You must be logged in to post Login


Lost Your Password?

Search Forums:


 






Minimum search word length is 4 characters – Maximum search word length is 84 characters
Wildcard Usage:
*  matches any number of characters    %  matches exactly one character

Preventing Wordpress Hackers

No Tags
UserPost

5:32 am
September 8, 2013


Financial Independence

Australia

Member

posts 7

I have a wordpress plugin which automatically blocks IP addresses trying to log into my admin panel after a number of incorrect password attempts. I have noticed that I have started recieving regular notifications of this happening, so I locked my /wp-admin/ directory using 'Password Protect Directories' in CPanel.

This doesn't seem to have stopped the login attempts, they are somehow still getting to my login page. Has anyone seen this before and can they give me any tips?

6:05 am
September 8, 2013


Financial Independence

Australia

Member

posts 7

Actually, just to update I figured out what my issue was. Hopefully this can help others as well so I thought I'd share my solution.

 

It turns out that the hackers weren't trying to access my admin area using /wp-admin/ but by simply using /wp-login.php

 

Using this tutorial I locked down my wp-login file and the bad requests stopped instantly.

9:42 am
September 8, 2013


debtroundup

Raleigh

Member

posts 190

I have a post going up on Modest Money this wednesday about protecting your site.  You shouldn't ever try to prevent access to wp-admin because there are many plugins that use it.  You should always lock down wp-login.php.  Nice work!

Debt Roundup | Sprout Wealth | Empowered Shopper

Connect with me on Twitter and Facebook

6:00 am
September 9, 2013


Financial Independence

Australia

Member

posts 7

I've had /wp-admin/ locked down for a few weeks and haven't noticed any ill effects. I'll definitely keep an eye out for your post though, it's a fine line between securing your site and going overboard and potentially effecting usability.

9:28 pm
September 9, 2013


Anton Ivanov

San Diego, CA

Member

posts 129

I would highly recommend the Better WP Security plugin. Once you set it up, it's the most full-proof WP protection I've seen. For example for log-ins into the admin panel, it actually renames and redirects the default WP log-in path to whatever you want to to prevent simple brute force attacks. You can also set a limit on incorrect log-in attempts, block certain users from accessing your site altogether, etc., etc.

Hope it helps you out!

7:45 am
September 11, 2013


Eric – PersonalProfitability.com

Portland, OR

Member

posts 2120

I have Wordfence on my most important sites (big server resource hog, so not all sites) and WP Firewall. The combination is pretty solid at keeping the bad guys out. There are lots of hacks that don't require using wp-login.

No Tags

About the Yakezie.com Forum

Forum Timezone: America/Los_Angeles

Forum Stats:

Groups: 2
Forums: 9
Topics: 6383
Posts: 84794

Membership:

There are 13651 Members
There have been 20 Guests

There are 9 Admins
There are 8 Moderators

Top Posters:

My Personal Finance Journey – 3159
Khaleef @ KNS Financial – 3149
Budgeting in the Fun Stuff – 3048
Sustainable PF – 2759
Miss T @ Prairie Eco-Thrifter – 2213
Eric – PersonalProfitability.com – 2120

Administrators: The College Investor (1935 Posts), Financial Samurai (1803 Posts), LaTisha @YoungFinances (1715 Posts), Forest Parks (1337 Posts), 20s Finances (1147 Posts), Money Reasons (697 Posts), Chris Johnson (78 Posts), Sydney at Untemplater (0 Posts), Suba (0 Posts)

Moderators: Suba @ Wealth Informatics (1876 Posts), sooverthis (1041 Posts), PK @ DQYDJ (361 Posts), jmichelsen (208 Posts), Ramona (13 Posts), JeremyNJohnson (4 Posts), Moderator (0 Posts), rackgeek (0 Posts)