5 ms·
It's even worse. Why can someone just keep trying to login on default WP installation? Why can they try to guess usernames? First thing I install is: https://ww
by digitalengineer 11y ago
It's even worse. Why can someone just keep trying to login on default WP installation? Why can they try to guess usernames? First thing I install is: https://www.wordfence.com https://www.wordfence.com
- throwaway21816 11y ago$10 has been deposited into your wordfence affiliate account. Thank you, have a good day.
- poopsintub 11y agoDownvoting a throwaway account. Stooping to new levels.
- dang 11y agoWe've banned this account for repeatedly breaking the HN guidelines.
- snowwrestler 11y agoDoes Wordpress still not have basic rate limiting on forms?
- krapp 11y agoIt does not.
- CLGrimes 11y agoEven still, default login attempts are set at 20. I've had a lot of recent bruteforce attacks, and set that delimiter to 5. On top of that, I try changing the wp-login location with 'rename wp-login'[1], and set it to something like http://www.site.com/hello http://www.site.com/hello . Doesn't stop everyone, but helps cut down attempts. [1]https://wordpress.org/plugins/rename-wp-login/ https://wordpress.org/plugins/rename-wp-login/
- lightlyused 11y agoEnumerating evil is never the correct solution.