Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




2 posts

Wannabe Geek


Topic # 223200 19-Sep-2017 00:50
Send private message quote this post

Long time reader, first time poster... hi all!

 

I have a VPS for hosting which I am having issues with an apache attack from a computer somewhere.

 

I understand the basics but I need someone's help to find the offending machine and fix the issue. The error I get is below, I have many like it. I have asked the host to check for viruses which they have and they cannot find any issue. I'm using a laptop myself which was off at the time of this error so I don't think it's me. 

 

 

 

[Fri Sep 15 10:27:20.897763 2017] [:error] [pid 404] [client 96.127.170.15:41786] [client 96.127.170.15] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "13"] [id "10014"] [msg "ip address blocked for 15 minutes, more than 3 login attempts in 3 minutes."] [hostname "secaccountants.com"] [uri "/wp-login.php"] [unique_id "WbvxWDGWhzE8Nx4NrTWnWQAAAF8"]

 

 

 

 


Create new topic
6689 posts

Uber Geek
+1 received by user: 3063

Moderator
Trusted
Subscriber

  Reply # 1868315 19-Sep-2017 06:54
2 people support this post
Send private message quote this post

That isn't an Apache attack - it is instead informing you it prevented a login to your Wordpress Admin portal.

 

Put the site behind Cloudflare (https://cloudflare.com).





Michael Murphy | https://murfy.nz
Want to be with an epic ISP? Want $20 to join them too? Well, use this link to sign up to BigPipe!
The Router GuideCommunity UniFi Cloud Controller | Ubiquiti Edgerouter Tutorial


IcI

460 posts

Ultimate Geek
+1 received by user: 101

Trusted

  Reply # 1868361 19-Sep-2017 08:33
2 people support this post
Send private message quote this post

Have to agree with michaelmurfy; start with Cloudflare or one of its competitors. Cloudflare do have a $0 plan for personal sites.

 

Your web site is using Wordpress. Looks like they are trying to find unpatched systems or ones with a default password. It is very unlikely that you will find the offending machine. Most likely they are zombie or bot nets doing the bidding of a master in the background.

 

Strengthen your security posture

 

     

  1. Don't host your login page on port 80.
  2. Keep WP patched & updated
  3. Keep your server patched & updated
  4. Decrease your threshold when you start to block a malicious attempt

 

 


 
 
 
 


13164 posts

Uber Geek
+1 received by user: 2191

Trusted
Subscriber

  Reply # 1868388 19-Sep-2017 09:09
Send private message quote this post

Putting a site behind CloudFlare is only useful if you have a Firewall that prevents access from non-cloudflare IPs. Your serve IP hasn't changed and is otherwise still accessible.

 

That warning message isn't really a problem. I use fail2ban to add attacker IPs to the CloudFlare firewall, and there's no direct access to my IP. AWS is good like that, lots of control.





AWS Certified Solution Architect Professional, Sysop Administrator Associate, and Developer Associate
TOGAF certified enterprise architect
Professional photographer




2 posts

Wannabe Geek


  Reply # 1869884 21-Sep-2017 01:16
Send private message quote this post

Thank you all for the replys. I will make changes as suggested and hope it's stays ok. Thanks


Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Vodafone TV — television in the cloud
Posted 17-Oct-2017 19:29


Nokia 8 review: Classy midrange pure Android phone
Posted 16-Oct-2017 07:27


Why carriers might want to embrace Commerce Commission study, MVNOs
Posted 13-Oct-2017 09:42


Fitbit launches Ionic, its health and fitness smartwatch
Posted 12-Oct-2017 15:52


Xero launches machine learning automation to improve coding accuracy for small businesses
Posted 12-Oct-2017 15:45


Bank of New Zealand uses Intel AI to detect financial crime
Posted 12-Oct-2017 15:39


Sony launches Xperia XZ1, a smartphone with real-time 3D capture
Posted 11-Oct-2017 10:26


Notes on Nokia’s phone comeback
Posted 10-Oct-2017 10:06


Air New Zealand begins Inflight Wi-Fi rollout
Posted 9-Oct-2017 20:16


The latest mobile phones in perspective
Posted 9-Oct-2017 18:34


Review: Acronis True Image 2018 — serious backup
Posted 8-Oct-2017 11:22


Lenovo launches ThinkPad Anniversary Edition 25
Posted 7-Oct-2017 23:16


Less fone, more tech as Vodafone gets brand make-over
Posted 6-Oct-2017 08:16


API Talent Achieves AWS MSP Partner Status
Posted 5-Oct-2017 21:20


Stellar Consulting Group now a Domo Partner
Posted 5-Oct-2017 21:03



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.