Wordpress sites exploited with "clever black hat SEO trick"

That said, it's suspected to be a case of brute-forcing the WordPress administrator accounts

So many times it boils down to this. And yet it's so easy to install some sort of firewall or 2FA with WP. Weak password + unsecured login system = webmaster willingly bending over
 
So many times it boils down to this. And yet it's so easy to install some sort of firewall or 2FA with WP. Weak password + unsecured login system = webmaster willingly bending over

Also plugins and themes. People install anything but forget that it's all active PHP code that can do anything on the server. I've seen WP installations with dozens of plugins. It's insane.
 
Unfortunately, most people are lazy and that's the reason they went for Worpress in the first place. I've seen sites with 30+ plugins installed and when I pointed this out to the webmasters, they weren't bothered at all. Lots of people learn the hard way when their site gets compromised.
 
So many times it boils down to this. And yet it's so easy to install some sort of firewall or 2FA with WP. Weak password + unsecured login system = webmaster willingly bending over
Could be that..
I'm certain it's good ol botnet

Wordpress has little to no security by default
 
Back
Top