Wordpress Exploit ... Heads Up For BHW Members

Good tip. Everyone talks about the need for "hardened" passwords, yet this is the 1st time I've thought about the need to also change the Username away from default.

As an aside, isn't there a plugin you can install that prevents any kind of sign-in for "x" amount of time, in the event that there are "y" number of failed login attempts?
 
"Update: The easiest way to do this is create a new user account in WordPress (give it admin access). Then login with that username and delete your old account."
 
Spotted this today as well.

Anyone using Heart Internet as a hosting provider, they've put a mandatory serverside username/password on all Wordpress admin directories as a tempory measure.

Caused me no end of headaches with a few clients saying they couldn't log into their accounts earlier... But better safe than sorry I guess.
 
How do I change the username?
I can't delete the admin profile and I can't change the admin username.
Backup your files [do not be foolish]. Then install the WordPress plugin Better WP Security
That should solve your problem in a real hurry. There are other ways of doing this but you seem like the type of person who needs the simplest solution. I hope this helps! Locate the plugin Better WP Security
 
Last edited:
Please don't call brute force attacks "exploits". It's misleading and causes unnecessary stir.

A simple plugin to safeguard against brute force is Limit Login. Everyone should make a habit of uploading on new installs.
 
250 000 i.ps already. Login LockDown will save you at least from brute force attacks.
 
I learned my lesson when those Albanians hacked my first wordpress site, never use admin.
 
to secure wordpress its easy ,
every hacker need a login,

just protect wp-login.php with httaccces password protect
if they can manage change the password still they need to login first to get wp admin page
 
People really need to get rid of that admin username. Recently I saw someone trying that on mine but luckily I had changed it long before. I got that plugin wp better security(I think that's the name), and it shows you a log of people trying to sign in.

I use that plugin as well, you can change admin account with it, set up logging, auto-ban etc. it's top notch.
 
My host has also placed a temporary username and password on wp-admin. You need to login to get access to the wp-admin page before you can login to your dashboard.
 
Back
Top