Blog

Forgotten Password Attack On WordPress

The WordPress Firewall plugin notified me of a new attack on my WordPress site today; an attempt to inject a file named "fgiwfi.php" via a "password_forgotten.php" injection. This was quickly followed by another e-mail alerting me to an attack from the same IP using the same forged link on another of my pages, but this time with a file name of "yjiujc.php". A third e-mail followed almost immediately from the same IP with a file named "yadydu.php". I don't know who this person is, but I'm very thankful for the WordPress Firewall plugin!

The WordPress Firewall plugin notification of an injection attack.

The WordPress Firewall plugin notification of an injection attack.

Recommended Actions

I took the following actions after receiving the first e-mail:

  1. I immediately inserted the offending IP address into my list of banned IP's using the WP-Ban plugin. I did this across all my sites.
  2. I then scanned my entire file system on each site for the presence of the above three files. The WordPress Firewall plugin did its job: no copy of any of the above files was found.

At The End Of The Day...

I really hate people who try to hack my sites. I'd love to see WordPress ship with WordPress Firewall and WP-Ban installed and activated at the time of installation with a listing of the known offensive sites. Yes, they can change their IP, which is why I use the combination of plugins, but I would love to make it so impossible for them to get to any WordPress site that they just give up and move elsewhere!

Leave a Comment

You can use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


5 × = forty five

Spam Protection by WP-SpamFree

Translate This Page

Translate to EnglishÜbersetzen Sie zum Deutsch/GermanTraduzca al Español/SpanishTraduisez au Français/FrenchTraduca ad Italiano/ItalianTraduza ao Português/Portuguese日本語に翻訳しなさい /Japanese
한국어에게 번역하십시오/Korean中文翻译/Chinese Simplified中文翻译/Chinese Traditionalترجمة الى العربية/ArabicVertaal aan het Nederlands/DutchΜεταφράστε στα ελληνικά/GreekПереведите к русскому/Russian
Oversetter til Norsk/NorwegianÖversätta till Svensk/Swedishहिन्दी अनुवाद करने के लिए/HindiTradueix al català/CatalanTulkot uz latviešu/LatvianPreložiť do slovenčiny/SlovakПереклад на українську/Ukrainian
Plugin by Taragana

Testimonials

Bill Hamilton is a masterful IT professional: integrating keen intellect, efficient project planning, and collaborative business practices to cohere the multi-disciplinary development team to laser focus. He consistently delivers on time, on budget, and above required functionality--an IT triple crown. His personal specialties include with rapid development, Scrum, data mart/warehousing and complex business rule-driven extract/transform/load. I would actively and aggressively seek Bill to be my technical lead.

CAPT Andrew P. Spencer
Chair, Clinical Excellence Navy Nursing Strategic Goal at Navy Medicine