![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Nov 2011
Location: montreal
Posts: 588
|
Just got notifications of several log in attempts to my site as admin
I am getting a lot of notifications from these spammers
192.99.154.24 77.247.181.162 they are using TOR.. what should I do.. SO far 50 trials with different IPs all appear as blocked by google |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
So Fucking Banned
Industry Role:
Join Date: Feb 2001
Location: Taipei
Posts: 25,198
|
are they hitting your login.php page (wordpress) or some other login page? You can ask your host to password protect that login page.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Jun 2003
Location: My High Horse
Posts: 6,346
|
I get them at least once a day I cant protect my login page because I have members that comment and that wouldnt really be conducive The first thing you want to do is make sure that if the admin account exists it doesnt have admin privileges just ordinary ones that way if they do manage to brute force it it doesnt get them anything if you have wordpress by all means run wordfence.
there are some php and some apache stuff to weed out some proxies...google it if ya need more help hit me up via email
__________________
Mike South It's No wonder I took up drugs and alcohol, it's the only way I could dumb myself down enough to cope with the morons in this biz. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Jun 2012
Posts: 457
|
You can get a list of tor IP's here and block them;
https://check.torproject.org/cgi-bin/TorBulkExitList.py The list is very dynamic though I pull a fresh my list every 15 mins. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
So Fucking Banned
Industry Role:
Join Date: Apr 2003
Location: online
Posts: 8,766
|
use wordpress plugins, like: captcha on wp-login and bruteprotect
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 | |
So Fucking Banned
Industry Role:
Join Date: Jun 2010
Location: Tokyo Red Light District
Posts: 2,145
|
Quote:
Get Word-Fence plug in or Fail2Ban Got our first from a TOR exit IP recently as well. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 |
Confirmed User
Industry Role:
Join Date: Nov 2011
Location: montreal
Posts: 588
|
Hellog guys, thanks. I already have wordfence. Good idea about the admin privileges.
Mike, I will be contacting for sure if I need more guidance! thanks!! I used to get one or two every dat, but yesterday 50 different Ips (each was lock oit after 20 attempts) really made me wonder was going on |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Confirmed User
Industry Role:
Join Date: Jan 2012
Location: NC
Posts: 7,683
|
rename login.php to somethign else.,
__________________
SSD Cloud Server, VPS Server, Simple Cloud Hosting | DigitalOcean
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Nov 2002
Location: FL - TN/NC
Posts: 5,211
|
Step 1 is this.
Never use defaults is always step 1 on an install, step 2 is to keep records of what you change them to. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Join Date: May 2008
Location: Pennsylvania
Posts: 4,204
|
I use wordfence and the user locker plugin. User Locker automatically locks an account with too many failed login attempts, and it can't be restored unless another administrator removes the lock.
Plus you can manually lock accounts, so the first thing I do is create "admin" to set up my wordpress, then create a different user name with administrator privileges; log into the new account, and lock and disable "admin."
__________________
Online strip gaming with sexy gamer girls Best thing I ever signed up for: Quality Razors, Cheap Price |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
I'm a great bowler.
Industry Role:
Join Date: Nov 2003
Location: Right Outside of Normal.
Posts: 13,310
|
This. Bury that mother fucker deep into some sub-directory. 99% of the time they don't do this shit manually. They search for defaults and go from there. If your login.php is located somewhere else, or you don't even have an admin directory, they'll go somewhere else.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Promoting Debate on GFY
Industry Role:
Join Date: Apr 2007
Posts: 27,173
|
![]()
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Carpe Visio
Industry Role:
Join Date: Jul 2002
Location: New York
Posts: 43,052
|
I manage a blog for someone who creates Paleo cookbooks and is a NYT Best Seller. The blog gets about 75-100k visitors on any given day.
I use WordFence and get notifications when people attempt to login. It happens all day long, 24/7. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
Confirmed User
Industry Role:
Join Date: May 2010
Posts: 5,735
|
I only allow my IP through to wp-login.php and deny everyone else so they can't even see the page let alone attempt to bruteforce.
|
![]() |
![]() ![]() ![]() ![]() ![]() |