9 ms·
I run a web server with some 50+ Wordpress installs on it. You better believe Fail2Ban is necessary. Without it all resources would be consumed by brute force a
by treerunner 10y ago
I run a web server with some 50+ Wordpress installs on it. You better believe Fail2Ban is necessary. Without it all resources would be consumed by brute force attacks. If someone knows of a better way I would like to hear about it.
- falcolas 10y agoIn my experience, better to let a webserver handle stopping bad traffic by whitelisting WordPress endpoints. Parsing a url and returning 404 from nginx is cheap and scalable, and allows through legitimate traffic that may be sharing an IP (such as TOR).
- snowwrestler 10y agoWe use the WordFence module to block brute force attacks, seems to work fine. I cannot believe that Wordpress still ships without basic rate limiting on its login form.