{"id":5164,"date":"2013-04-12T20:53:53","date_gmt":"2013-04-12T15:23:53","guid":{"rendered":"http:\/\/blog.resellerclub.com\/?p=5164"},"modified":"2026-02-13T11:25:55","modified_gmt":"2026-02-13T11:25:55","slug":"global-attack-on-wordpress-sites","status":"publish","type":"post","link":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/","title":{"rendered":"Global Attack on WordPress Sites"},"content":{"rendered":"<p>As I write this post, there is an on going and highly distributed, global attack on wordpress installations to crack open admin accounts and inject various malicious scripts.<\/p>\n<p>To give you a little history, we recently heard from a major law enforcement agency about a massive attack on US financial institutions originating from our servers.<\/p>\n<p>We did a detailed analysis of the attack pattern and found out that most of the attack was originating from CMSs (mostly wordpress). Further analysis revealed that the admin accounts had been compromised (in one form or the other) and malicious scripts were uploaded into the directories.<\/p>\n<p>Today, this attack is happening at a global level and wordpress instances across hosting providers are being targeted. Since the attack is highly distributed in nature (most of the IP&#8217;s used are spoofed), it is making it difficult for us to block all malicious data.<\/p>\n<p>To ensure that your customers\u2019 websites are secure and safeguarded from this attack, we recommend the following steps:<\/p>\n<ol>\n<li>Update and upgrade your wordpress installation and all installed plugins<\/li>\n<li>Install the security plugin listed <a href=\"http:\/\/wordpress.org\/extend\/plugins\/better-wp-security\/\" target=\"_blank\" rel=\"noopener\">here<\/a><\/li>\n<li>Ensure that your admin password is secure and preferably randomly generated<\/li>\n<li>Other ways of Hardening a WordPress installation are shared at <a href=\"http:\/\/codex.wordpress.org\/Hardening_WordPress\" target=\"_blank\" rel=\"noopener\">http:\/\/codex.wordpress.org\/Hardening_WordPress<\/a><\/li>\n<\/ol>\n<p>These additional steps can be taken to further secure wordpress websites:<\/p>\n<ul>\n<li>Disable DROP command for the DB_USER .This is never commonly needed for any purpose in a wordpress setup<\/li>\n<li>Remove README and license files (important) since this exposes version information<\/li>\n<li>Move wp-config.php to one directory level up, and change its permission to 400<\/li>\n<li>Prevent world reading of the htaccess file<\/li>\n<li>Restrict access to wp-admin only to specific IPs<\/li>\n<li>A few more plugins &#8211; wp-security-scan, wordpress-firewall, ms-user-management, wp-maintenance-mode, ultimate-security-scanner, wordfence, <a href=\"http:\/\/wordpress.org\/extend\/plugins\/better-wp-security\/\" target=\"_blank\" rel=\"noopener\">http:\/\/wordpress.org\/extend\/plugins\/better-wp-security\/.<\/a> These may help in several occasions<\/li>\n<\/ul>\n<p>Also, <a href=\"http:\/\/www.resellerclub.com\" target=\"_blank\" rel=\"noopener\">ResellerClub<\/a> recommends using SiteLock <a href=\"https:\/\/www.resellerclub.com\/sitelock\" target=\"_blank\" rel=\"noopener\">Website Security<\/a>, which is available free with all our cPanel accounts, to prevent the attack from affecting the functionality of your site.<\/p>\n<h2>Reseller Club Hosting Services<\/h2>\n<p><a href=\"https:\/\/www.resellerclub.com\/reseller-hosting\">Reseller Hosting<\/a> | <a href=\"https:\/\/www.resellerclub.com\/windows-reseller-hosting\">Windows Reseller Hosting<\/a> | <a href=\"https:\/\/www.resellerclub.com\/cloud-hosting\">Cloud Hosting<\/a> | <a href=\"https:\/\/www.resellerclub.com\/vps-hosting\">VPS Hosting<\/a> | <a href=\"https:\/\/www.resellerclub.com\/managed-vps-hosting\">Managed VPS Hosting<\/a> | <a href=\"https:\/\/www.resellerclub.com\/dedicated-server-hosting\">Dedicated Server Hosting<\/a> | <a href=\"https:\/\/www.resellerclub.com\/windows-dedicated-server-hosting\">Windows Dedicated Server<\/a> | <a href=\"https:\/\/www.resellerclub.com\/managed-dedicated-server-hosting\">Managed Dedicated Server<\/a> | <a href=\"https:\/\/www.resellerclub.com\/shared-hosting\">Linux Shared Hosting<\/a> | <a href=\"https:\/\/www.resellerclub.com\/windows-shared-hosting\">Windows Shared Hosting<\/a><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground:  !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 100% !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>As I write this post, there is an on going and highly distributed, global attack on wordpress installations to crack open admin accounts and inject various malicious scripts. To give you a little history, we recently heard from a major law enforcement agency about a massive attack on US financial institutions originating from our servers.<\/p>\n","protected":false},"author":30,"featured_media":6558,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[990,813,1533,4177],"tags":[46,45,34,134,40,42,410,411],"hashtags":[],"class_list":{"0":"post-5164","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news-en","8":"category-website-security-2","9":"category-tech","10":"category-wordpress","11":"tag-cheap-web-hosting","12":"tag-email-hosting","13":"tag-hosting","14":"tag-reseller","15":"tag-resellerclub","16":"tag-web-hosting","17":"tag-wordpress","18":"tag-wordpress-attack"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Global Attack on Wordpress Sites<\/title>\n<meta name=\"description\" content=\"There has been an highly distribute global attack on all wordpress installations on 12th April 2013. Here are few tips to keep your wordpress safe &amp; secure.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Global Attack on Wordpress Sites\" \/>\n<meta property=\"og:description\" content=\"There has been an highly distribute global attack on all wordpress installations on 12th April 2013. Here are few tips to keep your wordpress safe &amp; secure.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/\" \/>\n<meta property=\"og:site_name\" content=\"ResellerClub Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100005889763273\" \/>\n<meta property=\"article:published_time\" content=\"2013-04-12T15:23:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-02-13T11:25:55+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ankita Wadhwa\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/\",\"name\":\"ResellerClub Blog\",\"description\":\"Web Hosting &amp; Domains\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#webpage\",\"url\":\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/\",\"name\":\"Global Attack on Wordpress Sites\",\"isPartOf\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#primaryimage\"},\"datePublished\":\"2013-04-12T15:23:53+00:00\",\"dateModified\":\"2026-02-13T11:25:55+00:00\",\"author\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/45ecbcb4c8264977ac3f1901493b5e8a\"},\"description\":\"There has been an highly distribute global attack on all wordpress installations on 12th April 2013. Here are few tips to keep your wordpress safe & secure.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.resellerclub.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Global Attack on WordPress Sites\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/45ecbcb4c8264977ac3f1901493b5e8a\",\"name\":\"Ankita Wadhwa\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.resellerclub.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b3e3122796568d31f69370bd959959374f7f4d2c0e3a450791b629539fe0362f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b3e3122796568d31f69370bd959959374f7f4d2c0e3a450791b629539fe0362f?s=96&d=mm&r=g\",\"caption\":\"Ankita Wadhwa\"},\"url\":\"https:\/\/www.resellerclub.com\/blog\/author\/ankita-wa\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Global Attack on Wordpress Sites","description":"There has been an highly distribute global attack on all wordpress installations on 12th April 2013. Here are few tips to keep your wordpress safe & secure.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/","og_locale":"en_US","og_type":"article","og_title":"Global Attack on Wordpress Sites","og_description":"There has been an highly distribute global attack on all wordpress installations on 12th April 2013. Here are few tips to keep your wordpress safe & secure.","og_url":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/","og_site_name":"ResellerClub Blog","article_publisher":"https:\/\/www.facebook.com\/profile.php?id=100005889763273","article_published_time":"2013-04-12T15:23:53+00:00","article_modified_time":"2026-02-13T11:25:55+00:00","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ankita Wadhwa","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/www.resellerclub.com\/blog\/#website","url":"https:\/\/www.resellerclub.com\/blog\/","name":"ResellerClub Blog","description":"Web Hosting &amp; Domains","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.resellerclub.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#primaryimage","inLanguage":"en-US","url":"","contentUrl":""},{"@type":"WebPage","@id":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#webpage","url":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/","name":"Global Attack on Wordpress Sites","isPartOf":{"@id":"https:\/\/www.resellerclub.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#primaryimage"},"datePublished":"2013-04-12T15:23:53+00:00","dateModified":"2026-02-13T11:25:55+00:00","author":{"@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/45ecbcb4c8264977ac3f1901493b5e8a"},"description":"There has been an highly distribute global attack on all wordpress installations on 12th April 2013. Here are few tips to keep your wordpress safe & secure.","breadcrumb":{"@id":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.resellerclub.com\/blog\/global-attack-on-wordpress-sites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.resellerclub.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Global Attack on WordPress Sites"}]},{"@type":"Person","@id":"https:\/\/www.resellerclub.com\/blog\/#\/schema\/person\/45ecbcb4c8264977ac3f1901493b5e8a","name":"Ankita Wadhwa","image":{"@type":"ImageObject","@id":"https:\/\/www.resellerclub.com\/blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/b3e3122796568d31f69370bd959959374f7f4d2c0e3a450791b629539fe0362f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b3e3122796568d31f69370bd959959374f7f4d2c0e3a450791b629539fe0362f?s=96&d=mm&r=g","caption":"Ankita Wadhwa"},"url":"https:\/\/www.resellerclub.com\/blog\/author\/ankita-wa\/"}]}},"_links":{"self":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/5164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/users\/30"}],"replies":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/comments?post=5164"}],"version-history":[{"count":10,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/5164\/revisions"}],"predecessor-version":[{"id":39762,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/posts\/5164\/revisions\/39762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/media?parent=5164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/categories?post=5164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/tags?post=5164"},{"taxonomy":"hashtags","embeddable":true,"href":"https:\/\/www.resellerclub.com\/blog\/wp-json\/wp\/v2\/hashtags?post=5164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}