hacker after my site.

asiabob

Newbie
Joined
Aug 6, 2013
Messages
9
Reaction score
0
Anyone else using wordpress getting hit by brute force attempts?
I have over 350 ip's of the hacker, please see below for the current 50.
Also please use limit "log in attempts" plug in. It will save you a ton of headaches!

[TABLE="width: 149"]
[TR]
[TD]1.34.20.157[/TD]
[/TR]
[TR]
[TD]101.109.251.179[/TD]
[/TR]
[TR]
[TD]101.109.251.191[/TD]
[/TR]
[TR]
[TD]101.109.251.192[/TD]
[/TR]
[TR]
[TD]103.10.67.24[/TD]
[/TR]
[TR]
[TD]103.31.186.100[/TD]
[/TR]
[TR]
[TD]105.227.99.221[/TD]
[/TR]
[TR]
[TD]105.239.206.37[/TD]
[/TR]
[TR]
[TD]109.100.195.97[/TD]
[/TR]
[TR]
[TD]109.200.175.145[/TD]
[/TR]
[TR]
[TD]109.235.225.15[/TD]
[/TR]
[TR]
[TD]109.237.127.172[/TD]
[/TR]
[TR]
[TD]109.254.118.227[/TD]
[/TR]
[TR]
[TD]109.86.194.116[/TD]
[/TR]
[TR]
[TD]112.198.64.2[/TD]
[/TR]
[TR]
[TD]115.126.173.102[/TD]
[/TR]
[TR]
[TD]115.250.7.9[/TD]
[/TR]
[TR]
[TD]117.103.93.234[/TD]
[/TR]
[TR]
[TD]123.236.92.169[/TD]
[/TR]
[TR]
[TD]130.255.216.59[/TD]
[/TR]
[TR]
[TD]151.238.0.48[/TD]
[/TR]
[TR]
[TD]151.238.29.21[/TD]
[/TR]
[TR]
[TD]151.239.23.249[/TD]
[/TR]
[TR]
[TD]151.240.115.88[/TD]
[/TR]
[TR]
[TD]151.241.112.70[/TD]
[/TR]
[TR]
[TD]151.241.86.250[/TD]
[/TR]
[TR]
[TD]151.244.220.118[/TD]
[/TR]
[TR]
[TD]151.245.18.63[/TD]
[/TR]
[TR]
[TD]151.245.51.250[/TD]
[/TR]
[TR]
[TD]151.246.152.62[/TD]
[/TR]
[TR]
[TD]151.247.150.105[/TD]
[/TR]
[TR]
[TD]151.247.162.37[/TD]
[/TR]
[TR]
[TD]151.247.65.95[/TD]
[/TR]
[TR]
[TD]151.250.101.8[/TD]
[/TR]
[TR]
[TD]165.98.223.11[/TD]
[/TR]
[TR]
[TD]176.73.227.109[/TD]
[/TR]
[TR]
[TD]176.73.81.205[/TD]
[/TR]
[TR]
[TD]177.192.212.227[/TD]
[/TR]
[TR]
[TD]177.193.169.72[/TD]
[/TR]
[TR]
[TD]177.228.131.222[/TD]
[/TR]
[TR]
[TD]178.121.180.176[/TD]
[/TR]
[TR]
[TD]178.165.39.75[/TD]
[/TR]
[TR]
[TD]178.205.222.177[/TD]
[/TR]
[TR]
[TD]178.209.152.77[/TD]
[/TR]
[TR]
[TD]178.77.186.125[/TD]
[/TR]
[TR]
[TD]178.91.81.176[/TD]
[/TR]
[TR]
[TD]180.214.96.215[/TD]
[/TR]
[TR]
[TD]181.112.0.233[/TD]
[/TR]
[TR]
[TD]181.112.120.208[/TD]
[/TR]
[TR]
[TD]181.112.32.244[/TD]
[/TR]
[/TABLE]
 
Your case is nothing special. Hackers hit up hundreds of thousands of blogs per day with brute force.
 
Yep, I use security plugins that block after three attempts and I have reviewed my logs and blocked some of the more obvious offenders.

Nothing personal, they do this all the time!
 
This was an attack of unprecedented nature from a botnet operating on over 90,000+ IP addresses. Due to the nature of the attack, memory consumption on targeted servers has increased. In some cases this has resulted in degradation of performance, and unresponsive servers. This was due to a high volume of http requests which can cause some servers to start swapping memory to disk, and possibly run out of memory.
 
Anyone else using wordpress getting hit by brute force attempts?
I have over 350 ip's of the hacker, please see below for the current 50.
Also please use limit "log in attempts" plug in. It will save you a ton of headaches!

[TABLE="width: 149"]
[TR]
[TD]1.34.20.157[/TD]
[/TR]
[TR]
[TD]101.109.251.179[/TD]
[/TR]
[TR]
[TD]101.109.251.191[/TD]
[/TR]
[TR]
[TD]101.109.251.192[/TD]
[/TR]
[TR]
[TD]103.10.67.24[/TD]
[/TR]
[TR]
[TD]103.31.186.100[/TD]
[/TR]
[TR]
[TD]105.227.99.221[/TD]
[/TR]
[TR]
[TD]105.239.206.37[/TD]
[/TR]
[TR]
[TD]109.100.195.97[/TD]
[/TR]
[TR]
[TD]109.200.175.145[/TD]
[/TR]
[TR]
[TD]109.235.225.15[/TD]
[/TR]
[TR]
[TD]109.237.127.172[/TD]
[/TR]
[TR]
[TD]109.254.118.227[/TD]
[/TR]
[TR]
[TD]109.86.194.116[/TD]
[/TR]
[TR]
[TD]112.198.64.2[/TD]
[/TR]
[TR]
[TD]115.126.173.102[/TD]
[/TR]
[TR]
[TD]115.250.7.9[/TD]
[/TR]
[TR]
[TD]117.103.93.234[/TD]
[/TR]
[TR]
[TD]123.236.92.169[/TD]
[/TR]
[TR]
[TD]130.255.216.59[/TD]
[/TR]
[TR]
[TD]151.238.0.48[/TD]
[/TR]
[TR]
[TD]151.238.29.21[/TD]
[/TR]
[TR]
[TD]151.239.23.249[/TD]
[/TR]
[TR]
[TD]151.240.115.88[/TD]
[/TR]
[TR]
[TD]151.241.112.70[/TD]
[/TR]
[TR]
[TD]151.241.86.250[/TD]
[/TR]
[TR]
[TD]151.244.220.118[/TD]
[/TR]
[TR]
[TD]151.245.18.63[/TD]
[/TR]
[TR]
[TD]151.245.51.250[/TD]
[/TR]
[TR]
[TD]151.246.152.62[/TD]
[/TR]
[TR]
[TD]151.247.150.105[/TD]
[/TR]
[TR]
[TD]151.247.162.37[/TD]
[/TR]
[TR]
[TD]151.247.65.95[/TD]
[/TR]
[TR]
[TD]151.250.101.8[/TD]
[/TR]
[TR]
[TD]165.98.223.11[/TD]
[/TR]
[TR]
[TD]176.73.227.109[/TD]
[/TR]
[TR]
[TD]176.73.81.205[/TD]
[/TR]
[TR]
[TD]177.192.212.227[/TD]
[/TR]
[TR]
[TD]177.193.169.72[/TD]
[/TR]
[TR]
[TD]177.228.131.222[/TD]
[/TR]
[TR]
[TD]178.121.180.176[/TD]
[/TR]
[TR]
[TD]178.165.39.75[/TD]
[/TR]
[TR]
[TD]178.205.222.177[/TD]
[/TR]
[TR]
[TD]178.209.152.77[/TD]
[/TR]
[TR]
[TD]178.77.186.125[/TD]
[/TR]
[TR]
[TD]178.91.81.176[/TD]
[/TR]
[TR]
[TD]180.214.96.215[/TD]
[/TR]
[TR]
[TD]181.112.0.233[/TD]
[/TR]
[TR]
[TD]181.112.120.208[/TD]
[/TR]
[TR]
[TD]181.112.32.244[/TD]
[/TR]
[/TABLE]
Friend I think there is nothing to be worry. These all are dynamic IP addresses specially provided by WiMax service providers. Ordinarily they provide dynamic IPs to their customers, if the customers didn't apply for an static IP address.

Otherwise if you are sure about any of these IP, Then block them.

Good Luck.
 
Cool story OP. Just let the hacker hack your blog and then hire someone to get him outta there :D:D

[/troll]
 
I found a pretty sweet fix, several of my blogs were getting the same kind of action, and because of the size of the botnet, simply banning IPs as they show up, well, it's useless- they can attack for days without hitting three attempts with one IP.

There's a plugin called iq block country. You can literally block entire countries from accessing your backend, frontend, whatever. Just search for block country in your wordpress backend plugin area.

I chose to block all but my own country from seeing the backend. Pretty easy once you get a rhythm down- there's a massive list, but go to the add countries area and press "A", then "enter" repeatedly until you run out of countries to add, then go through the entire alphabet this way. Then , do a CTRL+F, and make sure your country is not in that list. That last bit is ridiculously important.

The other plugin I'm trying out is called "bruteprotect" and it blocks known bad IPs from your login page.

Also, you can rename your login page, but don't forget what you named it to. There's a plugin for that as well.

One last thing- get cloudflare if you can.
 
The security plugin in each of my wordpress installation are

1. Wordpress Firewall 2
2. WordPress File Monitor Plus
3. Better WP Security (also use for regular database backup)
 
You can also use a 3rd party firewall so that all your traffic is filtered and then directed to your site.
 
It's been a headace for long time. I was recommended by Bluehost to use "Captcha anti spam" wordpress plugin to tackle the brute force attack.
 
Back
Top