We are writing this post and at the same time, there is an on going and highly distributed, global attacks on wordpress websites to crack open admin accounts and inject various malicious scripts.
rnWe were recently informed from our Web Hosting Provider’s Data Centers about the several attacks been carried out, We did a detailed analysis of the attack pattern and found out that most of the attack was originating from CMSs (mostly wordpress). Further analysis revealed that the admin accounts had been compromised or hacked (in one form or the other) and malicious scripts were uploaded into the directories.
rnBecause today, this attack attempts is coming at a global level and wordpress instances across hosting providers are being targeted. Since the attack is highly distributed in nature (most of the IP’s used are spoofed), it is making it difficult for us to block all malicious data.
rnTo ensure that our customers’ websites are secure and safeguarded from this attack, we recommend the following steps:
rn- rn
- Update and upgrade your wordpress installation and all installed plugins rn
- Install the security plugin listed here rn
- Ensure that your admin password is secure and preferably randomly generated rn
- Other ways of Hardening a WordPress installation are shared at https://codex.wordpress.org/Hardening_WordPress rn
These additional steps can be taken to further secure wordpress websites:
rn- rn
- Disable DROP command for the DB_USER .This is never commonly needed for any purpose in a wordpress setup rn
- Remove README and license files (important) since this exposes version information rn
- Move wp-config.php to one directory level up, and change its permission to 400 rn
- Prevent world reading of the htaccess file rn
- Restrict access to wp-admin only to specific IPs rn
- A few more plugins – wp-security-scan, wordpress-firewall, ms-user-management, wp-maintenance-mode, ultimate-security-scanner, wordfence, https://wordpress.org/extend/plugins/better-wp-security/. These may help in several occasions rn
Also, we recommend using Cloudflare, which is available free with all our cPanel accounts, to
rnprevent the attack from affecting the functionality of your site. For any other assistance implementing the above security tweaks contact our support team. All customers website who have opted our website package are been implemented the above security by our support team by default. For all customers without maintenance service or website package are recommended to do the above tasks by themselves to safe guard their website.