Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Wordpress Brute Force Attack Has Username

Options
  • 26-01-2016 10:14pm
    #1
    Closed Accounts Posts: 7,967 ✭✭✭


    Hi all,

    I have a Wordpress site that's been getting brute force attacked for the last 6 months (at the very least, I only took it over then. I have Sucuri Security installed and just checked the logs to see that there are multiple failed logins from different IPs using the correct username. The username is pretty unusual so am wondering a few things:-
    1. How has the attack worked out that it has the correct username
    2. Is there much point in changing the username if an attack is guessing it within 6 months? Actually, just checked and Wordpress says my username cannot be changed? So I can't do anything here?
    3. What are the best practices for protecting against these types of attack?
    4. Any other good security plugins I should be using?

    Thanks for looking


Comments

Advertisement