Need help - Brute Force Login Attempts

Jenova

Registered Member
Joined
Jul 18, 2015
Messages
74
Reaction score
41
One of my WP based websites gets daily brute force login attempts according to my loginizer plugin logs and lockout emails. Does anyone have any advice on additional measures I could take to at least lessen the frequency of these? Thank you!
 
Configure your loginizer's lockout time to 99999 (infinite or for long periods of time). Then change a maximum of just 2 attempts before being locked out.

Also, you can blacklist that IP that is trying to brute-force entry.

Alternatively, just rename your wp-login.php to wp-login.ph_ or something... then when you want to log in, just rename it back to wp-login.php.
 
Configure your loginizer's lockout time to 99999 (infinite or for long periods of time). Then change a maximum of just 2 attempts before being locked out.

Also, you can blacklist that IP that is trying to brute-force entry.

Alternatively, just rename your wp-login.php to wp-login.ph_ or something... then when you want to log in, just rename it back to wp-login.php.

Wow! Awesome reply. I really appreciate you being so thorough and am making the changes now. Thank you!
 
Its probably automated, just make sure you have the latest version + some security plugins, bots are crawling and attempt to log-in all the time with dictionary based attacks. Also i would suggest to change wp-login entry point with something like - mycustomlogin.php
 
I didn't do that at first because it always seems to be different IPs and I don't really make time to work on that site every day. I guess I will have to. Thanks for taking the time to advise .
No.. ip ban is automated. You dont have to do manually. You can use fail2ban. You can find them on that wordpress link.
 
No.. ip ban is automated. You dont have to do manually. You can use fail2ban. You can find them on that wordpress link.
I did not know that! This is the best forum in the world.
 
Back
Top