There appears to be a serious vulnerability here ..
-
These IPs were able to log into my WP site using blank user names, and with admin rights according to my Succuri Plugin. Here’s what it says ..
This is from my recent logins report, BTW ..
( ) 77.79.40.195 hst-40-195.splius.lt 3 weeks ago
( ) 93.103.21.231 93-103-21-231.static.t-2.net 4 weeks agoThe blank brackets usually indicate the user name.
BTW, these logins also show up in Wordfence ..
Lithuania Siauliai, Lithuania logged in successfully as ” “
IP: 77.79.40.195 [block]
Hostname: hst-40-195.splius.lt
26 days 1 hour ago
Slovenia Kranj, Slovenia logged in successfully as ” “
IP: 93.103.21.231 [block]
Hostname: 93-103-21-231.static.t-2.net
28 days 3 hours agoHOW THE HELL DOES A BLANK LOGIN WORK?????????????????? ARGGG!!!!!!! There has to be some back door that they used to sidestep the usual login method.
First and foremost I would recommend that you go to your user list and see if you have a blank admin user in your accounts.
Second, I would guess we need to start comparing plugins. When these logins occurred I could not figure out how access was achieved and I reset the site. That required trimming out edits of all the php files on my site (actually there are 2 sites that this happened to but only of them was damaged via atttacking the php files. The IP addresses from the hacks were the same on both sites. There is a name for this attack and it was historically known as generic.029.
BTW, there ought to be a set of forums specifically for security issues.
- The topic ‘There appears to be a serious vulnerability here ..’ is closed to new replies.