WordFence Alerts - Increased Attack Rates

Cash Builder

BuSo Pro
Joined
Jan 14, 2017
Messages
454
Likes
607
Degree
2
I woke up this morning to 47 emails from Wordfence saying that they have detected and blocked multiple attacks in the last 10 minutes. The emails spanned over a period of about 3 hours.

Here is some text from one of the emails:

The Wordfence Web Application Firewall has blocked 185 attacks over the last 10 minutes. Below is a sample of these recent attacks:

June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: email=../../../../../../../../../../windows/win.ini .tst
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: email=../../../../../../../../../../boot.ini
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: url=/\../\../\../\../\../\../\../etc/passwd
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: email=../../../../../../../../../../windows/win.ini
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: url=invalid../../../../../../../../../../etc/passwd/././././././././././././././././././././././././././�
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: email=/\../\../\../\../\../\../\../etc/passwd
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: url=../.../.././../.../.././../.../.././../.../.././../.../.././../.../.././etc/passwd
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: url=../..//../..//../..//../..//../..//../..//../..//../..//etc/passwd
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for Directory Traversal in POST body: email=invalid../../../../../../../../../../etc/passwd/././././././././././././././././././././././././././�
June 26, 2017 8:14am 113.200.58.51 (China) Blocked for LFI: Local File Inclusion in POST body: url=/etc/passwd

I have the free version of Wordfence. Is there anything I need to do? Or is this just Wordfence doing its job?
 
I have the same problems. A lot of login attempts over periods of days

So following this thread
 
I had it a few weeks back, just the once, then no more. Good to know WF is doing it's job well :smile:
 
Considering the speed it happens it looks to be an automated attack that is looking for a misconfigured server.

This probably happens more than you'd think, but if things are up to date and set up correctly you should be fine. Servers are constantly being scanned like this in a variety of ways, as I'm sure there are lots of misconfigured setups out there that are easily exploited. Happens a lot to your SSH and other ports too.
 
Back