Ticket #851 (new maintenance)
Bot attacks on Transition Culture
Reported by: | chris | Owned by: | chris |
---|---|---|---|
Priority: | major | Milestone: | Maintenance |
Component: | Parrot server | Keywords: | |
Cc: | ade, sam, annesley, paul | Estimated Number of Hours: | 0.0 |
Add Hours to Ticket: | 0 | Billable?: | yes |
Total Hours: | 0.25 |
Description
Yesterday there was a load spike on ParrotServer caused by a bot doing thousands of POSTs to xmlrpc.php.
Change History
Note: See
TracTickets for help on using
tickets.
I have added this to the main .htaccess file for http://transitionculture.org/
I also used IP tables to block the IP address doing this yesterday -- it did 45,856 POSTs, pretending to be Google, in one day:
We should also consider installing WP fail2ban -- the site sees a lot of attempts to brute force it, for example there are between 500 and 1.5k attempts a day on Transition Culture, 62.5k in the last month:
For the server as a whole, 1/3 million brute force attempts in the last month: