• Under attack

    Some people will have noticed that some of the websites that I look after have been under attack this week. Naughty people are trying to gain control of a load of web servers and mine has been one of the many targeted.

    What has been happening is that someone has had the great idea of trying to crack as many WordPress sites using a brute force attack. That means setting computers up to try to log in to a site automatically using a computer program to try as many different password combinations as possible. The same technique was a feature in the film War Games of some years ago – the computer in question being the one which controlled US Missiles. My computers have slightly less power.

    People do this to gain control of servers so they can do naughty things like use them to send out lots of spam all at once. (Ever wondered where it came from?)

    The consequence for my readers this week is that at some times, my websites have been showing up in various security systems (Norton, AVG) as infected and this meant that people couldn’t get access to the sites whilst this protection was in use.

    I think I’ve nipped it all in the bud.

    For anyone experiencing the same trouble, here’s some of what you can do to help.

    • Change the password combination on your server.
    • Change the password combination on your blog/WordPress installation.
    • Install a plugin like Anti-Malware and use it to scan and remove malicious code that has been injected into your site.
    • Install a plugin like Better WP Security and word through what it recommends. At the very least, make sure you don’t have your administrator account in the name “admin” and use the plugin to lock down your login screen – you can set it to ban an incoming IP address after 10 failed attempts to log in, for example.
    • Don’t panic.

    For anyone who isn’t having the same trouble, consider doing the security things anyway.

4 responses to “Wiki?”

  1. Tim Avatar
    Tim

    Experience here is
    a) TWiki is amazingly awful to migrate between versions, requiring a fair bit of Perl knowledge
    b) Dokuwiki might be only written in PHP, but it’s an absolute joy to use, especially the plugin system (paste URL to zip-file into box, it downloads and unpacks it for you!)

    One of these I use for work, the other is rapidly becoming my general to-do-list / organization / life at home. Major plug for dokuwiki 🙂

  2.  Avatar
    Anonymous

    Docuwiki
    I’ll have a look at Docuwiki though I do have a working version of TWiki currently running at the moment. I know no Perl, and it was a bit of a challenge installing it in the first place.

  3.  Avatar
    Anonymous

    Docuwiki

    Well, I’ve looked at Docuwiki but can’t install it.

    Life is just too short for this:

    • Set up the correct permissions
      • Usually the webserver runs as a unprivileged user eg nobody, www-data or apache
      • The webserver needs to be able to write to some files and directories (so change the chown nobody to match your configuration e.g. chown apache …)
      • If you’re using access control, you need to change the group ownership permissions on the appropriate files and make them writeable by the web server user’s group (use group ownership, because as a user/web site admin, you’ll need to edit the files directly) – otherwise, users won’t be able to register, and you won’t be able to set ACL controls via the web interface, and you’ll get error messages; I always forget these steps when I do an install using ACL features, so that’s why I’m adding them here.
      • The group name the web server runs as is usually identical to the user name, except in the case of the “nobody/nogroup” combo – but check your server config just in case (just a user, TL)

     

  4. muratore Avatar
    muratore

    molella discotek people molella discotek people serx serx midi file graqtis midi file graqtis cenangium cenangium sansui amplificatore sansui amplificatore le ragazze di viterbo le ragazze di viterbo nissan terrano autocarro nissan terrano autocarro torturatore torturatore akg terni akg terni mercedes 270 serie c mercedes 270 serie c rokepo zola predosa rokepo zola predosa totò peppino e la dolce vita totò peppino e la dolce vita la rubrica di costantino e alessandra og la rubrica di costantino e alessandra og effects processor pro 2 2 effects processor pro 2 2 ludmila radchenko ludmila radchenko officer officer ospedale umberto primo ospedale umberto primo le tre demo di lords of everquest le tre demo di lords of everquest magicolor 2450 magicolor 2450 santo domingo viaggio santo domingo viaggio back street boys non mi lasciare cosi back street boys non mi lasciare cosi haiduchii din tei dragostea haiduchii din tei dragostea comunita economica comunita economica tm net my tm net my paradise cracked trailer paradise cracked trailer lettori cd gemini lettori cd gemini consultazioni provinciali 2004 consultazioni provinciali 2004 at 160ml siracusa at 160ml siracusa certificazioni di qualita certificazioni di qualita ipod 20 accessori ipod 20 accessori forbidden colours forbidden colours depurazione delle acque depurazione delle acque limpbizkit behind blue eyes limpbizkit behind blue eyes localizzazione localization localizzazione localization snow bo snow bo diablo editor diablo editor speed (lazy dog software) v1 0 speed (lazy dog software) v1 0 shakira screensaver shakira screensaver scuole di regia scuole di regia computer cable computer cable siti lesbici siti lesbici maradino maradino milano teknival 05 milano teknival 05 prg torino prg torino trasporti piemonte trasporti piemonte honsen honsen trenet charles trenet charles chi ti dice chi ti dice testo e traduzione emon testo e traduzione emon muratore muratore muratore

Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Posts

  • 6'U

    Last night’s episode of Six Feet Under did end with a surprising thud. What I could not really come to terms with was the Quakers in the Quaker Meeting sitting in pews in rows. Are there really Quakers who don’t face one another in meeting? Their singing of Holly Near’s song “Singing for our Lives”…

  • Sermon – 2 October 2005

    One of the things that we are being asked as Christian people more and more, is to tell people how to live. We used to be the ones who were there to tell people how to come close to God, and many of us still want to do that. The trouble is, people think that…

  • Which saint are you?

    Here is the result of a quiz which is doing the rounds at the moment. The odd thing is that I've actually been to the tomb of St Athanasius in Cairo. More details in wikipedia here:  http://en.wikipedia.org/wiki/Athanasius (The tomb itself was rather smelly). You are Athanasius! You are willing to fight alosing battle, just to make sure that the truthis…

  • Theology Flamb

    Perhaps the most impressive thing that I've seen this week was someone set fire to a mushroom stroganoff  (which had been doused in brandy) whilst conducting a rather complicated theological debate with me which began at the General Synod earlier in June.The question is over whether baptism is a pre-requisite of admission to communion. The…