Somebody Knocks on the Same Door Every Day
I counted seven days of access records from my Joomla sites
Let me say at the outset that I am not a security specialist. I am simply an individual who runs a few sites on Joomla.
So there is nothing difficult in this article. Something bothered me, I counted it, and what I found was not what I expected. That is all this is. I am writing it in case it is of any use to others who keep a Joomla site of their own.
There Is a Ledger You May Not Have Opened
The server your site sits on keeps a record called an access log, and it fills up on its own.
When someone came, where from, and which page they looked at. Line after line, endlessly, like a ledger. It is usually there without any setting up on your part.
Normally there is no need to look at it. I only open mine when something feels off.
This time, something did.
The Same Text Kept Appearing
Since the beginning of August, the same string of characters had been showing up again and again in my administrator records.
index.php?option=com_jce
Several times a day, from all sorts of places, aiming at exactly the same spot as if stamped from a mould.
So I gathered the access records for the seven days from 30 July to 5 August and counted them properly.
What com_jce Actually Refers To
com_jce is JCE, a text editing tool widely used with Joomla. It makes the article writing screen easier to work with, and I expect a good many people have it installed.
Why does that spot get targeted? The reason is simple.
A flaw was found in JCE some years ago. The kind that lets someone push a file in from outside. It was fixed long ago, of course.
But the world is full of Joomla sites left untouched for years. From an attacker's point of view, that makes it an efficient target: one hit and you are inside.
So today as well, machines are going around knocking on the same door of Joomla sites all over the world.
Five Hundred and Thirteen Knocks in Seven Days
Here is what the counting showed.
Requests aiming at com_jce came to 513 over seven days, sent from 56 different places.
Day by day, the quietest had 24 and the busiest 216. There was no day with none. They arrive every single day.
I run four sites, and every one of them was targeted. The handicraft shop and the music fan site alike, with no distinction made.
And not one of them got through.
The server's answer in every case was a refusal, recorded with the number 403. Among them, the 160 requests that constitute the actual attack were turned away at the door without exception.
The Numbers Show It Is Not a Person
Look at the records and it becomes obvious that a machine is doing this.
From one single source, for instance, the count came to 38 requests to each of three of my sites. Thirty eight, thirty eight, thirty eight. Nobody working by hand produces that. It is a list being worked through in order.
Looking at the same source second by second, seven requests arrived within one second. No pair of hands can do that either.
The interesting part is how they introduce themselves.
When something visits a site, it announces what kind of browser it is. Of the 513, some 157 announced themselves as Chrome on Linux, 60 as Chrome on Windows, and 38 as Safari on a Mac.
Untrue, naturally. They are dressed up as ordinary visitors to hide what they are.
Sixteen of them, though, gave the plain name of the tool they were built with. Some of them are not even bothering to hide.
The Most Surprising Thing I Found
This is the part that startled me most.
I also counted what else had been targeted over the same seven days.
Requests hunting for configuration files: 1,677. Requests looking for WordPress administrator and login screens: over 2,200 between them.
Which makes the 513 for com_jce one of the smaller categories.
All of my sites run on Joomla. I do not use WordPress anywhere. And yet requests knocking on WordPress doors outnumbered these more than four to one.
What does that tell us?
They are not checking what my sites are built with. They are working through every address in the world, knocking on every kind of door in turn. Only the houses that happen to be unlocked come to harm.
So I was not being targeted at all. I was simply caught in the net.
For reference, all visits over the seven days came to about 150,000, of which roughly 5,800 looked like attacks. About four per cent.
So What Should You Do
Set out as numbers it sounds alarming, but there is remarkably little to do.
First. If you use JCE, keep it on the latest version. That alone turns all 513 of these into wasted shots. An attack aimed at a flaw you have already fixed will never get through, however often it comes.
Second. Delete extensions you do not use. What is not there cannot be attacked.
Third. Look at your records now and then. Not daily. Just try not to be someone who has never looked at all.
If you have the capacity for it, adding something that stops suspicious requests at the entrance (extensions exist for this) means they never reach the inside at all. My own result of nothing getting through is thanks to that.
There Is No Need to Be Frightened
Finally, a word to anyone else keeping a site on their own.
Seeing these figures, there is no need to feel singled out. If a server is published on the internet, the same thing is happening to it. It rains equally on sites that opened yesterday and sites untouched for years. It is weather.
What matters is not reducing the attacks to zero. Nobody can do that.
It is keeping things in a state where a hit does not break through, and looking occasionally at what condition your own door is in. Those two things.
Someone knocks every day. If the lock holds, nothing happens. Counting this time made that clear in figures.
It is worth counting once in a while. That is my honest impression.