ä¸æ¨æ¥ããããã WordPressãçã大è¦æ¨¡ãªæ»æãä¸çä¸ã§è¦³æ¸¬ããã¦ãã¦ãã»ãã¥ãªãã£ãã³ãããã¹ãã£ã³ã°äºæ¥è ãªã©ã注æãå¼ã³æãã¦ãã¾ãã*1
WordPressãçã£ã大è¦æ¨¡ãªãã«ã¼ããã©ã¼ã¹æ»æ(?)ã観測ããã¦ããã¿ããã
— Masafumi Negishi (@MasafumiNegishi) April 12, 2013
CloudFlareã®å ±åâ http://t.co/CVoxZ7nYIc
Sucuriã®å ±åâ http://t.co/Q5jw0JD92X
æ»æã®æ¦è¦ãã¾ã¨ããã¨ããããªæãã§ãã
- WordPressã«å¯¾ãã¦ç¡å·®å¥ã«è¡ããã¦ãã
- 'admin' çã®ã¢ã«ã¦ã³ãã«å¯¾ããè¾æ¸æ»æãè¡ããã¦ãã
- æ»æå ã¨ã㦠9ä¸ãã 10ä¸ã® IPã¢ãã¬ã¹ã確èªããã¦ãããæ»æè 㯠Botnetãå©ç¨ãã¦ããã¨æããã
- ä¸æ£ã«ãã°ã¤ã³ãããã¨ãããã¯ãã¢ãªã©ã®ã¹ã¯ãªãããã¢ãããã¼ãããã
対çã«ã¤ãã¦ãWordPresséçºè
(ãã¡ã¦ã³ã)ã®ä¸äººã§ãã Matt Mullenwegもコメントãã¦ãã¾ããã次㮠2ã¤ã¯ããã«ãã£ãã»ããããã§ãããã
- admin ã¨ãã管çè ã¦ã¼ã¶åãå¤æ´ããã㨠*2
- ç°¡åã«æ¨æ¸¬ã§ããªãå¼·åãªãã¹ã¯ã¼ããè¨å®ãããã¨
ã¾ããã§ã«ä¸æ£ã«ãã°ã¤ã³ããã¦ãã¾ã£ãå¯è½æ§ãããã¾ããadminã¦ã¼ã¶ã«å¼±ããã¹ã¯ã¼ããè¨å®ãã¦ãããªã©å¿å½ããã®ããæ¹ã¯ãè¦è¦ãã®ãªãã¦ã¼ã¶ããã¡ã¤ã«ã追å ããã¦ããªãã確èªããã»ããããã§ãããã
ãã¦æ»æã®å 容ã«ã¤ãã¦ã¯ Sucuriの記事ãæ¯è¼ç詳ãããçããã¦ããã¦ã¼ã¶åããã¹ã¯ã¼ããæ»æå ã® IPã¢ãã¬ã¹ã®æ å ±ãªã©ãè¼ã£ã¦ãã¾ãã以ä¸ã®è¡¨ã¯ Sucuriã®ãã¼ã¿ãå ã«ä½æãããã®ã§ãã
試è¡ããã¦ããã¦ã¼ã¶å Top 5 ã¨è©¦è¡åæ°
ã¦ã¼ã¶å | 試è¡åæ° |
---|---|
admin | 652,911 |
test | 10,173 |
administrator | 8,992 |
Admin | 8,921 |
root | 2,495 |
試è¡ããã¦ãããã¹ã¯ã¼ã Top 5 ã¨è©¦è¡åæ°
ãã¹ã¯ã¼ã | 試è¡åæ° |
---|---|
admin | 16,798 |
123456 | 10,880 |
666666 | 9,727 |
111111 | 9,106 |
12345678 | 7,882 |
æ°ã«ãªãã®ã¯ãä¸è¦ã©ã³ãã ã«ãæãããã¹ã¯ã¼ããããªã試è¡ããã¦ããç¹ã§ããããã®ãã¹ã¯ã¼ããã°ã°ã£ã¦ã¿ãã¨â¦ãªããããããããã¹ã¯ã¼ããªã¹ããããã®ã§ãæ»æè ã¯ãããã£ãæ å ±ãããããéãã¦æ»æã«å©ç¨ãã¦ããã®ããããã¾ããã
ãã¨æ»æè ã®ç®çã§ãããä¸æ£ãã°ã¤ã³å¾ã« Blackhole Exploit Kitãªã©ãè¨ç½®ããæ´»åãä¸é¨ã§è¦³æ¸¬ããã¦ããããã§ããã¾ãä»åã®æ»æèªä½ã WordPressçã®ãµã¤ãããè¡ããã¦ããã¨ã®æ å ±ãããããµã¼ãã«ææããã¿ã¤ãã® Botnetãæ§ç¯ãããã¨ãã¦ããå¯è½æ§ãããã¾ãã(ä¾ãã° "Operation Ababil" ã§ä½¿ç¨ãããã¨ã¿ããã itsoknoproblembro ãªã©ã)
(åèæ
å ±)
ãã³ãçã®æ³¨æåèµ·
- Protecting Against WordPress Brute-Force Attacks - Sucuri Blog
- Mass WordPress Brute Force Attacks? - Myth or Reality - Sucuri Blog
- Patching the Internet in Realtime: Fixing the Current WordPress Brute Force Attack
- Global WordPress Brute Force Flood | HostGator Blog
- http://blog.resellerclub.com/2013/04/12/global-attack-on-wordpress-sites/
- Brute force attack on WordPress and Joomla powered sites - Melbourne
- WordPress wp-login.php brute force attack - InMotion Hosting
ã¾ã¨ãè¨äºãªã©
- Hackers Point Large Botnet At WordPress Sites To Steal Admin Passwords
- 全世界のWordPressサイトに大規模攻撃; デフォルトのアドミンユーザ名’admin’がねらわれている | TechCrunch Japan
- Huge attack on WordPress sites could spawn never-before-seen super botnet | Ars Technica
- Brute Force Attacks Build WordPress Botnet — Krebs on Security
- Hosting Providers Suspect Botnet Behind WordPress and Joomla Brute Force Attacks, Security Firm Says Attempts Have Tripled
- CloudFlare Blocks 60 Million Brute Force Wordpress Attacks in 1 Hour
*1:WordPressã ãã§ãªããJoomla!ãæ»æããã¦ããã¨å ±åãã¦ãããã³ããããã¾ãã
*2:WP2.9ã¾ã§ã¯ããã©ã«ã㧠admin ã«ãªããWP3.0ããã¯ã¤ã³ã¹ãã¼ã«æã«è¨å®å¯è½ããã§ã« admin ãããå ´åã«ã¯ãæ°è¦ã«å¥ã®ç®¡çè ã¦ã¼ã¶ãä½æãããã®å¾ã« admin ã¦ã¼ã¶ãåé¤ããã