Wednesday, 17 April 2013

How to Protect your Wordpress Website login against Brute Force Attack




What is a brute force attack and how to protect yourself against it ...

Brute-force attack is a way for someone to guess your account password by using a trial-error method. During a brute-force attack in a very short of time a high number of possible passwords are tried against your account. Brute-force attack methods are sophisticated in the sense that all possible combinations, of letters, numbers and special symbols are tried against your account password.

Most of these attacks are automated, and executed from one or many computers or powerful servers. Depending on the computing power, and the number of computers from which the attack is initiated, the brute-force attack can be a very serious threat for every site and web application.

The best friend for every brute-force attack is a weak account password. Passwords such as “123456″ and “pass” can be easily brute-forced in the range of minutes! Number one rule is tonever use a week/dictionary based password – please, refer to the following blog article “How to select a strong password” for more information on this subject. Changing (where possible) your default site administrator username to a non-standard/non-dictionary word can also help significantly for the overall brute-force attack security.

The brute-force attack method is gaining significant attention and is becoming number one threat for most of the popular web applications. We have taken the time to describe some of the more effective way to combat these attacks depending on your application:
WordPress brute-force attack security:  
. Add a plugin to restrict the login attempts –a fact you should carefully consider is that by default WordPress will not provide you with a login limiter. Which is why it is up to you to add such plugin in order to protect your site. A plugin you can check is the Limit Login Attempts plugin which main goal is to do what its name suggests – limit the login attempts.
2. Pick a strong password – it is essential that your administrator and account password is very strong, preferably 12 characters in length.  Changing the default WP administrator username from ‘admin’ to something else is also a key. For more information on how to pick a strong password  please refer to the article How to select a strong password. Selecting a strong password is essential not only for your administrator password, but for all passwords needed for your site.
3. Change your password every few months, and do not use previously used passwords.
4. Change your WP Security keys along with changing your password. This will prompt all users to have to re-log in to your blog which will enhance your blog security. More information on how to change the WP security keys (salt) you can find in this blog post.
5. Review your log files – check your hosting log files, for multiple requests to your wp_login.php file. If you find something unusual, immediately change your password, and security keys. If you find certain IP, or as it is in most cases, group of IPs that are constantly accessing your wp_login.php page or your wp-admin section, that means that you are under a brute force attack and you should take extra measures to secure your WP blog.
You can find more WordPress security tips in our designated to WP blog post.
Joomla! brute-force attack security:

1. Select a strong password – For more information on how to pick a strong password please refer to the article How to select a strong password. Selecting a strong password is essential not only for your administrator password, but for all passwords needed for your site. 

2. Use extensions that could help you to secure your site against brute-force attacks, such as Securitycheck or Max Failed Login Attempts. The idea is to limit the number of computers (IPs) which can access your Joomla Administrator login page, and limit the number of allowed failed login attempts. If you notice computer IPs that are constantly being blocked for wrong logins, that means that you are under a brute-force attack and should take extra measures to protect your site.

3. Review your log files – your web site access log contains a lot of useful information. In case you notice that there are unusual “Gets”, and “Posts” to your administrator login page, then certainly you are under a brute-force attack and you must change your password, and install a login limitter plugin for your Joomla.
You can find additional Joomla security tips in our designated blog post.
Drupal brute force attack security:  

1. Selecting a Strong Password – For more information on how to pick a strong password  please refer to the article How to select a strong password. Selecting a strong password is essential not only for your administrator password, but for all passwords needed for your site.

2. Add a CAPTCHA module to your login form which will ensure better protection since it will serve as a second wall to a brute-force attack. We recommend the CAPTCHA Drupal module, which will provide you with various of configuration options.

3.  Install additional security modules – you can use the Drupal Login Security module, which will serve as a login limiter or use Secure Password Hashes which will add extra ‘salt’ to your passwords, and provide your Drupal with an additional shield.


Protect your Magento site from brute force attack

1. Use a strong password – For more information on how to pick a strong password  please refer to the article How to select a strong password. Selecting a strong password is essential not only for your administrator password, but for all passwords needed for your site.

2. Use a customized admin URL – by default this is yoursite/admin, and every hacker wanting to break your account will start with it. In order to prevent this from happening you should follow these steps
1. Open your /app/etc/local.xml configuration file
2. Locate <![CDATA[admin]]> and replace ‘admin’ with the path you would like to use. For example if you change it to mylocalplace, the admin path will become /mylocalplace
After you have changed this URL, refresh your Magento cache – use an FTP client to delete the content of the var/cache/ directory and that’s it.

3. Restrict admin access only to certain IPs – you can do this via your .htaccess/web_config file. This will ensure that only known IPs will have access to your admin area.

4. Require SSL for all login pages - since Magento is used for e-commerce, the data is usually very sensitive. This is why it is recommended all login details to pass through a secure connection.

Final thoughts:
When adding protection against brute-force attacks, you should keep in mind two very important factors. The first is that this type attacks are after your password (user or admin passwords), trying to guess it by using different combinations, and variations. Meaning that you should make sure your password is strong and that you change it on a regular basis. It is also essential to change your default Administrator username – since most brute-force attacks use the standard for a given application Administrator username and rarely the attacks are trying to guess your Administrator username and password at the same time.

The second factor is that in most cases the brute-force attacks will trigger a lot of false login attempts – which can be seen either in your hosting account “access log” files, or if the application you use provide a dashboard where you can review your login history. If the application you are using for your site allows for login limit protection or there are extra “login limiter” plug ins available that can be installed, you should activate/install them ASAP.

We would love to hear your comments, and thoughts on this very important matter. Please, share your thoughts with us in the section below. I hope that you found the above information useful. If you would like to share your comments, or recommend a safe plug in, please comment in the section below or contact me



Prevent Website Hacking...How to build a more secure password for all your online accounts !



A few days ago Prism published a list with the worst passwords where as expected you can find words such as ‘password’ , ‘123456’, ‘dragon’, ‘sunshine’, etc. As obvious as it might be not to set your password to  ‘password’, many people still do  - taking the chance of anyone guessing their passwords and gaining access to their accounts and services. The focus of this article is teaching the readers and our clients on how to create a stronger password.
Selecting a good password is critical and it depends at parts on the product for which the password will be used.


For most hosting products & services the following minimum criteria must be meet:
• Linux Web Hosting with  cPanel control panel: the password requirement is  a minimum length of 6 (six) characters.




• 

  • Windows Web Hosting with WebsitePanel  control panel: the minimum password length must be 8 characters one of which must be a number.

• For Windows Web Hosting – email server  Smarter Mail the requirement for email password is at least 8 characters in length and a maximum of 20; other requirements is at least one special symbol, and a combination of upper and lower case letters.
• For Windows Private JVM (Tomcat) manager NGASI you will need to select a password with at least 8 characters; the password needs to include also special symbol.
As you can see from these requirements your “good password” at the very least should be 8 characters long.
Below are some good practices on how to pick a strong and more secure password for your products and services:
1) Find a word that has a certain meaning for you and then replace all the vowels with special symbols and numbers – for example ‘a’ with ‘@’, ‘o’ with ‘0’, etc. This replacement doesn’t have to follow any rules available on the net, as long as you are able to remember it.
Do not be tempted to use the numbers on your phone to replace the letters. Though this technique is part of the Leetspeak (replacing letters with numbers) it is pretty easy to be hacked. And in any case, do NOT use your username or your first name as a base for your passwords! I know it is tempting, but this is the first thing a hacker would try if decided to break your account.
For example: grapefruit becomes Gr@p5fru#t … not bad, right?
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4YCWgpfa7wbJstoryOJjrxKW5AGKQDrPuu1_Ggl1US3sgYS7koWmVnr90suVPgYoWlRaqxjjUvKpiRBNTao-WaK0mhWvNsbtYV44w1ZceD0INA_CSHdPEhNKJy01bccYo3EBf0SuelqS_/s1600/magento.jpg2) Select a password length with which you feel comfortable with. You will be requested for at least 6-8 symbols in most of the cases, so pick a pass longer than that. The rule of thumb is that the longer the password, the more difficult it is to be hacked. The most common length is 8 characters, but you should try to make it longer if possible (and if you can remember it). A good and is way to extend the length of your pass it to add numbers to it. Make sure that the sequence of numbers is easy for you to remember, and do not use your birthday as a sequence or the last 4 digits of your phone (since it can be easily guessed) – you can pick a date or a number that has some meaningful for you, for example the year in which you bought your first car or you have started your first job.

For example: bicycle could become B#cycle2003 (don’t forget to include at least one special symbol and one upper case letter)
3) Another often recommended method is shortening a sentence into a word. How does this work? You make up a sentence which is very easy for you to remember and then you take the first letter or the first two letters of each word and create your “good password”. You can even create your own algorithm – for example you can take the first and the last letter of each word, or the first letter from the first word, the second from the second word and so on. The only limitation here is yourself and with which codes you will feel most comfortable. If you decide not to substitute a letter with a number, you can always add one at the end.

For example: ‘My first pet was named Jessy’ becomes m*ftptwsndJ*1
4) Once you have shortened your sentence in a single word, you can create different combinations and use them for different services/accounts
For example: the word m*ftptwsndJ*1 can become “m*ftptwsndJ*1fb” or “m*ftptwsndJ*1gmail”
5) Instead of shortening words you can simply add couple of words together using a special symbol. For example: Jessy and orange can become “J52sy&0r@ng5″. Here I have used & as the link between the words and have replaced ‘e’ with 5, ‘a’ with @, ‘o’ with ‘0’ and the double ‘s’ with 2s which is one way to represent double letters.
6) Use upper and lower cases – you can pick a word such as “grapefruit” and you can change every second letter to be capital. In this case “grapefruit” will become “gR@P5FrU#T”
7) Use misspelled words – especially if you tend to make a mistake when entering your password, you can take advantage of this.
For example: grapefruit can easily become grapwfruti, which will turn into gr@pwfrut#1

As a summary to be considered good password it has to be at least 8 characters long; contains both upper and lower case characters, and has special symbols and numbers in it. It’s a good advice not to keep your password stored in your computer or on a piece of paper because you never know in which hands it might fall into. Try to memorize one strong password, and use different variations of that password for different accounts. If you can trust your memory the best way will be to have different passwords for your most important accounts and even better to change them on a regular basis. How many passwords you would have mainly depends on the risk you are willing to take and on the number of passwords you feel comfortable remembering.
In any case, I think that we all agree that we should not use the word ‘password’  for any of your services and online accounts. If you are in love with this word and insist on using this word, only a couple of changes are needed and you can end up with your “dream” password. For those of you, who have very complex passwords, good job; for the rest, now is the perfect time to change your existing passwords so that nobody can crack your accounts, or at least make it very difficult to do so.
Just so that I can support  the above password examples , I have tested each of them with the  Password meter tool from http://www.PasswordMeter.com – here the results of these tests:


 Password
Score
Complexity
Grapefruit
8
Very Weak
Gr@p5fru#t
93
Very Strong
Gr@pwfrut#1
91
Very Strong
gR@P5FrU#T
98
Very Strong
Bicycle
8
Very Weak
B#cycle2003
100
Very Strong
m*ftptwsndJ*1
99
Very Strong
m*ftptwsndJ*1fb
100
Very Strong
J52sy&0r@ng5
100
Very Strong
Password
8
Very Weak
P@2sW0Rd
84
Very Strong


Now that you know how to select a good password we recommend that you take your time and update all of your account service passwords. We do strongly encourage all of our clients to pay specific attention to the following passwords: Control Panel, FTP, Email, Database,  and at highest importance to any remote management services such as SSH or Administrator RDP access (for VPS and Cloud Clients).
   
We hope that you find this article useful. We would love to hear your comments and feedback in the comments section below. or contact us directly