.env files
-
Hello,
I have a question regarding the .env files. Unfortunately, my website has been under constant attack since 03.07. Initially, the attacker targeted the .env files in order to gain access using a hacked (older) WordPress login URL:
Date: 2024-07-03
Time: 21:58:31
IP: 136.243.212.110
Request: GET request with a suspicious parameter
User-Agent: serpstatbot/2.1 (advanced backlink tracking bot; https://serpstatbot.com/; [email protected])
Country: Germany
Size: 4360
Response time: 266The request with a suspicious parameter was the word of the old login URL, so it is sure, that the Hacker got some sensitive files. However, it was the older login URL. With your Plugin i changed this URL to another name.
After this and also other attacking requests, it appears that my website is infected with malware, as my hosting provider was able to detect something.
I must mention that my website is not officially accessible yet, and it is 99% certain that the attacker is an individual from a German company, as I had created a staging copy of my website for demonstration purposes just before. In order to create this staging copy, I deactivated the firewall of your plugin by deactivating and reactivating the entire plugin once, as I noticed that the firewall was not active in this state. So I created the staging copy in this state (additionally, I also disabled the function that prevented images from being transmitted) and only reactivated the firewall on the original website after creating the staging copy. Shortly after I shared the URL of the staging copy with this company, the attacks began and are still ongoing. However, my website is now under the “Under Attack” mode of my Hosting site, making it more manageable.
I would like to know if the .env files from your plugin are generally hidden or blocked to find out how much data the attacker could ultimately steal. Additionally, despite using now the Files .env deny codes in my .htaccess file I am unable to protect the .env files. No 404 error message is displayed and I still had constant and numerous attacks on the files until a few hours ago.
Thank you for your response and best regards,
albarosaP.S. Here is an example screenshot of how the .env requests look like: https://pasteboard.co/WphQ8k4ROb6s.png
- You must be logged in to reply to this topic.