Large Scale Botnet Brute Force Password Cracking Against WordPress Sites

The New Acunetix V12 Engine


There have always been a lot of brute force attempts/bot scans and hacking attempts on WordPress hosted sites (due to flaws in the core and a multitude of insecure plugins) – this site being no exception (they’ve even done some minor damage before).

But things appear to have really ramped up recently with a large increase in brute force attacks on WordPress sites. It seems to be the work of a rather crude botnet, which hits up the normal admin username (along with a few others like test/root etc) with a bunch of common passwords. Once it gets in, it leaves a backdoor and adss itself to the botnet – and starts scanning for other victims.

Sucuri have confirmed that the number of brute force attacks in April is double than that of previous months in their blog post here – Mass WordPress Brute Force Attacks? – Myth or Reality

Hosting providers are reporting a major upsurge in attempts to hack into blogs and content management systems late last week, with WordPress installations bearing the brunt of the hackers’ offensive.

WordPress installations across the world were hit by a brute force botnet attack, featuring attempts to hack into installations using a combination of popular usernames (eg, “admin” and “user”) and an array of common passwords. Attacks of this type are commonplace; it is the sharp rise in volume late last week to around three times the normal volume rather than anything technically cunning or devious that has set alarm bells ringing.

The primary target appears to be WordPress installations but Joomla users also reportedly took a bit of a hammering.

Early suggestions are that hackers are looking to harvest “low-hanging fruit” as quickly as possible in order to gain access to a bank of compromised sites for follow-up malfeasance, which could be anything from hosting malware to publishing phishing pages or running some sort of denial of service attack. “It’s doorknob rattling, but on an industrial and international scale,” notes Paul Ducklin, Sophos’s head of technology for Asia Pacific.

This is a large scale attack though, well organized and very well distributed with over 90,000 IP addresses involved. So using something like the WordPress plugin Limit Login Attempts wouldn’t help much – as they are not sending many login requests from each IP address.

Cloudflare have already pushed out a block for this type of attack, both for paying and free customers – so if you’re using that you should be safe. (Patching the Internet in Realtime: Fixing the Current WordPress Brute Force Attack)

If you notice your admin login or blog in general is very sluggish, you might have already been hacked. The outgoing brute force attempts take a lot of server resources.


WordPress founder Matt Mullenweg said that the attack illustrates the need to use a distinct username and a hard-to-guess password, common-sense advice that applies to using web services in general, not just for blog administration.

Olli-Pekka Niemi, vulnerability expert at security biz Stonesoft, outlined the range of possible motives behind the attack.

“A concern of this attack is that by compromising WordPress blogs attackers may be able to upload malicious content and embed this into the blog,” Niemi said. “When readers visit the blogs in question they would be then be subject to attack, come under compromise and develop into botnets. The attacks against the word press blogs seem to be distributed, with automated attacks coming from multiple sources.”

Matt Middleton-Leal, UK & Ireland regional director of corporate security dashboard firm Cyber-Ark, said hacks on corporate blogs might be used as an access point to hack into other (more sensitive) enterprise systems. Weak passwords need to be changed pronto, he argues.

“Common usernames and weak passwords are extremely risky online, however, the dangers are compounded if users re-use the same login credentials for other sites. Once the bad guys have cracked a username and password, it’s extremely common that they’ll attempt to use the same combination for additional sites in the attempt to fraudulently use accounts, or access information such as credit card details or corporate data.

“If WordPress users have been targeted in this attack, they should immediately seek to change their username and password details for their WordPress account, but also for any other accounts for which they use the same credentials,” he added.

There’s not a lot of info going around on what happens after a site has been compromised, in technical terms anyway – so I can’t really comment on that. But if you have decent file permissions, a strong password, you have already deleted the admin user long ago you should be safe.

If you want to add another level, just htpasswd protect your wp-admin directory. That will stop this (and any other similar attacks) dead in it’s tracks.

Stay safe fellow WordPress users.

Source: The Register

Posted in: Password Cracking, Web Hacking

, , , , , ,


Latest Posts:


Eraser - Windows Secure Erase Hard Drive Wiper Eraser – Windows Secure Erase Hard Drive Wiper
Eraser is a hard drive wiper for Windows which allows you to run a secure erase and completely remove sensitive data from your hard drive by overwriting it several times with carefully selected patterns.
Insecure software versions are a problem Web Security Stats Show XSS & Outdated Software Are Major Problems
Netsparker just published some anonymized Web Security Stats about the security vulnerabilities their online solution identified on their users’ web applications and web services during the last 3 years.
CTFR - Abuse Certificate Transparency Logs For HTTPS Subdomains CTFR – Abuse Certificate Transparency Logs For HTTPS Subdomains
CTFR is a Python-based tool to Abuse Certificate Transparency Logs to get subdomains from a HTTPS website in a few seconds.
testssl.sh - Test SSL Security Including Ciphers, Protocols & Detect Flaws testssl.sh – Test SSL Security Including Ciphers, Protocols & Detect Flaws
testssl.sh is a free command line tool to test SSL security, it checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as recent cryptographic flaws and more.
Four Year Old libSSH Bug Leaves Servers Wide Open Four Year Old libssh Bug Leaves Servers Wide Open
A fairly serious 4-year old libssh bug has left servers vulnerable to remote compromise, fortunately, the attack surface isn't that big as neither OpenSSH or the GitHub implementation are affected.
CHIPSEC - Platform Security Assessment Framework CHIPSEC – Platform Security Assessment Framework For Firmware Hacking
CHIPSEC is a platform security assessment framework for PCs including hardware, system firmware (BIOS/UEFI), and platform components for firmware hacking.


One Response to Large Scale Botnet Brute Force Password Cracking Against WordPress Sites

  1. Frank Steiner April 26, 2013 at 12:50 pm #

    It’s more important than ever to protect WordPress websites, or else there’s the chance that they could even be turned into used for criminal activities.

    I already had security measures in place to prevent brute force penetration but after seeing more than 10K tries to login into my blog in recent days I decided that whether or not they failed it wouldn’t cause pain having even tighter security.

    Now there is a Google Authenticator Plugin for WordPress. You could enable (or disable) it per user (admin, editor, etc). This plugin along with strong password is the best you can do to secure the back end. This is the plugin I installed for my personal website.