10:31 AM

WordPress Site Hacks Continue

70% of WordPress sites are running outdated software and are vulnerable to hackers launching DDoS attacks. Recent examples hit MIT, NEA and Penn State servers.

WordPress installations sporting known vulnerabilities continue to be compromised by hackers and turned into distributed denial of service (DDoS) launch pads.

That warning was sounded last week after IT professional Steven Veldkamp shared an intrusion prevention system (IPS) log with Hacker News, which found that a single 26-second DDoS attack against a site run by Veldkamp was launched from 569 different WordPress blogs. Those blogs appear to have been compromised by attackers, since they comprised everything from a "mercury science and policy" blog at the Massachusetts Institute of Technology (which as of press time remained offline) and a National Endowment for the Arts blog to WordPress sites run by Pennsylvania State University and Stevens Institute of Technology.

"The key aspect to note here is the number of compromised WordPress servers," said Stephen Gates, chief security evangelist at DDoS defense firm Corero Network Security, via email. "It's a simple mathematical equation -- attackers are looking to infect servers sitting in hosting environments with each server easily capable of generating 1 Gbps of attack traffic. It is quite easy to generate extremely high volumes and varieties of attack traffic by compromising just a few WordPress servers."

Once WordPress servers get compromised, attackers can use them for a variety of purposes, such as attacking U.S. financial institutions. "From volumetric attacks that melt down firewalls to the 'low and slow attacks' that sneak through firewalls undetected -- the list is really endless," Gates said.

[ Could crowdsourcing lead to a better security solution? Read Project Sonar Crowdsources A Better Bug Killer. ]

WordPress blogs, of course, are easy to provision and host. But that ease of installation -- and use -- means that such software is often run outside the purview of IT provisioning and oversight. Furthermore, many WordPress administrators fail to keep their software updated or follow security best practices, such as choosing unique usernames and strong passwords for WordPress admin accounts. As a result, numerous WordPress sites sporting known vulnerabilities -- or "admin" as the admin account name -- remain sitting ducks for automated attacks.

Indeed, malware is often used to automatically find and exploit vulnerable WordPress installations. In August, Matthew Bing, an Arbor Security Engineering & Response Team (ASERT) research analyst, noted that the Fort Disco malware -- first discovered in April 2013 -- was being used to target known vulnerabilities in content management systems, backed by six command-and-control servers that were running a botnet comprised of more than 25,000 Windows PCs. "To date, over 6,000 Joomla, WordPress and Datalife Engine installations have been the victims of password guessing," he said in a blog post.

How widespread is the problem of exploitable WordPress software? According to a study conducted by EnableSecurity CEO Sandro Gauci, the list of the one million most trafficked websites -- per the Alexa index -- includes 40,000 WordPress sites. But 70% of those sites are running a version of WordPress with known vulnerabilities.

Those statistics were relayed last week by WordPress security expert Robert Abela, who studied data that EnableSecurity's Gauci compiled over a four-day period in the middle of September, immediately following the September 11 release of WordPress 3.6.1, which remains the latest version.

In a blog post, Abela reported that of the 42,106 WordPress sites from the Alexa index identified, 19% had already been updated to the new version, while 31% of sites were still running the previous version (3.6). But the remaining 51% of cataloged WordPress sites ran one of 72 other versions, with 2% of all cataloged sites still running version 2.x, which dates from 2007 and earlier.

Needless to say, many historical WordPress updates have included patches for exploitable vulnerabilities. For example, the latest version of WordPress -- 3.6.1 -- patched a known vulnerability in version 3.6 that would have allowed an attacker to remotely execute code. Previous versions of WordPress have also sported a number of known bugs, including version 3.5.1 (8 vulnerabilities), 3.4.2 (12 vulnerabilities) and 3.3.1 (24 vulnerabilities).

All of this adds up to numerous WordPress sites that can be relatively easily hacked, based on a review of the top 10 most-seen versions of WordPress seen among the more than 40,000 counted by Gauci. "At least 30,823 WordPress websites out of 42,106 are vulnerable to exploitable vulnerabilities," said Abela. "This means that 73.2% of the most popular WordPress installations are vulnerable to vulnerabilities which can be detected using free automated tools. Considering the number of vulnerable WordPress installations out there, and the popularity of such websites, we are still surprised ... most of them haven't been hacked yet."

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
10/15/2013 | 6:46:04 PM
re: WordPress Site Hacks Continue
Great article Mathew. The average small business owner does not have the time or staff do keep their WordPress websites up to date. That is why I created a complete WordPress monitoring and maintenance service called WP-MONITOR we we take care of all of these vulnerabilities on WordPress sites for the clients. Not only do we take care of the security, but we also provide Daily WordPress Backup, Plugin Updates, Uptime Monitoring, Traffic Reports, Broken Links reports, Security Scanning, Malware removal, Theme Changes, more features than any other WordPress Monitoring plan.
Eddie Mayan
Eddie Mayan,
User Rank: Apprentice
10/10/2013 | 9:18:46 AM
re: WordPress Site Hacks Continue
It is very necessary to update with security or get a very best option to try Managed wordpress service like Cloudways.
User Rank: Apprentice
10/1/2013 | 11:38:41 PM
re: WordPress Site Hacks Continue
I wonder what the NSA will make of my Pictures posted ( Altered Photos of Hitler performing Stupid Magic tricks and other Dada/Surrealist rants raves and absurdity, They'll probably think it's some Code for something and since I post my Beliefs as "Anarcho-Surrealist", which means Nothing. I mean the header of one of my blogs is " A Hobo with a Jar of Mustard", and the other is "How can I disturb your sense of Reality today?" Anyway, I think all American should set up a an Identical blog, that streams 24/7 webcam shots of Toasters, or Toilets, or the inside of an old boot in a ditch..
Joanie Mann
Joanie Mann,
User Rank: Apprentice
10/1/2013 | 8:48:54 PM
re: WordPress Site Hacks Continue
I agree with Mr Carr - get the site hosted by WordPress or another professional host that will ensure the software is kept up to date. Too many businesses try to take these responsibilities upon themselves, but don't really have the skills or resources to do it really well. The issue isn't just the vulnerabilities they introduce for their own businesses, it's the fact that they become effectively complicit in creating issues for others, too. While not as loathsome, it's rather like drunk driving, where the potential victim(s) is not likely to be only the driver.
Thomas Claburn
Thomas Claburn,
User Rank: Ninja
10/1/2013 | 8:09:15 PM
re: WordPress Site Hacks Continue
The fact that asked me to agree to its "fascinating terms of service" was almost enough to get me to sign up on the spot.
David F. Carr
David F. Carr,
User Rank: Apprentice
10/1/2013 | 4:16:46 PM
re: WordPress Site Hacks Continue
If you can't take responsibility for keeping the software up to date, consider whether hosting with is practical for your purposes. You can pay to upgrade from the free service to one associated with your domain and then let their webmonkeys worry about software patches.
CISOs' No. 1 Concern in 2018: The Talent Gap
Dawn Kawamoto, Associate Editor, Dark Reading,  1/10/2018
'Back to Basics' Might Be Your Best Security Weapon
Lee Waskevich, Vice President, Security Solutions at ePlus Technology,  1/10/2018
How to Attract More Women Into Cybersecurity - Now
Dawn Kawamoto, Associate Editor, Dark Reading,  1/12/2018
Register for Dark Reading Newsletters
White Papers
Current Issue
The Year in Security: 2017
A look at the biggest news stories (so far) of 2017 that shaped the cybersecurity landscape -- from Russian hacking, ransomware's coming-out party, and voting machine vulnerabilities to the massive data breach of credit-monitoring firm Equifax.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.