hackers trying to hack my site with weird user names

don6644

Junior Member
Joined
Jul 13, 2023
Messages
140
Reaction score
263
I have wordfence security installed in one of my wordpress based sites. it's set to automatically block anybody who tries to log in using the wrong username. and it emails me any time this happens with the user name they tried to use.
if they tried to use something common like admin i would understand. but why do they use weird ass user names? for example, someone just tried logging in with user name dycx
why would my user name be dycx?
 
someones maybe was, and its forever in their dictionary. Hackers a lot of the times go by brute force, so keeping records of every victim footprint, is a good way to catch people over and over again, lol

I bet you wouldn't be the first to be double hacked if it ever happened once! lol Be careful out there. watch those plugins, and those dormant themes and things.
 
Hey man,
did you try to put your website through Cloudflare?
 
MMmmm... What's the rate of bruteforce? How many times are they attempting a login. During the day. What time? I understand if You don't want to answer these questions but realise its not helping
 
Hey man,
did you try to put your website through Cloudflare?
no, but I was thinking about it. the problem is I dont like those stupid captcha things checking your browser to make sure you are not a bot. I dont want to harass legit users.
someones maybe was, and its forever in their dictionary. Hackers a lot of the times go by brute force, so keeping records of every victim footprint, is a good way to catch people over and over again, lol

I bet you wouldn't be the first to be double hacked if it ever happened once! lol Be careful out there. watch those plugins, and those dormant themes and things.
ok interesting. seems like an inefficient way to hack.
 
no, but I was thinking about it. the problem is I dont like those stupid captcha things checking your browser to make sure you are not a bot. I dont want to harass legit users.

ok interesting. seems like an inefficient way to hack.
Fair enough. I don't use it either. I prefer to work with Claude to improve my security day after day.
 
I have wordfence security installed in one of my wordpress based sites. it's set to automatically block anybody who tries to log in using the wrong username. and it emails me any time this happens with the user name they tried to use.
if they tried to use something common like admin i would understand. but why do they use weird ass user names? for example, someone just tried logging in with user name dycx
why would my user name be dycx?

because the script is designed to login with common or used usernames with matching password, sometimes few plugins or default usernames set by plugins used to get into sites, that's why scripts used every possible combination to login then it can be "XXX" "dcyx" "abc123"
 
no, but I was thinking about it. the problem is I dont like those stupid captcha things checking your browser to make sure you are not a bot. I dont want to harass legit users.

ok interesting. seems like an inefficient way to hack.

You know you can setup re-captcha on the admin page only to try mitigate or lower bruteforce attacks right ? Doenst have to be sitewide.
 
The hacker probably scraped usernames from wikipedia or something and doing a dictionary attack.

It's better to use cloudflare if the attacks persist.
 
Back
Top