Someone is attacking my website

agree, cloudflare is the best option right now..i have the same experience but since i install cloduflare and invest some money to its, i feel a bit safe now
 
That is why i do not download nulled themes or plugins from this website or any blackhat websites. A couple of months ago one of my websites was hacked after adding a plugin i downloaded from this forum. It is the perfect way for hackers to infiltrate your website. Fortunately the website hacked wasn't one of my money sites.
 
Are they trying to login to regular accounts or the admin account?

I agree with the person who said put captcha on regular user account logins. This is a good time to review that everything is locked down from a server and wordpress perspective. There are plenty of good free security plugins that are well-known and are a good first line of defense.

And yea, like that other person said it's like a bot. I doubt it's a person changing ip as much as it's a different computer doing the zombie dance and looking for a way in.
 
What do you mean by brute forcing excuse the ignorant question still learning!
 
What do you mean by brute forcing excuse the ignorant question still learning!
Trying every kind of passwords possible. Starting from A, then B.... then AA..then AB..etc..

On the contrary, a dictionary attack is what you would expect.. an attack using a dictionary of known words/passwords.
 
Use WPBruiser plugin to stop them, fast plugin that does not slow you site down like WordFence does, never use WF.

Code:
https://wordpress.org/plugins/goodbye-captcha/

Stops spam also, use it as default on all my websites.


.
 
There are lists and services you can sign up for for a complete black list of IPs if you have access to a firewall THAT might help..

I can check mine which gets update and try and add it here. You can also sign up to Project Honey Pot that can give you a more unto date list of honey pots they have set up to catch spam attacks mainly used for SMTP attacks etc..
 
Trying every kind of passwords possible. Starting from A, then B.... then AA..then AB..etc..

On the contrary, a dictionary attack is what you would expect.. an attack using a dictionary of known words/passwords.
So they are trying to log on to your site? Utilizing a different series of passwords?
 
So they are trying to log on to your site? Utilizing a different series of passwords?
Exactly. There are scripts for doing this.
 
Exactly. There are scripts for doing this.
Well that’s shitty I’m sorry to hear that, thanks for the info though always nice to learn new things about the online world I’m a hands on guy that got hurt and can’t do hands on work for a while. I’m really trying to learn all I can!
 
Well that’s shitty I’m sorry to hear that, thanks for the info though always nice to learn new things about the online world I’m a hands on guy that got hurt and can’t do hands on work for a while. I’m really trying to learn all I can!
You are always welcome man. Sharing knowledge is always awesome. That's how everyone of us learn more.
 
Guys thanks for all the answers.... like i don't want to stop them... I have just one admin account and it has 2FA

I want to know why would someone attack a website that is making 5€ monthly or less

He looks like a noob or what?

He is trying to bruteforce accounts with 0 priviledges....

It would be easy to register because i accept new user automatically with buddypress xD
 
Guys thanks for all the answers.... like i don't want to stop them... I have just one admin account and it has 2FA

I want to know why would someone attack a website that is making 5€ monthly or less

He looks like a noob or what?

He is trying to bruteforce accounts with 0 priviledges....

It would be easy to register because i accept new user automatically with buddypress xD


domain expired or new? I've seen some crazy things with expired domains, but I believe it's a bot and your site was chosen.

see if this can help you: https://bitninja.io/
 
Back
Top