We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28042 ☆ A M B ☆
    • 24,524 Posts
    http://it.slashdot.org/story/13/04/12/1940248/wordpress-sites-under-wide-scale-brute-force-attack

    It's only a matter of time before this spreads to other systems; re-name all of your "admin" users!!!
      Studying MODX in the desert - http://sottwell.com
      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
      Join the Slack Community - http://modx.org
      • 28042 ☆ A M B ☆
      • 24,524 Posts
      You know, this was actually one reason why I liked the whole MODx Cloud idea... it was pretty sure that there weren't going to be any shoddy WordPress or other CMS sites on it making the whole server vulnerable. <sigh>
        Studying MODX in the desert - http://sottwell.com
        Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
        Join the Slack Community - http://modx.org
        • 22840
        • 1,572 Posts
        Yeh have seen this in the flesh, over a couple of days last week around 40% of Site5's servers were brought down twice that I know of, they said it was to do with wordpress but couldn't give details as they were still trying to resolve the attacks, wierd thing is though we have 7 VPS's with site 5 at work and none of them were affected ( yes they have wordpress ), only seems to be the shared hosting that was.
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          Well, 90,000 bots hammering at a shared server will at least give it a bellyache. The estimate is that around 10% of all WP sites being probed are getting compromised. Considering how many WP sites there are, that's a lot of compromised servers.
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 39333
            • 151 Posts
            There's always something worse out there. Get tunnel vision wasting time on old grundge sites and you get blind sided by actual threats. It's like complaining about someone buying a candy bar with food stamps while the banking system steals $5k from your wallet, then saying so?

            Nothing wrong with living in the past Wordpress users, oh wait, everything is wrong with that! For anyone still holding onto old wP sites I'd just say time to let it go and move on. Don't be so shallow, there not what you think you know about them nor what they became for this short time when assaulted and darkened by altered states from 20 year old script kiddies with vendettas. Or 20 year old vendettas from darkened script kiddies, take your pick.

            But I wouldn't expect for a second that they wouldn't push back when shoved around. For anyone who has served knows fight and has a willingness to be hurt for the right reasons, in the name of what's right. And also accepts eye for an eye, but not like life for an eye, or worse. That's like killing your neighbors dog for pooping on your grass. It's just a little poop you hypocrite!

            WP has held onto this position for many many years. Instead of speaking openly about the problems with the CMS they'd rather grasp desperately to their position and they're unfounded disdain over it. Yes unfounded.

            Grow up and get a real upcoming CMS. Like MODX!
              MODX...the Zen of CMS
              "Bight off more than you can chew and keep right on chewing."
              • 9207 ☆ A M B ☆
              • 2,475 Posts
              Don't ever take security for granted. http://rtfm.modx.com/display/revolution20/Hardening+MODX+Revolution

              If folks need a VPS that's hardened to "paranoid" requirements, hit me up: we're working on some hardened deployments with intrusion detection and automatic restores.