3 ms·
I'm curious, what security tools did you have in place that were failing to stop the attacks?
by perezbox 11y ago
I'm curious, what security tools did you have in place that were failing to stop the attacks?
- jakejake 11y agoIronically I can't login to their site from my current IP to see what security plugin they are using! It was stopping the attacks - it was just that the attacker would try 10 password attempts, then get blocked by the plugin and trigger the alert message. Then the attacker would switch IPs and try 10 more. One morning they had gotten a ton of messages and I found about 250k login attempts in the security logs. So the plugin was doing it's job, but it's better now that the attacks don't even make it that far. In fact you can't even hit a page within the wp-admin folder which is nice in case some type of zero-day exploit surfaces on a file within that area.
- SHIT_TALKER 11y agoSounds like WordFence. Email notifications are configurable. Turning off most of them is advisable. I've had trouble with users with nominally static IP addresses changing with sufficient frequency to be too much of an annoyance to stay with IP whitelist. Limiting the failed login attempts and maxing out the lockout period cuts down on a lot of the bot activity.