Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




2 posts

Wannabe Geek


#223200 19-Sep-2017 00:50
Send private message

Long time reader, first time poster... hi all!

 

I have a VPS for hosting which I am having issues with an apache attack from a computer somewhere.

 

I understand the basics but I need someone's help to find the offending machine and fix the issue. The error I get is below, I have many like it. I have asked the host to check for viruses which they have and they cannot find any issue. I'm using a laptop myself which was off at the time of this error so I don't think it's me. 

 

 

 

[Fri Sep 15 10:27:20.897763 2017] [:error] [pid 404] [client 96.127.170.15:41786] [client 96.127.170.15] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "13"] [id "10014"] [msg "ip address blocked for 15 minutes, more than 3 login attempts in 3 minutes."] [hostname "secaccountants.com"] [uri "/wp-login.php"] [unique_id "WbvxWDGWhzE8Nx4NrTWnWQAAAF8"]

 

 

 

 


Create new topic
/dev/null
9386 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  #1868315 19-Sep-2017 06:54
Send private message

That isn't an Apache attack - it is instead informing you it prevented a login to your Wordpress Admin portal.

 

Put the site behind Cloudflare (https://cloudflare.com).





1199 posts

Uber Geek

Trusted

  #1868361 19-Sep-2017 08:33
Send private message

Have to agree with michaelmurfy; start with Cloudflare or one of its competitors. Cloudflare do have a $0 plan for personal sites.

 

Your web site is using Wordpress. Looks like they are trying to find unpatched systems or ones with a default password. It is very unlikely that you will find the offending machine. Most likely they are zombie or bot nets doing the bidding of a master in the background.

 

Strengthen your security posture

 

     

  1. Don't host your login page on port 80.
  2. Keep WP patched & updated
  3. Keep your server patched & updated
  4. Decrease your threshold when you start to block a malicious attempt

 

 





Please keep this GZ community vibrant by contributing in a constructive & respectful manner.


 
 
 
 


16092 posts

Uber Geek

Trusted
Subscriber

  #1868388 19-Sep-2017 09:09
Send private message

Putting a site behind CloudFlare is only useful if you have a Firewall that prevents access from non-cloudflare IPs. Your serve IP hasn't changed and is otherwise still accessible.

 

That warning message isn't really a problem. I use fail2ban to add attacker IPs to the CloudFlare firewall, and there's no direct access to my IP. AWS is good like that, lots of control.




2 posts

Wannabe Geek


  #1869884 21-Sep-2017 01:16
Send private message

Thank you all for the replys. I will make changes as suggested and hope it's stays ok. Thanks


Create new topic





Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

National Institute for Health Innovation develops treatment app for gambling
Posted 6-Jul-2020 16:25


Nokia 2.3 to be available in New Zealand
Posted 6-Jul-2020 12:30


Menulog change colours as parent company merges with Dutch food delivery service
Posted 2-Jul-2020 07:53


Techweek2020 goes digital to make it easier for Kiwis to connect and learn
Posted 2-Jul-2020 07:48


Catalyst Cloud launches new Solutions Hub to support their kiwi Partners and Customers
Posted 2-Jul-2020 07:44


Microsoft to help New Zealand job seekers acquire new digital skills needed for the COVID-19 economy
Posted 2-Jul-2020 07:41


Hewlett Packard Enterprise introduces new HPE GreenLake cloud services
Posted 24-Jun-2020 08:07


New cloud data protection services from Hewlett Packard Enterprise
Posted 24-Jun-2020 07:58


Hewlett Packard Enterprise unveils HPE Ezmeral, new software portfolio and brand
Posted 24-Jun-2020 07:10


Apple reveals new developer technologies to foster the next generation of apps
Posted 23-Jun-2020 15:30


Poly introduces solutions for Microsoft Teams Rooms
Posted 23-Jun-2020 15:14


Lenovo launches new ThinkPad P Series mobile workstations
Posted 23-Jun-2020 09:17


Lenovo brings Linux certification to ThinkPad and ThinkStation Workstation portfolio
Posted 23-Jun-2020 08:56


Apple introduces new features for iPhone iOS14 and iPadOS 14
Posted 23-Jun-2020 08:28


Apple announces Mac transition to Apple silicon
Posted 23-Jun-2020 08:18



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.