WordPress and Joomla Brute Force Attacks
As several of our client sites are built on CMS platforms like WordPress or Joomla, this past week’s brute force attacks that have been all over the news (in case you missed it you can read more coverage from Forbes or or here at NBC news) have drastically changed the landscape of our work week as we updated security measures to protect ourselves from the onslaught. But, while our next post will be more technical in laying out some of security measures we took and some of the insight we gained, there are a few basics that we wanted to get out there as soon as possible for anyone with sites on or built from WordPress or Joomla.
What The Attack Is, And How To Protect Yourself
Over the past week, a coordinated hacker attack using a botnet was aimed at WordPress and Joomla sites was launched. By some reports, hundreds of thousands of IP addresses were used to try to break into sites by continually guessing popular usernames and password combinations. Take a look at this graph below, from Daniel Cid and Tony Perez on the Sucuri security blog, it does a great job at showing just how huge this attack is (remember, not even halfway into April at this point). They estimated that within the botnet (a series of computers under the control of a central command server and sometimes referred to as zombie computers) there was upwards of 90,000 separate IP addresses possibly representing 90,000 compromised unique computer devices.

We also tracked hacker login attempts on our sites – and our data pretty much lines up with the reports of the attack peak.
Our new security measures drastically reduced the login attempts earlier than would have naturally occurred – so don’t be fooled by our graph as the attacks have only started to wind down in the past 2 days. Initial analysis of our server logs using a specific fingerprint has so far identified over 500 unique IP addresses hitting our client sites. Obviously our client sites were but a sliver of what was affected in the overall attack. Numerous agencies have deemed this a global botnet attack, potentially affecting millions of websites. Many of the IP addresses involved in the attack were traced back to foreign locations such as Russia, Ukraine, Hong Kong, Vietnam and China. Below is an image of one of our server logs where even a single IP addresses was attempting different login/password combinations roughly every 30 seconds. This particular IP address traced back to Rome, Italy.

While the end results of the security breaches varied and we probably won’t know the real impetus for the attack or how successful the attack was for quite some time, the botnet attacks were mainly used so far to discover unprotected websites. Many security analysts say that this attack was likely only the first phase and it may be a few weeks before the next phase goes into operation.
If there’s one take away from the attacks, it’s that your best defense is to come up with an original user name and strong password. The attack focused mainly on finding sites that were using default login names like “admin”, and used a password that could be easily guessed by a dictionary bot (a simple string of numbers or common word(s)).
In case you are wondering just how creative you were in coming up with your login credentials, the top five user names being attempted are admin, test, administrator, Admin, and root. The top five passwords being attempted are admin, 123456, 666666, 111111, and 12345678.
That said, if your login name is admin and your password is admin, you’re sort of asking for trouble. Also, with WordPress, it’s important to differentiate your username from your author name – as we discuss in this blog post. If you don’t take this additional precaution a more motivated hacker will be able to easily determine your login name and will then only need to brute force your password.
So while the botnet attack boom continues, for now – just come up with an original username and password that contains a mix of uppercase and lowercase letters, numbers, and at least one or two special symbols.
If you are in need of any assistance in cleaning up a hacked Joomla, WordPress, or any website for that matter do not hesitate to call us at 1-800-975-5695.





