
What to do about a constant hacking script eating away at resources?
One of my websites for the last couple of months has been under a sustained hacking attack with fresh ip proxies used so its impossible to keep up with blocking IP's manually...
When checking cpanel log you can see that its just going around and around in circles with attempting to hack wp-admin (as well as checking for other platform files like .Net, aspx etc) ... Luckily they are unable to do anything as I have hardened up WP..
But its eating away at web resources... About 50% of the IPs are coming in from China, so I am tempted to block everything from China, but other than that it would be better if a more robust solution can be identified as if this is scaled up its going end up being a DOS attack... Looking at the logs its obvious you can tell the difference between a real person and a scripted call for e.g. calling a web page will also show image, css files etc.. But for the script you only see a one liner in the log file for the page and ip...So there must be something out there... The web host are unable to do anything either, the advice given is to wait it out....
Appreciate any ideas, advice on this....
Free Delivery Codes
Damon
CloudFlare Community Evangelist
Tips for using WordPress with CloudFlare