http://arstechnica.com/security/2013/04/huge-attack-on-wordpress-sites-could-spawn-never-before-seen-super-botnet/
Quote"Today, this attack is happening at a global level and WordPress instances across hosting providers are being targeted. Since the attack is highly distributed in nature (most of the IPs used are spoofed), it is making it difficult for us to block all malicious data."
QuoteAt least one company warned that the attackers may be in the process of building a "botnet" of infected computers that's vastly stronger and more destructive than those available today.
QuoteWith so much at stake, readers who run WordPress sites are strongly advised to lock down their servers immediately. The effort may not only protect the security of the individual site. It could help safeguard the Internet as a whole.
Email alert from Fluid Hosting:
A new botnet is targetting Wordpress installations all over the world. This botnet is working to brute-force attack Wordpress admin login details, so they can exploit sites. More details on the botnet can be found at : http://techcrunch.com/2013/04/12/hackers-point-large-botnet-at-wordpress-sites-to-steal-admin-passwords-and-gain-server-access/
In order to protect yourself, please ensure your Wordpress installation has a secure and complex password, http://en.support.wordpress.com/selecting-a-strong-password/. In addition, you may wish to change your Wordpress admin username to further increase security.
===========
Better change my ....oh, wait, all my stuff is static. Nevermind.
That explains why I'm getting more than usual IP blocks for attempted logins then.
Top defences seem to be to change your login name not to be "admin" and of possible move the login page to a different url (to stop the attempts causing load issues)
I use http://sucuri.net/ for all business critical WP sites
It must be a bad time to mass spam now
I beefed up my defenses: got rid of the User: admin (lazy bastard anyway) and used a super hard password that I had to write down.
Thanks for the tips! We really need to find something besides WP.
>We really need to find something besides WP.
WordPress isn't less secure than any other open source platform. The problem is insecure plugins and themes.
What Torben said.... plus it is a MASSIVE target.
When anything becomes the stardard it also becomes the target.
Right so we need a decent blog/cms script that is obscure, but easy to work with.
I have mine. You guys need to get your own.
Or just one without an easy to spot footprint.
Stealth Blog, that will be $36 Billion per install. :D
MovableType still puts out static pages. After WordPress bumped it out of the top market spot it has become quite obscure :(
I use Movable Type and like it.
Quite partial to a bit of Textpattern myself. http://textpattern.com/