Limit Login Attepts

Zaino

New member
Aug 5, 2011
1,825
10
0
What if anything do you all do about attempted hacking of your wordpress sites? I have 1 site in particular that gets hundreds of login attempts every week. Its all admin cracking attempts though so im not terribly worried, it just pisses me off knowing its happening.
 


Yes that is the plugin I am using. I am receiving tons of notification via email. Someone had mentioned in a nother thread soemwhere that IP blocking isnt really going to stop anyone. Would it stop anyone from here? No way lol.

I was more curious if everyone experiences this or what steps to avoid it all together?
 
Nothing will stop someone who is determined enough to get in.

Auto blocking IPs after X attempts will block most automated scripts and dummies on /wp-admin/. Wont stop someone with a huge botnet and w WP cracking script.
Renaming /wp-admin/ to something else will stop all autocracking/bruteforce scripts
Deleting user Admin and making the Admin username something else besides Admin

If you want to get more hardcore than that, you can restrict the wp-admin access to your IP only and that should stop anything.

Then you have weak plugins that could always get hacked so thats another way in.

I've slowly been migrating away from WP for anything that needs to be 'secure' and is going to be getting a lot of traffic/be important. GL.
 
Nothing will stop someone who is determined enough to get in.

Auto blocking IPs after X attempts will block most automated scripts and dummies on /wp-admin/. Wont stop someone with a huge botnet and w WP cracking script.
Renaming /wp-admin/ to something else will stop all autocracking/bruteforce scripts
Deleting user Admin and making the Admin username something else besides Admin

If you want to get more hardcore than that, you can restrict the wp-admin access to your IP only and that should stop anything.

Then you have weak plugins that could always get hacked so thats another way in.

I've slowly been migrating away from WP for anything that needs to be 'secure' and is going to be getting a lot of traffic/be important. GL.

What CMS are you migrating to? It's a pain to manage 10+ sites when all of them are under attack every single day.
 
update lulz

Capture_zpsfb6b1c4f.jpg