Word Press Shenanigans? Anyone seeing strange activity today?

Published: 2014-03-14. Last Updated: 2014-03-14 15:10:36 UTC
by Richard Porter (Version: 1)
4 comment(s)

We are getting different activity reports (Thanks for those!) on Word Press. Beyond the ping back issue that has been happening, is anyone else seeing strange WP behavior?

 

Richard Porter

--- ISC Handler on Duty

Twitter: Packetalien

Blog: packetalien.com

4 comment(s)

Comments

Haven't seen anything yet, but saw this on the PCWorld site: http://www.pcworld.com/article/2106940/large-ddos-attack-brings-wordpress-pingback-abuse-back-into-spotlight.html
Nothing unusual for the WordPress sites we are hosting, except for the regular brute force logins attacks.

Mitigating measures we took
1) Rename admin lgoin
2) Implement captcha
3) Restrict /wp-login.php (WordPress login page) to a small subnet of IP addresses only
ISC Diary from yesterday was linked to wordpress according to comments.

https://isc.sans.edu/forums/diary/Web+server+logs+containing+RS/17803
Nothing that I can see in my server logs.

Diary Archives