WordpressOver the past two weeks there have been UK-wide hacking attacks on websites with content management systems, in particular those with WordPress and Joomla installations.

These have taken the form of large-scale botnet attacks.  Most hosting providers offering WordPress and Joomla for web content management have been targeted. Hackers are reportedly utilising over 90,000 servers to attempt to compromise websites’ administrator panels.

The bots are looking for common account usernames — admin, test, administrator, Admin, root — on CMS sites and systematically trying common passwords such as 123456, password, 666666, 111111, or admin,  in order to gain entry.

Even if they fail to access your admin area, their repeated attacks on the login panel can cause your site to go down because of the number of automated hits on the site.

Definition:
The word ‘botnet’ stems from the two words ‘robot‘ and ‘network‘.With this type of attack robots try to breach the security of a website and then add to the site malicious coding that would help them to create a network of linked computers all working towards a common goal.

This might be to infect other websites or to transmit spam or a virus.

They can also be used to launch ‘Denial of Service’ attacks (DoS) similar to the ones which occurred recently and were widely reported in the press.

You may read about this botnet on the BBC website at http://www.bbc.co.uk/news/technology-22152296

The long-term solution:

In the long-term the best advice is to ‘beef-up’ your admin security. These type of attacks are, unfortunately, likely to become more common.

1. Keep your Joomla or WordPress websites upgraded to the latest versions.

2. If your admin username is ‘admin’ or another weak option, we recommend that you change this immediately to something unique.

3. Make sure you are using a strong password. That is one which includes upper and lower case letters, numbers and special characters.

4. Create a two-tier login to the admin panel at server level.

5. A stronger line of defense would be to have a your login panel no longer available from the usual /administrator or /wp-admin url