It's Crazy How much WP Websites get Attacked...

What other CMS do you use and why?

Webflow has a limited number of pages you can post, correct me if I am wrong
We will see in the future. Currently I'm not very interested in e-commerce development.
 
I do run few medium-sized websites, and I could not believe how many brute force attempts my /wp-admin page gets after installing the plugin that limits brute force attempts and logs login attempts.
Most of my websites get around 400-700 DIFFERENT login tries per day all from different IP's, with each sending multiple password tries, so essentially even with brute force limiting I get around 2000-2500 password tries per day sent :D

God only knows how many it was before the brute force limiter...Blows my Mind that there are so many people trying to ''hack'' websites.

When installing new wordpress installation, change your username from admin to something else , but not your website name as they try for it quite frequently..
also..Install a plugin that changes the location of your login page to something else..
I do run few medium-sized websites, and I could not believe how many brute force attempts my /wp-admin page gets after installing the plugin that limits brute force attempts and logs login attempts.
Most of my websites get around 400-700 DIFFERENT login tries per day all from different IP's, with each sending multiple password tries, so essentially even with brute force limiting I get around 2000-2500 password tries per day sent :D

God only knows how many it was before the brute force limiter...Blows my Mind that there are so many people trying to ''hack'' websites.

When installing new wordpress installation, change your username from admin to something else , but not your website name as they try for it quite frequently..
also..Install a plugin that changes the location of your login page to something else..
No... the crazy is to see how many user:admin password:admin or 123456 WP sites out there hahaha!
 
I do run few medium-sized websites, and I could not believe how many brute force attempts my /wp-admin page gets after installing the plugin that limits brute force attempts and logs login attempts.
Most of my websites get around 400-700 DIFFERENT login tries per day all from different IP's, with each sending multiple password tries, so essentially even with brute force limiting I get around 2000-2500 password tries per day sent :D

God only knows how many it was before the brute force limiter...Blows my Mind that there are so many people trying to ''hack'' websites.

When installing new wordpress installation, change your username from admin to something else , but not your website name as they try for it quite frequently..
also..Install a plugin that changes the location of your login page to something else..
The plugin is great expect when you site gets so big that so many people will try to brute force attempts that you will eventually get locked out of your account until the attacks stop lol

Since /wp-admin is the most common, most people first guess is that address, would suggest changing it to something else so less people have an attempt to attempt a brute force
 
Pretty, never had any break-ins though as I have quite some security hosting my own sites
 
It's normal just check GitHub you will find a bunch of scripts that auto search wp sites and brute force it with the username:password you have entered.
In other forums, I've seen people selling hacking WordPress admin panels for 1$ each lol. I suggest changing the admin panel location because mostly automatic scripts only performs bruteforce attack on wp-admin and won't bother finding the location of the admin panel if you have changed to something else
hello, could you share the website about hacking wp admin panels
 
Blows my Mind that there are so many people trying to ''hack'' websites.
The thing is - WP is standartized and there are endless websites. You can easily find em and you can attack em automated - the Wordpress attacks are normaly not by someone who wants to attack your site in special, but attacks hundreds at the same time. Some will break under the attack.
WP is a blessing and a curse when it comes to security - it is more mature than probably all homebrew systems, but it is also vulnerable to automated attacks because it is so widespread and security vulnerabilities often affect many thousend websites.
 
That is normal, did you lookup for example for SSH logins? Nothing new.

If you look at your SSH Logins you will see "many brute force attemps" and many other things against your server.
The wordpress is the same, that is due to Wordpress is ONE OF MOST USED CMS in the world, attract hackers, bad bots and bad guys also ;)
 
Now i'm getting a little bit of paranoid after everything I read I will defenetely secure and change the passwords for comlicated ones every week so, is better than losse everything we work hard right!
 
Back
Top