am i being attacked?

swon

Junior Member
Joined
Oct 16, 2016
Messages
107
Reaction score
167
this is what the WP loginizer plugin is telling me... Does this mean someone is currently actively attempting to break in?


suggestions to secure my site?
page 1.jpg page 2.jpg
 

Attachments

  • page 2.jpg
    page 2.jpg
    87.2 KB · Views: 1
  • page 1.jpg
    page 1.jpg
    86.7 KB · Views: 1
Could be just the average botnet scouring the web for insecure sites. Update WP immediately if you haven't. I fucking lost my dating site to that bullshit lol.
 
WP is up to date. seems like all the IP's are coming from Moscow and Moscow surrounding areas.
i changed the login page url to something completely random. not sure if that would make a difference.

seems like the attempts have ceased for now.
 
Honestly, just block all IPs coming from 3rd world countries and suspect nations like Russia, Ukraine, China, etc...

They don't convert, drain bandwidth and are possibly infected.
 
I also had this and I installed jetpack and the attacks are gone now.
 
I had Russians hammering a handful of my sites for a month before they gave up trying to bruteforce my passwords. I rarely check on some of these sites is why it went on for so long but my passwords are all 20+ character random alphanumeric and I use 2 factor on all my WordPress sites so needless to say they gave up eventually.

Strong passwords, 2 factor and keeping everything updated is your best defense. At the end of the day though a true hacker will get in if they want to bad enough.
 
Honestly, just block all IPs coming from 3rd world countries and suspect nations like Russia, Ukraine, China, etc...

They don't convert, drain bandwidth and are possibly infected.
why 3rd world countries !!
 
Honestly, just block all IPs coming from 3rd world countries and suspect nations like Russia, Ukraine, China, etc...

They don't convert, drain bandwidth and are possibly infected.

how do i block ips by country?
 
Thank for the input everyone... I added Stealth Login Page.
basically you will login with username, password, and an additional code.
incorrect login will redirect to a URL of your choice.

stealthlogin.jpg

if anyone is wondering where the url is redirecting to, its to this gif:

128.gif
 
Thank for the input everyone... I added Stealth Login Page.
basically you will login with username, password, and an additional code.
incorrect login will redirect to a URL of your choice.

View attachment 85620

if anyone is wondering where the url is redirecting to, its to this gif:

View attachment 85621
Lol, you should have redirected them to cia.gov or interpol or a very suspicious auto-download .exe
 
Look at these, to restrict access to login and admin pages:
https://wordpress.org/plugins/tags/wp-login
https://wordpress.org/plugins/tags/wp-admin

Have used these in the past:
https://wordpress.org/plugins/rename-wp-login/
https://wordpress.org/plugins/stealth-login-page/
https://wordpress.org/plugins/login-lockdown/
https://wordpress.org/plugins/limit-login-attempts/

And use wordfence, with their firewall, and cloudflare to, you should be alright after using these.
 
Great ideas guys! thank you all, i feel like i secured my website enough now.
 
Back
Top