Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: Word Press Shenanigans? Anyone seeing strange activity today? - Internet Security | DShield SANS ISC InfoSec Forums


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Word Press Shenanigans? Anyone seeing strange activity today?

We are getting different activity reports (Thanks for those!) on Word Press. Beyond the ping back issue that has been happening, is anyone else seeing strange WP behavior?

 

Richard Porter

--- ISC Handler on Duty

Twitter: Packetalien

Blog: packetalien.com

Richard

162 Posts
ISC Handler
Haven't seen anything yet, but saw this on the PCWorld site: http://www.pcworld.com/article/2106940/large-ddos-attack-brings-wordpress-pingback-abuse-back-into-spotlight.html
Anonymous
Nothing unusual for the WordPress sites we are hosting, except for the regular brute force logins attacks.

Mitigating measures we took
1) Rename admin lgoin
2) Implement captcha
3) Restrict /wp-login.php (WordPress login page) to a small subnet of IP addresses only
Mike7

42 Posts
ISC Diary from yesterday was linked to wordpress according to comments.

https://isc.sans.edu/forums/diary/Web+server+logs+containing+RS/17803
SasK

12 Posts
Nothing that I can see in my server logs.
cyborg4

1 Posts

Sign Up for Free or Log In to start participating in the conversation!