see a ton of wp 404 redirects in redirects

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
Jim007
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 136
Joined: Sat Oct 18, 2008 7:22 pm

see a ton of wp 404 redirects in redirects

Post by Jim007 » Sun Jan 17, 2021 2:45 pm

I have noticed lately that I have a ton of 404 redirects in the redirects component of joomla for wordpress urls. I know they are fishing for an entry into the site and info, I assume they are normal, but they are getting out of hand.

should I redirect them to somewhere else? There is no referring link on many of them for instance here is an example

wp-includes/css/css.php
and
wp-includes/fonts/css.php

I would like to redirect them to a site that basically says FU

I have got so fed up with the crap that I purchased the RSfirewall and blocked pretty much every geo ip address from every country on the europe, african and asian continent. I am USA based, I could care less if someone in France or Russia see my site.

User avatar
pe7er
Joomla! Master
Joomla! Master
Posts: 24984
Joined: Thu Aug 18, 2005 8:55 pm
Location: Nijmegen, Netherlands
Contact:

Re: see a ton of wp 404 redirects in redirects

Post by pe7er » Mon Jan 18, 2021 3:04 pm

Jim007 wrote:
Sun Jan 17, 2021 2:45 pm
I have noticed lately that I have a ton of 404 redirects in the redirects component of joomla for wordpress urls. I know they are fishing for an entry into the site and info, I assume they are normal, but they are getting out of hand.
Yes, that's "normal". Bots visit every website / IP address they run into, and try to fingerprint the websites they find.

should I redirect them to somewhere else?
I sometimes redirect all wp-admin + wp-includes links to http://127.0.0.1

I purchased the RSfirewall and blocked pretty much every geo ip address from every country on the europe, african and asian continent. I am USA based, I could care less if someone in France or Russia see my site.
Actually, IMHO GEO blocking IP addresses is not effective:
Non-US visitors (or bots) might use a VPN with a US IP address.

And sometimes even unwanted:
If you block all traffic outside the US, you might miss US citizens on holiday abroad. Or US citizens using IP addresses from their mother company based in Europe.
Kind Regards,
Peter Martin, Global Moderator
Company website: https://db8.nl/en/ - Joomla specialist, Nijmegen, Netherlands
The best website: https://the-best-website.com

sozzled
I've been banned!
Posts: 13639
Joined: Sun Jul 05, 2009 3:30 am
Location: Canberra, Australia

Re: see a ton of wp 404 redirects in redirects

Post by sozzled » Mon Jan 18, 2021 6:56 pm

See also viewtopic.php?f=714&t=958501 and viewtopic.php?f=714&t=983584&p=3620876#p3620690. Useful search terms are "referrer spam" or "spamdexing".

Jim007
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 136
Joined: Sat Oct 18, 2008 7:22 pm

Re: see a ton of wp 404 redirects in redirects

Post by Jim007 » Tue Jan 19, 2021 3:15 pm

Thanks everyone

Jim007
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 136
Joined: Sat Oct 18, 2008 7:22 pm

Re: see a ton of wp 404 redirects in redirects

Post by Jim007 » Thu Jan 21, 2021 3:52 pm

I just rethought my response, I know we are a community of open source, creative well intention die hards only trying to better themselves, their cause or business. But after the Solar Winds Hack, it truly opened my eyes to the world of dipshits we live in. Sure, my site since it is hosted would not stand up to a sophisticated attack as the SW hack, but I want to control it a little bit and cut back on the BS.

I GEO blocked Asia, Antarctica, Africa, Europe, Oceania and many if not all of the South American countries. I thought about it, we are an American company and only service a small city. I don't care what a neighboring state can view as it really doesn't affect my business, sure it is cool to see a nice website reflecting your company, but I don't need to say "look at me" So I geo-blocked them.

What is ridiculous is the amount of Russian and China intrusion attempts into the back-end admin area, and the different files they try to access when looking at the redirects component. It's pathetic. So, unfortunately, right now I am just a North American site. I have dropped from a high of 1200 attempts a day to less than 100 within 2 weeks.


Locked

Return to “Security in Joomla! 3.x”