Wordfence blocked a potential hacker to my site

Sandie2018

Power Member
Joined
Mar 26, 2018
Messages
699
Reaction score
338
Hi,

Today I got a message from Wordfence and I am shocked because it has never happened to me before. The message said:

A user with IP addr xxx.xxx.xx.xx has been locked out from signing in or using the password recovery form for the following reason: Exceeded the maximum number of login failures which is: 20. The last username they tried to sign in with was: 'test'.
The duration of the lockout is 4 hours.
User IP: xxx.xxx.xx.xx

I have a free version of Wordfence. Should I get a paid one? Will my site be protected better?
 
This will happen all the time, you do not need the pro version, its good, but when you need it you will know.

For now, learn what is available in the free version, it is enough to lock down your login page.

The good news is you are indexed :)
 
Its nothing to worry about and its what wordfence is there for. I few things I would say though - first of all, change that lockout so that it locks out after 3 incorrect password attempts and timescale can be something like 24 hours - just to prevent any possibility of a brute force attack being possible. Secondly, whitelist your IP in wordfence just to make sure you dont lock yourself out by mistake. Thirdly make sure you have a decent password - random characters, upper and lower case, numbers and symbols etc. Again to avoid any possibility of brute force or dictionary attack being possible. Make sure you keep everything up to date and make sure you take periodic backups to somewhere else, just in case.
 
Coincidentally, I am experiencing the exact same thing.

Only thing is I am using "Limited Login Attempts" plugin. Very same exact issue as you - 16-20 login failures and locked out.

What's annoying is the potential hacker is using many proxies. I've tried banning the IPs but they just keep using new ones.

And interestingly, their first attempt was my exact admin username that I've set which they are trying to hack. When that failed a couple of times, they start trying 'admin'.

Like others said, minimizing the number of login attempts and extending the lockout time is the way to go. I am sure they will give up sooner or later. As long as you've set a strong and unique alphanumeric password, I wouldn't worry anything about it.

I guess there is some large scale hacking attempt right now. lol
 
No reason to go for word fence premium version. The free one has a lot to offer
 
Happens everyday, its just noob hackers running python scripts, I have a long list of login attempts to all my sites, there are a few in particular that have the author name is the login name, yet they continue to try different names, that's how I know they are not even looking at the site, or otherwise they would try the correct login name.

Don't worry go about your daily business.
 
Back
Top