+ Reply to Thread
Results 1 to 4 of 4

Thread: Wordpress Security / Brute Force / Proxies question

  1. #1
    Junior Member
    Join Date
    Mar 2012
    Posts
    35
    Thanks
    10
    Thanked 25 Times in 14 Posts
    Rep Power
    1

    Wordpress Security / Brute Force / Proxies question

    It seems as if someone is trying to brute force my wordpress login. I am not so worried about it because the strength of my password. I also have security in place that locks the ip out after a couple of errors, but I was wondering..... If they are using a proxy, will they run out of ips? I am more concerned about my site slowing down if they get several machines rather than them actually breaking in.

    91.224.160.35 lockout
    99.128.101.225 lockout
    24.199.189.66 lockout
    212.183.165.15 lockout
    217.128.175.91 lockout
    81.202.44.26 lockout
    93.160.220.14 lockout
    83.165.194.24 lockout
    80.59.98.59 lockout


    Also can you guys give me some insight about these ips... I checked a couple and they seem EU based, but other than that I do not know much about them.

  2. #2
    Established Member
    Join Date
    Mar 2012
    Posts
    106
    Thanks
    70
    Thanked 122 Times in 66 Posts
    Rep Power
    4
    Seems like most of the usual ways to protect your WP install wouldn't work here.

    I would investigate either just having the wp-login.php being only accessible to your own IP (if you have a static IP) or for the mean-time just block everything trying to access wp-login.php .

  3. The Following 2 Users Say Thank You to monty For This Useful Post:

    Dave McM (August 28th, 2012), loanuniverse (August 28th, 2012)

  4. #3
    Junior Member
    Join Date
    Mar 2012
    Posts
    35
    Thanks
    10
    Thanked 25 Times in 14 Posts
    Rep Power
    1
    Yeahh, I might have to fiddle with the .htaccess file. Just got to figure out the ips of the computers that I sometime use for updating the site.

  5. #4
    Established Member
    Join Date
    Mar 2012
    Posts
    106
    Thanks
    70
    Thanked 122 Times in 66 Posts
    Rep Power
    4
    A clever way of implementing the blocking rule when you have multiple computers, IP addresses etc, that I once read, is to allow access to wp-login.php only via a link on an obscurely named static HTML page (which only you know).

    Checked on Google to find where I read this, and you can read the original post here.

  6. The Following 2 Users Say Thank You to monty For This Useful Post:

    grynge (August 28th, 2012), loanuniverse (August 28th, 2012)

+ Reply to Thread

Similar Threads

  1. Replies: 11
    Last Post: August 4th, 2012, 10:42 PM
  2. WordPress Security Mod
    By tke71709 in forum Website 101
    Replies: 1
    Last Post: February 22nd, 2012, 8:20 AM
  3. Question for the Techies about Wifi security
    By JJMcClure in forum Foo - everything off-topic
    Replies: 16
    Last Post: January 11th, 2012, 2:38 AM
  4. Godaddy + Wordpress + another quick question
    By Dreich in forum Website 101
    Replies: 18
    Last Post: July 2nd, 2010, 7:43 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts