The attacker installs code on the WordPress site that redirects visitors to other infected websites that are running the Nuclear Exploit Kit. The redirects may happen through a series of websites to try and prevent web browsers and Google from warning you that a site is infected. The sites involved in the redirect change frequently.
    • When a visitor to the infected site is redirected, the nuclear exploit kit searches for vulnerabilities in the site visitor’s Flash Plugin, Microsoft Silverlight, Adobe Reader or Internet Explorer.
    • If Nuclear finds a vulnerability, it exploits the visitor machine and installs the TeslaCrypt Ransomware.
    • The ransomware then encrypts all files on the workstation and extorts the owner into paying to get their system decrypted.

    This is what TeslaCrypt looks like:

    A screenshot of the screen that TeslaCrypt displays when your files are encrypted. Courtesy Bromium Labs.

    A screenshot of the screen that TeslaCrypt displays when your files are encrypted. Courtesy Bromium Labs.

     

    As you can tell from the sequence of events above, TeslaCrypt and the attackers behind it rely on a cascade of failures. They require multiple vulnerable WordPress sites to perform their infection and to set up a chain of redirects. They then need a visitor using an unpatched workstation with vulnerable applications to visit an infected site.

    The fact that Hollywood Presbyterian actually paid the ransom to regain access to their systems, speaks volumes about how effective a ransomware attack is and the impact it has on systems.

    Update: If you are infected with TeslaCrypt, there is a utility available written by an anonymous researcher called TeslaCrack which may help. Thanks to Samuel who posted it in the comments below, where you can find a link to the utility along with a few other links I’ve added discussing the utility.

    In another turn of events, the Linux distribution “Mint” reported on Saturday that they had their website hacked via a WordPress installation. According to Clement Lefebvre, the project leader, in reply to a comment on their blog:

    “We found an uploaded php backdoor in the theme directory of a wordpress installation, which was 1 day old and had no plugins running. The theme was new but most importantly I think we had lax file permissions on this. This was only set up hours before the attack but we were probably scanned for something like this for a while. Anyhow, we don’t know yet how it was uploaded but we know it happened there, and I’m certainly not pointing the finger at anybody. People just asked if we were running wordpress or if wordpress was used in the attack and I answered yes.”

    The attacker replaced the real Linux distribution that Mint users download from the site with a version that had malware installed. The modified Linux distribution turns your Linux machine into a member of an attack botnet that can be used for DDoS attacks.

    As WordPress site owners, our role in this is clear. If you don’t protect your WordPress site from attackers, you risk infecting your site visitors with Ransomware, turning their machines into an attack platform, or worse.

    When thinking about WordPress security, it’s important to consider the broader impact a hack might have, and the larger responsibility that we as site admins have to not just protect our own website and our investment, but our site members’ personally identifiable data and the security of visitors to our websites.

    At Wordfence, we continue to provide detailed advice on how to keep your WordPress site secure including here on our blog and in our WordPress Security Learning Center. Securing your site is critically important, not just to protect your investment, but for your site visitors’ safety.

    In other news: We’d like to remind all ElegantThemes customers to update their themes if they haven’t already. There was a critical security update released on Thursday that fixed a vulnerability in several of their themes. Update immediately if you haven’t done so already.

    As always we welcome your comments below. Please share this with the larger community to create awareness of our larger responsibility as WordPress site administrators.

    The post WordPress-Delivered Ransomware and Hacked Linux Distributions appeared first on Wordfence.