Thread Starter
thorro
(@thorro)
No, I’ve cleaned the sites and set up some logging traps, but attacker hasn’t returned.
Thread Starter
thorro
(@thorro)
Yes, but that explains all the brute force attacks. I’m afraid there’s a new exploit out there, to which even v3.5.1 is vulnerable.
Passwords weren’t brute forced in this case, since our firewall blocks all such attempts after a few tries and would make it almost impossible. Not to mention all the alerts from the firewall we would get.