Hacking probes everywhere....

Namecheap AuctionsNamecheap Auctions
NamecheapNamecheap
SpaceshipSpaceship
Watch

alien51

Take Me To Your LeaderTop Member
Impact
1,344
For several weeks now, my Cpanel logs are getting flooded by probing attacks from apparent hackers who seem to be searching if you have wordpress or joomla installed on your domains.

And they come from all sorts of countries. My banned ip address list on my htaccess is so long already. It's eating up too much of my time just checking the logs each day for all my domains. I sometimes wonder whether these are zombie machines (users who had no idea their computers are infected and being used for probing attacks).
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
Botnets, is that what you are saying?
 
0
•••
Use Drupal :p
 
0
•••
I sometimes wonder whether these are zombie machines (users who had no idea their computers are infected and being used for probing attacks).

it's automated, but not necessarily a zombie machine.
 
0
•••
I'm not sure if being "automated" means the guy who owns the machine where the IP address originated was unaware that the probing came from his IP.

I'm not sure anymore if i need to block all these IP addresses, or just let the 403 errors as they are (my htaccess settings prevent execution of php scripts in certain directories).

I've been blocking IP addresses almost everyday.
 
0
•••
0
•••
0
•••
loll would perform faster than Drupal and Joomla :)
 
0
•••
hacking issues

I'm not sure if being "automated" means the guy who owns the machine where the IP address originated was unaware that the probing came from his IP.

I'm not sure anymore if i need to block all these IP addresses, or just let the 403 errors as they are (my htaccess settings prevent execution of php scripts in certain directories).

I've been blocking IP addresses almost everyday.

nice topic bro, even my VPS been port scanned at least 20 times per weeks and sometimes SQL injections, luckily i use Mode security and Csf at my WHM so it automatic block ips, cannot imagine if they use my vps for thier DDOS attack scheme which what that always happen around us ><
 
0
•••
Can only pray don't let hackers target. Because that's a very fearful thing, what will become of very bad.
 
0
•••
nice topic bro, even my VPS been port scanned at least 20 times per weeks and sometimes SQL injections, luckily i use Mode security and Csf at my WHM so it automatic block ips, cannot imagine if they use my vps for thier DDOS attack scheme which what that always happen around us ><

20 a week? That is extremely low. In the past I have had my server attacked. It was not the attack that brought the server down it was the firewall. So many IP's were being blocked the server could no longer handle the size of the file that the blocked IP's were stored in.

---------- Post added at 12:09 PM ---------- Previous post was at 12:06 PM ----------

For several weeks now, my Cpanel logs are getting flooded by probing attacks from apparent hackers who seem to be searching if you have wordpress or joomla installed on your domains.

And they come from all sorts of countries. My banned ip address list on my htaccess is so long already. It's eating up too much of my time just checking the logs each day for all my domains. I sometimes wonder whether these are zombie machines (users who had no idea their computers are infected and being used for probing attacks).

It is almost certainly automated. Don't assume however that all checks are carried out by the same people. Many people out there are trying to exploit vulnerable scripts.

1 thing that does surprise me by the sound of it they are manually scanning for wordpress etc. If I were doing this I would personally hook into search engine results to find wordpres installations.
 
0
•••
20 a week? That is extremely low. In the past I have had my server attacked. It was not the attack that brought the server down it was the firewall. So many IP's were being blocked the server could no longer handle the size of the file that the blocked IP's were stored in.

---------- Post added at 12:09 PM ---------- Previous post was at 12:06 PM ----------



It is almost certainly automated. Don't assume however that all checks are carried out by the same people. Many people out there are trying to exploit vulnerable scripts.

1 thing that does surprise me by the sound of it they are manually scanning for wordpress etc. If I were doing this I would personally hook into search engine results to find wordpres installations.

0.0, wow that's kindda frightening knowing that the firewall will crash bcos of too much of log file,

btw about the scanning of wordpress sites, maybe bcos hackers recently ( well not that recently ) interested in vulnerabilities in wordpress, i think because of its popularity where thousands of webmasters/bloggers using it.
 
0
•••
20 in week isn't a DDoS attack. LOL

Perhaps everyone should leave log analysis to the experts. 20 in a week, probably something harmless that you are not aware of.

A DDoS attack is comprised of THOUSANDS and TENS OF THOUSANDS within minutes to hours.

Keep banning ip addresses over foobar and watch as you eventually block the world.

If you secure your server and website software you will need not worry about blocking every ip that does something you do not recognize. There is a lot of legit activity that n00bs will see as "hack attempts" and it is quite humorous.

Step One: Stop using open source, if you have access to the vulnerabilities, then the script kiddies do too. Code your own stuff securely and correctly and never give anyone access to that code. That is the best first bet. Also do not use software that requires IONCube, if it is encrypted then you have no idea what the code really says. It could say "come hack my stuff by clicking here" for all you know.
 
Last edited:
0
•••
It's not about wordpress, joomla, or drupal.
It's about server security.

They rooted the server.
 
0
•••
Hey genius, how did they root the server to begin with?

No, there is no evidence based on what the poster said that allow for the assumption that the server has been compromized.

You need to read before you reply.

For several weeks now, my Cpanel logs are getting flooded by probing attacks from apparent hackers who seem to be searching if you have wordpress or joomla installed on your domains.

These are bots, nothing more. They are shooting in the dark and if you keep up to date and keep your security tight, they will accomlish nothing. It is no big deal that they do this, if you are secure.
 
Last edited:
0
•••
lol, roger that... seems i am got lots to learn :hehe:

20 in week isn't a DDoS attack. LOL

Perhaps everyone should leave log analysis to the experts. 20 in a week, probably something harmless that you are not aware of.

A DDoS attack is comprised of THOUSANDS and TENS OF THOUSANDS within minutes to hours.

Keep banning ip addresses over foobar and watch as you eventually block the world.

If you secure your server and website software you will need not worry about blocking every ip that does something you do not recognize. There is a lot of legit activity that n00bs will see as "hack attempts" and it is quite humorous.

Step One: Stop using open source, if you have access to the vulnerabilities, then the script kiddies do too. Code your own stuff securely and correctly and never give anyone access to that code. That is the best first bet. Also do not use software that requires IONCube, if it is encrypted then you have no idea what the code really says. It could say "come hack my stuff by clicking here" for all you know.
 
0
•••
posted by DomainHelper:
Step One: Stop using open source ...

But ... your avatar said ...
 
0
•••
Step One: Stop using open source, if you have access to the vulnerabilities, then the script kiddies do too. Code your own stuff securely and correctly and never give anyone access to that code. That is the best first bet. Also do not use software that requires IONCube, if it is encrypted then you have no idea what the code really says. It could say "come hack my stuff by clicking here" for all you know.

So I take it you have ditched Linux and programmed your own operating system, ditched Apache and coded your own http server, ditched mySQL and coded your own SQL server, ditched PHP and programmed your own language (or better still programmed your sites in machine code or c) .....

Programming your own software is not necessarily going to make you secure. You state that if you can view the source so can others and find security holes, that is true but it is also true that those people who find the security hole could report it and it could be fixed quicker.
 
0
•••
Step One: Stop using open source, if you have access to the vulnerabilities, then the script kiddies do too. Code your own stuff securely and correctly and never give anyone access to that code.
It's mighty expensive to code everything yourself and you don't recommend buying code you can't see which makes this the only option. You could trust true third-party apps but I've yet to see evidence that a company product is that much more secure than major open source platforms.

Exploitation usually attacks the weakest point of any system - arrogance is one of easiest to spot AND easiest to exploit.

Open source works on the principle that there are more white hat than black hat hackers .. and this is after potentially 100s of people have potentially looked at the source.

I think you're being taken out of context though and you're talking about open source add ons developed by small teams and little review and this is something people should consider. You should be wary of what open source products you are using, stay up to date, and make a few simple changes (you can remove many indications that you are using wordpress/joomla/drupal with a few steps).

Most people get stuck where a poorly supported plugin prevents a major platform upgrade - this is something that crowd sourcing has yet to resolve. Consider even Firefox 5. Most people haven't upgraded due to some "add on". It's security vs other benefits. The other always wins until something happens.

That is the best first bet. Also do not use software that requires IONCube, if it is encrypted then you have no idea what the code really says. It could say "come hack my stuff by clicking here" for all you know.

This is true and important. It also means that you can't fulfill your desire of not sharing code to anyone else. You live in a one programmer / one installation environment because you can't share your code and advise people NOT to use encoded source.

It is essential that people DO NOT USE Templates with encoded source. These things are all over Usenet. Pay the $79 from a legitimate source... IP Theft is the #1 source for hackers to get access to your stuff.
 
Last edited:
0
•••
These are bots, nothing more. They are shooting in the dark and if you keep up to date and keep your security tight, they will accomlish nothing. It is no big deal that they do this, if you are secure.
Yes, shooting in the dark would be a hint that they're bots. Actually, most of the time my sites return a 404. And then a 403, based on my htaccess retriction settings.

But nonetheless, i don't feel comfortable just allowing a bot machine probe my sites over and over again like that with impunity, evenif i'm confident that i'm "secure". I'd rather block the IP and sleep soundly.
 
0
•••
Olitt — high-converting AI websites, only from $1/moOlitt — high-converting AI websites, only from $1/mo

We're social

Escrow.com
Spaceship
Escrowly
CryptoExchange.com
Domain Recover
URLs.com
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back