Seeing failed Wordpres log ins that are not me

crsx1

Newbie
Joined
Aug 8, 2014
Messages
46
Reaction score
0
Hey guys. I have the free Wordfence plugin and it always emails me when I log on, but recently starting last night I've noticed that there have been attempts to log into my site that are not me. They are using 'admin' as the username which won't get them too far. Are there any steps to take to eliminate log in attempts like this or are they normal? The failed log ins get locked out after 20 and I get notified of that.
 
Very common these days and they seem to come and go in waves. Set the lock out settings lower if it makes you feel better, but not having admin is a great start....and having a great password....
 
It looks like someone is trying to brute force their way into your website. I'm assuming you have a plugin such as Login Lockdown since you said they get locked out after 20 attempts. I had someone try to do this to one of my websites about 3 months ago, so I just set the login attempt limit to 3.

Another great plugin you could use is Rename wp-login.php. It intercepts the request for the WP-Login.php and the WP-Admin.php file (rendering WP-Login and Wp-Admin inaccessible) and allows you to access your Wordpress dashboard from a different file name. Since I've installed both of these plugins, I haven't had anyone attempt to brute force their way into my website.
 
Last edited:
I am using Wordfence Security Plugin and Limit login attempts, Both are free and works great.

The above suggestion is also good.

This is Normal, Do not worry.
 
Why did you set the lockdown limit to 20? Set it to 5 or 3 attempts and a lockout time of 24 hours.
 
Yes, don't have anything default. Changing your username as well as password simply makes everything difficult for them.
 
Good info guys. Yes it was set at 20 by default and I never had any problems until recently so I'm addressing them. Of course my username isn't admin so any brute force login is a lot tougher. Wordfence seems to have a lot of options for logins and lockout stuff which I've tightened up. dang hackers.
 
Good info guys. Yes it was set at 20 by default and I never had any problems until recently so I'm addressing them. Of course my username isn't admin so any brute force login is a lot tougher. Wordfence seems to have a lot of options for logins and lockout stuff which I've tightened up. dang hackers.

You would be surprised how many bruteforce attempts there are, even on systems that are not advertised publicly (say, private file server that nobody knows about). It's just automated tools that script kiddies use to try and get in. It could be that it's not even you being targeted - they might be trying to break into everything their script has in its way. As others already mentioned - as long as you don't use the default username and some very simple passwords, it would be extremely hard, if not nearly impossible for someone to get in by bruteforce alone. If you find those failed login attempt notifications annoying, do as someone already mentioned and change the location of the login script to another name.
 
You will be surprised by the hacking amounts daily.As long as you see that they are trying you are fine,when it stops...I had the same with wordfence/very difficult password,not saved anywhere,virus - malware-trojan free system etc/ They were trying so much that at the end they managed to break into my site and created another 2 admins.
That was the end of wordfence for me :)
 
Back
Top