WordPress sites getting hacked ‘within seconds’ of TLS certificates being issued
portswigger.net
portswigger.net
There are a dozen competing 'security' plugins, with some saying 'you don't need any of them, WP is secure enough by default', and others saying 'you actually need ModSecurity [1] / Jeff Starr's nG firewall [2] on your server'.
The agency that (shoddily...) built the webshop installed Wordfence Free [3], so I've just kept that for now, though I feel it's kind of slow (but that might just be caused by the bottom-of-barrel performance of the shared webhost it's currently running on).
[1] https://github.com/SpiderLabs/ModSecurity
The thing about mod_security is that it is server based. If you are on a shared host you have no control over this and every shared host has a different setup. And if you maintain the server, well, mod_security is not that easy to get right and to stay on top of things. Wordfence adds its own weaknesses ofcourse, it is more code that needs to be vetted. But for recognizing an intrusion or hack, it can work quite well I think. (haven't been hacked in years). This thing about server or account based is similar when it comes to caching of generated html pages, Varnish is server wide, a plugin is WP wide.
Yeah, since the performance on the current host is dire, I've been debating whether to go with another shared host or to just go the VPS route. The company wants to get into Microsoft 365 for e-mail/files, so maybe Azure is another option. I'm okay with spending some time setting things up, but I definitely don't want to have to put a lot of effort into ongoing maintenance.
The first key to WP application security is to stick to popular plugins and install patches as fast as possible. The vast, vast majority of Wordpress problems involved known vulnerabilities. “Fail secure” was our approach: better to install patches ASAP and then deal with side effects, than to defer too long and risk getting hacked.
The 2nd key is to configure caching and use a CDN partner to soak up load and defend against DDOS. We used DosArrest but I think Cloudflare would be the obvious choice these days.
If you want to be even more secure, don’t let WP write to its own application files except for a few minutes when you’re installing updates. But, this is not standard and therefore a pain to manage.
Or, do what we did and get out of the hosting business. All our WP sites run at WP Engine now and they take care of a ton of performance and security work for us. Still have to stay on top of patches though.
Yeah, the plugin situation is something I'm trying to get on top of. One of the reasons I feel the site was shoddily built is that it came with two dozen (active and inactive) plugins, half of which are seemingly configured incorrectly. I've got rid of the inactive plugins, but I still need to look into the active plugins and get rid of the unnecessary ones.
Caching is something I've been wanting to look into too. Don't know if I'll go the CDN route right away, but I'll keep it in mind.
Looked at WP Engine pricing and they seem pretty expensive (the company wants to replace a few more of their outdated sites with WP, so I think that would put us in the €110/mo tier). It's a small company and their websites aren't heavily patronized, so performance isn't really critical. The main consideration is not getting pwned.
* https://www.wordpress.org/plugins/simply-static/
* https://blog.hubspot.com/website/create-a-static-website-usi...
It also (can be) very easy to use. Plugins and theme bundles can make this more complex, but it's easy enough to hand a properly secured and deployed WordPress to a marketing or media team and have them do 90% of the work, which is a win for dev and ops teams.
There is nothing specific to WordPress about the issue this post relates IIUC apart from the fact it is a privileged target.
And there's no news when everything is fine, which is most of the time.
https://w3techs.com/technologies/overview/content_management
I don't know enough about iOS to comment.
Very little software appears to be actually secure. Maybe OpenSSH is on that short list, but even that has occasional problems. But for it's attack value the known vulnerabilities seem low.
the cost of getting your wordpress hacked for seo spam is not much for a business that don't have any sensitive data on wordpress(not that they even take it into account...)
It auto installs through cpanel and has always had an admin password.
It’s actually really easy for non-professional webmasters to self host and saving $10-???/month on hosting fees is nice.
There is yet to be any CMS which has the ease of use and capability of WordPress and its plugins.
Unfortunately with it being that easy users are often not very security savvy and don't update plugins/themes and end up getting hacked.
With a caching plugin it's as fast as a static website most of the time, which gets me 100% on Page Speed Insight, and the hosting is on a domestic connection. I've made sure to not use too many extensions and javascript-heavy things, to disable some stuff and avoid huge assets but I've not spent that much effort on it.
I've been maintaining a few WordPress websites since 2015 and I would chose WordPress again today for any new site on which non technical people must intervene (to write or manage content). It just works and is user friendly.
I'm not sure any CMS would save you if you don't do your security homework though.
This specific vuln is related to the fact that every install uses /wp-admin/install.php for initial setup. You don't need a "dedicated team" to protect yourself from that.
If I was setting up my own Wordpress I would go through the wizard as quickly as possible to stop others setting it up before me and doing malicious things with it.
> I would go through the wizard as quickly as possible
You might not be quicker than a bot.
It doesn't even occur to a lot of people that this might be a bad idea. Salespeople, marketing, a sole prop, or someone who wants to set up a blog are all people who would have absolutely no idea how to do this right... and no clue that they're doing it wrong.
I’m just flummoxed trying to imagine a person who can install and run certbot, but doesn’t know how to (or think to) configure locally, or even set a basic HTTP password on the site until WP is configured.
People don't have to understand what they're doing to use a tool. Sometimes, like this time, there can be drawbacks to this.
Do it offline, or on a private subnet, or whitelist your IP, or well anything you can to keep the world away from your install until you have it setup. Or, if possible, don't install WordPress.
In defence of WP this could happen to any CMS, but wp it's the most popular by far
Passive DNS is the product e.g. https://www.circl.lu/services/passive-dns/
https://www.farsightsecurity.com/technical/passive-dns/passi...
https://www.anomali.com/blog/introduction-to-passive-dns-usa...
Unsurprisingly lots of outfits want to publicly advertise this as a white hat feature you can purchase from them, but it's just technology, it works fine for bad guys too.
"Publish DNS records" does not exist. There is no sort of "firehose" where anyone can subscribe to a feed of newly registered domains.
I guess someone could continuously request every possible entry over and over to see when I do that, but don’t think it’s likely.
What happens is that when say, somebody uses their AT&T phone to ask A? tialaramex.prepend.com the AT&T DNS servers tell them that's 10.20.30.40 and the AT&T DNS servers tell a passive DNS outfit, "At 18:26 UTC the answer to A? tialaramex.prepend.com was apparently 10.20.30.40"
Now, I'm sure that lots of HN readers have a local manually configured DNS resolver that of course isn't feeding passive DNS. And some of them might even have an upstream DNS resolver which is bootstrapped and that too does not feed passive DNS. It's not even difficult if you were insistent upon doing it.
But, the design guy's iPhone which he used to take a quick screenshot? Probably just uses a public DNS resolver. The woman who trains front line support and asked for a sneak peak ready to start training on the new site? She probably has 8.8.8.8 set as her DNS resolver.
So just like asking for the publicly trusted certificate, this is another way that your DNS names go from "Nobody would guess what that is" to public knowledge in seconds once they leave your hands.
Should there obviously be a unique, temporary password encoded in the wp-config.php that prevents this? Of course. Would it diminish "ease"? Yes, and therefore it won't happen.
They're deathly afraid of making anything more difficult to the lowest common denominator, and, by extension, the scammers of the world.
Do any of those automatic cert bots support "not_before" dates in the past, or pre-ordering and delayed rotation of certs?
For a site that’s on the Internet, it should be a lot easier to get a free certificate from LetsEncrypt and also have it renew frequently (automated).
But in production, your visitors will likely be scared off by the browser warning on a self-signed cert.
Turns out multiple plugins make changing URLs a feature behind a monthly paywall as a monetization strategy. The sobering thing is that the fix is to update tables in the database. There are various examples in github for these things, however most people just use a plugin that literally does a find and replace for the old URI and replaces with the new. Frightening...