看了下 WP 日志,有一大坨 "GET /wp-login.php HTTP/1.1" 200 的记录,每两次换一个 IP ,很明显是恶意访问。但问题是如果是尝试暴力破解密码不应该是 POST 吗? GET 有什么用?看后面也没跟类似于 ?user=xxx&password=xxx 之类的参数。
频率大概几秒到几分钟一次,也远达不到 DDCC 。
所以这种攻击究竟在干什么呢?
177.135.125.206 - - [13/Aug/2016:05:13:00 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
177.135.125.206 - - [13/Aug/2016:05:13:01 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
89.211.148.154 - - [13/Aug/2016:05:14:31 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
89.211.148.154 - - [13/Aug/2016:05:14:32 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
78.98.40.39 - - [13/Aug/2016:05:14:53 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
78.98.40.39 - - [13/Aug/2016:05:14:54 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
109.242.65.92 - - [13/Aug/2016:05:15:50 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
109.242.65.92 - - [13/Aug/2016:05:15:53 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
190.209.182.227 - - [13/Aug/2016:05:16:19 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
190.209.182.227 - - [13/Aug/2016:05:16:20 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
2a01:cb04:80c:4200:6df1:44b1:d7fa:79f4 - - [13/Aug/2016:05:18:13 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"
2a01:cb04:80c:4200:6df1:44b1:d7fa:79f4 - - [13/Aug/2016:05:18:14 +0800] "GET /wp-login.php HTTP/1.1" 200 2834 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.1"