Showing posts with label WordPress. Show all posts
Showing posts with label WordPress. Show all posts

Monday, 7 March 2011

Further attacks on WordPress under investigation

 
Following a massive attack on WordPress.com on 3 March, WordPress was hit by a second attack in the early hours of the morning of 4 March. Apparently there was some speculation that the attacks might be connected to the current unrest in the Middle East, but investigation now appears to show that these attacks originated in China, with some traffic from Korea and Japan.

The Automattic status page which displays the operating status for WordPress and other services still shows the two outages. A note on the second attack states, "Unfortunately, the DDoS attack from yesterday returned in a different form this morning and affected sitewide performance,The good news is that we were able to mitigate it quickly and performance returned to normal around 11:15 UTC. We are continuing to monitor the situation closely."

WordPress founder Matt Mullenweg commented to TechCrunch that one of the targeted sites was a Chinese-language site that was also blocked on Baidu, leading to the initial assumption that the attack was political. Later he said that closer investigation showed it more likely to have been business related, although there has been no response from the site's owner.

[H-Online]

Friday, 4 March 2011

WordPress Hit by Second Massive Attack in Two Days

WordpressThe main WordPress.com site was the target of a major DDoS attack yesterday that knocked the popular blogging platform offline for a couple of hours, and another attack that hit the site again Friday morning. The service is back online now, but the attacks may be an indication that the service could be collateral damage in some politically motivated attacks against WordPress blogs.

The first attack hit WordPress in the early afternoon on Thursday, and WordPress officials said that at its peak the attack traffic was in the range of several Gigabits per second, according to a report by TechCrunch.

"WordPress.com is currently being targeted by a extremely large Distributed Denial of Service attack which is affecting connectivity in some cases. The size of the attack is multiple Gigabits per second and tens of millions of packets per second," officials said in a statement during the attack.

Officials at WordPress and Automattic, which owns WordPress, did not say whether they'd identified the source of the attack, but they hinted about what may have been behind it.

"This is the largest and most sustained attack we’ve seen in our 6 year history. We suspect it may have been politically motivated against one of our non-English blogs but we’re still investigating and have no definitive evidence yet," Matt Mullenweg, founder of WordPress and Automattic, told TechCrunch.

A second attack hit WordPress early Friday morning Eastern time, severely hampering the site's availability. According to uptime and availability graphs provided by Automattic, WordPress.com availability plunged from 100 percent to roughly 66 percent at about 5 a.m. Friday.

"Unfortunately, the DDoS attack from yesterday returned in a different form this morning and affected site-wide performance. The good news is that we were able to mitigate it quickly and performance returned to normal around 11:15 UTC. We are continuing to monitor the situation closely," a statement from Automattic on the site says.

WordPress is far and away the most popular blogging platform on the Web and is the hosting provider for some of the more highly trafficked media sites, including CBS and TechCrunch itself.

[ThreatPost]

Thursday, 3 March 2011

WordPress.com Suffers Largest DDoS Attack In Its History

You have no idea how hard it was to get this post up, as WordPress.com, our blog host, is currently under a denial of service attack. It’s been almost impossible to access the TechCrunch backend for the past 10 minutes (everything seems to be stable now) and users have been receiving a “Writes to the service have been disabled, we will be bringing everything back online ASAP” error message.

From the VIP blog post:
WordPress.com is currently being targeted by a extremely large Distributed Denial of Service attack which is affecting connectivity in some cases. The size of the attack is multiple Gigabits per second and tens of millions of packets per second.
We are working to mitigate the attack, but because of the extreme size, it is proving rather difficult. At this time, everything should be back to normal as the attack has subsided, but we are actively working with our upstream providers on measures to prevent such attacks from affecting connectivity going forward.
We will be making our VIP sites a priority in this endeavor, and as always, you can contact us via xxxxx@wordpress.com for the latest update. We will also update this post with more information as it becomes available
WordPress did not mention the origin of the attack (DDoS =! Anonymous) and I have contacted founder Matt Mullenweg for more information. WordPress.com currently serves 30 million publishers, including VIPs TED, CBS and TechCrunch, and is responsible for 10% of all websites in the world.

WordPress.com itself sees about 300 million unique visits monthly.

Update: Automattic and WordPress founder Matt Mullenweg tells us that this is the largest attack WordPress.com has ever seen, and is likely to be politically motivated:

“There’s an ongoing DDoS attack that was large enough to impact all three of our datacenters in Chicago, San Antonio, and Dallas — it’s currently been neutralized but it’s possible it could flare up again later, which we’re taking proactive steps to implement.


This is the largest and most sustained attack we’ve seen in our 6 year history. We suspect it may have been politically motivated against one of our non-English blogs but we’re still investigating and have no definitive evidence yet.”


You can check here for the latest status updates.

[TechCrunch]