Failed login attempts

It seems that some people have discovered our actual login URL. Very well done! But seriously, did you actually think “deface” is a valid username? Since we survived 2017 without any interruption or intrusion of any kind, New Year’s was only a couple of days ago, please accept our belated Christmas gift: Neither “admin” nor “deface” are valid usernames Shocker, huh?
Continue reading

The best protection is free

Judging from the server logs, at least you are trying. Your lack of imagination is curious, though. Automated SQL injection attempts in 2017 – really? If that’s the best vector you can think of, then well… best of luck. A few short words about security measures taken at our side: Only a couple of free plugins.
Continue reading

Attacking WordPress

We just published a list of general attack vectors and a couple of tools you can use to try and penetrate WordPress. Today’s tip: Think bigger! WordPress is hosted on a web server. If the WordPress you’re trying to get access to is set up like a goddamn fortress, maybe the underlying web server is not?
Continue reading