Brute force Attack on Fragtard

Kenadian

Staff member
Site Admin
The site was down for about an hour tonight as Tech. Support could not rid the blog of a brute force attack against the Wordpress Admin Login Page.

The only answer to help relieve the Server load was to Suspend the Fragtard Account.

I've since unsuspended it and added a plugin to Wordpress that denies access via IP, cookies, etc., to the WP Admin page after 4 failed attempts.

Hopefully this resolves the issue but a part of me worries this is just the beginning.

If you happen upon the site and see it suspended, it's not because the bills aren't paid it's because a serious attempt is being made at hacking into the Blog.
 

HaJa

Hardcore
Noticed it this morning here when i tried to access it.
Time in Sweden was around 0800.
 

Engnr

Moderator
Someone really has the time on their hands to do something like that to our little spot of the internet? Crazy......
 

Kenadian

Staff member
Site Admin
But on a side note it seems faster now when it's up again :D
It's possible that we've been getting hit for a while now but not to the extent it was last night. Upon unsuspending the Fragtard account the first time around, Tech. noticed a jump in Server Load to 60% immediately upon unsuspension.

Someone really has the time on their hands to do something like that to our little spot of the internet? Crazy......
It's not a person and I don't believe it's aimed at us, it's aimed at Wordpress installs. Every Software online has a fingerprint that a bot can be trained to look for. Run the bot for a few minutes and my guess is it returns thousands (if not millions) of potential targets.

I don't know the specifics but it's likely all automated and all that's happening is the WP Admin Login page is being attacked to gain access. The hardware running these attacks these days is easily powerful enough to hit the page with thousands of requests in mere seconds which is what is bringing our Server to it's knees.

Fortunately I do the best I can to protect our encrypted data and anyone who's gained .ftp access knows how convoluted my Password Algo is. There not impossible to crack but the time needed to crack my mixed caps and alphanumeric passwords is currently difficult enough to stem 99% of all attacks, maybe more.

Since the attacks all happen from the same address or set of addresses, software that can ban based off IP, cookies, etc., is basically the best option as an attack is theoretically stemmed at a set number of attempts; in our case 4.

This only works however if the machine running the algo maintains IP addresses and cookies which my guess is most if not all do but the time will come (assuming it hasn't already) where IP's and cookies are changed/cleared after each request.

...and so the battle continues.
 
Last edited:

little P

Super Mod
It's possible that we've been getting hit for a while now but not to the extent it was last night. Upon unsuspending the Fragtard account the first time around, Tech. noticed a jump in Server Load to 60% immediately upon unsuspension.



It's not a person and I don't believe it's aimed at us, it's aimed at Wordpress installs. Every Software online has a fingerprint that a bot can be trained to look for. Run the bot for a few minutes and my guess is it returns thousands (if not millions) of potential targets.

I don't know the specifics but it's likely all automated and all that's happening is the WP Admin Login page is being attacked to gain access. The hardware running these attacks these days is easily powerful enough to hit the page with thousands of requests in mere seconds which is what is bringing our Server to it's knees.

Fortunately I do the best I can to protect our encrypted data and anyone who's gained .ftp access knows how convoluted my Password Algo is. There not impossible to crack but the time needed to crack my mixed caps and alphanumeric passwords is currently difficult enough to stem 99% of all attacks, maybe more.

Since the attacks all happen from the same address or set of addresses, software that can ban based off IP, cookies, etc., is basically the best option as an attack is theoretically stemmed at a set number of attempts; in our case 4.

This only works however if the machine running the algo maintains IP addresses and cookies which my guess is most if not all do but the time will come (assuming it hasn't already) where IP's and cookies are changed/cleared after each request.

...and so the battle continues.
wow... what a bunch of assholes... thanks for doing all you do ya big gay moose :friends:
 
Its the Taliban, I know it. They want to take us down because we give the internet hope. We show the world that you can stand up against ones oppressors and those we oppress. And come together to play games for peace and war alike. That all races and all nations can work harmoniously and inharmoniously against evil and good.
 
Last edited:

Kenadian

Staff member
Site Admin
lol let the conspiracy theories begin :)

As a side note if anyone experiences site related issues please let me know with as much info as possible such as:
  • Date and Time
  • Brief description of issue; copy/paste any error messages
  • Browser and browser version

Thanks all for your continued support!
 

Twitch

Latest posts

iRacing Special Events 2026

ROAR: LMP3, GT4, Touring
  ~ Jan 9 - 10
Daytona 24: GTP, LMP2, GT3
  ~ Jan 16 - 18
Bathurst 12: GT3
  ~ Feb 20 - 22
Sebring 12: GTP, LMP2, GT3
  ~ Mar 27 - 29

Forum statistics

Threads
3,848
Messages
48,144
Members
627
Latest member
FUNsizeMEX
Top Bottom