WP Trackback Spam Attack

They say that the more popular you are, the more attacks you get. This is so true with WordPress right now. The massive code injection and hidden links on WordPress blogs are getting some serious coverage and just tonight I discovered another form of attack — the WP Trackback Spam flooding.

The attack is simple yet effective — flood wp-trackback.php with HTTP requests. It’s like a DDOS actually. There could be several ways to do this:

  • Software-driven. I’ve seen some softwares that can do 1,000 HTTP simultaneous requests to a site or specific webpage.
  • Code embed. Add the target page (in this case, wp-trackback.php) into a popular page or site which requests for it at every page load. Replicate that on many other high-traffic sites and viola, instant slashdot effect.
  • Bots. Similar to a GoogleBot or Yahoo! Metacrawler but these type have malicious intent only goes after a specific page — wp-trackback.php.

It’s hard really. Took me about 6 hours monitoring one of our servers where a blog was attacked. The attack would seem like a Digg-effect or a slashdot effect. However, any anti-Digg solutions would not work — even WP-SuperCache could not fend it off. Then it struck me, maybe the page is not being cached.

A check with the analytics showed this:

wordpress trackback

WP-Shortstats was tracking it. Thousands of trackback requests for almost all pages in the blog in a matter of hours.

What made it worse is that the wp-shortstats plugin is also recording this — meaning for each page request, there’s a corresponding SQL query executed by Shortstats that’s aggravating the situation.

The result — slow, crawling blog; eventually, an overloaded or crashed server.

The solution? Deactivating trackbacks won’t help. You need to delete wp-trackback.php or CHMOD it to 000. If you can identify the IP, block them too.

Your blog won’t be able to send/receive legit trackbacks but it’s the only solution for now.

Abe Olandres
Abe Olandres
Abe is the founder and Editor-in-Chief of YugaTech with over 20 years of experience in the technology industry. He is one of the pioneers of blogging in the country and considered by many as the Father of Tech Blogging in the Philippines. He is also a technology consultant, a tech columnist with several national publications, resource speaker and mentor/advisor to several start-up companies.
  1. I can’t believe people are doing this to my blog. Tsk. Tsk.

    :)
    Dark Knight
    BlueMumble

  2. wait. how would I be certain that I am being attacked? is it when I see the wp-trackback.php on the anlytics?

    I noticed some slowdown and database error yesterday on my blogs…

  3. @ash, that’s the only way I was able to detect the attack. caused the server to slow down and crash at times. Looks like your blog is on that server too.

  4. oh!.. still great it’s fixed… thanks.

  5. i don’t know if my selaplana.com experience this. i tried to investigate but i don’t know yet how to know if the blog has been attacked by this kind.

  6. OMG! i believe this is culprit, that’s why last month my host server to crash several times and my blog too..

    CHMOD to 000?is it just like deleting the wp.trackback thing??

  7. Good 235rter2rwer23r

  8. Xeto6s hi! how you doin?

  9. And who does not wish to pay for a hosting, is urgent here – the best free web hosting!

Leave a Reply

Your email address will not be published. Required fields are marked *

yugatech x epson

Latest Review

OPPO Find N5 Review
realme 14 Pro+ 5G Review
ASUS ROG Flow Z13 2025 Review
Chuwi Minibook X Review
Samsung Galaxy A36 5G Review

Latest Guide

A Look Inside Grab’s IoT Innovations at Grab HQ After GrabX2025
Top 10 AFFORDABLE 65-inch 4K TVs To Buy In The Philippines (Q1 2025)
BEV, Hybrid, PHEV: An Explainer for the Common Filipino Driver
2025 Postpaid Fiber Plans in the Philippines: PLDT, Globe, Converge, Sky
Top Apple products to kickstart the New Year through Home Credit

YugaAuto

Connection issue detected. Retrying in 2 seconds... (1/3)

YugaMoto

Connection issue detected. Retrying in 8 seconds... (3/3)

YugaGaming

Connection issue detected. Retrying in 4 seconds... (2/3)

AskYuga

This feed may not be accessible from your current location due to regional restrictions. You may need to use a VPN or contact the site administrator for assistance.
WP Trackback Spam Attack » YugaTech | Philippines Tech News & Reviews StatCounter - Free Web Tracker and Counter

Yearly Device Database

Smartphone pricelist Philippines 2024

Smartphone pricelist Philippines 2023

Smartphone pricelist Philippines 2022

Smartphone pricelist Philippines 2021

Smartphone pricelist Philippines 2020

Popular Topics

What We Do

YugaTech | Philippines Tech News & Reviews
© 2024. All Rights Reserved.