As most of you know I use several security plugins on sites to monitor and prevent certain types of common attacks on websites. This short article shows you what happens all of the time 24 x 7, 365 days a year, and from all around the world. So while you may think you are a small local charity based in a sleepy suburban town; something in Dhaka, Pakistan is trying to log into your website, in fact from all around the world!
This is a 12 hour snapshot
Follow this link to open this map in a new browser window. 40 locations were used in 12 hours.
The classic Brute Force attack
One form of attack is a Brute Force password guessing attack. This is where a hacker (more correctly a computer controlled by a hacker, or hacker network) attempts to sign in to the administrative login for a website. This is not something unique to WordPress, it is common where a login form is detected or known to exist. It represents a door, and doors can be opened with the right set of keys.
In this case it is a snap shot of a 12 hour period starting at just after midday on Sunday the 8th of May. The target site is a small local charity in Surrey.
A hacker or hacking group control a network of compromised computers distributed around the world. They decide to target a website. It is likely they targeted many simultaneously, but for the purposes of this article, I can only see one of them.
Lockout
The most common method of preventing (or more correctly reducing the risk) of a compromised password is to lock out the device that is attempting to get into your website. In most cases if a username is used that does not exist on the website it is locked out immediately, if a username is used that is used on the website, then several guesses can be made, but if all of them fail then the computer is locked out.
This makes this type of attack more difficult, and a lengthy process.
Switch to another computer
The solution for the hacker is wake up another computer somewhere else and try again. This is pretty easy to automate; try computer A, when locked out, try again with the next one in the list, then step and repeat until you reach the bottom of your list. At that point you can start all over again.
The map shows the extent of this hacker’s network. Last year I checked out one of the addresses of a computer that was attempting to login to a site. It turned out to be a website for an Italian farming machinery company. Something was residing in that website that could be awakened and used to attack other websites. Such is the world we live in today.
Passwords revealed
There is a feature on all of the sites where failed passwords can be revealed. This is turned off. On occasion I have turned it on to see what passwords are being tried. They are very rarely a completely random sequence of characters. They are more commonly passwords that you and I may have regularly used when we first started using passwords. for me that is in 1990. My passwords today are much more complex
Hackers use a password library or database. These are statistically chosen because they work. When I am training someone and helping them to set up a password with only a very few exceptions they are quite simple to crack with a brute force method and enough patience. That is all a hacker is doing here, and is not dissimilar to the methods used to crack the Enigma and other codes during the second world war.
The best defence?
There are ways to hide the login screen, however I have experimented there, and even that can be detected. The first and most important step is to use a strong password. The ones that WordPress issues are very strong. However you do not need to use those if you want to use your own. Do not use the same password in several locations.
Two factor login
One of the features on your site allow for two factor logins. This means that in order to login you receive a message in your email account that you click on to unlock your website. This means a hacker would need to have access to both your password (and username) AND your email account to get into your site.
I use this on a couple of sites. It works quite well, but it makes logging in more complicated.
Bottom line
For everyone, please ensure you maintain strong passwords on both your email system and on your websites (and everywhere else for that matter).
And by the way, the site in question is quite safe, the prevention mechanisms that were set up are working and nothing managed to get into the site.