![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
See signature :)
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
|
brute force on wp-login.php
What pisses me off is that my stats (awstats etc) gets messed up by them, there is no way to have accurate stats because more hits are from bots than from actual visitors.
/rant |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Industry Role:
Join Date: Aug 2007
Posts: 6,697
|
http://configserver.com/cp/csf.html and ban them manually if you can't use it to automatically ban them. I think there is a setting to do it.
![]()
__________________
You don't like my posts? Put me on ignore or fuck right off. I'll say what I want. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
See My SIG!
Industry Role:
Join Date: Dec 2003
Location: Sunny Paradise
Posts: 2,099
|
theres a patch for that!
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
See signature :)
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
|
If you mean for attacks then I installed wp harden plugin which redirects wp-login.php to home page.
Now I am looking for patch to see accurate awstats. Because now my numbers are inflated by bots and stats are basically useless, no idea how many of those are real visitors, how many bots. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
emperor of my world
Join Date: Aug 2004
Location: nethalands
Posts: 29,903
|
same here, seems like almost every wordpress site has this. What are those bots trying to accomplish? No way the passes can be cracked. Seems so useless in my opinion.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
It's 42
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
|
https://illuminatikarate.com/blog/ex...stats-reports/ |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
See signature :)
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
|
Quote:
Its either I prevent attacks (by using harden wp) but have compromised awstats or I do not prevnt attacks but fix awstats using this method ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Aug 2001
Location: Æøå
Posts: 2,001
|
I had the same problem but I've only allowed my IP to access the loginpage and now I get accurate (and disappointing) stats. It was my host who sat it up so don't ask me how
![]() btw for blogs I like to use the jetpack stats rather than awstats, it's real time too..
__________________
Make some easy pay per click money with Exoclick |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
. . .
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
|
it's even worse if you are running forums
![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Oct 2003
Location: L.A.
Posts: 5,740
|
Ban ip's for unsuccessful logins
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Jan 2012
Location: cyberspace
Posts: 790
|
EDIT** Never mind. Looking at the directory structure online wp-login.php is in the root directory.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So Fucking Fossilized
Industry Role:
Join Date: Sep 2011
Posts: 1,432
|
Use a more advanced statistics program.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Industry Role:
Join Date: Jan 2012
Location: cyberspace
Posts: 790
|
Here's a trick you can try. I haven't tried it but it looks like it should work.
Password protect your admin directory with .htacess and then use .htaccess to filematch that protection to your login.php file. http://www.inmotionhosting.com/suppo...n-php-attempts |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Registered User
Industry Role:
Join Date: May 2013
Location: Tampa
Posts: 97
|
Only allow access from your static ips to the admin section deny all else.
__________________
Enterprise Vps Solutions Internet Solutions Connecting The World Managed Services "Cpanel" - Virtual Private Server (VPS) - Control your own Cloud System - Shared Cpanel Web Hosting on HA www.Enterprisevpssolutions.com Tampa, Florida in Hivelocity Datacenter their Network Providers Global Crossing, Level3, TW Communications, Cogent, Global Telecom and Technology |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Porn is Dead. Move along.
Industry Role:
Join Date: Aug 2006
Posts: 13,295
|
yup use htaccess to only allow your ip in admin
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 |
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,242
|
htaccess block everyone from admin, do signups via the front end and disable redirection to admin after signup
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence. ![]() WP Stuff |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 |
visit hardlinks.org
Industry Role:
Join Date: Jun 2003
Location: Las Vegas , Nv >>> [email protected] or icq 94994627 anytime
Posts: 18,362
|
what would that htaccess command look like?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 |
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,242
|
Code:
Order Deny,Allow Deny from all Allow from xx.xx.xx.xx
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence. ![]() WP Stuff |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 |
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,242
|
or this
Code:
<Files wp-login.php> Order Deny,Allow Deny from all Allow from xx.xx.xx.xx </Files>
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence. ![]() WP Stuff |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Pay It Forward
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 76,937
|
__________________
TRUMP 2025 KEKAW!!! - Support The Laken Riley Act!!! END DACA - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
See signature :)
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
Confirmed User
Join Date: Oct 2003
Location: localhost
Posts: 699
|
10000's of plugin to autoban after x attempts.
__________________
------------------------------- Oliver Smith "Drunk Russian Hackers are Invincible" ASCII P0rn rules aim: olvrsmt icq: 21018030 |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 |
Sexy Beast
Industry Role:
Join Date: Jan 2005
Posts: 617
|
You can change this file name with no issues.
__________________
AdultWebHosting.com ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
So Fucking Banned
Industry Role:
Join Date: Oct 2007
Posts: 6,748
|
Great thread. Thanks for the experts pitching in. Shit is frustrating.
|
![]() |
![]() ![]() ![]() ![]() ![]() |