Example Brute Force Hacking Attempt

How strong are your keys?

As you are all probably aware I get messages from all of the websites I look after that advise me of certain things that are happening on them. It may be an administrator logging in, or someone editing a post or page. I generally ignore them unless they are occurring at strange times of the day, or it is an account name I do not recognise.

brute force attacks
A small selection of the emails I get each day and night!

 

One of the plugins I use advises me of “Brute Force” attacks. These are when someone attempts to repeatedly log in to a site using the administrative interface guessing the username and password. One such example happened late last night.

Passwords Passwords Passwords!

You will find here and in many other places I keep stressing the importance of passwords, and keeping them strong. Here is why:

Between 11:51pm and 11:58pm on the 26th of November a hacker from this IP address: 92.63.87.97 which is located in Latvia, launched a Brute Force attack on the website Horsewyse. In that time there were 10,200 attempts at logging into the website. That is around 25 per second.

This is not someone sitting at a computer typing in passwords, this is a computer that has been set up to attempt to login using a variety of user names supported by a password library. The password library will contain statistically likely passwords. Because it is automated it is fast. Networks of computers are also used to do this, and there is a class of attack called a DDoS (Distributed Denial of Service) attack where many computers (often more than 20 that all work together) are programmed to attack a site.

The server resources are all busy trying to authenticate the user, so the server will slow down. In the most extreme examples the hacker is attempting to keep the server so busy it either crashes, a protection mechanism kicks in which takes the serve off line or it becomes very slow.

Protection Mechanisms

We use a number of protection mechanisms on the websites to prevent anyone who is not an authorised user from logging into the system. One of the weakest links is the user password. Keep yours tough to guess!

Where are your front doors?

Remember that the web address to your email account is also a username and a password too! It is not just websites that get hacked. Email accounts are common targets too. Particularly the free accounts.

Related articles can be found here:

http://prestwoodva.org.uk/about-your-password-sir/

http://prestwoodva.org.uk/how-good-is-your-password/

Leave a Reply

Your email address will not be published. Required fields are marked *

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)