Saturday, July 18, 2026

WP site down again - incident response once again

 A follow-up to this post, https://hnsws.blogspot.com/2026/07/incident-and-response-malicious-bots.html

One more outage, following which, the next day, after an hour or so of feeding logs to Gemini, here is its diagnosis.

Based on the logs provided, the outage was caused by a malicious bot attack and SQL injection fuzzing campaign targeting your WordPress site, which struck a database that was already under stress from large, legitimate .NET API queries.

I'm not so sure the large API queries were legitimate. Anyway, Gemini suggested,

  1. Block the Scanning IPs / Implement a WAF
  2. Harden WordPress Cron (wp-cron.php)
  3. Optimize .NET API Payloads - A 1.62 MB JSON response is quite large for a single API call. Consider implementing pagination, data compression, or caching.
I passed on this info to the dotnet developers and to the wordpress admins, and also added the following to the WAF firewall on cloudflare - 

(http.request.uri.path contains ".env") or
(http.request.uri.path contains ".git") or
(http.request.uri.path contains ".htaccess") or
(http.request.uri.path contains ".sql") or
(http.request.uri.path contains ".bak") or
(http.request.uri.path contains "wp-config") or
(http.request.uri.path contains "/.well-known/gecko") or
(http.request.uri.path contains "/.trash") or
(http.request.uri.path contains "/.tmb") or
(http.request.uri.path contains "/.dj") or
(http.request.uri.path contains "/phpmyadmin") or
(http.request.uri.path contains "../") or
(http.request.uri.path contains "..%2f") or
(http.request.uri.path in {"/0.php" "/0x.php" "/002.php" "/1.php" "/100.php" "/122.php" "/0.kb-v3.php"}) or
(http.request.uri.query contains "%27") or
(http.request.uri.query contains "'") or
(http.request.uri.query contains "union select") or
(http.request.uri.query contains "concat(") or
(http.request.uri.query contains "sleep(")

As suggested by Gemini, I have left the action as "Managed Challenge" - meaning that cloudflare will ask a captcha or something like that if any legitimate query contains any of these. 


No comments:

Post a Comment