• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

This is how some people trying to HACK my site.

elmocando

Active member
Oct 17, 2019
638
164
43
localhost
1593171770273.png

1593171797318.png

Can anyone please let me know how harmful those attacks were?
 

Attachments

  • 1593170840790.png
    1593170840790.png
    50 KB · Views: 47
Last edited:
1593171770273.png

1593171797318.png

Can anyone please let me know how harmful those attacks were?
Would be better if you could provide more info like website technology stack, how are you tracking this info, whether using security plugin/system or not, which hosting you are using, how come these requests were blocked (503) so you have some security in place, etc.

In general these attacks happen on websites and are dangerous if website is not built keeping in mind security, not so-secured/popular hosting and good reputed security plugin or system.

These are intended to gain control on your website by gaining access to your database. Unique trait for these type of requests are very frequent + less difference between requests + different ips + most importanty - request uri has query params (which are main route to gaining unauthorized access to database ultimately your website.)

So yes its dangerous & harmful in a way they will get control of your website and will put up a message that website has been hacked - owner shall contact on this email, etc asking owner to pay to gain back access.
 
  • Love
Reactions: elmocando
With cloudflare you can JS Challenge countries that most of these attack come from. It's got a minimal impact on your users since it's an automated process.
 

Attachments

  • screen.png
    screen.png
    35 KB · Views: 34
I am using Wordpress as CMS, Wordfence as security plugin and Litespeed Server (shared Hosting).
So you are saying that, they can access to my DB? How can I block DB access than?
 
With cloudflare you can JS Challenge countries that most of these attack come from. It's got a minimal impact on your users since it's an automated process.
What if I just select BLOCK China as action instead of JS Challenge. Will this rule just block all chinese IPs'?
 
I am using Wordpress as CMS, Wordfence as security plugin and Litespeed Server (shared Hosting).
So you are saying that, they can access to my DB? How can I block DB access than?
Best way to know this is to google how to make your website/wordpress website secure & make up a list of everything and than implement/include them in your website.

Some of the important mentions are -
* Hosting - Popular/Secured/Reputed
* CDN - Popular/Secured/Reputed
* Wordpress Security Plugin (+ Firewall) - Popular/Reputed
* Themes & Plugins - Only Popular/Secured/HighlyRated/Reputed
* Not to use nulled plugins from unverified sources or not use them all
* & Many many more actually need to sit for this, their are hell lot of things you can do to secure your website
 
Best way to know this is to google how to make your website/wordpress website secure & make up a list of everything and than implement/include them in your website.

Some of the important mentions are -
* Hosting - Popular/Secured/Reputed
* CDN - Popular/Secured/Reputed
* Wordpress Security Plugin (+ Firewall) - Popular/Reputed
* Themes & Plugins - Only Popular/Secured/HighlyRated/Reputed
* Not to use nulled plugins from unverified sources or not use them all
* & Many many more actually need to sit for this, their are hell lot of things you can do to secure your website
Wow.... Thank you.
I need to learn so many things now.
Cloudflare CDN I am using, Wordfence as Security plugin and Firewall is also Wordfence.
If you have any suggestions, please let me know.
At present I have just created Firewall Rules on Cloudflare and Blocked few countries.
Let see what will happen next.
 
  • Like
Reactions: theanswor
Block Digital Ocean, Huawei Cloud, Linode, Vultr as ISP's too using Firewall rules. People seem to send a lot of useless traffic using these services.
A lot of people are using these services as they are cost-effective and give away a lot of FREE usage worth $100 or more.
 
  • Love
Reactions: elmocando
Here is a screenshot of how many people try to still access even when blocked since past 1 year. I have just shared a very small screenshot. Screen Shot 2020-06-26 at 5.47.49 PM.png
 
  • Like
Reactions: elmocando
Block Digital Ocean, Huawei Cloud, Linode, Vultr as ISP's too using Firewall rules. People seem to send a lot of useless traffic using these services.
A lot of people are using these services as they are cost-effective and give away a lot of FREE usage worth $100 or more.
Okay, I'll do it.
Thank you for the information.
 
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock