{"id":19392,"date":"2013-04-13T23:48:12","date_gmt":"2013-04-14T04:48:12","guid":{"rendered":"http:\/\/www.shamusyoung.com\/twentysidedtale\/?p=19392"},"modified":"2013-04-13T23:51:53","modified_gmt":"2013-04-14T04:51:53","slug":"botnet-attack","status":"publish","type":"post","link":"https:\/\/www.shamusyoung.com\/twentysidedtale\/?p=19392","title":{"rendered":"Botnet Attack"},"content":{"rendered":"<p><table   class=\"\" cellpadding='0' cellspacing='0' border='0' align='center'><tr><td><img src='https:\/\/www.shamusyoung.com\/twentysidedtale\/images\/splash_robots.jpg' class='insetimage'   alt='splash_robots.jpg' title='splash_robots.jpg'\/><\/td><\/tr><\/table><\/p>\n<p>For the last two days people have been sending me messages in email, Twitter, and Facebook. These messages invariably come in one of two forms:<\/p>\n<ol>\n<li>Hey Shamus! Did you know your website is down, or that it&#8217;s very slow?\n<li>Shamus, I just wanted to let you know that there&#8217;s a massive <a href=\"http:\/\/arstechnica.com\/security\/2013\/04\/huge-attack-on-wordpress-sites-could-spawn-never-before-seen-super-botnet\/\">brute-force attack of WordPress websites<\/a> going on right now.\n<\/ol>\n<p>These messages are probably related.<\/p>\n<p>Remember that a botnet is a bunch of hacked, trojan&#8217;d, malware-infected machines.  The machines are in living rooms, in classrooms, in offices.  Their owners probably have no idea they&#8217;re infected.  Maybe they were on some skeezy porn site. Or torrenting things they shouldn&#8217;t. Or maybe they clicked on one of those &#8220;Optimize your PC&#8221; scams. Whatever. The owners shrug, &#8220;That machine is slow these days.&#8221; <\/p>\n<p>This is a brute-force attack, which means thousands of different computers are going to thousands of different blogs and attempting to gain admin privileges using stupid, you-should-know-better credentials. My blog isn&#8217;t at any particular risk. While you can never say never, I shouldn&#8217;t be susceptible to brute-force over any kind of a reasonable timeframe. My password is what it should be: Long alphanumeric gibberish. It sucks to remember, but it ought to keep me safe for the next <a href=\"http:\/\/xkcd.com\/936\/\">few hundred years or so<\/a>. <\/p>\n<p>This is a friendly reminder to encourage your less-savvy friends to keep their machine clean. Their ignorance and hapless surfing habits are now a danger to everyone. This attack wouldn&#8217;t be worth it if large numbers of people didn&#8217;t use horrible passwords, and it wouldn&#8217;t be possible if large numbers of people didn&#8217;t allow their machines to be compromised. The un-savvy are now providing the incentive and the means for their own undoing. <\/p>\n<p>So yes. I know. Nothing I can do on my end.  I could spend hours scouring logs and banning IP&#8217;s, but I&#8217;d just be banning individual members of an amorphous blob. The best solution is to complain until the whole thing blows over.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For the last two days people have been sending me messages in email, Twitter, and Facebook. These messages invariably come in one of two forms: Hey Shamus! Did you know your website is down, or that it&#8217;s very slow? Shamus, I just wanted to let you know that there&#8217;s a massive brute-force attack of WordPress [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[111],"tags":[],"class_list":["post-19392","post","type-post","status-publish","format-standard","hentry","category-notices"],"_links":{"self":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/posts\/19392","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19392"}],"version-history":[{"count":0,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=\/wp\/v2\/posts\/19392\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.shamusyoung.com\/twentysidedtale\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}