Skip to content

Sorin Mustaca – Security & Technology

Cybersecurity, AI, Automotive Security, Antimalware Software, Product Management, Agile, Secure Software Development, SSDLC

  • Security
    • IT Security News English
    • IT Sicherheit News Deutsch
    • Securitate in limba Romana
    • Tipps und Ratschläge – IT Sicherheit
  • News
    • In the news
    • Quoted
  • About
    • About me
    • Contact
    • “Improve your security” free eBook
    • Scuba Diving Blog
  • Privacy Policy
  • Cyber Security Consulting
  • Work with me
  • Home
  • General
  • Do you really know who’s visiting your website?

Do you really know who’s visiting your website?

May 8, 2015

We live in the world of Analytics where words like “Big Data” are everywhere to be seen.

But, are you really sure that the visitors of your website or blog are really interested in your content?


My company offers consulting on how to prepare for TISAX, ISO27001, NIS2, CSMS and SOC2 audits.
Get in touch with us here: https://www.endpoint-cybersecurity.com/contact/

A few years ago, maybe… But now, the cybercriminals, or more exactly their bots, are trying to gain access to your website to serve their own content to your visitors.

How do we know that?

There are many ways to find that out, but the simplest ones are:

– install a web application firewall

If you have WordPress, you might want to try one of the “firewalls” that are available for free.

You will be astonished to see that a lot of the visitors try to login into your WordPress.

I wrote back in 2013 an article describing the anatomy of a live attack from China on a WordPress blog.

On a period of 2 days:

  • ~90% of the traffic was Spiders, Bots, Crawlers from Google, Baidu,
  • ~8% of the traffic were attempts to register an account like the one below:
  • ~2% were real visitors

All this happened because the website was pretty good indexed and it had a good domain name (IT Security News).

– Keep an eye on WordPress’ statistics

The situation improved a bit now, because WordPress took stance and rejects now all login attempts from “known” IPs.

This is how it looks now (period of a few months since I reset the statistics):

loginattempts

The blocked malicious login increases with about 100 attempts per day.

Unfortunately, you don’t see these things using services like Google Analytics or even WordPress’ own JetPack statistics.

You just see visitors if you look at the top level statistics…

analytics

Only if you dive deeper in the stats, you can see that many visitors – the vast majority if you are under attack or your site is being indexed by spiders and robots, will stop at the Home level. They don’t go further as they are satisfied by the meta keywords of the website, which are usually found in every page, including the Home page.

 

What can you do?

Well, the first thing to think about is if you want to do something about it. If you block spiders and robots, you will no longer be found by search engines. You probably don’t want this.

You can block however, malicious login attempts. There are tips how to harden WordPress. More or less the same applies to other platforms.

Or you can install a firewall plugin for WordPress and configure it to block the IPs which attempt to apply brute force.

 

 

Sorin Mustaca, CSSLP, Security+, Project+

www.sorinmustaca.com


© Copyright 2015 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca - Security & Technology


Want to work with me on this topic?
Check Endpoint Cybersecurity to see the consulting services we offer.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Telegram (Opens in new window) Telegram
  • Share on X (Opens in new window) X
  • Share on Threads (Opens in new window) Threads
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • More
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Pinterest (Opens in new window) Pinterest

Like this:

Like Loading…

Related

GeneralTagged: bots, crawler, firewall, login, spiders, wordfence, wordpress

Post navigation

Microsoft, you’re not as smart as you thing you are!
Spam is indeed good for something! But you will never guess what for.

Related Posts

The Automotive industry’s inadequate approach towards software (in the cars)

Introduction The automotive industry has witnessed a paradigm shift with the increasing integration of software in vehicles. Modern cars are no longer just mechanical devices with a motor, wheels and steering; they are now sophisticated machines having dozens of CPUs (called ECU), entire computers, high speed network to connect them (called CAN-bus) and relying on […]

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Telegram (Opens in new window) Telegram
  • Share on X (Opens in new window) X
  • Share on Threads (Opens in new window) Threads
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • More
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Pinterest (Opens in new window) Pinterest

Like this:

Like Loading…
Changing the ISP for my website

There will be interrupts today because I’ve moved my website from 1und1.de to Netbeat. &copy Copyright 2009 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca – Security & TechnologyWant to work with me on this topic?Check Endpoint Cybersecurity to see the consulting services we offer.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Telegram (Opens in new window) Telegram
  • Share on X (Opens in new window) X
  • Share on Threads (Opens in new window) Threads
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • More
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Pinterest (Opens in new window) Pinterest

Like this:

Like Loading…
Security update for Apple: iOS 6.1 fixes browser flaws

Apple has released a new version of iOS, the operating system that powers the iPhone, iPad, iPod. My company offers consulting on how to prepare for TISAX, ISO27001, NIS2, CSMS and SOC2 audits. Get in touch with us here: https://www.endpoint-cybersecurity.com/contact/ The new version fixes 20 security flaws related to the Safari browser. Some of the […]

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Telegram (Opens in new window) Telegram
  • Share on X (Opens in new window) X
  • Share on Threads (Opens in new window) Threads
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • More
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Pinterest (Opens in new window) Pinterest

Like this:

Like Loading…
Sorin Mustaca on Twitter Sorin Mustaca on Facebook View Sorin Mustaca's profile on LinkedIn Sorin Mustaca on XING
Subscribe to me on Substack

Categories

Top Posts & Pages

  • Implementing ISO 27001:2022 Annex A.18 - Compliance
  • Sign files unattended in batch mode while having an eToken (no password popup!) (updated)
  • Defender Application Control or Defender SmartScreen - what can you do to not be blocked by it
  • NIS2: 1. Perform a gap analysis
  • TISAX: new Catalogue ISA v6 available
  • Understanding ISO 27001:2022 Annex A.8 - Asset Management
  • Understanding ISO 27001:2022 Annex A.14 - System Acquisition, Development, and Maintenance
  • How to implement an Information Security Management System (ISMS)
  • Implementing ISO 27001:2022 Annex A.16 - Information Security Incident Management

Work with me

Endpoint Cybersecurity

www.endpoint-cybersecurity.com

- Consulting in building your security products for Windows, MacOS, Linux, iOS, Android
- Pentests and Security tests for applications
- Cybersecurity Management Systems for Automotive(CSMS/ISO 21434, WP.29, ISO 16949)
- Support in TISAX(r) audits
- Support in ISO 27001, NIS2, CRA audits

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 151 other subscribers

Pages

  • About
  • Contact
  • Cybersecurity and AI Collection
  • Download the free eBook
  • In the news
  • ISO 27001:2022 Collection
  • NIS2 Collection
  • Privacy Policy
  • Securitate in limba Romana
  • Tipps und Ratschläge – IT Sicherheit
  • Work with me
RSS IT Security News (EN)
  • Why IT security’s future is more than just AI models
  • Splunk Tutorial for Beginners: Search, Dashboards and Alerts (2026)
  • Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default
  • U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
  • Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
  • Brinks Home – 732,162 breached accounts
  • Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
  • Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
  • Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
  • New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
RSS IT Sicherheitsnews (DE)
  • Fake-Abbuchung über 909 Euro: Paypal-Kunden sollten diese Phishing-Mail kennen
  • Nach 11 Jahren: KI Claude knackt Passwort einer Bitcoin-Wallet mit 400.000 Dollar
  • Über 70 Kreativ-Tools integriert: Adobe-Plugin macht ChatGPT zur Canva-Alternative
  • Windows 11: Warum deinstallierte Apps nicht immer Speicherplatz freigeben
  • [UPDATE] [mittel] libtasn1: Schwachstelle ermöglicht Denial of Service
RSS Improve Your Security Ebook
  • Protecting Our Teens: A Guide to Creating Awareness About Online Dangers
  • A Guide to Teaching Online Safety and Navigating Cyber Dangers
  • How to easily secure your smartphone
  • Conclusion: The Ultimate Parent Guide for Protecting Your Child on the Internet
  • Online predators: The Ultimate Parent Guide for Protecting Your Child on the Internet

Copyright © 2001 - 2026 Sorin Mustaca – Security & Technology | Marvel Blog by Ascendoor | Powered by WordPress.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}

Loading Comments...

You must be logged in to post a comment.

    %d