Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 05-23-2013, 04:19 PM   #1
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
brute force on wp-login.php

What pisses me off is that my stats (awstats etc) gets messed up by them, there is no way to have accurate stats because more hits are from bots than from actual visitors.
/rant
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-23-2013, 04:37 PM   #2
signupdamnit
Confirmed User
 
signupdamnit's Avatar
 
Industry Role:
Join Date: Aug 2007
Posts: 6,697
http://configserver.com/cp/csf.html and ban them manually if you can't use it to automatically ban them. I think there is a setting to do it.
__________________

You don't like my posts? Put me on ignore or fuck right off. I'll say what I want.
signupdamnit is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 01:39 AM   #3
TrafficRush
See My SIG!
 
TrafficRush's Avatar
 
Industry Role:
Join Date: Dec 2003
Location: Sunny Paradise
Posts: 2,099
theres a patch for that!
__________________
INTRALINK DSP | SIGNUP TO MAKE BANK NOW
Skype: Traffic-RushHour | ICQ: 467617514
TrafficRush is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 03:35 AM   #4
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
Quote:
Originally Posted by TrafficRush View Post
theres a patch for that!
If you mean for attacks then I installed wp harden plugin which redirects wp-login.php to home page.

Now I am looking for patch to see accurate awstats. Because now my numbers are inflated by bots and stats are basically useless, no idea how many of those are real visitors, how many bots.
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 03:46 AM   #5
nico-t
emperor of my world
 
Join Date: Aug 2004
Location: nethalands
Posts: 29,903
same here, seems like almost every wordpress site has this. What are those bots trying to accomplish? No way the passes can be cracked. Seems so useless in my opinion.
nico-t is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 05:21 AM   #6
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
https://illuminatikarate.com/blog/ex...stats-reports/

It's in the conf file. You can exclude static IP addresses too.
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 08:11 AM   #7
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
Quote:
Originally Posted by Barry-xlovecam View Post
https://illuminatikarate.com/blog/ex...stats-reports/

It's in the conf file. You can exclude static IP addresses too.
Very nice, however I have an issue: I installed harden wp plugin so hits to wp-login.php are redirected to home page, meaning that awstats would count them because it won't be backend hit (I assume).
Its either I prevent attacks (by using harden wp) but have compromised awstats or I do not prevnt attacks but fix awstats using this method
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 09:30 AM   #8
geirlur
Confirmed User
 
geirlur's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Æøå
Posts: 2,001
I had the same problem but I've only allowed my IP to access the loginpage and now I get accurate (and disappointing) stats. It was my host who sat it up so don't ask me how

btw for blogs I like to use the jetpack stats rather than awstats, it's real time too..
__________________
Make some easy pay per click money with Exoclick
geirlur is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 11:01 AM   #9
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
it's even worse if you are running forums
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 11:23 AM   #10
PornDiscounts-V
Confirmed User
 
PornDiscounts-V's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: L.A.
Posts: 5,740
Ban ip's for unsuccessful logins
PornDiscounts-V is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 11:49 AM   #11
SplatterMaster
Confirmed User
 
SplatterMaster's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: cyberspace
Posts: 790
EDIT** Never mind. Looking at the directory structure online wp-login.php is in the root directory.

Last edited by SplatterMaster; 05-24-2013 at 12:02 PM..
SplatterMaster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 12:03 PM   #12
Dankasaur
So Fucking Fossilized
 
Industry Role:
Join Date: Sep 2011
Posts: 1,432
Use a more advanced statistics program.
Dankasaur is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 12:25 PM   #13
SplatterMaster
Confirmed User
 
SplatterMaster's Avatar
 
Industry Role:
Join Date: Jan 2012
Location: cyberspace
Posts: 790
Here's a trick you can try. I haven't tried it but it looks like it should work.

Password protect your admin directory with .htacess and then use .htaccess to filematch that protection to your login.php file.

http://www.inmotionhosting.com/suppo...n-php-attempts
SplatterMaster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 08:56 PM   #14
EnterpriseVpsSolutions
Registered User
 
Industry Role:
Join Date: May 2013
Location: Tampa
Posts: 97
Only allow access from your static ips to the admin section deny all else.
__________________
Enterprise Vps Solutions Internet Solutions Connecting The World
Managed Services "Cpanel" - Virtual Private Server (VPS) - Control your own Cloud System - Shared Cpanel Web Hosting on HA
www.Enterprisevpssolutions.com Tampa, Florida in Hivelocity Datacenter their Network Providers Global Crossing, Level3, TW Communications, Cogent, Global Telecom and Technology
EnterpriseVpsSolutions is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-24-2013, 09:27 PM   #15
Fat Panda
Porn is Dead. Move along.
 
Fat Panda's Avatar
 
Industry Role:
Join Date: Aug 2006
Posts: 13,295
yup use htaccess to only allow your ip in admin
Fat Panda is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2013, 07:09 AM   #16
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,242
htaccess block everyone from admin, do signups via the front end and disable redirection to admin after signup
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2013, 09:34 AM   #17
~Ray
visit hardlinks.org
 
~Ray's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Las Vegas , Nv >>> [email protected] or icq 94994627 anytime
Posts: 18,362
what would that htaccess command look like?
~Ray is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2013, 11:41 AM   #18
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,242
Quote:
Originally Posted by ~Ray View Post
what would that htaccess command look like?
Code:
Order Deny,Allow
Deny from all
Allow from xx.xx.xx.xx
file placed in wp-admin dir
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2013, 11:42 AM   #19
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,242
or this

Code:
<Files wp-login.php>
Order Deny,Allow
Deny from all
Allow from xx.xx.xx.xx
</Files>
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2013, 12:36 PM   #20
brassmonkey
Pay It Forward
 
brassmonkey's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 76,937
http://wordpress.org/plugins/hc-custom-wp-admin-url/
__________________
TRUMP 2025 KEKAW!!! - Support The Laken Riley Act!!!
END DACA - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com
brassmonkey is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2013, 01:05 PM   #21
BareBacked
Confirmed User
 
Join Date: Feb 2007
Location: www.BareBacked.com
Posts: 3,685
this is a huge pain in the ass
__________________
NEW SITE PAYING $30 for a $1 TRIAL

Selfies
BareBacked is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-25-2013, 04:33 PM   #22
mineistaken
See signature :)
 
mineistaken's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: ICQ 363 097 773
Posts: 29,656
Quote:
Originally Posted by EnterpriseVpsSolutions View Post
Only allow access from your static ips to the admin section deny all else.
Question - does awstats count denied visitors? I mean those would still technically hit the site (and show up on the stats?).
mineistaken is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-26-2013, 07:06 AM   #23
geirlur
Confirmed User
 
geirlur's Avatar
 
Industry Role:
Join Date: Aug 2001
Location: Æøå
Posts: 2,001
Quote:
Originally Posted by mineistaken View Post
Question - does awstats count denied visitors? I mean those would still technically hit the site (and show up on the stats?).
Doesn't show up for me
__________________
Make some easy pay per click money with Exoclick
geirlur is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 12:52 AM   #24
tahiti
Confirmed User
 
Join Date: Oct 2003
Location: localhost
Posts: 699
Quote:
Originally Posted by mineistaken View Post
What pisses me off is that my stats (awstats etc) gets messed up by them, there is no way to have accurate stats because more hits are from bots than from actual visitors.
/rant
10000's of plugin to autoban after x attempts.
__________________
-------------------------------
Oliver Smith
"Drunk Russian Hackers are Invincible"
ASCII P0rn rules
aim: olvrsmt
icq: 21018030
tahiti is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 01:22 AM   #25
KaliC
Sexy Beast
 
KaliC's Avatar
 
Industry Role:
Join Date: Jan 2005
Posts: 617
Quote:
Originally Posted by mineistaken View Post
What pisses me off is that my stats (awstats etc) gets messed up by them, there is no way to have accurate stats because more hits are from bots than from actual visitors.
/rant
You can change this file name with no issues.
__________________
AdultWebHosting.com
KaliC is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 05-29-2013, 01:26 AM   #26
Captain Kawaii
So Fucking Banned
 
Industry Role:
Join Date: Oct 2007
Posts: 6,748
Great thread. Thanks for the experts pitching in. Shit is frustrating.
Captain Kawaii is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.