Somebody is tryig to hack my site

Mobrich24

Junior Member
Joined
Jun 3, 2016
Messages
153
Reaction score
30
16 failed login attempts (4 lockout(s)) from IP: 91.210.147.25

Last user attempted: admin

IP was blocked for 24 hours

I've had this email quite a few times lately anyone know What's going on?
 
To the top this seems pretty serious. Has anyone else had this problem with Wordpress?
 
Are you getting those emails from Wordfence or some other security plugin? If so don't panic, because it's doing it's job and letting you know it is. I get dozens of these emails from Wordfence, I have it set to block many other kinds of attacks.
 
Are you getting those emails from Wordfence or some other security plugin? If so don't panic, because it's doing it's job and letting you know it is. I get dozens of these emails from Wordfence, I have it set to block many other kinds of attacks.

I'm not using any security its from Wordpress because whomever tried to login to my site failed a bunch of times. Do you suggest wordfence?
 
As long as you have a strong password you shouldn't worry about login attempts.
 
I get these all the time. Install Wordfence and Google the best configuration settings so that you can ban and lock out the offending IP's.
 
If you changed your username and have a strong password, they will not be able to bruteforce it like that, but you should ban the IP anyway.
 
technically, a 2 factor authentication plugin should be the advised course of action.
 
I am having the same problem at the moment. Don't worry about it. It seems you are using wordfence just like I do, just set the time banned to 30 days. If you lock yourself out for some reason, you can simply send yourself an email to unlock yourself again, so make sure your email system is working properly.

And change the name to something other than Admin and check the option that anybody who tries to login with a username that does not exist will instantly get blocked. Most attacks will be on Admin, but if you don't have an Admin account they will instantly be locked out. That's how I do it and even with a huge ton of proxies there is almost no way to brute force the password
 
I just use this plugin: https://wordpress.org/plugins/rename-wp-login/

Some saavy hackers can still get to your wp-login page even after you rename it, but most of them will have trouble.

Edit: I'm actually looking into this Google Authenticator plugin. I use it for BHW and a few other sites, so maybe it's also worth looking into for you as well. I think Wordfence also has a similar feature in their plugin.
 
Last edited:
i had the same problem, but don't worry until is shown like an attempt, if someone get access you won't get any notification.Also, install wordfence
 
Back
Top