Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

Wordpress Brute Force Attack Has Username

  • 26-01-2016 10:14PM
    #1
    Closed Accounts Posts: 7,967 ✭✭✭


    Hi all,

    I have a Wordpress site that's been getting brute force attacked for the last 6 months (at the very least, I only took it over then. I have Sucuri Security installed and just checked the logs to see that there are multiple failed logins from different IPs using the correct username. The username is pretty unusual so am wondering a few things:-
    1. How has the attack worked out that it has the correct username
    2. Is there much point in changing the username if an attack is guessing it within 6 months? Actually, just checked and Wordpress says my username cannot be changed? So I can't do anything here?
    3. What are the best practices for protecting against these types of attack?
    4. Any other good security plugins I should be using?

    Thanks for looking


Comments

Advertisement