[BlueOnyx:21565] Re: Attack by a botnet.

Fungal Style wayin at hotmail.com
Tue Dec 5 00:27:42 -05 2017


Thanks for the tips, in hind sight I should have set it up a little better, even if it is just a testing site I was working on…. I noticed they disappeared for a bit and have returned even though I have the domain pointing to Google now with the files not present, maybe for this round I need to wait for them just to give up, or just delete the dns records, see what they do then… (

The .htaccess as a basic security measure is something I did not think about and that would prevent a bot from just searching.

Thanks again.

Will have a read to see if I can get any further ideas, though 2fa and such won’t stop them from trying, as not finding them now is not working either….

I can probably write it off to experience… and put a drupal, magento or joomla site on the domain… ( as WP is not my first choice, was just a test/dev site.
<kicks self hard>


On 5/12/17, 2:19 pm, "Blueonyx on behalf of Michael Stauber" <blueonyx-bounces at mail.blueonyx.it on behalf of mstauber at blueonyx.it> wrote:

    Hi Brian,
    > It is a form of brute force attack from what I can tell and it is low
    > bandwidth as they are requesting part of a file (possibly to go
    > undetected as it is 2/10’s of bugger all data).
    > As I am only using the domain for testing currently I placed a 301 on it
    > and renamed the files it is requesting, but they are still going.
    Yeah, it's a botnet trying a brute force login to your WordPress
    backend. I'd either rename the wp-admin directory to something else
    and/or would throw an additional password protection of that folder in
    (via .htaccess) or would install a WordPress plugin that requires
    additional steps for logins than just username and password.
    Like the Google Authenticator:
    From that list this one seems to be pretty complete:
    There are also a couple of other WordPress plugins around that offer
    additional protection. Without any endorsement this URL shows some of them:
    With best regards
    Michael Stauber
    Blueonyx mailing list
    Blueonyx at mail.blueonyx.it

More information about the Blueonyx mailing list