Beware Of New WordPress Brute-Force Attacks. Protect your sites!!!

scorpion king

Supreme Member
Joined
May 2, 2010
Messages
1,240
Reaction score
2,454
Hackers targeting wordpress sites now. They attempting to login WP sites using bruit force method. I am not a wordpress expert
go give proper guidance how to protect your sites. I just want to make you aware of this. You can see more information here.

Code:
[URL]http://blog.hostgator.com/2013/04/11/global-wordpress-brute-force-flood/[/URL]
Code:
[URL]http://blog.cloudflare.com/patching-the-internet-fixing-the-wordpress-br[/URL]
Code:
[URL]http://blog.sucuri.net/2013/04/protecting-against-wordpress-brute-force-attacks.html[/URL]

Looking for expert's suggestions.
 
What if the wp-login file is renamed?

Will that help?
 
Code:
[URL]http://howsecureismypassword.net/[/URL]

this site says it takes 846 billion years to c rack my password.

If I understand this correctly, Brute force is the same as trying out random passwords. So the most important thing you need to have is a relatively complex password.
 
Did you reveal your password in that site? Change it now, coz they all have a shared database ;-)
Code:
[URL]http://howsecureismypassword.net/[/URL]

this site says it takes 846 billion years to c rack my password.

If I understand this correctly, Brute force is the same as trying out random passwords. So the most important thing you need to have is a relatively complex password.
 
Did you reveal your password in that site? Change it now, coz they all have a shared database ;-)

yes! they also asked me for my username and my webiste. I gave them all the information because I trust them.

I'm waiting for them to come... ;-)
 
Use incapsula dot com to protect your site.

img404.jpg
 
Last edited by a moderator:
What the heck is that? I gotta check!
EDIT: Ok, it seems to be like cloudflare is it? Let me have a go at it. Thanks or the input(i am out of thanks.. so can't thank ur post)

Use incapsula dot com to protect your site.


img404.jpg
 
Last edited by a moderator:
Code:
[URL]http://howsecureismypassword.net/[/URL]

this site says it takes 846 billion years to c rack my password.

If I understand this correctly, Brute force is the same as trying out random passwords. So the most important thing you need to have is a relatively complex password.

Brute force is trying many passwords or random passwords. With a good dictionary and good ruleset you can get most peoples passwords in under a day. The people that wouldnt be found are those using a non-standard and complex password. If you use words, names of movies/characters/shows then you're immediately insecure.

846 billion is the time it would take to test all combinations possible. They could get it on the first try however unlikely it is. Also, the security features come into play. If they limit your password to between 4 and 8 characters with no special characters then its much easier to find than one that imposes a requirement of 4 characters and any character.
 
You know you just got to love it that so many idiots leave their computers unprotected and are actually contributing their machines to this botnet. It's probably the same one doing the DNS on the bitcoin exchanges.
 
Does this mean it's no longer safe to use "password" as the password on all my sites?
 
Trolling? On a serious note, you need an alpha-numeric sentence instead of a word now-a-days.
Does this mean it's no longer safe to use "password" as the password on all my sites?
 
Back
Top