Categories: SecurityWorkspace

Over 160,000 WordPress Sites Used In DDoS Attacks

Online criminals have leveraged a feature used by more than 162,000 WordPress sites to launch a large distributed denial of service (DDoS) attack.

They took advantage of Pingback, which seeks a file known as XML-RPC, a remote procedure call protocol that uses XML to encode its calls and HTTP to take it over the Internet. As that responds with a decent level of traffic, it makes for a handy amplifier.

DDoS over WordPress

Security firm Sucuri, which detected the attack, did not fully explain how the anonymous target was knocked offline. It’s likely this was a typical amplification DDoS, where the attacker spoofed the IP address of the target, sent out Pingbacks to the thousands of WordPress sites that had the feature switched on, which subsequently sent large volumes of traffic to the victim, which was also a WordPress site.

“Just in the course of a few hours, over 162,000 different and legitimate WordPress sites tried to attack his site. We would likely have detected a lot more sites, but we decided we had seen enough and blocked the requests at the edge firewall, mostly to avoid filling the logs with junk,” Sucuri said in a blog post.

“Can you see how powerful it can be? One attacker can use thousands of popular and clean WordPress sites to perform their DDoS attack, while being hidden in the shadows, and that all happens with a simple ping back request to the XML-RPC file.

“This is a well known issue within WordPress and the core team is aware of it, it’s not something that will be patched though. In many cases this same issue is categorized as a feature, one that many plugins use, so in there lies the dilemma.”

WordPress users who don’t want to be part of these attacks can either add a plugin that includes a preventative filter, or disable the feature altogether.

Attackers are leveraging a wide range of amplifiers, including age-old protocols like the Network Timing Protocol, which can produce epic traffic from small requests.

Are you a security expert? Try our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

View Comments

  • I knew pingbacks were a bad idea, but I thought they were just a variation on spam.This is a lot worse.

    Dave

  • WordPress has many vulnerabilities that can be exploited very easily. Most people do not know that their WordPress blog is a part of a large DDoS attack being carried out against a target.
    Most commonly pingbacks and trackbacks are used in WordPress to send requests to a target website. DDoS attackers make use of this vulnerability launch a Application Layer DDoS attack.
    We all should take steps to hardened our WordPress security so it can not be used to launch a large scale DDoS attack. Learn how to protect and prevent your WordPress website to be used in DDoS attack. Details: http://www.cloudways.com/blog/ddos-attacks-wordpress-security/

Recent Posts

UK CMA Seeks Feedback On Microsoft, Amazon AI Partnerships

British regulator invites feedback on major partnerships Microsoft and Amazon have struck with smaller AI…

13 hours ago

Google Fires More Staff Over Israel Protest

Another 20 staff have been fired by Google over Israel protest and their “completely unacceptable…

14 hours ago

Australian PM Hits Out At Elon Musk Over Knife Attack Video

Censorship row brewing down under, after the Australian Prime Minister calls Elon Musk an 'arrogant…

15 hours ago

US SEC Seeks $5.3 Billion Fine From Terra’s Do Kwon

Financial regulator asks New York judge to impose $5.3 billion in fines against Terraform Labs…

16 hours ago

Microsoft Launches Smallest AI Model, Phi-3-mini

Lightweight artificial intelligence model launched this week by Microsoft, offering more cost-effective option for Azure…

20 hours ago

US Senate Passes TikTok Ban Or Divestment Bill

ByteDance protest falls on deaf ears, as Senate passes TikTok ban or divest bill, with…

21 hours ago