Attackers trick 162,000 WordPress sites into launching DDoS attack
arstechnica.com
arstechnica.com
Original HN post: https://news.ycombinator.com/item?id=7374577
As it was a relatively static site, I extracted the templates, removed the malware (which had injected itself into the header) and fudged it all into Jekyll[1] and uploaded it again as a static site to webfaction and changed the DNS entries.
Problem solved. Permanently.
I really wish people would do this more rather than pile loads of poorly maintained crap onto shared hosting.
Am I missing something?
[Edit: reworded for clarity]
"Pingbacks" are like trackbacks, except the referenced blog requests the URL that supposedly links back to it to verify there's actually a link there, and it appears that's what's being used to redirect the DDoS to the target server.
The obvious solution is to disable pingbacks. But they exist for a reason, and even if most people don't use them anymore there's going to be an uproar from the people who still do. Keep in mind there are still people pissed that blogrolls (links) were removed from WordPress core a couple versions ago. When was the last time you even heard the word "blogroll"?