Power Washing and Roof Cleaning Forum

Welcome to the National Soft Wash Alliance, America's Number One Networking and Training Forum. Join Today, Donations to keep the forum going are accepted, Bottom of the Home Page
Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: Wordpress DDoS exploit


Veteran Member

Status: Offline
Posts: 98
Date:
Wordpress DDoS exploit
Permalink  
 


I just emailed Ed Thompson about this and thought I should share it on some of the forums.

 

There is a current exploit (XML quadratic blowup attack) that is running throughout the WordPress and Drupal world. It uses the XMLRPC.PHP (pingbacks) to overload the system.

Other possible vulnerabilities:

  • Intel gathering — attacker may probe for specific ports in the target’s internal network
  • Port scanning — attacker may port-scan hosts in the internal network
  • DoS attacks — attacker may pingback via large number of sites for DoS attack
  • Router hacking — attacker may reconfigure an internal router on the network

Info here: http://www.breaksec.com/?p=6362

 and here they explain how it's used to turn your site into part of their army: http://blog.sucuri.net/2014/03/more-than-162000-wordpress-sites-used-for-distributed-denial-of-service-attack.html

Solutions...(do both)

WP just released an update...if you don't have automatic updates set, make sure to do it from the admin panel

Install this plugin  http://downloads.wordpress.org/plugin/disable-xml-rpc-pingback.1.0.zip

 

My server is 100% WP sites and the combined attacks have been spiking my server load, triggering alerts and actually took the whole server down for 4 minutes this morning. No site has been hacked but DDoS isn't an internal security issue. If you have an account on my server, I will be checking each site and updating those that haven't already.

Barry



__________________

Barry R.

Roof Cleaner, Pressure Washer

Cincinnati Ohio

 

 

 



Approved Exterior Cleaner

Status: Offline
Posts: 918
Date:
Permalink  
 

Thanks Barry

__________________

Thompson Roof Cleaning and Power Washing LLC

Full Service Soft-Wash Experts

www.ThompsonPowerwashing.com

(877) 420-WASH

New Jersey

 



PWS Vender

Status: Offline
Posts: 1770
Date:
Permalink  
 

Thanks for the heads up Barry!

__________________

Eric Seitz

Liberty SoftWash

(717) 324-4208

Roof Cleaner near York PA

Pressure Washer PA

Power Washing Equipment



Approved Exterior Cleaner

Status: Offline
Posts: 1037
Date:
Permalink  
 

Thanks for being on top of all this Barry



__________________

Brian C Jackson

35 Dodge Road

Pelham ,New Hampshire 03076

http://www.jacksoncontracting.net/roof-cleaning.html

(603)401-8408 

 



Approved Exterior Cleaner

Status: Offline
Posts: 1822
Date:
Permalink  
 

Thank you.... This is waaaayyyy above my pay grade and comprehension!

__________________

Ray Burke

Spray Wash Exterior Cleaning

Tallahassee Kitchen Exhaust & Hood Cleaning

 Superior Commercial Exterior Cleaning in Tallahassee, Florida

http://www.spray-wash.com

 

850-528-3226

850-320-6364

 

 



Approved Exterior Cleaner

Status: Offline
Posts: 5171
Date:
Permalink  
 

Barry do you have a simple way to explain this to us?

__________________

            clean rite logo (3).jpg

                          Suffolk County Long Island New York

                     Power Washing and Roof Cleaning Long Island

                                          Clean Rite Blog

 

 

 

                  

                    

              

 



Veteran Member

Status: Offline
Posts: 98
Date:
Permalink  
 

Art O wrote:

Barry do you have a simple way to explain this to us?


 

It's a lot more complex than this but to simplify a bit, think of a DDoS code as instructions for your "to do" list for tomorrow....

 

To Do list:

1. Shower

2. Dress

3. Brush teeth

4. email To Do list to 1 other employee

5. begin To Do list

To Do list:

1. Shower

2. Dress

3. Brush teeth

4. email To Do list to 1 other employee

5. begin To Do list

To Do list:

1. Shower

2. Dress

3. Brush teeth

4. email To Do list to 1 other employee

5. begin To Do list

To Do list:

1. Shower

2. Dress

3. Brush teeth

4. email To Do list to 1 other employee

5. begin To Do list

 

(repeat 5,000 times)

Now imagine you have and unlimited number of employees

 

Now imagine if steps 1-5 were thus:

1. random proxy server login

2. find random wordpress site IP + start new bot

3. open 20 connections

4. run hack xmlrpc until server crash

5. begin To Do list

 

This is a sample alert from my server last week that shows the exponential attack....13 processes (PID = Process ID)

User:trump1 PID:30340 PPID:30232 Run Time:11(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30352 PPID:30335 Run Time:10(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30358 PPID:30130 Run Time:9(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30364 PPID:29851 Run Time:9(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30365 PPID:30304 Run Time:9(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30370 PPID:30332 Run Time:8(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30378 PPID:28704 Run Time:7(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30387 PPID:29155 Run Time:6(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30392 PPID:30333 Run Time:5(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30396 PPID:28383 Run Time:5(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30409 PPID:30252 Run Time:4(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30415 PPID:30314 Run Time:3(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30421 PPID:30270 Run Time:2(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30425 PPID:30289 Run Time:1(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30430 PPID:30269 Run Time:0(secs) Memory:43688(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php
User:trump1 PID:30442 PPID:30329 Run Time:0(secs) Memory:36824(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/trump1/public_html/xmlrpc.php

 

Another....

User:tomb PID:14427 PPID:14152 Run Time:13(secs) Memory:44788(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14435 PPID:14370 Run Time:12(secs) Memory:44584(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14466 PPID:13933 Run Time:10(secs) Memory:44584(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14478 PPID:12834 Run Time:9(secs) Memory:44584(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14480 PPID:14468 Run Time:9(secs) Memory:44784(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14481 PPID:14469 Run Time:9(secs) Memory:44584(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14487 PPID:14475 Run Time:8(secs) Memory:44584(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14489 PPID:14362 Run Time:7(secs) Memory:44584(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14507 PPID:13896 Run Time:3(secs) Memory:44788(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14510 PPID:14474 Run Time:2(secs) Memory:44788(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14513 PPID:14382 Run Time:2(secs) Memory:44788(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14520 PPID:13736 Run Time:0(secs) Memory:40320(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php
User:tomb PID:14523 PPID:14387 Run Time:0(secs) Memory:37220(kb) exe:/usr/bin/php cmd:/usr/bin/php /home/tomb/public_html/xmlrpc.php

 

 



__________________

Barry R.

Roof Cleaner, Pressure Washer

Cincinnati Ohio

 

 

 



Retired Member

Status: Offline
Posts: 790
Date:
Permalink  
 

Thanks for the warning Barry! I use WP.

__________________

Dave Otey

 Advantage Roof Cleaning Company

Certified Roof Cleaning Specialist

630-730-8105

Aurora, IL

 

Exterior soft wash cleaning, siding, roof cleaning and cedar shake cleaning 

 



Veteran Member

Status: Offline
Posts: 98
Date:
Permalink  
 

Dave O wrote:

Thanks for the warning Barry! I use WP.


 

Update WP and install the plugin and you should be ok from anything harmful.I'm still seeing the attempts but the logs are showing a 301 (redirect) when they try to use the xmlrpc.php exploit.

 

I'd also suggest you use a login limiting plugin...set to 5 failed login attempts.

 

 

 



__________________

Barry R.

Roof Cleaner, Pressure Washer

Cincinnati Ohio

 

 

 



Approved Exterior Cleaner

Status: Offline
Posts: 1337
Date:
Permalink  
 

Barry call me when you can.

__________________

Diamond logo

Diamond Roof Cleaning and Power Washing in South New Jersey

278 Pinedge dr 

West Berlin NJ 08091

Michael De Rose-Owner

Cell-609-929-5812

 

 
 
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us
Chatbox
Please log in to join the chat!