[URGENT] Someone is trying to HACK my WP site

newon

Power Member
Joined
Dec 16, 2011
Messages
701
Reaction score
118
Since last few hours someone is trying hack my WP site. In last 4 hours more than 500 attemps on my login page.
>> I changed password to more harder one
>> I keep blocking IPs .... but he's changing IP frequently
>> I've added IP block for more than 5 missed attempts.

What more should I do... please please please help... It's URGENT
 
Now the attack is SEVERE... 1 attempt in every 10 secs.
My God, can't understand what to do
 
Dont be a child. I hate child
You dont even have to worry if he is attempting brute force
If you set password like 3jf2#jw$!33j9a there's zero chance he brute force that
I doubt this but If he is trying some unsual way than just backup your web and close site for few days
Or you could just buy Wpfence country block module and block the country
 
change it to something like fjio9234uf984fj981jthtn(*)E&W(*TRF&(WESH then youll be fine lmao there is no way he can get in with something like that
 
Dont be a child. I hate child
You dont even have to worry if he is attempting brute force
If you set password like 3jf2#jw$!33j9a there's zero chance he brute force that
I doubt this but If he is trying some unsual way than just backup your web and close site for few days
Or you could just buy Wpfence country block module and block the country

Those give some relaxation... Have a harder PW now (like you showed), WPFence installed, Backing up all data now.
 
As someone else mentioned, change the USERNAME, then in wpfence select the option that blocks anyone entering the wrong username - they will normally try to use the word "admin".
 
As someone else mentioned, change the USERNAME, then in wpfence select the option that blocks anyone entering the wrong username - they will normally try to use the word "admin".

Username change not help :) is a trick to find de admin username.. only a good password is safe :)
 
Are you, by any chance, using Cloudflare on your site? If you are, then there is an excellent solution to this problem.
 
Just change the admin directory name from wp_admin to something else (you'll also have to update the config file AFAIK)
And, password protect that directory from your cPanel.
 
I dont know if someone mentioned this already but you can :
1) Change your WP-admin page address - by default it is http://xxx.com/wp-admin - and you can change it to xxx.com/donaldtrumpneverwins
And I can bet that no one will find this "login" page to massively attack with logins.
2) Its called CLEF - just google for "get clef" - its 2 steps verification with your phone using your phone camera and barcodes - so in this case you can be much more safe and none of Pakistani haxors will take down your site.
 
Hackers are everywhere in online world. You must have to take some precautions and preventive steps to make sure that your site is safe from hackers. Always use a security plugin for your blog. Change your admin username and change your passwords frequently. Change the prefix of the database table where your WordPress site is install. Use captcha on your site registration and login pages.
 
Back
Top