"Global Attack on WordPress Sites" was the subject of the email that we sent out to all our ASK4Host.com customers early last week. This email was to inform them about steps we have taken to protect their websites on our servers and what steps they should take at their end to safeguard their websites.
Around the first and second week of April 2014, there was an ongoing and highly distributed global attack on WordPress installations to crack open admin accounts and inject various malicious scripts.
After a detailed analysis of the attack pattern, we found out that most attacks originated from WordPress sites. Further investigation revealed that the admin accounts had been compromised (in one form or the other), and malicious scripts were uploaded into the directories.
This attack was happening globally, and WordPress instances across hosting providers were targeted. Since the attack was highly distributed in nature (most of the IPs used are spoofed), it was difficult for us to block all malicious data.
Further, we found this attack was not limited to WordPress but also on Zoomla and most other open source Content Management Systems (CMS). Many of them, including WordPress, ask their users to update or install the security patches. Also, release information on how to safeguard sites from these attacks.
During the same time, Shimbi Labs' Budo users were at peace of mind because it was secured from such attacks and all safety majors were in place.
Let's see some of the Cons of Open Sources CMS and the Pros of close sources CMS.
Cons of Open CMS
- Because of the popularity of open-source systems, many people are familiar with open source code, which creates a higher risk for hacking.
- If you choose to design in an open-source system, your development team will need to put time and work into preventing third-party tampering.
- Complicated to integrate & Customise.
- Too many things which you don't need
Pros of Close CMS
- Closed source software usually equates to better security and support. It doesn't mean that it is perfect 100% secure, but if a problem occurs, the development company can quickly take care of it, and there is no cost to you.
- Closed source CMS comes with properly documented manuals. Many companies also offer human support.
- Some companies even offer regular updates that are continually improving the product.
- Comes with a clean and easy-to-use admin panel with only things you require.
However, this does not imply that open-source software is inherently flawed. We are ardent supporters of open-source software and the open-source movement. We want to emphasize that you should base your decision on long-term costs rather than short-term profits.