{"id":173,"date":"2015-02-03T16:35:27","date_gmt":"2015-02-03T16:35:27","guid":{"rendered":"http:\/\/www.ahosting.net\/blog\/?p=173"},"modified":"2025-10-20T10:28:30","modified_gmt":"2025-10-20T10:28:30","slug":"protecting-your-wordpress-blog-from-a-ddos-attack","status":"publish","type":"post","link":"https:\/\/www.ahosting.net\/blog\/protecting-your-wordpress-blog-from-a-ddos-attack\/","title":{"rendered":"Protecting Your WordPress Blog From A DDoS Attack"},"content":{"rendered":"<p>You could be forgiven for thinking Distributed Denial of Service attacks aren\u2019t really anything to be taken seriously. After all, they\u2019re basically the hacking equivalent of driving a truck into a storefront. Although they can wreak a bit of havoc, they don\u2019t require any real technical skill, and as such they\u2019re pretty easy to defend against, right?<\/p>\n<p>Right?<!--more--><\/p>\n<p>Well&#8230;not exactly. The unpleasant truth is that the tools with which DDoS attacks are being carried out are becoming more complicated; more advanced. As a result, these attacks are growing increasingly difficult to defend against. They are, according to Incapsula, \u201ca growing and ever-changing threat.\u201d<\/p>\n<p>Let\u2019s back up a bit. I think we\u2019re getting a little ahead of ourselves here. How about first, we define precisely what a DDoS is?<\/p>\n<p>We can use that as a decent segue into how you can protect your WordPress blog from one &#8211; and why you should. Sound good? Let\u2019s get started.<\/p>\n<h2><b>The Anatomy Of A Typical DDoS<\/b><\/h2>\n<p>Imagine there are two guys &#8211; Larry and Gary. They\u2019re competitors; each one operates an online storefront in the same industry as the other. Gary, he\u2019s a pretty cool dude &#8211; business is booming for him, and he\u2019s taking a bunch of customers away from Larry through no fault of his own.<\/p>\n<p>Larry doesn\u2019t like that. Unfortunately, he has no idea how to legitimately compete with Gary, so he instead opts to turn towards rather more&#8230;insidious means. He gets himself in touch with a fellow named Jim.<\/p>\n<p>Now, Jim\u2019s a pretty tech-savvy guy, and more than a little amoral with his skills. As a sort of pet project, he\u2019s recently managed to inflict several thousand home routers with a nasty little worm that he\u2019s got total control over. Larry knows this, and approaches him with a proposition &#8211; take Gary\u2019s website down.<\/p>\n<p>After receiving payment, Jim directs his botnet to repeatedly connect to Gary\u2019s website. Eventually, it can\u2019t handle the traffic, and crashes. Larry takes full advantage of the lull in business, and begins siphoning Gary\u2019s customers away.<\/p>\n<p>See, at the end of the day, a distributed denial of service attack basically just floods a site or network with bogus requests. Eventually, the system can\u2019t handle the heavy load of traffic, and simply shuts down. Crude, but remarkably effective &#8211; it\u2019s one of the oldest attacks in the world.<\/p>\n<p>Now, in the example we gave above, Larry was motivated purely by competition. There are many other reasons someone might execute a DDoS against someone else. It might be a political statement. They might be using it as a cover for a far more serious crime &#8211; such as data theft or fraud. Or they might just be a hateful troll, out to wreak havoc on the world. The simple truth is that there\u2019s really no such thing as a typical DDoS attack &#8211; every DDoS is a little different from every other; some are even able to change the avenue through which they attack on the fly.<\/p>\n<p>Scary, right?<\/p>\n<h2><b>Let\u2019s Crunch Some Numbers<\/b><\/h2>\n<p>Now, in case you don\u2019t quite believe me yet that DDoS attacks are bad news, I\u2019d like to offer you a few facts and figures; see if these don\u2019t change your mind. We\u2019ll start with the Incapsula\/Imperva study we cited earlier.<\/p>\n<p>According to them, businesses hit by a DDoS attack lose an average of $40,000 <b>per hour of downtime. <\/b>The lost revenue alone should be enough to make you a bit nervous, even without taking into account what other consequences you might suffer. Just look at what happened back in 2013, when three banks in the US were <a href=\"http:\/\/www.itnews.com.au\/News\/354155,millions-stolen-from-us-banks-after-wire-payment-switch-targeted.aspx\">fleeced for several million dollars during a DDoS<\/a>.<\/p>\n<p>Anyway, that should be more than enough evidence that DDoS attacks are bad news, and you should protect yourself. Now let\u2019s move to the next step. How exactly do you <b>accomplish <\/b>that?<\/p>\n<h2><b>Now That You Know Why To Protect Yourself, Let\u2019s Talk About How<\/b><\/h2>\n<p>First thing\u2019s first, I\u2019d highly advise you to turn off pingback on your blog &#8211; reason being that if it\u2019s enabled, <a href=\"http:\/\/blog.sucuri.net\/2014\/03\/more-than-162000-wordpress-sites-used-for-distributed-denial-of-service-attack.html\">you could potentially already have been <b>part <\/b>of a botnet<\/a>. Yeah, that\u2019s a pretty glaring vulnerability. I\u2019m not sure why it still exists.<\/p>\n<p>Anyway, once you\u2019ve gotten that out of the way, there are a few different tactics you could use to keep yourself safe. The first is to seek out a plugin designed with DDoS mitigation in mind. Personally, I\u2019d recommend <a href=\"https:\/\/www.secsign.com\/wordpress-security-prevent-brute-force-ddos-attacks\/\">SecSign<\/a>. You might also consider talking with your host, assuming you\u2019re paying for hosting &#8211; the vast majority of hosts already have some form of DDoS protection in place; you might well be protected without even realizing it.<\/p>\n<p>Assuming your host doesn\u2019t come through and you don\u2019t like the selection of anti-DDoS plugins out there, there\u2019s also the option of hooking up with a cloud security provider like <a href=\"http:\/\/www.prolexic.com\/bing-north-america\/ddos-mitigation.html\">Prolexic<\/a> or <a href=\"http:\/\/www.dosarrest.com\/\">DOSarrest<\/a>. As a last-ditch sort of deal, you could also flirt with the idea of purchasing your own DDoS mitigation system &#8211; though I\u2019ll warn you that\u2019s not a choice for people who are a little light in the wallet. You\u2019ll need a big budget for most halfway decent DDoS prevention systems.<\/p>\n<h2><b>In Closing<\/b><\/h2>\n<p>The distributed denial of service attack is one of the oldest tricks in the book as far as cyber-crime is concerned. It\u2019s aged remarkably well, all things considered &#8211; even with today\u2019s technology, DDoS attacks can be some of the most challenging things in the world to mitigate, particularly if you\u2019re going in unprepared. You owe it to yourself to make sure your blog\u2019s properly protected &#8211; because you definitely don\u2019t want to face the consequences if you get DDoSed and it\u2019s not.<\/p>\n<p>Image: Flickr\/<a href=\"https:\/\/www.flickr.com\/photos\/home_of_chaos\/6946313991\/sizes\/c\/\">Abode of Chaos<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You could be forgiven for thinking Distributed Denial of Service attacks aren\u2019t really anything to be taken seriously. After all, they\u2019re basically the hacking equivalent of driving a truck into a storefront. Although they can wreak a bit of havoc, they don\u2019t require any real technical skill, and as such they\u2019re pretty easy to defend [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":174,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[26],"tags":[],"class_list":["post-173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/comments?post=173"}],"version-history":[{"count":2,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/173\/revisions"}],"predecessor-version":[{"id":278,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/173\/revisions\/278"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/media\/174"}],"wp:attachment":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/media?parent=173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/categories?post=173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/tags?post=173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}