Technology Bites

  • Home
  • Tech
    • Software
    • Browsers
    • Google
    • Internet
    • Windows
  • Mobile
    • Android
    • Apple
    • Windows Phone
  • Products
    • Phones
    • Tablets
  • TIP US
You are here: Home / Tech News / WordPress Sites Under Brute Force Attack to Steal Admin Passwords

WordPress Sites Under Brute Force Attack to Steal Admin Passwords

There is a large brute force attack going on targeting WordPress sites in particular, the attack is aimed to steal passwords from WordPress sites. Attacker is trying to steal “admin” passwords of WP sites by using dictionary words and known passwords. The attack is happening at global level and WordPress instances across hosting providers are targeted.

wp_bruteforce_opt1

ClouFlare CEO posted a blog post on the attack, according to the post the attacker is using WP username “admin” and trying thousand of passwords. The attack is using a botnet that consists of atleast 90,000 IP addresses, so it becomes difficult to limit the attack. He thinks that the attack is carried using a weak botnet to gain access to the servers to create a strong botnet for more attacks.

One of the concerns of an attack like this is that the attacker is using a relatively weak botnet of home PCs in order to build a much larger botnet of beefy servers in preparation for a future attack. These larger machines can cause much more damage in DDoS attacks because the servers have large network connections and are capable of generating significant amounts of traffic.

Several hosting providers also posted about the attack, HostGator advised its users to change the passwords to a more secure ones. It also said that the attack is more distributed with 90,000 IP addresses participating. According to them it started last week and died soon and again started picking up yesterday morning. The symptoms of the attack are slow backend of the site and unable to login.

If you use WordPress as your blog CMS this is the time to change the password to a more secure one, and also you can use plugins to limit login attempts to improve security.

Another important thing to remember is changing the username “admin” to something else. When you install WordPress the default username is “admin”, very few people change that. While you can’t change the username in WordPress admin, you can always create a new user with full admin access and delete the admin user.

Image Credit: ClouFlare

Share this:

  • Tweet

Related

About Ram

I am a blogger and Technology Enthusiast. I write about software, tech news, gadgets. You can reach me at ram@teknobites.com, follow me on Google+ or on Twitter

« Fotor: Photo Editing app for Windows, Android, iOS and Windows Phone
Run Facebook Home on any Android device with out root »

Top Posts

  • Sync Flickr Photos with Local Folders
  • MSN launches new home page
  • Yahoo new home pages and how to get back to the old home page
  • Razr M Launcher + Circle Widgets for ALL Android Devices (ICS/JB)
  • Microsoft PDF Plugin for Office 2007
  • HTC M8 might come in late March with on-screen buttons
  • Microsoft tool makes it easy to move from Evernote to OneNote
  • Amazon launches Prime Video service in India
  • Lenovo Smart Band HW01 with OLED display launched at Rs 1999
  • Contact

About Us · Archive · Disclaimer & Privacy Policy · TIP US · Copyright © 2025 · Technology Bites

 

Loading Comments...