Posts tagged ‘DDOS’

WordPress / Site Hell, Hopefully Getting Better

All of my websites have been a mess this weekend as there has a been a worldwide brute force attack occurring for several days on WordPress admin accounts.  I avoid most of the common mistakes (using the default user name, simple passwords, etc) so I don't think anyone has breached a site but the constant calls of the login function acts effectively like a DDOS attack, flattening my server.

I have put in place some extra code to detect brute force attacks and temporarily and even permanently ban IP's.  Since attackers don't just sit in a single IP in Russia any more but use shifting and spoofed IP's, you may at some point find yourself locked out.  Email me if that happens.

When Hacking is Unnecesary

The Feds are claiming they know of at least one Denial of Service (DOS) attack on the Obamacare exchange.  Talk about irrelevant.   This is a site that crashes under the onslaught of about a dozen regular users.  A DOS attack could be executed by me and three of my friends just by trying to log on and create accounts.  First day exchange visitors are guilty of an unwitting DDOS attack just for navigating to the site.

I was just thinking this morning that it would have been a funny Onion article to show some average schlub with a headline that Joe Smith was being accused of a DOS attack for visiting the exchange on October 1.